import type { HitFrame, PathFrame, SandboxPolicy } from "../types"; import type { SandboxPolicyEnforcer } from "../contracts/policy_enforcer"; /** * A classified ripgrep outcome. * * @remarks * CLASSIFICATION ORDER IS LOAD-BEARING: diagnostics are checked BEFORE the exit status, because `rg` * runs under the sandbox and a denied path surfaces as a non-zero exit *plus* a violation record. * Triage generically first and a policy refusal is permanently mislabelled `io-failure` — the model * is told "search broke" when the truth is "you may not read there", and `denied-by-policy` becomes * unreachable despite being in the tool's outcome list. * * `no-matches` is a RESULT, not an error: `rg` exits 1 when it ran correctly and matched nothing. */ export type RipgrepFailure = { kind: 'denied-by-policy'; diagnostics: readonly string[]; } | { kind: 'invalid-pattern'; message: string; } | { kind: 'no-matches'; } | { kind: 'io-failure'; message: string; exitCode: number; }; /** Ripgrep backend. Both child pipes are drained immediately and concurrently. */ export declare const createRipgrepSearch: (enforcer: SandboxPolicyEnforcer, policy: SandboxPolicy) => { searchContent(o: { root: string; pattern: string; maxDepth: number; limit: number; ignoreCase?: boolean; literal?: boolean; glob?: string; iglob?: string; follow?: boolean; hidden?: boolean; noIgnore?: boolean; signal?: AbortSignal; }): AsyncIterable; findPaths(o: { root: string; glob: string; maxDepth: number; limit: number; iglob?: string; follow?: boolean; hidden?: boolean; noIgnore?: boolean; signal?: AbortSignal; }): AsyncIterable; };