merge origin/main into feat/wf5-securestorage

Brings MOSAIC_GIT_IDENTITY (per-seat git authorship) onto the delivery
branch, which had none of it. The branch carried W-F7's FLEET_SEAT seam in
the same launcher file; the two auto-merged cleanly.

Three single-hunk conflicts resolved:
- pr-merge.sh: kept branch policy allowing main OR next (next is the
  release stream).
- test-ci-queue-wait-tristate.sh: kept the branch's 4 added merge-readiness
  assertions; merge base and main both had zero, so nothing of main's is
  reverted.
- package.json test:framework-shell: union of both enumerations, 50 entries,
  no test dropped from either side. Picks up main's test-start-agent-session.sh
  and test-fleet-units.sh, which are the guards for the identity key.
This commit is contained in:
Jason Woltje
2026-08-14 23:15:56 -05:00
107 changed files with 7987 additions and 209 deletions
@@ -153,6 +153,38 @@ warn_if_symlink_tree_present() {
echo "[mosaic-doctor] Mosaic home: $MOSAIC_HOME"
# Compare the framework tools that this CLI/package ships with the deployed
# ~/.config copy that direct wrappers and systemd units actually execute. Doctor
# is the right boundary: observational, operator-invoked, and already designed
# to report drift without mutating live tooling or restarting active seats.
framework_drift_checker="$(cd -- "$(dirname -- "$0")/../quality/scripts" && pwd)/framework-drift-check.py"
if [[ -f "$framework_drift_checker" ]]; then
echo "[mosaic-doctor] Checking installed framework-tool drift..."
drift_timeout="${MOSAIC_DOCTOR_DRIFT_TIMEOUT_SEC:-15}"
if ! [[ "$drift_timeout" =~ ^[1-9][0-9]*$ ]]; then
warn "Invalid MOSAIC_DOCTOR_DRIFT_TIMEOUT_SEC='$drift_timeout' (expected positive integer); using 15s"
drift_timeout=15
fi
if command -v timeout >/dev/null 2>&1; then
set +e
timeout -s TERM -k 2 "${drift_timeout}s" \
python3 "$framework_drift_checker" --installed-root "$MOSAIC_HOME/tools"
drift_rc=$?
set -e
if [[ "$drift_rc" -eq 0 ]]; then
pass "Installed framework tools match shipped source"
elif [[ "$drift_rc" -eq 124 || "$drift_rc" -eq 137 || "$drift_rc" -eq 143 ]]; then
warn "CANNOT_ASSERT framework drift checker timed out after ${drift_timeout}s; continuing remaining doctor checks"
else
warn "Installed framework-tool drift detected (checker exit $drift_rc; no files changed)"
fi
else
warn "CANNOT_ASSERT timeout utility unavailable; refusing unbounded framework drift check and continuing remaining doctor checks"
fi
else
warn "Framework drift checker is absent from the shipped tools tree"
fi
# Canonical Mosaic checks
expect_file "$MOSAIC_HOME/STANDARDS.md"
expect_file "$MOSAIC_HOME/USER.md"