# CI exclusion manifest for defaults/scripts/tests/ (issue #4455)
#
# Every `test-*.sh` in this directory must appear in EXACTLY ONE of:
#   - ci-wired.txt     — run by run-ci-suites.sh in CI (hermetic on ubuntu-latest)
#   - ci-excluded.txt  — this file: explicitly excluded, with a one-line reason
#
# check-ci-suite-manifest.sh enforces that partition in CI, so a newly added
# suite that is in NEITHER list fails the check — it cannot silently join an
# unwired pool. To exclude a suite, add a line here: `<suite.sh>  <reason>`.
# Blank lines and lines beginning with `#` are ignored. The first whitespace-
# delimited token is the filename; everything after it is the (required) reason.
#
# Format: <test-file.sh>  <reason>

test-install-reinstall-safety.sh  Already wired in the "Installer Integration Tests" job (#4188); excluded here to avoid double-running it.
test-check-labels-drift.sh  Needs a built loom-daemon with `labels` (#10013); wired in the "Installer Integration Tests" job beside check-labels-drift.sh itself, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-spawn-codex.sh  Already wired in the "Codex Adapter Smoke (mocked)" job (#4468), which adds adapter-specific hermeticity guards; excluded here to avoid double-running it.

# epic #7810 PR 3: each of these drives a thin stub that execs a `loom-daemon`
# subcommand, so it needs a BUILT binary — which run-ci-suites.sh's job has no
# toolchain for. Wired in the "Native Port Suites" job instead,
# which downloads the shared build first. Each suite FAILS rather than SKIPs without a binary,
# so neither location can report green while running nothing.
test-classify-dependency-block.sh  Needs a built loom-daemon; wired in the "Native Port Suites" job (#7952), which downloads the shared build first.
test-classify-dependency-block-premise-false.sh  Needs a built loom-daemon; wired in the "Native Port Suites" job (#7952), which downloads the shared build first.
test-detect-dependency-cycle.sh  Needs a built loom-daemon; wired in the "Native Port Suites" job (#7952), which downloads the shared build first.
test-detect-startable-subset.sh  Needs a built loom-daemon; wired in the "Native Port Suites" job (#7952), which downloads the shared build first.
test-dep-recheck-fingerprint.sh  Needs a built loom-daemon; wired in the "Native Port Suites" job (#7961), which downloads the shared build first.
test-check-stale-blocked.sh  Needs a built loom-daemon — check-stale-blocked.sh is a Shape-A stub over `loom-daemon check-stale-blocked` (#8927); wired in the "Native Port Suites" job, which downloads the shared build first. Its no-binary assertion covers only the degrade path; the fixture-driven half must FAIL, never SKIP, without a binary.
test-post-verdict-gate.sh  Needs a built loom-daemon — drives post-verdict.sh against the real `forge verdict-gate` / `verdict-labels` (#10581); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-notify-cleared-blockers.sh  Needs a built loom-daemon — merge-pr.sh's `_notify_cleared_blockers` delegates the decision and the comment to `loom-daemon notify-cleared-blockers` (#9102); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-claude-wrapper-retry.sh  Needs a built loom-daemon since #8037 routed claude-wrapper.sh's six classifiers through `loom-daemon retry-classify`; wired in the "Native Port Suites" job, which downloads the shared build first. Its 44 assertions are unchanged from #8032 — they are the equivalence proof for that port.
test-merge-pr-partial-increment.sh  Needs a built loom-daemon since #8191 slice 1 routed merge-pr.sh's closing-reference analysis through `loom-daemon`; wired in the "Native Port Suites" job, which downloads the shared build first. Its assertions against the retired shell functions moved to the frozen `merge-pr-refs-retired.sh` fixture instead.
test-merge-pr-stale-mergeable.sh  Needs a built loom-daemon since the #8191 mergeable-recheck slice routed the recheck's terminal classification through `loom-daemon merge-pr mergeable-recheck`; wired in the "Native Port Suites" job, which downloads the shared build first. Its behavioral cases (a)-(f) are unchanged — they now drive the shell loop and the Rust decision together via the require-daemon-bin pin.
test-merge-pr-verdict-label-guard.sh  Needs a built loom-daemon since #8112 routed merge-pr.sh's verdict-label contradiction guard through `loom-daemon merge-pr verdict-contradiction` (epic #7810, #8191 slice 2); wired in the "Native Port Suites" job, which downloads the shared build first. Its fail-closed assertions are the point: the suite must FAIL, never SKIP, without a binary.
test-per-worktree-target-dir.sh  Needs a built loom-daemon: the per-worktree scheme's whole decision is `loom-daemon cargo-target-dir` (#8458), and the suite pins the working-tree binary through lib/require-daemon-bin.sh rather than an ambient install. Wired in the "Native Port Suites" job, which downloads the shared build first. It FAILS rather than SKIPs without a binary, so neither location can report green while running nothing.
