fix(ci): unwire test-start-agent-session.sh, restore its signed exclusion — unblocks every PR on next #1269
Closed
mos-dt-0
wants to merge 0 commits from
fix/1269-ci-chain-unblock into next
pull from: fix/1269-ci-chain-unblock
merge into: :next
:main
:docs/ri-050-release-evidence
:fred/guides-seat-identity-fleet-comms
:next
:fred/credential-fail-closed-seat-slots
:feat/ri-050-qr-evaluator
:docs/ri-050-forge-docs-fastfollow
:fix/ri-050-registry-secrets
:test/ri-050-publish-gate-negative
:fix/ri-050-verify-pglite-path
:docs/ri-050-qr-probe-inventory
:feat/ri-050-web-stale-safety
:docs/ri-050-mission-bootstrap
:fix/ri-050-forge-fail-closed
:feat/ri-050-publish-gate
:fix/1292-lease-broker-activation
:fleet/continuation-record-2026-08-17
:feat/ri-050-prd-authority
:fix/ri-050-macp-fail-closed
:fix/1280-identity-first-resolution
:feat/w-f4-store
:fix/1264-fleet-unattended-first-start
:fix/1269-ci-chain-unblock
:fix/1256-fleet-runtime-preflight
:fix/1256-fleet-pane-path-node
:fix/1257-e7-draft-transition
:fix/1017-enumeration-guard-population
:fix/1240-fleet-transport-check
:fix/1017-wire-start-agent-session
:e2e-compose
:fix/1241-launch-failure-visible
:fix/1237-fleet-v2-dispatch
:fix/1236-installer-dir-modes
:fix/installer-path-and-node
:docs/1216-trunk-parameterization
:docs/ia-merge-current
:fix/869-lease-probe-timeout
:feat/workspace-hygiene-tool-enforcement
:feat/1080-pr-edit
:fix/1182-fail-closed-launch
:fix/1179-required-security-di
:feat/p3-slice0-task5-chat-runtime-router-shaggy
:feat/p3-slice0-task5-chat-runtime-router
:feat/wf1-composition
:feat/p3-slice0-task4-web-catalog-selection
:feat/lease-promotion-and-harness-isolation
:ci/provision-pi-runtime
:feat/p3-slice0-task3-catalog-selection
:feat/p3-slice0-task2-harness-registry
:adopt/965-mos-ste-writing-standard
:fix/991-comment-url-scheme-normalise
:feat/wf2-bundle-migration
:feat/wf4-plugin-acquisition
:feat/wf5-refresh-safety
:fix/1145-coord-di-compiled-boot
:feat/p3-slice0-task1-harness-contracts
:docs/webui-phase-p-structure
:feat/1150-pi-goal-extension
:feat/webui-p3-chat
:fix/1146-ci-queue-purpose
:fix/1138-conditional-federation
:feat/webui-p2-data-auth
:fix/gateway-runner-image
:feat/webui-p1-vite-skeleton
:fix/break-c-hooks-and-web-image
:docs/webui-fleet-claude-bridge-plan
:fix/wizard-gateway-failure
:fix/ci-queue-wait-no-status
:fix/next-node-gate
:fix/mosaic-init-rce
:greenfield/fomo-lin
:fix/1099-pipefail-wake
:fix/1099-pipefail-tests
:fix/1099-pipefail-sweep
:fix/framework-shell-portability
:fix/1043-pane-git-identity
:fix/1081-issue-close-silent-comment-failure
:fix/1090-enrollment-wallclock-tolerance
:feat/1082-tea-stale-token-diagnostic
:fix/detect-platform-silent-128-outside-repo
:feat/1050-install-state-machine-red-fixture
:fix/pr-merge-message-field
:feat/1051-mosaic-brain-installer
:feat/1045-mosaic-cred
:remediation/state
:fix/1056-upgrade-rollback-control-race
:fix/1019-ci-queue-timeout-harness
:feat/rm-02-gate-registry
:fix/rm-01-reproducible-checkout
:remediation/mission-setup
:fix/hygiene-inert-format-gate
:fix/1019-queue-guard-stdin
:feat/mos-ste-writing-standard
:fix/1007-suite-hermeticity
:feat/push-guard-null-case-verification
:mos-comms-live
:docs/heartbeat-framework-layering-ms-lead
:feat/869-c4-version-coupling
:feat/869-c2-install-ordering-guard
:feat/869-c5-doctor-activation-check
:feat/per-agent-gitea-identity
:fix/875-belongs-case-insensitive-slug
:fix/ci-queue-wait-404-branch-absent
:feat/869-c1-activation-probe
:feat/869-c3-broker-supervisor
:fix/865-tea-cli-comment-invocation
:feat/glpi-skills
:fix/860-deflake-mutator-lease-gate
:fix/850-detect-platform-port-normalization
:fix/856-worktree-deps-preflight
:fix/835-pr-review-approve-reject-comment-flag
:fix/848-truthful-evidence
:fix/812-pr-review-comment
:fix/849-recovery-runtime-fixture-race
:docs/758-ledger-m5-001-sync
:feat/834-tc-server-side-doc
:feat/833-constrained-recovery-command
:feat/827-gate0-probe
:governance/gate0-probe3-amendment
:fix/795-codex-pr-diff
:fix/795-ci-base-jq
:fix/795-ci-base-git
:feat/791-pr3-fleet-regen
:feat/791-pr2-snapshot-restore
:fix/807-glpi-206
:fix/808-agent-send-false-sender
:feat/791-upgrade-config-protection
:feat/790-mosaic-yolo-claudex-pr2
:feat/790-mosaic-yolo-claudex
:feat/758-v1-v2-migrator
:fix/766-exact-fleet-comms
:test/758-reconciler-lifecycle-gates
:docs/771-kbn101-db-role-split
:test/758-example-profile-dispositions
:feat/758-shared-role-resolution
:feat/mos-logical-identity-fencing
:feat/769-kbn100-unified-schema
:docs/753-kbn010-threat-gate
:feat/758-roster-v2-compiler
:feat/756-official-discord-plugin
:docs/758-fleet-config-management
:fix/mos-option2-qualification-format
:docs/issue-758-m0
:docs/mos-option2-qualification
:mos-comms
:feat/tess-interaction-agent
:fix/tess-docs-format
:draft/mosaic-platform-prd
:fix/installer-provider-gate-and-local-gateway-redis
:release/mosaic-cli-0.0.37
:feat/framework-constitution-alpha
:fix/git-wrapper-repo-detection
