# Node host retirement and test crosswalk

The Node host was retired on 2026-10-08. The native MoonBit executable now owns
CLI parsing and actions, MCP stdio, HTTP service, provider transport, tool
execution, durable storage, approvals, and recovery. The browser and service
worker ship as generated MoonBit JavaScript. Node remains in build/check/test
scripts only; it is not a product runtime.

This crosswalk records which behavior moved to the product implementation and
where verification lives. The previous tests instantiated Node-specific
facades, injected JavaScript promises, and asserted event-loop callback order.
Those are not equivalent to native tests and are not claimed as such.

| Retired Node suite | Native/product coverage retained | Deliberate difference or uncovered case |
| --- | --- | --- |
| `tests/host/cli.test.mjs` | `runtime/cli_options_wbtest.mbt` covers aliases, value parsing, rejection of missing/unknown/extra arguments, approval policy, pruning bounds, bounded Session v4 import, and noninteractive approval cancellation. `runtime/mcp_stdio_wbtest.mbt` covers UTF-8, CRLF, 1 MiB framing, parse errors, and recovery. `runtime/runtime_wbtest.mbt` covers MCP checkpoint/reopen. `scripts/native-verify.mbtx` builds and invokes the native CLI. | Native CLI tests exercise MoonBit parser/actions and the no-Node verifier checks the executable entry point; the old Node `process.execPath`/environment injection harness is retired. |
| `tests/host/persistence.test.mjs` | `runtime/safety_store_fixture_wbtest.mbt` checks private versioned envelopes, exclusive writer lock, clean reopen, stale local lock recovery, remote-owner refusal, and stale snapshot conflict. `runtime/safety_fs_fixture_wbtest.mbt` checks symlink rejection, protected paths, atomic writes, version conflicts, and a swapped-ancestor race. Engine restore tests cover forged snapshots and interruption without replay. | Native lock/process and filesystem primitives are exercised on the native test target. Platform-specific syscall races are not represented as JavaScript filesystem mocks. |
| `tests/host/provider.test.mjs` | `provider/` tests provider request/response codecs and stream consistency; `runtime/provider_selection_wbtest.mbt`, `runtime/provider_http_wbtest.mbt`, and `runtime/utf8_stream_wbtest.mbt` cover safe provider selection, real loopback HTTP SSE fixtures, MIME/completion validation, deadlines, bounded bodies, split UTF-8, and malformed streams. | The old injectable `fetchImpl` cleanup/timer tests are not reproduced callback-for-callback. Native tests exercise the actual HTTP client and MoonBit decoder instead. |
| `tests/host/runtime.test.mjs` | `engine/engine_wbtest.mbt` covers approval barriers, effect correlation, bounded stream projection, cancellation, restore/no-replay, and capacity refusal. `runtime/runtime_wbtest.mbt`, `runtime/runtime_carrier_wbtest.mbt`, `runtime/scheduler_wbtest.mbt`, and `runtime/safety_tools_fixture_wbtest.mbt` cover native checkpoint/receipt lifecycle, background MCP dispatch and cancel fencing, scheduling, workspace execution, and reload. | The prior module-global facade ownership tests do not apply after removing that host boundary. Native tests cover separate native runtime/store instances and durable receipt ownership. |
| `tests/host/server.test.mjs` | `runtime/service_auth_wbtest.mbt`, `runtime/service_metadata_wbtest.mbt`, `runtime/service_restart_wbtest.mbt`, and `runtime/service_signal_wbtest.mbt` cover request identity, safe metadata, static asset allowlisting, restart, and shutdown. `web/browser-smoke.mjs` runs the compiled UI against a real native demo service, with strict CSP and actual v1 commands. | Node HTTP mock-server and legacy API fallback cases are removed with the legacy service. The native browser smoke exercises the supported v1 surface. |
| `tests/host/tools.test.mjs` | `runtime/safety_tools_fixture_wbtest.mbt` and `runtime/safety_fs_fixture_wbtest.mbt` exercise native read/write/edit/glob/grep/bash, bounds, protected data, symlinks, and cancellation/timeout behavior. | Native glob intentionally supports a documented subset. Regex grep is disabled on macOS when a hard worker-memory limit cannot be enforced. These limits are documented in `docs/native-runtime.md`. |