test-merge-pr-loom-pr-label-guard.sh  Needs a built loom-daemon since #8191's slice routed merge-pr.sh's `loom:pr` review-signal guard (#7419) through `loom-daemon merge-pr loom-pr-guard` (epic #7810); wired in the "Native Port Suites" job, which downloads the shared build first. Like its verdict-label-guard sibling above, its fail-closed assertions are the point: the suite must FAIL, never SKIP, without a binary.
test-merge-pr-hold-state-trust.sh  Needs a built loom-daemon: merge-pr.sh's champion:hold-state staleness check (#7419) reads PR comments through `_trusted_pr_comments`, which filters them with `loom-daemon forge trusted-comments` (#9548) before `loom-daemon merge-pr hold-state` extracts the marker, and the trust scenarios need the genuine filter, not a stub; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-classify-capacity-defer.sh  Needs a built loom-daemon since #9657: classify-capacity-defer.sh's comment reads (live and --comments-file) filter through `loom-daemon forge trusted-comments` (#9548), and the suite's trusted-vs-outsider scenarios pin the working-tree binary; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary — which is why it left the toolchain-free ci-wired.txt pool.
test-merge-pr-stale-required-checks.sh  Needs a built loom-daemon since #8248 routed merge-pr.sh's required-check freshness guard through `loom-daemon merge-pr stale-checks` (epic #7810, #8191 slice 3); wired in the "Native Port Suites" job, which downloads the shared build first. The wiring half runs against a stub LOOM_DAEMON_BIN; the real-binary half drives `--from-stdin` with the incident payload, so it must FAIL, never SKIP, without a binary.
test-merge-pr-head-sync-retry.sh  Needs a built loom-daemon since #8164 routed merge-pr.sh's post-base-sync head re-read and its structural self-sync retry through `loom-daemon merge-pr head-sync-retry` (epic #7810, #8191 slice 4); wired in the "Native Port Suites" job, which downloads the shared build first. Like its slice-3 sibling above, it must FAIL, never SKIP, without a binary.
test-merge-pr-label-freshness.sh  Needs a built loom-daemon: its end-to-end chain (stale-cache fetch -> $PR_LABELS -> merge decision, #8550) drives the REAL `loom-daemon merge-pr verdict-contradiction` for the decision half, exactly as its #8112 sibling above does; wired in the "Native Port Suites" job, which downloads the shared build first. It must FAIL, never SKIP, without a binary — a skipped decision half would leave only the source-grep assertions, which is what the suite exists to be more than.
test-merge-pr-workflow-scope-preflight.sh  Needs a built loom-daemon: merge-pr.sh's pre-merge workflow-token-scope guard (#10539) is `loom-daemon merge-pr workflow-scope`, and the suite drives the extracted `_check_workflow_scope` wrapper against the REAL subcommand with a stubbed `gh`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-stale-check-redate.sh  Needs a built loom-daemon since #8508 wired merge-pr.sh's `--redate-stale-checks` remedy through `loom-daemon merge-pr redate-checks` (epic #7810, on top of #8248's slice-3 guard); wired in the "Native Port Suites" job, which downloads the shared build first. Like its slice-3 sibling above, it must FAIL, never SKIP, without a binary.
test-merge-pr-auto-blocked-settle.sh  Needs a built loom-daemon since #8410's settle-then-re-validate path drives the real `_check_verdict_label_contradiction`, which shells out to `loom-daemon merge-pr verdict-contradiction` (the #8112 port); wired in the "Native Port Suites" job, which downloads the shared build first. Like its verdict-label-guard sibling it calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-defaults-version-bump-collision.sh  Needs a built loom-daemon since #8191's slice routed merge-pr.sh's pre-merge version-policy guard through `loom-daemon merge-pr version-policy` (epic #7810); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-verdict-staleness-guard-tree.sh  Needs a built loom-daemon: it drives verdict-staleness-guard.sh against the REAL `loom-daemon forge verdict-equivalent` (#9576, #9416) to prove a rewound head (`behind`, no files) is STALE, that the rebase-patch-identical kind refuses two empty diffs and a patch-less file entry, and that `LOOM_VERDICT_TREE_CARVEOUT=0` / `LOOM_VERDICT_EQUIVALENCE=0` disable their kinds on the shell path too (PR #9581 review); a stub of the verb would test the stub. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-local-branch-cleanup.sh  Needs a built loom-daemon since #8191's delete-branch slice routed merge-pr.sh's `_maybe_delete_local_branch` through `loom-daemon merge-pr delete-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-dirty-worktree-guard.sh  Needs a built loom-daemon since #8191's delete-branch slice, and doubly so since its dirty-guard slice: the post-merge cleanup path reaches `loom-daemon merge-pr delete-branch`, and the #5031 data-loss guard this suite is ABOUT is now `loom-daemon merge-pr dirty-guard`, which fails closed. