diff --git a/docs/plans/2026-09-06_foundation-map-handoff.md b/docs/plans/2026-09-06_foundation-map-handoff.md new file mode 100644 index 00000000..0efc06ad --- /dev/null +++ b/docs/plans/2026-09-06_foundation-map-handoff.md @@ -0,0 +1,136 @@ +# Foundation map handoff β€” MAP-HANDOFF-2 + +Status: commit-pinned source/plan baseline; ready for owner review and a separately +approved non-author review. No implementation or push authorized. + +## Baseline + +Source/plan commit: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`. +Foundation parent: `44f257cb06484feda3412d9382e3587393796353`. +Mapping revision: the separate commit containing this document and the +[technical map](2026-09-06_foundation-technical-map.md). + +All file:line source citations in the technical map refer to the source/plan +commit above unless explicitly historical. The map/handoff are not claimed to +exist at that earlier commit. MAP-HANDOFF-1's provisional baseline and delivery +waits were superseded after Jason authorized local commits and Dewey supplied +MS55-DW-3. Shared BUILD-LOG/SESSIONS retain the chronological receipts. + +## What is ready + +- All R1-R34 mapped to responsibilities; 20 source-linked findings and nine + inspected legacy source files, unchanged from 69d1bb3. +- packages/* succession target reconciled with current extensions/** source and + generated .pi installation. No source move or package-manager change proposed now. +- Dewey's shim, single adapter ownership and package-versus-process-privilege + qualifications adopted in the technical map. +- One small increment: read-only synthetic scope/permission inspector, seven core + acceptance cases plus the owner-reported cross-lane retasking negative scenario. + No live registration, authentication, sandbox or runtime guarantee is claimed. + +Jason's ~/.mosaic incident report is context only. No investigation/intervention +there occurred or is authorized. A coordinator message must not itself reassign +an agent, redefine its role or displace an owner-authorized goal. + +## Collaboration and verification boundary + +MS55-DW-1/2 coordination is complete. MS55-DW-3 reports Dewey's 43-path baseline +commit and index release; parent, path allowlist and empty index were independently +checked locally before staging mapping work. Dewey's native extension test/review +receipts establish that separate baseline, not managed-foundation acceptance. +No mapping review has yet been dispatched or approved by a non-author. + +## Non-author review checklist, when authorized + +1. Resolve the mapping revision and source/plan baseline independently. +2. Open every cited source location and validate all R1-R34 mappings, not just counts. +3. Challenge reuse/new classifications and the limited inspected inventory. +4. Check packages/* sequencing, single source ownership and trust-boundary separation. +5. Examine broad mounts, shared context, authorization gaps, uncertain retry and + deletion-before-receipt findings and their dependency ordering. +6. Confirm the inspector cannot imply real permission grants or sandbox proof. +7. Return independent findings; do not substitute author fixtures or #55 native + acceptance for runtime enforcement tests. + +## Remaining gate + +Owner review and separate authorization for non-author review. Implementation, +source moves, migration, push and issue closure remain outside this handoff. + +## Source/plan SHA-256 inventory at d4696d09 + +Every listed file was compared byte-for-byte against the named commit. This +inventory excludes credentials, generated installations and runtime state. The +mapping documents are versioned by their own containing commit, not this input list. + +```text +d4c4e08f56c299106133b57e58a78ddfcb015f131036d243d54f42e0fbdc741b .pi/.gitignore +ea5856b5d93811b43b1c1f278eab3283f7f909396dd74464f49dfe1717b51e0e .pi/README.md +3e4498c8066d5a796a8cfe6e07fc1aad118dac2827c771d954b4ae0c38dae84c .pi/SOURCE-SNAPSHOT.json +73823786b54acae627ddefe4b8a258f0554330e49213a118d32e1ffe59c40415 .pi/goal-dev.sh +d213c167d319dbbb42326f68c9c76ec01dbdd42e8f4f226d3232cc5b355bfebc adapters/pi/adapter.sh +a21dc87079d255261ae7318845073ec06bf9df7bac6874012ea0c84b0d1ec12d compose.yaml +ce58408289fceea4b99d8a77c69523a1c04e683f5084f31c7c4199ae0b9934f3 docs/plans/2026-09-06_agent-project-workspace-foundation.md +a49533e1a06e7610583141e7dbf5f529569b9fb3765bf0f4742ff287905f4dfb docs/plans/2026-09-06_foundation-phase2-contract.md +6e2a6b4e0d323940ee5139f5b01f3ecedb23522b9cfa7674fc3d817508cb152f docs/plans/2026-09-06_monorepo-source-layout.md +b746e8c9963dce430b83a7a5fd0973b789a753cc5edd8288291ecdc8f906b2af docs/plans/2026-09-06_ng-goal-footer-dev.md +6e854e83f2a2b26cb93473611b0a47264fb64dd08b6c272c6b18257238915c82 docs/plans/2026-09-06_workspace-schema-and-audit.md +9e0a95865f9479c5f2d06c485513326891727e5295b62c085efe41dddd7dbc0a docs/plans/ROADMAP.md +27fd60f68d30ddc8c1a0cef96714308b8e526f60a17852f7ec21957c1870ec81 docs/plans/foundation-v1-candidate/README.md +7883fde367a3c4377585a5d2f74f09e8f662651b479abb652779c3ed6c7a4c32 docs/plans/foundation-v1-candidate/REVIEW.md +b1a2b4d0df88ba6f7b197252807f3a3925ffff9375f4e70d4ff28593337c3438 docs/plans/foundation-v1-candidate/RUNTIME.md +82564a7d3200afcdda0850a9454cac6e6cd6a76687d2162c13cf214d7eac4607 docs/plans/foundation-v1-candidate/check.py +7806e42cd792935ddba1c8bcac853f049d79eab227fb7191fe622685e699203a docs/plans/foundation-v1-candidate/command-events.fixtures.json +19e9e50359790ec9a4de5b8c817026ac075e254968de1411867222646743d31f docs/plans/foundation-v1-candidate/command-events.schema.json +cbfcb88531838c8c3dd290257e5d9a657e552bb7dd0f67102b49a921a249da45 docs/plans/foundation-v1-candidate/fingerprint-vectors.json +d433d06da5cd38baf9e51c8857244ee70375db3b68e02a5325a6d1c2cc47da85 docs/plans/foundation-v1-candidate/records.fixtures.json +05774aaf6943cb69c113e39ff1c29676a2a230ca7bf665c50dbcaa8049672af6 docs/plans/foundation-v1-candidate/records.schema.json +02a611925923b2592d9e0e67741a542e6c2e8bec06d69ae5700f25c51d720a7a docs/plans/foundation-v1-candidate/runtime.fixtures.json +74deeb4cd6d87ff9306ed088b9641e51f9c41db71589b5364424908842ee51bc docs/plans/foundation-v1-candidate/runtime.schema.json +93d16f38738bb0610d5250ee54c271934e4f2201660becaa72982363d0711fda docs/plans/foundation-v1-candidate/semantic-model.fixtures.json +c89c3bb19624826c1a84658595c71694a1fd371b9155ef50ffa4c265c099daa8 docs/plans/foundation-v1-candidate/semantic-model.py +1551ee0bb11d4a16181186f5091ddbcfcb0ea1e4718997639542beb797442308 extensions/README.md +0850b651309b57a50f2933182376531c8bbcc75ab92d83c1798dfd1637fe8b8b extensions/goal/README.md +9bfcf60097ec83209f5acae443ce48dde55d39343426de63f89997e3275e67ed extensions/goal/index.ts +5db32424e7376f85f22b1055addf3784125da09c3ea23b86a3d0d338f852babd extensions/goal/lib/display.ts +57f1d89c998099b2a9b0c860e70a35db61261a5d1ae7f07cc9acff29fe21042e extensions/goal/lib/executive-update.ts +3837d31fad6481a3c69132ec7fb19849498d5d4c90b0e41eeb683daec19b50a1 extensions/goal/lib/parse.ts +6614b228b3d10252751bc4b68f62ada58f04dfb3a77a51086bb2d7ae42f39c8b extensions/goal/lib/settle.ts +ade39fa3c7a99295712dac41fdfe366384e2cfd695a967c62f0e3f424876ffae extensions/goal/lib/state.ts +78185bb61cb85ae8f2940a89e18063a1d90361d8a869582fff6f4787ec7430dd extensions/goal/lib/store.ts +cad6670a9e8206166b710cd464347aedee6401be9307248b10f9fcfc295585f0 extensions/goal/test/communication-closeout-contract.test.ts +8b28e3c63607dfc321e6b74cd967e92ae6f72ed3e31e2286fcf9a5964394bb02 extensions/goal/test/display.test.ts +66d9437111c4574ea255affe539b78c6ad896d7f43de191d154873b9ef500501 extensions/goal/test/executive-update.test.ts +dfb172ddd228205d3e72a47dfe11372b9cc39e4584017461efe037aa3dc8c08a extensions/goal/test/fencing.test.ts +ac5a69536ee07cc31c6f3a738ca2d5c446689bbfdae05dafffd9c6302864b96c extensions/goal/test/fixtures/.gitattributes +bbea48a46b1f8da7bc759f86856fb52830b7dde456b826317163c6dc6ccab319 extensions/goal/test/fixtures/skills-local/ms-executive-update/SKILL.md +c797776e992c4b1187d786ccb0cce57ca817ebd91ec56caebd4bc220d660ff9b extensions/goal/test/fixtures/skills-local/ms-honesty/SKILL.md +0132ad6508df2bcba0df7fb417e06cbe90c7ea663e334f2176c8973757bb4809 extensions/goal/test/fixtures/skills-local/ms-proactive-agent/SKILL.md +be377aa1e3128efddc00c651771e145acc6cb9d5c6f2599260d1e00ef617ac7d extensions/goal/test/goal.test.ts +3a03b44aea1a9f316ee1138092e3cb55507cdff34ca2cbf828d45ed90a46b699 extensions/goal/test/progress.test.ts +2a33f36881d38656e26ca7580907cf2b22df69d94243ebdfee7adef140d77040 extensions/goal/test/quiet-wait.test.ts +38df8499a64dd465ff5011b06fce80c0793bb53eb7c33bb685001e56451647f3 extensions/goal/test/runtime.test.ts +ea7e9e86782a8716a5e33a27d653227d162c595ba4aa02d1ee691fd4ddead081 extensions/mosaic-core/lib/adapter.ts +4604ae28cd16966d0e447a4e8075bbe320c3119d0a4c8fe870b98e2bb4fb6d03 extensions/mosaic-core/lib/enforce.ts +f291b11818ba01567c1f42bbd36fae63a2398a347426d863ecc6bdb7820358c7 extensions/mosaic-core/lib/gate-record.ts +8313837181a1ac07e7ca58f99873e66b305cd5b5e8d125c189b14d231bdc4620 extensions/mosaic-core/lib/goal-policy.ts +cea0165ab9b323c083ce2fcb1d9fa835e1ee534045cd67536aec17c339457d45 extensions/mosaic-core/lib/incarnation.ts +b52a129c97b822209acdf96ddae49c970bbb9a4dd74ac5bbe7440418e9cb2af1 extensions/mosaic-core/lib/journal.ts +b0c12f2cb9e974ad72d28773617a862e5e880612d63d1edc513c4e057d6f21d9 extensions/mosaic-core/lib/loader.ts +aabc1046dca38f03cfbe111259a21521b24b250736be42f548a57a0e315cf70b extensions/mosaic-core/lib/policy.ts +f174864dc499d0a39e7786e1220c54df3e9af2cd8523476c3d4bf2e2d5928264 extensions/mosaic-core/lib/proposal.ts +00448f6f00f72163bcde3e0a6fc9b87023c46a225316df7530bc14d9953b5e12 extensions/mosaic-core/lib/reconcile.ts +1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555 scripts/agent.sh +fe5d3e89272d3b04db687eabed30a95dde480a2f7bc784cd27e43fa9321f15a6 scripts/auth.sh +a8a41274c06ab6fe38c42d1e96db115b8d65b03a87ed1796c4d37288258a1d12 scripts/goal-dev.sh +430ee6bc4fcfbe4b9ac030aaa19cdb6fdc7407e1b17253b80178b9b0523b5a3a scripts/mosaic-config.mjs +525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83 scripts/mosaic-task.mjs +957ef76f949c2eb2e472182261bf2d1619e0cde44c506ab2bbb5c25dc063864d scripts/reset.sh +eee8c0a9c5708cbc9d0922ea733f09b34d50da8816f95a43e5afe3e3dfc24dbb scripts/sync-dev-extensions.sh +5d7b687f16fd1a9414b229501177d530ba3af4eadd3cac319b33f38fdba9bf99 scripts/test-extension-package.sh +4c5db63da5194a937ee4a488b796f60876a780482812d949e3337bf0d274a974 scripts/test-goal-native.py +4b210d5d785d06d699ceaa902ccb0451c09cb19397e861521f825c09e9e33ae5 src/load-contracts.sh +6749ebe3d0433b3dfefb40a44d58c4ca2606ab9f4ce01457dd52767059b7b13b src/run-agent.sh +ece76e2690012b53087357d467edf3f2c3f872d5db28bd97eaa1bbb217f5ed57 tasks/ng-goal-footer-implementation.json +d50fd5dbbd08a39b2a91424392d2b31bc2f9b4a1e3c3d09ee8061d5776989459 tasks/ng-goal-footer-review.json +``` diff --git a/docs/plans/2026-09-06_foundation-technical-map.md b/docs/plans/2026-09-06_foundation-technical-map.md new file mode 100644 index 00000000..6859884d --- /dev/null +++ b/docs/plans/2026-09-06_foundation-technical-map.md @@ -0,0 +1,352 @@ +# Foundation technical map β€” #53 / #55 + +Status: source/plan baseline pinned; prepared for owner review. Author: darkwing. +Scope: documentation/read-only investigation and explicitly authorized local +baseline/mapping commits; no implementation, migration, push or issue closure. Prepare for independent review, not self-approval. + +## Authority and coordination + +The active operator goal authorizes mapping the accepted phase-2 foundation with +Dewey, aligning canonical directories, identifying reuse/change and recommending +one small user-testable increment. This supersedes CURRENT's earlier wait for +mapping authorization; it does not reopen phase-2 acceptance. + +MS55-DW-1: Dewey requested scope/path coordination. The attempted direct tagged +reply returned exit 2: submission could not be confirmed. Jason identified a known +tmux-tool bug. Delivery remains unknown; no blind resend or private-pane polling. +Dewey subsequently directly acknowledged MS55-DW-1 and recorded the agreement in +his #55 layout plan. Receipt is now settled; no resend is needed. He is waiting +for Jason's mapping-goal authorization in his session; this session's active goal +already authorizes its own mapping work. Do not assume his work has started. + +Acknowledged division: +- Darkwing: this map, foundation requirement-to-code trace and CURRENT integration. +- Dewey: #55 canonical source, package/install boundaries and phased inventory. +- Shared BUILD-LOG/SESSIONS: append-only; no exclusive claim. +- Darkwing will not edit extensions/**, .pi/**, #54/#55 plans or Dewey's packaging + and goal test scripts. Accepted foundation documents remain stable inputs. + +## Initial measured directory alignment + +Repository HEAD measured at this checkpoint: 69d1bb3aa4b826218aa4cca3710f2d98c0b9d7ba. +The working tree includes uncommitted foundation and separate #54/#55 work; +HEAD alone does not identify that newer source. Exact content hashes are required +for the eventual review handoff. + +| Boundary | Existing location | Mapping disposition | +|---|---|---| +| Immutable worker instructions | contracts/ | Retain dedicated contract ownership; draft schemas are not installed contracts. | +| Reviewed role authority | roles/ | Retain; scope registration must narrow, not replace this authority. | +| Harness integration | adapters/ | Retain adapter boundary; trace mediated-runtime changes before proposing placement. | +| Skills | skills/ | Retain declarative resources; not automatically JavaScript workspace packages. | +| Goal extension/support source | extensions/goal/, extensions/mosaic-core/lib/ | #55 canonical-source input; do not duplicate or relocate in this mapping. | +| Generated native installation | .pi/extensions/ | #55 installation output, not canonical source. | +| Launch/build/test utilities | scripts/ | Distinguish tooling from future service logic; no moves proposed yet. | +| Existing runtime code | src/ | Inventory responsibilities before proposing apps/ or packages/. | +| Plans and evidence summaries | docs/ | Keep planning separate from runtime authority/evidence storage. | + +Directory existence was checked locally. The goal/source-install boundary comes +from Dewey's #55 layout record; its source/package verification is not foundation +runtime admission evidence. No empty apps/packages scaffolding is proposed. + +## Initial workplan (historical) + +1. Trace actual source entrypoints and state/authority paths against R1-R34. +2. Classify reuse unchanged, reuse with changes, replacement, and new component; + identify dependencies and proposed canonical placement without moving files. +3. Reconcile package/source boundaries with Dewey, settling MS55-DW-1 receipt. +4. Recommend one bounded user-testable increment and produce a hashed independent- + review handoff with unresolved risks. Owner review remains the completion gate. + +## Source