Seat identity: the commit object still says the wrong author, because #1043 only fixed the token #1196
Open
opened 2026-08-13 07:33:24 +00:00 by Mos
·
0 comments
No Branch/Tag Specified
main
docs/1216-trunk-parameterization
next
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1196
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
#1043mechanized the seat identity that decides who acts (MOSAIC_GIT_IDENTITY→ thecredential helper → which token authenticates the push). It did not cover the identity that decides
who the commit says wrote it —
user.name/user.emailon the commit object. Those aredifferent config keys, set by different code paths, and fixing the first left the second silently
wrong.
#1043predicted this shape exactly, in its own words:That is the realized state of
/src/mosaic-stacktoday, for the authorship keys.Evidence — measured on web1, 2026-08-13
The shared repo config carries one seat's identity:
That repository has 74 linked worktrees, and 2 of them carry a
config.worktreeoverride:So 72 worktrees — belonging to be-coder-06, coder4, f10-coder, fleet-enhance, rev-974, the rm-0x
lane and others — author every commit as
coder-mos1 <[email protected]>, whateverseat is actually working in them.
This was found by walking into it: a commit on
feat/workspace-hygiene-tool-enforcement(PR #1174)came out authored
coder-mos1on a branch whose entire history isHermes Agent <[email protected]>.git config --show-originlocated the cause in the shared config. Thecommit was amended under a worktree-scoped identity; the shared config was deliberately not
edited, because 72 other worktrees are live against it.
Why it is silent
Nothing reports it. The push succeeds — the token is correct, because
#1043fixed that half — sothe provider accepts the write and attributes the PR to the right account. Only the commit object
carries the wrong name, and no gate reads the commit object's author. The two halves disagree and
every check passes:
MOSAIC_GIT_IDENTITY#1043)GITEA_LOGINtealogin prints — who it says it isuser.name/user.emailuseConfigOnly = truemakes this worse in a specific way: it stops git from guessing an identity,which is correct, but it means the shared value is not a fallback for seats that forgot to set one —
it is the only value they will ever get, applied confidently and silently.
What has changed since #1043
#1043reasoned underextensions.worktreeConfigbeing off, which is why it concluded per-repogit config could not be the fix and the identity had to be a per-process env var. That extension is
now on for this repo, so
git config --worktree user.namegives a worktree its own authorshipwithout touching co-tenants. The tool that was missing when
#1043was written now exists.Ask
user.name/user.emailalongsideMOSAIC_GIT_IDENTITY, so the three identities are wired in one place and cannot drift apart.extensions.worktreeConfigis asserted on any repo the fleet creates worktrees in, since thescoped write silently becomes a shared write when it is off — the contamination path
#1043described.
at what the commit says is checking one of the two identities and reporting on both. The
write-differential check from
#1043is the natural home.[user]block in/src/mosaic-stack/.git/configis not to be removed casually:with
useConfigOnly = trueand no scoped override, deleting it does not restore correctauthorship, it makes
git commitfail for 72 live worktrees. Backfill the scoped identitiesfirst, then remove the shared one.
Not done here
No shared config was edited, no seat's checkout was touched, and nothing was rewritten. Commits
already authored under the wrong name are history and stay that way.
Refs #1043.