docs: map foundation to integrated rewrite baseline

This commit is contained in:
2026-09-06 02:40:05 -05:00
parent d4696d09eb
commit 7345f330fc
3 changed files with 580 additions and 2 deletions
@@ -0,0 +1,136 @@
# Foundation map handoff — MAP-HANDOFF-2
Status: commit-pinned source/plan baseline; ready for owner review and a separately
approved non-author review. No implementation or push authorized.
## Baseline
Source/plan commit: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`.
Foundation parent: `44f257cb06484feda3412d9382e3587393796353`.
Mapping revision: the separate commit containing this document and the
[technical map](2026-09-06_foundation-technical-map.md).
All file:line source citations in the technical map refer to the source/plan
commit above unless explicitly historical. The map/handoff are not claimed to
exist at that earlier commit. MAP-HANDOFF-1's provisional baseline and delivery
waits were superseded after Jason authorized local commits and Dewey supplied
MS55-DW-3. Shared BUILD-LOG/SESSIONS retain the chronological receipts.
## What is ready
- All R1-R34 mapped to responsibilities; 20 source-linked findings and nine
inspected legacy source files, unchanged from 69d1bb3.
- packages/* succession target reconciled with current extensions/** source and
generated .pi installation. No source move or package-manager change proposed now.
- Dewey's shim, single adapter ownership and package-versus-process-privilege
qualifications adopted in the technical map.
- One small increment: read-only synthetic scope/permission inspector, seven core
acceptance cases plus the owner-reported cross-lane retasking negative scenario.
No live registration, authentication, sandbox or runtime guarantee is claimed.
Jason's ~/.mosaic incident report is context only. No investigation/intervention
there occurred or is authorized. A coordinator message must not itself reassign
an agent, redefine its role or displace an owner-authorized goal.
## Collaboration and verification boundary
MS55-DW-1/2 coordination is complete. MS55-DW-3 reports Dewey's 43-path baseline
commit and index release; parent, path allowlist and empty index were independently
checked locally before staging mapping work. Dewey's native extension test/review
receipts establish that separate baseline, not managed-foundation acceptance.
No mapping review has yet been dispatched or approved by a non-author.
## Non-author review checklist, when authorized
1. Resolve the mapping revision and source/plan baseline independently.
2. Open every cited source location and validate all R1-R34 mappings, not just counts.
3. Challenge reuse/new classifications and the limited inspected inventory.
4. Check packages/* sequencing, single source ownership and trust-boundary separation.
5. Examine broad mounts, shared context, authorization gaps, uncertain retry and
deletion-before-receipt findings and their dependency ordering.
6. Confirm the inspector cannot imply real permission grants or sandbox proof.
7. Return independent findings; do not substitute author fixtures or #55 native
acceptance for runtime enforcement tests.
## Remaining gate
Owner review and separate authorization for non-author review. Implementation,
source moves, migration, push and issue closure remain outside this handoff.
## Source/plan SHA-256 inventory at d4696d09
Every listed file was compared byte-for-byte against the named commit. This
inventory excludes credentials, generated installations and runtime state. The
mapping documents are versioned by their own containing commit, not this input list.
```text
d4c4e08f56c299106133b57e58a78ddfcb015f131036d243d54f42e0fbdc741b .pi/.gitignore
ea5856b5d93811b43b1c1f278eab3283f7f909396dd74464f49dfe1717b51e0e .pi/README.md
3e4498c8066d5a796a8cfe6e07fc1aad118dac2827c771d954b4ae0c38dae84c .pi/SOURCE-SNAPSHOT.json
73823786b54acae627ddefe4b8a258f0554330e49213a118d32e1ffe59c40415 .pi/goal-dev.sh
d213c167d319dbbb42326f68c9c76ec01dbdd42e8f4f226d3232cc5b355bfebc adapters/pi/adapter.sh
a21dc87079d255261ae7318845073ec06bf9df7bac6874012ea0c84b0d1ec12d compose.yaml
ce58408289fceea4b99d8a77c69523a1c04e683f5084f31c7c4199ae0b9934f3 docs/plans/2026-09-06_agent-project-workspace-foundation.md
a49533e1a06e7610583141e7dbf5f529569b9fb3765bf0f4742ff287905f4dfb docs/plans/2026-09-06_foundation-phase2-contract.md
6e2a6b4e0d323940ee5139f5b01f3ecedb23522b9cfa7674fc3d817508cb152f docs/plans/2026-09-06_monorepo-source-layout.md
b746e8c9963dce430b83a7a5fd0973b789a753cc5edd8288291ecdc8f906b2af docs/plans/2026-09-06_ng-goal-footer-dev.md
6e854e83f2a2b26cb93473611b0a47264fb64dd08b6c272c6b18257238915c82 docs/plans/2026-09-06_workspace-schema-and-audit.md
9e0a95865f9479c5f2d06c485513326891727e5295b62c085efe41dddd7dbc0a docs/plans/ROADMAP.md
27fd60f68d30ddc8c1a0cef96714308b8e526f60a17852f7ec21957c1870ec81 docs/plans/foundation-v1-candidate/README.md
