This commit is contained in:
@@ -12,11 +12,13 @@ Use the canonical guide, API contract, source, and tests to determine current be
|
||||
- [Issue #756 documentation checklist](documentation/756-discord-plugin-checklist.md) — historical completion checklist for the official Discord plugin workstream.
|
||||
- [Framework consistency audit — 2026-02-17](documentation/AUDIT-2026-02-17-framework-consistency.md) — historical framework consistency and remediation snapshot.
|
||||
- [Compaction-refresh #830 checklist](compaction-refresh/830-documentation-checklist.md) — historical incomplete-at-snapshot documentation checklist.
|
||||
- [Issue #1264 documentation checklist](documentation/1264-documentation-checklist.md) — current in-repo user/admin/developer/report coverage and review gate.
|
||||
|
||||
## Code-review evidence
|
||||
|
||||
- [Issue #756 independent code review](code-review/756-code-review.md) — historical exact-scope review of the official Discord plugin workstream.
|
||||
- [Gateway security-hardening code review — 2026-03-13](code-review/gateway-security-20260313.md) — historical no-blocker review snapshot.
|
||||
- [Issue #1264 independent code and security review](code-review/1264-code-review.md) — initial finding, remediation, clean re-review, and remaining formal PR-review gate.
|
||||
|
||||
## Security evidence
|
||||
|
||||
@@ -26,6 +28,7 @@ Use the canonical guide, API contract, source, and tests to determine current be
|
||||
|
||||
- [P8-003 performance optimization report](qa/p8-003-performance-optimization.md) — historical implementation evidence; not a current SLO or production benchmark.
|
||||
- [Gateway security-hardening QA report — 2026-03-13](qa/gateway-security-20260313.md) — historical test report with its original live-smoke-test limitation.
|
||||
- [Issue #1264 unattended fleet first-start verification](qa/2026-08-16-1264-unattended-first-start.md) — RED/GREEN no-TTY CLI evidence, baseline gates, and explicit real-provider limitation.
|
||||
|
||||
## Native Kanban/SOT evidence
|
||||
|
||||
|
||||
@@ -0,0 +1,59 @@
|
||||
# Issue #1264 Independent Code and Security Review
|
||||
|
||||
> Scope: uncommitted delivery delta for `fix/1264-fleet-unattended-first-start` against
|
||||
> `origin/next@476db12b92971634b67fd2057b7577ee5894e449` | Reviewer: Codex CLI via Mosaic review tools
|
||||
|
||||
## Initial code review
|
||||
|
||||
Command:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/codex/codex-code-review.sh --uncommitted \
|
||||
-o /tmp/1264-codex-code-review.json
|
||||
```
|
||||
|
||||
Result: `request-changes`, confidence `0.93`, `20` files reviewed, `0` blockers, `1` should-fix.
|
||||
|
||||
Finding: `checkSoul()` trimmed `MOSAIC_AGENT_NAME` for pre-seed roster resolution while later
|
||||
composition used the original value. A padded exact name could therefore seed identity files and
|
||||
then fail composition.
|
||||
|
||||
Remediation:
|
||||
|
||||
- treat any present blank or surrounding-whitespace value as an invalid fleet launch;
|
||||
- reject it before roster lookup or identity writes; and
|
||||
- add three real-CLI no-side-effect regressions for leading padding, trailing padding, and empty
|
||||
values.
|
||||
|
||||
## Code re-review
|
||||
|
||||
Command:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/codex/codex-code-review.sh --uncommitted \
|
||||
-o /tmp/1264-codex-code-rereview.json
|
||||
```
|
||||
|
||||
Result: `approve`, confidence `0.86`, `15` files reviewed, no findings. The review sandbox could run
|
||||
package typecheck but could not run Vitest because its checkout was read-only and Vite attempted to
|
||||
create a timestamped config artifact (`EROFS`). This is not scored as test evidence; the executor's
|
||||
writable worktree independently passed the focused and full suites recorded in the QA report.
|
||||
|
||||
## Security review
|
||||
|
||||
Final command:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/codex/codex-security-review.sh --uncommitted \
|
||||
-o /tmp/1264-codex-security-rereview.json
|
||||
```
|
||||
|
||||
Result: risk `none`, confidence `0.91`, `20` files reviewed, `0` critical/high/medium/low findings.
