✔ W1: two processes acquire the same pair at once; exactly one claim (296.879466ms)
✔ W1: two writers publish the same revision at once: one wins, the other gets null, the winner's record stays (33.602049ms)
✔ W1: a revision name appears only after its bytes are synced; before that, only a temp file exists (19.988722ms)
✔ W2: acquire while a claim is reserved or active refuses already-active (634.77033ms)
✔ W3: acquire while stopping, uncertain, or stopped without proof refuses unsafe-replacement (453.736192ms)
✔ W4: same session with another seat tuple, and the reverse, both refuse; a loser on the seat key closes it no-unit (252.635706ms)
✔ W4: a hard link of one session under another seat is the same session: the second controller refuses already-active and launches nothing (207.837078ms)
✔ W4: a copy of one session under another seat is the same session: the second controller refuses already-active and launches nothing (246.981625ms)
✔ W4: a session header ID that changes after construction refuses target; nothing is claimed or launched (2.20387ms)
✔ W5: SIGKILL between every publication barrier of acquire and transition; restart never finds two holders or a lost claim (10701.199275ms)
✔ W5: SIGKILL between every publication barrier of release; restart finishes or holds the release (28622.102803ms)
✔ W6: controller killed mid-turn while the engine lives; restart is uncertain, no launch, prompts refuse (255.657875ms)
✔ W12: a live owner paused with SIGSTOP; a second controller refuses already-active and changes nothing (142.962745ms)
✔ W13: crash after the engine spawns, before active; restart finds the live unit: uncertain, no second spawn, force stop only (373.96892ms)
✔ W14: crash after reservation, before the spawn marker: stopped with a no-unit observation; the pair is free (273.544328ms)
✔ W20: crash after the spawn marker, scope collected; uncertain in both runs, the marker is copied, no launch until a boot proof (343.973996ms)
✔ W15: crash between the two keys during release; restart finishes it under the same claim ID (106.330855ms)
✔ W7: recorded boot ID differs on the same machine: stopped with a boot proof; open tool calls become uncertain (177.406761ms)
✔ W8: resume after a proven stop with the same pins: new claim ID, generation +1, same conversation, branch and leaf (272.637294ms)
✔ W9: resume with a changed binary, argv digest, branch or leaf is refused and the claim is unchanged (727.233609ms)
✔ W11: the controller writes no session file; only the fake engine's own appends appear (195.085291ms)
✔ W16: a highest revision that won't parse holds the pair uncertain; the older stopped revision is not reused (97.562888ms)
✔ W17: a claim root copied from another host refuses foreign-host and promotes nothing (72.519482ms)
✔ G1: a session path or claim root under .pi/state, ~/.claude, the data root or a registration refuses at construction (4.174078ms)
✔ G2: a symlink inside the fixture root to a live session file is refused by the real-path check (1.070535ms)
✔ G3: a fixture path swapped for a live path after construction is refused at bind (1.848447ms)
✔ K1: force stop kills a tool child that called setsid; stopped with a verified proof (3269.439191ms)
✔ K2: K1 on the process-group fallback ends uncertain, never stopped (444.526081ms)
✔ K3: SIGTERM acknowledged while a member lives: stopping until the kill phase, never stopped from TERM (2779.973182ms)
✔ K4: two engines; force stop one; the other survives by independent observation (4990.707418ms)
✔ K5: a stop during a tool call leaves the effect uncertain, and it is shown (2602.780023ms)
✔ K12: a member forking in a loop: the freeze stops it, enumeration is complete, populated 0 after cgroup.kill (2523.308505ms)
✔ K13: a member writing its pid into another cgroup is refused by the namespace; the kill is complete (2355.186127ms)
✔ K15: the shim gone, engine/cgroup.events unreadable, or the engine cgroup missing: evidence unavailable, not empty; uncertain (5053.411674ms)
✔ K10: controller killed between the TERM and kill phases: restart checks the invocation ID and re-runs from TERM for the same stop (714.496723ms)
✔ K11: controller killed after the confirmation is recorded, before TERM: restart checks the invocation ID and re-runs from TERM for the same stop (564.706305ms)
✔ K14: a unit with the recorded name but another invocation ID: evidence unavailable, no signals, uncertain (577.380937ms)
✔ K6: recover without proof, without confirmation, or with changed pins is refused (661.878683ms)
✔ K7: recover after proof, then launch: new claim and execution, generation +1, same leaf; the cancelled prompt is not replayed (366.946461ms)
✔ K8: an engine that loads another leaf on resume is refused before admission; it stays claimed until a proven stop (557.442049ms)
