import type { CommandEvidence, CommandExpectation } from "../schema/workspec.js"; export declare const COMMAND_OUTPUT_TAIL_LIMIT = 1024; export declare const EMPTY_COMMAND_OUTPUT = "[empty]"; /** Visible marker for a removed inherited value; it carries no source value. */ export declare const REDACTED_INHERITED_VALUE = "[redacted inherited value]"; export declare const SUPPRESSED_COMMAND_OUTPUT = "[command output suppressed after redaction safety check]"; export declare const TRUNCATED_COMMAND_OUTPUT = "\u2026 [truncated]"; /** Values captured when the child environment was constructed, never read at emission time. */ export interface InheritedValuesSnapshot { readonly values: readonly string[]; readonly named: Readonly>; } export declare function inheritedValuesSnapshot(values: readonly string[], named?: Readonly>): InheritedValuesSnapshot; /** * Produce the only persisted or rendered representation of command text. * Redaction is followed by an emission check; if its readable placeholder would * retain a value, the stream is suppressed and may lose its original tail. */ export declare function redactCommandOutput(snapshot: InheritedValuesSnapshot, stdout: string, stderr: string): { stdout: string; stderr: string; }; /** Redact a failure containing command-derived text without truncating its diagnostic. */ export declare function redactCommandFailure(snapshot: InheritedValuesSnapshot, message: string): string; /** Render an empty command stream with its explicit label only when that label is safe to emit. */ export declare function renderCommandOutputTail(snapshot: InheritedValuesSnapshot, value: string | undefined): string; /** Redact one command-derived field through the same bounded output representation. */ export declare function redactCommandText(snapshot: InheritedValuesSnapshot, value: string): string; /** Redact the complete command contract before it leaves the verifier. */ export declare function redactCommandEvidence(evidence: CommandEvidence, snapshot: InheritedValuesSnapshot): CommandEvidence; /** Reject serialized command expectations that retain a captured inherited value. */ export declare function commandExpectationMatches(snapshot: InheritedValuesSnapshot, expectation: CommandExpectation): boolean; /** Reject serialized command evidence that bypassed the command redaction boundary. */ export declare function commandEvidenceMatches(evidence: CommandEvidence, snapshot: InheritedValuesSnapshot): boolean; /** A persisted proof must retain the one canonical bounded and redacted output form. */ export declare function commandOutputMatches(snapshot: InheritedValuesSnapshot, stdout: string, stderr: string, expected: string): boolean;