merge origin/main into feat/wf5-securestorage

Brings MOSAIC_GIT_IDENTITY (per-seat git authorship) onto the delivery
branch, which had none of it. The branch carried W-F7's FLEET_SEAT seam in
the same launcher file; the two auto-merged cleanly.

Three single-hunk conflicts resolved:
- pr-merge.sh: kept branch policy allowing main OR next (next is the
  release stream).
- test-ci-queue-wait-tristate.sh: kept the branch's 4 added merge-readiness
  assertions; merge base and main both had zero, so nothing of main's is
  reverted.
- package.json test:framework-shell: union of both enumerations, 50 entries,
  no test dropped from either side. Picks up main's test-start-agent-session.sh
  and test-fleet-units.sh, which are the guards for the identity key.
This commit is contained in:
Jason Woltje
2026-08-14 23:15:56 -05:00
107 changed files with 7987 additions and 209 deletions
@@ -11,6 +11,16 @@
"timeout": 10
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "~/.config/mosaic/tools/git/wrapper-guard.sh",
"timeout": 10
}
]
}
],
"PostToolUse": [
@@ -51,12 +51,26 @@ Skills are discovered from:
### Extensions
The Mosaic Pi extension (`~/.config/mosaic/runtime/pi/mosaic-extension.ts`) handles:
`mosaic pi` loads framework-owned extensions directly from `~/.config/mosaic/runtime/pi/` in this
order:
- Session start/end lifecycle hooks
- Active mission detection and context injection
- Memory routing to `~/.config/mosaic/memory/`
- MACP queue status reporting
1. `mosaic-extension.ts` — session lifecycle, mission context, memory routing, lease/mutator gates,
and fleet heartbeat reporting.
2. `goal-extension.ts` — optional persistent `/goal` controller with per-turn and post-compaction
checks.
The goal extension is deployed by Mosaic and MUST NOT be copied into `~/.pi/agent/extensions/`.
Use `/goal set <statement>` (or `/goal <statement>`) to start, then `/goal status`, `/goal pause`,
`/goal resume`, or `/goal cancel` to control it. An active goal is injected before every model
request, restored from branch-specific session entries, and considered achieved only after two
consecutive evidence-bearing reports. Common credential shapes are redacted before controller-owned
goal-state entries are persisted or
displayed; Pi's own model/tool-call history is separate. Goals and reports must contain references
and pass/fail summaries rather than secrets or raw sensitive output.
- `MOSAIC_GOAL_MAX_TURNS` — autonomous turn limit, default `40`, accepted range `1..500`.
- `MOSAIC_GOAL_MAX_NO_PROGRESS` — identical no-progress report limit, default `6`, accepted range
`1..100`.
### Sessions
File diff suppressed because it is too large Load Diff