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-primary-checkout-advice.sh  Needs a built loom-daemon since #8191's delete-branch slice: its discovery-fallback cleanup path reaches `loom-daemon merge-pr delete-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-worktree-awk.sh  Needs a built loom-daemon since #8191's worktrees slice: the three porcelain lookups this suite is ABOUT (#3671's double-print, #3717's space-truncated path) are now `loom-daemon merge-pr worktree-primary|worktree-branch-for|worktree-find-by-branch`, and Tests 2/3 drive them directly instead of the hand-copied awk mirror they used to carry. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-primary-worktree-guard.sh  Needs a built loom-daemon since #8191's delete-branch slice: its `_remove_loom_worktree` cleanup path reaches `loom-daemon merge-pr delete-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-worktree-remove-diagnosis.sh  Needs a built loom-daemon since #8191's delete-branch slice: its post-merge cleanup path reaches `loom-daemon merge-pr delete-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-head-mismatch.sh  Needs a built loom-daemon since #8191's classify-response slice: the head-SHA-mismatch classifier this suite is ABOUT — and the precedence that keeps it out of the "Base branch was modified" retry arm (#5579) — is now `loom-daemon merge-pr classify-response`, and Part 2 drives the real binary through merge-pr.sh's own `_classify_merge_response` seam instead of the extracted `grep` predicate it replaced. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-closed-issue-cleanup.sh  Needs a built loom-daemon since #8191's closed-issue slice: the #6199 cleanup this suite is ABOUT — stripping `loom:building` from an issue the merge itself closed — is now `loom-daemon merge-pr closed-building`, and the suite pins the working-tree binary through lib/require-daemon-bin.sh. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-worktree-path.sh  Needs a built loom-daemon since #8191's async-close-race slice: Test 7 extracts merge-pr.sh's real `_issue_is_closed_for_cleanup` (#4186), whose decision is now `loom-daemon merge-pr issue-close-gate`, and drives it against the working-tree binary pinned through lib/require-daemon-bin.sh. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin` at file scope, so it must FAIL, never SKIP, without a binary — which is exactly why it cannot stay in the toolchain-free shell-suite-tests pool.
test-merge-pr-merge-ordering-guard.sh  Needs a built loom-daemon since #8191's stacked-children slice: the #3747-item-2 merge-ordering guard this suite is ABOUT is now `loom-daemon merge-pr stacked-children`, which discovers the children and writes the `refs/loom/parent/<branch>` pin. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-merge-pr-auto-reconcile.sh  Needs a built loom-daemon since #8191's reconcile slice: the post-merge stacked-child reconcile this suite is ABOUT — the parent-branch gate, the children-rollup parse and the safe/unsafe claim check (#4856) — is now `loom-daemon merge-pr reconcile-plan` / `merge-pr reconcile-child`, and the suite pins the working-tree binary through lib/require-daemon-bin.sh. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-cleanup-branches-pr-review-branch.sh  Needs a built loom-daemon since #8191's delete-branch slice: it extracts merge-pr.sh's real `_maybe_delete_local_branch`, which now delegates to `loom-daemon merge-pr delete-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-loom-daemon-update-resolve-json.sh  Needs a built loom-daemon since #7977 routed --resolve-json through it; wired in the "Native Port Suites" job, which downloads the shared build first. Split from test-loom-daemon-update.sh rather than moving it: the parent is one of the five host-mutating suites LIVE_DAEMON_GUARDED_SUITES owns, and that membership is pinned as a literal in test-run-ci-suites-daemon-guard.sh.
test-loom-daemon-update-fetch.sh  Needs a built loom-daemon since #8028 routed fetch_and_verify_artifact() through `loom-daemon release-fetch`; wired in the "Native Port Suites" job, which downloads the shared build first. Split from test-loom-daemon-update.sh for the same reason as its resolve-json sibling: the parent is one of the five host-mutating suites LIVE_DAEMON_GUARDED_SUITES owns, and that membership is pinned as a literal in test-run-ci-suites-daemon-guard.sh.
test-loom-daemon-update-dest-signature.sh  Needs a built loom-daemon for the same reason its test-loom-daemon-update-fetch.sh parent does (#8028 routed fetch_and_verify_artifact() through `loom-daemon release-fetch`, and lib/daemon-update-fixtures.sh pins $LOOM_DAEMON_BIN through require-daemon-bin.sh); wired in the "Native Port Suites" job, which downloads the shared build first. Split from test-loom-daemon-update-fetch.sh by #8770: its subject is the POST-provision destination signature check, not artifact fetch, and that suite had reached the file-size ratchet's 1000-line threshold. Not a LIVE_DAEMON_GUARDED_SUITES member (it starts and stops nothing), so this split touches the guard's literals not at all.
