diff --git a/Scripts/Fixtures/test-suite-contract-ledger.tsv b/Scripts/Fixtures/test-suite-contract-ledger.tsv index 765e222c6..b9dfcbd03 100644 --- a/Scripts/Fixtures/test-suite-contract-ledger.tsv +++ b/Scripts/Fixtures/test-suite-contract-ledger.tsv @@ -79,7 +79,7 @@ root/RepoPromptTests.AgentContextExportResolverTests/testPreviewContentIsPrefixB root/RepoPromptTests.AgentContextExportResolverTests/testRemoveRowRebasedOntoLatestSelectionPreservesNewlyAddedFiles root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRemoveRowRebasedOntoLatestSelectionPreservesNewlyAddedFiles AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.004000 unreviewed retain_pending_review 0 initial census source line 295 root/RepoPromptTests.AgentContextExportResolverTests/testRemoveRowResolvesLogicalSelectionKeysByFileIdentity root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRemoveRowResolvesLogicalSelectionKeysByFileIdentity AgentMode codemap.cutover.agent.file-identity-removal logical_alias,absolute_alias,file_id,async_rebase deterministic_regression root_swiftpm routine 2 AgentExportBoundWorktreeFixture Async row removal resolves logical and absolute original selection keys through the scoped catalog and removes every alias for the same file ID. Retaining a physical row path could leak worktree locations or remove the wrong rebased selection entry. 0.003500 temporary_root,actor_store,worktree_projection test_method+tearDownWithError retain 0 Renames testRemoveRowMutatesLogicalStoredSelectionByPhysicalizedPath and replaces physical-path equality with exact file identity. root/RepoPromptTests.AgentContextExportResolverTests/testRemovingInferredAutomaticRowDisablesTransientSourceIntent root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRemovingInferredAutomaticRowDisablesTransientSourceIntent AgentMode headless_p1.inferred_row_removal automatic_selection,source_intent,removal deterministic_regression root_swiftpm routine 1 AgentExportBoundFixture Removing an inferred automatic codemap row preserves explicit selection and disables codemapAutoEnabled source intent. Agent export could expose a no-op removal affordance for inferred rows. 0.023500 temp_roots;worktree_projection test_case+tearDown retain 0 Headless P1 grouped repair Agent removal contract -root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapLifetimeOmitsUnavailableTargetAndReportsLogicalMissingPath root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRevokedCodemapLifetimeOmitsUnavailableTargetAndReportsLogicalMissingPath AgentMode agent_context.codemap.revoked_lifetime_unavailable root_lifetime,publication_receipt,retry,selected_fallback,stale_omission stale_generation_contract root_swiftpm routine 3 AgentExportRevokedWorktreeFixture When the physical CodeMap target is revoked before model publication, export omits the unavailable bytes and reports the logical missing path. A revoked physical target could leak stale CodeMap content or disappear without a logical missing-path diagnostic. 2.090000 filesystem,git_fixture,actor_store,worktree_projection,concurrency test_method+repository_fixture_cleanup retain 0 root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapLifetimeOmitsStaleTargetBeforeModelPublication -> root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapLifetimeOmitsUnavailableTargetAndReportsLogicalMissingPath; inherited exact-ID drift reconciled during Item 3 ledger verification +root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapLifetimeOmitsStaleTargetBeforeModelPublication root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRevokedCodemapLifetimeOmitsStaleTargetBeforeModelPublication AgentMode codemap.cutover.agent.revocation-before-publish root_lifetime,publication_receipt,retry,selected_fallback,stale_omission stale_generation_contract root_swiftpm routine 3 AgentExportRevokedWorktreeFixture A root lifetime revoked immediately before final publication never emits the stale codemap target; the selected file remains a full row and coverage is typed unavailable. Agent export could publish a rendered entry from an unloaded session worktree or drop the selected-file fallback. 2.090000 filesystem,git_fixture,actor_store,worktree_projection,concurrency test_method+repository_fixture_cleanup retain 0 C2 final publication receipt revalidation regression. root/RepoPromptTests.AgentContextExportResolverTests/testSelectedFilesModelWithoutCodemapsDoesNotEnumerateWholeRoots root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testSelectedFilesModelWithoutCodemapsDoesNotEnumerateWholeRoots AgentMode agent_context_export_resolver.selected_files_model_without_codemaps_does_not_enumerate_whole_roots deterministic_regression root_swiftpm routine 1 AgentContextExportResolverTests asserts selected files model without codemaps does not enumerate whole roots with exact state, configuration, or formatted-output expectations. Agent context export could read the wrong checkout, enumerate too broadly, or bypass worktree/codemap freshness guards. 0.051500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.AgentContextExportResolverTests/testSelectedGitDiffPathsUseBoundWorktreeScope root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testSelectedGitDiffPathsUseBoundWorktreeScope AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.093000 unreviewed retain_pending_review 0 initial census source line 508 root/RepoPromptTests.AgentContextExportResolverTests/testSelectedUnavailableCodemapPreservesFullRowAndReportsIncompleteCoverage root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testSelectedUnavailableCodemapPreservesFullRowAndReportsIncompleteCoverage AgentMode codemap.cutover.agent.pending-policy selected_mode,full_fallback,typed_unavailable,non_git,no_runtime availability_contract root_swiftpm routine 2 AgentExportSelectedUnavailableFixture Selected-mode codemap unavailability preserves the selected file as a full row, exposes typed incomplete coverage, and stays runtime-inert for a non-Git root. Unavailable selected codemaps could disappear, masquerade as complete, or trigger legacy/runtime fallback work. 0.003500 temporary_root,actor_store test_method+tearDownWithError retain 0 C2 selected-file degradation contract. @@ -95,8 +95,6 @@ root/RepoPromptTests.AgentContextExportResolverTests/testSourceBuilderUsesReques root/RepoPromptTests.AgentContextExportResolverTests/testUnboundAgentExportDoesNotSeeSessionWorktreeRoots root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testUnboundAgentExportDoesNotSeeSessionWorktreeRoots AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.003500 unreviewed retain_pending_review 0 initial census source line 220 root/RepoPromptTests.AgentContextExportResolverTests/testWorktreeExportUsesPhysicalContentWhileDisplayingLogicalPath root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testWorktreeExportUsesPhysicalContentWhileDisplayingLogicalPath AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.019500 unreviewed retain_pending_review 0 initial census source line 117 root/RepoPromptTests.AgentContextExportResolverTests/testWorktreeSelectedCodemapUsesFrozenLogicalPresentationWithoutPhysicalLeak root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testWorktreeSelectedCodemapUsesFrozenLogicalPresentationWithoutPhysicalLeak AgentMode codemap.cutover.agent.preview-frozen-text logical_projection,no_physical_path,frozen_preview,clipboard_export,token_text_identity,exact_root production_shaped_store_integration root_swiftpm routine 4 AgentExportLogicalWorktreeCodemapFixture The selected worktree codemap row, preview, token count, and clipboard export derive from immutable modern rendered text with the logical root identity and no physical worktree path or body fallback. Preview and export could refetch legacy FileAPI data, diverge from accounting, or leak a session-worktree path. 1.466000 filesystem,git_fixture,artifact_store,actor_store,worktree_projection test_method+repository_fixture_cleanup retain 0 C2 shared frozen presentation and logical path regression; also covers codemap.cutover.agent.no-physical-row-path. -root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapReloadFallsBackToFreshAuthoritativeFullContent root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRevokedCodemapReloadFallsBackToFreshAuthoritativeFullContent AgentMode/ContextExport agent_context.codemap.revoked_reload_fresh_fallback revocation,reload,authoritative_full_content integration_contract root_swiftpm routine 1 ReviewGitRepositoryFixture A revoked CodeMap presentation reload publishes freshly read authoritative full content and excludes stale sentinels. Reload could reuse revoked or stale CodeMap bytes instead of current authoritative file content. 0.100000 filesystem,concurrency test_case retain 0 Inherited live-ID ledger drift reconciled during Item 3 authoritative verify-ledger pass -root/RepoPromptTests.AgentContextExportResolverTests/testRevokedCodemapClipboardPublishesFreshBoundBytesOnly root Tests/RepoPromptTests/AgentMode/AgentContextExportResolverTests.swift RepoPromptTests.AgentContextExportResolverTests testRevokedCodemapClipboardPublishesFreshBoundBytesOnly AgentMode/ContextExport agent_context.codemap.revoked_clipboard_fresh_bytes revocation,clipboard,bound_bytes integration_contract root_swiftpm routine 1 ReviewGitRepositoryFixture Clipboard publication after revocation contains only fresh bytes from the current bound source. Clipboard export could leak revoked or logical-root bytes after authority changes. 0.100000 filesystem,concurrency test_case retain 0 Inherited live-ID ledger drift reconciled during Item 3 authoritative verify-ledger pass root/RepoPromptTests.AgentControlToolCardPresentationTests/testReasoningEffortFallsBackToArgsWhenResultAgentObjectOmitsIt root Tests/RepoPromptTests/AgentMode/ToolCards/AgentControlToolCardPresentationTests.swift RepoPromptTests.AgentControlToolCardPresentationTests testReasoningEffortFallsBackToArgsWhenResultAgentObjectOmitsIt AgentMode agent_tool_card.reasoning_effort.args_fallback args_fallback,reasoning_effort,xhigh presentation_unit root_swiftpm routine 1 When the result agent omits reasoning_effort, the card uses the agent_run argument and presents the canonical XHigh badge without duplicate subtitle text. Sub-agent cards could omit the selected effort when a compact result relies on persisted invocation arguments. 0.000000 test_case retain 0 PR #462 reviewed reasoning-effort badge fallback contract. root/RepoPromptTests.AgentControlToolCardPresentationTests/testRecognizedReasoningEffortBadgeNormalizesXHighAndMax root Tests/RepoPromptTests/AgentMode/ToolCards/AgentControlToolCardPresentationTests.swift RepoPromptTests.AgentControlToolCardPresentationTests testRecognizedReasoningEffortBadgeNormalizesXHighAndMax AgentMode agent_tool_card.reasoning_effort.canonical_labels xhigh,max,display_name presentation_unit root_swiftpm routine 2 Known xhigh and max raw effort values render the canonical XHigh and Max badge labels. Reasoning badges could expose inconsistent raw tokens and obscure the selected high-cost effort. 0.000000 test_case retain 0 PR #462 reviewed canonical effort-label coverage across two values. root/RepoPromptTests.AgentControlToolCardPresentationTests/testUltraReasoningEffortBuildsBadgeAndIsNotDuplicatedInSubtitle root Tests/RepoPromptTests/AgentMode/ToolCards/AgentControlToolCardPresentationTests.swift RepoPromptTests.AgentControlToolCardPresentationTests testUltraReasoningEffortBuildsBadgeAndIsNotDuplicatedInSubtitle AgentMode agent_tool_card.reasoning_effort.ultra_badge ultra,badge,subtitle_deduplication presentation_unit root_swiftpm routine 1 An Ultra sub-agent result produces a visible Ultra badge while retaining the model ID and omitting duplicate raw reasoning text from the subtitle. Ultra runs could appear undisclosed or render duplicated effort text in the agent tool card. 0.000000 test_case retain 0 PR #462 reviewed Ultra tool-card presentation contract. @@ -109,7 +107,6 @@ root/RepoPromptTests.AgentConversationReplaySerializationTests/testEquivalentMod root/RepoPromptTests.AgentConversationReplaySerializationTests/testEquivalentModeMatchesLegacyBytesAndCategoryMetrics root Tests/RepoPromptTests/AgentMode/Transcript/AgentConversationReplaySerializationTests.swift RepoPromptTests.AgentConversationReplaySerializationTests testEquivalentModeMatchesLegacyBytesAndCategoryMetrics AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.AgentConversationReplaySerializationTests/testEquivalentModePreservesCustomRenderedUserTextExactly root Tests/RepoPromptTests/AgentMode/Transcript/AgentConversationReplaySerializationTests.swift RepoPromptTests.AgentConversationReplaySerializationTests testEquivalentModePreservesCustomRenderedUserTextExactly AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 80 root/RepoPromptTests.AgentConversationReplaySerializationTests/testEquivalentModeRetainsCompactedPrefixAuthority root Tests/RepoPromptTests/AgentMode/Transcript/AgentConversationReplaySerializationTests.swift RepoPromptTests.AgentConversationReplaySerializationTests testEquivalentModeRetainsCompactedPrefixAuthority AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.018500 unreviewed retain_pending_review 0 initial census source line 99 -root/RepoPromptTests.AgentExecutionLocationPickerLayoutTests/testPickerRegionKeepsStableOuterSizeAcrossLoadingPopulatedEmptyAndError root Tests/RepoPromptTests/AgentMode/AgentExecutionLocationPickerLayoutTests.swift RepoPromptTests.AgentExecutionLocationPickerLayoutTests testPickerRegionKeepsStableOuterSizeAcrossLoadingPopulatedEmptyAndError AgentMode/UI agent_execution_location.popover.stable_picker_region loading,populated,empty,error,popover_layout ui_layout_invariant root_swiftpm routine 4 NSHostingView fitting size stays at the bounded picker-region width and height for loading, populated, empty, and error content. Async worktree results could resize an open NSPopover and trigger the REPOPROMPT-3J AppKit window-frame crash path. appkit,swiftui XCTest process retain 0 Sentry REPOPROMPT-3J candidate mitigation regression root/RepoPromptTests.AgentExecutionWorktreeSelectionTests/testDedupePrefersNonPrunableForDuplicateWorktreeID root Tests/RepoPromptTests/AgentMode/AgentExecutionWorktreeSelectionTests.swift RepoPromptTests.AgentExecutionWorktreeSelectionTests testDedupePrefersNonPrunableForDuplicateWorktreeID AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.AgentExecutionWorktreeSelectionTests/testDedupeUsesNormalizedPathAsSecondGuard root Tests/RepoPromptTests/AgentMode/AgentExecutionWorktreeSelectionTests.swift RepoPromptTests.AgentExecutionWorktreeSelectionTests testDedupeUsesNormalizedPathAsSecondGuard AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 16 root/RepoPromptTests.AgentExecutionWorktreeSelectionTests/testVisuallySimilarDifferentWorktreesRemainDistinct root Tests/RepoPromptTests/AgentMode/AgentExecutionWorktreeSelectionTests.swift RepoPromptTests.AgentExecutionWorktreeSelectionTests testVisuallySimilarDifferentWorktreesRemainDistinct AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 26 @@ -137,8 +134,6 @@ root/RepoPromptTests.AgentLifecycleExecutionContractTests/testAgentExploreStartU root/RepoPromptTests.AgentLifecycleExecutionContractTests/testAgentRunStartWaitAndSteerPreserveLongerCallerTimeouts root Tests/RepoPromptTests/MCP/Control/AgentLifecycleExecutionContractTests.swift RepoPromptTests.AgentLifecycleExecutionContractTests testAgentRunStartWaitAndSteerPreserveLongerCallerTimeouts MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 17 root/RepoPromptTests.AgentLifecycleExecutionContractTests/testAgentRunStartWaitAndSteerRejectOversizedTimeouts root Tests/RepoPromptTests/MCP/Control/AgentLifecycleExecutionContractTests.swift RepoPromptTests.AgentLifecycleExecutionContractTests testAgentRunStartWaitAndSteerRejectOversizedTimeouts MCP mcp.agent_run.timeout_bounds agent_run,timeout,overflow_guard,start_wait_steer deterministic_regression root_swiftpm routine 2 Start, wait, and steer accept the 86400 second max and reject int/double/string values above it with an invalid-params message. Oversized external timeouts could overflow duration conversion or bypass the user-visible bound. 0.001000 value_parsing test_case retain 0 oversized external agent_run timeout overflow regression root/RepoPromptTests.AgentLifecycleExecutionContractTests/testAgentRunStartWaitAndSteerUseTwoMinuteDefault root Tests/RepoPromptTests/MCP/Control/AgentLifecycleExecutionContractTests.swift RepoPromptTests.AgentLifecycleExecutionContractTests testAgentRunStartWaitAndSteerUseTwoMinuteDefault MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 9 -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testCleanupSessionsIncludesPersistedProviderCleanupOutcome root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testCleanupSessionsIncludesPersistedProviderCleanupOutcome MCP/Agent agent_manage.cleanup_sessions.persisted_provider_cleanup_outcome cleanup_sessions,provider_cleanup,persisted_session,response_outcome main_actor_persistence_integration root_swiftpm routine 1 Cleanup deletes the persisted Codex session, invokes archive once with its stored conversation metadata, and returns the succeeded provider_cleanup status and message. MCP cleanup could delete local session state without cleaning the provider conversation or reporting the provider-side outcome. filesystem,window_state,actor WindowStatesManager,AgentSessionDataService test_case retain 0 PR #315/#316 reviewed persisted provider-conversation cleanup outcome contract. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testCleanupSessionsReportsUnsupportedProviderCleanupForNonCodexPersistedSession root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testCleanupSessionsReportsUnsupportedProviderCleanupForNonCodexPersistedSession MCP/Agent agent_manage.cleanup_sessions.unsupported_non_codex_provider_outcome cleanup_sessions,provider_cleanup,unsupported_provider,no_codex_fallback main_actor_persistence_integration root_swiftpm routine 1 Cleanup deletes the persisted OpenCode session, reports the exact unsupported provider_cleanup result, and never invokes the Codex cleaner. Non-Codex cleanup metadata could be misrouted to Codex or omitted from the MCP cleanup response. filesystem,window_state,actor WindowStatesManager,AgentSessionDataService test_case retain 0 PR #315/#316 reviewed unsupported non-Codex provider cleanup reporting contract. root/RepoPromptTests.AgentManageMCPToolServiceResumeTests/testResumeOfControlledSessionPreservesWaitOwnershipAcrossSteering root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceResumeTests.swift RepoPromptTests.AgentManageMCPToolServiceResumeTests testResumeOfControlledSessionPreservesWaitOwnershipAcrossSteering MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 7.238500 unreviewed retain_pending_review 0 initial census source line 8 root/RepoPromptTests.AgentModeChatSwitchActivationTests/testBackToBackWarmSwitchesPublishLatestDestination root Tests/RepoPromptTests/AgentMode/AgentModeChatSwitchActivationTests.swift RepoPromptTests.AgentModeChatSwitchActivationTests testBackToBackWarmSwitchesPublishLatestDestination AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.065500 unreviewed retain_pending_review 0 initial census source line 101 root/RepoPromptTests.AgentModeChatSwitchActivationTests/testHandoffRebindsComposerAndRejectsStaleSourceSubmitTarget root Tests/RepoPromptTests/AgentMode/AgentModeChatSwitchActivationTests.swift RepoPromptTests.AgentModeChatSwitchActivationTests testHandoffRebindsComposerAndRejectsStaleSourceSubmitTarget AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.064000 unreviewed retain_pending_review 0 initial census source line 7 @@ -159,13 +154,6 @@ root/RepoPromptTests.AgentModeMCPWaitEpochTests/testScopedInactiveSteeringCreate root/RepoPromptTests.AgentModeMCPWaitEpochTests/testScopedSteeringWithNilCurrentEpochCreatesSteeringEpoch root Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift RepoPromptTests.AgentModeMCPWaitEpochTests testScopedSteeringWithNilCurrentEpochCreatesSteeringEpoch AgentMode agent_run.steer.nil_epoch_classification steering,epoch,current_epoch_nil state_machine_regression root_swiftpm routine 1 Scoped steering transition on a reactivated nil-currentEpoch MCP context creates ordinal 1 with transitionKind=steering while preserving user-owned origin. Reactivated completed sessions could classify the first follow-up as initial and make waits treat steering as a fresh unrelated launch. in_process;agent_run_store AgentRunSessionStore test_case retain 0 Item 2 steer reactivation epoch classification regression root/RepoPromptTests.AgentModeMCPWaitEpochTests/testStaleTranscriptDoesNotOverrideAuthoritativeSourceWithoutAssistantTail root Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift RepoPromptTests.AgentModeMCPWaitEpochTests testStaleTranscriptDoesNotOverrideAuthoritativeSourceWithoutAssistantTail AgentMode agent_mode.terminal_publication_and_wait terminal_publication,wait_epoch,assistant_tail lifecycle_regression root_swiftpm routine 1 Terminal publication, wait replay, and assistant-tail state match the asserted lifecycle outcome. Agent waits could publish stale transcripts, lose terminal snapshots, or violate PR #299 tail ordering. 0.005000 test_case retain 0 Authoritative test-list reconciliation for the current integration worktree. root/RepoPromptTests.AgentModeMCPWaitEpochTests/testTerminalPublicationDuringEpochBeginContextGapDoesNotLoseSessionWait root Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift RepoPromptTests.AgentModeMCPWaitEpochTests testTerminalPublicationDuringEpochBeginContextGapDoesNotLoseSessionWait AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.003000 unreviewed retain_pending_review 0 initial census source line 7 -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testDeleteSessionCleansLiveProviderConversationOnce root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testDeleteSessionCleansLiveProviderConversationOnce AgentMode agent_mode.provider_conversation_cleanup.live_session_delete_once provider_cleanup,live_session,delete_session,exactly_once main_actor_service_integration root_swiftpm routine 1 Deleting a bound live Codex session returns the controller outcome and invokes archive exactly once with the explicit cleanup handle. Session deletion could skip provider cleanup or invoke it repeatedly, causing leaked or duplicated provider-side mutation. test_case retain 0 PR #315/#316 reviewed live session deletion cleanup contract. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testLiveCodexCleanupInvokesControllerAndReportsOutcome root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testLiveCodexCleanupInvokesControllerAndReportsOutcome AgentMode agent_mode.provider_conversation_cleanup.live_codex_controller_routing provider_cleanup,live_codex,explicit_handle,outcome main_actor_service_integration root_swiftpm routine 1 Live Codex cleanup returns the controller outcome and passes the explicit conversation ID, rollout path, and archive action in one call. Live cleanup could use stale legacy metadata, choose the wrong action, or lose the provider outcome. test_case retain 0 PR #315/#316 reviewed live Codex cleanup routing contract. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testPersistedCodexCleanupPrefersStoredGenericHandle root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testPersistedCodexCleanupPrefersStoredGenericHandle AgentMode agent_mode.provider_conversation_cleanup.persisted_generic_handle_precedence provider_cleanup,persisted_session,explicit_handle,legacy_metadata,precedence main_actor_service_integration root_swiftpm routine 1 Persisted Codex cleanup invokes archive once using the canonical stored generic handle instead of conflicting legacy Codex fields. Fallback metadata could override the authoritative handle and clean up the wrong provider conversation. test_case retain 0 PR #315/#316 reviewed persisted cleanup-handle precedence contract. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testPersistedCodexCleanupUsesStoredConversationMetadata root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testPersistedCodexCleanupUsesStoredConversationMetadata AgentMode agent_mode.provider_conversation_cleanup.persisted_codex_metadata_fallback provider_cleanup,persisted_session,codex_metadata,archive main_actor_service_integration root_swiftpm routine 1 Persisted Codex cleanup derives the conversation ID and rollout path from stored legacy metadata and invokes archive exactly once. Persisted sessions without a generic handle could leak provider conversations because legacy Codex metadata is ignored. test_case retain 0 PR #315/#316 reviewed persisted Codex metadata cleanup contract. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testPersistedUnsupportedProviderReportsUnsupportedAndSkipsCodexCleaner root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testPersistedUnsupportedProviderReportsUnsupportedAndSkipsCodexCleaner AgentMode agent_mode.provider_conversation_cleanup.persisted_unsupported_provider provider_cleanup,persisted_session,open_code,unsupported,no_codex_fallback main_actor_service_integration root_swiftpm routine 1 Persisted OpenCode cleanup returns the exact unsupported result and records no Codex cleaner invocation. Unsupported provider metadata could be silently ignored or incorrectly routed through the Codex cleanup implementation. test_case retain 0 PR #315/#316 reviewed persisted unsupported-provider cleanup contract. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testProviderCleanupRegistryReportsUnsupportedForNonCodexProviders root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testProviderCleanupRegistryReportsUnsupportedForNonCodexProviders AgentMode agent_mode.provider_conversation_cleanup.registry_non_codex_unsupported_matrix provider_cleanup,registry,claude,open_code,cursor,unknown_provider routing_policy_matrix root_swiftpm routine 4 The registry returns provider-specific unsupported messages for Claude, OpenCode, Cursor, and unknown providers while never calling the Codex cleaner. Registry drift could misroute any non-Codex provider or conceal why cleanup is unsupported. test_case retain 0 PR #315/#316 reviewed four-case non-Codex cleanup registry matrix. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testProviderCleanupRegistryRoutesCodexToCodexCleaner root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testProviderCleanupRegistryRoutesCodexToCodexCleaner AgentMode agent_mode.provider_conversation_cleanup.registry_codex_route provider_cleanup,registry,codex,archive,routing routing_policy_regression root_swiftpm routine 1 The registry returns the Codex cleaner outcome and forwards the exact handle and archive action in one invocation. Codex cleanup could be rejected as unsupported or routed with altered metadata or action. test_case retain 0 PR #315/#316 reviewed Codex cleanup registry routing contract. root/RepoPromptTests.AgentModeRunServiceLifecycleTests/testCancelRunCleansClaudeAndACPProvidersAfterCommonMCPToolCancellation root Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift RepoPromptTests.AgentModeRunServiceLifecycleTests testCancelRunCleansClaudeAndACPProvidersAfterCommonMCPToolCancellation AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.192000 unreviewed retain_pending_review 0 initial census source line 1152 root/RepoPromptTests.AgentModeRunServiceLifecycleTests/testCancelRunInterruptsCapturedSessionOwnedCodexTurnByExactID root Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift RepoPromptTests.AgentModeRunServiceLifecycleTests testCancelRunInterruptsCapturedSessionOwnedCodexTurnByExactID AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 1260 root/RepoPromptTests.AgentModeRunServiceLifecycleTests/testCancellationCanAwaitTrackedTerminalTeardownCompletion root Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift RepoPromptTests.AgentModeRunServiceLifecycleTests testCancellationCanAwaitTrackedTerminalTeardownCompletion AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.004000 unreviewed retain_pending_review 0 initial census source line 1026 @@ -268,7 +256,6 @@ root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testIncrementalRefre root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testLiveToolResultRefreshUsesIncrementalRetentionCompaction root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testLiveToolResultRefreshUsesIncrementalRetentionCompaction AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.057500 unreviewed retain_pending_review 0 initial census source line 55 root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testLocalRemovalTombstoneWinsOverLaterFullBatch root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testLocalRemovalTombstoneWinsOverLaterFullBatch AgentMode/SidebarIndex agent.sidebar_index.local_removal_tombstone late_batch_rejection;deletion_authority async_state_machine root_swiftpm routine 1 A local session-index removal remains absent when a later full batch still contains the removed session high 0.047500 test_case retain 0 Item 1 ledger reconciliation required by Item 2 validation root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testMCPActivationRejectsReservedBindingTransition root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testMCPActivationRejectsReservedBindingTransition AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.007500 unreviewed retain_pending_review 0 initial census source line 653 -root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testNestedSidebarThreadsDefaultCollapseAndPreserveSearchActiveAndExpandAll root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testNestedSidebarThreadsDefaultCollapseAndPreserveSearchActiveAndExpandAll AgentMode/SidebarIndex agent.sidebar_threads.default_collapse_visibility_controls nested_threads,default_collapse,active_path,search,expand_all,collapse_all main_actor_view_model_integration root_swiftpm routine 5 Nested sidebar rows default-collapse eligible parents, reveal the active descendant path, reveal search matches, expand all, and collapse all with exact row and state snapshots. Thread collapsing could hide the active or searched session, forget seeded state, or make expand/collapse-all controls inconsistent. test_case retain 0 PR #315/#316 reviewed five-scenario nested sidebar collapse and visibility contract. root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testPersistentBindingMoveIsBlockedByRunOwnershipAndStoreRegistration root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testPersistentBindingMoveIsBlockedByRunOwnershipAndStoreRegistration AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.012500 unreviewed retain_pending_review 0 initial census source line 626 root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testPersistentBindingSameIDIsIdempotentAndSameTabRebindRotatesGeneration root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testPersistentBindingSameIDIsIdempotentAndSameTabRebindRotatesGeneration AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.024000 unreviewed retain_pending_review 0 initial census source line 582 root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testRefreshingInactiveSessionDoesNotClobberActivePresentation root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testRefreshingInactiveSessionDoesNotClobberActivePresentation AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.048500 unreviewed retain_pending_review 0 initial census source line 184 @@ -316,6 +303,7 @@ root/RepoPromptTests.AgentPermissionSecureStoreTests/testSubagentReadFailureFail root/RepoPromptTests.AgentPermissionSecureStoreTests/testSuccessfulResetPersistsProductDefaultsAcrossRelaunch root Tests/RepoPromptTests/Security/AgentPermissionSecureStoreTests.swift RepoPromptTests.AgentPermissionSecureStoreTests testSuccessfulResetPersistsProductDefaultsAcrossRelaunch Security unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 139 root/RepoPromptTests.AgentPermissionSecureStoreTests/testUnsupportedFuturePlainSchemaFailsClosed root Tests/RepoPromptTests/Security/AgentPermissionSecureStoreTests.swift RepoPromptTests.AgentPermissionSecureStoreTests testUnsupportedFuturePlainSchemaFailsClosed Security unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 225 root/RepoPromptTests.AgentPermissionSecureStoreTests/testUpdateWriteFailureForcesEffectiveCacheFailClosed root Tests/RepoPromptTests/Security/AgentPermissionSecureStoreTests.swift RepoPromptTests.AgentPermissionSecureStoreTests testUpdateWriteFailureForcesEffectiveCacheFailClosed Security unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 303 +root/RepoPromptTests.AgentProviderContextBuilderTests/testAgentModeOverCapHandoffUsesBorrowedPresentationWithoutSecondDemandOrFreeze root Tests/RepoPromptTests/AgentMode/AgentProviderContextBuilderTests.swift RepoPromptTests.AgentProviderContextBuilderTests testAgentModeOverCapHandoffUsesBorrowedPresentationWithoutSecondDemandOrFreeze AgentMode agent_handoff.over_cap_borrowed_presentation production_closure,immutable_presentation,no_second_demand,no_second_freeze integration_regression root_swiftpm routine 1 AgentModeWindowHandoffFixture The production AgentModeViewModel over-cap closure emits a selection summary while demand and presentation-freeze counters remain unchanged during borrowed-presentation rendering. Over-cap Agent handoffs could refreeze or redemand codemaps, producing inconsistent output and duplicate work. 11.606000 temporary_git_repository,actor_store,window_composition global_settings,window_registry test_method+tearDown retain 0 Headless closure P1 regression for immutable operation-presentation reuse root/RepoPromptTests.AgentProviderContextBuilderTests/testForkCodemapCapIncludesRenderedHeaderImportsAndFreezesFallbackBundle root Tests/RepoPromptTests/AgentMode/AgentProviderContextBuilderTests.swift RepoPromptTests.AgentProviderContextBuilderTests testForkCodemapCapIncludesRenderedHeaderImportsAndFreezesFallbackBundle AgentMode agent_handoff.fork_codemap_exact_cap_and_snapshot rendered_header,imports,logical_path,exact_boundary,frozen_fallback deterministic_regression root_swiftpm routine 2 AgentProviderForkCodemapCapFixture A codemap renders at the exact token cap, falls back one token below it, and the fallback receives the original bundle even after the store snapshot is removed. Fork handoffs could omit path/import tokens from the cap or refetch codemaps after the cap decision. 0.018500 temporary_root,actor_store,worktree_projection,codemap_cache actor_store test_method+tearDownWithError retain 0 Blocking review regression for complete emitted codemap accounting and frozen fallback metadata root/RepoPromptTests.AgentProviderContextBuilderTests/testForkFileContentsBlockIncludesCanonicalWorktreeCodemapExactlyOnce root Tests/RepoPromptTests/AgentMode/AgentProviderContextBuilderTests.swift RepoPromptTests.AgentProviderContextBuilderTests testForkFileContentsBlockIncludesCanonicalWorktreeCodemapExactlyOnce AgentMode agent_handoff.canonical_codemap_packaging canonical_selection,missing_snapshot,worktree_projection,single_emission provider_context_packaging_integration root_swiftpm routine 2 AgentProviderCanonicalWorktreeCodemapFixture Agent handoff suppresses unavailable canonical codemap content, then emits the available worktree codemap exactly once in file-map context while preserving selected content and logical paths. Handoff accounting could count canonical codemaps but silently omit them, bypass the token cap with fallback full content, leak physical worktree paths, or duplicate rendered APIs. 0.020500 temporary_root,actor_store,worktree_projection,codemap_cache test_method+tearDownWithError retain 0 Focused Agent handoff canonical codemap packaging regression root/RepoPromptTests.AgentProviderContextBuilderTests/testForkFileContentsBlockReadsWorktreeContentAndDisplaysLogicalPath root Tests/RepoPromptTests/AgentMode/AgentProviderContextBuilderTests.swift RepoPromptTests.AgentProviderContextBuilderTests testForkFileContentsBlockReadsWorktreeContentAndDisplaysLogicalPath AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.093000 unreviewed retain_pending_review 0 initial census source line 30 @@ -336,9 +324,6 @@ root/RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests/testInheritedRestri root/RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests/testSubagentPolicyStorageFailureUsesCodexSafeManagedSnapshot root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceStartDefaultTests.swift RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests testSubagentPolicyStorageFailureUsesCodexSafeManagedSnapshot MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 138 root/RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests/testUntargetedStartWithoutModelIDResolvesThroughPairDefault root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceStartDefaultTests.swift RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests testUntargetedStartWithoutModelIDResolvesThroughPairDefault MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests/testWorkflowDefaultDoesNotOverridePairForUntargetedStart root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceStartDefaultTests.swift RepoPromptTests.AgentRunMCPToolServiceStartDefaultTests testWorkflowDefaultDoesNotOverridePairForUntargetedStart MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 173 -root/RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests/testApprovalRespondInvalidResponseErrorsNameResponseAcrossLiveVariants root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceRespondDiagnosticsTests.swift RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests testApprovalRespondInvalidResponseErrorsNameResponseAcrossLiveVariants MCP/AgentRun agent_run.respond.approval_invalid_response_diagnostics respond,approval,response_token,worktree_merge,permissions,provider_approval protocol_negative_matrix root_swiftpm routine 4 ControlledApprovalSessionFixture Invalid scalar responses return exact canonical response option lists for all four live approval variants and preserve the pending request. Variant-specific diagnostics could advertise the wrong public field or unsupported options. 0.758000 mcp_tool_service;in_process;window_state AgentRunSessionStore;WindowStatesManager;GlobalSettingsStore test_case retain 0 Canonical approval diagnostics across live variants. -root/RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests/testApprovalRespondRejectsNoncanonicalResponseArgumentsWithoutMutation root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceRespondDiagnosticsTests.swift RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests testApprovalRespondRejectsNoncanonicalResponseArgumentsWithoutMutation MCP/AgentRun agent_run.respond.approval_canonical_response_argument respond,approval,response_field,decision_rejection,nested_shape,no_mutation protocol_negative_matrix root_swiftpm routine 4 ControlledApprovalSessionFixture Missing, decision-only, nested, and conflicting approval payloads return exact invalid-params errors and leave the pending approval unchanged. Malformed requests could apply an unintended approval or establish an unsupported compatibility shape. 0.758000 mcp_tool_service;in_process;window_state AgentRunSessionStore;WindowStatesManager;GlobalSettingsStore test_case retain 0 Canonical scalar response boundary. -root/RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests/testApprovalRespondWithStaleInteractionIDReportsCurrentSafeIdentityWithoutMutation root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceRespondDiagnosticsTests.swift RepoPromptTests.AgentRunMCPToolServiceRespondDiagnosticsTests testApprovalRespondWithStaleInteractionIDReportsCurrentSafeIdentityWithoutMutation MCP/AgentRun agent_run.respond.stale_interaction_identity respond,interaction_id,stale_identity,privacy,no_mutation,poll_wait_recovery state_machine_regression root_swiftpm routine 5 ControlledApprovalSessionFixture A stale response reports only submitted/current identity and poll/wait recovery while preserving the current approval and excluding private sentinels. An out-of-order response could target a replacement interaction or leak approval contents. 0.758000 mcp_tool_service;in_process;window_state AgentRunSessionStore;WindowStatesManager;GlobalSettingsStore test_case retain 0 Fail-closed live MainActor identity authority. root/RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests/testSteerActiveUncontrolledSessionIsRejected root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceSteerResumeTests.swift RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests testSteerActiveUncontrolledSessionIsRejected MCP/AgentRun agent_run.steer.reject_active_uncontrolled_session steer,resume,reactivation_guard protocol_negative root_swiftpm routine 1 Active non-controlled sessions are rejected before dispatch, leave control context nil, and create no AgentRunSessionStore registration. Steer could adopt or race an active user-owned session outside the MCP control handle. mcp_tool_service;in_process AgentRunSessionStore;WindowStatesManager test_case retain 0 Item 2 steer reactivation regression root/RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests/testSteerCompletedUserOwnedSessionWithoutControlContextReactivatesAndStartsFollowUp root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceSteerResumeTests.swift RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests testSteerCompletedUserOwnedSessionWithoutControlContextReactivatesAndStartsFollowUp MCP/AgentRun agent_run.steer.reactivate_completed_user_owned_session steer,resume,user_owned_origin,epoch state_machine_regression root_swiftpm routine 1 Steer reactivates an existing completed user-owned session without flipping isMCPOriginated, dispatches the follow-up, and records a steering epoch. Completed sessions with expired control handles could fail to resume or be converted into MCP-originated sessions. mcp_tool_service;in_process AgentRunSessionStore;WindowStatesManager test_case retain 0 Item 2 steer reactivation regression root/RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests/testSteerReactivationDispatchFailureCleansControlContext root Tests/RepoPromptTests/MCP/AgentRunMCPToolServiceSteerResumeTests.swift RepoPromptTests.AgentRunMCPToolServiceSteerResumeTests testSteerReactivationDispatchFailureCleansControlContext MCP/AgentRun agent_run.steer.reactivation_dispatch_failure_cleanup steer,resume,cleanup,registration failure_cleanup root_swiftpm routine 1 Synthetic dispatch failure after steer reactivation clears follow-up pending state, deactivates control, and removes the AgentRunSessionStore registration. Failed steer reactivation could strand a stale MCP control context or active wait registration. mcp_tool_service;in_process AgentRunSessionStore;WindowStatesManager test_case retain 0 Item 2 steer reactivation regression @@ -379,9 +364,6 @@ root/RepoPromptTests.AgentRunSessionStoreRegistrationTests/testStaleTerminalExpi root/RepoPromptTests.AgentRunSessionStoreRegistrationTests/testTerminalPublicationAndRelatedSuccessorAreAtomicAndIdempotent root Tests/RepoPromptTests/MCP/AgentRunSessionStoreRegistrationTests.swift RepoPromptTests.AgentRunSessionStoreRegistrationTests testTerminalPublicationAndRelatedSuccessorAreAtomicAndIdempotent MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 69 root/RepoPromptTests.AgentRunSessionStoreRegistrationTests/testUnexpectedCurrentEpochTerminalRejectionWakesMatchingWaiter root Tests/RepoPromptTests/MCP/AgentRunSessionStoreRegistrationTests.swift RepoPromptTests.AgentRunSessionStoreRegistrationTests testUnexpectedCurrentEpochTerminalRejectionWakesMatchingWaiter MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 403 root/RepoPromptTests.AgentRunWaitDrainIntegrationTests/testRealParentWaitScopeDrainInterruptsOnceAndAllowsCleanRewait root Tests/RepoPromptTests/MCP/AgentRunWaitDrainIntegrationTests.swift RepoPromptTests.AgentRunWaitDrainIntegrationTests testRealParentWaitScopeDrainInterruptsOnceAndAllowsCleanRewait MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.085500 unreviewed retain_pending_review 0 initial census source line 8 -root/RepoPromptTests.AgentRunWaitDrainIntegrationTests/testStaleACPDispatchPreservesWaitSteeringMessageAfterWakeSuspension root Tests/RepoPromptTests/MCP/AgentRunWaitDrainIntegrationTests.swift RepoPromptTests.AgentRunWaitDrainIntegrationTests testStaleACPDispatchPreservesWaitSteeringMessageAfterWakeSuspension MCP agent.wait.stale_acp_dispatch_preserves_steering stale_origin,acp_dispatch,wake_suspension,run_identity_rotation,steering_message concurrency_regression root_swiftpm routine 1 AgentRunWaitDrainTestHarness,AgentRunWaiterWakeBarrier After an ACP interrupt wake is suspended and the originating run identity becomes stale, the dispatch does not claim the successor session and the interrupted wait returns the exact steering message. A stale ACP dispatch could consume or discard steering intended for the blocked parent wait, or incorrectly claim a successor run. concurrency;window_state;in_process_mcp GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunSessionStore test_harness_cleanup+task_cancellation+registration_and_window_teardown retain 0 PR #669 ledger reconciliation; one stale ACP dispatch lifecycle. -root/RepoPromptTests.AgentRunWaitDrainIntegrationTests/testStaleClaudeDispatchPreservesWaitSteeringMessageAfterWakeSuspension root Tests/RepoPromptTests/MCP/AgentRunWaitDrainIntegrationTests.swift RepoPromptTests.AgentRunWaitDrainIntegrationTests testStaleClaudeDispatchPreservesWaitSteeringMessageAfterWakeSuspension MCP agent.wait.stale_claude_dispatch_preserves_steering stale_origin,claude_dispatch,wake_suspension,run_identity_rotation,steering_message concurrency_regression root_swiftpm routine 1 AgentRunWaitDrainTestHarness,AgentRunWaiterWakeBarrier After a Claude interrupt wake is suspended and the originating run identity becomes stale, the dispatch does not claim the successor session and the interrupted wait returns the exact steering message. A stale Claude dispatch could consume or discard steering intended for the blocked parent wait, or incorrectly claim a successor run. concurrency;window_state;in_process_mcp GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunSessionStore test_harness_cleanup+task_cancellation+registration_and_window_teardown retain 0 PR #669 ledger reconciliation; one stale Claude dispatch lifecycle. -root/RepoPromptTests.AgentRunWaitDrainIntegrationTests/testStaleManualSubmitPreservesWaitSteeringMessageAfterWakeSuspension root Tests/RepoPromptTests/MCP/AgentRunWaitDrainIntegrationTests.swift RepoPromptTests.AgentRunWaitDrainIntegrationTests testStaleManualSubmitPreservesWaitSteeringMessageAfterWakeSuspension MCP agent.wait.stale_manual_submit_preserves_steering stale_origin,manual_submit,wake_suspension,run_identity_rotation,steering_message concurrency_regression root_swiftpm routine 1 AgentRunWaitDrainTestHarness,AgentRunWaiterWakeBarrier A submitted manual steering turn whose wake is suspended before run-identity rotation still interrupts the blocked wait with the exact original steering message. A stale manual-submission origin could lose steering text after waking the waiter, leaving the parent unable to act on the interruption. concurrency;window_state;in_process_mcp GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunSessionStore test_harness_cleanup+task_cancellation+registration_and_window_teardown retain 0 PR #669 ledger reconciliation; one stale manual-submit lifecycle. root/RepoPromptTests.AgentRunWorktreeStartTests/testActiveStartedThreadRequiresConfirmationAndNeverCommitsStaleIdentityMidSwitch root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testActiveStartedThreadRequiresConfirmationAndNeverCommitsStaleIdentityMidSwitch MCP unreviewed unreviewed root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture unreviewed unreviewed 0.007500 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain_pending_review 0 initial census source line 679 root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentExploreBatchCreatePreparesDistinctWorktreesBeforeProviderStart root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentExploreBatchCreatePreparesDistinctWorktreesBeforeProviderStart MCP unreviewed unreviewed root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture unreviewed unreviewed 6.074000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain_pending_review 0 initial census source line 980 root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentExploreBatchCreateRejectsSharedPathAndBranchBeforeTargetCreation root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentExploreBatchCreateRejectsSharedPathAndBranchBeforeTargetCreation MCP unreviewed unreviewed root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture unreviewed unreviewed 0.117000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain_pending_review 0 initial census source line 1113 @@ -399,22 +381,10 @@ root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentRunStartTreatsRoutedPar root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentRunStartInheritsRoutedWorktreeFromUIParentWithoutMCPControlContext root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentRunStartInheritsRoutedWorktreeFromUIParentWithoutMCPControlContext MCP agent.start.worktree-inheritance.ui_parent_nil_control_context routed_source,ui_parent,nil_control_context,default_inheritance,effective_path behavioral_regression root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture A routed child start from a UI-originated hydrated parent with persisted worktree bindings and no MCP control context inherits the binding in the start response and effective workspace path. UI-launched worktree-bound parent sessions could be rejected during routed child-start reconciliation because only MCP-controlled parents were accepted. 0.616000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Issue #383 routed worktree inheritance regression for UI-launched parents. root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentRunStartInheritsRoutedWorktreeFromFormerMCPParentWithoutControlContext root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentRunStartInheritsRoutedWorktreeFromFormerMCPParentWithoutControlContext MCP agent.start.worktree-inheritance.former_mcp_parent routed_source,sticky_mcp_origin,nil_control_context,default_inheritance,effective_path behavioral_regression root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture A routed child start from a hydrated parent with persisted worktree bindings, sticky isMCPOriginated=true, and no live MCP control context inherits the binding in the start response and effective workspace path. A former MCP-created parent later driven from the UI could permanently fail inherited child starts with an unavailable-control-context error despite valid persisted bindings. 0.750000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Issue #383 QA follow-up regression for sticky MCP-origin sessions after control context release. root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentStartExplicitWorktreeIDOverridesInheritedBindingAcrossRunExploreAndExplicitTab root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentStartExplicitWorktreeIDOverridesInheritedBindingAcrossRunExploreAndExplicitTab MCP agent.start.explicit-worktree-override existing_worktree_id,created_worktree,inherit_true,inherit_false,explore,explicit_tab behavioral_regression root_swiftpm routine 5 AgentRunWorktreeStartLifecycleFixture Explicit existing-worktree and app-created Agent Run routes contain only the requested binding regardless of inherit_worktree, Explore preserves its explicit binding, explicit-tab routing also suppresses the captured parent binding without creating a parent relationship, and spawned children retain their expected parent relationships. Automatic or frozen-source inheritance could leak a parent checkout alongside or instead of an explicitly selected or created child worktree on Run, Explore, or explicit-tab routes. 3.177000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture consolidated_replacement 0 Renamed from root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentStartExplicitWorktreeIDOverridesInheritedBindingAcrossRunAndExplore; retains replacements root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentRunStartExplicitWorktreeIDOverridesInheritanceSetting and root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentExploreStartExplicitWorktreeIDOverridesInheritedBindingBeforeProviderStart; strengthened with explicit-tab override precedence. -root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentStartWorktreeSelectorRejectsSecondaryGitRepoWhenPrimaryRootIsNonGit root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentStartWorktreeSelectorRejectsSecondaryGitRepoWhenPrimaryRootIsNonGit MCP agent.start.worktree-selector.non-git-primary-rejection non_git_primary,secondary_git,worktree_id,fail_closed,no_target_mutation behavioral_regression root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture A shorthand worktree ID targeting a secondary Git repository is rejected by the primary-root runtime boundary when the declared primary workspace root is non-Git, without creating a target tab. Fallback repository resolution could pair a secondary Git checkout with the non-Git primary logical root and bypass the primary-only provider runtime restriction. suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Primary-root fail-closed regression for implicit worktree repository selection. -root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentStartWorktreeSelectorsDefaultToWorkspacePrimaryRepoWhenRootsLoadedOutOfOrder root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentStartWorktreeSelectorsDefaultToWorkspacePrimaryRepoWhenRootsLoadedOutOfOrder MCP agent.start.worktree-selector.primary-root-default multi_root,inverse_root_order,primary_workspace,symlink_alias,worktree_id,branch_selector,implicit_repo_root,explicit_repo_root,nested_primary,same_repository,parent_loaded_first,git_style_repo_root,repository_relative_binding behavioral_regression root_swiftpm routine 7 AgentRunWorktreeStartLifecycleFixture Direct and symlink-aliased declared-primary paths promote the primary root ahead of inverse discovery order; worktree ID and branch selectors bind that repository for implicit and explicit selection; and a git-style repository selector preserves a declared nested primary root loaded after its parent while projecting the repository-relative physical binding. Using file-index load order or lexical path identity could reject a valid primary-root worktree before provider startup, associate it with the wrong logical root, or collapse a nested primary root to an earlier-loaded parent from the same repository. suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Multi-root shorthand selector regression for issue #554, strengthened for PR #568 nested-primary logical-root selection. -root/RepoPromptTests.AgentRunWorktreeStartTests/testAgentStartWorktreeSelectorsRejectCrossRepositoryMatchesForImplicitAndExplicitPrimaryRoot root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testAgentStartWorktreeSelectorsRejectCrossRepositoryMatchesForImplicitAndExplicitPrimaryRoot MCP agent.start.worktree-selector.repository-authority multi_root,worktree_id,branch_selector,implicit_repo_root,explicit_repo_root,cross_repository,fail_closed,no_target_mutation behavioral_regression root_swiftpm routine 4 AgentRunWorktreeStartLifecycleFixture Worktree ID and branch selectors targeting a secondary repository are rejected for both implicit and explicit primary-root selection, leaving tab and session counts unchanged. A globally unique foreign worktree selector could resolve across workspace repositories and be persisted under the selected primary logical root. suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Existing-worktree selector repository-authority regression for issue #554. root/RepoPromptTests.AgentRunWorktreeStartTests/testBindingTransitionMaterializesSessionWorktreeWithoutCodemapWork root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testBindingTransitionMaterializesSessionWorktreeWithoutCodemapWork MCP agent.worktree.binding_transition.zero_codemap_materialization initial_binding,watcher_ownership,idempotent_materialization,zero_codemap_work,last_release_cleanup deterministic_integration root_swiftpm routine 4 AgentRunWorktreeStartLifecycleFixture Initial binding materializes one watched physical root with zero legacy scans, modern demands, freezes, or initialization tasks; repeated projection reuses the owner/root without recrawl; unbind releases the final claim. Worktree binding could eagerly start codemap work, duplicate catalog ownership, or leak the final root claim. 0.064500 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 Milestone D replaces eager session-worktree codemap initialization with neutral materialization and zero-work assertions. root/RepoPromptTests.AgentRunWorktreeStartTests/testBindingTransitionValidatesAndMaterializesChangedSecondaryBindingWithoutRestartingPrimaryIdentity root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testBindingTransitionValidatesAndMaterializesChangedSecondaryBindingWithoutRestartingPrimaryIdentity MCP agent.worktree.binding-transition.secondary behavioral_regression root_swiftpm routine 2 AgentRunWorktreeStartLifecycleFixture Unavailable secondary binding rejects atomically; valid changed secondary materializes both physical roots without restarting provider or Codex identity high 0.804500 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture consolidated_replacement 0 replaces root/RepoPromptTests.AgentRunWorktreeStartTests/testBindingTransitionMaterializesChangedSecondaryBindingWithoutRestartingUnchangedPrimaryIdentity; root/RepoPromptTests.AgentRunWorktreeStartTests/testBindingTransitionRejectsUnavailableSecondaryBindingEvenWhenPrimaryIdentityIsUnchanged root/RepoPromptTests.AgentRunWorktreeStartTests/testCanonicalAgentRunReviewSourceStagesBindsToFreshWorktreeChildAndCleansUp root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCanonicalAgentRunReviewSourceStagesBindsToFreshWorktreeChildAndCleansUp MCP agent.oracle_review.canonical_run_binding launch_snapshot,exact_run,cleanup deterministic_lifecycle_integration root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture Canonical source packaging stages for an exact fresh worktree child run with an independent target binding and disappears on control deactivation. A stale or sibling child run could consume source-owned review packaging. 0.107000 suite_owned_temp_roots;awaited_window_teardown WindowStatesManager AgentRunWorktreeStartLifecycleFixture retain 0 Issue #264 exact-ID ledger reconciliation root/RepoPromptTests.AgentRunWorktreeStartTests/testChildSessionWorktreeBindingInheritanceCanBeOptedOut root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testChildSessionWorktreeBindingInheritanceCanBeOptedOut MCP unreviewed unreviewed root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture unreviewed unreviewed 0.003000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain_pending_review 0 initial census source line 76 -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexCancellationThenSessionCloseSharesOneJoinedRetirement root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexCancellationThenSessionCloseSharesOneJoinedRetirement MCP agent.worktree.codex-cancel-close-retirement cancel_interrupt,controller_shutdown,session_close,retirement_join,exactly_once,no_process_overlap concurrency_regression root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture;CancellationRetirementFakeCodexController;AgentRunWorktreeStartAsyncGate A gated cancellation detaches its controller before interrupt suspension; an overlapping session close joins the same per-tab retirement, both calls return only after shutdown finishes, and the controller receives exactly one shutdown call. Cancel followed quickly by tab close could directly shut down the detached controller again or return before the cancellation-owned retirement completes. async_tasks GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 PR #614 regression for joined cancellation and session-close retirement. -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexCancellationRetirementBlocksSameTabReplacementButNotAnotherTab root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexCancellationRetirementBlocksSameTabReplacementButNotAnotherTab MCP agent.worktree.codex-cancel-retirement cancel_interrupt,controller_shutdown,per_tab_isolation,replacement_fence,no_process_overlap concurrency_regression root_swiftpm routine 2 AgentRunWorktreeStartLifecycleFixture;CancellationRetirementFakeCodexController;AgentRunWorktreeStartAsyncGate A gated cancellation interrupt remains ahead of controller shutdown and blocks same-tab replacement until retirement completes, while another tab creates its controller independently. Cancel/send overlap could start a replacement Codex app-server before the retiring process finishes, while window-global serialization would unnecessarily block unrelated tabs. suite_owned_temp_roots;suite_owned_immutable_git_seed;async_tasks GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 PR4 cancellation path coverage for per-tab joinable Codex controller retirement. -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexControllerFailsClosedWhenInstalledLaunchRootBecomesMalformed root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexControllerFailsClosedWhenInstalledLaunchRootBecomesMalformed MCP agent.worktree.codex-controller-resolution-failure-teardown codex_launch_execution_split,approval,follow_up,computer_use,liveness,tool_tracking,replacement_identity lifecycle_regression root_swiftpm routine 3 AgentRunWorktreeStartLifecycleFixture;ReplacementIdentityFakeCodexController An installed controller whose selected logical root becomes malformed is shut down and loses its correlated runtime state, while a stale failure that settles after a replacement is installed shuts down only the captured controller and preserves the replacement's identity, event task, interaction state, and tool tracking; matching teardown removes old tracking before awaiting shutdown so a successor tracker installed during that suspension survives. A workspace resolution failure could leave unusable controller state active, clear a newer controller that was installed while terminal failure publication suspended, or remove successor tracking after an awaited stale-controller shutdown. 0.020000 suite_owned_temp_roots;suite_owned_immutable_git_seed GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 issue #554 WI-1 fail-closed installed-controller teardown and stale-publication replacement guard and shutdown-await tracking ordering -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexControllerRetirementIsPerTabAndJoinedBeforeWorkspaceReplacement root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexControllerRetirementIsPerTabAndJoinedBeforeWorkspaceReplacement MCP agent.worktree.codex-controller-per-tab-retirement controller_shutdown,per_tab_isolation,workspace_replacement,multi_repo,no_process_overlap concurrency_regression root_swiftpm routine 2 AgentRunWorktreeStartLifecycleFixture;ReplacementIdentityFakeCodexController;AgentRunWorktreeStartAsyncGate A blocked tab-A controller shutdown prevents only tab A's replacement factory, while tab B replaces independently on another repository/worktree; both replacements receive the current execution path after their own retirement completes. Fire-and-forget shutdown could overlap old and replacement Codex app-server processes for one tab, while a window-global join would unnecessarily block unrelated tabs. suite_owned_temp_roots;suite_owned_immutable_git_seed;async_tasks GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 PR4 per-tab joinable Codex controller retirement regression. -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexControllerReplacementKeysOnExecutionChangeAndSurvivesSecondaryBindingChanges root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexControllerReplacementKeysOnExecutionChangeAndSurvivesSecondaryBindingChanges MCP agent.worktree.codex-controller-replacement-key codex_launch_execution_split lifecycle_regression root_swiftpm routine 4 AgentRunWorktreeStartLifecycleFixture;ReplacementIdentityFakeCodexController Factory invocation pairs and controller ObjectIdentifier across ensure passes for creation, unchanged pair, secondary-binding change, and execution-directory change Codex controller could be recycled on secondary-binding churn or kept alive across an execution-directory change 0.088000 suite_owned_temp_roots;suite_owned_immutable_git_seed GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 issue #554 WI-1 Codex launch/execution path pair coverage -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexControllerReplacementKeysOnLaunchOnlyChange root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexControllerReplacementKeysOnLaunchOnlyChange MCP agent.worktree.codex-controller-replacement-launch-only codex_launch_execution_split lifecycle_regression root_swiftpm routine 2 AgentRunWorktreeStartLifecycleFixture;ReplacementIdentityFakeCodexController Factory invocation pairs and controller ObjectIdentifier across a logical-root-only binding change with unchanged execution directory A launch-directory-only change could reuse a Codex controller whose app-server was launched from the wrong root 0.038000 suite_owned_temp_roots;suite_owned_immutable_git_seed GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 issue #554 WI-1 Codex launch/execution path pair coverage -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexRuntimeWorkspacePathsFailsClosedOnMalformedSelectedLogicalRoot root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexRuntimeWorkspacePathsFailsClosedOnMalformedSelectedLogicalRoot MCP agent.worktree.codex-launch-root-validation codex_launch_execution_split protocol_negative root_swiftpm routine 3 AgentRunWorktreeStartLifecycleFixture Typed emptyLogicalRoot and launchDirectoryUnavailable errors plus the nil/nil fallback pair A malformed selected logical root could reach process spawn as an opaque launch failure instead of a pre-startup typed error 0.001000 suite_owned_temp_roots;suite_owned_immutable_git_seed AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 issue #554 WI-1 Codex launch/execution path pair coverage -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexRuntimeWorkspacePathsProjectionCoversBoundUnboundSecondaryAndMissingWorktree root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexRuntimeWorkspacePathsProjectionCoversBoundUnboundSecondaryAndMissingWorktree MCP agent.worktree.codex-path-pair-projection codex_launch_execution_split deterministic_service_contract root_swiftpm routine 5 AgentRunWorktreeStartLifecycleFixture Launch/execution pair equality across unbound, bound, secondary-binding, secondary-only, and missing-worktree projections Worktree-bound Codex sessions could launch the app-server from the worktree or move execution off the bound worktree 0.003000 suite_owned_temp_roots;suite_owned_immutable_git_seed AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 issue #554 WI-1 Codex launch/execution path pair coverage -root/RepoPromptTests.AgentRunWorktreeStartTests/testCodexWorkspaceResolutionFailureJoinsConcurrentSessionShutdownRetirement root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCodexWorkspaceResolutionFailureJoinsConcurrentSessionShutdownRetirement MCP agent.worktree.codex-workspace-resolution-retirement-join workspace_resolution_failure,controller_shutdown,session_teardown,retirement_join,exactly_once,no_process_overlap concurrency_regression root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture;ReplacementIdentityFakeCodexController;AgentRunWorktreeStartAsyncGate A gated malformed-root failure overlaps session teardown after failure publication; teardown synchronously detaches and registers the controller, the stale failure joins that same per-tab retirement, both calls return only after shutdown finishes, and the controller receives exactly one shutdown call. Workspace-resolution failure could directly shut down a controller already owned by session teardown, causing duplicate shutdown or returning outside the registered retirement authority. suite_owned_temp_roots;suite_owned_immutable_git_seed;async_tasks GlobalSettingsStore.globalCodeMapsDisabled;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 PR #614 regression for joined workspace-resolution failure and session-shutdown retirement. root/RepoPromptTests.AgentRunWorktreeStartTests/testCoordinatorCreateCarriesReceiptIntoEligibleOwnershipPreparation root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCoordinatorCreateCarriesReceiptIntoEligibleOwnershipPreparation MCP worktree_receipt.coordinator_production_chain loaded_root_admission,production_coordinator,receipt_hint,binding_transition,ownership_generation,session_correlation,no_noReceipt deterministic_integration root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture The production start coordinator creates the worktree receipt, binds its exact hint into the real transition, and commits eligible ownership with matching session, generation, and correlation and no noReceipt fallback. Coordinator plumbing could drop or rewrite valid creation evidence between Git creation and ownership preparation, forcing a full-crawl fallback despite an admitted base. 0.841000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown;user_defaults GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;UserDefaults.standard;GitWorkspaceStateAuthority.shared AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture;test_case+target_discard+window_teardown+defaults_restore retain 0 P1 production-chain replacement for the former manually assembled receipt-to-materializer test. root/RepoPromptTests.AgentRunWorktreeStartTests/testCoordinatorCreateFromLoadedLinkedBaseCarriesReceiptIntoEligibleServing root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCoordinatorCreateFromLoadedLinkedBaseCarriesReceiptIntoEligibleServing MCP worktree_receipt.linked_base_coordinator_chain linked_base,admitted_snapshot,receipt,hint,binding_match,owner_generation,diff_seed_serving deterministic_integration root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture The coordinator carries linked-base receipt evidence into one exact binding hint and publishes one seeded child with no noReceipt or full crawl. Coordinator transport could drop a valid linked-base receipt and force a safe but costly full crawl. 2.083000 git_subprocess;fsevents;suite_owned_temp_roots WindowStatesManager;GitWorkspaceStateAuthority.shared;instrumentation_lock test_case+target_discard+window_teardown+reset retain 0 Direct linked-base coordinator contrast for the full service regression. root/RepoPromptTests.AgentRunWorktreeStartTests/testCoordinatorPostCreateFailureRecordsOneTerminalReceiptDecision root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testCoordinatorPostCreateFailureRecordsOneTerminalReceiptDecision MCP worktree_receipt.coordinator_post_create_failure_terminal git_creation,coordinator_throw,retained_worktree,no_binding,exactly_once,terminal protocol_negative root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture An injected coordinator error after Git creation leaves the created worktree unbound and terminalizes the single correlated receipt attempt at coordinator stage without ambiguity. Post-create coordinator failure could leave a pending diagnostic forever or overwrite creation evidence during rethrow. 0.859500 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;GitWorkspaceStateAuthority.shared;instrumentation_lock AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain 0 P1 deterministic post-create coordinator terminalization repair. @@ -432,7 +402,6 @@ root/RepoPromptTests.AgentRunWorktreeStartTests/testRecoverableStartAbortBeforeT root/RepoPromptTests.AgentRunWorktreeStartTests/testReviewSourceStagingRejectsParentMutationAfterTargetCreation root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testReviewSourceStagingRejectsParentMutationAfterTargetCreation MCP agent.oracle_review.parent_lineage_freeze expected_parent,parent_mutation,staging,fail_closed deterministic_lifecycle_integration root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture Staging compares the target's current parent with the launch-time expected parent and records a fail-closed mismatch after intervening mutation. A target reparented during launch awaits could consume review authority intended for a different child lineage. 0.044500 suite_owned_temp_roots;awaited_window_teardown WindowStatesManager AgentRunWorktreeStartLifecycleFixture retain 0 Issue #264 launch-boundary review correction root/RepoPromptTests.AgentRunWorktreeStartTests/testSharedStartWorktreeCoordinatorHonorsPreCancelledCreateWithoutMutation root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testSharedStartWorktreeCoordinatorHonorsPreCancelledCreateWithoutMutation MCP unreviewed unreviewed root_swiftpm routine 1 AgentRunWorktreeStartLifecycleFixture unreviewed unreviewed 0.431000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture retain_pending_review 0 initial census source line 847 root/RepoPromptTests.AgentRunWorktreeStartTests/testStartedThreadLocationChangesPreserveConfirmationIdentityAndPendingHandoffContracts root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testStartedThreadLocationChangesPreserveConfirmationIdentityAndPendingHandoffContracts MCP agent.ui.location-change.started-thread behavioral_regression root_swiftpm routine 3 AgentRunWorktreeStartLifecycleFixture Restart confirmation, identity clearing, local/new/existing bindings, effective paths, and stable unstaged pending handoff across sequential idle changes high 1.445000 suite_owned_temp_roots;suite_owned_git_sandboxes;suite_owned_immutable_git_seed;awaited_window_teardown GlobalSettingsStore.mcpAutoStart;WindowStatesManager;ServerNetworkManager.bootstrapSocket;AgentRunWorktreeStartGitSeedOwner AgentRunWorktreeStartGitSeedOwner;AgentRunWorktreeStartLifecycleFixture consolidated_replacement 0 replaces root/RepoPromptTests.AgentRunWorktreeStartTests/testIdleStartedThreadRequiresRestartConfirmationBeforeReturningLocalAndClearsOldCWDProviderIdentity; root/RepoPromptTests.AgentRunWorktreeStartTests/testStartedThreadCanCreateNewWorktreeAndReplacePrimaryBinding; root/RepoPromptTests.AgentRunWorktreeStartTests/testStartedThreadCanSwitchAgainWhileRecoveryHandoffWaitsForNextSend -root/RepoPromptTests.AgentRunWorktreeStartTests/testWorktreeCodexControllerFakesPreserveDistinctStreamAndShutdownSemantics root Tests/RepoPromptTests/MCP/AgentRunWorktreeStartTests.swift RepoPromptTests.AgentRunWorktreeStartTests testWorktreeCodexControllerFakesPreserveDistinctStreamAndShutdownSemantics MCP agent.worktree.codex-controller-test-double-lifecycle finished_stream,open_stream,shutdown lifecycle_regression root_swiftpm routine 3 WorktreeStartFakeCodexController;ReplacementIdentityFakeCodexController The passive fake stream finishes immediately, the replacement fake stream remains open before shutdown, and shutdown increments its count before finishing the stream. Shared test defaults could mask distinct stream and shutdown semantics, invalidating controller replacement and teardown coverage. test_case retain 0 Test-double lifecycle contract keeps event-stream and shutdown behavior explicit outside passive defaults. root/RepoPromptTests.AgentRuntimeSidebarViewModelTests/testClaudeFableSelectionFallsBackToOneMillionTokenContextWindow root Tests/RepoPromptTests/AgentMode/AgentRuntimeSidebarViewModelTests.swift RepoPromptTests.AgentRuntimeSidebarViewModelTests testClaudeFableSelectionFallsBackToOneMillionTokenContextWindow AgentMode unreviewed unreviewed root_swiftpm scale 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 103 root/RepoPromptTests.AgentRuntimeSidebarViewModelTests/testCustomSlotMappingUsesBackendContextWindowFallback root Tests/RepoPromptTests/AgentMode/AgentRuntimeSidebarViewModelTests.swift RepoPromptTests.AgentRuntimeSidebarViewModelTests testCustomSlotMappingUsesBackendContextWindowFallback AgentMode agent_runtime.sidebar.custom_backend_context_window custom_claude_compatible,context_window,effort_encoding pure_view_model root_swiftpm routine 2 AgentRuntimeMetricsUIStoreFixture Custom backend sonnet:xhigh reports a 1M fallback while haiku falls back to the standard context window. Runtime sidebar token limits could mislead users for custom Claude-compatible slot mappings. 0.003000 test_case retain 0 PR #252 ledger reconciliation for custom context-window fallback root/RepoPromptTests.AgentRuntimeSidebarViewModelTests/testEncodedClaudeEffortSelectionResolvesContextWindowFallback root Tests/RepoPromptTests/AgentMode/AgentRuntimeSidebarViewModelTests.swift RepoPromptTests.AgentRuntimeSidebarViewModelTests testEncodedClaudeEffortSelectionResolvesContextWindowFallback AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 117 @@ -463,17 +432,11 @@ root/RepoPromptTests.AgentSelectedFilesModelCoordinatorTests/testLoadedIdentityC root/RepoPromptTests.AgentSelectedFilesModelCoordinatorTests/testPreservedDisplayedModelCannotMutateWhileNewIdentityLoads root Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift RepoPromptTests.AgentSelectedFilesModelCoordinatorTests testPreservedDisplayedModelCannotMutateWhileNewIdentityLoads AgentMode agent_selected_files_model_coordinator.preserved_displayed_model_cannot_mutate_while_new_identity_loads state_machine_regression root_swiftpm routine 1 AgentSelectedFilesModelCoordinatorTests asserts preserved displayed model cannot mutate while new identity loads with exact state, configuration, or formatted-output expectations. Selected-files model coordination could publish stale rows, duplicate resolver work, or accept canceled generations. 0.008000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.AgentSelectedFilesModelCoordinatorTests/testRecentlyLoadedDifferentIdentityRestoresFromCacheWithoutResolving root Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift RepoPromptTests.AgentSelectedFilesModelCoordinatorTests testRecentlyLoadedDifferentIdentityRestoresFromCacheWithoutResolving AgentMode agent_selected_files_model_coordinator.recently_loaded_different_identity_restores_from_cache_without_resolving state_machine_regression root_swiftpm routine 1 AgentSelectedFilesModelCoordinatorTests asserts recently loaded different identity restores from cache without resolving with exact state, configuration, or formatted-output expectations. Selected-files model coordination could publish stale rows, duplicate resolver work, or accept canceled generations. 0.004500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.AgentSelectedFilesModelCoordinatorTests/testStableLoadedIdentitySkipsSecondResolve root Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift RepoPromptTests.AgentSelectedFilesModelCoordinatorTests testStableLoadedIdentitySkipsSecondResolve AgentMode agent_selected_files_model_coordinator.stable_loaded_identity_skips_second_resolve state_machine_regression root_swiftpm routine 1 AgentSelectedFilesModelCoordinatorTests asserts stable loaded identity skips second resolve with exact state, configuration, or formatted-output expectations. Selected-files model coordination could publish stale rows, duplicate resolver work, or accept canceled generations. 0.002500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. -root/RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests/testAgentSessionRoundTripsProviderCleanupHandleAsVersionSeven root Tests/RepoPromptTests/AgentMode/AgentSessionProviderCleanupHandlePersistenceTests.swift RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests testAgentSessionRoundTripsProviderCleanupHandleAsVersionSeven AgentMode/Persistence agent_session.provider_cleanup_handle.version_seven_round_trip provider_cleanup_handle,serialization,version_seven,round_trip deterministic_persistence root_swiftpm routine 1 Encoding and decoding a version-seven AgentSession preserves the explicit OpenCode cleanup handle and resolves it unchanged. Session persistence could drop provider cleanup metadata and prevent later provider-side cleanup. test_case retain 0 PR #315/#316 reviewed version-seven provider cleanup handle round-trip contract. -root/RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests/testLegacyCodexFieldsBackfillProviderCleanupHandle root Tests/RepoPromptTests/AgentMode/AgentSessionProviderCleanupHandlePersistenceTests.swift RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests testLegacyCodexFieldsBackfillProviderCleanupHandle AgentMode/Persistence agent_session.provider_cleanup_handle.legacy_codex_backfill provider_cleanup_handle,legacy_json,codex,conversation_id,rollout_path compatibility_persistence root_swiftpm routine 1 A version-six Codex payload keeps its explicit handle nil but resolves an equivalent cleanup handle from legacy conversation ID and rollout path fields. Existing Codex sessions could lose cleanup capability after the serialization schema upgrade. test_case retain 0 PR #315/#316 reviewed legacy Codex cleanup-handle compatibility contract. -root/RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests/testMissingProviderIdentifiersResolveNoCleanupHandle root Tests/RepoPromptTests/AgentMode/AgentSessionProviderCleanupHandlePersistenceTests.swift RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests testMissingProviderIdentifiersResolveNoCleanupHandle AgentMode/Persistence agent_session.provider_cleanup_handle.missing_identifiers_nil provider_cleanup_handle,missing_metadata,nil_resolution pure_model_negative root_swiftpm routine 1 An OpenCode session with no cleanup handle or provider identifiers resolves no cleanup handle. Invented cleanup metadata could target an unrelated provider session. test_case retain 0 PR #315/#316 reviewed missing provider cleanup identifier boundary. -root/RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests/testProviderSessionIDBackfillsGenericProviderCleanupHandle root Tests/RepoPromptTests/AgentMode/AgentSessionProviderCleanupHandlePersistenceTests.swift RepoPromptTests.AgentSessionProviderCleanupHandlePersistenceTests testProviderSessionIDBackfillsGenericProviderCleanupHandle AgentMode/Persistence agent_session.provider_cleanup_handle.provider_session_id_backfill provider_cleanup_handle,legacy_json,claude,provider_session_id compatibility_persistence root_swiftpm routine 1 A version-six Claude payload keeps its explicit handle nil but resolves a generic cleanup handle from the legacy provider session ID. Legacy non-Codex sessions could lose resumable cleanup identity after decoding. test_case retain 0 PR #315/#316 reviewed generic provider-session cleanup-handle compatibility contract. -root/RepoPromptTests.AgentSessionSidebarUIStoreTests/testDefaultCollapseSeedingIsOneShotAndPreservesUserIntent root Tests/RepoPromptTests/AgentMode/AgentSessionSidebarUIStoreTests.swift RepoPromptTests.AgentSessionSidebarUIStoreTests testDefaultCollapseSeedingIsOneShotAndPreservesUserIntent AgentMode/Sidebar agent.sidebar_ui.default_collapse_one_shot default_collapse,seeding,user_intent,expand_all,new_thread pure_state_machine root_swiftpm routine 4 Initial eligible threads collapse once, a manual expansion stays expanded across reseeding, expand-all remains respected, and only a later unhandled thread receives default collapse. Repeated default seeding could override user expansion intent or fail to collapse newly eligible threads. test_case retain 0 PR #315/#316 reviewed four-scenario one-shot default-collapse state contract. -root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testAgentSessionRoundTripsWorktreeBindingsAsCurrentVersion root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testAgentSessionRoundTripsWorktreeBindingsAsCurrentVersion AgentMode agent_session.worktree_bindings.current_version_round_trip serialization,current_version,version_seven,worktree_bindings,round_trip deterministic_persistence root_swiftpm routine 1 The encoded JSON contains worktreeBindings, decodes at AgentSession.currentSerializationVersion 7, and preserves the exact binding array. Current-version persistence could omit worktree bindings, encode the wrong schema version, or corrupt binding identity across a save/load round trip. 0.000000 test_case retain 0 Renamed exact method ID: root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testAgentSessionRoundTripsWorktreeBindingsAsVersionSix -> root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testAgentSessionRoundTripsWorktreeBindingsAsCurrentVersion -root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testDataServiceStubAndFullRestorePreserveCodexResumeReference root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testDataServiceStubAndFullRestorePreserveCodexResumeReference AgentMode agent_session.codex_resume_reference_persistence stub_restore,full_restore,sidebar_index persistence_contract root_swiftpm routine 1 AgentSessionDataService Stub and full session restores preserve both the Codex thread ID and legacy rollout path, while sidebar indexing still selects the saved session. Losing either resume field during lightweight or full restore could make persisted Codex sessions impossible to resume. temp_directory test_case retain 0 PR #621 persistence coverage for Codex resume references across stub and full restore. +root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testAgentSessionRoundTripsWorktreeBindingsAsVersionSix root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testAgentSessionRoundTripsWorktreeBindingsAsVersionSix AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 24 root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testDataServiceStubAndMetadataExposeWorktreeBindingSummaries root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testDataServiceStubAndMetadataExposeWorktreeBindingSummaries AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.003000 unreviewed retain_pending_review 0 initial census source line 45 root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testLegacyMetadataIndexRecordsDecodeWithEmptyWorktreeBindingSummaries root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testLegacyMetadataIndexRecordsDecodeWithEmptyWorktreeBindingSummaries AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 85 root/RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests/testOldAgentSessionJSONDecodesWithEmptyWorktreeBindings root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeBindingPersistenceTests.swift RepoPromptTests.AgentSessionWorktreeBindingPersistenceTests testOldAgentSessionJSONDecodesWithEmptyWorktreeBindings AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 -root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsCurrentVersion root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeMergePersistenceTests.swift RepoPromptTests.AgentSessionWorktreeMergePersistenceTests testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsCurrentVersion AgentMode agent_session.worktree_merge_operations.current_version_round_trip serialization,current_version,version_seven,worktree_merge_operations,active_summary,round_trip deterministic_persistence root_swiftpm routine 1 The encoded JSON contains worktreeMergeOperations, decodes at AgentSession.currentSerializationVersion 7, preserves the exact operation array, and derives its active summary. Current-version persistence could omit or corrupt an active merge operation, encode the wrong schema version, or lose its sidebar-visible active summary. 0.001000 test_case retain 0 Renamed exact method ID: root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsVersionSix -> root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsCurrentVersion +root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsVersionSix root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeMergePersistenceTests.swift RepoPromptTests.AgentSessionWorktreeMergePersistenceTests testAgentSessionRoundTripsActiveWorktreeMergeOperationsAsVersionSix AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 24 root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testDataServiceStubMetadataAndSidebarExposeActiveMergeSummaries root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeMergePersistenceTests.swift RepoPromptTests.AgentSessionWorktreeMergePersistenceTests testDataServiceStubMetadataAndSidebarExposeActiveMergeSummaries AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 46 root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testFingerprintEqualityIgnoresGeneratedAtForPreviewRevalidation root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeMergePersistenceTests.swift RepoPromptTests.AgentSessionWorktreeMergePersistenceTests testFingerprintEqualityIgnoresGeneratedAtForPreviewRevalidation AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 196 root/RepoPromptTests.AgentSessionWorktreeMergePersistenceTests/testOldAgentSessionJSONDecodesWithEmptyWorktreeMergeOperations root Tests/RepoPromptTests/AgentMode/AgentSessionWorktreeMergePersistenceTests.swift RepoPromptTests.AgentSessionWorktreeMergePersistenceTests testOldAgentSessionJSONDecodesWithEmptyWorktreeMergeOperations AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 @@ -523,8 +486,6 @@ root/RepoPromptTests.AgentTranscriptWindowedProjectionTests/testOpenTurnRemainsV root/RepoPromptTests.AgentTranscriptWindowedProjectionTests/testExpandedFlagRestoresExactProjectionRowsAndBlocks root Tests/RepoPromptTests/AgentMode/Transcript/AgentTranscriptWindowedProjectionTests.swift RepoPromptTests.AgentTranscriptWindowedProjectionTests testExpandedFlagRestoresExactProjectionRowsAndBlocks AgentMode agent_mode.transcript.tail_windowed_projection explicit_expand,projection_equivalence projection_contract root_swiftpm routine 1 Expanded history returns the exact unwindowed working projection rows and blocks. The explicit expand affordance could lose historical rows or alter row identity/order. 0.001000 direct_in_process test_case retain 0 PR #391 tail-window transcript rendering ledger reconciliation. root/RepoPromptTests.AgentTranscriptWindowedProjectionTests/testAppendingNewMessagesPreservesStableCollapsedRangeIDAndFullTail root Tests/RepoPromptTests/AgentMode/Transcript/AgentTranscriptWindowedProjectionTests.swift RepoPromptTests.AgentTranscriptWindowedProjectionTests testAppendingNewMessagesPreservesStableCollapsedRangeIDAndFullTail AgentMode agent_mode.transcript.tail_windowed_projection append_stability,tail_window,identity projection_contract root_swiftpm routine 1 Appending a new turn keeps the collapsed range identity stable and preserves the newest 40 full turns through the new tail. Streaming appends could churn collapsed range identity or stop keeping the recent tail fully visible. 0.001000 direct_in_process test_case retain 0 PR #391 tail-window transcript rendering ledger reconciliation. root/RepoPromptTests.AgentTranscriptWindowedProjectionTests/testHiddenAnchorRemapsToCollapsedRangeAndVisibleAnchorsRemainUnchanged root Tests/RepoPromptTests/AgentMode/Transcript/AgentTranscriptWindowedProjectionTests.swift RepoPromptTests.AgentTranscriptWindowedProjectionTests testHiddenAnchorRemapsToCollapsedRangeAndVisibleAnchorsRemainUnchanged AgentMode agent_mode.transcript.tail_windowed_projection scroll_anchor,collapsed_history,tail_window projection_contract root_swiftpm routine 1 Anchors for hidden turns remap to the collapsed range while visible tail anchors retain their original block IDs. Scroll restoration or search focus could target a missing hidden block or corrupt visible-tail anchors. 0.001000 direct_in_process test_case retain 0 PR #391 tail-window transcript rendering ledger reconciliation. -root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testCodemapStatusNotificationsCoalesceRootRowResnapshots root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testCodemapStatusNotificationsCoalesceRootRowResnapshots AgentMode agent_sidebar.codemap.status_coalescing codemap,progress,combine,main_actor,resnapshot,coalescing concurrency_contract root_swiftpm routine 1 PassthroughSubject A same-turn burst of Code Map notifications coalesces into one main-actor root-row resnapshot that reads the latest authoritative status. Uncoalesced progress bursts could accumulate full-root remaps and SwiftUI invalidations faster than the engine publication cadence. direct_in_process test_case retain 0 Incremental Code Map progress sidebar-delivery regression. -root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testCodemapToggleResnapshotsAuthoritativeStateBeforeClearingPending root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testCodemapToggleResnapshotsAuthoritativeStateBeforeClearingPending AgentMode agent_sidebar.codemap.toggle_authority codemap,pause_resume,pending_action state_observation root_swiftpm routine 3 A paused row resumes, the resulting authoritative presentation is resnapshotted before pending state clears, and the next toggle pauses the same root without leaving an in-flight action marker. A stale row could invert pause/resume intent, admit duplicate work, or leave the compact control permanently disabled. direct_in_process test_case retain 0 Per-loaded-root Code Map pause/resume sidebar regression. root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testIndicatorHumanizesMachineFallbackWhileKeepingRawNameAccessible root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testIndicatorHumanizesMachineFallbackWhileKeepingRawNameAccessible AgentMode agent_worktree.identity_label_humanization worktree_indicator,accessibility,tooltip state_observation root_swiftpm routine 1 A machine-generated worktree fallback renders a humanized WT label while rawLabel, tooltip text, and accessibility text retain the full generated name. Raw app-managed worktree leaves could leak into compact sidebar capsules or be lost from recovery/accessibility text. 0.000000 direct_in_process test_case retain 0 Sidebar worktree capsule polish: display-time humanization with raw-name preservation. root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testIndicatorLabelFallsBackToWorktreeIDTail root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testIndicatorLabelFallsBackToWorktreeIDTail AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 261 root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testIndicatorMakeFallsBackToResolvedIdentityForMissingOrInvalidFields root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testIndicatorMakeFallsBackToResolvedIdentityForMissingOrInvalidFields AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 235 @@ -563,17 +524,9 @@ root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAgentSessionDeepLinkURL root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAgentSessionURLQueuesWhenNoLiveWindowsAreRegistered root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testAgentSessionURLQueuesWhenNoLiveWindowsAreRegistered App app.deeplink.agent_session_queue_no_windows agent_session,deeplink,window_states main_actor_integration root_swiftpm routine 1 Agent session deep link routes to pendingURLs when WindowStatesManager has no live windows. Cold-start agent session links could be dropped instead of queued for later routing. 0.000500 main_actor_singleton WindowStatesManager test_case retain 0 Agent mode lifetime hardening ledger reconciliation root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAppcastParserPrefersHighestBuildNumberForSameMarketingVersion root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testAppcastParserPrefersHighestBuildNumberForSameMarketingVersion App app.update.appcast_highest_build_for_same_marketing_version sparkle,appcast,build_number deterministic_parser_regression root_swiftpm routine 1 Parsing an appcast with duplicate marketing versions selects the entry carrying the highest Sparkle build number. Tip or stable update feeds could surface an older build when marketing versions collide. test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed appcast build-number tie-break coverage. root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAppcastParserSelectsHighestInlineVersionAndKeepsMetadata root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testAppcastParserSelectsHighestInlineVersionAndKeepsMetadata App unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 24 -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAppcastRequestIdentityRejectsDelayedAndOverlappingResults root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testAppcastRequestIdentityRejectsDelayedAndOverlappingResults App app.update.appcast_request_identity_currentness appcast,request_identity,update_channel,stale_result deterministic_state_regression root_swiftpm routine 4 Only the exact active request on the selected channel is current; delayed, superseded, and missing-active identities are rejected. Delayed or overlapping passive appcast results could overwrite update state for a newer request or different channel. test_case retain 0 Tip update notice transplant: reviewed passive appcast request-identity coverage. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testAvailableUpdateNoticeKeepsDetectedChannelAndCentralizesTipCopy root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testAvailableUpdateNoticeKeepsDetectedChannelAndCentralizesTipCopy App app.update.notice_tip_channel_presentation sparkle,tip_channel,update_notice,presentation deterministic_presentation_regression root_swiftpm routine 1 A Tip notice retains its detected channel and renders the unique build, marketing version, short commit, details action, menu title, and accessibility copy. Tip users could see ambiguous same-marketing-version notices or lose the build and commit identity needed to distinguish updates. test_case retain 0 Tip update notice transplant: reviewed centralized Tip presentation contract. root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testCanonicalAndLegacySchemesRouteOpeners root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testCanonicalAndLegacySchemesRouteOpeners App app.deeplink.scheme_support canonical_scheme,legacy_scheme,open_prompt direct_core root_swiftpm routine 4 repoprompt-ce and repoprompt schemes parse open and prompt legacy routes; unsupported schemes return unsupported. Deep links could fail across canonical and legacy scheme variants. 0.000000 test_case retain 0 Agent mode lifetime hardening ledger reconciliation root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testInAppAgentSessionRouteReturnsResultWithoutQueueingURL root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testInAppAgentSessionRouteReturnsResultWithoutQueueingURL App/Routing app_deep_link.agent_session_in_app_no_url_queue agent_session_route,in_app_routing,workspace_unavailable deterministic_regression root_swiftpm routine 1 In-app agent-session routing returns workspaceUnavailable without queueing a URL when no live windows are registered. HUD session jumps could enqueue ephemeral agent-session URLs and replay stale navigation later. shared_singleton WindowStatesManager test_case+defer_restore retain 0 PR #352 retained as a small side-effect regression for non-URL in-app routing. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testSparkleAppcastItemURLIdentifiesOnlyExactTrustedUpdateChannels root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testSparkleAppcastItemURLIdentifiesOnlyExactTrustedUpdateChannels App app.update.appcast_item_trusted_channel_mapping sparkle,update_channel,enclosure_url,trust_boundary security_boundary_regression root_swiftpm routine 7 Exact trusted stable and Tip GitHub enclosure URLs map to their channels; lookalike, query-bearing, insecure, malformed, and nil URLs are rejected. An untrusted or stale Sparkle notification could be attributed to the selected update channel and overwrite the visible notice. test_case retain 0 Tip update notice transplant: reviewed fail-closed enclosure URL mapping coverage. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testSparkleDisplayVersionNormalizationRemovesTipDecoration root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testSparkleDisplayVersionNormalizationRemovesTipDecoration App app.update.display_version_normalization sparkle,tip_channel,display_version,normalization deterministic_transformation_regression root_swiftpm routine 2 Tip build decoration and an ordinary leading v normalize to the undecorated semantic marketing version. Native Sparkle display labels could be compacted or double-prefixed when projected into custom update UI. test_case retain 0 Tip update notice transplant: reviewed Sparkle display-version normalization coverage. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testSparklePositiveResultTargetsOnlyMatchingActiveRequestForSettlement root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testSparklePositiveResultTargetsOnlyMatchingActiveRequestForSettlement App/Updates app.update.sparkle_positive_request_settlement sparkle,notification,request_lifecycle,update_channel,state_safety deterministic_state_machine root_swiftpm routine 4 A positive Sparkle result targets the active request only when its channel matches, while missing and mismatched requests remain untouched. A successful manual update check could block passive checks for five minutes or an uncorrelated callback could finish a request from another channel. test_case retain 0 Regression coverage for request-scoped positive-result settlement after the Sparkle session ends. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testSparklePositiveResultsCannotDowngradeKnownBuilds root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testSparklePositiveResultsCannotDowngradeKnownBuilds App/Updates app.update.sparkle_positive_build_monotonicity sparkle,notification,build_number,state_safety deterministic_state_machine root_swiftpm routine 5 A Sparkle positive result with a missing known build, equal build, or newer build is accepted, while older and malformed candidates cannot replace a known numeric build. A delayed or malformed Sparkle callback could downgrade the visible notice after a newer build was already detected. test_case retain 0 Regression coverage for monotonic positive Sparkle results. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testStableUpdateNoticeUsesStableCopyWithoutTipLabel root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testStableUpdateNoticeUsesStableCopyWithoutTipLabel App app.update.notice_stable_copy_compatibility sparkle,stable_channel,update_notice,presentation deterministic_presentation_regression root_swiftpm routine 1 A stable notice exposes version and build without Tip branding and uses neutral install copy when update details are unavailable. Stable updates could lose build identity, inherit Tip branding, or promise release notes that are unavailable. test_case retain 0 Tip update notice transplant: reviewed stable presentation compatibility contract. root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testTipBuildVersionSortsBetweenAdjacentStableBuilds root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testTipBuildVersionSortsBetweenAdjacentStableBuilds App app.update.tip_build_version_semantic_ordering sparkle,tip_channel,version_ordering deterministic_ordering_regression root_swiftpm routine 1 A dotted Tip build sorts after the current stable build, before the next stable build, and rejects over-specific versions. Tip-channel update eligibility could be misordered relative to stable releases. test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed Tip build-version ordering coverage. -root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testUncorrelatedSparkleNoUpdatePreservesNewerRequestAndNoticeDisposition root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testUncorrelatedSparkleNoUpdatePreservesNewerRequestAndNoticeDisposition App/Updates app.update.uncorrelated_no_update_state_safety sparkle,notification,request_lifecycle,stale_result,state_safety deterministic_state_machine root_swiftpm routine 1 After an older request finishes and a newer request starts, an uncorrelatable Sparkle no-update result preserves the newer request and notice disposition; the older token cannot finish it. A delayed no-update callback or captured timeout from an older Sparkle cycle could clear a valid notice or finish a newer user request. test_case retain 0 Regression coverage for uncorrelatable Sparkle notification ordering and captured timeout identity. root/RepoPromptTests.AppPlatformUtilityRecoveryTests/testUpdateChannelDefaultsToStableAndPersistsTipSelection root Tests/RepoPromptTests/App/AppPlatformUtilityRecoveryTests.swift RepoPromptTests.AppPlatformUtilityRecoveryTests testUpdateChannelDefaultsToStableAndPersistsTipSelection App app.update.channel_default_and_tip_persistence update_channel,user_defaults,feed_url preferences_unit root_swiftpm routine 2 UserDefaults(suiteName:) A fresh update-channel preference loads as stable, then a stored Tip selection reloads and exposes distinct stable/Tip feed URLs. Users could be silently moved to Tip feeds or lose an intentional Tip-channel selection. isolated_user_defaults test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed update-channel default and persistence coverage. root/RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests/testCodexReasoningSummariesSettingListsReadsAndWrites root Tests/RepoPromptTests/MCP/AppSettingsMCPServiceAgentModeSettingsTests.swift RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests testCodexReasoningSummariesSettingListsReadsAndWrites MCP app_settings_mcpservice_agent_mode_settings.codex_reasoning_summaries_setting_lists_reads_and_writes configuration_regression root_swiftpm routine 1 AppSettingsMCPServiceAgentModeSettingsTests asserts codex reasoning summaries setting lists reads and writes with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.003000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests/testSetWarnsWhenGlobalSettingsPersistenceIsBlocked root Tests/RepoPromptTests/MCP/AppSettingsMCPServiceAgentModeSettingsTests.swift RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests testSetWarnsWhenGlobalSettingsPersistenceIsBlocked MCP app_settings_mcpservice_agent_mode_settings.set_warns_when_global_settings_persistence_is_blocked configuration_regression root_swiftpm routine 1 AppSettingsMCPServiceAgentModeSettingsTests asserts app_settings set surfaces blocked global JSON persistence while keeping in-memory state. Agents could report settings saved even though globalSettings.json refuses writes and changes vanish on restart. 0.003000 unreviewed retain_pending_review 0 PR #418 app_settings persistence-block warning @@ -666,17 +619,8 @@ root/RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests/testNestedRepository root/RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests/testOneCheckoutFailureProducesExplicitPartialResultWithoutPhysicalPaths root Tests/RepoPromptTests/Prompt/AutomaticReviewGitDiffCoordinatorTests.swift RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests testOneCheckoutFailureProducesExplicitPartialResultWithoutPhysicalPaths Prompt prompt.git_review.explicit_partial_failure multi_checkout,partial_failure,path_redaction deterministic_unit root_swiftpm routine 1 One owner failure yields an explicit partial result without leaking physical checkout paths. Multi-repository failures could silently truncate output or expose worktree paths. 0.001000 test_case retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests/testSingleCheckoutIncludesStagedUnstagedAndUntrackedChanges root Tests/RepoPromptTests/Prompt/AutomaticReviewGitDiffCoordinatorTests.swift RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests testSingleCheckoutIncludesStagedUnstagedAndUntrackedChanges Prompt prompt.git_review.single_checkout_change_classes staged,unstaged,untracked real_git_integration root_swiftpm routine 3 ReviewGitRepositoryFixture A single checkout review includes staged, unstaged, and untracked selected changes. One working-tree change class could be omitted from automatic review. 0.177000 git_subprocess;filesystem per_test_temporary_repository_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests/testUnresolvedNoRepositoryAndUnsupportedBackendAreStructuredFailures root Tests/RepoPromptTests/Prompt/AutomaticReviewGitDiffCoordinatorTests.swift RepoPromptTests.AutomaticReviewGitDiffCoordinatorTests testUnresolvedNoRepositoryAndUnsupportedBackendAreStructuredFailures Prompt prompt.git_review.structured_owner_failures unresolved_path,no_repository,unsupported_backend deterministic_unit root_swiftpm routine 3 Unresolved paths, missing repositories, and unsupported backends remain explicit structured failures. Owner-resolution failures could disappear and produce a plausible partial diff. 0.000000 test_case retain 0 Uncommitted #264 contract reconciliation -root/RepoPromptTests.BareURLLinkifierTests/testBalancedParenthesesInsideURLArePreserved root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testBalancedParenthesesInsideURLArePreserved UI/Markdown markdown.bare_url.balanced_parentheses bare_url,http_https,parentheses,range_detection regression root_swiftpm fast 1 A balanced closing parenthesis inside the URL remains part of the exact linked substring. URL trimming could remove valid balanced path characters and open the wrong destination. appkit test_case retain 0 PR #684 rebased PR #70 bare-URL regression coverage. -root/RepoPromptTests.BareURLLinkifierTests/testBareURLDoesNotReceiveMarkdownRawLinkAttribute root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testBareURLDoesNotReceiveMarkdownRawLinkAttribute UI/Markdown markdown.bare_url.raw_link_attribute_separation bare_url,markdown_raw_link,attributed_string regression root_swiftpm fast 1 A generated bare link has no markdownRawLink attribute at its linked range. Bare prose URLs could be misclassified as authored Markdown links and bypass bare-link-specific behavior. appkit test_case retain 0 PR #684 rebased PR #70 bare-URL regression coverage. -root/RepoPromptTests.BareURLLinkifierTests/testBareURLReceivesPositiveMarkerAndVisualLinkStyling root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testBareURLReceivesPositiveMarkerAndVisualLinkStyling UI/Markdown markdown.bare_url.marker_and_visual_style bare_url,attributed_string,link_color,underline regression root_swiftpm fast 1 The linked range carries the bare-URL marker, single underline, and AppKit link color. Bare URLs could remain clickable but lose their identifying marker or visible link affordance. appkit test_case retain 0 PR #684 rebased PR #70 bare-URL regression coverage. -root/RepoPromptTests.BareURLLinkifierTests/testCallerCanSuppressURLThatTouchesDisplayedBoundary root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testCallerCanSuppressURLThatTouchesDisplayedBoundary UI/Markdown markdown.bare_url.display_boundary_suppression bare_url,streaming,boundary,visual_attributes regression root_swiftpm fast 2 A URL completed before terminal punctuation remains linked, while a URL touching the display boundary has no link marker or visual styling. Streaming previews could expose a partial destination or leave stale link styling after suppressing it. appkit test_case retain 0 PR #684 rebased PR #70 boundary-suppression coverage. -root/RepoPromptTests.BareURLLinkifierTests/testDisabledPolicyLeavesBareURLUnlinked root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testDisabledPolicyLeavesBareURLUnlinked UI/Markdown markdown.bare_url.disabled_policy bare_url,policy,disabled regression root_swiftpm fast 1 No link attributes are produced when bare-URL linkification is disabled. Callers that render non-prose content could unexpectedly gain clickable URLs. appkit test_case retain 0 PR #684 rebased PR #70 policy coverage. -root/RepoPromptTests.BareURLLinkifierTests/testHTTPAndHTTPSURLsBecomeLinks root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testHTTPAndHTTPSURLsBecomeLinks UI/Markdown markdown.bare_url.http_https_linkification bare_url,http,https,url_value regression root_swiftpm fast 2 Both HTTP and HTTPS prose URLs produce exact linked substrings and the first link stores the expected URL value. Supported web URLs could remain plain text or resolve to a truncated or incorrect destination. appkit test_case retain 0 PR #684 rebased PR #70 supported-scheme coverage. -root/RepoPromptTests.BareURLLinkifierTests/testHTTPHTTPSURLSignalPreflightIsCheapAndCaseInsensitive root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testHTTPHTTPSURLSignalPreflightIsCheapAndCaseInsensitive UI/Markdown markdown.bare_url.preflight_signal bare_url,preflight,case_insensitive,false_positive regression root_swiftpm fast 5 The preflight accepts lowercase HTTP and uppercase HTTPS signals and rejects www, mailto, and URL-free text. The fast path could skip valid uppercase links or invoke full detection for unsupported text. test_case retain 0 PR #684 rebased PR #70 preflight coverage. -root/RepoPromptTests.BareURLLinkifierTests/testPlainProseWebLinkClickFallsThroughToAppKitDefaultOpening root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testPlainProseWebLinkClickFallsThroughToAppKitDefaultOpening UI/Markdown markdown.bare_url.appkit_default_opening bare_url,click_handling,appkit regression root_swiftpm fast 1 The Markdown text-view coordinator returns false for a generated web link so AppKit performs the default opening action. The coordinator could consume ordinary web clicks without opening their destinations. appkit test_case retain 0 PR #684 rebased PR #70 click-routing coverage. -root/RepoPromptTests.BareURLLinkifierTests/testRejectedBareURLShapesStayPlainText root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testRejectedBareURLShapesStayPlainText UI/Markdown markdown.bare_url.rejected_shapes mailto,email,ftp,file,www,local_path protocol_negative root_swiftpm fast 6 Mailto, bare email, FTP, file, www-only, and local-path URL-like text all remain unlinked. The linkifier could expand beyond its HTTP/HTTPS contract or create unsafe and misleading destinations. appkit test_case retain 0 PR #684 rebased PR #70 rejected-shape coverage. -root/RepoPromptTests.BareURLLinkifierTests/testTrailingSentencePunctuationAndWrappingParensAreExcludedFromLinkRange root Tests/RepoPromptTests/Markdown/BareURLLinkifierTests.swift RepoPromptTests.BareURLLinkifierTests testTrailingSentencePunctuationAndWrappingParensAreExcludedFromLinkRange UI/Markdown markdown.bare_url.trailing_delimiter_trimming bare_url,punctuation,wrapping_parentheses,range_detection regression root_swiftpm fast 2 Sentence punctuation and unmatched wrapping parentheses are excluded from both exact linked substrings. Generated link destinations could absorb prose punctuation or closing delimiters. appkit test_case retain 0 PR #684 rebased PR #70 delimiter-trimming coverage. root/RepoPromptTests.BashToolResultParserRecoveryTests/testParserKeepsCommandLivenessAndMetadataContractsInSync root Tests/RepoPromptTests/AgentMode/Codex/BashToolResultParserRecoveryTests.swift RepoPromptTests.BashToolResultParserRecoveryTests testParserKeepsCommandLivenessAndMetadataContractsInSync AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 5 +root/RepoPromptTests.BenchmarkDiffApplierTests/testModifyChangeAppliesGeneratedDiffChunks root Tests/RepoPromptTests/Diagnostics/BenchmarkDiffApplierTests.swift RepoPromptTests.BenchmarkDiffApplierTests testModifyChangeAppliesGeneratedDiffChunks Diagnostics unreviewed unreviewed root_swiftpm diagnostic 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.BindContextRoutingRecoveryTests/testBindContextParsesCommaSeparatedWorkingDirs root Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift RepoPromptTests.BindContextRoutingRecoveryTests testBindContextParsesCommaSeparatedWorkingDirs MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 45 root/RepoPromptTests.BindContextRoutingRecoveryTests/testBindContextParsesReadOnlyOperationsWithoutSelectors root Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift RepoPromptTests.BindContextRoutingRecoveryTests testBindContextParsesReadOnlyOperationsWithoutSelectors MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 35 root/RepoPromptTests.BindContextRoutingRecoveryTests/testBindContextParsesWorkingDirsAndPrefersSelectedWindow root Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift RepoPromptTests.BindContextRoutingRecoveryTests testBindContextParsesWorkingDirsAndPrefersSelectedWindow MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 @@ -715,18 +659,9 @@ root/RepoPromptTests.CLIProcessRunnerLifecycleTests/testCancelAllTerminatesRepar root/RepoPromptTests.CLIProcessRunnerLifecycleTests/testStreamingProcessLifecycleCallbacksUseSamePIDAndTerminate root Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift RepoPromptTests.CLIProcessRunnerLifecycleTests testStreamingProcessLifecycleCallbacksUseSamePIDAndTerminate AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.065500 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.CLIProcessRunnerLifecycleTests/testStreamingProcessTerminationCallbackRunsAfterRunnerCancellation root Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift RepoPromptTests.CLIProcessRunnerLifecycleTests testStreamingProcessTerminationCallbackRunsAfterRunnerCancellation AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.066000 unreviewed retain_pending_review 0 initial census source line 40 root/RepoPromptTests.CLIProcessRunnerLifecycleTests/testTerminateAndReapUsesSpawnedProcessGroupForDirectProviderStyleProcess root Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift RepoPromptTests.CLIProcessRunnerLifecycleTests testTerminateAndReapUsesSpawnedProcessGroupForDirectProviderStyleProcess AI ai.cli_process_runner.terminate_and_reap_uses_spawned_process_group process_group,direct_provider,descendant_reaping subprocess_lifecycle_regression root_swiftpm routine 1 temporary_pid_marker Terminating a directly spawned provider-style shell reaps the same-process-group descendant recorded by the marker file. Direct provider launches could terminate only the parent and leak child processes. subprocess;filesystem;async_wait test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed direct-provider process-group reap coverage. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testBlockedOutcomePublicationDoesNotDelayAnotherChildReap root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testBlockedOutcomePublicationDoesNotDelayAnotherChildReap AI ai.process_termination.child_exit_observer.publication_isolation waitpid,dispatch_source,observer,publication_gate,echild subprocess_lifecycle_regression root_swiftpm routine 2 BlockedOutcomePublicationGate Child A closes its PID-signaling window while outcome publication is gated; child B still publishes exited(23) and is already reaped, then releasing A publishes exited(17) and confirms its reap. A blocked diagnostic publication hook could stall the serial registry, delay unrelated Codex exit evidence, or reopen competing PID signaling and waitpid ownership. subprocess;async_wait gate+actor_cleanup+addTeardownBlock retain 0 Worktree-bound Codex startup REVIEW remediation: deterministic publication isolation and sole-reaper coverage. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testBlockingReapChildStatusPreservesExitAndSignalSemantics root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testBlockingReapChildStatusPreservesExitAndSignalSemantics AI ai.process_termination.blocking_reap_status waitpid,blocking_reap,exit_status,signal,pre_reap_callback subprocess_lifecycle_regression root_swiftpm routine 2 GitProcessLifecycleTarget A dedicated off-executor registry reaps normal and signaled children with exact status semantics and closes lifecycle signaling before its destructive wait. Git completion could poll unnecessarily, diverge from exit decoding, or expose a PID-signaling gap at the destructive reap boundary. 0.100000 subprocess;async_wait test_case retain 0 Event-driven sole-reaper and synchronous pre-reap lifecycle-fence coverage. +root/RepoPromptTests.ProcessTerminationExitStatusTests/testBlockingReapChildStatusPreservesExitAndSignalSemantics root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testBlockingReapChildStatusPreservesExitAndSignalSemantics AI ai.process_termination.blocking_reap_status waitpid,blocking_reap,exit_status,signal,reap_callback subprocess_lifecycle_regression root_swiftpm routine 2 GitProcessLifecycleTarget A dedicated off-executor blocking waitpid reaps normal and signaled children with exact status semantics and marks lifecycle state before await resumes. Git completion could poll unnecessarily, diverge from exit decoding, or expose a post-reap lifecycle signaling gap. 0.100000 subprocess;async_wait test_case retain 0 Oracle P1 process-launch follow-up: event-driven sole-reaper and synchronous post-waitpid hook coverage. root/RepoPromptTests.ProcessTerminationExitStatusTests/testBlockingReapChildStatusTreatsECHILDAsOwnershipError root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testBlockingReapChildStatusTreatsECHILDAsOwnershipError AI ai.process_termination.blocking_reap_echild_ownership_error waitpid,blocking_reap,echild,ownership subprocess_lifecycle_regression root_swiftpm routine 1 A second sole-reaper wait for an already reaped child throws childOwnershipLost instead of fabricating exited(0). ECHILD could be misreported as a successful zero exit and conceal competing waitpid ownership. 0.050000 subprocess;async_wait test_case retain 0 GPT-5.6 Sol Ultra P1 follow-up: ECHILD ownership-error coverage. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testChildProcessExitObserverClosesSignalingBeforeDestructiveReap root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testChildProcessExitObserverClosesSignalingBeforeDestructiveReap AI ai.process_termination.child_exit_observer.pre_reap_signal_fence waitid,wnowait,waitpid,observer,pid_reuse,signal_window subprocess_lifecycle_regression root_swiftpm routine 1 BlockedPreReapGate The pre-reap gate proves the exited child remains waitable while root PID/group signaling is already rejected, then releasing the gate publishes exited(29) and leaves ECHILD for any second reap. Closing signaling only after waitpid could allow a concurrent signal to target a reused PID or process group. subprocess;async_wait;dispatch_wait gate+actor_cleanup+addTeardownBlock retain 0 Kernel-boundary sole-reaper signal-safety contract. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testChildProcessExitObserverSharesOneDetailedReap root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testChildProcessExitObserverSharesOneDetailedReap AI ai.process_termination.child_exit_observer.shared_sole_reap waitpid,observer,exit_status,echild,sole_reaper subprocess_lifecycle_regression root_swiftpm routine 1 ChildProcessExitObserver Repeated observer waits share exited(19), and a later direct reap reports childOwnershipLost. Multiple lifecycle consumers could perform competing destructive waits or fabricate exit evidence. subprocess;async_wait test_case retain 0 WI-2 sole-reaper observation coverage. root/RepoPromptTests.ProcessTerminationExitStatusTests/testDecodeWaitStatusPreservesExitSignalAndFallbackSemantics root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testDecodeWaitStatusPreservesExitSignalAndFallbackSemantics AI ai.process_termination.detailed_status_decode waitpid,exit_status,signal,fallback deterministic_unit root_swiftpm fast 4 Raw waitpid statuses decode to exited/uncaughtSignal cases whose normalized, terminationStatus, and terminationReason projections all agree. Detailed decoding could diverge from the historical 128+signal normalization or from NSTask terminationStatus parity. 0.000000 test_case retain 0 posix_spawn git launch migration: new behavioral coverage for ProcessLauncher-based GitService spawning. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testObservedExitSurvivesRepeatedWaitFailuresWithSoleReap root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testObservedExitSurvivesRepeatedWaitFailuresWithSoleReap AI ai.process_termination.child_exit_observer.repeated_wait_failure_retry wait_failed,observer,retry,backoff,sole_reaper subprocess_lifecycle_regression root_swiftpm routine 1 FailNTimesChildStatusObserver Three injected consecutive wait failures still end in one destructive reap publishing exited(7) with ECHILD left for any second reap. Repeated transient wait failures could abandon reap ownership, strand a zombie, or publish duplicate outcomes. subprocess;async_wait test_case retain 0 Clean-branch REVIEW loop 2 P0 remediation: repeated-failure retry keeps sole-reaper ownership. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testObservedTerminationEscalatesBeforeGroupOnlyCleanup root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testObservedTerminationEscalatesBeforeGroupOnlyCleanup AI ai.process_termination.observed_term_kill_group_cleanup sigterm,sigkill,process_group,root_reap,descendant_cleanup subprocess_lifecycle_regression root_swiftpm routine 1 sigterm_ignoring_process_family Observer-aware teardown escalates a TERM-resistant family to KILL, observes the root signal, removes the descendant, and leaves ECHILD for any second reap. Teardown could race a second waitpid, signal a reused root PID, or leak descendants. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 observer-aware teardown coverage. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testObservedTerminationRetriesWaitFailureAndEscalates root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testObservedTerminationRetriesWaitFailureAndEscalates AI ai.process_termination.observer_wait_failure_retry wait_failed,observer,retry,sigterm,sigkill,sole_reaper subprocess_lifecycle_regression root_swiftpm routine 1 FailOnceChildStatusObserver;sigterm_ignoring_process One injected wait failure returns observation to the registry, preserves TERM-to-KILL authority, publishes uncaughtSignal(SIGKILL), and leaves ECHILD for any second reap. Treating a wait failure as a completed reap could suppress escalation while the root remains alive or strand its exit status. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 Retryable sole-reaper failure contract. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testObservedTerminationReturnsAfterBoundedKillGraceWhileOutcomePublicationIsBlocked root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testObservedTerminationReturnsAfterBoundedKillGraceWhileOutcomePublicationIsBlocked AI ai.process_termination.observed_cleanup_bounded_tail sigterm,sigkill,observer,publication_gate,bounded_cleanup,descendant_cleanup subprocess_lifecycle_regression root_swiftpm routine 1 BlockedOutcomePublicationGate;ProcessTerminationCompletionProbe;descendant_process Observed teardown returns after bounded TERM and KILL grace and removes a TERM-resistant descendant while root outcome publication remains blocked; releasing publication later yields exited(37) from the sole reaper. Stop, replacement, or shutdown could hang indefinitely after the configured KILL grace expires or leak descendants when only outcome publication is delayed. subprocess;filesystem;async_wait;dispatch_wait gate+actor_cleanup+addTeardownBlock retain 0 Bounded cleanup-tail and descendant-cleanup contract. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testTerminalChildProbeDoesNotConsumeExitStatus root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testTerminalChildProbeDoesNotConsumeExitStatus AI ai.process_termination.child_status.nondestructive_terminal_probe waitid,wnowait,waitpid,exit_status,echild subprocess_lifecycle_regression root_swiftpm routine 2 The terminal-child probe detects both a zombie and an already-reaped child while leaving exited(31) available to the sole destructive reaper. A diagnostic probe could consume typed exit evidence or mistake an already-reaped root for a live process. subprocess;async_wait test_case retain 0 Worktree-bound Codex startup EOF arbitration regression coverage. -root/RepoPromptTests.ProcessTerminationExitStatusTests/testWaitFailureRetryDelayDoublesFromTenMillisecondsToOneSecondCeiling root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testWaitFailureRetryDelayDoublesFromTenMillisecondsToOneSecondCeiling AI ai.process_termination.child_exit_observer.wait_failure_backoff_curve wait_failed,observer,retry,backoff deterministic_unit root_swiftpm fast 3 Retry pacing starts at 10 ms, doubles per consecutive failure, and clamps at the 1 s ceiling for all later failures. An unbounded or fixed-interval retry could spin the outcome-publication queue at high frequency during persistent kernel wait failures. 0.000000 test_case retain 0 Clean-branch REVIEW loop 2 P0 remediation: bounded wait-failure backoff curve. root/RepoPromptTests.ProcessTerminationExitStatusTests/testWaitForTerminationStatusReportsRealChildExitAndSignal root Tests/RepoPromptTests/AI/ProcessTerminationExitStatusTests.swift RepoPromptTests.ProcessTerminationExitStatusTests testWaitForTerminationStatusReportsRealChildExitAndSignal AI ai.process_termination.detailed_status_reap waitpid,exit_status,signal,reaping subprocess_lifecycle_regression root_swiftpm routine 2 Real children reaped through waitForTerminationStatus report exited(3) and uncaughtSignal(SIGKILL) with normalized parity. The detailed wait variant could mis-decode real waitpid statuses or diverge from the normalized API for signal exits. 0.300000 subprocess;async_wait test_case retain 0 posix_spawn git launch migration: new behavioral coverage for ProcessLauncher-based GitService spawning. root/RepoPromptTests.ChatHistoryJSONOnlyTests/testCurrentChatSessionSaveLoadUsesCEWorkspaceRoot root Tests/RepoPromptTests/ChatHistoryJSONOnlyTests.swift RepoPromptTests.ChatHistoryJSONOnlyTests testCurrentChatSessionSaveLoadUsesCEWorkspaceRoot Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.ChatHistoryJSONOnlyTests/testLegacyChatSessionEditPayloadsAreIgnoredOnDecodeAndOmittedOnEncode root Tests/RepoPromptTests/ChatHistoryJSONOnlyTests.swift RepoPromptTests.ChatHistoryJSONOnlyTests testLegacyChatSessionEditPayloadsAreIgnoredOnDecodeAndOmittedOnEncode Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 70 @@ -749,8 +684,6 @@ root/RepoPromptTests.ClaudeNativeApprovalAndResumeTests/testNativeLiveModelSwitc root/RepoPromptTests.ClaudeNativeApprovalAndResumeTests/testRepoPromptPermissionAutoApprovalAndAllowPayloadPreserveToolUseID root Tests/RepoPromptTests/AgentMode/ClaudeCompatible/ClaudeNativeApprovalAndResumeTests.swift RepoPromptTests.ClaudeNativeApprovalAndResumeTests testRepoPromptPermissionAutoApprovalAndAllowPayloadPreserveToolUseID AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.ClaudeNativeIdentityPreambleTests/testGLMVariantAppendsIdentityPreambleFlagWithValidValue root Tests/RepoPromptTests/AgentMode/ClaudeCompatible/ClaudeNativeIdentityPreambleTests.swift RepoPromptTests.ClaudeNativeIdentityPreambleTests testGLMVariantAppendsIdentityPreambleFlagWithValidValue AgentMode claude_compatible.identity_preamble glm,launch_arguments,provider_variant protocol_contract root_swiftpm routine 1 Only GLM-compatible launches receive the required valid identity-preamble argument. Provider launch arguments could become invalid or leak GLM-only behavior to other variants. 0.000000 test_case retain 0 Authoritative test-list reconciliation for the current integration worktree. root/RepoPromptTests.ClaudeNativeIdentityPreambleTests/testNonGLMVariantsDoNotAppendIdentityPreambleFlag root Tests/RepoPromptTests/AgentMode/ClaudeCompatible/ClaudeNativeIdentityPreambleTests.swift RepoPromptTests.ClaudeNativeIdentityPreambleTests testNonGLMVariantsDoNotAppendIdentityPreambleFlag AgentMode claude_compatible.identity_preamble glm,launch_arguments,provider_variant protocol_contract root_swiftpm routine 1 Only GLM-compatible launches receive the required valid identity-preamble argument. Provider launch arguments could become invalid or leak GLM-only behavior to other variants. 0.000000 test_case retain 0 Authoritative test-list reconciliation for the current integration worktree. -root/RepoPromptTests.CollapsibleUserMessageTests/testPreviewBoundsLargeBridgedStringAtThreshold root Tests/RepoPromptTests/CollapsibleUserMessageTests.swift RepoPromptTests.CollapsibleUserMessageTests testPreviewBoundsLargeBridgedStringAtThreshold UI collapsible_user_message.bounded_bridged_preview performance,bridged_string,grapheme_limit pure_logic root_swiftpm routine 1 LargeBridgedStringFixture A million-character bridged string is classified as collapsible and produces exactly the 500-grapheme preview. Bridged storage or grapheme-offset changes could misclassify the message or split or extend the preview past the 500-character boundary. 0.038000 large_string test_case retain 0 Sentry REPOPROMPT-8W bridged-input regression; traversal complexity is enforced structurally by the limitedBy implementation, not a timing assertion. -root/RepoPromptTests.CollapsibleUserMessageTests/testPreviewUsesThresholdEqualityAndGraphemeBoundaries root Tests/RepoPromptTests/CollapsibleUserMessageTests.swift RepoPromptTests.CollapsibleUserMessageTests testPreviewUsesThresholdEqualityAndGraphemeBoundaries UI collapsible_user_message.threshold_and_grapheme_semantics threshold,equality,unicode,grapheme_cluster pure_logic root_swiftpm routine 7 UnicodeGraphemeTable Empty, zero-limit, exact-threshold, over-threshold, emoji-cluster, and decomposed-scalar inputs preserve collapse and preview semantics. A bounded optimization could collapse exact-threshold text or split an extended grapheme cluster. 0.001000 test_case retain 0 Sentry REPOPROMPT-8W semantic boundary regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testAgedBackgroundAdmissionIsOwnerFair root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testAgedBackgroundAdmissionIsOwnerFair CodeMap codemap.coordinator.aged_background_owner_fairness background_age_promotion,least_recent_owner,owner_history,exact_admission_order scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorClockGateFixture Once both background flights are aged, the fresh owner is admitted before the repeated owner that supplied the active blocker. Age promotion could discard owner history and let one owner monopolize the background queue. 0.011000 concurrency temporary_directory test_case retain 0 Background age-promotion owner-fairness regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testAgedBackgroundAdmitsAfterForegroundBound root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testAgedBackgroundAdmitsAfterForegroundBound CodeMap codemap.coordinator.aged_background_foreground_bound background_age_promotion,foreground_bound,demand_priority,exact_admission_order,telemetry scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorClockGateFixture After exactly two non-background admissions while background work is aged, the background flight is admitted before the third demand and the aged-background counters report the exact bound. Sustained foreground demand could exceed the configured bound and starve aged background work, or telemetry could hide the violation. 0.016500 concurrency temporary_directory test_case retain 0 Exact aged-background bounded-progress regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testAgedExplicitAdmissionPrecedesNewerDemandDespiteOwnerHistory root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testAgedExplicitAdmissionPrecedesNewerDemandDespiteOwnerHistory CodeMap codemap.coordinator.aged_explicit_progress age_promotion,newer_demand,owner_history,starvation_bound scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorClockGateFixture An explicit flight aged to the configured threshold is admitted before newer demand even when its owner was admitted most recently. Fresh demand owners could indefinitely beat age-promoted explicit work after promotion. 0.011000 concurrency temporary_directory test_case retain 0 Phase 5B aged explicit bounded progress @@ -761,7 +694,6 @@ root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testCancelledLocatorWa root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testCancellingOneWaiterDoesNotCancelSharedWork root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testCancellingOneWaiterDoesNotCancelSharedWork CodeMap codemap.coordinator.waiter_cancellation_isolation same_key_join,one_waiter_cancel,shared_completion concurrency_contract root_swiftpm routine 2 CodeMapCoordinatorGateFixture Cancelling one of two same-key waiters resumes only that waiter with cancellation while one shared build completes for the owner. One caller could cancel shared work still owned by another waiter. 0.005000 concurrency temporary_directory test_case retain 0 Phase 5B waiter-scoped cancellation root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testCoordinatorPersistenceContainsNoSourcePaths root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testCoordinatorPersistenceContainsNoSourcePaths CodeMap codemap.coordinator.path_free_observability source_sentinel,cas_files,locator_files,hook_events privacy_contract root_swiftpm routine 3 CodeMapCoordinatorPathSentinelFixture Persistent filenames, persistent bytes, and hook events exclude the source path sentinel and expose only digest identity. Coordinator persistence or diagnostics could leak workspace paths or source bytes. 0.220000 filesystem,security temporary_directory test_case retain 0 Phase 5B path-free persistence and hooks root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDefaultBuilderClientPhase5AQueueFullMapsToCoordinatorBusy root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testDefaultBuilderClientPhase5AQueueFullMapsToCoordinatorBusy CodeMap codemap.coordinator.default_admission_busy_mapping default_builder_client,phase5a_queue_full,retry_metadata,clean_flight bounded_concurrency root_swiftpm routine 1 CodeMapCoordinatorAdmissionFixture The default builder client preserves Phase 5A owner and priority admission and maps deterministic queue saturation to coordinator busy with the scheduler retry delay. Default admission wiring could leak a scheduler error, misclassify it as a build failure, or lose retry guidance. 0.003000 concurrency temporary_directory test_case retain 0 Phase 5B default Phase 5A admission mapping -root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDefaultEffectivePermitBoundRunsRealMixedLanguageParsesAndMatchesSerialGoldens root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testDefaultEffectivePermitBoundRunsRealMixedLanguageParsesAndMatchesSerialGoldens CodeMap codemap.syntax.effective_bulk_permit_bound default_effective_bulk_permit_bound,production_permit_path,host_width_queue_accounting,real_build_parallelism_when_capacity_allows,mixed_language,serial_byte_equivalence concurrency_contract root_swiftpm integration 6 CodeMapInlineMixedLanguageSources,CodeMapPermitGate,CodeMapArtifactBuilderClient The default coordinator equals the effective CodeMap bulk-permit cap; production permit-backed Swift, Python, TypeScript, and Go builds fill that cap, remaining work stays queued, and every concurrent artifact is byte-identical to its serial Core-owned outcome. Coordinator admission could exceed the bulk permit cap and park builds, consume the reserved foreground slot, serialize eligible work, corrupt cross-language captures, or change published artifacts. 0.500000 filesystem,concurrency,cpu codemap_core_static_query_cache,process_wide_content_limiter,temporary_directory test_case retain 0 Item 5 post-extraction production-permit bounded Core parse regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDemandAdmissionUsesLeastRecentlyAdmittedOwnerBeforeEnqueueOrder root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testDemandAdmissionUsesLeastRecentlyAdmittedOwnerBeforeEnqueueOrder CodeMap codemap.coordinator.owner_fair_admission demand_priority,least_recent_owner,enqueue_order scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorGateFixture A fresh demand owner is admitted before an earlier-enqueued demand from the owner most recently admitted. Demand scheduling could ignore owner history and let one owner monopolize admission by enqueue order. 0.010500 concurrency temporary_directory test_case retain 0 Phase 5B deterministic least-recent owner ordering root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDemandJoinUpgradesQueuedBackgroundFlight root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testDemandJoinUpgradesQueuedBackgroundFlight CodeMap codemap.coordinator.queued_flight_priority_upgrade background_flight,demand_join,owner_upgrade,priority_upgrade,single_build,admission_accounting scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorClockGateFixture A demand waiter joining a queued background flight moves the shared flight ahead of explicit work, builds it once under the demand owner and priority, and records one join and demand admission. A queued shared flight could retain stale background priority or owner, delaying demand work or spawning a duplicate build. 0.011500 concurrency temporary_directory test_case retain 0 Queued shared-flight demand-upgrade regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDemandPriorityOwnerFairnessAndForegroundSuppression root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testDemandPriorityOwnerFairnessAndForegroundSuppression CodeMap codemap.coordinator.fair_admission foreground_suppression,demand_priority,owner_fairness,explicit_progress scheduler_contract root_swiftpm routine 4 CodeMapCoordinatorAdmissionFixture The Phase 5A permit blocks builds during foreground activity, then coordinator demand ordering and owner fairness precede explicit work. Codemap builds could starve foreground reads or lower-priority owners indefinitely. 0.018500 concurrency process_wide_content_limiter,temporary_directory test_case retain 0 Phase 5B scheduling atop Phase 5A @@ -771,7 +703,6 @@ root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testDistinctKeysRespec root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testEarlyLocatorReadFailureIsTypedAccountedAndRetryable root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testEarlyLocatorReadFailureIsTypedAccountedAndRetryable CodeMap codemap.coordinator.early_failure_accounting locator_read_failure,typed_error,request_failure_reconciliation,clean_retry recovery_contract root_swiftpm routine 2 CodeMapCoordinatorLocatorFailureFixture A locator-store read failure returns the typed coordinator error, accounts one entered request and one failure without flight or retained-byte state, then succeeds on retry. An early security-relevant store failure could leak an implementation error, bypass failure accounting, retain source state, or poison retry. 0.284500 filesystem,security,concurrency temporary_directory test_case retain 0 Phase 5B typed early-failure accounting root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testExplicitAdmissionOccursAtConfiguredConsecutiveDemandLimit root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testExplicitAdmissionOccursAtConfiguredConsecutiveDemandLimit CodeMap codemap.coordinator.explicit_burst_bound consecutive_demand_limit,explicit_progress,exact_admission_order scheduler_contract root_swiftpm routine 1 CodeMapCoordinatorGateFixture After exactly the configured two consecutive demand admissions, queued explicit work is admitted before additional demand. Demand bursts could exceed the configured bound and starve ordinary explicit work. 0.014000 concurrency temporary_directory test_case retain 0 Phase 5B exact demand burst bound root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testHookOverflowDropsNewestPreservesAcceptedFIFOAndDrainsWithoutLeak root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testHookOverflowDropsNewestPreservesAcceptedFIFOAndDrainsWithoutLeak CodeMap codemap.coordinator.hook_overflow blocked_consumer,pending_bound,drop_newest,drop_accounting,fifo,drain_cleanup bounded_concurrency root_swiftpm routine 1 CodeMapCoordinatorHookBackpressureFixture With the consumer blocked, the dispatcher retains exactly its configured pending bound, drops the two newest overflow events, reports them monotonically, preserves the accepted FIFO prefix, and drains to idle. A blocked nonthrowing hook could grow memory, silently lose unaccounted events, reorder accepted diagnostics, or leak its drain task. 0.005500 concurrency temporary_directory test_case retain 0 Phase 5B bounded hook overflow accounting -root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testLastWaiterCancellationAtConcurrentBoundDoesNotDisturbPeerOrQueuedAdmission root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testLastWaiterCancellationAtConcurrentBoundDoesNotDisturbPeerOrQueuedAdmission CodeMap codemap.coordinator.concurrent_cancellation_isolation two_active_builds,one_queued,last_waiter_cancel,nonpreemptive_completion,peer_isolation,queued_admission cancellation_contract root_swiftpm routine 3 CodeMapCoordinatorGateFixture At a two-build concurrency bound, cancelling the last waiter of one admitted transaction leaves both admitted slots stable until release, preserves the peer, admits the queued build afterward, and durably completes all three builds. Last-waiter cancellation at N>1 could corrupt active-slot accounting, cancel an unrelated peer, strand queued work, or drop the already-admitted transaction. 0.010000 filesystem,concurrency temporary_directory test_case retain 0 Item 5 bounded-concurrency cancellation regression. root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testLastWaiterCancellationBeforeBuildPerformsNoBuildOrWrite root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testLastWaiterCancellationBeforeBuildPerformsNoBuildOrWrite CodeMap codemap.coordinator.pre_admission_orphan queued_flight,last_waiter_cancel,no_build,no_write cancellation_contract root_swiftpm routine 3 CodeMapCoordinatorGateFixture A queued flight losing its final waiter is removed before admission without builder execution or CAS persistence. Orphaned queued work could consume foreground capacity and write unused artifacts. 