import type { AdmissionRules } from '../types.ts'; /** * Whether the profile states a command rule at all: an allow list, an ask * or a deny. */ export declare function hasRules(rules: AdmissionRules | null): boolean; /** * Whether a rule in force reads a command's words past its name. * * The whole-line gate asks this for a word the runtime, not the gate, * will expand: the head of every command is read by every rule, but an * argument only matters to a pattern with a token after the name * (`git push`), a path-scoped rule, or a mount-scoped one, so a dynamic * argument to a command no such rule names is nothing a rule would have * seen anyway. */ export declare function readsArgs(rules: AdmissionRules | null, name: string): boolean; /** * Whether a path rule in force reads this command's paths. * * The argv builder asks this before deciding who resolves a glob * operand: a mount command's pattern is normally pushed down to the * backend, so the gate would see the pattern, not the matches, and * `cat /scratch/*\/k` would pass a rule on `/scratch/private` that * `cat /scratch/private/k` fails. When a rule that reads paths (or a * mount) applies to the command, whether it names the command or every * command, the shell expands the glob first, so the gate judges the * paths the command will touch. */ export declare function scopesPaths(rules: AdmissionRules | null, name: string): boolean; //# sourceMappingURL=reads.d.ts.map