✔ config directory and file path follow MOSAIC_CONFIG (1.46993ms)
✔ the fixture business validates and comes back frozen (3.65864ms)
✔ two instances may share a definition (1.05404ms)
✔ top-level refusals (3.346619ms)
✔ arbiters and projects (5.222003ms)
✔ role instances (2.840985ms)
✔ Vikunja bots (5.529147ms)
✔ a role without Vikunja takes no tracker block (1.73776ms)
✔ credential references match the definition's services (2.08883ms)
✔ launch (6.709177ms)
✔ loadBusiness: file checks (1.526452ms)
✔ loadBusiness: not a regular file (37.652055ms)
✔ loading writes nothing (1.309657ms)
✔ names that are Object.prototype properties don't count as declared (2.476127ms)
✔ the shipped example refuses as written and validates once filled in (0.52605ms)
✔ usage errors exit 4 (283.72903ms)
✔ validate: a good business exits 0 and prints instance digests (67.029589ms)
✔ validate: project files (305.887244ms)
✔ validate: missing files and a broken system config (248.794647ms)
✔ validate: credential reference problems exit 2 and name each one (62.924086ms)
✔ validate: a token file inside the repository is refused (65.917526ms)
✔ validate: role definitions come from MOSAIC_ROLES_DIR (186.048198ms)
✔ resolve: prints one instance's record (193.663903ms)
✔ resolve: refusals (386.422626ms)
✔ parse: exactly one of file or env, plus the service's date (1.918165ms)
✔ check: a good file has no problems (0.606329ms)
✔ check never opens the file: a write-only token passes (0.253188ms)
✔ check: file problems (0.698464ms)
✔ check: token files can't live in the repository or dataRoot, even through a linked directory (0.647238ms)
✔ check: dates and environment references (0.304771ms)
✔ path and load (1.699579ms)
✔ refusals (0.864022ms)
✔ systemVars flattens the validated config (1.491298ms)
✔ precedence: system, business, project, project role, agent (3.709113ms)
✔ limits narrow the definition and never widen it (1.852486ms)
✔ role.launch stays within-role only for the instance the launch block names (3.761048ms)
✔ limits.authority without role.launch leaves the launcher with no launch block (1.43637ms)
✔ limits.authority narrows cross-role actions too (0.814065ms)
✔ classify (0.916153ms)
✔ the record carries what the broker and launcher need (0.797372ms)
✔ digest: key order doesn't matter, any value change does (4.852509ms)
✔ refusals (1.887646ms)
✔ the four shipped version 2 roles load (2.349244ms)
✔ shipped role scopes match addendum B section 2 and the SR runbook (0.971249ms)
✔ shipped authority follows the note's table (0.495674ms)
✔ version 1 files keep loading with no authority (0.755756ms)
✔ the conductor policy isn't a role (0.203739ms)
✔ a missing role file is exit 4, a symbolic link too (0.312205ms)
✔ version 2 refusals (0.981826ms)
✔ authority: closed vocabulary, no gated-only action, no overlap (2.054732ms)
✔ credentials: Gitea scopes (0.783621ms)
✔ credentials: Vikunja scopes are a group-to-verbs map from the grantable list (0.892118ms)
✔ credentials: services (0.458892ms)
✔ contract: a non-empty regular Markdown file beside the role file (0.624834ms)
✔ every key names known layers and a merge rule (0.76137ms)
✔ unknown keys and wrong layers refuse (0.780944ms)
✔ types (1.595196ms)
✔ merge: defaults, then the most specific layer wins (0.253108ms)
✔ merge: limits only narrow, and provenance lists each source (0.323743ms)
✔ merge doesn't change its inputs (0.108269ms)
ℹ tests 60
ℹ suites 0
ℹ pass 60
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 1859.606824