|
||||
The review specifically confirmed roster validation before seeding, bounded no-symlink reads,
|
||||
no-clobber publication, unsafe/padded identity refusal, and fail-closed behavior before runtime.
|
||||
|
||||
## Independent PR review gate
|
||||
|
||||
Automated review is complete. The PR still requires a formal reviewer who is neither the implementation
|
||||
seat nor Fred, per the assignment. That review and CI status are recorded in the QA report when
|
||||
available.
|
||||
@@ -0,0 +1,27 @@
|
||||
# #1264 Documentation Completion Checklist
|
||||
|
||||
## Required artifacts
|
||||
|
||||
- [x] `docs/PRD.md` updated with `FCM-REQ-12` and `AC-FCM-10`.
|
||||
- [x] User workflow documents unattended fleet first start and separate prerequisites.
|
||||
- [x] Administrator operations page documents source/destination ownership, failure handling, and verification.
|
||||
- [x] Developer architecture page documents control flow, identity authority, concurrency, and non-goals.
|
||||
- [x] `docs/SITEMAP.md` and book indexes updated.
|
||||
- [x] QA evidence is under `docs/reports/qa/`; working notes are under `docs/scratchpads/`.
|
||||
- [x] Framework defaults README reflects fleet-versus-standalone behavior.
|
||||
|
||||
## API coverage
|
||||
|
||||
- [x] No HTTP/API endpoint or DTO changed; OpenAPI and endpoint indexes are not applicable.
|
||||
|
||||
## Structural standards
|
||||
|
||||
- [x] User, administrator, developer, report, and sitemap indexes link the new pages.
|
||||
- [x] No noncanonical file was added at the `docs/` root.
|
||||
- [x] Canonical documentation remains in-repo; no external publication was requested or performed.
|
||||
|
||||
## Review gate
|
||||
|
||||
- [x] Independent automated code/security review completed on the final uncommitted delta.
|
||||
- [x] Padded-name finding remediated and automated re-review approved with no findings.
|
||||
- [ ] Formal PR review by a reviewer other than goals/Fred completed on the exact pushed head.
|
||||
@@ -0,0 +1,185 @@
|
||||
# #1264 Unattended Fleet First-Start Verification
|
||||
|
||||
> Status: **IN PROGRESS** | Executor: goals | Date: 2026-08-16 | Target: isolated local fixtures only
|
||||
|
||||
## Objective
|
||||
|
||||
Verify that a named fleet seat launched through a systemd-equivalent, no-TTY environment on a clean
|
||||
host reaches its runtime boundary without an interactive Mosaic identity wizard. Preserve standalone
|
||||
wizard behavior and canonical roster ownership of exact seat identity.
|
||||
|
||||
## Source evidence accepted for local verification
|
||||
|
||||
Daphne's canary investigation was read from jarvis-brain commit
|
||||
`6c0b6fc70ae6a179a1b7ff9dedfc54e9adccd19a`, report
|
||||
`docs/reports/2026-08-16_sbx-canary-greenfield-e2e.md`. It measured:
|
||||
|
||||
```text
|
||||
systemd -> start-agent-session.sh -> mosaic yolo pi (PID 3726)
|
||||
-> child mosaic wizard (PID 3762)
|
||||
```
|
||||
|
||||
The canary pane remains preserved and was not accessed. Product behavior is independently tested here
|
||||
with temporary roots and fake runtime executables; no canary or installed-host inference is scored as
|
||||
local PASS evidence.
|
||||
|
||||
## Controls
|
||||
|
||||
- Worktree base: `origin/next@476db12b92971634b67fd2057b7577ee5894e449`.
|
||||
- `DATABASE_URL` remains unset.
|
||||
- No real credential, token, provider, VM, installed Mosaic tree, unit, timer, PATH profile, or live
|
||||
tmux session is read or mutated.
|
||||
- Tiny's concurrent runtime-preflight and `start-agent-session.sh` PATH work are out of scope.
|
||||
- Held PR #1213 is not a dependency.
