✔ F1: an ordinary commit after update-ref is refused until step 8; then it commits and the queue stays at C (1394.333101ms)
✔ F1: a plain `commit -e` whose guard ran before update-ref fails at its own HEAD update (1140.423108ms)
ℹ git commit -e: index.lock free during the editor
✔ F1: a `commit -e -- path` whose guard ran before update-ref fails at its own HEAD update (1043.222642ms)
ℹ git commit -e -- src.txt: index.lock held during the editor
✔ F1: step 8 with index.lock held exits 3, and ordinary commits stay refused until the printed command runs (1048.386411ms)
✔ F1: HEAD moving after the step-7 guard check and before update-ref: refused, nothing published (1040.712346ms)
✔ F1: H is recorded before the canary, so HEAD moving during the step-1 canary is refused at step 7 (1086.167611ms)
✔ F1: a queue commit landing after H is recorded: step 1 says HEAD moved, not the guard (1348.095069ms)
✔ F1: a queue commit landing between the HEAD check and the canary: the failed clean run is reported as HEAD moved (979.495808ms)
✔ F1: a shared-index change during the procedure is not committed (1110.412582ms)
✔ F1: a queue path staged after update-ref: step 8 stops and touches nothing (1131.105975ms)
✔ F1: a missing or a different hook refuses (766.438973ms)
✔ F1: same bytes without the exec bit, a symlinked hook, and core.hooksPath in the local or global scope each refuse before update-ref (1306.178912ms)
✔ F1: the canary refuses a hook that git would not run (778.002631ms)
✔ F1: the guard deactivated after step 1 is refused at the step-7 recheck (1134.54885ms)
✔ bootstrap: implementation-only HEAD, the guard, genesis, the --genesis commit, then an extending commit (1024.291992ms)
✔ bootstrap: --genesis with a base present, no base without --genesis, an op before the first commit, a changed map, another branch (1172.518852ms)
✔ bootstrap: the archived tests and validator run outside any repository (1010.000103ms)
✔ general: an unrelated staged file stays staged, and the committed blobs are the snapshot bytes (1041.606489ms)
✔ general: a queue write after the snapshot is not committed (1292.026899ms)
✔ general: a snapshot whose log does not extend the base refuses (1036.985538ms)
✔ general: install-hook privilege, repair of a same-bytes hook, and its refusals (155.146831ms)
✔ general: environment overrides, a linked worktree and usage (629.476877ms)
✔ general: a queue path staged before the run refuses at step 1 (699.778485ms)
✔ general: HEAD's queue tests failing in the archive refuse (893.985863ms)
✔ genesis document serializes deterministically and replays (5.690766ms)
✔ a hand edit that stays valid JSON fails replay; a formatting-only edit fails re-serialization (3.06713ms)
✔ a tampered result, receipt or viewSha fails replay (2.373692ms)
✔ op ids: 8 to 72 characters for callers, 80 in the log for .outcome entries (0.168839ms)
✔ add: defaults for an ordinary seat, privileged extras, refusals (3.866614ms)
✔ matrix: queued→briefed privileged; briefed→in-progress owner with after satisfied (5.484063ms)
✔ matrix: release, review round, changes requested and waiting-on-jason (14.747406ms)
✔ matrix J5: in-review→done by the gate owner with evidence naming the current round (8.983846ms)
✔ review issue, lead decision 23: none refuses, one is used, several need --issue, later rounds keep it (21.334866ms)
✔ the row schema refuses a round with a null issue, and the A1 review shape (P2) (2.877811ms)
✔ matrix R1: every state × target × actor class matches 8.7, gate owner jason or not, required or not (1364.684904ms)
✔ matrix: blocked keeps the claim and returns only to previousState (4.81789ms)
✔ matrix J4: parking is Jason's, refused while required; unpark returns to queued (2.761016ms)
✔ field edits: who may change what (5.564459ms)
✔ set issues keeps a logged narrowing of closes (N10) (2.874168ms)
✔ text the table shows refuses \ and <, everywhere it enters (N8) (2.281257ms)
✔ every accepted text renders to nine cells on every row (N8) (20.311867ms)
✔ genesis: the map refuses an owner among its row's reviewers; replay doesn't (2026-10-04) (0.441717ms)
✔ times and dates must be calendar values, not just the shape (2026-10-04) (1.62284ms)
✔ replay holds every op id to the caller's rule (N11) (4.080487ms)
✔ note: owner, listed reviewer or privileged; empty clears (0.964886ms)
✔ assign moves the claim with the owner; done clears it (2.13224ms)
✔ render is byte-stable and escapes pipes (0.452775ms)
✔ view classification: current, genuine stale, edited stale marker, changed current body, markers (0.538216ms)
✔ next: resume, then review, then start, then wait, then nothing; lowest id first (15.14622ms)
✔ canonical args make a retry's identity independent of list order (0.255143ms)
✔ manifests, headings and blob ids (0.357285ms)