✔ K9: an interrupt that never settles stays uncertain; force stop stays available; takeover is refused while fenced (3290.493335ms)
✔ K16: a claim from another machine ID refuses foreign-host; no boot proof is issued (24.581982ms)
✔ K17: two launcher calls with one eligibility record: one launch, the other refuses, no second engine (376.593608ms)
✔ K18: the leaf changes after eligibility: launch refused; the reservation stays until released with proof (271.967232ms)
✔ K19: a scope launched with only the engine environment still reaches the user manager; the engine sees no other names (82.577497ms)
✔ S1: `/goal x`, with leading spaces or a tab, refuses text-policy at admission; zero engine bytes (298.450359ms)
✔ S2: every prefix pinned Pi interprets is refused, from the list the code uses; the rest reach the engine exactly (219.778174ms)
✔ S3: `/goal` on the second line is pinned from the source: Pi checks only index 0, so it is admitted and sent exactly (435.308373ms)
✔ S4: a `/` left in the composer is cleared when control transfers and returns; the next submit sends only the new text (377.306704ms)
✔ S5: an observer terminal gets a paste then Enter, as send-message.sh does: not admitted: controller, nothing sent (208.797517ms)
✔ S6: a mediated-shaped registration (no tmux) passed to the board's replyToRow: 409 no tmux session; exec never runs (0.421764ms)
✔ S7: ESC, bracketed-paste markers and U+2028/U+2029 travel as one JSON string; the engine receives the exact text in one record (226.260973ms)
✔ P3: a Pi confirm, select, input or editor dialog is shown disabled with a reason and never answered (325.624776ms)
✔ E1: send, ack, user, toolCall, toolResult, final answer: shown once, no refresh, draft and reading position kept (254.701092ms)
✔ E2: U+2028, U+2029 inside JSON strings and CRLF line ends each parse as one record, on the splitter and through the controller (249.170151ms)
✔ E3: a multipart final, two blocks, null request correlation and duplicate delivery (225.932826ms)
✔ E4: a page read after message_end but before its entry is persisted: marker at the seam, re-read after run-settled, each message once (239.512549ms)
✔ E4: a gap or a new epoch also reconciles; nothing is concatenated across a gap (10.773179ms)
✔ E5: an unknown native event gives no client event; evidence records its type and bytes; the terminal count goes up (229.954779ms)
✔ E6: a tool result delayed across a pause and a reconnect is reconciled without a manual refresh (241.043249ms)
✔ E7: the terminal renders the same stream as the library client, as observer and then as controller, and submits only as controller (268.968065ms)
✔ terminal: engine control characters are made visible; a lost connection refuses submit (221.082673ms)
✔ terminal: outcome unknown is shown as such, with no resend offer, and nothing is resent (0.391363ms)
✔ terminal: text after Enter in the same input chunk starts the next message; it never joins the one submitted (0.275444ms)
✔ terminal: a paste-start marker split right after its ESC still opens the paste; the Enter inside it never submits (0.318012ms)
✖ terminal: Ctrl-T then Enter in one chunk is judged after the takeover, as if typed one key at a time (Filbert F2, #1507) (1.048883ms)
✔ terminal: an action that throws still releases the input held behind it, in order, then rethrows (5.38194ms)
✖ terminal: after an action throws, later input still runs; input() puts the error in the status line (Filbert N1 on #1522) (0.417655ms)
✔ terminal: invisible and bidi characters are made visible; head, status and notice lines stay one line (0.108076ms)
✔ every record these fixtures produced is a valid CHAT-01 record (E5: no record fails the schema) (226.913325ms)
✔ H1: two takeovers with the same expected generation: one wins, +1; the other refuses generation (263.394406ms)
✔ H2: the old controller's prompt after a takeover commits is refused with zero engine bytes (569.967493ms)
✔ H3: a takeover while a prompt holds the dispatch lock: written under the old actor, or refused; never both (905.563084ms)
✔ H4: self-takeover is refused (234.183058ms)
✔ H9: Interrupt racing a prompt's dispatch: before the write, dispatch-refused and no-turn; after, §3 rules (517.222561ms)
✔ H10: Interrupt and force stop together: one stop chain, force stop supersedes (1125.986535ms)
✔ H10: an overlap during the pause before the abort: no abort, the stop ends uncertain (219.559426ms)
✔ H10: a no-turn Interrupt lifts only its own fence; admission stays closed under force stop, overlap or revocation (716.109466ms)
✔ H11: the controller disconnects mid-turn: work continues, the claim is unchanged, control stays put (333.659671ms)
