docs(remediation): RM-62 — fleet management is a PREREQUISITE, and the rotation claim is corrected
Mos ruled (c): coder-mos1 stays idle/parked, not manually rotated. It holds no in-flight work, so there is nothing to rotate FOR, and a manual in-pane restart would dress a missing mechanism as a lifecycle operation — the D-41 overclaim itself. It stays AVAILABLE through RM-61's re-review in case that review needs its context; the next NEW lane goes to a fresh seat, not to a seat at 67%. RM-62 filed, because a dependency stated as prose with no owner becomes the permanent gap the charter warns about. Bringing the execution fleet under roster/systemd management BLOCKS RM-50, RM-58 and P-LIFECYCLE-001 — each is unsatisfiable against its real population until it lands. Banked explicitly that both would FAIL against their real target today: RM-50 applied now quarantines the seat implementing RM-50, and RM-58 has no mechanical reset path for any seat that needs one. RM-50 and RM-58 now carry RM-62 as a hard depends_on edge, and RM-50 carries the requirement that acceptance be proved against the unmanaged execution fleet rather than the roster-managed canaries. RECORD CORRECTION, initiated by Mos and banked here: this session's opening rotation validated the checkpoint+rehydration DESIGN losslessly — the residency attestation genuinely passed from the files — but the MECHANISM was a manual pane respawn. "The handoff rehydrated losslessly" is earned; "rotation worked" overclaims a mechanism that does not exist, and that overclaim is D-41. Same distinction as D-23's inert guard: the step ran, one property was observed, the mechanism was not. Board header now says so rather than implying a lifecycle rotation occurred. D-37 and D-41 are one cluster — the execution fleet lacks both its shared-infrastructure and its lifecycle management. Mos owns both, sequenced at a seam, never mid-lane. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 5
parent
37402e9770
commit
0de8ccb52c
@@ -1,8 +1,9 @@
|
||||
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
||||
|
||||
**Phase:** EXECUTING — RM-03 at owner-merge; RM-02 blocked on RM-61; RM-61 **rebuilding on D-40 BLOCKING**.
|
||||
**Updated:** 2026-08-01 — rotation seam CROSSED; successor seat resumed, attested, and is driving.
|
||||
(Prior seat rotated at ~803k tokens, ~4x threshold.)
|
||||
**Updated:** 2026-08-01 — seam crossed; successor seat resumed, attested from the files, and is driving.
|
||||
⚠ That was a **MANUAL pane respawn** (prior seat ~803k tokens): it validates the checkpoint+rehydration
|
||||
**design**, NOT a lifecycle **mechanism** — P-LIFECYCLE rotation does not exist yet (**D-41 / RM-62**).
|
||||
|
||||
## Head
|
||||
|
||||
|
||||
+39
-14
@@ -346,6 +346,30 @@ work**.
|
||||
> population, not against roster-managed canary seats.** A criterion satisfied only on the managed
|
||||
> canaries is **tested on the wrong population** — the D-17 coverage class, one layer up. This is the
|
||||
> same shape as D-38: the check passes while the thing it claims to cover goes untested.
|
||||
>
|
||||
> **Banked explicitly (Mos, 2026-08-01): BOTH WOULD FAIL AGAINST THEIR REAL TARGET TODAY.** RM-50
|
||||
> applied to the actual execution fleet quarantines the seat implementing RM-50; RM-58 has no mechanical
|
||||
> reset path for any of the seats that need one. Neither is a near-miss — each is unsatisfiable against
|
||||
> its true population until the prerequisite below lands.
|
||||
|
||||
> **★ SEQUENCING DEPENDENCY — a hard edge, not an afterthought (Mos, 2026-08-01).** Bringing the
|
||||
> execution fleet under roster/systemd management is a **PREREQUISITE** for RM-50, RM-58 and
|
||||
> P-LIFECYCLE-001 to be enforceable on it **at all**. Tracked as **RM-62**, which now blocks all three.
|
||||
> Recording it as prose with no owner would make it the permanent gap the charter warns about, so it
|
||||
> gets an id.
