@anthropic-ai/claude-agent-sdk
Version:
SDK for building AI agents with Claude Code's capabilities. Programmatically interact with Claude to build autonomous agents that can understand codebases, edit files, and execute workflows.
41 lines • 474 kB
JavaScript
// (c) Anthropic PBC. All rights reserved. Use is subject to the Legal Agreements outlined here: https://code.claude.com/docs/en/legal-and-compliance.
// Version: 0.3.295
// symbol-dispose-prelude: bun build --banner for every SDK bundle; the build
// scripts grep for this line's tag. Runs before any module body. bun lowers
// `using` to a helper that keys disposal on the registry symbol when the
// well-known one is missing, while disposable objects key on the well-known
// global directly; on engines without a native `Symbol.dispose` (Safari/iOS,
// Firefox ESR, `node:vm` contexts on Node <=22 such as Jest's `node`
// environment and vitest's vm pools, and Node before 18.18 / 20.4) the two
// disagree and every lowered `using` throws. Registering both symbols first
// makes the keys agree; a no-op where they are native, and a locked-down
// `Symbol` (SES lockdown) keeps today's behaviour instead of failing to load.
if (typeof Symbol.dispose !== 'symbol') {
try {
Symbol.dispose = Symbol.for('Symbol.dispose')
} catch {}
}
if (typeof Symbol.asyncDispose !== 'symbol') {
try {
Symbol.asyncDispose = Symbol.for('Symbol.asyncDispose')
} catch {}
}
import{D,$t,p,f,U,h,E,T,g,_e,F,qe,Xe,Ee,ye,be,d,Je,Ze,Ce,S,Y,H,te,Ae,B,Re,Qe,Oe,et,ne,K,Ue,re,q,P,l,a,o,de,i,Te,xe,oe,tt,we,k,x,se,nt,ve,j,z,ke,b,X,Ot,y,n,_,w,u,He,J,ie,vt,ae,kt,M,Z,rt,Be,Ke,R,le,pe,G,je,ze,fe,Ge,We,St,Dt,ot,ge,_t,De,m,Nt,at,t,O,W,yt,bt,N,lt,Ct,Pe,ct,Ie,Ft,s,At,V,Ht,Le,Q,Me,$e,e,ut,dt,pt,C,Ve,ee,r,he,Ye,v,Kt,ue,ft,Se,zt,Gt}from"./core-reghh1vn.mjs";import{resolve as tV}from"path";var qm=Object.prototype,Qm=qm.hasOwnProperty;function eg(c,A,L){var ce=c[A];if(!(Qm.call(c,A)&&U(ce,L))||L===void 0&&!(A in c))oe(c,A,L)}var Ao=eg;function tg(c,A,L,ce){if(!g(c))return c;A=k(A,c);var me=-1,Ne=A.length,Fe=Ne-1,st=c;while(st!=null&&++me<Ne){var gt=x(A[me]),ht=L;if(gt==="__proto__"||gt==="constructor"||gt==="prototype")return c;if(me!=Fe){var Et=st[gt];if(ht=ce?ce(Et,gt,st):void 0,ht===void 0)ht=g(Et)?Et:te(A[me+1])?[]:{}}Ao(st,gt,ht),st=st[gt]}return c}var rl=tg;function ng(c,A,L){var ce=-1,me=A.length,Ne={};while(++ce<me){var Fe=A[ce],st=se(c,Fe);if(L(st,Fe))rl(Ne,k(Fe,c),st)}return Ne}var Mr=ng;var og=et(Object.getPrototypeOf,Object),bo=og;var rg=Object.getOwnPropertySymbols,sg=!rg?Ze:function(c){var A=[];while(c)be(A,Ce(c)),c=bo(c);return A},Ur=sg;function ig(c){var A=[];if(c!=null)for(var L in Object(c))A.push(L);return A}var sl=ig;var ag=Object.prototype,lg=ag.hasOwnProperty;function cg(c){if(!g(c))return sl(c);var A=Oe(c),L=[];for(var ce in c)if(!(ce=="constructor"&&(A||!lg.call(c,ce))))L.push(ce);return L}var il=cg;function dg(c){return ne(c)?Qe(c,!0):il(c)}var kn=dg;function ug(c){return Je(c,kn,Ur)}var Co=ug;function pg(c,A){if(c==null)return{};var L=we(Co(c),function(ce){return[ce]});return A=j(A),Mr(c,L,function(ce,me){return A(ce,me[0])})}var Hr=pg;import{join as Oo}from"path";import{dirname as XM}from"path";var ei={};D(ei,{AGENT_PROXY_AUTH_TOKEN:()=>Ng,ANTHROPIC_API_KEY:()=>yg,ANTHROPIC_AUTH_TOKEN:()=>Og,ANTHROPIC_AWS_API_KEY:()=>Cg,ANTHROPIC_FEDERATION_RULE_ID:()=>_h,ANTHROPIC_FOUNDRY_API_KEY:()=>Tg,ANTHROPIC_FOUNDRY_AUTH_TOKEN:()=>Rg,ANTHROPIC_ORGANIZATION_ID:()=>yh,ANTHROPIC_PROFILE:()=>Ah,ANTHROPIC_WORKSPACE_ID:()=>Oh,AWS_BEARER_TOKEN_BEDROCK:()=>bg,AWS_CONTAINER_CREDENTIALS_FULL_URI:()=>Pg,AWS_CONTAINER_CREDENTIALS_RELATIVE_URI:()=>Ig,AWS_ROLE_ARN:()=>Lg,AWS_WEB_IDENTITY_TOKEN_FILE:()=>Dg,CLAUDE_CODE_ACCOUNT_TAGGED_ID:()=>Ch,CLAUDE_CODE_ACCOUNT_UUID:()=>bh,CLAUDE_CODE_API_KEY_FILE_DESCRIPTOR:()=>Ug,CLAUDE_CODE_API_KEY_HELPER_TTL_MS:()=>ah,CLAUDE_CODE_AUTH_FAIL_EXIT_MS:()=>ih,CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS:()=>Eh,CLAUDE_CODE_CUSTOM_OAUTH_URL:()=>Vg,CLAUDE_CODE_DESIGN_OAUTH_CLIENT_ID:()=>jg,CLAUDE_CODE_ENABLE_PROXY_AUTH_HELPER:()=>lh,CLAUDE_CODE_FEDERATION_CACHE_DIR:()=>Sh,CLAUDE_CODE_GATEWAY_TOKEN_FILE_DESCRIPTOR:()=>zg,CLAUDE_CODE_HFI_BEARER_TOKEN:()=>xg,CLAUDE_CODE_HOST_AUTH_ENV_VAR:()=>Jg,CLAUDE_CODE_HOST_AUTH_REFRESH_TIMEOUT_MS:()=>Xg,CLAUDE_CODE_HOST_CREDS_FILE:()=>Zg,CLAUDE_CODE_OAUTH_401_WAIT_MS:()=>sh,CLAUDE_CODE_OAUTH_CLIENT_ID:()=>Wg,CLAUDE_CODE_OAUTH_REFRESH_TOKEN:()=>Gg,CLAUDE_CODE_OAUTH_SCOPES:()=>$g,CLAUDE_CODE_OAUTH_TOKEN:()=>Ag,CLAUDE_CODE_OAUTH_TOKEN_FILE_DESCRIPTOR:()=>Hg,CLAUDE_CODE_ORGANIZATION_UUID:()=>Th,CLAUDE_CODE_PROXY_AUTH_HELPER_TTL_MS:()=>ch,CLAUDE_CODE_RATE_LIMIT_TIER:()=>Lh,CLAUDE_CODE_SDK_HAS_HOST_AUTH_REFRESH:()=>Yg,CLAUDE_CODE_SDK_HAS_OAUTH_REFRESH:()=>Kg,CLAUDE_CODE_SESSION_ACCESS_TOKEN:()=>qg,CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH:()=>fh,CLAUDE_CODE_SKIP_ANTHROPIC_GOOGLE_CLOUD_AUTH:()=>mh,CLAUDE_CODE_SKIP_AWS_CRED_CACHE:()=>hh,CLAUDE_CODE_SKIP_BEDROCK_AUTH:()=>dh,CLAUDE_CODE_SKIP_FOUNDRY_AUTH:()=>ph,CLAUDE_CODE_SKIP_MANTLE_AUTH:()=>gh,CLAUDE_CODE_SKIP_VERTEX_AUTH:()=>uh,CLAUDE_CODE_SUBSCRIPTION_TYPE:()=>Dh,CLAUDE_CODE_USER_EMAIL:()=>Rh,CLAUDE_CODE_WEBSOCKET_AUTH_FILE_DESCRIPTOR:()=>Fg,CLAUDE_LOCAL_OAUTH_API_BASE:()=>nh,CLAUDE_LOCAL_OAUTH_APPS_BASE:()=>oh,CLAUDE_LOCAL_OAUTH_CONSOLE_BASE:()=>rh,CLAUDE_SESSION_INGRESS_TOKEN_FILE:()=>Bg,CLAUDE_TRUSTED_DEVICE_TOKEN:()=>Qg,CLOUDSDK_AUTH_ACCESS_TOKEN:()=>wg,ENVIRONMENT_SERVICE_KEY:()=>vg,MCP_CLIENT_SECRET:()=>kg,MCP_XAA_IDP_CLIENT_SECRET:()=>Mg,USE_LOCAL_OAUTH:()=>eh,USE_STAGING_OAUTH:()=>th});function To(c){return{parse:(A)=>c(mg(A))}}function fg(c){let A=c?.trim();return A?A:void 0}function mg(c){return c===void 0?void 0:String(c)}var gg=To(fg),hg=To((c)=>c),Eg=To((c)=>o(c)),_g=To((c)=>{if(o(c))return!0;if(de(c))return!1;return}),Sg=ll();function al(c){if(typeof c==="boolean")return c?"1":"0";return String(c)}var I={str:()=>gg,rawStr:()=>hg,bool:()=>Eg,triBool:()=>_g,int:(c)=>c?ll(c):Sg,enum:(c)=>To((A)=>A!==void 0&&c.includes(A.trim())?A.trim():void 0)};function ll(c){return To((A)=>{if(A===void 0)return;if(c?.digitsOnly&&!/^[+-]?\d+$/.test(A.trim()))return;if(c?.wholeValue&&!/^[+-]?\d+$/.test(A.trim())&&_t(A.trim())===void 0)return;let L=De(A);if(!Number.isFinite(L))return;if(c?.min!==void 0&&L<c.min)return;if(c?.max!==void 0&&L>c.max)return;return L})}var yg=I.str(),Og=I.str(),Ag=I.str(),bg=I.str(),Cg=I.str(),Tg=I.str(),Rg=I.str(),Dg=I.str(),Lg=I.str(),Ig=I.str(),Pg=I.str(),wg=I.str(),xg=I.str(),Ng=I.str(),vg=I.str(),kg=I.str(),Mg=I.str(),Ug=I.str(),Hg=I.str(),zg=I.str(),Fg=I.str(),Bg=I.str(),Gg=I.str(),Wg=I.str(),jg=I.str(),$g=I.str(),Vg=I.str(),Kg=I.bool(),Yg=I.bool(),Xg=I.int({min:1}),Jg=I.str(),Zg=I.str(),qg=I.str(),Qg=I.str(),eh=I.bool(),th=I.bool(),nh=I.str(),oh=I.str(),rh=I.str(),sh=I.int({min:0}),ih=I.int({min:0}),ah=I.int(),lh=I.bool(),ch=I.int(),dh=I.bool(),uh=I.bool(),ph=I.bool(),fh=I.bool(),mh=I.bool(),gh=I.bool(),hh=I.bool(),Eh=I.int({min:1,max:2147483647}),_h=I.str(),Sh=I.str(),yh=I.str(),Oh=I.str(),Ah=I.str(),bh=I.str(),Ch=I.str(),Th=I.str(),Rh=I.str(),Dh=I.str(),Lh=I.str();var ti={};D(ti,{ANT_CLAUDE_CODE_METRICS_ENDPOINT:()=>HE,ANT_OTEL_EXPORTER_OTLP_ENDPOINT:()=>wE,ANT_OTEL_EXPORTER_OTLP_HEADERS:()=>xE,ANT_OTEL_EXPORTER_OTLP_PROTOCOL:()=>NE,ANT_OTEL_LOGS_EXPORTER:()=>vE,ANT_OTEL_METRICS_EXPORTER:()=>kE,ANT_OTEL_RESOURCE_ATTRIBUTES:()=>UE,ANT_OTEL_TRACES_EXPORTER:()=>ME,BETA_TRACING_ENDPOINT:()=>zE,CLAUDE_CODE_BENCH_LIVE_COUNTS:()=>Vh,CLAUDE_CODE_BYOC_ENABLE_DATADOG:()=>Qh,CLAUDE_CODE_DATADOG_FLUSH_INTERVAL_MS:()=>Zh,CLAUDE_CODE_DD_ERROR_TRACKING_FLUSH_INTERVAL_MS:()=>qh,CLAUDE_CODE_DEBUG_LOGS_DIR:()=>xh,CLAUDE_CODE_DEBUG_LOG_LEVEL:()=>wh,CLAUDE_CODE_DEBUG_REPAINTS:()=>Nh,CLAUDE_CODE_DIAGNOSTICS_FILE:()=>vh,CLAUDE_CODE_ENHANCED_TELEMETRY_BETA:()=>Kh,CLAUDE_CODE_FRAME_TIMING_LOG:()=>Fh,CLAUDE_CODE_FRAME_TIMING_SAMPLE_EVERY:()=>Bh,CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH:()=>CE,CLAUDE_CODE_OTEL_DIAG_STDERR:()=>eE,CLAUDE_CODE_OTEL_FLUSH_TIMEOUT_MS:()=>Yh,CLAUDE_CODE_OTEL_HEADERS_HELPER_DEBOUNCE_MS:()=>Jh,CLAUDE_CODE_OTEL_SHUTDOWN_TIMEOUT_MS:()=>Xh,CLAUDE_CODE_PERFETTO_TRACE:()=>Hh,CLAUDE_CODE_PERFETTO_WRITE_INTERVAL_S:()=>zh,CLAUDE_CODE_PROFILE_STARTUP:()=>Uh,CLAUDE_CODE_SESSION_LOG:()=>Gh,CLAUDE_CODE_TEE_SDK_STDOUT:()=>$h,CLAUDE_CODE_TERMINAL_RECORDING:()=>jh,CLAUDE_DEBUG:()=>Ih,CLAUDE_PTY_RECORD:()=>Wh,DEBUG:()=>Ph,DEBUG_CLAUDE_AGENT_SDK:()=>kh,DEBUG_SDK:()=>Mh,OTEL_ATTRIBUTE_VALUE_LENGTH_LIMIT:()=>OE,OTEL_EXPORTER_OTLP_ENDPOINT:()=>rE,OTEL_EXPORTER_OTLP_HEADERS:()=>sE,OTEL_EXPORTER_OTLP_LOGS_ENDPOINT:()=>aE,OTEL_EXPORTER_OTLP_LOGS_HEADERS:()=>lE,OTEL_EXPORTER_OTLP_LOGS_PROTOCOL:()=>cE,OTEL_EXPORTER_OTLP_METRICS_ENDPOINT:()=>dE,OTEL_EXPORTER_OTLP_METRICS_HEADERS:()=>uE,OTEL_EXPORTER_OTLP_METRICS_PROTOCOL:()=>pE,OTEL_EXPORTER_OTLP_METRICS_TEMPORALITY_PREFERENCE:()=>fE,OTEL_EXPORTER_OTLP_PROTOCOL:()=>iE,OTEL_EXPORTER_OTLP_TRACES_ENDPOINT:()=>mE,OTEL_EXPORTER_OTLP_TRACES_HEADERS:()=>gE,OTEL_EXPORTER_OTLP_TRACES_PROTOCOL:()=>hE,OTEL_LOGRECORD_ATTRIBUTE_VALUE_LENGTH_LIMIT:()=>AE,OTEL_LOGS_EXPORTER:()=>nE,OTEL_LOGS_EXPORT_INTERVAL:()=>_E,OTEL_LOG_ASSISTANT_RESPONSES:()=>RE,OTEL_LOG_MANAGED_SETTINGS:()=>IE,OTEL_LOG_RAW_API_BODIES:()=>PE,OTEL_LOG_TOOL_CONTENT:()=>DE,OTEL_LOG_TOOL_DETAILS:()=>LE,OTEL_LOG_USER_PROMPTS:()=>TE,OTEL_METRICS_EXPORTER:()=>tE,OTEL_METRIC_EXPORT_INTERVAL:()=>EE,OTEL_RESOURCE_ATTRIBUTES:()=>yE,OTEL_SPAN_ATTRIBUTE_VALUE_LENGTH_LIMIT:()=>bE,OTEL_TRACES_EXPORTER:()=>oE,OTEL_TRACES_EXPORT_INTERVAL:()=>SE});var Ih=I.bool(),Ph=I.str(),wh=I.str(),xh=I.str(),Nh=I.bool(),vh=I.str(),kh=I.bool(),Mh=I.bool(),Uh=I.bool(),Hh=I.str(),zh=I.int(),Fh=I.str(),Bh=I.int(),Gh=I.str(),Wh=I.str(),jh=I.str(),$h=I.bool(),Vh=I.bool(),Kh=I.bool(),Yh=I.int(),Xh=I.int(),Jh=I.int(),Zh=I.int({min:1}),qh=I.int({min:1}),Qh=I.bool(),eE=I.bool(),tE=I.str(),nE=I.str(),oE=I.str(),rE=I.str(),sE=I.str(),iE=I.str(),aE=I.str(),lE=I.str(),cE=I.str(),dE=I.str(),uE=I.str(),pE=I.str(),fE=I.str(),mE=I.str(),gE=I.str(),hE=I.str(),EE=I.int(),_E=I.int(),SE=I.int(),yE=I.str(),OE=I.int({min:0}),AE=I.int({min:0}),bE=I.int({min:0}),CE=I.int({min:1,digitsOnly:!0}),TE=I.bool(),RE=I.triBool(),DE=I.bool(),LE=I.bool(),IE=I.bool(),PE=I.bool(),wE=I.str(),xE=I.str(),NE=I.str(),vE=I.str(),kE=I.str(),ME=I.str(),UE=I.str(),HE=I.str(),zE=I.str();import{constants as WE}from"fs";import{access as ni,readdir as jE,readFile as $E,readlink as VE}from"fs/promises";import{homedir as KE}from"os";import{delimiter as YE,join as er,resolve as El}from"path";function cl(c){return!c.isDirectory()&&!c.isFile()&&!c.isSymbolicLink()&&!c.isFIFO()&&!c.isSocket()&&!c.isBlockDevice()&&!c.isCharacterDevice()}import{delimiter as oK,isAbsolute as FE}from"path";function BE(c){let A=process.cwd();return c.filter((L)=>!Be(L,A))}function dl(c){return GE(c,Bun.which(c))}function GE(c,A){if(!A||process.platform!=="win32"||FE(c))return A;return BE([A])[0]??null}var ul=async(c)=>dl(c),pl=dl;function fl(){if(process.platform!=="linux")return!1;return s().existsSync("/proc/sys/fs/binfmt_misc/WSLInterop")}function ml(){if(process.platform!=="linux")return;try{return s().readFileSync("/sys/hypervisor/uuid",{encoding:"utf8"}).trim().toLowerCase()}catch{return}}function gl(){if(process.platform!=="linux")return!1;return s().existsSync("/.dockerenv")}function XE(){if(s().existsSync(er(m(),".config.json")))return er(m(),".config.json");return JE()}function JE(){let c=`.claude${Kt()}.json`;return er(process.env.CLAUDE_CONFIG_DIR||KE(),c)}async function ZE(){return null}async function Ro(c){try{return!!await ul(c)}catch{return!1}}async function qE(){let c=[];if(await Ro("npm"))c.push("npm");if(await Ro("yarn"))c.push("yarn");if(await Ro("pnpm"))c.push("pnpm");return c}async function QE(){let c=[];if(await Ro("bun"))c.push("bun");if(await Ro("deno"))c.push("deno");if(await Ro("node"))c.push("node");return c}var hl=["git","node","npm","npx","yarn","pnpm","bun","deno","tsc","python","python3","py","pip","uv","poetry","ruby","gem","bundle","rake","dotnet","msbuild","nuget","cl","nmake","cmake","ninja","make","gcc","g++","clang","cargo","rustc","go","java","javac","mvn","gradle","docker"],e_=1000;async function t_(c){try{return/appinstaller/i.test(await VE(c))}catch{return!1}}async function n_(c){if(c===""||kt(c)||He(c))return!1;return!await Ct(El(c))}async function o_(c,A){let L=C()==="windows",ce=new Set(c),me=L?(process.env.PATHEXT??".COM;.EXE;.BAT;.CMD").toLowerCase().split(";").filter(Boolean):[],Ne=v((process.env.PATH??"").split(YE).map((Fe)=>Fe.replace(/^"|"$/g,"")).filter(Boolean));await Promise.all(Ne.map(async(Fe)=>{if(!await n_(Fe))return;let st;try{st=await jE(Fe,{withFileTypes:!0})}catch{return}let gt=L&&/[\\/]microsoft[\\/]windowsapps[\\/]?$/i.test(Fe);for(let ht of st){if(ht.isDirectory())continue;let Et=ht.name;if(L){let Rt=Et.toLowerCase(),Tt=Rt.lastIndexOf(".");if(Tt<=0||!me.includes(Rt.slice(Tt)))continue;Et=Rt.slice(0,Tt)}if(!ce.has(Et)||A.has(Et))continue;if(L){if(gt&&await t_(er(Fe,ht.name)))continue}else{let Rt=er(Fe,ht.name);if((ht.isSymbolicLink()||cl(ht))&&await Ct(El(Rt)))continue;try{await ni(Rt,WE.X_OK)}catch{continue}}A.add(Et)}}))}async function r_(){let c=new Set;try{await w(o_(hl,c),e_,"build tool PATH scan timed out")}catch{}return hl.filter((A)=>c.has(A))}function s_(c){try{if(!c.isWslEnvironment())return!1;let A=pl("npm");if(A===null)return!1;return A.startsWith("/mnt/c/")}catch(A){return!1}}function i_(){return process.env.__CFBundleIdentifier==="com.conductor.app"}var _l=["pycharm","intellij","webstorm","phpstorm","rubymine","clion","goland","rider","datagrip","appcode","dataspell","aqua","gateway","fleet","jetbrains","androidstudio"];function a_(c){let A=c.toLowerCase();return A.includes("windsurf")||A.includes("devin.app")||A.includes("devin desktop")||A.includes("devin-desktop")||/appdata[\\/]local[\\/](programs[\\/])?devin[\\/]/.test(A)}function l_(){if(process.env.CURSOR_TRACE_ID)return"cursor";let c=process.env.VSCODE_GIT_ASKPASS_MAIN?.toLowerCase()??"";if(c.includes("cursor"))return"cursor";if(a_(c))return"windsurf";if(c.includes("antigravity"))return"antigravity";let A=process.env.__CFBundleIdentifier?.toLowerCase();if(A?.includes("vscodium"))return"codium";if(A?.includes("windsurf")||A?.includes("devin"))return"windsurf";if(A?.includes("com.google.android.studio"))return"androidstudio";if(A){for(let L of _l)if(A.includes(L))return L}if(process.env.VisualStudioVersion)return"visualstudio";if(process.env.TERMINAL_EMULATOR==="JetBrains-JediTerm")return"pycharm";if(process.env.TERM==="xterm-ghostty")return"ghostty";if(process.env.TERM?.includes("kitty"))return"kitty";if(process.env.TERM_PROGRAM){if(/^devin([ -]desktop)?$/i.test(process.env.TERM_PROGRAM))return"windsurf";return process.env.TERM_PROGRAM}if(process.env.TMUX)return"tmux";if(process.env.STY)return"screen";if(process.env.KONSOLE_VERSION)return"konsole";if(process.env.GNOME_TERMINAL_SERVICE)return"gnome-terminal";if(process.env.XTERM_VERSION)return"xterm";if(process.env.VTE_VERSION)return"vte-based";if(process.env.TERMINATOR_UUID)return"terminator";if(process.env.KITTY_WINDOW_ID)return"kitty";if(process.env.ALACRITTY_LOG)return"alacritty";if(process.env.TILIX_ID)return"tilix";if(process.env.WT_SESSION)return"windows-terminal";if(process.env.SESSIONNAME&&process.env.TERM==="cygwin")return"cygwin";if(process.env.MSYSTEM)return process.env.MSYSTEM.toLowerCase();if(process.env.ConEmuANSI||process.env.ConEmuPID||process.env.ConEmuTask)return"conemu";if(process.env.WSL_DISTRO_NAME)return`wsl-${process.env.WSL_DISTRO_NAME}`;if(Ol())return"ssh-session";if(process.env.TERM){let L=process.env.TERM;if(L.includes("alacritty"))return"alacritty";if(L.includes("rxvt"))return"rxvt";if(L.includes("termite"))return"termite";return process.env.TERM}if(!process.stdout.isTTY)return"non-interactive";return null}class Sl{sources;globalClaudeFile;packageManagers;runtimes;detectedBuildTools;wslEnvironment;npmFromWindowsPath;deploymentEnvironment;primedWslInteropExists;primedHypervisorUuid;primedDockerenvExists;fallbackWslInteropExists;fallbackHypervisorUuid;fallbackDockerenvExists;constructor(c){this.sources=c}getGlobalClaudeFile(){return this.globalClaudeFile??=XE()}seedGlobalClaudeFile(c){if(this.globalClaudeFile===void 0)return this.globalClaudeFile=c,"seeded";return this.globalClaudeFile===c?"unchanged":"conflict"}getPackageManagers(){return this.packageManagers??=qE()}getRuntimes(){return this.runtimes??=QE()}getDetectedBuildTools(){return this.detectedBuildTools??=r_()}isWslEnvironment(){return this.wslEnvironment??=this.primedWslInteropExists??(process.platform==="linux"?this.fallbackWslInteropExists??=this.sources.wslInteropExistsSync():!1)}isNpmFromWindowsPath(){return this.npmFromWindowsPath??=s_(this)}hypervisorUuid(){return this.primedHypervisorUuid??(this.fallbackHypervisorUuid??=this.sources.readHypervisorUuidSync()??"")}isDockerenvPresent(){return this.primedDockerenvExists??(this.fallbackDockerenvExists??=this.sources.dockerenvExistsSync())}detectDeploymentEnvironment(){return this.deploymentEnvironment??=d_(this)}async prime(){if(this.primedWslInteropExists!==void 0||process.platform!=="linux")return;let[c,A,L]=await Promise.all([ni("/proc/sys/fs/binfmt_misc/WSLInterop").then(()=>!0,()=>!1),$E("/sys/hypervisor/uuid",{encoding:"utf8"}).then((ce)=>ce.trim().toLowerCase(),()=>{return}),ni("/.dockerenv").then(()=>!0,()=>!1)]);this.primedWslInteropExists=c,this.primedHypervisorUuid=A??"",this.primedDockerenvExists=L,this.wslEnvironment=void 0,this.npmFromWindowsPath=void 0,this.deploymentEnvironment=void 0}}var c_=new a(()=>new Sl({wslInteropExistsSync:fl,readHypervisorUuidSync:ml,dockerenvExistsSync:gl}));function qo(){return c_.of(R().host)}function yl(){return qo().detectDeploymentEnvironment()}function d_(c){if(o(process.env.CODESPACES))return"codespaces";if(process.env.GITPOD_WORKSPACE_ID)return"gitpod";if(o(process.env.CODER)||process.env.CODER_WORKSPACE_NAME)return"coder";if(o(process.env.DEVPOD)||process.env.DEVPOD_WORKSPACE_UID)return"devpod";if(process.env.DAYTONA_WS_ID)return"daytona";if(o(process.env.GOOGLE_CLOUD_WORKSTATIONS))return"gcp-cloud-workstations";if(process.env.C9_PID||process.env.C9_USER)return"aws-cloud9";if(process.env.REPL_ID||process.env.REPL_SLUG)return"replit";if(process.env.PROJECT_DOMAIN)return"glitch";if(o(process.env.VERCEL))return"vercel";if(process.env.RAILWAY_ENVIRONMENT_NAME||process.env.RAILWAY_SERVICE_NAME)return"railway";if(o(process.env.RENDER))return"render";if(o(process.env.NETLIFY))return"netlify";if(process.env.DYNO)return"heroku";if(process.env.FLY_APP_NAME||process.env.FLY_MACHINE_ID)return"fly.io";if(o(process.env.CF_PAGES))return"cloudflare-pages";if(process.env.DENO_DEPLOYMENT_ID)return"deno-deploy";if(process.env.AWS_LAMBDA_FUNCTION_NAME)return"aws-lambda";if(process.env.AWS_EXECUTION_ENV==="AWS_ECS_FARGATE")return"aws-fargate";if(process.env.AWS_EXECUTION_ENV==="AWS_ECS_EC2")return"aws-ecs";if(c.hypervisorUuid().startsWith("ec2"))return"aws-ec2";if(process.env.K_SERVICE)return"gcp-cloud-run";if(process.env.GOOGLE_CLOUD_PROJECT)return"gcp";if(process.env.WEBSITE_SITE_NAME||process.env.WEBSITE_SKU)return"azure-app-service";if(process.env.AZURE_FUNCTIONS_ENVIRONMENT)return"azure-functions";if(process.env.APP_URL?.includes("ondigitalocean.app"))return"digitalocean-app-platform";if(process.env.SPACE_CREATOR_USER_ID)return"huggingface-spaces";if(o(process.env.GITHUB_ACTIONS))return"github-actions";if(o(process.env.GITLAB_CI))return"gitlab-ci";if(process.env.CIRCLECI)return"circleci";if(process.env.BUILDKITE)return"buildkite";if(o(!1))return"ci";if(process.env.KUBERNETES_SERVICE_HOST)return"kubernetes";if(c.isDockerenvPresent())return"docker";if(Qo.platform==="darwin")return"unknown-darwin";if(Qo.platform==="linux")return"unknown-linux";if(Qo.platform==="win32")return"unknown-win32";return"unknown"}function Ol(){return!!(process.env.SSH_CONNECTION||process.env.SSH_CLIENT||process.env.SSH_TTY)}var Qo={probeInternalNetworkAccess:ZE,isCI:o(!1),platform:["win32","darwin"].includes(process.platform)?process.platform:"linux",arch:process.arch,nodeVersion:process.version,terminal:l_(),isSSH:Ol,getPackageManagers(){return qo().getPackageManagers()},getRuntimes(){return qo().getRuntimes()},isRunningWithBun:ge,isWslEnvironment(){return qo().isWslEnvironment()},isNpmFromWindowsPath(){return qo().isNpmFromWindowsPath()},isConductor:i_,detectDeploymentEnvironment:yl};var oi={};D(oi,{CLAUDE_AX_ANNOUNCEMENT_HOLD_MS:()=>m_,CLAUDE_AX_PREPARK_MS:()=>f_,CLAUDE_AX_REWRITE_HELD_ANNOUNCEMENT:()=>g_,CLAUDE_AX_SCREEN_READER:()=>u_,CLAUDE_AX_STARTUP_QUIET_MS:()=>p_,CLAUDE_CHROME_CLASSIFIER_FLOOR:()=>h_,CLAUDE_CODE_ACCESSIBILITY:()=>Ky,CLAUDE_CODE_ACT_DONT_REDERIVE:()=>Yy,CLAUDE_CODE_ALT_SCREEN_FULL_REPAINT:()=>__,CLAUDE_CODE_AMBER_ASTROLABE:()=>Ey,CLAUDE_CODE_ARTIFACT_ASSETS:()=>OO,CLAUDE_CODE_ARTIFACT_COMMENTS:()=>rO,CLAUDE_CODE_ARTIFACT_COMMENTS_AUTOREACT:()=>sO,CLAUDE_CODE_ARTIFACT_COMMENT_FAST_ACK:()=>aO,CLAUDE_CODE_ARTIFACT_COMMENT_FAST_ACK_FIXED:()=>lO,CLAUDE_CODE_ARTIFACT_COMMENT_RESPONDER:()=>iO,CLAUDE_CODE_ARTIFACT_DB:()=>cO,CLAUDE_CODE_ARTIFACT_DB_STR_REPLACE:()=>dO,CLAUDE_CODE_ARTIFACT_DELETE:()=>pO,CLAUDE_CODE_ARTIFACT_FRESH_READ:()=>PO,CLAUDE_CODE_ARTIFACT_HOT:()=>bO,CLAUDE_CODE_ARTIFACT_MULTI_FILE:()=>AO,CLAUDE_CODE_ARTIFACT_OPENING_PREFETCH:()=>wO,CLAUDE_CODE_ARTIFACT_OPEN_ACTION:()=>gO,CLAUDE_CODE_ARTIFACT_PATH_PIN:()=>CO,CLAUDE_CODE_ARTIFACT_PIN:()=>hO,CLAUDE_CODE_ARTIFACT_PRESENCE:()=>yO,CLAUDE_CODE_ARTIFACT_PREVIEW:()=>fO,CLAUDE_CODE_ARTIFACT_PREVIEW_EMULATOR:()=>mO,CLAUDE_CODE_ARTIFACT_QUICKSTART:()=>IO,CLAUDE_CODE_ARTIFACT_REPL:()=>uO,CLAUDE_CODE_ARTIFACT_ROOM:()=>SO,CLAUDE_CODE_ARTIFACT_SHARE:()=>EO,CLAUDE_CODE_ARTIFACT_START_KIT:()=>xO,CLAUDE_CODE_ARTIFACT_TEXT_VARIANT:()=>RO,CLAUDE_CODE_ARTIFACT_TOOLSET:()=>TO,CLAUDE_CODE_ARTIFACT_TYPES:()=>DO,CLAUDE_CODE_ARTIFACT_TYPE_CATALOG:()=>LO,CLAUDE_CODE_ARTIFACT_TYPE_CLOUD_CREATE:()=>NO,CLAUDE_CODE_ARTIFACT_VERIFY:()=>vO,CLAUDE_CODE_ARTIFACT_VERSIONS:()=>_O,CLAUDE_CODE_ATTRIBUTION_ANNOUNCEMENT:()=>Xy,CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST:()=>qb,CLAUDE_CODE_AUTO_CONNECT_IDE:()=>kO,CLAUDE_CODE_AUTO_MODE_SERVER:()=>MO,CLAUDE_CODE_BASALT_COVE:()=>R_,CLAUDE_CODE_BASH_EDIT_DIFF:()=>b_,CLAUDE_CODE_BASH_OUTPUT_AUDIENCE_NOTE:()=>nO,CLAUDE_CODE_BASH_SANDBOX_SHOW_INDICATOR:()=>UO,CLAUDE_CODE_BG_TASKS_REPORT_RUNNING:()=>U_,CLAUDE_CODE_BISON_CAIRN:()=>_y,CLAUDE_CODE_BREEZY_HORIZON:()=>D_,CLAUDE_CODE_BUBBLEWRAP:()=>HO,CLAUDE_CODE_CALM_MOCHI:()=>By,CLAUDE_CODE_CCR_EARLY_HYDRATE_PREFETCH:()=>zO,CLAUDE_CODE_CCR_EARLY_PLUGINS_SYNC:()=>WO,CLAUDE_CODE_CCR_EARLY_REMOTE_CONNECT:()=>FO,CLAUDE_CODE_CCR_EARLY_SKILLS_SYNC:()=>jO,CLAUDE_CODE_CCR_FOLD_FIRST_TURN_RESCAN:()=>$O,CLAUDE_CODE_CCR_SKIP_FRESH_MIGRATIONS:()=>VO,CLAUDE_CODE_CHILD_SESSION:()=>YO,CLAUDE_CODE_CHROME_MCP_ORG_DENIED:()=>JO,CLAUDE_CODE_COLD_COMPACT:()=>ZO,CLAUDE_CODE_COORDINATOR_FORCE_WORKER_INHERIT_MODEL:()=>H_,CLAUDE_CODE_COWORK_FRAME_ARTIFACTS:()=>B_,CLAUDE_CODE_COZY_TEAPOT:()=>C_,CLAUDE_CODE_CURRIED_TRINKET:()=>T_,CLAUDE_CODE_DESKTOP_SKILL_SWITCHES:()=>W_,CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING:()=>Y_,CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION:()=>V_,CLAUDE_CODE_DISABLE_ADVISOR_TOOL:()=>X_,CLAUDE_CODE_DISABLE_AGENT_VIEW:()=>J_,CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN:()=>Z_,CLAUDE_CODE_DISABLE_ARTIFACT:()=>q_,CLAUDE_CODE_DISABLE_ATTACHMENTS:()=>Q_,CLAUDE_CODE_DISABLE_ATTRIBUTION_CROSS_REPO:()=>eS,CLAUDE_CODE_DISABLE_AUTH_REFRESH_LOCK:()=>tS,CLAUDE_CODE_DISABLE_AUTO_MEMORY:()=>nS,CLAUDE_CODE_DISABLE_AWAITING_USER_IDLE:()=>oS,CLAUDE_CODE_DISABLE_BACKGROUND_TASKS:()=>rS,CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_DEFAULT:()=>iS,CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_GUARD:()=>aS,CLAUDE_CODE_DISABLE_BG_EXIT_HANDOFF:()=>lS,CLAUDE_CODE_DISABLE_BG_STABLE_PATH:()=>cS,CLAUDE_CODE_DISABLE_BUNDLED_SKILLS:()=>dS,CLAUDE_CODE_DISABLE_CFC_PROMPT:()=>uS,CLAUDE_CODE_DISABLE_CLAUDE_API_SKILL:()=>pS,CLAUDE_CODE_DISABLE_CLAUDE_CODE_SKILL:()=>fS,CLAUDE_CODE_DISABLE_CLAUDE_MDS:()=>mS,CLAUDE_CODE_DISABLE_CRON:()=>gS,CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT:()=>hS,CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS:()=>ES,CLAUDE_CODE_DISABLE_EXPLORE_PLAN_AGENTS:()=>SS,CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY:()=>yS,CLAUDE_CODE_DISABLE_FILE_CHECKPOINTING:()=>OS,CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS:()=>AS,CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT:()=>XS,CLAUDE_CODE_DISABLE_LAUNCH_COMPOSER:()=>bS,CLAUDE_CODE_DISABLE_MCP_TASK_BACKGROUND:()=>sS,CLAUDE_CODE_DISABLE_MEMORY_BULK_INFLATE:()=>CS,CLAUDE_CODE_DISABLE_MEMORY_MASS_DELETE_HOLD:()=>TS,CLAUDE_CODE_DISABLE_MEMORY_PERIODIC_RESYNC:()=>RS,CLAUDE_CODE_DISABLE_MEMORY_RO_UNSAVED_NOTICE:()=>DS,CLAUDE_CODE_DISABLE_MEMORY_STREAM_LIST:()=>LS,CLAUDE_CODE_DISABLE_MOUSE:()=>wS,CLAUDE_CODE_DISABLE_MOUSE_CLICKS:()=>xS,CLAUDE_CODE_DISABLE_NESTED_CHAIN_IDLE:()=>NS,CLAUDE_CODE_DISABLE_NESTED_USER_REPAIR:()=>vS,CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC:()=>kS,CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK:()=>MS,CLAUDE_CODE_DISABLE_NOTIFICATION_PRESENCE_CHECK:()=>US,CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL:()=>HS,CLAUDE_CODE_DISABLE_ORG_MEMORY:()=>zS,CLAUDE_CODE_DISABLE_PERMISSION_PROMPT_NOTIFY_HOOKS:()=>IS,CLAUDE_CODE_DISABLE_POLICY_SKILLS:()=>FS,CLAUDE_CODE_DISABLE_POWERSHELL_CMD_RM_DENY:()=>BS,CLAUDE_CODE_DISABLE_PRECOMPACT_SKIP:()=>GS,CLAUDE_CODE_DISABLE_PROACTIVITY:()=>WS,CLAUDE_CODE_DISABLE_REFUSAL_FALLBACK:()=>jS,CLAUDE_CODE_DISABLE_REFUSAL_RETRY:()=>$S,CLAUDE_CODE_DISABLE_STARTUP_WORK_GATE:()=>JS,CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS:()=>_S,CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT:()=>YS,CLAUDE_CODE_DISABLE_TERMINAL_TITLE:()=>ZS,CLAUDE_CODE_DISABLE_THINKING:()=>QS,CLAUDE_CODE_DISABLE_VIRTUAL_SCROLL:()=>ey,CLAUDE_CODE_DISABLE_WEB_FETCH:()=>ty,CLAUDE_CODE_DISABLE_WINDOWS_SHELL_LAUNCHER:()=>tb,CLAUDE_CODE_DISABLE_WORKFLOWS:()=>ny,CLAUDE_CODE_EDITOR_CODELIVERY:()=>z_,CLAUDE_CODE_ELEGANT_MEADOW:()=>M_,CLAUDE_CODE_ENABLE_APPEND_SUBAGENT_PROMPT:()=>ry,CLAUDE_CODE_ENABLE_AWAY_SUMMARY:()=>sy,CLAUDE_CODE_ENABLE_BACKGROUND_PLUGIN_REFRESH:()=>iy,CLAUDE_CODE_ENABLE_CFC:()=>ay,CLAUDE_CODE_ENABLE_DESIGN_SYNC:()=>ly,CLAUDE_CODE_ENABLE_EXPERIMENTAL_ADVISOR_TOOL:()=>cy,CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL:()=>dy,CLAUDE_CODE_ENABLE_FINE_GRAINED_TOOL_STREAMING:()=>uy,CLAUDE_CODE_ENABLE_LAUNCH_COMPOSER:()=>py,CLAUDE_CODE_ENABLE_MENU_KIND_LANES:()=>fy,CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION:()=>Cy,CLAUDE_CODE_ENABLE_REFRESH_MCP_TOOLS:()=>Ty,CLAUDE_CODE_ENABLE_REMOTE_RECAP:()=>Ry,CLAUDE_CODE_ENABLE_SDK_FILE_CHECKPOINTING:()=>Dy,CLAUDE_CODE_ENABLE_TASKS:()=>Ly,CLAUDE_CODE_ENABLE_TODO_TOOLS:()=>Iy,CLAUDE_CODE_ENABLE_TOKEN_USAGE_ATTACHMENT:()=>Py,CLAUDE_CODE_ENABLE_XAA:()=>wy,CLAUDE_CODE_EVAL_INTERVIEW_SESSION:()=>BA,CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS:()=>qO,CLAUDE_CODE_EXPERIMENTAL_OBSERVER_AGENTS:()=>QO,CLAUDE_CODE_FLEETVIEW_SIMPLE:()=>my,CLAUDE_CODE_FORCE_MID_CONVERSATION_SYSTEM:()=>aA,CLAUDE_CODE_FORCE_SESSION_PERSISTENCE:()=>rA,CLAUDE_CODE_FORCE_STRIKETHROUGH:()=>sA,CLAUDE_CODE_FORCE_TERMINAL_IMAGES:()=>iA,CLAUDE_CODE_FORCE_WINDOWS_CREDMAN:()=>cA,CLAUDE_CODE_FORK_SUBAGENT:()=>eA,CLAUDE_CODE_FORWARD_SUBAGENT_TEXT:()=>dA,CLAUDE_CODE_FORWARD_USER_INTENT:()=>F_,CLAUDE_CODE_GATEWAY_HINT_HEADERS:()=>ob,CLAUDE_CODE_GB_DISK_CACHE_WHEN_TELEMETRY_OFF:()=>gy,CLAUDE_CODE_GENTLE_PARASOL:()=>O_,CLAUDE_CODE_GLOB_HIDDEN:()=>tA,CLAUDE_CODE_GLOB_NO_IGNORE:()=>nA,CLAUDE_CODE_GORSE_PLOVER:()=>yy,CLAUDE_CODE_GROWTHBOOK_KICK_FROM_INIT:()=>BO,CLAUDE_CODE_GROWTHBOOK_KICK_ON_WARM_CACHE:()=>GO,CLAUDE_CODE_HARBOR_KITE:()=>xy,CLAUDE_CODE_HARBOR_KITE_CLOUD:()=>vy,CLAUDE_CODE_HARBOR_KITE_PACING_OFF:()=>Ny,CLAUDE_CODE_HARMONIC_RIDDLE:()=>Fy,CLAUDE_CODE_HIDE_CWD:()=>oA,CLAUDE_CODE_HOOKS_SAME_THREAD:()=>rC,CLAUDE_CODE_HOST_SCHEDULED_RUN:()=>G_,CLAUDE_CODE_HOVER_REST:()=>hy,CLAUDE_CODE_HUMBLE_HAMMOCK:()=>P_,CLAUDE_CODE_IDE_SKIP_AUTO_INSTALL:()=>uA,CLAUDE_CODE_IDE_SKIP_VALID_CHECK:()=>pA,CLAUDE_CODE_INCLUDE_PARTIAL_MESSAGES:()=>fA,CLAUDE_CODE_INLINE_TOOLS:()=>lA,CLAUDE_CODE_JUNIPER_SUNDIAL:()=>by,CLAUDE_CODE_KB_COHESION_FIXES:()=>Vy,CLAUDE_CODE_LANTERN_PRISM:()=>ky,CLAUDE_CODE_LARCH_CISTERN:()=>Sy,CLAUDE_CODE_MANAGED_CONFIG_PREFETCH:()=>KO,CLAUDE_CODE_MEMORY_PUSH_DELETE_MODE:()=>PS,CLAUDE_CODE_MODEL_CAPABILITIES:()=>Jy,CLAUDE_CODE_NANKEEN_KESTREL:()=>K_,CLAUDE_CODE_NATIVE_CURSOR:()=>mA,CLAUDE_CODE_NEW_INIT:()=>gA,CLAUDE_CODE_NONBLOCKING_STDOUT:()=>EA,CLAUDE_CODE_NO_FLICKER:()=>hA,CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE:()=>_A,CLAUDE_CODE_PARSED_WILLOW:()=>N_,CLAUDE_CODE_PEWTER_OWL:()=>rb,CLAUDE_CODE_PEWTER_OWL_TOOL:()=>sb,CLAUDE_CODE_PLAN_MODE_REQUIRED:()=>SA,CLAUDE_CODE_PLUGIN_BINARY_ASSETS:()=>ZA,CLAUDE_CODE_PLUGIN_DIRS:()=>iC,CLAUDE_CODE_PLUGIN_DIR_WATCH:()=>sC,CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE:()=>JA,CLAUDE_CODE_PLUGIN_PREFER_HTTPS:()=>QA,CLAUDE_CODE_PLUGIN_USE_ZIP_CACHE:()=>qA,CLAUDE_CODE_POLISHED_DEWDROP:()=>L_,CLAUDE_CODE_POLL_EVENTS:()=>yA,CLAUDE_CODE_POLL_EVENT_DECLARATIONS:()=>OA,CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY:()=>eb,CLAUDE_CODE_PROACTIVE:()=>AA,CLAUDE_CODE_PROJECTS_SESSION:()=>XA,CLAUDE_CODE_PROMPT_CACHE_TTL:()=>Vb,CLAUDE_CODE_PROPAGATE_TRACEPARENT:()=>nb,CLAUDE_CODE_REFUSAL_FALLBACK_CATCH_ALL:()=>VS,CLAUDE_CODE_REMOTE_TOOLS_FORWARD:()=>aC,CLAUDE_CODE_REMOTE_TOOLS_HOST_ALLOWS_UNATTENDED:()=>$_,CLAUDE_CODE_REMOTE_TOOLS_PIN_STORED_LOGIN:()=>j_,CLAUDE_CODE_REMOVE_PROMPT_STRINGS:()=>Oy,CLAUDE_CODE_REPORT_FINDINGS:()=>KS,CLAUDE_CODE_RIPPLING_TULIP:()=>zy,CLAUDE_CODE_RUSTLING_PIXEL:()=>I_,CLAUDE_CODE_SEND_FEEDBACK:()=>qS,CLAUDE_CODE_SESSION_ATTENDED:()=>XO,CLAUDE_CODE_SILENT_TURN_REMINDER:()=>qy,CLAUDE_CODE_SILENT_TURN_REMINDER_SECONDS:()=>eO,CLAUDE_CODE_SILENT_TURN_REMINDER_TEXT:()=>tO,CLAUDE_CODE_SILENT_TURN_REMINDER_TURNS:()=>Qy,CLAUDE_CODE_SKILL_PROPOSALS:()=>bA,CLAUDE_CODE_SKIP_PLUGIN_MCP_SERVERS:()=>CA,CLAUDE_CODE_SKIP_PLUGIN_MCP_SERVERS_EXCEPT:()=>TA,CLAUDE_CODE_SKIP_PROJECT_BACKFILL:()=>RA,CLAUDE_CODE_SKIP_PROMPT_HISTORY:()=>DA,CLAUDE_CODE_SKIP_REPO_UPLOAD:()=>LA,CLAUDE_CODE_SQUISHY_NEWT:()=>k_,CLAUDE_CODE_STELLAR_DRIFT:()=>w_,CLAUDE_CODE_STREAMED_BUMBLEBEE:()=>Gy,CLAUDE_CODE_STREAMED_BUMBLEBEE_TEXT:()=>Wy,CLAUDE_CODE_SUBAGENT_CACHE_EVICT:()=>IA,CLAUDE_CODE_SUBAGENT_CONFIG_WARNING:()=>jy,CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL:()=>Kb,CLAUDE_CODE_SUBAGENT_PROMPT_SNAPSHOT:()=>PA,CLAUDE_CODE_SUPPRESS_SESSION_ATTRIBUTION:()=>wA,CLAUDE_CODE_SYNC_PLUGINS:()=>NA,CLAUDE_CODE_SYNC_PLUGIN_INSTALL:()=>xA,CLAUDE_CODE_SYNC_SKILLS:()=>vA,CLAUDE_CODE_TAG_ISMETA_MESSAGES:()=>kA,CLAUDE_CODE_THINKING_DISPLAY_UPDATES:()=>oO,CLAUDE_CODE_THISTLE_GREBE:()=>S_,CLAUDE_CODE_THRIFTY_SONIC:()=>A_,CLAUDE_CODE_TOASTY_THIMBLE:()=>y_,CLAUDE_CODE_TODO_REMINDER_MODE:()=>My,CLAUDE_CODE_TOTAL_TOKENS_REMINDER:()=>Uy,CLAUDE_CODE_TOTAL_TOKENS_REMINDER_AFTER_USER_TURN:()=>$y,CLAUDE_CODE_TOTAL_TOKENS_REMINDER_BUDGET:()=>Hy,CLAUDE_CODE_TRANSCRIPT_LOCAL_GC:()=>MA,CLAUDE_CODE_TURN_UPDATES:()=>Zy,CLAUDE_CODE_TWO_STAGE_CLASSIFIER:()=>UA,CLAUDE_CODE_USE_COWORK_PLUGINS:()=>HA,CLAUDE_CODE_USE_NATIVE_FILE_SEARCH:()=>zA,CLAUDE_CODE_USE_POWERSHELL_TOOL:()=>FA,CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS:()=>WA,CLAUDE_CODE_WEBFETCH_DEADLINE_MS:()=>jA,CLAUDE_CODE_WEBFETCH_USE_CCR_PROXY:()=>$A,CLAUDE_CODE_WEBSEARCH_CITATIONS:()=>KA,CLAUDE_CODE_WEBSEARCH_USE_CCR_PROXY:()=>VA,CLAUDE_CODE_WEB_FETCH_AGENT:()=>GA,CLAUDE_CODE_WEB_SEARCH_FAST_ARG:()=>YA,CLAUDE_CODE_WHIMSICAL_ELEPHANT:()=>v_,CLAUDE_CODE_WILLOW_TERN:()=>Ay,CLAUDE_CODE_WISE_COMET:()=>x_,CLAUDE_CODE_WORKFLOWS:()=>oy,CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS:()=>fb,CLAUDE_CODE_WORKFLOW_PREFIX_STAGGER_MS:()=>pb,CLAUDE_CODE_WORKFLOW_SIZE_WARNING_AGENTS:()=>db,CLAUDE_CODE_WORKFLOW_SIZE_WARNING_TOKENS:()=>ub,CLAUDE_DISABLE_ADOPT:()=>ib,CLAUDE_IMPORT_CONVERSATIONS:()=>ab,CLAUDE_RUNNER_DISABLE_AWAITING_ACTION_OVERRIDE:()=>lb,CLAUDE_WORKFLOW_NAME_ONLY:()=>cb,DISABLE_AUTOUPDATER:()=>gb,DISABLE_AUTO_COMPACT:()=>mb,DISABLE_BRIEF_MODE_STOP_HOOK:()=>hb,DISABLE_BUG_COMMAND:()=>Eb,DISABLE_COST_WARNINGS:()=>_b,DISABLE_DOCTOR_COMMAND:()=>Sb,DISABLE_ERROR_REPORTING:()=>yb,DISABLE_EXTRA_USAGE_COMMAND:()=>Ob,DISABLE_FEEDBACK_COMMAND:()=>Ab,DISABLE_GROWTHBOOK:()=>bb,DISABLE_INSTALL_GITHUB_APP_COMMAND:()=>Cb,DISABLE_INTERLEAVED_THINKING:()=>Tb,DISABLE_LOGIN_COMMAND:()=>Rb,DISABLE_LOGOUT_COMMAND:()=>Db,DISABLE_PROMPT_CACHING:()=>Lb,DISABLE_PROMPT_CACHING_FABLE:()=>xb,DISABLE_PROMPT_CACHING_HAIKU:()=>Ib,DISABLE_PROMPT_CACHING_MYTHOS:()=>Nb,DISABLE_PROMPT_CACHING_OPUS:()=>Pb,DISABLE_PROMPT_CACHING_SONNET:()=>wb,DISABLE_TELEMETRY:()=>vb,DISABLE_UPDATES:()=>kb,DISABLE_UPGRADE_COMMAND:()=>Mb,EMBEDDED_SEARCH_TOOLS:()=>nC,ENABLE_BETA_TRACING_DETAILED:()=>Ub,ENABLE_CLAUDEAI_MCP_SERVERS:()=>Hb,ENABLE_ENHANCED_TELEMETRY_BETA:()=>zb,ENABLE_LOCKLESS_UPDATES:()=>Fb,ENABLE_LSP_TOOL:()=>Bb,ENABLE_MCP_LARGE_OUTPUT_FILES:()=>Gb,ENABLE_PID_BASED_VERSION_LOCKING:()=>Wb,ENABLE_PROMPT_CACHING_1H:()=>jb,ENABLE_PROMPT_CACHING_1H_BEDROCK:()=>$b,ENABLE_SESSION_BACKGROUNDING:()=>Yb,ENABLE_SESSION_PERSISTENCE:()=>Xb,ENABLE_TOOL_SEARCH:()=>Jb,FORCE_AUTOUPDATE_PLUGINS:()=>Zb,FORCE_CODE_TERMINAL:()=>Qb,FORCE_PROMPT_CACHING_5M:()=>eC,FORCE_VCR:()=>tC,INK_SCREEN_READER:()=>E_,USE_API_CONTEXT_MANAGEMENT:()=>oC});var Do=["5m","1h"];var u_=I.triBool(),p_=I.int({min:0}),f_=I.int({min:0}),m_=I.int({min:0}),g_=I.triBool(),h_=I.triBool(),E_=I.bool(),__=I.bool(),S_=I.str(),y_=I.str(),O_=I.str(),A_=I.triBool(),b_=I.triBool(),C_=I.enum(["strict","relaxed"]),T_=I.enum(["control","lean","short","capped"]),R_=I.bool(),D_=I.str(),L_=I.enum(["drop","block","off"]),I_=I.str(),P_=I.triBool(),w_=I.triBool(),x_=I.triBool(),N_=I.triBool(),v_=I.triBool(),k_=I.triBool(),M_=I.triBool(),U_=I.triBool(),H_=I.bool(),z_=I.bool(),F_=I.bool(),B_=I.bool(),G_=I.bool(),W_=I.bool(),j_=I.bool(),$_=I.str(),V_=I.bool(),K_=I.bool(),Y_=I.bool(),X_=I.bool(),J_=I.bool(),Z_=I.bool(),q_=I.bool(),Q_=I.bool(),eS=I.bool(),tS=I.bool(),nS=I.bool(),oS=I.bool(),rS=I.bool(),sS=I.bool(),iS=I.bool(),aS=I.bool(),lS=I.bool(),cS=I.bool(),dS=I.bool(),uS=I.bool(),pS=I.bool(),fS=I.bool(),mS=I.bool(),gS=I.bool(),hS=I.bool(),ES=I.bool(),_S=I.bool(),SS=I.bool(),yS=I.bool(),OS=I.bool(),AS=I.triBool(),bS=I.bool(),CS=I.bool(),TS=I.bool(),RS=I.bool(),DS=I.bool(),LS=I.bool(),IS=I.bool(),PS=I.enum(["corroborate","immediate","never"]),wS=I.triBool(),xS=I.triBool(),NS=I.bool(),vS=I.bool(),kS=I.bool(),MS=I.bool(),US=I.bool(),HS=I.bool(),zS=I.bool(),FS=I.bool(),BS=I.bool(),GS=I.bool(),WS=I.bool(),jS=I.bool(),$S=I.bool(),VS=I.triBool(),KS=I.bool(),YS=I.bool(),XS=I.bool(),JS=I.bool(),ZS=I.bool(),qS=I.triBool(),QS=I.bool(),ey=I.bool(),ty=I.bool(),ny=I.bool(),oy=I.triBool(),ry=I.bool(),sy=I.bool(),iy=I.bool(),ay=I.triBool(),ly=I.bool(),cy=I.bool(),dy=I.bool(),uy=I.triBool(),py=I.bool(),fy=I.bool(),my=I.bool(),gy=I.bool(),hy=I.triBool(),Ey=I.bool(),_y=I.triBool(),Sy=I.bool(),yy=I.bool(),Oy=I.str(),Ay=I.bool(),by=I.int({min:1,digitsOnly:!0}),Cy=I.triBool(),Ty=I.bool(),Ry=I.triBool(),Dy=I.bool(),Ly=I.triBool(),Iy=I.bool(),Py=I.bool(),wy=I.bool(),xy=I.str(),Ny=I.bool(),vy=I.bool(),ky=I.bool(),My=I.enum(["baseline","off"]),Uy=I.str(),Hy=I.int(),zy=I.str(),Fy=I.str(),By=I.str(),Gy=I.triBool(),Wy=I.str(),jy=I.triBool(),$y=I.triBool(),Vy=I.bool(),Ky=I.bool(),Yy=I.triBool(),Xy=I.triBool(),Jy=I.str(),Zy=I.triBool(),qy=I.triBool(),Qy=I.int({min:1}),eO=I.int({min:1,wholeValue:!0}),tO=I.str(),nO=I.triBool(),oO=I.triBool(),rO=I.triBool(),sO=I.triBool(),iO=I.triBool(),aO=I.triBool(),lO=I.triBool(),cO=I.triBool(),dO=I.triBool(),uO=I.triBool(),pO=I.triBool(),fO=I.triBool(),mO=I.triBool(),gO=I.triBool(),hO=I.triBool(),EO=I.triBool(),_O=I.bool(),SO=I.triBool(),yO=I.triBool(),OO=I.triBool(),AO=I.triBool(),bO=I.triBool(),CO=I.triBool(),TO=I.triBool(),RO=I.enum(["v0","v1","v2"]),DO=I.triBool(),LO=I.triBool(),IO=I.triBool(),PO=I.triBool(),wO=I.triBool(),xO=I.triBool(),NO=I.triBool(),vO=I.triBool(),kO=I.triBool(),MO=I.str(),UO=I.bool(),HO=I.bool(),zO=I.bool(),FO=I.bool(),BO=I.bool(),GO=I.bool(),WO=I.bool(),jO=I.bool(),$O=I.bool(),VO=I.bool(),KO=I.triBool(),YO=I.bool(),XO=I.triBool(),JO=I.bool(),ZO=I.bool(),qO=I.bool(),QO=I.bool(),eA=I.triBool(),tA=I.bool(),nA=I.bool(),oA=I.bool(),rA=I.bool(),sA=I.bool(),iA=I.bool(),aA=I.bool(),lA=I.triBool(),cA=I.str(),dA=I.bool(),uA=I.bool(),pA=I.bool(),fA=I.bool(),mA=I.bool(),gA=I.bool(),hA=I.triBool(),EA=I.triBool(),_A=I.bool(),SA=I.bool(),yA=I.bool(),OA=I.str(),AA=I.bool(),bA=I.bool(),CA=I.bool(),TA=I.str(),RA=I.bool(),DA=I.bool(),LA=I.bool(),IA=I.bool(),PA=I.bool(),wA=I.bool(),xA=I.bool(),NA=I.bool(),vA=I.bool(),kA=I.bool(),MA=I.triBool(),UA=I.bool(),HA=I.bool(),zA=I.bool(),FA=I.triBool(),BA=I.bool(),GA=I.triBool(),WA=I.int({min:1,digitsOnly:!0}),jA=I.int({min:0,digitsOnly:!0}),$A=I.bool(),VA=I.bool(),KA=I.bool(),YA=I.triBool(),XA=I.bool(),JA=I.bool(),ZA=I.bool(),qA=I.bool(),QA=I.bool(),eb=I.bool(),tb=I.bool(),nb=I.bool(),ob=I.triBool(),rb=I.triBool(),sb=I.triBool(),ib=I.bool(),ab=I.bool(),lb=I.bool(),cb=I.bool(),db=I.int({min:1}),ub=I.int({min:1}),pb=I.int({min:0}),fb=I.int({min:1,max:256,digitsOnly:!0}),mb=I.bool(),gb=I.bool(),hb=I.bool(),Eb=I.bool(),_b=I.bool(),Sb=I.bool(),yb=I.bool(),Ob=I.bool(),Ab=I.bool(),bb=I.bool(),Cb=I.bool(),Tb=I.bool(),Rb=I.bool(),Db=I.bool(),Lb=I.bool(),Ib=I.bool(),Pb=I.bool(),wb=I.bool(),xb=I.bool(),Nb=I.bool(),vb=I.bool(),kb=I.bool(),Mb=I.bool(),Ub=I.bool(),Hb=I.triBool(),zb=I.bool(),Fb=I.bool(),Bb=I.bool(),Gb=I.triBool(),Wb=I.triBool(),jb=I.bool(),$b=I.bool(),Vb=I.enum(Do),Kb=I.enum(Do),Yb=I.bool(),Xb=I.bool(),Jb=I.str(),Zb=I.bool(),qb=I.bool(),Qb=I.bool(),eC=I.bool(),tC=I.bool(),nC=I.bool(),oC=I.bool(),rC=I.bool(),sC=I.triBool(),iC=I.str(),aC=I.bool();var ri={};D(ri,{ALACRITTY_LOG:()=>YT,ALLUSERSPROFILE:()=>JC,ANDROID_HOME:()=>RT,ANDROID_SDK_ROOT:()=>DT,APPDATA:()=>FC,APP_URL:()=>TD,AWS_CA_BUNDLE:()=>fT,AWS_EXECUTION_ENV:()=>pD,AWS_LAMBDA_FUNCTION_NAME:()=>uD,AZURE_FUNCTIONS_ENVIRONMENT:()=>CD,BAT_THEME:()=>PD,BROWSER:()=>RC,BUILDKITE:()=>VR,BUN_CHROME_PATH:()=>ID,BUN_INSTALL:()=>LD,CARGO_HTTP_CAINFO:()=>gT,CDPATH:()=>dC,CF_PAGES:()=>cD,CIRCLECI:()=>$R,CLOUDSDK_ACTIVE_CONFIG_NAME:()=>OD,CLOUDSDK_CONFIG:()=>yD,CLOUDSDK_CORE_CUSTOM_CA_CERTS_FILE:()=>uT,CODER:()=>ZR,CODER_WORKSPACE_NAME:()=>qR,CODESPACES:()=>JR,COLORFGBG:()=>wT,COLORTERM:()=>PT,COMPUTERNAME:()=>UC,COMSPEC:()=>EC,CONTAINER_SANDBOX_MOUNT_POINT:()=>HC,CURL_CA_BUNDLE:()=>dT,CURSOR_TRACE_ID:()=>pR,ComSpec:()=>SC,ConEmuANSI:()=>sR,ConEmuPID:()=>iR,ConEmuTask:()=>aR,DAYTONA_WS_ID:()=>tD,DEMO_VERSION:()=>MD,DENO_CERT:()=>mT,DENO_DEPLOYMENT_ID:()=>dD,DISPLAY:()=>DC,DO_NOT_TRACK:()=>xT,DYNO:()=>lD,EDITOR:()=>CC,FORCE_COLOR:()=>IT,GCLOUD_PROJECT:()=>gD,GCM_INTERACTIVE:()=>yR,GH_CONFIG_DIR:()=>bR,GH_ENTERPRISE_TOKEN:()=>IR,GH_HOST:()=>DR,GH_REPO:()=>LR,GH_TOKEN:()=>RR,GITHUB_ACTIONS:()=>vR,GITHUB_ACTION_INPUTS:()=>kR,GITHUB_ACTION_PATH:()=>MR,GITHUB_ACTOR:()=>UR,GITHUB_ACTOR_ID:()=>HR,GITHUB_ENTERPRISE_TOKEN:()=>wR,GITHUB_ENV:()=>xR,GITHUB_EVENT_NAME:()=>zR,GITHUB_EVENT_PATH:()=>FR,GITHUB_REPOSITORY:()=>BR,GITHUB_REPOSITORY_ID:()=>GR,GITHUB_REPOSITORY_OWNER:()=>WR,GITHUB_REPOSITORY_OWNER_ID:()=>jR,GITHUB_TOKEN:()=>PR,GITHUB_WORKSPACE:()=>NR,GITLAB_CI:()=>KR,GITPOD_WORKSPACE_ID:()=>QR,GIT_ASKPASS:()=>SR,GIT_CONFIG_COUNT:()=>OR,GIT_CONFIG_GLOBAL:()=>AR,GIT_CONFIG_NOSYSTEM:()=>OT,GIT_SSH_COMMAND:()=>ER,GIT_SSL_CAINFO:()=>yT,GIT_SSL_CAPATH:()=>AT,GIT_TERMINAL_PROMPT:()=>_R,GNOME_TERMINAL_SERVICE:()=>VT,GOOGLE_APPLICATION_CREDENTIALS:()=>hD,GOOGLE_CLOUD_PROJECT:()=>mD,GOOGLE_CLOUD_WORKSTATIONS:()=>eD,GRPC_DEFAULT_SSL_ROOTS_FILE_PATH:()=>ET,HEX_CACERTS_PATH:()=>ST,HISTFILE:()=>oT,HOME:()=>lC,HOMEDRIVE:()=>$C,HOMEPATH:()=>VC,HOMESHARE:()=>KC,HTTPLIB2_CA_CERTS:()=>pT,HUB_CONFIG:()=>CR,INTELLIJ_TERMINAL_COMMAND_BLOCKS:()=>lR,INTELLIJ_TERMINAL_COMMAND_BLOCKS_REWORKED:()=>cR,IS_DEMO:()=>kD,IS_SANDBOX:()=>vD,ITERM_SESSION_ID:()=>GT,JAVA_HOME:()=>CT,JAVA_TOOL_OPTIONS:()=>TT,KITTY_WINDOW_ID:()=>WT,KONSOLE_VERSION:()=>jT,KUBERNETES_SERVICE_HOST:()=>DD,K_SERVICE:()=>fD,LANG:()=>IC,LC_ALL:()=>PC,LC_TERMINAL:()=>MT,LC_TIME:()=>wC,LOCALAPPDATA:()=>BC,MSYSTEM:()=>rR,NETLIFY:()=>aD,NIX_SSL_CERT_FILE:()=>_T,NODE_EXTRA_CA_CERTS:()=>iT,NODE_OPTIONS:()=>rT,NODE_PATH:()=>sT,NO_COLOR:()=>LT,NoDefaultCurrentDirectoryInExePath:()=>bC,OneDrive:()=>GC,OneDriveCommercial:()=>jC,OneDriveConsumer:()=>WC,P4PORT:()=>wD,PATH:()=>cC,PATHEXT:()=>AC,PIP_CERT:()=>hT,PLAYWRIGHT_BROWSERS_PATH:()=>xD,PREFIX:()=>pC,PROGRAMDATA:()=>XC,PROJECT_DOMAIN:()=>rD,PWD:()=>uC,ProgramData:()=>YC,ProgramFiles:()=>OC,RENDER:()=>iD,REPL_ID:()=>nD,REPL_SLUG:()=>oD,REQUESTS_CA_BUNDLE:()=>cT,RUNNER_ENVIRONMENT:()=>XR,RUNNER_OS:()=>YR,SAFEUSER:()=>ZC,SESSIONNAME:()=>JT,SHELL:()=>hC,SPACE_CREATOR_USER_ID:()=>RD,SSH_AUTH_SOCK:()=>hR,SSH_CLIENT:()=>fR,SSH_CONNECTION:()=>mR,SSH_TTY:()=>gR,SSL_CERT_DIR:()=>lT,SSL_CERT_FILE:()=>aT,STY:()=>ZT,SUDO_GID:()=>vC,SUDO_UID:()=>NC,SUDO_USER:()=>kC,SYSTEMROOT:()=>_C,SystemRoot:()=>yC,TEMP:()=>gC,TERM:()=>NT,TERMINAL:()=>UT,TERMINAL_EMULATOR:()=>HT,TERMINATOR_UUID:()=>zT,TERMUX_VERSION:()=>FT,TERM_PROGRAM:()=>vT,TERM_PROGRAM_VERSION:()=>kT,TILIX_ID:()=>BT,TMP:()=>mC,TMPDIR:()=>fC,TMUX:()=>qT,TMUX_PANE:()=>QT,TRACEPARENT:()=>UD,TRACESTATE:()=>HD,USER:()=>xC,USERNAME:()=>MC,USERPROFILE:()=>zC,USE_BUILTIN_RIPGREP:()=>ND,UV_THREADPOOL_SIZE:()=>bT,VERCEL:()=>sD,VISUAL:()=>TC,VSCODE_GIT_ASKPASS_MAIN:()=>uR,VTE_VERSION:()=>KT,WAYLAND_DISPLAY:()=>LC,WEBSITE_SITE_NAME:()=>AD,WEBSITE_SKU:()=>bD,WSL_DISTRO_NAME:()=>nR,WSL_INTEROP:()=>oR,WT_SESSION:()=>XT,XDG_CACHE_HOME:()=>tT,XDG_CONFIG_HOME:()=>QC,XDG_DATA_HOME:()=>eT,XDG_RUNTIME_DIR:()=>qC,XDG_STATE_HOME:()=>nT,XTERM_VERSION:()=>$T,ZDOTDIR:()=>TR,ZED_TERM:()=>tR,ZELLIJ:()=>eR,__CFBundleIdentifier:()=>dR,gcloud_project:()=>ED,google_application_credentials:()=>SD,google_cloud_project:()=>_D});var lC=I.str(),cC=I.str(),dC=I.str(),uC=I.str(),pC=I.str(),fC=I.str(),mC=I.str(),gC=I.str(),hC=I.str(),EC=I.str(),_C=I.str(),SC=I.str(),yC=I.str(),OC=I.str(),AC=I.str(),bC=I.str(),CC=I.str(),TC=I.str(),RC=I.str(),DC=I.str(),LC=I.str(),IC=I.str(),PC=I.str(),wC=I.str(),xC=I.str(),NC=I.int({min:0,digitsOnly:!0}),vC=I.int({min:0,digitsOnly:!0}),kC=I.str(),MC=I.str(),UC=I.str(),HC=I.str(),zC=I.str(),FC=I.str(),BC=I.str(),GC=I.str(),WC=I.str(),jC=I.str(),$C=I.str(),VC=I.str(),KC=I.str(),YC=I.str(),XC=I.str(),JC=I.str(),ZC=I.str(),qC=I.str(),QC=I.str(),eT=I.str(),tT=I.str(),nT=I.str(),oT=I.str(),rT=I.str(),sT=I.str(),iT=I.str(),aT=I.str(),lT=I.str(),cT=I.str(),dT=I.str(),uT=I.str(),pT=I.str(),fT=I.str(),mT=I.str(),gT=I.str(),hT=I.str(),ET=I.str(),_T=I.str(),ST=I.str(),yT=I.str(),OT=I.str(),AT=I.str(),bT=I.str(),CT=I.str(),TT=I.str(),RT=I.str(),DT=I.str(),LT=I.rawStr(),IT=I.rawStr(),PT=I.str(),wT=I.str(),xT=I.str(),NT=I.str(),vT=I.str(),kT=I.str(),MT=I.str(),UT=I.str(),HT=I.str(),zT=I.str(),FT=I.str(),BT=I.str(),GT=I.str(),WT=I.str(),jT=I.str(),$T=I.str(),VT=I.str(),KT=I.str(),YT=I.str(),XT=I.str(),JT=I.str(),ZT=I.str(),qT=I.str(),QT=I.str(),eR=I.str(),tR=I.str(),nR=I.str(),oR=I.str(),rR=I.str(),sR=I.str(),iR=I.str(),aR=I.str(),lR=I.str(),cR=I.str(),dR=I.str(),uR=I.str(),pR=I.rawStr(),fR=I.str(),mR=I.str(),gR=I.str(),hR=I.str(),ER=I.str(),_R=I.str(),SR=I.str(),yR=I.str(),OR=I.str(),AR=I.str(),bR=I.str(),CR=I.str(),TR=I.str(),RR=I.str(),DR=I.str(),LR=I.str(),IR=I.str(),PR=I.str(),wR=I.str(),xR=I.str(),NR=I.str(),vR=I.str(),kR=I.rawStr(),MR=I.str(),UR=I.str(),HR=I.str(),zR=I.str(),FR=I.str(),BR=I.str(),GR=I.str(),WR=I.str(),jR=I.str(),$R=I.str(),VR=I.str(),KR=I.str(),YR=I.str(),XR=I.str(),JR=I.str(),ZR=I.str(),qR=I.str(),QR=I.str(),eD=I.str(),tD=I.str(),nD=I.str(),oD=I.str(),rD=I.str(),sD=I.str(),iD=I.str(),aD=I.str(),lD=I.str(),cD=I.str(),dD=I.str(),uD=I.str(),pD=I.str(),fD=I.str(),mD=I.str(),gD=I.str(),hD=I.str(),ED=I.str(),_D=I.str(),SD=I.str(),yD=I.str(),OD=I.str(),AD=I.str(),bD=I.str(),CD=I.str(),TD=I.str(),RD=I.str(),DD=I.str(),LD=I.str(),ID=I.str(),PD=I.str(),wD=I.str(),xD=I.str(),ND=I.str(),vD=I.str(),kD=I.str(),MD=I.str(),UD=I.str(),HD=I.str();var si={};D(si,{AI_AGENT:()=>sw,ALLOW_ANT_COMPUTER_USE_MCP:()=>iw,ANTHROPIC_CONFIG_DIR:()=>zD,BASH_MAX_OUTPUT_LENGTH:()=>Ux,CCR_SESSION_PROFILE:()=>aw,CLAUBBIT:()=>lw,CLAUDECODE:()=>cw,CLAUDE_AFK_COUNTDOWN_MS:()=>Hx,CLAUDE_AFK_TIMEOUT_MS:()=>zx,CLAUDE_AFTER_LAST_COMPACT:()=>FD,CLAUDE_AGENTS_SELECT:()=>BD,CLAUDE_AGENT_SDK_CLIENT_APP:()=>GD,CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS:()=>dw,CLAUDE_AGENT_SDK_DISABLE_MCP_MANIFESTS:()=>uw,CLAUDE_AGENT_SDK_MCP_NO_PREFIX:()=>pw,CLAUDE_AGENT_SDK_VERSION:()=>WD,CLAUDE_ARTIFACT_HOST_GRANT:()=>jD,CLAUDE_ASYNC_AGENT_STALL_TIMEOUT_MS:()=>Fx,CLAUDE_AUTOCOMPACT_PCT_OVERRIDE:()=>$D,CLAUDE_AUTO_BACKGROUND_TASKS:()=>fw,CLAUDE_BASH_MAINTAIN_PROJECT_WORKING_DIR:()=>mw,CLAUDE_BG_AUTH_SNAPSHOT_PATH:()=>VD,CLAUDE_BG_AUTO_MEMORY_OFF:()=>QD,CLAUDE_BG_BACKEND:()=>KD,CLAUDE_BG_CARRIED_PROMPTS_SHA256:()=>cL,CLAUDE_BG_CLAIM_AUTH:()=>YD,CLAUDE_BG_DISPATCHER_RATE_LIMIT_TIER:()=>XD,CLAUDE_BG_DISPATCHER_SUBSCRIPTION_TYPE:()=>JD,CLAUDE_BG_ISOLATION:()=>ZD,CLAUDE_BG_MEMORY_TOGGLED_OFF:()=>qD,CLAUDE_BG_POST_CLEAR_RESPAWN:()=>eL,CLAUDE_BG_PTY_AUTH:()=>tL,CLAUDE_BG_RENDEZVOUS_SOCK:()=>nL,CLAUDE_BG_RV_AUTH:()=>oL,CLAUDE_BG_SESSION_PERMISSION_RULES:()=>rL,CLAUDE_BG_SOCKET_TOKENS_PATH:()=>sL,CLAUDE_BG_SOURCE:()=>iL,CLAUDE_BG_STARTUP_WEDGE_MS:()=>Bx,CLAUDE_BG_TCC_DISCLAIMED:()=>aL,CLAUDE_BG_WORKSPACE_TRUSTED:()=>lL,CLAUDE_BRIDGE_BASE_URL:()=>dL,CLAUDE_BRIDGE_OAUTH_TOKEN:()=>uL,CLAUDE_BRIDGE_REATTACH_GROUPING:()=>pL,CLAUDE_BRIDGE_REATTACH_NO_BACKFILL:()=>gw,CLAUDE_BRIDGE_REATTACH_OUTBOUND_ONLY:()=>hw,CLAUDE_BRIDGE_REATTACH_OWNER_ACCT:()=>fL,CLAUDE_BRIDGE_REATTACH_OWNER_ORG:()=>mL,CLAUDE_BRIDGE_REATTACH_SEQ:()=>Gx,CLAUDE_BRIDGE_REATTACH_SESSION:()=>gL,CLAUDE_BRIDGE_SESSION_INGRESS_URL:()=>hL,CLAUDE_CHROME_PAIRED_DEVICE_ID:()=>EL,CLAUDE_CHROME_PERMISSION_MODE:()=>_L,CLAUDE_CHROME_TAB_GROUP_KEY:()=>SL,CLAUDE_CLIENT_PRESENCE_FILE:()=>yL,CLAUDE_CODE_ACTION:()=>OL,CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD:()=>AL,CLAUDE_CODE_ADDITIONAL_PROTECTION:()=>Ew,CLAUDE_CODE_ADOPT_UNDERIVABLE_PARKED_PERMISSION:()=>px,CLAUDE_CODE_AGENT:()=>bL,CLAUDE_CODE_APPEND_PROMPT_HEAD:()=>CL,CLAUDE_CODE_ARTIFACT:()=>TL,CLAUDE_CODE_ARTIFACTS_API_BASE_URL:()=>DL,CLAUDE_CODE_ARTIFACTS_API_TOKEN:()=>LL,CLAUDE_CODE_ARTIFACT_ASSET_BASE_URL:()=>IL,CLAUDE_CODE_ARTIFACT_AUTO_OPEN:()=>RL,CLAUDE_CODE_ARTIFACT_LIVE_BASE_URL:()=>PL,CLAUDE_CODE_ARTIFACT_SYNC_BASE_URL:()=>wL,CLAUDE_CODE_ARTIFACT_VIEWER_BASE_URL:()=>xL,CLAUDE_CODE_ATTRIBUTION_STATUS_TIMEOUT_MS:()=>NL,CLAUDE_CODE_AUTO_COMPACT_WINDOW:()=>kL,CLAUDE_CODE_AUTO_MODE_EXTERNAL_PERMISSIONS:()=>_w,CLAUDE_CODE_AUTO_MODE_TIER:()=>Sw,CLAUDE_CODE_BASE_REF:()=>ML,CLAUDE_CODE_BASE_REFS:()=>UL,CLAUDE_CODE_BLOCKING_LIMIT_OVERRIDE:()=>HL,CLAUDE_CODE_BRIDGE_CHILD_ARTIFACT:()=>aI,CLAUDE_CODE_BRIDGE_CHILD_AUTO_DEFAULT:()=>iI,CLAUDE_CODE_BRIDGE_CHILD_MACHINE_SETTINGS:()=>lI,CLAUDE_CODE_BRIDGE_MCP_CARRIER:()=>zL,CLAUDE_CODE_BRIDGE_OWNER_ACCOUNT_UUID:()=>FL,CLAUDE_CODE_BRIDGE_OWNER_ORG_UUID:()=>BL,CLAUDE_CODE_BRIDGE_PROMPT_SHA256:()=>WL,CLAUDE_CODE_BRIDGE_SESSION_ID:()=>jL,CLAUDE_CODE_BRIDGE_SOURCE_DIR:()=>GL,CLAUDE_CODE_BRIEF:()=>yw,CLAUDE_CODE_BRIEF_UPLOAD:()=>Ow,CLAUDE_CODE_CCR_SURFACE:()=>lx,CLAUDE_CODE_CLASSIFIER_SUMMARY:()=>VL,CLAUDE_CODE_CONFIG_PROBE:()=>cI,CLAUDE_CODE_CONFIG_WATCH_EVENTS:()=>dI,CLAUDE_CODE_CONTAINER_ID:()=>KL,CLAUDE_CODE_COORDINATOR_SKILL_GUIDANCE:()=>Aw,CLAUDE_CODE_DAEMON_COLD_START:()=>bw,CLAUDE_CODE_DECSTBM:()=>YL,CLAUDE_CODE_DESKTOP_APP_VERSION:()=>XL,CLAUDE_CODE_DEV_RAW_CHANGELOG_URL:()=>JL,CLAUDE_CODE_DISABLE_ATTRIBUTION_BASELINE_REUSE:()=>vL,CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP:()=>Cw,CLAUDE_CODE_DISABLE_HOOK_FORWARDING:()=>qL,CLAUDE_CODE_DISABLE_PLUGIN_FORWARDING:()=>QL,CLAUDE_CODE_DISABLE_TURN_HANDOFF:()=>eI,CLAUDE_CODE_DISABLE_VITALS_EMITTER:()=>tI,CLAUDE_CODE_DISABLE_WORKING_SYNC:()=>nI,CLAUDE_CODE_DONT_INHERIT_ENV:()=>Tw,CLAUDE_CODE_DOWNLOAD_DEADLINE_MS_FOR_TESTING:()=>oI,CLAUDE_CODE_EMIT_SESSION_STATE_EVENTS:()=>Rw,CLAUDE_CODE_EMIT_STARTUP_TIMING:()=>Lw,CLAUDE_CODE_EMIT_TOOL_USE_SUMMARIES:()=>Iw,CLAUDE_CODE_ENTRYPOINT:()=>rI,CLAUDE_CODE_ENVIRONMENT_KIND:()=>sI,CLAUDE_CODE_ENVIRONMENT_RUNNER_VERSION:()=>uI,CLAUDE_CODE_EVAL_CONFINED:()=>nx,CLAUDE_CODE_EXIT_AFTER_FIRST_RENDER:()=>Pw,CLAUDE_CODE_EXIT_AFTER_STOP_DELAY:()=>Wx,CLAUDE_CODE_FLAG_FETCH_WAIT_MS:()=>ww,CLAUDE_CODE_FOOTER_INDICATOR:()=>pI,CLAUDE_CODE_FORCE_BRIDGE:()=>xw,CLAUDE_CODE_FORCE_EVALUATE_MEMORY:()=>Nw,CLAUDE_CODE_FORCE_FULLSCREEN_UPSELL:()=>vw,CLAUDE_CODE_FORCE_MEMORY_SURVEY:()=>kw,CLAUDE_CODE_FORCE_TIP_ID:()=>fI,CLAUDE_CODE_GIT_BASH_PATH:()=>mI,CLAUDE_CODE_GLOB_TIMEOUT_SECONDS:()=>jx,CLAUDE_CODE_GOAL_CHECKIN_MINUTES:()=>$x,CLAUDE_CODE_HIDE_SETTINGS_HINT:()=>gI,CLAUDE_CODE_HOLD_REPORT_PARK_AT_INIT:()=>Ex,CLAUDE_CODE_HOME_SEED_HOLD_TIMEOUT_MS:()=>hI,CLAUDE_CODE_HOME_SEED_VERDICT_TIMEOUT_MS:()=>EI,CLAUDE_CODE_HOSTED_DESKTOP:()=>Uw,CLAUDE_CODE_HOST_PLATFORM:()=>_I,CLAUDE_CODE_HOST_PROMPT_SUPERSEDES_RECORD:()=>Mw,CLAUDE_CODE_HOST_SESSION_ID:()=>SI,CLAUDE_CODE_HOST_SKILL_CATALOG:()=>yI,CLAUDE_CODE_HOST_WORKTREE:()=>OI,CLAUDE_CODE_HOST_WORKTREE_FENCE:()=>AI,CLAUDE_CODE_IDE_HOST_OVERRIDE:()=>bI,CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS:()=>CI,CLAUDE_CODE_IDLE_THRESHOLD_MINUTES:()=>Vx,CLAUDE_CODE_IDLE_TOKEN_THRESHOLD:()=>Kx,CLAUDE_CODE_IS_COWORK:()=>Hw,CLAUDE_CODE_LEGACY_BUNDLE:()=>ZL,CLAUDE_CODE_LOOP_KEEPALIVE:()=>zw,CLAUDE_CODE_LOOP_PERSISTENT:()=>Fw,CLAUDE_CODE_MANAGED_SETTINGS_PATH:()=>TI,CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS:()=>Yx,CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH:()=>GN,CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH:()=>Xx,CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION:()=>Jx,CLAUDE_CODE_MCP_ALLOWLIST_ENV:()=>RI,CLAUDE_CODE_MCP_APPS_HOST:()=>BN,CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS:()=>MN,CLAUDE_CODE_MCP_CONNECTOR_PREWAIT_MS:()=>UN,CLAUDE_CODE_MCP_MEMORY_CGROUP:()=>Lx,CLAUDE_CODE_MCP_PREWAIT_SERVERS:()=>zN,CLAUDE_CODE_MCP_PREWAIT_SERVERS_MS:()=>FN,CLAUDE_CODE_MCP_STARTUP_WAIT_MS:()=>HN,CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT:()=>kN,CLAUDE_CODE_MEMORY_SUBAGENT_APPEND:()=>tw,CLAUDE_CODE_MOCK_REMOTE_SETTINGS:()=>Bw,CLAUDE_CODE_MOCK_TRIAL:()=>Gw,CLAUDE_CODE_OVERRIDE_DATE:()=>DI,CLAUDE_CODE_PARKED_PERMISSION_WAIT_MS:()=>ux,CLAUDE_CODE_PARKED_RUN_BEFORE_CLEAR:()=>hx,CLAUDE_CODE_PARKED_STOP_RETIRES:()=>gx,CLAUDE_CODE_PERFORCE_MODE:()=>II,CLAUDE_CODE_PLAN_V2_AGENT_COUNT:()=>qx,CLAUDE_CODE_PLAN_V2_EXPLORE_AGENT_COUNT:()=>Qx,CLAUDE_CODE_PLUGIN_ATTRIBUTION:()=>PI,CLAUDE_CODE_PLUGIN_CACHE_DIR:()=>wI,CLAUDE_CODE_PLUGIN_GIT_TIMEOUT_MS:()=>eN,CLAUDE_CODE_PLUGIN_SEED_DIR:()=>xI,CLAUDE_CODE_POST_TURN_MEMORY:()=>Ww,CLAUDE_CODE_POST_TURN_MEMORY_CONFIG:()=>NI,CLAUDE_CODE_POST_TURN_MEMORY_SYNC:()=>jw,CLAUDE_CODE_POWERUP_ONBOARDING:()=>vI,CLAUDE_CODE_PROJECT_DIR_NAME:()=>kI,CLAUDE_CODE_PWSH_PARSE_TIMEOUT_MS:()=>tN,CLAUDE_CODE_QUESTION_EXTENDED:()=>UI,CLAUDE_CODE_QUESTION_OPTIONAL_DESCRIPTIONS:()=>HI,CLAUDE_CODE_QUESTION_PREVIEW_FORMAT:()=>MI,CLAUDE_CODE_RELAUNCH_HOME_TRUST:()=>zI,CLAUDE_CODE_RELAUNCH_PROACTIVITY_BASELINE:()=>FI,CLAUDE_CODE_RELAUNCH_PROACTIVITY_DECIDED:()=>BI,CLAUDE_CODE_RELAUNCH_PROACTIVITY_EVER_ON:()=>GI,CLAUDE_CODE_RELAUNCH_PROACTIVITY_LEVEL:()=>WI,CLAUDE_CODE_RELAUNCH_TERMINAL_SIZE:()=>jI,CLAUDE_CODE_REMOTE:()=>$w,CLAUDE_CODE_REMOTE_ENVIRONMENT_TYPE:()=>$I,CLAUDE_CODE_REMOTE_HERMETIC_MODE:()=>Vw,CLAUDE_CODE_REMOTE_MEMORY_DIR:()=>VI,CLAUDE_CODE_REMOTE_RAW_EVENTS_FILE:()=>KI,CLAUDE_CODE_REMOTE_SDK_URL:()=>YI,CLAUDE_CODE_REMOTE_SEND_KEEPALIVES:()=>Kw,CLAUDE_CODE_REMOTE_SESSION_ID:()=>XI,CLAUDE_CODE_REMOTE_SESSION_ORIGIN:()=>JI,CLAUDE_CODE_REMOTE_SETTINGS_PATH:()=>ZI,CLAUDE_CODE_REMOTE_SETTINGS_POLL_MS:()=>nN,CLAUDE_CODE_REPL:()=>Yw,CLAUDE_CODE_REPO_CHECKOUTS:()=>qI,CLAUDE_CODE_RESTRICTED:()=>Xw,CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG:()=>Jw,CLAUDE_CODE_RESULT_NONCE:()=>$L,CLAUDE_CODE_RESUME_FROM_SESSION:()=>QI,CLAUDE_CODE_RESUME_INTERRUPTED_TURN:()=>Zw,CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS:()=>Qw,CLAUDE_CODE_RESUME_PROMPT:()=>eP,CLAUDE_CODE_RESUME_REASON:()=>ex,CLAUDE_CODE_RESUME_SOURCE_ALIVE:()=>qw,CLAUDE_CODE_RESUME_THRESHOLD_MINUTES:()=>oN,CLAUDE_CODE_RESUME_TOKEN_THRESHOLD:()=>rN,CLAUDE_CODE_RESUME_TOLERATES_CONTEXT_APPENDS:()=>fx,CLAUDE_CODE_RESUME_TOLERATES_CONTEXT_SEEDS:()=>mx,CLAUDE_CODE_SAFE_MODE:()=>tx,CLAUDE_CODE_SANDBOXED:()=>ox,CLAUDE_CODE_SCRIPT_CAPS:()=>sN,CLAUDE_CODE_SCROLL_SPEED:()=>tP,CLAUDE_CODE_SDK_READS_SESSION_STATE:()=>Dw,CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS:()=>iN,CLAUDE_CODE_SESSION_ID:()=>nP,CLAUDE_CODE_SESSION_KIND:()=>oP,CLAUDE_CODE_SESSION_NAME:()=>rP,CLAUDE_CODE_SESSION_ORIGIN:()=>sP,CLAUDE_CODE_SESSION_START_ANNOUNCEMENTS_BEFORE_PROMPT:()=>rx,CLAUDE_CODE_SHELL:()=>iP,CLAUDE_CODE_SHELL_PREFIX:()=>aP,CLAUDE_CODE_SIMPLE:()=>sx,CLAUDE_CODE_SIMPLE_SYSTEM_PROMPT:()=>lP,CLAUDE_CODE_SKILL_ATTRIBUTION:()=>cP,CLAUDE_CODE_SLEEP_COMPACT:()=>dP,CLAUDE_CODE_SPAWN_TIMESTAMP_MS:()=>aN,CLAUDE_CODE_SSE_PORT:()=>lN,CLAUDE_CODE_STALL_TIMEOUT_MS_FOR_TESTING:()=>uP,CLAUDE_CODE_STARTUP_FAILURE_RESULTS:()=>LI,CLAUDE_CODE_STOP_HOOK_BLOCK_CAP:()=>cN,CLAUDE_CODE_SUBPROCESS_ENV_SCRUB:()=>ix,CLAUDE_CODE_SUPERVISED:()=>ax,CLAUDE_CODE_SYNC_PLUGINS_BUFFERED_DOWNLOAD:()=>cx,CLAUDE_CODE_SYNC_PLUGINS_DOWNLOAD_STALL_MS:()=>dx,CLAUDE_CODE_SYNC_PLUGINS_INSTALL_TIMEOUT_MS:()=>uN,CLAUDE_CODE_SYNC_PLUGINS_MCP_TIMEOUT_MS:()=>pN,CLAUDE_CODE_SYNC_PLUGIN_INSTALL_TIMEOUT_MS:()=>dN,CLAUDE_CODE_SYNC_REUSE_WITHIN_MS:()=>fN,CLAUDE_CODE_SYNC_SESSION_REFS:()=>_x,CLAUDE_CODE_SYNC_SKILLS_INSTALL_TIMEOUT_MS:()=>mN,CLAUDE_CODE_SYNC_SKILLS_WAIT_TIMEOUT_MS:()=>gN,CLAUDE_CODE_SYNTAX_HIGHLIGHT:()=>Sx,CLAUDE_CODE_SYSTEM_PROMPT_GB_FEATURE:()=>pP,CLAUDE_CODE_TAGS:()=>fP,CLAUDE_CODE_TASK_LIST_ID:()=>gP,CLAUDE_CODE_TEAM_TEARDOWN_PARK_TIMEOUT_MS:()=>hN,CLAUDE_CODE_TERMINAL_MCP_TOOLS:()=>mP,CLAUDE_CODE_TEST_ALLOW_REAL_NETWORK:()=>yx,CLAUDE_CODE_TEST_FIXTURES_ROOT:()=>hP,CLAUDE_CODE_TEST_FORCE_DENY:()=>Ox,CLAUDE_CODE_TEST_NO_GIT_BASH:()=>Ax,CLAUDE_CODE_TEST_NO_PWSH:()=>bx,CLAUDE_CODE_TMPDIR:()=>EP,CLAUDE_CODE_TMUX_PREFIX:()=>_P,CLAUDE_CODE_TMUX_PREFIX_CONFLICTS:()=>Cx,CLAUDE_CODE_TMUX_SESSION:()=>SP,CLAUDE_CODE_TMUX_TRUECOLOR:()=>Tx,CLAUDE_CODE_TOOL_MEMORY_CGROUP_EXCLUDE:()=>Rx,CLAUDE_CODE_TOOL_MEMORY_LIMIT:()=>Dx,CLAUDE_CODE_TRIGGER_ID:()=>yP,CLAUDE_CODE_TUI_JUST_SWITCHED:()=>Ix,CLAUDE_CODE_TUI_TRIAL:()=>Px,CLAUDE_CODE_ULTRAREVIEW_PREFLIGHT_FIXTURE:()=>OP,CLAUDE_CODE_ULTRAREVIEW_QUOTA_FIXTURE:()=>AP,CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS:()=>EN,CLAUDE_CODE_VOICE_FORWARD_INTERIMS_TYPED:()=>wx,CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR:()=>Zx,CLAUDE_CODE_WORKER_CHECKIN_SCHEDULE:()=>bP,CLAUDE_CODE_WORKER_EPOCH:()=>_N,CLAUDE_CODE_WORKSPACE_HOST_PATHS:()=>CP,CLAUDE_CONFIG_DIR:()=>TP,CLAUDE_COWORK_MEMORY_EXTRA_GUIDELINES:()=>RP,CLAUDE_COWORK_MEMORY_GUIDELINES:()=>DP,CLAUDE_COWORK_MEMORY_INDEX_CONTENT:()=>LP,CLAUDE_COWORK_MEMORY_PATH_OVERRIDE:()=>IP,CLAUDE_ENV_FILE:()=>PP,CLAUDE_FORCE_DISPLAY_SURVEY:()=>xx,CLAUDE_INTERNAL_ASSISTANT_TEAM_NAME:()=>wP,CLAUDE_INTERNAL_FC_OVERRIDES:()=>xP,CLAUDE_JOB_DIR:()=>NP,CLAUDE_MEMORY_STORES:()=>vP,CLAUDE_PROJECT_UUID:()=>kP,CLAUDE_PTY_HEARTBEAT_MS:()=>SN,CLAUDE_PTY_HOST_EXEC:()=>MP,CLAUDE_PTY_HOST_NO_STABLE_PATH:()=>UP,CLAUDE_PTY_ORPHAN_CHECK_MS:()=>yN,CLAUDE_RELAUNCH_SESSION_ADD_DIRS:()=>HP,CLAUDE_REMOTE_CONTROL_SESSION_NAME_PREFIX:()=>zP,CLAUDE_REMOTE_WORKFLOW_ARGS:()=>FP,CLAUDE_REMOTE_WORKFLOW_SCRIPT:()=>BP,CLAUDE_RUNNER_ACTIVITY_FD:()=>ON,CLAUDE_RUNNER_FETCH_DEPTH:()=>GP,CLAUDE_RUNNER_FETCH_SERVER_PROGRESS_CAP_MS:()=>WP,CLAUDE_SECURESTORAGE_CONFIG_DIR:()=>jP,CLAUDE_SERVE_DRAIN_TIMEOUT_MS:()=>AN,CLAUDE_SNIP:()=>$P,CLAUDE_SSH_LOCAL_BINARY:()=>VP,CLAUDE_SSH_VERSION:()=>KP,CLAUDE_STAGE_FILE_ROOT:()=>YP,CLAUDE_TMPDIR:()=>XP,LOCAL_BRIDGE:()=>Nx,MCP_CONNECTION_NONBLOCKING:()=>vx,MCP_CONNECT_TIMEOUT_MS:()=>bN,MCP_DISCOVERY_CACHE:()=>CN,MCP_DISCOVERY_CACHE_MAX_STALE_S:()=>TN,MCP_DISCOVERY_CACHE_STRIKES:()=>RN,MCP_DISCOVERY_CACHE_TTL_S:()=>DN,MCP_OAUTH_CALLBACK_PORT:()=>LN,MCP_OAUTH_CLIENT_METADATA_URL:()=>JP,MCP_PROTOCOL_NEGOTIATION:()=>IN,MCP_REMOTE_SERVER_CONNECTION_BATCH_SIZE:()=>PN,MCP_SDK_GENERATION:()=>xN,MCP_SERVER_CONNECTION_BATCH_SIZE:()=>wN,MCP_TIMEOUT:()=>NN,MCP_TOOL_TIMEOUT:()=>vN,MCP_TRUNCATION_PROMPT_OVERRIDE:()=>ZP,SDK_NATIVE_BIN:()=>qP,SESSION_INGRESS_URL:()=>QP,SLASH_COMMAND_TOOL_CHAR_BUDGET:()=>WN,SYSTEM_REMINDER_MEMORY_CONTEXT:()=>ew,TEST_ENABLE_SESSION_PERSISTENCE:()=>kx,ULTRAPLAN_PROMPT_FILE:()=>nw,VCR_RECORD:()=>Mx,VITALS_EMITTER_BIN:()=>ow,VOICE_STREAM_BASE_URL:()=>rw});var zD=I.str(),FD=I.str(),BD=I.str(),GD=I.str(),WD=I.str(),jD=I.rawStr(),$D=I.str(),VD=I.str(),KD=I.str(),YD=I.str(),XD=I.str(),JD=I.str(),ZD=I.str(),qD=I.str(),QD=I.str(),eL=I.bool(),tL=I.str(),nL=I.str(),oL=I.str(),rL=I.str(),sL=I.str(),iL=I.str(),aL=I.str(),lL=I.bool(),cL=I.str(),dL=I.str(),uL=I.str(),pL=I.str(),fL=I.str(),mL=I.str(),gL=I.str(),hL=I.str(),EL=I.str(),_L=I.str(),SL=I.str(),yL=I.str(),OL=I.str(),AL=I.str(),bL=I.str(),CL=I.str(),TL=I.str(),RL=I.str(),DL=I.str(),LL=I.str(),IL=I.str(),PL=I.str(),wL=I.str(),xL=I.str(),NL=I.int({min:0}),vL=I.bool(),kL=I.str(),ML=I.str(),UL=I.str(),HL=I.str(),zL=I.enum(["1","spent"]),FL=I.str(),BL=I.str(),GL=I.str(),WL=I.str(),jL=I.str(),$L=I.str(),VL=I.str(),KL=I.str(),YL=I.str(),XL=I.str(),JL=I.str(),ZL=I.bool(),qL=I.bool(),QL=I.bool(),eI=I.bool(),tI=I.bool(),nI=I.bool(),oI=I.str(),rI=I.str(),sI=I.str(),iI=I.bool(),aI=I.bool(),lI=I.bool(),cI=I.bool(),dI=I.bool(),uI=I.str(),pI=I.str(),fI=I.str(),mI=I.str(),gI=I.str(),hI=I.int({min:0}),EI=I.int({min:0}),_I=I.str(),SI=I.str(),yI=I.str(),OI=I.str(),AI=I.str(),bI=I.str(),CI=I.int({min:1,wholeValue:!0}),TI=I.str(),RI=I.str(),DI=I.str(),LI=I.bool(),II=I.str(),PI=I.str(),wI=I.str(),xI=I.str(),NI=I.str(),vI=I.str(),kI=I.str(),MI=I.str(),UI=I.bool(),HI=I.bool(),zI=I.str(),FI=I.str(),BI=I.str(),GI=I.str(),WI=I.str(),jI=I.str(),$I=I.str(),VI=I.str(),KI=I.str(),YI=I.str(),XI=I.str(),JI=I.str(),ZI=I.str(),qI=I.str(),QI=I.str(),eP=I.str(),tP=I.str(),nP=I.str(),oP=I.str(),rP=I.str(),sP=I.enum(["claude_ai_chat"]),iP=I.str(),aP=I.str(),lP=I.str(),cP=I.str(),dP=I.bool(),uP=I.str(),pP=I.str(),fP=I.str(),mP=I.str(),gP=I.str(),hP=I.str(),EP=I.str(),_P=I.str(),SP=I.str(),yP=I.str(),OP=I.str(),AP=I.str(),bP=I.str(),CP=I.str(),TP=I.str(),RP=I.str(),DP=I.str(),LP=I.str(),IP=I.str(),PP=I.str(),wP=I.str(),xP=I.str(),NP=I.str(),vP=I.str(),kP=I.str(),MP=I.str(),UP=I.str(),HP=I.str(),zP=I.str(),FP=I.str(),BP=I.str(),GP=I.str(),WP=I.str(),jP=I.str(),$P=I.str(),VP=I.str(),KP=I.str(),YP=I.str(),XP=I.str(),JP=I.str(),ZP=I.str(),qP=I.str(),QP=I.str(),ew=I.bool(),tw=I.bool(),nw=I.str(),ow=I.str(),rw=I.str(),sw=I.bool(),iw=I.bool(),aw=I.bool(),lw=I.bool(),cw=I.bool(),dw=I.bool(),uw=I.bool(),pw=I.bool(),fw=I.bool(),mw=I.bool(),gw=I.bool(),hw=I.bool(),Ew=I.bool(),_w=I.bool(),Sw=I.rawStr(),yw=I.bool(),Ow=I.bool(),Aw=I.bool(),bw=I.bool(),Cw=I.bool(),Tw=I.bool(),Rw=I.bool(),Dw=I.bool(),Lw=I.bool(),Iw=I.bool(),Pw=I.bool(),ww=I.int({min:0}),xw=I.bool(),Nw=I.bool(),vw=I.bool(),kw=I.bool(),Mw=I.bool(),Uw=I.bool(),Hw=I.bool(),zw=I.triBool(),Fw=I.bool(),Bw=I.str(),Gw=I.bool(),Ww=I.bool(),jw=I.bool(),$w=I.bool(),Vw=I.bool(),Kw=I.bool(),Yw=I.triBool(),Xw=I.bool(),Jw=I.bool(),Zw=I.bool(),qw=I.str(),Qw=I.str(),ex=I.str(),tx=I.bool(),nx=I.bool(),ox=I.bool(),rx=I.bool(),sx=I.bool(),ix=I.triBool(),ax=I.bool(),lx=I.str(),cx=I.bool(),dx=I.int({min:1}),ux=I.int({min:0}),px=I.bool(),fx=I.bool(),mx=I.bool(),gx=I.bool(),hx=I.bool(),Ex=I.bool(),_x=I.bool(),Sx=I.str(),yx=I.bool(),Ox=I.rawStr(),Ax=I.str(),bx=I.str(),Cx=I.bool(),Tx=I.rawStr(),Rx=I.str(),Dx=I.str(),Lx=I.str(),Ix=I.str(),Px=I.str(),wx=I.bool(),xx=I.bool(),Nx=I.bool(),vx=I.triBool(),kx=I.bool(),Mx=I.bool(),Ux=I.int(),Hx=I.int(),zx=I.int(),Fx=I.int({min:1,max:2147483647,digitsOnly:!0}),Bx=I.int(),Gx=I.int(),Wx=I.int(),jx=I.int({min:1}),$x=I.int({min:0,max:10080,digitsOnly:!0}),Vx=I.int(),Kx=I.int(),Yx=I.int({min:1,digitsOnly:!0}),Xx=I.int({min:1,digitsOnly:!0}),Jx=I.int({min:1,digitsOnly:!0}),Zx=I.int({min:0,digitsOnly:!0}),qx=I.int(),Qx=I.int(),eN=I.int(),tN=I.int(),nN=I.int(),oN=I.int(),rN=I.int(),sN=I.int(),iN=I.int({min:1}),aN=I.int(),lN=I.int(),cN=I.int(),dN=I.int({min:1}),uN=I.int({min:1}),pN=I.int({min:0}),fN=I.int({min:0,max:86400000}),mN=I.int(),gN=I.int(),hN=I.int({min:1000,max:60000}),EN=I.int({wholeValue:!0}),_N=I.int(),SN=I.int({min:1}),yN=I.int({min:1}),ON=I.int({min:3}),AN=I.int({min:1}),bN=I.int(),CN=I.triBool(),TN=I.int({min:1}),RN=I.int({min:1}),DN=I.int({min:1}),LN=I.int({min:1}),IN=I.str(),PN=I.int({min:1}),wN=I.int({min:1}),xN=I.str(),NN=I.int(),vN=I.int({min:1}),kN=I.int(),MN=I.int(),UN=I.int({min:1}),HN=I.int({min:0}),zN=I.str(),FN=I.int({min:0,digitsOnly:!0}),BN=I.bool(),GN=I.int({min:1,digitsOnly:!0}),WN=I.int({min:1});var