Files
ThothII/backend/test/windows-auth-storage.test.ts
T

568 lines
25 KiB
TypeScript

import { appendFileSync, chmodSync, existsSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from "node:fs";
import { spawn } from "node:child_process";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { fileURLToPath } from "node:url";
import { EventEmitter } from "node:events";
import { PassThrough } from "node:stream";
import { afterEach, describe, expect, test, vi } from "vitest";
import {
createPosixAuthStorageBridge,
createWindowsAuthStorageBridge,
} from "../src/auth/windows-auth-storage.js";
const root = "C:\\ProgramData\\ThothII\\auth";
const posixRoot = "/var/lib/thothii/auth";
const filename = "a".repeat(64) + ".json";
const realChildFixture = fileURLToPath(new URL("./fixtures/windows-auth-storage-real-child.mjs", import.meta.url));
const fixtureRoots: string[] = [];
function shellQuote(value: string): string {
return `'${value.replaceAll("'", `'\\''`)}'`;
}
async function waitForMarker(marker: string, expected: string): Promise<void> {
const deadline = Date.now() + 3_000;
while (Date.now() < deadline) {
if (existsSync(marker) && readFileSync(marker, "utf8").includes(expected)) return;
await new Promise<void>((resolve) => setTimeout(resolve, 10));
}
throw new Error(`real helper marker did not contain ${expected}`);
}
function realChildBridge(
mode: "timeout" | "stdout" | "stderr" | "stdin",
pathStyle: "windows" | "posix",
) {
const directory = mkdtempSync(join(tmpdir(), "thothii-auth-bridge-child-"));
fixtureRoots.push(directory);
const marker = join(directory, "marker.txt");
const launcher = join(directory, "tht.exe");
writeFileSync(launcher, `#!/bin/sh\nexec ${shellQuote(process.execPath)} ${shellQuote(realChildFixture)} ${shellQuote(mode)} ${shellQuote(marker)} "$@"\n`, { mode: 0o700 });
chmodSync(launcher, 0o700);
const factory = pathStyle === "windows" ? createWindowsAuthStorageBridge : createPosixAuthStorageBridge;
return {
marker,
bridge: factory({
thtExecutable: pathStyle === "windows" ? "C:\\tht.exe" : launcher,
spawnChild: (_executable, args, options) => spawn(launcher, [...args], options),
// Leave enough startup headroom for a real child under a busy CI host while retaining a
// sub-1.5-second bound from request start through final settlement.
deadlinesForTest: { timeoutMs: 750, terminationGraceMs: 50, finalSettlementMs: 500 },
...(mode === "stdin" ? {
beforeInputForTest: async () => {
await waitForMarker(marker, "stdin-closed");
appendFileSync(marker, "before-input\n");
},
} : {}),
} as never),
};
}
afterEach(() => {
for (const directory of fixtureRoots.splice(0)) {
const marker = join(directory, "marker.txt");
try {
const pid = Number(/^started:(\d+)$/m.exec(readFileSync(marker, "utf8"))?.[1]);
if (Number.isSafeInteger(pid) && pid > 0) process.kill(pid, "SIGKILL");
} catch { /* the test-owned child already exited or did not start */ }
rmSync(directory, { recursive: true, force: true });
}
});
class FakeBridgeChild extends EventEmitter {
readonly stdin = new PassThrough();
readonly stdout = new PassThrough();
readonly stderr = new PassThrough();
readonly kill = vi.fn(() => true);
readonly unref = vi.fn();
close(code = 0, signal: NodeJS.Signals | null = null): void {
this.emit("close", code, signal);
}
}
function bridgeForChild(child: FakeBridgeChild, pathStyle: "windows" | "posix" = "windows") {
const spawnChild = vi.fn(() => child);
const factory = pathStyle === "windows" ? createWindowsAuthStorageBridge : createPosixAuthStorageBridge;
const bridge = factory({
thtExecutable: pathStyle === "windows" ? "C:\\tht.exe" : "/opt/thothii/bin/tht",
spawnChild,
} as never);
return { bridge, spawnChild };
}
describe("Windows auth-storage bridge", () => {
test("uses the same bounded hidden bridge to ensure a POSIX session layout", async () => {
const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = [];
const bridge = createPosixAuthStorageBridge({
thtExecutable: "/opt/thothii/bin/tht",
invoke: async (call) => {
calls.push(call);
return {
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"prepared":true}\n'),
stderr: Buffer.alloc(0),
};
},
});
await expect(bridge.ensureLayout("/var/lib/thothii/auth")).resolves.toBeUndefined();
expect(calls).toHaveLength(1);
expect(calls[0]).toMatchObject({
executable: "/opt/thothii/bin/tht",
args: ["_auth-storage"],
timeoutMs: 5_000,
});
expect(JSON.parse(calls[0]!.input.toString("utf8"))).toEqual({