|
||||
|
||||
**★ RECORD CORRECTION — the earlier `mos-remediation` rotation (Mos, 2026-08-01).** The rotation that
|
||||
opened this session demonstrated the **checkpoint + rehydration DESIGN** losslessly — the residency
|
||||
attestation genuinely passed from the files, and that validates the design. But the **MECHANISM was a
|
||||
manual pane respawn run by hand**, not the deterministic-coordinator-enforced rotation P-LIFECYCLE-001
|
||||
specifies. _"The handoff rehydrated losslessly"_ is true and earned. _"Rotation worked"_ **overclaims a
|
||||
mechanism that does not exist** — and that overclaim IS D-41. Same distinction as D-23's inert guard:
|
||||
**the step ran, one property was observed, the mechanism was not.** Mos amended the coordinator
|
||||
checkpoint to read manual-stopgap rather than lifecycle-rotation.
|
||||
|
||||
**Cluster note:** D-37 (shared `.git/config` / `worktreeConfig`) and D-41 (no lifecycle management) are
|
||||
**one cluster** — the execution fleet lacks both its shared-infrastructure and its lifecycle management.
|
||||
Both are Mos's to own and sequence at a seam, never mid-lane.
|
||||
|
||||
**Honest labelling of today's rotation:** it is a **manual pane restart with a hand-verified handoff
|
||||
artifact, dressed as a lifecycle operation.** Acceptable as a stopgap; it must **not** be recorded as
|
||||
@@ -1819,20 +1843,21 @@ spread is itself information, and X1 says we calibrate on real merged PRs.
|
||||
|
||||
### P5 — Retirements, hygiene, conformance
|
||||
|
||||
| id | task | src | depends_on | est (S/O) | tier |
|
||||
| ----- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- | ------------------------------------------ | ---------------- | ------ |
|
||||
| RM-50 | One roster-owned socket/host; quarantine unmanaged; **deterministic reaper for stale sessions AND dead-session disk scratch** (D-7) | O+S+live | RM-04 | 14K / 150K | sonnet |
|
||||
| RM-51 | Auto-sync **allowlist** (never auto-stage unknown paths) + worktree/lease isolation | O+S | RM-02 | 8K / 110K | sonnet |
|
||||
| RM-52 | Retire the Python controller + duplicate MACP islands (3 → 1) | O+S | RM-26, RM-27, RM-25, RM-28 | 14K / 110K | codex |
|
||||
| RM-53 | Flat-file orchestration → DB hard cutover, with rehearsed rollback artifact | O+S | RM-27, RM-30, RM-34, RM-29 | (in S-10) / 200K | opus |
|
||||
| RM-54 | Fleet-wide inert-gate audit against the RM-02 registry | O | RM-02 | — / 120K | sonnet |
|
||||
| RM-55 | **Conformance harness:** fault-inject the live failure classes on real artifacts | O+S | RM-35, RM-41, RM-53 | 18K / 260K | opus |
|
||||
| RM-56 | Retirement proof: CI asserts all three retirements are complete **and stay complete** | O | RM-52, RM-45, RM-53 | — / 90K | codex |
|
||||
| RM-57 | Operator cutover docs + activation proof; map all 15 decisions to evidence | S | RM-04, RM-36, RM-45, RM-55 | 6K / — | codex |
|
||||
| RM-61 | **CI-contract exemption for the #1000 teardown artifact** — signature-scoped, negative-control-proven, bounded, retiring with #1000 (ruled B, Mos 2026-08-01) | mos-remediation | — (unassigned; no free write-capable seat) | 15K | sonnet |
|
||||
| RM-60 | **External pre-execution trust boundary for CI (option B — the correct primitive, not the cautious one)** — protected default-branch pipeline config or an immutable trusted launcher that enters the sandbox **before** any PR-controlled executable/config is evaluated; unblocks isolated per-commit replay (RM02-REQ-10) | mos-remediation (D-25) | infra/provider authority (Mos + Jason) | 25K | opus |
|
||||
| RM-59 | **Close the D-19 residual risk** — generated-state verification anchored **outside** the worktree's authority (executor/spine-side attestation), retiring the same-UID self-authentication gap | mos-remediation (D-19) | RM-12, RM-21, RM-25 | 20K | opus |
