import { z } from 'zod'; /** * One thing that gets deployed and runs on its own: a Lambda function, * an ECS task's container, a plain container, a k8s deployment, or an * edge worker. */ /** * `instanceName` is the stable identifier the deployment medium uses: * the CFN logical resource id for Lambda and ECS, the deployment name * for k8s, the container name for a plain container, and the script * name for an edge worker. */ declare const DeployableUnitSchema: z.ZodObject<{ deploymentTarget: z.ZodEnum<{ lambda: "lambda"; "ecs-task": "ecs-task"; container: "container"; "k8s-deployment": "k8s-deployment"; worker: "worker"; }>; instanceName: z.ZodString; }, z.core.$strip>; type DeployableUnit = z.infer; /** * The `instanceName` for an ECS task's container: the task definition's * own logical id, plus the container name from CFN's * `ContainerDefinitions[*].Name`. Everyone who writes an ECS * `DeployableUnit`, and everyone who matches a routing edge against * one, has to put the two together the same way, so they all call this. */ declare function ecsContainerInstanceName(taskDefinitionLogicalId: string, containerName: string): string; declare const FunctionCallSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"function-call">; module: z.ZodOptional; exportName: z.ZodOptional; package: z.ZodOptional; exportPath: z.ZodOptional>; }, z.core.$strip>; type FunctionCallSemantics = z.infer; declare const GraphqlOperationSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"graphql-operation">; operationName: z.ZodOptional; operationType: z.ZodEnum<{ query: "query"; mutation: "mutation"; subscription: "subscription"; }>; }, z.core.$strip>; type GraphqlOperationSemantics = z.infer; declare const GraphqlResolverSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"graphql-resolver">; typeName: z.ZodNullable; fieldName: z.ZodString; }, z.core.$strip>; type GraphqlResolverSemantics = z.infer; declare const MessageBusSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"message-bus">; messageBus: z.ZodEnum<{ aws_sqs: "aws_sqs"; "aws.sns": "aws.sns"; s3: "s3"; eventbridge: "eventbridge"; aws_kinesis: "aws_kinesis"; aws_firehose: "aws_firehose"; gcp_pubsub: "gcp_pubsub"; bullmq: "bullmq"; kafka: "kafka"; nats: "nats"; "cloudflare-queues": "cloudflare-queues"; "cloudflare-cron": "cloudflare-cron"; "cloudflare-tail": "cloudflare-tail"; }>; channel: z.ZodNullable; }, z.core.$strip>; type MessageBusSemantics = z.infer; /** * The bus technologies the schema allows. It comes from the enum, so a * value added there cannot drift from a hand-written copy elsewhere. */ type MessageBusTechnology = MessageBusSemantics["messageBus"]; /** * Where the protocol modules come together. * * Each protocol under this directory exports one * `BoundarySemanticsDefinition`. This file lists them twice, once for * the schema union and once for the behavior lookup, and the type check * at the bottom fails compilation if the two lists ever cover different * sets. Adding a protocol changes this file and no other, by one line in * each list. */ /** * The discriminated union every boundary binding validates against. * Built from the protocol modules' own schemas. */ declare const SemanticsSchema: z.ZodDiscriminatedUnion<[z.ZodObject<{ name: z.ZodLiteral<"rest">; method: z.ZodNullable; path: z.ZodNullable; declaredResponses: z.ZodOptional>; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"function-call">; module: z.ZodOptional; exportName: z.ZodOptional; package: z.ZodOptional; exportPath: z.ZodOptional>; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"graphql-resolver">; typeName: z.ZodNullable; fieldName: z.ZodString; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"graphql-operation">; operationName: z.ZodOptional; operationType: z.ZodEnum<{ query: "query"; mutation: "mutation"; subscription: "subscription"; }>; }, z.core.