Files
orca/src/shared
Merge Sim 466a745cb9 fix(claude): make every dispositive verdict prove itself, not just the probe
Round 2 of review on #17993. The tri-state had reached the ownership probe and
one caller; five other places still turned a failed observation into an answer,
and one turned a user's request into a refusal.

Enumerated every path in the lane that can produce a dispositive verdict — path
checks, marker reads, credential reads, error classification, and the four
decisions that clear or delete durable state — and fixed them together rather
than one at a time.

- The credentials read is now a result, not `string | null`. Its null said "there
  are no credentials", which `doSyncForCurrentSelection` acts on by clearing the
  user's account; a locked file, an unsearchable directory, or a failed realpath
  produced the same null. Both sync branches now leave the selection alone on an
  indeterminate read and clear only on a completed absence or invalid content.
  The darwin keychain read is classified the same way: its helper resolves null
  only for a genuine not-found, and every other failure throws.
- The account path check requires exactly one segment between the managed root
  and `auth`. A shell `*` matches `/`, so the guest accepted
  `<root>/other/acct/auth` as account `acct`, and the host-side `endsWith` agreed.
  Orca only ever creates `<root>/<accountId>/auth`.
- `isDefinitiveAbsence` guards its errno read again. Reverting it last commit was
  wrong: the sibling STA-5616 fix is on another branch, so this branch shipped a
  fail-closed predicate that throws. Written byte-identical to `349510a18e` so the
  merge is a no-op rather than a conflict.
- The unproven-error predicate is total. `instanceof` runs a prototype lookup a
  Proxy can trap and throw from, so it moves inside the guard; a chain longer
  than the inspection depth counts as unproven, because those links were never
  looked at. A cycle still answers `false` — every reachable link was seen.
- Explicit removal surfaces a failed unlink instead of reporting success. The
  caller already rolls its settings change back and rethrows, so the account
  returns and the user can retry; telling them it is gone while the credentials
  are still on disk is the same silent retention this path was fixed to stop. A
  root spelling that could not be canonicalised is reported too: with one
  spelling to compare against, "not ours" was never established.

Three tests asserted a failure scenario without injecting the failure — the
removal test armed a probe that no longer runs, a darwin test used a one-shot
rejection an earlier call consumed, and keychain call counts accumulated across
tests. Each now proves the fault reached the code under test.

Refs STA-5674.
2026-09-01 16:25:59 -07:00
..
2026-05-31 05:55:04 -07:00