import type { Server } from 'node:http'; import { MeshLinkPeer } from './peer'; import { type MeshLinkFrame, type MeshLinkFrameHeader } from './protocol'; export interface MeshLinkRuntimeOptions { path: string; secret: string; httpServer?: Server; connectTimeoutMs: number; idleTimeoutMs: number; maxFrameBytes: number; maxBufferedBytes: number; maxPeers?: number; maxInboundPeers?: number; maxOutboundPeers?: number; maxCachedUrls?: number; /** Maximum static, owned, and resolver-created endpoint pins. */ maxEndpointPins?: number; endpointPins?: Readonly>; } type MeshRoute = (peer: MeshLinkPeer, frame: MeshLinkFrame) => Promise; export interface MeshLinkResolvedEndpointPin { publicKey: string; /** Absolute local deadline; resolvers should derive this from the live lease. */ expiresAt: number; } export type MeshLinkEndpointPinResolver = (processId: string, endpointId: string) => Promise; export declare function getMeshLinkProcessId(): string; export declare function acquireMeshLinkRuntime(options: MeshLinkRuntimeOptions): MeshLinkRuntime; export declare class MeshLinkRuntime { private readonly options; private readonly onClose?; private readonly wsServer; private readonly authenticator; private readonly routes; private readonly endpointPins; private readonly endpointPinResolvers; private readonly peersByUrl; private readonly peersByIdentity; private readonly acceptedPeers; private readonly allPeers; private readonly peerDirections; private readonly connectingSockets; private readonly peerCloseHandlers; private readonly incomingBudget; private readonly cleanupUpgradeHandler; private readonly idleTimer; private readonly endpointId; private readonly endpointKeyPair; private pendingHandshakes; private closed; constructor(options: MeshLinkRuntimeOptions, onClose?: (() => void) | undefined); assertCompatible(options: MeshLinkRuntimeOptions): void; get id(): string; get publicKey(): string; /** Install a membership pin before accepting or selecting that endpoint. */ pinEndpoint(endpointId: string, publicKey: string, processId?: string, ttlMs?: number): () => void; /** Resolve a missing pin from a live membership source during the WebSocket * handshake. The resolver must validate the process+endpoint lease itself. */ registerEndpointPinResolver(resolver: MeshLinkEndpointPinResolver): () => void; get isClosed(): boolean; register(meshKey: string, route: MeshRoute): () => void; onPeerClosed(handler: (processId: string, endpointId: string) => void): () => void; request(url: string, header: Omit, body: Uint8Array, timeoutMs: number, remoteProcessId?: string, remoteEndpointId?: string, remoteEndpointPublicKey?: string): Promise; /** * Send a reverse tunnel frame to the current winning link for an * authenticated identity. Do not retain a peer object here: duplicate * link arbitration can legitimately replace it while a tunnel is open. */ requestPeer(remoteProcessId: string, remoteEndpointId: string | undefined, header: Omit, body: Uint8Array, timeoutMs: number, remoteEndpointPublicKey?: string): Promise; closePeer(remoteProcessId: string | undefined, remoteEndpointId: string | undefined, reason: string, remoteEndpointPublicKey?: string): void; close(): void; private closeIfUnused; private readonly verifyClient; private verifyIncomingClient; private acceptPeer; private getPeer; private connect; private createPeer; private resolveDuplicatePeer; private assertOpen; private addHandshakeIdentityHeaders; private closeIdlePeers; private get maxPeers(); private get maxEndpointPins(); private get maxInboundPeers(); private get maxOutboundPeers(); private get maxCachedUrls(); private canCreatePeer; private evictUrlCacheEntry; private addEndpointProof; private endpointProof; private verifyEndpointProof; private authorizeEndpointPin; private getEndpointPin; private pruneEndpointPins; } export {}; //# sourceMappingURL=runtime.d.ts.map