import { z } from "zod"; import { type MutationLock } from "../recovery/service.js"; import { type SemanticApprovalPacket } from "./service.js"; import type { CoordinationClock } from "../coordination/clock.js"; import { type HumanScope, type HumanScopeBinding } from "./human_scope.js"; import { type ResourceState } from "./human_resources.js"; export { humanScopeSchema } from "./human_scope.js"; export type { HumanScope, HumanScopeBinding } from "./human_scope.js"; declare const approvalSchema: z.ZodObject<{ kind: z.ZodLiteral<"approved">; schemaVersion: z.ZodLiteral<"human-authorization/1.0">; packet: z.ZodType; scope: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"qualification-run">; runId: z.ZodEffects; refs: z.ZodArray, "many">; operations: z.ZodArray, "many">; maxCommits: z.ZodNumber; maxWriteAttempts: z.ZodNumber; maxCleanupAttempts: z.ZodNumber; cleanupExpiresAt: z.ZodString; takeoverAllocations: z.ZodOptional; workItem: z.ZodString; controlRef: z.ZodEffects; sourceRef: z.ZodEffects; genesisSha: z.ZodString; maxCommits: z.ZodNumber; maxWriteAttempts: z.ZodNumber; }, "strict", z.ZodTypeAny, { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }, { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }>, "many">>; localResources: z.ZodOptional, string, string>; commonDir: z.ZodEffects, string, string>; configHash: z.ZodString; hostBindingHash: z.ZodString; expiresAt: z.ZodString; cleanupExpiresAt: z.ZodString; maxConcurrent: z.ZodNumber; items: z.ZodArray; clientId: z.ZodString; path: z.ZodEffects, string, string>; branch: z.ZodEffects, string, string>; fixtureId: z.ZodEffects; sourceSha: z.ZodString; operations: z.ZodTuple<[z.ZodLiteral<"import-source">, z.ZodLiteral<"create-once">, z.ZodLiteral<"observe">, z.ZodLiteral<"close-exact">], null>; }, "strict", z.ZodTypeAny, { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }, { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }>, "many">; }, "strict", z.ZodTypeAny, { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; }, { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; }>>; synthetic: z.ZodOptional; objectFormat: z.ZodLiteral<"sha1">; kind: z.ZodEnum<["control-genesis", "source-fixture"]>; metadata: z.ZodObject<{ runId: z.ZodString; objectId: z.ZodString; seconds: z.ZodNumber; }, "strict", z.ZodTypeAny, { runId: string; objectId: string; seconds: number; }, { runId: string; objectId: string; seconds: number; }>; parents: z.ZodArray; treeSha: z.ZodString; commitText: z.ZodString; commitSha: z.ZodString; commitBytesSha256: z.ZodString; objectPlanHash: z.ZodString; }, "strict", z.ZodTypeAny, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }>, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }>, "many">; controls: z.ZodArray, "many">; publications: z.ZodArray; }, "strict", z.ZodTypeAny, { expected: string | null; transactionId: string; fixtureId: string; ref: string; }, { expected: string | null; transactionId: string; fixtureId: string; ref: string; }>, "many">; }, "strict", z.ZodTypeAny, { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }, { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }>, { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }, { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }>>; manifest: z.ZodOptional>; binding: z.ZodObject<{ commonDir: z.ZodEffects; repository: z.ZodString; repositoryId: z.ZodEffects; endpointHash: z.ZodString; credentialBindingHash: z.ZodString; credentialRef: z.ZodEffects; credentialPurpose: z.ZodLiteral<"git-transport">; actor: z.ZodEffects; hostId: z.ZodString; configHash: z.ZodString; controlEpoch: z.ZodObject<{ schemaVersion: z.ZodLiteral<"coordination-epoch/1">; protocol: z.ZodLiteral<"github-coordination/1.0">; mode: z.ZodEnum<["isolated-qualification", "production"]>; coordinationConfigDigest: z.ZodString; policy: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"none">; }, "strict", z.ZodTypeAny, { kind: "none"; }, { kind: "none"; }>, z.ZodObject<{ kind: z.ZodLiteral<"harness-policy-file">; sha256: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "harness-policy-file"; sha256: string; }, { kind: "harness-policy-file"; sha256: string; }>]>; }, "strict", z.ZodTypeAny, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }>; implementation: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"source">; head: z.ZodString; tree: z.ZodString; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "source"; head: string; tree: string; artifactDigest: string; }, { kind: "source"; head: string; tree: string; artifactDigest: string; }>, z.ZodObject<{ kind: z.ZodLiteral<"package">; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "package"; artifactDigest: string; }, { kind: "package"; artifactDigest: string; }>]>; runnerHash: z.ZodString; }, "strict", z.ZodTypeAny, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }>; expiresAt: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; synthetic?: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; } | undefined; manifest?: { clientId: string; manifestHash: string; } | undefined; }, { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; synthetic?: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; } | undefined; manifest?: { clientId: string; manifestHash: string; } | undefined; }>, z.ZodObject<{ kind: z.ZodLiteral<"production-enable">; configBeforeHash: z.ZodNullable; configAfterHash: z.ZodString; controlRef: z.ZodEffects; genesisSha: z.ZodString; genesisTree: z.ZodString; qualificationEvidenceHash: z.ZodString; maxBootstrapAttempts: z.ZodNumber; genesisObject: z.ZodOptional; objectFormat: z.ZodLiteral<"sha1">; kind: z.ZodEnum<["control-genesis", "source-fixture"]>; metadata: z.ZodObject<{ runId: z.ZodString; objectId: z.ZodString; seconds: z.ZodNumber; }, "strict", z.ZodTypeAny, { runId: string; objectId: string; seconds: number; }, { runId: string; objectId: string; seconds: number; }>; parents: z.ZodArray; treeSha: z.ZodString; commitText: z.ZodString; commitSha: z.ZodString; commitBytesSha256: z.ZodString; objectPlanHash: z.ZodString; }, "strict", z.ZodTypeAny, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }>, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }, { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }>>; binding: z.ZodObject<{ commonDir: z.ZodEffects; repository: z.ZodString; repositoryId: z.ZodEffects; endpointHash: z.ZodString; credentialBindingHash: z.ZodString; credentialRef: z.ZodEffects; credentialPurpose: z.ZodLiteral<"git-transport">; actor: z.ZodEffects; hostId: z.ZodString; configHash: z.ZodString; controlEpoch: z.ZodObject<{ schemaVersion: z.ZodLiteral<"coordination-epoch/1">; protocol: z.ZodLiteral<"github-coordination/1.0">; mode: z.ZodEnum<["isolated-qualification", "production"]>; coordinationConfigDigest: z.ZodString; policy: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"none">; }, "strict", z.ZodTypeAny, { kind: "none"; }, { kind: "none"; }>, z.ZodObject<{ kind: z.ZodLiteral<"harness-policy-file">; sha256: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "harness-policy-file"; sha256: string; }, { kind: "harness-policy-file"; sha256: string; }>]>; }, "strict", z.ZodTypeAny, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }>; implementation: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"source">; head: z.ZodString; tree: z.ZodString; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "source"; head: string; tree: string; artifactDigest: string; }, { kind: "source"; head: string; tree: string; artifactDigest: string; }>, z.ZodObject<{ kind: z.ZodLiteral<"package">; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "package"; artifactDigest: string; }, { kind: "package"; artifactDigest: string; }>]>; runnerHash: z.ZodString; }, "strict", z.ZodTypeAny, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }>; expiresAt: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "production-enable"; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; controlRef: string; genesisSha: string; configBeforeHash: string | null; configAfterHash: string; genesisTree: string; qualificationEvidenceHash: string; maxBootstrapAttempts: number; genesisObject?: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; } | undefined; }, { kind: "production-enable"; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; controlRef: string; genesisSha: string; configBeforeHash: string | null; configAfterHash: string; genesisTree: string; qualificationEvidenceHash: string; maxBootstrapAttempts: number; genesisObject?: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; } | undefined; }>, z.ZodObject<{ kind: z.ZodLiteral<"takeover">; workItem: z.ZodString; controlRef: z.ZodEffects; expectedControlSha: z.ZodString; expected: z.ZodObject<{ recordHash: z.ZodString; generation: z.ZodNumber; owner: z.ZodEffects; machine: z.ZodEffects; lastObservedHead: z.ZodString; controlEpochDigest: z.ZodString; }, "strict", z.ZodTypeAny, { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }, { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }>; targetOwner: z.ZodEffects; targetHostId: z.ZodString; newEpochDigest: z.ZodString; targetWorkspace: z.ZodEffects; targetBranch: z.ZodEffects, string, string>; targetHead: z.ZodString; sourceRepositoryId: z.ZodEffects; newLease: z.ZodObject<{ ttlMs: z.ZodNumber; notAfter: z.ZodString; }, "strict", z.ZodTypeAny, { ttlMs: number; notAfter: string; }, { ttlMs: number; notAfter: string; }>; assetRisk: z.ZodObject<{ schemaVersion: z.ZodLiteral<"takeover-risk/1">; target: z.ZodObject<{ workspace: z.ZodEffects; commonDir: z.ZodEffects; actor: z.ZodEffects; hostId: z.ZodString; branch: z.ZodEffects, string, string>; head: z.ZodString; assets: z.ZodObject<{ indexHash: z.ZodString; entries: z.ZodArray; category: z.ZodEnum<["tracked", "untracked", "ignored"]>; status: z.ZodString; kind: z.ZodEnum<["file", "symlink", "missing"]>; mode: z.ZodNumber; size: z.ZodNumber; sha256: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }, { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }>, "many">; }, "strict", z.ZodTypeAny, { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }, { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }>; handling: z.ZodLiteral<"retain-all-assets">; uniqueCommits: z.ZodNumber; unpushedCommits: z.ZodNumber; remoteOnlyCommits: z.ZodNumber; }, "strict", z.ZodTypeAny, { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }, { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }>; remote: z.ZodObject<{ repositoryId: z.ZodEffects; endpointHash: z.ZodString; ref: z.ZodString; head: z.ZodString; }, "strict", z.ZodTypeAny, { endpointHash: string; head: string; repositoryId: string; ref: string; }, { endpointHash: string; head: string; repositoryId: string; ref: string; }>; source: z.ZodObject<{ kind: z.ZodLiteral<"not-observed">; reason: z.ZodLiteral<"source-machine-not-accessed">; historicalProofHash: z.ZodOptional; }, "strict", z.ZodTypeAny, { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }, { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }>; risks: z.ZodTuple<[z.ZodLiteral<"source-assets-unknown">, z.ZodLiteral<"external-writers-not-fenced">, z.ZodLiteral<"old-assets-retained">, z.ZodLiteral<"not-zero-loss-transfer">], null>; }, "strict", z.ZodTypeAny, { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }, { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }>; assetRiskHash: z.ZodString; transactionId: z.ZodEffects; maxCommits: z.ZodNumber; maxWriteAttempts: z.ZodNumber; qualification: z.ZodOptional; allocationId: z.ZodEffects; genesisSha: z.ZodString; }, "strict", z.ZodTypeAny, { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; }, { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; }>>; binding: z.ZodObject<{ commonDir: z.ZodEffects; repository: z.ZodString; repositoryId: z.ZodEffects; endpointHash: z.ZodString; credentialBindingHash: z.ZodString; credentialRef: z.ZodEffects; credentialPurpose: z.ZodLiteral<"git-transport">; actor: z.ZodEffects; hostId: z.ZodString; configHash: z.ZodString; controlEpoch: z.ZodObject<{ schemaVersion: z.ZodLiteral<"coordination-epoch/1">; protocol: z.ZodLiteral<"github-coordination/1.0">; mode: z.ZodEnum<["isolated-qualification", "production"]>; coordinationConfigDigest: z.ZodString; policy: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"none">; }, "strict", z.ZodTypeAny, { kind: "none"; }, { kind: "none"; }>, z.ZodObject<{ kind: z.ZodLiteral<"harness-policy-file">; sha256: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "harness-policy-file"; sha256: string; }, { kind: "harness-policy-file"; sha256: string; }>]>; }, "strict", z.ZodTypeAny, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }, { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }>; implementation: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"source">; head: z.ZodString; tree: z.ZodString; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "source"; head: string; tree: string; artifactDigest: string; }, { kind: "source"; head: string; tree: string; artifactDigest: string; }>, z.ZodObject<{ kind: z.ZodLiteral<"package">; artifactDigest: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "package"; artifactDigest: string; }, { kind: "package"; artifactDigest: string; }>]>; runnerHash: z.ZodString; }, "strict", z.ZodTypeAny, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }, { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }>; expiresAt: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "takeover"; expected: { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }; transactionId: string; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; sourceRepositoryId: string; targetHead: string; workItem: string; controlRef: string; expectedControlSha: string; maxCommits: number; maxWriteAttempts: number; targetOwner: string; targetHostId: string; newEpochDigest: string; targetWorkspace: string; targetBranch: string; newLease: { ttlMs: number; notAfter: string; }; assetRisk: { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }; assetRiskHash: string; qualification?: { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; } | undefined; }, { kind: "takeover"; expected: { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }; transactionId: string; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; sourceRepositoryId: string; targetHead: string; workItem: string; controlRef: string; expectedControlSha: string; maxCommits: number; maxWriteAttempts: number; targetOwner: string; targetHostId: string; newEpochDigest: string; targetWorkspace: string; targetBranch: string; newLease: { ttlMs: number; notAfter: string; }; assetRisk: { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }; assetRiskHash: string; qualification?: { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; } | undefined; }>]>; scopeHash: z.ZodString; approvedBy: z.ZodEffects; approvedAt: z.ZodString; source: z.ZodObject<{ kind: z.ZodLiteral<"explicit-human">; messageHash: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "explicit-human"; messageHash: string; }, { kind: "explicit-human"; messageHash: string; }>; }, "strict", z.ZodTypeAny, { schemaVersion: "human-authorization/1.0"; kind: "approved"; approvedBy: string; approvedAt: string; scope: { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; synthetic?: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; } | undefined; manifest?: { clientId: string; manifestHash: string; } | undefined; } | { kind: "production-enable"; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; controlRef: string; genesisSha: string; configBeforeHash: string | null; configAfterHash: string; genesisTree: string; qualificationEvidenceHash: string; maxBootstrapAttempts: number; genesisObject?: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; } | undefined; } | { kind: "takeover"; expected: { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }; transactionId: string; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; sourceRepositoryId: string; targetHead: string; workItem: string; controlRef: string; expectedControlSha: string; maxCommits: number; maxWriteAttempts: number; targetOwner: string; targetHostId: string; newEpochDigest: string; targetWorkspace: string; targetBranch: string; newLease: { ttlMs: number; notAfter: string; }; assetRisk: { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }; assetRiskHash: string; qualification?: { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; } | undefined; }; source: { kind: "explicit-human"; messageHash: string; }; packet: SemanticApprovalPacket; scopeHash: string; }, { schemaVersion: "human-authorization/1.0"; kind: "approved"; approvedBy: string; approvedAt: string; scope: { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; synthetic?: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; } | undefined; manifest?: { clientId: string; manifestHash: string; } | undefined; } | { kind: "production-enable"; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; controlRef: string; genesisSha: string; configBeforeHash: string | null; configAfterHash: string; genesisTree: string; qualificationEvidenceHash: string; maxBootstrapAttempts: number; genesisObject?: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; } | undefined; } | { kind: "takeover"; expected: { owner: string; recordHash: string; machine: string; generation: number; controlEpochDigest: string; lastObservedHead: string; }; transactionId: string; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; sourceRepositoryId: string; targetHead: string; workItem: string; controlRef: string; expectedControlSha: string; maxCommits: number; maxWriteAttempts: number; targetOwner: string; targetHostId: string; newEpochDigest: string; targetWorkspace: string; targetBranch: string; newLease: { ttlMs: number; notAfter: string; }; assetRisk: { schemaVersion: "takeover-risk/1"; target: { workspace: string; commonDir: string; uniqueCommits: number; unpushedCommits: number; hostId: string; head: string; branch: string; actor: string; assets: { entries: { kind: "file" | "symlink" | "missing"; sha256: string; path: string; status: string; category: "untracked" | "ignored" | "tracked"; mode: number; size: number; }[]; indexHash: string; }; handling: "retain-all-assets"; remoteOnlyCommits: number; }; source: { kind: "not-observed"; reason: "source-machine-not-accessed"; historicalProofHash?: string | undefined; }; remote: { endpointHash: string; head: string; repositoryId: string; ref: string; }; risks: ["source-assets-unknown", "external-writers-not-fenced", "old-assets-retained", "not-zero-loss-transfer"]; }; assetRiskHash: string; qualification?: { runId: string; allocationId: string; genesisSha: string; parentApprovalRef: string; } | undefined; }; source: { kind: "explicit-human"; messageHash: string; }; packet: SemanticApprovalPacket; scopeHash: string; }>; declare const attemptSchema: z.ZodObject<{ attemptId: z.ZodString; transactionId: z.ZodEffects; operation: z.ZodEnum<["create", "cas", "cleanup"]>; candidateId: z.ZodNullable; ref: z.ZodEffects; head: z.ZodNullable; expected: z.ZodNullable; reservedAt: z.ZodString; cleanupEvidenceHash: z.ZodOptional; cleanupManifest: z.ZodOptional>; }, "strict", z.ZodTypeAny, { expected: string | null; transactionId: string; head: string | null; reservedAt: string; ref: string; operation: "create" | "cas" | "cleanup"; attemptId: string; candidateId: string | null; cleanupEvidenceHash?: string | undefined; cleanupManifest?: { clientId: string; manifestHash: string; } | undefined; }, { expected: string | null; transactionId: string; head: string | null; reservedAt: string; ref: string; operation: "create" | "cas" | "cleanup"; attemptId: string; candidateId: string | null; cleanupEvidenceHash?: string | undefined; cleanupManifest?: { clientId: string; manifestHash: string; } | undefined; }>; declare const candidateSchema: z.ZodObject<{ candidateId: z.ZodString; transactionId: z.ZodEffects; parentSha: z.ZodNullable; treeSha: z.ZodString; subject: z.ZodDiscriminatedUnion<"kind", [z.ZodObject<{ kind: z.ZodLiteral<"coordination-record">; workItem: z.ZodString; recordHash: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "coordination-record"; recordHash: string; workItem: string; }, { kind: "coordination-record"; recordHash: string; workItem: string; }>, z.ZodObject<{ kind: z.ZodLiteral<"control-genesis">; objectPlanHash: z.ZodString; fixtureId: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "control-genesis"; objectPlanHash: string; fixtureId: string; }, { kind: "control-genesis"; objectPlanHash: string; fixtureId: string; }>, z.ZodObject<{ kind: z.ZodLiteral<"source-fixture">; objectPlanHash: z.ZodString; fixtureId: z.ZodString; }, "strict", z.ZodTypeAny, { kind: "source-fixture"; objectPlanHash: string; fixtureId: string; }, { kind: "source-fixture"; objectPlanHash: string; fixtureId: string; }>]>; commitMetadataHash: z.ZodString; objectDirectory: z.ZodEffects; reservedAt: z.ZodString; }, "strict", z.ZodTypeAny, { transactionId: string; reservedAt: string; treeSha: string; objectDirectory: string; candidateId: string; parentSha: string | null; subject: { kind: "coordination-record"; recordHash: string; workItem: string; } | { kind: "control-genesis"; objectPlanHash: string; fixtureId: string; } | { kind: "source-fixture"; objectPlanHash: string; fixtureId: string; }; commitMetadataHash: string; }, { transactionId: string; reservedAt: string; treeSha: string; objectDirectory: string; candidateId: string; parentSha: string | null; subject: { kind: "coordination-record"; recordHash: string; workItem: string; } | { kind: "control-genesis"; objectPlanHash: string; fixtureId: string; } | { kind: "source-fixture"; objectPlanHash: string; fixtureId: string; }; commitMetadataHash: string; }>; declare const candidateResultSchema: z.ZodObject<{ candidateId: z.ZodString; status: z.ZodEnum<["created", "failed", "unknown"]>; head: z.ZodNullable; evidenceHash: z.ZodString; }, "strict", z.ZodTypeAny, { status: "unknown" | "failed" | "created"; evidenceHash: string; head: string | null; candidateId: string; }, { status: "unknown" | "failed" | "created"; evidenceHash: string; head: string | null; candidateId: string; }>; declare const outcomeSchema: z.ZodObject<{ attemptId: z.ZodString; status: z.ZodEnum<["applied", "rejected", "unknown"]>; evidenceHash: z.ZodString; push: z.ZodOptional; stdout: z.ZodString; error: z.ZodNullable; }, "strict", z.ZodTypeAny, { error: string | null; status: number | null; stdout: string; }, { error: string | null; status: number | null; stdout: string; }>>; }, "strict", z.ZodTypeAny, { status: "unknown" | "applied" | "rejected"; evidenceHash: string; attemptId: string; push?: { error: string | null; status: number | null; stdout: string; } | undefined; }, { status: "unknown" | "applied" | "rejected"; evidenceHash: string; attemptId: string; push?: { error: string | null; status: number | null; stdout: string; } | undefined; }>; type Approval = z.infer; type Attempt = z.infer; type Outcome = z.infer; type Candidate = z.infer; type CandidateResult = z.infer; export interface HumanAuthorization { approval: Approval; attempts: Array; candidates: Array; revoked: boolean; writesClosed: boolean; resourcesReservedAt?: string; resourceStates?: Record; } /** State checks only; expiry, binding and the actual write lock remain mandatory at their owning boundaries. */ export declare function assertHumanWritesOpen(commonDir: string, state: HumanAuthorization): void; /** Read-only: an unindexed durable tail reports recovery, never silently grants or loses a write attempt. */ export declare function loadHumanAuthorization(commonDir: string, approvalRef: string): HumanAuthorization; /** Complete read-only family; never lose a durable child because its LKG append was interrupted. */ export declare function loadHumanAuthorizationFamily(commonDir: string, approvalRef: string): { parent: HumanAuthorization; children: { approvalRef: string; state: HumanAuthorization; }[]; }; /** Invoked by the explicit approval command; a Reviewer verdict or caller-created JSON is not an approvalRef. */ export declare function recordHumanApproval(commonDir: string, input: Omit, approvedPlanHash: string, clock?: CoordinationClock): string; export declare function assertHumanCandidateScope(scope: HumanScope, intent: Pick): void; /** Must precede commit-tree, including candidates that lose a CAS or never get dispatched. */ export declare function reserveCandidateQuota(commonDir: string, approvalRef: string, observed: HumanScopeBinding, intent: Omit, clock: CoordinationClock): Candidate; export declare function reserveCandidateQuotaLocked(lock: MutationLock, commonDir: string, approvalRef: string, observed: HumanScopeBinding, intent: Omit, clock: CoordinationClock): Candidate; export declare function recordCandidateResult(commonDir: string, approvalRef: string, input: CandidateResult): void; export declare function recordCandidateResultLocked(lock: MutationLock, commonDir: string, approvalRef: string, input: CandidateResult): void; /** Budget registration only, not dispatch authority. Native guards still bind each actual write; crashes never refund reservations. */ export declare function reserveWriteAttempt(commonDir: string, approvalRef: string, observed: HumanScopeBinding, request: Omit & { attemptId?: string; candidateId?: string | null; }, clock: CoordinationClock): Attempt; export declare function reserveWriteAttemptLocked(lock: MutationLock, commonDir: string, approvalRef: string, observed: HumanScopeBinding, request: Omit & { attemptId?: string; candidateId?: string | null; }, clock: CoordinationClock): Attempt; /** Evidence comes from the fixed operation/readback path; CLI never accepts a caller's Applied boolean. */ export declare function recordWriteOutcome(commonDir: string, approvalRef: string, input: Outcome): void; export declare function recordWriteOutcomeLocked(lock: MutationLock, commonDir: string, approvalRef: string, input: Outcome): void; export declare function revokeHumanAuthorization(commonDir: string, approvalRef: string, reason: string): void; /** Permanent ordinary-write closure, not revocation or a claim that unknown work has drained. */ export declare function closeQualificationWrites(commonDir: string, approvalRef: string): HumanAuthorization; export declare function closeQualificationWritesLocked(lock: MutationLock, commonDir: string, approvalRef: string): HumanAuthorization; /** Read-only projection of the original human chain; no Delivery lease or second resource ledger. */ export declare function qualificationResourceReservations(commonDir: string): { approvalRef: string; reservedAt: string; phase: "reserved" | "mkdir-owned" | "add-started" | "ready" | "released"; status: "reserved" | "mkdir-owned" | "add-started" | "ready" | "released" | "retained"; authorityRoot: string; path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; /** Accounting only. Native workspace admission checks capacity/path policy before calling under the same lock. */ export declare function reserveQualificationResourcesLocked(lock: MutationLock, commonDir: string, approvalRef: string, observed: HumanScopeBinding, clock: CoordinationClock): void; /** The sole durable resource-event boundary. Recorded facts still require native re-observation before mutation. */ export declare function recordQualificationResourceLocked(lock: MutationLock, commonDir: string, approvalRef: string, resourceId: string, input: unknown, observed: HumanScopeBinding, clock: CoordinationClock): void; //# sourceMappingURL=human.d.ts.map