CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Medium

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

test_prune_worktrees.shskills/herdr-foreman/tests/

#!/usr/bin/env bash
# Outcome-based tests for skills/herdr-foreman/prune-worktrees.sh.
#
# Real local git repos, driven offline: a bare "origin" plus a shared checkout
# cloned from it, per scenario, so the cases share no state and run in any
# order (rules/testing-standards.md Independence). WORKTREE_ROOT points at the
# temp dir so nothing lands in the operator's real ~/.worktrees.
#
# The harness drops `set -e` to aggregate results, so every fixture-setup
# command is checked explicitly and aborts with a fatal diagnostic on failure
# (rules/error-handling.md aggregate-reporting carve-out).
#
# Covers:
#   1. Merged + clean      -> worktree removed, branch deleted.
#   2. Merged via origin   -> a branch whose commit landed on origin's default
#                             branch is removed after the fetch.
#   3. Unpushed, idle      -> kept, reason unpushed; branch survives.
#   4. Dirty (untracked)   -> kept, reason dirty.
#   5. Dirty (modified)    -> kept, reason dirty.
#   6. Detached, unpushed  -> kept, reason unpushed.
#   7. Locked              -> kept, reason locked.
#   8. Outside the root    -> kept, reason outside-root, never removed.
#   9. Shared checkout     -> never listed, never removed; default branch kept.
#  10. Branch, no worktree -> merged one deleted, unpushed one kept.
#  11. Dry run             -> same decisions reported, nothing changes.
#  12. Stale metadata      -> a hand-deleted worktree dir is pruned.
#  13. Foreign worktree    -> a directory of ANOTHER repo under the root is
#                             untouched.
#  14. Usage / not a repo  -> exit 1, no JSON.
#  15. Fetch failure       -> exit 1, no JSON; nothing judged from stale refs.
#  16. Tool failure        -> a merge-base error is a failed row on stdout and
#                             stderr, exit 2, never a kept 'unmerged'.
#  17. Dry-run metadata    -> stale metadata and origin/HEAD survive a dry run;
#                             the remote default is still resolved.
#  18. Unenterable         -> a worktree the run cannot cd into is a failed
#                             row, exit 2 (skipped as root, who can enter anything).
#  19. Shadowing           -> a tag named like a branch, or a local branch
#                             named origin/main, cannot stand in for either operand.
#  20. Untraversable parent-> absence is not confirmed; failed row, metadata
#                             kept, exit 2 (skipped as root).
#  21. Raced branch        -> a tip that moved after its ancestry check is kept.
#  22. Half-done removal   -> a removal is reported even when its branch
#                             deletion then fails.
#  23. Deferred prunable   -> a prunable branch survives a skipped metadata removal.
#  24. Newline path        -> a record is not split by a newline in the path
#                             (kept idle-unknown: the probe cannot match it).
#  25. Branch config       -> a deleted branch's branch.<name> config goes too.
#  26. Locked and gone     -> git keeps its metadata, so its branch is kept too.
#  27. No -z               -> a git without `-z` decides nothing at all.
#  28. Dry-run deferral    -> a preview defers what the live run would defer.
#  29. Config sibling      -> branch.<name>.<key> of a LONGER branch name is
#                             not read as this branch's config.
#  30. Claimed branch      -> a branch a worktree holds is kept, not deleted.
#  31. Claimed mid-delete  -> a worktree claiming it inside the deletion's own
#                             window gets the branch back.
#  32. Newline parent      -> absence is confirmed through a parent whose own
#                             name ends in a newline.
#  33. Unreadable recheck   -> a failed post-deletion occupancy read is a
#                             failure, never an unoccupied answer.
#  87. Root replaced      -> a root swapped after the first removal stops
#                             every later removal, branch deletion and the
#                             metadata removal; exit 2.
#  88. Caller's root id    -> a root other than PRUNE_ROOT_ID names decides
#                             nothing; exit 1.
#  89. Root unlistable     -> a root that loses its permissions mid-run is a
#                             changed root (skipped as root, who lists
#                             anything).
#  90. Root moved at the   -> a root renamed between its last identity check
#      metadata step          and the metadata prune keeps the registrations
#                             of the worktrees it still holds.
#  91. Lock fails          -> a live entry that cannot be locked stops the
#                             prune: the stale entry and its branch stay;
#                             exit 2 (skipped as root).
#  92. Path reappears      -> a worktree moved back between the absence check
#                             and the prune keeps its files, commits and
#                             registration.
#  93. Stale outside root  -> a vanished registration outside the root is
#                             dropped too.
#  94. Relative link       -> a vanished registration git recorded with a
#                             relative gitdir is dropped (skipped on a git
#                             without --relative-paths).
#  95. Operator's lock     -> an entry someone else locked stays locked with
#                             its reason; this run's own locks are all gone.
#  96. Killed run's lock   -> a prune lock whose pid is dead is released at
#                             the next run; one held by a live pid is not.
#  34. Recreated config   -> a branch.<name> section recreated after the
#                             deletion is left untouched.
#  35. Reachable, idle      -> a clean worktree whose HEAD an origin branch
#                             holds is removed, detached or on a pushed branch.
#  36. In use               -> a process with its cwd inside keeps it.
#  37. Dirty, idle          -> kept and reported with its changed-file count and
#                             command; nothing touched.
#  38. Locked, idle         -> kept, reported with its lock reason.
#  39. Not idle             -> fresh activity keeps a reachable worktree.
#  40. Unpushed, idle       -> kept and reported with its commit count and push
#                             command.
#  41. No process probe     -> lsof missing keeps it as idle-unknown.
#  43. Dry run              -> the removal is previewed, nothing changes.
#  44-45. Merged path       -> fresh activity or a process inside keeps a clean
#                             merged worktree.
#  46. Fresh edit           -> a tracked file edited now keeps an old worktree.
#  47. Changed at removal   -> a process arriving before the removal keeps it,
#                             in a dry run's preview too (47b).
#  51. Dirty submodule      -> kept.
#  59. Newline path         -> lsof cannot report it faithfully: never idle.
#  60. Other remote         -> a ref of a remote other than origin proves nothing.
#  61. Proof gone           -> reachability re-derived just before removal.
#  62. Gitlink, embedded    -> a dirty gitlink without .gitmodules, and an
#                             embedded repository (untracked, ignored, or below
#                             an untracked directory), keep the worktree.
#  69. Dry/live agreement   -> both judge origin as it is now.
#  71. Force-push           -> a merge dropped before the removal keeps it.
#  72. Credential URL       -> a failed remote command never relays the URL.
#  80. Origin-held branch   -> a branch with no worktree whose tip origin holds
#                             is deleted.
#  81. Unpushed branch      -> idle: reported with count, age and command;
#                             fresh: not-idle; neither is deleted.
#  82. Branch proof         -> a merge dropped before the deletion keeps it.
#  83. Partial lsof         -> an unreadable cwd of a live process: idle-unknown;
#                             a mount lsof could not stat, or an exited
#                             process, is no gap.
#  85. Default changed      -> origin's HEAD naming another branch before the
#                             removal keeps a merged worktree and branch.
#  84. Unreadable subdir    -> the nested-repository walk keeps the worktree.
#
# Run: bash skills/herdr-foreman/tests/test_prune_worktrees.sh
set -uo pipefail

die() { echo "fatal: $*" >&2; exit 2; }
cleanup() {
  # `ps -p` exits 1 for a pid that is gone and prints nothing on stderr.
  if [[ -n "${SLEEPER:-}" ]] && ps -p "$SLEEPER" >/dev/null; then kill "$SLEEPER" || echo "warn: could not stop sleeper $SLEEPER" >&2; fi
  [[ -n "${TMP:-}" ]] && ! rm -rf "$TMP" && echo "warn: could not remove $TMP" >&2
  return 0
}
pass() { PASS=$((PASS+1)); }
fail() { FAIL=$((FAIL+1)); echo "  ✗ FAIL: $1" >&2; }

# Run a fixture command, stderr captured: on failure the harness stops with
# the command's own words and the command to rerun, never a silent exit.
quiet() { # <what> <command...>
  local what="$1" rc=0; shift
  "$@" 2>"$TMP/quiet.err" || rc=$?
  if (( rc != 0 )); then
    die "${what} (exit ${rc}): $(tr '\n' ' ' < "$TMP/quiet.err") — rerun \`$*\` by hand to see the whole failure"
  fi
}

mk_repo() { # <prefix> -> sets SHARED, SEED, BARE
  local prefix="$1"
  BARE="$TMP/${prefix}.git"
  SEED="$TMP/${prefix}-seed"
  git init -q --bare -b main "$BARE"            || die "git init --bare failed"
  quiet "git clone failed" git clone -q "$BARE" "$SEED"
  printf 'x\n' > "$SEED/f"                      || die "seed write failed"
  git -C "$SEED" -c user.name=t -c user.email=t@t add f  || die "git add failed"
  git -C "$SEED" -c user.name=t -c user.email=t@t commit -q -m c1 || die "git commit failed"
  git -C "$SEED" push -q origin main            || die "git push failed"
  SHARED="$TMP/${prefix}-shared"
  quiet "git clone (shared) failed" git clone -q "$BARE" "$SHARED"
  quiet "git remote set-head failed" git -C "$SHARED" remote set-head origin --auto >/dev/null
  # Every case gets its own worktree root: no case sees another's worktrees.
  ROOT="$TMP/root-${prefix}"
  mkdir -p "$ROOT" || die "cannot create the worktree root $ROOT"
}

add_wt() { # <shared> <branch> <path>  (cut at main)
  quiet "worktree add $2 failed" git -C "$1" worktree add -q -b "$2" "$3" origin/main
}

commit_in() { # <worktree> <file>
  printf 'y\n' > "$1/$2" || die "write $2 failed"
  git -C "$1" -c user.name=t -c user.email=t@t add "$2" || die "git add in $1 failed"
  git -C "$1" -c user.name=t -c user.email=t@t commit -q -m "c-$2" || die "git commit in $1 failed"
}

run() { # <args...>
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 bash "$SCRIPT" "$@" 2>"$TMP/err.$RUN_SEQ")"
  RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
}

# jq-free field readers over $OUT.
removed_paths() { python3 -c 'import json,sys; print("\n".join(r["path"] for r in json.load(sys.stdin)["worktrees_removed"]))' <<<"$OUT"; }
kept_reason() { python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((r["reason"] for r in d["worktrees_kept"] if r["path"]==sys.argv[1]), ""))' "$1" <<<"$OUT"; }
branches_deleted() { python3 -c 'import json,sys; print("\n".join(json.load(sys.stdin)["branches_deleted"]))' <<<"$OUT"; }
branch_kept_reason() { python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((r["reason"] for r in d["branches_kept"] if r["branch"]==sys.argv[1]), ""))' "$1" <<<"$OUT"; }
field() { python3 -c 'import json,sys; print(json.load(sys.stdin)[sys.argv[1]])' "$1" <<<"$OUT"; }
mentions_path() { python3 -c 'import json,sys; d=json.load(sys.stdin); sys.exit(0 if any(r["path"]==sys.argv[1] for r in d["worktrees_kept"]+d["worktrees_removed"]) else 1)' "$1" <<<"$OUT"; }
has_branch() { # <shared> <branch> -> 0 present, 1 absent; a git error aborts the harness
  local rc=0
  git -C "$1" show-ref --verify --quiet "refs/heads/$2" || rc=$?
  case "$rc" in 0) return 0 ;; 1) return 1 ;; *) die "git show-ref failed (exit $rc) for $2 in $1" ;; esac
}
# Echo `unlocked`, or `locked:<reason>`, for the registered <path>; a missing
# registration or a failed read aborts the harness.
lock_of() { # <shared> <path>
  local snap="$TMP/lock-of.snap"
  git -C "$1" worktree list --porcelain -z >"$snap" || die "git worktree list failed in $1"
  python3 - "$snap" "$2" <<'PY' || die "lock_of: $2 is not registered"
import sys
raw = open(sys.argv[1], "rb").read().decode("utf-8", "surrogateescape")
state, found = None, False
for field in raw.split("\0"):
    if field.startswith("worktree "):
        found = field[len("worktree "):] == sys.argv[2]
        if found:
            state = "unlocked"
    elif found and field == "locked":
        state = "locked:"
    elif found and field.startswith("locked "):
        state = "locked:" + field[len("locked "):]
if state is None:
    sys.exit(1)
print(state)
PY
}

listed() { # <shared> <path>  -> 0 listed, 1 not listed; a tool failure aborts the harness
  local inventory rc=0
  inventory="$(git -C "$1" worktree list --porcelain)" || die "git worktree list failed in $1"
  grep -qxF "worktree $2" <<<"$inventory" || rc=$?
  case "$rc" in 0) return 0 ;; 1) return 1 ;; *) die "grep failed (exit $rc) reading the worktree inventory" ;; esac
}


