/** * Finding out who the user is on their OWN machine, so remote-agent mode * doesn't have to ask. * * The reverse tunnel already reaches the user's sshd; once their key is * authorized, `whoami` over it answers the question exactly. The only guess is * which login to attempt, and the server's own username is both the common * answer and precisely what a bare `ssh localhost` would try. */ /** Logins worth trying, best first: an explicit hint, then the server's own. */ export declare function candidateUsernames(serverUser: string, hint?: string): string[]; /** The login reported by the remote `whoami`, or null if nothing usable came back. */ export declare function parseWhoami(stdout: string): string | null; /** * Try each candidate login over the reverse channel and return the first that * authenticates, as the remote host itself reports it. null = nobody answered * (tunnel down, key not authorized yet, or a different login) — the caller * must then ask, and say plainly that this is what it needs. */ export declare function discoverRemoteUser(port: number, hint?: string): Promise; /** Where the pushed token lives on the user's machine ($HOME-relative). */ export declare const REMOTE_TOKEN_PATH = ".nebula/token"; /** * Deliver an auth token to the user's machine over the reverse channel so the * remote agent's `nebula` CLI authenticates with a real credential — instead * of relying on the loopback piggyback, which silently dies the moment its * tunnel terminates on a different host than the server (2026-08-17). * * The token travels on ssh's STDIN only: never in argv (visible in `ps` and * shell history on a shared login node), never echoed. Written 0600 under a * private dir, atomically, and acknowledged with a marker so a half-written * or missing file is reported as failure, not success. */ export declare function pushRemoteAgentToken(port: number, user: string, token: string, timeoutMs?: number): Promise;