6.5 KiB
6.5 KiB
#1043 — Fleet pane git-identity propagation
Objective
Ensure a fleet seat's launched runtime process receives its roster-derived MOSAIC_GIT_IDENTITY, and lock the complete generated-environment propagation boundary with an enumerated set comparison.
Tracking
- External issue:
mosaicstack/stack#1043 - Branch:
fix/1043-pane-git-identity - Coordinator:
tl-mosaic docs/TASKS.md: read-only by project worker contract; not modified.
Constraints
- RED-first bug reproducer is mandatory.
- R7 delete-the-subject mutation must turn the behavioral test red.
- Assert launched-process environment, not source text.
- One push only; do not poll CI after push.
- Run the CI queue guard immediately before push and report its
state=line as state, not evidence. - Do not modify a live host launcher or obtain/copy another credential.
- Self-post the PR, verify provider attribution, then stop.
- Final status wording:
believed-fixed, pending jarvis validation.
Scope inventory
Re-derived against origin/main at 85d2108e:
- Launch consumer:
packages/mosaic/framework/tools/fleet/start-agent-session.sh - Behavioral launch test:
packages/mosaic/framework/tools/fleet/test-start-agent-session.sh - Generated-environment contract/parser:
packages/mosaic/src/fleet/generated-env-boundary.ts - Roster projection producers:
packages/mosaic/src/commands/fleet.tspackages/mosaic/src/fleet/fleet-reconciler.tspackages/mosaic/src/fleet/fleet-agent-crud.tspackages/mosaic/src/fleet/v1-v2-migration.ts
- Contract and producer tests discovered by repository search.
- Generated-environment operator/developer docs and their executable documentation contract test.
Discrepancy sent to tl-mosaic: current main no longer contains the charter's PANE_SHELL_SNIPPET; #772 replaced it with an /usr/bin/env -i argv launch boundary, and current generated projections do not declare git identity. Code-read inventory is NOT MEASURED behavior.
Plan
- Add the process-environment set-comparison regression first and record RED.
- Add roster-derived
MOSAIC_GIT_IDENTITY=<agent name>to the complete generated projection contract. - Validate identity syntax and equality with
MOSAIC_AGENT_NAME; pass it through the clean pane environment. - Update affected projection tests and generated-environment docs.
- Run focused and baseline gates.
- Perform R7 by deleting the pane propagation entry, prove RED, restore, and prove GREEN.
- Run independent review, remediate, commit, queue guard, one push, self-post PR, verify provider attribution, and stop without CI polling.
Budget
No explicit token cap was provided. Working cap: one narrow logical unit, no dependency installation unless existing tooling requires it, no unrelated refactor.
Evidence log
TDD and mutation evidence
- RED-first, repository launcher:
bash packages/mosaic/framework/tools/fleet/test-start-agent-session.shexited 64 on pre-fix source withcode=unknown-key key=MOSAIC_GIT_IDENTITY. The generated seat could not launch with the required declared identity. - GREEN: the same repository launcher test emitted
ok - start-agent-session generated environment boundary. - R7 delete-the-subject: removed only
"MOSAIC_GIT_IDENTITY=$MOSAIC_GIT_IDENTITY"from the repository launch array; the same test exited 1 withFAIL: runtime pane omitted or changed generated environment keys: MOSAIC_GIT_IDENTITY. - R7 restoration: restored that launch entry; the same test returned green.
- Launcher under test is explicitly
packages/mosaic/framework/tools/fleet/start-agent-session.shthrough the test's$START, not the stale installed host copy.
Situational and focused tests
- Repository launcher boundary: green, including set comparison of all nine generated projection entries and fail-before-tmux cases for missing, unsafe, mismatched, and local-shadow Git identity.
- Fleet systemd launcher integration:
bash packages/mosaic/framework/systemd/user/test-fleet-units.sh— green. - Focused Mosaic Vitest set: 6 files, 311 tests — green.
bash -non changed shell files — green.git diff --check— green.
Baseline gates
pnpm typecheck— 45/45 tasks green.pnpm lint— 25/25 tasks green.pnpm format:check— green.pnpm test:checkout— green.- Repository-wide Vitest under a hermetic current-version npm prefix: Mosaic 81/81 files and 1510/1510 tests green; other workspace test tasks shown green before the framework-shell phase.
- Canonical
pnpm testis not fully green on this host for unrelated environment-sensitive gates:- the first two runs exposed the globally installed Mosaic 0.0.48 update banner in three CLI smoke tests expecting empty stderr;
- after isolating that global-version input, the framework wake assertion aborted at the known
#973BashBASH_LINENOconvention check (exit 97; observed[3 5], expected[3 4]). No tests were weakened or bypassed; focused changed-surface tests are green. CI remains the canonical clean-environment result and is intentionally not polled after push per charter.
Independent review
- Codex code review first pass: request changes for missing shell rejection-path coverage.
- Remediation: added table-driven missing/unsafe/mismatch/local-shadow launcher cases, each asserting no tmux call.
- Codex code re-review: approve, no findings, confidence 0.88.
- Codex security review: risk
none, no findings, confidence 0.97.
Acceptance criteria mapping
| Acceptance criterion | Evidence |
|---|---|
| AC-FGI-01: launched process receives every generated key/value | Repository launcher process-environment comm -23 set comparison; GREEN and R7 RED evidence above |
| AC-FGI-02: missing, unsafe, or split identity fails before tmux | Table-driven shell cases plus TypeScript generated-boundary tests |
| AC-FGI-03: focused/baseline/review evidence recorded | Commands and review outcomes above; host-sensitive full-suite limitations stated explicitly |
Documentation checklist
- PRD updated with #1043 requirements and acceptance criteria.
- Fleet launch runbook, generated-env concept, and generated-env reference updated.
- No API/OpenAPI, sitemap, user publishing target, deployment, or external docs publication change applies.
docs/TASKS.mdremains unmodified per its single-writer project contract.
Residual risk
- Landing on
maindoes not update the currently installed host launcher. Host framework installation/reseed and Jarvis live-seat validation are separate downstream events. - Canonical CI result is pending and will not be polled by this seat.