7883fde367a3c4377585a5d2f74f09e8f662651b479abb652779c3ed6c7a4c32 docs/plans/foundation-v1-candidate/REVIEW.md
b1a2b4d0df88ba6f7b197252807f3a3925ffff9375f4e70d4ff28593337c3438 docs/plans/foundation-v1-candidate/RUNTIME.md
82564a7d3200afcdda0850a9454cac6e6cd6a76687d2162c13cf214d7eac4607 docs/plans/foundation-v1-candidate/check.py
7806e42cd792935ddba1c8bcac853f049d79eab227fb7191fe622685e699203a docs/plans/foundation-v1-candidate/command-events.fixtures.json
19e9e50359790ec9a4de5b8c817026ac075e254968de1411867222646743d31f docs/plans/foundation-v1-candidate/command-events.schema.json
cbfcb88531838c8c3dd290257e5d9a657e552bb7dd0f67102b49a921a249da45 docs/plans/foundation-v1-candidate/fingerprint-vectors.json
d433d06da5cd38baf9e51c8857244ee70375db3b68e02a5325a6d1c2cc47da85 docs/plans/foundation-v1-candidate/records.fixtures.json
05774aaf6943cb69c113e39ff1c29676a2a230ca7bf665c50dbcaa8049672af6 docs/plans/foundation-v1-candidate/records.schema.json
02a611925923b2592d9e0e67741a542e6c2e8bec06d69ae5700f25c51d720a7a docs/plans/foundation-v1-candidate/runtime.fixtures.json
74deeb4cd6d87ff9306ed088b9641e51f9c41db71589b5364424908842ee51bc docs/plans/foundation-v1-candidate/runtime.schema.json
93d16f38738bb0610d5250ee54c271934e4f2201660becaa72982363d0711fda docs/plans/foundation-v1-candidate/semantic-model.fixtures.json
c89c3bb19624826c1a84658595c71694a1fd371b9155ef50ffa4c265c099daa8 docs/plans/foundation-v1-candidate/semantic-model.py
1551ee0bb11d4a16181186f5091ddbcfcb0ea1e4718997639542beb797442308 extensions/README.md
0850b651309b57a50f2933182376531c8bbcc75ab92d83c1798dfd1637fe8b8b extensions/goal/README.md
9bfcf60097ec83209f5acae443ce48dde55d39343426de63f89997e3275e67ed extensions/goal/index.ts
5db32424e7376f85f22b1055addf3784125da09c3ea23b86a3d0d338f852babd extensions/goal/lib/display.ts
57f1d89c998099b2a9b0c860e70a35db61261a5d1ae7f07cc9acff29fe21042e extensions/goal/lib/executive-update.ts
3837d31fad6481a3c69132ec7fb19849498d5d4c90b0e41eeb683daec19b50a1 extensions/goal/lib/parse.ts
6614b228b3d10252751bc4b68f62ada58f04dfb3a77a51086bb2d7ae42f39c8b extensions/goal/lib/settle.ts
ade39fa3c7a99295712dac41fdfe366384e2cfd695a967c62f0e3f424876ffae extensions/goal/lib/state.ts
78185bb61cb85ae8f2940a89e18063a1d90361d8a869582fff6f4787ec7430dd extensions/goal/lib/store.ts
cad6670a9e8206166b710cd464347aedee6401be9307248b10f9fcfc295585f0 extensions/goal/test/communication-closeout-contract.test.ts
8b28e3c63607dfc321e6b74cd967e92ae6f72ed3e31e2286fcf9a5964394bb02 extensions/goal/test/display.test.ts
66d9437111c4574ea255affe539b78c6ad896d7f43de191d154873b9ef500501 extensions/goal/test/executive-update.test.ts
dfb172ddd228205d3e72a47dfe11372b9cc39e4584017461efe037aa3dc8c08a extensions/goal/test/fencing.test.ts
ac5a69536ee07cc31c6f3a738ca2d5c446689bbfdae05dafffd9c6302864b96c extensions/goal/test/fixtures/.gitattributes
bbea48a46b1f8da7bc759f86856fb52830b7dde456b826317163c6dc6ccab319 extensions/goal/test/fixtures/skills-local/ms-executive-update/SKILL.md
c797776e992c4b1187d786ccb0cce57ca817ebd91ec56caebd4bc220d660ff9b extensions/goal/test/fixtures/skills-local/ms-honesty/SKILL.md
0132ad6508df2bcba0df7fb417e06cbe90c7ea663e334f2176c8973757bb4809 extensions/goal/test/fixtures/skills-local/ms-proactive-agent/SKILL.md
be377aa1e3128efddc00c651771e145acc6cb9d5c6f2599260d1e00ef617ac7d extensions/goal/test/goal.test.ts
3a03b44aea1a9f316ee1138092e3cb55507cdff34ca2cbf828d45ed90a46b699 extensions/goal/test/progress.test.ts
2a33f36881d38656e26ca7580907cf2b22df69d94243ebdfee7adef140d77040 extensions/goal/test/quiet-wait.test.ts
38df8499a64dd465ff5011b06fce80c0793bb53eb7c33bb685001e56451647f3 extensions/goal/test/runtime.test.ts
ea7e9e86782a8716a5e33a27d653227d162c595ba4aa02d1ee691fd4ddead081 extensions/mosaic-core/lib/adapter.ts
4604ae28cd16966d0e447a4e8075bbe320c3119d0a4c8fe870b98e2bb4fb6d03 extensions/mosaic-core/lib/enforce.ts
f291b11818ba01567c1f42bbd36fae63a2398a347426d863ecc6bdb7820358c7 extensions/mosaic-core/lib/gate-record.ts
8313837181a1ac07e7ca58f99873e66b305cd5b5e8d125c189b14d231bdc4620 extensions/mosaic-core/lib/goal-policy.ts
cea0165ab9b323c083ce2fcb1d9fa835e1ee534045cd67536aec17c339457d45 extensions/mosaic-core/lib/incarnation.ts
b52a129c97b822209acdf96ddae49c970bbb9a4dd74ac5bbe7440418e9cb2af1 extensions/mosaic-core/lib/journal.ts
b0c12f2cb9e974ad72d28773617a862e5e880612d63d1edc513c4e057d6f21d9 extensions/mosaic-core/lib/loader.ts
aabc1046dca38f03cfbe111259a21521b24b250736be42f548a57a0e315cf70b extensions/mosaic-core/lib/policy.ts
f174864dc499d0a39e7786e1220c54df3e9af2cd8523476c3d4bf2e2d5928264 extensions/mosaic-core/lib/proposal.ts
00448f6f00f72163bcde3e0a6fc9b87023c46a225316df7530bc14d9953b5e12 extensions/mosaic-core/lib/reconcile.ts
1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555 scripts/agent.sh
fe5d3e89272d3b04db687eabed30a95dde480a2f7bc784cd27e43fa9321f15a6 scripts/auth.sh