0.006500 filesystem,concurrency temporary_directory test_case retain 0 Phase 5B pre-admission cancellation root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testLastWaiterCancellationDuringNonPreemptiveBuildCompletesAdmittedTransaction root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testLastWaiterCancellationDuringNonPreemptiveBuildCompletesAdmittedTransaction CodeMap codemap.coordinator.nonpreemptive_durable_publication nonpreemptive_build,last_waiter_cancel,waiter_detachment,cas_persistence,locator_publication cancellation_contract root_swiftpm routine 3 CodeMapCoordinatorGateFixture After build admission, final-waiter cancellation detaches only the caller while the shared transaction durably persists the CAS artifact and publishes the final waiter's locator. Final-waiter cancellation could leave an admitted artifact or locator unpublished and make the completed result undiscoverable. 0.460000 filesystem,concurrency temporary_directory test_case retain 0 Codemap hydration remediation Slice 1 durable final-waiter publication root/RepoPromptTests.CodeMapArtifactBuildCoordinatorTests/testLocatorInputRequiresExactCleanGitBlobProvenanceForSHA1AndSHA256 root Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift RepoPromptTests.CodeMapArtifactBuildCoordinatorTests testLocatorInputRequiresExactCleanGitBlobProvenanceForSHA1AndSHA256 CodeMap codemap.coordinator.git_blob_validation clean_git_blob,repository_namespace,object_format,sha1,sha256,pipeline_match,artifact_key_match,typed_validation_error,pre_request_accounting validation_contract root_swiftpm routine 4 CodeMapCoordinatorGitBlobFixture Locator-associated source input requires exact clean-Git provenance and accepts both SHA-1 and SHA-256; validated-worktree, namespace, object-format, OID, pipeline, and artifact-key mismatches return typed errors before store access. A locator could associate validated-worktree or clean bytes with an unrelated repository namespace, Git object identity, pipeline, or artifact key. 0.554500 security syntax_manager,temporary_directory test_case retain 0 Phase 5B conservative Git blob validation and typed pre-request invariant @@ -798,16 +729,15 @@ root/RepoPromptTests.CodeMapArtifactContainerTests/testRecoveryRemovesOnlyStrict root/RepoPromptTests.CodeMapArtifactContainerTests/testRootsComponentsShardsAndLeavesRejectSymlinkTypeModeAndContainmentAttacks root Tests/RepoPromptTests/CodeMap/CodeMapArtifactContainerTests.swift RepoPromptTests.CodeMapArtifactContainerTests testRootsComponentsShardsAndLeavesRejectSymlinkTypeModeAndContainmentAttacks CodeMap codemap.cas_file_store.path_hardening root_walk,openat,no_follow,owner_mode,regular_file,containment,traversal security_contract root_swiftpm routine 8 CodeMapArtifactFileStoreAttackFixture Unsafe root mode, symlink root/component/leaf, nonregular directory/FIFO leaves, unsafe leaf mode, and traversal root are rejected without serving or escaping. A hostile cache tree could redirect reads/writes outside the explicit root or make unsafe objects trusted artifacts. 0.005000 filesystem temporary_directory test_case retain 0 Phase 3 Item 2 immutable container and hardened file persistence root/RepoPromptTests.CodeMapArtifactContainerTests/testStrictFramingRejectsEveryTruncationTrailingBytesAndConfiguredBounds root Tests/RepoPromptTests/CodeMap/CodeMapArtifactContainerTests.swift RepoPromptTests.CodeMapArtifactContainerTests testStrictFramingRejectsEveryTruncationTrailingBytesAndConfiguredBounds CodeMap codemap.cas_container.bounded_decode all_prefix_truncations,trailing_bytes,payload_cap,collection_cap,string_cap,json_depth,json_tokens,encode_cap bounded_decoder root_swiftpm routine 1582 CodeMapArtifactContainerMalformedFixture Every one of 1575 truncated prefixes plus trailing bytes and configured payload, collection, string, JSON nesting, JSON token, and encode bounds are rejected before unbounded decode. Malformed disk bytes could cause allocation amplification, partial acceptance, or trailing-data ambiguity. 0.119000 test_case retain 0 Phase 3 Item 2 immutable container and hardened file persistence root/RepoPromptTests.CodeMapArtifactContainerTests/testStrictFramingRejectsKeySchemaKindLengthChecksumSummaryAndPayloadFaults root Tests/RepoPromptTests/CodeMap/CodeMapArtifactContainerTests.swift RepoPromptTests.CodeMapArtifactContainerTests testStrictFramingRejectsKeySchemaKindLengthChecksumSummaryAndPayloadFaults CodeMap codemap.cas_container.strict_verification magic,version,header,key,filename,schema,kind,length,checksum,summary,payload,canonical_json mutation_matrix root_swiftpm routine 18 CodeMapArtifactContainerMalformedFixture Eighteen independent framing and payload mutations are rejected at their strict key, filename, schema, kind, length, checksum, summary, decode, or canonical-payload boundary. Corrupt or malicious bytes could alias a valid immutable key/outcome or bypass structural integrity checks. 0.002000 test_case retain 0 Phase 3 Item 2 immutable container and hardened file persistence -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testArtifactKeyRejectsSourceAndPipelineDecoderPolicyMismatch root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testArtifactKeyRejectsSourceAndPipelineDecoderPolicyMismatch CodeMap codemap.cas_key.decoder_policy_match source_policy,pipeline_policy,mismatch_rejection negative_contract codemap_core routine 1 CodeMapCoreSourceSnapshotFixture A source snapshot whose decoder policy differs from the pipeline identity is rejected with the typed decoder-policy-mismatch error before key construction. A decoder-policy mismatch could reuse an artifact produced from different source-text semantics. 0.000000 test_case retain 0 Phase 3 accepted decoder-policy mismatch regression; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testCanonicalPipelineAndKeyMatchIndependentReferenceEncoder root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testCanonicalPipelineAndKeyMatchIndependentReferenceEncoder CodeMap codemap.cas_key.reference_encoding independent_encoder,domain_separation,big_endian,round_trip,storage_sha256 serialization_contract codemap_core routine 2 CodeMapPipelineIdentityFixture,CodeMapCoreSourceSnapshotFixture An independent test encoder exactly matches production pipeline and artifact-key bytes, the storage digest, and byte-identical strict decode/re-encode. A platform hash, Codable order, field omission, or framing drift could split or alias the content-addressed namespace. 0.000500 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 independent canonical encoder contract; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testEveryPipelineComponentLimitAndFlagChangesCanonicalKey root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testEveryPipelineComponentLimitAndFlagChangesCanonicalKey CodeMap codemap.cas_key.component_sensitivity language,decoder,grammar,abi,query,semantic_versions,schema,policy,limits,flags,raw_digest,byte_count mutation_matrix codemap_core routine 25 CodeMapPipelineIdentityFixture,CodeMapCoreSourceSnapshotFixture Every identity field, semantic-version component, required limit, explicit true/false flag, raw digest, and byte count mutation changes canonical key storage identity; an unknown decoder ID is rejected. A behavior-affecting pipeline or raw-source change could reuse a stale artifact key. 0.002000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 complete identity mutation matrix; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testFixedCanonicalKeyBytesAndStorageDigestGolden root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testFixedCanonicalKeyBytesAndStorageDigestGolden CodeMap codemap.cas_key.fixed_golden fixed_identity,canonical_bytes,storage_digest,runtime_identity_independent serialization_contract codemap_core routine 1 CodeMapArtifactKeyGoldenFixture A fully fixed synthetic pipeline and raw digest produce one committed canonical-byte base64 value and storage SHA-256 independent of the runtime language registry. Canonical framing or digest behavior could drift while a runtime-derived reference encoder changes in lockstep. 0.000000 test_case retain 0 Phase 3 accepted fixed canonical byte and digest golden; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptTests.CodeMapSourceSnapshotAdapterTests/testCoreAdapterPreservesRawProvenanceAndDecodedTextWithoutReread root Tests/RepoPromptTests/CodeMap/CodeMapSourceSnapshotAdapterTests.swift RepoPromptTests.CodeMapSourceSnapshotAdapterTests testCoreAdapterPreservesRawProvenanceAndDecodedTextWithoutReread CodeMap codemap.source.core_adapter_raw_provenance repetition,validation_identity_independence,byte_distinct_encodings,decoded_text_equivalence adapter_contract root_swiftpm routine 3 CodeMapSourceSnapshotFixture The app-owned validated snapshot projects exact raw digest/count, decoder policy, and decoded text into the provenance-free core value without reread; validation fingerprints do not affect the key while byte-distinct encodings do. The app adapter could rehash/redecode, leak validation identity into core values, or collapse byte-distinct source identities. 0.000000 tree_sitter syntax_manager test_case retain 0 Item 3 split from CodeMapArtifactKeyTests; app owns provenance/decoding adapter only -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testLanguageRegistryCoversEveryLanguageAndUsesExactRegisteredQueryBytes root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testLanguageRegistryCoversEveryLanguageAndUsesExactRegisteredQueryBytes CodeMap codemap.pipeline.authoritative_registry all_languages,stable_ids,package_revisions,live_abi,exact_query_digest,typescript_tsx registry_contract codemap_core routine 13 CodeMapSyntaxEnginePipelineRegistryFixture All LanguageType cases have unique stable IDs, Package.swift revisions, live nonzero grammar ABI values, and SHA-256 of the exact registered query bytes; TS and TSX remain distinct IDs while sharing query and revision. A package pin, grammar object, query compiler input, or language mapping could drift from pipeline identity and serve incompatible artifacts. 0.002000 tree_sitter syntax_manager test_case retain -1 Phase 3 Item 1 exhaustive authoritative language registry; Item 3 owner moved to RepoPromptCodeMapCoreTests; Dart scenario removed alongside active Dart CodeMap support -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testStorageDigestAndShardAreIdentityFreeDigestOnlyNames root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testStorageDigestAndShardAreIdentityFreeDigestOnlyNames CodeMap codemap.cas_key.identity_free_storage_name lowercase_hex,shard,digest_only,path_root_session_exclusion privacy_contract codemap_core routine 1 CodeMapCoreSourceSnapshotFixture Storage identity is exactly 64 lowercase hexadecimal SHA-256 characters, its shard is the first two characters, and neither exposes path/root/worktree/session sentinels. Artifact filenames or shard layout could leak source or workspace identity instead of using opaque content identity. 0.000000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 digest-only storage naming contract; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testStrictKeyDecoderRejectsNoncanonicalFraming root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testStrictKeyDecoderRejectsNoncanonicalFraming CodeMap codemap.cas_key.strict_decode all_prefix_truncations,size_cap,trailing_bytes,domain,pipeline_length bounded_decoder codemap_core routine 572 CodeMapArtifactKeyMalformedFixture Every truncated canonical-key prefix plus oversize, trailing-byte, wrong-domain, and mismatched pipeline-length inputs are rejected. Malformed key framing could permit ambiguous identities, out-of-bounds reads, or allocation amplification before container verification. 0.001000 test_case retain 0 Phase 3 Item 1 strict bounded artifact-key decoder; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testStrictPipelineDecoderRejectsNoncanonicalAndMalformedInputs root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testStrictPipelineDecoderRejectsNoncanonicalAndMalformedInputs CodeMap codemap.pipeline.strict_decode all_prefix_truncations,size_cap,trailing_bytes,domain,utf8,versions,required_fields,ordering,duplicates,booleans bounded_decoder codemap_core routine 524 CodeMapPipelineIdentityMalformedFixture Every truncated pipeline prefix and malformed domain, UTF-8, revision, version, count, required-field set, name order, duplicate, boolean, oversize, or trailing-byte case is rejected. Noncanonical pipeline bytes could alias semantic identities, admit unknown policy, or amplify corrupt input during container decode. 0.005000 test_case retain 0 Phase 3 Item 1 strict bounded pipeline decoder; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests/testConcurrentAllLanguageBuildsAndQueryInitializationAreDeterministic root Tests/RepoPromptCodeMapCoreTests/CodeMapArtifactKeyTests.swift RepoPromptCodeMapCoreTests.CodeMapArtifactKeyTests testConcurrentAllLanguageBuildsAndQueryInitializationAreDeterministic CodeMap codemap.pipeline.concurrent_determinism all_languages,query_initialization,parallel_builds,exact_outcomes concurrency_contract codemap_core routine 13 CodeMapCoreSourceSnapshotFixture,CodeMapSyntaxEngineRegistry Eight concurrent first-use builds for every registered language produce one exact canonical outcome per language, equal to a serial build. Lazy query initialization or shared mutable parser state could race, crash, or produce schedule-dependent artifacts. 0.050000 tree_sitter,concurrency test_case retain -1 Item 3 explicit concurrent all-language and query-initialization proof; Dart scenario removed alongside active Dart CodeMap support +root/RepoPromptTests.CodeMapArtifactKeyTests/testArtifactKeyRejectsSourceAndPipelineDecoderPolicyMismatch root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testArtifactKeyRejectsSourceAndPipelineDecoderPolicyMismatch CodeMap codemap.cas_key.decoder_policy_match source_policy,pipeline_policy,mismatch_rejection negative_contract root_swiftpm routine 1 CodeMapSourceSnapshotFixture A source snapshot whose decoder policy differs from the pipeline identity is rejected with the typed decoder-policy-mismatch error before key construction. A decoder-policy mismatch could reuse an artifact produced from different source-text semantics. 0.000000 test_case retain 0 Phase 3 accepted decoder-policy mismatch regression +root/RepoPromptTests.CodeMapArtifactKeyTests/testCanonicalPipelineAndKeyMatchIndependentReferenceEncoder root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testCanonicalPipelineAndKeyMatchIndependentReferenceEncoder CodeMap codemap.cas_key.reference_encoding independent_encoder,domain_separation,big_endian,round_trip,storage_sha256 serialization_contract root_swiftpm routine 2 CodeMapPipelineIdentityFixture,CodeMapSourceSnapshotFixture An independent test encoder exactly matches production pipeline and artifact-key bytes, the storage digest, and byte-identical strict decode/re-encode. A platform hash, Codable order, field omission, or framing drift could split or alias the content-addressed namespace. 0.000500 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 independent canonical encoder contract +root/RepoPromptTests.CodeMapArtifactKeyTests/testEveryPipelineComponentLimitAndFlagChangesCanonicalKey root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testEveryPipelineComponentLimitAndFlagChangesCanonicalKey CodeMap codemap.cas_key.component_sensitivity language,decoder,grammar,abi,query,semantic_versions,schema,policy,limits,flags,raw_digest,byte_count mutation_matrix root_swiftpm routine 25 CodeMapPipelineIdentityFixture,CodeMapSourceSnapshotFixture Every identity field, semantic-version component, required limit, explicit true/false flag, raw digest, and byte count mutation changes canonical key storage identity; an unknown decoder ID is rejected. A behavior-affecting pipeline or raw-source change could reuse a stale artifact key. 0.002000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 complete identity mutation matrix +root/RepoPromptTests.CodeMapArtifactKeyTests/testFixedCanonicalKeyBytesAndStorageDigestGolden root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testFixedCanonicalKeyBytesAndStorageDigestGolden CodeMap codemap.cas_key.fixed_golden fixed_identity,canonical_bytes,storage_digest,runtime_identity_independent serialization_contract root_swiftpm routine 1 CodeMapArtifactKeyGoldenFixture A fully fixed synthetic pipeline and raw digest produce one committed canonical-byte base64 value and storage SHA-256 independent of the runtime language registry. Canonical framing or digest behavior could drift while a runtime-derived reference encoder changes in lockstep. 0.000000 test_case retain 0 Phase 3 accepted fixed canonical byte and digest golden +root/RepoPromptTests.CodeMapArtifactKeyTests/testKeyUsesRawSnapshotProvenanceWithoutRereadOrValidationIdentity root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testKeyUsesRawSnapshotProvenanceWithoutRereadOrValidationIdentity CodeMap codemap.cas_key.raw_provenance repetition,validation_identity_independence,byte_distinct_encodings,decoded_text_equivalence pure_model root_swiftpm routine 3 CodeMapSourceSnapshotFixture Repeated exact bytes under different validation fingerprints produce one key while UTF-8 and BOM UTF-16 bytes decoding to equal text produce distinct keys. Key construction could reread, hash decoded text, or leak filesystem validation identity into reusable content identity. 0.000000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 exact snapshot provenance contract +root/RepoPromptTests.CodeMapArtifactKeyTests/testLanguageRegistryCoversEveryLanguageAndUsesExactRegisteredQueryBytes root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testLanguageRegistryCoversEveryLanguageAndUsesExactRegisteredQueryBytes CodeMap codemap.pipeline.authoritative_registry all_languages,stable_ids,package_revisions,live_abi,exact_query_digest,typescript_tsx registry_contract root_swiftpm routine 14 SyntaxManagerPipelineRegistryFixture All LanguageType cases have unique stable IDs, Package.swift revisions, live nonzero grammar ABI values, and SHA-256 of the exact registered query bytes; TS and TSX remain distinct IDs while sharing query and revision. A package pin, grammar object, query compiler input, or language mapping could drift from pipeline identity and serve incompatible artifacts. 0.002000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 exhaustive authoritative language registry +root/RepoPromptTests.CodeMapArtifactKeyTests/testStorageDigestAndShardAreIdentityFreeDigestOnlyNames root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testStorageDigestAndShardAreIdentityFreeDigestOnlyNames CodeMap codemap.cas_key.identity_free_storage_name lowercase_hex,shard,digest_only,path_root_session_exclusion privacy_contract root_swiftpm routine 1 CodeMapSourceSnapshotFixture Storage identity is exactly 64 lowercase hexadecimal SHA-256 characters, its shard is the first two characters, and neither exposes path/root/worktree/session sentinels. Artifact filenames or shard layout could leak source or workspace identity instead of using opaque content identity. 0.000000 tree_sitter syntax_manager test_case retain 0 Phase 3 Item 1 digest-only storage naming contract +root/RepoPromptTests.CodeMapArtifactKeyTests/testStrictKeyDecoderRejectsNoncanonicalFraming root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testStrictKeyDecoderRejectsNoncanonicalFraming CodeMap codemap.cas_key.strict_decode all_prefix_truncations,size_cap,trailing_bytes,domain,pipeline_length bounded_decoder root_swiftpm routine 572 CodeMapArtifactKeyMalformedFixture Every truncated canonical-key prefix plus oversize, trailing-byte, wrong-domain, and mismatched pipeline-length inputs are rejected. Malformed key framing could permit ambiguous identities, out-of-bounds reads, or allocation amplification before container verification. 0.001000 test_case retain 0 Phase 3 Item 1 strict bounded artifact-key decoder +root/RepoPromptTests.CodeMapArtifactKeyTests/testStrictPipelineDecoderRejectsNoncanonicalAndMalformedInputs root Tests/RepoPromptTests/CodeMap/CodeMapArtifactKeyTests.swift RepoPromptTests.CodeMapArtifactKeyTests testStrictPipelineDecoderRejectsNoncanonicalAndMalformedInputs CodeMap codemap.pipeline.strict_decode all_prefix_truncations,size_cap,trailing_bytes,domain,utf8,versions,required_fields,ordering,duplicates,booleans bounded_decoder root_swiftpm routine 524 CodeMapPipelineIdentityMalformedFixture Every truncated pipeline prefix and malformed domain, UTF-8, revision, version, count, required-field set, name order, duplicate, boolean, oversize, or trailing-byte case is rejected. Noncanonical pipeline bytes could alias semantic identities, admit unknown policy, or amplify corrupt input during container decode. 0.005000 test_case retain 0 Phase 3 Item 1 strict bounded pipeline decoder root/RepoPromptTests.CodeMapArtifactRuntimeTests/testBindingEngineProviderIsInertAndMemoizesOneEngineAcrossConcurrentCallers root Tests/RepoPromptTests/CodeMap/CodeMapArtifactRuntimeTests.swift RepoPromptTests.CodeMapArtifactRuntimeTests testBindingEngineProviderIsInertAndMemoizesOneEngineAcrossConcurrentCallers CodeMap codemap.runtime.binding_engine_provider_singleton inert_factory,concurrent_callers,reference_identity concurrency_contract root_swiftpm routine 3 RuntimeProviderOverlapGate The runtime does not construct an engine until requested and all overlapping callers receive one reference-identical actor. Concurrent process consumers could bypass global engine limits by constructing distinct actors. 0.003000 filesystem,concurrency test_case retain 0 Slice 2B2 process-shared inert engine ownership root/RepoPromptTests.CodeMapArtifactRuntimeTests/testBindingEngineProviderMemoizesUnconfiguredFailureWithoutFallback root Tests/RepoPromptTests/CodeMap/CodeMapArtifactRuntimeTests.swift RepoPromptTests.CodeMapArtifactRuntimeTests testBindingEngineProviderMemoizesUnconfiguredFailureWithoutFallback CodeMap codemap.runtime.binding_engine_provider_unconfigured unconfigured,memoized_failure,no_fallback ownership_contract root_swiftpm routine 2 An unconfigured runtime reports the same cached typed failure without constructing fallback engine state. An implicit fallback could create unbounded hidden engine ownership. 0.002000 test_case retain 0 Slice 2B2 inert provider failure contract root/RepoPromptTests.CodeMapArtifactRuntimeTests/testDefaultDebugProviderDoesNotScheduleApplicationSupportCleanup root Tests/RepoPromptTests/CodeMap/CodeMapArtifactRuntimeTests.swift RepoPromptTests.CodeMapArtifactRuntimeTests testDefaultDebugProviderDoesNotScheduleApplicationSupportCleanup CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002500 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage @@ -864,43 +794,18 @@ root/RepoPromptTests.CodeMapArtifactStoreTests/testTypedCrashOrphansRepairInvent root/RepoPromptTests.CodeMapBuildAdmissionTests/testCancellingQueuedCodemapBuildAdmissionRemovesWaiterWithoutPermitLeak root Tests/RepoPromptTests/Services/FileSystem/CodeMapBuildAdmissionTests.swift RepoPromptTests.CodeMapBuildAdmissionTests testCancellingQueuedCodemapBuildAdmissionRemovesWaiterWithoutPermitLeak CodeMap codemap.build_admission.queued_cancellation foreground_suppression,waiter_cleanup,permit_ownership,idle_state deterministic_concurrency root_swiftpm routine 1 ContentReadAsyncLimiter,CodeMapAdmissionSignal Cancelling a codemap build while a real foreground token suppresses admission throws CancellationError, never starts the operation, removes its owner lane and waiter, grants no permit, and returns to idle after token release. A cancelled queued build could execute, consume or leak a permit, retain owner scheduling state, or remain queued indefinitely. 0.013000 async_tasks,cancellation_gates per_test_limiter task_cancel_await+explicit_token_cleanup retain 0 Phase 5A existing-limiter cancellation contract root/RepoPromptTests.CodeMapBuildAdmissionTests/testCodemapBuildAdmissionPreservesForegroundPriorityAndOwnerRoundRobin root Tests/RepoPromptTests/Services/FileSystem/CodeMapBuildAdmissionTests.swift RepoPromptTests.CodeMapBuildAdmissionTests testCodemapBuildAdmissionPreservesForegroundPriorityAndOwnerRoundRobin CodeMap codemap.build_admission.existing_scheduler_metadata foreground_precedence,owner_round_robin,owner_fifo,task_priority,bulk_accounting deterministic_concurrency root_swiftpm routine 2 ContentReadAsyncLimiter,CodeMapAdmissionGate,CodeMapAdmissionRecorder A content-search waiter queued after codemap builds is admitted first, then codemap requests alternate owners while preserving owner FIFO, execute at no less than requested task priority, and retain exact normal/bulk accounting. The admission seam could bypass foreground priority, discard owner identity, reorder one owner's work, ignore execution priority, or classify builds outside the established codemap counters. 0.057500 async_tasks,cancellation_gates per_test_limiter task_join+gate_release retain 0 Phase 5A owner and priority metadata contract root/RepoPromptTests.CodeMapBuildAdmissionTests/testProcessWideCodemapBuildAdmissionWaitsForForegroundActivityAndUsesRequestedPriority root Tests/RepoPromptTests/Services/FileSystem/CodeMapBuildAdmissionTests.swift RepoPromptTests.CodeMapBuildAdmissionTests testProcessWideCodemapBuildAdmissionWaitsForForegroundActivityAndUsesRequestedPriority CodeMap codemap.build_admission.process_wide_foreground_gate process_wide_singleton,root_load_token,task_priority,codemap_accounting deterministic_concurrency root_swiftpm routine 2 CodeMapAdmissionGate,CodeMapAdmissionSignal The process-wide wrapper queues without starting or granting during a real root-load foreground activity, then runs at no less than requested task priority after final token release and increments only the existing bulk/codemap grant accounting. A new build path could bypass the singleton limiter, run during foreground root work, lose priority context, or introduce separate counters and capacity. 0.011500 async_tasks,cancellation_gates process_wide_content_read_limiter task_join+explicit_token_cleanup retain 0 Phase 5A process-wide wrapper contract -root/RepoPromptCodeMapCoreTests.CodeMapGoldenTests/testFixturesMatchGoldenCodeMapDescriptions root Tests/RepoPromptCodeMapCoreTests/CodeMapGoldenTests.swift RepoPromptCodeMapCoreTests.CodeMapGoldenTests testFixturesMatchGoldenCodeMapDescriptions CodeMap codemap.golden.artifact_renderer path_free_artifact,artifact_renderer,language_matrix,golden golden_snapshot codemap_core routine 13 c_smoke,cpp_edge_methods,cs_smoke,go_smoke,java_smoke,js_smoke,php_edge_namespaces,py_smoke,rb_smoke,rs_smoke,swift_smoke,ts_smoke,tsx_component Each practical-language fixture renders through the immutable artifact terminal and matches its committed golden. The artifact renderer could drift from current extraction/rendering or committed golden snapshots across the supported language matrix. 0.543500 tree_sitter,fixture_bundle syntax_manager test_case retain -1 Item 1 duplicate render removal; path-free artifact golden coverage across all 13 registered language fixtures including C#; Item 3 fixtures/goldens sole-owned by RepoPromptCodeMapCoreTests; Dart scenario removed alongside active Dart CodeMap support -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testJSTSSignatureNormalizerGeneratedASCIIEquivalenceAndCounters root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testJSTSSignatureNormalizerGeneratedASCIIEquivalenceAndCounters CodeMap codemap.query_optimization.jsts_signature_ascii_generated_equivalence javascript,typescript,tsx,signature_normalization,ascii_fast_path,deterministic_generated_corpus,legacy_equivalence,counter_accounting regression codemap_core fast 1 Two thousand deterministically generated ASCII signature strings exactly match the unchanged Character-based legacy authority while no-op and rewrite route accounting covers every input. The UTF-8 normalizer could diverge on punctuation, whitespace, or trailing-semicolon shapes or misattribute routed ASCII work. synthetic_source test_case retain 0 Iteration 1 bounded generated equivalence and route-accounting regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testJSTSSignatureNormalizerMatchesLegacyBehavior root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testJSTSSignatureNormalizerMatchesLegacyBehavior CodeMap codemap.query_optimization.jsts_signature_ascii_equivalence javascript,typescript,tsx,signature_normalization,ascii_fast_path,legacy_equivalence,whitespace,semicolon,lexical_blindness regression codemap_core fast 26 Twenty-six explicit ASCII shapes preserve lexical-blind whitespace collapse and exactly-one trailing-semicolon removal against the unchanged Character-based authority. The UTF-8 fast path could change normalized signatures for whitespace, syntax-shaped punctuation, literals, comments, templates, JSX, or repeated semicolons. test_case retain 0 Iteration 1 explicit ASCII normalization equivalence matrix. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testJSTSSignatureNormalizerRoutesSharedJavaScriptTypeScriptAndTSXPipeline root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testJSTSSignatureNormalizerRoutesSharedJavaScriptTypeScriptAndTSXPipeline CodeMap codemap.query_optimization.jsts_signature_pipeline_routes javascript,typescript,tsx,signature_normalization,pipeline_routing,counter_accounting regression codemap_core routine 3 JavaScript, TypeScript, and TSX pipeline builds exercise the shared extractor and account every normalization through exactly one ASCII or Unicode route while preserving successful artifacts. A language route could bypass normalization, double-count calls, or silently stop exercising the shared primitive. tree_sitter,synthetic_source syntax_manager test_case retain 0 Iteration 1 shared JS/TS/TSX execution and accounting regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testJSTSSignatureNormalizerUnicodeUsesLegacyFallback root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testJSTSSignatureNormalizerUnicodeUsesLegacyFallback CodeMap codemap.query_optimization.jsts_signature_unicode_fallback javascript,typescript,tsx,signature_normalization,unicode,legacy_fallback,legacy_equivalence,counter_accounting regression codemap_core fast 7 Seven non-ASCII identifier, type, spacing, and literal shapes exactly match the unchanged Character-based authority and route exclusively through Unicode fallback. Unicode input could be partially rewritten by the ASCII path or reported under the wrong mechanism route. test_case retain 0 Iteration 1 Unicode fallback and legacy-equivalence regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testNonSwiftReferencedTypeDuplicatesStillUseTypeCleanerCache root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testNonSwiftReferencedTypeDuplicatesStillUseTypeCleanerCache CodeMap codemap.query_optimization.non_swift_referenced_types_cache typescript,tsx,referenced_types,duplicate_input,type_cleaner_cache,swift_dedup_exclusion,counter_accounting regression codemap_core fast 2 TypeScript and TSX duplicate raw types preserve the same type set while the second insertion reuses the TypeCleaner cache, doubles output accounting, and leaves every Swift-only dedup counter at zero. Swift-only raw-type deduplication could leak into TypeScript or TSX, bypassing established TypeCleaner cache and output accounting behavior. test_case retain 0 Run 007 non-Swift cache-path and Swift-dedup exclusion regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testPreMaterializedSwiftAndTypeScriptGeneratorAttribution root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testPreMaterializedSwiftAndTypeScriptGeneratorAttribution CodeMap codemap.query_optimization.prematerialized_generator_attribution swift,typescript,tsx,pre_materialized_captures,generator_attribution,repeat_artifact_equality diagnostic codemap_core routine 3 Pre-materialized Swift, TypeScript, and TSX captures generate an identical artifact across repeated runs and expose generator-only capture-index and capture-loop timing attribution. Generator-only optimization could change artifact output or lose a deterministic attribution surface that separates query execution from extraction cost. tree_sitter,cpu_timing,synthetic_source syntax_manager test_case retain 0 Generator-only diagnostic timings are reported without machine-dependent thresholds. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testStructuralFastPathsPreserveRoutingAndTypes root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testStructuralFastPathsPreserveRoutingAndTypes CodeMap codemap.query_optimization.structural_routing swift,typescript,tsx,query_capture_budget,duplicate_suppression regression codemap_core routine 3 Complex Swift declarations preserve bounded parameter/type extraction, while function-only TypeScript arrows are emitted only as functions and non-function initializer text containing arrows remains a global variable. Query slimming or duplicate suppression could lose Swift type detail, duplicate TypeScript arrows as globals, or suppress ordinary variables based on initializer text. 0.312000 tree_sitter,synthetic_source syntax_manager test_case retain 0 Query-first optimization correctness and attribution contract -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftParameterFallbackSkipsNestedAttributeColons root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftParameterFallbackSkipsNestedAttributeColons CodeMap codemap.query_optimization.swift_parameter_attribute_colon swift,parameter_type_fallback,property_wrapper,string_literal,nested_delimiters,default_value regression codemap_core fast 1 A Swift parameter with a property-wrapper argument containing a colon retains its local name and exact declared type while excluding the default value. The bounded fallback could treat an attribute argument colon as the parameter declaration separator and emit a malformed type. tree_sitter,synthetic_source syntax_manager test_case retain 0 Focused regression for top-level Swift parameter delimiter scanning. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftParameterTypeASCIIFastPathGeneratedEquivalenceAndCounters root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftParameterTypeASCIIFastPathGeneratedEquivalenceAndCounters CodeMap codemap.query_optimization.swift_parameter_ascii_generated_equivalence swift,parameter_type,ascii_fast_path,deterministic_generated_corpus,legacy_equivalence,counter_accounting,utf8_byte_accounting regression codemap_core fast 1 Two thousand deterministically generated ASCII parameter strings exactly match the legacy parser while every call is attributed to the ASCII fast path with exact invocation and input-byte counters. The optimized scanner could diverge on an unanticipated ASCII delimiter shape or undercount routed work and processed bytes. synthetic_source test_case retain 0 Bounded generated equivalence and fast-path attribution regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftParameterTypeASCIIFastPathMatchesLegacyBehavior root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftParameterTypeASCIIFastPathMatchesLegacyBehavior CodeMap codemap.query_optimization.swift_parameter_ascii_equivalence swift,parameter_type,ascii_fast_path,legacy_equivalence,nested_delimiters,string_literals,malformed_input regression codemap_core fast 30 Thirty explicit ASCII parameter shapes produce the legacy parser's exact optional type result across labels, attributes, defaults, nested delimiters, strings, comments, malformed input, and missing or empty types. The ASCII fast scanner could choose the wrong top-level colon or equals sign, accept malformed nesting, or otherwise change extracted parameter types. test_case retain 0 Explicit ASCII parameter scanner equivalence matrix. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftParameterTypeUnicodeAlwaysUsesLegacyFallback root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftParameterTypeUnicodeAlwaysUsesLegacyFallback CodeMap codemap.query_optimization.swift_parameter_unicode_fallback swift,parameter_type,unicode,legacy_fallback,legacy_equivalence,counter_accounting,utf8_byte_accounting regression codemap_core fast 6 Six non-ASCII parameter shapes exactly match legacy results, never enter the ASCII fast path, and produce exact Unicode-fallback, invocation, and input-byte accounting. Unicode identifiers, types, spacing, literals, or malformed input could be misrouted through the ASCII scanner and change extraction semantics or attribution. test_case retain 0 Unicode routing and legacy-equivalence regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftPropertyTypeASCIIFastPathMatchesLegacyBehavior root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftPropertyTypeASCIIFastPathMatchesLegacyBehavior CodeMap codemap.query_optimization.swift_property_ascii_equivalence swift,property_type,ascii_fast_path,legacy_equivalence,modifiers,attributes,nested_delimiters,malformed_input regression codemap_core fast 57 Nineteen direct declarations, twenty-two modifier-prefixed declarations, and sixteen fallback declarations preserve the legacy parser's exact optional property type while the ASCII resolver selects the expected direct or fallback route. The ASCII property scanner could mis-handle declaration modifiers, attributes, nested delimiters, initializers, comments, malformed input, or missing types and change extracted property types. test_case retain 0 Run 006 explicit ASCII property scanner equivalence matrix. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftPropertyTypeGeneratedASCIIEquivalenceAndCounters root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftPropertyTypeGeneratedASCIIEquivalenceAndCounters CodeMap codemap.query_optimization.swift_property_ascii_generated_equivalence swift,property_type,ascii_fast_path,deterministic_generated_corpus,legacy_equivalence,counter_accounting,utf8_byte_accounting regression codemap_core fast 1 Two thousand deterministically generated ASCII property strings exactly match the legacy parser while direct and fallback route totals, invocation count, and input-byte accounting remain exact. The optimized scanner could diverge on an unanticipated ASCII declaration shape or undercount routed work and processed bytes. synthetic_source test_case retain 0 Run 006 bounded generated equivalence and route-attribution regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftPropertyTypePipelineRoutesTopLevelMemberProtocolAndComputedDeclarations root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftPropertyTypePipelineRoutesTopLevelMemberProtocolAndComputedDeclarations CodeMap codemap.query_optimization.swift_property_pipeline_routing swift,property_type,pipeline_routing,top_level,member,computed_property,protocol_requirement,counter_accounting regression codemap_core routine 4 A single Swift artifact preserves exact types for top-level, stored-member, computed-member, and protocol-requirement properties while routing all four through the ASCII property path with no legacy or LTE regex fallback. Pipeline routing could omit or corrupt a property type, retain computed accessor text in the name, or silently bypass the optimized property scanner for a declaration context. tree_sitter,synthetic_source syntax_manager test_case retain 0 Run 006 end-to-end property declaration-context routing regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftPropertyTypeUnicodeAlwaysUsesLegacyFallback root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftPropertyTypeUnicodeAlwaysUsesLegacyFallback CodeMap codemap.query_optimization.swift_property_unicode_fallback swift,property_type,unicode,legacy_fallback,legacy_equivalence,counter_accounting,utf8_byte_accounting regression codemap_core fast 7 Seven non-ASCII property declarations exactly match legacy results, never take an ASCII direct route, and produce exact Unicode-fallback, invocation, and input-byte accounting. Unicode identifiers, types, spacing, attributes, or literals could be misrouted through the ASCII scanner and change extraction semantics or attribution. test_case retain 0 Run 006 Unicode routing and legacy-equivalence regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftReferencedTypesDedupMatchesFreshInsertionAuthority root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftReferencedTypesDedupMatchesFreshInsertionAuthority CodeMap codemap.query_optimization.swift_referenced_types_dedup_equivalence swift,referenced_types,raw_type_dedup,fresh_insertion_authority,ordering,insert_many,unicode,prefilter regression codemap_core fast 12 Nine named raw-type sequence families plus forward and reverse orderings produce the exact union and sorted output of fresh Swift accumulator insertions, and batched insertion matches individual insertion. Raw-type deduplication could change extracted referenced types for duplicates, trimming, case, complex syntax, Unicode, filtered inputs, ordering, or the batched API. test_case retain 0 Run 007 fresh-insertion authority matrix with nine sequence, two ordering, and one batched-insertion scenarios. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftReferencedTypesDedupPreservesFirstSeenBehavior root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftReferencedTypesDedupPreservesFirstSeenBehavior CodeMap codemap.query_optimization.swift_referenced_types_first_seen swift,referenced_types,raw_type_dedup,first_seen,type_cleaner,counter_accounting regression codemap_core fast 1 A first-seen Swift generic raw type produces the fresh TypeCleaner-derived type set and sorted output with one eligible and first-seen insertion, no duplicate bytes, and internally consistent cleaner/output counters. The dedup gate could suppress a first occurrence, change its extracted type set, or misattribute first-seen cleaner work as a duplicate. test_case retain 0 Run 007 first-seen behavior and attribution regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftReferencedTypesDedupSkipsExactTrimmedDuplicates root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftReferencedTypesDedupSkipsExactTrimmedDuplicates CodeMap codemap.query_optimization.swift_referenced_types_trimmed_duplicate swift,referenced_types,raw_type_dedup,trimmed_duplicate,type_cleaner_bypass,counter_accounting,utf8_byte_accounting regression codemap_core fast 1 A whitespace-padded repeat of one Swift generic type preserves the first type set and sorted output, records one normalized duplicate and its exact UTF-8 bytes, and performs no additional TypeCleaner cache or output work. Deduplication could compare unnormalized input, re-run expensive cleaning for an equivalent type, alter output, or report incorrect duplicate accounting. test_case retain 0 Run 007 trimmed-duplicate bypass and exact counter regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftReferencedTypesPrefilterRunsBeforeDedup root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftReferencedTypesPrefilterRunsBeforeDedup CodeMap codemap.query_optimization.swift_referenced_types_prefilter_ordering swift,referenced_types,prefilter,raw_type_dedup,primitive_types,container_types,nil_empty_whitespace,counter_accounting regression codemap_core fast 7 Repeated Int, Void, Array, nil, empty, and whitespace-only Swift inputs remain empty; the four nonempty types are prefiltered with exact accounting before any dedup or TypeCleaner work. Moving dedup ahead of input and type prefilters could admit irrelevant types, count filtered duplicates, or perform unnecessary TypeCleaner work. test_case retain 0 Run 007 seven-input prefilter-ordering and zero-downstream-work regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftSignatureWhitespaceNormalizerCounters root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftSignatureWhitespaceNormalizerCounters CodeMap codemap.query_optimization.swift_signature_whitespace_counters swift,signature_whitespace,ascii_noop,ascii_rewrite,unicode_fallback,legacy_equivalence,utf8_byte_accounting instrumentation_contract codemap_core fast 3 One ASCII no-op, one ASCII rewrite, and one Unicode fallback exactly match legacy normalization while route totals and aggregate input/output UTF-8 byte counters equal the processed strings. Normalization work could be attributed to the wrong route or report incomplete byte totals, hiding fast-path regressions despite correct visible strings. test_case retain 0 Deterministic signature-normalization attribution contract. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSwiftSignatureWhitespaceNormalizerMatchesLegacyBehavior root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSwiftSignatureWhitespaceNormalizerMatchesLegacyBehavior CodeMap codemap.query_optimization.swift_signature_whitespace_equivalence swift,signature_whitespace,ascii,unicode,legacy_equivalence,string_literals,comments regression codemap_core fast 19 Nineteen explicit signature shapes exactly match legacy trimming and whitespace collapsing across ASCII runs, empty and unchanged text, literals, comments, closures, non-ASCII identifiers, and Unicode spaces. The optimized normalizer could change signature text by collapsing the wrong characters or mishandling empty, literal, comment, or Unicode content. test_case retain 0 Explicit signature whitespace equivalence matrix. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testSyntheticSwiftAndTypeScriptAttribution root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testSyntheticSwiftAndTypeScriptAttribution CodeMap codemap.query_optimization.synthetic_attribution swift,typescript,tsx,query_capture_budget,performance_attribution diagnostic codemap_core routine 3 Deterministic 200-declaration Swift, TypeScript, and TSX corpora complete successfully and report parse, capture materialization, indexing, capture-loop, regex/signature, and capture-count attribution without machine-dependent assertions. Future query changes could silently increase capture amplification or reintroduce regex/signature work without a repeatable focused measurement surface. 1.760000 tree_sitter,cpu_timing,synthetic_source syntax_manager test_case retain 0 Diagnostic timings are reported only; correctness and attribution coverage remain deterministic -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testTypeScriptAndTSXCorpusCorrectnessReference root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testTypeScriptAndTSXCorpusCorrectnessReference CodeMap codemap.query_optimization.typescript_tsx_strict_reference typescript,tsx,compile_gate,runtime_gate,write_once,exact_compare,external_local_references,atomic_cleanup,ordered_capture_tuples,canonical_artifacts regression codemap_core routine 4 TypeScriptSyntheticCorpus,TSXSyntheticCorpus,LocalCodeMapReferenceFiles When compiled with RPCE_ENABLE_BENCHMARK_TESTS=1 and enabled by RP_RUN_TYPESCRIPT_CODEMAP_REFERENCE=1, deterministic TypeScript and TSX corpora each build identical repeated artifacts; write mode exclusively creates both caller-supplied external local reference files only when neither exists and removes files created by the current attempt if the two-file write fails, while compare mode requires exact query, content, ordered-capture, artifact-digest, canonical-artifact, and capture-tuple equality for both languages. A candidate could silently drift TypeScript or TSX captures/artifacts, overwrite a baseline authority, leave a partial two-file reference set after failure, or treat a self-generated candidate artifact as correctness proof. 1.300000 tree_sitter,synthetic_source,filesystem external_tmp_reference_files caller_managed_local_references test_case retain 0 Opt-in compile/runtime-gated TS/TSX baseline authority; four language-by-mode scenarios, external files are never committed and successful references are write-once. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testTypeScriptUncontainedMembersFallThroughBeforeExtraction root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testTypeScriptUncontainedMembersFallThroughBeforeExtraction CodeMap codemap.query_optimization.ts_uncontained_fallthrough typescript,container_routing,generic_fallback,pre_extraction_guard regression codemap_core routine 7 Every TypeScript member capture family declines strategy handling before line, signature, or type extraction when no matching class or interface boundary exists. A widened TypeScript strategy gate could consume uncontained members, attach them to unrelated containers, or perform wasted extraction before fallback. tree_sitter,synthetic_source syntax_manager test_case retain 0 Direct strategy boundary regression for method, field, and interface signature captures. +root/RepoPromptTests.CodeMapGoldenTests/testFixturesMatchGoldenCodeMapDescriptions root Tests/RepoPromptTests/CodeMap/CodeMapGoldenTests.swift RepoPromptTests.CodeMapGoldenTests testFixturesMatchGoldenCodeMapDescriptions CodeMap codemap.golden.artifact_renderer path_free_artifact,artifact_renderer,language_matrix,golden golden_snapshot root_swiftpm routine 13 c_smoke,cpp_edge_methods,dart_smoke,go_smoke,java_smoke,js_smoke,php_edge_namespaces,py_smoke,rb_smoke,rs_smoke,swift_smoke,ts_smoke,tsx_component Each practical-language fixture renders through the immutable artifact terminal and matches its committed golden. The artifact renderer could drift from current extraction/rendering or committed golden snapshots across the supported language matrix. 0.543500 tree_sitter,fixture_bundle syntax_manager test_case retain 0 Item 1 duplicate render removal; path-free artifact golden coverage across all 13 existing language fixtures root/RepoPromptTests.CodeMapGoldenTests/testSnapshotFileTreeMarksCodeMapFixtures root Tests/RepoPromptTests/CodeMap/CodeMapGoldenTests.swift RepoPromptTests.CodeMapGoldenTests testSnapshotFileTreeMarksCodeMapFixtures CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 23 root/RepoPromptTests.CodeMapGoldenTests/testSnapshotFileTreeNoneModeProducesNoOutputOrLegend root Tests/RepoPromptTests/CodeMap/CodeMapGoldenTests.swift RepoPromptTests.CodeMapGoldenTests testSnapshotFileTreeNoneModeProducesNoOutputOrLegend CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 36 root/RepoPromptTests.CodeMapGoldenTests/testSnapshotFileTreeSelectedModeStillRendersSelectionAndLegend root Tests/RepoPromptTests/CodeMap/CodeMapGoldenTests.swift RepoPromptTests.CodeMapGoldenTests testSnapshotFileTreeSelectedModeStillRendersSelectionAndLegend CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 46 root/RepoPromptTests.CodeMapRootManifestStoreTests/testAccountingRejectsShardReplacementBeforeReturningDetachedCounts root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAccountingRejectsShardReplacementBeforeReturningDetachedCounts CodeMap codemap.root_manifest.accounting_terminal_authority accounting,terminal_revalidation,shard_identity,path_identity,fail_closed security_contract root_swiftpm routine 1 CodeMapRootManifestAccountingTerminalFixture Replacing a counted shard after the scan but before return causes insecureDirectory; detached manifest counts are never returned as current accounting. A same-UID shard swap could let accounting report values collected from a detached directory as authoritative current state. 0.244000 filesystem,security,concurrency temporary_directory test_case retain 0 Slice 2A P2 terminal accounting authority root/RepoPromptTests.CodeMapRootManifestStoreTests/testAccountingTracksExactBytesQuarantineAndPartialBounds root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAccountingTracksExactBytesQuarantineAndPartialBounds CodeMap codemap.root_manifest.accounting_exact_bounds manifest_bytes,record_count,temporary_count,quarantine_count,partial_scan,quarantine_quota accounting_contract root_swiftpm routine 5 CodeMapRootManifestAccountingFixture Exact live byte and record totals match three encoded manifests; a one-entry scan reports partial bounds; corrupt leaves and one temporary are counted separately; maintenance removes the temporary and trims three quarantines to the quota of two. Accounting could mix live, corrupt, temporary, or quarantined bytes, claim a bounded partial scan is complete, or let quarantine cardinality exceed policy. 0.704000 filesystem,security temporary_directory test_case retain 0 Slice 2A exact bounded manifest accounting root/RepoPromptTests.CodeMapRootManifestStoreTests/testConcurrentLoadsPersistMonotonicCoalescedAccessEpoch root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testConcurrentLoadsPersistMonotonicCoalescedAccessEpoch CodeMap codemap.root_manifest.access_refresh_coalescing thirty_two_loads,coalescing,durable_access,monotonic_update,generation_stability concurrency_contract root_swiftpm routine 3 CodeMapRootManifestAccessRefreshFixture Thirty-two concurrent successful loads coalesce to persisted access epoch 500 without changing generation or records; a later unchanged update requesting epoch 400 cannot regress the durable maximum. Per-hit foreground fsync could amplify read latency, concurrent touches could race backwards, or access-only publication could spuriously advance semantic generation. 0.246000 filesystem,concurrency temporary_directory test_case retain 0 Slice 2A durable coalesced logical access -root/RepoPromptTests.CodeMapRootManifestStoreTests/testCorruptOversizedTruncatedAndChecksumRecordsQuarantineAsMiss root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCorruptOversizedTruncatedAndChecksumRecordsQuarantineAsMiss CodeMap codemap.root_manifest.corruption_quarantine truncation,checksum,oversize,short_header,quarantine,whole_snapshot_miss,typed_decode_accounting corruption_recovery root_swiftpm routine 4 CodeMapRootManifestCorruptionFixture Four corrupt container shapes are quarantined, disappear from the live namespace, and return a whole-manifest miss with zero admitted records; the three frames reaching the codec are attributed as two checksum and one envelope failures. Malformed or oversized persistence could allocate unbounded memory, serve a valid prefix, remain repeatedly readable, or erase the stage needed to diagnose repeated regeneration. 0.237000 filesystem,security temporary_directory test_case retain 0 Slice 2A bounded corruption, quarantine-as-miss, and safe typed attribution contract +root/RepoPromptTests.CodeMapRootManifestStoreTests/testCorruptOversizedTruncatedAndChecksumRecordsQuarantineAsMiss root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCorruptOversizedTruncatedAndChecksumRecordsQuarantineAsMiss CodeMap codemap.root_manifest.corruption_quarantine truncation,checksum,oversize,short_header,quarantine,whole_snapshot_miss corruption_recovery root_swiftpm routine 4 CodeMapRootManifestCorruptionFixture Four corrupt container shapes are quarantined, disappear from the live namespace, and return a whole-manifest miss with zero admitted records. Malformed or oversized persistence could allocate unbounded memory, serve a valid prefix, or remain repeatedly readable instead of failing closed. 0.237000 filesystem,security temporary_directory test_case retain 0 Slice 2A bounded corruption and quarantine-as-miss contract root/RepoPromptTests.CodeMapRootManifestStoreTests/testCorruptTargetReplacementAtQuotaCountsAsInsertion root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCorruptTargetReplacementAtQuotaCountsAsInsertion CodeMap codemap.root_manifest.corrupt_replacement_quota corrupt_target,count_quota,byte_quota,quarantine,eviction security_boundary root_swiftpm routine 2 CodeMapRootManifestQuotaCorruptionFixture At exact count and byte quotas, a corrupt target contributes no replacement credit; quarantine followed by replacement leaves exactly one live manifest within the configured byte bound. Subtracting the unaccounted corrupt inode could let replacement publish an extra manifest or excess bytes beyond the store quota. 0.477000 filesystem,security temporary_directory test_case retain 0 Slice 2A corrupt-target quota accounting regression root/RepoPromptTests.CodeMapRootManifestStoreTests/testCrashBoundariesRecoverOrphansAndPreserveCompleteSnapshots root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCrashBoundariesRecoverOrphansAndPreserveCompleteSnapshots CodeMap codemap.root_manifest.crash_boundary_recovery temporary_write,file_fsync,rename,directory_fsync,orphan_cleanup,restart crash_recovery root_swiftpm routine 4 CodeMapRootManifestCrashBoundaryFixture Simulated termination after write, file fsync, rename, and directory fsync yields either the old or new complete snapshot as appropriate; restart maintenance removes only pre-rename orphan temps. A killed writer could expose a partial manifest, lose the prior committed snapshot, or leave unbounded temporary residue. 0.950500 filesystem temporary_directory test_case retain 0 Slice 2A atomic publication fault-boundary recovery root/RepoPromptTests.CodeMapRootManifestStoreTests/testDelayedOldWriterCannotReplaceNewerNamespaceAuthority root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testDelayedOldWriterCannotReplaceNewerNamespaceAuthority CodeMap codemap.manifest_store.stale_authority_fence delayed_old_writer,new_authority,exact_predecessor,locked_rejection,final_authority concurrency_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture,ManifestAccessRefreshGate An old-authority merge is gated before the secure lock; a writer carrying the exact observed predecessor publishes the newer authority, then the delayed writer is rejected as stale and exact hit/stale reloads preserve only the newer record. A detached predecessor writer could discard the current authority's records and rename its obsolete snapshot over the namespace. 0.236500 filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 delayed predecessor authority fence root/RepoPromptTests.CodeMapRootManifestStoreTests/testHostileChecksummedCodecFramesFailClosedWithinBounds root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testHostileChecksummedCodecFramesFailClosedWithinBounds CodeMap codemap.root_manifest.hostile_codec_bounds canonical_round_trip,namespace_prefix,authority_prefix,record_count,payload_bound,utf8,invalid_path,mode,outcome,contribution,trailing,duplicate,order,authority,key bounded_decoder root_swiftpm routine 16 CodeMapRootManifestHostileCodecFixture One canonical encode-decode-reencode round-trip and fifteen checksum-valid hostile frames cover bounded lengths/counts, UTF-8 and path canonicality, malformed mode/outcome/contribution tags, terminal contribution misuse, trailing payload, duplicate/order rejection, and authority/key mismatch. A checksum-valid frame could force disproportionate allocation or admit noncanonical, ambiguous, semantically invalid, or cross-authority records. 0.250500 filesystem,security codec_fixture test_case retain 0 Slice 2A bounded canonical decoder adversarial coverage -root/RepoPromptTests.CodeMapRootManifestStoreTests/testStoredManifestDecodeFailureAttributesValidatedFrameStage root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testStoredManifestDecodeFailureAttributesValidatedFrameStage CodeMap codemap.root_manifest.decode_failure_attribution checksum,codec_version,namespace_digest,record_validation,trailing_payload,expected_namespace,safe_diagnostics bounded_decoder root_swiftpm routine 6 CodeMapRootManifestHostileCodecFixture Six deterministic corruptions report the exact safe decode stage after progressively stronger checksum, codec, namespace, record, payload, and expected-namespace validation. Collapsing every quarantine to generic corruption prevents distinguishing repeated canonical or record validation failures from byte damage and can hide regeneration loops. 0.120000 filesystem,security codec_fixture test_case retain 0 Issue 466 typed manifest quarantine attribution; records no paths or payloads root/RepoPromptTests.CodeMapRootManifestStoreTests/testIndependentStoresMergeDisjointNamespaceDeltasWithoutClobbering root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testIndependentStoresMergeDisjointNamespaceDeltasWithoutClobbering CodeMap codemap.manifest_store.namespace_delta_merge two_store_instances,same_namespace,disjoint_upserts,first_lock_held,successor_blocked,serialized_rmw persistence_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture A deterministic gate holds the first store inside the secure lock, proves the second attempted but could not enter, then releases it; the successor observes the first publication and the final generation-two snapshot contains both disjoint paths. Scheduling-only concurrency could pass without overlap, while an unlocked or pre-lock read-modify-write could clobber another store's namespace record. 0.222000 filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 deterministic serialized locked RMW root/RepoPromptTests.CodeMapRootManifestStoreTests/testIndependentWritersAndReadersObserveOnlyCompleteAtomicSnapshots root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testIndependentWritersAndReadersObserveOnlyCompleteAtomicSnapshots CodeMap codemap.root_manifest.atomic_cross_instance_publication cross_instance_locking,concurrent_replace,concurrent_read,multi_record_snapshot,fail_closed_miss concurrency_contract root_swiftpm routine 2 CodeMapRootManifestConcurrencyFixture Two store actors repeatedly replace one namespace with either of two exact two-record snapshots while readers observe only a complete listed snapshot or a fail-closed racing miss; the final state is also one complete snapshot. Cross-instance writers or non-atomic publication could expose mixed, truncated, or partially merged multi-record bindings. 0.491500 filesystem,concurrency temporary_directory,cross_instance_lock test_case retain 0 Slice 2A atomic multi-record snapshot publication root/RepoPromptTests.CodeMapRootManifestStoreTests/testLoadRejectsStaleAuthoritySchemaPolicyPipelineAndWholeSnapshotMismatch root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testLoadRejectsStaleAuthoritySchemaPolicyPipelineAndWholeSnapshotMismatch CodeMap codemap.root_manifest.authority_fencing authority_generation,index_generation,schema,policy,pipeline,whole_snapshot stale_generation_contract root_swiftpm routine 5 CodeMapRootManifestAuthorityFixture Changed authority returns stale; schema, policy, and pipeline namespaces miss; a record authority-digest mutation invalidates the complete snapshot. A stale repository generation or incompatible semantic identity could be partially served as current clean bindings. 0.215000 filesystem,security temporary_directory test_case retain 0 Slice 2A whole-snapshot authority and identity fencing @@ -925,12 +830,12 @@ root/RepoPromptTests.CodeMapSourceSnapshotTests/testDigestRejectsInvalidWidthAnd root/RepoPromptTests.CodeMapSourceSnapshotTests/testSnapshotDecodeResultDistinguishesEmptyAndUndecodableBytes root Tests/RepoPromptTests/CodeMap/CodeMapSourceSnapshotTests.swift RepoPromptTests.CodeMapSourceSnapshotTests testSnapshotDecodeResultDistinguishesEmptyAndUndecodableBytes CodeMap codemap.source.decode_outcomes empty_source,undecodable_source,shared_decoder pure_model root_swiftpm routine 2 CodeMapSourceSnapshotFixture Empty bytes decode to exact empty UTF-8 text while invalid bytes produce the explicit undecodable failure. Decode failures could collapse into empty content or unstable parser inputs. 0.000000 test_case retain 0 Phase 2 shared decoder outcome contract root/RepoPromptTests.CodeMapSourceSnapshotTests/testSnapshotIdentityIsStableAndDistinguishesByteEncodingsWithSameText root Tests/RepoPromptTests/CodeMap/CodeMapSourceSnapshotTests.swift RepoPromptTests.CodeMapSourceSnapshotTests testSnapshotIdentityIsStableAndDistinguishesByteEncodingsWithSameText CodeMap codemap.source.raw_identity stable_identity,byte_distinct_encodings,decoded_text_equivalence pure_model root_swiftpm routine 2 CodeMapSourceSnapshotFixture Repeated identical bytes preserve digest and decode identity, while UTF-8 and BOM UTF-16 bytes for the same text have distinct raw digests and byte counts. Hashing decoded text could alias byte-distinct source revisions or make identity nondeterministic. 0.000000 test_case retain 0 Phase 2 exact raw-byte identity contract root/RepoPromptTests.CodeMapSourceSnapshotTests/testSnapshotPreservesExactBytesDigestCountAndValidationToken root Tests/RepoPromptTests/CodeMap/CodeMapSourceSnapshotTests.swift RepoPromptTests.CodeMapSourceSnapshotTests testSnapshotPreservesExactBytesDigestCountAndValidationToken CodeMap codemap.source.envelope_exactness raw_bytes,sha256,byte_count,decoder_policy,closed_provenance,validated_worktree pure_model root_swiftpm routine 1 CodeMapSourceSnapshotFixture The immutable envelope retains the exact input Data, known SHA-256 and byte count, shared decoder result, policy, and closed validated-worktree provenance. Envelope construction could hash or count transformed text, drop source provenance, or decode a different buffer. 0.000000 test_case retain 0 Slice 1A evolves the Phase 2 one-buffer envelope to closed source provenance -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testArtifactSerializationIsPathFreeAndRecomputesDerivedValues root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testArtifactSerializationIsPathFreeAndRecomputesDerivedValues CodeMap codemap.artifact.path_free_serialization key_whitelist,identity_exclusion,derived_recomputation,value_semantics serialization_contract codemap_core routine 5 CodeMapSyntaxArtifactFixture Artifact JSON contains only source-derived arrays, excludes identity keys and sentinels, round-trips, ignores injected derived fields, and retains value semantics under copied-array mutation. Path, root, validation, digest, or mutable derived state could leak into the reusable artifact format. 0.000000 test_case retain 0 Item 2 immutable path-free artifact contract; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testBuilderMapsDecodeEmptyNoSymbolsOversizeAndParseFailures root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testBuilderMapsDecodeEmptyNoSymbolsOversizeAndParseFailures CodeMap codemap.artifact.deterministic_outcomes decode_failure,empty_source,no_symbols,oversize,nil_tree,nil_root deterministic_negative codemap_core routine 7 CodeMapCoreSourceSnapshotFixture,CodeMapSyntaxQueryStub The direct builder maps undecodable bytes, empty content, capture-free content, injected oversize and parse failures, and a real line-limit breach to distinct terminal outcomes. Deterministic negatives could collapse into no symbols, become transient throws, or enter parsing after a terminal source outcome. 0.000000 tree_sitter syntax_manager test_case retain 0 Item 2 direct envelope-to-artifact outcome mapping; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testBuilderPropagatesExactTransientQueryError root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testBuilderPropagatesExactTransientQueryError CodeMap codemap.artifact.transient_failure_boundary query_error,no_negative_persistence,no_artifact,no_catalog,no_lease protocol_negative codemap_core routine 1 CodeMapSyntaxQueryStub The synchronous core builder propagates an injected transient query error exactly instead of converting it to a deterministic artifact outcome. An operational parser/query failure could be mistaken for a reusable terminal negative and suppress a later valid retry. 0.002000 test_case retain 0 Item 3 split: pure exact-error propagation is core-owned; coordinator retry test separately proves no CAS insertion -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testOutcomeSerializationUsesStableExplicitDiscriminators root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testOutcomeSerializationUsesStableExplicitDiscriminators CodeMap codemap.artifact.outcome_serialization explicit_discriminator,stable_json,unknown_case_rejection serialization_contract codemap_core routine 6 CodeMapSyntaxArtifactOutcomeFixture Sorted JSON uses explicit stable discriminators for no-symbol, decode, oversize, nil-tree, and nil-root outcomes and rejects an unsupported discriminator. Synthesized or ambiguous enum encoding could make persisted deterministic outcomes schema-unstable or admit binding-local unsupported state. 0.000000 test_case retain 0 Item 2 stable deterministic outcome schema; Item 3 owner moved to RepoPromptCodeMapCoreTests -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testReadyArtifactIsDeterministicAcrossSourceMetadataAndHasNoFilenameInput root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testReadyArtifactIsDeterministicAcrossSourceMetadataAndHasNoFilenameInput CodeMap codemap.artifact.content_determinism validation_identity_independence,filename_independence,repeatability,legacy_filename_shaping pure_model codemap_core routine 5 CodeMapCoreSourceSnapshotFixture,JavaFilenameShapingFixture Repeated builds from equal decoded content with different raw digest metadata produce the same path-free artifact, and Java extraction has no filename input. Binding identity or filename-sensitive legacy shaping could contaminate the shared artifact graph, or separating terminals could silently remove legacy filename behavior. 0.001000 tree_sitter syntax_manager test_case retain 0 Item 3 replaces app validation identity with provenance-free core source metadata -root/RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests/testUnsupportedExtensionsRemainOutsideArtifactOutcomes root Tests/RepoPromptCodeMapCoreTests/CodeMapSyntaxArtifactTests.swift RepoPromptCodeMapCoreTests.CodeMapSyntaxArtifactTests testUnsupportedExtensionsRemainOutsideArtifactOutcomes CodeMap codemap.artifact.unsupported_binding_boundary language_registry,unsupported_extension registry_boundary codemap_core routine 2 CodeMapSyntaxEngineRegistryFixture Unknown extensions resolve to no language and report no codemap support before any artifact outcome can be built. Unsupported binding state could be serialized as a content-addressed artifact outcome without a valid language pipeline. 0.000000 test_case retain 0 Item 2 unsupported remains binding-local; Item 3 owner moved to RepoPromptCodeMapCoreTests +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testArtifactSerializationIsPathFreeAndRecomputesDerivedValues root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testArtifactSerializationIsPathFreeAndRecomputesDerivedValues CodeMap codemap.artifact.path_free_serialization key_whitelist,identity_exclusion,derived_recomputation,value_semantics serialization_contract root_swiftpm routine 5 CodeMapSyntaxArtifactFixture Artifact JSON contains only source-derived arrays, excludes identity keys and sentinels, round-trips, ignores injected derived fields, and retains value semantics under copied-array mutation. Path, root, validation, digest, or mutable derived state could leak into the reusable artifact format. 0.000000 test_case retain 0 Item 2 immutable path-free artifact contract +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testBuilderMapsDecodeEmptyNoSymbolsOversizeAndParseFailures root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testBuilderMapsDecodeEmptyNoSymbolsOversizeAndParseFailures CodeMap codemap.artifact.deterministic_outcomes decode_failure,empty_source,no_symbols,oversize,nil_tree,nil_root deterministic_negative root_swiftpm routine 7 CodeMapSourceSnapshotFixture,CodeMapSyntaxQueryStub The direct builder maps undecodable bytes, empty content, capture-free content, injected oversize and parse failures, and a real line-limit breach to distinct terminal outcomes. Deterministic negatives could collapse into no symbols, become transient throws, or enter parsing after a terminal source outcome. 0.000000 tree_sitter syntax_manager test_case retain 0 Item 2 direct envelope-to-artifact outcome mapping +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testBuilderPropagatesTransientQueryFailuresWithoutArtifactOrCatalogState root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testBuilderPropagatesTransientQueryFailuresWithoutArtifactOrCatalogState CodeMap codemap.artifact.transient_failure_boundary query_error,no_negative_persistence,no_artifact,no_catalog,no_lease protocol_negative root_swiftpm routine 4 CodeMapSyntaxQueryStub,CodeMapArtifactStoreFixture A transient query/configuration error is thrown unchanged and leaves artifact, catalog, and lease namespaces empty. Operational failures could be persisted as terminal content-addressed negatives and suppress valid retries. 0.002000 test_case retain 0 Item 2 transient failure boundary +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testOutcomeSerializationUsesStableExplicitDiscriminators root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testOutcomeSerializationUsesStableExplicitDiscriminators CodeMap codemap.artifact.outcome_serialization explicit_discriminator,stable_json,unknown_case_rejection serialization_contract root_swiftpm routine 6 CodeMapSyntaxArtifactOutcomeFixture Sorted JSON uses explicit stable discriminators for no-symbol, decode, oversize, nil-tree, and nil-root outcomes and rejects an unsupported discriminator. Synthesized or ambiguous enum encoding could make persisted deterministic outcomes schema-unstable or admit binding-local unsupported state. 0.000000 test_case retain 0 Item 2 stable deterministic outcome schema +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testReadyArtifactIsDeterministicAcrossValidationIdentityAndHasNoFilenameInput root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testReadyArtifactIsDeterministicAcrossValidationIdentityAndHasNoFilenameInput CodeMap codemap.artifact.content_determinism validation_identity_independence,filename_independence,repeatability,legacy_filename_shaping pure_model root_swiftpm routine 5 CodeMapSourceSnapshotFixture,JavaFilenameShapingFixture Repeated builds and equal raw content under different validation fingerprints produce the same path-free artifact; a Java top-level function stays global in the artifact while two legacy filenames produce their distinct synthetic classes. Binding identity or filename-sensitive legacy shaping could contaminate the shared artifact graph, or separating terminals could silently remove legacy filename behavior. 0.001000 tree_sitter syntax_manager test_case retain 0 Item 2 content-only artifact generation and explicit legacy terminal separation +root/RepoPromptTests.CodeMapSyntaxArtifactTests/testUnsupportedExtensionsRemainOutsideArtifactOutcomes root Tests/RepoPromptTests/CodeMap/CodeMapSyntaxArtifactTests.swift RepoPromptTests.CodeMapSyntaxArtifactTests testUnsupportedExtensionsRemainOutsideArtifactOutcomes CodeMap codemap.artifact.unsupported_binding_boundary language_registry,unsupported_extension registry_boundary root_swiftpm routine 2 SyntaxManagerRegistryFixture Unknown extensions resolve to no language and report no codemap support before any artifact outcome can be built. Unsupported binding state could be serialized as a content-addressed artifact outcome without a valid language pipeline. 0.000000 test_case retain 0 Item 2 unsupported remains binding-local root/RepoPromptTests.CodeMapV6CacheDeletionTests/testCacheDirectoryReplacementRaceDoesNotTouchReplacementOrPublishCompletion root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testCacheDirectoryReplacementRaceDoesNotTouchReplacementOrPublishCompletion CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage root/RepoPromptTests.CodeMapV6CacheDeletionTests/testCandidatePathReplacementRaceIsRetainedAndPreventsCompletion root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testCandidatePathReplacementRaceIsRetainedAndPreventsCompletion CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage root/RepoPromptTests.CodeMapV6CacheDeletionTests/testCompletionDirectorySynchronizationFailureLeavesAtomicRecordForRetry root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testCompletionDirectorySynchronizationFailureLeavesAtomicRecordForRetry CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage @@ -945,9 +850,47 @@ root/RepoPromptTests.CodeMapV6CacheDeletionTests/testPlannerAndExecutorDeleteOnl root/RepoPromptTests.CodeMapV6CacheDeletionTests/testPlannerRetainsSymlinkHardlinkWrongModeOversizedAndSyntheticWrongOwnerEntries root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testPlannerRetainsSymlinkHardlinkWrongModeOversizedAndSyntheticWrongOwnerEntries CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage root/RepoPromptTests.CodeMapV6CacheDeletionTests/testRemovalDirectorySynchronizationFailureRetriesOnNextExecution root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testRemovalDirectorySynchronizationFailureRetriesOnNextExecution CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage root/RepoPromptTests.CodeMapV6CacheDeletionTests/testReportTelemetryShapeContainsOnlyNumericStoredFields root Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift RepoPromptTests.CodeMapV6CacheDeletionTests testReportTelemetryShapeContainsOnlyNumericStoredFields CodeMap unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 Codemap cleanup milestone coverage +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt WorkspaceContext/CodeMap codemap.automatic_presentation.reconstruction_watcher_fence candidate_reconstruction,watcher_invalidation,no_targets,no_receipt,typed_retry filesystem_race_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapSelectionGraphProbe,WorkspaceCodemapPresentationCoordinator A watcher mutation during automatic target reconstruction returns one targetless presentation with no receipt or publication revalidation and typed retry coverage. A stale reconstructed target set could be published after path authority changes. filesystem,git_fixture,artifact_store,actor,concurrency store_session+coordinator_operation+root_unload retain 0 Census closure for watcher-invalidated automatic reconstruction.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticPresentationWatcherInvalidationDuringReconstructionNeverPublishesTargetsWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionDoesNotResolveForeignOnlyDefinition root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionDoesNotResolveForeignOnlyDefinition WorkspaceContext/CodeMap codemap.cutover.auto.foreign_only_negative foreign_definition,exact_root,cross_root_negative dependency_isolation root_swiftpm routine 2 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory A definition available only in another loaded root never satisfies the selected source and contributes zero automatic targets. Global name or path aggregation could leak a foreign-root definition into automatic selection. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Cutover A1 foreign-only negative; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionDoesNotResolveForeignOnlyDefinition to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionDoesNotResolveForeignOnlyDefinition; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionDoesNotResolveForeignOnlyDefinition to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionDoesNotResolveForeignOnlyDefinition during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery WorkspaceContext/CodeMap codemap.cutover.auto.source_response_currentness source_generation,post_query_race,stale_coverage,no_targets stale_generation_contract root_swiftpm routine 1 CodemapStoreFixture,CodemapArmableSuspensionGate,WorkspaceCodemapSelectionGraphFactory Cancelling the selected source after its exact-root graph query but before response mapping drops every target and returns typed stale graph currentness. Actor reentrancy could let targets derived from a revoked selected-source contribution escape at the response boundary. filesystem,git_fixture,artifact_store,actor,concurrency store_session+query_gate+graph_worker+root_unload retain 0 Cutover A1 response-boundary source ticket revalidation; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionDropsResultWhenSourceChangesAfterGraphQuery during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets WorkspaceContext/CodeMap codemap.cutover.auto.graph_proof_revocation graph_proof_revocation,post_query_race,typed_omission,fail_closed currentness_contract root_swiftpm routine 2 CodemapStoreFixture,CodemapArmableSuspensionGate,WorkspaceCodemapSelectionGraphFactory Cancelling a target after graph query revokes the captured graph proof, so automatic selection returns no targets or target issues, reports unavailable invalidGraphResult for the root, and omits the publication receipt. A revoked graph proof could still authorize stale automatic targets or a publication receipt. filesystem,git_fixture,artifact_store,actor,concurrency store_session+query_gate+graph_worker+root_unload retain 0 Renamed root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionOmitsTargetWhoseGenerationBecomesStale -> root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets; Cutover A1 post-query graph-proof revocation fence; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionGraphProofRevocationAfterQueryFailsClosedWithoutTargets during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt WorkspaceContext/CodeMap codemap.cutover.auto.aggregate-budget-atomic multi_root,later_budget,private_staging,targetless,receiptless bounded_input_contract root_swiftpm routine 3 CodemapStoreFixture A later-root target budget failure discards every earlier staged root target and the publication receipt. Incremental root publication could leak valid earlier targets from an atomically failed request. filesystem,git_fixture,artifact_store,actor store_session+root_unload retain 0 Selection milestone aggregate budget atomicity; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionLaterRootBudgetDiscardsEarlierTargetsAndReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary WorkspaceContext/CodeMap codemap.cutover.auto.exact-root-merge multi_root,partitioned_query,response_merge,root_qualified_targets dependency_isolation root_swiftpm routine 3 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory Two selected roots are queried through two exact-epoch graph actors and their root-qualified targets are merged only in the response projection. A mixed-root query or early aggregate could confuse root epochs, counts, or target ownership. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Cutover A1 exact-root independent merge; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionQueriesTwoRootsIndependentlyAndMergesAtResponseBoundary during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery WorkspaceContext/CodeMap codemap.cutover.auto.out_of_scope_preflight root_scope,outside_source,no_graph_work dependency_isolation root_swiftpm routine 3 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory A root-qualified source excluded by the requested scope is rejected as typed outsideRootScope before graph actor creation or query work. Out-of-scope identity could cross the graph boundary and leak targets from an unauthorized root. filesystem,git_fixture,actor store_session+root_unload retain 0 Cutover A2 explicit root-scope preflight contract; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRejectsSourceOutsideRequestedRootScopeBeforeGraphQuery during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork WorkspaceContext/CodeMap codemap.cutover.auto.typed_source_states missing,pending,unavailable,stale_catalog_generation,no_new_work availability_contract root_swiftpm routine 4 CodemapStoreFixture,CodemapResolutionGate,WorkspaceCodemapSelectionGraphFactory Missing, pending, terminal-unavailable, and stale-generation selected identities remain distinct typed source issues without graph creation or extra provider access. Collapsing source states could trigger fallback work or allow stale catalog identity into selection. filesystem,git_fixture,artifact_store,actor,concurrency store_session+demand_gate+root_unload retain 0 Cutover A1 typed source coverage; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionReportsMissingPendingUnavailableAndStaleSourcesWithoutNewWork during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions WorkspaceContext/CodeMap codemap.cutover.auto.scope_partition_resnapshot multi_root,scope_change,partition_boundary,resnapshot,stale_root async_concurrency_lifecycle root_swiftpm routine 1 CodemapStoreFixture,CodemapRootSuspensionGate A root removed while the first partition is suspended forces a bounded request resnapshot and returns typed stale coverage for the removed root without obsolete targets. Merging independently awaited partitions against the initial scope could publish targets or issues for a root no longer in the current catalog. filesystem,git_fixture,artifact_store,actor,concurrency store_session+query_gate+graph_worker+root_unload retain 0 A1 P1 root-scope partition resnapshot repair; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionResnapshotsScopeChangeBetweenRootPartitions during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait WorkspaceContext/CodeMap codemap.cutover.auto.pending_ready_resnapshot pending,ready,post_query_race,resnapshot,bounded_retry async_concurrency_lifecycle root_swiftpm routine 1 CodemapStoreFixture,CodemapArmableSuspensionGate,WorkspaceCodemapSelectionGraphFactory A pending selected identity that becomes ready during another source graph await is resnapshotted and never returned as an obsolete pending issue. Actor reentrancy could preserve a pre-await pending issue and omit the newly ready source from the response. filesystem,git_fixture,artifact_store,actor,concurrency store_session+publication_gate+query_gate+graph_worker+root_unload retain 0 A1 P1 pending-to-ready response resnapshot repair; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRetriesWhenPendingSourceBecomesReadyDuringGraphAwait during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage WorkspaceContext/CodeMap codemap.cutover.auto.target-limit-budget output_budget,target_limit,targetless,receiptless,typed_coverage bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory Automatic selection preserves the exact targetLimit attempted/limit disposition without targets, receipt, fallback, or partial publication. Flattening a terminal target budget could make consumers retry it or publish partially staged targets. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Split root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReturnsTypedBudgetAndBusyCoverage -> root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage + root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage; this row retains the target-limit scenario while the separate mapper test restores the rebuilding consumer-translation scenario.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRootReloadDropsOldTargets root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionRootReloadDropsOldTargets WorkspaceContext/CodeMap codemap.cutover.auto.root_reload_currentness root_epoch,unload_reload,old_targets,stale_coverage stale_generation_contract root_swiftpm routine 2 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory A previously resolving source identity returns no targets and typed stale root-epoch coverage after unload and same-path reload. Old automatic targets could cross a root-lifetime ABA boundary into a replacement catalog. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Cutover A1 root reload fencing; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRootReloadDropsOldTargets to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRootReloadDropsOldTargets; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRootReloadDropsOldTargets to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionRootReloadDropsOldTargets during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets WorkspaceContext/CodeMap codemap.cutover.auto.incomplete_definition_universe current_sources,incomplete_projection,targetless,receiptless,zero_extra_work availability_contract root_swiftpm routine 1 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory Automatic selection over a current but incomplete definition universe reports typed incomplete coverage with zero targets and no publication receipt or additional provider, build, or manifest work. Incomplete projection authority could publish pre-proof targets or trigger unrelated artifact work. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload consolidated_replacement 0 Store-level replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionIncompletePreloadDemandsProjectionWithoutPublishingPreProofTargets; one intrinsic targetless pre-proof scenario is credited.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testAutomaticSelectionWithIncompleteDefinitionUniversePublishesNoTargets during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testProvisionalAutomaticSelectionDropsStaleCandidateWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testProvisionalAutomaticSelectionDropsStaleCandidateWithoutReceipt WorkspaceContext/CodeMap codemap.provisional_auto_selection.stale_candidate_no_receipt provisional_selection,path_invalidation,stale_currentness,no_receipt stale_generation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture A path-invalidated provisional candidate is dropped, emits no receipt, and reports stale-currentness partial coverage. A stale provisional candidate could publish without a revalidatable receipt after path authority changed. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Reviewed ledger reconciliation for PR314 live missing XCTest ID.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProvisionalAutomaticSelectionDropsStaleCandidateWithoutReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testProvisionalAutomaticSelectionDropsStaleCandidateWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testProvisionalAutomaticSelectionPublishesReadyTargetWithIncompleteDiagnostics root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testProvisionalAutomaticSelectionPublishesReadyTargetWithIncompleteDiagnostics WorkspaceContext/CodeMap codemap.provisional_auto_selection.ready_target_incomplete_diagnostics provisional_selection,ready_target,incomplete_graph_diagnostics,receipt_revalidation,duplicate_target_stale availability_contract root_swiftpm routine 3 CodemapStoreFixture,ReviewGitRepositoryFixture Provisional automatic selection can publish a ready target despite incomplete graph diagnostics with a revalidatable receipt; duplicate receipt targets are stripped and duplicate target slots stale revalidation. Incomplete graph diagnostics or duplicate target slots could block valid provisional publication or publish non-revalidatable duplicates. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Reviewed ledger reconciliation for PR314 live missing XCTest ID; scenario count covers ready publication, duplicate receipt stripping, and stale duplicate-slot revalidation.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProvisionalAutomaticSelectionPublishesReadyTargetWithIncompleteDiagnostics to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testProvisionalAutomaticSelectionPublishesReadyTargetWithIncompleteDiagnostics during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testSecondFlushRecoveryRetiresFlightAndCoalescesSignalsIntoOneSuccessor root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testSecondFlushRecoveryRetiresFlightAndCoalescesSignalsIntoOneSuccessor WorkspaceContext/CodeMap codemap.graph.recovery_observer_convergence generation_matched_seal,flight_retirement,observer_coalescing,newer_serial,bounded_successor,teardown async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,CodemapSelectionGraphProbe,CodemapSuspensionGate From a generation-matched seal, a retired publication flight installs one observer, a real newer overlay serial rearms that observer into one bounded successor, and only Target.swift publishes before flight and observer teardown. Recovery signaling could lose newer work, spawn an unbounded observer chain, publish unrelated targets, or leave active recovery state. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Step 5/6 recovery flight and observer convergence closure; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testSecondFlushRecoveryRetiresFlightAndCoalescesSignalsIntoOneSuccessor to root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testSecondFlushRecoveryRetiresFlightAndCoalescesSignalsIntoOneSuccessor during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery WorkspaceContext/CodeMap codemap.automatic_selection.accounting_equality_boundary equality_boundary,accounting_overflow,zero_graph_query,zero_runtime bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture An accounting maximum reached at the equality boundary returns typed accountingOverflow before graph query or runtime access. Off-by-one accounting could admit work at the configured hard bound or launch graph work for a targetless failure. actor,in_memory store_session retain 0 Census closure for exact automatic-selection accounting boundary.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionAccountingEqualityBoundaryFailsBeforeGraphQuery during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt WorkspaceContext/CodeMap codemap.cutover.auto.accounting-overflow injected_bound,checked_addition,typed_overflow,targetless,receiptless bounded_input_contract root_swiftpm routine 3 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory A deliberately tiny accounting bound produces typed accounting overflow with no staged roots, targets, or publication receipt. Unchecked count arithmetic or maximum-plus-one sentinels could trap or leak partially staged automatic targets. filesystem,git_fixture,artifact_store,actor store_session+graph_worker+root_unload retain 0 Blocker closure overflow accounting; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionAccountingOverflowFailsClosedWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound WorkspaceContext/CodeMap codemap.cutover.auto.source-busy-deadline persistent_busy,production_waiter,request_deadline,before_round_cap,stale_publication,targetless,receiptless,external_timeout async_concurrency_lifecycle root_swiftpm routine 1 CodemapStoreFixture,WorkspaceSelectionMutationService Persistent source busy under the production waiter reaches the request deadline before the configured round cap; finalization fails closed as stale publicationReceipt with no targets or receipt and drains source retains within an external timeout. Deadline waiting could overrun indefinitely, reach an unrelated round cap, publish an intermediate busy result, or leak source ownership. filesystem,git_fixture,artifact_store,actor,concurrency store_session+external_timeout+root_unload retain 0 Split from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionBusySourceExhaustionStopsAtConfiguredBounds; preserves the deadline/finalization scenario.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionBusySourceDeadlineStopsBeforeRoundBound during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline WorkspaceContext/CodeMap codemap.cutover.auto.source-busy-round-bound persistent_busy,six_round_cap,before_deadline,targetless,receiptless,ticket_drain,external_timeout async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,WorkspaceSelectionMutationService,CodemapAutomaticSelectionSequenceHarness A step-controlled persistent-busy sequence reaches the six-round cap before the longer request deadline, returns typed sourceBusy coverage without targets or receipt, and drains every issued ticket within an external test timeout. Busy retry could spin past its round cap, conflate the cap with deadline exhaustion, publish incomplete targets, or leak source tickets. filesystem,git_fixture,artifact_store,actor,concurrency store_session+sequence_harness+external_timeout+root_unload retain 0 Split from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionBusySourceExhaustionStopsAtConfiguredBounds; preserves round-bound, fail-closed result, and ownership-drain scenarios.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionBusySourceRoundBoundStopsBeforeDeadline during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets WorkspaceContext/CodeMap codemap.cutover.auto.source-demand-cancellation create_join,per_caller_retain,creator_release,shared_ready,last_owner_cleanup async_concurrency_lifecycle root_swiftpm routine 4 CodemapStoreFixture,WorkspaceSelectionMutationService,CodemapSuspensionGate A selection-created demand and later join receive distinct retain IDs; selection cancellation drops the creator retain only, the joined caller reaches ready with retain count one, and its final release drains accounting and performs destructive cleanup. Caller cancellation could revoke a shared task or bundle while another retain remains, or the last release could leak the underlying owner. filesystem,git_fixture,artifact_store,actor,concurrency store_session+fanout_gate+root_unload retain 0 Final selection milestone store-level per-caller demand leases; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionCancellationMidSourceFanoutCancelsOnlyIssuedTickets during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot WorkspaceContext/CodeMap codemap.automatic_selection.all_root_source_readiness multi_root,ready_source,non_git_source,no_targets,no_receipt availability_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceSelectionMutationService A mixed-root automatic request with one ready Git source and one unavailable plain-root source returns noReadySources with no targets or receipt. Partial per-root readiness could publish an incomplete cross-root automatic target set. filesystem,git_fixture,artifact_store,actor store_session+root_unload retain 0 Census closure for all-root source readiness.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRequiresReadySourceCoverageInEveryRoot during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady WorkspaceContext/CodeMap codemap.cutover.auto.source-demand-owned busy_twice,ready,current_proof,target,receipt,publication_lease_release,source_drain,external_timeout async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,WorkspaceSelectionMutationService,CodemapAutomaticSelectionSequenceHarness,WorkspaceCodemapSelectionGraphFactory A step-controlled source sequence produces exactly two busy outcomes then current proof-backed target and receipt publication; receipt revalidation releases the publication lease and drains source ownership within an external timeout. Retry sequencing could hang, accept the wrong number of busy outcomes, publish stale proof or targets, or leak the source retain. filesystem,git_fixture,artifact_store,actor,concurrency store_session+sequence_harness+external_timeout+graph_worker+root_unload retain 0 Reviewed bounded replacement for the former unbounded-yield retry fixture; three busy-transition, publication-currentness, and ownership-cleanup scenarios retained.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRetriesBusySourceTwiceThenBecomesReady during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt WorkspaceContext/CodeMap codemap.automatic_selection.transient_graph_readiness_retry transient_graph_not_built,stale_currentness,bounded_retry,target,receipt async_concurrency_lifecycle root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory Automatic selection retries transient graph not-built and stale-currentness dispositions until the complete graph publishes one target with a matching publication receipt. A transient graph-readiness response could be treated as terminal, omit a valid target, or publish a receipt without complete coverage proof. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt; pre-existing missing ledger row added for moved live ID; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRetriesTransientGraphReadinessThenPublishesReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt WorkspaceContext/CodeMap codemap.automatic_selection.runtime_budget_terminal runtime_budget,terminal_coverage,targetless,receiptless bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory A runtime graph output-budget terminal result remains budget coverage with no targets, no publication receipt, and at most one graph query. Terminal graph budget failures could be retried, flattened, or leak partial automatic targets or receipts. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt; pre-existing missing ledger row added for moved live ID; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRuntimeBudgetRemainsTerminalWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt WorkspaceContext/CodeMap codemap.automatic_selection.runtime_invalid_snapshot_terminal runtime_invalid_snapshot,typed_unavailable,targetless,receiptless stale_generation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory A runtime invalidSnapshot graph disposition maps to typed graph runtime unavailable coverage with no targets, no publication receipt, and exactly one graph query. Invalid runtime snapshots could be retried as transient readiness, misclassified, or publish targets from stale graph state. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt; pre-existing missing ledger row added for moved live ID; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionRuntimeInvalidSnapshotRemainsTerminalWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout WorkspaceContext/CodeMap codemap.cutover.auto.source-demand-preflight request_cap,n,n_plus_one,preflight,no_excess_demand bounded_input_contract root_swiftpm routine 3 CodemapStoreFixture,WorkspaceSelectionMutationService The request aggregate source cap admits exactly N sources and rejects N+1 before issuing another source demand. Late source admission could fan out excess artifact work before returning a typed budget result. filesystem,artifact_store,actor,concurrency store_session+root_unload retain 0 Blocker closure source-demand preflight; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionSourceDemandLimitAllowsNAndRejectsNPlusOneBeforeFanout during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage WorkspaceContext/CodeMap codemap.cutover.auto.rebuilding-consumer-translation rebuilding,runtime_busy,consumer_translation,current_root,targetless,receiptless state_translation_contract root_swiftpm routine 1 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory A current complete store graph whose query boundary returns runtime rebuilding passes through resolveAutomaticCodemapSelection and maps to exact root and aggregate busy coverage with no targets, receipt, graph output accounting, or graph key. The production resolver could flatten rebuilding to unavailable or accidentally expose targets or a receipt while graph publication is incomplete. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_query_injection+graph_worker+root_unload retain 0 Split root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReturnsTypedBudgetAndBusyCoverage -> root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionReturnsTypedTargetLimitBudgetCoverage + root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage; this row restores the distinct rebuilding consumer-translation scenario through the production store resolver using a current graph and a narrow DEBUG-only graph-query override.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionTranslatesRebuildingRuntimeToBusyConsumerCoverage during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBusyTests.swift RepoPromptTests.CodemapAutomaticSelectionBusyTests testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork WorkspaceContext/CodeMap codemap.cutover.auto.inert_without_demand not_demanded,no_io,no_artifact,no_graph,no_eager_work dependency_isolation root_swiftpm routine 1 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory Resolving a current catalog identity without an existing demand returns typed unavailable coverage while runtime, engine, manifest, build, and graph counters remain zero. Automatic selection could become an eager demand seam or touch source, Git, CAS, artifact, or graph-build dependencies. filesystem,actor store_session+root_unload retain 0 Cutover A1 zero-work authority lookup; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork to root/RepoPromptTests.CodemapAutomaticSelectionBusyTests/testAutomaticSelectionWithoutExistingDemandPerformsNoIOOrArtifactWork during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch WorkspaceContext/CodeMap codemap.automatic_selection.configured_overflow_sealed_catalog configured_limit_plus_one,sealed_projection,small_match,publication_receipt bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory A sealed catalog with supported Swift candidates at configured manifest-adoption limit + 1 still resolves its one matching target and issues a publication receipt. A manifest-cache shortcut could reject a bounded automatic-selection result once candidate count exceeds the configured adoption limit. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Census closure for configured manifest-adoption overflow automatic selection; default production scale is no longer claimed by this PR-CI fixture.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionAboveManifestCacheCountPermitsSmallSealedMatch during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues WorkspaceContext/CodeMap codemap.cutover.auto.finalization-deadline publication_cleanup,deadline,fail_closed,targetless,receiptless,retain_drain,external_timeout async_concurrency_lifecycle root_swiftpm routine 2 CodemapStoreFixture,CodemapSuspensionGate,WorkspaceCodemapSelectionGraphFactory When cancellation cleanup remains blocked through finalization, the request deadline returns stale publicationReceipt coverage with no targets or receipt and drains source/target retains; an external race proves bounded completion before releasing cleanup. Finalization could hang behind cleanup, publish after its deadline, or leak source/target ownership. filesystem,git_fixture,artifact_store,actor,concurrency store_session+cleanup_gate+external_timeout+graph_worker+root_unload retain 0 Reviewed finalization fail-closed and cleanup-continuation scenarios; missing ledger row added during seam closure review.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionFinalizationDeadlineFailsClosedWhileCleanupContinues during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness WorkspaceContext/CodeMap codemap.cutover.auto.unsupported-inventory supported_count,large_unsupported_inventory,raw_inventory_pressure,responsive_inventory,target,receipt,zero_build_delta bounded_input_contract root_swiftpm routine 2 CodemapStoreFixture,CodemapArmableSuspensionGate,WorkspaceCodemapSelectionGraphFactory A catalog with exactly two supported Swift candidates and 8,193 unsupported raw workspace files remains responsive, selects only Target.swift with a receipt, and performs zero selection-scoped artifact builds. Unsupported enterprise inventory could block completeness, amplify artifact work, or contaminate automatic targets. filesystem,git_fixture,artifact_store,actor,concurrency store_session+query_gate+graph_worker+root_unload retain 0 Reviewed supported-inventory and responsiveness/no-extra-work scenarios using historical large raw unsupported inventory scale intentionally decoupled from manifest-adoption limits; missing ledger row added during seam closure review.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionIgnoresUnsupportedEnterpriseInventoryForCompleteness during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed WorkspaceContext/CodeMap codemap.automatic_selection.matched_target_budget sealed_projection,two_matches,candidate_demand_limit,targetless,no_receipt bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory Two sealed-graph matches against a one-target demand limit return the exact attempted and limit values with no targets or receipt. Target trimming after graph resolution could publish a partial result instead of enforcing the hard match budget. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Census closure for sealed matched-target budget.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionSealedGraphMatchedTargetBudgetFailsClosed during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed WorkspaceContext/CodeMap codemap.automatic_selection.result_byte_budget sealed_projection,byte_limit,attempted_bytes,targetless,no_receipt bounded_input_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapSelectionGraphFactory A sealed graph result exceeding the one-byte query limit returns typed attempted and limit accounting with no targets or receipt. Oversized automatic-selection results could be materialized or partially published after the byte budget is exceeded. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Census closure for automatic-selection result byte bound.; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testAutomaticSelectionSealedGraphResultByteBudgetFailsClosed during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority WorkspaceContext/CodeMap codemap.cutover.auto.target-background-build missing_cas,matched_target,background_priority,no_unrelated_build capability_lifecycle_contract root_swiftpm routine 4 CodemapStoreFixture,WorkspaceSelectionMutationService A verified manifest match with a missing CAS payload builds only the matched target at background priority. Missing CAS recovery could promote work, build unrelated files, or fail to materialize the requested target. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Selection milestone bounded target recovery; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionBuildsOnlyMatchedMissingCASTargetAtBackgroundPriority during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot WorkspaceContext/CodeMap codemap.cutover.auto.same-root-only cold_manifest,same_name,foreign_root,negative dependency_isolation root_swiftpm routine 2 CodemapStoreFixture,WorkspaceSelectionMutationService Cold manifest planning never uses a same-name definition from another loaded root. A global definition index could cross root authority and return a foreign target. filesystem,git_fixture,artifact_store,actor store_session+root_unload retain 0 Selection milestone exact-root candidate planning; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionNeverPlansSameNamedDefinitionFromAnotherRoot during codemap seam split +root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionColdTests.swift RepoPromptTests.CodemapAutomaticSelectionColdTests testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild WorkspaceContext/CodeMap codemap.cutover.auto.cold-manifest-target cold_source,manifest_envelope,cas_hit,no_unrelated_build,publication_receipt capability_lifecycle_contract root_swiftpm routine 5 CodemapStoreFixture,WorkspaceSelectionMutationService Cold selection discovers the unchanged same-root target from verified manifest contribution metadata, reuses CAS without rebuilding unrelated files, and issues a revalidatable receipt. Cold selection could require speculative parsing, miss unchanged targets, or publish without currentness proof. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Selection milestone cold manifest and CAS discovery; PR314 CI split: moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild to root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild; scenarios preserved.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapAutomaticSelectionSeamTests/testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild to root/RepoPromptTests.CodemapAutomaticSelectionColdTests/testColdAutomaticSelectionUsesManifestEnvelopeAndCASWithoutUnrelatedBuild during codemap seam split root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testBulkCancellationTransitionsEmitExactPathFreeAggregateTelemetry root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testBulkCancellationTransitionsEmitExactPathFreeAggregateTelemetry WorkspaceContext workspace_codemap_binding_engine.bulk_cancellation_telemetry path_invalidation,authority_invalidation,unload,shutdown,active,queued,already_cancelled,aggregate_hook,path_free,exactly_once cancellation_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineMultiEntryGate,EngineHookEvents For each bulk transition, one already-cancelled active request contributes its existing value-one event while the mixed remaining active and queued requests produce exactly one path-free aggregate value-two event; counter and hook totals remain exactly three after late task completion. Bulk cancellation could increment the counter without a matching hook, leak path data, omit queued or active work, or double-count an already-cancelled request when workers finish. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Final Slice 2B2 P2 bulk cancellation telemetry; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testBulkCancellationTransitionsEmitExactPathFreeAggregateTelemetry to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testBulkCancellationTransitionsEmitExactPathFreeAggregateTelemetry in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testCatalogInvalidationFencesVisibilityWithoutScheduling root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testCatalogInvalidationFencesVisibilityWithoutScheduling WorkspaceContext/CodeMap codemap.binding.catalog_invalidation catalog_invalidation,visibility,no_replacement_work,idempotence cancellation_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngineAccounting,EngineHookEvents Catalog invalidation revokes the overlay, rejects demand without replacement scheduling, preserves exact accounting, and repeats inertly. Catalog replacement could be misrepresented as repository authority, leave live visibility, or schedule hidden rebuild work. git_subprocess,filesystem,artifact_store,actor,concurrency fixture_cleanup+root_unload retain 0 Slice 3C typed catalog invalidation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testCatalogInvalidationFencesVisibilityWithoutScheduling to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testCatalogInvalidationFencesVisibilityWithoutScheduling in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testConcurrentRegistrationReservesRootSlotBeforeManifestLoad root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testConcurrentRegistrationReservesRootSlotBeforeManifestLoad WorkspaceContext workspace_codemap_binding_engine.registration_reservation root_slot,manifest_load_gate,concurrent_registration concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineBuildGate A suspended first registration owns the sole root slot and a second root returns busy before capability or manifest work. Concurrent registration could overshoot root capacity or overwrite a session. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 engine concurrency/resource/reentrancy hardening; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testConcurrentRegistrationReservesRootSlotBeforeManifestLoad to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testConcurrentRegistrationReservesRootSlotBeforeManifestLoad in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testEditRenameDeleteWatcherAndCheckoutInvalidationsFenceVisibilityWithoutScheduling root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testEditRenameDeleteWatcherAndCheckoutInvalidationsFenceVisibilityWithoutScheduling WorkspaceContext workspace_codemap_binding_engine.invalidation_fences modify,rename,delete,watcher_gap,checkout,synchronous_revoke,explicit_reregister async_state_machine root_swiftpm routine 6 ReviewGitRepositoryFixture,CodeMapArtifactRuntime Path and authority invalidations synchronously revoke overlay and manifest visibility; watcher and checkout fences require explicit re-registration. Stale ready state could remain visible across edits, watcher loss, rename/delete, or checkout authority changes. git_subprocess;filesystem;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 inert binding engine orchestration; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testEditRenameDeleteWatcherAndCheckoutInvalidationsFenceVisibilityWithoutScheduling to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testEditRenameDeleteWatcherAndCheckoutInvalidationsFenceVisibilityWithoutScheduling in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testEnginePublicationCountersSaturateWithoutWrapping root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testEnginePublicationCountersSaturateWithoutWrapping WorkspaceContext workspace_codemap_binding_engine.saturating_publication_accounting uint64_max,ready_publication,build,materialized_bytes,no_wrap bounded_state_machine root_swiftpm routine 3 ReviewGitRepositoryFixture,CodeMapArtifactRuntime Ready, build, and byte counters seeded at UInt64.max remain saturated after real publication work. Counter wrap could conceal publication volume or corrupt diagnostics. git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 saturating engine counters; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testEnginePublicationCountersSaturateWithoutWrapping to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testEnginePublicationCountersSaturateWithoutWrapping in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testInvalidationFencesBlockedCompletionBeforeOverlayPublication root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testInvalidationFencesBlockedCompletionBeforeOverlayPublication WorkspaceContext workspace_codemap_binding_engine.invalidation_completion_fence blocked_build,path_invalidation,cancellation,visibility_revocation,exactly_once_telemetry concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBuildGate Path invalidation cancels and fences a blocked build completion before publication, increments cancellation telemetry once, and a repeated invalidation does not count it again. A completion racing invalidation could resurrect stale ready state or double-count one logical cancellation. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 engine concurrency/resource/reentrancy hardening; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testInvalidationFencesBlockedCompletionBeforeOverlayPublication to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testInvalidationFencesBlockedCompletionBeforeOverlayPublication in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testInvalidationsFenceBlockedCapabilityRegistrationBeforeAwait root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testInvalidationsFenceBlockedCapabilityRegistrationBeforeAwait WorkspaceContext workspace_codemap_binding_engine.registration_invalidation_fence blocked_capability,path,watcher_gap,checkout,repository_authority,synchronous_attempt_revocation concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBuildGate Each path or root-authority invalidation removes the registering attempt before awaiting capability release; the blocked registration fails, publishes no eligible root, and drains its canceled resolution observer after the gate opens. A capability result could publish an eligible session after an invalidation that returned while resolution was suspended. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 capability-phase invalidation fence; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testInvalidationsFenceBlockedCapabilityRegistrationBeforeAwait to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testInvalidationsFenceBlockedCapabilityRegistrationBeforeAwait in binding-engine thematic split. @@ -958,17 +901,36 @@ root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testRootBoundsAndPath root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testSourceAcquisitionFailureReleasesOverlayPreflightAndActiveRequest root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testSourceAcquisitionFailureReleasesOverlayPreflightAndActiveRequest WorkspaceContext workspace_codemap_binding_engine.failure_cleanup source_failure,preflight_cancel,active_request,pending_entry,waiter_reservation async_resource_lifecycle root_swiftpm routine 4 ReviewGitRepositoryFixture,WorkspaceCodemapLiveOverlay A validated-source acquisition failure returns a typed transient result and releases the engine request, overlay preflight, pending entry, waiter, and reservation. A failure after admission could leave an uncancellable pending ticket that permanently consumes bounds. git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 failure cleanup contract; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testSourceAcquisitionFailureReleasesOverlayPreflightAndActiveRequest to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testSourceAcquisitionFailureReleasesOverlayPreflightAndActiveRequest in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testUnloadCancellationTelemetryCountsActiveRequestExactlyOnce root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testUnloadCancellationTelemetryCountsActiveRequestExactlyOnce WorkspaceContext workspace_codemap_binding_engine.unload_cancellation_telemetry active_request,root_unload,repeat_unload,exactly_once,cancellation_counter cancellation_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBuildGate Root unload cancels one blocked active request; a repeated unload is inert and the cancellation counter remains exactly one after late worker completion. Unload or the worker's later cancellation path could double-count one logical cancellation. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 exactly-once cancellation telemetry; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testUnloadCancellationTelemetryCountsActiveRequestExactlyOnce to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testUnloadCancellationTelemetryCountsActiveRequestExactlyOnce in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testUnloadDuringBlockedCapabilityRegistrationReleasesRootSlotImmediately root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testUnloadDuringBlockedCapabilityRegistrationReleasesRootSlotImmediately WorkspaceContext workspace_codemap_binding_engine.capability_registration_unload blocked_capability,root_slot,synchronous_release,replacement_registration,late_completion,bounded_history concurrency_contract root_swiftpm routine 5 ReviewGitRepositoryFixture,EngineFirstResolutionGate Unload removes the registering record and capability waiter/flight without waiting for a non-cooperative resolver, admits a replacement at the one-root bound, and ignores then drains the stale completion while released history stays bounded. A blocked capability resolver could retain the only root slot, leak active capability state, or publish after a replacement registration. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 unload during blocked capability registration; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testUnloadDuringBlockedCapabilityRegistrationReleasesRootSlotImmediately to root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testUnloadDuringBlockedCapabilityRegistrationReleasesRootSlotImmediately in binding-engine thematic split. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testDirtyWorktreeReplacementDoesNotJoinQueuedManifestRemoval root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testDirtyWorktreeReplacementDoesNotJoinQueuedManifestRemoval WorkspaceContext workspace_codemap_binding_engine.dirty_worktree_manifest_exclusion blocked_manifest_write,path_removal,dirty_worktree,overlay_ready,reload concurrency_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBlockingGate,EngineHookEvents A dirty-worktree replacement remains overlay-ready but does not join the queued durable manifest removal; reload adopts no stale record and resolves current source state. An unstaged artifact could be incorrectly treated as durable manifest authority or revive the removed clean record after reload. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Renamed from root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testBatchedRemoveThenUpsertForSamePathPersistsNewestMutation; PR #487 repair corrects the drifted premise that dirty-worktree artifacts are manifest-upserted. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testFailedManifestBatchResolvesEveryAbsorbedRevisionOnce root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testFailedManifestBatchResolvesEveryAbsorbedRevisionOnce WorkspaceContext workspace_codemap_binding_engine.manifest_batch_failure_waiters blocked_manifest_write,three_revisions,batch_failure,deferred_retry,all_waiters,exactly_once_failure concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublication,EngineHookEvents A fault in the second two-item publication parks both absorbed revisions, one autonomous retry persists them, both requests resolve once, one failure event is recorded, and the pipeline returns clean. A batch error could fail or resume only its highest revision, leak an earlier continuation, double-report failure, or strand retryable work dirty. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 repair updates the drifted failed-batch row to the executable autonomous-retry contract. root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testPathInvalidationDuringManifestWriteDrainsNewestRevision root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testPathInvalidationDuringManifestWriteDrainsNewestRevision WorkspaceContext workspace_codemap_binding_engine.invalidation_writer_drain blocked_manifest_write,path_invalidation,demand_cancellation,dirty_state_drain concurrency_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBlockingGate Path invalidation racing a blocked manifest write completes without manifest-write failure, cancels the affected demand, and leaves no dirty manifest state. A blocked predecessor could strand invalidation or leave the pipeline dirty. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Atomic cutover Slice 1 blocked-writer drain; does not claim persisted revision contents or every waiter; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testPathInvalidationDuringManifestWriteDrainsNewestRevision to root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testPathInvalidationDuringManifestWriteDrainsNewestRevision in binding-engine thematic split. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testQueuedManifestCompletionsShareOneBoundedPublicationAndResolveAllWaiters root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testQueuedManifestCompletionsShareOneBoundedPublicationAndResolveAllWaiters WorkspaceContext workspace_codemap_binding_engine.manifest_writer_batching blocked_manifest_write,three_revisions,two_publications,waiter_completion,reload,diagnostic_counters,coexistence_smoke concurrency_contract root_swiftpm routine 6 ReviewGitRepositoryFixture,EngineBlockingGate,EngineHookEvents,MCPCodeStructureSettlementRegistry As a PR487 coexistence smoke, a detached read-only settlement lease does not claim manifest-writer authority while the blocked publication absorbs two queued revisions; the provider's fixed 10-second readiness ceiling, not this smoke, remains the liveness guarantee. One-completion-per-publication, incorrect batch completion, or coupling read-only settlement to writer authority could preserve CPU amplification, lose records, or strand an absorbed revision waiter. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Issue 466 real-pipeline publication amplification regression root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testQueuedAndLastOwnerCancellationDrainReservationsAndFairnessHistoryAfterOrdinalRebase root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testQueuedAndLastOwnerCancellationDrainReservationsAndFairnessHistoryAfterOrdinalRebase WorkspaceContext workspace_codemap_binding_engine.cancellation_fairness_cleanup queued_cancel,last_owner_cancel,repeat_owner_cancel,exactly_once_telemetry,source_reservation,ordinal_rebase,history_prune cancellation_contract root_swiftpm routine 6 ReviewGitRepositoryFixture,EngineBuildGate At exact one-active and one-queued bounds near ordinal overflow, owner cancellation drains reservations and fairness history; repeated owner cancellation returns zero and the counter remains exactly two. Cancellation or ordinal exhaustion could double-count repeated owner release, leak queue/source ownership, retain unbounded fairness history, or poison later FIFO admission. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 bounded cancellation and fairness history; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testQueuedAndLastOwnerCancellationDrainReservationsAndFairnessHistoryAfterOrdinalRebase to root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testQueuedAndLastOwnerCancellationDrainReservationsAndFairnessHistoryAfterOrdinalRebase in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testSameNamespaceWriterDrainsUnloadedPredecessorBeforeSuccessor root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testSameNamespaceWriterDrainsUnloadedPredecessorBeforeSuccessor WorkspaceContext workspace_codemap_binding_engine.namespace_writer_serialization two_root_epochs,same_worktree,same_pipeline,blocked_predecessor,unload concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineBlockingGate Two root epochs targeting one worktree/pipeline share a namespace writer; unloading a blocked predecessor cancels its demand while the successor drains afterward and the final manifest contains both disjoint records. A canceled predecessor could race a successor or root-local snapshots could clobber same-namespace records. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 namespace authority and predecessor ordering; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testSameNamespaceWriterDrainsUnloadedPredecessorBeforeSuccessor to root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testSameNamespaceWriterDrainsUnloadedPredecessorBeforeSuccessor in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testSerializedManifestWriterPersistsNewestRecordSetWhenSecondCompletionArrivesFirst root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testSerializedManifestWriterPersistsNewestRecordSetWhenSecondCompletionArrivesFirst WorkspaceContext workspace_codemap_binding_engine.manifest_revision_writer serialized_writer,revision_two_queued,coalesced_revision,reverse_completion,reload concurrency_contract root_swiftpm routine 5 ReviewGitRepositoryFixture,EngineBlockingGate,EngineHookEvents A hook proves revision two is queued at the serialized writer while revision one is gated; after release the newest complete record set persists and reload adopts both records. A timing-only active-request heuristic could release revision one before revision two reaches the writer, masking reverse-write overwrite bugs. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 deterministic manifest writer serialization; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testSerializedManifestWriterPersistsNewestRecordSetWhenSecondCompletionArrivesFirst to root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testSerializedManifestWriterPersistsNewestRecordSetWhenSecondCompletionArrivesFirst in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testShutdownWaitsForBlockedManifestWriterAndDrainsEngineWork root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testShutdownWaitsForBlockedManifestWriterAndDrainsEngineWork WorkspaceContext workspace_codemap_binding_engine.shutdown_drain blocked_manifest_writer,request_cancel,writer_join,idempotent_shutdown,fixture_lifecycle async_resource_lifecycle root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBlockingGate,EngineCompletionFlag Shutdown remains incomplete while a canceled manifest writer is synchronously blocked, then joins writer and demand work, clears roots and queues, and is idempotent after release. Fixture deletion could race a manifest writer, adoption, capability observer, or request task and cause combined-suite flakes or use-after-cleanup failures. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 engine quiescence and fixture lifecycle; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testShutdownWaitsForBlockedManifestWriterAndDrainsEngineWork to root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testShutdownWaitsForBlockedManifestWriterAndDrainsEngineWork in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testAutomaticSelectionMatchedCandidateBytesAreBounded root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testAutomaticSelectionMatchedCandidateBytesAreBounded WorkspaceContext workspace_codemap_binding_engine.automatic_selection_matched_byte_budget automatic_selection,matched_candidate,retained_projection_bytes,typed_budget bounded_state_machine root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub After a source ticket and complete candidate projection produce a real type match, planning with a one-byte matched-candidate limit returns the retainedProjectionBytes budget dimension with an attempted value above one and the exact limit. Automatic selection could retain unbounded matched projection payloads or report the wrong budget dimension and prevent callers from handling pressure deterministically. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testAutomaticSelectionMatchedCandidateBytesAreBounded to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testAutomaticSelectionMatchedCandidateBytesAreBounded in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testCompletedProjectionPreparesAndCommitsOverlayGenerationSuccessorWithoutReplay root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testCompletedProjectionPreparesAndCommitsOverlayGenerationSuccessorWithoutReplay WorkspaceContext workspace_codemap_binding_engine.completed_projection_successor_commit completed_projection,overlay_generation,prepare,commit,retained_demand,no_replay,idempotence async_state_machine root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub A completed generation-1 projection initially satisfies retained demand; a later live overlay contribution prepares a successor that immediately fences the old demand stale and carries the new contribution generation; committing succeeds, duplicate preparation returns nil, and no second preload is scheduled. Overlay advancement could leave retained consumers on obsolete coverage, replay projection work during metadata-only successor commit, or admit duplicate successor seals. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testCompletedProjectionPreparesAndCommitsOverlayGenerationSuccessorWithoutReplay to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testCompletedProjectionPreparesAndCommitsOverlayGenerationSuccessorWithoutReplay in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionCompletenessDoesNotUseManifestAdoptionRetentionCap root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testProjectionCompletenessDoesNotUseManifestAdoptionRetentionCap WorkspaceContext workspace_codemap_binding_engine.projection_completeness_independent_adoption_cap projection_completeness,manifest_adoption_cap,full_catalog,coverage_proof,subset_stale bounded_state_machine root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub With the manifest-adoption retention cap set to one, preload still proves the complete two-candidate catalog and automatic-selection planning reports both indexed; presenting only a subset is rejected stale against that full-catalog proof. Projection completeness could be truncated by an unrelated adoption cap or accept a candidate subset that does not match the sealed catalog universe. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionCompletenessDoesNotUseManifestAdoptionRetentionCap to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionCompletenessDoesNotUseManifestAdoptionRetentionCap in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionResourceBudgetExposesTypedTerminalCoverage root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testProjectionResourceBudgetExposesTypedTerminalCoverage WorkspaceContext workspace_codemap_binding_engine.projection_terminal_budget_coverage projection_preload,retained_projection_bytes,budget_limited,terminal_coverage,automatic_selection,typed_budget bounded_state_machine root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub A one-byte retained-projection limit ends preload in budgetLimited with exact retainedProjectionBytes diagnostics, no retry or suspended job, and no active batch; automatic-selection planning returns the identical typed budget triple. Projection resource exhaustion could retry forever, leave active work suspended, or lose the typed terminal reason needed by automatic selection. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionResourceBudgetExposesTypedTerminalCoverage to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionResourceBudgetExposesTypedTerminalCoverage in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionRestartsAgainstConcurrentOverlayContributionGeneration root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testProjectionRestartsAgainstConcurrentOverlayContributionGeneration WorkspaceContext workspace_codemap_binding_engine.projection_overlay_generation_restart projection_preload,publication_race,overlay_contribution,stale_snapshot,restart,sequence_reset,coalescing concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineAsyncGate,EngineProjectionGenerationRacePublisher,EngineProjectionRecorder A live overlay publication racing the first projection snapshot causes one superseded coverage and an automatic restart at a higher contribution generation with segment sequence reset to zero; the logical preload remains one schedule and a repeated schedule call coalesces. Projection could commit against an obsolete overlay generation, continue sequence state across restart, or duplicate scheduled coverage during recovery. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionRestartsAgainstConcurrentOverlayContributionGeneration to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testProjectionRestartsAgainstConcurrentOverlayContributionGeneration in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineOverlayTests/testRejectedCompletedProjectionSuccessorRestartsWorkerAndCoalescesRetainedDemand root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineOverlayTests.swift RepoPromptTests.CodemapBindingEngineOverlayTests testRejectedCompletedProjectionSuccessorRestartsWorkerAndCoalescesRetainedDemand WorkspaceContext workspace_codemap_binding_engine.completed_projection_successor_restart completed_projection,overlay_generation,rejected_successor,worker_restart,coalescing,retained_demand,release async_state_machine root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub After completed coverage and a prepared overlay successor, restarting returns true exactly once and a duplicate restart returns false; replacement coverage drains with two total schedules and updates the existing retained ticket to the successor proof; releasing the ticket clears retained demand. Rejecting a prepared successor could strand completed coverage, start duplicate workers, leave retained consumers stale, or leak retained ownership. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testRejectedCompletedProjectionSuccessorRestartsWorkerAndCoalescesRetainedDemand to root/RepoPromptTests.CodemapBindingEngineOverlayTests/testRejectedCompletedProjectionSuccessorRestartsWorkerAndCoalescesRetainedDemand in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEnginePipelineTests/testOneRootServesMultipleLanguagePipelines root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEnginePipelineTests.swift RepoPromptTests.CodemapBindingEnginePipelineTests testOneRootServesMultipleLanguagePipelines WorkspaceContext workspace_codemap_binding_engine.multi_pipeline_root swift,typescript,concurrent_demand,one_root_epoch concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,CodeMapArtifactRuntime One language-neutral root registration concurrently serves Swift and TypeScript demands and freezes both ready bindings. A root record could remain language-bound or one pipeline could replace another. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Atomic cutover Slice 1 multi-pipeline root; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testOneRootServesMultipleLanguagePipelines to root/RepoPromptTests.CodemapBindingEnginePipelineTests/testOneRootServesMultipleLanguagePipelines in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEnginePipelineTests/testPipelineManifestsRemainDistinct root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEnginePipelineTests.swift RepoPromptTests.CodemapBindingEnginePipelineTests testPipelineManifestsRemainDistinct WorkspaceContext workspace_codemap_binding_engine.pipeline_manifest_isolation swift,typescript,namespace_digest,record_partition persistence_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,CodeMapArtifactRuntime Swift and TypeScript demands under one root persist different manifest namespaces containing only their own records. Pipeline records could overwrite or contaminate another language manifest. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Atomic cutover Slice 1 pipeline-scoped manifests; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testPipelineManifestsRemainDistinct to root/RepoPromptTests.CodemapBindingEnginePipelineTests/testPipelineManifestsRemainDistinct in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEnginePipelineTests/testRootInvalidationRevokesEveryPipeline root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEnginePipelineTests.swift RepoPromptTests.CodemapBindingEnginePipelineTests testRootInvalidationRevokesEveryPipeline WorkspaceContext workspace_codemap_binding_engine.multi_pipeline_invalidation swift,typescript,repository_authority_invalidation,pre_invalidation_ready,revoked_pipelines,manifest_drain async_state_machine root_swiftpm routine 2 ReviewGitRepositoryFixture,CodeMapArtifactRuntime Swift and TypeScript demands are both ready and visible before repository-authority invalidation; afterward the live snapshot contains neither pipeline, freeze is unavailable, and dirty manifest state is drained. Repository-authority invalidation could revoke only one pipeline, leave a live entry, or retain dirty manifest state. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 repository-authority invalidation with pre-ready and post-revocation proof; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testRootInvalidationRevokesEveryPipeline to root/RepoPromptTests.CodemapBindingEnginePipelineTests/testRootInvalidationRevokesEveryPipeline in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testDemandAdmissionCountsActiveAndDrainingProjectionMaterializationUsage root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testDemandAdmissionCountsActiveAndDrainingProjectionMaterializationUsage WorkspaceContext workspace_codemap_binding_engine.projection_usage_demand_admission projection_materialization,active_usage,draining_usage,source_reservation,demand_queue,admission async_resource_lifecycle root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBuildGate,EngineProjectionRecorder,EngineProjectionCatalogStub A gated projection materialization holds the exact source reservation and queues foreground demand while active; invalidation leaves the same draining reservation and still queues demand; releasing the build admits that demand ready and returns request, queue, and projection resources to zero. Foreground demand could oversubscribe source/materialization limits by ignoring active or canceled-but-draining projection work, or remain stranded after resources drain. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testDemandAdmissionCountsActiveAndDrainingProjectionMaterializationUsage to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testDemandAdmissionCountsActiveAndDrainingProjectionMaterializationUsage in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testNonGitRootBecomesUnavailableWithoutArtifactManifestOrBuildWork root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testNonGitRootBecomesUnavailableWithoutArtifactManifestOrBuildWork WorkspaceContext workspace_codemap_binding_engine.non_git_zero_work non_git,terminal_capability,zero_manifest,zero_coordinator,zero_build compatibility_negative root_swiftpm routine 4 ReviewGitRepositoryFixture,CodeMapArtifactRuntime A non-Git root becomes terminally unavailable after capability resolution with no manifest read, coordinator request, or builder execution. Fail-open non-Git handling could invoke artifact infrastructure or publish codemaps outside eligible repositories. git_subprocess;filesystem;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 inert binding engine orchestration; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testNonGitRootBecomesUnavailableWithoutArtifactManifestOrBuildWork to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testNonGitRootBecomesUnavailableWithoutArtifactManifestOrBuildWork in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandClockExpiryBoundsRetryClampAndRevocationAreDeterministic root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionDemandClockExpiryBoundsRetryClampAndRevocationAreDeterministic WorkspaceContext workspace_codemap_binding_engine.projection_demand_bounds_expiry_revocation retained_demand,request_limit,file_id_limit,metadata_limit,retry_clamp,clock_expiry,late_completion,path_revocation bounded_state_machine root_swiftpm routine 6 ReviewGitRepositoryFixture,EngineUptimeClock,EngineAsyncGate,EngineProjectionRecorder A controlled clock proves request-count rejection with the 25 ms retry floor, expiry that releases capacity, exact file-ID and metadata-byte limit diagnostics, expiry when a blocked batch completes after deadline, and stale revocation with exact telemetry after path invalidation. Retained projection demands could exceed count or metadata bounds, spin on undersized retry values, retain capacity past deadline, become ready after late completion, or survive invalidation. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionDemandClockExpiryBoundsRetryClampAndRevocationAreDeterministic to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandClockExpiryBoundsRetryClampAndRevocationAreDeterministic in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandEarliestDeadlineOvertakesPreloadAndSharesBackgroundFairnessQuantum root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionDemandEarliestDeadlineOvertakesPreloadAndSharesBackgroundFairnessQuantum WorkspaceContext workspace_codemap_binding_engine.projection_deadline_fairness projection_queue,earliest_deadline,preload,retained_demand,background_fairness,ordinal_rebase concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineAsyncGate,EngineHookEvents After one blocked preload, queued work is admitted in the exact order earlier-deadline demand, background preload fairness quantum, then later-deadline demand, even with the admission ordinal initialized at overflow. Projection scheduling could ignore retained-demand deadlines, starve background preload work, or corrupt ordering when admission ordinals rebase. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionDemandEarliestDeadlineOvertakesPreloadAndSharesBackgroundFairnessQuantum to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandEarliestDeadlineOvertakesPreloadAndSharesBackgroundFairnessQuantum in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandJoinsActiveBatchWithoutPreemptionAndBecomesExactReady root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionDemandJoinsActiveBatchWithoutPreemptionAndBecomesExactReady WorkspaceContext workspace_codemap_binding_engine.projection_demand_join active_preload,retained_projection_demand,join,no_preemption,exact_ready,release async_resource_lifecycle root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineAsyncGate,EngineProjectionRecorder A retained projection demand joins the admitted blocked preload without cancellation, becomes exactly ready after the batch resumes, and releases its retained ownership. Demand could preempt shared preload work, never become ready, or leak retained projection ownership. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup consolidated_replacement 0 Replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionIncompletePreloadDemandsProjectionWithoutPublishingPreProofTargets; three intrinsic join-ready-release lifecycle scenarios are credited and no duplicate store scenario is transferred.; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionDemandJoinsActiveBatchWithoutPreemptionAndBecomesExactReady to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionDemandJoinsActiveBatchWithoutPreemptionAndBecomesExactReady in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadCleanMaterializationOversizePublishesTerminalEntry root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadCleanMaterializationOversizePublishesTerminalEntry WorkspaceContext workspace_codemap_binding_engine.projection_clean_oversize_terminal projection_preload,clean_blob,materialization_limit,oversize,terminal_entry,no_build compatibility_negative root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineProjectionRecorder,GitBlobSourceMaterializationService A clean Git candidate exceeding blob materialization policy publishes a terminal oversize projection entry and never invokes the syntax builder or increments projection-build telemetry. Oversize clean blobs could be retried indefinitely, omitted from terminal coverage, or reach the parser despite the materialization bound. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadCleanMaterializationOversizePublishesTerminalEntry to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadCleanMaterializationOversizePublishesTerminalEntry in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadMapsWorktreeAndTerminalGitClassificationsWithoutCleanReuse root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadMapsWorktreeAndTerminalGitClassificationsWithoutCleanReuse WorkspaceContext workspace_codemap_binding_engine.projection_git_classification_matrix checkout_transform,conflict,assume_unchanged,skip_worktree,symlink,gitlink,validated_source,terminal_exclusion git_fixture_contract root_swiftpm routine 6 ReviewGitRepositoryFixture,EngineProjectionCatalogStub,EngineProjectionRecorder One preload page reads and builds exactly four authoritative worktree cases, terminally excludes symlink and gitlink candidates, seals coverage, and performs no clean locator work. Preload could trust index flags or conflict stages, read excluded paths, or leave deterministic exclusions transient. git_subprocess;filesystem;artifact_store;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 7 explicit preload classification outcomes; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadMapsWorktreeAndTerminalGitClassificationsWithoutCleanReuse to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadMapsWorktreeAndTerminalGitClassificationsWithoutCleanReuse in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadMissingEnvelopeClassifiesThenReusesLocatorAndCAS root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadMissingEnvelopeClassifiesThenReusesLocatorAndCAS WorkspaceContext workspace_codemap_binding_engine.projection_missing_envelope_locator_reuse projection_preload,missing_envelope,classification,locator,cas,manifest_repair,no_source_read persistence_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub After removing the current manifest envelope but retaining locator and CAS state, preload performs one classification and one manifest repair while doing no source read, materialization, or projection build. A missing manifest envelope could force redundant source work or fail to reconstruct persistent warm state from verified locator and CAS data. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadMissingEnvelopeClassifiesThenReusesLocatorAndCAS to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadMissingEnvelopeClassifiesThenReusesLocatorAndCAS in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadReusesUnchangedBlobAndBuildsOnlyChangedFilePerWorktree root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadReusesUnchangedBlobAndBuildsOnlyChangedFilePerWorktree WorkspaceContext workspace_codemap_binding_engine.projection_worktree_reuse main,linked,external,unchanged_blob,locator_hit,cas_reuse,dirty_source,changed_only_build git_fixture_contract root_swiftpm routine 6 ReviewGitRepositoryFixture,CodeMapArtifactRuntime,EngineProjectionCatalogStub For main, linked, and explicitly external worktrees, a mixed preload reuses exactly one unchanged locator/CAS artifact and performs exactly one validated-source build for unique dirty bytes. Cross-worktree preload could rebuild unchanged blobs, reuse dirty blob identity, or leak worktree manifests across authority boundaries. git_subprocess;filesystem;artifact_store;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 7 changed-only build and cross-worktree locator proof; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadReusesUnchangedBlobAndBuildsOnlyChangedFilePerWorktree to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadReusesUnchangedBlobAndBuildsOnlyChangedFilePerWorktree in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadSchedulingIsExplicitIdempotentAndSealsEmptyCatalog root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadSchedulingIsExplicitIdempotentAndSealsEmptyCatalog WorkspaceContext workspace_codemap_binding_engine.projection_preload_explicit_idempotent_empty_seal projection_preload,explicit_schedule,idempotence,empty_catalog,coverage_seal,accounting async_state_machine root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub Registration schedules no preload implicitly; two explicit schedule calls coalesce into one job and one scheduled/completed count; the empty catalog publishes exactly one seal with no segment and drains active and queued batches. Registration could trigger hidden preload work, duplicate schedules could create parallel jobs, or an empty catalog could complete without a coverage seal. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadSchedulingIsExplicitIdempotentAndSealsEmptyCatalog to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadSchedulingIsExplicitIdempotentAndSealsEmptyCatalog in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadUnloadCancelsBlockedCatalogPageAndDrainsAccounting root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadUnloadCancelsBlockedCatalogPageAndDrainsAccounting WorkspaceContext workspace_codemap_binding_engine.projection_unload_catalog_cancellation projection_preload,blocked_catalog_page,root_unload,cancellation,resource_drain,no_publication cancellation_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineAsyncGate,EngineProjectionRecorder Unloading a root whose projection catalog page is blocked cancels the coverage when the gate releases, publishes no snapshot, and leaves zero jobs, batches, and projection resources with exactly one canceled-coverage count. Root unload could leak a catalog worker or projection reservation, publish after lifetime end, or miss cancellation accounting. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadUnloadCancelsBlockedCatalogPageAndDrainsAccounting to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadUnloadCancelsBlockedCatalogPageAndDrainsAccounting in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadUsesCurrentV2EnvelopeAndFinalSegmentCarriesSealCompletion root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadUsesCurrentV2EnvelopeAndFinalSegmentCarriesSealCompletion WorkspaceContext workspace_codemap_binding_engine.projection_v2_envelope_seal projection_preload,v2_envelope,warm_hit,no_classification,no_source_work,segment,seal persistence_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub Preload consumes a current v2 manifest envelope with one envelope hit and no classification, build, materialization, or source read; it emits one non-empty segment followed by a seal whose completion identity and counts exactly match the segment. Warm projection could bypass the versioned envelope, perform redundant source work, or publish a final seal inconsistent with its terminal segment. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadUsesCurrentV2EnvelopeAndFinalSegmentCarriesSealCompletion to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadUsesCurrentV2EnvelopeAndFinalSegmentCarriesSealCompletion in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadWorktreeFileTooLargePublishesTerminalEntry root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionPreloadWorktreeFileTooLargePublishesTerminalEntry WorkspaceContext workspace_codemap_binding_engine.projection_worktree_oversize_terminal projection_preload,dirty_worktree,validated_reader,file_too_large,oversize,terminal_entry,no_build compatibility_negative root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineProjectionRecorder,EngineProjectionCatalogStub A dirty worktree candidate whose validated reader reports fileTooLarge is classified once and published as terminal oversize without starting or invoking a projection build. Oversize worktree files could be treated as transient, retried or parsed repeatedly, or omitted from deterministic projection coverage. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionPreloadWorktreeFileTooLargePublishesTerminalEntry to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionPreloadWorktreeFileTooLargePublishesTerminalEntry in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionRescheduleCountsSameRootDrainingSourceAndMaterialization root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionRescheduleCountsSameRootDrainingSourceAndMaterialization WorkspaceContext workspace_codemap_binding_engine.projection_reschedule_draining_resources projection_reschedule,same_root,draining_source,materialization_limit,retry,resource_accounting async_resource_lifecycle root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineMultiEntryGate,EngineProjectionRecorder,EngineProjectionCatalogStub After invalidation cancels a gated preload, a same-root replacement retries rather than acquiring a second source/materialization reservation; only one build enters before release and final projection resources and active batches drain to zero. A canceled-but-draining same-root batch could be omitted from resource bounds, allowing duplicate materialization or leaking reservations after reschedule. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionRescheduleCountsSameRootDrainingSourceAndMaterialization to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionRescheduleCountsSameRootDrainingSourceAndMaterialization in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionRescheduleWaitsForSameRootDrainingBatchAdmission root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testProjectionRescheduleWaitsForSameRootDrainingBatchAdmission WorkspaceContext workspace_codemap_binding_engine.projection_reschedule_draining_batch_bound projection_reschedule,same_root,draining_batch,per_root_limit,queue,cancellation concurrency_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineMultiEntryGate,EngineProjectionRecorder,EngineProjectionCatalogStub At a one-active-batch-per-root bound, invalidation leaves the first gated batch draining and queues the replacement without starting a second build; release yields one canceled coverage, two schedules, completed replacement coverage, and zero active batches. Rescheduling could ignore a draining batch and violate the per-root active bound, or fail to admit the replacement after the predecessor drains. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testProjectionRescheduleWaitsForSameRootDrainingBatchAdmission to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testProjectionRescheduleWaitsForSameRootDrainingBatchAdmission in binding-engine thematic split. +root/RepoPromptTests.CodemapBindingEngineProjectionTests/testRetainedProjectionDemandUsesSpareCapacityBeforeForegroundQuantumIsExhausted root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineProjectionTests.swift RepoPromptTests.CodemapBindingEngineProjectionTests testRetainedProjectionDemandUsesSpareCapacityBeforeForegroundQuantumIsExhausted WorkspaceContext workspace_codemap_binding_engine.projection_demand_spare_capacity retained_projection_demand,foreground_request,spare_projection_capacity,fairness_quantum,no_starvation concurrency_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineAsyncGate,EngineProjectionRecorder,EngineHookEvents While a foreground source read occupies its own admission path, retained projection demand uses otherwise spare projection capacity, starts exactly one batch, completes coverage before the foreground request is released, and then releases its ticket. A shared fairness quantum could unnecessarily serialize independent projection capacity behind foreground work and starve retained projection demand. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 2026-06-26 scoped authoritative-census ledger reconciliation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testRetainedProjectionDemandUsesSpareCapacityBeforeForegroundQuantumIsExhausted to root/RepoPromptTests.CodemapBindingEngineProjectionTests/testRetainedProjectionDemandUsesSpareCapacityBeforeForegroundQuantumIsExhausted in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testPostCommitManifestAdoptionAuthorityRaceRollsBackOverlaySessionAndLease root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineRootLeaseTests.swift RepoPromptTests.CodemapBindingEngineRootLeaseTests testPostCommitManifestAdoptionAuthorityRaceRollsBackOverlaySessionAndLease WorkspaceContext workspace_codemap_binding_engine.adoption_atomic_rollback post_commit_gate,authority_invalidation,overlay_rollback,session_consistency,lease_release concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineBuildGate Authority invalidation after the overlay adoption commit but before the engine resumes rolls the adoption back, leaves no ready entry, and releases exact retained lease accounting. A reentrant authority change could leave overlay-ready state without a matching engine session or leak an adopted lease. git_subprocess;filesystem;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 transactional adoption rollback; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testPostCommitManifestAdoptionAuthorityRaceRollsBackOverlaySessionAndLease to root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testPostCommitManifestAdoptionAuthorityRaceRollsBackOverlaySessionAndLease in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testSequentialRootsRetainGlobalAdoptionLeaseBudgetUntilUnloadThenRecover root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineRootLeaseTests.swift RepoPromptTests.CodemapBindingEngineRootLeaseTests testSequentialRootsRetainGlobalAdoptionLeaseBudgetUntilUnloadThenRecover WorkspaceContext workspace_codemap_binding_engine.global_adoption_lease_lifetime sequential_roots,global_count_bound,retained_bytes,unload_release,same_session_retry memory_lifetime_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,CodeMapArtifactRuntime A retained warm adoption holds the exact global count and byte budget; a second root's adoption remains retryable under pressure and succeeds in the same root session after unloading the first owner. Transient lease pressure could become a terminal empty adoption, or unload could fail to release capacity for a same-session retry. git_subprocess;filesystem;actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 accounting strengthened for Cutover Slice 1 same-session adoption retry; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testSequentialRootsRetainGlobalAdoptionLeaseBudgetUntilUnloadThenRecover to root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testSequentialRootsRetainGlobalAdoptionLeaseBudgetUntilUnloadThenRecover in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testUnloadDuringBlockedManifestRegistrationFailsAndReleasesRootAndLeaseState root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineRootLeaseTests.swift RepoPromptTests.CodemapBindingEngineRootLeaseTests testUnloadDuringBlockedManifestRegistrationFailsAndReleasesRootAndLeaseState WorkspaceContext workspace_codemap_binding_engine.registration_unload_fence blocked_manifest_load,unload,registration_failure,root_cleanup,lease_cleanup concurrency_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,EngineBuildGate Unload during a gated lazy manifest demand immediately cancels the request and releases root, active/admission, owner, history, overlay, and lease accounting while the shared I/O remains blocked; shutdown still joins that detached I/O after release. A cancelled unload waiter could retain active/admission capacity until blocked manifest I/O returns, or detached I/O could escape shutdown joining and republish stale state. git_subprocess;filesystem;actor temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 blocked-adoption unload detachment and drain; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testUnloadDuringBlockedManifestRegistrationFailsAndReleasesRootAndLeaseState to root/RepoPromptTests.CodemapBindingEngineRootLeaseTests/testUnloadDuringBlockedManifestRegistrationFailsAndReleasesRootAndLeaseState in binding-engine thematic split. @@ -990,54 +952,73 @@ root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestMutat root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestMutationAfterClassificationFailsClosedWithoutSourceRead root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineWarmManifestTests.swift RepoPromptTests.CodemapBindingEngineWarmManifestTests testWarmManifestMutationAfterClassificationFailsClosedWithoutSourceRead WorkspaceContext workspace_codemap_binding_engine.warm_manifest_post_classification_fence classification,source_authority_fingerprint,worktree_mutation,stale_suppression,no_source_read filesystem_race_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,EngineOneShotFileMutation The first demand emits a manifest hit and invokes the post-classification fingerprint hook; the mutation is rejected during authority capture, the stale candidate stays absent, the trigger completes, no lease is retained, and no source read occurs. Lazy adoption could remain unexecuted in the test or carry an obsolete clean classification into a later authority token. git_subprocess,filesystem,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 first-demand post-classification TOCTOU regression; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testWarmManifestMutationAfterClassificationFailsClosedWithoutSourceRead to root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestMutationAfterClassificationFailsClosedWithoutSourceRead in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestMutationDuringClassificationCannotPublishStaleCleanEntry root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineWarmManifestTests.swift RepoPromptTests.CodemapBindingEngineWarmManifestTests testWarmManifestMutationDuringClassificationCannotPublishStaleCleanEntry WorkspaceContext workspace_codemap_binding_engine.warm_manifest_registration_race classification_gate,worktree_mutation,retry,stale_suppression,no_source_read filesystem_race_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineOneShotFileMutation The first demand emits a manifest hit and invokes the Git-collection mutation hook; the stale candidate remains unadopted, the trigger completes, no adoption lease remains, and no validated-source read occurs. A vacuous lazy-registration test could miss that classification never ran, or publish a manifest entry proven against an obsolete file generation. git_fixture,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 first-demand warm-adoption mutation; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testWarmManifestMutationDuringClassificationCannotPublishStaleCleanEntry to root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestMutationDuringClassificationCannotPublishStaleCleanEntry in binding-engine thematic split. root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestRejectsExplicitNonCleanCandidateStatesWithoutSourceRead root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineWarmManifestTests.swift RepoPromptTests.CodemapBindingEngineWarmManifestTests testWarmManifestRejectsExplicitNonCleanCandidateStatesWithoutSourceRead WorkspaceContext workspace_codemap_binding_engine.warm_manifest_non_clean_matrix staged_only,staged_and_unstaged,untracked_replacement,conflict,checkout_transform,no_source_read git_fixture_contract root_swiftpm routine 5 ReviewGitRepositoryFixture,CodeMapArtifactRuntime For all five non-clean states, the first demand emits a manifest hit, rejects the stale candidate, completes a clean trigger materialization, performs no source read, and retains no adoption lease. A vacuous lazy-registration test could skip classification, or non-clean Git/index/worktree states could be mislabeled as persisted clean manifest artifacts. git_subprocess,filesystem,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 first-demand warm-candidate fail-closed matrix; Moved from root/RepoPromptTests.WorkspaceCodemapBindingEngineTests/testWarmManifestRejectsExplicitNonCleanCandidateStatesWithoutSourceRead to root/RepoPromptTests.CodemapBindingEngineWarmManifestTests/testWarmManifestRejectsExplicitNonCleanCandidateStatesWithoutSourceRead in binding-engine thematic split. -root/RepoPromptTests.CodemapFullLoadDebugHarnessTests/testAggregateReadyRequiresEveryRootTerminal root Tests/RepoPromptTests/Diagnostics/CodemapFullLoadDebugHarnessTests.swift RepoPromptTests.CodemapFullLoadDebugHarnessTests testAggregateReadyRequiresEveryRootTerminal WorkspaceContext/CodeMap codemap.full_load.aggregate_terminal_contract proof_complete,terminal_ineligible,pending,failed,zero_root authority_contract root_swiftpm fast 4 Only proof-complete eligible roots plus terminal ineligible or excluded roots produce ready; pending, failed, and zero-root inputs remain non-ready. A diagnostic waiter could report readiness from task absence, partial roots, or incomplete diagnostics. test_case retain 0 Phase 3 authoritative aggregate contract. -root/RepoPromptTests.CodemapFullLoadDebugHarnessTests/testCorrelationAcceptsOnlyArmedTargetAndOperation root Tests/RepoPromptTests/Diagnostics/CodemapFullLoadDebugHarnessTests.swift RepoPromptTests.CodemapFullLoadDebugHarnessTests testCorrelationAcceptsOnlyArmedTargetAndOperation WorkspaceContext/CodeMap codemap.full_load.accepted_switch_correlation arm_id,target_workspace,operation_id,accepted_uptime,switch_result correlation_contract root_swiftpm fast 4 Wrong targets and operation IDs are rejected; the exact accepted operation retains its monotonic boundary and switched result. A no-op, unrelated, or superseded switch could be correlated with later codemap completion. test_case retain 0 Phase 3 accepted-switch correlation contract. -root/RepoPromptTests.CodemapFullLoadDebugHarnessTests/testMixedEpochUniverseDoesNotRevalidate root Tests/RepoPromptTests/Diagnostics/CodemapFullLoadDebugHarnessTests.swift RepoPromptTests.CodemapFullLoadDebugHarnessTests testMixedEpochUniverseDoesNotRevalidate WorkspaceContext/CodeMap codemap.full_load.mixed_epoch_revalidation root_lifetime,catalog_generation,ingress_generation,engine_identity stale_generation_contract root_swiftpm fast 2 An identical visible-root identity set revalidates, while a replacement lifetime and generations fail exact equality. Actor reentrancy could merge proof from an old root epoch with a new visible universe and manufacture success. test_case retain 0 Phase 3 mixed-epoch fail-closed contract. -root/RepoPromptTests.CodemapFullLoadDebugHarnessTests/testPrivacySafePayloadOmitsPathsAndSourceText root Tests/RepoPromptTests/Diagnostics/CodemapFullLoadDebugHarnessTests.swift RepoPromptTests.CodemapFullLoadDebugHarnessTests testPrivacySafePayloadOmitsPathsAndSourceText WorkspaceContext/CodeMap codemap.full_load.payload_privacy identifiers,generations,counters,no_paths,no_source_text privacy_contract root_swiftpm fast 1 The serialized per-root payload contains no root/full-path keys, source-text field, or user-home path. Hidden diagnostics could leak physical repository paths or source content into benchmark artifacts. test_case retain 0 Phase 3 privacy-safe payload contract. -root/RepoPromptTests.CodemapFullLoadDebugHarnessTests/testStatisticsRetainValidSlowSamples root Tests/RepoPromptTests/Diagnostics/CodemapFullLoadDebugHarnessTests.swift RepoPromptTests.CodemapFullLoadDebugHarnessTests testStatisticsRetainValidSlowSamples WorkspaceContext/CodeMap codemap.full_load.statistics_slow_sample_retention raw_samples,median,nearest_rank_p95,tukey_flag,reliability statistics_contract root_swiftpm fast 1 A valid slow sample remains in raw data and nearest-rank p95 while Tukey only flags it and reliability becomes low. Benchmark reporting could silently discard slow valid runs and overstate improvement stability. test_case retain 0 Phase 3 variance-aware statistics contract. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testDecodeRecoveryExhaustionWinsOverObservedTermination root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testDecodeRecoveryExhaustionWinsOverObservedTermination AgentMode/Codex codex.app_server.lifecycle.decode_exhaustion_precedence decode_recovery,poisoning,observer_exit,first_claim subprocess_lifecycle_regression root_swiftpm routine 1 persistent_codex_fixture Exhausting the decode recovery budget terminates the matching generation with its original reason despite the resulting observed child exit. Malformed-output poisoning could be relabeled as an unexpected crash or affect a later generation. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 lifecycle-precedence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testDeinitLeavesReapOwnershipWithObserver root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testDeinitLeavesReapOwnershipWithObserver AgentMode/Codex codex.app_server.exit_observer.deinit_reap deinit,sole_reaper,zombie_prevention subprocess_lifecycle_regression root_swiftpm routine 1 persistent_codex_fixture Dropping the client leaves the detached observer as the only reaper and waitpid reaches ECHILD without the test consuming status. Client deinit could cancel reap ownership and strand a zombie app-server process. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 sole-reaper lifecycle coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testExplicitStopWinsOverObservedTermination root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testExplicitStopWinsOverObservedTermination AgentMode/Codex codex.app_server.lifecycle.explicit_stop_precedence explicit_stop,observer_exit,first_claim subprocess_lifecycle_regression root_swiftpm routine 1 persistent_codex_fixture A blocked request receives processNotRunning and the generation retains explicitStop after TERM produces an observed exit. Intentional stop could be mislabeled as an unexpected process crash. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 lifecycle-precedence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testListModelsRetriesTypedProcessExitOnceOnFreshProcess root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testListModelsRetriesTypedProcessExitOnceOnFreshProcess AgentMode/Codex codex.app_server.model_list.typed_exit_retry model_list,process_exit,retry,fresh_process subprocess_lifecycle_regression root_swiftpm routine 1 exit_then_model_codex_fixture A typed processExited failure during model/list receives one fresh-process retry and returns the successful replacement process model response. Typed exit recovery could regress from the established EOF recovery behavior and leave model discovery unavailable after a transient app-server exit. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 typed-exit model-list recovery coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testNilLaunchDirectoryUsesCLIProcessConfigurationDefaultInExitEvidence root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testNilLaunchDirectoryUsesCLIProcessConfigurationDefaultInExitEvidence AgentMode/Codex codex.app_server.launch_directory.default launch_directory,temp_directory,process_cwd,exit_evidence subprocess_lifecycle_regression root_swiftpm routine 1 working_directory_exit_codex_fixture A nil process launch directory records the CLIProcessConfiguration temp default, the child reports the same canonical cwd, and typed exit evidence preserves exited(41). The app-server could inherit the app cwd while diagnostics claim a different launch contract. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 App-server launch-directory authority contract. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStaleObservedExitCannotMutateReplacementGeneration root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStaleObservedExitCannotMutateReplacementGeneration AgentMode/Codex codex.app_server.lifecycle.stale_generation_exit_rejection generation,observer_identity,replacement async_concurrency_lifecycle root_swiftpm routine 1 persistent_codex_fixture A delivered old-generation exit leaves the replacement PID, generation, running state, and termination reason unchanged. Late observer callbacks could poison a replacement transport. subprocess;filesystem;actor test_case+fixture_cleanup retain 0 WI-2 generation-safety coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStopDuringPrepublicationObserverSettlementPreventsReplacementSpawn root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStopDuringPrepublicationObserverSettlementPreventsReplacementSpawn AgentMode/Codex codex.app_server.lifecycle.stop_observer_settlement_spawn_fence stop,observer_settlement,startup_cancellation,pre_spawn,termination_retirement async_concurrency_lifecycle root_swiftpm routine 1 persistent_codex_fixture,ChildExitOutcomePublicationGate A stop during pre-publication observer settlement waits for the winning settlement and revokes the concurrent replacement start; releasing settlement afterward cannot produce a second process spawn or live transport. A replacement start waiting on observer settlement could retain startup authority past stop and spawn an app-server after shutdown. subprocess;filesystem;actor;async_wait test_case+fixture_cleanup retain 0 WI-2 pre-publication settlement post-stop spawn-fence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStopDuringRestartPreparationPreventsSpawnAfterReturn root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStopDuringRestartPreparationPreventsSpawnAfterReturn AgentMode/Codex codex.app_server.lifecycle.stop_restart_spawn_fence stop,restart,startup_cancellation,pre_spawn,termination_retirement async_concurrency_lifecycle root_swiftpm routine 1 persistent_codex_fixture,ProcessSpawnPreparationGate A stop during blocked restart preparation returns only after revoking startup authority; releasing preparation afterward cannot produce a second process spawn or live transport. A settled teardown task could let stop return without cancelling a restart, allowing an app-server to spawn and survive after shutdown. subprocess;filesystem;actor;async_wait test_case+fixture_cleanup retain 0 WI-2 restart pre-spawn shutdown regression coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStartupEOFReturnsTypedExitWithSettledBoundedStderr root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStartupEOFReturnsTypedExitWithSettledBoundedStderr AgentMode/Codex codex.app_server.process_exit.typed_stderr_evidence stdout_eof,exit_status,terminal_probe,observer_join,root_signal_window,stderr_tail,truncation,descendant_stderr,family_cleanup,first_claim,shared_completion subprocess_lifecycle_regression root_swiftpm routine 1 early_exit_codex_fixture,ChildExitOutcomePublicationGate A publication gate holds beyond the diagnostic window after pre-reap root-PID signaling closure, forcing the non-destructive terminal probe and sole-observer join before processExited returns the exact final 8 KiB raw stderr suffix; a losing stop remains pending until the winning settlement completes. Startup EOF could signal a reaped or reused PID, collapse a real exit into processNotRunning, consume status with a second reap, snapshot incomplete descendant-held stderr, or let duplicate lifecycle callers return before teardown completes. subprocess;filesystem;async_wait;dispatch_wait test_case+fixture_cleanup retain 0 Deterministic kernel-boundary signal closure, terminal-probe arbitration, bounded startup diagnostics, descendant cleanup, and shared-completion coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStartupSignalExitKeepsSignalSemanticsAndOmitsEmptyStderr root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStartupSignalExitKeepsSignalSemanticsAndOmitsEmptyStderr AgentMode/Codex codex.app_server.process_exit.signal_evidence signal,empty_stderr,typed_exit subprocess_lifecycle_regression root_swiftpm routine 1 early_exit_codex_fixture A SIGKILL startup exit remains uncaughtSignal(SIGKILL), retains empty raw stderr, and omits stderr from rendered diagnostics. Signal exits could be normalized into ambiguous integer codes or render empty diagnostic noise. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 typed exit-evidence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStartupStdoutEOFWhileRootLivesKeepsGenericFailure root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStartupStdoutEOFWhileRootLivesKeepsGenericFailure AgentMode/Codex codex.app_server.process_exit.live_root_stdout_eof stdout_eof,live_root,generic_failure,termination subprocess_lifecycle_regression root_swiftpm routine 1 live_after_stdout_eof_codex_fixture EOF from a still-running root retains processNotRunning with stdoutEOF and proceeds through normal termination instead of waiting indefinitely for typed exit. Terminal-exit arbitration could join a live root observer forever or fabricate typed evidence when only stdout closed. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 Worktree-bound Codex startup EOF arbitration converse coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testStderrCaptureRetainsExactRawSuffixAtEveryBoundary root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testStderrCaptureRetainsExactRawSuffixAtEveryBoundary AgentMode/Codex codex.app_server.stderr_tail.byte_boundaries stderr,byte_cap,truncation,invalid_utf8,multichunk deterministic_unit root_swiftpm fast 6 CodexProcessStderrCapture Empty, 1, 8191, 8192, 8193, and multi-chunk invalid-UTF-8 inputs retain the exact expected suffix and truncation bit. Boundary drift could lose bytes, overrun the cap, or decode evidence before rendering. test_case retain 0 WI-2 raw stderr capture coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testTimeoutPoisoningWinsOverObservedTermination root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testTimeoutPoisoningWinsOverObservedTermination AgentMode/Codex codex.app_server.lifecycle.timeout_precedence timeout,transport_poisoning,observer_exit,first_claim subprocess_lifecycle_regression root_swiftpm routine 1 persistent_codex_fixture A timed-out thread/start retains requestFailed timeout and the timeout termination reason after observer-driven teardown. Timeout poisoning could be relabeled as a process crash and lose its request-level meaning. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 lifecycle-precedence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testTransportWriteFailureWinsOverObservedTermination root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testTransportWriteFailureWinsOverObservedTermination AgentMode/Codex codex.app_server.lifecycle.stdin_write_precedence stdin,EPIPE,observer_exit,first_claim subprocess_lifecycle_regression root_swiftpm routine 1 persistent_codex_fixture,FDWriteError An injected EPIPE during initialize remains transportWriteFailed with stdinWrite lifecycle reason after observer-owned teardown. A write failure could collapse to processNotRunning or processExited and hide the actionable errno. subprocess;filesystem;async_wait test_case+fixture_cleanup retain 0 WI-2 lifecycle-precedence coverage. -root/RepoPromptTests.CodexAppServerClientProcessExitTests/testTypedSpawnErrnosMapToExecutableUnavailable root Tests/RepoPromptTests/AgentMode/Codex/CodexAppServerClientProcessExitTests.swift RepoPromptTests.CodexAppServerClientProcessExitTests testTypedSpawnErrnosMapToExecutableUnavailable AgentMode/Codex codex.app_server.spawn_failure.executable_unavailable spawn,errno_2,errno_13,executable_unavailable,sentinel process_launch_failure_regression root_swiftpm routine 2 ProcessLauncherError,processSpawnPreparation Typed ENOENT and EACCES spawn failures at the app-server launch boundary become sentinel-prefixed executableUnavailable client errors. A runtime disappearing or losing execute permission after resolution could be mislabeled as authentication-required or generic failure. filesystem;subprocess test_case+fixture_cleanup retain -11 root/RepoPromptTests.CodexRuntimeLaunchFailureClassificationTests/testSpawnErrnoThirteenDetailsProduceClassifiedPermissionMessage -> root/RepoPromptTests.CodexAppServerClientProcessExitTests/testTypedSpawnErrnosMapToExecutableUnavailable; root/RepoPromptTests.CodexRuntimeLaunchFailureClassificationTests/testSpawnErrnoTwoDetailsProduceClassifiedExecutableUnavailableMessage -> root/RepoPromptTests.CodexAppServerClientProcessExitTests/testTypedSpawnErrnosMapToExecutableUnavailable; root/RepoPromptTests.CodexRuntimeLaunchFailureClassificationTests/testUnrelatedFailureDetailsAreNotClassifiedAsLaunchFailures -> removed with the redundant textual runtimeLaunchFailureMessage helper. The sentinel classifier contract remains live; the -11 delta replaces 13 synthetic helper scenarios with the two real POSIX launch outcomes. +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphButStrictQueryRemainsIncomplete root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphButStrictQueryRemainsIncomplete WorkspaceContext/CodeMap codemap.store.graph.ready_partial lazy_factory,accepted_ready_snapshot,pending_omission,partial_coverage,catalog_currentness capability_lifecycle_contract root_swiftpm routine 5 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,CodemapArmableSuspensionGate Graph construction remains zero before accepted ready publication, one exact-epoch graph is reused for newer ready overlays, current ready sources query as partial, pending publication is omitted, and catalog advance rejects old authority. Eager graph work or admission of pending/stale bindings could perform forbidden work or publish obsolete cross-generation results. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Slice 3B lazy exact-epoch store graph activation and ready-partial query; Slice A metadata rename testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphAndReturnsPartial -> testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphButStrictQueryRemainsIncomplete with all 5 scenarios preserved; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphButStrictQueryRemainsIncomplete to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testAcceptedReadyOverlayLazilyBuildsOneExactEpochGraphButStrictQueryRemainsIncomplete during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testDurableProjectionPublishesMarkerReadinessAfterDemandRelease root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testDurableProjectionPublishesMarkerReadinessAfterDemandRelease WorkspaceContext/CodeMap codemap.marker_readiness.durable_after_release durable_projection,demand_release,readiness_stream,file_tree_marker durable_publication_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture After the demand retain is released, durable readiness emits a ready update and the current tree still renders the file marker. Marker visibility could incorrectly depend on transient demand ownership and disappear after release. filesystem,git_fixture,artifact_store,actor,concurrency store_session+readiness_observer+root_unload retain 0 Census closure for durable marker readiness.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testDurableProjectionPublishesMarkerReadinessAfterDemandRelease to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testDurableProjectionPublishesMarkerReadinessAfterDemandRelease during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGetFileTreeCurrentSnapshotDoesNotAwaitOrRetainBlockedCodemapDemand root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testGetFileTreeCurrentSnapshotDoesNotAwaitOrRetainBlockedCodemapDemand WorkspaceContext/CodeMap codemap.tree.current_snapshot_nonblocking pending_demand,bounded_timeout,atomic_poll,bounded_drain,ready_marker,zero_retain async_concurrency_lifecycle root_swiftpm routine 2 CodemapStoreFixture,CodemapBoundedCompletionState,CodemapResolutionGate A current-snapshot tree completes before the fixed deadline without awaiting or retaining blocked codemap demand, omits the pending marker, and publishes the ready marker only after readiness without starting presentation work. A tree read could hang in structured task-group draining after timeout, retain blocked demand, or publish a marker before immutable readiness. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+bounded_external_timeout+root_unload retain 0 Final blocker closure for bounded tree timeout and pending-to-ready marker publication.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGetFileTreeCurrentSnapshotDoesNotAwaitOrRetainBlockedCodemapDemand to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGetFileTreeCurrentSnapshotDoesNotAwaitOrRetainBlockedCodemapDemand during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGetFileTreeCurrentSnapshotOmitsMarkerForReadyNoSymbols root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testGetFileTreeCurrentSnapshotOmitsMarkerForReadyNoSymbols WorkspaceContext/CodeMap codemap.tree.no_symbols_marker ready_no_symbols,current_snapshot,no_marker,zero_extra_work presentation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture A readyNoSymbols artifact remains visible in the current tree without a plus marker and without starting presentation work. No-symbol readiness could be misrepresented as an available codemap or trigger unnecessary rendering work. filesystem,git_fixture,artifact_store,actor store_session+demand_owner+root_unload retain 0 Census closure for no-symbol marker semantics.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGetFileTreeCurrentSnapshotOmitsMarkerForReadyNoSymbols to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGetFileTreeCurrentSnapshotOmitsMarkerForReadyNoSymbols during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphQueryRejectsForeignEpochAndUnreadySourcesWithoutCrossRootTargets root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testGraphQueryRejectsForeignEpochAndUnreadySourcesWithoutCrossRootTargets WorkspaceContext/CodeMap codemap.store.graph.root_isolation exact_root_epoch,same_name_roots,foreign_only_definition,unready_source,cross_root_negative dependency_isolation root_swiftpm routine 4 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,CodemapResolutionGate Two visible same-name roots build and query independent exact-epoch graphs; foreign-only definitions never become targets, foreign identities fail before graph access, and unready sources create no graph work. Root-name or file-name collisions could create cross-root candidates or let pending authority enter a query. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Slice 3B exact-root partitioning and foreign-only isolation; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGraphQueryRejectsForeignEpochAndUnreadySourcesWithoutCrossRootTargets to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphQueryRejectsForeignEpochAndUnreadySourcesWithoutCrossRootTargets during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphUpdateHidesQueuedContributionAndUnloadRevokesBlockedBuild root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testGraphUpdateHidesQueuedContributionAndUnloadRevokesBlockedBuild WorkspaceContext/CodeMap codemap.store.graph.coalesced_currentness contribution_generation,immediate_query,queued_rebuild,unload_revocation,unload_reload async_concurrency_lifecycle root_swiftpm routine 4 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,CodemapSelectionGraphBuildGate A newer desired contribution immediately hides an older queued shard; query remains immediate; unload revokes the blocked build; same-path reload receives a new epoch and graph. A queued worker could publish after revocation, expose an old contribution, or cross an unload/reload ABA boundary. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Renamed root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGraphUpdateCoalescesNewerContributionAndSuppressesSupersededPublication -> root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGraphUpdateHidesQueuedContributionAndUnloadRevokesBlockedBuild; Slice 3B unload revocation and queued-currentness coverage; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGraphUpdateHidesQueuedContributionAndUnloadRevokesBlockedBuild to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphUpdateHidesQueuedContributionAndUnloadRevokesBlockedBuild during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphWorkerConsumesNewerSnapshotArrivingDuringProcessAdmissionWait root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testGraphWorkerConsumesNewerSnapshotArrivingDuringProcessAdmissionWait WorkspaceContext/CodeMap codemap.graph.admission_wait_latest_snapshot process_admission_wait,newer_contribution,latest_observed_key,single_publication concurrency_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapSelectionGraphBuildGate,CodemapSelectionGraphProbe,CodemapSuspensionGate A graph worker waiting for global admission consumes the newer contribution snapshot and publishes that latest key exactly once after the blocker releases. An admitted worker could publish the snapshot captured before its wait, lose newer contributions, or perform a redundant stale build. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_workers+admission_gate+root_unload retain 0 Census closure for latest-snapshot graph admission.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testGraphWorkerConsumesNewerSnapshotArrivingDuringProcessAdmissionWait to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testGraphWorkerConsumesNewerSnapshotArrivingDuringProcessAdmissionWait during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testMarkerReadinessIgnoresCrossRootAndStaleEpochUpdates root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testMarkerReadinessIgnoresCrossRootAndStaleEpochUpdates WorkspaceContext/CodeMap codemap.marker_readiness.root_epoch_isolation cross_root_file,stale_epoch,current_marker,foreign_marker_negative identity_isolation_contract root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture A current-epoch update containing a foreign-root file cannot clear the current root marker, and a stale-epoch update is rejected; the foreign root remains unmarked. Readiness updates could cross root or lifetime boundaries and expose or revoke the wrong file marker. filesystem,git_fixture,artifact_store,actor store_session+root_unload retain 0 Cross-root and stale-epoch negative scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testMarkerReadinessIgnoresCrossRootAndStaleEpochUpdates to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testMarkerReadinessIgnoresCrossRootAndStaleEpochUpdates during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testMultiRootGraphQueryEnforcesAggregateBudgetBeforeNPlusOneMaterialization root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testMultiRootGraphQueryEnforcesAggregateBudgetBeforeNPlusOneMaterialization WorkspaceContext/CodeMap codemap.store.graph.aggregate_query_budgets multi_root,exact_boundary,n_plus_one,incremental_materialization,typed_budget bounded_input_contract root_swiftpm routine 3 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory Two roots at the aggregate reference-failure limit materialize exactly two results; adding a third root returns the typed N+1 budget failure while only the first two results materialize. Querying and retaining every per-root result before aggregate accounting could accumulate up to the root cap in oversized result arrays. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Slice 3B incremental aggregate query-budget repair; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testMultiRootGraphQueryEnforcesAggregateBudgetBeforeNPlusOneMaterialization to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testMultiRootGraphQueryEnforcesAggregateBudgetBeforeNPlusOneMaterialization during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testNonGitDemandBecomesTerminalWithoutSourceReadManifestBuildOrGraphWork root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testNonGitDemandBecomesTerminalWithoutSourceReadManifestBuildOrGraphWork WorkspaceContext/CodeMap codemap.store_seam.git_terminal_gate non_git,capability_gate,source_read,manifest,build,graph availability_contract root_swiftpm routine 6 CodemapStoreFixture,CodeMapArtifactRuntimeProvider,WorkspaceCodemapSelectionGraphFactory The engine capability service returns terminal non-Git while source reads, classifications, manifests, builds, materialization, and injected graph-factory invocations stay at zero. An ad hoc or duplicated Git gate could admit non-Git roots into expensive or unsafe codemap work. filesystem,actor test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B inert modern codemap store seam; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testNonGitDemandBecomesTerminalWithoutSourceReadManifestBuildOrGraphWork to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testNonGitDemandBecomesTerminalWithoutSourceReadManifestBuildOrGraphWork during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testNonGitPresentationPlanStartsNoCodemapRuntimeDemandBuildOrCASWork root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testNonGitPresentationPlanStartsNoCodemapRuntimeDemandBuildOrCASWork WorkspaceContext headless_p1.non_git_zero_work non_git,preflight,zero_runtime protocol_negative root_swiftpm routine 1 CodemapStoreFixture Non-Git presentation planning reports typed terminal coverage with all modern runtime, engine, manifest, and build counters at zero. Headless non-Git exports could accidentally start modern codemap or CAS work. temp_directory;codemap_runtime test_case+addTeardownBlock retain 0 Headless P1 grouped repair non-Git contract; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testNonGitPresentationPlanStartsNoCodemapRuntimeDemandBuildOrCASWork to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testNonGitPresentationPlanStartsNoCodemapRuntimeDemandBuildOrCASWork during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testPresentationFreezeRejectsPendingForeignEpochDuplicateAndLogicalPathMismatch root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testPresentationFreezeRejectsPendingForeignEpochDuplicateAndLogicalPathMismatch WorkspaceContext/CodeMap codemap.store.presentation.freeze_validation pending,non_git,mixed_epoch,duplicate_file,logical_path_mismatch,unretained_publication availability_contract root_swiftpm routine 5 CodemapStoreFixture,WorkspaceCodemapFrozenPresentationBundle Pending and terminal non-Git demands remain typed immediate outcomes, while mixed epochs, duplicate files, logical-path mismatches, and bundles without retained store authority fail closed without blocking later valid freeze publication. Invalid, foreign, unavailable, or fabricated presentation authority could be retained or trigger a legacy fallback. filesystem,git_fixture,artifact_store,actor,concurrency store_session+caller_bundle+explicit_release+root_unload retain 0 Slice 3A freeze admission and typed non-ready validation; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testPresentationFreezeRejectsPendingForeignEpochDuplicateAndLogicalPathMismatch to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testPresentationFreezeRejectsPendingForeignEpochDuplicateAndLogicalPathMismatch during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testPresentationRenderFailsClosedAfterDemandCancellationCatalogAdvanceAndUnload root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testPresentationRenderFailsClosedAfterDemandCancellationCatalogAdvanceAndUnload WorkspaceContext/CodeMap codemap.store.presentation.revocation cancellation,catalog_generation,root_unload,all_or_nothing,release_idempotence stale_generation_contract root_swiftpm routine 4 CodemapStoreFixture,WorkspaceCodemapFrozenPresentationBundle Cancellation removes multi-entry publication authority before cleanup resumes; catalog advance and unload revoke old bundles; explicit release is idempotent; every stale render returns no partial entries. A revoked handle or stale catalog/root entitlement could publish partial or obsolete codemap text. filesystem,git_fixture,artifact_store,actor,concurrency store_session+caller_bundle+explicit_release+root_unload retain 0 Slice 3A fail-closed presentation revocation and publication checks; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testPresentationRenderFailsClosedAfterDemandCancellationCatalogAdvanceAndUnload to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testPresentationRenderFailsClosedAfterDemandCancellationCatalogAdvanceAndUnload during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testProjectionManifestFailureDoesNotPublishMarkerReadiness root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testProjectionManifestFailureDoesNotPublishMarkerReadiness WorkspaceContext/CodeMap codemap.marker_readiness.manifest_failure_gate manifest_write_failure,complete_graph,no_ready_marker durable_publication_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodeMapRootManifestStoreHooks,CodemapSelectionGraphProbe Even when graph coverage completes, a simulated post-temporary-write manifest failure leaves the file visible but without a ready marker. Marker readiness could advertise projection data that never became durably discoverable. filesystem,git_fixture,artifact_store,actor,concurrency store_session+manifest_fault+root_unload retain 0 Census closure for manifest-gated marker readiness.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionManifestFailureDoesNotPublishMarkerReadiness to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testProjectionManifestFailureDoesNotPublishMarkerReadiness during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testProjectionManifestFailureRecoveredByLaterBatchPublishesAllMarkers root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testProjectionManifestFailureRecoveredByLaterBatchPublishesAllMarkers WorkspaceContext/CodeMap codemap.projection.manifest_failure_marker_recovery manifest_failure,durable_retry,same_page_batch,marker_readiness,authority_identity durable_publication_contract root_swiftpm routine 3 CodemapStoreFixture,CodeMapRootManifestStoreHooks An explicitly admitted engine projection survives the first manifest write failure, a later same-page durable batch covers both exact file authorities, and both current tree markers publish as ready. A failed manifest checkpoint could strand covered files without durable readiness markers or publish readiness for stale file authority. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Step 5/6 durable manifest recovery and exact marker closure; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionManifestFailureRecoveredByLaterBatchPublishesAllMarkers to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testProjectionManifestFailureRecoveredByLaterBatchPublishesAllMarkers during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testReadyArtifactProducesFileTreeMarkerBeforeGraphPublication root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testReadyArtifactProducesFileTreeMarkerBeforeGraphPublication WorkspaceContext/CodeMap codemap.marker_readiness.pre_graph ready_artifact,blocked_graph,file_tree_marker,zero_extra_work presentation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapGraphPublicationGate,CodemapSelectionGraphProbe A ready artifact renders its plus marker while graph publication is blocked, without a new build, graph factory, or presentation operation. Tree markers could be incorrectly coupled to graph publication or trigger additional codemap work. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_gate+root_unload retain 0 Census closure for pre-graph marker availability.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testReadyArtifactProducesFileTreeMarkerBeforeGraphPublication to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testReadyArtifactProducesFileTreeMarkerBeforeGraphPublication during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testReadyPublicationsTargetFreezeIndividuallyAndCoalesceOneRootGraphFreeze root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testReadyPublicationsTargetFreezeIndividuallyAndCoalesceOneRootGraphFreeze WorkspaceContext/CodeMap codemap.graph.ready_publication_coalescing two_ready_files,targeted_freeze,batched_signal,one_full_root_freeze,one_worker concurrency_contract root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapGraphPublicationGate,CodemapSelectionGraphProbe Two ready publications each perform a targeted freeze and signal while blocked, then release coalesces them into one full-root freeze, one worker, and one graph. Per-file readiness could launch redundant full-root graph builds or lose a ready contribution during coalescing. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_gate+graph_worker+root_unload retain 0 Two per-file publications coalesced into one root flush.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testReadyPublicationsTargetFreezeIndividuallyAndCoalesceOneRootGraphFreeze to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testReadyPublicationsTargetFreezeIndividuallyAndCoalesceOneRootGraphFreeze during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testStagedIncompleteResidentGraphReturnsTypedStructureCoverageWithoutReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testStagedIncompleteResidentGraphReturnsTypedStructureCoverageWithoutReceipt WorkspaceContext/CodeMap codemap.structure.staged_incomplete_coverage resident_nodes,staged_projection,incomplete_universe,typed_unavailable,no_receipt availability_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapSelectionGraphProbe A resident two-node graph with an accepted but unsealed projection segment returns exact incomplete definition-universe coverage instead of a structure result. Resident nodes from a staged replacement could be mistaken for complete authoritative structure. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_worker+root_unload retain 0 Census closure for staged incomplete graph coverage.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStagedIncompleteResidentGraphReturnsTypedStructureCoverageWithoutReceipt to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testStagedIncompleteResidentGraphReturnsTypedStructureCoverageWithoutReceipt during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testTargetedInvalidationClearsOnlyAffectedMarkerReadiness root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testTargetedInvalidationClearsOnlyAffectedMarkerReadiness WorkspaceContext/CodeMap codemap.marker_readiness.targeted_invalidation modified_file,marker_clear,unrelated_marker_preserved invalidation_contract root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture After two files become marker-ready, modifying one clears only its marker while the stable file marker remains visible. Path invalidation could leave a stale marker or revoke readiness for unrelated files in the root. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Affected-clear and unrelated-preservation scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testTargetedInvalidationClearsOnlyAffectedMarkerReadiness to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testTargetedInvalidationClearsOnlyAffectedMarkerReadiness during codemap seam split +root/RepoPromptTests.CodemapGraphFreezeQueryTests/testUnloadCancelsBlockedGraphPublicationFlightWithoutLateWorker root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphFreezeQueryTests.swift RepoPromptTests.CodemapGraphFreezeQueryTests testUnloadCancelsBlockedGraphPublicationFlightWithoutLateWorker WorkspaceContext/CodeMap codemap.graph.unload_blocked_publication blocked_publication,root_unload,no_full_freeze,no_worker,no_graph cancellation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapGraphPublicationGate,CodemapSelectionGraphProbe Unloading while graph publication is blocked retains the targeted ready freeze but starts no full-root freeze, graph worker, or graph factory. A suspended publication flight could resume after unload and recreate revoked graph authority. filesystem,git_fixture,artifact_store,actor,concurrency store_session+graph_gate+root_unload retain 0 Census closure for blocked graph-flight cancellation.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testUnloadCancelsBlockedGraphPublicationFlightWithoutLateWorker to root/RepoPromptTests.CodemapGraphFreezeQueryTests/testUnloadCancelsBlockedGraphPublicationFlightWithoutLateWorker during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testExplicitMaterializationAndRepositoryAuthorityChangeRescheduleCurrentPreload root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testExplicitMaterializationAndRepositoryAuthorityChangeRescheduleCurrentPreload WorkspaceContext/CodeMap codemap.preload.mutation_reschedule failed_move,explicit_materialization,create_file,repository_authority_detach,reschedule_order filesystem_lifecycle_contract root_swiftpm routine 4 CodemapStoreFixture A failed move restores one preload, explicit materialization and file creation each reschedule it, and a repository-layout change detaches authority before the fifth schedule without starting runtime work. Filesystem and repository mutations could strand, duplicate, or reorder preload work against stale authority. filesystem,actor,concurrency store_session+preload_flight+root_unload retain 0 Four mutation and authority-reschedule scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testExplicitMaterializationAndRepositoryAuthorityChangeRescheduleCurrentPreload to root/RepoPromptTests.CodemapPreloadTests/testExplicitMaterializationAndRepositoryAuthorityChangeRescheduleCurrentPreload during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testFirstExplicitDemandReturnsStableExactRootPendingTicketAndRegistersOnce root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testFirstExplicitDemandReturnsStableExactRootPendingTicketAndRegistersOnce WorkspaceContext/CodeMap codemap.store_seam.exact_pending_registration explicit_demand,stable_ticket,root_epoch,route_registration,single_setup async_concurrency_lifecycle root_swiftpm routine 5 CodemapStoreFixture,CodeMapArtifactRuntimeProvider Duplicate explicit demand shares one exact-root pending ticket, provider access, engine construction, capability resolution, and registry route. Duplicate demand could start competing registration or bind to the wrong root lifetime. filesystem,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B inert modern codemap store seam; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testFirstExplicitDemandReturnsStableExactRootPendingTicketAndRegistersOnce to root/RepoPromptTests.CodemapPreloadTests/testFirstExplicitDemandReturnsStableExactRootPendingTicketAndRegistersOnce during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testFirstProjectionPageLazilyPublishesRecordsOnlyShardAfterRootReady root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testFirstProjectionPageLazilyPublishesRecordsOnlyShardAfterRootReady WorkspaceContext/CodeMap codemap.projection_catalog.lazy_records_shard root_ready,lazy_publication,records_only_shard,zero_path_index lazy_initialization_contract root_swiftpm routine 1 CodemapStoreFixture,CodemapResolutionGate No projection shard exists after root load; the first catalog page publishes one records-only exact-epoch shard without building a path index. Root load could eagerly construct the projection catalog or first-page access could build an unnecessary large path index. filesystem,artifact_store,actor,concurrency store_session+registration_gate+root_unload retain 0 Census closure for lazy first projection page.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testFirstProjectionPageLazilyPublishesRecordsOnlyShardAfterRootReady to root/RepoPromptTests.CodemapPreloadTests/testFirstProjectionPageLazilyPublishesRecordsOnlyShardAfterRootReady during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testLargeRootFirstProjectionShardBuildRunsOffActor root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testLargeRootFirstProjectionShardBuildRunsOffActor WorkspaceContext/CodeMap codemap.projection_catalog.off_actor_large_shard large_root,multi_page_files,blocked_catalog_build,actor_responsiveness,records_only_page concurrency_contract root_swiftpm routine 1 CodemapStoreFixture,CodemapResolutionGate,CodemapRootSuspensionGate While the first multi-page projection shard build is blocked, root inventory, scope availability, and content reads remain responsive; release returns the bounded records-only page. Building a large first shard on the store actor could stall ordinary workspace tools or allocate an unnecessary path index. filesystem,artifact_store,actor,concurrency store_session+catalog_build_gate+root_unload retain 0 Runtime optimization batch reduced synthetic file count while preserving off-actor large-root shard construction coverage.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testLargeRootFirstProjectionShardBuildRunsOffActor to root/RepoPromptTests.CodemapPreloadTests/testLargeRootFirstProjectionShardBuildRunsOffActor during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadAndDemandJoinEligibilityAndSetupSingleflights root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testProjectionPreloadAndDemandJoinEligibilityAndSetupSingleflights WorkspaceContext/CodeMap codemap.preload.demand_join_singleflight eligibility_flight,demand_join,setup_singleflight,runtime_singleton,engine_singleton concurrency_contract root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapSuspensionGate A foreground demand joins the blocked preload eligibility flight, then preload handoff and demand setup share one preflight, provider, runtime, engine, and setup task. Concurrent preload and demand could duplicate Git eligibility or process infrastructure and race registrations. filesystem,git_fixture,artifact_store,actor,concurrency store_session+eligibility_gate+demand_owner+root_unload retain 0 Eligibility join and setup-singleflight scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionPreloadAndDemandJoinEligibilityAndSetupSingleflights to root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadAndDemandJoinEligibilityAndSetupSingleflights during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadNonGitEligibilityPerformsZeroRuntimeWorkWithoutDemand root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testProjectionPreloadNonGitEligibilityPerformsZeroRuntimeWorkWithoutDemand WorkspaceContext/CodeMap codemap.preload.non_git_inertness non_git,terminal_eligibility,zero_runtime,zero_manifest,zero_graph dependency_isolation root_swiftpm routine 1 CodemapStoreFixture,CodemapSelectionGraphProbe One non-Git eligibility probe terminally classifies preload without provider, runtime, engine, manifest, build, or graph work. Automatic preload could start expensive codemap infrastructure for roots that cannot support Git-backed projection. filesystem,actor store_session+preload_flight+root_unload retain 0 Census closure for non-Git preload inertness.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionPreloadNonGitEligibilityPerformsZeroRuntimeWorkWithoutDemand to root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadNonGitEligibilityPerformsZeroRuntimeWorkWithoutDemand during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadStartIsAfterOrdinaryRootInventorySearchAndReadVisibility root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testProjectionPreloadStartIsAfterOrdinaryRootInventorySearchAndReadVisibility WorkspaceContext/CodeMap codemap.preload.ordinary_visibility_order root_inventory,search_catalog,content_read,scheduled,start_order lifecycle_ordering_contract root_swiftpm routine 2 CodemapStoreFixture,CodemapRootSuspensionGate With preload start blocked, inventory, search, and content read are already usable with zero provider work; release proves root-ready precedes scheduling and scheduling precedes start. Eager preload could delay ordinary root visibility or begin before catalog and search authority are published. filesystem,actor,concurrency store_session+preload_start_gate+root_unload retain 0 Ordinary visibility and exact event-order scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionPreloadStartIsAfterOrdinaryRootInventorySearchAndReadVisibility to root/RepoPromptTests.CodemapPreloadTests/testProjectionPreloadStartIsAfterOrdinaryRootInventorySearchAndReadVisibility during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testRepositoryLayoutChangeDetachesEngineSessionThenRegistersCurrentAuthority root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testRepositoryLayoutChangeDetachesEngineSessionThenRegistersCurrentAuthority WorkspaceContext/CodeMap codemap.preload.repository_authority_reregistration repository_layout,session_detach,stale_ticket,fresh_registration,single_runtime capability_lifecycle_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture A repository-layout publication detaches the old session, stales its ticket, and registers current authority through a second setup while reusing the process runtime and engine. Repository topology changes could leave old tickets live, skip re-registration, or duplicate process infrastructure. filesystem,git_fixture,artifact_store,actor,concurrency store_session+demand_owner+root_unload retain 0 Census closure for repository-authority session rollover.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testRepositoryLayoutChangeDetachesEngineSessionThenRegistersCurrentAuthority to root/RepoPromptTests.CodemapPreloadTests/testRepositoryLayoutChangeDetachesEngineSessionThenRegistersCurrentAuthority during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testRootLoadSearchAndReadDoNotInvokeCodemapRuntimeProvider root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testRootLoadSearchAndReadDoNotInvokeCodemapRuntimeProvider WorkspaceContext/CodeMap codemap.store_seam.lazy_inertness root_load,catalog_publication,search,read dependency_isolation root_swiftpm routine 4 CodemapStoreFixture,CodeMapArtifactRuntimeProvider,WorkspaceCodemapSelectionGraphFactory Root loading, catalog publication, indexed search, content read, and unload invoke neither the modern codemap runtime provider nor the injected graph factory. Ordinary workspace activity could eagerly construct process codemap infrastructure or start modern work. filesystem,actor test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B inert modern codemap store seam; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testRootLoadSearchAndReadDoNotInvokeCodemapRuntimeProvider to root/RepoPromptTests.CodemapPreloadTests/testRootLoadSearchAndReadDoNotInvokeCodemapRuntimeProvider during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testStaleLifetimeRepositoryDeltaDoesNotAcquireFenceOrDetachCurrentAuthority root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testStaleLifetimeRepositoryDeltaDoesNotAcquireFenceOrDetachCurrentAuthority WorkspaceContext/CodeMap codemap.preload.stale_lifetime_delta stale_lifetime,repository_delta,no_fence,no_detach,no_setup stale_generation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture A repository delta carrying a foreign lifetime leaves events and setup counts unchanged and performs no new preflight, provider, runtime, or engine access. A delayed watcher publication could fence or detach the current replacement root lifetime. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Census closure for stale-lifetime repository delta isolation.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStaleLifetimeRepositoryDeltaDoesNotAcquireFenceOrDetachCurrentAuthority to root/RepoPromptTests.CodemapPreloadTests/testStaleLifetimeRepositoryDeltaDoesNotAcquireFenceOrDetachCurrentAuthority during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testTransientEligibilityUsesOneAuthorityCheckedBackoffRetry root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testTransientEligibilityUsesOneAuthorityCheckedBackoffRetry WorkspaceContext/CodeMap codemap.preload.eligibility_backoff transient_eligibility,deterministic_clock,busy_demand,single_retry,terminal_non_git retry_policy_contract root_swiftpm routine 2 CodemapStoreFixture,CodemapRetryTestClock,CodemapRetrySleepGate The first transient eligibility result records the exact 100-nanosecond backoff and absolute 1,100-nanosecond deadline and keeps demand busy without re-probing; clock advance performs one retry that terminates non-Git with no provider access. Transient preflight could busy-loop, ignore the authority-checked deadline, or let foreground demand bypass the root backoff. filesystem,actor,concurrency store_session+retry_sleep+root_unload retain 0 Backoff enforcement and single terminal retry scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testTransientEligibilityUsesOneAuthorityCheckedBackoffRetry to root/RepoPromptTests.CodemapPreloadTests/testTransientEligibilityUsesOneAuthorityCheckedBackoffRetry during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testTransientSetupUsesOneBackoffThenFreshSetupRegistration root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testTransientSetupUsesOneBackoffThenFreshSetupRegistration WorkspaceContext/CodeMap codemap.preload.setup_backoff setup_failure,deterministic_clock,single_backoff,fresh_setup,handoff retry_policy_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture,CodemapRetryTestClock,CodemapRetrySleepGate An initial unconfigured runtime failure sleeps for the exact 250-nanosecond backoff, then creates one fresh setup registration that hands off successfully. A transient setup failure could reuse poisoned registration state, retry without backoff, or create extra setup tasks. filesystem,git_fixture,artifact_store,actor,concurrency store_session+retry_sleep+root_unload retain 0 Census closure for transient setup retry.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testTransientSetupUsesOneBackoffThenFreshSetupRegistration to root/RepoPromptTests.CodemapPreloadTests/testTransientSetupUsesOneBackoffThenFreshSetupRegistration during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testUnloadCancelsAndDrainsBlockedProjectionPreloadLaunch root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testUnloadCancelsAndDrainsBlockedProjectionPreloadLaunch WorkspaceContext/CodeMap codemap.preload.unload_blocked_launch blocked_start,unload,cancellation,flight_drain,zero_provider cancellation_contract root_swiftpm routine 1 CodemapStoreFixture,CodemapRootSuspensionGate Unloading a root whose preload start is blocked emits cancellation, removes launch phase and eligibility flight before release, and performs no provider access. Root unload could leave a blocked preload flight or allow late setup after authority is gone. filesystem,actor,concurrency store_session+preload_start_gate+root_unload retain 0 Census closure for blocked preload launch drain.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testUnloadCancelsAndDrainsBlockedProjectionPreloadLaunch to root/RepoPromptTests.CodemapPreloadTests/testUnloadCancelsAndDrainsBlockedProjectionPreloadLaunch during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testUnloadCancelsBlockedPreloadRetrySleepWithoutManualRelease root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testUnloadCancelsBlockedPreloadRetrySleepWithoutManualRelease WorkspaceContext/CodeMap codemap.preload.unload_retry_sleep blocked_backoff,root_unload,task_cancellation,no_manual_release cancellation_contract root_swiftpm routine 1 CodemapStoreFixture,CodemapRetryTestClock,CodemapRetrySleepGate Root unload cancels an in-flight 1000-nanosecond preload retry sleep and empties the root set without the test releasing the sleeper. A retry sleeper could retain root lifetime state and prevent unload from draining. filesystem,actor,concurrency store_session+retry_sleep+root_unload retain 0 Census closure for unload-owned retry cancellation.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testUnloadCancelsBlockedPreloadRetrySleepWithoutManualRelease to root/RepoPromptTests.CodemapPreloadTests/testUnloadCancelsBlockedPreloadRetrySleepWithoutManualRelease during codemap seam split +root/RepoPromptTests.CodemapPreloadTests/testWatcherPathInvalidationSupersedesAndReschedulesProjectionPreload root Tests/RepoPromptTests/WorkspaceContext/CodemapPreloadTests.swift RepoPromptTests.CodemapPreloadTests testWatcherPathInvalidationSupersedesAndReschedulesProjectionPreload WorkspaceContext/CodeMap codemap.preload.watcher_reschedule file_delta,full_resync_gap,supersede,reschedule,eligibility_cache filesystem_lifecycle_contract root_swiftpm routine 2 CodemapStoreFixture A file-modification watcher delta supersedes then reschedules preload while reusing terminal eligibility, and a full-resync gap schedules again with a fresh preflight; neither starts runtime work. Watcher churn could leave stale preload work active, skip required rescheduling, or unnecessarily repeat cached eligibility. filesystem,actor,concurrency store_session+preload_flight+root_unload retain 0 Path-delta and full-resync-gap scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testWatcherPathInvalidationSupersedesAndReschedulesProjectionPreload to root/RepoPromptTests.CodemapPreloadTests/testWatcherPathInvalidationSupersedesAndReschedulesProjectionPreload during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testFrozenPresentationBundleRetainsReadyHandleLeaseAcrossAwaitAndRendersLogicalPaths root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testFrozenPresentationBundleRetainsReadyHandleLeaseAcrossAwaitAndRendersLogicalPaths WorkspaceContext/CodeMap codemap.store.presentation.lease_render ready_handles,caller_lease,logical_display_path,deterministic_order,pipeline_identity,no_source_reread capability_lifecycle_contract root_swiftpm routine 4 CodemapStoreFixture,WorkspaceCodemapFrozenPresentationBundle A caller-held frozen bundle remains renderable across a controlled suspension, renders deterministically ordered logical paths without physical paths, preserves artifact pipeline identity, and performs no additional source read, build, or manifest load. Presentation could expose a worktree path, lose its lease across an await, reorder output, or re-enter legacy or source-building paths. filesystem,git_fixture,artifact_store,actor,concurrency store_session+caller_bundle+explicit_release+root_unload retain 0 Slice 3A handle-backed immutable presentation lease and logical rendering; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testFrozenPresentationBundleRetainsReadyHandleLeaseAcrossAwaitAndRendersLogicalPaths to root/RepoPromptTests.CodemapPresentationTests/testFrozenPresentationBundleRetainsReadyHandleLeaseAcrossAwaitAndRendersLogicalPaths during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationCancellationDuringPendingWaitReleasesOwnedDemandOnce root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testOperationPresentationCancellationDuringPendingWaitReleasesOwnedDemandOnce WorkspaceContext/CodeMap codemap.cutover.presentation.operationpresentationcancellationduringpendingwaitreleasesowneddemandonce operation_presentation,headless_consumer production_shaped_store_integration root_swiftpm routine 1 The B1+B2 headless consumer uses one frozen modern operation presentation. Legacy snapshot authority or duplicate rendering could re-enter prompt and export flows. test_case retain 0 B1+B2 ledger row restored from authoritative live list; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testOperationPresentationCancellationDuringPendingWaitReleasesOwnedDemandOnce to root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationCancellationDuringPendingWaitReleasesOwnedDemandOnce during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationCoordinatesMultiRootLogicalOutputAndReleasesAllRetains root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testOperationPresentationCoordinatesMultiRootLogicalOutputAndReleasesAllRetains WorkspaceContext/CodeMap codemap.cutover.presentation.operationpresentationcoordinatesmultirootlogicaloutputandreleasesallretains operation_presentation,headless_consumer production_shaped_store_integration root_swiftpm routine 1 The B1+B2 headless consumer uses one frozen modern operation presentation. Legacy snapshot authority or duplicate rendering could re-enter prompt and export flows. test_case retain 0 B1+B2 ledger row restored from authoritative live list; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testOperationPresentationCoordinatesMultiRootLogicalOutputAndReleasesAllRetains to root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationCoordinatesMultiRootLogicalOutputAndReleasesAllRetains during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationMixedReadyAndPendingPublishesReadyReceipt root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testOperationPresentationMixedReadyAndPendingPublishesReadyReceipt WorkspaceContext headless_p1.receipt.ready_subset mixed_ready_pending,publication_receipt deterministic_regression root_swiftpm routine 1 CodemapStoreFixture A mixed ready/pending operation publishes the ready entry and receipt contains only its candidate, ticket, and bundle entry. Pending sibling work could poison valid partial publication. temp_git_repository;codemap_runtime test_case+addTeardownBlock retain 0 Headless P1 grouped repair receipt contract; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testOperationPresentationMixedReadyAndPendingPublishesReadyReceipt to root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationMixedReadyAndPendingPublishesReadyReceipt during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationPendingIsTypedAndReleasedWithoutFallback root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testOperationPresentationPendingIsTypedAndReleasedWithoutFallback WorkspaceContext/CodeMap codemap.cutover.presentation.operationpresentationpendingistypedandreleasedwithoutfallback operation_presentation,headless_consumer production_shaped_store_integration root_swiftpm routine 1 The B1+B2 headless consumer uses one frozen modern operation presentation. Legacy snapshot authority or duplicate rendering could re-enter prompt and export flows. test_case retain 0 B1+B2 ledger row restored from authoritative live list; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testOperationPresentationPendingIsTypedAndReleasedWithoutFallback to root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationPendingIsTypedAndReleasedWithoutFallback during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationRevocationBeforePublicationRetriesAndReturnsIncomplete root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testOperationPresentationRevocationBeforePublicationRetriesAndReturnsIncomplete WorkspaceContext/CodeMap codemap.cutover.presentation.operationpresentationrevocationbeforepublicationretriesandreturnsincomplete operation_presentation,headless_consumer production_shaped_store_integration root_swiftpm routine 1 The B1+B2 headless consumer uses one frozen modern operation presentation. Legacy snapshot authority or duplicate rendering could re-enter prompt and export flows. test_case retain 0 B1+B2 ledger row restored from authoritative live list; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testOperationPresentationRevocationBeforePublicationRetriesAndReturnsIncomplete to root/RepoPromptTests.CodemapPresentationTests/testOperationPresentationRevocationBeforePublicationRetriesAndReturnsIncomplete during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testProjectionCatalogPagesAndCallbacksRequireExactCurrentShard root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testProjectionCatalogPagesAndCallbacksRequireExactCurrentShard WorkspaceContext/CodeMap codemap.projection_catalog.exact_current_shard pagination,path_bytes,cursor,token,pipeline,path_generation,stale,superseded capability_lifecycle_contract root_swiftpm routine 8 CodemapStoreFixture,CodemapResolutionGate Three bounded pages enumerate only supported paths with exact identity and counts; current callbacks accept the matching token and pipeline, invalid cursor and pipeline are stale, edit invalidates old callbacks and advances the path generation, and unload supersedes publication and makes the token unavailable. Catalog callbacks could accept malformed pagination or publish projection results against the wrong pipeline, path generation, root epoch, or unloaded shard. filesystem,artifact_store,actor,concurrency store_session+catalog_client+registration_gate+root_unload retain 0 Eight pagination, callback-currentness, edit, and unload scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testProjectionCatalogPagesAndCallbacksRequireExactCurrentShard to root/RepoPromptTests.CodemapPresentationTests/testProjectionCatalogPagesAndCallbacksRequireExactCurrentShard during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testScopedOperationCancellationAfterRenderReleasesDemandAndPresentationOnce root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testScopedOperationCancellationAfterRenderReleasesDemandAndPresentationOnce WorkspaceContext/CodeMap codemap.cutover.presentation.scoped-cancellation-cleanup operation_scope,post_render_cancellation,demand_release,presentation_release,exactly_once async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,CodemapSuspensionGate Cancellation while a consumer constructs its final payload releases the rendered presentation and owned demand exactly once and returns CancellationError. A final-publication scope could leak leases or double-cancel retained demand when the Agent export task is cancelled after rendering. filesystem,git_fixture,artifact_store,actor,concurrency store_session+scoped_operation+fixture_cleanup retain 0 C2 scoped final-publication ownership regression.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testScopedOperationCancellationAfterRenderReleasesDemandAndPresentationOnce to root/RepoPromptTests.CodemapPresentationTests/testScopedOperationCancellationAfterRenderReleasesDemandAndPresentationOnce during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStaleEngineCompletionMapsToStaleCurrentness root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStaleEngineCompletionMapsToStaleCurrentness WorkspaceContext/CodeMap codemap.demand.stale_completion_retry engine_rejection,stale_currentness,retry,ready stale_generation_contract root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture A rejected stale engine completion maps to a stale demand result, while a fresh retry completes ready on the second result. An engine currentness rejection could leak as a generic failure or poison later demand retries. filesystem,git_fixture,artifact_store,actor,concurrency store_session+demand_owner retain 0 Stale completion and fresh retry scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStaleEngineCompletionMapsToStaleCurrentness to root/RepoPromptTests.CodemapPresentationTests/testStaleEngineCompletionMapsToStaleCurrentness during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStructurePresentationSeedUsesPairedCodemapRenderAndReleasesReceiptResources root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStructurePresentationSeedUsesPairedCodemapRenderAndReleasesReceiptResources WorkspaceContext workspace.codemap.structure_presentation_receipt demand_retain,frozen_bundle,logical_path,cleanup production_shaped_store_integration root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture Seed presentation uses paired immutable text/tokens and returns demand and bundle retains to zero. MCP publication could leak leases or mix token and text authorities. test_case retain 0 Grouped headless codemap cutover; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStructurePresentationSeedUsesPairedCodemapRenderAndReleasesReceiptResources to root/RepoPromptTests.CodemapPresentationTests/testStructurePresentationSeedUsesPairedCodemapRenderAndReleasesReceiptResources during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStructurePublicationRevocationRetriesThenReturnsTypedStale root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStructurePublicationRevocationRetriesThenReturnsTypedStale WorkspaceContext workspace.codemap.structure_publication_stale combined_fence,revocation,retry,stale async_lifecycle root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture Root revocation at the combined fence retries once and returns typed stale with no content. A stale graph or presentation could publish after root revocation. test_case retain 0 Grouped headless codemap cutover; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStructurePublicationRevocationRetriesThenReturnsTypedStale to root/RepoPromptTests.CodemapPresentationTests/testStructurePublicationRevocationRetriesThenReturnsTypedStale during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStructureSeedAdmissionIgnoresStaleAndOutOfScopeSeedsWithoutLosingIssues root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStructureSeedAdmissionIgnoresStaleAndOutOfScopeSeedsWithoutLosingIssues WorkspaceContext/CodeMap codemap.structure.seed_admission_filtering stale_seed,out_of_scope_seed,allowed_seed,issue_preservation,zero_demand bounded_input_contract root_swiftpm routine 3 CodemapStoreFixture,ReviewGitRepositoryFixture,WorkspaceCodemapPresentationCoordinator Stale and out-of-scope seeds are excluded before the one-seed limit while retaining their exact issues; the allowed seed proceeds to the token-limit issue with zero artifact work. Counting invalid seeds could trigger a false seed budget or discard diagnostic issues and start forbidden demand work. filesystem,git_fixture,artifact_store,actor store_session+coordinator_operation+root_unload retain 0 Stale, out-of-scope, and admitted-seed scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStructureSeedAdmissionIgnoresStaleAndOutOfScopeSeedsWithoutLosingIssues to root/RepoPromptTests.CodemapPresentationTests/testStructureSeedAdmissionIgnoresStaleAndOutOfScopeSeedsWithoutLosingIssues during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStructureSeedDemandLimitRejectsBeforeRuntimeOrBuild root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStructureSeedDemandLimitRejectsBeforeRuntimeOrBuild WorkspaceContext headless_p1.seed_pre_demand_budget seed_limit,zero_runtime,zero_build budget_negative root_swiftpm routine 1 CodemapStoreFixture N+1 resolved seeds return typed budget before provider, runtime, engine, manifest, or build counters advance. Unbounded seed expansion could start excessive artifact work before trimming. temp_git_repository;codemap_runtime test_case+addTeardownBlock retain 0 Headless P1 grouped repair demand contract; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStructureSeedDemandLimitRejectsBeforeRuntimeOrBuild to root/RepoPromptTests.CodemapPresentationTests/testStructureSeedDemandLimitRejectsBeforeRuntimeOrBuild during codemap seam split +root/RepoPromptTests.CodemapPresentationTests/testStructureWarmPublishedArtifactBypassesDemandFreezeGraphAndGitIdentity root Tests/RepoPromptTests/WorkspaceContext/CodemapPresentationTests.swift RepoPromptTests.CodemapPresentationTests testStructureWarmPublishedArtifactBypassesDemandFreezeGraphAndGitIdentity WorkspaceContext/CodeMap codemap.structure.durable_warm_serving published_projection,cas,no_demand,no_freeze,no_graph,no_git,logical_path durable_publication_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture After cold publication and presentation release, the identical no-traversal structure request renders the durable projection without seed admission, demand, freeze, graph signaling, manifest load, build, or Git classification. Warm structure serving could re-enter transient presentation ownership or expensive Git and catalog work. git_subprocess,filesystem,artifact_store,actor,concurrency store_session+fixture_cleanup+root_unload retain 0 Codemap hydration remediation Slice 1 production warm-path proof; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testStructureWarmPublishedArtifactBypassesDemandFreezeGraphAndGitIdentity to root/RepoPromptTests.CodemapPresentationTests/testStructureWarmPublishedArtifactBypassesDemandFreezeGraphAndGitIdentity during codemap seam split +root/RepoPromptTests.CodemapStoreMutationTests/testCheckoutFencesOldAuthorityAndCreatePreservesUnrelatedSuccessorDemand root Tests/RepoPromptTests/WorkspaceContext/CodemapStoreMutationTests.swift RepoPromptTests.CodemapStoreMutationTests testCheckoutFencesOldAuthorityAndCreatePreservesUnrelatedSuccessorDemand WorkspaceContext/CodeMap codemap.store.fence.checkout_path_local_create checkout,path_local_create,successor_generation,unrelated_survival,presentation,graph async_concurrency_lifecycle root_swiftpm routine 5 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,WorkspaceCodemapFrozenPresentationBundle,WorkspaceCodemapBindingEngineAccounting Checkout drains old authority while a later path-local create preserves unrelated ready successor demand and starts no eager full-root rescan. Checkout could retain stale authority or create could unnecessarily revoke unrelated codemap demand. 1.293000 filesystem,git_fixture,artifact_store,actor,concurrency store_session+cleanup_flight+path_fence+root_unload retain 0 Renamed from testCheckoutAndCatalogAdvanceFenceOldAuthorityBeforeSuccessorDemand; updated for path-local create semantics. +root/RepoPromptTests.CodemapStoreMutationTests/testStoreEditRenameAndDeleteRevokeAuthorityBeforeReturningAndRecoverAfterRetainedInvalidation root Tests/RepoPromptTests/WorkspaceContext/CodemapStoreMutationTests.swift RepoPromptTests.CodemapStoreMutationTests testStoreEditRenameAndDeleteRevokeAuthorityBeforeReturningAndRecoverAfterRetainedInvalidation WorkspaceContext/CodeMap codemap.store.fence.crud_retained_convergence edit,rename,delete,immediate_revocation,path_generation,retained_recovery async_concurrency_lifecycle root_swiftpm routine 6 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,WorkspaceCodemapFrozenPresentationBundle,WorkspaceCodemapBindingEngineAccounting Edit, rename, and delete immediately revoke affected authority, preserve unrelated handles, and later recover after retained derived invalidation converges. Mutations could block disk I/O on derived work, return with stale authority, or fail to recover successor demand. 0.931000 filesystem,git_fixture,artifact_store,actor,concurrency store_session+path_fence+retained_invalidation+root_unload retain 0 Renamed from testStoreEditRenameAndDeleteAwaitCodemapAuthorityFenceBeforeReturning; locks immediate revocation plus retained convergence. +root/RepoPromptTests.CodemapStoreMutationTests/testUnloadAwaitsPresentationGraphAndEngineRevocationBeforeReturning root Tests/RepoPromptTests/WorkspaceContext/CodemapStoreMutationTests.swift RepoPromptTests.CodemapStoreMutationTests testUnloadAwaitsPresentationGraphAndEngineRevocationBeforeReturning WorkspaceContext/CodeMap codemap.store.fence.unload unload,presentation,graph,route,engine,return_boundary async_concurrency_lifecycle root_swiftpm routine 4 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,WorkspaceCodemapFrozenPresentationBundle,WorkspaceCodemapBindingEngineAccounting Root unload revokes caller-retained presentation handles, graph query authority, exact route, and engine root state before returning. Queued graph or demand work could publish after unload or a stale route/handle could survive root lifetime termination. filesystem,git_fixture,artifact_store,actor,concurrency store_session+cleanup_flight+root_unload retain 0 Slice 3C atomic unload revocation boundary; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testUnloadAwaitsPresentationGraphAndEngineRevocationBeforeReturning to root/RepoPromptTests.CodemapStoreMutationTests/testUnloadAwaitsPresentationGraphAndEngineRevocationBeforeReturning during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testCancellationAfterReadyRevokesRetainedHandleIdempotently root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testCancellationAfterReadyRevokesRetainedHandleIdempotently WorkspaceContext/CodeMap codemap.store_seam.ready_cancellation ready,cancellation,retained_bundle,handle_revocation,idempotency capability_lifecycle_contract root_swiftpm routine 2 CodemapStoreFixture,CodeMapArtifactRuntimeProvider Cancelling a ready demand changes its status to cancelled and closes its retained bundle so the returned handle is revoked; repeating cancellation preserves revocation without path-wide invalidation while the engine-owned ready lease remains live. A cancelled ready record could retain store-owned handle authority, double-close its bundle, or incorrectly revoke engine-owned path state. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B ready-demand cancellation repair; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testCancellationAfterReadyRevokesRetainedHandleIdempotently to root/RepoPromptTests.CodemapWatcherFenceTests/testCancellationAfterReadyRevokesRetainedHandleIdempotently during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testCatalogAdvanceFencesPendingTicketAndExactRegistryRoute root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testCatalogAdvanceFencesPendingTicketAndExactRegistryRoute WorkspaceContext/CodeMap codemap.store_seam.catalog_currentness catalog_generation,pending_ticket,exact_route,cleanup stale_generation_contract root_swiftpm routine 4 CodemapStoreFixture,CodeMapArtifactRuntimeProvider Catalog publication immediately makes the prior ticket stale, detaches its exact registry route, and drains the old engine authority. A completion or route from an older catalog could publish into the current root authority. filesystem,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B inert modern codemap store seam; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testCatalogAdvanceFencesPendingTicketAndExactRegistryRoute to root/RepoPromptTests.CodemapWatcherFenceTests/testCatalogAdvanceFencesPendingTicketAndExactRegistryRoute during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testFinalReadyRetainReleaseRemovesDemandBundleOwnerAndLiveOverlay root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testFinalReadyRetainReleaseRemovesDemandBundleOwnerAndLiveOverlay WorkspaceContext/CodeMap codemap.demand.final_ready_release ready_retain,record_removal,bundle_close,owner_cleanup,overlay_cleanup,idempotent_release async_resource_lifecycle root_swiftpm routine 2 CodemapStoreFixture,ReviewGitRepositoryFixture The final ready-retain release removes the demand record, closes its bundle, drops the last owner and live overlay, and a repeated release returns false. Final release could leak overlay authority or let a closed handle remain usable, while repeated cleanup could mutate successor state. filesystem,git_fixture,artifact_store,actor,concurrency store_session+demand_owner+root_unload retain 0 Initial cleanup plus idempotent repeated-release scenarios.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testFinalReadyRetainReleaseRemovesDemandBundleOwnerAndLiveOverlay to root/RepoPromptTests.CodemapWatcherFenceTests/testFinalReadyRetainReleaseRemovesDemandBundleOwnerAndLiveOverlay during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testManifestCandidateAfterPathInvalidationUsesSuccessorPathGeneration root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testManifestCandidateAfterPathInvalidationUsesSuccessorPathGeneration WorkspaceContext/CodeMap codemap.manifest_candidate.successor_path_generation path_invalidation,successor_ticket,path_generation,registry_manifest_binding stale_generation_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture After path invalidation, the successor ticket advances path and request generation and registry manifest binding resolves using the successor generation. Manifest candidate binding could reuse an obsolete path generation after invalidation and publish stale codemap authority. filesystem,git_fixture,artifact_store,actor,concurrency store_session+root_unload retain 0 Reviewed ledger reconciliation for PR314 live missing XCTest ID.; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testManifestCandidateAfterPathInvalidationUsesSuccessorPathGeneration to root/RepoPromptTests.CodemapWatcherFenceTests/testManifestCandidateAfterPathInvalidationUsesSuccessorPathGeneration during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testPathRepairPublishesReadyContributionCompletedDuringRebuild root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testPathRepairPublishesReadyContributionCompletedDuringRebuild WorkspaceContext/CodeMap codemap.store.graph.path_repair_contribution_race path_repair,ready_contribution,rebuild_gate,resnapshot,latest_wins,stale_snapshot async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,CodemapSelectionGraphBuildGate A ready contribution accepted after the path-repair snapshot but during its blocked rebuild is included by the repair resnapshot loop and remains covered by the current graph. A stale repair snapshot could overwrite or permanently omit an unrelated ready contribution completed while rebuild publication was suspended. filesystem,git_fixture,artifact_store,actor,concurrency store_session+path_fence+graph_worker+root_unload retain 0 Slice 3C P1 path-repair contribution publication race repair; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testPathRepairPublishesReadyContributionCompletedDuringRebuild to root/RepoPromptTests.CodemapWatcherFenceTests/testPathRepairPublishesReadyContributionCompletedDuringRebuild during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testReadyCancellationCleanupCannotCancelSamePathSuccessor root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testReadyCancellationCleanupCannotCancelSamePathSuccessor WorkspaceContext/CodeMap codemap.store_seam.cancellation_successor_isolation ready_cancellation,state_transition,exact_owner,same_path_successor,cleanup_ordering,graph_actor_identity,root_epoch async_concurrency_lifecycle root_swiftpm routine 3 CodemapStoreFixture,WorkspaceFileContextStore,WorkspaceCodemapSelectionGraphFactory With old cancellation cleanup and successor ready publication independently gated, the cancelled record is revoked before suspension, the successor republishes through the identical single graph actor in the same root epoch, and unload/reload creates a second actor for the new epoch. Path-wide cleanup could capture the successor, or cancellation could recreate graph authority within one epoch and violate exact-one actor identity. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B cancellation closure regression; Slice 3B exact-one graph actor identity repair; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testReadyCancellationCleanupCannotCancelSamePathSuccessor to root/RepoPromptTests.CodemapWatcherFenceTests/testReadyCancellationCleanupCannotCancelSamePathSuccessor during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testReadyDemandsReuseInjectedRuntimeRegistryAndEngineSingletons root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testReadyDemandsReuseInjectedRuntimeRegistryAndEngineSingletons WorkspaceContext/CodeMap codemap.store_seam.ready_identity_lease ready_identity,frozen_handle,two_files,runtime_singleton,registry_singleton,engine_singleton,revocation capability_lifecycle_contract root_swiftpm routine 5 CodemapStoreFixture,CodeMapArtifactRuntimeProvider Two Git-backed ready demands carry exact binding identities and revocable handles while reusing one injected runtime, registry, engine, and exact-root route. Ready publication could lose binding identity, duplicate process infrastructure, or outlive root authority. filesystem,git_fixture,artifact_store,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B combines the planned ready lease gate with explicit singleton reuse; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testReadyDemandsReuseInjectedRuntimeRegistryAndEngineSingletons to root/RepoPromptTests.CodemapWatcherFenceTests/testReadyDemandsReuseInjectedRuntimeRegistryAndEngineSingletons during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testUnloadAndReloadFenceOldLifetimeAndDrainCodemapRootState root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testUnloadAndReloadFenceOldLifetimeAndDrainCodemapRootState WorkspaceContext/CodeMap codemap.store_seam.root_lifetime_cleanup unload,reload,root_epoch,stale_ticket,drain async_concurrency_lifecycle root_swiftpm routine 5 CodemapStoreFixture,CodeMapArtifactRuntimeProvider Unload detaches the route, revokes and drains engine authority before return, and same-path reload receives a distinct epoch that cannot reuse the old ticket. Old lifetime tasks or tokens could cross an unload/reload ABA boundary and affect the successor root. filesystem,actor,concurrency test_case+fixture_cleanup+explicit_root_unload retain 0 Slice B inert modern codemap store seam; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testUnloadAndReloadFenceOldLifetimeAndDrainCodemapRootState to root/RepoPromptTests.CodemapWatcherFenceTests/testUnloadAndReloadFenceOldLifetimeAndDrainCodemapRootState during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testWatcherModifyDeleteAndGapAwaitPresentationGraphAndEngineFences root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testWatcherModifyDeleteAndGapAwaitPresentationGraphAndEngineFences WorkspaceContext/CodeMap codemap.store.fence.watcher modify,delete,watcher_gap,path_local_survival,presentation_revocation,graph_fence async_concurrency_lifecycle root_swiftpm routine 6 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,WorkspaceCodemapFrozenPresentationBundle,WorkspaceCodemapBindingEngineAccounting Watcher modify/delete preserve unrelated demand/presentation/graph authority while revoking affected handles; a watcher gap drains graph, route, and engine authority before return. Late watcher cleanup could publish stale handles or graph shards, or path-local invalidation could unnecessarily revoke unrelated demand authority. filesystem,git_fixture,artifact_store,actor,concurrency store_session+path_fence+graph_worker+root_unload retain 0 Slice 3C watcher lifecycle fencing and unrelated-path survival; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testWatcherModifyDeleteAndGapAwaitPresentationGraphAndEngineFences to root/RepoPromptTests.CodemapWatcherFenceTests/testWatcherModifyDeleteAndGapAwaitPresentationGraphAndEngineFences during codemap seam split +root/RepoPromptTests.CodemapWatcherFenceTests/testWatcherRenamePairFencesOnlyOldAndNewPaths root Tests/RepoPromptTests/WorkspaceContext/CodemapWatcherFenceTests.swift RepoPromptTests.CodemapWatcherFenceTests testWatcherRenamePairFencesOnlyOldAndNewPaths WorkspaceContext/CodeMap codemap.store.fence.watcher_rename_pair watcher,rename_pair,removed_added,path_local,presentation,graph,path_generation async_concurrency_lifecycle root_swiftpm routine 5 CodemapStoreFixture,WorkspaceCodemapSelectionGraphFactory,WorkspaceCodemapFrozenPresentationBundle A watcher removed-plus-added rename revokes the old path, advances the new path generation, and preserves unrelated ready handle, presentation, and graph authority. Treating the added half as catalog replacement could revoke the entire root, while missing either path fence could retain stale rename authority. filesystem,git_fixture,artifact_store,actor,concurrency store_session+path_fence+graph_worker+root_unload retain 0 Slice 3C P1 watcher rename-pair path-local fencing repair; moved from root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testWatcherRenamePairFencesOnlyOldAndNewPaths to root/RepoPromptTests.CodemapWatcherFenceTests/testWatcherRenamePairFencesOnlyOldAndNewPaths during codemap seam split root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testAcceptedSteerRemainsSentWhenMatchingTurnCompletesBeforeReceiptResumes root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testAcceptedSteerRemainsSentWhenMatchingTurnCompletesBeforeReceiptResumes AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.064500 unreviewed retain_pending_review 0 initial census source line 588 -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveCodexNativeSendRejectsBeforeDispatchWhenAgentRunDrainFails root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveCodexNativeSendRejectsBeforeDispatchWhenAgentRunDrainFails AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 Corrected stale census ID to the implemented pre-dispatch rejection method. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveCodexNativeSendRejectsBeforeDispatchWhenActiveRunChangesDuringDrain root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveCodexNativeSendRejectsBeforeDispatchWhenActiveRunChangesDuringDrain AgentMode codex.manual_send.active_run_identity_revalidation active_run,run_id,drain,pre_dispatch_rejection,no_retry async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A manual active send whose captured run identity changes while the real drain is suspended rejects before provider dispatch without starting steering or queuing fallback work. A drained send could dispatch into a successor run or silently retry against the wrong provider turn. test_case+continuation_gate retain 0 Deterministic captured-run identity regression for the post-drain pre-dispatch boundary. +root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveCodexNativeSendFailsWithoutSendingWhenAgentRunDrainFails root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveCodexNativeSendFailsWithoutSendingWhenAgentRunDrainFails AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 470 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveCodexNativeSendUsesRealAgentRunDrainBeforeSending root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveCodexNativeSendUsesRealAgentRunDrainBeforeSending AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.034000 unreviewed retain_pending_review 0 initial census source line 412 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveCodexNativeSendWithoutExactIdentityQueuesWithoutStarting root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveCodexNativeSendWithoutExactIdentityQueuesWithoutStarting AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.007500 unreviewed retain_pending_review 0 initial census source line 511 -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testSilentCommandWithoutRunIDSurvivesRecoveryWindowAndLaterCompletes root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testSilentCommandWithoutRunIDSurvivesRecoveryWindowAndLaterCompletes AgentMode codex.app_server.watchdog_authoritative_tool_liveness missing_run_id,run_attempt,thread_snapshot,command_execution,silent_tool,terminal_barrier,opaque_process_handle,id_domain_bridge async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController A nil-runID start-only silent command remains active across repeated watchdog recovery windows when a unique opaque execution handle maps its raw call ID to a differing in-progress snapshot item ID, then a later terminal event completes once and clears tool state. Legitimate long-running silent commands could be failed after 300 seconds, or an opaque execution handle could be mistaken for a local PID. test_case+watchdog_cleanup retain 0 Renamed root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveRunWithoutRunIDSettlesInsteadOfRearmingWatchdog -> root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testSilentCommandWithoutRunIDSurvivesRecoveryWindowAndLaterCompletes; replaces missing-runID immediate failure with authoritative snapshot reconciliation. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testSilentCompositeWaitCorrelatesToAuthoritativeCommandAndLaterCompletes root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testSilentCompositeWaitCorrelatesToAuthoritativeCommandAndLaterCompletes AgentMode codex.app_server.watchdog_composite_command_liveness composite_wait,command_execution,invocation_id,item_id,authoritative_snapshot,no_shutdown async_concurrency_lifecycle root_swiftpm integration 1 CodexNativeSessionController.test_parseToolLifecycleEvent,CodexNativeSessionController.test_parseThreadSnapshot,LivenessFakeCodexController A silent wait call whose invocation ID exactly round-trips from the authoritative in-progress commandExecution item remains running across repeated recovery windows without controller shutdown, then completes normally. Rejecting the wait name as incompatible with commandExecution could force reattachment and ultimately fail a live composite command despite exact provider identity evidence. test_case+watchdog_cleanup retain 0 Focused incident regression for composite functions.wait liveness. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTerminalCommandSnapshotWithoutRunIDClearsStaleSpanAndFailsBoundedly root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTerminalCommandSnapshotWithoutRunIDClearsStaleSpanAndFailsBoundedly AgentMode codex.app_server.watchdog_terminal_tool_cleanup missing_run_id,run_attempt,thread_snapshot,terminal_command,stale_span,bounded_failure,opaque_process_handle,id_domain_bridge async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController A fresh full snapshot uses a unique opaque execution handle to map a differing terminal item ID to the stale local command span, removes it, and lets the unchanged nil-runID active state reach one bounded failure without controller invalidation. A stale open span could exempt a lost terminal event forever or nil runID could bypass snapshot probing. test_case+watchdog_cleanup retain 0 Authoritative terminal-item cleanup and bounded nil-runID failure coverage. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTerminalTurnFinalizesPersistedRunningCompositeExecResult root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTerminalTurnFinalizesPersistedRunningCompositeExecResult AgentMode codex.app_server.terminal_composite_command_cleanup terminal_drain,persisted_result,command_execution,exec,running_spinner lifecycle_regression root_swiftpm integration 1 LivenessFakeCodexController A terminal Codex turn rewrites a persisted exec tool result explicitly typed as a running commandExecution to completed while preserving its tool name and invocation identity. A composite command result outside bash live-state tracking could retain a running payload and leave its transcript card spinning after the provider turn ended. test_case retain 0 Focused persisted composite command terminal-sweep regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testThreadSnapshotParsesAuthoritativeActiveCommandItem root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testThreadSnapshotParsesAuthoritativeActiveCommandItem AgentMode codex.app_server.thread_snapshot_tool_items thread_read,items_view,command_execution,item_status,opaque_process_handle protocol_contract root_swiftpm integration 1 CodexNativeSessionController.test_parseThreadSnapshot A schema-shaped thread/read response with a full active turn parses the command item identity and in-progress lifecycle without interpreting processId as a POSIX PID. Schema drift or parser omissions could remove the authoritative evidence required for safe long-command liveness. test_case retain 0 Focused parser contract for watchdog-authoritative active command item state. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testThreadSnapshotPreservesToolIdentityAcrossMultipleActiveTurns root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testThreadSnapshotPreservesToolIdentityAcrossMultipleActiveTurns AgentMode codex.app_server.thread_snapshot_turn_scoping thread_read,multiple_active_turns,item_identity,opaque_process_handle protocol_contract root_swiftpm integration 1 CodexNativeSessionController.test_parseThreadSnapshot A full thread snapshot preserves each command item’s provider turn and opaque execution handle across multiple active turns. Ordering-dependent or cross-turn matching could let stale work affect the authoritative current turn. test_case retain 0 Explicit multi-active-turn identity parsing coverage. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testThreadSnapshotWithIncompleteActiveTurnItemsFailsClosed root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testThreadSnapshotWithIncompleteActiveTurnItemsFailsClosed AgentMode codex.app_server.thread_snapshot_item_authority thread_read,multiple_active_turns,items_view,summary,fail_closed protocol_negative root_swiftpm integration 1 CodexNativeSessionController.test_parseThreadSnapshot If any active turn exposes only summary items the snapshot is not authoritative for tool reconciliation. Incomplete item projections could make a reused identifier appear unique and affect unrelated work. test_case retain 0 Fail-closed full-items authority regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testUnrelatedInProgressCommandDoesNotCorroborateLocalSpan root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testUnrelatedInProgressCommandDoesNotCorroborateLocalSpan AgentMode codex.app_server.watchdog_tool_identity in_progress,unrelated_item,fail_closed,turn_scope async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController An unrelated same-kind in-progress snapshot command does not advance watchdog progress for a local command span with different item and process identities. Broad-kind fallback could exempt a stale local span forever. test_case retain 0 Regression for review finding 1. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testNamelessMCPItemDoesNotCorroborateNamedLocalSpan root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testNamelessMCPItemDoesNotCorroborateNamedLocalSpan AgentMode codex.app_server.watchdog_tool_name_identity mcp_tool_call,missing_tool_name,matching_invocation_id,fail_closed async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController An authoritative in-progress MCP snapshot item with the same invocation ID but no tool name does not advance watchdog progress for a named local tool span, which remains in flight. Treating a missing provider tool name as a wildcard could falsely corroborate incomplete snapshot evidence and exempt a stalled named tool span. test_case retain 0 Explicit tool-name identity regression inherited from origin/main commit 4276f513. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testUnrelatedTerminalCommandDoesNotFinalizeOrClearLocalSpan root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testUnrelatedTerminalCommandDoesNotFinalizeOrClearLocalSpan AgentMode codex.app_server.watchdog_terminal_tool_identity terminal_item,unrelated_item,fail_closed,bash_state async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController An unrelated same-kind terminal snapshot command leaves the local span and running bash state untouched. Singleton same-kind cleanup could falsely finalize unrelated live work. test_case retain 0 Regression for review finding 2. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTerminalSnapshotAmongMultipleCommandsOnlyClearsExactIdentity root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTerminalSnapshotAmongMultipleCommandsOnlyClearsExactIdentity AgentMode codex.app_server.watchdog_terminal_tool_identity multiple_commands,exact_item_id,selective_cleanup async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController Among multiple local and snapshot commands only the exact item identity finalizes and clears its corresponding span. Same-kind multiplicity could clear the wrong row or all spans. test_case retain 0 One-to-one terminal reconciliation coverage. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testSnapshotItemFromAnotherActiveTurnCannotAffectCurrentTurnSpan root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testSnapshotItemFromAnotherActiveTurnCannotAffectCurrentTurnSpan AgentMode codex.app_server.watchdog_tool_turn_scope multiple_active_turns,authoritative_turn,cross_turn,fail_closed async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController Even matching item and process identities from another active turn cannot finalize or clear the authoritative current-turn span. Cross-turn snapshot evidence could corrupt a successor or concurrent turn. test_case retain 0 Authoritative current-turn scoping regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testDuplicateSnapshotProcessHandlesFailClosed root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testDuplicateSnapshotProcessHandlesFailClosed AgentMode codex.app_server.watchdog_process_identity multiple_commands,duplicate_handle,ambiguity,fail_closed async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController A duplicated opaque process handle across snapshot commands is ambiguous and cannot corroborate the local span. A non-unique secondary identifier could recreate same-kind ambiguity under another name. test_case retain 0 Unique opaque-handle mapping regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testDuplicateLocalProcessHandlesFailClosed root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testDuplicateLocalProcessHandlesFailClosed AgentMode codex.app_server.watchdog_process_identity multiple_local_spans,duplicate_handle,ambiguity,fail_closed async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController A single snapshot command cannot corroborate either of two current-turn local spans that share its opaque handle. Non-unique local handle correlation could exempt or clear the wrong span. test_case retain 0 Mirror-side unique opaque-handle regression. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveThreadSnapshotCountsAsWatchdogLivenessAndReconcilesWaitingFlags root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveThreadSnapshotCountsAsWatchdogLivenessAndReconcilesWaitingFlags AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.038500 unreviewed retain_pending_review 0 initial census source line 7 -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testBackToBackComposerActiveSendDrainRejectionsRestoreEachDraftExactlyOnce root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testBackToBackComposerActiveSendDrainRejectionsRestoreEachDraftExactlyOnce AgentMode codex.manual_send.rejection_chain_rollback dispatch_serialization,draft_exact_once,runtime_anchor,runtime_footer,elapsed_timer async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate Two identical optimistic manual submissions rejected in issued order restore two draft copies, remove only their bubbles, and recover the original anchor, footer map, and run-start timestamp. Back-to-back pre-dispatch rejection could reorder cleanup, collapse identical drafts, leak optimistic anchors, or leave elapsed time anchored to a rejected turn. test_case+continuation_gate retain 0 Deterministic chained-rejection coverage for caller-owned dispatch-ticket cleanup and timer-baseline rollback. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testComposerActiveSendDrainRejectionDoesNotOverwriteNewerComposerChoices root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testComposerActiveSendDrainRejectionDoesNotOverwriteNewerComposerChoices AgentMode codex.manual_send.newer_composer_state_preservation draft,tagged_file,workflow_deselection,mutation_generation,restoration_event_coalescing async_concurrency_lifecycle root_swiftpm integration 3 LivenessFakeCodexController,LivenessSnapshotReadGate,AgentComposerDraftRestorationReducer A rejected manual submission preserves newer composer choices; the shared view reducer merges typing that arrives after model composition and retains cumulative text when earlier restoration events coalesce. Delayed rejection could overwrite newer composer input, resurrect a workflow the user deliberately deselected, or drop an earlier rejected draft before SwiftUI applies the event. test_case+continuation_gate retain 0 Deterministic model-state and composer-local reducer coverage for post-composition typing and coalesced restoration delivery. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testComposerTabSessionReplacementBeforeDispatchRestoresIntoAuthoritativeSession root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testComposerTabSessionReplacementBeforeDispatchRestoresIntoAuthoritativeSession AgentMode codex.manual_send.tab_session_authority tab_session_identity,dispatch_gate,optimistic_rollback,computer_use_activation,draft,image,tagged_file,workflow,mutation_generation async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,CodexDispatchSerialGate A tab-session replacement while a manual send waits at the serial dispatch gate prevents provider dispatch, clears optimistic runtime state from the captured source, and merges the rejected composer operation into the authoritative replacement without overwriting newer choices. A delayed send could steer a successor session, leak source-session transcript or computer-use state, or restore stale composer choices over newer replacement-session input. test_case+dispatch_gate+published_event retain 0 Deterministic same-turn tab-session authority and cross-session composer restoration regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testComposerActiveSendDrainRejectionRemovesOnlyOptimisticBubbleAndRestoresFullComposerState root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testComposerActiveSendDrainRejectionRemovesOnlyOptimisticBubbleAndRestoresFullComposerState AgentMode codex.manual_send.full_pre_dispatch_rollback optimistic_bubble,draft,image,tagged_file,workflow,runtime_anchor,runtime_footer,elapsed_timer,newer_runtime_state async_concurrency_lifecycle root_swiftpm integration 2 LivenessFakeCodexController,LivenessSnapshotReadGate A failed active-send drain removes only the undelivered bubble, restores composer state and elapsed time, and atomically preserves a newer footer without reinserting its already-accounted anchor. Pre-dispatch rejection could lose composer state, overwrite newer runtime accounting, or reinsert an anchor for duplicate duration attribution. test_case+continuation_gate retain 0 Renamed from root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testComposerActiveSendDrainRejectionRemovesOnlyOptimisticBubbleAndRestoresRawDraft and expanded to full composer plus conditional runtime rollback. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testAlternatingStableSnapshotAndProbeFailureRemainsRunning root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testAlternatingStableSnapshotAndProbeFailureRemainsRunning AgentMode codex.app_server.watchdog_probe_failure_tolerance repeated_active_snapshot,probe_failure,remain_running,no_interrupt async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController Alternating unchanged active snapshots and transport probe failures preserve the running session, partial assistant output, controller, and eventual authoritative completion without interrupt or terminal error. Probe transport failures could be mistaken for authoritative terminal evidence and destroy a still-running provider turn. test_case+controller_shutdown retain 0 Exact replacement mapping: testAlternatingStableSnapshotAndProbeFailureKeepsOriginalRecoveryDeadline -> testAlternatingStableSnapshotAndProbeFailureRemainsRunning; lifecycle recovery no longer terminalizes ambiguous probe failures. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testProviderProgressDuringSnapshotProbeSupersedesStaleTerminalization root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testProviderProgressDuringSnapshotProbeSupersedesStaleTerminalization AgentMode codex.app_server.watchdog_progress_generation actor_reentrancy,snapshot_probe,provider_progress,stale_result,terminal_guard async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A provider delta accepted while snapshot probing is suspended supersedes the stale probe result, leaving the run and controller active without interrupt or shutdown. A stale probe result could interrupt and terminalize a healthy turn after newer provider progress arrived during an actor suspension. test_case+continuation_gate retain 0 Deterministic MainActor reentrancy regression using a one-shot snapshot continuation gate. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testPriorAttemptSuspendedSnapshotProbeCannotSettleSuccessorWithAliasedGeneration root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testPriorAttemptSuspendedSnapshotProbeCannotSettleSuccessorWithAliasedGeneration AgentMode codex.app_server.watchdog_run_attempt_identity actor_reentrancy,snapshot_probe,run_attempt,progress_generation,controller_identity,stale_result async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A suspended attempt-A probe resumes after attempt B starts with the same run ID controller and aliased progress generation, then exits without interrupting invalidating or terminally settling B. A stale watchdog probe could pass run controller and generation guards after a successor attempt resets state, then destroy the live successor. test_case+continuation_gate retain 0 Deterministic cross-attempt MainActor reentrancy regression for exact run-attempt scoping. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testChangingActiveSnapshotsRemainValidProgress root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testChangingActiveSnapshotsRemainValidProgress AgentMode codex.app_server.watchdog_snapshot_progress watchdog,thread_snapshot,state_delta,liveness lifecycle_regression root_swiftpm integration 1 LivenessFakeCodexController Alternating active snapshot fingerprints remain running beyond the recovery threshold and issue no interrupt. A real upstream state delta could be mistaken for a repeated heartbeat and terminate a healthy turn. test_case+watchdog_cleanup retain 0 Bounded Codex app-server liveness regression coverage. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCancellationClearsCanonicalAssistantAndReasoningReconciliationState root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCancellationClearsCanonicalAssistantAndReasoningReconciliationState AgentMode codex.transcript.reasoning_reconciliation reasoning,item_completed,transcript_order lifecycle_regression root_swiftpm integration 1 Authoritative reasoning arrays replace, materialize, remove, and order existing thinking rows as asserted. Reasoning could duplicate, remain stale, reorder transcript rows, or leave stale running status. 0.001000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCanonicalAssistantCompletionFlushesEarlierPendingScopeFirst root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCanonicalAssistantCompletionFlushesEarlierPendingScopeFirst AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm integration 1 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.002000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCanonicalAssistantCompletionReconcilesNoDeltaExactPrefixUTF8DuplicateAndEmpty root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCanonicalAssistantCompletionReconcilesNoDeltaExactPrefixUTF8DuplicateAndEmpty AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm integration 6 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.004000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. @@ -1056,8 +1037,6 @@ root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testNilCompletionWit root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testNilStartFollowedByNilCompletionCompletesAnonymousTurn root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testNilStartFollowedByNilCompletionCompletesAnonymousTurn AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.002500 unreviewed retain_pending_review 0 initial census source line 360 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testPendingRequestUserInputSuppressesWatchdogAndPreservesQueue root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testPendingRequestUserInputSuppressesWatchdogAndPreservesQueue AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.159000 unreviewed retain_pending_review 0 initial census source line 215 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testReasoningSealsEarlierPendingAssistantBeforeMaterializing root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testReasoningSealsEarlierPendingAssistantBeforeMaterializing AgentMode codex.transcript.reasoning_reconciliation reasoning,item_completed,transcript_order lifecycle_regression root_swiftpm integration 1 Authoritative reasoning arrays replace, materialize, remove, and order existing thinking rows as asserted. Reasoning could duplicate, remain stale, reorder transcript rows, or leave stale running status. 0.005000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testRepeatedIdenticalActiveSnapshotReattachesWithoutModelInputOrInterrupt root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testRepeatedIdenticalActiveSnapshotReattachesWithoutModelInputOrInterrupt AgentMode codex.app_server.watchdog_active_reattach repeated_active_snapshot,reattach,reconciliation,no_model_input,no_interrupt lifecycle_regression root_swiftpm integration 1 LivenessFakeCodexController An unchanged active snapshot triggers one provider reattach and full snapshot reconciliation while preserving partial output and the running turn without steer, new model input, or interrupt; later completion settles once. Recovery could duplicate model input, interrupt valid provider work, loop controller replacement, or lose the authoritative completion. test_case+controller_shutdown retain 0 Exact replacement chain: testRepeatedIdenticalActiveSnapshotInterruptsExactTurnAndSettlesOnce -> testRepeatedIdenticalActiveSnapshotSendsFollowUpWithoutInterrupt -> testRepeatedIdenticalActiveSnapshotReattachesWithoutModelInputOrInterrupt. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testRepeatedNoActiveSnapshotReattachesAndReconcilesMissedCompletion root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testRepeatedNoActiveSnapshotReattachesAndReconcilesMissedCompletion AgentMode codex.app_server.watchdog_no_active_reattach_completion no_active_snapshot,reattach,latest_turn_status,missed_completion,partial_transcript lifecycle_regression root_swiftpm integration 1 LivenessFakeCodexController Repeated no-active snapshots trigger one reattach, reconcile a missed completed latest turn without model input or interrupt, preserve partial assistant output, and commit completion once. A missed provider completion could leave the local run stuck, trigger duplicate model work, or be misreported as failure after reconnect. test_case+controller_shutdown retain 0 Exact replacement chain: testRepeatedNoActiveSnapshotSettlesAfterExactInterruptAttempt -> testRepeatedNoActiveSnapshotReconnectsAndDispatchesAutomaticContinuation -> testRepeatedNoActiveSnapshotReattachesAndReconcilesMissedCompletion. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testScopedErrorWithoutAuthoritativeIdentityFailsClosed root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testScopedErrorWithoutAuthoritativeIdentityFailsClosed AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 171 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testStaleCompletionBeforeObservedStartPreservesPendingTurnThenMatchingTurnFinalizes root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testStaleCompletionBeforeObservedStartPreservesPendingTurnThenMatchingTurnFinalizes AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 262 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testStaleStructuredScopeIsIgnored root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testStaleStructuredScopeIsIgnored AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 148 @@ -1066,10 +1045,10 @@ root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testStructuredLivene root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testStructuredRetryAndMissingMetadataFallbackRemainActiveWithoutRows root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testStructuredRetryAndMissingMetadataFallbackRemainActiveWithoutRows AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 90 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTurnCompletionClearsEmptyScheduledAssistantFlushBeforeBarrier root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTurnCompletionClearsEmptyScheduledAssistantFlushBeforeBarrier AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm integration 1 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.003500 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTurnCompletionCoalescesBufferedAssistantTailBeforeTerminalSeal root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTurnCompletionCoalescesBufferedAssistantTailBeforeTerminalSeal AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm integration 1 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.006500 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTurnStartSilenceRemainsRunningWithoutSpeculativeRedispatch root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTurnStartSilenceRemainsRunningWithoutSpeculativeRedispatch AgentMode codex.app_server.turn_start_silence_no_redispatch turn_start,provider_silence,remain_running,no_redispatch async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController A delayed initial turn/start records exactly one dispatch, returns sent, and leaves the session running without interrupt, shutdown, error, or speculative redispatch. Turn-start silence could trigger duplicate model work or falsely terminalize a request still being admitted by the provider. test_case+controller_shutdown retain 0 Exact replacement mapping: testTurnStartSilenceIsBoundedWithoutSpeculativeRedispatch -> testTurnStartSilenceRemainsRunningWithoutSpeculativeRedispatch; provider admission silence remains non-terminal. root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testTypedSteerRejectionReturnsFallbackWithoutReplacingAuthoritativeIdentity root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testTypedSteerRejectionReturnsFallbackWithoutReplacingAuthoritativeIdentity AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.008500 unreviewed retain_pending_review 0 initial census source line 532 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testUnmatchedCompletionOnlyWebResultPreservesArgsForPersistenceAndReplay root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testUnmatchedCompletionOnlyWebResultPreservesArgsForPersistenceAndReplay AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.002500 unreviewed retain_pending_review 0 initial census source line 52 root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testWatchdogFlushesCachedExplicitErrorWhenProbeFindsNoActiveTurn root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testWatchdogFlushesCachedExplicitErrorWhenProbeFindsNoActiveTurn AgentMode codex.app_server.structured_failure_authority turn_error,will_retry,transport,watchdog lifecycle_regression root_swiftpm integration 1 Scoped async errors and failed turn completion produce the asserted single authoritative failure outcome. Failures could duplicate rows, lose the server message, terminate retries, or be discarded on transport loss. 0.037000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. +root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testWatchdogPauseRemainsRunningAndDoesNotAppendTranscriptFailure root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testWatchdogPauseRemainsRunningAndDoesNotAppendTranscriptFailure AgentMode unreviewed unreviewed root_swiftpm integration 1 unreviewed unreviewed 0.035500 unreviewed retain_pending_review 0 initial census source line 194 root/RepoPromptTests.CodexCLIProviderReconciliationTests/testCanonicalCompletionReconcilesStreamingTailAndConnectionReplacement root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testCanonicalCompletionReconcilesStreamingTailAndConnectionReplacement AI codex.provider.event_reconciliation canonical_assistant,turn_failure,streaming,connection provider_integration root_swiftpm routine 2 The public Codex provider stream and connection paths reconcile authoritative assistant text and propagate structured failures as asserted. Non-Agent Codex consumers could lose tails, retain corrected text, or hide authoritative failure messages. 0.026500 test_case retain 0 Authoritative test-list reconciliation for the current integration worktree. root/RepoPromptTests.CodexCLIProviderReconciliationTests/testStructuredFailedCompletionMessagePropagatesThroughStreamingAndConnectionPaths root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testStructuredFailedCompletionMessagePropagatesThroughStreamingAndConnectionPaths AI codex.provider.event_reconciliation canonical_assistant,turn_failure,streaming,connection provider_integration root_swiftpm routine 2 The public Codex provider stream and connection paths reconcile authoritative assistant text and propagate structured failures as asserted. Non-Agent Codex consumers could lose tails, retain corrected text, or hide authoritative failure messages. 0.027000 test_case retain 0 Authoritative test-list reconciliation for the current integration worktree. root/RepoPromptTests.CodexFallbackFIFOTests/testClearChatDiscardsFallbackInputWithoutReversingDeliveryAcknowledgement root Tests/RepoPromptTests/AgentMode/Codex/CodexFallbackFIFOTests.swift RepoPromptTests.CodexFallbackFIFOTests testClearChatDiscardsFallbackInputWithoutReversingDeliveryAcknowledgement AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.008000 unreviewed retain_pending_review 0 initial census source line 759 @@ -1103,16 +1082,9 @@ root/RepoPromptTests.CodexGoalSupportDefaultTests/testMissingGlobalSettingsGoalS root/RepoPromptTests.CodexGoalSupportDefaultTests/testMissingGlobalSettingsReasoningSummariesScalarDefaultsDisabled root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testMissingGlobalSettingsReasoningSummariesScalarDefaultsDisabled AgentMode codex_goal_support_default.missing_global_settings_reasoning_summaries_scalar_defaults_disabled configuration_regression root_swiftpm routine 1 CodexGoalSupportDefaultTests asserts missing global settings reasoning summaries scalar defaults disabled with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.001500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.CodexGoalSupportDefaultTests/testMissingUserDefaultsGoalKeyDefaultsEnabled root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testMissingUserDefaultsGoalKeyDefaultsEnabled AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 17 root/RepoPromptTests.CodexGoalSupportDefaultTests/testMissingUserDefaultsReasoningSummariesKeyDefaultsDisabled root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testMissingUserDefaultsReasoningSummariesKeyDefaultsDisabled AgentMode codex_goal_support_default.missing_user_defaults_reasoning_summaries_key_defaults_disabled configuration_regression root_swiftpm routine 1 CodexGoalSupportDefaultTests asserts missing user defaults reasoning summaries key defaults disabled with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.001000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. -root/RepoPromptTests.CodexGoalSupportDefaultTests/testProviderConversationCleanupActionDefaultsArchiveAndPersistsDelete root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testProviderConversationCleanupActionDefaultsArchiveAndPersistsDelete AgentMode agent_mode.provider_conversation_cleanup.action_default_and_persisted_override provider_cleanup,settings,archive_default,delete_override,persistence configuration_regression root_swiftpm routine 2 A missing cleanup-action scalar resolves to archive, while the persisted delete raw value resolves to the explicit delete action. Cleanup settings drift could make destructive deletion the implicit default or ignore an explicit user-selected cleanup action. test_case retain 0 PR #316 / issue #298 reviewed provider cleanup action default and persisted override contract. -root/RepoPromptTests.CodexGoalSupportDefaultTests/testProviderConversationCleanupHandleFallsBackToProviderSessionID root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testProviderConversationCleanupHandleFallsBackToProviderSessionID AgentMode agent_mode.provider_conversation_cleanup.handle_provider_session_fallback provider_cleanup,oracle,cleanup_handle,provider_session_id,normalization metadata_routing_regression root_swiftpm routine 1 A Claude result without an explicit cleanup handle produces provider claudeCode with the trimmed provider session ID and no conversation ID. Oracle cleanup could be skipped or routed with an untrimmed or incorrect provider session identifier. test_case retain 0 PR #316 / issue #298 reviewed handle-driven Oracle cleanup fallback contract. -root/RepoPromptTests.CodexGoalSupportDefaultTests/testProviderConversationCleanupHandlePrefersExplicitHandle root Tests/RepoPromptTests/AgentMode/Codex/CodexGoalSupportDefaultTests.swift RepoPromptTests.CodexGoalSupportDefaultTests testProviderConversationCleanupHandlePrefersExplicitHandle AgentMode agent_mode.provider_conversation_cleanup.handle_explicit_metadata_precedence provider_cleanup,oracle,cleanup_handle,explicit_metadata,precedence metadata_routing_regression root_swiftpm routine 1 An explicit provider cleanup handle is returned unchanged even when a fallback provider session ID is also present. Fallback inference could overwrite authoritative cleanup metadata and target the wrong provider conversation. test_case retain 0 PR #316 / issue #298 reviewed explicit cleanup-handle precedence contract. -root/RepoPromptTests.CodexIntegrationConfigurationTests/testCodexConfigUsesRepoPromptOwnedBuildSeparatedState root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testCodexConfigUsesRepoPromptOwnedBuildSeparatedState MCP codex.config.owned_build_state codex_home,debug_release,state_isolation deterministic_configuration root_swiftpm routine 1 The active build channel resolves config.toml beneath RepoPrompt CE/Codex/{Debug,Release}/home and never ~/.codex. RepoPrompt configuration could mutate ordinary Codex CLI or official Codex App state. 