import type { Runtime } from '../base.ts'; import { LanguageRuntime } from '../language.ts'; import { type Evaluator } from '../mixin.ts'; import { type RouteDecision, type RouteContext, type RoutePolicy } from './types.ts'; /** Policy evaluation is bounded: a hung script must not freeze every * line (command limits resolve after policy, so nothing above this * layer would). Matches the python POLICY_EVAL_TIMEOUT_SECONDS; a * holder object so tests can tighten it. */ export declare const POLICY_EVAL_TIMEOUT: { seconds: number; }; /** * The world's policy engine for a script. * * Config-borne policy scripts run on it; any runtime implementing * Evaluator qualifies (monty/pyodide in the default worlds, or a user * runtime in any language). The first evaluator whose `language` * matches the script's wins, so a .js policy runs on quickjs even when * a python evaluator sits earlier in the world; with no language (or no * match) the first evaluator serves. Null when the world has no * evaluator, which only matters once a ScriptSource actually needs one. * The attribute read here is the one `run` answers for too * (Runtime.language), so an engine cannot speak one language at this * door and another at that one. */ export declare function evaluatorOf(entries: readonly Runtime[], language?: string): (Runtime & Evaluator) | null; /** * The world's interpreter for a script CLI, evaluatorOf's run twin. * * The first entry whose `run` speaks the language wins, the same * first-match rule. Unlike evaluatorOf there is no any-language * fallback: a python program cannot run on a js engine, so no match * means null and the caller reports the world's entries. */ export declare function runtimeForLanguage(entries: readonly Runtime[], language: string): LanguageRuntime | null; /** * Normalize a policy verdict to a runtime name or null to pass. * * The object form is the extensible spelling: `{runtime: name}` places * the line, `{deny: reason}` refuses it, and the keys are mutually * exclusive. Unknown keys fail loud so a typo never silently passes. */ export declare function parseVerdict(verdict: unknown): string | null; /** * Resolve the policy ladder for one line: policy, then scripts. * * A policy verdict overlays the named runtime's captures on the static * bindings (an affirmative choice, never a refusal). With no verdict, * per-runtime scripts filter the entry list: an entry with no script * is always willing, and the willing entries re-bind in list order. * The vfs runtime is filtered exactly like the others; a command left * without a willing runtime is an admission failure at dispatch. * Config-borne scripts run on the world's evaluator (evaluatorOf), * never on a hardcoded interpreter. */ export declare function decideLine(entries: readonly Runtime[], policy: RoutePolicy | null, ctx: RouteContext, staticBindings: Record): Promise; //# sourceMappingURL=decide.d.ts.map