✔ W1: two processes acquire the same pair at once; exactly one claim (208.33252ms)
✔ W1: two writers publish the same revision at once: one wins, the other gets null, the winner's record stays (9.811798ms)
✔ W1: a revision name appears only after its bytes are synced; before that, only a temp file exists (5.537445ms)
✔ W2: acquire while a claim is reserved or active refuses already-active (228.104072ms)
✔ W3: acquire while stopping, uncertain, or stopped without proof refuses unsafe-replacement (324.120499ms)
✔ W4: same session with another seat tuple, and the reverse, both refuse; a loser on the seat key closes it no-unit (209.598509ms)
✔ W4: a hard link of one session under another seat is the same session: the second controller refuses already-active and launches nothing (27.238547ms)
✔ W4: a copy of one session under another seat is the same session: the second controller refuses already-active and launches nothing (22.122492ms)
✔ W4: a session header ID that changes after construction refuses target; nothing is claimed or launched (3.087845ms)
✔ W5: SIGKILL between every publication barrier of acquire and transition; restart never finds two holders or a lost claim (5701.445297ms)
✔ W5: SIGKILL between every publication barrier of release; restart finishes or holds the release (22244.010272ms)
✔ W6: controller killed mid-turn while the engine lives; restart is uncertain, no launch, prompts refuse (149.81459ms)
✔ W12: a live owner paused with SIGSTOP; a second controller refuses already-active and changes nothing (88.345296ms)
✔ W13: crash after the engine spawns, before active; restart finds the live unit: uncertain, no second spawn, force stop only (223.831116ms)
✔ W14: crash after reservation, before the spawn marker: stopped with a no-unit observation; the pair is free (188.323071ms)
✔ W20: crash after the spawn marker, scope collected; uncertain in both runs, the marker is copied, no launch until a boot proof (217.683612ms)
✔ W15: crash between the two keys during release; restart finishes it under the same claim ID (32.560634ms)
✔ W7: recorded boot ID differs on the same machine: stopped with a boot proof; open tool calls become uncertain (96.660024ms)
✔ W8: resume after a proven stop with the same pins: new claim ID, generation +1, same conversation, branch and leaf (32.019907ms)
✔ W9: resume with a changed binary, argv digest, branch or leaf is refused and the claim is unchanged (91.969696ms)
✔ W11: the controller writes no session file; only the fake engine's own appends appear (22.329944ms)
✔ W16: a highest revision that won't parse holds the pair uncertain; the older stopped revision is not reused (54.201621ms)
✔ W17: a claim root copied from another host refuses foreign-host and promotes nothing (60.552307ms)
✔ G1: a session path or claim root under .pi/state, ~/.claude, the data root or a registration refuses at construction (3.596267ms)
✔ G2: a symlink inside the fixture root to a live session file is refused by the real-path check (1.126052ms)
✔ G3: a fixture path swapped for a live path after construction is refused at bind (1.770404ms)
✖ K1: force stop kills a tool child that called setsid; stopped with a verified proof (2653.677511ms)
✔ K2: K1 on the process-group fallback ends uncertain, never stopped (129.308388ms)
✖ K3: SIGTERM acknowledged while a member lives: stopping until the kill phase, never stopped from TERM (2165.26786ms)
✔ K4: two engines; force stop one; the other survives by independent observation (4287.963097ms)
✔ K5: a stop during a tool call leaves the effect uncertain, and it is shown (2182.565146ms)
✔ K12: a member forking in a loop: the freeze stops it, enumeration is complete, populated 0 after cgroup.kill (2258.603392ms)
✔ K13: a member writing its pid into another cgroup is refused by the namespace; the kill is complete (2153.528491ms)
✔ K15: the shim gone, engine/cgroup.events unreadable, or the engine cgroup missing: evidence unavailable, not empty; uncertain (4403.942608ms)
✖ K10: controller killed between the TERM and kill phases: restart checks the invocation ID and re-runs from TERM for the same stop (180.585304ms)
✔ K11: controller killed after the confirmation is recorded, before TERM: restart checks the invocation ID and re-runs from TERM for the same stop (302.630477ms)
✔ K14: a unit with the recorded name but another invocation ID: evidence unavailable, no signals, uncertain (265.388551ms)
✔ K6: recover without proof, without confirmation, or with changed pins is refused (69.424274ms)
✔ K7: recover after proof, then launch: new claim and execution, generation +1, same leaf; the cancelled prompt is not replayed (38.2806ms)