version: 1,
operation: "ensure-layout",
root: "/var/lib/thothii/auth",
});
expect(JSON.stringify(calls[0]!.args)).not.toContain("/var/lib/thothii/auth");
await expect(bridge.ensureLayout("/var/lib/thothii/../auth"))
.rejects.toThrow("auth_session_store_invalid");
});
test("permits reservation slots only for OIDC record operations", async () => {
const requests: Array<Record<string, unknown>> = [];
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async ({ input }) => {
const request = JSON.parse(input.toString("utf8")) as Record<string, unknown>;
requests.push(request);
const operation = request.operation;
const body = operation === "create"
? { created: true }
: operation === "read"
? { found: true, contentBase64: Buffer.from("slot").toString("base64") }
: operation === "remove"
? { removed: true }
: { entries: [{ name: "slot-00.json", modifiedUnixMs: 1 }] };
return {
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`),
stderr: Buffer.alloc(0),
};
},
});
await expect(bridge.create("C:\\auth", "oidc", "slot-00.json", Buffer.from("slot"))).resolves.toBe(true);
await expect(bridge.read("C:\\auth", "oidc", "slot-00.json")).resolves.toEqual(Buffer.from("slot"));
await expect(bridge.list("C:\\auth", "oidc")).resolves.toEqual([
{ name: "slot-00.json", modifiedUnixMs: 1 },
]);
await expect(bridge.remove("C:\\auth", "oidc", "slot-00.json")).resolves.toBe(true);
await expect(bridge.create("C:\\auth", "sessions", "slot-00.json", Buffer.from("slot")))
.rejects.toThrow("auth_session_store_invalid");
await expect(bridge.create("C:\\auth", "oidc", "slot-64.json", Buffer.from("slot")))
.rejects.toThrow("auth_session_store_invalid");
expect(requests).toHaveLength(4);
});
test("uses hidden tht argv and sends record bytes only over bounded stdin", async () => {
const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = [];
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\Program Files\\ThothII\\tht.exe",
invoke: async (call) => {
calls.push(call);
return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"created":true}\n'), stderr: Buffer.alloc(0) };
},
});
await expect(bridge.create(root, "sessions", filename, Buffer.from('{"subject":"record-data"}'))).resolves.toBe(true);
expect(calls).toHaveLength(1);
expect(calls[0]).toMatchObject({
executable: "C:\\Program Files\\ThothII\\tht.exe",
args: ["_auth-storage"],
});
expect(JSON.stringify(calls[0].args)).not.toContain("record-data");
expect(JSON.parse(calls[0].input.toString("utf8"))).toMatchObject({
version: 1,
operation: "create",
root,
directory: "sessions",
filename,
contentBase64: Buffer.from('{"subject":"record-data"}').toString("base64"),
});
expect(calls[0].timeoutMs).toBeGreaterThan(0);
});
test("validates Windows roots and reads auth.yaml through the same bounded hidden bridge", async () => {
const asyncCalls: Array<Record<string, unknown>> = [];
const syncCalls: Array<{ args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }> = [];
const config = Buffer.from("version: 1\nmode: local\n");
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\Program Files\\ThothII\\tht.exe",
invoke: async ({ input }) => {
asyncCalls.push(JSON.parse(input.toString("utf8")) as Record<string, unknown>);
return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"validated":true}\n'), stderr: Buffer.alloc(0) };
},
invokeSync: (call: { args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }) => {
syncCalls.push(call);
return {
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, found: true, contentBase64: config.toString("base64") })}\n`),
stderr: Buffer.alloc(0),
};
},
} as never) as unknown as {
validateRoot(root: string): Promise<void>;
readAuthConfig(path: string): Buffer;
};
await expect(bridge.validateRoot(root)).resolves.toBeUndefined();
expect(bridge.readAuthConfig(`${root}\\auth.yaml`)).toEqual(config);
expect(asyncCalls).toEqual([{ version: 1, operation: "validate-root", root }]);
expect(JSON.parse(syncCalls[0]!.input.toString("utf8"))).toEqual({
version: 1, operation: "read-auth-config", root, filename: "auth.yaml",
});
expect(syncCalls[0]!.args).toEqual(["_auth-storage"]);
expect(syncCalls[0]!.timeoutMs).toBe(5_000);
expect(syncCalls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024);
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(root);
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(config.toString("utf8"));
});
