/** Revalidate at I/O time; never truncate a file before checking the opened inode. */ export declare function checkedFilePath(workspaceRoot: string, path: string, operation: 'read' | 'write' | 'delete'): string; export declare function readWorkspaceFile(workspace: string, path: string, maxBytes?: number): Buffer; /** Use the same checked inode as synchronous access, yielding between bounded reads. */ export declare function readWorkspaceFileAsync(workspace: string, path: string, signal?: AbortSignal, maxBytes?: number): Promise; export declare function writeWorkspaceFile(workspace: string, path: string, content: string | Buffer): void; export declare function deleteWorkspaceFile(workspace: string, path: string): void; /** Refuse publication of directory trees containing protected or escaping entries. */ export declare function assertWorkspaceTreeReadable(workspace: string, path: string): void;