interface FireAndForgetChild { on(event: "error", listener: (error: Error) => void): unknown; unref(): unknown; } export interface SecretFileAclSpawnSyncResult { status?: number | null; stdout?: string | Buffer | null; stderr?: string | Buffer | null; error?: unknown; } export interface SecretFileAclSpawnSyncOptions { windowsHide: true; encoding: "utf8"; stdio: ["ignore", "pipe", "pipe"]; } export type SecretFileAclSpawn = (command: string, args: string[], options: { windowsHide: true; stdio: "ignore"; }) => FireAndForgetChild; export type SecretFileAclSpawnSync = (command: string, args: string[], options: SecretFileAclSpawnSyncOptions) => SecretFileAclSpawnSyncResult; export interface SecretFileAclOptions { platform?: NodeJS.Platform | undefined; username?: string | undefined; systemRoot?: string | undefined; /** A raw owner SID. `null` deliberately skips resolution and uses the username fallback. */ ownerSid?: string | null | undefined; spawn?: SecretFileAclSpawn | undefined; spawnSync?: SecretFileAclSpawnSync | undefined; } /** Return an absolute path to a trusted Windows System32 executable. */ export declare function windowsSystem32Executable(executable: string, systemRoot?: string | undefined): string; /** Pure argv builder for the SID lookup. */ export declare function ownerSidWhoamiArgs(): string[]; /** Parse only the numeric SID cell from `whoami /user /fo csv /nh`. */ export declare function parseOwnerSid(stdout: string): string | null; /** * `icacls name /grant:r Sid:perm` accepts simple rights without parentheses; `F` is * full access. Numeric SIDs carry the required `*` prefix. SYSTEM and Administrators * remain explicit because removing inherited ACEs must not lock out backup/admin agents. */ export declare function secretFileIcaclsArgs(path: string, owner: string): string[]; /** Pure argv builder for a directory whose children must inherit the restricted ACL. */ export declare function secretDirectoryIcaclsArgs(path: string, owner: string): string[]; /** Clear the process-local SID cache. Exported solely for deterministic injected tests. */ export declare function resetSecretFileAclOwnerSidCache(): void; /** * Resolve the current Windows owner by SID. Resolution is best effort and cached for the * process. Child output is captured and is never logged or attached to a thrown error. */ export declare function resolveWindowsOwnerSid(opts?: Pick): string | null; /** * Restrict a secret file to its owner while retaining SYSTEM and Administrators. This keeps * the established fire-and-forget contract used by onboarding and control authorization. */ export declare function restrictSecretFileOnWindows(path: string, opts?: SecretFileAclOptions): void; /** Synchronous create-time file hardening for tmp-before-publish write sequences. */ export declare function restrictSecretFileOnWindowsSync(path: string, opts?: SecretFileAclOptions): void; /** Synchronous directory hardening with inheritable owner/SYSTEM/Administrators grants. */ export declare function restrictSecretDirectoryOnWindowsSync(path: string, opts?: SecretFileAclOptions): void; export {};