test-loom-daemon-update-fetch-refusal.sh  Needs a built loom-daemon carrying `release-explain` (#8654): the forced --fetch refusal's still-uploading vs genuinely-unbuilt wording comes from that subcommand, and the suite pins it via require-daemon-bin.sh; wired in the "Native Port Suites" job, which downloads the shared build first. A sibling of test-loom-daemon-update-fetch.sh because that suite is at the file-size ratchet. Not a LIVE_DAEMON_GUARDED_SUITES member (it starts and stops nothing).
test-daemon-update-fixture-containment.sh  Needs a built loom-daemon for the same reason test-loom-daemon-update.sh does: sourcing lib/daemon-update-fixtures.sh pins $LOOM_DAEMON_BIN through require-daemon-bin.sh. Wired in the "Native Port Suites" job, which downloads the shared build first. Its subject is that fixture library itself (#8712) — the containment guard that keeps a fake loom-daemon out of a real loom-daemon/target/release/ — so it belongs to none of the flow suites and is not a LIVE_DAEMON_GUARDED_SUITES member (it starts and stops nothing).
test-loom-daemon-watchdog.sh  Needs a built loom-daemon since #8086 made cli/loom-daemon-watchdog.sh a thin stub over `loom-daemon daemon-watchdog`; wired in the "Native Port Suites (daemon lifecycle, watchdog)" job, which downloads the shared build first. MOVED here rather than split (unlike its loom-daemon-update siblings above) because there is nothing left to split: all 188 assertions drive the stub, so a residual parent would be an empty file. It stays named in run-ci-suites.sh's LIVE_DAEMON_GUARDED_SUITES and in test-run-ci-suites-daemon-guard.sh's literal — see that suite's own note on why a guarded-but-unwired entry is asserted differently rather than dropped.
test-loom-daemon-start.sh  Needs a built loom-daemon since #8087 made cli/loom-daemon-start.sh a thin stub over `loom-daemon daemon-start`; wired in the "Native Port Suites (daemon lifecycle, watchdog)" job, which downloads the shared build first. MOVED here rather than split, for the same reason as test-loom-daemon-watchdog.sh above: all 143 assertions drive the stub, so a residual parent would be an empty file. It stays named in run-ci-suites.sh's LIVE_DAEMON_GUARDED_SUITES and in test-run-ci-suites-daemon-guard.sh's literal.
test-loom-daemon-launchd-plist.sh  Needs a built loom-daemon since #8087: every case renders a plist by invoking the real cli/loom-daemon-start.sh --print-plist, which is now a thin stub over `loom-daemon daemon-start`; wired in the "Native Port Suites (daemon lifecycle, watchdog)" job, which downloads the shared build first. Not a LIVE_DAEMON_GUARDED_SUITES member (it renders, it does not start/stop anything), so unlike its start/update siblings this move touches the guard's literals not at all.
test-loom-daemon-update.sh  Needs a built loom-daemon since #8087: lib/daemon-update-fixtures.sh copies the real cli/loom-daemon-start.sh into every fixture and the restart / --relaunch / full-update flows exec it, so the whole suite now depends on the `loom-daemon daemon-start` stub resolving a binary. MOVED rather than split a third time — the dependency is in the shared fixture builder, not in an isolable block of cases, so the #7977/#8028 split that kept this parent wired is no longer available. It stays named in run-ci-suites.sh's LIVE_DAEMON_GUARDED_SUITES and in test-run-ci-suites-daemon-guard.sh's literal.
test-skip-labels.sh  Needs a built loom-daemon: skip-labels.sh (#8255) is a thin stub over `loom-daemon skip-labels`; wired in the "Native Port Suites" job, which downloads the shared build first.
test-premise-check.sh  Needs a built loom-daemon: premise-check.sh (#8396) is a thin stub over `loom-daemon premise-check`; wired in the "Native Port Suites" job, which downloads the shared build first. It FAILS rather than skips without a binary — the exit codes it pins are what curator.md and sweep-wave-lifecycle.md branch on.
test-check-duplicate.sh  Needs a built loom-daemon since #8360 moved check-duplicate.sh's similarity scan (keyword extraction, Jaccard scoring, threshold banding, degenerate detection) into `loom-daemon duplicate-scan`; wired in the "Native Port Suites" job, which downloads the shared build first. Its exact-percentage assertions are the equivalence evidence for that port, so it FAILS rather than skips without a binary.
test-create-issue-duplicate-check.sh  Needs a built loom-daemon since #8360 for its END-TO-END case, which runs the real check-duplicate.sh (and thus the real `loom-daemon duplicate-scan`); wired in the "Native Port Suites" job, which downloads the shared build first. The stub-mode cases need no binary but travel with their suite.
