{"version":3,"sources":["../src/types.ts","../src/scope.ts","../src/canonical.ts","../src/private-scope.ts","../src/verify.ts","../src/federation.ts"],"names":["lockSeal","lockUnseal","sha256"],"mappings":";;;;;;AAEO,IAAM,gBAAA,GAAmB;;;ACyBzB,IAAM,iBAAA,GAAwD;AAAA,EACjE,aAAa,EAAE,IAAA,EAAM,CAAC,WAAA,EAAa,MAAA,EAAQ,WAAW,CAAA,EAAE;AAAA,EACxD,aAAa,EAAE,IAAA,EAAM,CAAC,WAAA,EAAa,mBAAA,EAAqB,UAAU,CAAA,EAAE;AAAA,EACpE,cAAc,EAAE,IAAA,EAAM,CAAC,MAAA,EAAQ,WAAA,EAAa,qBAAqB,CAAA,EAAE;AAAA,EACnE,aAAa,EAAE,IAAA,EAAM,CAAC,SAAA,EAAW,QAAQ,CAAA,EAAE;AAAA,EAC3C,iBAAiB,EAAE,IAAA,EAAM,CAAC,MAAA,EAAQ,OAAA,EAAS,WAAW,CAAA,EAAE;AAAA,EACxD,cAAA,EAAgB,EAAE,IAAA,EAAM,CAAC,UAAU,QAAA,EAAU,SAAA,EAAW,eAAe,CAAA,EAAE;AAAA,EACzE,WAAW,EAAE,IAAA,EAAM,CAAC,UAAA,EAAY,MAAA,EAAQ,cAAc,CAAA,EAAE;AAAA,EACxD,cAAc,EAAE,IAAA,EAAM,CAAC,QAAA,EAAU,MAAA,EAAQ,iBAAiB,CAAA;AAC9D;AAGA,IAAM,YAAA,uBAAmB,GAAA,CAAY;AAAA,EACjC,WAAA;AAAA,EACA,mBAAA;AAAA,EACA,UAAA;AAAA,EACA,eAAA;AAAA,EACA,SAAA;AAAA,EACA,UAAA;AAAA,EACA,cAAA;AAAA,EACA,iBAAA;AAAA,EACA;AACJ,CAAC,CAAA;AAED,IAAM,QAAA,GAAW,mBAAA;AACjB,IAAM,aAAA,GAAgB,wBAAA;AAMf,IAAM,eAAA,GAAN,cAA8B,KAAA,CAAM;AAAA,EACvC,YAAY,OAAA,EAAiB;AACzB,IAAA,KAAA,CAAM,OAAO,CAAA;AACb,IAAA,IAAA,CAAK,IAAA,GAAO,iBAAA;AAAA,EAChB;AACJ;AAEO,SAAS,WAAW,KAAA,EAAsB;AAC7C,EAAA,IAAI,OAAO,KAAA,KAAU,QAAA,IAAY,KAAA,CAAM,WAAW,CAAA,EAAG;AACjD,IAAA,MAAM,IAAI,gBAAgB,kCAAkC,CAAA;AAAA,EAChE;AACA,EAAA,IAAI,IAAA,CAAK,IAAA,CAAK,KAAK,CAAA,EAAG;AAClB,IAAA,MAAM,IAAI,eAAA,CAAgB,CAAA,kCAAA,EAAqC,KAAK,SAAA,CAAU,KAAK,CAAC,CAAA,CAAE,CAAA;AAAA,EAC1F;AAEA,EAAA,MAAM,QAAA,GAAW,KAAA,CAAM,OAAA,CAAQ,GAAG,CAAA;AAClC,EAAA,IAAI,QAAA,GAAW,CAAA,EAAG,MAAM,IAAI,gBAAgB,wCAAwC,CAAA;AAEpF,EAAA,MAAM,OAAA,GAAU,KAAA,CAAM,KAAA,CAAM,CAAA,EAAG,QAAQ,CAAA;AACvC,EAAA,IAAI,CAAC,QAAA,CAAS,IAAA,CAAK,OAAO,CAAA,QAAS,IAAI,eAAA,CAAgB,CAAA,iBAAA,EAAoB,OAAO,CAAA,CAAE,CAAA;AAEpF,EAAA,MAAM,IAAA,GAAO,KAAA,CAAM,KAAA,CAAM,QAAA,GAAW,CAAC,CAAA;AACrC,EAAA,MAAM,QAAA,GAAW,IAAA,CAAK,OAAA,CAAQ,GAAG,CAAA;AAEjC,EAAA,IAAI,IAAA;AACJ,EAAA,IAAI,cAAA,GAAiB,EAAA;AACrB,EAAA,IAAI,WAAW,CAAA,EAAG;AACd,IAAA,IAAA,GAAO,IAAA;AAAA,EACX,CAAA,MAAO;AACH,IAAA,IAAA,GAAO,IAAA,CAAK,KAAA,CAAM,CAAA,EAAG,QAAQ,CAAA;AAC7B,IAAA,IAAI,CAAC,KAAK,QAAA,CAAS,GAAG,GAAG,MAAM,IAAI,gBAAgB,yCAAyC,CAAA;AAC5F,IAAA,cAAA,GAAiB,IAAA,CAAK,KAAA,CAAM,QAAA,GAAW,CAAA,EAAG,EAAE,CAAA;AAAA,EAChD;AACA,EAAA,IAAI,CAAC,QAAA,CAAS,IAAA,CAAK,IAAI,CAAA,QAAS,IAAI,eAAA,CAAgB,CAAA,cAAA,EAAiB,IAAI,CAAA,CAAE,CAAA;AAE3E,EAAA,MAAM,cAAiC,EAAC;AACxC,EAAA,IAAI,cAAA,CAAe,SAAS,CAAA,EAAG;AAC3B,IAAA,KAAA,MAAW,KAAA,IAAS,mBAAA,CAAoB,cAAc,CAAA,EAAG;AACrD,MAAA,WAAA,CAAY,IAAA,CAAK,eAAA,CAAgB,KAAK,CAAC,CAAA;AAAA,IAC3C;AAAA,EACJ;AAGA,EAAA,MAAM,IAAA,uBAAW,GAAA,EAAY;AAC7B,EAAA,KAAA,MAAW,KAAK,WAAA,EAAa;AACzB,IAAA,IAAI,IAAA,CAAK,GAAA,CAAI,CAAA,CAAE,GAAG,CAAA,EAAG,MAAM,IAAI,eAAA,CAAgB,CAAA,0BAAA,EAA6B,CAAA,CAAE,GAAG,CAAA,CAAE,CAAA;AACnF,IAAA,IAAA,CAAK,GAAA,CAAI,EAAE,GAAG,CAAA;AAAA,EAClB;AAEA,EAAA,OAAO,EAAE,OAAA,EAAS,IAAA,EAAM,WAAA,EAAY;AACxC;AAEA,SAAS,oBAAoB,IAAA,EAAwB;AACjD,EAAA,MAAM,MAAgB,EAAC;AACvB,EAAA,IAAI,KAAA,GAAQ,CAAA;AACZ,EAAA,IAAI,QAAA,GAAW,KAAA;AACf,EAAA,IAAI,KAAA,GAAQ,CAAA;AACZ,EAAA,KAAA,IAAS,CAAA,GAAI,CAAA,EAAG,CAAA,GAAI,IAAA,CAAK,QAAQ,CAAA,EAAA,EAAK;AAClC,IAAA,MAAM,EAAA,GAAK,KAAK,CAAC,CAAA;AACjB,IAAA,IAAI,QAAA,EAAU;AACV,MAAA,IAAI,EAAA,KAAO,IAAA,IAAQ,CAAA,GAAI,CAAA,GAAI,KAAK,MAAA,EAAQ;AACpC,QAAA,CAAA,EAAA;AACA,QAAA;AAAA,MACJ;AACA,MAAA,IAAI,EAAA,KAAO,KAAK,QAAA,GAAW,KAAA;AAC3B,MAAA;AAAA,IACJ;AACA,IAAA,IAAI,OAAO,GAAA,EAAK;AACZ,MAAA,QAAA,GAAW,IAAA;AACX,MAAA;AAAA,IACJ;AACA,IAAA,IAAI,OAAO,GAAA,EAAK,KAAA,EAAA;AAAA,SAAA,IACP,OAAO,GAAA,EAAK,KAAA,EAAA;AAAA,SAAA,IACZ,EAAA,KAAO,GAAA,IAAO,KAAA,KAAU,CAAA,EAAG;AAChC,MAAA,GAAA,CAAI,IAAA,CAAK,IAAA,CAAK,KAAA,CAAM,KAAA,EAAO,CAAC,CAAC,CAAA;AAC7B,MAAA,KAAA,GAAQ,CAAA,GAAI,CAAA;AAAA,IAChB;AAAA,EACJ;AACA,EAAA,GAAA,CAAI,IAAA,CAAK,IAAA,CAAK,KAAA,CAAM,KAAK,CAAC,CAAA;AAC1B,EAAA,OAAO,GAAA;AACX;AAEA,SAAS,gBAAgB,KAAA,EAAgC;AACrD,EAAA,IAAI,MAAM,MAAA,KAAW,CAAA,EAAG,MAAM,IAAI,gBAAgB,kBAAkB,CAAA;AAKpE,EAAA,MAAM,MAAiB,CAAC,IAAA,EAAM,MAAM,IAAA,EAAM,GAAA,EAAK,KAAK,GAAG,CAAA;AAGvD,EAAA,MAAM,aAAA,GAAgB,+BAAA,CAAgC,IAAA,CAAK,KAAK,CAAA;AAChE,EAAA,IAAI,aAAA,EAAe;AACf,IAAA,OAAO,EAAE,GAAA,EAAK,aAAA,CAAc,CAAC,CAAA,EAAI,IAAI,GAAA,EAAK,KAAA,EAAO,MAAA,EAAW,MAAA,EAAQ,KAAA,EAAM;AAAA,EAC9E;AAEA,EAAA,KAAA,MAAW,MAAM,GAAA,EAAK;AAClB,IAAA,MAAM,GAAA,GAAM,KAAA,CAAM,OAAA,CAAQ,EAAE,CAAA;AAC5B,IAAA,IAAI,OAAO,CAAA,EAAG;AACd,IAAA,MAAM,GAAA,GAAM,KAAA,CAAM,KAAA,CAAM,CAAA,EAAG,GAAG,CAAA;AAC9B,IAAA,IAAI,CAAC,QAAA,CAAS,IAAA,CAAK,GAAG,CAAA,EAAG;AACzB,IAAA,MAAM,GAAA,GAAM,KAAA,CAAM,KAAA,CAAM,GAAA,GAAM,GAAG,MAAM,CAAA;AACvC,IAAA,MAAM,EAAE,KAAA,EAAO,MAAA,EAAO,GAAI,WAAW,GAAG,CAAA;AACxC,IAAA,OAAO,EAAE,GAAA,EAAK,EAAA,EAAI,KAAA,EAAO,MAAA,EAAO;AAAA,EACpC;AACA,EAAA,MAAM,IAAI,eAAA,CAAgB,CAAA,6BAAA,EAAgC,KAAK,CAAA,CAAE,CAAA;AACrE;AAEA,SAAS,WAAW,GAAA,EAAiD;AACjE,EAAA,IAAI,IAAI,MAAA,KAAW,CAAA,EAAG,MAAM,IAAI,gBAAgB,2BAA2B,CAAA;AAC3E,EAAA,IAAI,GAAA,CAAI,UAAA,CAAW,GAAG,CAAA,EAAG;AACrB,IAAA,IAAI,CAAC,GAAA,CAAI,QAAA,CAAS,GAAG,CAAA,IAAK,GAAA,CAAI,SAAS,CAAA,EAAG;AACtC,MAAA,MAAM,IAAI,eAAA,CAAgB,CAAA,2BAAA,EAA8B,GAAG,CAAA,CAAE,CAAA;AAAA,IACjE;AACA,IAAA,IAAI,CAAA,GAAI,EAAA;AACR,IAAA,KAAA,IAAS,IAAI,CAAA,EAAG,CAAA,GAAI,GAAA,CAAI,MAAA,GAAS,GAAG,CAAA,EAAA,EAAK;AACrC,MAAA,MAAM,EAAA,GAAK,IAAI,CAAC,CAAA;AAChB,MAAA,IAAI,OAAO,IAAA,IAAQ,CAAA,GAAI,CAAA,GAAI,GAAA,CAAI,SAAS,CAAA,EAAG;AACvC,QAAA,MAAM,IAAA,GAAO,GAAA,CAAI,EAAE,CAAC,CAAA;AACpB,QAAA,CAAA,IAAK,IAAA;AAAA,MACT,CAAA,MAAA,IAAW,OAAO,GAAA,EAAK;AACnB,QAAA,MAAM,IAAI,eAAA,CAAgB,CAAA,0BAAA,EAA6B,GAAG,CAAA,CAAE,CAAA;AAAA,MAChE,CAAA,MAAO;AACH,QAAA,CAAA,IAAK,EAAA;AAAA,MACT;AAAA,IACJ;AACA,IAAA,OAAO,EAAE,KAAA,EAAO,CAAA,EAAG,MAAA,EAAQ,IAAA,EAAK;AAAA,EACpC;AACA,EAAA,IAAI,CAAC,aAAA,CAAc,IAAA,CAAK,GAAG,CAAA,EAAG;AAC1B,IAAA,MAAM,IAAI,eAAA,CAAgB,CAAA,0BAAA,EAA6B,KAAK,SAAA,CAAU,GAAG,CAAC,CAAA,CAAE,CAAA;AAAA,EAChF;AACA,EAAA,OAAO,EAAE,KAAA,EAAO,GAAA,EAAK,MAAA,EAAQ,KAAA,EAAM;AACvC;AAMO,SAAS,kBAAkB,KAAA,EAAsB;AACpD,EAAA,MAAM,MAAA,GAAS,CAAC,GAAG,KAAA,CAAM,WAAW,CAAA,CAAE,IAAA,CAAK,CAAC,CAAA,EAAG,CAAA,KAAO,EAAE,GAAA,GAAM,CAAA,CAAE,MAAM,EAAA,GAAK,CAAA,CAAE,MAAM,CAAA,CAAE,GAAA,GAAM,IAAI,CAAE,CAAA;AACjG,EAAA,MAAM,KAAA,GAAQ,MAAA,CAAO,GAAA,CAAI,mBAAmB,CAAA;AAC5C,EAAA,MAAM,KAAA,GAAQ,KAAA,CAAM,IAAA,CAAK,GAAG,CAAA;AAC5B,EAAA,OAAO,CAAA,EAAG,KAAA,CAAM,OAAO,CAAA,CAAA,EAAI,KAAA,CAAM,IAAI,CAAA,EAAG,KAAA,CAAM,MAAA,KAAW,CAAA,GAAI,EAAA,GAAK,CAAA,CAAA,EAAI,KAAK,CAAA,CAAA,CAAG,CAAA,CAAA;AAClF;AAEO,SAAS,wBAAwB,KAAA,EAAuB;AAC3D,EAAA,OAAO,iBAAA,CAAkB,UAAA,CAAW,KAAK,CAAC,CAAA;AAC9C;AAEA,SAAS,oBAAoB,CAAA,EAA4B;AACrD,EAAA,IAAI,EAAE,EAAA,KAAO,GAAA,EAAK,OAAO,CAAA,EAAG,EAAE,GAAG,CAAA,EAAA,CAAA;AACjC,EAAA,MAAM,CAAA,GAAI,EAAE,MAAA,GAAS,UAAA,CAAW,EAAE,KAAA,IAAS,EAAE,CAAA,GAAI,CAAA,CAAE,KAAA,IAAS,EAAA;AAC5D,EAAA,OAAO,GAAG,CAAA,CAAE,GAAG,GAAG,CAAA,CAAE,EAAE,GAAG,CAAC,CAAA,CAAA;AAC9B;AAEA,SAAS,WAAW,CAAA,EAAmB;AACnC,EAAA,IAAI,GAAA,GAAM,GAAA;AACV,EAAA,KAAA,MAAW,MAAM,CAAA,EAAG;AAChB,IAAA,IAAI,EAAA,KAAO,GAAA,IAAO,EAAA,KAAO,IAAA,SAAa,IAAA,GAAO,EAAA;AAAA,SACxC,GAAA,IAAO,EAAA;AAAA,EAChB;AACA,EAAA,GAAA,IAAO,GAAA;AACP,EAAA,OAAO,GAAA;AACX;AAeO,SAAS,aAAA,CAAc,KAAA,EAAc,OAAA,GAA6B,EAAC,EAAS;AAC/E,EAAA,MAAM,IAAA,GAAO,QAAQ,IAAA,IAAQ,QAAA;AAC7B,EAAA,MAAM,GAAA,GAAM,kBAAkB,CAAA,EAAG,KAAA,CAAM,OAAO,CAAA,CAAA,EAAI,KAAA,CAAM,IAAI,CAAA,CAAE,CAAA;AAC9D,EAAA,IAAI,CAAC,GAAA,EAAK;AACN,IAAA,IAAI,SAAS,QAAA,EAAU;AACnB,MAAA,MAAM,IAAI,gBAAgB,CAAA,oBAAA,EAAuB,KAAA,CAAM,OAAO,CAAA,CAAA,EAAI,KAAA,CAAM,IAAI,CAAA,CAAE,CAAA;AAAA,IAClF;AACA,IAAA;AAAA,EACJ;AACA,EAAA,MAAM,UAAA,GAAa,IAAI,GAAA,CAAI,GAAA,CAAI,IAAI,CAAA;AACnC,EAAA,KAAA,MAAW,CAAA,IAAK,MAAM,WAAA,EAAa;AAC/B,IAAA,IAAI,CAAC,UAAA,CAAW,GAAA,CAAI,CAAA,CAAE,GAAG,CAAA,EAAG;AACxB,MAAA,IAAI,SAAS,QAAA,EAAU;AACnB,QAAA,MAAM,IAAI,eAAA;AAAA,UACN,CAAA,gCAAA,EAAmC,MAAM,OAAO,CAAA,CAAA,EAAI,MAAM,IAAI,CAAA,EAAA,EAAK,EAAE,GAAG,CAAA;AAAA,SAC5E;AAAA,MACJ;AAAA,IAEJ;AAAA,EACJ;AACJ;AAWO,SAAS,UAAA,CAAW,WAAkB,OAAA,EAAyB;AAClE,EAAA,IAAI,SAAA,CAAU,OAAA,KAAY,OAAA,CAAQ,OAAA,EAAS,OAAO,KAAA;AAClD,EAAA,IAAI,SAAA,CAAU,IAAA,KAAS,OAAA,CAAQ,IAAA,EAAM,OAAO,KAAA;AAE5C,EAAA,MAAM,OAAA,uBAAc,GAAA,EAA6B;AACjD,EAAA,KAAA,MAAW,KAAK,SAAA,CAAU,WAAA,UAAqB,GAAA,CAAI,CAAA,CAAE,KAAK,CAAC,CAAA;AAE3D,EAAA,KAAA,MAAW,CAAA,IAAK,QAAQ,WAAA,EAAa;AACjC,IAAA,MAAM,EAAA,GAAK,OAAA,CAAQ,GAAA,CAAI,CAAA,CAAE,GAAG,CAAA;AAC5B,IAAA,IAAI,CAAA,CAAE,OAAO,GAAA,EAAK;AAElB,IAAA,IAAI,CAAA,CAAE,OAAO,GAAA,EAAK;AACd,MAAA,IAAI,CAAC,IAAI,OAAO,KAAA;AAChB,MAAA,IAAI,GAAG,EAAA,KAAO,GAAA,IAAO,GAAG,KAAA,KAAU,CAAA,CAAE,OAAO,OAAO,KAAA;AAClD,MAAA;AAAA,IACJ;AAEA,IAAA,IAAI,CAAA,CAAE,OAAO,IAAA,EAAM;AACf,MAAA,IAAI,CAAC,IAAI,OAAO,KAAA;AAChB,MAAA,IAAI,GAAG,EAAA,KAAO,GAAA,IAAO,EAAA,CAAG,KAAA,KAAU,EAAE,KAAA,EAAO;AAC3C,MAAA,IAAI,GAAG,EAAA,KAAO,IAAA,IAAQ,EAAA,CAAG,KAAA,KAAU,EAAE,KAAA,EAAO;AAC5C,MAAA,OAAO,KAAA;AAAA,IACX;AAGA,IAAA,IAAI,CAAA,CAAE,EAAA,KAAO,GAAA,IAAO,CAAA,CAAE,EAAA,KAAO,IAAA,IAAQ,CAAA,CAAE,EAAA,KAAO,GAAA,IAAO,CAAA,CAAE,EAAA,KAAO,IAAA,EAAM;AAChE,MAAA,IAAI,CAAC,IAAI,OAAO,KAAA;AAChB,MAAA,IAAI,CAAC,YAAA,CAAa,GAAA,CAAI,CAAA,CAAE,GAAG,GAAG,OAAO,KAAA;AACrC,MAAA,IAAI,EAAA,CAAG,EAAA,KAAO,GAAA,EAAK,OAAO,KAAA;AAC1B,MAAA,IAAI,GAAG,KAAA,KAAU,MAAA,IAAa,CAAA,CAAE,KAAA,KAAU,QAAW,OAAO,KAAA;AAC5D,MAAA,IAAI,CAAC,WAAA,CAAY,EAAA,EAAI,CAAC,GAAG,OAAO,KAAA;AAChC,MAAA;AAAA,IACJ;AAAA,EACJ;AACA,EAAA,OAAO,IAAA;AACX;AAEA,SAAS,WAAA,CAAY,IAAqB,CAAA,EAA6B;AACnE,EAAA,MAAM,OAAA,GAAU,UAAU,EAAE,CAAA;AAC5B,EAAA,MAAM,MAAA,GAAS,UAAU,CAAC,CAAA;AAC1B,EAAA,IAAI,CAAC,OAAA,IAAW,CAAC,MAAA,EAAQ,OAAO,KAAA;AAChC,EAAA,OAAO,OAAO,EAAA,IAAM,OAAA,CAAQ,EAAA,IAAM,OAAA,CAAQ,MAAM,MAAA,CAAO,EAAA;AAC3D;AAEA,SAAS,UAAU,CAAA,EAAuD;AACtE,EAAA,IAAI,CAAA,CAAE,KAAA,KAAU,MAAA,EAAW,OAAO,IAAA;AAClC,EAAA,MAAM,CAAA,GAAI,MAAA,CAAO,CAAA,CAAE,KAAK,CAAA;AACxB,EAAA,IAAI,CAAC,MAAA,CAAO,QAAA,CAAS,CAAC,GAAG,OAAO,IAAA;AAChC,EAAA,QAAQ,EAAE,EAAA;AAAI,IACV,KAAK,GAAA;AACD,MAAA,OAAO,EAAE,EAAA,EAAI,CAAA,EAAG,EAAA,EAAI,CAAA,EAAE;AAAA,IAC1B,KAAK,GAAA;AACD,MAAA,OAAO,EAAE,EAAA,EAAI,CAAA,QAAA,EAAW,EAAA,EAAI,IAAI,CAAA,EAAE;AAAA;AAAA,IACtC,KAAK,IAAA;AACD,MAAA,OAAO,EAAE,EAAA,EAAI,CAAA,QAAA,EAAW,EAAA,EAAI,CAAA,EAAE;AAAA,IAClC,KAAK,GAAA;AACD,MAAA,OAAO,EAAE,EAAA,EAAI,CAAA,GAAI,CAAA,EAAG,IAAI,QAAA,EAAS;AAAA,IACrC,KAAK,IAAA;AACD,MAAA,OAAO,EAAE,EAAA,EAAI,CAAA,EAAG,EAAA,EAAI,QAAA,EAAS;AAAA,IACjC;AACI,MAAA,OAAO,IAAA;AAAA;AAEnB;;;ACtSO,SAAS,mBAAmB,MAAA,EAA4B;AAC3D,EAAA,MAAM,SAAA,GAAY,OAAO,GAAA,CAAI,CAAC,MAAM,iBAAA,CAAkB,UAAA,CAAW,CAAC,CAAC,CAAC,CAAA;AACpE,EAAA,OAAO,CAAC,GAAG,SAAS,CAAA,CAAE,KAAK,CAAC,CAAA,EAAG,CAAA,KAAO,CAAA,GAAI,CAAA,GAAI,EAAA,GAAK,CAAA,GAAI,CAAA,GAAI,IAAI,CAAE,CAAA;AACrE;AAMO,SAAS,2BAA2B,MAAA,EAA4D;AACnG,EAAA,MAAM,MAAA,GAAS,MAAA,CAAO,GAAA,CAAI,UAAU,CAAA;AACpC,EAAA,MAAM,gBAAA,GAAmB,MAAA,CAAO,GAAA,CAAI,iBAAiB,CAAA;AACrD,EAAA,MAAM,OAAA,GAAU,gBAAA,CAAiB,GAAA,CAAI,CAAC,CAAA,EAAG,CAAA,MAAO,EAAE,CAAA,EAAG,CAAA,EAAG,MAAA,CAAO,CAAC,CAAA,EAAG,CAAE,CAAA;AACrE,EAAA,OAAA,CAAQ,IAAA,CAAK,CAAC,CAAA,EAAG,CAAA,KAAO,EAAE,CAAA,GAAI,CAAA,CAAE,CAAA,GAAI,EAAA,GAAK,CAAA,CAAE,CAAA,GAAI,CAAA,CAAE,CAAA,GAAI,IAAI,CAAE,CAAA;AAC3D,EAAA,OAAO;AAAA,IACH,WAAW,OAAA,CAAQ,GAAA,CAAI,CAAC,CAAA,KAAM,EAAE,CAAC,CAAA;AAAA,IACjC,QAAQ,OAAA,CAAQ,GAAA,CAAI,CAAC,CAAA,KAAM,EAAE,CAAC;AAAA,GAClC;AACJ;AAMO,SAAS,2BAA2B,KAAA,EAAyC;AAChF,EAAA,MAAM,UAAA,GAAa,KAAA,CAAM,MAAA,CAAO,IAAA,CAAK,GAAG,CAAA;AACxC,EAAA,OAAO;AAAA,IACH,wBAAA;AAAA,IACA,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,OAAA,EAAU,MAAM,KAAK,CAAA,CAAA;AAAA,IACrB,WAAW,UAAU,CAAA,CAAA;AAAA,IACrB,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,kBAAA,EAAqB,MAAM,gBAAgB,CAAA,CAAA;AAAA,IAC3C,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,YAAA,EAAe,MAAM,UAAU,CAAA,CAAA;AAAA,IAC/B,CAAA,OAAA,EAAU,MAAM,KAAK,CAAA;AAAA,GACzB,CAAE,KAAK,IAAI,CAAA;AACf;AAEO,SAAS,uBAAuB,KAAA,EAAqC;AACxE,EAAA,OAAO;AAAA,IACH,oBAAA;AAAA,IACA,CAAA,SAAA,EAAY,MAAM,OAAO,CAAA,CAAA;AAAA,IACzB,CAAA,cAAA,EAAiB,MAAM,YAAY,CAAA,CAAA;AAAA,IACnC,CAAA,gBAAA,EAAmB,MAAM,cAAc,CAAA,CAAA;AAAA,IACvC,CAAA,cAAA,EAAiB,MAAM,YAAY,CAAA,CAAA;AAAA,IACnC,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,eAAA,EAAkB,MAAM,aAAa,CAAA,CAAA;AAAA,IACrC,CAAA,iBAAA,EAAoB,MAAM,eAAe,CAAA;AAAA,GAC7C,CAAE,KAAK,IAAI,CAAA;AACf;AAEO,SAAS,2BAA2B,KAAA,EAAyC;AAChF,EAAA,OAAO;AAAA,IACH,wBAAA;AAAA,IACA,CAAA,SAAA,EAAY,MAAM,OAAO,CAAA,CAAA;AAAA,IACzB,CAAA,eAAA,EAAkB,MAAM,aAAa,CAAA,CAAA;AAAA,IACrC,CAAA,QAAA,EAAW,MAAM,MAAM,CAAA,CAAA;AAAA,IACvB,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA;AAAA,GACjC,CAAE,KAAK,IAAI,CAAA;AACf;AAEO,SAAS,8BAA8B,KAAA,EAA4C;AACtF,EAAA,MAAM,UAAA,GAAa,KAAA,CAAM,MAAA,CAAO,IAAA,CAAK,GAAG,CAAA;AACxC,EAAA,OAAO;AAAA,IACH,2BAAA;AAAA,IACA,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,OAAA,EAAU,MAAM,KAAK,CAAA,CAAA;AAAA,IACrB,WAAW,UAAU,CAAA,CAAA;AAAA,IACrB,CAAA,WAAA,EAAc,MAAM,SAAS,CAAA,CAAA;AAAA,IAC7B,CAAA,YAAA,EAAe,MAAM,UAAU,CAAA,CAAA;AAAA,IAC/B,CAAA,OAAA,EAAU,MAAM,KAAK,CAAA;AAAA,GACzB,CAAE,KAAK,IAAI,CAAA;AACf;AAMO,SAAS,yBAAyB,KAAA,EAA6C;AAClF,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,MAAA,CAAO,0BAAA,CAA2B,KAAK,CAAC,CAAA;AACrE;AAEO,SAAS,qBAAqB,KAAA,EAAyC;AAC1E,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,MAAA,CAAO,sBAAA,CAAuB,KAAK,CAAC,CAAA;AACjE;AAEO,SAAS,yBAAyB,KAAA,EAA6C;AAClF,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,MAAA,CAAO,0BAAA,CAA2B,KAAK,CAAC,CAAA;AACrE;AAEO,SAAS,4BAA4B,KAAA,EAAgD;AACxF,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,MAAA,CAAO,6BAAA,CAA8B,KAAK,CAAC,CAAA;AACxE;AAEO,SAAS,oBAAoB,KAAA,EAAyC;AACzE,EAAA,OAAO,SAAA,CAAU,MAAA,CAAO,wBAAA,CAAyB,KAAK,CAAC,CAAC,CAAA;AAC5D;AAEO,SAAS,gBAAgB,KAAA,EAAqC;AACjE,EAAA,OAAO,SAAA,CAAU,MAAA,CAAO,oBAAA,CAAqB,KAAK,CAAC,CAAC,CAAA;AACxD;AAEO,SAAS,oBAAoB,KAAA,EAAyC;AACzE,EAAA,OAAO,SAAA,CAAU,MAAA,CAAO,wBAAA,CAAyB,KAAK,CAAC,CAAC,CAAA;AAC5D;AAEO,SAAS,uBAAuB,KAAA,EAA4C;AAC/E,EAAA,OAAO,SAAA,CAAU,MAAA,CAAO,2BAAA,CAA4B,KAAK,CAAC,CAAC,CAAA;AAC/D;AAMO,SAAS,uBAAuB,GAAA,EAAiC;AACpE,EAAA,OAAO,aAAa,GAAoD,CAAA;AAC5E;AAEO,SAAS,mBAAmB,GAAA,EAA6B;AAC5D,EAAA,OAAO,aAAa,GAAoD,CAAA;AAC5E;AAEO,SAAS,uBAAuB,GAAA,EAAiC;AACpE,EAAA,OAAO,aAAa,GAAoD,CAAA;AAC5E;AAEO,SAAS,yBAAyB,GAAA,EAAqC;AAC1E,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,OAAO,sBAAA,CAAuB,GAAG,IAAI,IAAI,CAAA;AACtE;AAEO,SAAS,qBAAqB,GAAA,EAAiC;AAClE,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,OAAO,kBAAA,CAAmB,GAAG,IAAI,IAAI,CAAA;AAClE;AAEO,SAAS,yBAAyB,GAAA,EAAqC;AAC1E,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,OAAO,sBAAA,CAAuB,GAAG,IAAI,IAAI,CAAA;AACtE;AAEO,SAAS,UAAU,KAAA,EAA2B;AACjD,EAAA,OAAO,SAAA,CAAU,MAAA,CAAO,KAAK,CAAC,CAAA;AAClC;ACtJO,SAAS,oBAAoB,MAAA,EAA8B;AAC9D,EAAA,MAAM,SAAA,GAAY,mBAAmB,MAAM,CAAA;AAC3C,EAAA,MAAM,IAAA,GAAO,IAAA,CAAK,SAAA,CAAU,SAAS,CAAA;AACrC,EAAA,OAAO,IAAI,WAAA,EAAY,CAAE,MAAA,CAAO,IAAI,CAAA;AACxC;AAMO,SAAS,oBAAoB,KAAA,EAA6B;AAC7D,EAAA,MAAM,IAAA,GAAO,IAAI,WAAA,CAAY,OAAA,EAAS,EAAE,OAAO,IAAA,EAAM,CAAA,CAAE,MAAA,CAAO,KAAK,CAAA;AACnE,EAAA,MAAM,MAAA,GAAkB,IAAA,CAAK,KAAA,CAAM,IAAI,CAAA;AACvC,EAAA,IAAI,CAAC,KAAA,CAAM,OAAA,CAAQ,MAAM,CAAA,IAAK,CAAC,MAAA,CAAO,KAAA,CAAM,CAAC,CAAA,KAAM,OAAO,CAAA,KAAM,QAAQ,CAAA,EAAG;AACvE,IAAA,MAAM,IAAI,MAAM,gDAAgD,CAAA;AAAA,EACpE;AACA,EAAA,OAAO,MAAA;AACX;AAmBA,eAAsB,WAClB,KAAA,EACgC;AAChC,EAAA,MAAM,GAAA,GAAM,MAAMA,IAAA,CAAS;AAAA,IACvB,IAAA,EAAM,UAAA;AAAA,IACN,OAAA,EAAS,mBAAA,CAAoB,KAAA,CAAM,MAAM,CAAA;AAAA,IACzC,QAAQ,KAAA,CAAM,MAAA;AAAA,IACd,YAAY,KAAA,CAAM,UAAA;AAAA,IAClB,GAAI,KAAA,CAAM,IAAA,KAAS,UAAa,EAAE,IAAA,EAAM,MAAM,IAAA,EAAK;AAAA,IACnD,GAAI,KAAA,CAAM,SAAA,KAAc,UAAa,EAAE,SAAA,EAAW,MAAM,SAAA;AAAU,GACrE,CAAA;AACD,EAAA,OAAO,GAAA;AACX;AAuBA,eAAsB,aAClB,KAAA,EACuB;AACvB,EAAA,MAAM,CAAA,GAAI,MAAMC,MAAA,CAAW;AAAA,IACvB,UAAU,KAAA,CAAM,QAAA;AAAA,IAChB,QAAQ,KAAA,CAAM,MAAA;AAAA,IACd,GAAI,MAAM,YAAA,GAAe,EAAE,cAAc,KAAA,CAAM,YAAA,KAAiB,EAAC;AAAA,IACjE,GAAI,KAAA,CAAM,sBAAA,KAA2B,MAAA,IAAa;AAAA,MAC9C,wBAAwB,KAAA,CAAM;AAAA;AAClC,GACH,CAAA;AACD,EAAA,OAAO;AAAA,IACH,MAAA,EAAQ,mBAAA,CAAoB,CAAA,CAAE,OAAO,CAAA;AAAA,IACrC,QAAQ,CAAA,CAAE,MAAA;AAAA,IACV,iBAAiB,CAAA,CAAE;AAAA,GACvB;AACJ;AAGO,SAAS,iBAEd,QAAA,EAA4E;AAC1E,EAAA,OAAO,CAAC,CAAC,QAAA,CAAS,gBAAA;AACtB;;;ACjFO,IAAM,uBAAA,GAA0B;AAYhC,IAAM,UAAA,GAAN,cAAyB,KAAA,CAAM;AAAA,EAElC,WAAA,CAAY,MAAsB,OAAA,EAAiB;AAC/C,IAAA,KAAA,CAAM,OAAO,CAAA;AACb,IAAA,IAAA,CAAK,IAAA,GAAO,IAAA;AACZ,IAAA,IAAA,CAAK,IAAA,GAAO,YAAA;AAAA,EAChB;AACJ;AAwBA,eAAsB,iBAAiB,KAAA,EAA+D;AAClG,EAAA,MAAM,MAAM,KAAA,CAAM,QAAA;AAElB,EAAA,IAAI,GAAA,CAAI,MAAM,gBAAA,EAAkB;AAC5B,IAAA,OAAO,GAAA,CAAI,uBAAA,EAAyB,CAAA,mBAAA,EAAsB,GAAA,CAAI,CAAC,CAAA,cAAA,CAAgB,CAAA;AAAA,EACnF;AAEA,EAAA,MAAM,KAAA,GAAQ,qBAAqB,GAAG,CAAA;AACtC,EAAA,IAAI,OAAO,OAAO,KAAA;AAIlB,EAAA,IAAI,GAAA,CAAI,MAAA,KAAW,MAAA,IAAa,GAAA,CAAI,qBAAqB,MAAA,EAAW;AAChE,IAAA,OAAO,GAAA;AAAA,MACH,wBAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,IAAI,GAAA,CAAI,MAAA,KAAW,MAAA,IAAa,GAAA,CAAI,qBAAqB,MAAA,EAAW;AAChE,IAAA,OAAO,GAAA;AAAA,MACH,2BAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AAIA,EAAA,IAAI,aAAA;AAEJ,EAAA,IAAI,GAAA,CAAI,qBAAqB,MAAA,EAAW;AAGpC,IAAA,IAAI,IAAI,gBAAA,CAAiB,IAAA,EAAM,OAAA,KAAY,GAAA,CAAI,UAAU,OAAA,EAAS;AAC9D,MAAA,OAAO,GAAA;AAAA,QACH,aAAA;AAAA,QACA,CAAA,+BAAA,EAAkC,IAAI,gBAAA,CAAiB,IAAA,EAAM,OAAO,CAAA,oCAAA,EAAuC,GAAA,CAAI,UAAU,OAAO,CAAA,CAAA;AAAA,OACpI;AAAA,IACJ;AAEA,IAAA,IAAI,CAAC,MAAM,iBAAA,EAAmB;AAC1B,MAAA,OAAO,GAAA;AAAA,QACH,qBAAA;AAAA,QACA;AAAA,OACJ;AAAA,IACJ;AAIA,IAAA,IAAI;AACA,MAAA,MAAM,CAAA,GAAI