/** * Scoped preflight verification: the second, row-scoped, format-evidence read. * * The every-dispatch base preflight read is values-only (see * `GOOGLE_SHEETS_API_PREFLIGHT_BASE_FIELDS`). Because a `numberValue` cell * rendered with the canonical date number format normalizes to a `date` * kind (and, for identity columns, to a completely different identity * string), any cell whose normalization can depend on a number format must * be re-read WITH format evidence before its hash or identity is trusted: * * - every existing row a batch resolves for a CAS/replay/deletion hash * (row-banded: full registered column span, values + BOTH number-format * sources, parsed exactly like the historical full-mask read), and * - the whole identity column when any identity cell read as a number under * the base mask (column-banded), so identity duplicate detection cannot * drift for date-formatted numeric identities. * * The bands are fetched in ONE ranged `spreadsheets.get` (the real API * returns one GridData per requested range, in order — verified against the * live API), so every verification cell's value and both its formats come * from a single sheet snapshot; base-read values are NEVER merged with * verification formats. If the bands would exceed the per-request range * budget, the caller falls back to the historical whole-table full-evidence * read instead, which is correct by construction. * * Between the base read and the verification read a human can shift rows. * That is fail-closed by revalidating the row anchor inside the verification * snapshot (a present, different anchor proves a shift and blanks the row so * planning cannot accept it) and by the CAS hash itself. */ import { resolveGridCell } from "./preflightRows.js"; import { type BandRange, type ReadCalibration } from "@hikoutei/ikisaki"; import type { ParsedGridData, PreflightContext } from "./preflightTypes.js"; /** * Hard cap on ranges per `spreadsheets.get`, shared engine-wide (the * historical per-lane copies unified into `MAX_READ_RANGES_PER_REQUEST`). */ export declare const MAX_VERIFY_RANGES_PER_REQUEST = 40; /** The real API rejects a single requested range above 10,000 cells. */ export declare const MAX_VERIFY_CELLS_PER_RANGE = 9500; /** * Discriminated outcome of planning one route's verification read. The * pre-engine `overflow` member (and its whole-table full-evidence fallback) * is REMOVED: a band plan exceeding the per-request range/byte budget now * expands into additional sequential band requests instead of degrading to * one uncapped whole-table read (unified read engine §5 step 5). */ export type PreflightVerificationPlan = { readonly kind: "none"; } | { readonly kind: "ranges"; readonly items: readonly BandRange[]; }; /** Serial-string aliases of an ISO-shaped identity (empty otherwise). */ export declare function identitySerialAliases(identity: string): readonly string[]; /** * Builds the verification plan for one route: the row bands for resolved * CAS/replay rows plus, when the route's identity cells need format * evidence, the whole identity column band. Returns `"none"` when no * verification read is needed at all (pure-insert batch, no numeric * identity). Every band is chunked to the shared per-range cell cap AND * the per-evidence-class byte budget; a plan exceeding one request's range * budget expands into additional sequential requests at packing time (the * caller never degrades to a whole-table read). * * `exactLastRow` band ends are CLOSED (the planned extent is proven by the * context/target set), so every hashed cell still sits in exactly one band * of one server snapshot. */ export declare function planPreflightVerification(context: PreflightContext, targetRowNumbers: readonly number[], calibration: ReadCalibration): PreflightVerificationPlan; /** * Replaces the verification-relevant state of a base preflight context from * ONE verification document's grids (the ordered per-range GridData list of * the route's tab), producing a context whose hashes, identities, and * duplicate checks are format-exact. * * Contract with the caller: every banded cell's value AND both format * sources come from the same request, so a human edit between the base read * and this read can never mix a base value with a verification format into * one hash. Rows whose base anchor is present but whose verification anchor * is missing or different are provably shifted (e.g. a human row inserted * above the target) and blank out (fail closed); rows banded but absent/blank * in the snapshot are treated the same way. * Identity values for all rows are rebuilt from the identity-column band * when present. The identity duplicate check (deferred at base indexing for * numeric identities) re-runs fail-closed here. */ export declare function patchPreflightContext(context: PreflightContext, grids: readonly ParsedGridData[], targetRowNumbers: readonly number[], options: { readonly includeIdentityBand: boolean; }): PreflightContext; /** * Resolves raw CellData across an ordered per-range GridData list. * * The accessor lives with the row-reading helpers (shared with the scoped * base-read synthesis); re-exported here so verification readers keep one * import surface. */ export { resolveGridCell as resolveVerifyCell }; //# sourceMappingURL=preflightVerify.d.ts.map