test-worktree-snapshot.sh  Needs a built loom-daemon since #8195 slice 2 made `worktree.sh snapshot` a thin stub over `loom-daemon worktree-wip snapshot`; wired in the "Native Port Suites" job, which downloads the shared build first. All 15 assertions are unchanged from the shell implementation — they are the equivalence evidence for that port — so it FAILS rather than skips without a binary.
test-worktree-stash-baseline.sh  Needs a built loom-daemon since #8195 slice 2 made `worktree.sh stash-push`/`stash-pop` thin stubs over `loom-daemon worktree-wip`; wired in the "Native Port Suites" job, which downloads the shared build first. All 52 assertions (including the #5217 cross-worktree race fixture and the #6076 `main` target) are unchanged, so it FAILS rather than skips without a binary.
test-verify-proposal-refs.sh  Needs a built loom-daemon since #8656 moved verify-proposal-refs.sh's line-range check into `loom-daemon git-blob-lines --range`, which follows a 120000 (symlink) tree entry to the document it points at before counting; wired in the "Native Port Suites" job, which downloads the shared build first. It FAILS rather than skips without a binary — a suite that skipped would report green while re-admitting the exact bug (every `.loom/docs/*.md` citation reported as a miss) #8656 exists to close.
test-worktree-remove.sh  Needs a built loom-daemon since #8195 slice 3 made `worktree.sh remove` a thin stub over `loom-daemon worktree-remove`; wired in the "Native Port Suites" job, which downloads the shared build first. All 26 assertions (the sentinel contract, the #4449 dirty guard and its four remedies, the CWD hop) are unchanged — they are the equivalence evidence for that port — so it FAILS rather than skips without a binary.
test-worktree-remove-squash-merge.sh  Needs a built loom-daemon since #8195 slice 3: the squash-aware branch-delete rule `worktree.sh remove` used to `awk` out of merge-pr.sh's live source is now `loom-daemon/src/worktree_cli/branch_delete.rs`. Its 10 assertions (including the fake-forge head-SHA match and the "forge unavailable" note) are unchanged, so it FAILS rather than skips without a binary.
test-worktree-local-branch-upstream-tracking.sh  Needs a built loom-daemon since #8195 slice 9 made worktree.sh's branch-reuse upstream correction (#6095/#6100) `loom-daemon worktree-upstream --arm local-branch`; wired in the "Native Port Suites" job, which downloads the shared build first. Its 6 assertions are unchanged from the shell implementation — they are the equivalence evidence for that port — and without a binary the correction does not run at all, so it FAILS rather than skips.
test-worktree-existing-dir-drift-check.sh  Needs a built loom-daemon since #8195 slice 9 made the registered-worktree fast path's upstream correction + behind-the-pushed-tip drift report (#6257/#6291) `loom-daemon worktree-upstream --arm registered-worktree` — the same implementation its local-branch sibling above now uses, retiring the hand-copied duplicate this suite's own header describes — and since #8354 it also needs `loom-daemon worktree-stale-ref`, which decides that same fast path's staleness REFERENCE (#8287). Its original 9 assertions are unchanged, and Tests 4 and 5 (6 more) are the end-to-end wiring evidence for the stale-ref port, so it FAILS rather than skips without a binary.
test-worktree-sentinel-reinvoke.sh  Needs a built loom-daemon since #8195 slice 10 made worktree.sh's --sparse/--full family `loom-daemon worktree-sparse` — including the re-configure arm Tests 3/4 drive, with its registration check and #3548 sentinel back-fill; wired in the "Native Port Suites" job, which downloads the shared build first. All assertions are unchanged, and without a binary --sparse/--full refuse with exit 2 before touching anything, so it FAILS rather than skips.
test-worktree-nested-symlinks.sh  Needs a built loom-daemon since #8195 slice 4 moved worktree.sh's shared-artifact symlinking (root and nested node_modules, worktree.linkPaths, .mcp.json) and its .git/info/exclude bookkeeping into `loom-daemon worktree-link`; wired in the "Native Port Suites" job, which downloads the shared build first. Every assertion is unchanged from the shell implementation except Test 5's one retired-and-strengthened pair (recorded in the suite via `retired()`, per verification-recipes.md §6), so it FAILS rather than skips without a binary.
test-cargo-target-dir-reclaim.sh  Needs a built loom-daemon since #8195 slice 3: its `worktree.sh remove` cases now drive the RUST reclaim (`worktree_ops/cargo_target.rs`) rather than lib/cargo-target-dir.sh's bash one. All 44 assertions are unchanged (Test 7's resolution-parity cases still compare the two shell implementations); wired in the "Native Port Suites" job, which downloads the shared build first, and it FAILS rather than skips without a binary.
