import type { SandboxFileSystem } from "./contracts/file_system"; import type { PathTranslator } from "./contracts/path_translator"; /** Why a path was rejected outright, before any normalisation. */ export type SandboxPathRejection = 'nul' | 'home' | 'absolute-host' | 'device' | 'unc'; /** * Classify an unambiguous host escape, or `undefined` when the path is acceptable. * * @remarks * The REASON is returned, not just a boolean, because the narrated outcome carries it and the model * acts on it: "paths are workspace-relative" is useless advice for a NUL byte, and a UNC form needs * a different correction from a `~`. Reporting every rejection as `escape` collapses five distinct * mistakes into one unhelpful message. * * ORDER IS LOAD-BEARING and matches the plan's step 1. Recognition runs on the CANONICAL separator * representation (both `/` and `\` treated as separators) but still BEFORE any stripping, so a * slash-mixed form like `/\server\share` cannot slip past a naive prefix test and then become a * root-relative path once separators are collapsed. UNC is distinguished from merely-repeated * leading separators by having a NON-EMPTY first segment. Nothing is percent-decoded and nothing is * case-folded: a literal `%2e%2e` is a filename, not traversal. * * @param input - The model-supplied path, exactly as given. * @returns The rejection reason, or `undefined` to continue normalising. */ export declare const classifySandboxPathRejection: (input: string) => SandboxPathRejection | undefined; /** Return whether a path is an unambiguous host escape before normalisation. */ export declare const isRejectedSandboxPath: (input: string) => boolean; /** Normalise a model path; leading separators denote the sandbox root. */ export declare const normalizeSandboxPath: (input: string) => string; /** * Create a symlink guard for paths whose final component may not exist yet. * Stat failures are treated as absence, matching the sandbox regular-file helpers. */ export declare const createExistingSymlinkGuard: (root: string, fileSystem: SandboxFileSystem) => ((relative: string) => Promise); /** Create a translator that applies the five-step, workspace-relative path policy. */ export declare const createPathTranslator: (root: string, fileSystem: SandboxFileSystem) => PathTranslator;