import { appendFileSync, chmodSync, existsSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from "node:fs"; import { spawn } from "node:child_process"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { fileURLToPath } from "node:url"; import { EventEmitter } from "node:events"; import { PassThrough } from "node:stream"; import { afterEach, describe, expect, test, vi } from "vitest"; import { createPosixAuthStorageBridge, createWindowsAuthStorageBridge, } from "../src/auth/windows-auth-storage.js"; const root = "C:\\ProgramData\\ThothII\\auth"; const posixRoot = "/var/lib/thothii/auth"; const filename = "a".repeat(64) + ".json"; const realChildFixture = fileURLToPath(new URL("./fixtures/windows-auth-storage-real-child.mjs", import.meta.url)); const fixtureRoots: string[] = []; function shellQuote(value: string): string { return `'${value.replaceAll("'", `'\\''`)}'`; } async function waitForMarker(marker: string, expected: string): Promise { const deadline = Date.now() + 3_000; while (Date.now() < deadline) { if (existsSync(marker) && readFileSync(marker, "utf8").includes(expected)) return; await new Promise((resolve) => setTimeout(resolve, 10)); } throw new Error(`real helper marker did not contain ${expected}`); } function realChildBridge( mode: "timeout" | "stdout" | "stderr" | "stdin", pathStyle: "windows" | "posix", ) { const directory = mkdtempSync(join(tmpdir(), "thothii-auth-bridge-child-")); fixtureRoots.push(directory); const marker = join(directory, "marker.txt"); const launcher = join(directory, "tht.exe"); writeFileSync(launcher, `#!/bin/sh\nexec ${shellQuote(process.execPath)} ${shellQuote(realChildFixture)} ${shellQuote(mode)} ${shellQuote(marker)} "$@"\n`, { mode: 0o700 }); chmodSync(launcher, 0o700); const factory = pathStyle === "windows" ? createWindowsAuthStorageBridge : createPosixAuthStorageBridge; return { marker, bridge: factory({ thtExecutable: pathStyle === "windows" ? "C:\\tht.exe" : launcher, spawnChild: (_executable, args, options) => spawn(launcher, [...args], options), // Keep this stricter than the five-second production timeout without assuming that a // real Node child can always start within 750 ms on a busy shared runner. deadlinesForTest: { timeoutMs: 2_000, terminationGraceMs: 50, finalSettlementMs: 500 }, ...(mode === "stdin" ? { beforeInputForTest: async () => { await waitForMarker(marker, "stdin-closed"); appendFileSync(marker, "before-input\n"); }, } : {}), } as never), }; } afterEach(() => { for (const directory of fixtureRoots.splice(0)) { const marker = join(directory, "marker.txt"); try { const pid = Number(/^started:(\d+)$/m.exec(readFileSync(marker, "utf8"))?.[1]); if (Number.isSafeInteger(pid) && pid > 0) process.kill(pid, "SIGKILL"); } catch { /* the test-owned child already exited or did not start */ } rmSync(directory, { recursive: true, force: true }); } }); class FakeBridgeChild extends EventEmitter { readonly stdin = new PassThrough(); readonly stdout = new PassThrough(); readonly stderr = new PassThrough(); readonly kill = vi.fn(() => true); readonly unref = vi.fn(); close(code = 0, signal: NodeJS.Signals | null = null): void { this.emit("close", code, signal); } } function bridgeForChild(child: FakeBridgeChild, pathStyle: "windows" | "posix" = "windows") { const spawnChild = vi.fn(() => child); const factory = pathStyle === "windows" ? createWindowsAuthStorageBridge : createPosixAuthStorageBridge; const bridge = factory({ thtExecutable: pathStyle === "windows" ? "C:\\tht.exe" : "/opt/thothii/bin/tht", spawnChild, } as never); return { bridge, spawnChild }; } describe("Windows auth-storage bridge", () => { test("uses a dedicated native storage executable without replacing the harness tht", async () => { vi.stubEnv("THT_BIN", "/opt/venv/bin/tht"); vi.stubEnv("THT_AUTH_STORAGE_BIN", "/usr/local/bin/tht-auth-storage"); const calls: Array<{ executable: string }> = []; const bridge = createPosixAuthStorageBridge({ invoke: async (call) => { calls.push(call); return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"prepared":true}\n'), stderr: Buffer.alloc(0), }; }, }); await bridge.ensureLayout("/data/auth"); expect(calls).toHaveLength(1); expect(calls[0]!.executable).toBe("/usr/local/bin/tht-auth-storage"); expect(process.env.THT_BIN).toBe("/opt/venv/bin/tht"); vi.unstubAllEnvs(); }); test("uses the same bounded hidden bridge to ensure a POSIX session layout", async () => { const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = []; const bridge = createPosixAuthStorageBridge({ thtExecutable: "/opt/thothii/bin/tht", invoke: async (call) => { calls.push(call); return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"prepared":true}\n'), stderr: Buffer.alloc(0), }; }, }); await expect(bridge.ensureLayout("/var/lib/thothii/auth")).resolves.toBeUndefined(); expect(calls).toHaveLength(1); expect(calls[0]).toMatchObject({ executable: "/opt/thothii/bin/tht", args: ["_auth-storage"], timeoutMs: 5_000, }); expect(JSON.parse(calls[0]!.input.toString("utf8"))).toEqual({ version: 1, operation: "ensure-layout", root: "/var/lib/thothii/auth", }); expect(JSON.stringify(calls[0]!.args)).not.toContain("/var/lib/thothii/auth"); await expect(bridge.ensureLayout("/var/lib/thothii/../auth")) .rejects.toThrow("auth_session_store_invalid"); }); test("permits reservation slots only for OIDC record operations", async () => { const requests: Array> = []; const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async ({ input }) => { const request = JSON.parse(input.toString("utf8")) as Record; requests.push(request); const operation = request.operation; const body = operation === "create" ? { created: true } : operation === "read" ? { found: true, contentBase64: Buffer.from("slot").toString("base64") } : operation === "remove" ? { removed: true } : { entries: [{ name: "slot-00.json", modifiedUnixMs: 1 }] }; return { code: 0, stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`), stderr: Buffer.alloc(0), }; }, }); await expect(bridge.create("C:\\auth", "oidc", "slot-00.json", Buffer.from("slot"))).resolves.toBe(true); await expect(bridge.read("C:\\auth", "oidc", "slot-00.json")).resolves.toEqual(Buffer.from("slot")); await expect(bridge.list("C:\\auth", "oidc")).resolves.toEqual([ { name: "slot-00.json", modifiedUnixMs: 1 }, ]); await expect(bridge.remove("C:\\auth", "oidc", "slot-00.json")).resolves.toBe(true); await expect(bridge.create("C:\\auth", "sessions", "slot-00.json", Buffer.from("slot"))) .rejects.toThrow("auth_session_store_invalid"); await expect(bridge.create("C:\\auth", "oidc", "slot-64.json", Buffer.from("slot"))) .rejects.toThrow("auth_session_store_invalid"); expect(requests).toHaveLength(4); }); test("uses hidden tht argv and sends record bytes only over bounded stdin", async () => { const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = []; const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\Program Files\\ThothII\\tht.exe", invoke: async (call) => { calls.push(call); return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"created":true}\n'), stderr: Buffer.alloc(0) }; }, }); await expect(bridge.create(root, "sessions", filename, Buffer.from('{"subject":"record-data"}'))).resolves.toBe(true); expect(calls).toHaveLength(1); expect(calls[0]).toMatchObject({ executable: "C:\\Program Files\\ThothII\\tht.exe", args: ["_auth-storage"], }); expect(JSON.stringify(calls[0].args)).not.toContain("record-data"); expect(JSON.parse(calls[0].input.toString("utf8"))).toMatchObject({ version: 1, operation: "create", root, directory: "sessions", filename, contentBase64: Buffer.from('{"subject":"record-data"}').toString("base64"), }); expect(calls[0].timeoutMs).toBeGreaterThan(0); }); test("validates Windows roots and reads auth.yaml through the same bounded hidden bridge", async () => { const asyncCalls: Array> = []; const syncCalls: Array<{ args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }> = []; const config = Buffer.from("version: 1\nmode: local\n"); const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\Program Files\\ThothII\\tht.exe", invoke: async ({ input }) => { asyncCalls.push(JSON.parse(input.toString("utf8")) as Record); return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"validated":true}\n'), stderr: Buffer.alloc(0) }; }, invokeSync: (call: { args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }) => { syncCalls.push(call); return { code: 0, stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, found: true, contentBase64: config.toString("base64") })}\n`), stderr: Buffer.alloc(0), }; }, } as never) as unknown as { validateRoot(root: string): Promise; readAuthConfig(path: string): Buffer; }; await expect(bridge.validateRoot(root)).resolves.toBeUndefined(); expect(bridge.readAuthConfig(`${root}\\auth.yaml`)).toEqual(config); expect(asyncCalls).toEqual([{ version: 1, operation: "validate-root", root }]); expect(JSON.parse(syncCalls[0]!.input.toString("utf8"))).toEqual({ version: 1, operation: "read-auth-config", root, filename: "auth.yaml", }); expect(syncCalls[0]!.args).toEqual(["_auth-storage"]); expect(syncCalls[0]!.timeoutMs).toBe(5_000); expect(syncCalls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024); expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(root); expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(config.toString("utf8")); }); test("reads native Windows users.yaml only through a bounded hidden bridge request", async () => { const users = Buffer.from("version: 1\nusers:\n - passwordHash: not-in-argv\n", "utf8"); const calls: Array<{ args: readonly string[]; input: Buffer; maximumOutputBytes: number }> = []; const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\Program Files\\ThothII\\tht.exe", invoke: async (call) => { calls.push(call); return { code: 0, stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, found: true, contentBase64: users.toString("base64"), })}\n`), stderr: Buffer.alloc(0), }; }, }); await expect(bridge.readLocalUsers(`${root}\\users.yaml`)).resolves.toEqual(users); expect(calls).toHaveLength(1); expect(calls[0]!.args).toEqual(["_auth-storage"]); expect(calls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024); expect(JSON.parse(calls[0]!.input.toString("utf8"))).toEqual({ version: 1, operation: "read-local-users", root, filename: "users.yaml", }); expect(JSON.stringify(calls[0]!.args)).not.toContain("not-in-argv"); expect(calls[0]!.input.toString("utf8")).not.toContain("not-in-argv"); }); test.each([ { label: "nonzero", result: { code: 1, stdout: Buffer.from('{"version":1,"ok":true}\n'), stderr: Buffer.from("secret") } }, { label: "malformed stdout", result: { code: 0, stdout: Buffer.from("not-json"), stderr: Buffer.alloc(0) } }, { label: "unexpected stdout", result: { code: 0, stdout: Buffer.from('{"version":1,"ok":true}\nextra'), stderr: Buffer.alloc(0) } }, { label: "unexpected JSON field", result: { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"created":true,"detail":"secret"}\n'), stderr: Buffer.alloc(0) } }, ])("fails closed on $label bridge output", async ({ result }) => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => result, }); await expect(bridge.create(root, "sessions", filename, Buffer.from("record"))) .rejects.toThrow("auth_session_store_invalid"); }); test("fails closed on a bridge timeout without disclosing request content", async () => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => { throw new Error("timeout secret-record"); }, }); await expect(bridge.create(root, "sessions", filename, Buffer.from("secret-record"))) .rejects.toThrow("auth_session_store_invalid"); }); test("rejects a claimed-read response without bounded record bytes", async () => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, stdout: Buffer.from('{"version":1,"ok":true,"found":true}\n'), stderr: Buffer.alloc(0) }), }); await expect(bridge.readClaim(root, filename)).rejects.toThrow("auth_session_store_invalid"); }); test("rejects an executable value that would require shell parsing", () => { expect(() => createWindowsAuthStorageBridge({ thtExecutable: "tht.exe && unexpected" })) .toThrow("auth_session_store_invalid"); }); test("parses the lower-camel list DTO emitted by the Go helper for a nonempty directory", async () => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, // This is the raw JSON object emitted by authstorage.response after Go's DTO encoding. stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${filename}","modifiedUnixMs":1893456245000}]}\n`), stderr: Buffer.alloc(0), }), }); await expect(bridge.list(root, "oidc")).resolves.toEqual([ { name: filename, modifiedUnixMs: 1_893_456_245_000 }, ]); }); test("passes an explicit bounded directory limit to the Go helper", async () => { const invoke = vi.fn(async () => ({ code: 0, stdout: Buffer.from('{"version":1,"ok":true,"entries":[]}\n'), stderr: Buffer.alloc(0), })); const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke }); await expect(bridge.list(root, "oidc", 192)).resolves.toEqual([]); expect(JSON.parse(invoke.mock.calls[0][0].input.toString("utf8"))).toMatchObject({ operation: "list", directory: "oidc", maximumEntries: 192, }); }); test("uses a strict, bounded continuation page for ordinary Windows session maintenance", async () => { const invoke = vi.fn(async () => ({ code: 0, stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${filename}","modifiedUnixMs":1}],"more":false}\n`), stderr: Buffer.alloc(0), })); const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke }) as unknown as { listPage(root: string, directory: "sessions", after: string | undefined, maximumEntries: number): Promise<{ entries: Array<{ name: string; modifiedUnixMs: number }>; more: boolean; }>; }; await expect(bridge.listPage(root, "sessions", "0".repeat(64) + ".json", 512)).resolves.toEqual({ entries: [{ name: filename, modifiedUnixMs: 1 }], more: false, }); expect(JSON.parse(invoke.mock.calls[0][0].input.toString("utf8"))).toMatchObject({ operation: "list", directory: "sessions", maximumEntries: 512, continuation: true, afterName: "0".repeat(64) + ".json", }); }); test("rejects ambiguous ordinary-session continuation responses", async () => { const after = "f".repeat(64) + ".json"; const low = "a".repeat(64) + ".json"; const high = "b".repeat(64) + ".json"; const cases = [ { label: "missing more marker", body: { entries: [{ name: filename, modifiedUnixMs: 1 }] } }, { label: "more without a full page", body: { entries: [{ name: filename, modifiedUnixMs: 1 }], more: true } }, { label: "non-progressing name", body: { entries: [{ name: low, modifiedUnixMs: 1 }], more: false } }, { label: "duplicate names", body: { entries: [{ name: high, modifiedUnixMs: 1 }, { name: high, modifiedUnixMs: 2 }], more: false } }, ]; for (const { body } of cases) { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`), stderr: Buffer.alloc(0), }), }) as unknown as { listPage(root: string, directory: "sessions", afterName: string | undefined, maximumEntries: number): Promise; }; await expect(bridge.listPage(root, "sessions", after, 512)).rejects.toThrow("auth_session_store_invalid"); } }); test("accepts a bounded ordinary-session page larger than the legacy 256-entry limit", async () => { const entries = Array.from({ length: 300 }, (_unused, index) => ({ name: `${index.toString(16).padStart(64, "0")}.json`, modifiedUnixMs: 1_893_456_245_000, })); const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, entries })}\n`), stderr: Buffer.alloc(0), }), }); await expect(bridge.list(root, "sessions", 300)).resolves.toHaveLength(300); }); test("parses the Go helper's required empty entries array", async () => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, stdout: Buffer.from('{"version":1,"ok":true,"entries":[]}\n'), stderr: Buffer.alloc(0), }), }); await expect(bridge.list(root, "sessions")).resolves.toEqual([]); }); test("allows only canonical OIDC claim removal and rejects claims elsewhere", async () => { const claim = `${"b".repeat(64)}.claim`; const invoke = vi.fn(async () => ({ code: 0, stdout: Buffer.from('{"version":1,"ok":true,"removed":true}\n'), stderr: Buffer.alloc(0), })); const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke }); await expect(bridge.remove(root, "oidc", claim)).resolves.toBe(true); await expect(bridge.remove(root, "sessions", claim)).rejects.toThrow("auth_session_store_invalid"); await expect(bridge.read(root, "oidc", claim)).rejects.toThrow("auth_session_store_invalid"); await expect(bridge.create(root, "oidc", claim, Buffer.from("record"))).rejects.toThrow("auth_session_store_invalid"); await expect(bridge.replace(root, "oidc", claim, Buffer.from("record"))).rejects.toThrow("auth_session_store_invalid"); await expect(bridge.remove(root, "oidc", `../${claim}`)).rejects.toThrow("auth_session_store_invalid"); await expect(bridge.remove(root, "oidc", `${claim}.bak`)).rejects.toThrow("auth_session_store_invalid"); expect(invoke).toHaveBeenCalledTimes(1); }); test("rejects OIDC claim entries returned for a sessions list", async () => { const claim = `${"c".repeat(64)}.claim`; const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke: async () => ({ code: 0, stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${claim}","modifiedUnixMs":1}]}\n`), stderr: Buffer.alloc(0), }), }); await expect(bridge.list(root, "sessions")).rejects.toThrow("auth_session_store_invalid"); }); test("settles a stdin-closed looping helper by a final deadline when close never arrives", async () => { vi.useFakeTimers(); const child = new FakeBridgeChild(); const { bridge, spawnChild } = bridgeForChild(child); const pending = bridge.list(root, "sessions"); const outcome = pending.then(() => "resolved", () => "rejected"); try { await vi.advanceTimersByTimeAsync(5_000); expect(spawnChild).toHaveBeenCalledOnce(); expect(child.kill).toHaveBeenCalledOnce(); expect(child.unref).toHaveBeenCalledOnce(); expect(child.stdin.destroyed).toBe(true); await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending"); await vi.advanceTimersByTimeAsync(1_000); expect(child.kill).toHaveBeenCalledTimes(2); await expect(outcome).resolves.toBe("rejected"); expect(() => child.emit("error", new