test-worktree-orphan-guard-spaces.sh  Needs a built loom-daemon since #8195 slice 5 moved worktree.sh's crash-debris cleanup — the orphan guard whose false answer `rm -rf`s a live worktree (#7858/#7849) — into `loom-daemon worktree-cleanup`; wired in the "Native Port Suites" job, which downloads the shared build first. All 8 behavioral assertions plus the 2 fixture-sanity ones are unchanged from the shell implementation; only the 3 static idiom greps could not survive (there is no shell body left to grep) and they are retired in place via `retired()` per verification-recipes.md §6. It FAILS rather than skips without a binary.
test-worktree-concurrency.sh  Needs a built loom-daemon since #8195 slice 5: Tests 2 and 3 assert that a stale `.git/worktrees/issue-N/index.lock` and a half-created unregistered `issue-N` dir are recovered, and that recovery is now `loom-daemon worktree-cleanup` rather than shell — without the binary it does not happen at all. All 10 assertions are unchanged (the six lock/concurrency ones are untouched by the port, since #8226 reverted delegating the worktree-add lock), so it FAILS rather than skips without a binary.
test-worktree-race-rescue.sh  Needs a built loom-daemon since #8195 slice 6 moved lib/worktree-race-rescue.sh's `loom_worktree_reset_or_rescue` — the guard that rescues foreign uncommitted work instead of letting `git reset --hard` discard it (#6706/#6334, the #6320 incident) and refuses while a live process holds the worktree (#7463) — into `loom-daemon worktree-reset`; wired in the "Native Port Suites" job, which downloads the shared build first. All 25 assertions across its 10 tests are unchanged from the shell implementation — they are the equivalence evidence for that port — so it FAILS rather than skips without a binary.
test-worktree-issue-lock.sh  Needs a built loom-daemon: worktree.sh's issue claim-lock cross-check (#8553) delegates to `loom-daemon worktree-lock check-issue`; wired in the "Native Port Suites" job, which downloads the shared build first. It FAILS rather than skips without a binary.
test-worktree-lease-co-occupancy.sh  Needs a built loom-daemon: worktree.sh's shared-lease guard on the uncommitted-changes preserve path (rjwalters/kicad-tools#5783) delegates to `loom-daemon lease co-occupancy`; wired in the "Native Port Suites" job, which downloads the shared build first. It FAILS rather than skips without a binary.

# scripts/ (repo root, top-level only) — since #5278. Each of these already
# runs as its own direct step in ci.yml and/or build-gate.sh; excluded here
# (rather than wired) to avoid double-running it via run-ci-suites.sh.
scripts/test-ci-result-gate.sh  Already wired directly in ci.yml's always-run Structural Checks job ("Test the CI Result aggregate gate", #10444); excluded here to avoid double-running it behind the path filter.
scripts/test-release-decision.sh  Already wired directly in ci.yml's always-run Structural Checks job ("Test the release decision and release.yml wiring", #10826); excluded here to avoid double-running it behind the path filter.
scripts/test-install-local-mode.sh  Already wired directly in ci.yml's "Installer local/gitignore mode" step and build-gate.sh; excluded here to avoid double-running it.
scripts/test-installer.sh  Already wired directly in ci.yml's "Installer Integration Tests" job and build-gate.sh; excluded here to avoid double-running it.
scripts/test-migrate-consumer.sh  Already wired directly in ci.yml's "migrate-consumer" step and build-gate.sh; excluded here to avoid double-running it.
scripts/test-daemon-liveness.sh  Runs in the post-Builder buildGate (.loom/config.json -> bash .loom/scripts/build-gate.sh) on a BUILDER'S HOST, not in CI — no workflow invokes build-gate.sh (#8069). Left unwired here on purpose: it spawns a decoy process named `loom-daemon` to prove `pgrep -x` rejects what `pgrep -f` accepts (#5548), so wiring it into run-ci-suites.sh should go with a deliberate LIVE_DAEMON_GUARDED_SUITES decision rather than riding along with this change.

# Not a thin-stub suite: test-spawn-claude.sh exercises spawn-claude.sh, which
# CALLS `loom-daemon tokens select`. Same operational need (a built binary),
# different reason — it is not equivalence evidence for a port.
test-spawn-claude.sh  Needs a built loom-daemon (spawn-claude.sh token selection, #4228); wired in the "Native Port Suites" job (#8069), which downloads the shared build first. Until #8069 it ran in NO job at all — the old reason here said wiring it needed "a cargo build step or a binary stub — follow-up", and that job has since been built.
test-token-model-class.sh  Same constraint as test-spawn-claude.sh above, which it was split out of (#8058): it drives spawn-claude.sh / claude-wrapper.sh against a real `loom-daemon tokens select|mark-bad`, so it needs a built binary. Wired in the "Native Port Suites" job (#8069) alongside its parent — that job already has the shared build, so there is no reason left to leave this one excluded pending a follow-up.