✔ H12: an exact retry after reconnecting to the same incarnation returns the same receipt; one dispatch (216.405515ms)
✔ H13: a retry with the same request ID and different text is refused (198.95763ms)
✔ H14: late stdout from the old engine after a replacement is dropped by incarnation, counted, never rendered (642.435178ms)
✔ H15: a revoked connection's command is refused; the revocation fence holds (319.532164ms)
✔ H16: a second controller for the same session refuses already-active; the first is untouched (225.456339ms)
✔ H10: a second force stop while the first escalation runs refuses fenced; one escalation, and the claim records only the first stop's phases (978.006103ms)
✔ a force stop whose fence throws leaves no escalation flag behind, so the next force stop runs (Darkwing F2, #1507) (468.487843ms)
✔ H17: a confirmation reused, answered from another connection, or used after the stop changed is refused (1216.293202ms)
✔ H18: two prompts before any native output: the second refuses busy; one engine write (235.150364ms)
✔ H19: the pipe fails mid-line under a large prompt: delivery-unknown transport-unknown, poisoned, no later write (373.41183ms)
✔ H19: the link itself never writes again after an unknown outcome, whoever calls it (0.694791ms)
✔ H19: the controller dies mid-write of a large line: after restart the outcome is unknown and nothing is resent (692.751101ms)
✔ H20: the line is written but the ack is lost when the controller dies: orphan, outcome unknown, nothing resent (557.237066ms)
✔ H21: a retry of the exact request with the old token after a crash is stale-incarnation; no second write (726.214256ms)
✔ H22: after H21 and a valid recovery, a new request with the new token is admitted (3075.482023ms)
✔ H23: requests pending at a restart are not resent; each shows outcome unknown (614.452576ms)
✔ a plain conversation: catalogue row, one page, CHAT-01 records (7.735959ms)
✔ native entries map to blocks: tools, thinking, bash, notices, ids that do not fit (1.850053ms)
✔ F1: a malformed line is an unavailable part at its position, and reading continues (1.901921ms)
✔ F1: a missing parent stops the history with a notice that names the unreadable lines (2.66378ms)
✔ F1: an unreadable fork is never merged into another branch's history (1.606899ms)
✔ F1: a follow stays on its branch when the next entry's parent is unreadable (2.120974ms)
✔ F1: a file whose entries are all unreadable shows a notice per line (0.794561ms)
✔ F2: a truncated trailing line marks the view incomplete, not an error (1.319727ms)
✔ pagination: 100 parts, then the rest; parts concatenate to the whole branch (3.680396ms)
✔ F3: a replaced file (new inode) refuses old cursors with reconcile (4.255977ms)
✔ F4: a same-inode rewrite of the prefix refuses old cursors with reconcile (4.929874ms)
✔ F5: growth between pages keeps the epoch and the page stops at the pinned length (4.998962ms)
✔ F6: unknown, foreign and expired cursors refuse and leave the cursor usable (7.120789ms)
✔ F7: a symlinked file and a symlinked directory component are refused, never opened (7.957622ms)
✔ F8: a file swapped for a symlink after the catalogue is refused (1.729244ms)
✔ F9: registrations never add or redirect a root (1.649047ms)
✔ F10: a header cwd naming another project is refused (4.348808ms)
✔ F11: parentSession renders with a marker and the parent is never opened (0.780672ms)
✔ F12: two leaves: the default leaf is shown and the other branch reads alone (3.913409ms)
✔ F12: a follow refuses when an appended duplicate id changes the branch's earlier parts (2.097609ms)
✔ F12: a second root (Pi's resetLeaf) starts its own branch (1.327085ms)
✔ F13: compaction is a marker in place, then the retained content (0.81907ms)
✔ F14: long strings split into fragments and parts, reassemble exactly, and pages respect the byte cap (557.254154ms)
✔ fragments never cut a surrogate pair and keep an empty string (4.98921ms)
✔ F15: a Claude seat is an unsupported-harness placeholder whose directory is never read (1.683243ms)
✔ unknown conversations, empty files and non-Pi files refuse (2.338516ms)
✔ an unreadable file or root inside the roots is refused per row, not a failed catalogue (1.071919ms)
✔ a seat directory without search permission refuses that root, not the catalogue (1.93729ms)
✔ every page and cursor is a valid CHAT-01 record (834.056181ms)
✔ the engine pin holds for the installed package (2.722366ms)
✔ pinned Pi, sealed and without credentials, answers the controller's commands with the shapes the fake models (268.4409ms)
✔ sealed, pinned Pi ignores a trusted project's .pi resources; --approve past the seal would load them, and checkSeal refuses it (Filbert F2 on #1522) (540.509377ms)
✔ pinned Pi appends thinking_level_change at start when the branch lacks one, so the leaf moves (K8 then fails closed) (287.689775ms)
