/** * src/gates/paths.ts — path-policy gates (pure). Ported verbatim from the ZOB * harness safety gates. Uses only node builtins and src/core/paths helpers. */ /** * Resolve the child working directory, ensuring it stays inside the repo root. */ export declare function resolveChildCwd(repoRoot: string, requestedCwd: string | undefined): { cwd: string; errors: string[]; }; /** * Validate an allowed-path policy list: each entry must be repo-relative, * inside the repo, with no NUL bytes, broad roots, absolute/home paths, or * traversal segments. Returns an array of errors. */ export declare function validateAllowedPathPolicy(paths: string[] | undefined, label: string, repoRoot: string): string[]; /** * Validate a forbidden (deny-only) path policy list: no NUL bytes, no broad * deny patterns, and repo-relative deny patterns must stay inside the repo. */ export declare function validateForbiddenPathPolicy(paths: string[] | undefined, label: string, repoRoot: string): string[]; /** * Path-policy gate for allowed-path lists (aliases the allowed-path validator). */ export declare function validatePathPolicy(paths: string[] | undefined, label: string, repoRoot: string): string[]; /** * Parse a path-list environment variable (comma, colon, or newline separated). */ export declare function parsePathListEnv(value: string | undefined): string[];