test("reads native Windows users.yaml only through a bounded hidden bridge request", async () => {
const users = Buffer.from("version: 1\nusers:\n - passwordHash: not-in-argv\n", "utf8");
const calls: Array<{ args: readonly string[]; input: Buffer; maximumOutputBytes: number }> = [];
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\Program Files\\ThothII\\tht.exe",
invoke: async (call) => {
calls.push(call);
return {
code: 0,
stdout: Buffer.from(`${JSON.stringify({
version: 1, ok: true, found: true, contentBase64: users.toString("base64"),
})}\n`),
stderr: Buffer.alloc(0),
};
},
});
await expect(bridge.readLocalUsers(`${root}\\users.yaml`)).resolves.toEqual(users);
expect(calls).toHaveLength(1);
expect(calls[0]!.args).toEqual(["_auth-storage"]);
expect(calls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024);
expect(JSON.parse(calls[0]!.input.toString("utf8"))).toEqual({
version: 1, operation: "read-local-users", root, filename: "users.yaml",
});
expect(JSON.stringify(calls[0]!.args)).not.toContain("not-in-argv");
expect(calls[0]!.input.toString("utf8")).not.toContain("not-in-argv");
});
test.each([
{ label: "nonzero", result: { code: 1, stdout: Buffer.from('{"version":1,"ok":true}\n'), stderr: Buffer.from("secret") } },
{ label: "malformed stdout", result: { code: 0, stdout: Buffer.from("not-json"), stderr: Buffer.alloc(0) } },
{ label: "unexpected stdout", result: { code: 0, stdout: Buffer.from('{"version":1,"ok":true}\nextra'), stderr: Buffer.alloc(0) } },
{ label: "unexpected JSON field", result: { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"created":true,"detail":"secret"}\n'), stderr: Buffer.alloc(0) } },
])("fails closed on $label bridge output", async ({ result }) => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => result,
});
await expect(bridge.create(root, "sessions", filename, Buffer.from("record")))
.rejects.toThrow("auth_session_store_invalid");
});
test("fails closed on a bridge timeout without disclosing request content", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => { throw new Error("timeout secret-record"); },
});
await expect(bridge.create(root, "sessions", filename, Buffer.from("secret-record")))
.rejects.toThrow("auth_session_store_invalid");
});
test("rejects a claimed-read response without bounded record bytes", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({ code: 0, stdout: Buffer.from('{"version":1,"ok":true,"found":true}\n'), stderr: Buffer.alloc(0) }),
});
await expect(bridge.readClaim(root, filename)).rejects.toThrow("auth_session_store_invalid");
});
test("rejects an executable value that would require shell parsing", () => {
expect(() => createWindowsAuthStorageBridge({ thtExecutable: "tht.exe && unexpected" }))
.toThrow("auth_session_store_invalid");
});
test("parses the lower-camel list DTO emitted by the Go helper for a nonempty directory", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
// This is the raw JSON object emitted by authstorage.response after Go's DTO encoding.
stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${filename}","modifiedUnixMs":1893456245000}]}\n`),
stderr: Buffer.alloc(0),
}),
});
await expect(bridge.list(root, "oidc")).resolves.toEqual([
{ name: filename, modifiedUnixMs: 1_893_456_245_000 },
]);
});
test("passes an explicit bounded directory limit to the Go helper", async () => {
const invoke = vi.fn(async () => ({
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"entries":[]}\n'),
stderr: Buffer.alloc(0),
}));
const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke });
await expect(bridge.list(root, "oidc", 192)).resolves.toEqual([]);
expect(JSON.parse(invoke.mock.calls[0][0].input.toString("utf8"))).toMatchObject({
operation: "list",
directory: "oidc",
maximumEntries: 192,
});
});
test("uses a strict, bounded continuation page for ordinary Windows session maintenance", async () => {
const invoke = vi.fn(async () => ({
code: 0,
stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${filename}","modifiedUnixMs":1}],"more":false}\n`),
stderr: Buffer.alloc(0),
}));
const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke }) as unknown as {
listPage(root: string, directory: "sessions", after: string | undefined, maximumEntries: number): Promise<{
entries: Array<{ name: string; modifiedUnixMs: number }>;
more: boolean;
}>;
};
await expect(bridge.listPage(root, "sessions", "0".repeat(64) + ".json", 512)).resolves.toEqual({