a8a41274c06ab6fe38c42d1e96db115b8d65b03a87ed1796c4d37288258a1d12 scripts/goal-dev.sh
430ee6bc4fcfbe4b9ac030aaa19cdb6fdc7407e1b17253b80178b9b0523b5a3a scripts/mosaic-config.mjs
525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83 scripts/mosaic-task.mjs
957ef76f949c2eb2e472182261bf2d1619e0cde44c506ab2bbb5c25dc063864d scripts/reset.sh
eee8c0a9c5708cbc9d0922ea733f09b34d50da8816f95a43e5afe3e3dfc24dbb scripts/sync-dev-extensions.sh
5d7b687f16fd1a9414b229501177d530ba3af4eadd3cac319b33f38fdba9bf99 scripts/test-extension-package.sh
4c5db63da5194a937ee4a488b796f60876a780482812d949e3337bf0d274a974 scripts/test-goal-native.py
4b210d5d785d06d699ceaa902ccb0451c09cb19397e861521f825c09e9e33ae5 src/load-contracts.sh
6749ebe3d0433b3dfefb40a44d58c4ca2606ab9f4ce01457dd52767059b7b13b src/run-agent.sh
ece76e2690012b53087357d467edf3f2c3f872d5db28bd97eaa1bbb217f5ed57 tasks/ng-goal-footer-implementation.json
d50fd5dbbd08a39b2a91424392d2b31bc2f9b4a1e3c3d09ee8061d5776989459 tasks/ng-goal-footer-review.json
```
@@ -0,0 +1,352 @@
# Foundation technical map — #53 / #55
Status: source/plan baseline pinned; prepared for owner review. Author: darkwing.
Scope: documentation/read-only investigation and explicitly authorized local
baseline/mapping commits; no implementation, migration, push or issue closure. Prepare for independent review, not self-approval.
## Authority and coordination
The active operator goal authorizes mapping the accepted phase-2 foundation with
Dewey, aligning canonical directories, identifying reuse/change and recommending
one small user-testable increment. This supersedes CURRENT's earlier wait for
mapping authorization; it does not reopen phase-2 acceptance.
MS55-DW-1: Dewey requested scope/path coordination. The attempted direct tagged
reply returned exit 2: submission could not be confirmed. Jason identified a known
tmux-tool bug. Delivery remains unknown; no blind resend or private-pane polling.
Dewey subsequently directly acknowledged MS55-DW-1 and recorded the agreement in
his #55 layout plan. Receipt is now settled; no resend is needed. He is waiting
for Jason's mapping-goal authorization in his session; this session's active goal
already authorizes its own mapping work. Do not assume his work has started.
Acknowledged division:
- Darkwing: this map, foundation requirement-to-code trace and CURRENT integration.
- Dewey: #55 canonical source, package/install boundaries and phased inventory.
- Shared BUILD-LOG/SESSIONS: append-only; no exclusive claim.
- Darkwing will not edit extensions/**, .pi/**, #54/#55 plans or Dewey's packaging
and goal test scripts. Accepted foundation documents remain stable inputs.
## Initial measured directory alignment
Repository HEAD measured at this checkpoint: 69d1bb3aa4b826218aa4cca3710f2d98c0b9d7ba.
The working tree includes uncommitted foundation and separate #54/#55 work;
HEAD alone does not identify that newer source. Exact content hashes are required
for the eventual review handoff.
| Boundary | Existing location | Mapping disposition |
|---|---|---|
| Immutable worker instructions | contracts/ | Retain dedicated contract ownership; draft schemas are not installed contracts. |
| Reviewed role authority | roles/ | Retain; scope registration must narrow, not replace this authority. |
| Harness integration | adapters/ | Retain adapter boundary; trace mediated-runtime changes before proposing placement. |
| Skills | skills/ | Retain declarative resources; not automatically JavaScript workspace packages. |
| Goal extension/support source | extensions/goal/, extensions/mosaic-core/lib/ | #55 canonical-source input; do not duplicate or relocate in this mapping. |
| Generated native installation | .pi/extensions/ | #55 installation output, not canonical source. |
| Launch/build/test utilities | scripts/ | Distinguish tooling from future service logic; no moves proposed yet. |
| Existing runtime code | src/ | Inventory responsibilities before proposing apps/ or packages/. |
| Plans and evidence summaries | docs/ | Keep planning separate from runtime authority/evidence storage. |
Directory existence was checked locally. The goal/source-install boundary comes
from Dewey's #55 layout record; its source/package verification is not foundation
runtime admission evidence. No empty apps/packages scaffolding is proposed.
## Initial workplan (historical)
1. Trace actual source entrypoints and state/authority paths against R1-R34.
2. Classify reuse unchanged, reuse with changes, replacement, and new component;
identify dependencies and proposed canonical placement without moving files.
3. Reconcile package/source boundaries with Dewey, settling MS55-DW-1 receipt.
4. Recommend one bounded user-testable increment and produce a hashed independent-
review handoff with unresolved risks. Owner review remains the completion gate.
