Record fixture increment review, publication and owner test gate (#1500)
This commit is contained in:
@@ -188,3 +188,15 @@ are never rewritten or removed; corrections are new entries.
|
||||
- 2026-09-10 — darkwing — #1500 owner approved prerequisite correction only. D1-D10 package repairs and 43 package/48 combined tests pass; M20-CORRECTION-FILBERT-1 dispatched to Filbert/default at manifest af97b5be, transport exit0/application acceptance unknown. Required return is correction verdict plus direct reply, follow-up Darkwing. No materialization/live credential/service changes.
|
||||
|
||||
- 2026-09-10 — darkwing for Filbert — #1500 M20-CORRECTION-FILBERT-1 APPROVED af97b5be, exact 12 changed files committed at 63353428, source hashes verified; clean committed-tree fixtures 48/48 pass. Push and fresh remote SHA verified. Corrective slice complete; materialization/refresh needs separate owner approval. Review limitations retained.
|
||||
2026-09-10 | Sage | Owner-directed private workspace relocation verified; repository recovery pointers updated. No private content commit/push or history rewrite.
|
||||
|
||||
- 2026-09-10 — darkwing — #1500 fixture-only implementation approved by Jason. Resolution/generation implemented; combined60/60 tests pass after complete output readback added. Rocko acknowledged exact0.85.1 public-source re-fetch for isolation findings; Filbert stage23 frozen review dispatched exit0/application acceptance unknown. Required returns: isolation findings and stage23 verdict with direct replies; follow-up Darkwing. No source commit/live effects yet.
|
||||
|
||||
- 2026-09-10 — darkwing — #1500 goal86baedd4 fake refresh boundary implemented; seven focused tests pass; store/generation integration and final independent review outstanding; no live Pi or credentials.
|
||||
|
||||
- 2026-09-10 — darkwing — #1500 final Filbert APPROVED11255dd4 verified; all21 live/snapshot hashes match; clean baseline-plus-overlay74/74 pass at /tmp/m20-final-verified-overlay.log. Implementation/review goal met; no commit/push. Broader charter regression applicability/task-suite gate remains before publication.
|
||||
|
||||
- 2026-09-10 — darkwing — #1500 publication authorized continuation: clean reviewed overlay config24/24 auth15/15 pass; unchanged loader two synthetic identity-env controls pass. Full task/release suites have undeclared live effects, not run. Filbert publication regression applicability/foundation-conductor request dispatched exit0/application acceptance unknown; source remains reviewed11255dd4.
|
||||
2026-09-10 | Sage | Private advisory framework and assessment dependency recorded outside public checkout; no client/IP detail published, no implementation or deployment.
|
||||
|
||||
- 2026-09-10 — darkwing — #1500 reviewed source3daee5ad published/remote verified; five clean committed-tree suites green; owner applicability disposition recorded; demo2/2 verified; owner acceptance remains pending.
|
||||
|
||||
+16
-5
@@ -15,11 +15,22 @@ b8008eda, d5307d2b, 86e009dde52bd588b4ade344bc292d5518843e1d (remote verified).
|
||||
source 6335342873985538da3e7dc80cf9e9505e758832 pushed and remote verified.
|
||||
Committed-tree package/launcher fixtures passed 48/48; source and test limits:
|
||||
`docs/plans/reviews/2026-09-10_m20-correction-completion.md`.
|
||||
Next action: obtain owner approval for the separately drafted fixture-only
|
||||
materialization/refresh increment before implementing it. Existing draft:
|
||||
`docs/plans/2026-09-10_m20-increment2-charter.md`.
|
||||
The corrective slice grants no materialization, live refresh, real credential,
|
||||
service or deployment authority. #1500 remains open for this separate gate.
|
||||
Jason subsequently APPROVED the fixture-only materialization/refresh increment.
|
||||
Fixture-only resolution, generation and fake refresh are implemented locally.
|
||||
Filbert APPROVED the complete increment at manifest11255dd4 in
|
||||
`docs/plans/reviews/2026-09-10_m20-refresh-final-verdict.md`.
|
||||
Darkwing verified all21 reviewed bytes match the live tree and independently
|
||||
reran74/74 tests in a clean baseline-plus-reviewed-overlay copy.
|
||||
Jason approved the increment-specific task/release applicability disposition.
|
||||
Source published at3daee5ad89dc6a006ca554ad7fda2b23eb96bb03; exact remote verified.
|
||||
Clean committed-tree checks: package/launcher74, config24, auth15, foundation43,
|
||||
conductor17 all pass. Task/release not run or claimed passing.
