get_gitea_login_for_host matches tea login by NAME, so a seat present on both hosts silently authors as the shared account (distinct from #1044) #1188
Open
opened 2026-08-13 01:12:00 +00:00 by Mos
·
0 comments
No Branch/Tag Specified
main
docs/1216-trunk-parameterization
next
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1188
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
get_gitea_login_for_hostresolves a seat's identity to atealogin by comparing the identity string to the login's NAME.tea's login namespace is flat and global, but identity is per-host. A seat that exists on bothgit.uscllc.comandgit.mosaicstack.devcan therefore only ever be name-matched on one of them — on the other it falls through to first-host-match, which on mosaicstack is the sharedMosaccount.This is distinct from #1044 and should not be merged into it. #1044 is
get_gitea_tokenfailing open on an unset identity. This defect fires with the identity explicitly set and a valid per-slot token present, becausepr-create.sh's primary path istea pr create --login "$GITEA_LOGIN_NAME"and never reaches the token resolver at all.Measured, with positive control and a negative result that is the actual finding
Same host, same wrapper, four live fleet seats,
MOSAIC_GIT_IDENTITYset on every call:GITEA_LOGINcoder2mosaicstack-mos→ @Mosmosaicstack-coder2✅coder3mosaicstack-mos→ @Mosmosaicstack-coder3✅be-coder-06be-coder-06✅be-coder-08be-coder-08✅be-coder-06/be-coder-08are the positive control: the wrapper attributes correctly when a login's NAME happens to equal the identity, so the fault is not "attribution never works."Field instances: PR #1186 (
coder2) and PR #1173 (coder3) were both created with the identity set correctly and both carry@Mosas the PR-object author.The negative result is the finding. I registered mosaicstack logins for both seats —
tea logins addverified against/userand returned "Login as coder2 on https://git.mosaicstack.dev successful" — and they still resolve toMos. Registration could not fix them, because the namescoder2andcoder3were already taken by theirgit.uscllc.comlogins, so the new logins had to bemosaicstack-coder2/mosaicstack-coder3, which a name-only matcher does not recognise.This corrects the staged-precondition comment in
detect-platform.shThe comment stages the mosaicstack fail-closed refusal behind a
read:userscope grant, namingcoder-mos1/coder-mos2/f10-coder/merge-gateas unregisterable. For the seats that actually failed, that was never the blocker:coder2andcoder3verify against/userfine. Their blocker is the flat namespace.To be explicit, so the two justifications stay unconflated exactly as that comment asks: this issue is not a request for
read:user. It is the opposite — it shows that for these seats the scope was never the obstacle.mosaicstack-rev-974(userrev-974) already exists in the login list and is a latent instance of the same defect: identityrev-974acting on mosaicstack will not match that login's name and will resolve toMostoday.Proposed fix
userfield, not its name (name as fallback), in bothtea_login_matches_hostand the identity branch ofget_gitea_login_for_host.mosaicstack-coder2hasuser: coder2; matching onuserresolves it with no rename and no env override, and fixesmosaicstack-rev-974at the same time.echo "$_mgi", which is only correct while name == identity. That coupling is what forced the flat-namespace constraint in the first place;tea --loginneeds the login name.Interim mitigation in force
Affected seats now prefix
GITEA_LOGIN=mosaicstack-<seat>alongsideMOSAIC_GIT_IDENTITY=<seat>on every authoring call.GITEA_LOGINis honoured first and is still verified against the host, so it is an explicit correction rather than a bypass. It is a mitigation for two known seats and closes nothing: the next seat provisioned onto mosaicstack with a name collision impersonates the shared account silently, exactly as these two did.Note for whoever implements this
tea logins add --tokenalso reads$GITEA_SERVER_TOKENfrom the environment. Register logins that way — putting the token on--tokenplaces a credential on argv, which is visible in the process table on hosts withouthidepid.