$strip>, z.ZodObject<{ deploymentTarget: z.ZodOptional>; instanceName: z.ZodOptional; name: z.ZodLiteral<"runtime-config">; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"storage">; storageSystem: z.ZodNullable; scope: z.ZodString; container: z.ZodNullable; accessPath: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"message-bus">; messageBus: z.ZodEnum<{ aws_sqs: "aws_sqs"; "aws.sns": "aws.sns"; s3: "s3"; eventbridge: "eventbridge"; aws_kinesis: "aws_kinesis"; aws_firehose: "aws_firehose"; gcp_pubsub: "gcp_pubsub"; bullmq: "bullmq"; kafka: "kafka"; nats: "nats"; "cloudflare-queues": "cloudflare-queues"; "cloudflare-cron": "cloudflare-cron"; "cloudflare-tail": "cloudflare-tail"; }>; channel: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"metric">; metricSystem: z.ZodString; metricType: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ deploymentTarget: z.ZodEnum<{ lambda: "lambda"; "ecs-task": "ecs-task"; container: "container"; "k8s-deployment": "k8s-deployment"; worker: "worker"; }>; name: z.ZodLiteral<"unit-invocation">; instanceName: z.ZodNullable; }, z.core.$strip>], "name">; type Semantics = z.infer; declare const RestSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"rest">; method: z.ZodNullable; path: z.ZodNullable; declaredResponses: z.ZodOptional>; }, z.core.$strip>; type RestSemantics = z.infer; /** * Normalize a route path to a canonical form for matching. * * - Converts Express-style params (`:id`) to brace-style (`{id}`), and * keeps a range modifier (`:id?`, `:rest+`, `:rest*`) inside the braces * - Strips trailing slashes (except bare `/`) * - Lowercases the static segments (params stay case-sensitive) */ declare function normalizePath(path: string): string; /** * A path with every parameter reduced to its position. `/users/{id}` * and `/users/:userId` both come out `/users/{}`, which is the set of * requests each one serves, and what deciding whether two sides * describe one endpoint rests on. The name a parameter is written * under is worth keeping in a report and worth nothing in a comparison. * A parameter's range stays, since `{tenant?}` serves a different set * of requests from `{tenant}`. */ declare function pathShape(path: string): string; /** * Whether two REST methods mean the same thing. Equal methods agree, * and `"*"` agrees with any stated method, because a handler that * responds to every method responds to this one. A null method was never * stated, so it agrees with nothing: there is no claim to agree with. * * This is the counterpart of `busesAgree`. No list of methods appears * here, so a wildcard pairs with whatever methods consumers write. */ declare function methodsAgree(a: string | null, b: string | null): boolean; /** * Whether a declared route path admits a concrete request path. Both * sides compare on their normalized forms, and a hole in the request * is text like any other, so a route inside a mount pattern is admitted * by it and a wider route is not. */ declare function routePathAdmits(declaredPath: string, requestPath: string): boolean; /** Whether two declared route paths serve at least one request in common. */ declare function routePathsMeet(a: string, b: string): boolean; /** * The pairing key is `(deploymentTarget, instanceName)`, which is * exactly a deployable unit, so the two fields come from * `DeployableUnitSchema` instead of being written out a second time. * * A provider states both. The reading side is the code, which knows it * reads its configuration and not which deployment will run it, so a * recognizer standing at a read leaves both off rather than guessing. * The pairing pass takes the deployment from the provider anyway. */ declare const RuntimeConfigSemanticsSchema: z.ZodObject<{ deploymentTarget: z.ZodOptional>; instanceName: z.ZodOptional; name: z.ZodLiteral<"runtime-config">; }, z.core.$strip>; type RuntimeConfigSemantics = z.infer; declare const StorageSemanticsSchema: z.ZodObject<{ name: z.ZodLiteral<"storage">; storageSystem: z.ZodNullable; scope: z.ZodString; container: z.ZodNullable; accessPath: z.ZodNullable; }, z.core.