|
||||
Next action: present the two-test fixture demonstration for Jason's acceptance;
|
||||
keep #1500 open pending that response. Publication and demo receipt:
|
||||
`docs/plans/reviews/2026-09-10_m20-increment2-publication.md`.
|
||||
Headless identity-env fix is separate intake in the owner disposition record.
|
||||
No production refresh, live-suite effects or increment3 authority inferred. Charter: `docs/plans/2026-09-10_m20-increment2-charter.md`.
|
||||
No live refresh, real credentials, service installation or deployment authorized.
|
||||
Increment 1 and pi 0.85.1 were published through b3fa2210; passing original tests
|
||||
is not evidence that these newly identified prerequisites are satisfied.
|
||||
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
# #1500 fixture-only increment publication
|
||||
|
||||
Reviewed source commit: 3daee5ad89dc6a006ca554ad7fda2b23eb96bb03, pushed to origin/refactor and exact remote pin verified. All21 files in independently approved manifest11255dd4 match committed bytes. Ten changed files selectively committed; unrelated agent/WUI/skill artifacts remain unstaged.
|
||||
|
||||
Clean committed archive verification, with isolated HOME/environment and a disposable Git baseline for conductor tests:
|
||||
|
||||
- Package and launcher: 74/74, /tmp/m20-committed-package-launcher.log.
|
||||
- Config: 24/24, /tmp/m20-committed-config.log.
|
||||
- Auth: 15/15, /tmp/m20-committed-auth.log.
|
||||
- Foundation: 43/43, /tmp/m20-committed-foundation.log.
|
||||
- Conductor: 17/17, /tmp/m20-committed-conductor.log.
|
||||
|
||||
Task/release suites were not run and are not claimed passing. Jason explicitly approved this increment-specific applicability disposition, recorded in 2026-09-10_m20-publication-owner-disposition.md. That record also tracks the separate headless identity-environment fix intake. Earlier failed evidence remains preserved.
|
||||
|
||||
## Owner demonstration
|
||||
|
||||
From repository root:
|
||||
|
||||
```
|
||||
node --test --test-name-pattern='two concurrent|expired credentials refresh' packages/mosaic/tests/materialize.test.mjs
|
||||
```
|
||||
|
||||
Expected: two passing tests. They demonstrate two executions of the same agent selecting separate fixture accounts with distinct private outputs, and expired synthetic OAuth rotating before generation with reuse in the next execution. Tests remove temporary state. They print test results, not credential contents. No real Pi, OAuth, network clients or services run.
|
||||
|
||||
Implementation and independent review are complete; owner fixture-demo acceptance remains pending. #1500 should not be called owner-accepted before that response. Production credentials, refresh services, launcher integration and deployment remain outside this increment.
|
||||
@@ -0,0 +1,13 @@
|
||||
# #1500 publication disposition
|
||||
|
||||
Jason answered "go" to the explicit recommendation to publish the fixture-only increment with task/release checks marked not applicable and the reproduced identity-environment leak tracked separately.
|
||||
|
||||
This disposition applies only to reviewed manifest11255dd4. Package/launcher74, config24, auth15, foundation43 and conductor17 checks are independently green. Task/release suites are not claimed passing: this unintegrated package changes no task or release execution path; their live model/release effects remain unauthorized. Evidence: 2026-09-10_m20-publication-regression-verdict.md. This is not a permanent waiver for later integrated work.
|
||||
|
||||
Publication is authorized after exact-byte verification and clean committed-tree checks. No real Pi, credentials, live OAuth, service, Docker release or deployment is authorized. Production refresh needs a separate charter.
|
||||
|
||||
## Separate follow-up task: headless identity environment leak
|
||||
|
||||
Owner of intake: Darkwing. Status: recorded, implementation not authorized by this publication disposition. Scope to charter separately: stop native launcher identity leaking through compose into headless task prompts. Evidence: compose.yaml26 forwards MOSAIC_AGENT_NAME; unchanged load-contracts.sh emits identity iff that variable is set. Coordinator and Filbert independently reproduced set/unset controls using synthetic contracts. The historical complete task-suite failure was not rerun.
|
||||
|
||||
Acceptance proposal: headless dispatch removes seat identity/role/SOUL overrides while intentional interactive seat identity remains intact; deterministic fixture coverage for both paths; independent review before integration; any live end-to-end rerun needs separate authorization. Do not modify the reviewed registry increment to absorb this unrelated fix.