ii={};D(ii,{ANTHROPIC_CUSTOM_MODEL_OPTION:()=>uv,ANTHROPIC_CUSTOM_MODEL_OPTION_DESCRIPTION:()=>fv,ANTHROPIC_CUSTOM_MODEL_OPTION_NAME:()=>pv,ANTHROPIC_DEFAULT_FABLE_MODEL:()=>KN,ANTHROPIC_DEFAULT_FABLE_MODEL_DESCRIPTION:()=>XN,ANTHROPIC_DEFAULT_FABLE_MODEL_NAME:()=>YN,ANTHROPIC_DEFAULT_HAIKU_MODEL:()=>nv,ANTHROPIC_DEFAULT_HAIKU_MODEL_DESCRIPTION:()=>rv,ANTHROPIC_DEFAULT_HAIKU_MODEL_NAME:()=>ov,ANTHROPIC_DEFAULT_MODEL:()=>$N,ANTHROPIC_DEFAULT_OPUS_MODEL:()=>JN,ANTHROPIC_DEFAULT_OPUS_MODEL_DESCRIPTION:()=>qN,ANTHROPIC_DEFAULT_OPUS_MODEL_NAME:()=>ZN,ANTHROPIC_DEFAULT_SONNET_MODEL:()=>QN,ANTHROPIC_DEFAULT_SONNET_MODEL_DESCRIPTION:()=>tv,ANTHROPIC_DEFAULT_SONNET_MODEL_NAME:()=>ev,ANTHROPIC_MODEL:()=>jN,ANTHROPIC_SMALL_FAST_MODEL:()=>VN,CLAUDE_CODE_3P_PROBE_WROTE_HAIKU_DEFAULT:()=>av,CLAUDE_CODE_3P_PROBE_WROTE_OPUS_DEFAULT:()=>iv,CLAUDE_CODE_3P_PROBE_WROTE_SONNET_DEFAULT:()=>sv,CLAUDE_CODE_3P_SEEDED_OPUS_DEFAULT:()=>cv,CLAUDE_CODE_3P_SEEDED_SONNET_DEFAULT:()=>lv,CLAUDE_CODE_ALWAYS_ENABLE_EFFORT:()=>Cv,CLAUDE_CODE_AUTO_MODE_MODEL:()=>hv,CLAUDE_CODE_BG_CLASSIFIER_MODEL:()=>Ev,CLAUDE_CODE_CLIENT_DATA_URL:()=>Nv,CLAUDE_CODE_DISABLE_1M_CONTEXT:()=>Iv,CLAUDE_CODE_DISABLE_EXPLORE_INHERIT_CAP:()=>Ov,CLAUDE_CODE_DISABLE_FAST_MODE:()=>Rv,CLAUDE_CODE_DISABLE_LEGACY_MODEL_REMAP:()=>Av,CLAUDE_CODE_DISABLE_MODEL_ACCESS_FALLBACK:()=>yv,CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT:()=>Pv,CLAUDE_CODE_EFFORT_LEVEL:()=>bv,CLAUDE_CODE_MAX_EFFORT_REMINDER:()=>Tv,CLAUDE_CODE_MODEL_CATALOG:()=>wv,CLAUDE_CODE_MODEL_CATALOG_URL:()=>xv,CLAUDE_CODE_NO_MODEL_FALLBACK:()=>Sv,CLAUDE_CODE_SKIP_FAST_MODE_NETWORK_ERRORS:()=>Dv,CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK:()=>Lv,CLAUDE_CODE_SKIP_MODEL_ACCESS_MEMORY:()=>dv,CLAUDE_CODE_SUBAGENT_MODEL:()=>mv,CLAUDE_CODE_SUBAGENT_MODEL_FORCE:()=>gv,FALLBACK_FOR_ALL_PRIMARY_MODELS:()=>_v});var jN=I.str(),$N=I.str(),VN=I.str(),KN=I.str(),YN=I.str(),XN=I.str(),JN=I.str(),ZN=I.str(),qN=I.str(),QN=I.str(),ev=I.str(),tv=I.str(),nv=I.str(),ov=I.str(),rv=I.str(),sv=I.str(),iv=I.str(),av=I.str(),lv=I.str(),cv=I.str(),dv=I.bool(),uv=I.str(),pv=I.str(),fv=I.str(),mv=I.str(),gv=I.bool(),hv=I.str(),Ev=I.str(),_v=I.str(),Sv=I.bool(),yv=I.bool(),Ov=I.bool(),Av=I.bool(),bv=I.str(),Cv=I.bool(),Tv=I.triBool(),Rv=I.bool(),Dv=I.bool(),Lv=I.bool(),Iv=I.bool(),Pv=I.bool(),wv=I.str(),xv=I.str(),Nv=I.str();var ai={};D(ai,{ALL_PROXY:()=>Fv,ANTHROPIC_BETAS:()=>Kv,ANTHROPIC_CUSTOM_HEADERS:()=>Yv,API_FORCE_IDLE_TIMEOUT:()=>dk,API_TIMEOUT_MS:()=>ak,CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS:()=>yk,CLAUDE_CODE_ATTRIBUTION_HEADER:()=>Zv,CLAUDE_CODE_CERT_STORE:()=>Vv,CLAUDE_CODE_CLIENT_CERT:()=>Gv,CLAUDE_CODE_CLIENT_KEY:()=>Wv,CLAUDE_CODE_CLIENT_KEY_PASSPHRASE:()=>jv,CLAUDE_CODE_DISABLE_MTLS_RELOAD_ON_STALE_CONNECTION:()=>$v,CLAUDE_CODE_EAGER_FLUSH:()=>Tk,CLAUDE_CODE_EXTRA_BODY:()=>Xv,CLAUDE_CODE_EXTRA_METADATA:()=>Jv,CLAUDE_CODE_FILE_READ_MAX_OUTPUT_TOKENS:()=>tk,CLAUDE_CODE_FORCE_SYNC_OUTPUT:()=>Rk,CLAUDE_CODE_GZIP_CCR_REQUEST_BODIES:()=>gk,CLAUDE_CODE_GZIP_DATADOG_LOGS:()=>hk,CLAUDE_CODE_GZIP_REQUEST_BODIES:()=>mk,CLAUDE_CODE_GZIP_REQUEST_BODY_BLOCKS:()=>_k,CLAUDE_CODE_GZIP_REQUEST_BODY_LEVEL:()=>Ek,CLAUDE_CODE_MAX_CONTEXT_TOKENS:()=>ek,CLAUDE_CODE_MAX_OUTPUT_TOKENS:()=>Qv,CLAUDE_CODE_MAX_RETRIES:()=>qv,CLAUDE_CODE_MAX_TOOL_USE_CONCURRENCY:()=>nk,CLAUDE_CODE_MAX_TURNS:()=>ok,CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES:()=>lk,CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS:()=>ck,CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS:()=>Ik,CLAUDE_CODE_RETRY_WATCHDOG:()=>bk,CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS:()=>Ck,CLAUDE_CODE_SLOW_OPERATION_THRESHOLD_MS:()=>Lk,CLAUDE_ENABLE_BYTE_WATCHDOG:()=>uk,CLAUDE_ENABLE_BYTE_WATCHDOG_BEDROCK:()=>pk,CLAUDE_ENABLE_STREAM_WATCHDOG:()=>fk,CLAUDE_MOCK_HEADERLESS_429:()=>Dk,CLAUDE_SLOW_FIRST_BYTE_MS:()=>Ak,CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS:()=>Ok,CLAUDE_STREAM_IDLE_TIMEOUT_MS:()=>Sk,HTTPS_PROXY:()=>kv,HTTP_PROXY:()=>vv,MAX_MCP_OUTPUT_TOKENS:()=>ik,MAX_STRUCTURED_OUTPUT_RETRIES:()=>sk,MAX_THINKING_TOKENS:()=>rk,NO_PROXY:()=>Mv,all_proxy:()=>Bv,http_proxy:()=>Uv,https_proxy:()=>Hv,no_proxy:()=>zv});var vv=I.str(),kv=I.str(),Mv=I.str(),Uv=I.str(),Hv=I.str(),zv=I.str(),Fv=I.str(),Bv=I.str(),Gv=I.str(),Wv=I.str(),jv=I.str(),$v=I.bool(),Vv=I.str(),Kv=I.str(),Yv=I.str(),Xv=I.str(),Jv=I.str(),Zv=I.str(),qv=I.int(),Qv=I.int(),ek=I.int(),tk=I.int(),nk=I.int({min:1}),ok=I.str(),rk=I.int(),sk=I.int(),ik=I.int(),ak=I.int(),lk=I.int({min:0,digitsOnly:!0}),ck=I.int({min:500,max:32000,digitsOnly:!0}),dk=I.int(),uk=I.triBool(),pk=I.bool(),fk=I.triBool(),mk=I.triBool(),gk=I.triBool(),hk=I.triBool(),Ek=I.int({min:0,max:9,digitsOnly:!0}),_k=I.int({min:0,max:2,digitsOnly:!0}),Sk=I.int({min:1}),yk=I.int({min:1}),Ok=I.int({min:1}),Ak=I.int({min:1}),bk=I.bool(),Ck=I.int({min:1,digitsOnly:!0}),Tk=I.bool(),Rk=I.bool(),Dk=I.bool(),Lk=I.int(),Ik=I.int({min:0});var li={};D(li,{AGENT_PROXY_URL:()=>WM,ANTHROPIC_AWS_BASE_URL:()=>Wk,ANTHROPIC_AWS_WORKSPACE_ID:()=>jk,ANTHROPIC_BASE_URL:()=>Mk,ANTHROPIC_BEDROCK_BASE_URL:()=>zk,ANTHROPIC_BEDROCK_MANTLE_BASE_URL:()=>Gk,ANTHROPIC_BEDROCK_REGION_PREFIX:()=>Fk,ANTHROPIC_BEDROCK_SERVICE_TIER:()=>Bk,ANTHROPIC_FOUNDRY_BASE_URL:()=>qk,ANTHROPIC_FOUNDRY_RESOURCE:()=>Qk,ANTHROPIC_GOOGLE_CLOUD_BASE_URL:()=>Yk,ANTHROPIC_GOOGLE_CLOUD_LOCATION:()=>Vk,ANTHROPIC_GOOGLE_CLOUD_PROJECT:()=>$k,ANTHROPIC_GOOGLE_CLOUD_WORKSPACE_ID:()=>Kk,ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION:()=>fM,ANTHROPIC_UNIX_SOCKET:()=>mM,ANTHROPIC_VERTEX_BASE_URL:()=>Xk,ANTHROPIC_VERTEX_PROJECT_ID:()=>Jk,AWS_ACCESS_KEY_ID:()=>sM,AWS_CONFIG_FILE:()=>oM,AWS_DEFAULT_REGION:()=>tM,AWS_ENDPOINT_URL:()=>lM,AWS_ENDPOINT_URL_BEDROCK:()=>cM,AWS_ENDPOINT_URL_BEDROCK_RUNTIME:()=>dM,AWS_ENDPOINT_URL_STS:()=>uM,AWS_PROFILE:()=>nM,AWS_REGION:()=>eM,AWS_SECRET_ACCESS_KEY:()=>iM,AWS_SESSION_TOKEN:()=>aM,AWS_SHARED_CREDENTIALS_FILE:()=>rM,AWS_USE_FIPS_ENDPOINT:()=>pM,CCR_AGENT_PROXY_CA_CERT_B64:()=>UM,CCR_AGENT_PROXY_CA_WATCH_ENABLED:()=>HM,CCR_AGENT_PROXY_ENABLED:()=>LM,CCR_AGENT_PROXY_FRAME_HOSTS:()=>zM,CCR_AGENT_PROXY_INCLUDE_HOSTS:()=>NM,CCR_AGENT_PROXY_NO_PROXY_LOCAL_ONLY:()=>MM,CCR_AGENT_PROXY_RECEIVE_GATE_DISABLED:()=>vM,CCR_AGENT_PROXY_RELAY_MODE:()=>xM,CCR_AGENT_PROXY_UPLOAD_GATE_DISABLED:()=>kM,CCR_ENABLE_BUNDLE:()=>FM,CCR_FORCE_BUNDLE:()=>BM,CCR_ON_BRANCH_DEFAULT_GUARD:()=>GM,CLAUDE_CODE_AGENT_PROXY_GH_SHIM:()=>PM,CLAUDE_CODE_AGENT_PROXY_GIT_CONFIG:()=>IM,CLAUDE_CODE_AGENT_PROXY_GIT_HOSTS:()=>wM,CLAUDE_CODE_API_BASE_URL:()=>Hk,CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY:()=>CM,CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS:()=>TM,CLAUDE_CODE_GB_BASE_URL:()=>RM,CLAUDE_CODE_GB_REFRESH_INTERVAL_MS:()=>DM,CLAUDE_CODE_HOST_GATEWAY_LINEAGE:()=>hM,CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST:()=>gM,CLAUDE_CODE_PROXY_RESOLVES_HOSTS:()=>_M,CLAUDE_CODE_SIMULATE_PROXY_USAGE:()=>EM,CLAUDE_CODE_SKIP_HFI_VERSION_CHECK:()=>jM,CLAUDE_CODE_USE_ANTHROPIC_AWS:()=>Nk,CLAUDE_CODE_USE_ANTHROPIC_GOOGLE_CLOUD:()=>vk,CLAUDE_CODE_USE_BEDROCK:()=>Pk,CLAUDE_CODE_USE_FOUNDRY:()=>xk,CLAUDE_CODE_USE_GATEWAY:()=>SM,CLAUDE_CODE_USE_MANTLE:()=>kk,CLAUDE_CODE_USE_VERTEX:()=>wk,CLAUDE_GATEWAY_ALLOW_LOOPBACK:()=>yM,CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS:()=>bM,CLAUDE_GATEWAY_LOG_LEVEL:()=>AM,CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY:()=>OM,CLOUD_ML_REGION:()=>Zk,_CLAUDE_CODE_ASSUME_FIRST_PARTY_BASE_URL:()=>Uk});var Al=["us","eu","apac","jp","au","us-gov","global"],bl=["us","eu","apac","jp","au","global"];var Pk=I.bool(),wk=I.bool(),xk=I.bool(),Nk=I.bool(),vk=I.bool(),kk=I.bool(),Mk=I.str(),Uk=I.triBool(),Hk=I.str(),zk=I.str(),Fk=I.enum(bl),Bk=I.str(),Gk=I.str(),Wk=I.str(),jk=I.str(),$k=I.str(),Vk=I.str(),Kk=I.str(),Yk=I.str(),Xk=I.str(),Jk=I.str(),Zk=I.str(),qk=I.str(),Qk=I.str(),eM=I.str(),tM=I.str(),nM=I.str(),oM=I.str(),rM=I.str(),sM=I.str(),iM=I.str(),aM=I.str(),lM=I.str(),cM=I.str(),dM=I.str(),uM=I.str(),pM=I.str(),fM=I.str(),mM=I.str(),gM=I.bool(),hM=I.bool(),EM=I.bool(),_M=I.bool(),SM=I.bool(),yM=I.bool(),OM=I.bool(),AM=I.str(),bM=I.int({min:1,max:2147000000,digitsOnly:!0}),CM=I.bool(),TM=I.int({min:1,max:2147483647,digitsOnly:!0}),RM=I.str(),DM=I.int(),LM=I.bool(),IM=I.bool(),PM=I.bool(),wM=I.str(),xM=I.str(),NM=I.str(),vM=I.bool(),kM=I.bool(),MM=I.bool(),UM=I.str(),HM=I.bool(),zM=I.str(),FM=I.bool(),BM=I.bool(),GM=I.enum(["enforce","observe","off"]),WM=I.str(),jM=I.bool();var VM={...ei,...li,...ii,...oi,...ai,...ri,...ti,...si};function ci(c,A){let L=Object.create(A);for(let[ce,me]of Object.entries(c)){let Ne=L,Fe;Object.defineProperty(L,ce,{get:()=>{let st=process.env[ce];if(st!==Ne)Fe=me.parse(st),Ne=st;return Fe},enumerable:!0,configurable:!0})}return Object.defineProperties(L,{set:{value:(ce,me)=>{process.env[ce]=al(me)}},unset:{value:(ce)=>{delete process.env[ce]}}}),L}var Pn=ci(VM,Qo),KM={},jK=ci(KM,null),YM={},$K=ci(YM,null);function Tl(){}async function JM(c,A){let L=s();try{await L.appendFile(c,A)}catch{await L.mkdir(XM(c)).catch(Tl),await L.appendFile(c,A)}}class Rl{pendingWrite=Promise.resolve();cleanupRegistered=!1;append(c,A){if(this.pendingWrite=this.pendingWrite.then(JM.bind(null,c,A)).catch(Tl),!this.cleanupRegistered)this.cleanupRegistered=!0,at(()=>this.flush())}flush(){return this.pendingWrite}}var ZM=new a(()=>new Rl);function qM(){return le(ZM)}function tr(c,A,L){let ce=eU();if(!ce)return;let me;try{me=Cl(c,A,QM(L))}catch{me=Cl(c,A,{diagnostics_payload_failed:!0})}qM().append(ce,me)}function QM(c){try{return(typeof c==="function"?c():c)??{}}catch{return{diagnostics_payload_failed:!0}}}function Cl(c,A,L){let ce={timestamp:new Date().toISOString(),level:c,event:A,data:L};return t(ce)+`
`}function eU(){return Pn.CLAUDE_CODE_DIAGNOSTICS_FILE}import{open as tU}from"fs/promises";function nU(c,A,L){zr(c.statSync(A),A,L)}function zr(c,A,L){if(c.isDirectory())throw Object.assign(Error("EISDIR: illegal operation on a directory, read"),{code:"EISDIR",errno:-21,syscall:"read",path:A});if(!c.isFile())throw Object.assign(Error("Not a regular file (device, FIFO, or socket)"),{code:"ERR_NOT_REGULAR_FILE",path:A});if(L!==void 0&&c.size>L)throw Object.assign(Error("File exceeds maxBytes limit"),{code:"ERR_FILE_TOO_LARGE",path:A,size:c.size,maxBytes:L})}function di(c,A,L){if(L===void 0)return;if(c>L)throw Object.assign(Error("File exceeds maxBytes limit"),{code:"ERR_FILE_TOO_LARGE",path:A,size:c,maxBytes:L})}function Dl(c){return c!=null&&typeof c==="object"&&"code"in c&&c.code==="ERR_FILE_TOO_LARGE"}function Ll(c){if(c.byteLength===0)return"utf8";if(c.byteLength>=2){if(c[0]===255&&c[1]===254)return"utf16le"}if(c.byteLength>=3&&c[0]===239&&c[1]===187&&c[2]===191)return"utf8";return"utf8"}function oU(c){let{buffer:A,bytesRead:L}=s().readSync(c,{length:4096});return Ll(A.subarray(0,L))}function Il(c){let A=0,L=0;for(let ce=0;ce<c.length;ce++)if(c[ce]===`
`)if(ce>0&&c[ce-1]==="\r")A++;else L++;return A>L?"CRLF":"LF"}function rU(c,A){let L=s(),{resolvedPath:ce,isSymlink:me}=Ie(L,c);if(me)e(`Reading through symlink: ${c} -> ${ce}`);nU(L,c,A);let Ne=oU(c),Fe;if(A===void 0)Fe=L.readFileSync(c,{encoding:Ne});else{let{buffer:gt,bytesRead:ht}=L.readSync(c,{length:A+1});di(ht,c,A),Fe=gt.subarray(0,ht).toString(Ne)}let st=Il(Fe.slice(0,4096));return{content:Fe.replaceAll(`\r
`,`
`),encoding:Ne,lineEndings:st}}function eo(c,A){return rU(c,A).content}async function Pl(c,A){let Fe=[];try{let L=s();let{resolvedPath:ce,isSymlink:me}=Ie(L,c);if(me)e(`Reading through symlink: ${c} -> ${ce}`);zr(await L.stat(c),c,A);const Ne=p(Fe,await tU(c,yt()),1);return await sU(Ne,c,A)}catch(st){var gt=st,ht=1}finally{var Et=f(Fe,gt,ht);Et&&await Et}}async function sU(c,A,L){zr(await c.stat(),A,L);let ce=L===void 0?await c.readFile():await At(c,L+1,"file");di(ce.length,A,L);let me=Ll(ce.subarray(0,4096)),Ne=ce.toString(me),Fe=Il(Ne.slice(0,4096));return{content:Ne.replaceAll(`\r
`,`
`),encoding:me,lineEndings:Fe}}var wl;(function(c){c[c.lineFeed=10]="lineFeed",c[c.carriageReturn=13]="carriageReturn",c[c.space=32]="space",c[c._0=48]="_0",c[c._1=49]="_1",c[c._2=50]="_2",c[c._3=51]="_3",c[c._4=52]="_4",c[c._5=53]="_5",c[c._6=54]="_6",c[c._7=55]="_7",c[c._8=56]="_8",c[c._9=57]="_9",c[c.a=97]="a",c[c.b=98]="b",c[c.c=99]="c",c[c.d=100]="d",c[c.e=101]="e",c[c.f=102]="f",c[c.g=103]="g",c[c.h=104]="h",c[c.i=105]="i",c[c.j=106]="j",c[c.k=107]="k",c[c.l=108]="l",c[c.m=109]="m",c[c.n=110]="n",c[c.o=111]="o",c[c.p=112]="p",c[c.q=113]="q",c[c.r=114]="r",c[c.s=115]="s",c[c.t=116]="t",c[c.u=117]="u",c[c.v=118]="v",c[c.w=119]="w",c[c.x=120]="x",c[c.y=121]="y",c[c.z=122]="z",c[c.A=65]="A",c[c.B=66]="B",c[c.C=67]="C",c[c.D=68]="D",c[c.E=69]="E",c[c.F=70]="F",c[c.G=71]="G",c[c.H=72]="H",c[c.I=73]="I",c[c.J=74]="J",c[c.K=75]="K",c[c.L=76]="L",c[c.M=77]="M",c[c.N=78]="N",c[c.O=79]="O",c[c.P=80]="P",c[c.Q=81]="Q",c[c.R=82]="R",c[c.S=83]="S",c[c.T=84]="T",c[c.U=85]="U",c[c.V=86]="V",c[c.W=87]="W",c[c.X=88]="X",c[c.Y=89]="Y",c[c.Z=90]="Z",c[c.asterisk=42]="asterisk",c[c.backslash=92]="backslash",c[c.closeBrace=125]="closeBrace",c[c.closeBracket=93]="closeBracket",c[c.colon=58]="colon",c[c.comma=44]="comma",c[c.dot=46]="dot",c[c.doubleQuote=34]="doubleQuote",c[c.minus=45]="minus",c[c.openBrace=123]="openBrace",c[c.openBracket=91]="openBracket",c[c.plus=43]="plus",c[c.slash=47]="slash",c[c.formFeed=12]="formFeed",c[c.tab=9]="tab"})(wl||(wl={}));var aU=Array(20).fill(0).map((c,A)=>" ".repeat(A));var lU={" ":{"\n":Array(200).fill(0).map((c,A)=>`
`+" ".repeat(A)),"\r":Array(200).fill(0).map((c,A)=>"\r"+" ".repeat(A)),"\r\n":Array(200).fill(0).map((c,A)=>`\r
`+" ".repeat(A))},"\t":{"\n":Array(200).fill(0).map((c,A)=>`
`+"\t".repeat(A)),"\r":Array(200).fill(0).map((c,A)=>"\r"+"\t".repeat(A)),"\r\n":Array(200).fill(0).map((c,A)=>`\r
`+"\t".repeat(A))}};var Nl;(function(c){c.DEFAULT={allowTrailingComma:!1}})(Nl||(Nl={}));var vl;(function(c){c[c.None=0]="None",c[c.UnexpectedEndOfComment=1]="UnexpectedEndOfComment",c[c.UnexpectedEndOfString=2]="UnexpectedEndOfString",c[c.UnexpectedEndOfNumber=3]="UnexpectedEndOfNumber",c[c.InvalidUnicode=4]="InvalidUnicode",c[c.InvalidEscapeCharacter=5]="InvalidEscapeCharacter",c[c.InvalidCharacter=6]="InvalidCharacter"})(vl||(vl={}));var kl;(function(c){c[c.OpenBraceToken=1]="OpenBraceToken",c[c.CloseBraceToken=2]="CloseBraceToken",c[c.OpenBracketToken=3]="OpenBracketToken",c[c.CloseBracketToken=4]="CloseBracketToken",c[c.CommaToken=5]="CommaToken",c[c.ColonToken=6]="ColonToken",c[c.NullKeyword=7]="NullKeyword",c[c.TrueKeyword=8]="TrueKeyword",c[c.FalseKeyword=9]="FalseKeyword",c[c.StringLiteral=10]="StringLiteral",c[c.NumericLiteral=11]="NumericLiteral",c[c.LineCommentTrivia=12]="LineCommentTrivia",c[c.BlockCommentTrivia=13]="BlockCommentTrivia",c[c.LineBreakTrivia=14]="LineBreakTrivia",c[c.Trivia=15]="Trivia",c[c.Unknown=16]="Unknown",c[c.EOF=17]="EOF"})(kl||(kl={}));var Ml;(function(c){c[c.InvalidSymbol=1]="InvalidSymbol",c[c.InvalidNumberFormat=2]="InvalidNumberFormat",c[c.PropertyNameExpected=3]="PropertyNameExpected",c[c.ValueExpected=4]="ValueExpected",c[c.ColonExpected=5]="ColonExpected",c[c.CommaExpected=6]="CommaExpected",c[c.CloseBraceExpected=7]="CloseBraceExpected",c[c.CloseBracketExpected=8]="CloseBracketExpected",c[c.EndOfFileExpected=9]="EndOfFileExpected",c[c.InvalidCommentToken=10]="InvalidCommentToken",c[c.UnexpectedEndOfComment=11]="UnexpectedEndOfComment",c[c.UnexpectedEndOfString=12]="UnexpectedEndOfString",c[c.UnexpectedEndOfNumber=13]="UnexpectedEndOfNumber",c[c.InvalidUnicode=14]="InvalidUnicode",c[c.InvalidEscapeCharacter=15]="InvalidEscapeCharacter",c[c.InvalidCharacter=16]="InvalidCharacter"})(Ml||(Ml={}));var Lo=typeof performance==="object"&&performance&&typeof performance.now==="function"?performance:Date,Hl=new Set,ui=typeof process==="object"&&!!process?process:{},zl=(c,A,L,ce)=>{typeof ui.emitWarning==="function"?ui.emitWarning(c,A,L,ce):console.error(`[${L}] ${A}: ${c}`)},{AbortController:Fr,AbortSignal:Ul}=globalThis;if(typeof Fr>"u"){Ul=class{onabort;_onabort=[];reason;aborted=!1;addEventListener(ce,me){this._onabort.push(me)}},Fr=class{constructor(){A()}signal=new Ul;abort(ce){if(this.signal.aborted)return;this.signal.reason=ce,this.signal.aborted=!0;for(let me of this.signal._onabort)me(ce);this.signal.onabort?.(ce)}};let c=ui.env?.LRU_CACHE_IGNORE_AC_WARNING!=="1",A=()=>{if(!c)return;c=!1,zl("AbortController is not defined. If using lru-cache in node 14, load an AbortController polyfill from the `node-abort-controller` package. A minimal polyfill is provided for use by LRUCache.fetch(), but it should not be relied upon in other contexts (eg, passing it to other APIs that use AbortController/AbortSignal might have undesirable effects). You may disable this with LRU_CACHE_IGNORE_AC_WARNING=1 in the env.","NO_ABORT_CONTROLLER","ENOTSUP",A)}}var gU=(c)=>!Hl.has(c),D1=Symbol("type"),jn=(c)=>c&&c===Math.floor(c)&&c>0&&isFinite(c),Fl=(c)=>!jn(c)?null:c<=Math.pow(2,8)?Uint8Array:c<=Math.pow(2,16)?Uint16Array:c<=Math.pow(2,32)?Uint32Array:c<=Number.MAX_SAFE_INTEGER?nr:null;class nr extends Array{constructor(c){super(c);this.fill(0)}}class Io{heap;length;static#l=!1;static create(c){let A=Fl(c);if(!A)return[];Io.#l=!0;let L=new Io(c,A);return Io.#l=!1,L}constructor(c,A){if(!Io.#l)throw TypeError("instantiate Stack using Stack.create(n)");this.heap=new A(c),this.length=0}push(c){this.heap[this.length++]=c}pop(){return this.heap[--this.length]}}class Br{#l;#u;#g;#h;#P;#w;ttl;ttlResolution;ttlAutopurge;updateAgeOnGet;updateAgeOnHas;allowStale;noDisposeOnSet;noUpdateTTL;maxEntrySize;sizeCalculation;noDeleteOnFetchRejection;noDeleteOnStaleGet;allowStaleOnFetchAbort;allowStaleOnFetchRejection;ignoreFetchAbort;#r;#E;#o;#n;#e;#c;#p;#a;#s;#_;#i;#S;#y;#f;#O;#R;#d;static unsafeExposeInternals(c){return{starts:c.#y,ttls:c.#f,sizes:c.#S,keyMap:c.#o,keyList:c.#n,valList:c.#e,next:c.#c,prev:c.#p,get head(){return c.#a},get tail(){return c.#s},free:c.#_,isBackgroundFetch:(A)=>c.#t(A),backgroundFetch:(A,L,ce,me)=>c.#v(A,L,ce,me),moveToTail:(A)=>c.#I(A),indexes:(A)=>c.#A(A),rindexes:(A)=>c.#b(A),isStale:(A)=>c.#m(A)}}get max(){return this.#l}get maxSize(){return this.#u}get calculatedSize(){return this.#E}get size(){return this.#r}get fetchMethod(){return this.#P}get memoMethod(){return this.#w}get dispose(){return this.#g}get disposeAfter(){return this.#h}constructor(c){let{max:A=0,ttl:L,ttlResolution:ce=1,ttlAutopurge:me,updateAgeOnGet:Ne,updateAgeOnHas:Fe,allowStale:st,dispose:gt,disposeAfter:ht,noDisposeOnSet:Et,noUpdateTTL:Rt,maxSize:Tt=0,maxEntrySize:It=0,sizeCalculation:Lt,fetchMethod:Bt,memoMethod:xt,noDeleteOnFetchRejection:Yt,noDeleteOnStaleGet:Xt,allowStaleOnFetchRejection:Wt,allowStaleOnFetchAbort:qt,ignoreFetchAbort:on}=c;if(A!==0&&!jn(A))throw TypeError("max option must be a nonnegative integer");let cn=A?Fl(A):Array;if(!cn)throw Error("invalid max value: "+A);if(this.#l=A,this.#u=Tt,this.maxEntrySize=It||this.#u,this.sizeCalculation=Lt,this.sizeCalculation){if(!this.#u&&!this.maxEntrySize)throw TypeError("cannot set sizeCalculation without setting maxSize or maxEntrySize");if(typeof this.sizeCalculation!=="function")throw TypeError("sizeCalculation set to non-function")}if(xt!==void 0&&typeof xt!=="function")throw TypeError("memoMethod must be a function if defined");if(this.#w=xt,Bt!==void 0&&typeof Bt!=="function")throw TypeError("fetchMethod must be a function if specified");if(this.#P=Bt,this.#R=!!Bt,this.#o=new Map,this.#n=Array(A).fill(void 0),this.#e=Array(A).fill(void 0),this.#c=new cn(A),this.#p=new cn(A),this.#a=0,this.#s=0,this.#_=Io.create(A),this.#r=0,this.#E=0,typeof gt==="function")this.#g=gt;if(typeof ht==="function")this.#h=ht,this.#i=[];else this.#h=void 0,this.#i=void 0;if(this.#O=!!this.#g,this.#d=!!this.#h,this.noDisposeOnSet=!!Et,this.noUpdateTTL=!!Rt,this.noDeleteOnFetchRejection=!!Yt,this.allowStaleOnFetchRejection=!!Wt,this.allowStaleOnFetchAbort=!!qt,this.ignoreFetchAbort=!!on,this.maxEntrySize!==0){if(this.#u!==0){if(!jn(this.#u))throw TypeError("maxSize must be a positive integer if specified")}if(!jn(this.maxEntrySize))throw TypeError("maxEntrySize must be a positive integer if specified");this.#B()}if(this.allowStale=!!st,this.noDeleteOnStaleGet=!!Xt,this.updateAgeOnGet=!!Ne,this.updateAgeOnHas=!!Fe,this.ttlResolution=jn(ce)||ce===0?ce:1,this.ttlAutopurge=!!me,this.ttl=L||0,this.ttl){if(!jn(this.ttl))throw TypeError("ttl must be a positive integer if specified");this.#k()}if(this.#l===0&&this.ttl===0&&this.#u===0)throw TypeError("At least one of max, maxSize, or ttl is required");if(!this.ttlAutopurge&&!this.#l&&!this.#u){if(gU("LRU_CACHE_UNBOUNDED"))Hl.add("LRU_CACHE_UNBOUNDED"),zl("TTL caching without ttlAutopurge, max, or maxSize can result in unbounded memory consumption.","UnboundedCacheWarning","LRU_CACHE_UNBOUNDED",Br)}}getRemainingTTL(c){return this.#o.has(c)?1/0:0}#k(){let c=new nr(this.#l),A=new nr(this.#l);this.#f=c,this.#y=A,this.#M=(me,Ne,Fe=Lo.now())=>{if(A[me]=Ne!==0?Fe:0,c[me]=Ne,Ne!==0&&this.ttlAutopurge){let st=setTimeout(()=>{if(this.#m(me))this.#C(this.#n[me],"expire")},Ne+1);if(st.unref)st.unref()}},this.#D=(me)=>{A[me]=c[me]!==0?Lo.now():0},this.#T=(me,Ne)=>{if(c[Ne]){let Fe=c[Ne],st=A[Ne];if(!Fe||!st)return;me.ttl=Fe,me.start=st,me.now=L||ce();let gt=me.now-st;me.remainingTTL=Fe-gt}};let L=0,ce=()=>{let me=Lo.now();if(this.ttlResolution>0){L=me;let Ne=setTimeout(()=>L=0,this.ttlResolution);if(Ne.unref)Ne.unref()}return me};this.getRemainingTTL=(me)=>{let Ne=this.#o.get(me);if(Ne===void 0)return 0;let Fe=c[Ne],st=A[Ne];if(!Fe||!st)return 1/0;let gt=(L||ce())-st;return Fe-gt},this.#m=(me)=>{let Ne=A[me],Fe=c[me];return!!Fe&&!!Ne&&(L||ce())-Ne>Fe}}#D=()=>{};#T=()=>{};#M=()=>{};#m=()=>!1;#B(){let c=new nr(this.#l);this.#E=0,this.#S=c,this.#L=(A)=>{this.#E-=c[A],c[A]=0},this.#U=(A,L,ce,me)=>{if(this.#t(L))return 0;if(!jn(ce))if(me){if(typeof me!=="function")throw TypeError("sizeCalculation must be a function");if(ce=me(L,A),!jn(ce))throw TypeError("sizeCalculation return invalid (expect positive integer)")}else throw TypeError("invalid size value (must be positive integer). When maxSize or maxEntrySize is used, sizeCalculation or size must be set.");return ce},this.#x=(A,L,ce)=>{if(c[A]=L,this.#u){let me=this.#u-c[A];while(this.#E>me)this.#N(!0)}if(this.#E+=c[A],ce)ce.entrySize=L,ce.totalCalculatedSize=this.#E}}#L=(c)=>{};#x=(c,A,L)=>{};#U=(c,A,L,ce)=>{if(L||ce)throw TypeError("cannot set size without setting maxSize or maxEntrySize on cache");return 0};*#A({allowStale:c=this.allowStale}={}){if(this.#r)for(let A=this.#s;;){if(!this.#H(A))break;if(c||!this.#m(A))yield A;if(A===this.#a)break;else A=this.#p[A]}}*#b({allowStale:c=this.allowStale}={}){if(this.#r)for(let A=this.#a;;){if(!this.#H(A))break;if(c||!this.#m(A))yield A;if(A===this.#s)break;else A=this.#c[A]}}#H(c){return c!==void 0&&this.#o.get(this.#n[c])===c}*entries(){for(let c of this.#A())if(this.#e[c]!==void 0&&this.#n[c]!==void 0&&!this.#t(this.#e[c]))yield[this.#n[c],this.#e[c]]}*rentries(){for(let c of this.#b())if(this.#e[c]!==void 0&&this.#n[c]!==void 0&&!this.#t(this.#e[c]))yield[this.#n[c],this.#e[c]]}*keys(){for(let c of this.#A()){let A=this.#n[c];if(A!==void 0&&!this.#t(this.#e[c]))yield A}}*rkeys(){for(let c of this.#b()){let A=this.#n[c];if(A!==void 0&&!this.#t(this.#e[c]))yield A}}*values(){for(let c of this.#A())if(this.#e[c]!==void 0&&!this.#t(this.#e[c]))yield this.#e[c]}*rvalues(){for(let c of this.#b())if(this.#e[c]!==void 0&&!this.#t(this.#e[c]))yield this.#e[c]}[Symbol.iterator](){return this.entries()}[Symbol.toStringTag]="LRUCache";find(c,A={}){for(let L of this.#A()){let ce=this.#e[L],me=this.#t(ce)?ce.__staleWhileFetching:ce;if(me===void 0)continue;if(c(me,this.#n[L],this))return this.get(this.#n[L],A)}}forEach(c,A=this){for(let L of this.#A()){let ce=this.#e[L],me=this.#t(ce)?ce.__staleWhileFetching:ce;if(me===void 0)continue;c.call(A,me,this.#n[L],this)}}rforEach(c,A=this){for(let L of this.#b()){let ce=this.#e[L],me=this.#t(ce)?ce.__staleWhileFetching:ce;if(me===void 0)continue;c.call(A,me,this.#n[L],this)}}purgeStale(){let c=!1;for(let A of this.#b({allowStale:!0}))if(this.#m(A))this.#C(this.#n[A],"expire"),c=!0;return c}info(c){let A=this.#o.get(c);if(A===void 0)return;let L=this.#e[A],ce=this.#t(L)?L.__staleWhileFetching:L;if(ce===void 0)return;let me={value:ce};if(this.#f&&this.#y){let Ne=this.#f[A],Fe=this.#y[A];if(Ne&&Fe){let st=Ne-(Lo.now()-Fe);me.ttl=st,me.start=Date.now()}}if(this.#S)me.size=this.#S[A];return me}dump(){let c=[];for(let A of this.#A({allowStale:!0})){let L=this.#n[A],ce=this.#e[A],me=this.#t(ce)?ce.__staleWhileFetching:ce;if(me===void 0||L===void 0)continue;let Ne={value:me};if(this.#f&&this.#y){Ne.ttl=this.#f[A];let Fe=Lo.now()-this.#y[A];Ne.start=Math.floor(Date.now()-Fe)}if(this.#S)Ne.size=this.#S[A];c.unshift([L,Ne])}return c}load(c){this.clear();for(let[A,L]of c){if(L.start){let ce=Date.now()-L.start;L.start=Lo.now()-ce}this.set(A,L.value,L)}}set(c,A,L={}){if(A===void 0)return this.delete(c),this;let{ttl:ce=this.ttl,start:me,noDisposeOnSet:Ne=this.noDisposeOnSet,sizeCalculation:Fe=this.sizeCalculation,status:st}=L,{noUpdateTTL:gt=this.noUpdateTTL}=L,ht=this.#U(c,A,L.size||0,Fe);if(this.maxEntrySize&&ht>this.maxEntrySize){if(st)st.set="miss",st.maxEntrySizeExceeded=!0;return this.#C(c,"set"),this}let Et=this.#r===0?void 0:this.#o.get(c);if(Et===void 0){if(Et=this.#r===0?this.#s:this.#_.length!==0?this.#_.pop():this.#r===this.#l?this.#N(!1):this.#r,this.#n[Et]=c,this.#e[Et]=A,this.#o.set(c,Et),this.#c[this.#s]=Et,this.#p[Et]=this.#s,this.#s=Et,this.#r++,this.#x(Et,ht,st),st)st.set="add";gt=!1}else{this.#I(Et);let Rt=this.#e[Et];if(A!==Rt){if(this.#R&&this.#t(Rt)){Rt.__abortController.abort(Error("replaced"));let{__staleWhileFetching:Tt}=Rt;if(Tt!==void 0&&!Ne){if(this.#O)this.#g?.(Tt,c,"set");if(this.#d)this.#i?.push([Tt,c,"set"])}}else if(!Ne){if(this.#O)this.#g?.(Rt,c,"set");if(this.#d)this.#i?.push([Rt,c,"set"])}if(this.#L(Et),this.#x(Et,ht,st),this.#e[Et]=A,st){st.set="replace";let Tt=Rt&&this.#t(Rt)?Rt.__staleWhileFetching:Rt;if(Tt!==void 0)st.oldValue=Tt}}else if(st)st.set="update"}if(ce!==0&&!this.#f)this.#k();if(this.#f){if(!gt)this.#M(Et,ce,me);if(st)this.#T(st,Et)}if(!Ne&&this.#d&&this.#i){let Rt=this.#i,Tt;while(Tt=Rt?.shift())this.#h?.(...Tt)}return this}pop(){try{while(this.#r){let c=this.#e[this.#a];if(this.#N(!0),this.#t(c)){if(c.__staleWhileFetching)return c.__staleWhileFetching}else if(c!==void 0)return c}}finally{if(this.#d&&this.#i){let c=this.#i,A;while(A=c?.shift())this.#h?.(...A)}}}#N(c){let A=this.#a,L=this.#n[A],ce=this.#e[A];if(this.#R&&this.#t(ce))ce.__abortController.abort(Error("evicted"));else if(this.#O||this.#d){if(this.#O)this.#g?.(ce,L,"evict");if(this.#d)this.#i?.push([ce,L,"evict"])}if(this.#L(A),c)this.#n[A]=void 0,this.#e[A]=void 0,this.#_.push(A);if(this.#r===1)this.#a=this.#s=0,this.#_.length=0;else this.#a=this.#c[A];return this.#o.delete(L),this.#r--,A}has(c,A={}){let{updateAgeOnHas:L=this.updateAgeOnHas,status:ce}=A,me=this.#o.get(c);if(me!==void 0){let Ne=this.#e[me];if(this.#t(Ne)&&Ne.__staleWhileFetching===void 0)return!1;if(!this.#m(me)){if(L)this.#D(me);if(ce)ce.has="hit",this.#T(ce,me);return!0}else if(ce)ce.has="stale",this.#T(ce,me)}else if(ce)ce.has="miss";return!1}peek(c,A={}){let{allowStale:L=this.allowStale}=A,ce=this.#o.get(c);if(ce===void 0||!L&&this.#m(ce))return;let me=this.#e[ce];return this.#t(me)?me.__staleWhileFetching:me}#v(c,A,L,ce){let me=A===void 0?void 0:this.#e[A];if(this.#t(me))return me;let Ne=new Fr,{signal:Fe}=L;Fe?.addEventListener("abort",()=>Ne.abort(Fe.reason),{signal:Ne.signal});let st={signal:Ne.signal,options:L,context:ce},gt=(Lt,Bt=!1)=>{let{aborted:xt}=Ne.signal,Yt=L.ignoreFetchAbort&&Lt!==void 0;if(L.status)if(xt&&!Bt){if(L.status.fetchAborted=!0,L.status.fetchError=Ne.signal.reason,Yt)L.status.fetchAbortIgnored=!0}else L.status.fetchResolved=!0;if(xt&&!Yt&&!Bt)return Et(Ne.signal.reason);let Xt=Tt;if(this.#e[A]===Tt)if(Lt===void 0)if(Xt.__staleWhileFetching)this.#e[A]=Xt.__staleWhileFetching;else this.#C(c,"fetch");else{if(L.status)L.status.fetchUpdated=!0;this.set(c,Lt,st.options)}return Lt},ht=(Lt)=>{if(L.status)L.status.fetchRejected=!0,L.status.fetchError=Lt;return Et(Lt)},Et=(Lt)=>{let{aborted:Bt}=Ne.signal,xt=Bt&&L.allowStaleOnFetchAbort,Yt=xt||L.allowStaleOnFetchRejection,Xt=Yt||L.noDeleteOnFetchRejection,Wt=Tt;if(this.#e[A]===Tt){if(!Xt||Wt.__staleWhileFetching===void 0)this.#C(c,"fetch");else if(!xt)this.#e[A]=Wt.__staleWhileFetching}if(Yt){if(L.status&&Wt.__staleWhileFetching!==void 0)L.status.returnedStale=!0;return Wt.__staleWhileFetching}else if(Wt.__returned===Wt)throw Lt},Rt=(Lt,Bt)=>{let xt=this.#P?.(c,me,st);if(xt&&xt instanceof Promise)xt.then((Yt)=>Lt(Yt===void 0?void 0:Yt),Bt);Ne.signal.addEventListener("abort",()=>{if(!L.ignoreFetchAbort||L.allowStaleOnFetchAbort){if(Lt(void 0),L.allowStaleOnFetchAbort)Lt=(Yt)=>gt(Yt,!0)}})};if(L.status)L.status.fetchDispatched=!0;let Tt=new Promise(Rt).then(gt,ht),It=Object.assign(Tt,{__abortController:Ne,__staleWhileFetching:me,__returned:void 0});if(A===void 0)this.set(c,It,{...st.options,status:void 0}),A=this.#o.get(c);else this.#e[A]=It;return It}#t(c){if(!this.#R)return!1;let A=c;return!!A&&A instanceof Promise&&A.hasOwnProperty("__staleWhileFetching")&&A.__abortController instanceof Fr}async fetch(c,A={}){let{allowStale:L=this.allowStale,updateAgeOnGet:ce=this.updateAgeOnGet,noDeleteOnStaleGet:me=this.noDeleteOnStaleGet,ttl:Ne=this.ttl,noDisposeOnSet:Fe=this.noDisposeOnSet,size:st=0,sizeCalculation:gt=this.sizeCalculation,noUpdateTTL:ht=this.noUpdateTTL,noDeleteOnFetchRejection:Et=this.noDeleteOnFetchRejection,allowStaleOnFetchRejection:Rt=this.allowStaleOnFetchRejection,ignoreFetchAbort:Tt=this.ignoreFetchAbort,allowStaleOnFetchAbort:It=this.allowStaleOnFetchAbort,context:Lt,forceRefresh:Bt=!1,status:xt,signal:Yt}=A;if(!this.#R){if(xt)xt.fetch="get";return this.get(c,{allowStale:L,updateAgeOnGet:ce,noDeleteOnStaleGet:me,status:xt})}let Xt={allowStale:L,updateAgeOnGet:ce,noDeleteOnStaleGet:me,ttl:Ne,noDisposeOnSet:Fe,size:st,sizeCalculation:gt,noUpdateTTL:ht,noDeleteOnFetchRejection:Et,allowStaleOnFetchRejection:Rt,allowStaleOnFetchAbort:It,ignoreFetchAbort:Tt,status:xt,signal:Yt},Wt=this.#o.get(c);if(Wt===void 0){if(xt)xt.fetch="miss";let qt=this.#v(c,Wt,Xt,Lt);return qt.__returned=qt}else{let qt=this.#e[Wt];if(this.#t(qt)){let dn=L&&qt.__staleWhileFetching!==void 0;if(xt){if(xt.fetch="inflight",dn)xt.returnedStale=!0}return dn?qt.__staleWhileFetching:qt.__returned=qt}let on=this.#m(Wt);if(!Bt&&!on){if(xt)xt.fetch="hit";if(this.#I(Wt),ce)this.#D(Wt);if(xt)this.#T(xt,Wt);return qt}let cn=this.#v(c,Wt,Xt,Lt),Hn=cn.__staleWhileFetching!==void 0&&L;if(xt){if(xt.fetch=on?"stale":"refresh",Hn&&on)xt.returnedStale=!0}return Hn?cn.__staleWhileFetching:cn.__returned=cn}}async forceFetch(c,A={}){let L=await this.fetch(c,A);if(L===void 0)throw Error("fetch() returned undefined");return L}memo(c,A={}){let L=this.#w;if(!L)throw Error("no memoMethod provided to constructor");let{context:ce,forceRefresh:me,...Ne}=A,Fe=this.get(c,Ne);if(!me&&Fe!==void 0)return Fe;let st=L(c,Fe,{options:Ne,context:ce});return this.set(c,st,Ne),st}get(c,A={}){let{allowStale:L=this.allowStale,updateAgeOnGet:ce=this.updateAgeOnGet,noDeleteOnStaleGet:me=this.noDeleteOnStaleGet,status:Ne}=A,Fe=this.#o.get(c);if(Fe!==void 0){let st=this.#e[Fe],gt=this.#t(st);if(Ne)this.#T(Ne,Fe);if(this.#m(Fe)){if(Ne)Ne.get="stale";if(!gt){if(!me)this.#C(c,"expire");if(Ne&&L)Ne.returnedStale=!0;return L?st:void 0}else{if(Ne&&L&&st.__staleWhileFetching!==void 0)Ne.returnedStale=!0;return L?st.__staleWhileFetching:void 0}}else{if(Ne)Ne.get="hit";if(gt)return st.__staleWhileFetching;if(this.#I(Fe),ce)this.#D(Fe);return st}}else if(Ne)Ne.get="miss"}#z(c,A){this.#p[A]=c,this.#c[c]=A}#I(c){if(c!==this.#s){if(c===this.#a)this.#a=this.#c[c];else this.#z(this.#p[c],this.#c[c]);this.#z(this.#s,c),this.#s=c}}delete(c){return this.#C(c,"delete")}#C(c,A){let L=!1;if(this.#r!==0){let ce=this.#o.get(c);if(ce!==void 0)if(L=!0,this.#r===1)this.#F(A);else{this.#L(ce);let me=this.#e[ce];if(this.#t(me))me.__abortController.abort(Error("deleted"));else if(this.#O||this.#d){if(this.#O)this.#g?.(me,c,A);if(this.#d)this.#i?.push([me,c,A])}if(this.#o.delete(c),this.#n[ce]=void 0,this.#e[ce]=void 0,ce===this.#s)this.#s=this.#p[ce];else if(ce===this.#a)this.#a=this.#c[ce];else{let Ne=this.#p[ce];this.#c[Ne]=this.#c[ce];let Fe=this.#c[ce];this.#p[Fe]=this.#p[ce]}this.#r--,this.#_.push(ce)}}if(this.#d&&this.#i?.length){let ce=this.#i,me;while(me=ce?.shift())this.#h?.(...me)}return L}clear(){return this.#F("delete")}#F(c){for(let A of this.#b({allowStale:!0})){let L=this.#e[A];if(this.#t(L))L.__abortController.abort(Error("deleted"));else{let ce=this.#n[A];if(this.#O)this.#g?.(L,ce,c);if(this.#d)this.#i?.push([L,ce,c])}}if(this.#o.clear(),this.#e.fill(void 0),this.#n.fill(void 0),this.#f&&this.#y)this.#f.fill(0),this.#y.fill(0);if(this.#S)this.#S.fill(0);if(this.#a=0,this.#s=0,this.#_.length=0,this.#E=0,this.#r=0,this.#d&&this.#i){let A=this.#i,L;while(L=A?.shift())this.#h?.(...L)}}}function Gr(c,A,L=100){let ce=new Br({max:L}),me=(...Ne)=>{let Fe=A(...Ne),st=ce.get(Fe);if(st!==void 0)return st;let gt=c(...Ne);return ce.set(Fe,gt),gt};return me.cache={clear:()=>ce.clear(),size:()=>ce.size,delete:(Ne)=>ce.delete(Ne),get:(Ne)=>ce.peek(Ne),has:(Ne)=>ce.has(Ne),set:(Ne,Fe)=>void ce.set(Ne,Fe)},me}var hU=8192;function Gl(c,A){try{return{ok:!0,value:JSON.parse(he(c))}}catch(L){if(A)ut(Ot(L,`safeParseJSON: invalid JSON (${L instanceof Error?L.constructor.name:typeof L}, ${c.length} bytes)`));return{ok:!1}}}class Wl{cached=Gr(Gl,(c)=>c,50);cache=this.cached.cache;parse(c,A){return this.cached(c,A)}}var Bl=new Wl;var to=Object.assign(function(A,L=!0){if(!A)return null;let ce=A.length>hU?Gl(A,L):Bl.parse(A,L);return ce.ok?ce.value:null},{cache:Bl.cache});import{accessSync as EU,constants as Kl,realpath as _U,realpathSync as SU}from"fs";import{access as yU}from"fs/promises";import{basename as J1,dirname as OU,join as jl,resolve as AU}from"path";import{promisify as bU}from"util";function Yl(c,A,L,ce){let me=s(),Ne=Zl(c,A,L,ce),Fe=Ne.next();while(!Fe.done){let st;try{st=CU(me,Fe.value)}catch(gt){Fe=Ne.throw(gt);continue}Fe=Ne.next(st)}return Fe.value}async function Xl(c,A,L,ce){let me=s(),Ne=Zl(c,A,L,ce),Fe=Ne.next();while(!Fe.done){let st;try{st=await TU(me,Fe.value)}catch(gt){Fe=Ne.throw(gt);continue}Fe=Ne.next(st)}return Fe.value}var Jl={unreadableAncestry:"unverified",surfaceNetworkRaw:!0,literalLinkText:"opaque"};function CU(c,{ask:A,path:L}){switch(A){case"isLink":return c.lstatSync(L).isSymbolicLink();case"networkJunction":return Pe(c,L,Jl);case"realpath":return Z(SU.native(L));case"writable":return EU(L,Kl.W_OK),!0}}async function TU(c,{ask:A,path:L}){switch(A){case"isLink":return(await c.lstat(L)).isSymbolicLink();case"networkJunction":return ct(c,L,Jl);case"realpath":return Z(await bU(_U.native)(L));case"writable":return await yU(L,Kl.W_OK),!0}}function*Zl(c,A,L,ce){let me=jl(c,...A),Ne;try{if(Ne=yield*pi(AU(c),ce),!Ne){let ht=c,Et=!1;for(let[Rt,Tt]of A.entries())if(ht=jl(ht,Tt),Et=Rt===A.length-1?L??(yield*pi(ht)):yield*pi(ht,ce),Et)break;if(!Et)return null}}catch{return null}if(Ne){let ht=ql()?yield*$l(yield*fi(me)):"unknown";return{path:me,folder:c,kind:"outside",targetWritable:ht}}let Fe=yield*fi(me),st=yield*fi(c);if(Fe==="gone"||st==="gone")return null;if(st==="unverified"||"network"in st||Fe==="unverified")return{path:me,folder:c,kind:"unverified"};if("real"in Fe&&bt(st.real,Fe.real))return{path:me,folder:c,kind:"inside"};let gt=yield*$l(Fe);return{path:me,folder:c,kind:"outside",targetWritable:gt}}function*pi(c,A){let L=A?.get(c);if(L===void 0)L=(yield{ask:"isLink",path:c})===!0,A?.set(c,L);return L}function*fi(c){if(vt(c)&&!M(c))return{network:c};try{let A=yield{ask:"networkJunction",path:c};if(A===N||A===lt)return"unverified";if(typeof A==="string")return{network:A};let L=yield{ask:"realpath",path:c};return typeof L==="string"?{real:L}:"unverified"}catch(A){let L=n(A);return L==="ENOENT"||L==="ENOTDIR"?"gone":"unverified"}}function ql(){try{let c=C();return c!=="windows"&&c!=="wsl"}catch{return!1}}function*$l(c){try{if(typeof c==="string"||!("real"in c)||!ql())return"unknown";let A=yield*Vl(c.real);if(A==="yes")return"yes";let L=yield*Vl(OU(c.real));if(L==="yes")return"yes";return A==="no"&&L==="no"?"no":"unknown"}catch{return"unknown"}}function*Vl(c){try{return yield{ask:"writable",path:c},"yes"}catch(A){switch(n(A)){case"EACCES":case"EPERM":case"EROFS":return"no";default:return"unknown"}}}import{join as RU}from"path";class Ql{managedFilePath=void 0;dropInDir=void 0;getManagedFilePath(){return this.managedFilePath??=LU(),this.managedFilePath}getDropInDir(){return this.dropInDir??=RU($n(),"managed-settings.d"),this.dropInDir}clearDropInDir(){this.dropInDir=void 0}reset(){this.managedFilePath=void 0,this.dropInDir=void 0}}var DU=new Ql;function $n(){return DU.getManagedFilePath()}function LU(){let c=IU();if(c!==void 0)return c;switch(C()){case"macos":return"/Library/Application Support/ClaudeCode";case"windows":return"C:\\Program Files\\ClaudeCode";default:return"/etc/claude-code"}}function IU(){return}var or=["low","medium","high","xhigh","max"];class ec{resetters=[];built=[];lazy(c){let A,L=()=>{A=void 0};return this.resetters.push(L),()=>{if(A===void 0)A=c(),this.built.push(L);return A}}builtCount(){return this.built.length}releaseBuiltSince(c){for(let A of this.built.splice(c))A()}reset(){for(let c of this.resetters)c();this.built.length=0}}var PU=new ec;function Mt(c){return PU.lazy(c)}var rr=/^(?:Read|Edit)\((?:\.\/)?!/;var Mn=Mt(()=>[{path:["allowManagedPermissionRulesOnly"],restrictive:!0},{path:["allowManagedHooksOnly"],restrictive:!0},{path:["allowManagedMcpServersOnly"],restrictive:!0},{path:["enforceAvailableModels"],restrictive:!0},{path:["disableAllHooks"],restrictive:!0},{path:["disableClaudeAiConnectors"],restrictive:!0},{path:["disableCommandPluginSources"],restrictive:!0},{path:["disableSideloadFlags"],restrictive:!0},{path:["disableSkillShellExecution"],restrictive:!0},{path:["disableRemoteControl"],restrictive:!0},{path:["disableAgentView"],restrictive:!0},{path:["disableWorkflows"],restrictive:!0},{path:["disableArtifact"],restrictive:!0},{path:["disableBundledSkills"],restrictive:!0},{path:["fastModePerSessionOptIn"],restrictive:!0},{path:["isolatePeerMachines"],restrictive:!0},{path:["strictPluginOnlyCustomization"],restrictive:!0},{path:["disableAutoMode"],restrictive:"disable"},{path:["disableDeepLinkRegistration"],restrictive:"disable"},{path:["permissions","disableBypassPermissionsMode"],restrictive:"disable"},{path:["permissions","disableAutoMode"],restrictive:"disable"},{path:["permissions","blockReadsOutsideWorkingDirectories"],restrictive:!0},{path:["autoMode","classifyAllShell"],restrictive:!0},...[],{path:["worktree","bgIsolation"],restrictive:"worktree"},{path:["enableArtifact"],restrictive:!1},{path:["enableWorkflows"],restrictive:!1},{path:["syncClaudeAiSkills"],restrictive:!1},{path:["syncClaudeAiPlugins"],restrictive:!1},{path:["useAutoModeDuringPlan"],restrictive:!1},{path:["skipDangerousModePermissionPrompt"],restrictive:!1},{path:["skipAutoPermissionPrompt"],restrictive:!1},{path:["enableAllProjectMcpServers"],restrictive:!1},{path:["channelsEnabled"],restrictive:!1},{path:["skipWebFetchPreflight"],restrictive:!1},{path:["skipWorkflowUsageWarning"],restrictive:!1},{path:["autoUploadSessions"],restrictive:!1},{path:["remoteControlAtStartup"],restrictive:!1},{path:["remoteTools","allowUnattendedServing"],restrictive:!1},{path:["autoContinueAtUsageLimit"],restrictive:!1},...[],...[],{path:["attribution","sessionUrl"],restrictive:!1},{path:["crossSessionInbound"],restrictive:["refuse","hold"]},{path:["remoteControl","shareHostProfile"],restrictive:["off","basic"]},{path:["modelProposedGoals"],restrictive:["disabled","alwaysAsk"]},{path:["maxEffortLevel"],restrictive:or},{path:["feedbackDrafts"],restrictive:"off"},{path:["availableModelsMatch"],restrictive:"exact"},{path:["askUserQuestionTimeout"],restrictive:"never"},{path:["dialogExpiry"],restrictive:"never"},{path:["sandbox","enabled"],restrictive:!0},{path:["sandbox","failIfUnavailable"],restrictive:!0},{path:["sandbox","autoAllowBashIfSandboxed"],restrictive:!1},{path:["sandbox","allowUnsandboxedCommands"],restrictive:!1},{path:["sandbox","enableWeakerNestedSandbox"],restrictive:!1},{path:["sandbox","enableWeakerNetworkIsolation"],restrictive:!1},{path:["sandbox","allowAppleEvents"],restrictive:!1},{path:["sandbox","network","allowManagedDomainsOnly"],restrictive:!0},{path:["sandbox","network","strictAllowlist"],restrictive:!0},{path:["sandbox","network","allowAllUnixSockets"],restrictive:!1},{path:["sandbox","network","allowLocalBinding"],restrictive:!1},{path:["sandbox","filesystem","allowManagedReadPathsOnly"],restrictive:!0},{path:["sandbox","filesystem","disabled"],restrictive:!1},{path:["sandbox","credentials","allowPlaintextInject"],restrictive:!1},{path:["sandbox","credentials","sigv4","streaming"],restrictive:"deny"},{path:["sandbox","credentials","sigv4","presigned"],restrictive:"deny"},{path:["sandbox","credentials","sigv4","sigv4a"],restrictive:"deny"},{path:["isolation","required"],restrictive:!0},{path:["isolation","persistHome"],restrictive:!1}]);function no(c){return Array.isArray(c)?c:[c]}function pn(c,A){let L=c;for(let ce of A){if(L===null||typeof L!=="object")return;L=L[ce]}return L}function fn(c,A,L){let ce=[c],me=c;for(let Fe of A.slice(0,-1)){let st={...me[Fe]};me[Fe]=st,me=st,ce.push(me)}let Ne=A.at(-1);if(L!==void 0){me[Ne]=L;return}delete me[Ne];for(let Fe=ce.length-1;Fe>0;Fe--){if(Object.keys(ce[Fe]).length>0)break;delete ce[Fe-1][A[Fe-1]]}}function Wr(c,A){let L=pn(A,c.path);return c.normalize===void 0?L:c.normalize(L)}function xU(c,A,L){if(L!==void 0&&!U(c[A],L)||L===void 0&&!(A in c))oe(c,A,L)}var sr=xU;var $r={};D($r,{default:()=>ir});var rc=typeof $r=="object"&&$r&&!$r.nodeType&&$r,tc=rc&&typeof jr=="object"&&jr&&!jr.nodeType&&jr,NU=tc&&tc.exports===rc,nc=NU?h.Buffer:void 0,oc=nc?nc.allocUnsafe:void 0;function vU(c,A){if(A)return c.slice();var L=c.length,ce=oc?oc(L):new c.constructor(L);return c.copy(ce),ce}var ir=vU;function kU(c){var A=new c.constructor(c.byteLength);return new Ee(A).set(new Ee(c)),A}var Po=kU;function MU(c,A){var L=A?Po(c.buffer):c.buffer;return new c.constructor(L,c.byteOffset,c.length)}var Vr=MU;function UU(c,A){var L=-1,ce=c.length;A||(A=Array(ce));while(++L<ce)A[L]=c[L];return A}var Kr=UU;var sc=Object.create,HU=function(){function c(){}return function(A){if(!g(A))return{};if(sc)return sc(A);c.prototype=A;var L=new c;return c.prototype=void 0,L}}(),ic=HU;function zU(c){return typeof c.constructor=="function"&&!Oe(c)?ic(bo(c)):{}}var Yr=zU;function FU(c){return S(c)&&ne(c)}var ac=FU;var BU="[object Object]",GU=Function.prototype,WU=Object.prototype,lc=GU.toString,jU=WU.hasOwnProperty,$U=lc.call(Object);function VU(c){if(!S(c)||T(c)!=BU)return!1;var A=bo(c);if(A===null)return!0;var L=jU.call(A,"constructor")&&A.constructor;return typeof L=="function"&&L instanceof L&&lc.call(L)==$U}var Xr=VU;function KU(c,A){if(A==="constructor"&&typeof c[A]==="function")return;if(A=="__proto__")return;return c[A]}var ar=KU;function YU(c,A,L,ce){var me=!L;L||(L={});var Ne=-1,Fe=A.length;while(++Ne<Fe){var st=A[Ne],gt=ce?ce(L[st],c[st],st,L,c):void 0;if(gt===void 0)gt=c[st];if(me)oe(L,st,gt);else Ao(L,st,gt)}return L}var Tn=YU;function XU(c){return Tn(c,kn(c))}var cc=XU;function JU(c,A,L,ce,me,Ne,Fe){var st=ar(c,L),gt=ar(A,L),ht=Fe.get(gt);if(ht){sr(c,L,ht);return}var Et=Ne?Ne(st,gt,L+"",c,A,Fe):void 0,Rt=Et===void 0;if(Rt){var Tt=d(gt),It=!Tt&&H(gt),Lt=!Tt&&!It&&Re(gt);if(Et=gt,Tt||It||Lt)if(d(st))Et=st;else if(ac(st))Et=Kr(st);else if(It)Rt=!1,Et=ir(gt,!0);else if(Lt)Rt=!1,Et=Vr(gt,!0);else Et=[];else if(Xr(gt)||Y(gt)){if(Et=st,Y(st))Et=cc(st);else if(!g(st)||_e(st))Et=Yr(gt)}else Rt=!1}if(Rt)Fe.set(gt,Et),me(Et,gt,ce,Ne,Fe),Fe.delete(gt);sr(c,L,Et)}var dc=JU;function uc(c,A,L,ce,me){if(c===A)return;tt(A,function(Ne,Fe){if(me||(me=new F),g(Ne))dc(c,A,Fe,L,uc,ce,me);else{var st=ce?ce(ar(c,Fe),Ne,Fe+"",c,A,me):void 0;if(st===void 0)st=Ne;sr(c,Fe,st)}},kn)}var pc=uc;function ZU(c,A,L){switch(L.length){case 0:return c.call(A);case 1:return c.call(A,L[0]);case 2:return c.call(A,L[0],L[1]);case 3:return c.call(A,L[0],L[1],L[2])}return c.apply(A,L)}var fc=ZU;var mc=Math.max;function qU(c,A,L){return A=mc(A===void 0?c.length-1:A,0),function(){var ce=arguments,me=-1,Ne=mc(ce.length-A,0),Fe=Array(Ne);while(++me<Ne)Fe[me]=ce[A+me];me=-1;var st=Array(A+1);while(++me<A)st[me]=ce[me];return st[A]=L(Fe),fc(c,this,st)}}var Jr=qU;function QU(c){return function(){return c}}var gc=QU;var eH=!xe?ve:function(c,A){return xe(c,"toString",{configurable:!0,enumerable:!1,value:gc(A),writable:!0})},hc=eH;var tH=800,nH=16,oH=Date.now;function rH(c){var A=0,L=0;return function(){var ce=oH(),me=nH-(ce-L);if(L=ce,me>0){if(++A>=tH)return arguments[0]}else A=0;return c.apply(void 0,arguments)}}var Ec=rH;var sH=Ec(hc),Zr=sH;function iH(c,A){return Zr(Jr(c,A,ve),c+"")}var _c=iH;function aH(c,A,L){if(!g(L))return!1;var ce=typeof A;if(ce=="number"?ne(L)&&te(A,L.length):ce=="string"&&(A in L))return U(L[A],c);return!1}var Sc=aH;function lH(c){return _c(function(A,L){var ce=-1,me=L.length,Ne=me>1?L[me-1]:void 0,Fe=me>2?L[2]:void 0;if(Ne=c.length>3&&typeof Ne=="function"?(me--,Ne):void 0,Fe&&Sc(L[0],L[1],Fe))Ne=me<3?void 0:Ne,me=1;A=Object(A);while(++ce<me){var st=L[ce];if(st)c(A,st,ce,Ne)}return A})}var yc=lH;var cH=yc(function(c,A,L,ce){pc(c,A,L,ce)}),mn=cH;function dH(c,A){var L=-1,ce=c==null?0:c.length;while(++L<ce)if(A(c[L],L,c)===!1)break;return c}var Oc=dH;function uH(c,A){return c&&Tn(A,K(A),c)}var Ac=uH;function pH(c,A){return c&&Tn(A,kn(A),c)}var bc=pH;function fH(c,A){return Tn(c,Ce(c),A)}var Cc=fH;function mH(c,A){return Tn(c,Ur(c),A)}var Tc=mH;var gH=Object.prototype,hH=gH.hasOwnProperty;function EH(c){var A=c.length,L=new c.constructor(A);if(A&&typeof c[0]=="string"&&hH.call(c,"index"))L.index=c.index,L.input=c.input;return L}var Rc=EH;function _H(c,A){var L=A?Po(c.buffer):c.buffer;return new c.constructor(L,c.byteOffset,c.byteLength)}var Dc=_H;var SH=/\w*$/;function yH(c){var A=new c.constructor(c.source,SH.exec(c));return A.lastIndex=c.lastIndex,A}var Lc=yH;var Ic=E?E.prototype:void 0,Pc=Ic?Ic.valueOf:void 0;function OH(c){return Pc?Object(Pc.call(c)):{}}var wc=OH;var AH="[object Boolean]",bH="[object Date]",CH="[object Map]",TH="[object Number]",RH="[object RegExp]",DH="[object Set]",LH="[object String]",IH="[object Symbol]",PH="[object ArrayBuffer]",wH="[object DataView]",xH="[object Float32Array]",NH="[object Float64Array]",vH="[object Int8Array]",kH="[object Int16Array]",MH="[object Int32Array]",UH="[object Uint8Array]",HH="[object Uint8ClampedArray]",zH="[object Uint16Array]",FH="[object Uint32Array]";function BH(c,A,L){var ce=c.constructor;switch(A){case PH:return Po(c);case AH:case bH:return new ce(+c);case wH:return Dc(c,L);case xH:case NH:case vH:case kH:case MH:case UH:case HH:case zH:case FH:return Vr(c,L);case CH:return new ce;case TH:case LH:return new ce(c);case RH:return Lc(c);case DH:return new ce;case IH:return wc(c)}}var xc=BH;var GH="[object Map]";function WH(c){return S(c)&&q(c)==GH}var Nc=WH;var vc=B&&B.isMap,jH=vc?Ae(vc):Nc,kc=jH;var $H="[object Set]";function VH(c){return S(c)&&q(c)==$H}var Mc=VH;var Uc=B&&B.isSet,KH=Uc?Ae(Uc):Mc,Hc=KH;var YH=1,XH=2,JH=4,zc="[object Arguments]",ZH="[object Array]",qH="[object Boolean]",QH="[object Date]",ez="[object Error]",Fc="[object Function]",tz="[object GeneratorFunction]",nz="[object Map]",oz="[object Number]",Bc="[object Object]",rz="[object RegExp]",sz="[object Set]",iz="[object String]",az="[object Symbol]",lz="[object WeakMap]",cz="[object ArrayBuffer]",dz="[object DataView]",uz="[object Float32Array]",pz="[object Float64Array]",fz="[object Int8Array]",mz="[object Int16Array]",gz="[object Int32Array]",hz="[object Uint8Array]",Ez="[object Uint8ClampedArray]",_z="[object Uint16Array]",Sz="[object Uint32Array]",rn={};rn[zc]=rn[ZH]=rn[cz]=rn[dz]=rn[qH]=rn[QH]=rn[uz]=rn[pz]=rn[fz]=rn[mz]=rn[gz]=rn[nz]=rn[oz]=rn[Bc]=rn[rz]=rn[sz]=rn[iz]=rn[az]=rn[hz]=rn[Ez]=rn[_z]=rn[Sz]=!0;rn[ez]=rn[Fc]=rn[lz]=!1;function qr(c,A,L,ce,me,Ne){var Fe,st=A&YH,gt=A&XH,ht=A&JH;if(L)Fe=me?L(c,ce,me,Ne):L(c);if(Fe!==void 0)return Fe;if(!g(c))return c;var Et=d(c);if(Et){if(Fe=Rc(c),!st)return Kr(c,Fe)}else{var Rt=q(c),Tt=Rt==Fc||Rt==tz;if(H(c))return ir(c,st);if(Rt==Bc||Rt==zc||Tt&&!me){if(Fe=gt||Tt?{}:Yr(c),!st)return gt?Tc(c,bc(Fe,c)):Cc(c,Ac(Fe,c))}else{if(!rn[Rt])return me?c:{};Fe=xc(c,Rt,st)}}Ne||(Ne=new F);var It=Ne.get(c);if(It)return It;if(Ne.set(c,Fe),Hc(c))c.forEach(function(xt){Fe.add(qr(xt,A,L,xt,c,Ne))});else if(kc(c))c.forEach(function(xt,Yt){Fe.set(Yt,qr(xt,A,L,Yt,c,Ne))});var Lt=ht?gt?Co:Ue:gt?kn:K,Bt=Et?void 0:Lt(c);return Oc(Bt||c,function(xt,Yt){if(Bt)Yt=xt,xt=c[Yt];Ao(Fe,Yt,qr(xt,A,L,Yt,c,Ne))}),Fe}var Gc=qr;function yz(c){var A=c==null?0:c.length;return A?c[A-1]:void 0}var Wc=yz;function Oz(c,A,L){var ce=-1,me=c.length;if(A<0)A=-A>me?0:me+A;if(L=L>me?me:L,L<0)L+=me;me=A>L?0:L-A>>>0,A>>>=0;var Ne=Array(me);while(++ce<me)Ne[ce]=c[ce+A];return Ne}var jc=Oz;function Az(c,A){return A.length<2?c:se(c,jc(A,0,-1))}var $c=Az;var bz=Object.prototype,Cz=bz.hasOwnProperty;function Tz(c,A){A=k(A,c);var L=-1,ce=A.length;if(!ce)return!0;while(++L<ce){var me=x(A[L]);if(me==="__proto__"&&!Cz.call(c,"__proto__"))return!1;if((me==="constructor"||me==="prototype")&&L<ce-1)return!1}var Ne=$c(c,A);return Ne==null||delete Ne[x(Wc(A))]}var Qr=Tz;function Rz(c){return Xr(c)?void 0:c}var Vc=Rz;var Kc=E?E.isConcatSpreadable:void 0;function Dz(c){return d(c)||Y(c)||!!(Kc&&c&&c[Kc])}var Yc=Dz;function Xc(c,A,L,ce,me){var Ne=-1,Fe=c.length;L||(L=Yc),me||(me=[]);while(++Ne<Fe){var st=c[Ne];if(A>0&&L(st))if(A>1)Xc(st,A-1,L,ce,me);else be(me,st);else if(!ce)me[me.length]=st}return me}var Jc=Xc;function Lz(c){var A=c==null?0:c.length;return A?Jc(c,1):[]}var Zc=Lz;function Iz(c){return Zr(Jr(c,void 0,Zc),c+"")}var es=Iz;var Pz=1,wz=2,xz=4,Nz=es(function(c,A){var L={};if(c==null)return L;var ce=!1;if(A=we(A,function(Ne){return Ne=k(Ne,c),ce||(ce=Ne.length>1),Ne}),Tn(c,Co(c),L),ce)L=Gc(L,Pz|wz|xz,Vc);var me=A.length;while(me--)Qr(L,A[me]);return L}),lr=Nz;function vz(c,A){return Mr(c,A,function(L,ce){return nt(c,ce)})}var qc=vz;var kz=es(function(c,A){return c==null?{}:qc(c,A)}),wo=kz;function Mz(c,A){return c==null?!0:Qr(c,A)}var Qc=Mz;import{homedir as Tj}from"os";import{basename as Rj,dirname as Vs,join as En,resolve as ln}from"path";var Uz="Expected a function";function Hz(c){if(typeof c!="function")throw TypeError(Uz);return function(){var A=arguments;switch(A.length){case 0:return!c.call(this);case 1:return!c.call(this,A[0]);case 2:return!c.call(this,A[0],A[1]);case 3:return!c.call(this,A[0],A[1],A[2])}return!c.apply(this,A)}}var ed=Hz;function zz(c,A){return Hr(c,ed(j(A)))}var oo=zz;function Fz(c,A,L,ce){var me=c.length,Ne=L+(ce?1:-1);while(ce?Ne--:++Ne<me)if(A(c[Ne],Ne,c))return Ne;return-1}var td=Fz;function Bz(c){return c!==c}var nd=Bz;function Gz(c,A,L){var ce=L-1,me=c.length;while(++ce<me)if(c[ce]===A)return ce;return-1}var od=Gz;function Wz(c,A,L){return A===A?od(c,A,L):td(c,nd,L)}var rd=Wz;function jz(c,A){var L=c==null?0:c.length;return!!L&&rd(c,A,0)>-1}var sd=jz;function $z(c,A,L){var ce=-1,me=c==null?0:c.length;while(++ce<me)if(L(A,c[ce]))return!0;return!1}var id=$z;function Vz(){}var ad=Vz;var Kz=1/0,Yz=!(re&&1/ye(new re([,-0]))[1]==Kz)?ad:function(c){return new re(c)},ld=Yz;var Xz=200;function Jz(c,A,L){var ce=-1,me=sd,Ne=c.length,Fe=!0,st=[],gt=st;if(L)Fe=!1,me=id;else if(Ne>=Xz){var ht=A?null:ld(c);if(ht)return ye(ht);Fe=!1,me=Xe,gt=new qe}else gt=A?[]:st;e:while(++ce<Ne){var Et=c[ce],Rt=A?A(Et):Et;if(Et=L||Et!==0?Et:0,Fe&&Rt===Rt){var Tt=gt.length;while(Tt--)if(gt[Tt]===Rt)continue e;if(A)gt.push(Rt);st.push(Et)}else if(!me(gt,Rt,L)){if(gt!==st)gt.push(Rt);st.push(Et)}}return st}var cd=Jz;function Zz(c,A){return c&&c.length?cd(c,j(A,2)):[]}var dd=Zz;import{join as cf}from"path";var ud={cli:!0,mcp:!0,"sdk-cli":!0,"sdk-ts":!0,"sdk-py":!0,bench:!0,"claude-vscode":!0,"claude-code-github-action":!0,"local-agent":!0,local_agent:!0,"claude-desktop":!0,remote:!0,remote_baku:!0,remote_cowork:!0,remote_trigger:!0,remote_cowork_trigger:!0,remote_desktop:!0,remote_mobile:!0,remote_projects:!0,claude_in_slack:!0,"claude-in-slack":!0,"claude-in-teams":!0,"claude-desktop-3p":!0,"claude-security":!0,"ssh-remote":!0,"claude-coworker":!0,"claude-coworker-terminal":!0};var U4=new Set(Object.keys(ud));var Qz=new Set(["claude-desktop-3p","local-agent"]);function mi(){let c=Pn.CLAUDE_CODE_ENTRYPOINT;return c!==void 0&&Qz.has(c)}function ts(){return!1}function eF(c){return c?.startsWith("remote")===!0}class pd{entrypoint=void 0;interactive=!1;spawnedByAttendedSession=void 0;childSession=!1;hasRemoteSessionOrContainerId=!1;claudecode=!1;coworkFrameArtifacts=!1;hostScheduledRun=!1;desktopSkillSwitches=!1;hostUnattendedGrant=void 0;chromeTabGroupKey=void 0;hostAssignedGroup=void 0;hostSkillCatalog=void 0;remoteControlOwnerDeclared=!1;setEntrypoint(c){this.entrypoint=c}setInteractive(c){this.interactive=c}setSpawnedByAttendedSession(c){this.spawnedByAttendedSession=c}setChildSession(c){this.childSession=c}setHasRemoteSessionOrContainerId(c){this.hasRemoteSessionOrContainerId=c}setClaudecode(c){this.claudecode=c}setCoworkFrameArtifacts(c){this.coworkFrameArtifacts=c}setHostScheduledRun(c){this.hostScheduledRun=c}setDesktopSkillSwitches(c){this.desktopSkillSwitches=c}setHostUnattendedGrant(c){this.hostUnattendedGrant=c}setChromeTabGroupKey(c){this.chromeTabGroupKey=c}setHostSkillCatalog(c){this.hostSkillCatalog=c}setRemoteControlOwnerDeclared(c){this.remoteControlOwnerDeclared=c}setHostAssignedGroup(c){this.hostAssignedGroup=c}}var H4=new a(()=>new pd);var tF=new Set(["claude-vscode","claude-desktop","claude-desktop-3p","local-agent","local_agent","remote","remote_desktop","remote_mobile","remote_projects","remote_cowork","ssh-remote","claude-in-slack","claude_in_slack","claude-in-teams","claude-coworker","claude-coworker-terminal"]),z4=new Set([...tF].filter(eF));import{isAbsolute as fd}from"path";import*as Vt from"zod/v4";var gi="When managed settings or a --settings file set allowUnsandboxedCommands: false, or managed settings set network.allowManagedDomainsOnly: true",nF="When managed settings or a --settings file set allowUnsandboxedCommands: false, network.deniedDomains "+"or a WebFetch(domain:…) deny rule, when managed settings set network.allowManagedDomainsOnly: true, "+"or when managed, --settings or user settings set network.strictAllowlist: true",oF="When managed settings or a --settings file set allowUnsandboxedCommands: false, filesystem.denyRead, "+"a Read(…) deny rule or a credentials.files entry (deny or mask), or managed settings set network.allowManagedDomainsOnly: true",rF="When managed settings or a --settings file set filesystem.denyRead, a Read(…) deny rule "+"or a credentials.files entry (deny or mask)",Vn="project settings (.claude/settings.json and .claude/settings.local.json)",xo=`${gi}, values from ${Vn} are ignored.`,ns=`${gi}, true from ${Vn} is ignored (false there still applies).`,md=`${gi}, and managed, --settings or user settings set true, false from ${Vn} is ignored (true there still applies).`,gd=`${nF}, values from ${Vn} are ignored. With network.allowManagedDomainsOnly, only managed settings may set it.`,sF=`${oF}, a value from ${Vn} that would re-open a path managed, --settings or user settings deny reading is ignored, as is one spelled as a glob or a network path (UNC or automount); one carving out of the project's own denyRead still applies. A value inside a directory sandboxed commands can write is re-checked before every command and dropped once it has been re-pointed into a denied path.`,iF=`${xo} ${rF}, a value from ${Vn} under or equal to a denied path, or spelled as a glob or a network path (UNC or automount), is ignored. A value inside a directory sandboxed commands can already write is re-checked before every command and dropped once it has been re-pointed into a denied read path.`,aF=Mt(()=>Vt.object({allowedDomains:Vt.array(Vt.string()).optional().describe("Domains sandboxed commands may reach without a prompt (wildcards such as *.example.com supported). "+"Merged with WebFetch(domain:…) allow rules and across settings sources. "+xo+" With network.allowManagedDomainsOnly, only managed settings supply it."),deniedDomains:Vt.array(Vt.string()).optional().describe("Domains that are always blocked, even if matched by allowedDomains. Supports the same wildcard syntax as allowedDomains. Merged from all settings sources regardless of allowManagedDomainsOnly."),strictAllowlist:Vt.boolean().optional().describe("When true, the sandbox runtime deterministically denies hosts not in allowedDomains instead of prompting. "+"Enforced for sandboxed commands only — in-process tools such as WebFetch are not gated by this setting. "+"Only honored from user, managed/policy, or CLI (--settings) settings — "+`${Vn} are ignored, and while it is on their allowedDomains `+"and WebFetch(domain:…) allow rules are left out of the allowlist."),allowManagedDomainsOnly:Vt.boolean().optional().describe("When true (and set in managed settings), only allowedDomains and WebFetch(domain:...) allow rules from managed settings are respected. User, project, local, and flag settings domains are ignored. Denied domains are still respected from all sources."),allowUnixSockets:Vt.array(Vt.string()).optional().describe("macOS only: Unix socket paths to allow. Ignored on Linux (seccomp cannot filter by path). Merged across settings sources. "+xo),allowAllUnixSockets:Vt.boolean().optional().describe("If true, allow all Unix sockets (disables blocking on both platforms). "+ns),allowLocalBinding:Vt.boolean().optional().describe("macOS only: If true, sandboxed commands can bind to localhost ports. "+ns),allowMachLookup:Vt.array(Vt.string().refine((c)=>!(c.endsWith("*")?c.slice(0,-1):c).includes("*"),{message:'Wildcards are only allowed as a single trailing "*" (e.g., "com.example.