d75ee1cca5
Two cases in WorktreeSessionManagerTest, covering the gap that let the NPE ship (313 tests, was 311). 1. worktreeAcquireWithNoRequestedOrCallerCwdStillResolvesANonNullRepoRoot — the null/null case a plain REST spawn produces. 2. worktreeAcquireHonoursTheProfileConfiguredCwd — the quieter second bug on the same line, where a pinned per-profile cwd: was ignored entirely. Both assert on the cwd RECORDED by FakeWorktrees rather than expecting a throw. That is deliberate: FakeWorktrees.repoRoot only records its argument and returns a canned root, so a null passes through the fake harmlessly while the real GitWorktrees runs `git -C null` and NPEs. The fake being more permissive than the real seam is exactly why 311 tests stayed green over a broken feature — asserting "an exception was raised" would be untestable here and would give false confidence. Verified as genuine regressions, not tautologies: with the pre-CB-507 expression restored both fail, with the messages they were written to give (expected: not <null>, and expected </pinned/dir> but was <null>). Restored after. Drafted by an opencode-free worker over the bridge in an isolated worktree (branch worker/cb-507-regression-test-11591f-4). Its test 1 was correct as written. Test 2 was wrong and went red: it passed "/pinned/dir" as the 4th constructor argument, which is configDir, not cwd (the 11th, after mcpUrl), so cwd stayed null and the chain fell through to the daemon cwd. Corrected on integration, along with removing two unused locals and adding the rationale comments.