# Age a worktree: its directory and its gitdir's HEAD, index and logs/HEAD all
# last written on 2020-01-01. IDLE_NOW is nine days later, fixed.
IDLE_NOW=1578614400
age_wt() { # <worktree>
  local gitdir f
  gitdir="$(git -C "$1" rev-parse --absolute-git-dir)" || die "rev-parse --absolute-git-dir failed in $1"
  for f in "$gitdir/HEAD" "$gitdir/index" "$gitdir/logs/HEAD"; do
    if [[ -e "$f" ]]; then touch -t 202001010000 "$f" || die "touch $f failed"; fi
  done
  find "$1" -path "$1/.git" -prune -o -exec touch -h -t 202001010000 {} + || die "touch the files of $1 failed"
}
idle_run() { # <extra env...> -- runs the script on $SHARED with the fixed clock
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_NOW="$IDLE_NOW" "$@" bash "$SCRIPT" "$SHARED" "${IDLE_ARGS[@]+"${IDLE_ARGS[@]}"}" 2>"$TMP/err.$RUN_SEQ")"
  RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
}



# Start a background process whose cwd is <dir>, and return only once it is
# there: the child writes its physical cwd into a FIFO after the cd, then
# execs sleep; the harness's read of that FIFO returns exactly then, with no
# polling and no deadline. The process is registered with the fake lsof.
start_sleeper() { # <dir>
  local want ready="$TMP/sleeper.ready" got
  want="$(cd "$1" && pwd -P && printf x)" || die "cannot resolve the sleeper's directory $1"
  want="${want%x}"; want="${want%$'\n'}"
  rm -f "$ready" || die "cannot clear the sleeper's FIFO $ready"
  mkfifo "$ready" || die "mkfifo $ready failed"
  (
    if cd "$1"; then
      { pwd -P; printf x; } > "$ready"
      exec sleep 3600
    fi
    printf 'cd-failed' > "$ready"
  ) &
  SLEEPER=$!
  got="$(cat "$ready")" || die "cannot read the sleeper's FIFO $ready"
  [[ "$got" == *x ]] || die "the sleeper could not enter $1: $got"
  got="${got%x}"; got="${got%$'\n'}"
  [[ "$got" == "$want" ]] || die "the sleeper reported cwd '$got', not '$want'"
  # Registered with the fake probe; a path it cannot hold on one line is one
  # the script refuses to match before probing at all.
  if [[ "$want" != *$'\n'* ]]; then
    printf '%s %s\n' "$SLEEPER" "$want" >> "$FAKE_LSOF_CWDS" || die "cannot register the sleeper with the fake lsof"
  fi
}

kept_field() { python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((r.get(sys.argv[2], "") for r in d["worktrees_kept"] if r["path"]==sys.argv[1]), ""))' "$1" "$2" <<<"$OUT"; }
removed_head() { python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((r["head"] for r in d["worktrees_removed"] if r["path"]==sys.argv[1]), ""))' "$1" <<<"$OUT"; }
lock_reason_of() { python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((r.get("lock_reason") or "" for r in d["worktrees_kept"] if r["path"]==sys.argv[1]), ""))' "$1" <<<"$OUT"; }
# An lsof stand-in: silent until its <n>th call, then reporting a process
# working inside <path>.
lsof_turns_busy() { # <dir> <n> <path>
  mkdir -p "$1" || die "mkdir $1 failed"
  # shellcheck disable=SC2016  # The stand-in's $(...) must run in the stand-in, not here.
  printf '#!/usr/bin/env bash\nset -euo pipefail\nprintf x >> %q\nif (( $(wc -c < %q) >= %s )); then printf "p1\\0\\nfcwd\\0n%%s\\0\\n" %q; fi\n' \
    "$1/calls" "$1/calls" "$2" "$3" > "$1/lsof" || die "write lsof stand-in failed"
  chmod +x "$1/lsof" || die "chmod lsof stand-in failed"
}

# Stop the background sleeper: SIGTERM, then its exit status must be 143
# (128 + SIGTERM); anything else means the fixture did not behave as assumed.
stop_sleeper() {
  local st=0
  kill "$SLEEPER" || die "could not stop the sleeper $SLEEPER"
  wait "$SLEEPER" || st=$?
  case "$st" in
    143) SLEEPER=""; : > "$FAKE_LSOF_CWDS" || die "cannot clear the fake lsof's records" ;;
    *) die "the sleeper $SLEEPER ended with status $st, not 143 (SIGTERM)" ;;
  esac
}
# The process probe every run uses: a stand-in for lsof that prints one
# NUL-framed cwd record per "<pid> <cwd>" line of $FAKE_LSOF_CWDS and nothing
# else, so the host's own process table never reaches a test. A case that
# needs a process inside a worktree registers it there; a case exercising the
# probe's failure modes names its own stand-in through PRUNE_LSOF.
write_fake_lsof() { # <path>
  mkdir -p "$(dirname "$1")" || die "mkdir for the fake lsof failed"
  cat > "$1" <<'SH' || die "write the fake lsof failed"
#!/usr/bin/env bash
set -euo pipefail
list="${FAKE_LSOF_CWDS:-}"
if [[ -z "$list" || ! -s "$list" ]]; then exit 0; fi
while IFS=' ' read -r pid cwd; do
  printf 'p%s\0\nfcwd\0n%s\0\n' "$pid" "$cwd"
done < "$list"
SH
  chmod +x "$1" || die "chmod the fake lsof failed"
}

main() {
  PASS=0; FAIL=0; RUN_SEQ=0
  SCRIPT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/prune-worktrees.sh"
  [[ -f "$SCRIPT" ]] || die "script not found: $SCRIPT"
  TMP="$(mktemp -d)" || die "mktemp failed"
  # The script reports physical paths; macOS mktemp hands out a symlinked /var.
  TMP="$(cd "$TMP" && pwd -P)" || die "resolve TMP failed"
  trap cleanup EXIT
  # The operator's git config never reaches the script under test: no global
  # identity, as on a CI runner, so every commit the script writes must carry
  # its own. Fixtures pass theirs with -c.
  : > "$TMP/gitconfig" || die "cannot create an empty global git config"
  export GIT_CONFIG_GLOBAL="$TMP/gitconfig" GIT_CONFIG_NOSYSTEM=1
  write_fake_lsof "$TMP/fake-lsof/lsof"
  export PRUNE_LSOF="$TMP/fake-lsof/lsof" FAKE_LSOF_CWDS="$TMP/fake-lsof/cwds"
  ROOT="$TMP/worktrees"
  mkdir -p "$ROOT" || die "mkdir root failed"
  real_git="$(command -v git)" || die "git not found on PATH — install git to run these tests"

  # --- 1, 3, 4, 5, 6, 7, 9, 10 share one repo: one run decides them all.
  mk_repo one
  add_wt "$SHARED" review/merged "$ROOT/one-merged"
  add_wt "$SHARED" test/unmerged "$ROOT/one-unmerged"; commit_in "$ROOT/one-unmerged" u
  add_wt "$SHARED" test/untracked "$ROOT/one-untracked"; printf 'z\n' > "$ROOT/one-untracked/scratch" || die "write failed"
  git -C "$SHARED" config status.showUntrackedFiles no || die "config failed"
  add_wt "$SHARED" test/modified "$ROOT/one-modified"; printf 'changed\n' > "$ROOT/one-modified/f" || die "write failed"
  quiet "detached add failed" git -C "$SHARED" worktree add -q --detach "$ROOT/one-detached" origin/main
  commit_in "$ROOT/one-detached" d
  add_wt "$SHARED" test/locked "$ROOT/one-locked"; git -C "$SHARED" worktree lock "$ROOT/one-locked" || die "lock failed"
  git -C "$SHARED" branch --no-track merged-no-wt origin/main || die "branch failed"
  git -C "$SHARED" branch --no-track unmerged-no-wt origin/main || die "branch failed"
  quiet "scratch add failed" git -C "$SHARED" worktree add -q "$TMP/one-scratch" unmerged-no-wt
  commit_in "$TMP/one-scratch" w
  git -C "$SHARED" worktree remove "$TMP/one-scratch" || die "scratch remove failed"

  run "$SHARED"
  echo "1. merged + clean worktree is removed and its branch deleted"
  if (( RC == 0 )) && [[ "$(removed_paths)" == *"$ROOT/one-merged"* ]] && [[ ! -e "$ROOT/one-merged" ]] && ! has_branch "$SHARED" review/merged; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  echo "3. an idle worktree with unpushed commits is kept with reason unpushed"
  if [[ "$(kept_reason "$ROOT/one-unmerged")" == unpushed ]] && [[ -d "$ROOT/one-unmerged" ]] && has_branch "$SHARED" test/unmerged; then pass; else fail "out=$OUT"; fi
  echo "4. untracked file keeps the worktree as dirty, even with status.showUntrackedFiles=no"
  if [[ "$(kept_reason "$ROOT/one-untracked")" == dirty ]] && [[ -f "$ROOT/one-untracked/scratch" ]]; then pass; else fail "out=$OUT"; fi
  echo "5. modified file keeps the worktree as dirty"
  if [[ "$(kept_reason "$ROOT/one-modified")" == dirty ]] && [[ -d "$ROOT/one-modified" ]]; then pass; else fail "out=$OUT"; fi
  echo "6. a detached worktree holding an unpushed commit is kept"
  if [[ "$(kept_reason "$ROOT/one-detached")" == unpushed ]] && [[ -d "$ROOT/one-detached" ]]; then pass; else fail "out=$OUT"; fi
  echo "7. locked worktree is kept"
  if [[ "$(kept_reason "$ROOT/one-locked")" == locked ]] && [[ -d "$ROOT/one-locked" ]]; then pass; else fail "out=$OUT"; fi
  echo "9. the shared checkout is never listed and the default branch survives"
  if ! mentions_path "$SHARED" && has_branch "$SHARED" main && [[ "$(field default_branch)" == main ]]; then pass; else fail "out=$OUT"; fi
  echo "10. merged branch without a worktree is deleted; unmerged one is kept"
  if [[ "$(branches_deleted)" == *merged-no-wt* ]] && ! has_branch "$SHARED" merged-no-wt && [[ "$(branch_kept_reason unmerged-no-wt)" == unpushed ]] && has_branch "$SHARED" unmerged-no-wt; then pass; else fail "out=$OUT"; fi

  # --- 2. merged via origin: commit on a branch, land it on origin main, prune.
  mk_repo two
  add_wt "$SHARED" feat/landed "$ROOT/two-landed"; commit_in "$ROOT/two-landed" landed
  git -C "$ROOT/two-landed" push -q origin feat/landed || die "push failed"
  git -C "$SEED" fetch -q origin || die "seed fetch failed"
  git -C "$SEED" -c user.name=t -c user.email=t@t merge -q --no-ff origin/feat/landed -m merge || die "seed merge failed"
  git -C "$SEED" push -q origin main || die "seed push failed"
  run "$SHARED"
  echo "2. a branch landed on origin's default branch is removed after the fetch"
  if (( RC == 0 )) && [[ "$(removed_paths)" == *"$ROOT/two-landed"* ]] && ! has_branch "$SHARED" feat/landed; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 8. outside the root.
  mk_repo eight
  quiet "outside add failed" git -C "$SHARED" worktree add -q -b review/outside "$TMP/eight-outside" origin/main
  run "$SHARED"
  echo "8. a worktree outside the root is kept and reported"
  if (( RC == 0 )) && [[ "$(kept_reason "$TMP/eight-outside")" == outside-root ]] && [[ -d "$TMP/eight-outside" ]] && has_branch "$SHARED" review/outside; then pass; else fail "rc=$RC out=$OUT"; fi

