# test233 — Grok co-presence integration against current main
date=2026-08-04T08:45:11+00:00
scope=resolved CLI symbols, Grok runtime, dashboard inbox lanes, Codex session manager

$ grok-runtime bun test /workspace/agent-node/src/runtime/grok-copresence
bun test v1.3.1 (89fa0f34)

agent-node/src/runtime/grok-copresence/profile-process.test.ts:
(pass) Grok co-presence profile is pinned for the whole process > same input yields two exact, non-overlapping process capabilities [149.01ms]

agent-node/src/runtime/grok-copresence/jsonl.test.ts:
(pass) Grok copresence envelope and user parsing > parses only an exact, query-anchored Agent Network envelope
(pass) Grok copresence envelope and user parsing > extracts the first authoritative user_query from string or Grok text-array content [1.00ms]
(pass) Grok copresence envelope and user parsing > does not trust a syntactically valid prefix unless the bridge registered it [2.00ms]
(pass) Grok copresence envelope and user parsing > nested user_query text cannot turn an owned network task into human delegation [1.00ms]
(pass) Grok copresence turn reducer > waits for completion and replies with the last non-empty assistant record
(pass) Grok copresence turn reducer > keeps the last no-tool assistant when later tool-bearing chatter exists [1.00ms]
(pass) Grok copresence turn reducer > handles completion/chat-history polling order without returning an empty reply
(pass) Grok copresence turn reducer > does not finalize an intermediate assistant visible before the completion event
(pass) Grok copresence turn reducer > retains a completion observed before even the network user line [1.00ms]
(pass) Grok copresence turn reducer > retains an event-first human completion only for a trusted PTY submission
(pass) Grok copresence turn reducer > never carries an unowned idle completion into a later network task [1.00ms]
(pass) Grok copresence turn reducer > binds an event-first completion to the exact registered network task
(pass) Grok copresence turn reducer > consumes sanitized sample A block content and turn_number boundary
(pass) Grok copresence turn reducer > consumes sanitized sample B and selects only the 14th no-tool assistant [1.00ms]
(pass) Grok copresence turn reducer > ignores standalone system-reminder user records without abandoning a network turn
(pass) Grok copresence turn reducer > fails a terminal record without turn_started and never binds it to the next user [1.00ms]
(pass) Grok copresence turn reducer > never maps a human turn or failed network turn to a network reply
(pass) Grok copresence turn reducer > abandons an unfinished network turn rather than attaching its answer to a human turn [1.00ms]
(pass) Grok copresence turn reducer > pairs events correctly when chat_history leads by two unnumbered turns [1.00ms]
(pass) Grok copresence turn reducer > does not let a new start overtake an abandoned numbered terminal
(pass) Grok completion compatibility and defensive parsing > recognizes only top-level turn_ended with an exact successful outcome
(pass) Grok completion compatibility and defensive parsing > binds turn_started turn_number while permission lifecycle remains inert [1.00ms]
(pass) Grok completion compatibility and defensive parsing > fails a started turn when turn_ended has no outcome
(pass) Grok completion compatibility and defensive parsing > fails closed on an overlapping turn_started epoch
(pass) Grok completion compatibility and defensive parsing > retains only a bounded tail of raw completion candidates
(pass) Grok completion compatibility and defensive parsing > contains malformed and overlong lines instead of parsing or retaining them [2.00ms]
(pass) Grok completion compatibility and defensive parsing > incrementally joins split lines and drops a fragmented oversized line once [2.00ms]
(pass) persistent JSONL tail cursor > starts fresh at end by default, with an explicit start override
(pass) persistent JSONL tail cursor > continues and fails closed on truncate or inode rotation
(pass) persistent JSONL tail cursor > treats corrupt persisted state as non-replayable and advances JSON-safely [1.00ms]

agent-node/src/runtime/grok-copresence/attach.test.ts:
(pass) Grok co-presence local attach server > serves one owner-only client and cleans its socket on close [26.00ms]
(pass) Grok co-presence local attach server > rejects a second client without disturbing the attached human [6.00ms]
(pass) Grok co-presence local attach server > routes input and resize frames only through serialized arbiter callbacks [7.00ms]
(pass) Grok co-presence local attach server > fails closed when an inbound frame exceeds the configured bound [19.00ms]
(pass) Grok co-presence local attach server > refuses symlinks and regular files at the socket path [3.00ms]

