import { type LifecycleMapping, type EpGateRow } from "./lifecycle-state.js"; /** One raw store entry as the sequencing consumes it (a KV entry stripped to what a CAS needs). */ export interface LifecycleKvEntry { value: Uint8Array; revision: number; operation: string; } /** * The injected write transport (§13.1 three-way split): the ONLY store access this sequencing * uses. `getRecord`/`createRecord`/`updateRecord` bind the space's RECORDS store (head + uid * keys; create/update map a CAS loss to an `EpEnvelopeError` `conflict`, the contract of core * `createRecordEntry`/`updateRecordEntry`); `getAuth`/`putAuth` bind the AUTH store (gate keys; * `putAuth` throws the broker's RAW error on a CAS loss — this module classifies it). A * transport implementation carries no sequencing decisions of its own. */ export interface LifecycleStateTransport { getRecord(key: string): Promise; createRecord(key: string, value: unknown): Promise; updateRecord(key: string, value: unknown, expectedRevision: number): Promise; getAuth(key: string): Promise; putAuth(key: string, payload: Uint8Array, expectedRevision: number): Promise; } /** Candidate read for a CAS-fenced head mutation (raw get; the auth decision is the CAS itself, * §13.1: a read is never a fence). A DEL/PURGE marker is CORRUPTION, never absence. */ export declare function headCandidate(t: LifecycleStateTransport, owner: string, actor: string): Promise<{ mapping: LifecycleMapping; revision: number; } | undefined>; /** Observe the gate (the candidate read feeding a revision-pinned CAS). A DEL/PURGE marker * refuses loudly. */ export declare function gateObserve(t: LifecycleStateTransport, lifecycleUid: string): Promise<{ row: EpGateRow; revision: number; } | undefined>; /** Try to reserve ONE explicit candidate UID. Create-only: `"won"` reserves it forever; * `"burned"` means the candidate already exists OR carries a deletion marker — either way it * is unusable, per the never-reuse rule. */ export declare function uidTryReserve(t: LifecycleStateTransport, lifecycleUid: string, audit: { owner: string; actor: string; mintedBy: string; }): Promise<"won" | "burned">; /** Reserve a fresh lifecycle UID space-globally (§13.1): mint a CSPRNG candidate, win its * create-only reservation, and on a collision burn the candidate and draw another. */ export declare function uidReserveFresh(t: LifecycleStateTransport, audit: { owner: string; actor: string; mintedBy: string; }): Promise; /** Read a UID reservation's audit `{ owner, actor }` (recorded at {@link uidTryReserve}). A * DEL/PURGE marker refuses loudly. */ export declare function uidReadReservation(t: LifecycleStateTransport, lifecycleUid: string): Promise<{ owner: string; actor: string; } | undefined>; /** Create the gate FROZEN under its operation's durable intent (create-only). A gate is BORN * only under an ACTIVATION intent, and only for a UID whose space-global reservation was * already WON. Born unmintable at generation 0. */ export declare function gateCreateFrozen(t: LifecycleStateTransport, args: { lifecycleUid: string; op: { opId: string; kind: "activation"; }; }): Promise<{ row: EpGateRow; revision: number; }>; /** CAS the gate `open → frozen` carrying the freezing operation's durable intent, at the * observed revision. The bar of every barrier. */ export declare function gateFreeze(t: LifecycleStateTransport, args: { lifecycleUid: string; revision: number; op: { opId: string; kind: "takeover" | "registration" | "retirement"; successor?: string; }; }): Promise<{ row: EpGateRow; revision: number; }>; /** CAS the gate `frozen → open` at the NEXT generation — op-pinned: only the freeze's own * operation reopens, as its barrier's final step. NEVER retirement (a retirement freeze never * reopens; its only exit is the terminal). */ export declare function gateReopen(t: LifecycleStateTransport, args: { lifecycleUid: string; revision: number; opId: string; }): Promise<{ row: EpGateRow; revision: number; }>; /** CAS the gate `frozen → retired` (terminal; never reopened) — op-pinned like the reopen. Only * an ACTIVATION orphan or a RETIREMENT terminalizes. Idempotence at `retired` is SAME-OP * idempotence. */ export declare function gateRetire(t: LifecycleStateTransport, args: { lifecycleUid: string; revision: number; opId: string; }): Promise<{ row: EpGateRow; revision: number; }>; /** The takeover barrier's epoch-advance head CAS. Advances the epoch by exactly one, * revision-pinned, only while the head is ACTIVE at the SAME uid; clears the revoked root * stamp in the SAME CAS; idempotent only for the barrier's OWN completed advance. */ export declare function headAdvanceEpochWithinTakeover(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; fromEpoch: number; opId: string; }): Promise<"advanced" | "already-advanced">; /** The issuance path's head CAS stamping the incarnation's ROOT credential — the mint protocol's * RELEASE-LAST final step. ABSENT → value ONLY (idempotent for the SAME value): root ROTATION * is exclusively a barrier's job, never this seam's. */ export declare function headSetCurrentRootCredential(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; credentialId: string; }): Promise; /** The retirement's head CONTAINMENT CAS (`active → retiring`, bound to the retirement * operation's durable intent). Idempotent for the operation's crash-resume; a stranger never * advances it. */ export declare function headBeginRetirement(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; opId: string; }): Promise<"retiring" | "already-retiring">; /** The retirement's TERMINAL head CAS (`retiring → retired`, op-pinned) — the LAST step: * `retired` ASSERTS completed cleanup, which is what makes the alias replaceable. The op * intent is dropped (it belongs to `retiring` only). */ export declare function headCompleteRetirement(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; opId: string; }): Promise<"retired" | "already-retired">; /** The full §13.1 initial-activation saga for a FRESH uid. See the executor's public doc * (implementations/auth `activateLifecycle`) for the refusal matrix; the head-CAS loser * terminalizes its own orphan gate (uid stays burned) and rethrows the `conflict`. */ export declare function runActivationSaga(t: LifecycleStateTransport, args: { owner: string; actor: string; managerInstance: string; }): Promise<{ mapping: LifecycleMapping; revision: number; opId: string; }>; /** The production ISSUANCE activation AT THE CALLER'S uid: same saga order with * ADOPT-instead-of-burn resume semantics (a reservation or frozen ACTIVATION gate already * carried by OUR alias at this uid is prior durable progress; a CAS loss to a SIBLING at the * same coordinates converges on the winner's state). See the executor's public doc * (implementations/auth `activateLifecycleAtUid`) for the refusal matrix. */ export declare function runActivationSagaAtUid(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; managerInstance: string; }): Promise; /** Resume a crashed activation saga from its durable coordinates. Reads the durable state and * finishes the SAME operation deterministically; idempotent; never advances another * operation's freeze. */ export declare function resumeActivationSaga(t: LifecycleStateTransport, args: { owner: string; actor: string; lifecycleUid: string; opId: string; }): Promise<"completed" | "terminalized" | "already-settled">; //# sourceMappingURL=lifecycle-saga.d.ts.map