0.001000 test_case retain 0 PR3 build-separated Codex config ownership contract. root/RepoPromptTests.CodexIntegrationConfigurationTests/testDiscoveryEnsureWritesBareRepoPromptCEServerHeader root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testDiscoveryEnsureWritesBareRepoPromptCEServerHeader MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 41 root/RepoPromptTests.CodexIntegrationConfigurationTests/testMCPServerEntryParserHandlesQuotedBareAndNestedHeaders root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testMCPServerEntryParserHandlesQuotedBareAndNestedHeaders MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 107 root/RepoPromptTests.CodexIntegrationConfigurationTests/testModelReasoningSummaryOverridesEmitExpectedAppServerValues root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testModelReasoningSummaryOverridesEmitExpectedAppServerValues MCP codex_integration_configuration.model_reasoning_summary_overrides_emit_expected_app_server_values configuration_regression root_swiftpm routine 1 CodexIntegrationConfigurationTests asserts model reasoning summary overrides emit expected app server values with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.010000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. -root/RepoPromptTests.CodexIntegrationConfigurationTests/testOldExternalCodexPolicyIsDeclinedBeforeWritingUnknownKey root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testOldExternalCodexPolicyIsDeclinedBeforeWritingUnknownKey MCP codex.config.external_version_gate direct_only_tool_namespaces,external_override,compatibility deterministic_configuration root_swiftpm routine 1 An incompatible external runtime policy returns an actionable conflict with byte-identical TOML and no unknown key. Codex 0.141.x could reject a blindly written direct_only_tool_namespaces key. 0.001000 test_case retain 0 PR3 pre-0.142 external override configuration gate. -root/RepoPromptTests.CodexIntegrationConfigurationTests/testOwnedCodeModePolicyIsExactIdempotentAndPreservesUnrelatedSettings root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testOwnedCodeModePolicyIsExactIdempotentAndPreservesUnrelatedSettings MCP codex.config.code_mode_owned_policy direct_only_tool_namespaces,idempotence,toml_preservation,namespace_case deterministic_configuration root_swiftpm routine 1 One mutation writes the exact enabled/direct-only policy and RepoPrompt MCP block, preserves unrelated TOML, and a second mutation is byte-stable. Auto-configuration could rewrite user settings, drift namespace case, or expose RepoPrompt tools in nested code mode. 0.001000 test_case retain 0 PR3 owned Codex TOML mutation contract. -root/RepoPromptTests.CodexIntegrationConfigurationTests/testOwnedCodeModePolicySurfacesNamespaceConflictWithoutMutation root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testOwnedCodeModePolicySurfacesNamespaceConflictWithoutMutation MCP codex.config.code_mode_layout_conflict non_prefixed_mcp_tool_names,dotted_keys,inline_tables,conflict,toml_preservation deterministic_configuration root_swiftpm routine 4 Legacy namespace, dotted owned-key, inline features-table, and inline owned-value conflicts each produce a diagnostic and leave TOML byte-identical. Conflicting code-mode layouts could be silently rewritten or combined into invalid TOML or an unsafe tool surface. 0.001000 test_case retain 0 PR3 code-mode conflict fail-closed contract expanded for dotted and inline layouts. root/RepoPromptTests.CodexIntegrationConfigurationTests/testPersistentMutationAddsGlobalLimitWhenExistingNumericIsQuoted root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testPersistentMutationAddsGlobalLimitWhenExistingNumericIsQuoted MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 180 root/RepoPromptTests.CodexIntegrationConfigurationTests/testPersistentMutationIsIdempotentAfterRepair root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testPersistentMutationIsIdempotentAfterRepair MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 196 root/RepoPromptTests.CodexIntegrationConfigurationTests/testPersistentMutationPreservesUnderscoredGlobalLimitAndStripsServerLevelLimit root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testPersistentMutationPreservesUnderscoredGlobalLimitAndStripsServerLevelLimit MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 143 @@ -1128,23 +1100,8 @@ root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5MigrationLeavesOth root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5MigrationPreservesLaterEquivalentDuplicateAssignments root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testV5MigrationPreservesLaterEquivalentDuplicateAssignments MCP codex.mcp.v5_equivalent_policy_deduplication parallel_tool_calls;active_timeout;equivalent_duplicates;comment_preservation deterministic_configuration root_swiftpm routine 1 V5 migration collapses duplicate timeout and parallel-policy assignments while preserving the later compliant values and comments medium 0.000000 in_memory_configuration per_test_value retain 0 V5 later compliant timeout and parallel-policy preservation regression. Renamed: root/RepoPromptTests.CodexIntegrationConfigurationTests/testV4MigrationPreservesLaterEquivalentDuplicateAssignments -> root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5MigrationPreservesLaterEquivalentDuplicateAssignments root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5MigrationRestoresLongTimeoutAndParallelPolicyTogether root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testV5MigrationRestoresLongTimeoutAndParallelPolicyTogether MCP codex.mcp.parallel_policy_migration timeout_repair;parallel_tool_calls;migration_idempotence deterministic_configuration root_swiftpm routine 2 Existing enabled parallel policy stays enabled while timeout repair remains idempotent, and an existing disabled policy migrates to exactly one enabled assignment high 0.001000 in_memory_configuration per_test_value retain 0 V5 migration regression for both V4 enabled and disabled persisted policies. Renamed: root/RepoPromptTests.CodexIntegrationConfigurationTests/testV4MigrationRestoresLongTimeoutAndParallelPolicyTogether -> root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5MigrationRestoresLongTimeoutAndParallelPolicyTogether root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5PolicyConstantsPreserveLongActiveTimeoutAndEnableParallelCalls root Tests/RepoPromptTests/MCP/CodexIntegration/CodexIntegrationConfigurationTests.swift RepoPromptTests.CodexIntegrationConfigurationTests testV5PolicyConstantsPreserveLongActiveTimeoutAndEnableParallelCalls MCP codex.mcp.v5_policy_constants active_timeout;parallel_tool_calls;schema_version deterministic_configuration root_swiftpm routine 1 V5 policy constants keep the long active timeout and advertise parallel tool calls enabled high 0.000000 in_memory_configuration per_test_value retain 0 V5 policy constant regression. Renamed: root/RepoPromptTests.CodexIntegrationConfigurationTests/testV4PolicyConstantsPreserveLongActiveTimeoutAndDisableParallelCalls -> root/RepoPromptTests.CodexIntegrationConfigurationTests/testV5PolicyConstantsPreserveLongActiveTimeoutAndEnableParallelCalls -root/RepoPromptTests.CodexMCPBootstrapReadinessTests/testCancellationDuringProvisioningDoesNotCrossLaunchBoundary root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPBootstrapReadinessTests.swift RepoPromptTests.CodexMCPBootstrapReadinessTests testCancellationDuringProvisioningDoesNotCrossLaunchBoundary AgentMode codex.app_server.fail_closed_mcp_provisioning provisioning_gate,cancellation cancellation_contract root_swiftpm routine 1 ProvisionerSuspensionGate A cancellation while the provisioner is suspended aborts startOrResume with CancellationError before app-server process start, thread request, or expected-agent PID registration. A cancellation racing provisioning could launch the child process or send a turn after the run was already cancelled. 0.002000 async_tasks;cancellation_gates test_case retain 0 Issue #514: cancellation cannot cross the Codex MCP provisioning launch boundary. -root/RepoPromptTests.CodexMCPBootstrapReadinessTests/testSuccessfulProvisionerProceedsToProcessStartAndThreadRequest root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPBootstrapReadinessTests.swift RepoPromptTests.CodexMCPBootstrapReadinessTests testSuccessfulProvisionerProceedsToProcessStartAndThreadRequest AgentMode codex.app_server.authoritative_runtime_handoff provisioning_gate,startup_ordering,captured_login_shell,managed_state_environment async_state_machine root_swiftpm routine 1 CodexFakeAppServerScript,ProvisionerSuspensionGate,ProvisionedRuntimeRecorder A shell-only absolute override is probed once, passed unchanged to provisioning, and reused for app-server launch with managed CODEX_HOME/CODEX_SQLITE_HOME; process and thread startup remain ordered after the gate. Native Agent Mode could provision one runtime then launch another, miss a shell-only override when the bundle is unavailable, or leak the child into user Codex state. 1.340000 python_subprocess;temp_directory;async_tasks test_case retain 0 Issue #514 startup ordering plus PR3 single-runtime authority handoff. -root/RepoPromptTests.CodexMCPBootstrapReadinessTests/testThrowingProvisionerAbortsBeforeProcessStartAndThreadRequest root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPBootstrapReadinessTests.swift RepoPromptTests.CodexMCPBootstrapReadinessTests testThrowingProvisionerAbortsBeforeProcessStartAndThreadRequest AgentMode codex.app_server.fail_closed_mcp_provisioning provisioning_gate,startup_abort,resume async_state_machine root_swiftpm routine 2 A throwing provisioner aborts startOrResume with provisioningUnavailable for both a fresh start and a resume, before any app-server process start or thread/start or thread/resume request, and registers no expected-agent PID nor emits a spurious PID clear. A Codex child could launch and reach its first turn despite failed RepoPrompt MCP provisioning, running a session without RepoPrompt tools. 0.001000 test_case retain 0 Issue #514: fail-closed Codex MCP provisioning for fresh start and resume. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testCancellationDuringRoutingWaitDoesNotReachFirstTurn root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testCancellationDuringRoutingWaitDoesNotReachFirstTurn AgentMode codex.agent_mode.fail_closed_mcp_routing_boundary routing_gate,cancellation,pre_first_turn cancellation_contract root_swiftpm routine 1 RoutingReadinessFakeCodexController,TerminalPublicationRecorder,RunIDBox A run cancelled while the MCP routing wait is suspended returns a cancelled outcome, never calls startUserTurn, and publishes no terminal state. A cancellation racing the suspended routing wait could let the child dispatch its first turn or publish a spurious fail-closed terminal state. 0.030000 global_connection_gate;server_network_manager;async_tasks mcp_shared_server;ServerNetworkManager MCPSharedServerTestLease retain 0 Issue #514: a run cancelled during the routing wait does not reach its first turn. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testMissingRolloutFallbackClassifierMatchesOnlyKnownMissingForms root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testMissingRolloutFallbackClassifierMatchesOnlyKnownMissingForms AgentMode codex.agent_mode.missing_rollout_fallback_classifier resume,missing_rollout,error_classification classification_contract root_swiftpm routine 8 Only recognized missing-rollout error forms trigger a fresh-start fallback; malformed, permission, and corruption errors remain terminal. An over-broad classifier could discard resumable state or hide permission and corruption failures behind an unintended fresh start. test_case retain 0 PR #621 exact positive and negative classifier matrix for missing-rollout fallback. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testResumeFallbackToFreshRoutingFailureUsesStartPrefixAndDeduplicates root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testResumeFallbackToFreshRoutingFailureUsesStartPrefixAndDeduplicates AgentMode codex.agent_mode.actual_startup_disposition_routing_failure resume,fresh_fallback,routing_gate,error_prefix,dedup,stale_disposition async_state_machine root_swiftpm routine 2 RoutingReadinessFakeCodexController,TerminalPublicationRecorder A missing-rollout resume retries as a fresh start, then an unrouted fallback records exactly one start-prefixed readiness failure and one terminal publication; failure classification also recognizes that fresh-start prefix even if the stored disposition is stale-resumed. A successful fresh fallback could be mislabeled as a resume failure, or stale disposition could bypass generic native-start failure deduplication and publish a second terminal failure. global_connection_gate;server_network_manager;async_tasks mcp_shared_server;ServerNetworkManager MCPSharedServerTestLease retain 0 Actual startup disposition owns user-visible routing failure classification, while dedup remains a superset of both native failure prefixes. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testRestoredResumeRequiresRealMatchingMCPAdmissionBeforeFirstTurn root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testRestoredResumeRequiresRealMatchingMCPAdmissionBeforeFirstTurn AgentMode codex.agent_mode.real_matching_mcp_admission expected_pid,policy_admission,route_commit,resume,pre_first_turn async_state_machine root_swiftpm routine 1 RoutingReadinessFakeCodexController,TerminalPublicationRecorder,RunIDBox A restored Codex resume remains behind the first-turn boundary until a real matching expected-PID policy admission commits its run route, then dispatches exactly one turn without a terminal failure. Direct waiter notification could mask a broken policy admission or permit restored Codex metadata to resume without a newly committed live process route. global_connection_gate;server_network_manager;async_tasks mcp_shared_server;ServerNetworkManager MCPSharedServerTestLease retain 0 Renamed from testResumingChildWhoseRoutingConfirmsReachesFirstTurn and strengthened to require real matching MCP admission for PR4. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testToolPreferenceChangeDuringSuspendedStartPreservesReconnectForNextEnsure root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testToolPreferenceChangeDuringSuspendedStartPreservesReconnectForNextEnsure AgentMode codex.agent_mode.tool_preference_generation_reconnect thread_start,suspended_start,preference_generation,reconnect,controller_replacement async_state_machine root_swiftpm routine 1 RoutingReadinessFakeCodexController,RoutingReadinessAsyncGate A tool-preference generation change during suspended thread/start remains reconnect-pending after startup and forces exactly one controller replacement on the next ensure. Clearing reconnect after a generation mismatch would silently keep stale thread-level MCP and native-tool configuration because turn/start has no config override bag. async_tasks test_case retain 0 PR4 regression for thread-level Codex tool configuration drift during suspended startup. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testUnroutedChildFailsClosedBeforeFirstTurnWithoutLeakingBootstrapState root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testUnroutedChildFailsClosedBeforeFirstTurnWithoutLeakingBootstrapState AgentMode codex.agent_mode.fail_closed_mcp_routing_boundary routing_gate,pre_first_turn,bootstrap_cleanup async_state_machine root_swiftpm routine 1 RoutingReadinessFakeCodexController,TerminalPublicationRecorder When a Codex child's thread starts but its routing wait times out, startUserTurn never fires, the send outcome and exactly one terminal publication both report a failed run, exactly one readiness error is recorded in the child transcript, the controller is released, and the bootstrap gate, routing waiter, and one-shot connection policy are all cleared. A tool-less Codex child could reach its first turn over an unrouted connection, or a failed start could leak the bootstrap gate, routing waiter, or pending connection policy. 0.538000 global_connection_gate;server_network_manager;async_tasks mcp_shared_server;ServerNetworkManager MCPSharedServerTestLease retain 0 Issue #514: an unrouted Codex child fails closed before its first turn with no leaked bootstrap state. -root/RepoPromptTests.CodexMCPRoutingReadinessTests/testUnroutedResumeFailsClosedWithResumeFailurePrefix root Tests/RepoPromptTests/AgentMode/Codex/CodexMCPRoutingReadinessTests.swift RepoPromptTests.CodexMCPRoutingReadinessTests testUnroutedResumeFailsClosedWithResumeFailurePrefix AgentMode codex.agent_mode.fail_closed_mcp_routing_boundary routing_gate,resume,pre_first_turn,error_classification async_state_machine root_swiftpm routine 1 RoutingReadinessFakeCodexController,TerminalPublicationRecorder An unrouted resumed Codex child never dispatches its next turn, publishes exactly one failed terminal state, records exactly one routing-readiness error with the native resume failure prefix, and records no fresh-start failure prefix. An unrouted resume could dispatch a turn, publish duplicate terminal state, or be mislabeled as a fresh start and obscure the failing lifecycle boundary. 0.538000 global_connection_gate;server_network_manager;async_tasks mcp_shared_server;ServerNetworkManager MCPSharedServerTestLease retain 0 Issue #514: an unrouted Codex resume fails closed with resume-specific classification. root/RepoPromptTests.CodexModelPollingServiceTests/testLastSubscriberStopsOwnedClientAndLaterSubscriberRestartsPolling root Tests/RepoPromptTests/AI/CodexModelPollingServiceTests.swift RepoPromptTests.CodexModelPollingServiceTests testLastSubscriberStopsOwnedClientAndLaterSubscriberRestartsPolling AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.032000 unreviewed retain_pending_review 0 initial census source line 5 -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testArchiveByConversationIDSendsThreadArchiveRequest root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testArchiveByConversationIDSendsThreadArchiveRequest AI/Codex codex_native.conversation_cleanup.archive_by_conversation_id provider_cleanup,codex_app_server,thread_archive,conversation_id protocol_request_regression root_swiftpm routine 1 Archiving by conversation ID succeeds and sends one thread/archive request with the exact threadId. Codex conversations could remain unarchived or the request could target the wrong thread. test_case retain 0 PR #315/#316 reviewed direct Codex thread archive contract. -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testArchiveByRolloutPathResolvesSummaryThenArchivesThread root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testArchiveByRolloutPathResolvesSummaryThenArchivesThread AI/Codex codex_native.conversation_cleanup.rollout_resolution_archive provider_cleanup,codex_app_server,rollout_path,conversation_summary,thread_archive protocol_sequence_regression root_swiftpm routine 1 Archiving by rollout path first requests the conversation summary, then archives the resolved thread ID in exact request order. Rollout-only sessions could fail cleanup or archive a thread without authoritative ID resolution. test_case retain 0 PR #315/#316 reviewed rollout-path Codex archive sequence contract. -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testArchiveRequestFailureMapsToFailedOutcome root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testArchiveRequestFailureMapsToFailedOutcome AI/Codex codex_native.conversation_cleanup.archive_failure_mapping provider_cleanup,codex_app_server,error_mapping,failed_outcome protocol_error_mapping root_swiftpm routine 1 A rejected archive request returns failed status with the underlying localized cleanup error message. Provider cleanup failures could be mislabeled as success or lose actionable error detail. test_case retain 0 PR #315/#316 reviewed Codex archive failure mapping contract. -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testDeleteByConversationIDSendsThreadDeleteRequest root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testDeleteByConversationIDSendsThreadDeleteRequest AI/Codex codex_native.conversation_cleanup.delete_by_conversation_id provider_cleanup,codex_app_server,thread_delete,conversation_id protocol_request_regression root_swiftpm routine 1 Deleting by conversation ID succeeds and sends one thread/delete request with the exact threadId. Codex deletion could remain unavailable, target the wrong thread, or falsely report success without issuing the authoritative protocol request. test_case retain 0 Exact replacement mapping: testDeleteIsUnsupportedAndDoesNotSendRequest -> testDeleteByConversationIDSendsThreadDeleteRequest; bundled Codex 0.144.6 thread/delete contract. root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testActualCodexWebSearchLifecycleShapesPreserveQueriesAndIgnoreRawDuplicate root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testActualCodexWebSearchLifecycleShapesPreserveQueriesAndIgnoreRawDuplicate AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 240 -root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testRawExecCallIDAndSnapshotItemIDShareOnlyOpaqueProcessHandle root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testRawExecCallIDAndSnapshotItemIDShareOnlyOpaqueProcessHandle AgentMode codex.app_server.command_identity_domains raw_exec,call_id,snapshot_item_id,opaque_process_handle protocol_contract root_swiftpm routine 1 CodexNativeSessionController.test_handleNotification,CodexNativeSessionController.test_parseThreadSnapshot A raw exec begin and authoritative snapshot produce different invocation IDs but expose the same opaque execution handle as the deterministic bridge. Raw call IDs could be incorrectly assumed to equal snapshot item IDs, or numeric handles could be mistaken for POSIX liveness. test_case retain 0 Protocol-shaped identity-domain regression for watchdog correlation. root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testAssistantCompleteReconciliationIsIsolatedAndResetsWhenTurnCompletes root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testAssistantCompleteReconciliationIsIsolatedAndResetsWhenTurnCompletes AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm routine 1 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.001000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testAssistantCompleteReconciliationResetsAtCanonicalItemBoundary root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testAssistantCompleteReconciliationResetsAtCanonicalItemBoundary AgentMode codex.transcript.assistant_reconciliation assistant,item_completed,terminal_barrier lifecycle_regression root_swiftpm routine 1 Streamed and authoritative assistant content yields the asserted rows, ordering, tail, and terminal drain state. Assistant output could duplicate, lose UTF-8 tails, cross tool boundaries, or regress PR #299 terminal conclusions. 0.000500 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testCanonicalAndDeprecatedContextCompactionDeduplicate root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testCanonicalAndDeprecatedContextCompactionDeduplicate AgentMode codex.app_server.context_compaction context_compaction,dedup,legacy_fallback protocol_contract root_swiftpm routine 4 Canonical compaction items and the deprecated fallback emit the expected deduplicated context update count. Context usage could be updated twice or a distinct compaction could be dropped. 0.001000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. @@ -1183,24 +1140,18 @@ root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testAgentModeDe root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testAgentModeDefaultCarriesExplicitGoalOptOutToStartAndResume root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testAgentModeDefaultCarriesExplicitGoalOptOutToStartAndResume AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.531500 unreviewed retain_pending_review 0 initial census source line 30 root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testAgentModeDefaultCarriesGoalFeatureConfigToStartAndResume root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testAgentModeDefaultCarriesGoalFeatureConfigToStartAndResume AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.523500 unreviewed retain_pending_review 0 initial census source line 16 root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testAgentModeDefaultCarriesReasoningSummaryOptInToStartAndResume root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testAgentModeDefaultCarriesReasoningSummaryOptInToStartAndResume AgentMode codex_native_session_controller_goal_config.agent_mode_default_carries_reasoning_summary_opt_in_to_start_and_resume configuration_regression root_swiftpm routine 1 CodexNativeSessionControllerGoalConfigTests asserts agent mode default carries reasoning summary opt in to start and resume with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.525500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testControllerDefaultTimeoutDoesNotScheduleTurnStartDeadline root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testControllerDefaultTimeoutDoesNotScheduleTurnStartDeadline AgentMode codex.app_server.turn_start_timeout_exemption default_timeout,turn_start,no_retry async_state_machine root_swiftpm routine 1 fake_codex_app_server A controller-configured default request timeout leaves one silent turn/start pending with no timeout task and records exactly one dispatch until explicit cancellation. Applying the control-plane deadline to uncertain turn acceptance could report a false failure or encourage a duplicate turn submission. python_subprocess;temp_directory;jsonl_record test_case+addTeardownBlock+tearDown retain 0 PR5 production-path regression for semantic turn/start timeout exemption. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testControllerOptionBoundsSilentInitializeAndPoisonsExactTransportGeneration root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testControllerOptionBoundsSilentInitializeAndPoisonsExactTransportGeneration AgentMode codex.app_server.initialize_default_timeout initialize,default_timeout,transport_generation,timeout_poisoning,termination_ownership process_lifecycle root_swiftpm routine 1 fake_codex_app_server The controller option bounds one silent production initialize request, returns the typed timeout, and records timeout poisoning against the unchanged exact transport generation. A silent initialize could hang a tab indefinitely or leave its timed-out transport eligible for later control requests. python_subprocess;temp_directory;jsonl_record test_case+addTeardownBlock+tearDown retain 0 PR5 production-path regression for bounded initialize and exact-generation timeout poisoning; authoritative reap completion remains covered by the client process-observer tests. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testDefaultAppServerClientLaunchOmitsProcessReasoningSummaryOverride root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testDefaultAppServerClientLaunchOmitsProcessReasoningSummaryOverride AgentMode codex_native_session_controller_goal_config.default_app_server_client_launch_omits_process_reasoning_summary_override configuration_regression root_swiftpm routine 1 CodexNativeSessionControllerGoalConfigTests asserts default app server client launch omits process reasoning summary override with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.212000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testDefaultConfigOverridesOmitThreadReasoningSummaryWhenUnspecified root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testDefaultConfigOverridesOmitThreadReasoningSummaryWhenUnspecified AgentMode codex_native_session_controller_goal_config.default_config_overrides_omit_thread_reasoning_summary_when_unspecified configuration_regression root_swiftpm routine 1 CodexNativeSessionControllerGoalConfigTests asserts default config overrides omit thread reasoning summary when unspecified with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.006000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testExplicitAppServerClientLaunchSerializesProcessReasoningSummaryAuto root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testExplicitAppServerClientLaunchSerializesProcessReasoningSummaryAuto AgentMode codex_native_session_controller_goal_config.explicit_app_server_client_launch_serializes_process_reasoning_summary_auto configuration_regression root_swiftpm routine 1 CodexNativeSessionControllerGoalConfigTests asserts explicit app server client launch serializes process reasoning summary auto with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.208500 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testInitializedNotificationOmitsParams root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testInitializedNotificationOmitsParams AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 1 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.236500 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testLifecyclePhaseDiagnosticsUseFixedRedactedFieldsAcrossSuccessAndProvisioningFailure root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testLifecyclePhaseDiagnosticsUseFixedRedactedFieldsAcrossSuccessAndProvisioningFailure AgentMode codex.app_server.lifecycle_phase_diagnostics runtime_resolution,provisioning,spawn_initialize,thread_start,thread_resume,turn_acceptance,shutdown,redaction,transport_generation diagnostic_integration root_swiftpm routine 3 fake_codex_app_server Successful fresh and resumed production lifecycle boundaries emit fixed phase outcome duration and available transport-generation fields including the controller-owned shutdown call, while a provisioning failure emits only its typed failed outcome and never the injected path prompt token auth URL stderr or raw-error sentinel. Lifecycle stalls could remain unattributed, or diagnostic fields could leak sensitive paths payloads identifiers authentication material stderr or raw failures. python_subprocess;temp_directory;jsonl_record AgentModePerfDiagnostics test_case+addTeardownBlock+tearDown retain 0 PR5 redacted lifecycle phase timing coverage using the existing opt-in performance diagnostics surface. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testNativeSessionControllerDefaultOptionsOmitProcessReasoningSummaryOverride root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testNativeSessionControllerDefaultOptionsOmitProcessReasoningSummaryOverride AgentMode codex_native_session_controller_goal_config.native_session_controller_default_options_omit_process_reasoning_summary_override configuration_regression root_swiftpm routine 1 CodexNativeSessionControllerGoalConfigTests asserts native session controller default options omit process reasoning summary override with exact state, configuration, or formatted-output expectations. Provider/model configuration could serialize the wrong reasoning-summary/default option and change launched agent behavior. 0.261000 test_suite_ledger_stabilization_2026-07-03 retain 0 Gate 0 exact-ID stabilization 2026-07-03: live method added from authoritative conductor list; metadata intentionally minimal and suite-scoped. +root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testOptionalMemoryModeRetriesDoNotFailStartup root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testOptionalMemoryModeRetriesDoNotFailStartup AgentMode codex.app_server.memory_mode_best_effort startup_readiness,background_retry async_state_machine root_swiftpm routine 2 Startup succeeds despite ignored memoryMode/set responses, records bounded foreground attempts, and a background retry lands after readiness. high 2.000000 test_case retain 0 Codex app-server startup stall fix: optional memory-mode disable is best effort and cannot hold startup readiness. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testPathOnlyResumeFailsLocallyBeforeWritingRequest root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testPathOnlyResumeFailsLocallyBeforeWritingRequest AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 1 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.002000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testProcessLaunchDirectoryUpdateKeepsRunningTransportAndAppliesAfterRestart root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testProcessLaunchDirectoryUpdateKeepsRunningTransportAndAppliesAfterRestart AgentMode codex.app_server.process_launch_directory_next_start running_transport,next_start,working_directory process_lifecycle root_swiftpm routine 2 fake_codex_app_server Changing the configured launch directory preserves the running PID and transport generation, then the same client records the new working directory after an explicit stop and restart. Reconstructing Config or coupling directory updates to restart policy could terminate active sessions or launch the next app-server from a stale directory. subprocess test_case retain 0 Client-level lifecycle coverage for launch-directory next-start behavior. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testProcessLaunchPolicyUpdateRestartsOnlyForEffectiveChanges root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testProcessLaunchPolicyUpdateRestartsOnlyForEffectiveChanges AgentMode codex.app_server.process_launch_policy_effective_change feature_policy,reasoning_summary,explicit_stop process_lifecycle root_swiftpm routine 3 fake_codex_app_server An identical policy preserves PID and generation, while feature-policy and reasoning-summary changes each stop the running transport with explicitStop. Mechanical Config mutation could accidentally restart unchanged sessions or fail to restart when process launch policy changes. subprocess test_case retain 0 Client-level lifecycle coverage for effective launch-policy restart behavior. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testProtocolShapeRejectionsPreserveMessageAndUseManagedRuntimeGuidance root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testProtocolShapeRejectionsPreserveMessageAndUseManagedRuntimeGuidance AgentMode codex.app_server.request_conformance initialize,resume,json_rpc,managed_runtime_guidance protocol_contract root_swiftpm routine 4 Protocol-shape errors preserve the server message and direct managed users to RepoPrompt CE recovery while naming the explicit override escape hatch, never a generic installed-CLI update. Malformed initialization or resume requests could prevent Codex sessions from starting or misdirect bundled-runtime users toward an unrelated CLI install. 0.000500 test_case retain 0 Renamed from testProtocolShapeRejectionsPreserveMessageAndAdviseCLIUpdate for PR3 managed-runtime guidance. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testResumeWithBlankPathOmitsPathAndSendsRequiredThreadID root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testResumeWithBlankPathOmitsPathAndSendsRequiredThreadID AgentMode codex.app_server.request_conformance thread_resume,blank_path,thread_id,request_shape protocol_contract root_swiftpm routine 1 fake_codex_app_server A whitespace-only persisted rollout path is omitted from thread/resume while the required threadId is still serialized. Forwarding a blank path could violate the app-server request contract and prevent a valid thread-ID resume. python_subprocess;temp_directory;jsonl_record test_case+addTeardownBlock+tearDown retain 0 PR #621 blank-path resume request-shape regression. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testSchemaAlignedThreadRequestsOmitUndeclaredFieldsAndAcceptMissingGoal root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testSchemaAlignedThreadRequestsOmitUndeclaredFieldsAndAcceptMissingGoal AgentMode codex.app_server.request_conformance thread_start,thread_resume,thread_goal,request_shape protocol_contract root_swiftpm routine 5 Thread start and resume omit undeclared effort and path fields, missing goals remain nil, and blocked and usage-limited goal statuses decode exactly. Schema drift could send rejected thread parameters or mis-handle missing and terminal goal statuses during Codex session startup or resume. 2.397000 test_case retain 0 Codex app-server schema gate boundary coverage. +root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testProtocolShapeRejectionsPreserveMessageAndAdviseCLIUpdate root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testProtocolShapeRejectionsPreserveMessageAndAdviseCLIUpdate AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 4 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.000500 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. +root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testResumeRequiresThreadIDAndIncludesOptionalPath root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testResumeRequiresThreadIDAndIncludesOptionalPath AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 1 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.228000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testResumeWithoutPathSendsRequiredThreadIDOnly root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testResumeWithoutPathSendsRequiredThreadIDOnly AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 1 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.244000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testSafeManagedMCPOverridesSuppressThirdPartyServers root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testSafeManagedMCPOverridesSuppressThirdPartyServers AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 60 root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testUnrelatedRequestFailureDoesNotAddCLIUpdateHint root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testUnrelatedRequestFailureDoesNotAddCLIUpdateHint AgentMode codex.app_server.request_conformance initialize,resume,json_rpc protocol_contract root_swiftpm routine 1 Request frame shape or compatibility error text matches the modern app-server contract. Malformed initialization or resume requests could prevent Codex sessions from starting. 0.000000 test_case retain 0 Codex app-server modernization Items 1–3 integration coverage. -root/RepoPromptTests.CodexNativeSessionControllerGoalConfigTests/testWorktreePathSeparationPreservesStartResumeTurnAndWorkspaceWriteProtocol root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerGoalConfigTests.swift RepoPromptTests.CodexNativeSessionControllerGoalConfigTests testWorktreePathSeparationPreservesStartResumeTurnAndWorkspaceWriteProtocol AgentMode codex.app_server.worktree_path_separation process_launch_cwd,thread_start,thread_resume,turn_start,workspace_write protocol_contract root_swiftpm routine 2 fake_codex_app_server A fake app-server records the logical-root process cwd while fresh and resumed threads, turns, and workspace-write roots carry the distinct worktree root with their protocol results intact. Recoupling process and execution directories could reintroduce worktree-only startup failures or run Codex requests and writes against the logical checkout. subprocess test_case retain 0 Cross-layer worktree path-separation coverage for fresh and resumed sessions. root/RepoPromptTests.CodexNativeSessionControllerInterruptTests/testActiveTurnMismatchParserMatrix root Tests/RepoPromptTests/AI/CodexNativeSessionControllerInterruptTests.swift RepoPromptTests.CodexNativeSessionControllerInterruptTests testActiveTurnMismatchParserMatrix AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.CodexNativeSessionControllerInterruptTests/testResolvedInterruptTurnIDMatrix root Tests/RepoPromptTests/AI/CodexNativeSessionControllerInterruptTests.swift RepoPromptTests.CodexNativeSessionControllerInterruptTests testResolvedInterruptTurnIDMatrix AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 22 root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testCancellationReconciliationInterruptsUniqueSnapshotTurnWithoutPromotingIt root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testCancellationReconciliationInterruptsUniqueSnapshotTurnWithoutPromotingIt AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 229 @@ -1208,18 +1159,9 @@ root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testInterrupt root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testJSONRPCFailureParserPreservesMethodCodeMessageAndData root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testJSONRPCFailureParserPreservesMethodCodeMessageAndData AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 253 root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testStrictMessageFallbackMapsCurrentMismatchShapeWithoutPromotingActualID root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testStrictMessageFallbackMapsCurrentMismatchShapeWithoutPromotingActualID AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 167 root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testStructuredSteerErrorsMapWithoutLosingJSONRPCPayload root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testStructuredSteerErrorsMapWithoutLosingJSONRPCPayload AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 89 -root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testTurnStartPreservesImageEntriesWhenAddingTextPayload root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testTurnStartPreservesImageEntriesWhenAddingTextPayload AI codex.app_server.turn_input_payload turn_start,text_elements,image_preservation protocol_contract root_swiftpm routine 1 Turn dispatch preserves image entries and appends a text item with the exact snake_case text_elements field and no legacy camelCase key. Malformed text input can suppress Codex turn/completed and leave Agent Mode sessions hanging indefinitely. 0.000500 test_case retain 0 PR #450 Codex app-server turn payload key regression. root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testTurnStartReturnsProvisionalReceiptWithoutInstallingActiveIdentity root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testTurnStartReturnsProvisionalReceiptWithoutInstallingActiveIdentity AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testTurnSteerAcceptedMismatchReturnsAcceptedReceiptWithoutResend root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testTurnSteerAcceptedMismatchReturnsAcceptedReceiptWithoutResend AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 68 root/RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests/testTurnSteerUsesExactExpectedIDAndOmitsStartOnlySettings root Tests/RepoPromptTests/AI/CodexNativeSessionControllerTurnDispatchTests.swift RepoPromptTests.CodexNativeSessionControllerTurnDispatchTests testTurnSteerUsesExactExpectedIDAndOmitsStartOnlySettings AI unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 35 -root/RepoPromptTests.CodexRuntimeAuthorityTests/testBundledRuntimeResolvesIntelPackageIndependently root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testBundledRuntimeResolvesIntelPackageIndependently AI codex.runtime_authority.intel_selection bundled_runtime,x86_64,architecture deterministic_filesystem_integration root_swiftpm routine 1 An x86_64 request resolves only the x86_64 target package and provenance. A universal public artifact could ship both targets but still execute an unusable arm64 runtime on Intel. 0.005000 filesystem;temp_directory test_case retain 0 PR3 Intel runtime selection regression. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testBundledRuntimeResolvesRequestedArchitectureAndOwnedState root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testBundledRuntimeResolvesRequestedArchitectureAndOwnedState AI codex.runtime_authority.bundled_state bundled_runtime,architecture,state_isolation,provenance deterministic_filesystem_integration root_swiftpm routine 3 The selected arm64 package, owned CODEX_HOME/CODEX_SQLITE_HOME directories, and redacted bundled provenance/version are exact. Codex could select the wrong packaged runtime, leak into user state, or expose sensitive state paths in diagnostics. 0.010000 filesystem;temp_directory test_case retain 0 PR3 bundled runtime authority and isolated-state contract. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testCodexPreflightUsesCapturedLoginShellOverrideInsteadOfInheritedAppEnvironment root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testCodexPreflightUsesCapturedLoginShellOverrideInsteadOfInheritedAppEnvironment AI codex.runtime_authority.captured_shell_override captured_login_shell,external_override,trace_redaction,exec_environment deterministic_filesystem_integration root_swiftpm routine 1 Preflight selects the valid shell-only absolute override instead of an incompatible inherited-app value, keeps exported display text path-redacted, and builds exec process configuration with managed CODEX_HOME/CODEX_SQLITE_HOME. Native or exec Codex could ignore the authoritative captured shell snapshot, expose a private override path, or launch against user-managed state. filesystem;temp_directory;subprocess test_case retain 0 PR3 missing ledger reconciliation plus captured-shell runtime and exec-environment contract. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testExplicitExternalOverrideIsAbsoluteVersionGatedAndObservable root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testExplicitExternalOverrideIsAbsoluteVersionGatedAndObservable AI codex.runtime_authority.external_override_policy external_override,absolute_path,app_server_floor,diagnostics,version_cache deterministic_filesystem_integration root_swiftpm routine 7 A 0.145.0 absolute override resolves with redacted provenance; 0.144.6, relative, and missing overrides return exact typed failures; identity-bound successful and failed probes are reused, and a slow invalid probe does not hold the global cache lock. An explicit override could violate the app-server contract, drift through PATH, expose paths, or repeatedly serialize callers behind a bad version probe. 0.010000 filesystem;temp_directory;subprocess test_case retain 0 PR3 explicit override compatibility, diagnostics, and bounded probe-cache contract. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testManagedAuthGuidanceUsesRepoPromptOwnedLoginFlow root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testManagedAuthGuidanceUsesRepoPromptOwnedLoginFlow AI codex.runtime_authority.managed_auth_guidance managed_runtime,authentication,user_guidance deterministic_configuration root_swiftpm routine 1 Managed authentication guidance directs users to RepoPrompt's Login with ChatGPT flow and never to a shell codex login command. Bundled-runtime users could be sent to an unrelated installed CLI and authenticate the wrong state home. test_case retain 0 PR3 missing ledger reconciliation for managed-runtime authentication guidance. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testMissingOrCorruptBundledRuntimeFailsClosedWithoutPATHFallback root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testMissingOrCorruptBundledRuntimeFailsClosedWithoutPATHFallback AI codex.runtime_authority.fail_closed bundled_runtime,missing,corrupt_metadata,path_isolation deterministic_filesystem_integration root_swiftpm routine 2 Missing and corrupt bundled packages return typed failures even when PATH contains arbitrary candidates. RepoPrompt could silently execute an unverified PATH binary when its owned runtime is damaged. 0.005000 filesystem;temp_directory test_case retain 0 PR3 fail-closed bundled runtime regression. -root/RepoPromptTests.CodexRuntimeAuthorityTests/testOverrideEnvironmentIsTheOnlyFallbackWhenBundleIsMissing root Tests/RepoPromptTests/AI/CodexRuntimeAuthorityTests.swift RepoPromptTests.CodexRuntimeAuthorityTests testOverrideEnvironmentIsTheOnlyFallbackWhenBundleIsMissing AI codex.runtime_authority.explicit_environment_override external_override,environment,no_path_fallback deterministic_filesystem_integration root_swiftpm routine 1 Only REPOPROMPT_CODEX_EXECUTABLE selects a compatible external runtime when bundle resources are unavailable. Runtime selection could silently depend on arbitrary shell PATH state. 0.005000 filesystem;temp_directory test_case retain 0 PR3 sole explicit external override contract. -root/RepoPromptTests.CodexRuntimeLaunchFailureClassificationTests/testSentinelClassifierAcceptsPrefixedMessagesAndRejectsRewrittenGuidance root Tests/RepoPromptTests/AI/CodexRuntimeLaunchFailureClassificationTests.swift RepoPromptTests.CodexRuntimeLaunchFailureClassificationTests testSentinelClassifierAcceptsPrefixedMessagesAndRejectsRewrittenGuidance AI codex.runtime_launch_failure.sentinel_classifier_contract sentinel_prefix,whitespace_tolerance,rewritten_guidance_rejection deterministic_unit root_swiftpm routine 5 isCodexExecutableUnavailableMessage accepts only messages leading with the RepoPrompt could not start Codex: sentinel, tolerating leading whitespace and rejecting rewritten friendly guidance. Widened or drifted sentinel matching could misroute Codex failure phases between executableUnavailable and failed. 0.001000 test_case retain 0 Sentry PR #612 finding: sentinel-classified post-resolution launch failures. root/RepoPromptTests.CodexSteerAckTrackerTests/testAcceptedCodexAckAfterRunReplacementDoesNotWakeReplacementWaiters root Tests/RepoPromptTests/AgentMode/Codex/CodexSteerAckTrackerTests.swift RepoPromptTests.CodexSteerAckTrackerTests testAcceptedCodexAckAfterRunReplacementDoesNotWakeReplacementWaiters AgentMode codex.mcp_steer_ack_replacement_guard agent_run.wait,codex,provider_ack,run_replacement wait_wake_regression root_swiftpm routine 1 A gated Codex provider ack accepted after local run/controller replacement returns accepted delivery without releasing replacement waiters as steering_requested. Late provider acceptance could wake or signal the replacement/current run and interrupt an unrelated waiter. test_case retain 0 Final Oracle review P1 active Codex waiter identity guard. root/RepoPromptTests.CodexSteerAckTrackerTests/testActiveMCPWaiterIsNotInterruptedBeforeCodexProviderAck root Tests/RepoPromptTests/AgentMode/Codex/CodexSteerAckTrackerTests.swift RepoPromptTests.CodexSteerAckTrackerTests testActiveMCPWaiterIsNotInterruptedBeforeCodexProviderAck AgentMode codex.mcp_steer_ack_order agent_run.wait,codex,provider_ack wait_wake_regression root_swiftpm routine 1 An existing MCP wait remains registered while Codex steer is pending and wakes with steering_requested only after provider acceptance. Waiters could be unlatched as interrupted_by_steering before Codex accepts the steer, losing the active turn. test_case retain 0 Steer crash fix item 3 active Codex waiter wake semantics. root/RepoPromptTests.CodexSteerAckTrackerTests/testCancellationUnblocksDispatchAndTombstonesAttempt root Tests/RepoPromptTests/AgentMode/Codex/CodexSteerAckTrackerTests.swift RepoPromptTests.CodexSteerAckTrackerTests testCancellationUnblocksDispatchAndTombstonesAttempt AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 49 @@ -1245,17 +1187,15 @@ root/RepoPromptTests.ContextBuilderFollowUpFinalizationMonitorTests/testOracleWa root/RepoPromptTests.ContextBuilderFollowUpFinalizationMonitorTests/testStalledFakeQueryTimesOutWithAttributedSubphaseAndCancelsStream root Tests/RepoPromptTests/ContextBuilder/ContextBuilderFollowUpFinalizationMonitorTests.swift RepoPromptTests.ContextBuilderFollowUpFinalizationMonitorTests testStalledFakeQueryTimesOutWithAttributedSubphaseAndCancelsStream ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 55 root/RepoPromptTests.ContextBuilderFollowUpFinalizationMonitorTests/testTimeoutOutcomeWinsWhenCancellationAlsoCompletesFinalization root Tests/RepoPromptTests/ContextBuilder/ContextBuilderFollowUpFinalizationMonitorTests.swift RepoPromptTests.ContextBuilderFollowUpFinalizationMonitorTests testTimeoutOutcomeWinsWhenCancellationAlsoCompletesFinalization ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 94 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testCommitAndClearTabContextReportsPersistenceSubphasesInOrder root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testCommitAndClearTabContextReportsPersistenceSubphasesInOrder ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.190000 unreviewed retain_pending_review 0 initial census source line 371 -root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testContextBuilderToolProviderReportsPhasesAndSkipsSelectionIngressBarrier root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testContextBuilderToolProviderReportsPhasesAndSkipsSelectionIngressBarrier ContextBuilder context_builder.progress.selection_rendering_fast_path standard_mcp_progress,selection_rendering,ingress_barrier,stage_envelope production_lineage_integration root_swiftpm routine 2 ContextBuilderImmediateCompletionProvider The registered provider path orders discovery finalization before selection rendering and generation, performs zero scoped ingress-barrier work while rendering the committed snapshot, and proves an awaitPending control still performs barrier work. Selection reply rendering could remain invisible or reintroduce an unbounded ingress join even though the Context Builder snapshot already owns authority. async_tasks window_state;routing_waiter test_case+provider_cleanup retain 0 Production phase envelope plus structural fast-success ingress proof. +root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testContextBuilderToolProviderReportsDiscoveryAndGenerationStageEnvelope root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testContextBuilderToolProviderReportsDiscoveryAndGenerationStageEnvelope ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.154000 unreviewed retain_pending_review 0 initial census source line 266 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testContextBuilderToolProviderUsesCallerPromptWithoutMutatingDiscoveryFallback root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testContextBuilderToolProviderUsesCallerPromptWithoutMutatingDiscoveryFallback ContextBuilder context_builder.typed_prompt.request_local_handoff prompt_authority,state_preservation,hidden_guidance integration_regression root_swiftpm routine 1 Injected follow-up and returned prompt contain caller task/context without discovery guidance or discovery output while the canonical tab retains its committed fallback. Typed MCP responses from empty tabs could fail, leak discovery-only guidance, execute discovery prose, or overwrite canonical tab state. 0.524000 singleton_window_registry window_state retain 0 request-local typed prompt handoff across provider execution and result packaging root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testDeferredRunMappingSurvivesCommitUntilCallerCleanup root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testDeferredRunMappingSurvivesCommitUntilCallerCleanup ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.048000 unreviewed retain_pending_review 0 initial census source line 425 -root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testPhaseCatalogCoversExpectedDiscoveryAndGenerationSequence root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testPhaseCatalogCoversExpectedDiscoveryAndGenerationSequence ContextBuilder context_builder.progress.phase_catalog provider_startup,child_connection,routing_timeout,selection_rendering,review_authorization,stage_mapping deterministic_catalog_contract root_swiftpm routine 1 The catalog includes the neutral selection-reply rendering phase and review authorization phase with exact processing/generating stage placement alongside all discovery and generation phases. A phase could disappear, move to the wrong top-level stage, or lose its exact wire identifier. 0.000000 method_local_values retain 0 Exact progress phase catalog including post-discovery rendering and review authorization. -root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testPostCommitMCPCancellationReturnsCommittedPromptAndSelection root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testPostCommitMCPCancellationReturnsCommittedPromptAndSelection ContextBuilder context_builder.cancellation.post_commit_snapshot committed_snapshot,cancellation,response_suppression integration_regression root_swiftpm routine 1 ContextBuilderImmediateCompletionProvider A deterministic post-commit gate cancels the active run and proves the result retains the committed prompt and selection while suppressing follow-up generation. Cancellation after commit could regress to mutable or initial state, or incorrectly start a follow-up response. async_tasks window_state test_case+provider_cleanup retain 0 PR #588 committed-snapshot cancellation contract reconciled into the ledger. -root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testPreCommitMCPCancellationRendersInitialSnapshotWithoutIngressBarrier root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testPreCommitMCPCancellationRendersInitialSnapshotWithoutIngressBarrier ContextBuilder context_builder.cancellation.pre_commit_initial_snapshot initial_snapshot,cancellation,ingress_barrier,response_suppression integration_regression root_swiftpm routine 1 ContextBuilderImmediateCompletionProvider A deterministic provider-event gate cancels before commit and proves the informational result renders the immutable initial prompt and selection with zero scoped ingress-barrier work. Pre-commit cancellation could consult mutable active state, lose initial context, or join unrelated later filesystem ingress. async_tasks window_state test_case+provider_cleanup retain 0 No polling or sleeps; captured initial snapshot and structural barrier counters are authoritative. +root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testPhaseCatalogCoversExpectedDiscoveryAndGenerationSequence root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testPhaseCatalogCoversExpectedDiscoveryAndGenerationSequence ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testResponseDispositionRoutesRequestedModesAndFailsClosedOnMissingFollowUpState root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testResponseDispositionRoutesRequestedModesAndFailsClosedOnMissingFollowUpState ContextBuilder completion_routing focused root_swiftpm routine 9 regression retain 0.000000 stable retain 0 committed snapshot response routing and fail-closed follow-up state root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testRunMCPPlanOrQuestionReportsProductionPhaseSequenceThroughFinalization root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testRunMCPPlanOrQuestionReportsProductionPhaseSequenceThroughFinalization ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.229000 unreviewed retain_pending_review 0 initial census source line 166 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testSoftStageBoundEmitsOnceWithoutFailingTimeline root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testSoftStageBoundEmitsOnceWithoutFailingTimeline ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 139 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testSuspendingSinkPreservesEveryTimedTransitionWhenItReentersTimeline root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testSuspendingSinkPreservesEveryTimedTransitionWhenItReentersTimeline ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 66 -root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testTimelineEmitsTimedTransitionsAndUsesCurrentSubphaseForHeartbeat root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testTimelineEmitsTimedTransitionsAndUsesCurrentSubphaseForHeartbeat ContextBuilder context_builder.progress.post_discovery_heartbeat selection_rendering,review_authorization,ordered_completion,heartbeat deterministic_timeline_contract root_swiftpm routine 1 Synthetic clock assertions prove selection rendering completes before review authorization and each phase supplies the current processing/generating heartbeat identity. Heartbeats could continue reporting stale discovery or generic generation while post-discovery work is stalled. 0.000500 method_local_values retain 0 No wall-clock waits; exact synthetic elapsed-time and phase identity assertions. +root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testTimelineEmitsTimedTransitionsAndUsesCurrentSubphaseForHeartbeat root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testTimelineEmitsTimedTransitionsAndUsesCurrentSubphaseForHeartbeat ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 28 root/RepoPromptTests.ContextBuilderMCPProgressTimelineTests/testTypedPromptResolverEnforcesPrecedenceAndReservedMarkupGrammar root Tests/RepoPromptTests/ContextBuilder/ContextBuilderMCPProgressTimelineTests.swift RepoPromptTests.ContextBuilderMCPProgressTimelineTests testTypedPromptResolverEnforcesPrecedenceAndReservedMarkupGrammar ContextBuilder context_builder.typed_prompt.resolution prompt_precedence,lazy_sanitization,reserved_markup parser_boundary root_swiftpm routine 16 Table assertions prove committed-prompt precedence, exact lowercase sibling removal, quote-aware attribute rejection, malformed reserved-markup rejection, and caller fallback into typed generation. Malformed or hidden discovery guidance could reach typed generation, or valid committed prompts could be rejected. 0.001000 test_case retain 0 request-local prompt authority and fail-closed reserved-markup grammar root/RepoPromptTests.ContextBuilderModelStartupSelectionTests/testCachedCLIFlagIsNotReadyUntilCurrentProcessVerification root Tests/RepoPromptTests/ContextBuilder/ContextBuilderModelStartupSelectionTests.swift RepoPromptTests.ContextBuilderModelStartupSelectionTests testCachedCLIFlagIsNotReadyUntilCurrentProcessVerification ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 307 root/RepoPromptTests.ContextBuilderModelStartupSelectionTests/testCursorStartupReadinessJoinsRunningPollWithoutDynamicMetadata root Tests/RepoPromptTests/ContextBuilder/ContextBuilderModelStartupSelectionTests.swift RepoPromptTests.ContextBuilderModelStartupSelectionTests testCursorStartupReadinessJoinsRunningPollWithoutDynamicMetadata ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 259 @@ -1270,14 +1210,12 @@ root/RepoPromptTests.ContextBuilderModelStartupSelectionTests/testUnavailablePer root/RepoPromptTests.ContextBuilderModelStartupSelectionTests/testUnconfiguredClaudeCodeCannotBecomeEffectiveStartupSelection root Tests/RepoPromptTests/ContextBuilder/ContextBuilderModelStartupSelectionTests.swift RepoPromptTests.ContextBuilderModelStartupSelectionTests testUnconfiguredClaudeCodeCannotBecomeEffectiveStartupSelection ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 48 root/RepoPromptTests.ContextBuilderModelStartupSelectionTests/testValidPersistedSelectionSurvivesStoreReloadAndStartupResolution root Tests/RepoPromptTests/ContextBuilder/ContextBuilderModelStartupSelectionTests.swift RepoPromptTests.ContextBuilderModelStartupSelectionTests testValidPersistedSelectionSurvivesStoreReloadAndStartupResolution ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.003500 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.ContextBuilderNestedMCPFailureTests/testNestedReadHandlerCompletesThenExactResponseDeliveryFailureSettlesOuterContextBuilder root Tests/RepoPromptTests/ContextBuilder/ContextBuilderNestedMCPFailureTests.swift RepoPromptTests.ContextBuilderNestedMCPFailureTests testNestedReadHandlerCompletesThenExactResponseDeliveryFailureSettlesOuterContextBuilder ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.743000 unreviewed retain_pending_review 0 initial census source line 10 -root/RepoPromptTests.ContextBuilderNestedMCPFailureTests/testNestedReadHandlerNeverReturnsAndDetachedTimeoutSettlesOuterContextBuilder root Tests/RepoPromptTests/ContextBuilder/ContextBuilderNestedMCPFailureTests.swift RepoPromptTests.ContextBuilderNestedMCPFailureTests testNestedReadHandlerNeverReturnsAndDetachedTimeoutSettlesOuterContextBuilder ContextBuilder context_builder.nested_read_timeout_detached_settlement nested_mcp,read_file,watchdog_timeout,detached_settlement,connection_liveness async_lifecycle root_swiftpm routine 1 PersistentMCPTestFixture,MCPExecutionIgnoringCancellationGate,ExecutionWatchdogManualClock A stalled nested read_file returns the outer Context Builder failure after watchdog detachment, leaves the nested connection non-terminal, and records detached settlement after the handler is released. Regressing to force-disconnect would unnecessarily kill the nested MCP connection, while failing to drain detached work could leak settlement state across later tool calls. 0.664000 mcp_server,manual_clock MCPSharedServerTestLease test_case+fixture_cleanup retain 0 Renamed testNestedReadHandlerNeverReturnsAndWatchdogDisconnectSettlesOuterContextBuilder -> testNestedReadHandlerNeverReturnsAndDetachedTimeoutSettlesOuterContextBuilder for PR #644 detach-and-settle semantics. +root/RepoPromptTests.ContextBuilderNestedMCPFailureTests/testNestedReadHandlerNeverReturnsAndWatchdogDisconnectSettlesOuterContextBuilder root Tests/RepoPromptTests/ContextBuilder/ContextBuilderNestedMCPFailureTests.swift RepoPromptTests.ContextBuilderNestedMCPFailureTests testNestedReadHandlerNeverReturnsAndWatchdogDisconnectSettlesOuterContextBuilder ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.664000 unreviewed retain_pending_review 0 initial census source line 75 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testLogicalReleaseAdmitsSuccessorAndRejectsOldEvents root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testLogicalReleaseAdmitsSuccessorAndRejectsOldEvents ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 333 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testMCPRoutingFailureAfterImmediateStreamReturnCleansBootstrapAndAllowsImmediateRetry root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testMCPRoutingFailureAfterImmediateStreamReturnCleansBootstrapAndAllowsImmediateRetry ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.285500 unreviewed retain_pending_review 0 initial census source line 598 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testMissingCommitOwnershipDoesNotRequestTermination root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testMissingCommitOwnershipDoesNotRequestTermination ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 173 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testPendingTeardownDoesNotRetainActiveRunSlot root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testPendingTeardownDoesNotRetainActiveRunSlot ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 354 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testProductionMCPCancellationResumesBeforeTeardownAndRejectsLateProviderEvent root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testProductionMCPCancellationResumesBeforeTeardownAndRejectsLateProviderEvent ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.148000 unreviewed retain_pending_review 0 initial census source line 391 -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testRouteSettlementCoordinatorBoundsBufferedPayloadsAndEvents root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testRouteSettlementCoordinatorBoundsBufferedPayloadsAndEvents ContextBuilder context_builder.route_settlement.bounded_pre_route_buffer pre_route_buffer,event_count,string_payload,drop_diagnostics deterministic_unit root_swiftpm routine 5 ContextBuilderRouteSettlementCoordinator,AIStreamResult Content payload trimming preserves compact lifecycle diagnostics; redundant progress is coalesced; protected-only tool/error/result streams retain at most the hard count cap; an oversized tool argument is dropped under the total string-payload budget with aggregate drop counts; and an oversized type discriminator is evicted and accounted at the zero-character limit. Pre-route provider events could grow without bound or diagnostics could retain oversized non-content payloads or type discriminators while reporting incomplete drop totals. test_case retain 0 PR #592 bounded pre-route coordinator regression; scenarios extracted from unrelated terminal-claim coverage. -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testRouteSettlementCoordinatorClaimsFirstSettlement root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testRouteSettlementCoordinatorClaimsFirstSettlement ContextBuilder context_builder.route_settlement.first_terminal_claim routed_first,provider_terminal_first,exactly_once deterministic_unit root_swiftpm routine 2 ContextBuilderRouteSettlementCoordinator Routed-first and provider-terminal-first orderings each settle exactly once and reject the later competing terminal candidate. A late competing route or provider completion could overwrite the coordinator's first authoritative settlement. test_case retain 0 PR #592 route-settlement scenarios extracted from unrelated terminal-claim coverage. root/RepoPromptTests.ContextBuilderRunLifecycleTests/testRealConnectionCleanupCannotEraseContextBeforeCommit root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testRealConnectionCleanupCannotEraseContextBeforeCommit ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.089000 unreviewed retain_pending_review 0 initial census source line 202 root/RepoPromptTests.ContextBuilderRunLifecycleTests/testStaleRunRetirementStillDisposesProviderAndCancelsExecution root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testStaleRunRetirementStillDisposesProviderAndCancelsExecution ContextBuilder context_builder.run_lifecycle.stale_retirement_teardown stale_run,provider_disposal,execution_cancellation,teardown_completion deterministic_lifecycle_integration root_swiftpm routine 1 ControllableLifecycleTestProvider,LifecycleTestGate Retiring a stale run disposes its provider exactly once, cancels and joins the execution task, and records terminal teardown completion. Stale runs could leak provider or execution work, or never reach terminal teardown after losing active ownership. window_composition;async_tasks GlobalSettingsStore.mcpAutoStart WindowStateComposition+defer retain 0 Upstream test added by 8cc9f312; PR #275 rebase ledger reconciliation. root/RepoPromptTests.ContextBuilderRunLifecycleTests/testSuccessfulCommitPrecedesChildTerminationAndCleanupWaitsForJoin root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testSuccessfulCommitPrecedesChildTerminationAndCleanupWaitsForJoin ContextBuilder unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 54 @@ -1304,7 +1242,7 @@ root/RepoPromptTests.ContextBuilderWorkspaceContextTests/testResolveWithoutBindi root/RepoPromptTests.ContextBuilderWorkspaceContextTests/testTwoRootUnboundSliceElectsSelectedRepositoryAndIgnoresCrossRootAutoCodemap root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorkspaceContextTests.swift RepoPromptTests.ContextBuilderWorkspaceContextTests testTwoRootUnboundSliceElectsSelectedRepositoryAndIgnoresCrossRootAutoCodemap ContextBuilder context_builder.review_target.two_root_election multi_root,slice_selection,auto_codemap_exclusion,selection_revision,final_validation,root_generation focused_filesystem_security_integration root_swiftpm routine 6 ReviewGitRepositoryFixture,WorkspaceFileContextStore Classic-first root ordering still elects the CE checkout owning the frozen slice, ignores Classic auto-codemaps, transports the target/revision, rejects final cross-repository selection, and detects root reload. Context Builder could silently redirect review authority to an unrelated loaded root or accept stale checkout ownership. 1.287500 git_subprocess;filesystem;workspace_store per_test_temporary_repository_cleanup retain 0 Review-routing frozen target election regression root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testAgentModeContextBuilderFailsClosedBeforeProviderCreationWhenWorktreeIsUnavailable root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testAgentModeContextBuilderFailsClosedBeforeProviderCreationWhenWorktreeIsUnavailable ContextBuilder context_builder.worktree_binding.unavailable_fail_closed agent_mode,worktree_binding,unavailable_worktree,fail_closed,provider_not_created,path_redaction production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture,ContextBuilderWorktreeProbeProvider An Agent Context Builder request whose frozen worktree binding points at a missing checkout fails before provider creation, redacts the physical missing-worktree path, and does not fall back to canonical workspace content. Unavailable Agent worktree bindings could leak local paths, invoke the provider with stale canonical context, or review the wrong checkout. 0.305500 filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 XCTest optimization ledger metadata audit for touched ContextBuilder worktree fail-closed row; executable ID and scenario count unchanged. root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testAgentModeContextBuilderUsesFrozenWorktreeAcrossNestedToolsAccountingAndFollowUps root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testAgentModeContextBuilderUsesFrozenWorktreeAcrossNestedToolsAccountingAndFollowUps ContextBuilder context_builder.worktree_binding.nested_tools_followups agent_mode,worktree_binding,nested_tools,token_accounting,follow_up,artifact_publication,no_canonical_leak production_shaped_mcp_transport_integration root_swiftpm routine 4 PersistentMCPTestFixture,ReviewGitRepositoryFixture,ContextBuilderWorktreeProbeProvider A frozen Agent worktree selection routes nested tree/read/search calls, token-accounting context, selected Git artifacts, and follow-up packaging through the worktree while preserving logical paths and preventing canonical checkout leakage. Nested Context Builder tools or follow-up review packaging could silently use the canonical checkout, leak physical worktree paths, or publish artifacts from the wrong repository state. git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 XCTest optimization ledger metadata audit for touched routine-vs-strict codemap row; executable ID unchanged and codemap E2E remains opt-in. -root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testAgentModeEmptyInitialSelectionDefersAndRoutesWithoutExplicitContext root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testAgentModeEmptyInitialSelectionDefersAndRoutesWithoutExplicitContext ContextBuilder context_builder.review_target.deferred_agent_route_revision_fences agent_mode,no_explicit_context,empty_initial,worktree_only,deferred_election,selection_rendering,review_authorization,phase_progress,pre_revision_fence,post_revision_fence,oracle_noninvocation,parent_selected_git,artifact_publication,captured_selection production_shaped_mcp_transport_integration root_swiftpm routine 5 PersistentMCPTestFixture,ReviewGitRepositoryFixture,ContextBuilderWorktreeProbeProvider A run-scoped Agent request without context_id promotes an empty selection to exact worktree-only final authority, emits ordered discovery-finalization, selection-rendering, review-authorization, and generation progress, then direct parent selected-scope Git publishes that worktree diff while deterministic authorization mutations fail before Oracle invocation. Implicit Agent routing, stale snapshots, revision races, or unattributed authorization work could review or publish the wrong committed selection or hide the phase where review stalls. 63.227500 git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Existing five scenarios retained; the successful deferred-review scenario now also pins continuous post-discovery phase order. +root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testAgentModeEmptyInitialSelectionDefersAndRoutesWithoutExplicitContext root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testAgentModeEmptyInitialSelectionDefersAndRoutesWithoutExplicitContext ContextBuilder context_builder.review_target.deferred_agent_route_revision_fences agent_mode,no_explicit_context,empty_initial,worktree_only,deferred_election,pre_revision_fence,post_revision_fence,oracle_noninvocation,parent_selected_git,artifact_publication,captured_selection production_shaped_mcp_transport_integration root_swiftpm routine 5 PersistentMCPTestFixture,ReviewGitRepositoryFixture,ContextBuilderWorktreeProbeProvider A run-scoped Agent request without context_id promotes an empty selection to an exact worktree-only final authorization, then direct parent selected-scope Git publishes that worktree diff without a selection refresh, while deterministic mutations before and after authorization fail before Oracle invocation. Implicit Agent routing, a stale parent run snapshot, or revision races could review or publish the wrong committed selection or bypass deferred worktree authority. 63.227500 git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Issue #264 Batch 2 routing/fence regression plus fourth-commit selected Git stabilization root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testAgentModeTwoRootContextBuilderImplicitGitPublishesSelectedRepository root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testAgentModeTwoRootContextBuilderImplicitGitPublishesSelectedRepository ContextBuilder context_builder.review_target.nested_git_publication agent_mode,discover_run,multi_root,implicit_git,artifact_publication,selected_artifact,classic_isolation,final_review production_shaped_mcp_transport_integration root_swiftpm routine 4 PersistentMCPTestFixture,ReviewGitRepositoryFixture,ContextBuilderWorktreeProbeProvider An unbound two-root Agent Context Builder child omits repo_root yet publishes and auto-selects only the CE checkout artifact, then final review uses that patch without Classic leakage or automatic fallback. Ambient root order could publish an authoritative Classic artifact despite an all-CE frozen selection. git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Review-routing live-shaped nested Git regression root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testNonAgentContextBuilderKeepsCanonicalWorkspaceBehavior root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testNonAgentContextBuilderKeepsCanonicalWorkspaceBehavior ContextBuilder context_builder.non_agent.canonical_workspace_review non_agent,canonical_workspace,explicit_context,selected_git_artifacts,follow_up,automatic_fallback_suppressed,no_worktree_binding production_shaped_mcp_transport_integration root_swiftpm routine 4 PersistentMCPTestFixture,ReviewGitRepositoryFixture,ContextBuilderWorktreeProbeProvider A non-Agent Context Builder review bound to the visible canonical tab keeps canonical workspace routing, publishes selected Git artifacts for that checkout, suppresses automatic fallback, and packages the follow-up with the persisted source selection plus MAP and patch artifacts. Non-Agent reviews could inherit Agent worktree binding behavior, lose canonical selected-artifact authority, or replace the explicitly published diff with automatic fallback context. 1.648500 git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 XCTest optimization ledger metadata audit for touched non-Agent canonical behavior row; executable ID and scenario count unchanged. root/RepoPromptTests.CursorACPLaunchResolverTests/testAbsoluteConfiguredPathIgnoresDecoyCursorAgentEarlierInPath root Tests/RepoPromptTests/AgentMode/CursorACPLaunchResolverTests.swift RepoPromptTests.CursorACPLaunchResolverTests testAbsoluteConfiguredPathIgnoresDecoyCursorAgentEarlierInPath AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 409 @@ -1379,22 +1317,6 @@ root/RepoPromptTests.DurableArtifactStoreTests/testSecurityRejectsModeHardlinkSy root/RepoPromptTests.DurableArtifactStoreTests/testStreamingPublicationHasNoEntryCountCapAndValidatesAuthenticatedExactEOF root Tests/RepoPromptTests/Persistence/DurableArtifacts/DurableArtifactStoreTests.swift RepoPromptTests.DurableArtifactStoreTests testStreamingPublicationHasNoEntryCountCapAndValidatesAuthenticatedExactEOF Persistence/DurableArtifacts durable_artifacts.streaming_publication_has_no_entry_count_cap_and_validates_authenticated_exact_e_o_f durable_artifacts,filesystem integration infrastructure routine 20002 DurableArtifactTestSupport Exact XCTest assertions over durable bytes, inode identity, authenticated decode, lock outcome, CAS result, or GC report. Regression could expose partial or attacker-controlled durable state, split lock authority, or delete a replacement inode. 0.285000 filesystem temporary_directory test_case retain 0 Slice 1 durable substrate; ledger insertion deferred until serving integration settles. root/RepoPromptTests.DurableArtifactStoreTests/testUnsortedAndDuplicateRecordsFailWithoutLeavingTrustedOrWorkFiles root Tests/RepoPromptTests/Persistence/DurableArtifacts/DurableArtifactStoreTests.swift RepoPromptTests.DurableArtifactStoreTests testUnsortedAndDuplicateRecordsFailWithoutLeavingTrustedOrWorkFiles Persistence/DurableArtifacts durable_artifacts.unsorted_and_duplicate_records_fail_without_leaving_trusted_or_work_files durable_artifacts,filesystem integration infrastructure routine 2 DurableArtifactTestSupport Exact XCTest assertions over durable bytes, inode identity, authenticated decode, lock outcome, CAS result, or GC report. Regression could expose partial or attacker-controlled durable state, split lock authority, or delete a replacement inode. 0.004000 filesystem temporary_directory test_case retain 0 Slice 1 durable substrate; ledger insertion deferred until serving integration settles. root/RepoPromptTests.DurableArtifactStoreTests/testValidatedDescriptorPublicationIgnoresTemporaryPathReplacement root Tests/RepoPromptTests/Persistence/DurableArtifacts/DurableArtifactStoreTests.swift RepoPromptTests.DurableArtifactStoreTests testValidatedDescriptorPublicationIgnoresTemporaryPathReplacement Persistence/DurableArtifacts durable_artifacts.validated_descriptor_publication_ignores_temporary_path_replacement durable_artifacts,filesystem integration infrastructure routine 1 DurableArtifactTestSupport Exact XCTest assertions over durable bytes, inode identity, authenticated decode, lock outcome, CAS result, or GC report. Regression could expose partial or attacker-controlled durable state, split lock authority, or delete a replacement inode. 0.006000 filesystem temporary_directory test_case retain 0 Slice 1 durable substrate; ledger insertion deferred until serving integration settles. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testBareProseURLLinksOnlyWhenPolicyEnabled root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testBareProseURLLinksOnlyWhenPolicyEnabled UI/Markdown markdown.compiler.bare_url_policy bare_url,policy,compiler_integration regression root_swiftpm fast 2 The same prose URL is unlinked with the disabled policy and linked with the HTTP/HTTPS policy. Compiler wiring could ignore the caller's bare-URL policy. appkit test_case retain 0 PR #684 rebased PR #70 Markdown integration coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testExplicitMarkdownLinkAtDocumentEndSurvivesBoundarySuppression root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testExplicitMarkdownLinkAtDocumentEndSurvivesBoundarySuppression UI/Markdown markdown.compiler.explicit_link_boundary_preservation explicit_link,boundary_suppression,markdown_raw_link regression root_swiftpm fast 1 An explicit Markdown link at the document boundary keeps its label and raw destination without a bare-URL marker. Boundary suppression could remove authored Markdown links along with incomplete bare links. appkit test_case retain 0 PR #684 rebased PR #70 authored-link boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testExplicitMarkdownLinkStillWorksWhenBareURLPolicyDisabled root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testExplicitMarkdownLinkStillWorksWhenBareURLPolicyDisabled UI/Markdown markdown.compiler.explicit_link_policy_independence explicit_link,bare_url,disabled_policy,markdown_raw_link regression root_swiftpm fast 1 An explicit Markdown link remains linked with its raw destination when bare-URL processing is disabled. Disabling prose URL detection could accidentally disable authored Markdown links. appkit test_case retain 0 PR #684 rebased PR #70 authored-link policy coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testExplicitMarkdownLinkWithURLLabelSurvivesBoundarySuppression root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testExplicitMarkdownLinkWithURLLabelSurvivesBoundarySuppression UI/Markdown markdown.compiler.url_label_explicit_link_preservation explicit_link,url_label,boundary_suppression,markdown_raw_link regression root_swiftpm fast 1 An explicit link whose visible label is itself a URL keeps its authored destination and is not marked as a bare URL. Text-shape detection could mistake a URL label for a generated bare link and suppress it at the boundary. appkit test_case retain 0 PR #684 rebased PR #70 explicit URL-label coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testFencedCodeBlockURLDoesNotBecomeBareLink root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testFencedCodeBlockURLDoesNotBecomeBareLink UI/Markdown markdown.compiler.fenced_code_url_boundary bare_url,fenced_code,prose,syntax_boundary regression root_swiftpm fast 2 A URL in fenced code remains plain while the prose URL outside the fence becomes linked. Markdown compilation could add interactive prose semantics inside code blocks. appkit test_case retain 0 PR #684 rebased PR #70 fenced-code boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testImageGeneratedLinkAtDocumentEndSurvivesBoundarySuppression root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testImageGeneratedLinkAtDocumentEndSurvivesBoundarySuppression UI/Markdown markdown.compiler.image_link_boundary_preservation image_link,boundary_suppression,generated_label regression root_swiftpm fast 1 The compiler-generated image link remains present at the document boundary without a bare-URL marker. Boundary suppression could erase links produced by non-prose Markdown nodes. appkit test_case retain 0 PR #684 rebased PR #70 image-link boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testInlineCodeURLDoesNotBecomeBareLink root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testInlineCodeURLDoesNotBecomeBareLink UI/Markdown markdown.compiler.inline_code_url_boundary bare_url,inline_code,prose,syntax_boundary regression root_swiftpm fast 2 The URL inside inline code remains plain while the adjacent prose URL becomes linked. Bare-link processing could leak into inline code or fail to link ordinary prose in the same document. appkit test_case retain 0 PR #684 rebased PR #70 inline-code boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testMarkdownWebLinkClickFallsThroughToAppKitDefaultOpening root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testMarkdownWebLinkClickFallsThroughToAppKitDefaultOpening UI/Markdown markdown.compiler.web_link_appkit_default_opening bare_url,click_handling,appkit regression root_swiftpm fast 1 A web link produced through the Markdown compiler is not consumed by the coordinator, leaving AppKit to open it. Compiled prose links could render correctly but fail to open when clicked. appkit test_case retain 0 PR #684 rebased PR #70 compiled-link click coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testPreviewBoundarySuppressionRemovesBareURLAtDocumentEnd root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testPreviewBoundarySuppressionRemovesBareURLAtDocumentEnd UI/Markdown markdown.compiler.preview_boundary_suppression bare_url,preview,streaming,boundary,visual_attributes regression root_swiftpm fast 2 A punctuated completed URL stays linked while a URL touching the preview boundary loses its link marker and styling. Streaming Markdown could expose incomplete destinations or stale visual link attributes. appkit test_case retain 0 PR #684 rebased PR #70 preview-boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testPreviewLikeMarkdownProtectsInlineAndFencedCodeURLs root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testPreviewLikeMarkdownProtectsInlineAndFencedCodeURLs UI/Markdown markdown.compiler.preview_code_boundary_matrix bare_url,preview,inline_code,fenced_code,prose regression root_swiftpm fast 3 Preview-like Markdown links only the prose URL while leaving inline-code and fenced-code URLs plain. Combined streaming and syntax-boundary handling could add links inside either code representation. appkit test_case retain 0 PR #684 rebased PR #70 preview syntax-boundary matrix. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testRenderSignatureConfigurationIncludesBareURLPolicy root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testRenderSignatureConfigurationIncludesBareURLPolicy UI/Markdown markdown.render_signature.bare_url_policy bare_url,render_signature,cache,streaming_delta cache_contract root_swiftpm fast 1 Changing only the bare-URL policy changes signature equality, rendering compatibility, and disables append-delta reuse. The render cache could reuse output created under a different URL policy. test_case retain 0 PR #684 rebased PR #70 render-signature policy coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testRenderSignatureConfigurationIncludesBoundarySuppression root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testRenderSignatureConfigurationIncludesBoundarySuppression UI/Markdown markdown.render_signature.boundary_suppression bare_url,boundary_suppression,render_signature,cache,streaming_delta cache_contract root_swiftpm fast 1 Changing only boundary suppression changes signature equality, rendering compatibility, and disables append-delta reuse. The render cache could reuse ordinary prose output for a streaming preview boundary. test_case retain 0 PR #684 rebased PR #70 render-signature boundary coverage. -root/RepoPromptTests.EnhancedMarkdownBareURLTests/testSymbolGeneratedLinkDoesNotReceiveBareURLMarker root Tests/RepoPromptTests/Markdown/EnhancedMarkdownBareURLTests.swift RepoPromptTests.EnhancedMarkdownBareURLTests testSymbolGeneratedLinkDoesNotReceiveBareURLMarker UI/Markdown markdown.compiler.symbol_link_marker_separation symbol_link,bare_url_marker,boundary_suppression regression root_swiftpm fast 1 A parsed symbol link remains linked but does not receive the generated bare-URL marker. Symbol links could be misclassified and suppressed or restyled as prose URLs. appkit test_case retain 0 PR #684 rebased PR #70 symbol-link boundary coverage. -root/RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests/testAdjacentInlineCodeSpansKeepExactEmbeddingRangesAcrossNeutralCharacters root Tests/RepoPromptTests/Markdown/EnhancedMarkdownCompilerBidirectionalTests.swift RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests testAdjacentInlineCodeSpansKeepExactEmbeddingRangesAcrossNeutralCharacters UI/Markdown markdown.inline_code.adjacent_embedding_ranges bidi,inline_code,neutral_characters,utf16_offsets regression root_swiftpm fast 3 Exact backing string and writingDirection attribute ranges for three adjacent inline-code spans separated by neutral characters. Direction attributes could bleed across neutral separators or merge adjacent code-span ranges, changing mixed-bidi display semantics. appkit test_case retain 0 Issue #654 inline-code direction slice. -root/RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests/testInlineCodeEmbeddingCoversExactRangesWithoutChangingRTLParagraphStrings root Tests/RepoPromptTests/Markdown/EnhancedMarkdownCompilerBidirectionalTests.swift RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests testInlineCodeEmbeddingCoversExactRangesWithoutChangingRTLParagraphStrings UI/Markdown markdown.inline_code.ltr_embedding_exact_ranges bidi,inline_code,rtl,utf16_offsets regression root_swiftpm fast 2 Exact backing strings, absence of bidi controls, and exact LTR-embedding ranges for inline code within and at the start of RTL prose. Inline-code direction safety could mutate logical strings, force surrounding RTL prose LTR, or apply an override instead of an embedding. appkit test_case retain 0 Issue #654 inline-code direction slice. -root/RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests/testTableCellSecondPassPreservesInlineCodeEmbeddingAndBackingString root Tests/RepoPromptTests/Markdown/EnhancedMarkdownCompilerBidirectionalTests.swift RepoPromptTests.EnhancedMarkdownCompilerBidirectionalTests testTableCellSecondPassPreservesInlineCodeEmbeddingAndBackingString UI/Markdown markdown.inline_code.table_cell_attribute_preservation bidi,inline_code,table_cell,attributed_string regression root_swiftpm fast 1 Exact compiled table backing string and inline-code writingDirection range after table-cell attribute normalization. Table-cell compilation could silently discard the inline-code embedding while rebuilding attributed cell content. appkit test_case retain 0 Issue #654 inline-code direction slice; does not cover table geometry. root/RepoPromptTests.FileMentionPickerStyleTests/testCompactConfigurationPreservesExistingDefaults root Tests/RepoPromptTests/Mentions/FileMentionPickerStyleTests.swift RepoPromptTests.FileMentionPickerStyleTests testCompactConfigurationPreservesExistingDefaults Mentions unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.FileMentionPickerStyleTests/testExpandedConfigurationUsesRoomierFilePickerValues root Tests/RepoPromptTests/Mentions/FileMentionPickerStyleTests.swift RepoPromptTests.FileMentionPickerStyleTests testExpandedConfigurationUsesRoomierFilePickerValues Mentions unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 16 root/RepoPromptTests.FileMentionPickerStyleTests/testNormalizationDefaultsMissingEmptyAndInvalidRawValuesToCompact root Tests/RepoPromptTests/Mentions/FileMentionPickerStyleTests.swift RepoPromptTests.FileMentionPickerStyleTests testNormalizationDefaultsMissingEmptyAndInvalidRawValuesToCompact Mentions unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 26 @@ -1439,10 +1361,6 @@ root/RepoPromptTests.FileSystemContentLoadingConcurrencyTests/testValidatedRawCo root/RepoPromptTests.FileSystemContentLoadingConcurrencyTests/testValidatedRawContentRejectsMidReadMutation root Tests/RepoPromptTests/Services/FileSystem/FileSystemContentLoadingConcurrencyTests.swift RepoPromptTests.FileSystemContentLoadingConcurrencyTests testValidatedRawContentRejectsMidReadMutation Services filesystem.validated_raw.mutation_fence fingerprint_change,atomic_replacement,descriptor_validation async_concurrency_lifecycle root_swiftpm routine 1 FileSystemContentLoadingTemporaryRootFixture,AsyncGate,AsyncCounter Atomic pathname replacement after the first raw chunk is rejected as fingerprintChanged with no snapshot returned. A mixed or stale buffer could be accepted after a file revision changes during the read. 0.003500 temporary_root,disk_io,async_tasks,file_mutation,cancellation_gate per_test_service+task_join+tearDownWithError retain 0 Phase 2 fail-closed revision fence root/RepoPromptTests.FileSystemContentLoadingConcurrencyTests/testValidatedRawContentRejectsSymlinkRetargetDuringRead root Tests/RepoPromptTests/Services/FileSystem/FileSystemContentLoadingConcurrencyTests.swift RepoPromptTests.FileSystemContentLoadingConcurrencyTests testValidatedRawContentRejectsSymlinkRetargetDuringRead Services filesystem.validated_raw.symlink_retarget no_follow,path_fingerprint,descriptor_identity,canonical_containment async_concurrency_lifecycle root_swiftpm routine 2 FileSystemContentLoadingTemporaryRootFixture,AsyncGate,AsyncCounter Replacing the opened leaf or an intermediate directory with a symlink during the read is rejected by descriptor, pathname, or canonical-containment validation and returns no snapshot. A symlink retarget could bind attacker-controlled or unrelated bytes to an authorized workspace path. 0.007000 temporary_root,disk_io,async_tasks,file_mutation,symlink,cancellation_gate per_test_service+task_join+tearDownWithError retain 0 Phase 2 fail-closed symlink retarget contract root/RepoPromptTests.FileSystemContentLoadingConcurrencyTests/testValidatedRawContentRejectsUnsafeMissingAndOversizedInputs root Tests/RepoPromptTests/Services/FileSystem/FileSystemContentLoadingConcurrencyTests.swift RepoPromptTests.FileSystemContentLoadingConcurrencyTests testValidatedRawContentRejectsUnsafeMissingAndOversizedInputs Services filesystem.validated_raw.authorization_and_bounds traversal,symlink_leaf,out_of_root,missing,oversize filesystem_negative root_swiftpm routine 5 FileSystemContentLoadingTemporaryRootFixture Traversal, symlink leaf, and out-of-root targets are rejected as invalid paths; missing and over-limit sources throw their exact errors. Unsafe, absent, or oversized sources could enter the immutable envelope or cause unbounded memory use. 0.001500 temporary_root,disk_io,symlink,error_paths per_test_service+tearDownWithError retain 0 Phase 2 fail-closed authorization and size contract -root/RepoPromptTests.FileSystemDirentRecordTests/testDecoderRejectsRecordAndNameLengthsOutsideAvailableBytes root Tests/RepoPromptTests/Services/FileSystem/FileSystemDirentRecordTests.swift RepoPromptTests.FileSystemDirentRecordTests testDecoderRejectsRecordAndNameLengthsOutsideAvailableBytes Services filesystem.dirent.record_and_name_bounds d_reclen,d_namlen,truncated_record,oversized_record,fail_closed deterministic_unit root_swiftpm fast 4 SyntheticDirentRecord Records whose declared size disagrees with available bytes, whose name exceeds the record, or whose record falls outside the imported dirent bounds are rejected. Malformed directory metadata could trigger an out-of-bounds read or synthesize a truncated path. bounded_memory test_case retain 0 REPOPROMPT-A9 variable-record boundary regression. -root/RepoPromptTests.FileSystemDirentRecordTests/testGuardPageRecordDecodesWithoutFullDirentRead root Tests/RepoPromptTests/Services/FileSystem/FileSystemDirentRecordTests.swift RepoPromptTests.FileSystemDirentRecordTests testGuardPageRecordDecodesWithoutFullDirentRead Services filesystem.dirent.guard_page_no_overread guard_page,mmap,mprotect,page_boundary,no_full_struct_copy memory_safety_regression root_swiftpm fast 1 DarwinGuardPageDirentRecord A valid variable-length dirent ending at a readable page boundary decodes exactly while the following page remains inaccessible. Copying MemoryLayout.size bytes from a short OS record could cross into an unmapped page and crash. virtual_memory,guard_page test_case+munmap retain 0 REPOPROMPT-A9 page-boundary no-overread regression. -root/RepoPromptTests.FileSystemDirentRecordTests/testVariableLengthRecordDecodesWithoutFullDirentStorage root Tests/RepoPromptTests/Services/FileSystem/FileSystemDirentRecordTests.swift RepoPromptTests.FileSystemDirentRecordTests testVariableLengthRecordDecodesWithoutFullDirentStorage Services filesystem.dirent.variable_record_decode layout_derived_offsets,short_record,exact_name_bytes,d_type deterministic_unit root_swiftpm fast 1 SyntheticDirentRecord A valid record shorter than MemoryLayout.size decodes its exact name bytes and type from layout-derived offsets. Copying the imported full dirent can read beyond the OS-owned variable-length record and crash. bounded_memory test_case retain 0 REPOPROMPT-A9 no-full-struct-copy regression. -root/RepoPromptTests.FileSystemDirentRecordTests/testZeroNameLengthFallbackRequiresTerminatorWithinRecord root Tests/RepoPromptTests/Services/FileSystem/FileSystemDirentRecordTests.swift RepoPromptTests.FileSystemDirentRecordTests testZeroNameLengthFallbackRequiresTerminatorWithinRecord Services filesystem.dirent.zero_namlen_fallback d_namlen_zero,nul_termination,record_boundary deterministic_unit root_swiftpm fast 2 SyntheticDirentRecord A zero d_namlen record decodes only when a NUL terminator occurs within d_reclen. The compatibility fallback could scan beyond the record or accept unterminated bytes as a path. bounded_memory test_case retain 0 REPOPROMPT-A9 bounded fallback regression. root/RepoPromptTests.FileSystemServiceEventPathMappingTests/testRoutineEventPathsMapOnlySafeRootRelativeValues root Tests/RepoPromptTests/Services/FileSystem/FileSystemServiceEventPathMappingTests.swift RepoPromptTests.FileSystemServiceEventPathMappingTests testRoutineEventPathsMapOnlySafeRootRelativeValues Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 12 root/RepoPromptTests.FileSystemServiceEventPathMappingTests/testSymlinkCanonicalFallbackMapsUnsafeCanonicalPathInsideRoot root Tests/RepoPromptTests/Services/FileSystem/FileSystemServiceEventPathMappingTests.swift RepoPromptTests.FileSystemServiceEventPathMappingTests testSymlinkCanonicalFallbackMapsUnsafeCanonicalPathInsideRoot Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 34 root/RepoPromptTests.FileSystemServiceIgnoreRecoveryTests/testLoadContentsSkipsDirectorySymlinksWhenConfigured root Tests/RepoPromptTests/Services/FileSystem/FileSystemServiceIgnoreRecoveryTests.swift RepoPromptTests.FileSystemServiceIgnoreRecoveryTests testLoadContentsSkipsDirectorySymlinksWhenConfigured Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 37 @@ -1472,12 +1390,9 @@ root/RepoPromptTests.GitBlobCapabilityBoundCatFileTests/testCatFileCaptureBounda root/RepoPromptTests.GitBlobCapabilityBoundCatFileTests/testHostileRepositoryEnvironmentCannotExposeObjectsFromAnotherRepository root Tests/RepoPromptTests/Services/VCS/GitBlobCapabilityBoundCatFileTests.swift RepoPromptTests.GitBlobCapabilityBoundCatFileTests testHostileRepositoryEnvironmentCannotExposeObjectsFromAnotherRepository Services vcs.git_blob_materialization.repository_isolation ordinary,linked_worktree,repository_a,repository_b,object_unavailable security_contract root_swiftpm routine 4 ReviewGitRepositoryFixture Under repository-B routing/object/config environment, A reads its own blob and rejects a B-only blob for both ordinary and linked A capabilities. Hostile environment state could cross repository authority boundaries and disclose or publish B objects as A. 0.516000 git_subprocess;filesystem test_case retain 0 Slice 1A hostile repository isolation root/RepoPromptTests.GitBlobCapabilityBoundCatFileTests/testPromisorMissingObjectNeverInvokesRemoteHelper root Tests/RepoPromptTests/Services/VCS/GitBlobCapabilityBoundCatFileTests.swift RepoPromptTests.GitBlobCapabilityBoundCatFileTests testPromisorMissingObjectNeverInvokesRemoteHelper Services vcs.git_blob_materialization.no_lazy_fetch partial_clone,promisor,missing_object,remote_helper,no_network security_contract root_swiftpm routine 1 ReviewGitRepositoryFixture A missing promisor object returns local unavailable and an executable ext remote helper marker proves no helper invocation occurred. Materialization could trigger hidden network access, credential prompts, helpers, or mutable remote bytes. 1.155000 git_subprocess;filesystem test_case retain 0 Slice 1A no-lazy-fetch contract root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testAssociationProofRejectsIndependentIdentityKeyAndCASInputsBeforePublication root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testAssociationProofRejectsIndependentIdentityKeyAndCASInputsBeforePublication CodeMap codemap.git_locator.proof_bound_publication clean_provenance,repository_namespace,object_format,raw_byte_count,raw_sha256,pipeline,git_blob_oid,cas_handle,no_hook_no_file validation_contract root_swiftpm routine 9 GitBlobLocatorProofFixture Validated-worktree provenance and independent namespace, object-format, count, digest, pipeline, OID, or CAS-handle mismatches cannot mint the opaque association and produce no locator file or publish hook; the valid clean proof publishes once. An independently constructible locator/key pair could advertise missing, corrupt, or unrelated CAS content. 0.521500 filesystem,security temporary_directory test_case retain 0 Phase 5B proof-bound locator publication -root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testAutomaticMaintenanceSeedsCrashCleanupAndEvictsToLowWaterProtectingNewRecord root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testAutomaticMaintenanceSeedsCrashCleanupAndEvictsToLowWaterProtectingNewRecord CodeMap/Persistence codemap.locator_store.automatic_maintenance_hysteresis first_insert_seed,crash_residue,high_water,low_water,protected_publication persistence_contract root_swiftpm routine 2 GitBlobCodeMapLocatorStoreFixture,CodeMapArtifactStore The first successful insert removes secure crash residue and seeds accounting; exceeding count high-water evicts to the configured 90 percent low-water while the just-published verified record remains readable. Skipping the seed sweep could retain crash debris, while hysteresis could over-evict or delete the publication that triggered maintenance. filesystem,actor,crypto,debug_accounting temporary_directory test_case+fixture_cleanup retain 0 P0/P1 measured locator-maintenance amortization: seed cleanup and low-water protection. root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testCodecAndStoreFailClosedForKeyMismatchAndCorruption root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testCodecAndStoreFailClosedForKeyMismatchAndCorruption CodeMap codemap.git_locator.corruption pipeline_mismatch,identity_mismatch,checksum,corruption,verified_repair corruption_contract root_swiftpm routine 5 GitBlobLocatorStoreFixture Pipeline/key mismatch and identity mismatch fail closed; modified record bytes read corrupt and a proof-bound write atomically repairs them. A corrupt or cross-pipeline locator could target the wrong artifact key or resist a verified repair. 0.010000 filesystem test_case retain 0 Phase 4 inert Git blob locator root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testConcurrentDistinctPublicationsAtCountQuotaDoNotReportIntegrityCollision root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testConcurrentDistinctPublicationsAtCountQuotaDoNotReportIntegrityCollision CodeMap codemap.git_locator.concurrent_quota_publication distinct_writers,count_quota,publication,maintenance,no_false_collision filesystem_race_contract root_swiftpm routine 2 GitBlobLocatorAsyncBarrier Two distinct writers publish concurrently at the count quota without a false integrity collision; maintenance then retains exactly one readable locator. Quota pressure could misclassify valid concurrent publication as corruption or leave the store above its bound. 0.014000 filesystem;concurrency test_case retain 0 Phase 4 P2 ledger reconciliation -root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testCrossInstanceDebtIsIntervalBoundedAndExplicitMaintenanceRestoresExactQuota root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testCrossInstanceDebtIsIntervalBoundedAndExplicitMaintenanceRestoresExactQuota CodeMap/Persistence codemap.locator_store.cross_instance_bounded_debt cross_instance,actor_local_estimate,reconciliation_interval,bounded_debt,explicit_maintenance,exact_quota persistence_contract root_swiftpm routine 2 GitBlobCodeMapLocatorStoreFixture,CodeMapArtifactStore Two initialized stores accumulate no more than maximumRecordCount plus interval-minus-one inserts per store before reconciliation, and explicit maintain returns the shared namespace to the exact count and byte quotas. Actor-local estimates could permit unbounded cross-process growth or make explicit maintenance inherit the automatic low-water/debt policy. filesystem,actor,concurrency,crypto temporary_directory,cross_instance_lock test_case+fixture_cleanup retain 0 P0/P1 bounded cross-process debt and exact explicit maintenance contract. root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testCrossInstancePublicationHasNoInsecureLeafWindowAndOneWinner root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testCrossInstancePublicationHasNoInsecureLeafWindowAndOneWinner CodeMap codemap.git_locator.atomic_publication cross_instance,reader_writer,winner_loser,rename_exclusive filesystem_race_contract root_swiftpm routine 5 GitBlobLocatorAsyncGate Concurrent stores observe miss or hit without a two-link insecure window, and repeated writers resolve idempotently. Hard-link publication could create false security failures across actors. 0.010500 filesystem;concurrency test_case retain 0 Phase 4 review regression -root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testIdempotentWritesSkipMaintenanceAndInsertedWritesReconcileAtConfiguredInterval root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testIdempotentWritesSkipMaintenanceAndInsertedWritesReconcileAtConfiguredInterval CodeMap/Persistence codemap.locator_store.amortized_write_maintenance already_present,zero_sweep,insert_estimate,reconciliation_interval,sweep_accounting persistence_contract root_swiftpm routine 2 GitBlobCodeMapLocatorStoreFixture,CodeMapArtifactStore A securely matched repeated write adds no maintenance sweep, while distinct successful inserts update actor-local estimates and trigger exactly one new sweep at the configured reconciliation interval. Idempotent or every inserted publication could regress to a full namespace scan and recreate flock contention proportional to worker count times record count. filesystem,actor,crypto,debug_accounting temporary_directory test_case+fixture_cleanup retain 0 P0/P1 complexity oracle: repeat writes stay single-record and insert sweeps are interval-amortized. root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testMaintenanceClosesEachRecordDescriptorDuringLargePass root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testMaintenanceClosesEachRecordDescriptorDuringLargePass CodeMap codemap.git_locator.maintenance_descriptor_scope large_pass,descriptor_lifetime,tmp_cleanup filesystem_maintenance_contract root_swiftpm routine 1 A 512-entry maintenance pass examines and removes every temporary record without retaining per-record descriptors. Descriptor lifetime growth could exhaust process file descriptors during bounded maintenance. 0.110500 filesystem test_case retain 0 Phase 4 P2 ledger reconciliation root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testMaintenanceEnforcesCountAndByteQuotasAndCleansCrashResidueOnRestart root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testMaintenanceEnforcesCountAndByteQuotasAndCleansCrashResidueOnRestart CodeMap codemap.git_locator.maintenance count_quota,byte_quota,corrupt_cleanup,tmp_cleanup,restart,shard_pruning filesystem_maintenance_contract root_swiftpm routine 6 GitBlobLocatorStoreFixture Bounded maintenance enforces count and byte limits and removes corrupt or temporary residue after restart. An inert locator could grow without bound or retain crash/corruption debris. 0.031000 filesystem test_case retain 0 Phase 4 review regression root/RepoPromptTests.GitBlobCodeMapLocatorStoreTests/testNamespaceUsesSharedCommonDirectoryForCanonicalAndLinkedLayouts root Tests/RepoPromptTests/CodeMap/GitBlobCodeMapLocatorStoreTests.swift RepoPromptTests.GitBlobCodeMapLocatorStoreTests testNamespaceUsesSharedCommonDirectoryForCanonicalAndLinkedLayouts CodeMap codemap.git_locator.shared_namespace salted_namespace,common_dir,canonical,linked,no_path identity_contract root_swiftpm routine 4 GitRepositoryLayoutFixture Canonical and linked layouts with one commonDir share a salted path-free namespace; salts remain isolating. Worktree-local or path-bearing namespace keys could defeat reuse or leak source paths. 0.001000 filesystem test_case retain 0 Phase 4 inert Git blob locator @@ -1532,14 +1447,11 @@ root/RepoPromptTests.GitBranchSwitchServiceTests/testSwitchRejectsBranchCheckedO root/RepoPromptTests.GitBranchSwitchServiceTests/testSwitchesToExistingLocalBranchInPlace root Tests/RepoPromptTests/Services/VCS/GitBranchSwitchServiceTests.swift RepoPromptTests.GitBranchSwitchServiceTests testSwitchesToExistingLocalBranchInPlace Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.261000 unreviewed retain_pending_review 0 initial census source line 16 root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testArtifactModesShowWI9CommandCountReductions root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testArtifactModesShowWI9CommandCountReductions Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.270000 unreviewed retain_pending_review 0 initial census source line 45 root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testBatchedUntrackedDiffPreservesRepositoryRelativePatchPaths root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testBatchedUntrackedDiffPreservesRepositoryRelativePatchPaths Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.086500 unreviewed retain_pending_review 0 initial census source line 89 -root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testExplicitArtifactPathScopesDiscoveryAmidManyUnrelatedUntrackedFiles root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testExplicitArtifactPathScopesDiscoveryAmidManyUnrelatedUntrackedFiles Services/VCS git.artifacts.explicit_path_scopes_discovery explicit_pathspec,untracked_noise,discovery_commands,artifact_manifest,patch_exclusion behavioral_regression root_swiftpm routine 1 GitWorkCountFixture,GitDiffSnapshotStore A standard publication requested for one absolute untracked path reports selected scope, forwards one pathspec to all three discovery commands, and emits a one-file manifest and patch excluding 128 unrelated files. Explicit artifact paths could trigger repository-wide discovery or leak unrelated untracked files into manifests and persisted patches. git;filesystem;subprocess;artifact_io per_test_temporary_git_workspace_cleanup retain 0 PR #668 ledger reconciliation; one path-scoped publication scenario with a 128-file noise boundary. root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testFullDiffBatchesMultipleUntrackedFilesIntoOneGitProcess root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testFullDiffBatchesMultipleUntrackedFilesIntoOneGitProcess Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.133500 unreviewed retain_pending_review 0 initial census source line 106 root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testUncommittedSummaryUsesFiveGitProcesses root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testUncommittedSummaryUsesFiveGitProcesses Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.115500 unreviewed retain_pending_review 0 initial census source line 23 root/RepoPromptTests.GitCommandWorkCountDiagnosticsTests/testWarmStatusUsesOnePorcelainV2GitProcess root Tests/RepoPromptTests/Services/VCS/GitCommandWorkCountDiagnosticsTests.swift RepoPromptTests.GitCommandWorkCountDiagnosticsTests testWarmStatusUsesOnePorcelainV2GitProcess Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.121500 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.GitDiffDataMaintenanceTests/testPostPublishRetentionUsesLightweightIndexAndPreservesLimit root Tests/RepoPromptTests/Services/VCS/GitDiffDataMaintenanceTests.swift RepoPromptTests.GitDiffDataMaintenanceTests testPostPublishRetentionUsesLightweightIndexAndPreservesLimit Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.012500 unreviewed retain_pending_review 0 initial census source line 5 -root/RepoPromptTests.GitDiffEngineWorktreePathFilterTests/testAbsoluteMetacharacterPathIsLiteralWhileRelativePathspecKeepsGitGlobSemantics root Tests/RepoPromptTests/Services/VCS/GitDiffEngineWorktreePathFilterTests.swift RepoPromptTests.GitDiffEngineWorktreePathFilterTests testAbsoluteMetacharacterPathIsLiteralWhileRelativePathspecKeepsGitGlobSemantics Services/VCS git.diff.worktree_absolute_metacharacter_literal absolute_path,literal_metacharacters,relative_pathspec,git_glob,linked_worktree behavioral_regression root_swiftpm routine 2 LinkedWorktreeDiffFixture An absolute path containing [slug] selects only that literal file and patch, while the same repository-relative pathspec retains Git glob semantics and also matches pages/s.tsx. Absolute filesystem paths could be interpreted as Git globs and include unintended files, or normalization could incorrectly disable intentional relative pathspec globbing. git;filesystem;subprocess;suite_owned_git_sandbox per_test_linked_worktree_sandbox_cleanup retain 0 PR #668 ledger reconciliation; two distinct pathspec-semantics scenarios: absolute literal and relative glob. root/RepoPromptTests.GitDiffEngineWorktreePathFilterTests/testAbsolutePathFilterInLinkedWorktreeMatchesUnfilteredDiff root Tests/RepoPromptTests/Services/VCS/GitDiffEngineWorktreePathFilterTests.swift RepoPromptTests.GitDiffEngineWorktreePathFilterTests testAbsolutePathFilterInLinkedWorktreeMatchesUnfilteredDiff Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.197500 unreviewed retain_pending_review 0 initial census source line 6 -root/RepoPromptTests.GitDiffEngineWorktreePathFilterTests/testAbsolutePathOutsideLinkedWorktreeReturnsEmptyWithoutWholeCheckoutFallback root Tests/RepoPromptTests/Services/VCS/GitDiffEngineWorktreePathFilterTests.swift RepoPromptTests.GitDiffEngineWorktreePathFilterTests testAbsolutePathOutsideLinkedWorktreeReturnsEmptyWithoutWholeCheckoutFallback Services/VCS git.diff.worktree_outside_absolute_path_fails_closed absolute_path,outside_worktree,selected_scope,empty_result,no_fallback negative_path root_swiftpm routine 1 LinkedWorktreeDiffFixture An absolute path belonging to the primary checkout but outside the linked worktree yields selected scope with no requested paths, changed files, summary files, or diff text. An out-of-worktree absolute filter could be dropped and silently fall back to diffing the entire linked checkout, exposing unrelated changes. git;filesystem;subprocess;suite_owned_git_sandbox per_test_linked_worktree_sandbox_cleanup retain 0 PR #668 ledger reconciliation; one fail-closed outside-worktree path scenario. root/RepoPromptTests.GitDiffPublishedArtifactsTests/testBuildsExactIdentitiesAliasesAndPrimaryOrdering root Tests/RepoPromptTests/Services/VCS/GitDiffPublishedArtifactsTests.swift RepoPromptTests.GitDiffPublishedArtifactsTests testBuildsExactIdentitiesAliasesAndPrimaryOrdering VCS vcs.git_artifacts.exact_identity_projection exact_identity,client_alias,primary_order deterministic_filesystem_unit root_swiftpm routine 3 GitDiffPublishedArtifactSet Published artifacts carry exact absolute identities, safe aliases, and deterministic primary ordering. Selection could persist aliases, reorder primaries, or lose exact catalog identity. 0.001500 filesystem per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.GitDiffPublishedArtifactsTests/testRejectsUnsafeManifestPatchPathsAndIdentityMismatches root Tests/RepoPromptTests/Services/VCS/GitDiffPublishedArtifactsTests.swift RepoPromptTests.GitDiffPublishedArtifactsTests testRejectsUnsafeManifestPatchPathsAndIdentityMismatches VCS vcs.git_artifacts.reject_unsafe_projection path_traversal,manifest_identity,fail_closed deterministic_filesystem_unit root_swiftpm routine 2 GitDiffPublishedArtifactSet Unsafe manifest patch paths and snapshot identity mismatches fail construction. Malicious or stale manifest paths could escape the snapshot or bind to another identity. 0.001000 filesystem per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.GitLoadedRootAuthorityEvidenceTests/testAcceptedWatermarkInvalidatesCachedFooterBeforeActorDelivery root Tests/RepoPromptTests/Services/VCS/GitLoadedRootAuthorityEvidenceTests.swift RepoPromptTests.GitLoadedRootAuthorityEvidenceTests testAcceptedWatermarkInvalidatesCachedFooterBeforeActorDelivery Services/VCS git.loaded_root_authority.accepted_watermark_invalidates_cached_footer watermark,cache_invalidation,footer,actor_delivery cache_contract root_swiftpm routine 1 AuthorityEvidenceFixture Accepted watermarks invalidate cached footers before actor delivery. Regression could deliver stale footer evidence after a newer authoritative watermark. 0.040000 git;filesystem;spill_io;concurrency temporary_directory;git_process_admission test_case+lease_cleanup retain 0 Readiness optimization ledger reconciliation. @@ -1777,7 +1689,6 @@ root/RepoPromptTests.GitWorktreePorcelainParserTests/testParseNULTerminatedDetac root/RepoPromptTests.GitWorktreePorcelainParserTests/testParseNULTerminatedNormalMainAndLinkedWorktree root Tests/RepoPromptTests/Services/VCS/GitWorktreePorcelainParserTests.swift RepoPromptTests.GitWorktreePorcelainParserTests testParseNULTerminatedNormalMainAndLinkedWorktree Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.GitWorktreePorcelainParserTests/testParseNULTerminatedPreservesExactPathsWithTrailingWhitespaceAndNewlines root Tests/RepoPromptTests/Services/VCS/GitWorktreePorcelainParserTests.swift RepoPromptTests.GitWorktreePorcelainParserTests testParseNULTerminatedPreservesExactPathsWithTrailingWhitespaceAndNewlines Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 52 root/RepoPromptTests.GitWorktreePorcelainParserTests/testParseNewlineTerminatedFallback root Tests/RepoPromptTests/Services/VCS/GitWorktreePorcelainParserTests.swift RepoPromptTests.GitWorktreePorcelainParserTests testParseNewlineTerminatedFallback Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 67 -root/RepoPromptTests.GitWorktreePorcelainParserTests/testStandardizedPathAliasesCollapseOnlyForEquivalentRepositoryLayouts root Tests/RepoPromptTests/Services/VCS/GitWorktreePorcelainParserTests.swift RepoPromptTests.GitWorktreePorcelainParserTests testStandardizedPathAliasesCollapseOnlyForEquivalentRepositoryLayouts Services/VCS git.worktree_list.standardized_path_alias_authority path_standardization,layout_equivalence,directory_marker_equivalence,unresolved_layout_rejection,conflict_rejection regression root_swiftpm fast 6 GitWorktreePorcelainParser Equivalent records with compatible resolved layouts collapse despite URL directory-marker differences; unresolved, partially resolved, conflicting layouts, or conflicting record metadata throw the corresponding conflict. Duplicate standardized paths could crash worktree listing or silently select repository metadata or layout when filesystem identity is unresolved or conflicting. test_case retain 0 REPOPROMPT-54 alias-collapse regression and fail-closed repository-layout authority root/RepoPromptTests.GitWorktreePorcelainParserTests/testWorktreeListZFallsBackOnlyForUnsupportedCapabilityFailures root Tests/RepoPromptTests/Services/VCS/GitWorktreePorcelainParserTests.swift RepoPromptTests.GitWorktreePorcelainParserTests testWorktreeListZFallsBackOnlyForUnsupportedCapabilityFailures Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 123 root/RepoPromptTests.IgnoreDebugMetricsRecorderTests/testMetricsAreDisabledWhenRecordingIsNotEnabled root Tests/RepoPromptTests/Services/FileSystem/IgnoreDebugMetricsRecorderTests.swift RepoPromptTests.IgnoreDebugMetricsRecorderTests testMetricsAreDisabledWhenRecordingIsNotEnabled Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 11 root/RepoPromptTests.IgnoreDebugMetricsRecorderTests/testMetricsRecordWhenExplicitlyEnabledAndCanResetAndSnapshot root Tests/RepoPromptTests/Services/FileSystem/IgnoreDebugMetricsRecorderTests.swift RepoPromptTests.IgnoreDebugMetricsRecorderTests testMetricsRecordWhenExplicitlyEnabledAndCanResetAndSnapshot Services unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 24 @@ -1794,7 +1705,6 @@ root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testExplicitCL root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testExplicitPerCallTimeoutPolicyOverridesSemanticWait root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testExplicitPerCallTimeoutPolicyOverridesSemanticWait MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 82 root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testImmediateTimeoutWaitsForCancellationAttemptToFinish root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testImmediateTimeoutWaitsForCancellationAttemptToFinish MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.007000 unreviewed retain_pending_review 0 initial census source line 133 root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testOrdinaryToolRetains300SecondClientDeadline root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testOrdinaryToolRetains300SecondClientDeadline MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 23 -root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testProgressEnabledToolCallsRequestStandardMCPProgress root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testProgressEnabledToolCallsRequestStandardMCPProgress MCP mcp.cli_tool_call.standard_progress_token progress_token,metadata,context_builder in_memory_transport root_swiftpm routine 1 InMemoryTransport,MCPRequestSendBarrier Progress-enabled CLI tool calls include a unique standard MCP progress token in tools/call request metadata. Without the token, long-running CLI calls cannot receive standards-compliant progress and can appear hung. 0.001000 in_memory_transport test_case+client_server_cleanup retain 0 Request-scoped standard progress metadata root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testTimeoutCancellationDrainIsBoundedWhenAttemptStalls root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testTimeoutCancellationDrainIsBoundedWhenAttemptStalls MCP mcp.cli_tool_call.bounded_cancellation_drain tool_timeout,cancellation_delivery,task_cleanup async_race root_swiftpm routine 1 InMemoryTransport,CLIAsyncGate,CLIAsyncSignal A timeout returns after the configured drain deadline while an injected cancellation delivery remains stalled, then the owned delivery task finishes after release. A stalled cancellation notification could hang exec shutdown or leak detached drain observers. 0.001000 in_memory_transport,async_client_server test_case+client_server_cleanup retain 0 PR #252 final cancellation cleanup root/RepoPromptTests.InteractiveMCPClientSessionCancellationTests/testZeroSemanticWaitLeavesClientDeadlineUnbounded root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionCancellationTests.swift RepoPromptTests.InteractiveMCPClientSessionCancellationTests testZeroSemanticWaitLeavesClientDeadlineUnbounded MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 111 root/RepoPromptTests.InteractiveMCPClientSessionConnectTimeoutTests/testCallerCancellationCancelsConnectAndTimeoutTasks root Tests/RepoPromptTests/MCP/Control/InteractiveMCPClientSessionConnectTimeoutTests.swift RepoPromptTests.InteractiveMCPClientSessionConnectTimeoutTests testCallerCancellationCancelsConnectAndTimeoutTasks MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 70 @@ -1839,14 +1749,8 @@ root/RepoPromptTests.LocalSigningIdentityRegistryTests/testRejectsMissingWrongOw root/RepoPromptTests.LocalSigningIdentityRegistryTests/testSigningContextRequiresMatchingSignedMetadataAndRegistryGeneration root Tests/RepoPromptTests/Security/LocalSigningIdentityRegistryTests.swift RepoPromptTests.LocalSigningIdentityRegistryTests testSigningContextRequiresMatchingSignedMetadataAndRegistryGeneration Security unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 43 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testAuthoritativePIDOwnedAgentModeRouteCannotReplaceLiveAffinityForAnyRole root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testAuthoritativePIDOwnedAgentModeRouteCannotReplaceLiveAffinityForAnyRole MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.059500 unreviewed retain_pending_review 0 initial census source line 734 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testAuthoritativeRouteCannotReplaceLiveAffinityForMismatchedPID root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testAuthoritativeRouteCannotReplaceLiveAffinityForMismatchedPID MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.113000 unreviewed retain_pending_review 0 initial census source line 790 -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testConfirmOrFenceLateCandidateSkipsStaleTerminalPredecessorMapping root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testConfirmOrFenceLateCandidateSkipsStaleTerminalPredecessorMapping MCP mcp.routing_authority.conditional_revocation_fence stale_terminal_predecessor,late_candidate_probe,multi_connection_run_mapping,route_preservation async_race root_swiftpm routine 1 WindowState,MCPPolicyAuthorityTestConnection With a transport-terminal predecessor mapping still cached for the run, the late candidate probe considers every mapped connection and confirms the committed successor route instead of fencing. Sampling one arbitrary run mapping could observe only the stale terminal predecessor, return no candidate, and revoke a route the successor connection had already validly committed. actor;window_state;server_network_manager;debug_hooks mcp_shared_server;ServerNetworkManager;WindowStatesManager;debug_hooks MCPSharedServerTestLease+window_unregister+cleanup retain 0 Locks all-matching-connection candidate selection over runIDByConnectionID for the late commit probe. -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testConfirmOrFencePreventsSuspendedCommitAfterRevocationFence root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testConfirmOrFencePreventsSuspendedCommitAfterRevocationFence MCP mcp.routing_authority.conditional_revocation_fence commit_after_fence,policy_application_generation,fail_closed async_race root_swiftpm routine 1 WindowState,MCPPolicyAuthorityTestConnection A route application suspended before final commit is rejected after confirm-or-fence publishes the run revocation fence and policy cleanup executes. A timed-out lease could revoke policy yet allow an already-staged connection to commit and publish routed afterward. actor;window_state;server_network_manager;debug_hooks mcp_shared_server;ServerNetworkManager;WindowStatesManager;debug_hooks MCPSharedServerTestLease+window_unregister+cleanup retain 0 Exact fence-before-commit ordering regression. -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testConfirmOrFenceReobservesCommitThatLandsAfterInitialFalseSample root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testConfirmOrFenceReobservesCommitThatLandsAfterInitialFalseSample MCP mcp.routing_authority.conditional_revocation_fence commit_before_fence,authoritative_revalidation,route_preservation async_race root_swiftpm routine 1 WindowState,MCPPolicyAuthorityTestConnection After an initial false route sample, a suspended policy application commits before final revalidation; confirm-or-fence returns committed and preserves the live route. A lease timeout could observe false, then destroy a valid route that committed before revocation fencing. actor;window_state;server_network_manager;debug_hooks mcp_shared_server;ServerNetworkManager;WindowStatesManager;debug_hooks MCPSharedServerTestLease+window_unregister+cleanup retain 0 Exact commit-before-fence ordering regression. -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testConfirmOrFenceRetriesCommitThatLandsAfterNilMainActorMapping root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testConfirmOrFenceRetriesCommitThatLandsAfterNilMainActorMapping MCP mcp.routing_authority.conditional_revocation_fence late_main_actor_mapping,bounded_authoritative_retry,route_preservation async_race root_swiftpm routine 1 WindowState,MCPPolicyAuthorityTestConnection After the final MainActor lookup returns no committed mapping, the policy commit tail lands before the actor fence turn; the late candidate triggers one full retry and preserves the route. A valid route could finish committing between a nil MainActor result and the subsequent actor fence, then be revoked without re-observation. actor;window_state;server_network_manager;debug_hooks mcp_shared_server;ServerNetworkManager;WindowStatesManager;debug_hooks MCPSharedServerTestLease+window_unregister+cleanup retain 0 Exact late-MainActor-return commit-before-fence regression. -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testDisconnectDuringObservationAwaitIsRejectedByExistingStalenessGuard root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testDisconnectDuringObservationAwaitIsRejectedByExistingStalenessGuard MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A observation-hop disconnect regression root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testHelperIdentityTransitionWaitsForLateExpectedPIDRegistration root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testHelperIdentityTransitionWaitsForLateExpectedPIDRegistration MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.076000 unreviewed retain_pending_review 0 initial census source line 19 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testKnownAgentBootstrapTimesOutInsteadOfFallingBackWhenLiveAffinityIsUnusable root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testKnownAgentBootstrapTimesOutInsteadOfFallingBackWhenLiveAffinityIsUnusable MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.055500 unreviewed retain_pending_review 0 initial census source line 241 -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testMatchedNonOneShotRunPolicyAlsoPublishesObservation root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testMatchedNonOneShotRunPolicyAlsoPublishesObservation MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A non-one-shot observation regression root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testMixedQueuePrioritizesConsumablePIDGatedRunPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testMixedQueuePrioritizesConsumablePIDGatedRunPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 201 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testParallelSameProviderRunsConsumeOnlyTheirRunSpecificPIDPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testParallelSameProviderRunsConsumeOnlyTheirRunSpecificPIDPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.046500 unreviewed retain_pending_review 0 initial census source line 135 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testPendingPolicyRollbackDoesNotRestorePreviousRunAfterPrimaryGenerationChanges root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testPendingPolicyRollbackDoesNotRestorePreviousRunAfterPrimaryGenerationChanges MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.025000 unreviewed retain_pending_review 0 initial census source line 1592 @@ -1855,8 +1759,7 @@ root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testPolicyCleanupWhileWait root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testPolicyInstallFreezesBlankTabStateBeforeFirstSelectionGet root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testPolicyInstallFreezesBlankTabStateBeforeFirstSelectionGet MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.269500 unreviewed retain_pending_review 0 initial census source line 344 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRejectedAuthoritativeRoutePreservesPriorLiveAffinityForReconnect root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRejectedAuthoritativeRoutePreservesPriorLiveAffinityForReconnect MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 953 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRetainedConnectionCanConsumeSameRunPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRetainedConnectionCanConsumeSameRunPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 621 -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRetainedConnectionCannotConsumeDifferentRunPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRetainedConnectionCannotConsumeDifferentRunPolicy MCP mcp.policy_admission.run_session_observation_authority wrong_run,wrong_session,child_observation,policy_consumption,connection_retention production_shaped_policy_admission_integration root_swiftpm routine 3 WindowState,MCPRoutingWaiter A retained wrong-run connection and a fresh connection carrying another run's session token are both rejected without latching child observation; a fresh-session connection consumes the pending policy, binds the intended tab, and latches observation. Rejected connections could falsely classify a routing timeout as post-connection or steal run/session affinity before the authoritative consumer arrives. 0.033000 actor;window_state;server_network_manager WindowStatesManager;ServerNetworkManager.shared;MCPRoutingWaiter test_case+window_unregister+cleanup retain 0 Production admission boundary covers both rejection authorities and the consuming positive path. -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRevocationDuringObservationAwaitCannotPublishRoute root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRevocationDuringObservationAwaitCannotPublishRoute MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A observation-hop revocation regression +root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRetainedConnectionCannotConsumeDifferentRunPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRetainedConnectionCannotConsumeDifferentRunPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.033000 unreviewed retain_pending_review 0 initial census source line 466 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRouteMappingFailureRejectsAndRestoresOneShotPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRouteMappingFailureRejectsAndRestoresOneShotPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 1014 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRoutingSignalWaitsForOneShotPolicyCommit root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRoutingSignalWaitsForOneShotPolicyCommit MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.039000 unreviewed retain_pending_review 0 initial census source line 1122 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testRunPolicyRevocationInvalidatesSuspendedApplicationBeforeAdmission root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testRunPolicyRevocationInvalidatesSuspendedApplicationBeforeAdmission MCP mcp.agent_policy.revocation_invalidates_suspended_admission policy_revocation,route_installation,stale_connection async_race root_swiftpm routine 1 MCPAgentPolicyAdmissionRaceFixture A suspended pending-policy application rejects after policy revocation and leaves no connection mapping, pending policy, or run policy state. Revoked agent policies could still admit a suspended connection and recreate run routing after cancellation. 0.012000 server_network_manager;async_tasks ServerNetworkManager.shared test_case+cleanup retain 0 PR #252 ledger reconciliation for policy revocation race @@ -1872,7 +1775,6 @@ root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testSupersededPendingToken root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testSupersededStaleReplacementRollbackDoesNotOverwriteNewerOwner root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testSupersededStaleReplacementRollbackDoesNotOverwriteNewerOwner MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.030500 unreviewed retain_pending_review 0 initial census source line 1312 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testSuspendedRouteInstallationReservesOneShotPolicyAndRollbackRestoresIt root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testSuspendedRouteInstallationReservesOneShotPolicyAndRollbackRestoresIt MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.021000 unreviewed retain_pending_review 0 initial census source line 1052 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testTerminalRunCleanupReleasesAffinityBeforeFreshRunBinding root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testTerminalRunCleanupReleasesAffinityBeforeFreshRunBinding MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 670 -root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testTransportTerminalPublicationPreventsCommittedRouteConfirmation root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testTransportTerminalPublicationPreventsCommittedRouteConfirmation MCP mcp.routing_authority.transport_terminal_fence transport_close,connection_liveness,double_sample,late_double_close async_race root_swiftpm routine 2 WindowState,MCPPolicyAuthorityTestConnection A synchronously published transport-terminal marker makes an otherwise mapped route non-authoritative before async removal, while a late close callback after full removal cannot reinsert the marker. A closing connection could be upgraded to routed while removal was pending, or a late duplicate close could leave a permanent terminal marker for a removed connection ID. actor;window_state;server_network_manager;debug_hooks mcp_shared_server;ServerNetworkManager;WindowStatesManager;debug_hooks MCPSharedServerTestLease+window_unregister+cleanup retain 0 Transport terminal publication is part of the authoritative route snapshot and is scoped to live/removing connections. root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testUnreservedAgentModePolicyCannotReplaceLiveAffinity root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testUnreservedAgentModePolicyCannotReplaceLiveAffinity MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 877 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testWrongClientCannotConsumeOpenCodePolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testWrongClientCannotConsumeOpenCodePolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 107 root/RepoPromptTests.MCPAgentPolicyAdmissionRaceTests/testWrongPIDCannotConsumeRunPolicy root Tests/RepoPromptTests/MCP/Control/MCPAgentPolicyAdmissionRaceTests.swift RepoPromptTests.MCPAgentPolicyAdmissionRaceTests testWrongPIDCannotConsumeRunPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.097000 unreviewed retain_pending_review 0 initial census source line 68 @@ -1899,28 +1801,35 @@ root/RepoPromptTests.MCPAskOracleWorktreeTests/testExplicitOracleContinuationReq root/RepoPromptTests.MCPAskOracleWorktreeTests/testExplicitWindowProvenanceEndsBeforePostProviderHooks root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testExplicitWindowProvenanceEndsBeforePostProviderHooks MCP mcp.dispatch.explicit_window_scope one_shot_window,provider_scope,post_provider_hook,task_local_cleanup production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture,ToolDispatchAuthorization A live-shaped hidden window argument is available only during provider execution and is absent before result formatting and completion observers. Post-provider hooks or inherited tasks could replay one-shot active-tab packaging authority without a new explicit selector. 0.263000 mcp_socket;window_registry;shared_network_manager mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Issue #264 review finding: narrow TaskLocal to provider execution. root/RepoPromptTests.MCPAskOracleWorktreeTests/testGitDiffArtifactsReturnWhenExplicitLinkedWorktreeAdvertisementIsUnauthorized root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testGitDiffArtifactsReturnWhenExplicitLinkedWorktreeAdvertisementIsUnauthorized MCP mcp.oracle.review.explicit_linked_worktree_unauthorized_git_diff_artifact oracle_review,git_diff_artifact,linked_worktree,authorization production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture,ReviewGitRepositoryFixture,OracleReviewPackagingTraceCapture An explicitly advertised linked-worktree git-diff artifact is returned even when the source window is not authorized to advertise that linked worktree. Oracle review packaging could drop or misroute explicit diff artifacts across linked-worktree authorization boundaries. git_subprocess;filesystem;mcp_socket;async_stream mcp_shared_server;global_settings;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed explicit linked-worktree artifact authorization coverage. root/RepoPromptTests.MCPAskOracleWorktreeTests/testGitDiffSelectedArtifactsAutoSelectPatchForBoundLinkedWorktreeWithoutSessionRootCatalog root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testGitDiffSelectedArtifactsAutoSelectPatchForBoundLinkedWorktreeWithoutSessionRootCatalog MCP mcp.git.artifact_publication.selected_bound_linked_worktree selected_artifact,linked_worktree,worktree_binding,no_session_root_catalog,auto_selection production_shaped_mcp_integration root_swiftpm routine 1 PersistentMCPTestFixture,ReviewGitRepositoryFixture Selected-scope git diff publication for a bound linked worktree auto-selects both MAP and all.patch from the worktree patch while preserving the logical source selection without requiring a pre-cataloged session root. Selected artifact publication could resolve only canonical/logical paths, publish an empty snapshot, and auto-select MAP without the aggregate patch. 