agent-node/src/runtime/grok-copresence/state.test.ts:
(pass) Grok co-presence arbitration > lets the first human byte win a simultaneous human/network race [1.00ms]
(pass) Grok co-presence arbitration > gives a newly active human composer priority over an existing FIFO [1.00ms]
(pass) Grok co-presence arbitration > dequeues network tasks FIFO and never preempts an active turn [1.00ms]
(pass) Grok co-presence arbitration > cancels only queued timeouts and rejects duplicate task ids
(pass) Grok co-presence arbitration > retains the active network task and FIFO across disconnect/reconnect [1.00ms]
(pass) Grok co-presence arbitration > marks approvals waiting for the human without emitting a response
(pass) Grok co-presence arbitration > clears an already-waiting preview todo resolution in either active turn without completing it [1.00ms]

agent-node/src/runtime/grok-copresence/profile-wiring.test.ts:
(pass) Grok co-presence profile wiring > pins validated config before dynamically loading the runtime
(pass) Grok co-presence profile wiring > cannot mutate the capability according to a logical turn owner

agent-node/src/runtime/grok-copresence/leader-lifecycle.test.ts:
(pass) Grok auto-Leader lifecycle identity > rejects a different kernel executable hidden behind a pinned argv0 [1.00ms]
(pass) Grok auto-Leader lifecycle identity > rejects a live native listener whose argv0 forges the pinned executable [231.01ms]
(pass) Grok auto-Leader lifecycle identity > terminates one exact generation and removes only its stale socket [100.00ms]
(pass) Grok auto-Leader lifecycle identity > does not adopt a listener whose generation marker differs [218.01ms]
(pass) Grok auto-Leader lifecycle identity > does not signal or unlink after the socket pathname is replaced [74.00ms]
(pass) Grok auto-Leader lifecycle identity > revalidates the exact identity before escalating a TERM-resistant Leader [592.03ms]
(pass) Grok auto-Leader lifecycle identity > does not escalate when a TERM-resistant Leader replaces its listener [358.02ms]
(pass) Grok auto-Leader lifecycle identity > does not signal after the configured binary inode is replaced [75.00ms]
(pass) Grok auto-Leader lifecycle identity > retains the stale socket when another process from the generation remains [289.01ms]

agent-node/src/runtime/grok-copresence/allowlist-near-miss.test.ts:
(pass) grok copresence preview tool profile is an exact value set > a profile tool with an otherwise valid tuple is accepted [1.00ms]
(pass) grok copresence preview tool profile is an exact value set > refuses "todo_write2"
(pass) grok copresence preview tool profile is an exact value set > refuses "search_tool2"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool2"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool_v2"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool-admin"
(pass) grok copresence preview tool profile is an exact value set > refuses "Use_Tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "USE_TOOL"
(pass) grok copresence preview tool profile is an exact value set > refuses "Todo_Write"
(pass) grok copresence preview tool profile is an exact value set > refuses " use_tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool "
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool\n"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_too"
(pass) grok copresence preview tool profile is an exact value set > refuses "tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "not_use_tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "xuse_toolx"
(pass) grok copresence preview tool profile is an exact value set > refuses "ｕｓｅ＿ｔｏｏｌ"
(pass) grok copresence preview tool profile is an exact value set > refuses "use​tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_to​ol"
(pass) grok copresence preview tool profile is an exact value set > refuses ""
(pass) grok copresence preview tool profile is an exact value set > refuses " "
(pass) grok copresence preview tool profile is an exact value set > refuses "Search_Tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "TODO_WRITE"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool\r"
(pass) grok copresence preview tool profile is an exact value set > refuses "use_tool\u0000"
(pass) grok copresence preview tool profile is an exact value set > refuses "x_todo_write"
(pass) grok copresence preview tool profile is an exact value set > refuses "use-tool"
(pass) grok copresence preview tool profile is an exact value set > refuses "todo-write"
(pass) grok copresence preview tool profile is an exact value set > the profile is exactly the three pinned tools

agent-node/src/runtime/grok-copresence/profile-selection.test.ts:
(pass) Grok co-presence process capability profile > accepts only the two exact startup profiles
(pass) Grok co-presence process capability profile > defaults closed and rejects an invalid process profile

