✔ W1: two processes acquire the same pair at once; exactly one claim (207.636312ms)
✔ W1: two writers publish the same revision at once: one wins, the other gets null, the winner's record stays (31.671819ms)
✔ W1: a revision name appears only after its bytes are synced; before that, only a temp file exists (17.531549ms)
✔ W2: acquire while a claim is reserved or active refuses already-active (365.224435ms)
✔ W3: acquire while stopping, uncertain, or stopped without proof refuses unsafe-replacement (375.743275ms)
✔ W4: same session with another seat tuple, and the reverse, both refuse; a loser on the seat key closes it no-unit (238.900008ms)
✔ W4: a hard link of one session under another seat is the same session: the second controller refuses already-active and launches nothing (225.805156ms)
✔ W4: a copy of one session under another seat is the same session: the second controller refuses already-active and launches nothing (299.615632ms)
✔ W4: a session header ID that changes after construction refuses target; nothing is claimed or launched (2.531001ms)
✔ W5: SIGKILL between every publication barrier of acquire and transition; restart never finds two holders or a lost claim (13253.125745ms)
✔ W5: SIGKILL between every publication barrier of release; restart finishes or holds the release (39168.220723ms)
✔ W6: controller killed mid-turn while the engine lives; restart is uncertain, no launch, prompts refuse (265.09423ms)
✔ W12: a live owner paused with SIGSTOP; a second controller refuses already-active and changes nothing (139.935762ms)
✔ W13: crash after the engine spawns, before active; restart finds the live unit: uncertain, no second spawn, force stop only (610.02107ms)
✔ W14: crash after reservation, before the spawn marker: stopped with a no-unit observation; the pair is free (282.459774ms)
✔ W20: crash after the spawn marker, scope collected; uncertain in both runs, the marker is copied, no launch until a boot proof (329.709422ms)
✔ W15: crash between the two keys during release; restart finishes it under the same claim ID (215.645266ms)
✔ W7: recorded boot ID differs on the same machine: stopped with a boot proof; open tool calls become uncertain (283.574969ms)
✔ W8: resume after a proven stop with the same pins: new claim ID, generation +1, same conversation, branch and leaf (499.324428ms)
✔ W9: resume with a changed binary, argv digest, branch or leaf is refused and the claim is unchanged (949.098027ms)
✔ W11: the controller writes no session file; only the fake engine's own appends appear (199.013326ms)
✔ W16: a highest revision that won't parse holds the pair uncertain; the older stopped revision is not reused (91.935987ms)
✔ W17: a claim root copied from another host refuses foreign-host and promotes nothing (85.208259ms)
✔ G1: a session path or claim root under .pi/state, ~/.claude, the data root or a registration refuses at construction (4.098139ms)
✔ G2: a symlink inside the fixture root to a live session file is refused by the real-path check (1.436034ms)
✔ G3: a fixture path swapped for a live path after construction is refused at bind (1.844956ms)
✔ no shim from this file's tests is left running for the after hook (24.673716ms)
✔ K1: force stop kills a tool child that called setsid; stopped with a verified proof (976.65867ms)
✔ K2: K1 on the process-group fallback ends uncertain, never stopped (475.498215ms)
✔ K3: SIGTERM acknowledged while a member lives: stopping until the kill phase, never stopped from TERM (942.748798ms)
✔ K4: two engines; force stop one; the other survives by independent observation (3043.619425ms)
✔ K5: a stop during a tool call leaves the effect uncertain, and it is shown (1136.345293ms)
✔ K12: a member forking in a loop: the freeze stops it, enumeration is complete, populated 0 after cgroup.kill (888.096775ms)
✔ K13: a member writing its pid into another cgroup is refused by the namespace; the kill is complete (768.265805ms)
✔ K15: the shim gone, engine/cgroup.events unreadable, or the engine cgroup missing: evidence unavailable, not empty; uncertain (5881.341427ms)
✔ K10: controller killed between the TERM and kill phases: restart checks the invocation ID and re-runs from TERM for the same stop (1038.181376ms)
