# #1264 Unattended Fleet First-Start Verification > Status: **IN PROGRESS** | Executor: goals | Date: 2026-08-16 | Target: isolated local fixtures only ## Objective Verify that a named fleet seat launched through a systemd-equivalent, no-TTY environment on a clean host reaches its runtime boundary without an interactive Mosaic identity wizard. Preserve standalone wizard behavior and canonical roster ownership of exact seat identity. ## Source evidence accepted for local verification Daphne's canary investigation was read from jarvis-brain commit `6c0b6fc70ae6a179a1b7ff9dedfc54e9adccd19a`, report `docs/reports/2026-08-16_sbx-canary-greenfield-e2e.md`. It measured: ```text systemd -> start-agent-session.sh -> mosaic yolo pi (PID 3726) -> child mosaic wizard (PID 3762) ``` The canary pane remains preserved and was not accessed. Product behavior is independently tested here with temporary roots and fake runtime executables; no canary or installed-host inference is scored as local PASS evidence. ## Controls - Worktree base: `origin/next@476db12b92971634b67fd2057b7577ee5894e449`. - `DATABASE_URL` remains unset. - No real credential, token, provider, VM, installed Mosaic tree, unit, timer, PATH profile, or live tmux session is read or mutated. - Tiny's concurrent runtime-preflight and `start-agent-session.sh` PATH work are out of scope. - Held PR #1213 is not a dependency. ## Requirements-to-evidence map | Acceptance criterion | Method | Evidence | | ---------------------------------------------------------------------- | ----------------------------------------------------- | ------------------------------ | | No-TTY fleet first start avoids wizard and reaches runtime | Real built-CLI subprocess with piped stdin | Focused GREEN, CLI test 1 | | Missing top-level identity files are initialized from shipped defaults | Exact-byte and `0600` assertions | Focused GREEN, CLI tests 1/11 | | Exact seat identity remains roster-owned | Captured argv plus unknown/padded/blank-name refusals | Focused GREEN, CLI tests 1/6–9 | | Existing operator identity is never overwritten | Custom bytes/mode with defaults removed | Focused GREEN, CLI tests 2/3 | | Concurrent/repeated first start is safe | Four parallel CLIs plus repeated launch | Focused GREEN, CLI tests 2/11 | | Missing/unsafe defaults fail without prompting | Missing, symlink, oversized, and installed-link tests | Focused GREEN, unit/CLI tests | | Standalone launch retains wizard | Same real CLI without fleet identity | Focused GREEN, CLI test 10 | ## Command evidence ### Worktree helper refusal and sanctioned fallback Command: ```bash ~/bin/mosaic-worktree.sh new fix/1264-fleet-unattended-first-start --from origin/next ``` Exit: `1`. Stderr was retained; the helper refused because the derived worktree path was under `/var/home/jason.woltje`, while `/src` does not exist on this host. Fred explicitly authorized the plain-git fallback and path used for this task. Command: ```bash git -C /var/home/jason.woltje/src/stack worktree add \ /var/home/jason.woltje/agent-work/1264-unattended-first-start \ -b fix/1264-fleet-unattended-first-start origin/next ``` Exit: `0`; HEAD `476db12b92971634b67fd2057b7577ee5894e449`. ### RED Production source remained unchanged after adding the reproducer. The built CLI represented `origin/next@476db12` behavior. Command: ```bash env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \ src/commands/launch-first-start.spec.ts ``` Exit: `1`. ```text Test Files 1 failed (1) Tests 1 failed (1) [mosaic] SOUL.md not found. Running setup wizard... ◆ What would you like to do? [mosaic] Setup failed. Run: mosaic wizard AssertionError: expected 1 to be +0 ``` The fixture used piped stdin (not a TTY), a temporary `HOME`/`MOSAIC_HOME`, shipped default bytes, a canonical one-seat roster, a fake `pi`, and a fake lease-runtime boundary. The wizard rendered and the runtime-boundary capture was never