agent-node/src/runtime/grok-copresence/runtime.test.ts:
(pass) Grok copresence launch and injection policy > keeps the fixed-tool auto-resolution exception exact and limited to active turns [1.00ms]
(pass) Grok copresence launch and injection policy > admits exact automatic lifecycles only for the fixed preview tool boundary
(pass) Grok copresence launch and injection policy > exposes only reviewed value-free task failure codes and exact JSONL subcodes [1.00ms]
(pass) Grok copresence launch and injection policy > keeps the JSONL subcode allowlist direct, frozen, and actual-path-only
(pass) Grok copresence launch and injection policy > locks the probed Grok TUI build exactly
(pass) Grok copresence launch and injection policy > pins one TUI-effective commhub-only agent profile and hard-denies fallback routes [1.00ms]
(pass) Grok copresence launch and injection policy > rejects terminal escape injection and reserved origin markup [1.00ms]
(pass) Grok copresence launch and injection policy > recognizes the pinned TUI composer footer across ANSI fragments
(pass) Grok copresence launch and injection policy > rejects external permission sources and noninteractive modes [2.00ms]
(pass) Grok copresence runtime integration > terminates the independently persistent auto-Leader and its unchanged stale socket [573.02ms]
(pass) Grok copresence runtime integration > cleans and hardens the exact pinned footprint only after confirmed close [548.02ms]
(pass) Grok copresence runtime integration > cleans each exact sandbox placeholder at its confirmed recovery boundary [910.04ms]
(pass) Grok copresence runtime integration > removes an old placeholder before a recovery generation reuses its PID [1162.05ms]
(pass) Grok copresence runtime integration > queues network input until the pinned TUI composer is ready [1214.05ms]
(pass) Grok copresence runtime integration > maps keyless fake-writer file mutations to exact value-free tail subcodes [3789.16ms]
(pass) Grok copresence runtime integration > continues exactly once across prefix-preserving atomic chat rewrites [2242.09ms]
(pass) Grok copresence runtime integration > rejects an atomic replacement that preserves only the consumed prefix [678.03ms]
(pass) Grok copresence runtime integration > rejects a same-inode shrink below the highest observed size even when offset remains valid [570.02ms]
(pass) Grok copresence runtime integration > does not expose an intermediate atomic generation before its successor preserves it [1129.05ms]
(pass) Grok copresence runtime integration > does not expose a pinned generation unlinked between path check and read [1137.05ms]
(pass) Grok copresence runtime integration > maps chat and events reset callback failures and stops polling after fatal [1483.06ms]
(pass) Grok copresence runtime integration > maps keyless reducer, lifecycle, and combined flush invariants at their boundaries [2429.10ms]
(pass) Grok copresence runtime integration > close waits for and tears down a Leader spawned by in-flight recovery [911.04ms]
(pass) Grok copresence runtime integration > retains containment and lifetime locks when a closing recovery PTY will not stop [2931.12ms]
(pass) Grok copresence runtime integration > excludes a different runtime from the same canonical project for the full TUI lifetime [1117.05ms]
(pass) Grok copresence runtime integration > contains an exited recovery generation before reusing its PID [1734.07ms]
(pass) Grok copresence runtime integration > retains final-cleanup ownership after every failed recovery PID is consumed [926.04ms]
(pass) Grok copresence runtime integration > arbitrates a live PTY, settles final JSONL, attaches once, and resumes [3989.17ms]
(pass) Grok copresence runtime integration > fails closed on automatic permission resolution without a human action [598.03ms]
(pass) Grok copresence runtime integration > accepts only the pinned preview todo_write automatic resolution tuple [1891.08ms]
(pass) Grok copresence runtime integration > keeps the shared TUI alive when the pinned preview auto-resolves todo_write in a human turn [1759.07ms]
(pass) Grok copresence runtime integration > keeps the shared TUI alive across exact search_tool then use_tool in a human turn [1672.07ms]
(pass) Grok copresence runtime integration > rejects every mutated preview todo_write automatic resolution tuple [4030.17ms]
(pass) Grok copresence runtime integration > preserves exact permission lifecycle order across coalesced and split event reads [2316.10ms]
(pass) Grok copresence runtime integration > fails closed on malformed or oversized permission lifecycle JSONL [1168.05ms]
(pass) Grok copresence runtime integration > rejects terminal reordering around automatic permission lifecycles [1722.07ms]
(pass) Grok copresence runtime integration > allows repeated fixed-tool automatic permission lifecycles in one network turn [1088.05ms]
(pass) Grok copresence runtime integration > never replies with a tool-bearing assistant when the final log is delayed past settling [1880.08ms]
(pass) Grok copresence runtime integration > rejects a completed turn that never resolved its approval [605.03ms]
(pass) Grok copresence runtime integration > does not resume a TUI that crashed at an approval prompt [619.03ms]
(pass) Grok copresence runtime integration > rejects a permission record that landed just before the crash poll [970.04ms]
(pass) Grok copresence runtime integration > refuses process-level resume with a persisted unresolved approval [247.01ms]
(pass) Grok copresence runtime integration > permits process-level resume after a persisted approval was resolved [553.02ms]
(pass) Grok copresence runtime integration > arms both resume tails before spawn-time permission records can be skipped [315.01ms]
(pass) Grok copresence runtime integration > discards spawn-time orphan completions before accepting the first new network task [1144.05ms]
(pass) Grok copresence runtime integration > drains more than one tail chunk before attach and fully cleans a startup rejection [900.04ms]
(pass) Grok copresence runtime integration > accepts the pinned startup auto-approval transition [571.02ms]
(pass) Grok copresence runtime integration > reruns the spawn audit and refuses recovery when it fails [809.03ms]
(pass) Grok copresence runtime integration > keeps auto-approval across recovery before scheduling [1730.07ms]
(pass) Grok copresence runtime integration > jointly drains chat and events until both recovery cursors are stable [1840.08ms]
(pass) Grok copresence runtime integration > rejects a beforeSpawn callback that widens a controlled child setting [212.01ms]
(pass) Grok copresence runtime integration > gives every real lifetime-lock holder only the exact helper environment [585.02ms]

