✔ sessionModel: agent vars win, then the system's execution settings (14.572512ms)
✔ a pi bundle: prompt, policy, tools and manifest, 0600 in a 0700 directory (6.174951ms)
✔ a claude-code bundle adds the wrapped gate hook and the MCP config (4.600206ms)
✔ a bundle is written once: an existing file refuses (3.074615ms)
✔ a path with a single quote can't go into the hook command (2.569843ms)
✔ allow exits 0, a deny exits 2 with the reason on stderr (174.908763ms)
✔ a missing or wrong policy, or a bad event, exits 2 (103.705751ms)
✔ the bundle's wrapped command: a missing gate or node still blocks (1110.897092ms)
✔ claude: typed tools through MCP, the hook blocks, builtins outside --tools don't exist (979.613205ms)
✔ claude: the hook alone blocks a path outside the workspace (566.447612ms)
✔ claude: a second turn resumes the first turn's session (772.777865ms)
✖ claude adapter: --restricted is always passed (5.834159ms)
✖ claude: CLAUDE.md files and auto-memory don't reach the model; without --restricted they do (419.9886ms)
✔ claude: a missing hook or MCP file refuses before claude starts (8.321942ms)
✔ pi: policy tools and typed tools pass, anything else is blocked (4.740971ms)
✔ claude: builtins map from pi names, typed tools need the mcp prefix (1.104453ms)
✔ file tool paths must resolve inside the workspace (1.531795ms)
✔ pi's own path normalisation can't be used to step out (1.36492ms)
✔ a symlink inside the workspace that points out is outside (1.197825ms)
✔ a dangling symlink is refused at any depth, in both harnesses (3.833957ms)
✔ read is checked under every spelling pi's read would open, in both harnesses (20.828356ms)
✔ other spellings cover directories, dangling links and pi's cwd (3.062402ms)
✔ claude path fields per tool (0.980935ms)
✔ glob patterns stay inside the workspace (1.034332ms)
✔ a path that can't be checked is blocked (0.50853ms)
✔ initialize, ping and tools/list (71.834384ms)
✔ tools/call goes through the tool socket; a refusal is an isError result (40.220197ms)
✔ unknown tools and methods are JSON-RPC errors and never reach the socket (41.041288ms)
✔ a missing argument is a usage error (35.408963ms)
✔ pi: typed tools reach the socket, the gate blocks, agent_end writes the marker (451.856779ms)
✔ pi: a write through a dangling symlink is blocked, and nothing appears outside (424.083966ms)
✔ pi: a read is refused when pi would open another spelling outside (391.039296ms)
✔ pi: a missing extension refuses before any model call (8.084161ms)
✔ pi: an extension without its configuration fails pi's start (309.06089ms)
✔ founderCheck: founder variables, then a needed service without a usable token (1.760127ms)
✔ turnRequest names the sender, class, reply and decision (0.295283ms)
✔ a message becomes a turn, the answer goes back as a RESULT, SIGTERM releases and exits 0 (289.066856ms)
✔ a SIGTERM before the claim stops the runner with exit 0 and no claim (145.925972ms)
✔ typed tools carry the runner's capability; launch goes to the host's launch socket (572.943605ms)
✔ a RESULT gets no automatic reply; failed turns reply with the reason (1382.676577ms)
✔ SIGTERM during a turn kills the turn's process group and still exits 0 (195.488321ms)
✔ founder credentials stop before the claim (20) (266.220648ms)
✔ a refused claim exits 21; an ended run's capability exits 22 (300.197563ms)
✔ the launch ending under a running session exits 22 (189.321104ms)
✔ a broker that stays unreachable exits 23 after brokerRetries polls (294.356597ms)
✔ a broker that is down at the claim exits 23, not 21 (126.069492ms)
✔ no capability, or a malformed one, on stdin exits 2 (225.894325ms)
✔ a missing or malformed policy exits 2 before the claim (172.34215ms)
✔ the PM gets launch, its task verbs and the reads (9.918179ms)
✔ a coder gets no launch, no resolve_decision, and no task tools without a tracker (3.000201ms)
✔ launch only when the business's launch block names the instance as launcher (2.299358ms)
✔ an action outside the instance's authority has no tool (2.45242ms)
✔ callTool: one JSON line out, the result back, a refusal rejects (12.67808ms)
ℹ tests 53
ℹ suites 0
ℹ pass 51
ℹ fail 2
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 10736.672106

✖ failing tests:

test at packages/harness/tests/claude-session.test.mjs:143:1
✖ claude adapter: --restricted is always passed (5.834159ms)
  AssertionError [ERR_ASSERTION]: -p x --output-format text --system-prompt {} --model claude-sonnet-5-5 --tools  --allowedTools mcp__mosaic --permission-mode dontAsk --settings /home/jwoltje/darkwing-scratch/tmp/mosaic-harness-W55fmH/settings.json --strict-mcp-config --mcp-config /home/jwoltje/darkwing-scratch/tmp/mosaic-harness-W55fmH/mcp.json --disable-slash-commands --session-id 884e6813-b3f5-4c85-9d05-e7f40f63932e 
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41c/wt/packages/harness/tests/claude-session.test.mjs:166:10)
      at Test.runInAsyncScope (node:async_hooks:226:14)
      at Test.run (node:internal/test_runner/test:1402:25)
      at Test.processPendingSubtests (node:internal/test_runner/test:974:18)
      at Test.postRun (node:internal/test_runner/test:1542:19)
      at Test.run (node:internal/test_runner/test:1467:12)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: false,
    expected: true,
    operator: '==',
    diff: 'simple'
  }

test at packages/harness/tests/claude-session.test.mjs:170:1
✖ claude: CLAUDE.md files and auto-memory don't reach the model; without --restricted they do (419.9886ms)
  AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal:
  + actual - expected
  
  + [
  +   'MARKER-USER',
  +   'MARKER-PARENT',
  +   'MARKER-WS',
  +   'MARKER-MEMORY'
  + ]
  - []
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41c/wt/packages/harness/tests/claude-session.test.mjs:193:10)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: [ 'MARKER-USER', 'MARKER-PARENT', 'MARKER-WS', 'MARKER-MEMORY' ],
    expected: [],
    operator: 'deepStrictEqual',
    diff: 'simple'
  }