entries: [{ name: filename, modifiedUnixMs: 1 }],
more: false,
});
expect(JSON.parse(invoke.mock.calls[0][0].input.toString("utf8"))).toMatchObject({
operation: "list",
directory: "sessions",
maximumEntries: 512,
continuation: true,
afterName: "0".repeat(64) + ".json",
});
});
test("rejects ambiguous ordinary-session continuation responses", async () => {
const after = "f".repeat(64) + ".json";
const low = "a".repeat(64) + ".json";
const high = "b".repeat(64) + ".json";
const cases = [
{ label: "missing more marker", body: { entries: [{ name: filename, modifiedUnixMs: 1 }] } },
{ label: "more without a full page", body: { entries: [{ name: filename, modifiedUnixMs: 1 }], more: true } },
{ label: "non-progressing name", body: { entries: [{ name: low, modifiedUnixMs: 1 }], more: false } },
{ label: "duplicate names", body: { entries: [{ name: high, modifiedUnixMs: 1 }, { name: high, modifiedUnixMs: 2 }], more: false } },
];
for (const { body } of cases) {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`),
stderr: Buffer.alloc(0),
}),
}) as unknown as {
listPage(root: string, directory: "sessions", afterName: string | undefined, maximumEntries: number): Promise<unknown>;
};
await expect(bridge.listPage(root, "sessions", after, 512)).rejects.toThrow("auth_session_store_invalid");
}
});
test("accepts a bounded ordinary-session page larger than the legacy 256-entry limit", async () => {
const entries = Array.from({ length: 300 }, (_unused, index) => ({
name: `${index.toString(16).padStart(64, "0")}.json`,
modifiedUnixMs: 1_893_456_245_000,
}));
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, entries })}\n`),
stderr: Buffer.alloc(0),
}),
});
await expect(bridge.list(root, "sessions", 300)).resolves.toHaveLength(300);
});
test("parses the Go helper's required empty entries array", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"entries":[]}\n'),
stderr: Buffer.alloc(0),
}),
});
await expect(bridge.list(root, "sessions")).resolves.toEqual([]);
});
test("allows only canonical OIDC claim removal and rejects claims elsewhere", async () => {
const claim = `${"b".repeat(64)}.claim`;
const invoke = vi.fn(async () => ({
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"removed":true}\n'),
stderr: Buffer.alloc(0),
}));
const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke });
await expect(bridge.remove(root, "oidc", claim)).resolves.toBe(true);
await expect(bridge.remove(root, "sessions", claim)).rejects.toThrow("auth_session_store_invalid");
await expect(bridge.read(root, "oidc", claim)).rejects.toThrow("auth_session_store_invalid");
await expect(bridge.create(root, "oidc", claim, Buffer.from("record"))).rejects.toThrow("auth_session_store_invalid");
await expect(bridge.replace(root, "oidc", claim, Buffer.from("record"))).rejects.toThrow("auth_session_store_invalid");
await expect(bridge.remove(root, "oidc", `../${claim}`)).rejects.toThrow("auth_session_store_invalid");
await expect(bridge.remove(root, "oidc", `${claim}.bak`)).rejects.toThrow("auth_session_store_invalid");
expect(invoke).toHaveBeenCalledTimes(1);
});
test("rejects OIDC claim entries returned for a sessions list", async () => {
const claim = `${"c".repeat(64)}.claim`;
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
stdout: Buffer.from(`{"version":1,"ok":true,"entries":[{"name":"${claim}","modifiedUnixMs":1}]}\n`),
stderr: Buffer.alloc(0),
}),
});
await expect(bridge.list(root, "sessions")).rejects.toThrow("auth_session_store_invalid");
});
test("settles a stdin-closed looping helper by a final deadline when close never arrives", async () => {
vi.useFakeTimers();
const child = new FakeBridgeChild();
const { bridge, spawnChild } = bridgeForChild(child);
const pending = bridge.list(root, "sessions");
const outcome = pending.then(() => "resolved", () => "rejected");
try {
await vi.advanceTimersByTimeAsync(5_000);
expect(spawnChild).toHaveBeenCalledOnce();
expect(child.kill).toHaveBeenCalledOnce();
expect(child.unref).toHaveBeenCalledOnce();
expect(child.stdin.destroyed).toBe(true);
await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending");
await vi.advanceTimersByTimeAsync(1_000);
expect(child.kill).toHaveBeenCalledTimes(2);
await expect(outcome).resolves.toBe("rejected");
expect(() => child.emit("error", new Error("late helper failure"))).not.toThrow();
expect(() => child.stdin.emit("error", new Error("late stdin failure"))).not.toThrow();
