import type { SandboxPolicy } from "./types"; import type { SandboxEventSink } from "./observability"; import type { SandboxPolicyEnforcer } from "./contracts/policy_enforcer"; /** Platform identity supplied by the construction site. */ export type SandboxPlatform = 'darwin' | 'linux' | 'win32' | string; /** Inputs to the construction-time environment admission check. */ export interface PreflightOptions { /** Policy backend to admit. */ readonly enforcer: SandboxPolicyEnforcer; /** Platform override, primarily for hermetic tests. */ readonly platform?: SandboxPlatform; /** Explicit opt-in to run without OS containment when a pre-execution condition applies. */ readonly allowUnsandboxedFallback?: boolean; /** Claude Code's strict mode: per-call escape/bypass is ignored by the consumer. */ readonly strictMode?: boolean; /** Whether the optional SRT peer was resolved. Defaults to true for injected test enforcers. */ readonly optionalPeerPresent?: boolean; /** Receives dependency warnings; warnings never make admission fail. */ readonly onSandbox?: SandboxEventSink; /** Path redaction is performed by the observability sink, not by this admission check. */ readonly fsNodeVersion?: string; } /** Immutable decision retained by a sandbox handle for its entire lifetime. */ export interface SandboxPreflight { /** Whether the construction opted into fallback. */ readonly allowUnsandboxedFallback: boolean; /** Whether one of the permitted pre-execution conditions fired. */ readonly fallbackFired: boolean; /** Whether per-call bypasses must be ignored. */ readonly strictMode: boolean; /** Non-fatal dependency diagnostics. */ readonly dependencyWarnings: readonly string[]; /** Version provenance for fs_node, when supplied by the backend. */ readonly fsNodeVersion?: string; } /** Run the once-only, fail-closed environment gauntlet used by `createSandbox()`. */ export declare const preflightSandbox: (options: PreflightOptions) => Promise; /** Compatibility alias for the construction-site call in WP-A1. */ export declare const runSandboxPreflight: (options: PreflightOptions) => Promise; /** Probe spawning after policy admission, rather than as part of preflight. */ export declare const probeSandboxSpawn: (enforcer: SandboxPolicyEnforcer, policy: SandboxPolicy) => Promise;