*" or "*" for all services).'})).optional().describe('macOS only: Additional XPC/Mach service names to allow looking up. Supports trailing-wildcard prefix matching (e.g., "com.apple.coresimulator.*"). Needed for tools that communicate via XPC such as the iOS Simulator or Playwright. Merged across settings sources. '+xo),httpProxyPort:Vt.number().optional().describe("Local TCP port of your own HTTP proxy for sandboxed traffic, used instead of the proxy Claude Code runs. "+gd),socksProxyPort:Vt.number().optional().describe("Local TCP port of your own SOCKS5 proxy for sandboxed traffic, used instead of the proxy Claude Code runs. "+gd),tlsTerminate:Vt.object({caCertPath:Vt.string().min(1).optional(),caKeyPath:Vt.string().min(1).optional()}).optional().describe("[EXPERIMENTAL] Enable in-process TLS termination so the per-request filter can see HTTPS request bodies. Provide a CA cert+key, or omit both to have sandbox-runtime generate an ephemeral one for the session. On native Windows an ephemeral CA cannot pass the sandbox trust check, so omitting the paths uses a persistent CA managed by the sandbox runtime (set up and trusted via /sandbox install); configured paths are passed to the sandbox runtime verbatim, which rejects a bad or incomplete pair at sandbox initialization. "+"Only honored from user, managed/policy, or CLI (`--settings`) settings — project settings "+"(.claude/settings.json and .claude/settings.local.json) are ignored.")}).optional()),lF=Mt(()=>Vt.object({allowWrite:Vt.array(Vt.string()).optional().describe("Additional paths to allow writing within the sandbox. Merged with paths from Edit(...) allow permission rules. "+iF),denyWrite:Vt.array(Vt.string()).optional().describe("Additional paths to deny writing within the sandbox. Merged with paths from Edit(...) deny permission rules."),denyRead:Vt.array(Vt.string()).optional().describe("Additional paths to deny reading within the sandbox. Merged with paths from Read(...) deny permission rules."),allowRead:Vt.array(Vt.string()).optional().describe("Paths to re-allow reading within denyRead regions. Takes precedence over denyRead for matching paths. "+sF),allowManagedReadPathsOnly:Vt.boolean().optional().describe("When true (set in managed settings), only allowRead paths from policySettings are used."),disabled:Vt.boolean().optional().describe("macOS and Linux/WSL only: skip filesystem isolation entirely while keeping network and seccomp isolation. Ignored on native Windows, where the sandboxed process runs as a separate user with no inherent rights, so skipping the filesystem rules would "+"withhold every access grant rather than loosen them — filesystem isolation stays on there. "+"Sandboxed commands get unrestricted read/write access to the host filesystem; network egress is still confined to network.allowedDomains. Intended for deployments whose goal is egress control rather than filesystem containment. Does not change Bash prompting: sandbox.autoAllowBashIfSandboxed is independent and still defaults to true, so set it to false to keep prompting for sandboxed commands. Drops the read protection from filesystem.denyRead and credentials.files deny entries for sandboxed commands, since both are enforced by the filesystem layer this turns off; credentials.files mask entries (sentinel binds) and credentials.envVars deny/mask are unaffected. "+"Only honored from user, managed/policy, or CLI (`--settings`) settings — "+"project settings (.claude/settings.json and .claude/settings.local.json) are ignored. If managed settings configure sandbox.filesystem at all, or list any sandbox.credentials.files deny entry, only managed settings can set this: an admin who deployed filesystem restrictions must not have them switched off by a user-writable file. (sandbox.credentials.envVars and credentials.files mask entries "+"do not pin it — env scrubbing and sentinel binds are independent of the filesystem "+"layer and survive this setting.) When unset, filesystem isolation stays on.")}).optional());function hd(c,A,L){if(c.length===0||c.some((ce)=>ce.length===0))L.addIssue({code:Vt.ZodIssueCode.custom,path:["maskClaims"],message:"maskClaims must name at least one non-empty claim — omit maskClaims for whole-token masking."});if(A===void 0)L.addIssue({code:Vt.ZodIssueCode.custom,path:["maskClaims"],message:"maskClaims requires decode — without a decode format there is no token to read claims from. Set decode, or omit maskClaims."})}function Ed(c,A){let L;try{L=new RegExp(c)}catch(me){A.addIssue({code:Vt.ZodIssueCode.custom,path:["extract"],message:`extract is not a valid regular expression: ${y(me)}`});return}if(new RegExp(L.source+"|").exec("").length-1<1)A.addIssue({code:Vt.ZodIssueCode.custom,path:["extract"],message:"extract must contain at least one capturing group — "+'group 1 is the credential value to mask (e.g. "token:\\s*(\\S+)").'})}function _d(c){if(typeof c!=="object"||c===null)return c;let A=c;if(A.mode!=="deny")return c;let L={...A};if("extract"in L&&typeof L.extract!=="string")delete L.extract;if("onExtractNoMatch"in L&&L.onExtractNoMatch!=="warn"&&L.onExtractNoMatch!=="deny"&&L.onExtractNoMatch!=="error")delete L.onExtractNoMatch;if("decode"in L&&L.decode!=="jwt")delete L.decode;if("maskClaims"in L&&!(Array.isArray(L.maskClaims)&&L.maskClaims.every((ce)=>typeof ce==="string")))delete L.maskClaims;if("maskDuplicates"in L&&typeof L.maskDuplicates!=="boolean")delete L.maskDuplicates;if("injectHosts"in L&&!(Array.isArray(L.injectHosts)&&L.injectHosts.every((ce)=>typeof ce==="string")))delete L.injectHosts;return L}var os=Mt(()=>Vt.preprocess(_d,Vt.object({path:Vt.string().min(1).describe("Path to a credential file or directory. Same resolution as sandbox.filesystem.* paths: absolute, ~ expanded, or relative to the settings file root (project root for project settings, ~/.claude for user settings)."),mode:Vt.enum(["deny","mask"]).describe("Access mode for this path. `deny` blocks reads inside the sandbox; `mask` shows sandboxed commands a sentinel-substituted copy (whole-file, or only the spans captured by `extract`) and the "+"host proxy swaps sentinel→real on egress to `injectHosts`. "+"On macOS and Windows `mask` currently degrades to `deny`."),extract:Vt.string().optional().describe("Optional regex for structured masking when mode is `mask`. Applied globally to the file; capture group 1 of each match is a credential value, and only those captured spans are replaced "+"with sentinels — the rest of the file is preserved so a tool "+"that parses it (.netrc, JSON, YAML) still succeeds. Without `extract`, the entire file content is replaced with one sentinel (whole-file masking, suited to single-secret files). If the regex matches nothing, behavior is governed by `onExtractNoMatch` (default `warn`). Accepted but ignored for `deny`."),onExtractNoMatch:Vt.enum(["warn","deny","error"]).optional().describe("What to do when `extract` matches nothing in the file — or, "+"with `decode`, when no candidate survives verification. `warn` (default) emits a stderr warning and leaves the file readable as-is inside the sandbox (fail-open, for credentials that may be legitimately absent); `deny` degrades the entry to "+"mode `deny` so the file is unreadable (fail-closed) — under "+"`sandbox.filesystem.disabled` it is treated as `error`, since read-denies are dropped in that mode; `error` aborts at sandbox setup so nothing runs until the config is fixed. Only meaningful when mode is `mask` and `extract` or `decode` is set; accepted but ignored otherwise."),decode:Vt.enum(["jwt"]).optional().describe("Optional encoded-credential format for `mask` mode. `jwt`: candidates are located with a built-in JWT regex (or the explicit `extract` pattern, if set), verified to actually be JWTs before masking, and replaced with a structurally valid fake JWT so client-side token parsing inside the sandbox keeps working. If no candidate verifies, behavior is governed by `onExtractNoMatch` (default `warn`). Accepted but ignored for `deny`."),maskClaims:Vt.array(Vt.string()).optional().describe("Names of top-level payload claims to mask inside each decoded value, instead of replacing the whole token. Each named claim present with a string value gets its own sentinel and the token is rebuilt around the modified payload; all other claims are preserved so a tool that decodes the token and reads a non-secret claim keeps working. Requires `decode`. If no named claim matches in any verified token, behavior is governed by `onExtractNoMatch` (default `warn`). Only meaningful when mode is `mask`; accepted but ignored for `deny`."),maskDuplicates:Vt.boolean().optional().describe("If true, verbatim occurrences of each captured credential value outside the regex-matched spans are also replaced with the "+"corresponding sentinel — for a secret repeated where the regex "+"does not reach (e.g. pasted into a comment). Matches raw substrings, so short or common values may corrupt unrelated content; intended for long, high-entropy secrets. Defaults to false. Only meaningful when mode is `mask` and `extract` or `decode` is set; accepted but ignored otherwise."),injectHosts:Vt.array(Vt.string()).optional().describe("Optional narrowing of where the proxy substitutes this credential. Only meaningful when mode is `mask`; accepted but ignored for `deny`. If unset, defaults to "+"`network.allowedDomains` — the credential is injected at "+"every reachable host. Each entry must be reachable via `network.allowedDomains` (sandbox-runtime validates this).")}).superRefine((c,A)=>{if(c.mode==="mask"&&c.path.endsWith("/"))A.addIssue({code:Vt.ZodIssueCode.custom,path:["path"],message:'Credential mode "mask" applies to a single file, not a directory. List the specific credential file(s), or use "deny" for the directory.'});if(c.mode==="mask"&&c.extract!==void 0)Ed(c.extract,A);if(c.mode==="mask"&&c.maskClaims!==void 0)hd(c.maskClaims,c.decode,A)}))),No=()=>Vt.string().regex(/^[A-Za-z_][A-Za-z0-9_]*$/,"Environment variable name must start with a letter or underscore and contain only letters, digits, and underscores"),rs=Mt(()=>Vt.preprocess(_d,Vt.object({name:No().describe("Environment variable name."),mode:Vt.enum(["deny","mask"]).describe("Access mode for this environment variable. `deny` unsets the variable for sandboxed commands; `mask` shows sandboxed commands a sentinel value and the "+"host proxy swaps sentinel→real on egress to `injectHosts`."),extract:Vt.string().optional().describe("Optional regex for structured masking when mode is `mask`. Applied globally to the value; capture group 1 of each match is a credential value, and only those captured spans are "+"replaced with sentinels — the rest of the value is preserved "+"so a tool that parses it (a `DATABASE_URL` connection string, a composite `KEY:SECRET` pair) still succeeds inside the sandbox. Without `extract`, the entire value is replaced with one sentinel (whole-value masking, suited to bare tokens). If the regex matches nothing, behavior is governed by `onExtractNoMatch` (default `warn`). Cannot be combined with `decode` (the decode path never consults it). Accepted but ignored for `deny`."),onExtractNoMatch:Vt.enum(["warn","deny","error"]).optional().describe("What to do when `extract` matches nothing in the value. `warn` (default) emits a stderr warning and lets the variable pass through unmasked (fail-open, for credentials that may be legitimately absent); `deny` unsets the variable inside the sandbox (fail-closed); `error` aborts at sandbox setup so nothing runs until the config is fixed. Only meaningful when mode is `mask` and `extract` is set without `decode`. On a mask entry with `decode`, the runtime takes the decode path and never consults this field, so a fail-closed setting "+"cannot be honored — `deny` and `error` are rejected there; "+"only `warn` is accepted. In all other shapes the field is accepted but ignored."),decode:Vt.enum(["jwt"]).optional().describe("Optional encoded-credential format for `mask` mode. `jwt`: the variable's whole value is verified to actually be a JWT and replaced with a structurally valid fake JWT so client-side token parsing inside the sandbox keeps working; the proxy swaps the whole fake token on egress. If the value does not verify, the variable is left unmasked with a stderr warning "+"(fail-open). Cannot be combined with `extract` — the decode "+"path never consults it. Accepted but ignored for `deny`."),maskClaims:Vt.array(Vt.string()).optional().describe("Names of top-level payload claims to mask inside the decoded value, instead of replacing the whole token. Each named claim present with a string value gets its own sentinel and the token is rebuilt around the modified payload; all other claims are preserved so claim-reading clients keep working. Requires `decode`. If no named claim matches, the variable is left unmasked with a stderr warning (fail-open). Only meaningful when mode is `mask`; accepted but ignored for `deny`."),injectHosts:Vt.array(Vt.string()).optional().describe("Optional narrowing of where the proxy substitutes this credential. Only meaningful when mode is `mask`; accepted but ignored for `deny`. If unset, defaults to "+"`network.allowedDomains` — the credential is injected at "+"every reachable host. Each entry must be reachable via `network.allowedDomains` (sandbox-runtime validates this).")}).superRefine((c,A)=>{if(c.mode==="mask"&&c.extract!==void 0)Ed(c.extract,A);if(c.mode==="mask"&&c.maskClaims!==void 0)hd(c.maskClaims,c.decode,A);if(c.mode==="mask"&&c.decode!==void 0&&c.extract!==void 0)A.addIssue({code:Vt.ZodIssueCode.custom,path:["extract"],message:"extract cannot be combined with decode on an env entry — the runtime takes the decode path (whole-value JWT verification) and never consults extract, silently disabling the structured masking. Remove one of the two."});if(c.mode==="mask"&&c.decode!==void 0&&(c.onExtractNoMatch==="deny"||c.onExtractNoMatch==="error"))A.addIssue({code:Vt.ZodIssueCode.custom,path:["onExtractNoMatch"],message:"onExtractNoMatch cannot be honored on an env entry with decode — the runtime takes the decode path (which is unconditionally fail-open on verify failure) and never consults extract or onExtractNoMatch. Remove onExtractNoMatch, or drop decode to use extract-based masking (whose no-match handling does honor it)."})}))),Kn=["AWS_ACCESS_KEY_ID","AWS_SECRET_ACCESS_KEY","AWS_SESSION_TOKEN"];var hi="_INVALID_PAIR_",ss="_PARENT_PAIR_SUPPRESSOR_";var is=Mt(()=>Vt.object({accessKeyIdVar:No().describe("Name of the masked env var holding the AWS access key id."),secretAccessKeyVar:No().describe("Name of the masked env var holding the AWS secret access key."),sessionTokenVar:No().optional().describe("Optional name of the masked env var holding the AWS session token (temporary credentials). When set, the proxy sends the real token as x-amz-security-token on re-signed requests and adds it to the signed header set if the client did not.")}).superRefine((c,A)=>{let L=new Map;for(let[ce,me]of[["accessKeyIdVar",c.accessKeyIdVar],["secretAccessKeyVar",c.secretAccessKeyVar],["sessionTokenVar",c.sessionTokenVar]]){if(me===void 0)continue;let Ne=L.get(me);if(Ne!==void 0)A.addIssue({code:Vt.ZodIssueCode.custom,path:[ce],message:`${ce} names the same env var ('${me}') as ${Ne} — each pair member must be a distinct variable.`});else L.set(me,ce)}})),cF=Mt(()=>{let c=Vt.enum(["deny","passthrough"]);return Vt.object({streaming:c.optional().describe("Policy for aws-chunked streaming uploads (x-amz-content-sha256: STREAMING-*): per-chunk signatures chain off the seed signature, so re-signing would require rewriting the body. `deny` (default) fails closed with a 403; `passthrough` forwards the request unre-signed (the upstream will reject its signature)."),presigned:c.optional().describe("Policy for presigned URLs (X-Amz-Algorithm/X-Amz-Signature in the query, no Authorization header): the signature lives in the URL itself. `deny` (default) or `passthrough`."),sigv4a:c.optional().describe("Policy for SigV4A (AWS4-ECDSA-P256-SHA256) asymmetric signatures: there is no shared-key HMAC to recompute. `deny` (default) or `passthrough`.")})}),dF=Mt(()=>Vt.object({files:Vt.array(os()).optional().describe("Credential files or directories to protect. `deny` blocks reads inside the sandbox; `mask` substitutes a sentinel inside the sandbox (whole-file, or per-`extract` capture) and injects the real value at the proxy. On macOS and Windows `mask` degrades to `deny`."),envVars:Vt.array(rs()).optional().describe("Environment variables to protect. `deny` unsets the variable for sandboxed commands; `mask` substitutes a sentinel inside the sandbox and injects the real value at the proxy."),allowPlaintextInject:Vt.boolean().optional().describe("Allow sentinel→real substitution on the plain-HTTP proxy path. "+"Defaults to false: without TLS termination the upstream identity is unverified and the credential travels in cleartext. Set only for trusted-network test fixtures. Only honored from user, managed/policy, or CLI (`--settings`) "+"settings — project settings (.claude/settings.json and "+".claude/settings.local.json) are ignored."),awsPairs:Vt.array(is()).optional().describe("Explicit groupings of masked env vars into AWS credential pairs for SigV4 re-signing, for non-standard variable names. The conventional AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN trio is paired automatically when masked. Only honored from user, managed/policy, or CLI (`--settings`) "+"settings — project settings (.claude/settings.json and "+".claude/settings.local.json) are ignored. A member is only usable when its env var is forwarded as a whole-value `mask` entry (an entry carrying `extract` or `decode` does not "+"qualify — re-signing needs the whole real value). A pair "+"whose key id or secret member is unusable never re-signs: it is dropped, unless it names a conventional AWS variable, in which case it is forwarded as an inert suppressor so implicit auto-pairing stays overridden. A pair whose ONLY unusable member is the session token still re-signs, without an x-amz-security-token (temporary-credential requests fail upstream until the entry is fixed)."),sigv4:cF().optional().describe("Policies for AWS SigV4 request shapes the proxy cannot re-sign (streaming, presigned, sigv4a) when they reference a masked credential pair: `deny` (default) or `passthrough`. Only honored from user, managed/policy, or CLI (`--settings`) "+"settings — project settings (.claude/settings.json and "+".claude/settings.local.json) are ignored.")}).superRefine((c,A)=>{let L=new Set;for(let[ce,me]of(c?.awsPairs??[]).entries()){let Ne=[["accessKeyIdVar",me.accessKeyIdVar],["secretAccessKeyVar",me.secretAccessKeyVar],["sessionTokenVar",me.sessionTokenVar]],Fe=new Set;for(let[st,gt]of Ne){if(gt===void 0)continue;if(L.has(gt))A.addIssue({code:Vt.ZodIssueCode.custom,path:["awsPairs",ce,st],message:`"${gt}" appears in more than one awsPairs slot (within or across pairs) — each variable can fill exactly one slot.`});Fe.add(gt)}for(let st of Fe)L.add(st)}}).optional()),Ei=Mt(()=>Vt.object({enabled:Vt.boolean().optional().describe("Run Bash commands inside the sandbox. Default: false. "+md),failIfUnavailable:Vt.boolean().optional().describe("Exit with an error at startup if sandbox.enabled is true but the sandbox cannot start (missing dependencies or unsupported platform). When false (default), a warning is shown and commands run unsandboxed. Intended for managed-settings deployments that require sandboxing as a hard gate. "+md),autoAllowBashIfSandboxed:Vt.boolean().optional(),allowUnsandboxedCommands:Vt.boolean().optional().describe(`Allow commands to run outside the sandbox via the dangerouslyDisableSandbox parameter. When false, the dangerouslyDisableSandbox parameter is completely ignored and all commands must run sandboxed. Default: true. A false in managed, --settings or user settings holds whatever ${Vn} say (false there still applies).`),network:aF(),filesystem:lF(),credentials:dF(),ignoreViolations:Vt.record(Vt.string(),Vt.array(Vt.string())).optional().describe('Sandbox violations to leave unreported: a map of command patterns ("*" for every command) to the filesystem paths whose violations are ignored. Merged across settings sources. '+xo),enableWeakerNestedSandbox:Vt.boolean().optional().describe("Linux only: Run without the fresh /proc mount, for hosts such as unprivileged Docker containers that cannot create one. "+"**Reduces security** — the host /proc stays readable by sandboxed commands. Default: false. "+ns),enableWeakerNetworkIsolation:Vt.boolean().optional().describe("macOS only: Allow access to com.apple.trustd.agent in the sandbox. Needed for Go-based CLI tools (gh, gcloud, terraform, etc.) to verify TLS certificates when using httpProxyPort with a MITM proxy and custom CA. "+"**Reduces security** — opens a potential data exfiltration vector through the trustd service. Default: false. "+ns),allowAppleEvents:Vt.boolean().optional().describe("macOS only: Allow sandboxed commands to send Apple Events (and look up the appleeventsd Mach service). Needed for `open`, `osascript`, and browser-based auth flows that open URLs. "+"**Removes code-execution isolation** — sandboxed commands can launch other applications "+"unsandboxed with no user prompt, and can script running apps (e.g. Terminal) subject to the user's per-app TCC automation consent. "+"Only honored from user, managed/policy, or CLI (--settings) settings — "+"project settings (.claude/settings.json and .claude/settings.local.json) are ignored. Default: false"),excludedCommands:Vt.array(Vt.string()).optional().describe("Command patterns (Bash permission-rule syntax) that always run outside the sandbox. A convenience, not a security boundary: excluded commands still go through the permission flow. Merged across settings sources. "+xo),ripgrep:Vt.object({command:Vt.string(),args:Vt.array(Vt.string()).optional()}).optional().describe("Custom ripgrep configuration for bundled ripgrep support. "+"Only honored from user, managed/policy, or CLI (--settings) settings — "+"project settings (.claude/settings.json and .claude/settings.local.json) are ignored."),bwrapPath:Vt.preprocess((c)=>typeof c==="string"&&fd(c)?c:void 0,Vt.string()).optional().catch(void 0).describe("Linux/WSL only: Absolute path to the bwrap (bubblewrap) binary. Overrides auto-detection via PATH. Only honored from admin-controlled managed settings."),socatPath:Vt.preprocess((c)=>typeof c==="string"&&fd(c)?c:void 0,Vt.string()).optional().catch(void 0).describe("Linux/WSL only: Absolute path to the socat binary used for the sandbox network proxy. Overrides auto-detection via PATH. Only honored from admin-controlled managed settings.")}).passthrough());var Sd=new Set(["disableAllHooks"]),yd=["accessKeyIdVar","secretAccessKeyVar","sessionTokenVar"];function Od(c){let A={};for(let Lt of Mn()){let{path:Bt,restrictive:xt}=Lt;if(Sd.has(Bt[0]))continue;let Yt=Wr(Lt,c);if((typeof Yt==="boolean"||typeof Yt==="string")&&no(xt).includes(Yt))fn(A,Bt,Yt)}if(pn(c,["attribution"])===!1)fn(A,["attribution","sessionUrl"],!1);let L=as(c.permissions,["deny","ask","disableBypassPermissionsMode","disableAutoMode"]);if(L)A.permissions={...A.permissions,...L};for(let Lt of uF)if(c[Lt]!==void 0)A[Lt]=c[Lt];for(let[Lt,Bt]of Object.entries(c))if((Lt.startsWith("disable")&&(Bt===!0||Bt==="disable")||Lt.startsWith("enable")&&Bt===!1)&&!Sd.has(Lt))A[Lt]=Bt;if(c.disableAllHooks===!0)A.allowManagedHooksOnly=!0;if(Array.isArray(c.httpHookAllowedEnvVars)&&c.httpHookAllowedEnvVars.length===0)A.httpHookAllowedEnvVars=[];let ce=as(c.sandbox?.filesystem,["denyRead","denyWrite","allowManagedReadPathsOnly"]),me=as(c.sandbox?.network,["deniedDomains","strictAllowlist","allowManagedDomainsOnly"]),Ne=as(c.sandbox?.credentials,["files","envVars"])??{},Fe=c.sandbox?.credentials?.awsPairs,st=r(Fe)&&yd.some((Lt)=>(Lt in Fe)),ht=(Array.isArray(Fe)?Fe:st?[Fe]:[]).flatMap((Lt)=>r(Lt)?yd.map((Bt)=>Lt[Bt]):[]),Et=Fe!==void 0&&!Array.isArray(Fe)&&!st,Rt=Kn.filter((Lt)=>Et||ht.includes(Lt));if(Rt.length>0)Ne.awsPairs=Rt.map((Lt,Bt)=>({accessKeyIdVar:Lt,secretAccessKeyVar:`${ss}${Bt+1}_`}));let Tt=c.sandbox?.credentials?.sigv4;if(Tt){let Lt={};for(let[Bt,xt]of Object.entries(Tt))if(xt==="deny")Lt[Bt]="deny";if(Object.keys(Lt).length>0)Ne.sigv4=Lt}let It=Object.keys(Ne).length>0;if(ce||me||It){let Lt=A.sandbox??{};A.sandbox={...Lt,...ce&&{filesystem:{...Lt.filesystem,...ce}},...me&&{network:{...Lt.network,...me}},...It&&{credentials:{...Lt.credentials,...Ne}}}}return Object.keys(A).length>0?A:null}function as(c,A){if(!c)return;let L={};for(let ce of A)if(c[ce]!==void 0)L[ce]=c[ce];return Object.keys(L).length>0?L:void 0}var uF=["allowedMcpServers","deniedMcpServers","allowManagedMcpServersOnly","disabledMcpjsonServers","allowManagedHooksOnly","allowedHttpHookUrls","strictKnownMarketplaces","allowedMarketplaces","blockedMarketplaces","strictPluginOnlyCustomization","availableModels","enforceAvailableModels","availableModelsMatch","deniedModels","allowedProviders"];function bd(c){let A=0,L=c.length;while(A<L&&Ad(c.charCodeAt(A)))A++;while(L>A&&Ad(c.charCodeAt(L-1)))L--;let ce=pF(c.slice(A,L));if(ce!==-1)return{kind:"line_break",index:_i(c,A+ce)};for(let me=A;me<L;me++){let Ne=c.charCodeAt(me);if(Ne===0)return{kind:"nul",index:_i(c,me)};if(Ne>255)return{kind:"non_ascii",index:_i(c,me),codePoint:fF(c,me)}}return null}function pF(c){let A=c.indexOf(`
`),L=c.indexOf("\r");if(A===-1)return L;return L===-1?A:Math.min(A,L)}function Ad(c){return c===9||c===32||c===10||c===13}function fF(c,A){return c.codePointAt(A)??c.charCodeAt(A)}function _i(c,A){let L=0;for(let ce=0;ce<A;ce++){let me=c.charCodeAt(ce);if(me>=55296&&me<=56319&&ce+1<c.length&&(c.charCodeAt(ce+1)&64512)===56320)ce++;L++}return L}var Si=["CLAUDE_CODE_USE_BEDROCK","CLAUDE_CODE_USE_VERTEX","CLAUDE_CODE_USE_FOUNDRY","CLAUDE_CODE_USE_ANTHROPIC_AWS","CLAUDE_CODE_USE_ANTHROPIC_GOOGLE_CLOUD","CLAUDE_CODE_USE_MANTLE","CLAUDE_CODE_USE_GATEWAY","ANTHROPIC_FOUNDRY_RESOURCE","ANTHROPIC_VERTEX_PROJECT_ID","ANTHROPIC_AWS_WORKSPACE_ID","ANTHROPIC_GOOGLE_CLOUD_PROJECT","ANTHROPIC_GOOGLE_CLOUD_LOCATION","ANTHROPIC_GOOGLE_CLOUD_WORKSPACE_ID","CLOUD_ML_REGION"],Cd=["CLAUDE_CODE_USE_BEDROCK","CLAUDE_CODE_USE_ANTHROPIC_AWS","CLAUDE_CODE_USE_MANTLE"];var Td="OTEL_EXPORTER_OTLP_",Rd=["OTEL_LOG_RAW_API_BODIES","OTEL_LOG_USER_PROMPTS","OTEL_LOG_ASSISTANT_RESPONSES","OTEL_LOG_TOOL_CONTENT","OTEL_LOG_TOOL_DETAILS","OTEL_LOG_MANAGED_SETTINGS","OTEL_LOGS_EXPORTER","ENABLE_BETA_TRACING_DETAILED","BETA_TRACING_ENDPOINT","ANT_OTEL_LOGS_EXPORTER"],Dd=[Td,`ANT_${Td}`];var Ld={apiKeyHelper:["ANTHROPIC_BASE_URL","_CLAUDE_CODE_ASSUME_FIRST_PARTY_BASE_URL"],awsAuthRefresh:[...Cd,"ANTHROPIC_BEDROCK_BASE_URL","ANTHROPIC_AWS_BASE_URL","ANTHROPIC_BEDROCK_MANTLE_BASE_URL"],awsCredentialExport:[...Cd,"ANTHROPIC_BEDROCK_BASE_URL","ANTHROPIC_AWS_BASE_URL","ANTHROPIC_BEDROCK_MANTLE_BASE_URL"],gcpAuthRefresh:["CLAUDE_CODE_USE_VERTEX","CLAUDE_CODE_USE_ANTHROPIC_GOOGLE_CLOUD","ANTHROPIC_VERTEX_BASE_URL","ANTHROPIC_GOOGLE_CLOUD_BASE_URL"]},mF=["CLAUDE_CODE_MEMORY_API_BASE_URL","CLAUDE_CODE_MEMORY_API_TOKEN"];var yi=["ANTHROPIC_BASE_URL","_CLAUDE_CODE_ASSUME_FIRST_PARTY_BASE_URL","ANTHROPIC_BEDROCK_BASE_URL","ANTHROPIC_VERTEX_BASE_URL","ANTHROPIC_FOUNDRY_BASE_URL","ANTHROPIC_AWS_BASE_URL","ANTHROPIC_GOOGLE_CLOUD_BASE_URL","ANTHROPIC_BEDROCK_MANTLE_BASE_URL","CLAUDE_CODE_ARTIFACTS_API_BASE_URL","CLAUDE_CODE_ARTIFACTS_API_TOKEN","CLAUDE_CODE_ARTIFACT_ASSET_BASE_URL","CLAUDE_CODE_ARTIFACT_LIVE_BASE_URL","CLAUDE_CODE_ARTIFACT_SYNC_BASE_URL","CLAUDE_CODE_ARTIFACT_VIEWER_BASE_URL",...mF],gF=[{endpoint:"ANTHROPIC_BASE_URL",companions:["_CLAUDE_CODE_ASSUME_FIRST_PARTY_BASE_URL","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_BEDROCK_BASE_URL",selection:"CLAUDE_CODE_USE_BEDROCK",companions:["CLAUDE_CODE_SKIP_BEDROCK_AUTH","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_VERTEX_BASE_URL",selection:"CLAUDE_CODE_USE_VERTEX",companions:["CLAUDE_CODE_SKIP_VERTEX_AUTH","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_FOUNDRY_BASE_URL",selection:"CLAUDE_CODE_USE_FOUNDRY",companions:["CLAUDE_CODE_SKIP_FOUNDRY_AUTH","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_AWS_BASE_URL",selection:"CLAUDE_CODE_USE_ANTHROPIC_AWS",companions:["CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_GOOGLE_CLOUD_BASE_URL",selection:"CLAUDE_CODE_USE_ANTHROPIC_GOOGLE_CLOUD",companions:["CLAUDE_CODE_SKIP_ANTHROPIC_GOOGLE_CLOUD_AUTH","ANTHROPIC_CUSTOM_HEADERS"]},{endpoint:"ANTHROPIC_BEDROCK_MANTLE_BASE_URL",selection:"CLAUDE_CODE_USE_MANTLE",companions:["CLAUDE_CODE_SKIP_MANTLE_AUTH","ANTHROPIC_CUSTOM_HEADERS"]}],Q4=v(gF.flatMap((c)=>[c.endpoint,...c.companions])),Oi=["ANTHROPIC_API_KEY","ANTHROPIC_AUTH_TOKEN","CLAUDE_CODE_OAUTH_TOKEN","AWS_BEARER_TOKEN_BEDROCK","ANTHROPIC_FOUNDRY_API_KEY","ANTHROPIC_FOUNDRY_AUTH_TOKEN","ANTHROPIC_AWS_API_KEY"],hF=["CLAUDE_CODE_SKIP_BEDROCK_AUTH","CLAUDE_CODE_SKIP_VERTEX_AUTH","CLAUDE_CODE_SKIP_FOUNDRY_AUTH","CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH","CLAUDE_CODE_SKIP_ANTHROPIC_GOOGLE_CLOUD_AUTH","CLAUDE_CODE_SKIP_MANTLE_AUTH"],Ai=["ANTHROPIC_MODEL","ANTHROPIC_DEFAULT_MODEL","ANTHROPIC_DEFAULT_FABLE_MODEL","ANTHROPIC_DEFAULT_FABLE_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_FABLE_MODEL_NAME","ANTHROPIC_DEFAULT_FABLE_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_HAIKU_MODEL","ANTHROPIC_DEFAULT_HAIKU_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_HAIKU_MODEL_NAME","ANTHROPIC_DEFAULT_HAIKU_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_OPUS_MODEL","ANTHROPIC_DEFAULT_OPUS_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_OPUS_MODEL_NAME","ANTHROPIC_DEFAULT_OPUS_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_SONNET_MODEL","ANTHROPIC_DEFAULT_SONNET_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_SONNET_MODEL_NAME","ANTHROPIC_DEFAULT_SONNET_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_SMALL_FAST_MODEL","ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION","CLAUDE_CODE_SUBAGENT_MODEL","CLAUDE_CODE_3P_PROBE_WROTE_SONNET_DEFAULT","CLAUDE_CODE_3P_PROBE_WROTE_OPUS_DEFAULT","CLAUDE_CODE_3P_PROBE_WROTE_HAIKU_DEFAULT","CLAUDE_CODE_3P_SEEDED_SONNET_DEFAULT","CLAUDE_CODE_3P_SEEDED_OPUS_DEFAULT"],bi=["ANTHROPIC_CUSTOM_MODEL_OPTION","ANTHROPIC_CUSTOM_MODEL_OPTION_DESCRIPTION","ANTHROPIC_CUSTOM_MODEL_OPTION_NAME","ANTHROPIC_CUSTOM_MODEL_OPTION_SUPPORTED_CAPABILITIES"],EF=["CLAUDE_CODE_OAUTH_TOKEN_FILE_DESCRIPTOR","CLAUDE_CODE_GATEWAY_TOKEN_FILE_DESCRIPTOR","CLAUDE_CODE_API_KEY_FILE_DESCRIPTOR","CLAUDE_CODE_WEBSOCKET_AUTH_FILE_DESCRIPTOR","CCR_AGENT_PROXY_TOKEN_FILE_DESCRIPTOR"],eZ=["CLAUDE_CODE_OAUTH_TOKEN",...EF,"CLAUDE_CODE_ARTIFACTS_API_TOKEN","CLAUDE_CODE_SLACK_TAG_TOKEN","CLAUDE_CODE_HFI_BEARER_TOKEN","CLAUDE_BRIDGE_OAUTH_TOKEN","CLAUDE_TRUSTED_DEVICE_TOKEN","AGENT_PROXY_AUTH_TOKEN","CLAUDE_CODE_MCP_SERVE_AUTH_TOKEN","CLAUDE_BG_AUTH_SNAPSHOT_PATH","CLAUDE_BG_SOCKET_TOKENS_PATH","CLAUDE_BG_RV_AUTH","CLAUDE_BG_PTY_AUTH","CLAUDE_BG_CLAIM_AUTH"],_F=["AWS_ACCESS_KEY_ID","AWS_SECRET_ACCESS_KEY","AWS_SESSION_TOKEN"],Ci=[..._F,"AWS_PROFILE","AWS_CONFIG_FILE","AWS_SHARED_CREDENTIALS_FILE","GOOGLE_APPLICATION_CREDENTIALS","GOOGLE_CLOUD_PROJECT"];var Ti=["AWS_CONTAINER_CREDENTIALS_FULL_URI","AWS_CONTAINER_CREDENTIALS_RELATIVE_URI","AWS_CONTAINER_AUTHORIZATION_TOKEN","AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE","AWS_EC2_METADATA_SERVICE_ENDPOINT","AWS_EC2_METADATA_SERVICE_ENDPOINT_MODE","AWS_WEB_IDENTITY_TOKEN_FILE","AWS_ROLE_ARN"],Ri=["GCE_METADATA_HOST","GCE_METADATA_ROOT","GCE_METADATA_IP","METADATA_SERVER_DETECTION"],tZ=new Set(["CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST",...Si,...yi,...Oi,...hF,"CLAUDE_CODE_HOST_AUTH_ENV_VAR","CLAUDE_CODE_SDK_HAS_HOST_AUTH_REFRESH","CLAUDE_CODE_HOST_AUTH_REFRESH_TIMEOUT_MS","CLAUDE_CODE_HOST_CREDS_FILE",...Ci,"GCLOUD_PROJECT","GOOGLE_CLOUD_QUOTA_PROJECT",...Ri,...Ti,"AWS_REGION","AWS_DEFAULT_REGION",...Ai,"ANTHROPIC_BEDROCK_SERVICE_TIER","ANTHROPIC_BEDROCK_REGION_PREFIX","CLAUDE_CODE_CERT_STORE","DISABLE_GROWTHBOOK","CLAUDE_CODE_AUTO_MODE_MODEL","CLAUDE_CODE_BG_CLASSIFIER_MODEL","CLAUDE_CODE_SUBAGENT_MODEL_FORCE",...bi]);var Id=["apiKeyHelper","awsAuthRefresh","awsCredentialExport","fileSuggestion","gcpAuthRefresh","otelHeadersHelper","processWrapper","policyHelpers","proxyAuthHelper","statusLine","subagentStatusLine"],Di=["bwrapPath","ripgrep","socatPath"],Pd=["allowAppleEvents","credentials","enableWeakerNestedSandbox","enableWeakerNetworkIsolation","filesystem.disabled","network.allowAllUnixSockets","network.allowMachLookup","network.allowUnixSockets","network.httpProxyPort","network.socksProxyPort","network.tlsTerminate"],wd=["required","egress"],SF=new Set(["ANTHROPIC_BEDROCK_REGION_PREFIX","ANTHROPIC_BEDROCK_SERVICE_TIER","ANTHROPIC_CUSTOM_MODEL_OPTION","ANTHROPIC_CUSTOM_MODEL_OPTION_DESCRIPTION","ANTHROPIC_CUSTOM_MODEL_OPTION_NAME","ANTHROPIC_CUSTOM_MODEL_OPTION_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_FABLE_MODEL","ANTHROPIC_DEFAULT_FABLE_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_FABLE_MODEL_NAME","ANTHROPIC_DEFAULT_FABLE_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_MODEL","ANTHROPIC_DEFAULT_HAIKU_MODEL","ANTHROPIC_DEFAULT_HAIKU_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_HAIKU_MODEL_NAME","ANTHROPIC_DEFAULT_HAIKU_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_OPUS_MODEL","ANTHROPIC_DEFAULT_OPUS_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_OPUS_MODEL_NAME","ANTHROPIC_DEFAULT_OPUS_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_DEFAULT_SONNET_MODEL","ANTHROPIC_DEFAULT_SONNET_MODEL_DESCRIPTION","ANTHROPIC_DEFAULT_SONNET_MODEL_NAME","ANTHROPIC_DEFAULT_SONNET_MODEL_SUPPORTED_CAPABILITIES","ANTHROPIC_FOUNDRY_API_KEY","ANTHROPIC_MODEL","ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION","ANTHROPIC_SMALL_FAST_MODEL","AWS_DEFAULT_REGION","AWS_PROFILE","AWS_REGION","BASH_DEFAULT_TIMEOUT_MS","BASH_MAX_OUTPUT_LENGTH","BASH_MAX_TIMEOUT_MS","CLAUDE_BASH_MAINTAIN_PROJECT_WORKING_DIR","CLAUDE_CODE_API_KEY_HELPER_TTL_MS","CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS","CLAUDE_CODE_DISABLE_TERMINAL_TITLE","CLAUDE_CODE_ENABLE_AUTO_MODE","CLAUDE_CODE_ENABLE_DESIGN_SYNC","CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL","CLAUDE_CODE_ENABLE_TELEMETRY","CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS","CLAUDE_CODE_IDE_SKIP_AUTO_INSTALL","CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH","CLAUDE_CODE_MAX_OUTPUT_TOKENS","CLAUDE_CODE_SKIP_BEDROCK_AUTH","CLAUDE_CODE_SKIP_FOUNDRY_AUTH","CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH","CLAUDE_CODE_SKIP_ANTHROPIC_GOOGLE_CLOUD_AUTH","CLAUDE_CODE_SKIP_MANTLE_AUTH","CLAUDE_CODE_SKIP_VERTEX_AUTH","CLAUDE_CODE_SUBAGENT_MODEL","CLAUDE_CODE_USE_BEDROCK","CLAUDE_CODE_USE_FOUNDRY","CLAUDE_CODE_USE_ANTHROPIC_AWS","CLAUDE_CODE_USE_ANTHROPIC_GOOGLE_CLOUD","CLAUDE_CODE_USE_GATEWAY","CLAUDE_CODE_USE_MANTLE","CLAUDE_CODE_USE_POWERSHELL_TOOL","CLAUDE_CODE_USE_VERTEX","DISABLE_AUTOUPDATER","DISABLE_BUG_COMMAND","DISABLE_COST_WARNINGS","DISABLE_FEEDBACK_COMMAND","DISABLE_GROWTHBOOK","DISABLE_INSTALLATION_CHECKS","DISABLE_UPDATES","ENABLE_TOOL_SEARCH","MAX_MCP_OUTPUT_TOKENS","MAX_THINKING_TOKENS","MCP_CONNECT_TIMEOUT_MS","MCP_TIMEOUT","MCP_TOOL_TIMEOUT","OTEL_EXPORTER_OTLP_COMPRESSION","OTEL_EXPORTER_OTLP_HEADERS","OTEL_EXPORTER_OTLP_LOGS_COMPRESSION","OTEL_EXPORTER_OTLP_LOGS_HEADERS","OTEL_EXPORTER_OTLP_LOGS_PROTOCOL","OTEL_EXPORTER_OTLP_METRICS_COMPRESSION","OTEL_EXPORTER_OTLP_METRICS_HEADERS","OTEL_EXPORTER_OTLP_METRICS_PROTOCOL","OTEL_EXPORTER_OTLP_METRICS_TEMPORALITY_PREFERENCE","OTEL_EXPORTER_OTLP_PROTOCOL","OTEL_EXPORTER_OTLP_TRACES_COMPRESSION","OTEL_EXPORTER_OTLP_TRACES_HEADERS","OTEL_EXPORTER_OTLP_TRACES_PROTOCOL","OTEL_LOG_ASSISTANT_RESPONSES","OTEL_LOG_TOOL_CONTENT","OTEL_LOG_TOOL_DETAILS","OTEL_LOG_USER_PROMPTS","OTEL_LOGS_EXPORT_INTERVAL","OTEL_LOGS_EXPORTER","OTEL_METRIC_EXPORT_INTERVAL","OTEL_METRICS_EXPORTER","OTEL_METRICS_INCLUDE_ACCOUNT_UUID","OTEL_METRICS_INCLUDE_ENTRYPOINT","OTEL_METRICS_INCLUDE_REPOSITORY","OTEL_METRICS_INCLUDE_RESOURCE_ATTRIBUTES","OTEL_METRICS_INCLUDE_SESSION_ID","OTEL_METRICS_INCLUDE_VERSION","OTEL_RESOURCE_ATTRIBUTES","OTEL_SERVICE_NAME","OTEL_TRACES_EXPORT_INTERVAL","OTEL_TRACES_EXPORTER","USE_BUILTIN_RIPGREP","VERTEX_REGION_CLAUDE_3_5_HAIKU","VERTEX_REGION_CLAUDE_3_5_SONNET","VERTEX_REGION_CLAUDE_3_7_SONNET","VERTEX_REGION_CLAUDE_4_0_OPUS","VERTEX_REGION_CLAUDE_4_0_SONNET","VERTEX_REGION_CLAUDE_4_1_OPUS","VERTEX_REGION_CLAUDE_4_5_OPUS","VERTEX_REGION_CLAUDE_4_6_OPUS","VERTEX_REGION_CLAUDE_4_7_OPUS","VERTEX_REGION_CLAUDE_4_8_OPUS","VERTEX_REGION_CLAUDE_5_OPUS","VERTEX_REGION_CLAUDE_5_5_OPUS","VERTEX_REGION_CLAUDE_FABLE_5","VERTEX_REGION_CLAUDE_FABLE_5_1","VERTEX_REGION_CLAUDE_4_5_SONNET","VERTEX_REGION_CLAUDE_4_6_SONNET","VERTEX_REGION_CLAUDE_5_SONNET","VERTEX_REGION_CLAUDE_5_5_SONNET","VERTEX_REGION_CLAUDE_HAIKU_4_5","VERTEX_REGION_CLAUDE_HAIKU_5_5","CLAUDE_AUTOCOMPACT_PCT_OVERRIDE","CLAUDE_CODE_AUTO_COMPACT_WINDOW","CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT","CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS","CLAUDE_CODE_MAX_CONTEXT_TOKENS","DISABLE_AUTO_COMPACT","DISABLE_COMPACT","CLAUDE_CODE_ALWAYS_ENABLE_EFFORT","CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING","CLAUDE_CODE_DISABLE_FAST_MODE","CLAUDE_CODE_DISABLE_LEGACY_MODEL_REMAP","CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK","CLAUDE_CODE_DISABLE_THINKING","CLAUDE_CODE_EFFORT_LEVEL","CLAUDE_CODE_MAX_EFFORT_REMINDER","CLAUDE_CODE_PROMPT_CACHE_TTL","CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL","DISABLE_INTERLEAVED_THINKING","DISABLE_PROMPT_CACHING","DISABLE_PROMPT_CACHING_FABLE","DISABLE_PROMPT_CACHING_HAIKU","DISABLE_PROMPT_CACHING_OPUS","DISABLE_PROMPT_CACHING_SONNET","ENABLE_PROMPT_CACHING_1H","ENABLE_PROMPT_CACHING_1H_BEDROCK","FALLBACK_FOR_ALL_PRIMARY_MODELS","FORCE_PROMPT_CACHING_5M","CLAUDE_AUTO_BACKGROUND_TASKS","CLAUDE_CODE_DISABLE_ADVISOR_TOOL","CLAUDE_CODE_DISABLE_AGENT_VIEW","CLAUDE_CODE_DISABLE_ARTIFACT","CLAUDE_CODE_DISABLE_BACKGROUND_TASKS","CLAUDE_CODE_DISABLE_BUNDLED_SKILLS","CLAUDE_CODE_DISABLE_CRON","CLAUDE_CODE_DISABLE_EXPLORE_PLAN_AGENTS","CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY","CLAUDE_CODE_DISABLE_FILE_CHECKPOINTING","CLAUDE_CODE_DISABLE_MCP_TASK_BACKGROUND","CLAUDE_CODE_DISABLE_MEMORY_RO_UNSAVED_NOTICE","CLAUDE_CODE_DISABLE_WORKFLOWS","CLAUDE_CODE_ENABLE_AWAY_SUMMARY","CLAUDE_CODE_ENABLE_FINE_GRAINED_TOOL_STREAMING","CLAUDE_CODE_ENABLE_FUNCTION_HOOKS","CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION","CLAUDE_CODE_ENABLE_TASKS","CLAUDE_CODE_FORK_SUBAGENT","CLAUDE_CODE_PLAN_MODE_REQUIRED","DISABLE_DOCTOR_COMMAND","DISABLE_EXTRA_USAGE_COMMAND","DISABLE_INSTALL_GITHUB_APP_COMMAND","DISABLE_LOGIN_COMMAND","DISABLE_LOGOUT_COMMAND","DISABLE_UPGRADE_COMMAND","CLAUDE_AX_SCREEN_READER","CLAUDE_CODE_ACCESSIBILITY","CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN","CLAUDE_CODE_DISABLE_MOUSE","CLAUDE_CODE_DISABLE_MOUSE_CLICKS","CLAUDE_CODE_DISABLE_VIRTUAL_SCROLL","CLAUDE_CODE_FORCE_STRIKETHROUGH","CLAUDE_CODE_FORCE_TERMINAL_IMAGES","CLAUDE_CODE_HIDE_CWD","CLAUDE_CODE_NATIVE_CURSOR","CLAUDE_CODE_NO_FLICKER","CLAUDE_CODE_SCROLL_SPEED","CLAUDE_CODE_SYNTAX_HIGHLIGHT","API_TIMEOUT_MS","CLAUDE_ASYNC_AGENT_STALL_TIMEOUT_MS","CLAUDE_CODE_FILE_READ_MAX_OUTPUT_TOKENS","CLAUDE_CODE_GLOB_TIMEOUT_SECONDS","CLAUDE_CODE_MAX_RETRIES","CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION","CLAUDE_CODE_MAX_TOOL_USE_CONCURRENCY","CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION","CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS","CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT","CLAUDE_CODE_TEAM_TEARDOWN_PARK_TIMEOUT_MS","CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR","CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS","CLAUDE_STREAM_IDLE_TIMEOUT_MS","MAX_STRUCTURED_OUTPUT_RETRIES","MCP_REMOTE_SERVER_CONNECTION_BATCH_SIZE","MCP_SERVER_CONNECTION_BATCH_SIZE","SLASH_COMMAND_TOOL_CHAR_BUDGET","TASK_MAX_OUTPUT_LENGTH","MCP_CONNECTION_NONBLOCKING","CLAUDE_ENABLE_BYTE_WATCHDOG","CLAUDE_ENABLE_BYTE_WATCHDOG_BEDROCK","CLAUDE_ENABLE_STREAM_WATCHDOG"]),yF=new Set(["API_FORCE_IDLE_TIMEOUT","CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC","CLAUDE_CODE_DISABLE_WEB_FETCH","DISABLE_ERROR_REPORTING","DISABLE_TELEMETRY","DO_NOT_TRACK"]),OF=new Set(["ENABLE_BETA_TRACING_DETAILED","OTEL_LOG_RAW_API_BODIES"]),AF=/auth|key|token|cookie|secret|credential|session|signature|passw|jwt|assertion|cert|oidc|org|tenant|account|project|workspace|user|email|identity|principal|consumer|client|host|url|base|target|upstream|endpoint|proxy|forward|route|fallback|override|apigw|x-goog-|l5d-|bypass|guardrail|amz|x-ms-|azureml|extra-parameters|envoy|helicone|litellm|cf-aig|cf-access|beta|version/;function bF(c){if(/\r(?!\n)/.test(c))return!0;return c.split(/\n|\r\n/).some((A)=>{let L=A.indexOf(":");if(L===-1)return!1;let ce=A.slice(0,L).trim();return!CF.test(ce)||bd(A.slice(L+1))!==null||AF.test(ce.toLowerCase())})}var CF=/^[!#$%&'*+.^_`|~0-9A-Za-z-]+$/;function xd(c,A){let L=c.toUpperCase();return SF.has(L)||TF(L,A)||L==="ANTHROPIC_CUSTOM_HEADERS"&&!bF(A)}function TF(c,A){return yF.has(c)&&o(A)||OF.has(c)&&de(A)}import{posix as Lp,win32 as Ip}from"path";import*as it from"zod/v4";import*as cr from"zod/v4";var ro=["acceptEdits","auto","bypassPermissions","default","dontAsk","plan"],DF=[...ro],Nd=DF;function vo(c){return c==="manual"?"default":c}var rZ=`Cannot set permission mode: must be one of ${ro.join(", ")}`;var sZ={dangerousRemoval:{bypassImmune:!0,classifierRouted:!0,autoModeDeny:!0,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},backgroundOperator:{bypassImmune:!1,classifierRouted:!0,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},suspiciousWindowsPath:{bypassImmune:!1,classifierRouted:!0,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},isolatePeerMachines:{bypassImmune:!0,classifierRouted:!1,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},restrictedMode:{bypassImmune:!0,classifierRouted:!1,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},outsideReadsBlocked:{bypassImmune:!0,classifierRouted:!1,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!1},claudeSettingsFile:{bypassImmune:!1,classifierRouted:!1,autoModeDeny:!1,hostPersonOnly:!0,localProjectionOnly:!1,servedUnplaceable:!1},internalHardDeny:{bypassImmune:!1,classifierRouted:!1,autoModeDeny:!1,hostPersonOnly:!1,localProjectionOnly:!1,servedUnplaceable:!0},...{},...{}};var vd=["auto","iterm2","terminal_bell","iterm2_with_bell","kitty","ghostty","notifications_disabled"];var kd=["normal","vim"];var Md=["auto","12-hour","24-hour","24-hour-utc"],Ud=["auto","tmux","iterm2","in-process"],LF=["dark","light","light-daltonized","dark-daltonized","light-ansi","dark-ansi"],Hd=["auto",...LF],zd=["auto","alwaysAsk","disabled"],Fd=1e5,Bd=1e6;import*as Gd from"zod/v4";import*as wn from"zod/v4/core";var IF=wn.$ZodType,PF=Gd.ZodType,Li=wn.$constructor("ZodDeferredOptional",(c,A)=>{IF.init(c,A),PF.init(c,A),c._zod.optin="optional",c._zod.optout="optional",Object.defineProperty(c._zod,"innerType",{get:A.built,configurable:!0}),c._zod.processJSONSchema=(L,ce,me)=>{let Ne=A.getter();wn.process(Ne,L,me),L.seen.get(c).ref=Ne},wn.util.defineLazy(c._zod,"values",()=>{let L=A.getter()._zod.values;return L?new Set([...L,void 0]):void 0}),wn.util.defineLazy(c._zod,"pattern",()=>{let L=A.getter()._zod.pattern;return L?new RegExp(`^(${wn.util.cleanRegex(L.source)})?$`):void 0}),wn.util.defineLazy(c._zod,"propValues",()=>A.getter()._zod.propValues),c._zod.parse=(L,ce)=>{if(L.value===void 0)return L;return A.getter()._zod.run(L,ce)},c.unwrap=A.getter});function On(c){let A;return new Li({type:"lazy",getter:()=>{if(A===void 0){let ce=c();if(ce._zod.optin!==void 0)throw Error("deferredOptional(): the schema the build callback returned already handles a missing key itself (.optional(), .catch(), .default(), .prefault(), z.preprocess(), or a union or wrapper holding one). Return the plain schema and let deferredOptional() make it optional, or use that schema with .optional() without deferring it.");A=ce}return A},built:()=>A})}import*as Ut from"zod/v4";var wF=String.raw`\$\{([A-Za-z_][A-Za-z0-9_]*)(?::-[^}]*)?\}`;function Wd(c){return new RegExp(wF).test(c)}var pZ=Mt(()=>Ut.enum(["local","user","project","dynamic","enterprise","claudeai","managed","agent"])),fZ=Mt(()=>Ut.enum(["stdio","sse","sse-ide","http","ws","sdk"]));var xF=/^[A-Za-z0-9_-]+$/;var ko=Mt(()=>Ut.literal("comms").optional().catch(void 0)),Yn=Mt(()=>Ut.number().int().positive()),NF=300000,jd=Mt(()=>Ut.number().int().positive().optional().catch(void 0).describe("@internal CCR backend wire hint; folded into timeout at parse."));function $d({request_timeout_ms:c,...A}){return{...A,...A.timeout===void 0&&c!==void 0&&{timeout:Math.min(c,NF)}}}var vF=Mt(()=>Ut.object({type:Ut.literal("stdio").optional(),command:Ut.string().min(1,"Command cannot be empty"),args:Ut.array(Ut.string()).default([]),env:Ut.record(Ut.string(),Ut.string()).optional(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),bareElicitationCapability:Ut.boolean().optional(),role:ko()})),kF=Mt(()=>Ut.boolean()),Vd=Mt(()=>Ut.object({clientId:Ut.string().optional(),callbackPort:Ut.number().int().positive().optional(),authServerMetadataUrl:Ut.string().url().startsWith("https://",{message:"authServerMetadataUrl must use https://"}).optional(),scopes:Ut.string().min(1).optional(),xaa:kF().optional()})),Kd=Mt(()=>Ut.object({name:Ut.string(),permission_policy:Ut.enum(["always_allow","always_ask","always_deny"]).optional()})),Yd=Mt(()=>Ut.object({type:Ut.literal("sse"),url:Ut.string(),headers:Ut.record(Ut.string(),Ut.string()).optional(),headersHelper:Ut.string().optional(),oauth:Vd().optional(),timeout:Yn().optional(),request_timeout_ms:jd(),tools:Ut.array(Kd()).optional(),alwaysLoad:Ut.boolean().optional(),bareElicitationCapability:Ut.boolean().optional(),discoveryCache:Ut.boolean().optional(),role:ko(),toolPermissions:Ut.record(Ut.string(),xi()).optional()}).transform($d)),MF=Mt(()=>Ut.object({type:Ut.literal("sse-ide"),url:Ut.string(),ideName:Ut.string(),ideRunningInWindows:Ut.boolean().optional(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),role:ko()})),UF=Mt(()=>Ut.object({type:Ut.literal("ws-ide"),url:Ut.string(),ideName:Ut.string(),authToken:Ut.string().optional(),ideRunningInWindows:Ut.boolean().optional(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),role:ko()})),Xd=Mt(()=>Ut.object({type:Ut.enum(["http","streamable-http"]).transform(()=>"http"),url:Ut.string(),headers:Ut.record(Ut.string(),Ut.string()).optional(),headersHelper:Ut.string().optional(),oauth:Vd().optional(),timeout:Yn().optional(),request_timeout_ms:jd(),tools:Ut.array(Kd()).optional(),alwaysLoad:Ut.boolean().optional(),bareElicitationCapability:Ut.boolean().optional(),discoveryCache:Ut.boolean().optional(),role:ko(),toolPermissions:Ut.record(Ut.string(),xi()).optional()}).transform($d)),HF=["command","args","env","headersHelper"],zF=new Set(["http","streamable-http","sse"]),FF=/[\p{Cc}\p{Cf}\u2028\u2029]/u,BF=/[\p{Cc}\p{Cf}\u2028\u2029]/gu;function Ii(c){return/^[A-Za-z0-9_-]+$/.test(c)&&c!=="__proto__"&&c!=="constructor"&&c!=="prototype"}function GF(c){try{let A=new URL(c);return A.protocol==="https:"&&A.hostname!==""}catch{return!1}}function Jd(c,A="",L=0){if(typeof c==="string")return[[A,c,!1]];if(L>4||c===null||typeof c!=="object")return[];return Object.entries(c).flatMap(([ce,me])=>{let Ne=ce.replace(BF,(st)=>`\\u${st.codePointAt(0).toString(16).padStart(4,"0")}`),Fe=A?`${A}.${Ne}`:Ne;return[[Fe,ce,!0],...Jd(me,Fe,L+1)]})}var Pi=Mt(()=>Ut.record(Ut.string(),Ut.unknown()).check((c)=>{let A=(ce,me)=>{c.issues.push({code:"custom",path:ce,message:me,input:c.value})};for(let ce of HF)if(Object.hasOwn(c.value,ce))A([ce],`"${ce}" is not allowed in managed settings: only http/sse URL servers can be delivered this way, and a managed settings document must not name a program to run`);if(!zF.has(c.value.type))A(["type"],'managed settings can only deliver "http" or "sse" servers');let L=c.value.url;if(typeof L==="string"&&!GF(L))A(["url"],"managed settings servers must use a valid https:// url");for(let[ce,me,Ne]of Jd(c.value))if(FF.test(me))A(ce.split("."),"contains control or invisible format characters (in a key or a value); a managed settings document must not be able to print escape sequences");else if(!Ne&&Wd(me))A(ce.split("."),"${VAR} references are not expanded in managed settings; use a literal value (a managed settings document must not read the user's environment)")}).pipe(Ut.union([Xd(),Yd()]))),wi=`"managedMcpServers" must be an object keyed by server name (the .mcp.json mcpServers shape; Claude Desktop's array form of its same-named key is not accepted here: use the server name as the key and "type" instead of "transport"). No managed MCP servers are installed from it until it is fixed.`;function ls(c,A){if(c===void 0)return;if(c===null||typeof c!=="object"||Array.isArray(c)){A("",wi);return}let L=Object.create(null);for(let[ce,me]of Object.entries(c)){if(!Ii(ce)){A("<invalid name>","server names may only contain letters, numbers, hyphens and underscores");continue}let Ne=Pi().safeParse(me);if(Ne.success){L[ce]=Ne.data;continue}let Fe=Ne.error.issues[0];A(ce,Fe?[Fe.path.join("."),Fe.message].filter(Boolean).join(": "):"failed validation")}return L}var WF=Mt(()=>Ut.object({type:Ut.literal("ws"),url:Ut.string(),headers:Ut.record(Ut.string(),Ut.string()).optional(),headersHelper:Ut.string().optional(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),bareElicitationCapability:Ut.boolean().optional(),role:ko()})),jF=Mt(()=>Ut.object({type:Ut.literal("sdk"),name:Ut.string(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),disableAutoBackground:Ut.boolean().optional().catch(void 0)})),xi=Mt(()=>Ut.enum(["allow","ask","blocked"])),$F=Mt(()=>Ut.object({type:Ut.literal("claudeai-proxy"),url:Ut.string(),id:Ut.string().regex(xF),displayName:Ut.string().optional(),iconUrl:Ut.string().optional(),timeout:Yn().optional(),alwaysLoad:Ut.boolean().optional(),toolPermissions:Ut.record(Ut.string(),xi()).optional(),stateless:Ut.boolean().optional(),cachedInitResponse:Ut.record(Ut.string(),Ut.unknown()).nullish(),discoverSupport:Ut.enum(["supported","legacy","unknown"]).optional().catch(void 0),cachedDiscoverResponse:Ut.record(Ut.string(),Ut.unknown()).nullish(),eligible:Ut.boolean().nullish(),ineligibleReason:Ut.string().nullish(),enterpriseManaged:Ut.boolean().optional()})),cs=Mt(()=>Ut.union([vF(),Yd(),MF(),UF(),Xd(),WF(),jF(),$F()]));var mZ=Mt(()=>Ut.object({mcpServers:Ut.record(Ut.string(),cs())}));import*as Mo from"zod/v4";var dr=["anthropic","customEndpoint","bedrock","vertex","foundry","anthropicAws","mantle","gateway"],VF=/^anthropic[A-Z][A-Za-z0-9]*$/,KF=new Set(dr);function Ni(c){return typeof c==="string"&&KF.has(c)}function vi(c){return Ni(c)||typeof c==="string"&&VF.test(c)}import*as Uo from"zod/v4";var SZ=C()==="macos"?"⏺":"●";var Zd=/(?<![^\s\p{P}])\p{M}+/gu;function YF(c){return Ht(ZF(We(c))).replace(/ {2,}/g," ").trim()}var XF=/\x1b\[[\x30-\x3f]*[\x20-\x2f]*[\x40-\x7e]|\x1b[\]PX^_][^\x1b\x07]*(?:\x07|\x1b\\)/g,JF=4;function ZF(c){let A=c;for(let L=0;L<JF;L++){let ce=A.replace(XF,"");if(ce===A)break;A=ce}return A}function ki(c,A=160){return qF(YF(QF(c,A)).normalize("NFC").replace(/[`\uff40\u02cb\u1fef\u2035]/g,"'").replace(Zd,""),A)}var wZ=new RegExp(`[^\\S ]|[${V}]`,"u");function qF(c,A=2000){return c.length>A?`${fe(c,A)}…`:c}function QF(c,A){let L=fe(c,A*8);if(L.length===c.length)return L;let ce=/\x1b(?:[\]PX^_][^\x1b\x07]*\x1b?|\[[\x30-\x3f]*[\x20-\x2f]*)$/.exec(L);if(ce===null)return L;let me=c.slice(ce.index);return(me[1]==="["?/^\x1b\[[\x30-\x3f]*[\x20-\x2f]*[\x40-\x7e]/.test(me):/^\x1b[\]PX^_][^\x1b\x07]*(?:\x07|\x1b\\)/.test(me))?L.slice(0,ce.index):L}var qd={Task:"Agent",KillShell:"TaskStop",KillBash:"TaskStop",ListPeers:"ListAgents",Brief:"SendUserMessage",ListMcpResources:"ListMcpResourcesTool",ReadMcpResource:"ReadMcpResourceTool",ReadMcpResourceDir:"ReadMcpResourceDirTool"};function Mi(c){return Object.hasOwn(qd,c)?qd[c]:c}var Qd="workspace",kZ=`mcp__${Qd}__bash`,MZ=`mcp__${Qd}__web_fetch`;function ds(c){return c.includes("*")}function eB(c){return c.replaceAll("\\","\\\\").replaceAll("(","\\(").replaceAll(")","\\)")}function tB(c){return nB(c).replaceAll("\\\\","\\")}function nB(c){return c.replaceAll("\\(","(").replaceAll("\\)",")")}function Ui(c){if(typeof c==="string"&&!c.includes("(")&&!c.includes(")"))return{kind:"bare"};let A=oB(c,"("),L=rB(c,")");if(A===-1&&L===-1)return{kind:"bare"};let ce=c.substring(0,A);if(A===-1||L<=A||L!==c.length-1||/[()]/.test(ce))return{kind:"malformed"};return{kind:"call",toolName:ce,rawContent:c.substring(A+1,L)}}function eu(c){let A=Ui(c);if(A.kind!=="call"||!A.toolName)return{toolName:Mi(c)};if(A.rawContent===""||A.rawContent==="*")return{toolName:Mi(A.toolName)};let L=tB(A.rawContent);return{toolName:Mi(A.toolName),ruleContent:L}}function so(c){if(!c.ruleContent)return c.toolName;let A=eB(c.ruleContent);return`${c.toolName}(${A})`}function oB(c,A){for(let L=0;L<c.length;L++)if(c[L]===A){let ce=0,me=L-1;while(me>=0&&c[me]==="\\")ce++,me--;if(ce%2===0)return L}return-1}function rB(c,A){for(let L=c.length-1;L>=0;L--)if(c[L]===A){let ce=0,me=L-1;while(me>=0&&c[me]==="\\")ce++,me--;if(ce%2===0)return L}return-1}function us(c){let A=c.split("__"),[L,ce,...me]=A;if(L!=="mcp"||!ce)return null;let Ne=me.length>0?me.join("__"):void 0;return{serverName:ce,toolName:Ne}}var sB=new Set(["Claude Preview","Claude Browser"]),iB=new Set(["claude-in-chrome","Claude in Chrome"]),e5=new Set([...iB,...sB]);var aB=["Claude_Browser__"],lB=["claude-in-chrome__","Claude_in_Chrome__"],t5=[...aB,...lB];var u5=Mt(()=>Uo.preprocess(vo,Uo.enum(Nd))),p5=Mt(()=>Uo.preprocess(vo,Uo.enum(ro)));import{posix as LB,win32 as IB}from"path";import*as mt from"zod/v4";var nu={".ts":"ts",".tsx":"tsx",".jsx":"jsx",".js":"js",".mjs":"js",".cjs":"js",".mts":"ts",".cts":"ts"};var Hi=Object.keys(nu);var uB=`${Hi.slice(0,-1).join(", ")} or `+String(Hi.at(-1));import{isIPv4 as pB,isIPv6 as fB}from"net";var mB=new Set(["metadata.google.internal","metadata.goog","metadata","instance-data","instance-data.ec2.internal","ip6-localhost","ip6-loopback","localhost.localdomain","localhost4","localhost4.localdomain4","localhost6","localhost6.localdomain6"]),ru=new Set(["100.100.100.200","168.63.129.16","192.0.0.192"]);function su(c,A,L,ce){return c===127||c===169&&A===254||c===0}function gB(c){let A=c.indexOf("%"),ce=(A>=0?c.slice(0,A):c).toLowerCase().split("::");if(ce.length>2)return;let me=ce[0]?ce[0].split(":"):[],Ne=ce.length===2&&ce[1]?ce[1].split(":"):[],Fe=ce.length===2?Ne:me,st=[],gt=Fe.at(-1);if(gt!==void 0&>.includes(".")){let It=gt.split(".").map(Number);if(It.length!==4||It.some((Lt)=>!Number.isInteger(Lt)||Lt<0||Lt>255))return;st=It,Fe.pop()}let ht=(It)=>{let Lt=[];for(let Bt of It){if(!/^[0-9a-f]{1,4}$/.test(Bt))return;let xt=parseInt(Bt,16);Lt.push(xt>>8,xt&255)}return Lt},Et=ht(ce.length===2?me:[]),Rt=ht(Fe);if(Et===void 0||Rt===void 0)return;let Tt=Et.length+Rt.length+st.length;if(Tt>16||ce.length===1&&Tt!==16)return;return[...Et,...Array(16-Tt).fill(0),...Rt,...st]}function hB(c){return iu(c)&&c[4]===0&&c[5]===1}function iu(c){return c[0]===0&&c[1]===100&&c[2]===255&&c[3]===155}function EB(c){let A=[];if(c[0]===32&&c[1]===2)A.push(c.slice(2,6));let L=c.slice(0,10).every((st)=>st===0),ce=L&&c[10]===255&&c[11]===255,me=L&&c[10]===0&&c[11]===0,Ne=iu(c)&&c.slice(4,12).every((st)=>st===0),Fe=(c[8]===0||c[8]===2)&&c[9]===0&&c[10]===94&&c[11]===254;if(ce||me||Ne||Fe)A.push(c.slice(12,16));return A}function au(c){let A=c.toLowerCase().replace(/^\[|\]$/g,"");if(A.endsWith("."))A=A.slice(0,-1);if(A===""||A==="localhost"||A.endsWith(".localhost"))return!0;if(mB.has(A))return!0;if(A.startsWith("instance-data.")&&A.endsWith(".compute.internal"))return!0;if(pB(A)){if(ru.has(A))return!0;let[ce=0,me=0,Ne=0,Fe=0]=A.split(".").map(Number);return su(ce,me,Ne,Fe)}if(!fB(A))return!1;let L=gB(A);if(L===void 0)return!0;if(hB(L))return!0;if(L.every((ce)=>ce===0))return!0;if(L.slice(0,15).every((ce)=>ce===0)&&L[15]===1)return!0;if(A==="fd00:ec2::254")return!0;if(L[0]===254&&(L[1]??0)>=128&&(L[1]??0)<=191)return!0;return EB(L).some((ce)=>{let[me=0,Ne=0,Fe=0,st=0]=ce;return su(me,Ne,Fe,st)||ru.has(`${me}.${Ne}.${Fe}.${st}`)})}var _B=/[\uD800-\uDBFF][\uDC00-\uDFFF]|[\uD800-\uDBFF]|[\uDC00-\uDFFF]/g;function SB(c){return c.replace(_B,(A)=>A.length===2?A:"")}var yB=/[\p{Cc}\p{Cf}\p{Zl}\p{Zp}\p{Default_Ignorable_Code_Point}\u2800]|(?!\u0020)\p{Zs}/gu;function lu(c){if(typeof c!=="string")return"";let A=c;for(let L=0;L<64;L++){let ce=SB(A).replace(yB,"");if(ce===A)return ce;A=ce}return""}import*as Zt from"zod/v4";var cu=["bash","powershell"];var ur=Mt(()=>Zt.string().optional().describe('Permission rule syntax to filter when this hook runs (e.g., "Bash(git *)"). Only runs if the tool call matches the pattern. Avoids spawning hooks for non-matching commands.')),du=Mt(()=>Zt.enum(["continue","block"]).optional().describe("What a failure of this hook does: it could not start (a missing script or plugin directory), timed out, exited with a code other than 0 or 2, or printed JSON that is invalid or fails validation. 'continue' (default): the failure is reported and the action goes ahead. 'block': the failure counts as exit code 2, so the action the event guards (a tool call, a permission request, a prompt) is blocked. Ignored for async hooks and on Stop, SubagentStop, TaskCompleted and TeammateIdle."));function OB(){let c=Zt.object({type:Zt.literal("command").describe("Shell command hook type"),command:Zt.string().describe("Shell command to execute"),args:Zt.array(Zt.string()).optional().describe("Argument list for exec form. When present, `command` is resolved as "+"an executable and spawned directly with these arguments — no shell. "+"Path placeholders like ${CLAUDE_PLUGIN_ROOT} are substituted per-element as plain strings, so paths with quotes, $, or backticks never reach a shell parser. When absent, `command` runs through a shell (bash on POSIX, PowerShell on Windows without Git Bash)."),if:ur(),shell:Zt.enum(cu).optional().describe("Shell interpreter. 'bash' uses your $SHELL (bash/zsh/sh); 'powershell' uses pwsh. Defaults to bash (powershell on Windows without Git Bash)."),timeout:Zt.number().positive().optional().describe("Timeout in seconds for this specific command"),onFailure:du(),statusMessage:Zt.string().optional().describe("Custom status message to display in spinner while hook runs"),once:Zt.boolean().optional().describe("If true, hook runs once and is removed after execution"),async:Zt.boolean().optional().describe("If true, hook runs in background without blocking"),asyncRewake:Zt.boolean().optional().describe("If true, hook runs in background and wakes the model on exit code 2 (blocking error). Implies async."),rewakeMessage:Zt.string().min(1).optional().describe("@internal Custom prefix for the system-reminder shown to the model when an asyncRewake hook exits with code 2. The hook output is appended after this prefix."),rewakeSummary:Zt.string().min(1).optional().describe('@internal One-line summary shown to the user in the terminal when an asyncRewake hook exits with code 2. Defaults to "Stop hook feedback".'),cloud:Zt.enum(["device","skip"]).optional().catch("skip").describe("@internal Where this hook may run when a cloud session is driven from this machine. 