import type { AdmissionRules, ProfileScript } from '../../policy/types.ts'; import { type CommandsBlock, type CompiledProfile, type SessionProfile } from '../../policy/profile.ts'; import { type Session } from './session.ts'; /** * The profile a session is created from. A name is looked up as written; a * profile object is itself; null picks `profiles.default` when the * workspace defines one and leaves the session unrestricted otherwise. * There is no inheritance chain: a profile is the whole document, so * nothing is assembled from somewhere else before it is read. Throws * PolicyError on a name the workspace does not define. */ export declare function resolveProfile(profiles: Readonly>, profile: string | SessionProfile | null | undefined): SessionProfile | null; /** * The profile's commands block with the inline document's rules added. An * inline document may only restrict, so it carries ask and deny rules * and never an allow list: a list there would install a command the * profile does not have, which is the one thing a per-call document must * not do. */ /** * Refuse an allow list in an inline document. * * The refusal belongs to *where the document was written*, not to * whether a profile happened to resolve, so both paths into `withInline` * run it: a workspace with no default profile must not quietly accept a * list a workspace with one refuses. */ export declare function refuseAllow(inline: CommandsBlock | null | undefined): void; /** * Refuse a show entry in an inline document. * * An inline document may only restrict: it adds ask and deny rules and * hides. A show re-opens a subtree or states a mode, which is the * profile's to say; same rule as `refuseAllow`, and it runs on both * paths into `withInline` for the same reason. */ export declare function refuseShow(inline: SessionProfile): void; /** * A profile with the inline document of one `createSession` added. * * The one rule about combining two documents: an inline document may * add ask and deny rules and hides, never an allow list and never a * script, and that holds even when there is no profile to add to. Modes * take the weaker of the two, `cwd` and `env` are the inline document's * when it states them (they are session presets, not permissions). * Either side null returns the other unchanged; the profile's policy * survives the merge, since the inline document can only add rules * beside it. */ export declare function withInline(base: SessionProfile | null, inline: SessionProfile | null): SessionProfile | null; /** * A profile's admission rules: its own, plus every mount section's, in one * list; null when the profile states none. Mount rules come first so the * section closest to the data speaks first when several rules match at * the same anchor depth and only the message differs. */ export declare function compileCommands(profile: SessionProfile): AdmissionRules | null; /** * The profile's policy program, compiled onto the session. `name` is * the profile's name, empty for a document passed without one; what the * policy reads as `ctx.profile`. * * @throws PolicyError - the policy is still a path, which means it * reached the workspace without passing the config door that loads one. */ export declare function compileScript(effective: SessionProfile, name: string): ProfileScript | null; /** The session fields a profile compiles to. */ export declare function compileProfile(effective: SessionProfile | null, name?: string): CompiledProfile; /** * Stamp a compiled profile's narrowing onto a session: the fields no * shell line can edit (the per-mount modes, hidden paths, show entries, * hidden variables, hide reasons, the admission rules, the profile's * script, the profile's name). Applied at creation and again * whenever a stored record could carry a stale copy (the default * session after hydration), so the document, not the store, is what an * agent runs under. */ export declare function narrow(session: Session, compiled: CompiledProfile): void; /** * Narrow a fresh session and seed its scratch state from the profile. * A profile's env is a *process* environment, the same shape * `ws.env = {...}` speaks, so every name in it is exported: seeding * them plain left `$TOKEN` expanding while every command, CLI and * guest runtime in the profiled session saw nothing, since all three * read `envSnapshot` and that is the exported set. The cwd is where * the session starts; both are the agent's to change afterwards, which * is why hydration keeps the stored ones and re-stamps only `narrow`. */ export declare function applyProfile(session: Session, compiled: CompiledProfile): void; //# sourceMappingURL=resolve.d.ts.map