✔ K11: controller killed after the confirmation is recorded, before TERM: restart checks the invocation ID and re-runs from TERM for the same stop (778.528574ms)
✔ K14: a unit with the recorded name but another invocation ID: evidence unavailable, no signals, uncertain (454.270423ms)
✔ K6: recover without proof, without confirmation, or with changed pins is refused (731.569118ms)
✔ K7: recover after proof, then launch: new claim and execution, generation +1, same leaf; the cancelled prompt is not replayed (487.686365ms)
✔ K8: an engine that loads another leaf on resume is refused before admission; it stays claimed until a proven stop (880.595621ms)
✔ K9: an interrupt that never settles stays uncertain; force stop stays available; takeover is refused while fenced (3957.867674ms)
✔ K16: a claim from another machine ID refuses foreign-host; no boot proof is issued (60.917654ms)
✔ K17: two launcher calls with one eligibility record: one launch, the other refuses, no second engine (595.755511ms)
✔ K18: the leaf changes after eligibility: launch refused; the reservation stays until released with proof (476.456199ms)
✔ K19: a scope launched with only the engine environment still reaches the user manager; the engine sees no other names (83.135937ms)
✖ R1: after a proven force stop the controller releases the scope; the shim and the unit are gone (8643.176352ms)
✖ R2: close releases the scope of a binding proven stopped, once, when the stop's own release hasn't run (576.569113ms)
✔ R3: no release after an unavailable stop or an unverified proof: the scope and its shim stay as evidence (1317.296796ms)
✖ R4: after a normal engine exit the scope stays until a proven force stop releases it (8688.575873ms)
✔ R5: the harness finds a running shim and reaps it, and never signals a shim outside a mosaic-chat- scope (Filbert N1 and N2 on #1533) (596.211364ms)
✔ R6: releaseCohort releases nothing for another invocation ID or a cohort without a scope (122.08846ms)
✔ no shim from this file's tests is left running for the after hook (25.976516ms)
✔ S1: `/goal x`, with leading spaces or a tab, refuses text-policy at admission; zero engine bytes (202.474345ms)
✔ S2: every prefix pinned Pi interprets is refused, from the list the code uses; the rest reach the engine exactly (216.296105ms)
✔ S3: `/goal` on the second line is pinned from the source: Pi checks only index 0, so it is admitted and sent exactly (198.638065ms)
✔ S4: a `/` left in the composer is cleared when control transfers and returns; the next submit sends only the new text (278.82666ms)
✔ S5: an observer terminal gets a paste then Enter, as send-message.sh does: not admitted: controller, nothing sent (194.620148ms)
✔ S6: a mediated-shaped registration (no tmux) passed to the board's replyToRow: 409 no tmux session; exec never runs (0.437381ms)
✔ S7: ESC, bracketed-paste markers and U+2028/U+2029 travel as one JSON string; the engine receives the exact text in one record (200.939948ms)
✔ P3: a Pi confirm, select, input or editor dialog is shown disabled with a reason and never answered (341.197899ms)
✔ E1: send, ack, user, toolCall, toolResult, final answer: shown once, no refresh, draft and reading position kept (337.851502ms)
✔ E2: U+2028, U+2029 inside JSON strings and CRLF line ends each parse as one record, on the splitter and through the controller (295.460905ms)
✔ E3: a multipart final, two blocks, null request correlation and duplicate delivery (239.146079ms)
✔ E4: a page read after message_end but before its entry is persisted: marker at the seam, re-read after run-settled, each message once (227.685473ms)
✔ E4: a gap or a new epoch also reconciles; nothing is concatenated across a gap (10.981311ms)
✔ E5: an unknown native event gives no client event; evidence records its type and bytes; the terminal count goes up (214.520823ms)
✔ E6: a tool result delayed across a pause and a reconnect is reconciled without a manual refresh (221.356733ms)
✔ E7: the terminal renders the same stream as the library client, as observer and then as controller, and submits only as controller (274.526795ms)
✔ terminal: engine control characters are made visible; a lost connection refuses submit (217.87438ms)
