SIGN IN SIGN UP

test(secret): decide each corpus command once per default mode in the invariant block

Why:
- The invariants over the corpus and seeded fuzz recomputed the same
  default-config verdict about 14 times per command; the block took
  ~18s of the ~150s Windows suite (Windows CI runs 37111903728,
  37111907907, 37111912156), and Windows source checks are the CI
  critical path.

What:
- settleOnce decides a command once per mode, lazily, and the
  invariant tests share it; no assertion changes.
- Each comparison keeps one freshly decided side: "decides the same way
  twice" and the allow-home invariant compare a fresh decision with the
  shared one, so neither becomes a self-comparison.

Validation:
- secret-protection.test.ts x3: invariant block 3.56-3.67s -> 1.53-1.55s,
  file 4.34-4.46s -> 2.32-2.41s (57 pass).
- The four cache-reading tests pass alone (-t), with an empty cache.
- bun run check passed (3508 pass, 4 skip, 0 fail).

LOC:
  src/     +0 / -0 = net +0
  tests/  +16 / -8 = net +8
  *.md     +0 / -0 = net +0
  Total   +16 / -8 = net +8
K
kenryu42 committed
2573184344bbf4fcb85705d0ddb20e4ff6aa22bc
Parent: 1265092