fix(#1264): bootstrap fleet identity without a TTY
ci/woodpecker/pr/ci Pipeline failed

This commit is contained in:
goals
2026-08-16 17:37:32 -05:00
parent 476db12b92
commit 43fa047787
21 changed files with 1255 additions and 11 deletions
@@ -0,0 +1,185 @@
# #1264 Unattended Fleet First-Start Verification
> Status: **IN PROGRESS** | Executor: goals | Date: 2026-08-16 | Target: isolated local fixtures only
## Objective
Verify that a named fleet seat launched through a systemd-equivalent, no-TTY environment on a clean
host reaches its runtime boundary without an interactive Mosaic identity wizard. Preserve standalone
wizard behavior and canonical roster ownership of exact seat identity.
## Source evidence accepted for local verification
Daphne's canary investigation was read from jarvis-brain commit
`6c0b6fc70ae6a179a1b7ff9dedfc54e9adccd19a`, report
`docs/reports/2026-08-16_sbx-canary-greenfield-e2e.md`. It measured:
```text
systemd -> start-agent-session.sh -> mosaic yolo pi (PID 3726)
-> child mosaic wizard (PID 3762)
```
The canary pane remains preserved and was not accessed. Product behavior is independently tested here
with temporary roots and fake runtime executables; no canary or installed-host inference is scored as
local PASS evidence.
## Controls
- Worktree base: `origin/next@476db12b92971634b67fd2057b7577ee5894e449`.
- `DATABASE_URL` remains unset.
- No real credential, token, provider, VM, installed Mosaic tree, unit, timer, PATH profile, or live
tmux session is read or mutated.
- Tiny's concurrent runtime-preflight and `start-agent-session.sh` PATH work are out of scope.
- Held PR #1213 is not a dependency.
## Requirements-to-evidence map
| Acceptance criterion | Method | Evidence |
| ---------------------------------------------------------------------- | ----------------------------------------------------- | ------------------------------ |
| No-TTY fleet first start avoids wizard and reaches runtime | Real built-CLI subprocess with piped stdin | Focused GREEN, CLI test 1 |
| Missing top-level identity files are initialized from shipped defaults | Exact-byte and `0600` assertions | Focused GREEN, CLI tests 1/11 |
| Exact seat identity remains roster-owned | Captured argv plus unknown/padded/blank-name refusals | Focused GREEN, CLI tests 1/69 |
| Existing operator identity is never overwritten | Custom bytes/mode with defaults removed | Focused GREEN, CLI tests 2/3 |
| Concurrent/repeated first start is safe | Four parallel CLIs plus repeated launch | Focused GREEN, CLI tests 2/11 |
| Missing/unsafe defaults fail without prompting | Missing, symlink, oversized, and installed-link tests | Focused GREEN, unit/CLI tests |
| Standalone launch retains wizard | Same real CLI without fleet identity | Focused GREEN, CLI test 10 |
## Command evidence
### Worktree helper refusal and sanctioned fallback
Command:
```bash
~/bin/mosaic-worktree.sh new fix/1264-fleet-unattended-first-start --from origin/next
```
Exit: `1`. Stderr was retained; the helper refused because the derived worktree path was under
`/var/home/jason.woltje`, while `/src` does not exist on this host. Fred explicitly authorized the
plain-git fallback and path used for this task.
Command:
```bash
git -C /var/home/jason.woltje/src/stack worktree add \
/var/home/jason.woltje/agent-work/1264-unattended-first-start \
-b fix/1264-fleet-unattended-first-start origin/next
```
Exit: `0`; HEAD `476db12b92971634b67fd2057b7577ee5894e449`.
### RED
Production source remained unchanged after adding the reproducer. The built CLI represented
`origin/next@476db12` behavior.
Command:
```bash
env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \
src/commands/launch-first-start.spec.ts
```
Exit: `1`.
```text
Test Files 1 failed (1)
Tests 1 failed (1)
[mosaic] SOUL.md not found. Running setup wizard...
◆ What would you like to do?
