/** * L8 probe HARNESS (SPEC-RSI-L7-L8 ยงA.2/ยงA.6). Orchestrates the probe matrix against a boundary and folds the * per-probe results into `ProbeRecord`s the artifact consumes. * * ๐Ÿ”ด BUILDABLE-NOW vs HONESTLY-PENDING (no fake-green): * - P0/P2 (runtime-verification + isolation): run for real now โ€” they read the live runtimeClass + kernel + * host-unreachability through an INJECTED exec seam ({@link ProbeExec}). The unit test injects a deterministic * fake; the live runner injects a thin wrapper over the real adapter. The harness FAILS LOUD on a runc * downgrade (P0) โ€” it never silently degrades and reports PASS. * - P1 (immutable-mount): the STRUCTURE + the independent-grader logic exist (probes.ts gradeP1), but the * real-RO-grader EXECUTION is BLOCKED on the adapter podSpecPatch seam. So unless the caller asserts the seam * is present (and supplies a real P1Observation), this harness emits an HONEST PENDING record citing the * blocker โ€” NEVER a synthesized pass. * - P3 (bash-egress): the STRUCTURE + attempt matrix exist, but there is no egress enforcement layer today and * the cluster CNI is unknown. So unless the caller supplies a real P3Observation from an enforcement layer, * this harness emits an HONEST PENDING record. (When a P3Observation IS supplied, it is graded honestly and * against the current boundary that grade is `egressEnforced:false` โ€” a real finding, still not a pass.) * * The unit test covers ONLY this orchestration + the pure folds. It must NEVER assert a probe "passes" against a * real boundary โ€” that authoritative verdict comes only from the live runner (scripts/, gated, real cluster). */ import { type Backend, type ProbeExec, type P1Observation, type P3Observation } from "./probes.js"; import type { ProbeRecord } from "./artifact.js"; import type { L8Escape } from "./escape.js"; export interface RunProbesOpts { backend: Backend; /** The adapter's self-declared capabilities.isolation (recorded, never trusted). */ declaredIsolation: boolean; /** Host kernel captured out-of-band (kata only; `ssh build-host uname -r`). null on e2b (RISK-7). */ hostKernel: string | null; /** The runtimeClass the adapter was configured with (the live runner reads the ACTUAL one from the cluster; * for the deterministic harness this is supplied). "" / "runc" โ‡’ no VM boundary. */ actualRuntimeClass: string; /** * ๐Ÿ”ด P1: a real P1Observation, ONLY when the adapter RO-mount seam is present (mode==="adapter-RO-seam-present") * AND it came from a real sandbox run. Omit it โ‡’ P1 is recorded as honest-pending (the default, until the seam * lands). NEVER synthesize this to fake a pass. */ p1?: P1Observation; /** * ๐Ÿ”ด P3: a real P3Observation, ONLY when a real egress-enforcement layer exists and the external collector ran. * Omit it โ‡’ P3 is recorded as honest-pending. When supplied against the current (unenforced) boundary it grades * to egressEnforced:false โ€” honest, not a pass. */ p3?: P3Observation; } export interface RunProbesResult { /** P0/P2-derived runtime facts the artifact's `boundary` is built from. */ isolationClassVerified: boolean; kernelDistinctFromHost: boolean | null; runtimeClass: string; capSysAdminAbsent: boolean; probes: ProbeRecord[]; escapes: L8Escape[]; } /** * Run the probe matrix against the supplied observations. P0/P2 are real-now (from the exec seam); P1/P3 are * pending unless a real observation is supplied. Returns the probe records + any objectively-observed escapes. * * `exec` is the injected boundary exec โ€” used to read the guest kernel (P0) and the host-unreachability set (P2). * On a real run this is a thin wrapper over `RemoteExecutionEnv.exec`; in tests it is a deterministic fake. */ export declare function runDeployContractProbes(exec: ProbeExec, opts: RunProbesOpts): Promise; //# sourceMappingURL=run-probes.d.ts.map