$strip>; type StorageSemantics = z.infer; /** * `postgresql:invoices`, `aws.dynamodb:editions#by-publication`. The * pairing pass has no key to fall back on here, so a reader who types * this back at `suss ask`, the pass that indexes accesses by it, and an * intent doc that says which store a write reaches all read this one. */ declare function storageLabel(semantics: StorageSemantics): string; /** The engine, or the words a report writes where nobody settled one. */ declare function storageSystemLabel(semantics: StorageSemantics): string; /** * What an access writes for its columns when it asked for all of them, * which is a query with no explicit projection. It covers every column * rather than saying which one, so anything comparing column lists has * to tell it apart from a list of columns. */ declare const EVERY_FIELD = "*"; /** The store on its own, which a finding writes without the system. */ declare function storageContainerLabel(semantics: StorageSemantics): string; /** * @suss/ir-core schemas: primitives shared by every suss IR. * * These are the types that any IR built on suss references: the * structure of a value (`TypeShape`), the identity of a boundary * (`BoundaryBinding` and its `Semantics` variants), where something is * in the source (`SourceLocation`), and how much to trust a claim * (`Confidence`). Behavioural summaries, intent docs, and later on * observation records all speak in these terms, so they are defined * here, in one place none of those IRs needs another IR to reach. * * The schemas are the single source of truth, and the package's * `index.ts` derives the types from them with `z.infer`. */ declare const ConfidenceSourceSchema: z.ZodEnum<{ inferred_static: "inferred_static"; inferred_ai: "inferred_ai"; declared: "declared"; derived: "derived"; }>; declare const ConfidenceLevelSchema: z.ZodEnum<{ high: "high"; medium: "medium"; low: "low"; }>; /** * What came of corroborating a claim by running the code * (`suss corroborate`). Inputs that satisfy the claim's own conditions * are generated and run through the function, and the observation * either agreed every time (`observed`), disagreed at least once * (`refuted`, which is either an extractor bug or a surprise, and the * counterexample says which input), or never produced a verdict * (`untested`, meaning no satisfying input was found, or every * satisfying run hit a dependency the harness cannot supply). * * Corroboration adds observations to a derivation. It is extra * evidence, and it never rewrites the derived claim. */ declare const CorroborationSchema: z.ZodObject<{ outcome: z.ZodEnum<{ observed: "observed"; refuted: "refuted"; untested: "untested"; }>; runs: z.ZodNumber; counterexample: z.ZodOptional; reason: z.ZodOptional; }, z.core.$strip>; declare const ConfidenceInfoSchema: z.ZodObject<{ source: z.ZodEnum<{ inferred_static: "inferred_static"; inferred_ai: "inferred_ai"; declared: "declared"; derived: "derived"; }>; level: z.ZodEnum<{ high: "high"; medium: "medium"; low: "low"; }>; corroboration: z.ZodOptional; runs: z.ZodNumber; counterexample: z.ZodOptional; reason: z.ZodOptional; }, z.core.$strip>>; }, z.core.$strip>; declare const SourceLocationSchema: z.ZodObject<{ file: z.ZodString; range: z.ZodObject<{ start: z.ZodNumber; end: z.ZodNumber; }, z.core.$strip>; span: z.ZodOptional>; exportName: z.ZodNullable; workspace: z.ZodOptional; }, z.core.$strip>; declare const BoundaryBindingSchema: z.ZodObject<{ transport: z.ZodString; semantics: z.ZodDiscriminatedUnion<[z.ZodObject<{ name: z.ZodLiteral<"rest">; method: z.ZodNullable; path: z.ZodNullable; declaredResponses: z.ZodOptional>; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"function-call">; module: z.ZodOptional; exportName: z.ZodOptional; package: z.ZodOptional; exportPath: z.ZodOptional>; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"graphql-resolver">; typeName: z.ZodNullable; fieldName: z.ZodString; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"graphql-operation">; operationName: z.ZodOptional; operationType: z.ZodEnum<{ query: "query"; mutation: "mutation"; subscription: "subscription"; }>; }, z.core.$strip>, z.ZodObject<{ deploymentTarget: z.ZodOptional>; instanceName: z.ZodOptional; name: z.ZodLiteral<"runtime-config">; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"storage">; storageSystem: z.ZodNullable; scope: z.ZodString; container: z.ZodNullable; accessPath: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"message-bus">; messageBus: z.ZodEnum<{ aws_sqs: "aws_sqs"; "aws.sns": "aws.sns"; s3: "s3"; eventbridge: "eventbridge"; aws_kinesis: "aws_kinesis"; aws_firehose: "aws_firehose"; gcp_pubsub: "gcp_pubsub"; bullmq: "bullmq"; kafka: "kafka"; nats: "nats"; "cloudflare-queues": "cloudflare-queues"; "cloudflare-cron": "cloudflare-cron"; "cloudflare-tail": "cloudflare-tail"; }>; channel: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ name: z.ZodLiteral<"metric">; metricSystem: z.ZodString; metricType: z.ZodNullable; }, z.core.