export declare function readQualificationInput(path: string): unknown; /** Rebuild from native, non-secret observations; a claimed binding is never its own evidence. */ declare function preparePlan(projectRoot: string, input: unknown): { planHash: string; packets: { clientId: string; packet: import("../approval/service.js").SemanticApprovalPacket; }[]; schemaVersion: "qualification-cli-plan/1"; managementCommonDir: string; manifest: { schemaVersion: "qualification-run-manifest/1"; expiresAt: string; repository: string; endpointHash: string; repositoryId: string; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; synthetic: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }; manifestHash: string; requiredCases: ("dg01-identity-scope" | "dg01-cas" | "dg01-acquire-contention" | "dg01-objects-history" | "dg01-time-renew" | "dg01-late-renew" | "dg01-recovery" | "dg01-handoff" | "dg01-drain" | "dg01-terminal" | "dg01-cli-gates" | "dg01-human-budget")[]; clients: { scope: { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; synthetic: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; }; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; }; clientId: string; }[]; cleanupClientId: string; sameShaPublicationNegativeControl?: { expected: string | null; fixtureId: string; ref: string; publications: { transactionId: string; clientId: string; }[]; caseId: "dg01-cas"; } | undefined; acquireContention?: { controlRef: string; caseId: "dg01-acquire-contention"; contenders: { transactionId: string; clientId: string; }[]; } | undefined; execution?: { kind: "local-synthetic-publication/1"; steps: { transactionId: string; fixtureId: string; operation: "bootstrap" | "publish-source"; clientId: string; stepId: string; }[]; resourceStep?: { clientId: string; stepId: string; } | undefined; } | { kind: "local-acquire-contention/1"; steps: { transactionId: string; fixtureId: string; operation: "bootstrap" | "publish-source"; clientId: string; stepId: string; }[]; resourceStep?: { clientId: string; stepId: string; } | undefined; } | { kind: "local-same-sha-publication/1"; } | undefined; }; targets: { clientId: string; projectRoot: string; scope: { kind: "qualification-run"; operations: ("create" | "cas")[]; expiresAt: string; binding: { repository: string; endpointHash: string; commonDir: string; hostId: string; credentialBindingHash: string; repositoryId: string; credentialRef: string; credentialPurpose: "git-transport"; actor: string; configHash: string; controlEpoch: { schemaVersion: "coordination-epoch/1"; mode: "isolated-qualification" | "production"; protocol: "github-coordination/1.0"; coordinationConfigDigest: string; policy: { kind: "none"; } | { kind: "harness-policy-file"; sha256: string; }; }; implementation: { kind: "source"; head: string; tree: string; artifactDigest: string; } | { kind: "package"; artifactDigest: string; }; runnerHash: string; }; runId: string; maxCommits: number; maxWriteAttempts: number; cleanupExpiresAt: string; refs: string[]; maxCleanupAttempts: number; takeoverAllocations?: { sourceRef: string; workItem: string; controlRef: string; allocationId: string; genesisSha: string; maxCommits: number; maxWriteAttempts: number; }[] | undefined; localResources?: { expiresAt: string; commonDir: string; configHash: string; authorityRoot: string; hostBindingHash: string; cleanupExpiresAt: string; maxConcurrent: number; items: { path: string; operations: ["import-source", "create-once", "observe", "close-exact"]; branch: string; fixtureId: string; resourceId: string; clientId: string; sourceSha: string; }[]; } | undefined; synthetic?: { objects: { schemaVersion: "synthetic-object/1"; kind: "control-genesis" | "source-fixture"; objectPlanHash: string; objectFormat: "sha1"; metadata: { runId: string; objectId: string; seconds: number; }; parents: string[]; treeSha: string; commitText: string; commitSha: string; commitBytesSha256: string; }[]; controls: { fixtureId: string; ref: string; }[]; publications: { expected: string | null; transactionId: string; fixtureId: string; ref: string; }[]; } | undefined; manifest?: { clientId: string; manifestHash: string; } | undefined; }; }[]; }; export type QualificationCliPlan = ReturnType; export declare function planQualificationCommand(projectRoot: string, input: unknown): { planPath: string; planHash: string; secretsRead: boolean; remoteWrites: number; approved: boolean; productionEnabled: boolean; summary: { repository: string; repositoryId: string; refs: string[]; execution: "local-synthetic-publication/1" | "local-acquire-contention/1" | "local-same-sha-publication/1"; steps: { transactionId: string; fixtureId: string; operation: "bootstrap" | "publish-source"; clientId: string; stepId: string; }[]; cleanupClientId: string; clients: { clientId: string; maxCommits: number; maxWriteAttempts: number; maxCleanupAttempts: number; expiresAt: string; cleanupExpiresAt: string; }[]; maxCommits: number; maxWriteAttempts: number; maxCleanupAttempts: number; expiresAt: string; cleanupExpiresAt: string; content: string; }; }; export declare function loadQualificationCliPlan(projectRoot: string, path: string): QualificationCliPlan; /** Only the explicit CLI invocation registers authority. This saved confirmation is an idempotent audit input, never a run ticket. */ export declare function approveQualificationCommand(plan: QualificationCliPlan, approvedHash: string, approvedBy: string, approvalSource: string): { executionStatus: "completed"; planHash: string; registered: { clientId: string; approvalRef: string; }[]; pending: never[]; productionEnabled: boolean; error?: undefined; recovery?: undefined; } | { executionStatus: "partial"; planHash: string; registered: { clientId: string; approvalRef: string; }[]; pending: string[]; error: string; recovery: string; productionEnabled?: undefined; }; export {}; //# sourceMappingURL=qualification_plan.d.ts.map