/** * child/index.ts — child extension adapter (standalone port of the harness * `.pi/extensions/zob-child-safety/index.ts`). * * Loaded inside child lanes via `-e`. Registers the write-safety guard over * the edit/write tools: blocks writes outside allowed/forbidden/zero-access/ * read-only/sandbox rules via validateRuntimeWritePolicy + blockedFeedback. * * Uses the LOCAL child/pi-types.ts mirror (zero @earendil-works/* imports, * invariant I9); the real Pi API is wired at load time by the child runner. */ import type { ExtensionAPI } from "./pi-types.js"; export { pathMatches, parsePathListEnv, validateRuntimeWritePolicy } from "./policy.js"; export { ESCALATION_DIR_ENV, ESCALATION_EXIT_CODE, RUN_ID_ENV, escalationFilePath, escalationMessageHash, isSubagentSession, writeEscalationFile, } from "./escalation.js"; export { AGENTS_DIR_ENV, ALLOWED_SUBAGENTS_ENV, DEPTH_ENV, MAX_DEPTH_ENV, NESTED_ENV, SUBAGENT_TOOL_NAME, agentAllowed, nestedToolEnabled, parseAllowlist, registerNestedSubagentTool, } from "./nested.js"; /** Env var carrying the absolute path of this run's `.steer` file (B2). */ export declare const STEER_FILE_ENV = "PI_SUBAGENTS_STEER_FILE"; /** Steer payload consumed from the file written by the parent (src/lanes/steer.ts). */ export interface ConsumedSteerPayload { runId: string; message: string; timestamp: number; } /** * Consume-once read of the steer file (the parent writes it atomically via * rename, so a read never observes a partial payload). Deletes the file as * soon as it is read so the same steering message can never be injected * twice; an unreadable/invalid payload is still consumed (and dropped) so a * corrupt file cannot wedge the poll loop. * * Returns null when there is nothing to inject: no env var, no file, a * read race, or an invalid/empty payload. */ export declare function consumeSteerFile(steerFile: string | undefined): ConsumedSteerPayload | null; export default function zobChildSafety(pi: ExtensionAPI): void;