✔ config directory and file path follow MOSAIC_CONFIG (1.452137ms)
✔ the fixture business validates and comes back frozen (5.578344ms)
✔ two instances may share a definition (1.441253ms)
✔ top-level refusals (5.152839ms)
✔ arbiters and projects (7.563057ms)
✔ role instances (3.855653ms)
✔ Vikunja bots (9.49824ms)
✔ a role without Vikunja takes no tracker block (3.98548ms)
✔ credential references match the definition's services (5.343946ms)
✔ launch (10.588077ms)
✔ loadBusiness: file checks (3.090109ms)
✔ loadBusiness: not a regular file (42.83915ms)
✔ loading writes nothing (1.21552ms)
✔ names that are Object.prototype properties don't count as declared (2.449986ms)
✔ the shipped example refuses as written and validates once filled in (1.466161ms)
✔ usage errors exit 4 (285.939347ms)
✔ validate: a good business exits 0 and prints instance digests (65.835211ms)
✔ validate: project files (316.787862ms)
✔ validate: missing files and a broken system config (242.410619ms)
✔ validate: credential reference problems exit 2 and name each one (66.429598ms)
✔ validate: a token file inside the repository is refused (61.975689ms)
✔ validate: role definitions come from MOSAIC_ROLES_DIR (189.828413ms)
✔ resolve: prints one instance's record (192.088605ms)
✔ resolve: refusals (370.817334ms)
✔ parse: exactly one of file or env, plus the service's date (2.912184ms)
✔ check: a good file has no problems (0.697025ms)
✔ check never opens the file: a write-only token passes (0.352511ms)
✔ check: file problems (0.754102ms)
✔ check: token files can't live in the repository or dataRoot, even through a linked directory (0.720844ms)
✔ check: dates and environment references (0.368981ms)
✔ path and load (2.114907ms)
✔ refusals (1.225659ms)
✔ systemVars flattens the validated config (2.575859ms)
✔ precedence: system, business, project, project role, agent (8.530151ms)
✔ limits narrow the definition and never widen it (3.350867ms)
✔ role.launch stays within-role only for the instance the launch block names (7.962531ms)
✔ limits.authority without role.launch leaves the launcher with no launch block (2.886369ms)
✔ limits.authority narrows cross-role actions too (2.092685ms)
✔ classify (2.292167ms)
✔ the record carries what the broker and launcher need (1.011055ms)
✔ digest: key order doesn't matter, any value change does (7.193711ms)
✔ refusals (2.432054ms)
✔ the four shipped version 2 roles load (3.955928ms)
✔ shipped role scopes match addendum B section 2 and the SR runbook (1.776154ms)
✔ shipped authority follows the note's table (1.111235ms)
✔ version 1 files keep loading with no authority (1.386411ms)
✔ the conductor policy isn't a role (0.428507ms)
✔ a missing role file is exit 4, a symbolic link too (0.540084ms)
✔ version 2 refusals (5.32113ms)
✔ authority: closed vocabulary, no gated-only action, no overlap (3.077258ms)
✔ credentials: Gitea scopes (1.661659ms)
✔ credentials: Vikunja scopes are a group-to-verbs map from the grantable list (2.161649ms)
✔ credentials: services (0.922355ms)
✔ contract: a non-empty regular Markdown file beside the role file (0.714248ms)
✔ every key names known layers and a merge rule (1.083157ms)
✔ unknown keys and wrong layers refuse (0.688039ms)
✔ types (2.09786ms)
✔ merge: defaults, then the most specific layer wins (0.434102ms)
✔ merge: limits only narrow, and provenance lists each source (0.444915ms)
✔ merge doesn't change its inputs (0.176633ms)
ℹ tests 60
ℹ suites 0
ℹ pass 60
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 1866.960358
