v24.21.0
✔ launch identity is stamped, payload identity is refused and stale holder cannot send (235.92328ms)
✔ decision classes route from policy; gated resolution is human-only, choice and target must match (426.910198ms)
✔ claim exclusion, holder release, gated revoke and rerouting to a new holder are atomic (495.105331ms)
✔ launch events require a human CLI capability; generic emit cannot forge authority events (228.698793ms)
✔ within-role decisions close atomically and invalid options or blocking omissions refuse (213.364447ms)
✔ observer capabilities read human inbox but cannot mutate or forge launch identity (225.385799ms)
✔ task action subjects and linked decision trail are complete and ordered (288.189341ms)
✔ launch binding is durable and reconnecting requires the identical trusted record (115.454413ms)
✔ business isolation includes inherited object names and cross-business message references (237.185536ms)
✔ authority never transfers between action, run, target, unresolved or replaced role holder (339.545483ms)
✔ task projection uses schema current view, skipping earlier and equal-start polls (201.677639ms)
✔ revocation permanently bars the old run from reclaiming first, including after broker restart (224.355313ms)
✔ empty message references refuse before storage; refusal-evidence failure stays a typed error (162.265056ms)
✔ both arbiters require human resolution when their cross-role route is themselves (295.039131ms)
✔ S1 adapter takes resolved limits and refs, rejects mismatched instance, never mutates input (2.787893ms)
✔ only validated broker references load; returned data and exceptions cannot expose a known token (4.70321ms)
✔ bad file modes, symlinks, repository/data paths, malformed tokens and missing dates refuse (4.119351ms)
✔ expiry refuses use and env references never become client data (1.029855ms)
✔ S1 parsed service refs work, service mismatch refuses, Gitea rotation due is a warning state (1.699922ms)
✔ opaque tokens shorter than 16 characters refuse before use (0.358077ms)
✔ human proof binds CLI entry, process start and nonce; agents and incomplete ancestry refuse (3.73813ms)
✔ process reader gets own kernel identity without exposing environment values (0.776608ms)
✔ EACCES ancestor environments skip only markers; commands and registered launches still refuse (2.587563ms)
✔ real pid 1 remains inspectable when its environment is protected (0.494531ms)
✔ within-role sends cite an open gated launch decision without spending it or naming it in grants (337.195777ms)
✔ missing and foreign-business citations refuse and roll back message and grant (289.73417ms)
✔ cross-role sends still need a matching resolved decision and consume it once (454.4974ms)
✔ broker process binds trusted launches, offers reader capabilities, refuses human mutation, closes cleanly (319.212871ms)
✔ startup token refusal returns safe code without value or partial listening broker (33.355174ms)
✔ loaded fixture token is absent from socket replies and SQLite, including refusal evidence (268.632275ms)
✔ killed broker leaves an explicit stale lock; another process cannot silently reclaim it (247.294035ms)
✔ trusted host registers later launches; socket clients never have a registration verb (287.231207ms)
✔ runtime excludes declared project roots even when host supplies no repoRoots (37.381501ms)
✔ a refused launch binding leaves the broker and existing capabilities alive; bad protocol stops it (211.009213ms)
✔ v3b prototype refusals, views and append-only mutations (1621.484807ms)
✔ gated approval authorizes once, survives store reopen, and fresh approval works (408.772144ms)
✔ another run cannot consume an approval; a failed check leaves it usable (384.58817ms)
✔ two scheduled callers have exactly one grant and one consumed refusal (308.166326ms)
✔ failed commit rolls consumption back; cross-role consumes and within-role stays reusable (408.067494ms)
✔ class drift gated to cross-role refuses before consumption (276.232894ms)
✔ class drift cross-role to gated refuses before consumption (325.648398ms)
✔ class drift gated to within-role refuses before consumption (229.333491ms)
✔ class drift cross-role to within-role refuses before consumption (285.037582ms)
✔ class drift within-role to gated refuses before consumption (248.866242ms)
✔ class drift within-role to cross-role refuses before consumption (240.466824ms)
✔ message.send consumes approval and prevents a later send or authorize (236.059843ms)
✔ role.revoke consumes approval and prevents a later revoke or authorize (317.996245ms)
✔ creates private WAL store and excludes a second writer until explicit close (131.553502ms)
✔ rollback is atomic and schema metadata is checked against trusted DDL, not just itself (354.078946ms)
✔ existing empty database and symlink runtime directory refuse, never initialize over damage (315.784909ms)
✔ crash during a transaction recovers no partial event after explicit fixture-only lock removal (316.674129ms)
✔ writer refuses mixed at/read_at forms atomically, even through trusted SQL helpers (147.610319ms)
✔ async transactions refuse before invoking their function (105.656724ms)
✔ socket capability stamps launch identity; shared views use wire, no SQL client (254.245647ms)
✔ two wire claims serialize; a lost reply never automatically retries (270.023535ms)
✔ malformed, oversized and identity-forging envelopes refuse without echoing input (187.584216ms)
✔ client preserves UTF-8 when a response divides a multibyte character (11.863202ms)
✔ committed mutation followed by dropped reply reports unknown and is never retried (279.410147ms)
ℹ tests 58
ℹ suites 0
ℹ pass 58
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 3767.887114