  # --- 11. dry run.
  mk_repo eleven
  add_wt "$SHARED" review/dry "$ROOT/eleven-dry"
  git -C "$SHARED" branch --no-track dry-no-wt origin/main || die "branch failed"
  run "$SHARED" --dry-run
  echo "11. dry run reports the decisions and changes nothing"
  if (( RC == 0 )) && [[ "$(field dry_run)" == True ]] && [[ "$(removed_paths)" == *"$ROOT/eleven-dry"* ]] && [[ "$(branches_deleted)" == *dry-no-wt* ]] && [[ -d "$ROOT/eleven-dry" ]] && has_branch "$SHARED" review/dry && has_branch "$SHARED" dry-no-wt; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 12. stale metadata.
  mk_repo twelve
  add_wt "$SHARED" review/gone "$ROOT/twelve-gone"
  rm -rf "$ROOT/twelve-gone" || die "rm failed"
  run "$SHARED"
  echo "12. a hand-deleted worktree's metadata is pruned and its merged branch deleted in the same run"
  if (( RC == 0 )) && ! listed "$SHARED" "$ROOT/twelve-gone" && [[ "$(kept_reason "$ROOT/twelve-gone")" == prunable ]] && [[ "$(branches_deleted)" == *review/gone* ]] && ! has_branch "$SHARED" review/gone; then pass; else fail "rc=$RC out=$OUT"; fi

  # --- 13. foreign worktree under the root.
  mk_repo thirteen
  local foreign_shared="$SHARED"
  mk_repo other
  add_wt "$SHARED" review/other "$ROOT/thirteen-other"
  run "$foreign_shared"
  echo "13. another repository's worktree under the root is untouched"
  if (( RC == 0 )) && [[ -d "$ROOT/thirteen-other" ]] && [[ "$OUT" != *thirteen-other* ]]; then pass; else fail "rc=$RC out=$OUT"; fi

  # --- 15. an unreachable origin is a precondition failure: nothing is judged from stale refs.
  mk_repo fifteen
  add_wt "$SHARED" review/stale "$ROOT/fifteen-stale"
  git -C "$SHARED" remote set-url origin "$TMP/nowhere.git" || die "set-url failed"
  run "$SHARED"
  echo "15. a failed fetch is exit 1 with no JSON and the merged worktree untouched"
  if (( RC == 1 )) && [[ -z "$OUT" ]] && [[ "$ERRTEXT" == *"stale refs"* ]] && [[ -d "$ROOT/fifteen-stale" ]] && has_branch "$SHARED" review/stale; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 16. a merge-base tool failure is a failed row on stderr and stdout, exit 2, never "unmerged".
  mk_repo sixteen
  add_wt "$SHARED" review/broken "$ROOT/sixteen-broken"
  git -C "$SHARED" symbolic-ref refs/remotes/origin/HEAD refs/remotes/origin/vanished || die "symbolic-ref failed"
  git -C "$SEED" push -q origin main:refs/heads/vanished || die "push vanished failed"
  git -C "$SEED" symbolic-ref HEAD refs/heads/vanished || die "seed symbolic-ref failed"
  git -C "$BARE" symbolic-ref HEAD refs/heads/vanished || die "bare HEAD failed"
  git -C "$SHARED" fetch -q origin || die "fetch failed"
  # origin's default is now `vanished`; a git shim makes merge-base itself fail
  # (exit 128), the tool failure this case is about.
  mkdir -p "$TMP/shim" || die "mkdir shim failed"
  cat > "$TMP/shim/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in *merge-base*) echo "fatal: simulated merge-base failure" >&2; exit 128 ;; esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim/git" || die "chmod shim failed"
  run_with_shim() { RUN_SEQ=$((RUN_SEQ+1)); OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"; }
  run_with_shim
  echo "16. a merge-base tool failure lands in failed, on stderr, exit 2, worktree untouched"
  if (( RC == 2 )) && [[ "$OUT" == *'"failed": [{'*merge-base* ]] && [[ "$ERRTEXT" == *"merge-base failed"* ]] && [[ "$(kept_reason "$ROOT/sixteen-broken")" == "" ]] && [[ -d "$ROOT/sixteen-broken" ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 17. dry run leaves stale metadata and remote-tracking refs in place.
  mk_repo seventeen
  add_wt "$SHARED" review/preview "$ROOT/seventeen-preview"
  rm -rf "$ROOT/seventeen-preview" || die "rm failed"
  git -C "$SHARED" symbolic-ref refs/remotes/origin/HEAD refs/remotes/origin/elsewhere || die "symbolic-ref failed"
  head_before="$(cat "$SHARED/.git/refs/remotes/origin/HEAD")" || die "read HEAD failed"
  run "$SHARED" --dry-run
  echo "17. dry run prunes no metadata, rewrites no origin/HEAD, and still finds the remote default"
  if (( RC == 0 )) && listed "$SHARED" "$ROOT/seventeen-preview" && [[ "$(cat "$SHARED/.git/refs/remotes/origin/HEAD")" == "$head_before" ]] && [[ "$(field default_branch)" == main ]] && [[ "$(kept_reason "$ROOT/seventeen-preview")" == prunable ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 18. an unenterable worktree is a failed row, exit 2, never prunable.
  if [[ "$(id -u)" != 0 ]]; then
    mk_repo eighteen
    add_wt "$SHARED" review/sealed "$ROOT/eighteen-sealed"
    chmod 000 "$ROOT/eighteen-sealed" || die "chmod failed"
    run "$SHARED"
    chmod 755 "$ROOT/eighteen-sealed" || die "chmod restore failed"
    echo "18. a worktree that cannot be entered is a failed row on stderr, exit 2"
    if (( RC == 2 )) && [[ "$OUT" == *'"failed": [{'*"cannot enter"* ]] && [[ "$ERRTEXT" == *"cannot enter"* ]] && [[ "$ERRTEXT" == *"skipping"* ]] && has_branch "$SHARED" review/sealed && listed "$SHARED" "$ROOT/eighteen-sealed"; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 19. a merged tag named like an unmerged branch must not shadow it.
  mk_repo nineteen
  add_wt "$SHARED" review/shadow "$ROOT/nineteen-shadow"; commit_in "$ROOT/nineteen-shadow" s
  git -C "$SHARED" tag review/shadow origin/main || die "tag failed"
  quiet "shadow branch failed" git -C "$SHARED" branch --no-track origin/main origin/main
  run "$SHARED"
  echo "19. ancestry is judged on fully qualified refs: a same-name tag or an origin/main local branch cannot shadow"
  if (( RC == 0 )) && [[ "$(kept_reason "$ROOT/nineteen-shadow")" == unpushed ]] && [[ -d "$ROOT/nineteen-shadow" ]] && has_branch "$SHARED" review/shadow; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 20. an ancestor that denies traversal is not "gone".
  if [[ "$(id -u)" != 0 ]]; then
    mk_repo twenty
    mkdir -p "$ROOT/twenty-parent" || die "mkdir failed"
    add_wt "$SHARED" review/hidden "$ROOT/twenty-parent/hidden"
    chmod 000 "$ROOT/twenty-parent" || die "chmod failed"
    run "$SHARED"
    chmod 755 "$ROOT/twenty-parent" || die "chmod restore failed"
    echo "20. a worktree behind an untraversable parent is a failed row, metadata and branch kept, exit 2"
    if (( RC == 2 )) && [[ "$OUT" == *'"failed": [{'*"cannot confirm"* ]] && [[ "$ERRTEXT" == *"skipping"* ]] && has_branch "$SHARED" review/hidden && listed "$SHARED" "$ROOT/twenty-parent/hidden"; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 21. a branch that moves between its ancestry check and the deletion is kept.
  mk_repo twentyone
  add_wt "$SHARED" review/racing "$ROOT/twentyone-racing"
  # Advance origin/main so the shim has a second merged commit to move to.
  commit_in "$SEED" second
  git -C "$SEED" push -q origin main || die "push failed"
  git -C "$SHARED" fetch -q origin || die "fetch failed"
  mkdir -p "$TMP/shim21" || die "mkdir shim failed"
  cat > "$TMP/shim21/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
# Move the branch on the THIRD read of its tip — the first judges it, the
# second is the pre-removal recheck, the third comes after the worktree is gone
# (so the move is allowed) and before the compare-and-delete. The new tip is
# merged too, so only the guard can keep the branch. A move that fails breaks
# the fixture's premise: say so and stop rather than let the run pass.
case "\$*" in *"refs/heads/review/racing"*)
  printf 'x' >> "$TMP/shim21/reads"
  if [[ "\$(cat "$TMP/shim21/reads")" == xxx ]]; then
    # The move's own chatter must not reach stdout: the caller is capturing it
    # as the branch tip.
    if ! "$(command -v git)" -C "$SHARED" branch -f review/racing refs/remotes/origin/main >&2; then
      echo "shim21: fixture could not move review/racing" >&2
      exit 1
    fi
  fi ;;
esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim21/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim21:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "21. a branch that moved after its ancestry check is kept, its removal still reported, exit 2"
  if (( RC == 2 )) && [[ "$(removed_paths)" == *"$ROOT/twentyone-racing"* ]] && [[ "$OUT" == *"moved after its ancestry check"* ]] && has_branch "$SHARED" review/racing; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 22. a worktree removal whose branch deletion fails still reports the removal.
  mk_repo twentytwo
  add_wt "$SHARED" review/halfway "$ROOT/twentytwo-halfway"
  mkdir -p "$TMP/shim22" || die "mkdir shim failed"
  cat > "$TMP/shim22/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in *"update-ref -d"*) echo "fatal: fixture refuses the deletion" >&2; exit 1 ;; esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim22/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim22:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "22. the JSON reports the removal that happened even when the branch deletion fails"
  if (( RC == 2 )) && [[ "$(removed_paths)" == *"$ROOT/twentytwo-halfway"* ]] && [[ ! -e "$ROOT/twentytwo-halfway" ]] && [[ "$OUT" == *'"failed": [{'*"deleting"* ]] && [[ "$OUT" == *"fixture refuses the deletion"* ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 23. a prunable branch is deferred when the metadata removal is skipped.
  if [[ "$(id -u)" != 0 ]]; then
    mk_repo twentythree
    add_wt "$SHARED" review/vanished "$ROOT/twentythree-vanished"
    rm -rf "$ROOT/twentythree-vanished" || die "rm failed"
    add_wt "$SHARED" review/sealed23 "$ROOT/twentythree-sealed"
    chmod 000 "$ROOT/twentythree-sealed" || die "chmod failed"
    run "$SHARED"
    chmod 755 "$ROOT/twentythree-sealed" || die "chmod restore failed"
    echo "23. a prunable branch is not deleted while its metadata survives a skipped metadata removal"
    if (( RC == 2 )) && [[ "$(kept_reason "$ROOT/twentythree-vanished")" == prunable ]] && [[ "$(branches_deleted)" != *review/vanished* ]] && has_branch "$SHARED" review/vanished; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 24. a worktree path holding a newline is one field, not two.
  mk_repo twentyfour
  newline_path="$ROOT/twentyfour-$(printf 'a\nb')"
  git -C "$SHARED" worktree add -q -b review/newline "$newline_path" origin/main \
    || die "fixture could not create a worktree at a newline-bearing path"
  run "$SHARED"
  # The process probe cannot report such a path faithfully, so it is kept;
  # the point here is that it is reported whole, as one record.
  echo "24. a newline in a worktree path does not split its record"
  if (( RC == 0 )) && [[ "$OUT" != *'"path": "'"$ROOT"'/twentyfour-a"'* ]] && [[ "$(kept_reason "$newline_path")" == idle-unknown ]] \
    && has_branch "$SHARED" review/newline; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 25. a tracked branch's config goes with it.
  mk_repo twentyfive
  quiet "fixture could not create a tracking worktree" \
    git -C "$SHARED" worktree add -q --track -b review/tracked "$ROOT/twentyfive-tracked" origin/main
  git -C "$SHARED" config --get-regexp '^branch\.review/tracked\.' >/dev/null || die "fixture branch has no tracking config"
  run "$SHARED"
  echo "25. a deleted branch leaves no stale branch.<name> config behind"
  cfg_rc=0
  git -C "$SHARED" config --get-regexp '^branch\.review/tracked\.' >/dev/null 2>"$TMP/cfg.err" || cfg_rc=$?
  (( cfg_rc == 0 || cfg_rc == 1 )) || die "git config failed (exit $cfg_rc): $(cat "$TMP/cfg.err")"
  if (( RC == 0 )) && [[ "$(removed_paths)" == *"$ROOT/twentyfive-tracked"* ]] && (( cfg_rc == 1 )); then pass; else fail "rc=$RC cfg_rc=$cfg_rc out=$OUT err=$ERRTEXT"; fi