created. Complete combined stdout/stderr was retained at `/tmp/1264-red.out` during execution. ### GREEN and baseline After the production change, the original one-test command exited `0` with `1/1` passing. The final focused command was: ```bash env -u DATABASE_URL pnpm --filter @mosaicstack/mosaic exec vitest run \ src/commands/fleet-first-start-identity.spec.ts \ src/commands/launch-first-start.spec.ts \ src/commands/launch.spec.ts \ src/commands/compose-contract.spec.ts \ src/config/file-adapter.test.ts \ src/cli-smoke.spec.ts ``` Exit: `0`; `6/6` files and `119/119` tests passed. The 11 production-kind CLI tests cover no-TTY launch, captured exact roster name/class, byte-equal `0600` seeds, no-clobber/idempotence, partial seed, missing/symlink defaults, unknown/padded/blank ambient members, standalone interactive control, and four concurrent first starts with no temporary residue. Nine direct filesystem tests cover successful/no-clobber hard-link publication, unexpected link errors, source prevalidation, existing operator contracts, idempotence, symlink sources/destinations, and oversized input. Full package Vitest: ```text Test Files 88 passed (88) Tests 1568 passed (1568) Exit 0 ``` New helper coverage: ```text Statements 100% | Branches 93.33% | Functions 100% | Lines 100% 9/9 tests passed; coverage command exit 0 ``` Baseline commands: ```text pnpm preflight exit 0 pnpm typecheck 45/45 tasks, exit 0 pnpm lint 25/25 tasks, exit 0 pnpm build 25/25 tasks, exit 0 pnpm format:check exit 0 pnpm --filter @mosaicstack/mosaic build exit 0 bash framework/tools/fleet/test-start-agent-session.sh exit 0; retained expected fixture LD_PRELOAD warning bash framework/tools/quality/scripts/test-install-migration.sh 21 passed, 0 failed, exit 0 bash framework/tools/_scripts/test-mosaic-init-rce.sh PASS, exit 0 git diff --check exit 0 ``` The aggregate `test:framework-shell` command exited `1` at `invariant_r_unittest.py`: `5/6` tests passed and the remaining test refused the operator-global Pi drift from measured `0.84.1` to installed `0.84.2`. This is retained as an environment/version-coupling failure, not scored as a #1264 code failure and not retried. The aggregate stopped there; later aggregate stages are **UNTESTED** except for the three targeted shell suites listed above. Root `pnpm test` is **UNTESTED** because it can execute the prohibited local PostgreSQL-dependent gateway isolation path. No PostgreSQL service, connection, migration, or initialization was used. CI is **UNTESTED — pending PR**. ## Explicitly untested - Canary VM remediation or restart: **UNTESTED and prohibited for this task**. - Real Pi authentication/provider prompt and task execution: **UNTESTED**. - PR #1213 composition layer: **UNTESTED and not required**. - Deployment/published npm package behavior: **UNTESTED until CI/release; deployment is not this PR's scope**. ## Review and residual risks Initial independent Codex code review returned `request-changes` with one should-fix: a padded `MOSAIC_AGENT_NAME` could be trimmed for pre-seed validation and later rejected in composition, leaving seeds behind. The implementation now rejects blank or padded values before roster lookup or writes; three no-side-effect regression cases pass. Codex re-review approved the remediated delta with no findings (`confidence=0.86`). Its read-only sandbox could not execute Vitest because Vite needed a temporary config artifact; executor-owned focused/full results above are the test evidence. Final Codex security review found no confirmed vulnerabilities (`risk=none`, confidence `0.91`). Formal PR review by a reviewer other than goals/Fred and CI remain pending. Real Pi authentication/provider prompt and task execution remain unmeasured. The local gate proves that Mosaic crosses its identity boundary and reaches the fake lease-runtime boundary; it does not claim provider readiness or deployment.