TestDebugLogFilePermsAreOwnerOnly: the log captures every prompt and tool-call payload: bash args can carry heredoc secrets, so a world-readable log leaks them. 0o600 only.
(t *testing.T)
| 679 | if !strings.Contains(logStr, want) { |
| 680 | t.Fatalf("verbose log missing %q\n--- log.txt ---\n%s", want, logStr) |
| 681 | } |
| 682 | } |
| 683 | |
| 684 | // Dated timestamp: "[2006-01-02 15:04:05.000]", not the old bare clock. |
| 685 | first := logStr[:strings.IndexByte(logStr, '\n')] |
| 686 | if len(first) < 21 || first[0] != '[' || first[5] != '-' || first[8] != '-' || first[11] != ' ' { |
| 687 | t.Fatalf("log timestamp missing date component: %q", first) |
| 688 | } |
| 689 | } |
| 690 | |
| 691 | // TestCtxPressureTripwire: the round_done companion warning fires only when the |
| 692 | // server counted prompt reaches 95% of the active window. The bytes/4 packer |
| 693 | // undercounts code heavy history (~1.6x measured on a real run), so the server |
| 694 | // count is the only signal that the real prompt is about to spill past the |
| 695 | // window into silent server side truncation. |
nothing calls this directly
no test coverage detected