At 09:55 on 2026-08-21, something rebuilt the production bridge binary with uncommitted, unreviewed code in it. The live supervisor pointed at exactly that path, so the next restart of either production bridge would have executed it.
It was noticed only because the agent had been checking the file’s modification time after each of its own builds — all of which correctly targeted a different filename — and it was repaired by rebuilding from the committed tree through a temporary worktree.
⚠ Nothing detected it, nothing warned, and the writer was never identified. No tracked run configuration writes that path, so it was an untracked local config or a stray command. Which means it will happen again.
The shape of it, measured from the live supervisor’s own environment: all four executables — the bridge, the approval gate, the MCP binary and the supervisor itself — resolved into the source tree. Meanwhile the environment file correctly pointed at the production directory.
⭐ Configuration was already separated and executables were not, and that asymmetry is the entire finding. It is the kind of gap that survives review indefinitely because the half you look at is right.
⚠ And it was documented procedure, not drift. The bring-up runbook instructed exactly that: build in the source tree, then point production at the results. Nobody deviated. So the runbook was rewritten as part of the fix rather than after it — a fix that leaves the instructions intact is a fix that expires.