| CLI decomposition | Routing, entry, options, rendering, foundation, platform, ecosystem, governance, and engineering handlers have direct contract tests. | src/cli/, test/cli-*-handlers.test.js, test/cli-entry-output.test.js |
| State recovery | Atomic writes, checksums, exclusive locks, stale-lock recovery, journals, bounded retention, snapshots, recovery validation, and fail-closed corruption handling. | src/state-engine.js, test/state-engine.test.js |
| Concurrency | Exactly 32 concurrent state writers complete without lost updates. | test/state-engine.test.js |
| Failure injection | Disk-full and permission failures remain visible, preserve committed state, and remove owned temporary files. | src/state-engine.js, test/state-engine.test.js |
| Corruption fuzzing | 1,000 deterministic malformed journal cases fail without changing state. | test/state-engine-fuzz.test.js |
| Vault lifecycle | AES-256-GCM, Argon2id, PBKDF2 fallback, migration, rotation rollback, recovery, tamper rejection, and bounded encrypted history. | src/credentials.js, test/credentials.test.js |
| Mutation testing | State, vault, consent, policy, and rollback each exceed the 80% mutation threshold; the deterministic suite kills 19 of 19 safety mutants. | scripts/mutation-gate.js, npm run test:mutation |
| Performance | Warm CLI startup and ordinary state reads have enforced budgets of 250 ms and 50 ms. CLI startup uses one warm-up and the median of five measured launches so transient runner contention cannot mask sustained regressions. | scripts/benchmark.js, src/performance-metrics.js, npm run benchmark |
| Coverage enforcement | The test runner fails below 90% lines, 85% branches, or 90% functions. | scripts/run-tests.js, npm run test:coverage |
| Managed documentation | Canonical generated references update only when their prior content hash proves generator ownership; modified files fail closed as conflicts. | src/documentation-generator.js, test/documentation-generator.test.js |
| Workspace compatibility | Published-state fixtures for v1.1 and v1.2 migrate and roll back without losing state. | test/fixtures/workspaces/, test/upgrade.test.js |
| CI | Windows, Ubuntu, and macOS run the compatibility suite; Ubuntu additionally runs coverage, mutation, and performance gates. | .github/workflows/ci.yml |