import type { CleanupRecord } from './errors.js'; import { type AttachmentRecord } from './identity.js'; import type { AttachmentId, ByteLimit, Capacity, ClientId, GenerationId, IpcOperationCorrelation, IpcVersionAxes, OpaqueId, OwnedBytes, SerializableRecord } from './primitives.js'; import type { BoundedAsyncStream } from './streams.js'; /** Two overlapping bootstraps support React StrictMode handoff without permitting unbounded amplification. */ export declare const ELECTRON_MAX_ACTIVE_RENDERER_LEASES_PER_IDENTITY = 2; /** Framework-neutral name for the bounded overlapping client lease policy. */ export declare const IPC_MAX_ACTIVE_CLIENT_LEASES_PER_IDENTITY = 2; /** Trusted-host permissions for security-sensitive desktop IPC operations. */ export type IpcSecurityPermission = 'security:state' | 'security:pair' | 'security:cancel-pairing' | 'security:unpair' | 'security:custom-ceremony'; export interface RendererIdentity { readonly clientId: ClientId; readonly windowScope: string; readonly sessionScope: string; } /** Main-issued lifetime identity for one renderer bootstrap, independent of authenticated sender identity. */ export interface RendererLeaseIdentity { readonly leaseId: OpaqueId<'renderer-lease'>; readonly generation: GenerationId<'renderer-lease-generation', string>; } /** Main-process authentication facts derived from Electron's sender, never renderer input. */ export interface TrustedIpcSender { readonly authenticatedClientId: ClientId; readonly authenticatedWindowScope: string; readonly authenticatedSessionScope: string; /** Derived by the main process; renderer payloads cannot grant or change it. */ readonly securityPermissions?: readonly IpcSecurityPermission[]; } /** Framework-neutral aliases used by desktop webview transports such as Tauri. */ export type IpcClientIdentity = RendererIdentity; export type IpcClientLeaseIdentity = RendererLeaseIdentity; export type TrustedIpcCaller = TrustedIpcSender; /** Fixed limits owned by the main process for one attached Electron backend. */ export interface IpcQuota { readonly maximumMessageBytes: ByteLimit; readonly maximumOutstandingOperations: Capacity; readonly maximumRetainedBytes: ByteLimit; } /** * Untrusted renderer request. Attachment and versions are checked against the * main-process authority; renderer code cannot select quotas or other limits. */ export interface IpcEnvelope { readonly versions: IpcVersionAxes; readonly attachment: AttachmentRecord; readonly attachmentId: AttachmentId; readonly renderer: RendererIdentity; readonly rendererLease: RendererLeaseIdentity; readonly correlation: IpcOperationCorrelation; readonly dispatchEpoch: GenerationId<'ipc-dispatch-epoch', `${Attachment}:${Operation}`>; readonly command: string; readonly payload: SerializableRecord; readonly binaryPayload: OwnedBytes | null; readonly quota?: never; } export interface RendererSnapshot { readonly attachment: AttachmentRecord; readonly attachmentId: AttachmentId; readonly renderer: RendererIdentity; readonly rebindRequired: true; readonly activeLeaseCount: number; readonly activeLeases: readonly string[]; readonly attachmentGeneration: GenerationId<'backend-generation', Attachment>; readonly restorable: false; } /** Immutable main-process configuration for exactly one attached backend generation. */ export interface ElectronMainArbiterAuthority { readonly attachment: AttachmentRecord; readonly versions: IpcVersionAxes; readonly quota: IpcQuota; } /** Routing hooks receive requests only after all authority checks have completed. */ export interface ElectronMainArbiterHandlers { route(envelope: IpcEnvelope): Promise; release(identity: RendererIdentity, lease: RendererLeaseIdentity): Promise; } export interface ElectronMainArbiter { registerRenderer(identity: RendererIdentity, versions?: IpcVersionAxes): RendererLeaseIdentity; route(sender: TrustedIpcSender, envelope: IpcEnvelope): Promise; releaseRenderer(sender: TrustedIpcSender, lease: RendererLeaseIdentity): Promise; } /** * Main-process IPC authority. It owns the current full attachment tuple, * negotiated version axes, and hard quotas rather than trusting renderer data. */ export declare class IpcArbiterContext implements ElectronMainArbiter { /** * Safety bound on terminal notices retained for renderer replay. * * A trust-boundary quota, deliberately not renderer-configurable: it bounds * how much main-process memory a reloading renderer can pin while it re-reads * the terminal outcomes it missed. */ private static readonly maximumTerminalReplayEntries; private readonly renderers; private readonly authority; private readonly handlers; private nextRendererLease; constructor(authority: ElectronMainArbiterAuthority, handlers: ElectronMainArbiterHandlers); registerRenderer(identity: RendererIdentity, versions?: IpcVersionAxes, securityPermissions?: readonly IpcSecurityPermission[]): RendererLeaseIdentity; route(sender: TrustedIpcSender, envelope: IpcEnvelope): Promise; releaseRenderer(sender: TrustedIpcSender, lease: RendererLeaseIdentity): Promise; private assertRendererDoesNotSupplyAuthority; private assertSender; private assertSecurityPermissions; private assertRegisteredRenderer; private assertRendererActive; private assertAttachment; private assertVersions; private prepareEnvelope; private requireAccounting; private reserveOperation; private markReplayTerminal; /** * Retains settled replay keys only while their exact byte accounting fits the * configured renderer budget and the bounded LRU window. A Map's insertion * order gives us deterministic eviction without timers or delayed cleanup. */ private trimTerminalReplayLedger; private oldestTerminalReplayKey; } /** Framework-neutral authority aliases. Electron names remain source-compatible for 4.0 migration. */ export type IpcArbiterAuthority = ElectronMainArbiterAuthority; export type IpcArbiterHandlers = ElectronMainArbiterHandlers; export type IpcArbiter = ElectronMainArbiter; export interface ElectronRendererBoundary { readonly identity: RendererIdentity; readonly events: BoundedAsyncStream; snapshot(): Promise>; } //# sourceMappingURL=ipc.d.ts.map