## Source trace checkpoint: launcher, adapter, policy and evidence
Read directly on 2026-09-06 at 06:59 UTC. These classifications concern the
inspected paths, not a claim that no similar capability exists anywhere else.
| Source locator | As built | Reuse/change classification and requirement impact |
|---|---|---|
| scripts/agent.sh:78-130 | Reads reusable seat definition; copies SOUL into a shared per-agent data-root path; writes a seat record if absent. | Reuse identity source concept (R1). Change materialization to immutable execution-specific inputs (R16/R17); preserve canonical source ownership rather than duplicating definitions per workspace. |
| scripts/agent.sh:132-170 | Default session is agent-NAME; declared role resolves tools, intersected with requested tools. | Replace global default with explicit project/workspace/session resolution (R3/R4/R12). Reuse narrowing principle, not this as a full scope authorizer. |
| scripts/agent.sh:181-199 | Mission copied to shared per-agent path; workspace defaults to agent name; native Compose launch. | Change launch orchestration and mission snapshots. Existing directory names cannot establish membership. R34 requires a mediated client path, not merely native launch with another flag. |
| adapters/pi/adapter.sh:23-50 | Changes cwd, supports ephemeral/fork/persistent modes; a nonempty session directory adds -c; tools are explicit or disabled. | Retain adapter separation and explicit tool/discovery controls. Replace directory-nonempty/latest selection with exact binding and genuine-first-use checks. Preserve fork/history behavior only after explicit compatible adoption. |
| adapters/pi/adapter.sh:63-96 | Native TUI or print; ambient extensions/context/templates disabled; explicit provider/model and prompt. | Reuse explicit configuration/discovery suppression where verified. New mediated transport/tool gateway required for R34/R33. Do not enable the native #55 extension in managed workers as an implicit shortcut. |
| scripts/mosaic-task.mjs:252-273,670-676 | Closed role fields, filename identity, known unique tools and network enum; resolve-role emits tools and network. | Reuse validation principles and tests with changes. This role format does not express the new project/workspace registrations or 29-operation catalog. Network metadata emission is not evidence of network enforcement (R13/R33). |
| scripts/mosaic-task.mjs:362-378 | Task tools intersect mission tools; empty intersection yields tool-free. | Reuse least-privilege operation, expand to all required ceilings, targets and current revisions. Do not infer authorization from tool presence or combine assignments. |
| scripts/mosaic-task.mjs:295-325 | Exclusive wx creates input snapshots; writeOnce writes then closes, without fsync in this helper. | Reuse exclusive-create intent and snapshot conventions. Change publisher for durable commit ordering, classifications, trusted origins and recovery. Exclusive creation alone is not crash durability. |
| scripts/mosaic-task.mjs:442-466 | Result stores prompt/response, task/session/tools, exit/signal/model and times, then writeOnce. | Retain legacy run evidence and useful provenance fields. Do not treat it as the R14/R33 invocation ledger: new scope/assignment/authorization/limits/intent/observation records and controlled detailed evidence are required. |
### Proposed component boundaries, not source moves
- Scope/reference/policy resolution: a reusable domain module with no process,
credential or filesystem-effect authority. Existing validation/intersection code
is an input, not permission to copy its narrower semantics unchanged.
- Managed launch/control coordination: separate runtime responsibility above the
harness adapter; owns claims, current intent and authenticated control routing.
- Pi adapter: owns engine protocol translation and exact-session/config binding,
not canonical project membership or global policy decisions.
- Trusted evidence publisher/supervisor: distinct from worker output. Owns durable
intent/outcome publication and trustworthy stopping observations.
- Keep proposed modules unallocated to new apps/packages until their dependency
and build boundaries are reconciled with Dewey. Existing scripts remain untouched.
### Dependency implications
A read-only scope/permission inspector can precede managed execution: it needs
strict records, a coherent synthetic reference graph and a clearly labelled
permission calculation. It does not need provider credentials or Pi launch.
Live registration needs the trusted publisher and protection from legacy broad-
mount paths first. Managed launch then depends on scope resolution, publisher,
claim/control protocol, adapter admission and real isolation/stopping proof.
### Exact inspected file identities
- `scripts/agent.sh`: `1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555`
- `adapters/pi/adapter.sh`: `d213c167d319dbbb42326f68c9c76ec01dbdd42e8f4f226d3232cc5b355bfebc`
- `scripts/mosaic-task.mjs`: `525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83`
## Mount, context and lifecycle trace
Read-only source inspection, 2026-09-06 07:01 UTC. No reset, prune, retry,
container launch or credential-file read was performed.
| Source locator | Observed behavior | Classification / required boundary |
|---|---|---|
| compose.yaml:38-43 | Whole configured data root mounted at /var/lib/mosaic without :ro; auth file separately mounted read-only. | Replace mount design for managed admission. Read-only auth mounting does not establish credential separation from the engine, and whole-root exposure is not workspace isolation. Preserve runtime-only credential handling, not broad mounts. |
| src/run-agent.sh:20-41 | Adapter name/path checks; dispatch after generating one shared /var/lib/mosaic/system-prompt.md. | Reuse dispatch validation with changes. Context builder must publish execution-specific immutable inputs, not a shared prompt destination. |
| src/load-contracts.sh:18-58 | Governance files required; optional seat SOUL; OUT.partial is a fixed sibling staging name. | Reuse governance precedence and missing-source refusal. Replace shared staging/output with uniquely owned execution snapshots and verified publication; current concurrent same-output writers can contend. |
| src/load-contracts.sh:68-77,81-98 | Appends every user/*.md, then mission objective/directives. Header's stated layer order differs from actual user-before-mission order. | Replace blanket context discovery with classified, authorized selection and explicit ordering. Actual code, not header prose, defines this baseline. R6/R16/R17 and context privacy require recorded source revisions. |
| scripts/reset.sh:16-48 | Loads configured data root, rejects root symlink/resolution mismatch/missing marker, then recursively removes that root. | Retain useful refusal checks, change lifecycle integration before protected foundation state exists. Despite hard-coded-path commentary, implementation compares resolved path with configured TARGET, not a fixed literal. No active-claim/reference protection or reset receipt is present in this path. |
| scripts/mosaic-task.mjs:548-595 | Retry reads task snapshot, redirects relative mission to recorded snapshot, then runs it as a new run. | Reuse provenance and original-record preservation. Do not use as uncertain-effects recovery: no old process/effect reconciliation gate is visible in retryRun. New run identity alone does not make replay safe. |
| scripts/mosaic-task.mjs:598-641 | Prune sorts run directories, keeps a count, defaults to preview; --yes removes each directory before appending its receipt. Directory-read failures are caught as no entries. | Reuse preview/explicit-apply UX, not protected-retention semantics. Add live-reference/claim protection, distinguish unreadable state from empty state, and make deletion/receipt failure recoverable. Deletion-before-receipt exposes an uncertainty window. |
### Proposed authority and state ownership
| Responsibility | Proposed owner | Required separation |
|---|---|---|
| Approved context selection and snapshot construction | Trusted context builder under launch coordinator | Does not trust workspace file discovery or client classification; private inputs stay out of shared work metadata. |
| Actual mounts, egress and process cohorts | Sandbox supervisor/gateway | Separate command jobs from credential-bearing engine; no worker access to evidence/policy/control roots. |
| Canonical records and required evidence | Trusted publisher and retention coordinator | Writer/retention share a serialized protection boundary; a worker cannot prune its own audit trail. |
| Uncertain outcome recovery | Authorized recovery coordinator plus trustworthy observers | Distinct from replay; must establish stopping and reconcile effects before admitting replacement/retry. |
| Native extension development installation | Dewey's #55 tooling | .pi installation acceptance is not evidence that container mounts or managed lifecycle meet these requirements. |
### Ordering constraint for the rewrite
Before live foundation state is treated as protected, close legacy broad-mount
launch paths into that state and integrate reset/prune protection. Before managed
Resume/Fresh, provide exact scoped session/claim resolution and immutable context
snapshots. Before uncertain-effect retry, provide trustworthy stopping, evidence
availability and explicit reconciliation. These are dependencies, not source moves
or authorizations to repair the current scripts during mapping.