,MAAM,YAAA,CAAa;AAAA,QACzB,UAAU,GAAA,CAAI,gBAAA;AAAA,QACd,QAAQ,KAAA,CAAM,iBAAA;AAAA,QACd,GAAI,MAAM,YAAA,GAAe,EAAE,cAAc,KAAA,CAAM,YAAA,KAAiB,EAAC;AAAA,QACjE,sBAAA,EAAwB,CAAC,CAAC,KAAA,CAAM;AAAA,OACnC,CAAA;AACD,MAAA,aAAA,GAAgB,CAAA,CAAE,MAAA;AAAA,IACtB,SAAS,CAAA,EAAG;AACR,MAAA,MAAM,GAAA,GAAO,CAAA,CAAY,OAAA,IAAW,MAAA,CAAO,CAAC,CAAA;AAK5C,MAAA,IAAI,+CAAA,CAAgD,IAAA,CAAK,GAAG,CAAA,EAAG;AAC3D,QAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,MACzC;AACA,MAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,IACzC;AAAA,EACJ,CAAA,MAAO;AACH,IAAA,aAAA,GAAgB,GAAA,CAAI,MAAA;AAAA,EACxB;AAIA,EAAA,IAAI,eAAA;AACJ,EAAA,IAAI;AACA,IAAA,KAAA,MAAW,CAAA,IAAK,aAAA,EAAe,aAAA,CAAc,UAAA,CAAW,CAAC,CAAA,EAAG,EAAE,IAAA,EAAM,KAAA,CAAM,SAAA,IAAa,QAAA,EAAU,CAAA;AACjG,IAAA,eAAA,GAAkB,mBAAmB,aAAa,CAAA;AAAA,EACtD,SAAS,CAAA,EAAG;AACR,IAAA,MAAM,GAAA,GAAM,CAAA,YAAa,eAAA,GAAkB,CAAA,CAAE,UAAW,CAAA,CAAY,OAAA;AACpE,IAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,EACzC;AAKA,EAAA,KAAA,IAAS,CAAA,GAAI,CAAA,EAAG,CAAA,GAAI,eAAA,CAAgB,QAAQ,CAAA,EAAA,EAAK;AAC7C,IAAA,IAAI,aAAA,CAAc,CAAC,CAAA,KAAM,eAAA,CAAgB,CAAC,CAAA,EAAG;AACzC,MAAA,OAAO,GAAA;AAAA,QACH,qBAAA;AAAA,QACA,CAAA,eAAA,EAAkB,CAAC,CAAA,iCAAA,EAAoC,eAAA,CAAgB,CAAC,CAAC,CAAA,KAAA,EAAQ,aAAA,CAAc,CAAC,CAAC,CAAA;AAAA,OACrG;AAAA,IACJ;AAAA,EACJ;AAGA,EAAA,MAAM,QAAA,GAAW,GAAA,CAAI,IAAA,EAAM,IAAA,IAAQ,CAAA;AACnC,EAAA,MAAM,eAAA,GAAkB,GAAA,CAAI,IAAA,EAAM,cAAA,IAAkB,MAAA;AACpD,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,SAAA,EAAW,IAAI,SAAA,CAAU,OAAA;AAAA,IACzB,KAAA,EAAO,IAAI,KAAA,CAAM,OAAA;AAAA,IACjB,MAAA,EAAQ,eAAA;AAAA,IACR,SAAA,EAAW,QAAA;AAAA,IACX,gBAAA,EAAkB,eAAA;AAAA,IAClB,WAAW,GAAA,CAAI,SAAA;AAAA,IACf,YAAY,GAAA,CAAI,UAAA;AAAA,IAChB,OAAO,GAAA,CAAI;AAAA,GACf;AACA,EAAA,MAAM,oBAAA,GAAuB,2BAA2B,UAAU,CAAA;AAClE,EAAA,MAAM,kBAAkB,SAAA,CAAUC,MAAAA,CAAO,wBAAA,CAAyB,UAAU,CAAC,CAAC,CAAA;AAC9E,EAAA,IAAI,eAAA,KAAoB,IAAI,EAAA,EAAI;AAC5B,IAAA,OAAO,GAAA;AAAA,MACH,UAAA;AAAA,MACA,CAAA,kBAAA,EAAqB,eAAe,CAAA,8BAAA,EAAiC,GAAA,CAAI,EAAE,CAAA,CAAA;AAAA,KAC/E;AAAA,EACJ;AAGA,EAAA,IAAI,CAAC,MAAM,yBAAA,EAA2B;AAClC,IAAA,IAAI,CAAC,KAAA,CAAM,YAAA,EAAc,OAAO,GAAA,CAAI,aAAa,8BAA8B,CAAA;AAC/E,IAAA,MAAM,EAAA,GAAK,MAAM,KAAA,CAAM,YAAA,CAAa,GAAA,CAAI,EAAA,EAAI,GAAA,CAAI,GAAA,CAAI,KAAA,EAAO,GAAA,CAAI,SAAA,CAAU,OAAO,CAAA;AAChF,IAAA,IAAI,CAAC,EAAA,EAAI,OAAO,GAAA,CAAI,aAAa,kCAAkC,CAAA;AAAA,EACvE;AAGA,EAAA,IAAI,CAAC,MAAM,iBAAA,EAAmB;AAC1B,IAAA,MAAM,GAAA,GAAM,KAAA,CAAM,GAAA,oBAAO,IAAI,IAAA,EAAK;AAClC,IAAA,MAAM,MAAA,GAAS,IAAI,IAAA,CAAK,GAAA,CAAI,SAAS,CAAA;AACrC,IAAA,MAAM,OAAA,GAAU,IAAI,IAAA,CAAK,GAAA,CAAI,UAAU,CAAA;AACvC,IAAA,IAAI,OAAA,IAAW,MAAA,EAAQ,OAAO,GAAA,CAAI,eAAe,yBAAyB,CAAA;AAC1E,IAAA,IAAI,GAAA,GAAM,QAAQ,OAAO,GAAA,CAAI,mBAAmB,CAAA,2BAAA,EAA8B,GAAA,CAAI,SAAS,CAAA,CAAE,CAAA;AAC7F,IAAA,IAAI,GAAA,IAAO,SAAS,OAAO,GAAA,CAAI,aAAa,CAAA,sBAAA,EAAyB,GAAA,CAAI,UAAU,CAAA,CAAE,CAAA;AAAA,EACzF;AAKA,EAAA,MAAM,gBAAA,GACF,IAAI,gBAAA,KAAqB,MAAA,GACnB,EAAE,GAAG,GAAA,EAAK,MAAA,EAAQ,eAAA,EAAgB,GAClC,GAAA;AAEV,EAAA,OAAO;AAAA,IACH,EAAA,EAAI,IAAA;AAAA,IACJ,QAAA,EAAU,gBAAA;AAAA,IACV,gBAAA,EAAkB,oBAAA;AAAA,IAClB,IAAI,GAAA,CAAI;AAAA,GACZ;AACJ;AAiDA,eAAsB,aAAa,KAAA,EAAuD;AACtF,EAAA,MAAM,IAAI,KAAA,CAAM,MAAA;AAChB,EAAA,MAAM,IAAI,KAAA,CAAM,UAAA;AAGhB,EAAA,MAAM,KAAA,GAAiC,KAAA,CAAM,kBAAA,IAAsB,EAAC;AACpE,EAAA,MAAM,QAAA,GAAW,MAAM,aAAA,IAAiB,uBAAA;AACxC,EAAA,IAAI,KAAA,CAAM,SAAS,QAAA,EAAU;AACzB,IAAA,OAAO,GAAA;AAAA,MACH,gCAAA;AAAA,MACA,CAAA,YAAA,EAAe,KAAA,CAAM,MAAM,CAAA,iBAAA,EAAoB,QAAQ,CAAA;AAAA,KAC3D;AAAA,EACJ;AAMA,EAAA,MAAM,EAAA,GAAK,MAAM,gBAAA,CAAiB;AAAA,IAC9B,QAAA,EAAU,CAAA;AAAA,IACV,cAAc,KAAA,CAAM,YAAA;AAAA,IACpB,2BAA2B,KAAA,CAAM,yBAAA;AAAA,IACjC,WAAW,KAAA,CAAM,SAAA;AAAA,IACjB,iBAAA,EAAmB,IAAA;AAAA;AAAA,IACnB,GAAI,MAAM,iBAAA,GAAoB,EAAE,mBAAmB,KAAA,CAAM,iBAAA,KAAsB;AAAC,GACnF,CAAA;AACD,EAAA,IAAI,CAAC,EAAA,CAAG,EAAA,EAAI,OAAO,EAAA;AACnB,EAAA,MAAM,eAAmC,EAAA,CAAG,QAAA;AAM5C,EAAA,IAAI,MAAA,GAAoB,YAAA;AACxB,EAAA,MAAM,gBAAyC,EAAC;AAChD,EAAA,KAAA,MAAW,OAAO,KAAA,EAAO;AACrB,IAAA,MAAM,QAAA,GAAW,MAAM,0BAAA,CAA2B,GAAA,EAAK,KAAK,CAAA;AAC5D,IAAA,IAAI,CAAC,QAAA,CAAS,EAAA,EAAI,OAAO,QAAA;AACzB,IAAA,MAAM,IAAI,MAAM,eAAA,CAAgB,QAAA,CAAS,QAAA,EAAU,QAAQ,KAAK,CAAA;AAChE,IAAA,IAAI,CAAC,CAAA,CAAE,EAAA,EAAI,OAAO,CAAA;AAClB,IAAA,aAAA,CAAc,IAAA,CAAK,SAAS,QAAQ,CAAA;AACpC,IAAA,MAAA,GAAS,QAAA,CAAS,QAAA;AAAA,EACtB;AAEA,EAAA,MAAM,IAAA,GACF,cAAc,MAAA,GAAS,CAAA,GAAI,cAAc,aAAA,CAAc,MAAA,GAAS,CAAC,CAAA,GAAK,YAAA;AAG1E,EAAA,IAAI,CAAA,CAAE,MAAM,gBAAA,EAAkB;AAC1B,IAAA,OAAO,GAAA,CAAI,uBAAA,EAAyB,CAAA,eAAA,EAAkB,CAAA,CAAE,CAAC,CAAA,cAAA,CAAgB,CAAA;AAAA,EAC7E;AACA,EAAA,MAAM,KAAA,GAAQ,iBAAiB,CAAC,CAAA;AAChC,EAAA,IAAI,OAAO,OAAO,KAAA;AAElB,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,OAAA,EAAS,EAAE,MAAA,CAAO,OAAA;AAAA,IAClB,YAAA,EAAc,EAAE,OAAA,CAAQ,IAAA;AAAA,IACxB,cAAA,EAAgB,EAAE,OAAA,CAAQ,MAAA;AAAA,IAC1B,YAAA,EAAc,EAAE,OAAA,CAAQ,IAAA;AAAA,IACxB,WAAW,CAAA,CAAE,SAAA;AAAA,IACb,eAAe,CAAA,CAAE,aAAA;AAAA,IACjB,iBAAiB,CAAA,CAAE;AAAA,GACvB;AACA,EAAA,MAAM,oBAAA,GAAuB,uBAAuB,UAAU,CAAA;AAC9D,EAAA,MAAM,kBAAkB,SAAA,CAAUA,MAAAA,CAAO,oBAAA,CAAqB,UAAU,CAAC,CAAC,CAAA;AAC1E,EAAA,IAAI,eAAA,KAAoB,EAAE,EAAA,EAAI;AAC1B,IAAA,OAAO,IAAI,UAAA,EAAY,CAAA,kBAAA,EAAqB,eAAe,CAAA,4BAAA,EAA+B,CAAA,CAAE,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EACrG;AAEA,EAAA,IAAI,CAAC,MAAM,yBAAA,EAA2B;AAClC,IAAA,IAAI,CAAC,KAAA,CAAM,YAAA,EAAc,OAAO,GAAA,CAAI,aAAa,8BAA8B,CAAA;AAC/E,IAAA,MAAM,EAAA,GAAK,MAAM,KAAA,CAAM,YAAA,CAAa,CAAA,CAAE,EAAA,EAAI,CAAA,CAAE,GAAA,CAAI,KAAA,EAAO,CAAA,CAAE,MAAA,CAAO,OAAO,CAAA;AACvE,IAAA,IAAI,CAAC,EAAA,EAAI,OAAO,GAAA,CAAI,sBAAsB,yCAAyC,CAAA;AAAA,EACvF;AAIA,EAAA,IAAI,CAAA,CAAE,aAAA,KAAkB,IAAA,CAAK,EAAA,EAAI;AAC7B,IAAA,OAAO,GAAA,CAAI,yBAAyB,CAAA,sBAAA,EAAyB,CAAA,CAAE,aAAa,CAAA,cAAA,EAAiB,IAAA,CAAK,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EAC3G;AACA,EAAA,IAAI,CAAA,CAAE,MAAA,CAAO,OAAA,KAAY,IAAA,CAAK,MAAM,OAAA,EAAS;AACzC,IAAA,OAAO,GAAA,CAAI,kBAAA,EAAoB,CAAA,eAAA,EAAkB,CAAA,CAAE,MAAA,CAAO,OAAO,CAAA,iBAAA,EAAoB,IAAA,CAAK,KAAA,CAAM,OAAO,CAAA,CAAA,CAAG,CAAA;AAAA,EAC9G;AAGA,EAAA,MAAM,SAAS,IAAI,IAAA,CAAK,IAAA,CAAK,SAAS,EAAE,OAAA,EAAQ;AAChD,EAAA,MAAM,UAAU,IAAI,IAAA,CAAK,IAAA,CAAK,UAAU,EAAE,OAAA,EAAQ;AAClD,EAAA,MAAM,SAAS,IAAI,IAAA,CAAK,CAAA,CAAE,SAAS,EAAE,OAAA,EAAQ;AAC7C,EAAA,IAAI,MAAA,CAAO,KAAA,CAAM,MAAM,CAAA,IAAK,MAAA,CAAO,KAAA,CAAM,OAAO,CAAA,IAAK,MAAA,CAAO,KAAA,CAAM,MAAM,CAAA,EAAG;AACvE,IAAA,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AAAA,EAC9D;AACA,EAAA,IAAI,MAAA,GAAS,MAAA,IAAU,MAAA,IAAU,OAAA,EAAS;AACtC,IAAA,OAAO,GAAA,CAAI,iBAAA,EAAmB,CAAA,iBAAA,EAAoB,CAAA,CAAE,SAAS,CAAA,yBAAA,EAA4B,IAAA,CAAK,SAAS,CAAA,EAAA,EAAK,IAAA,CAAK,UAAU,CAAA,CAAA,CAAG,CAAA;AAAA,EAClI;AAMA,EAAA,IAAI,CAAC,KAAK,MAAA,EAAQ;AACd,IAAA,OAAO,GAAA,CAAI,6BAA6B,8CAA8C,CAAA;AAAA,EAC1F;AACA,EAAA,IAAI,SAAA,EAAW,QAAA;AACf,EAAA,IAAI;AACA,IAAA,SAAA,GAAY,iBAAA,CAAkB,UAAA,CAAW,CAAA,CAAE,eAAe,CAAC,CAAA;AAC3D,IAAA,MAAM,OAAA,GAAU,KAAK,MAAA,CAAO,GAAA,CAAI,CAAC,CAAA,KAAM,UAAA,CAAW,CAAC,CAAC,CAAA;AACpD,IAAA,MAAM,eAAA,GAAkB,UAAA,CAAW,CAAA,CAAE,eAAe,CAAA;AACpD,IAAA,aAAA,CAAc,iBAAiB,EAAE,IAAA,EAAM,KAAA,CAAM,SAAA,IAAa,UAAU,CAAA;AACpE,IAAA,QAAA,GAAW,QAAQ,IAAA,CAAK,CAAC,MAAM,UAAA,CAAW,eAAA,EAAiB,CAAC,CAAC,CAAA;AAAA,EACjE,SAAS,CAAA,EAAG;AACR,IAAA,MAAM,GAAA,GAAM,CAAA,YAAa,eAAA,GAAkB,CAAA,CAAE,UAAW,CAAA,CAAY,OAAA;AACpE,IAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,EACzC;AACA,EAAA,IAAI,CAAC,QAAA,EAAU,OAAO,IAAI,gBAAA,EAAkB,CAAA,iBAAA,EAAoB,SAAS,CAAA,sCAAA,CAAwC,CAAA;AAKjH,EAAA,IAAI,KAAA,CAAM,WAAA,IAAe,KAAA,CAAM,WAAA,CAAY,SAAS,CAAA,EAAG;AACnD,IAAA,MAAM,QAAA,GAAwB,CAAC,YAAA,EAAc,GAAG,aAAa,CAAA;AAC7D,IAAA,KAAA,MAAW,QAAQ,QAAA,EAAU;AACzB,MAAA,KAAA,MAAW,GAAA,IAAO,MAAM,WAAA,EAAa;AACjC,QAAA,IAAI,GAAA,CAAI,aAAA,KAAkB,IAAA,CAAK,EAAA,EAAI;AAInC,QAAA,MAAM,EAAA,GAAK,MAAM,gBAAA,CAAiB;AAAA,UAC9B,QAAA,EAAU,GAAA;AAAA,UACV,UAAA,EAAY,IAAA;AAAA,UACZ,cAAc,KAAA,CAAM,YAAA;AAAA,UACpB,2BAA2B,KAAA,CAAM;AAAA,SACpC,CAAA;AACD,QAAA,IAAI,CAAC,GAAG,EAAA,EAAI;AACZ,QAAA,MAAM,SAAA,GAAY,uBAAA,CAAwB,GAAA,EAAK,KAAA,CAAM,wBAAwB,CAAA;AAC7E,QAAA,MAAM,UAAA,GAAa,mBAAA,CAAoB,CAAA,EAAG,KAAA,CAAM,wBAAwB,CAAA;AACxE,QAAA,IAAI,YAAA,CAAa,SAAA,EAAW,UAAU,CAAA,IAAK,CAAA,EAAG;AAC1C,UAAA,OAAO,GAAA,CAAI,aAAa,CAAA,WAAA,EAAc,IAAA,CAAK,EAAE,CAAA,gBAAA,EAAmB,GAAA,CAAI,EAAE,CAAA,yBAAA,CAA2B,CAAA;AAAA,QACrG;AAAA,MACJ;AAAA,IACJ;AAAA,EACJ;AAGA,EAAA,IAAI,MAAM,OAAA,EAAS;AACf,IAAA,MAAM,aAAa,SAAA,GAAY,SAAA,CAAUA,MAAAA,CAAO,KAAA,CAAM,OAAO,CAAC,CAAA;AAC9D,IAAA,IAAI,UAAA,KAAe,CAAA,CAAE,OAAA,CAAQ,IAAA,EAAM;AAC/B,MAAA,OAAO,GAAA,CAAI,sBAAsB,CAAA,cAAA,EAAiB,UAAU,6BAA6B,CAAA,CAAE,OAAA,CAAQ,IAAI,CAAA,CAAA,CAAG,CAAA;AAAA,IAC9G;AAAA,EACJ;AAGA,EAAA,IAAI,MAAA;AACJ,EAAA,IAAI,CAAA,CAAE,QAAQ,IAAA,EAAM;AAChB,IAAA,MAAA,GAAS,EAAE,QAAQ,MAAA,EAAO;AAAA,EAC9B,CAAA,MAAA,IAAW,CAAA,CAAE,GAAA,CAAI,MAAA,KAAW,SAAA,EAAW;AACnC,IAAA,MAAA,GAAS,EAAE,QAAQ,SAAA,EAAU;AAAA,EACjC,CAAA,MAAO;AACH,IAAA,MAAM,CAAA,GAAI,EAAE,GAAA,CAAI,YAAA;AAChB,IAAA,MAAM,IAAA,GAAO,EAAE,GAAA,CAAI,UAAA;AACnB,IAAA,IAAI,CAAA,KAAM,IAAA,IAAQ,IAAA,KAAS,IAAA,EAAM;AAC7B,MAAA,OAAO,GAAA,CAAI,eAAe,wDAAwD,CAAA;AAAA,IACtF;AACA,IAAA,IAAI,QAAA,GAAW,KAAA;AACf,IAAA,IAAI,MAAM,eAAA,EAAiB;AACvB,MAAA,IAAI;AACA,QAAA,QAAA,GAAW,MAAM,KAAA,CAAM,eAAA,CAAgB,EAAE,GAAA,CAAI,KAAA,EAAO,GAAG,IAAI,CAAA;AAAA,MAC/D,SAAS,CAAA,EAAG;AACR,QAAA,OAAO,GAAA,CAAI,aAAA,EAAe,CAAA,uBAAA,EAA2B,CAAA,CAAY,OAAO,CAAA,CAAE,CAAA;AAAA,MAC9E;AAAA,IACJ;AACA,IAAA,MAAA,GAAS,EAAE,MAAA,EAAQ,WAAA,EAAa,aAAa,CAAA,EAAG,SAAA,EAAW,MAAM,QAAA,EAAS;AAAA,EAC9E;AAEA,EAAA,OAAO;AAAA,IACH,EAAA,EAAI,IAAA;AAAA,IACJ,QAAA,EAAU,CAAA;AAAA,IACV,gBAAA,EAAkB,oBAAA;AAAA,IAClB,IAAI,CAAA,CAAE,EAAA;AAAA,IACN,UAAA,EAAY,YAAA;AAAA,IACZ,KAAA,EAAO,aAAA;AAAA,IACP,cAAA,EAAgB,SAAA;AAAA,IAChB;AAAA,GACJ;AACJ;AAQA,eAAe,0BAAA,CACX,KACA,KAAA,EAGwE;AACxE,EAAA,IAAI,GAAA,CAAI,MAAA,KAAW,MAAA,IAAa,GAAA,CAAI,qBAAqB,MAAA,EAAW;AAChE,IAAA,OAAO,GAAA;AAAA,MACH,wBAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,IAAI,GAAA,CAAI,MAAA,KAAW,MAAA,IAAa,GAAA,CAAI,qBAAqB,MAAA,EAAW;AAChE,IAAA,OAAO,GAAA;AAAA,MACH,2BAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,IAAI,GAAA,CAAI,qBAAqB,MAAA,EAAW;AACpC,IAAA,OAAO,EAAE,EAAA,EAAI,IAAA,EAAM,QAAA,EAAU,GAAA,EAAI;AAAA,EACrC;AACA,EAAA,IAAI,IAAI,gBAAA,CAAiB,IAAA,EAAM,OAAA,KAAY,GAAA,CAAI,UAAU,OAAA,EAAS;AAC9D,IAAA,OAAO,GAAA;AAAA,MACH,aAAA;AAAA,MACA,CAAA,6CAAA,EAAgD,IAAI,gBAAA,CAAiB,IAAA,EAAM,OAAO,CAAA,oCAAA,EAAuC,GAAA,CAAI,UAAU,OAAO,CAAA,CAAA;AAAA,KAClJ;AAAA,EACJ;AACA,EAAA,IAAI,CAAC,MAAM,iBAAA,EAAmB;AAC1B,IAAA,OAAO,GAAA;AAAA,MACH,qBAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,IAAI;AACA,IAAA,MAAM,CAAA,GAAI,MAAM,YAAA,CAAa;AAAA,MACzB,UAAU,GAAA,CAAI,gBAAA;AAAA,MACd,QAAQ,KAAA,CAAM,iBAAA;AAAA,MACd,GAAI,MAAM,YAAA,GAAe,EAAE,cAAc,KAAA,CAAM,YAAA,KAAiB,EAAC;AAAA,MACjE,sBAAA,EAAwB,CAAC,CAAC,KAAA,CAAM;AAAA,KACnC,CAAA;AACD,IAAA,OAAO,EAAE,EAAA,EAAI,IAAA,EAAM,QAAA,EAAU,EAAE,GAAG,GAAA,EAAK,MAAA,EAAQ,CAAA,CAAE,MAAA,EAAO,EAAE;AAAA,EAC9D,SAAS,CAAA,EAAG;AACR,IAAA,MAAM,GAAA,GAAO,CAAA,CAAY,OAAA,IAAW,MAAA,CAAO,CAAC,CAAA;AAC5C,IAAA,IAAI,+CAAA,CAAgD,IAAA,CAAK,GAAG,CAAA,EAAG;AAC3D,MAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,IACzC;AACA,IAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,EACzC;AACJ;AAiBA,eAAsB,iBAAiB,KAAA,EAA+D;AAClG,EAAA,MAAM,MAAM,KAAA,CAAM,QAAA;AAClB,EAAA,MAAM,IAAI,KAAA,CAAM,UAAA;AAEhB,EAAA,IAAI,GAAA,CAAI,MAAM,gBAAA,EAAkB;AAC5B,IAAA,OAAO,GAAA,CAAI,uBAAA,EAAyB,CAAA,mBAAA,EAAsB,GAAA,CAAI,CAAC,CAAA,cAAA,CAAgB,CAAA;AAAA,EACnF;AACA,EAAA,MAAM,KAAA,GAAQ,qBAAqB,GAAG,CAAA;AACtC,EAAA,IAAI,OAAO,OAAO,KAAA;AAElB,EAAA,IAAI,GAAA,CAAI,aAAA,KAAkB,CAAA,CAAE,EAAA,EAAI;AAC5B,IAAA,OAAO,GAAA,CAAI,yBAAyB,CAAA,0BAAA,EAA6B,GAAA,CAAI,aAAa,CAAA,oBAAA,EAAuB,CAAA,CAAE,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EACpH;AAGA,EAAA,MAAM,OAAA,GAAU,CAAA,CAAE,UAAA,EAAY,OAAA,IAAW,CAAC,WAAW,CAAA;AACrD,EAAA,MAAM,WAAA,uBAAkB,GAAA,EAAY;AACpC,EAAA,IAAI,OAAA,CAAQ,SAAS,WAAW,CAAA,cAAe,GAAA,CAAI,CAAA,CAAE,UAAU,OAAO,CAAA;AACtE,EAAA,IAAI,OAAA,CAAQ,SAAS,OAAO,CAAA,cAAe,GAAA,CAAI,CAAA,CAAE,MAAM,OAAO,CAAA;AAC9D,EAAA,IAAI,CAAC,WAAA,CAAY,GAAA,CAAI,GAAA,CAAI,MAAA,CAAO,OAAO,CAAA,EAAG;AACtC,IAAA,OAAO,IAAI,wBAAA,EAA0B,CAAA,kBAAA,EAAqB,GAAA,CAAI,MAAA,CAAO,OAAO,CAAA,0BAAA,CAA4B,CAAA;AAAA,EAC5G;AAEA,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,OAAA,EAAS,IAAI,MAAA,CAAO,OAAA;AAAA,IACpB,eAAe,GAAA,CAAI,aAAA;AAAA,IACnB,QAAQ,GAAA,CAAI,MAAA;AAAA,IACZ,WAAW,GAAA,CAAI;AAAA,GACnB;AACA,EAAA,MAAM,oBAAA,GAAuB,2BAA2B,UAAU,CAAA;AAClE,EAAA,MAAM,kBAAkB,SAAA,CAAUA,MAAAA,CAAO,wBAAA,CAAyB,UAAU,CAAC,CAAC,CAAA;AAC9E,EAAA,IAAI,eAAA,KAAoB,IAAI,EAAA,EAAI;AAC5B,IAAA,OAAO,IAAI,UAAA,EAAY,CAAA,kBAAA,EAAqB,eAAe,CAAA,gCAAA,EAAmC,GAAA,CAAI,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EAC3G;AAEA,EAAA,IAAI,CAAC,MAAM,yBAAA,EAA2B;AAClC,IAAA,IAAI,CAAC,KAAA,CAAM,YAAA,EAAc,OAAO,GAAA,CAAI,aAAa,8BAA8B,CAAA;AAC/E,IAAA,MAAM,EAAA,GAAK,MAAM,KAAA,CAAM,YAAA,CAAa,GAAA,CAAI,EAAA,EAAI,GAAA,CAAI,GAAA,CAAI,KAAA,EAAO,GAAA,CAAI,MAAA,CAAO,OAAO,CAAA;AAC7E,IAAA,IAAI,CAAC,EAAA,EAAI,OAAO,GAAA,CAAI,aAAa,6CAA6C,CAAA;AAAA,EAClF;AAEA,EAAA,OAAO,EAAE,IAAI,IAAA,EAAM,QAAA,EAAU,KAAK,gBAAA,EAAkB,oBAAA,EAAsB,EAAA,EAAI,GAAA,CAAI,EAAA,EAAG;AACzF;AAMA,SAAS,qBAAqB,GAAA,EAAwD;AAClF,EAAA,IAAI,IAAI,IAAA,KAAS,kBAAA,EAAoB,OAAO,GAAA,CAAI,eAAe,iCAAiC,CAAA;AAChG,EAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,EAAE,GAAG,OAAO,GAAA,CAAI,eAAe,mCAAmC,CAAA;AACnF,EAAA,IAAI,CAAC,GAAA,CAAI,SAAA,EAAW,OAAA,IAAW,GAAA,CAAI,SAAA,CAAU,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,mBAAmB,CAAA;AAC5G,EAAA,IAAI,CAAC,GAAA,CAAI,KAAA,EAAO,OAAA,IAAW,GAAA,CAAI,KAAA,CAAM,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,eAAe,CAAA;AAMhG,EAAA,IAAI,GAAA,CAAI,WAAW,MAAA,EAAW;AAC1B,IAAA,IAAI,CAAC,MAAM,OAAA,CAAQ,GAAA,CAAI,MAAM,CAAA,IAAK,GAAA,CAAI,OAAO,MAAA,KAAW,CAAA;AACpD,MAAA,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AAAA,EAClE;AACA,EAAA,IAAI,GAAA,CAAI,SAAS,IAAA,EAAM;AACnB,IAAA,IAAI,CAAC,MAAA,CAAO,SAAA,CAAU,GAAA,CAAI,KAAK,IAAI,CAAA,IAAK,GAAA,CAAI,IAAA,CAAK,IAAA,GAAO,CAAA,EAAG,OAAO,GAAA,CAAI,eAAe,wCAAwC,CAAA;AAC7H,IAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,IAAA,CAAK,cAAc,CAAA,EAAG,OAAO,GAAA,CAAI,aAAA,EAAe,oCAAoC,CAAA;AAAA,EACzG;AACA,EAAA,IAAI,CAAC,SAAS,GAAA,CAAI,SAAS,GAAG,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AACxF,EAAA,IAAI,CAAC,SAAS,GAAA,CAAI,UAAU,GAAG,OAAO,GAAA,CAAI,eAAe,iCAAiC,CAAA;AAC1F,EAAA,IAAI,CAAC,iBAAiB,IAAA,CAAK,GAAA,CAAI,KAAK,CAAA,EAAG,OAAO,GAAA,CAAI,aAAA,EAAe,sCAAsC,CAAA;AACvG,EAAA,IAAI,GAAA,CAAI,GAAA,EAAK,GAAA,KAAQ,QAAA,IAAY,OAAO,GAAA,CAAI,GAAA,CAAI,KAAA,KAAU,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,aAAa,CAAA;AAC3G,EAAA,IAAI,GAAA,CAAI,IAAI,MAAA,KAAW,GAAA,CAAI,UAAU,OAAA,EAAS,OAAO,GAAA,CAAI,aAAA,EAAe,yCAAyC,CAAA;AACjH,EAAA,OAAO,IAAA;AACX;AAEA,SAAS,iBAAiB,CAAA,EAA8C;AACpE,EAAA,IAAI,EAAE,IAAA,KAAS,cAAA,EAAgB,OAAO,GAAA,CAAI,eAAe,6BAA6B,CAAA;AACtF,EAAA,IAAI,CAAC,QAAQ,CAAA,CAAE,EAAE,GAAG,OAAO,GAAA,CAAI,eAAe,mCAAmC,CAAA;AACjF,EAAA,IAAI,CAAC,CAAA,CAAE,OAAA,IAAW,OAAO,EAAE,OAAA,CAAQ,IAAA,KAAS,QAAA,IAAY,CAAC,CAAA,CAAE,OAAA,CAAQ,IAAA,CAAK,UAAA,CAAW,SAAS,CAAA,EAAG;AAC3F,IAAA,OAAO,GAAA,CAAI,eAAe,wCAAwC,CAAA;AAAA,EACtE;AACA,EAAA,IAAI,CAAC,MAAA,CAAO,SAAA,CAAU,CAAA,CAAE,QAAQ,MAAM,CAAA,IAAK,CAAA,CAAE,OAAA,CAAQ,MAAA,GAAS,CAAA,EAAG,OAAO,GAAA,CAAI,eAAe,wBAAwB,CAAA;AACnH,EAAA,IAAI,CAAC,CAAA,CAAE,MAAA,EAAQ,OAAA,IAAW,CAAA,CAAE,MAAA,CAAO,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,gBAAgB,CAAA;AAC/F,EAAA,IAAI,CAAC,SAAS,CAAA,CAAE,SAAS,GAAG,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AACtF,EAAA,IAAI,CAAC,QAAQ,CAAA,CAAE,aAAa,GAAG,OAAO,GAAA,CAAI,eAAe,8BAA8B,CAAA;AACvF,EAAA,IAAI,OAAO,CAAA,CAAE,eAAA,KAAoB,QAAA,IAAY,CAAA,CAAE,eAAA,CAAgB,MAAA,KAAW,CAAA,EAAG,OAAO,GAAA,CAAI,aAAA,EAAe,0BAA0B,CAAA;AACjI,EAAA,IAAI,CAAA,CAAE,GAAA,EAAK,GAAA,KAAQ,QAAA,IAAY,OAAO,CAAA,CAAE,GAAA,CAAI,KAAA,KAAU,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,aAAa,CAAA;AACvG,EAAA,IAAI,CAAA,CAAE,IAAI,MAAA,KAAW,CAAA,CAAE,OAAO,OAAA,EAAS,OAAO,GAAA,CAAI,aAAA,EAAe,sCAAsC,CAAA;AACvG,EAAA,OAAO,IAAA;AACX;AAEA,SAAS,qBAAqB,GAAA,EAAwD;AAClF,EAAA,IAAI,IAAI,IAAA,KAAS,kBAAA,EAAoB,OAAO,GAAA,CAAI,eAAe,iCAAiC,CAAA;AAChG,EAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,EAAE,GAAG,OAAO,GAAA,CAAI,eAAe,mCAAmC,CAAA;AACnF,EAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,aAAa,GAAG,OAAO,GAAA,CAAI,eAAe,8BAA8B,CAAA;AACzF,EAAA,IAAI,CAAC,GAAA,CAAI,MAAA,EAAQ,OAAA,IAAW,GAAA,CAAI,MAAA,CAAO,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,gBAAgB,CAAA;AACnG,EAAA,IAAI,OAAO,GAAA,CAAI,MAAA,KAAW,QAAA,IAAY,GAAA,CAAI,MAAA,CAAO,MAAA,GAAS,GAAA,EAAK,OAAO,GAAA,CAAI,aAAA,EAAe,qCAAqC,CAAA;AAC9H,EAAA,IAAI,CAAC,SAAS,GAAA,CAAI,SAAS,GAAG,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AACxF,EAAA,IAAI,GAAA,CAAI,GAAA,EAAK,GAAA,KAAQ,QAAA,IAAY,OAAO,GAAA,CAAI,GAAA,CAAI,KAAA,KAAU,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,aAAa,CAAA;AAC3G,EAAA,IAAI,GAAA,CAAI,IAAI,MAAA,KAAW,GAAA,CAAI,OAAO,OAAA,EAAS,OAAO,GAAA,CAAI,aAAA,EAAe,sCAAsC,CAAA;AAC3G,EAAA,OAAO,IAAA;AACX;AAEA,SAAS,wBAAwB,GAAA,EAA8D;AAC3F,EAAA,IAAI,IAAI,IAAA,KAAS,qBAAA,EAAuB,OAAO,GAAA,CAAI,eAAe,oCAAoC,CAAA;AACtG,EAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,EAAE,GAAG,OAAO,GAAA,CAAI,eAAe,mCAAmC,CAAA;AACnF,EAAA,IAAI,CAAC,QAAQ,GAAA,CAAI,SAAS,GAAG,OAAO,GAAA,CAAI,eAAe,0BAA0B,CAAA;AACjF,EAAA,IAAI,CAAC,GAAA,CAAI,SAAA,EAAW,OAAA,IAAW,GAAA,CAAI,SAAA,CAAU,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,mBAAmB,CAAA;AAC5G,EAAA,IAAI,CAAC,GAAA,CAAI,KAAA,EAAO,OAAA,IAAW,GAAA,CAAI,KAAA,CAAM,GAAA,KAAQ,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,eAAe,CAAA;AAIhG,EAAA,IAAI,GAAA,CAAI,WAAW,MAAA,EAAW;AAC1B,IAAA,IAAI,CAAC,MAAM,OAAA,CAAQ,GAAA,CAAI,MAAM,CAAA,IAAK,GAAA,CAAI,OAAO,MAAA,KAAW,CAAA;AACpD,MAAA,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AAAA,EAClE;AAEA,EAAA,IAAI,MAAA,IAAU,GAAA,IAAQ,GAAA,CAA2B,IAAA,KAAS,MAAA,EAAW;AACjE,IAAA,OAAO,GAAA,CAAI,eAAe,sDAAsD,CAAA;AAAA,EACpF;AACA,EAAA,IAAI,CAAC,SAAS,GAAA,CAAI,SAAS,GAAG,OAAO,GAAA,CAAI,eAAe,gCAAgC,CAAA;AACxF,EAAA,IAAI,CAAC,SAAS,GAAA,CAAI,UAAU,GAAG,OAAO,GAAA,CAAI,eAAe,iCAAiC,CAAA;AAC1F,EAAA,IAAI,CAAC,iBAAiB,IAAA,CAAK,GAAA,CAAI,KAAK,CAAA,EAAG,OAAO,GAAA,CAAI,aAAA,EAAe,sCAAsC,CAAA;AACvG,EAAA,IAAI,GAAA,CAAI,GAAA,EAAK,GAAA,KAAQ,QAAA,IAAY,OAAO,GAAA,CAAI,GAAA,CAAI,KAAA,KAAU,QAAA,EAAU,OAAO,GAAA,CAAI,aAAA,EAAe,aAAa,CAAA;AAC3G,EAAA,IAAI,GAAA,CAAI,IAAI,MAAA,KAAW,GAAA,CAAI,UAAU,OAAA,EAAS,OAAO,GAAA,CAAI,aAAA,EAAe,yCAAyC,CAAA;AACjH,EAAA,OAAO,IAAA;AACX;AAgBA,eAAe,eAAA,CACX,CAAA,EACA,MAAA,EACA,KAAA,EACkC;AAClC,EAAA,IAAI,CAAA,CAAE,MAAM,gBAAA,EAAkB;AAC1B,IAAA,OAAO,GAAA,CAAI,uBAAA,EAAyB,CAAA,sBAAA,EAAyB,CAAA,CAAE,CAAC,CAAA,cAAA,CAAgB,CAAA;AAAA,EACpF;AACA,EAAA,MAAM,KAAA,GAAQ,wBAAwB,CAAC,CAAA;AACvC,EAAA,IAAI,OAAO,OAAO,KAAA;AAKlB,EAAA,IAAI,CAAC,EAAE,MAAA,EAAQ;AACX,IAAA,OAAO,GAAA;AAAA,MACH,2BAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AAGA,EAAA,IAAI,mBAAA;AACJ,EAAA,IAAI;AACA,IAAA,mBAAA,GAAsB,kBAAA,CAAmB,EAAE,MAAM,CAAA;AAAA,EACrD,SAAS,CAAA,EAAG;AACR,IAAA,MAAM,GAAA,GAAM,CAAA,YAAa,eAAA,GAAkB,CAAA,CAAE,UAAW,CAAA,CAAY,OAAA;AACpE,IAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,EACzC;AACA,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,WAAW,CAAA,CAAE,SAAA;AAAA,IACb,SAAA,EAAW,EAAE,SAAA,CAAU,OAAA;AAAA,IACvB,KAAA,EAAO,EAAE,KAAA,CAAM,OAAA;AAAA,IACf,MAAA,EAAQ,mBAAA;AAAA,IACR,WAAW,CAAA,CAAE,SAAA;AAAA,IACb,YAAY,CAAA,CAAE,UAAA;AAAA,IACd,OAAO,CAAA,CAAE;AAAA,GACb;AACA,EAAA,MAAM,eAAA,GAAkB,uBAAuB,UAAU,CAAA;AACzD,EAAA,IAAI,eAAA,KAAoB,EAAE,EAAA,EAAI;AAC1B,IAAA,OAAO,IAAI,UAAA,EAAY,CAAA,gCAAA,EAAmC,eAAe,CAAA,8BAAA,EAAiC,CAAA,CAAE,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EACrH;AAGA,EAAA,IAAI,YAAA;AACJ,EAAA,IAAI;AACA,IAAA,YAAA,GAAe,EAAE,MAAA,CAAO,GAAA,CAAI,CAAC,GAAA,KAAQ,UAAA,CAAW,GAAG,CAAC,CAAA;AACpD,IAAA,KAAA,MAAW,CAAA,IAAK,cAAc,aAAA,CAAc,CAAA,EAAG,EAAE,IAAA,EAAM,KAAA,CAAM,SAAA,IAAa,QAAA,EAAU,CAAA;AAAA,EACxF,SAAS,CAAA,EAAG;AACR,IAAA,MAAM,GAAA,GAAM,CAAA,YAAa,eAAA,GAAkB,CAAA,CAAE,UAAW,CAAA,CAAY,OAAA;AACpE,IAAA,OAAO,GAAA,CAAI,uBAAuB,GAAG,CAAA;AAAA,EACzC;AAGA,EAAA,IAAI,CAAC,MAAM,yBAAA,EAA2B;AAClC,IAAA,IAAI,CAAC,KAAA,CAAM,YAAA,EAAc,OAAO,GAAA,CAAI,aAAa,gDAAgD,CAAA;AACjG,IAAA,MAAM,EAAA,GAAK,MAAM,KAAA,CAAM,YAAA,CAAa,CAAA,CAAE,EAAA,EAAI,CAAA,CAAE,GAAA,CAAI,KAAA,EAAO,CAAA,CAAE,SAAA,CAAU,OAAO,CAAA;AAC1E,IAAA,IAAI,CAAC,EAAA,EAAI,OAAO,GAAA,CAAI,aAAa,gDAAgD,CAAA;AAAA,EACrF;AAGA,EAAA,IAAI,CAAA,CAAE,SAAA,KAAc,MAAA,CAAO,EAAA,EAAI;AAC3B,IAAA,OAAO,GAAA;AAAA,MACH,oCAAA;AAAA,MACA,CAAA,yBAAA,EAA4B,CAAA,CAAE,SAAS,CAAA,qCAAA,EAAwC,OAAO,EAAE,CAAA,CAAA;AAAA,KAC5F;AAAA,EACJ;AACA,EAAA,IAAI,CAAA,CAAE,SAAA,CAAU,OAAA,KAAY,MAAA,CAAO,MAAM,OAAA,EAAS;AAC9C,IAAA,OAAO,GAAA;AAAA,MACH,oCAAA;AAAA,MACA,4BAA4B,CAAA,CAAE,SAAA,CAAU,OAAO,CAAA,+BAAA,EAAkC,MAAA,CAAO,MAAM,OAAO,CAAA,CAAA;AAAA,KACzG;AAAA,EACJ;AAGA,EAAA,MAAM,UAAU,IAAI,IAAA,CAAK,CAAA,CAAE,SAAS,EAAE,OAAA,EAAQ;AAC9C,EAAA,MAAM,WAAW,IAAI,IAAA,CAAK,CAAA,CAAE,UAAU,EAAE,OAAA,EAAQ;AAChD,EAAA,MAAM,UAAU,IAAI,IAAA,CAAK,MAAA,CAAO,SAAS,EAAE,OAAA,EAAQ;AACnD,EAAA,MAAM,WAAW,IAAI,IAAA,CAAK,MAAA,CAAO,UAAU,EAAE,OAAA,EAAQ;AACrD,EAAA,IAAI,MAAA,CAAO,KAAA,CAAM,OAAO,CAAA,IAAK,OAAO,KAAA,CAAM,QAAQ,CAAA,IAAK,MAAA,CAAO,MAAM,OAAO,CAAA,IAAK,MAAA,CAAO,KAAA,CAAM,QAAQ,CAAA,EAAG;AACpG,IAAA,OAAO,GAAA,CAAI,eAAe,yCAAyC,CAAA;AAAA,EACvE;AACA,EAAA,IAAI,YAAY,OAAA,EAAS;AACrB,IAAA,OAAO,GAAA,CAAI,eAAe,8CAA8C,CAAA;AAAA,EAC5E;AACA,EAAA,IAAI,OAAA,GAAU,OAAA,IAAW,QAAA,GAAW,QAAA,EAAU;AAC1C,IAAA,OAAO,GAAA;AAAA,MACH,kCAAA;AAAA,MACA,CAAA,sBAAA,EAAyB,CAAA,CAAE,SAAS,CAAA,EAAA,EAAK,CAAA,CAAE,UAAU,CAAA,gCAAA,EAAmC,MAAA,CAAO,SAAS,CAAA,EAAA,EAAK,MAAA,CAAO,UAAU,CAAA,CAAA;AAAA,KAClI;AAAA,EACJ;AAGA,EAAA,IAAI,CAAC,OAAO,MAAA,EAAQ;AAChB,IAAA,OAAO,GAAA;AAAA,MACH,2BAAA;AAAA,MACA;AAAA,KACJ;AAAA,EACJ;AACA,EAAA,MAAM,kBAAA,GAAqB,OAAO,MAAA,CAAO,GAAA,CAAI,CAAC,GAAA,KAAQ,UAAA,CAAW,GAAG,CAAC,CAAA;AACrE,EAAA,KAAA,IAAS,CAAA,GAAI,CAAA,EAAG,CAAA,GAAI,YAAA,CAAa,QAAQ,CAAA,EAAA,EAAK;AAC1C,IAAA,MAAM,UAAA,GAAa,aAAa,CAAC,CAAA;AACjC,IAAA,MAAM,0BAAA,GAA6B,mBAAmB,IAAA,CAAK,CAAC,MAAM,UAAA,CAAW,UAAA,EAAY,CAAC,CAAC,CAAA;AAC3F,IAAA,IAAI,CAAC,0BAAA,EAA4B;AAC7B,MAAA,OAAO,GAAA;AAAA,QACH,iCAAA;AAAA,QACA,CAAA,oBAAA,EAAuB,iBAAA,CAAkB,UAAU,CAAC,CAAA,sDAAA;AAAA,OACxD;AAAA,IACJ;AAAA,EACJ;AAEA,EAAA,OAAO;AAAA,IACH,EAAA,EAAI,IAAA;AAAA,IACJ,QAAA,EAAU,CAAA;AAAA,IACV,gBAAA,EAAkB,EAAA;AAAA;AAAA,IAClB,IAAI,CAAA,CAAE;AAAA,GACV;AACJ;AAmCA,eAAsB,oBAClB,KAAA,EACkC;AAGlC,EAAA,MAAM,QAAA,GAAW,MAAM,0BAAA,CAA2B,KAAA,CAAM,UAAU,KAAK,CAAA;AACvE,EAAA,IAAI,CAAC,QAAA,CAAS,EAAA,EAAI,OAAO,QAAA;AACzB,EAAA,MAAM,IAAI,MAAM,eAAA,CAAgB,SAAS,QAAA,EAAU,KAAA,CAAM,QAAQ,KAAK,CAAA;AACtE,EAAA,IAAI,CAAC,CAAA,CAAE,EAAA,EAAI,OAAO,CAAA;AAElB,EAAA,IAAI,CAAC,MAAM,iBAAA,EAAmB;AAC1B,IAAA,MAAM,OAAO,KAAA,CAAM,GAAA,oBAAO,IAAI,IAAA,IAAQ,OAAA,EAAQ;AAC9C,IAAA,MAAM,SAAS,IAAI,IAAA,CAAK,MAAM,QAAA,CAAS,SAAS,EAAE,OAAA,EAAQ;AAC1D,IAAA,MAAM,UAAU,IAAI,IAAA,CAAK,MAAM,QAAA,CAAS,UAAU,EAAE,OAAA,EAAQ;AAC5D,IAAA,IAAI,GAAA,GAAM,QAAQ,OAAO,GAAA,CAAI,mBAAmB,CAAA,wBAAA,EAA2B,KAAA,CAAM,QAAA,CAAS,SAAS,CAAA,iBAAA,CAAmB,CAAA;AACtH,IAAA,IAAI,GAAA,IAAO,SAAS,OAAO,GAAA,CAAI,aAAa,CAAA,yBAAA,EAA4B,KAAA,CAAM,QAAA,CAAS,UAAU,CAAA,QAAA,CAAU,CAAA;AAAA,EAC/G;AAEA,EAAA,OAAO,CAAA;AACX;AAUA,SAAS,mBAAA,CACL,GACA,OAAA,EACa;AACb,EAAA,IAAI,CAAA,CAAE,GAAA,EAAK,MAAA,KAAW,WAAA,EAAa;AAC/B,IAAA,MAAM,IAAI,OAAA,GAAU,OAAA,CAAQ,CAAC,CAAA,GAAI,EAAE,GAAA,CAAI,YAAA;AACvC,IAAA,IAAI,CAAA,KAAM,QAAQ,CAAA,KAAM,MAAA,SAAkB,EAAE,IAAA,EAAM,QAAA,EAAU,WAAA,EAAa,CAAA,EAAE;AAAA,EAC/E;AACA,EAAA,OAAO,EAAE,IAAA,EAAM,QAAA,EAAU,EAAA,EAAI,IAAI,KAAK,CAAA,CAAE,SAAS,CAAA,CAAE,OAAA,EAAQ,EAAE;AACjE;AAEA,SAAS,uBAAA,CACL,GACA,OAAA,EACa;AACb,EAAA,IAAI,CAAA,CAAE,GAAA,EAAK,MAAA,KAAW,WAAA,EAAa;AAC/B,IAAA,MAAM,IAAI,OAAA,GAAU,OAAA,CAAQ,CAAC,CAAA,GAAI,EAAE,GAAA,CAAI,YAAA;AACvC,IAAA,IAAI,CAAA,KAAM,QAAQ,CAAA,KAAM,MAAA,SAAkB,EAAE,IAAA,EAAM,QAAA,EAAU,WAAA,EAAa,CAAA,EAAE;AAAA,EAC/E;AACA,EAAA,OAAO,EAAE,IAAA,EAAM,QAAA,EAAU,EAAA,EAAI,IAAI,KAAK,CAAA,CAAE,SAAS,CAAA,CAAE,OAAA,EAAQ,EAAE;AACjE;AAGA,SAAS,YAAA,CAAa,GAAkB,CAAA,EAA0B;AAC9D,EAAA,IAAI,CAAA,CAAE,SAAS,QAAA,IAAY,CAAA,CAAE,SAAS,QAAA,EAAU,OAAO,CAAA,CAAE,WAAA,GAAc,CAAA,CAAE,WAAA;AAGzE,EAAA,IAAI,CAAA,CAAE,IAAA,KAAS,QAAA,EAAU,OAAO,EAAA;AAChC,EAAA,IAAI,CAAA,CAAE,IAAA,KAAS,QAAA,EAAU,OAAO,CAAA;AAChC,EAAA,OAAO,CAAA,CAAE,KAAK,CAAA,CAAE,EAAA;AACpB;AAIA,SAAS,GAAA,CAAI,MAAsB,OAAA,EAAkC;AACjE,EAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,IAAA,EAAM,OAAA,EAAQ;AACtC;AAIA,SAAS,QAAQ,CAAA,EAAyB;AACtC,EAAA,OAAO,OAAO,CAAA,KAAM,QAAA,IAAY,gBAAA,CAAiB,KAAK,CAAC,CAAA;AAC3D;AAEA,SAAS,SAAS,CAAA,EAAyB;AACvC,EAAA,OACI,OAAO,CAAA,KAAM,QAAA,IACb,gDAAA,CAAiD,KAAK,CAAC,CAAA;AAE/D;AC9xBO,SAAS,qCAAqC,UAAA,EAA0C;AAC3F,EAAA,MAAM,YAAY,UAAA,CAAW,SAAA,CACxB,IAAI,CAAC,CAAA,KAAM,EAAE,OAAO,CAAA,CACpB,KAAK,CAAC,CAAA,EAAG,MAAO,CAAA,GAAI,CAAA,GAAI,KAAK,CAAA,GAAI,CAAA,GAAI,IAAI,CAAE,CAAA;AAChD,EAAA,OAAO;AAAA,IACH,wBAAA;AAAA,IACA,CAAA,WAAA,EAAc,WAAW,SAAS,CAAA,CAAA;AAAA,IAClC,GAAG,SAAA,CAAU,GAAA,CAAI,CAAC,CAAA,KAAM,CAAA,UAAA,EAAa,CAAC,CAAA,CAAE;AAAA,GAC5C,CAAE,KAAK,IAAI,CAAA;AACf;AAGO,SAAS,8BAA8B,UAAA,EAA0C;AACpF,EAAA,OAAO,SAAA,CAAUA,MAAAA,CAAO,IAAI,WAAA,EAAY,CAAE,OAAO,oCAAA,CAAqC,UAAU,CAAC,CAAC,CAAC,CAAA;AACvG;AAEA,SAAS,eAAe,CAAA,EAA6C;AACjE,EAAA,IAAI,OAAO,CAAA,KAAM,QAAA,EAAU,OAAO,IAAA;AAClC,EAAA,MAAM,CAAA,GAAI,kBAAA,CAAmB,IAAA,CAAK,CAAC,CAAA;AACnC,EAAA,IAAI,CAAC,GAAG,OAAO,IAAA;AACf,EAAA,MAAM,EAAA,GAAK,MAAA,CAAO,CAAA,CAAE,CAAC,CAAC,CAAA;AACtB,EAAA,MAAM,EAAA,GAAK,MAAA,CAAO,CAAA,CAAE,CAAC,CAAC,CAAA;AACtB,EAAA,IAAI,CAAC,MAAA,CAAO,SAAA,CAAU,EAAE,KAAK,CAAC,MAAA,CAAO,SAAA,CAAU,EAAE,CAAA,IAAK,EAAA,GAAK,CAAA,IAAK,EAAA,GAAK,IAAI,OAAO,IAAA;AAChF,EAAA,OAAO,EAAE,CAAA,EAAG,EAAA,EAAI,CAAA,EAAG,EAAA,EAAG;AAC1B;AAEA,IAAM,KAAA,GAAQ,gBAAA;AACd,IAAM,OAAA,GAAU,gDAAA;AAMhB,eAAe,qBAAA,CACX,SAAA,EACA,GAAA,EACA,eAAA,EACA,KAAA,EAC4E;AAE5E,EAAA,IAAI,SAAA,EAAW,QAAQ,YAAA,EAAc;AACjC,IAAA,OAAO,IAAA,CAAK,eAAe,oCAAoC,CAAA;AAAA,EACnE;AACA,EAAA,MAAM,aAAa,SAAA,CAAU,UAAA;AAC7B,EAAA,IAAI,CAAC,UAAA,IAAc,UAAA,CAAW,IAAA,KAAS,kBAAA,EAAoB;AACvD,IAAA,OAAO,IAAA,CAAK,eAAe,4CAA4C,CAAA;AAAA,EAC3E;AACA,EAAA,MAAM,MAAA,GAAS,cAAA,CAAe,UAAA,CAAW,SAAS,CAAA;AAClD,EAAA,IAAI,CAAC,QAAQ,OAAO,IAAA,CAAK,eAAe,CAAA,qBAAA,EAAwB,UAAA,CAAW,SAAS,CAAA,CAAA,CAAG,CAAA;AACvF,EAAA,IAAI,CAAC,KAAA,CAAM,OAAA,CAAQ,UAAA,CAAW,SAAS,KAAK,UAAA,CAAW,SAAA,CAAU,MAAA,KAAW,MAAA,CAAO,CAAA,EAAG;AAClF,IAAA,OAAO,IAAA,CAAK,eAAe,yCAAyC,CAAA;AAAA,EACxE;AAGA,EAAA,MAAM,cAAA,GAAiB,8BAA8B,UAAU,CAAA;AAC/D,EAAA,IAAI,SAAA,CAAU,kBAAkB,cAAA,EAAgB;AAC5C,IAAA,OAAO,IAAA;AAAA,MACH,6BAAA;AAAA,MACA,CAAA,wBAAA,EAA2B,SAAA,CAAU,aAAa,CAAA,qBAAA,EAAwB,cAAc,CAAA,CAAA;AAAA,KAC5F;AAAA,EACJ;AAGA,EAAA,IAAI,GAAA,EAAK,QAAQ,mBAAA,EAAqB;AAClC,IAAA,OAAO,IAAA,CAAK,eAAe,qCAAqC,CAAA;AAAA,EACpE;AACA,EAAA,IAAI,GAAA,CAAI,SAAA,KAAc,UAAA,CAAW,SAAA,EAAW;AACxC,IAAA,OAAO,IAAA;AAAA,MACH,sBAAA;AAAA,MACA,CAAA,eAAA,EAAkB,GAAA,CAAI,SAAS,CAAA,2BAAA,EAA8B,WAAW,SAAS,CAAA,CAAA;AAAA,KACrF;AAAA,EACJ;AAGA,EAAA,MAAM,OAAO,GAAA,CAAI,UAAA;AACjB,EAAA,IAAI,CAAC,MAAM,OAAA,CAAQ,IAAI,GAAG,OAAO,IAAA,CAAK,eAAe,iCAAiC,CAAA;AACtF,EAAA,IAAI,IAAA,CAAK,MAAA,GAAS,MAAA,CAAO,CAAA,EAAG;AACxB,IAAA,OAAO,IAAA;AAAA,MACH,qBAAA;AAAA,MACA,CAAA,EAAG,IAAA,CAAK,MAAM,CAAA,gCAAA,EAAmC,OAAO,CAAC,CAAA;AAAA,KAC7D;AAAA,EACJ;AAGA,EAAA,MAAM,WAAA,GAAc,IAAI,GAAA,CAAI,UAAA,CAAW,SAAA,CAAU,IAAI,CAAC,CAAA,KAAM,CAAA,CAAE,OAAO,CAAC,CAAA;AACtE,EAAA,MAAM,IAAA,uBAAW,GAAA,EAAY;AAC7B,EAAA,KAAA,MAAW,KAAK,IAAA,EAAM;AAClB,IAAA,IAAI,CAAC,WAAA,CAAY,GAAA,CAAI,CAAA,CAAE,gBAAgB,CAAA,EAAG;AACtC,MAAA,OAAO,IAAA,CAAK,oBAAA,EAAsB,CAAA,EAAG,CAAA,CAAE,gBAAgB,CAAA,2BAAA,CAA6B,CAAA;AAAA,IACxF;AACA,IAAA,IAAI,IAAA,CAAK,GAAA,CAAI,CAAA,CAAE,gBAAgB,CAAA,EAAG;AAC9B,MAAA,OAAO,IAAA,CAAK,sBAAA,EAAwB,CAAA,EAAG,CAAA,CAAE,gBAAgB,CAAA,sBAAA,CAAwB,CAAA;AAAA,IACrF;AACA,IAAA,IAAA,CAAK,GAAA,CAAI,EAAE,gBAAgB,CAAA;AAAA,EAC/B;AAGA,EAAA,IAAI,CAAC,MAAM,yBAAA,EAA2B;AAClC,IAAA,IAAI,CAAC,KAAA,CAAM,YAAA,EAAc,OAAO,IAAA,CAAK,aAAa,8BAA8B,CAAA;AAChF,IAAA,KAAA,MAAW,KAAK,IAAA,EAAM;AAClB,MAAA,MAAM,EAAA,GAAK,MAAM,KAAA,CAAM,YAAA,CAAa,iBAAiB,CAAA,CAAE,KAAA,EAAO,EAAE,gBAAgB,CAAA;AAChF,MAAA,IAAI,CAAC,EAAA,EAAI;AACL,QAAA,OAAO,IAAA,CAAK,WAAA,EAAa,CAAA,SAAA,EAAY,CAAA,CAAE,gBAAgB,CAAA,yBAAA,CAA2B,CAAA;AAAA,MACtF;AAAA,IACJ;AAAA,EACJ;AACA,EAAA,OAAO,EAAE,IAAI,IAAA,EAAK;AACtB;AAYA,eAAsB,2BAClB,KAAA,EAC+B;AAC/B,EAAA,MAAM,MAAM,KAAA,CAAM,QAAA;AAClB,EAAA,IAAI,KAAK,IAAA,KAAS,kBAAA,EAAoB,OAAO,IAAA,CAAK,eAAe,iCAAiC,CAAA;AAClG,EAAA,IAAI,CAAC,KAAA,CAAM,IAAA,CAAK,GAAA,CAAI,EAAA,IAAM,EAAE,CAAA,EAAG,OAAO,IAAA,CAAK,aAAA,EAAe,mCAAmC,CAAA;AAC7F,EAAA,IAAI,CAAC,GAAA,CAAI,KAAA,EAAO,OAAA,IAAW,GAAA,CAAI,KAAA,CAAM,GAAA,KAAQ,QAAA,EAAU,OAAO,IAAA,CAAK,aAAA,EAAe,eAAe,CAAA;AACjG,EAAA,IAAI,CAAC,MAAM,OAAA,CAAQ,GAAA,CAAI,MAAM,CAAA,IAAK,GAAA,CAAI,MAAA,CAAO,MAAA,KAAW,CAAA,EAAG;AACvD,IAAA,OAAO,IAAA,CAAK,eAAe,kCAAkC,CAAA;AAAA,EACjE;AACA,EAAA,IAAI,CAAC,OAAA,CAAQ,IAAA,CAAK,GAAA,CAAI,SAAS,CAAA,IAAK,CAAC,OAAA,CAAQ,IAAA,CAAK,GAAA,CAAI,UAAU,CAAA,EAAG;AAC/D,IAAA,OAAO,IAAA,CAAK,eAAe,6CAA6C,CAAA;AAAA,EAC5E;AACA,EAAA,IAAI,CAAC,iBAAiB,IAAA,CAAK,GAAA,CAAI,KAAK,CAAA,EAAG,OAAO,IAAA,CAAK,aAAA,EAAe,4BAA4B,CAAA;AAG9F,EAAA,IAAI,eAAA;AACJ,EAAA,IAAI;AACA,IAAA,eAAA,GAAkB,kBAAA,CAAmB,IAAI,MAAM,CAAA;AAAA,EACnD,SAAS,CAAA,EAAG;AACR,IAAA,OAAO,IAAA,CAAK,qBAAA,EAAwB,CAAA,CAAY,OAAO,CAAA;AAAA,EAC3D;AACA,EAAA,KAAA,IAAS,CAAA,GAAI,CAAA,EAAG,CAAA,GAAI,eAAA,CAAgB,QAAQ,CAAA,EAAA,EAAK;AAC7C,IAAA,IAAI,IAAI,MAAA,CAAO,CAAC,CAAA,KAAM,eAAA,CAAgB,CAAC,CAAA,EAAG;AACtC,MAAA,OAAO,IAAA,CAAK,qBAAA,EAAuB,CAAA,YAAA,EAAe,CAAC,CAAA,uBAAA,CAAyB,CAAA;AAAA,IAChF;AAAA,EACJ;AAIA,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,SAAA,EAAW,CAAA,WAAA,EAAc,GAAA,CAAI,SAAA,EAAW,iBAAiB,EAAE,CAAA,CAAA;AAAA,IAC3D,KAAA,EAAO,IAAI,KAAA,CAAM,OAAA;AAAA,IACjB,MAAA,EAAQ,eAAA;AAAA,IACR,SAAA,EAAW,GAAA,CAAI,IAAA,EAAM,IAAA,IAAQ,CAAA;AAAA,IAC7B,gBAAA,EAAkB,GAAA,CAAI,IAAA,EAAM,cAAA,IAAkB,MAAA;AAAA,IAC9C,WAAW,GAAA,CAAI,SAAA;AAAA,IACf,YAAY,GAAA,CAAI,UAAA;AAAA,IAChB,OAAO,GAAA,CAAI;AAAA,GACf;AACA,EAAA,MAAM,eAAA,GAAkB,oBAAoB,UAAU,CAAA;AACtD,EAAA,IAAI,eAAA,KAAoB,IAAI,EAAA,EAAI;AAC5B,IAAA,OAAO,KAAK,UAAA,EAAY,CAAA,kBAAA,EAAqB,eAAe,CAAA,kBAAA,EAAqB,GAAA,CAAI,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EAC9F;AAEA,EAAA,MAAM,MAAA,GAAS,MAAM,qBAAA,CAAsB,GAAA,CAAI,WAAW,GAAA,CAAI,GAAA,EAAK,GAAA,CAAI,EAAA,EAAI,KAAK,CAAA;AAChF,EAAA,IAAI,CAAC,MAAA,CAAO,EAAA,EAAI,OAAO,MAAA;AAEvB,EAAA,IAAI,CAAC,MAAM,iBAAA,EAAmB;AAC1B,IAAA,MAAM,GAAA,GAAM,KAAA,CAAM,GAAA,oBAAO,IAAI,IAAA,EAAK;AAClC,IAAA,MAAM,MAAA,GAAS,IAAI,IAAA,CAAK,GAAA,CAAI,SAAS,CAAA;AACrC,IAAA,MAAM,OAAA,GAAU,IAAI,IAAA,CAAK,GAAA,CAAI,UAAU,CAAA;AACvC,IAAA,IAAI,OAAA,IAAW,MAAA,EAAQ,OAAO,IAAA,CAAK,eAAe,yBAAyB,CAAA;AAC3E,IAAA,IAAI,GAAA,GAAM,QAAQ,OAAO,IAAA,CAAK,mBAAmB,CAAA,2BAAA,EAA8B,GAAA,CAAI,SAAS,CAAA,CAAE,CAAA;AAC9F,IAAA,IAAI,GAAA,IAAO,SAAS,OAAO,IAAA,CAAK,aAAa,CAAA,sBAAA,EAAyB,GAAA,CAAI,UAAU,CAAA,CAAE,CAAA;AAAA,EAC1F;AAEA,EAAA,OAAO,EAAE,IAAI,IAAA,EAAM,EAAA,EAAI,IAAI,EAAA,EAAI,gBAAA,EAAkB,0BAAA,CAA2B,UAAU,CAAA,EAAE;AAC5F;AAUA,eAAsB,2BAClB,KAAA,EAC+B;AAC/B,EAAA,MAAM,MAAM,KAAA,CAAM,QAAA;AAClB,EAAA,IAAI,KAAK,IAAA,KAAS,kBAAA,EAAoB,OAAO,IAAA,CAAK,eAAe,iCAAiC,CAAA;AAClG,EAAA,IAAI,CAAC,KAAA,CAAM,IAAA,CAAK,GAAA,CAAI,EAAA,IAAM,EAAE,CAAA,EAAG,OAAO,IAAA,CAAK,aAAA,EAAe,mCAAmC,CAAA;AAC7F,EAAA,IAAI,CAAC,KAAA,CAAM,IAAA,CAAK,GAAA,CAAI,aAAA,IAAiB,EAAE,CAAA,EAAG,OAAO,IAAA,CAAK,aAAA,EAAe,8BAA8B,CAAA;AACnG,EAAA,IAAI,OAAO,GAAA,CAAI,MAAA,KAAW,YAAY,GAAA,CAAI,MAAA,CAAO,SAAS,GAAA,EAAK;AAC3D,IAAA,OAAO,IAAA,CAAK,eAAe,yCAAoC,CAAA;AAAA,EACnE;AACA,EAAA,IAAI,CAAC,QAAQ,IAAA,CAAK,GAAA,CAAI,SAAS,CAAA,EAAG,OAAO,IAAA,CAAK,aAAA,EAAe,gCAAgC,CAAA;AAI7F,EAAA,MAAM,UAAA,GAAa;AAAA,IACf,OAAA,EAAS,CAAA,WAAA,EAAc,GAAA,CAAI,MAAA,EAAQ,iBAAiB,EAAE,CAAA,CAAA;AAAA,IACtD,eAAe,GAAA,CAAI,aAAA;AAAA,IACnB,QAAQ,GAAA,CAAI,MAAA;AAAA,IACZ,WAAW,GAAA,CAAI;AAAA,GACnB;AACA,EAAA,MAAM,eAAA,GAAkB,oBAAoB,UAAU,CAAA;AACtD,EAAA,IAAI,eAAA,KAAoB,IAAI,EAAA,EAAI;AAC5B,IAAA,OAAO,KAAK,UAAA,EAAY,CAAA,kBAAA,EAAqB,eAAe,CAAA,kBAAA,EAAqB,GAAA,CAAI,EAAE,CAAA,CAAA,CAAG,CAAA;AAAA,EAC9F;AAEA,EAAA,MAAM,MAAA,GAAS,MAAM,qBAAA,CAAsB,GAAA,CAAI,QAAQ,GAAA,CAAI,GAAA,EAAK,GAAA,CAAI,EAAA,EAAI,KAAK,CAAA;AAC7E,EAAA,IAAI,CAAC,MAAA,CAAO,EAAA,EAAI,OAAO,MAAA;AAEvB,EAAA,OAAO,EAAE,IAAI,IAAA,EAAM,EAAA,EAAI,IAAI,EAAA,EAAI,gBAAA,EAAkB,0BAAA,CAA2B,UAAU,CAAA,EAAE;AAC5F;AAEA,SAAS,IAAA,CAAK,MAAsB,OAAA,EAAuE;AACvG,EAAA,OAAO,EAAE,EAAA,EAAI,KAAA,EAAO,IAAA,EAAM,OAAA,EAAQ;AACtC","file":"index.mjs","sourcesContent":["// Wire types for OC Agent v1 envelopes. See SPEC.md §4, §5, §9.\n\nexport const ENVELOPE_VERSION = 1 as const;\n\nexport type EnvelopeKind =\n    | 'agent-delegation'\n    | 'agent-action'\n    | 'agent-revocation'\n    | 'agent-subdelegation';\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Shared building blocks\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface ActorRef {\n    /** mainnet Bitcoin address (P2WPKH, P2TR, or P2PKH). */\n    address: string;\n    alg: 'bip322';\n}\n\nexport interface Signature {\n    alg: 'bip322';\n    pubkey: string; // equals the producing actor's address\n    value: string; // base64 BIP-322 signature over hex(id)\n}\n\nexport type RevocationHolder = 'principal' | 'agent';\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Delegation (SPEC §4)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface DelegationBond {\n    /** Non-negative sats declared as bonded at issuance time. */\n    sats: number;\n    /** SHA-256 hex of the OrangeCheck canonical message signed by principal.address. */\n    attestation_id: string;\n}\n\nexport interface DelegationRevocationRef {\n    /** Who MAY publish a revocation. Default [\"principal\"]. */\n    holders: RevocationHolder[];\n    /** Optional Nostr-addressable pointer to a published revocation. Non-cryptographic. */\n    ref: string | null;\n}\n\n/**\n * v1.2 private-scope mode: a wholesale OC Lock v2 LockEnvelope wrapping the\n * canonical scope list as its payload. We re-import the LockEnvelope type\n * structurally rather than depending on the @orangecheck/lock-core type — agent-\n * core's type surface stays loose so verifiers can be authored in either an\n * agent-only or full-family setup.\n */\nexport interface ScopesEncryptedEnvelope {\n    v: 2;\n    kind: 'identity';\n    id: string;\n    alg: { kem: 'x25519'; aead: 'aes-256-gcm'; kdf: 'hkdf-sha256' };\n    from: { address: string; attestation_id?: string };\n    recipients: Array<{\n        address: string;\n        device_id: string;\n        device_pk: string;\n        eph_pk: string;\n        wrapped_key: string;\n        nonce_kek: string;\n    }>;\n    ciphertext: string;\n    nonce_ct: string;\n    hint?: string;\n    created_at: string;\n    expires_at: string | null;\n    payment: unknown | null;\n    sig: { alg: 'bip322'; pubkey: string; value: string };\n}\n\nexport interface DelegationEnvelope {\n    v: typeof ENVELOPE_VERSION;\n    kind: 'agent-delegation';\n    id: string; // 64-hex sha256(canonical_message)\n    principal: ActorRef;\n    agent: ActorRef;\n    /**\n     * v1.0 / v1.1 public mode: sorted lexicographically in the canonical\n     * message; stored in sorted order on the envelope too.