✔ inbox lists only decisions routed to the human, with what approving authorizes and how to decide (148.697373ms)
✔ decide resolves by id prefix with --yes, and the trail shows it in broker order with the task to follow (149.700256ms)
✔ decide refuses without a terminal or --yes, on an unknown option and on a short reference (128.806462ms)
✔ decide prints a declining choice as declining (120.583876ms)
✔ an unknown outcome is reported once and never resent (137.338274ms)
✔ a decision closed before the answer arrives exits 2 and points at its trail (127.075516ms)
✔ a prefix that matches two open decisions exits 2 and resolves neither (128.145326ms)
✔ without --business a command uses the live host's business, and a stale host.json is not a host (121.555421ms)
✔ every human command refuses inside an agent run before it touches the bus (121.159027ms)
✔ usage errors exit 4; no business and no host is a usage error (114.317995ms)
✔ agents and tasks print through the broker (130.258556ms)
✔ notify.json: missing, loose, malformed and extra keys refuse; a binding or null passes (1.201353ms)
✔ bootConfig builds the broker's boot message for one business, with no trackers key when no project names one (51.334717ms)
✔ trackers come from the tracker.* variables of the one project that names a tracker project (37.112733ms)
✔ with two projects, the one that sets tracker.project supplies the tracker and the other is no conflict (35.596109ms)
✔ two projects that each name a tracker project refuse, since the boot shape holds one (33.392489ms)
✔ a business without tracker.baseUrl gets no trackers entry (31.250826ms)
✔ an unknown business and a broken system config refuse with exit 3 (51.127857ms)
✔ empty views say so (0.939438ms)
✔ the trail keeps the broker's order and names a decision's task without its rows (1.310236ms)
✔ tasks print the tracker fields the snapshot carries (0.218466ms)
✔ the host boots the broker, binds a launch in process, and the notifier DMs a blocking decision exactly once (938.914142ms)
✔ a notifier that dies takes the host down with exit 1, so the unit restarts the pair (246.786456ms)
✔ a second host for the same data root refuses with exit 3 while the first runs (190.983502ms)
✔ a broker reply that misses the wait breaks the channel: the late reply answers nothing, later requests refuse, the host exits 1 (1191.036938ms)
✖ a broker reply with another request's id, or none, breaks the channel and the host exits 1 (160.601147ms)
✔ a notifier that refuses stops the broker and the host refuses with exit 3 (230.076697ms)
✔ a notifier that refuses after the broker died still refuses with exit 3, without a send to the dead broker (190.261213ms)
✔ a notifier that dies before it replies, after the broker died, still refuses, without a send to the dead broker (131.603939ms)
✔ a close send that fails with EPIPE after the notifier refuses still gives the notifier's refusal, exit 3 (195.26257ms)
✔ a close send that fails with EPIPE after the notifier dies unanswered still gives the notifier's error (726.01043ms)
✔ close() whose stop and close sends fail with EPIPE still finishes, with exit 1 (1625.636559ms)
✔ watchChildren reports a child that died before it was called, and one that dies later (208.572521ms)
✔ bus stop refuses to signal a live pid that is not a bus host (226.062986ms)
✔ bus start refuses with exit 3 and the code when the broker refuses to boot; bus status names the lock (433.248251ms)
✔ bus start refuses with exit 3 without a notifier config (192.266722ms)
✔ bus start runs until bus stop; status reports it while it runs (893.270829ms)
✔ bus-service.sh renders the unit and installs it into a given directory (29.435844ms)
✔ bus start --pm: the PM runs under its own PID namespace, registered, with a manifest (300.480969ms)
✔ the PM launches a coder through its launch tool; the coder answers; refusals name their code (684.354163ms)
✔ a runner that stops at once ends its launch with the runner's reason (273.925464ms)
✔ a host that died hard leaves its sessions to the next host, which kills them and ends their runs so the role can be launched again (802.080225ms)
✔ a host that died hard leaves its sessions to the next host, which finds one already exited (23) and ends their runs so the role can be launched again (4630.122168ms)
✔ a malformed sessions.json refuses the host start with exit 3 and stays as it was (254.910333ms)
✔ an over-long launch request is refused at once, not at the 10 s idle timeout (210.969484ms)