✔ terminal: outcome unknown is shown as such, with no resend offer, and nothing is resent (0.583858ms)
✔ terminal: text after Enter in the same input chunk starts the next message; it never joins the one submitted (0.288987ms)
✔ terminal: a paste-start marker split right after its ESC still opens the paste; the Enter inside it never submits (0.331664ms)
✔ terminal: Ctrl-T then Enter in one chunk is judged after the takeover, as if typed one key at a time (Filbert F2, #1507) (0.50306ms)
✔ terminal: input held behind Ctrl-T waits for that takeover while an earlier action is still pending (Darkwing T1 on #1522) (30.957714ms)
✔ terminal: a hold inside held input holds again, and once it is drained later input and Ctrl-C still reach the terminal (Darkwing note 1 on #1522) (0.461908ms)
✔ terminal: an action that throws still releases the input held behind it, in order, then rethrows (5.689579ms)
✔ terminal: after an action throws, later input still runs; input() puts the error in the status line (Filbert N1 on #1522) (0.378544ms)
✔ terminal: input() reports an error when it happens, so it never overwrites a later status; held input's promise doesn't carry the holder's error (Filbert N4 on #1522) (0.335821ms)
✔ terminal: invisible and bidi characters are made visible; head, status and notice lines stay one line (0.093501ms)
✔ every record these fixtures produced is a valid CHAT-01 record (E5: no record fails the schema) (225.033292ms)
✔ H1: two takeovers with the same expected generation: one wins, +1; the other refuses generation (246.890313ms)
✔ H2: the old controller's prompt after a takeover commits is refused with zero engine bytes (312.851641ms)
✔ H3: a takeover while a prompt holds the dispatch lock: written under the old actor, or refused; never both (811.813782ms)
✔ H4: self-takeover is refused (297.074042ms)
✔ H9: Interrupt racing a prompt's dispatch: before the write, dispatch-refused and no-turn; after, §3 rules (617.007528ms)
✔ H10: Interrupt and force stop together: one stop chain, force stop supersedes (1112.052305ms)
✔ H10: an overlap during the pause before the abort: no abort, the stop ends uncertain (251.177186ms)
✔ H10: a no-turn Interrupt lifts only its own fence; admission stays closed under force stop, overlap or revocation (552.166906ms)
✔ H11: the controller disconnects mid-turn: work continues, the claim is unchanged, control stays put (270.296071ms)
✔ H12: an exact retry after reconnecting to the same incarnation returns the same receipt; one dispatch (174.004826ms)
✔ H13: a retry with the same request ID and different text is refused (239.627211ms)
✔ H14: late stdout from the old engine after a replacement is dropped by incarnation, counted, never rendered (893.349674ms)
✔ H15: a revoked connection's command is refused; the revocation fence holds (654.644864ms)
✔ H16: a second controller for the same session refuses already-active; the first is untouched (223.473935ms)
✔ H10: a second force stop while the first escalation runs refuses fenced; one escalation, and the claim records only the first stop's phases (972.900194ms)
✔ a force stop whose fence throws leaves no escalation flag behind, so the next force stop runs (Darkwing F2, #1507) (384.526377ms)
✔ H17: a confirmation reused, answered from another connection, or used after the stop changed is refused (830.365315ms)
✔ H18: two prompts before any native output: the second refuses busy; one engine write (235.744185ms)
✔ H19: the pipe fails mid-line under a large prompt: delivery-unknown transport-unknown, poisoned, no later write (364.981386ms)
✔ H19: the link itself never writes again after an unknown outcome, whoever calls it (0.648115ms)
✔ H19: the controller dies mid-write of a large line: after restart the outcome is unknown and nothing is resent (726.725677ms)
✔ H20: the line is written but the ack is lost when the controller dies: orphan, outcome unknown, nothing resent (609.885128ms)
✔ H21: a retry of the exact request with the old token after a crash is stale-incarnation; no second write (777.19598ms)
✔ H22: after H21 and a valid recovery, a new request with the new token is admitted (3161.318197ms)
✔ H23: requests pending at a restart are not resent; each shows outcome unknown (772.608145ms)