'device': offer it to the cloud session and run it here even when its script sits where the cloud session can write on this machine or cannot be pinned — the author accepts that the session may have changed files this hook executes. 'skip': never offer it to cloud sessions. Omit for the default: a command hook whose script could be read and pinned and lies outside everything the cloud session can write here is offered; other command hooks are not. Applies to this entry only: the same hook written in another settings scope keeps its own setting. An unrecognised value reads as 'skip' (the file still loads; the hook stays on this machine).")}),A=Zt.object({type:Zt.literal("prompt").describe("LLM prompt hook type"),prompt:Zt.string().describe("Prompt to evaluate with LLM. Use $ARGUMENTS placeholder for hook input JSON."),if:ur(),timeout:Zt.number().positive().optional().describe("Timeout in seconds for this specific prompt evaluation"),model:Zt.string().optional().describe('Model to use for this prompt hook (e.g., "claude-sonnet-5"). If not specified, uses the default small fast model.'),continueOnBlock:Zt.boolean().optional().describe(`Sets the continue value for the decision:"block" produced when ok is false. Default false (turn ends). Whether continue:true lets the turn proceed depends on the event's decision:"block" semantics. On PostToolUse, the reason is fed back to Claude and the turn continues.`),statusMessage:Zt.string().optional().describe("Custom status message to display in spinner while hook runs"),once:Zt.boolean().optional().describe("If true, hook runs once and is removed after execution")}),L=Zt.object({type:Zt.literal("mcp_tool").describe("MCP tool hook type"),server:Zt.string().describe("Name of an already-configured MCP server to invoke"),tool:Zt.string().describe("Name of the tool on that server to call"),input:Zt.record(Zt.string(),Zt.unknown()).optional().describe('Arguments passed to the MCP tool. String values support ${path} interpolation from the hook input JSON (e.g. "${tool_input.file_path}").'),if:ur(),timeout:Zt.number().positive().optional().describe("Timeout in seconds for this specific tool call"),statusMessage:Zt.string().optional().describe("Custom status message to display in spinner while hook runs"),once:Zt.boolean().optional().describe("If true, hook runs once and is removed after execution")}),ce=Zt.object({type:Zt.literal("http").describe("HTTP hook type"),url:Zt.string().url().describe("URL to POST the hook input JSON to"),if:ur(),timeout:Zt.number().positive().optional().describe("Timeout in seconds for this specific request"),onFailure:du(),headers:Zt.record(Zt.string(),Zt.string()).optional().describe('Additional headers to include in the request. Values may reference environment variables using $VAR_NAME or ${VAR_NAME} syntax (e.g., "Authorization": "Bearer $MY_TOKEN"). Only variables listed in allowedEnvVars will be interpolated.'),allowedEnvVars:Zt.array(Zt.string()).optional().describe("Explicit list of environment variable names that may be interpolated in header values. Only variables listed here will be resolved; all other $VAR references are left as empty strings. Required for env var interpolation to work."),statusMessage:Zt.string().optional().describe("Custom status message to display in spinner while hook runs"),once:Zt.boolean().optional().describe("If true, hook runs once and is removed after execution"),cloud:Zt.enum(["device","skip"]).optional().catch("skip").describe("@internal Where this hook may run when a cloud session is driven from this machine. 'skip': never offer it to cloud sessions; 'device' or omitted: offered (an HTTP hook has no script to pin). Applies to this entry only. An unrecognised value reads as 'skip' (the file still loads).")}),me=Zt.object({type:Zt.literal("agent").describe("Agentic verifier hook type"),prompt:Zt.string().describe('Prompt describing what to verify (e.g. "Verify that unit tests ran and passed."). Use $ARGUMENTS placeholder for hook input JSON.'),if:ur(),timeout:Zt.number().positive().optional().describe("Timeout in seconds for agent execution (default 60)"),model:Zt.string().optional().describe('Model to use for this agent hook (e.g., "claude-sonnet-5"). If not specified, uses Haiku.'),statusMessage:Zt.string().optional().describe("Custom status message to display in spinner while hook runs"),once:Zt.boolean().optional().describe("If true, hook runs once and is removed after execution")});return{BashCommandHookSchema:c,PromptHookSchema:A,HttpHookSchema:ce,AgentHookSchema:me,McpToolHookSchema:L}}var ps=Mt(()=>{let{BashCommandHookSchema:c,PromptHookSchema:A,AgentHookSchema:L,HttpHookSchema:ce,McpToolHookSchema:me}=OB();return Zt.discriminatedUnion("type",[...[c,A,L,ce,me]])}),zi=Mt(()=>Zt.object({matcher:Zt.string().optional().describe('String pattern to match (e.g. tool names like "Write")'),hooks:Zt.array(ps()).describe("List of hooks to execute when the matcher matches")})),lo=Mt(()=>Zt.partialRecord(Zt.enum(G),Zt.array(zi())));function fs(){return new Set(ps().options.map((c)=>c.shape.type.value))}function AB(c,A){if(!c||typeof c!=="object"||Array.isArray(c)){let me=io(c);return{problem:`Hook entry must be an object; received ${me}`,received:me,aboutType:!1}}let L=c.type;if(typeof L!=="string"){let me=io(L);return{problem:L===void 0?'Hook entry has no "type"':`Hook entry "type" must be a string; received ${me}`,received:me,aboutType:!0}}if(!A.has(L)){let me=ot(L);return{problem:`Unknown hook type "${me}"`,received:me,aboutType:!0}}let ce=ps().safeParse(c);if(!ce.success)return{problem:`Invalid ${L} hook (${uu(ce.error)})`,received:L,aboutType:!1};return}function uu(c){return c.issues.map((A)=>A.path.length>0?`${A.path.join(".")}: ${A.message}`:A.message).join("; ")}function ms(c){if(!c||typeof c!=="object"||Array.isArray(c))return!1;if(!("matcher"in c)&&Object.keys(c).some((L)=>G.includes(L)))return!1;let A=c.hooks;if(Array.isArray(A))return A.length>0;return!!A&&typeof A==="object"&&(("matcher"in c)||typeof A.type==="string")}function ao(c,A=3,{matchersCount:L=!0,unscannedKeys:ce=bB,inHooksList:me=!1}={}){if(mu(c))return!0;if(L&&ms(c))return!0;if(A===0||!c||typeof c!=="object")return!1;if(Array.isArray(c))return c.some((Ne)=>ao(Ne,A-1,{matchersCount:L,unscannedKeys:ce,inHooksList:me}));if(me&&typeof c.type==="string")return!1;return Object.entries(c).some(([Ne,Fe])=>!ce.has(Ne)&&ao(Fe,A-1,{unscannedKeys:ce,matchersCount:L&&!G.includes(Ne),inHooksList:Ne==="hooks"&&Array.isArray(Fe)}))}function pu(c,A){if(!c||typeof c!=="object"||Array.isArray(c))return!1;return mu(c)||Object.entries(c).some(([L,ce])=>L!=="hooks"&&!A.has(L)&&ao(ce,3,{unscannedKeys:A,matchersCount:!G.includes(L)}))}var bB=new Set,fu=new Set(["mcpServers","managedMcpServers","lspServers","pluginConfigs","enabledPlugins","extraKnownMarketplaces","env","skillOverrides","modelSettings"]),CB=new Set(["metadata","mcpServers","lspServers"]),x5=new Set([...CB,"experimental"]);function mu(c){if(!c||typeof c!=="object"||Array.isArray(c))return!1;return Object.entries(c).some(([A,L])=>pr.has(A)&&L!==null&&L!==void 0&&!(Array.isArray(L)&&L.length===0))}function Fi(c){if(ms(c))return!0;if(Array.isArray(c))return c.some(Fi);if(!c||typeof c!=="object")return!1;return Object.entries(c).some(([A,L])=>pr.has(A)&&L!==null&&L!==void 0&&!(Array.isArray(L)&&L.length===0))}var pr=new Set(["PreToolUse","PermissionRequest"]);function gu(c,A){if(!Array.isArray(c))return{stripped:[],unloadableGuards:[]};let L=pr.has(A),ce=fs(),me=zi(),Ne=[],Fe=[];for(let st=c.length-1;st>=0;st--){let gt=c[st],ht=(It,Lt)=>{if(!L)c.splice(st,1);Ne.push({matcherIndex:st,hookIndex:void 0,path:`${st}`,problem:It,received:Lt,aboutType:!1})};if(ao(gt,3,{matchersCount:!1})){(L?Ne:Fe).push({matcherIndex:st,hookIndex:void 0,path:`${st}`,problem:"holds PreToolUse/PermissionRequest hooks where a matcher was expected",received:io(gt),aboutType:!1});continue}if(!gt||typeof gt!=="object"||Array.isArray(gt)){ht(`Hook matcher must be an object; received ${io(gt)}`,io(gt));continue}let Et=gt.hooks;if(!Array.isArray(Et)){ht(`Hook matcher "hooks" must be an array of hook entries; received ${io(Et)}`,io(Et));continue}let Rt=[];for(let It=Et.length-1;It>=0;It--){let Lt=AB(Et[It],ce);if(Lt!==void 0){if(!L)Et.splice(It,1);Rt.push({matcherIndex:st,hookIndex:It,path:`${st}.hooks.${It}`,...Lt})}}let Tt=me.safeParse(L?{...gt,hooks:[]}:gt);if(!Tt.success){ht(`Invalid hook matcher (${uu(Tt.error)})`,"matcher");continue}Ne.push(...Rt)}return Ne.reverse(),Fe.reverse(),L?{stripped:[],unloadableGuards:Ne}:{stripped:Ne,unloadableGuards:Fe}}var co="a PreToolUse/PermissionRequest hook that cannot be loaded may be what guards the permissions declared beside it, so nothing it sits in is applied until the entry is fixed or removed";function io(c){if(c===null||c===void 0)return String(c);if(Array.isArray(c))return"an array";let A=typeof c;return`${A==="object"?"an":"a"} ${A}`}var hu=new Set(["http","https","ws","wss","ftp"]);function uo(c){c=c.replace(/^[\x00-\x20]+/,"").replace(/[\t\n\r]/g,"");let A=c.indexOf("://");if(A===-1)return!1;let L=c.slice(A+3),ce=c.slice(0,A).toLowerCase();if(hu.has(ce)){let Fe=L.match(/^[/\\]+/)?.[0]??"";if(Fe.includes("\\"))return!0;L=L.slice(Fe.length)}let me=L.search(/[/?#]/);return(me===-1?L:L.slice(0,me)).includes("\\")}var An="github.com",H5=[`git@${An}:`,`ssh://git@${An}/`],z5=[`https://${An}`,`https://${An}/`,An],F5=`users.noreply.${An}`;var TB=/[:/\\?#@\s]/;function fr(c){let A=_u(c.replace(/[\t\n\r]/g,"").toLowerCase());if(A===""||TB.test(A))return A;try{let L=new URL(`https://${A}`);if(L.username!==""||L.password!==""||L.port!==""||L.pathname!=="/"||L.search!==""||L.hash!=="")return A;return _u(L.hostname)}catch{return A}}var Su=Gr(function(A){let L=fr(A);while(L.startsWith("www."))L=L.slice(4);return L},(c)=>c,50);function yu(c,A){return Su(c)===A}function Xn(c){return yu(c,An)}function Eu(c){return/[%\x00-\x1f\x7f-\u{10FFFF}]/u.test(c)}function Bi(c){if(Le(c))return!0;if(c.includes("://")){if(uo(c))return!0;try{let me=new URL(c);if(me.protocol==="http:"||me.protocol==="https:")return!1;return Eu(me.hostname)}catch{return!0}}let A=c.indexOf(":"),L=c.indexOf("@");if(A>=0&&L>A)return!0;let ce=c.match(/^(?:[^@]+@)?([^:]+):/)?.[1];return ce?Eu(ce):!1}function _u(c){let A=c.length;while(A>0&&c[A-1]===".")A--;return c.slice(0,A)}function Gi(c){let A=fr(c);return Xn(A)?An:A}function Ou(c){let A=c.trimStart(),L=/^([A-Za-z][A-Za-z0-9+.-]*):\/\//.exec(A);if(L===null||/^https?$/i.test(L[1]??""))return Q(A);return Q(L[0]+$e(A.slice(L[0].length)))}function Au(c){let A=/^([^@:/[\]]+)@([^@:/[\]]+):(.*)$/s.exec(c);return A&&!Le(c)?{user:A[1],host:A[2],path:A[3]}:null}var bu=600;var Xi=500,PB=32;function wu(){return{claudeaiPluginId:mt.string().max(128).optional().catch(void 0),archiveSha256:np().optional().catch(void 0)}}function xu(){return{directoryRepositoryKey:mt.string().max(4096).optional().catch(void 0)}}function Ji(c){if(!/^https?:\/\/[^/\\]/i.test(c))return!1;try{let{protocol:A}=new URL(c);return A==="https:"||A==="http:"}catch{return!1}}function Nu(){return{npmVersionSpec:mt.string().max(256).optional().catch(void 0),npmResolved:mt.string().max(2048).optional().catch(void 0),npmIntegrity:mt.string().max(256).optional().catch(void 0),npmRegistry:mt.string().max(2048).refine(Ji).optional().catch(void 0)}}function vu(){return{sourceCommand:mt.string().max(Xi+20).optional().catch(void 0).describe("The `command`-source command the user accepted at explicit install/update. The once-per-session background re-resolve only runs while the marketplace entry still declares this exact command; a changed command (or an entry that became command-sourced later) is skipped with a warning until the user runs an explicit update."),sourceProducerPath:mt.string().max(4096).refine(Cu,{message:"must be an absolute path"}).optional().catch(void 0).describe("The directory a `command`-source plugin was last resolved to (what its command printed). Served in place in link mode and re-copied every session in copy mode, so the sandbox write-denies it; refreshed on every install/update, including no-op updates that resolve to a new location."),previousProducerPaths:mt.array(mt.unknown()).transform((c)=>c.filter((A)=>typeof A==="string"&&A.length<=4096&&Cu(A)).slice(-PB)).optional().catch(void 0).describe("Producer directories this installation was resolved to before the current one (most recent last, bounded). A concurrent older session may still serve one of them, so the sandbox keeps write-denying them too.")}}function Cu(c){return LB.isAbsolute(c)||IB.isAbsolute(c)}var ku=/[^\x20-\x7E]| {4,}/;function Zi(){return mt.string().max(Xi,{message:"headersHelper must not be longer than the install consent UI can display"}).refine((c)=>!ku.test(c),{message:"headersHelper must be printable ASCII (letters, digits, punctuation, single spaces) with no runs of 4 or more spaces"})}var wB="anthropic-plugin-directory",xB=["healthcare"],NB=new Set(["claude-community","claude-plugins-community",...xB]),vB=new Set(["claude-code-marketplace","claude-code-plugins","claude-plugins-official","anthropic-marketplace","anthropic-plugins","agent-skills","anthropic-agent-skills","life-sciences","knowledge-work-plugins","claude-for-legal","claude-for-financial-services","financial-services-plugins","first-party-plugins","claude-tag-plugins"]),kB=new Set([wB,"claude-plugin-directory"]),qi=new Set([...vB,...NB,...kB]);var Mu=["marketplace","plugins","official"];function MB(){return Mu}var Uu="official[^a-z0-9]*(anthropic|claude)|(?:anthropic|claude)[^a-z0-9]*official",I3=new RegExp(Uu,"i");function Hu(c){return new RegExp(`(?:${Uu}|^(?:anthropic|claude)[^a-z0-9]*(${c.join("|")}))`,"i")}var UB=Hu(MB()),HB=Hu(Mu),zB=/[^\u0020-\u007E]/;function zu(c){if(qi.has(c.toLowerCase()))return!1;if(FB(c))return!0;if(UB.test(c))return!0;return!1}function FB(c){return!qi.has(c.toLowerCase())&&(zB.test(c)||HB.test(c))}var bn=Mt(()=>mt.string().startsWith("./")),po=Mt(()=>bn().endsWith(".json")),Tu=Mt(()=>mt.union([mt.literal("."),bn()])),Ru=Mt(()=>mt.union([bn().refine((c)=>c.endsWith(".mcpb")||c.endsWith(".dxt"),{message:"MCPB file path must end with .mcpb or .dxt"}).describe("Path to MCPB file relative to plugin root"),mt.string().url().refine((c)=>c.endsWith(".mcpb")||c.endsWith(".dxt"),{message:"MCPB URL must end with .mcpb or .dxt"}).describe("URL to MCPB file")])),$i=Mt(()=>bn().endsWith(".md")),Vi=Mt(()=>mt.union([$i(),bn()])),Qi={inline:"--plugin-dir session plugins",builtin:"built-in plugins","skills-dir":"plugins auto-loaded from .claude/skills/",synced:"plugins synced from your claude.ai account","claude-plugin-test":"plugins loaded by claude plugin test",npm:"plugins installed from an npm registry (`<package>@npm`); remove this marketplace and add it again under another name",pip:"plugins installed from a Python package index (reserved; not yet available)",uv:"plugins installed from a Python package index through uv (reserved; not yet available)",cargo:"plugins installed from a Rust crate registry (reserved; not yet available)",github:"plugins installed straight from a GitHub repository (`<owner>/<repo>@github`; reserved; not yet available)",gh:"plugins installed straight from a GitHub repository (reserved; not yet available)"},Fu="npm",BB=["pip","uv","cargo","github","gh"];function Bu(c){return Object.hasOwn(Qi,c)}var GB=[Fu,...BB];function Gu(c){return GB.includes(c.toLowerCase())}function WB(c,A){let L=c.toLowerCase();if(Gu(L)&&Bu(L))A.addIssue({code:"custom",message:`Marketplace name "${L}" is reserved for ${Qi[L]}`})}var jB="Marketplace name impersonates an official Anthropic/Claude marketplace",ea=(c)=>mt.string().min(1,"Marketplace must have a name").refine((A)=>!A.includes(" "),{message:'Marketplace name cannot contain spaces. Use kebab-case (e.g., "my-marketplace")'}).refine((A)=>!sp.test(A),{message:"Marketplace name cannot contain control or bidirectional-formatting characters"}).refine((A)=>!A.includes("/")&&!A.includes("\\")&&!A.includes("..")&&A!==".",{message:'Marketplace name cannot contain path separators (/ or \\), ".." sequences, or be "."'}).refine((A)=>!c(A),{message:jB}).superRefine((A,L)=>{let ce=A.toLowerCase();if(!Bu(ce)||Gu(ce))return;L.addIssue({code:"custom",message:`Marketplace name "${ce}" is reserved for ${Qi[ce]}`})}),$B=Mt(()=>ea(zu)),VB=Mt(()=>ea(()=>!1));function KB(c){return ea(c).superRefine(WB)}var gs=Mt(()=>mt.string().min(1,"Plugin name cannot be empty").refine((c)=>!c.includes(" "),{message:'Plugin name cannot contain spaces. Use kebab-case (e.g., "my-plugin")'}).refine((c)=>!sp.test(c),{message:"Plugin name cannot contain control or bidirectional-formatting characters"})),ta=Mt(()=>mt.object({name:mt.string().min(1,"Author name cannot be empty").describe("Display name of the plugin author or organization"),email:mt.string().optional().describe("Contact email for support or feedback"),url:mt.string().optional().describe("Website, GitHub profile, or organization URL")})),YB=Mt(()=>mt.object({$schema:mt.string().optional().describe("JSON Schema reference for editor autocomplete/validation; ignored at load time"),name:gs().describe("Unique identifier for the plugin, used for namespacing (prefer kebab-case)"),displayName:mt.string().optional().describe('Human-readable name shown in UI (e.g., "GitHub Utils"). Falls back to `name` when omitted. Unlike `name`, may contain spaces and any casing; not used for namespacing or lookup.'),version:mt.string().optional().describe("Semantic version (e.g., 1.2.3) following semver.org specification"),description:mt.string().optional().describe("Brief, user-facing explanation of what the plugin provides"),author:ta().optional().describe("Information about the plugin creator or maintainer"),homepage:mt.string().url().optional().describe("Plugin homepage or documentation URL"),repository:mt.string().optional().describe("Source code repository URL"),license:mt.string().optional().describe("SPDX license identifier (e.g., MIT, Apache-2.0)"),keywords:mt.array(mt.string()).optional().describe("Tags for plugin discovery and categorization"),defaultEnabled:mt.boolean().optional().describe("Whether the plugin starts enabled when the user has no explicit enabled/disabled setting for it (default: true). Explicit enabledPlugins values always win, and a plugin required by an enabled dependent is enabled regardless of this value."),dependencies:mt.array(sG()).optional().describe(`Plugins that must be enabled for this plugin to function. Bare names (no "@marketplace") are resolved against the declaring plugin's own marketplace.`),metadata:mt.preprocess((c)=>r(c)?c:void 0,mt.record(mt.string(),mt.unknown()).optional()).describe("Free-form metadata for the plugin author's own use (e.g. entitlement or catalog fields). Preserved on the parsed manifest but not read by Claude Code.")})),XB=1,P3=Mt(()=>mt.object({$schema:mt.string().optional().catch(void 0).describe("JSON Schema reference for editor autocomplete/validation; ignored at load time"),description:mt.string().optional().describe("Brief, user-facing explanation of what these hooks provide"),hooks:mt.lazy(()=>lo()).optional().describe("The hooks provided by the plugin, in the same format as the one used for settings"),modules:mt.array(mt.string()).max(XB,{message:"hooks.json `modules` names one hooks module per plugin; a second entry is refused"}).optional().describe(`The hooks module: one path, relative to this hooks.json, of a module exporting register(on). The module, and every file it imports from the plugin, is named like code (${uB}; a file named otherwise is not loaded) and is an ES module whatever its suffix. What it hooks and calls is read from its source before it loads; \`claude plugin validate\` shows the result.`),surface:mt.never({error:'hooks.json `surface` is gone: name the module in the Client element, `Client({ module: "./board.tsx", key })`, a path relative to the file that builds it'}).optional()}).refine((c)=>c.hooks!==void 0||(c.modules?.length??0)>0,{message:"hooks.json must have `hooks` (the hook matchers) or `modules` (hooks modules), or both"})),JB=Mt(()=>mt.object({hooks:mt.union([po().describe("Path to file with additional hooks (in addition to those in hooks/hooks.json, if it exists), relative to the plugin root"),mt.lazy(()=>lo()).describe("Additional hooks (in addition to those in hooks/hooks.json, if it exists)"),mt.array(mt.union([po().describe("Path to file with additional hooks (in addition to those in hooks/hooks.json, if it exists), relative to the plugin root"),mt.lazy(()=>lo()).describe("Additional hooks (in addition to those in hooks/hooks.json, if it exists)")]))])})),ZB=Mt(()=>mt.object({source:Vi().optional().describe("Path to command markdown file, relative to plugin root"),content:mt.string().optional().describe("Inline markdown content for the command"),description:mt.string().optional().describe("Command description override"),argumentHint:mt.string().optional().describe('Hint for command arguments (e.g., "[file]")'),model:mt.string().optional().describe("Default model for this command"),allowedTools:mt.array(mt.string()).optional().describe("Tools allowed when command runs")}).refine((c)=>c.source&&!c.content||!c.source&&c.content,{message:'Command must have either "source" (file path) or "content" (inline markdown), but not both'})),qB=Mt(()=>mt.object({commands:mt.union([Vi().describe("Path to a command file or skill directory, relative to the plugin root. When set, the commands/ directory is not auto-loaded — list its files here if you want both."),mt.array(Vi().describe("Path to a command file or skill directory, relative to the plugin root. When set, the commands/ directory is not auto-loaded — list its files here if you want both.")).describe("List of command file or skill directory paths. When set, the commands/ directory is not auto-loaded."),mt.record(mt.string(),ZB()).describe('Object mapping of command names to their metadata and source files. Command name becomes the slash command name (e.g., "about" → "/plugin:about")')])})),QB=Mt(()=>mt.object({agents:mt.union([$i().describe("Path to an agent file, relative to the plugin root. When set, the agents/ directory is not auto-loaded — list its files here if you want both."),mt.array($i().describe("Path to an agent file, relative to the plugin root. When set, the agents/ directory is not auto-loaded — list its files here if you want both.")).describe("List of agent file paths. When set, the agents/ directory is not auto-loaded.")])})),e0=Mt(()=>mt.object({skills:mt.union([Tu().describe('Path to a skill directory, relative to the plugin root ("." / "./" denote the plugin root itself). Loaded in addition to the skills/ directory (except: for a marketplace entry whose source resolves to the marketplace root, declaring a specific subdirectory replaces the skills/ scan).'),mt.array(Tu().describe('Path to a skill directory, relative to the plugin root ("." / "./" denote the plugin root itself).')).describe("List of skill directory paths, loaded in addition to the skills/ directory (except: for a marketplace entry whose source resolves to the marketplace root, declaring specific subdirectories replaces the skills/ scan).")])})),t0=Mt(()=>mt.union([mt.string(),mt.array(mt.string())])),Wu=Mt(()=>mt.object({outputStyles:mt.union([bn().describe("Path to an output-styles directory or file, relative to the plugin root. When set, the output-styles/ directory is not auto-loaded — list its files here if you want both."),mt.array(bn().describe("Path to an output-styles directory or file, relative to the plugin root. When set, the output-styles/ directory is not auto-loaded — list its files here if you want both.")).describe("List of output-style directory or file paths. When set, the output-styles/ directory is not auto-loaded.")])})),n0=Mt(()=>mt.string().max(64).regex(/^[a-z][a-z0-9_-]*$/,"must match ^[a-z][a-z0-9_-]*$")),o0=16,r0=Mt(()=>mt.object({id:n0(),remote:mt.string().max(256).regex(/^(npm:[@a-z0-9/._-]+(@[a-z0-9._+-]+)?|github:[\w.-]+\/[\w.-]+@[\w./-]+#.+\.js)$/,"must be npm:<pkg>[@ver] or github:<owner>/<repo>@<ref>#<path>.js").optional(),integrity:mt.string().max(512).regex(/^sha(256|384|512)-[A-Za-z0-9+/=]+$/,"must be SRI form: sha256-, sha384-, or sha512-<base64>").optional()}).strict()),s0=Mt(()=>mt.object({syntaxHighlighting:mt.object({hljsLanguages:mt.array(r0()).max(o0)}).strict()})),ju=Mt(()=>mt.object({themes:mt.union([bn().describe("Path to a themes directory or file, relative to the plugin root. When set, the themes/ directory is not auto-loaded — list its files here if you want both."),mt.array(bn().describe("Path to a themes directory or file, relative to the plugin root. When set, the themes/ directory is not auto-loaded — list its files here if you want both.")).describe("List of theme directory or file paths. When set, the themes/ directory is not auto-loaded.")])})),i0=Mt(()=>mt.object({workflows:mt.union([bn().describe("Path to a workflows directory or .js file, relative to the plugin root. When set, the workflows/ directory is not auto-loaded — list its files here if you want both."),mt.array(bn().describe("Path to a workflows directory or .js file, relative to the plugin root. When set, the workflows/ directory is not auto-loaded — list its files here if you want both.")).describe("List of workflow directory or .js file paths. When set, the workflows/ directory is not auto-loaded.")]).optional()})),Du=Mt(()=>mt.string().min(1)),a0=Mt(()=>mt.string().min(2).refine((c)=>c.startsWith("."),{message:'File extensions must start with dot (e.g., ".ts", not "ts")'})),l0=Mt(()=>mt.object({mcpServers:mt.union([po().describe("MCP servers to include in the plugin (in addition to those in the .mcp.json file, if it exists)"),Ru().describe("Path or URL to MCPB file containing MCP server configuration"),mt.record(mt.string(),cs()).describe("MCP server configurations keyed by server name"),mt.array(mt.union([po().describe("Path to MCP servers configuration file"),Ru().describe("Path or URL to MCPB file"),mt.record(mt.string(),cs()).describe("Inline MCP server configurations")])).describe("Array of MCP server configurations (paths, MCPB files, or inline definitions)")])})),$u=Mt(()=>mt.object({type:mt.enum(["string","number","boolean","directory","file"]).describe("Type of the configuration value"),title:mt.string().describe("Human-readable label shown in the config dialog"),description:mt.string().describe("Help text shown beneath the field in the config dialog"),required:mt.boolean().optional().describe("If true, validation fails when this field is empty"),default:mt.union([mt.string(),mt.number(),mt.boolean(),mt.array(mt.string())]).optional().describe("Default value used when the user provides nothing"),multiple:mt.boolean().optional().describe("For string type: allow an array of strings"),sensitive:mt.boolean().optional().describe("If true, masks dialog input and stores value in secure storage (keychain/credentials file) instead of settings.json"),min:mt.number().optional().describe("Minimum value (number type only)"),max:mt.number().optional().describe("Maximum value (number type only)"),options:mt.array(mt.string().min(1,"An option cannot be empty").max(64,"An option can be at most 64 characters").refine((c)=>lu(c)===c,{message:"An option cannot contain control, invisible or bidirectional-formatting characters"}).refine((c)=>c.trim()===c,{message:"An option cannot start or end with a space"})).min(1,"options needs at least one value").refine((c)=>new Set(c.map((A)=>A.toLowerCase())).size===c.length,{message:"options cannot repeat a value (in any letter case)"}).readonly().optional().describe("For string type: the only values the field takes. /config shows the field as a picker over them, and a stored value outside them counts as unset")}).strict().superRefine((c,A)=>{if(c.options===void 0)return;if(c.type!=="string"||c.multiple===!0||c.sensitive===!0){A.addIssue({code:"custom",path:["options"],message:'options is only for a field of type "string" that is neither multiple nor sensitive'});return}if(c.default===void 0){if(c.required!==!0)A.addIssue({code:"custom",path:["default"],message:"a field with options needs a default among them, or required: true"});return}if(typeof c.default!=="string"||!c.options.includes(c.default))A.addIssue({code:"custom",path:["default"],message:`default must be one of the options: ${c.options.join(", ")}`})})),c0=Mt(()=>mt.object({userConfig:mt.record(mt.string().regex(/^[A-Za-z_]\w*$/,"Option keys must be valid identifiers (letters, digits, underscore; no leading digit) — they become CLAUDE_PLUGIN_OPTION_<KEY> env vars in hooks"),$u()).optional().describe("User-configurable values this plugin needs. Prompted at enable time. Non-sensitive values saved to settings.json; sensitive values to secure storage. Available as ${user_config.KEY} in MCP/LSP server config, hook commands, and (non-sensitive only) skill/agent content. Keep sensitive value counts small.")})),d0=Mt(()=>mt.object({channels:mt.array(mt.object({server:mt.string().min(1).describe("Name of the MCP server this channel binds to. Must match a key in this plugin's mcpServers."),displayName:mt.string().optional().describe('Human-readable name shown in the config dialog title (e.g., "Telegram"). Defaults to the server name.'),userConfig:mt.record(mt.string(),$u()).optional().describe("Fields to prompt the user for when enabling this plugin in assistant mode. Saved values are substituted into ${user_config.KEY} references in the mcpServers env.")}).strict()).describe("Channels this plugin provides. Each entry declares an MCP server as a message channel and optionally specifies user configuration to prompt for at enable time.")})),Lu=Mt(()=>mt.strictObject({command:mt.string().min(1).refine((c)=>{if(c.includes(" ")&&!c.startsWith("/"))return!1;return!0},{message:"Command should not contain spaces. Use args array for arguments."}).describe('Command to execute the LSP server (e.g., "typescript-language-server")'),args:mt.array(Du()).optional().describe("Command-line arguments to pass to the server"),extensionToLanguage:mt.record(a0(),Du()).refine((c)=>Object.keys(c).length>0,{message:"extensionToLanguage must have at least one mapping"}).describe("Mapping from file extension to LSP language ID. File extensions and languages are derived from this mapping."),transport:mt.enum(["stdio","socket"]).default("stdio").describe("Communication transport mechanism"),env:mt.record(mt.string(),mt.string()).optional().describe("Environment variables to set when starting the server"),initializationOptions:mt.unknown().optional().describe("Initialization options passed to the server during initialization"),settings:mt.unknown().optional().describe("Settings passed to the server via workspace/didChangeConfiguration"),workspaceFolder:mt.string().optional().describe("Workspace folder path to use for the server"),startupTimeout:mt.number().int().positive().optional().describe("Maximum time to wait for server startup (milliseconds)"),shutdownTimeout:mt.number().int().positive().optional().describe("Maximum time to wait for graceful shutdown (milliseconds)"),requestTimeout:mt.number().int().positive().max(2147483647).optional().describe("Maximum time to wait for the server to answer a request (milliseconds). Defaults to 60000."),restartOnCrash:mt.boolean().optional().describe("Whether to restart the server if it crashes"),maxRestarts:mt.number().int().nonnegative().optional().describe("Maximum number of restart attempts before giving up"),diagnostics:mt.boolean().optional().describe("Whether to push publishDiagnostics into the agent context after edits. Set to false to keep LSP navigation (goToDefinition, hover, etc.) but suppress automatic diagnostic injection. Defaults to true.")})),u0=Mt(()=>mt.strictObject({name:mt.string().min(1).describe("Identifier for this monitor, unique within the plugin. Used to dedupe so re-arming (plugin reload, repeat skill invoke) does not spawn duplicates."),command:mt.string().min(1).describe('Shell command to run as a persistent background monitor. Each stdout line is delivered to the model as a <task_notification> event; the process runs for the session lifetime. ${CLAUDE_PLUGIN_ROOT}, ${CLAUDE_PLUGIN_DATA}, ${CLAUDE_PROJECT_DIR}, ${user_config.*}, and ${ENV_VAR} are substituted. Runs in the session cwd (the named --project-config-root when a host set one) — prefix with `cd "${CLAUDE_PLUGIN_ROOT}" && ` if the script needs its own directory.'),description:mt.string().min(1).describe("Short human-readable description of what is being monitored (shown in task panel and notification summary)."),when:mt.union([mt.literal("always"),mt.string().startsWith("on-skill-invoke:").refine((c)=>c.length>16,{message:"on-skill-invoke: must specify a skill name"})]).default("always").describe('Arm trigger. "always" arms at session start and on plugin reload. "on-skill-invoke:<skill>" arms the first time that skill is dispatched (via Skill tool or slash command).')})),p0=Mt(()=>mt.array(u0()).refine((c)=>new Set(c.map((A)=>A.name)).size===c.length,{message:"Monitor names must be unique within a plugin"})),Vu=Mt(()=>mt.object({monitors:mt.union([po().describe("Path to a JSON file containing the monitors array, relative to the plugin root"),p0()]).describe("Background watch scripts the host arms as persistent Monitor tasks (unsandboxed, same trust tier as hooks) so plugins need not instruct the model to arm them. When omitted, monitors/monitors.json at the plugin root is loaded if present.")})),f0=Mt(()=>mt.object({lspServers:mt.union([po().describe("Path to .lsp.json configuration file relative to plugin root"),mt.record(mt.string(),Lu()).describe("LSP server configurations keyed by server name"),mt.array(mt.union([po().describe("Path to LSP configuration file"),mt.record(mt.string(),Lu()).describe("Inline LSP server configurations")])).describe("Array of LSP server configurations (paths or inline definitions)")])})),m0=/^@[a-z0-9][a-z0-9-._]*\/[a-z0-9][a-z0-9-._]*$/,g0=/^[a-z0-9][a-z0-9-._]*$/,h0=/^@[a-z0-9][a-z0-9-._]*\/\*$/;function Ku(c){return!c.includes("..")&&!c.includes("//")&&(m0.test(c)||g0.test(c))}var Yu=Mt(()=>mt.string().refine((c)=>!c.includes("..")&&!c.includes("//"),"Package name cannot contain path traversal patterns").refine((c)=>Ku(c),"Invalid npm package name format")),E0=/^[a-z0-9](?:[a-z0-9._-]*[a-z0-9_-])?$/,_0=/^[0-9a-f]{64}$/;var S0=64;var y0=Mt(()=>mt.object({sha256:mt.string().regex(_0)}));function O0(c){let A=mt.record(mt.string(),mt.unknown()).safeParse(c);if(!A.success)return;let L=Object.create(null),ce=0;for(let[me,Ne]of Object.entries(A.data)){if(ce>=S0)break;let Fe=y0().safeParse(Ne);if(E0.test(me)&&Fe.success)L[me]=Fe.data,ce++}return ce>0?L:void 0}var A0=Mt(()=>mt.object({binaries:mt.unknown().transform(O0).describe("sha256-pinned files to fetch into bin/ at install time, keyed by basename (target triple encoded in the name)")})),b0=Mt(()=>mt.object({settings:mt.record(mt.string(),mt.unknown()).optional().describe("Settings to merge into the user settings while this plugin is enabled. Only the documented allowlisted keys are applied.")})),C0=Mt(()=>mt.object({types:bn().refine((c)=>c.endsWith(".d.ts"),{message:"types must name a TypeScript declaration file ending in '.d.ts'"}).refine((c)=>!c.split(/[\\/]/).includes(".."),{message:"types must stay inside the plugin directory (no '..' segment)"}).optional().describe("Path to the plugin's type contract, relative to the plugin root and starting with ./: a self-contained .d.ts (no import, export-from, require or reference) that exports the types of the noun the plugin's hooks module adds in engine.create at its top level and declares the noun in a `declare module 'claude-code' { interface EngineInterface { ... } }` block, nothing else. A mod that lists this plugin under dependencies gets the contract laid at .claude-plugin/types/<plugin>/index.d.ts each time the engine loads it from a folder the person owns, so it types against the noun with nothing copied; claude plugin validate checks the file.")})),T0=Mt(()=>mt.object({experimental:mt.preprocess((c)=>r(c)?c:void 0,mt.object({...ju().partial().shape,...s0().partial().shape,...Vu().partial().shape,...Wu().partial().shape,evals:t0().optional().describe("Directory of eval cases for the plugin evaluation harness, relative to the plugin root (default: evals/). A list is accepted; its first entry is the case directory.")}).passthrough().optional().describe("Components whose manifest shape may change without a deprecation cycle. Move a key out of here once it is promoted to stable."))}));var R0=Mt(()=>mt.object({...YB().shape,...JB().partial().shape,...qB().partial().shape,...QB().partial().shape,...e0().partial().shape,...Wu().partial().shape,...ju().partial().shape,...i0().shape,...d0().partial().shape,...l0().partial().shape,...f0().partial().shape,...Vu().partial().shape,...b0().partial().shape,...C0().partial().shape,...c0().partial().shape,...A0().partial().shape,...T0().partial().shape})),Xu=new Set(["url","github","git","npm","file","directory","skills-dir","hostPattern","pathPattern","settings"]);function Ju(c){try{return new RegExp(c),!0}catch{return!1}}function D0(c){return uo(c)||Le(c)}var Zu="ssh.github.com";function Wi(c){return Xn(c)||fr(c)===Zu}var L0=/^[A-Za-z0-9._-]+$/;function I0(c){return L0.test(c)&&!c.startsWith("-")&&c!=="."&&c!==".."}function qu(c){if(!c.endsWith("/*"))return null;let A=c.slice(0,-2);return I0(A)?A:null}function P0(c){let A=[];for(let L of c.split("/")){if(L===".")continue;if(L===".."){A.pop();continue}A.push(L)}return A.filter((L)=>L!=="").join("/")}function w0(c){let A=c.length;for(;;){let L=A;while(L>0&&c.charCodeAt(L-1)===47)L--;if(L>=4&&c.startsWith(".git",L-4))L-=4;if(L===A)return A===c.length?c:c.slice(0,A);A=L}}function Iu(c){let A=Gi(c);return A===Zu?An:A}function x0(c,A){if(c.includes("://"))try{let ce=Ou(c);if(ce===null)return c;ce.hostname=Iu(ce.hostname),ce.username="",ce.password="",ce.search="",ce.hash="";try{ce.pathname=decodeURIComponent(ce.pathname)}catch{}let me=P0(ce.pathname);return ce.pathname=A?.stripDotGit?w0(me):me,ce.toString()}catch{return c}let L=Me(c);return L?`${Iu(L.host)}:${L.path}`:c}var N0=new Set(["http:","https:","git:","git+http:","git+https:"]);function v0(c){if(Bi(c))return c;if(c.includes("://"))try{let ce=new URL(c);if(ce.hostname=Gi(ce.hostname),N0.has(ce.protocol)||Xn(ce.hostname))ce.username="",ce.password="";return ce.toString()}catch{return c}let A=Au(c);if(!A)return c;let L=A.host.toLowerCase().replace(/\.+$/,"");return Xn(L)?`${An}:${A.path}`:`${A.user}@${L}:${A.path}`}function Qu(c){if(c.includes("://")){if(D0(c))return!1;let Ne=Me(c)?.host;if(Ne!==void 0&&Wi(Ne)&&x0(c,{stripDotGit:!0}).includes("*"))return!0;let Fe=Q(c)?.hostname;if(!Fe||!Wi(Fe))return!1;let st=v0(c);try{let gt=new URL(st);return gt.hostname.includes("*")||gt.pathname.includes("*")}catch{return st.includes("*")}}let A=Me(c),L=A?.host,ce=A?.path;if(!L||ce===void 0||!Wi(L))return!1;let me=ce;try{me=decodeURIComponent(ce)}catch{}return me.includes("*")}function ep(c){return mt.discriminatedUnion("source",[mt.object({source:mt.literal("url"),url:mt.string().url().describe("Direct URL to marketplace.json file"),headers:mt.record(mt.string(),mt.string()).optional().describe("Custom HTTP headers (e.g., for authentication)"),headersHelper:Zi().optional().describe("Command that prints a JSON object of HTTP headers (e.g. a short-lived auth token). Its output overrides `headers` and, like `headers`, is inherited by same-origin archive downloads from this marketplace. Runs from a fixed directory (the Claude config home, never the session's), so give a bare command found via PATH or an absolute path; it is re-run on later refreshes of this marketplace.")}),mt.object({source:mt.literal("github"),repo:mt.string().describe('GitHub repository in owner/repo format. ONLY in the managed-settings policy lists (strictKnownMarketplaces / blockedMarketplaces) the owner-wildcard form "owner/*" matches every repository under exactly that owner. Everywhere else (marketplace add, extraKnownMarketplaces, known_marketplaces.json) the value '+"must name a single repository — a wildcard is taken literally and fails to clone."),ref:mt.string().optional().describe('Git branch or tag to use (e.g., "main", "v1.0.0"). Defaults to repository default branch.'),path:mt.string().optional().describe("Path to marketplace.json within repo (defaults to .claude-plugin/marketplace.json)"),sparsePaths:mt.array(mt.string()).optional().describe('Directories to include via git sparse-checkout (cone mode). Use for monorepos where the marketplace lives in a subdirectory. Example: [".claude-plugin", "plugins"]. If omitted, the full repository is cloned.'),skipLfs:mt.boolean().optional().describe("Has no effect; accepted so existing settings keep working. Claude Code's own git never downloads Git LFS content: LFS-tracked files in the marketplace repository are checked out as pointer files whether or not this is set, and adding or updating the marketplace says how many were. To fetch their content, run `git lfs pull` in the marketplace's checkout under ~/.claude/plugins/marketplaces/.")}),mt.object({source:mt.literal("git"),url:mt.string().describe("Full git repository URL"),ref:mt.string().optional().describe('Git branch or tag to use (e.g., "main", "v1.0.0"). Defaults to repository default branch.'),path:mt.string().optional().describe("Path to marketplace.json within repo (defaults to .claude-plugin/marketplace.json)"),sparsePaths:mt.array(mt.string()).optional().describe('Directories to include via git sparse-checkout (cone mode). Use for monorepos where the marketplace lives in a subdirectory. Example: [".claude-plugin", "plugins"]. If omitted, the full repository is cloned.'),skipLfs:mt.boolean().optional().describe("Has no effect; accepted so existing settings keep working. Claude Code's own git never downloads Git LFS content: LFS-tracked files in the marketplace repository are checked out as pointer files whether or not this is set, and adding or updating the marketplace says how many were. To fetch their content, run `git lfs pull` in the marketplace's checkout under ~/.claude/plugins/marketplaces/.")}),mt.object({source:mt.literal("npm"),package:Yu().or(mt.string().regex(h0,"Invalid npm package name format")).describe('npm package containing marketplace.json (e.g. "@acme/claude-marketplace"). In strictKnownMarketplaces / blockedMarketplaces an entry also governs plugins installed straight from the npm marketplace (`<package>@npm`): an exact package name matches that package, and "@acme/*" matches every package under the scope.'),version:mt.string().optional().describe('Version or range to fetch (e.g. "1.4.0", "^1.4"); defaults to the latest dist-tag'),registry:mt.string().url().refine(Ji,"Registry must be an http(s) URL").optional().describe(`Registry URL. When adding a marketplace: a one-off registry override (otherwise your npm configuration decides). In a policy entry: the origin and path prefix the package's RESOLVED tarball URL must fall under (e.g. "https://npm.example.com/api/npm/internal/"); under allowManagedPermissionRulesOnly, an npm marketplace keeps plugin allowed-tools only when both the entry and the registration pin this same registry.`)}),mt.object({source:mt.literal("file"),path:mt.string().describe("Local file path to marketplace.json")}),mt.object({source:mt.literal("directory"),path:mt.string().describe("Local directory containing .claude-plugin/marketplace.json")}),mt.object({source:mt.literal("skills-dir")}).describe("Policy-list sentinel for the ~/.claude/skills/ auto-load (@skills-dir plugins). In strictKnownMarketplaces: opt the scan back IN (by default any allowlist blocks it). In blockedMarketplaces: turn the scan OFF without otherwise restricting marketplaces. Only meaningful in those two managed-settings lists (areLocalPluginDirsAllowedByPolicy); known_marketplaces.json / marketplace add etc. ignore it."),mt.object({source:mt.literal("hostPattern"),hostPattern:mt.string().describe('Regex pattern to match the host/domain extracted from any marketplace source type. For github sources, matches against github.com. For git sources (SSH or HTTPS), extracts the hostname from the URL. Use in strictKnownMarketplaces to allow all marketplaces from a specific host (e.g., "^github\\.mycompany\\.com$").')}),mt.object({source:mt.literal("pathPattern"),pathPattern:mt.string().describe('Regex pattern matched against the .path field of file and directory sources. Use in strictKnownMarketplaces to allow filesystem-based marketplaces alongside hostPattern restrictions for network sources. Use ".*" to allow all filesystem paths, or a narrower pattern (e.g., "^/opt/approved/") to restrict to specific directories.')}),mt.object({source:mt.literal("settings"),name:c?VB().describe("Marketplace name, as stored in known_marketplaces.json. A reserved name is refused per entry at load (revalidateReservedNameEntry); a look-alike name is judged when that marketplace's own catalog is parsed (catalogNameSchemaFor)."):$B().refine((A)=>!qi.has(A.toLowerCase()),{message:"Reserved marketplace names cannot be used with settings sources. validateOfficialNameSource only accepts github/git sources from anthropics/* for these names; a settings source would be rejected after loadAndCacheMarketplace has already written to disk with cleanupNeeded=false."}).describe("Marketplace name. Must match the extraKnownMarketplaces key (enforced); the synthetic manifest is written under this name. Same validation "+"as PluginMarketplaceSchema plus reserved-name rejection — "+"validateOfficialNameSource runs after the disk write, too late to clean up."),plugins:mt.array(z0()).describe("Plugin entries declared inline in settings.json"),owner:ta().optional()}).describe("Inline marketplace manifest defined directly in settings.json. The reconciler writes a synthetic marketplace.json to the cache; diffMarketplaces detects edits via isEqual on the stored source (the plugins array is inside this object, so edits surface as sourceChanged).")])}var mr=Mt(()=>ep(!1));var na=String.raw`[\w./+-]`,w3=new RegExp(`^(?:#${na}*)?$`),x3=new RegExp(String.raw`^(?:(?:git\+)?ssh:\/\/)?[^@:/\\?#%]+@[^@:/\\?#]+:[^@?#]*(?:#${na}*)?$`),N3=new RegExp(String.raw`^(?:(?:github|gitlab|bitbucket):)?[^@:/\\?#%]+(?:\/[^@:/\\?#%]+)+(?:#${na}*)?$`);var k0=Mt(()=>ep(!0));function tp(){return mr()}var oa=Mt(()=>tp()),hs=Mt(()=>tp()),ji=Mt(()=>mt.string().length(40).regex(/^[a-f0-9]{40}$/,"Must be a full 40-character lowercase git commit SHA")),np=Mt(()=>mt.string().regex(/^[0-9a-fA-F]{64}$/,"Must be a 64-character hex SHA-256 digest")),M0="Archive URLs must use https:// and must not point at a loopback, link-local, or cloud-metadata host";function U0(c){try{let A=new URL(c);return A.protocol==="https:"&&!au(A.hostname)}catch{return!1}}var H0=Mt(()=>mt.object({source:mt.literal("archive"),url:mt.string().url().refine(U0,{message:M0}).describe("HTTPS URL of a zip archive containing the plugin. The plugin root (the directory holding .claude-plugin/) may be at the top of the archive "+"or nested one directory deep — a single wrapping directory is stripped."),sha256:np().optional().describe("SHA-256 digest of the archive. When set, every download is verified against it and the install is refused on mismatch. It also serves as the version identity when neither plugin.json nor the marketplace entry declares a `version`. Recommended. Note the update signal is the version string (plugin.json "+"version, else the entry version, else this digest) — changing only the digest "+"while a version is declared does not trigger an update.")}).describe("Plugin distributed as a zip archive fetched over HTTPS — for hosting on any "+"static file server or artifact repository (S3, GitLab, nginx) with no git or npm on the client. Authentication: the entry's own `headers` / `headersHelper` (bound to this URL), overlaid on the enclosing url-source marketplace's headers (static or `headersHelper`-minted) when the archive shares its origin.")),op=Mt(()=>mt.union([mt.preprocess((c)=>c==="."?"./":c,bn()).describe("Path to the plugin root, relative to the marketplace root (the directory containing .claude-plugin/, not .claude-plugin/ itself)"),mt.object({source:mt.literal("npm"),package:Yu().or(mt.string().refine((c)=>/^(?:file|https?|git(?:\+https?|\+ssh)?|ssh|github|gitlab|bitbucket):/i.test(c)||!c.includes(".."),'Package reference cannot contain ".." path segments')).describe("Package name (or url, or local path, or anything else that can be passed to `npm` as a package)"),version:mt.string().optional().describe("Specific version or version range (e.g., ^1.0.0, ~2.1.0)"),registry:mt.string().url().refine(Ji,"Registry must be an http(s) URL").optional().describe("Custom NPM registry URL (defaults to using system default, likely npmjs.org)")}).describe("NPM package as plugin source"),mt.object({source:mt.literal("url"),url:mt.string().describe("Full git repository URL (https:// or git@)"),ref:mt.string().optional().describe('Git branch or tag to use (e.g., "main", "v1.0.0"). Defaults to repository default branch.'),sha:ji().optional().describe("Specific commit SHA to use")}),mt.object({source:mt.literal("github"),repo:mt.string().describe("GitHub repository in owner/repo format"),ref:mt.string().optional().describe('Git branch or tag to use (e.g., "main", "v1.0.0"). Defaults to repository default branch.'),sha:ji().optional().describe("Specific commit SHA to use")}),mt.object({source:mt.literal("git-subdir"),url:mt.string().describe("Git repository: GitHub owner/repo shorthand, https://, or git@ URL"),path:mt.string().min(1).describe('Subdirectory within the repo containing the plugin (e.g., "tools/claude-plugin"). '+"Checked out sparsely — over https or ssh as a partial clone (--filter=tree:0) — to minimize bandwidth for monorepos."),ref:mt.string().optional().describe('Git branch or tag to use (e.g., "main", "v1.0.0"). Defaults to repository default branch.'),sha:ji().optional().describe("Specific commit SHA to use")}).describe("Plugin located in a subdirectory of a larger repository (monorepo). Only the specified subdirectory is materialized; the rest of the repo is not downloaded."),H0(),mt.object({source:mt.literal("command"),command:mt.string().min(1).max(Xi,{message:"command must not be longer than the install consent UI can display"}).refine((c)=>!ku.test(c),{message:"command must be printable ASCII (letters, digits, punctuation, single spaces) with no runs of 4 or more spaces"}).describe("Shell command that prints the absolute path of the plugin directory on stdout (exactly one line) and exits 0. It must leave a complete plugin in that directory before exiting; the directory is copied into the plugin cache, so the printed path may change between runs (it is re-resolved on every install and update, and once per session in the background). Runs through the platform shell (sh on macOS/Linux, cmd.exe on Windows) from the user's home directory with Claude Code's subprocess environment."),timeout:mt.number().int().positive().max(bu).optional().describe("Seconds to wait for the command before giving up (default: 60)"),mode:mt.enum(["copy","link"]).optional().describe("copy (default): the printed directory is copied into the plugin cache and content-hashed, so it may be deleted afterwards. link: the cache entry links to the printed directory "+"in place (no copy, no size limit; macOS/Linux) — for large exports; the directory must then stay "+"valid while Claude Code runs, and a different printed path is what signals new content.")}).describe("Plugin directory produced by a locally installed tool (e.g. an IDE that renders its plugin for the currently selected SDK). Claude Code runs the command, copies the directory it prints, and re-runs it in the background at startup to pick up changes."),mt.object({source:mt.literal("unsupported"),error:mt.string().optional()}).describe("Placeholder for source types this Claude Code version does not recognize, or a known type whose fields failed validation (then `error` "+"holds the reason). Never authored by hand — PluginMarketplaceSchema rewrites "+"unparseable sources to this so the entry remains in marketplace.plugins (detectDelistedPlugins must not see it as removed). Install attempts fail at cachePlugin with an actionable message.")])),z0=Mt(()=>mt.object({name:gs().describe("Plugin name as it appears in the target repository"),source:op().describe("Where to fetch the plugin from. Must be a remote source — relative "+"paths have no marketplace repository to resolve against. Under allowManagedPermissionRulesOnly, a settings marketplace keeps its plugins' allowed-tools only when every npm entry here pins a `registry` on a bare package name; unpinned, the package resolves through the member's own npm config, and a non-bare spelling (an `npm:` alias, a `name@range`, a URL or git spec) packs as an "+"exotic spec the pin does not bind — either way the marketplace "+"vouches no tool grants."),description:mt.string().optional(),version:mt.string().optional(),strict:mt.boolean().optional(),headers:mt.record(mt.string(),mt.string()).optional().describe("HTTP headers sent when downloading this entry's `archive` source."),headersHelper:Zi().optional().describe("Command that prints a JSON object of HTTP headers for downloading this entry's `archive` source. Runs only when a user explicitly installs or updates this plugin. Unlike a catalog entry, an entry written here does not need `strict: false`: it is declared in a settings file, which has no manifest fields to inline. A declaration in project settings is not operator-authored, so request-routing and client-identity header names are still filtered there. Use an absolute path.")}).refine((c)=>typeof c.source!=="string",{message:'Plugins in a settings-sourced marketplace must use remote sources (github, git-subdir, npm, url, archive, command). Relative-path sources like "./foo" have no marketplace repository to resolve against.'}).refine((c)=>typeof c.source==="string"||c.source.source!=="unsupported",{message:"source.source: 'unsupported' is a parse-time placeholder and cannot be authored. Use a remote source (github, git-subdir, npm, url, archive, command)."}));var F0=Mt(()=>mt.object({cli:mt.array(mt.string().max(64)).max(10).optional().describe('First command tokens (e.g. ["stripe"]) — exact match against commands run this session.'),hosts:mt.array(mt.string().max(128)).max(20).optional().describe('Hostnames (e.g. ["api.stripe.com"]) — exact, case-insensitive match against '+"hostnames seen in https?:// URLs in bash commands run this session. Bare hostname only: lowercase, no scheme, no port, no path."),filesRead:mt.array(mt.string().max(256)).max(10).optional().describe('Glob patterns (e.g. ["**/*.tf"]) — the plugin is relevant when a file Claude has read '+"this session matches any pattern. Matched against read-file paths, forward-slash normalized, case-insensitive."),manifestDeps:mt.array(mt.object({file:mt.string().max(256),pattern:mt.string().max(256)})).max(10).optional().describe("Dependency declared in a package manifest. Each {file, pattern} is a pair of RegExp sources: "+"`file` matches the manifest filename (package.json, go.mod, requirements.txt, …); "+"`pattern` matches the dependency declaration inside that file. Evaluated against files read this session."),cwd:mt.array(mt.string().max(256)).max(10).optional().describe('Glob patterns (e.g. ["Engine/Source/Runtime/Renderer/**"]) — the plugin is relevant when the '+`session's working directory is at or under a directory matching the pattern. Matched against the cwd both relative to the enclosing git repo root and as an absolute path, forward-slash normalized, case-insensitive. A bare directory (no glob characters) means "cwd is at or under this directory". Known at session start, so this signal can surface a suggestion before the first turn.`)})),B0=Mt(()=>mt.object({topic:mt.string().max(64).optional().describe('What the user is working with when this plugin is relevant — fills "Working with {topic}?". '+'Often the product name (e.g. "Stripe"); use a domain (e.g. "design") when the plugin name does not read naturally as a topic. Defaults to the plugin name with each hyphen-segment capitalized.'),signals:F0().optional().describe("Matchers that determine when the plugin is relevant.")})),G0=Mt(()=>R0().partial().extend({name:gs().describe("Unique identifier matching the plugin name"),source:op().describe("Where to fetch the plugin from"),headers:mt.record(mt.string(),mt.string()).optional().describe("Custom HTTP headers for fetching this plugin's archive; overrides the marketplace's"),headersHelper:Zi().optional().describe("Command that prints a JSON object of HTTP headers for fetching this plugin's archive (e.g. a short-lived auth token); overrides this entry's `headers` and the marketplace's. Runs only when the user installs or updates this plugin, never during catalog browse. An entry that sets it must be `strict: false` with its manifest inlined here, so consent is informed from the entry alone before the command runs."),category:mt.string().optional().describe('Category for organizing plugins (e.g., "productivity", "development")'),tags:mt.array(mt.string()).optional().describe("Tags for searchability and discovery"),strict:mt.boolean().optional().default(!0).describe("Require the plugin manifest to be present in the plugin folder. If false, the marketplace entry provides the manifest."),relevance:mt.preprocess((c)=>r(c)?c:void 0,B0().optional()).describe(`Declares when this plugin is relevant to the user's work. Consumed by the spinner tip ("Working with {topic}?"), session-start auto-suggest, and marketplace browse ranking.`)})),W0=Mt(()=>mt.object({name:gs()}));function j0(c){let A=G0();return c.flatMap((L,ce)=>{let me=A.safeParse(L);if(me.success){let st=me.data.source;if(typeof st==="object"&&st.source==="unsupported"&&st.error!==void 0)return[{...me.data,source:{source:"unsupported"}}];return[me.data]}let Ne=W0().safeParse(L).data?.name,Fe=me.error.issues.map((st)=>`${st.path.join(".")}: ${st.message}`).join(", ");if(Ne){e(`Stubbing unparseable marketplace plugin entry (${Ne}): ${Fe}`,{level:"warn"});let st=rp(r(L)?L.source:void 0)?Z0:ra(L)?void 0:V0(me.error.issues)??Es(me.error.issues);return[{name:Ne,source:{source:"unsupported",...st&&{error:st}},strict:!0}]}return e(`Dropping unparseable marketplace plugin entry (index ${ce}): ${Fe}`,{level:"warn"}),[]})}var $0=new Set(["npm","url","github","git-subdir","archive","command","unsupported"]);function ra(c){if(!c||typeof c!=="object")return!1;let A=c.source;if(!A||typeof A!=="object")return!1;let L=A.source;return typeof L==="string"&&!$0.has(L)}function V0(c){let A=c.find((ce)=>ce.path.length===1&&ce.path[0]==="source");if(!A||A.code!=="invalid_union")return;let L=A.errors.find((ce)=>!ce.some((me)=>me.path.length===0||me.code==="invalid_value"&&me.path[0]==="source"));if(!L||L.length===0)return;return Es(L.map((ce)=>({...ce,path:["source",...ce.path]})))}var K0=/^[A-Za-z0-9_$.-]{1,40}$/;function Un(c){return K0.test(c)?c:"<key>"}var Y0=3,X0=160;function Es(c){let A=c.slice(0,Y0).map((ce)=>{let me=ce.path.map(String).map((Fe)=>Un(Fe)).join("."),Ne=ce.code==="unrecognized_keys"?`Unrecognized ${ce.keys.length===1?"field":"fields"}: ${ce.keys.map(Un).join(", ")}`:ki(ce.message,X0);return me?`${me}: ${Ne}`:Ne}),L=c.length-A.length;return L>0?`${A.join(", ")} (+${L} more)`:A.join(", ")}var J0=/^[A-Za-z0-9][-A-Za-z0-9._]*$/,Z0='Bare source names resolve under metadata.pluginRoot, which this marketplace does not set (or sets to a path outside the marketplace root). Use a "./relative/path" source, or set metadata.pluginRoot to allow bare names.';function rp(c){return typeof c==="string"&&J0.test(c)&&!c.includes("..")}function q0(c){if(typeof c!=="string"||c===""||c.startsWith("/")||c.includes("\\")||c.includes(":"))return;let A=c.replace(/^\.\//,"").replace(/\/+$/,"");if(A===""||A===".")return".";if(A.split("/").some((L)=>L===""||L==="."||L===".."))return;return A}function Q0(c,A){if(A===void 0||!r(c)||!rp(c.source))return c;let L=A==="."?`./${c.source}`:`./${A}/${c.source}`;return{...c,source:L}}function eG(c){if(!r(c)||!Array.isArray(c.plugins))return c;let A=r(c.metadata)?q0(c.metadata.pluginRoot):void 0;if(A===void 0)return c;return{...c,plugins:c.plugins.map((L)=>Q0(L,A))}}var tG=Mt(()=>mt.object({$schema:mt.string().optional().describe("JSON Schema reference for editor autocomplete/validation; ignored at load time"),name:KB(zu),version:mt.string().optional().describe("Marketplace manifest version"),description:mt.string().optional().describe("Human-readable description of this marketplace"),owner:ta().describe("Marketplace maintainer or curator information"),plugins:mt.array(mt.unknown()).transform(j0).describe("Collection of available plugins in this marketplace"),forceRemoveDeletedPlugins:mt.boolean().optional().describe("When true, plugins removed from this marketplace will be automatically uninstalled and flagged for users"),metadata:mt.object({pluginRoot:mt.string().optional().describe('Base directory for bare plugin source names, relative to the marketplace root (e.g. "./plugins" resolves "source": "formatter" as ./plugins/formatter). Sources that already start with "./" are unaffected.'),version:mt.string().optional().describe("Marketplace version"),description:mt.string().optional().describe("Marketplace description")}).optional().describe("Optional marketplace metadata"),allowCrossMarketplaceDependenciesOn:mt.array(mt.string()).optional().describe("Marketplace names whose plugins may be auto-installed as dependencies. Only the root marketplace's allowlist applies — no transitive trust."),renames:mt.record(mt.string(),mt.string().nullable()).optional().catch(void 0).describe("Append-only map of old plugin name → current name (or null when removed). The loader follows this on plugin-not-found and migrates user settings to the new name.")})),v3=Mt(()=>mt.preprocess(eG,tG()));var Ki="[A-Za-z0-9][-A-Za-z0-9._]*",k3=new RegExp(`^${Ki}$`);var nG=new RegExp(`^${Ki}@${Ki}$`),Pu=`@${Fu}`;function oG(c){return c.endsWith(Pu)&&Ku(c.slice(0,-Pu.length))}var gr=Mt(()=>mt.string().refine((c)=>nG.test(c)||oG(c),"Plugin ID must be in format: plugin@marketplace")),M3=new RegExp(`[@:\\s/\\\\${V}]`,"u"),U3=new RegExp(`[${V}]`,"u"),sp=/[\p{Cc}\u200E\u200F\u202A-\u202E\u2066-\u2069]/u,rG=/^[A-Za-z0-9][-A-Za-z0-9._]*(@[A-Za-z0-9][-A-Za-z0-9._]*)?(@\^[^@]*)?$/,sG=Mt(()=>mt.union([mt.string().regex(rG,"Dependency must be a plugin name, optionally qualified with @marketplace").transform((c)=>c.replace(/@\^[^@]*$/,"")),mt.object({name:mt.string().min(1).regex(/^[A-Za-z0-9][-A-Za-z0-9._]*$/),marketplace:mt.string().min(1).regex(/^[A-Za-z0-9][-A-Za-z0-9._]*$/).optional()}).loose().transform((c)=>c.marketplace?`${c.name}@${c.marketplace}`:c.name)])),iG=Mt(()=>mt.object({version:mt.string().describe("Currently installed version"),installedAt:mt.string().describe("ISO 8601 timestamp of installation"),lastUpdated:mt.string().optional().describe("ISO 8601 timestamp of last update"),installPath:mt.string().describe("Absolute path to the installed plugin directory"),gitCommitSha:mt.string().optional().describe("Git commit SHA for git-based plugins (for version tracking)"),resolvedVersion:mt.string().optional().describe("Tag-derived semver this install resolved to (when fetched via a version constraint). Used by verifyAndDemote in preference to manifest.version, since the upstream may have forgotten to bump plugin.json."),auto:mt.boolean().optional().describe("True when this plugin was pulled in as a dependency rather than installed explicitly. Auto-installed plugins are eligible for removal by the orphan sweep when nothing depends on them. Absent = manual (preserves pre-flag installs)."),...wu(),...xu(),...vu(),...Nu()})),H3=Mt(()=>mt.object({version:mt.literal(1).describe("Schema version 1"),plugins:mt.record(gr(),iG()).describe("Map of plugin IDs to their installation metadata")})),aG=Mt(()=>mt.enum(["managed","user","project","local"])),lG=Mt(()=>mt.object({scope:aG().describe("Installation scope"),projectPath:mt.string().optional().describe("Project path (required for project/local scopes)"),installPath:mt.string().describe("Absolute path to the versioned plugin directory"),version:mt.string().optional().describe("Currently installed version"),installedAt:mt.string().optional().describe("ISO 8601 timestamp of installation"),lastUpdated:mt.string().optional().describe("ISO 8601 timestamp of last update"),gitCommitSha:mt.string().optional().describe("Git commit SHA for git-based plugins"),resolvedVersion:mt.string().optional().describe("Tag-derived semver this install resolved to"),auto:mt.boolean().optional().describe("True when pulled in as a dependency. Eligible for orphan sweep."),...wu(),...xu(),...vu(),...Nu()})),z3=Mt(()=>mt.object({version:mt.literal(2).describe("Schema version 2"),plugins:mt.record(gr(),mt.array(lG())).describe("Map of plugin IDs to arrays of installation entries")})),F3=Mt(()=>mt.object({version:mt.literal(2),plugins:mt.record(mt.string(),mt.unknown())}));var cG=Mt(()=>mt.object({source:k0().describe("Where to fetch the marketplace from"),installLocation:mt.string().describe("Local cache path where marketplace manifest is stored"),lastUpdated:mt.string().describe("ISO 8601 timestamp of last marketplace refresh"),autoUpdate:mt.boolean().optional().describe("Whether to automatically update this marketplace and its installed plugins on startup")})),B3=Mt(()=>mt.record(mt.string(),cG()));import*as ip from"zod/v4";function Ho(c){return c==="true"?!0:c==="false"?!1:c}var _s=["aspell","hunspell","ispell"];import*as Jn from"zod/v4";var dG=["autoMode","deepLink","voice","briefView","screenReader"],sa={},Ss={autoMode:{buildGate:()=>!1,shape:()=>sa,permissionsShape:()=>sa,permissionModes:()=>[]},deepLink:{buildGate:()=>!0,shape:()=>({disableDeepLinkRegistration:Jn.enum(["disable"]).optional().describe("Prevent claude-cli:// protocol handler registration with the OS")})},voice:{buildGate:()=>!0,shape:()=>({voiceEnabled:Jn.boolean().optional().describe("Enable voice mode (hold-to-talk dictation)")})},briefView:{buildGate:()=>!0,shape:()=>({defaultView:Jn.enum(["chat","transcript"]).optional().describe("Default transcript view: chat (SendUserMessage checkpoints only) or transcript (full)")})},screenReader:{buildGate:()=>!1,shape:()=>sa}};function zo(){return dG.filter((c)=>Ss[c].buildGate())}function ap(c){let A={};for(let L of c)A={...A,...Ss[L].shape()};return A}function lp(c){let A={};for(let L of c)A={...A,...Ss[L].permissionsShape?.()};return A}function ia(c){let A=[];for(let L of c)A.push(...Ss[L].permissionModes?.()??[]);return A}import*as Fo from"zod/v4";var uG=64;class ys{fields;activeWhenAbsent;keys;built=new Map;byPresentKeys=new Map;wholeSchema;constructor(c,A=new Set){this.fields=c;this.activeWhenAbsent=A;this.keys=Object.keys(c).filter((L)=>c[L]!==void 0)}has(c){return Object.hasOwn(this.fields,c)&&this.fields[c]!==void 0}field(c){let A=this.built.get(c);if(A)return A;let L=this.has(c)?this.fields[c]:void 0;if(!L)return;let ce=L();return this.built.set(c,ce),ce}carries(c,A){return this.activeWhenAbsent.has(A)||typeof c==="object"&&c!==null&&A in c}whole(){return this.wholeSchema??=Fo.object(this.shapeOf(this.keys)).passthrough(),this.wholeSchema}forDocument(c,A="passthrough"){let L=this.keys.filter((st)=>this.carries(c,st));if(L.length===this.keys.length&&A==="passthrough")return this.whole();let ce=`${A}
