/** * Reserved-path collision predicates for `hikoutei setup`. * * Purely local filesystem checks run before any confirmation, runner * invocation, or API mutation: the setup file paths (service-account key, * --output, checkpoint, checkpoint temp, lock) must never canonically * resolve to one another. Extracted verbatim from the setup flow; no flow * state is consulted here. */ /** * Result of checking the setup file paths for canonical collisions. * * `--output` must never resolve to the service-account key path, the * checkpoint path, the checkpoint temp path (`.tmp`), or the setup * lock path (`.lock`), and the key path must never resolve to any of * the other reserved paths; writing one over the other would destroy the key, * the resume state, or the lock. The comparison uses canonical paths * (realpath of the nearest existing ancestor plus remaining segments, with * dangling symlink targets resolved by readlink), device/inode identity for * existing hardlinks, and case-folded equality on case-insensitive platforms * (macOS/Windows). Any aliasing rejects the run before confirmation, runner * invocation, or API mutation. */ export type SetupPathCollision = { readonly status: "ok"; } | { readonly status: "collision"; readonly message: string; }; /** * Rejects canonical collisions among key, output, checkpoint, checkpoint * temp, lock, and credential-pool key paths. * * Returns a stable structured usage error message when any two reserved * paths resolve to the same file (symlink aliases, dangling symlink * targets, hardlinks, and case aliases on case-insensitive platforms * included); the caller maps it to `invalid_args`. This check is purely * local and runs before any confirmation or mutation. */ export declare function findSetupPathCollision(input: { readonly keyPath: string; readonly outputPath: string; readonly statePath: string; /** * Planned or stored credential-pool key paths (entries 2..N). Every * pool key is a reserved setup artifact: aliasing the output, the key, * the checkpoint, the temp, the lock, or another pool key rejects the * run before any mutation. Empty by default so single-SA callers are * unchanged. */ readonly poolKeyPaths?: readonly string[]; }): SetupPathCollision; //# sourceMappingURL=setupPathCollision.d.ts.map