Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

test: cover session permission, command, and persist fail-closed gates

open
Stack 2/2
#346 opened by cursor[bot]cursor/missing-test-coverage-266c→main
Conversation0
cursor[bot]
Commits
0
Files changed…
opened this pull request
Author
· last week

Main is still at e2d5f95e (unchanged since 2026-09-11). This run adds fail-closed coverage for extracted session collaborators that #331–#345 did not claim.

Risky behavior now covered

  • Child-session authority: agent sessions cannot list/hydrate/delete/spawn or use workspace backups.
  • Snapshot isolation: live children, foreign workspaces, unknown ids, and missing snapshots fail closed; the active session cannot delete itself.
  • Busy reset: a running session cannot wipe history, todos, or provider state.
  • Config conflicts: setting a value and its clear flag together is rejected and not persisted; blank titles do not rename.
  • Slash commands / extension ids: blank, unknown, and empty-expand commands never become user messages; blank skill/plugin/marketplace ids fail before lookup; busy or mutation-blocked sessions do not mutate.
  • Persistence queue: disabled persistence never writes; a queued flush projects lastEventSeq + 1; exhausted sqlite locks emit persist + lock telemetry after 3 attempts.

Test files added/updated

  • test/session/sessionAdmin.fail-closed.test.ts (added)
  • test/session/sessionMetadata.fail-closed.test.ts (added)
  • test/session/skillManager.fail-closed.test.ts (added)
  • test/server/persistenceManager.test.ts (updated)

Why these tests materially reduce regression risk

These paths are permission, validation, and persistence gates on shared session collaborators. A regression would leak child-session control, apply contradictory config clears, turn invalid slash commands into user turns, or drop/mis-sequence snapshot writes. The tests prove the reject/no-op contract without changing production behavior.

Validation

  • Targeted 15 new tests + existing PersistenceManager suite + test/platform-boundary.test.ts: 22 passed
  • bun run typecheck and Biome on the repo: clean
  • Isolated targeted files are the evidence (full suite historically truncates late)
  • No os.tmpdir() in new tests (platform-boundary ratchet)
Open in Web View Automation 
This branch can’t be merged automatically yet
Branch comparison failed — verify branches still exist in storage.
0 approving reviews
None yet
Checks
No checks recorded
Fast-forward
Source must contain the target branch tip
main ← cursor/missing-test-coverage-266c

Sign in to comment.

Stack

2/2
1

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.

Update README.md

#125 mobile-fixes ← main

Updated 4 months ago

merged
2

test: cover session permission, command, and persist fail-closed gates

#346 main ← cursor/missing-test-coverage-266c

Updated last week

open