#828 shipped fail-closed enforcement hooks (mutator-gate.py,
receipt-observer-client.py) with nothing supervising daemon.py or
guaranteeing its socket exists before a gated runtime starts. This adds
the activation-side supervisor mechanism:
- a systemd --user unit (mosaic-lease-broker.service) mirroring the
existing tmux-fleet unit convention, with RuntimeDirectoryMode=0700
so it satisfies daemon.py's secure_parent() fail-closed check
- a wrapper script (start-lease-broker.sh) that resolves the broker
socket with the same precedence as defaultLeaseBrokerSocket() in
commands/launch.ts, and colocates the state file next to it
- broker-supervisor.ts: deterministic path resolution, an idempotent
apply() that materializes the unit/wrapper/daemon sources (reseed-safe,
never runs systemctl or starts the daemon), and a health predicate
(isBrokerSupervisorHealthy / checkBrokerSupervisorHealth) other cards
(e.g. the C1 activation probe) can call
All tests use temp dirs/fakes; nothing here installs, enables, or
starts anything on this host.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>