✔ the migration map: one queue-map block, exact keys (0.479229ms)
✔ every call but `queue` reaches the seat CLI exactly as before A2 (611.676876ms)
✔ `queue` reaches the queue CLI with the rest of the arguments (191.123194ms)
✔ the pre-A2 fixture is the script A2 changed (0.333019ms)
✔ acquire publishes the record by link; release removes only its own lock (13.52631ms)
✔ a kill between the temp write and the link leaves no lock (60.068353ms)
✔ a short or failed temp write refuses and leaves no lock and no temp (12.061676ms)
✔ a link error other than EEXIST refuses (7.528959ms)
✔ an error after the link releases the lock: unreadable gate, failing temp stat (21.595397ms)
✔ a release that fails on a gate path is reported, never a stack trace (P1) (35.474346ms)
✔ a paused holder: another writer waits 10 s, then refuses naming it live (10096.129815ms)
✔ two concurrent unlockers: the second refuses on the gate (41.230435ms)
✔ a writer publishing during an unlock, lock first: unlock sees it live and refuses (15.701983ms)
✔ a writer publishing during an unlock, gate first: the writer releases and refuses (23.024055ms)
✔ a gate swapped while held is left in place and reported, on success and on refusal (N1) (28.760912ms)
✔ a reused pid within one boot is mismatch; unlock removes the lock and never signals the process (19.667117ms)
✔ the same pid and start on a different boot is mismatch (0.759783ms)
✔ a foreign host is unknown whatever the local pid says; unlock refuses (76.967929ms)
✔ unreadable /proc: classification is unknown and acquire refuses (0.651702ms)
✔ invalid records: empty, unparsable, wrong keys, bad start or boot (0.200101ms)
✔ a stale gate blocks writers; --check-gate says mismatch for a reused pid (26.005879ms)
✔ a delayed release by a dead owner, after unlock and a new owner: the inode check keeps the new lock (38.06564ms)
✔ release checks the inode too: a byte-identical lock file with a new inode is left in place (32.627128ms)
✔ unlock refuses a live, unknown or invalid lock, and does nothing without one (58.944186ms)
✔ the migration map validates and renders the golden genesis table (3.663208ms)
✔ the marked QUEUE.md holds every row and parked item between its markers (1.75139ms)
✔ map-check reports each kind of drift (4.798679ms)
✔ a request posts once as the requester; a retry sends nothing (959.691743ms)
✔ each transport answer maps to posted, failed or uncertain (8.9 step 3) (4781.600922ms)
✔ the pre-send checks: GET user must name the requester, under the deadline (1631.634711ms)
✔ the lead's request refuses a token for login sage (969.770152ms)
✔ the credential file: the seat's own, 0600, no symlink, never the shared default (994.404807ms)
✔ an unresolved request blocks a new request, a new round, waiting-on-jason and done (2477.452402ms)
✔ a same-op retry after a kill sends nothing, even with a stale view (3473.638937ms)
✔ a held lock at the outcome exits 3 and names what the transport said (778.547047ms)
✔ late outcomes: after an abandon, and after a resolve with the same or another id (2851.521584ms)
✔ resolve checks the comment: issue, markers, round, candidate and author (1706.445578ms)
✔ the lead resolves a seat's request: the comment's author is the requester, fetched with the lead's token (751.233734ms)
✔ validateRow checks a request round's shape, which every replayed entry must keep (544.743962ms)
✔ request, changes, a new candidate, approval: every round pinned; no review files (1803.039322ms)
✔ a row with no reviewers opens a round that posts nothing (1260.304455ms)
✔ verify-commit: a prospective tree must hold exactly the candidate's paths (1410.610666ms)
✔ semantics: v1 entries replay as before; review entries need v2 (510.662268ms)
✔ set reviewers refuses the row's owner (2026-09-28) (372.077566ms)
✔ the owner records no verdict, even as a listed reviewer (502.160993ms)
✔ a request comment over the length limit is not sent (590.732364ms)
✔ a late POST on a closed row leaves a conflict nothing can resolve, and resolve asks nothing (728.424304ms)
✔ a Jason-gated row reaches waiting-on-jason only on every reviewer's approval (2602.294566ms)
✔ genesis: refusals before anything is written (451.161238ms)
✔ genesis: the map must be committed, well formed, with committed briefs and seats (677.54461ms)
✔ genesis: markers, a stray witness, once only; a retry returns the receipt (608.082873ms)
✔ genesis: a file holding genesis alone with no witness is confirmed by sync or a retry (516.991848ms)
✔ canonical checks: worktree, second clone, detached HEAD, wrong branch, GIT_DIR, foreign code; a symlink works (664.566655ms)
✔ --by that differs from MOSAIC_AGENT_NAME warns on stderr and logs nothing more (N12) (814.810242ms)
