/** * child/policy.ts — pure child write-safety policy. * * EXACT port of the harness `.pi/extensions/zob-child-safety/src/policy.ts`. * Kept 100% pure (node:path / node:os only, zero @earendil-works/* imports, * invariant I9) so it can run headless inside child lanes. The child extension * adapter (child/index.ts) registers the safety guard over the edit/write * tools using this policy. */ export interface DamageRule { pattern: string; reason: string; ask?: boolean; } export interface DamageRules { bashToolPatterns: DamageRule[]; zeroAccessPaths: string[]; readOnlyPaths: string[]; noDeletePaths: string[]; } export declare const DEFAULT_RULES: DamageRules; export declare function pathMatches(targetPath: string, pattern: string, cwd: string, policyRoot?: string): boolean; export declare function parsePathListEnv(value: string | undefined): string[]; export declare function validateRuntimeWritePolicy(input: { targetPath: string; cwd: string; policyRoot?: string; allowedPaths?: string[]; forbiddenPaths?: string[]; zeroAccessPaths?: string[]; readOnlyPaths?: string[]; sandboxRoot?: string; }): { allowed: boolean; violations: string[]; }; export declare function blockedFeedback(toolName: string, reason: string, attempted: string): string;