} finally {
child.close();
vi.useRealTimers();
}
});
test("releases bounded late-error guards when a finally-dead helper closes", async () => {
vi.useFakeTimers();
const child = new FakeBridgeChild();
const { bridge } = bridgeForChild(child);
const outcome = bridge.list(root, "sessions").then(() => "resolved", () => "rejected");
try {
await vi.advanceTimersByTimeAsync(6_000);
await expect(outcome).resolves.toBe("rejected");
expect(child.listenerCount("error")).toBe(1);
expect(child.stdin.listenerCount("error")).toBe(1);
expect(child.stdout.listenerCount("error")).toBe(1);
expect(child.stderr.listenerCount("error")).toBe(1);
child.close();
expect(child.listenerCount("error")).toBe(0);
expect(child.stdin.listenerCount("error")).toBe(0);
expect(child.stdout.listenerCount("error")).toBe(0);
expect(child.stderr.listenerCount("error")).toBe(0);
} finally {
vi.useRealTimers();
}
});
test.each(["stdout", "stderr"] as const)("aborts a %s-flooding helper and waits for close", async (stream) => {
const child = new FakeBridgeChild();
const { bridge, spawnChild } = bridgeForChild(child);
const pending = bridge.list(root, "sessions");
const outcome = pending.then(() => "resolved", () => "rejected");
await Promise.resolve();
expect(spawnChild).toHaveBeenCalledOnce();
child[stream].write(Buffer.alloc(64 * 1024 + 1));
await Promise.resolve();
expect(child.kill).toHaveBeenCalledOnce();
expect(child.stdin.destroyed).toBe(true);
await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending");
child.close();
await expect(outcome).resolves.toBe("rejected");
});
test("aborts a helper when its stdin errors and waits for termination", async () => {
const child = new FakeBridgeChild();
const { bridge, spawnChild } = bridgeForChild(child);
const stdinErrored = new Promise<void>((resolve) => child.stdin.once("error", () => resolve()));
child.stdin.once("finish", () => child.stdin.destroy(new Error("stdin failure")));
const pending = bridge.list(root, "sessions");
const outcome = pending.then(() => "resolved", () => "rejected");
await Promise.resolve();
expect(spawnChild).toHaveBeenCalledOnce();
await stdinErrored;
expect(child.kill).toHaveBeenCalledOnce();
child.close();
await expect(outcome).resolves.toBe("rejected");
});
test("aborts an errored child exactly once and waits for its close event", async () => {
const child = new FakeBridgeChild();
const { bridge, spawnChild } = bridgeForChild(child);
const pending = bridge.list(root, "sessions");
const outcome = pending.then(() => "resolved", () => "rejected");
await Promise.resolve();
expect(spawnChild).toHaveBeenCalledOnce();
child.emit("error", new Error("helper error"));
child.emit("error", new Error("duplicate helper error"));
expect(child.kill).toHaveBeenCalledOnce();
await expect(Promise.race([outcome, Promise.resolve("pending")])).resolves.toBe("pending");
child.close();
await expect(outcome).resolves.toBe("rejected");
expect(() => child.emit("error", new Error("late helper failure"))).not.toThrow();
expect(() => child.stdin.emit("error", new Error("late stdin failure"))).not.toThrow();
expect(() => child.stdout.emit("error", new Error("late stdout failure"))).not.toThrow();
expect(() => child.stderr.emit("error", new Error("late stderr failure"))).not.toThrow();
});
test("fails closed when launching the helper throws before a child exists", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
spawnChild: () => { throw new Error("launch detail must not escape"); },
});
await expect(bridge.list(root, "sessions")).rejects.toThrow("auth_session_store_invalid");
});
test.each([
...(["windows", "posix"] as const).flatMap((pathStyle) =>
(["timeout", "stdout", "stderr", "stdin"] as const).map((mode) => ({ pathStyle, mode }))),
])("settles a real $pathStyle $mode helper within the production deadline", async ({ pathStyle, mode }) => {
const { bridge, marker } = realChildBridge(mode, pathStyle);
const startedAt = Date.now();
const pending = bridge.list(pathStyle === "windows" ? root : posixRoot, "sessions");
const outcome = pending.then(() => undefined, (error: unknown) => error);
await waitForMarker(marker, "started");
if (mode === "stdin") await waitForMarker(marker, "before-input");
await expect(outcome).resolves.toMatchObject({ message: "auth_session_store_invalid" });
await waitForMarker(marker, "terminated");
expect(Date.now() - startedAt).toBeLessThan(1_500);
}, 5_000);
});