✔ N25: ordinary Interrupt reconciles; a non-empty queue_update in the window is O5 (611.026628ms)
✔ N1: an extension's follow-up queued after the fence is cleared before any abort; O5, Unknown (764.388387ms)
✔ N1: a follow-up queued before the fence is O5 at once; the Interrupt refuses fenced (264.467228ms)
✔ N2: with abort first, the fake runs the external item (the ordering guard has teeth) (21.700682ms)
✔ N3: the fence lands in preflight, preflight errors, no run: failed, No run, uncertain (387.715704ms)
✔ N4: the ack arrives after the first abort and a run starts: clear and abort again; Interrupted (238.933065ms)
✔ N5: an input handler takes the prompt: ack, no run, delivery-unknown handled-without-run (359.666641ms)
✔ N6: an extension queues between clear_queue and abort: O5 and O6, Unknown (522.709088ms)
✔ N7: clear_queue times out: no abort, nativeQueue unknown, force stop still ends it (1904.764961ms)
✔ N7: clear_queue answers an error: no abort, nativeQueue unknown, the link not poisoned (210.184241ms)
✔ N8: an extension prompt starts a run during Mosaic preflight; the losing settle is O3 (302.764591ms)
✔ N9: a run that started before the fence and ends aborted: failed interrupted, Interrupted (210.628946ms)
✔ N9: decision 34: a run that ends aborted with no stop in progress: aborted-without-stop, uncertain, outcome unknown (252.47441ms)
✔ N9: an aborted that lands after the fence but before any abort is written: aborted-without-stop, Unknown (373.828393ms)
✔ N10: fake conformance (32.105439ms)
✔ N11: the run fails before any user message_start: delivery-unknown ack-without-start, never failed (459.654921ms)
✔ N12: input that starts a run after the final empty clear is O1 and not part of the stop's proof (316.01937ms)
✔ N13: agent_start with no slot held is O1; a later prompt refuses with zero engine bytes (303.206479ms)
✔ N14: the run completes while clear_queue is in flight: finished, Completed first, uncertain (472.412874ms)
✔ N14: the run completes after the abort is written, before Pi applies it: finished, never relabelled (428.917428ms)
✔ N15: the fence lands in preflight, then an input handler takes it: handled-without-run, No run (699.491437ms)
✔ N16: Interrupt with no slot and no run refuses no-turn: no stop, no bytes, admission open (282.746565ms)
✔ N17: the run fails on its own during the exchange: failed, Failed on its own (418.366953ms)
✔ N18: no final assistant message_end, or a lost line: working stays working; before working, transport-unknown (822.805927ms)
✔ N19: a losing extension prompt settles inside the Mosaic run before its user message: O3, run-overlap (583.639915ms)
✔ N20: an extension triggerTurn during Mosaic preflight starts first; while streaming it queues with no signal (439.183085ms)
✔ N21: a losing settle after the receipt settled finished is O2; the receipt stays finished (225.307202ms)
✔ N22: an agent-level custom message is dropped by the clear with no signal; evidence names the seal (250.532768ms)
✔ N23: a nextTurn message survives clear and abort and attaches to the next prompt, with no signal (249.623854ms)
✔ N24: the seal is an allow-list: --extension, a missing --no-* flag, a second --mode or --session, a session or output flag, or a stray word refuses unsealed-engine; no engine starts (286.109959ms)
✔ N24b: the seal covers the engine command and environment: config can't name either, the env is built from names, and a mutated command is refused at bind (270.012875ms)
ℹ tests 159
ℹ suites 0
ℹ pass 157
ℹ fail 2
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 46457.536737

✖ failing tests:

test at packages/conversation/tests/flows.test.mjs:622:1
✖ terminal: Ctrl-T then Enter in one chunk is judged after the takeover, as if typed one key at a time (Filbert F2, #1507) (1.048883ms)
  AssertionError [ERR_ASSERTION]: text typed after the takeover is sent
  + actual - expected
  
  + []
  - [
  -   'hi'
  - ]
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r40/wt/packages/conversation/tests/flows.test.mjs:629:12)
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: [],
    expected: [ 'hi' ],
    operator: 'deepStrictEqual',
    diff: 'simple'
  }

test at packages/conversation/tests/flows.test.mjs:695:1
✖ terminal: after an action throws, later input still runs; input() puts the error in the status line (Filbert N1 on #1522) (0.417655ms)
  AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal:
  + actual - expected
  
  + []
  - [
  -   'hi'
  - ]
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r40/wt/packages/conversation/tests/flows.test.mjs:710:10)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: [],
    expected: [ 'hi' ],
    operator: 'deepStrictEqual',
    diff: 'simple'
  }