✔ no shim from this file's tests is left running for the after hook (26.243188ms)
✔ a plain conversation: catalogue row, one page, CHAT-01 records (5.924855ms)
✔ native entries map to blocks: tools, thinking, bash, notices, ids that do not fit (1.71635ms)
✔ F1: a malformed line is an unavailable part at its position, and reading continues (1.910233ms)
✔ F1: a missing parent stops the history with a notice that names the unreadable lines (2.719744ms)
✔ F1: an unreadable fork is never merged into another branch's history (1.375009ms)
✔ F1: a follow stays on its branch when the next entry's parent is unreadable (1.976274ms)
✔ F1: a file whose entries are all unreadable shows a notice per line (0.811346ms)
✔ F2: a truncated trailing line marks the view incomplete, not an error (1.381024ms)
✔ pagination: 100 parts, then the rest; parts concatenate to the whole branch (3.412276ms)
✔ F3: a replaced file (new inode) refuses old cursors with reconcile (5.38275ms)
✔ F4: a same-inode rewrite of the prefix refuses old cursors with reconcile (4.192834ms)
✔ F5: growth between pages keeps the epoch and the page stops at the pinned length (4.362975ms)
✔ F6: unknown, foreign and expired cursors refuse and leave the cursor usable (6.411819ms)
✔ F7: a symlinked file and a symlinked directory component are refused, never opened (7.614048ms)
✔ F8: a file swapped for a symlink after the catalogue is refused (1.774105ms)
✔ F9: registrations never add or redirect a root (1.893373ms)
✔ F10: a header cwd naming another project is refused (5.077911ms)
✔ F11: parentSession renders with a marker and the parent is never opened (0.860447ms)
✔ F12: two leaves: the default leaf is shown and the other branch reads alone (4.159008ms)
✔ F12: a follow refuses when an appended duplicate id changes the branch's earlier parts (1.934562ms)
✔ F12: a second root (Pi's resetLeaf) starts its own branch (1.296195ms)
✔ F13: compaction is a marker in place, then the retained content (0.713412ms)
✔ F14: long strings split into fragments and parts, reassemble exactly, and pages respect the byte cap (514.555301ms)
✔ fragments never cut a surrogate pair and keep an empty string (4.961625ms)
✔ F15: a Claude seat is an unsupported-harness placeholder whose directory is never read (1.499461ms)
✔ unknown conversations, empty files and non-Pi files refuse (2.509135ms)
✔ an unreadable file or root inside the roots is refused per row, not a failed catalogue (1.110792ms)
✔ a seat directory without search permission refuses that root, not the catalogue (2.049583ms)
✔ every page and cursor is a valid CHAT-01 record (771.592435ms)
✔ the engine pin holds for the installed package (1.839777ms)
✔ pinned Pi, sealed and without credentials, answers the controller's commands with the shapes the fake models (258.023466ms)
✔ sealed, pinned Pi ignores a trusted project's .pi resources; --approve past the seal would load them, and checkSeal refuses it (Filbert F2 on #1522) (534.072833ms)
✔ pinned Pi appends thinking_level_change at start when the branch lacks one, so the leaf moves (K8 then fails closed) (237.137804ms)
✔ N25: ordinary Interrupt reconciles; a non-empty queue_update in the window is O5 (499.752552ms)
✔ N1: an extension's follow-up queued after the fence is cleared before any abort; O5, Unknown (433.973546ms)
✔ N1: a follow-up queued before the fence is O5 at once; the Interrupt refuses fenced (227.498429ms)
✔ N2: with abort first, the fake runs the external item (the ordering guard has teeth) (21.085678ms)
✔ N3: the fence lands in preflight, preflight errors, no run: failed, No run, uncertain (408.771003ms)
✔ N4: the ack arrives after the first abort and a run starts: clear and abort again; Interrupted (319.475731ms)
✔ N5: an input handler takes the prompt: ack, no run, delivery-unknown handled-without-run (422.64905ms)
✔ N6: an extension queues between clear_queue and abort: O5 and O6, Unknown (536.684562ms)
✔ N7: clear_queue times out: no abort, nativeQueue unknown, force stop still ends it (1926.54673ms)
✔ N7: clear_queue answers an error: no abort, nativeQueue unknown, the link not poisoned (261.85206ms)
✔ N8: an extension prompt starts a run during Mosaic preflight; the losing settle is O3 (526.165066ms)
