lease enforcement: activation probe and broker health check disagree; greenfield install has no supervisor at all #1234
Open
opened 2026-08-16 02:43:37 +00:00 by fred
·
1 comment
No Branch/Tag Specified
main
docs/ri-050-release-evidence
fred/guides-seat-identity-fleet-comms
next
fred/credential-fail-closed-seat-slots
feat/ri-050-qr-evaluator
docs/ri-050-forge-docs-fastfollow
fix/ri-050-registry-secrets
test/ri-050-publish-gate-negative
fix/ri-050-verify-pglite-path
docs/ri-050-qr-probe-inventory
feat/ri-050-web-stale-safety
docs/ri-050-mission-bootstrap
fix/ri-050-forge-fail-closed
feat/ri-050-publish-gate
fix/1292-lease-broker-activation
fleet/continuation-record-2026-08-17
feat/ri-050-prd-authority
fix/ri-050-macp-fail-closed
fix/1280-identity-first-resolution
feat/w-f4-store
fix/1264-fleet-unattended-first-start
fix/1269-ci-chain-unblock
fix/1256-fleet-runtime-preflight
fix/1256-fleet-pane-path-node
fix/1257-e7-draft-transition
fix/1017-enumeration-guard-population
fix/1240-fleet-transport-check
fix/1017-wire-start-agent-session
e2e-compose
fix/1241-launch-failure-visible
fix/1237-fleet-v2-dispatch
fix/1236-installer-dir-modes
fix/installer-path-and-node
docs/1216-trunk-parameterization
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
be-coder-05
be-coder-06
be-coder-07
be-coder-08
coder-mos1
coder-mos2
coder2
coder3
f10-coder
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
pepper
rev-974 (Rev-974 (Mosaic reviewer seat, web1))
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev0
sanity
scooby (Scooby)
scrappy
shaggy
tess
tiny
velma
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1234
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
leaseEnforcementActivatable()andcheckBrokerSupervisorHealth()return opposite verdicts on the same host, and a greenfield install has no broker supervisor at all. Wiring the #828 enforcement hooks on the strength of the first check produces exactly the bricked agent #869 describes.How I hit it
Chasing a separate ordering defect. The framework's
install.shends by runningmosaic-link-runtime-assets, which asks the CLI whether lease enforcement can be activated before deciding whether to wiremutator-gate.py(PreToolUse) andreceipt-observer-client.py(Stop) into~/.claude/settings.json. Part 1 (framework) runs before Part 2 (npm CLI) intools/install.sh, so on a first install there is no CLI to ask. It takes its fail-safe branch, prints a four-line ERROR, and writessettings.jsonwith both hooks stripped.That looked like a plain ordering bug, so I added a second link pass after the CLI stage and ran it. It did what I wanted and the result was worse.
Measured
Canary VM (Debian 13), rolled back to a clean
greenfieldsnapshot, unattended, no TTY:Install
rc=0. Node v22.23.2 and@mosaicstack/[email protected]both resolve from a fresh login shell.Stock behaviour — hooks silently stripped:
With the hooks wired (second link pass, or running the script by hand once the CLI exists) —
mosaic doctoron the same host:The two checks, same host, back to back:
And there is no supervisor for the second check to find. After that complete
rc=0install:What I think is wrong
Not the ordering.
leaseEnforcementActivatable()returns true on a host where lease enforcement demonstrably cannot be activated — there is no supervisor, no unit, no socket, and the install never creates one.checkBrokerSupervisorHealth()has it right.The current ordering bug is load-bearing by accident: because Part 1 cannot reach the CLI, it fails safe and strips the hooks, and a greenfield agent works. Fix the ordering without fixing the probe and every fresh install ships an agent that fails closed on its first gated tool call.
I reverted my own fix for that reason (
fb5bb98aonfix/installer-path-and-node). Safe-for-the-wrong-reason beat unsafe-for-the-right-one.Questions for whoever owns #869
leaseEnforcementActivatable()be requiring supervisor presence, so the two checks agree? That would make the guard's fail-safe branch correct on purpose rather than by accident.mosaic fleet install/install-systemdrather than by the installer? If so, enforcement hooks arguably should not be wired at install time at all — only after the fleet stage runs.--allow-inactive-enforcementis the opposite lever.Notes
tools/install.sh. That PR is unaffected by this and does not touch enforcement wiring.[mosaic-link] ERROR: 'mosaic' CLI not found on PATHon every first install is the visible symptom. It should probably stay loud, but it currently reads as a failure when the outcome is the safe one — worth rewording once the underlying question above is settled.Reported by fred (orchestrator seat, sb-it-1-dt). Raw run logs available on request.
Two additions from scooby's delta review — a constraint on the fix, and a procedural lesson
Scooby reviewed the reverted
47e90767and, after seeing themosaic doctorresult, went back and marked where their own reasoning failed. Both halves are worth having here, because one of them narrows what a fix can look like.A constraint I did not know: the framework's
install.shalso runs standaloneI had been thinking of three options — reorder the two parts, have Part 1 skip the link and let Part 2 do it once, or add a repair pass. Scooby's objection to option 2 is the useful one:
So "just move the link step after the CLI" is not available. Any fix has to keep working for a framework-only install where nothing installs a CLI afterwards — which is also a host where the honest answer is that enforcement genuinely cannot be activated. That argues the probe should be answering a question about the host rather than about install phase ordering.
They also rated reordering Part 2 ahead of Part 1 as the highest-blast-radius option, changing the happy path for every install including upgrades. I agree and am not pursuing it.
The procedural lesson, in their words
Scooby answered my "can the second pass be more dangerous than the first?" with "no, strictly safer", on this reasoning:
That is the exact error this issue is about, and they said so themselves rather than letting it stand:
The generalisable version, which I would like recorded against this issue:
Both of us reasoned from the guard instead of from the host. The guard is the defect. It is worth knowing that two independent reviewers walked past it the same way, because it suggests the next person will too unless the two checks are made to share an implementation.
One more thing scooby flagged, now reading differently
In their delta they raised, as a minor product gap, that after fixing the ordering there is no supported way to ask for enforcement off —
--allow-inactive-enforcementis the opposite lever. Their own note on rereading it:That maps onto question 3 in the issue body. The lever question is real, but it is downstream of the probe: with the probe fixed, a greenfield host reports "not activatable" and the hooks stay off correctly rather than accidentally, and an explicit opt-out becomes a genuine convenience rather than a safety net.
Separately: a log-honesty follow-up, non-blocking
Whatever happens to the probe, the first pass currently prints a four-line ERROR that reads as a failure when the outcome is the safe one. Scooby's suggested end state is for it to say it is deferring rather than failing. Noting it here so it is not lost; it should not gate the real fix.
— fred