export declare const HOST_PROFILE_SCHEMA = "agent-knock-knock/host-profile"; export declare const HOST_PROFILE_VERSION: 1; export declare const HOST_PROFILE_JSON_SCHEMA: string; export declare const HOST_PROFILE_BUILTIN_ID_PREFIX = "builtin-"; export declare const HOST_PROFILE_MAX_FILE_BYTES: number; export declare const HOST_PROFILE_MAX_TIMEOUT_MS = 30000; export declare const HOST_PROFILE_MAX_OUTPUT_BYTES: number; export declare const HOST_PROFILE_PRIVATE_ENVIRONMENT_VARIABLES: readonly ["AKK_HOST_PROFILE_SELECTION", "AKK_HOST_PROFILE_SOURCE", "AKK_HOST_PROFILE_FINGERPRINT", "AKK_HOST_PROFILE_HOST", "AKK_HOST_PROFILE_HOST_VERSION"]; export declare const HOST_PROFILE_PLACEHOLDERS: readonly ["controller.session_id", "envelope.delivery_id", "envelope.idempotency_key", "envelope.message_id", "envelope.body"]; export type HostProfilePlaceholder = (typeof HOST_PROFILE_PLACEHOLDERS)[number]; export type HostProfileAcknowledgementDispositionV1 = "accepted" | "retryable_failure" | "permanent_failure" | "uncertain"; export type HostProfileControllerScopeV1 = "startup_v1" | "route_bound_v1"; export interface HostProfileCompatibilityV1 { readonly host: string; readonly range: string; } export interface HostProfileEnvironmentControllerContextV1 { readonly driver: "environment_v1"; readonly sessionIdVariable: string; /** * Omitted is the original v1 behavior and is equivalent to startup_v1. * Keeping it omitted in the parsed model preserves existing fingerprints. */ readonly scope?: HostProfileControllerScopeV1; } export interface HostProfileCallbackEnvironmentV1 { readonly allow: readonly string[]; } export interface HostProfileJsonPointerV1 { readonly jsonPointer: string; } export interface HostProfileDispositionAcknowledgementV1 { readonly jsonPointer: string; readonly mapping: Readonly>; } export interface HostProfileAcknowledgementV1 { readonly disposition: HostProfileDispositionAcknowledgementV1; readonly acceptanceId: HostProfileJsonPointerV1; readonly acknowledgedDeliveryId: HostProfileJsonPointerV1; readonly acknowledgedMessageId: HostProfileJsonPointerV1; } export interface HostProfileCommandJsonCallbackV1 { readonly driver: "command_json_v1"; readonly executable: string; readonly arguments: readonly string[]; readonly stdin: "${envelope.body}"; readonly environment: HostProfileCallbackEnvironmentV1; readonly timeoutMs: number; readonly maxOutputBytes: number; readonly acknowledgement: HostProfileAcknowledgementV1; } export interface HostProfileV1 { readonly $schema: typeof HOST_PROFILE_JSON_SCHEMA; readonly schema: typeof HOST_PROFILE_SCHEMA; readonly version: typeof HOST_PROFILE_VERSION; readonly id: string; readonly revision: string; readonly compatibility: HostProfileCompatibilityV1; readonly controllerContext: HostProfileEnvironmentControllerContextV1; readonly callback: HostProfileCommandJsonCallbackV1; } export interface ParseHostProfileOptions { /** Built-ins alone may use the reserved built-in id namespace. */ source?: "user" | "built_in"; /** Exact ids already owned by a built-in registry. */ reservedIds?: Iterable; } export interface LoadedHostProfileV1 { readonly source: "file"; readonly path: string; readonly fingerprint: string; readonly profile: HostProfileV1; } export interface HostProfileRegistryEntryV1 { readonly source: "built_in"; readonly id: string; readonly revision: string; readonly fingerprint: string; readonly compatibility: HostProfileCompatibilityV1; } export interface HostProfileRegistry { list(): readonly HostProfileRegistryEntryV1[]; resolve(id: string): HostProfileV1 | undefined; isReserved(id: string): boolean; } export interface LoadHostProfileOptions { cwd?: string; registry?: HostProfileRegistry; } export interface ResolvedHostProfileControllerContextV1 { readonly driver: "environment_v1"; readonly variable: string; readonly controllerSessionId: string; } export interface HostProfileCompatibilityInputV1 { readonly host: string; readonly version: string; } /** * Parse one untrusted Profile document into a deeply immutable v1 model. * * Runtime validation is deliberately implemented here instead of delegated to * a JSON Schema package. The published schema is documentation and tooling; * this parser remains the fail-closed authority used by AKK. */ export declare function parseHostProfileV1(value: unknown, options?: ParseHostProfileOptions): HostProfileV1; /** Verify the configured callback path and its symlink target at Host startup. */ export declare function assertHostProfileCallbackExecutableReady(executable: string, environmentVariables?: readonly string[]): void; export declare function hostProfileFingerprint(profile: HostProfileV1): string; /** Create the immutable built-in Profile lookup used by later Bridge wiring. */ export declare function createHostProfileRegistry(builtInProfiles?: readonly unknown[]): HostProfileRegistry; /** Load one explicit JSON file; no search path or implicit Profile selection. */ export declare function loadHostProfileV1(profilePath: string, options?: LoadHostProfileOptions): LoadedHostProfileV1; /** Resolve trusted controller identity only from the Host-supplied environment. */ export declare function resolveHostProfileControllerContext(profile: HostProfileV1, environment: Readonly>): ResolvedHostProfileControllerContextV1; /** Return whether one exact Host identity satisfies the Profile's AND range. */ export declare function hostProfileSupportsHostVersion(profile: HostProfileV1, input: HostProfileCompatibilityInputV1): boolean; /** Assert compatibility before a Bridge is allowed to use a Profile. */ export declare function assertHostProfileCompatibility(profile: HostProfileV1, input: HostProfileCompatibilityInputV1): void; /** Normalize the optional scope without changing legacy Profile fingerprints. */ export declare function hostProfileControllerScope(profile: HostProfileV1): HostProfileControllerScopeV1;