export declare const SAFE_MODE_COMMANDS: readonly ["doctor", "audit", "plan", "receipt", "lkg", "recovery-plan", "recovery-verify"]; export type SafeModeCommand = typeof SAFE_MODE_COMMANDS[number]; export interface RecoveryContext { projectDir: string; commonDir: string; repository?: boolean; } export interface RecoveryApproval { schemaVersion: "recovery-approval/2.0"; kind: "semantic-human-approval"; id: string; targetKind: "file-apply" | "file-rollback" | "workspace" | "invalid"; targetId: string; planHash: string; action: RecoveryAction; packetHash: string; evidenceHash: string; contextDigest: string; approvedBy: string; approvedAt: string; expiresAt: string; approvalHash: string; } export interface FileApplyOperation { path: string; beforeHash: string | null; afterHash: string; } export interface FileApplyJournal { schemaVersion: "file-apply-journal/1.0"; kind: "file-apply-journal"; recoveryId: string; planHash: string; operations: FileApplyOperation[]; status: "started" | "failed-compensated" | "failed-uncompensated"; written: string[]; journalHash: string; } export interface FileRollbackJournal { schemaVersion: "file-rollback-journal/1.0"; kind: "file-rollback-journal"; recoveryId: string; planHash: string; appliedReceiptEventHash: string; operations: FileApplyOperation[]; status: "started"; restored: string[]; journalHash: string; } export interface RecoveryFinding { kind: "file-apply" | "file-rollback" | "workspace" | "invalid"; id: string; planHash?: string; action: RecoveryAction; packetHash: string; evidenceHash: string; quarantineSource?: { root: "project" | "common"; path: string; }; } export type RecoveryAction = "resume-apply" | "resume-rollback" | "quarantine-invalid-evidence"; export declare function safeModeAllows(command: string): command is SafeModeCommand; export declare function requireSafeModeCommand(command: string): void; declare const mutationLockBrand: unique symbol; export type MutationLock = Readonly<{ [mutationLockBrand]: true; }>; /** Only the actual in-process holder can authorize a lock-internal operation. Never infer reentrancy from a path. */ export declare function assertMutationLock(context: RecoveryContext, lock: MutationLock): void; /** This is the same lock path used by the worktree lifecycle. */ export declare function acquireMutationLock(context: RecoveryContext): MutationLock; /** Existing checkout migration may move the held directory, but cannot substitute a new lock. */ export declare function relocateMutationLock(lock: MutationLock, move: { from: string; to: string; context: RecoveryContext; }): MutationLock; export declare function releaseMutationLock(lock: MutationLock): void; /** The callback must await all its managed writers; an unresolved callback keeps the lock held. */ export declare function withMutationLock(context: RecoveryContext, operation: (lock: MutationLock) => T | Promise): Promise; export declare function createFileApplyJournal(input: Omit): FileApplyJournal; export declare function createFileRollbackJournal(input: Omit): FileRollbackJournal; export declare function validateFileApplyJournal(journal: FileApplyJournal): void; export declare function validateFileRollbackJournal(journal: FileRollbackJournal): void; export declare function fileApplyRecoveryPacketHash(journal: FileApplyJournal, context: RecoveryContext): string; export declare function createRecoveryApproval(args: { context: RecoveryContext; finding: RecoveryFinding; approvedBy: string; approvedAt: string; expiresAt: string; }): RecoveryApproval; export declare function recordRecoveryApproval(context: RecoveryContext, approval: RecoveryApproval): string; export declare function recoveryExecutionAllowed(context: RecoveryContext, approvalRef: string | undefined, finding: RecoveryFinding, now?: Date): RecoveryApproval; /** Moves one currently-invalid evidence object aside; it never deletes or rewrites it. */ export declare function quarantineInvalidEvidence(context: RecoveryContext, approvalRef: string | undefined, findingId: string, now?: Date): string; /** Inspect durable journals without trusting caller-supplied safe-mode booleans. */ export declare function inspectRecoveryState(context: RecoveryContext): RecoveryFinding[]; /** Every transaction Apply derives safe mode from durable state under the repository mutation lock. */ export declare function requireMutationAllowed(context: RecoveryContext, recovery?: { kind: "file-apply" | "file-rollback" | "workspace"; id: string; action: Exclude; approvalRef?: string; now?: Date; }): void; export {}; //# sourceMappingURL=service.d.ts.map