${L.join(`
`)}`,me=this.byPresentKeys.get(ce);if(me)return this.byPresentKeys.delete(ce),this.byPresentKeys.set(ce,me),me;let Ne=this.shapeOf(L),Fe=A==="strip"?Fo.preprocess((st,gt)=>{for(let ht of this.wrongDocumentIssues(st,Ne))gt.addIssue(ht);return st},Fo.object(Ne)):Fo.object(Ne).passthrough().check((st)=>{st.issues.push(...this.wrongDocumentIssues(st.value,Ne))});if(this.byPresentKeys.size>=uG)for(let st of this.byPresentKeys.keys()){this.byPresentKeys.delete(st);break}return this.byPresentKeys.set(ce,Fe),Fe}wrongDocumentIssues(c,A){if(typeof c!=="object"||c===null)return[];let L=[];for(let ce of Object.keys(c))if(!Object.hasOwn(A,ce)&&this.has(ce))L.push({code:"custom",input:c[ce],path:[ce],message:"This settings schema was built for a document without this key"});return L}shapeOf(c){let A={};for(let L of c){let ce=this.field(L);if(ce)A[L]=ce}return A}}import*as As from"zod/v4";var J3=new RegExp("\x00ESCAPED_STAR\x00","g"),Z3=new RegExp("\x00ESCAPED_BACKSLASH\x00","g");var q3=new RegExp("\x00GLOBSTAR\x00","g");function cp(c){return c.match(/^(.+):\*$/)?.[1]??null}function dp(c){let A=c.trimEnd();if(!A.endsWith("*"))return!1;let L=0,ce=A.length-2;while(ce>=0&&A[ce]==="\\")L++,ce--;return L%2===0}var Os={filePatternTools:["Read","Write","Edit","Glob","NotebookRead","NotebookEdit","Cd"],bashPrefixTools:["Bash"],customValidation:{WebSearch:(c)=>{if(c.includes("*")||c.includes("?"))return{valid:!1,error:"WebSearch does not support wildcards",suggestion:"Use exact search terms without * or ?",examples:["WebSearch(claude ai)","WebSearch(typescript tutorial)"]};return{valid:!0}},WebFetch:(c)=>{if(c.includes("://")||c.startsWith("http"))return{valid:!1,error:"WebFetch permissions use domain format, not URLs",suggestion:'Use "domain:hostname" format',examples:["WebFetch(domain:example.com)","WebFetch(domain:github.com)"]};if(!c.startsWith("domain:"))return{valid:!1,error:'WebFetch permissions must use "domain:" prefix',suggestion:'Use "domain:hostname" format',examples:["WebFetch(domain:example.com)","WebFetch(domain:*.google.com)"]};return{valid:!0}}}};function aa(c){return Os.filePatternTools.includes(c)}function up(c){return Os.bashPrefixTools.includes(c)}function pp(c){return Object.hasOwn(Os.customValidation,c)?Os.customValidation[c]:void 0}function gp(c,A){let L=0,ce=A-1;while(ce>=0&&c[ce]==="\\")L++,ce--;return L%2!==0}function fp(c,A){let L=0;for(let ce=0;ce<c.length;ce++)if(c[ce]===A&&!gp(c,ce))L++;return L}var pG=/(?:^|[^\\])\\[()]/;function fG(c){return pG.test(c)&&fp(c,"(")!==fp(c,")")}var mG=/^(?:[|&;<>]|\d+[<>])/;function gG(c){return mG.test(c)}function la(c){for(let A=0;A<c.length;A++)if(c[A]==="*"&&!gp(c,A))return!0;return!1}function hG(c){if(c.endsWith(":*"))return;let A=c.trim().split(/\s+/).filter(Boolean),L=A[0];if(A.length<3||L===void 0||la(L))return;let ce=!1;for(let me of A.slice(1)){if(gG(me))return;if(la(me)){ce=!0;continue}if(me.startsWith("-"))continue;return ce?L:void 0}return}function mp(c){if(!ds(c))return null;let A=us(c);if(A&&!ds(A.serverName))return null;return{valid:!1,error:`Wildcard tool name "${c}" is not supported in allow rules`,suggestion:"An allow pattern must name the scope it widens — globs are permitted only in the tool position after a literal mcp__<server>__ prefix. Deny and ask rules accept wildcards anywhere",examples:["mcp__puppeteer__*","mcp__github__get_*"]}}function ca(c,A){if(!c||c.trim()==="")return{valid:!1,error:"Permission rule cannot be empty"};let L=Ui(c);if(L.kind==="malformed")return{valid:!1,error:"Malformed Tool(content) rule",suggestion:'Rules take the form Tool or Tool(content) and must end at the closing ")"; parentheses inside the content are literal'};if(L.kind==="call"&&L.rawContent===""){if(!L.toolName)return{valid:!1,error:"Empty parentheses with no tool name",suggestion:"Specify a tool name before the parentheses"};return{valid:!1,error:"Empty parentheses",suggestion:`Either specify a pattern or use just "${L.toolName}" without parentheses`,examples:[`${L.toolName}`,`${L.toolName}(some-pattern)`]}}let ce=eu(c),me=us(ce.toolName);if(me){if(L.kind==="call")return{valid:!1,error:"MCP rules do not support patterns in parentheses",suggestion:`Use "${ce.toolName}" without parentheses, or use "mcp__${me.serverName}__*" for all tools`,examples:[`mcp__${me.serverName}`,`mcp__${me.serverName}__*`,me.toolName&&me.toolName!=="*"?`mcp__${me.serverName}__${me.toolName}`:void 0].filter(Boolean)};if(A==="allow"){let Fe=mp(ce.toolName);if(Fe)return Fe}return{valid:!0}}if(!ce.toolName||ce.toolName.length===0)return{valid:!1,error:"Tool name cannot be empty"};if(A==="allow"){let Fe=mp(ce.toolName);if(Fe)return Fe}if(!ce.toolName.includes("_")&&ce.toolName[0]!==ce.toolName[0]?.toUpperCase())return{valid:!1,error:"Tool names must start with uppercase",suggestion:`Use "${je(String(ce.toolName))}"`};if(L.kind==="call"&&fG(L.rawContent)){let Fe=aa(ce.toolName);return{valid:!1,error:'Ambiguous "\\(" or "\\)" beside an unescaped parenthesis',suggestion:Fe?"Write a Windows path with forward slashes, or spell a literal parenthesis as [(] or [)]":'Double a backslash that is a path separator ("\\\\("), and escape literal parentheses in pairs',examples:Fe?[`${ce.toolName}(C:/Projects/(drafts)/**)`,`${ce.toolName}(C:\\Projects\\[(]drafts)\\**)`]:[`${ce.toolName}(C:\\tools\\\\(x86)\\run.exe *)`]}}let Ne=pp(ce.toolName);if(Ne&&ce.ruleContent!==void 0){let Fe=Ne(ce.ruleContent);if(!Fe.valid)return Fe}if(up(ce.toolName)&&ce.ruleContent!==void 0){let Fe=ce.ruleContent;if(Fe===":*")return{valid:!1,error:"Prefix cannot be empty before :*",suggestion:"Specify a command prefix before :*",examples:["Bash(npm *)","Bash(git *)"]};if(A==="allow"){let gt=hG(Fe);if(gt!==void 0){let ht=gt==="git",Et=ht?" For git, options such as -c and --exec-path can run arbitrary commands.":"",Rt=ht?" (for example Bash(git status *))":"";return{valid:!0,warning:`${so(ce)} has a wildcard before the rest of the command, so it also matches any options inserted at that position and approves them without a prompt.${Et} Replace that * with the exact value you mean, or only use * after the subcommand${Rt}.`}}}let st=cp(Fe)?.trimEnd();if(st!==void 0){if(la(st)){let gt=dp(st),ht=gt?"matches only commands containing a literal * at that position":"will likely never match",Et=gt?st:`${st}*`,Rt=A==="allow"?" Replace that * with the exact value you mean.":Et.endsWith(":*")?"":` Use ${so({toolName:ce.toolName,ruleContent:Et})} for wildcard matching.`;return{valid:!0,warning:`${so(ce)} mixes * with the trailing :* prefix syntax, so it is matched as a literal prefix (the * is not expanded) and ${ht}.${Rt}`}}}else if(Fe.includes(":*")&&!Fe.endsWith(":*")){let gt=A==="allow"?"Replace that :* with the exact value you mean.":"It already matches as a * wildcard; moving :* to the end would make it a literal prefix and change which commands match.";return{valid:!0,warning:`${so(ce)} has a :* that is not at the end, so it is matched as a * wildcard (the : is literal), not as the trailing :* prefix syntax. ${gt}`}}}if(aa(ce.toolName)&&ce.ruleContent!==void 0){if(ce.ruleContent.includes(":*"))return{valid:!1,error:'The ":*" syntax is only for Bash prefix rules',suggestion:'Use glob patterns like "*" or "**" for file matching',examples:[`${ce.toolName}(*.ts) - matches .ts files`,`${ce.toolName}(src/**) - matches all files in src`,`${ce.toolName}(**/*.test.ts) - matches test files`]}}if(ce.ruleContent!==void 0){let Fe=ce.toolName==="Write"||ce.toolName==="NotebookEdit"||ce.toolName==="MultiEdit"?"Edit":ce.toolName==="Glob"?"Read":void 0;if(Fe!==void 0&&!ce.ruleContent.includes(":*"))return{valid:!0,warning:`${so(ce)} is not matched by file permission checks — only ${Fe}(path) rules are. Use ${so({toolName:Fe,ruleContent:ce.ruleContent})} instead (${Fe} rules cover all file-${Fe==="Edit"?"editing":"reading"} tools).`}}return{valid:!0}}var da=Mt(()=>Ep()),hp=Mt(()=>Ep("allow"));function Ep(c){return As.string().superRefine((A,L)=>{let ce=ca(A,c);if(!ce.valid){let me=ce.error;if(ce.suggestion)me+=`. ${ce.suggestion}`;if(ce.examples&&ce.examples.length>0)me+=`. Examples: ${ce.examples.join(", ")}`;L.addIssue({code:As.ZodIssueCode.custom,message:me,params:{received:A}})}})}var yr=["accept","hold","refuse"],Ds=["off","basic","full"],EG=Mt(()=>it.record(it.string(),it.coerce.string()));function Pp(c){return it.object({allow:it.array(hp()).optional().describe("List of permission rules for allowed operations"),deny:it.array(da()).optional().describe("List of permission rules for denied operations"),ask:it.array(da()).optional().describe("List of permission rules that should always prompt for confirmation"),defaultMode:it.preprocess(vo,it.enum([...ro,...ia(c)])).optional().describe("Default permission mode when Claude Code needs access ('manual' is accepted as an alias for 'default')"),disableBypassPermissionsMode:it.enum(["disable"]).optional().describe("Disable the ability to bypass permission prompts"),blockReadsOutsideWorkingDirectories:it.boolean().optional().describe('Refuse file-tool reads (Read, Grep, Glob, LSP) outside the working directories in every permission mode; true in any settings source wins. Also set when the user picks "block" on the one-time auto-mode prompt for a read outside the working directories.'),...lp(c),additionalDirectories:it.array(it.string()).optional().describe("Additional directories to include in the permission scope")}).passthrough()}var B6=Mt(()=>Pp(zo())),_G=Mt(()=>it.union([it.string(),it.object({}).passthrough().describe('{ id: stable id (letters, digits, ".", "_", "-"; max 64), text: the tip (max 500 characters, one line), cooldownSessions?: sessions to wait before showing it again (default 0), priority?: tie-break weight among never-shown tips (default 0) }')])),SG=Mt(()=>it.preprocess((c)=>Array.isArray(c)?c.filter((A)=>typeof A==="string"||!!A&&typeof A==="object"&&!Array.isArray(A)):[],it.array(_G()))),ga=Mt(()=>it.object({source:mr().describe("Where to fetch the marketplace from"),installLocation:it.string().optional().describe("Local cache path where marketplace manifest is stored (auto-generated if not provided)"),autoUpdate:it.boolean().optional().describe("Whether to automatically update this marketplace and its installed plugins on startup")})),ha=Mt(()=>{let c=()=>it.number().min(0).max(1e4);return it.object({input:c(),output:c(),cacheRead:c(),cacheWrite:c()})}),Ea=Mt(()=>it.number().gt(0).lte(10).optional()),_a=Mt(()=>it.object({model:it.string().describe('Model to select, taken verbatim: an alias ("opus"), an Anthropic model ID, or a provider-format ID (Vertex, Bedrock, gateway). Same values --model accepts.'),label:it.string().optional().describe("Row title. Defaults to the model name."),description:it.string().optional().describe("Row subtitle. Defaults to a generic description."),behavesAs:it.string().optional().describe("For a model this version of Claude Code does not know: the ID of a model it does know "+'(e.g. "claude-opus-4-8") whose client-side handling — prompt profile, capability and effort '+"defaults — applies to it. Changes neither the row's label nor the model ID sent. Without it, "+"a model-catalog row for a model this version does not know is not offered until Claude Code is updated.")})),Ls=Mt(()=>it.object({serverName:it.string().regex(/^[a-zA-Z0-9_-]+$/,"Server name can only contain letters, numbers, hyphens, and underscores").optional().describe("Name of the MCP server that users are allowed to configure"),serverCommand:it.array(it.string()).min(1,"Server command must have at least one element (the command)").optional().describe("Command array [command, ...args] to match exactly for allowed stdio servers"),serverUrl:it.string().optional().describe('URL pattern with wildcard support (e.g., "https://*.example.com/*") for allowed remote MCP servers')}).refine((c)=>Ye([c.serverName!==void 0,c.serverCommand!==void 0,c.serverUrl!==void 0],Boolean)===1,{message:'Entry must have exactly one of "serverName", "serverCommand", or "serverUrl"'})),Is=Mt(()=>it.object({serverName:it.string().min(1,"Server name must be non-empty").refine((c)=>c.trim().length>0,{message:"Server name must not be whitespace-only"}).refine((c)=>c===c.trim(),{message:"Server name has leading or trailing whitespace and will never match (names are compared verbatim)"}).optional().describe("Name of the MCP server that is explicitly blocked"),serverCommand:it.array(it.string()).min(1,"Server command must have at least one element (the command)").optional().describe("Command array [command, ...args] to match exactly for blocked stdio servers"),serverUrl:it.string().optional().describe('URL pattern with wildcard support (e.g., "https://*.example.com/*") for blocked remote MCP servers')}).refine((c)=>Ye([c.serverName!==void 0,c.serverCommand!==void 0,c.serverUrl!==void 0],Boolean)===1,{message:'Entry must have exactly one of "serverName", "serverCommand", or "serverUrl"'})),wp=Mt(()=>it.object({marketplace:it.string(),plugin:it.string()})),yG=Mt(()=>it.preprocess((c)=>{if(typeof c!=="string"||!gr().safeParse(c).success)return c;let A=c.indexOf("@");return{marketplace:c.slice(A+1),plugin:c.slice(0,A)}},wp())),OG=/[\x00-\x1f\x7f-\x9f\u2028\u2029]|\p{DI}/u;function AG(c){let A=c.replaceAll("/","\\");if(J(A))return!1;return/^\\{2}[^\\]/.test(A)}function bG(c){return ae(c)||/^\/network\/servers(\/|$)/i.test(c)||ie(c)}function CG(c){return/^\/(proc|dev\/(fd|stdin|stdout|stderr))(\/|$)/i.test(c)}function TG(c,A,L={}){if(A==="win32"){let ce=c.replaceAll("/","\\");if(J(ce))return!1;let me=AG(ce);if(L.rejectUnc&&me)return!1;if(L.rejectDriveRelative){if(!/^[A-Za-z]:\\/.test(ce)&&!me&&/^(\\|[A-Za-z]:)/.test(ce))return!1}if(Ip.normalize(ce)!==ce)return!1;let Ne=ce.split("\\");if(Ne.some((st)=>st==="."||st===".."))return!1;if(Ne.some((st,gt)=>/[. ]$/.test(st)||st.includes(":")&&!(gt===0&&/^[A-Za-z]:$/.test(st))))return!1;let Fe=ce.startsWith("\\\\")?ce.slice(2):ce;if(/\\{2}/.test(Fe))return!1;return!ce.endsWith("\\")||/^([A-Za-z]:)?\\$/.test(ce)}if(L.rejectNetworkRoot&&bG(c))return!1;if(L.rejectMagicLinkRoot&&CG(c))return!1;if(Lp.normalize(c)!==c)return!1;if(c.split("/").some((ce)=>ce==="."||ce===".."))return!1;if(/\/{2}/.test(c))return!1;return!c.endsWith("/")||c==="/"}var RG=/\.(exe|ps1)$/i;function DG(c){return/\.ps1$/i.test(c)}function LG(c){return DG(c)&&/[[\]`*?]/.test(c)}var IG='a .ps1 path must not contain "[", "]", "`", "*", or "?" on Windows (PowerShell resolves them as wildcard syntax)',PG=()=>it.string().describe("Absolute path to the helper executable"),Zn=(c)=>it.preprocess((A)=>A===null?void 0:A,c.optional()).optional(),wG=Ve,_p=(c)=>it.number().int().min(c).transform((A)=>Math.min(A,wG)),Sp=["path","script","defaultSettings"];function xp(c){if(!c||typeof c!=="object"||Array.isArray(c))return!1;let A=c;return Sp.some((L)=>A[L]===null)&&Sp.every((L)=>A[L]===null||A[L]===void 0)}var yp=64,Ts=Mt(()=>it.object({path:PG(),timeoutMs:Zn(_p(1000)),refreshIntervalMs:Zn(it.union([it.literal(0),_p(60000)]))})),Np=()=>it.enum(["replace","merge"]).describe("How the helper's managedSettings compose with the settings of the source that delivered this entry: 'replace' (default) — the output is the policy; 'merge' — the output is deep-merged over that source's own settings the way merged managed sources compose (helper scalars win, arrays union, objects merge — except fallbackModel, forceLoginOrgUUID, gatewayInternalNetworks, sandbox.filesystem.allowRead, sandbox.credentials.awsPairs, sandbox.ripgrep and the restriction allowlists such as allowedMcpServers, allowedProviders, availableModels and allowedHttpHookUrls, which are the helper's whole value when it emits one; tighten a permission with a deny), so a failed helper costs only the delta");function vp(c){return c==="continue"||c==="refuse"}var xG=()=>it.preprocess((c)=>c===void 0||vp(c)?c:"refuse",it.enum(["continue","refuse"]).describe(`What happens when this entry's helper fails at startup (bad path, missing file or interpreter, non-zero exit, timeout, oversize or invalid output) and no static settings payload (this entry's own, the linux entry's on WSL, or the map's "default") applies in its place: 'refuse' — Claude Code does not start, naming the failure; 'continue' — Claude Code starts without the helper's output, on the delivering source's own settings, with a /status notice. Default: 'refuse' when the entry comes from MDM or the managed settings file, 'continue' when it comes from remote managed settings. Any other value is treated as 'refuse', with a /status notice. The install and update commands start no session and are never refused over a remote entry: they report the refusal in /status. An entry whose other fields fail validation runs no helper; from MDM or the managed settings file, any value but 'continue' on it then refuses to start Claude Code until the entry is fixed, unless a static settings payload (the entry's own, kept when it validates, the linux entry's for a wsl one, or the map's "default") serves in its place. From remote, a non-interactive session runs the helper off settings verified this session without the interactive approval, so 'refuse' there too means the helper ran and failed; a launch whose remote settings could not be verified this session (offline, fetch failed) starts without the helper regardless; and a failure first reached after the session has started (settings verified or approved mid-session, which on a machine that only ever runs non-interactively is every launch) ends a session no person watches (non-interactive, a background session no client is attached to, or a teammate session) as the refused start would have, and leaves a watched interactive one (a terminal, with or without remote control, or an attached background session) running under a /status notice with its next start refused. Background refresh failures always keep the last good output whatever this says`)),NG=5,vG=()=>it.number().int().min(0).transform((c)=>Math.min(c,NG)).describe("How many more times to run this entry's helper when a run fails to execute — it could not be launched, exited non-zero, or was stopped at timeoutMs — before that counts as a failure (a non-negative integer; default 0, a single attempt; above 5 is treated as 5). Attempts are separated by a short randomized backoff (from 250 ms, doubling per attempt, at most 4 s each) and each attempt gets the full timeoutMs, so a start that waits on the helper can wait up to (retries + 1) × timeoutMs plus the backoff. Output the helper did produce and that was refused — oversized, not a JSON object, an invalid envelope, or settings that fail validation — is not retried, and neither is an invalid path. Applies alike at startup and on each background refresh; only once the attempts are used up do the entry's failure rules (a static settings payload in its place, onFailure, the refresh notice) apply, naming the last attempt's failure"),kG=(c)=>(c==="windows"?it.literal("pwsh",{message:"interpreter must be 'pwsh' on windows ('sh' is not supported there)"}):it.literal("sh",{message:"interpreter must be 'sh' on macos/linux/wsl"})).describe("Fixed interpreter for `script`: 'sh' (/bin/sh) on macos/linux/wsl entries; 'pwsh' (PowerShell at its fixed install locations, never PATH) on the windows entry"),MG="exactly one of path/script must be configured",UG='"script" and "interpreter" must be configured together',HG="script must be ASCII-only on Windows (PowerShell decodes stdin with the console OEM code page); spell non-ASCII characters as escapes, e.g. [char]0x00E9",zG=(c)=>it.string({message:"script must be a string"}).min(1,{message:"script must not be empty"}).max(65536,{message:"script must be at most 65536 characters"}).refine((A)=>!A.includes("\x00"),{message:"script must not contain NUL bytes"}).refine((A)=>Ge(A),{message:"script must be valid UTF-8 (no lone surrogates)"}).refine((A)=>c!=="windows"||!/[\u0080-\uffff]/.test(A),{message:HG}).describe("Inline helper script, delivered to the fixed interpreter over stdin (never written to disk)");var gn=["macos","linux","windows","wsl"];function Sa(c){return c==="wsl"?["wsl","linux"]:[c]}function FG(c){return c==="windows"?"win32":"posix"}function BG(c){return{rejectDriveRelative:c==="windows",rejectUnc:c==="windows",rejectNetworkRoot:c!=="windows",rejectMagicLinkRoot:c!=="windows",requireWin32ExecutableSuffix:c==="windows"}}function GG(c){let A=FG(c),L=BG(c);return it.string().max(1024,{message:"path must be at most 1024 characters"}).refine((ce)=>!OG.test(ce),{message:"path must not contain control, line/paragraph-separator, or invisible (default-ignorable) characters"}).refine((ce)=>(A==="win32"?Ip:Lp).isAbsolute(ce),{message:"path must be absolute"}).refine((ce)=>!(A==="win32"&&L.requireWin32ExecutableSuffix)||RG.test(ce),{message:"path must end in .exe or .ps1 on Windows"}).refine((ce)=>A!=="win32"||!LG(ce),{message:IG}).refine((ce)=>TG(ce,A,L),{message:A==="win32"?'path must be in normalized form: no "." or ".." segments, no doubled or trailing separators, no component ending in "." or a space, no ":" outside the drive letter, no device-namespace (\\\\?\\) prefix, no drive-relative (\\dir or C:name) or UNC (\\\\server\\share) form':'path must be in normalized form: no "." or ".." segments, no doubled or trailing separators, and not under a network automount root (/net/<host>, /Network/Servers, or macOS /.vol /.file /.nofollow /.resolve) or a kernel magic-link root (/proc, /dev/fd)'}).describe("Absolute path to the helper executable")}var ya=[...gn,"default"],ua=["path","script","interpreter","outputBehavior","onFailure","retries","timeoutMs","refreshIntervalMs","defaultSettings"],Cs=["managedSettings","appendSystemPrompt"],fo=Mt(()=>it.record(it.string(),it.unknown()).superRefine((c,A)=>{for(let L of["policyHelper","policyHelpers"])if(c[L]!==void 0&&c[L]!==null)A.addIssue({code:"custom",message:`must not contain "${L}" — the default payload is applied as managed settings and cannot configure further policy helpers`});for(let L of ua)if(c[L]!==void 0&&c[L]!==null)A.addIssue({code:"custom",message:`must not contain "${L}" — a static payload is a managed-settings object, not a policyHelpers entry; entry fields (${ua.join("/")}) belong on the per-OS entries (policyHelpers.${gn.join("/")})`});for(let L of Cs)if(c[L]!==void 0&&c[L]!==null)A.addIssue({code:"custom",message:`must not contain "${L}" — a static payload is the managedSettings SUBTREE, not the helper's stdout envelope; paste the object your helper emits UNDER "managedSettings", not the envelope around it`});for(let L of ya)if(c[L]!==void 0&&c[L]!==null)A.addIssue({code:"custom",message:`must not contain "${L}" — a static payload is the VALUE of a policyHelpers key (a managed-settings object), never another policyHelpers map; don't paste the map or its "${L}" line inside the slot`})})),WG='Entry must carry "path" (a helper executable) or "script" + "interpreter" (an inline helper), and/or "defaultSettings" (a static settings payload)';function jG(c){let{path:A,script:L,interpreter:ce,defaultSettings:me}=c;if(A!==void 0&&L!==void 0)return MG;if(L===void 0!==(ce===void 0))return UG;if(A===void 0&&L===void 0&&me===void 0)return WG;return null}function kp(c,A){return Ts().omit({path:!0}).extend({path:Zn(GG(c)),script:Zn(zG(c)),interpreter:Zn(kG(c)),outputBehavior:Zn(Np()),onFailure:Zn(xG()),retries:Zn(vG()),defaultSettings:it.preprocess((L)=>L===null?void 0:L,A.optional()).optional()}).check((L)=>{if(L.issues.length>0)return;let ce=jG(L.value);if(ce!==null)L.issues.push({code:"custom",message:ce,input:L.value})})}var G6=Mt(()=>kp("linux",fo()));function pa(c,A=fo()){return c==="default"?fo():kp(c,A)}var $G=Mt(()=>it.object(Object.fromEntries(ya.map((c)=>[c,it.preprocess((A)=>{if(A===null)return;if(c!=="default"&&xp(A))return;return A},pa(c).optional()).optional()])))),Sr=["skills","agents","hooks","mcp"];function Mp(c){return it.preprocess((A)=>{if(!Array.isArray(A))return A;let L=A.filter((ce)=>Sr.includes(ce));if(L.length<A.length)c?.(A.length-L.length);return L},it.union([it.boolean(),it.array(it.enum(Sr))]))}function Up(){return it.union([it.array(it.string()),it.boolean(),it.undefined()])}var Op=Object.freeze({type:"invalid-entry-stripped"}),VG=Mt(()=>it.union([it.object({type:it.literal("regex").describe('Config variant. This client understands "regex": matches turn output and builds a URL from named capture groups. Entries with other variants are preserved but skipped at runtime.'),pattern:it.string().describe("Regex matched against turn output (tool results and assistant text)"),url:it.string().describe("Link target. {name} placeholders are filled from named regex capture groups, e.g. (?<id>...) -> {id}. Values are URL-encoded; the origin must be literal in the template. The scheme must be https, http, or a recognized editor or workspace deep-link scheme: vscode, vscode-insiders, cursor, windsurf, zed, jetbrains, idea, slack, linear, notion, figma."),label:it.string().optional().describe("Badge text. {name} placeholders filled from named capture groups; defaults to the full match.")}).passthrough(),it.object({type:it.string().describe("Config variant discriminator for entries this client does not understand; the entry is preserved as-is and skipped at runtime.")}).passthrough()])),Ap=()=>it.number().int().min(Fd).max(Bd).optional().catch(void 0);function Hp(c,{strictPolicyHelperKeys:A=!1}={}){function L(me){return it.record(it.string(),ga()).check((Ne)=>{for(let[Fe,st]of Object.entries(Ne.value))if(st.source.source==="settings"&&st.source.name!==Fe)Ne.issues.push({code:"custom",input:st.source.name,path:[Fe,"source","name"],message:`Settings-sourced marketplace name must match its ${me} key (got key "${Fe}" but source.name "${st.source.name}")`})})}let ce=(me,Ne)=>A?it.preprocess((Fe)=>{if(Fe===null)return;return Ne?Ne(Fe):Fe},me):me.catch(void 0);return{$schema:()=>it.string().optional().describe("JSON Schema reference for Claude Code settings"),apiKeyHelper:()=>it.string().optional().describe("Path to a script that outputs authentication values"),proxyAuthHelper:()=>it.string().optional().describe("Shell command that outputs a Proxy-Authorization header value (EAP)"),awsCredentialExport:()=>it.string().optional().describe("Path to a script that exports AWS credentials"),awsAuthRefresh:()=>it.string().optional().describe("Path to a script that refreshes AWS authentication"),gcpAuthRefresh:()=>it.string().optional().describe("Command to refresh GCP authentication (e.g., gcloud auth application-default login)"),processWrapper:()=>it.string().optional().describe("Corporate launcher argv prefix for the background-agent supervisor, the sessions and workers it hosts, and the other covered background processes listed in the Claude Code corporate-launcher documentation. Equivalent to the CLAUDE_CODE_PROCESS_WRAPPER environment variable, which takes precedence when set. Honored from managed settings, a --settings/SDK-supplied settings file, and user settings, in that precedence order; project and local settings are ignored."),policyHelper:()=>ce(Ts().optional(),(me)=>me&&typeof me==="object"&&!Array.isArray(me)&&me.path===null?void 0:me).describe("Executable that computes managed settings at startup. Honored only from admin-controlled policy sources."),policyHelpers:()=>ce($G().optional()).describe(`@internal Per-OS variant of policyHelper, keyed by platform: macos, linux, windows, wsl, plus an optional "default" entry that is a STATIC settings payload (a JSON object of managed settings, not a helper). Each per-OS entry carries a helper — a "path", or an inline "script" + "interpreter" delivered to a fixed interpreter over stdin, either with timeoutMs/refreshIntervalMs — its own static "defaultSettings" payload, or both; an entry may be payload-only. Selection for a platform walks its chain (the platform's own entry; on wsl the linux entry next): the first helper on the chain wins over policyHelper; if no helper is configured — or the selected helper fails at startup or refresh — the first payload applies (the chain's "defaultSettings" in platform-specific-first order, then the top-level "default", applied with no process spawned; unrecognized platforms reach only "default"); with no payload either, policyHelper. Honored from admin-controlled policy sources, and from remote managed settings — a payload of plain policy as delivered, like any other remote key; a helper, or a payload carrying anything the managed-settings approval dialog lists, only once the settings are verified this session and approved there (policyHelper itself is never honored from remote).`),...Pn.CLAUDE_CODE_ENABLE_XAA&&{xaaIdp:()=>it.object({issuer:it.string().url().describe("IdP issuer URL for OIDC discovery"),clientId:it.string().describe("Claude Code's client_id registered at the IdP"),callbackPort:it.number().int().positive().optional().describe("Fixed loopback callback port for the IdP OIDC login. Only needed if the IdP does not honor RFC 8252 port-any matching.")}).optional().describe("XAA (SEP-990) IdP connection. Configure once; all XAA-enabled MCP servers reuse this.")},fileSuggestion:()=>it.object({type:it.literal("command"),command:it.string()}).optional().describe("Custom file suggestion configuration for @ mentions"),respectGitignore:()=>it.boolean().optional().describe("Whether file picker should respect .gitignore files (default: true). Note: .ignore files are always respected."),breakReminder:()=>it.object({enabled:it.boolean().optional().describe("Show a friendly nudge after sustained continuous use (default false). Must be true for the reminder to fire."),intervalMinutes:it.number().int().positive().optional().describe("Minutes of continuous use before the reminder fires (default 30). Re-fires every interval until you take a break."),breakThresholdMinutes:it.number().int().positive().optional().describe("Minutes of inactivity that count as a break and reset the timer (default 10)"),message:it.string().optional().describe("Custom reminder text. Leave unset for a rotating set of friendly nudges.")}).optional().describe("@internal Opt-in break reminder. When enabled, shows a dismissible nudge after sustained continuous use. Never blocks — just a friendly heads-up."),quietHours:()=>it.object({enabled:it.boolean().optional().describe("Show a one-time nudge when you start or keep using the CLI inside your quiet-hours window (default false)."),start:it.string().regex(/^([01]?\d|2[0-3]):[0-5]\d$/,'Expected 24-hour local time "HH:MM" (e.g. "22:00")').optional().describe('Start of the quiet-hours window, 24-hour local time "HH:MM".'),end:it.string().regex(/^([01]?\d|2[0-3]):[0-5]\d$/,'Expected 24-hour local time "HH:MM" (e.g. "07:00")').optional().describe('End of the quiet-hours window, 24-hour local time "HH:MM". May be earlier than start for an overnight range.')}).optional().describe("@internal Opt-in quiet hours. When enabled, shows a single soft nudge per session while inside the configured local-time window. Never blocks."),cleanupPeriodDays:()=>it.number().int().positive().optional().describe("Number of days to retain chat transcripts before automatic cleanup (default: 30). Minimum 1. Use a large value for long retention; use --no-session-persistence to disable transcript writes entirely."),desktopSessionCleanupPeriodDays:()=>it.number().int().nonnegative().optional().describe("Retention ceiling in days for session transcripts created or last written by a desktop-host surface (Claude Desktop, Cowork), which are otherwise exempt from the cleanupPeriodDays sweep. 0 (the default) means no ceiling: such transcripts are kept until deleted another way. Unlike cleanupPeriodDays, 0 is allowed because this setting never disables writes — it only bounds an exemption from deletion. The ceiling is a hard cap: it also bounds an active archive grace, so the grace window of a release marker never keeps files past the ceiling. Ignored when cleanupPeriodDays is managed by org policy. A ceiling at or below cleanupPeriodDays effectively disables the exemption: those transcripts age out on the regular cleanupPeriodDays schedule, so the effective retention is whichever of the two periods is longer."),syncClaudeAiSkills:()=>it.boolean().optional().describe("Set to false to turn off syncing of the skills you have enabled on claude.ai. In your user settings (or managed settings): nothing more is downloaded, previously synced skills (~/.claude/skills/synced) can no longer be run, are hidden from every session started afterwards, and are moved to ~/.claude/skills/.trash at the next launch (deleted after cleanupPeriodDays; re-downloaded, not restored, if you re-enable). In .claude/settings.local.json or --settings: downloads stop and synced skills are blocked and hidden for sessions in that workspace or invocation only (nothing is moved). Not read from project settings (.claude/settings.json). Only false is honored — the feature is enabled server-side for your account, so setting true does not turn it on early. While it is on, synced skills are available in every session, re-synced about every 10 minutes while a session is in use and a quarter as often otherwise, and removed when you disable them on claude.ai. Only applies when signed in with your Claude account."),syncClaudeAiPlugins:()=>it.boolean().optional().describe("Set to false to turn off syncing of the plugins you have enabled on claude.ai. In your user settings (or managed settings): nothing more is downloaded, previously synced plugins (~/.claude/plugins/synced) are hidden from every session started afterwards and moved to ~/.claude/plugins/.trash at the next launch (deleted after cleanupPeriodDays; re-downloaded, not restored, if you re-enable). In .claude/settings.local.json or --settings: downloads stop and synced plugins are hidden for sessions in that workspace or invocation only (nothing is moved). Not read from project settings (.claude/settings.json). Only false is honored — the feature is enabled server-side for your account, so setting true does not turn it on early. While it is on, synced plugins load in every session like plugins you installed yourself (a plugin you installed with the same name takes precedence), are re-synced at each launch, and are removed when you disable them on claude.ai. Only applies when signed in with your Claude account."),skillListingMaxDescChars:()=>it.number().int().positive().optional().describe("Per-skill description character cap in the skill listing sent to Claude (default: 1536). Descriptions longer than this are truncated. Raise to opt in to higher per-turn context cost."),skillListingBudgetFraction:()=>it.number().gt(0).lte(1).optional().describe("Fraction of the context window (in characters) reserved for the skill listing sent to Claude (default: 0.01 = 1%). When the listing exceeds this, descriptions are shortened to fit. Raise to opt in to higher per-turn context cost."),wslInheritsWindowsSettings:()=>it.boolean().optional().describe("When set to true in either admin-only Windows source — the HKLM SOFTWARE/Policies/ClaudeCode registry key or C:/Program Files/ClaudeCode/managed-settings.json — WSL reads managed settings from the full Windows policy chain (HKLM, C:/Program Files/ClaudeCode via DrvFs, HKCU) in addition to /etc/claude-code. Windows sources take priority. The flag is also required in HKCU itself for HKCU policy to apply on WSL (double opt-in: admin enables the chain, user confirms HKCU). On native Windows the flag has no effect."),env:()=>On(()=>EG()).describe("Environment variables to set for Claude Code sessions"),attribution:()=>{let me=it.object({commit:it.string().optional().describe("Attribution text for git commits, including any trailers. Empty string hides attribution."),pr:it.string().optional().describe("Attribution text for pull request descriptions. Empty string hides attribution."),sessionUrl:it.boolean().optional().describe("Whether to append the claude.ai session link to commits and PRs created from web or Remote Control sessions (default: true). Set to false to omit the Claude-Session trailer and PR-body link."),...!1}).passthrough();return it.union([it.boolean(),me],{error:(Ne)=>{let Fe=(Ne.errors??[]).flat().filter((gt)=>gt.path.length>0);if(Fe.length>0)return Fe.map((gt)=>`${gt.path.join(".")}: ${gt.message.replace(/^Invalid input: /,"")}`).join("; ");return`Expected false, true, or an object such as { "commit": "", "pr": "" }, but received ${Array.isArray(Ne.input)?"array":Ne.input===null?"null":typeof Ne.input}`}}).transform((Ne)=>{if(typeof Ne!=="boolean")return Ne;return Ne?{}:{commit:"",pr:"",sessionUrl:!1}}).pipe(me).optional().describe('Customize attribution text for commits and PRs. Each field defaults to the standard Claude Code attribution if not set. Set to false to hide all attribution, the same as { "commit": "", "pr": "", "sessionUrl": false }. Setting it to true is the same as leaving it out. Older Claude Code versions reject true or false here, so use the object form in settings files shared across versions.')},includeCoAuthoredBy:()=>it.boolean().optional().describe("Deprecated: Use attribution instead. Whether to include Claude's co-authored by attribution in commits and PRs (defaults to true)"),...!1,...!1,includeGitInstructions:()=>it.boolean().optional().describe("Include built-in commit and PR workflow instructions in Claude's system prompt (default: true)"),permissions:()=>On(()=>Pp(c)).describe("Tool usage permissions configuration"),model:()=>it.string().optional().describe("Override the default model used by Claude Code"),fallbackModel:()=>it.array(it.string()).optional().describe('Fallback model(s) tried in order when the primary model is overloaded or unavailable. Each element accepts a model name or alias; "default" expands to the default model. CLI --fallback-model takes precedence.'),availableModels:()=>it.array(it.string()).optional().describe('Allowlist of models that users can select. Accepts family aliases ("opus" allows any opus version), version prefixes ("opus-4-5" allows that version and any model ID that extends it, so "claude-opus-5" also allows "claude-opus-5-5"), and full model IDs. If undefined, all models are available. If empty array, only the default model is available. Typically set in managed settings by enterprise administrators.'),enforceAvailableModels:()=>it.boolean().optional().describe("When true and availableModels is a non-empty array, the Default model selection is also constrained: if the default model for the user tier is not in availableModels, Default resolves to the first allowed availableModels entry instead. Has no effect when availableModels is unset or an empty array. Typically set in managed settings by enterprise administrators."),availableModelsMatch:()=>it.enum(["prefix","exact"]).optional().describe('How availableModels entries match model IDs. "prefix" (the default) lets an entry also allow any model ID that extends it, so "claude-opus-5" allows "claude-opus-5-5". "exact" keeps that matching but stops a model ID entry from allowing other versions: "claude-opus-5" allows Opus 5 and its dated and -fast IDs, but not Opus 5.5 or a later release until it is listed, and a -latest ID needs a -latest entry. Family aliases ("opus") still allow the whole family; aliases whose model depends on the release or settings (best, opusplan, default) are ignored. With "exact" and a list that names at least one model, the Default option also uses only a listed model; if none can be used, Claude Code will not start. Haiku background models, and hooks and other helper requests that pick their own model, are not restricted (deniedModels covers them; allowManagedHooksOnly limits hooks). Read from managed settings only.'),deniedModels:()=>it.array(it.string()).optional().describe('Models users cannot select, even when availableModels allows them. A family alias ("opus") blocks that family. A model ID blocks that version in every spelling: dates, -fast and provider prefixes are ignored, so "claude-opus-5-5" blocks every Opus 5.5 ID but not Opus 5. An ID with no minor version ("claude-opus-5") also blocks later minor versions, as it allows them in availableModels. Aliases whose model depends on the release or settings (best, opusplan, default) are ignored. The Default option steps down past a blocked model; if the Default has no allowed model to step down to, Claude Code will not start. Read from managed settings only.'),modelOverrides:()=>it.record(it.string(),it.string()).optional().describe('Override mapping from Anthropic model ID (e.g. "claude-opus-4-6") to provider-specific model ID (e.g. a Bedrock inference profile ARN). Typically set in managed settings by enterprise administrators.'),modelPicker:()=>it.object({options:it.array(_a()).describe("Rows to show in the /model picker, in order."),replaceBuiltInOptions:it.boolean().optional().describe("When true, the picker shows only the Default row and these options — the built-in "+"lineup, gateway-discovered models and ANTHROPIC_CUSTOM_MODEL_OPTION are hidden. When false or unset, these options are added after the built-in lineup.")}).optional().describe("Curate the /model picker: an ordered list of models with your own labels, independent of the built-in lineup and of Claude Code releases. availableModels still applies to these rows. Honored from managed, --settings/SDK, and user settings only (not from a project checkout); the highest-precedence of those that defines modelPicker wins outright (no merging across sources). Typically set in managed settings by enterprise administrators."),modelPricing:()=>it.object({multiplier:Ea(),overrides:it.record(it.string(),ha()).optional()}).optional().describe("Price usage at your organization's contracted rates instead of list price. "+"Affects every spend figure Claude Code reports — /cost, the status line, the SDK total_cost_usd, "+"--max-budget-usd, and the OpenTelemetry cost metric and events — which remain USD estimates, not an invoice "+'(the per-Mtok price labels in /model stay at list). "overrides" maps a model ID to its USD-per-million-token rates (input, output, cacheRead, '+"cacheWrite — all four required, each 0 to 10000; cacheWrite prices both 5-minute and 1-hour cache writes). "+"A matching row is charged exactly as written; fast-mode and US-data-residency surcharges are not added on top. "+'A key Claude Code itself uses for a built-in model — its ID such as "claude-sonnet-4-6", or its '+"first-party, Bedrock (any or no region prefix), Vertex or Foundry ID — covers every dated and provider form "+"of that model; any other key — a gateway model alias, or a spelling Claude Code does not itself use — "+'matches that model ID only (case-insensitive), and such an exact match wins over a built-in row. On Bedrock an application inference profile is matched by its backing model. An invalid row or multiplier is reported and skipped; the rest still apply. "multiplier" in (0, 10] scales every computed cost, overridden or not (0.85 = 85% of the price, 1.2 = 120%). Only honored from managed settings (server-managed, MDM / OS policy, or managed-settings.json), '+"or — when none of those sets it — when supplied by a host application that manages the model "+"provider; ignored in user, project, local and --settings sources."),...!1,enableAllProjectMcpServers:()=>it.boolean().optional().describe("Whether to automatically approve all MCP servers in the project"),enabledMcpjsonServers:()=>it.array(it.string()).optional().describe("List of approved MCP servers from .mcp.json"),disabledMcpjsonServers:()=>it.array(it.string()).optional().describe("List of rejected MCP servers from .mcp.json"),disableClaudeAiConnectors:()=>it.boolean().optional().describe("When true in any settings source, claude.ai MCP cloud connectors are not auto-fetched or connected, and a claudeai-proxy server passed explicitly (e.g. via --mcp-config or the SDK mcpServers option) does not connect either. Any-source-true wins: a project can opt out, but a project-level false cannot override a user-level true."),skillOverrides:()=>it.record(it.string(),it.enum(["on","name-only","user-invocable-only","off"])).optional().describe('Per-skill listing overrides keyed by skill name. "name-only" lists the skill without its description; "user-invocable-only" hides it from the model but keeps /name; "off" hides it from both. Absent = on.'),disableBundledSkills:()=>it.boolean().optional().describe("Disable the skills and workflows that ship with Claude Code: bundled skills and workflows are removed entirely; built-in slash commands stay typable but are hidden from the model. Plugins, .claude/skills/, and .claude/commands/ are unaffected. Equivalent to CLAUDE_CODE_DISABLE_BUNDLED_SKILLS=1."),managedMcpServers:()=>On(()=>it.record(it.string().refine(Ii,{error:"server names may only contain letters, numbers, hyphens and underscores, and may not be __proto__, constructor or prototype"}),Pi(),{error:wi})).describe(`MCP servers the organization provides to every user, keyed by server name, each with the .mcp.json entry shape; only "http" and "sse" servers are accepted (nothing that names a program to run, no \${VAR} references). Honored from managed settings only; users cannot remove them, deniedMcpServers still applies, and they need no allowedMcpServers entry. Not read in Claude Desktop's Code tab on a third-party deployment or in Cowork sessions, where Claude Desktop supplies and locks the session's MCP servers itself.`),allowedMcpServers:()=>On(()=>it.array(Ls())).describe("Enterprise allowlist of the MCP servers users may use. Governs servers users add (user, project and local config, --mcp-config, agent frontmatter, plugins, claude.ai connectors); servers the organization itself delivers (managedMcpServers, and managed-mcp.json entries that use no ${VAR} expansion) are allowed without being listed; a managed-mcp.json entry that uses ${VAR} expansion is still checked against this list. If undefined, all servers are allowed. If empty array, users can use no servers of their own. Denylist takes precedence - if a server is on both lists, it is denied."),deniedMcpServers:()=>On(()=>it.array(Is())).describe("Enterprise denylist of MCP servers that are explicitly blocked. If a server is on the denylist, it will be blocked across all scopes including enterprise. Denylist takes precedence over allowlist - if a server is on both lists, it is denied."),hooks:()=>On(()=>lo()).describe("Custom commands to run before/after tool executions"),worktree:()=>it.object({symlinkDirectories:it.array(it.string()).optional().describe('Directories to symlink from main repository to worktrees to avoid disk bloat. Must be explicitly configured - no directories are symlinked by default. Common examples: "node_modules", ".cache", ".bin"'),sparsePaths:it.array(it.string()).optional().describe("Directories to include when creating worktrees, via git sparse-checkout (cone mode). "+"Dramatically faster in large monorepos — only the listed paths are written to disk."),baseRef:it.enum(["fresh","head"]).optional().describe("Which ref new worktrees branch from. 'fresh' (default) branches from origin/<default-branch> for a clean tree. 'head' branches from your current local HEAD so unpushed commits and feature-branch state are present. Applies to --worktree, EnterWorktree, and agent isolation."),bgIsolation:it.enum(["worktree","none"]).optional().catch(void 0).describe("Isolation mode for background sessions in this repo. 'worktree' (default) blocks Edit/Write in the main checkout until EnterWorktree is called. 'none' lets background jobs edit the working copy directly."),location:it.string().optional().catch(void 0).describe("Directory under which Claude Code Desktop creates the worktrees of SSH sessions that run on this machine (an absolute path or one starting with ~/), instead of <project>/.claude/worktrees. Read by the desktop app from the SSH host user settings; a location chosen in the desktop app's SSH connection settings takes precedence. The CLI (--worktree, EnterWorktree, agent isolation) does not read it yet.")