✔ sessionModel: agent vars win, then the system's execution settings (14.067777ms)
✔ a pi bundle: prompt, policy, tools and manifest, 0600 in a 0700 directory (4.83597ms)
✔ a claude-code bundle adds the wrapped gate hook and the MCP config (3.203511ms)
✔ a bundle is written once: an existing file refuses (2.324752ms)
✔ a path with a single quote can't go into the hook command (2.432801ms)
✔ allow exits 0, a deny exits 2 with the reason on stderr (125.69164ms)
✔ a missing or wrong policy, or a bad event, exits 2 (87.248095ms)
✔ the bundle's wrapped command: a missing gate or node still blocks (1096.130839ms)
✔ claude: typed tools through MCP, the hook blocks, builtins outside --tools don't exist (822.887941ms)
✔ claude: the hook alone blocks a path outside the workspace (619.788359ms)
✔ claude: a second turn resumes the first turn's session (720.544276ms)
✔ claude: a missing hook or MCP file refuses before claude starts (7.807494ms)
✔ pi: policy tools and typed tools pass, anything else is blocked (2.760889ms)
✔ claude: builtins map from pi names, typed tools need the mcp prefix (0.858294ms)
✔ file tool paths must resolve inside the workspace (1.329669ms)
✔ pi's own path normalisation can't be used to step out (1.208492ms)
✔ a symlink inside the workspace that points out is outside (1.109705ms)
✔ claude path fields per tool (0.783786ms)
✔ glob patterns stay inside the workspace (1.009446ms)
✔ a path that can't be checked is blocked (0.632633ms)
✔ initialize, ping and tools/list (44.810011ms)
✔ tools/call goes through the tool socket; a refusal is an isError result (34.700842ms)
✔ unknown tools and methods are JSON-RPC errors and never reach the socket (35.585978ms)
✔ a missing argument is a usage error (39.424495ms)
✔ pi: typed tools reach the socket, the gate blocks, agent_end writes the marker (377.597538ms)
✔ pi: a missing extension refuses before any model call (8.384513ms)
✔ pi: an extension without its configuration fails pi's start (294.902223ms)
✖ founderCheck: founder variables, then a needed service without a usable token (2.011371ms)
✔ turnRequest names the sender, class, reply and decision (0.351869ms)
✔ a message becomes a turn, the answer goes back as a RESULT, SIGTERM releases and exits 0 (239.104388ms)
✔ a SIGTERM before the claim stops the runner with exit 0 and no claim (134.155238ms)
✔ typed tools carry the runner's capability; launch goes to the host's launch socket (534.9943ms)
✔ a RESULT gets no automatic reply; failed turns reply with the reason (1584.330846ms)
✔ SIGTERM during a turn kills the turn's process group and still exits 0 (150.826229ms)
✔ the PM gets launch, its task verbs and the reads (7.17446ms)
✔ a coder gets no launch, no resolve_decision, and no task tools without a tracker (2.29576ms)
✔ launch only when the business's launch block names the instance as launcher (1.646169ms)
✔ an action outside the instance's authority has no tool (1.594448ms)
✔ callTool: one JSON line out, the result back, a refusal rejects (8.633147ms)
ℹ tests 39
ℹ suites 0
ℹ pass 38
ℹ fail 1
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 263663.299994

✖ failing tests:

test at packages/harness/tests/runner.test.mjs:34:1
✖ founderCheck: founder variables, then a needed service without a usable token (2.011371ms)
  AssertionError [ERR_ASSERTION]: The "string" argument must be of type string. Received type object (null)
      at TestContext.<anonymous> (file:///home/jwoltje/darkwing-scratch/r41/wt/packages/harness/tests/runner.test.mjs:38:10)
      at Test.runInAsyncScope (node:async_hooks:226:14)
      at Test.run (node:internal/test_runner/test:1402:25)
      at Test.start (node:internal/test_runner/test:1262:17)
      at startSubtestAfterBootstrap (node:internal/test_runner/harness:387:17) {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: null,
    expected: /GITEA_TOKEN, SSH_AUTH_SOCK/,
    operator: 'match',
    diff: 'simple'
  }
