import type { SandboxPolicy } from "../sandbox/launcher.js"; export type EvalPlatform = "darwin" | "linux" | "win32"; export interface EvalRunSpec { readonly runDir: string; readonly command: readonly [string, ...string[]]; readonly runtimeReadPaths?: readonly string[]; readonly piHomeSource?: string; } export interface ValidatedEvalRunSpec { readonly runDir: string; readonly command: readonly [string, ...string[]]; readonly runtimeReadPaths: readonly string[]; readonly piHomeSource?: string; } export interface ResolvedEvalExecutable { readonly commandPath: string; readonly command?: readonly [string, ...string[]]; readonly readPaths: readonly string[]; } export interface EvalSandboxConfigOptions { readonly platform: EvalPlatform; readonly runDir: string; readonly runtimeReadPaths: readonly string[]; readonly writableScratchPaths?: readonly string[]; readonly parentProxyUrl: string; } export interface EvalIsolatedPiHomePaths { readonly agentDir: string; readonly homeDir: string; readonly tmpDir: string; } export declare function evalIsolatedPiHomeWritablePaths(piHome: EvalIsolatedPiHomePaths): readonly string[]; export interface ValidatedPiInstallation { readonly packageRoot: string; } export declare function isTrustedPiInstallation(candidate: ValidatedPiInstallation | undefined, trusted: ValidatedPiInstallation | undefined): boolean; export declare const MAX_SHEBANG_READ_BYTES = 4096; export declare const MAX_SHEBANG_RESOLUTION_DEPTH = 16; export declare function isWithin(root: string, candidate: string): boolean; export declare function resolveEvalExecutable(executable: string, runDir: string, selectedPath: string): Promise; export declare function buildEvalExecutableReadPaths(resolved: ResolvedEvalExecutable, piInstallation?: ValidatedPiInstallation): string[]; export declare function findValidatedPiPackageRoot(executablePath: string, excludedRunDir?: string): Promise; export declare function isBroadRuntimePath(candidate: string, platform?: NodeJS.Platform): boolean; export declare function isSensitiveSystemExtensionParent(parent: string): boolean; export declare function isPioneerApplicationDataPath(candidate: string, platform?: NodeJS.Platform, environment?: NodeJS.ProcessEnv, home?: string): boolean; export declare function isPioneerStatePath(candidate: string, platform?: NodeJS.Platform, environment?: NodeJS.ProcessEnv, home?: string): boolean; export declare function isXdgConfigCredentialPath(candidate: string, platform?: NodeJS.Platform, environment?: NodeJS.ProcessEnv): boolean; export declare function isSensitiveCredentialPath(file: string): boolean; export declare function protectedExtensionParents(): Promise>; export declare function isBroadExtensionParent(candidate: string, platform?: NodeJS.Platform): boolean; export declare function isBroadWritablePath(candidate: string, platform?: NodeJS.Platform): boolean; export declare function pathsOverlap(first: string, second: string): boolean; export declare function assertPiHomeSeparatedFromActorGrants(piHomeSource: string, actorGrantPaths: readonly string[]): void; export declare function validateEvalWorkLogPath(workLogPath: string, actorGrantPaths: readonly string[]): Promise; export declare function assertEvalWorkLogNotActorVisible(workLogPath: string, actorGrantPaths: readonly string[]): Promise; export declare function validateEvalRunSpec(spec: EvalRunSpec): Promise; export declare function isPublicInternetAddress(address: string): boolean; export declare function buildEvalSandboxConfig(options: EvalSandboxConfigOptions): SandboxPolicy; //# sourceMappingURL=isolation.d.ts.map