 137 pass
 0 fail
 732 expect() calls
Ran 137 tests across 9 files. [61.02s]

$ node-main-conflict-tests bun test /workspace/agent-node/src/inbox-dispatch.test.ts /workspace/agent-node/src/inbox-dispatch-wiring.test.ts /workspace/agent-node/src/runtime/inbox-drain-lane.test.ts /workspace/agent-node/src/util/single-flight.test.ts /workspace/agent-node/src/runtime/codex-app-server/session-manager.test.ts /workspace/agent-node/src/cli-explicit-delegation.test.ts /workspace/agent-node/src/credential-redaction.test.ts /workspace/agent-node/src/private-log.test.ts /workspace/agent-node/src/runtime/grok-build-cli-home.test.ts /workspace/agent-node/src/runtime/grok-build-cli.test.ts /workspace/agent-node/src/runtime/grok-child-env.test.ts
bun test v1.3.1 (89fa0f34)

agent-node/src/inbox-dispatch.test.ts:
(pass) isInteractiveDashboardTask > accepts a Hub-authenticated dashboard chat task [3.00ms]
(pass) isInteractiveDashboardTask > pre-stamp admin rows stay FIFO because aliases are not auth facts
(pass) isInteractiveDashboardTask > rejects node-authenticated spoofing, malformed ids, and plain messages
(pass) dispatchInboxBatch > awaited batches preserve legacy runtime serialization [2.00ms]
(pass) dispatchInboxBatch > a later SSE snapshot enters while the first detached turn is still running [2.00ms]
(pass) dispatchInboxBatch > the real serialized drain lane can fetch a later SSE snapshot before the active turn ends [1.00ms]
(pass) dispatchInboxBatch > detached completion failures remain observable [2.00ms]
(pass) dispatchInboxBatch > settling detached work emits a wake for the next Hub inbox window [1.00ms]
(pass) dispatchInboxBatch > a throwing settle callback cannot strand queued N+1 work [2.00ms]
(pass) dispatchInboxBatch > same-tick duplicate kicks claim one row exactly once
(pass) dispatchInboxBatch > bounded admission waits N+1 and starts it after a slot settles [3.00ms]
(pass) dispatchInboxBatch > durable reply drain waits until detached Codex rows finish
(pass) dispatchInboxBatch > active Codex direct delivery and durable drain send one reply, not two [8.00ms]

agent-node/src/inbox-dispatch-wiring.test.ts:
(pass) Codex app-server live inbox kick wiring > a Codex snapshot releases the serialized fetch lane after submission
(pass) Codex app-server live inbox kick wiring > Codex detached admission is explicitly bounded and completion wakes the Hub window [1.00ms]
(pass) Codex app-server live inbox kick wiring > pending reply drain is fenced while detached Codex rows are active

agent-node/src/runtime/inbox-drain-lane.test.ts:
(pass) inbox drain lanes > an informational lane drains while the work lane is busy
(pass) inbox drain lanes > each lane remains serial
(pass) inbox drain lanes > repeated wakeups for the same drain coalesce into one dirty rerun [1.00ms]
(pass) inbox drain lanes > a failed drain is reported and does not poison later retries [1.00ms]
(pass) inbox drain lanes > retry mode backs off and eventually completes the same drain [3.00ms]
(pass) inbox drain lanes > one failed inbox item does not starve later items in the same snapshot
(pass) inbox drain lanes > ack-only retry does not duplicate the first notification or delay the second [1.00ms]

agent-node/src/util/single-flight.test.ts:
(pass) single-flight resource initialization > concurrent callers share exactly one initializer [1.00ms]
(pass) single-flight resource initialization > a rejected initializer is cleared and can be retried [1.00ms]

agent-node/src/runtime/codex-app-server/session-manager.test.ts:
(pass) createCodexSessionManager > the production Codex inbox path is wired through the shared holder [1.00ms]
(pass) createCodexSessionManager > concurrent Dashboard handlers share one complete open attempt [1.00ms]
(pass) createCodexSessionManager > a rejected open is cleared and the next row can retry [1.00ms]
(pass) createCodexSessionManager > stopped and explicitly invalidated sessions are never reused
(pass) createCodexSessionManager > a session that dies during bootstrap is not published [1.00ms]

