✔ actual process kill between provider execution and persisted result recovers without duplicate work or charge (9971.9582ms)
✔ outside-owner enrollment saves one identity, reuses it for status, and keeps secrets out of results (575.4402ms)
✔ public gateway completes prefix-hosted provider loop and denies operator and ambiguous routes (3934.7283ms)
✔ gateway rejects redirects, bounds request/response size, and returns safe upstream failures (358.3142ms)
✔ agent API never forwards credentials through redirects and cancels stalled responses (427.9282ms)
✔ paid buyer can record raw usefulness claims idempotently without changing verified reputation or receipts (1881.8514ms)
✔ outcome reports require the paid task owner and bounded criterion/assessment (475.5816ms)
✔ autonomous buyer discovers two implementations, selects, falls back, pays, receives result, and learns (911.1329ms)
✔ 24 concurrent duplicate commissions produce one execution, debit and reputation success (1124.4112ms)
✔ buyer and fulfilled provider can export signed evidence; unrelated agents cannot, and tampering fails (1134.2121ms)
✔ idempotency is canonical across object key order and scoped to buyer identity (334.7704ms)
✔ unfunded buyer does no work; explicit funding and retry resume the same commission (601.3498ms)
✔ capture failure retries saved result without repeating provider work or penalizing reputation (385.2123ms)
✔ invalid result is rejected and authorizations are released before approved fallback (533.5976ms)
✔ provider timeout falls back and does not charge for the late provider result (15444.4257ms)
✔ all providers failing releases every hold; replay is passive and explicit retry is bounded (699.8059ms)
✔ quotes remain pinned when provider price and marketplace fee change (349.0481ms)
✔ buyer budget includes fee and refuses an unaffordable fallback before commission (560.9959ms)
✔ authentication prevents impersonation, unauthorized payouts, private event reads and task reads (424.2347ms)
✔ new independent provider joins through registration and publication without changing the market (621.9409ms)
✔ no unpaid result is exposed while settlement requires operator reconciliation (401.9145ms)
✔ concurrent distinct tasks cannot overspend a sandbox funding authorization (1469.7376ms)
✔ operator reconciliation retains work and payment identity; buyer cannot bypass review (2845.9574ms)
✔ public OpenAPI resolves references and preserves authentication for financial routes (736.0032ms)
✔ market recovers persisted validated work after restart and settles exactly once (1036.9429ms)
✔ two workers on one SQLite database cannot both execute a task (1384.089ms)
✔ event history and balanced accounting are append-only, and funding replays cannot mint extra test money (352.6689ms)
✔ SSRF controls reject private, metadata, rebinding-compatible IPs, credentials and non-HTTP schemes (8.6444ms)
✔ both summarizers deliver grounded Unicode results; malformed contracts are rejected (7.1617ms)
✔ valid JSON with a non-object body is rejected before registration or commissioning (854.44ms)
✔ provider persists and deduplicates an identical signed attempt after its own restart (953.9613ms)
✔ Stripe adapter uses manual capture, deterministic idempotency and atomic destination fee routing (137.4027ms)
✔ Stripe lost authorization response retries the same operation and blocks fallback until reconciled (29.8518ms)
✔ Stripe destination settlement verifies EUR conversion without confusing it with a USD quote (33.9763ms)
✔ Stripe zero fee quotes need no application fee object and delayed routing retries the original capture (29.8038ms)
✔ Stripe lost capture response is reconciled by reading the intent without another capture (40.1234ms)
✔ Stripe expired unresolved idempotency keys require review instead of recreating payments (18.9635ms)
✔ Stripe definitive card decline can be cancelled and retried with a fresh funded attempt (26.0837ms)
✔ Stripe mandate limits concurrent authorizations and excludes processor fees from platform profit claims (28.9692ms)
✔ Stripe amount or destination mismatch never yields a settled receipt (16.4281ms)
✔ Stripe client rejects live keys and serializes nested fields without exposing credentials (10.6739ms)
✔ self-service payout enrollment reuses agent-owned account and verifies capabilities (97.8718ms)
✔ self-service buyer enrollment binds saved payment method and spending mandate to authenticated owner (39.7544ms)
✔ concurrent buyer and provider enrollment preserves both payment identities (150.3192ms)
✔ stale enrollment completion cannot overwrite a newer owner spending mandate (20.685ms)
ℹ tests 45
ℹ suites 0
ℹ pass 45
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 63802.8718