|
||||
|
||||
## Requirements-to-evidence map
|
||||
|
||||
| Acceptance criterion | Method | Evidence |
|
||||
| ---------------------------------------------------------------------- | ----------------------------------------------------- | ------------------------------ |
|
||||
| No-TTY fleet first start avoids wizard and reaches runtime | Real built-CLI subprocess with piped stdin | Focused GREEN, CLI test 1 |
|
||||
| Missing top-level identity files are initialized from shipped defaults | Exact-byte and `0600` assertions | Focused GREEN, CLI tests 1/11 |
|
||||
| Exact seat identity remains roster-owned | Captured argv plus unknown/padded/blank-name refusals | Focused GREEN, CLI tests 1/6–9 |
|
||||
| Existing operator identity is never overwritten | Custom bytes/mode with defaults removed | Focused GREEN, CLI tests 2/3 |
|
||||
| Concurrent/repeated first start is safe | Four parallel CLIs plus repeated launch | Focused GREEN, CLI tests 2/11 |
|
||||
| Missing/unsafe defaults fail without prompting | Missing, symlink, oversized, and installed-link tests | Focused GREEN, unit/CLI tests |
|
||||
| Standalone launch retains wizard | Same real CLI without fleet identity | Focused GREEN, CLI test 10 |
|
||||
|
||||
## Command evidence
|
||||
|
||||
### Worktree helper refusal and sanctioned fallback
|
||||
|
||||
Command:
|
||||
|
||||
```bash
|
||||
~/bin/mosaic-worktree.sh new fix/1264-fleet-unattended-first-start --from origin/next
|
||||
```
|
||||
|
||||
Exit: `1`. Stderr was retained; the helper refused because the derived worktree path was under
|
||||
`/var/home/jason.woltje`, while `/src` does not exist on this host. Fred explicitly authorized the
|
||||
plain-git fallback and path used for this task.
|
||||
|
||||
Command:
|
||||
|
||||
```bash
|
||||
git -C /var/home/jason.woltje/src/stack worktree add \
|
||||
/var/home/jason.woltje/agent-work/1264-unattended-first-start \
|
||||
-b fix/1264-fleet-unattended-first-start origin/next
|
||||
```
|
||||
|
||||
Exit: `0`; HEAD `476db12b92971634b67fd2057b7577ee5894e449`.
|
||||
|
||||
### RED
|
||||
|
||||
Production source remained unchanged after adding the reproducer. The built CLI represented
|
||||
`origin/next@476db12` behavior.
|
||||
|
||||
Command:
|
||||
|
||||
```bash
|
||||
env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \
|
||||
src/commands/launch-first-start.spec.ts
|
||||
```
|
||||
|
||||
Exit: `1`.
|
||||
|
||||
```text
|
||||
Test Files 1 failed (1)
|
||||
Tests 1 failed (1)
|
||||
[mosaic] SOUL.md not found. Running setup wizard...
|
||||
◆ What would you like to do?
|
||||
[mosaic] Setup failed. Run: mosaic wizard
|
||||
AssertionError: expected 1 to be +0
|
||||
```
|
||||
|
||||
The fixture used piped stdin (not a TTY), a temporary `HOME`/`MOSAIC_HOME`, shipped default bytes,
|
||||
a canonical one-seat roster, a fake `pi`, and a fake lease-runtime boundary. The wizard rendered and
|
||||
the runtime-boundary capture was never created. Complete combined stdout/stderr was retained at
|
||||
`/tmp/1264-red.out` during execution.
|
||||
|
||||
### GREEN and baseline
|
||||
|
||||
After the production change, the original one-test command exited `0` with `1/1` passing. The final
|
||||
focused command was:
|
||||
|
||||
```bash
|
||||
env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \
|
||||
src/commands/fleet-first-start-identity.spec.ts \
|
||||
src/commands/launch-first-start.spec.ts \
|
||||
src/commands/launch.spec.ts \
|
||||
src/commands/compose-contract.spec.ts \
|
||||
src/config/file-adapter.test.ts \
|
||||
src/cli-smoke.spec.ts
|
||||
```
|
||||
|
||||
Exit: `0`; `6/6` files and `119/119` tests passed. The 11 production-kind CLI tests cover no-TTY
|
||||
launch, captured exact roster name/class, byte-equal `0600` seeds, no-clobber/idempotence, partial
|
||||
seed, missing/symlink defaults, unknown/padded/blank ambient members, standalone interactive control,
|
||||
and four concurrent first starts with no temporary residue. Nine direct filesystem tests cover
|
||||
successful/no-clobber hard-link publication, unexpected link errors, source prevalidation, existing
|
||||
operator contracts, idempotence, symlink sources/destinations, and oversized input.