}).optional().describe("Git worktree configuration: the CLI --worktree flag, EnterWorktree and agent isolation, plus the location Claude Code Desktop uses for SSH-session worktrees on this machine."),disableAllHooks:()=>it.boolean().optional().describe("Disable all hooks and statusLine execution: the hooks defined in settings files and by installed plugins. Features built into Claude Code are not hooks in this sense and keep working; each has its own switch."),disableAgentView:()=>it.boolean().optional().describe("Disable agent view (`claude agents`, `--bg`, /background, the on-demand daemon). Typically set in managed settings. Equivalent to CLAUDE_CODE_DISABLE_AGENT_VIEW=1."),disableRemoteControl:()=>it.boolean().optional().describe("Disable Remote Control (claude.ai/code, `claude remote-control`, `--remote-control`/`--rc`, auto-start, and the in-session toggle). Typically set in managed settings."),disableWorkflows:()=>it.boolean().optional().describe("Disable the Workflows feature. Code Review on pull requests and /ultrareview run in Anthropic's cloud and are not stopped by this setting, except an /ultrareview that has to restart partway through. A machine that runs a review itself refuses it when that machine's own administrator set this, or CLAUDE_CODE_DISABLE_WORKFLOWS in an `env` block, in its managed settings (MDM, the managed-settings file or an administrator's policy helper). Set in the environment before Claude Code starts, CLAUDE_CODE_DISABLE_WORKFLOWS disables Workflows. Beyond the cases above it stops a review only when the review's own session starts with it set."),disableArtifact:()=>it.boolean().optional().describe("Deprecated: use enableArtifact: false. Still honored — true disables the Artifact tool; false is ignored."),enableArtifact:()=>it.boolean().optional().describe("Turn the Artifact tool on or off. Off in any of managed, --settings, or user settings wins; project and local settings can only turn it off. Unset defaults to on once the feature is available."),enableWorkflows:()=>it.boolean().optional().describe("Enable or disable the Workflows feature for this user. Unset = default by plan once the feature is available."),workflowSizeGuideline:()=>it.enum(["unrestricted","small","medium","large"]).optional().describe('Advisory size guideline for the dynamic workflows Claude writes: "small" aims for fewer than 5 agents, "medium" fewer than 10, "large" fewer than 50, and "unrestricted" sends no guideline. Unset defaults to "medium", or "small" on Pro plans. A value here — including from managed settings — takes precedence over the "Dynamic workflow size" choice in /config, and that /config row is hidden while a settings file provides the key. This is a guideline, not an enforced limit.'),workflowKeywordTriggerEnabled:()=>it.boolean().optional().describe('Enable the "ultracode" keyword trigger: including the keyword in a prompt opts that turn into the Workflow tool. Set to false to disable the trigger. Default: true.'),disableSkillShellExecution:()=>it.boolean().optional().describe("Disable inline shell execution in skills and custom slash commands from user, project, or plugin sources. Commands are replaced with a placeholder instead of being run."),defaultShell:()=>it.enum(["bash","powershell"]).optional().describe("Default shell for input-box ! commands. Defaults to 'bash' on all platforms (no Windows auto-flip)."),bashEditDiffEnabled:()=>it.boolean().optional().describe("Whether the Bash tool shows a diff of the files a Bash command changed (PostToolUse Bash hooks get the changed-file list in tool_response). Set to false to turn that off. Default: on when the Bash tool handles file edits. Only user, flag or policy settings can turn it on outside auto and bypassPermissions modes."),bashOutputMaxChars:()=>it.number().int().positive().optional().catch(void 0).describe("How many characters of a successful Bash or PowerShell command's output Claude receives inline (default 30000; values clamp to 4000-128000). Output past this is saved to a file and Claude receives a short preview plus the path. When set, this also replaces BASH_MAX_OUTPUT_LENGTH, which on its own only sizes the read-back window."),taskOutputMaxChars:()=>it.number().int().positive().optional().catch(void 0).describe("Deprecated: no longer has any effect (the TaskOutput tool was removed). Read a background task's output file with the Read tool instead."),respondToBashCommands:()=>it.boolean().optional().describe("Whether Claude responds after an input-box ! bash command runs. Set to false to add the command output to context without a response. Default: true."),allowManagedHooksOnly:()=>it.boolean().optional().describe("When true (and set in managed settings), only hooks from managed settings and from plugins that managed settings enable run. User, project, and local hooks and the hooks of plugins the user installed are ignored. Features built into Claude Code are not hooks in this sense and keep working."),allowedHttpHookUrls:()=>it.array(it.string()).optional().describe('Allowlist of URL patterns that HTTP hooks may target. Supports * as a wildcard (e.g. "https://hooks.example.com/*"). When set, HTTP hooks with non-matching URLs are blocked. If undefined, all URLs are allowed. If empty array, no HTTP hooks are allowed. Arrays merge across settings sources (same semantics as allowedMcpServers).'),httpHookAllowedEnvVars:()=>it.array(it.string()).optional().describe("Allowlist of environment variable names HTTP hooks may interpolate into headers. When set, each hook's effective allowedEnvVars is the intersection with this list. If undefined, no restriction is applied. Arrays merge across settings sources (same semantics as allowedMcpServers)."),allowManagedPermissionRulesOnly:()=>it.boolean().optional().describe("When true (and set in managed settings), permission rules from user, project, local, and --settings files and allow rules from --allowedTools are ignored; only managed settings can add allow rules through settings. "+"The allowed-tools frontmatter of skills and custom commands from user, project, and --add-dir sources, and of plugins no managed setting vouches for, is ignored too. Plugins keep theirs only on an admin-backed channel: host-delivered --plugin-dir plugins, the official marketplace registered from its unpinned anthropics source, claude.ai-synced plugins Anthropic attests, the saved login organization's claude.ai-hosted marketplaces, marketplaces whose registered source managed extraKnownMarketplaces declares or an exact or owner-pinned (owner/*) strictKnownMarketplaces entry names at the path it pins (an npm marketplace source only when the registration and the declared entry pin the same registry, and a settings marketplace source only when every nested npm plugin entry pins one on a bare package name — unpinned, the package resolves through the member's own npm config, and a non-bare spelling packs as an exotic spec the pin does not bind, so nothing an entry names is what was fetched), and npm-direct (package@npm) plugins whose recorded resolution a registry-pinned managed npm strictKnownMarketplaces entry names (host and path patterns and enabledPlugins ids do not vouch); managed and bundled skills keep theirs. "+"--disallowedTools, skill disallowed-tools, and other deny and ask rules from the command line or the current session still apply."),allowManagedMcpServersOnly:()=>it.boolean().optional().describe("When true (and set in managed settings), allowedMcpServers is only read from managed settings. deniedMcpServers still merges from all sources, so users can deny servers for themselves. Users can still add their own MCP servers, but only the admin-defined allowlist applies."),allowAllClaudeAiMcps:()=>it.boolean().optional().describe("When true (and set in managed settings), claude.ai cloud MCP connectors load alongside managed-mcp.json instead of being suppressed by its exclusive-control lockdown. Default off preserves the lockdown. Read from managed settings only."),allowClaudeInChromeWithManagedMcp:()=>it.boolean().optional().describe("When true (and set in device managed settings: MDM, the managed-settings.json file, or a policy helper those configure), the built-in Claude in Chrome MCP server can run alongside managed-mcp.json instead of being blocked by its exclusive-control lockdown. deniedMcpServers and the organization's Claude in Chrome setting still block it. Default off preserves the lockdown."),strictPluginOnlyCustomization:()=>Mp().optional().catch(void 0).describe('When set in managed settings, blocks non-plugin customization sources for the listed surfaces. Array form locks specific surfaces (e.g. ["skills", "hooks"]); `true` locks all four; `false` is an explicit no-op. Blocked: ~/.claude/{surface}/, .claude/{surface}/ (project), settings.json hooks, .mcp.json. NOT blocked: managed (policySettings) sources, plugin-provided customizations. '+"Composes with strictKnownMarketplaces for end-to-end admin control — plugins gated by "+"marketplace allowlist, everything else blocked here."),statusLine:()=>it.object({type:it.literal("command"),command:it.string(),padding:it.number().optional(),refreshInterval:it.number().min(1).optional().catch(void 0).describe("Re-run the status line command every N seconds in addition to event-driven updates"),hideVimModeIndicator:it.boolean().optional().describe("Hide the built-in `-- INSERT --` / `-- VISUAL --` indicator below the prompt. Use this when your status line script renders `vim.mode` itself.")}).optional().describe("Custom status line display configuration"),prUrlTemplate:()=>it.string().optional().describe('URL template for PR links in the footer link badges and inline messages. The detected git PR is rendered as the first footer-link badge. Placeholders: {host} {owner} {repo} {number} {url}. Example: "https://reviews.example.com/{owner}/{repo}/pull/{number}"'),footerLinksRegexes:()=>it.array(VG().catch(Op)).transform((me)=>me.filter((Ne)=>Ne!==Op)).optional().catch(void 0).describe("Extra clickable footer badges that appear when a regex matches turn output (tool results and assistant responses). Read from user, flag, and managed settings only; ignored in project .claude/settings.json and local .claude/settings.local.json. At most 5 badges render; the oldest is displaced by newer matches and /clear removes them. Use to surface IDs printed by project CLIs as session links."),subagentStatusLine:()=>it.object({type:it.literal("command"),command:it.string()}).optional().describe("Custom per-subagent status line shown in the agent panel; receives row context as JSON on stdin"),enabledPlugins:()=>it.record(it.string(),Up()).optional().describe('Enabled plugins using plugin-id@marketplace-id format. Example: { "formatter@anthropic-tools": true }. Also supports extended format with version constraints. Settings precedence is user < project < local < flag < policy, so to disable a plugin that project settings enable, set it to false in .claude/settings.local.json — setting false in ~/.claude/settings.json is overridden by the project.'),prependPlugins:()=>it.array(it.string()).optional().catch(void 0).describe("Managed plugins (plugin@marketplace ids that managed enabledPlugins sets true) whose hooks run first, outermost, in the listed order: the first id listed sees every event before any other plugin and every result after it. Managed plugins not listed here or in appendPlugins follow the listed ones; user, project and marketplace plugins come after those; then appendPlugins; then the built-in plugins. The bundled cc-plugin-sec-default@builtin seats itself outermost (on a machine with managed settings and for Team and Enterprise organizations) unless this list is set, in which case list it where it should sit or leave it out. Name it there as sec-default@builtin, the id every release reads, for as long as any machine in the organization may run a release from before its rename; a release that knows the new id reads either. Any other id that is not an enabled managed plugin is skipped; an id listed in both keys is prepended. Only honored from managed settings (or, on a machine with none, from user settings for your own plugins); ignored in project, local and --settings sources."),appendPlugins:()=>it.array(it.string()).optional().catch(void 0).describe("Managed plugins (plugin@marketplace ids that managed enabledPlugins sets true) whose hooks run last among plugins, innermost, in the listed order: the last id listed sits just above the built-in plugins and sees each event as every other plugin left it. Only honored from managed settings (or, on a machine with none, from user settings for your own plugins); ignored in project, local and --settings sources."),extraKnownMarketplaces:()=>On(()=>L("extraKnownMarketplaces")).describe("Additional marketplaces to make available for this repository. Typically used in repository .claude/settings.json to ensure team members have required plugin sources."),additionalMarketplaces:()=>On(()=>L("additionalMarketplaces")).describe("Alias for extraKnownMarketplaces: this key is read exactly as if it were spelled "+"extraKnownMarketplaces. Do not set both in one file — if both appear, this key is ignored "+"with a warning. Claude Code may rewrite this key as extraKnownMarketplaces when it updates the file. Clients older than this alias ignore it, so prefer extraKnownMarketplaces while older Claude Code versions still share the same settings."),strictKnownMarketplaces:()=>On(()=>it.array(hs())).describe('Enterprise strict list of allowed marketplace sources. When set in managed settings, ONLY these sources can be added as marketplaces. Entries match exactly, except that a github entry may use the owner-wildcard form {"source":"github","repo":"owner/*"} to allow every repository under that owner. The check happens BEFORE downloading, so blocked sources never touch the filesystem. '+"Note: this is a policy gate only — it does NOT register marketplaces. "+"To pre-register allowed marketplaces for users, also set extraKnownMarketplaces."),allowedMarketplaces:()=>On(()=>it.array(hs())).describe("Alias for strictKnownMarketplaces (managed settings only): this key is read exactly as if it "+"were spelled strictKnownMarketplaces. Do not set both in one file — if both appear, this key "+"is ignored with a warning. Clients older than this alias ignore it, so keep using strictKnownMarketplaces when the allowlist must also bind older Claude Code versions."),blockedMarketplaces:()=>On(()=>it.array(oa())).describe('Enterprise blocklist of marketplace sources. When set in managed settings, these sources are blocked from being added as marketplaces. Entries match exactly, except that a github entry may use the owner-wildcard form {"source":"github","repo":"owner/*"} to block every repository under that owner. The check happens BEFORE downloading, so blocked sources never touch the filesystem.'),disableCommandPluginSources:()=>it.boolean().optional().describe("Controls the `command` plugin source, whose plugin directory is produced by running a marketplace-declared command on this machine. true: command-sourced plugins are never installed, updated, or re-resolved (the command never runs). false: explicitly allowed. "+"Unset: follows allowManagedHooksOnly — an org that restricts hook execution to managed "+"settings gets command sources disabled too. Only honored from managed settings."),...!1,disableSideloadFlags:()=>it.boolean().optional().describe("When true (and set in managed settings), rejects the --plugin-dir, --plugin-url, --agents, and non-sdk --mcp-config CLI flags at startup. Closes the CLI-flag bypass of strictKnownMarketplaces. Pair with allowedMcpServers for per-server MCP control; this setting does not gate other MCP entry points (SDK setMcpServers, claude mcp add, .mcp.json). Also blocks surfaces that spawn the CLI with these flags internally (see settings documentation). Only honored from managed settings; ignored in user/project/local settings."),pluginSuggestionMarketplaces:()=>it.array(it.string()).optional().describe("Marketplace names whose plugins may surface as contextual install suggestions (relevance-based tips). No marketplace-declared suggestions surface without this allowlist; the built-in first-party frontend-design tip is unaffected. Only honored when set in managed settings (policy scope); the key is ignored in user, project, and local settings. A name only takes effect when the marketplace is registered on the machine AND its registered source is also declared in managed settings, either as the extraKnownMarketplaces entry for that name or as an entry of strictKnownMarketplaces. A marketplace registered from a different source under an allowlisted name is ignored. The official marketplace is exempt from the source requirement: allowlisting its name alone suffices, since that name can only register from the official Anthropic source."),forceLoginMethod:()=>it.enum(["claudeai","console","gateway"]).optional().catch(void 0).describe('Force a specific login method: "claudeai" for Claude Pro/Max, "console" for Console billing, "gateway" for the Cloud gateway OIDC device flow'),forceLoginGatewayUrl:()=>it.string().min(1).optional().catch(void 0).describe('Cloud gateway URL to pre-fill during login, alongside forceLoginMethod: "gateway". Honored from admin-controlled managed settings (MDM / managed-settings.json / policy helper) and, on a machine with none of those, from your own user settings; ignored in project, local, flag, and remote-delivered settings.'),gatewayInternalNetworks:()=>it.array(it.string()).optional().catch([Fp]).meta({default:void 0}).describe("IPv4 CIDR blocks (at most 4, each /8 to /32, not overlapping) your Cloud gateway sits in: the public block your organization numbers its internal network from, which lets /login reach a gateway there. A block must lie entirely outside private space, where /login accepts a gateway without this key. /login accepts a gateway inside a listed block over a direct connection only, and only when this machine's own address on that connection is inside the same block, so /login must happen from a machine whose own address is inside the block (not through a proxy, VPN pool, container or NAT segment outside it). A bar against copied settings files, not proof of location. Honored only from admin-controlled managed settings (MDM / managed-settings.json / policy helper); ignored in user, project, and remote-delivered settings."),parentSettingsBehavior:()=>it.enum(["first-wins","merge"]).optional().describe(`Controls whether the SDK parent tier (Options.managedSettings / --managed-settings) layers under this admin tier. "first-wins" (the default, except in a gateway session Claude Desktop's Code `+'tab launched, where "merge" is): parent is dropped — admin tiers '+`are the only policy source. "merge": parent's restrictive-only-filtered settings union under the admin winner. Has no effect when no admin tier exists (parent applies as the sole policy tier, still filtered restrictive-only).`),managedSourcesBehavior:()=>it.enum(["first-wins","merge"]).optional().describe('Controls how the managed settings sources compose. "first-wins" (default): the highest-priority source present (server-managed > MDM (managed plist / HKLM) > managed-settings.json) is the managed tier alone. "merge": every present source deep-merges with fixed '+"precedence server-managed > MDM > managed-settings.json — scalars "+"take the highest source's value (a restrictive boolean or enum — "+"the allowManaged*Only locks, the disable* switches, the sandbox "+"lock family — takes the strictest value any source sets) and "+"arrays union, except fallbackModel, the restriction allowlists allowedMcpServers, allowedProviders, availableModels, strictKnownMarketplaces and allowedChannelPlugins, and sandbox.credentials.awsPairs and sandbox.ripgrep (the highest source that sets one owns it whole), modelOverrides (the whole map of the highest source that sets it, dropped when that source sits below the one that sets availableModels), managedMcpServers (server names union; a name set by two sources takes the higher source's whole entry), and the keys taken from the highest source only: the auth pins forceLoginOrgUUID, forceLoginMethod, forceLoginGatewayUrl and gatewayInternalNetworks, the credential helpers apiKeyHelper, awsAuthRefresh, awsCredentialExport, gcpAuthRefresh, otelHeadersHelper and proxyAuthHelper, modelPicker, permissions.defaultMode, parentSettingsBehavior and the policyHelper configuration (env keeps its own per-key union). Honored only from the highest-priority source present; enable it only when every lower source is admin-controlled, since lower sources then contribute entries such as permissions.allow. HKCU and --managed-settings never take part in the merge."),forceLoginOrgUUID:()=>it.union([it.string(),it.array(it.string())]).optional().describe("Organization UUID to require for OAuth login. Accepts a single UUID string or an array of UUIDs (any one is permitted). When set in managed settings, login fails if the authenticated account does not belong to a listed organization."),allowedProviders:()=>it.preprocess((me)=>Array.isArray(me)?me.filter(Ni):me,it.array(it.enum(dr))).optional().catch(void 0).describe(`Managed settings only (managed-settings.json, MDM, or server-managed). The API providers Claude Code may use on this machine: "anthropic" (the Anthropic API on Anthropic's own host, via a claude.ai or Console sign-in or an API key; pair it with forceLoginMethod / forceLoginOrgUUID to require a sign-in), "bedrock", "vertex", "foundry", "anthropicAws", "mantle" (each meaning that provider's own service: its regional, FIPS, private-endpoint and sovereign-cloud hosts), "customEndpoint" (the `+"Anthropic API or a cloud provider's API sent to some other host — ANTHROPIC_BASE_URL, that "+"provider's ANTHROPIC_*_BASE_URL, a Foundry resource name that is not a bare name, or for "+"Bedrock the AWS SDK's AWS_ENDPOINT_URL[_BEDROCK[_RUNTIME]] — such as an LLM gateway; admitted "+`only for the value pinned in the "env" block of the same managed source), or "gateway" (the Cloud gateway sign-in). A session on a provider that is not listed is refused at startup, at login, and when it next contacts the API, with a message naming what selected the provider and the entry that would allow it. Under a list, where first-party traffic goes (ANTHROPIC_BASE_URL, a gateway sign-in) is honored only when the same managed source pins it in "env" (or forceLoginGatewayUrl), and a claude ssh tunnel into the machine is refused. A cloud provider's credential and tenancy variables, and the network path and TLS trust (HTTPS_PROXY, NODE_EXTRA_CA_CERTS, CLAUDE_CODE_CERT_STORE), are not judged by this list; set those for the fleet in the managed "env" block, whose values replace the user's. To route Bedrock through a gateway for a fleet, pin ANTHROPIC_BEDROCK_BASE_URL there (it is what the clients use, ahead of an endpoint_url in ~/.aws/config, which this list does not judge); the AWS SDK's AWS_ENDPOINT_URL* pins only sanction where the SDK's own clients go and never stand in for the "bedrock" entry. Unset allows every provider; an empty array allows none. Only a list in managed-settings.json or MDM is enforcement on the machine: it cannot be widened or hidden by server-managed settings and reaches every session. A list set `+"only in the admin console reaches only sessions that fetch your server-managed settings — not "+"a session on a cloud provider, another organization or a non-Anthropic ANTHROPIC_BASE_URL, one authenticating only with apiKeyHelper or ANTHROPIC_AUTH_TOKEN, a Pro/Max login, --bare without "+"an API key, or a first launch before the fetch lands — all conditions the user controls. "+`Versions that predate this setting ignore it; pair it with a minimum-version policy on a mixed fleet. 'claude auth status' reports the Anthropic API as apiProvider "firstParty".`),forceRemoteSettingsRefresh:()=>it.boolean().optional().describe("When set in managed settings, the CLI blocks startup until remote managed settings are freshly fetched, and exits if the fetch fails"),otelHeadersHelper:()=>it.string().optional().describe("Path to a script that outputs OpenTelemetry headers"),outputStyle:()=>it.string().optional().describe("Controls the output style for assistant responses"),viewMode:()=>it.enum(["default","verbose","focus"]).optional().catch(void 0).describe("Default transcript view mode on startup"),language:()=>it.string().optional().describe('Preferred language for Claude responses and voice dictation (e.g., "japanese", "spanish")'),skipWebFetchPreflight:()=>it.boolean().optional().describe("Skip the WebFetch blocklist check for enterprise environments with restrictive security policies"),sandbox:()=>On(()=>Ei()),...!1,feedbackSurveyRate:()=>it.number().min(0).max(1).optional().describe("Probability (0–1) that the session quality survey appears when eligible. 0.05 is a reasonable starting point."),feedbackDrafts:()=>it.enum(["notify","quiet","off"]).optional().describe('Model-drafted feedback (the SendFeedback tool). "notify" (default) shows a one-line notice when a draft is queued; "quiet" shows only the footer counter; "off" disables the tool entirely so drafts are never queued.'),spinnerTipsEnabled:()=>it.boolean().optional().describe("Whether to show tips in the spinner"),spinnerVerbs:()=>it.object({mode:it.enum(["append","replace"]),verbs:it.array(it.string())}).optional().describe('Customize spinner verbs. mode: "append" adds verbs to defaults, "replace" uses only your verbs.'),spinnerTipsOverride:()=>it.object({excludeDefault:it.boolean().optional().catch(void 0),tips:SG().optional(),tipsFile:it.string().optional().catch(void 0).describe("Absolute or ~/ local path to a JSON file holding an array of tips (same shapes as `tips`); honored from user, --settings and on-disk managed settings only. Read once per CLI process (restart to pick up edits)."),label:it.string().optional().catch(void 0).describe('Prefix shown before your tips in the spinner (default "Tip")')}).passthrough().optional().catch(void 0).describe("Add your organization's own tips to the spinner tip rotation. tips: strings or {id, text, cooldownSessions?, priority?} objects; tipsFile: a JSON file of the same; label: prefix shown before your tips; excludeDefault: if true, only show your tips (default: false)."),syntaxHighlightingDisabled:()=>it.boolean().optional().describe("Whether to disable syntax highlighting in diffs"),maxProseWidth:()=>it.number().int().min(40).optional().catch(void 0).describe("Maximum width, in terminal columns, of the prose in Claude's responses (paragraphs, headings, lists, blockquotes). In a wider terminal the prose wraps at this width while tables and code blocks keep the full width; only the display wraps, the response text itself gains no line breaks. Minimum 40. Unset (the default) uses the full terminal width."),spellcheck:()=>it.object({enabled:it.boolean().optional().catch(void 0).describe("Turn on spell checking of the prompt input (default: false)"),checker:it.string().optional().catch(void 0).describe(`Which spell checker to run: ${_s.map((me)=>`"${me}"`).join(", ")}, or "auto" (default) for the first of those found on PATH`),language:it.string().optional().catch(void 0).describe(`Dictionary to use, passed to the checker as-is (aspell --lang, hunspell -d, ispell -d), e.g. "en_GB"; names are checker-specific (letters, digits and _ - . , only). Default: the checker's own default`),color:it.string().optional().catch(void 0).describe(`Color of misspelled words (they are also underlined): a terminal color name such as "red" or "magenta", "#rrggbb", "rgb(r,g,b)", "ansi256(n)" or "ansi:<name>". Default: the theme's error color`)}).passthrough().optional().catch(void 0).describe(`Underline misspelled words in the prompt input as you type, using an installed ${_s.slice(0,-1).join(", ")} or ${_s.at(-1)} (off unless "enabled" is true; does nothing if none is installed). Read from user, flag and managed settings only (the whole block from the highest-precedence of those applies); ignored in project .claude/settings.json and .claude/settings.local.json.`),terminalTitleFromRename:()=>it.boolean().optional().describe("Whether /rename updates the terminal tab title (defaults to true). Set to false to keep auto-generated topic titles."),promptCacheTtl:()=>it.enum(Do).optional().catch(void 0).describe('Prompt cache TTL for the main conversation (interactive, -p and SDK turns, plus the helpers that run inline with it): "5m" or "1h". Unset = automatic: 1 hour on a Claude subscription within its usage limits, 5 minutes on an API key, Bedrock, Vertex or Foundry. 1-hour cache writes are billed at a higher rate; the cache stays warm across longer breaks. The CLAUDE_CODE_PROMPT_CACHE_TTL environment variable takes precedence.'),subagentPromptCacheTtl:()=>it.enum(Do).optional().catch(void 0).describe("Prompt cache TTL for everything outside the main conversation — subagents, workflows, background and helper requests: "+'"5m" or "1h". Unset = automatic (5 minutes unless ENABLE_PROMPT_CACHING_1H=1). The CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL environment variable takes precedence.'),alwaysThinkingEnabled:()=>it.boolean().optional().describe("When false, thinking is disabled. When absent or true, thinking is enabled automatically for supported models."),effortLevel:()=>it.enum(["low","medium","high","xhigh"]).optional().catch(void 0).describe("Persisted effort level for supported models."),maxEffortLevel:()=>it.enum(or).optional().catch(void 0).describe("Maximum effort level. Anything above it (an /effort or /model pick, --effort, CLAUDE_CODE_EFFORT_LEVEL, a model default) is clamped to it, on every provider including Bedrock, Vertex and Foundry. Combines with an organization's per-model effort cap by taking the lower of the two; across settings files the lowest value wins, and modelSettings.<model>.maxEffortLevel replaces it per model. Enforced client-side: an effort supplied through CLAUDE_CODE_EXTRA_BODY is not clamped."),modelSettings:()=>it.preprocess((me)=>typeof me==="object"&&me!==null&&!Array.isArray(me)?oo(me,(Ne,Fe)=>Object.hasOwn(Object.prototype,Fe)):me,it.record(it.string(),it.object({effortLevel:it.enum(["low","medium","high","xhigh"]).optional().catch(void 0).describe("Persisted effort level for this model."),maxEffortLevel:it.enum(or).optional().catch(void 0).describe('Maximum effort level for this model. Within one settings file it replaces the top-level maxEffortLevel for the model ("max" exempts it); across settings files the lowest applicable value wins. Keyed like effortLevel: the canonical model name also matches its dated, [1m], Bedrock and Vertex spellings.'),autoCompactWindow:it.union([it.literal("auto"),Ap()]).describe('Auto-compact window for this model, in tokens (100000 to 1000000), or "auto" for the window tuned for the model. Within one settings file it replaces the top-level autoCompactWindow for the model. /autocompact saves here. The canonical model name as key also matches its dated, [1m], Bedrock and Vertex spellings.')}).passthrough().optional().catch(void 0))).optional().catch(void 0).describe("Per-model settings keyed by canonical model name."),ultracode:()=>it.boolean().optional().catch(void 0).describe("Enable ultracode for the session: standing dynamic-workflow orchestration at any effort level. "+"Session-scoped — typically provided via --settings or the apply_flag_settings control request; "+"interactive toggles never persist it. Requires workflows to be enabled and a model that supports ultracode."),autoCompactWindow:()=>Ap().describe("Auto-compact window size"),...!1,advisorModel:()=>it.string().optional().describe("Advisor model for the server-side advisor tool."),fastMode:()=>it.boolean().optional().describe("When true, fast mode is enabled. When absent or false, fast mode is off."),fastModePerSessionOptIn:()=>it.boolean().optional().describe("When true, fast mode does not persist across sessions. Each session starts with fast mode off."),promptSuggestionEnabled:()=>it.boolean().optional().describe("When false, prompt suggestions are disabled. When absent or true, prompt suggestions are enabled."),emojiCompletionEnabled:()=>it.boolean().optional().describe("When false, the :emoji: shortcode typeahead (the suggestion popup and the :name: inline replacement) is disabled. When absent or true, it is enabled."),awaySummaryEnabled:()=>it.boolean().optional().describe("@internal When false, the session recap (shown when you return after being away for 5+ minutes) is disabled. When absent or true, recap is enabled. Hidden from public SDK types until external launch."),showClearContextOnPlanAccept:()=>it.boolean().optional().describe('When true, the plan-approval dialog offers a "clear context" option. Defaults to false.'),askUserQuestionTimeout:()=>it.enum(["60s","5m","10m","never"]).optional().catch(void 0).describe("Idle time before Claude's questions auto-continue with any answers "+"selected so far. Defaults to never — auto-continue only runs "+"when explicitly set to 60s/5m/10m."),dialogExpiry:()=>it.enum(["60s","5m","10m","never"]).optional().catch(void 0).describe('Max time a permission/user dialog forwarded to a remote client stays parked awaiting an answer, and how long a HELD cross-session message awaits approval, before either resolves to its safe no-action default (cancelled / dropped-with-denial). Defaults to 5m to match the long-standing remote-dialog deadline; "never" disables the deadline. Local-only permission prompts (no remote client) are unaffected. The CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS env var, when set, overrides this. Read from trusted sources only (never a checked-in repo settings file).'),agent:()=>it.string().optional().describe("Name of an agent (built-in or custom) to use for the main thread. Applies the agent's system prompt, tool restrictions, and model."),modelProposedGoals:()=>it.enum(zd).optional().catch(void 0).describe("@internal Controls the ProposeGoal tool (model-proposed session goals). 'auto' (the default when absent) lets the model choose per proposal whether to ask for approval via its ask_user parameter; 'alwaysAsk' routes every model-proposed goal through the approval dialog; 'disabled' turns the tool off. A typed /goal is unaffected. Consent-affecting, so it is read "+"from trusted sources only (user/policy/flag) — "+"workspace-resident project and local settings are ignored."),companyAnnouncements:()=>it.array(it.string()).optional().describe("Company announcements to display at startup (one will be randomly selected if multiple are provided)"),pluginConfigs:()=>it.record(it.string(),it.object({mcpServers:it.record(it.string(),it.record(it.string(),it.union([it.string(),it.number(),it.boolean(),it.array(it.string())]))).optional().describe("User configuration values for MCP servers keyed by server name"),options:it.record(it.string(),it.union([it.string(),it.number(),it.boolean(),it.array(it.string())])).optional().describe("Non-sensitive option values from plugin manifest userConfig, keyed by option name. Sensitive values go to secure storage instead.")}).or(it.undefined())).optional().describe("Per-plugin configuration including MCP server user configs, keyed by plugin ID (plugin@marketplace format)"),remote:()=>it.object({defaultEnvironmentId:it.string().optional().describe("Default environment ID to use for cloud sessions")}).optional().describe("Cloud session configuration"),autoUpdatesChannel:()=>it.enum(["latest","stable","rc"]).optional().describe("Release channel for auto-updates (latest or stable)"),minimumVersion:()=>it.string().optional().describe("Minimum version to stay on - prevents downgrades when switching to stable channel"),requiredMinimumVersion:()=>it.string().optional().describe("Minimum Claude Code version required to start. If the running version is older, Claude Code exits at startup with instructions to update. Only enforced from managed (policy) settings."),requiredMaximumVersion:()=>it.string().optional().describe("Maximum Claude Code version allowed to start. If the running version is newer, Claude Code exits at startup with instructions to install an approved version. Only enforced from managed (policy) settings."),plansDirectory:()=>it.string().optional().describe("Custom directory for plan files, relative to project root. If not set, defaults to ~/.claude/plans/"),tui:()=>it.enum(["default","fullscreen"]).optional().describe('Terminal UI renderer. "fullscreen" uses the flicker-free alt-screen renderer with virtualized scrollback (equivalent to CLAUDE_CODE_NO_FLICKER=1). "default" uses the classic main-screen renderer.'),...!1,voice:()=>it.object({enabled:it.boolean().optional(),mode:it.enum(["hold","tap"]).optional().describe("'hold' (default): hold to talk. 'tap': tap to start, tap to stop+submit."),autoSubmit:it.boolean().optional().describe("Submit the prompt when hold-to-talk is released (hold mode only)")}).optional().describe("Voice mode settings (hold-to-talk / tap-to-toggle dictation)"),channelsEnabled:()=>it.boolean().optional().describe("Managed-org opt-in for channel notifications (MCP servers with the claude/channel capability pushing inbound messages). claude.ai Teams/Enterprise: default off. Console: default on unless managed settings exist. Set true to allow; users then select servers via --channels."),allowedChannelPlugins:()=>it.array(wp()).optional().describe("Managed-org allowlist of channel plugins. When set, "+"replaces the default Anthropic allowlist — admins decide which "+"plugins may push inbound messages. Undefined falls back to the default. Requires channelsEnabled: true."),prefersReducedMotion:()=>it.boolean().optional().describe("Reduce or disable animations for accessibility (spinner shimmer, flash effects, etc.)"),timeFormat:()=>it.union([it.enum(Md),it.string()]).optional().describe('Clock format for times shown in the UI: "auto" (default, follows the locale), "12-hour", "24-hour", "24-hour-utc" ("18:05Z"), or a strftime pattern such as "%H:%M" (any value containing "%"; other values read as "auto"). A pattern replaces the time everywhere; message timestamps show only the pattern, so include %Y-%m-%d for the date. /config offers the presets; a pattern is set here.'),timeZone:()=>it.string().optional().describe('IANA time zone for times shown in the UI, e.g. "UTC" or "Europe/Dublin". Default: the system time zone. An unknown name falls back to the system time zone.'),doneMeansMerged:()=>it.boolean().optional().describe("@internal When true, Claude keeps working until the PR is ready for you to merge, a cron/Monitor is armed to resume later, or it hands you a self-contained next step."),totalTokensReminder:()=>it.enum(["off","infinite","fixed","countdown","padded-countdown"]).optional().describe("@internal Emit a <total_tokens>N tokens left</total_tokens> block in the system prompt, after each tool result, and (when totalTokensReminderAfterUserTurn is on) after each regular user prompt. 'infinite' uses the literal value Infinite, 'fixed' uses 5000000, 'countdown' uses the live remaining context-window tokens, 'padded-countdown' counts down from totalTokensReminderBudget (re-anchoring to the full budget on each regular user prompt when totalTokensReminderAfterUserTurn "+"is on — task-budget semantics). Defaults to padded-countdown. "+"Env var CLAUDE_CODE_TOTAL_TOKENS_REMINDER overrides."),totalTokensReminderBudget:()=>it.number().int().positive().optional().describe("@internal Starting budget (tokens) for totalTokensReminder 'padded-countdown' mode. Defaults to 15000000. Server-controlled via GrowthBook; env var CLAUDE_CODE_TOTAL_TOKENS_REMINDER_BUDGET overrides."),totalTokensReminderAfterUserTurn:()=>it.boolean().optional().describe("@internal When true, emit the totalTokensReminder block after each regular user prompt and (for 'padded-countdown') re-anchor the task budget to the full configured value at the start of each user turn. When false, the reminder appears only in the system prompt and after each tool-result batch, and 'padded-countdown' counts down over the whole session. Defaults to on. Env var CLAUDE_CODE_TOTAL_TOKENS_REMINDER_AFTER_USER_TURN overrides; server-controlled via GrowthBook tengu_lapis_anchor_user_turn."),autoMemoryEnabled:()=>it.boolean().optional().describe("Enable auto-memory for this project. When false, Claude will not read from or write to the auto-memory directory."),autoMemoryDirectory:()=>it.string().optional().describe("Custom directory path for auto-memory storage. Supports ~/ prefix for home directory expansion. Ignored if set in projectSettings (checked-in .claude/settings.json) for security. When unset, defaults to ~/.claude/projects/<sanitized-cwd>/memory/."),...!1,autoDreamEnabled:()=>it.boolean().optional().describe("Enable background memory consolidation (auto-dream). When set, overrides the server-side default."),showThinkingSummaries:()=>it.boolean().optional().describe("Request API-side thinking summaries and show them in the conversation and in the transcript view (ctrl+o). Set explicitly to override the default for your install."),skipDangerousModePermissionPrompt:()=>it.boolean().optional().describe("Whether the user has accepted the bypass permissions mode dialog"),skipWorkflowUsageWarning:()=>it.boolean().optional().describe("@internal Whether the user has accepted the multi-agent workflow usage warning. Until set, auto permission mode prompts before running a workflow."),disableAutoMode:()=>it.enum(["disable"]).optional().describe("Disable auto mode"),remoteTools:()=>it.object({allowUnattendedServing:it.boolean().optional().describe("@internal When false in managed or user settings, a cloud session in auto mode may not run commands on this computer without a person approving each one, whatever consent the computer has given; a project, local or --settings value is ignored. Default: true.")}).optional().describe("@internal How this computer serves tool calls to cloud sessions"),sshConfigs:()=>it.array(it.object({id:it.string().describe("Unique identifier for this SSH config. Used to match configs across settings sources."),name:it.string().describe("Display name for the SSH connection"),sshHost:it.string().describe('SSH host in format "user@hostname" or "hostname", or a host alias from ~/.ssh/config'),sshPort:it.number().int().optional().describe("SSH port (default: 22)"),sshIdentityFile:it.string().optional().describe("Path to SSH identity file (private key)"),startDirectory:it.string().optional().describe("Default working directory on the remote host. Supports tilde expansion (e.g. ~/projects). If not specified, defaults to the remote user home directory. Can be overridden by the [dir] positional argument in `claude ssh <config> [dir]`.")})).optional().describe("SSH connection configurations for remote environments. Typically set in managed settings by enterprise administrators to pre-configure SSH connections for team members."),claudeMd:()=>it.string().optional().describe("CLAUDE.md-style instructions injected as organization-managed memory. Only honored from managed/policy settings."),claudeMdExcludes:()=>it.array(it.string()).optional().describe('Glob patterns or absolute paths of CLAUDE.md files to exclude from loading. Patterns are matched against absolute file paths using picomatch. Only applies to User, Project, and Local memory types (Managed/policy files cannot be excluded). Examples: "/home/user/monorepo/CLAUDE.md", "**/code/CLAUDE.md", "**/some-dir/.claude/rules/**"'),pluginTrustMessage:()=>it.string().optional().describe('Custom message to append to the plugin trust warning shown before installation. Only read from policy settings (managed-settings.json / MDM). Useful for enterprise administrators to add organization-specific context (e.g., "All plugins from our internal marketplace are vetted and approved.").'),theme:()=>it.union([it.enum(Hd),it.string().startsWith("custom:").transform((me)=>me)]).optional().catch(void 0).describe("Color theme for the UI"),editorMode:()=>it.enum(kd).optional().catch(void 0).describe("Key binding mode for the prompt input"),keybindingFlavor:()=>it.enum(["classic","readline"]).optional().catch(void 0).describe("Deprecated: no longer has any effect. The prompt's word-editing keys always follow Bash (readline) conventions."),vimInsertModeRemaps:()=>it.record(it.string(),it.unknown()).optional().catch(void 0).describe('Vim INSERT-mode key-sequence remaps, e.g. {"jj": "<Esc>"}. Each key is exactly two printable characters typed in sequence; "<Esc>" (return to NORMAL mode) is the only supported target. Applies when editorMode is "vim".'),verbose:()=>it.boolean().optional().describe("Show full tool output instead of truncated summaries"),preferredNotifChannel:()=>it.enum(vd).optional().catch(void 0).describe("Preferred OS notification channel"),autoCompactEnabled:()=>it.boolean().optional().describe("Automatically compact conversation when context fills"),precomputeCompactionEnabled:()=>it.boolean().optional().describe("Precompute the compaction summary in the background before it is needed. Only applies when auto-compact is on."),idleCompaction:()=>it.boolean().optional().describe("Set to false to stop Claude Code from compacting a long conversation while the session is idle. Setting it to true does not turn idle compaction on."),switchModelsOnFlag:()=>it.boolean().optional().describe("When safeguards flag a message, automatically switch to a different model to keep chatting. When off, your session will pause instead."),autoContinueAtUsageLimit:()=>it.boolean().optional().describe("When a claude.ai usage limit stops your session, wait for the limit to reset and continue the task automatically. When off, the limit dialog offers the wait as a choice instead."),autoScrollEnabled:()=>it.boolean().optional().describe("Auto-scroll the conversation view to bottom (fullscreen mode only)"),wheelScrollAccelerationEnabled:()=>it.boolean().optional().describe("Ramp mouse-wheel scroll speed during fast scrolls (fullscreen mode only)"),fileCheckpointingEnabled:()=>it.boolean().optional().describe("Snapshot files before edits so /rewind can restore them"),showTurnDuration:()=>it.boolean().optional().describe('Show "Cooked for Nm Ns" after each assistant turn'),showMessageTimestamps:()=>it.boolean().optional().describe("Stamp each message with its arrival time"),terminalProgressBarEnabled:()=>it.boolean().optional().describe("Emit OSC 9;4 progress sequences during long operations"),todoFeatureEnabled:()=>it.boolean().optional().describe("Enable the todo / task tracking panel"),teammateMode:()=>it.enum(Ud).optional().catch(void 0).describe("How spawned teammates execute (tmux, iterm2, in-process, auto)"),remoteControlAtStartup:()=>it.boolean().optional().describe("Start Remote Control bridge automatically each session"),remoteControl:()=>it.object({shareHostProfile:it.enum(Ds).optional().catch(void 0).describe("@internal What a Remote Control environment reports about this machine when it registers: 'off' reports nothing, 'basic' the OS, architecture and detected developer tools, 'full' also the names of MCP servers configured on this machine (never a repository's .mcp.json). When unset, the level comes from the feature rollout, which may be any of the three. Managed, --settings and user settings choose the level (the most restrictive wins); project and local settings can only lower it, never raise it. Read when Remote Control starts; lowering it later applies from the next registration, raising it from the next start.")}).optional().describe("@internal Remote Control (`claude remote-control`) options"),isolatePeerMachines:()=>it.boolean().optional().describe("Require explicit approval before SendMessage can reach a peer session on another machine via Remote Control"),daemonColdStart:()=>it.enum(["transient","ask"]).optional().describe("When no background service is running: 'transient' spawns one for this login session; 'ask' offers to install it persistently"),crossSessionInbound:()=>it.enum(yr).optional().catch(void 0).describe("Inbound cross-session peer messages (SendMessage from your other sessions): 'accept' delivers them, 'hold' parks them for your review without letting Claude act, 'refuse' opts this session out. An explicit value always wins. Unset (mode parity): a message auto-delivers only when the sending session's permission-mode class matches yours (bypass↔bypass or prompting↔prompting); a mismatched sender's message is held for your approval; a sender that asserts no class is held only while this session bypasses permission prompts."),autoUploadSessions:()=>it.boolean().optional().describe("Mirror local sessions to claude.ai as view-only (no remote control)"),inputNeededNotifEnabled:()=>it.boolean().optional().describe("Push to mobile when a permission prompt or question is waiting"),agentPushNotifEnabled:()=>it.boolean().optional().describe("Allow Claude to push proactive mobile notifications"),...z(ap(c),(me)=>()=>me)}}function Oa(c,A={}){let L=Hp(c,A);return new ys(L).whole()}var KG=new Set,YG=new Set,Ps=Mt(()=>new ys(Hp(zo()),KG)),XG=Mt(()=>Ps().whole());function ws(c){return Ps().forDocument(c)}var bp=Object.freeze({serverName:"invalid-entry-stripped"});function zp(c){for(let A of c){let L=A.path.length>0?`${A.path.map(String).join(".")}: `:"";if(A.code==="invalid_union"){for(let ce of A.errors){let me=zp(ce);if(me!==null)return`${L}${me}`}if("note"in A&&typeof A.note==="string"&&A.note!=="")return`${L}${A.note}`}if(A.message!=="")return`${L}${A.message}`}return null}var Aa=Mt(()=>{let c=Ps();return Mn().flatMap(({path:A,restrictive:L})=>{if(A.length!==1||A[0]==="strictPluginOnlyCustomization"||A[0]==="disableAllHooks"||typeof L!=="boolean"&&typeof L!=="string")return[];let ce=A[0],me=c.field(ce);if(me===void 0||me instanceof it.ZodCatch)return[];return[{key:ce,restrictive:L,field:me}]})}),xs=Mt(()=>["strictKnownMarketplaces","blockedMarketplaces","strictPluginOnlyCustomization",...Aa().map((c)=>c.key)]),mo=["managedSourcesBehavior","wslInheritsWindowsSettings"];function Or(c){return r(c)&&Object.values(c).every(Or)}function ba(c){let A=c.wslInheritsWindowsSettings;if(A===void 0||A===null)return"disarmed";let L=Ho(A);return L===!0?"armed":L===!1?"disarmed":"unreadable"}function Ca(c){let A=c.source==="hostPattern"?c.hostPattern:c.source==="pathPattern"?c.pathPattern:null;if(A!==null&&!Ju(A))return`${c.source}: regex does not compile; the entry cannot be enforced`;if(c.source==="github"&&c.repo.includes("*")&&qu(c.repo)===null)return'github: an owner wildcard must be exactly "<owner>/*"; the entry cannot be enforced';if(c.source==="git"&&Qu(c.url))return'git: wildcards are only supported in github-form entries, as "<owner>/*"; the entry cannot be enforced';if((c.source==="github"||c.source==="git")&&c.ref!==void 0&&c.ref.includes("*"))return`${c.source}: ref contains "*", which git does not allow in ref names; the entry cannot be enforced`;return null}function Cp(c,A){return it.union([it.null().transform(()=>{return}),it.array(it.unknown()).transform((L)=>{let ce=[];for(let[me,Ne]of L.entries()){let Fe=(c==="blockedMarketplaces"?oa():hs()).safeParse(Ne);if(Fe.success){let st=Ca(Fe.data);if(st!==null){if(c==="blockedMarketplaces")A({path:`${c}[${me}]`,message:`Unenforceable entry was kept: ${st}; it can never match a marketplace source, but marketplace restrictions stay active`}),ce.push(Fe.data);else A({path:`${c}[${me}]`,message:`Invalid entry was ignored: ${st}`});continue}ce.push(Fe.data)}else A({path:`${c}[${me}]`,message:`Invalid entry was ignored: ${zp(Fe.error.issues)??"failed validation"}`})}if(c==="blockedMarketplaces"&&L.length>0&&ce.length===0)A({path:c,message:'Every entry of "blockedMarketplaces" was invalid; none of them can be enforced until it is fixed.'});return ce})]).optional()}function Tp(c,A,L){return it.array(A.catch((ce)=>(L({path:`${c}[]`,message:`Invalid entry was ignored: ${ce.issues[0]?.message??"failed validation"}`}),bp))).transform((ce)=>ce.filter((me)=>me!==bp)).optional()}var Fp="(unreadable)";function bs(c,A,L,ce,me,Ne){return it.array(it.unknown()).transform((Fe)=>{let st=[];for(let[gt,ht]of Fe.entries()){let Et=A.safeParse(ht);if(Et.success){st.push(Et.data);let Rt=me?.(ht,Et.data);if(Rt!==void 0)L({path:`${c}[${gt}]`,message:Rt,statusOnly:!0})}else{let Rt=Et.error.issues[0],Tt=Rt===void 0?"failed validation":Rt.path.length?`${Rt.path.join(".")}: ${Rt.message}`:Rt.message;L({path:`${c}[${gt}]`,message:`Invalid entry was ignored: ${Tt}`,...Ne?.invalidEntryIsStatusOnly&&{statusOnly:!0}})}}if(Fe.length>0&&st.length===0)L({path:c,message:`Every entry of "${c}" was invalid; enforcing an empty allowlist (${ce}) until it is fixed.`});return st}).optional().catch(()=>(L({path:c,message:`"${c}" was present but invalid; enforcing an empty allowlist (${ce}) until it is fixed.`}),[]))}var Bo=Mt(()=>new Map(Mn().flatMap(({path:c,restrictive:A})=>c.length>1?[[c.join("."),no(A)[0]]]:[]))),JG=new Map([["permissions",{restrictions:["deny","ask"],grants:["allow","additionalDirectories","defaultMode"]}],["autoMode",{restrictions:["soft_deny","hard_deny","deny"],grants:["allow","environment"],withholdOnEntryDrop:!0}],["sandbox.network",{restrictions:["deniedDomains"],grants:["allowedDomains"],withholdOnEntryDrop:!0}],["sandbox.filesystem",{restrictions:["denyWrite","denyRead"],grants:["allowWrite","allowRead"],withholdOnEntryDrop:!0}]]),Ns=new Map([["permissions.defaultMode",{read:(c)=>{let A=vo(c);return[...ro,...ia(zo())].find((L)=>L===A)},inert:new Set(["default","dontAsk","plan"]),floor:"default"}]]);function Ta(c,A,L,ce){let me=[],Ne=JG.get(c);if(Ne===void 0)return me;let Fe=Ne.restrictions.flatMap((gt)=>{switch(L(gt)){case"unreadable":return[`"${gt}"`];case"trimmed":return Ne.withholdOnEntryDrop?[`an entry of "${gt}"`]:[];case void 0:return[]}});if(Fe.length===0)return me;let st=Fe.join(" and ");for(let gt of Ne.grants){let ht=Ns.get(`${c}.${gt}`),Et=ht===void 0?A[gt]:ht.read(A[gt]);if(Et===void 0||ht?.inert.has(Et)===!0)continue;if(ht===void 0)delete A[gt];else A[gt]=ht.floor,me.push(gt);ce({path:`${c}.${gt}`,message:ht===void 0?`"${gt}" was withheld because ${st} in the same block could not be read; it takes effect again once that is fixed.`:`"${gt}" was withheld because ${st} in the same block could not be read; treating it as ${_r(ht.floor)} until that is fixed.`,...ht!==void 0&&{substituted:!0}})}return me}function Rs(c){for(let A of Bo().keys())if(A.startsWith(`${c}.`))return!0;return!1}function vs(c){return c!=="sandbox.credentials"&&!c.startsWith("sandbox.credentials.")&&Rs(c)}function Ra(c){let A=c;while(A instanceof it.ZodOptional||A instanceof Li||A instanceof it.ZodPipe)A=A instanceof it.ZodPipe?A.out:A.unwrap();return A instanceof it.ZodObject?A:void 0}var Rp=new Set(["remoteTools","remoteControl"]);function Bp(c,A){return typeof A==="object"&&A!==null&&c.has(A)}function Gp(c,A,L){let ce={};for(let[me,Ne]of Object.entries(A.shape)){let Fe=`${c}.${me}`;if(L?.has(Fe))continue;let st=Bo().get(Fe),gt=Ra(Ne);if(st!==void 0)ce[me]=st;else if(gt!==void 0&&Rs(Fe))ce[me]=Gp(Fe,gt,L)}return ce}function Dp(c,A){return{path:c,message:`"${A}" was null, which is read as key removal; this source does not set it.`,statusOnly:!0,removal:!0}}function _r(c){return typeof c==="string"?`"${c}"`:String(c)}function Er(c,A=0){let L=c===void 0||c.input===void 0?"failed validation":c.code==="custom"&&c.message!==void 0?c.message:("expected"in c)&&typeof c.expected==="string"?`expected ${c.expected}`:("values"in c)&&Array.isArray(c.values)?`expected ${c.values.map(_r).join(" or ")}`:"failed validation",ce=(c?.path??[]).slice(A);if(ce.length===0)return L;return ce.every((me)=>typeof me==="number")?`${ce.join(".")}: ${L}`:`nested value: ${L}`}function Wp(c){return c===!1||c==="false"}function Da(c,A){if(A===null)return!0;return(c.includes(".")?Bo().get(c):Aa().find((ce)=>ce.key===c)?.restrictive)==="disable"&&Wp(A)}function fa(c,A,L,ce){let me=c.slice(c.lastIndexOf(".")+1);if(typeof A==="boolean")return it.preprocess((Ne)=>{let Fe=Ho(Ne);if(Fe!==Ne)ce({path:c,message:`"${me}" holds the string "${String(Fe)}" where a boolean belongs; reading it as ${String(Fe)}. Write it without quotes.`,statusOnly:!0});return Fe},L);if(A==="disable")return it.preprocess((Ne)=>{if(Wp(Ne)){ce({path:c,message:`"${me}" was set to false; reading it as absent (the key's only value is "disable"). Remove the key instead.`,statusOnly:!0,removal:!0});return}return Ne},L);return L}function ZG(c,A,L,ce,me,Ne,Fe){let st=c.slice(c.lastIndexOf(".")+1),gt=Bo().get(c),ht=Fe?void 0:gt,Et=Ns.get(c),Rt=A instanceof it.ZodCatch?A.unwrap():void 0,Tt=Rt instanceof it.ZodType?Rt:A;return fa(c,gt,Tt,L).catch((Lt)=>{if(ht!==void 0)return L({path:c,message:`"${st}" was present but invalid (${Er(Lt.issues[0])}); treating it as ${_r(ht)}, its restrictive value, until it is fixed.`,substituted:!0}),ce.add(st),ht;if(Et!==void 0)return L({path:c,message:`"${st}" was present but invalid (${Er(Lt.issues[0])}); treating it as ${_r(Et.floor)} until it is fixed.`,substituted:!0}),ce.add(st),Et.floor;if(Tt.safeParse([]).success){let Bt=Lt.value;if(Array.isArray(Bt)){let xt=new Map;for(let Xt of Lt.issues){let Wt=Xt.path?.[0];if(typeof Wt==="number"&&!xt.has(Wt))xt.set(Wt,Er(Xt,1))}let Yt=Tt.safeParse(Bt.filter((Xt,Wt)=>!xt.has(Wt)));if(xt.size>0&&xt.size<Bt.length&&Yt.success){for(let[Xt,Wt]of xt)L({path:`${c}[${Xt}]`,message:`Invalid entry was ignored (${Wt}); it cannot take effect until it is fixed.`});return Ne.add(st),Yt.data}}}L({path:c,message:gt===void 0?`"${st}" was present but invalid (${Er(Lt.issues[0])}) and was ignored; it cannot take effect until it is fixed.`:`"${st}" was present but invalid (${Er(Lt.issues[0])}) and was ignored, not treated as ${_r(gt)}; it cannot take effect until it is fixed.`}),me.add(st);return})}function ma(c,A,L,ce={}){let me=c.slice(c.lastIndexOf(".")+1),Ne=new Set,Fe=new Set,st=new Set,gt={};for(let[Rt,Tt]of Object.entries(A.shape)){let It=`${c}.${Rt}`,Lt=Ra(Tt);gt[Rt]=ce.override?.[It]??(Lt!==void 0&&Rs(It)?ma(It,Lt,L,{...ce,strictField:Tt}):ZG(It,Tt,L,Ne,Fe,st,ce.neverSubstitute?.has(It)===!0))}let ht=new Set([...ce.skeletonExclude??[],...ce.neverSubstitute??[]]),Et=A.safeExtend(gt);return it.unknown().transform((Rt)=>{if(Rt===null){L(Dp(c,me));return}Ne.clear(),Fe.clear(),st.clear();let Tt=r(Rt)||ce.strictField===void 0?void 0:ce.strictField.safeParse(Rt),It=Tt?.success===!0&&r(Tt.data)?Tt.data:Rt,Lt=r(It)?Et.safeParse(oo(It,(Xt)=>Xt===null||Xt===void 0)):void 0;if(!r(It)||Lt?.success!==!0){let Xt=Gp(c,A,ht),Wt=Object.keys(Xt);if(L({path:c,message:Wt.length>0?`"${me}" was present but not an object; treating its locks as their restrictive values (${Wt.join(", ")}) until it is fixed.`:`"${me}" was present but not an object and was ignored; it cannot take effect until it is fixed.`,...Wt.length>0&&{substituted:!0}}),Wt.length===0)return;if(!Rp.has(c))ce.synthesized?.add(Xt);return Xt}for(let[Xt,Wt]of Object.entries(It)){let qt=`${c}.${Xt}`;if(Wt===null&&(Bo().has(qt)||Rs(qt)))L(Dp(qt,Xt))}let Bt={...Lt.data};for(let Xt of Ta(c,Bt,(Wt)=>Fe.has(Wt)?"unreadable":st.has(Wt)?"trimmed":void 0,L))Ne.add(Xt);let xt=oo(Bt,(Xt)=>Xt===void 0);if(Object.keys(xt).length===0)return Object.entries(It).some(([Xt,Wt])=>Wt!==void 0&&Object.hasOwn(A.shape,Xt))?void 0:xt;let Yt=ce.synthesized;if(Yt!==void 0&&!Rp.has(c)&&Object.entries(xt).every(([Xt,Wt])=>Ne.has(Xt)||Bp(Yt,Wt)||Or(Wt)))Yt.add(xt);return xt}).optional()}function La(c,A,L){let ce=Ps(),me=(wt)=>YG.has(wt)||ce.carries(L,wt),Ne=(wt)=>{let Pt=ce.field(wt);if(!Pt)throw Error("policyTolerantSettingsSchema: not a settings field of this build");return Pt},Fe=new Map,st=(wt,Pt)=>{Fe.set(wt,Pt)};for(let wt of["prependPlugins","appendPlugins"])if(ce.has(wt))st(wt,()=>it.array(it.string()).optional().catch((Pt)=>{c({path:wt,message:`${Pt.issues[0]?.message??"Failed schema validation"}. This field was ignored; read as unset.`});return}));st("wslInheritsWindowsSettings",()=>it.union([it.null().transform(()=>{return}),it.preprocess((wt)=>{let Pt=Ho(wt);if(Pt!==wt)c({path:"wslInheritsWindowsSettings",message:`"wslInheritsWindowsSettings" holds the string "${String(Pt)}" where a boolean belongs; reading it as ${String(Pt)}. Write it without quotes.`,statusOnly:!0});return Pt},Ne("wslInheritsWindowsSettings"))]).optional().catch(()=>{c({path:"wslInheritsWindowsSettings",message:`"wslInheritsWindowsSettings" was present but invalid (it takes true or false), so this source's WSL opt-in cannot be read until it is fixed. WSL fails it closed: in an administrator source it arms the Windows policy chain with no user-writable source (/etc/claude-code, HKCU) read beneath it; in HKCU it leaves HKCU unapplied.`});return})),st("strictKnownMarketplaces",()=>Cp("strictKnownMarketplaces",c).catch(()=>(c({path:"strictKnownMarketplaces",message:'"strictKnownMarketplaces" was present but invalid; enforcing an empty allowlist (no marketplaces admitted) until it is fixed.'}),[]))),st("blockedMarketplaces",()=>Cp("blockedMarketplaces",c).catch(()=>{c({path:"blockedMarketplaces",message:'"blockedMarketplaces" was present but invalid and was dropped; its entries cannot be enforced until it is fixed.'});return})),st("allowedMcpServers",()=>Tp("allowedMcpServers",Ls(),c).catch(()=>(c({path:"allowedMcpServers",message:'"allowedMcpServers" was present but invalid; enforcing an empty allowlist (no MCP servers admitted) until it is fixed.'}),[]))),st("deniedMcpServers",()=>Tp("deniedMcpServers",Is(),c).catch(()=>{c({path:"deniedMcpServers",message:'"deniedMcpServers" was present but invalid and was dropped; its entries cannot be enforced until it is fixed.'});return})),st("managedMcpServers",()=>it.unknown().transform((wt)=>ls(wt,(Pt,jt)=>c({path:Pt?`managedMcpServers.${Pt}`:"managedMcpServers",message:Pt?`Managed MCP server was ignored: ${jt}`:jt,statusOnly:!0}))).optional());let gt=new Set;for(let{key:wt,restrictive:Pt,field:jt}of Aa()){let Jt=typeof Pt==="string"?