Test-only follow-up to the merged P0 (#2531). No production change, no
changeset (internal).
## Why
This bug reached users **three times**, each as the same mistake in a
new place:
| | What happened |
|---|---|
| FN-8600 | the reclaim sweep removed a worktree a live **planner** was
using — fixed by registering planning paths and teaching *that* sweep
`isPathActive` |
| FN-6756 | the leaked-slot reaper never got the same signal; its last
line of defense computed liveness from four TaskExecutor-owned maps, so
a triage planner matched none of them |
| (same PR) | fixing that was not enough — `recoverPausedAbortFailures`
**discarded** the refusal and still logged `"Auto-recovered…"`, audited
and counted it. The whole bug again, while reporting success |
The shared cause is not any one sweep: **“liveness” was re-derived per
call site**, so closing one door left the next open and nothing failed.
Every one of those fixes was found by review, not by CI. This makes the
next one a CI failure.
## Four properties, each written to fail on the exact defect that got
through
1. **Every `clearPhantomExecutorBinding?.(` call site consumes its
return** — a bare expression statement (including
`void`/`await`-prefixed) is the signature of the pause-abort defect.
2. **The destructive path delegates to `hasLiveSessionSurface`** rather
than inlining the session-map disjunction — a second copy can drift from
the one callers gate on, which is precisely how each sweep got “fixed”
without fixing the next.
3. **The probe is wired** in `in-process-runtime`. `self-healing.ts`
already records `releaseExecutorWorktreeOwnership` as a
declared-but-never-wired option that silently no-opped; an unwired
*probe* is worse, since `?.() === true` is `false` when unwired and
every gate would quietly stop deferring with nothing failing.
4. **The probe counts registered session paths**, not just executor maps
— a triage planner appears in no executor-owned map, so that term is the
only thing that sees it.
Grep-level, comment-stripped, production source only; no engine boot and
no fixtures (FN-5048). Fails closed on an empty/moved source file so a
rename cannot make it silently check nothing.
## Proven, one injection at a time
**The first draft of property 1 was worthless** — its filter chain was
convoluted enough to discard every candidate, so the injected bare call
passed. Caught by actually running the injection instead of trusting the
green, and rewritten as a single “is this a bare expression statement”
rule.
| Injection | Result |
|---|---|
| discard the return value | fails, naming the call site |
| re-derive liveness inline | fails on the delegation assertion |
| unwire the probe | fails, naming `in-process-runtime` |
| drop the registry term | fails, naming `activeSessionRegistry` |
Clean tree passes 4/4; all three sources restored byte-identical (`git
status` shows only the new file).
**Verified:** `pnpm lint` clean · engine `tsc` clean · `pnpm test:gate`
green (414 + 10 + 71).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Tests**
* Added safeguards to ensure liveness checks remain consistently
enforced.
* Verified phantom executor cleanup uses shared session-liveness
detection.
* Added coverage for registered session paths to prevent false inactive
states.
* Added fail-closed checks when required runtime source is unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>