### Additional source identities
- `compose.yaml`: `a21dc87079d255261ae7318845073ec06bf9df7bac6874012ea0c84b0d1ec12d`
- `src/run-agent.sh`: `6749ebe3d0433b3dfefb40a44d58c4ca2606ab9f4ce01457dd52767059b7b13b`
- `src/load-contracts.sh`: `4b210d5d785d06d699ceaa902ccb0451c09cb19397e861521f825c09e9e33ae5`
- `scripts/reset.sh`: `957ef76f949c2eb2e472182261bf2d1619e0cde44c506ab2bbb5c25dc063864d`
- `scripts/mosaic-task.mjs`: `525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83`
## Complete requirement responsibility index
This index covers every accepted requirement, not every implementation. “New”
means not provided by the inspected paths; repository-wide absence is not proven.
Source detail is in the two trace tables above; accepted behavior is in the
foundation plan R1-R34. Uninspected responsibilities remain explicit gaps.
| Requirement | Proposed responsibility | Mapping finding |
|---|---|---|
| R1 | Identity | Launcher identity reuse; scoped runtime binding changes |
| R2 | Scope/policy | New registration/delegation resolver; existing tools-only role validation is insufficient |
| R3 | Scope/policy | New single-parent project/workspace graph and explicit membership |
| R4 | Session/control | Replace global session default with scoped identity |
| R5 | Scope/policy | Explicit selection resolver replaces agent-name workspace default |
| R6 | Context | Replace shared/global work input paths with authorized snapshots |
| R7 | Session/control | Exact Resume/initial/Fresh state; replace nonempty-directory continuation |
| R8 | Work coordination | New assignment selection/Abandon/prerequisite transitions |
| R9 | Session/control | Authorized service launch and work-record recovery |
| R10 | Session/control | New exclusive scoped claim; scaling/budgets remain later-phase requirements |
| R11 | CLI/client | New shared operation interface; no client-owned task truth |
| R12 | Messaging | New explicit scoped addressing/delivery; not established by inspected launcher |
| R13 | Sandbox | Replace whole-root mount boundary and prove containment |
| R14 | Evidence | Expand run provenance into trusted classified action evidence |
| R15 | Governance | Retain explicit owner phase and user-test gates |
| R16 | Context | Replace shared SOUL materialization with immutable execution snapshot |
| R17 | Context | New comparable fingerprint and cross-interface notice flow |
| R18 | Scope/policy | New mission ownership/parent graph and reference checks |
| R19 | Work coordination | New bounded decomposition and non-author acceptance checks |
| R20 | Work coordination | Separate taskless read/chat from assigned changes |
| R21 | Session/control | New active-conflict response and explicit connection |
| R22 | Context | New transcript-specific visibility and handoff checks |
| R23 | Scope/policy | New revocation propagation linked to supervisor stopping |
| R24 | Session/control | New controller/observer generations and transfer |
| R25 | Session/control | New fenced, verified-safe replacement protocol |
| R26 | Recovery | Replace blind retry use for uncertainty with evidence-based reconciliation |
| R27 | Evidence | New fail-closed recording/admission and preauthorized fail-safe stop |
| R28 | Context | Replace blanket user Markdown inclusion with classification/selection |
| R29 | Retention | New retirement/reopen without deletion; protect required evidence |
| R30 | Session/control | New reviewed legacy adoption; preserve originals |
| R31 | Work coordination | New current-intent reconciliation and stale-action rejection |
| R32 | Scope/policy | Extend reviewed ceilings with standard scope roles and narrowing |
| R33 | Evidence/sandbox | New mediated invocation records plus actually enforced limits |
| R34 | CLI/client | New Mosaic-controlled terminal; retain Pi behind reviewed adapter |
## Canonical placement matrix for Dewey reconciliation
ROADMAP.md:127-166 records an owner decision, not just an optional legacy pattern:
post-M20 succession uses packages/*, with restructuring delayed until script
replacement to avoid two migrations. This corrects any reading of the initial
map as leaving the entire package target undecided. #55 extensions/** is current
canonical source, not an implicit repeal of that post-M20 destination.