`"${Pt}"`:String(Pt);st(wt,()=>it.union([it.null().transform(()=>{return}),fa(wt,Pt,jt,c)]).optional().catch(()=>(c({path:wt,message:`"${wt}" was present but invalid; treating it as ${Jt} (its restrictive value) until it is fixed.`,substituted:!0}),gt.add(wt),Pt)))}st("strictPluginOnlyCustomization",()=>it.union([it.null().transform(()=>{return}),Mp((wt)=>c({path:"strictPluginOnlyCustomization",message:`"strictPluginOnlyCustomization" lists ${wt} ${ze(wt,"entry","entries")} this version does not recognize as a surface (known: ${Sr.join(", ")}); an unrecognized entry locks nothing, so check it for a typo.`,statusOnly:!0}))]).optional().catch(()=>(c({path:"strictPluginOnlyCustomization",message:'"strictPluginOnlyCustomization" was present but invalid; treating it as true (skills, agents, hooks and MCP servers load from managed settings and plugins only) until it is fixed.',substituted:!0}),gt.add("strictPluginOnlyCustomization"),!0))),st("enabledPlugins",()=>{let wt=Up();return it.record(it.string(),it.unknown()).transform((Pt)=>{let jt=[],Jt=0;for(let[Qt,en]of Object.entries(Pt)){let nn=wt.safeParse(en);if(nn.success){jt.push([Qt,nn.data]);continue}Jt++,c({path:gr().safeParse(Qt).success?`enabledPlugins.${Qt}`:"enabledPlugins.<invalid id>",message:"Invalid entry was ignored: the value must be true, false, or a list of version constraints. This plugin is neither force-enabled nor blocked until it is fixed."})}if(Jt>0&&jt.length===0){c({path:"enabledPlugins",message:'Every entry of "enabledPlugins" was invalid; no plugin is force-enabled or blocked by it until it is fixed.'});return}return Object.fromEntries(jt)}).optional().catch(()=>{c({path:"enabledPlugins",message:'"enabledPlugins" was present but invalid (not a map of plugin ids) and was ignored; no plugin is force-enabled or blocked by it until it is fixed.'});return})}),st("availableModels",()=>it.array(it.unknown()).transform((wt,Pt)=>{let jt=[];for(let Jt of wt)if(typeof Jt==="string")jt.push(Jt);else c({path:"availableModels",message:`"availableModels" contained a non-string entry (${JSON.stringify(Jt)}); the entry was ignored.`});return jt}).optional().catch(()=>(c({path:"availableModels",message:'"availableModels" was present but invalid; enforcing an empty allowlist (only the default model is available) until it is fixed.'}),[]))),st("deniedModels",()=>it.array(it.unknown()).transform((wt)=>{let Pt=[];for(let jt of wt)if(typeof jt==="string")Pt.push(jt);else c({path:"deniedModels",message:`"deniedModels" contained a non-string entry (${jt===null?"null":typeof jt}); the entry was ignored.`});return Pt}).optional().catch(()=>{c({path:"deniedModels",message:'"deniedModels" was present but is not a list of model names, so it was ignored and blocks no models until it is fixed.'});return})),st("allowedHttpHookUrls",()=>bs("allowedHttpHookUrls",it.string(),c,"no HTTP hooks may run")),st("httpHookAllowedEnvVars",()=>bs("httpHookAllowedEnvVars",it.string(),c,"no environment variables may be interpolated into HTTP hook headers")),st("allowedChannelPlugins",()=>bs("allowedChannelPlugins",yG(),c,"no channel plugins admitted",(wt,Pt)=>typeof wt==="string"?`"allowedChannelPlugins" entry "${wt}" was accepted; prefer the documented object form {"plugin": "${Pt.plugin}", "marketplace": "${Pt.marketplace}"}.`:void 0)),st("gatewayInternalNetworks",()=>it.array(it.string()).optional().catch(()=>(c({path:"gatewayInternalNetworks",message:'"gatewayInternalNetworks" was present but invalid; gateway sign-in governed by this source is refused until it is fixed.'}),[Fp]))),st("forceLoginOrgUUID",()=>Ne("forceLoginOrgUUID").catch(()=>(c({path:"forceLoginOrgUUID",message:'"forceLoginOrgUUID" was present but invalid; no organization is permitted to log in until it is fixed.'}),[]))),st("allowedProviders",()=>bs("allowedProviders",it.custom(vi,{message:`not a known provider name (${dr.join(", ")})`}),c,"no API provider may be used, so Claude Code will not start on this machine",void 0,{invalidEntryIsStatusOnly:!0}));let ht=!1,Et=(wt,Pt)=>{let jt=wt.safeParse(Pt);if(jt.success)return;return jt.error.issues.slice(0,3).map((Jt)=>Jt.path.length?`${Jt.path.join(".")}: ${Jt.message}`:Jt.message).join("; ")},Rt;st("policyHelper",()=>it.preprocess((wt)=>{if(ht=!1,Rt=wt,wt&&typeof wt==="object"&&!Array.isArray(wt)){let Pt=wt;for(let jt of["defaultSettings","default",...Cs])if(Pt[jt]!==void 0&&Pt[jt]!==null)c({path:"policyHelper",message:`"${jt}" on the singular policyHelper is ignored — static fallback payloads belong on the policyHelpers per-OS entries ("defaultSettings") or the map's "default" key. The intended fallback will NOT apply from here.`,statusOnly:!0});for(let jt of["policyHelper","policyHelpers"])if(Pt[jt]!==void 0&&Pt[jt]!==null)c({path:"policyHelper",message:`"${jt}" inside the singular policyHelper is ignored — "policyHelper" and "policyHelpers" are TOP-LEVEL settings keys; nothing nests inside the singular entry. The nested config will NOT apply from here.`,statusOnly:!0});for(let jt of gn)if(Pt[jt]!==void 0&&Pt[jt]!==null)c({path:"policyHelper",message:`"${jt}" on the singular policyHelper is ignored — per-OS entries live on the policyHelpers MAP ("policyHelpers": {"${jt}": ...}), not inside the singular key. The intended per-OS config will NOT apply from here.`,statusOnly:!0});if(Pt.claudeMd!==void 0&&Pt.claudeMd!==null)c({path:"policyHelper",message:`"claudeMd" on the singular policyHelper is ignored — "claudeMd" is a managed-settings key: put it at the settings top level or inside a static payload, or emit it from the helper's stdout envelope. The intended instructions will NOT apply from here.`,statusOnly:!0});if(Pt.outputBehavior!==void 0&&Pt.outputBehavior!==null)c({path:"policyHelper",message:`"outputBehavior" on the singular policyHelper is ignored — it is only honored on the policyHelpers per-OS entries (policyHelpers.${gn.join("/")}); this helper's output REPLACES the policy tier whatever the value says.`,statusOnly:!0});if(Pt.onFailure!==void 0&&Pt.onFailure!==null)c({path:"policyHelper",message:`"onFailure" on the singular policyHelper is ignored — it is only honored on the policyHelpers per-OS entries (policyHelpers.${gn.join("/")}); a failure of this helper REFUSES to start Claude Code whatever the value says.`,statusOnly:!0});if(Pt.retries!==void 0&&Pt.retries!==null)c({path:"policyHelper",message:`"retries" on the singular policyHelper is ignored — it is only honored on the policyHelpers per-OS entries (policyHelpers.${gn.join("/")}); this helper is run ONCE per start or refresh, never re-run, whatever the value says.`,statusOnly:!0});if(Pt.path===null||Pt.path===void 0)ht=!0}return wt===null?void 0:wt},Ts().optional()).catch((wt)=>{c({path:"policyHelper",message:`${wt.issues[0]?.message??Et(Ts(),Rt)??"Failed schema validation"}. This field was ignored.`,...ht&&{statusOnly:!0}});return}));let Tt=(wt,Pt)=>{c({path:wt,message:`"${wt}" is not a valid static settings payload: ${Pt??"failed validation"}. When delivered from an OS-admin policy source (MDM or the managed settings file), Claude Code will not start until this is fixed.`,startupFatal:!0})},It=[],Lt=(wt)=>{let Pt=!1,jt,Jt=pa(wt,fo().optional().catch((Qt)=>{Pt=!0,Tt(`policyHelpers.${wt}.defaultSettings`,Qt.issues[0]?.message??Et(fo(),jt&&typeof jt==="object"&&!Array.isArray(jt)?jt.defaultSettings:void 0));return}));return it.preprocess((Qt)=>{if(Pt=!1,jt=Qt,wt!=="default"&&Qt&&typeof Qt==="object"&&!Array.isArray(Qt)){let en=Qt;for(let tn of[...Cs,"claudeMd"])if(en[tn]!==void 0&&en[tn]!==null)c({path:`policyHelpers.${wt}`,message:`"${tn}" on the policyHelpers.${wt} entry is ignored — helper output cannot be pre-seeded on an entry; a static fallback payload goes under this entry's "defaultSettings" (a managed-settings object). The intended content will NOT apply from here.`,statusOnly:!0});for(let tn of["policyHelper","policyHelpers"])if(en[tn]!==void 0&&en[tn]!==null)c({path:`policyHelpers.${wt}`,message:`"${tn}" on the policyHelpers.${wt} entry is ignored — "policyHelper" and "policyHelpers" are TOP-LEVEL settings keys; nothing nests inside an entry. The nested config will NOT apply from here.`,statusOnly:!0});for(let tn of gn)if(en[tn]!==void 0&&en[tn]!==null)c({path:`policyHelpers.${wt}`,message:`"${tn}" on the policyHelpers.${wt} entry is ignored — per-OS entries are SIBLINGS on the policyHelpers map, not nested inside each other. The intended ${tn} config will NOT apply from here.`,statusOnly:!0});if(en.default!==void 0&&en.default!==null)c({path:`policyHelpers.${wt}`,message:`"default" on the policyHelpers.${wt} entry is ignored — the per-entry static payload field is spelled "defaultSettings"; "default" is the MAP's any-platform catch-all key (a sibling of the OS entries). The intended fallback will NOT apply from here.`,statusOnly:!0});let nn=en.onFailure;if(nn!==void 0&&nn!==null&&!vp(nn)){let tn;if(typeof nn==="string"){let Sn=nn.replace(/[^\x20-\x7e]/gu,"?");tn=JSON.stringify(Sn.length>yp?`${Sn.slice(0,yp-1)}…`:Sn)}else if(typeof nn==="number"||typeof nn==="boolean")tn=String(nn);else tn=`a non-string value (${Array.isArray(nn)?"array":typeof nn})`;c({path:`policyHelpers.${wt}.onFailure`,message:`"onFailure": ${tn} on the policyHelpers.${wt} entry is not a recognized value ("continue" or "refuse"); it is treated as "refuse" — a startup failure of this entry's helper with no static payload in its place will not start Claude Code.`,statusOnly:!0})}if(xp(Qt))return}return Qt===null?void 0:Qt},Jt.optional()).catch((Qt)=>{if(wt==="default"){Tt("policyHelpers.default",Qt.issues[0]?.message??Et(fo(),jt));return}if(Pt)return;let en=Et(pa(wt),jt)??"failed validation",nn=jt,tn=nn&&typeof nn==="object"&&!Array.isArray(nn)?nn:null,Sn=tn?.onFailure,Dn=Sn!==void 0&&Sn!==null&&Sn!=="continue",Ln=(un)=>{let yn=`policyHelpers.${wt}`;if(Dn)It.push({entryKey:wt,message:un});else c({path:yn,message:un,statusOnly:!0})};if(tn){let un=tn.defaultSettings;if(un!==void 0&&un!==null){let yn=fo().safeParse(un);if(yn.success){let _n=tn.outputBehavior,In=_n===void 0||_n===null?null:Np().safeParse(_n);if(In&&!In.success){Ln(`Invalid entry was ignored: ${en}. Its "defaultSettings" static payload was NOT kept: "outputBehavior" is unrecognized, so whether the payload replaces or merges over this source's settings is unknown. No policy helper runs on ${wt} from this entry.`);return}return c({path:`policyHelpers.${wt}`,message:`Invalid entry: its helper fields were ignored (${en}), but its "defaultSettings" static payload was kept. No policy helper runs on ${wt} from this entry.`,statusOnly:!0}),{defaultSettings:yn.data,...In&&{outputBehavior:In.data}}}}}Ln(`Invalid entry was ignored: ${en}. No policy helper runs on ${wt} from this entry.`);return})};st("policyHelpers",()=>it.preprocess((wt)=>{if(It=[],wt&&typeof wt==="object"&&!Array.isArray(wt)){let Pt=wt;for(let jt of["defaultSettings",...Cs,"claudeMd"])if(Pt[jt]!==void 0&&Pt[jt]!==null)c({path:"policyHelpers",message:`"${jt}" directly on the policyHelpers map is ignored — static fallback payloads go on a per-OS entry's "defaultSettings" or the map's "default" key (a managed-settings object), and helper-output keys come from the helper's stdout. The intended content will NOT apply from here.`,statusOnly:!0});for(let jt of["policyHelper","policyHelpers"])if(Pt[jt]!==void 0&&Pt[jt]!==null)c({path:"policyHelpers",message:`"${jt}" inside the policyHelpers map is ignored — "policyHelper" and "policyHelpers" are TOP-LEVEL settings keys; the map's keys are the per-OS entries and "default". The nested config will NOT apply from here.`,statusOnly:!0});for(let jt of ua.filter((Jt)=>Jt!=="defaultSettings"))if(Pt[jt]!==void 0&&Pt[jt]!==null){let Jt=jt==="script"||jt==="interpreter"?"; inline scripts are per-OS only (the singular policyHelper key takes a path)":jt==="outputBehavior"||jt==="onFailure"||jt==="retries"?"":", or on the singular policyHelper key";c({path:"policyHelpers",message:`"${jt}" directly on the policyHelpers map is ignored — helper configs go on a per-OS entry (policyHelpers.${gn.join("/")})${Jt}. No helper runs from this field here.`,statusOnly:!0})}}return wt===null?void 0:wt},it.object(Object.fromEntries(ya.map((wt)=>[wt,Lt(wt)]))).transform((wt)=>{for(let Pt of Object.keys(wt))if(wt[Pt]===void 0)delete wt[Pt];for(let{entryKey:Pt,message:jt}of It){let Jt=`policyHelpers.${Pt}`,Qt=Sa(Pt).find((nn)=>wt[nn]?.defaultSettings!==void 0&&wt[nn]?.defaultSettings!==null),en=Qt!==void 0?`${Qt}.defaultSettings`:wt.default!==void 0?"default":null;c(en!==null?{path:Jt,message:`${jt} Its "onFailure" requires the helper; the "policyHelpers.${en}" static payload serves in its place.`,statusOnly:!0}:{path:Jt,message:`${jt} Its "onFailure" requires the helper, so when delivered from an OS-admin policy source (MDM or the managed settings file), Claude Code will not start until this is fixed.`,startupFatal:!0})}return It=[],wt}).optional().catch((wt)=>(c({path:"policyHelpers",message:`"policyHelpers" could not be parsed: expected an object mapping OS keys (${gn.join(", ")}) to helper entries, plus an optional "default" settings payload (${wt.issues[0]?.message??"failed schema validation"}). When delivered from an OS-admin policy source (MDM or the managed settings file), Claude Code will not start until this is fixed.`,startupFatal:!0}),{}))));let Bt=new WeakSet;for(let wt of ce.keys){if(wt==="sandbox"||!vs(wt))continue;st(wt,()=>{let Pt=Ne(wt),jt=Ra(Pt);if(jt===void 0)return Pt.catch((Jt)=>{c({path:wt,message:`${Jt.issues[0]?.message??"Failed schema validation"}. This field was ignored.`});return});return ma(wt,jt,c,{synthesized:Bt,strictField:Pt})})}let xt=Object.freeze({mode:"deny"}),Yt=Object.freeze({accessKeyIdVar:"_STRIPPED_",secretAccessKeyVar:"_STRIPPED_2_"}),Xt=0,Wt=[],qt=new Set,on=new Set,cn=A===void 0?"":`${[...A].reduce((wt,Pt)=>Math.imul(wt^Pt.charCodeAt(0),16777619)>>>0,2166136261).toString(16).toUpperCase().padStart(8,"0")}_`,Nn=(wt,Pt)=>{if(typeof wt!=="object"||wt===null)return;let jt=(an)=>Pt.some((vn)=>vn.path?.includes(an)),Jt=(an)=>{let vn=wt[an];if(typeof vn==="string")return vn;return jt(an)?"":void 0},Qt=Jt("accessKeyIdVar"),en=Jt("secretAccessKeyVar"),nn=Jt("sessionTokenVar"),tn=Kn;if(![Qt,en,nn].some((an)=>an!==void 0&&tn.includes(an)))return;let Sn=(an)=>an!==void 0&&No().safeParse(an).success;Xt+=1;let Dn=(an)=>`${hi}${an}_${cn}${Xt}_`,Ln=Sn(Qt)?Qt:Dn("ACCESS_KEY_ID"),un=Sn(en)&&en!==Ln?en:Dn("SECRET_ACCESS_KEY"),yn=nn===void 0?void 0:Sn(nn)&&nn!==Ln&&nn!==un?nn:Dn("SESSION_TOKEN"),_n=(an)=>an.startsWith(hi);if(!_n(Ln)&&!_n(un)){let an=tn.includes(un)?un:void 0;if(un=Dn("SECRET_ACCESS_KEY"),an!==void 0){let vn=Nn({accessKeyIdVar:an},[]);if(vn!==void 0)Wt.push(vn)}}let In=is().safeParse({accessKeyIdVar:Ln,secretAccessKeyVar:un,...yn!==void 0&&{sessionTokenVar:yn}});return In.success?In.data:void 0},Hn=(wt,Pt,jt)=>it.array(Pt.catch((Jt)=>{let Qt=jt(Jt.value);if(Qt!==void 0)return c({path:`sandbox.credentials.${wt}[]`,message:`Invalid entry was degraded to mode "deny": ${Jt.issues[0]?.message??"failed validation"}. The credential stays blocked (not masked) until the entry is fixed.${wt==="files"?" Under sandbox.filesystem.disabled, file read-denies are not enforced.":""}`,substituted:!0}),Qt;return c({path:`sandbox.credentials.${wt}[]`,message:`Invalid entry was ignored: ${Jt.issues[0]?.message??"failed validation"}. This credential is NOT protected until the entry is fixed.`}),xt})).transform((Jt)=>{let Qt=Jt.filter((en)=>en!==xt);if(Jt.length>0&&Qt.length===0)qt.add(wt);return Qt}).optional().catch((Jt)=>{if(typeof Jt.value==="object"&&Jt.value!==null&&!Array.isArray(Jt.value)){let Qt=Pt.safeParse(Jt.value);if(Qt.success)return c({path:`sandbox.credentials.${wt}`,message:`"${wt}" must be an array; a lone entry object was accepted as a one-element list. Wrap it in [ ] to silence this warning.`}),[Qt.data];let en=jt(Jt.value);if(en!==void 0)return c({path:`sandbox.credentials.${wt}`,message:`"${wt}" must be an array; its lone entry object was invalid and was degraded to mode "deny". The credential stays blocked (not masked) until it is fixed.`,substituted:!0}),[en]}return c({path:`sandbox.credentials.${wt}`,message:`${Jt.issues[0]?.message??"Invalid value"}. "${wt}" was ignored; these credential entries are NOT protected until it is fixed.`}),qt.add(wt),[]});st("sandbox",()=>{let wt=it.object({files:Hn("files",os(),(Pt)=>{if(typeof Pt!=="object"||Pt===null||!("mode"in Pt)||Pt.mode!=="mask"&&Pt.mode!=="deny"||!("path"in Pt)||typeof Pt.path!=="string")return;let jt=os().safeParse({path:Pt.path,mode:"deny"});return jt.success?jt.data:void 0}),envVars:Hn("envVars",rs(),(Pt)=>{if(typeof Pt!=="object"||Pt===null||!("mode"in Pt)||Pt.mode!=="mask"&&Pt.mode!=="deny"||!("name"in Pt)||typeof Pt.name!=="string")return;let jt=rs().safeParse({name:Pt.name,mode:"deny"});return jt.success?jt.data:void 0}),allowPlaintextInject:fa("sandbox.credentials.allowPlaintextInject",Bo().get("sandbox.credentials.allowPlaintextInject"),it.boolean().optional(),c).catch((Pt)=>(c({path:"sandbox.credentials.allowPlaintextInject",message:`${Pt.issues[0]?.message??"Invalid value"}. "allowPlaintextInject" was degraded to an explicit false; plaintext credential injection stays disabled (lower-precedence values cannot enable it) until it is fixed.`,substituted:!0}),qt.add("allowPlaintextInject"),!1)),awsPairs:it.array(is().catch((Pt)=>{let jt=Nn(Pt.value,Pt.issues);if(jt!==void 0)return c({path:"sandbox.credentials.awsPairs[]",message:`Invalid pair was degraded to a non-functional suppressor: ${Pt.issues[0]?.message??"failed validation"}. It keeps implicit AWS auto-pairing suppressed but re-signs nothing until it is fixed.`,substituted:!0}),jt;return c({path:"sandbox.credentials.awsPairs[]",message:`Invalid pair was ignored: ${Pt.issues[0]?.message??"failed validation"}. SigV4 re-signing stays unconfigured for this pair until it is fixed.`}),Yt})).transform((Pt)=>{let jt=Pt.filter((Jt)=>Jt!==Yt);if(Wt.length>0)jt.push(...Wt),Wt.length=0;if(Pt.length>0&&jt.length===0)qt.add("awsPairs");return jt}).optional().catch((Pt)=>{let jt=typeof Pt.value==="object"&&Pt.value!==null?Nn(Pt.value,[]):void 0,Jt=typeof Pt.value==="object"&&Pt.value!==null&&(("accessKeyIdVar"in Pt.value)||("secretAccessKeyVar"in Pt.value)||("sessionTokenVar"in Pt.value));if(jt===void 0&&Jt)return Wt.length=0,c({path:"sandbox.credentials.awsPairs",message:`${Pt.issues[0]?.message??"Invalid value"}. "awsPairs" must be an array; its lone pair-shaped entry claimed no conventional AWS name and was ignored. SigV4 re-signing stays unconfigured until it is fixed.`}),qt.add("awsPairs"),[];let Qt=jt!==void 0?[jt]:Kn.flatMap((en)=>{let nn=Nn({accessKeyIdVar:en},[]);return nn!==void 0?[nn]:[]});if(Wt.length>0)Qt.push(...Wt),Wt.length=0;if(jt===void 0)qt.add("awsPairs");return c({path:"sandbox.credentials.awsPairs",message:`${Pt.issues[0]?.message??"Invalid value"}. "awsPairs" was degraded to non-functional suppressor pair(s); implicit AWS auto-pairing stays suppressed but nothing re-signs until it is fixed.`,substituted:!0}),Qt}),sigv4:it.object(Object.fromEntries(["streaming","presigned","sigv4a"].map((Pt)=>[Pt,it.enum(["deny","passthrough"]).optional().catch((jt)=>(c({path:`sandbox.credentials.sigv4.${Pt}`,message:`${jt.issues[0]?.message??"Invalid value"}. "${Pt}" was degraded to an explicit deny; this SigV4 request shape stays denied until it is fixed.`,substituted:!0}),on.add(Pt),"deny"))]))).transform((Pt)=>{let jt=Object.entries(Pt).filter(([,Jt])=>Jt!==void 0);if(jt.length>0&&jt.every(([Jt])=>on.has(Jt)))qt.add("sigv4");return on.clear(),Pt}).optional().catch((Pt)=>(c({path:"sandbox.credentials.sigv4",message:`${Pt.issues[0]?.message??"Invalid value"}. "sigv4" was degraded to an all-deny block (all shapes stay denied, and lower-precedence sigv4 values cannot take effect) until it is fixed.`,substituted:!0}),on.clear(),qt.add("sigv4"),{streaming:"deny",presigned:"deny",sigv4a:"deny"}))}).transform((Pt)=>{let jt=Object.entries(Pt).filter(([,Jt])=>Jt!==void 0);if(jt.length>0&&jt.every(([Jt])=>qt.has(Jt)))Bt.add(Pt);return qt.clear(),Pt}).optional().catch((Pt)=>{c({path:"sandbox.credentials",message:`${Pt.issues[0]?.message??"Failed schema validation"}. The credentials block was degraded to a fail-closed skeleton (all-deny sigv4, implicit AWS auto-pairing suppressed, no masking) until it is fixed.`,substituted:!0});let jt=Kn.flatMap((Qt)=>{let en=Nn({accessKeyIdVar:Qt},[]);return en!==void 0?[en]:[]});Wt.length=0,qt.clear(),on.clear();let Jt={allowPlaintextInject:!1,awsPairs:jt,sigv4:{streaming:"deny",presigned:"deny",sigv4a:"deny"}};return Bt.add(Jt),Jt});return ma("sandbox",Ei(),c,{override:{"sandbox.credentials":wt},skeletonExclude:new Set(["sandbox.enabled"]),neverSubstitute:new Set(["sandbox.failIfUnavailable"]),synthesized:Bt})});let dn={};for(let wt of ce.keys){if(!me(wt))continue;let Pt=Fe.get(wt);dn[wt]=Pt?Pt():Ne(wt).catch((jt)=>{c({path:wt,message:`${jt.issues[0]?.message??"Failed schema validation"}. This field was ignored.`});return})}for(let[wt,Pt]of Fe)if(!(wt in dn)&&me(wt))dn[wt]=Pt();return it.object(dn).passthrough().check((wt)=>{wt.issues.push(...ce.wrongDocumentIssues(wt.value,dn))}).transform((wt)=>{for(let Jt of Object.keys(wt))if(wt[Jt]===void 0)delete wt[Jt];let Pt=Object.keys(wt).filter((Jt)=>!mo.some((Qt)=>Qt===Jt)&&!Or(wt[Jt])),jt=Pt.length>0&&Pt.every((Jt)=>gt.has(Jt)||Bp(Bt,wt[Jt]));if(gt.clear(),jt)for(let Jt of Pt)c({path:Jt,message:`"${Jt}" holds nothing that could be applied as written and is this source's only policy content; its fail-closed reading binds (beside a lower managed settings source's policy, when one supplies it) until it is fixed.`,statusOnly:!0,onlySubstitutes:!0});return wt})}function qG(){let c=dt();return c!==void 0&&pt(c)}function jp(){let c=C(),A=c==="wsl"&&!qG()?"linux":c;switch(A){case"unknown":return{platform:A,chain:[]};default:return{platform:A,chain:Sa(A)}}}var Go=[{alias:"additionalMarketplaces",canonical:"extraKnownMarketplaces"},{alias:"allowedMarketplaces",canonical:"strictKnownMarketplaces"}];function $p(c,A,L){if(!r(c))return[];let ce=[];for(let{alias:me,canonical:Ne}of Go){if(!(me in c))continue;if(c[me]===null){if(!(Ne in c)&&L?.loneNullAlias==="rename")c[Ne]=null;delete c[me];continue}if(Ne in c&&c[Ne]!==null)ce.push({file:A,path:me,message:`"${me}" is an alias for "${Ne}" and this file sets both; the "${me}" value was ignored. Use only "${Ne}".`,severity:"warning",alias:me,canonical:Ne});else c[Ne]=c[me];delete c[me]}return ce}function Ia(c){if(typeof c!=="object"||c===null)return!1;let A=Object.getPrototypeOf(c);return A===Object.prototype||A===null}function ks(c){if(Array.isArray(c))return c.map(ks);if(c!==null&&typeof c==="object"){let A={};for(let L of Object.keys(c).sort())A[L]=ks(c[L]);return A}return c}var tW=["enabled","enabledPlatforms"],Ar="network.allowedDomains",nW=new Set(["OTEL_LOG_MANAGED_SETTINGS"]);function Yp(c){if(!c)return{shellSettings:{},envVars:{},sandboxSettings:{},isolationSettings:{},hasHooks:!1,payloadSlots:{}};let A=Xp(c),L=oW(c);rW([A,...L.map(([,Fe])=>Fe)]);let ce={};for(let[Fe,st]of L){let gt={shellSettings:st.hasHooks?{...st.shellSettings,hooks:qn(st.hooks)}:st.shellSettings,envVars:st.envVars,sandboxSettings:st.sandboxSettings,isolationSettings:st.isolationSettings};if(qp(gt))ce[Fe]=gt}let{sandboxSwitches:me,...Ne}=A;return{...Ne,payloadSlots:ce}}function Xp(c){let A={},L;for(let Rt of Id){let Tt=c[Rt];if(Rt==="policyHelpers"){if(Tt!==null&&typeof Tt==="object")for(let Lt of gn){let Bt=pW(Tt[Lt]);if(Bt){if(A[`policyHelpers.${Lt}`]=Bt.command,Bt.scriptSize)L??={},L[`policyHelpers.${Lt}`]=Bt.scriptSize}}continue}let It;if(typeof Tt==="string")It=Tt;else if(Tt!==null&&typeof Tt==="object"&&"command"in Tt&&typeof Tt.command==="string")It=Tt.command;if(It!==void 0&&It.length>0)A[Rt]=It}let ce=_W(c);if(ce&&typeof ce==="object")for(let[Rt,Tt]of Object.entries(ce)){let It=Tt?.source;if(!It||typeof It!=="object")continue;if(It.source==="url"&&typeof It.headersHelper==="string"&&It.headersHelper.length>0)A[`extraKnownMarketplaces[${t(Rt)}].source.headersHelper`]=Kp(It.headersHelper,"url",It.url);if(It.source==="settings"&&Array.isArray(It.plugins)){let Lt=new Map;for(let Bt of It.plugins){let xt=t(Bt?.name),Yt=Lt.get(xt)??0;Lt.set(xt,Yt+1);let Xt=Bt?.source;if(Xt!==null&&typeof Xt==="object"&&"source"in Xt&&Xt.source==="command"&&"command"in Xt&&typeof Xt.command==="string"&&Xt.command.length>0)A[`extraKnownMarketplaces[${t(Rt)}].plugins[${t(Bt.name)}][${Yt}].source.command`]=Xt.command;if(typeof Bt?.headersHelper==="string"&&Bt.headersHelper.length>0){let Wt=Bt.source,qt=Wt!==null&&typeof Wt==="object";A[`extraKnownMarketplaces[${t(Rt)}].plugins[${t(Bt.name)}][${Yt}].headersHelper`]=Kp(Bt.headersHelper,qt&&"source"in Wt?Wt.source:void 0,qt&&"url"in Wt?Wt.url:void 0)}}}}let me=c.sandbox,Ne={},Fe={enabled:Wo(me,"enabled"),enabledPlatforms:Wo(me,"enabledPlatforms"),[Ar]:Wo(me,Ar)};if(me!==null&&typeof me==="object"){let Rt={enabled:Fe.enabled,enabledPlatforms:Fe.enabledPlatforms};for(let Tt of Di){let It=gW(me[Tt]);if(It)A[`sandbox.${Tt}`]=qn({value:It,...Rt})}for(let Tt of Pd){let It=Wo(me,Tt);if(sW(Tt,It))Ne[`sandbox.${Tt}`]=qn({value:It,...Rt,...Qp.has(Tt)&&{allowedDomains:ef(Fe[Ar])}})}}let st=c.isolation,gt={};for(let Rt of wd){let Tt=Wo(st,Rt);if(iW(Rt,Tt))gt[`isolation.${Rt}`]=qn({value:Tt})}let ht={};if(c.env&&typeof c.env==="object")for(let[Rt,Tt]of Object.entries(c.env)){if(Tt===void 0)continue;let It=String(Tt);if(It.length>0&&!nW.has(Rt.toUpperCase())&&!xd(Rt,It))ht[Rt]=It}let Et=c.hooks!==void 0&&c.hooks!==null&&typeof c.hooks==="object"&&Object.keys(c.hooks).length>0;return{shellSettings:A,inlineHelperScriptSizes:L,envVars:ht,sandboxSettings:Ne,isolationSettings:gt,hasHooks:Et,hooks:Et?c.hooks:void 0,sandboxSwitches:Fe}}function oW(c){return wa(c).map(([A,L])=>[A,Xp(L)])}function wa(c){let A=[];for(let L of Zp){let ce=`policyHelpers.${L}`,me=Wo(c,ce);if(!Ia(me))continue;let{policyHelper:Ne,policyHelpers:Fe,...st}=me;A.push([ce,st])}return A}function Jp(c){return gn.find((A)=>c===`policyHelpers.${A}.defaultSettings`)}function rW(c){let A=c.map((ce)=>Object.keys(ce.sandboxSettings).length>0||Di.some((me)=>ce.shellSettings[`sandbox.${me}`]!==void 0)),L=c.map((ce)=>[...Qp].some((me)=>ce.sandboxSettings[`sandbox.${me}`]!==void 0));c.forEach((ce,me)=>{if(A.some((Ne,Fe)=>Ne&&Fe!==me))for(let Ne of tW){let Fe=ce.sandboxSwitches[Ne];if(Fe!==void 0)ce.sandboxSettings[`sandbox.${Ne}`]=qn({value:Fe})}if(L.some((Ne,Fe)=>Ne&&Fe!==me)){let Ne=ce.sandboxSwitches[Ar];if(Ne!==void 0)ce.sandboxSettings[`sandbox.${Ar}`]=qn({value:ef(Ne)??Ne})}})}var Zp=[...gn.map((c)=>`${c}.defaultSettings`),"default"];function Pa(c){let A=[];for(let L of Zp){let ce=`policyHelpers.${L}`,me=c.payloadSlots[ce];if(me!==void 0&&qp(me))A.push([ce,me])}return A}function qp(c){return Object.keys(c.shellSettings).length>0||Object.keys(c.envVars).length>0||Object.keys(c.sandboxSettings).length>0||Object.keys(c.isolationSettings).length>0}var Qp=new Set(["credentials","network.tlsTerminate"]);function ef(c){return Array.isArray(c)?v(c.filter((A)=>typeof A==="string")).sort():void 0}function Wo(c,A){let L=c;for(let ce of A.split(".")){if(L===null||typeof L!=="object")return;L=L[ce]}return L}function sW(c,A){if(A===void 0||A===null||A===!1)return!1;if(Array.isArray(A)&&A.length===0)return!1;return!(c==="credentials"&&lW(A))}function iW(c,A){if(A===void 0||A===null)return!1;switch(c){case"required":return A!==!1;case"egress":return!Ia(A)||Object.entries(A).some(([L,ce])=>aW.has(L)?ce!==void 0&&ce!==null&&!(Array.isArray(ce)&&ce.length===0):ce!==void 0)}}var aW=new Set(["allowedHosts","deniedHosts"]);function lW(c){if(typeof c!=="object"||c===null)return!1;return Object.entries(c).every(([A,L])=>{if(L===void 0)return!0;if(A==="files"||A==="envVars")return Array.isArray(L)&&L.every((ce)=>typeof ce==="object"&&ce!==null&&ce.mode==="deny");if(A==="sigv4")return typeof L==="object"&&L!==null&&Object.values(L).every((ce)=>ce===void 0||ce==="deny");return A==="allowPlaintextInject"&&L===!1})}function cW(c){return Object.keys(c.shellSettings).some(dW)}function dW(c){return gn.some((A)=>c===`policyHelpers.${A}`)}function tf(c){return cW(c)||Object.keys(c.shellSettings).some((A)=>A.startsWith("extraKnownMarketplaces["))||Pa(c).length>0}function uW(c){return c==="sh"||c==="pwsh"}function pW(c){if(c===null||typeof c!=="object")return;let{path:A,script:L,interpreter:ce,timeoutMs:me,refreshIntervalMs:Ne}=c,Fe,st;if(typeof A==="string"&&A)Fe=A;else if(typeof L==="string"&&L&&uW(ce))Fe={interpreter:ce,script:mW(L)},st=fW(L);else return;return{command:t([Fe,me??null,Ne??null]),scriptSize:st}}function fW(c){return{bytes:Buffer.byteLength(c,"utf8"),lines:Dt(c,`
`)+(c.endsWith(`
`)?0:1)}}function mW(c){return ft(t(c))}function gW(c){if(typeof c==="string")return c||void 0;if(c===null||typeof c!=="object"||!("command"in c)||typeof c.command!=="string"||!c.command)return;let A="args"in c&&Array.isArray(c.args)?c.args.map(String):[];return t([c.command,...A])}function hW(c){return qn(nf(c))}function nf(c){return{shellSettings:c.shellSettings,envVars:c.envVars,sandboxSettings:Object.keys(c.sandboxSettings).length>0?c.sandboxSettings:void 0,...Vp(c),hooks:c.hooks,payloadSlots:Pa(c).length>0?Object.fromEntries(Pa(c).map(([A,L])=>{let{isolationSettings:ce,...me}=L;return[A,{...me,...Vp(L)}]})):void 0}}function Vp(c){return Object.keys(c.isolationSettings).length>0?{isolationSettings:c.isolationSettings}:{}}function qn(c){return t(ks(c))}function of(c){return ft(hW(c))}function rf(c,A,L){if(of(A)===c)return!0;return typeof L==="string"&&L.length>0&&ft(qn({...nf(A),claudeMd:L}))===c}function Kp(c,A,L){return t([c,typeof A==="string"?A:null,typeof L==="string"?L:null])}var EW=new Set(["dns","unix","ipv4","ipv6"]),Cq=new Set([...EW,"http","https","ws","wss","ftp","file","grpc","grpcs","otlp","xds","tcp","udp","tls","h2","h2c","http2"]);function sf(c){return c.replace(/[^\x20-\x7e]/gu,"?")}function _W(c){let A=c.extraKnownMarketplaces;if(A!==void 0&&A!==null)return A;let L=c;for(let{alias:ce,canonical:me}of Go){if(me!=="extraKnownMarketplaces")continue;let Ne=L[ce];if(Ne!==void 0&&Ne!==null&&typeof Ne==="object")return Ne}return}var yW="remote-settings.json";var df="remote-settings-helper-consent";function OW(){return cf(m(),df)}function AW(c){let A=Yp(c);return tf(A)?A:void 0}function bW(c){return oo(c,(A,L)=>L.startsWith("$")&&L!=="$schema")}class uf{sessionCache=null;eligible=void 0;eligibilityMemo=void 0;ineligibleReason=void 0;evalPolicySnapshotOnly=!1;lastLoadStatus=void 0;lastLoadStatusChanged=i();policySettingsNotified=!1;verifiedPayload=null;unverifiedView=null;projectedView=null;projectedParse=null;consentedPayload=null;deferredPayload=null;resetEpoch=0;backendView=void 0;replaceSessionCache(c,A){if(this.sessionCache=c,A?.verified){if(this.verifiedPayload=c,A.consentDeferred)this.deferredPayload=c}}seedFromDisk(c){this.sessionCache=c;let A=AW(c);if(A!==void 0){let L=xW();if(L===void 0||!rf(L,A,c.claudeMd))return}this.consentedPayload??=c}markConsented(c){this.consentedPayload=c}dropConsentDeferral(){this.deferredPayload=null}markPolicySettingsNotified(){this.policySettingsNotified=!0}recordEligibility(c,A){if(this.eligible=c,A.memoize)this.eligibilityMemo=c,this.ineligibleReason=c?void 0:A.ineligibleReason}resetListener=null;registerResetListener(c){if(this.resetListener!==null)throw Error("registerSyncCacheResetListener: a listener is already registered; a second one would unhook the first");this.resetListener=c}reset(){this.sessionCache=null,this.eligible=void 0,this.eligibilityMemo=void 0,this.ineligibleReason=void 0,this.evalPolicySnapshotOnly=!1,this.lastLoadStatus=void 0,this.policySettingsNotified=!1,this.verifiedPayload=null,this.unverifiedView=null,this.projectedView=null,this.projectedParse=null,this.consentedPayload=null,this.deferredPayload=null,this.resetEpoch++,this.emitLoadStatusChanged(void 0)}emitLoadStatusChanged(c){try{this.lastLoadStatusChanged.emit(c)}catch(A){e(`Remote settings: load-status listener threw: ${y(A)}`,{level:"error"})}}}var CW=new a(()=>new uf);function go(){return CW.of(R().host)}function pf(){return go().lastLoadStatus}function jo(){return}function TW(){return go().evalPolicySnapshotOnly}function xa(){return pe()||TW()}function ff(c){let{projectedView:A,projectedParse:L}=go();return c!==null&&(A?.view===c||L?.view===c)}var RW=[["allowedHttpHookUrls"],["httpHookAllowedEnvVars"],["isolation","required"]],mf=[{path:["sandbox","credentials","files"],names:"path"},{path:["sandbox","credentials","envVars"],names:"name"}];function DW(c){for(let L of RW)fn(c,L,void 0);for(let{path:L,names:ce}of mf){let me=pn(c,L),Ne=(Array.isArray(me)?me:[me]).flatMap((Fe)=>r(Fe)&&typeof Fe[ce]==="string"?[{[ce]:Fe[ce],mode:"deny"}]:[]);fn(c,L,Ne.length>0?Ne:void 0)}for(let L of[["permissions","deny"],["permissions","ask"]]){let ce=pn(c,L);if(Array.isArray(ce)){let me=ce.filter((Ne)=>typeof Ne!=="string"||!rr.test(Ne));fn(c,L,me)}}for(let{path:L,restrictive:ce}of Mn()){let me=pn(c,L),Ne=L[0]==="strictPluginOnlyCustomization"?me:Ho(me);if(ce===!0&&Ne===!1)fn(c,L,void 0)}let A=c.strictPluginOnlyCustomization;if(Array.isArray(A)&&!A.some((L)=>Sr.includes(L)))delete c.strictPluginOnlyCustomization;if(c.availableModelsMatch==="prefix")delete c.availableModelsMatch}function af(c){if(!c||!xa())return c;let A={...Od(c)};if(pe())DW(A);return{...A,managedSourcesBehavior:"merge"}}function LW(){return jo()===void 0&&ts()}function IW(){return jo()??cf(m(),yW)}var gf=8388608;function PW(){if(LW())return null;try{let c=NW();if(c===null)return null;let A=O(he(c));if(!A||typeof A!=="object"||Array.isArray(A))return null;return bW(A)}catch(c){if(Dl(c))e(`Remote settings: Disk cache exceeds ${gf} bytes; ignoring it as if absent`);return null}}var wW=4096;function xW(){let c=Na();if(c!==void 0)return c.attestation;try{return eo(OW(),wW).trim()||void 0}catch{return}}function NW(){let c=Na();if(c!==void 0)return c.content;if(pe()&&jo()===void 0)return null;return eo(IW(),gf)}function Na(){let c=go().backendView;if(!l()||c===void 0||!c.ready||c.stoodDown||jo()!==void 0)return;if(!Nt(c.configHome)){c.standDown("config home changed");return}return c}var n9=ue.state("remote-settings"),o9=ue.state(df);var vW=new Set(["HTTPS_PROXY","HTTP_PROXY","NO_PROXY","CLAUDE_CODE_PROXY_RESOLVES_HOSTS","CLAUDE_CODE_ENABLE_PROXY_AUTH_HELPER","CLAUDE_CODE_PROXY_AUTH_HELPER_TTL_MS","API_FORCE_IDLE_TIMEOUT","ANTHROPIC_UNIX_SOCKET","NODE_EXTRA_CA_CERTS","CLAUDE_CODE_CERT_STORE","CLAUDE_CODE_CLIENT_CERT","CLAUDE_CODE_CLIENT_KEY","CLAUDE_CODE_CLIENT_KEY_PASSPHRASE","ALL_PROXY","NODE_OPTIONS","NODE_TLS_REJECT_UNAUTHORIZED",...Si,...yi,"AWS_ENDPOINT_URL_STS","AWS_ENDPOINT_URL","AWS_ENDPOINT_URL_SSO","AWS_ENDPOINT_URL_SSO_OIDC","AWS_ENDPOINT_URL_BEDROCK","AWS_ENDPOINT_URL_BEDROCK_RUNTIME",...Ci,...Ti,...Ri,"CLOUDSDK_CONFIG","GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES","GCLOUD_PROJECT","CLAUDE_CODE_CUSTOM_OAUTH_URL",...Oi,"CLAUDE_CODE_API_BASE_URL","CLAUDE_CODE_OAUTH_REFRESH_TOKEN","CLAUDE_CODE_OAUTH_SCOPES","CLAUDE_CODE_OAUTH_CLIENT_ID","CLAUDE_CODE_SESSION_ACCESS_TOKEN","CLAUDE_SESSION_INGRESS_TOKEN_FILE","CLAUDE_CODE_ENVIRONMENT_KIND","CLAUDE_CODE_REMOTE_SESSION_ID","ANTHROPIC_FEDERATION_RULE_ID","ANTHROPIC_ORGANIZATION_ID","ANTHROPIC_WORKSPACE_ID","ANTHROPIC_SERVICE_ACCOUNT_ID","ANTHROPIC_IDENTITY_TOKEN","ANTHROPIC_IDENTITY_TOKEN_FILE","ANTHROPIC_SCOPE","ANTHROPIC_PROFILE","ANTHROPIC_CONFIG_DIR","CLAUDE_CODE_FEDERATION_CACHE_DIR","HOME","XDG_CONFIG_HOME","APPDATA","USERPROFILE","HOMEDRIVE","HOMEPATH","PROGRAMDATA","ALLUSERSPROFILE","ANTHROPIC_CUSTOM_HEADERS","CLAUDE_CODE_HOST_CREDS_FILE","CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST","CLAUDE_CODE_HOST_AUTH_ENV_VAR","CLAUDE_CONFIG_DIR","CLAUDE_SECURESTORAGE_CONFIG_DIR","CLAUDE_CODE_REMOTE_SETTINGS_PATH","CLAUDE_CODE_MANAGED_SETTINGS_PATH","CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION","CLAUDE_CODE_MOCK_REMOTE_SETTINGS","USE_LOCAL_OAUTH","USE_STAGING_OAUTH","CLAUDE_LOCAL_OAUTH_API_BASE","CLAUDE_LOCAL_OAUTH_APPS_BASE","CLAUDE_LOCAL_OAUTH_CONSOLE_BASE","CLAUDE_BRIDGE_BASE_URL","CLAUDE_BRIDGE_OAUTH_TOKEN","CLAUDE_BRIDGE_SESSION_INGRESS_URL","CLAUDE_REMOTE_TOOLS_BRIDGE_URL","CLAUDE_CODE_GB_BASE_URL"].map((c)=>c.toUpperCase()));function kW(c){if(!c||!c.env&&!("managedMcpServers"in c))return c;let{managedMcpServers:A,...L}=c;return c.env?{...L,env:oo(c.env,(ce,me)=>vW.has(me.toUpperCase()))}:L}function hf(){let c=_f();if(c===null||xa()||Ef(go(),c))return!1;if(lf(c))return!0;let A=wa(c);if(A.length===0)return!1;let{chain:L}=jp();return A.some(([ce,me])=>{let Ne=Jp(ce);return(Ne===void 0||L.includes(Ne))&&lf(me)})}function lf(c){let A=c.managedMcpServers;return r(A)&&Object.keys(A).length>0}function Ef(c,A){return A===c.verifiedPayload||Boolean(jo())}function _f(){let c=go();if(!jo()&&c.eligible!==!0)return null;if(c.sessionCache)return c.sessionCache;let A=Na()!==void 0,L=PW();if(L){if(c.seedFromDisk(L),A)Se().invalidatePolicyLayer();else zt();return L}return null}function Sf(c){let A=_f(),L=go(),ce=Ef(L,A)?A:MW(L,A);if(ce===null||!xa())return ce;if(L.projectedView?.raw!==ce)L.projectedView={raw:ce,view:af(ce)};let me=L.projectedView.view;if(!c)return me;if(L.projectedParse?.raw!==ce){let Ne={...me};if(yf(Ne,af(c(ce))??{}),pe())for(let{path:Fe,names:st}of mf){let gt=[me,Ne].flatMap((ht)=>pn(ht,Fe)??[]);if(gt.length>0)fn(Ne,Fe,dd(gt,st))}L.projectedParse={raw:ce,view:Ne}}return L.projectedParse.view}function yf(c,A){for(let[L,ce]of Object.entries(A)){let me=c[L];if(me!==ce&&r(me)&&r(ce)){let Ne={...me};yf(Ne,ce),c[L]=Ne}else c[L]=ce}}function MW(c,A){if(A===null)return null;if(c.unverifiedView?.raw!==A)c.unverifiedView={raw:A,view:kW(A)};return c.unverifiedView.view}var UW=ke(new Set,(c)=>c.clear());function Of(c){UW.add(c)}var HW=process.platform==="darwin"?16777216:process.platform==="linux"||process.platform==="android"?524288:0,a9=process.platform==="darwin"?536870912:0,l9=process.platform==="linux"||process.platform==="android"?2097152:0;var O9=ke({noFollowAny:"untried",localVolumes:void 0},(c)=>{c.noFollowAny="untried",c.localVolumes=void 0});var A9=Symbol("no procfs"),b9=Symbol("descriptor path unreadable");var C9=Symbol("boundRead.linkToNothing");function Af(c,A,L){if(c===A)return 0;let ce=c.length,me=A.length,Ne=L+1;if(Math.abs(ce-me)>L)return Ne;let Fe=new Int32Array(me+2).fill(Ne),st=new Int32Array(me+2).fill(Ne),gt=new Int32Array(me+2).fill(Ne);for(let ht=0;ht<=Math.min(me,L);ht++)st[ht]=ht;for(let ht=1;ht<=ce;ht++){let Et=Math.max(1,ht-L),Rt=Math.min(me,ht+L);gt[Et-1]=Et===1?Math.min(ht,Ne):Ne;let Tt=gt[Et-1];for(let It=Et;It<=Rt;It++){let Lt=Math.min(st[It]+1,gt[It-1]+1,st[It-1]+(c[ht-1]===A[It-1]?0:1),Ne);if(ht>1&&It>1&&c[ht-1]===A[It-2]&&c[ht-2]===A[It-1])Lt=Math.min(Lt,Fe[It-2]+1);gt[It]=Lt,Tt=Math.min(Tt,Lt)}if(gt[Rt+1]=Ne,Tt>L)return Ne;[Fe,st,gt]=[st,gt,Fe]}return st[me]}var bf=["claude-3-5-haiku","claude-3-5-sonnet","claude-3-7-sonnet","claude-fable-5","claude-fable-5-1","claude-haiku-4-5","claude-haiku-5-5","claude-mythos-5","claude-mythos-5-1","claude-opus-4-0","claude-opus-4-1","claude-opus-4-5","claude-opus-4-6","claude-opus-4-7","claude-opus-4-8","claude-opus-5","claude-opus-5-5","claude-sonnet-4-0","claude-sonnet-4-5","claude-sonnet-4-6","claude-sonnet-5","claude-sonnet-5-5"],Cf=["sonnet","opus","haiku","fable","best","sonnet[1m]","opus[1m]","fable[1m]","opusplan"],Qn=["sonnet","opus","haiku","fable"];function Ms(c){return Cf.includes(c)}function va(c){return c.replace(/\[1m\]$/i,"")}function Tf(c){return c.replace(/\[(1|2)m\]/gi,"")}function ho(c){return Qn.includes(c)}function Bn(c){let A=c.trim().toLowerCase();if(A===""||/\s/.test(A))return null;A=A.replace(/\[[12]m\]$/,"");let L=A.lastIndexOf("/");if(L!==-1)A=A.slice(L+1);let ce=/^(?:([a-z-]+)\.)?anthropic\.(claude-.*)$/.exec(A);if(ce){let[,st,gt=""]=ce;if(st!==void 0&&!Al.includes(st))return null;A=gt}let me=FW(A);if(!me)return null;let Ne=A.slice(me.base.length);if(Ne!==""&&!/^[-@]/.test(Ne))return null;let Fe={family:me.family,major:me.major,legacyVersionFirst:me.legacyVersionFirst,base:me.base};if(me.minor!==void 0)Fe.minor=me.minor;if(!zW(Ne))Fe.trailer=Ne;else{let st=/(?:-v\d+@|[-@])(\d{8})/.exec(Ne)?.[1];if(st!==void 0)Fe.date=st}return Fe}function zW(c){return/^(?:-fast|-latest)?(?:-v\d{1,3}@\d{8}|[-@]\d{8})?(?:-v\d{1,3}(?::\d{1,3})?)?$/.test(c)}function Rf(c,A){return c.major-A.major||(c.minor??0)-(A.minor??0)}function FW(c){let A=/^claude-([a-z]+)-(\d{1,2})(?!\d)(?:-(\d{1,2})(?!\d))?/.exec(c);if(A){let[ce,me="",Ne="",Fe]=A;return{family:me,major:Number(Ne),minor:Fe===void 0?void 0:Number(Fe),legacyVersionFirst:!1,base:ce}}let L=/^claude-(\d{1,2})(?!\d)(?:-(\d{1,2})(?!\d))?-([a-z]+)/.exec(c);if(L){let[ce,me="",Ne,Fe=""]=L;return{family:Fe,major:Number(me),minor:Ne===void 0?void 0:Number(Ne),legacyVersionFirst:!0,base:ce}}return null}function Cn(c){let A=c.replace(/[\u0000-\u001f\u007f-\u009f]/g,"?");return A.length>128?`${A.slice(0,128)}…`:A}function BW(){let c=[...Qn],A=c.pop();return c.length===0?A??"":`${c.join(", ")} or ${A}`}function Us(c){return c.charAt(0).toUpperCase()+c.slice(1)}function Df(c){let A=c.trim().toLowerCase(),L=Tf(A).trim(),ce=L!==A?" Context-size tags such as [1m] are ignored: the entry blocks the model at every context size.":"";if(L==="")return{entry:null,warning:"An empty deniedModels entry was ignored."};if(ho(L))return{entry:{kind:"family",family:L},...ce!==""&&{warning:`"${Cn(c)}" blocks every ${Us(L)} model.${ce}`}};if(Ms(L)||L==="default")return{entry:null,warning:`"${Cn(c)}" was ignored: it names a different model depending on the release and settings. Name the model instead, for example "claude-opus-5-5".`};let me=Bn(L),Ne=me!==null||L.startsWith("claude-")?L:`claude-${L}`,Fe=me??(Ne!==L?Bn(Ne):null);if(Fe){let st=Ne.lastIndexOf(Fe.base),gt=st===-1?"":Ne.slice(st+Fe.base.length),ht=Fe.trailer===void 0&>!==""?` "${Cn(gt)}" is ignored.`:"";return{entry:{kind:"model",id:Fe},...(ce!==""||ht!=="")&&{warning:`"${Cn(c)}" blocks ${GW(Fe)}.${ht}${ce}`}}}return{entry:{kind:"literal",value:L},warning:WW(c,L)}}function GW(c){let A=Us(c.family);return c.minor===void 0?`every ${A} ${c.major}.x model`:`${A} ${c.major}.${c.minor} in every spelling and snapshot`}function WW(c,A){let L=`"${Cn(c)}" blocks only the exact model name "${Cn(A)}"; other spellings of the same model are not blocked.`,ce=A.replace(/(\d)\.(\d)/g,"$1-$2");if(ce!==A){let Ne=ce.startsWith("claude-")?ce:`claude-${ce}`;if(Bn(Ne)!==null)return`${L} To block a version, write it with a hyphen: "${Cn(Ne)}".`}let me=new RegExp(`^(${Qn.join("|")})\\s+(\\d+)(?:\\.(\\d+))?$`).exec(A);if(me){let[,Ne,Fe,st]=me;return st!==void 0?`${L} To block a version, write its model ID, for example "claude-${Ne}-${Fe}-${st}".`:`${L} To block only version ${Fe}, write "claude-${Ne}-${Fe}-0"; "claude-${Ne}-${Fe}" blocks every ${Us(Ne)} ${Fe}.x model.`}if(/^[a-z]+$/.test(A)){let Ne=Qn.find((Fe)=>Af(A,Fe,1)===1);return Ne!==void 0?`${L} If you meant the ${Us(Ne)} family, write "${Ne}".`:`${L} To block a model family other than ${BW()}, list its versioned IDs.`}return L}function Lf(c){let A=va(c.trim().toLowerCase());if(A==="")return{kind:"ignored"};if(ho(A))return{kind:"family",family:A};let L=A.startsWith("claude-")?A.slice(7):"";if(ho(L))return{kind:"family",family:L};if(Ms(A)||A==="default")return{kind:"ignored"};let ce=Bn(A)!==null||A.startsWith("claude-")?A:`claude-${A}`,me=Bn(ce);return me!==null?{kind:"model",id:me,latest:$W(ce,me),spelling:ce}:{kind:"literal",value:A}}function jW(c,A){let L=c.toLowerCase(),ce=L.lastIndexOf(A.base);return ce===-1?"":L.slice(ce+A.base.length)}function $W(c,A){return A.trailer===void 0&&jW(c,A).startsWith("-latest")}function VW(c,A){for(let L of A){if(ho(L))continue;let ce=L.indexOf(c);if(ce===-1)continue;let me=ce+c.length;if(me===L.length||L[me]==="-")return!0}return!1}function KW(c){return c.charAt(0).toUpperCase()+c.slice(1)}function If(c){let A;for(let L of bf){let ce=Bn(L);if(ce!==null&&ce.family===c&&!ce.legacyVersionFirst&&(A===void 0||Rf(ce,A)>0))A=ce}return A?.base}function Pf(c,A){let L=Lf(c);switch(L.kind){case"ignored":{if(c.trim()==="")return"An empty availableModels entry was ignored.";let ce=If("opus");return`"${Cn(c)}" in availableModels was ignored, because "availableModelsMatch" is "exact" and this name means a different model depending on the release and settings. List the model IDs you want to allow instead${ce===void 0?"":`, for example "${ce}"`}.`}case"family":{let ce=A.filter((Ne)=>Lf(Ne).kind!=="ignored").map((Ne)=>va(Ne.trim().toLowerCase()));if(ho(c.trim().toLowerCase())&&VW(L.family,ce))return;let me=If(L.family);return`"${Cn(c)}" in availableModels allows every ${KW(L.family)} model, including future releases, even though "availableModelsMatch" is "exact". To allow only some versions, list their model IDs instead${me===void 0?"":`, for example "${me}"`}.`}case"model":return;case"literal":return YW(c,L.value)}}function YW(c,A){let L=`"${Cn(c)}" in availableModels allows only a model named exactly "${Cn(A)}".`,ce=A.replace(/(\d)\.(\d)/g,"$1-$2");if(ce!==A){let Ne=ce.startsWith("claude-")?ce:`claude-${ce}`;if(Bn(Ne)!==null)return`${L} To allow a version, write it with a hyphen: "${Cn(Ne)}".`}let me=new RegExp(`^(${Qn.join("|")})\\s+(\\d+)(?:\\.(\\d+))?$`).exec(A);if(me){let[,Ne,Fe,st]=me;return`${L} To allow a version, write its model ID, for example "claude-${Ne}-${Fe}${st!==void 0?`-${st}`:""}".`}return}function XW(c){return c!==void 0&&(c.commit!==void 0||c.pr!==void 0)}function wf(c,A){let L=c?.commitTrailers;if(typeof L==="boolean")return L?"explicit-enabled":"disabled";if(c!==void 0&&XW(c))return c.commit===""?"disabled":"implicit-enabled";if(A!==void 0)return A?"implicit-enabled":"disabled";return}var JW=["allowManagedMcpServersOnly","allowedMcpServers","deniedMcpServers","disabledMcpjsonServers","enabledMcpjsonServers","enableAllProjectMcpServers","disableClaudeAiConnectors","managedMcpServers"];function Hs({slot:c,adminTiers:A}){return c?.allowManagedMcpServersOnly===!0||A.some((L)=>L.allowManagedMcpServersOnly===!0)}function ka({slot:c,adminTiers:A}){return c?.allowedMcpServers??A.find((L)=>L.allowedMcpServers!==void 0)?.allowedMcpServers}function xf(c,A){return JW.filter((L)=>c[L]!==void 0&&!ZW(L,c,A))}function ZW(c,A,L){let ce=L.slot??{};switch(c){case"deniedMcpServers":return!0;case"allowManagedMcpServersOnly":return A.allowManagedMcpServersOnly===Hs(L);case"disableClaudeAiConnectors":return A.disableClaudeAiConnectors===(ce.disableClaudeAiConnectors===!0||L.adminTiers.some((me)=>me.disableClaudeAiConnectors===!0));case"allowedMcpServers":return P(A.allowedMcpServers,Hs(L)?ka(L):ce.allowedMcpServers);case"disabledMcpjsonServers":return(A.disabledMcpjsonServers??[]).every((me)=>ce.disabledMcpjsonServers?.includes(me)===!0);case"enabledMcpjsonServers":return(A.enabledMcpjsonServers??[]).every((me)=>ce.enabledMcpjsonServers?.includes(me)===!0);case"enableAllProjectMcpServers":return(A.enableAllProjectMcpServers??!1)===(ce.enableAllProjectMcpServers??!1);case"managedMcpServers":{let me=ce.managedMcpServers??{};return Object.entries(A.managedMcpServers??{}).every(([Ne,Fe])=>Object.hasOwn(me,Ne)&&P(me[Ne],Fe))}}}import{userInfo as qW}from"os";var Nf="com.anthropic.claudecode",zs="HKLM\\SOFTWARE\\Policies\\ClaudeCode",Fs="HKCU\\SOFTWARE\\Policies\\ClaudeCode",br="Settings",Ma="/usr/bin/plutil",vf=["-convert","json","-o","-","--"],kf=["-lint","-s","--"],Mf=5000,Bs=2097152,Uf="/mnt/c/Windows/System32/reg.exe",Rn="/mnt/c/Program Files/ClaudeCode";function Cr(){if(process.platform!=="linux")return!1;if(process.env.WSL_DISTRO_NAME)return!0;try{let c=$t("fs").readFileSync("/proc/version","utf8").toLowerCase();return c.includes("microsoft")||c.includes("wsl")}catch{return!1}}function Hf(){let c="";try{c=qW().username}catch{}let A=[];if(c)A.push({path:`/Library/Managed Preferences/${c}/${Nf}.plist`,label:"per-user managed preferences"});return A.push({path:`/Library/Managed Preferences/${Nf}.plist`,label:"device-level managed preferences"}),A}var zf=512;function Ua(c){return c.map(QW)}function QW(c){let{file:A,severity:L,docLink:ce,statusOnly:me,startupFatal:Ne,errorClass:Fe,errno:st,preserveOnWrite:gt,mcpErrorMetadata:ht,userWritable:Et,wslIgnored:Rt,substituted:Tt,onlySubstitutes:It,removal:Lt,path:Bt,message:xt,expected:Yt,suggestion:Xt,invalidValue:Wt,...qt}=c,on=qt;return{file:A,severity:L,docLink:ce,statusOnly:me,startupFatal:Ne,errorClass:Fe,errno:st,preserveOnWrite:gt,mcpErrorMetadata:ht,userWritable:Et,wslIgnored:Rt,substituted:Tt,onlySubstitutes:It,removal:Lt,path:Tr(Bt),message:Tr(xt),expected:Yt===void 0?void 0:Tr(Yt),suggestion:Xt===void 0?void 0:Tr(Xt),invalidValue:typeof Wt==="string"?Tr(Wt):void 0}}function Tr(c){let A=sf(c.replace(/\s+/gu," "));return A.length>zf?`${A.slice(0,zf-1)}…`:A}import{globalRegistry as Z9,toJSONSchema as q9}from"zod/v4";import{$ZodLazy as e8}from"zod/v4/core";var Gn="https://code.claude.com/docs/en",ej=[{matches:(c)=>c.path==="permissions.defaultMode"&&c.code==="invalid_value",tip:{suggestion:'Valid modes: "acceptEdits" (ask before file changes), "plan" (analysis only), "bypassPermissions" (auto-accept all), or "default" (standard behavior)',docLink:`${Gn}/iam#permission-modes`}},{matches:(c)=>c.path==="apiKeyHelper"&&c.code==="invalid_type",tip:{suggestion:'Provide a shell command that outputs your API key to stdout. The script should output only the API key. Example: "/bin/generate_temp_api_key.sh"'}},{matches:(c)=>c.path==="cleanupPeriodDays"&&c.code==="too_small",tip:{suggestion:'cleanupPeriodDays must be at least 1. To keep transcripts for a long time, set a large number (e.g. 3650 for ~10 years). To disable transcript writes entirely, remove this setting and use the --no-session-persistence CLI flag or the SDK persistSession:false option instead. (0 is rejected because it previously silently disabled all transcript writes, which users setting it to mean "never clean up" did not expect.)'}},{matches:(c)=>c.path.startsWith("env.")&&c.code==="invalid_type",tip:{suggestion:'Environment variables must be strings. Wrap numbers and booleans in quotes. Example: "DEBUG": "true", "PORT": "3000"',docLink:`${Gn}/settings#environment-variables`}},{matches:(c)=>(c.path==="permissions.allow"||c.path==="permissions.deny")&&c.code==="invalid_type"&&c.expected==="array",tip:{suggestion:'Permission rules must be in an array. Format: ["Tool(specifier)"]. Examples: ["Bash(npm run build)", "Edit(docs/**)", "Read(~/.zshrc)"]. Use * for wildcards.'}},{matches:(c)=>c.path==="hooks"&&c.code==="unrecognized_keys",tip:{suggestion:"Not a recognized hook event. Common events: PreToolUse, PostToolUse, UserPromptSubmit, SessionStart, SessionEnd, Stop. Check spelling and capitalization.",docLink:`${Gn}/hooks`}},{matches:(c)=>/\.hooks\.\d+\.command$/.test(c.path)&&c.code==="invalid_type"&&c.received==="undefined",tip:{suggestion:'Command hooks require `command`. For exec form (no shell), set `command` to the executable and `args` to its arguments: {"type": "command", "command": "echo", "args": ["hi"]}. For shell form, set `command` to the full shell string: {"type": "command", "command": "echo hi"}.',docLink:`${Gn}/hooks#exec-form-and-shell-form`}},{matches:(c)=>c.path.includes("hooks")&&c.code==="invalid_type",tip:{suggestion:'Hooks use a matcher + hooks array. The matcher is a string: a tool name ("Bash"), pipe-separated list ("Edit|Write"), or empty to match all. Example: {"PostToolUse": [{"matcher": "Edit|Write", "hooks": [{"type": "command", "command": "echo Done"}]}]}'}},{matches:(c)=>c.code==="invalid_type"&&c.expected==="boolean",tip:{suggestion:'Use true or false without quotes. Example: "includeCoAuthoredBy": true'}},{matches:(c)=>c.code==="unrecognized_keys",tip:{suggestion:"Check for typos or refer to the documentation for valid fields",docLink:`${Gn}/settings`}},{matches:(c)=>c.code==="invalid_value"&&c.enumValues!==void 0,tip:{suggestion:void 0}},{matches:(c)=>c.code==="invalid_type"&&c.expected==="object"&&c.received===null&&c.path==="",tip:{suggestion:"Check for missing commas, unmatched brackets, or trailing commas. Use a JSON validator to identify the exact syntax error."}},{matches:(c)=>c.path==="permissions.additionalDirectories"&&c.code==="invalid_type",tip:{suggestion:'Must be an array of directory paths. Example: ["~/projects", "/tmp/workspace"]. You can also use --add-dir flag or /add-dir command',docLink:`${Gn}/iam#working-directories`}}],tj={permissions:`${Gn}/iam#configuring-permissions`,env:`${Gn}/settings#environment-variables`,hooks:`${Gn}/hooks`};function Ff(c){let A=ej.find((ce)=>ce.matches(c));if(!A)return null;let L={...A.tip};if(c.code==="invalid_value"&&c.enumValues&&!L.suggestion)L.suggestion=`Valid values: ${c.enumValues.map((ce)=>`"${ce}"`).join(", ")}`;if(!L.docLink&&c.path)L.docLink=tj[St(c.path,".")];return L}var x8=Mt(()=>Oa(zo(),{strictPolicyHelperKeys:!0}).strict());function Bf(c){return c.code==="invalid_type"}function Gf(c){return c.code==="invalid_value"}function nj(c){return c.code==="unrecognized_keys"}function Wf(c){return c.code==="too_small"}function hn(c){if(c===null)return"null";if(c===void 0)return"undefined";if(Array.isArray(c))return"array";return typeof c}function jf(c){let A=c.match(/received (\w+)/);return A?A[1]:void 0}function Rr(c,A){return c.issues.flatMap((ce)=>{if(ce.code!=="invalid_union"||ce.path.join(".")!=="attribution")return[ce];let me=ce.errors.flat().filter((Ne)=>Ne.path.length>0);return me.length>0?me.map((Ne)=>({...Ne,path:[...ce.path,...Ne.path]})):[ce]}).map((ce)=>{let me=ce.path.map(String).join("."),Ne=ce.message,Fe,st,gt,ht,Et;if(Gf(ce))st=ce.values.map((Tt)=>String(Tt)),gt=st.join(" | "),ht=void 0,Et=void 0;else if(Bf(ce)){gt=ce.expected;let Tt=jf(ce.message);ht=Tt??hn(ce.input),Et=Tt??hn(ce.input)}else if(Wf(ce))gt=String(ce.minimum);else if(ce.code==="custom"&&"params"in ce)ht=ce.params.received,Et=ht;let Rt=Ff({path:me,code:ce.code,expected:gt,received:ht,enumValues:st,message:ce.message,value:ht});if(Gf(ce))Fe=st?.map((Tt)=>`"${Tt}"`).join(", "),Ne=`Invalid value. Expected one of: ${Fe}`;else if(Bf(ce)){let Tt=jf(ce.message)??hn(ce.input);if(ce.expected==="object"&&Tt==="null"&&me==="")Ne="Invalid or malformed JSON";else Ne=`Expected ${ce.expected}, but received ${Tt}`}else if(nj(ce)){let Tt=ce.keys.join(", ");Ne=`Unrecognized ${ze(ce.keys.length,"field")}: ${Tt}`}else if(Wf(ce))Ne=`Number must be greater than or equal to ${ce.minimum}`,Fe=String(ce.minimum);return{file:A,path:me,message:Ne,expected:Fe,invalidValue:Et,suggestion:Rt?.suggestion,docLink:Rt?.docLink}})}function oj(c,A,L){if(!c||typeof c!=="object")return[];let ce=c;if(!ce.permissions||typeof ce.permissions!=="object")return[];let me=ce.permissions,Ne=[],Fe=new Map;for(let st of["allow","deny","ask"]){let gt=me[st];if(!Array.isArray(gt))continue;let ht=gt.filter((Et)=>{if(typeof Et!=="string")return Ne.push({file:A,path:`permissions.${st}`,message:`Non-string value in ${st} array was removed`,severity:"warning",invalidValue:Et}),!1;let Rt=ca(Et,st);if(!Rt.valid){let Tt=`Invalid permission rule "${Et}" was skipped: ${Rt.error}`;if(Rt.suggestion)Tt+=`. ${Rt.suggestion}`;return Ne.push({file:A,path:`permissions.${st}`,message:Tt,severity:"warning",invalidValue:Et}),!1}return!0});if(L?.policySource&&st!=="allow"&>.length>0&&ht.length===0){if(!L.strictParseFollows)continue;Fe.set(st,"unreadable")}else if(ht.length<gt.length)Fe.set(st,"trimmed");me[st]=ht}return Ta("permissions",me,(st)=>Fe.get(st),(st)=>Ne.push({file:A,path:st.path,message:st.message,severity:"warning",...st.substituted&&{substituted:st.substituted}})),Ne}var rj=new Set(G);function sj(c,A){if(!c||typeof c!=="object")return[];return[...pu(c,fu)?[{file:A,path:"hooks",message:`PreToolUse/PermissionRequest hooks are declared outside "hooks" (at the top level or under another key) — ${co}.`,severity:"fatal",docLink:"https://code.claude.com/docs/en/hooks"}]:[],...ij(c,A)]}function ij(c,A){if(!("hooks"in c))return[];if(c.hooks===null||typeof c.hooks!=="object"||Array.isArray(c.hooks)){let me=hn(c.hooks);if(Array.isArray(c.hooks)&&(c.hooks.some(r)||Fi(c.hooks)))return[{file:A,path:"hooks",message:`"hooks" must be an object mapping event names to matcher arrays; received ${me} — ${co}.`,invalidValue:me,docLink:"https://code.claude.com/docs/en/hooks"}];return delete c.hooks,[{file:A,path:"hooks",message:`"hooks" must be an object mapping event names to matcher arrays; received ${me}. This field was ignored.`,severity:"warning",invalidValue:me,docLink:"https://code.claude.com/docs/en/hooks"}]}let L=c.hooks;if(ms(L))return[{file:A,path:"hooks",message:`"hooks" must be an object mapping event names to matcher arrays; received a single matcher — ${co}.`,docLink:"https://code.claude.com/docs/en/hooks"}];let ce=[];for(let me of Object.keys(L)){let Ne=ot(me);if(!rj.has(me)){if(ao(L[me],3,{matchersCount:!Array.isArray(L[me])})){ce.push({file:A,path:`hooks.${Ne}`,message:`"${Ne}" is not a hook event, but it holds PreToolUse/PermissionRequest hooks — ${co}.`,docLink:"https://code.claude.com/docs/en/hooks"});continue}delete L[me],ce.push({file:A,path:`hooks.${Ne}`,message:`Unknown hook event "${Ne}" was ignored. Valid events: ${G.join(", ")}`,severity:"warning",invalidValue:Ne,docLink:"https://code.claude.com/docs/en/hooks",preserveOnWrite:!0});continue}if(!Array.isArray(L[me])){let Fe=L[me],st=hn(Fe);if(pr.has(me)&&Fe!==null||ao(Fe,3,{matchersCount:!1})){ce.push({file:A,path:`hooks.${Ne}`,message:`Hook event "${Ne}" must be an array of matchers; received ${st} — ${co}.`,invalidValue:st,docLink:"https://code.claude.com/docs/en/hooks"});continue}delete L[me],ce.push({file:A,path:`hooks.${Ne}`,message:`Hook event "${Ne}" must be an array of matchers; received ${st}. This entry was ignored.`,severity:"warning",invalidValue:st,docLink:"https://code.claude.com/docs/en/hooks",...Fe!==null&&{preserveOnWrite:!0}})}}for(let[me,Ne]of Object.entries(L)){let{stripped:Fe,unloadableGuards:st}=gu(Ne,me);for(let gt of st)ce.push({file:A,path:gt.aboutType?`hooks.${me}.${gt.path}.type`:`hooks.${me}.${gt.path}`,message:`${gt.problem} — ${co}.${gt.aboutType?` Valid types: ${[...fs()].join(", ")}`:""}`,severity:"fatal",invalidValue:gt.received,docLink:"https://code.claude.com/docs/en/hooks"});for(let gt of Fe)ce.push({file:A,path:gt.aboutType?`hooks.${me}.${gt.path}.type`:`hooks.${me}.${gt.path}`,message:gt.aboutType?`${gt.problem}; entry ignored. Valid types: ${[...fs()].join(", ")}`:`${gt.problem}; ${gt.hookIndex===void 0?"matcher":"entry"} ignored.`,severity:"warning",invalidValue:gt.received,docLink:"https://code.claude.com/docs/en/hooks",preserveOnWrite:!0})}if(ce.length>0&&Object.keys(L).length===0)delete c.hooks;return ce}var aj=[{key:"allowedMcpServers",schema:Ls},{key:"deniedMcpServers",schema:Is}];function lj(c,A,L){if(!c||typeof c!=="object")return[];let ce=c,me=[];for(let{key:Ne,schema:Fe}of aj){if(!(Ne in ce))continue;if(!Array.isArray(ce[Ne])){if(L?.keepWholeFieldInvalid)continue;let ht=ce[Ne];delete ce[Ne],me.push({file:A,path:Ne,message:`"${Ne}" must be an array; received ${hn(ht)}. This field was ignored.