trace checkpoint: launcher, adapter, policy and evidence + +Read directly on 2026-09-06 at 06:59 UTC. These classifications concern the +inspected paths, not a claim that no similar capability exists anywhere else. + +| Source locator | As built | Reuse/change classification and requirement impact | +|---|---|---| +| scripts/agent.sh:78-130 | Reads reusable seat definition; copies SOUL into a shared per-agent data-root path; writes a seat record if absent. | Reuse identity source concept (R1). Change materialization to immutable execution-specific inputs (R16/R17); preserve canonical source ownership rather than duplicating definitions per workspace. | +| scripts/agent.sh:132-170 | Default session is agent-NAME; declared role resolves tools, intersected with requested tools. | Replace global default with explicit project/workspace/session resolution (R3/R4/R12). Reuse narrowing principle, not this as a full scope authorizer. | +| scripts/agent.sh:181-199 | Mission copied to shared per-agent path; workspace defaults to agent name; native Compose launch. | Change launch orchestration and mission snapshots. Existing directory names cannot establish membership. R34 requires a mediated client path, not merely native launch with another flag. | +| adapters/pi/adapter.sh:23-50 | Changes cwd, supports ephemeral/fork/persistent modes; a nonempty session directory adds -c; tools are explicit or disabled. | Retain adapter separation and explicit tool/discovery controls. Replace directory-nonempty/latest selection with exact binding and genuine-first-use checks. Preserve fork/history behavior only after explicit compatible adoption. | +| adapters/pi/adapter.sh:63-96 | Native TUI or print; ambient extensions/context/templates disabled; explicit provider/model and prompt. | Reuse explicit configuration/discovery suppression where verified. New mediated transport/tool gateway required for R34/R33. Do not enable the native #55 extension in managed workers as an implicit shortcut. | +| scripts/mosaic-task.mjs:252-273,670-676 | Closed role fields, filename identity, known unique tools and network enum; resolve-role emits tools and network. | Reuse validation principles and tests with changes. This role format does not express the new project/workspace registrations or 29-operation catalog. Network metadata emission is not evidence of network enforcement (R13/R33). | +| scripts/mosaic-task.mjs:362-378 | Task tools intersect mission tools; empty intersection yields tool-free. | Reuse least-privilege operation, expand to all required ceilings, targets and current revisions. Do not infer authorization from tool presence or combine assignments. | +| scripts/mosaic-task.mjs:295-325 | Exclusive wx creates input snapshots; writeOnce writes then closes, without fsync in this helper. | Reuse exclusive-create intent and snapshot conventions. Change publisher for durable commit ordering, classifications, trusted origins and recovery. Exclusive creation alone is not crash durability. | +| scripts/mosaic-task.mjs:442-466 | Result stores prompt/response, task/session/tools, exit/signal/model and times, then writeOnce. | Retain legacy run evidence and useful provenance fields. Do not treat it as the R14/R33 invocation ledger: new scope/assignment/authorization/limits/intent/observation records and controlled detailed evidence are required. | + +### Proposed component boundaries, not source moves + +- Scope/reference/policy resolution: a reusable domain module with no process, + credential or filesystem-effect authority. Existing validation/intersection code + is an input, not permission to copy its narrower semantics unchanged. +- Managed launch/control coordination: separate runtime responsibility above the + harness