import type { Policy } from '../base.ts'; import { type Action, type CommandContext, type OpsContext, type SessionCommandsQuery } from '../types.ts'; /** * The profile's `commands` rules, enforced. * * Seeded by the workspace after `MountRootPolicy` (POSIX messages still * win) and before user policies, so a document rule speaks before a * coded one when both match. It reads the session's compiled rules * through the narrow `SessionCommandsQuery` by the session id the door * put in the context, never through ambient state: an explicit fact * survives the async hop that drops a store. Verdicts render through * the one outcome table (`renderDeny`), so an agent cannot tell a * document deny from a coded one. * * `preCommand` renders one `decide` call, which is where the law lives: * the allow list first (a line it does not cover is refused whole, * though its head was visible), then the winning rule, refused whole or * per operand by whether it names paths, or taken to the approval door * when it asks. `preOps` walks the deny rules that are pure paths, so * FUSE, programmatic ops and the warm cache cannot bypass a path the * profile protects; there is no ask at the op door, which cannot wait on a * host. */ export declare class PermissionsPolicy implements Policy { private readonly sessions; constructor(sessions: SessionCommandsQuery); preCommand(ctx: CommandContext): Action | null; preOps(ctx: OpsContext): Action | null; } //# sourceMappingURL=permissions.d.ts.map