  # --- 26. a locked entry whose directory is gone keeps its branch.
  mk_repo twentysix
  add_wt "$SHARED" review/lockedgone "$ROOT/twentysix-lockedgone"
  git -C "$SHARED" worktree lock "$ROOT/twentysix-lockedgone" || die "lock failed"
  rm -rf "$ROOT/twentysix-lockedgone" || die "rm failed"
  run "$SHARED"
  echo "26. a locked entry whose metadata stays does not release its branch"
  if (( RC == 0 )) && [[ "$(kept_reason "$ROOT/twentysix-lockedgone")" == locked ]] && [[ "$(branches_deleted)" != *review/lockedgone* ]] && has_branch "$SHARED" review/lockedgone; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 27. without -z there is no unambiguous inventory, so nothing is decided.
  # No newline path is needed: the line-oriented form cannot be trusted at all,
  # since a path whose tail reads as an attribute passes any scan (#410).
  mk_repo twentyseven
  add_wt "$SHARED" review/plain "$ROOT/twentyseven-plain"
  mkdir -p "$TMP/shim27" || die "mkdir shim failed"
  cat > "$TMP/shim27/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
# Stand in for a git older than 2.36, which has no -z on this subcommand.
case "\$*" in *"worktree list"*-z*) echo "error: unknown option z" >&2; exit 129 ;; esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim27/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim27:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "27. a git without -z refuses the inventory, deciding nothing"
  plain_dir=0; [[ -d "$ROOT/twentyseven-plain" ]] && plain_dir=1
  plain_branch=0; has_branch "$SHARED" review/plain && plain_branch=1
  if (( RC == 1 )) && [[ -z "$OUT" ]] && [[ "$ERRTEXT" == *"cannot be listed unambiguously"* ]] && (( plain_dir )) && (( plain_branch )); then pass; else fail "rc=$RC dir=$plain_dir branch=$plain_branch out=$OUT err=$ERRTEXT"; fi

  # --- 28. a dry run previews the deferral a live run would make.
  if [[ "$(id -u)" != 0 ]]; then
    mk_repo twentyeight
    add_wt "$SHARED" review/previewgone "$ROOT/twentyeight-gone"
    rm -rf "$ROOT/twentyeight-gone" || die "rm failed"
    add_wt "$SHARED" review/sealed28 "$ROOT/twentyeight-sealed"
    chmod 000 "$ROOT/twentyeight-sealed" || die "chmod failed"
    run "$SHARED" --dry-run
    chmod 755 "$ROOT/twentyeight-sealed" || die "chmod restore failed"
    echo "28. a dry run does not promise a deletion the live run would defer"
    if (( RC == 2 )) && [[ "$(branches_deleted)" != *review/previewgone* ]] && has_branch "$SHARED" review/previewgone; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 29. a longer branch's config is not this branch's config.
  mk_repo twentynine
  # --no-track: a tracking branch has its own branch.<name>.* section, and
  # removing that would succeed whether or not the probe matched the sibling.
  git -C "$SHARED" branch --no-track review/foo origin/main || die "branch failed"
  # Section `review/foo.bar`, key `remote` — `branch.review/foo.` prefixes it,
  # but it belongs to another branch entirely.
  git -C "$SHARED" config "branch.review/foo.bar.remote" origin || die "config failed"
  run "$SHARED"
  echo "29. a sibling branch's config section is not mistaken for this branch's"
  sibling_kept=0
  config_rc=0
  git -C "$SHARED" config --get "branch.review/foo.bar.remote" >/dev/null || config_rc=$?
  case "$config_rc" in 0) sibling_kept=1 ;; 1) ;; *) die "git config --get failed (exit $config_rc)" ;; esac
  if (( RC == 0 )) && [[ "$(branches_deleted)" == *review/foo* ]] && ! has_branch "$SHARED" review/foo && (( sibling_kept )); then pass; else fail "rc=$RC sibling=$sibling_kept out=$OUT err=$ERRTEXT"; fi

  # --- 30. a branch a worktree holds is kept even when the inventory missed it.
  mk_repo thirty
  add_wt "$SHARED" review/claimed "$ROOT/thirty-claimed"
  mkdir -p "$TMP/shim30" || die "mkdir shim failed"
  # The run's own inventory read comes back empty, so the branch reaches the
  # branch pass as if no worktree held it; every other read is the real thing.
  # A live run reads the registry once before the inventory, to release the
  # locks of a killed run, so the inventory is the second `-z` read.
  cat > "$TMP/shim30/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in
  *"worktree list"*-z*)
    if [[ ! -e "$TMP/shim30/first" ]]; then
      : > "$TMP/shim30/first"
    elif [[ ! -e "$TMP/shim30/seen" ]]; then
      : > "$TMP/shim30/seen"; exit 0
    fi ;;
esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim30/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim30:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "30. a branch checked out in a worktree the inventory missed is kept"
  if (( RC == 0 )) && [[ "$(branch_kept_reason review/claimed)" == checked-out ]] && has_branch "$SHARED" review/claimed && [[ -d "$ROOT/thirty-claimed" ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 31. a worktree claiming the branch inside the deletion window.
  mk_repo thirtyone
  git -C "$SHARED" branch review/raced origin/main || die "branch failed"
  mkdir -p "$TMP/shim31" || die "mkdir shim failed"
  # `update-ref -d` has no checked-out guard: the shim claims the branch just
  # before the deletion lands, exactly the race the inventory cannot see.
  cat > "$TMP/shim31/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in
  *"update-ref -d refs/heads/review/raced"*)
    if [[ ! -e "$TMP/shim31/seen" ]]; then
      : > "$TMP/shim31/seen"
      if ! "$(command -v git)" -C "$SHARED" worktree add -q "$ROOT/thirtyone-raced" review/raced >/dev/null; then
        echo "shim31: fixture could not claim review/raced" >&2
      fi
    fi ;;
esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim31/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim31:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "31. a branch claimed while it was being deleted is put back"
  if (( RC == 2 )) && has_branch "$SHARED" review/raced && [[ "$OUT" == *"was restored at"* ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 33. a post-deletion occupancy read that fails is not "nothing holds it".
  mk_repo thirtythree
  git -C "$SHARED" branch --no-track review/unreadable origin/main || die "branch failed"
  mkdir -p "$TMP/shim33" || die "mkdir shim failed"
  # The reads before the deletion answer; the one after it fails, so the run
  # must say the safety check did not run rather than report a clean deletion.
  cat > "$TMP/shim33/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in
  *"worktree list"*-z*)
    if [[ -e "$TMP/shim33/deleted" ]]; then echo "fatal: fixture inventory failure" >&2; exit 128; fi ;;
  *"update-ref -d refs/heads/review/unreadable"*) : > "$TMP/shim33/deleted" ;;
esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim33/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim33:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "33. a failed post-deletion occupancy read is reported, not read as unoccupied"
  if (( RC == 2 )) && [[ "$OUT" == *"could not be read"* ]] && [[ "$OUT" == *"fixture inventory failure"* ]] && [[ "$(branches_deleted)" != *review/unreadable* ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 32. a parent whose own name ends in a newline still confirms absence.
  mk_repo thirtytwo
  nl_parent="$ROOT/thirtytwo-p"$'\n'
  mkdir -p "$nl_parent" || die "mkdir newline parent failed"
  quiet "fixture could not create a worktree under a newline-bearing parent" \
    git -C "$SHARED" worktree add -q -b review/nlparent "$nl_parent/wt" origin/main
  rm -rf "$nl_parent/wt" || die "rm failed"
  run "$SHARED"
  echo "32. absence is confirmed through a parent whose name ends in a newline"
  if (( RC == 0 )) && [[ "$ERRTEXT" != *"cannot confirm the worktree is gone"* ]] && ! has_branch "$SHARED" review/nlparent; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 34. the config cleanup will not delete a recreated branch's section.
  # The window is narrow: after the post-deletion occupancy re-check says the
  # branch is free, and before `--remove-section` runs. The shim recreates the
  # branch during the config READ, which sits exactly in it.
  mk_repo thirtyfour
  git -C "$SHARED" branch --no-track review/recreated origin/main || die "branch failed"
  git -C "$SHARED" config "branch.review/recreated.description" "original" || die "config failed"
  mkdir -p "$TMP/shim34" || die "mkdir shim failed"
  cat > "$TMP/shim34/git" <<SHIM || die "shim write failed"
#!/usr/bin/env bash
set -euo pipefail
case "\$*" in
  *"config --get-regexp"*)
    if [[ ! -e "$TMP/shim34/seen" ]]; then
      : > "$TMP/shim34/seen"
      if ! "$(command -v git)" -C "$SHARED" worktree add -q --track -b review/recreated "$ROOT/thirtyfour-live" origin/main >/dev/null 2>"$TMP/shim34/add.err"; then
        echo "shim34: fixture could not recreate review/recreated: \$(cat "$TMP/shim34/add.err")" >&2
      fi
    fi ;;
esac
exec "$(command -v git)" "\$@"
SHIM
  chmod +x "$TMP/shim34/git" || die "chmod shim failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim34:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?; ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "34. a branch.<name> section recreated after the deletion is left untouched"
  kept_config=0
  config_rc=0
  git -C "$SHARED" config --get "branch.review/recreated.remote" >/dev/null || config_rc=$?
  case "$config_rc" in 0) kept_config=1 ;; 1) ;; *) die "git config --get failed (exit $config_rc)" ;; esac
  if (( kept_config )) && [[ "$OUT" == *"remove nothing by hand"* ]] && [[ "$OUT" == *'"branches_deleted": ['*'review/recreated'* ]]; then
    pass; else fail "the recreated branch's config must survive and be reported: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 35-38: one live run over idle worktrees of every kind.
  mk_repo idle
  local det="$ROOT/idle-detached" pushed="$ROOT/idle-pushed" busy="$ROOT/idle-busy" stale="$ROOT/idle-stale" held="$ROOT/idle-held"
  quiet "detached worktree add failed" git -C "$SHARED" worktree add -q --detach "$det" origin/main
  add_wt "$SHARED" review/pushed "$pushed"; commit_in "$pushed" p.txt
  quiet "push review/pushed failed" git -C "$pushed" push -q origin review/pushed
  git -C "$SHARED" fetch -q origin || die "fetch after push failed"
  quiet "busy worktree add failed" git -C "$SHARED" worktree add -q --detach "$busy" origin/main
  add_wt "$SHARED" feat/stale "$stale"; commit_in "$stale" s.txt
  printf 'untracked work\n' > "$stale/notes.txt" || die "untracked write failed"
  quiet "held worktree add failed" git -C "$SHARED" worktree add -q --detach "$held" origin/main
  git -C "$SHARED" worktree lock --reason "Active Herdr reviewer" "$held" || die "worktree lock failed"
  local stale_tip
  stale_tip="$(git -C "$stale" rev-parse HEAD)" || die "rev-parse stale HEAD failed"
  start_sleeper "$busy"
  local wt; for wt in "$det" "$pushed" "$busy" "$stale" "$held"; do age_wt "$wt"; done
  idle_run
  stop_sleeper
  echo "35. an idle clean worktree on a pushed commit is removed, detached or on a pushed branch"
  if (( RC == 0 )) && ! listed "$SHARED" "$det" && ! listed "$SHARED" "$pushed" \
    && [[ -n "$(removed_head "$det")" ]] && ! has_branch "$SHARED" review/pushed; then
    pass; else fail "reachable removal: rc=$RC out=$OUT err=$ERRTEXT"; fi
  echo "36. a process with its cwd inside keeps an idle worktree"
  if [[ "$(kept_reason "$busy")" == in-use ]] && listed "$SHARED" "$busy"; then
    pass; else fail "in-use: out=$OUT"; fi
  echo "37. an idle worktree with unpushed commits and untracked work is kept and reported, never touched"
  if [[ "$(kept_reason "$stale")" == dirty ]] && listed "$SHARED" "$stale" && [[ -e "$stale/notes.txt" ]] \
    && [[ "$(kept_field "$stale" dirty_files)" == 1 ]] && (( $(kept_field "$stale" age_hours) >= 24 )) && [[ "$(kept_field "$stale" command)" == "git -C $stale status" ]] \
    && has_branch "$SHARED" feat/stale && [[ "$(git -C "$SHARED" rev-parse feat/stale)" == "$stale_tip" ]]; then
    pass; else fail "dirty kept: out=$OUT err=$ERRTEXT"; fi
  echo "38. a locked idle worktree is kept with its lock reason"
  if [[ "$(kept_reason "$held")" == locked && "$(lock_reason_of "$held")" == "Active Herdr reviewer" ]] && listed "$SHARED" "$held"; then
    pass; else fail "locked: out=$OUT"; fi
  git -C "$SHARED" worktree unlock "$held" || die "worktree unlock failed"

