/** * Per-session cap on consecutive blocked Stop remediations. * * The Stop verdict re-blocks until the ledger shows the end-of-turn evidence, * which assumes the agent CAN produce it. A session whose evidence can never * land (e.g. a headless child whose status command resolves to a different * owner) bounces forever: every retry replays the stop cycle until the budget * or the operator kills it. This counter is the backstop: once a single stop * cycle has been blocked `cap` times in a row, the verdict is allowed through * so the session can terminate. * * A "stop cycle" is delimited by the adapter's continuation flag (Claude * Code's `stop_hook_active`): a stop without the flag starts a fresh cycle and * resets the count. Adapters that never set the flag (Cursor) reset on every * stop, so the cap never engages there and behavior is unchanged. * * State is a tmpdir counter file keyed by session id — deliberately outside * the ledger, because remediation stops do not land fresh `turn.completed` * events (the turn span is already closed), so ledger evidence cannot count * them. */ export declare const DEFAULT_STOP_REMEDIATION_CAP = 5; /** * Record one blocked stop and report whether the cap is exhausted. * * Call only when the Stop verdict blocked. `continuation` is the adapter's * "this stop follows a stop-hook block" flag; false starts a fresh cycle. * Returns the retained block count and whether this cycle has already been * blocked `cap` times, meaning the caller should allow the stop instead of * blocking again. */ export interface RemediationBlockRecord { count: number; exceeded: boolean; } export declare function recordRemediationBlock(sessionId: string, continuation: boolean, cap?: number): RemediationBlockRecord; /** Clear the cycle counter after an allowed stop. */ export declare function clearRemediationCount(sessionId: string): void; //# sourceMappingURL=remediation-cap.d.ts.map