\n     *\n     * v1.2 private mode: this field is OMITTED from the envelope JSON;\n     * `scopes_encrypted` is set instead. After decryption, the recovered\n     * scope list takes this field's place in the in-memory envelope object\n     * for the remainder of verification.\n     */\n    scopes?: string[];\n    /**\n     * v1.2 private mode (PRIVATE-SCOPE.md §1.1): an OC Lock v2 envelope\n     * wrapping the canonical scope-list bytes as its payload, sealed to one\n     * or more recipients (typically the agent ± named verifiers). MUTUALLY\n     * EXCLUSIVE with `scopes`.\n     */\n    scopes_encrypted?: ScopesEncryptedEnvelope;\n    bond: DelegationBond | null;\n    issued_at: string; // ISO 8601 UTC\n    expires_at: string; // ISO 8601 UTC\n    nonce: string; // 32-hex random\n    revocation: DelegationRevocationRef;\n    sig: Signature;\n}\n\nexport interface DelegationCanonicalInput {\n    principal: string;\n    agent: string;\n    scopes: string[]; // pre-canonicalized, pre-sorted\n    bond_sats: number;\n    /** 64-hex attestation id or the literal string \"none\". */\n    bond_attestation: string;\n    issued_at: string;\n    expires_at: string;\n    nonce: string;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Agent-action (SPEC §5) — strict extension of OC Stamp\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface ActionContent {\n    hash: string; // \"sha256:<64-hex>\"\n    length: number;\n    mime: string;\n    ref: string | null;\n}\n\nexport interface ActionOts {\n    status: 'pending' | 'confirmed';\n    proof: string;\n    calendars: string[];\n    block_height: number | null;\n    block_hash: string | null;\n    upgraded_at: string | null;\n}\n\nexport interface ActionEnvelope {\n    v: typeof ENVELOPE_VERSION;\n    kind: 'agent-action';\n    id: string;\n    content: ActionContent;\n    signer: ActorRef; // agent\n    signed_at: string;\n    delegation_id: string; // 64-hex\n    scope_exercised: string; // a sub-scope of some granted scope\n    ots: ActionOts | null;\n    sig: Signature;\n}\n\nexport interface ActionCanonicalInput {\n    address: string; // agent address\n    content_hash: string;\n    content_length: number;\n    content_mime: string;\n    signed_at: string;\n    delegation_id: string;\n    scope_exercised: string;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Sub-delegation (SUB-DELEGATION.md, v1.1)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface SubdelegationEnvelope {\n    v: typeof ENVELOPE_VERSION;\n    kind: 'agent-subdelegation';\n    id: string; // 64-hex sha256(canonical_message)\n    parent_id: string; // 64-hex; the immediate parent envelope's id\n    /** The sub-principal — equal to parent.agent.address. */\n    principal: ActorRef;\n    /** The recipient sub-agent. */\n    agent: ActorRef;\n    /**\n     * v1.0 / v1.1 public mode: each scope MUST be a sub-scope of some scope\n     * on the parent. v1.2 private mode: omitted; `scopes_encrypted` set.\n     */\n    scopes?: string[];\n    /** v1.2 private mode — same shape as the root delegation field. */\n    scopes_encrypted?: ScopesEncryptedEnvelope;\n    issued_at: string; // ISO 8601 UTC; >= parent.issued_at\n    expires_at: string; // ISO 8601 UTC; <= parent.expires_at\n    nonce: string; // 32-hex random\n    revocation: DelegationRevocationRef;\n    sig: Signature;\n}\n\nexport interface SubdelegationCanonicalInput {\n    parent_id: string;\n    principal: string;\n    agent: string;\n    scopes: string[]; // pre-canonicalized, pre-sorted\n    issued_at: string;\n    expires_at: string;\n    nonce: string;\n}\n\n/** Either a root or a sub envelope; chain links walk up to a root delegation. */\nexport type ChainLink = DelegationEnvelope | SubdelegationEnvelope;\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Revocation (SPEC §9)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface RevocationEnvelope {\n    v: typeof ENVELOPE_VERSION;\n    kind: 'agent-revocation';\n    id: string;\n    delegation_id: string;\n    signer: ActorRef;\n    /** Short ASCII rationale, <= 128 bytes. Empty string if omitted. */\n    reason: string;\n    signed_at: string;\n    ots: ActionOts | null;\n    sig: Signature;\n}\n\nexport interface RevocationCanonicalInput {\n    address: string;\n    delegation_id: string;\n    reason: string;\n    signed_at: string;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Error codes (SPEC §11)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport type AgentErrorCode =\n    | 'E_UNSUPPORTED_VERSION'\n    | 'E_MALFORMED'\n    | 'E_BAD_ID'\n    | 'E_BAD_SIG'\n    | 'E_BAD_SCOPE_GRAMMAR'\n    | 'E_NOT_YET_VALID'\n    | 'E_EXPIRED'\n    | 'E_REVOKED'\n    | 'E_DELEGATION_MISMATCH'\n    | 'E_AGENT_MISMATCH'\n    | 'E_OUT_OF_WINDOW'\n    | 'E_SCOPE_DENIED'\n    | 'E_BAD_ACTION_STAMP'\n    | 'E_NO_BOND'\n    | 'E_BOND_UNMET'\n    | 'E_BOND_UNVERIFIED'\n    | 'E_REVOKER_UNAUTHORIZED'\n    | 'E_CALENDAR_UNREACHABLE'\n    | 'E_SUBDELEGATION_DEPTH_EXCEEDED'\n    | 'E_SUBDELEGATION_PRINCIPAL_MISMATCH'\n    | 'E_SUBDELEGATION_EXPIRES_EXTENDED'\n    | 'E_SUBDELEGATION_SCOPE_ESCALATED'\n    | 'E_SCOPES_BOTH_PROVIDED'\n    | 'E_SCOPES_NEITHER_PROVIDED'\n    | 'E_SCOPES_UNREADABLE'\n    | 'E_BAD_LOCK_ENVELOPE'\n    // v1.2 federation principal (FEDERATION.md §3.3)\n    | 'E_BAD_FEDERATION_DESCRIPTOR'\n    | 'E_THRESHOLD_MISMATCH'\n    | 'E_THRESHOLD_NOT_MET'\n    | 'E_UNKNOWN_GUARDIAN'\n    | 'E_DUPLICATE_GUARDIAN';\n\nexport interface VerifyOk<T> {\n    ok: true;\n    envelope: T;\n    canonicalMessage: string;\n    id: string;\n}\n\nexport interface VerifyErr {\n    ok: false;\n    code: AgentErrorCode;\n    message: string;\n}\n\nexport type VerifyDelegationResult = VerifyOk<DelegationEnvelope> | VerifyErr;\nexport type VerifyRevocationResult = VerifyOk<RevocationEnvelope> | VerifyErr;\nexport type VerifySubdelegationResult = VerifyOk<SubdelegationEnvelope> | VerifyErr;\n\nexport interface VerifyActionOkExtra {\n    /** The ROOT delegation rooting the authority chain. */\n    delegation: DelegationEnvelope;\n    /**\n     * The sub-delegation chain `[S_1, …, S_leaf]`. Empty when the action cites\n     * the root directly. The action's authority leaf is\n     * `chain[chain.length - 1] ?? delegation`.\n     */\n    chain: SubdelegationEnvelope[];\n    scopeExercised: string;\n    anchor:\n        | { status: 'none' }\n        | { status: 'pending' }\n        | { status: 'confirmed'; blockHeight: number; blockHash: string; verified: boolean };\n}\n\nexport type VerifyActionResult =\n    | (VerifyOk<ActionEnvelope> & VerifyActionOkExtra)\n    | VerifyErr;\n","// Scope grammar, canonicalization, and sub-scope relation. See SPEC.md §7.\n//\n// A scope is <product>:<verb>(<constraint-list>).\n// Constraints are <key><op><value>, op ∈ { =, !=, <, <=, >, >=, * }.\n// Canonical form: constraints sorted by key; no whitespace.\n\nexport type ScopeOp = '=' | '!=' | '<' | '<=' | '>' | '>=' | '*';\n\nexport interface ScopeConstraint {\n    key: string;\n    op: ScopeOp;\n    /** `undefined` for the wildcard `*` op; otherwise the raw textual value (unquoted). */\n    value: string | undefined;\n    /** True if the value was supplied as a quoted string; preserved for round-trip fidelity. */\n    quoted: boolean;\n}\n\nexport interface Scope {\n    product: string;\n    verb: string;\n    constraints: ScopeConstraint[];\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Registered products/verbs (SPEC §7.3) and constraint keys (SPEC §7.6).\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport const REGISTERED_SCOPES: Record<string, { keys: string[] }> = {\n    'lock:seal': { keys: ['recipient', 'mime', 'max_bytes'] },\n    'lock:chat': { keys: ['recipient', 'max_bytes_per_msg', 'max_msgs'] },\n    'stamp:sign': { keys: ['mime', 'max_bytes', 'content_hash_prefix'] },\n    'vote:cast': { keys: ['poll_id', 'choice'] },\n    'nostr:publish': { keys: ['kind', 'relay', 'max_bytes'] },\n    'http:request': { keys: ['origin', 'method', 'max_rps', 'max_bytes_out'] },\n    'ln:send': { keys: ['max_sats', 'node', 'max_fee_sats'] },\n    'mcp:invoke': { keys: ['server', 'tool', 'max_invocations'] },\n};\n\n/** Keys whose values are compared numerically for sub-scope ordering. */\nconst NUMERIC_KEYS = new Set<string>([\n    'max_bytes',\n    'max_bytes_per_msg',\n    'max_msgs',\n    'max_bytes_out',\n    'max_rps',\n    'max_sats',\n    'max_fee_sats',\n    'max_invocations',\n    'kind',\n]);\n\nconst IDENT_RE = /^[a-z][a-z0-9_]*$/;\nconst BARE_TOKEN_RE = /^[A-Za-z0-9_.:/@+\\-]+$/;\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Parse\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport class ScopeParseError extends Error {\n    constructor(message: string) {\n        super(message);\n        this.name = 'ScopeParseError';\n    }\n}\n\nexport function parseScope(input: string): Scope {\n    if (typeof input !== 'string' || input.length === 0) {\n        throw new ScopeParseError('scope must be a non-empty string');\n    }\n    if (/\\s/.test(input)) {\n        throw new ScopeParseError(`scope may not contain whitespace: ${JSON.stringify(input)}`);\n    }\n\n    const colonIdx = input.indexOf(':');\n    if (colonIdx < 0) throw new ScopeParseError('scope missing \"product:verb\" separator');\n\n    const product = input.slice(0, colonIdx);\n    if (!IDENT_RE.test(product)) throw new ScopeParseError(`invalid product: ${product}`);\n\n    const rest = input.slice(colonIdx + 1);\n    const parenIdx = rest.indexOf('(');\n\n    let verb: string;\n    let constraintText = '';\n    if (parenIdx < 0) {\n        verb = rest;\n    } else {\n        verb = rest.slice(0, parenIdx);\n        if (!rest.endsWith(')')) throw new ScopeParseError('scope constraint list must end with \")\"');\n        constraintText = rest.slice(parenIdx + 1, -1);\n    }\n    if (!IDENT_RE.test(verb)) throw new ScopeParseError(`invalid verb: ${verb}`);\n\n    const constraints: ScopeConstraint[] = [];\n    if (constraintText.length > 0) {\n        for (const piece of splitTopLevelCommas(constraintText)) {\n            constraints.push(parseConstraint(piece));\n        }\n    }\n\n    // No duplicate keys.\n    const seen = new Set<string>();\n    for (const c of constraints) {\n        if (seen.has(c.key)) throw new ScopeParseError(`duplicate constraint key: ${c.key}`);\n        seen.add(c.key);\n    }\n\n    return { product, verb, constraints };\n}\n\nfunction splitTopLevelCommas(text: string): string[] {\n    const out: string[] = [];\n    let depth = 0;\n    let inQuotes = false;\n    let start = 0;\n    for (let i = 0; i < text.length; i++) {\n        const ch = text[i];\n        if (inQuotes) {\n            if (ch === '\\\\' && i + 1 < text.length) {\n                i++;\n                continue;\n            }\n            if (ch === '\"') inQuotes = false;\n            continue;\n        }\n        if (ch === '\"') {\n            inQuotes = true;\n            continue;\n        }\n        if (ch === '(') depth++;\n        else if (ch === ')') depth--;\n        else if (ch === ',' && depth === 0) {\n            out.push(text.slice(start, i));\n            start = i + 1;\n        }\n    }\n    out.push(text.slice(start));\n    return out;\n}\n\nfunction parseConstraint(piece: string): ScopeConstraint {\n    if (piece.length === 0) throw new ScopeParseError('empty constraint');\n\n    // The `*` op (wildcard) is an op with no value. Recognized by \"key=*\" form.\n    // SPEC uses \"key=*\"; we also accept \"key*\" as legacy alias.\n    // Ops in descending length so \">=\" beats \">\" and \"!=\" beats \"!\".\n    const OPS: ScopeOp[] = ['>=', '<=', '!=', '=', '>', '<'];\n\n    // Special-case wildcard: \"key=*\" or \"key*\".\n    const wildcardMatch = /^([a-z][a-z0-9_]*)(?:=\\*|\\*)$/.exec(piece);\n    if (wildcardMatch) {\n        return { key: wildcardMatch[1]!, op: '*', value: undefined, quoted: false };\n    }\n\n    for (const op of OPS) {\n        const idx = piece.indexOf(op);\n        if (idx <= 0) continue; // key must come first and be non-empty\n        const key = piece.slice(0, idx);\n        if (!IDENT_RE.test(key)) continue;\n        const raw = piece.slice(idx + op.length);\n        const { value, quoted } = parseValue(raw);\n        return { key, op, value, quoted };\n    }\n    throw new ScopeParseError(`constraint missing operator: ${piece}`);\n}\n\nfunction parseValue(raw: string): { value: string; quoted: boolean } {\n    if (raw.length === 0) throw new ScopeParseError('constraint value is empty');\n    if (raw.startsWith('\"')) {\n        if (!raw.endsWith('\"') || raw.length < 2) {\n            throw new ScopeParseError(`unterminated quoted value: ${raw}`);\n        }\n        let v = '';\n        for (let i = 1; i < raw.length - 1; i++) {\n            const ch = raw[i]!;\n            if (ch === '\\\\' && i + 1 < raw.length - 1) {\n                const next = raw[++i]!;\n                v += next;\n            } else if (ch === '\"') {\n                throw new ScopeParseError(`unescaped quote in value: ${raw}`);\n            } else {\n                v += ch;\n            }\n        }\n        return { value: v, quoted: true };\n    }\n    if (!BARE_TOKEN_RE.test(raw)) {\n        throw new ScopeParseError(`invalid bare-token value: ${JSON.stringify(raw)}`);\n    }\n    return { value: raw, quoted: false };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Canonicalize\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport function canonicalizeScope(scope: Scope): string {\n    const sorted = [...scope.constraints].sort((a, b) => (a.key < b.key ? -1 : a.key > b.key ? 1 : 0));\n    const parts = sorted.map(serializeConstraint);\n    const inner = parts.join(',');\n    return `${scope.product}:${scope.verb}${parts.length === 0 ? '' : `(${inner})`}`;\n}\n\nexport function canonicalizeScopeString(input: string): string {\n    return canonicalizeScope(parseScope(input));\n}\n\nfunction serializeConstraint(c: ScopeConstraint): string {\n    if (c.op === '*') return `${c.key}=*`;\n    const v = c.quoted ? quoteValue(c.value ?? '') : c.value ?? '';\n    return `${c.key}${c.op}${v}`;\n}\n\nfunction quoteValue(v: string): string {\n    let out = '\"';\n    for (const ch of v) {\n        if (ch === '\"' || ch === '\\\\') out += '\\\\' + ch;\n        else out += ch;\n    }\n    out += '\"';\n    return out;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Registry-based validation\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface ValidationOptions {\n    /**\n     * Strict: reject unknown products/verbs and unknown constraint keys.\n     * Permissive: accept unknown products/verbs; ignore unknown keys without treating them as wider.\n     * Default: 'strict'.\n     */\n    mode?: 'strict' | 'permissive';\n}\n\nexport function validateScope(scope: Scope, options: ValidationOptions = {}): void {\n    const mode = options.mode ?? 'strict';\n    const reg = REGISTERED_SCOPES[`${scope.product}:${scope.verb}`];\n    if (!reg) {\n        if (mode === 'strict') {\n            throw new ScopeParseError(`unregistered scope: ${scope.product}:${scope.verb}`);\n        }\n        return; // permissive: no further checks\n    }\n    const registered = new Set(reg.keys);\n    for (const c of scope.constraints) {\n        if (!registered.has(c.key)) {\n            if (mode === 'strict') {\n                throw new ScopeParseError(\n                    `unregistered constraint key for ${scope.product}:${scope.verb}: ${c.key}`\n                );\n            }\n            // permissive: ignore\n        }\n    }\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Sub-scope relation (SPEC §7.4)\n// ─────────────────────────────────────────────────────────────────────────────\n\n/**\n * Is `exercised` a sub-scope of `granted`?\n * Returns true iff every constraint of `granted` admits the corresponding constraint\n * (or absence) in `exercised`, per SPEC §7.4.\n */\nexport function isSubScope(exercised: Scope, granted: Scope): boolean {\n    if (exercised.product !== granted.product) return false;\n    if (exercised.verb !== granted.verb) return false;\n\n    const exIndex = new Map<string, ScopeConstraint>();\n    for (const c of exercised.constraints) exIndex.set(c.key, c);\n\n    for (const g of granted.constraints) {\n        const ex = exIndex.get(g.key);\n        if (g.op === '*') continue; // wildcard: no requirement\n\n        if (g.op === '=') {\n            if (!ex) return false;\n            if (ex.op !