/** * src/gates/write-scope.ts — runtime/delegation write-scope gates plus sandbox, * diff-gate, rollback metadata builders and child env construction. * * Pure gates (validateRuntimeWritePolicy, validateDelegationWriteScope, * validateDelegateTaskWriteScope) have no side effects. The metadata builders * and buildChildEnv are STATEFUL (timestamps / base env) and therefore accept * injectable inputs (`now`, `baseEnv`) so they stay testable. Zero * @earendil-works/* imports. */ import type { BudgetSidecar } from "./types.js"; /** * Runtime write-policy gate: checks a target path against zero-access, * forbidden, read-only, allowed-path, and sandbox-root policies. Returns a * boolean allow decision plus the list of violations. */ export declare function validateRuntimeWritePolicy(input: { targetPath: string; cwd: string; policyRoot?: string; allowedPaths?: string[]; forbiddenPaths?: string[]; zeroAccessPaths?: string[]; readOnlyPaths?: string[]; sandboxRoot?: string; }): { allowed: boolean; violations: string[]; }; /** * Delegation write-scope gate: write/edit tools require non-empty allowed_paths. */ export declare function validateDelegationWriteScope(source: string, requiredTools: string[], allowedPaths: string[] | undefined): string[]; /** `delegate_task`-flavoured write-scope gate (aliases the generic validator). */ export declare function validateDelegateTaskWriteScope(requiredTools: string[], allowedPaths: string[] | undefined): string[]; /** * Build sandbox metadata envelope. STATEFUL (`createdAt`); the timestamp is * injectable via `now` for deterministic tests. */ export declare function createSandboxMetadata(input: { runId: string; repoRoot: string; sandboxRoot: string; allowedPaths?: string[]; forbiddenPaths?: string[]; budget?: BudgetSidecar; }, now?: string): Record; /** * Build diff-gate result envelope. STATEFUL (`evaluatedAt`); injectable `now`. */ export declare function createDiffGateResult(input: { runId: string; diffHash?: string; changedPaths?: string[]; allowed: boolean; violations?: string[]; }, now?: string): Record; /** * Build rollback metadata envelope. STATEFUL (`createdAt`); injectable `now`. */ export declare function createRollbackMetadata(input: { runId: string; baseRef?: string; snapshotPath?: string; changedPaths?: string[]; }, now?: string): Record; /** * Build the child process env. STATEFUL: reads a base env (default * `process.env`) and injects ZOB path-policy vars. The base env is injectable * via `baseEnv` for deterministic tests. Zero direct non-injectable env reads * once a caller passes `baseEnv`. */ export declare function buildChildEnv(repoRoot: string, pathPolicy?: { allowedPaths?: string[]; forbiddenPaths?: string[]; sandboxRoot?: string; }, baseEnv?: NodeJS.ProcessEnv): NodeJS.ProcessEnv;