Invert the delivery verdict from negative to positive evidence. Previously, success was declared by the ABSENCE of a draft snippet on a prompt line: if the `❯|^>|│ >` glyph matched nothing (busy-receiver draft on an unmatched line, or wrong-pane drift), an UNSUBMITTED message read as "✓ delivered" exit 0 — a silent worker->lead relay stall (filed by UC-LEAD, PR #3046: three review verdicts reported delivered but never surfaced for ~50 min). Fix: success now requires POSITIVE evidence — either the queued banner, or the REPL input box located AND clear of the message tail. If the input box cannot be located, status is `unconfirmed` -> exit 2 + stderr ("could not confirm submission ... may be UNDELIVERED"). The near-dead `*)` indeterminate default also flips from silently returning 0 to exit 2. Bracketed-paste and double-Enter delivery mechanics are unchanged; queued/draft/delivered semantics are preserved, only the failure-mode default direction changes. Adds `test-send-message-verdict.sh`: 3 real tmux-pane fixtures (delivered / unconfirmed-glyphless / draft) locking the fail-loud verdict logic, and upgrades `test-send-message-socket.sh` fixtures from a glyphless bash prompt to `❯`-prompt REPLs so the patched binary can read delivery positively. Reproduce-first evidence (baseline vs patched, glyphless-pane fixture): baseline: rc=0, stdout "✓ delivered to =noglyph" (silent false positive) patched: rc=2, stderr "could not confirm submission ... may be UNDELIVERED" Test results after port: test-send-message-verdict.sh -> PASS=3 FAIL=0 test-send-message-socket.sh -> ok Firewall: grep -niE 'jason|woltje|jarvis' on changed files = 0 hits; tools/quality/scripts/verify-sanitized.sh -> sanitization gate passed. shellcheck: 1 pre-existing SC2034 finding (unused loop var `attempt`, present identically in baseline) carried through; 0 new findings. Part of #891
Inter-Agent tmux Comms — Standard & Tooling
Reliable, self-identifying messaging between Mosaic agents running in tmux panes (Claude Code / Codex / OpenCode REPLs), across hosts.
The addressing standard (required)
Every cross-agent tmux message MUST begin with an addressing preamble:
[<src_host>:<src_session> -> <dst_host>:<dst_session>] <message>
host=hostname -sof the machine the agent runs on (e.g.web1,sb-it-mgr-0-lt).session= the tmux session name (e.g.mos-claude,rev0-4,installer-1).- Replies FLIP the preamble: the recipient answers with
[<dst> -> <src>] ....
Why: a fresh or context-wiped agent always knows who sent a message and to whom. No ambiguity about origin or lane after a tmux wipe / session restart.
Example exchange:
[web1:mos-claude -> sb-it-mgr-0-lt:installer-1] status on #29?
[sb-it-mgr-0-lt:installer-1 -> web1:mos-claude] Q2 done, opening PR #34.
The helper: agent-send.sh
Prepends the preamble automatically (auto-detecting your own host:session) and
delivers reliably to local OR remote panes.
# Local target (same host, default tmux server)
agent-send.sh -s <dst_session> -m "message"
# Local target on a Mosaic fleet socket
agent-send.sh -L mosaic-fleet -s '=coder0' -m "message"
# Remote target (over ssh)
agent-send.sh -H user@host -s <dst_session> -m "message"
# From a file / stdin
agent-send.sh -H user@host -s <dst_session> -f msg.txt
echo "msg" | agent-send.sh -s <dst_session>
Key flags: -L named tmux socket · -s dst session (required) · -H ssh target for remote · -n dst
hostname for the preamble (else auto-resolved) · -m/-f/stdin body · -S
override source label · -v verbose · -r N Enter-flush attempts.
For durable fleet use, prefer exact tmux targets such as =coder0. The helper
normalizes exact session targets to pane-qualified targets internally so pane
commands do not fall back to tmux's prefix matching behavior.
Named socket isolation
Durable Mosaic fleets should use a dedicated tmux socket, for example:
tmux -L mosaic-fleet ls
agent-send.sh -L mosaic-fleet -s '=coder0' -m "status?"
send-message.sh -L mosaic-fleet -t '=coder0' -m "raw pane message"
This keeps fleet operations away from the user's default tmux server. It is the safe rollout path on hosts that already have manual tmux sessions.
Why a helper exists (the submission gotcha)
Pasting into an interactive REPL via raw tmux send-keys is unreliable: a
trailing Enter is frequently swallowed and the message sits as an unsubmitted
draft ("Press up to edit queued messages"). Over an ssh -> nested tmux hop the
plain Enter keyname often does not register at all — C-m is needed.
send-message.sh solves this for a local pane: bracketed-paste the body
(so multi-line content doesn't submit early), pause, then send Enter as its own
keystroke and flush with a second, verifying against a draft heuristic.
agent-send.sh solves the remote case by shipping send-message.sh over ssh
(ssh host bash -s -- ... < send-message.sh) and running it local to the target
pane — so the reliable send-keys always happens on the pane's own host. The remote
needs only bash + tmux + base64; no mosaic install required there. The
message crosses the wire as base64 (-b) to avoid all shell-quoting hazards.
Files
agent-send.sh— inter-agent wrapper (preamble + local/remote dispatch).send-message.sh— low-level reliable single-pane submitter (-bbase64 input).auto-submit-drafts.sh— watchdog that flushes stable unsubmitted prompt drafts on a coordinator pane (default targetmos-claude); run it as a long-lived process alongside the coordinator session.agent-send.test.sh— regression + grammar lock foragent-send.sh.test-send-message-socket.sh— smoke test for named-socket isolation.
Distribution
These live in the installed framework copy at
~/.config/mosaic/tools/tmux/. install.sh rsyncs the framework source tree
to each host, so to propagate permanently, land both files in the framework
source repo and re-run the installer on each host. Until then, agent-send.sh
already works against any reachable host because it ships send-message.sh over
ssh per-send — no pre-install on the target host is needed to send to it.