$strip>, z.ZodObject<{ deploymentTarget: z.ZodEnum<{ lambda: "lambda"; "ecs-task": "ecs-task"; container: "container"; "k8s-deployment": "k8s-deployment"; worker: "worker"; }>; name: z.ZodLiteral<"unit-invocation">; instanceName: z.ZodNullable; }, z.core.$strip>], "name">; recognition: z.ZodString; }, z.core.$strip>; type TypeShape = { type: "record"; properties: Record; spreads?: Array<{ sourceText: string; }> | undefined; } | { type: "dictionary"; values: TypeShape; } | { type: "array"; items: TypeShape; } | { type: "literal"; value: string | number | boolean; raw?: string | undefined; } | { type: "text"; } | { type: "integer"; } | { type: "number"; } | { type: "boolean"; } | { type: "null"; } | { type: "undefined"; } | { type: "union"; variants: TypeShape[]; } | { type: "ref"; name: string; /** * Where this type is written down, when it is written down * anywhere. It is the key into the summary's table of definitions. * * A name does not identify a type. Every instantiation of one * generic reports the generic's own name and file, so `Omit` and `Omit` are both `Omit`, and a * table keyed on that gives the second one the first one's fields. * This key is built from what the type actually is. */ def?: string | undefined; /** * The file that declares this type, when the project declares it. * Absent for a name the language or a dependency owns, which means * the same thing everywhere. * * A name on its own does not identify a type. Two modules each * declaring a `User` produce the same ref, and a checker comparing * them has nothing to go on. This is what tells them apart. */ from?: string | undefined; } | { type: "unknown"; }; /** * The key a table of definitions uses for the type a ref points at. * * A ref has the name and the file that declares it, and that pair * already identifies the type, so a table keyed on it needs nothing new * on the ref. A name that the language or a dependency owns has no * file, and keys on the name alone. */ declare function typeDefinitionKey(ref: { def?: string | undefined; }): string | null; declare const TypeShapeSchema: z.ZodType; /** * A shape with the definitions it refers to substituted back into it. * * Comparing two shapes means comparing their structure, and a ref has * none. Rather than teach every comparison to look in a table, the * definitions go back into the shape once and everything downstream * reads what it always read. * * Substituting a definition is not a level of nesting, so it does not * spend depth. Counting it meant a type six deep came back three deep, * and a consumer reading a field past that was told the provider did * not have it. A type that refers to itself is stopped by the names * already substituted on this path, the shape walk's own cycle guard. */ declare function withDefinitionsInlined(shape: TypeShape, definitions: Record | undefined, depth?: number, inProgress?: ReadonlySet): TypeShape; export { storageSystemLabel as A, BoundaryBindingSchema as B, ConfidenceInfoSchema as C, type DeployableUnit as D, EVERY_FIELD as E, type FunctionCallSemantics as F, type GraphqlOperationSemantics as G, typeDefinitionKey as H, withDefinitionsInlined as I, type MessageBusSemantics as M, type RestSemantics as R, type Semantics as S, type TypeShape as T, ConfidenceLevelSchema as a, ConfidenceSourceSchema as b, CorroborationSchema as c, SourceLocationSchema as d, type MessageBusTechnology as e, DeployableUnitSchema as f, FunctionCallSemanticsSchema as g, GraphqlOperationSemanticsSchema as h, type GraphqlResolverSemantics as i, GraphqlResolverSemanticsSchema as j, MessageBusSemanticsSchema as k, RestSemanticsSchema as l, type RuntimeConfigSemantics as m, RuntimeConfigSemanticsSchema as n, SemanticsSchema as o, type StorageSemantics as p, StorageSemanticsSchema as q, TypeShapeSchema as r, ecsContainerInstanceName as s, methodsAgree as t, normalizePath as u, pathShape as v, routePathAdmits as w, routePathsMeet as x, storageContainerLabel as y, storageLabel as z };