| Responsibility | Current source/input | Post-M20 proposed destination | Packaging/ownership boundary |
|---|---|---|---|
| User CLI and managed terminal | scripts/agent.sh and other wrappers | packages/mosaic/ | CLI consumes domain/runtime APIs; wrappers retire only after replacement acceptance. |
| Engine/session/control/supervision | src/, adapters/, launcher orchestration | packages/agent/ | Runtime owns process/session protocol; adapter internals do not own global role authority. |
| Strict records, references and policy intersection | scripts/mosaic-config.mjs, parts of mosaic-task.mjs; candidate schemas | packages/config/ | Pure validation/resolution separated from effectful publication; first inspector can exercise this boundary. |
| Provider/account materialization | #50 plan/current auth tooling | packages/auth/ | Credential ownership stays here; no credential migration or refresh experiment in mapping. |
| Evidence/work/recovery coordination | mosaic-task.mjs portions plus new responsibilities | Initially packages/agent/ internal modules | Separate trusted writer and policy interfaces; do not invent extra top-level packages without independent build needs. |
| Contracts/roles/missions/tasks/skills | Existing dedicated directories | Retain declarative directories | Packages consume reviewed resources; no promotion of drafts or workspace-written authority. |
| Goal extension and imported support | extensions/goal/, extensions/mosaic-core/lib/ | Current source retained pending explicit M20 extension packaging decision | Dewey owns inventory/provenance; whether to stage a package artifact or move source later remains a specific unresolved boundary. |
| Native development installation | .pi/extensions/, sync/test scripts | Generated installation remains separate | Never package .pi/state or treat native acceptance as managed-runtime proof. |
ROADMAP's target also retains src/ while describing packages/agent as absorbing
src/adapters. The map must distinguish a retained container entry shim/build input
from absorbed runtime implementation; do not move both copies and create competing
sources. That exact shim boundary and extension distribution placement need Dewey's
reconciliation. No package-manager change or empty package scaffolding is authorized.
## Earlier review-baseline gate (resolved below)
Dewey's #55 reconciliation and ms-archify require commit-pinned code and plan
citations for a formal map. The accepted phase-2 plan and #55 work are currently
uncommitted. Current hashes make this preparatory inventory reproducible, but do
not satisfy the formal commit-pinned handoff gate. No commit/push is authorized
by this goal. Do not label this document an independently review-ready Archify map
yet or use HEAD to pretend it contains the dirty source.
Remaining ready work: inspect config/auth/interface inventories read-only and
specify the first inspector's exact acceptance boundary. External dependencies:
Dewey's package/shim reconciliation and an owner-authorized baseline strategy
before formal independent review. Review dispatch itself is a separate gate.
## Config/auth/interface inventory and first-increment boundary
Read source only; no configuration, credential contents, auth status, login or
refresh operation was accessed/executed during this checkpoint.
| Source | Finding | Disposition |
|---|---|---|
| scripts/mosaic-config.mjs:39-61,76-174 | Config path can be overridden by MOSAIC_CONFIG; regular-file/symlink and strict field checks; canonical data-root checks exclude root/home/config ancestors; lstat errors are treated as missing. | Reuse strict validation and protected-root principles; reconcile the override with sole-config canon rather than silently adopting a second config authority. Distinguish missing from unreadable/error where fail-closed diagnostics matter. |
| scripts/mosaic-config.mjs:194-239 | Bootstrap uses exclusive create, validates existing config without replacement; validate/env expose resolved non-secret fields and shell quoting. | Retain bootstrap-only creation and read-only resolution. Future domain validation must not bootstrap or load live config when running a synthetic inspector. |
| scripts/auth.sh:19-96 | Config-backed account directory and reporting of provider/type/permission metadata. Reads credential JSON when invoked; parse errors include parser text. | Preserve ownership separation, not a proven redaction guarantee. Do not reuse credential-reading report functions in the inspector. Error disclosure and account materialization belong to separate auth review. |
| scripts/agent.sh:28-64 | Per-launch named account checks readability, symlink and mode 0600, exports selected mount source; no project selection flag in this parser. | Reuse explicit refusal rather than account fallback. Replace flat account/path selection with #50 registry bindings at the later auth boundary; introduce full scope at the managed CLI, not by inferring it from cwd. |
### Recommended increment: synthetic scope/permission inspector
Purpose: let Jason see whether one agent's project/workspace membership and
permissions resolve as intended before any live state or worker can be affected.
This is a recommendation for a later charter, not an implementation task started.
Input: one explicit local synthetic bundle containing a coherent graph of agent,
project, two workspaces, registrations, mission/task/assignment and declared mock
policy sources. No live registry, credential, engine history or data-root lookup.
Independent shape fixtures cannot simply be concatenated into this graph.
Output: deterministic text plus structured result, identifying selected agent,
project and workspace, reference errors and the calculated least-privilege result.
Every successful output says preview only: no live registration or permission grant.
Unknown/missing policy is a refusal, never an empty layer skipped during intersection.
Acceptance cases for the implementation charter:
1. Valid bundle resolves the explicitly named first workspace and its permitted read.
2. Same agent, second workspace without registration: refuse without revealing that
workspace's private payload or selecting the first workspace instead.
3. Missing parent, multiple/incorrect ownership, dependency cycle and stale revision:
report the violated rule; do not repair or invent references.
4. Broader task grant cannot widen mission/registration/agent ceilings; another
assignment cannot supply missing permission. Explicit empty grants allow nothing.
5. Ambiguous name, duplicate ID/revision, unknown field and malformed UTF-8/path:
reject before producing a permission preview that appears valid.
6. Source bundle stays byte-identical; no writes to config, data root, .pi/state,
roles or installations; no child engine, network, credential or migration action.
7. Jason runs the positive and negative examples and understands both the scope
display and the preview disclaimer before any dependent increment is chartered.
Proposed exit classes (not installed): 0 valid preview, 2 malformed/invalid graph,
3 simulated permission refusal, 4 input/I/O failure. Final naming/packaging belongs
to the later charter, consistent with packages/config domain ownership and the
packages/mosaic CLI target. No npm/Turbo change is needed to approve this boundary.
Deferred: authoritative publication, real authentication, sandbox tests, process
control, native/managed goal integration, OAuth refresh, live registration, session
adoption, reset/prune changes and repository restructuring. These require their
own dependencies, implementation tests and owner acceptance.