== '=' || ex.value !== g.value) return false;\n            continue;\n        }\n\n        if (g.op === '!=') {\n            if (!ex) return false;\n            if (ex.op === '=' && ex.value !== g.value) continue;\n            if (ex.op === '!=' && ex.value === g.value) continue;\n            return false;\n        }\n\n        // Ordered ops: >=, <=, >, <. Exercised's implied range must be ⊆ granted's.\n        if (g.op === '<' || g.op === '<=' || g.op === '>' || g.op === '>=') {\n            if (!ex) return false;\n            if (!NUMERIC_KEYS.has(g.key)) return false;\n            if (ex.op === '*') return false;\n            if (ex.value === undefined || g.value === undefined) return false;\n            if (!rangeSubset(ex, g)) return false;\n            continue;\n        }\n    }\n    return true;\n}\n\nfunction rangeSubset(ex: ScopeConstraint, g: ScopeConstraint): boolean {\n    const exRange = opToRange(ex);\n    const gRange = opToRange(g);\n    if (!exRange || !gRange) return false;\n    return gRange.lo <= exRange.lo && exRange.hi <= gRange.hi;\n}\n\nfunction opToRange(c: ScopeConstraint): { lo: number; hi: number } | null {\n    if (c.value === undefined) return null;\n    const n = Number(c.value);\n    if (!Number.isFinite(n)) return null;\n    switch (c.op) {\n        case '=':\n            return { lo: n, hi: n };\n        case '<':\n            return { lo: -Infinity, hi: n - 1 }; // integers only\n        case '<=':\n            return { lo: -Infinity, hi: n };\n        case '>':\n            return { lo: n + 1, hi: Infinity };\n        case '>=':\n            return { lo: n, hi: Infinity };\n        default:\n            return null;\n    }\n}\n","// Canonical messages + envelope canonicalization for OC Agent. SPEC §4.1, §5.1, §9.1.\n//\n// Three canonical-message builders live here — one per envelope kind. Each one\n// produces the exact byte sequence a signer signs via BIP-322 and the hash\n// input for the envelope id.\n//\n// The RFC 8785 JSON canonicalizer and hex utilities are re-exported from\n// @orangecheck/stamp-core so OC Agent and OC Stamp are guaranteed to produce\n// identical bytes for identical structural inputs.\n\nimport { sha256 } from '@noble/hashes/sha256';\nimport { canonicalize, hexEncode } from '@orangecheck/stamp-core/canonical';\n\nimport { canonicalizeScope, parseScope, type Scope } from './scope.js';\nimport type {\n    ActionCanonicalInput,\n    ActionEnvelope,\n    DelegationCanonicalInput,\n    DelegationEnvelope,\n    RevocationCanonicalInput,\n    RevocationEnvelope,\n    SubdelegationCanonicalInput,\n} from './types.js';\n\nexport { canonicalize, hexEncode };\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Scope sorting + serialization\n// ─────────────────────────────────────────────────────────────────────────────\n\n/**\n * Canonicalize and sort a list of scope strings for the delegation canonical\n * message. Each scope is first parsed, then re-emitted in canonical form\n * (constraints sorted by key), and the whole list is sorted lexicographically.\n */\nexport function canonicalizeScopes(scopes: string[]): string[] {\n    const canonical = scopes.map((s) => canonicalizeScope(parseScope(s)));\n    return [...canonical].sort((a, b) => (a < b ? -1 : a > b ? 1 : 0));\n}\n\n/**\n * Same as `canonicalizeScopes` but returns `Scope` objects too, for callers\n * that need them.\n */\nexport function parseAndCanonicalizeScopes(scopes: string[]): { canonical: string[]; parsed: Scope[] } {\n    const parsed = scopes.map(parseScope);\n    const canonicalStrings = parsed.map(canonicalizeScope);\n    const indexed = canonicalStrings.map((s, i) => ({ s, p: parsed[i]! }));\n    indexed.sort((a, b) => (a.s < b.s ? -1 : a.s > b.s ? 1 : 0));\n    return {\n        canonical: indexed.map((x) => x.s),\n        parsed: indexed.map((x) => x.p),\n    };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Canonical messages (SPEC §4.1, §5.1, §9.1)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport function delegationCanonicalMessage(input: DelegationCanonicalInput): string {\n    const scopeField = input.scopes.join(',');\n    return [\n        'oc-agent:delegation:v1',\n        `principal: ${input.principal}`,\n        `agent: ${input.agent}`,\n        `scopes: ${scopeField}`,\n        `bond_sats: ${input.bond_sats}`,\n        `bond_attestation: ${input.bond_attestation}`,\n        `issued_at: ${input.issued_at}`,\n        `expires_at: ${input.expires_at}`,\n        `nonce: ${input.nonce}`,\n    ].join('\\n');\n}\n\nexport function actionCanonicalMessage(input: ActionCanonicalInput): string {\n    return [\n        'oc-agent:action:v1',\n        `address: ${input.address}`,\n        `content_hash: ${input.content_hash}`,\n        `content_length: ${input.content_length}`,\n        `content_mime: ${input.content_mime}`,\n        `signed_at: ${input.signed_at}`,\n        `delegation_id: ${input.delegation_id}`,\n        `scope_exercised: ${input.scope_exercised}`,\n    ].join('\\n');\n}\n\nexport function revocationCanonicalMessage(input: RevocationCanonicalInput): string {\n    return [\n        'oc-agent:revocation:v1',\n        `address: ${input.address}`,\n        `delegation_id: ${input.delegation_id}`,\n        `reason: ${input.reason}`,\n        `signed_at: ${input.signed_at}`,\n    ].join('\\n');\n}\n\nexport function subdelegationCanonicalMessage(input: SubdelegationCanonicalInput): string {\n    const scopeField = input.scopes.join(',');\n    return [\n        'oc-agent:subdelegation:v1',\n        `parent_id: ${input.parent_id}`,\n        `principal: ${input.principal}`,\n        `agent: ${input.agent}`,\n        `scopes: ${scopeField}`,\n        `issued_at: ${input.issued_at}`,\n        `expires_at: ${input.expires_at}`,\n        `nonce: ${input.nonce}`,\n    ].join('\\n');\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Bytes + ids\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport function delegationCanonicalBytes(input: DelegationCanonicalInput): Uint8Array {\n    return new TextEncoder().encode(delegationCanonicalMessage(input));\n}\n\nexport function actionCanonicalBytes(input: ActionCanonicalInput): Uint8Array {\n    return new TextEncoder().encode(actionCanonicalMessage(input));\n}\n\nexport function revocationCanonicalBytes(input: RevocationCanonicalInput): Uint8Array {\n    return new TextEncoder().encode(revocationCanonicalMessage(input));\n}\n\nexport function subdelegationCanonicalBytes(input: SubdelegationCanonicalInput): Uint8Array {\n    return new TextEncoder().encode(subdelegationCanonicalMessage(input));\n}\n\nexport function computeDelegationId(input: DelegationCanonicalInput): string {\n    return hexEncode(sha256(delegationCanonicalBytes(input)));\n}\n\nexport function computeActionId(input: ActionCanonicalInput): string {\n    return hexEncode(sha256(actionCanonicalBytes(input)));\n}\n\nexport function computeRevocationId(input: RevocationCanonicalInput): string {\n    return hexEncode(sha256(revocationCanonicalBytes(input)));\n}\n\nexport function computeSubdelegationId(input: SubdelegationCanonicalInput): string {\n    return hexEncode(sha256(subdelegationCanonicalBytes(input)));\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Envelope canonicalization (SPEC §6; RFC 8785 + scope-sorting)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport function canonicalizeDelegation(env: DelegationEnvelope): string {\n    return canonicalize(env as unknown as Parameters<typeof canonicalize>[0]);\n}\n\nexport function canonicalizeAction(env: ActionEnvelope): string {\n    return canonicalize(env as unknown as Parameters<typeof canonicalize>[0]);\n}\n\nexport function canonicalizeRevocation(env: RevocationEnvelope): string {\n    return canonicalize(env as unknown as Parameters<typeof canonicalize>[0]);\n}\n\nexport function canonicalDelegationBytes(env: DelegationEnvelope): Uint8Array {\n    return new TextEncoder().encode(canonicalizeDelegation(env) + '\\n');\n}\n\nexport function canonicalActionBytes(env: ActionEnvelope): Uint8Array {\n    return new TextEncoder().encode(canonicalizeAction(env) + '\\n');\n}\n\nexport function canonicalRevocationBytes(env: RevocationEnvelope): Uint8Array {\n    return new TextEncoder().encode(canonicalizeRevocation(env) + '\\n');\n}\n\nexport function sha256Hex(bytes: Uint8Array): string {\n    return hexEncode(sha256(bytes));\n}\n","// Private-scope helpers (PRIVATE-SCOPE.md, v1.2). Wrapping the OC Lock\n// `seal` and `unseal` primitives with the OC Agent-specific payload format\n// (canonical JSON array of scope strings, UTF-8 encoded).\n//\n// Why this lives in agent-core and not the consumer side: the canonical-\n// message commitment is the same across modes, so verifyDelegation needs to\n// be able to recover the plaintext. Centralizing the payload codec here\n// means every conformant verifier hashes the same bytes.\n\nimport { seal as lockSeal, unseal as lockUnseal } from '@orangecheck/lock-core';\nimport type {\n    DeviceRecord,\n    LockEnvelope,\n    SealInput,\n    UnsealInput,\n} from '@orangecheck/lock-core';\n\nimport { canonicalizeScopes } from './canonical.js';\nimport type { ScopesEncryptedEnvelope } from './types.js';\n\n/**\n * The plaintext payload sealed inside the OC Lock envelope. Canonical JSON\n * array of scope strings. Scopes are first put in canonical form (constraints\n * sorted by key) and the array is sorted lexicographically — same discipline\n * as v1.0 public-mode `scopes` field, so that the canonical-message bytes\n * match byte-for-byte across modes.\n */\nexport function encodeScopesPayload(scopes: string[]): Uint8Array {\n    const canonical = canonicalizeScopes(scopes);\n    const json = JSON.stringify(canonical);\n    return new TextEncoder().encode(json);\n}\n\n/**\n * Inverse of `encodeScopesPayload`. Returns the canonicalized scope array.\n * Throws if the payload doesn't decode to a string array.\n */\nexport function decodeScopesPayload(bytes: Uint8Array): string[] {\n    const json = new TextDecoder('utf-8', { fatal: true }).decode(bytes);\n    const parsed: unknown = JSON.parse(json);\n    if (!Array.isArray(parsed) || !parsed.every((s) => typeof s === 'string')) {\n        throw new Error('scopes payload must be a JSON array of strings');\n    }\n    return parsed as string[];\n}\n\nexport interface SealScopesInput {\n    scopes: string[];\n    /** Principal / sender — the same address that signs the OC Agent envelope. */\n    sender: SealInput['sender'];\n    /** Authorized decryptors. Must include at least the agent. */\n    recipients: DeviceRecord[];\n    /** Optional human hint stored in the OC Lock envelope. */\n    hint?: string;\n    /** Optional expiry on the OC Lock envelope itself. Independent of the\n     *  delegation's expires_at; usually left null. */\n    expiresAt?: Date | null;\n}\n\n/**\n * Seal a scope list to one or more recipients. Returns the OC Lock envelope\n * to be embedded as `delegation.scopes_encrypted`.\n */\nexport async function sealScopes(\n    input: SealScopesInput\n): Promise<ScopesEncryptedEnvelope> {\n    const env = await lockSeal({\n        kind: 'identity',\n        payload: encodeScopesPayload(input.scopes),\n        sender: input.sender,\n        recipients: input.recipients,\n        ...(input.hint !== undefined && { hint: input.hint }),\n        ...(input.expiresAt !== undefined && { expiresAt: input.expiresAt }),\n    });\n    return env as unknown as ScopesEncryptedEnvelope;\n}\n\nexport interface UnsealScopesInput {\n    envelope: ScopesEncryptedEnvelope;\n    device: UnsealInput['device'];\n    /** BIP-322 verifier callback. If omitted, the embedded LockEnvelope's\n     *  signature is NOT checked — useful for inspection or test paths. */\n    verifyBip322?: UnsealInput['verifyBip322'];\n    /** Skip the inner sender-signature check entirely. Default false. */\n    skipSenderVerification?: boolean;\n}\n\n/** Result of unseal: decoded scope list plus the recovered sender address. */\nexport interface UnsealedScopes {\n    scopes: string[];\n    sender: { address: string; attestation_id?: string };\n    matchedDeviceId: string;\n}\n\n/**\n * Decrypt an OC Agent v1.2 `scopes_encrypted` field with one of the\n * recipient device keys.\n */\nexport async function unsealScopes(\n    input: UnsealScopesInput\n): Promise<UnsealedScopes> {\n    const r = await lockUnseal({\n        envelope: input.envelope as unknown as LockEnvelope,\n        device: input.device,\n        ...(input.verifyBip322 ? { verifyBip322: input.verifyBip322 } : {}),\n        ...(input.skipSenderVerification !== undefined && {\n            skipSenderVerification: input.skipSenderVerification,\n        }),\n    });\n    return {\n        scopes: decodeScopesPayload(r.payload),\n        sender: r.sender,\n        matchedDeviceId: r.matchedDeviceId,\n    };\n}\n\n/** Convenience predicate. */\nexport function hasPrivateScopes<\n    T extends { scopes?: string[]; scopes_encrypted?: ScopesEncryptedEnvelope }\n>(envelope: T): envelope is T & { scopes_encrypted: ScopesEncryptedEnvelope } {\n    return !!envelope.scopes_encrypted;\n}\n","// verifyDelegation / verifyAction / verifyRevocation — reference implementation\n// of OC Agent v1 verification. SPEC §8.\n\nimport { sha256 } from '@noble/hashes/sha256';\n\nimport {\n    actionCanonicalBytes,\n    actionCanonicalMessage,\n    canonicalizeScopes,\n    computeSubdelegationId,\n    delegationCanonicalBytes,\n    delegationCanonicalMessage,\n    hexEncode,\n    revocationCanonicalBytes,\n    revocationCanonicalMessage,\n} from './canonical.js';\nimport { unsealScopes } from './private-scope.js';\nimport {\n    canonicalizeScope,\n    isSubScope,\n    parseScope,\n    ScopeParseError,\n    validateScope,\n    type ValidationOptions,\n} from './scope.js';\nimport {\n    ENVELOPE_VERSION,\n    type ActionEnvelope,\n    type AgentErrorCode,\n    type ChainLink,\n    type DelegationEnvelope,\n    type RevocationEnvelope,\n    type SubdelegationEnvelope,\n    type VerifyActionResult,\n    type VerifyDelegationResult,\n    type VerifyRevocationResult,\n    type VerifySubdelegationResult,\n} from './types.js';\n\n/** Default maximum chain depth, per SUB-DELEGATION.md §2.1. */\nexport const DEFAULT_MAX_CHAIN_DEPTH = 5;\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Shared options\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyBase {\n    verifyBip322?: (msg: string, signatureB64: string, address: string) => Promise<boolean>;\n    skipSignatureVerification?: boolean;\n    scopeMode?: ValidationOptions['mode'];\n}\n\nexport class AgentError extends Error {\n    code: AgentErrorCode;\n    constructor(code: AgentErrorCode, message: string) {\n        super(message);\n        this.code = code;\n        this.name = 'AgentError';\n    }\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Delegation (SPEC §8.1)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyDelegationInput extends VerifyBase {\n    envelope: DelegationEnvelope;\n    /** Current time for temporal checks; defaults to new Date(). */\n    now?: Date;\n    /** Skip temporal checks entirely (useful for inspecting historical envelopes). */\n    skipTemporalCheck?: boolean;\n    /**\n     * v1.2 private-scope decryption key. When the envelope carries\n     * `scopes_encrypted`, the verifier MUST supply a device key matching one\n     * of the recipient entries to recover the plaintext scope list. Without\n     * this, verification returns `E_SCOPES_UNREADABLE`.\n     */\n    decryptScopesWith?: {\n        device_id: string;\n        secretKey: Uint8Array;\n    };\n}\n\nexport async function verifyDelegation(input: VerifyDelegationInput): Promise<VerifyDelegationResult> {\n    const env = input.envelope;\n\n    if (env.v !== ENVELOPE_VERSION) {\n        return err('E_UNSUPPORTED_VERSION', `delegation version ${env.v} not supported`);\n    }\n\n    const shape = checkDelegationShape(env);\n    if (shape) return shape;\n\n    // ─── v1.2 PRE-VERIFICATION (PRIVATE-SCOPE.md §2 steps P1–P6) ───────────\n    // Steps P1 / P2: mutual exclusion + presence.\n    if (env.scopes !== undefined && env.scopes_encrypted !== undefined) {\n        return err(\n            'E_SCOPES_BOTH_PROVIDED',\n            'envelope carries both scopes and scopes_encrypted; pick one'\n        );\n    }\n    if (env.scopes === undefined && env.scopes_encrypted === undefined) {\n        return err(\n            'E_SCOPES_NEITHER_PROVIDED',\n            'envelope carries neither scopes nor scopes_encrypted'\n        );\n    }\n\n    // The plaintext scope list. Either copied from env.scopes (public mode)\n    // or recovered by decrypting env.scopes_encrypted (private mode).\n    let workingScopes: string[];\n\n    if (env.scopes_encrypted !