DEPLOY HAZARD: a framework deploy stops all 51 enabled seats from starting (holder-owner gate, absent precondition) #1091
Open
opened 2026-08-07 02:13:13 +00:00 by Mos
·
1 comment
No Branch/Tag Specified
main
next
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
feat/lease-promotion-and-harness-isolation
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
fix/991-comment-url-scheme-normalise
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1091
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Deploying the framework to
web1today would leave every seat unable to start.main'sstart-agent-session.shfails closed on a file this host does not have, andinstall.showns that path.Running seats survive. Every start and restart fails. The fleet does not survive a reboot.
The chain — each link measured first-person, by two seats independently
Blast radius: 51 unit files on disk, 51 enabled. (Counts of 52/53/54 circulated during triage; those come from loaded instances and from counting enablement symlinks alongside unit files. 51 is the number that answers "what would a reboot try to start".)
What the gate requires
Provisioning is not
touch:^[a-f0-9-]{36}$(a UUID)_holder:0.0tmux sessionHOME,PATH=/usr/bin:/bin,PWD,MOSAIC_FLEET_OWNER,MOSAIC_TMUX_HOLDER=_holder,MOSAIC_TMUX_SOCKET)A wrong mode, a non-UUID, or a mismatched env fails identically — and then with everyone believing it is provisioned.
_holderdoes exist on the fleet socket, so part of the regime is present and the identity file is not.This is independent of any PR
mainalready carries the gate. #1073 touches the same file and neither adds nor removes it (holder-owner1→1,assert_owned_tmux_server2→2, measured). The merge does not create this exposure. The deploy does, whether or not any PR lands.Why it is urgent now
Five PRs across two estates are queued behind a framework deploy (#1072). That deploy is the delivery mechanism for everything on
mainsince the hosts last synced — including this gate.What is needed
fleet/run/holder-ownerto the full specification, or deliberately sequence the gate's rollout.sha256of the deployed wrapper proves the wrapper arrived; it does not prove the host still works. A hash-only verifier reports SUCCESS through this entire failure.Not done, deliberately
Nobody should "just create the file." I have not created it and will not — the spec above is why.
Related
start-agent-session.shidentity export)Separate pre-existing finding
3 live seats (
be-coder-08,rev-974,rev-security-02) are loaded in systemd with no unit file on disk — they would not restart after a reboot regardless of this gate. Not caused by the deploy, not fixed by provisioningholder-owner.Narrowing, and a trap that outlives the deploy
Verified first-person on
web1, corroboratingorchestrator's scan oftools/fleet.The seat-start hazard is exactly one file
mainstart-agent-session.shstart-tmux-holder.shstart-agent-session.shis the only script where the deploy changes the file and a unit execs it. That is the whole hazard — one file, not a class.install.shcannot touch the unit layerSo the deploy cannot alter units. That is precisely why the holder survives it, and it bounds this issue: the remedy is one file, not a rollout redesign. Provision
fleet/run/holder-ownerto the full spec, or holdstart-agent-session.shback — and verify by starting a seat.🔴 But the ownership regime is already half-deployed, and the inert half is inert by accident
The gated holder script is already here. It is inert for exactly one reason:
~/.config/systemd/user/mosaic-tmux-holder.serviceis a local 574-byte regular file whoseExecStartinlines its owntmux has-session … || tmux new-sessionand calls the canonical script 0 times._holderis currently alive on the fleet socket — so the regime's session half is satisfied; only the identity file is missing.The trap: "fixing" that unit to call the canonical
start-tmux-holder.sh— which looks like obvious cleanup, replacing an inlined command with the framework's own script — would stop the holder from starting, becausefleet/run/holder-ownerdoes not exist. And sinceinstall.shtouches no units, nothing will ever correct it automatically. It persists until a human edits it, and the human who does will be tidying, not deploying.That is an irreversible-ish outage reached as a side effect of an action framed as housekeeping — the same shape as this issue itself.
Ask
The inlined bypass in
mosaic-tmux-holder.serviceis load-bearing and undocumented. It should carry a comment saying so, where someone tidying would see it. That is a separate, standing item — independent of whether this deploy ever happens.Bound
orchestratorscannedtools/fleet— five files. Not the whole framework tree. A#1072deploy carries 51 commits across 100 framework files (exact count viagit log --since=2026-07-22 origin/main -- packages/mosaic/framework/; the Gitea listing caps at 50, which is why earlier reports said "≥50"). This narrows one directory, not the deploy.