### Config/auth/interface source identities
- `scripts/mosaic-config.mjs`: `430ee6bc4fcfbe4b9ac030aaa19cdb6fdc7407e1b17253b80178b9b0523b5a3a`
- `scripts/auth.sh`: `fe5d3e89272d3b04db687eabed30a95dde480a2f7bc784cd27e43fa9321f15a6`
- `scripts/agent.sh`: `1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555`
## Owner-reported cross-lane retasking scenario
Jason reports that orch-01 in the separate ~/.mosaic environment redirected two
agents from their owner-set goals into supervisor work for another agent, outside
their lanes. This is owner-reported context, not an independently investigated
incident or a proven root-cause diagnosis. Jason explicitly prohibited involvement
in that environment's failure; no inspection, messaging or intervention there is
part of this goal.
Map to R8/R12/R19/R23/R31/R32: current goal/mission/assignment and scope authority
must be checked when reassignment is requested. A coordinator title, message or
new role description is not authorization. A goal reminder is not an enforcement
boundary. Another workspace's permission cannot be borrowed, and changing a scope
role cannot silently replace reusable identity or the owner's approved intent.
Add this adversarial case to the proposed inspector/implementation acceptance set:
- Agent A has an active owner-authorized assignment in workspace A. A coordinator
from workspace B requests reassignment into supervision for another goal.
- Without explicit applicable delegation and a valid recorded change within owner
intent, refuse the request; preserve A's goal/assignment and report the conflict.
- A message alone cannot mutate assignment, role, goal or acceptance state.
- If a properly authorized change is requested, account for underway effects and
follow reconciliation; never abandon old work merely because a new message arrived.
- Later runtime tests must prove original work remains selected and stale/cross-scope
actions are fenced. An offline preview alone cannot establish this behavior.
## Integrated baseline and reconciled ownership
Source and accepted-plan baseline: d4696d09eb1b5dcf1028f30db2cd63735f51cb16,
whose parent is foundation baseline 44f257cb06484feda3412d9382e3587393796353.
All source file:line citations in this map now refer to d4696d09 unless explicitly
labelled historical. Inspected legacy source bytes are unchanged from 69d1bb3.
The mapping revision is the separate commit containing this map and its handoff;
no circular claim that d4696d09 already contains these mapping documents is made.
Jason authorized scoped local baseline commits. Dewey's MS55-DW-3 receipt was
verified locally: exact parent, 43 allowed paths and an empty released index.
The former baseline-authorization and coordination waits are resolved. No push,
implementation, migration or independent review is authorized by that resolution.
Dewey's MS55-DW-2 qualifications are adopted:
- extensions/** remains current canonical source until explicitly chartered M20
packaging; mosaic-core/lib remains internal support, not another entrypoint.
- Post-M20 src/ retains only unavoidable bootstrap/exec shims. Current material
context behavior migrates/replaces, never duplicates packages/agent logic.
Adapters also have one canonical post-M20 owner under packages/agent.
- packages/mosaic handles presentation/routing, not policy truth. packages/config
owns pure validation and deterministic policy calculation, not publication.
- packages/agent contains runtime coordination and separated writer/recovery
interfaces. A package is not a process trust boundary: engines must not inherit
publisher/supervisor privileges simply by importing the same package.
- packages/auth contains code/metadata, never packaged secrets. Declarative
top-level directories remain authoritative inputs, not generated installations.
The initial inspector remains the recommended bounded increment. No independently
built packages, empty scaffold or package-manager migration is needed now. Exact
extension distribution packaging and any retained shim are implementation-charter
choices constrained by the reconciled ownership rules, not unresolved permission
to create duplicate sources.
Next gate: owner review of the mapped baseline and separate authorization of a
non-author review. This mapping prepares that handoff; it does not supply the
reviewer's verdict or authorize the inspector implementation.
+92 -2
View File
@@ -7,11 +7,101 @@ update this file to the next action). No ambiguity, no re-planning.
## Next action
Review `docs/plans/2026-09-03_auth-provider-harness-registry.md` against its ten review gates; revise until owner-approved. No implementation starts before approval.
Owner review of the completed technical map and separate authorization of a
non-author review. Handoff: `docs/plans/2026-09-06_foundation-map-handoff.md`
(MAP-HANDOFF-2); map: `docs/plans/2026-09-06_foundation-technical-map.md`.
Source/accepted-plan baseline: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`,
parent `44f257cb06484feda3412d9382e3587393796353`. Mapping documents are pinned by
the separate commit containing this checkpoint, not falsely attributed to d4696d09.
Dewey's MS55-DW-3 commit, 43-path scope, parent and index release were verified.
Jason's conditional resumption authorization is satisfied. R1-R34 coverage,
reconciled package/source ownership, source identities and the bounded inspector
recommendation are ready for owner review. Preparing that handoff does not imply
independent approval. No implementation, migration, source moves, push or issue
closure is authorized. No involvement in the reported ~/.mosaic failure.
The extension owns the active mapping goal's lifecycle; this file records task
progress and the next approval gate. Earlier phase-2 acceptance remains valid.
## Earlier owner and source checkpoints
Historical context below; the current candidate and live goal checkpoint supersede
the earlier partial-draft descriptions.
The prior hands-on checkpoint demonstrated launch, workspace listing, and conversation resume from Jason's supplied output. Fresh context and mission recovery were not tested. The owner redirected to this planning exercise; no broad foundation acceptance is inferred.
Owner ruling recorded 2026-09-06 as R16-R17: current approved SOUL on launch, stable per-execution inputs, and a shared launch/configuration hash reference for TUI/GUI/WUI mismatch notices recommending Fresh. D10 is partly resolved. Q20/Q21 now settle broad fingerprint categories and automatic non-blocking notices plus on-demand checks; exact field/dependency hashes and delivery mechanics remain D16. This does not advance the phase or authorize implementation.