  # --- 39-40: fresh activity keeps a worktree; an idle clean unpushed one is reported.
  mk_repo fresh
  local fresh_det="$ROOT/fresh-detached" mid="$ROOT/fresh-mid"
  quiet "fresh worktree add failed" git -C "$SHARED" worktree add -q --detach "$fresh_det" origin/main
  add_wt "$SHARED" feat/mid "$mid"; commit_in "$mid" m.txt
  age_wt "$mid"
  idle_run
  echo "39. a reachable worktree with fresh activity is kept"
  if [[ "$(kept_reason "$fresh_det")" == not-idle ]] && listed "$SHARED" "$fresh_det"; then
    pass; else fail "not idle: out=$OUT"; fi
  echo "40. an idle clean worktree with unpushed commits is kept with its count and push command"
  if [[ "$(kept_reason "$mid")" == unpushed ]] && listed "$SHARED" "$mid" \
    && [[ "$(kept_field "$mid" unpushed_commits)" == 1 ]] && (( $(kept_field "$mid" age_hours) >= 24 )) && [[ "$(kept_field "$mid" command)" == "git -C $mid push -u origin HEAD" ]]; then
    pass; else fail "unpushed kept: out=$OUT"; fi

  # --- 41. no process probe: nothing is judged idle.
  mk_repo noprobe
  local np="$ROOT/noprobe-detached"
  quiet "noprobe worktree add failed" git -C "$SHARED" worktree add -q --detach "$np" origin/main
  age_wt "$np"
  idle_run PRUNE_LSOF="$TMP/no-such-lsof"
  echo "41. a missing process probe keeps an idle worktree as idle-unknown"
  if (( RC == 0 )) && [[ "$(kept_reason "$np")" == idle-unknown ]] && listed "$SHARED" "$np" && [[ "$ERRTEXT" == *"install lsof"* ]]; then
    pass; else fail "no probe: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 43. a dry run previews the removal and changes nothing.
  mk_repo dryidle
  local dd="$ROOT/dryidle-detached" ds="$ROOT/dryidle-stale"
  quiet "dryidle worktree add failed" git -C "$SHARED" worktree add -q --detach "$dd" origin/main
  add_wt "$SHARED" feat/drystale "$ds"; commit_in "$ds" d.txt
  age_wt "$dd"; age_wt "$ds"
  IDLE_ARGS=(--dry-run)
  idle_run
  IDLE_ARGS=()
  echo "43. a dry run previews the removal and changes nothing"
  if (( RC == 0 )) && [[ -n "$(removed_head "$dd")" && "$(kept_reason "$ds")" == unpushed ]] \
    && listed "$SHARED" "$dd" && listed "$SHARED" "$ds" && has_branch "$SHARED" feat/drystale; then
    pass; else fail "dry run: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 44-45: the merged path waits for idleness and an empty worktree too.
  mk_repo mergedidle
  local mfresh="$ROOT/mergedidle-fresh" mbusy="$ROOT/mergedidle-busy"
  add_wt "$SHARED" review/mfresh "$mfresh"
  add_wt "$SHARED" review/mbusy "$mbusy"
  age_wt "$mbusy"
  start_sleeper "$mbusy"
  idle_run
  stop_sleeper
  echo "44. a clean merged worktree with fresh activity is kept"
  if [[ "$(kept_reason "$mfresh")" == not-idle ]] && listed "$SHARED" "$mfresh" && has_branch "$SHARED" review/mfresh; then
    pass; else fail "merged not idle: out=$OUT"; fi
  echo "45. a process inside keeps a clean merged worktree"
  if [[ "$(kept_reason "$mbusy")" == in-use ]] && listed "$SHARED" "$mbusy"; then
    pass; else fail "merged in use: out=$OUT"; fi

  # --- 46. a tracked file edited now keeps an otherwise old worktree.
  mk_repo freshedit
  local fe="$ROOT/freshedit-wt"
  add_wt "$SHARED" feat/freshedit "$fe"; commit_in "$fe" e.txt
  age_wt "$fe"
  printf 'edited now\n' >> "$fe/e.txt" || die "edit failed"
  touch -t 202001091200 "$fe/e.txt" || die "touch edit failed"
  idle_run
  echo "46. a fresh edit to a tracked file keeps an otherwise old worktree as not yet idle"
  if [[ "$(kept_reason "$fe")" == not-idle ]] && listed "$SHARED" "$fe"; then
    pass; else fail "fresh edit: out=$OUT err=$ERRTEXT"; fi

  # --- 47. a process arriving between the judgment and the removal keeps it.
  mk_repo race
  local rw="$ROOT/race-detached"
  quiet "race worktree add failed" git -C "$SHARED" worktree add -q --detach "$rw" origin/main
  age_wt "$rw"
  lsof_turns_busy "$TMP/lsof47" 2 "$rw"
  idle_run PRUNE_LSOF="$TMP/lsof47/lsof"
  echo "47. a worktree that turns busy before its removal is kept"
  if (( RC == 0 )) && [[ "$(kept_reason "$rw")" == changed ]] && listed "$SHARED" "$rw" && [[ "$ERRTEXT" == *"process is now working inside"* ]]; then
    pass; else fail "changed at removal: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 47b. the dry run takes the same recheck before previewing a removal.
  mk_repo racedry
  local rdw="$ROOT/racedry-detached"
  quiet "racedry worktree add failed" git -C "$SHARED" worktree add -q --detach "$rdw" origin/main
  age_wt "$rdw"
  lsof_turns_busy "$TMP/lsof47b" 2 "$rdw"
  IDLE_ARGS=(--dry-run)
  idle_run PRUNE_LSOF="$TMP/lsof47b/lsof"
  IDLE_ARGS=()
  echo "47b. a dry run keeps a worktree that turns busy before the preview, as the live run would"
  if (( RC == 0 )) && [[ "$(kept_reason "$rdw")" == changed ]] && [[ -z "$(removed_head "$rdw")" ]] && listed "$SHARED" "$rdw"; then
    pass; else fail "dry-run recheck: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 59. a path lsof cannot report faithfully is never judged idle.
  mk_repo newline
  local nlwt="$ROOT/nl"$'\n'"wt" nlbusy="$ROOT/nlb"$'\n'"busy"
  quiet "newline worktree add failed" git -C "$SHARED" worktree add -q --detach "$nlwt" origin/main
  quiet "newline busy worktree add failed" git -C "$SHARED" worktree add -q --detach "$nlbusy" origin/main
  age_wt "$nlwt"; age_wt "$nlbusy"
  start_sleeper "$nlbusy"
  idle_run
  stop_sleeper
  echo "59. worktrees whose path holds a newline are kept as idle-unknown, a process inside or not"
  if (( RC == 0 )) && [[ "$(kept_reason "$nlwt")" == idle-unknown && "$(kept_reason "$nlbusy")" == idle-unknown ]] \
    && listed "$SHARED" "$nlwt" && listed "$SHARED" "$nlbusy"; then
    pass; else fail "newline: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 51. a dirty submodule keeps an idle worktree.
  mk_repo submod
  local sub_origin="$TMP/sublib.git" sw="$ROOT/submod-wt"
  git init -q --bare -b main "$sub_origin" || die "sub origin init failed"
  quiet "sub seed clone failed" git clone -q "$sub_origin" "$TMP/sublib-seed"
  printf 's\n' > "$TMP/sublib-seed/s" || die "sub seed write failed"
  git -C "$TMP/sublib-seed" -c user.name=t -c user.email=t@t add s || die "sub add failed"
  git -C "$TMP/sublib-seed" -c user.name=t -c user.email=t@t commit -q -m s1 || die "sub commit failed"
  quiet "sub push failed" git -C "$TMP/sublib-seed" push -q origin main
  add_wt "$SHARED" feat/submod "$sw"
  quiet "submodule add failed" git -C "$sw" -c protocol.file.allow=always submodule --quiet add "$sub_origin" lib
  git -C "$sw" -c user.name=t -c user.email=t@t commit -q -m "add lib" || die "submodule commit failed"
  printf 'nested edit\n' >> "$sw/lib/s" || die "nested edit failed"
  age_wt "$sw"
  idle_run
  echo "51. a worktree whose submodule holds changes is kept"
  if [[ "$(kept_reason "$sw")" == submodule-dirty ]] && listed "$SHARED" "$sw"; then
    pass; else fail "submodule: out=$OUT err=$ERRTEXT"; fi

  # --- 60. only origin's refs prove reachability.
  mk_repo otherremote
  local orw="$ROOT/otherremote-wt"
  git init -q --bare -b main "$TMP/upstream.git" || die "upstream init failed"
  git -C "$SHARED" remote add upstream "$TMP/upstream.git" || die "remote add failed"
  quiet "otherremote worktree add failed" git -C "$SHARED" worktree add -q --detach "$orw" origin/main
  commit_in "$orw" u.txt
  quiet "push upstream failed" git -C "$orw" push -q upstream HEAD:refs/heads/side
  git -C "$SHARED" fetch -q upstream || die "fetch upstream failed"
  age_wt "$orw"
  idle_run
  echo "60. a HEAD held only by another remote's ref is not reachable"
  if [[ "$(kept_reason "$orw")" == unpushed ]] && listed "$SHARED" "$orw"; then
    pass; else fail "other remote: out=$OUT err=$ERRTEXT"; fi

  # --- 61. the reachability proof is re-derived just before the removal.
  mk_repo proofgone
  local pg="$ROOT/proofgone-wt"
  quiet "proofgone worktree add failed" git -C "$SHARED" worktree add -q --detach "$pg" origin/main
  age_wt "$pg"
  mkdir -p "$TMP/shim61" || die "mkdir shim61 failed"
  # The second read of origin's branch tips (`ls-remote --heads`, the one just
  # before the removal) answers that origin holds no branch at all.
  # shellcheck disable=SC2016  # The shim's "$@" and $a must expand in the shim, not here.
  printf '#!/usr/bin/env bash\nset -euo pipefail\nfor a in "$@"; do if [[ "$a" == --heads ]]; then printf x >> %q; if [[ "$(cat %q)" == xx ]]; then exit 0; fi; fi; done\nexec %q "$@"\n' \
    "$TMP/shim61/n" "$TMP/shim61/n" "$real_git" > "$TMP/shim61/git" || die "shim61 write failed"
  chmod +x "$TMP/shim61/git" || die "chmod shim61 failed"
  idle_run PATH="$TMP/shim61:$PATH"
  echo "61. a worktree whose origin ref vanished before its removal is kept"
  if [[ "$(kept_reason "$pg")" == changed ]] && listed "$SHARED" "$pg" && [[ "$ERRTEXT" == *"origin no longer holds"* ]]; then
    pass; else fail "proof gone: out=$OUT err=$ERRTEXT"; fi