adapter; owns claims, current intent and authenticated control routing. +- Pi adapter: owns engine protocol translation and exact-session/config binding, + not canonical project membership or global policy decisions. +- Trusted evidence publisher/supervisor: distinct from worker output. Owns durable + intent/outcome publication and trustworthy stopping observations. +- Keep proposed modules unallocated to new apps/packages until their dependency + and build boundaries are reconciled with Dewey. Existing scripts remain untouched. + +### Dependency implications + +A read-only scope/permission inspector can precede managed execution: it needs +strict records, a coherent synthetic reference graph and a clearly labelled +permission calculation. It does not need provider credentials or Pi launch. +Live registration needs the trusted publisher and protection from legacy broad- +mount paths first. Managed launch then depends on scope resolution, publisher, +claim/control protocol, adapter admission and real isolation/stopping proof. + +### Exact inspected file identities + +- `scripts/agent.sh`: `1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555` +- `adapters/pi/adapter.sh`: `d213c167d319dbbb42326f68c9c76ec01dbdd42e8f4f226d3232cc5b355bfebc` +- `scripts/mosaic-task.mjs`: `525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83` + +## Mount, context and lifecycle trace + +Read-only source inspection, 2026-09-06 07:01 UTC. No reset, prune, retry, +container launch or credential-file read was performed. + +| Source locator | Observed behavior | Classification / required boundary | +|---|---|---| +| compose.yaml:38-43 | Whole configured data root mounted at /var/lib/mosaic without :ro; auth file separately mounted read-only. | Replace mount design for managed admission. Read-only auth mounting does not establish credential separation from the engine, and whole-root exposure is not workspace isolation. Preserve runtime-only credential handling, not broad mounts. | +| src/run-agent.sh:20-41 | Adapter name/path checks; dispatch after generating one shared /var/lib/mosaic/system-prompt.md. | Reuse dispatch validation with changes. Context builder must publish execution-specific immutable inputs, not a shared prompt destination. | +| src/load-contracts.sh:18-58 | Governance files required; optional seat SOUL; OUT.partial is a fixed sibling staging name. | Reuse governance precedence and missing-source refusal. Replace shared staging/output with uniquely owned execution snapshots and verified publication; current concurrent same-output writers can contend. | +| src/load-contracts.sh:68-77,81-98 | Appends every user/*.md, then mission objective/directives. Header's stated layer order differs from actual user-before-mission order. | Replace blanket context discovery with classified, authorized selection and explicit ordering. Actual code, not header prose, defines this baseline. R6/R16/R17 and context privacy require recorded source revisions. | +| scripts/reset.sh:16-48 | Loads configured data root, rejects root symlink/resolution mismatch/missing marker, then recursively removes that root. | Retain useful refusal checks, change lifecycle integration before protected foundation state exists. Despite hard-coded-path commentary, implementation compares resolved path with configured TARGET, not a fixed literal. No active-claim/reference protection or reset receipt is present in this path. | +| scripts/mosaic-task.mjs:548-595 | Retry reads task snapshot, redirects relative mission to recorded snapshot, then runs it as a new run. | Reuse provenance and original-record preservation. Do not use as uncertain-effects recovery: no old process/effect reconciliation gate is visible in retryRun. New run identity alone does