import { Media } from "../../common"; import type { SandboxEpoch } from "./types"; import type { SandboxFileSystem } from "./contracts/file_system"; import type { MediaKind, MediaReader, MediaTrustTier } from "../../common"; /** The capability needed to decide whether a sandbox handle is still alive. */ export type SandboxEpochIsLive = (epoch: SandboxEpoch) => boolean; /** Arguments for {@link createSandboxMediaReader}. */ export interface SandboxMediaReaderOptions { /** The filesystem capability belonging to the sandbox handle. */ fileSystem: SandboxFileSystem; /** The already translated backend path. */ path: string; /** The epoch held by the sandbox handle when this reader was issued. */ epoch: SandboxEpoch; /** Predicate owned by the sandbox manager; this reader never issues or invalidates epochs. */ isEpochLive: SandboxEpochIsLive; } /** * Create a non-describable, replayable reader over a sandbox file. * * @remarks * Every operation checks the owning epoch, stats the path, and refuses anything whose filesystem * kind is not `file` before opening it. Every stream call then asks the injected filesystem for a * fresh stream; this reader deliberately has no byte cap and does not import a host filesystem. * The reader omits `describe()` because approval-bound sandbox capabilities must not cross a * serialisation boundary. * * @param options - The sandbox filesystem, translated path, epoch, and liveness predicate. * @returns A file-backed {@link MediaReader}. */ export declare const createSandboxMediaReader: (options: SandboxMediaReaderOptions) => MediaReader; /** Arguments for {@link createSandboxMedia}. */ export interface SandboxMediaOptions extends SandboxMediaReaderOptions { /** Media modality assigned by the stage operation. */ kind: MediaKind; /** MIME type resolved by the stage operation. */ mimeType: string; /** Model-visible source filename. */ filename: string; /** Configuration-supplied provenance tier. */ trustTier: MediaTrustTier; /** Optional provenance label retained on the Media value. */ source?: string; } /** * Construct the staged media value returned by a mutating sandbox operation. * * @remarks * The shipped Media factories supply the conservative modality hazard and keep the trust-tier * choice explicit at this call site. The reader remains deliberately non-describable. * * @param options - File-reader and media labelling options. * @returns A staged {@link Media} value. */ export declare const createSandboxMedia: (options: SandboxMediaOptions) => Media;