✔ N9: a run that started before the fence and ends aborted: failed interrupted, Interrupted (292.165984ms)
✔ N9: decision 34: a run that ends aborted with no stop in progress: aborted-without-stop, uncertain, outcome unknown (556.174851ms)
✔ N9: an aborted that lands after the fence but before any abort is written: aborted-without-stop, Unknown (391.852322ms)
✔ N10: fake conformance (31.082605ms)
✔ N11: the run fails before any user message_start: delivery-unknown ack-without-start, never failed (478.572614ms)
✔ N12: input that starts a run after the final empty clear is O1 and not part of the stop's proof (311.539451ms)
✔ N13: agent_start with no slot held is O1; a later prompt refuses with zero engine bytes (327.69438ms)
✔ N14: the run completes while clear_queue is in flight: finished, Completed first, uncertain (377.85985ms)
✔ N14: the run completes after the abort is written, before Pi applies it: finished, never relabelled (406.809075ms)
✔ N15: the fence lands in preflight, then an input handler takes it: handled-without-run, No run (415.148898ms)
✔ N16: Interrupt with no slot and no run refuses no-turn: no stop, no bytes, admission open (223.174587ms)
✔ N17: the run fails on its own during the exchange: failed, Failed on its own (362.138514ms)
✔ N18: no final assistant message_end, or a lost line: working stays working; before working, transport-unknown (823.257562ms)
✔ N19: a losing extension prompt settles inside the Mosaic run before its user message: O3, run-overlap (522.049384ms)
✔ N20: an extension triggerTurn during Mosaic preflight starts first; while streaming it queues with no signal (609.470456ms)
✔ N21: a losing settle after the receipt settled finished is O2; the receipt stays finished (310.027929ms)
✔ N22: an agent-level custom message is dropped by the clear with no signal; evidence names the seal (311.932454ms)
✔ N23: a nextTurn message survives clear and abort and attaches to the next prompt, with no signal (200.59052ms)
✔ N24: the seal is an allow-list: --extension, a missing --no-* flag, a second --mode or --session, a session or output flag, or a stray word refuses unsealed-engine; no engine starts (241.550105ms)
✔ N24b: the seal covers the engine command and environment: config can't name either, the env is built from names, and a mutated command is refused at bind (205.758549ms)
ℹ tests 171
ℹ suites 0
ℹ pass 168
ℹ fail 3
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 62347.19459

✖ failing tests:

test at packages/conversation/tests/cohort.test.mjs:767:1
✖ R1: after a proven force stop the controller releases the scope; the shim and the unit are gone (8643.176352ms)
  Error: timed out waiting for the release
      at until (file:///home/jwoltje/darkwing-scratch/r50a/wt2/packages/conversation/tests/cohort.test.mjs:49:33)
      at async TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r50a/wt2/packages/conversation/tests/cohort.test.mjs:774:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7)

test at packages/conversation/tests/cohort.test.mjs:784:1
✖ R2: close releases the scope of a binding proven stopped, once, when the stop's own release hasn't run (576.569113ms)
  AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal:
  + actual - expected
  
  + []
  - [
  -   [
  -     'close',
  -     'released',
  -     'mosaic-chat-c113b34935ebb759fe6dcdcb4',
  -     'absent'
  -   ]
  - ]
  
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r50a/wt2/packages/conversation/tests/cohort.test.mjs:797:12)
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: [],
    expected: [ [ 'close', 'released', 'mosaic-chat-c113b34935ebb759fe6dcdcb4', 'absent' ] ],
    operator: 'deepStrictEqual',
    diff: 'simple'
  }

test at packages/conversation/tests/cohort.test.mjs:855:1
✖ R4: after a normal engine exit the scope stays until a proven force stop releases it (8688.575873ms)
  Error: timed out waiting for the release
      at until (file:///home/jwoltje/darkwing-scratch/r50a/wt2/packages/conversation/tests/cohort.test.mjs:49:33)
      at async TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r50a/wt2/packages/conversation/tests/cohort.test.mjs:869:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7)
