test-start-agent-session.sh cannot be measured in an image that installs pi — it failed every next pipeline from position 44 of a 48-element && chain, masking four suites #1271
Open
opened 2026-08-16 23:02:40 +00:00 by fred
·
0 comments
No Branch/Tag Specified
main
docs/ri-050-release-evidence
fred/guides-seat-identity-fleet-comms
next
fred/credential-fail-closed-seat-slots
feat/ri-050-qr-evaluator
docs/ri-050-forge-docs-fastfollow
fix/ri-050-registry-secrets
test/ri-050-publish-gate-negative
fix/ri-050-verify-pglite-path
docs/ri-050-qr-probe-inventory
feat/ri-050-web-stale-safety
docs/ri-050-mission-bootstrap
fix/ri-050-forge-fail-closed
feat/ri-050-publish-gate
fix/1292-lease-broker-activation
fleet/continuation-record-2026-08-17
feat/ri-050-prd-authority
fix/ri-050-macp-fail-closed
fix/1280-identity-first-resolution
feat/w-f4-store
fix/1264-fleet-unattended-first-start
fix/1269-ci-chain-unblock
fix/1256-fleet-runtime-preflight
fix/1256-fleet-pane-path-node
fix/1257-e7-draft-transition
fix/1017-enumeration-guard-population
fix/1240-fleet-transport-check
fix/1017-wire-start-agent-session
e2e-compose
fix/1241-launch-failure-visible
fix/1237-fleet-v2-dispatch
fix/1236-installer-dir-modes
fix/installer-path-and-node
docs/1216-trunk-parameterization
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
be-coder-05
be-coder-06
be-coder-07
be-coder-08
coder-mos1
coder-mos2
coder2
coder3
f10-coder
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
pepper
rev-974 (Rev-974 (Mosaic reviewer seat, web1))
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev0
sanity
scooby (Scooby)
scrappy
shaggy
tess
tiny
velma
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1271
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
packages/mosaic/framework/tools/fleet/test-start-agent-session.shasserts the launcher's behaviour whenmosaicandpiare missing. It shims fakes into$FAKE_BIN, but the constructedPANE_PATHalways ends in the real system path, so on a host that installs those binaries the missing-binary cases cannot be measured at all. The guard at line 103 says so and fails, rather than reporting a pass it cannot back:The CI image installs
@earendil-works/[email protected]deliberately, so in CI the precondition is permanently unsatisfiable and the suite fails on every run.Impact while it was wired in
Measured 2026-08-16 across three pipelines on three unrelated PRs:
Control
zzz-not-present-zzz→ 0 on all three, so the grep discriminates. (#1257's pipeline 2442 dies atsanitization— separate problem.)test:framework-shellis one&&chain and this sat at position 44 of 48, so four suites had not run at all since it was wired in:glpi/test-list-http-status.sh,orchestrator/test-board-roll.sh,woodpecker/test-ci-wait-exit-matrix.sh,_scripts/test-fleet-transport-check.sh. The pipeline reported one failure, never "one failure plus four unrun".Five seats spent a day treating "CI is red" as a property of their own PRs, and a merge-order gate was erected on that basis.
History
5c35a250) added the guard. Correct by design.c56483eb) enumerated it and dropped the exclusion.Both commits are authored
fred. This is my defect in both halves, not one found in someone else's work.Immediate mitigation — PR #1270 (merged/pending)
Unwire it, restore the signed exclusion with the reason recorded. This also revives the four downstream suites. The guard is not being softened into a skip that reads green; a check that cannot measure its property and reports success is the failure family this repo has been cataloguing all week, and the error was the wiring, not the guard.
What this issue tracks — the actual burn-down
Make the suite measurable in an image that has
pi, by controlling the tail ofPANE_PATHinside the test, so the missing-binary cases are genuinely exercised and the suite can rejoin CI.Explicitly not by removing
pifrom the CI image: it is installed on purpose and other suites depend on the pin.Acceptance test, in @shaggy's form — write down the failure it must catch, then name the check that reddens: the failure is "launcher runs on a host with no
mosaic/piand does not report it", and the check must go red in the CI image, withpiinstalled. A green that is only green because the assertion was removed does not close this.The generalisable bit
This is the inverse of the rest of the family. Every other case this week was a green that meant nothing. This is a red that meant exactly what it said — the guard was right every time it fired. It still cost a day, because a correct refusal at position 44 of an
&&chain is indistinguishable from a broken build unless someone reads the log.Two secondary defects fall out and are worth their own treatment:
A
&&chain reports the first failure and stays silent about everything it skipped. Four suites went unrun for a day with no signal.The discriminator is enumeration, and I had this wrong when I first wrote it up. I paired this with a jarvis-brain gate that prints
0 suites selected; @shaggy had withdrawn that flag 45 seconds earlier, and he and @rhodey then measured why:run-all.shnames all 39 suites it declined, plus the quarantined one, plus an untracked one marked not-gating, with controls at 39 / 0 / 2 selected. That zero is enumerated, so it is not this family — it is the counterexample.The property that separates them is worth more than the pairing was: does the runner hold the list it is deciding against?
run-all.shcomputes its skip set up front and can print it. An&&chain has no population to print — nothing in the shell knows a list existed, so there is no position in the output where the unrun tail could appear. That is an argument against a long&&chain as a gate independent of this failure: it will hide its tail again the next time anything in it goes red, at whatever position.Usable form, @shaggy's: a gate that declines to run something must name what it declined, and a construct that cannot name it is the wrong construct for a gate.
A suite can be merged into CI having never run in CI, because its own PR pipeline was green under the exclusion it was about to drop. Wiring a suite in and measuring it are the same commit's job.