/** * autonomy/evidence-bundle.ts — Typed EvidenceBundle (Phase B.1, F-194). * * An `EvidenceBundle` is the typed observation that fills in an * `ObjectiveRun`. It captures the command that ran, the working * directory, the env digest, the exit code, the SHA-256 of the stdout * and stderr streams, the test counts and reports, the git revisions * before and after, the patch and lockfile hashes, the evaluator + * rubric SHA-256s, and the resource usage. * * The bundle is signed with `signBundle` and verified with * `verifyBundleSignature`. The signature is computed over the * canonicalized JSON of all non-signature fields so a third party can * replay it offline and confirm no field was tampered with after the * fact. * * Invariants: * - Every SHA-256 field is a 64-character lowercase hex string. * - `bundleId` is server-stamped via `randomUUID()`. * - `signature` is computed via `signBundle`; the signature input * is the JSON.stringify of the bundle with the signature field * stripped, re-parsed, and the keys sorted. * - `verifyBundleSignature` MUST return `true` for any bundle * produced by `signBundle` and `false` for any tampered bundle. */ /** * Schema version of `EvidenceBundle` (audit #84, P2 spec-sprawl reduction). * Bump on ANY breaking change to the schema (new required field, removed * field, or semantic change). Additive changes (new optional field) bump * the minor version. */ export declare const EVIDENCE_BUNDLE_SCHEMA_VERSION = "1.0.0"; /** Test-count summary embedded in an evidence bundle. */ export interface TestCounts { readonly total: number; readonly passed: number; readonly failed: number; readonly skipped: number; } /** Test report metadata for a single test framework invocation. */ export interface TestReport { /** Framework identifier (e.g. `node:test`, `vitest`). */ readonly framework: string; /** Suite name or path the report belongs to. */ readonly suite: string; /** SHA-256 of the full report file (hex). */ readonly reportSha256: string; /** Wall-clock duration of the run in milliseconds. */ readonly durationMs: number; } /** Resource-usage sample attached to an evidence bundle. */ export interface ResourceUsage { readonly wallClockMs: number; readonly peakMemoryMb: number; /** USD cost in micro-cents (1 USD = 1_000_000 uSD). */ readonly costUsdMicroCents: number; /** Token usage breakdown by role. */ readonly tokens: { readonly input: number; readonly output: number; readonly cached?: number; }; } /** The typed observation that fills in an `ObjectiveRun`. */ export interface EvidenceBundle { readonly bundleId: string; /** Run this bundle belongs to. */ readonly objectiveRunId: string; /** Optional parent run id if this bundle nests under another run. */ readonly runId?: string; /** Absolute path to the command run. */ readonly command: string; /** Working directory of the command. */ readonly cwd: string; /** SHA-256 of the canonicalized env vars present at run time. */ readonly envDigest: string; /** Exit code of the command (negative if killed by signal). */ readonly exitCode: number; /** SHA-256 of the captured stdout (hex). */ readonly stdoutSha256: string; /** SHA-256 of the captured stderr (hex). */ readonly stderrSha256: string; /** Aggregate test counts for the run. */ readonly testCounts: TestCounts; /** Per-framework test reports. */ readonly testReports: ReadonlyArray; /** Git revision at the start of the run. */ readonly baselineRevision: string; /** Git revision at the end of the run. */ readonly resultingRevision: string; /** SHA-256 of the patch produced by the run (hex). */ readonly patchSha256: string; /** SHA-256 of the lockfile at the end of the run (hex). */ readonly lockfileSha256: string; /** Version string of the evaluator that produced this bundle. */ readonly evaluatorVersion: string; /** SHA-256 of the evaluator binary or container image (hex). */ readonly evaluatorSha256: string; /** SHA-256 of the rubric that scored this run (hex). */ readonly rubricSha256: string; /** Resource usage sample. */ readonly resourceUsage: ResourceUsage; /** HMAC-SHA256 signature over the canonical JSON of all other fields. */ readonly signature: string; /** Server-stamped ISO 8601 timestamp. */ readonly createdAt: string; /** Schema version that produced this record (audit #84). */ readonly schemaVersion: string; } /** Length in characters of a SHA-256 hex digest. */ export declare const SHA256_HEX_LENGTH = 64; /** Assert a value is a 64-char lowercase hex SHA-256 string. */ export declare function assertSha256Hex(field: string, value: unknown): asserts value is string; /** Compute a deterministic signature payload from the bundle minus the signature field. */ export declare function canonicalize(bundle: Omit): string; /** Sign a bundle with the supplied secret and return the signed bundle. */ export declare function signBundle(bundle: Omit, secret: string): EvidenceBundle; /** Verify the signature on a bundle. Returns true iff the HMAC matches. */ export declare function verifyBundleSignature(bundle: EvidenceBundle, secret: string): boolean; /** SHA-256 a buffer or string and return the lowercase hex digest. */ export declare function sha256Hex(input: string | Buffer): string; /** Generate a new server-stamped `bundleId`. */ export declare function newBundleId(): string; /** Convenience constructor that fills in server-stamped ids + timestamp + signature. */ export declare function createEvidenceBundle(fields: Omit, secret: string): EvidenceBundle; //# sourceMappingURL=evidence-bundle.d.ts.map