|
||||
@@ -0,0 +1,32 @@
|
||||
# M20-I2-PUBLICATION-GATES-FILBERT-1 (#1500) — regression applicability verdict
|
||||
|
||||
Reviewer: Filbert. Candidate unchanged at manifest `11255dd4…`; execution in a disposable baseline `27e4873a` + reviewed-overlay tree with clean HOME and scrubbed `MOSAIC_*` environment. No real Pi, credentials, network model calls, Docker builds/releases, services, source edits, commits, or shared logs. This verdict owns regression applicability/reconciliation feedback; publication decisions remain the coordinator's and the owner's.
|
||||
|
||||
## Independently executed, exact reviewed overlay
|
||||
|
||||
- **Foundation:** `scripts/test-foundation.sh` — 43 passed, 0 failed. Inspected first: sandboxed mkdtemp, synthetic fixtures, subprocess spawns of the inspector only, canary non-disclosure checks; no Docker/network/credential surface.
|
||||
- **Conductor:** `scripts/test-conductor.sh` — 17 passed, 0 failed. Inspected first: all git operations target sandbox clones with a sandbox config and mock adapter. Two failures during my runs were artifacts of my own disposable method, documented for the record: an archive tree lacks `.git` (fixed with a scratch init) and a scrubbed HOME lacks the git identity the apply step needs (fixed with explicit identity env). Neither touched the candidate.
|
||||
- **Config:** 24/24; **Auth:** 15/15 — both in the isolated environment. Package+launcher 74/74 was reproduced in this same overlay tree during the final increment review.
|
||||
|
||||
These four gates are satisfied by independent evidence on the exact reviewed bytes.
|
||||
|
||||
## Not executed, with source evidence
|
||||
|
||||
- **test-task.sh** requires the real container path with a real model and live Pi recall ("Live recall: real pi, real phrasing", the unconditional block at lines ~480+). Executing it would exceed this review's authorization (real Docker, model calls, credentials). Applicability analysis instead:
|
||||
- Nothing outside the package references it: no `packages/mosaic`/`@mosaic/registry` import exists in `scripts/`, `src/`, `compose.yaml`, or the root manifest. The fixture-only package is unintegrated; the task pipeline cannot execute any changed code.
|
||||
- The suite's one failing check ("no agent identity on headless run") predates this work entirely — increment 1 recorded byte-identical failure parity at stashed baseline `54c12312`.
|
||||
- The mechanism is now independently reproduced by me, not just asserted: `compose.yaml:26` forwards host `MOSAIC_AGENT_NAME` into the container, and `src/load-contracts.sh` emits an `AGENT IDENTITY` section if and only if that variable is set (my synthetic control: set → section present; unset → absent). The variable is present in the host environment. The historical failure is host-environment contamination through compose, unrelated to this package; its fix (env hygiene in the task launch path) is separate scoped work.
|
||||
- **test-release.sh** with Docker available (it is up on this host) takes the real-activation path: image builds and activation drills. The increment's diff is `packages/mosaic` plus review documents only — no `RELEASE`, compose, scripts, or packaging-surface change — and image rebuild is out of charter scope. The release-relevant surface (the pi pin) was last changed in increment 1, whose release run was independently green at that candidate and is published.
|
||||
|
||||
## Recommendation — owner disposition required, no waiver
|
||||
|
||||
The charter's task and release gates cannot be satisfied by offline evidence for this slice, and I do not waive them. Two honest paths, either of which needs an explicit owner record before publication:
|
||||
|
||||
1. **Task gate:** record that the suite is not applicable to this unintegrated fixture-only package (zero shared code paths), that its single failure is pre-existing with a now-reproduced contamination mechanism and a separately scoped fix, and that a full rerun requires an authorized Docker/model window if the owner wants end-to-end evidence.
|
||||
2. **Release gate:** record that the release surface is unchanged since increment 1's green run and image rebuild is out of scope — or, if the owner wants release evidence against the integrated tree, authorize a Docker window for the real-activation suite.
|
||||
|
||||
A silent "baseline waiver" would be the wrong record: it would paper over a real, reproduced environment leak that deserves its own fix task regardless of this increment.
|
||||
|
||||
## Bottom line
|
||||
|
||||
Foundation, conductor, config, auth, package, and launcher gates: green by independent rerun on the exact reviewed overlay. Task and release: not executable within this review's safety envelope; applicability is documented above with source evidence and a reproduced mechanism; the owner should choose the disposition path before publication. Production refresh remains excluded.