✔ K8: an engine that loads another leaf on resume is refused before admission; it stays claimed until a proven stop (48.757019ms)
✔ K9: an interrupt that never settles stays uncertain; force stop stays available; takeover is refused while fenced (3026.567752ms)
✔ K16: a claim from another machine ID refuses foreign-host; no boot proof is issued (5.577601ms)
✔ K17: two launcher calls with one eligibility record: one launch, the other refuses, no second engine (35.813713ms)
✔ K18: the leaf changes after eligibility: launch refused; the reservation stays until released with proof (28.909283ms)
✔ S1: `/goal x`, with leading spaces or a tab, refuses text-policy at admission; zero engine bytes (49.842944ms)
✔ S2: every prefix pinned Pi interprets is refused, from the list the code uses; the rest reach the engine exactly (37.949131ms)
✔ S3: `/goal` on the second line is pinned from the source: Pi checks only index 0, so it is admitted and sent exactly (34.393597ms)
✔ S4: a `/` left in the composer is cleared when control transfers and returns; the next submit sends only the new text (55.353224ms)
✔ S5: an observer terminal gets a paste then Enter, as send-message.sh does: not admitted: controller, nothing sent (24.11355ms)
✔ S6: a mediated-shaped registration (no tmux) passed to the board's replyToRow: 409 no tmux session; exec never runs (0.684512ms)
✔ S7: ESC, bracketed-paste markers and U+2028/U+2029 travel as one JSON string; the engine receives the exact text in one record (26.735815ms)
✔ P3: a Pi confirm, select, input or editor dialog is shown disabled with a reason and never answered (127.693023ms)
✔ E1: send, ack, user, toolCall, toolResult, final answer: shown once, no refresh, draft and reading position kept (43.227988ms)
✔ E2: U+2028, U+2029 inside JSON strings and CRLF line ends each parse as one record, on the splitter and through the controller (26.124057ms)
✔ E3: a multipart final, two blocks, null request correlation and duplicate delivery (38.762027ms)
✔ E4: a page read after message_end but before its entry is persisted: marker at the seam, re-read after run-settled, each message once (38.724253ms)
✔ E4: a gap or a new epoch also reconciles; nothing is concatenated across a gap (10.71162ms)
✔ E5: an unknown native event gives no client event; evidence records its type and bytes; the terminal count goes up (30.187625ms)
✔ E6: a tool result delayed across a pause and a reconnect is reconciled without a manual refresh (48.049709ms)
✔ E7: the terminal renders the same stream as the library client, as observer and then as controller, and submits only as controller (43.974693ms)
✔ terminal: engine control characters are made visible; a lost connection refuses submit (30.554731ms)
✔ terminal: outcome unknown is shown as such, with no resend offer, and nothing is resent (0.71206ms)
✔ terminal: text after Enter in the same input chunk starts the next message; it never joins the one submitted (0.501472ms)
✔ terminal: a paste-start marker split right after its ESC still opens the paste; the Enter inside it never submits (0.71016ms)
✔ terminal: invisible and bidi characters are made visible; head, status and notice lines stay one line (0.205325ms)
✔ every record these fixtures produced is a valid CHAT-01 record (E5: no record fails the schema) (440.560715ms)
✔ H1: two takeovers with the same expected generation: one wins, +1; the other refuses generation (70.048519ms)
✔ H2: the old controller's prompt after a takeover commits is refused with zero engine bytes (89.612495ms)
✔ H3: a takeover while a prompt holds the dispatch lock: written under the old actor, or refused; never both (151.740861ms)
✔ H4: self-takeover is refused (19.567355ms)
✔ H9: Interrupt racing a prompt's dispatch: before the write, dispatch-refused and no-turn; after, §3 rules (126.266639ms)
✔ H10: Interrupt and force stop together: one stop chain, force stop supersedes (127.987954ms)
✔ H10: an overlap during the pause before the abort: no abort, the stop ends uncertain (30.194643ms)
✔ H10: a no-turn Interrupt lifts only its own fence; admission stays closed under force stop, overlap or revocation (90.744705ms)
✔ H11: the controller disconnects mid-turn: work continues, the claim is unchanged, control stays put (137.197933ms)
✔ H12: an exact retry after reconnecting to the same incarnation returns the same receipt; one dispatch (15.871752ms)
✔ H13: a retry with the same request ID and different text is refused (16.248157ms)
✔ H14: late stdout from the old engine after a replacement is dropped by incarnation, counted, never rendered (137.840526ms)
✔ H15: a revoked connection's command is refused; the revocation fence holds (67.750797ms)