Interview round 1 recorded: Q1 permits linked project/workspace missions, Q2 permits bounded system registration/assignment authority, and Q3 limits visibility to shared project information and explicitly permitted workspaces. Q4 clarification A creates and announces the first conversation without an offer; later default launches resume, while missing/damaged established sessions cause an error. Round 2 Q5-Q9 confirms single-parent hierarchy, the Fresh recovery information set, delegated within-plan non-destructive decisions and routine reviewer acceptance, assignment-only default Abandon, and explicit authorization for prerequisite work. Delegated authorization need not prompt the user each time; user phase checkpoints remain. Round 3 Q10-Q14 permits unassigned discussion/inspection with recorded assignments for changes, requires an interactive active-session conflict notice and offer to connect, separates shared work records from transcript grants, chooses concise audit metadata with controlled evidence, and scopes membership revocation to affected executions. Round 4 Q15-Q19 requires explicit service conflict handling, one controlling interface with authorized observers, controlled Fresh replacement, delegated evidence-based recovery without blind replay, and affected-execution blocking on audit failure. Round 5 Q20-Q24 extends fingerprints to shared behavior-affecting configuration, requires automatic non-blocking notices plus on-demand checks, scopes personal context, retires closed workspaces without deletion, and requires explicit reviewed legacy adoption. Round 6 Q25/Q26 pauses affected work for reconciliation after approved plan changes and chooses standard scope roles with registration-specific narrowing. Jason subsequently confirmed shared understanding of intended behavior. Jason then authorized phase 2. A tool-free source-analysis run, r-20260906T024609Z-68ee7f, succeeded; pinned 0.84.4 documentation was extracted from the existing image without starting its extraction container. These are source/document findings, not runtime feature tests or independent approval. The first contract candidate is partial. Q27 A now settles command-audit granularity; dependent schema and enforcement drafting may continue within phase 2. Full schema/plan approval remains pending.
## Accepted phase-2 checkpoint (historical)
- Goal: issue-53-phase2. Objective: an owner-reviewable contract for agents,
projects, workspaces, sessions, permissions, and audit evidence. Completion
owner: Jason. Author/workspace/session remain those recorded below.
- State: satisfied. Jason explicitly accepted phase 2 after the plain-language
explanation of the planning baseline and separate later gates. P2-7 is complete.
REVIEW.md retains D1-D16 and the unproved implementation mechanisms. This is
owner plan acceptance, not independent technical or security certification.
- Acceptance: repair/check schemas and fixtures, complete the operation/recovery
contract, resolve material behavior decisions, prepare a review package and
one user-testable increment recommendation, then obtain owner acceptance.
- Evidence: `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 command
and 38 record shape cases, 16 path cases, 7 restricted-domain hash vectors,
155 runtime/control/artifact cases and 35 synthetic rule-model cases. Ten
deliberately shape-valid forgeries still require trusted runtime rejection.
These are not runtime security tests or independent acceptance.
- Reboot fixture defects were repaired, not discarded. Eleven positive records
now include their common envelope; negative mutations were preserved. Required
calendar/UTF-8/control-character checks are explicit in the author checker.
- Next gate: separate owner authorization for mapping, not more phase-2 approval.
No mapping or implementation started. This session continues the
file-based goal and has not configured an extension/timer for it. Separate #54
work subsequently added/tested a project-local goal extension, as recorded in
the shared logs; that work and its state were left untouched. This session has
not migrated issue-53-phase2 into that runtime. Elapsed time never grants approval.
- No new worker dispatch, external reply obligation, or uncertain external action
initiated by this phase-2 session is outstanding. No numeric work budget supplied;
aggregate usage remains unavailable.
- Authority remains phase-2 planning and read-only investigation. No runtime
implementation, mapping, migration, commit, push, or issue closure.
## Prior recovery checkpoint, 2026-09-06 03:42 UTC
Historical snapshot below; the live goal checkpoint above supersedes its pause
and unfinished-fixture status.
- Goal: issue-53-phase2. State: paused by owner steering. Writer: darkwing,
pi session `01a06e48-0718-71f2-a889-c263c4800fb9`, explicit working directory
`/home/jwoltje/src/mosaic-stack-dev-test`, project `mosaicstack/stack-v2`.
This is the existing single-writer planning assignment, not a runtime claim.
- HEAD remains `69d1bb3`. Preserved all uncommitted planning and unrelated skill
work. No reset, cleanup, commit, push, or implementation occurred.
- Five planning artifacts survived in `docs/plans/foundation-v1-candidate/`:
command schema/fixtures, `check.py`, and record schema/fixtures. The three
command-check file hashes match the pre-reboot checksums.
- `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 shape fixtures
and 5 deliberate shape-valid forgeries. This does not prove runtime security.
- The unfinished record checker is NOT integrated into check.py. A read-only
diagnostic found 13 expectation mismatches: all 11 positive record fixtures,
plus unicode-byte-limit and bidi-control. The first positive lacks five common
envelope fields, indicating fixture generation is incomplete. Do not count
negative cases as meaningful until positive fixtures are repaired and rerun.
- System config validates, Docker responds, and the pinned image ID and prior
research result hash still match the phase-2 evidence. No Mosaic worker
container was running at inspection. Pinned temporary docs remain available.
- Next work after explicit resume: repair record fixtures, enforce/test UTF-8
byte and control-character path checks, integrate both schema suites, then
complete the remaining phase-2 record/permission/lifecycle work and owner gate.
- No outstanding assistant-initiated external action or reply is known. Wake is
manual: Jason sends a resume instruction. No timer or automatic continuation
is registered. Aggregate usage is unavailable; no numeric budget was supplied.
## Queue (ordered per docs/plans/ROADMAP.md)
1. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation
1. Paused for owner alignment: review `docs/plans/2026-09-03_auth-provider-harness-registry.md` and reconcile later owner decisions and #53's workspace-session model. Gate 7 remains unresolved. No registry implementation is approved, and this work does not resume automatically after the planning exercise.
2. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation
## Rules