test-spawn-claude-credential-proxy.sh  Same constraint as test-spawn-claude.sh above (#8697): it drives spawn-claude.sh's contained dispatch through a real `loom-daemon worker proxy-exec` listener and host-side `tokens select`, so it needs a built binary. Wired in the "Native Port Suites" job; FAILS rather than SKIPs without a binary.
test-spawn-codex-session-mount-stale.sh  Needs a built loom-daemon since #10661: its last cases drive the real `loom-daemon session-exec host` against a fake docker to pin the SESSION_MOUNT_STALE announcement and the dispatch lock (`lss_expect_lock`). Wired in the "Native Port Suites" job next to test-spawn-codex-session-exec.sh, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it FAILS rather than SKIPs without a binary.
test-spawn-claude-ambient-scrub.sh  Same constraint as test-spawn-claude.sh above (#10413): it drives spawn-claude.sh's pool-selection branch against a real `loom-daemon tokens select` (plus the ambient-credential scrub that branch now performs), so it needs a built binary. Wired in the "Native Port Suites" job; resolves the binary launcher-style (CARGO_TARGET_DIR then target/{release,debug}) and FAILS rather than SKIPs without one.
test-spawn-codex-session-exec.sh  Needs a built loom-daemon since #9979: the session-container boundary (sandbox off only in a container whose label AND HostConfig are hardened) is decided by `loom-daemon session-exec posture`, and this suite drives the real binary through spawn-codex.sh with a JSON-answering fake docker. Wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it FAILS rather than SKIPs without a binary.

test-loom-dispatcher.sh  Wired through scripts/test-installer.sh in Installer Integration Tests; requires the Rust spawn-worker dispatcher (#8362).
test-spawn-generic.sh  Wired in native-port equivalence job; requires the Rust spawn-worker dispatcher (#8362).
test-spawn-generic-launch.sh  Wired in the "Native Port Suites" job alongside test-spawn-generic.sh; spawn-generic-launch.sh resolves a tier-3 runtime's launch shape via `loom-daemon runtime-launch-env` (#8671), so this suite needs the binary that job builds. It pins one via loom_test_require_daemon_bin and FAILS rather than skips without it.

test-sweep-checkpoint.sh  Native Rust checkpoint port (#8525); retained equivalence suite runs in Native Port Suites with a built binary.
test-reconcile-stack.sh  Needs a built loom-daemon since #8583 moved reconcile-stack.sh's planning/execution (fetch + pin the remote default-branch tip, worktree routing, parent-ref/ancestry resolution, the rebase itself) into `loom-daemon reconcile-stack`; wired in the "Native Port Suites" job, which downloads the shared build first. Its scenarios predate the port apart from J/K and the two rebase-target assertions the fix changed, so it is the equivalence evidence and FAILS rather than skips without a binary.
test-worktree-json-purity.sh  Needs a built loom-daemon since #8195 slice 7 moved worktree.sh's `_handle_feature_branch_in_main_worktree` into `loom-daemon worktree-branch-conflict`; wired in the "Native Port Suites" job, which downloads the shared build first. Test 3 (auto-recovery retry path) asserts the create path SUCCEEDS after auto-switching a clean main workspace back to the default branch, which requires the recovery to actually run — unlike slice 4/5's best-effort links/cleanup — so it FAILS rather than skips without a binary.
test-sweep-lease-renew-fd-hygiene.sh  Needs a built loom-daemon since #10203 moved the lease renewer's inherited-fd sanitising into `loom-daemon lease renewer sanitize-exec`; wired in the "Native Port Suites" job (the daemon-built job, next to test-worktree-json-purity.sh), which downloads the shared build first. It pins the built daemon, so it FAILS rather than skips without a binary.
test-worktree-stale-closed-branch.sh  Needs a built loom-daemon since #9083's closed-unmerged arm of worktree.sh's branch-resolution contract is `loom-daemon worktree-closed-pr-branch` — a Rust-only addition with no shell twin (the file it is dispatched from is `contract`-category, so its growth has no override); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it FAILS rather than skips without a binary.
test-fleet-send.sh  Needs a built loom-daemon since #9517 (the suite pins the `fleet-send` subcommand); wired in the "Native Port Suites" job, which downloads the shared build first.
defaults/hooks/tests/test-guard-mcp-tools.sh  Needs a built loom-daemon since #9108's `mcp__loom__.*` PreToolUse guard decision is `loom-daemon guard-mcp-tools` (Rust, native from the start per the shell-language policy — no shell twin to port); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it FAILS rather than skips without a binary — the guard's whole point is being ON THE PATH, and a silently-skipped suite would report green having asserted nothing about that.