agent-node/src/cli-explicit-delegation.test.ts:
(pass) extractExplicitDelegation > matches send_task alias/task call [1.00ms]
(pass) extractExplicitDelegation > matches mcp send_task positional call
(pass) extractExplicitDelegation > matches 给 X 发任务
(pass) extractExplicitDelegation > matches 和 X 沟通一下
(pass) extractExplicitDelegation > matches bare 和 X 沟通一下
(pass) extractExplicitDelegation > matches 和 X send_task 一下
(pass) extractExplicitDelegation > matches 和 X send_task 一下 with no punctuation before body [1.00ms]
(pass) extractExplicitDelegation > matches bare 和 X send_task 一下
(pass) extractExplicitDelegation > matches 让 X 做
(pass) extractExplicitDelegation > matches 交给 X
(pass) extractExplicitDelegation > does not match no alias
(pass) extractExplicitDelegation > does not match normal Q&A
(pass) extractExplicitDelegation > matches bare send_task <alias> <task> (MCP-like)
(pass) extractExplicitDelegation > matches bare send_task with multi-word task body
(pass) extractExplicitDelegation > matches 你去给 X 打个招呼
(pass) extractExplicitDelegation > matches 你去给 X with longer body
(pass) extractExplicitDelegation > matches 给 X 发个消息 BODY (verb-suffix stripped) [1.00ms]
(pass) extractExplicitDelegation > matches 给 X 发 BODY (bare verb)
(pass) extractExplicitDelegation > matches 给 X 沟通一下 BODY
(pass) extractExplicitDelegation > matches 给 X 说 BODY
(pass) extractExplicitDelegation > matches 给 X 发任务 (regression — specific pattern still wins)

agent-node/src/credential-redaction.test.ts:
(pass) credential persistence redactor > removes exact caller-known values regardless of punctuation or context
(pass) credential persistence redactor > redacts network, GitHub, AWS and provider token shapes in free text [1.00ms]
(pass) credential persistence redactor > redacts credential assignments while preserving keys and valid JSON
(pass) credential persistence redactor > redacts shell/error assignment forms including quoted values
(pass) credential persistence redactor > redacts an unlabelled connection URI with embedded userinfo
(pass) credential persistence redactor > does not over-delete normal prose and non-credential settings [1.00ms]
(pass) credential persistence redactor > deep-redacts JSON-like values without mutating the input
(pass) credential value collection > collects exact sensitive values and shaped values under unknown keys [7.00ms]
(pass) credential value collection > key classifier is exact enough not to treat ordinary AWS settings as credentials

agent-node/src/private-log.test.ts:
(pass) Grok preview private ordinary logs > scrubs and repairs legacy logs before appending through a 0600 file [6.00ms]
(pass) Grok preview private ordinary logs > rejects a symlinked directory or final log file [1.00ms]
(pass) Grok preview private ordinary logs > rejects a multiply-linked log instead of rewriting another pathname [1.00ms]
(pass) Grok preview private ordinary logs > does not follow a log-directory symlink introduced after preparation [1.00ms]