  # --- 62. a dirty gitlink is found without .gitmodules; an embedded repository keeps a worktree.
  mk_repo gitlink
  local gl="$ROOT/gitlink-wt" nr="$ROOT/gitlink-nested" sub62="$TMP/sublib62.git"
  git init -q --bare -b main "$sub62" || die "sub62 origin init failed"
  quiet "sub62 seed clone failed" git clone -q "$sub62" "$TMP/sublib62-seed"
  printf 's\n' > "$TMP/sublib62-seed/s" || die "sub62 seed write failed"
  git -C "$TMP/sublib62-seed" -c user.name=t -c user.email=t@t add s || die "sub62 add failed"
  git -C "$TMP/sublib62-seed" -c user.name=t -c user.email=t@t commit -q -m s1 || die "sub62 commit failed"
  quiet "sub62 push failed" git -C "$TMP/sublib62-seed" push -q origin main
  add_wt "$SHARED" feat/gitlink "$gl"
  quiet "submodule add failed" git -C "$gl" -c protocol.file.allow=always submodule --quiet add "$sub62" lib
  git -C "$gl" -c user.name=t -c user.email=t@t commit -q -m "add lib" || die "submodule commit failed"
  rm "$gl/.gitmodules" || die "rm .gitmodules failed"
  printf 'nested edit\n' >> "$gl/lib/s" || die "nested edit failed"
  add_wt "$SHARED" feat/nested "$nr"; commit_in "$nr" base.txt
  git init -q "$nr/embedded" || die "embedded init failed"
  printf 'inner\n' > "$nr/embedded/inner.txt" || die "inner write failed"
  # An embedded repository inside an ignored directory, and one nested below an
  # untracked directory: git's own listing shows neither.
  local ig="$ROOT/gitlink-ignored" deep="$ROOT/gitlink-deep"
  add_wt "$SHARED" feat/ignored "$ig"
  printf 'vendor/\n' > "$ig/.gitignore" || die "gitignore write failed"
  git -C "$ig" -c user.name=t -c user.email=t@t add .gitignore || die "gitignore add failed"
  git -C "$ig" -c user.name=t -c user.email=t@t commit -q -m ignore || die "gitignore commit failed"
  mkdir -p "$ig/vendor" || die "mkdir vendor failed"
  git init -q "$ig/vendor/lib" || die "ignored embedded init failed"
  add_wt "$SHARED" feat/deep "$deep"; commit_in "$deep" d.txt
  mkdir -p "$deep/outer" || die "mkdir outer failed"
  printf 'o\n' > "$deep/outer/plain.txt" || die "outer write failed"
  git init -q "$deep/outer/inner" || die "deep embedded init failed"
  age_wt "$gl"; age_wt "$nr"; age_wt "$ig"; age_wt "$deep"
  idle_run
  echo "62a. a dirty submodule is kept even with .gitmodules gone"
  if [[ "$(kept_reason "$gl")" == submodule-dirty ]] && listed "$SHARED" "$gl"; then pass; else fail "gitlink: out=$OUT err=$ERRTEXT"; fi
  echo "62b. an untracked embedded repository keeps its worktree"
  if [[ "$(kept_reason "$nr")" == nested-repo ]] && listed "$SHARED" "$nr"; then
    pass; else fail "nested repo: out=$OUT err=$ERRTEXT"; fi
  echo "62c. an embedded repository in an ignored directory, or below an untracked one, keeps its worktree"
  if [[ "$(kept_reason "$ig")" == nested-repo && "$(kept_reason "$deep")" == nested-repo ]] && listed "$SHARED" "$ig" && listed "$SHARED" "$deep"; then
    pass; else fail "hidden nested repos: out=$OUT err=$ERRTEXT"; fi

  # --- 69. dry run and live run agree after origin deletes a branch.
  mk_repo agree
  local ag="$ROOT/agree-wt"
  quiet "agree worktree add failed" git -C "$SHARED" worktree add -q --detach "$ag" origin/main
  commit_in "$ag" gone.txt
  quiet "push side failed" git -C "$ag" push -q origin HEAD:refs/heads/side
  git -C "$SHARED" fetch -q origin || die "fetch side failed"
  quiet "delete side on origin failed" git -C "$SEED" push -q origin --delete side
  age_wt "$ag"
  IDLE_ARGS=(--dry-run)
  idle_run
  IDLE_ARGS=()
  local dry_reason; dry_reason="$(kept_reason "$ag")"
  idle_run
  echo "69. a HEAD held only by an origin branch deleted since the last fetch is kept by both dry and live runs"
  if [[ "$dry_reason" == unpushed && "$(kept_reason "$ag")" == unpushed ]] && listed "$SHARED" "$ag"; then
    pass; else fail "dry/live agreement: dry=$dry_reason out=$OUT err=$ERRTEXT"; fi

  # --- 71. a force-push that drops the merge between judgment and removal keeps it.
  mk_repo forcepush
  local fp="$ROOT/forcepush-wt" fp_base
  fp_base="$(git -C "$SHARED" rev-parse origin/main)" || die "rev-parse base failed"
  add_wt "$SHARED" review/fp "$fp"; commit_in "$fp" fp.txt
  quiet "push to main failed" git -C "$fp" push -q origin HEAD:main
  git -C "$SHARED" fetch -q origin || die "fetch after merge failed"
  age_wt "$fp"
  mkdir -p "$TMP/shim71" || die "mkdir shim71 failed"
  # The second read of origin's main (just before the removal) answers with the
  # pre-merge commit, as after a force-push that dropped the merge.
  # shellcheck disable=SC2016  # The shim's "$@" and $a must expand in the shim, not here.
  printf '#!/usr/bin/env bash\nset -euo pipefail\nif [[ "$*" == *ls-remote*refs/heads/main* ]]; then printf x >> %q; if [[ "$(cat %q)" == xx ]]; then printf "%%s\\trefs/heads/main\\n" %q; exit 0; fi; fi\nexec %q "$@"\n' \
    "$TMP/shim71/n" "$TMP/shim71/n" "$fp_base" "$real_git" > "$TMP/shim71/git" || die "shim71 write failed"
  chmod +x "$TMP/shim71/git" || die "chmod shim71 failed"
  idle_run PATH="$TMP/shim71:$PATH"
  echo "71. a merge dropped by a force-push before the removal keeps the worktree and its branch"
  if [[ "$(kept_reason "$fp")" == changed ]] && listed "$SHARED" "$fp" && has_branch "$SHARED" review/fp \
    && [[ "$ERRTEXT" == *"origin no longer holds"* ]]; then
    pass; else fail "force-push: out=$OUT err=$ERRTEXT"; fi

  # --- 72. a failing remote command never relays the remote URL.
  mk_repo secretremote
  # git strips user:password@ from its own errors but prints the rest of the
  # URL, so the token sits in the path, where it survives into stderr.
  git -C "$SHARED" remote set-url origin "http://127.0.0.1:9/s3cr3t-token/repo.git" || die "set-url failed"
  run "$SHARED"
  echo "72. a failed fetch reports its exit code and repair, never the credential-bearing URL"
  if (( RC == 1 )) && [[ "$ERRTEXT" == *"exited"* && "$ERRTEXT" == *"to see why"* ]] && [[ "$ERRTEXT" != *s3cr3t-token* ]]; then
    pass; else fail "secret redaction: rc=$RC err=$ERRTEXT"; fi

  # --- 80. a branch with no worktree whose tip an origin branch holds is deleted.
  mk_repo pushedbranch
  local pb="$ROOT/pushedbranch-wt"
  add_wt "$SHARED" feat/pushed "$pb"; commit_in "$pb" p.txt
  quiet "push feat/pushed failed" git -C "$pb" push -q origin feat/pushed
  quiet "remove the worktree by hand failed" git -C "$SHARED" worktree remove "$pb"
  run "$SHARED"
  echo "80. a branch with no worktree whose tip origin holds is deleted"
  if (( RC == 0 )) && [[ "$(branches_deleted)" == *feat/pushed* ]] && ! has_branch "$SHARED" feat/pushed; then
    pass; else fail "origin-held branch: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 81. an idle unpushed branch is reported; a fresh one is not-idle.
  #         Every commit and reflog entry carries a fixed date (git stamps
  #         reflog entries with GIT_COMMITTER_DATE), judged at IDLE_NOW.
  mk_repo localonly
  local old_at="2020-01-01T00:00:00Z" new_at="2020-01-09T20:00:00Z"
  GIT_COMMITTER_DATE="$old_at" quiet "old branch failed" git -C "$SHARED" branch --no-track feat/old origin/main
  GIT_COMMITTER_DATE="$new_at" quiet "new branch failed" git -C "$SHARED" branch --no-track feat/new origin/main
  local c_old c_new
  c_old="$(GIT_AUTHOR_DATE="$old_at" GIT_COMMITTER_DATE="$old_at" git -C "$SHARED" -c user.name=t -c user.email=t@t commit-tree "origin/main^{tree}" -p origin/main -m old)" || die "old commit failed"
  c_new="$(GIT_AUTHOR_DATE="$new_at" GIT_COMMITTER_DATE="$new_at" git -C "$SHARED" -c user.name=t -c user.email=t@t commit-tree "origin/main^{tree}" -p origin/main -m new)" || die "new commit failed"
  GIT_COMMITTER_DATE="$old_at" quiet "move feat/old failed" git -C "$SHARED" update-ref -m old refs/heads/feat/old "$c_old"
  GIT_COMMITTER_DATE="$new_at" quiet "move feat/new failed" git -C "$SHARED" update-ref -m new refs/heads/feat/new "$c_new"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_NOW="$IDLE_NOW" PRUNE_IDLE_HOURS=24 bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  local kept_old; kept_old="$(python3 -c 'import json,sys; d=json.load(sys.stdin); print(next((json.dumps(b, sort_keys=True) for b in d["branches_kept"] if b["branch"]=="feat/old"), ""))' <<<"$OUT")"
  echo "81. an idle unpushed branch is reported with its count, age and push command, and left in place"
  if (( RC == 0 )) && [[ "$kept_old" == *'"reason": "unpushed"'* && "$kept_old" == *'"unpushed_commits": 1'* && "$kept_old" == *'"age_hours": 216'* && "$kept_old" == *'push -u origin feat/old'* ]] \
    && has_branch "$SHARED" feat/old; then
    pass; else fail "unpushed branch: rc=$RC kept=$kept_old out=$OUT err=$ERRTEXT"; fi
  echo "81b. a branch with activity inside the window is not-idle, and left in place"
  if [[ "$(branch_kept_reason feat/new)" == not-idle ]] && has_branch "$SHARED" feat/new; then
    pass; else fail "fresh branch: out=$OUT"; fi