✔ H16: a second controller for the same session refuses already-active; the first is untouched (18.408706ms)
✔ H10: a second force stop while the first escalation runs refuses fenced; one escalation, and the claim records only the first stop's phases (58.879625ms)
✔ H17: a confirmation reused, answered from another connection, or used after the stop changed is refused (54.75082ms)
✔ H18: two prompts before any native output: the second refuses busy; one engine write (15.210695ms)
✔ H19: the pipe fails mid-line under a large prompt: delivery-unknown transport-unknown, poisoned, no later write (119.912673ms)
✔ H19: the link itself never writes again after an unknown outcome, whoever calls it (0.74475ms)
✔ H19: the controller dies mid-write of a large line: after restart the outcome is unknown and nothing is resent (526.777789ms)
✔ H20: the line is written but the ack is lost when the controller dies: orphan, outcome unknown, nothing resent (406.518664ms)
✔ H21: a retry of the exact request with the old token after a crash is stale-incarnation; no second write (372.815504ms)
✔ H22: after H21 and a valid recovery, a new request with the new token is admitted (2470.446235ms)
✔ H23: requests pending at a restart are not resent; each shows outcome unknown (457.248222ms)
✔ a plain conversation: catalogue row, one page, CHAT-01 records (11.82056ms)
✔ native entries map to blocks: tools, thinking, bash, notices, ids that do not fit (2.271047ms)
✔ F1: a malformed line is an unavailable part at its position, and reading continues (2.730979ms)
✔ F1: a missing parent stops the history with a notice that names the unreadable lines (3.52433ms)
✔ F1: an unreadable fork is never merged into another branch's history (1.850162ms)
✔ F1: a follow stays on its branch when the next entry's parent is unreadable (4.636359ms)
✔ F1: a file whose entries are all unreadable shows a notice per line (1.641695ms)
✔ F2: a truncated trailing line marks the view incomplete, not an error (2.301832ms)
✔ pagination: 100 parts, then the rest; parts concatenate to the whole branch (7.597286ms)
✔ F3: a replaced file (new inode) refuses old cursors with reconcile (5.634047ms)
✔ F4: a same-inode rewrite of the prefix refuses old cursors with reconcile (7.869533ms)
✔ F5: growth between pages keeps the epoch and the page stops at the pinned length (11.185671ms)
✔ F6: unknown, foreign and expired cursors refuse and leave the cursor usable (14.562294ms)
✔ F7: a symlinked file and a symlinked directory component are refused, never opened (15.568579ms)
✔ F8: a file swapped for a symlink after the catalogue is refused (3.87859ms)
✔ F9: registrations never add or redirect a root (2.922432ms)
✔ F10: a header cwd naming another project is refused (6.505993ms)
✔ F11: parentSession renders with a marker and the parent is never opened (1.280591ms)
✔ F12: two leaves: the default leaf is shown and the other branch reads alone (8.701968ms)
✔ F12: a follow refuses when an appended duplicate id changes the branch's earlier parts (3.047678ms)
✔ F12: a second root (Pi's resetLeaf) starts its own branch (2.529818ms)
✔ F13: compaction is a marker in place, then the retained content (1.200056ms)
✔ F14: long strings split into fragments and parts, reassemble exactly, and pages respect the byte cap (927.08769ms)
✔ fragments never cut a surrogate pair and keep an empty string (6.246556ms)
✔ F15: a Claude seat is an unsupported-harness placeholder whose directory is never read (1.891982ms)
✔ unknown conversations, empty files and non-Pi files refuse (3.354143ms)
✔ an unreadable file or root inside the roots is refused per row, not a failed catalogue (1.403634ms)
✔ a seat directory without search permission refuses that root, not the catalogue (2.386158ms)
✔ every page and cursor is a valid CHAT-01 record (963.005061ms)
✔ the engine pin holds for the installed package (4.64981ms)
✔ pinned Pi, sealed and without credentials, answers the controller's commands with the shapes the fake models (492.509878ms)
✔ pinned Pi appends thinking_level_change at start when the branch lacks one, so the leaf moves (K8 then fails closed) (449.300806ms)
✔ N25: ordinary Interrupt reconciles; a non-empty queue_update in the window is O5 (99.699963ms)
✔ N1: an extension's follow-up queued after the fence is cleared before any abort; O5, Unknown (56.005591ms)
✔ N1: a follow-up queued before the fence is O5 at once; the Interrupt refuses fenced (36.010734ms)
✔ N2: with abort first, the fake runs the external item (the ordering guard has teeth) (23.120368ms)
✔ N3: the fence lands in preflight, preflight errors, no run: failed, No run, uncertain (40.605984ms)
✔ N4: the ack arrives after the first abort and a run starts: clear and abort again; Interrupted (32.198961ms)