agent-node/src/runtime/grok-build-cli-home.test.ts:
(pass) prepareGrokCliHome > derives an opaque path segment and rejects dot identities
(pass) prepareGrokCliHome > accepts only the pinned Grok regular-file copy of source agent_id [6.00ms]
(pass) prepareGrokCliHome > isolates config/trust, preserves a shared auth path, and creates stable sandbox profiles [3.00ms]
(pass) prepareGrokCliHome > refuses broad-mode or symlinked source auth without repairing it [2.00ms]
(pass) prepareGrokCliHome > repairs an existing Grok session store to owner-only modes [2.00ms]
(pass) prepareGrokCliHome > does not follow a symlink while repairing an existing session store [1.00ms]
(pass) prepareGrokCliHome > keeps the post-stop cleanup policy exact and reviewable [1.00ms]
(pass) prepareGrokCliHome > removes exact empty read-only project placeholders before resume without admitting executable sources [5.00ms]
(pass) prepareGrokCliHome > validates every exact project placeholder before unlinking any sibling [1.00ms]
(pass) prepareGrokCliHome > does not let a fatal project counterexample starve independent state containment [3.00ms]
(pass) prepareGrokCliHome > preserves nonempty, linked, wrong-mode, and wrong-type project counterexamples [6.00ms]
(pass) prepareGrokCliHome > preserves real project extension directories and still rejects executable contents on resume [2.00ms]
(pass) prepareGrokCliHome > removes only exact transient state and hardens retained post-stop state [6.00ms]
(pass) prepareGrokCliHome > hardens only the native lock derived from the exact leader socket [2.00ms]
(pass) prepareGrokCliHome > retains a non-empty leader log and rejects post-stop link attacks [2.00ms]
(pass) prepareGrokCliHome > refuses a non-empty exact sandbox placeholder [2.00ms]
(pass) prepareGrokCliHome > reclaims an empty mode-000 sandbox marker under a foreign pid without aborting [2.00ms]
(pass) prepareGrokCliHome > keeps a non-empty foreign sandbox marker unreadable so it fails closed [2.00ms]
(pass) prepareGrokCliHome > validates exact TUI process ids before mutation and refuses a placeholder symlink [2.00ms]
(pass) prepareGrokCliHome > enables the single TUI leader only for explicit copresence mode [16.00ms]
(pass) prepareGrokCliHome > admits only canonical owner-held commhub MCP artifacts [4.00ms]
(pass) prepareGrokCliHome > rejects a shared auth path covered by a required sandbox deny before state mutation [1.00ms]
(pass) prepareGrokCliHome > refuses to claim sandbox isolation when no deny target exists [1.00ms]
(pass) prepareGrokCliHome > rejects a source GROK_HOME reached through an ancestor symlink before state mutation [1.00ms]
(pass) prepareGrokCliHome > removes runtime-owned native hooks before every turn [1.00ms]
(pass) prepareGrokCliHome > unlinks a runtime-owned hook symlink without touching its external target [2.00ms]
(pass) prepareGrokCliHome > fails closed when a project native hook path exists [1.00ms]
(pass) prepareGrokCliHome > trusts only the exact canonical nested cwd and atomically replaces stale grants [2.00ms]
(pass) prepareGrokCliHome > rejects broad or symlinked folder-trust targets before writing trust state [2.00ms]
(pass) prepareGrokCliHome > refuses a planted trust-store symlink and leaves its target untouched [2.00ms]
(pass) prepareGrokCliHome > rejects every project executable source before granting folder trust [11.00ms]
(pass) prepareGrokCliHome > does not impose the shared-folder strict policy on legacy headless mode [4.00ms]
(pass) prepareGrokCliHome > rejects repo-root hooks from a nested cwd and dangling hook links [1.00ms]
(pass) prepareGrokCliHome > rejects a symlinked project .grok directory [1.00ms]
(pass) prepareGrokCliHome > rejects symlinked isolated homes and generated state without changing targets [3.00ms]
(pass) prepareGrokCliHome > rejects a state-home path escape before chmod, removal, or writes [1.00ms]
(pass) prepareGrokCliHome > requires a valid zero-hook inspect response [1.00ms]
(pass) prepareGrokCliHome > flocks the canonical project inode across symlink aliases and releases cleanly [114.00ms]
(pass) prepareGrokCliHome > gives the real flock holder only the exact helper environment [60.00ms]

agent-node/src/runtime/grok-build-cli.test.ts:
(pass) buildGrokCliArgs > rejects an older Grok CLI before it can ignore required safety flags [1.00ms]
(pass) buildGrokCliArgs > uses streaming headless mode and resumes an existing session
(pass) buildGrokCliArgs > fails closed instead of auto-approving when permission bypass is disabled
(pass) buildGrokCliArgs > maps an explicit node tool allowlist and keeps MCP unavailable
(pass) buildGrokCliArgs > intersects explicit tools with the read-only set when auto-approval is off [1.00ms]
(pass) buildGrokCliArgs > rejects unknown node tool names instead of silently widening access
(pass) buildGrokCliArgs > rejects an explicit empty tool allowlist instead of widening to all tools
(pass) buildGrokCliArgs > denies model reads of runtime credential and node-state paths
(pass) runGrokCliTurn > reduces streaming JSON text and persists the end-event session [44.00ms]
(pass) runGrokCliTurn > spawns with exactly the projected environment and no ambient credentials [41.00ms]
(pass) runGrokCliTurn > keeps the production-shaped setpriv/sh launcher on the exact PWD-bound env [46.00ms]
(pass) runGrokCliTurn > refuses a shell launcher when PWD is missing from the reviewed env [1.00ms]
(pass) runGrokCliTurn > removes the prompt when spawn rejects a malformed allowed env value [1.00ms]
(pass) runGrokCliTurn > surfaces non-zero exits and stderr [39.00ms]
(pass) runGrokCliTurn > fails fast when headless Grok asks for an interactive login [45.00ms]
(pass) runGrokCliTurn > rejects cancelled turns [42.00ms]
(pass) runGrokCliTurn > rejects a formal error event even if the process exits zero [43.00ms]
(pass) runGrokCliTurn > rejects max-turn truncation instead of reporting a partial reply as success [42.00ms]
(pass) runGrokCliTurn > terminates the process group when the caller aborts [37.00ms]
(pass) runGrokCliTurn > kills a silent child after the idle timeout [37.00ms]

