✔ sessionModel: agent vars win, then the system's execution settings (16.351458ms)
✔ a pi bundle: prompt, policy, tools and manifest, 0600 in a 0700 directory (8.486143ms)
✔ a claude-code bundle adds the wrapped gate hook and the MCP config (4.924205ms)
✔ a bundle is written once: an existing file refuses (7.714847ms)
✔ a path with a single quote can't go into the hook command (2.914831ms)
✔ allow exits 0, a deny exits 2 with the reason on stderr (181.225521ms)
✔ a missing or wrong policy, or a bad event, exits 2 (98.543767ms)
✔ the bundle's wrapped command: a missing gate or node still blocks (1103.411534ms)
✔ claude: typed tools through MCP, the hook blocks, builtins outside --tools don't exist (1129.58691ms)
✔ claude: the hook alone blocks a path outside the workspace (591.639549ms)
✔ claude: a second turn resumes the first turn's session (766.438591ms)
✔ claude adapter: --restricted is always passed (5.009647ms)
✔ claude: CLAUDE.md files and auto-memory don't reach the model; without --restricted they do (835.863042ms)
✔ claude: a missing hook or MCP file refuses before claude starts (7.995462ms)
✔ pi: policy tools and typed tools pass, anything else is blocked (5.256191ms)
✔ claude: builtins map from pi names, typed tools need the mcp prefix (1.416363ms)
✔ file tool paths must resolve inside the workspace (1.80134ms)
✔ pi's own path normalisation can't be used to step out (1.464984ms)
✔ a symlink inside the workspace that points out is outside (1.213263ms)
✔ a dangling symlink is refused at any depth, in both harnesses (4.554847ms)
✔ claude path fields per tool (1.932074ms)
✔ glob patterns stay inside the workspace (2.028059ms)
✔ a path that can't be checked is blocked (1.256848ms)
✔ initialize, ping and tools/list (66.673477ms)
✔ tools/call goes through the tool socket; a refusal is an isError result (42.240996ms)
✔ unknown tools and methods are JSON-RPC errors and never reach the socket (46.54748ms)
✔ a missing argument is a usage error (51.277827ms)
✔ pi: typed tools reach the socket, the gate blocks, agent_end writes the marker (504.50749ms)
✔ pi: a write through a dangling symlink is blocked, and nothing appears outside (494.672447ms)
✔ pi: a missing extension refuses before any model call (17.138359ms)
✔ pi: an extension without its configuration fails pi's start (370.307009ms)
✔ founderCheck: founder variables, then a needed service without a usable token (2.439718ms)
✔ turnRequest names the sender, class, reply and decision (0.393876ms)
✔ a message becomes a turn, the answer goes back as a RESULT, SIGTERM releases and exits 0 (356.294943ms)
✔ a SIGTERM before the claim stops the runner with exit 0 and no claim (179.594114ms)
✔ typed tools carry the runner's capability; launch goes to the host's launch socket (599.210351ms)
✔ a RESULT gets no automatic reply; failed turns reply with the reason (1476.753805ms)
✔ SIGTERM during a turn kills the turn's process group and still exits 0 (213.92013ms)
✔ founder credentials stop before the claim (20) (209.305788ms)
✔ a refused claim exits 21; an ended run's capability exits 22 (250.403664ms)
✔ the launch ending under a running session exits 22 (167.505496ms)
✔ a broker that stays unreachable exits 23 after brokerRetries polls (271.078035ms)
✔ a broker that is down at the claim exits 23, not 21 (101.373681ms)
✔ no capability, or a malformed one, on stdin exits 2 (216.397926ms)
✔ a missing or malformed policy exits 2 before the claim (166.370584ms)
✔ the PM gets launch, its task verbs and the reads (11.256865ms)
✔ a coder gets no launch, no resolve_decision, and no task tools without a tracker (6.134091ms)
✔ launch only when the business's launch block names the instance as launcher (4.965631ms)
✔ an action outside the instance's authority has no tool (2.448784ms)
✔ callTool: one JSON line out, the result back, a refusal rejects (12.464112ms)
ℹ tests 50
ℹ suites 0
ℹ pass 50
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 10983.011443
