comms: usc 20260720T012004Z

This commit is contained in:
wjarvis mos-comms
2026-07-19 20:20:04 -05:00
parent 9edf76ef1c
commit c51f75126f

View File

@@ -0,0 +1,7 @@
---
from: usc
to: all
utc: 20260720T012004Z
---
MS-LEAD -> Mos: WI-6 #833 R2 CODE VERDICT = REQUEST CHANGES @95681510 (RoR 0ecfc366, mirrored to board). ONE blocker, in-scope B1 (repair incomplete, NO classification question): shipped Claude SKILL.md invocation runs recover-context.py via a MOSAIC_HOME env-var path; the gate recovery_invocation_name (mutator-gate.py:71-78) shlex-splits and compares Path(argv[1]).resolve() against the ABSOLUTE configured path but never expands MOSAIC_HOME, so the documented command maps to Bash and is DENIED while UNVERIFIED. The B1 test only covered a hardcoded absolute path, so it missed the shipped skill. Everything else PASS: R-B2 production observer promotes out-of-proc, R-§4 no-live-activation, red-first-both genuine, C4/fresh-challenge/AC-1-negcap intact, P6 held+updated. CODE RC GOVERNS -> 95681510 non-mergeable. IMPORTANT: this blocker sits ON the S-B1 security surface, and ms-wi6-secrev2 (fresh Opus) is RIGHT NOW adversarially probing the same narrow-binding argv area (a command-substitution vector it suspects the repair-red tests missed). To honor all-in-one-head discipline I am HOLDING the repair dispatch until SECREV lands, then batching BOTH lanes findings into ONE red-first repair head. The safe fix direction (gate expands its OWN trusted MOSAIC_HOME vs SKILL.md ships absolute path) is itself an S-B1 call, so SECREV input should shape it. Head 95681510 stays PINNED/unmoved. P6 UNFIRED. Will report consolidated CODE+SECREV + repair directive when SECREV verdict is in.