✔ config directory and file path follow MOSAIC_CONFIG (2.247029ms)
✔ the fixture business validates and comes back frozen (6.633818ms)
✔ two instances may share a definition (2.079058ms)
✔ top-level refusals (6.494276ms)
✔ arbiters and projects (9.593184ms)
✔ role instances (4.099484ms)
✔ Vikunja bots (9.407995ms)
✔ a role without Vikunja takes no tracker block (2.980678ms)
✔ credential references match the definition's services (4.080229ms)
✔ launch (13.062449ms)
✔ loadBusiness: file checks (2.443093ms)
✔ loadBusiness: not a regular file (60.332879ms)
✔ loading writes nothing (1.620853ms)
✔ names that are Object.prototype properties don't count as declared (5.165091ms)
✔ the shipped example refuses as written and validates once filled in (0.861003ms)
✔ usage errors exit 4 (422.043713ms)
✔ validate: a good business exits 0 and prints instance digests (105.035447ms)
✔ validate: project files (427.125782ms)
✔ validate: missing files and a broken system config (307.241615ms)
✔ validate: credential reference problems exit 2 and name each one (95.518816ms)
✔ validate: a token file inside the repository is refused (87.525855ms)
✔ validate: role definitions come from MOSAIC_ROLES_DIR (285.815308ms)
✔ resolve: prints one instance's record (278.379994ms)
✔ resolve: refusals (502.16823ms)
✔ parse: exactly one of file or env, plus the service's date (3.909755ms)
✔ check: a good file has no problems (0.982554ms)
✔ check never opens the file: a write-only token passes (0.391532ms)
✔ check: file problems (1.499342ms)
✔ check: token files can't live in the repository or dataRoot, even through a linked directory (1.002701ms)
✔ check: dates and environment references (0.599406ms)
✔ path and load (2.380308ms)
✔ refusals (1.438365ms)
✔ systemVars flattens the validated config (2.454743ms)
✔ precedence: system, business, project, project role, agent (6.249979ms)
✔ limits narrow the definition and never widen it (3.213516ms)
✔ role.launch stays within-role only for the instance the launch block names (9.064504ms)
✔ limits.authority without role.launch leaves the launcher with no launch block (4.036328ms)
✔ limits.authority narrows cross-role actions too (1.761735ms)
✔ classify (1.653353ms)
✔ the record carries what the broker and launcher need (1.368244ms)
✔ digest: key order doesn't matter, any value change does (10.405106ms)
✔ refusals (3.017749ms)
✔ the four shipped version 2 roles load (4.981049ms)
✔ shipped role scopes match addendum B section 2 and the SR runbook (1.460327ms)
✔ shipped authority follows the note's table (0.791107ms)
✔ version 1 files keep loading with no authority (1.248782ms)
✔ the conductor policy isn't a role (0.328608ms)
✔ a missing role file is exit 4, a symbolic link too (0.536317ms)
✔ version 2 refusals (1.944397ms)
✔ authority: closed vocabulary, no gated-only action, no overlap (2.922779ms)
✔ credentials: Gitea scopes (1.349151ms)
✔ credentials: Vikunja scopes are a group-to-verbs map from the grantable list (1.633512ms)
✔ credentials: services (0.882165ms)
✔ contract: a non-empty regular Markdown file beside the role file (1.18187ms)
✔ every key names known layers and a merge rule (0.886623ms)
✔ unknown keys and wrong layers refuse (1.149448ms)
✔ types (2.318627ms)
✔ merge: defaults, then the most specific layer wins (0.405798ms)
✔ merge: limits only narrow, and provenance lists each source (0.514157ms)
✔ merge doesn't change its inputs (0.234247ms)
ℹ tests 60
ℹ suites 0
ℹ pass 60
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 2597.243526
