import { type ParseResult, type VisualBrowserInput, type VisualDiagnosticResult, type VisualEvent, type VisualHandoff, type VisualModel, type VisualResponse, type VisualSessionDescriptor, type VisualSessionRequest, type VisualSessionStarted, type VisualStatus } from './protocol-contract.js'; export * from './protocol-contract.js'; /** * The one way this adapter mints a source digest. * * `visual-model/v1` requires a canonical model to record the digests it was * derived from (`YMVS112`) and pins their shape to 64 lowercase hex characters, * so the value lives beside the validator that enforces it: the request builder * mints them for the initial model, the session server re-mints them on every * recompile and checks a commit's pins against the files on disk, and all three * are the same hash by construction rather than by three matching literals. * * There is a fourth, and it is not by construction. A commit's pins become the * `expected` revisions a `SourceStore` compares before it writes (ADR 0100), * and a store's revision is opaque: what `createFileSystemStore` mints happens * to be this same sha256, which is the only reason a pin can be handed to it * directly. The visual runtime only ever addresses a local filesystem, so that * coincidence is safe today and a protocol version spent on carrying opaque * revisions instead would buy nothing. It is held by a test rather than by a * comment: `visual-protocol.test.ts` asserts the two agree, so a change to * either side fails rather than silently making every commit's precondition * unsatisfiable. That failure is when the protocol bump earns its cost. */ export declare const digestOf: (source: string) => string; /** * Encode a native absolute path for the wire. * * Every filesystem path a protocol document carries is a canonical local * `file:` URI, minted by Node's own `pathToFileURL`. A URI is invertible * where the forward-slash string transform it replaces was not: a POSIX * directory whose own name contains a literal backslash percent-encodes to * `%5C` and stays distinguishable from a Windows separator, and a UNC path * grows a non-empty host rather than passing as an ordinary POSIX-rooted * path. * * Encoding cannot fail. `pathToFileURL` has no error path for an * already-absolute native string, and every caller holds a `resolve`/`join` * result it produced itself. A relative path reaching here is a programming * error rather than a protocol fault, and throws as one. */ export declare const toWireFileUri: (native: string) => string; /** Why one wire path was refused. Each shape is reported as `YMVS414`. */ export type WireFileUriRefusal = 'malformed' | 'nonlocal' | 'noncanonical'; export type WireFileUriResult = { readonly ok: true; readonly value: string; } | { readonly ok: false; readonly reason: WireFileUriRefusal; }; /** * Decode a wire path back to native, the way untrusted input has to be read. * * A descriptor's bearer capabilities are never spent on a document whose path * fields have not passed this first, so the three refusals are checked in a * fixed order and none of them is ever quietly repaired: * * - `malformed` — not a parseable `file:` URI, or one `fileURLToPath` itself * rejects (`ERR_INVALID_URL`, `ERR_INVALID_URL_SCHEME`, * `ERR_INVALID_FILE_URL_PATH`). A bare native path lands here too: it has * no scheme, or, for a Windows drive root, one that is not `file:`. * - `nonlocal` — a non-empty host, which `pathToFileURL` never produces for a * local path: `file://server/share/x` names a network share. The host is * read off the parsed URL rather than inferred from a `fileURLToPath` * failure, because that call refuses a foreign host on POSIX but resolves * one to a UNC path on Windows, and reading it directly is the only way one * URI earns the same refusal on both. * - `noncanonical` — decodes, host is empty, but re-encoding the decoded path * does not reproduce the input byte-for-byte. Two spellings of one target is * the aliasing this representation exists to close, so the other spelling is * refused rather than normalized into the canonical one. `file://localhost/x` * lands here rather than in `nonlocal`: WHATWG `URL` normalizes a * `localhost` file host away, leaving a URI that is simply not the spelling * this codec mints for `/x`. */ export declare const fromWireFileUri: (uri: string) => WireFileUriResult; export declare const parseVisualModel: (input: unknown) => ParseResult; export declare const parseVisualSessionRequest: (input: unknown) => ParseResult; export declare const parseVisualSessionStarted: (input: unknown) => ParseResult; export declare const parseVisualSessionDescriptor: (input: unknown) => ParseResult; /** * The type an untrusted frame claims to be, when the protocol has that type. * * A refusal has to say what it refused, and the browser is holding a control * open until it does. The claim is worth reporting before the document is * known to be valid because the frame that named it is the one that failed. */ export declare const visualBrowserInputType: (input: unknown) => VisualBrowserInput['type'] | undefined; export declare const parseVisualBrowserInput: (input: unknown) => ParseResult; export declare const parseVisualEvent: (input: unknown) => ParseResult; export declare const parseVisualResponse: (input: unknown) => ParseResult; export declare const parseVisualHandoff: (input: unknown) => ParseResult; export declare const parseVisualStatus: (input: unknown) => ParseResult; export declare const parseVisualDiagnosticResult: (input: unknown) => ParseResult;