1.404500 git_subprocess;filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 CI-only linked-worktree selected artifact publication regression -root/RepoPromptTests.MCPAskOracleWorktreeTests/testOracleCleanupHelperInvokesAIQueriesServiceDelete root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testOracleCleanupHelperInvokesAIQueriesServiceDelete MCP/Oracle oracle.provider_conversation_cleanup.ai_queries_delete provider_cleanup,oracle,ai_queries_service,delete,model_routing main_actor_service_integration root_swiftpm routine 1 The Oracle cleanup helper invokes AIQueriesService cleanup once with the exact handle, Claude Sonnet model, and delete action. Oracle teardown could leak provider conversations or send cleanup through the wrong model or action. test_case retain 0 PR #315/#316 reviewed Oracle provider-conversation cleanup delegation contract. root/RepoPromptTests.MCPAskOracleWorktreeTests/testOracleLogLookupDoesNotAdoptLegacyOrSiblingRun root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testOracleLogLookupDoesNotAdoptLegacyOrSiblingRun MCP mcp.oracle.log.exact_owner chat_log,run_id,legacy_rejection deterministic_unit root_swiftpm routine 2 ChatSession Log lookup selects the exact run-owned chat and returns nil when only legacy or sibling chats exist. Oracle log recovery could cross run ownership boundaries. 0.000000 per_test_value_fixture retain 0 Issue #264 exact-ID ledger reconciliation root/RepoPromptTests.MCPAskOracleWorktreeTests/testOracleReviewTransportUsesPublishedCanonicalPatchForFreshAndContinuingChat root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testOracleReviewTransportUsesPublishedCanonicalPatchForFreshAndContinuingChat MCP mcp.oracle.review.canonical_transport oracle_review,fresh_chat,continuing_chat,selected_artifact,transport_fingerprint,provider_serialization production_shaped_mcp_transport_integration root_swiftpm routine 2 PersistentMCPTestFixture,ReviewGitRepositoryFixture,OracleReviewPackagingTraceCapture Fresh and continuing canonical Oracle review authorize the real published patch, resolve selectedArtifact, and preserve its fingerprint through submission and Custom OpenAI prompt serialization while keeping MAP once and suppressing automatic fallback. Oracle session routing, transport, or provider serialization could replace or omit the selected patch, especially on continuation. 1.115500 git_subprocess;filesystem;mcp_socket;async_stream mcp_shared_server;global_settings;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Two lifecycle scenarios: fresh request and continuation by chat_id root/RepoPromptTests.MCPAskOracleWorktreeTests/testOracleReviewTransportUsesPublishedLinkedWorktreePatchForFreshAndContinuingChat root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testOracleReviewTransportUsesPublishedLinkedWorktreePatchForFreshAndContinuingChat MCP mcp.oracle.review.linked_worktree_transport oracle_review,fresh_chat,continuing_chat,selected_artifact,worktree_isolation,transport_fingerprint,provider_serialization production_shaped_mcp_transport_integration root_swiftpm routine 2 PersistentMCPTestFixture,ReviewGitRepositoryFixture,OracleReviewPackagingTraceCapture Fresh and continuing linked-worktree Oracle review preserve the exact published worktree patch fingerprint through submission and Custom OpenAI prompt serialization while canonical content remains absent. Oracle continuation or provider serialization could lose the worktree patch, fall back automatically, or leak canonical checkout content. 1.605000 git_subprocess;filesystem;mcp_socket;async_stream mcp_shared_server;global_settings;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Two lifecycle scenarios: fresh request and continuation by chat_id root/RepoPromptTests.MCPAskOracleWorktreeTests/testOracleSendContextKeepsConversationOwnerSeparateFromDelegatedPackagingSource root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testOracleSendContextKeepsConversationOwnerSeparateFromDelegatedPackagingSource MCP mcp.oracle.review.identity_split conversation_owner,packaging_source,delegation_consumer deterministic_unit root_swiftpm routine 1 AgentRunOracleReviewContext The child conversation IDs remain distinct from source packaging IDs and exact delegated artifact consumer lineage. Using source identity for chat ownership or child identity for artifact provenance would break isolation. 0.000000 per_test_value_fixture retain 0 Issue #264 exact-ID ledger reconciliation root/RepoPromptTests.MCPAskOracleWorktreeTests/testVisibleLinkedWorktreeOracleUsesPublishedPatchForFreshAndContinuingChat root Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift RepoPromptTests.MCPAskOracleWorktreeTests testVisibleLinkedWorktreeOracleUsesPublishedPatchForFreshAndContinuingChat MCP mcp.oracle.review.visible_linked_transport visible_root,linked_worktree,fresh_chat,continuing_chat,selected_artifact,canonical_isolation production_shaped_mcp_transport_integration root_swiftpm routine 2 PersistentMCPTestFixture,ReviewGitRepositoryFixture,OracleReviewPackagingTraceCapture Fresh and continuing non-Agent visible-linked Oracle review preserve the exact published patch while MAP stays ordinary and automatic fallback remains unused. Oracle could reject the advertised linked artifact, recompute a diff, or leak canonical checkout content. 1.461000 git_subprocess;filesystem;mcp_socket;async_stream mcp_shared_server;global_settings;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Visible linked direct Oracle regression root/RepoPromptTests.MCPBootstrapLeaseTests/testCleanupWhileQueuedReleasesGateOwnershipThatArrivesLater root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testCleanupWhileQueuedReleasesGateOwnershipThatArrivesLater MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011500 unreviewed retain_pending_review 0 initial census source line 7 -root/RepoPromptTests.MCPBootstrapLeaseTests/testConcurrentCleanupJoinsSingleInFlightPolicyClear root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testConcurrentCleanupJoinsSingleInFlightPolicyClear MCP mcp.bootstrap_lease.cleanup_is_joinable_single_flight bootstrap_lease,require_routing,cleanup_joinable async_lifecycle root_swiftpm routine 1 ClearerGate,CleanupEventLog With a gated, suspending policy clearer, a DEBUG join probe deterministically proves cancelAndCleanup enters clearPolicyOnce's existing-operation branch while the clear is parked; neither requireRouting nor cancelAndCleanup returns until the single clear completes, which runs exactly once with exactly one joiner. At-most-once cleanup that only flips a flag would let one path return while the shared clear is still suspended, reporting failure before cleanup finished. 0.016000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 #514 fail-closed requireRouting joinable single-flight cleanup contract root/RepoPromptTests.MCPBootstrapLeaseTests/testDeferredCursorRoutingAdvertisesOracleLogAfterPolicyAdmission root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testDeferredCursorRoutingAdvertisesOracleLogAfterPolicyAdmission MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.061000 unreviewed retain_pending_review 0 initial census source line 134 root/RepoPromptTests.MCPBootstrapLeaseTests/testDeferredRoutingReleaseFreesGateAndTerminalCleanupClearsPolicy root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testDeferredRoutingReleaseFreesGateAndTerminalCleanupClearsPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 72 -root/RepoPromptTests.MCPBootstrapLeaseTests/testIndefiniteRoutedOutcomeRemainsObservableForLeaseLifetime root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testIndefiniteRoutedOutcomeRemainsObservableForLeaseLifetime MCP mcp.bootstrap_lease.indefinite_terminal_outcome_lifetime bootstrap_lease,indefinite_route,terminal_cache,waiter_cleanup deterministic_actor_lifecycle root_swiftpm routine 1 MCPBootstrapLease,PolicyRecorder After an indefinite release returns routed and process-global waiter cleanup removes its terminal state, repeated reads from the same one-shot lease still return routed without clearing policy. Immediate provider completion could observe nil after waiter teardown and incorrectly win settlement with completedWithoutRoute. global_connection_gate;async_tasks HeadlessAgentConnectionGate;MCPRoutingWaiter test_case+cleanup retain 0 PR #592 lease-owned terminal lifetime regression. -root/RepoPromptTests.MCPBootstrapLeaseTests/testLateCommittedRouteRecheckWinsBeforeTimeoutCleanup root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testLateCommittedRouteRecheckWinsBeforeTimeoutCleanup MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A late committed-route confirmation regression -root/RepoPromptTests.MCPBootstrapLeaseTests/testLegacyLeaseBooleanWrapperIgnoresObservedConnectionGrace root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testLegacyLeaseBooleanWrapperIgnoresObservedConnectionGrace MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A legacy absolute-deadline regression root/RepoPromptTests.MCPBootstrapLeaseTests/testPIDOwnedAcquireFailsClosedWhenPolicyCannotBeArmed root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testPIDOwnedAcquireFailsClosedWhenPolicyCannotBeArmed MCP mcp.bootstrap_lease.pid_policy_arm_failure_fails_closed bootstrap_lease,pid_policy,gate_cleanup async_lifecycle root_swiftpm routine 1 MCPBootstrapLeaseFixture,PolicyRecorder A PID-owned lease whose expected-PID policy cannot be armed fails acquisition, clears policy once, releases waiters, and leaves no active gate. Bootstrap admission could proceed without PID policy enforcement or leave gate ownership wedged after arming failure. 0.001000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 PR #252 ledger reconciliation for PID-owned policy arm failure root/RepoPromptTests.MCPBootstrapLeaseTests/testPIDOwnedEarlyReleaseCleanupRemovesRetainedPolicyForEveryExit root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testPIDOwnedEarlyReleaseCleanupRemovesRetainedPolicyForEveryExit MCP mcp.bootstrap_lease.pid_early_release_cleanup bootstrap_lease,pid_policy,cleanup_matrix async_lifecycle root_swiftpm routine 3 MCPBootstrapLeaseFixture Timeout, cancellation, and failure exits each remove retained pending policy, clear routing waiters, and leave the gate idle. Early-release PID policy cleanup could leak retained policies or waiters across terminal paths. 0.017500 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 PR #252 ledger reconciliation for PID-owned early-release cleanup root/RepoPromptTests.MCPBootstrapLeaseTests/testPIDOwnedSameClientLeasesReleaseBootstrapGateBeforeEitherRoutes root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testPIDOwnedSameClientLeasesReleaseBootstrapGateBeforeEitherRoutes MCP mcp.bootstrap_lease.parallel_pid_owned_same_client bootstrap_lease,pid_policy,gate_release async_lifecycle root_swiftpm routine 2 MCPBootstrapLeaseFixture,PolicyRecorder Two same-client PID-owned leases both arm policy without holding the global gate, record early gate release diagnostics, and cleanup both waiters plus policies. Parallel PID-owned leases could serialize unnecessarily or leak gate/policy state before either route completes. 0.002000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 PR #252 ledger reconciliation for parallel PID-owned leases -root/RepoPromptTests.MCPBootstrapLeaseTests/testRepeatedRequireRoutingWithRacingCancelJoinsSinglePolicyClear root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testRepeatedRequireRoutingWithRacingCancelJoinsSinglePolicyClear MCP mcp.bootstrap_lease.require_routing_repeated_call_racing_cancel bootstrap_lease,require_routing,fail_closed async_lifecycle root_swiftpm routine 1 PolicyRecorder One requireRouting registers the routing waiter and suspends; a second repeated call fails fast on the already-releasing lease without awaiting the releasing call's cleanup; a racing cancelAndCleanup runs. Both calls fail closed with .routingUnavailable and the injected policy clearer runs exactly once. A repeated call or a cancellation racing the suspended wait could surface a wrong error or double-clear the pending policy. 0.002000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 #514 fail-closed requireRouting repeated-call racing cleanup contract -root/RepoPromptTests.MCPBootstrapLeaseTests/testRequireRoutingReturnsWhenRunRoutes root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testRequireRoutingReturnsWhenRunRoutes MCP mcp.bootstrap_lease.require_routing_returns_on_live_route bootstrap_lease,require_routing,fail_closed async_lifecycle root_swiftpm routine 1 PolicyRecorder requireRouting returns without throwing when the live routing waiter is signalled routed; it releases the bootstrap gate, tears down the routing waiter, and does not invoke the injected policy clearer. A routed run could throw spuriously or clear the pending policy the real connection still needs. 0.001000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 #514 fail-closed requireRouting live-route success contract -root/RepoPromptTests.MCPBootstrapLeaseTests/testRequireRoutingThrowsCancellationErrorWhenCancelledAfterRegistration root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testRequireRoutingThrowsCancellationErrorWhenCancelledAfterRegistration MCP mcp.bootstrap_lease.require_routing_cancellation_is_cancellation_error bootstrap_lease,require_routing,fail_closed async_lifecycle root_swiftpm routine 1 PolicyRecorder Cancelling requireRouting after its routing waiter registers surfaces CancellationError rather than a readiness error; the injected policy clearer runs once and the bootstrap gate and routing waiter are torn down. A cancelled routing wait could be misreported as a routing readiness failure or leak gate/policy/waiter state. 0.001000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 #514 fail-closed requireRouting cancellation-attribution contract -root/RepoPromptTests.MCPBootstrapLeaseTests/testRequireRoutingThrowsReadinessErrorWhenRoutingTimesOut root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testRequireRoutingThrowsReadinessErrorWhenRoutingTimesOut MCP mcp.bootstrap_lease.require_routing_throws_on_timeout bootstrap_lease,require_routing,fail_closed async_lifecycle root_swiftpm routine 1 PolicyRecorder requireRouting throws MCPBootstrapReadinessError.routingUnavailable when the routing wait times out; it invokes the injected policy clearer once, tears down the routing waiter, and releases the bootstrap gate. A routing timeout could keep returning false and be silently ignored instead of raising a typed readiness failure, or leak gate/policy/waiter state. 0.016000 global_connection_gate;server_network_manager;async_tasks HeadlessAgentConnectionGate;ServerNetworkManager.shared test_case+cleanup retain 0 #514 fail-closed requireRouting routing-timeout contract -root/RepoPromptTests.MCPBootstrapLeaseTests/testRoutingStartupProgressDistinguishesSuccessAndBothTimeoutSides root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testRoutingStartupProgressDistinguishesSuccessAndBothTimeoutSides MCP mcp.bootstrap_lease.routing_startup_progress child_observation,routing_confirmation,timeout_classification,cleanup async_lifecycle_matrix root_swiftpm routine 3 MCPBootstrapLease,BootstrapProgressRecorder,PolicyRecorder Success emits observed/waiting/confirmed; pre-connection and post-connection deadlines emit their distinct timeout phases while retaining existing gate, policy, and waiter cleanup. Routing progress could misclassify timeout lineage or alter bootstrap cleanup and gate behavior. 0.030000 global_connection_gate;async_tasks HeadlessAgentConnectionGate;MCPRoutingWaiter test_case+cleanup retain 0 Three-outcome routing startup progress matrix with behavior-preserving cleanup assertions. -root/RepoPromptTests.MCPBootstrapLeaseTests/testTimeoutSnapshotFencesLateChildObservationProgress root Tests/RepoPromptTests/MCP/Control/MCPBootstrapLeaseTests.swift RepoPromptTests.MCPBootstrapLeaseTests testTimeoutSnapshotFencesLateChildObservationProgress MCP mcp.bootstrap_lease.timeout_progress_fence timeout_snapshot,late_child_observation,progress_order,cleanup deterministic_actor_race root_swiftpm routine 1 MCPBootstrapLease,BootstrapProgressRecorder,BootstrapPolicyClearGate After the routing deadline snapshots a pre-connection timeout, a gated cleanup permits a deterministic late sticky child observation but progress remains waiting-for-child then timeout-before-connection with no observed or waiting-for-routing phases. A post-timeout observer wake could emit non-monotonic child phases after the terminal timeout classification and mislead callers. 0.011000 global_connection_gate;actor;async_tasks HeadlessAgentConnectionGate;MCPRoutingWaiter test_case+cleanup retain 0 Deterministic policy-clear gate opens the exact post-snapshot race window without changing routing timing. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testBoundedDirectoryExpansionRejectsAtLimitPlusOneBeforeDownstreamWork root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testBoundedDirectoryExpansionRejectsAtLimitPlusOneBeforeDownstreamWork MCP mcp.code_structure.directory_seed_budget_early_exit paths_scope,directory_expansion,limit_plus_one,seed_demand,hard_budget,zero_downstream_work production_shaped_mcp_integration root_swiftpm routine 1 ReviewGitRepositoryFixture,MCPCodeStructureWorktreeFixture A directory request with max_files one stops after the second unique candidate, returns seed_demand hard_budget_exceeded with attempted two and limit one, and performs zero logical-path computations or coordinator calls. Unbounded folder expansion could enumerate or codemap an entire tree before enforcing the caller file budget. 0.531500 temp_git_repository;window_state WindowStatesManager;ServerNetworkManager test_case+fixture_cleanup+window_unregister retain 0 Registered-tool bounded directory-expansion admission regression. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testDeletedMaterializedWorktreeFailsClosedInsteadOfReturningCachedStructure root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testDeletedMaterializedWorktreeFailsClosedInsteadOfReturningCachedStructure MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 1.448500 unreviewed retain_pending_review 0 initial census source line 362 +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testInheritedWorktreeSequentialStructureThenTreePublishesLogicalMarkerWithoutPhysicalLeakage root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testInheritedWorktreeSequentialStructureThenTreePublishesLogicalMarkerWithoutPhysicalLeakage MCP mcp.code_structure.inherited_worktree_logical_marker inherited_worktree,sequential_structure,tree,logical_marker,physical_path_redaction production_shaped_worktree_integration root_swiftpm routine 1 ReviewGitRepositoryFixture A worktree-inherited sequential code-structure and tree flow publishes logical markers without exposing physical worktree paths. Canonical content or physical worktree paths could leak into MCP files, tree output, or codemap text. 2.007000 test_case retain 0 Renamed from testSeedModernResultUsesLogicalPathWithoutPhysicalLeakage during worktree logical-marker coverage. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testMissingWorktreeSnapshotReturnsPendingThenRendersRefreshedLogicalPath root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testMissingWorktreeSnapshotReturnsPendingThenRendersRefreshedLogicalPath MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 1.689500 unreviewed retain_pending_review 0 initial census source line 25 +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testNonGitRootReturnsTypedUnavailableWithoutLegacySnapshotBuild root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testNonGitRootReturnsTypedUnavailableWithoutLegacySnapshotBuild MCP mcp.code_structure.non_git_unavailable registered_tool,non_git,typed_unavailable,git_command_count,request_identity production_shaped_mcp_integration root_swiftpm routine 1 MCPCodeStructureWorktreeFixture The registered get_code_structure tool returns git_root_unavailable for a non-Git root and appends exactly one successful matching request diagnostic with command_count zero. A non-Git request could perform hidden Git work, omit the completed zero-work record, or lose request attribution while still returning typed output. 0.052500 temp_directory;window_state WindowStatesManager;MCPToolWorkCountDiagnostics test_case+window_unregister retain 0 Registered-tool zero-Git diagnostic strengthens the grouped headless codemap cutover contract. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testPhysicalPathDedupAvoidsFalseOverflowAcrossOverlappingRoots root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testPhysicalPathDedupAvoidsFalseOverflowAcrossOverlappingRoots MCP mcp.code_structure.physical_path_dedup overlapping_roots,distinct_file_ids,same_physical_path,exclusion,max_files,one_demand production_shaped_store_integration root_swiftpm routine 2 ReviewGitRepositoryFixture,MCPCodeStructureWorktreeFixture An already-excluded physical file contributes zero expansion candidates at a zero limit, and duplicate records for the same physical path do not trigger max_files overflow or more than one logical-path computation and coordinator invocation. Overlapping loaded roots could double-count one physical file, cause false hard-budget failures, and duplicate codemap work. 0.789000 temp_git_repository;window_state WindowStatesManager test_case+fixture_cleanup+window_unregister retain 0 Physical-identity deduplication across overlapping-root boundaries. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testReadinessPressureDTOsAreTypedEmptyAndRetryConsistent root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testReadinessPressureDTOsAreTypedEmptyAndRetryConsistent MCP mcp.code_structure.readiness_pressure_dto busy,timeout,projection_unavailable,legacy_partial,legacy_pending,projection_budget,typed_retry,empty_payload deterministic_dto_formatter_matrix root_swiftpm routine 7 MCPCodeStructureWorktreeFixture Busy, timeout, two projection-unavailable variants, legacy partial and pending, and projection-budget presentations map to exact typed statuses and issues; pressure responses discard files and work totals, retry metadata is normalized, and budget remains nonretryable with exact attempted and limit values. Readiness pressure could leak stale codemaps, misstate completed work, or expose contradictory status, issue, and retry metadata to MCP clients. 0.000500 in_memory_dto test_case retain 0 Seven-case code-structure pressure DTO contract matrix. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testResidentForwardAndReverseExpansionUseRootLocalBoundedTraversal root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testResidentForwardAndReverseExpansionUseRootLocalBoundedTraversal MCP mcp.code_structure.root_local_expansion forward_bfs,reverse_bfs,resident_graph production_shaped_store_integration root_swiftpm routine 1 ReviewGitRepositoryFixture Resident forward and reverse requests return seed-first depth provenance and partial coverage. The MCP consumer could loop one-hop queries, lose provenance, or cross root authority. 1.346000 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSeedDemandBudgetRejectsExpandedSeedsBeforeDemand root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSeedDemandBudgetRejectsExpandedSeedsBeforeDemand MCP headless_p1.mcp_seed_budget_dto seed_demand,hard_budget,max_files protocol_negative root_swiftpm routine 1 MCPCodeStructureWorktreeFixture Two expanded seeds under maximum_files one return hard_budget_exceeded in seed_demand with attempted and limit and no files. MCP could demand the full expanded seed set before enforcing request limits. 0.667000 temp_git_repository;window_state test_case+window_unregister retain 0 Headless P1 grouped repair MCP budget contract +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSeedOrderingAndOutputAreDeterministic root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSeedOrderingAndOutputAreDeterministic MCP mcp.code_structure.deterministic_order logical_path,ordering,repeatability production_shaped_store_integration root_swiftpm routine 1 ReviewGitRepositoryFixture Permuted seed records produce byte-equivalent DTO ordering. Hash or physical-path ordering could make responses nondeterministic. 1.255000 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSelectedScopeRejectsAtLimitPlusOneWithoutContentOrCodemapWork root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSelectedScopeRejectsAtLimitPlusOneWithoutContentOrCodemapWork MCP mcp.code_structure.selected_seed_budget_early_exit selected_scope,limit_plus_one,seed_demand,hard_budget,zero_content_reads,zero_codemap_work production_shaped_mcp_integration root_swiftpm routine 1 ReviewGitRepositoryFixture,MCPCodeStructureWorktreeFixture,CodeStructureContentReadCounter A three-file selection with max_files one stops at the second unique seed, returns attempted two and limit one, and performs no content reads, logical-path computations, or coordinator invocations. Selected-scope admission could read file contents or start codemap work before detecting that the seed set exceeds its hard file budget. 0.549500 temp_git_repository;window_state;content_read_hook WindowStatesManager;ServerNetworkManager test_case+hook_reset+fixture_cleanup+window_unregister retain 0 Registered-tool selected-scope pre-work budget regression. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSelectedScopeStaleFolderIsIgnoredWhileExactRootAliasResolves root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSelectedScopeStaleFolderIsIgnoredWhileExactRootAliasResolves MCP mcp.code_structure.selected_folder_resolution selected_scope,stale_folder,basename_collision,exact_root_alias,folder_expansion production_shaped_store_integration root_swiftpm routine 2 ReviewGitRepositoryFixture,MCPCodeStructureWorktreeFixture A stale folder path sharing only the selected folder basename resolves no files and visits no candidates, while the exact root-qualified alias resolves the one current file without exceeding the limit. Basename fallback could silently retarget stale selections to unrelated current folders, while strict matching could also reject valid root aliases. 0.544000 temp_git_repository;window_state WindowStatesManager test_case+fixture_cleanup+window_unregister retain 0 Selected-folder stale-path rejection and exact-alias positive boundary. +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testStoreCanScanSessionWorktreeRoot root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testStoreCanScanSessionWorktreeRoot MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.842000 unreviewed retain_pending_review 0 initial census source line 7 +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testStrictTokenBudgetNeverAdmitsOversizedFirstEntry root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testStrictTokenBudgetNeverAdmitsOversizedFirstEntry MCP mcp.code_structure.strict_token_budget token_budget,first_entry,typed_budget production_shaped_store_integration root_swiftpm routine 1 ReviewGitRepositoryFixture An oversized first codemap is omitted and reported with token_limit and zero charged tokens. The first result could bypass the caller token budget. 0.997000 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSwitchingCodeStructureScopeFromWorktreeAToBDoesNotReuseA root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSwitchingCodeStructureScopeFromWorktreeAToBDoesNotReuseA MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 2.433000 unreviewed retain_pending_review 0 initial census source line 278 +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testTargetedSelfHealingIsBoundedByMaxResults root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testTargetedSelfHealingIsBoundedByMaxResults MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.604000 unreviewed retain_pending_review 0 initial census source line 420 +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testUnavailableWorktreeReturnsTypedIssueBeforeCanonicalRead root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testUnavailableWorktreeReturnsTypedIssueBeforeCanonicalRead MCP mcp.code_structure.missing_worktree_fail_closed worktree_unavailable,canonical_isolation,typed_issue production_shaped_worktree_integration root_swiftpm routine 1 WorkspaceRootBindingProjection A missing bound worktree returns git_root_unavailable without canonical content or physical issue leakage. Missing worktrees could fall back to canonical checkout reads. 0.639000 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.MCPCodeStructureWorktreeTests/testWaitMillisecondsParameterIsNotExposedAndIsRejected root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testWaitMillisecondsParameterIsNotExposedAndIsRejected MCP mcp.code_structure.wait_policy public_schema,wait_ms,default_request,unknown_limit,rejection_before_capture protocol_negative root_swiftpm routine 2 MCPCodeStructureWorktreeFixture The registered schema omits wait_ms and an invocation without limits captures the exact default request; submitting wait_ms returns an unknown-limits error and captures no request. A caller-controlled wait knob could re-enter the public protocol, silently alter server readiness behavior, or be accepted despite schema omission. 0.126500 temp_directory;window_state WindowStatesManager;ServerNetworkManager test_case+window_unregister retain 0 Public get_code_structure wait-policy schema and decoder boundary. root/RepoPromptTests.MCPConfigExportServiceTests/testEmptyConfigUsesSameUniqueLeaseLifecycle root Tests/RepoPromptTests/MCP/MCPConfigExportServiceTests.swift RepoPromptTests.MCPConfigExportServiceTests testEmptyConfigUsesSameUniqueLeaseLifecycle MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 154 root/RepoPromptTests.MCPConfigExportServiceTests/testExistingConfigAndLeaseDirectoryComponentsAreRestrictedToOwnerOnly root Tests/RepoPromptTests/MCP/MCPConfigExportServiceTests.swift RepoPromptTests.MCPConfigExportServiceTests testExistingConfigAndLeaseDirectoryComponentsAreRestrictedToOwnerOnly MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 130 root/RepoPromptTests.MCPConfigExportServiceTests/testLaunchConfigRejectsSymlinkedLeaseDirectory root Tests/RepoPromptTests/MCP/MCPConfigExportServiceTests.swift RepoPromptTests.MCPConfigExportServiceTests testLaunchConfigRejectsSymlinkedLeaseDirectory MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 107 @@ -1933,11 +1842,6 @@ root/RepoPromptTests.MCPContextBuilderGitReviewPolicyTests/testAdmissionPreserve root/RepoPromptTests.MCPContextBuilderGitReviewPolicyTests/testPublishedOutcomesRequireCompleteExactFrozenCheckoutMatches root Tests/RepoPromptTests/MCP/MCPContextBuilderGitReviewPolicyTests.swift RepoPromptTests.MCPContextBuilderGitReviewPolicyTests testPublishedOutcomesRequireCompleteExactFrozenCheckoutMatches MCP mcp.context_builder.git_policy.publication complete_pair,repository_match,worktree_match,outcome_count,duplicate_target,post_publish_freshness deterministic_filesystem_integration root_swiftpm routine 8 ReviewGitRepositoryFixture,WorkspaceFileContextStore Published outcomes are accepted only with complete artifact-manifest pairs for exact frozen repositories and checkout kinds, unique targets, matching counts, and live roots. Incomplete or mismatched publication metadata could reach ingress, advertisement, or auto-selection outside frozen review authority. 0.954000 git_subprocess;filesystem;workspace_store per_test_temporary_repository_cleanup retain 0 Focused post-publication fence matrix root/RepoPromptTests.MCPControlMessagesTests/testControlNotificationsRoundTripWireFormats root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testControlNotificationsRoundTripWireFormats MCP mcp.control_notifications.wire_roundtrip json_rpc,notification,codec deterministic_wire_contract root_swiftpm routine 3 Exact JSON-RPC notification envelopes and parsed control payload values, including newline, method, id absence, dates, and fields. medium 0.001000 json_codec method_local_values consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.MCPControlMessagesTests/testTerminateNotificationJSONLineRoundTrips, root/RepoPromptTests.MCPControlMessagesTests/testRunCompletedNotificationJSONLineRoundTrips, root/RepoPromptTests.MCPControlMessagesTests/testProgressNotificationJSONLineRoundTripsWithStringDate root/RepoPromptTests.MCPControlMessagesTests/testKillSignalPayloadPathAndJSONRoundTrip root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testKillSignalPayloadPathAndJSONRoundTrip MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 89 -root/RepoPromptTests.MCPControlMessagesTests/testSDKProgressTokensRoundTripThroughCallAndNotificationParameters root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testSDKProgressTokensRoundTripThroughCallAndNotificationParameters MCP mcp.progress.sdk_token_roundtrip progress_token,string_token,integer_token,call_metadata,notification_parameters sdk_codec_contract root_swiftpm routine 2 Pinned swift-sdk CallTool metadata and ProgressNotification parameters preserve both string and integer progress tokens through JSON round-trip. Standard MCP hosts could lose or change request correlation tokens between tools/call and notifications/progress. 0.001000 json_codec method_local_values retain 0 Pinned SDK progress-token integration confirmation. -root/RepoPromptTests.MCPControlMessagesTests/testStandardMCPProgressCoalescesOnePendingUpdateInWireOrder root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testStandardMCPProgressCoalescesOnePendingUpdateInWireOrder MCP mcp.progress.bounded_coalescing bounded_pending,latest_wins,monotonic_sequence,wire_order actor_backpressure_regression root_swiftpm routine 3 ProgressRecordingMCPConnection,ProgressDeliveryGate,MCPRequestProgressState A blocked progress write retains exactly one latest-wins pending update and the sole burst worker completes sends in monotonic wire order. A slow progress client could create unbounded tasks or memory, deliver stale updates, or overlap ordered sends. 0.001000 actor;async_tasks test_case retain 0 Bounded capacity-one coalescing with deterministic transport backpressure. -root/RepoPromptTests.MCPControlMessagesTests/testStandardMCPProgressConnectionTerminalFailureDropsPendingAndStopsWorker root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testStandardMCPProgressConnectionTerminalFailureDropsPendingAndStopsWorker MCP mcp.progress.connection_terminal connection_close,pending_drop,worker_stop,late_emission actor_terminal_regression root_swiftpm routine 2 ProgressRecordingMCPConnection,ProgressDeliveryGate,MCPRequestProgressState A terminal progress-delivery result drops the bounded pending update, ends the burst worker, and rejects later progress. A closed connection could consume the remaining progress backlog with repeated failed writes. 0.001000 actor;async_tasks test_case retain 0 Deterministic connection-terminal delivery simulation. -root/RepoPromptTests.MCPControlMessagesTests/testStandardMCPProgressFinalizationDropsPendingWithoutWaitingForInFlightDelivery root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testStandardMCPProgressFinalizationDropsPendingWithoutWaitingForInFlightDelivery MCP mcp.progress.final_result_priority invalidation,pending_drop,in_flight_bound,late_emission,final_result_priority actor_lifecycle_regression root_swiftpm routine 3 ProgressRecordingMCPConnection,ProgressDeliveryGate,MCPRequestProgressState Finalization returns while one advisory write is blocked, drops the sole pending update, permits at most that in-flight trailing notification, and rejects later progress. A slow progress-token client could delay the final tool result by the transport write deadline or drain a backlog after completion. 0.001000 actor;async_tasks test_case retain 0 Replaces testStandardMCPProgressSerializesWireOrderAndStopsAfterRequestInvalidation; drain semantics intentionally removed. -root/RepoPromptTests.MCPControlMessagesTests/testStandardMCPProgressUsesRequestTokenWithoutDuplicatingCLIControlFallback root Tests/RepoPromptTests/MCP/Control/MCPControlMessagesTests.swift RepoPromptTests.MCPControlMessagesTests testStandardMCPProgressUsesRequestTokenWithoutDuplicatingCLIControlFallback MCP mcp.progress.standard_and_cli_fallback progress_token,monotonic_sequence,repoprompt_cli,legacy_deduplication,compatibility actor_protocol_integration root_swiftpm routine 3 ProgressRecordingMCPConnection,ProgressDeliveryGate,MCPRequestProgressState Generic and RepoPrompt CLI callers with standard tokens receive only token-correlated MCP progress, while a tokenless bundled CLI call retains exactly one custom control fallback. A token-bearing RepoPrompt CLI could receive duplicate standard and legacy progress output, or tokenless compatibility could disappear. 0.001000 actor test_case retain 0 Renamed from testStandardMCPProgressUsesRequestTokenWhileCLIControlRemainsFallback; adds explicit token-bearing RepoPrompt CLI no-duplicate coverage. root/RepoPromptTests.MCPFileActionPartialSuccessTests/testCreateSelectionPersistenceWarningPreservesSuccessfulFileAction root Tests/RepoPromptTests/MCP/MCPFileActionPartialSuccessTests.swift RepoPromptTests.MCPFileActionPartialSuccessTests testCreateSelectionPersistenceWarningPreservesSuccessfulFileAction MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 6 root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testNonRetryableAndNormalSearchFormattingOmitBackpressureSemantics root Tests/RepoPromptTests/MCP/MCPFileSearchBackpressureFormattingTests.swift RepoPromptTests.MCPFileSearchBackpressureFormattingTests testNonRetryableAndNormalSearchFormattingOmitBackpressureSemantics MCP mcp.search.nonretryable_and_normal_output formatter_dto,negative_contract deterministic_dto_formatter_matrix root_swiftpm routine 2 Pattern failure stays nonretryable and normal output omits all optional backpressure semantics. medium 0.000000 formatter_dto method_local_values consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testPatternFailureFormattingRemainsNonRetryable, root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testNormalSearchDTOOmitsOptionalBackpressureFields root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testRetryableSearchFailuresPreserveTypedDTOAndWarningFormatting root Tests/RepoPromptTests/MCP/MCPFileSearchBackpressureFormattingTests.swift RepoPromptTests.MCPFileSearchBackpressureFormattingTests testRetryableSearchFailuresPreserveTypedDTOAndWarningFormatting MCP mcp.search.retryable_failure_types formatter_dto,worktree_scope deterministic_dto_formatter_matrix root_swiftpm routine 2 Typed retryable worktree/freshness failures preserve exact DTO, scope, warning, status, and cross-status negatives. medium 0.001000 formatter_dto method_local_values consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testUnavailableWorktreeMapsToTypedRetryableDTOAndWarningFormatting, root/RepoPromptTests.MCPFileSearchBackpressureFormattingTests/testFreshnessTimeoutMapsToDistinctRetryableDTOAndWarningFormatting @@ -1964,10 +1868,6 @@ root/RepoPromptTests.MCPProxyTerminalRecordTests/testLocalSocketReadFailureIsAtt root/RepoPromptTests.MCPProxyTerminalRecordTests/testProxyTaskGroupOutcomesClassifyCleanCompletionAndCancellation root Tests/RepoPromptTests/MCP/MCPProxyTerminalRecordTests.swift RepoPromptTests.MCPProxyTerminalRecordTests testProxyTaskGroupOutcomesClassifyCleanCompletionAndCancellation MCP mcp.proxy.task_group_outcome_classification proxy,cancellation,outcome_classification deterministic_regression root_swiftpm routine 1 MCPServiceProxyTaskGroupPolicy Clean transport completion stays clean while watcher and service cancellation outcomes normalize to host task-cancelled provenance. A canceled proxy could persist a false clean terminal record and hide lifecycle failures. 0.000000 test_case retain 0 PR #252 final proxy cancellation cleanup root/RepoPromptTests.MCPProxyTerminalRecordTests/testSocketReadFailureRemainsRetryablePeerTransportFailure root Tests/RepoPromptTests/MCP/MCPProxyTerminalRecordTests.swift RepoPromptTests.MCPProxyTerminalRecordTests testSocketReadFailureRemainsRetryablePeerTransportFailure MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 60 root/RepoPromptTests.MCPProxyTerminalRecordTests/testTerminalRecordCopiesLiveLedgerSnapshotAndServerReason root Tests/RepoPromptTests/MCP/MCPProxyTerminalRecordTests.swift RepoPromptTests.MCPProxyTerminalRecordTests testTerminalRecordCopiesLiveLedgerSnapshotAndServerReason MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 128 -root/RepoPromptTests.MCPServiceProxyRaceTests/testAlreadyCancelledCallerDoesNotStartChildren root Tests/RepoPromptTests/MCP/MCPServiceProxyRaceTests.swift RepoPromptTests.MCPServiceProxyRaceTests testAlreadyCancelledCallerDoesNotStartChildren MCP mcp.proxy.pre_cancelled_entry proxy,cancellation,child_start_boundary deterministic_regression root_swiftpm fast 1 A caller cancelled before entering the proxy race surfaces CancellationError without starting, cancelling, or completing any child operation. A pre-cancelled proxy could still launch transport and watcher work, obscuring caller cancellation provenance and extending teardown. 0.001000 test_case retain 0 PR #517 final cancellation-handler ordering regression. -root/RepoPromptTests.MCPServiceProxyRaceTests/testEachChildCanWinWithValueOrErrorAndDrainsLosers root Tests/RepoPromptTests/MCP/MCPServiceProxyRaceTests.swift RepoPromptTests.MCPServiceProxyRaceTests testEachChildCanWinWithValueOrErrorAndDrainsLosers MCP mcp.proxy.first_completion_priority proxy,cancellation,error_priority,task_drain deterministic_regression root_swiftpm fast 6 Each of the three proxy operations can win with its value or error, and both losing operations observe cancellation and complete before the race returns. Changing completion priority or failing to drain a suspended loser could misclassify terminal state or reintroduce the Swift release-runtime teardown abort. 0.001000 test_case retain 0 Issue #513 explicit-task first-completion race coverage. -root/RepoPromptTests.MCPServiceProxyRaceTests/testOuterCancellationCancelsAndDrainsAllChildren root Tests/RepoPromptTests/MCP/MCPServiceProxyRaceTests.swift RepoPromptTests.MCPServiceProxyRaceTests testOuterCancellationCancelsAndDrainsAllChildren MCP mcp.proxy.outer_cancellation_drain proxy,cancellation,task_drain deterministic_regression root_swiftpm fast 1 Caller cancellation reaches all three proxy operations, surfaces as CancellationError, and waits for every operation to complete before returning. Outer cancellation could leak or tear down a suspended proxy operation and persist incorrect terminal provenance. 0.001000 test_case retain 0 Issue #513 cancellation-handler teardown coverage. -root/RepoPromptTests.MCPServiceProxyRaceTests/testRaceDoesNotReturnUntilCancelledLosersComplete root Tests/RepoPromptTests/MCP/MCPServiceProxyRaceTests.swift RepoPromptTests.MCPServiceProxyRaceTests testRaceDoesNotReturnUntilCancelledLosersComplete MCP mcp.proxy.loser_completion_barrier proxy,cancellation,task_drain deterministic_regression root_swiftpm fast 1 A controlled loser-completion gate proves the proxy race remains suspended after cancellation until both losing operations finish. Returning after cancel without awaiting loser completion recreates the compiler-frame teardown shape implicated in swift_task_dealloc aborts. 0.001000 test_case retain 0 Issue #513 structural regression oracle; fails against cancel-without-await. root/RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests/testAuthoritativeSelectionPreservationRequiresFullCanonicalSuperset root Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests testAuthoritativeSelectionPreservationRequiresFullCanonicalSuperset MCP mcp.read_file.auto_selection.authoritative_selection_preservation exact,additive_superset,full_supersedes_slice,selected_path_loss,full_to_slice_demotion,auto_codemap_loss,slice_narrowing,codemap_mode_change deterministic_table_unit root_swiftpm routine 8 stored_selection Certificate mint revalidation accepts only a full canonical superset of the authoritative result across selected paths, auto-codemap paths, slices, and codemap mode. critical 0.000000 in_memory per_test_state retain 0 read-file selection rebasing full-state preservation guard root/RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests/testCancelledCanonicalDrainResumesPromptlyWithoutStoppingWorker root Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests testCancelledCanonicalDrainResumesPromptlyWithoutStoppingWorker MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.004500 unreviewed retain_pending_review 0 initial census source line 141 root/RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests/testCancelledMirrorDrainResumesPromptlyWithoutStoppingWorker root Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift RepoPromptTests.MCPReadFileAutoSelectionCoordinatorTests testCancelledMirrorDrainResumesPromptlyWithoutStoppingWorker MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.004500 unreviewed retain_pending_review 0 initial census source line 175 @@ -2025,17 +1925,12 @@ root/RepoPromptTests.MCPResponseDeliveryTracerSafetyTests/testWriterDeliversAllB root/RepoPromptTests.MCPResponseDeliveryTracerSafetyTests/testWriterDropsUndeliverableDataForBrokenAndClosedDescriptors root Tests/RepoPromptTests/MCP/Control/MCPResponseDeliveryTracerSafetyTests.swift RepoPromptTests.MCPResponseDeliveryTracerSafetyTests testWriterDropsUndeliverableDataForBrokenAndClosedDescriptors MCP mcp.response_delivery.undeliverable_data posix_io,broken_pipe,closed_descriptor posix_descriptor_integration root_swiftpm routine 2 Broken-pipe and closed-descriptor writes return false without raising. high 0.000000 pipe,file_descriptor per_case_fd_defer_cleanup consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.MCPResponseDeliveryTracerSafetyTests/testWriterDropsDataOnBrokenPipeWithoutRaising, root/RepoPromptTests.MCPResponseDeliveryTracerSafetyTests/testWriterDropsDataOnClosedDescriptorWithoutRaising root/RepoPromptTests.MCPResponseSendDeadlineConfigurationTests/testBootstrapServerAndTransportsUseCentralResponseDeliveryPolicy root Tests/RepoPromptTests/MCP/Control/MCPResponseSendDeadlineConfigurationTests.swift RepoPromptTests.MCPResponseSendDeadlineConfigurationTests testBootstrapServerAndTransportsUseCentralResponseDeliveryPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 28 root/RepoPromptTests.MCPResponseSendDeadlineConfigurationTests/testCEPinsReviewedSwiftSDKResponseDeliveryCommit root Tests/RepoPromptTests/MCP/Control/MCPResponseSendDeadlineConfigurationTests.swift RepoPromptTests.MCPResponseSendDeadlineConfigurationTests testCEPinsReviewedSwiftSDKResponseDeliveryCommit MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 6 -root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testAdaptiveRoutingCanCommitDuringObservedGrace root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testAdaptiveRoutingCanCommitDuringObservedGrace MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A adaptive grace route regression -root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testAdaptiveRoutingDistinguishesBothDeadlinePhasesAndDoesNotRefreshGrace root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testAdaptiveRoutingDistinguishesBothDeadlinePhasesAndDoesNotRefreshGrace MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A typed adaptive deadline regression -root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testLegacyAbsoluteWaitIgnoresObservationAndClassifiesStickyObservation root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testLegacyAbsoluteWaitIgnoresObservationAndClassifiesStickyObservation MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A waiter legacy absolute-deadline regression -root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testLegacyNonpositiveTimeoutWaitsIndefinitelyUntilCancellationOrRouting root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testLegacyNonpositiveTimeoutWaitsIndefinitelyUntilCancellationOrRouting MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A legacy indefinite-wait compatibility regression root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRoutingWaiterCleanupResumesUnresolvedWaitersAsFailure root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRoutingWaiterCleanupResumesUnresolvedWaitersAsFailure MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 181 root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRoutingWaiterRecordsOnlyAcceptedTerminalSignal root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRoutingWaiterRecordsOnlyAcceptedTerminalSignal MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 119 root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRoutingWaiterTimeoutIsPerWaiterAndDoesNotResolveRun root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRoutingWaiterTimeoutIsPerWaiterAndDoesNotResolveRun MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011000 unreviewed retain_pending_review 0 initial census source line 147 root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryBoundsFieldsValuesCapacityAndLimitOrdering root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRunRoutingHistoryBoundsFieldsValuesCapacityAndLimitOrdering MCP mcp.run_routing.history_bounds_and_ordering diagnostics_contract,history_projection deterministic_diagnostics_projection root_swiftpm routine 3 History field/value bounds, ring capacity/drop counts, and newest-limit sequence ordering remain exact. high 0.010000 global_manager_history ServerNetworkManager per_case_history_reset consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryBoundsFieldCountAndValueLength, root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryIsBoundedAndReportsDroppedEvents, root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryLimitReturnsNewestMatchingEventsInSequenceOrder root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryFiltersByRunAndRedactsSensitiveFields root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRunRoutingHistoryFiltersByRunAndRedactsSensitiveFields MCP unreviewed unreviewed root_swiftpm routine 2 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 9 root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testRunRoutingHistoryToolAllowsOmittedRunIDAndBoundsLimit root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testRunRoutingHistoryToolAllowsOmittedRunIDAndBoundsLimit MCP unreviewed unreviewed root_swiftpm routine 3 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 211 -root/RepoPromptTests.MCPRunRoutingDiagnosticsTests/testTypedCancellationAndCleanupRemainDistinct root Tests/RepoPromptTests/MCP/Control/MCPRunRoutingDiagnosticsTests.swift RepoPromptTests.MCPRunRoutingDiagnosticsTests testTypedCancellationAndCleanupRemainDistinct MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 PR-A terminal outcome typing regression root/RepoPromptTests.MCPSelectionContentPackagingTests/testBorrowedSelectionReplyTokenAccountingUsesFrozenPresentationNotActiveSnapshot root Tests/RepoPromptTests/MCP/MCPSelectionContentPackagingTests.swift RepoPromptTests.MCPSelectionContentPackagingTests testBorrowedSelectionReplyTokenAccountingUsesFrozenPresentationNotActiveSnapshot MCP mcp.selection.borrowed_reply_frozen_codemap_tokens borrowed_tab_reply,frozen_presentation,token_accounting,no_active_snapshot production_shaped_store_integration root_swiftpm routine 1 ReviewGitRepositoryFixture Borrowed tab selection replies use the supplied frozen codemap presentation for total, summary, tokenStats, and emitted blocks instead of active-tab publication authority. Borrowed selection replies could report mismatched tokens or render stale active-tab codemap blocks. 0.501500 test_case retain 0 Reviewed ledger reconciliation for PR314 live missing XCTest ID. root/RepoPromptTests.MCPSelectionContentPackagingTests/testContentViewIncludesCanonicalCodemapBlocksExactlyOnce root Tests/RepoPromptTests/MCP/MCPSelectionContentPackagingTests.swift RepoPromptTests.MCPSelectionContentPackagingTests testContentViewIncludesCanonicalCodemapBlocksExactlyOnce MCP mcp.selection.content_view_canonical_codemap_packaging canonical_selection,missing_snapshot,content_view,single_emission,unrenderable_fail_closed mcp_reply_packaging_integration root_swiftpm routine 3 MCPSelectionCanonicalCodemapFixture The selection content view omits an unavailable auto codemap from both metadata and blocks, then rejects malformed codemap entries without falling through to full content, and reports and emits the available canonical codemap exactly once alongside selected content. MCP collection and resolution snapshots could race, leak dependency full content, disagree with block output, or omit available canonical APIs. 0.501000 temporary_root,window_state,actor_store,codemap_cache global_code_map_setting,mcp_auto_start test_method+defer_cleanup+defer_global_restore retain 0 Focused manage_selection content-view canonical codemap regression root/RepoPromptTests.MCPSelectionContentPackagingTests/testSelectionReplyCodemapTokensUseFrozenPresentationInsteadOfStaleEntryResults root Tests/RepoPromptTests/MCP/MCPSelectionContentPackagingTests.swift RepoPromptTests.MCPSelectionContentPackagingTests testSelectionReplyCodemapTokensUseFrozenPresentationInsteadOfStaleEntryResults MCP mcp.selection.frozen_codemap_presentation_tokens selection_reply,paired_tokens,no_legacy_bundle production_shaped_store_integration root_swiftpm routine 1 ReviewGitRepositoryFixture Selection token summaries use the shared frozen operation presentation instead of stale entry estimates. Selection replies could retain the legacy snapshot authority or report mismatched tokens. 0.509500 test_case retain 0 Grouped headless codemap cutover @@ -2088,15 +1983,9 @@ root/RepoPromptTests.MCPSocketDescriptorHardeningTests/testStoppedManagerRejects root/RepoPromptTests.MCPSocketDescriptorHardeningTests/testSuccessiveSameSessionBootstrapAdmissionsDoNotDoubleDiscountReplacement root Tests/RepoPromptTests/MCP/Control/MCPSocketDescriptorHardeningTests.swift RepoPromptTests.MCPSocketDescriptorHardeningTests testSuccessiveSameSessionBootstrapAdmissionsDoNotDoubleDiscountReplacement MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.047500 unreviewed retain_pending_review 0 initial census source line 78 root/RepoPromptTests.MCPTerminalRecordTests/testDebugFingerprintMatchesDurableTerminalFingerprint root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testDebugFingerprintMatchesDurableTerminalFingerprint MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 173 root/RepoPromptTests.MCPTerminalRecordTests/testFirstTerminalRecordClaimRetriesOriginalRecordWithoutSubstitutingNewCause root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testFirstTerminalRecordClaimRetriesOriginalRecordWithoutSubstitutingNewCause MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 135 -root/RepoPromptTests.MCPTerminalRecordTests/testLegacyRecordDecodesWithNilWatchdogAttribution root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testLegacyRecordDecodesWithNilWatchdogAttribution MCP mcp.terminal_record.legacy_decode_compatibility codable,optional_fields,watchdog_attribution serialization_compatibility root_swiftpm fast 1 legacy_terminal_record_json A pre-attribution terminal record decodes with all seven watchdog attribution fields nil. Older durable diagnostics could become unreadable after the append-only schema extension. in_memory_json test_case retain 0 PR-B1 append-only durable watchdog attribution compatibility root/RepoPromptTests.MCPTerminalRecordTests/testRecordRoundTripUsesTerminalPrefixAndExcludesRawSecrets root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testRecordRoundTripUsesTerminalPrefixAndExcludesRawSecrets MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001500 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.MCPTerminalRecordTests/testSaltedFingerprintIsStableAndDoesNotExposeToken root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testSaltedFingerprintIsStableAndDoesNotExposeToken MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 187 root/RepoPromptTests.MCPTerminalRecordTests/testStoreRetainsNewestTerminalRecordsWithoutTouchingCLIEvents root Tests/RepoPromptTests/MCP/MCPTerminalRecordTests.swift RepoPromptTests.MCPTerminalRecordTests testStoreRetainsNewestTerminalRecordsWithoutTouchingCLIEvents MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 1.371500 unreviewed retain_pending_review 0 initial census source line 62 -root/RepoPromptTests.MCPCodeStructureSettlementRegistryTests/testCancellationFencesAdmissionUntilExactLateSettlement root Tests/RepoPromptTests/MCP/Control/MCPCodeStructureSettlementRegistryTests.swift RepoPromptTests.MCPCodeStructureSettlementRegistryTests testCancellationFencesAdmissionUntilExactLateSettlement MCP mcp.tool_execution.structure_settlement_cancellation request_cancellation,busy_loop,late_settlement,lease_identity concurrency_contract root_swiftpm fast 7 MCPCodeStructureSettlementRegistry Cancellation synchronously fences three retries as abandoned; exact late settlement lifts busy, and stale completion cannot clear a replacement lease. An externally canceled provider could become invisible, admit overlapping retries, or clear a newer invocation's fence. concurrency method_local_registry test_case retain 0 Replaces cancellation and generation-safety scenarios from testAdmissionPreservesSecondCallAndUsesGenerationSafeDetachedBusySlot -root/RepoPromptTests.MCPCodeStructureSettlementRegistryTests/testCancellationDuringDetachingBecomesAbandonedWithoutDowngradingDetached root Tests/RepoPromptTests/MCP/Control/MCPCodeStructureSettlementRegistryTests.swift RepoPromptTests.MCPCodeStructureSettlementRegistryTests testCancellationDuringDetachingBecomesAbandonedWithoutDowngradingDetached MCP mcp.tool_execution.structure_settlement_cancel_races detaching,cancellation,idempotence,detached_no_downgrade concurrency_contract root_swiftpm fast 6 MCPCodeStructureSettlementRegistry Cancellation during detaching becomes abandoned, activation is rejected, and cancellation after detached leaves detached ownership intact until settlement. Cancellation races could downgrade or prematurely release the sole zombie fence. concurrency method_local_registry test_case retain 0 Expands race coverage from testAdmissionPreservesSecondCallAndUsesGenerationSafeDetachedBusySlot -root/RepoPromptTests.MCPCodeStructureSettlementRegistryTests/testGraceExpiryPromotesAfterCompetingLeaseSettles root Tests/RepoPromptTests/MCP/Control/MCPCodeStructureSettlementRegistryTests.swift RepoPromptTests.MCPCodeStructureSettlementRegistryTests testGraceExpiryPromotesAfterCompetingLeaseSettles MCP mcp.tool_execution.structure_settlement_grace_promotion grace_expiry,promotion,busy_gating,late_settlement concurrency_contract root_swiftpm fast 5 MCPCodeStructureSettlementRegistry A competing lease settles before grace expiry, so the remaining lease atomically promotes to detach and fences retries until late settlement. Freezing force-disconnect at initial admission could destroy a healthy connection instead of using newly available detach capacity. concurrency method_local_registry test_case retain 0 Replaces detach-eligibility scenarios from testAdmissionPreservesSecondCallAndUsesGenerationSafeDetachedBusySlot -root/RepoPromptTests.MCPCodeStructureSettlementRegistryTests/testCompetingCancellationIsAbandonedAndSettlesThroughAbandonedPath root Tests/RepoPromptTests/MCP/Control/MCPCodeStructureSettlementRegistryTests.swift RepoPromptTests.MCPCodeStructureSettlementRegistryTests testCompetingCancellationIsAbandonedAndSettlesThroughAbandonedPath MCP mcp.tool_execution.structure_settlement_competing_cancellation request_cancellation,abandoned,busy_reason,late_settlement concurrency_contract root_swiftpm fast 7 MCPCodeStructureSettlementRegistry Two admitted calls canceled behind the same fence both remain abandoned, the busy reason stays abandoned, and each exact late settlement clears only its own lease. Misclassifying request cancellation as force-disconnection could omit the terminal cancellation trace or report the wrong retry reason. concurrency method_local_registry test_case retain 0 Fable post-implementation cancellation-path correction -root/RepoPromptTests.MCPCodeStructureSettlementRegistryTests/testGraceExpiryBehindZombieForceDisconnectsWithoutClearingFirstLease root Tests/RepoPromptTests/MCP/Control/MCPCodeStructureSettlementRegistryTests.swift RepoPromptTests.MCPCodeStructureSettlementRegistryTests testGraceExpiryBehindZombieForceDisconnectsWithoutClearingFirstLease MCP mcp.tool_execution.structure_settlement_grace_force_disconnect grace_expiry,force_disconnect,abandoned,lease_identity concurrency_contract root_swiftpm fast 7 MCPCodeStructureSettlementRegistry A grace-expiring call behind an abandoned lease enters the actual force-disconnect path, and its settlement cannot clear the first invocation's busy fence. A competing grace expiry could incorrectly detach a second call or release another invocation's fence. concurrency method_local_registry test_case retain 0 Split from the former combined zombie-bound regression root/RepoPromptTests.MCPToolAdmissionPolicyTests/testClassificationExhaustivelyCoversCanonicalCatalogWithoutDefault root Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift RepoPromptTests.MCPToolAdmissionPolicyTests testClassificationExhaustivelyCoversCanonicalCatalogWithoutDefault MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.MCPToolAdmissionPolicyTests/testGateBCapacitiesRecordConservativeWI3BaselineChoices root Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift RepoPromptTests.MCPToolAdmissionPolicyTests testGateBCapacitiesRecordConservativeWI3BaselineChoices MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 53 root/RepoPromptTests.MCPToolAdmissionPolicyTests/testGitAdmissionSerializesLinkedWorktreesByCommonDirectory root Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift RepoPromptTests.MCPToolAdmissionPolicyTests testGitAdmissionSerializesLinkedWorktreesByCommonDirectory MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.823000 unreviewed retain_pending_review 0 initial census source line 290 @@ -2116,12 +2005,7 @@ root/RepoPromptTests.MCPToolExecutionContractTests/testMissingClassificationIsDe root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testAppWideExclusiveResourceReleasesBeforeFormattingTail root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testAppWideExclusiveResourceReleasesBeforeFormattingTail MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.277500 unreviewed retain_pending_review 0 initial census source line 242 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testAskUserLifecycleExemptionDoesNotInstallExecutionWatchdog root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testAskUserLifecycleExemptionDoesNotInstallExecutionWatchdog MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.297000 unreviewed retain_pending_review 0 initial census source line 387 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testBoundedFileToolsEmitHandlerCompletionAndConnectionRemainsUsable root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testBoundedFileToolsEmitHandlerCompletionAndConnectionRemainsUsable MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.291000 unreviewed retain_pending_review 0 initial census source line 11 -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testHistoryPartialResultLeavesPersistentConnectionUsable root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testHistoryPartialResultLeavesPersistentConnectionUsable MCP/History history.watchdog.partial_connection_survival history_mcp,persistent_connection,watchdog,partial_result integration_regression root_swiftpm routine 1 PersistentMCPTestFixture A warning-grade bounded history partial completes its handler and the same persistent MCP connection successfully serves a follow-up tools/list request without becoming watchdog-terminal. History could return a partial payload yet still poison the transport and force an app restart before the next MCP request. in_process_mcp;persistent_connection;operation_override MCPSharedServerTestLease test_case retain 0 Track B same-connection transport-survival regression; no visible app lifecycle. root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testBoundedWindowAndGlobalDispatchBranchesReturnOneTimeoutAndKeepConnectionUsable root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testBoundedWindowAndGlobalDispatchBranchesReturnOneTimeoutAndKeepConnectionUsable MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.344000 unreviewed retain_pending_review 0 initial census source line 633 -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testManageSelectionWatchdogPersistsAttributedTerminalRecordThroughPeerPIDGuard root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testManageSelectionWatchdogPersistsAttributedTerminalRecordThroughPeerPIDGuard MCP mcp.watchdog.durable_attribution manage_selection,peer_pid_guard,first_claim,force_disconnect_contract,phase_age persistent_socket_integration root_swiftpm routine 1 PersistentMCPTestFixture,ExecutionWatchdogManualClock,MCPExecutionIgnoringCancellationGate An uncooperative manage_selection call crosses deadline and grace under its force-disconnect contract, closes its socket, and writes one attributed app terminal record after the bootstrap peer-PID guard. Force-disconnect watchdog closures could remain unattributed or tests could bypass the production persistence guard. filesystem,socketpair,actor,manual_clock ServerNetworkManager.shared shared_server_lease+fixture_cleanup retain 0 PR-B1 real guarded persistence coverage using an injected writer destination -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testCancelledCodeStructureFencesDetachClassToolsUntilLateSettlementAndKeepsConnectionUsable root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testCancelledCodeStructureFencesDetachClassToolsUntilLateSettlementAndKeepsConnectionUsable MCP mcp.tool_execution.abandoned_structure_end_to_end request_cancellation,abandoned_busy,repeat_retry,detach_class_fence,manage_selection_liveness,late_settlement,single_call_provider_bound persistent_transport_regression root_swiftpm routine 7 PersistentMCPTestFixture,ExecutionWatchdogManualClock,MCPCodeStructureSettlementProviderProbe For one canceled uncooperative structure call, the abandoned fence keeps three retries and detach-class read_file out of provider entry with typed generic busy, leaves manage_selection usable without terminal disconnect, and exact late settlement restores read and structure admission without overlap beyond that single abandoned call. Request cancellation could release the lane before recording hidden provider ownership, allowing same-window detach-class overlap, stalling unrelated tools, or leaving admission fenced after settlement drains. local_socket,concurrency,virtual_clock shared_mcp_server_lease fixture_lexical_scope retain 0 Settlement lifecycle regression; PR487 coverage is coexistence only -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testDetachedCodeStructureTimeoutKeepsConnectionUsableAndDrainsLateProvider root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testDetachedCodeStructureTimeoutKeepsConnectionUsableAndDrainsLateProvider MCP mcp.tool_execution.detached_structure_end_to_end manual_clock,thirty_seconds,five_seconds,same_connection,busy,late_diagnostics,permit_release persistent_transport_regression root_swiftpm routine 12 PersistentMCPTestFixture,ExecutionWatchdogManualClock,MCPCodeStructureSettlementProviderProbe Virtual time reaches 36 seconds; the second legal structure call completes, the first returns typed detached timeout without terminal closure, read_file succeeds on the same connection, busy is stable while detached, and eventual drain emits only detached-settled diagnostics with inactive ownership dimensions. The watchdog could close a healthy connection, retain permits, publish a second result, admit multiple detached providers, or leak its settlement slot and sleepers. 0.400000 local_socket,concurrency,virtual_clock shared_mcp_server_lease,test_debug_capture fixture_lexical_scope retain 0 PR-B2 persistent same-connection settlement regression -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testLateCompletionTraceDoesNotClaimCancellationWasRequested root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testLateCompletionTraceDoesNotClaimCancellationWasRequested MCP mcp.tool_execution.late_completion_trace persistent_mcp,absolute_deadline,operation_event_first,no_false_cancellation,cleanup persistent_transport_regression root_swiftpm routine 4 PersistentMCPTestFixture,ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,MCPExecutionIgnoringCancellationGate A late read_file completion returns the timeout reply and traces one deadline plus settledDuringGrace with cancellation_requested=false, no cancellation origin or cancellation-requested phase, grace_outcome=late_completion, and no residual virtual work. Timestamp-correct timeout classification could still publish misleading cancellation diagnostics or leak watchdog work. local_socket,concurrency,virtual_clock shared_mcp_server_lease,test_debug_capture fixture_lexical_scope retain 0 Persistent MCP trace contract for the inverse event ordering. root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testLongRunningFileSearchSurvivesFormerWatchdogAndHonorsCallerCancellation root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testLongRunningFileSearchSurvivesFormerWatchdogAndHonorsCallerCancellation MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.339500 unreviewed retain_pending_review 0 initial census source line 478 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testManageSelectionAndFileActionsReportReplyConstructionPhase root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testManageSelectionAndFileActionsReportReplyConstructionPhase MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.262500 unreviewed retain_pending_review 0 initial census source line 334 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testManageWorkspacesCreateDeleteAndListSelectExactContracts root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testManageWorkspacesCreateDeleteAndListSelectExactContracts MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.359000 unreviewed retain_pending_review 0 initial census source line 915 @@ -2133,25 +2017,15 @@ root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testRealManageSele root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testSameWindowExclusiveResourceReleasesBeforeCompletionObserverTail root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testSameWindowExclusiveResourceReleasesBeforeCompletionObserverTail MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.253000 unreviewed retain_pending_review 0 initial census source line 67 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testSameWindowSmallReadResourcesReleaseBeforeFormattingTail root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testSameWindowSmallReadResourcesReleaseBeforeFormattingTail MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.251500 unreviewed retain_pending_review 0 initial census source line 149 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testUncooperativeManageWorkspacesSwitchForceDisconnectsAndBlocksQueuedProviderEntry root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testUncooperativeManageWorkspacesSwitchForceDisconnectsAndBlocksQueuedProviderEntry MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.298500 unreviewed retain_pending_review 0 initial census source line 1047 -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testUncooperativeSmallReadsDetachFirstThenForceDisconnectCompetingExpiryAndFenceQueuedCall root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testUncooperativeSmallReadsDetachFirstThenForceDisconnectCompetingExpiryAndFenceQueuedCall MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.276000 unreviewed retain_pending_review 0 initial census source line 1669 +root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testUncooperativeSmallReadDeadlineForceDisconnectsAndCallBeyondCapacityNeverEntersProvider root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testUncooperativeSmallReadDeadlineForceDisconnectsAndCallBeyondCapacityNeverEntersProvider MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.276000 unreviewed retain_pending_review 0 initial census source line 1669 root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testWindowIDInjectionAndExplicitValueReachResolvedProviderArguments root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testWindowIDInjectionAndExplicitValueReachResolvedProviderArguments MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.232500 unreviewed retain_pending_review 0 initial census source line 1618 -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCancellationLatchCancelsGraceTaskAppendedAfterExternalCancellation root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testCancellationLatchCancelsGraceTaskAppendedAfterExternalCancellation MCP mcp.tool_execution.task_cancellation_latch request_cancellation,grace_registration,append_after_cancel,sleeper_cleanup concurrency_contract root_swiftpm routine 3 ExecutionWatchdogManualClock,ExecutionWatchdogCallbackGate,ExecutionWatchdogUncooperativeGate When external cancellation latches the task store before grace registration resumes, the subsequently appended grace task is canceled immediately and leaves no sleeper or registration waiter. Clearing the current task list without a terminal latch could leak a cleanup-grace sleeper appended after cancellation. concurrency,virtual_clock method_local_actors test_case retain 0 Regression for append-after-cancel task ownership. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testExternalCancellationWinsOverQueuedOnTimeCompletion root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testExternalCancellationWinsOverQueuedOnTimeCompletion MCP mcp.tool_execution.external_cancellation_precedence request_cancellation,queued_completion,on_time_completion,cleanup concurrency_contract root_swiftpm routine 3 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,ExecutionWatchdogUncooperativeGate External cancellation returns CancellationError even when an on-time completion is already queued, emits only request cancellation, and drains sleepers and scheduler waiters. A queued successful completion could override caller cancellation or retain watchdog work. concurrency,virtual_clock method_local_actors test_case retain 0 Cancellation precedence for queued on-time completion. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCompletionAtDeadlineTimesOutWithoutRequestingCancellation root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testCompletionAtDeadlineTimesOutWithoutRequestingCancellation MCP mcp.tool_execution.deadline_equality absolute_deadline,equality,no_cancellation,cleanup concurrency_contract root_swiftpm routine 3 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate A completion timestamp equal to the absolute deadline returns executionTimedOut(success), emits deadline then settlement without a cancellation request, and leaves no sleeper or scheduler waiter. Using <= could incorrectly accept equality, or timeout cleanup could claim cancellation and leak owned work. concurrency,virtual_clock method_local_actors test_case retain 0 Deadline equality regression; strict completionTime < deadlineInstant contract. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCompletionJustBeforeDeadlineReturnsValueWithoutTimeoutEvents root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testCompletionJustBeforeDeadlineReturnsValueWithoutTimeoutEvents MCP mcp.tool_execution.deadline_precedence absolute_deadline,just_before,success,sleeper_cleanup concurrency_contract root_swiftpm routine 2 ExecutionWatchdogManualClock,ExecutionWatchdogUncooperativeGate A completion one nanosecond before the absolute deadline returns its value with no timeout events and no remaining sleeper. Consumer scheduling or an inclusive boundary could reject an on-time provider result. concurrency,virtual_clock method_local_actors test_case retain 0 Renamed root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCompletionBeforeDeadlineReturnsValueWithoutTimeoutEvents -> root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCompletionJustBeforeDeadlineReturnsValueWithoutTimeoutEvents; strengthened with virtual-time boundary and cleanup. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testDeadlineEventConsumedFirstRejectsLateCompletionRecordedBeforeConsumption root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testDeadlineEventConsumedFirstRejectsLateCompletionRecordedBeforeConsumption MCP mcp.tool_execution.deadline_precedence deadline_event_first,late_completion,event_consumption,no_cancellation,cleanup concurrency_contract root_swiftpm routine 4 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,ExecutionWatchdogUncooperativeGate When deadline consumption is paused and a later completion is atomically recorded, timeout wins with deadline/settlement events, no cancellation request, and no lingering sleeper or waiter. The old un-timestamped state allowed a post-deadline result to win when deadline consumption was delayed. concurrency,virtual_clock method_local_actors test_case retain 0 Direct regression for deadline-first late-completion race. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testExternalCancellationWinsOverStoredLateCompletion root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testExternalCancellationWinsOverStoredLateCompletion MCP mcp.tool_execution.external_cancellation_precedence request_cancellation,stored_completion,late_completion,cleanup concurrency_contract root_swiftpm routine 3 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,ExecutionWatchdogUncooperativeGate External cancellation returns CancellationError despite a stored late completion, emits only request cancellation, and drains sleepers and scheduler waiters. A queued late completion could override caller cancellation or retain watchdog tasks. concurrency,virtual_clock method_local_actors test_case retain 0 Cancellation remains authoritative over queued completion consumption. -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testLateOperationEventConsumedBeforeAlreadyDueDeadlineStillTimesOut root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testLateOperationEventConsumedBeforeAlreadyDueDeadlineStillTimesOut MCP mcp.tool_execution.deadline_precedence operation_event_first,already_due_deadline,late_completion,trace_sequence,cleanup concurrency_contract root_swiftpm routine 4 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,ExecutionWatchdogUncooperativeGate A late operation event consumed before an already-produced deadline event still times out, emits deadline then settlement without a false cancellation request, and drains all waiters. Event-consumer ordering could allow late success or falsely report watchdog cancellation. concurrency,virtual_clock method_local_actors test_case retain 0 Inverse deterministic ordering regression. +root/RepoPromptTests.MCPToolExecutionWatchdogTests/testCompletionBeforeDeadlineReturnsValueWithoutTimeoutEvents root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testCompletionBeforeDeadlineReturnsValueWithoutTimeoutEvents MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.MCPToolExecutionWatchdogTests/testDeadlineCancelsCooperativeOperationAndReturnsSingleTimeout root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testDeadlineCancelsCooperativeOperationAndReturnsSingleTimeout MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011000 unreviewed retain_pending_review 0 initial census source line 25 root/RepoPromptTests.MCPToolExecutionWatchdogTests/testDeadlineStartsCancellationGraceBeforeAwaitingDiagnostics root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testDeadlineStartsCancellationGraceBeforeAwaitingDiagnostics MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011500 unreviewed retain_pending_review 0 initial census source line 57 -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testDetachAndSettleReturnsWithoutJoiningAndReportsLateSettlement root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testDetachAndSettleReturnsWithoutJoiningAndReportsLateSettlement MCP mcp.tool_execution.watchdog_detach_lifetime manual_clock,cleanup_grace,late_settlement,no_join,sleeper_cleanup concurrency_contract root_swiftpm routine 6 ExecutionWatchdogManualClock,ExecutionWatchdogUncooperativeGate Grace expiry returns executionDetached without joining, emits the exact watchdog-origin detach phases, cancels every clock sleeper, and later reports one success settlement after provider release. A structured join, lost callback, or residual sleeper could hang the timeout response or leak watchdog resources. 0.025000 concurrency,virtual_clock method_local_actors test_case retain 0 PR-B2 watchdog lifetime handoff contract root/RepoPromptTests.MCPToolExecutionWatchdogTests/testExternalCancellationCancelsOwnedTasksAndPropagatesCancellation root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testExternalCancellationCancelsOwnedTasksAndPropagatesCancellation MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011000 unreviewed retain_pending_review 0 initial census source line 199 root/RepoPromptTests.MCPToolExecutionWatchdogTests/testHandlerPhaseRecorderUsesWatchdogClockAndFormatsEscalationContext root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testHandlerPhaseRecorderUsesWatchdogClockAndFormatsEscalationContext MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 160 root/RepoPromptTests.MCPToolExecutionWatchdogTests/testManualClockAdvancesElapsedTimeWithoutRegisteredSleepers root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testManualClockAdvancesElapsedTimeWithoutRegisteredSleepers MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 135 root/RepoPromptTests.MCPToolExecutionWatchdogTests/testManualClockRejectsElapsedAdvanceWhileSleeperIsRegistered root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testManualClockRejectsElapsedAdvanceWhileSleeperIsRegistered MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.011000 unreviewed retain_pending_review 0 initial census source line 144 -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testSettlementDuringDetachActivationReportsSettledDuringGrace root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testSettlementDuringDetachActivationReportsSettledDuringGrace MCP mcp.tool_execution.watchdog_detach_activation_settlement manual_clock,detaching,settled_during_grace,synchronous_settlement concurrency_contract root_swiftpm fast 6 ExecutionWatchdogManualClock,ExecutionWatchdogUncooperativeGate,MCPCodeStructureSettlementRegistry Completion observed between detach resolution and activation emits synchronous settled-during-grace semantics and returns executionTimedOut instead of falsely reporting a detached execution. A resolved completion could be mislabeled detached, producing contradictory trace and settlement ownership. concurrency,virtual_clock method_local_actors test_case retain 0 Fable post-implementation detach truthfulness correction -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testSlotCompletionJustBeforeDeadlineReturnsValueAndReleasesLease root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testSlotCompletionJustBeforeDeadlineReturnsValueAndReleasesLease MCP mcp.tool_execution.watchdog_slot_deadline_precedence manual_clock,just_before,success,lease_release,sleeper_cleanup concurrency_contract root_swiftpm fast 4 ExecutionWatchdogManualClock,ExecutionWatchdogUncooperativeGate,MCPCodeStructureSettlementRegistry A slot-admitted completion one nanosecond before the absolute deadline returns its value with no timeout events, releases the invocation lease, and leaves no sleeper. Slot admission could perturb the on-time success path or leak the settlement lease after synchronous success. concurrency,virtual_clock method_local_actors test_case retain 0 Split from testSlotCompletionQueuedBehindDeadlineReturnsSuccessfulResult in the PR #575/#576 semantic reconciliation -root/RepoPromptTests.MCPToolExecutionWatchdogTests/testSlotCompletionRecordedBeforeDeadlineConsumptionSettlesLeaseAndTimesOut root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testSlotCompletionRecordedBeforeDeadlineConsumptionSettlesLeaseAndTimesOut MCP mcp.tool_execution.watchdog_slot_deadline_mailbox manual_clock,event_queue,completion_mailbox,absolute_deadline,late_completion,lease_release concurrency_contract root_swiftpm fast 6 ExecutionWatchdogManualClock,ExecutionWatchdogSchedulingGate,ExecutionWatchdogUncooperativeGate,MCPCodeStructureSettlementRegistry A slot completion recorded while deadline consumption is paused is recovered through the one-shot mailbox, settles its lease synchronously, and still times out under absolute-timestamp authority with settledDuringGrace(cancellation_requested=false). Without slot-path completion recovery, event scheduling could discard a provider settlement already accepted by the registry; without timestamp authority, delayed consumption could let a post-deadline result win. concurrency,virtual_clock method_local_actors test_case retain 0 Renamed root/RepoPromptTests.MCPToolExecutionWatchdogTests/testSlotCompletionQueuedBehindDeadlineReturnsSuccessfulResult -> root/RepoPromptTests.MCPToolExecutionWatchdogTests/testSlotCompletionRecordedBeforeDeadlineConsumptionSettlesLeaseAndTimesOut; re-expressed under PR #575 absolute-deadline authority. root/RepoPromptTests.MCPToolExecutionWatchdogTests/testUncooperativeOperationEscalatesAfterCleanupGraceWithoutJoiningIt root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogTests.swift RepoPromptTests.MCPToolExecutionWatchdogTests testUncooperativeOperationEscalatesAfterCleanupGraceWithoutJoiningIt MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.023500 unreviewed retain_pending_review 0 initial census source line 98 root/RepoPromptTests.ManageWorktreeToolServiceTests/testManageWorktreeReplyEncodesSnakeCaseVisualBindingFields root Tests/RepoPromptTests/MCP/ManageWorktreeToolServiceTests.swift RepoPromptTests.ManageWorktreeToolServiceTests testManageWorktreeReplyEncodesSnakeCaseVisualBindingFields MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.002000 unreviewed retain_pending_review 0 initial census source line 19 root/RepoPromptTests.ManageWorktreeToolServiceTests/testWorktreeManageCapabilityRoutingAndRemovedAliasPolicy root Tests/RepoPromptTests/MCP/ManageWorktreeToolServiceTests.swift RepoPromptTests.ManageWorktreeToolServiceTests testWorktreeManageCapabilityRoutingAndRemovedAliasPolicy MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 7 @@ -2206,9 +2080,6 @@ root/RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests/testHardReadError root/RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests/testReentrantReadableEventDoesNotNestFrameDelivery root Tests/RepoPromptTests/MCP/NewlineDelimitedSocketReaderFairnessTests.swift RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests testReentrantReadableEventDoesNotNestFrameDelivery MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 139 root/RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests/testSplitAndMultipleFramesPreserveOrderAcrossReadableEvents root Tests/RepoPromptTests/MCP/NewlineDelimitedSocketReaderFairnessTests.swift RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests testSplitAndMultipleFramesPreserveOrderAcrossReadableEvents MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 48 root/RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests/testStopDuringFrameDeliveryCancelsSourceAndSuppressesBufferedFrames root Tests/RepoPromptTests/MCP/NewlineDelimitedSocketReaderFairnessTests.swift RepoPromptTests.NewlineDelimitedSocketReaderFairnessTests testStopDuringFrameDeliveryCancelsSourceAndSuppressesBufferedFrames MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 184 -root/RepoPromptTests.NonProseURLLinkificationBoundaryTests/testNSTextViewHelperDisablesAutomaticURLDetection root Tests/RepoPromptTests/AgentMode/ToolCards/NonProseURLLinkificationBoundaryTests.swift RepoPromptTests.NonProseURLLinkificationBoundaryTests testNSTextViewHelperDisablesAutomaticURLDetection AgentMode/UI agent_mode.non_prose_url_detection.text_view_flags non_prose,url_detection,data_detection,appkit regression root_swiftpm fast 1 The helper clears both automatic link and automatic data detection flags on an NSTextView. AppKit could independently re-link URLs in output surfaces that intentionally bypass prose linkification. appkit test_case retain 0 PR #684 rebased PR #70 non-prose boundary coverage. -root/RepoPromptTests.NonProseURLLinkificationBoundaryTests/testToolScrollableMarkdownTextViewRendersToolOutputWithoutLinks root Tests/RepoPromptTests/AgentMode/ToolCards/NonProseURLLinkificationBoundaryTests.swift RepoPromptTests.NonProseURLLinkificationBoundaryTests testToolScrollableMarkdownTextViewRendersToolOutputWithoutLinks AgentMode/UI agent_mode.non_prose_url_detection.tool_output tool_output,non_prose,url_detection,attributed_string regression root_swiftpm fast 1 The tool-output text view preserves the exact text, disables automatic detectors, and contains no link attributes. Tool results could become interactive prose and create accidental navigation targets. appkit test_case retain 0 PR #684 rebased PR #70 tool-output boundary coverage. -root/RepoPromptTests.NonProseURLLinkificationBoundaryTests/testUnifiedDiffAttributedTextDoesNotAddLinksForURLsInDiffLines root Tests/RepoPromptTests/AgentMode/ToolCards/NonProseURLLinkificationBoundaryTests.swift RepoPromptTests.NonProseURLLinkificationBoundaryTests testUnifiedDiffAttributedTextDoesNotAddLinksForURLsInDiffLines AgentMode/UI agent_mode.non_prose_url_detection.unified_diff unified_diff,non_prose,url_detection,added_line,deleted_line regression root_swiftpm fast 1 A rendered unified diff containing URLs in deleted and added lines has no link attributes. Diff content could acquire clickable prose semantics and interfere with review interactions. appkit test_case retain 0 PR #684 rebased PR #70 diff-rendering boundary coverage. root/RepoPromptTests.OpenCodeACPLaunchResolverTests/testBareCommandUsesCapturedEnvironmentAndCachesCanonicalPathForSpawn root Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift RepoPromptTests.OpenCodeACPLaunchResolverTests testBareCommandUsesCapturedEnvironmentAndCachesCanonicalPathForSpawn AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.236500 unreviewed retain_pending_review 0 initial census source line 27 root/RepoPromptTests.OpenCodeACPLaunchResolverTests/testBareCommandWithoutSuccessfulPreflightFailsClosed root Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift RepoPromptTests.OpenCodeACPLaunchResolverTests testBareCommandWithoutSuccessfulPreflightFailsClosed AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 119 root/RepoPromptTests.OpenCodeACPLaunchResolverTests/testCachedIdentityDriftFailsBeforeSpawn root Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift RepoPromptTests.OpenCodeACPLaunchResolverTests testCachedIdentityDriftFailsBeforeSpawn AgentMode unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.161000 unreviewed retain_pending_review 0 initial census source line 207 @@ -2235,10 +2106,6 @@ root/RepoPromptTests.OracleOperationToolCardRoutingTests/testOracleToolCallRouti root/RepoPromptTests.PathMatchingRecoveryTests/testAliasAndAbsoluteResolutionStayScopedToTheMatchingRoot root Tests/RepoPromptTests/WorkspaceContext/PathMatching/PathMatchingRecoveryTests.swift RepoPromptTests.PathMatchingRecoveryTests testAliasAndAbsoluteResolutionStayScopedToTheMatchingRoot WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.PathMatchingRecoveryTests/testMovePathResolverRejectsAmbiguousAndCrossRootAliases root Tests/RepoPromptTests/WorkspaceContext/PathMatching/PathMatchingRecoveryTests.swift RepoPromptTests.PathMatchingRecoveryTests testMovePathResolverRejectsAmbiguousAndCrossRootAliases WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 35 root/RepoPromptTests.PathMatchingRecoveryTests/testUnicodeAndCaseInsensitiveLookupPreserveStoredRelativePath root Tests/RepoPromptTests/WorkspaceContext/PathMatching/PathMatchingRecoveryTests.swift RepoPromptTests.PathMatchingRecoveryTests testUnicodeAndCaseInsensitiveLookupPreserveStoredRelativePath WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 21 -root/RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests/testStandardizedPathsNormalizeAndPreserveContainmentBoundaries root Tests/RepoPromptWorkspaceCoreTests/WorkspacePathPolicyTests.swift RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests testStandardizedPathsNormalizeAndPreserveContainmentBoundaries WorkspaceCore workspace_core.path.standardization_boundaries relative_normalization;join;descendant_boundary;diagnostic_escaping pure_unit isolated_core routine 5 Path normalization, joining, containment, and diagnostic escaping return exact canonical values at path-prefix boundaries. Normalization drift could escape root confinement, conflate sibling prefixes, or render unsafe diagnostics. test_case retain 0 Path-core extraction direct path primitive contract -root/RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests/testAliasResolutionUsesDeterministicGeneratedAliasesForDuplicateNames root Tests/RepoPromptWorkspaceCoreTests/WorkspacePathPolicyTests.swift RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests testAliasResolutionUsesDeterministicGeneratedAliasesForDuplicateNames WorkspaceCore workspace_core.path.generated_alias_resolution duplicate_root_names;generated_alias;longest_alias pure_unit isolated_core routine 3 Duplicate root names receive deterministic parent-qualified aliases and the qualified input resolves to the exact root and remainder. Alias drift could retarget a path to the wrong loaded root. test_case retain 0 Path-core extraction direct alias policy contract -root/RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests/testCreatePreflightRejectsAmbiguousAndImplicitMultiRootPaths root Tests/RepoPromptWorkspaceCoreTests/WorkspacePathPolicyTests.swift RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests testCreatePreflightRejectsAmbiguousAndImplicitMultiRootPaths WorkspaceCore workspace_core.path.create_preflight_multi_root ambiguous_alias;implicit_multi_root pure_unit isolated_core routine 2 Create preflight rejects both duplicate aliases and unqualified paths when multiple roots are visible, with exact structured errors. Create requests could silently target an unintended root. test_case retain 0 Path-core extraction direct create preflight contract -root/RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests/testMovePathResolverRejectsAmbiguousAndCrossRootAliases root Tests/RepoPromptWorkspaceCoreTests/WorkspacePathPolicyTests.swift RepoPromptWorkspaceCoreTests.WorkspacePathPolicyTests testMovePathResolverRejectsAmbiguousAndCrossRootAliases WorkspaceCore workspace_core.path.move_root_confinement cross_root_alias;ambiguous_alias pure_unit isolated_core routine 2 Move resolution returns exact cross-root and ambiguous-alias errors without producing a destination. Move requests could cross root authority or choose an ambiguous destination. test_case retain 0 Direct owning-core coverage; existing app integration coverage remains retained root/RepoPromptTests.PathSearchIndexRecoveryTests/testSearchMatchesFilenameSubpathTokensAndPublishesDeterministicRankMetadata root Tests/RepoPromptTests/WorkspaceContext/Search/PathSearchIndexRecoveryTests.swift RepoPromptTests.PathSearchIndexRecoveryTests testSearchMatchesFilenameSubpathTokensAndPublishesDeterministicRankMetadata WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.005000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.PersistentAgentModeMCPReadFileConnectionTests/testAgentOwnedExplicitSetPersistsForIndependentCanonicalLookup root Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift RepoPromptTests.PersistentAgentModeMCPReadFileConnectionTests testAgentOwnedExplicitSetPersistsForIndependentCanonicalLookup MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.541500 unreviewed retain_pending_review 0 initial census source line 28 root/RepoPromptTests.PersistentAgentModeMCPReadFileConnectionTests/testAgentOwnedHiddenWorktreeWatcherRebases6500LineReadSlicesBeforePostEditReads root Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift RepoPromptTests.PersistentAgentModeMCPReadFileConnectionTests testAgentOwnedHiddenWorktreeWatcherRebases6500LineReadSlicesBeforePostEditReads MCP mcp.hidden_session_worktree.read_slice_watcher_rebase persistent_agent,read_file,6500_lines,watcher_rebase,physical_logical_mapping,full_selection_dominance,no_hidden_ui_tree,stale_deferred_commit,partition_cas deterministic_integration root_swiftpm routine 5 PersistentAgentModeMCPConnectionFixture,SessionWorktreeOwnershipFixture,WorkspaceSelectionSliceFixture Three canonical read_file slices rebase exactly after atomic replacement; a gated successor cannot resurrect a concurrently removed logical target or physical partition entry; the hidden root never projects into UI and later reads cannot downgrade a full selection. critical 1.386500 socketpair,temporary_worktree,actor_store,watcher_publisher,async_tasks test_fixture+explicit_root_unload retain 0 hidden session-root watcher rebase, stale deferred partition/target fencing, and full-file-wins integration @@ -2337,7 +2204,6 @@ root/RepoPromptTests.PromptContextPreAssemblyServiceTests/testSliceOnlyAuthorize root/RepoPromptTests.PromptContextPreAssemblyServiceTests/testStrictReviewRejectedArtifactNeverInvokesAutomaticFallback root Tests/RepoPromptTests/Prompt/PromptContextPreAssemblyServiceTests.swift RepoPromptTests.PromptContextPreAssemblyServiceTests testStrictReviewRejectedArtifactNeverInvokesAutomaticFallback Prompt prompt.preassembly.strict_rejected_artifact strict_authorization,rejected_artifact,content_unreadable,fail_closed,no_fallback deterministic_filesystem_integration root_swiftpm routine 1 ArtifactFixture,ProviderCapture An artifact rejected during strict reauthorization fails before automatic fallback is invoked. A deleted or unreadable selected artifact could be replaced by an unrelated automatic diff. 0.293000 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Issue #264 Batch 3 regression root/RepoPromptTests.PromptContextPreAssemblyServiceTests/testStrictReviewRejectsChangedArtifactProvenanceBeforeAutomaticFallback root Tests/RepoPromptTests/Prompt/PromptContextPreAssemblyServiceTests.swift RepoPromptTests.PromptContextPreAssemblyServiceTests testStrictReviewRejectsChangedArtifactProvenanceBeforeAutomaticFallback Prompt prompt.preassembly.strict_changed_provenance strict_authorization,artifact_provenance,fail_closed,no_fallback deterministic_filesystem_integration root_swiftpm routine 1 ArtifactFixture,ProviderCapture Changed artifact checkout provenance fails before automatic fallback is invoked. Packaging could mask provenance drift by silently generating a different automatic diff. 0.295000 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Issue #264 Batch 3 regression root/RepoPromptTests.PromptContextPreAssemblyServiceTests/testStrictReviewRejectsMismatchedFrozenGitContextBeforeFallback root Tests/RepoPromptTests/Prompt/PromptContextPreAssemblyServiceTests.swift RepoPromptTests.PromptContextPreAssemblyServiceTests testStrictReviewRejectsMismatchedFrozenGitContextBeforeFallback Prompt prompt.preassembly.strict_frozen_git_context strict_authorization,compare_intent,delegation_consumer,frozen_context,fail_closed,no_fallback deterministic_filesystem_integration root_swiftpm routine 1 ArtifactFixture,ProviderCapture Strict review packaging rejects any separately supplied Git context that differs from the context frozen into final authorization. A changed compare base or delegation consumer could be paired with otherwise valid final authority and alter packaged review context. 0.294000 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Issue #264 Batch 3 holistic review finding regression -root/RepoPromptTests.PromptContextPreAssemblyServiceTests/testSelectedUnavailableCodemapOmitsNilFallbackReadAndReportsLogicalMissingPath root Tests/RepoPromptTests/Prompt/PromptContextPreAssemblyServiceTests.swift RepoPromptTests.PromptContextPreAssemblyServiceTests testSelectedUnavailableCodemapOmitsNilFallbackReadAndReportsLogicalMissingPath Prompt prompt.preassembly.codemap_unavailable_missing_path selected,unavailable,nil_fallback,logical_path integration_contract root_swiftpm routine 1 WorkspaceRootBindingProjectionFixture Selected unavailable CodeMap content performs no nil fallback read and reports the logical missing path. Prompt assembly could read outside the authoritative presentation or omit the missing-path diagnostic. 0.100000 filesystem,concurrency test_case retain 0 Inherited live-ID ledger drift reconciled during Item 3 authoritative verify-ledger pass root/RepoPromptTests.PromptContextResolvedFileTreeTests/testResolvedFileTreeRenderingTruthTable root Tests/RepoPromptTests/Prompt/PromptContextResolvedFileTreeTests.swift RepoPromptTests.PromptContextResolvedFileTreeTests testResolvedFileTreeRenderingTruthTable Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.PromptMigrationRemovalTests/testLegacyCopyOverridesAndCustomizationsIgnoreRemovedFields root Tests/RepoPromptTests/Prompt/PromptMigrationRemovalTests.swift RepoPromptTests.PromptMigrationRemovalTests testLegacyCopyOverridesAndCustomizationsIgnoreRemovedFields Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 59 root/RepoPromptTests.PromptMigrationRemovalTests/testLegacyCopyPresetEditAndMCPFieldsDecodeSafelyAndDoNotReencode root Tests/RepoPromptTests/Prompt/PromptMigrationRemovalTests.swift RepoPromptTests.PromptMigrationRemovalTests testLegacyCopyPresetEditAndMCPFieldsDecodeSafelyAndDoNotReencode Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 34 @@ -2508,17 +2374,10 @@ root/RepoPromptTests.StoreBackedWorkspaceSearchTests/testWatcherQualifiedWarmSea root/RepoPromptTests.StoreBackedWorkspaceSearchTests/testWatcherQualifiedWarmSearchSkipsPerFileMetadataValidation root Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift RepoPromptTests.StoreBackedWorkspaceSearchTests testWatcherQualifiedWarmSearchSkipsPerFileMetadataValidation WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.029000 unreviewed retain_pending_review 0 initial census source line 202 root/RepoPromptTests.StoreBackedWorkspaceSearchTests/testWorkspaceSearchReadinessSnapshotFenceMatchesMainActorAuthorityAcrossGenerationChange root Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift RepoPromptTests.StoreBackedWorkspaceSearchTests testWorkspaceSearchReadinessSnapshotFenceMatchesMainActorAuthorityAcrossGenerationChange WorkspaceContext workspace.search.readiness_snapshot_fence main_actor_equivalence;workspace_switch;generation_supersession async_concurrency root_swiftpm routine 4 WorkspaceManagerComposition;AsyncGate Off-main validation accepts the ready ticket, both authorities reject it inside the generation-advance interval and after switch invalidation, then only the new-generation ticket remains valid high 0.148500 temp_directory;concurrent_tasks;workspace_switch WorkspaceManagerViewModel.workspaceSearchReadinessFence test_case+addTeardownBlock retain 0 Four reviewed lifecycle scenarios cover ready equivalence, in-interval fence invalidation, switch invalidation supersession, and generation replacement root/RepoPromptTests.TabContextRoutingTests/testActiveTabCompatibilityDecisionAllowsOnlyLegacyNonRunScopedCallers root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testActiveTabCompatibilityDecisionAllowsOnlyLegacyNonRunScopedCallers MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 456 -root/RepoPromptTests.TabContextRoutingTests/testAgentRunDetachedStartPreservesCallerBindingAndOwnsChildBySessionID root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunDetachedStartPreservesCallerBindingAndOwnsChildBySessionID MCP mcp.agent_run.caller_binding.detached_preservation caller_binding,detached,session_id,child_control main_actor_production_wiring_integration root_swiftpm routine 1 WindowState,AgentRunMCPToolService,TabContextSnapshot A detached child differs from the source tab, the caller connection remains bound to the source, and the returned session ID controls the child. Agent Run could rebind the caller to the child or return a session ID for the wrong child. window_state WindowStatesManager;ServerNetworkManager per_test_window_teardown retain 0 External Agent Run caller-binding ownership regression. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunDispatchFailureDiscardsChildAndPreservesCallerBinding root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunDispatchFailureDiscardsChildAndPreservesCallerBinding MCP mcp.agent_run.caller_binding.dispatch_failure caller_binding,dispatch_failure,child_cleanup,registration,no_child lifecycle_regression root_swiftpm routine 1 WindowState,AgentRunMCPToolService,TabContextSnapshot,AgentRunSessionStore Post-activation dispatch failure removes the child, deactivates its registration, restores tab counts, and preserves the caller's source binding. Starter or outer cleanup could leave a phantom child, active registration, or displaced caller binding. window_state AgentRunSessionStore;WindowStatesManager;ServerNetworkManager test_case+session_store_cleanup+window_teardown retain 0 External Agent Run post-activation cleanup regression. root/RepoPromptTests.TabContextRoutingTests/testAgentRunExplicitLaunchSourceIsExactAndDoesNotUseActiveTabCompatibility root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunExplicitLaunchSourceIsExactAndDoesNotUseActiveTabCompatibility MCP mcp.agent_run.launch_source.explicit_context explicit_binding,exact_tab,workspace_affinity main_actor_routing_integration root_swiftpm routine 1 WindowState,TabContextSnapshot An explicitly bound launch source resolves its exact workspace/tab without active-tab compatibility. Explicit control could be displaced by mutable active-tab state. window_state WindowStatesManager per_test_window retain 0 Issue #264 explicit-context control. root/RepoPromptTests.TabContextRoutingTests/testAgentRunExplicitWindowLaunchRejectsInferredAndMismatchedRoutes root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunExplicitWindowLaunchRejectsInferredAndMismatchedRoutes MCP mcp.agent_run.launch_source.explicit_window_fail_closed inferred_affinity,connection_identity,tool_identity,effective_window,target_window,target_object_identity,server_identity main_actor_negative_routing root_swiftpm routine 6 WindowState,RequestMetadata Top-level packaging rejects inferred-only affinity plus connection, tool, effective-window, WindowState, and MCPServerViewModel identity mismatches. Sticky or auto routing could be laundered into trusted one-shot packaging authority or cross-window source capture. 0.021500 window_state WindowStatesManager per_test_window retain 0 Issue #264 CLI compatibility fail-closed identity matrix. root/RepoPromptTests.TabContextRoutingTests/testAgentRunLaunchRejectsExplicitContextWindowConflict root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunLaunchRejectsExplicitContextWindowConflict MCP mcp.agent_run.launch_source.window_conflict explicit_hint,window_affinity,fail_closed main_actor_negative_routing root_swiftpm routine 1 WindowState,TabContextHint An explicit context hint whose window conflicts with the target window is rejected before child creation. A cross-window hint could delegate another window's selection or Git capability. 0.023000 window_state WindowStatesManager per_test_window retain 0 Issue #264 negative window-affinity control. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunNonDetachedStartPreservesCallerBindingThroughTerminalWait root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunNonDetachedStartPreservesCallerBindingThroughTerminalWait MCP mcp.agent_run.caller_binding.non_detached_wait caller_binding,non_detached_wait,wait_registration,wait_epoch,wait_cursor,terminal_publication lifecycle_regression root_swiftpm routine 1 WindowState,AgentRunMCPToolService,RunningSessionFixture,WaitCursor One registered waiter receives the exact child terminal publication while the caller connection remains bound to the source tab. The start could skip the genuine wait, publish on a stale epoch, or displace caller affinity during the wait. window_state;live_snapshot_store;concurrent_tasks AgentRunSessionStore;WindowStatesManager;ServerNetworkManager test_case+session_store_cleanup+window_teardown retain 0 External Agent Run genuine non-detached wait regression. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunNonDetachedWaitCancellationPreservesCallerBindingAndChildControl root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunNonDetachedWaitCancellationPreservesCallerBindingAndChildControl MCP mcp.agent_run.caller_binding.wait_cancellation caller_binding,wait_cancellation,waiter_drain,child_control,registration async_concurrency root_swiftpm routine 1 WindowState,AgentRunMCPToolService,RunningSessionFixture,WaitCursor Under a stable non-actionable state, cancellation throws, drains the waiter, preserves the caller binding, and leaves the child controllable. Cancellation could fabricate actionability, leak a waiter, discard the child, or displace caller affinity. window_state;live_snapshot_store;concurrent_tasks AgentRunSessionStore;WindowStatesManager;ServerNetworkManager test_case+session_store_cleanup+window_teardown retain 0 External Agent Run non-detached wait-cancellation regression. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunPreActivationFailureDiscardsCreatedChildAndPreservesCallerBinding root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunPreActivationFailureDiscardsCreatedChildAndPreservesCallerBinding MCP mcp.agent_run.caller_binding.pre_activation_failure caller_binding,pre_activation_failure,child_cleanup,no_registration,no_dispatch lifecycle_regression root_swiftpm routine 1 WindowState,AgentRunMCPToolService,TabContextSnapshot Preparation failure after target creation removes the child, restores counts, creates no registration, dispatches nothing, and preserves the caller's source binding. Outer orchestration could leave a target or mutate caller ownership after preparation failure. window_state WindowStatesManager;ServerNetworkManager per_test_window_teardown retain 0 External Agent Run pre-activation cleanup regression. root/RepoPromptTests.TabContextRoutingTests/testAgentRunPublicStartRejectsInvalidLaunchRoutesBeforeDispatch root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunPublicStartRejectsInvalidLaunchRoutesBeforeDispatch MCP mcp.agent_run.public_start.fail_closed_routes public_start,window_conflict,inferred_affinity,provenance_mismatch,missing_active_tab,missing_run_route,no_dispatch,no_child main_actor_production_wiring_integration root_swiftpm routine 6 WindowState,AgentRunMCPToolService Public production-wired agent_run.start rejects conflicting context, inferred affinity, mismatched one-shot provenance, two invalid run-scoped routes, and missing active compose before provider dispatch while leaving compose tabs unchanged. Invalid source routing could create phantom children, invoke providers, or delegate a mutable or foreign tab. 0.042500 window_state WindowStatesManager per_test_window_teardown retain 0 Issue #264 public fail-closed start boundary. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunStartOverlapRoutesManageSelectionToCallerSourceTab root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunStartOverlapRoutesManageSelectionToCallerSourceTab MCP mcp.agent_run.caller_binding.concurrent_selection caller_binding,concurrent_selection,manage_selection,continuation_gate,source_tab,target_tab async_concurrency root_swiftpm routine 2 WindowState,AgentRunMCPToolService,TabContextSnapshot,ContinuationGate In-flight and post-completion selection mutations route to the source tab only while the child remains unchanged and the caller binding stays on the source. Unauthorized start-time rebinding could reject or route same-connection source selection to the child. window_state;concurrent_tasks WindowStatesManager;ServerNetworkManager per_test_window_teardown retain 0 Two scenarios cover in-flight and post-completion source selection routing. -root/RepoPromptTests.TabContextRoutingTests/testAgentRunStartRejectsMismatchedHintAndPreservesCallerBinding root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunStartRejectsMismatchedHintAndPreservesCallerBinding MCP mcp.agent_run.caller_binding.explicit_hint_mismatch caller_binding,explicit_hint,window_conflict,fail_closed,no_dispatch,no_child main_actor_negative_routing root_swiftpm routine 1 WindowState,AgentRunMCPToolService,RequestMetadata,TabContextSnapshot A mismatched one-shot hint fails before child creation or dispatch while tab count and caller source binding remain unchanged. A one-shot hint could override canonical binding or create a child before fail-closed rejection. window_state WindowStatesManager;ServerNetworkManager per_test_window_teardown retain 0 External Agent Run explicit-hint mismatch regression. root/RepoPromptTests.TabContextRoutingTests/testAgentRunStartWithoutSourceRejectsNestedOriginsButAllowsLegitimateTopLevelOrigins root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunStartWithoutSourceRejectsNestedOriginsButAllowsLegitimateTopLevelOrigins MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 1604 root/RepoPromptTests.TabContextRoutingTests/testAgentRunWindowOnlyLaunchFreezesExactActiveComposeTabWithoutConversationParent root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunWindowOnlyLaunchFreezesExactActiveComposeTabWithoutConversationParent MCP mcp.agent_run.launch_source.window_only window_affinity,active_compose,selection_snapshot,parent_split main_actor_routing_integration root_swiftpm routine 1 WindowState,TabContextSnapshot A window-only top-level launch freezes the exact active compose tab and selection while leaving conversation-parent resolution nil. The child could inherit blank packaging, the wrong tab, or a false parent session. 0.029500 window_state WindowStatesManager per_test_window retain 0 Issue #264 launch-boundary regression. root/RepoPromptTests.TabContextRoutingTests/testAgentRunWindowOnlyLaunchRejectsMissingActiveComposeTabAndRunScopedFallback root Tests/RepoPromptTests/MCP/TabContextRoutingTests.swift RepoPromptTests.TabContextRoutingTests testAgentRunWindowOnlyLaunchRejectsMissingActiveComposeTabAndRunScopedFallback MCP mcp.agent_run.launch_source.fail_closed missing_active_tab,run_scoped,agent_run,discover_run,active_tab_rejection main_actor_negative_routing root_swiftpm routine 3 WindowState,TabContextSnapshot One-shot window routing fails without an active compose tab, and Agent or discover run-scoped metadata cannot use it as active-tab fallback. Ambiguous or missing routes could silently package the blank child or first stored tab. 0.026500 window_state WindowStatesManager per_test_window retain 0 Issue #264 fail-closed routing matrix. @@ -2564,29 +2423,17 @@ root/RepoPromptTests.TestProcessRunnerTests/testDrainsLargeOutputWhileChildIsRun root/RepoPromptTests.TestProcessRunnerTests/testTimeoutReturnsWhenChildProcessKeepsPipeOpen root Tests/RepoPromptTests/Helpers/TestProcessRunnerTests.swift RepoPromptTests.TestProcessRunnerTests testTimeoutReturnsWhenChildProcessKeepsPipeOpen Helpers test_process_runner.timeout_parent_waits_with_pipe_open test_helper,timeout,pipe,child_process subprocess_timeout_regression root_swiftpm routine 1 A shell whose child keeps the output pipe open returns a timeout promptly with the parent output prefix captured. The test helper could hang waiting for pipe EOF after timeout, stalling focused validation. subprocess;wall_clock_timeout test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed pipe-open timeout coverage. root/RepoPromptTests.TestProcessRunnerTests/testTimeoutReturnsWhenExitedParentLeavesChildHoldingPipe root Tests/RepoPromptTests/Helpers/TestProcessRunnerTests.swift RepoPromptTests.TestProcessRunnerTests testTimeoutReturnsWhenExitedParentLeavesChildHoldingPipe Helpers test_process_runner.timeout_exited_parent_child_holds_pipe test_helper,timeout,orphan_child,pipe subprocess_timeout_regression root_swiftpm routine 1 A shell parent that exits while a child holds the pipe still returns within the timeout/grace budget with the expected output prefix. The test helper could block on orphaned pipe holders after the parent exits. subprocess;wall_clock_timeout test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed exited-parent pipe-holder timeout coverage. root/RepoPromptTests.TestProcessRunnerTests/testTimeoutTerminatesProcessAndReportsContext root Tests/RepoPromptTests/Helpers/TestProcessRunnerTests.swift RepoPromptTests.TestProcessRunnerTests testTimeoutTerminatesProcessAndReportsContext Helpers test_process_runner.timeout_terminates_and_reports_context test_helper,timeout,current_directory,partial_output subprocess_timeout_regression root_swiftpm routine 1 temporary_working_directory A timed-out process is terminated and the thrown timeout error reports cwd, timeout duration, captured output, and formatted context. Timeout diagnostics could omit context or fail to terminate the child process. subprocess;filesystem;wall_clock_timeout test_case retain 0 origin/main reconciliation after commits 5c1504f1/dc79e7a4: reviewed timeout termination and diagnostic context coverage. -root/RepoPromptTests.TextDirectionPolicyTests/testAppKitAdaptersPreserveLogicalStringsAndNaturalOverrides root Tests/RepoPromptTests/UI/TextDirectionPolicyTests.swift RepoPromptTests.TextDirectionPolicyTests testAppKitAdaptersPreserveLogicalStringsAndNaturalOverrides UI/TextDirection ui.text_direction.appkit_adapter.logical_string_integrity semantic_roles,appkit,natural_direction,backing_string deterministic_appkit_unit root_swiftpm fast 3 All three roles preserve the exact Unicode scalar sequence; natural prose leaves a seeded RTL direction unchanged while LTR roles update paragraph-style and text-view direction only. Direction application could mutate user text or force prose away from platform-resolved behavior. appkit_text_system test_case retain 0 Issue #650 shared AppKit adapter and backing-string integrity contract. -root/RepoPromptTests.TextDirectionPolicyTests/testRolesMapToSharedBaseAndFrameworkDirections root Tests/RepoPromptTests/UI/TextDirectionPolicyTests.swift RepoPromptTests.TextDirectionPolicyTests testRolesMapToSharedBaseAndFrameworkDirections UI/TextDirection ui.text_direction.role_mapping semantic_roles,appkit,swiftui,natural_direction deterministic_policy_contract root_swiftpm fast 3 Every declared role maps through the shared base decision to the exact optional AppKit and SwiftUI framework directions. Role-mapping drift could force natural prose or leave dedicated code and Markdown code blocks without an LTR base. test_case retain 0 Issue #650 shared semantic direction mapping contract. root/RepoPromptTests.TextFieldMentionHelpersTests/testFileTagClickThenAcceptCommitsClickedSuggestion root Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift RepoPromptTests.TextFieldMentionHelpersTests testFileTagClickThenAcceptCommitsClickedSuggestion Mentions unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.005000 unreviewed retain_pending_review 0 initial census source line 7 root/RepoPromptTests.TextFieldMentionHelpersTests/testSlashSkillClickSurvivesDelayedRefreshCompletionBeforeAccept root Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift RepoPromptTests.TextFieldMentionHelpersTests testSlashSkillClickSurvivesDelayedRefreshCompletionBeforeAccept Mentions unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.087000 unreviewed retain_pending_review 0 initial census source line 42 -root/RepoPromptTests.TextViewRangeSafetyTests/testRestoreSelectionCandidateClampsShorterAndEmptyReplacementsBeforeInstallation root Tests/RepoPromptTests/App/TextViewRangeSafetyTests.swift RepoPromptTests.TextViewRangeSafetyTests testRestoreSelectionCandidateClampsShorterAndEmptyReplacementsBeforeInstallation UI/Markdown ui.markdown.selection_restore.candidate_first attributed_replacement,empty_storage,selection_restore,utf16_clamping deterministic_appkit_unit root_swiftpm fast 2 RecordingSelectionTextView Shorter and empty attributed replacements install only selection candidates clamped to the post-replacement UTF-16 storage length. A stale pre-replacement Markdown selection could be passed through TextKit before later repair. appkit_text_system test_case retain 0 Issue #651 candidate-first selection installation regression coverage. -root/RepoPromptTests.TextViewRangeSafetyTests/testRestoreSelectionCandidateHandlesNSNotFoundAndPreservesLegacyClampBehavior root Tests/RepoPromptTests/App/TextViewRangeSafetyTests.swift RepoPromptTests.TextViewRangeSafetyTests testRestoreSelectionCandidateHandlesNSNotFoundAndPreservesLegacyClampBehavior UI/Shared ui.text_view.selection_restore.legacy_behavior no_op_set,nsnotfound,return_value,scroll_restore deterministic_appkit_unit root_swiftpm fast 4 RecordingSelectionTextView NSNotFound maps to the end caret while the legacy clamp API skips a redundant setter, returns the clamped range, and still scrolls it. Changing the shared seam could regress special AppKit selection handling or existing clamp caller behavior. appkit_text_system test_case retain 0 Issue #651 preserves the exact legacy clampSelectionToCurrentString contract. -root/RepoPromptTests.TextViewRangeSafetyTests/testRestoreSelectionCandidatePreservesUTF16BoundariesAndTruncatesOverrun root Tests/RepoPromptTests/App/TextViewRangeSafetyTests.swift RepoPromptTests.TextViewRangeSafetyTests testRestoreSelectionCandidatePreservesUTF16BoundariesAndTruncatesOverrun UI/Shared ui.text_view.selection_restore.utf16_boundaries combining_marks,emoji,selection_preservation,utf16_overrun deterministic_appkit_unit root_swiftpm fast 3 RecordingSelectionTextView Valid emoji and combining-mark UTF-16 ranges are preserved exactly and an overrunning candidate is truncated to storage bounds. Character-count or grapheme-based clamping could corrupt AppKit UTF-16 selection offsets. appkit_text_system test_case retain 0 Issue #651 shared range boundary regression matrix. -root/RepoPromptTests.TextViewUndoSafeReplacementTests/testCallerPolicyClampsSelectionAfterReplacement root Tests/RepoPromptTests/Mentions/TextViewUndoSafeReplacementTests.swift RepoPromptTests.TextViewUndoSafeReplacementTests testCallerPolicyClampsSelectionAfterReplacement UI/TextField ui.text_field.undo_external.selection_clamping selection_restore,utf16_clamping deterministic_appkit_unit root_swiftpm fast 1 UndoTextViewFixture A shorter full-document replacement restores the prior selection clamped to the new UTF-16 length. External synchronization could restore an out-of-bounds TextKit selection after replacing the document. appkit_text_system test_case retain 0 REPOPROMPT-4D helper-level regression coverage for retained selection policy. -root/RepoPromptTests.TextViewUndoSafeReplacementTests/testExternalReplacementClearsExistingUndoAndRedoStacks root Tests/RepoPromptTests/Mentions/TextViewUndoSafeReplacementTests.swift RepoPromptTests.TextViewUndoSafeReplacementTests testExternalReplacementClearsExistingUndoAndRedoStacks UI/TextField ui.text_field.undo_external.clears_history external_replacement,undo_stack,redo_stack deterministic_appkit_unit root_swiftpm fast 2 UndoTextViewFixture Replacing the full document through the helper clears both a typing undo history and a typing redo history from the supplied manager. Stale TextKit edit actions could target storage ranges from the previous document and crash during later undo or redo. appkit_text_system test_case retain 0 REPOPROMPT-4D helper-level regression coverage for both history directions. -root/RepoPromptTests.TextViewUndoSafeReplacementTests/testReplacementDuringUndoAndRedoDefersHistoryClearUntilTransactionCompletes root Tests/RepoPromptTests/Mentions/TextViewUndoSafeReplacementTests.swift RepoPromptTests.TextViewUndoSafeReplacementTests testReplacementDuringUndoAndRedoDefersHistoryClearUntilTransactionCompletes UI/TextField ui.text_field.undo_external.reentrant_deferred_clear undo_reentrancy,redo_reentrancy,deferred_history_clear deterministic_appkit_unit root_swiftpm fast 2 UndoTextViewFixture Replacements invoked during undo and redo preserve each active transaction's opposite-stack registration, then clear both stacks on the next main-queue turn. Clearing during the transaction could corrupt the in-flight group, while permanently skipping the clear could leave stale TextKit ranges available afterward. appkit_text_system test_case retain 0 REPOPROMPT-4D deferred-clear coverage avoids exception-based assertions. -root/RepoPromptTests.TextViewUndoSafeReplacementTests/testTypingRegistersUndoBeforeExternalReplacement root Tests/RepoPromptTests/Mentions/TextViewUndoSafeReplacementTests.swift RepoPromptTests.TextViewUndoSafeReplacementTests testTypingRegistersUndoBeforeExternalReplacement UI/TextField ui.text_field.undo_external.typing_baseline textkit_typing,undo_registration deterministic_appkit_unit root_swiftpm fast 1 UndoTextViewFixture A real NSTextView insert registers undo with its coordinator-style manager and restores the original document when undone. A false-positive regression harness could pass without exercising TextKit typing undo at all. appkit_text_system test_case retain 0 REPOPROMPT-4D baseline proves the AppKit undo path used by subsequent helper tests. -root/RepoPromptTests.TextViewUndoSafeReplacementTests/testTypingUndoResumesFromExternallyReplacedDocument root Tests/RepoPromptTests/Mentions/TextViewUndoSafeReplacementTests.swift RepoPromptTests.TextViewUndoSafeReplacementTests testTypingUndoResumesFromExternallyReplacedDocument UI/TextField ui.text_field.undo_external.new_document_baseline external_replacement,textkit_typing,undo_resume deterministic_appkit_unit root_swiftpm fast 1 UndoTextViewFixture After external replacement clears stale history, new typing creates a fresh undo action that restores the externally supplied document. Over-clearing or broken coalescing could leave undo disabled or restore content from the old document. appkit_text_system test_case retain 0 REPOPROMPT-4D post-replacement undo continuity coverage. root/RepoPromptTests.ToolCatalogSnapshotTests/testCodexAnnotationProjectionPreservesCanonicalMetadataAcrossIdentityMatrix root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testCodexAnnotationProjectionPreservesCanonicalMetadataAcrossIdentityMatrix MCP mcp.catalog.codex_annotation_projection annotation_projection,window_state main_actor_catalog_and_value_matrix root_swiftpm routine 3 Canonical metadata remains truthful; positive Codex clears only read-only hints; all other identities preserve metadata. medium 0.015500 window_state,global_settings GlobalSettingsStore per_case_window_teardown consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.ToolCatalogSnapshotTests/testCanonicalReadOnlyAnnotationsRemainTruthfulOutsideCodexProjection, root/RepoPromptTests.ToolCatalogSnapshotTests/testCodexProjectionClearsOnlyReadOnlyHintForPositiveCodexIdentity, root/RepoPromptTests.ToolCatalogSnapshotTests/testCodexProjectionPreservesMetadataForMissingAmbiguousAndNonCodexIdentities -root/RepoPromptTests.ToolCatalogSnapshotTests/testAgentRunRespondSchemaAdvertisesCanonicalScalarResponseOnly root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testAgentRunRespondSchemaAdvertisesCanonicalScalarResponseOnly MCP mcp.catalog.agent_run_respond_scalar_response schema_contract,agent_run,respond,response_field,no_alias main_actor_catalog_contract root_swiftpm routine 1 WindowToolCatalog The agent_run schema advertises a scalar response with canonical example, omits decision and object alternatives, and keeps only op globally required. Generated clients could emit unsupported response shapes or break non-approval interactions by requiring response globally. 0.117000 window_state;global_settings GlobalSettingsStore per_case_window_teardown retain 0 Semantic contract for the index-18 catalog golden. root/RepoPromptTests.ToolCatalogSnapshotTests/testLifecycleSchemasAdvertiseConfigurableDefaultsWithoutMaximumClamp root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testLifecycleSchemasAdvertiseConfigurableDefaultsWithoutMaximumClamp MCP mcp.catalog.lifecycle_wait_schema schema_contract,window_state main_actor_catalog_matrix root_swiftpm routine 2 Fresh catalogs preserve exact configurable wait descriptions and absence of maximum clamps. medium 0.034000 window_state,global_settings GlobalSettingsStore per_case_window_teardown consolidated_replacement 0 iteration 4 replacement for: root/RepoPromptTests.ToolCatalogSnapshotTests/testAgentLifecycleSchemasAdvertiseTwoMinuteDefaultsWithoutMaximumClamp, root/RepoPromptTests.ToolCatalogSnapshotTests/testInteractiveLifecycleSchemasPreserveConfigurableWaitsWithoutMaximumClamp root/RepoPromptTests.ToolCatalogSnapshotTests/testProductionRegistrationUsesCatalogServiceNotViewModel root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testProductionRegistrationUsesCatalogServiceNotViewModel MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.034000 unreviewed retain_pending_review 0 initial census source line 184 root/RepoPromptTests.ToolCatalogSnapshotTests/testWindowToolCatalogSignatureMatchesGolden root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testWindowToolCatalogSignatureMatchesGolden MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.036500 unreviewed retain_pending_review 0 initial census source line 12 root/RepoPromptTests.ToolCatalogSnapshotTests/testWorktreePublicAPISchemaFieldsRemainAdvertised root Tests/RepoPromptTests/MCP/ToolCatalogSnapshotTests.swift RepoPromptTests.ToolCatalogSnapshotTests testWorktreePublicAPISchemaFieldsRemainAdvertised MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.022500 unreviewed retain_pending_review 0 initial census source line 212 root/RepoPromptTests.ToolOutputFormatterAgentManageTests/testListAgentsCollapsesGpt56MaxUltraVariantsWithoutInvalidNestedIDs root Tests/RepoPromptTests/MCP/ToolOutputFormatterAgentManageTests.swift RepoPromptTests.ToolOutputFormatterAgentManageTests testListAgentsCollapsesGpt56MaxUltraVariantsWithoutInvalidNestedIDs MCP mcp.agent_manage.gpt56_effort_family_formatting codex,gpt_5_6,max,ultra,formatter,legacy_codex_max deterministic_formatter_unit root_swiftpm routine 2 list_agents output groups GPT-5.6 Sol effort variants under one family without nested Ultra/Max raw IDs and preserves GPT-5.1 Codex Max as a legitimate family display. Agent discovery output could suggest invalid nested effort IDs or collapse legitimate Codex Max family names incorrectly. 0.000000 test_case retain 0 PR #462 reviewed formatter contract across GPT-5.6 effort grouping and legacy Codex Max preservation. -root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testAgentRunApprovalGuidanceUsesCopyableCanonicalResponseCommand root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testAgentRunApprovalGuidanceUsesCopyableCanonicalResponseCommand MCP agent_run.respond.approval_formatter_guidance formatter,respond,approval,response_field,copyable_command deterministic_formatter_matrix root_swiftpm routine 2 Waiting approval output includes actual IDs in a copyable scalar response command, canonical values, and amendment guidance only when supported. Agents could repeatedly submit the wrong field or an unsupported amendment shape. 0.001000 test_case retain 0 Human-copyable canonical MCP response guidance. root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testAgentRunOutputShowsWorktreeSummaryAndUnavailableState root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testAgentRunOutputShowsWorktreeSummaryAndUnavailableState MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 298 root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testBindOutputIncludesPreviousBindingAndNextStepCommands root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testBindOutputIncludesPreviousBindingAndNextStepCommands MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 78 -root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testCodeStructurePendingOutputUsesSemanticRecoveryAndWorktreeScope root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testCodeStructurePendingOutputUsesSemanticRecoveryAndWorktreeScope MCP mcp.code_structure.pending_semantic_recovery formatter,semantic_recovery,worktree_scope deterministic_formatter_unit root_swiftpm routine 1 Formatter prints the two-line semantic retry guidance for a pending result while preserving logical worktree scope metadata. Pending model-facing output could leak internal indexing telemetry or omit useful scoped recovery guidance. 0.001000 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testCodeStructureOutputShowsTypedPendingIssueAndWorktreeScope root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testCodeStructureOutputShowsTypedPendingIssueAndWorktreeScope MCP mcp.code_structure.formatter_typed_status formatter,stable_issue,worktree_scope deterministic_formatter_unit root_swiftpm routine 1 Formatter prints literal pending status and stable artifact_pending issue while preserving logical scope metadata. Formatting could infer status or hide machine-stable issue codes. 0.001000 test_case retain 0 Grouped headless codemap cutover root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testCreateOutputIncludesUsefulNextStepCommands root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testCreateOutputIncludesUsefulNextStepCommands MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 44 root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testCreateOutputShowsWorktreeIncludeWarning root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testCreateOutputShowsWorktreeIncludeWarning MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 61 root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testDiscoveryToolOutputsShowSessionBoundWorktreeScope root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testDiscoveryToolOutputsShowSessionBoundWorktreeScope MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 190 @@ -2651,7 +2498,6 @@ root/RepoPromptTests.WindowStateDisplayedTitleTests/testDisplayedWindowTitleFoll root/RepoPromptTests.WindowStateDisplayedTitleTests/testDisplayedWindowTitleRefreshesWhenActiveAgentSessionIsRenamedThroughAgentMode root Tests/RepoPromptTests/App/WindowStateDisplayedTitleTests.swift RepoPromptTests.WindowStateDisplayedTitleTests testDisplayedWindowTitleRefreshesWhenActiveAgentSessionIsRenamedThroughAgentMode App unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.124500 unreviewed retain_pending_review 0 initial census source line 45 root/RepoPromptTests.WorkflowPromptCatalogTests/testAgentWorkflowTemplatesRenderFromProviderNeutralCatalog root Tests/RepoPromptTests/Prompt/WorkflowPromptCatalogTests.swift RepoPromptTests.WorkflowPromptCatalogTests testAgentWorkflowTemplatesRenderFromProviderNeutralCatalog Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 62 root/RepoPromptTests.WorkflowPromptCatalogTests/testCatalogMetadataMatchesWorkflowIDs root Tests/RepoPromptTests/Prompt/WorkflowPromptCatalogTests.swift RepoPromptTests.WorkflowPromptCatalogTests testCatalogMetadataMatchesWorkflowIDs Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 37 -root/RepoPromptTests.WorkflowPromptCatalogTests/testDeepPlanCatalogMetadataTracksPreservationWorkflow root Tests/RepoPromptTests/Prompt/WorkflowPromptCatalogTests.swift RepoPromptTests.WorkflowPromptCatalogTests testDeepPlanCatalogMetadataTracksPreservationWorkflow Prompt workflow_prompt.deep_plan_preservation_metadata deep_plan,preservation,critique,fidelity content_contract root_swiftpm routine 1 The Deep Plan descriptor advertises the preservation baseline, evidence-backed correction, completeness critique, and final fidelity workflow while excluding obsolete copy. Catalog metadata could drift from the installed Deep Plan workflow and misrepresent its preservation contract. test_case retain 0 PR #621 Deep Plan catalog-description synchronization. root/RepoPromptTests.WorkflowPromptCatalogTests/testRenderedManagedPromptFrontmatterCompatibility root Tests/RepoPromptTests/Prompt/WorkflowPromptCatalogTests.swift RepoPromptTests.WorkflowPromptCatalogTests testRenderedManagedPromptFrontmatterCompatibility Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 48 root/RepoPromptTests.WorkflowPromptCatalogTests/testWorkflowCommandOrdersAndNamesStayStable root Tests/RepoPromptTests/Prompt/WorkflowPromptCatalogTests.swift RepoPromptTests.WorkflowPromptCatalogTests testWorkflowCommandOrdersAndNamesStayStable Prompt unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 5 root/RepoPromptTests.WorkspaceApprovalCancellationTests/testApprovalRequestedFromCancelledTaskResolvesDeniedWithoutPresentingOverlay root Tests/RepoPromptTests/MCP/WorkspaceApprovalCancellationTests.swift RepoPromptTests.WorkspaceApprovalCancellationTests testApprovalRequestedFromCancelledTaskResolvesDeniedWithoutPresentingOverlay MCP unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.001000 unreviewed retain_pending_review 0 initial census source line 76 @@ -2705,12 +2551,15 @@ root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testCheckoutAndAuthorityIn root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testCleanManifestBaselineRequiresExactCapabilityAuthorityAndCurrentNamespace root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testCleanManifestBaselineRequiresExactCapabilityAuthorityAndCurrentNamespace WorkspaceContext workspace_codemap_live_overlay.clean_manifest_adoption eligible_capability,manifest_namespace,manifest_authority,clean_binding state_machine root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore An exact current capability, namespace, manifest authority, resolved clean proof, handle, and lease adopt one clean baseline; a different authority is rejected without mutation. A stale or foreign manifest could become authoritative for the current root lifetime. 0.370000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 validated clean manifest baseline root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testCompletionStaleFencesIdentifyEveryAuthorityDimension root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testCompletionStaleFencesIdentifyEveryAuthorityDimension WorkspaceContext workspace_codemap_live_overlay.exact_stale_fences root_lifetime,catalog_generation,repository_authority,path,path_generation,ingress_generation,request_generation,contribution_generation async_state_machine_negative root_swiftpm integration 8 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Factory-valid variants isolate catalog, repository authority, path generation, ingress generation, request generation, and contribution generation where construction permits; root-lifetime and path cases assert the earliest precise binding rejection without claiming all other fields are identical. A stale authority dimension could cross its cut, or ledger wording could overstate isolation that factory-valid root/path variants cannot provide. 1.500000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 precise stale-fence matrix with narrowed factory-valid claims root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testCompletionValidationAndBusyAdmissionRemainRetryable root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testCompletionValidationAndBusyAdmissionRemainRetryable WorkspaceContext workspace_codemap_live_overlay.transactional_completion binding_mismatch,artifact_handle,lease_busy,retry async_state_machine_negative root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Binding and handle mismatches plus saturated lease admission are rejected before pending mutation; the same ticket later accepts a valid completion after proof correction or capacity release. A failed proof or busy admission could consume pending state and make valid retry impossible. 0.933000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 transactional completion retry contract +root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testContributionGenerationExhaustionRevokesOldGraphSnapshotWithoutABA root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testContributionGenerationExhaustionRevokesOldGraphSnapshotWithoutABA WorkspaceContext workspace_codemap_live_overlay.contribution_generation_overflow uint64_max,contribution_generation,fail_closed,no_aba bounded_state_machine root_swiftpm integration 2 WorkspaceCodemapAuthorityTestFixture Contribution generation exhaustion revokes authority and makes the old graph snapshot unconsumable without wrapping. Generation wrap could validate an obsolete graph snapshot. 0.336000 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 2B2 checked generation boundary root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testDirtyPendingAndReadyShadowCleanUntilExplicitManifestRevalidation root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testDirtyPendingAndReadyShadowCleanUntilExplicitManifestRevalidation WorkspaceContext workspace_codemap_live_overlay.dirty_shadow clean_baseline,dirty,pending,ready,revalidation async_state_machine root_swiftpm integration 5 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Pending and ready validated-worktree entries shadow the clean baseline; modification revocation does not reveal it, while explicit manifest revalidation restores it. A dirty revocation could accidentally reveal a stale clean artifact before Git revalidation. 0.392500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 dirty shadow and clean revalidation root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testExactDuplicateCompletionRequiresCurrentTicketAndClosesDuplicateLease root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testExactDuplicateCompletionRequiresCurrentTicketAndClosesDuplicateLease WorkspaceContext workspace_codemap_live_overlay.exact_duplicate_ticket request_id,request_generation,contribution_generation,duplicate_lease,stale_after_ready async_resource_lifecycle root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Only the exact originating ready ticket is idempotent, its newly supplied duplicate lease closes immediately, and a forged post-ready ticket is rejected without changing the retained lease. A stale completion could be mislabeled duplicate or leak one lease per replay. 0.298000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 exact duplicate currentness and lease disposal root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testFocusedRegistrationDemandOutcomeAndInvalidationSemantics root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testFocusedRegistrationDemandOutcomeAndInvalidationSemantics WorkspaceContext workspace_codemap_live_overlay.focused_semantic_matrix registration_duplicate,capability_rejection,catalog_rejection,owner_join,ready_fast_path,ready_no_symbols,ready_overwrite_rejection,request_conflict,stale_request,decode_failed,parse_failed,delete async_state_machine root_swiftpm integration 13 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Exact registration replay, invalid capability/catalog rejection, owner joins, ready reuse, stale/equal demand rejection, validated unavailable overwrite protection, remaining deterministic outcomes, and delete invalidation preserve distinct dispositions. Uncovered registration, demand, outcome, or delete paths could silently violate overlay state semantics. 0.719000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 focused registration/demand/outcome/invalidation gaps root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testFrozenBundleConcurrentCloseAndReadIsLinearizableAndReleasesExactlyOnce root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testFrozenBundleConcurrentCloseAndReadIsLinearizableAndReleasesExactlyOnce WorkspaceContext workspace_codemap_live_overlay.bundle_concurrent_close sixty_four_readers,linearizable_close,typed_closed,double_close,exact_release async_resource_lifecycle root_swiftpm integration 64 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Sixty-four concurrent snapshot, frozen-handle, and render reads linearize with double close; each read either succeeds while protected or returns typed closed, and the final lease count and bytes are exactly zero. A read/close race could expose an unprotected handle, crash, double-release, or leave the CAS lease pinned. 0.297000 git_fixture,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 lock-backed bundle close/read invariant root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testFrozenBundleLeaseSurvivesEvictionAndRootUnloadThenReleasesOnBundleLifecycle root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testFrozenBundleLeaseSurvivesEvictionAndRootUnloadThenReleasesOnBundleLifecycle WorkspaceContext workspace_codemap_live_overlay.bundle_lease_lifecycle artifact_lease,frozen_bundle,root_unload,release async_resource_lifecycle root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore A frozen bundle keeps the CAS lease active across root unload, exposes only a guarded handle while open, and double close synchronously revokes snapshot, graph, render, and handle access with typed closed while releasing count and bytes. Root eviction could invalidate open frozen access, or bundle teardown could expose an unprotected raw handle, fake post-close access, or leak CAS lease count and bytes. 0.299500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 lease-safe frozen bundle lifecycle root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testFrozenBundleRemainsInternallyConsistentAcrossReplacement root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testFrozenBundleRemainsInternallyConsistentAcrossReplacement WorkspaceContext workspace_codemap_live_overlay.freeze_consistency freeze,replacement,request_generation,contribution_generation,render_projection snapshot_consistency root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore A frozen generation retains its original request, contribution generation, handle, and externally projected rendering while the live root advances to a replacement generation. Mixed-generation snapshot fields could corrupt rendering or accounting. 