== undefined) {\n        // Step P3: issuer binding — the inner Lock envelope's `from.address`\n        // must match the OC Agent envelope's principal.\n        if (env.scopes_encrypted.from?.address !== env.principal.address) {\n            return err(\n                'E_MALFORMED',\n                `scopes_encrypted.from.address (${env.scopes_encrypted.from?.address}) does not match principal.address (${env.principal.address})`\n            );\n        }\n        // Step P5: decryption capability.\n        if (!input.decryptScopesWith) {\n            return err(\n                'E_SCOPES_UNREADABLE',\n                'envelope carries scopes_encrypted; no decryption key provided'\n            );\n        }\n        // Step P6: decrypt. Step P4 (inner-sig verify) is handled inside\n        // unsealScopes via the same BIP-322 verifier — but only when\n        // skipSignatureVerification is false.\n        try {\n            const r = await unsealScopes({\n                envelope: env.scopes_encrypted,\n                device: input.decryptScopesWith,\n                ...(input.verifyBip322 ? { verifyBip322: input.verifyBip322 } : {}),\n                skipSenderVerification: !!input.skipSignatureVerification,\n            });\n            workingScopes = r.scopes;\n        } catch (e) {\n            const msg = (e as Error).message ?? String(e);\n            // Distinguish \"I had a key but the cryptographic operation failed\n            // (bad envelope)\" from \"I had no matching recipient\" — the latter\n            // is the more common case and gets E_SCOPES_UNREADABLE; the\n            // former gets E_BAD_LOCK_ENVELOPE.\n            if (/no matching recipient|no recipient|device_id/i.test(msg)) {\n                return err('E_SCOPES_UNREADABLE', msg);\n            }\n            return err('E_BAD_LOCK_ENVELOPE', msg);\n        }\n    } else {\n        workingScopes = env.scopes!;\n    }\n\n    // ─── Standard verification (SPEC.md §8.1) ──────────────────────────────\n    // Scope grammar.\n    let canonicalScopes: string[];\n    try {\n        for (const s of workingScopes) validateScope(parseScope(s), { mode: input.scopeMode ?? 'strict' });\n        canonicalScopes = canonicalizeScopes(workingScopes);\n    } catch (e) {\n        const msg = e instanceof ScopeParseError ? e.message : (e as Error).message;\n        return err('E_BAD_SCOPE_GRAMMAR', msg);\n    }\n\n    // In public mode the envelope's `scopes` array must already be in\n    // canonical sorted order. (Private mode: the decrypted plaintext is\n    // canonicalized at seal time, so this loop is a no-op for it.)\n    for (let i = 0; i < canonicalScopes.length; i++) {\n        if (workingScopes[i] !== canonicalScopes[i]) {\n            return err(\n                'E_BAD_SCOPE_GRAMMAR',\n                `scope at index ${i} not in canonical form; expected ${canonicalScopes[i]} got ${workingScopes[i]}`\n            );\n        }\n    }\n\n    // Canonical message reconstruction.\n    const bondSats = env.bond?.sats ?? 0;\n    const bondAttestation = env.bond?.attestation_id ?? 'none';\n    const canonInput = {\n        principal: env.principal.address,\n        agent: env.agent.address,\n        scopes: canonicalScopes,\n        bond_sats: bondSats,\n        bond_attestation: bondAttestation,\n        issued_at: env.issued_at,\n        expires_at: env.expires_at,\n        nonce: env.nonce,\n    };\n    const reconstructedMessage = delegationCanonicalMessage(canonInput);\n    const reconstructedId = hexEncode(sha256(delegationCanonicalBytes(canonInput)));\n    if (reconstructedId !== env.id) {\n        return err(\n            'E_BAD_ID',\n            `reconstructed id (${reconstructedId}) does not match envelope.id (${env.id})`\n        );\n    }\n\n    // Signature.\n    if (!input.skipSignatureVerification) {\n        if (!input.verifyBip322) return err('E_BAD_SIG', 'no BIP-322 verifier supplied');\n        const ok = await input.verifyBip322(env.id, env.sig.value, env.principal.address);\n        if (!ok) return err('E_BAD_SIG', 'BIP-322 signature did not verify');\n    }\n\n    // Temporal.\n    if (!input.skipTemporalCheck) {\n        const now = input.now ?? new Date();\n        const issued = new Date(env.issued_at);\n        const expires = new Date(env.expires_at);\n        if (expires <= issued) return err('E_MALFORMED', 'expires_at <= issued_at');\n        if (now < issued) return err('E_NOT_YET_VALID', `delegation not valid until ${env.issued_at}`);\n        if (now >= expires) return err('E_EXPIRED', `delegation expired at ${env.expires_at}`);\n    }\n\n    // In private mode, return a hydrated envelope that includes the recovered\n    // plaintext scopes so callers (verifyAction's chain walker, web-app\n    // consumers) don't have to repeat the decryption.\n    const returnedEnvelope: DelegationEnvelope =\n        env.scopes_encrypted !== undefined\n            ? { ...env, scopes: canonicalScopes }\n            : env;\n\n    return {\n        ok: true,\n        envelope: returnedEnvelope,\n        canonicalMessage: reconstructedMessage,\n        id: env.id,\n    };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Action (SPEC §8.2–8.3)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyActionInput extends VerifyBase {\n    action: ActionEnvelope;\n    /** The ROOT delegation rooting the authority chain. Always required. */\n    delegation: DelegationEnvelope;\n    /**\n     * Optional v1.1 sub-delegation chain from S_1 (immediate child of `delegation`)\n     * to S_leaf (the envelope `action.delegation_id` cites). When provided, the\n     * verifier walks each link checking parent-id linkage, principal-equals-\n     * parent-agent, scope containment, and temporal containment. The action's\n     * delegation_id MUST equal the leaf's id; the action's signer MUST equal\n     * the leaf's agent. See SUB-DELEGATION.md §2.2.\n     */\n    subdelegationChain?: SubdelegationEnvelope[];\n    /**\n     * Maximum permitted chain depth (number of subdelegations).\n     * Default `DEFAULT_MAX_CHAIN_DEPTH` (5). Verifiers MAY lower; MUST NOT raise\n     * silently above their advertised cap. Chains exceeding this fail with\n     * E_SUBDELEGATION_DEPTH_EXCEEDED before any per-link work is performed.\n     */\n    maxChainDepth?: number;\n    /**\n     * Known revocations targeting any envelope in the chain (root + each\n     * subdelegation). The verifier checks every link per SUB-DELEGATION.md §2.2\n     * step 5 — a revocation against ANY link invalidates the action.\n     */\n    revocations?: RevocationEnvelope[];\n    content?: Uint8Array;\n    verifyOtsAnchor?: (proofB64: string, blockHeight: number, blockHash: string) => Promise<boolean>;\n    /** If action and revocation are both OTS-anchored, pass a function that returns the comparable block height of each via proof parsing. Defaults: use envelope.ots.block_height. */\n    resolveAnchorBlockHeight?: (env: ActionEnvelope | RevocationEnvelope) => number | null;\n    /**\n     * v1.2 private-scope decryption key. Applied to the root delegation AND\n     * every subdelegation in the chain that carries `scopes_encrypted`. If a\n     * link is private-mode and no key matches its recipients, verification\n     * fails E_SCOPES_UNREADABLE — the chain's transitive narrowing cannot be\n     * checked without the plaintext.\n     */\n    decryptScopesWith?: {\n        device_id: string;\n        secretKey: Uint8Array;\n    };\n}\n\nexport async function verifyAction(input: VerifyActionInput): Promise<VerifyActionResult> {\n    const a = input.action;\n    const d = input.delegation;\n\n    // 0. Chain-depth check (SUB-DELEGATION.md §2.1) — before any per-link work.\n    const chain: SubdelegationEnvelope[] = input.subdelegationChain ?? [];\n    const maxDepth = input.maxChainDepth ?? DEFAULT_MAX_CHAIN_DEPTH;\n    if (chain.length > maxDepth) {\n        return err(\n            'E_SUBDELEGATION_DEPTH_EXCEEDED',\n            `chain depth ${chain.length} exceeds maximum ${maxDepth}`\n        );\n    }\n\n    // 1. First verify the root delegation. verifyDelegation handles v1.2\n    //    private-scope hydration internally — when the root is private-mode,\n    //    the returned envelope already has `scopes` populated from the\n    //    decrypted plaintext.\n    const dr = await verifyDelegation({\n        envelope: d,\n        verifyBip322: input.verifyBip322,\n        skipSignatureVerification: input.skipSignatureVerification,\n        scopeMode: input.scopeMode,\n        skipTemporalCheck: true, // action window check dominates\n        ...(input.decryptScopesWith ? { decryptScopesWith: input.decryptScopesWith } : {}),\n    });\n    if (!dr.ok) return dr;\n    const rootHydrated: DelegationEnvelope = dr.envelope;\n\n    // 1b. Walk the sub-delegation chain (SUB-DELEGATION.md §2.2 step 3).\n    //     Each link may independently be private-mode; we hydrate it before\n    //     handing it to verifyChainLink so the chain walker sees plaintext\n    //     scopes uniformly.\n    let parent: ChainLink = rootHydrated;\n    const hydratedChain: SubdelegationEnvelope[] = [];\n    for (const sub of chain) {\n        const hydrated = await hydrateSubdelegationScopes(sub, input);\n        if (!hydrated.ok) return hydrated;\n        const r = await verifyChainLink(hydrated.envelope, parent, input);\n        if (!r.ok) return r;\n        hydratedChain.push(hydrated.envelope);\n        parent = hydrated.envelope;\n    }\n    /** The envelope `action.delegation_id` should cite (root if no chain, leaf otherwise). */\n    const leaf: ChainLink =\n        hydratedChain.length > 0 ? hydratedChain[hydratedChain.length - 1]! : rootHydrated;\n\n    // 2. Core action checks.\n    if (a.v !== ENVELOPE_VERSION) {\n        return err('E_UNSUPPORTED_VERSION', `action version ${a.v} not supported`);\n    }\n    const shape = checkActionShape(a);\n    if (shape) return shape;\n\n    const canonInput = {\n        address: a.signer.address,\n        content_hash: a.content.hash,\n        content_length: a.content.length,\n        content_mime: a.content.mime,\n        signed_at: a.signed_at,\n        delegation_id: a.delegation_id,\n        scope_exercised: a.scope_exercised,\n    };\n    const reconstructedMessage = actionCanonicalMessage(canonInput);\n    const reconstructedId = hexEncode(sha256(actionCanonicalBytes(canonInput)));\n    if (reconstructedId !== a.id) {\n        return err('E_BAD_ID', `reconstructed id (${reconstructedId}) does not match action.id (${a.id})`);\n    }\n\n    if (!input.skipSignatureVerification) {\n        if (!input.verifyBip322) return err('E_BAD_SIG', 'no BIP-322 verifier supplied');\n        const ok = await input.verifyBip322(a.id, a.sig.value, a.signer.address);\n        if (!ok) return err('E_BAD_ACTION_STAMP', 'action BIP-322 signature did not verify');\n    }\n\n    // 3. Authority chain — leaf-binding (action cites the leaf of the chain,\n    //    which is the root delegation when no subdelegation chain is present).\n    if (a.delegation_id !== leaf.id) {\n        return err('E_DELEGATION_MISMATCH', `action.delegation_id (${a.delegation_id}) != leaf.id (${leaf.id})`);\n    }\n    if (a.signer.address !== leaf.agent.address) {\n        return err('E_AGENT_MISMATCH', `action signer (${a.signer.address}) != leaf.agent (${leaf.agent.address})`);\n    }\n\n    // 4. Window — against the leaf.\n    const issued = new Date(leaf.issued_at).getTime();\n    const expires = new Date(leaf.expires_at).getTime();\n    const signed = new Date(a.signed_at).getTime();\n    if (Number.isNaN(issued) || Number.isNaN(expires) || Number.isNaN(signed)) {\n        return err('E_MALFORMED', 'unparseable ISO 8601 timestamp');\n    }\n    if (signed < issued || signed >= expires) {\n        return err('E_OUT_OF_WINDOW', `action.signed_at ${a.signed_at} is outside leaf window [${leaf.issued_at}, ${leaf.expires_at})`);\n    }\n\n    // 5. Scope containment — against the leaf's granted set.\n    //    Leaf is post-hydration, so `scopes` is guaranteed populated. The\n    //    runtime guard satisfies the type checker and would only fire if a\n    //    caller bypassed the hydration path.\n    if (!leaf.scopes) {\n        return err('E_SCOPES_NEITHER_PROVIDED', 'leaf has no plaintext scopes after hydration');\n    }\n    let exercised, accepted;\n    try {\n        exercised = canonicalizeScope(parseScope(a.scope_exercised));\n        const granted = leaf.scopes.map((s) => parseScope(s));\n        const exercisedParsed = parseScope(a.scope_exercised);\n        validateScope(exercisedParsed, { mode: input.scopeMode ?? 'strict' });\n        accepted = granted.some((g) => isSubScope(exercisedParsed, g));\n    } catch (e) {\n        const msg = e instanceof ScopeParseError ? e.message : (e as Error).message;\n        return err('E_BAD_SCOPE_GRAMMAR', msg);\n    }\n    if (!accepted) return err('E_SCOPE_DENIED', `scope_exercised (${exercised}) not a sub-scope of any granted scope`);\n\n    // 6. Revocation check — applies per-link to ALL envelopes in the chain\n    //    (root + every subdelegation). Per SUB-DELEGATION.md §2.2 step 5, a\n    //    revocation against ANY link invalidates the action.\n    if (input.revocations && input.revocations.length > 0) {\n        const allLinks: ChainLink[] = [rootHydrated, ...hydratedChain];\n        for (const link of allLinks) {\n            for (const rev of input.revocations) {\n                if (rev.delegation_id !== link.id) continue;\n                // Verify the revocation itself (signature + canonical + signer\n                // authorization). verifyRevocation accepts ChainLink, so the\n                // call shape is identical for root vs sub.\n                const rr = await verifyRevocation({\n                    envelope: rev,\n                    delegation: link,\n                    verifyBip322: input.verifyBip322,\n                    skipSignatureVerification: input.skipSignatureVerification,\n                });\n                if (!rr.ok) continue; // malformed revocations don't affect the action\n                const effective = effectiveRevocationTime(rev, input.resolveAnchorBlockHeight);\n                const actionTime = actionEffectiveTime(a, input.resolveAnchorBlockHeight);\n                if (compareTimes(effective, actionTime) <= 0) {\n                    return err('E_REVOKED', `chain link ${link.id} was revoked by ${rev.id} before action was signed`);\n                }\n            }\n        }\n    }\n\n    // 7. Content check.\n    if (input.content) {\n        const actualHash = 'sha256:' + hexEncode(sha256(input.content));\n        if (actualHash !== a.content.hash) {\n            return err('E_BAD_ACTION_STAMP', `content hash (${actualHash}) != action.content.hash (${a.content.hash})`);\n        }\n    }\n\n    // 8. Anchor info.\n    let anchor: VerifyActionResult extends infer R ? R extends { anchor: infer X } ? X : never : never;\n    if (a.ots === null) {\n        anchor = { status: 'none' } as typeof anchor;\n    } else if (a.ots.status === 'pending') {\n        anchor = { status: 'pending' } as typeof anchor;\n    } else {\n        const h = a.ots.block_height;\n        const hash = a.ots.block_hash;\n        if (h === null || hash === null) {\n            return err('E_MALFORMED', 'confirmed OTS proof missing block_height or block_hash');\n        }\n        let verified = false;\n        if (input.verifyOtsAnchor) {\n            try {\n                verified = await input.verifyOtsAnchor(a.ots.proof, h, hash);\n            } catch (e) {\n                return err('E_MALFORMED', `anchor verifier threw: ${(e as Error).message}`);\n            }\n        }\n        anchor = { status: 'confirmed', blockHeight: h, blockHash: hash, verified } as typeof anchor;\n    }\n\n    return {\n        ok: true,\n        envelope: a,\n        canonicalMessage: reconstructedMessage,\n        id: a.id,\n        delegation: rootHydrated,\n        chain: hydratedChain,\n        scopeExercised: exercised,\n        anchor,\n    };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// v1.2 chain-link hydration — decrypt scopes_encrypted on subdelegations\n// before passing them to the chain walker so all containment checks operate\n// on plaintext.\n// ─────────────────────────────────────────────────────────────────────────────\n\nasync function hydrateSubdelegationScopes(\n    sub: SubdelegationEnvelope,\n    input: VerifyBase & {\n        decryptScopesWith?: { device_id: string; secretKey: Uint8Array };\n    }\n): Promise<{ ok: true; envelope: SubdelegationEnvelope } | VerifyErrResult> {\n    if (sub.scopes !== undefined && sub.scopes_encrypted !