/** * Context Chain Gate — C1 * * Converts chain verification evidence into a merge-gate decision and * a PR comment (Infracost-style). Two things hard-fail. Everything else * is configurable or comment-only. * * Hard failures (always block merge): * 1. no_governance_receipt — no receipt at all * 2. tamper_detected — receipt hash does not match producer run * * Configurable gate (team decides; default: warn only): * 3. verifier_failed — unverified claims, incomplete integrity, * missing artifacts, unresolved assumptions * * Comment-only (never block, always visible): * - Cost: actual vs budget — money is already spent, blocking adds friction * - Chain lineage: chainId, producerRunId, consumerRunId * - Integrity state * * Standing rules: * - Pure functions, no side effects. * - evaluateChainGate never reads environment variables or config files. * - renderGatePrComment produces valid GitHub-flavored markdown. * - No fake data, no placeholder behaviour. */ import type { ContextHandoffReceipt } from "../contracts/index.js"; import type { ChainIntegrityState, ContextHandoffVerification } from "../contracts/index.js"; export interface ChainGateConfig { /** * When true, a failed verifier (unverified claims, incomplete integrity, * missing artifacts, unresolved assumptions) blocks the merge. * Default: false — warn in PR comment, do not block. */ blockOnVerifierFailure: boolean; } export interface ChainGateCost { actualUsd: number; budgetUsd: number; } export interface ChainGateInput { /** null means no receipt was provided — triggers the hard no_governance_receipt failure. */ receipt: ContextHandoffReceipt | null; /** null when receipt is null. Must be provided when receipt is non-null. */ verification: ContextHandoffVerification | null; cost?: ChainGateCost; config?: Partial; } export type ChainGateConclusion = "failure" | "neutral" | "success"; export interface ChainGateResult { noGovernance: boolean; tamperDetected: boolean; verifierFailed: boolean; shouldBlock: boolean; conclusion: ChainGateConclusion; failureReasonCode?: string; failureMessage?: string; cost?: ChainGateCost & { exceeded: boolean; }; integrity: ChainIntegrityState | "absent"; } /** * Evaluates whether the chain gate should block merge, and assembles * the data needed for the PR comment. * * Call order: * 1. Check for missing receipt (hard fail). * 2. Check for tamper_detected integrity (hard fail). * 3. Check verifier result against config (configurable gate). * 4. Return success / neutral with full comment data. */ export declare function evaluateChainGate(input: ChainGateInput): ChainGateResult; export interface GatePrCommentOptions { runId?: string; chainId?: string; handoffId?: string; producerRunId?: string; prNumber?: number; headSha?: string; } /** * Renders an Infracost-style GitHub PR comment summarising the gate result. * * Hard failures and cost overruns are shown prominently. * Cost is always present when provided — never omitted, never a blocking signal. * Lineage fields (chainId, producerRunId, runId) provide audit trail links. */ export declare function renderGatePrComment(result: ChainGateResult, options?: GatePrCommentOptions): string;