|
||||
@@ -0,0 +1,29 @@
|
||||
# M20-I2-FINAL-FILBERT-1 (#1500) — final whole-increment verdict
|
||||
|
||||
Reviewer: Filbert (independent; prior stage reviewer — this verdict relies on fresh whole-increment evidence). Frozen candidate `/tmp/m20-refresh-final-review-xn34lpeb` at manifest SHA-256 `11255dd4d76adb1762af0b5dd0d9eac114f48d5775594dd29ba554e4a96d82e6`, 21 files verified before and after; snapshot unchanged. All execution in a disposable baseline-plus-overlay tree. No real Pi, network, credentials, Docker, services, timers, commits, or shared-log edits.
|
||||
|
||||
## Verdict: APPROVED for the fixture-only increment
|
||||
|
||||
## Independent receipts
|
||||
|
||||
- **Combined suites:** `node --test packages/mosaic/tests/ scripts/test-darkwing-launch.mjs scripts/test-rocko-launch.mjs` — 74 tests, 74 pass, 0 fail, exit 0, reproducing the author's `/tmp/m20-refresh-integrated.log` claim. The failure-mode child's `FIXTURE_PRIVATE_DIAGNOSTIC` stderr appears nowhere in the output.
|
||||
- **My probes:** rotated output carries fresh markers and expiry with caller input untouched; near-expiry OAuth auto-refreshes inside the generation transaction without an explicit option; the rotation commits to the in-memory store (visible to a later transaction); a failed refresh refuses with `refresh-failed` and leaves the store's prior rotation intact. Zero `/tmp/mosaic-*-fixture-*` residue after the full run and the probes.
|
||||
- **Delta discipline:** versus the stage-23 snapshot, only `materialize-fixture.mjs` (refresh integration, `after-publish` fault), `materialize.test.mjs` (seven new tests), `README.md` (fixture/refresh documentation and limits), and the new `refresh-fixture.mjs`/`refresh.test.mjs` differ; `execution.mjs`, `fixture-store.mjs`, `index.mjs`, and the package manifest are byte-identical to the stage-reviewed bytes. The refresh runner is internal — not exported from the package index.
|
||||
|
||||
## Findings against the requested attention points
|
||||
|
||||
1. **Fixed-only runner:** the child is `process.execPath` with a fixed embedded program and fixed argv (`auth check --provider <p>`), `shell:false`; executable/env injection attempts refuse before spawning and before burning the execution claim.
|
||||
2. **Isolation:** isolated `PI_CODING_AGENT_DIR`/`HOME`/cwd per invocation from an env literal of exactly three variables — no inherited environment, no `PATH`, so no user-executable resolution; the fake self-checks its env purity and exits on any extra variable. This matches Rocko's corrected static findings (hash `6943eef5…` verified): `PI_CODING_AGENT_DIR` is the sole credential isolation lever, auth dispatch precedes cwd/settings/extension/trust setup, and the lock stays inside the agent dir.
|
||||
3. **Output/error privacy:** child stdio discarded, never buffered or parsed; the parent validates only the rewritten `auth.json` under `O_NOFOLLOW`, uid/mode/4 KiB bounds, fixed `invalid-refresh-output` code with no parser excerpts; all diagnostics are fixed codes in the marker language.
|
||||
4. **Child cleanup/timeout:** SIGKILL on timeout with close-event resolution and root removal in `finally`; `refresh-timeout`/`refresh-failed` refusals; no orphaned temp trees observed.
|
||||
5. **Lock scope and rollback:** refresh runs inside the store transaction; rotation commits only on successful generation (my R3/R4); same-account contention refuses `credential-busy` while an independent account's generation proceeds; failed refresh preserves prior generation bytes and store state, and the same execution ID cannot retry.
|
||||
6. **Uncertainty regression (added after my early review):** `after-publish` fault records an `uncertain` receipt, retains the complete published generation, empties `pending`, rolls back the in-memory draft, and refuses same-ID replay. This closes the gap I flagged; the README states the residual honestly (store commit and publication are not crash-atomic together; no external issuer exists to reconcile in this simulator).
|
||||
7. **Fork/enrollment/native-ceiling semantics:** unchanged stage-reviewed `execution.mjs`; its tests all still pass in the combined run.
|
||||
8. **README claims:** accurate and deliberately bounded — in-process locks, same-UID/hardlink residual, static-only 0.85.1 evidence, and the explicit warning that the model-catalog network flag does not suppress OAuth refresh networking and that real Pi must never be substituted, even with synthetic OAuth.
|
||||
9. **Rocko corrected evidence:** the correction receipt is honest (stale pin claim, placeholder path, over-broad no-network claim — each fixed with the original preserved); the corrected bounded claims are the ones this increment relies on.
|
||||
|
||||
## Limits and conditions
|
||||
|
||||
- This approves the fixture-only increment exactly as frozen. Committing/pushing the reviewed bytes is the authorized next step; owner acceptance follows per charter.
