Fleet comms/session identity: watcher verification, per-agent session homes, wedge detection after binary updates #1295
Open
opened 2026-08-17 21:54:15 +00:00 by mos-dt-0
·
2 comments
No Branch/Tag Specified
main
docs/ri-050-release-evidence
fred/guides-seat-identity-fleet-comms
next
fred/credential-fail-closed-seat-slots
feat/ri-050-qr-evaluator
docs/ri-050-forge-docs-fastfollow
fix/ri-050-registry-secrets
test/ri-050-publish-gate-negative
fix/ri-050-verify-pglite-path
docs/ri-050-qr-probe-inventory
feat/ri-050-web-stale-safety
docs/ri-050-mission-bootstrap
fix/ri-050-forge-fail-closed
feat/ri-050-publish-gate
fix/1292-lease-broker-activation
fleet/continuation-record-2026-08-17
feat/ri-050-prd-authority
fix/ri-050-macp-fail-closed
fix/1280-identity-first-resolution
feat/w-f4-store
fix/1264-fleet-unattended-first-start
fix/1269-ci-chain-unblock
fix/1256-fleet-runtime-preflight
fix/1256-fleet-pane-path-node
fix/1257-e7-draft-transition
fix/1017-enumeration-guard-population
fix/1240-fleet-transport-check
fix/1017-wire-start-agent-session
e2e-compose
fix/1241-launch-failure-visible
fix/1237-fleet-v2-dispatch
fix/1236-installer-dir-modes
fix/installer-path-and-node
docs/1216-trunk-parameterization
docs/ia-merge-current
fix/869-lease-probe-timeout
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1182-fail-closed-launch
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/ci-queue-wait-no-status
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
be-coder-05
be-coder-06
be-coder-07
be-coder-08
coder-mos1
coder-mos2
coder2
coder3
f10-coder
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
pepper
rev-974 (Rev-974 (Mosaic reviewer seat, web1))
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev0
sanity
scooby (Scooby)
scrappy
shaggy
tess
tiny
velma
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1295
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Measured on sb-it-1-dt, 2026-08-17 (docs-seat incident): a non-orchestrator fleet session ended up holding and acting on other agents' context. Root cause is three mechanical gaps in comms delivery and session identity — not model behavior. Interim prose guardrails have landed in the user-owned
~/.mosaic/contract tree (SOUL.md fleet boundaries, STANDARDS.md session identity + watcher hygiene); this issue tracks the mechanical fixes so the prose fences can retire.The three gaps (all measured)
Session files keyed by cwd, resumable by any process in that cwd. One
~/src/stackpi session file served three lives: a/goal-command dev conversation (Aug 10), the goals seat resumed onto it (Aug 13,gpt-5.6-solturns), then 22 comms-watcher injections absorbed while the seat was wedged (Aug 17).pi --continuein a shared cwd resumes whatever ran there last.Comms watchers deliver by tmux session name with no identity verification.
install-watcher.shunits target a session name; nothing verifies the pane's process is the intended agent. A renamed or reused session name silently reroutes mail. Watchers also kept injecting for hours into a seat answering nothing — no unread-backlog alarm. (Related known gotcha: delivery confirmation is runtime-glyph-dependent — E7.)No wedge detection after runtime binary updates. pi 0.84.1→0.84.2 was installed under live seats; in-memory seats fail on first provider switch (module layout mismatch: openai-completions adapter imports a symbol exported only by 0.84.2), every call dies with
stopReason:"error"before spending a token, exit code still 0, and every liveness instrument (tmux flag, -icanon, foreground process, pane_alive) stays green. Third member of the dead-seat-passes-liveness family; first that passes the terminal check too.Proposed mechanical fixes
docs/decisions/mosaic-stack/2026-08-17_mosaic-d-002_agent-home-profiles.md, Pending): sessions/transcripts/settings under~/.mosaic/fleet/agents/<name>/, targeted config-dir env vars per harness (not literal HOME). Prototype already validated (~/.mosaic/fleet/agents/probe— auth-bundle symlink chain, per-agent sessions).MOSAIC_AGENT_NAMEfrom/proc/<pane_pid>/environ, or match the launch-ledger PID). Mismatch or unresolvable target → refuse delivery + alert, never type into a squatter.stopReason:"error"in the session file after a binary change = alert. Both derivable from existing artifacts (session JSONL, launch ledger).--name <seat>(or equivalent) so resume is never cwd-ambiguous.Longer term
Message queue + forced separation (planned) supersedes the watcher path entirely; the identity-verification and wedge-detection pieces remain valid regardless of transport.
Provisioning follow-up (from sb-it-1-dt hardening, same day): watcher setup should move into agent instantiation —
mosaic agent --new(and fleet launch) should ensure the comms watcher user-service exists, is active, and targets the right session/socket, rather than leaving it to whoever remembers.Interim implementation now lives in the brain repo:
scripts/comms/ensure-watcher.sh— idempotent ensure (present+match=no-op; missing/inactive/drift=install or repair via the existinginstall-watcher.sh), a non-mutating--statusmode for boot checks, and two interim identity warnings that directly cover the incident's failure modes:MOSAIC_AGENT_NAME(read from/proc/<child>/environ) → WARN (misrouting class); bare runtimes get a NOTE that identity is unverifiable until per-agent launches landDocumented as a fleet requirement in the user-owned
~/.mosaic/AGENTS.md("Fleet Comms Watcher"): provisioned at instantiation, never a running agent's duty; boot check via--status. The framework-side move is: fold ensure semantics intomosaic agent --new/fleet launch +mosaic doctor(drift check), keeping the same contract.Continuation record for tonight's follow-on work (fleet identity, comms delivery, ~/.mosaic tree preservation): scratchpads/2026-08-17-fleet-identity-comms-mosaic-tree.md, delivered via PR #1296 into next. It consolidates the decisions register (MOSAIC-D-001/-002 pending ruling in jarvis-brain, tooling-migration direction, provisioning-at-instantiation), the as-built ~/.mosaic inventory, and the sequenced work queue whose first item is the comms-tooling migration + unit regeneration.