✔ op ids: missing, too long, reserved; a retry answers; another payload refuses (724.5479ms)
✔ a retried add returns the id it first allocated, after reassignment and after done (926.400294ms)
✔ Rocko's S4 schedule: a lost result, another writer, then the retry opens no second round (693.102178ms)
✔ the review issue and the evidence round through the CLI (lead decision 23, 8.7) (1314.956701ms)
✔ claims and add defaults through the CLI; candidates are manifests or reachable commits (833.698274ms)
✔ add, set reviewers and assign refuse the row's owner as a reviewer (561.836478ms)
✔ the working-brief check: a changed working copy refuses the start and flags next (740.488008ms)
✔ next: resume first, then nothing for an idle seat; needs a seat (332.061522ms)
✔ view stale: new ops and verify refuse naming the unshown op; retries answer; reads warn; render fixes (723.660043ms)
✔ view unknown: a hand edit, an old marker over an edited body, missing or duplicate markers (1178.648381ms)
✔ a hand edit to queue.json refuses every verb, reads included (583.959579ms)
✔ verify and render --check leave bytes and mtimes unchanged (448.949088ms)
✔ render is byte-stable across runs and repositories (360.732181ms)
✔ snapshot and verify --snapshot (912.444616ms)
✔ usage errors exit 4 (597.283022ms)
✔ a short write, ENOSPC or a file fsync failure: nothing visible, temp removed (328.527789ms)
✔ a rename failure: nothing visible, temp removed (186.448983ms)
✔ a directory fsync failure: uncertain, exit 3, no receipt; the tail refuses new ops; a retry confirms (339.137729ms)
✔ a directory fsync failure, then sync names the op (468.11189ms)
✔ a witness write failure: uncertain, durable, exit 3; the view is untouched (264.12832ms)
✔ the .git fsync after the witness rename fails: uncertain, exit 3, the witness says so (205.910147ms)
✔ confirming a tail fsyncs queue.json and docs/plans before the witness; either failure changes nothing (288.87307ms)
✔ the docs/plans fsync after the view rename fails: the op stands, the view is written, a warning says so (284.74277ms)
✔ a lock swapped while held is left in place and reported, on a receipt and on a refusal (240.77ms)
✔ a lock that cannot be released after an op is reported, on a receipt and on a refusal (228.15754ms)
✔ unlock prints a swapped gate's warning on stderr, the result on stdout (193.658921ms)
✔ a view write that fails keeps the op and reports a stale view (223.76549ms)
✔ SIGKILL before the rename: nothing recorded; the retry removes the leftover temp (651.409888ms)
✔ SIGKILL after the rename, before the witness: the tail refuses new ops and sync names the op (696.44472ms)
✔ SIGKILL after the witness, before the view: the stale refusal names the op (647.791881ms)
✔ SIGKILL after the view, before the receipt: the retry returns the receipt (630.032102ms)
✔ git checkout between steps 1 and 7: step 7 refuses and nothing is written (253.696153ms)
✔ git stash restoring an older valid pair: history lost; accept-history needs privilege, a reason and --yes (1090.94125ms)
✔ a deleted witness: refused after the locked recheck; accept-history records it absent (328.131904ms)
✔ a header edit during a write: the op stands, the view write is skipped with a warning (190.651961ms)
✔ a reader paused between the witness and the file while a writer finishes: no lost-history report (227.906033ms)
✖ rows: every row as show prints it, in list order; writes nothing; same notes and refusals as list (289.368789ms)
✔ file-then-witness order forced by a hook: the locked recheck prevents a false report (256.465651ms)
✔ a writer paused before and after the witness rename: readers see a tail, then a match (240.28425ms)
✔ a true rollback is reported only after the locked recheck; a held lock names its holder instead (623.838286ms)
✔ an accept-history in progress: an unlocked reader waits on the lock and never reports lost history (680.193502ms)
✔ the platform check refuses other filesystems (151.391011ms)
✔ tmpfs passes only a test layer that allows it (N5) (262.172995ms)
✔ unlock keeps a multi-line lock record on stdout (P3) (230.37843ms)
ℹ tests 149
ℹ suites 0
ℹ pass 148
ℹ fail 1
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 31778.109925

✖ failing tests:

test at tests/write.test.mjs:337:1
✖ rows: every row as show prints it, in list order; writes nothing; same notes and refusals as list (289.368789ms)
  AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal:
  + actual - expected
  
  + []
  - [
  -   'rev 1 visible, not confirmed durable'
  - ]
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r54b/mutwt/packages/queue/tests/write.test.mjs:349:10)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: [],
    expected: [ 'rev 1 visible, not confirmed durable' ],
    operator: 'deepStrictEqual',
    diff: 'simple'
  }
