/** * Context Handoff Verifier — A-CTX-2 * * Pure functions for verifying upstream-to-downstream context handoffs and * deciding whether to circuit-break before the downstream agent executes. * * Standing rules: * - These functions are pure and side-effect-free. * - verifyContextHandoff fails closed — any ambiguity → not ok. * - decideContextCircuitBreak is the sole gate before adapter execution. * - The downstream adapter MUST NOT be called when shouldStop is true. */ import type { ContextCircuitBreakResult, ContextHandoffReceipt, ContextHandoffVerification } from "../contracts/index.js"; export interface VerifyContextHandoffInput { handoff: ContextHandoffReceipt; /** true when the producer receipt file hash has been independently confirmed */ producerReceiptVerified: boolean; /** Map of sha256 → true for every artifact hash available to the verifier */ availableArtifacts: ReadonlyMap; } /** * Deterministically verifies a context handoff. * * Returns ok=false when ANY of the following is true: * - schemaVersion is not in SUPPORTED_SCHEMAS * - producerReceiptVerified is false * - upstreamIntegrity is not "verified" * - a required artifact is absent from availableArtifacts * - an artifact sha256 does not appear in availableArtifacts (hash changed) * - any required claim has state "unverified" or "rejected" * - any claim has state "unknown" * - unresolvedAssumptions is non-empty * - handoffId, chainId, producerRunId, or producerReceiptHash is blank */ export declare function verifyContextHandoff(input: VerifyContextHandoffInput): ContextHandoffVerification; /** * Converts a ContextHandoffVerification into a gate decision. * * Healthy: { shouldStop: false, silent: true } * Broken: { shouldStop: true, silent: false, reasonCode, message, nextAction } */ export declare function decideContextCircuitBreak(verification: ContextHandoffVerification): ContextCircuitBreakResult;