|
||||
| RM-58 | **Mechanical pre-dispatch context reset** — the orchestrator resets a seat out-of-band and verifies it, rather than asking the agent to reset itself | mos-remediation (D-4) | RM-31, RM-50 | 8K | sonnet |
|
||||
| id | task | src | depends_on | est (S/O) | tier |
|
||||
| ----- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- | ------------------------------------------ | ---------------- | ------ |
|
||||
| RM-50 | One roster-owned socket/host; quarantine unmanaged; **deterministic reaper for stale sessions AND dead-session disk scratch** (D-7). **Acceptance MUST be proved against the UNMANAGED execution fleet, not the roster-managed canaries (D-41)** | O+S+live | RM-04, **RM-62** | 14K / 150K | sonnet |
|
||||
| RM-51 | Auto-sync **allowlist** (never auto-stage unknown paths) + worktree/lease isolation | O+S | RM-02 | 8K / 110K | sonnet |
|
||||
| RM-52 | Retire the Python controller + duplicate MACP islands (3 → 1) | O+S | RM-26, RM-27, RM-25, RM-28 | 14K / 110K | codex |
|
||||
| RM-53 | Flat-file orchestration → DB hard cutover, with rehearsed rollback artifact | O+S | RM-27, RM-30, RM-34, RM-29 | (in S-10) / 200K | opus |
|
||||
| RM-54 | Fleet-wide inert-gate audit against the RM-02 registry | O | RM-02 | — / 120K | sonnet |
|
||||
| RM-55 | **Conformance harness:** fault-inject the live failure classes on real artifacts | O+S | RM-35, RM-41, RM-53 | 18K / 260K | opus |
|
||||
| RM-56 | Retirement proof: CI asserts all three retirements are complete **and stay complete** | O | RM-52, RM-45, RM-53 | — / 90K | codex |
|
||||
| RM-57 | Operator cutover docs + activation proof; map all 15 decisions to evidence | S | RM-04, RM-36, RM-45, RM-55 | 6K / — | codex |
|
||||
| RM-61 | **CI-contract exemption for the #1000 teardown artifact** — signature-scoped, negative-control-proven, bounded, retiring with #1000 (ruled B, Mos 2026-08-01) | mos-remediation | — (unassigned; no free write-capable seat) | 15K | sonnet |
|
||||
| RM-60 | **External pre-execution trust boundary for CI (option B — the correct primitive, not the cautious one)** — protected default-branch pipeline config or an immutable trusted launcher that enters the sandbox **before** any PR-controlled executable/config is evaluated; unblocks isolated per-commit replay (RM02-REQ-10) | mos-remediation (D-25) | infra/provider authority (Mos + Jason) | 25K | opus |
|
||||
| RM-59 | **Close the D-19 residual risk** — generated-state verification anchored **outside** the worktree's authority (executor/spine-side attestation), retiring the same-UID self-authentication gap | mos-remediation (D-19) | RM-12, RM-21, RM-25 | 20K | opus |
|
||||
| RM-58 | **Mechanical pre-dispatch context reset** — the orchestrator resets a seat out-of-band and verifies it, rather than asking the agent to reset itself | mos-remediation (D-4) | RM-31, RM-50, **RM-62** | 8K | sonnet |
|
||||
| RM-62 | **★ PREREQUISITE — bring the EXECUTION fleet under roster/systemd management.** Every working seat (`coder-mos1`, `rev-974`, `f10-coder`, `merge-gate`, `pm-scout-*`, `rev-3107b`, `ultron-3107`, **and `mos-remediation`**) is `inactive/disabled` + UNMANAGED — there is no lifecycle surface to enforce anything against. **BLOCKS RM-50, RM-58, P-LIFECYCLE-001**; each is unsatisfiable against its real population until this lands. One infrastructure cluster with D-37's shared-config fix; Mos owns both, sequenced at a seam, never mid-lane | mos-remediation (D-41) | infra authority (Mos) | TBD | opus |
|
||||
|
||||
**Critical path:** `RM-01 → RM-02 → RM-10 → RM-11 → RM-12 → RM-21 → RM-23 → RM-31 → RM-33 → RM-34 → RM-53 → RM-55`.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user