| `tests/host/workspace-metadata.test.mjs` | `runtime/service_metadata_wbtest.mbt` covers plain workspaces, nested Git worktrees, provider/model redaction, and static assets. | Metadata is now derived by the native service at request time; no Node helper API remains. |
| `tests/integration/live-stream.test.mjs` | `engine/engine_wbtest.mbt`, `runtime/runtime_wbtest.mbt`, `runtime/runtime_carrier_wbtest.mbt`, `runtime/provider_http_wbtest.mbt`, and `runtime/utf8_stream_wbtest.mbt` cover stream identity, partial/final consistency, Unicode segmentation, cancellation, real SSE parsing, idle/total deadlines, and recovery. The carrier fixture also proves MCP send acknowledgement, `session_get` / cancel responsiveness while a provider is held open, late-tool fencing, and a new send after cancellation. The browser smoke observes the native live UI path. | JavaScript promise-injection tests for every callback interleaving are not retained verbatim. Engine invariants and native HTTP behavior are tested at their owning boundaries. |
| `tests/integration/provider-retry.test.mjs` | `engine/retry_wbtest.mbt` verifies eligibility, event ordering, policy identity, budgets, cancellation, and restore/no-replay. `runtime/runtime_carrier_wbtest.mbt` runs the native runtime against a keyless loopback OpenAI Chat Completions server: HTTP 503 with `Retry-After`, byte-identical retry request, one approved real workspace write, a follow-up provider completion, durable retry/tool events, and close/reopen without another request. `runtime/provider_http_wbtest.mbt` covers HTTP stream parsing and timeout behavior; CLI retry bounds are in `runtime/cli_options_wbtest.mbt`. | The old suite's exhaustive injected save-failure and every backoff/shutdown callback interleaving are not reproduced. The new carrier fixture verifies one actual transient HTTP retry through checkpoint, approval, tool, and reopen, not all storage failure points. |
| `tests/integration/session-v4-import.test.mjs` | `engine/session_v4_wbtest.mbt` tests inert/read-only import, atomic rejection, projection, image references, replacement, and retry correlation. `runtime/cli_options_wbtest.mbt` imports and reopens all 25 pinned upstream catalog JSONL fixtures through the native runtime with zero effects. The two adapted retry fixtures remain separately covered by engine tests. | The removed Node integration assertions that mutated its host facade are not retained; archive validation and durable native reopen are covered directly by MoonBit. |
| `tests/integration/upstream-parallel-tools.test.mjs` | `engine/engine_wbtest.mbt` and `runtime/scheduler_wbtest.mbt` cover bounded parallel reads, call-order results, barriers, and cancellation. The browser acceptance fixture verifies the native UI’s send/approval/prune/fork path. | The old local HTTP fixture’s exact captured provider request transcript and response count are not retained as an identical integration test. |
| `tests/integration/upstream-replay.test.mjs` | Native demo and `web/browser-smoke.mjs` cover a keyless real tool turn, approval, durable native commands, fork, pruning, and reopen. Engine provider/tool correlation tests exercise the upstream-derived turn fixture. `runtime/runtime_carrier_wbtest.mbt` additionally proves the native carrier can receive a real loopback HTTP provider tool call, wait for explicit approval, execute one write, send the result in a follow-up request, and reopen the completed session. | The retired full upstream Messages API transcript is not replayed byte-for-byte; the carrier regression uses a keyless OpenAI Chat Completions fixture. It does not contact an external provider or use an API key. |

The Node host source and its host-dependent test files were removed rather than
left as a second, unsupported product path. Upstream fixtures and provenance
files remain under `tests/fixtures/`. Historical test results in
[`verification.md`](verification.md) describe the dated Node-host baseline and
are retained as historical records; current verification is appended there
separately.
