/** Named in every refusal so a caller can tell "this name was never an engine collection" from "this build's list is older than yours". Bump it whenever ENGINE_COLLECTIONS or ENGINE_COLLECTION_PATTERNS changes. */ export declare const ENGINE_ALLOWLIST_VERSION = 11; /** What a collection HOLDS. `knowledge` is the retrieval corpus — documents and the chunks an engine mints from them; everything else is `storage`. Deliberately a property of the DATA, not of anyone's billing: Vendo Cloud meters the two kinds apart, but a category like "unmetered" is a price list, not a data kind, and does not belong in a contract every BYO mount reads. */ export type CollectionKind = "storage" | "knowledge"; /** What the registry declares about one engine collection. */ export interface EngineCollectionSpec { kind: CollectionKind; /** The fields an `engine.list` watermark may bound, because THIS collection keeps them indexed. Absent for the 36 collections with nothing to walk forward through: an unindexed bound is a full table scan wearing a filter's clothes, so it is refused rather than served slowly. */ indexed?: readonly string[]; } /** The collections the `engine` op family may touch: Vendo's OWN internal drawers, nothing a host or a generated app owns. The registry lives in core because guard, automations and apps all need it and none of them may import the umbrella (layering); core imports nothing, so it is a literal here and a drift test in @vendoai/vendo holds it to the real constants. ONE registry, not a list plus a side-table of attributes: a second place naming these collections is how the allowlist rots, and `kind` and `indexed` are facts ABOUT an entry, so they live on the entry. */ export declare const ENGINE_COLLECTION_REGISTRY: { readonly vendo_grants: { readonly kind: "storage"; }; readonly vendo_approvals: { readonly kind: "storage"; }; readonly vendo_audit: { readonly kind: "storage"; }; readonly vendo_threads: { readonly kind: "storage"; }; readonly vendo_runs: { readonly kind: "storage"; readonly indexed: readonly ["started_at"]; }; readonly vendo_apps: { readonly kind: "storage"; }; readonly vendo_automations: { readonly kind: "storage"; }; readonly vendo_effects: { readonly kind: "storage"; }; readonly vendo_app_grants: { readonly kind: "storage"; }; readonly vendo_mcp_clients: { readonly kind: "storage"; }; readonly vendo_mcp_grants: { readonly kind: "storage"; }; readonly vendo_knowledge_docs: { readonly kind: "knowledge"; }; readonly vendo_knowledge_chunks: { readonly kind: "knowledge"; }; readonly vendo_parked_call: { readonly kind: "storage"; }; readonly vendo_parked_call_outcome: { readonly kind: "storage"; }; readonly vendo_host_components: { readonly kind: "storage"; }; readonly vendo_pin_baselines: { readonly kind: "storage"; }; readonly vendo_placements: { readonly kind: "storage"; }; readonly vendo_placement_slots: { readonly kind: "storage"; }; readonly vendo_parked_action: { readonly kind: "storage"; }; readonly vendo_parked_build: { readonly kind: "storage"; }; readonly vendo_slots: { readonly kind: "storage"; }; readonly vendo_app_seen: { readonly kind: "storage"; }; readonly vendo_workspace_commits: { readonly kind: "storage"; }; readonly "automations:captures": { readonly kind: "storage"; }; readonly "automations:schedule": { readonly kind: "storage"; }; readonly "automations:deliveries": { readonly kind: "storage"; }; readonly "automations:sponsorships": { readonly kind: "storage"; }; readonly "automations:sponsored": { readonly kind: "storage"; }; readonly "guard:controls": { readonly kind: "storage"; }; readonly "guard:approval-claims": { readonly kind: "storage"; }; readonly vendo_channel_links: { readonly kind: "storage"; }; readonly vendo_channel_events: { readonly kind: "storage"; }; readonly vendo_channel_asks: { readonly kind: "storage"; }; readonly vendo_tenant_connectors: { readonly kind: "storage"; }; }; export type EngineCollection = keyof typeof ENGINE_COLLECTION_REGISTRY; /** The registry's names, in registry order — the allowlist itself. Derived, so adding a collection is one edit and the two can never disagree. */ export declare const ENGINE_COLLECTIONS: readonly EngineCollection[]; /** The ONE dynamic engine collection: the per-app capped version log and pin-intent trail, assembled at packages/vendo/src/apps/persistence/history.ts:84. Pin intents are rows INSIDE this collection, not a second drawer — there is one builder and one pattern, and a second of either is how an allowlist rots. Throws `validation` on an id the pattern would not accept: an empty or colon-bearing id composes a name that lands in some other app's drawer. */ export declare function engineAppHistory(appId: string): string; /** Anchored and length-bounded on purpose: an unanchored or unbounded id part matches any string that merely CONTAINS the prefix, which turns the allowlist into a wildcard and the gate into decoration. */ export declare const ENGINE_COLLECTION_PATTERNS: readonly [RegExp]; export declare function isEngineCollection(collection: string): boolean; /** The gate itself. Refusals point at the right door, because "blocked" with no alternative reads as a bug in Vendo rather than a wrong call. */ export declare function assertEngineCollection(collection: string): void; /** What a collection holds, for the byte accounting `footprint()` reports. A legal collection with no registry entry — today only the app-history pattern — is `storage`: `knowledge` is the closed exception (the corpus and its chunks), never the default, so a collection invented later is never silently counted as index cost. */ export declare function collectionKind(collection: string): CollectionKind; /** The gate on an `engine.list` watermark bound. A field this collection does not keep indexed is refused, not scanned: the whole point of the bound is a cheap forward walk, and one that degrades into a full scan under load is a performance cliff hidden behind a working API. `validation`, not `blocked`: the collection is legal and the caller's right to read it is not in question — the FIELD is wrong, and the message says which fields are right. */ export declare function assertIndexedField(collection: string, field: string): void;