import type { DerivedRules } from "../types"; /** * Load upstream's own glob matcher. * * @remarks * Deep-imported rather than ported, so this evaluator CANNOT drift from the profile SRT actually * generates — a hand-copied `globToRegex` would make parity a maintenance promise instead of a * property. The specifier is deliberately PACKAGE-RELATIVE and resolved through the optional peer, * matching `escape.ts`'s deep import of `quote()`: an absolute path would resolve only on the * machine that wrote it and would fail at runtime for every consumer of the published package. * * The module is safe to reach into — `sandbox-utils.js` imports only `os`/`path`/`fs`, so this * cannot pull upstream's bundled zod into a repo that has never depended on it. * * @returns Upstream's `globToRegex`. */ export declare const loadGlobToRegex: () => Promise<(glob: string) => string>; /** * The in-process policy decision procedure. * * @remarks * BESPOKE POLICY CODE, not a thin wrapper: SRT exports rule LISTS * (`getFsReadConfig()`/`getFsWriteConfig()`) but **no authorization predicate**, so the decision is * ours to make and ours to get wrong. It backs the tools that run OUR code — `open_file*`, * `stage_file`, `save_media`, `list_directory` — where there is no untrusted binary between the check * and the `open()`, so applying the same derived rules in-process is the same path without a * subprocess rather than a weaker one. * * The residuals are real and unmitigated: a TOCTOU race between check and open, and any bug in this * evaluator. There is no OS backstop on this path — SRT restricts spawned children only. The * compensating controls are the mandatory gate and a narrow `writeRoot`. */ export type FsNode = { /** Whether a read of `path` is permitted. Reads default to ALLOW; `allowRead` wins inside `denyRead`. */ canRead(path: string): boolean; /** Whether a write to `path` is permitted. Writes default to DENY; `denyWrite` wins inside `allowWrite`, and the mandatory-deny set applies on top. */ canWrite(path: string): boolean; }; /** * Compile every glob-bearing rule through upstream's own `globToRegex`. * * @remarks * MUST be awaited before the evaluator is consulted, because the deep import is async while the * evaluator is not. {@link srtEnforcer} does this for every rule in the derived lists immediately * after capturing them — NOT {@link createFsNode}, which is synchronous and therefore cannot. An * earlier comment here named `createFsNode`, which was simply false: nothing primed, so the * synchronous fallback was the only path production ever took. * * @param rules - Raw rule strings from the derived lists. */ export declare const primeGlobMatcher: (rules: Iterable) => Promise; /** In-process counterpart of SRT's two derived restriction lists. */ export declare const createFsNode: (rules: DerivedRules) => FsNode; /** Construct a derived snapshot from the shapes returned by SRT. */ export declare const derivedRulesFromSrt: (input: { platform: "darwin" | "linux"; read: { denyOnly: readonly string[]; allowWithinDeny?: readonly string[]; }; write: { allowOnly: readonly string[]; denyWithinAllow: readonly string[]; }; filesystemDisabled?: boolean; network?: { /** OURS, not upstream's: `true` only when WE constructed the session in disabled mode. */ disabled?: boolean; allowedDomains?: readonly string[]; deniedDomains?: readonly string[]; }; mandatoryDeny?: { form: "glob" | "expanded-paths"; entries: readonly string[]; allowGitConfig: boolean; searchDepth: number; dotGitWasDirectory?: boolean; }; }) => DerivedRules; /** The exact upstream dangerous file names, retained for parity tests. */ export declare const DANGEROUS_FILES: readonly [ ".gitconfig", ".gitmodules", ".bashrc", ".bash_profile", ".zshrc", ".zprofile", ".profile", ".ripgreprc", ".mcp.json" ]; /** * Directories SRT mandatory-denies, reproduced from upstream. * * @remarks * `.git` is deliberately ABSENT: upstream filters it out of its own list and handles it separately, * because the rules differ per platform and per `.git` being a directory rather than a worktree file. * Reproducing it here would deny what the profile permits. */ export declare const DANGEROUS_DIRECTORIES: readonly [ ".vscode", ".idea", ".claude/commands", ".claude/agents" ]; /** * Reproduce SRT's profile-injected mandatory-deny set for the CURRENT platform. * * @remarks * THIS IS OUR REPRODUCTION, NOT SRT'S OUTPUT, and the distinction bounds what any check built on it * can prove. SRT exposes no function for this set: it is injected at PROFILE GENERATION, * `linuxGetMandatoryDenyPaths` is a non-exported local, and `macGetMandatoryDenyPatterns` is not * re-exported from the package index. So the entries are re-derived here with the same lists upstream * uses — which is why the constant-parity test diffs those lists directly, and why a drift check over * this axis proves only "our inputs did not change", never "our reproduction still matches SRT". * * Without it the in-process evaluator has NO mandatory denies at all, and `save_media` writes * `.bashrc` or `.mcp.json` where the spawned shell is refused — the "one boundary, two answers" * failure this reproduction exists to prevent. * * FORM DIFFERS BY PLATFORM and the two are not comparable: * · macOS emits GLOBS the seatbelt profile matches natively — each name resolved against the cwd * plus a the subtree form subtree pattern, so it matches at any depth. * · Linux emits CONCRETE PATHS from a bounded `rg` scan, so it is point-in-time and depth-limited; * a file created afterwards, or nested deeper than `mandatoryDenySearchDepth`, is NOT covered * there. We reproduce the cwd-rooted entries; the scan's discoveries are the profile's own. * * `.git/hooks` and `.git/config` are PLATFORM-CONDITIONAL: macOS pushes `hooks` unconditionally and * `config` unless `allowGitConfig`, while Linux pushes neither for the workspace root unless `.git` * is a real DIRECTORY (in a worktree it is a file, and denying it would break bwrap). * * @param options - The cwd the profile was built against, and the inputs that change the set. * @returns The reproduced entries, in the platform's own form. */ export declare const reproduceMandatoryDeny: (options: { cwd: string; allowGitConfig: boolean; platform?: "darwin" | "linux"; dotGitIsDirectory?: boolean; }) => string[];