export type VerifierProvider = 'mock' | 'anthropic' | 'local' | 'host-cli'; /** Shared options for every `select…Verifier` factory (Phase 40.1). */ export interface VerifierSelectOptions { /** Overrides the configured provider. */ override?: VerifierProvider; /** Test seam: stand in for `process.env`. */ env?: NodeJS.ProcessEnv; /** Test seam: emit warnings somewhere other than `process.stderr`. */ warn?: (message: string) => void; /** Where a `.env` file is discovered (default `process.cwd()`) — a key found * there is treated the same as one exported into the env (AC-1). */ cwd?: string; } /** * Describes one verifier family: how to read its `{ provider, model }` config * slice and how to build each of its three providers. `C` is the (Pick) config * param the binding accepts; `V` is the verifier type produced. */ export interface VerifierFactorySpec { /** Warning-prefix label, e.g. `'code-review'`. */ label: string; /** Read this family's config slice. `model` and the Phase-72 hardening fields * admit `| undefined` so the (exactOptionalPropertyTypes) config slices * assign directly. Families without the hardening fields (everything but the * top-level `verifier` slice) simply return them as `undefined`. */ read(config: C | null): { provider?: VerifierProvider; model?: string | undefined; /** Phase 72: anthropic request timeout (ms). */ timeoutMs?: number | undefined; /** Phase 72: anthropic retry budget. */ maxRetries?: number | undefined; /** Phase 72: extra headers for the local provider. */ localHeaders?: Record | undefined; } | undefined; mock(): V; anthropic(opts: { apiKey: string; model?: string; timeout?: number; maxRetries?: number; }): V; local(opts: { baseURL: string; model: string; headers?: Record; }): V; /** * Phase 165: `host-cli` provider builder — spawns the user's already- * installed, already-authenticated host CLI (`claude`/`codex`) in headless * mode instead of calling an HTTP endpoint. Optional (unlike `mock` / * `anthropic` / `local`): a verifier family that hasn't wired a * `host-cli`-backed verifier class yet simply falls back to `mock` with a * warning (see `createVerifierFactory`) rather than failing to compile — * this lets `host-cli` land as a provider without forcing every family's * factory file to change in lockstep. */ hostCli?(opts: { bin: string; model?: string; }): V; } /** * Phase 72: pure builder for the `local` provider's extra headers. Returns a * bearer `Authorization` from `apiKey` merged under any `custom` headers (custom * wins), or `undefined` when there is nothing to send so the caller can omit the * key entirely. Header values are secrets — never log the result. */ export declare function buildLocalHeaders(apiKey: string | undefined, custom: Record | undefined): Record | undefined; /** * Build a `select…Verifier(config, opts)` function (Phase 40.1 consolidation of * six byte-identical factories). One selection algorithm: * `provider = override ?? slice.provider ?? 'mock'`; the `anthropic` provider * needs `ANTHROPIC_API_KEY`; the `local` provider needs `CADENCE_LOCAL_BASE_URL` * and a model (`slice.model ?? CADENCE_LOCAL_MODEL`); a missing prerequisite * falls back to `mock` with one stderr warning so the caller knows it downgraded. */ /** * Mirrors the selection algorithm's first line without building a verifier or * touching env: `provider = override ?? slice.provider ?? 'mock'`. `defaulted` * is true only when the provider fell through to `'mock'` with no explicit * choice — that is the silent-false-confidence case worth warning about. An * explicit `mock` (config or override) is NOT defaulted. */ export declare function resolveEffectiveProvider(slice: { provider?: VerifierProvider; } | undefined, opts?: { override?: VerifierProvider; }): { provider: VerifierProvider; defaulted: boolean; }; /** * Prominent stderr banner for the mock case under a verification gate. * Phase 104: rendered from the single source-of-truth `MOCK_VERIFIER_NOTICE` * so the "mock = not real verification" wording stays identical to `doctor`, * `init`, and `config explain` (no duplicated honesty literal). */ export declare const MOCK_FALLBACK_BANNER: string; /** * Phase 244 (T2, rec-20260729-001): prominent stderr banner for a settle * that is actually executing through a `cadence` binary whose realpath * resolves OUTSIDE this repo's own checkout, despite the repo having its * own local build — e.g. a stale globally-installed binary silently * shadowing this checkout's `packages/core/bin/cadence.cjs` (confirmed on * phases 233/234: the written SUMMARY silently downgraded to * `schemaVersion: 1` with no `assurance` record). See * `detectForeignCadenceBinary` in `services/settle.ts` for the detection * logic. Unlike `MOCK_FALLBACK_BANNER` above, this has no fixed text — the * mismatch is only actionable if the operator can see exactly which two * paths disagree — so it is a builder function, not a static constant, * following the same multi-line array-join shape. */ export declare function buildForeignBinaryBanner(runningBinaryPath: string, repoToplevel: string): string; export declare function createVerifierFactory(spec: VerifierFactorySpec): (config: C | null, opts?: VerifierSelectOptions) => V; //# sourceMappingURL=verifier-factory.d.ts.map