✔ N5: an input handler takes the prompt: ack, no run, delivery-unknown handled-without-run (129.781085ms)
✔ N6: an extension queues between clear_queue and abort: O5 and O6, Unknown (60.975823ms)
✔ N7: clear_queue times out: no abort, nativeQueue unknown, force stop still ends it (1540.123798ms)
✔ N7: clear_queue answers an error: no abort, nativeQueue unknown, the link not poisoned (17.607252ms)
✔ N8: an extension prompt starts a run during Mosaic preflight; the losing settle is O3 (71.219891ms)
✔ N9: a run that started before the fence and ends aborted: failed interrupted, Interrupted (14.260687ms)
✔ N9: decision 34: a run that ends aborted with no stop in progress: aborted-without-stop, uncertain, outcome unknown (19.355928ms)
✔ N9: an aborted that lands after the fence but before any abort is written: aborted-without-stop, Unknown (40.425771ms)
✔ N10: fake conformance (34.674337ms)
✔ N11: the run fails before any user message_start: delivery-unknown ack-without-start, never failed (45.385869ms)
✔ N12: input that starts a run after the final empty clear is O1 and not part of the stop's proof (26.329147ms)
✔ N13: agent_start with no slot held is O1; a later prompt refuses with zero engine bytes (70.140045ms)
✔ N14: the run completes while clear_queue is in flight: finished, Completed first, uncertain (30.960887ms)
✔ N14: the run completes after the abort is written, before Pi applies it: finished, never relabelled (33.997394ms)
✔ N15: the fence lands in preflight, then an input handler takes it: handled-without-run, No run (24.416409ms)
✔ N16: Interrupt with no slot and no run refuses no-turn: no stop, no bytes, admission open (13.466921ms)
✔ N17: the run fails on its own during the exchange: failed, Failed on its own (26.194657ms)
✔ N18: no final assistant message_end, or a lost line: working stays working; before working, transport-unknown (105.895233ms)
✔ N19: a losing extension prompt settles inside the Mosaic run before its user message: O3, run-overlap (137.573966ms)
✔ N20: an extension triggerTurn during Mosaic preflight starts first; while streaming it queues with no signal (85.246925ms)
✔ N21: a losing settle after the receipt settled finished is O2; the receipt stays finished (16.090188ms)
✔ N22: an agent-level custom message is dropped by the clear with no signal; evidence names the seal (14.423581ms)
✔ N23: a nextTurn message survives clear and abort and attaches to the next prompt, with no signal (14.347618ms)
✔ N24: the seal is an allow-list: --extension, a missing --no-* flag, a second --mode or --session, a session or output flag, or a stray word refuses unsealed-engine; no engine starts (44.072894ms)
ℹ tests 152
ℹ suites 0
ℹ pass 149
ℹ fail 3
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 32310.893453

✖ failing tests:

test at packages/conversation/tests/cohort.test.mjs:139:1
✖ K1: force stop kills a tool child that called setsid; stopped with a verified proof (2653.677511ms)
  AssertionError [ERR_ASSERTION]: the escaped child is a listed member
      at TestContext.<anonymous> (file:///home/jwoltje/filbert-scratch/r45/base/packages/conversation/tests/cohort.test.mjs:151:12)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async startSubtestAfterBootstrap (node:internal/test_runner/harness:387:3) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: false,
    expected: true,
    operator: '==',
    diff: 'simple'
  }

test at packages/conversation/tests/cohort.test.mjs:176:1
✖ K3: SIGTERM acknowledged while a member lives: stopping until the kill phase, never stopped from TERM (2165.26786ms)
  AssertionError [ERR_ASSERTION]: the member ignored TERM
      at TestContext.<anonymous> (file:///home/jwoltje/filbert-scratch/r45/base/packages/conversation/tests/cohort.test.mjs:190:12)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: false,
    expected: true,
    operator: '==',
    diff: 'simple'
  }

test at packages/conversation/tests/cohort.test.mjs:426:3
✖ K10: controller killed between the TERM and kill phases: restart checks the invocation ID and re-runs from TERM for the same stop (180.585304ms)
  AssertionError [ERR_ASSERTION]: the member is alive across the crash
      at TestContext.<anonymous> (file:///home/jwoltje/filbert-scratch/r45/base/packages/conversation/tests/cohort.test.mjs:431:12)
      at process.processTicksAndRejections (node:internal/process/task_queues:104:5)
      at async Test.run (node:internal/test_runner/test:1409:7)
      at async Test.processPendingSubtests (node:internal/test_runner/test:974:7) {
    generatedMessage: false,
    code: 'ERR_ASSERTION',
    actual: false,
    expected: true,
    operator: '==',
    diff: 'simple'
  }