test-worktree-base-override.sh  Needs a built loom-daemon since #8195 slice 13 made worktree.sh's `--base` stacked-PR resolution `loom-daemon worktree-base` (without one `--base` refuses, exit 2). Its assertions are unchanged and are the end-to-end wiring evidence for that port, so it FAILS rather than skips without a binary.
test-check-branch-name.sh  Needs a built loom-daemon since #8195 slice 13: its worktree.sh `--base <payload-ref>` refusal cases (#9106) now run through `loom-daemon worktree-base`, whose refname guard is the one they pin. Assertions unchanged; it FAILS rather than skips without a binary.
test-worktree-stale-merged-branch.sh  Needs a built loom-daemon since #8195 slice 14 made worktree.sh's LOCAL-branch reuse arm `loom-daemon worktree-branch-reuse`: Tests 4-5's #8280 already-landed refusal (and its fail-open-on-`unknown` sibling) are that subcommand now. Its 10 assertions are unchanged — they are the equivalence evidence for that port — and without a binary the refusal does not run at all, so it FAILS rather than skips. Tests 1-3 (the REMOTE arm, still lib/worktree-forge-pr-check.sh) are untouched by the slice.
test-worktree-remote-branch-tracking.sh  Needs a built loom-daemon since #8195 slice 14: Tests 3-4 assert the local-reuse arm's "already exists - reusing it" line (their own proof of WHICH arm ran) and the #8280 divergence warning, both of which are `loom-daemon worktree-branch-reuse` now. Assertions unchanged; without a binary the arm prints nothing, so it FAILS rather than skips. Tests 1-2 (the REMOTE arm) are untouched by the slice.
test-merge-pr-wait-for-checks-empty-settle.sh  Needs a built loom-daemon since #8191 slice routed merge-pr.sh's `_wait_for_checks_then_sync_merge` failing/pending/total_count read through `loom-daemon merge-pr check-runs-rollup`; wired in the "Native Port Suites" job, which downloads the shared build first. It pins the binary via `loom_test_require_daemon_bin --self-only`, so it FAILS rather than skips without one.
test-forge-check-runs-pagination.sh  Needs a built loom-daemon for the same reason as its sibling above: Part 3 extracts and runs the REAL `_wait_for_checks_then_sync_merge`, which since the #8191 slice reads its failing/pending/total_count via `loom-daemon merge-pr check-runs-rollup`; wired in the "Native Port Suites" job, which downloads the shared build first. It pins the binary via `loom_test_require_daemon_bin --self-only`, so it FAILS rather than skips without one. Parts 1/2/4/5 (forge-helpers.sh pagination, no daemon involved) move with it rather than splitting the suite.
test-merge-pr-unstable-fallback.sh  Needs a built loom-daemon since #8191's check-runs-rollup slice: its #3664 pending-vs-failing classification assertions drive the real `loom-daemon merge-pr check-runs-rollup` instead of mirroring the retired jq filters; wired in the "Native Port Suites" job, which downloads the shared build first. It pins the binary via `loom_test_require_daemon_bin`, so it FAILS rather than skips without one.
test-merge-pr-help.sh  Needs a built loom-daemon since #8191's usage slice: merge-pr.sh's --help text is `loom-daemon merge-pr usage`, and without the verb --help degrades to a one-line usage. Wired in the "Native Port Suites" job, which downloads the shared build first. It pins the binary via `loom_test_require_daemon_bin --self-only`, so it FAILS rather than skips without one; its assertions are unchanged.
test-merge-pr-merge-method.sh  Needs a built loom-daemon since #8191's usage slice: Test 1 reads merge-pr.sh --help, whose text is `loom-daemon merge-pr usage`. Wired in the "Native Port Suites" job, which downloads the shared build first. It pins the binary via `loom_test_require_daemon_bin --self-only` (only LOOM_DAEMON_SELF_BIN, so Tests 5/6's PATH stub and LOOM_DAEMON_BIN keep their meaning), so it FAILS rather than skips without one; its assertions are unchanged.
test-provision-codex-hooks.sh  Needs a built loom-daemon since #9390 made `provision-codex-hooks.sh verify` a stub over `loom-daemon codex-hooks verify`; wired in the "Native Port Suites" job, which downloads the shared build first. Its install/remove half is still shell, but the readiness assertions are the equivalence proof for the port, so it calls `loom_test_require_daemon_bin` and must FAIL, never SKIP, without a binary.
test-spawn-codex-guarded.sh  Needs a built loom-daemon (the hook readiness behind spawn-codex.sh is `loom-daemon codex-hooks verify`, #9390); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
test-spawn-codex-sealed.sh  Needs a built loom-daemon (`loom-daemon codex-hooks verify --allow-sealed` and `session-exec posture`, #10102); wired in the "Native Port Suites" job, which downloads the shared build first. It calls `loom_test_require_daemon_bin`, so it must FAIL, never SKIP, without a binary.
