/** * A whole-command refusal exits as bash does for a command it found but * may not run. */ export declare const POLICY_DENIED_EXIT = 126; /** * Which verb wins when two rules speak about the same subject at the * same anchor depth: deny before ask. Both gates order by it, which is * what keeps the entry gate from contradicting the admission gate. */ export declare const DENY_FIRST = 0; export declare const ASK_SECOND = 1; /** * The same ordering as the outcome a rule produces, for the gate that * has already named the verb. ALLOW is absent because only a rule ties * against a rule, and nothing in the document says allow at a path. */ export declare const VERB_ORDER: Readonly>; /** * The reason a bare command pattern under `commands.deny` carries, and * the one a bare pattern under `commands.ask` carries. */ export declare const DEFAULT_DENY_REASON = "denied by policy"; export declare const DEFAULT_ASK_REASON = "no standing approval"; /** * The one pattern token that matches any one line token; trailing, it * matches whatever follows, which a prefix already does. */ export declare const WILDCARD = "*"; /** * Ops that act on a whole subtree at once, so a pure path rule refuses * them on the directory that holds its scope or on any ancestor: moving * or removing `/x` takes `/x/locked/*` along. `rename` is the * dispatcher's; `rmdir` removes the scope's own directory; `rm_r` is the * command tier's recursive remove. */ export declare const SUBTREE_OPS: ReadonlySet; /** * Commands whose operand is a whole subtree they move or remove, so a * path rule judges the operand the way it judges a SUBTREE_OPS op: the * directory holding the scope, or any ancestor of it, is the scope. Only * the destroyers: a reader given an ancestor (`grep -r`, `du`, `tar`) is * the command tier's I/O to refuse file by file, not a line to refuse * whole. */ export declare const SUBTREE_COMMANDS: ReadonlySet; /** * Ops that read an entry's metadata and nothing of its content, which a * deny rule lets through at the op door: deny means present and refused, * not absent, so a listing shows the entry's name and size and the read * of it is what fails, as GNU reports an unreadable file. The command * tier's guard leaves its `stat` slot unwrapped for the same reason; a * hidden path is the hide arm's, and stays ENOENT. */ export declare const METADATA_OPS: ReadonlySet; /** How long one profile script may run before its profile is refused. */ export declare const SCRIPT_EVAL_TIMEOUT_SECONDS = 10; //# sourceMappingURL=constants.d.ts.map