  # --- 82. a merge dropped from origin before a branch-pass deletion keeps the branch.
  mk_repo branchproof
  local bp="$ROOT/branchproof-wt" bp_base
  bp_base="$(git -C "$SHARED" rev-parse origin/main)" || die "rev-parse base failed"
  add_wt "$SHARED" review/bp "$bp"; commit_in "$bp" bp.txt
  quiet "push to main failed" git -C "$bp" push -q origin HEAD:main
  quiet "fetch after merge failed" git -C "$SHARED" fetch -q origin
  quiet "remove bp worktree failed" git -C "$SHARED" worktree remove "$bp"
  mkdir -p "$TMP/shim82" || die "mkdir shim82 failed"
  # shellcheck disable=SC2016  # The shim's "$@" and $(...) must expand in the shim, not here.
  printf '#!/usr/bin/env bash\nset -euo pipefail\nif [[ "$*" == *ls-remote*refs/heads/main* ]]; then printf x >> %q; if [[ "$(cat %q)" == xx ]]; then printf "%%s\\trefs/heads/main\\n" %q; exit 0; fi; fi\nexec %q "$@"\n' \
    "$TMP/shim82/n" "$TMP/shim82/n" "$bp_base" "$real_git" > "$TMP/shim82/git" || die "shim82 write failed"
  chmod +x "$TMP/shim82/git" || die "chmod shim82 failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim82:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "82. a merge dropped from origin just before the branch deletion keeps the branch"
  if (( RC == 0 )) && [[ "$(branch_kept_reason review/bp)" == changed ]] && has_branch "$SHARED" review/bp; then
    pass; else fail "branch proof: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 86. origin dropping the commit while the worktree is removed keeps the branch.
  mk_repo wtproof
  local wp="$ROOT/wtproof-wt"
  add_wt "$SHARED" review/wp "$wp"; commit_in "$wp" wp.txt
  quiet "push review/wp failed" git -C "$wp" push -q origin HEAD:review/wp
  quiet "fetch after push failed" git -C "$SHARED" fetch -q origin
  mkdir -p "$TMP/shim86" || die "mkdir shim86 failed"
  # The real removal runs, then origin loses the branch: the window between
  # the first proof and the branch deletion. A failed drop breaks the premise.
  # shellcheck disable=SC2016  # The shim's "$@" and $? must expand in the shim, not here.
  printf '#!/usr/bin/env bash\nset -euo pipefail\nif [[ "$*" == *"worktree remove"* ]]; then rc=0; %q "$@" || rc=$?; %q -C %q update-ref -d refs/heads/review/wp || { echo "shim86: could not drop review/wp" >&2; exit 1; }; exit "$rc"; fi\nexec %q "$@"\n' \
    "$real_git" "$real_git" "$BARE" "$real_git" > "$TMP/shim86/git" || die "shim86 write failed"
  chmod +x "$TMP/shim86/git" || die "chmod shim86 failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$TMP/shim86:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "86. origin dropping the commit while its worktree is removed keeps the branch, exit 2"
  if (( RC == 2 )) && [[ "$(removed_paths)" == *"$wp"* ]] && [[ "$OUT" == *"origin stopped holding"* ]] && has_branch "$SHARED" review/wp; then
    pass; else fail "worktree proof: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 83. a partial lsof listing (exit 0, an unreadable cwd) is not an answer.
  mk_repo lsofpartial
  local lp="$ROOT/lsofpartial-detached"
  quiet "lsofpartial worktree add failed" git -C "$SHARED" worktree add -q --detach "$lp" origin/main
  age_wt "$lp"
  mkdir -p "$TMP/lsof83" || die "mkdir lsof83 failed"
  printf '#!/usr/bin/env bash\nset -euo pipefail\nprintf "p1\\0\\nfcwd\\0n/ (readlink: Permission denied)\\0\\n"\n' > "$TMP/lsof83/lsof" || die "write lsof83 failed"
  chmod +x "$TMP/lsof83/lsof" || die "chmod lsof83 failed"
  idle_run PRUNE_LSOF="$TMP/lsof83/lsof"
  echo "83. an lsof listing with an unreadable cwd keeps the worktree as idle-unknown"
  if (( RC == 0 )) && [[ "$(kept_reason "$lp")" == idle-unknown ]] && listed "$SHARED" "$lp" && [[ "$ERRTEXT" == *"incomplete listing"* ]]; then
    pass; else fail "partial lsof: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 83b. a mount lsof could not stat is no gap in the cwd records.
  mk_repo lsofmount
  local lm="$ROOT/lsofmount-detached"
  quiet "lsofmount worktree add failed" git -C "$SHARED" worktree add -q --detach "$lm" origin/main
  age_wt "$lm"
  mkdir -p "$TMP/lsof83b" || die "mkdir lsof83b failed"
  cat > "$TMP/lsof83b/lsof" <<'SH' || die "write lsof83b failed"
#!/usr/bin/env bash
set -euo pipefail
printf 'p1\0\nfcwd\0n/\0\n'
printf '%s\n' "lsof: WARNING: can't stat() smbfs file system /Volumes/backup" \
  "      Output information may be incomplete." \
  '      assuming "dev=36000040" from mount table' >&2
SH
  chmod +x "$TMP/lsof83b/lsof" || die "chmod lsof83b failed"
  idle_run PRUNE_LSOF="$TMP/lsof83b/lsof"
  echo "83b. an lsof warning about an unstattable mount still judges the worktree idle"
  if (( RC == 0 )) && ! listed "$SHARED" "$lm" && [[ -n "$(removed_head "$lm")" ]] && [[ "$ERRTEXT" == *"could not stat"* ]]; then
    pass; else fail "mount warning: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 83c. an unreadable cwd of a process that has since exited is no gap.
  mk_repo lsofgone
  local lg="$ROOT/lsofgone-detached" gone
  quiet "lsofgone worktree add failed" git -C "$SHARED" worktree add -q --detach "$lg" origin/main
  age_wt "$lg"
  bash -c 'exit 0' &
  gone=$!
  wait "$gone" || die "the short-lived process failed"
  mkdir -p "$TMP/lsof83c" || die "mkdir lsof83c failed"
  printf '#!/usr/bin/env bash\nset -euo pipefail\nprintf "p%s\\0\\nfcwd\\0n/ (readlink: No such process)\\0\\n"\n' "$gone" > "$TMP/lsof83c/lsof" || die "write lsof83c failed"
  chmod +x "$TMP/lsof83c/lsof" || die "chmod lsof83c failed"
  idle_run PRUNE_LSOF="$TMP/lsof83c/lsof"
  echo "83c. an unreadable cwd of an exited process still judges the worktree idle"
  if (( RC == 0 )) && ! listed "$SHARED" "$lg" && [[ -n "$(removed_head "$lg")" ]]; then
    pass; else fail "exited process: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 85. origin's default branch changing mid-run voids a merged proof.
  mk_repo newdefault
  local nd="$ROOT/newdefault-wt"
  add_wt "$SHARED" review/nd "$nd"
  age_wt "$nd"
  quiet "branch without a worktree failed" git -C "$SHARED" branch --no-track review/nd-nowt origin/main
  quiet "push other failed" git -C "$SHARED" push -q origin origin/main:refs/heads/other
  mkdir -p "$TMP/lsof85" || die "mkdir lsof85 failed"
  printf '#!/usr/bin/env bash\nset -euo pipefail\ngit -C %q symbolic-ref HEAD refs/heads/other\n' "$BARE" > "$TMP/lsof85/lsof" || die "write lsof85 failed"
  chmod +x "$TMP/lsof85/lsof" || die "chmod lsof85 failed"
  idle_run PRUNE_LSOF="$TMP/lsof85/lsof"
  echo "85. a default branch that changes before the removal keeps the worktree and the branch"
  if (( RC == 0 )) && [[ "$(kept_reason "$nd")" == changed ]] && listed "$SHARED" "$nd" \
    && [[ "$(branch_kept_reason review/nd-nowt)" == changed ]] && has_branch "$SHARED" review/nd-nowt; then
    pass; else fail "default changed: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 84. a directory the nested-repository walk cannot read keeps the worktree.
  if [[ "$(id -u)" == 0 ]]; then
    echo "84. skipped: root reads every directory"
  else
    mk_repo walkerr
    local we="$ROOT/walkerr-wt"
    quiet "walkerr worktree add failed" git -C "$SHARED" worktree add -q --detach "$we" origin/main
    printf 'build/\n' > "$we/.git-info-exclude" || die "write exclude failed"
    mkdir -p "$(git -C "$we" rev-parse --git-common-dir)/info" || die "mkdir info failed"
    printf 'sealed/\n' >> "$(git -C "$we" rev-parse --git-common-dir)/info/exclude" || die "write info/exclude failed"
    rm "$we/.git-info-exclude" || die "rm scratch failed"
    mkdir -p "$we/sealed/inner" || die "mkdir sealed failed"
    age_wt "$we"
    chmod 000 "$we/sealed" || die "chmod sealed failed"
    idle_run
    chmod 755 "$we/sealed" || die "restore sealed failed"
    echo "84. an unreadable directory under the worktree keeps it, reported as a failure"
    if (( RC == 2 )) && listed "$SHARED" "$we" && [[ "$OUT" == *"cannot read its submodules or nested repositories"* ]]; then
      pass; else fail "walk error: rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 87. a root replaced during the run stops every later destructive step.
  mk_repo eightyfive
  add_wt "$SHARED" review/a85 "$ROOT/a85"
  add_wt "$SHARED" review/b85 "$ROOT/b85"
  git -C "$SHARED" branch --no-track review/c85 origin/main || die "branch c85 failed"
  local shim85="$TMP/shim85" root85="$ROOT"
  mkdir -p "$shim85" || die "mkdir shim85 failed"
  # The first `worktree remove` runs for real, then swaps the root for an
  # empty directory of the same name: the later worktree, the removed one's
  # branch, the metadata removal and the branch pass all come after the swap.
  cat > "$shim85/git" <<SHIM || die "shim85 write failed"
#!/usr/bin/env bash
set -euo pipefail
if [[ "\$*" == *"worktree remove"* && ! -e "$shim85/done" ]]; then
  "$real_git" "\$@"
  : > "$shim85/done"
  mv "$root85" "$root85.moved"
  mkdir "$root85"
  exit 0
fi
exec "$real_git" "\$@"
SHIM
  chmod +x "$shim85/git" || die "chmod shim85 failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$shim85:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "87. a root replaced during the run stops every later removal, deletion and metadata removal"
  if (( RC == 2 )) && [[ -e "$shim85/done" ]] && [[ "$OUT" == *"worktree root was replaced"* ]] \
    && listed "$SHARED" "$ROOT/b85" && [[ -d "$root85.moved/b85" ]] \
    && has_branch "$SHARED" review/a85 && has_branch "$SHARED" review/b85 && has_branch "$SHARED" review/c85; then
    pass; else fail "root replaced mid-run: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 88. a root that is not the one the caller proved decides nothing.
  mk_repo eightysix
  add_wt "$SHARED" review/a86 "$ROOT/a86"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PRUNE_ROOT_ID="0:0" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "88. a root other than the one PRUNE_ROOT_ID names is exit 1, no JSON, nothing removed"
  if (( RC == 1 )) && [[ -z "$OUT" && -d "$ROOT/a86" && "$ERRTEXT" == *PRUNE_ROOT_ID* ]] && has_branch "$SHARED" review/a86; then
    pass; else fail "caller root id: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 89. a root that becomes unlistable during the run is a changed root.
  if [[ "$(id -u)" == 0 ]]; then
    echo "89. skipped: root lists every directory"
  else
    mk_repo eightynine
    add_wt "$SHARED" review/a89 "$ROOT/a89"
    add_wt "$SHARED" review/b89 "$ROOT/b89"
    local shim89="$TMP/shim89" root89="$ROOT"
    mkdir -p "$shim89" || die "mkdir shim89 failed"
    # The first `worktree remove` runs for real, then the root loses every
    # permission: same directory, same inode, but nothing below it is readable.
    cat > "$shim89/git" <<SHIM || die "shim89 write failed"
#!/usr/bin/env bash
set -euo pipefail
if [[ "\$*" == *"worktree remove"* && ! -e "$shim89/done" ]]; then
  "$real_git" "\$@"
  : > "$shim89/done"
  chmod 000 "$root89"
  exit 0
fi
exec "$real_git" "\$@"
SHIM
    chmod +x "$shim89/git" || die "chmod shim89 failed"
    RUN_SEQ=$((RUN_SEQ+1))
    OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$shim89:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
    ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
    chmod 755 "$root89" || die "restore root89 failed"
    echo "89. a root that becomes unlistable during the run stops every later destructive step"
    if (( RC == 2 )) && [[ -e "$shim89/done" ]] && [[ "$OUT" == *"worktree root was replaced or became unreadable"* ]] \
      && listed "$SHARED" "$ROOT/b89" && [[ -d "$ROOT/b89" ]] \
      && has_branch "$SHARED" review/a89 && has_branch "$SHARED" review/b89; then
      pass; else fail "root unlistable mid-run: rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 90. a root renamed inside the metadata step keeps its live worktrees' entries.
  mk_repo ninety
  add_wt "$SHARED" review/gone90 "$ROOT/gone90"
  rm -rf "$ROOT/gone90" || die "rm gone90 failed"
  add_wt "$SHARED" review/live90 "$ROOT/live90"; commit_in "$ROOT/live90" live
  local shim90="$TMP/shim90" moved90="$ROOT.moved90"
  mkdir -p "$shim90" || die "mkdir shim90 failed"
  # The metadata step's first git call (a whole-repository `worktree prune`, a
  # per-entry `worktree remove`, or the admin-directory lookup) runs just after
  # the root's identity was re-proven; the shim renames the root first, inside
  # that window.
  cat > "$shim90/git" <<SHIM || die "shim90 write failed"
#!/usr/bin/env bash
set -euo pipefail
if [[ ( "\$*" == *"worktree prune"* || "\$*" == *"worktree remove"* || "\$*" == *"--git-common-dir"* ) && ! -e "$shim90/done" ]]; then
  : > "$shim90/done"
  mv "$ROOT" "$moved90"
fi
exec "$real_git" "\$@"
SHIM
  chmod +x "$shim90/git" || die "chmod shim90 failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$shim90:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  if [[ -e "$moved90" ]]; then mv "$moved90" "$ROOT" || die "restore root after 90 failed"; fi
  echo "90. a root renamed during the metadata step keeps the registration of every worktree it holds"
  if [[ -e "$shim90/done" ]] && listed "$SHARED" "$ROOT/live90" && [[ -d "$ROOT/live90" ]] \
    && ! listed "$SHARED" "$ROOT/gone90" && has_branch "$SHARED" review/live90; then
    pass; else fail "root moved at the metadata step: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 91. a live entry that cannot be locked stops the prune.
  if [[ "$(id -u)" == 0 ]]; then
    echo "91. skipped: root writes into any directory"
  else
    mk_repo ninetyone
    add_wt "$SHARED" review/gone91 "$ROOT/gone91"
    rm -rf "$ROOT/gone91" || die "rm gone91 failed"
    add_wt "$SHARED" review/live91 "$ROOT/live91"; commit_in "$ROOT/live91" live91
    # Its admin entry refuses the lock file; git still reads it.
    chmod 555 "$SHARED/.git/worktrees/live91" || die "chmod live91 admin failed"
    run "$SHARED"
    chmod 755 "$SHARED/.git/worktrees/live91" || die "restore live91 admin failed"
    echo "91. a lock that cannot be taken stops the prune and drops nothing"
    if (( RC == 2 )) && [[ "$OUT" == *"could not lock it"*"re-run"* ]] \
      && listed "$SHARED" "$ROOT/gone91" && has_branch "$SHARED" review/gone91 \
      && listed "$SHARED" "$ROOT/live91" && [[ "$(branches_deleted)" != *review/gone91* ]]; then
      pass; else fail "lock fails: rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 92. a worktree that reappears before the cleanup is never touched.
  mk_repo ninetytwo
  add_wt "$SHARED" review/back92 "$ROOT/back92"; commit_in "$ROOT/back92" kept92
  local tip92 aside92="$TMP/aside92" shim92="$TMP/shim92"
  tip92="$(git -C "$ROOT/back92" rev-parse HEAD)" || die "rev-parse back92 failed"
  mv "$ROOT/back92" "$aside92" || die "move back92 aside failed"
  mkdir -p "$shim92" || die "mkdir shim92 failed"
  # Gone at the inventory, back on disk when the cleanup's first git call runs.
  cat > "$shim92/git" <<SHIM || die "shim92 write failed"
#!/usr/bin/env bash
set -euo pipefail
if [[ ( "\$*" == *"worktree prune"* || "\$*" == *"worktree remove"* || "\$*" == *"--git-common-dir"* ) && ! -e "$shim92/done" ]]; then
  : > "$shim92/done"
  mv "$aside92" "$ROOT/back92"
fi
exec "$real_git" "\$@"
SHIM
  chmod +x "$shim92/git" || die "chmod shim92 failed"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env WORKTREE_ROOT="$ROOT" PRUNE_IDLE_HOURS=0 PATH="$shim92:$PATH" bash "$SCRIPT" "$SHARED" 2>"$TMP/err.$RUN_SEQ")"; RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
  echo "92. a worktree moved back before the cleanup keeps its files, commits and registration"
  if [[ -e "$shim92/done" ]] && [[ -f "$ROOT/back92/kept92" ]] && listed "$SHARED" "$ROOT/back92" \
    && [[ "$(git -C "$SHARED" rev-parse refs/heads/review/back92)" == "$tip92" ]] \
    && [[ "$(git -C "$ROOT/back92" rev-parse HEAD)" == "$tip92" ]]; then
    pass; else fail "path reappears: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 93. a vanished registration outside the root is dropped as well.
  mk_repo ninetythree
  add_wt "$SHARED" review/out93 "$TMP/outside93"
  rm -rf "$TMP/outside93" || die "rm outside93 failed"
  run "$SHARED"
  echo "93. a vanished registration outside the worktree root is dropped"
  if (( RC == 0 )) && [[ "$(kept_reason "$TMP/outside93")" == prunable ]] && ! listed "$SHARED" "$TMP/outside93"; then
    pass; else fail "stale outside root: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 94. a relative-path registration is found and dropped.
  mk_repo ninetyfour
  local rel94_rc=0
  git -C "$SHARED" worktree add -q --relative-paths -b review/rel94 "$ROOT/rel94" origin/main >"$TMP/rel94.out" 2>&1 || rel94_rc=$?
  if (( rel94_rc != 0 )) && grep -q -- '--relative-paths' "$TMP/rel94.out"; then
    echo "94. skipped: this git has no --relative-paths ($(tr '\n' ' ' < "$TMP/rel94.out"))"
  elif (( rel94_rc != 0 )); then
    die "worktree add --relative-paths failed: $(cat "$TMP/rel94.out")"
  else
    grep -q '^\.\.' "$SHARED/.git/worktrees/rel94/gitdir" || die "fixture gitdir is not relative: $(cat "$SHARED/.git/worktrees/rel94/gitdir")"
    rm -rf "$ROOT/rel94" || die "rm rel94 failed"
    run "$SHARED"
    echo "94. a vanished registration with a relative gitdir is dropped"
    if (( RC == 0 )) && [[ "$(kept_reason "$ROOT/rel94")" == prunable ]] && ! listed "$SHARED" "$ROOT/rel94"; then
      pass; else fail "relative gitdir: rc=$RC out=$OUT err=$ERRTEXT"; fi
  fi

