Files
stack/docs/plans/reviews/2026-09-10_m20-publication-owner-disposition.md
T

1.8 KiB

#1500 publication disposition

Jason answered "go" to the explicit recommendation to publish the fixture-only increment with task/release checks marked not applicable and the reproduced identity-environment leak tracked separately.

This disposition applies only to reviewed manifest11255dd4. Package/launcher74, config24, auth15, foundation43 and conductor17 checks are independently green. Task/release suites are not claimed passing: this unintegrated package changes no task or release execution path; their live model/release effects remain unauthorized. Evidence: 2026-09-10_m20-publication-regression-verdict.md. This is not a permanent waiver for later integrated work.

Publication is authorized after exact-byte verification and clean committed-tree checks. No real Pi, credentials, live OAuth, service, Docker release or deployment is authorized. Production refresh needs a separate charter.

Separate follow-up task: headless identity environment leak

Owner of intake: Darkwing. Status: recorded, implementation not authorized by this publication disposition. Scope to charter separately: stop native launcher identity leaking through compose into headless task prompts. Evidence: compose.yaml26 forwards MOSAIC_AGENT_NAME; unchanged load-contracts.sh emits identity iff that variable is set. Coordinator and Filbert independently reproduced set/unset controls using synthetic contracts. The historical complete task-suite failure was not rerun.

Acceptance proposal: headless dispatch removes seat identity/role/SOUL overrides while intentional interactive seat identity remains intact; deterministic fixture coverage for both paths; independent review before integration; any live end-to-end rerun needs separate authorization. Do not modify the reviewed registry increment to absorb this unrelated fix.