import { type PathSpec } from '../../types.ts'; import type { MountEntry } from '../mount/mount.ts'; export declare const BARE_PREFIX = "/"; /** * The prefix a namespace path is governed by. * * A node-table entry (a symlink, an attr overlay) is namespace state with * no backend behind it, but it lives at a path, and the mount whose * subtree holds that path is what a session statement about it is scored * against. Its lineage is therefore the same longest-prefix rule dispatch * resolves the path by, and the prefix is the whole of what the rule * needs: it is the key a profile's per-mount mode is written under. * Mirrors Python's `workspace/dispatcher/lineage.py`. */ export declare function turfOf(mount: MountEntry | null): string; /** * Refuse a node-table write the session's grant does not cover. * * A symlink create, a link unlink or rename endpoint, and the no-mount * attr overlay all mutate namespace state at a path, and a session * handed a read-only view of that path must not reach any of them, or a * read-only grant would stop a file while waving its sibling link * through. Same voice as the backend gate: EROFS stamped with the * operand, so chokepoints render 'Read-only file system'. * * **The gate is the session's grant, not the mount's own mode**, and the * ceiling passed to `effectivePathMode` is WRITE for exactly that * reason. The two planes say different things with one word. * `mode: read` on a mount is overwhelmingly a statement about a * *backend* that cannot write — notion, github, mem0, postgres, mongodb, * every vector store — and symlinks are namespace state, so a link above * such a mount needs no write capability from it and is pinned working * on four of them (`integ/resources//sym.json`). A session grant is a * statement about what this *session* may do, which covers both planes, * so it is the one that binds here. The consequence to know: * sessionless, a deliberately read-mode mount still takes a link. * Separating "this backend cannot write" from "this deployment forbids * names here" needs a second field on the mount table, which does not * exist and is not worth inventing for it; a deployment wanting that * today states it in `preOps`. */ export declare function requireTurfWritable(mount: MountEntry | null, path: PathSpec): void; //# sourceMappingURL=lineage.d.ts.map