✔ config directory and file path follow MOSAIC_CONFIG (2.210719ms)
✔ the fixture business validates and comes back frozen (8.770712ms)
✔ two instances may share a definition (2.177367ms)
✔ top-level refusals (8.827406ms)
✔ arbiters and projects (14.50992ms)
✔ role instances (4.839355ms)
✔ Vikunja bots (11.538611ms)
✔ a role without Vikunja takes no tracker block (3.793442ms)
✔ credential references match the definition's services (4.868786ms)
✔ launch (14.960448ms)
✔ loadBusiness: file checks (3.236296ms)
✔ loadBusiness: not a regular file (91.08637ms)
✔ loading writes nothing (2.57653ms)
✔ names that are Object.prototype properties don't count as declared (6.890756ms)
✔ the shipped example refuses as written and validates once filled in (2.883122ms)
✔ usage errors exit 4 (869.470778ms)
✔ validate: a good business exits 0 and prints instance digests (82.042246ms)
✔ validate: project files (417.1794ms)
✔ validate: missing files and a broken system config (390.376836ms)
✔ validate: credential reference problems exit 2 and name each one (99.3234ms)
✔ validate: a token file inside the repository is refused (103.756822ms)
✔ validate: role definitions come from MOSAIC_ROLES_DIR (234.927357ms)
✔ resolve: prints one instance's record (281.877257ms)
✔ resolve: refusals (989.310152ms)
✔ parse: exactly one of file or env, plus the service's date (4.549447ms)
✔ check: a good file has no problems (1.209331ms)
✔ check never opens the file: a write-only token passes (0.804481ms)
✔ check: file problems (1.630366ms)
✔ check: token files can't live in the repository or dataRoot, even through a linked directory (1.247451ms)
✔ check: dates and environment references (0.70132ms)
✔ path and load (3.972788ms)
✔ refusals (2.078689ms)
✔ systemVars flattens the validated config (3.4031ms)
✔ precedence: system, business, project, project role, agent (9.73379ms)
✔ limits narrow the definition and never widen it (5.213511ms)
✔ role.launch stays within-role only for the instance the launch block names (9.175749ms)
✔ limits.authority without role.launch leaves the launcher with no launch block (3.165563ms)
✔ limits.authority narrows cross-role actions too (2.155587ms)
✔ classify (2.074589ms)
✔ the record carries what the broker and launcher need (1.773542ms)
✔ digest: key order doesn't matter, any value change does (11.515402ms)
✔ refusals (3.850074ms)
✔ the four shipped version 2 roles load (5.81714ms)
✔ shipped role scopes match addendum B section 2 and the SR runbook (2.413725ms)
✔ shipped authority follows the note's table (1.528904ms)
✔ version 1 files keep loading with no authority (1.516579ms)
✔ the conductor policy isn't a role (0.505683ms)
✔ a missing role file is exit 4, a symbolic link too (0.688851ms)
✔ version 2 refusals (2.788584ms)
✔ authority: closed vocabulary, no gated-only action, no overlap (3.696945ms)
✔ credentials: Gitea scopes (1.798267ms)
✔ credentials: Vikunja scopes are a group-to-verbs map from the grantable list (1.959897ms)
✔ credentials: services (0.894557ms)
✔ contract: a non-empty regular Markdown file beside the role file (1.458286ms)
✔ every key names known layers and a merge rule (2.305419ms)
✔ unknown keys and wrong layers refuse (1.12706ms)
✔ types (2.631133ms)
✔ merge: defaults, then the most specific layer wins (0.412703ms)
✔ merge: limits only narrow, and provenance lists each source (0.911658ms)
✔ merge doesn't change its inputs (0.224637ms)
ℹ tests 60
ℹ suites 0
ℹ pass 60
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 3610.609773