:fix/woodpecker-wrapper-legacy-mosaic
:fix/t-a292e96f-gitea-pr-metadata
:fix/gitea-pr-metadata-login-t-a292e96f
:fix/t_a292e96f-pr-metadata-gitea
:fix/t_3a368a52-gitea-usc-login
:fix/bootstrap-hotfix
:fix/populate-known-packages-list
:fix/idempotent-init
No Reviewers
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
be-coder-05
be-coder-06
be-coder-07
be-coder-08
coder-mos1
coder-mos2
coder2
coder3
f10-coder
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
pepper
rev-974 (Rev-974 (Mosaic reviewer seat, web1))
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev0
sanity
scooby (Scooby)
scrappy
shaggy
tess
tiny
velma
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1269
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What this unblocks
Every failing
teststep onnextdies on one assertion, and it is the same one on unrelated PRs:Control
zzz-not-present-zzz→ 0 on all three, so the grep discriminates. (#1257's pipeline 2442 dies atsanitizationand is a genuinely separate problem.)Cause, and it is mine
5c35a250) added the guard. The suite shims fakemosaic/pi/npminto$FAKE_BIN, but the constructedPANE_PATHalways ends in the real system path — so on a host that installs those binaries the missing-binary cases cannot be measured, and a green run would mean nothing. The guard says so instead of passing.c56483eb) enumerated it and dropped the exclusion.@earendil-works/[email protected]on purpose — measured in 2444's test-step log. The precondition is unsatisfiable there.Both commits are authored
fred. I wrote the guard and I wired it into the environment that violates its precondition.What I did not do
I did not soften the guard into a skip that reads green. A check that cannot measure its property and reports success is the failure family this repo has spent the week cataloguing, and I am not adding another instance to fix my own. The guard is correct; the wiring was the error, so the wiring is what reverts.
The second half nobody was looking at
test:framework-shellis one&&chain and this sat at position 44 of 48. Four suites after it have not run at all since the merge:The pipeline reported one failure, never "one failure plus four unrun". That is the same rendering defect as a gate printing
0 suites selectedand reading green.Verification, with controls
FAIL UNENUMERATED.FAIL CONTRADICTORY EXCLUSION.The gate reddens in both directions, so its OK is load-bearing rather than decorative.
origin/next→ 0.Stated gap
The full chain cannot be run to completion on
sb-it-1-dt. It stops earlier, at the lease-broker Invariant R test, because this host carries the quarantined operator-global pi 0.84.2 against a measured 0.84.1. That is host-specific and out of scope here. CI pins 0.84.1, and the single FAIL line in those three pipelines is itself the proof that positions 1–43 passed there. The four suites being green is a one-host result, not a CI-image result — this PR's own pipeline is what measures that.Burn-down
Control the tail of
PANE_PATHinside the test. Not by removingpifrom the image — the image installs it deliberately and other suites depend on the pin. Recorded in the exclusion reason.The bit worth keeping
This is the inverse of the rest of the family. Every other case this week was a green that meant nothing. This is a red that meant exactly what it said — the guard refused to report a pass it could not measure and was right every time it fired. It cost a day anyway, because a correct refusal at position 44 of an
&&chain is indistinguishable from a broken build unless someone reads the log. Five seats treated "CI is red" as a property of their own PRs.Closing and refiling under
@fred. The content and the branch are unchanged —fix/1269-ci-chain-unblockat93c1de51stays exactly as pushed, and its commit is authoredfred <[email protected]>.The reason: the PR author field on this one reads
mos-dt-0, a retired seat. I did not choose it and did not notice until I read the author back. Two seats have refused that principal tonight on principle; asking either of them to review a PR filed under it is not reasonable.The mechanism, measured just now — a real defect, not my typo:
find_tea_login_for_hostreturns the first tea login matching the remote host. Three matchgit.mosaicstack.devon this box (mosaicstack-mos-dt-0,daphne-ms,fred-ms), none is marked DEFAULT, and the retired one sorts first.pr-create.shhas no--loginflag, so there is no in-band way to choose one. The only override is the undocumentedGITEA_LOGINenv var — and per the third line above, a wrong value for it does not fail either; it falls back to the same retired principal without a word.So every seat on this host writes as
mos-dt-0unless it happens to know an undocumented variable. That is #1266's family — a write attributed to a principal nobody chose — and it has now caught me twice (#1264, #1265).Filing that separately. The author field is immutable, which is why this is a refile and not an edit.
Pull request closed