import type { Policy } from '../base.ts'; import type { Action, CommandContext } from '../types.ts'; /** * Spot mkdir's -p/--parents by raw token scan. The policy fires before * flag parsing (its refusals must win over parse errors and stay * consistent across the single-mount and cross-mount paths), so the * shorthand cluster (-pv) is detected on the raw argv rather than * through the spec parser. */ export declare function hasParentsFlag(argv: readonly string[]): boolean; /** * The built-in rule: a mount root is not an ordinary directory. * * Two rules, one boundary. The first mirrors the kernel's refusal to unlink * or replace a mountpoint (EBUSY on Linux), with each command's own GNU * message: rm, rmdir, mv, mkdir, touch and ln. * * The second is mirage's own, and is a deliberate divergence: an archiver or * a recursive copy pointed at a mount root would read an entire backend into * one object. Real tar and cp allow it because a mountpoint there is just * another directory; here the mount table is the deployment's configuration, * and consuming a whole mount is neither what the operand looks like it costs * nor something an agent should be able to do to data it was merely given a * view of. The refusal names the boundary in each tool's own voice rather * than inventing a mirage error, so a caller sees a filesystem answer. * * Only positional operands are tested. tar's `-C` and unzip's `-d` are * destinations to extract INTO, which is ordinary use of a mount, so reading * them here would refuse the safe direction as well. * * Fires before mount resolution and cross-mount routing so the refusal is the * same however the operands span mounts, and before runtime placement so a * routed command is refused identically. MountRegistry seeds it as the first * policy (mount-root semantics belong to the mount layer), so its exact * messages win over user policies by order, not by privilege. */ export declare class MountRootPolicy implements Policy { preCommand(ctx: CommandContext): Action | null; } //# sourceMappingURL=mount_root.d.ts.map