== undefined) {\n        return err(\n            'E_SCOPES_BOTH_PROVIDED',\n            'subdelegation carries both scopes and scopes_encrypted'\n        );\n    }\n    if (sub.scopes === undefined && sub.scopes_encrypted === undefined) {\n        return err(\n            'E_SCOPES_NEITHER_PROVIDED',\n            'subdelegation carries neither scopes nor scopes_encrypted'\n        );\n    }\n    if (sub.scopes_encrypted === undefined) {\n        return { ok: true, envelope: sub };\n    }\n    if (sub.scopes_encrypted.from?.address !== sub.principal.address) {\n        return err(\n            'E_MALFORMED',\n            `subdelegation.scopes_encrypted.from.address (${sub.scopes_encrypted.from?.address}) does not match principal.address (${sub.principal.address})`\n        );\n    }\n    if (!input.decryptScopesWith) {\n        return err(\n            'E_SCOPES_UNREADABLE',\n            'subdelegation carries scopes_encrypted; no decryption key provided for the chain'\n        );\n    }\n    try {\n        const r = await unsealScopes({\n            envelope: sub.scopes_encrypted,\n            device: input.decryptScopesWith,\n            ...(input.verifyBip322 ? { verifyBip322: input.verifyBip322 } : {}),\n            skipSenderVerification: !!input.skipSignatureVerification,\n        });\n        return { ok: true, envelope: { ...sub, scopes: r.scopes } };\n    } catch (e) {\n        const msg = (e as Error).message ?? String(e);\n        if (/no matching recipient|no recipient|device_id/i.test(msg)) {\n            return err('E_SCOPES_UNREADABLE', msg);\n        }\n        return err('E_BAD_LOCK_ENVELOPE', msg);\n    }\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Revocation (SPEC §9, §8 transitive)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyRevocationInput extends VerifyBase {\n    envelope: RevocationEnvelope;\n    /**\n     * The envelope targeted by the revocation. Required to check signer is\n     * authorized. May be a v1.0 root delegation OR a v1.1 sub-delegation —\n     * both have identical `principal`, `agent`, `id`, and `revocation.holders`\n     * field shapes per SUB-DELEGATION.md §3.\n     */\n    delegation: ChainLink;\n}\n\nexport async function verifyRevocation(input: VerifyRevocationInput): Promise<VerifyRevocationResult> {\n    const env = input.envelope;\n    const d = input.delegation;\n\n    if (env.v !== ENVELOPE_VERSION) {\n        return err('E_UNSUPPORTED_VERSION', `revocation version ${env.v} not supported`);\n    }\n    const shape = checkRevocationShape(env);\n    if (shape) return shape;\n\n    if (env.delegation_id !== d.id) {\n        return err('E_DELEGATION_MISMATCH', `revocation.delegation_id (${env.delegation_id}) != delegation.id (${d.id})`);\n    }\n\n    // Signer must be authorized per delegation.revocation.holders.\n    const holders = d.revocation?.holders ?? ['principal'];\n    const holderAddrs = new Set<string>();\n    if (holders.includes('principal')) holderAddrs.add(d.principal.address);\n    if (holders.includes('agent')) holderAddrs.add(d.agent.address);\n    if (!holderAddrs.has(env.signer.address)) {\n        return err('E_REVOKER_UNAUTHORIZED', `revocation signer ${env.signer.address} not in delegation holders`);\n    }\n\n    const canonInput = {\n        address: env.signer.address,\n        delegation_id: env.delegation_id,\n        reason: env.reason,\n        signed_at: env.signed_at,\n    };\n    const reconstructedMessage = revocationCanonicalMessage(canonInput);\n    const reconstructedId = hexEncode(sha256(revocationCanonicalBytes(canonInput)));\n    if (reconstructedId !== env.id) {\n        return err('E_BAD_ID', `reconstructed id (${reconstructedId}) does not match revocation.id (${env.id})`);\n    }\n\n    if (!input.skipSignatureVerification) {\n        if (!input.verifyBip322) return err('E_BAD_SIG', 'no BIP-322 verifier supplied');\n        const ok = await input.verifyBip322(env.id, env.sig.value, env.signer.address);\n        if (!ok) return err('E_BAD_SIG', 'revocation BIP-322 signature did not verify');\n    }\n\n    return { ok: true, envelope: env, canonicalMessage: reconstructedMessage, id: env.id };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Shape checks\n// ─────────────────────────────────────────────────────────────────────────────\n\nfunction checkDelegationShape(env: DelegationEnvelope): VerifyDelegationResult | null {\n    if (env.kind !== 'agent-delegation') return err('E_MALFORMED', 'kind must be \"agent-delegation\"');\n    if (!isHex64(env.id)) return err('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!env.principal?.address || env.principal.alg !== 'bip322') return err('E_MALFORMED', 'principal invalid');\n    if (!env.agent?.address || env.agent.alg !== 'bip322') return err('E_MALFORMED', 'agent invalid');\n    // v1.2: scopes OR scopes_encrypted (exactly one). Mutual exclusion +\n    // presence checks are performed by the verify-time PRE-VERIFICATION block\n    // (PRIVATE-SCOPE.md §2 steps P1–P2) so they can return their own error\n    // codes (E_SCOPES_BOTH_PROVIDED / E_SCOPES_NEITHER_PROVIDED) rather than\n    // collapsing into E_MALFORMED.\n    if (env.scopes !== undefined) {\n        if (!Array.isArray(env.scopes) || env.scopes.length === 0)\n            return err('E_MALFORMED', 'scopes must be non-empty array');\n    }\n    if (env.bond !== null) {\n        if (!Number.isInteger(env.bond.sats) || env.bond.sats < 0) return err('E_MALFORMED', 'bond.sats must be non-negative integer');\n        if (!isHex64(env.bond.attestation_id)) return err('E_MALFORMED', 'bond.attestation_id must be 64-hex');\n    }\n    if (!isIsoUtc(env.issued_at)) return err('E_MALFORMED', 'issued_at must be ISO 8601 UTC');\n    if (!isIsoUtc(env.expires_at)) return err('E_MALFORMED', 'expires_at must be ISO 8601 UTC');\n    if (!/^[0-9a-f]{32}$/.test(env.nonce)) return err('E_MALFORMED', 'nonce must be 32 lowercase hex chars');\n    if (env.sig?.alg !== 'bip322' || typeof env.sig.value !== 'string') return err('E_MALFORMED', 'sig invalid');\n    if (env.sig.pubkey !== env.principal.address) return err('E_MALFORMED', 'sig.pubkey must equal principal.address');\n    return null;\n}\n\nfunction checkActionShape(a: ActionEnvelope): VerifyActionResult | null {\n    if (a.kind !== 'agent-action') return err('E_MALFORMED', 'kind must be \"agent-action\"');\n    if (!isHex64(a.id)) return err('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!a.content || typeof a.content.hash !== 'string' || !a.content.hash.startsWith('sha256:')) {\n        return err('E_MALFORMED', 'content.hash must start with \"sha256:\"');\n    }\n    if (!Number.isInteger(a.content.length) || a.content.length < 0) return err('E_MALFORMED', 'content.length invalid');\n    if (!a.signer?.address || a.signer.alg !== 'bip322') return err('E_MALFORMED', 'signer invalid');\n    if (!isIsoUtc(a.signed_at)) return err('E_MALFORMED', 'signed_at must be ISO 8601 UTC');\n    if (!isHex64(a.delegation_id)) return err('E_MALFORMED', 'delegation_id must be 64-hex');\n    if (typeof a.scope_exercised !== 'string' || a.scope_exercised.length === 0) return err('E_MALFORMED', 'scope_exercised required');\n    if (a.sig?.alg !== 'bip322' || typeof a.sig.value !== 'string') return err('E_MALFORMED', 'sig invalid');\n    if (a.sig.pubkey !== a.signer.address) return err('E_MALFORMED', 'sig.pubkey must equal signer.address');\n    return null;\n}\n\nfunction checkRevocationShape(env: RevocationEnvelope): VerifyRevocationResult | null {\n    if (env.kind !== 'agent-revocation') return err('E_MALFORMED', 'kind must be \"agent-revocation\"');\n    if (!isHex64(env.id)) return err('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!isHex64(env.delegation_id)) return err('E_MALFORMED', 'delegation_id must be 64-hex');\n    if (!env.signer?.address || env.signer.alg !== 'bip322') return err('E_MALFORMED', 'signer invalid');\n    if (typeof env.reason !== 'string' || env.reason.length > 128) return err('E_MALFORMED', 'reason must be a string <=128 bytes');\n    if (!isIsoUtc(env.signed_at)) return err('E_MALFORMED', 'signed_at must be ISO 8601 UTC');\n    if (env.sig?.alg !== 'bip322' || typeof env.sig.value !== 'string') return err('E_MALFORMED', 'sig invalid');\n    if (env.sig.pubkey !== env.signer.address) return err('E_MALFORMED', 'sig.pubkey must equal signer.address');\n    return null;\n}\n\nfunction checkSubdelegationShape(env: SubdelegationEnvelope): VerifySubdelegationResult | null {\n    if (env.kind !== 'agent-subdelegation') return err('E_MALFORMED', 'kind must be \"agent-subdelegation\"');\n    if (!isHex64(env.id)) return err('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!isHex64(env.parent_id)) return err('E_MALFORMED', 'parent_id must be 64-hex');\n    if (!env.principal?.address || env.principal.alg !== 'bip322') return err('E_MALFORMED', 'principal invalid');\n    if (!env.agent?.address || env.agent.alg !== 'bip322') return err('E_MALFORMED', 'agent invalid');\n    // v1.2: scopes OR scopes_encrypted (post-hydration the chain walker\n    // always sees `scopes` populated). Mutual exclusion + presence checked\n    // by hydrateSubdelegationScopes.\n    if (env.scopes !== undefined) {\n        if (!Array.isArray(env.scopes) || env.scopes.length === 0)\n            return err('E_MALFORMED', 'scopes must be non-empty array');\n    }\n    // Sub-delegations MUST NOT carry a bond field (SUB-DELEGATION.md §1.3).\n    if ('bond' in env && (env as { bond?: unknown }).bond !== undefined) {\n        return err('E_MALFORMED', 'sub-delegation envelopes MUST NOT carry a bond field');\n    }\n    if (!isIsoUtc(env.issued_at)) return err('E_MALFORMED', 'issued_at must be ISO 8601 UTC');\n    if (!isIsoUtc(env.expires_at)) return err('E_MALFORMED', 'expires_at must be ISO 8601 UTC');\n    if (!/^[0-9a-f]{32}$/.test(env.nonce)) return err('E_MALFORMED', 'nonce must be 32 lowercase hex chars');\n    if (env.sig?.alg !== 'bip322' || typeof env.sig.value !== 'string') return err('E_MALFORMED', 'sig invalid');\n    if (env.sig.pubkey !== env.principal.address) return err('E_MALFORMED', 'sig.pubkey must equal principal.address');\n    return null;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Sub-delegation chain link (SUB-DELEGATION.md §2.2 step 3)\n// ─────────────────────────────────────────────────────────────────────────────\n\n/**\n * Verify a single sub-delegation envelope as a chain link from `parent`.\n * Performs steps 3a–3g in order; returns the corresponding VerifyErr on\n * failure or `{ ok: true, envelope: s }` on success.\n *\n * Skips the standalone temporal-validity check (SUB-DELEGATION.md §2.2 step\n * 3d) — for action verification, the action-window check (step 4c) on the\n * leaf is the binding temporal constraint. Callers that want a current-time\n * \"is this subdelegation active right now\" check can use `verifySubdelegation`.\n */\nasync function verifyChainLink(\n    s: SubdelegationEnvelope,\n    parent: ChainLink,\n    input: VerifyBase\n): Promise<VerifySubdelegationResult> {\n    if (s.v !== ENVELOPE_VERSION) {\n        return err('E_UNSUPPORTED_VERSION', `subdelegation version ${s.v} not supported`);\n    }\n    const shape = checkSubdelegationShape(s);\n    if (shape) return shape;\n\n    // verifyChainLink expects post-hydration scopes (callers run\n    // hydrateSubdelegationScopes upfront). The runtime guard makes the\n    // type-checker happy and protects against bypass.\n    if (!s.scopes) {\n        return err(\n            'E_SCOPES_NEITHER_PROVIDED',\n            'subdelegation has no plaintext scopes — caller must hydrate v1.2 envelopes before invoking verifyChainLink'\n        );\n    }\n\n    // Step 3a: canonical id.\n    let canonicalScopesList: string[];\n    try {\n        canonicalScopesList = canonicalizeScopes(s.scopes);\n    } catch (e) {\n        const msg = e instanceof ScopeParseError ? e.message : (e as Error).message;\n        return err('E_BAD_SCOPE_GRAMMAR', msg);\n    }\n    const canonInput = {\n        parent_id: s.parent_id,\n        principal: s.principal.address,\n        agent: s.agent.address,\n        scopes: canonicalScopesList,\n        issued_at: s.issued_at,\n        expires_at: s.expires_at,\n        nonce: s.nonce,\n    };\n    const reconstructedId = computeSubdelegationId(canonInput);\n    if (reconstructedId !== s.id) {\n        return err('E_BAD_ID', `reconstructed subdelegation id (${reconstructedId}) does not match envelope id (${s.id})`);\n    }\n\n    // Step 3b: scope grammar validation (registry-aware).\n    let parsedScopes;\n    try {\n        parsedScopes = s.scopes.map((str) => parseScope(str));\n        for (const p of parsedScopes) validateScope(p, { mode: input.scopeMode ?? 'strict' });\n    } catch (e) {\n        const msg = e instanceof ScopeParseError ? e.message : (e as Error).message;\n        return err('E_BAD_SCOPE_GRAMMAR', msg);\n    }\n\n    // Step 3c: BIP-322 signature.\n    if (!input.skipSignatureVerification) {\n        if (!input.verifyBip322) return err('E_BAD_SIG', 'no BIP-322 verifier supplied for subdelegation');\n        const ok = await input.verifyBip322(s.id, s.sig.value, s.principal.address);\n        if (!ok) return err('E_BAD_SIG', 'subdelegation BIP-322 signature did not verify');\n    }\n\n    // Step 3e: linkage.\n    if (s.parent_id !== parent.id) {\n        return err(\n            'E_SUBDELEGATION_PRINCIPAL_MISMATCH',\n            `subdelegation.parent_id (${s.parent_id}) does not match parent envelope id (${parent.id})`\n        );\n    }\n    if (s.principal.address !== parent.agent.address) {\n        return err(\n            'E_SUBDELEGATION_PRINCIPAL_MISMATCH',\n            `subdelegation.principal (${s.principal.address}) does not match parent.agent (${parent.agent.address})`\n        );\n    }\n\n    // Step 3f: temporal containment.\n    const sIssued = new Date(s.issued_at).getTime();\n    const sExpires = new Date(s.expires_at).getTime();\n    const pIssued = new Date(parent.issued_at).getTime();\n    const pExpires = new Date(parent.expires_at).getTime();\n    if (Number.isNaN(sIssued) || Number.isNaN(sExpires) || Number.isNaN(pIssued) || Number.isNaN(pExpires)) {\n        return err('E_MALFORMED', 'unparseable ISO 8601 timestamp in chain');\n    }\n    if (sExpires <= sIssued) {\n        return err('E_MALFORMED', 'subdelegation expires_at must be > issued_at');\n    }\n    if (sIssued < pIssued || sExpires > pExpires) {\n        return err(\n            'E_SUBDELEGATION_EXPIRES_EXTENDED',\n            `subdelegation window [${s.issued_at}, ${s.expires_at}) is not contained in parent's [${parent.issued_at}, ${parent.expires_at})`\n        );\n    }\n\n    // Step 3g: scope containment (transitive narrowing).\n    if (!parent.scopes) {\n        return err(\n            'E_SCOPES_NEITHER_PROVIDED',\n            'parent has no plaintext scopes — caller must hydrate v1.2 parents before invoking verifyChainLink'\n        );\n    }\n    const parentScopesParsed = parent.scopes.map((str) => parseScope(str));\n    for (let i = 0; i < parsedScopes.length; i++) {\n        const childScope = parsedScopes[i]!;\n        const containedBySomeParentScope = parentScopesParsed.some((p) => isSubScope(childScope, p));\n        if (!containedBySomeParentScope) {\n            return err(\n                'E_SUBDELEGATION_SCOPE_ESCALATED',\n                `subdelegation scope ${canonicalizeScope(childScope)} is not a sub-scope of any granted scope on the parent`\n            );\n        }\n    }\n\n    return {\n        ok: true,\n        envelope: s,\n        canonicalMessage: '', // not populated for chain links; computeSubdelegationId is the binding form\n        id: s.id,\n    };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Standalone subdelegation verification (no action context)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifySubdelegationInput extends VerifyBase {\n    envelope: SubdelegationEnvelope;\n    /**\n     * The immediate parent envelope. Required for linkage / containment checks.\n     * If the parent is itself v1.2 private-mode (`scopes_encrypted`) the caller\n     * MUST pre-hydrate it (e.g., via verifyDelegation's returned envelope) —\n     * the chain walker reads `parent.scopes` directly.\n     */\n    parent: ChainLink;\n    /** Skip the \"now ∈ [issued, expires)\" check. Useful for inspection. */\n    skipTemporalCheck?: boolean;\n    /** Defaults to new Date(). */\n    now?: Date;\n    /**\n     * v1.2 private-scope decryption key for the subdelegation envelope itself.\n     * Not used for the parent — the caller hydrates the parent.\n     */\n    decryptScopesWith?: {\n        device_id: string;\n        secretKey: Uint8Array;\n    };\n}\n\n/**\n * Verify a single sub-delegation envelope against its immediate parent.\n * Includes the standalone temporal-validity check (`now ∈ [issued, expires)`)\n * unless `skipTemporalCheck` is set. Useful for pre-flighting a chain link\n * outside of action verification.