import type { SandboxPolicy, DerivedRules } from "../types"; /** Policy boundary. `run` resolves on spawn and exposes live streams plus a later completion promise. */ export interface SandboxPolicyEnforcer { /** Whether this enforcer can enforce on the current platform. `false` (a browser tab, where SRT does not exist) raises `E_SANDBOX_UNSUPPORTED_ENV` at construction rather than degrading — a shim that enforces nothing reads as sandboxed. */ isSupported(): boolean; /** Whether this adapter adopted an already-enabled process-global sandbox rather than initializing it. */ readonly adopted?: boolean; /** Probe external prerequisites. A non-empty `errors` throws `E_SANDBOX_DEPENDENCY_MISSING`; `warnings` are surfaced through observability and are NOT fatal. */ checkDependencies(): Promise<{ errors: string[]; warnings: string[]; }>; /** * Spawn under a narrowing policy; a non-zero exit is data, not a rejected promise. * * @remarks * When `op.signal` aborts, an implementation MUST terminate the spawned child (including a * child hidden behind a sandbox wrapper) and settle `completed`; it MUST NOT leave the child * running after the lifecycle owner has cancelled the invocation. The returned streams may end * as a consequence of termination, but `completed` remains the authoritative settlement signal. */ run(op: { argv: string[]; policy: SandboxPolicy; correlationId: string; cwd: string; /** * An ADDITIVE per-call overlay on the child's environment, applied LAST. * * @remarks * NOT the host-inheritance control. What a child inherits from the host is the ADAPTER's decision * (the Node/SRT one denies by default and takes an allow-list at construction); this field only * adds to whatever that produced, and an adapter MUST NOT let it silently widen what the deployment * allowed. Leaving these semantics unstated is how the Node adapter came to spread the entire * `process.env` into every child while this field sat unused. */ env?: Record; /** * Lifecycle cancellation for this child. Implementations must kill the spawned child and * settle `completed` when this signal aborts. */ signal?: AbortSignal; }): Promise<{ stdout: ReadableStream; stderr: ReadableStream; completed: Promise<{ exitCode: number; failed: boolean; }>; }>; /** Return the opaque derived snapshot used for drift validation. */ effectivePolicy(): DerivedRules | undefined; /** Retrieve diagnostics by correlation id, never by command text. */ diagnosticsFor(correlationId: string): string[]; /** Release what this enforcer OWNS. A no-op when it adopted a foreign sandbox — tearing down a manager we did not initialize would strip ACEs a host app depends on. */ dispose(): Promise; } /** Duck-type schema. */ export declare const sandboxPolicyEnforcerSchema: import("@nhtio/validation").AnySchema; /** Structural guard. */ export declare const implementsSandboxPolicyEnforcer: (value: unknown) => value is SandboxPolicyEnforcer;