0.394500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 internally consistent freeze +root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphSnapshotEmitsOnlyCurrentReadyBindings root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphSnapshotEmitsOnlyCurrentReadyBindings WorkspaceContext workspace_codemap_live_overlay.graph_emission ready_binding,pending,unavailable,contribution_generation,graph_model projection_contract root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Graph emission includes only the current ready binding, excludes pending and unavailable entries, and is accepted directly by the existing graph model store. Pending or unavailable artifacts could become graph nodes, or graph authority could diverge from overlay authority. 0.533500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 ready-only graph binding projection +root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphSnapshotsRequireConsumeTimeCurrentness root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphSnapshotsRequireConsumeTimeCurrentness WorkspaceContext workspace_codemap_live_overlay.graph_consume_currentness snapshot_consume,catalog_generation,repository_authority,invalidation,replacement,root_unload snapshot_consistency root_swiftpm integration 6 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Graph snapshots consume only while fully current; independently forged catalog and repository-authority envelopes plus invalidation, replacement, and unload are rejected. A captured or foreign-envelope graph snapshot could be consumed after authority, catalog, or contribution revocation. 0.393500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 consume-time graph validation root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testManifestAdoptionClearsOnlyItsPipelineShadows root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testManifestAdoptionClearsOnlyItsPipelineShadows WorkspaceContext workspace_codemap_overlay.pipeline_shadow_ownership swift,typescript,path_invalidation,pipeline_adoption async_state_machine root_swiftpm integration 2 WorkspaceCodemapLiveOverlayRootFixture Invalidating one path in each of two pipelines creates two qualified shadows; re-adopting Swift clears only the Swift shadow and leaves the TypeScript shadow visible. Successful adoption for one pipeline could erase unrelated invalidation evidence owned by another pipeline. 0.391000 filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Cutover Slice 1 internal pipeline-qualified shadow ownership root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testManifestAdoptionPreflightsRecordBytesEntriesAndLeasesBeforeValidation root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testManifestAdoptionPreflightsRecordBytesEntriesAndLeasesBeforeValidation WorkspaceContext workspace_codemap_live_overlay.manifest_preflight_bounds same_generation,equality_probe,record_count,estimated_bytes,entry_count,lease_projection,pre_validation,busy,state_preservation bounded_state_machine root_swiftpm integration 6 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore After a one-record baseline, oversized and over-leased same-generation inputs return typed busy with zero record-equality traversals; a valid exact duplicate proves the hook by traversing once, while estimated-byte and entry bounds also reject before validation and preserve baseline state. Oversized same-generation manifests could force full equality, dictionary materialization, or entry validation before backpressure, causing unbounded transient work or partial state mutation. 1.123000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 final P2 pre-equality bounded manifest adoption root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testManifestAdoptionTicketCurrentRequiresExactLiveRootGeneration root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testManifestAdoptionTicketCurrentRequiresExactLiveRootGeneration WorkspaceContext workspace_codemap_live_overlay.adoption_ticket_currentness catalog_generation,repository_authority,invalidation_generation,unload async_state_machine_negative root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture Ticket-current queries accept only the exact live root/catalog/authority/invalidation generation and reject invalidation or unload. A stale engine adoption could continue acquiring leases after revocation. 0.199000 git_fixture,artifact_store,actor test_case+fixture_cleanup retain 0 Slice 2B2 manifest adoption reentrancy fence @@ -2730,12 +2579,12 @@ root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testRootUnloadIsIsolatedAn root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testSnapshotsAndBundlesDoNotExposePhysicalRootOrSourceBytes root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testSnapshotsAndBundlesDoNotExposePhysicalRootOrSourceBytes WorkspaceContext workspace_codemap_live_overlay.path_free_snapshot relative_path,physical_path,source_bytes,bundle,snapshot security_serialization_contract root_swiftpm integration 3 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Published entry snapshots expose only root-relative value projections, never a raw CAS handle; reflection over every typed unavailable state, snapshots, and bundle entries contains neither physical paths nor retained source bytes. Physical checkout paths, source buffers, unrestricted reason strings, or raw CAS handles could leak through immutable consumer snapshots. 0.341500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 path/source leakage guard root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testStaleCompletionMatrixDropsReplacedInvalidatedAndUnloadedRequests root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testStaleCompletionMatrixDropsReplacedInvalidatedAndUnloadedRequests WorkspaceContext workspace_codemap_live_overlay.stale_completion_matrix request_replacement,path_invalidation,root_unload,stale_drop_accounting async_state_machine_negative root_swiftpm integration 4 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Replaced tickets, watcher/path invalidation, and root unload drop previously valid completions and increment stale-drop accounting without publication. A stale factory-valid completion could cross replacement, invalidation, or root-unload cuts. 0.399000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 stale completion fencing matrix root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testStaleManifestAdoptionRollbackCannotEraseNewCommitAfterReregistration root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testStaleManifestAdoptionRollbackCannotEraseNewCommitAfterReregistration WorkspaceContext workspace_codemap_live_overlay.adoption_rollback_operation_identity post_commit_gate,unregister,reregister,same_generations,operation_id,stale_rollback,lease_preservation concurrency_contract root_swiftpm integration 5 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore,OverlayFirstCommitGate Adoption A commits and suspends; the root unregisters and re-registers with identical generation authority, adoption B commits, and A's rollback is rejected by its unique operation ID while B remains ready. An ABA reuse of epoch, authority, catalog, invalidation, and manifest generations could let stale adoption A erase newer adoption B and release its lease. 0.304500 git_fixture,artifact_store,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Slice 2B2 adoption rollback ABA fence +root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testTerminalCompletionBecomesUnavailableAndNeverEmitsGraphContribution root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testTerminalCompletionBecomesUnavailableAndNeverEmitsGraphContribution WorkspaceContext workspace_codemap_live_overlay.terminal_unavailable terminal_artifact,unavailable,lease_release,graph_exclusion state_machine root_swiftpm integration 3 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore A factory-valid terminal artifact resolves to unavailable state, is absent from frozen ready bundles, and emits no graph binding. Terminal negative artifacts could be mistaken for renderable or graph-ready codemaps. 0.334500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 terminal unavailable state root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testUnavailableFloodEvictsOldestNegativeWithoutOvershoot root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testUnavailableFloodEvictsOldestNegativeWithoutOvershoot WorkspaceContext workspace_codemap_live_overlay.unavailable_flood_reclamation unavailable_flood,oldest_first,deterministic_eviction,entry_cap,monotonic_accounting bounded_state_machine root_swiftpm integration 5 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore A saturated unavailable flood evicts the oldest negative entry deterministically for each unrelated demand while entry counts stay at the cap and eviction accounting increases monotonically. Ownerless unavailable entries could permanently starve new demand or cause nondeterministic/overshooting reclamation. 0.601500 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 deterministic unavailable flood eviction root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testUnavailablePublicationIsTicketBoundAndEntryBounded root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testUnavailablePublicationIsTicketBoundAndEntryBounded WorkspaceContext workspace_codemap_live_overlay.unavailable_authority demand_ticket,exact_duplicate,invalid_reason,entry_bound,same_path_identity,contribution_generation,negative_reclamation state_machine_negative root_swiftpm integration 7 WorkspaceCodemapAuthorityTestFixture,CodeMapArtifactStore Unavailable publication requires the exact current demand/contribution ticket, accepts only the closed path-free reason enum, remains bounded under same-path replacement, and yields capacity to unrelated demand by deterministic reclamation. Identity-only or ownerless unavailable state could overwrite current state, evade bounds, or permanently monopolize admission. 0.493000 git_fixture,artifact_store,actor temporary_directory test_case+fixture_cleanup retain 0 Slice 2B1 proof-bound unavailable state root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testAncestorGitCreationInvalidatesProofAndRunsGitPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testAncestorGitCreationInvalidatesProofAndRunsGitPreflight WorkspaceContext codemap.local_git_classification.ancestor_proof_invalidation ancestor_git,proof_validation,zero_git,preflight deterministic_regression root_swiftpm routine 2 TemporaryFilesystemFixture;AsyncCounter An unchanged proof serves terminal non-Git with zero Git; creating ancestor .git invalidates it and forces the next demand through Git preflight. Ancestor repository creation could leave a root permanently cached as non-Git until reload. 0.004000 temp_directory actor_store test_case+root_unload+fixture_cleanup retain 0 Self-validating ancestor Git evidence. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testBareLikeOrPermissionAmbiguousRootRequiresGitPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testBareLikeOrPermissionAmbiguousRootRequiresGitPreflight WorkspaceContext codemap.local_git_classification.ambiguous bare_like,missing_root,fail_open deterministic_regression root_swiftpm routine 2 TemporaryFilesystemFixture Bare-like and missing or otherwise ambiguous roots fail open to the existing Git preflight. A conservative local classifier could falsely terminal-cache an unusual Git or inaccessible root as non-Git. 0.001000 temp_directory test_case+fixture_cleanup retain 0 Ambiguous filesystem evidence never short-circuits Git. -root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository WorkspaceContext codemap.local_git_classification.watcher_conversion git_layout_watcher,terminal_non_git,cache_invalidation,repository_conversion,git_preflight,ready_admission git_fixture_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,WorkspaceFileContextStore A plain root first proves terminal non-Git without preflight; after real Git initialization and a layout-watcher delta, the cached proof is invalidated, authoritative Git preflight runs, and codemap demand becomes ready. A cached terminal non-Git classification could survive repository conversion and permanently block codemap admission. 11.167000 git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup+root_unload consolidated_replacement 0 Renamed root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeInvalidatesDefiniteNonGitClassification -> root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository and consolidated root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testRepositoryLayoutInvalidationReprobesCachedTerminalGitSession -> root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository; the strengthened row preserves the original two watcher-conversion scenarios, and the duplicate store scenario receives no additional credit. -root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testInvalidatedNonGitProofReclassifiesLocallyBeforeConvertedRepositoryPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testInvalidatedNonGitProofReclassifiesLocallyBeforeConvertedRepositoryPreflight WorkspaceContext codemap.local_git_classification.invalidated_proof_reclassification invalidated_non_git_proof,local_reclassification,zero_git,repository_conversion,git_preflight,ready_admission deterministic_regression root_swiftpm routine 2 ReviewGitRepositoryFixture,WorkspaceFileContextStore,LocalGitProofValidationGate,AsyncCounter An invalid cached non-Git proof reruns local classification and a fresh non-Git proof avoids Git preflight; subsequent repository conversion reaches authoritative Git preflight and admits ready codemap demand. An invalid cached proof could bypass cheap local reclassification, execute unnecessary Git work for a still-plain root, or leave later repository conversion on the wrong authority path. 0.000000 git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup+root_unload retain 0 Regression for stale-proof local reclassification followed by authoritative repository-conversion admission. +root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository WorkspaceContext codemap.local_git_classification.watcher_conversion git_layout_watcher,terminal_non_git,cache_invalidation,repository_conversion,git_preflight,ready_admission git_fixture_contract root_swiftpm routine 2 ReviewGitRepositoryFixture,WorkspaceFileContextStore A plain root first proves terminal non-Git without preflight; after real Git initialization and a layout-watcher delta, the cached proof is invalidated, exactly one Git preflight runs, and codemap demand becomes ready. A cached terminal non-Git classification could survive repository conversion and permanently block codemap admission. 11.167000 git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup+root_unload consolidated_replacement 0 Renamed root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeInvalidatesDefiniteNonGitClassification -> root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository and consolidated root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testRepositoryLayoutInvalidationReprobesCachedTerminalGitSession -> root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testGitLayoutWatcherChangeReprobesAndAdmitsConvertedRepository; the strengthened row preserves the original two watcher-conversion scenarios, and the duplicate store scenario receives no additional credit. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testIntermediateSymlinkRetargetInvalidatesProofAndRunsGitPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testIntermediateSymlinkRetargetInvalidatesProofAndRunsGitPreflight WorkspaceContext codemap.local_git_classification.symlink_proof_invalidation intermediate_symlink,retarget,proof_validation,zero_git,preflight deterministic_regression root_swiftpm routine 2 TemporaryFilesystemFixture;AsyncCounter An unchanged intermediate-symlink proof serves with zero Git; retargeting the link invalidates it and forces Git preflight. A symlink retarget could preserve a stale terminal non-Git cache across a repository-boundary change. 0.009000 symlink;temp_directory actor_store test_case+root_unload+fixture_cleanup retain 0 Self-validating intermediate-symlink identity. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testLinkedWorktreeGitFileRequiresGitPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testLinkedWorktreeGitFileRequiresGitPreflight WorkspaceContext codemap.local_git_classification.gitfile linked_worktree,gitfile,fail_open deterministic_regression root_swiftpm routine 1 TemporaryFilesystemFixture A linked-worktree-style .git file always routes to Git preflight. A gitfile checkout could be misclassified as terminal non-Git. 0.001000 temp_directory test_case+fixture_cleanup retain 0 Linked-worktree gitfile safety. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testPlainDirectoryIsDefinitelyNonGitWithoutExecutingGit root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testPlainDirectoryIsDefinitelyNonGitWithoutExecutingGit WorkspaceContext codemap.local_git_classification.plain_root plain_directory,root_boundary,sibling_git,zero_git deterministic_regression root_swiftpm routine 1 TemporaryFilesystemFixture A plain directory with no Git control entry in its physical ancestor chain is definitely non-Git; a sibling repository does not cross the root boundary. Cold non-Git code structure could regress to avoidable Git subprocesses or sibling-root leakage. 0.001000 temp_directory test_case+fixture_cleanup retain 0 Definite non-Git and root-boundary classification. @@ -2743,6 +2592,32 @@ root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testSymlinkedRo root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testTransientPreflightIsNotTerminallyCached root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testTransientPreflightIsNotTerminallyCached WorkspaceContext codemap.local_git_classification.transient_not_cached transient_unavailable,retry,repository_changing concurrency_regression root_swiftpm routine 2 TemporaryFilesystemFixture;AsyncCounter Two demands after a requires-preflight classification each retry a transient repository-changing result. Transient Git unavailability could be terminally cached and suppress later recovery. 0.002000 temp_directory actor_store test_case+root_unload+fixture_cleanup retain 0 Only definite non-Git is terminally cached. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testUnloadReloadReclassifiesNewRootEpoch root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testUnloadReloadReclassifiesNewRootEpoch WorkspaceContext codemap.local_git_classification.root_epoch_reload unload,reload,lifetime_id,zero_git deterministic_integration root_swiftpm routine 3 TemporaryFilesystemFixture;AsyncCounter Repeated demand classifies once per root epoch, unload clears the cache, and reload reclassifies without invoking Git. A terminal non-Git result could leak across root lifetimes or repeatedly probe within one epoch. 0.005500 temp_directory actor_store test_case+root_unload+fixture_cleanup retain 0 Root-epoch cache and unload invalidation. root/RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests/testWorktreeSubdirectoryRequiresGitPreflight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLocalGitClassificationTests.swift RepoPromptTests.WorkspaceCodemapLocalGitClassificationTests testWorktreeSubdirectoryRequiresGitPreflight WorkspaceContext codemap.local_git_classification.ancestor_git git_directory,loaded_subdirectory,ancestor_walk deterministic_regression root_swiftpm routine 1 TemporaryFilesystemFixture A loaded subdirectory beneath an ancestor .git directory routes to Git preflight. Subdirectory workspace roots could be falsely classified non-Git when the control entry exists above them. 0.001000 temp_directory test_case+fixture_cleanup retain 0 Bounded ancestor Git detection. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testAuthoritySeededStorePrivatelyIssuesDistinctCurrentNodeIdentities root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testAuthoritySeededStorePrivatelyIssuesDistinctCurrentNodeIdentities WorkspaceContext/CodeMap codemap.graph.node.authority_issuance resolved_binding,request_generation,contribution_generation,binding_generation,opaque_ordinal,exact_duplicate,stale_rejection,equal_generation_conflict,current_replacement stale_generation_contract root_swiftpm routine 9 WorkspaceCodemapAuthorityTestFixture A resolved Slice 1A binding seeds a private store; equal exact duplicates consume nothing, higher request generations issue the next graph binding generation and ordinal, and later lower or equal-conflicting generations leave the current endpoint and accounting unchanged. Dropping request generation or defining ambiguous generation ties could let stale work replace a current graph endpoint or double-charge accounting. 0.548000 filesystem test_case retain 0 Slice 1B request/contribution/binding generation precedence +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testContributionAcceptanceRequiresResolvedCurrentSlice1AAuthority root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testContributionAcceptanceRequiresResolvedCurrentSlice1AAuthority WorkspaceContext/CodeMap codemap.graph.acceptance.slice1a_authority resolved_binding,root_id,root_lifetime,catalog,repository_authority,schema,policy,terminal_artifact stale_generation_contract root_swiftpm routine 8 WorkspaceCodemapAuthorityTestFixture Acceptance derives contributions only from resolved Slice 1A bindings and rejects root, lifetime, catalog, repository authority, schema, policy, unresolved binding, and unavailable-artifact mismatches before accounting. A self-consistent forged snapshot or stale authority could mint an endpoint or consume graph budget. 1.642500 filesystem test_case retain 0 Renamed stale-snapshot ID to resolved Slice 1A authority fence +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testContributionIsPathFreeCanonicalAndDeterministicFromV1ArtifactFields root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testContributionIsPathFreeCanonicalAndDeterministicFromV1ArtifactFields WorkspaceContext/CodeMap codemap.graph.contribution.canonical_v1 path_free,nfc,case_preserving,utf8_byte_order,definition_reference_domains,length_framing,permutation_stable deterministic_model_contract root_swiftpm routine 12 NFC and NFD names normalize before deduplication and byte ordering; case remains distinct, every tested input permutation is stable, and swapped domains or ambiguous concatenations produce distinct framed digests. Unicode-form, locale, domain, or framing ambiguity could make graph contributions non-deterministic or collide across distinct symbol sets. 0.001000 test_case retain 0 Slice 1B explicit Unicode and framing canonicalization +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testDuplicateDefinitionsProduceDeterministicAllCandidateSetOrFailClosedOverflow root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testDuplicateDefinitionsProduceDeterministicAllCandidateSetOrFailClosedOverflow WorkspaceContext/CodeMap codemap.graph.duplicate_definitions.total_order root_relative_utf8,file_id,binding_generation,ordinal,permutation_stable,exact_duplicate,candidate_overflow deterministic_model_contract root_swiftpm routine 9 WorkspaceCodemapAuthorityTestFixture Candidate permutations remain stable, and a dedicated production ordering key independently exercises the full path then file ID then binding generation then ordinal tie chain across three permutations; duplicates deduplicate and overflow returns no prefix. An untested comparator tie could preserve input order and make duplicate-definition traversal permutation-dependent. 0.638000 filesystem test_case retain 0 Slice 1B exhaustive duplicate-order tie chain +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testEdgeStoreRejectsEveryForeignGraphKeyComponentAndConsumesBudget root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testEdgeStoreRejectsEveryForeignGraphKeyComponentAndConsumesBudget WorkspaceContext/CodeMap codemap.graph.edge.authority_and_budget source_side,target_side,root_id,root_lifetime,catalog,repository_authority,contribution_generation,schema,policy,store_identity,edge_budget protocol_negative root_swiftpm routine 17 WorkspaceCodemapAuthorityTestFixture The shared side-aware validator rejects every graph-key component on both source and target sides; real projectable foreign targets and independent-store targets are rejected, while current same-store endpoints construct one accounted edge. Checking only the source endpoint or only part of the graph key could admit a foreign target across authority, schema, policy, or store boundaries. 1.406500 filesystem test_case retain 0 Slice 1B full source/target graph-key matrix +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testSizeAccountingAndAcceptanceFailClosedOnLimitAndArithmeticOverflow root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testSizeAccountingAndAcceptanceFailClosedOnLimitAndArithmeticOverflow WorkspaceContext/CodeMap codemap.graph.budget.cumulative_store nodes,postings,edges,bytes,exact_boundary,n_plus_one,cumulative_postings,cumulative_bytes,second_edge,unchanged_rejection,arithmetic_overflow,sendable bounded_input_contract root_swiftpm routine 19 WorkspaceCodemapAuthorityTestFixture Store accounting reaches exact cumulative posting, byte, and two-edge boundaries; rejects the second contribution or edge at N+1 without mutation; retains single-dimension exact/N+1 checks; and types overflow in every dimension with Sendable value contracts. A cumulative-only off-by-one or partial mutation on rejection could exceed graph limits even when individual additions fit. 0.485000 filesystem test_case retain 0 Slice 1B cumulative exact/N+1 graph budgets +root/RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests/testValidatedQueryResultsFailClosedOnCoverageAuthorityAndStaleness root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphModelTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphModelTests testValidatedQueryResultsFailClosedOnCoverageAuthorityAndStaleness WorkspaceContext/CodeMap codemap.graph.query.validated_result partial,unavailable,complete,proven_missing,source_coverage,self_target,selected_peer_target,foreign_target,duplicate_target,stale_source,stale_target,catalog,repository_authority availability_contract root_swiftpm routine 22 WorkspaceCodemapAuthorityTestFixture Factories and final result validation reject self or selected-peer targets; proven-missing records require exact complete catalog and repository authority and fail under unknown, partial, unavailable, stale-catalog, or foreign-authority universes; prior coverage and staleness fences remain enforced. A selected source could be reintroduced as a target or an incomplete/stale universe could falsely prove a definition absent. 0.898500 filesystem test_case retain 0 Slice 1B selected-source exclusion and complete-only proof +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testActorAndProcessAdmissionAreExactRecoverableAndReleaseOnce root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testActorAndProcessAdmissionAreExactRecoverableAndReleaseOnce WorkspaceContext/CodeMap codemap.graph.runtime.admission_lifecycle active_limit,reserved_binding_limit,actor_local,process_shared,n_plus_one,process_status,concurrent_close,deinit,cancellation,invalidation,recovery,failed_closed graph_runtime_concurrency_contract root_swiftpm routine 12 WorkspaceCodemapAuthorityTestFixture,SelectionGraphBuildGate,CodeMapSelectionGraphAdmission Direct reservations exercise the active-count bound; actor-local and cross-actor shared binding reservations exercise exact and N+1 capacity, process rejection status, and zero-count recovery after concurrent close, deinit, cancellation, invalidation, success, and retry; invalid accounting fails closed. A leaked, double-released, or non-fail-closed low-priority permit could starve graph runtimes or undercount concurrent graph work. 0.527500 git_fixture,actor,concurrency test_case+fixture_cleanup retain 0 Slice 3 inert admission lifecycle and fail-closed accounting; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testActorAndProcessAdmissionAreExactRecoverableAndReleaseOnce -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testActorAndProcessAdmissionAreExactRecoverableAndReleaseOnce; Consolidates root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionGraphAdmissionReleaseEmitsReadinessAndRetrySucceeds admission-release recovery coverage; its 12 intrinsic scenarios remain unchanged and the duplicate store scenario receives no additional credit. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testCrossActorProcessActiveReservationLimitSaturatesAndRecovers root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testCrossActorProcessActiveReservationLimitSaturatesAndRecovers WorkspaceContext/CodeMap codemap.graph.runtime.process_active_admission active_reservation_limit,cross_actor,process_shared,exact_saturation,n_plus_one,process_status,recovery graph_runtime_concurrency_contract root_swiftpm routine 2 WorkspaceCodemapAuthorityTestFixture,SelectionGraphBuildGate,CodeMapSelectionGraphAdmission One actor holds the sole process reservation while a second actor receives the exact activeReservationCountLimit rebuild and query dispositions; releasing the first permit returns both counters to zero and lets the second actor publish. Conflating process active-count saturation with reserved-binding capacity could report the wrong busy reason or fail to recover after the active permit closes. 0.464500 git_fixture,actor,concurrency test_case+fixture_cleanup retain 0 Slice 3 distinct cross-actor process active-reservation saturation and recovery; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testCrossActorProcessActiveReservationLimitSaturatesAndRecovers -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testCrossActorProcessActiveReservationLimitSaturatesAndRecovers; Consolidates root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionGraphAdmissionReleaseEmitsReadinessAndRetrySucceeds process-saturation recovery coverage; its 2 intrinsic scenarios remain unchanged and the duplicate store scenario receives no additional credit. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testEqualGenerationAuthorityConflictFailsClosedUntilHigherGeneration root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testEqualGenerationAuthorityConflictFailsClosedUntilHigherGeneration WorkspaceContext/CodeMap codemap.graph.runtime.equal_generation_conflict equal_generation,repository_authority_conflict,invalid_snapshot,exact_replay,higher_generation_recovery stale_generation_contract root_swiftpm routine 3 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission An equal-generation conflicting authority invalidates queries, exact-key replay cannot publish while conflict remains, and only a higher generation clears the conflict and restores ready publication. A conflicting authority could leave queries invalid while a redundant rebuild misleadingly returns published or restores stale data. 0.837500 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 fail-closed authority conflict; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testEqualGenerationAuthorityConflictFailsClosedUntilHigherGeneration -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testEqualGenerationAuthorityConflictFailsClosedUntilHigherGeneration +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testEquivalentProjectionSuccessorResealsGenerationOneToThreeWithoutRebuild root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testEquivalentProjectionSuccessorResealsGenerationOneToThreeWithoutRebuild WorkspaceContext/CodeMap codemap.graph.projection.equivalent_successor_reseal predecessor_proof,successor_seal,generation_jump,equivalent_snapshot,no_rebuild,resident_bytes,invalid_snapshot stale_generation_contract root_swiftpm routine 4 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph A generation-1 projection cannot serve generation 3 before resealing; a structurally changed live snapshot is superseded without replacing generation 1; an exact successor seal reuses the resident projection bytes and serves generation 3; and a same-generation invalid snapshot remains fail-closed despite successor replay. A stale proof could serve a newer generation, a mismatched successor could replace the last valid shard, or successor replay could mask a same-generation authority conflict. 0.475500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Projection generation handoff without graph rebuild. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testGraphSizeBudgetsAcceptNAndRejectNPlusOneForEveryDimension root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testGraphSizeBudgetsAcceptNAndRejectNPlusOneForEveryDimension WorkspaceContext/CodeMap codemap.graph.runtime.graph_size_budgets nodes,postings,edges,bytes,exact_boundary,n_plus_one,no_partial_publication bounded_input_contract root_swiftpm routine 8 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission Each node, posting, edge, and byte dimension publishes at its measured exact limit, rejects the same snapshot when its attempted total is limit plus one with the exact dimension, and leaves queries budget-unavailable. An off-by-one check in any graph-size dimension could exceed work bounds or publish a truncated shard. 0.433500 git_fixture,actor test_case+fixture_cleanup retain 0 Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testGraphPostingBudgetAcceptsNAndRejectsNPlusOne -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testGraphSizeBudgetsAcceptNAndRejectNPlusOneForEveryDimension; expanded exact N/N+1 coverage to all four dimensions; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testGraphSizeBudgetsAcceptNAndRejectNPlusOneForEveryDimension -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testGraphSizeBudgetsAcceptNAndRejectNPlusOneForEveryDimension +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testImmediateStatusMatrixDistinguishesEmptyNotBuiltStaleBusyCancelledBudgetAndUnavailable root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testImmediateStatusMatrixDistinguishesEmptyNotBuiltStaleBusyCancelledBudgetAndUnavailable WorkspaceContext/CodeMap codemap.graph.runtime.immediate_status partial,empty,missing,not_built,rebuilding,actor_busy,cancelled,stale,input_budget,revoked,target_bound availability_contract root_swiftpm routine 9 WorkspaceCodemapAuthorityTestFixture,SelectionGraphBuildGate,CodeMapSelectionGraphAdmission Queries immediately distinguish not-built, rebuilding, cancelled, stale, revoked, and empty-partial missing-source states; actor admission, input-binding, and unique-target overflow paths fail closed without a truncated result. A query could wait for readiness, counterfeit unavailable state as success, expose a truncated prefix, or let a graph exceed a hard bound. 0.723500 git_fixture,actor,concurrency test_case+fixture_cleanup retain 0 Slice 3 immediate status and bounds matrix; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testImmediateStatusMatrixDistinguishesEmptyNotBuiltStaleBusyCancelledBudgetAndUnavailable -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testImmediateStatusMatrixDistinguishesEmptyNotBuiltStaleBusyCancelledBudgetAndUnavailable +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testProjectionCoverageAndBytesAreRevokedOnPathFence root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testProjectionCoverageAndBytesAreRevokedOnPathFence WorkspaceContext/CodeMap codemap.graph.projection.path_fence_revocation path_invalidation,coverage_revocation,resident_bytes,staged_bytes,not_built state_machine root_swiftpm routine 1 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph Fencing contributions for the current root epoch clears staged and resident projection bytes, increments revoked coverage exactly once, and makes the formerly sealed key immediately unavailable as notBuilt. Path invalidation could leave stale projection coverage or retained bytes authoritative and let queries serve data from obsolete repository paths. 0.459500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Path-invalidation projection revocation coverage. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testProjectionSegmentByteBudgetIsTypedAndTargetless root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testProjectionSegmentByteBudgetIsTypedAndTargetless WorkspaceContext/CodeMap codemap.graph.projection.segment_byte_budget projection_segment,retained_projection_bytes,typed_budget,targetless,fail_closed bounded_input_contract root_swiftpm routine 1 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph A projection segment larger than the one-byte retained/staged limits is rejected, and the subsequent query returns a retainedProjectionBytes budget disposition whose attempted count exceeds the exact limit instead of returning targets. Oversized projected data could bypass memory bounds, publish a partial target set, or surface an untyped unavailable state that callers cannot classify. 0.406500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Retained projection byte-budget fail-closed coverage. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testProjectionSegmentSupersedesSameGenerationLiveBuildWithoutLateDowngrade root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testProjectionSegmentSupersedesSameGenerationLiveBuildWithoutLateDowngrade WorkspaceContext/CodeMap codemap.graph.projection.same_generation_live_supersession same_generation,staged_projection,live_build,cancellation,supersession,exact_seal,no_late_downgrade graph_runtime_concurrency_contract root_swiftpm routine 1 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph,SelectionGraphBuildGate When a same-generation live rebuild is blocked, staging a projection forces the late live build to finish cancelled or superseded; the exact projection seal is then accepted and the ready query returns the projected target. A late live rebuild could overwrite staged projection authority, downgrade complete coverage, or prevent the exact projection from sealing. 0.528500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Same-generation staged-projection versus live-build arbitration. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testQueryBudgetsBoundRawSourcesUniqueTargetsAndReferenceFailures root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testQueryBudgetsBoundRawSourcesUniqueTargetsAndReferenceFailures WorkspaceContext/CodeMap codemap.graph.runtime.query_budgets raw_selected_sources,duplicate_flood,unique_targets,multiple_resolutions,reference_failures,exact_boundary,n_plus_one,no_prefix bounded_input_contract root_swiftpm routine 5 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission Raw selected sources accept N and reject a duplicate flood at N+1 before deduplication; two resolution edges may share one bounded unique target; reference failures accept N and reject N+1 without a prefix. Dedup-before-budget or edge-count target accounting could permit unbounded input, and unbounded failure output could exhaust query work or memory. 0.697000 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 raw input, unique target, and failure output bounds; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testQueryBudgetsBoundRawSourcesUniqueTargetsAndReferenceFailures -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testQueryBudgetsBoundRawSourcesUniqueTargetsAndReferenceFailures +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testReadyPartialResolutionIsDeterministicAcrossPermutationsAndCandidateBounds root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testReadyPartialResolutionIsDeterministicAcrossPermutationsAndCandidateBounds WorkspaceContext/CodeMap codemap.graph.runtime.deterministic_partial binding_permutation,selected_source_permutation,exact_duplicate_source,conflicting_generation,duplicate_definitions,selected_target_exclusion,candidate_overflow,duplicate_binding deterministic_model_contract root_swiftpm routine 8 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission Normal and reversed ready bindings plus distinct selected-source orders yield identical canonical results; exact duplicate sources deduplicate, conflicting generations reject, selected peers disappear from both targets and resolutions, and duplicate binding or candidate overflow fails closed. Input order, ambiguous selected generations, duplicate definitions, or selected peers could make graph expansion nondeterministic or unsafe. 0.494000 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 deterministic root-local query graph runtime; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testReadyPartialResolutionIsDeterministicAcrossPermutationsAndCandidateBounds -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testReadyPartialResolutionIsDeterministicAcrossPermutationsAndCandidateBounds +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testRejectedCancelledAndSupersededBuildsPreserveTheLastCompleteShard root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testRejectedCancelledAndSupersededBuildsPreserveTheLastCompleteShard WorkspaceContext/CodeMap codemap.graph.runtime.atomic_publication rejection,cancellation,supersession,generation_keyed_gate,explicit_release_order,observation_serial,immutable_shard,no_partial_publication state_machine root_swiftpm routine 3 WorkspaceCodemapAuthorityTestFixture,SelectionGraphBuildGate,CodeMapSelectionGraphAdmission Generation-keyed publication gates independently hold N and N+1, release N+1 to publish while N remains blocked, then prove N completes superseded without replacing N+1; rejected and cancelled builds retain the previous complete shard physically while current queries fail closed. A scheduler-dependent test could miss a delayed or failed rebuild overwriting current authority or exposing a partially mutated replacement. 0.614000 git_fixture,actor,concurrency test_case+fixture_cleanup retain 0 Slice 3 deterministic atomic immutable publication; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testRejectedCancelledAndSupersededBuildsPreserveTheLastCompleteShard -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testRejectedCancelledAndSupersededBuildsPreserveTheLastCompleteShard +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testReplacementProjectionStagingPreservesCompleteShardUntilExactSeal root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testReplacementProjectionStagingPreservesCompleteShardUntilExactSeal WorkspaceContext/CodeMap codemap.graph.projection.atomic_replacement_staging complete_shard,staged_replacement,typed_incomplete,exact_seal,atomic_publication state_machine root_swiftpm routine 3 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph While generation 2 is staged, the generation-1 complete shard and its resident byte count remain published; a generation-2 structure query reports typed incomplete coverage without old nodes; and only the exact seal atomically publishes generation 2 as complete. Replacement staging could evict the last complete shard, leak old nodes under the new key, or publish an incomplete replacement before its exact proof is sealed. 0.398500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Atomic replacement projection staging and exact-seal commit. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testRootIsolationAndEpochReplacementCannotResolveForeignTargets root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testRootIsolationAndEpochReplacementCannotResolveForeignTargets WorkspaceContext/CodeMap codemap.graph.runtime.root_isolation root_epoch,foreign_only_definition,unresolved_local,cross_root_unrepresentable,foreign_snapshot,root_unload,lifetime_replacement protocol_negative root_swiftpm routine 5 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission A definition present solely in root B resolves there while root A remains unresolved; foreign snapshots are rejected and unload/reload lifetime identity cannot reuse the old actor or key. A root filter applied after traversal could leak a root-B-only definition into root A or let an unloaded lifetime reuse stale graph authority. 0.957500 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 construction-time root isolation; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testRootIsolationAndEpochReplacementCannotResolveForeignTargets -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testRootIsolationAndEpochReplacementCannotResolveForeignTargets +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testStagedIncompleteShardWithResidentNodesReturnsNoStructureResult root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testStagedIncompleteShardWithResidentNodesReturnsNoStructureResult WorkspaceContext/CodeMap codemap.graph.projection.staged_structure_targetless resident_nodes,incomplete_coverage,structure_query,targetless,fail_closed availability_contract root_swiftpm routine 1 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph An unsealed staged projection may account for two resident nodes, but its structure query returns typed incomplete coverage with the exact supported-candidate and remaining counts and no structure result. Resident staged nodes could be mistaken for sealed definition-universe coverage and leak structure results before publication is complete. 0.401500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Structure queries remain fail-closed while projection coverage is staged. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testStaleSourceAndTargetGenerationsAreOmittedWithoutPartialPublication root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testStaleSourceAndTargetGenerationsAreOmittedWithoutPartialPublication WorkspaceContext/CodeMap codemap.graph.runtime.generation_fencing stale_source,current_target_generation,old_target_omission,invalid_snapshot,retained_complete_shard stale_generation_contract root_swiftpm routine 3 WorkspaceCodemapAuthorityTestFixture Stale source generations produce no traversal, replacement shards emit only current target generations, and invalid newer input cannot partially replace the last complete shard. Stale endpoints or partial invalid builds could escape the immutable currentness fence. 0.693500 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 source and target generation fencing; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testStaleSourceAndTargetGenerationsAreOmittedWithoutPartialPublication -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testStaleSourceAndTargetGenerationsAreOmittedWithoutPartialPublication +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testStrictQueryIsTargetlessUntilExactProjectionSeal root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testStrictQueryIsTargetlessUntilExactProjectionSeal WorkspaceContext/CodeMap codemap.graph.projection.exact_seal_gate live_overlay,unstarted_projection,staged_projection,duplicate_segment,exact_seal,targetless_until_complete availability_contract root_swiftpm routine 4 WorkspaceCodemapAuthorityTestFixture,WorkspaceCodemapSelectionGraph Unstarted and staged projection generations remain explicitly incomplete and targetless, duplicate segments are idempotent, and only the exact seal exposes the target with complete coverage. Live overlay or staged nodes could be mistaken for a complete definition universe and publish targets before proof. 0.498500 git_fixture,actor,concurrency temporary_directory test_case+fixture_cleanup consolidated_replacement 0 Replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionIncompletePreloadDemandsProjectionWithoutPublishingPreProofTargets; four intrinsic graph states are credited and no duplicate store scenario is transferred. +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testStructureTraversalSupportsBoundedForwardReverseAndBothBFS root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testStructureTraversalSupportsBoundedForwardReverseAndBothBFS WorkspaceContext workspace.codemap.structure_bfs forward,reverse,both,depth,node_budget deterministic_actor_unit root_swiftpm routine 1 ReviewGitRepositoryFixture Root-local BFS returns deterministic minimum depths and a deterministic node-budget prefix. Expansion could become unbounded, nondeterministic, or consumer-owned. 0.523500 test_case retain 0 Grouped headless codemap cutover +root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testValueOnlyBoundaryNeedsNoProducerOrIOAfterSnapshotCapture root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphTests testValueOnlyBoundaryNeedsNoProducerOrIOAfterSnapshotCapture WorkspaceContext/CodeMap codemap.graph.runtime.value_only_boundary caller_supplied_snapshot,fixture_removed,no_runtime_client,no_filesystem_read,no_git_read,no_build_trigger,sendable dependency_isolation root_swiftpm routine 2 WorkspaceCodemapAuthorityTestFixture,CodeMapSelectionGraphAdmission A captured ready snapshot rebuilds and queries after its repository fixture is deleted, using a constructor that accepts only root, policy, admission, and path-free diagnostics values. A hidden producer, filesystem, Git, artifact, coordinator, or builder dependency could make an inert query perform external work. 0.391000 git_fixture,actor test_case+fixture_cleanup retain 0 Slice 3 compile-time and runtime forbidden-I/O proof; Renamed root/RepoPromptTests.WorkspaceCodemapSelectionGraphRehearsalTests/testValueOnlyBoundaryNeedsNoProducerOrIOAfterSnapshotCapture -> root/RepoPromptTests.WorkspaceCodemapSelectionGraphTests/testValueOnlyBoundaryNeedsNoProducerOrIOAfterSnapshotCapture root/RepoPromptTests.WorkspaceCodemapUIPresentationTests/testCurrentMarkerRequiresRenderablePresentationIdentity root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapUIPresentationTests.swift RepoPromptTests.WorkspaceCodemapUIPresentationTests testCurrentMarkerRequiresRenderablePresentationIdentity WorkspaceContext codemap.cutover.ui.marker_renderable_identity ui_marker,presentation_identity,fail_closed presentation_contract root_swiftpm routine 2 WorkspaceCodemapUIPresentationEntry,PromptFileEntry A prompt entry displays a codemap marker only when it carries an immutable renderable presentation entry for the file. Path or extension heuristics could display stale/non-renderable codemap markers. 0.000000 main_actor,in_memory per_test_state retain 0 Milestone D current marker identity gate. root/RepoPromptTests.WorkspaceCodemapUIPresentationTests/testNonGitPreviewIsTypedUnavailableWithoutCodemapArtifactWork root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapUIPresentationTests.swift RepoPromptTests.WorkspaceCodemapUIPresentationTests testNonGitPreviewIsTypedUnavailableWithoutCodemapArtifactWork WorkspaceContext codemap.cutover.ui.non_git_unavailable_zero_work non_git,typed_coverage,zero_scan,zero_initialization deterministic_integration root_swiftpm routine 3 WorkspaceFileContextStore,WorkspaceCodemapUIPresentationScanCounter A non-Git UI preview returns typed unavailable coverage with zero legacy scan or session initialization tasks. Non-Git UI access could perform unsupported eager work or fabricate a preview. 0.004000 temporary_root,actor_store,main_actor per_test_temporary_root_cleanup retain 0 Milestone D non-Git UI fail-closed contract. root/RepoPromptTests.WorkspaceCodemapUIPresentationTests/testPreviewPayloadUsesImmutableLogicalPathAndText root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapUIPresentationTests.swift RepoPromptTests.WorkspaceCodemapUIPresentationTests testPreviewPayloadUsesImmutableLogicalPathAndText WorkspaceContext codemap.cutover.ui.preview_logical_immutable preview,logical_path,immutable_text,no_physical_path presentation_contract root_swiftpm routine 3 WorkspaceCodemapUIPresentationEntry Preview payload preserves immutable rendered text and logical display path without exposing the physical root path. Session-worktree physical paths or mutable file content could leak into preview. 0.000000 main_actor,in_memory per_test_state retain 0 Milestone D immutable logical preview payload. @@ -2756,7 +2631,6 @@ root/RepoPromptTests.WorkspaceFileContextStoreTests/testAcceptedCallbackBeforeAc root/RepoPromptTests.WorkspaceFileContextStoreTests/testAggressiveAppliedIngressLimitsConcurrentRootFlushFanOut root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testAggressiveAppliedIngressLimitsConcurrentRootFlushFanOut WorkspaceContext workspace_file_context_store.aggressive_applied_ingress_limits_concurrent_root_flush_fan_out watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.012000 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 2400 root/RepoPromptTests.WorkspaceFileContextStoreTests/testAmbiguousLookupConsumersFailWithoutMaterializingCandidates root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testAmbiguousLookupConsumersFailWithoutMaterializingCandidates WorkspaceContext workspace_store.lookup.ambiguity_terminal fresh_fixture_per_preserved_scenario,labeled_equivalent_cases negative_path_resolution root_swiftpm routine 3 WorkspaceFileContextStoreTemporaryRootFixture Exact ambiguity renderer and mutation error text with nil/no-candidate/no-record results and empty selected IDs. Ambiguous aliases could materialize or mutate an arbitrary workspace candidate. 0.016000 temporary_root,actor_store,path_lookup,error_paths test_case+tearDownWithError consolidated_replacement 0 count optimization iteration 3 replaces: root/RepoPromptTests.WorkspaceFileContextStoreTests/testValuePathResolutionReportsAmbiguousRelativePathWithExistingRendererMessage, root/RepoPromptTests.WorkspaceFileContextStoreTests/testAmbiguousRelativeIgnoredFileDoesNotMaterializeEitherRoot, root/RepoPromptTests.WorkspaceFileContextStoreTests/testAmbiguousAliasIsTerminalForExplicitReadAndSelectionLookup root/RepoPromptTests.WorkspaceFileContextStoreTests/testAppliedIndexProjectionDiagnosticsReportProducedHandledLag root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testAppliedIndexProjectionDiagnosticsReportProducedHandledLag WorkspaceContext workspace_file_context_store.applied_index_projection_diagnostics_report_produced_handled_lag diagnostic_accounting diagnostics_contract root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceDiagnosticsCaptureFixture Exact diagnostic counters, retained samples, timing fields, and associated store state assertions. Diagnostics could hide lag, drop wrong samples, or misreport work while state appears correct. 0.100500 temporary_root,actor_store,diagnostics_capture test_local_debug_hooks test_case+tearDownWithError retain 0 initial census source line 4706 -root/RepoPromptTests.WorkspaceFileContextStoreTests/testAppliedIndexRecordLookupReturnsOnlyRequestedCanonicalMembersWithBoundedWork root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testAppliedIndexRecordLookupReturnsOnlyRequestedCanonicalMembersWithBoundedWork WorkspaceContext workspace_file_context_store.applied_index_record_lookup_bounded_canonical_membership seeded_authority,relative_path_identity,discoverability,bounded_work bounded_projection root_swiftpm routine 3 WorkspaceFileContextStoreTemporaryRootFixture A seeded root lookup returns only requested file and folder records that remain canonical, discoverable members and reports work proportional to requested IDs. Missing or inconsistent applied-index IDs could trigger an unbounded main-actor snapshot or project stale records. temporary_root,actor_store,bounded_lookup test_local_debug_hooks test_case+tearDownWithError retain 0 REPOPROMPT-1C bounded applied-index record lookup contract root/RepoPromptTests.WorkspaceFileContextStoreTests/testBarrierAfterWatcherRestartDoesNotWaitForPublicationEmittedWhileSinkDetached root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testBarrierAfterWatcherRestartDoesNotWaitForPublicationEmittedWhileSinkDetached WorkspaceContext workspace_file_context_store.barrier_after_watcher_restart_does_not_wait_for_publication_emitted_while_sink_detached watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.004000 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 1305 root/RepoPromptTests.WorkspaceFileContextStoreTests/testBarrierCaptureCutExcludesCallbackAcceptedAfterCaptureUntilNextBarrier root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testBarrierCaptureCutExcludesCallbackAcceptedAfterCaptureUntilNextBarrier WorkspaceContext workspace_file_context_store.barrier_capture_cut_excludes_callback_accepted_after_capture_until_next_barrier watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.032500 temporary_root,actor_store,watcher_publisher,async_tasks test_local_debug_hooks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 1241 root/RepoPromptTests.WorkspaceFileContextStoreTests/testBatchRootUnloadDeduplicatesIDsPublishesEventsAndClearsLoadedRoots root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testBatchRootUnloadDeduplicatesIDsPublishesEventsAndClearsLoadedRoots WorkspaceContext workspace_file_context_store.batch_root_unload_deduplicates_i_ds_publishes_events_and_clears_loaded_roots root_identity,ui_store_projection root_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceFilesViewModelRootShellFixture Exact root/UI/store identity, load or unload outcome, projected state, and cleanup assertions. Root lifecycle changes could leave stale UI/store state or unload a replacement lifetime. 0.007000 temporary_root,actor_store,root_lifecycle,main_actor_manager test_case+tearDownWithError+explicit_manager_or_store_unload retain 0 initial census source line 3774 @@ -2861,8 +2735,6 @@ root/RepoPromptTests.WorkspaceFileContextStoreTests/testUnloadRootForceDiscardsW root/RepoPromptTests.WorkspaceFileContextStoreTests/testUnloadRootReportsCompletedWatcherStopWhenStopFinishesWithinGrace root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testUnloadRootReportsCompletedWatcherStopWhenStopFinishesWithinGrace WorkspaceContext workspace_file_context_store.unload_root_reports_completed_watcher_stop_when_stop_finishes_within_grace watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.160500 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 989 root/RepoPromptTests.WorkspaceFileContextStoreTests/testValidatedReadAndSearchSnapshotsPublishExactPreEditSourceAndFenceFileIdentity root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testValidatedReadAndSearchSnapshotsPublishExactPreEditSourceAndFenceFileIdentity WorkspaceContext workspace.store.slice_rebase_pre_edit_source validated_read,validated_search,bounded_cache,root_lifetime,file_id,delete_recreate_fence deterministic_regression root_swiftpm routine 3 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Validated read and search snapshots publish their exact pre-edit bytes with matching root lifetime and file identity; deleting and recreating the path changes file ID and cannot reuse the prior source. critical 0.015000 temporary_root,actor_store,disk_io,cache_state test_case+tearDownWithError+root_unload retain 0 bounded lifetime/file-ID fenced source for downstream slice rebasing root/RepoPromptTests.WorkspaceFileContextStoreTests/testValidatedSessionScopeRejectsSamePathRootReplacement root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testValidatedSessionScopeRejectsSamePathRootReplacement WorkspaceContext workspace.session_scope.pinned_root_identity same_path_replacement;root_lifetime;fail_closed;worktree_scope;mutation_rejection async_state_transition root_swiftpm routine 1 WorkspaceFileContextStore;temporary_roots After a session worktree root is replaced at the same path, the pinned scope reports unavailable, excludes the replacement root, rejects catalog/read resolution, rejects physical/canonical service creates, atomically rejects direct store write admission, and leaves disk content unchanged high 0.007000 filesystem WorkspaceFileContextStore.rootStatesByID test_case retain 0 Pinned root identity regression for post-lookup same-path replacement across read, search, mutation resolution, and atomic store write admission -root/RepoPromptTests.WorkspaceFileContextStoreTests/testValidatedSessionSelectorConflictsExposeNoRootsOrCodemapEpochs root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testValidatedSessionSelectorConflictsExposeNoRootsOrCodemapEpochs WorkspaceContext workspace.session_scope.structural_conflict_fail_closed duplicate_root_id;multiple_paths;role_conflict;no_root_leakage;codemap_empty protocol_negative root_swiftpm routine 2 WorkspaceFileContextStore;temporary_roots Within-role path conflicts and cross-role UUID conflicts make availability, root resolution, catalog access, and CodeMap root epochs fail closed without exposing canonical or physical roots. Conflicting selectors could leak one role into store output or trap while building UUID-keyed maps. 0.010000 filesystem;workspace_store WorkspaceFileContextStore.rootStatesByID test_case+temporary_root_cleanup retain 0 REPOPROMPT-2K structural selector regression. -root/RepoPromptTests.WorkspaceFileContextStoreTests/testValidatedSessionSelectorDedupesNameOnlyReferences root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testValidatedSessionSelectorDedupesNameOnlyReferences WorkspaceContext workspace.session_scope.name_insensitive_identity duplicate_root_id;display_name;normalized_path;codemap_epoch deterministic_filesystem_integration root_swiftpm routine 1 WorkspaceFileContextStore;temporary_root Name-only duplicate refs normalize to one canonical UUID/path binding and preserve root plus CodeMap epoch resolution. Display-name drift could crash UUID map construction or make a valid root unavailable. 0.005000 filesystem;workspace_store WorkspaceFileContextStore.rootStatesByID test_case+temporary_root_cleanup retain 0 REPOPROMPT-2K name-only dedupe regression. root/RepoPromptTests.WorkspaceFileContextStoreTests/testWatcherActivationFailureThrowsAndRollsBackStoreLifecycle root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testWatcherActivationFailureThrowsAndRollsBackStoreLifecycle WorkspaceContext workspace_file_context_store.watcher_activation_failure_throws_and_rolls_back_store_lifecycle watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.025000 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 1108 root/RepoPromptTests.WorkspaceFileContextStoreTests/testWatcherAddedUIViewModelsUseStoreRecordIDs root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testWatcherAddedUIViewModelsUseStoreRecordIDs WorkspaceContext workspace_file_context_store.watcher_added_u_i_view_models_use_store_record_i_ds watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.021500 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 4673 root/RepoPromptTests.WorkspaceFileContextStoreTests/testWatcherBoundedWaitPrefersCompletionThatRacesTimeout root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testWatcherBoundedWaitPrefersCompletionThatRacesTimeout WorkspaceContext workspace_file_context_store.watcher_bounded_wait_prefers_completion_that_races_timeout watcher_ingress,accepted_applied_ordering async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStoreTemporaryRootFixture,WorkspaceWatcherIngressFixture Exact publication ordering, accepted/applied barrier or watcher state, resulting catalog/projection, and stop/unload cleanup assertions. Watcher or ingress races could lose, reorder, duplicate, or outlive workspace mutations. 0.000000 temporary_root,actor_store,watcher_publisher,async_tasks test_case+tearDownWithError+explicit_watcher_stop_or_root_unload retain 0 initial census source line 919 @@ -2899,9 +2771,11 @@ root/RepoPromptTests.WorkspaceFilesAppliedIndexProjectionTests/testValidRootUnlo root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testAutomaticPublicationTargetReconstructionPreservesExactReceiptOrder root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testAutomaticPublicationTargetReconstructionPreservesExactReceiptOrder WorkspaceContext codemap.cutover.auto.publication_target_reconstruction_order receipt_order,revalidated_targets,exact_target_order deterministic_model_contract root_swiftpm routine 1 WorkspaceFilesViewModel Given matching receipt and revalidation targets ordered second then first, automatic publication reconstruction returns the corresponding file identities in that exact receipt order. Dictionary lookup or canonical sorting could reorder validated automatic targets and make publication or UI marker order diverge from the authoritative receipt. 0.001000 main_actor,in_memory per_test_state retain 0 Automatic publication reconstruction preserves receipt ordering. root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testAutomaticPublicationTargetReconstructionRejectsEveryMismatchAtomicallyAndRetries root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testAutomaticPublicationTargetReconstructionRejectsEveryMismatchAtomicallyAndRetries WorkspaceContext codemap.cutover.auto.publication_target_reconstruction_fail_closed count_mismatch,order_mismatch,duplicate_target,foreign_root,source_collision,missing_file,atomic_clear,retry protocol_negative root_swiftpm routine 6 WorkspaceFilesViewModel Each of six malformed receipt/revalidation reconstructions is rejected atomically, clears every inferred target, and marks automatic readiness retry pending. Malformed or stale publication targets could be partially committed, retain obsolete markers, or suppress the required retry. 0.000500 main_actor,in_memory per_test_state consolidated_replacement 0 Replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTimeoutClearsProjectionAndReadinessRetryRecovers; six intrinsic mismatch scenarios are credited and no duplicate timeout scenario is transferred. root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testExplicitCodemapOnlyIntentSelectsRequestedManualFileAndDisablesAuto root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testExplicitCodemapOnlyIntentSelectsRequestedManualFileAndDisablesAuto WorkspaceContext codemap.cutover.manual.ui-selection explicit_codemap_only,manual_selection,clear_inferred_projection selection_contract root_swiftpm routine 2 WorkspaceFilesViewModelAutoCodemapFixture An explicit codemap-only UI action clears transient inference, selects the requested file as a persistent manual codemap, and disables auto mode. Explicit manual intent could be lost, converted into full selection, or accidentally retain inferred targets. 0.000000 main_actor,selection_state test_method+view_model_deinit retain 0 D+E P1 manual codemap selection repair +root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testGraphReadinessDoesNotMutateManualMode root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testGraphReadinessDoesNotMutateManualMode WorkspaceContext codemap.cutover.auto.graph_readiness_manual_invariant graph_readiness,manual_mode,no_mode_mutation selection_contract root_swiftpm routine 1 WorkspaceFilesViewModelAutoCodemapFixture A graph readiness event leaves explicit manual mode disabled and the transient auto projection empty. Asynchronous graph publication could silently override user manual intent. 0.000000 main_actor,selection_state test_method+view_model_deinit consolidated_replacement 0 Milestone D readiness resync manual-mode invariant; replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTimeoutClearsProjectionAndReadinessRetryRecovers; the existing manual-mode scenario remains credited once with no transferred duplicate credit. root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testMilestoneDProductionCallersContainNoEagerCodemapOrCacheActions root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testMilestoneDProductionCallersContainNoEagerCodemapOrCacheActions WorkspaceContext codemap.cutover.ui.no_eager_callers source_gate,eager_scan,repair,cache_actions,legacy_stream structural_source_guard root_swiftpm routine 7 WorkspaceFilesViewModel,WorkspaceManagerViewModel,WorkspaceCheckoutRefreshService,AgentModeViewModel,WorkspaceRootBindingProjection Milestone D production integration files contain no eager scan, repair, session initialization, legacy update-stream, or cache-action callers. A future UI or lifecycle edit could reconnect dormant legacy source APIs before Milestone E deletes them. 0.223000 filesystem,source_scan test_method retain 0 Milestone D caller-removal guard; legacy store definitions remain intentionally for Milestone E. root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testNewSourceGenerationClearsExistingInferredMarkersSynchronously root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testNewSourceGenerationClearsExistingInferredMarkersSynchronously WorkspaceContext codemap.cutover.auto.source_generation_marker_reset new_source_generation,inferred_markers,synchronous_clear,automatic_mode state_machine root_swiftpm routine 1 WorkspaceFilesViewModel Selecting a new source generation synchronously clears the prior inferred codemap markers while keeping automatic codemap mode enabled. Stale inferred markers could survive source-generation churn and be presented as current. 0.001000 main_actor,in_memory per_test_state consolidated_replacement 0 Replacement coverage for root/RepoPromptTests.WorkspaceFileContextStoreCodemapSeamTests/testAutomaticSelectionTimeoutClearsProjectionAndReadinessRetryRecovers; one intrinsic source-generation reset scenario is credited and no duplicate timeout scenario is transferred. root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testOrdinaryFileRemovalPreservesAutoAndFullClearRestoresIt root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testOrdinaryFileRemovalPreservesAutoAndFullClearRestoresIt WorkspaceContext workspace_files.auto_codemap_removal_and_clear_reset ordinary_file_remove,full_clear_reset selection_contract root_swiftpm routine 2 WorkspaceFilesViewModelAutoCodemapFixture Removing an ordinary selected file keeps auto mode enabled, while the public full-clear flow empties selections and restores auto mode. Ordinary selection churn could accidentally opt out of automatic codemaps or a full clear could leave the tab stuck in manual mode. 0.001000 main_actor,selection_state,async_tasks test_method+view_model_deinit retain 0 Selection milestone ordinary removal and clear reset +root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testPublicationRevalidationIsFinalAwaitBeforeSynchronousCommit root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testPublicationRevalidationIsFinalAwaitBeforeSynchronousCommit WorkspaceContext codemap.cutover.auto.publication-currentness final_await,generation_check,synchronous_mapping,synchronous_publish structural_source_guard root_swiftpm routine 4 WorkspaceFilesViewModel Receipt revalidation is the final suspension point before synchronous generation checks, target mapping, and projection publication. A post-validation await could allow stale root, catalog, path, or request generations to publish. 0.009000 filesystem,source_scan,main_actor test_method retain 0 Selection milestone final-await publication fence root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testSnapshotAndEncodingContainNoInferredPathState root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testSnapshotAndEncodingContainNoInferredPathState WorkspaceContext codemap.cutover.auto.no-persisted-path-state ui_snapshot,new_encoding,no_inferred_paths serialization_contract root_swiftpm routine 2 WorkspaceFilesViewModelAutoCodemapFixture,StoredSelection UI snapshots persist explicit selected, sliced, and manual-codemap paths while inferred automatic targets remain transient and unencoded. Transient graph targets could regain serialized or compatibility-projection authority. 0.001000 main_actor,codable,selection_state test_method+view_model_deinit retain 0 Selection milestone zero persisted inferred-path state root/RepoPromptTests.WorkspaceGitDataRootLoadingTests/testReturnsAndReusesExactWorkspaceGitDataRoot root Tests/RepoPromptTests/WorkspaceContext/WorkspaceGitDataRootLoadingTests.swift RepoPromptTests.WorkspaceGitDataRootLoadingTests testReturnsAndReusesExactWorkspaceGitDataRoot WorkspaceContext workspace.git_data_root.load_and_reuse root_loading,exact_identity,reuse main_actor_filesystem_integration root_swiftpm routine 2 WorkspaceFileContextStore Workspace Git-data root loading returns and reuses the exact workspaceGitData root identity. Repeated publication could create divergent root identities or fail to catalog artifacts. 0.087500 filesystem;workspace_store workspace_manager per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.WorkspaceGitDataRootLoadingTests/testSystemWorkspaceAndWrongLoadedKindFailExplicitly root Tests/RepoPromptTests/WorkspaceContext/WorkspaceGitDataRootLoadingTests.swift RepoPromptTests.WorkspaceGitDataRootLoadingTests testSystemWorkspaceAndWrongLoadedKindFailExplicitly WorkspaceContext workspace.git_data_root.explicit_failures system_workspace,wrong_kind,fail_closed main_actor_filesystem_integration root_swiftpm routine 2 WorkspaceFileContextStore System workspaces and an already-loaded wrong-kind root fail explicitly. Git-data publication could attach to an unauthorized workspace or wrong root kind. 0.008500 filesystem;workspace_store workspace_manager per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation @@ -2936,23 +2810,18 @@ root/RepoPromptTests.WorkspacePerRootPathSearchIndexTests/testOverlayTransitions root/RepoPromptTests.WorkspacePerRootPathSearchIndexTests/testPerRootMergeMatchesAuthoritativeGlobalIndexAcrossScopes root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift RepoPromptTests.WorkspacePerRootPathSearchIndexTests testPerRootMergeMatchesAuthoritativeGlobalIndexAcrossScopes WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.023000 unreviewed retain_pending_review 0 initial census source line 21 root/RepoPromptTests.WorkspacePerRootPathSearchIndexTests/testRootUnloadDropsOnlyItsReadyIndexWhileReplacementGenerationIsPending root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift RepoPromptTests.WorkspacePerRootPathSearchIndexTests testRootUnloadDropsOnlyItsReadyIndexWhileReplacementGenerationIsPending WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.317500 unreviewed retain_pending_review 0 initial census source line 144 root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testFirstParityMismatchAtomicallyDisablesRetainedShadow root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testFirstParityMismatchAtomicallyDisablesRetainedShadow WorkspaceContext worktree_seed.shadow_fail_closed_once parity_mismatch,atomic_disable,concurrent_search,retained_index,no_rerun concurrency root_swiftpm routine 3 SyntheticProjectedSearchSnapshot Concurrent first mismatches produce one comparison, atomically discard the projection, and retained indexes never rerun it. A copied projection could survive store invalidation or repeatedly execute after known divergence. 0.013500 c_index;bounded_in_memory lock_protected_shadow_control test_case retain 0 Milestone 8C P1 fail-closed shadow isolation repair. -root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testMaterializedOverlayHistoryUsesBoundedPagesWithoutInvalidatingRetainedGeneration root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testMaterializedOverlayHistoryUsesBoundedPagesWithoutInvalidatingRetainedGeneration WorkspaceContext workspace_path_search.materialized_overlay_bounded_page_lifetime bounded_pages,materialized_overlay,reader_lifetime,shared_page_tail,exact_order deterministic_integration root_swiftpm routine 3 WorkspaceSearchRootPathIndex After 340 materialized-overlay patches, the current index remains structurally bounded and search-exact while both a recent-payload generation and a shared-page-tail generation retain their own exact results. Paged overlay history could exceed structural bounds, invalidate retained readers, or reorder current or historical search results. 0.031500 bounded_in_memory path_search_index test_case retain 0 Reconciles pre-existing rename root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testMaterializedOverlaySegmentsCompactWithoutInvalidatingRetainedGeneration -> root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testMaterializedOverlayHistoryUsesBoundedPagesWithoutInvalidatingRetainedGeneration from c1429603f2ca1426077e847d6e7fb422e3459eb0; scenarios are current bounded/search parity, retained recent payloads, and retained shared-page tail. -root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testOverlayHistoryPagesPreserveOrderBranchesAndIterativeSharedTailRelease root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testOverlayHistoryPagesPreserveOrderBranchesAndIterativeSharedTailRelease WorkspaceContext workspace_path_search.overlay_history_page_lifetime newest_first_order,full_page_branch,recent_branch,shared_page_tail,iterative_teardown deterministic_regression root_swiftpm routine 4 WorkspacePathSearchOverlayHistory Exact newest-first order and page metrics survive both full-page and recent-payload branches, and releasing a 2,048-page history deinitializes only the unique prefix before safely releasing the retained shared tail. A recursive page teardown could overflow the stack, a branch could reorder history, or shared-tail release could prematurely destroy retained payloads. bounded_in_memory deinit_probe retain 0 Reconciles the live test added without a ledger row by c1429603f2ca1426077e847d6e7fb422e3459eb0; scenarios are base page order, full-page branch, recent-payload branch, and iterative shared-tail teardown. +root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testMaterializedOverlaySegmentsCompactWithoutInvalidatingRetainedGeneration root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testMaterializedOverlaySegmentsCompactWithoutInvalidatingRetainedGeneration WorkspaceContext workspace_path_search.segment_compaction_lifetime segments,compaction,reader_lifetime,exact_order deterministic_integration root_swiftpm routine 1 WorkspaceSearchRootPathIndex Compaction publishes a new immutable segment chain while retained generations stay exact. Compaction could invalidate readers or reorder top-K. 0.031500 bounded_in_memory path_search_index test_case retain 0 Added exact immutable-generation compaction coverage; no entry-count fallback. root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testProjectedMatcherCancellationJoinsLargeWorker root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testProjectedMatcherCancellationJoinsLargeWorker WorkspaceContext worktree_seed.projected_search_cooperative_cancellation large_base,c_atomic,swift_task,joined_worker,no_partial_results concurrency root_swiftpm routine 2 LargeProjectedSearchIndex Immediate task cancellation reaches the C scan, returns a cancelled outcome before exhausting the fixture, and joins the detached worker before value completion. Unstructured projected work could outlive a cancelled caller and record partial parity or consume unbounded background work. 0.776000 c_index;large_in_memory task_cancellation test_case+worker_join retain 0 Milestone 8C P1 cooperative cancellation repair. root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testProjectedMatcherExactlyMatchesFullTargetIndexAcrossQueriesAndLimits root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testProjectedMatcherExactlyMatchesFullTargetIndexAcrossQueriesAndLimits WorkspaceContext worktree_seed.projected_search_exact_parity literal,wildcard,space_and,unicode,newline,absolute,display,limit,ordering deterministic_unit root_swiftpm routine 9 SyntheticProjectedSearchSnapshot Projected membership, IDs, score, tie-break key, ordering, and limits exactly match the authoritative full target index. A relative-only matcher could diverge for target prefixes or top-K ordering. 0.005500 c_index;bounded_in_memory test_case retain 0 Milestone 8C projected matcher parity. root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testProjectedMatcherUsesBoundedTopKStorageAndReusableScratch root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testProjectedMatcherUsesBoundedTopKStorageAndReusableScratch WorkspaceContext worktree_seed.projected_search_bounded_top_k large_base,heap,top_k,reusable_scratch,virtual_key,control_byte boundary root_swiftpm routine 4 LargeProjectedSearchIndex A 20k-entry projection exactly matches the full index while heap peak equals K, comparison work is logarithmically bounded, and one max-key scratch buffer is used. Per-entry keys or linear insertion could make shadow search O(baseCount*limit) in time or allocations. 0.625000 c_index;bounded_heap;large_in_memory test_case retain 0 Milestone 8C P1 projected-search complexity repair. root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testProjectionHasNoEntryCountFallbackAndPreservesCrossRootIsolation root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testProjectionHasNoEntryCountFallbackAndPreservesCrossRootIsolation WorkspaceContext worktree_seed.projected_search_scope_boundary overlay_31,overlay_32,cross_root_negative protocol_negative root_swiftpm routine 3 SyntheticProjectedSearchSnapshot Thirty-one and thirty-two changes both remain exact segmented projections with materialized-search parity, and foreign root prefixes never match or enter results. Segment or tombstone handling could reorder exact top-K results or leak across root-local graph boundaries. 0.011000 c_index;bounded_in_memory test_case retain 0 Enterprise D segmented projection parity; the former 31/32 boundary is a regression point, not a fallback threshold. -root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testRealProjectedPatchesUseBoundedPagesAndRetainOlderGenerations root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testRealProjectedPatchesUseBoundedPagesAndRetainOlderGenerations WorkspaceContext worktree_seed.real_projected_patch_page_history add,delete,rename,modify,31,32,bounded_pages,immutable_generation,shared_page_tail boundary root_swiftpm routine 8 SyntheticProjectedSearchSnapshot Real projected generations preserve add/delete/rename/modify and former 31/32-boundary parity, remain within bounded page metrics through 340 payloads, and keep both pre-page and shared-page-tail generations immutable and search-exact. Paged projected history could lose tombstones, exceed structural bounds, invalidate older generations or shared tails, or change deterministic result ordering. 0.142000 c_index;bounded_in_memory test_case retain 0 Reconciles pre-existing rename root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testRealProjectedPatchesCross32CompactSegmentsAndRetainOlderGenerations -> root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testRealProjectedPatchesUseBoundedPagesAndRetainOlderGenerations from c1429603f2ca1426077e847d6e7fb422e3459eb0; preserves six prior patch/boundary scenarios and adds bounded-page and retained shared-tail scenarios. +root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testRealProjectedPatchesCross32CompactSegmentsAndRetainOlderGenerations root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testRealProjectedPatchesCross32CompactSegmentsAndRetainOlderGenerations WorkspaceContext worktree_seed.real_projected_patch_boundary add,delete,rename,modify,31,32,immutable_generation boundary root_swiftpm routine 6 SyntheticProjectedSearchSnapshot Real projected generations append immutable segments across 32 distinct paths, compact segment blocks without materializing the root, preserve retained readers, and maintain exact top-K parity. Segment compaction could invalidate older generations, lose tombstones, or change deterministic result ordering. 0.142000 c_index;bounded_in_memory test_case retain 0 Enterprise D watcher-fenced segmented serving coverage across the former 31/32 cliff. root/RepoPromptTests.WorkspaceProjectedPathSearchTests/testRealProjectedRootIndexExactlyMatchesMaterializedSearchAndEntryOrdering root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceProjectedPathSearchTests.swift RepoPromptTests.WorkspaceProjectedPathSearchTests testRealProjectedRootIndexExactlyMatchesMaterializedSearchAndEntryOrdering WorkspaceContext worktree_seed.real_projected_search_parity empty_query,matcher,ordering,limit deterministic_unit root_swiftpm routine 4 SyntheticProjectedSearchSnapshot The serving projected root index exactly matches materialized results, empty-query order, and limits. First search could diverge from authoritative target-local path semantics. 0.004500 c_index;bounded_in_memory test_case retain 0 Milestone 8D watcher-fenced atomic serving coverage. root/RepoPromptTests.WorkspacePublishedGitArtifactIngressTests/testLoadedBeforeWriteIngressCatalogsExactSnapshotWithoutWatcherDelivery root Tests/RepoPromptTests/WorkspaceContext/WorkspacePublishedGitArtifactIngressTests.swift RepoPromptTests.WorkspacePublishedGitArtifactIngressTests testLoadedBeforeWriteIngressCatalogsExactSnapshotWithoutWatcherDelivery WorkspaceContext workspace.git_artifact_ingress.post_write loaded_before_write,no_watcher,exact_catalog deterministic_filesystem_integration root_swiftpm routine 1 GitDiffPublishedArtifactSet,WorkspaceFileContextStore Explicit post-write ingress catalogs the exact snapshot even when no watcher event arrives. Freshly published artifacts could remain unreadable until an unrelated watcher callback. 0.008500 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.WorkspacePublishedGitArtifactIngressTests/testPartialIngressRequiresManifestAndCandidateReadiness root Tests/RepoPromptTests/WorkspaceContext/WorkspacePublishedGitArtifactIngressTests.swift RepoPromptTests.WorkspacePublishedGitArtifactIngressTests testPartialIngressRequiresManifestAndCandidateReadiness WorkspaceContext workspace.git_artifact_ingress.partial_readiness manifest,candidate_readiness,partial_failure deterministic_filesystem_integration root_swiftpm routine 2 GitDiffPublishedArtifactSet,WorkspaceFileContextStore Partial ingress marks artifacts selection-ready only when manifest and candidate records are readable. Publication could auto-select a patch whose manifest or content failed ingress. 0.010500 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.WorkspacePublishedGitArtifactIngressTests/testRootUnloadDuringIngressInvalidatesWholeBatch root Tests/RepoPromptTests/WorkspaceContext/WorkspacePublishedGitArtifactIngressTests.swift RepoPromptTests.WorkspacePublishedGitArtifactIngressTests testRootUnloadDuringIngressInvalidatesWholeBatch WorkspaceContext workspace.git_artifact_ingress.root_lifetime_batch root_unload,batch_atomicity,fail_closed deterministic_async_filesystem_integration root_swiftpm routine 1 GitDiffPublishedArtifactSet,WorkspaceFileContextStore Root unload during ingress invalidates the entire artifact batch. A partial batch could survive after capability root lifetime ends. 0.006500 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation root/RepoPromptTests.WorkspacePublishedGitArtifactIngressTests/testWrongRootKindLifetimeAndTraversalFailClosedWithOrderedOutcomes root Tests/RepoPromptTests/WorkspaceContext/WorkspacePublishedGitArtifactIngressTests.swift RepoPromptTests.WorkspacePublishedGitArtifactIngressTests testWrongRootKindLifetimeAndTraversalFailClosedWithOrderedOutcomes WorkspaceContext workspace.git_artifact_ingress.security_failures wrong_kind,stale_root,path_traversal,ordered_outcomes deterministic_filesystem_integration root_swiftpm routine 3 GitDiffPublishedArtifactSet,WorkspaceFileContextStore Wrong root kind, stale lifetime, and traversal inputs fail closed with deterministic outcomes. Ingress could cross root boundaries, accept stale authority, or return nondeterministic partial status. 0.009000 filesystem;workspace_store per_test_temporary_root_cleanup retain 0 Uncommitted #264 contract reconciliation -root/RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests/testFullyEqualReferenceAcrossRolesConflicts root Tests/RepoPromptTests/WorkspaceContext/WorkspaceLookupRootSelectorValidatorTests.swift RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests testFullyEqualReferenceAcrossRolesConflicts WorkspaceContext workspace.session_scope.selector_role_uniqueness canonical_role;physical_role;equal_ref;fail_closed protocol_negative root_swiftpm fast 1 WorkspaceRootRef A fully equal ref present in both role sets returns the categorical multiple-role conflict. Equal set members could bypass role-conflict detection and leak a root across authority roles. 0.000000 in_memory test_case retain 0 REPOPROMPT-2K pure validator regression. -root/RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests/testNameOnlyDuplicatesNormalizeToOneIDPathBinding root Tests/RepoPromptTests/WorkspaceContext/WorkspaceLookupRootSelectorValidatorTests.swift RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests testNameOnlyDuplicatesNormalizeToOneIDPathBinding WorkspaceContext workspace.session_scope.selector_name_insensitive_identity display_name;path_standardization;dedupe;uuid_map deterministic_unit root_swiftpm fast 1 WorkspaceRootRef Name-divergent refs with one UUID and standardized path produce one canonical UUID-to-path binding. Display names could become structural identity and trigger duplicate-key traps. 0.000000 in_memory test_case retain 0 REPOPROMPT-2K pure validator regression. -root/RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests/testWithinRoleMultiplePathConflictFailsClosed root Tests/RepoPromptTests/WorkspaceContext/WorkspaceLookupRootSelectorValidatorTests.swift RepoPromptTests.WorkspaceLookupRootSelectorValidatorTests testWithinRoleMultiplePathConflictFailsClosed WorkspaceContext workspace.session_scope.selector_path_uniqueness duplicate_root_id;multiple_paths;categorical_conflict protocol_negative root_swiftpm fast 1 WorkspaceRootRef One UUID mapped to two canonical paths returns the categorical multiple-path conflict. Ambiguous UUID-to-path authority could select an arbitrary root or trap during map construction. 0.000000 in_memory test_case retain 0 REPOPROMPT-2K pure validator regression. root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testBoundRootsForMetadataAreDeterministicallySorted root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testBoundRootsForMetadataAreDeterministicallySorted WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 86 -root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testLogicalRootLabelsDeduplicatePhysicalIDsBeforeCollisionAccountingUsingFirstDescriptor root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testLogicalRootLabelsDeduplicatePhysicalIDsBeforeCollisionAccountingUsingFirstDescriptor WorkspaceContext workspace.logical_root_identity.first_descriptor_deduplication duplicate_physical_id,first_descriptor,collision_accounting,input_order deterministic_regression root_swiftpm routine 2 Both descriptor orders return exactly two labels; the first shared descriptor determines its generated epoch label, while only retained preferred names participate in Control collision resolution. A duplicate physical root could trap unique-key construction or inflate name counts and replace stable logical labels. 0.000000 in_memory test_case retain 0 Item 1 duplicate-ID normalization regression; two conflicting-order scenarios preserve first-whole-descriptor semantics. root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testDuplicateLogicalRootBasenamesProduceStableUniqueNonPhysicalLabels root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testDuplicateLogicalRootBasenamesProduceStableUniqueNonPhysicalLabels WorkspaceContext headless_p1.logical_root_identity duplicate_basename,worktree_scope,path_leak deterministic_regression root_swiftpm routine 2 WorkspaceRootBindingProjectionFixture Permutation-stable duplicate labels are unique and encoded worktree scope contains no logical or physical absolute roots. Root metadata could be ambiguous or expose canonical/worktree paths. 0.001000 test_case retain 0 Headless P1 grouped repair root identity contract root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testFileTreeSnapshotIsDisplayedAsLogicalRoot root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testFileTreeSnapshotIsDisplayedAsLogicalRoot WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 136 root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testMaterializationStartsZeroCodemapTasks root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testMaterializationStartsZeroCodemapTasks WorkspaceContext workspace_projection.materialization_zero_codemap_work materialize,zero_scan,zero_demand,zero_freeze,zero_initialization deterministic_integration root_swiftpm routine 4 WorkspaceRootBindingProjectionTemporaryRootFixture,ProjectionCodemapCounter Session-worktree materialization starts zero legacy scans, modern demands, presentation freezes, or initialization tasks. Root materialization could regress to eager scan fan-out or hidden modern work. 0.019000 temporary_root,actor_store,async_probe per_test_materializer+explicit_session_owner_release retain 0 Milestone D removes materializer initializeCodemaps while preserving root ownership. @@ -2962,8 +2831,6 @@ root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testMaterializerFailsCl root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testSelectionCanPhysicalizeForLookupThenLogicalizeForPersistence root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testSelectionCanPhysicalizeForLookupThenLogicalizeForPersistence WorkspaceContext workspace.binding_projection.selection_identity physicalize_round_trip,logical_physical_alias_slice_union deterministic_unit root_swiftpm routine 2 workspace_root_binding_projection Selection paths round-trip through a worktree projection, and logical/physical aliases that collapse to one identity union their slice ranges without narrowing. high 0.000500 in_memory per_test_state retain 0 read-file rebasing path-identity and alias-collision coverage root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testSingleBoundRootDoesNotStealUnboundRootAlias root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testSingleBoundRootDoesNotStealUnboundRootAlias WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 55 root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testSingleBoundRootProjectsRelativeAndLogicalPathsToWorktree root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testSingleBoundRootProjectsRelativeAndLogicalPathsToWorktree WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000500 unreviewed retain_pending_review 0 initial census source line 6 -root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testTwoBindingsSharingWorktreeEmitOneDeterministicPhysicalRoot root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testTwoBindingsSharingWorktreeEmitOneDeterministicPhysicalRoot WorkspaceContext workspace.binding_projection.shared_physical_read_projection two_logical_bindings;shared_worktree;non_sorted_input;physical_root_deduplication;ownership;availability;scoped_lookup;content_read;worktree_scope;first_wins_label;reply_projection;path_redaction deterministic_filesystem_integration root_swiftpm routine 4 WorkspaceRootBindingProjectionTemporaryRootFixture;SharedWorktreeSwiftSourceFixture;ToolResultDTOs.ReadFileReply Non-sorted logical bindings sharing one owned worktree materialize one available scoped physical root; an absolute logical file path translates into that root, lookup/read returns fixture bytes, and the projected read reply preserves content/display plus two ordered mappings with the store-derived first-wins label while encoded output redacts all absolute roots. Shared bindings could produce duplicate physical refs or unavailable scope, resolve/read canonical content, diverge between store and worktree-scope label authorities, reorder or collapse mappings, drop reply content/scope, or leak canonical/worktree absolute paths. 0.020000 temporary_root;actor_store;async_projection_worker;json_encoding WorkspaceFileContextStore.sessionWorktreeOwnership test_case+temporary_fixture_cleanup+explicit_session_owner_release+logical_root_unload retain 0 Item 3 expands the existing shared-physical regression across materialization/ownership, scoped lookup/read, projected reply, and encoded redaction boundaries. -root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testWorktreeScopeDeduplicatesSharedPhysicalLabelSourceButPreservesLogicalMappings root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testWorktreeScopeDeduplicatesSharedPhysicalLabelSourceButPreservesLogicalMappings WorkspaceContext workspace.worktree_scope.shared_physical_label_source shared_physical_root,stable_first_label_source,logical_mapping_cardinality,binding_metadata,path_redaction deterministic_regression root_swiftpm routine 2 Ordered shared-root mappings use the first logical-path binding as their common label source while preserving per-binding metadata; equal mapping values remain duplicated and encoded paths stay redacted. Duplicate physical label sources could trap DTO construction, choose unstable labels, collapse logical mappings, lose binding metadata, or expose absolute paths. 0.000000 in_memory test_case retain 0 Item 2 direct DTO regression; two scenarios cover distinct ordered worktrees and intentionally equal duplicate mapping values. root/RepoPromptTests.WorkspaceRootBindingProjectionTests/testWorktreeScopeMetadataUsesBindingWorktreeNameForEffectiveName root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootBindingProjectionTests.swift RepoPromptTests.WorkspaceRootBindingProjectionTests testWorktreeScopeMetadataUsesBindingWorktreeNameForEffectiveName WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 103 root/RepoPromptTests.WorkspaceRootCreationReceiptCoordinatorTests/testActivationUsesExplicitCutAndWaitsForFlushAndCallbackBarrier root Tests/RepoPromptTests/Services/VCS/WorkspaceRootCreationReceiptCoordinatorTests.swift RepoPromptTests.WorkspaceRootCreationReceiptCoordinatorTests testActivationUsesExplicitCutAndWaitsForFlushAndCallbackBarrier Services worktree_receipt.witness_activation_cut_barrier explicit_start_cut,pre_start_replay,flush,accepted_watermark,callback_barrier deterministic_unit root_swiftpm routine 3 WitnessFixture;ScriptedWitnessBackend The stream replays an event after the explicit cut but before start, and startup returns only after flush plus callback acceptance with the expected watermark. Mutation could begin before the witness can accept replayed creation events. 0.001500 bounded_in_memory;temp_directory callback_queue;recorder_lock test_case+fixture_cleanup+stream_teardown retain 0 Deterministic activation/readiness contract. root/RepoPromptTests.WorkspaceRootCreationReceiptCoordinatorTests/testAdmissionAndStableRootReplacementRemainFailClosed root Tests/RepoPromptTests/Services/VCS/WorkspaceRootCreationReceiptCoordinatorTests.swift RepoPromptTests.WorkspaceRootCreationReceiptCoordinatorTests testAdmissionAndStableRootReplacementRemainFailClosed Services worktree_receipt.witness_stable_root_admission existing_destination,equal_destination,root_replacement,device_inode protocol_negative root_swiftpm routine 3 WitnessFixture;ScriptedWitnessBackend An existing destination, a non-strict destination, and replacement of the stable root all reject proof. The witness could watch an unsafe path or survive movement/replacement of its authority root. 0.001000 bounded_in_memory;temp_directory callback_queue;recorder_lock test_case+fixture_cleanup+stream_teardown retain 0 Canonical stable-root admission and identity contract. @@ -3011,7 +2878,6 @@ root/RepoPromptTests.WorkspaceRootSyncTests/testReorderRootFoldersNoOpDoesNotEmi root/RepoPromptTests.WorkspaceRootSyncTests/testRootShellProjectionBatchPublishesOneFinalNotification root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testRootShellProjectionBatchPublishesOneFinalNotification Workspaces workspace_roots.sidebar_projection.batch_final_order workspace_switch,root_attach_batch,reorder state_observation root_swiftpm routine 1 A batched root attach plus reorder suppresses intermediate emissions and publishes one final visible-root ID snapshot in reordered order. Workspace switch hydration could expose transient append order before final root ordering settles. direct_in_process;combine_publisher test_case retain 0 PR #351 cleanup: retained minimal root attach/reorder batching contract. root/RepoPromptTests.WorkspaceRootSyncTests/testRootShellProjectionPublisherIgnoresUnrelatedPublishedChanges root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testRootShellProjectionPublisherIgnoresUnrelatedPublishedChanges Workspaces workspace_roots.sidebar_projection.publisher_precision objectWillChange,root_rows,noise_suppression state_observation_negative root_swiftpm routine 1 Changing unrelated published workspace-file state does not emit the root-shell projection publisher. Non-root file tree or selection churn could continue driving Agent Mode sidebar root-row resnapshots. direct_in_process;combine_publisher test_case retain 0 PR #351 cleanup: retained precise-publisher negative boundary. root/RepoPromptTests.WorkspaceRootSyncTests/testRootShellProjectionsMirrorRootOrderAndHideSystemRootsForVisibleProjection root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testRootShellProjectionsMirrorRootOrderAndHideSystemRootsForVisibleProjection Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 102 -root/RepoPromptTests.WorkspaceRootSyncTests/testValidatedSessionSelectorFiltersSafelyWithoutDuplicateIDTrapOrRoleLeakage root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testValidatedSessionSelectorFiltersSafelyWithoutDuplicateIDTrapOrRoleLeakage WorkspaceFiles workspace_files.validated_selector_fail_closed name_dedupe;multiple_paths;role_conflict;ui_filtering;no_trap deterministic_unit root_swiftpm routine 3 WorkspaceFilesViewModel;FolderViewModel The UI file projection returns the valid name-deduped root while path and role conflicts return empty without trapping or leaking either role. Opening a conflicting session scope could crash the UI or display unauthorized canonical/physical files. 0.001000 in_memory WorkspaceFilesViewModel.rootFolders test_case retain 0 REPOPROMPT-2K UI regression. root/RepoPromptTests.WorkspaceRootSyncTests/testWorkspaceDecodeCreatesDefaultComposeTabAndIgnoresRemovedLegacyFields root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testWorkspaceDecodeCreatesDefaultComposeTabAndIgnoresRemovedLegacyFields Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 136 root/RepoPromptTests.WorkspaceRootSyncTests/testWorkspaceFolderLoadConcurrencyLimitIsBounded root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testWorkspaceFolderLoadConcurrencyLimitIsBounded Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 174 root/RepoPromptTests.WorkspaceRootSyncTests/testWorkspaceSaveMergeKeepsLocalRepoPathsAfterLocalRootEdit root Tests/RepoPromptTests/WorkspaceRootSyncTests.swift RepoPromptTests.WorkspaceRootSyncTests testWorkspaceSaveMergeKeepsLocalRepoPathsAfterLocalRootEdit Root unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.000000 unreviewed retain_pending_review 0 initial census source line 201 @@ -3030,11 +2896,6 @@ root/RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests/testManifestAuthen root/RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests/testManifestRejectsDuplicateByteExactPathWithoutPublishing root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootTargetSeedPlanManifestTests.swift RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests testManifestRejectsDuplicateByteExactPathWithoutPublishing WorkspaceContext workspace_root_target_plan.duplicate_rejection duplicate,byte_exact,transactional_publication protocol_negative root_swiftpm routine 2 WorkspaceRootTargetSeedPlanManifestStore Duplicate paths fail without publication. Duplicate paths could make reconciliation ambiguous. 0.002000 temp_directory;spill_io manifest_store test_case+lease_cleanup retain 0 Ephemeral plan schema with inventory compatibility v4; no adapter. root/RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests/testManifestScaleStreamsAreBounded root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootTargetSeedPlanManifestTests.swift RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests testManifestScaleStreamsAreBounded WorkspaceContext target_seed_plan_manifest.routine_boundary manifest_streaming,seeded_inventory,routine_boundary stress root_swiftpm routine 2 WorkspaceRootTargetSeedPlanManifestStore 10K target seed plans stream sorted overlay records with exact footer/reader counts and bounded buffered/resident path bytes. Target seed plan manifests could regress bounded streaming behavior in routine overlay publication. 1.0 routine_scale temporary_artifacts test_case retain 0 routine 10K boundary contract replacing the default 100K run root/RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests/testManifestScaleStreamsOneHundredThousandOrMillionWhenEnabled root Tests/RepoPromptTests/WorkspaceContext/WorkspaceRootTargetSeedPlanManifestTests.swift RepoPromptTests.WorkspaceRootTargetSeedPlanManifestTests testManifestScaleStreamsOneHundredThousandOrMillionWhenEnabled WorkspaceContext target_seed_plan_manifest.scale_100k_or_million manifest_streaming,seeded_inventory,scale_gate,million_opt_in stress root_swiftpm scale 3 WorkspaceRootTargetSeedPlanManifestStore 100K target seed plans, or 1M when RPCE_RUN_MILLION_ENTRY_TESTS=1, stream sorted records with exact footer counts and bounded buffered/resident path bytes. Target seed plan manifests could buffer too much data or corrupt counts during large overlay publication. 6.0 scale,opt_in temporary_artifacts test_case retain 0 gated behind RPCE_RUN_SCALE_TESTS=1 for 100K; RPCE_RUN_MILLION_ENTRY_TESTS=1 still selects the million-entry lane -root/RepoPromptTests.WorkspaceSavePreparationTests/testPreparationFailureDoesNotAdvanceLastSavedVersion root Tests/RepoPromptTests/Workspaces/WorkspaceSavePreparationTests.swift RepoPromptTests.WorkspaceSavePreparationTests testPreparationFailureDoesNotAdvanceLastSavedVersion Workspaces workspace_save.preparation_failure_not_acknowledged encode_failure,last_saved_version,dirty_state persistence_negative root_swiftpm routine 1 WorkspaceSaveTemporaryRootFixture A save preparation failure leaves the dirty state version unacknowledged and does not advance lastSavedVersion. Encode or pre-enqueue failures could be acknowledged as durable and suppress the required retry. temporary_root,workspace_disk_writer,main_actor_manager WorkspaceDiskWriter,GlobalSettingsStore test_case+tearDown+temporary_root_cleanup retain 0 REPOPROMPT-A deterministic workspace-save preparation contract -root/RepoPromptTests.WorkspaceSavePreparationTests/testQuiescentCapturePublishesWorkspaceOnceWithoutReloadingComposeTabs root Tests/RepoPromptTests/Workspaces/WorkspaceSavePreparationTests.swift RepoPromptTests.WorkspaceSavePreparationTests testQuiescentCapturePublishesWorkspaceOnceWithoutReloadingComposeTabs Workspaces workspace_save.quiescent_single_publication capture_coalescing,compose_tabs,reload_gate state_observation root_swiftpm routine 1 WorkspaceSaveTemporaryRootFixture,WorkspaceSaveCapturePublicationDiagnostics A quiescent save capture records exactly one capture-scoped workspace element publication and does not reload already-equivalent compose tabs. Routine capture could publish multiple intermediate workspace states or reconstruct tabs unnecessarily. temporary_root,debug_diagnostics,main_actor_manager WorkspaceDiskWriter,GlobalSettingsStore test_case+tearDown+temporary_root_cleanup retain 0 REPOPROMPT-A deterministic workspace-save preparation contract -root/RepoPromptTests.WorkspaceSavePreparationTests/testSaveBailsWithoutEnqueueOrAcknowledgementWhenWorkspaceRemovedAfterPreparation root Tests/RepoPromptTests/Workspaces/WorkspaceSavePreparationTests.swift RepoPromptTests.WorkspaceSavePreparationTests testSaveBailsWithoutEnqueueOrAcknowledgementWhenWorkspaceRemovedAfterPreparation Workspaces workspace_save.removal_after_await_bails workspace_identity,removal_after_await,no_enqueue,no_acknowledgement deterministic_concurrency root_swiftpm routine 1 WorkspaceSaveTemporaryRootFixture,WorkspaceSavePreparationGate Removing the captured workspace while preparation is suspended prevents enqueue, disk creation, and lastSavedVersion acknowledgement. A stale index after an await could write a removed workspace or acknowledge unsaved state. temporary_root,workspace_disk_writer,async_gate,main_actor_manager WorkspaceDiskWriter,GlobalSettingsStore test_case+tearDown+temporary_root_cleanup retain 0 REPOPROMPT-A deterministic workspace-save preparation contract -root/RepoPromptTests.WorkspaceSavePreparationTests/testSaveKeepsCapturedWorkspaceIdentityAndURLAcrossReorderAfterPreparation root Tests/RepoPromptTests/Workspaces/WorkspaceSavePreparationTests.swift RepoPromptTests.WorkspaceSavePreparationTests testSaveKeepsCapturedWorkspaceIdentityAndURLAcrossReorderAfterPreparation Workspaces workspace_save.explicit_identity_url_across_reorder workspace_identity,exact_file_url,reorder_after_await deterministic_concurrency root_swiftpm routine 1 WorkspaceSaveTemporaryRootFixture,WorkspaceSavePreparationGate Reordering workspaces while preparation is suspended still saves the originally captured workspace ID to its exact captured URL. A stale array index could redirect a save to a different workspace or storage path after suspension. temporary_root,workspace_disk_writer,async_gate,main_actor_manager WorkspaceDiskWriter,GlobalSettingsStore test_case+tearDown+temporary_root_cleanup retain 0 REPOPROMPT-A deterministic workspace-save preparation contract -root/RepoPromptTests.WorkspaceSavePreparationTests/testSaveRetriesSameIdentityOnceWhenStateChangesAfterPreparation root Tests/RepoPromptTests/Workspaces/WorkspaceSavePreparationTests.swift RepoPromptTests.WorkspaceSavePreparationTests testSaveRetriesSameIdentityOnceWhenStateChangesAfterPreparation Workspaces workspace_save.bounded_same_identity_retry workspace_identity,state_version,bounded_retry deterministic_concurrency root_swiftpm routine 1 WorkspaceSaveTemporaryRootFixture A state-version change after preparation performs exactly one same-ID retry and persists the newer state. Unbounded retry or stale-index reuse could hang saves or persist the wrong workspace generation. temporary_root,workspace_disk_writer,main_actor_manager WorkspaceDiskWriter,GlobalSettingsStore test_case+tearDown+temporary_root_cleanup retain 0 REPOPROMPT-A deterministic workspace-save preparation contract root/RepoPromptTests.WorkspaceSearchServiceTests/testPathMatchWarmupPreservesLookupBehavior root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift RepoPromptTests.WorkspaceSearchServiceTests testPathMatchWarmupPreservesLookupBehavior WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.003000 unreviewed retain_pending_review 0 initial census source line 311 root/RepoPromptTests.WorkspaceSearchServiceTests/testSearchCatalogGenerationChangesOnRootLoadDeltaAndUnload root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift RepoPromptTests.WorkspaceSearchServiceTests testSearchCatalogGenerationChangesOnRootLoadDeltaAndUnload WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.005500 unreviewed retain_pending_review 0 initial census source line 15 root/RepoPromptTests.WorkspaceSearchServiceTests/testWorkspaceSearchServiceCatchesUpWhenEventPrecedesSubscription root Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift RepoPromptTests.WorkspaceSearchServiceTests testWorkspaceSearchServiceCatchesUpWhenEventPrecedesSubscription WorkspaceContext unreviewed unreviewed root_swiftpm routine 1 unreviewed unreviewed 0.016000 unreviewed retain_pending_review 0 initial census source line 227 @@ -3241,18 +3102,6 @@ root/RepoPromptTests.HistoryMCPToolServiceTests/testTime_groupByDay_attributedPe root/RepoPromptTests.HistoryMCPToolServiceTests/testTime_groupByDayHonorsLimit root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testTime_groupByDayHonorsLimit AgentMode/History history.mcp_service.time_group_by_day_honors_limit history_mcp,validation,truncation,token_budget deterministic_service_contract root_swiftpm routine 1 HistoryMCPMockScannerFixture History tool service returns exact DTOs, validation errors, truncation flags, scan diagnostics, and active-duration aggregates for mocked session records/transcripts. History MCP callers could receive misleading validation, missing sessions, excessive output, or incorrect time/search results. direct_in_process;mock_scanner UserDefaults.historyIdleThreshold test_case retain 0 PR #303 history MCP service contract row; reviewed in final minimization pass. root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_budgetExhaustionKeepsReturnedRangeContiguous root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_budgetExhaustionKeepsReturnedRangeContiguous MCP/History history.get_session.contiguous_budget_window budgeting,range_integrity regression root_swiftpm routine 1 HistoryTestFixture Budget exhaustion around a target turn returns a contiguous rendered range without holes in returned_turn_start/end. A model could trust a returned range that silently omitted interior turns. temp_directory;json_fixture test_case retain 0 PR #303 F8 regression root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_resolvesFreshlySavedSessionViaRefreshOnCacheMiss root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_resolvesFreshlySavedSessionViaRefreshOnCacheMiss MCP/History history.get_session.cache_bypass_on_miss scan_cache,fresh_session regression root_swiftpm routine 1 HistoryTestFixture A session saved after cached inventory population resolves through one cache-bypassed retry. Freshly completed sessions could be invisible for the scan-cache TTL. temp_directory;json_fixture test_case retain 0 PR #303 F6 regression -root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_directResolutionAvoidsInventoryScans root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_directResolutionAvoidsInventoryScans MCP/History history.get_session.direct_resolution get_session,direct_lookup,scan_budget regression root_swiftpm routine 1 HistoryMCPMockScannerFixture A directly located session returns without invoking cached or refreshing inventory scans. Known-session follow-ups could pay two cross-workspace inventory scans and hit the MCP watchdog. direct_in_process;mock_scanner test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_incompleteDirectLookupDoesNotRunFullFallback root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_incompleteDirectLookupDoesNotRunFullFallback MCP/History history.get_session.incomplete_direct_no_fallback get_session,direct_lookup,shared_deadline,retryable regression root_swiftpm routine 1 HistoryMCPMockScannerFixture An incomplete direct lookup returns a retryable non-authoritative result without starting a full inventory fallback. A timed-out direct lookup could immediately repeat the expensive store walk and kill the MCP transport. direct_in_process;mock_scanner test_case retain 0 Track B shared-deadline UX regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_sharedDeadlineWithInsufficientFallbackTimeIsNotAuthoritativeNotFound root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_sharedDeadlineWithInsufficientFallbackTimeIsNotAuthoritativeNotFound MCP/History history.get_session.shared_deadline_fallback_guard get_session,shared_deadline,retryable,not_found regression root_swiftpm routine 1 HistoryInjectedContinuousClockFixture When the request-wide deadline leaves insufficient fallback time, get_session returns retryable incomplete diagnostics and never authoritative not-found. A nearly exhausted request could start another store scan or falsely tell the model that a valid session does not exist. direct_in_process;mock_scanner;injected_clock test_case retain 0 Track B shared-deadline UX regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testGetSession_singleSnapshotRefreshDecisionCannotRaceIntoAuthoritativeNotFound root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testGetSession_singleSnapshotRefreshDecisionCannotRaceIntoAuthoritativeNotFound MCP/History history.get_session.atomic_refresh_deadline_decision get_session,shared_deadline,race,retryable,not_found regression root_swiftpm routine 1 HistoryInjectedContinuousClockFixture A single remaining-time snapshot atomically chooses refresh at the deadline boundary, so a race cannot silently become authoritative not-found. Separate near-deadline checks could cross the deadline, skip refresh without diagnostics, and falsely report a missing session. direct_in_process;mock_scanner;injected_clock test_case retain 0 Track B post-review atomic deadline regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testListSessions_failedStubEnrichmentPreservesStoredMetadataWithLowerBoundDiagnostics root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testListSessions_failedStubEnrichmentPreservesStoredMetadataWithLowerBoundDiagnostics MCP/History history.list.truthful_stub_partial stub_enrichment,partial_result,sessions_scanned,diagnostics,stored_metadata regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Failed per-session enrichment preserves stored index metadata, reports zero completed scans, and aggregates typed diagnostics. Unreadable transcripts could make known sessions disappear or inflate sessions_scanned in partial output. direct_in_process;mock_scanner test_case retain 0 Track B truthful-partial UX regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testListSessions_oversizedTranscriptPreservesStoredSessionMetadata root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testListSessions_oversizedTranscriptPreservesStoredSessionMetadata MCP/History history.list.oversized_transcript_metadata_fallback transcript_bytes,stored_metadata,partial_result,diagnostics regression root_swiftpm routine 1 HistoryMCPMockScannerFixture An oversized transcript preserves the indexed session row with a typed non-retryable diagnostic and zero completed hydration scans. Per-file safety limits could silently hide valid stored sessions. direct_in_process;mock_scanner test_case retain 0 Track B per-file fallback UX regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testListSessions_repeatedReadFailuresAggregateDiagnosticsWithoutHidingSessions root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testListSessions_repeatedReadFailuresAggregateDiagnosticsWithoutHidingSessions MCP/History history.list.diagnostic_aggregation_bound diagnostics,aggregation,payload_bound,stored_metadata regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Two hundred fifty identical transcript failures collapse to one counted diagnostic while indexed session totals remain visible. Degraded stores could inflate JSON and Markdown without bound or erase known sessions. direct_in_process;mock_scanner test_case retain 0 Track B bounded-diagnostics UX regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testSearch_corruptTranscriptProducesTypedLowerBoundPartial root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testSearch_corruptTranscriptProducesTypedLowerBoundPartial MCP/History history.search.corrupt_transcript_lower_bound search,transcript_decode,typed_diagnostic,lower_bound regression root_swiftpm routine 1 HistoryMCPMockScannerFixture A corrupt transcript yields a typed non-retryable read diagnostic and explicit lower-bound search totals. Search could silently skip corrupt transcripts and present incomplete totals as authoritative. direct_in_process;mock_scanner test_case retain 0 Track B incomplete-coverage regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testTime_calendarCorruptTranscriptDisclosesIncompleteCoverage root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testTime_calendarCorruptTranscriptDisclosesIncompleteCoverage MCP/History history.time.calendar_corrupt_transcript_coverage calendar,transcript_decode,typed_diagnostic,lower_bound regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Calendar time may omit unusable intervals but marks coverage incomplete with a typed non-retryable diagnostic and lower-bound totals. Calendar aggregation could silently omit corrupt sessions and look complete. direct_in_process;mock_scanner test_case retain 0 Track B calendar coverage regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testListSessions_inventoryBudgetSurfacesTypedRetryableTruncation root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testListSessions_inventoryBudgetSurfacesTypedRetryableTruncation MCP/History history.list.inventory_budget_diagnostic work_budget,typed_diagnostic,retryable protocol_regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Inventory budget exhaustion sets scan_truncated and preserves the typed retryable diagnostic. Partial inventory could be presented as complete or lose actionable retry classification. direct_in_process;mock_scanner test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testSearch_turnBudgetReturnsTypedPartialResults root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testSearch_turnBudgetReturnsTypedPartialResults MCP/History history.search.turn_budget_partial work_budget,turns,partial_result regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Search stops at the explicit turn budget while retaining matches and a typed retryable truncation diagnostic. A large transcript could monopolize execution until the outer watchdog discarded all useful partial results. direct_in_process;mock_scanner test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistoryMCPToolServiceTests/testSearch_midTranscriptCancellationPropagates root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testSearch_midTranscriptCancellationPropagates MCP/History history.search.transcript_cancellation cancellation,transcript,cooperative concurrency_regression root_swiftpm routine 1 HistoryMCPMockScannerFixture Cancellation during transcript loading propagates as CancellationError rather than being swallowed as a skipped session. Canceled MCP work could continue consuming the actor and delay the watchdog or later requests. direct_in_process;mock_scanner test_case retain 0 PR B cooperative history work budget regression. root/RepoPromptTests.HistoryMCPToolServiceTests/testIdleThreshold_settingsDefaultClampedToValidRange root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testIdleThreshold_settingsDefaultClampedToValidRange MCP/History history.idle_threshold.settings_clamp settings,validation regression root_swiftpm routine 1 HistoryTestFixture Out-of-range stored default idle threshold is clamped to the accepted query range. Corrupt settings could produce invalid duration calculations or surprising validation behavior. temp_directory;json_fixture test_case retain 0 PR #303 F4 regression root/RepoPromptTests.HistoryMCPToolServiceTests/testTime_groupByDay_mergesOverlappingAndNestedTurnIntervals root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testTime_groupByDay_mergesOverlappingAndNestedTurnIntervals MCP/History history.time.calendar_merged_intervals duration,double_counting regression root_swiftpm routine 1 HistoryTestFixture Calendar grouped time merges overlapping/nested turn intervals before summing active duration. Calendar totals could double-count overlapping activity intervals. temp_directory;json_fixture test_case retain 0 PR #303 F1 regression root/RepoPromptTests.HistoryMCPToolServiceTests/testTime_groupBySession_emptyLiveTranscriptZerosDuration root Tests/RepoPromptTests/AgentMode/History/HistoryMCPToolServiceTests.swift RepoPromptTests.HistoryMCPToolServiceTests testTime_groupBySession_emptyLiveTranscriptZerosDuration MCP/History history.time.empty_live_transcript_zero duration,staleness regression root_swiftpm routine 1 HistoryTestFixture A successfully loaded empty live transcript contributes zero rather than stale stored duration fallback. Stale duration primitives could survive after an empty transcript rewrite. temp_directory;json_fixture test_case retain 0 PR #303 stale-duration regression @@ -3263,23 +3112,6 @@ root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_skipsHidde root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_discoversSingleWorkspace root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_discoversSingleWorkspace AgentMode/History history.scanner.scan_all_workspaces_discovers_single_workspace history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_discoversMultipleWorkspaces root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_discoversMultipleWorkspaces AgentMode/History history.scanner.scan_all_workspaces_discovers_multiple_workspaces history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_cacheInvalidatesChangedIndexAfterTTL root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_cacheInvalidatesChangedIndexAfterTTL AgentMode/History history.scanner.scan_all_workspaces_cache_invalidates_changed_index_after_ttl history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_coldFifteenThousandDirectoryShapeStopsAtWorkspaceBudget root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_coldFifteenThousandDirectoryShapeStopsAtWorkspaceBudget MCP/History history.scanner.cold_directory_budget workspace_enumeration,work_budget,large_shape performance_regression root_swiftpm routine 1 HistorySyntheticWorkspaceDirectoryFixture A synthetic 15000-directory cold inventory stops after the configured workspace count and reports typed retryable truncation. Large Application Support inventories could block the scanner actor until the MCP watchdog fires. synthetic_directory_inventory test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_warmInventoryCacheAvoidsRepeatedIndexDecode root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_warmInventoryCacheAvoidsRepeatedIndexDecode MCP/History history.scanner.warm_inventory_cache index_cache,warm_path,decode_count regression root_swiftpm routine 1 HistoryTempWorkspaceFixture A completed warm inventory returns unchanged data without another index decode. Budget accounting could accidentally penalize cache hits and truncate iterative history queries. temp_directory;json_fixture_files test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_midScanCancellationPropagates root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_midScanCancellationPropagates MCP/History history.scanner.mid_scan_cancellation workspace_enumeration,cancellation,yield concurrency_regression root_swiftpm routine 1 HistorySyntheticWorkspaceDirectoryFixture Cancellation after observed workspace progress exits the cooperative directory loop with CancellationError. Canceled inventory work could remain uncancellable and hold the scanner actor through thousands of stats. synthetic_directory_inventory test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_indexBudgetIsTypedRetryableAndPartialScanIsNotTTLCached root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_indexBudgetIsTypedRetryableAndPartialScanIsNotTTLCached MCP/History history.scanner.index_budget_retry index_budget,typed_diagnostic,ttl_cache regression root_swiftpm routine 1 HistoryTempWorkspaceFixture An index-count partial scan is retryable, is not TTL-cached, and reuses completed signature-cache work on retry. A partial inventory could poison the 90-second cache or force repeated index decoding. temp_directory;json_fixture_files test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_exactWorkspaceUUIDPreNarrowsColdIndexWork root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_exactWorkspaceUUIDPreNarrowsColdIndexWork MCP/History history.scanner.workspace_uuid_prenarrow workspace_scope,index_decode,pre_narrow regression root_swiftpm routine 1 HistoryTempWorkspaceFixture An exact workspace UUID scopes cold index decoding to the matching storage directory. Scoped history calls could still open every workspace index and exhaust their budget unnecessarily. temp_directory;json_fixture_files test_case retain 0 PR B cooperative history work budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testLocateSession_findsTargetAtOrdinal14999WithoutBroadWorkspaceCap root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testLocateSession_findsTargetAtOrdinal14999WithoutBroadWorkspaceCap MCP/History history.scanner.direct_lookup_ordinal_14999 direct_lookup,large_shape,workspace_cap regression root_swiftpm routine 1 HistorySyntheticWorkspaceDirectoryFixture Direct stat-only lookup finds a session in workspace ordinal 14999 without applying the broad 5000-workspace inventory cap. Valid sessions in large stores could be hidden and misreported as not found. synthetic_directory_inventory;injected_provider test_case retain 0 Track B 15000-workspace lookup regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_exactUUIDZeroFallsBackToCanonicalWorkspaceIdentity root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_exactUUIDZeroFallsBackToCanonicalWorkspaceIdentity MCP/History history.scanner.exact_uuid_false_zero_fallback workspace_scope,pre_narrow,fallback,shared_deadline regression root_swiftpm routine 1 HistoryTempWorkspaceFixture A zero-result exact UUID storage-name prefilter falls back under the same deadline and resolves canonical workspace identity. An optimization-only directory-name assumption could falsely return an empty workspace result. temp_directory;json_fixture_files test_case retain 0 Track B exact-workspace correctness regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_oversizedIndexReturnsTypedNonRetryablePartial root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_oversizedIndexReturnsTypedNonRetryablePartial MCP/History history.scanner.index_file_byte_bound index_bytes,per_file_limit,typed_diagnostic,partial_result regression root_swiftpm routine 1 HistoryTempWorkspaceFixture An oversized metadata index is rejected before decode with a typed non-retryable partial diagnostic. A single oversized index could monopolize memory/CPU or surface misleading retry advice. temp_directory;json_fixture_files test_case retain 0 Track B bounded-read UX regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_oversizedIndexDoesNotHideLaterValidWorkspace root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_oversizedIndexDoesNotHideLaterValidWorkspace MCP/History history.scanner.per_file_index_failure_continues index_bytes,per_file_limit,diagnostics,continued_discovery regression root_swiftpm routine 1 HistoryTempWorkspaceFixture An oversized index is diagnosed and skipped while a later valid workspace remains discoverable in the same request. A single bad index could globally stop discovery and hide all later sessions. temp_directory;json_fixture_files test_case retain 0 Track B post-review per-file isolation regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_nonDirectoryEntriesDoNotConsumeWorkspaceBudget root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_nonDirectoryEntriesDoNotConsumeWorkspaceBudget MCP/History history.scanner.non_directory_budget_exclusion workspace_budget,non_directory,discovery regression root_swiftpm routine 1 HistoryTempWorkspaceFixture Non-directory entries are skipped before workspace-budget accounting, leaving capacity for a valid workspace. Stray files could consume the workspace cap and hide valid saved workspaces. temp_directory;injected_provider test_case retain 0 Track B truthful workspace-budget regression. -root/RepoPromptTests.HistorySessionScannerTests/testScanWorkspaces_oversizedWorkspaceJSONFallsBackWithTypedDiagnostic root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanWorkspaces_oversizedWorkspaceJSONFallsBackWithTypedDiagnostic MCP/History history.scanner.workspace_metadata_byte_bound workspace_json,per_file_limit,fallback,typed_diagnostic regression root_swiftpm routine 1 HistoryTempWorkspaceFixture Oversized workspace.json falls back to directory identity with a typed diagnostic without reading or decoding the file. Unbounded workspace metadata reads could consume the request deadline or memory. temp_directory;json_fixture_files test_case retain 0 Track B workspace metadata bound regression. -root/RepoPromptTests.HistorySessionScannerTests/testLoadSession_insufficientProportionalDecodeTimeFailsBeforeDecode root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testLoadSession_insufficientProportionalDecodeTimeFailsBeforeDecode MCP/History history.scanner.proportional_decode_time_guard transcript_decode,remaining_time,injected_clock regression root_swiftpm routine 1 HistoryInjectedContinuousClockFixture A transcript decode is rejected before JSON decoding when remaining time is below the file-size-proportional guard. Large decode work could start near deadline and overrun the transport watchdog. temp_directory;json_fixture_files;injected_clock test_case retain 0 Track B deadline-gap regression. -root/RepoPromptTests.HistorySessionScannerTests/testIndexScanCache_repeatedExactScopesStayEntryAndByteBounded root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testIndexScanCache_repeatedExactScopesStayEntryAndByteBounded MCP/History history.scanner.index_cache_exact_scope_bound index_cache,exact_scope,entry_bound,byte_bound,lru performance_regression root_swiftpm routine 1 HistoryTempWorkspaceFixture Repeated exact-workspace scans obey deterministic index-cache entry and byte ceilings and evict the oldest entry. Scoped query loops could grow decoded index memory without bound. temp_directory;json_fixture_files test_case retain 0 Track B persistent cache-bound regression. -root/RepoPromptTests.HistorySessionScannerTests/testIndexScanCache_repeatedPartialScansStayBounded root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testIndexScanCache_repeatedPartialScansStayBounded MCP/History history.scanner.index_cache_partial_bound index_cache,partial_scan,entry_bound,byte_bound performance_regression root_swiftpm routine 1 HistorySyntheticWorkspaceDirectoryFixture Repeated truncated inventory scans retain useful decoded indexes without exceeding deterministic cache entry or byte bounds. Partial retries could accumulate decoded indexes indefinitely. temp_directory;json_fixture_files;injected_provider test_case retain 0 Track B persistent partial-cache regression. -root/RepoPromptTests.HistorySessionScannerTests/testInventoryScanGate_cancelledWaitersLeaveNoTombstonesAndReleaseFIFO root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testInventoryScanGate_cancelledWaitersLeaveNoTombstonesAndReleaseFIFO MCP/History history.scanner.scan_gate_cancelled_waiter_cleanup scan_gate,cancellation,fairness,tombstone_bound concurrency_regression root_swiftpm routine 1 HistoryInventoryScanGateFixture Queued cancellation drains every waiter, releases the holder, and leaves no cancellation tombstones or leaked queue state. Repeated canceled scans could grow gate state or block later history requests. direct_in_process;async_waiters test_case retain 0 Track B scan-gate lifecycle regression. -root/RepoPromptTests.HistorySessionScannerTests/testLoadSession_oversizedTranscriptFailsBeforeDecode root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testLoadSession_oversizedTranscriptFailsBeforeDecode MCP/History history.scanner.transcript_file_byte_bound transcript_bytes,per_file_limit,decode_guard regression root_swiftpm routine 1 HistoryTempWorkspaceFixture An oversized transcript fails with a typed non-retryable byte diagnostic before JSON decode. A pathological session file could exhaust the request budget and endanger transport survival. temp_directory;json_fixture_files test_case retain 0 Track B bounded-read UX regression. -root/RepoPromptTests.HistorySessionScannerTests/testTranscriptCache_usesDeterministicByteBoundedLRUEviction root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testTranscriptCache_usesDeterministicByteBoundedLRUEviction MCP/History history.scanner.transcript_cache_byte_lru transcript_cache,byte_budget,lru,determinism performance_regression root_swiftpm routine 1 HistoryTempWorkspaceFixture Transcript caching evicts the least-recently-used entry deterministically when the configured byte ceiling is crossed. Count-only arbitrary eviction could retain huge transcripts, waste memory, and make repeated query latency unpredictable. temp_directory;json_fixture_files test_case retain 0 Track B cache-survival regression. root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_workspaceWithoutAgentSessionsDir root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_workspaceWithoutAgentSessionsDir AgentMode/History history.scanner.scan_all_workspaces_workspace_without_agent_sessions_dir history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_workspaceWithoutIndexFile root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_workspaceWithoutIndexFile AgentMode/History history.scanner.scan_all_workspaces_workspace_without_index_file history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. root/RepoPromptTests.HistorySessionScannerTests/testScanAllWorkspaces_corruptIndexFile_reportsReadFailed root Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift RepoPromptTests.HistorySessionScannerTests testScanAllWorkspaces_corruptIndexFile_reportsReadFailed AgentMode/History history.scanner.scan_all_workspaces_corrupt_index_file_reports_read_failed history_scanner,workspace_discovery,index_cache,filesystem filesystem_scanner_contract root_swiftpm routine 1 HistoryTempWorkspaceFixture Scanner discovers workspace session indexes, resolves workspace identity, filters metadata, loads transcripts, handles stale/corrupt indexes, and refreshes changed cached indexes. History queries could miss workspaces, re-read stale indexes, misattribute sessions, or fail on corrupt/local session data. temp_directory;json_fixture_files temporary_application_support_root test_case retain 0 PR #303 history scanner contract row; reviewed in final minimization pass. @@ -3346,8 +3178,6 @@ root/RepoPromptTests.AgentSessionMetadataRecordExtensionTests/testRecordFromStub root/RepoPromptTests.AgentSessionMetadataRecordExtensionTests/testRecordFromFullSessionProducesNonZeroV5Fields root Tests/RepoPromptTests/AgentMode/AgentSessionMetadataRecordExtensionTests.swift RepoPromptTests.AgentSessionMetadataRecordExtensionTests testRecordFromFullSessionProducesNonZeroV5Fields AgentMode/History history.metadata_record.record_from_full_session_produces_non_zero_v5_fields metadata_index,duration_primitives,v5_schema,decode_compatibility metadata_codec_contract root_swiftpm routine 1 AgentSessionMetadataRecordFixture Metadata records decode/encode schema-v5 history fields and compute key paths, tool counts, activity bounds, active-duration primitives, and enrichment state deterministically. History time/list/search could compute wrong durations, lose file activity, or break compatibility with existing metadata indexes. direct_in_process test_case retain 0 PR #303 metadata-index history row; reviewed in final minimization pass. root/RepoPromptTests.AgentSessionMetadataRecordExtensionTests/testLacksTranscriptDerivedFieldsAndOnDemandEnrichmentEquivalence root Tests/RepoPromptTests/AgentMode/AgentSessionMetadataRecordExtensionTests.swift RepoPromptTests.AgentSessionMetadataRecordExtensionTests testLacksTranscriptDerivedFieldsAndOnDemandEnrichmentEquivalence AgentMode/History history.metadata_record.lacks_transcript_derived_fields_and_on_demand_enrichment_equivalence metadata_index,duration_primitives,v5_schema,decode_compatibility metadata_codec_contract root_swiftpm routine 1 AgentSessionMetadataRecordFixture Metadata records decode/encode schema-v5 history fields and compute key paths, tool counts, activity bounds, active-duration primitives, and enrichment state deterministically. History time/list/search could compute wrong durations, lose file activity, or break compatibility with existing metadata indexes. direct_in_process test_case retain 0 PR #303 metadata-index history row; reviewed in final minimization pass. root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterTreatsNoMatchesAsSuccessfulEmptyResult root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterTreatsNoMatchesAsSuccessfulEmptyResult MCP/Formatter history.formatter.history_formatter_treats_no_matches_as_successful_empty_result history_mcp,formatter,token_budget,model_guidance formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture History MCP formatter emits compact, model-actionable summaries for empty results, truncation, skipped workspaces, search follow-up IDs, stale indexes, and get_session windows. Models could waste tokens, miss retry/follow-up guidance, or misinterpret history MCP results. direct_in_process;formatter_dto test_case retain 0 PR #303 history formatter row; reviewed in final minimization pass. -root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterPreservesRetryableErrorDiagnosticsAndAdvice root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterPreservesRetryableErrorDiagnosticsAndAdvice MCP/Formatter history.formatter.retryable_error_diagnostics history_mcp,formatter,retryable,diagnostics,model_guidance formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture A retryable history error renders warning grade, phase-specific budget diagnostics, and authoritative next-step advice. Formatter error paths could discard retryability and diagnostics, causing needless restarts or incorrect not-found conclusions. direct_in_process;formatter_dto test_case retain 0 Track B partial-result UX regression. -root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterCompactsRepeatedAndCappedScanDiagnostics root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterCompactsRepeatedAndCappedScanDiagnostics MCP/Formatter history.formatter.compact_scan_diagnostics history_mcp,formatter,diagnostics,aggregation,payload_bound formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture Repeated diagnostics render once with a count, capped groups render a compact omission marker, and warning-grade retry advice remains visible. Formatter expansion could re-inflate bounded DTO diagnostics or discard actionable partial-result guidance. direct_in_process;formatter_dto test_case retain 0 Track B bounded-diagnostics formatter regression. root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterShowsFilesTouchedTruncation root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterShowsFilesTouchedTruncation MCP/Formatter history.formatter.history_formatter_shows_files_touched_truncation history_mcp,formatter,token_budget,model_guidance formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture History MCP formatter emits compact, model-actionable summaries for empty results, truncation, skipped workspaces, search follow-up IDs, stale indexes, and get_session windows. Models could waste tokens, miss retry/follow-up guidance, or misinterpret history MCP results. direct_in_process;formatter_dto test_case retain 0 PR #303 history formatter row; reviewed in final minimization pass. root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterSummarizesSkippedWorkspaces root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterSummarizesSkippedWorkspaces MCP/Formatter history.formatter.history_formatter_summarizes_skipped_workspaces history_mcp,formatter,token_budget,model_guidance formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture History MCP formatter emits compact, model-actionable summaries for empty results, truncation, skipped workspaces, search follow-up IDs, stale indexes, and get_session windows. Models could waste tokens, miss retry/follow-up guidance, or misinterpret history MCP results. direct_in_process;formatter_dto test_case retain 0 PR #303 history formatter row; reviewed in final minimization pass. root/RepoPromptTests.ToolOutputFormatterWorktreeTests/testHistoryFormatterShowsSearchFollowUpIdentifiersAndRequest root Tests/RepoPromptTests/MCP/ToolOutputFormatterWorktreeTests.swift RepoPromptTests.ToolOutputFormatterWorktreeTests testHistoryFormatterShowsSearchFollowUpIdentifiersAndRequest MCP/Formatter history.formatter.history_formatter_shows_search_follow_up_identifiers_and_request history_mcp,formatter,token_budget,model_guidance formatter_output_contract root_swiftpm routine 1 ToolOutputFormatterHistoryDTOFixture History MCP formatter emits compact, model-actionable summaries for empty results, truncation, skipped workspaces, search follow-up IDs, stale indexes, and get_session windows. Models could waste tokens, miss retry/follow-up guidance, or misinterpret history MCP results. direct_in_process;formatter_dto test_case retain 0 PR #303 history formatter row; reviewed in final minimization pass. @@ -3373,8 +3203,9 @@ root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testPromptAgentModelsNotif root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelDoesNotFallbackUnsyncedBuiltinChatToOracle root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentModelsViewModelDoesNotFallbackUnsyncedBuiltinChatToOracle Settings agent_models.ui.unsynced_compose_empty_state builtin_chat,sync_toggle,display_state deterministic_regression root_swiftpm routine 2 Unsynchronized empty Built-in Chat selection shows its placeholder, while synchronized selection displays the Oracle model. The settings UI could falsely display the Oracle model as the Built-in Chat choice while synchronization is disabled. isolated_userdefaults;notification_center AgentModelsSettingsViewModel;GlobalSettingsStore test_case retain 0 PR #275 correction regression. root/RepoPromptTests.AutoRecommendationEngineScopedSettingsTests/testContextBuilderRecommendationWriteIntentDistinguishesAutomaticSeedFromExplicitApply root Tests/RepoPromptTests/AgentMode/AutoRecommendationEngineScopedSettingsTests.swift RepoPromptTests.AutoRecommendationEngineScopedSettingsTests testContextBuilderRecommendationWriteIntentDistinguishesAutomaticSeedFromExplicitApply AgentMode agent_models.recommendations.context_builder_write_ownership context_builder,automatic_seed,user_ownership deterministic_regression root_swiftpm routine 3 Automatic recommendation seeding remains unmarked, explicit application marks user ownership, and later automatic work cannot demote it. Automatic seeding could block future initialization or overwrite a user-owned Context Builder selection because ownership intent was lost. temp_directory;isolated_userdefaults GlobalSettingsStore;AutoRecommendationEngine test_case+addTeardownBlock retain 0 PR #275 correction regression. root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelReportsStoredRecommendedRolePinAsOverrideAndClearsIt root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentModelsViewModelReportsStoredRecommendedRolePinAsOverrideAndClearsIt Settings settings.agent_models.role_default_pinned_recommended_affordance scoped_agent_models,mcp_role_defaults,pinned_recommended,reset_affordance deterministic_view_model root_swiftpm routine 1 temporary_settings_store,isolated_user_defaults A same-as-recommended MCP role override remains exposed as a stored override in Agent Models settings so Clear Pin and section reset controls are available. Same-as-recommended pins could be persisted but hidden from Settings reset affordances, leaving no obvious way to return to recommendation tracking. temporary_store,user_defaults method_local_values+fake_store retain 0 PR #275 reviewer regression for stored role pins matching current recommendation. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelClearingSynchronizedModelDisablesSyncWithoutClearingSibling root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentModelsViewModelClearingSynchronizedModelDisablesSyncWithoutClearingSibling Settings agent_models.ui.clearing_synced_model_disables_sync builtin_chat,oracle_model,sync_toggle,workspace_overrides,global_profile deterministic_regression root_swiftpm routine 4 Clearing either synchronized model disables sync and preserves the sibling model for both global and workspace profiles. Clearing one side of a synchronized pair could erase the sibling selection or leave an invalid sync-enabled tuple. isolated_userdefaults;notification_center AgentModelsSettingsViewModel;WindowSettingsManager;GlobalSettingsStore test_case retain 0 Renamed root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelBlankBuiltinChatDoesNotMirrorToOracleWhenSynced -> root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelClearingSynchronizedModelDisablesSyncWithoutClearingSibling; expands coverage to both model directions. -root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testRetainedPayloadRefreshChangesOnlyMatchingResultRenderIdentity root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testRetainedPayloadRefreshChangesOnlyMatchingResultRenderIdentity AgentMode agent.transcript.retained_payload_render_identity retained_payload,result_identity,refresh_scope deterministic_regression root_swiftpm routine 1 AgentModeViewModelFixture Refreshing retained payload changes render identity only for the matching result and leaves unrelated rows stable. Broad refresh invalidation could rerender unrelated transcript results or leave the changed payload stale. 0.006000 window_registry test_case retain 0 Authoritative-list reconciliation after origin/main rebase. +root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelBlankBuiltinChatDoesNotMirrorToOracleWhenSynced root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentModelsViewModelBlankBuiltinChatDoesNotMirrorToOracleWhenSynced Settings agent_models.ui.blank_compose_sync_guard builtin_chat,sync_toggle,oracle_model,workspace_overrides,global_profile deterministic_regression root_swiftpm routine 2 Blank Built-in Chat selections do not mirror into the Oracle model for global or workspace Agent Models profiles while sync is enabled. The settings UI could reintroduce the upstream blank-chat Oracle reset through direct scoped profile writes. isolated_userdefaults;notification_center AgentModelsSettingsViewModel;WindowSettingsManager;GlobalSettingsStore test_case retain 0 Oracle rebase review regression for upstream #305 scoped Agent Models path. +root/RepoPromptTests.AgentModeViewModelInactiveRefreshTests/testRetainedPayloadRefreshChangesOnlyMatchingResultRenderIdentity root Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift RepoPromptTests.AgentModeViewModelInactiveRefreshTests testRetainedPayloadRefreshChangesOnlyMatchingResultRenderIdentity AgentMode agent.transcript.retained_payload_targeted_render_identity matching_result_revision,unrelated_result_stability,raw_payload incremental_projection_contract root_swiftpm routine 2 AgentModeViewModel Refreshing one retained raw tool-result payload advances only that result's render identity while preserving the unrelated result's revision and payload. An incremental tool-result refresh could invalidate every rendered row or attach one invocation's raw payload to another result. 0.000000 main_actor,in_memory test_case retain 0 test-quality audit ledger reconciliation; two result-identity scenarios +root/RepoPromptTests.CodemapAutomaticSelectionBasicTests/testPublisherIngressAppliesCatalogWhileCorrelatedCodemapInvalidationIsStalled root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionBasicTests.swift RepoPromptTests.CodemapAutomaticSelectionBasicTests testPublisherIngressAppliesCatalogWhileCorrelatedCodemapInvalidationIsStalled WorkspaceContext/CodeMap codemap.publisher.applied_ingress_independent_invalidation applied_ingress,catalog_publication,stalled_invalidation,explicit_create async_concurrency_lifecycle root_swiftpm routine 2 CodemapStoreFixture,CodemapSuspensionGate Catalog ingress becomes applied and explicit create reaches disk while correlated derived codemap invalidation remains gate-blocked. Publisher-derived convergence could block canonical catalog visibility or explicit mutation I/O. 0.585000 filesystem,actor,concurrency store_session+publication_gate+root_unload retain 0 Issue #390 applied-ingress independence regression. root/RepoPromptTests.MCPFileActionPartialSuccessTests/testApplyEditsFreshnessPendingAcknowledgementWarnsAgainstReplay root Tests/RepoPromptTests/MCP/MCPFileActionPartialSuccessTests.swift RepoPromptTests.MCPFileActionPartialSuccessTests testApplyEditsFreshnessPendingAcknowledgementWarnsAgainstReplay MCP mcp.apply_edits.partial_success_no_replay mutation_applied,freshness_pending,operation_id,replay_warning deterministic_dto_contract root_swiftpm routine 1 source_text Applied edit acknowledgement with pending freshness explicitly warns against replay and labels the operation ID as correlation-only. Agents could replay an already-applied edit and duplicate or corrupt content after derived freshness lag. 0.001000 source_text source_read_only retain 0 Issue #390 partial-success acknowledgement regression. root/RepoPromptTests.MCPFileActionPartialSuccessTests/testFreshnessPendingAcknowledgementIsAppliedAndNotBlindlyRetryable root Tests/RepoPromptTests/MCP/MCPFileActionPartialSuccessTests.swift RepoPromptTests.MCPFileActionPartialSuccessTests testFreshnessPendingAcknowledgementIsAppliedAndNotBlindlyRetryable MCP mcp.file_actions.partial_success_no_blind_retry mutation_applied,freshness_pending,retryability,correlation_id deterministic_dto_contract root_swiftpm routine 1 ToolResultDTOs.FileActionReply A freshness-pending file action remains mutation_state applied and is not represented as a blindly retryable pre-mutation failure. Agents could repeat successful create, move, or delete operations after delayed derived convergence. 0.000000 formatter_dto method_local_values retain 0 Issue #390 file action partial-success contract. root/RepoPromptTests.MCPMutationRetryableFailureTests/testCreateSelectionUsesCanonicalPersistencePath root Tests/RepoPromptTests/MCP/MCPMutationRetryableFailureTests.swift RepoPromptTests.MCPMutationRetryableFailureTests testCreateSelectionUsesCanonicalPersistencePath MCP mcp.file_actions.create_selection_canonical_path create,selection_persistence,canonical_authority,acknowledgement structural_source_guard root_swiftpm routine 1 source_text Create selection intent persists through the canonical coordinator before a successful acknowledgement is formatted. Create could report success while selection remains private or is lost before Oracle packaging. 0.009000 source_text source_read_only retain 0 Issues #390 and #515 canonical create-selection regression. @@ -3411,253 +3242,3 @@ root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testBoundInactiveWor root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testExplicitInactiveWorkspaceContextBuilderUsesTargetAuthorityWithoutVisibleProjection root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testExplicitInactiveWorkspaceContextBuilderUsesTargetAuthorityWithoutVisibleProjection ContextBuilder context_builder.inactive_workspace.explicit_authority explicit_context,inactive_workspace,scoped_profile,provider_path,nested_tools,no_ui_projection production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture,ContextBuilderWorktreeProbeProvider An explicit inactive workspace B target owns provider, model, planning fallback, budget, root, tab storage, and nested tools without activating or mutating visible workspace A. An explicit inactive run could capture A authority before resolving B or contaminate visible bindings. filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Inactive-workspace Context Builder authority release regression root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testInactiveWorkspaceContextBuilderFailsClosedWhenTargetProjectionIsUnavailable root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testInactiveWorkspaceContextBuilderFailsClosedWhenTargetProjectionIsUnavailable ContextBuilder context_builder.inactive_workspace.projection_fail_closed inactive_workspace,missing_projection,fail_closed,no_provider,no_binding_side_effect production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture An inactive target whose file projection is unavailable fails before binding or provider creation and leaves visible workspace A active. Unavailable B projection could silently route nested tools or provider execution through visible A. filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Inactive-workspace Context Builder fail-closed release regression root/RepoPromptTests.ContextBuilderWorktreeInheritanceTests/testInactiveWorkspaceContextBuilderSurvivesVisibleTabSwitchAndCancelsWithoutLateProjection root Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift RepoPromptTests.ContextBuilderWorktreeInheritanceTests testInactiveWorkspaceContextBuilderSurvivesVisibleTabSwitchAndCancelsWithoutLateProjection ContextBuilder context_builder.inactive_workspace.cancellation_lifecycle inactive_workspace,visible_tab_switch,visible_workspace_switch,target_removal,cancellation,late_callback,exactly_once,no_ui_projection production_shaped_mcp_transport_integration root_swiftpm routine 1 PersistentMCPTestFixture,ContextBuilderWorktreeProbeProvider A gated inactive B run survives unrelated visible tab and workspace switches, then exact B removal clears ownership and rejects late completion without projecting into the visible workspace. Workspace switches, exact target removal, or late provider callbacks could cancel the wrong run, commit after cancellation, or overwrite visible bindings. filesystem;mcp_socket;workspace_store mcp_shared_server;window_registry MCPSharedServerTestLease;PersistentMCPTestFixture retain 0 Inactive-workspace Context Builder lifecycle release regression -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testButtonPointerStandardAndAccessibilityActivationUseTargetAction root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testButtonPointerStandardAndAccessibilityActivationUseTargetAction App/Titlebar agent_chat_titlebar.button_activation pointer,target_action,perform_click,accessibility,focus_ring_configuration deterministic_regression root_swiftpm routine 4 AppKitButtonFixture Press-to-open mouseDown, programmatic performClick, and inherited accessibility press all deliver the button through standard target/action while the exterior focus mask is configured for its rounded bounds. A custom-only pointer path could bypass standard target/action or assistive activation, or leave an unbordered titlebar control without configured focus-ring geometry. appkit NSApplication test_case retain 0 Chat titlebar safety regression coverage; keyboard traversal and rendered focus remain integration-level behavior. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testMenuItemsCaptureImmutableRepresentedTarget root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testMenuItemsCaptureImmutableRepresentedTarget App/Titlebar agent_chat_titlebar.menu_target_capture immutable_target,self_target,strong_closure_retention,workspace,tab,session,name deterministic_regression root_swiftpm routine 4 AgentChatOptionsMenuFixture Each self-targeted menu item invokes its retained closure with the exact workspace, tab, session, and name captured when the menu was built. A delayed menu command could resolve a newly current chat or lose its action because AppKit does not retain a weak external target. appkit NSApplication test_case retain 0 Chat titlebar safety regression coverage. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testSnapshotAndTargetValidationFailClosedAcrossLifecycleChanges root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testSnapshotAndTargetValidationFailClosedAcrossLifecycleChanges App/Titlebar agent_chat_titlebar.target_revalidation workspace,tab,session,name,tab_switch,fail_closed deterministic_regression root_swiftpm routine 8 AgentChatTitlebarSafetyFixture The immutable menu target remains bound across a current-tab switch but rejects workspace, tab, name, or session drift before mutating the captured tab. Titlebar actions could mutate a later-current chat or accept a stale identity after rename, deletion, workspace switch, or session rebind. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Chat titlebar safety regression coverage. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testGuardedCloseAndStashRejectStaleMutationContext root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testGuardedCloseAndStashRejectStaleMutationContext Prompt/Tabs compose_tabs.guarded_titlebar_mutation close,stash,async_revalidation,fail_closed deterministic_regression root_swiftpm routine 2 AgentChatTitlebarSafetyFixture The existing compose-tab mutation guard leaves both open and stashed collections unchanged when the caller context is stale for close and stash. An async titlebar delete or stash could continue after its exact workspace, tab, session, or name target becomes stale. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Thin caller forwarding coverage for the existing PromptViewModel mutation guard. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testGuardedCloseCommitsTabRemovalAfterListenerCleanupInvalidatesTarget root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testGuardedCloseCommitsTabRemovalAfterListenerCleanupInvalidatesTarget Prompt/Tabs compose_tabs.guarded_close_commit_boundary close,async_cleanup,session_invalidation,commit_boundary,state_consistency deterministic_regression root_swiftpm routine 1 AgentChatTitlebarSafetyFixture Once close-listener cleanup invalidates the captured agent-session target, the compose tab still completes removal while the sibling tab remains open. Post-cleanup identity revalidation could leave an open compose tab whose agent session and runtime state were already deleted. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Titlebar close commit-boundary regression coverage. -root/RepoPromptTests.MCPAgentRoleDefaultsServiceTests/testCanonicalPinPresentationExposesStoredRecommendedPinAndRawReset root Tests/RepoPromptTests/AgentMode/MCPAgentRoleDefaultsServiceTests.swift RepoPromptTests.MCPAgentRoleDefaultsServiceTests testCanonicalPinPresentationExposesStoredRecommendedPinAndRawReset AgentMode agent_models.role_defaults.canonical_pin_presentation mcp_role_defaults,pinned_recommended,clear_affordance,recommendation_tracking deterministic_regression root_swiftpm routine 2 A stored same-as-recommended pin reports Pinned to recommended with Clear Pin, and clearing removes storage while the effective selection remains recommended. Same-as-recommended pins could remain durable but invisible or fail to return to recommendation tracking when cleared. test_case retain 0 Issue #508 compact and full Agent Models pin-state contract. -root/RepoPromptTests.MCPAgentRoleDefaultsServiceTests/testStoredOverridePredicateDoesNotDependOnResolvedRows root Tests/RepoPromptTests/AgentMode/MCPAgentRoleDefaultsServiceTests.swift RepoPromptTests.MCPAgentRoleDefaultsServiceTests testStoredOverridePredicateDoesNotDependOnResolvedRows AgentMode agent_models.role_defaults.raw_stored_override_predicate mcp_role_defaults,unavailable_catalog,section_reset deterministic_regression root_swiftpm routine 2 Stored overrides remain detectable when no role rows resolve, then become absent after an explicit reset. A catalog outage could hide the section-level reset control for durable role pins. test_case retain 0 Issue #508 reset affordance must not depend on resolved catalog rows. -root/RepoPromptTests.MCPAgentRoleDefaultsServiceTests/testWorkspaceClearUsesSameScopeAsWorkspaceResolution root Tests/RepoPromptTests/AgentMode/MCPAgentRoleDefaultsServiceTests.swift RepoPromptTests.MCPAgentRoleDefaultsServiceTests testWorkspaceClearUsesSameScopeAsWorkspaceResolution AgentMode agent_models.role_defaults.workspace_clear_scope_integrity workspace_overrides,global_isolation,explicit_scope deterministic_regression root_swiftpm routine 2 An explicit workspace clear removes only the workspace pin and preserves the different global pin. A clear action derived from a workspace resolution could cross the global/workspace boundary. test_case retain 0 Issue #508 coverage reconciled with PR #534 explicit mutation scope. -root/RepoPromptTests.RecommendationWizardScopedTargetTests/testEditingScopeResolverMapsInheritanceToGlobalOrWorkspace root Tests/RepoPromptTests/AgentMode/RecommendationWizardScopedTargetTests.swift RepoPromptTests.RecommendationWizardScopedTargetTests testEditingScopeResolverMapsInheritanceToGlobalOrWorkspace AgentMode agent_models.scope.resolve_inheritance workspace_overrides,global_scope,no_workspace deterministic_regression root_swiftpm routine 3 Scope resolution maps no workspace and inherited settings to global, and maps workspace overrides to that workspace. Duplicated scope inference could disagree across the wizard, settings UI, and role-default storage. test_case retain 0 Issue #508 scope-authority regression. -root/RepoPromptTests.RecommendationWizardScopedTargetTests/testQuickApplyGlobalTargetPreservesWorkspaceProfileAndUsesWorkspaceBookkeeping root Tests/RepoPromptTests/AgentMode/RecommendationWizardScopedTargetTests.swift RepoPromptTests.RecommendationWizardScopedTargetTests testQuickApplyGlobalTargetPreservesWorkspaceProfileAndUsesWorkspaceBookkeeping AgentMode agent_models.wizard.global_target_workspace_bookkeeping recommendation_wizard,global_profile,workspace_profile,notifications,completion deterministic_view_model root_swiftpm routine 3 temporary_settings_store,isolated_user_defaults Quick Apply mutates the inherited global profile, preserves the dormant workspace profile, records completion/source identity for the initiating workspace, and emits one coalesced global affected-scope notification. The wizard could write a shadowed workspace profile, lose workspace-local attribution, or emit duplicate global refresh notifications. filesystem,user_defaults notification_center test_case+addTeardownBlock retain 0 Issue #508 scoped wizard global-target contract; Oracle affected-scope coalescing follow-up. -root/RepoPromptTests.RecommendationWizardScopedTargetTests/testInheritanceChangeRecomputesWorkspaceTargetBeforeQuickApply root Tests/RepoPromptTests/AgentMode/RecommendationWizardScopedTargetTests.swift RepoPromptTests.RecommendationWizardScopedTargetTests testInheritanceChangeRecomputesWorkspaceTargetBeforeQuickApply AgentMode agent_models.wizard.inheritance_change_retargets_before_apply recommendation_wizard,workspace_overrides,stale_action_rejection,mcp_presets,scoped_notifications deterministic_view_model root_swiftpm routine 4 temporary_settings_store,isolated_user_defaults Changing inheritance immediately retargets Agent Models writes to the workspace while mixed Quick Apply emits exact workspace and global preset affected scopes. A debounced inheritance change or single-scope apply notification could mutate the wrong profile or leave global preset consumers stale. filesystem,user_defaults notification_center test_case+addTeardownBlock retain 0 Issue #508 retargeting contract layered on PR #534 action revision guards; Oracle affected-scope follow-up. -root/RepoPromptTests.RecommendationWizardScopedTargetTests/testWorkspaceSwitchCannotApplyPreviousWorkspaceRecommendations root Tests/RepoPromptTests/AgentMode/RecommendationWizardScopedTargetTests.swift RepoPromptTests.RecommendationWizardScopedTargetTests testWorkspaceSwitchCannotApplyPreviousWorkspaceRecommendations AgentMode agent_models.wizard.workspace_switch_rejects_cached_target recommendation_wizard,workspace_switch,workspace_overrides,global_isolation deterministic_view_model root_swiftpm routine 3 temporary_settings_store,isolated_user_defaults Switching workspaces resets the wizard target and applies only the newly active workspace recommendations while preserving global and prior-workspace profiles. Cached recommendations could cross workspace boundaries during the debounce window after a tab switch. filesystem,user_defaults notification_center test_case+addTeardownBlock retain 0 Issue #508 workspace-switch regression. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testBlockedSchemaTelemetryMirrorPreservesExistingValueAndDefaultsAbsentMirrorOff root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testBlockedSchemaTelemetryMirrorPreservesExistingValueAndDefaultsAbsentMirrorOff Settings settings.telemetry.blocked_schema_mirror_preservation future_schema,incompatible_schema,telemetry,user_defaults_mirror,byte_preservation persistence_regression root_swiftpm routine 6 temporary_settings_file,isolated_user_defaults Future and incompatible schema blocks preserve both file bytes and an existing telemetry mirror, while an absent mirror fails safe to false. A deliberate schema block could be misclassified as corruption and overwrite a previously explicit telemetry mirror. filesystem,user_defaults method_local_values+defer retain 0 Issue #508 blocked-schema telemetry classification. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testMissingTelemetrySettingsRemovesStaleMirrorAndUsesBuildDefault root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testMissingTelemetrySettingsRemovesStaleMirrorAndUsesBuildDefault Settings settings.telemetry.missing_file_clears_stale_mirror missing_file,telemetry,user_defaults_mirror,build_default persistence_regression root_swiftpm routine 1 temporary_settings_file,isolated_user_defaults A missing settings file removes a stale telemetry mirror and the store uses the build default. Stale legacy consent could survive after the canonical JSON file is absent. filesystem,user_defaults method_local_values+defer retain 0 Issue #508 telemetry mirror absence contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testSuccessfulRecoveryResynchronizesTelemetryMirror root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testSuccessfulRecoveryResynchronizesTelemetryMirror Settings settings.telemetry.recovery_resynchronizes_mirror future_schema,recovery,telemetry,user_defaults_mirror persistence_regression root_swiftpm routine 1 temporary_settings_file,isolated_user_defaults User-initiated recovery clears the schema block and resynchronizes the telemetry mirror from the recovered current-schema document. Recovery could leave the telemetry mirror carrying stale state from the blocked document. filesystem,user_defaults method_local_values+defer retain 0 Issue #508 recovery telemetry regression. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentModelsViewModelRejectsSyncWhenOracleModelIsBlank root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentModelsViewModelRejectsSyncWhenOracleModelIsBlank Settings agent_models.ui.reject_sync_with_blank_oracle sync_toggle,blank_model,global_profile,workspace_overrides deterministic_regression root_swiftpm routine 2 The global and workspace Agent Models view models keep synchronization disabled when the Oracle model is blank. UI setters could create a sync-enabled profile whose planning model is absent. isolated_userdefaults,notification_center test_case retain 0 Issue #508 UI guard complements the durable boundary validation. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testInvalidSynchronizedAgentModelsStateRepairsGlobalAndDormantWorkspaceProfiles root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testInvalidSynchronizedAgentModelsStateRepairsGlobalAndDormantWorkspaceProfiles Settings agent_models.persistence.invalid_sync_load_repair sync_toggle,blank_model,divergent_model,global_profile,dormant_workspace,unrelated_save,reload,idempotence deterministic_persistence root_swiftpm routine 6 temporary_settings_file,isolated_user_defaults Compatible file-backed startup and reload restoration disable both-blank, one-blank, and divergent sync flags in global and dormant workspace profiles while preserving both model raws through an unrelated save, byte-stable relaunch, and compatible reload repair persistence. Invalid synchronized JSON could survive relaunch or an unrelated whole-document save, including in inactive or orphaned workspace entries. filesystem,user_defaults GlobalSettingsFileStore+defer retain 0 PR #545 P1 restoration invariant regression; six distinct tuple/scope scenarios. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testLegacyScalarModelSettersPreserveSiblingAndRejectInvalidSync root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testLegacyScalarModelSettersPreserveSiblingAndRejectInvalidSync Settings agent_models.persistence.legacy_scalar_sync_invariant legacy_api,model_clear,sibling_preservation,blank_oracle deterministic_regression root_swiftpm routine 3 Legacy scalar compose and planning clears preserve the sibling and disable sync, while enabling sync with a blank Oracle persists false. Non-MCP scalar callers could durably leave sync enabled with blank or divergent model values or erase the untargeted model. isolated_userdefaults GlobalSettingsStore+fake_store retain 0 PR #545 P1 shared durable-authority regression. -root/RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests/testModelSyncClearsAndEnablesPreserveDurableInvariant root Tests/RepoPromptTests/MCP/AppSettingsMCPServiceAgentModeSettingsTests.swift RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests testModelSyncClearsAndEnablesPreserveDurableInvariant MCP/Settings app_settings.models.sync_invariant model_clear,sibling_preservation,blank_oracle,valid_enable,in_process_mcp deterministic_persistence root_swiftpm routine 4 temporary_settings_file,isolated_user_defaults In-process app_settings rejects durable true for a blank Oracle, snaps a valid enable to equal nonblank models, and clears either model while preserving its sibling and disabling sync. MCP model mutations could persist invalid synchronized tuples or blank the untargeted Oracle/chat model. filesystem,user_defaults AppSettingsMCPService;GlobalSettingsStore retain 0 PR #545 P1 MCP durable-invariant regression. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testDurableAgentModelsSettersDisableEveryInvalidSynchronizedTuple root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testDurableAgentModelsSettersDisableEveryInvalidSynchronizedTuple Settings agent_models.persistence.invalid_sync_tuple_validation sync_toggle,blank_model,divergent_model,global_profile,workspace_overrides,diagnostics deterministic_regression root_swiftpm routine 6 Global and workspace durable profile setters preserve both model raws, disable both-blank, one-blank, and divergent sync attempts, and retain exact assertion plus agent_models.profile.invalid_sync. diagnostic evidence for each rejected class. Programmatic callers could persist invalid synchronized profiles despite boundary diagnostics. isolated_userdefaults,notification_center assertion_probe+test_case retain 0 Renamed from root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testDurableAgentModelsSettersDiagnoseEveryInvalidSynchronizedTuple; PR #545 changes the contract from diagnose-only to state-safe normalization. -root/RepoPromptTests.RecommendationWizardScopedTargetTests/testPresetOnlyWorkspaceTargetNotifiesGlobalScope root Tests/RepoPromptTests/AgentMode/RecommendationWizardScopedTargetTests.swift RepoPromptTests.RecommendationWizardScopedTargetTests testPresetOnlyWorkspaceTargetNotifiesGlobalScope AgentMode agent_models.wizard.preset_only_global_notification recommendation_wizard,workspace_overrides,mcp_presets,global_scope,notifications deterministic_view_model root_swiftpm routine 3 temporary_settings_store,isolated_user_defaults A preset-only workspace-targeted wizard step applies global MCP preset settings and emits one canonical global notification attributed to the source workspace. Preset-only apply could emit workspace metadata and leave global preset consumers stale or refresh the wrong workspace boundary. filesystem,user_defaults notification_center test_case+addTeardownBlock retain 0 Oracle affected-scope blocker regression. -root/RepoPromptTests.AutoRecommendationEngineScopedSettingsTests/testBulkApplyWithPresetExposureNotifiesEachAffectedScopeAndCoalescesGlobal root Tests/RepoPromptTests/AgentMode/AutoRecommendationEngineScopedSettingsTests.swift RepoPromptTests.AutoRecommendationEngineScopedSettingsTests testBulkApplyWithPresetExposureNotifiesEachAffectedScopeAndCoalescesGlobal AgentMode agent_models.recommendations.bulk_apply_affected_scopes workspace_overrides,mcp_presets,global_scope,scoped_notifications,deduplication deterministic_regression root_swiftpm routine 2 temporary_settings_store,isolated_user_defaults Bulk engine apply with preset exposure emits workspace plus global notifications for workspace targets and coalesces a global Agent Models target to one global event. The non-wizard bulk path could omit preset scope refreshes or emit duplicate global notifications. filesystem,user_defaults notification_center test_case+addTeardownBlock retain 0 Oracle affected-scope blocker regression for includePresetExposure. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testRepeatedSemanticQuarantineDelaysAndEventuallyRepairsTheFailingAuthority root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testRepeatedSemanticQuarantineDelaysAndEventuallyRepairsTheFailingAuthority CodeMap codemap.root_manifest.semantic_corruption_backpressure semantic_corruption,quarantine,cooldown,eventual_repair,bounded_diagnostics failure_recovery root_swiftpm routine 4 ManifestAccessClock Repeated semantic corruption delays the second repair, then publishes and reloads successfully after the authority-scoped cooldown. Cooldown could drop durability work or never repair the quarantined manifest. filesystem,security,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Issue 466 eventual semantic-corruption recovery -root/RepoPromptTests.CodeMapRootManifestStoreTests/testCoalescedAccessRefreshesAvoidStoreWideReconciliation root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCoalescedAccessRefreshesAvoidStoreWideReconciliation CodeMap codemap.root_manifest.access_refresh_scan_amplification multiple_namespaces,coalesced_touches,no_store_scan,fixed_width_metadata,atomic_publication performance_contract root_swiftpm routine 3 CodeMapRootManifestAccessRefreshFixture Three pending namespace touches persist epoch 500 with unchanged generations and records while the maintenance drain performs zero store-wide reconciliation scans. Re-publishing every stale access touch through quota reconciliation makes a burst decode the full store once per namespace and approaches quadratic CPU work. 0.250000 filesystem,concurrency,performance temporary_directory test_case retain 0 Issue 466 fixed-width access refresh bypasses unrelated store reconciliation after exact target revalidation -root/RepoPromptTests.CodeMapRootManifestStoreTests/testCommittedMaintenanceRetryPreservesProtectedPublicationUnderQuotaPressure root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCommittedMaintenanceRetryPreservesProtectedPublicationUnderQuotaPressure CodeMap codemap.root_manifest.retry_exact_target_protection bounded_retry,quota_pressure,exact_identity,protected_target,observable_debt security_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture,ManifestEntryInsertionHook,ManifestTemporaryBurstInsertionHook Bounded follow-up maintenance preserves the exact committed target while injected quota pressure remains observable after retry exhaustion. A retry could evict the durable target it was created to protect or falsely claim that bounded maintenance completed. 0.250000 filesystem,security,concurrency,performance temporary_directory test_case+fixture_cleanup retain 0 Issue 466 exact committed-target protection across bounded retries -root/RepoPromptTests.CodeMapRootManifestStoreTests/testCommittedMaintenanceRetryStopsAfterBoundedAttempts root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testCommittedMaintenanceRetryStopsAfterBoundedAttempts CodeMap codemap.root_manifest.retry_attempt_bound retry_backoff,attempt_limit,pending_debt,target_readability security_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture,ManifestTemporaryBurstInsertionHook Follow-up maintenance stops after three attempts, retains explicit pending debt, and leaves the committed target readable. Unbounded retry tasks could consume actor and filesystem work indefinitely, while dropping debt could hide incomplete cleanup. 0.250000 filesystem,security,concurrency,performance temporary_directory test_case+fixture_cleanup retain 0 Issue 466 bounded committed-maintenance retry contract -root/RepoPromptTests.CodeMapRootManifestStoreTests/testDurableCommitSchedulesBoundedFollowUpMaintenance root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testDurableCommitSchedulesBoundedFollowUpMaintenance CodeMap codemap.root_manifest.durable_commit_follow_up durable_commit,temporary_burst,background_maintenance,debt_clear,target_readability security_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture,ManifestTemporaryBurstInsertionHook A durably committed publication schedules bounded cleanup, removes injected temporary debris, clears debt, and remains readable. Reporting the durable rename as failure or omitting bounded cleanup could cause duplicate writes or unbounded crash residue. 0.250000 filesystem,security,concurrency,performance temporary_directory test_case+fixture_cleanup retain 0 Issue 466 durable-success follow-up maintenance -root/RepoPromptTests.CodeMapRootManifestStoreTests/testEvictingPublicationUsesAtMostThreeBoundedStoreScans root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testEvictingPublicationUsesAtMostThreeBoundedStoreScans CodeMap codemap.root_manifest.evicting_publication_scan_bound quota_eviction,lru,scan_upper_bound,protected_target,terminal_authority security_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture An evicting publication stays within a three-scan upper bound, removes the quota victim, and preserves the new exact target. Duplicated reconciliation could amplify full-store work or evict the just-published target while enforcing quota. 0.250000 filesystem,security,concurrency,performance temporary_directory test_case+fixture_cleanup retain 0 Issue 466 behavioral upper bound for evicting publication reconciliation -root/RepoPromptTests.CodeMapRootManifestStoreTests/testInPlaceChildMutationInvalidatesDecodedManifestCache root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testInPlaceChildMutationInvalidatesDecodedManifestCache CodeMap codemap.root_manifest.per_file_cache_authority in_place_mutation,file_identity,content_checksum,decode_cache,authoritative_accounting security_contract root_swiftpm routine 1 CodeMapRootManifestAccountingFixture After an external in-place manifest rewrite leaves the parent directory entry intact, authoritative accounting validates a changed content checksum, decodes the new snapshot, and observes both records. Trusting parent-directory or coarse per-file timestamps could reuse stale decoded content after an adversarial same-tick child rewrite and return incorrect quota or record accounting. 0.200000 filesystem,security,performance temporary_directory test_case retain 0 Issue 466 cache requires complete per-file identity plus a freshly verified SHA-256 content checksum -root/RepoPromptTests.CodeMapRootManifestStoreTests/testLaterCleanPublicationClearsObsoleteCommittedMaintenanceDebt root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testLaterCleanPublicationClearsObsoleteCommittedMaintenanceDebt CodeMap codemap.root_manifest.maintenance_debt_supersession pending_retry,later_publication,authoritative_clean_scan,task_cancellation,exact_targets concurrency_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture,ManifestTemporaryBurstInsertionHook,ManifestAccessRefreshGate A later publication that completes an authoritative clean terminal reconciliation cancels obsolete committed-maintenance debt while both exact manifests remain readable. Stale debt could later protect an obsolete target, perform unnecessary reconciliation, or evict a newer committed manifest under quota pressure. 0.250000 filesystem,security,concurrency temporary_directory test_case+fixture_cleanup retain 0 Manifest reconciliation debt supersession regression -root/RepoPromptTests.CodeMapRootManifestStoreTests/testOrdinaryPublicationUsesAtMostTwoBoundedStoreScans root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testOrdinaryPublicationUsesAtMostTwoBoundedStoreScans CodeMap codemap.root_manifest.publication_scan_bound authoritative_enumeration,terminal_authority,quota,lru,target_readback,two_scans,cache_invalidation performance_contract root_swiftpm routine 2 CodeMapRootManifestStoreFixture A normal atomic publication performs at most one quota scan plus one post-rename authority scan, remains readable, then namespace removal releases its decoded cache entry. Running general cleanup, quota projection, and final accounting twice per publication turns one manifest completion into six full-store scans; removing terminal authority admits post-rename adversarial mutations, while missing removal invalidation retains large decoded snapshots outside disk quotas. 0.200000 filesystem,security,performance temporary_directory test_case retain 0 Issue 466 publication-specific reconciliation reduces six scans to two while preserving terminal authority and bounding cache lifetime -root/RepoPromptTests.CodeMapRootManifestStoreTests/testPostRenameMutationIsReconciledWithoutReportingDurableCommitAsFailure root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testPostRenameMutationIsReconciledWithoutReportingDurableCommitAsFailure CodeMap codemap.root_manifest.committed_maintenance_outcome post_rename_mutation,terminal_scan,quota,lru,protected_target,durable_success security_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture,ManifestEntryInsertionHook A same-UID valid manifest inserted after the target rename is detected by terminal authority accounting and evicted; the protected fsynced target remains readable and publication returns durable success. Dropping terminal reconciliation can return with an over-quota store, while throwing after verified commit makes the binding writer retain and retry a mutation already durable on disk. 0.250000 filesystem,security,concurrency temporary_directory test_case retain 0 Issue 466 post-commit anomaly uses best-effort maintenance without converting durable commit into failure -root/RepoPromptTests.CodeMapRootManifestStoreTests/testPublicMaintainHonorsPendingCommittedTargetProtection root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testPublicMaintainHonorsPendingCommittedTargetProtection CodeMap codemap.root_manifest.public_maintenance_committed_protection public_maintain,pending_retry,exact_identity,quota_eviction,protected_target security_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture,ManifestEntryInsertionHook,ManifestTemporaryBurstInsertionHook,ManifestAccessRefreshGate Public maintenance consumes authoritative pending protection, removes injected debris and the newer intruder, and preserves the exact older committed target before clearing debt. A maintenance entry point that omits pending protection could evict a durably committed target while claiming successful quota reconciliation. 0.250000 filesystem,security,concurrency temporary_directory test_case+fixture_cleanup retain 0 Manifest reconciliation public-maintenance protection regression -root/RepoPromptTests.CodeMapRootManifestStoreTests/testDecodedManifestCacheHonorsEncodedByteBudget root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testDecodedManifestCacheHonorsEncodedByteBudget CodeMap codemap.root_manifest.decoded_cache_byte_budget encoded_byte_budget,lru_eviction,cache_accounting,multiple_namespaces performance_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture Two decoded manifests larger than the configured one-manifest byte budget never exceed that budget and leave only one cached snapshot. An entry-count-only or unbounded decoded cache could retain large record arrays outside the persisted store quota and grow process memory with workspace count. 0.250000 filesystem,performance temporary_directory test_case+fixture_cleanup retain 0 PR #488 decoded-manifest cache uses an explicit encoded-byte budget and LRU eviction. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testMaintenanceRepeatedSemanticQuarantineDelaysAndBackpressuresRepair root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testMaintenanceRepeatedSemanticQuarantineDelaysAndBackpressuresRepair CodeMap codemap.root_manifest.maintenance_semantic_backpressure maintenance_scan,semantic_corruption,typed_attribution,quarantine,backpressure,repair corruption_recovery root_swiftpm routine 1 CodeMapRootManifestStoreFixture Repeated maintenance scans quarantine semantic contribution corruption, record typed failures without resolved authority, apply one backpressure delay, and permit repair. Scan-discovered semantic corruption could bypass regeneration backpressure and trigger an unbounded repair loop because maintenance lacks a resolved writer authority. 0.250000 filesystem,security,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #488 scan-discovered semantic corruption attribution and repair backpressure. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testNearCapacityPublicationKeepsScanCountAndElapsedTimeBounded root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testNearCapacityPublicationKeepsScanCountAndElapsedTimeBounded CodeMap codemap.root_manifest.near_capacity_publication_evidence 255_resident_manifests,default_256_manifest_cap,two_scans,elapsed_bound,authoritative_accounting performance_contract root_swiftpm routine 1 CodeMapRootManifestStoreFixture,ManifestEntryInsertionHook A publication into a 255-of-256 default-policy manifest store completes with exactly two authoritative scans, remains under fifteen seconds, and returns complete 256-manifest accounting. Small-fixture scan-count tests alone could hide size-dependent amplification or an unexpectedly slow terminal scan near the production capacity. 15.000000 filesystem,performance temporary_directory test_case+fixture_cleanup retain 0 PR #487/#488 combined near-capacity scan and wall-time evidence. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testManifestWriterBatchByteLimitPreventsQueuedItemCoalescing root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testManifestWriterBatchByteLimitPreventsQueuedItemCoalescing WorkspaceContext workspace_codemap_binding_engine.manifest_batch_byte_bound blocked_manifest_write,byte_limit,no_coalescing bounded_state_machine root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBlockingGate,EngineHookEvents A one-byte multi-item allowance prevents queued item coalescing. Batch supplementation could exceed the configured byte bound. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 Issue 466 byte-bound regression -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testManifestWriterBatchItemLimitSplitsLargeQueuedRun root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testManifestWriterBatchItemLimitSplitsLargeQueuedRun WorkspaceContext workspace_codemap_binding_engine.manifest_batch_item_bound sixty_six_entries,sixty_four_item_cap bounded_state_machine root_swiftpm routine 2 ManifestQueueTestItem Sixty-six compatible FIFO entries pop as one 64-item batch followed by two entries. An unbounded dequeue could create oversized publications. actor_state_primitive test_case retain 0 Issue 466 item-bound primitive -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testDeferredWorkAbandonsAfterMaxAttemptsWithoutPublishingDeferredRecords root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testDeferredWorkAbandonsAfterMaxAttemptsWithoutPublishingDeferredRecords WorkspaceContext workspace_codemap_binding_engine.manifest_retry_exhaustion persistent_publication_failure,bounded_retry,head_batch_abandonment,pinned_dirty,persisted_snapshot concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublications After exactly three failed attempts, only the exhausted frozen head batch is abandoned, its waiters resolve, the live pipeline remains explicitly dirty, and the durable manifest still contains only the successful predecessor publication. A retry-exhausted writer could publish abandoned records, transfer attempts to a successor, or falsely report an undurable live session clean. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 repair changes abandonment from false-clean to pinned dirty while preserving the predecessor-only durable snapshot. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testDeferredWorkDrainsAfterOneShotFailureAndSurvivesReload root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testDeferredWorkDrainsAfterOneShotFailureAndSurvivesReload WorkspaceContext workspace_codemap_binding_engine.manifest_retry_one_shot_recovery blocked_manifest_write,queued_batch,one_shot_failure,autonomous_retry,reload concurrency_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublication,EngineHookEvents A queued two-item batch that fails once retries autonomously, reports one failure, persists all records, and survives root reload. A transient manifest publication failure could strand queued work, inflate diagnostics, or lose recovered records after reload. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 bounded one-shot manifest retry recovery contract; combined near-capacity performance remains #487/#488 stack validation. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testDeferredWorkRecoversAfterRepeatedFailure root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testDeferredWorkRecoversAfterRepeatedFailure WorkspaceContext workspace_codemap_binding_engine.manifest_retry_repeated_recovery blocked_manifest_write,queued_batch,two_failures,autonomous_retry,exact_diagnostics concurrency_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublications,EngineHookEvents A queued two-item batch survives two publication failures, retries in FIFO order, reports exactly two failures, and completes on the third attempt. Repeated transient failures could reorder deferred work, double-count diagnostics, abandon work too early, or fail to resume every waiter. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 repeated manifest retry semantics; combined near-capacity performance remains #487/#488 stack validation. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testSuccessfulManifestRetryResetsConsecutiveFailureCount root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testSuccessfulManifestRetryResetsConsecutiveFailureCount WorkspaceContext workspace_codemap_binding_engine.manifest_retry_consecutive_failure_reset isolated_failures,successful_retries,failure_streak_reset,no_early_abandonment,reload concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineManifestFaultOnPublications,EngineHookEvents Three isolated publication failures separated by successful retries remain independent, retain every manifest record, and report exact diagnostics. A cumulative failure counter could abandon later work after three non-consecutive transient failures despite successful recovery between them. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 consecutive manifest retry failure semantics. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testArrivalDuringRetryStaysQueuedBehindDeferredHeadUntilDelayResumes root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testArrivalDuringRetryStaysQueuedBehindDeferredHeadUntilDelayResumes WorkspaceContext workspace_codemap_binding_engine.manifest_retry_admission_delay failed_head,retry_delay_gate,new_arrival,no_early_writer,fifo,reload concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineAsyncGate,EngineManifestFaultOnPublication,EngineCompletionFlag While a failed head is parked in the injected retry delay, a new revision stays queued, neither waiter completes and no second publication starts; releasing the delay persists the head then successor in FIFO order and both reload. A new admission could cancel retry backoff, start a writer early, overtake deferred work, or strand either waiter. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 deterministic arrival-during-retry regression. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testDeferredCapRetainsOldestPrefixShedsNewestSuffixAndKeepsPipelineDirty root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testDeferredCapRetainsOldestPrefixShedsNewestSuffixAndKeepsPipelineDirty WorkspaceContext workspace_codemap_binding_engine.manifest_deferred_suffix_shedding small_cap,five_revisions,oldest_prefix,newest_suffix,exact_waiters,pinned_dirty,reload concurrency_contract root_swiftpm routine 5 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublication,EngineHookEvents With a three-item deferred cap, five deterministic admissions retain and durably publish revisions one through three, reject the newest two durability waiters while preserving overlay readiness, pin the session dirty, and reload only the retained prefix before resolving shed current source safely. Capacity pressure could discard oldest admitted work, detach retained waiters, claim a false-clean pipeline, or expose shed records as durable after reload. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 newest-suffix capacity and reload-safety regression. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testShedNewestSamePathMutationKeepsSessionDirtyAndReloadDoesNotTrustStaleManifest root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testShedNewestSamePathMutationKeepsSessionDirtyAndReloadDoesNotTrustStaleManifest WorkspaceContext workspace_codemap_binding_engine.manifest_same_path_shed_safety same_path,small_cap,newest_shed,pending_owner,pinned_dirty,no_authority,reload concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublication,EngineHookEvents Two same-path removals behind a failed predecessor overflow a two-item cap; the newest waiter fails, the live pipeline stays dirty after its pending entry is discarded, no durable manifest authority is manufactured, and reload starts with no stale entry. Discarding a newest same-path owner could erase the only pending map entry, falsely mark clean, or let reload trust stale authority. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 same-path false-clean and reload-authority regression. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testCapacitySheddingDoesNotResetHeadAttemptsOrAbandonRetainedSuccessor root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testCapacitySheddingDoesNotResetHeadAttemptsOrAbandonRetainedSuccessor WorkspaceContext workspace_codemap_binding_engine.manifest_cap_attempt_identity persistent_head_failure,small_cap,suffix_shed,three_attempts,successor_durability concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,EngineBlockingGate,EngineManifestFaultOnPublications,EngineHookEvents Under a two-item cap, shedding the newest third revision does not reset the failing first head's budget; exactly three head failures abandon only that head and the retained second revision then persists. Suffix pressure could reset attempts, grow the exhausted batch to include newer work, retry forever, or abandon the retained successor. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 per-head bounded-attempt regression under capacity pressure. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testLateWaiterForExhaustedHeadResolvesFalseWhenSuccessorExhausts root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testLateWaiterForExhaustedHeadResolvesFalseWhenSuccessorExhausts WorkspaceContext workspace_codemap_binding_engine.manifest_exhausted_head_late_waiter late_head_waiter,successor_relevance,two_exhausted_heads,terminal_waiter_sweep,peak_backlog concurrency_contract root_swiftpm routine 5 ReviewGitRepositoryFixture,EngineAsyncGate,ManifestRetryStepper,EngineManifestFaultOnPublications,EngineHookEvents,EngineCompletionFlag Revision one exhausts before its waiter installs; while revision two remains relevant the late waiter installs, then terminal abandonment of revision two resolves both waiters false and counts the frozen head in peak backlog. Exact-only exhausted-head waiter detachment could strand the older waiter forever after the successor also exhausts. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 final Oracle P1 late-waiter liveness regression. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testThrowingRetryWaiterRecoversWithoutWedgingNamespace root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testThrowingRetryWaiterRecoversWithoutWedgingNamespace WorkspaceContext workspace_codemap_binding_engine.manifest_retry_waiter_error_recovery one_shot_failure,injected_waiter_error,non_cancelled_resume,no_wedge concurrency_contract root_swiftpm routine 3 ReviewGitRepositoryFixture,ManifestThrowingRetryWaiter,EngineManifestFaultOnPublication,EngineCompletionFlag An independently throwing injected retry waiter is not treated as task cancellation; deferred work resumes immediately, publishes once, resolves its demand, and leaves the namespace clean. A finished throwing retry task could remain recorded and permanently park all later admissions. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 final Oracle P2 retry-waiter liveness regression. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testCancelledRetryHeadDoesNotTransferAttemptsToSuccessor root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testCancelledRetryHeadDoesNotTransferAttemptsToSuccessor WorkspaceContext workspace_codemap_binding_engine.manifest_cancelled_head_attempt_reset two_head_failures,invalidation_cancel,stale_proof,new_successor,fresh_budget,durable_remove concurrency_contract root_swiftpm routine 4 ReviewGitRepositoryFixture,ManifestRetryStepper,EngineManifestFaultOnPublications,EngineHookEvents After two failures, invalidation cancels the deferred head; its stale retry is discarded without transferring attempts, the successor survives its own first failure, retries, and durably publishes the empty manifest clean. A canceled or stale head could donate its failure count to the next batch and cause premature abandonment after one successor failure. git_subprocess,filesystem,actor,concurrency temporary_directory test_case+fixture_cleanup retain 0 PR #487 head-change attempt isolation regression. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testAccessRefreshSkippingGlobalReconciliationRejectsPublishedTargetFileDisplacement root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAccessRefreshSkippingGlobalReconciliationRejectsPublishedTargetFileDisplacement CodeMap codemap.root_manifest.access_refresh_target_file_displacement access_refresh,expected_snapshot,no_growth,skip_reconciliation,post_rename,target_identity,fail_closed security_contract root_swiftpm routine 1 CodeMapRootManifestAccessRefreshFixture,ManifestTargetFileReplacementHook A scheduled non-growing semantic access refresh performs no global scan and rejects a secure same-content target-file replacement after publication; the displaced path retains only the admitted epoch-100 snapshot. The optimized access-refresh path could report a publication against a target inode displaced after rename, treating attacker-replaced path content as its committed epoch-160 snapshot. 0.000000 filesystem,security,concurrency temporary_directory test_case retain 0 PR 552 Sentry review 4702629671 post-rename target-file fencing -root/RepoPromptTests.CodeMapRootManifestStoreTests/testAccessRefreshSkippingGlobalReconciliationRejectsTargetShardDisplacement root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAccessRefreshSkippingGlobalReconciliationRejectsTargetShardDisplacement CodeMap codemap.root_manifest.access_refresh_shard_displacement access_refresh,expected_snapshot,no_growth,skip_reconciliation,post_rename,shard_identity,fail_closed security_contract root_swiftpm routine 1 CodeMapRootManifestAccessRefreshFixture,ManifestShardReplacementHook A scheduled non-growing semantic access refresh performs no global scan and rejects target-shard displacement after publication; the replacement authoritative shard contains no manifest. The optimized access-refresh path could report a write through a descriptor whose shard pathname was displaced after rename, granting detached storage false mutation authority. 0.000000 filesystem,security,concurrency temporary_directory test_case retain 0 PR 552 Sentry review 4702629671 post-rename shard fencing -root/RepoPromptTests.CodeMapRootManifestStoreTests/testSemanticNoOpBelowAccessRefreshThresholdDoesNotRewriteOrScan root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testSemanticNoOpBelowAccessRefreshThresholdDoesNotRewriteOrScan CodeMap codemap.root_manifest.semantic_noop_below_access_refresh_threshold semantic_noop,below_threshold,no_rewrite,skip_reconciliation,no_growth deterministic_persistence root_swiftpm routine 1 ManifestPublicationCounter,ManifestScanInspectionRecorder A semantic no-op update below the access-refresh threshold returns unchanged, performs no publication or global manifest scan, preserves the durable access epoch and generation, and leaves store accounting unchanged. A no-op manifest update could rewrite and fsync unchanged state, trigger a store-wide scan, grow accounting, or incorrectly advance durable access metadata. filesystem,actor temporary_directory test_case retain 0 PR #552 below-threshold semantic no-op regression. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testAccessRefreshAtThresholdPublishesWithoutGlobalScanOrStoreGrowth root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAccessRefreshAtThresholdPublishesWithoutGlobalScanOrStoreGrowth CodeMap codemap.root_manifest.access_refresh_exact_threshold access_refresh,exact_threshold,publication,skip_reconciliation,no_growth deterministic_persistence root_swiftpm routine 1 ManifestPublicationCounter,ManifestScanInspectionRecorder,ManifestAccessClock At the exact refresh threshold, a successful load publishes only the updated access epoch without advancing generation, scanning unrelated manifests, or changing store accounting. The threshold boundary could skip a required durable refresh, run an unnecessary global reconciliation, grow the store, or spuriously advance semantic generation. filesystem,actor,concurrency temporary_directory test_case retain 0 PR #552 exact access-refresh threshold regression. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testRecordMutationBelowAccessRefreshThresholdStillRewrites root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testRecordMutationBelowAccessRefreshThresholdStillRewrites CodeMap codemap.root_manifest.record_mutation_below_access_refresh_threshold record_mutation,below_threshold,semantic_rewrite,generation,access_epoch deterministic_persistence root_swiftpm routine 1 ManifestPublicationCounter A record-set mutation below the access-refresh threshold publishes the new records and access epoch and advances manifest generation exactly once. Applying access-refresh coalescing to semantic record changes could suppress required persistence and leave the durable manifest stale. filesystem,actor temporary_directory test_case retain 0 PR #552 below-threshold record-mutation regression. -root/RepoPromptTests.CodeMapRootManifestStoreTests/testAuthorityMutationBelowAccessRefreshThresholdStillRewrites root Tests/RepoPromptTests/CodeMap/CodeMapRootManifestStoreTests.swift RepoPromptTests.CodeMapRootManifestStoreTests testAuthorityMutationBelowAccessRefreshThresholdStillRewrites CodeMap codemap.root_manifest.authority_mutation_below_access_refresh_threshold authority_mutation,below_threshold,semantic_rewrite,generation,access_epoch deterministic_persistence root_swiftpm routine 1 ManifestPublicationCounter An authority mutation below the access-refresh threshold publishes the new authority and access epoch and advances manifest generation exactly once. Applying access-refresh coalescing to authority changes could suppress required persistence and retain stale namespace authority. filesystem,actor temporary_directory test_case retain 0 PR #552 below-threshold authority-mutation regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testLargeMixedBatchIsBoundedAndReportsEveryEligibleOutcome root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testLargeMixedBatchIsBoundedAndReportsEveryEligibleOutcome MCP/Agent agent_manage.cleanup_sessions.bounded_mixed_batch cleanup_sessions,batch_cap,partial_results,eligibility main_actor_service_integration mcp_agent_control routine 5 CleanupRecorder A maximum-size mixed cleanup batch reports every eligibility outcome and rejects the first oversized request. Unbounded cleanup input could outrun the watchdog or omit per-session outcomes. window_state,actor WindowStatesManager per_test_window retain 0 Bounded cleanup batch and eligibility regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testMissingMetadataIndexUsesDirectSessionLookup root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testMissingMetadataIndexUsesDirectSessionLookup MCP/Agent agent_manage.cleanup_sessions.direct_metadata_lookup cleanup_sessions,metadata_index,direct_uuid_lookup,persistence main_actor_persistence_integration mcp_agent_control routine 1 temporary_workspace,AgentSessionDataService Cleanup resolves and durably deletes a persisted MCP session by UUID when its metadata index is missing. A cache or index miss could trigger a full inventory scan or make an eligible persisted session undeletable. filesystem,window_state WindowStatesManager,AgentSessionDataService per_test_window retain 0 Direct persisted-session lookup regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testCancellationBetweenIDsReturnsCommittedAndUnprocessedLedger root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testCancellationBetweenIDsReturnsCommittedAndUnprocessedLedger MCP/Agent agent_manage.cleanup_sessions.cancellation_partial_ledger cleanup_sessions,cancellation,partial_success,retry_ids main_actor_service_integration mcp_agent_control routine 2 CleanupRecorder Cancellation between IDs preserves the committed deletion and returns every unprocessed ID as an explicit retry candidate. Cancellation could hide committed mutation or invite blind replay of already-deleted sessions. actor,cancellation WindowStatesManager per_test_window retain 0 Cancellation and durable partial-success ledger regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testRetryOfCommittedDeletionIsAlreadyAbsentWithoutRepeatingMutation root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testRetryOfCommittedDeletionIsAlreadyAbsentWithoutRepeatingMutation MCP/Agent agent_manage.cleanup_sessions.idempotent_retry cleanup_sessions,idempotency,already_absent,no_replay main_actor_service_integration mcp_agent_control routine 1 CleanupRecorder Retrying a committed cleanup reports completed with already_absent and does not repeat persisted deletion or reference finalization. A caller retry after partial delivery could repeat durable cleanup side effects. actor WindowStatesManager per_test_window retain 0 Idempotent cleanup retry regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testOpenTabPathUsesSingleDeleteAuthorityWithoutFallbackDeleteOrFinalize root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testOpenTabPathUsesSingleDeleteAuthorityWithoutFallbackDeleteOrFinalize MCP/Agent agent_manage.cleanup_sessions.single_open_tab_authority cleanup_sessions,open_tab,exactly_once,delete_authority main_actor_window_integration mcp_agent_control routine 1 CleanupRecorder Open-tab cleanup delegates to the tab delete authority without fallback persisted deletion or reference finalization. Duplicated cleanup authorities could delete or finalize the same persisted session twice. window_state,actor WindowStatesManager per_test_window retain 0 Exactly-once open-tab cleanup authority regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testCancellationAfterPersistedLookupReturnsCurrentAndRemainingWithoutMutation root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testCancellationAfterPersistedLookupReturnsCurrentAndRemainingWithoutMutation MCP/Agent agent_manage.cleanup_sessions.post_resolution_cancellation_fence cleanup_sessions,cancellation,persisted_lookup,pre_mutation,retry_ids main_actor_service_integration mcp_agent_control routine 2 CleanupRecorder Cancellation observed after persisted lookup returns the current and remaining IDs as unprocessed retry candidates without deleting or finalizing the current session. A cancellation arriving during resolution could mutate the current session before returning it as retryable, causing ambiguous or repeated deletion. actor,cancellation WindowStatesManager per_test_window retain 0 Post-resolution cancellation fence regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testResolutionFailurePreservesCommittedLedgerAndContinuesLaterIDs root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testResolutionFailurePreservesCommittedLedgerAndContinuesLaterIDs MCP/Agent agent_manage.cleanup_sessions.resolution_failure_partial_ledger cleanup_sessions,resolution_failure,partial_success,retry_ids,continue_batch main_actor_service_integration mcp_agent_control routine 3 CleanupRecorder A lookup failure after one committed deletion is reported as resolution_failed with a retry ID while a later eligible ID still deletes and every outcome remains in the response. A per-ID resolution error could abort the batch and discard prior committed results or omit later requested IDs. actor,error_injection WindowStatesManager per_test_window retain 0 Per-ID resolution failure ledger regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testWorkspaceDriftFallsBackToPersistedDeletePinnedToCapturedWorkspace root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testWorkspaceDriftFallsBackToPersistedDeletePinnedToCapturedWorkspace MCP/Agent agent_manage.cleanup_sessions.workspace_drift_pinned_authority cleanup_sessions,workspace_drift,open_tab,fallback,persisted_delete main_actor_window_integration mcp_agent_control routine 1 CleanupRecorder When the target window changes workspaces during lookup, cleanup rejects the open-tab path and sends persisted deletion and reference finalization to the originally captured workspace. Workspace drift could route deletion authority or durable reference cleanup to the newly active workspace. window_state,actor,persistence WindowStatesManager per_test_window retain 0 Captured-workspace cleanup authority regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testInvalidNonStringAndDuplicateInputsFailAtomically root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testInvalidNonStringAndDuplicateInputsFailAtomically MCP/Agent agent_manage.cleanup_sessions.atomic_input_validation cleanup_sessions,invalid_uuid,non_string,duplicate,atomic_rejection main_actor_service_integration mcp_agent_control routine 3 CleanupRecorder Invalid UUID strings, non-string elements, and duplicate UUIDs each reject the complete cleanup request before lookup or mutation. Silent compaction could mutate valid IDs while omitting malformed or duplicate inputs from the response ledger. actor,input_validation WindowStatesManager per_test_window retain 0 Atomic cleanup input-validation regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testLastIDMutationCancellationIsProcessedRetryableAndCancelled root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testLastIDMutationCancellationIsProcessedRetryableAndCancelled MCP/Agent agent_manage.cleanup_sessions.mutation_cancellation_last_id cleanup_sessions,cancellation,mutation_started,last_id,retry_ids main_actor_service_integration mcp_agent_control routine 1 CleanupRecorder Cancellation thrown by the final ID mutation reports the current ID as processed and retryable, no unprocessed IDs, and cancelled status without finalization. A mutation-stage CancellationError on the final ID could be misreported as delete_failed with partial status or incorrectly marked unprocessed. actor,cancellation,error_injection WindowStatesManager per_test_window retain 0 Mutation-stage cancellation ledger regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testOpenDeleteFailurePreservesLocalStateAndRetryConverges root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testOpenDeleteFailurePreservesLocalStateAndRetryConverges MCP/Agent agent_manage.cleanup_sessions.open_delete_state_preservation cleanup_sessions,open_tab,delete_failed,durable_false,state_preservation,retry_convergence main_actor_window_integration mcp_agent_control routine 2 CleanupRecorder An open-tab durable deletion failure reports delete_failed with durable false and local cleanup incomplete while preserving the live tab/session; a retry through the same authority then converges successfully. Local runtime or UI state could be destroyed before a durable deletion failure, losing user state while still requiring a retry. window_state,actor,error_injection WindowStatesManager per_test_window retain 0 Exact replacement mapping: testOpenDeleteFailureReportsPartialMutationAndRetryConverges -> testOpenDeleteFailurePreservesLocalStateAndRetryConverges; preserved-state deletion failure regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testLiveOpenTabDeleteFinalizesWorkspaceSessionReferences root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testLiveOpenTabDeleteFinalizesWorkspaceSessionReferences MCP/Agent agent_manage.cleanup_sessions.live_open_reference_finalization cleanup_sessions,open_tab,workspace_metadata,reference_finalization main_actor_persistence_integration mcp_agent_control routine 1 temporary_workspace,AgentModeViewModel Live open-tab cleanup delegates to the owning delete authority and clears every compose or stashed workspace reference to the deleted session. A cleanup path that deletes the tab and session file without finalizing workspace bindings could leave stale activeAgentSessionID metadata. filesystem,window_state,actor WindowStatesManager,AgentSessionDataService per_test_window retain 0 Live open-tab workspace-reference finalization regression. -root/RepoPromptRegexCoreTests.PCRE2ConcurrencyTests/testOneCompiledRegexMatchesConcurrentlyWithIndependentState root Tests/RepoPromptRegexCoreTests/PCRE2ConcurrencyTests.swift RepoPromptRegexCoreTests.PCRE2ConcurrencyTests testOneCompiledRegexMatchesConcurrentlyWithIndependentState RegexCore regex_core.concurrent_shared_code shared_compiled_code,independent_match_state,sendability concurrency_stress isolated_core routine 1 One immutable compiled regex returns exact full and capture byte ranges across 256 concurrent independent matches. Shared PCRE2 code could race mutable match state, corrupt ranges, or invalidate the audited Sendable boundary. native_library test_case retain 0 RegexCore extraction owner coverage for audited concurrent matching invariant. -root/RepoPromptRegexCoreTests.PCRE2JITTests/testJITDisabledAutoAndRequiredOutcomes root Tests/RepoPromptRegexCoreTests/PCRE2JITTests.swift RepoPromptRegexCoreTests.PCRE2JITTests testJITDisabledAutoAndRequiredOutcomes RegexCore regex_core.jit.construction_outcomes disabled,automatic,required,host_capability native_interop isolated_core routine 3 Disabled JIT stays disabled, automatic mode reports an attempted host outcome, and required mode either compiles JIT code or reports the exact unavailable error. JIT policy drift could silently bypass a required mode or report compiled code that was never constructed. native_library test_case retain 0 RegexCore extraction owner coverage for host-aware JIT construction. -root/RepoPromptRegexCoreTests.PCRE2JITTests/testJITEnvironmentValueMapping root Tests/RepoPromptRegexCoreTests/PCRE2JITTests.swift RepoPromptRegexCoreTests.PCRE2JITTests testJITEnvironmentValueMapping RegexCore regex_core.jit.environment_mapping case_normalization,whitespace,disabled_aliases,required_aliases,default_auto pure_unit isolated_core routine 11 The pure resolver maps every supported disabled and required spelling after normalization and defaults missing, empty, and unknown values to automatic mode. Environment parsing drift could split CodeMap and search construction authority or change established runtime overrides. test_case retain 0 RegexCore extraction tests the common JIT authority without process-environment mutation. -root/RepoPromptRegexCoreTests.PCRE2RegexTests/testCompileMatchCapturesAndUTF8ByteRanges root Tests/RepoPromptRegexCoreTests/PCRE2RegexTests.swift RepoPromptRegexCoreTests.PCRE2RegexTests testCompileMatchCapturesAndUTF8ByteRanges RegexCore regex_core.match.utf8_capture_ranges compile,first_match,utf8,captures,no_match native_interop isolated_core routine 2 A compiled Unicode pattern returns exact full and capture UTF-8 byte ranges and rejects a shorter nonmatching subject. Byte-range or capture drift could corrupt search slices and CodeMap capture extraction. native_library test_case retain 0 RegexCore extraction direct wrapper contract. -root/RepoPromptRegexCoreTests.PCRE2RegexTests/testEnumerationAdvancesPastZeroLengthUnicodeMatches root Tests/RepoPromptRegexCoreTests/PCRE2RegexTests.swift RepoPromptRegexCoreTests.PCRE2RegexTests testEnumerationAdvancesPastZeroLengthUnicodeMatches RegexCore regex_core.enumeration.zero_length_unicode_progress enumeration,zero_length,unicode_scalar_boundary,liveness pure_unit isolated_core routine 1 Zero-length lookahead matches advance at exact UTF-8 scalar boundaries and terminate after the expected ranges. A byte or character-index progress bug could loop indefinitely or split a Unicode scalar. native_library test_case retain 0 RegexCore extraction enumeration liveness contract. -root/RepoPromptRegexCoreTests.PCRE2RegexTests/testLiteralEscapingHandlesEmbeddedQuoteTerminator root Tests/RepoPromptRegexCoreTests/PCRE2RegexTests.swift RepoPromptRegexCoreTests.PCRE2RegexTests testLiteralEscapingHandlesEmbeddedQuoteTerminator RegexCore regex_core.literal.embedded_quote_terminator literal_escaping,embedded_terminator,exact_match pure_unit isolated_core routine 2 Escaping a literal containing the PCRE2 quote terminator matches the exact literal and rejects a different candidate. Malformed quote escaping could turn literal search input into executable regex syntax. native_library test_case retain 0 RegexCore extraction literal safety contract. -root/RepoPromptRegexCoreTests.PCRE2RegexTests/testMatchLimitIsReported root Tests/RepoPromptRegexCoreTests/PCRE2RegexTests.swift RepoPromptRegexCoreTests.PCRE2RegexTests testMatchLimitIsReported RegexCore regex_core.match_limit.error_mapping match_context,match_limit,error_kind native_interop_negative isolated_core routine 1 A pathological nonmatch under an explicit one-step limit deterministically reports PCRE2Error.matchLimitExceeded with match kind. Limit failures could be lost or mistranslated, defeating app-owned search timeout policy. native_library test_case retain 0 RegexCore owns mechanism while RepoPromptApp retains limit policy. -root/RepoPromptRegexCoreTests.PCRE2RegexTests/testMatchSessionSupportsSequentialReuse root Tests/RepoPromptRegexCoreTests/PCRE2RegexTests.swift RepoPromptRegexCoreTests.PCRE2RegexTests testMatchSessionSupportsSequentialReuse RegexCore regex_core.match_session.sequential_reuse single_consumer,reuse,contains,first_match,captures native_interop isolated_core routine 3 One scoped session reuses mutable match state sequentially across a positive contains check, negative check, and captured first match. Session state could leak between subjects or be mistaken for concurrently shareable state. native_library test_case retain 0 RegexCore extraction owner coverage for deliberately non-Sendable session ownership. -root/RepoPromptTests.WorkspaceMarkdownFileOpenTests/testOpenFileForMarkdownLinkAwaitsAndPropagatesFailure root Tests/RepoPromptTests/WorkspaceContext/WorkspaceMarkdownFileOpenTests.swift RepoPromptTests.WorkspaceMarkdownFileOpenTests testOpenFileForMarkdownLinkAwaitsAndPropagatesFailure WorkspaceFiles workspace_files.markdown_open.awaited_failure async_open,completion,failure_propagation deterministic_async_unit root_swiftpm routine 1 The markdown-link open path remains suspended until the injected application opener completes and returns its failure result. A synchronous or fire-and-forget open path could hang the main thread or report success before AppKit finishes. appkit_workspace test_case retain 0 PR #589 async default-application open regression. -root/RepoPromptTests.WorkspaceMarkdownFileOpenTests/testOpenFileForMarkdownLinkPropagatesSuccessAndStandardizedURL root Tests/RepoPromptTests/WorkspaceContext/WorkspaceMarkdownFileOpenTests.swift RepoPromptTests.WorkspaceMarkdownFileOpenTests testOpenFileForMarkdownLinkPropagatesSuccessAndStandardizedURL WorkspaceFiles workspace_files.markdown_open.standardized_success async_open,path_standardization,success_propagation deterministic_async_unit root_swiftpm routine 1 The markdown-link open path passes the standardized absolute URL to the injected opener and returns its success result. The asynchronous repair could change path resolution or discard the application-open completion result. appkit_workspace test_case retain 0 PR #589 async default-application open regression. -root/RepoPromptTests.WorkspaceMarkdownFileOpenTests/testOpenFileForMarkdownLinkResolvedFileAwaitsAndPropagatesFailure root Tests/RepoPromptTests/WorkspaceContext/WorkspaceMarkdownFileOpenTests.swift RepoPromptTests.WorkspaceMarkdownFileOpenTests testOpenFileForMarkdownLinkResolvedFileAwaitsAndPropagatesFailure WorkspaceFiles workspace_files.markdown_open.resolved_awaited_failure resolved_file,indexed_path,relative_link,async_open,completion,failure_propagation deterministic_async_unit root_swiftpm routine 1 An indexed relative markdown-link path resolves to a real FileViewModel, stays suspended until its injected opener completes, and returns the opener's failure. The resolved-file branch could regress to fire-and-forget behavior while the unresolved fallback remained correct, reporting success before AppKit completion. appkit_workspace,filesystem test_case+fixture_cleanup retain 0 PR #589 reviewer-required resolved-file async completion regression. -root/RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests/testCaptureIndexCountsMissingNamedBuckets root Tests/RepoPromptCodeMapCoreTests/CodeMapQueryOptimizationBenchmarkTests.swift RepoPromptCodeMapCoreTests.CodeMapQueryOptimizationBenchmarkTests testCaptureIndexCountsMissingNamedBuckets CodeMapQueryOptimizationBenchmarkTests.swift graph_native.code_map_query_optimization_benchmark_tests.test_capture_index_counts_missing_named_buckets behavioral_contract root_swiftpm routine 1 Capture index counts missing named buckets. Regression would violate the reviewed capture index counts missing named buckets contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testQuickHandoffRejectsStaleTargetWithoutClipboardWrite root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testQuickHandoffRejectsStaleTargetWithoutClipboardWrite AgentMode agent_mode.handoff.quick_stale_target quick_handoff,immutable_target,stale_target,provider_not_read,no_clipboard presentation_contract root_swiftpm routine 1 AgentChatTitlebarSafetyFixture Quick Handoff rejects a stale captured target before reading the default provider and leaves the clipboard untouched. A stale menu action could resolve settings or copy a prompt for a renamed, rebound, or otherwise invalid target. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Renamed root/RepoPromptTests.AgentChatTitlebarSafetyTests/testCopyHandoffPromptWritesValidTargetAndRejectsStaleTarget -> root/RepoPromptTests.AgentChatTitlebarSafetyTests/testQuickHandoffRejectsStaleTargetWithoutClipboardWrite; work item 2 fail-closed quick-copy target validation contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testHandoffPromptRendersExactBuildAwareMCPAndCLIRouting root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testHandoffPromptRendersExactBuildAwareMCPAndCLIRouting App graph_native.agent_chat_titlebar_safety_tests.test_handoff_prompt_renders_exact_build_aware_mcpand_clirouting presentation_contract root_swiftpm routine 1 Handoff prompt renders exact build aware mcpand clirouting. Regression would violate the reviewed handoff prompt renders exact build aware mcpand clirouting contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.AgentProviderContextBuilderTests/testAgentModeOverCapHandoffUsesBorrowedPresentationWithZeroSourceDemandOrSecondFreeze root Tests/RepoPromptTests/AgentMode/AgentProviderContextBuilderTests.swift RepoPromptTests.AgentProviderContextBuilderTests testAgentModeOverCapHandoffUsesBorrowedPresentationWithZeroSourceDemandOrSecondFreeze AgentMode graph_native.agent_provider_context_builder_tests.test_agent_mode_over_cap_handoff_uses_borrowed_presentation_with_zero_source_demand_or_second_freeze presentation_contract root_swiftpm routine 1 Agent mode over cap handoff uses borrowed presentation with zero source demand or second freeze. Regression would violate the reviewed agent mode over cap handoff uses borrowed presentation with zero source demand or second freeze contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testCoverageAndPendingUpdatesDriveProgressAndStatus root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testCoverageAndPendingUpdatesDriveProgressAndStatus AgentMode graph_native.agent_workspace_roots_sidebar_store_tests.test_coverage_and_pending_updates_drive_progress_and_status behavioral_contract root_swiftpm routine 1 Partial catalog enumeration preserves classified/pending counts but withholds the moving supported-file denominator, so the sidebar stays indeterminate instead of showing a regressing percentage. Publishing a percentage against chunk-by-chunk discovery can make codemap progress repeatedly jump backward around the same value. test_case retain 0 PR #621 follow-up: partial discovery uses indeterminate progress until the supported-file total is stable. -root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testPresentationMapsEveryGraphNativeAvailabilityState root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testPresentationMapsEveryGraphNativeAvailabilityState AgentMode graph_native.agent_workspace_roots_sidebar_store_tests.test_presentation_maps_every_graph_native_availability_state presentation_contract root_swiftpm routine 7 Presentation maps every graph native availability state. Regression would violate the reviewed presentation maps every graph native availability state contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests/testSuspensionOverridesAvailabilityWithoutDestroyingGraphObservability root Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift RepoPromptTests.AgentWorkspaceRootsSidebarStoreTests testSuspensionOverridesAvailabilityWithoutDestroyingGraphObservability AgentMode graph_native.agent_workspace_roots_sidebar_store_tests.test_suspension_overrides_availability_without_destroying_graph_observability behavioral_contract root_swiftpm routine 1 Suspension overrides availability without destroying graph observability. Regression would violate the reviewed suspension overrides availability without destroying graph observability contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodeStructureToolCardTests/testFlatArgumentsDecodeAndOmittedPathsMeanSelection root Tests/RepoPromptTests/AgentMode/ToolCards/CodeStructureToolCardTests.swift RepoPromptTests.CodeStructureToolCardTests testFlatArgumentsDecodeAndOmittedPathsMeanSelection AgentMode graph_native.code_structure_tool_card_tests.test_flat_arguments_decode_and_omitted_paths_mean_selection protocol_contract root_swiftpm routine 2 Flat arguments decode and omitted paths mean selection. Regression would violate the reviewed flat arguments decode and omitted paths mean selection contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodeStructureToolCardTests/testGraphNativeResultBuildsFourStatusSummary root Tests/RepoPromptTests/AgentMode/ToolCards/CodeStructureToolCardTests.swift RepoPromptTests.CodeStructureToolCardTests testGraphNativeResultBuildsFourStatusSummary AgentMode graph_native.code_structure_tool_card_tests.test_graph_native_result_builds_four_status_summary protocol_contract root_swiftpm routine 4 Graph native result builds four status summary. Regression would violate the reviewed graph native result builds four status summary contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testAutomaticSelectionUsesCommittedGraphAndTargetOnlyBackgroundDemand root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testAutomaticSelectionUsesCommittedGraphAndTargetOnlyBackgroundDemand WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_automatic_selection_uses_committed_graph_and_target_only_background_demand behavioral_contract root_swiftpm routine 1 Automatic selection uses committed graph and target only background demand. Regression would violate the reviewed automatic selection uses committed graph and target only background demand contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testFinalRevalidationDropsTargetMutatedDuringDemandAndCleansTicket root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testFinalRevalidationDropsTargetMutatedDuringDemandAndCleansTicket WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_final_revalidation_drops_target_mutated_during_demand_and_cleans_ticket behavioral_contract root_swiftpm routine 1 Final revalidation drops target mutated during demand and cleans ticket. Regression would violate the reviewed final revalidation drops target mutated during demand and cleans ticket contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testGraphCatalogFirstPageExposesImmutableProjectedTotalFromStore root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testGraphCatalogFirstPageExposesImmutableProjectedTotalFromStore WorkspaceContext/CodeMap codemap.graph_catalog.projected_total_store_publication first_page_total,immutable_projection,partial_page,store_publication integration_contract root_swiftpm routine 1 CodemapStoreFixture,ReviewGitRepositoryFixture The first real-store graph catalog page exposes the immutable projected total even when its entry limit returns only part of the catalog. Dropping the projected total at the store boundary could make batched indexing progress indeterminate or regress its denominator. git_fixture,filesystem,actor temporary_directory store_session+fixture_cleanup retain 0 Code Map store projected-total regression. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testGraphBudgetRootDoesNotSuppressHealthyRealStoreRoot root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testGraphBudgetRootDoesNotSuppressHealthyRealStoreRoot WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_graph_budget_root_does_not_suppress_healthy_real_store_root behavioral_contract root_swiftpm routine 1 Graph budget root does not suppress healthy real store root. Regression would violate the reviewed graph budget root does not suppress healthy real store root contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testInvalidEarlierRootDoesNotChargeAcceptedBudgetsOrSuppressHealthyLaterRoot root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testInvalidEarlierRootDoesNotChargeAcceptedBudgetsOrSuppressHealthyLaterRoot WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_invalid_earlier_root_does_not_charge_accepted_budgets_or_suppress_healthy_later_root behavioral_contract root_swiftpm routine 1 Invalid earlier root does not charge accepted budgets or suppress healthy later root. Regression would violate the reviewed invalid earlier root does not charge accepted budgets or suppress healthy later root contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testPresentationCandidateDemandCapStopsBeforeAutomaticTargetDemandLoop root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testPresentationCandidateDemandCapStopsBeforeAutomaticTargetDemandLoop WorkspaceContext graph_native.automatic_selection.presentation_target_demand_cap_ordering pre_demand_guard,target_demand_limit,no_ticket_acquisition,presentation integration_contract root_swiftpm routine 1 CodemapStoreFixture An oversized automatic presentation returns the target-demand budget result before acquiring any artifact demand ticket. Automatic presentation could bypass the reviewed cap and enqueue every graph target before rendering. test_case retain 0 PR #621 review follow-up for the automatic-presentation target-demand cap. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testPublisherIngressAppliesCatalogWhileCorrelatedCodemapInvalidationIsStalled root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testPublisherIngressAppliesCatalogWhileCorrelatedCodemapInvalidationIsStalled WorkspaceContext/CodeMap codemap.publisher.applied_ingress_independent_invalidation applied_ingress,catalog_publication,stalled_invalidation,explicit_create async_concurrency_lifecycle root_swiftpm routine 2 CodemapStoreFixture,CodemapSuspensionGate Catalog ingress becomes applied and explicit create reaches disk while correlated derived codemap invalidation remains gate-blocked. Publisher-derived convergence could block canonical catalog visibility, explicit mutation I/O, or event-driven root-fence progress. 0.585000 filesystem,actor,concurrency store_session+publication_gate+root_unload retain 0 Issue #390 applied-ingress independence regression, ported from the retired basic suite while integrating main #613 path-quiescence coverage. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testRealTwoRootQueriesRemainIsolatedThenMergeDeterministically root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testRealTwoRootQueriesRemainIsolatedThenMergeDeterministically WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_real_two_root_queries_remain_isolated_then_merge_deterministically behavioral_contract root_swiftpm routine 1 Real two root queries remain isolated then merge deterministically. Regression would violate the reviewed real two root queries remain isolated then merge deterministically contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testRevalidationPreservesUnaffectedSiblingTargetAfterRealStoreMutation root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testRevalidationPreservesUnaffectedSiblingTargetAfterRealStoreMutation WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_revalidation_preserves_unaffected_sibling_target_after_real_store_mutation behavioral_contract root_swiftpm routine 1 Revalidation preserves unaffected sibling target after real store mutation. Regression would violate the reviewed revalidation preserves unaffected sibling target after real store mutation contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testRootReloadAndVisibleScopeChangesInvalidateReceipts root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testRootReloadAndVisibleScopeChangesInvalidateReceipts WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_root_reload_and_visible_scope_changes_invalidate_receipts behavioral_contract root_swiftpm routine 1 Root reload and visible scope changes invalidate receipts. Regression would violate the reviewed root reload and visible scope changes invalidate receipts contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testTargetDemandBusyRetryReleasesPriorTicketAndSucceeds root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testTargetDemandBusyRetryReleasesPriorTicketAndSucceeds WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_target_demand_busy_retry_releases_prior_ticket_and_succeeds behavioral_contract root_swiftpm routine 1 Target demand busy retry releases prior ticket and succeeds. Regression would violate the reviewed target demand busy retry releases prior ticket and succeeds contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testTargetDemandCancellationDrainsExactOwnedTicket root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testTargetDemandCancellationDrainsExactOwnedTicket WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_target_demand_cancellation_drains_exact_owned_ticket concurrency_contract root_swiftpm routine 1 Target demand cancellation drains exact owned ticket. Regression would violate the reviewed target demand cancellation drains exact owned ticket contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testTargetDemandDeadlineDrainsExactOwnedTicket root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testTargetDemandDeadlineDrainsExactOwnedTicket WorkspaceContext graph_native.codemap_automatic_selection_graph_native_tests.test_target_demand_deadline_drains_exact_owned_ticket concurrency_contract root_swiftpm routine 1 Target demand deadline drains exact owned ticket. Regression would violate the reviewed target demand deadline drains exact owned ticket contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testEditRenameDeleteFenceVisibilityWatcherReconcilesAndCheckoutRevokes root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testEditRenameDeleteFenceVisibilityWatcherReconcilesAndCheckoutRevokes WorkspaceContext graph_native.codemap_binding_engine_invalidation_tests.test_edit_rename_delete_fence_visibility_watcher_reconciles_and_checkout_revokes concurrency_contract root_swiftpm routine 1 Edit rename delete fence visibility watcher reconciles and checkout revokes. Regression would violate the reviewed edit rename delete fence visibility watcher reconciles and checkout revokes contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapBindingEngineInvalidationTests/testRejectedReconciliationFenceRevokesBindingOwnedGraphAndDrainsPullWork root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineInvalidationTests.swift RepoPromptTests.CodemapBindingEngineInvalidationTests testRejectedReconciliationFenceRevokesBindingOwnedGraphAndDrainsPullWork WorkspaceContext graph_native.codemap_binding_engine_invalidation_tests.test_rejected_reconciliation_fence_revokes_binding_owned_graph_and_drains_pull_work concurrency_contract root_swiftpm routine 1 Rejected reconciliation fence revokes binding owned graph and drains pull work. Regression would violate the reviewed rejected reconciliation fence revokes binding owned graph and drains pull work contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapBindingEngineManifestWriteTests/testGraphIndexMutationKeepsAdmissionOrderAheadOfLaterSessionMutation root Tests/RepoPromptTests/WorkspaceContext/CodemapBindingEngineManifestWriteTests.swift RepoPromptTests.CodemapBindingEngineManifestWriteTests testGraphIndexMutationKeepsAdmissionOrderAheadOfLaterSessionMutation WorkspaceContext graph_native.codemap_binding_engine_manifest_write_tests.test_graph_index_mutation_keeps_admission_order_ahead_of_later_session_mutation behavioral_contract root_swiftpm routine 1 Graph index mutation keeps admission order ahead of later session mutation. Regression would violate the reviewed graph index mutation keeps admission order ahead of later session mutation contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodemapGraphNativeDeletionRegressionTests/testProductionSourcesContainNoLegacyCodemapProjectionAuthority root Tests/RepoPromptTests/WorkspaceContext/CodemapGraphNativeDeletionRegressionTests.swift RepoPromptTests.CodemapGraphNativeDeletionRegressionTests testProductionSourcesContainNoLegacyCodemapProjectionAuthority WorkspaceContext graph_native.codemap_graph_native_deletion_regression_tests.test_production_sources_contain_no_legacy_codemap_projection_authority structural_guard root_swiftpm routine 1 Production sources contain no legacy codemap projection authority. Regression would violate the reviewed production sources contain no legacy codemap projection authority contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testCancelCommitRaceResolvesExactlyOnceForEitherOrdering root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testCancelCommitRaceResolvesExactlyOnceForEitherOrdering ContextBuilder graph_native.context_builder_run_lifecycle_tests.test_cancel_commit_race_resolves_exactly_once_for_either_ordering concurrency_contract root_swiftpm routine 1 Cancel commit race resolves exactly once for either ordering. Regression would violate the reviewed cancel commit race resolves exactly once for either ordering contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testCancellationDuringFinalCommitDefersUntilSafeBoundary root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testCancellationDuringFinalCommitDefersUntilSafeBoundary ContextBuilder graph_native.context_builder_run_lifecycle_tests.test_cancellation_during_final_commit_defers_until_safe_boundary concurrency_contract root_swiftpm routine 1 Cancellation during final commit defers until safe boundary. Regression would violate the reviewed cancellation during final commit defers until safe boundary contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testDeferredWorkspaceCancellationPreservesErrorPolicyAfterCommitBoundaryCheck root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testDeferredWorkspaceCancellationPreservesErrorPolicyAfterCommitBoundaryCheck ContextBuilder graph_native.context_builder_run_lifecycle_tests.test_deferred_workspace_cancellation_preserves_error_policy_after_commit_boundary_check concurrency_contract root_swiftpm routine 1 Deferred workspace cancellation preserves error policy after commit boundary check. Regression would violate the reviewed deferred workspace cancellation preserves error policy after commit boundary check contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.ContextBuilderRunLifecycleTests/testPreCommitCancellationRemainsImmediate root Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift RepoPromptTests.ContextBuilderRunLifecycleTests testPreCommitCancellationRemainsImmediate ContextBuilder graph_native.context_builder_run_lifecycle_tests.test_pre_commit_cancellation_remains_immediate concurrency_contract root_swiftpm routine 1 Pre commit cancellation remains immediate. Regression would violate the reviewed pre commit cancellation remains immediate contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testAssemblerPublishesFourStatusesMixedRootsAndLogicalPaths root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testAssemblerPublishesFourStatusesMixedRootsAndLogicalPaths MCP graph_native.mcpcode_structure_worktree_tests.test_assembler_publishes_four_statuses_mixed_roots_and_logical_paths protocol_contract root_swiftpm routine 4 Assembler publishes four statuses mixed roots and logical paths. Regression would violate the reviewed assembler publishes four statuses mixed roots and logical paths contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testDeterministicTruncationAndNodeOrderingAreStable root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testDeterministicTruncationAndNodeOrderingAreStable MCP graph_native.mcpcode_structure_worktree_tests.test_deterministic_truncation_and_node_ordering_are_stable protocol_contract root_swiftpm routine 1 Deterministic truncation and node ordering are stable. Regression would violate the reviewed deterministic truncation and node ordering are stable contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testConstrainedMultiRootSignaturesRemainGloballySeedFirst root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testConstrainedMultiRootSignaturesRemainGloballySeedFirst MCP code_structure_output.global_seed_signature_priority_contract presentation_contract root_swiftpm routine 1 Constrained multi-root signature rendering preserves every seed before any related file regardless of root order. A size-limited response could omit a later-root seed in favor of an earlier-root related signature. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSemanticSizeMappingAndFlatArgumentsDecodeStrictly root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSemanticSizeMappingAndFlatArgumentsDecodeStrictly MCP graph_native.mcpcode_structure_worktree_tests.test_semantic_size_mapping_and_flat_arguments_decode_strictly protocol_contract root_swiftpm routine 8 Semantic size tiers map strictly to internal budgets, omitted size defaults to medium, current responses round-trip, and invalid flat arguments reject. Regression would violate the strict current-only semantic size contract or its internal policy mapping. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testPublishedSchemaHasExactlyFiveFlatOptionalFieldsAndRejectsUnknownFields root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testPublishedSchemaHasExactlyFiveFlatOptionalFieldsAndRejectsUnknownFields MCP graph_native.mcpcode_structure_worktree_tests.test_published_schema_has_exactly_five_flat_optional_fields_and_rejects_unknown_fields protocol_contract root_swiftpm routine 1 Published schema has exactly five flat optional fields and generically rejects an unknown field. Regression would weaken the strict current five-field request contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testReconciliationAndRenderFailurePreserveGraphEvidence root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testReconciliationAndRenderFailurePreserveGraphEvidence MCP graph_native.mcpcode_structure_worktree_tests.test_reconciliation_and_render_failure_preserve_graph_evidence protocol_contract root_swiftpm routine 1 Reconciliation and render failure preserve graph evidence. Regression would violate the reviewed reconciliation and render failure preserve graph evidence contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testSignaturesFalsePerformsZeroArtifactDemandOrPresentationCoordination root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testSignaturesFalsePerformsZeroArtifactDemandOrPresentationCoordination MCP graph_native.mcpcode_structure_worktree_tests.test_signatures_false_performs_zero_artifact_demand_or_presentation_coordination protocol_contract root_swiftpm routine 1 Signatures false performs zero artifact demand or presentation coordination. Regression would violate the reviewed signatures false performs zero artifact demand or presentation coordination contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testCatalogCoverageAllowsPartialQueriesButCompleteRequiresNoPendingSlots root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testCatalogCoverageAllowsPartialQueriesButCompleteRequiresNoPendingSlots WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_catalog_coverage_allows_partial_queries_but_complete_requires_no_pending_slots behavioral_contract root_swiftpm routine 3 Catalog coverage allows partial queries but complete requires no pending slots. Regression would violate the reviewed catalog coverage allows partial queries but complete requires no pending slots contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testCheckpointValidatesCoverageAndCanonicalizesSlotOrder root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testCheckpointValidatesCoverageAndCanonicalizesSlotOrder WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_checkpoint_validates_coverage_and_canonicalizes_slot_order behavioral_contract root_swiftpm routine 3 Checkpoint validates coverage and canonicalizes slot order. Regression would violate the reviewed checkpoint validates coverage and canonicalizes slot order contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testExtractedCatalogPageValidationPreservesCanonicalCursorContract root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testExtractedCatalogPageValidationPreservesCanonicalCursorContract WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_extracted_catalog_page_validation_preserves_canonical_cursor_contract behavioral_contract root_swiftpm routine 3 Extracted catalog page validation preserves canonical cursor contract. Regression would violate the reviewed extracted catalog page validation preserves canonical cursor contract contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testGraphSlotValidationBindsRootPipelineStateAndDiagnosticDigest root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testGraphSlotValidationBindsRootPipelineStateAndDiagnosticDigest WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_graph_slot_validation_binds_root_pipeline_state_and_diagnostic_digest behavioral_contract root_swiftpm routine 3 Graph slot validation binds root pipeline state and diagnostic digest. Regression would violate the reviewed graph slot validation binds root pipeline state and diagnostic digest contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testRemovalFenceAndPullContractsKeepDestructiveChangesExplicit root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testRemovalFenceAndPullContractsKeepDestructiveChangesExplicit WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_removal_fence_and_pull_contracts_keep_destructive_changes_explicit concurrency_contract root_swiftpm routine 3 Removal fence and pull contracts keep destructive changes explicit. Regression would violate the reviewed removal fence and pull contracts keep destructive changes explicit contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testSinglePolicyEnforcesChangedSetCoalesceInvariantAndDerivesBudgets root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testSinglePolicyEnforcesChangedSetCoalesceInvariantAndDerivesBudgets WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_single_policy_enforces_changed_set_coalesce_invariant_and_derives_budgets behavioral_contract root_swiftpm routine 3 Single policy enforces changed set coalesce invariant and derives budgets. Regression would violate the reviewed single policy enforces changed set coalesce invariant and derives budgets contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests/testSnapshotReceiptRejectsCrossRootWatermarkAndKeepsFreshnessInternal root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphFoundationModelTests.swift RepoPromptTests.WorkspaceCodemapGraphFoundationModelTests testSnapshotReceiptRejectsCrossRootWatermarkAndKeepsFreshnessInternal WorkspaceContext graph_native.workspace_codemap_graph_foundation_model_tests.test_snapshot_receipt_rejects_cross_root_watermark_and_keeps_freshness_internal behavioral_contract root_swiftpm routine 3 Snapshot receipt rejects cross root watermark and keeps freshness internal. Regression would violate the reviewed snapshot receipt rejects cross root watermark and keeps freshness internal contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testChangedSetOverflowForcesSuccessiveAuthoritativeResyncs root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testChangedSetOverflowForcesSuccessiveAuthoritativeResyncs WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_changed_set_overflow_forces_successive_authoritative_resyncs concurrency_contract root_swiftpm routine 1 Changed set overflow forces successive authoritative resyncs. Regression would violate the reviewed changed set overflow forces successive authoritative resyncs contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testContributionGenerationExhaustionRevokesGraphChangesWithoutABA root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testContributionGenerationExhaustionRevokesGraphChangesWithoutABA WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_contribution_generation_exhaustion_revokes_graph_changes_without_aba behavioral_contract root_swiftpm routine 1 Contribution generation exhaustion revokes graph changes without aba. Regression would violate the reviewed contribution generation exhaustion revokes graph changes without aba contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphLedgerPullSemanticsAccumulateFloorAndEmitDestructiveRemoval root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphLedgerPullSemanticsAccumulateFloorAndEmitDestructiveRemoval WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_graph_ledger_pull_semantics_accumulate_floor_and_emit_destructive_removal behavioral_contract root_swiftpm routine 1 Graph ledger pull semantics accumulate floor and emit destructive removal. Regression would violate the reviewed graph ledger pull semantics accumulate floor and emit destructive removal contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphLivePathPrecedenceAndReconciliationPreserveArtifactResidency root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphLivePathPrecedenceAndReconciliationPreserveArtifactResidency WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_graph_live_path_precedence_and_reconciliation_preserve_artifact_residency behavioral_contract root_swiftpm routine 1 Graph live path precedence and reconciliation preserve artifact residency. Regression would violate the reviewed graph live path precedence and reconciliation preserve artifact residency contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphSlotsPreservePathGenerationForExactFenceMatching root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphSlotsPreservePathGenerationForExactFenceMatching WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_graph_slots_preserve_path_generation_for_exact_fence_matching concurrency_contract root_swiftpm routine 3 Live pending, ready, and invalidated graph slots preserve path generation for exact fence matching. Collapsing path generation into request generation can bypass a qualified destructive fence and expose a retired slot. test_case retain 0 PR #621 review regression for exact graph fence identity propagation. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testGraphWatcherReconciliationCoalescesAndForcesCheckpointRemovingMissingSlots root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testGraphWatcherReconciliationCoalescesAndForcesCheckpointRemovingMissingSlots WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_graph_watcher_reconciliation_coalesces_and_forces_checkpoint_removing_missing_slots behavioral_contract root_swiftpm routine 1 Graph watcher reconciliation coalesces and forces checkpoint removing missing slots. Regression would violate the reviewed graph watcher reconciliation coalesces and forces checkpoint removing missing slots contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testProjectedCatalogTotalDrivesDeterminateProgressAcrossSevenPages root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testProjectedCatalogTotalDrivesDeterminateProgressAcrossSevenPages WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_projected_catalog_total_drives_determinate_progress_across_seven_pages first_page_total,385_candidates,seven_pages,determinate_progress,completion behavioral_contract root_swiftpm routine 7 WorkspaceCodemapAuthorityTestFixture The immutable projection total seals a stable 385-candidate denominator on page one while classification advances across seven pages and completion remains reserved for zero pending candidates. A cumulative-only page count could leave large catalogs apparently frozen or report premature completion. git_fixture,actor temporary_directory test_case+fixture_cleanup retain 0 Code Map stable projected denominator regression. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testReconciliationRemovalsCarryDestructiveReasonsAndAwaitFencesBeforeCompleteCheckpoint root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testReconciliationRemovalsCarryDestructiveReasonsAndAwaitFencesBeforeCompleteCheckpoint WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_reconciliation_removals_carry_destructive_reasons_and_await_fences_before_complete_checkpoint concurrency_contract root_swiftpm routine 1 Reconciliation removals carry destructive reasons and await fences before complete checkpoint. Regression would violate the reviewed reconciliation removals carry destructive reasons and await fences before complete checkpoint contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapLiveOverlayTests/testTerminalCompletionBecomesUnavailableAndNeverFreezesArtifact root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift RepoPromptTests.WorkspaceCodemapLiveOverlayTests testTerminalCompletionBecomesUnavailableAndNeverFreezesArtifact WorkspaceContext graph_native.workspace_codemap_live_overlay_tests.test_terminal_completion_becomes_unavailable_and_never_freezes_artifact behavioral_contract root_swiftpm routine 1 Terminal completion becomes unavailable and never freezes artifact. Regression would violate the reviewed terminal completion becomes unavailable and never freezes artifact contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testAutomaticSelectionBudgetLimitsAcceptExactCountsAndRejectOneOver root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testAutomaticSelectionBudgetLimitsAcceptExactCountsAndRejectOneOver WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_automatic_selection_budget_limits_accept_exact_counts_and_reject_one_over behavioral_contract root_swiftpm routine 1 Automatic selection budget limits accept exact counts and reject one over. Regression would violate the reviewed automatic selection budget limits accept exact counts and reject one over contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testAutomaticSelectionQueriesCommittedSnapshotWithoutSourceArtifactDemand root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testAutomaticSelectionQueriesCommittedSnapshotWithoutSourceArtifactDemand WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_automatic_selection_queries_committed_snapshot_without_source_artifact_demand behavioral_contract root_swiftpm routine 1 Automatic selection queries committed snapshot without source artifact demand. Regression would violate the reviewed automatic selection queries committed snapshot without source artifact demand contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testDestructiveRemovalFencesAtomicallyAndReceiptsRevalidateCumulatively root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testDestructiveRemovalFencesAtomicallyAndReceiptsRevalidateCumulatively WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_destructive_removal_fences_atomically_and_receipts_revalidate_cumulatively concurrency_contract root_swiftpm routine 1 Destructive removal fences atomically and receipts revalidate cumulatively. Regression would violate the reviewed destructive removal fences atomically and receipts revalidate cumulatively contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testIncrementalDefinitionFanoutAndPartialUnresolvedEvidence root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testIncrementalDefinitionFanoutAndPartialUnresolvedEvidence WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_incremental_definition_fanout_and_partial_unresolved_evidence behavioral_contract root_swiftpm routine 1 Incremental definition fanout and partial unresolved evidence. Regression would violate the reviewed incremental definition fanout and partial unresolved evidence contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testLaterOverflowResyncQueuesBehindInFlightResyncAndPreservesPreviousCommit root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testLaterOverflowResyncQueuesBehindInFlightResyncAndPreservesPreviousCommit WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_later_overflow_resync_queues_behind_in_flight_resync_and_preserves_previous_commit concurrency_contract root_swiftpm routine 1 Later overflow resync queues behind in flight resync and preserves previous commit. Regression would violate the reviewed later overflow resync queues behind in flight resync and preserves previous commit contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testMixedRootAggregationIsDeterministicAndPreservesSuccessfulTargets root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testMixedRootAggregationIsDeterministicAndPreservesSuccessfulTargets WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_mixed_root_aggregation_is_deterministic_and_preserves_successful_targets behavioral_contract root_swiftpm routine 1 Mixed root aggregation is deterministic and preserves successful targets. Regression would violate the reviewed mixed root aggregation is deterministic and preserves successful targets contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testNonPreemptiveApplyKeepsLastCommitQueryableAndAdvancesUnderChurn root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testNonPreemptiveApplyKeepsLastCommitQueryableAndAdvancesUnderChurn WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_non_preemptive_apply_keeps_last_commit_queryable_and_advances_under_churn concurrency_contract root_swiftpm routine 1 Non preemptive apply keeps last commit queryable and advances under churn. Regression would violate the reviewed non preemptive apply keeps last commit queryable and advances under churn contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testReconciliationDeadlineActivelyRevokesWithoutFailureCallback root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testReconciliationDeadlineActivelyRevokesWithoutFailureCallback WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_reconciliation_deadline_actively_revokes_without_failure_callback concurrency_contract root_swiftpm routine 1 Reconciliation deadline actively revokes without failure callback. Regression would violate the reviewed reconciliation deadline actively revokes without failure callback contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testRootShutdownCooperativelyAbortsLargeCandidateWithoutPreemptingNormalChurn root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testRootShutdownCooperativelyAbortsLargeCandidateWithoutPreemptingNormalChurn WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_root_shutdown_cooperatively_aborts_large_candidate_without_preempting_normal_churn concurrency_contract root_swiftpm routine 1 Root shutdown cooperatively aborts large candidate without preempting normal churn. Regression would violate the reviewed root shutdown cooperatively aborts large candidate without preempting normal churn contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testSameFileIDRenameFencesOnlyRetiredSlotMidDiffAndMidResync root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testSameFileIDRenameFencesOnlyRetiredSlotMidDiffAndMidResync WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_same_file_idrename_fences_only_retired_slot_mid_diff_and_mid_resync concurrency_contract root_swiftpm routine 1 Same file idrename fences only retired slot mid diff and mid resync. Regression would violate the reviewed same file idrename fences only retired slot mid diff and mid resync contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testTraverseLatestIsDeterministicAndTruncatesWithoutCrossingRootSnapshots root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testTraverseLatestIsDeterministicAndTruncatesWithoutCrossingRootSnapshots WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_traverse_latest_is_deterministic_and_truncates_without_crossing_root_snapshots behavioral_contract root_swiftpm routine 1 Traverse latest is deterministic and truncates without crossing root snapshots. Regression would violate the reviewed traverse latest is deterministic and truncates without crossing root snapshots contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests/testWatcherGapCoalescesResyncClearsAndFenceCapRevokes root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapSelectionGraphIncrementalTests.swift RepoPromptTests.WorkspaceCodemapSelectionGraphIncrementalTests testWatcherGapCoalescesResyncClearsAndFenceCapRevokes WorkspaceContext graph_native.workspace_codemap_selection_graph_incremental_tests.test_watcher_gap_coalesces_resync_clears_and_fence_cap_revokes concurrency_contract root_swiftpm routine 1 Watcher gap coalesces resync clears and fence cap revokes. Regression would violate the reviewed watcher gap coalesces resync clears and fence cap revokes contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testValueReceiptRevalidationIsFinalAwaitBeforeSynchronousCommit root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testValueReceiptRevalidationIsFinalAwaitBeforeSynchronousCommit WorkspaceContext graph_native.workspace_files_auto_codemap_mode_tests.test_value_receipt_revalidation_is_final_await_before_synchronous_commit behavioral_contract root_swiftpm routine 1 Value receipt revalidation is final await before synchronous commit. Regression would violate the reviewed value receipt revalidation is final await before synchronous commit contract. test_case retain 0 Phase 5 reviewed live-ID addition for the graph-native codemap cutover. -root/RepoPromptTests.CodeStructureToolCardTests/testUnavailablePathEchoPreservesMachineSummaryContract root Tests/RepoPromptTests/AgentMode/ToolCards/CodeStructureToolCardTests.swift RepoPromptTests.CodeStructureToolCardTests testUnavailablePathEchoPreservesMachineSummaryContract AgentMode code_structure_output.tool_card_machine_summary_contract protocol_contract root_swiftpm routine 1 Unavailable path echo preserves the existing machine summary and failure presentation. A formatter-only response change could accidentally alter the tool-card DTO contract. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testAssemblerMakesSeedNotIndexedRetryableOnlyWhileIndexing root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testAssemblerMakesSeedNotIndexedRetryableOnlyWhileIndexing MCP code_structure_output.seed_not_indexed_retry_contract protocol_contract root_swiftpm routine 1 DTO assembly makes seed_not_indexed retryable while the root index is incomplete. Agents could receive contradictory non-retryable guidance during active indexing. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.MCPCodeStructureWorktreeTests/testUnavailableBuilderEchoesRequestedPathWithoutChangingDTOShape root Tests/RepoPromptTests/MCP/MCPCodeStructureWorktreeTests.swift RepoPromptTests.MCPCodeStructureWorktreeTests testUnavailableBuilderEchoesRequestedPathWithoutChangingDTOShape MCP code_structure_output.path_not_found_echo_contract protocol_contract root_swiftpm routine 1 The unavailable builder echoes the first translated request path through the existing issue path field. A path_not_found reply could remain unactionable or require a DTO schema change. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testGraphOnlyModeRendersAdjacencyAndIsolatedSeeds root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testGraphOnlyModeRendersAdjacencyAndIsolatedSeeds MCP code_structure_output.graph_only_adjacency_contract presentation_contract root_swiftpm routine 1 Graph-only output groups edges by source and preserves isolated seed evidence. Graph-only mode could lose relationship or isolated-node information during compaction. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testPendingAndUnavailableFixturesUseExactSemanticRecovery root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testPendingAndUnavailableFixturesUseExactSemanticRecovery MCP code_structure_output.pending_unavailable_recovery_contract presentation_contract root_swiftpm routine 4 Pending and unavailable fixtures use the exact semantic recovery contract without zero-result noise. Agents could receive internal retry details or ambiguous recovery guidance when no useful result exists. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testUnknownIssueUsesPlainLanguageFallbackWithoutPhaseOrIssueBlock root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testUnknownIssueUsesPlainLanguageFallbackWithoutPhaseOrIssueBlock MCP code_structure_output.unknown_issue_fallback_contract presentation_contract root_swiftpm routine 2 Unknown actionable issues fall back to one plain-language diagnostic without phase or machine-code blocks. Unexpected issues could leak implementation vocabulary or produce unactionable markdown. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testLiveSampleFixturesRecordLineAndByteSavings root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testLiveSampleFixturesRecordLineAndByteSavings MCP code_structure_output.sample_payload_savings_contract presentation_contract root_swiftpm routine 2 Signature-heavy partial and mid-index pending fixtures remain smaller in lines and bytes than the prior formatter shape. Formatter changes could regress the measured payload reduction. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testMultiRootDeclaresEachRootOnceWithoutFreshnessDiagnostics root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testMultiRootDeclaresEachRootOnceWithoutFreshnessDiagnostics MCP code_structure_output.multi_root_declaration_contract presentation_contract root_swiftpm routine 1 Multi-root output declares each logical root once without freshness or indexing diagnostics. Compaction could erase root ownership or repeat long logical prefixes. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testPartialFixtureUsesSingleSemanticConvergenceClause root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testPartialFixtureUsesSingleSemanticConvergenceClause MCP code_structure_output.partial_convergence_contract presentation_contract root_swiftpm routine 1 Useful partial output carries exactly one semantic convergence clause before the actionable body. Formatter drift could reintroduce repeated paths, nodes, or diagnostic noise. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testSelfEdgesAndFreshnessTelemetryRemainInDTOButNotMarkdown root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testSelfEdgesAndFreshnessTelemetryRemainInDTOButNotMarkdown MCP code_structure_output.self_edge_presentation_contract presentation_contract root_swiftpm routine 1 Self edges and freshness telemetry remain machine-readable while staying absent from model-facing markdown. Self references could mislead agents or corrupt machine-readable edge accounting. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testSignatureModeOmitsGraphForTrivialEdgeAndStripsFileHeader root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testSignatureModeOmitsGraphForTrivialEdgeAndStripsFileHeader MCP code_structure_output.signature_dedup_contract presentation_contract root_swiftpm routine 2 Signature mode omits redundant node and trivial graph sections and strips the duplicate File header. Signature replies could triple-list files and repeat their logical path inside fenced content. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testSingleRootPathsRenderRootRelativeAndSharedBaseOnce root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testSingleRootPathsRenderRootRelativeAndSharedBaseOnce MCP code_structure_output.root_base_compaction_contract presentation_contract root_swiftpm routine 1 Single-root output declares the root and profitable shared base once and renders compact paths below them. Long worktree and directory prefixes could dominate code-structure payloads. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testSmallSignatureSizeKeepsSeedAndReportsOmittedRelatedFile root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testSmallSignatureSizeKeepsSeedAndReportsOmittedRelatedFile MCP code_structure_output.small_signature_size_contract presentation_contract root_swiftpm routine 1 Small output size preserves the seed signature and names omitted related files with one semantic recovery action. Size pressure could produce incoherent graph or signature output. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testTruncationEmitsOneActionWithSizeLadder root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testTruncationEmitsOneActionWithSizeLadder MCP code_structure_output.truncation_recovery_contract presentation_contract root_swiftpm routine 3 Truncated output emits exactly one recovery action following the small-to-medium-to-large size ladder. Truncation could preserve cause without actionable semantic-size recovery or duplicate advice. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testAllFormatterFixturesSuppressInternalTelemetryVocabulary root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testAllFormatterFixturesSuppressInternalTelemetryVocabulary MCP code_structure_output.internal_telemetry_absence_contract presentation_contract root_swiftpm routine 1 Every formatter fixture suppresses index counts, retry timing, unresolved names, and internal-reference bookkeeping. Internal indexing telemetry could crowd out useful relationships in normal model-facing replies. test_case retain 0 Compact code-structure output acceptance coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testCompleteFixtureMatchesMinimalGoldenOutput root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testCompleteFixtureMatchesMinimalGoldenOutput MCP code_structure_output.complete_minimal_golden_contract presentation_contract root_swiftpm routine 1 Useful complete output contains counts, root, and body with no Diagnostics section. A complete reply could regress to diagnostic-heavy or status-prefixed model output. test_case retain 0 Supersession 2 minimal model-facing presentation coverage. -root/RepoPromptTests.ToolOutputFormatterCodeStructureTests/testMixedSeedFixtureReportsOnlyTheUncoveredSeedHole root Tests/RepoPromptTests/MCP/ToolOutputFormatterCodeStructureTests.swift RepoPromptTests.ToolOutputFormatterCodeStructureTests testMixedSeedFixtureReportsOnlyTheUncoveredSeedHole MCP code_structure_output.mixed_seed_actionable_hole_contract presentation_contract root_swiftpm routine 1 A mixed useful result reports only the actionable uncovered seed while suppressing internal indexing detail. Partial useful output could duplicate diagnostics or expose transient index bookkeeping. test_case retain 0 Supersession 2 minimal model-facing presentation coverage. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testPartialResultWithPendingSiblingRequiresReadinessRetryAfterPublishing root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testPartialResultWithPendingSiblingRequiresReadinessRetryAfterPublishing WorkspaceContext graph_native.automatic_selection.partial_pending_retry_decision partial_result,pending_sibling,bounded_retry behavioral_contract root_swiftpm fast 1 A partial automatic-selection result with a ready target and pending sibling remains eligible for the bounded readiness retry after publication. Publishing a useful subset could permanently strand its pending sibling. test_case retain 0 Mixed partial automatic-selection retry regression coverage. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testPendingViewModelSelectionRetriesWhenMarkerBecomesReadyWithoutRootStatusChange root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testPendingViewModelSelectionRetriesWhenMarkerBecomesReadyWithoutRootStatusChange WorkspaceContext graph_native.automatic_selection.pending_readiness_lifecycle marker_readiness,bounded_retry,target_only_demand integration_contract root_swiftpm routine 1 CodemapStoreFixture,TestReleaseFence A target demand that exceeds the synchronous policy later enters the automatic codemap projection through one bounded readiness retry without a root availability transition. Pending automatic codemap targets could remain absent forever when root availability does not change. test_case retain 0 Pending automatic-selection retry regression coverage. -root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testMatchingReadyMarkerCoalescesReadinessRetry root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testMatchingReadyMarkerCoalescesReadinessRetry WorkspaceContext graph_native.workspace_files_auto_retry.marker_coalescing marker_readiness,coalescing concurrency_contract root_swiftpm fast 1 WorkspaceFilesAutoCodemapModeTests retry fixture Only a matching ready marker consumes the pending retry; duplicate delivery does not create another generation. Unrelated or duplicate marker events could cause retry storms. test_case retain 0 Pending automatic-selection retry regression coverage. -root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testPendingReadinessRetryAutonomouslySchedulesOnceWithoutReadinessEvents root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testPendingReadinessRetryAutonomouslySchedulesOnceWithoutReadinessEvents WorkspaceContext graph_native.workspace_files_auto_retry.autonomous_bound autonomous_retry,bounded_retry concurrency_contract root_swiftpm fast 1 WorkspaceFilesAutoCodemapModeTests retry fixture A pending generation schedules exactly one autonomous retry without marker or root-status events. Automatic selection could deadlock when readiness settles without UI-visible state churn. test_case retain 0 Pending automatic-selection retry regression coverage. -root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testPendingReadinessRetryCancelsForModeSelectionAndRootChanges root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testPendingReadinessRetryCancelsForModeSelectionAndRootChanges WorkspaceContext graph_native.workspace_files_auto_retry.invalidation mode_change,selection_change,root_change,cancellation concurrency_contract root_swiftpm fast 3 WorkspaceFilesAutoCodemapModeTests retry fixture Mode, selection, and visible-root changes each cancel and clear the pending autonomous retry. Stale retry work could survive ownership changes and publish into a newer UI generation. test_case retain 0 Pending automatic-selection retry regression coverage. -root/RepoPromptTests.WorkspaceFilesAutoCodemapModeTests/testStaleReadyMarkerAfterSelectionGenerationChangeDoesNotPublish root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFilesAutoCodemapModeTests.swift RepoPromptTests.WorkspaceFilesAutoCodemapModeTests testStaleReadyMarkerAfterSelectionGenerationChangeDoesNotPublish WorkspaceContext graph_native.workspace_files_auto_retry.stale_generation generation_safety,marker_readiness concurrency_contract root_swiftpm fast 1 WorkspaceFilesAutoCodemapModeTests retry fixture A ready marker from an invalidated selection generation cannot publish automatic codemap files or advance the current generation. Late marker delivery could repopulate stale automatic targets after selection changes. test_case retain 0 Pending automatic-selection retry regression coverage. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testDefaultCandidateDemandCapRejects1025Targets root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testDefaultCandidateDemandCapRejects1025Targets WorkspaceContext graph_native.automatic_selection.default_target_demand_cap boundary_1024,boundary_1025,target_demand_limit behavioral_contract root_swiftpm fast 2 The default request policy accepts 1,024 candidate demands and reports the existing target-demand budget issue for 1,025. A future policy change could silently remove or shift the reviewed automatic-selection demand boundary. test_case retain 0 PR #621 review follow-up for the automatic-selection target-demand cap. -root/RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests/testCandidateDemandCapStopsBeforeTargetDemandLoop root Tests/RepoPromptTests/WorkspaceContext/CodemapAutomaticSelectionGraphNativeTests.swift RepoPromptTests.CodemapAutomaticSelectionGraphNativeTests testCandidateDemandCapStopsBeforeTargetDemandLoop WorkspaceContext graph_native.automatic_selection.target_demand_cap_ordering pre_demand_guard,target_demand_limit,no_ticket_acquisition integration_contract root_swiftpm routine 1 CodemapStoreFixture An oversized revalidated target set returns the target-demand budget result before acquiring any artifact demand ticket. Automatic selection could enqueue every graph target before its readiness deadline and overwhelm demand admission. test_case retain 0 PR #621 review follow-up for the automatic-selection target-demand cap. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testHistogramBucketAssignmentIsDeterministicAndBounded root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testHistogramBucketAssignmentIsDeterministicAndBounded MCP/Diagnostics mcp.concurrency_evidence.histogram_bucket_bounds boundary_inputs,clamping,overflow,sum,max deterministic_unit root_swiftpm fast 5 Bucket counts, sum, and maximum exactly match boundary, clamped, and overflow inputs. Incorrect buckets would make measured latency distributions unusable. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testHistogramQuantileEstimatesUseBucketUpperBounds root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testHistogramQuantileEstimatesUseBucketUpperBounds MCP/Diagnostics mcp.concurrency_evidence.histogram_quantiles empty,p50,p95,quantile_clamping deterministic_unit root_swiftpm fast 4 Empty and populated histograms return the exact reviewed bucket-upper-bound quantile estimates. Incorrect quantiles could support unsafe capacity decisions. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testHistogramOverflowQuantileFallsBackToObservedMax root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testHistogramOverflowQuantileFallsBackToObservedMax MCP/Diagnostics mcp.concurrency_evidence.histogram_overflow_quantile overflow,observed_max deterministic_unit root_swiftpm fast 1 An overflow-bucket quantile returns the exact observed maximum. Overflow latency could be understated. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testLaneLifecycleTracksWaitingAndHeldHighWater root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testLaneLifecycleTracksWaitingAndHeldHighWater MCP/Diagnostics mcp.concurrency_evidence.lane_gauges waiting,held,abandonment,cancellation_rejection concurrency_contract root_swiftpm fast 5 Lane waiting and held high-water marks, admission counts, abandonment, cancellation rejection, and wait latency remain exact. Misleading lane evidence could drive unsafe concurrency policy. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testGaugesClampAtZeroOnUnpairedReleases root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testGaugesClampAtZeroOnUnpairedReleases MCP/Diagnostics mcp.concurrency_evidence.lane_gauge_clamping unpaired_release,unpaired_abandonment deterministic_unit root_swiftpm fast 2 Unpaired release and abandonment events never drive current gauges below zero. Negative gauges would corrupt evidence snapshots. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testLeaseWaitAndRejectionCounters root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testLeaseWaitAndRejectionCounters MCP/Diagnostics mcp.concurrency_evidence.lease_rejection_counts lease_latency,cancelled,unclassified deterministic_unit root_swiftpm fast 3 Lease latency and typed cancellation and unclassified rejection counts match exact inputs. Rejection causes could be silently misclassified. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testCallCompletionCountsClassifiedToolNamesOnly root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testCallCompletionCountsClassifiedToolNamesOnly MCP/Diagnostics mcp.concurrency_evidence.completion_privacy_bound classified,unclassified,total_histogram behavioral_contract root_swiftpm fast 3 Known tools are counted by canonical name while unknown names are aggregated and total latency is recorded. Private or future tool names could leak through telemetry. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testExecutionTraceEventsFeedExecutionHistogramAndPhaseCounters root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testExecutionTraceEventsFeedExecutionHistogramAndPhaseCounters MCP/Diagnostics mcp.concurrency_evidence.trace_ingestion known_phases,handler_latency,unknown_tool deterministic_unit root_swiftpm fast 4 Trace phases and handler completion latency feed the exact class counters and histogram. Watchdog evidence could diverge from execution traces. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testTracerEmitFeedsSharedRecorder root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testTracerEmitFeedsSharedRecorder MCP/Diagnostics mcp.concurrency_evidence.tracer_wiring shared_recorder,delta deterministic_unit root_swiftpm fast 1 Emitting a tracer event increments the shared recorder phase count by exactly one. Production trace wiring could silently stop feeding evidence. 0.000000 in_memory MCPToolConcurrencyEvidenceRecorder.shared test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testSnapshotIsDeterministicallyOrderedAndResetClearsState root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testSnapshotIsDeterministicallyOrderedAndResetClearsState MCP/Diagnostics mcp.concurrency_evidence.snapshot_determinism ordering,repeatability,reset deterministic_unit root_swiftpm fast 3 Repeated snapshots are equal and class-sorted, and reset clears all bounded state. Snapshots could be nondeterministic or retain stale evidence. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testSnapshotAndResetIsAtomicallyEquivalentToSnapshotThenReset root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testSnapshotAndResetIsAtomicallyEquivalentToSnapshotThenReset MCP/Diagnostics mcp.concurrency_evidence.snapshot_atomic_drain atomic_drain,clear,resume concurrency_contract root_swiftpm fast 3 Atomic snapshot-and-reset returns the pre-reset state, clears it, and accepts subsequent recording. Drain races could lose or duplicate evidence. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testCompletionKeepsTotalHistogramAndPerToolCountsConsistent root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testCompletionKeepsTotalHistogramAndPerToolCountsConsistent MCP/Diagnostics mcp.concurrency_evidence.completion_consistency total_histogram,per_tool_counts deterministic_unit root_swiftpm fast 2 Aggregate total histogram count equals the sum of bounded per-tool completion counts. Atomic completion accounting could split totals from tool counts. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testLeaseWaitTerminationClassifiesOnlyCancellationAsCancelled root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testLeaseWaitTerminationClassifiesOnlyCancellationAsCancelled MCP/Diagnostics mcp.concurrency_evidence.rejection_classification cancellation,generic_failure deterministic_unit root_swiftpm fast 2 Only CancellationError maps to cancelled while other lease errors map to generic failure. Failures could be mislabeled as cancellation. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests/testEvidenceClassMirrorsAdmissionClassification root Tests/RepoPromptTests/MCP/Control/MCPToolConcurrencyEvidenceRecorderTests.swift RepoPromptTests.MCPToolConcurrencyEvidenceRecorderTests testEvidenceClassMirrorsAdmissionClassification MCP/Diagnostics mcp.concurrency_evidence.class_mirror all_classes,nil_unclassified,raw_values deterministic_unit root_swiftpm fast 3 Every admission class preserves its raw value and nil maps to unclassified. Telemetry classes could drift from admission policy. 0.000000 in_memory test_case retain 0 PR #632 reviewed live-ID addition for bounded concurrency evidence telemetry. -root/RepoPromptTests.AgentModeProviderConversationCleanupTests/testRestoredCodexSessionWithoutLiveControllerUsesCleanupRegistry root Tests/RepoPromptTests/AgentMode/AgentModeProviderConversationCleanupTests.swift RepoPromptTests.AgentModeProviderConversationCleanupTests testRestoredCodexSessionWithoutLiveControllerUsesCleanupRegistry AgentMode agent_mode.provider_conversation_cleanup.restored_registry_fallback provider_cleanup,restored_session,no_live_controller,codex_registry main_actor_service_integration root_swiftpm routine 1 PersistedCleanupRecorder A restored inactive Codex session with persisted cleanup metadata and no live controller routes delete cleanup through the provider registry exactly once. Restored tabs could delete local state while leaking the provider conversation because cleanup incorrectly depends on a live controller. actor GlobalSettingsStore test_case retain 0 PR #630 restored-session provider cleanup authority regression. -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testDeleteByRolloutPathResolvesSummaryThenDeletesThread root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testDeleteByRolloutPathResolvesSummaryThenDeletesThread AI/Codex codex_native.conversation_cleanup.rollout_resolution_delete provider_cleanup,codex_app_server,rollout_path,conversation_summary,thread_delete protocol_sequence_regression root_swiftpm routine 1 CleanupRequestRecorder Deleting by rollout path resolves the authoritative conversation ID first, then sends thread/delete with the resolved threadId in exact order. Rollout-only Codex sessions could remain undeleted or issue deletion against an unverified identifier. test_case retain 0 PR #630 Codex rollout-path deletion sequence. -root/RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests/testCleanupCancellationMapsToCancelledOutcome root Tests/RepoPromptTests/AI/CodexNativeSessionControllerConversationCleanupTests.swift RepoPromptTests.CodexNativeSessionControllerConversationCleanupTests testCleanupCancellationMapsToCancelledOutcome AI/Codex codex_native.conversation_cleanup.cancellation_mapping provider_cleanup,codex_app_server,cancellation,cancelled_outcome protocol_error_mapping root_swiftpm routine 1 CleanupRequestRecorder A CancellationError from thread/delete is preserved as a cancelled provider cleanup outcome after one authoritative request. Provider cancellation could be flattened into failure and make batch retry accounting contradict Task cancellation. cancellation test_case retain 0 PR #630 provider cleanup cancellation truthfulness. -root/RepoPromptTests.AgentSessionDataServiceDeletionTests/testDeleteDrainsInFlightSaveAndPreventsFileResurrection root Tests/RepoPromptTests/AgentMode/AgentSessionDataServiceDeletionTests.swift RepoPromptTests.AgentSessionDataServiceDeletionTests testDeleteDrainsInFlightSaveAndPreventsFileResurrection AgentMode agent_session.persistence.delete_save_fence persistence,delete,tombstone,in_flight_save,file_resurrection async_persistence_race root_swiftpm routine 1 SessionWriteGate,temporary_workspace Deletion installs a tombstone while a session write is deterministically suspended, drains that write, discards its result, and leaves no restorable session file. A pending or in-flight save could recreate a durably deleted session file and resurrect deleted user state. filesystem,actor,concurrency temporary_directory test_case+async_task_drain retain 0 PR #630 deterministic save-resurrection regression. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testPersistedSessionLoadFailurePreventsDeletionAndProviderCleanup root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testPersistedSessionLoadFailurePreventsDeletionAndProviderCleanup MCP/Agent agent_manage.cleanup_sessions.persisted_load_failure cleanup_sessions,resolution_failed,persisted_load,no_mutation main_actor_service_integration mcp_agent_control routine 1 CleanupRecorder A persisted-session load failure is reported as resolution_failed, prevents durable deletion and provider cleanup, and remains retryable. A pre-mutation decode or I/O failure could be mislabeled as delete_failed or allow remote cleanup before local durability is known. actor,error_injection WindowStatesManager per_test_window retain 0 PR #630 pre-mutation persisted-load classification. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testPersistedSessionLoadCancellationStopsBeforeMutation root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testPersistedSessionLoadCancellationStopsBeforeMutation MCP/Agent agent_manage.cleanup_sessions.persisted_load_cancellation cleanup_sessions,cancellation,persisted_load,pre_mutation,retry_ids main_actor_service_integration mcp_agent_control routine 1 CleanupRecorder Cancellation during persisted-session load stops before deletion or provider cleanup and returns the current ID as unprocessed and retryable. Swallowed load cancellation could mutate local or provider state after the caller has cancelled. actor,cancellation WindowStatesManager per_test_window retain 0 PR #630 persisted-load cancellation propagation. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testPersistedCleanupDeletesDurablyBeforeProviderCleanup root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testPersistedCleanupDeletesDurablyBeforeProviderCleanup MCP/Agent agent_manage.cleanup_sessions.local_before_remote_ordering cleanup_sessions,persisted_session,durable_delete,provider_cleanup,ordering main_actor_service_integration mcp_agent_control routine 1 CleanupEventRecorder Persisted cleanup loads metadata, commits durable local deletion, and only then invokes provider cleanup in exact event order. Remote cleanup could succeed before a local deletion failure, leaving preserved local state unable to resume its deleted provider conversation. actor,ordering WindowStatesManager per_test_window retain 0 PR #630 local-durability-before-remote-cleanup ordering. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testPersistedDeleteFailureDoesNotRunProviderCleanup root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testPersistedDeleteFailureDoesNotRunProviderCleanup MCP/Agent agent_manage.cleanup_sessions.delete_failure_blocks_remote cleanup_sessions,delete_failed,provider_cleanup,ordering main_actor_service_integration mcp_agent_control routine 1 CleanupEventRecorder A persisted durable deletion failure reports delete_failed, performs no finalization, and never invokes provider cleanup. Remote cleanup could destroy provider resumability even though local session deletion failed and user state remains. actor,error_injection WindowStatesManager per_test_window retain 0 PR #630 preserved-state deletion failure ordering. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testFinalProviderCleanupCancellationKeepsCommittedDeletionOutOfRetryLedger root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testFinalProviderCleanupCancellationKeepsCommittedDeletionOutOfRetryLedger MCP/Agent agent_manage.cleanup_sessions.final_provider_cancellation cleanup_sessions,cancellation,provider_cleanup,durable_delete,no_retry main_actor_service_integration mcp_agent_control routine 1 CleanupRecorder,AgentManageCleanupRecorder Provider cleanup cancellation on the final ID returns cancelled status while retaining the committed ID in deleted_sessions with durable true and no retry IDs. A committed final deletion could be falsely reported as retryable or cancellation could be flattened into partial failure. actor,cancellation WindowStatesManager per_test_window retain 0 PR #630 final-ID cancellation ledger truthfulness. -root/RepoPromptTests.AgentManageMCPToolServiceCleanupTests/testProviderCleanupCancellationStopsLargerBatchAfterCommittedDeletion root Tests/RepoPromptTests/MCP/AgentManageMCPToolServiceCleanupTests.swift RepoPromptTests.AgentManageMCPToolServiceCleanupTests testProviderCleanupCancellationStopsLargerBatchAfterCommittedDeletion MCP/Agent agent_manage.cleanup_sessions.batch_provider_cancellation cleanup_sessions,cancellation,provider_cleanup,durable_delete,unprocessed,retry_ids main_actor_service_integration mcp_agent_control routine 2 CleanupRecorder,AgentManageCleanupRecorder Provider cleanup cancellation preserves the first committed deletion, leaves it out of retry IDs, and returns both later IDs as unprocessed and retryable without further mutation. Batch cancellation could replay an already-deleted ID, omit later IDs, or continue mutating after cancellation. actor,cancellation WindowStatesManager per_test_window retain 0 PR #630 larger-batch provider cancellation accounting. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testActiveToIdleProbeTransitionDoesNotCountAsProgress root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testActiveToIdleProbeTransitionDoesNotCountAsProgress AgentMode codex.app_server.watchdog_probe_transition_no_progress active_snapshot,idle_snapshot,progress_generation,no_model_input async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController An active-to-idle ambiguous probe transition updates only probe classification while preserving the original progress timestamp and generation, running state, and zero model dispatches. Changing ambiguous probe kind could be falsely counted as provider progress and indefinitely postpone recovery. actor,concurrency test_case retain 0 Current-main lifecycle recovery ledger reconciliation. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCompletionDuringActiveReattachReconciliationIsBufferedAndReplayed root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCompletionDuringActiveReattachReconciliationIsBufferedAndReplayed AgentMode codex.app_server.reattach_completion_buffer_replay reattach,reconciliation,turn_completed,buffer,replay async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A completion arriving while post-reattach snapshot reconciliation is suspended remains buffered, then replays after the snapshot gate to complete once without model input, steer, interrupt, or transcript loss. A completion racing reattach reconciliation could be dropped or applied before authority is restored, leaving the run stuck or duplicated. actor,concurrency test_case+continuation_gate retain 0 Current-main active-reattach terminal race regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCompletionDuringActiveReattachReconciliationReplaysWhenSnapshotIsIdle root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCompletionDuringActiveReattachReconciliationReplaysWhenSnapshotIsIdle AgentMode codex.app_server.reattach_completion_idle_snapshot_replay reattach,reconciliation,idle_snapshot,turn_completed,replay async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A completion buffered during reattach reconciliation replays to completed after an idle post-reattach snapshot, with one reattach, no error, and a terminal commit. An idle snapshot could suppress a completion that arrived during reconciliation and strand the local run. actor,concurrency test_case+continuation_gate retain 0 Current-main idle-snapshot reattach terminal replay regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testCompletionDuringActiveReattachReconciliationReplaysWhenSnapshotFails root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testCompletionDuringActiveReattachReconciliationReplaysWhenSnapshotFails AgentMode codex.app_server.reattach_completion_failed_snapshot_replay reattach,reconciliation,snapshot_failure,turn_completed,replay async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController,LivenessSnapshotReadGate A completion buffered during reattach reconciliation replays to completed even when the post-reattach snapshot read fails, with one reattach, no error, and a terminal commit. A transport failure during reconciliation could discard an already-received authoritative completion. actor,concurrency,error_injection test_case+continuation_gate retain 0 Current-main failed-snapshot reattach terminal replay regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testContinuedActiveSilenceAfterReattachDoesNotLoopOrTerminalize root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testContinuedActiveSilenceAfterReattachDoesNotLoopOrTerminalize AgentMode codex.app_server.reattach_single_attempt_active_silence reattach,active_snapshot,silence,no_loop,no_terminal async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController After one active-turn reattach, continued identical active snapshots do not trigger another reattach, model input, interrupt, error, or terminalization. Recovery could loop controller replacement or destructively terminalize a provider turn that remains active after reattach. actor,concurrency test_case+controller_shutdown retain 0 Added as testFailedActiveFollowUpIsNotRepeatedOrTerminal, then renamed to the current reattach authority contract. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testPersistentProbeFailureRecoversOnceThenFailsClearly root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testPersistentProbeFailureRecoversOnceThenFailsClearly AgentMode codex.app_server.persistent_probe_failure_bounded_recovery probe_failure,reattach,single_recovery,failed_terminal async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController Persistent snapshot failures cause one bounded controller recovery, then one clear failed terminal outcome with no turn interrupt. Repeated transport failures could loop recovery forever, silently remain active, or emit duplicate failures. actor,concurrency,error_injection test_case+controller_shutdown retain 0 Current-main persistent probe failure recovery regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testRepeatedNoActiveSnapshotReattachesAndReconcilesFailure root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testRepeatedNoActiveSnapshotReattachesAndReconcilesFailure AgentMode codex.app_server.watchdog_no_active_reattach_failure no_active_snapshot,reattach,latest_turn_status,failed_terminal async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController Repeated no-active snapshots trigger one reattach and reconcile the provider latest-turn failure into one exact local error without model input or interrupt. A missed provider failure could leave the run stuck, trigger duplicate work, or be mislabeled after reconnect. actor,concurrency test_case+controller_shutdown retain 0 Current-main no-active failure reconciliation regression. -root/RepoPromptTests.CodexAgentModeCoordinatorLivenessTests/testRepeatedNoActiveSnapshotWithoutTerminalStatusReturnsControlWithoutModelInput root Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift RepoPromptTests.CodexAgentModeCoordinatorLivenessTests testRepeatedNoActiveSnapshotWithoutTerminalStatusReturnsControlWithoutModelInput AgentMode codex.app_server.watchdog_no_active_reattach_return_control no_active_snapshot,reattach,no_terminal_status,cancelled,no_model_input async_concurrency_lifecycle root_swiftpm integration 1 LivenessFakeCodexController When reattach finds no active turn or terminal status, the run returns control as cancelled with a continuation system note and no model input, interrupt, or error. Ambiguous provider state could silently dispatch duplicate model input or leave the UI permanently running. actor,concurrency test_case+controller_shutdown retain 0 Added as testSecondIdleAfterAutomaticContinuationFailsClearly, then renamed to the current no-model-input contract. -root/RepoPromptTests.ModelPickerStringOrderingTests/testClaudeCodePickerExposesOpus5WithOfficialEffortsAndStableOrdering root Tests/RepoPromptTests/AI/ModelPickerStringOrderingTests.swift RepoPromptTests.ModelPickerStringOrderingTests testClaudeCodePickerExposesOpus5WithOfficialEffortsAndStableOrdering AI/Models ai_model.claude_opus_5_picker_contract claude_code,opus_5,effort_variants,menu_ordering,defaults,cli_resolution model_catalog_contract root_swiftpm routine 1 The Claude Code picker exposes Opus 5 with low through max official efforts in stable family order, rejects ultra, preserves high defaults, and resolves effort-encoded CLI selections. Opus 5 could be absent, misordered, expose unsupported effort levels, or map picker/default selections to the wrong CLI request. test_case retain 0 Current-main Opus 5 model catalog coverage. -root/RepoPromptTests.ModelPickerStringOrderingTests/testClaudeOpusRecommendationCopyTracksStableAlias root Tests/RepoPromptTests/AI/ModelPickerStringOrderingTests.swift RepoPromptTests.ModelPickerStringOrderingTests testClaudeOpusRecommendationCopyTracksStableAlias AI/Models ai_model.claude_opus_stable_alias_copy claude_code,opus,stable_alias,recommendation_copy presentation_contract root_swiftpm routine 1 Recommendation copy names the stable Claude Code Opus alias as Opus 5 on the Anthropic API, removes the old Opus 4.6 wording, and retains the runtime specifier opus. Stale recommendation text or raw model binding could misrepresent the configured Claude Code runtime selection. test_case retain 0 Current-main Opus 5 recommendation copy coverage. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testHandoffPromptExplicitEmptyMatchesLegacyPromptByteForByte root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testHandoffPromptExplicitEmptyMatchesLegacyPromptByteForByte AgentMode agent_mode.handoff_prompt.empty_compatibility handoff,prompt,empty,debug_cli,release_cli presentation_contract root_swiftpm routine 2 Explicit empty instructions produce the exact legacy Handoff prompt for both debug and release CLI identities. An empty saved default could alter established Handoff prompt bytes or routing instructions. test_case retain 0 Work item 1 exact-empty compatibility contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testHandoffPromptAppendsInstructionsVerbatim root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testHandoffPromptAppendsInstructionsVerbatim AgentMode agent_mode.handoff_prompt.verbatim_append handoff,prompt,whitespace,verbatim presentation_contract root_swiftpm routine 1 Nonempty instructions append after the exact delimiter and preserve leading, internal, and trailing whitespace without a synthetic newline. Prompt rendering could normalize user text or corrupt the compatibility prompt boundary. test_case retain 0 Work item 1 verbatim rendering contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testHandoffPromptTreatsWhitespaceOnlyInstructionsAsNonEmpty root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testHandoffPromptTreatsWhitespaceOnlyInstructionsAsNonEmpty AgentMode agent_mode.handoff_prompt.whitespace_nonempty handoff,prompt,whitespace_only presentation_contract root_swiftpm routine 1 Whitespace-only instructions render an Additional instructions section and remain byte-exact. Trimming could silently discard an intentional whitespace-only configured value. test_case retain 0 Work item 1 exact-isEmpty branch contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testHandoffInstructionsPolicyAcceptsTwentyThousandAndRejectsTwentyThousandOne root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testHandoffInstructionsPolicyAcceptsTwentyThousandAndRejectsTwentyThousandOne AgentMode agent_mode.handoff_instructions.character_limit handoff,policy,character_count,grapheme,boundary deterministic_policy root_swiftpm routine 4 The shared policy counts Swift Characters, accepts empty and 20,000, and rejects 20,001 while treating a multi-scalar grapheme as one. Scalar counting or an off-by-one error could reject valid defaults or accept unsupported oversized instructions. test_case retain 0 Work item 1 shared validation boundary contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsDefaultsEmptyWithoutMaterializing root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsDefaultsEmptyWithoutMaterializing Settings settings.agent_mode.handoff_instructions.absent_default optional_scalar,empty_default,no_write persistence_regression root_swiftpm routine 1 An absent Handoff instruction scalar reads as empty while remaining nil and leaving settings bytes unchanged. A read could materialize a default field or unexpectedly rewrite user settings. test_case retain 0 Work item 1 absent-value persistence contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsSavesAndReloadsVerbatim root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsSavesAndReloadsVerbatim Settings settings.agent_mode.handoff_instructions.verbatim_roundtrip optional_scalar,whitespace,reload persistence_regression root_swiftpm routine 1 Leading and trailing whitespace plus blank lines survive save and reconstruction of the file-backed settings store. Persistence could normalize or lose reusable Handoff instructions across launch. test_case retain 0 Work item 1 verbatim persistence contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsClearRemovesOptionalField root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsClearRemovesOptionalField Settings settings.agent_mode.handoff_instructions.clear_nil optional_scalar,clear,nil persistence_regression root_swiftpm routine 1 Setting exact empty clears a previously saved instruction value to nil and restores the empty getter result. Clearing could persist an empty string or leave a stale default active. test_case retain 0 Work item 1 clear-to-nil persistence contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsNoOpClearDoesNotRewriteFile root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsNoOpClearDoesNotRewriteFile Settings settings.agent_mode.handoff_instructions.noop_clear optional_scalar,no_op,no_write persistence_regression root_swiftpm routine 1 Clearing an already absent instruction value succeeds without changing settings bytes. A no-op clear could cause unnecessary publication or file writes. test_case retain 0 Work item 1 no-op persistence contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsPreservesAgentModeSiblings root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsPreservesAgentModeSiblings Settings settings.agent_mode.handoff_instructions.sibling_preservation optional_scalar,agent_mode,siblings,set,clear persistence_regression root_swiftpm routine 2 Setting and clearing Handoff instructions preserve every seeded sibling Agent Mode scalar. A narrow setting mutation could erase unrelated Agent Mode preferences. test_case retain 0 Work item 1 sibling-preserving mutation contract. -root/RepoPromptTests.SettingsJSONOnlyPersistenceTests/testAgentSessionHandoffInstructionsSetterEnforcesCharacterLimitWithoutMutation root Tests/RepoPromptTests/SettingsJSONOnlyPersistenceTests.swift RepoPromptTests.SettingsJSONOnlyPersistenceTests testAgentSessionHandoffInstructionsSetterEnforcesCharacterLimitWithoutMutation Settings settings.agent_mode.handoff_instructions.setter_limit optional_scalar,character_limit,rejection,no_mutation persistence_regression root_swiftpm routine 2 The typed setter persists and reloads 20,000 Characters, then rejects 20,001 without changing memory or file bytes. An oversized write could replace a valid saved default or bypass the shared policy. test_case retain 0 Work item 1 defensive persistence boundary contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testQuickHandoffUsesCurrentStoredDefault root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testQuickHandoffUsesCurrentStoredDefault AgentMode agent_mode.handoff.quick_invocation_default quick_handoff,invocation_time,stored_default,build_cli,clipboard presentation_contract root_swiftpm routine 1 AgentChatTitlebarSafetyFixture Quick Handoff resolves the provider at invocation and copies one prompt containing the newest default and authoritative build-aware CLI identity. Capturing the default when the menu opens could copy stale instructions or drift from the current settings authority. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Work item 2 invocation-time quick-copy contract. -root/RepoPromptTests.AgentChatTitlebarSafetyTests/testQuickHandoffReportsOversizedStoredInstructionsWithoutCopying root Tests/RepoPromptTests/App/AgentChatTitlebarSafetyTests.swift RepoPromptTests.AgentChatTitlebarSafetyTests testQuickHandoffReportsOversizedStoredInstructionsWithoutCopying AgentMode agent_mode.handoff.quick_oversized_feedback quick_handoff,oversized_default,explicit_feedback,no_fallback,no_clipboard presentation_contract root_swiftpm routine 1 AgentChatTitlebarSafetyFixture An oversized stored default reports its exact count and limit once while suppressing rendering and clipboard mutation. A persistent invalid default could silently no-op or fall back to a prompt that omits the user's configured safety instructions. temp_directory WindowStatesManager;GlobalSettingsStore test_case retain 0 Work item 2 bounded invalid-default feedback contract. -root/RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests/testHandoffInstructionsRemainOutsideAppSettingsCatalog root Tests/RepoPromptTests/MCP/AppSettingsMCPServiceAgentModeSettingsTests.swift RepoPromptTests.AppSettingsMCPServiceAgentModeSettingsTests testHandoffInstructionsRemainOutsideAppSettingsCatalog AgentMode agent_mode.handoff_instructions.app_settings_boundary catalog_list,unknown_get,unknown_set,no_mutation protocol_negative root_swiftpm routine 3 GlobalSettingsStore,AppSettingsMCPService The Agent Mode catalog contains no Handoff key, and candidate get/set requests retain the exact unknown-key rejection while durable state remains empty. A local-only reusable instruction could accidentally expand the public MCP settings allowlist or become remotely mutable. filesystem,user_defaults test_case retain 0 Work item 3 negative app_settings catalog boundary. -root/RepoPromptTests.CodemapGraphStatusDebugDiagnosticsTests/testOperationAttachesToCurrentWindowWorkspaceWithoutArm root Tests/RepoPromptTests/Diagnostics/CodemapGraphStatusDebugDiagnosticsTests.swift RepoPromptTests.CodemapGraphStatusDebugDiagnosticsTests testOperationAttachesToCurrentWindowWorkspaceWithoutArm Diagnostics/CodeMap codemap.graph_status.current_workspace_attach debug_mcp,current_window,no_arm,no_workspace_switch,stable_schema diagnostic_contract root_swiftpm routine 1 WindowState,WorkspaceFileContextStore The hidden DEBUG operation resolves the requested current window and returns schema version 1 with roots, totals, and event-page fields without arming or switching a diagnostic harness. Diagnostics could require disruptive harness setup or report a workspace other than the currently attached window. actor,debug_only window_registry,global_settings test_case+window_teardown retain 0 Patch 1 attachable live graph diagnostics current-workspace contract. -root/RepoPromptTests.CodemapGraphStatusDebugDiagnosticsTests/testOperationRejectsInvalidRootAndEventCursorParameters root Tests/RepoPromptTests/Diagnostics/CodemapGraphStatusDebugDiagnosticsTests.swift RepoPromptTests.CodemapGraphStatusDebugDiagnosticsTests testOperationRejectsInvalidRootAndEventCursorParameters Diagnostics/CodeMap codemap.graph_status.parameter_validation invalid_root_id,negative_cursor,zero_limit,stable_error diagnostic_contract root_swiftpm routine 3 WindowState Malformed root IDs, negative event cursors, and an out-of-range event limit each return the stable invalid_params diagnostic error. Invalid paging or root selectors could be silently coerced and make an attached diagnosis ambiguous. actor,debug_only window_registry,global_settings test_case+window_teardown retain 0 Patch 1 DEBUG MCP parameter boundary coverage. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testCompletedRetainedWorkerExposesMonotonicLifecycleAndReasonedEvents root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testCompletedRetainedWorkerExposesMonotonicLifecycleAndReasonedEvents WorkspaceContext/CodeMap codemap.graph_index.authoritative_lifecycle_observability monotonic_uptime,phase,page,checkpoint,projection,worker_finished,retained_worker,reason_enum diagnostic_contract root_swiftpm routine 1 ReviewGitRepositoryFixture,GraphObservabilityTestClock,WorkspaceCodemapBindingEngine A completed graph-index job retains authoritative ordered lifecycle timestamps, projection and checkpoint state, reports no live worker, and emits monotonic reasoned DEBUG events. A retained job with a nil worker could be indistinguishable from active work or lose the phase boundary that explains a stall. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Patch 1 engine lifecycle and dead-retained-worker observability. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testManifestFailureClassifierUsesBoundedPrivacySafeReasonTags root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testManifestFailureClassifierUsesBoundedPrivacySafeReasonTags WorkspaceContext/CodeMap codemap.manifest.failure_reason_classification stale_authority,writer_authority,quota,model_failure,security,io,cancellation,operation_allowlist diagnostic_contract root_swiftpm routine 13 WorkspaceCodemapManifestFailureClassifier Typed manifest store and model failures map to bounded stable reason tags, I/O operations retain only safe bounded identifiers, cancellation remains distinct, and unsupported failures fall back to other. An attached diagnosis could expose a path-bearing operation, collapse actionable permanent failures into one opaque count, or grow an unbounded reason vocabulary. debug_only,error_injection table_driven retain 0 DEBUG-only manifest writer failure taxonomy and privacy boundary. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testDeadRetainedGraphWorkerReschedulesFromSameCheckpoint root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testDeadRetainedGraphWorkerReschedulesFromSameCheckpoint WorkspaceContext/CodeMap codemap.graph_index.dead_worker_reschedule retained_job,nil_task,checkpoint,restart,recovery_count async_concurrency_lifecycle root_swiftpm routine 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine Scheduling a current nonterminal retained job with no worker restarts the same job from its checkpoint and increments bounded recovery accounting. A silently dead retained job could return handed-off forever while no worker exists. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Phase B dead-worker reschedule regression. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testGraphIndexStaleManifestLoadLiftsAuthorityBeforeRecordsAreMinted root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testGraphIndexStaleManifestLoadLiftsAuthorityBeforeRecordsAreMinted WorkspaceContext/CodeMap codemap.manifest.graph_index_stale_authority_lift stale_authority,generation_lift,graph_index,record_minting persistence_integration root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore A validated stale graph-index manifest lifts a virgin pipeline authority before new graph records are minted. New records could be minted under an authority already rejected by durable state. git_subprocess,filesystem,actor,error_injection temporary_directory test_case+fixture_cleanup retain 0 Authority-lift seam retained for Phase B compatibility. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testGraphIndexManifestPersistenceOccursOnceAtEnumerationSeal root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testGraphIndexManifestPersistenceOccursOnceAtEnumerationSeal WorkspaceContext/CodeMap codemap.manifest.graph_index_single_seal_persistence multi_page,namespace_load,page_no_submit,page_no_wait,page_no_write,seal_commit,snapshot_volume performance_contract root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore A multi-page graph-index coverage loads its manifest namespace once, performs no page-loop submissions, waits, or writes, and persists the coalesced last-writer-wins snapshot once at enumeration seal. Per-page full-manifest decode, sort, encode, and fsync could restore aggregate quadratic work or graph readiness could become durability-gated again. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 P1a/P1b seal-time persistence complexity regression. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testNoProgressWatchdogRecoveryIsBounded root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testNoProgressWatchdogRecoveryIsBounded WorkspaceContext/CodeMap codemap.graph_index.watchdog_bounded_recovery no_progress,monotonic_uptime,restart,recovery_cap,stalled_reason async_concurrency_lifecycle root_swiftpm routine 3 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine Deterministic no-progress evaluation restarts a dead worker only up to the configured cap, then records watchdog exhaustion without another worker. A watchdog could loop recovery forever or leave exhaustion anonymous. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Phase B bounded watchdog regression. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testObservedFutureAuthorityFailureTerminallyDiscardsWithoutRetry root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testObservedFutureAuthorityFailureTerminallyDiscardsWithoutRetry WorkspaceContext/CodeMap codemap.manifest.future_authority_terminal_fast stale_authority,generation_pair,terminal_discard,no_retry,event_ring,last_failure diagnostic_contract root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore,GraphObservabilityTestClock A typed observed-stale authority at or beyond the current generation records bounded generation diagnostics and terminally discards after one attempt with no deferred retry. A permanent stale-authority conflict could consume repeated long store attempts while hiding the conflicting generations. git_subprocess,filesystem,actor,debug_only,error_injection temporary_directory test_case+fixture_cleanup retain 0 Renamed terminal-fast authority diagnostic contract. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testPrioritizeNowClearsBackoffRestartsDeadWorkerAndPromotesWithoutCatalogRead root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testPrioritizeNowClearsBackoffRestartsDeadWorkerAndPromotesWithoutCatalogRead WorkspaceContext/CodeMap codemap.graph_index.prioritize_now_o1 prioritize,retry_clear,dead_worker,restart,queue_promotion,no_scan async_concurrency_lifecycle root_swiftpm routine 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,GraphCatalogReadCounter Prioritize-now clears retry state, restarts a dead worker, and marks queue promotion without reading the graph catalog synchronously. A user priority command could scan on the caller actor or fail to revive the worker. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Phase B O(1) backend prioritize contract. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testSupersededWorkerExitRecordsReasonInsteadOfSilentRetainedState root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testSupersededWorkerExitRecordsReasonInsteadOfSilentRetainedState WorkspaceContext/CodeMap codemap.graph_index.reasoned_superseded_exit superseded,worker_exit,completion_reason,event_ring async_concurrency_lifecycle root_swiftpm routine 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine A superseded worker funnels through completion, clears the worker, and records a privacy-safe superseded reason in retained state and DEBUG events. A currentness exit could silently leave an unstamped retained job. git_subprocess,filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Phase B reasoned worker-exit regression. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testVirginManifestAuthorityLiftAdvancesGenerationSevenToEight root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testVirginManifestAuthorityLiftAdvancesGenerationSevenToEight WorkspaceContext/CodeMap codemap.manifest.virgin_authority_lift_seven_to_eight stale_authority,generation_lift,virgin_pipeline,idempotence persistence_integration root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore A virgin manifest pipeline observing generation seven rebuilds current authority at generation eight while retaining current authority identity strings. Incorrect authority reconstruction could skip a durable predecessor or mutate unrelated authority identity. git_subprocess,filesystem,actor,error_injection temporary_directory test_case+fixture_cleanup retain 0 Authority-lift coverage; observed-predecessor assertion remains under Phase B follow-up. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testVirginManifestAuthorityLiftAdvancesSameGenerationPredecessorOnce root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testVirginManifestAuthorityLiftAdvancesSameGenerationPredecessorOnce WorkspaceContext/CodeMap codemap.manifest.virgin_authority_lift_one_to_two stale_authority,generation_lift,virgin_pipeline,idempotence persistence_integration root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore A virgin manifest pipeline observing generation one lifts current authority to generation two once and remains stable on a second demand. A process-local reset could loop forever against an equal durable authority generation. git_subprocess,filesystem,actor,error_injection temporary_directory test_case+fixture_cleanup retain 0 Authority-lift coverage; observed-predecessor assertion remains under Phase B follow-up. -root/RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests/testWarmManifestHitDoesNotLiftAuthority root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapBindingEngineObservabilityTests.swift RepoPromptTests.WorkspaceCodemapBindingEngineObservabilityTests testWarmManifestHitDoesNotLiftAuthority WorkspaceContext/CodeMap codemap.manifest.warm_hit_no_authority_lift manifest_hit,authority_stability,warm_path,no_lift persistence_integration root_swiftpm integration 1 ReviewGitRepositoryFixture,WorkspaceCodemapBindingEngine,CodeMapRootManifestStore A warm current-authority manifest hit preserves the existing authority generation and identity. Authority liveness repair could unnecessarily churn valid warm-cache authority. git_subprocess,filesystem,actor temporary_directory test_case+fixture_cleanup retain 0 Warm-path authority stability regression. -root/RepoPromptTests.WorkspaceCodemapGraphIndexDebugEventRingTests/testRingBoundsOverwriteAndPagesByExclusiveOrdinal root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphIndexDebugEventRingTests.swift RepoPromptTests.WorkspaceCodemapGraphIndexDebugEventRingTests testRingBoundsOverwriteAndPagesByExclusiveOrdinal WorkspaceContext/CodeMap codemap.graph_index.debug_ring_bounded_pagination capacity,oldest_overwrite,exclusive_cursor,bounded_page diagnostic_contract root_swiftpm routine 2 WorkspaceCodemapGraphIndexDebugEventRing The DEBUG event ring overwrites only the oldest entry at capacity and pages later events by an exclusive ordinal with a bounded limit. An unbounded or unstable event history could add debug-memory pressure or make incremental diagnosis skip or repeat transitions. actor,debug_only test_case retain 0 Patch 1 bounded ring and cursor pagination coverage. -root/RepoPromptTests.WorkspaceCodemapGraphIndexDebugEventRingTests/testRingCoalescesEligibleEventsAndPreservesReasonBoundaries root Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGraphIndexDebugEventRingTests.swift RepoPromptTests.WorkspaceCodemapGraphIndexDebugEventRingTests testRingCoalescesEligibleEventsAndPreservesReasonBoundaries WorkspaceContext/CodeMap codemap.graph_index.debug_ring_coalescing coalescing,reason_boundary,ordinal,exclusive_cursor,meaningful_transition diagnostic_contract root_swiftpm routine 3 WorkspaceCodemapGraphIndexDebugEventRing Adjacent eligible events with the same identity and reason coalesce with a fresh observable ordinal while a reason change remains a separate ordered transition. Over-aggressive coalescing could erase the cause of a phase change, while absent coalescing could flood the ring. actor,debug_only test_case retain 0 Patch 1 DEBUG event coalescing and reason preservation. -root/RepoPromptTests.WorkspaceFileContextStoreGraphObservabilityTests/testCurrentStoreSnapshotExposesRetryExhaustionWithoutArmOrWorkspaceSwitch root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreGraphObservabilityTests.swift RepoPromptTests.WorkspaceFileContextStoreGraphObservabilityTests testCurrentStoreSnapshotExposesRetryExhaustionWithoutArmOrWorkspaceSwitch WorkspaceContext/CodeMap codemap.graph_index.store_retry_exhaustion_observability current_store,retry_exhausted,launch_timestamps,task_nil,event_paging,no_arm diagnostic_contract root_swiftpm routine 2 WorkspaceFileContextStore,GraphStoreObservabilityTestClock The current store snapshot exposes monotonic launch state, an explicit exhausted retry marker with no retained task, and a pageable retryExhausted event without diagnostic arming or workspace switching. A parked retry-exhausted root could silently appear idle and leave attached diagnostics unable to name the terminal retry condition. actor,debug_only test_case retain 0 Patch 1 store launch and retry-exhaustion observability. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testThreadSnapshotPreservesLatestTerminalTurnIdentity root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testThreadSnapshotPreservesLatestTerminalTurnIdentity AI codex.thread_snapshot.terminal_turn_identity thread_read,turn_id,terminal_status,structured_failure protocol_contract root_swiftpm routine 1 Thread snapshot parsing pairs the latest terminal status and structured failure details with that terminal turn identifier. A stale terminal status could settle the wrong active provider turn, or persisted failure diagnostics could be discarded. 0.010000 test_case retain 0 Issue #170 exact-turn Context Builder settlement regression. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testMissingCanonicalCompletionReconcilesFromMatchingPersistedTurn root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testMissingCanonicalCompletionReconcilesFromMatchingPersistedTurn AI codex.provider.missed_completion_reconciliation assistant_completed,thread_read,turn_id,message_stop lifecycle_regression root_swiftpm routine 1 A matching persisted completed turn settles a stream exactly once after canonical turn completion is missed. Context Builder could persist a complete response but wait until its long inactivity ceiling. 0.010000 test_case retain 0 Issue #170 completed-provider settlement regression. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testMissingFailedCompletionReconcilesFromMatchingSystemErrorSnapshot root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testMissingFailedCompletionReconcilesFromMatchingSystemErrorSnapshot AI codex.provider.missed_failure_reconciliation assistant_completed,thread_read,turn_id,system_error,structured_failure lifecycle_regression root_swiftpm routine 1 A matching persisted failed turn in system-error runtime state settles with its authoritative persisted failure message. Failed provider turns could remain hung because system-error was rejected as terminal, or settle with a generic error that discards the persisted cause. 0.010000 test_case retain 0 Issue #170 failed-provider settlement regression. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testPersistedTerminalForDifferentTurnDoesNotSettleCurrentStream root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testPersistedTerminalForDifferentTurnDoesNotSettleCurrentStream AI codex.provider.terminal_turn_correlation thread_read,stale_turn,turn_id,negative_contract protocol_negative root_swiftpm routine 1 A terminal snapshot for a different turn cannot settle the current stream. A stale completed turn could truncate or falsely complete current Context Builder output. 0.010000 test_case retain 0 Issue #170 stale-turn negative contract. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testSnapshotReconciliationDoesNotProbeBeforeAssistantCompletion root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testSnapshotReconciliationDoesNotProbeBeforeAssistantCompletion AI codex.provider.reconciliation_candidate_gate assistant_completed,thread_read,probe_gate protocol_negative root_swiftpm routine 1 Terminal snapshot probing remains disabled until an assistant completion candidate exists. Polling every active turn could add load or race ordinary provider lifecycle events. 0.010000 test_case retain 0 Issue #170 reconciliation eligibility guard. -root/RepoPromptTests.CodexCLIProviderReconciliationTests/testMatchingTerminalSnapshotWithActiveTurnDoesNotSettleCurrentStream root Tests/RepoPromptTests/AI/CodexCLIProviderReconciliationTests.swift RepoPromptTests.CodexCLIProviderReconciliationTests testMatchingTerminalSnapshotWithActiveTurnDoesNotSettleCurrentStream AI codex.provider.active_turn_settlement_guard thread_read,active_turn,turn_id,negative_contract protocol_negative root_swiftpm routine 1 Even a matching historical terminal record cannot settle while the snapshot reports an active turn. Concurrent or successor work could be truncated by stale terminal snapshot reconciliation. 0.010000 test_case retain 0 Issue #170 active-turn negative contract. -root/RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests/testLateTerminalInteractionDoesNotReopenCompletedCanonicalCommand root Tests/RepoPromptTests/AgentMode/Codex/CodexNativeSessionControllerEventRecoveryTests.swift RepoPromptTests.CodexNativeSessionControllerEventRecoveryTests testLateTerminalInteractionDoesNotReopenCompletedCanonicalCommand AgentMode codex.command_execution.late_interaction_ordering item_completed,terminal_interaction,turn_id,canonical_events lifecycle_regression root_swiftpm routine 1 A late same-item terminal interaction after canonical completion emits no new running command update. Pinned Codex .145 event ordering could resurrect a completed terminal card. 0.010000 test_case retain 0 Issue #170 terminal-card settlement; validated against rust-v0.145.0 and upstream fix 9fc715c086. -root/RepoPromptTests.MCPMutationRetryableFailureTests/testDurableFileActionDoesNotReenterStoreForPostMutationIngress root Tests/RepoPromptTests/MCP/MCPMutationRetryableFailureTests.swift RepoPromptTests.MCPMutationRetryableFailureTests testDurableFileActionDoesNotReenterStoreForPostMutationIngress MCP mcp.file_actions.post_mutation_settlement durable_mutation,catalog_commit,context_builder,actor_contention structural_source_guard root_swiftpm routine 1 After durable workspace mutation the handler constructs its acknowledgement without a second ingress wait. A completed delete could block behind Context Builder and time out as cancelled after moving the file. 0.010000 test_case retain 0 Issue #170 durable file_actions settlement invariant. -root/RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests/testUncooperativeFileActionPreMutationWorkDetachesWithoutClosingTransport root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionWatchdogIntegrationTests.swift RepoPromptTests.MCPToolExecutionWatchdogIntegrationTests testUncooperativeFileActionPreMutationWorkDetachesWithoutClosingTransport MCP mcp.file_actions.watchdog_detach file_actions,watchdog,detach,transport,premutation lifecycle_regression root_swiftpm routine 1 Uncooperative pre-mutation file_actions work detaches after grace without closing the persistent transport. A blocked mutation provider could still strand sibling calls by force-closing the connection. 0.010000 test_case retain 0 Issue #170 file_actions detach-and-settle regression. -root/RepoPromptTests.WorkspaceFileContextStoreTests/testMutationCompletionBeforeWaiterRegistrationSettlesWithoutLostWakeup root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testMutationCompletionBeforeWaiterRegistrationSettlesWithoutLostWakeup WorkspaceContext filesystem.mutation_waiter.completion_mailbox uncancellable_mutation,lost_wakeup,trash,completion_mailbox,settlement async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStore,FileSystemService A trash mutation that reconciles before waiter registration stores its terminal result, then settles successfully with no retained waiter or completion. A durable file mutation could complete on disk while its dropped wakeup strands file_actions until the execution contract cancels it. 0.010000 filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Issue #170 durable delete settlement regression reproduced from the live debug app. -root/RepoPromptTests.WorkspaceFileContextStoreTests/testTrashSettlesFromDurableAbsenceBeforeFinderCallReturns root Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift RepoPromptTests.WorkspaceFileContextStoreTests testTrashSettlesFromDurableAbsenceBeforeFinderCallReturns WorkspaceContext filesystem.trash.durable_postcondition_settlement trash,foundation_tail_latency,durable_absence,settlement,catalog_reconciliation async_concurrency_lifecycle root_swiftpm routine 1 WorkspaceFileContextStore,FileSystemService A trash mutation settles and reconciles its catalog from durable source-path absence while the injected Finder tail remains blocked. macOS FileManager.trashItem can remove the source immediately but block beyond the MCP deadline, causing a false cancellation after the durable effect. 0.010000 filesystem,actor,debug_only temporary_directory test_case+fixture_cleanup retain 0 Issue #170 live delete reproduced independently with a 35.27-second Foundation Trash tail. -root/RepoPromptTests.ProcessLauncherDescriptorInheritanceTests/testSpawnedChildDoesNotInheritBlockedSIGCHLDMask root Tests/RepoPromptTests/MCP/Control/ProcessLauncherDescriptorInheritanceTests.swift RepoPromptTests.ProcessLauncherDescriptorInheritanceTests testSpawnedChildDoesNotInheritBlockedSIGCHLDMask MCP process.launcher.child_signal_mask posix_spawn,sigchld,signal_mask,codex,process_exit process_lifecycle_regression root_swiftpm routine 1 ProcessLauncher A child launched from a thread with SIGCHLD blocked starts with an explicit empty signal mask and exits normally. A Codex app-server could inherit a GCD worker's blocked SIGCHLD and leave completed unified-exec commands permanently running. 0.010000 subprocess,signal_mask,debug_only test_case+process_cleanup retain 0 Issue #170 terminal settlement launch-boundary regression validated against pinned Codex 0.145.0. -root/RepoPromptTests.MCPToolExecutionContractTests/testFileActionsDeleteUsesFinderTrashDeadline root Tests/RepoPromptTests/MCP/Control/MCPToolExecutionContractTests.swift RepoPromptTests.MCPToolExecutionContractTests testFileActionsDeleteUsesFinderTrashDeadline MCP mcp.file_actions.trash_execution_contract file_actions,delete,trash,deadline,detach_and_settle protocol_contract root_swiftpm routine 1 Delete arguments select the 60-second Finder Trash deadline while create retains the ordinary bounded contract. A system Trash tail longer than 30 seconds could falsely cancel an already-applied destructive mutation. 0.010000 test_case retain 0 Issue #170 live delete contract validated against an independently reproduced 35.27-second Foundation tail. -root/RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests/testCanonicalCatalogActionsPoliciesAndDependenciesMatchFrozenManifest root Tests/RepoPromptTests/MCP/Control/HeadlessMCPDomainRuntimeM0ContractTests.swift RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests testCanonicalCatalogActionsPoliciesAndDependenciesMatchFrozenManifest MCP/HeadlessRuntime headless_runtime.m0.catalog_policy_dependency_freeze tool_catalog,actions,schemas,admission,execution,advertisement,dependencies contract_inventory root_swiftpm routine 4 headless_mcp_domain_runtime_m0_contract The live 27-tool catalog, 86 discriminated actions, 12 actionless required-property contracts, per-tool default/typed-error sources, normalized policy/capability advertisement projections, and all 84 window-tool dependencies equal the reviewed M0 manifest. Catalog or dependency drift could enter later runtime migrations without explicit parity accounting. direct_in_process;window_state GlobalSettingsStore.mcpAutoStart test_case+window_teardown retain 0 M0 contract-freeze guard; four consolidated catalog/default-policy/dependency scenarios. -root/RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests/testEveryExecutableEvidenceCitationResolvesInCuratedTestLedger root Tests/RepoPromptTests/MCP/Control/HeadlessMCPDomainRuntimeM0ContractTests.swift RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests testEveryExecutableEvidenceCitationResolvesInCuratedTestLedger MCP/HeadlessRuntime headless_runtime.m0.executable_citation_ledger_reconciliation contract_json,editflowperf_json,curated_ledger,exact_ids contract_inventory root_swiftpm routine 2 headless_mcp_domain_runtime_m0_contract,headless-mcp-domain-runtime-m0-editflowperf-baseline,test-suite-contract-ledger Every executable-test citation in both M0 JSON artifacts resolves exactly to the indexed curated ledger, while the reviewed six-citation inventory detects silently dropped or malformed evidence references. Stale or malformed evidence IDs could make the M0 contract cite tests that no longer exist and falsely imply preserved coverage. linear_inventory_scan test_case retain 0 M0 exact-ID citation reconciliation; two artifact inventories are traversed once and checked through an indexed ledger map. -root/RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests/testSDKCredentialAndPrivateChildContractsAreFailClosedEvidence root Tests/RepoPromptTests/MCP/Control/HeadlessMCPDomainRuntimeM0ContractTests.swift RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests testSDKCredentialAndPrivateChildContractsAreFailClosedEvidence MCP/HeadlessRuntime headless_runtime.m0.terminal_credential_child_gate sdk_stdio,credential_boundary,private_endpoint,launch_token,unresolved_measurement security_contract root_swiftpm routine 5 headless_mcp_domain_runtime_m0_contract,item0_measurement_record The pinned SDK source assessment, explicitly unobserved Keychain procedure record, packaged CLI signing order, current bootstrap lease, and future private endpoint/token contract stay fail closed without production implementation. A future child could inherit an unsafe transport, credential, or launch assumption from unreviewed drift. direct_in_process;source_inventory test_case retain 0 M0 SDK/credential/packaging/child-boundary guard; credential status is unresolved, not negative empirical evidence. -root/RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests/testPersistenceApprovalMainActorAndPerformanceInventoriesRemainComplete root Tests/RepoPromptTests/MCP/Control/HeadlessMCPDomainRuntimeM0ContractTests.swift RepoPromptTests.HeadlessMCPDomainRuntimeM0ContractTests testPersistenceApprovalMainActorAndPerformanceInventoriesRemainComplete MCP/HeadlessRuntime headless_runtime.m0.persistence_actor_perf_freeze persistence,save_sources,approval,main_actor,editflowperf contract_inventory root_swiftpm routine 5 headless_mcp_domain_runtime_m0_contract,headless-mcp-domain-runtime-m0-editflowperf-baseline Every save source is classified, approval semantics remain explicit, all 42 MCP-local MainActor declaration sites plus external collaborators and source-guarded per-tool provider prefixes are guarded while delegated hops remain explicitly reviewed-only, and the five-stage EditFlowPerf structural contract preserves its explicitly unobserved live-latency fallback. State or actor migrations could silently lose durability, approval, or performance-boundary semantics. direct_in_process;source_inventory test_case retain 0 M0 persistence, approval, complete MainActor denominator, and thresholded deterministic performance-evidence guard. diff --git a/Scripts/test_ci_app_test_runner.py b/Scripts/test_ci_app_test_runner.py index 972aa03b8..8a9a823ad 100644 --- a/Scripts/test_ci_app_test_runner.py +++ b/Scripts/test_ci_app_test_runner.py @@ -97,6 +97,24 @@ def write_ledger(self, directory: Path, rows: list[dict[str, str]]) -> Path: handle.write("\t".join(columns) + "\n") for row in rows: values = {column: "" for column in columns} + values.update( + { + "method_id": f"root/{row['suite']}/{row['method']}", + "target": "root", + "file": "Tests/Fake.swift", + "domain": "Root", + "primary_contract_id": "contract", + "validation_class": "unit", + "layer": "root_swiftpm", + "execution_tier": "fast", + "scenario_count": "1", + "observable_oracle": "oracle", + "failure_risk": "low", + "lifecycle_owner": "owner", + "current_disposition": "retain", + "preserved_scenario_delta": "0", + } + ) values.update(row) handle.write("\t".join(values[column] for column in columns) + "\n") return path @@ -1379,59 +1397,6 @@ def test_main_rejects_missing_explicit_bundle_name(self) -> None: self.assertIn("did not match any built XCTest bundle", output.getvalue()) run_all_suites.assert_not_called() - def write_ledger(self, directory: Path, rows: list[dict[str, str]]) -> Path: - header = [ - "method_id", - "target", - "file", - "suite", - "method", - "domain", - "primary_contract_id", - "secondary_contract_tags", - "validation_class", - "layer", - "execution_tier", - "scenario_count", - "fixture_ids", - "observable_oracle", - "failure_risk", - "runtime_seconds", - "resource_cost_tags", - "shared_state_tags", - "lifecycle_owner", - "current_disposition", - "replacement_method_id", - "preserved_scenario_delta", - "notes", - ] - path = directory / "ledger.tsv" - lines = ["\t".join(header)] - for row in rows: - complete = {key: "" for key in header} - complete.update( - { - "method_id": f"root/{row['suite']}/{row['method']}", - "target": "root", - "file": "Tests/Fake.swift", - "domain": "Root", - "primary_contract_id": "contract", - "validation_class": "unit", - "layer": "root_swiftpm", - "execution_tier": "fast", - "scenario_count": "1", - "observable_oracle": "oracle", - "failure_risk": "low", - "lifecycle_owner": "owner", - "current_disposition": "retain", - "preserved_scenario_delta": "0", - } - ) - complete.update(row) - lines.append("\t".join(complete[key] for key in header)) - path.write_text("\n".join(lines) + "\n", encoding="utf-8") - return path - def test_plan_selected_suites_uses_runtime_balanced_shard_and_slow_first(self) -> None: with tempfile.TemporaryDirectory() as tmp: ledger = self.write_ledger(Path(tmp), [ diff --git a/Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift b/Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift index d3fe489bf..c2cf99fc3 100644 --- a/Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift +++ b/Tests/RepoPromptTests/AI/CLIProcessRunnerLifecycleTests.swift @@ -194,29 +194,35 @@ final class CLIProcessRunnerLifecycleTests: XCTestCase { } private static func waitForPIDFile(_ url: URL, timeout: TimeInterval = 3) async throws -> pid_t { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { + var processID: pid_t? + try await AsyncTestWait.waitUntil("CLI process PID file", timeout: timeout) { if let text = try? String(contentsOf: url, encoding: .utf8), let value = Int32(text.trimmingCharacters(in: .whitespacesAndNewlines)) { - return value + processID = value + return true } - try? await Task.sleep(for: .milliseconds(20)) + return false } - throw CLIProcessRunnerLifecycleTestError.pidFileTimedOut + guard let processID else { throw CLIProcessRunnerLifecycleTestError.pidFileTimedOut } + return processID } private static func waitUntilProcessGone(_ pid: pid_t, timeout: TimeInterval = 5) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if !processExists(pid) { return true } - try? await Task.sleep(for: .milliseconds(20)) + do { + try await AsyncTestWait.waitUntil("CLI process \(pid) to exit", timeout: timeout) { + !processExists(pid) + } + return true + } catch { + return false } - return !processExists(pid) } private static func processExists(_ pid: pid_t) -> Bool { - if Darwin.kill(pid, 0) == 0 { return true } + if Darwin.kill(pid, 0) == 0 { + return true + } return errno == EPERM } @@ -276,27 +282,30 @@ private actor ProcessLifecycleRecorder { } func waitForStart() async -> Bool { - for _ in 0 ..< 100 { - if startedPID != nil { return true } - try? await Task.sleep(for: .milliseconds(10)) + do { + try await AsyncTestWait.waitUntil("process lifecycle start", timeout: 1) { await self.startedPID != nil } + return true + } catch { + return false } - return false } func waitForReadiness() async -> Bool { - for _ in 0 ..< 100 { - if readinessObserved { return true } - try? await Task.sleep(for: .milliseconds(10)) + do { + try await AsyncTestWait.waitUntil("process lifecycle readiness", timeout: 1) { await self.readinessObserved } + return true + } catch { + return false } - return false } func waitForTermination() async -> Bool { - for _ in 0 ..< 300 { - if terminatedPID != nil { return true } - try? await Task.sleep(for: .milliseconds(10)) + do { + try await AsyncTestWait.waitUntil("process lifecycle termination", timeout: 3) { await self.terminatedPID != nil } + return true + } catch { + return false } - return false } func snapshot() -> (startedPID: pid_t?, terminatedPID: pid_t?) { diff --git a/Tests/RepoPromptTests/AI/CodexModelPollingServiceTests.swift b/Tests/RepoPromptTests/AI/CodexModelPollingServiceTests.swift index 3ac1a367e..0dd6d7846 100644 --- a/Tests/RepoPromptTests/AI/CodexModelPollingServiceTests.swift +++ b/Tests/RepoPromptTests/AI/CodexModelPollingServiceTests.swift @@ -36,18 +36,14 @@ final class CodexModelPollingServiceTests: XCTestCase { } private func waitUntil( - timeout: Duration = .seconds(2), + timeout: TimeInterval = 2, condition: @escaping @Sendable () async -> Bool ) async throws { - let clock = ContinuousClock() - let deadline = clock.now.advanced(by: timeout) - while await !condition() { - guard clock.now < deadline else { - XCTFail("Timed out waiting for condition") - return - } - try await Task.sleep(for: .milliseconds(10)) - } + try await AsyncTestWait.waitUntil( + "Codex model polling condition", + timeout: timeout, + condition: condition + ) } } diff --git a/Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift b/Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift index 4fba7486e..bcbeb1e00 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentModeMCPWaitEpochTests.swift @@ -687,13 +687,9 @@ final class AgentModeMCPWaitEpochTests: XCTestCase { } private func waitForWaiter(registration: AgentRunSessionStore.Registration) async throws { - for _ in 0 ..< 200 { - if await AgentRunSessionStore.shared.test_waiterCount(registration: registration) == 1 { - return - } - await Task.yield() + try await AsyncTestWait.waitUntil("Agent Run session waiter registration") { + await AgentRunSessionStore.shared.test_waiterCount(registration: registration) == 1 } - XCTFail("Timed out waiting for waiter") } private func makeViewModel() -> AgentModeViewModel { @@ -755,7 +751,9 @@ private actor EpochBeginGate { } func waitUntilPaused() async { - if isPaused { return } + if isPaused { + return + } await withCheckedContinuation { continuation in pauseWaiters.append(continuation) } diff --git a/Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift b/Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift index 2ca576156..c4cf9efc8 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentModeRunServiceLifecycleTests.swift @@ -2030,11 +2030,9 @@ final class AgentModeRunServiceLifecycleTests: XCTestCase { _ message: String, condition: @escaping @MainActor () -> Bool ) async throws { - for _ in 0 ..< 500 { - if condition() { return } - try? await Task.sleep(nanoseconds: 1_000_000) + try await AsyncTestWait.waitUntil(message, timeout: 0.5) { + await MainActor.run { condition() } } - throw LifecycleTimeoutError(operation: message, timeoutSeconds: 0.5) } func assertOrderedEvents( diff --git a/Tests/RepoPromptTests/AgentMode/AgentModeStopSubmitTargetTests.swift b/Tests/RepoPromptTests/AgentMode/AgentModeStopSubmitTargetTests.swift index 16b2fb07d..79d3d26fc 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentModeStopSubmitTargetTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentModeStopSubmitTargetTests.swift @@ -317,12 +317,11 @@ final class AgentModeStopSubmitTargetTests: XCTestCase { timeout: TimeInterval = 2, _ predicate: @escaping () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if predicate() { return } - try await Task.sleep(nanoseconds: 10_000_000) - } - XCTFail("Timed out waiting for asynchronous Codex submission") + try await AsyncTestWait.waitUntil( + "asynchronous Codex submission", + timeout: timeout, + condition: predicate + ) } func testGuardedFirstSendRejectsReusedSourceTargetBeforeCreatingAnotherDestination() async throws { diff --git a/Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift b/Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift index 2f1815a10..bac25275e 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentModeViewModelInactiveRefreshTests.swift @@ -993,7 +993,8 @@ final class AgentModeViewModelInactiveRefreshTests: XCTestCase { let owner = viewModel.test_receiveWorkspaceSwitchNotification(workspace) await viewModel.test_handleWorkspaceSwitch(workspace, owner: owner) - await harness.waitForRequestCount(1) + let firstRequestStarted = await harness.waitForRequestCount(1) + XCTAssertTrue(firstRequestStarted) let generationWhileBindingIsInstalled = try XCTUnwrap(viewModel.test_activeSessionIndexRefreshGeneration) let restoredSession = try XCTUnwrap(viewModel.session(for: rootTabID, createIfNeeded: true)) XCTAssertEqual(restoredSession.activeAgentSessionID, rootSessionID) @@ -1155,7 +1156,8 @@ final class AgentModeViewModelInactiveRefreshTests: XCTestCase { let owner = viewModel.test_receiveWorkspaceSwitchNotification(workspace) await viewModel.test_handleWorkspaceSwitch(workspace, owner: owner) - await harness.waitForRequestCount(1) + let firstRequestStarted = await harness.waitForRequestCount(1) + XCTAssertTrue(firstRequestStarted) let originalGeneration = try XCTUnwrap(viewModel.test_activeSessionIndexRefreshGeneration) try await waitUntil { viewModel.test_ownerValidatedSessionIndex[originalSessionID] != nil @@ -1166,7 +1168,8 @@ final class AgentModeViewModelInactiveRefreshTests: XCTestCase { _ = viewModel.test_installPersistentSessionBinding(sessionID: replacementSessionID, on: session) let successorGeneration = try XCTUnwrap(viewModel.test_activeSessionIndexRefreshGeneration) XCTAssertGreaterThan(successorGeneration, originalGeneration) - await harness.waitForRequestCount(2) + let successorRequestStarted = await harness.waitForRequestCount(2) + XCTAssertTrue(successorRequestStarted) XCTAssertTrue(viewModel.test_ownerValidatedSessionIndex.isEmpty) await firstGate.release() @@ -1227,7 +1230,8 @@ final class AgentModeViewModelInactiveRefreshTests: XCTestCase { XCTAssertEqual(Set(viewModel.test_ownerValidatedSessionIndex.keys), [rootSessionID, childSessionID]) viewModel.test_refreshSessionListCache(for: workspace) - await harness.waitForRequestCount(2) + let secondRequestStarted = await harness.waitForRequestCount(2) + XCTAssertTrue(secondRequestStarted) try await waitUntil { viewModel.test_ownerValidatedSessionIndex[rootSessionID]?.savedAt == updatedRootEntry.savedAt } @@ -1673,12 +1677,10 @@ final class AgentModeViewModelInactiveRefreshTests: XCTestCase { timeout: TimeInterval = 3, _ condition: @escaping @MainActor () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try await Task.sleep(nanoseconds: 1_000_000) - } - XCTFail("Timed out waiting for condition") + try await AsyncTestWait.waitUntil( + "inactive Agent Mode refresh condition", + timeout: timeout + ) { await MainActor.run { condition() } } } private func makeViewModel() -> AgentModeViewModel { @@ -1824,9 +1826,14 @@ private actor SidebarIndexStreamHarness { return boundSessionIDByTabIDByRequest[requestIndex][tabID] } - func waitForRequestCount(_ expectedCount: Int) async { - while requestCount < expectedCount { - try? await Task.sleep(nanoseconds: 1_000_000) + func waitForRequestCount(_ expectedCount: Int) async -> Bool { + do { + try await AsyncTestWait.waitUntil("inactive refresh request count \(expectedCount)") { + await self.requestCount >= expectedCount + } + return true + } catch { + return false } } } diff --git a/Tests/RepoPromptTests/AgentMode/AgentSelectedFilePreviewLifecycleTests.swift b/Tests/RepoPromptTests/AgentMode/AgentSelectedFilePreviewLifecycleTests.swift index 982575b95..4c0af67ab 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentSelectedFilePreviewLifecycleTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentSelectedFilePreviewLifecycleTests.swift @@ -240,12 +240,14 @@ final class AgentSelectedFilePreviewLifecycleTests: XCTestCase { @MainActor private func waitForPreviewText(_ expected: String, in coordinator: AgentSelectedFilePreviewLoadCoordinator) async -> Bool { - for _ in 0 ..< 500 { - if coordinator.previewText == expected { return true } - await Task.yield() - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("preview text to equal \(expected)", timeout: 0.5) { + await MainActor.run { coordinator.previewText == expected } + } + return true + } catch { + return false } - return coordinator.previewText == expected } private func drainCancelledTask() async { @@ -270,11 +272,12 @@ private actor PreviewLoadGate { } func waitUntilStarted() async -> Bool { - for _ in 0 ..< 500 { - if started { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("preview load to start", timeout: 0.5) { await self.started } + return true + } catch { + return false } - return started } func release(_ value: String?) { @@ -283,11 +286,12 @@ private actor PreviewLoadGate { } func waitUntilCompleted() async -> Bool { - for _ in 0 ..< 500 { - if completed { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("preview load to complete", timeout: 0.5) { await self.completed } + return true + } catch { + return false } - return completed } } @@ -304,11 +308,14 @@ private actor MultiPreviewLoadGate { } func waitUntilStarted(_ displayName: String) async -> Bool { - for _ in 0 ..< 500 { - if started.contains(displayName) { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("preview load for \(displayName) to start", timeout: 0.5) { + await self.started.contains(displayName) + } + return true + } catch { + return false } - return started.contains(displayName) } func release(_ displayName: String, value: String?) { @@ -317,10 +324,13 @@ private actor MultiPreviewLoadGate { } func waitUntilCompleted(_ displayName: String) async -> Bool { - for _ in 0 ..< 500 { - if completed.contains(displayName) { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("preview load for \(displayName) to complete", timeout: 0.5) { + await self.completed.contains(displayName) + } + return true + } catch { + return false } - return completed.contains(displayName) } } diff --git a/Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift b/Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift index 09b969c24..0364eff89 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentSelectedFilesModelCoordinatorTests.swift @@ -361,12 +361,14 @@ final class AgentSelectedFilesModelCoordinatorTests: XCTestCase { promptText: String, in coordinator: AgentSelectedFilesModelCoordinator ) async -> Bool { - for _ in 0 ..< 500 { - if coordinator.model?.source.promptText == promptText, !coordinator.isLoading { return true } - await Task.yield() - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("selected-files model \(promptText)") { + coordinator.model?.source.promptText == promptText && !coordinator.isLoading + } + return true + } catch { + return coordinator.model?.source.promptText == promptText && !coordinator.isLoading } - return coordinator.model?.source.promptText == promptText && !coordinator.isLoading } @MainActor @@ -374,12 +376,14 @@ final class AgentSelectedFilesModelCoordinatorTests: XCTestCase { promptText: String, in coordinator: AgentSelectedFilesModelCoordinator ) async -> Bool { - for _ in 0 ..< 500 { - if coordinator.model?.source.promptText == promptText { return true } - await Task.yield() - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("displayed selected-files model \(promptText)") { + coordinator.model?.source.promptText == promptText + } + return true + } catch { + return coordinator.model?.source.promptText == promptText } - return coordinator.model?.source.promptText == promptText } private func makeRequest( @@ -445,11 +449,14 @@ private actor GatedModelResolver { } func waitUntilStartCount(_ key: String, count: Int) async -> Bool { - for _ in 0 ..< 500 { - if startedCounts[key, default: 0] >= count { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("\(count) gated model resolver starts for \(key)") { + await self.startCount(for: key) >= count + } + return true + } catch { + return startedCounts[key, default: 0] >= count } - return startedCounts[key, default: 0] >= count } func releaseNext(_ key: String) { @@ -462,6 +469,10 @@ private actor GatedModelResolver { func startCount() -> Int { starts } + + private func startCount(for key: String) -> Int { + startedCounts[key, default: 0] + } } private actor ProgressiveCodemapModelResolver { @@ -483,11 +494,14 @@ private actor ProgressiveCodemapModelResolver { func waitUntilStartCount(_ usage: CodeMapUsage, count: Int) async -> Bool { let key = usage.rawValue - for _ in 0 ..< 500 { - if startedCounts[key, default: 0] >= count { return true } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("\(count) progressive codemap resolver starts for \(key)") { + await self.startCount(for: key) >= count + } + return true + } catch { + return startedCounts[key, default: 0] >= count } - return startedCounts[key, default: 0] >= count } func releaseNext(_ usage: CodeMapUsage) { @@ -501,6 +515,10 @@ private actor ProgressiveCodemapModelResolver { func startedUsages() -> [CodeMapUsage] { usages } + + private func startCount(for key: String) -> Int { + startedCounts[key, default: 0] + } } private func makeModel(for request: AgentSelectedFilesModelRequest) -> AgentContextExportModel { diff --git a/Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift b/Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift index ebec227fa..54a33eafa 100644 --- a/Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift +++ b/Tests/RepoPromptTests/AgentMode/AgentWorkspaceRootsSidebarStoreTests.swift @@ -759,12 +759,13 @@ final class AgentWorkspaceRootsSidebarStoreTests: XCTestCase { timeout: TimeInterval = 2, _ condition: @escaping @MainActor () -> Bool ) async { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try? await Task.sleep(nanoseconds: 1_000_000) + do { + try await AsyncTestWait.waitUntil("workspace roots sidebar condition", timeout: timeout) { + await MainActor.run { condition() } + } + } catch { + XCTFail("Timed out waiting for workspace roots sidebar condition: \(error)") } - XCTFail("Timed out waiting for condition") } private func makeProjection( diff --git a/Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift b/Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift index 14933fa88..39b2e1504 100644 --- a/Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift +++ b/Tests/RepoPromptTests/AgentMode/Codex/CodexAgentModeCoordinatorLivenessTests.swift @@ -2999,16 +2999,12 @@ final class CodexAgentModeCoordinatorLivenessTests: XCTestCase { private func waitUntil( timeout: TimeInterval = 2.0, - file: StaticString = #filePath, - line: UInt = #line, - _ condition: @escaping () -> Bool + _ condition: @escaping @MainActor () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try await Task.sleep(nanoseconds: 10_000_000) - } - XCTFail("Timed out waiting for condition", file: file, line: line) + try await AsyncTestWait.waitUntil( + "Codex Agent Mode coordinator condition", + timeout: timeout + ) { await MainActor.run { condition() } } } } diff --git a/Tests/RepoPromptTests/AgentMode/CursorACPLaunchResolverTests.swift b/Tests/RepoPromptTests/AgentMode/CursorACPLaunchResolverTests.swift index a5301ee5c..949743b6c 100644 --- a/Tests/RepoPromptTests/AgentMode/CursorACPLaunchResolverTests.swift +++ b/Tests/RepoPromptTests/AgentMode/CursorACPLaunchResolverTests.swift @@ -809,12 +809,14 @@ final class CursorACPLaunchResolverTests: XCTestCase { } private func waitUntilFileExists(_ url: URL, timeout: TimeInterval = 2) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - repeat { - if FileManager.default.fileExists(atPath: url.path) { return true } - await Task.yield() - } while Date() < deadline - return false + do { + try await AsyncTestWait.waitUntil("Cursor launch marker file", timeout: timeout) { + FileManager.default.fileExists(atPath: url.path) + } + return true + } catch { + return false + } } } diff --git a/Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift b/Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift index fc9a8a656..b05711fb0 100644 --- a/Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift +++ b/Tests/RepoPromptTests/AgentMode/History/HistorySessionScannerTests.swift @@ -9,7 +9,6 @@ final class HistorySessionScannerTests: XCTestCase { private var workspacesRoot: URL! private var scanner: HistorySessionScanner! private let encoder = JSONEncoder() - private let decoder = JSONDecoder() override func setUp() { super.setUp() diff --git a/Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift b/Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift index 1c1ea93e4..8131da9a5 100644 --- a/Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift +++ b/Tests/RepoPromptTests/AgentMode/OpenCodeACPLaunchResolverTests.swift @@ -301,12 +301,14 @@ final class OpenCodeACPLaunchResolverTests: XCTestCase { } private func waitUntilFileExists(_ url: URL, timeout: TimeInterval = 2) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - repeat { - if FileManager.default.fileExists(atPath: url.path) { return true } - await Task.yield() - } while Date() < deadline - return false + do { + try await AsyncTestWait.waitUntil("OpenCode launch marker file", timeout: timeout) { + FileManager.default.fileExists(atPath: url.path) + } + return true + } catch { + return false + } } } diff --git a/Tests/RepoPromptTests/App/WindowStateDisplayedTitleTests.swift b/Tests/RepoPromptTests/App/WindowStateDisplayedTitleTests.swift index a45eab925..d8930f22b 100644 --- a/Tests/RepoPromptTests/App/WindowStateDisplayedTitleTests.swift +++ b/Tests/RepoPromptTests/App/WindowStateDisplayedTitleTests.swift @@ -34,7 +34,11 @@ final class WindowStateDisplayedTitleTests: XCTestCase { let activeWorkspace = try XCTUnwrap(window.workspaceManager.activeWorkspace) XCTAssertEqual(activeWorkspace.id, workspace.id) - try await waitForDisplayedTitle(window, and: nsWindow, endingWith: workspaceName) + try await waitForDisplayedTitle( + window, + and: nsWindow, + expectedDescription: "suffix \"\(workspaceName)\"" + ) { $0.hasSuffix(workspaceName) } } catch { await cleanup(window: window, rootURL: rootURL) throw error @@ -75,8 +79,10 @@ final class WindowStateDisplayedTitleTests: XCTestCase { try await waitForDisplayedTitle( window, and: nsWindow, - equalTo: "Renamed Agent Session — \(workspaceName)" - ) + expectedDescription: "\"Renamed Agent Session — \(workspaceName)\"" + ) { + $0 == "Renamed Agent Session — \(workspaceName)" + } } catch { await cleanup(window: window, rootURL: rootURL) throw error @@ -101,46 +107,22 @@ final class WindowStateDisplayedTitleTests: XCTestCase { try? FileManager.default.removeItem(at: rootURL) } - /// The displayed title is published from a deferred task, so poll briefly instead of - /// asserting immediately after the workspace switch returns. The title may carry an - /// Agent session prefix ("T1 — "), so only the workspace suffix is asserted. + /// The displayed title is published from a deferred task, so wait for both title surfaces. private func waitForDisplayedTitle( _ window: WindowState, and nsWindow: NSWindow, - endingWith expectedSuffix: String, - timeout: TimeInterval = 5 + expectedDescription: String, + matches: @escaping (String) -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if window.displayedWindowTitle.hasSuffix(expectedSuffix), - nsWindow.title.hasSuffix(expectedSuffix) - { - return - } - try await Task.sleep(nanoseconds: 50_000_000) - } - XCTFail( - "displayedWindowTitle was \"\(window.displayedWindowTitle)\" and NSWindow.title was \"\(nsWindow.title)\", expected suffix \"\(expectedSuffix)\"" - ) - } - - private func waitForDisplayedTitle( - _ window: WindowState, - and nsWindow: NSWindow, - equalTo expected: String, - timeout: TimeInterval = 5 - ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if window.displayedWindowTitle == expected, - nsWindow.title == expected - { - return + do { + try await AsyncTestWait.waitUntil("both displayed window titles to match \(expectedDescription)", timeout: 5) { + matches(window.displayedWindowTitle) && matches(nsWindow.title) } - try await Task.sleep(nanoseconds: 50_000_000) + } catch { + XCTFail( + "displayedWindowTitle was \"\(window.displayedWindowTitle)\" and NSWindow.title was \"\(nsWindow.title)\", expected \(expectedDescription)" + ) + throw error } - XCTFail( - "displayedWindowTitle was \"\(window.displayedWindowTitle)\" and NSWindow.title was \"\(nsWindow.title)\", expected \"\(expected)\"" - ) } } diff --git a/Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift b/Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift index 5affb7087..7863d0282 100644 --- a/Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift +++ b/Tests/RepoPromptTests/CodeMap/CodeMapArtifactBuildCoordinatorTests.swift @@ -514,7 +514,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { let lookupFailure = CoordinatorFailOnce() let lookupClient = CodeMapArtifactStoreClient( lookup: { key in - if await lookupFailure.take() { throw CoordinatorTestError.transient } + if await lookupFailure.take() { + throw CoordinatorTestError.transient + } return try await fixture.artifactStore.lookup(key: key) }, insert: { try await fixture.artifactStore.insert(key: $0, deterministicOutcome: $1) }, @@ -533,7 +535,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { let buildInput = try makeInput("retry-build", root: fixture.root) let buildFailure = CoordinatorFailOnce() let buildCoordinator = makeCoordinator(fixture: fixture) { _, _, _ in - if await buildFailure.take() { throw CoordinatorTestError.transient } + if await buildFailure.take() { + throw CoordinatorTestError.transient + } return .readyNoSymbols } await assertTransientFailure { try await buildCoordinator.resolve(request(buildInput)) } @@ -551,7 +555,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { let persistClient = CodeMapArtifactStoreClient( lookup: { try await fixture.artifactStore.lookup(key: $0) }, insert: { key, outcome in - if await persistFailure.take() { throw CoordinatorTestError.transient } + if await persistFailure.take() { + throw CoordinatorTestError.transient + } return try await fixture.artifactStore.insert(key: key, deterministicOutcome: outcome) }, lease: { try await fixture.artifactStore.lease(handle: $0) }, @@ -982,7 +988,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { policy: policy(maximumConcurrentBuildCount: 1, maximumQueuedBuildCount: 4) ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let ownerA = UUID() @@ -1023,7 +1031,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { clock: clock.clock ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let owner = UUID() @@ -1073,7 +1083,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { clock: clock.clock ) { input, ownerID, priority in await builds.record(key: input.artifactKey, ownerID: ownerID, priority: priority) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let backgroundOwner = UUID() @@ -1121,7 +1133,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { policy: policy(maximumConcurrentBuildCount: 1, maximumQueuedBuildCount: 2) ) { input, ownerID, priority in await builds.record(key: input.artifactKey, ownerID: ownerID, priority: priority) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let backgroundOwner = UUID() @@ -1182,7 +1196,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { clock: clock.clock ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let owner = UUID() @@ -1248,7 +1264,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { clock: clock.clock ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let repeatedOwner = UUID() @@ -1299,7 +1317,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { clock: testClock.clock ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let repeatedOwner = UUID() @@ -1347,7 +1367,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { ) ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let blockerTask = Task { try await coordinator.resolve(request(blocker, priority: .explicit)) } @@ -1391,7 +1413,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { policy: policy(maximumConcurrentBuildCount: 1, maximumQueuedBuildCount: 2) ) { input, _, _ in await order.record(input.artifactKey.storageDigestHex) - if input.artifactKey == blocker.artifactKey { await gate.enter() } + if input.artifactKey == blocker.artifactKey { + await gate.enter() + } return .readyNoSymbols } let repeatedOwner = UUID() @@ -1438,7 +1462,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { maximumRetainedInputByteCount: firstInput.source.rawByteCount ) ) { _, _, _ in - if await blockFirstBuild.take() { await gate.enter() } + if await blockFirstBuild.take() { + await gate.enter() + } return .readyNoSymbols } @@ -1552,7 +1578,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { maximumRetainedInputByteCount: budget ) ) { _, _, _ in - if await failure.take() { throw CoordinatorTestError.transient } + if await failure.take() { + throw CoordinatorTestError.transient + } return .readyNoSymbols } await assertTransientFailure { @@ -1631,7 +1659,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { ), hooks: CodeMapArtifactBuildCoordinatorHooks { event in await events.append(event) - if event.kind == .flightCreated { await consumerGate.enter() } + if event.kind == .flightCreated { + await consumerGate.enter() + } } ) @@ -1678,7 +1708,9 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { let failure = CoordinatorFailOnce() let locatorClient = GitBlobCodeMapLocatorStoreClient( read: { identity in - if await failure.take() { throw CoordinatorTestError.transient } + if await failure.take() { + throw CoordinatorTestError.transient + } return try await fixture.locatorStore.read(identity: identity) }, write: { try await fixture.locatorStore.write(association: $0) } @@ -2190,16 +2222,6 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { ) } - private func gitBlobOID(_ bytes: Data, format: GitObjectFormat) -> String { - var canonical = Data("blob \(bytes.count)\0".utf8) - canonical.append(bytes) - let digest = switch format { - case .sha1: Data(Insecure.SHA1.hash(data: canonical)) - case .sha256: Data(SHA256.hash(data: canonical)) - } - return digest.map { String(format: "%02x", $0) }.joined() - } - private func writeUncheckedLocatorRecord( identity: GitBlobCodeMapLocatorIdentity, key: CodeMapArtifactKey, @@ -2311,12 +2333,12 @@ final class CodeMapArtifactBuildCoordinatorTests: XCTestCase { file: StaticString = #filePath, line: UInt = #line ) async throws { - for _ in 0 ..< 10000 { - if await predicate() { return } - await Task.yield() + do { + try await AsyncTestWait.waitUntil("CodeMap artifact coordinator condition", condition: predicate) + } catch { + XCTFail("condition was not reached: \(error)", file: file, line: line) + throw error } - XCTFail("condition was not reached", file: file, line: line) - throw CoordinatorTestError.transient } private func makeSecureRoot() throws -> URL { diff --git a/Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift b/Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift index 6e32145f4..7098da41a 100644 --- a/Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift +++ b/Tests/RepoPromptTests/CodeMap/CodeMapV6CacheDeletionTests.swift @@ -391,13 +391,6 @@ final class CodeMapV6CacheDeletionTests: XCTestCase { XCTAssertEqual(try Data(contentsOf: file), try XCTUnwrap(expected[file.path])) } } - - func testReportTelemetryShapeContainsOnlyNumericStoredFields() { - let report = CodeMapV6CacheDeletionReport() - for child in Mirror(reflecting: report).children { - XCTAssertTrue(child.value is Int || child.value is UInt64, "non-numeric field: \(child.label ?? "?")") - } - } } private struct InjectedFailure: Error {} diff --git a/Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift b/Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift index 0c40bfb34..1d7920fa4 100644 --- a/Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift +++ b/Tests/RepoPromptTests/ContextBuilder/ContextBuilderRunLifecycleTests.swift @@ -1323,8 +1323,8 @@ final class ContextBuilderRunLifecycleTests: XCTestCase { await executionCancelled.waitUntilArrived() await executionTask.value await fulfillment(of: [providerDisposeFinished], timeout: 1) - for _ in 0 ..< 100 where record.teardownFinishedAt == nil { - await Task.yield() + try await AsyncTestWait.waitUntil("stale Context Builder run teardown to finish") { + await MainActor.run { record.teardownFinishedAt != nil } } let disposeCallCount = await provider.disposeCallCount() @@ -1831,13 +1831,14 @@ final class ContextBuilderRunLifecycleTests: XCTestCase { } private func waitForRoutingWaiter(runID: UUID) async -> Bool { - for _ in 0 ..< 1000 { - if await MCPRoutingWaiter.debugContinuationCount(runID: runID) == 1 { - return true + do { + try await AsyncTestWait.waitUntil("MCP routing waiter registration", timeout: 2) { + await MCPRoutingWaiter.debugContinuationCount(runID: runID) == 1 } - await Task.yield() + return true + } catch { + return false } - return false } #if DEBUG @@ -1882,7 +1883,9 @@ final class ContextBuilderRunLifecycleTests: XCTestCase { var data = Data() while data.count < 32 { guard let byte = try stdout.fileHandleForReading.read(upToCount: 1), !byte.isEmpty else { break } - if byte == Data([0x0A]) { break } + if byte == Data([0x0A]) { + break + } data.append(byte) } guard let text = String(data: data, encoding: .utf8), diff --git a/Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift b/Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift index 57691c624..64f54497e 100644 --- a/Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift +++ b/Tests/RepoPromptTests/ContextBuilder/ContextBuilderWorktreeInheritanceTests.swift @@ -2338,15 +2338,6 @@ import XCTest ) } - private func makeTemporaryRoot(name: String) throws -> URL { - let url = FileManager.default.temporaryDirectory - .appendingPathComponent("ContextBuilderWorktreeInheritanceTests", isDirectory: true) - .appendingPathComponent("\(name)-\(UUID().uuidString)", isDirectory: true) - try FileManager.default.createDirectory(at: url, withIntermediateDirectories: true) - addTeardownBlock { try? FileManager.default.removeItem(at: url) } - return url.standardizedFileURL - } - @discardableResult private func initializeGitRepository( at root: URL, diff --git a/Tests/RepoPromptTests/Helpers/AsyncTestCondition.swift b/Tests/RepoPromptTests/Helpers/AsyncTestCondition.swift index ce7bd3564..c3259c14c 100644 --- a/Tests/RepoPromptTests/Helpers/AsyncTestCondition.swift +++ b/Tests/RepoPromptTests/Helpers/AsyncTestCondition.swift @@ -48,11 +48,12 @@ enum AsyncTestWait { guard now < deadline else { throw AsyncTestConditionTimeout(description: description, timeout: timeout) } - let sleepDeadline = min( - deadline, - now.advanced(by: .nanoseconds(Int64(delay))) - ) - try await clock.sleep(until: sleepDeadline, tolerance: .zero) + // ContinuousClock.sleep(until:tolerance:) has produced an invalid + // clock-state transition when the enclosing XCTest task is torn down + // immediately after the condition succeeds. A bounded relative task + // sleep provides the same polling backoff without retaining that clock + // sleeper across XCTest teardown. + try await Task.sleep(nanoseconds: delay) delay = min(delay > maximumDelay / 2 ? maximumDelay : delay * 2, maximumDelay) } } diff --git a/Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift b/Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift index 447595bb3..9418d0192 100644 --- a/Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/BindContextRoutingRecoveryTests.swift @@ -72,22 +72,8 @@ final class BindContextRoutingRecoveryTests: XCTestCase { } } - func testMCPConnectionManagerHasNoIncompleteBindContextFastPathOrUnsafeRegisteredServicesSnapshot() throws { - let source = try readMCPConnectionManagerSource() - XCTAssertFalse(source.contains("fastBindContextReadOnlyResult")) - XCTAssertFalse(source.contains("served read-only request via fast path")) - XCTAssertFalse(source.contains("registeredServicesSnapshot")) - XCTAssertFalse(source.contains("nonisolated(unsafe) private var registeredServicesSnapshot")) - } - func testStandardWorkspaceSwitchBindsConnectionOnlyWhenWindowIDIsExplicit() { XCTAssertTrue(WindowRoutingService.shouldBindConnectionAfterStandardWorkspaceSwitch(explicitWindowIDProvided: true)) XCTAssertFalse(WindowRoutingService.shouldBindConnectionAfterStandardWorkspaceSwitch(explicitWindowIDProvided: false)) } - - private func readMCPConnectionManagerSource() throws -> String { - let root = try RepoRoot.url() - let url = root.appendingPathComponent("Sources/RepoPrompt/Infrastructure/MCP/MCPConnectionManager.swift") - return try String(contentsOf: url, encoding: .utf8) - } } diff --git a/Tests/RepoPromptTests/MCP/Control/MCPSocketDescriptorHardeningTests.swift b/Tests/RepoPromptTests/MCP/Control/MCPSocketDescriptorHardeningTests.swift index 6700f1b87..0d5e83aba 100644 --- a/Tests/RepoPromptTests/MCP/Control/MCPSocketDescriptorHardeningTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/MCPSocketDescriptorHardeningTests.swift @@ -1057,7 +1057,9 @@ final class MCPSocketDescriptorHardeningTests: XCTestCase { while Date() < deadline { var descriptor = pollfd(fd: fd, events: Int16(POLLIN | POLLHUP | POLLERR), revents: 0) let result = Darwin.poll(&descriptor, 1, 50) - if result < 0, errno == EINTR { continue } + if result < 0, errno == EINTR { + continue + } guard result > 0 else { continue } var byte: UInt8 = 0 @@ -1194,8 +1196,12 @@ final class MCPSocketDescriptorHardeningTests: XCTestCase { var byte: UInt8 = 0 let count = Darwin.recv(fd, &byte, 1, Int32(MSG_PEEK | MSG_DONTWAIT)) - if count == 0 { return true } - if count < 0, errno != EAGAIN, errno != EWOULDBLOCK { return false } + if count == 0 { + return true + } + if count < 0, errno != EAGAIN, errno != EWOULDBLOCK { + return false + } } return false } @@ -1217,14 +1223,16 @@ final class MCPSocketDescriptorHardeningTests: XCTestCase { private static func waitUntil( timeout: TimeInterval = 2, - condition: () async -> Bool + condition: @escaping () async -> Bool ) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await condition() { return true } - try? await Task.sleep(for: .milliseconds(20)) + do { + try await AsyncTestWait.waitUntil("MCP socket descriptor condition", timeout: timeout) { + await condition() + } + return true + } catch { + return false } - return await condition() } } diff --git a/Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift b/Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift index fdd86b02c..2772386da 100644 --- a/Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/MCPToolAdmissionPolicyTests.swift @@ -403,12 +403,15 @@ final class MCPToolAdmissionPolicyTests: XCTestCase { } } - private func waitUntil(_ condition: () async -> Bool) async -> Bool { - for _ in 0 ..< 200 { - if await condition() { return true } - try? await Task.sleep(for: .milliseconds(5)) + private func waitUntil(_ condition: @escaping () async -> Bool) async -> Bool { + do { + try await AsyncTestWait.waitUntil("MCP tool admission condition", timeout: 1) { + await condition() + } + return true + } catch { + return false } - return false } } diff --git a/Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift b/Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift index cf0b14aaf..0f349eba6 100644 --- a/Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/PersistentAgentModeMCPReadFileConnectionTests.swift @@ -1420,8 +1420,12 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { let acceptedBeforeRead = fixture.window.mcpServer .debugReadFileAutoSelectionContextSnapshot(for: target)?.acceptedIntentCount ?? 0 var arguments: [String: Any] = ["path": path] - if let startLine { arguments["start_line"] = startLine } - if let limit { arguments["limit"] = limit } + if let startLine { + arguments["start_line"] = startLine + } + if let limit { + arguments["limit"] = limit + } let response = try await fixture.socketClient.request( id: id, method: "tools/call", @@ -1446,7 +1450,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { while ContinuousClock.now < deadline { let accepted = fixture.window.mcpServer .debugReadFileAutoSelectionContextSnapshot(for: target)?.acceptedIntentCount ?? 0 - if accepted >= minimum { return true } + if accepted >= minimum { + return true + } try? await Task.sleep(for: .milliseconds(10)) } let accepted = fixture.window.mcpServer @@ -2558,7 +2564,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { func waitUntilMarked(_ signal: PersistentAsyncSignal, timeout: Duration) async -> Bool { let deadline = ContinuousClock.now + timeout while ContinuousClock.now < deadline { - if await signal.isMarked() { return true } + if await signal.isMarked() { + return true + } try? await Task.sleep(for: .milliseconds(10)) } return await signal.isMarked() @@ -2638,7 +2646,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { static func diagnosticsPayload(_ result: CallTool.Result) throws -> [String: Any] { let text = result.content.compactMap { content -> String? in - if case let .text(text, _, _) = content { return text } + if case let .text(text, _, _) = content { + return text + } return nil }.joined() let data = try XCTUnwrap(text.data(using: .utf8)) @@ -2760,7 +2770,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { .appendingPathComponent("GeneratedOracleExportFileWriterTests.swift") let logical = try String(contentsOf: targetURL, encoding: .utf8) var lines = logical.split(separator: "\n", omittingEmptySubsequences: false).map(String.init) - if lines.last == "" { lines.removeLast() } + if lines.last == "" { + lines.removeLast() + } guard lines.count >= 175 else { throw ClientFixtureError.liveFixtureTooShort(lines.count) } return (logical, lines.prefix(175).joined(separator: "\n") + "\n") } @@ -3502,7 +3514,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { $0 as AnyObject === routingService as AnyObject } let names = await routingService.tools.map(\.name) - if registered, names.contains(MCPGlobalToolName.bindContext) { break } + if registered, names.contains(MCPGlobalToolName.bindContext) { + break + } try await Task.sleep(for: .milliseconds(10)) } if peerCatalogService == nil { @@ -4037,49 +4051,6 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { } } - private final class SocketPairResponseWaiter: @unchecked Sendable { - private let lock = NSLock() - private var continuation: CheckedContinuation? - - init(_ continuation: CheckedContinuation) { - self.continuation = continuation - } - - func resume(returning value: String) { - take()?.resume(returning: value) - } - - func resume(throwing error: Error) { - take()?.resume(throwing: error) - } - - private func take() -> CheckedContinuation? { - lock.lock() - defer { lock.unlock() } - defer { continuation = nil } - return continuation - } - } - - private final class SocketPairResponseWaiterHolder: @unchecked Sendable { - private let lock = NSLock() - private var waiter: SocketPairResponseWaiter? - - func install(_ waiter: SocketPairResponseWaiter) { - lock.lock() - self.waiter = waiter - lock.unlock() - } - - func resume(throwing error: Error) { - lock.lock() - let waiter = waiter - self.waiter = nil - lock.unlock() - waiter?.resume(throwing: error) - } - } - private final class SocketPairJSONRPCClient: @unchecked Sendable { enum ClientError: Error { case closed @@ -4167,7 +4138,9 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { isCancelled: () -> Bool ) throws -> String { while true { - if isCancelled() { throw CancellationError() } + if isCancelled() { + throw CancellationError() + } let line = try readLine(deadline: deadline, isCancelled: isCancelled) let object = try JSONSerialization.jsonObject(with: line) as? [String: Any] guard let object else { throw ClientError.invalidResponse } @@ -4203,14 +4176,18 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { written += result continue } - if result < 0, errno == EINTR { continue } + if result < 0, errno == EINTR { + continue + } throw ClientError.posix(operation: "write", code: errno) } } private func readLine(deadline: Date, isCancelled: () -> Bool) throws -> Data { while true { - if isCancelled() { throw CancellationError() } + if isCancelled() { + throw CancellationError() + } if let newline = buffer.firstIndex(of: 0x0A) { let line = Data(buffer[..= 0 else { throw ClientError.closed } var descriptor = pollfd(fd: fd, events: Int16(POLLIN), revents: 0) let remainingMilliseconds = Int32(deadline.timeIntervalSinceNow * 1000) - if remainingMilliseconds <= 0 { throw ClientError.timedOut } + if remainingMilliseconds <= 0 { + throw ClientError.timedOut + } let pollResult = Darwin.poll(&descriptor, 1, min(100, remainingMilliseconds)) - if pollResult == 0 { continue } + if pollResult == 0 { + continue + } if pollResult < 0 { - if errno == EINTR { continue } + if errno == EINTR { + continue + } throw ClientError.posix(operation: "poll", code: errno) } if descriptor.revents & Int16(POLLERR | POLLHUP | POLLNVAL) != 0, @@ -4240,8 +4223,12 @@ final class PersistentAgentModeMCPReadFileConnectionTests: XCTestCase { buffer.append(contentsOf: bytes.prefix(readCount)) continue } - if readCount == 0 { throw ClientError.closed } - if errno == EINTR { continue } + if readCount == 0 { + throw ClientError.closed + } + if errno == EINTR { + continue + } throw ClientError.posix(operation: "read", code: errno) } } diff --git a/Tests/RepoPromptTests/MCP/Control/ProcessLauncherDescriptorInheritanceTests.swift b/Tests/RepoPromptTests/MCP/Control/ProcessLauncherDescriptorInheritanceTests.swift index 3cc440cfa..7b4bf8902 100644 --- a/Tests/RepoPromptTests/MCP/Control/ProcessLauncherDescriptorInheritanceTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/ProcessLauncherDescriptorInheritanceTests.swift @@ -254,17 +254,6 @@ final class ProcessLauncherDescriptorInheritanceTests: XCTestCase { #endif } - private static func assertSourceContains( - _ snippets: [String], - in source: String, - file: StaticString = #filePath, - line: UInt = #line - ) { - for snippet in snippets { - XCTAssertTrue(source.contains(snippet), "Missing ProcessLauncher result check: \(snippet)", file: file, line: line) - } - } - private static func firstReceivedMessage( from stream: AsyncThrowingStream ) async throws -> Data? { @@ -307,7 +296,9 @@ final class ProcessLauncherDescriptorInheritanceTests: XCTestCase { while data.count < count, Date() < deadline { var descriptor = pollfd(fd: fd, events: Int16(POLLIN | POLLHUP | POLLERR), revents: 0) let result = Darwin.poll(&descriptor, 1, 50) - if result < 0, errno == EINTR { continue } + if result < 0, errno == EINTR { + continue + } guard result > 0 else { continue } var buffer = [UInt8](repeating: 0, count: count - data.count) @@ -334,7 +325,9 @@ final class ProcessLauncherDescriptorInheritanceTests: XCTestCase { while Date() < deadline { var status: Int32 = 0 let result = Darwin.waitpid(pid, &status, WNOHANG) - if result == pid { return status } + if result == pid { + return status + } if result < 0 { throw POSIXError(POSIXErrorCode(rawValue: errno) ?? .ECHILD) } @@ -368,8 +361,12 @@ final class ProcessLauncherDescriptorInheritanceTests: XCTestCase { var byte: UInt8 = 0 let count = Darwin.recv(fd, &byte, 1, Int32(MSG_PEEK | MSG_DONTWAIT)) - if count == 0 { return true } - if count < 0, errno != EAGAIN, errno != EWOULDBLOCK { return false } + if count == 0 { + return true + } + if count < 0, errno != EAGAIN, errno != EWOULDBLOCK { + return false + } } return false } @@ -377,7 +374,9 @@ final class ProcessLauncherDescriptorInheritanceTests: XCTestCase { private static func waitUntilClosed(_ fd: Int32, timeout: TimeInterval = 2) -> Bool { let deadline = Date().addingTimeInterval(timeout) while Date() < deadline { - if isClosed(fd) { return true } + if isClosed(fd) { + return true + } usleep(20000) } return isClosed(fd) diff --git a/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPReceiveOverflowTests.swift b/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPReceiveOverflowTests.swift index e16af9e62..fe50e1f97 100644 --- a/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPReceiveOverflowTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPReceiveOverflowTests.swift @@ -253,7 +253,9 @@ final class UnixSocketMCPReceiveOverflowTests: XCTestCase { Darwin.write(fd, buffer.baseAddress, buffer.count) } if written < 0 { - if errno == EINTR { continue } + if errno == EINTR { + continue + } throw POSIXError(POSIXErrorCode(rawValue: errno) ?? .EIO) } guard written > 0 else { @@ -281,11 +283,17 @@ final class UnixSocketMCPReceiveOverflowTests: XCTestCase { pollIntervalNanoseconds: UInt64 = 5_000_000, _ condition: @escaping () async -> Bool ) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await condition() { return true } - try? await Task.sleep(nanoseconds: pollIntervalNanoseconds) + do { + try await AsyncTestWait.waitUntil( + "Unix socket receive-overflow condition", + timeout: timeout, + initialDelayNanoseconds: pollIntervalNanoseconds, + maximumDelayNanoseconds: pollIntervalNanoseconds, + condition: condition + ) + return true + } catch { + return false } - return await condition() } } diff --git a/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPTerminalCleanupTests.swift b/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPTerminalCleanupTests.swift index ce537b17c..b954ddc24 100644 --- a/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPTerminalCleanupTests.swift +++ b/Tests/RepoPromptTests/MCP/Control/UnixSocketMCPTerminalCleanupTests.swift @@ -755,12 +755,16 @@ final class UnixSocketMCPTerminalCleanupTests: XCTestCase { while Date() < deadline { var descriptor = pollfd(fd: fd, events: Int16(POLLIN | POLLHUP | POLLERR), revents: 0) let pollResult = Darwin.poll(&descriptor, 1, 50) - if pollResult < 0, errno == EINTR { continue } + if pollResult < 0, errno == EINTR { + continue + } guard pollResult > 0 else { continue } var byte: UInt8 = 0 let count = Darwin.read(fd, &byte, 1) - if count < 0, errno == EINTR { continue } + if count < 0, errno == EINTR { + continue + } guard count > 0 else { throw POSIXError(.EIO) } if byte == UInt8(ascii: "\n") { return data @@ -777,7 +781,9 @@ final class UnixSocketMCPTerminalCleanupTests: XCTestCase { Darwin.write(fd, buffer.baseAddress, buffer.count) } if written < 0 { - if errno == EINTR { continue } + if errno == EINTR { + continue + } throw POSIXError(POSIXErrorCode(rawValue: errno) ?? .EIO) } guard written > 0 else { throw POSIXError(.EIO) } @@ -808,11 +814,17 @@ final class UnixSocketMCPTerminalCleanupTests: XCTestCase { pollIntervalNanoseconds: UInt64 = 5_000_000, _ condition: @escaping () async -> Bool ) async -> Bool { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await condition() { return true } - try? await Task.sleep(nanoseconds: pollIntervalNanoseconds) + do { + try await AsyncTestWait.waitUntil( + "Unix socket terminal cleanup condition", + timeout: timeout, + initialDelayNanoseconds: pollIntervalNanoseconds, + maximumDelayNanoseconds: pollIntervalNanoseconds, + condition: condition + ) + return true + } catch { + return false } - return await condition() } } diff --git a/Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift b/Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift index 085948c9c..a3961d4c7 100644 --- a/Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift +++ b/Tests/RepoPromptTests/MCP/MCPAskOracleWorktreeTests.swift @@ -2799,49 +2799,6 @@ import XCTest context.window.promptManager.loadComposeTabsFromWorkspace(activeWorkspace, syncPromptText: true) } - private func writeGitArtifactManifest( - to url: URL, - snapshotID: String, - repoKey: String, - repoRoot: URL, - layout: GitRepositoryLayout, - tabID: UUID - ) throws { - let manifest = GitDiffSnapshotManifest( - snapshotID: snapshotID, - generatedAt: Date(timeIntervalSince1970: 1), - mode: .standard, - compare: "HEAD", - compareInput: nil, - scope: .selected, - requestedPaths: ["Sources/Feature.swift"], - fingerprint: GitDiffFingerprint( - headSHA: "abc", - baseRef: "HEAD", - statusHash: "status", - generatedAt: Date(timeIntervalSince1970: 1) - ), - contextLines: 3, - detectRenames: false, - summary: GitDiffSnapshotManifest.Summary(files: 1, insertions: 1, deletions: 0), - files: [], - repoKey: repoKey, - repoRoot: repoRoot.path, - isWorktree: true, - worktreeName: repoRoot.lastPathComponent, - worktreeRoot: repoRoot.path, - mainWorktreeRoot: layout.knownMainWorktreeRoot?.path, - commonGitDir: layout.commonDir.path, - tabID: tabID - ) - let encoder = JSONEncoder() - encoder.dateEncodingStrategy = .iso8601 - try write( - XCTUnwrap(try String(data: encoder.encode(manifest), encoding: .utf8)), - to: url - ) - } - private func requireSelectedPath( suffix: String, in selection: StoredSelection, diff --git a/Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift b/Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift index fd134f873..b6b313c54 100644 --- a/Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift +++ b/Tests/RepoPromptTests/MCP/MCPReadFileAutoSelectionCoordinatorTests.swift @@ -738,21 +738,6 @@ final class MCPReadFileAutoSelectionCoordinatorTests: XCTestCase { XCTAssertTrue(recordedBatches.isEmpty) } - private func waitUntil( - timeout: Duration = .seconds(2), - condition: @MainActor () -> Bool - ) async -> Bool { - let clock = ContinuousClock() - let deadline = clock.now.advanced(by: timeout) - while clock.now < deadline { - if condition() { - return true - } - try? await Task.sleep(for: .milliseconds(1)) - } - return condition() - } - private func makeCoordinator( recorder: CoordinatorRecorder, applyCanonical: MCPReadFileAutoSelectionCoordinator.ApplyCanonical? = nil @@ -783,6 +768,21 @@ final class MCPReadFileAutoSelectionCoordinatorTests: XCTestCase { bindingGeneration: bindingGeneration ) } + + private func waitUntil( + timeout: Duration = .seconds(5), + condition: @escaping () async -> Bool + ) async -> Bool { + let clock = ContinuousClock() + let deadline = clock.now.advanced(by: timeout) + while clock.now < deadline { + if await condition() { + return true + } + try? await Task.sleep(for: .milliseconds(10)) + } + return await condition() + } } private actor CoordinatorRecorder { diff --git a/Tests/RepoPromptTests/MCP/WorkspaceApprovalCancellationTests.swift b/Tests/RepoPromptTests/MCP/WorkspaceApprovalCancellationTests.swift index 2fb71a522..ed5b7b88a 100644 --- a/Tests/RepoPromptTests/MCP/WorkspaceApprovalCancellationTests.swift +++ b/Tests/RepoPromptTests/MCP/WorkspaceApprovalCancellationTests.swift @@ -104,15 +104,11 @@ final class WorkspaceApprovalCancellationTests: XCTestCase { private func waitUntil( timeout: TimeInterval = 3, - file: StaticString = #filePath, - line: UInt = #line, _ condition: @escaping @MainActor () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try await Task.sleep(nanoseconds: 10_000_000) - } - XCTFail("Timed out waiting for condition", file: file, line: line) + try await AsyncTestWait.waitUntil( + "workspace approval cancellation condition", + timeout: timeout + ) { await MainActor.run { condition() } } } } diff --git a/Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift b/Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift index 13d20c535..439067736 100644 --- a/Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift +++ b/Tests/RepoPromptTests/Mentions/TextFieldMentionHelpersTests.swift @@ -79,7 +79,8 @@ final class TextFieldMentionHelpersTests: XCTestCase { try await waitUntil { provider.callCount == 2 } helper.clickSuggestionForTesting(at: 1) provider.completeRefresh() - try await Task.sleep(nanoseconds: 50_000_000) + try await waitUntil { provider.completedRefreshCount == 1 } + XCTAssertEqual(helper.suggestionsForTesting, [first, clicked]) let handled = helper.handleCommandIfNeeded( textView: textView, @@ -94,11 +95,9 @@ final class TextFieldMentionHelpersTests: XCTestCase { private func waitUntil( _ condition: @escaping @MainActor () -> Bool ) async throws { - for _ in 0 ..< 100 { - if condition() { return } - try await Task.sleep(nanoseconds: 10_000_000) - } - XCTFail("Timed out waiting for condition") + try await AsyncTestWait.waitUntil( + "text-field mention condition" + ) { await MainActor.run { condition() } } } } @@ -108,6 +107,7 @@ private final class DelayedSuggestionProvider { let refreshed: [MentionSuggestion] private var continuation: CheckedContinuation<[MentionSuggestion], Never>? private(set) var callCount = 0 + private(set) var completedRefreshCount = 0 init(initial: [MentionSuggestion], refreshed: [MentionSuggestion]) { self.initial = initial @@ -119,9 +119,11 @@ private final class DelayedSuggestionProvider { if callCount == 1 { return initial } - return await withCheckedContinuation { continuation in + let suggestions = await withCheckedContinuation { continuation in self.continuation = continuation } + completedRefreshCount += 1 + return suggestions } func completeRefresh() { diff --git a/Tests/RepoPromptTests/Services/VCS/GitLoadedRootAuthorityEvidenceTests.swift b/Tests/RepoPromptTests/Services/VCS/GitLoadedRootAuthorityEvidenceTests.swift index 0a8621046..0a6f9c1c7 100644 --- a/Tests/RepoPromptTests/Services/VCS/GitLoadedRootAuthorityEvidenceTests.swift +++ b/Tests/RepoPromptTests/Services/VCS/GitLoadedRootAuthorityEvidenceTests.swift @@ -812,7 +812,9 @@ final class GitLoadedRootAuthorityEvidenceTests: XCTestCase { } var values: [Data] = [] for try await value in group { - if let value { values.append(value) } + if let value { + values.append(value) + } } return values } @@ -1002,16 +1004,13 @@ final class GitLoadedRootAuthorityEvidenceTests: XCTestCase { } private func waitUntil( - file: StaticString = #filePath, - line: UInt = #line, _ predicate: @escaping () async -> Bool ) async throws { - let deadline = Date().addingTimeInterval(2) - repeat { - if await predicate() { return } - try await Task.sleep(nanoseconds: 1_000_000) - } while Date() < deadline - XCTFail("Timed out waiting for deterministic cache state", file: file, line: line) + try await AsyncTestWait.waitUntil( + "deterministic Git authority cache state", + timeout: 2, + condition: predicate + ) } func testStaleCatalogBatchFailsClosedAndLeavesNoReusableAdmission() async throws { @@ -1131,7 +1130,9 @@ final class GitLoadedRootAuthorityEvidenceTests: XCTestCase { return false } while let url = enumerator.nextObject() as? URL { - if url.lastPathComponent.hasPrefix("run.") { return true } + if url.lastPathComponent.hasPrefix("run.") { + return true + } } return false } @@ -1988,7 +1989,9 @@ private actor PrefixControlCollectorGate { } func waitUntilCollectionStarts() async { - if count > 0 { return } + if count > 0 { + return + } await withCheckedContinuation { collectionStartWaiters.append($0) } } } diff --git a/Tests/RepoPromptTests/Services/VCS/GitProcessAdmissionControllerTests.swift b/Tests/RepoPromptTests/Services/VCS/GitProcessAdmissionControllerTests.swift index 02014aa9e..ecb0ffc1f 100644 --- a/Tests/RepoPromptTests/Services/VCS/GitProcessAdmissionControllerTests.swift +++ b/Tests/RepoPromptTests/Services/VCS/GitProcessAdmissionControllerTests.swift @@ -199,30 +199,55 @@ final class GitProcessAdmissionControllerTests: XCTestCase { XCTAssertEqual(snapshot.activeLeaseCount, 0) } - func testBudgetsBoundGlobalAndPerRepositoryConcurrency() async { + func testBudgetsBoundGlobalAndPerRepositoryConcurrency() async throws { let controller = GitProcessAdmissionController(globalLimit: 2, perRepositoryLimit: 1) let probe = GitAdmissionProbe() let repositories = ["repo-a", "repo-a", "repo-b", "repo-c"] - await withTaskGroup(of: Void.self) { group in - for repository in repositories { - group.addTask { - do { - let lease = try await controller.acquire(repositoryKey: repository) - await probe.enter(repository: repository) - try? await Task.sleep(nanoseconds: 30_000_000) - await probe.leave(repository: repository) - await controller.release(lease) - } catch { - XCTFail("unexpected admission failure: \(error)") - } + let runAdmission: (String) -> Task = { repository in + Task { + do { + let lease = try await controller.acquire(repositoryKey: repository) + await probe.enterAndWait(repository: repository) + await probe.leave(repository: repository) + await controller.release(lease) + } catch { + XCTFail("unexpected admission failure: \(error)") } } } - let snapshot = await probe.snapshot() - XCTAssertLessThanOrEqual(snapshot.peakGlobal, 2) - XCTAssertLessThanOrEqual(snapshot.peakByRepository["repo-a"] ?? 0, 1) + let firstTask = runAdmission(repositories[0]) + try await AsyncTestWait.waitUntil("repo-a Git permit to be active") { + await probe.snapshot().activeByRepository["repo-a"] == 1 + } + let tasks = [firstTask] + repositories.dropFirst().map(runAdmission) + + do { + try await AsyncTestWait.waitUntil("both global Git permits and repo-a to be active") { + let snapshot = await probe.snapshot() + return snapshot.activeGlobal == 2 && snapshot.activeByRepository["repo-a"] == 1 + } + } catch { + await probe.releaseAll() + for task in tasks { + task.cancel() + await task.value + } + throw error + } + + var snapshot = await probe.snapshot() + XCTAssertEqual(snapshot.activeGlobal, 2) + XCTAssertEqual(snapshot.activeByRepository["repo-a"], 1) + await probe.releaseAll() + for task in tasks { + await task.value + } + + snapshot = await probe.snapshot() + XCTAssertEqual(snapshot.peakGlobal, 2) + XCTAssertEqual(snapshot.peakByRepository["repo-a"], 1) XCTAssertEqual(snapshot.completed, repositories.count) } @@ -247,11 +272,10 @@ final class GitProcessAdmissionControllerTests: XCTestCase { private func waitUntil( _ predicate: @escaping () async -> Bool ) async throws { - for _ in 0 ..< 10000 { - if await predicate() { return } - await Task.yield() - } - XCTFail("Timed out waiting for Git admission state") + try await AsyncTestWait.waitUntil( + "Git process admission state", + condition: predicate + ) } private func admissionTask( @@ -351,8 +375,10 @@ private actor GitAdmissionProbe { private var peakGlobal = 0 private var peakByRepository: [String: Int] = [:] private var completed = 0 + private var released = false + private var releaseWaiters: [CheckedContinuation] = [] - func enter(repository: String) { + func enterAndWait(repository: String) async { activeGlobal += 1 activeByRepository[repository, default: 0] += 1 peakGlobal = max(peakGlobal, activeGlobal) @@ -360,6 +386,10 @@ private actor GitAdmissionProbe { peakByRepository[repository] ?? 0, activeByRepository[repository] ?? 0 ) + if released { + return + } + await withCheckedContinuation { releaseWaiters.append($0) } } func leave(repository: String) { @@ -368,7 +398,20 @@ private actor GitAdmissionProbe { completed += 1 } - func snapshot() -> (peakGlobal: Int, peakByRepository: [String: Int], completed: Int) { - (peakGlobal, peakByRepository, completed) + func releaseAll() { + released = true + let waiters = releaseWaiters + releaseWaiters.removeAll() + waiters.forEach { $0.resume() } + } + + func snapshot() -> ( + activeGlobal: Int, + activeByRepository: [String: Int], + peakGlobal: Int, + peakByRepository: [String: Int], + completed: Int + ) { + (activeGlobal, activeByRepository, peakGlobal, peakByRepository, completed) } } diff --git a/Tests/RepoPromptTests/Services/VCS/GitWorkspaceStateAuthorityTests.swift b/Tests/RepoPromptTests/Services/VCS/GitWorkspaceStateAuthorityTests.swift index d0745cc5f..eccc3be59 100644 --- a/Tests/RepoPromptTests/Services/VCS/GitWorkspaceStateAuthorityTests.swift +++ b/Tests/RepoPromptTests/Services/VCS/GitWorkspaceStateAuthorityTests.swift @@ -360,15 +360,12 @@ final class GitWorkspaceStateAuthorityTests: XCTestCase { } private func waitUntil( - file: StaticString = #filePath, - line: UInt = #line, _ predicate: @escaping () async -> Bool ) async throws { - for _ in 0 ..< 1000 { - if await predicate() { return } - try await Task.sleep(for: .milliseconds(1)) - } - XCTFail("Timed out waiting for authority invalidation", file: file, line: line) + try await AsyncTestWait.waitUntil( + "Git workspace authority invalidation", + condition: predicate + ) } } diff --git a/Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift b/Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift index 5fc964935..f9473d961 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/Search/StoreBackedWorkspaceSearchTests.swift @@ -2618,73 +2618,6 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { } #endif - func testBroadSearchOrchestrationChecksScopeAndReadinessBeforeAndAfterAdmission() throws { - let source = try String( - contentsOf: RepoRoot.url().appendingPathComponent("Sources/RepoPrompt/Features/Search/StoreBackedWorkspaceSearch.swift"), - encoding: .utf8 - ) - try assertOrdered([ - "try await ensureRootScopeAvailable(rootScope, store: store)", - "let readinessTicket = try await acquireSearchReadiness(", - "readinessTicket: readinessTicket,", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let effectiveMode = mode == .auto ? FileSearchActor.inferredAutoMode(pattern) : mode", - "return try await store.withStoreBackedSearchAccess(", - "if admissionClass != nil {", - "try await ensureRootScopeAvailable(", - "readinessTicket: readinessTicket,", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "var parsedSearchScope:", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let freshnessRootRefs:", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "appliedIngressSamples = try await awaitAppliedIngress(", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let contentFreshnessPolicy = await store.contentSearchFreshnessPolicy(", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "parsedSearchScope = await refreshExactSearchScopeClauses(", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "return try await performSearch(" - ], in: source) - let performSearchStart = try XCTUnwrap(source.range(of: "private static func performSearch(")) - try assertOrdered([ - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let catalogRequirement: WorkspaceSearchCatalogAccessRequirement = switch mode", - "let catalogAccess = await store.searchCatalogAccess(", - "requirement: catalogRequirement", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let visibleRootRefs = await store.rootRefs(scope: .visibleWorkspace)", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "let filterResult = await withTaskCancellationHandler", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "results = try await EditFlowPerf.measure(", - "try await fileSearchActor.searchUnified(", - "try await validateSearchReadiness(readinessTicket, workspaceManager: workspaceManager)", - "results.scopedFileCount = filesToSearch.count" - ], in: String(source[performSearchStart.lowerBound...])) - } - - func testSearchScopeParserKeepsRequiredResolutionOrder() throws { - let source = try String( - contentsOf: RepoRoot.url().appendingPathComponent("Sources/RepoPrompt/Features/Search/StoreBackedWorkspaceSearch.swift"), - encoding: .utf8 - ) - try assertOrdered([ - "let hasWildcard = normalized.contains(\"*\")", - "if hasWildcard {", - "await store.exactPathResolutionIssue(for: normalized, kind: .either, rootScope: rootScope)", - "await store.lookupDiscoverableCatalogPathForExactAbsoluteSearchScope(", - "let lookupResults = await store.lookupPaths(lookupRequests)", - "appendClause(.legacyPrefix(candidateLower: normalizedPath.lowercased()))", - "await store.lookupDiscoverablePath(" - ], in: source) - XCTAssertEqual( - source.components(separatedBy: "parseSearchScopePaths(").count - 1, - 2, - "Explicit search paths must be parsed once, then exact clauses refreshed by root-local lookup" - ) - } - private func searchSwiftFiles(paths: [String], store: WorkspaceFileContextStore) async throws -> SearchResults { try await StoreBackedWorkspaceSearch.search( pattern: "*.swift", @@ -2763,14 +2696,10 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { file: StaticString = #filePath, line: UInt = #line ) async throws { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while manager.workspaceSearchReadinessWaiterCountForTesting != expectedCount, - waited < timeoutNanoseconds - { - try await Task.sleep(nanoseconds: interval) - waited += interval - } + try await AsyncTestWait.waitUntil( + "workspace search readiness waiter count \(expectedCount)", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await MainActor.run { manager.workspaceSearchReadinessWaiterCountForTesting == expectedCount } } XCTAssertEqual( manager.workspaceSearchReadinessWaiterCountForTesting, expectedCount, @@ -2812,41 +2741,42 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { store: WorkspaceFileContextStore, timeoutNanoseconds: UInt64 = 1_000_000_000 ) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while await store.searchLaneSnapshotForTesting().waiterCount != expectedCount, waited < timeoutNanoseconds { - try? await Task.sleep(nanoseconds: interval) - waited += interval + do { + try await AsyncTestWait.waitUntil( + "search admission waiter count \(expectedCount)", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await store.searchLaneSnapshotForTesting().waiterCount == expectedCount } + return true + } catch { + return false } - return await store.searchLaneSnapshotForTesting().waiterCount == expectedCount } private func waitForSearchLaneIdle( store: WorkspaceFileContextStore, timeoutNanoseconds: UInt64 = 1_000_000_000 ) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while await !store.searchLaneSnapshotForTesting().isIdle, waited < timeoutNanoseconds { - try? await Task.sleep(nanoseconds: interval) - waited += interval + do { + try await AsyncTestWait.waitUntil( + "search lane to become idle", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await store.searchLaneSnapshotForTesting().isIdle } + return true + } catch { + return false } - return await store.searchLaneSnapshotForTesting().isIdle } private func waitForCacheIdle( store: WorkspaceFileContextStore, timeoutNanoseconds: UInt64 = 1_000_000_000 ) async -> WorkspaceSearchDecodedContentCache.Snapshot { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while waited < timeoutNanoseconds { + try? await AsyncTestWait.waitUntil( + "decoded-content cache to become idle", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { let snapshot = await store.searchDecodedContentCacheSnapshotForTesting() - if snapshot.activeFlightCount == 0, snapshot.waiterCount == 0 { - return snapshot - } - try? await Task.sleep(nanoseconds: interval) - waited += interval + return snapshot.activeFlightCount == 0 && snapshot.waiterCount == 0 } return await store.searchDecodedContentCacheSnapshotForTesting() } @@ -2856,19 +2786,19 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { correlationID: UUID, timeoutNanoseconds: UInt64 = 1_000_000_000 ) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while waited < timeoutNanoseconds { - let snapshot = EditFlowPerf.debugCaptureSnapshot(finish: false) - if snapshot.lifecycleEvents.contains(where: { - $0.eventName == eventName && $0.correlationID == correlationID.uuidString - }) { - return true + do { + try await AsyncTestWait.waitUntil( + "lifecycle event \(eventName)", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { + EditFlowPerf.debugCaptureSnapshot(finish: false).lifecycleEvents.contains { + $0.eventName == eventName && $0.correlationID == correlationID.uuidString + } } - try? await Task.sleep(nanoseconds: interval) - waited += interval + return true + } catch { + return false } - return false } private func dimensionInt(_ key: String, in dimensions: String) -> Int? { @@ -2890,14 +2820,6 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { } #endif - private func assertOrdered(_ needles: [String], in source: String) throws { - var lowerBound = source.startIndex - for needle in needles { - let range = try XCTUnwrap(source.range(of: needle, range: lowerBound ..< source.endIndex), "Missing ordered source fragment: \(needle)") - lowerBound = range.upperBound - } - } - #if DEBUG private actor AsyncCounter { private var count = 0 @@ -2912,13 +2834,15 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { } func waitUntilValue(atLeast target: Int, timeoutNanoseconds: UInt64 = 1_000_000_000) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while count < target, waited < timeoutNanoseconds { - try? await Task.sleep(nanoseconds: interval) - waited += interval + do { + try await AsyncTestWait.waitUntil( + "async counter value \(target)", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await self.count >= target } + return true + } catch { + return false } - return count >= target } } @@ -2930,13 +2854,15 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { } func waitUntilMarked(timeoutNanoseconds: UInt64 = 1_000_000_000) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while !marked, waited < timeoutNanoseconds { - try? await Task.sleep(nanoseconds: interval) - waited += interval + do { + try await AsyncTestWait.waitUntil( + "async signal to be marked", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await self.marked } + return true + } catch { + return false } - return marked } } @@ -2969,13 +2895,15 @@ final class StoreBackedWorkspaceSearchTests: XCTestCase { } func waitUntilStartedCount(_ expectedCount: Int, timeoutNanoseconds: UInt64 = 1_000_000_000) async -> Bool { - let interval: UInt64 = 10_000_000 - var waited: UInt64 = 0 - while startedCount < expectedCount, waited < timeoutNanoseconds { - try? await Task.sleep(nanoseconds: interval) - waited += interval + do { + try await AsyncTestWait.waitUntil( + "async gate start count \(expectedCount)", + timeout: TimeInterval(timeoutNanoseconds) / 1_000_000_000 + ) { await self.startedCount >= expectedCount } + return true + } catch { + return false } - return startedCount >= expectedCount } func release() { diff --git a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceFileSearchIndexBenchmarkSupport.swift b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceFileSearchIndexBenchmarkSupport.swift index 50c870742..83de3de6f 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceFileSearchIndexBenchmarkSupport.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceFileSearchIndexBenchmarkSupport.swift @@ -913,21 +913,6 @@ return value } - private func distributionDictionary(_ distribution: WorkspaceBenchmarkDistribution) -> [String: Any] { - [ - "retainedSampleCount": distribution.rawValues.count, - "rawValues": distribution.rawValues, - "mean": distribution.mean, - "median": distribution.median, - "nearestRankP95": distribution.nearestRankP95, - "sampleVariance": distribution.sampleVariance, - "sampleStandardDeviation": distribution.sampleStandardDeviation, - "coefficientOfVariation": distribution.coefficientOfVariation.map { $0 as Any } ?? NSNull(), - "minimum": distribution.minimum, - "maximum": distribution.maximum - ] - } - private func validityIssueDictionary(_ issue: WorkspaceBenchmarkValidityIssue) -> [String: Any] { ["code": issue.code, "detail": issue.detail] } @@ -1343,10 +1328,6 @@ return lines } - private func markdownEscaped(_ value: String) -> String { - value.replacingOccurrences(of: "|", with: "\\|") - } - private func coldStartRows(_ aggregate: WorkspaceFileSearchIndexBenchmarkAggregate) -> [String] { var lines = [ "", diff --git a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift index fc53cf130..8e62851c6 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspacePerRootPathSearchIndexTests.swift @@ -547,31 +547,27 @@ import XCTest private func waitForIndexedGeneration( _ expected: UInt64, service: WorkspaceSearchService, - timeout: TimeInterval = 2.0, - file: StaticString = #filePath, - line: UInt = #line + timeout: TimeInterval = 2.0 ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await service.indexedGeneration == expected { return } - try await Task.sleep(nanoseconds: 10_000_000) + try await AsyncTestWait.waitUntil( + "per-root indexed workspace search generation \(expected)", + timeout: timeout + ) { + await service.indexedGeneration == expected } - XCTFail("Timed out waiting for indexed generation \(expected)", file: file, line: line) } private func waitForPendingGeneration( _ expected: UInt64, service: WorkspaceSearchService, - timeout: TimeInterval = 2.0, - file: StaticString = #filePath, - line: UInt = #line + timeout: TimeInterval = 2.0 ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await service.pendingGeneration == expected { return } - try await Task.sleep(nanoseconds: 10_000_000) + try await AsyncTestWait.waitUntil( + "per-root pending workspace search generation \(expected)", + timeout: timeout + ) { + await service.pendingGeneration == expected } - XCTFail("Timed out waiting for pending generation \(expected)", file: file, line: line) } private func makeTemporaryRoot(name: String) throws -> URL { @@ -612,7 +608,9 @@ import XCTest } func waitUntilEntered() async -> UInt64? { - if enteredGeneration != nil { return enteredGeneration } + if enteredGeneration != nil { + return enteredGeneration + } return await withCheckedContinuation { continuation in enteredWaiters.append(continuation) } diff --git a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift index 1e4efa0ee..0ceff1cf5 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/Search/WorkspaceSearchServiceTests.swift @@ -330,37 +330,27 @@ final class WorkspaceSearchServiceTests: XCTestCase { private func waitForIndexedGeneration( _ expectedGeneration: UInt64, service: WorkspaceSearchService, - timeout: TimeInterval = 2.0, - file: StaticString = #filePath, - line: UInt = #line + timeout: TimeInterval = 2.0 ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await service.indexedGeneration == expectedGeneration { - return - } - try await Task.sleep(nanoseconds: 10_000_000) + try await AsyncTestWait.waitUntil( + "indexed workspace search generation \(expectedGeneration)", + timeout: timeout + ) { + await service.indexedGeneration == expectedGeneration } - let actual = await service.indexedGeneration - XCTFail("Timed out waiting for indexed generation \(expectedGeneration); actual=\(String(describing: actual))", file: file, line: line) } private func waitForPendingGeneration( _ expectedGeneration: UInt64, service: WorkspaceSearchService, - timeout: TimeInterval = 2.0, - file: StaticString = #filePath, - line: UInt = #line + timeout: TimeInterval = 2.0 ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if await service.pendingGeneration == expectedGeneration { - return - } - try await Task.sleep(nanoseconds: 10_000_000) + try await AsyncTestWait.waitUntil( + "pending workspace search generation \(expectedGeneration)", + timeout: timeout + ) { + await service.pendingGeneration == expectedGeneration } - let actual = await service.pendingGeneration - XCTFail("Timed out waiting for pending generation \(expectedGeneration); actual=\(String(describing: actual))", file: file, line: line) } private func makeTemporaryRoot(name: String) throws -> URL { diff --git a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGitCapabilityServiceTests.swift b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGitCapabilityServiceTests.swift index db9fb190f..a79f0215d 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGitCapabilityServiceTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapGitCapabilityServiceTests.swift @@ -893,12 +893,12 @@ final class WorkspaceCodemapGitCapabilityServiceTests: XCTestCase { let first = Task { await service.resolve(root: rootRequest) } let second = Task { await service.resolve(root: rootRequest) } - await waitForEntryCount(2, gate: gate) - await waitForWaiterCount(2, service: service) + try await waitForEntryCount(2, gate: gate) + try await waitForWaiterCount(2, service: service) first.cancel() await assertEqual(first.value, .eligible(initial)) - await waitForWaiterCount(1, service: service) + try await waitForWaiterCount(1, service: service) await assertEqual(service.state(for: rootRequest.rootEpoch), .resolving(generation: 2)) await gate.resumeAll() @@ -923,10 +923,10 @@ final class WorkspaceCodemapGitCapabilityServiceTests: XCTestCase { let rootRequest = request(for: root, seed: 61) let task = Task { await service.resolve(root: rootRequest) } - await waitForEntryCount(1, gate: gate) + try await waitForEntryCount(1, gate: gate) task.cancel() await assertEqual(task.value, .unresolved) - await waitForWaiterCount(0, service: service) + try await waitForWaiterCount(0, service: service) await assertEqual(service.state(for: rootRequest.rootEpoch), .unresolved) await gate.resumeAll() @@ -954,7 +954,7 @@ final class WorkspaceCodemapGitCapabilityServiceTests: XCTestCase { let staleRequest = request(for: staleRoot, seed: 71) await gate.setPaused(true) let staleTask = Task { await service.resolve(root: staleRequest) } - await waitForEntryCount(2, gate: gate) + try await waitForEntryCount(2, gate: gate) await service.release(rootEpoch: staleRequest.rootEpoch) await assertEqual(staleTask.value, .unresolved) await gate.resumeAll() @@ -1116,23 +1116,19 @@ final class WorkspaceCodemapGitCapabilityServiceTests: XCTestCase { ) } - private func waitForEntryCount(_ expected: Int, gate: CapabilityResolutionGate) async { - for _ in 0 ..< 500 { - if await gate.entryCount() >= expected { return } - try? await Task.sleep(for: .milliseconds(2)) + private func waitForEntryCount(_ expected: Int, gate: CapabilityResolutionGate) async throws { + try await AsyncTestWait.waitUntil("\(expected) capability resolution entries") { + await gate.entryCount() >= expected } - XCTFail("Timed out waiting for \(expected) capability resolution entries") } private func waitForWaiterCount( _ expected: Int, service: WorkspaceCodemapGitCapabilityService - ) async { - for _ in 0 ..< 500 { - if await service.snapshotForTesting().waiterCount == expected { return } - try? await Task.sleep(for: .milliseconds(2)) + ) async throws { + try await AsyncTestWait.waitUntil("\(expected) capability resolution waiters") { + await service.snapshotForTesting().waiterCount == expected } - XCTFail("Timed out waiting for \(expected) capability waiters") } private func fakeGitScript(topLevel: String) -> String { diff --git a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift index 9641b994c..0c6f4b78e 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceCodemapLiveOverlayTests.swift @@ -196,7 +196,11 @@ final class WorkspaceCodemapLiveOverlayTests: XCTestCase { let snapshot = try unwrapValue(snapshotValue) assertEqualValue(snapshot.entries.count, 2) assertTrueValue(snapshot.entries.allSatisfy { - if case .shadowed(.renamed) = $0.state { true } else { false } + if case .shadowed(.renamed) = $0.state { + true + } else { + false + } }) } @@ -1629,7 +1633,7 @@ final class WorkspaceCodemapLiveOverlayTests: XCTestCase { assertEqualValue(terminalAccounting.entryCount, 0) assertEqualValue(terminalAccounting.shadowEntryCount, 0) assertEqualValue(terminalAccounting.leaseCount, 0) - try await eventually { + try await AsyncTestWait.waitUntil("artifact store active lease drain") { await fixture.artifactStore.accounting().activeLeaseCount == 0 } } @@ -3670,19 +3674,6 @@ final class WorkspaceCodemapLiveOverlayTests: XCTestCase { ) } - private func eventually( - timeoutNanoseconds: UInt64 = 2_000_000_000, - condition: @escaping @Sendable () async -> Bool - ) async throws { - let start = ContinuousClock.now - while await !condition() { - if ContinuousClock.now - start > .nanoseconds(Int64(timeoutNanoseconds)) { - throw TestError.timeout - } - try await Task.sleep(nanoseconds: 10_000_000) - } - } - private func uuid(_ value: String) -> UUID { UUID(uuidString: value)! } @@ -3810,5 +3801,4 @@ private enum TestError: Error { case artifactMissing case artifactOutcomeMismatch case cleanSourceExpected - case timeout } diff --git a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift index 4a6561045..e675ce7f5 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceFileContextStoreTests.swift @@ -5,24 +5,6 @@ import CryptoKit import RepoPromptCodeMapCore import XCTest -private enum CodemapInitializationResetBoundary: String, CaseIterable { - case cancelAll - case checkoutMutation - case cacheClear -} - -private actor UUIDRecorder { - private var values: [UUID] = [] - - func append(_ value: UUID) { - values.append(value) - } - - func snapshot() -> [UUID] { - values - } -} - final class WorkspaceFileContextStoreTests: XCTestCase { private var cancellables = Set() @@ -3572,7 +3554,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { for _ in 0 ..< 1000 { let stats = await store.scopedIngressBarrierStatsForTesting(rootID: rootID) - if await flushGate.startCount() >= 3 || stats.coalescedSuccessorCount == 1 { break } + if await flushGate.startCount() >= 3 || stats.coalescedSuccessorCount == 1 { + break + } await Task.yield() } clock.advance(milliseconds: 175) @@ -3683,7 +3667,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { await store.awaitAppliedIngressForAllRoots() } for _ in 0 ..< 1000 { - if await flushGate.startCount() >= 8 { break } + if await flushGate.startCount() >= 8 { + break + } await Task.yield() } for _ in 0 ..< 50 { @@ -8008,7 +7994,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { private var cancelledWaiterIDs: Set = [] func sleep(nanoseconds: UInt64) async { - if releasedNanoseconds.contains(nanoseconds) { return } + if releasedNanoseconds.contains(nanoseconds) { + return + } let waiterID = UUID() await withTaskCancellationHandler { await withCheckedContinuation { continuation in @@ -8116,7 +8104,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { let clock = ContinuousClock() let deadline = clock.now.advanced(by: timeout) while clock.now < deadline { - if await condition() { return true } + if await condition() { + return true + } await Task.yield() } return await condition() @@ -8245,28 +8235,6 @@ final class WorkspaceFileContextStoreTests: XCTestCase { } } - @MainActor - private func waitUntilRootFolderVisible( - manager: WorkspaceFilesViewModel, - timeout: TimeInterval = 5, - file: StaticString = #filePath, - line: UInt = #line - ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if !manager.rootFolders.isEmpty { - return - } - try await Task.sleep(nanoseconds: 10_000_000) - } - XCTFail("Timed out waiting for partial root UI append", file: file, line: line) - } - - private func readWorkspaceFilesViewModelSource() throws -> String { - let root = try RepoRoot.url() - let url = root.appendingPathComponent("Sources/RepoPrompt/Features/WorkspaceFiles/ViewModels/WorkspaceFilesViewModel.swift") - return try String(contentsOf: url, encoding: .utf8) - } #endif func testValidatedReadAndSearchSnapshotsPublishExactPreEditSourceAndFenceFileIdentity() async throws { @@ -8295,7 +8263,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { var events: [WorkspaceAppliedIndexBatchEvent] = [] for await event in stream where !event.modifiedFileIDs.isEmpty { events.append(event) - if events.count == 3 { return events } + if events.count == 3 { + return events + } } return events } @@ -8374,7 +8344,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { try await Task.sleep(nanoseconds: 20_000_000) } let file = try XCTUnwrap(manager.findFileByFullPath(fullPath)) - if let id { XCTAssertEqual(file.id, id) } + if let id { + XCTAssertEqual(file.id, id) + } return file } @@ -8387,7 +8359,9 @@ final class WorkspaceFileContextStoreTests: XCTestCase { try await Task.sleep(nanoseconds: 20_000_000) } let folder = try XCTUnwrap(manager.findFolderByFullPath(fullPath)) - if let id { XCTAssertEqual(folder.id, id) } + if let id { + XCTAssertEqual(folder.id, id) + } return folder } diff --git a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceSelectionCoordinatorTests.swift b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceSelectionCoordinatorTests.swift index 331211ff1..1c0b2661d 100644 --- a/Tests/RepoPromptTests/WorkspaceContext/WorkspaceSelectionCoordinatorTests.swift +++ b/Tests/RepoPromptTests/WorkspaceContext/WorkspaceSelectionCoordinatorTests.swift @@ -901,20 +901,18 @@ private actor SelectionMirrorGate { private var started = false private var released = false - func markStartedAndWaitForRelease(timeout: Duration = .seconds(5)) async { + func markStartedAndWaitForRelease(timeout: TimeInterval = 5) async { started = true - let deadline = ContinuousClock.now + timeout - while !released, ContinuousClock.now < deadline { - try? await Task.sleep(for: .milliseconds(10)) - } + try? await AsyncTestWait.waitUntil("selection mirror gate release", timeout: timeout) { await self.released } } - func waitUntilStarted(timeout: Duration = .seconds(2)) async -> Bool { - let deadline = ContinuousClock.now + timeout - while !started, ContinuousClock.now < deadline { - try? await Task.sleep(for: .milliseconds(10)) + func waitUntilStarted(timeout: TimeInterval = 2) async -> Bool { + do { + try await AsyncTestWait.waitUntil("selection mirror gate start", timeout: timeout) { await self.started } + return true + } catch { + return false } - return started } func release() { @@ -934,12 +932,15 @@ private actor SelectionMirrorCompletion { completedCount += 1 } - func waitUntilComplete(timeout: Duration = .seconds(2)) async -> Bool { - let deadline = ContinuousClock.now + timeout - while completedCount < expectedCount, ContinuousClock.now < deadline { - try? await Task.sleep(for: .milliseconds(10)) + func waitUntilComplete(timeout: TimeInterval = 2) async -> Bool { + do { + try await AsyncTestWait.waitUntil("selection mirror completion", timeout: timeout) { + await self.completedCount == self.expectedCount + } + return true + } catch { + return false } - return completedCount == expectedCount } } diff --git a/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchPresentationTests.swift b/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchPresentationTests.swift index dff319f86..c8ee219c0 100644 --- a/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchPresentationTests.swift +++ b/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchPresentationTests.swift @@ -174,12 +174,14 @@ final class WorkspaceSwitchPresentationTests: XCTestCase { line: UInt = #line, _ condition: @escaping @MainActor () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try await Task.sleep(nanoseconds: 10_000_000) + do { + try await AsyncTestWait.waitUntil("workspace switch presentation condition", timeout: timeout) { + await MainActor.run { condition() } + } + } catch { + XCTFail("Timed out waiting for workspace switch presentation condition: \(error)", file: file, line: line) + throw error } - XCTFail("Timed out waiting for condition", file: file, line: line) } } diff --git a/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchRecoveryTests.swift b/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchRecoveryTests.swift index e05cdb5b6..ab0f61a0f 100644 --- a/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchRecoveryTests.swift +++ b/Tests/RepoPromptTests/Workspaces/WorkspaceSwitchRecoveryTests.swift @@ -725,7 +725,6 @@ final class WorkspaceSwitchRecoveryTests: XCTestCase { XCTAssertTrue(returnFromBResult.didSwitch) assertSelectionFixture(fixture, composition: composition) - try await Task.sleep(nanoseconds: 250_000_000) await manager.pollAndSaveStateAsync() let workspaceURL = manager.workspaceFileURL(for: fixture.workspace) let saved = try WorkspaceManagerViewModel.loadWorkspaceFromFile(at: workspaceURL) @@ -752,7 +751,6 @@ final class WorkspaceSwitchRecoveryTests: XCTestCase { XCTAssertEqual(manager.activeWorkspaceID, fixture.workspace.id) assertSelectionFixture(fixture, composition: composition) - try await Task.sleep(nanoseconds: 250_000_000) await manager.pollAndSaveStateAsync() let workspaceURL = manager.workspaceFileURL(for: fixture.workspace) let saved = try WorkspaceManagerViewModel.loadWorkspaceFromFile(at: workspaceURL) @@ -1388,12 +1386,14 @@ final class WorkspaceSwitchRecoveryTests: XCTestCase { line: UInt = #line, _ condition: @escaping @MainActor () -> Bool ) async throws { - let deadline = Date().addingTimeInterval(timeout) - while Date() < deadline { - if condition() { return } - try await Task.sleep(nanoseconds: 10_000_000) + do { + try await AsyncTestWait.waitUntil("workspace switch recovery condition", timeout: timeout) { + await MainActor.run { condition() } + } + } catch { + XCTFail("Timed out waiting for workspace switch recovery condition: \(error)", file: file, line: line) + throw error } - XCTFail("Timed out waiting for condition", file: file, line: line) } } @@ -1498,7 +1498,9 @@ private actor WorkspaceSwitchManualSleeper { private var cancelledWaiterIDs: Set = [] func sleep(nanoseconds: UInt64) async { - if releasedNanoseconds.contains(nanoseconds) { return } + if releasedNanoseconds.contains(nanoseconds) { + return + } let waiterID = UUID() await withTaskCancellationHandler { await withCheckedContinuation { continuation in @@ -1564,14 +1566,18 @@ private actor WorkspaceSwitchRecoveryGate { } func waitUntilArrived() async { - if arrived { return } + if arrived { + return + } await withCheckedContinuation { continuation in arrivalContinuations.append(continuation) } } func waitUntilCompleted() async { - if completed { return } + if completed { + return + } await withCheckedContinuation { continuation in completionContinuations.append(continuation) }