[mosaic] Setup failed. Run: mosaic wizard
AssertionError: expected 1 to be +0
```
The fixture used piped stdin (not a TTY), a temporary `HOME`/`MOSAIC_HOME`, shipped default bytes,
a canonical one-seat roster, a fake `pi`, and a fake lease-runtime boundary. The wizard rendered and
the runtime-boundary capture was never created. Complete combined stdout/stderr was retained at
`/tmp/1264-red.out` during execution.
### GREEN and baseline
After the production change, the original one-test command exited `0` with `1/1` passing. The final
focused command was:
```bash
env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \
src/commands/fleet-first-start-identity.spec.ts \
src/commands/launch-first-start.spec.ts \
src/commands/launch.spec.ts \
src/commands/compose-contract.spec.ts \
src/config/file-adapter.test.ts \
src/cli-smoke.spec.ts
```
Exit: `0`; `6/6` files and `119/119` tests passed. The 11 production-kind CLI tests cover no-TTY
launch, captured exact roster name/class, byte-equal `0600` seeds, no-clobber/idempotence, partial
seed, missing/symlink defaults, unknown/padded/blank ambient members, standalone interactive control,
and four concurrent first starts with no temporary residue. Nine direct filesystem tests cover
successful/no-clobber hard-link publication, unexpected link errors, source prevalidation, existing
operator contracts, idempotence, symlink sources/destinations, and oversized input.
Full package Vitest:
```text
Test Files 88 passed (88)
Tests 1568 passed (1568)
Exit 0
```
New helper coverage:
```text
Statements 100% | Branches 93.33% | Functions 100% | Lines 100%
9/9 tests passed; coverage command exit 0
```
Baseline commands:
```text
pnpm preflight exit 0
pnpm typecheck 45/45 tasks, exit 0
pnpm lint 25/25 tasks, exit 0
pnpm build 25/25 tasks, exit 0
pnpm format:check exit 0
pnpm --filter @mosaicstack/mosaic build exit 0
bash framework/tools/fleet/test-start-agent-session.sh
exit 0; retained expected fixture LD_PRELOAD warning
bash framework/tools/quality/scripts/test-install-migration.sh
21 passed, 0 failed, exit 0
bash framework/tools/_scripts/test-mosaic-init-rce.sh
PASS, exit 0
git diff --check exit 0
```
The aggregate `test:framework-shell` command exited `1` at `invariant_r_unittest.py`: `5/6` tests
passed and the remaining test refused the operator-global Pi drift from measured `0.84.1` to
installed `0.84.2`. This is retained as an environment/version-coupling failure, not scored as a
#1264 code failure and not retried. The aggregate stopped there; later aggregate stages are
**UNTESTED** except for the three targeted shell suites listed above.
Root `pnpm test` is **UNTESTED** because it can execute the prohibited local PostgreSQL-dependent
gateway isolation path. No PostgreSQL service, connection, migration, or initialization was used.
CI is **UNTESTED — pending PR**.
## Explicitly untested
- Canary VM remediation or restart: **UNTESTED and prohibited for this task**.
- Real Pi authentication/provider prompt and task execution: **UNTESTED**.
- PR #1213 composition layer: **UNTESTED and not required**.
- Deployment/published npm package behavior: **UNTESTED until CI/release; deployment is not this PR's scope**.
## Review and residual risks
Initial independent Codex code review returned `request-changes` with one should-fix: a padded
`MOSAIC_AGENT_NAME` could be trimmed for pre-seed validation and later rejected in composition,
leaving seeds behind. The implementation now rejects blank or padded values before roster lookup or
writes; three no-side-effect regression cases pass. Codex re-review approved the remediated delta
with no findings (`confidence=0.86`). Its read-only sandbox could not execute Vitest because Vite
needed a temporary config artifact; executor-owned focused/full results above are the test evidence.
Final Codex security review found no confirmed vulnerabilities (`risk=none`, confidence `0.91`).
Formal PR review by a reviewer other than goals/Fred and CI remain pending.
Real Pi authentication/provider prompt and task execution remain unmeasured. The local gate proves
that Mosaic crosses its identity boundary and reaches the fake lease-runtime boundary; it does not
claim provider readiness or deployment.