agent-node/src/runtime/grok-child-env.test.ts:
(pass) Grok child environment boundary > builds the exact reviewed key set and drops every unreviewed credential
(pass) Grok child environment boundary > re-projects a beforeSpawn result instead of trusting arbitrary keys [1.00ms]
(pass) Grok child environment boundary > rejects a beforeSpawn callback that changes a controlled value [1.00ms]
(pass) Grok child environment boundary > keeps the inherited list exact and reviewable
(pass) Grok child environment boundary > keeps PTY PWD equal and adds only reviewed terminal/sandbox controls [1.00ms]
(pass) Grok child environment boundary > builds the narrower helper environment from an empty object

 129 pass
 0 fail
 525 expect() calls
Ran 129 tests across 11 files. [866.00ms]

$ network-main-conflict-tests bun test /workspace/agent-network/src/normalize-runtime.test.ts /workspace/agent-network/src/grok-attach-client.test.ts /workspace/agent-network/src/grok-copresence-profile.test.ts /workspace/agent-network/src/owner-env-file.test.ts /workspace/agent-network/src/copresence-cli-wiring.test.ts /workspace/agent-network/src/opencode-copresence-cli.test.ts
bun test v1.3.1 (89fa0f34)

agent-network/src/normalize-runtime.test.ts:
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > legacy normalization: unknown string → claude-agent-sdk
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > empty string → claude-agent-sdk
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > undefined (no arg) → claude-agent-sdk
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > undefined profile arg → claude-agent-sdk
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > profile with missing runtime field → claude-agent-sdk
(pass) normalizeRuntime — fallback default is claude-agent-sdk (Vincent no-Max) > profile with empty-string runtime field → claude-agent-sdk
(pass) normalizeRuntimeStrict — execution boundaries fail closed > missing and empty runtime still select the documented default
(pass) normalizeRuntimeStrict — execution boundaries fail closed > canonical names and supported aliases are accepted
(pass) normalizeRuntimeStrict — execution boundaries fail closed > a non-empty unknown runtime is rejected
(pass) normalizeRuntime — explicit choices are preserved > explicit 'claude-code-cli' → claude-code-cli (operator opt-in still works)
(pass) normalizeRuntime — explicit choices are preserved > explicit 'claude-agent-sdk' → claude-agent-sdk
(pass) normalizeRuntime — explicit choices are preserved > alias 'claude' → claude-agent-sdk (existing canonicalization)
(pass) normalizeRuntime — explicit choices are preserved > alias 'claude-sdk' → claude-agent-sdk
(pass) normalizeRuntime — explicit choices are preserved > alias 'agent-sdk' (string form) → claude-agent-sdk
(pass) normalizeRuntime — explicit choices are preserved > 'codex' / 'codex-sdk' → codex-sdk
(pass) normalizeRuntime — explicit choices are preserved > 'grok' / 'grok-build' / 'grok-build-acp' → grok-build-acp
(pass) normalizeRuntime — explicit choices are preserved > explicit Grok co-presence names → grok-build-cli
(pass) normalizeRuntime — explicit choices are preserved > explicit 'opencode-cli' → opencode-cli (canonical launcher name)
(pass) normalizeRuntime — explicit choices are preserved > alias 'opencode' → opencode-cli (short form)
(pass) normalizeRuntime — explicit choices are preserved > profile with runtime='opencode-cli' → opencode-cli
(pass) normalizeRuntime — explicit choices are preserved > profile with runtime='opencode' → opencode-cli
(pass) normalizeRuntime — explicit choices are preserved > explicit 'codex-app-server' → codex-app-server
(pass) normalizeRuntime — explicit choices are preserved > alias 'codex-tui' → codex-app-server
(pass) normalizeRuntime — explicit choices are preserved > alias 'codex-appserver' → codex-app-server
(pass) normalizeRuntime — explicit choices are preserved > 'codex-sdk' still → codex-sdk (not shadowed by the app-server branch)
(pass) normalizeRuntime — explicit choices are preserved > 'codex' still → codex-sdk (legacy short alias unchanged)
(pass) normalizeRuntime — explicit choices are preserved > profile with runtime='codex-app-server' → codex-app-server
(pass) normalizeRuntime — profile object paths > profile with runtime='claude-code-cli' → claude-code-cli (explicit, preserved) [1.00ms]
(pass) normalizeRuntime — profile object paths > profile with runtime='agent-sdk' + codexRuntime='codex' → codex-sdk (legacy hybrid)
(pass) normalizeRuntime — profile object paths > profile with runtime='agent-sdk' + no codexRuntime → claude-agent-sdk
(pass) normalizeRuntime — profile object paths > legacy profile normalization keeps unknown → default for display/migration

