/** * Engine-owned git for in-place write routes. * * The caller owns the branch — `/mma:flow`, a Forge project, or a Forge loop has already cut * and checked out `mma/-` before dispatching. The engine never creates a branch or * a worktree; it edits the caller's checkout in place and commits there. * * Everything here runs in the DAEMON process via execFile, outside every worker sandbox. That * separation is what lets workers be denied git entirely while commits still happen: the worker * only ever edits files. */ interface RepoBaseline { /** HEAD before the worker ran. `null` for a non-git target. */ readonly head: string | null; /** The branch the CALLER checked out. Committing anywhere else would be a silent mis-delivery. */ readonly branch: string | null; /** FR-4: `git status --porcelain` was non-empty before dispatch. `false` for a non-git target. */ readonly dirtyAtDispatch: boolean; /** Exact `git status --porcelain` text at dispatch. Used to prove the worker actually changed * something before we commit — see {@link commitAll}. */ readonly statusText: string; } export interface CommitOutcome { /** True when a new commit was created (false when there was nothing to commit). */ readonly committed: boolean; /** HEAD after the attempt — unchanged from the baseline when nothing was committed. */ readonly head: string | null; /** FR-3: `git diff --name-only ..HEAD`. Empty when nothing was committed. */ readonly filesChanged: string[]; } /** * Capture the pre-dispatch baseline. Per the spec's constraint, a git target that cannot yield a * HEAD must fail BEFORE a worker starts rather than run without a diff baseline — the caller * signals that by receiving a thrown error here. */ export declare function captureBaseline(cwd: string): Promise; /** * Cross-runner tamper detection, checked after the worker turn and BEFORE the engine commits. * * Claude's confinement hook can refuse a mutating `git` command outright. Codex runs under a * native OS sandbox with no per-command interception, so prevention is not available there and * claiming otherwise would be false assurance. What IS available on every runner is detection: * the engine recorded HEAD and the branch before dispatch and can simply check they still hold. * * A moved HEAD or a switched branch means the worker ran git despite being told not to. Failing * loudly here is essential — committing onto a branch the caller did not select, or on top of a * worker's own rewrite, would silently mis-deliver the work. */ export declare function assertRepoUntampered(cwd: string, baseline: RepoBaseline): Promise; /** * Stage everything and commit on whatever branch the caller checked out. * * `git add -A` is intentional and specified: the branch belongs to this task, so pre-existing * and concurrent working-tree changes are swept in deliberately. `dirtyAtDispatch` is what * discloses that to the caller. Ignored files stay excluded — `add -A` does not stage untracked * paths matched by `.gitignore`. * * A commit failure must never destroy work: we never reset, checkout, or clean. Edits stay on * disk for `git status` and manual recovery, and the error propagates. * * Authorship is the CALLER's own git identity — see {@link identityOverrides}. */ export declare function commitAll(cwd: string, baseline: RepoBaseline, message: string): Promise; export {}; //# sourceMappingURL=repo-commit.d.ts.map