/** * build-report-data — compute ReportData from the enriched POC * pipeline output. Everything here is tool arithmetic over measured * window values; the agent's only input is the annotation map, which * is validated fail-closed (unknown hash or over-cap length refuses * the render — never silently truncated or dropped). * * Honesty constraints implemented here: * - severity gate: below MIN_SEVERITY_COVERAGE no volume action is * proposed at all (a gate must fail on known-broken input). * - THE CHANGE renders the container-keyed grammar configure_engine * truly emits; the per-statement gap is stated, not papered over. * - impacts are this window's arithmetic; no extrapolation. */ import type { RenderInput, _EnrichedPattern } from '../poc-report-renderer.js'; import type { IncidentCluster } from '../detectors/incident-cluster.js'; import { type InstallMethod } from './command-matrix.js'; import { type ReportData } from './report-data.js'; /** A cluster must carry at least this share of window bytes to drive * the verdict + an operational action. */ export declare const DOMINANT_CLUSTER_SHARE = 0.2; export declare const CAPS_FILE_NAME = "log10x-caps.csv"; export interface BuildReportOptions { siem: string | null; siemLabel: string | null; forwarder: string | null; install: InstallMethod; namespace?: string; workload?: string; /** Agent annotation slots, keyed by evidence hash. */ annotations?: Record; generatedAtIso: string; mcpVersion: string; } export declare class ReportRefusal extends Error { } export interface BuiltReport { data: ReportData; /** Verbatim caps.csv content matching THE CHANGE rows, or null when * the plan has no volume action. Written beside the report so the * apply commands reference a real file. */ capsCsv: string | null; } export declare function buildReportData(input: RenderInput, enriched: { patterns: _EnrichedPattern[]; clusters: IncidentCluster[]; }, opts: BuildReportOptions): BuiltReport; export declare function windowLabel(windowHours: number, window?: string): string;