✔ a launch client that never closes its side doesn't hold the host's close (148.695994ms)
✔ a runner that ignores SIGTERM is killed when the host closes (1266.625366ms)
✔ zoned uses the IANA zone across DST (21.67197ms)
✔ each open blocking decision is DM'd once, across polls and a restart; non-blocking ones are not (144.729882ms)
✔ two blocking decisions get two DMs with different nonces (155.268269ms)
✔ the digest nonce differs per business and per day and fits Discord's 25 characters (0.297991ms)
✔ a failed DM is journaled, backs off, and is retried until it lands (126.071063ms)
✔ five definite refusals stop a DM: one gave-up line, one log line, and a restart keeps the count (122.754724ms)
✔ 429s, 5xx-style unknowns and refusals without a status never count toward the limit (131.978289ms)
✔ a crash between the fifth refusal and its gave-up line: the next poll appends it and sends nothing (117.924008ms)
✔ polled every POLL_MS against a permanent 403, a DM is sent at 0, 30, 60, 90 and 120 min and gives up only then (176.265305ms)
✔ a restart after the second refusal does not send before that refusal's 30 min are up (156.975988ms)
✔ the digest goes at 08:00 Chicago once a day, with blocking ones marked as DM'd (145.563662ms)
✔ a late start with no digest for the day sends one at once; an empty inbox gets one line (122.564352ms)
✔ an inbox read failure is logged and the next poll retries (0.603809ms)
✔ no Discord id reaches the journal or the log (122.743751ms)
✔ the journal: a torn tail is copied out and truncated, so an append after it reopens cleanly (34.661862ms)
✔ the journal: a crash between the copy and the truncate leaves a tail the next open repairs (54.673675ms)
✔ the journal: a whole file that is one torn line truncates to empty (29.981829ms)
✔ the journal: a malformed complete line refuses and leaves the file and any torn tail alone (2.234882ms)
✔ the journal: a loose file mode, a loose directory or a symlinked journal refuses (0.621975ms)
✔ the journal: a line with a wrong type refuses with exit 3 and names the field (1.834696ms)
✔ the journal: a symlinked directory refuses and says it is a link (0.466476ms)
✔ the journal: a dangling directory link, a parent that is a file and a journal that is a directory each refuse with exit 3 (0.510543ms)
✔ the journal: an append after the file was swapped for a symlink refuses and writes nothing through it (0.383721ms)
✔ the journal: a directory it cannot write or create refuses with exit 3 and names the path (0.427926ms)
✔ digest content stays within Discord's 2000 characters (0.255025ms)
✔ runLoop never overlaps ticks and stops after the one in flight (111.486218ms)
task.close {} answered: invalid-request; fake saw 18 requests, first GET /info 200, GET /projects/1 200, GET /projects/1/views 200
task.close on a missing task answered: task-not-found; it made GET /tasks/999 404
✔ bootConfig trackers reach the S3 adapter in the real broker child, which goes ready against a fake Vikunja (428.349483ms)
✔ the transport writes {business, verb, args} to the child and reads its JSON (46.508343ms)
✔ a bus code on stderr becomes the exit code; garbage and timeouts are outcome problems (2169.509112ms)
✔ busExit and refuseInsideAgent (0.4227ms)
✔ talk sends a REQUEST, prints and reads everything that arrives, and stops at the reply (244.465517ms)
✔ talk --wait 0 only sends; no reply within --wait exits 1 and says where it will show (1151.118912ms)
✔ talk, stop and launches off/on refuse inside an agent run; bad arguments are usage errors (112.967802ms)
✔ launches off and on go to the broker and change the business's launch state (140.237907ms)
✔ launches list reads sessions.json and marks a stale entry; stop reports it and refuses a non-runner (140.61441ms)
ℹ tests 82
ℹ suites 0
ℹ pass 81
ℹ fail 1
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 8661.544704

✖ failing tests:

test at packages/cli/tests/host.test.mjs:240:1
✖ a broker reply with another request's id, or none, breaks the channel and the host exits 1 (160.601147ms)
  AssertionError [ERR_ASSERTION]: another id
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41b/wt/packages/cli/tests/host.test.mjs:258:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: CliError: identity refused: unauthenticated
        at file:///home/jwoltje/darkwing-scratch/r41b/wt/packages/cli/src/host.mjs:205:29
        at process.processTicksAndRejections (node:internal/process/task_queues:104:5),
    operator: 'rejects',
    diff: 'simple'
  }
