✔ sessionModel: agent vars win, then the system's execution settings (12.960219ms)
✔ a pi bundle: prompt, policy, tools and manifest, 0600 in a 0700 directory (5.112444ms)
✔ a claude-code bundle adds the wrapped gate hook and the MCP config (3.679235ms)
✔ a bundle is written once: an existing file refuses (2.812263ms)
✔ a path with a single quote can't go into the hook command (2.517504ms)
✔ allow exits 0, a deny exits 2 with the reason on stderr (136.603784ms)
✔ a missing or wrong policy, or a bad event, exits 2 (82.034771ms)
✔ the bundle's wrapped command: a missing gate or node still blocks (1094.979161ms)
✔ claude: typed tools through MCP, the hook blocks, builtins outside --tools don't exist (777.212211ms)
✔ claude: the hook alone blocks a path outside the workspace (472.515691ms)
✔ claude: a second turn resumes the first turn's session (762.499074ms)
✔ claude adapter: --restricted is always passed (4.735663ms)
✔ claude: CLAUDE.md files and auto-memory don't reach the model; without --restricted they do (746.837511ms)
✔ claude: a missing hook or MCP file refuses before claude starts (7.681726ms)
✔ pi: policy tools and typed tools pass, anything else is blocked (3.542476ms)
✔ claude: builtins map from pi names, typed tools need the mcp prefix (0.71412ms)
✔ file tool paths must resolve inside the workspace (1.156309ms)
✔ pi's own path normalisation can't be used to step out (1.080151ms)
✔ a symlink inside the workspace that points out is outside (1.165845ms)
✔ a dangling symlink is refused at any depth, in both harnesses (4.072642ms)
✔ read is checked under every spelling pi's read would open, in both harnesses (20.693322ms)
✔ other spellings cover directories, dangling links and pi's cwd (2.800193ms)
✖ a relative path climbs from the workspace's real path, in both harnesses (3.279667ms)
✔ claude path fields per tool (2.601182ms)
✔ glob patterns stay inside the workspace (1.257995ms)
✔ a path that can't be checked is blocked (0.55942ms)
✔ initialize, ping and tools/list (52.537718ms)
✔ tools/call goes through the tool socket; a refusal is an isError result (40.673685ms)
✔ unknown tools and methods are JSON-RPC errors and never reach the socket (35.993545ms)
✔ a missing argument is a usage error (29.947767ms)
✔ pi: typed tools reach the socket, the gate blocks, agent_end writes the marker (384.717068ms)
✔ pi: a write through a dangling symlink is blocked, and nothing appears outside (329.198526ms)
✔ pi: a read is refused when pi would open another spelling outside (337.808371ms)
✖ pi: a relative path climbs from the real path of a workspace behind a symlink (340.250878ms)
✖ pi: a relative path climbs from the real path of a dataRoot behind a symlink (318.836655ms)
✔ pi: a missing extension refuses before any model call (6.434745ms)
✔ pi: an extension without its configuration fails pi's start (272.153021ms)
✔ founderCheck: founder variables, then a needed service without a usable token (1.55466ms)
✔ turnRequest names the sender, class, reply and decision (0.996447ms)
✔ a message becomes a turn, the answer goes back as a RESULT, SIGTERM releases and exits 0 (246.016744ms)
✔ a SIGTERM before the claim stops the runner with exit 0 and no claim (101.349298ms)
✔ typed tools carry the runner's capability; launch goes to the host's launch socket (398.221516ms)
✔ a RESULT gets no automatic reply; failed turns reply with the reason (1294.309301ms)
✔ SIGTERM during a turn kills the turn's process group and still exits 0 (145.992858ms)
✔ founder credentials stop before the claim (20) (173.49626ms)
✔ a refused claim exits 21; an ended run's capability exits 22 (185.73365ms)
✔ the launch ending under a running session exits 22 (141.709901ms)
✔ a broker that stays unreachable exits 23 after brokerRetries polls (243.783028ms)
✔ a broker that is down at the claim exits 23, not 21 (105.666355ms)
✔ no capability, or a malformed one, on stdin exits 2 (184.835076ms)
✔ a missing or malformed policy exits 2 before the claim (137.674261ms)
✔ the PM gets launch, its task verbs and the reads (9.441748ms)
✔ a coder gets no launch, no resolve_decision, and no task tools without a tracker (2.792932ms)
✔ launch only when the business's launch block names the instance as launcher (2.844521ms)
✔ an action outside the instance's authority has no tool (2.336641ms)
✔ callTool: one JSON line out, the result back, a refusal rejects (14.398564ms)
ℹ tests 56
ℹ suites 0
ℹ pass 53
ℹ fail 3
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 10316.014664

✖ failing tests:

test at packages/harness/tests/gate.test.mjs:181:1
✖ a relative path climbs from the workspace's real path, in both harnesses (3.279667ms)
  AssertionError [ERR_ASSERTION]: Expected values to be strictly equal:
  
  true !== false
  
      at blocked (file:///home/jwoltje/darkwing-scratch/r41d/wt/packages/harness/tests/gate.test.mjs:19:10)
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41d/wt/packages/harness/tests/gate.test.mjs:195:7)
      at Test.runInAsyncScope (node:async_hooks:226:14)
      at Test.run (node:internal/test_runner/test:1402:25)
      at Test.processPendingSubtests (node:internal/test_runner/test:974:18)
      at Test.postRun (node:internal/test_runner/test:1542:19)
      at Test.run (node:internal/test_runner/test:1467:12)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: true,
    expected: false,
    operator: 'strictEqual',
    diff: 'simple'
  }

test at packages/harness/tests/pi-session.test.mjs:184:3
✖ pi: a relative path climbs from the real path of a workspace behind a symlink (340.250878ms)
  AssertionError [ERR_ASSERTION]: The input was expected to not match the regular expression /SECRET/. Input:
  
  'ANSWER [[false,"SECRET-OUTSIDE\\n"],[false,"Successfully wrote to ../../a/ws/planted.txt"],[false,"inside\\n"],[false,"Successfully wrote to ../ws/fine.md"]]\n'
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41d/wt/packages/harness/tests/pi-session.test.mjs:199:12)
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: 'ANSWER [[false,"SECRET-OUTSIDE\\n"],[false,"Successfully wrote to ../../a/ws/planted.txt"],[false,"inside\\n"],[false,"Successfully wrote to ../ws/fine.md"]]\n',
    expected: /SECRET/,
    operator: 'doesNotMatch',
    diff: 'simple'
  }

test at packages/harness/tests/pi-session.test.mjs:184:3
✖ pi: a relative path climbs from the real path of a dataRoot behind a symlink (318.836655ms)
  AssertionError [ERR_ASSERTION]: The input was expected to not match the regular expression /SECRET/. Input:
  
  'ANSWER [[false,"SECRET-OUTSIDE\\n"],[false,"Successfully wrote to ../../../../data/workspaces/b/i/planted.txt"],[false,"inside\\n"],[false,"Successfully wrote to ../i/fine.md"]]\n'
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41d/wt/packages/harness/tests/pi-session.test.mjs:199:12)
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: 'ANSWER [[false,"SECRET-OUTSIDE\\n"],[false,"Successfully wrote to ../../../../data/workspaces/b/i/planted.txt"],[false,"inside\\n"],[false,"Successfully wrote to ../i/fine.md"]]\n',
    expected: /SECRET/,
    operator: 'doesNotMatch',
    diff: 'simple'
  }
