/** * Where reveal sidecars are stored. Exported so the PreToolUse placeholder * advisory can name the directory a spliced original was saved under without * re-deriving the env override. * @returns {string} */ export function revealDir(): string; /** * Delete this project's reveal sidecars and spans older than {@link REVEAL_TTL_MS}. * * Nothing else removes them: every entry is content-addressed, so a store that is * never swept grows for the life of the machine. Called from SessionStart, the one * touchpoint that runs once per session rather than once per tool call. * @returns {void} */ export function sweepStaleReveals(): void; /** * Persist one reveal's pre-splice text and return the model-facing hint naming * its path, or null when the write fails (the splice already protected the * output, so a failed convenience write must not break sanitization). The store * dir is verified private/uid-owned and the file is created symlink-refusingly * (O_EXCL): the path is content-addressed, so an attacker who chose the page bytes * can precompute it and pre-plant a symlink there to redirect this write onto a * victim file — writeFileNoFollow refuses that instead of following it. * @param {string} content * @returns {string | null} */ export function persistReveal(content: string): string | null; /** * The store path for one Layer-2 splice's original bytes, keyed by the * placeholder key. Throws on a malformed key (fail loud: every caller extracts * the key from LAYER2_PLACEHOLDER_RE, whose capture group can only yield a * valid key, so a bad one here is a caller bug, not input). * @param {string} key * @returns {string} */ export function spanPath(key: string): string; /** * Persist one Layer-2 splice's (already-redacted) original under its * placeholder key, with the same hardened treatment as {@link persistReveal}: * the dir must be a private uid-owned 0700 directory, and the file is created * symlink-refusingly (O_EXCL) because the path is content-addressed — an * attacker who chose the page bytes can precompute it and pre-plant a symlink. * Content-addressed dedupe: an existing entry (same key = same raw original) * is left in place and counts as success. Returns true when the span is on * disk (written now or already there); false on any failure — non-fatal by * contract, exactly like a failed reveal write (the splice already protected * the output; a later rehydration of this key fails CLOSED with a deny). * * The KEY is the caller's, extracted from the placeholder — never recomputed * from `content`: the key was minted from the RAW original, and `content` is * the redacted original, so a recomputed hash would not match. The key is a * NAME, not an integrity check. * @param {string} key * @param {string} content the splice's original, redacted BEFORE this call * @returns {boolean} */ export function persistSpan(key: string, content: string): boolean; /** * The stored original for one Layer-2 placeholder key, or null when no span is * stored (or the store is unusable). The open refuses symlinks (O_NOFOLLOW): * the path is precomputable, so a planted symlink must not let this read pull * an arbitrary file's bytes into a rehydrated write. * @param {string} key * @returns {string | null} */ export function readSpan(key: string): string | null; /** * True when this PostToolUse event is a Read of a reveal sidecar file, so its * output must be marked untrusted even though Read is otherwise a trusted local * tool. Containment is checked against the lexically resolved path with a * trailing separator so a sibling dir sharing the prefix (…-reveal-evil) cannot * pass. The model picks what it Reads (no attacker-planted symlinks to escape), * so lexical resolution — not realpath — is the right boundary here. * @param {string} toolName * @param {any} toolInput * @returns {boolean} */ export function isRevealRead(toolName: string, toolInput: any): boolean; /** * How long a reveal sidecar or span file is kept before a later session sweeps it. * It must outlast the longest session that could still rehydrate a placeholder the * model is holding, so it is generous rather than tight — these files are small, * and the cost of sweeping one too early is a rehydration that fails closed. */ export const REVEAL_TTL_MS: number; /** * The model-facing line telling it Layer-2 placeholders round-trip: pushed once * per tool output whose splices were persisted, so the model knows to leave the * keyed placeholders byte-for-byte intact when copying text back into a file — * Edit/Write restore each to the stored original automatically. */ export const SPAN_ROUNDTRIP_NOTICE: string; /** Envelope prepended to a reveal-file Read so its bytes are framed as untrusted. */ export const REVEAL_READ_ENVELOPE: string;