✔ launch identity is stamped, payload identity is refused and stale holder cannot send (157.589774ms)
✔ decision classes route from policy; gated resolution is human-only, choice and target must match (214.882734ms)
✔ claim exclusion, holder release, gated revoke and rerouting to a new holder are atomic (234.370396ms)
✔ launch events require a human CLI capability; generic emit cannot forge authority events (154.43658ms)
✔ within-role decisions close atomically and invalid options or blocking omissions refuse (147.744863ms)
✔ observer capabilities read human inbox but cannot mutate or forge launch identity (128.923406ms)
✔ task action subjects and linked decision trail are complete and ordered (135.580688ms)
✔ launch binding is durable and reconnecting requires the identical trusted record (70.784072ms)
✔ business isolation includes inherited object names and cross-business message references (128.216659ms)
✔ authority never transfers between action, run, target, unresolved or replaced role holder (214.293626ms)
✔ task projection uses schema current view, skipping earlier and equal-start polls (104.369741ms)
✔ revocation permanently bars the old run from reclaiming first, including after broker restart (202.700031ms)
✔ empty message references refuse before storage; refusal-evidence failure stays a typed error (113.034346ms)
✔ both arbiters require human resolution when their cross-role route is themselves (186.11149ms)
✔ S1 adapter takes resolved limits and refs, rejects mismatched instance, never mutates input (4.901157ms)
✔ only validated broker references load; returned data and exceptions cannot expose a known token (7.674124ms)
✔ bad file modes, symlinks, repository/data paths, malformed tokens and missing dates refuse (13.179581ms)
✔ expiry refuses use and env references never become client data (1.129997ms)
✔ S1 parsed service refs work, service mismatch refuses, Gitea rotation due is a warning state (2.104835ms)
✔ opaque tokens shorter than 16 characters refuse before use (0.516553ms)
✔ human proof binds CLI entry, process start and nonce; agents and incomplete ancestry refuse (3.290937ms)
✔ process reader gets own kernel identity without exposing environment values (2.69631ms)
✔ EACCES ancestor environments skip only markers; commands and registered launches still refuse (1.407953ms)
✔ real pid 1 remains inspectable when its environment is protected (0.446615ms)
✔ within-role sends cite an open gated launch decision without spending it or naming it in grants (179.466727ms)
✔ missing and foreign-business citations refuse and roll back message and grant (157.029434ms)
✔ cross-role sends still need a matching resolved decision and consume it once (216.213587ms)
✔ broker process binds trusted launches, offers reader capabilities, refuses human mutation, closes cleanly (191.273445ms)
✔ startup token refusal returns safe code without value or partial listening broker (44.184184ms)
✔ loaded fixture token is absent from socket replies and SQLite, including refusal evidence (163.394401ms)
✔ killed broker leaves an explicit stale lock; another process cannot silently reclaim it (172.087705ms)
✔ trusted host registers later launches; socket clients never have a registration verb (162.33158ms)
✔ runtime excludes declared project roots even when host supplies no repoRoots (43.79939ms)
✔ a refused launch binding leaves the broker and existing capabilities alive; bad protocol stops it (151.635091ms)
✔ v3b prototype refusals, views and append-only mutations (921.886122ms)
✔ gated approval authorizes once, survives store reopen, and fresh approval works (235.197428ms)
✔ another run cannot consume an approval; a failed check leaves it usable (188.114042ms)
✔ two scheduled callers have exactly one grant and one consumed refusal (145.100506ms)
✔ failed commit rolls consumption back; cross-role consumes and within-role stays reusable (262.999514ms)
✔ class drift gated to cross-role refuses before consumption (174.183825ms)
✔ class drift cross-role to gated refuses before consumption (161.959479ms)
✔ class drift gated to within-role refuses before consumption (140.823855ms)
✔ class drift cross-role to within-role refuses before consumption (165.128575ms)
✔ class drift within-role to gated refuses before consumption (149.257083ms)
✔ class drift within-role to cross-role refuses before consumption (164.919308ms)
✔ message.send consumes approval and prevents a later send or authorize (195.343532ms)
✔ role.revoke consumes approval and prevents a later revoke or authorize (207.352231ms)
✔ creates private WAL store and excludes a second writer until explicit close (115.38464ms)
✔ rollback is atomic and schema metadata is checked against trusted DDL, not just itself (145.673579ms)
✔ existing empty database and symlink runtime directory refuse, never initialize over damage (161.739595ms)
✔ crash during a transaction recovers no partial event after explicit fixture-only lock removal (158.645686ms)
✔ writer refuses mixed at/read_at forms atomically, even through trusted SQL helpers (88.416456ms)
✔ async transactions refuse before invoking their function (81.367723ms)
✔ socket capability stamps launch identity; shared views use wire, no SQL client (135.569067ms)
✔ two wire claims serialize; a lost reply never automatically retries (149.058021ms)
✔ malformed, oversized and identity-forging envelopes refuse without echoing input (101.144057ms)
✔ client preserves UTF-8 when a response divides a multibyte character (13.072058ms)
✔ committed mutation followed by dropped reply reports unknown and is never retried (120.466141ms)
ℹ tests 58
ℹ suites 0
ℹ pass 58
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 2334.386318