Error("late helper failure"))).not.toThrow(); expect(() => child.stdin.emit("error", new Error("late stdin failure"))).not.toThrow(); } finally { child.close(); vi.useRealTimers(); } }); test("releases bounded late-error guards when a finally-dead helper closes", async () => { vi.useFakeTimers(); const child = new FakeBridgeChild(); const { bridge } = bridgeForChild(child); const outcome = bridge.list(root, "sessions").then(() => "resolved", () => "rejected"); try { await vi.advanceTimersByTimeAsync(6_000); await expect(outcome).resolves.toBe("rejected"); expect(child.listenerCount("error")).toBe(1); expect(child.stdin.listenerCount("error")).toBe(1); expect(child.stdout.listenerCount("error")).toBe(1); expect(child.stderr.listenerCount("error")).toBe(1); child.close(); expect(child.listenerCount("error")).toBe(0); expect(child.stdin.listenerCount("error")).toBe(0); expect(child.stdout.listenerCount("error")).toBe(0); expect(child.stderr.listenerCount("error")).toBe(0); } finally { vi.useRealTimers(); } }); test.each(["stdout", "stderr"] as const)("aborts a %s-flooding helper and waits for close", async (stream) => { const child = new FakeBridgeChild(); const { bridge, spawnChild } = bridgeForChild(child); const pending = bridge.list(root, "sessions"); const outcome = pending.then(() => "resolved", () => "rejected"); await Promise.resolve(); expect(spawnChild).toHaveBeenCalledOnce(); child[stream].write(Buffer.alloc(64 * 1024 + 1)); await Promise.resolve(); expect(child.kill).toHaveBeenCalledOnce(); expect(child.stdin.destroyed).toBe(true); await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending"); child.close(); await expect(outcome).resolves.toBe("rejected"); }); test("aborts a helper when its stdin errors and waits for termination", async () => { const child = new FakeBridgeChild(); const { bridge, spawnChild } = bridgeForChild(child); const stdinErrored = new Promise((resolve) => child.stdin.once("error", () => resolve())); child.stdin.once("finish", () => child.stdin.destroy(new Error("stdin failure"))); const pending = bridge.list(root, "sessions"); const outcome = pending.then(() => "resolved", () => "rejected"); await Promise.resolve(); expect(spawnChild).toHaveBeenCalledOnce(); await stdinErrored; expect(child.kill).toHaveBeenCalledOnce(); child.close(); await expect(outcome).resolves.toBe("rejected"); }); test("aborts an errored child exactly once and waits for its close event", async () => { const child = new FakeBridgeChild(); const { bridge, spawnChild } = bridgeForChild(child); const pending = bridge.list(root, "sessions"); const outcome = pending.then(() => "resolved", () => "rejected"); await Promise.resolve(); expect(spawnChild).toHaveBeenCalledOnce(); child.emit("error", new Error("helper error")); child.emit("error", new Error("duplicate helper error")); expect(child.kill).toHaveBeenCalledOnce(); await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending"); child.close(); await expect(outcome).resolves.toBe("rejected"); expect(() => child.emit("error", new Error("late helper failure"))).not.toThrow(); expect(() => child.stdin.emit("error", new Error("late stdin failure"))).not.toThrow(); expect(() => child.stdout.emit("error", new Error("late stdout failure"))).not.toThrow(); expect(() => child.stderr.emit("error", new Error("late stderr failure"))).not.toThrow(); }); test("fails closed when launching the helper throws before a child exists", async () => { const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", spawnChild: () => { throw new Error("launch detail must not escape"); }, }); await expect(bridge.list(root, "sessions")).rejects.toThrow("auth_session_store_invalid"); }); test.each([ ...(["windows", "posix"] as const).flatMap((pathStyle) => (["timeout", "stdout", "stderr", "stdin"] as const).map((mode) => ({ pathStyle, mode }))), ])("settles a real $pathStyle $mode helper within the production deadline", async ({ pathStyle, mode }) => { const { bridge, marker } = realChildBridge(mode, pathStyle); const startedAt = Date.now(); const pending = bridge.list(pathStyle === "windows" ? root : posixRoot, "sessions"); const outcome = pending.then(() => undefined, (error: unknown) => error); await waitForMarker(marker, "started"); if (mode === "stdin") await waitForMarker(marker, "before-input"); await expect(outcome).resolves.toMatchObject({ message: "auth_session_store_invalid" }); await waitForMarker(marker, "terminated"); expect(Date.now() - startedAt).toBeLessThan(3_000); }, 5_000); });