ac790e4cce
seedTrustDialog targets ~/.claude.json when a profile sets no configDir. Two IDE-overlay fixtures built a worktree-shaped @TempDir, which opens the #149 isProvisionedWorktree gate, and left configDir null — so every test run added two project entries to the operator's real file. 116 had accumulated, none of them still existing on disk, and 32 of those came from current code. The #149 gate only closed the opposite case: a fixture with cwd unset falling back to user.dir. A fixture that builds a worktree on purpose walks straight through it. - ideProfile/ideProfileModule now take configDir first and mandatory, so each fixture states where the trust seed goes. - noFixtureSeededTheDefaultClaudeJson snapshots the temp-dir project keys in @BeforeAll and fails in @AfterAll on any key this class added. Differential, not absolute: an absolute check would fail on every host still carrying the historical entries, and such a check gets deleted rather than fixed. Not done: a blanket -Duser.home redirect in surefire. EnvAllowListScrubTest tests the credential scrub against the operator's real login chain and guards with assumeTrue($HOME/.zshrc exists), so the redirect would silently skip two security tests. Proof: with the bug put back on one fixture the guard fails and names the path; reverted and confirmed identical with diff -q. A full suite run under a fake home now creates no .claude.json at all. mvn clean install: 0 compile errors, 1255 tests, BUILD SUCCESS.