`,severity:"warning",invalidValue:ht});continue}let st=ce[Ne],gt=[];for(let ht=0;ht<st.length;ht++){let Et=Fe().safeParse(st[ht]);if(Et.success)gt.push(st[ht]);else me.push({file:A,path:`${Ne}[${ht}]`,message:`Invalid entry was ignored: ${Et.error.issues[0]?.message??"failed validation"}`,severity:"warning",invalidValue:st[ht]})}if(gt.length<st.length)ce[Ne]=gt}return me}var cj=["strictKnownMarketplaces","blockedMarketplaces"];function dj(c){if(!r(c))return;for(let A of xs())if(c[A]===null)delete c[A]}function uj(c,A,L){if(!r(c))return[];let ce=[];for(let me of cj){let Ne=c[me];if(!Array.isArray(Ne))continue;let Fe=[],st=[];for(let gt=0;gt<Ne.length;gt++){let ht=mr().safeParse(Ne[gt]);if(!ht.success){Fe.push(Ne[gt]),st.push(gt);continue}let Et=Ca(ht.data);if(Et===null){Fe.push(Ne[gt]),st.push(gt);continue}if(me==="blockedMarketplaces"){Fe.push(Ne[gt]),st.push(gt),ce.push({file:A,path:`${me}[${gt}]`,message:`Unenforceable entry was kept: ${Et}; it can never match a marketplace source, but marketplace restrictions stay active`,severity:"warning"});continue}ce.push({file:A,path:`${me}[${gt}]`,message:`Invalid entry was ignored: ${Et}`,severity:"warning"})}if(Fe.length<Ne.length)c[me]=Fe,L?.set(me,st)}return ce}function pj(c,A){if(!r(c)||c.managedMcpServers===void 0)return[];let ce=[],me=ls(c.managedMcpServers,(Ne,Fe)=>ce.push({file:A,path:Ne?`managedMcpServers.${Ne}`:"managedMcpServers",message:Ne?`Managed MCP server was ignored: ${Fe}`:Fe,severity:"warning"}));if(me===void 0)delete c.managedMcpServers;else c.managedMcpServers=me;return ce}function fj(c){if(!c||typeof c!=="object")return;let A=c.source;if(!A||typeof A!=="object")return;let L=A.source;return typeof L==="string"?L:void 0}function mj(c){if(!c||typeof c!=="object")return!1;let A=c.source;if(!A||typeof A!=="object")return!1;let L=A.plugins;return Array.isArray(L)&&L.some(ra)}function gj(c,A){if(!c||typeof c!=="object")return[];let L=c,ce="extraKnownMarketplaces";if(!(ce in L))return[];let me=L[ce];if(!me||typeof me!=="object"||Array.isArray(me)){let st=hn(me);return delete L[ce],[{file:A,path:ce,message:`"${ce}" must be an object mapping marketplace names to declarations; received ${st}. This field was ignored.`,severity:"warning",invalidValue:st}]}let Ne=me,Fe=[];for(let st of Object.keys(Ne)){let gt=ga().safeParse(Ne[st]),ht,Et=!1;if(!gt.success){let Rt=fj(Ne[st]);if(Rt!==void 0&&!Xu.has(Rt)||mj(Ne[st]))continue;ht=Es(gt.error.issues)}else if(gt.data.source.source==="settings"&>.data.source.name!==st)ht=`key "${Un(st)}" must match the settings source name "${Un(gt.data.source.name)}"`;if(ht!==void 0)Fe.push({file:A,path:`${ce}.${Un(st)}`,message:Et?"Marketplace entry was ignored: its name reads like an official Anthropic or Claude marketplace. It stays in this file: rename it (the key and the source's name) to use it, or delete it. If /plugin also shows a marketplace of this name as refused, remove that one in /plugin → Marketplaces once this entry is renamed or deleted.":`Invalid marketplace entry was ignored: ${ht}`,severity:"warning",...Et&&{preserveOnWrite:!0}}),delete Ne[st]}return Fe}function hj(c,A){if(!c||typeof c!=="object")return[];let L=c,ce="modelPicker";if(!(ce in L))return[];let me=L[ce];if(!r(me)||!Array.isArray(me.options)){let gt=r(me)?`options: ${hn(me.options)}`:hn(me);return delete L[ce],[{file:A,path:ce,message:`"${ce}" must be an object with an "options" array of { model, label?, description?, behavesAs? } rows; received ${gt}. This field was ignored.`,severity:"warning",invalidValue:gt}]}let Ne=[];if("replaceBuiltInOptions"in me&&typeof me.replaceBuiltInOptions!=="boolean"){let gt=hn(me.replaceBuiltInOptions);delete me.replaceBuiltInOptions,Ne.push({file:A,path:`${ce}.replaceBuiltInOptions`,message:`"replaceBuiltInOptions" must be true or false; received ${gt}. This entry was ignored (the rows are added to the built-in lineup).`,severity:"warning",invalidValue:gt})}let Fe=me.options,st=[];for(let gt=0;gt<Fe.length;gt++){let ht=_a().safeParse(Fe[gt]);if(ht.success){st.push(Fe[gt]);continue}Ne.push({file:A,path:`${ce}.options.${gt}`,message:`${_j(ht.error.issues[0])}. This row was ignored; the other rows still apply.`,severity:"warning",invalidValue:hn(Fe[gt])})}if(st.length!==Fe.length)me.options=st;return Ne}function Ej(c,A){if(!c||typeof c!=="object"||Array.isArray(c))return[];let L=c;if(!("modelPricing"in L)||L.modelPricing===void 0)return[];let ce=L.modelPricing;if(!ce||typeof ce!=="object"||Array.isArray(ce))return delete L.modelPricing,[{file:A,path:"modelPricing",message:`"modelPricing" must be an object; received ${hn(ce)}. It was ignored.`,severity:"warning"}];let me=ce,Ne=[];if(me.multiplier!==void 0&&!Ea().safeParse(me.multiplier).success)Ne.push({file:A,path:"modelPricing.multiplier",message:'"multiplier" must be a number greater than 0 and at most 10. It was ignored.',severity:"warning",invalidValue:me.multiplier}),delete me.multiplier;if(me.overrides!==void 0){let Fe=me.overrides;if(!Fe||typeof Fe!=="object"||Array.isArray(Fe))Ne.push({file:A,path:"modelPricing.overrides",message:`"overrides" must be an object mapping model ID to rates; received ${hn(Fe)}. It was ignored.`,severity:"warning"}),delete me.overrides;else{let st=Fe;for(let gt of Object.keys(st)){let ht=ha().safeParse(st[gt]);if(ht.success&>!=="constructor"&>!=="__proto__")continue;let Et=ht.success?void 0:ht.error.issues[0];Ne.push({file:A,path:`modelPricing.overrides.${Un(gt)}`,message:`Invalid pricing row was ignored (${Et?`${Et.path.join(".")||"row"}: ${Et.message}`:"not a model ID"}).`,severity:"warning",invalidValue:st[gt]}),delete st[gt]}}}return Ne}function _j(c){if(!c)return"Invalid modelPicker row";return`modelPicker row ${c.path.length>0?`"${c.path.join(".")}" `:""}${c.message}`.trim()}function Sj(c,A,L){if(!c||typeof c!=="object"||Array.isArray(c))return[];let ce=c,me=ce.crossSessionInbound;if(me===void 0||yj(me))return[];if(L?.policySource)ce.crossSessionInbound="refuse";else delete ce.crossSessionInbound;return[bj(me,A,L?.policySource===!0)]}function yj(c){return typeof c==="string"&&yr.includes(c)}var Oj="crossSessionInbound";function Aj(c){let A=yr.map((ce)=>`"${ce}"`).join(", "),L=typeof c==="string"?`"${Un(c).replace(/^<key>$/,"<value>")}"`:hn(c);return`must be one of ${A}; received ${L}`}function bj(c,A,L=!1){let ce=yr.map((Ne)=>`"${Ne}"`).join(", "),me=L?'In managed settings an unrecognized value is treated as "refuse" (the most restrictive): cross-session messages to this session are turned away until an administrator fixes it.':"This value was ignored; while it is present, cross-session messages are held for your approval instead of being delivered. Set it to one of the values above.";return{file:A,path:Oj,message:`"crossSessionInbound" ${Aj(c)}. ${me}`,severity:"warning",expected:ce,...L&&{statusOnly:!0}}}var $f="remoteControl.shareHostProfile";function Cj(c,A,L){if(!r(c)||c.remoteControl===void 0)return[];let ce=L?.policySource===!0,me=Ds.map((Tt)=>`"${Tt}"`).join(", "),Ne=ce?'In managed settings this is treated as "off" (the most restrictive): Remote Control environments report nothing about this machine until an administrator fixes it.':"While it is present, Remote Control environments report nothing about this machine.",Fe=(Tt)=>({file:A,path:$f,message:`${Tt}. ${Ne}`,severity:"warning",expected:me,...ce?{statusOnly:!0}:{preserveOnWrite:!0}}),st=(Tt)=>typeof Tt==="string"?`"${Un(Tt).replace(/^<key>$/,"<value>")}"`:hn(Tt),gt=c.remoteControl;if(!r(gt)){if(ce)c.remoteControl={shareHostProfile:"off"};else delete c.remoteControl;return[Fe(`"remoteControl" must be an object like { "shareHostProfile": ${me.replace(/, /g," | ")} }; received ${st(gt)}`)]}let ht=[],Et=Object.keys(gt).filter((Tt)=>Tt!=="shareHostProfile");if(Et.length>0){if(ce)gt.shareHostProfile="off";ht.push(Fe(`"remoteControl" has an unrecognized key ${Et.map((Tt)=>`"${Un(Tt)}"`).join(", ")} (its only key is "shareHostProfile")`))}let Rt=gt.shareHostProfile;if(Rt!==void 0&&!(typeof Rt==="string"&&Ds.includes(Rt))){if(ce)gt.shareHostProfile="off";else delete gt.shareHostProfile;ht.push(Fe(`"${$f}" must be one of ${me}; received ${st(Rt)}`))}return ht}function Dr(c,A,L){let ce=[...$p(c,A)];return dj(c),ce.push(...oj(c,A,{policySource:L?.policySource,strictParseFollows:L?.mcpServerEntrySalvageOnly}),...sj(c,A),...gj(c,A),...hj(c,A),...Ej(c,A),...Sj(c,A,{policySource:L?.policySource}),...Cj(c,A,{policySource:L?.policySource}),...L?.skipMcpServerEntryFilter?[]:lj(c,A,{keepWholeFieldInvalid:L?.mcpServerEntrySalvageOnly}),...L?.mcpServerEntrySalvageOnly?pj(c,A):[],...L?.mcpServerEntrySalvageOnly?uj(c,A,L.marketplacePatternIndexMapOut):[]),ce}function ja(c){let A=new Set(c.allowedSources);return A.add("flagSettings"),A.add("policySettings"),Gt.filter((L)=>A.has(L))}function Dj(){return En($n(),"managed-settings.json")}function sm(c){if(C()==="wsl"){let A=Yo(Va(c));if(c.wslInherits?.()){let L=Ha(Rn,c.store);if(Yo(L)||A)return L;let ce=Ha($n(),c.store);return{...ce,errors:[...L.errors,...ce.errors],loadState:Wn(L.loadState,ce.loadState)}}if(A)return{settings:null,errors:[],documentHasPolicyContent:!1,loadState:"absent"}}return Ha($n(),c.store)}function Vf(c,A,L){L.push(...A.errors);let{settings:ce}=A;if(!ce||Object.keys(ce).length===0)return;for(let[me,Ne]of Ns){let Fe=me.split(".");if(pn(ce,Fe)===void 0)continue;let st=A.errors.find((Et)=>Et.substituted&&Et.path===me),gt=st!==void 0,ht=pn(c.merged,Fe);if(gt&&ht!==void 0&&!c.floors.has(me)){let Et=Fe.at(-1);if(Ne.inert.has(Ne.read(ht))){Qc(ce,Fe),L.push({file:st.file,path:me,message:`That substitute is not applied: "${Et}" keeps the value an earlier managed-settings document of this folder wrote.`,severity:"warning",statusOnly:!0});continue}L.push({file:st.file,path:me,message:`That substitute also displaces the wider "${Et}" an earlier managed-settings document of this folder wrote, until this document is fixed.`,severity:"warning",statusOnly:!0})}if(gt)c.floors.add(me);else c.floors.delete(me)}if(c.merged=mn(c.merged,ce,xn),c.found=!0,xr(ce)&&!A.errors.some((me)=>me.onlySubstitutes))c.authored=!0}function $a(c){return c.endsWith(".json")&&!c.startsWith(".")}function Lj(c){return(c.isFile()||c.isSymbolicLink())&&$a(c.name)}function Kf(c,A,L,ce){let me=c.managedDocumentLinks;me.noteWalked(En(A,...L),()=>Yl(A,L,ce,me.folderIsLink))}function Ha(c,A){let L=[],ce={merged:{},found:!1,authored:!1,floors:new Set},me=!1,Ne="absent",Fe=$o(En(c,"managed-settings.json"),A,void 0,!0);if(Vf(ce,Fe,L),me||=Pr(Fe),Ne=Wn(Ne,So(Fe)),So(Fe)!=="absent")Kf(A,c,["managed-settings.json"]);let st=En(c,"managed-settings.d");try{let ht=A.folderListingForPolicyWalk(st),Et,Rt;if(ht!==void 0)Et=ht;else{let Tt=s().readdirSync(st).filter(Lj);Et=Tt.map((It)=>It.name).sort(),Rt=new Set(Tt.filter((It)=>!It.isFile()).map((It)=>It.name)),A.noteWalkListing(st,Et)}for(let Tt of Et){let It=$o(En(st,Tt),A,void 0,!0);if(Vf(ce,It,L),me||=Pr(It),Ne=Wn(Ne,So(It)),So(It)!=="absent")Kf(A,c,["managed-settings.d",Tt],Rt?.has(Tt))}}catch(ht){let Et=n(ht);if(Et!=="ENOENT"&&Et!=="ENOTDIR")e(`managed-settings.d read failed: ${ht}`,{level:"error"}),L.push(wr(st,ht,"directory")),Ne="didNotLoad"}let gt=ce.found&&Xo(ce.merged)?ce.merged:null;return{settings:gt,errors:L,documentHasPolicyContent:me,loadState:Ne,...gt!==null&&!ce.authored&&xr(gt)&&{onlySubstitutes:!0}}}function Ij(c,A){if(_(c))Uj(A);else e(`settings file read failed at ${A}: ${c}`,{level:"error"})}function $o(c,A,L,ce){let me=L!==void 0?`${c}\x00pinned`:c,Ne=A.parsedFiles.get(me);if(Ne)return{...Ne,settings:Ne.settings?W(Ne.settings):null};let Fe=vj(c,L,ce);return A.parsedFiles.set(me,Fe),{...Fe,settings:Fe.settings?W(Fe.settings):null}}function Va(c){let A=c.mdm?.();if(!A)return{settings:null,errors:[],documentHasPolicyContent:!1,loadState:"absent"};return{settings:A.settings&&Object.keys(A.settings).length>0?A.settings:null,errors:Fj(A.errors,()=>Ka(c)),documentHasPolicyContent:Pr(A),loadState:So(A),...A.onlySubstitutes&&{onlySubstitutes:A.onlySubstitutes}}}function Ir(c,A){let L=Xf.get(c),ce=L?.get(A);if(ce)return Yf(ce);let me=Pj(c,A);if(L)L.set(A,me);else Xf.set(c,new Map([[A,me]]));return Yf(me)}function Yf(c){return{settings:c.settings&&W(c.settings),errors:c.errors.map((A)=>({...A})),documentHasPolicyContent:c.documentHasPolicyContent,loadState:c.loadState,removed:c.removed,...c.onlySubstitutes&&{onlySubstitutes:c.onlySubstitutes}}}var Xf=new WeakMap;function Pj(c,A){let L=W(c),ce=Dr(L,A,{skipMcpServerEntryFilter:!0,policySource:!0}),me=[],Ne=La(cm(A,me),A,L).safeParse(L);if(!Ne.success)return{settings:null,errors:[...ce,...Rr(Ne.error,A)],documentHasPolicyContent:!1,loadState:"didNotLoad",removed:[]};let Fe=[...ce,...me],st=c,gt=Object.keys(Ne.data).length>0?Ne.data:null;return{settings:gt,errors:Fe,documentHasPolicyContent:Sm(c,Ne.data),loadState:"loaded",removed:Object.keys(st).filter((ht)=>im(ht,st[ht])&&Ne.data[ht]===void 0&&Fe.every((Et)=>Et.statusOnly||Et.path!==ht&&!Et.path.startsWith(`${ht}.`))),...gt!==null&&me.some((ht)=>ht.onlySubstitutes)&&{onlySubstitutes:!0}}}function im(c,A){let L=xs();return L.includes(c)||Go.some(({alias:ce,canonical:me})=>ce===c&&L.includes(me))?Da(c,A):vs(c)&&am(c,A)}function am(c,A){return A===null||r(A)&&Object.keys(A).length>0&&Object.entries(A).every(([L,ce])=>{let me=`${c}.${L}`;return Da(me,ce)||vs(me)&&am(me,ce)})}function yo(c){return mi()&&(c==="managedMcpServers"||c.startsWith("managedMcpServers."))}var Ks=["managedMcpServers","isolation"],wj=[...Ks,"deniedModels","availableModelsMatch"];function lm(c,A){if(!r(c))return[];let L=[];for(let ce of wj){if(!(ce in c))continue;if(delete c[ce],!yo(ce))L.push({file:A,path:ce,message:`"${ce}" is only honored from managed settings and was ignored here.`,severity:"warning",preserveOnWrite:!0})}return L}function cm(c,A){return(L)=>{if(yo(L.path))return;if(A.push({file:c,path:L.path,message:L.message,severity:"warning",...L.statusOnly&&{statusOnly:L.statusOnly},...L.startupFatal&&{startupFatal:L.startupFatal},...L.substituted&&{substituted:L.substituted},...L.onlySubstitutes&&{onlySubstitutes:L.onlySubstitutes},...L.removal&&{removal:L.removal}}),L.statusOnly||L.startupFatal)e(`${c}: ${L.path}: ${L.message}`,{level:L.startupFatal?"error":"warn"})}}function Ka(c){let A=c?.remote?c.remote():Sf((ht)=>Ir(ht,"remote managed settings").settings),L=!c?.remote&&!yo("managedMcpServers")&&hf()?[{file:"remote managed settings",path:"managedMcpServers",message:"The organization's MCP servers in the cached remote settings are withheld until the server confirms them this session; they connect as soon as it does.",severity:"warning",statusOnly:!0}]:[],ce=c?.remote?void 0:pf(),me=(ce?.state==="stale_cache"||ce?.state==="failed")&&ce.failure.errorKind==="ruled_empty"?Ua(ce.failure.rulings??[]):[];if(!A||Object.keys(A).length===0)return{settings:null,errors:[...L,...me],servedSnapshot:!1,documentHasPolicyContent:!1};let{settings:Ne,errors:Fe,documentHasPolicyContent:st,onlySubstitutes:gt}=Ir(A,"remote managed settings");return{settings:Ne,errors:[...L,...me,...Ua(Fe)],servedSnapshot:ff(A),documentHasPolicyContent:st,...gt&&{onlySubstitutes:gt}}}var Jf="parent managed settings";function xj(c){let A=c.parentManaged;if(!A||Object.keys(A).length===0)return{settings:null,errors:[]};let L=Ir(A,Jf);for(let ce of Ks)if(L.settings?.[ce]!==void 0&&!yo(ce))L.errors.push({file:Jf,path:ce,message:`"${ce}" is only honored from the organization's managed settings sources (server-managed, MDM, managed-settings.json), not from settings a host passes in, and was ignored here.`,severity:"warning",statusOnly:!0});return L}function dm(c){let A=c.flagInline;if(!A)return{settings:null,errors:[]};let L=mi(),ce=c.store.inlineFlagParse;if(ce?.inline!==A||ce.desktopSupplied!==L)ce={inline:A,desktopSupplied:L,parsed:Nj(A)},c.store.inlineFlagParse=ce;let{settings:me,errors:Ne}=ce.parsed;return{settings:me&&W(me),errors:Ne.map((Fe)=>({...Fe}))}}function Nj(c){let A=W(c),L=[...lm(A,"SDK inline settings"),...Dr(A,"SDK inline settings")],ce=ws(A).safeParse(A);if(!ce.success)return{settings:null,errors:[...L,...Rr(ce.error,"SDK inline settings")]};if(L.some((me)=>me.severity==="fatal"))return{settings:null,errors:L};return{settings:ce.data,errors:L}}var Ys=2097152;function vj(c,A,L){try{let ce;if(A!==void 0)ce=A;else{let me=L||kj(c)?Ie(s(),c):Ft(s(),c);ce=eo(me.resolvedPath,Ys)}return Ya(ce,c,L)}catch(ce){return zj(ce,c)}}function Ya(c,A,L){if(c.trim()==="")return{settings:{},errors:[],loadState:"loaded"};let ce=to(c,!1);if(L){if(!r(ce))return{settings:null,errors:[Xs(A)],loadState:"didNotLoad"};let st=W(ce),gt=Dr(st,A,{skipMcpServerEntryFilter:!0,policySource:!0}),ht=[],Et=La(cm(A,ht),A,st).safeParse(st);if(!Et.success)return{settings:null,errors:[...gt,...Rr(Et.error,A)],documentHasPolicyContent:!1,loadState:"didNotLoad"};return{settings:Et.data,errors:[...gt,...ht],documentHasPolicyContent:Sm(ce,Et.data),loadState:"loaded"}}let me=W(ce),Ne=[...lm(me,A),...Dr(me,A)],Fe=ws(me).safeParse(me);if(!Fe.success){let st=Rr(Fe.error,A);return{settings:null,errors:[...Ne,...st]}}if(Ne.some((st)=>st.severity==="fatal"))return{settings:null,errors:Ne};return{settings:Fe.data,errors:Ne}}function Xs(c,{userWritable:A=!1}={}){return A?{file:c,path:"",message:`Managed settings document (${c}) could not be parsed as a JSON object; none of its settings are in effect. Fix or remove it.`,severity:"warning",statusOnly:!0,userWritable:!0}:{file:c,path:"",message:"Managed settings document could not be parsed as a JSON object; none of its settings are in effect. Fix or remove it.",startupFatal:!0}}function kj(c){let A=u(Vs(ln(c))),L=ln(m());return A===u(L)||A===Mj(L)}var za;function Mj(c){if(za?.lexical!==c){let A=Vs(c);za={lexical:c,physical:u(En(rt(A)??A,Rj(c)))}}return za.physical}function Uj(c){e(`Broken symlink or missing file encountered for settings.json at path: ${c}`)}function Hj(){return{settings:null,errors:[],loadState:"absent"}}function zj(c,A){if(Ij(c,A),_(c))return Hj();return{settings:null,errors:[wr(A,c)],loadState:"didNotLoad"}}function wr(c,A,L="file"){return{file:c,path:"",message:`${L==="directory"?"Managed settings drop-in directory":"Settings file"} could not be read: ${A instanceof Error?A.message:String(A)}`,severity:"fatal",errorClass:"unreadable",...n(A)!==void 0&&{errno:n(A)}}}function um(c){return{file:c,path:"wslInheritsWindowsSettings",message:`"wslInheritsWindowsSettings" in ${c} holds a value that cannot be read (it takes true or false) and no Windows administrator policy is deployed beside it (HKLM or ${Rn}), so whether WSL inherits Windows policy is unknown: no Windows or managed-file policy is in effect (/etc/claude-code is not read beneath it), and unless server-managed settings supply the policy — they apply regardless — sign-in and policy enforcement fail closed until the flag is fixed.`,severity:"fatal",statusOnly:!0}}function Zf(c){return c.path==="wslInheritsWindowsSettings"&&c.severity==="fatal"}function Fj(c,A){if(!c.some(Zf))return c;if(!js(A()))return c;return c.map((L)=>Zf(L)?{...L,severity:"warning"}:L)}function qf(c,A){switch(c){case"userSettings":return ln(m());case"policySettings":return ln(Gs(A));case"projectSettings":return ln(A.projectConfigDir??Gs(A));case"localSettings":{if(A.projectConfigDir!==void 0)return ln(A.projectConfigDir);return pm(Gs(A),A.canonicalGitRoot)}case"flagSettings":return A.flagPath?Vs(ln(A.flagPath)):ln(Gs(A))}}function Gs(c){if(c.cwd===null)throw new Ke;return c.cwd}function pm(c,A){let L=Bj(c,A);if(L.decided!==void 0)return L.decided;if(!$j(L.root))return L.cwdResolved;return L.root}function Bj(c,A){let L=A?.(c);if(!L)return{decided:ln(c)};let ce=ln(L),me=ln(c);if(ce===me)return{decided:ce};let Ne;try{Ne=Vj()}catch{return{decided:me}}if(ce===Ne)return{decided:me};return{decided:void 0,root:ce,cwdResolved:me}}function Gj(c){return Se().localStoreProbes.canonicalRootOwnerUids(c,Wj)}function Wj(c){let A=s(),L=null;try{L=A.lstatSync(En(c,".claude")).uid}catch(ce){if(!_(ce))throw ce}return{rootUid:A.statSync(c).uid,gitEntryUid:jj(c),claudeEntryUid:L}}function jj(c){let A=s();try{return A.lstatSync(En(c,".git")).uid}catch(L){throw L}}function $j(c){if(typeof process.getuid!=="function"&&typeof process.geteuid!=="function")return e(`localSettings: not canonicalizing the consent store to ${c} — this platform has no uid semantics to verify directory ownership with, so the store stays at the session cwd (canonicalization is POSIX-only)`,{level:"warn"}),!1;let A=typeof process.geteuid==="function"?process.geteuid():process.getuid?.();try{let{rootUid:L,gitEntryUid:ce,claudeEntryUid:me}=Gj(c);if(L===A&&ce===A&&(me===null||me===A))return!0;return e(`localSettings: not canonicalizing the consent store to ${c} — it (uid ${L}), its .git entry (uid ${ce}), or its .claude entry (uid ${me??"absent"}) is not owned by the current user (uid ${A}); the store stays at the session cwd (the pre-canonicalization behavior). If you own this repo, chown it (including .git and .claude) or run from a directory you own.`,{level:"warn"}),!1}catch(L){return e(`localSettings: not canonicalizing the consent store to ${c} — its ownership could not be verified (${L instanceof Error?L.message:String(L)}); the store stays at the session cwd`,{level:"warn"}),!1}}function Vj(){return Se().localStoreProbes.normalizedRealHomeDir(Kj)}function Kj(){let c=rt(Tj());if(c===null)throw Error("home directory realpath unavailable");return u(c)}var Qf={default:"settings.json",cowork:"cowork_settings.json"};function Yj(c){if(c.coworkPlugins||Pn.CLAUDE_CODE_USE_COWORK_PLUGINS)return Qf.cowork;return Qf.default}function Vo(c,A){switch(c){case"userSettings":return En(qf(c,A),Yj(A));case"projectSettings":case"localSettings":{if(A.cwd===null&&A.projectConfigDir===void 0)return;return En(qf(c,A),fm(c))}case"policySettings":return Dj();case"flagSettings":return A.flagPath}}function fm(c){switch(c){case"projectSettings":return En(".claude","settings.json");case"localSettings":return En(".claude","settings.local.json")}}function mm(c){if(c.cwd===null||pm(c.cwd,c.canonicalGitRoot)===ln(c.cwd))return;if(c.projectConfigDir!==void 0)return;return En(ln(c.cwd),fm("localSettings"))}function gm(c,A){let L=A.store.repoTierFreeze.tier(c);if(L!==void 0)return L.settings;let ce=A.store.perSource.get(c);if(ce!==void 0)return ce;let me=R$(c,A),Ne=me&&Lr(c,me,A);return A.store.perSource.set(c,Ne),Ne}function hm(c){return(c.parentSettingsBehavior??(ts()?"merge":"first-wins"))==="merge"}function Xj(c,A=!1){return!c||hm(c)||A}var Jj=[["permissions","defaultMode"],["modelPicker","replaceBuiltInOptions"]];function Zj(c){let A={};for(let{path:L,restrictive:ce}of Mn()){let me=pn(c,L);if(L[0]==="sandbox"&&no(ce).includes(me))fn(A,L,me)}return A.sandbox??{}}function qj(c,A){let L={};if(c.allowManagedHooksOnly===!0)L.allowManagedHooksOnly=!0;if(c.disableCommandPluginSources===!0)L.disableCommandPluginSources=!0;if(c.allowManagedMcpServersOnly===!0)L.allowManagedMcpServersOnly=!0;if(c.disableClaudeAiConnectors===!0)L.disableClaudeAiConnectors=!0;if(c.syncClaudeAiSkills===!1)L.syncClaudeAiSkills=!1;if(c.syncClaudeAiPlugins===!1)L.syncClaudeAiPlugins=!1;if(c.remoteTools?.allowUnattendedServing===!1)L.remoteTools={...L.remoteTools,allowUnattendedServing:!1};if(c.allowManagedPermissionRulesOnly===!0)L.allowManagedPermissionRulesOnly=!0;if(c.disableAutoMode==="disable")L.disableAutoMode="disable";let ce=c.remoteControl?.shareHostProfile;if(ce==="off"||ce==="basic")L.remoteControl={...L.remoteControl,shareHostProfile:ce};if(wf(c.attribution,c.includeCoAuthoredBy)==="disabled")L.attribution={...L.attribution,commitTrailers:!1};if(c.attribution?.sessionUrl===!1)L.attribution={...L.attribution,sessionUrl:!1};let me=c.strictPluginOnlyCustomization;if(me===!0||Array.isArray(me)&&me.length>0)L.strictPluginOnlyCustomization=me;if(c.deniedMcpServers)L.deniedMcpServers=c.deniedMcpServers;if(c.blockedMarketplaces?.length)L.blockedMarketplaces=c.blockedMarketplaces;if(c.deniedModels&&c.deniedModels.length>0)L.deniedModels=c.deniedModels;if(A.forceLoginOrgUUID===void 0&&c.forceLoginOrgUUID)L.forceLoginOrgUUID=c.forceLoginOrgUUID;for(let Ne of Ga)if(A[Ne]===void 0&&c[Ne])Object.assign(L,{[Ne]:c[Ne]});if(c.enforceAvailableModels===!0)L.enforceAvailableModels=!0;if(c.availableModelsMatch==="exact")L.availableModelsMatch="exact";if(c.permissions){let Ne=wo(c.permissions,["deny","ask"]);for(let Fe of["deny","ask"]){let st=Ne[Fe];if(st!==void 0)Ne[Fe]=st.filter((gt)=>{if(!rr.test(gt))return!0;return e(`Ignoring ${Fe} rule "${gt}" from the parent process's managed settings: a rule starting with "!" removes paths from the rules listed before it instead of restricting anything, so it is not merged into the policy rules. Spell the deny without the exception instead.`,{level:"warn"}),!1})}if(c.permissions.disableBypassPermissionsMode==="disable")Ne.disableBypassPermissionsMode="disable";if(c.permissions.disableAutoMode==="disable")Ne.disableAutoMode="disable";if(c.permissions.blockReadsOutsideWorkingDirectories===!0)Ne.blockReadsOutsideWorkingDirectories=!0;if(A.allowManagedPermissionRulesOnly!==!0){let{allow:Fe,additionalDirectories:st}=c.permissions;if(Fe&&A.sandbox?.network?.allowManagedDomainsOnly!==!0)Ne.allow=Fe;if(st)Ne.additionalDirectories=st}if(Object.keys(Ne).length>0)L.permissions=Ne}if(c.sandbox){let{network:Ne,filesystem:Fe,credentials:st}=c.sandbox,gt={},ht=Ne?wo(Ne,["deniedDomains"]):{},Et=Fe?wo(Fe,["denyRead","denyWrite"]):{};if(Ne){if(A.sandbox?.network?.allowManagedDomainsOnly!==!0&&Ne.allowedDomains)ht.allowedDomains=Ne.allowedDomains}if(Object.keys(ht).length>0)gt.network=ht;if(Fe){if(A.sandbox?.filesystem?.allowManagedReadPathsOnly!==!0&&Fe.allowRead)Et.allowRead=Fe.allowRead}if(Object.keys(Et).length>0)gt.filesystem=Et;if(st){let Rt=(st.files??[]).map((Lt)=>Lt.mode==="deny"?{path:Lt.path,mode:"deny"}:{path:Lt.path,mode:"mask",injectHosts:[]}),Tt=(st.envVars??[]).filter((Lt)=>Lt.mode==="deny").map((Lt)=>({name:Lt.name,mode:"deny"})),It={...Rt.length>0&&{files:Rt},...Tt.length>0&&{envVars:Tt}};if(st.sigv4){let Lt={};for(let Bt of["streaming","presigned","sigv4a"])if(st.sigv4[Bt]==="deny")Lt[Bt]="deny";It.sigv4=Lt}{let Lt=Em(st.awsPairs??[],[]);if(Lt.length>0)It.awsPairs=Lt}if(Object.keys(It).length>0)gt.credentials=It}if(mn(gt,Zj(c)),Object.keys(gt).length>0)L.sandbox=gt}return L}function Em(c,A){let L=Kn,ce=new Set(A.flatMap(em));return v(c.flatMap(em)).filter((me)=>L.includes(me)&&!ce.has(me)).map((me,Ne)=>({accessKeyIdVar:me,secretAccessKeyVar:`${ss}${Ne+1}_`}))}function em(c){if(!r(c))return[];return[c.accessKeyIdVar,c.secretAccessKeyVar,c.sessionTokenVar].filter((A)=>typeof A==="string")}var Qj=new Set([...[...Ai].filter((c)=>c!=="ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION"),...bi,"CLAUDE_CODE_AUTO_MODE_MODEL","CLAUDE_CODE_BG_CLASSIFIER_MODEL","CLAUDE_CODE_SUBAGENT_MODEL_FORCE"]);function e$(c,A){if(!A||!c)return null;let L={};if(c.model!==void 0)L.model=c.model;if(c.availableModels!==void 0)L.availableModels=c.availableModels;if(c.availableModelsMatch==="exact"||c.availableModelsMatch!==void 0&&c.availableModels!==void 0)L.availableModelsMatch=c.availableModelsMatch;if(c.enforceAvailableModels!==void 0)L.enforceAvailableModels=c.enforceAvailableModels;if(c.deniedModels!==void 0&&c.deniedModels.length>0)L.deniedModels=c.deniedModels;if(c.fallbackModel!==void 0)L.fallbackModel=c.fallbackModel;if(c.modelPicker!==void 0)L.modelPicker=c.modelPicker;return Object.keys(L).length>0?L:null}function t$(c){let A=[];for(let L of c?.deniedModels??[]){let{warning:ce}=Df(L);if(ce!==void 0)A.push({file:"managed settings",path:"deniedModels",message:ce,severity:"warning",statusOnly:!0})}return A}function n$(c){if(c?.availableModelsMatch!=="exact")return[];let A=c.availableModels??[];return A.flatMap((L)=>{let ce=Pf(L,A);return ce===void 0?[]:[{file:"managed settings",path:"availableModels",message:ce,severity:"warning",statusOnly:!0}]})}function tm(c,A){let L=c.deniedModels;if(Object.assign(c,A),L!==void 0&&A.deniedModels!==void 0)c.deniedModels=v([...L,...A.deniedModels])}function Ws(c){if(delete c.model,delete c.fallbackModel,delete c.modelPicker,delete c.modelOverrides,c.env){let A={};for(let[L,ce]of Object.entries(c.env))if(!Qj.has(L.toUpperCase()))A[L]=ce;c.env=A}}function o$(c){let A=c.store.policy.allTiers;if(A!==void 0)return A;let L=m$(c);return c.store.policy.allTiers=L,L}function _o(){return C()==="macos"?"plist":"hklm"}function _m(c){let A=Nr(c);if(A.composes==="tier")return"helper";let L=Ko(c);if(A.composes==="remoteSlot"||L.present.remote)return"remote";if(L.present.mdm)return _o();if(L.present.file)return"file";if(L.parentSlice||L.hostModelOverlay)return"parent";let ce=c.hkcu?.();return ce&&Object.keys(ce.settings).length>0?"hkcu":null}function Ko(c){let A=[],L=Ka(c),{settings:ce,servedSnapshot:me}=L;A.push(...L.errors);let Ne=Nr(c),Fe=Ne.composes==="remoteSlot"?Ne.helper:Fa(ce),st=Va(c),gt=st.settings;A.push(...st.errors);let ht=Fa(gt),Et=c.file?.()??sm(c),Rt=Et.settings;A.push(...Et.errors);let Tt=Fa(Rt),It=Ne.composes==="remoteSlot"?Fe!==null:js(L),Lt=js(st),Bt=js(Et),xt=Ba(Fe,It),Yt=Ba(ht,Lt),Xt=Ba(Tt,Bt),Wt=Fe!==null&&xt>=Math.max(Yt,Xt),qt=ht!==null&&Yt>=Xt,on=[[ce,Wt],[gt,qt],[Rt,Tt!==null]],Nn=(Ne.composes==="remoteSlot"?Ne.helper:on.find(([sn,zn])=>sn!==null&&(sn===ce&&me?zn:sn.managedSourcesBehavior!==void 0||zn))?.[0])?.managedSourcesBehavior,Hn=Fe!==null&&!Wt,dn=Hn?null:Fe,Js=ht!==null&&!qt&&dn===null,wt=Js?null:ht,Pt=[],jt=[[Hn,"remote",Fe],[Js,_o(),ht]];for(let[sn,zn,Fn]of jt){if(!sn||Fn===null)continue;if(Pt.push([Fn,zn]),!xr(Fn))continue;let Zo=zn==="remote"&&Lt?_o():"file";A.push({file:Eo[zn],path:Object.keys(Fn).find((kr)=>!mo.includes(kr))??"",message:`${Eo[zn]} holds only values that could not be applied as written, so ${Eo[Zo]} supplies the managed settings while that fail-closed reading still binds beside it (the most restrictive value of each such key applies), until it is fixed.`,severity:"warning",statusOnly:!0})}let{settings:Jt,errors:Qt}=xj(c);A.push(...Qt);let en=(Lt?wt:null)??(Bt?Tt:null),nn=Jt!==null&&(en===null||hm(en)),tn=[l$(dn,me&&Ne.composes!=="remoteSlot",[wt,Tt,...nn?[wo(Jt,Ga)]:[]]),wt,Tt,...Pt.map(([sn])=>sn)].filter((sn)=>sn!==null),Sn=[...dn!==null?["remote"]:[],...wt!==null?[_o()]:[],...Tt!==null?["file"]:[],...Pt.map(([,sn])=>sn)],Dn=dn!==null&&me&&Ne.composes!=="remoteSlot",{admin:Ln,merged:un}=r$(tn,Nn,Dn,Pt.length),yn=Ln===null?[L,st,Et].find(Pr):void 0,_n=Ln??(yn?{}:null),In={remote:dn!==null||yn===L,mdm:wt!==null||yn===st,file:Tt!==null||yn===Et},an=!(dn!==null&&It&&!Dn)&&!(wt!==null&&Lt)&&!Bt,vn=[];if(un){let sn=In.remote?"remote":In.mdm?_o():"file",zn=[[wt,_o()],[Tt,"file"]];for(let[Fn,Zo]of zn){if(Fn===null||Fn===tn[0]||Dn&&Fn===tn[1])continue;let kr=Xa.filter((Qs)=>Object.values(Fn[Qs]??{}).some((ol)=>ol!==void 0&&ol!==null)),[nl]=kr;if(nl===void 0)continue;vn.push(Zo),A.push({file:Eo[Zo],path:nl,message:`${kr.map((Qs)=>`"${Qs}"`).join(" and ")} in ${Eo[Zo]} ignored: policy helper configuration is read from the highest managed settings source only (${Eo[sn]} here), even with managedSourcesBehavior "merge". Configure the helper in that source instead.`,severity:"warning",statusOnly:!0})}}let Zs=(sn)=>sn!==null&&(sn===tn[0]||Object.keys(lr(sn,Rm())).length>0),Ym={remote:Zs(dn),mdm:Zs(wt),file:Zs(Tt)},Xm={allowManagedPermissionRulesOnly:tn.some((sn)=>sn.allowManagedPermissionRulesOnly===!0)||void 0,forceLoginOrgUUID:_n?.forceLoginOrgUUID,...wo(_n??{},Ga),allowedMcpServers:Hs({slot:_n,adminTiers:tn})||Jt?.allowManagedMcpServersOnly===!0&&_n?.allowManagedMcpServersOnly!==!1?ka({slot:_n,adminTiers:tn}):_n?.allowedMcpServers,sandbox:{network:{allowManagedDomainsOnly:tn.some((sn)=>sn.sandbox?.network?.allowManagedDomainsOnly===!0)||void 0},filesystem:{allowManagedReadPathsOnly:tn.some((sn)=>sn.sandbox?.filesystem?.allowManagedReadPathsOnly===!0)||void 0}}},tl=Xj(Ln,an),qs=Jt&&tl?qj(Jt,Xm):null,Jm=qs&&Object.keys(qs).length>0?qs:null,Zm=e$(Jt,c.hostManagedProvider);return{tiers:tn,tierSources:Sn,admin:_n,parentSlice:Jm,hostModelOverlay:Zm,errors:A,present:In,mode:Nn,merged:un,composed:Ym,snapshotFirst:Dn,parentNeverShutOut:an,shadowedHelperSources:vn,parentIncluded:tl,heldEmpty:yn!==void 0}}function r$(c,A,L,ce){let me=c[0];if(!me)return{admin:null,merged:!1};let{managedSourcesBehavior:Ne,...Fe}=me,st=A==="merge"&&c.length>=2;if(!st&&ce===0)return{admin:Ne===void 0?me:Fe,merged:!1};let gt=c.slice(st?1:c.length-ce).map((Et,Rt)=>{let Tt=st&&L&&Rt===0,It=Tt?{...Et}:lr(Et,Rm());if(!Tt){for(let Bt of Jj)if(pn(It,Bt)!==void 0)fn(It,Bt,void 0)}let Lt=pn(It.sandbox,["enabledPlatforms"]);if(Array.isArray(Lt)&&Lt.includes(C()))fn(It,["sandbox","enabledPlatforms"],void 0);else if(Lt!==void 0)delete It.sandbox;return It});if(!st)return nm(Fe,[me,...gt]),{admin:Fe,merged:!1};let ht={};for(let Et of[...gt].reverse())mn(ht,Et,Wa);return mn(ht,Fe,L?c$:Wa),nm(ht,[me,...gt]),s$(ht,[me,...gt],L),{admin:ht,merged:!0}}var Xa=["policyHelper","policyHelpers"],Eo={remote:"server-managed settings",plist:"the managed preferences plist",hklm:"the HKLM policy key",file:"managed-settings.json"};function Xo(c){return Object.keys(c).some((A)=>!mo.includes(A))}function xr(c){return Object.entries(c).some(([A,L])=>!mo.includes(A)&&!Or(L))}function Fa(c){return c&&Xo(c)?c:null}function js(c){return c.settings!==null&&xr(c.settings)&&!c.onlySubstitutes}function Ba(c,A){if(c===null)return-1;if(A)return 2;return xr(c)?1:0}function Sm(c,A){return Object.entries(c).some(([L,ce])=>ce!==null&&!im(L,ce)&&!mo.includes(L))||A!==null&&Xo(A)}function Pr(c){return c.documentHasPolicyContent??(c.settings!==null&&Xo(c.settings))}function So(c){return c.loadState??(c.settings!==null?"loaded":"absent")}function Wn(c,A){if(c==="didNotLoad"||A==="didNotLoad")return"didNotLoad";return c==="loaded"||A==="loaded"?"loaded":"absent"}function Yo(c){return c.userWritable!==!0&&(Pr(c)||c.loadState==="didNotLoad")}function s$(c,A,L){let ce=A.findIndex((Ne)=>Ne.availableModels!==void 0),me=A.findIndex((Ne)=>Ne.modelOverrides!==void 0);if(me!==-1&&(ce===-1||me<=ce||L&&ce===0))c.modelOverrides={...A[me].modelOverrides};else delete c.modelOverrides}var ym=["allowedMcpServers","availableModels","strictKnownMarketplaces","allowedChannelPlugins","allowedProviders"],i$=["awsPairs","ripgrep"];function Om(c,A,L){if(A===void 0)return c;if(Array.isArray(A))return L==="awsPairs"&&Array.isArray(c)?[...A,...Em(c,A)]:[...A];if(!r(A))return A;return z(A,(ce)=>Array.isArray(ce)?[...ce]:ce)}var a$=["allowedMcpServers","availableModels","strictKnownMarketplaces","allowedChannelPlugins","allowedProviders","allowedMarketplaces","allowedHttpHookUrls","httpHookAllowedEnvVars"],Ga=["allowedMcpServers","availableModels","strictKnownMarketplaces","allowedProviders"];function l$(c,A,L){if(c===null||!A)return c;let ce=a$.filter((me)=>L.some((Ne)=>Ne?.[me]!==void 0));return ce.length===0?c:lr(c,ce)}function Wa(c,A,L){if(L!==void 0&&(ym.includes(L)||i$.includes(L)))return Om(c,A,L);return Am(c,A,L)}function c$(c,A,L){if(L!==void 0&&ym.includes(L))return Om(c,A,L);return Am(c,A,L)}function Am(c,A,L){if(Array.isArray(c)&&Array.isArray(A)&&L!=="fallbackModel")return v([...A,...c]);return xn(c,A,L)}function nm(c,A){let L=A[0],ce=c;for(let me of Mn()){let{path:Ne,restrictive:Fe}=me,st=no(Fe),gt=Math.min(...A.map((ht)=>st.indexOf(Wr(me,ht))).filter((ht)=>ht!==-1));if(Number.isFinite(gt))fn(ce,Ne,st[gt]);else if(pn(L,Ne)===void 0&&pn(c,Ne)!==void 0)fn(ce,Ne,void 0)}if(c.strictPluginOnlyCustomization!==!0){let me=v(A.flatMap((Ne)=>Array.isArray(Ne.strictPluginOnlyCustomization)?Ne.strictPluginOnlyCustomization:[]));if(me.length>0)c.strictPluginOnlyCustomization=me;else if(L?.strictPluginOnlyCustomization===void 0)delete c.strictPluginOnlyCustomization}}function Nr(c){let A=c.helper?.()??null;if(!A)return{composes:"none"};let L=c.helperArmedFromRemote?.()===!1?"tier":"remoteSlot";if(c.helperMergesOutput?.()!==!0)return{composes:L,helper:A,mergedOver:null};if(!c.store.policy.mergedHelper){let{base:ce,mergedOver:me}=L==="remoteSlot"?{base:Ka(c).settings,mergedOver:"remote"}:bm(c);c.store.policy.mergedHelper={helper:f$(ce,A),mergedOver:Object.keys(Cm(ce)).length>0?me:null}}return{composes:L,...c.store.policy.mergedHelper}}function bm(c){let A=Va(c);if(Ko({...c,helper:void 0}).present.mdm)return{base:A.settings,mergedOver:_o(),errors:A.errors};let L=c.file?.()??sm(c);return{base:L.settings,mergedOver:"file",errors:[...A.errors,...L.errors]}}function Cm(c){return lr(c??{},Xa)}function d$(c,A){let L=new Map;for(let[me,Ne]of Object.entries(A)){let Fe=me.toUpperCase();if(!L.has(Fe))L.set(Fe,Ne)}let ce={};for(let[me,Ne]of Object.entries(c))ce[me]=L.get(me.toUpperCase())??Ne;return Object.assign(ce,A)}var u$=["forceLoginOrgUUID","gatewayInternalNetworks","allowedHttpHookUrls","httpHookAllowedEnvVars","allowRead"];function p$(c,A,L){let ce=L!==void 0&&A!==void 0&&u$.includes(L)?A:Wa(c,A,L);return ce===A&&Array.isArray(ce)?[...ce]:ce}function f$(c,A){let L=Cm(c),ce=mn({},L,A,p$);if(L.env&&A.env)ce.env=d$(L.env,A.env);return ce}function m$(c){let A=Nr(c);if(A.composes==="tier")return[A.helper];let{tiers:L,parentSlice:ce}=Ko(c);return ce?[...L,ce]:L}function g$(c,A,L){let ce={slot:L,adminTiers:c};return c.flatMap((me,Ne)=>{let Fe=A[Ne],st=xf(me,ce);return Fe!==void 0&&st.length>0?[{source:Fe,keys:st}]:[]})}var Tm=["apiKeyHelper","awsAuthRefresh","awsCredentialExport","gcpAuthRefresh"];var $s=[...Tm,"otelHeadersHelper","proxyAuthHelper"],om=["disableAllHooks","enabledPlugins","extraKnownMarketplaces","agent","allowedHttpHookUrls","httpHookAllowedEnvVars","autoMemoryDirectory","modelOverrides","allowedMcpServers","skipWebFetchPreflight","autoUploadSessions","xaaIdp","claudeMdExcludes","enableAllProjectMcpServers","enabledMcpjsonServers"];function h$(c,A,L){if(!om.some((me)=>A[me]!==void 0)||(L.launchFolderKeysFrom?.(c)??"as_read")==="as_read")return A;let ce={...A};for(let me of om)delete ce[me];return Of("keys"),ce}function Lr(c,A,L){return E$(c,h$(c,A,L),L)}function E$(c,A,L){let ce=$s.some((st)=>A[st]!==void 0);if(!ce&&c!=="policySettings")return A;let me=L.credentialHelperKeysFrom(c);if(me==="as_read")return A;let Ne=c==="policySettings"&&me==="machine_admin"?_$(L):{};if(!ce&&Object.keys(Ne).length===0)return A;let Fe={...A};for(let st of $s)delete Fe[st];return Object.assign(Fe,Ne)}function _$(c){let A=S$(c),L={};for(let ce of $s){let me=A?.[ce];if(me!==void 0)L[ce]=me}return L}function S$(c){let A=y$(c),L=Nr(A);return L.composes==="tier"?L.helper:Ko(A).admin}function y$(c){let A=c.helperArmedFromRemote?.()===!1&&c.helperArmedFromUserWritableBase?.()===!1;return{...c,store:new Te,remote:()=>null,helper:A?c.helper:()=>null,...c.mdm?.().userWritable===!0&&{mdm:()=>({settings:{},errors:[]})}}}var O$=[...$s,"forceLoginOrgUUID","forceLoginMethod","forceLoginGatewayUrl","gatewayInternalNetworks","parentSettingsBehavior","env","modelPicker",...Xa,...mo];function Rm(){return O$}function A$(c){return Dd.some((A)=>c.startsWith(A))||Rd.includes(c)}function b$(c,A,L,ce=0){let me=new Map,Ne=new Map,Fe=!1;for(let[st,gt]of c.entries()){let ht=new Set,Et=A?.[st]===!0;for(let[Rt,Tt]of Object.entries(gt??{})){let It=Rt.toUpperCase(),Lt=A$(It);if(Lt&&Tt.trim()==="")continue;if(Lt&&Fe)continue;if(Lt&&st>ce&&A?.[st]===!0)continue;let Bt=me.get(It);if(Bt!==void 0){if(ht.has(It))Ne.set(Rt,Tt);else if(!Ne.has(Rt))Ne.set(Rt,Bt);continue}if(st>ce&&L?.[st]?.has(It))continue;if(Ne.set(Rt,Tt),ht.add(It),me.set(It,Tt),Lt)Et=!0}if(Et)Fe=!0}return Object.fromEntries(Ne)}var C$="CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION";function rm(c){if(!c)return;let A={};for(let[L,ce]of Object.entries(c))if(L.toUpperCase()!==C$)A[L]=ce;return A}function T$(c,A){let L=Object.entries(c??{}),ce=A??{};return L.length===Object.keys(ce).length&&L.every(([me,Ne])=>ce[me]===Ne)}function Dm(c){let A=Nr(c),L=(c.helperWarnings?.()??[]).filter((xt)=>!yo(xt.path));if(A.composes==="tier"){let{helper:xt}=A;c.store.lastPolicyEnvComposition=null;let Yt=c.hostManagedProvider?{...xt}:xt;if(c.hostManagedProvider)Ws(Yt);c.store.policy.pairedModelOverrides={value:c.hostManagedProvider&&xt.availableModels!==void 0?xt.modelOverrides:void 0},c.store.policy.deniedModelsOverrides={value:c.hostManagedProvider?xt.modelOverrides:void 0};let Xt=c.store.policy.helperBaseStatusNotices??=[...c.helperMergesOutput?.()===!0?bm(c).errors.filter((Wt)=>!Wt.statusOnly):[],...Ko(c).errors.filter((Wt)=>Wt.statusOnly)];return{settings:Yt,errors:[...Xt,...L]}}let{tiers:ce,tierSources:me,admin:Ne,parentSlice:Fe,hostModelOverlay:st,errors:gt,present:ht,snapshotFirst:Et}=Ko(c);if(gt.push(...L),!Ne&&!Fe){c.store.lastPolicyEnvComposition=null,c.store.policy.pairedModelOverrides={value:void 0},c.store.policy.deniedModelsOverrides={value:void 0};let xt=c.hkcu?.();if(xt&&Object.keys(xt.settings).length>0){let Yt=c.hostManagedProvider?{...xt.settings}:xt.settings;if(c.hostManagedProvider){if(Ws(Yt),st)tm(Yt,st)}return{settings:Yt,errors:[...gt,...xt.errors]}}if(st)return{settings:{...st},errors:[...gt,...xt?.errors??[]]};return{settings:null,errors:[...gt,...xt?.errors??[]]}}let Rt=mn({},Fe??{},Ne??{},xn);if(Fe?.availableModelsMatch==="exact")Rt.availableModelsMatch="exact";if(ce.some((xt)=>xt.forceRemoteSettingsRefresh===!0))Rt.forceRemoteSettingsRefresh=!0;let Tt=Pn.CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION===!0,It=Rt.env;if(!Tt){let xt=b$(ce.map((Yt)=>Yt.env),ce.map((Yt)=>(Yt.otelHeadersHelper??"").trim()!==""),ce.map((Yt)=>{let Xt=new Set;for(let Wt of Tm){let qt=Yt[Wt];if(typeof qt==="string"&&qt.trim()!=="")for(let on of Ld[Wt])Xt.add(on)}return Xt.size>0?Xt:void 0}),Et?1:0);if(Object.keys(xt).length>0)Rt.env=xt;else delete Rt.env}if(Rt.env){let xt=rm(Rt.env);if(xt&&Object.keys(xt).length>0)Rt.env=xt;else delete Rt.env}if(c.hostManagedProvider){if(Ws(Rt),st)tm(Rt,st)}let Lt={env:rm(It)};if(c.hostManagedProvider)Ws(Lt);let Bt=!Tt&&!T$(Rt.env,Lt.env);c.store.lastPolicyEnvComposition={unionOptedOut:Tt,unionChangedEnv:Bt,remoteTierPresent:ht.remote,mdmTierPresent:ht.mdm,fileTierPresent:ht.file,adminTierCount:ce.length,tiersWithEnv:Ye(ce,(xt)=>Object.keys(xt.env??{}).length>0)},c.store.policy.pairedModelOverrides={value:c.hostManagedProvider&&Ne?.availableModels!==void 0&&Ne.modelOverrides!==void 0&&st?.availableModels===void 0?Ne.modelOverrides:void 0},c.store.policy.deniedModelsOverrides={value:c.hostManagedProvider?Ne?.modelOverrides:void 0};for(let{source:xt,keys:Yt}of g$(ce,me,Rt)){let[Xt]=Yt;if(Xt===void 0)continue;let Wt=Eo[xt],qt=Yt.length===1;gt.push({file:Wt,path:Xt,message:`${Yt.map((on)=>`"${on}"`).join(" and ")} in ${Wt} ${qt?"is":"are"} not applied: ${Wt} is not the managed settings source that applies for ${qt?"this key":"these keys"} (/status lists the setting sources). Remove ${qt?"it":"them"} from ${Wt}, or set ${qt?"it":"them"} in the source that applies.`,severity:"warning",statusOnly:!0})}return{settings:Rt,errors:gt}}function R$(c,A,{includeLegacyLocalSettings:L=!0}={}){if(c==="policySettings")return Dm(A).settings;let ce=Vo(c,A),{settings:me}=ce?$o(ce,A.store,c==="flagSettings"?A.flagExpectedContent:void 0):{settings:null};if(c==="flagSettings"){let{settings:Ne}=dm(A);if(Ne)return mn(me||{},Ne,xn)}if(c==="localSettings"&&L){let Ne=mm(A);if(Ne){let{settings:Fe}=$o(Ne,A.store);if(Fe)return A.onLegacyLocalSettingsRead?.("per_source"),mn(Fe,me||{},xn)}}return me}function D$(c,A){return{...c,...A}}function xn(c,A,L){if(L==="modelPicker"&&A!==void 0)return Lm(A);if(Array.isArray(c)&&Array.isArray(A)){if(L==="fallbackModel")return A;return v([...c,...A])}if((L==="extraKnownMarketplaces"||L==="managedMcpServers")&&r(c)&&r(A))return D$(c,A);return}function Lm(c){if(!r(c))return c;let A=c.options;return{...c,...Array.isArray(A)&&{options:A.map((L)=>r(L)?{...L}:L)}}}function L$(c){if(c.store.isLoadingFromDisk)return{settings:{},errors:[]};let A=Date.now();tr("info","settings_load_started"),c.store.isLoadingFromDisk=!0;try{let L=c.store.pluginBase,ce={};if(L)ce=mn(ce,L,xn);let me=[],Ne=new Set,Fe=new Set,st=(xt)=>{for(let Yt of xt){let Xt=`${Yt.file}:${Yt.path}:${Yt.message}`;if(!Ne.has(Xt))Ne.add(Xt),me.push(Yt)}},gt=[],ht=[$n()];if(C()==="wsl"&&c.wslInherits?.())ht.push(Rn);let Et=new Set(ht.map((xt)=>ln(En(xt,"managed-settings.json")))),Rt=new Set(ht.map((xt)=>ln(En(xt,"managed-settings.d")))),Tt=(xt)=>{let Yt=ln(xt);return Et.has(Yt)||Rt.has(Vs(Yt))},It=(xt,Yt,Xt)=>{if(Xt?.channelLabel!==!0&&Tt(xt))return;let Wt=Yt.sandbox?.filesystem?.allowRead?.length??0,qt=Yt.sandbox?.network?.allowedDomains?.length??0;if(Wt>0||qt>0)gt.push({file:xt,allowReadCount:Wt,allowedDomainsCount:qt})},Lt=null;for(let xt of ja(c)){if(xt==="policySettings"){let{settings:Wt,errors:qt}=Dm(c);if(Lt=Wt,st(t$(Wt)),st(n$(Wt)),Wt)ce=mn(ce,Lr(xt,Wt,c),xn);st(qt);continue}let Yt=c.store.repoTierFreeze.tier(xt);if(Yt!==void 0){let Wt=Vo(xt,c);if(Wt)Fe.add(ln(Wt));if(st([...Yt.errors]),Yt.settings)ce=mn(ce,Yt.settings,xn);continue}if(xt==="localSettings"){let Wt=mm(c);if(Wt&&!Fe.has(ln(Wt))){Fe.add(ln(Wt));let{settings:qt,errors:on}=$o(Wt,c.store);if(st(on),qt)c.onLegacyLocalSettingsRead?.("cascade"),It(Wt,qt),ce=mn(ce,Lr(xt,qt,c),xn)}}let Xt=Vo(xt,c);if(Xt){let Wt=ln(Xt),qt=xt==="flagSettings"&&c.flagExpectedContent!==void 0;if(!Fe.has(Wt)||qt){Fe.add(Wt);let{settings:on,errors:cn}=$o(Xt,c.store,xt==="flagSettings"?c.flagExpectedContent:void 0);if(st(cn),on){if(xt==="flagSettings"&&c.flagInlineJson===!0)It("--settings (inline JSON)",on,{channelLabel:!0});else It(Xt,on);ce=mn(ce,Lr(xt,on,c),xn)}}}if(xt==="flagSettings"){let{settings:Wt,errors:qt}=dm(c);if(st(qt),Wt)It("SDK inline settings",Wt,{channelLabel:!0}),ce=mn(ce,Lr(xt,Wt,c),xn)}}if(Lt){if(Lt.availableModels!==void 0)ce.availableModels=[...Lt.availableModels];if(Lt.enforceAvailableModels!==void 0)ce.enforceAvailableModels=Lt.enforceAvailableModels;if(Lt.modelPicker!==void 0)ce.modelPicker=Lm(Lt.modelPicker)}let Bt=Lt?.deniedModels;if(Bt!==void 0)ce.deniedModels=[...Bt];else delete ce.deniedModels;if(gt.length>0){let xt=o$(c),Yt=(Xt,Wt,qt,on,cn)=>({file:Xt,path:Wt,severity:"warning",statusOnly:!0,message:`${Wt} is ignored — managed settings set ${qt}, so only ${on} from managed settings are honored. The ${cn===1?"entry":`${cn} entries`} in ${Xt} will NOT apply (see https://code.claude.com/docs/en/settings#sandbox-settings).`});if(xt.some((Xt)=>Xt.sandbox?.filesystem?.allowManagedReadPathsOnly===!0)){for(let Xt of gt)if(Xt.allowReadCount>0)st([Yt(Xt.file,"sandbox.filesystem.allowRead","allowManagedReadPathsOnly","allowRead paths",Xt.allowReadCount)])}if(xt.some((Xt)=>Xt.sandbox?.network?.allowManagedDomainsOnly===!0)){for(let Xt of gt)if(Xt.allowedDomainsCount>0)st([Yt(Xt.file,"sandbox.network.allowedDomains","allowManagedDomainsOnly","allowed domains (and WebFetch domain rules)",Xt.allowedDomainsCount)])}}return tr("info","settings_load_completed",{duration_ms:Date.now()-A,source_count:Fe.size,error_count:me.length}),{settings:ce,errors:me}}finally{c.store.isLoadingFromDisk=!1}}function I$(c){let A=c.store.mergedSettings;if(A!==null)return A;let L=L$(c);return c.store.mergedSettings=L,L}function P$(c){let{settings:A}=I$(c);return A||{}}function Im(c){c.store.invalidateAll();let A=[];for(let L of ja(c)){let ce=gm(L,c);if(ce&&Object.keys(ce).length>0)A.push({source:L,settings:ce})}return{effective:P$(c),sources:A}}function Pm(c,A){let L=ja(A);for(let ce=L.length-1;ce>=0;ce--){let me=L[ce];if(gm(me,A)?.[c]!==void 0)return me}return null}import{execFile as w$}from"child_process";import{accessSync as x$,closeSync as N$,constants as v$,openSync as k$,readSync as M$}from"fs";class vm{promise=null;start(){if(this.promise)return;this.promise=Za()}reset(){this.promise=null}}var U$=new vm;function H$(c){if(!c)return{status:"ok",exitCode:0,errno:null,signal:null};let A=c,L=typeof A.signal==="string"&&A.signal?A.signal:null;if(typeof A.code==="string")return{status:"spawn_error",exitCode:null,errno:A.code,signal:null};if(A.killed===!0)return{status:"timeout",exitCode:null,errno:null,signal:L};if(L)return{status:"killed",exitCode:null,errno:null,signal:L};return{status:"exited",exitCode:typeof A.code==="number"?A.code:null,errno:null,signal:null}}function Ja(c,A,L){let ce=Date.now();return new Promise((me)=>{try{w$(c,A,{encoding:"utf-8",timeout:Mf,windowsHide:!0,...L!==void 0&&{maxBuffer:L}},(Ne,Fe)=>{me({stdout:Fe??"",...H$(Ne),durationMs:Date.now()-ce})})}catch(Ne){let Fe=Ne.code;me({stdout:"",status:"spawn_error",exitCode:null,errno:typeof Fe==="string"?Fe:null,signal:null,durationMs:Date.now()-ce})}})}function wm(c){return{status:c.status,exitCode:c.exitCode,errno:c.errno,signal:c.signal,durationMs:c.durationMs}}function xm(c){return c.status==="ok"||c.status==="exited"&&c.exitCode!==null}function z$(c){return c.status==="spawn_error"&&c.errno==="ERR_CHILD_PROCESS_STDIO_MAXBUFFER"}function F$(c){let A;try{return A=k$(c,"r"),M$(A,Buffer.alloc(1),0,1,0),null}catch(L){return{code:L&&typeof L==="object"&&"code"in L?L.code:void 0,message:L instanceof Error?L.message:String(L)}}finally{if(A!==void 0)try{N$(A)}catch{}}}function Za(){return(async()=>{if(process.platform==="darwin"){let c=Hf(),L=(await Promise.all(c.map(async({path:me,...Ne})=>{try{x$(me,v$.R_OK)}catch(ht){let Et=ht&&typeof ht==="object"&&"code"in ht?ht.code:void 0;if(Et==="ENOENT"||Et==="ENOTDIR")return null;return{stdout:null,unreadReason:ht instanceof Error?ht.message:String(ht),...typeof Et==="string"&&{unreadErrno:Et},...Ne}}let Fe=await Ja(Ma,[...vf,me],Bs);if(!xm(Fe))return{stdout:null,unreadReason:"plutil did not finish converting it",...Ne};if(Fe.status==="ok")return{stdout:Fe.stdout,...Ne};let st=await Ja(Ma,[...kf,me]);if(!xm(st))return{stdout:null,unreadReason:"plutil did not finish checking it",...Ne};if(st.status==="ok")return{stdout:null,unreadReason:"it holds a value plutil cannot convert to JSON (a date or data value)",...Ne};let gt=F$(me);if(gt!==null){if(gt.code==="ENOENT"||gt.code==="ENOTDIR")return null;return{stdout:null,unreadReason:gt.message,...typeof gt.code==="string"&&{unreadErrno:gt.code},...Ne}}return{stdout:"",...Ne}}))).filter((me)=>me!==null),ce=L.findIndex((me)=>me.stdout!==null);return{plistStdouts:ce===-1?L:L.slice(0,ce+1),hklmStdout:null,hkcuStdout:null,outcomes:{hklm:null,hkcu:null}}}if(process.platform==="win32"){let A=`${process.env.SYSTEMROOT||"C:\\Windows"}\\System32\\reg.exe`;return Nm(A)}if(Cr())return Nm(Uf);return{plistStdouts:null,hklmStdout:null,hkcuStdout:null,outcomes:{hklm:null,hkcu:null}}})()}async function Nm(c){let A=(me)=>Ja(c,["query",me,"/v",br],Bs),[L,ce]=await Promise.all([A(zs),A(Fs)]);return{plistStdouts:null,hklmStdout:L.status==="ok"?L.stdout:null,...z$(L)&&{hklmUnreadReason:`the value exceeds ${Bs/1048576} MiB`},hkcuStdout:ce.status==="ok"?ce.stdout:null,outcomes:{hklm:wm(L),hkcu:wm(ce)}}}function km(){return U$.promise}var B$=Object.freeze({settings:{},errors:[],loadState:"absent"}),Jo=Object.freeze({settings:{},errors:[]});class Bm{mdm=null;hkcu=null;wslInherits=!1;loadPromise=null;startLoad(c){if(this.loadPromise)return;this.loadPromise=(async()=>{let A=Date.now(),ce=await(km()??Za()),{mdm:me,hkcu:Ne,wslInherits:Fe}=await q$(ce,c);this.replace(me,Ne,Fe);let st=Date.now()-A;e(`MDM settings load completed in ${st}ms`);try{ee("tengu_managed_settings_os_read",Z$(ce,st))}catch{}if(Object.keys(me.settings).length>0){e(`MDM settings found: ${Object.keys(me.settings).join(", ")}`);try{tr("info","mdm_settings_loaded",{duration_ms:st,key_count:Object.keys(me.settings).length,error_count:me.errors.length})}catch{}}})()}replace(c,A,L){this.mdm=c,this.hkcu=A,this.wslInherits=L}reset(){this.mdm=null,this.hkcu=null,this.wslInherits=!1,this.loadPromise=null}}var Mm="@builtin",G$=["prependPlugins","appendPlugins"];function W$(c){return typeof c==="object"&&c!==null&&!Array.isArray(c)}var j$=new a(()=>new Bm);function vr(){return j$.of(R().host)}function $$(c){vr().startLoad(c)}async function Gm(){let c=vr();if(!c.loadPromise)$$();await c.loadPromise}function Wm(){return vr().mdm??B$}function jm(){return vr().hkcu??Jo}function $m(){return vr().wslInherits}function qa(c,A,{userWritable:L=!1}={}){let ce=to(c,!1);if(!r(ce))return{settings:{},errors:[Xs(A,{userWritable:L})],documentHasPolicyContent:!1,loadState:"didNotLoad"};let me=[],Ne=ce;for(let Tt of L?Ks:[]){if(!(Tt in Ne))continue;if(Ne=Ne===ce?{...ce}:Ne,delete Ne[Tt],!yo(Tt))me.push({file:A,path:Tt,message:`"${Tt}" is only honored from administrator-controlled managed settings and was ignored in ${A}, which the user account can write.`,severity:"warning",statusOnly:!0})}if(L){for(let It of G$){if(!(It in Ne))continue;Ne=Ne===ce?{...ce}:Ne,delete Ne[It],me.push({file:A,path:It,message:`"${It}" is only honored from administrator-controlled managed settings and was ignored in ${A}, which the user account can write.`,severity:"warning",statusOnly:!0})}let Tt=Ne.enabledPlugins;if(W$(Tt)){if(Object.entries(Tt).filter(([Lt,Bt])=>Lt.endsWith(Mm)||Bt!==!1).length>0){Ne=Ne===ce?{...ce}:Ne;let Lt=Hr(Tt,(Bt,xt)=>!xt.endsWith(Mm)&&Bt===!1);if(Object.keys(Lt).length>0)Ne.enabledPlugins=Lt;else delete Ne.enabledPlugins;me.push({file:A,path:"enabledPlugins",message:`"enabledPlugins" entries that enable a plugin, or name a built-in, are only honored from administrator-controlled managed settings and were ignored in ${A}, which the user account can write.`,severity:"warning",statusOnly:!0})}}}let{settings:Fe,errors:st,documentHasPolicyContent:gt,loadState:ht,onlySubstitutes:Et}=Ir(Ne,A),Rt=[...me,...st];return{settings:Fe??{},errors:L?Rt.map((Tt)=>({...Tt.severity==="warning"&&!Tt.startupFatal?Tt:{...V$(Tt),severity:"warning",statusOnly:!0},userWritable:!0})):Rt,documentHasPolicyContent:gt,loadState:ht,...Et&&{onlySubstitutes:Et}}}function V$({startupFatal:c,...A}){return A}function Um(c,A,L,ce){return{file:c,path:"",message:`Managed settings document (${c}) could not be read: ${A}; none of its settings are in effect.`,severity:L?"warning":"fatal",statusOnly:!0,errorClass:"unreadable",...ce!==void 0&&{errno:ce},...L&&{userWritable:!0}}}function Hm(c,A="Settings"){let L=A.replace(/[.*+?^${}()|[\]\\]/g,"\\$&"),ce=new RegExp(`^[ \\t]+${L}[ \\t]+REG_(?:EXPAND_)?SZ[ \\t]+([\\s\\S]*)`,"im"),me=c.match(ce)?.[1]?.trimEnd();return me?me:null}var K$=new Map([["ENOENT",b("ENOENT")],["EACCES",b("EACCES")],["EPERM",b("EPERM")],["ENOEXEC",b("ENOEXEC")],["EAGAIN",b("EAGAIN")],["EMFILE",b("EMFILE")],["ENOMEM",b("ENOMEM")],["ETIMEDOUT",b("ETIMEDOUT")],["ERR_CHILD_PROCESS_STDIO_MAXBUFFER",b("ERR_CHILD_PROCESS_STDIO_MAXBUFFER")]]),Y$=new Map([["SIGTERM",b("SIGTERM")],["SIGKILL",b("SIGKILL")],["SIGINT",b("SIGINT")]]);function X$(c){if(!c)return;return K$.get(c)??b("other")}function J$(c){if(!c)return;return Y$.get(c)??b("other")}function zm(c,A){if(!A)return{};return{[`${c}_status`]:X(A.status),[`${c}_exit_code`]:A.exitCode??void 0,[`${c}_errno`]:X$(A.errno),[`${c}_signal`]:J$(A.signal),[`${c}_duration_ms`]:A.durationMs}}function Z$(c,A){return{is_wsl:Cr(),await_ms:A,...zm("hklm",c.outcomes.hklm),...zm("hkcu",c.outcomes.hkcu)}}async function q$(c,A){let L=[],ce=!1,me="absent";for(let Bt of c.plistStdouts??[]){let{label:xt,userWritable:Yt}=Bt;if(Yt&&ce)continue;let Xt=Bt.stdout===null?{settings:{},errors:[Um(xt,Bt.unreadReason,Yt,Bt.unreadErrno)],documentHasPolicyContent:!1,loadState:"didNotLoad",...Yt&&{userWritable:Yt}}:{...qa(Bt.stdout,xt,{userWritable:Yt}),...Yt&&{userWritable:Yt}};if(Yt?Xo(Xt.settings):Xt.documentHasPolicyContent)return{mdm:{...Xt,errors:[...L,...Xt.errors],documentHasPolicyContent:!0},hkcu:Jo,wslInherits:!1};if(ce||=Yo(Xt),L.push(...Xt.errors),!Yt)me=Wn(me,Xt.loadState)}let Ne=`Registry: ${zs}\\${br}`,Fe=null,st="disarmed";if(c.hklmStdout!==null){let Bt=Hm(c.hklmStdout)??"";Fe=qa(Bt,Ne);let xt=to(Bt,!1);if(r(xt))st=ba(xt)}else if(c.hklmUnreadReason!==void 0)Fe={settings:{},errors:[Um(Ne,c.hklmUnreadReason,!1)],documentHasPolicyContent:!1,loadState:"didNotLoad"};let gt=Fe!==null&&Yo(Fe);if(Fe)L.push(...Fe.errors),me=Wn(me,Fe.loadState);let ht=Cr(),Et="disarmed",Rt=Ne,Tt=[];if(ht){if(Et=st,Et!=="armed"){let Bt=await eV(A);if(Tt=Bt.links,Bt.flag==="armed"||Et==="disarmed")Et=Bt.flag,Rt=Bt.unreadableFlagPath??Rn;if(Et==="disarmed")L.push(...Bt.records),me=Wn(me,Bt.loadState)}}let It=Et!=="disarmed",Lt={settings:{},errors:L,loadState:me};if(ht&&!It){let Bt=new Set(Fe?.errors.filter((xt)=>xt.severity==="warning"));return{mdm:{...Lt,errors:Lt.errors.map((xt)=>Bt.has(xt)?{...xt,wslIgnored:!0}:xt),...Tt.length>0&&{managedDocumentLinks:Tt}},hkcu:Jo,wslInherits:!1}}if(Fe&>)return{mdm:Fe,hkcu:Jo,wslInherits:It};if(Et==="unreadable"){let Bt=await el(Rn,A);return{mdm:{...Lt,errors:Bt?Lt.errors:[...Lt.errors,um(Rt)],documentHasPolicyContent:!0,loadState:Wn(Lt.loadState,"loaded")},hkcu:Jo,wslInherits:It}}if(c.hkcuStdout!==null&&!await Q$(It,A)){let Bt=qa(Hm(c.hkcuStdout)??"",`Registry: ${Fs}\\${br}`,{userWritable:!0});if(!ht||Bt.settings.wslInheritsWindowsSettings===!0){let{wslInheritsWindowsSettings:xt,managedSourcesBehavior:Yt,...Xt}=Bt.settings;return{mdm:Lt,hkcu:{settings:Xt,errors:Bt.errors},wslInherits:It}}if(Bt.errors.length>0)return{mdm:Lt,hkcu:{settings:{},errors:Bt.errors},wslInherits:It}}return{mdm:Lt,hkcu:Jo,wslInherits:It}}async function Vm(c,A){if(l()&&A!==void 0)return(await Pl(c,Ys)).content;return eo(c,Ys)}async function Q$(c,A){if(c&&await el(Rn,A))return!0;return el($n(),A)}async function Fm(c,A){let L;try{L=await Vm(c,A)}catch(ce){return!_(ce)}try{let ce=Ya(L,c,!0);return Yo({...ce,loadState:So(ce)})}catch{return!0}}function Qa(c){let A=n(c);return A==="ENOENT"||A==="ENOTDIR"}async function eV(c){let A=[],L="absent",ce=[],me=new Map;async function Ne(Rt,Tt){let It=Oo(Rn,...Rt),Lt;try{Lt=await Vm(It,c)}catch(Yt){if(Qa(Yt))return"disarmed";A.push(wr(It,Yt)),L="didNotLoad"}let Bt=await Xl(Rn,Rt,Tt,me);if(Bt!==null)ce.push(Bt);if(Lt===void 0)return"disarmed";let xt=Lt.trim()===""?{}:to(Lt,!1);if(!r(xt))return A.push(Xs(It)),L="didNotLoad","disarmed";return L=Wn(L,"loaded"),ba(xt)}let Fe=Oo(Rn,"managed-settings.json"),st=await Ne(["managed-settings.json"]);if(st==="armed")return{flag:st,records:A,loadState:L,links:ce};let gt=st==="unreadable"?Fe:void 0,ht=Oo(Rn,"managed-settings.d"),Et;try{Et=await s().readdir(ht)}catch(Rt){if(!Qa(Rt))A.push(wr(ht,Rt,"directory")),L="didNotLoad";return{flag:st,unreadableFlagPath:gt,records:A,loadState:L,links:ce}}for(let Rt of Et){if(!(Rt.isFile()||Rt.isSymbolicLink())||!Rt.name.endsWith(".json")||Rt.name.startsWith("."))continue;let Tt=await Ne(["managed-settings.d",Rt.name],Rt.isSymbolicLink());if(Tt==="armed")return{flag:Tt,records:A,loadState:L,links:ce};if(Tt==="unreadable")st=Tt,gt??=Oo(ht,Rt.name)}return{flag:st,unreadableFlagPath:gt,records:A,loadState:L,links:ce}}async function el(c,A){if(await Fm(Oo(c,"managed-settings.json"),A))return!0;let L=Oo(c,"managed-settings.d"),ce;try{ce=await s().readdir(L)}catch(me){return!Qa(me)}for(let me of ce)if((me.isFile()||me.isSymbolicLink())&&$a(me.name)&&await Fm(Oo(L,me.name),A))return!0;return!1}var nV={user:"userSettings",project:"projectSettings",local:"localSettings"},Km={userSettings:"user",projectSettings:"project",localSettings:"local",flagSettings:"flag",policySettings:"managed"},oV=["user","project","local"];async function aQ(c={}){await Gm();let A={store:new Te,cwd:tV(c.cwd??s().cwd()),allowedSources:(c.settingSources??oV).map((st)=>nV[st]),parentManaged:c.managedSettings??null,flagInline:null,flagPath:void 0,mdm:Wm,hkcu:jm,wslInherits:$m,credentialHelperKeysFrom:()=>"as_read",...c.serverManagedSettings!==void 0&&{remote:()=>c.serverManagedSettings}},{effective:L,sources:ce}=Im(A),me=_m(A)??void 0,Ne=ce.map(({source:st,settings:gt})=>({source:Km[st],settings:gt,path:st==="policySettings"?void 0:Vo(st,A),...st==="policySettings"&&{policyOrigin:me}})),Fe={};for(let st of Object.keys(L)){let gt=Pm(st,A);if(gt)Fe[st]={source:Km[gt],path:gt==="policySettings"?void 0:Vo(gt,A),...gt==="policySettings"&&{policyOrigin:me}}}return{effective:L,provenance:Fe,sources:Ne}}export{aQ as resolveSettingsForSdk};