import { type VerifierProvider } from '../verify/verifier-factory.js'; import type { CommandIO, CommandResult } from './io.js'; export interface SettleArgs { ac?: string[]; acPass?: string[]; passAll?: boolean; auto?: boolean; force?: boolean; allowMissingCoverage?: boolean; deep?: boolean; allowAutoComplex?: boolean; allowStaleDraft?: boolean; allowOpenTasks?: boolean; allowFailingBuild?: boolean; allowVerifierFailure?: boolean; allowCodeReviewFailure?: boolean; allowSecurityAuditFailure?: boolean; allowSkillAuditMiss?: boolean; /** Phase 156: do not refuse on a boundary-scan violation; record the * offenders into SUMMARY and settle anyway. */ allowBoundaryScanFailure?: boolean; /** Phase 83: bypass the worktree phase-collision backstop. */ allowPhaseCollision?: boolean; interactive?: boolean; /** Phase 73: override config.verifier.provider for the deep-verify gate * (precedence flag > config > default mock). */ verifier?: VerifierProvider; /** Phase 148: when set, any `converted` recommendation targeting the * settling phase is promoted straight to `shipped` (with this text as * `shippedRef`) instead of the default `settle-pending` advance. */ shipRef?: string; /** Phase 214 (T4): per-AC evidence-floor bypass, `AC-id:reason` pairs * (repeatable). Exempts exactly the named AC from the `gates.evidenceFloor` * refusal — never a blanket "skip the floor for everything" flag. A * non-empty reason is required for every entry. */ evidenceFloorBypass?: string[]; } /** * Phase 244 (T1): pure detector for rec-20260729-001 — `cadence settle run` * silently writing a downgraded SUMMARY (`schemaVersion: 1`, no `assurance` * record) when the process actually executing it is a globally-installed * `cadence` binary that predates this repo's own build, rather than this * checkout's `packages/core/bin/cadence.cjs` (confirmed on phases 233/234). * The two binaries report an IDENTICAL `--version` string on an unreleased * branch (unbumped `package.json` matches whatever is currently published), * so version comparison cannot detect the mismatch — DO NOT key detection on * it. This checks instead whether the binary that is actually executing * lives inside this repo's own git worktree. * * Deliberately pure: takes already-resolved facts as plain string/boolean * arguments — no `process`/filesystem access inside the function itself, per * this repo's pure-core/impure-shell convention (CLAUDE.md) — so it is * directly unit-testable without fixtures. Both `runningBinaryRealpath` and * `repoToplevel` are expected CANONICAL (symlink-resolved), not merely * absolute — `isPathInside` below only normalizes via `path.resolve`, which * does not follow symlinks, so a symlinked `repoToplevel` passed in * unresolved can produce a false mismatch against an already-realpath'd * binary. `resolveForeignBinaryFacts` (the wired caller, T2) realpaths both. * `repoHasOwnCadenceBuild` (does `repoToplevel` have both * `packages/core/bin/cadence.cjs` and `.cadence/` at its root — i.e. is this * recognizably the CADENCE monorepo itself, not a consumer project) is the * caller's other responsibility before calling in. * * Reports a mismatch ONLY when BOTH are true: the running binary sits * outside `repoToplevel`, AND the repo is recognizably CADENCE's own * monorepo. An ordinary consumer repo settling via a globally-installed * `cadence` is never a mismatch — `repoHasOwnCadenceBuild` gates that off * (244-01's first acceptance criterion's false-positive-avoidance case). A * binary resolved from inside `repoToplevel` is never a mismatch either, * regardless of `repoHasOwnCadenceBuild` (the true-positive case only fires * on the conjunction, not on either condition alone). * * Wired into `resolveSettleGateSet` below (T2) via `resolveForeignBinaryFacts`. */ export declare function detectForeignCadenceBinary(runningBinaryRealpath: string, repoToplevel: string, repoHasOwnCadenceBuild: boolean): boolean; /** * Phase 244 (T2): resolves the two facts `detectForeignCadenceBinary` needs * beyond `repoToplevel` (already available to callers as `cwd`) — whether * `cwd` is recognizably CADENCE's own monorepo checkout (both * `packages/core/bin/cadence.cjs` and `.cadence/` present at its root), and * the running binary's realpath. Takes `argv1` as an explicit parameter * (never reads `process.argv` itself) so a test can pass any string — * including an unresolvable one — without needing to mutate global state. * The one caller that reads `process.argv` for real, * `resolveSettleGateSet` below, does so via its own `argv1` parameter's * default value, keeping that read in one place and overridable. Mirrors * `settleService` itself taking `repoRoot` instead of reading `process.cwd()` * (CLAUDE.md's pure-core/impure-shell split). * * Returns `null` whenever there is no mismatch to report — `argv1` is * missing/unresolvable (best-effort: an unresolvable path degrades to "no * mismatch", never a false alarm — CLAUDE.md's "Throwing Observer" convention * for introspection code), `cwd` doesn't look like CADENCE's own build, or * the running binary genuinely is inside `cwd` — so callers can use * `foreignBinaryMismatch ? { foreignBinaryMismatch } : {}` directly for the * `exactOptionalPropertyTypes`-safe SUMMARY spread, with no separate boolean * to keep in sync. * * `cwd` is best-effort realpath'd before the containment check (never * before the `repoHasOwnCadenceBuild` check — `existsSync` already follows * symlinks fine there): `detectForeignCadenceBinary` requires both its path * arguments canonical, and `argv1` already is (via `realpathSync` below), so * a symlinked `cwd` — e.g. `cadence mcp serve --repo` pointed through a * symlink — would otherwise compare a canonical binary path against a * non-canonical repo path and report a false mismatch for a settle that is * genuinely running this repo's own build. The *returned* `repoToplevel` * stays the original `cwd` (what the operator/caller actually passed), not * the realpath — this field is for a human/audit trail, and resolving fails * closed (falls back to the original `cwd`) rather than throwing, matching * this function's existing best-effort-degrade shape. */ export declare function resolveForeignBinaryFacts(cwd: string, argv1: string | undefined): { runningBinaryPath: string; repoToplevel: string; } | null; /** * `cadence settle run` — close the loop: run the settle gate stack, write * SUMMARY.{json,md}, and return to IDLE. Faithful extraction of the former CLI * action body (process streams + exit code routed through `io`/the result). */ export declare function settleService(repoRoot: string, opts: SettleArgs, io: CommandIO): Promise; //# sourceMappingURL=settle.d.ts.map