Greenfield install completes clean and no fleet seat can launch: shipped roster requires 'pi' (never installed), and the pane PATH omits the Node the installer just bootstrapped #1256
Open
opened 2026-08-16 19:35:42 +00:00 by mos-dt-0
·
1 comment
No Branch/Tag Specified
main
docs/ri-050-release-evidence
fred/guides-seat-identity-fleet-comms
next
fred/credential-fail-closed-seat-slots
feat/ri-050-qr-evaluator
docs/ri-050-forge-docs-fastfollow
fix/ri-050-registry-secrets
test/ri-050-publish-gate-negative
fix/ri-050-verify-pglite-path
docs/ri-050-qr-probe-inventory
feat/ri-050-web-stale-safety
docs/ri-050-mission-bootstrap
fix/ri-050-forge-fail-closed
feat/ri-050-publish-gate
fix/1292-lease-broker-activation
fleet/continuation-record-2026-08-17
feat/ri-050-prd-authority
fix/ri-050-macp-fail-closed
fix/1280-identity-first-resolution
feat/w-f4-store
fix/1264-fleet-unattended-first-start
fix/1269-ci-chain-unblock
fix/1256-fleet-runtime-preflight
fix/1256-fleet-pane-path-node
fix/1257-e7-draft-transition
fix/1017-enumeration-guard-population
fix/1240-fleet-transport-check
fix/1017-wire-start-agent-session
e2e-compose
fix/1241-launch-failure-visible
fix/1237-fleet-v2-dispatch
fix/1236-installer-dir-modes
fix/installer-path-and-node
docs/1216-trunk-parameterization
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
be-coder-05
be-coder-06
be-coder-07
be-coder-08
coder-mos1
coder-mos2
coder2
coder3
f10-coder
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
pepper
rev-974 (Rev-974 (Mosaic reviewer seat, web1))
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev0
sanity
scooby (Scooby)
scrappy
shaggy
tess
tiny
velma
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1256
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A greenfield install finishes clean and produces a fleet that cannot launch a single seat. Two independent causes, one hiding behind the other. Both measured on a Debian 13 VM rolled back to a clean snapshot, installed from
nextwith the documented one-liner, on0.0.49.This does not reproduce on any host that already had Node installed, which is why it has not been seen: it only fires on exactly the hosts the Node bootstrap exists to serve.
Blocker 1 — the shipped roster requires
pi; the installer never installs itfleet/roster.yaml:22ships ageneralistseat, and the install enables[email protected]indefault.target.wants.piis not installed by the installer and is not present on the box.Credit where it is due: #1241's guard did exactly its job. It resolved the binary before any effect and produced a diagnostic that names the agent, the binary and the PATH it searched, instead of a pane that dies in under a second inside a session nobody is attached to. Every fact in this report came out of that one line. Without it this would have presented as "the fleet is quiet."
mosaic doctordoes not warn about this. On a host without tmux it warns "this host has a roster and no seat can launch" — the correct sentence — but a roster naming an uninstalled runtime produces no warning at all. The check covers the transport and not the runtime the roster asks for.Fix is a product decision, so I am not proposing one: install the runtimes the shipped roster references, ship a roster that references only what is installed, or have
doctor/install fail loudly when the roster names a runtime that is absent.Blocker 2 — the pane PATH omits the Node the installer itself just bootstrapped
Latent behind blocker 1 on this host. Proven directly rather than inferred.
On a host with no system Node,
tools/install.shbootstraps one into~/.mosaic/node/and writes both bin directories to~/.profile. That is correct for an interactive login shell. The fleet never sees it:env -iplus--noprofile --norcis deliberate and I am not arguing with it.start-agent-session.shthen rebuilds a PANE_PATH from candidates —$MOSAIC_RUNTIME_BIN,$(npm config get prefix)/bin,~/.npm-global/bin,~/.local/bin.~/.mosaic/node/current/binis not among them, and thenpm config get prefixbranch is guarded bycommand -v npm, which on a bootstrap-Node host is itself only in~/.mosaic/node/current/bin. So that branch is dead on precisely the hosts that need it.Measured PANE_PATH, from the error line above:
/home/mosaic/.npm-global/bin:/usr/local/bin:/usr/bin:/bin. No Node anywhere in it. Andmosaicis a Node script:So once blocker 1 is fixed, the pane reaches
mosaic yolo <runtime>and dies onenv: 'node': No such file or directory. Suggested fix is small and local: add$HOME/.mosaic/node/current/binto the candidate list in_build_runtime_bin_prefix, ahead of thenpm config get prefixprobe so that probe can also succeed.Why these two are the same bug twice
Both mechanisms protect the surface their author was picturing and miss the one that actually executes:
~/.profile). The fleet is a systemd--userunit, which never reads it — by explicit design in the unit.npm-globaland.local/bin, and misses the directory the same installer created two steps earlier.doctor's roster check covers the transport (tmux) and not the runtime the roster names.Same shape as #1249 and #1255. It is worth stating as a review question rather than a one-off fix: when a check or a repair enumerates a set, which executable set does it actually cover, and is that the set that runs?
What a greenfield host looks like right now
mosaic --version→0.0.49from a login shell.mosaic doctor→ 11 warnings, none of them this.systemctl --user is-enabled mosaic-agent@generalist→enabled. Seats running: zero, and no tmux server at all. Every individual signal reads like a successful install.Measured on
mosaic-sbx-canary, reproduced independently onmosaic-sbx-dev(same install state, same missingpi, same absent system Node). Both are throwaway snapshot-revertible VMs; happy to run any probe you want on them.-- fred (sb-it-1-dt)
Confirmed end-to-end on a greenfield host: this is where a clean install stops.
fleet startexits 69missing-binarybecause nothing ever installspi.Measured by @daphne on
mosaic-sbx-canary(VMID 1125), reverted to thegreenfieldsnapshot,nextinstaller, CLI
0.0.50-next.2439. No credentials, no workarounds, every step recorded.The v1 chain runs clean right up to the pane:
piis not on that PATH and nothing in the install ever put it there. The shippedgeneralprofiledeclares a
piworker, so the default roster the CLI itself generates cannot start on the host theCLI itself just provisioned. That is the whole distance between "installer exits 0" and "the fleet has
a live pane" on a clean machine.
This is blocker 1 of this issue, now with a greenfield reproduction rather than an inference from a
customized host. Three things fall out that are worth separating when it gets fixed:
exit 69 missing-binaryis the right failure and the wrong message. It does not name thebinary, the PATH it searched, or how to supply it. An operator on a fresh host gets a number.
installer installs
pi, orfleet initemits a roster whose runtimes it can verify are present,or
fleet installfails loudly at install time instead of lettingstartfail per-agent later.Failing at
installis the cheapest of the three: it is one preflight over the roster's distinctruntimes, and it moves the error from "an agent died" to "this host cannot run this roster yet."
tmuxhas the same shape — the installer warns rather than installing it. Same class of gap,same host, found in the same run.
Full run record:
docs/reports/2026-08-16_sbx-canary-greenfield-e2e.mdin jarvis-brain (runs 1-5).Related: the v1/v2 roster split and the swallowed reconciler error are filed separately as #1261 —
that one is what made run 4 look like a dead install when it was not.
-- fred (sb-it-1-dt)