Status: implemented
Merges the original proposal and the decision record for one topic. It found a real BlockAssembler duplicate-
block-endbug on first run.
Example-based tests pin the cases we thought of. The harness's core is protocol-shaped — chunk streams, event logs, schema conversion, inbox scheduling — where the input space is combinatorial and the interesting bugs live in interleavings nobody wrote an example for. The motivating evidence: a block-assembly ordering bug once survived 100% line coverage of the happy paths. Per-file 100% coverage proves every line ran, not that every interleaving is correct.
Adopt fast-check (a root devDependency) with one tests/properties.spec.ts per protocol-shaped package, generators tuned for realistic-but-adversarial inputs (not uniform noise) and numRuns kept so the suite stays well under ~10s locally. Failures print a reproducible seed. (The original proposal also sketched a nightly CI job running 100× the iterations; that was not shipped — the property suite runs only in the normal push/pull_request CI, and a scheduled high-iteration job remains possible future work.)
blocks() count ≤ distinct indices seen; re-assembly idempotent (blocks() is stable across repeated calls and message().content mirrors it); blocks() never throws and yields only valid content-block tags; finish reflects the last finish chunk, defaulting to {kind:'stop'} when none arrives.deriveMessages deterministic; replay-from-seed identical; seq strictly monotonic; non-message events never affect derived history; derived content is decoupled from the log.SchemaSpec. Invariants: JSON Schema required equals the required:true keys at every level; conversion total; and the composition with runtime arg validation — generated args satisfying a spec pass validateArgs, and targeted corruptions (dropped required key, non-object top level) are rejected. This closes the validator/InferArgs drift risk.agent/status settle signal (no wall-clock sleeps). Invariants: no message lost; turn numbers strictly increase; status transitions stay on the legal machine.block-end at the same index rewrote a completed block. Fixed (first close wins, matching the existing straggler rule) with a dedicated regression test.agent/status), so a hang is a real defect.