agent-network/src/grok-attach-client.test.ts:
(pass) validateGrokAttachSocket rejects symlinks, non-sockets, and foreign owners [3.00ms]
(pass) connectGrokAttach bridges base64 terminal I/O, status, resize, and detach [11.00ms]
(pass) connectGrokAttach splits large input so every NDJSON frame stays bounded [1.00ms]
(pass) connectGrokAttach fails closed on an invalid handshake and oversized frame [3.00ms]
(pass) a single-client rejection before hello preserves the server error
(pass) hello followed by a fatal frame in the same chunk cannot return a dead session [1.00ms]
(pass) detach force-closes a peer that never completes its half-close [14.00ms]
(pass) callback failure and invalid limits fail before returning an attached client [1.00ms]
(pass) remote detach is surfaced and closes without echoing a detach frame [1.00ms]

agent-network/src/grok-copresence-profile.test.ts:
(pass) Grok copresence profile defaults > builds the Grok agent-node parent environment from an exact empty allowlist
(pass) Grok copresence profile defaults > does not mistake an old headless-only agent-node for co-presence support
(pass) Grok copresence profile defaults > builds the npm resolver environment from an exact empty allowlist [1.00ms]
(pass) Grok copresence profile defaults > prepares two distinct empty owner-only npm config files without following symlinks [3.00ms]
(pass) Grok copresence profile defaults > enables copresence only for non-headless grok-build-cli [1.00ms]
(pass) Grok copresence profile defaults > uses the owner-bound state home even when XDG is owner-only [1.00ms]
(pass) Grok copresence profile defaults > falls back to a bounded owner tmp path when the state home is too long

agent-network/src/owner-env-file.test.ts:
(pass) loadOwnerOnlyEnvFile > loads the isolated commhub credential without overriding explicit identity [1.00ms]
(pass) loadOwnerOnlyEnvFile > rejects relative, broad-mode, and symlinked credential files [1.00ms]

agent-network/src/copresence-cli-wiring.test.ts:
(pass) cli.ts copresence start ordering (structural gate) > the copresence start path really does create tmux sessions with -e (anchor for the tests below)
(pass) cli.ts copresence start ordering (structural gate) > Blocker 5: prepareIdentityForStart runs BEFORE the first tmux new-session
(pass) cli.ts copresence start ordering (structural gate) > Blocker 5: no marker write happens before the identity preparation call [1.00ms]
(pass) cli.ts copresence start ordering (structural gate) > Blocker 6: a blocked preparation aborts the start (never falls through to session creation)
(pass) cli.ts copresence start ordering (structural gate) > Blocker 12: the tmux capability preflight runs BEFORE the first tmux new-session
(pass) cli.ts copresence stop wiring (structural gate) > Blockers 1+2: the stop-time reap is given the marker's recorded pids as scope anchors
(pass) cli.ts copresence stop wiring (structural gate) > marker removal happens only on a successful reap

agent-network/src/opencode-copresence-cli.test.ts:
(pass) OpenCode co-presence CLI wiring > persists copresence mode before launching the bridge
(pass) OpenCode co-presence CLI wiring > starts only exact alias and alias-bridge tmux sessions
(pass) OpenCode co-presence CLI wiring > does not depend on a long-lived tmux server's stale launcher environment
(pass) OpenCode co-presence CLI wiring > waits for the owner-only runtime launcher before starting the official TUI [1.00ms]
(pass) OpenCode co-presence CLI wiring > the generic --copresence dispatcher selects OpenCode by stored runtime
(pass) OpenCode co-presence CLI wiring > operator help names the create, attach, and stop commands [1.00ms]
(pass) OpenCode co-presence CLI wiring > prints an exact tmux target so an exited TUI cannot prefix-match the bridge

 63 pass
 0 fail
 150 expect() calls
Ran 63 tests across 6 files. [131.00ms]

$ agent-node-build bun build /workspace/agent-node/src/cli.ts --outdir /tmp/agent-node-dist --entry-naming cli.js --target node --external @anthropic-ai/claude-agent-sdk --external @anthropic-ai/claude-agent-sdk-\* --external @openai/codex-sdk --external node-pty --external zod --external undici
Bundled 77 modules in 38ms

  cli.js  0.71 MB  (entry point)


$ agent-network-cli-build bun build /workspace/agent-network/bin/cli.ts --outdir /tmp/agent-network-dist --target node --external @inquirer/prompts --external @sleep2agi/commhub-server --external bun:sqlite --external node-pty --external ../../server/\*
Bundled 22 modules in 55ms

  cli.js  0.58 MB  (entry point)


Summary: PASS (Docker-only integration regression)