|
||||
- Nothing here is a production refresh protocol: a real backend needs a separate charter covering reconciliation, distributed locking, and crash-atomicity. Never substitute real Pi in these tests.
|
||||
- Residuals already on record carry forward: in-process locks, same-UID tampering/hardlink provenance, and the correction verdict's design-only items.
|
||||
@@ -0,0 +1,24 @@
|
||||
# M20-I2-STAGE23-FILBERT-1 (#1500) — early stage 2/3 verdict
|
||||
|
||||
Reviewer: Filbert (independent; also the correction reviewer — fresh evidence only). Frozen snapshot `/tmp/m20-stage23-review-51p59lff` at manifest SHA-256 `9330fc5f01ab046242ddef92dd11a21030729596640535b8f76927b38d6d825d`, 17 files verified before and after (snapshot unchanged; tests ran only in a disposable copy). Exactly the five declared paths differ from baseline `27e4873a…`; the twelve context files are byte-identical. This is an early read-only stage review, not final increment approval.
|
||||
|
||||
## Verdict: STAGE-SUPPORTED
|
||||
|
||||
## Tested observations
|
||||
|
||||
- **Suites:** 55/55 package tests in my disposable copy (43 correction tests unchanged plus 12 new materialize tests, the fault loop expanding to two) and 5/5 launcher fixtures — the claimed 60/60 combined, reproduced independently.
|
||||
- **Fixture scope held.** `fixtureOnly: true` is mandatory on requests, stores, workspaces, and manifests; the credential language accepts only `FIXTURE_[A-Z0-9_-]{1,128}` markers (my probe: `sk-REALLOOKING123` refused); the workspace is a fixed `/tmp/mosaic-materialization-fixture-` mkdtemp with no caller-selected root; generate's only option is the `fault` injection (extra keys refused); only WeakSet-branded in-memory stores are accepted — a hand-built lookalike with a hostile transaction is refused before executing (suite-verified; no production adapter can be injected).
|
||||
- **Resolution semantics.** Scope fields are explicit, validId-bounded, and absent-or-malformed inputs refuse; overrides are enrollment-bounded; fork pins survive default changes, reject override divergence (`fork-account-change`), refuse missing pins (`missing-fork-pin`) and revoked enrollment (`account-not-enrolled`), and unpinned relaunches use the profile default — the gate-6 ruling encoded as tested behavior. Native providers refuse model ceilings (`native-model-enforcement-unavailable`) and cross-slot aliasing; custom endpoints enforce the api allowlist and model enrollment. Requests and registries are structuredClone'd at entry, and invalid registries cannot resolve (no partial-entry fallback).
|
||||
- **Generation.** Claims are exclusive by atomic mkdir and retained across failures, including both injected faults (prior published bytes unchanged, `pending` cleaned, `failure.json` recorded, no blind same-ID retry); publication is rename-based with pre-checks, full byte readback of all three artifacts under mode/uid/size verification, fsync of files and directories; manifests carry scope/profile/account-refs/manifestId only — no tokens, expiries, or credential digests (suite regex plus source read). A symlinked pre-existing final target is refused without following.
|
||||
- **My probes beyond the suite:** same session, two executions, two different accounts → two distinct complete generations with the right credentials each (the charter's headline two-execution scenario); refused options do not burn the execution claim (validation precedes claiming); `close()` verifies path identity and removes the workspace (ENOENT after).
|
||||
- **No process/network surface** in the three new modules (source grep; the only `exec` hits are the word "execution"), so nothing here implements or implies refresh.
|
||||
|
||||
## Design-verified only (not execution-tested)
|
||||
|
||||
- The `publication-uncertain` path: reachable only if the post-rename `result.json` write fails, which no fault hook exposes. The handler's logic is correct on review (`pending` is removed only when not published; the uncertain state is recorded distinctly), but the final increment review should either add a fault hook after publish or note the path as uncovered.
|
||||
- Cross-process safety: claim and generation directories are exclusive per workspace, and store locks are in-process only. Both are consistent with the fixture-only slice; neither is a production concurrency claim.
|
||||
- Hardlink residual from the correction verdict carries forward unchanged (outside this slice's threat model).
|
||||
|
||||
## Remaining gates
|
||||
|
||||
Rocko's verification of the exact 0.85.1 refresh isolation is still open, and refresh is not implemented here — nothing in this verdict may be read as refresh support. Final whole-increment review must include refresh tests, target-version evidence, and the uncertain-path coverage note above. No commit, push, or live activation is implied by this early feedback.
|
||||
Reference in New Issue
Block a user