v24.21.0
✔ launch identity is stamped, payload identity is refused and stale holder cannot send (168.817976ms)
✔ decision classes route from policy; gated resolution is human-only, choice and target must match (313.208626ms)
✔ claim exclusion, holder release, gated revoke and rerouting to a new holder are atomic (302.696792ms)
✔ launch events require a human CLI capability; generic emit cannot forge authority events (174.078331ms)
✔ within-role decisions close atomically and invalid options or blocking omissions refuse (166.043648ms)
✔ observer capabilities read human inbox but cannot mutate or forge launch identity (126.024638ms)
✔ task action subjects and linked decision trail are complete and ordered (170.274208ms)
✔ launch binding is durable and reconnecting requires the identical trusted record (81.476104ms)
✔ business isolation includes inherited object names and cross-business message references (150.077621ms)
✔ authority never transfers between action, run, target, unresolved or replaced role holder (229.844251ms)
✔ task projection uses schema current view, skipping earlier and equal-start polls (105.93614ms)
✔ revocation permanently bars the old run from reclaiming first, including after broker restart (176.471326ms)
✔ empty message references refuse before storage; refusal-evidence failure stays a typed error (113.396458ms)
✔ both arbiters require human resolution when their cross-role route is themselves (190.95561ms)
✔ S1 adapter takes resolved limits and refs, rejects mismatched instance, never mutates input (1.69599ms)
✔ only validated broker references load; returned data and exceptions cannot expose a known token (5.619075ms)
✔ bad file modes, symlinks, repository/data paths, malformed tokens and missing dates refuse (2.666542ms)
✔ expiry refuses use and env references never become client data (0.706395ms)
✔ S1 parsed service refs work, service mismatch refuses, Gitea rotation due is a warning state (1.409483ms)
✔ opaque tokens shorter than 16 characters refuse before use (0.311777ms)
✔ human proof binds CLI entry, process start and nonce; agents and incomplete ancestry refuse (2.168625ms)
✔ process reader gets own kernel identity without exposing environment values (0.491319ms)
✔ EACCES ancestor environments skip only markers; commands and registered launches still refuse (1.663546ms)
✔ real pid 1 remains inspectable when its environment is protected (0.307122ms)
✔ broker process binds trusted launches, offers reader capabilities, refuses human mutation, closes cleanly (182.635495ms)
✔ startup token refusal returns safe code without value or partial listening broker (32.982398ms)
✔ loaded fixture token is absent from socket replies and SQLite, including refusal evidence (233.71422ms)
✔ killed broker leaves an explicit stale lock; another process cannot silently reclaim it (212.036986ms)
✔ trusted host registers later launches; socket clients never have a registration verb (173.561943ms)
✔ runtime excludes declared project roots even when host supplies no repoRoots (33.573525ms)
✔ a refused launch binding leaves the broker and existing capabilities alive; bad protocol stops it (142.219081ms)
✔ v3b prototype refusals, views and append-only mutations (1127.795659ms)
✔ gated approval authorizes once, survives store reopen, and fresh approval works (240.5127ms)
✔ another run cannot consume an approval; a failed check leaves it usable (299.636661ms)
✔ two scheduled callers have exactly one grant and one consumed refusal (188.519503ms)
✔ failed commit rolls consumption back; cross-role consumes and within-role stays reusable (304.19416ms)
✔ class drift gated to cross-role refuses before consumption (195.89971ms)
✔ class drift cross-role to gated refuses before consumption (164.954025ms)
✔ class drift gated to within-role refuses before consumption (157.003222ms)
✔ class drift cross-role to within-role refuses before consumption (194.824232ms)
✔ class drift within-role to gated refuses before consumption (162.080633ms)
✔ class drift within-role to cross-role refuses before consumption (169.207993ms)
✔ message.send consumes approval and prevents a later send or authorize (172.590743ms)
✔ role.revoke consumes approval and prevents a later revoke or authorize (216.382204ms)
✔ creates private WAL store and excludes a second writer until explicit close (122.973435ms)
✔ rollback is atomic and schema metadata is checked against trusted DDL, not just itself (197.930322ms)
✔ existing empty database and symlink runtime directory refuse, never initialize over damage (288.655009ms)
✔ crash during a transaction recovers no partial event after explicit fixture-only lock removal (161.180697ms)
✔ writer refuses mixed at/read_at forms atomically, even through trusted SQL helpers (110.373629ms)
✔ async transactions refuse before invoking their function (83.296435ms)
✔ socket capability stamps launch identity; shared views use wire, no SQL client (152.484588ms)
✔ two wire claims serialize; a lost reply never automatically retries (186.003021ms)
✔ malformed, oversized and identity-forging envelopes refuse without echoing input (180.813868ms)
✔ client preserves UTF-8 when a response divides a multibyte character (13.90465ms)
✔ committed mutation followed by dropped reply reports unknown and is never retried (155.521905ms)
ℹ tests 55
ℹ suites 0
ℹ pass 55
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 2532.657625