\n */\nexport async function verifySubdelegation(\n    input: VerifySubdelegationInput\n): Promise<VerifySubdelegationResult> {\n    // v1.2: hydrate private-mode envelopes before chain-link checks so\n    // the walker uniformly reads plaintext scopes.\n    const hydrated = await hydrateSubdelegationScopes(input.envelope, input);\n    if (!hydrated.ok) return hydrated;\n    const r = await verifyChainLink(hydrated.envelope, input.parent, input);\n    if (!r.ok) return r;\n\n    if (!input.skipTemporalCheck) {\n        const now = (input.now ?? new Date()).getTime();\n        const issued = new Date(input.envelope.issued_at).getTime();\n        const expires = new Date(input.envelope.expires_at).getTime();\n        if (now < issued) return err('E_NOT_YET_VALID', `subdelegation issued_at ${input.envelope.issued_at} is in the future`);\n        if (now >= expires) return err('E_EXPIRED', `subdelegation expires_at ${input.envelope.expires_at} is past`);\n    }\n\n    return r;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Time comparison for revocation vs action (SPEC §9.3)\n// ─────────────────────────────────────────────────────────────────────────────\n\ntype EffectiveTime =\n    | { kind: 'anchor'; blockHeight: number }\n    | { kind: 'signed'; ms: number };\n\nfunction actionEffectiveTime(\n    a: ActionEnvelope,\n    resolve?: (env: ActionEnvelope | RevocationEnvelope) => number | null\n): EffectiveTime {\n    if (a.ots?.status === 'confirmed') {\n        const h = resolve ? resolve(a) : a.ots.block_height;\n        if (h !== null && h !== undefined) return { kind: 'anchor', blockHeight: h };\n    }\n    return { kind: 'signed', ms: new Date(a.signed_at).getTime() };\n}\n\nfunction effectiveRevocationTime(\n    r: RevocationEnvelope,\n    resolve?: (env: ActionEnvelope | RevocationEnvelope) => number | null\n): EffectiveTime {\n    if (r.ots?.status === 'confirmed') {\n        const h = resolve ? resolve(r) : r.ots.block_height;\n        if (h !== null && h !== undefined) return { kind: 'anchor', blockHeight: h };\n    }\n    return { kind: 'signed', ms: new Date(r.signed_at).getTime() };\n}\n\n/** Returns <0 if a < b, 0 if equal, >0 if a > b. Anchored always beats signed-only. */\nfunction compareTimes(a: EffectiveTime, b: EffectiveTime): number {\n    if (a.kind === 'anchor' && b.kind === 'anchor') return a.blockHeight - b.blockHeight;\n    // If only one anchored, the anchored one is authoritative: an unanchored action cannot\n    // prove priority against an anchored revocation, so the anchored side is treated as \"earlier\".\n    if (a.kind === 'anchor') return -1;\n    if (b.kind === 'anchor') return 1;\n    return a.ms - b.ms;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n\nfunction err(code: AgentErrorCode, message: string): VerifyErrResult {\n    return { ok: false, code, message };\n}\n\ntype VerifyErrResult = { ok: false; code: AgentErrorCode; message: string };\n\nfunction isHex64(s: unknown): s is string {\n    return typeof s === 'string' && /^[0-9a-f]{64}$/.test(s);\n}\n\nfunction isIsoUtc(s: unknown): s is string {\n    return (\n        typeof s === 'string' &&\n        /^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}(\\.\\d+)?Z$/.test(s)\n    );\n}\n","// OC Agent v1.2 — Federation Principal (FEDERATION.md).\n//\n// ADDITIVE module. Implements the federation-principal extension WITHOUT\n// touching the v1 single-address path (types.ts DelegationEnvelope, verify.ts\n// verifyDelegation are unchanged + byte-identical against their vectors). A\n// dispatcher routes by `principal.alg` / `signer.alg`:\n//\n//   principal.alg === 'bip322'      → verifyDelegation   (v1, unchanged)\n//   principal.alg === 'federation'  → verifyFederationDelegation (this module)\n//\n// A federation principal is a content-addressed M-of-N guardian set. A\n// delegation / revocation under it is authentic iff M of N declared guardians\n// have BIP-322-signed the canonical message. The canonical-message + id rules\n// are unchanged — only the principal line (`federation:<descriptor_id>`) and the\n// signature block (`federation-bip322` with M-of-N) generalize. FEDERATION.md\n// §2 / §3 / §4.\n\nimport { sha256 } from '@noble/hashes/sha256';\n\nimport {\n    canonicalizeScopes,\n    computeDelegationId,\n    computeRevocationId,\n    delegationCanonicalMessage,\n    hexEncode,\n    revocationCanonicalMessage,\n} from './canonical.js';\nimport type { ActorRef, AgentErrorCode, DelegationBond, DelegationRevocationRef } from './types.js';\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Types (FEDERATION.md §2 / §3.2)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface FederationGuardian {\n    /** mainnet Bitcoin address (P2WPKH, P2TR, or P2PKH). */\n    address: string;\n    alg: 'bip322';\n    /** Optional human label. NOT part of the cryptographic identity. */\n    name?: string;\n}\n\nexport interface FederationDescriptor {\n    v: 1;\n    kind: 'agent-federation';\n    /** \"M-of-N\", 1 ≤ M ≤ N, N === guardians.length. */\n    threshold: string;\n    guardians: FederationGuardian[];\n}\n\nexport interface FederationPrincipal {\n    alg: 'federation';\n    descriptor_id: string;\n    descriptor: FederationDescriptor;\n}\n\nexport interface FederationSignature {\n    alg: 'federation-bip322';\n    threshold: string;\n    signatures: Array<{ guardian_address: string; value: string }>;\n}\n\nexport interface FederationDelegationEnvelope {\n    v: 1;\n    kind: 'agent-delegation';\n    id: string;\n    principal: FederationPrincipal;\n    agent: ActorRef;\n    scopes: string[];\n    bond: DelegationBond | null;\n    issued_at: string;\n    expires_at: string;\n    nonce: string;\n    revocation: DelegationRevocationRef;\n    sig: FederationSignature;\n}\n\nexport interface FederationRevocationEnvelope {\n    v: 1;\n    kind: 'agent-revocation';\n    id: string;\n    delegation_id: string;\n    /** Federation principal that authorizes the revocation (the guardian set). */\n    signer: FederationPrincipal;\n    reason: string;\n    signed_at: string;\n    ots?: unknown | null;\n    sig: FederationSignature;\n}\n\nexport type FederationVerifyResult =\n    | { ok: true; id: string; canonicalMessage: string }\n    | { ok: false; code: AgentErrorCode; message: string };\n\nexport interface VerifyFederationBase {\n    /** Injected BIP-322 verifier. Required unless `skipSignatureVerification`. */\n    verifyBip322?: (msg: string, signatureB64: string, address: string) => Promise<boolean>;\n    skipSignatureVerification?: boolean;\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Descriptor canonicalization (FEDERATION.md §2.1 / §2.2)\n// ─────────────────────────────────────────────────────────────────────────────\n\n/**\n * The canonical, line-oriented descriptor message. Guardians are emitted in\n * lexicographic byte order of their address (NOT the JSON array order); the\n * `name` label is excluded — it is JSON-only metadata. No trailing LF.\n */\nexport function federationDescriptorCanonicalMessage(descriptor: FederationDescriptor): string {\n    const addresses = descriptor.guardians\n        .map((g) => g.address)\n        .sort((a, b) => (a < b ? -1 : a > b ? 1 : 0));\n    return [\n        'oc-agent:federation:v1',\n        `threshold: ${descriptor.threshold}`,\n        ...addresses.map((a) => `guardian: ${a}`),\n    ].join('\\n');\n}\n\n/** descriptor_id := H(canonical_descriptor_bytes). 64 lowercase hex. */\nexport function computeFederationDescriptorId(descriptor: FederationDescriptor): string {\n    return hexEncode(sha256(new TextEncoder().encode(federationDescriptorCanonicalMessage(descriptor))));\n}\n\nfunction parseThreshold(t: unknown): { m: number; n: number } | null {\n    if (typeof t !== 'string') return null;\n    const m = /^(\\d+)-of-(\\d+)$/.exec(t);\n    if (!m) return null;\n    const mm = Number(m[1]);\n    const nn = Number(m[2]);\n    if (!Number.isInteger(mm) || !Number.isInteger(nn) || mm < 1 || mm > nn) return null;\n    return { m: mm, n: nn };\n}\n\nconst HEX64 = /^[0-9a-f]{64}$/;\nconst ISO_UTC = /^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}(\\.\\d+)?Z$/;\n\n/**\n * Shared descriptor + quorum validation (FEDERATION.md §3.3 checks 3–8 minus the\n * id check, plus BIP-322). `reconstructedId` is the already-computed envelope id.\n */\nasync function checkFederationQuorum(\n    principal: FederationPrincipal,\n    sig: FederationSignature,\n    reconstructedId: string,\n    input: VerifyFederationBase\n): Promise<{ ok: true } | { ok: false; code: AgentErrorCode; message: string }> {\n    // §3.3.2 — principal alg.\n    if (principal?.alg !== 'federation') {\n        return fail('E_MALFORMED', 'principal.alg must be \"federation\"');\n    }\n    const descriptor = principal.descriptor;\n    if (!descriptor || descriptor.kind !== 'agent-federation') {\n        return fail('E_MALFORMED', 'principal.descriptor missing or wrong kind');\n    }\n    const parsed = parseThreshold(descriptor.threshold);\n    if (!parsed) return fail('E_MALFORMED', `malformed threshold \"${descriptor.threshold}\"`);\n    if (!Array.isArray(descriptor.guardians) || descriptor.guardians.length !== parsed.n) {\n        return fail('E_MALFORMED', 'guardians length must equal N in M-of-N');\n    }\n\n    // §3.3.3 — descriptor_id matches the canonical hash of the inlined descriptor.\n    const computedDescId = computeFederationDescriptorId(descriptor);\n    if (principal.descriptor_id !== computedDescId) {\n        return fail(\n            'E_BAD_FEDERATION_DESCRIPTOR',\n            `declared descriptor_id (${principal.descriptor_id}) != canonical hash (${computedDescId})`\n        );\n    }\n\n    // §3.3.4 — sig.threshold equals descriptor.threshold.\n    if (sig?.alg !== 'federation-bip322') {\n        return fail('E_MALFORMED', 'sig.alg must be \"federation-bip322\"');\n    }\n    if (sig.threshold !== descriptor.threshold) {\n        return fail(\n            'E_THRESHOLD_MISMATCH',\n            `sig.threshold (${sig.threshold}) != descriptor.threshold (${descriptor.threshold})`\n        );\n    }\n\n    // §3.3.5 — at least M signatures.\n    const sigs = sig.signatures;\n    if (!Array.isArray(sigs)) return fail('E_MALFORMED', 'sig.signatures must be an array');\n    if (sigs.length < parsed.m) {\n        return fail(\n            'E_THRESHOLD_NOT_MET',\n            `${sigs.length} signature(s) below threshold M=${parsed.m}`\n        );\n    }\n\n    // §3.3.6 / §3.3.7 — every signer is a declared guardian; no duplicates.\n    const guardianSet = new Set(descriptor.guardians.map((g) => g.address));\n    const seen = new Set<string>();\n    for (const s of sigs) {\n        if (!guardianSet.has(s.guardian_address)) {\n            return fail('E_UNKNOWN_GUARDIAN', `${s.guardian_address} is not a declared guardian`);\n        }\n        if (seen.has(s.guardian_address)) {\n            return fail('E_DUPLICATE_GUARDIAN', `${s.guardian_address} signed more than once`);\n        }\n        seen.add(s.guardian_address);\n    }\n\n    // §3.3.8 — each signature verifies under BIP-322 over the hex-encoded id.\n    if (!input.skipSignatureVerification) {\n        if (!input.verifyBip322) return fail('E_BAD_SIG', 'no BIP-322 verifier supplied');\n        for (const s of sigs) {\n            const ok = await input.verifyBip322(reconstructedId, s.value, s.guardian_address);\n            if (!ok) {\n                return fail('E_BAD_SIG', `guardian ${s.guardian_address} signature did not verify`);\n            }\n        }\n    }\n    return { ok: true };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Delegation under a federation principal (FEDERATION.md §3)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyFederationDelegationInput extends VerifyFederationBase {\n    envelope: FederationDelegationEnvelope;\n    now?: Date;\n    skipTemporalCheck?: boolean;\n}\n\nexport async function verifyFederationDelegation(\n    input: VerifyFederationDelegationInput\n): Promise<FederationVerifyResult> {\n    const env = input.envelope;\n    if (env?.kind !== 'agent-delegation') return fail('E_MALFORMED', 'kind must be \"agent-delegation\"');\n    if (!HEX64.test(env.id ?? '')) return fail('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!env.agent?.address || env.agent.alg !== 'bip322') return fail('E_MALFORMED', 'agent invalid');\n    if (!Array.isArray(env.scopes) || env.scopes.length === 0) {\n        return fail('E_MALFORMED', 'scopes must be a non-empty array');\n    }\n    if (!ISO_UTC.test(env.issued_at) || !ISO_UTC.test(env.expires_at)) {\n        return fail('E_MALFORMED', 'issued_at / expires_at must be ISO 8601 UTC');\n    }\n    if (!/^[0-9a-f]{32}$/.test(env.nonce)) return fail('E_MALFORMED', 'nonce must be 32 hex chars');\n\n    // Canonical scopes (identical rules to v1) must be sorted on the envelope.\n    let canonicalScopes: string[];\n    try {\n        canonicalScopes = canonicalizeScopes(env.scopes);\n    } catch (e) {\n        return fail('E_BAD_SCOPE_GRAMMAR', (e as Error).message);\n    }\n    for (let i = 0; i < canonicalScopes.length; i++) {\n        if (env.scopes[i] !== canonicalScopes[i]) {\n            return fail('E_BAD_SCOPE_GRAMMAR', `scope index ${i} not in canonical order`);\n        }\n    }\n\n    // §3.3.1 / §3.1 — reconstruct the id with the `federation:<descriptor_id>`\n    // principal substitution. Everything else is the v1 canonical message.\n    const canonInput = {\n        principal: `federation:${env.principal?.descriptor_id ?? ''}`,\n        agent: env.agent.address,\n        scopes: canonicalScopes,\n        bond_sats: env.bond?.sats ?? 0,\n        bond_attestation: env.bond?.attestation_id ?? 'none',\n        issued_at: env.issued_at,\n        expires_at: env.expires_at,\n        nonce: env.nonce,\n    };\n    const reconstructedId = computeDelegationId(canonInput);\n    if (reconstructedId !== env.id) {\n        return fail('E_BAD_ID', `reconstructed id (${reconstructedId}) != envelope.id (${env.id})`);\n    }\n\n    const quorum = await checkFederationQuorum(env.principal, env.sig, env.id, input);\n    if (!quorum.ok) return quorum;\n\n    if (!input.skipTemporalCheck) {\n        const now = input.now ?? new Date();\n        const issued = new Date(env.issued_at);\n        const expires = new Date(env.expires_at);\n        if (expires <= issued) return fail('E_MALFORMED', 'expires_at <= issued_at');\n        if (now < issued) return fail('E_NOT_YET_VALID', `delegation not valid until ${env.issued_at}`);\n        if (now >= expires) return fail('E_EXPIRED', `delegation expired at ${env.expires_at}`);\n    }\n\n    return { ok: true, id: env.id, canonicalMessage: delegationCanonicalMessage(canonInput) };\n}\n\n// ─────────────────────────────────────────────────────────────────────────────\n// Revocation under a federation principal (FEDERATION.md §4)\n// ─────────────────────────────────────────────────────────────────────────────\n\nexport interface VerifyFederationRevocationInput extends VerifyFederationBase {\n    envelope: FederationRevocationEnvelope;\n}\n\nexport async function verifyFederationRevocation(\n    input: VerifyFederationRevocationInput\n): Promise<FederationVerifyResult> {\n    const env = input.envelope;\n    if (env?.kind !== 'agent-revocation') return fail('E_MALFORMED', 'kind must be \"agent-revocation\"');\n    if (!HEX64.test(env.id ?? '')) return fail('E_MALFORMED', 'id must be 64 lowercase hex chars');\n    if (!HEX64.test(env.delegation_id ?? '')) return fail('E_MALFORMED', 'delegation_id must be 64-hex');\n    if (typeof env.reason !== 'string' || env.reason.length > 128) {\n        return fail('E_MALFORMED', 'reason must be a string ≤128 bytes');\n    }\n    if (!ISO_UTC.test(env.signed_at)) return fail('E_MALFORMED', 'signed_at must be ISO 8601 UTC');\n\n    // §4 — the `address:` line carries the `federation:<descriptor_id>`\n    // substitution; everything else is the v1 revocation canonical message.\n    const canonInput = {\n        address: `federation:${env.signer?.descriptor_id ?? ''}`,\n        delegation_id: env.delegation_id,\n        reason: env.reason,\n        signed_at: env.signed_at,\n    };\n    const reconstructedId = computeRevocationId(canonInput);\n    if (reconstructedId !== env.id) {\n        return fail('E_BAD_ID', `reconstructed id (${reconstructedId}) != envelope.id (${env.id})`);\n    }\n\n    const quorum = await checkFederationQuorum(env.signer, env.sig, env.id, input);\n    if (!quorum.ok) return quorum;\n\n    return { ok: true, id: env.id, canonicalMessage: revocationCanonicalMessage(canonInput) };\n}\n\nfunction fail(code: AgentErrorCode, message: string): { ok: false; code: AgentErrorCode; message: string } {\n    return { ok: false, code, message };\n}\n"]}