v26.8.1
✔ launch identity is stamped, payload identity is refused and stale holder cannot send (309.288448ms)
✔ decision classes route from policy; gated resolution is human-only, choice and target must match (389.505343ms)
✔ claim exclusion, holder release, gated revoke and rerouting to a new holder are atomic (388.378687ms)
✔ launch events require a human CLI capability; generic emit cannot forge authority events (282.319597ms)
✔ within-role decisions close atomically and invalid options or blocking omissions refuse (342.637861ms)
✔ observer capabilities read human inbox but cannot mutate or forge launch identity (286.281563ms)
✔ task action subjects and linked decision trail are complete and ordered (234.634195ms)
✔ launch binding is durable and reconnecting requires the identical trusted record (139.318368ms)
✔ business isolation includes inherited object names and cross-business message references (233.819604ms)
✔ authority never transfers between action, run, target, unresolved or replaced role holder (392.107224ms)
✔ task projection uses schema current view, skipping earlier and equal-start polls (181.476509ms)
✔ revocation permanently bars the old run from reclaiming first, including after broker restart (248.26384ms)
✔ empty message references refuse before storage; refusal-evidence failure stays a typed error (175.355958ms)
✔ both arbiters require human resolution when their cross-role route is themselves (213.325796ms)
✔ S1 adapter takes resolved limits and refs, rejects mismatched instance, never mutates input (1.797616ms)
✔ only validated broker references load; returned data and exceptions cannot expose a known token (5.495212ms)
✔ bad file modes, symlinks, repository/data paths, malformed tokens and missing dates refuse (8.858866ms)
✔ expiry refuses use and env references never become client data (1.204726ms)
✔ S1 parsed service refs work, service mismatch refuses, Gitea rotation due is a warning state (1.723925ms)
✔ opaque tokens shorter than 16 characters refuse before use (0.334733ms)
✔ human proof binds CLI entry, process start and nonce; agents and incomplete ancestry refuse (2.786979ms)
✔ process reader gets own kernel identity without exposing environment values (1.719189ms)
✔ EACCES ancestor environments skip only markers; commands and registered launches still refuse (1.104467ms)
✔ real pid 1 remains inspectable when its environment is protected (0.472363ms)
✔ within-role sends cite an open gated launch decision without spending it or naming it in grants (358.694493ms)
✔ missing and foreign-business citations refuse and roll back message and grant (280.488708ms)
✔ cross-role sends still need a matching resolved decision and consume it once (378.131086ms)
✔ broker process binds trusted launches, offers reader capabilities, refuses human mutation, closes cleanly (306.608846ms)
✔ startup token refusal returns safe code without value or partial listening broker (38.704728ms)
✔ loaded fixture token is absent from socket replies and SQLite, including refusal evidence (253.957547ms)
✔ killed broker leaves an explicit stale lock; another process cannot silently reclaim it (266.396841ms)
✔ trusted host registers later launches; socket clients never have a registration verb (279.147369ms)
✔ runtime excludes declared project roots even when host supplies no repoRoots (42.325635ms)
✔ a refused launch binding leaves the broker and existing capabilities alive; bad protocol stops it (368.437951ms)
✔ v3b prototype refusals, views and append-only mutations (1715.387995ms)
✔ gated approval authorizes once, survives store reopen, and fresh approval works (418.109218ms)
✔ another run cannot consume an approval; a failed check leaves it usable (353.859553ms)
✔ two scheduled callers have exactly one grant and one consumed refusal (241.394104ms)
✔ failed commit rolls consumption back; cross-role consumes and within-role stays reusable (607.068845ms)
✔ class drift gated to cross-role refuses before consumption (316.906561ms)
✔ class drift cross-role to gated refuses before consumption (328.648705ms)
✔ class drift gated to within-role refuses before consumption (279.136459ms)
✔ class drift cross-role to within-role refuses before consumption (279.892283ms)
✔ class drift within-role to gated refuses before consumption (278.753046ms)
✔ class drift within-role to cross-role refuses before consumption (231.006303ms)
✔ message.send consumes approval and prevents a later send or authorize (240.480023ms)
✔ role.revoke consumes approval and prevents a later revoke or authorize (237.166599ms)
✔ creates private WAL store and excludes a second writer until explicit close (231.440902ms)
✔ rollback is atomic and schema metadata is checked against trusted DDL, not just itself (257.362193ms)
✔ existing empty database and symlink runtime directory refuse, never initialize over damage (295.830776ms)
✔ crash during a transaction recovers no partial event after explicit fixture-only lock removal (247.185327ms)
✔ writer refuses mixed at/read_at forms atomically, even through trusted SQL helpers (136.784102ms)
✔ async transactions refuse before invoking their function (172.440818ms)
✔ socket capability stamps launch identity; shared views use wire, no SQL client (287.255309ms)
✔ two wire claims serialize; a lost reply never automatically retries (263.102933ms)
✔ malformed, oversized and identity-forging envelopes refuse without echoing input (166.897513ms)
✔ client preserves UTF-8 when a response divides a multibyte character (11.875821ms)
✔ committed mutation followed by dropped reply reports unknown and is never retried (218.929616ms)
ℹ tests 58
ℹ suites 0
ℹ pass 58
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 3912.090626