|
||||
|
||||
Full package Vitest:
|
||||
|
||||
```text
|
||||
Test Files 88 passed (88)
|
||||
Tests 1568 passed (1568)
|
||||
Exit 0
|
||||
```
|
||||
|
||||
New helper coverage:
|
||||
|
||||
```text
|
||||
Statements 100% | Branches 93.33% | Functions 100% | Lines 100%
|
||||
9/9 tests passed; coverage command exit 0
|
||||
```
|
||||
|
||||
Baseline commands:
|
||||
|
||||
```text
|
||||
pnpm preflight exit 0
|
||||
pnpm typecheck 45/45 tasks, exit 0
|
||||
pnpm lint 25/25 tasks, exit 0
|
||||
pnpm build 25/25 tasks, exit 0
|
||||
pnpm format:check exit 0
|
||||
pnpm --filter @mosaicstack/mosaic build exit 0
|
||||
bash framework/tools/fleet/test-start-agent-session.sh
|
||||
exit 0; retained expected fixture LD_PRELOAD warning
|
||||
bash framework/tools/quality/scripts/test-install-migration.sh
|
||||
21 passed, 0 failed, exit 0
|
||||
bash framework/tools/_scripts/test-mosaic-init-rce.sh
|
||||
PASS, exit 0
|
||||
git diff --check exit 0
|
||||
```
|
||||
|
||||
The aggregate `test:framework-shell` command exited `1` at `invariant_r_unittest.py`: `5/6` tests
|
||||
passed and the remaining test refused the operator-global Pi drift from measured `0.84.1` to
|
||||
installed `0.84.2`. This is retained as an environment/version-coupling failure, not scored as a
|
||||
#1264 code failure and not retried. The aggregate stopped there; later aggregate stages are
|
||||
**UNTESTED** except for the three targeted shell suites listed above.
|
||||
|
||||
Root `pnpm test` is **UNTESTED** because it can execute the prohibited local PostgreSQL-dependent
|
||||
gateway isolation path. No PostgreSQL service, connection, migration, or initialization was used.
|
||||
CI is **UNTESTED — pending PR**.
|
||||
|
||||
## Explicitly untested
|
||||
|
||||
- Canary VM remediation or restart: **UNTESTED and prohibited for this task**.
|
||||
- Real Pi authentication/provider prompt and task execution: **UNTESTED**.
|
||||
- PR #1213 composition layer: **UNTESTED and not required**.
|
||||
- Deployment/published npm package behavior: **UNTESTED until CI/release; deployment is not this PR's scope**.
|
||||
|
||||
## Review and residual risks
|
||||
|
||||
Initial independent Codex code review returned `request-changes` with one should-fix: a padded
|
||||
`MOSAIC_AGENT_NAME` could be trimmed for pre-seed validation and later rejected in composition,
|
||||
leaving seeds behind. The implementation now rejects blank or padded values before roster lookup or
|
||||
writes; three no-side-effect regression cases pass. Codex re-review approved the remediated delta
|
||||
with no findings (`confidence=0.86`). Its read-only sandbox could not execute Vitest because Vite
|
||||
needed a temporary config artifact; executor-owned focused/full results above are the test evidence.
|
||||
|
||||
Final Codex security review found no confirmed vulnerabilities (`risk=none`, confidence `0.91`).
|
||||
Formal PR review by a reviewer other than goals/Fred and CI remain pending.
|
||||
|
||||
Real Pi authentication/provider prompt and task execution remain unmeasured. The local gate proves
|
||||
that Mosaic crosses its identity boundary and reaches the fake lease-runtime boundary; it does not
|
||||
claim provider readiness or deployment.
|
||||
Reference in New Issue
Block a user