  # --- 95. an entry someone else locked keeps that lock; this run leaves none.
  mk_repo ninetyfive
  add_wt "$SHARED" review/held95 "$ROOT/held95"; commit_in "$ROOT/held95" held95
  git -C "$SHARED" worktree lock --reason "operator hold" "$ROOT/held95" || die "lock held95 failed"
  add_wt "$SHARED" review/other95 "$ROOT/other95"; commit_in "$ROOT/other95" other95
  add_wt "$SHARED" review/gone95 "$ROOT/gone95"
  rm -rf "$ROOT/gone95" || die "rm gone95 failed"
  run "$SHARED"
  echo "95. an operator's lock survives the run and the run leaves no lock of its own"
  if (( RC == 0 )) && [[ "$(lock_of "$SHARED" "$ROOT/held95")" == "locked:operator hold" ]] \
    && [[ "$(lock_of "$SHARED" "$ROOT/other95")" == unlocked ]] && ! listed "$SHARED" "$ROOT/gone95"; then
    pass; else fail "operator lock: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 96. a killed run's lock is released; a live run's is not.
  mk_repo ninetysix
  local dead96
  bash -c 'exit 0' &
  dead96=$!
  wait "$dead96" || die "the short-lived process for 96 failed"
  add_wt "$SHARED" review/left96 "$ROOT/left96"; commit_in "$ROOT/left96" left96
  git -C "$SHARED" worktree lock --reason "prune-worktrees:${dead96}:crashed" "$ROOT/left96" || die "lock left96 failed"
  add_wt "$SHARED" review/busy96 "$ROOT/busy96"; commit_in "$ROOT/busy96" busy96
  git -C "$SHARED" worktree lock --reason "prune-worktrees:$$:running" "$ROOT/busy96" || die "lock busy96 failed"
  run "$SHARED"
  echo "96. a lock left by a killed prune is released; one held by a live prune stays"
  if (( RC == 0 )) && [[ "$(lock_of "$SHARED" "$ROOT/left96")" == unlocked ]] \
    && [[ "$(kept_reason "$ROOT/left96")" == unpushed ]] \
    && [[ "$(lock_of "$SHARED" "$ROOT/busy96")" == "locked:prune-worktrees:$$:running" ]]; then
    pass; else fail "stale lock: rc=$RC out=$OUT err=$ERRTEXT"; fi

  # --- 14. usage / not a repo.
  run
  echo "14a. usage is exit 1 with no JSON"
  if (( RC == 1 )) && [[ -z "$OUT" ]] && [[ "$ERRTEXT" == *usage* ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  mkdir -p "$TMP/notrepo" || die "mkdir failed"
  run "$TMP/notrepo"
  echo "14b. a non-repository is exit 1"
  if (( RC == 1 )) && [[ -z "$OUT" ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi
  run "$SHARED" --bogus
  echo "14c. an unknown flag is exit 1"
  if (( RC == 1 )) && [[ -z "$OUT" ]]; then pass; else fail "rc=$RC out=$OUT err=$ERRTEXT"; fi

  echo
  echo "passed=$PASS failed=$FAIL"
  (( FAIL == 0 ))
}

# Entry-point guard (rules/file-hygiene.md Standalone Scripts).
if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then
  main "$@"
fi

skills

herdr-foreman

tests

__init__.py

fakes.py

test_assign.py

test_attention.py

test_billing.py

test_bounded_run.sh

test_capabilities.py

test_capability_routing.py

test_chronology.py

test_churn.py

test_classify.sh

test_claude_native.py

test_cli.py

test_compose_briefs.sh

test_composer.py

test_composition.py

test_config.py

test_continuity_cli.py

test_cost_report.py

test_diagnostics.py

test_engagement.py

test_entrypoints.py

test_foreman_launcher.sh

test_foreman_queue.py

test_foreman_reset.py

test_foreman_seat.py

test_foreman_tier_check.py

test_freeze.py

test_herdr.py

test_historical.py

test_home.py

test_label_workspaces.sh

test_launch.py

test_legacy_recovery.py

test_lifecycle.py

test_load_set.py

test_measure.py

test_members.py

test_memory.py

test_minimum_adequate.py

test_oracle.py

test_parsers.py

test_partition.py

test_planner.py

test_probe.py

test_provision_worktree.sh

test_prune_remote_branches.sh

test_prune_report_caches.py

test_prune_result.py

test_prune_worktrees.sh

test_recovery_cli.py

test_recovery.py

test_renderable.py

test_report_contract.py

test_report_delivery.py

test_report_gates.py

test_report_verdict.py

test_reset_input_hook.py

test_resolve_gates.sh

test_resolve_policy_paths.py

test_restoration.py

test_retrospective_runtime.py

test_retrospective.py

test_review_package.py

test_role_clear.py

test_roster.sh

test_round_preflight.sh

test_runnable.py

test_scoring.py

test_script_dir_newline.sh

test_seat_holds.py

test_selection.py

test_skill_invocations.sh

test_slice_scope_parity.py

test_specialist_cli.py

test_specialist_delivery.py

test_specialist_recovery.py

test_specialist_retention.py

test_stale_grok_delivery.py

test_start_judge_worker.py

test_state.py

test_successors.py

test_supervision_cli.py

test_supervision_diagnostics.py

test_supervision_gate.py

test_supervision_replay.py

test_supervision.py

test_sweep_worktrees.sh

test_tier_integration.py

test_tiers.py

test_triggers.py

test_typesafe_client.py

test_verdict_gates.py

test_verify_authority.sh

test_wait_report.sh

tier_fixture.py

bounded-run.sh

compose-briefs.sh

config.example.json

foreman-tier-check.py

foreman.sh

label-workspaces.sh

provision-worktree.sh

prune-remote-branches.sh

prune-report-caches.py

prune-worktrees.sh

resolve-gates.sh

resolve-policy-paths.sh

review-package.sh

roster.sh

round-preflight.sh

SKILL.md

start-judge-worker.sh

state-schema.md

sweep-worktrees.sh

verify-authority.sh

wait-report.sh

README.md

tile.json