not make replay safe. | +| scripts/mosaic-task.mjs:598-641 | Prune sorts run directories, keeps a count, defaults to preview; --yes removes each directory before appending its receipt. Directory-read failures are caught as no entries. | Reuse preview/explicit-apply UX, not protected-retention semantics. Add live-reference/claim protection, distinguish unreadable state from empty state, and make deletion/receipt failure recoverable. Deletion-before-receipt exposes an uncertainty window. | + +### Proposed authority and state ownership + +| Responsibility | Proposed owner | Required separation | +|---|---|---| +| Approved context selection and snapshot construction | Trusted context builder under launch coordinator | Does not trust workspace file discovery or client classification; private inputs stay out of shared work metadata. | +| Actual mounts, egress and process cohorts | Sandbox supervisor/gateway | Separate command jobs from credential-bearing engine; no worker access to evidence/policy/control roots. | +| Canonical records and required evidence | Trusted publisher and retention coordinator | Writer/retention share a serialized protection boundary; a worker cannot prune its own audit trail. | +| Uncertain outcome recovery | Authorized recovery coordinator plus trustworthy observers | Distinct from replay; must establish stopping and reconcile effects before admitting replacement/retry. | +| Native extension development installation | Dewey's #55 tooling | .pi installation acceptance is not evidence that container mounts or managed lifecycle meet these requirements. | + +### Ordering constraint for the rewrite + +Before live foundation state is treated as protected, close legacy broad-mount +launch paths into that state and integrate reset/prune protection. Before managed +Resume/Fresh, provide exact scoped session/claim resolution and immutable context +snapshots. Before uncertain-effect retry, provide trustworthy stopping, evidence +availability and explicit reconciliation. These are dependencies, not source moves +or authorizations to repair the current scripts during mapping. + +### Additional source identities + +- `compose.yaml`: `a21dc87079d255261ae7318845073ec06bf9df7bac6874012ea0c84b0d1ec12d` +- `src/run-agent.sh`: `6749ebe3d0433b3dfefb40a44d58c4ca2606ab9f4ce01457dd52767059b7b13b` +- `src/load-contracts.sh`: `4b210d5d785d06d699ceaa902ccb0451c09cb19397e861521f825c09e9e33ae5` +- `scripts/reset.sh`: `957ef76f949c2eb2e472182261bf2d1619e0cde44c506ab2bbb5c25dc063864d` +- `scripts/mosaic-task.mjs`: `525bab31453ab84afa379421c619405632b9c85d639e2f4a6188dcf7ae825b83` + +## Complete requirement responsibility index + +This index covers every accepted requirement, not every implementation. β€œNew” +means not provided by the inspected paths; repository-wide absence is not proven. +Source detail is in the two trace tables above; accepted behavior is in the +foundation plan R1-R34. Uninspected responsibilities remain explicit gaps. + +| Requirement | Proposed responsibility | Mapping finding | +|---|---|---| +| R1 | Identity | Launcher identity reuse; scoped runtime binding changes | +| R2 | Scope/policy | New registration/delegation resolver; existing tools-only role validation is insufficient | +| R3 | Scope/policy | New single-parent project/workspace graph and explicit membership | +| R4 | Session/control | Replace global session default with scoped identity | +| R5 | Scope/policy | Explicit selection resolver replaces agent-name workspace default | +| R6 | Context | Replace shared/global work input paths with authorized snapshots | +| R7 | Session/control | Exact Resume/initial/Fresh state; replace nonempty-directory continuation | +| R8 | Work coordination | New assignment selection/Abandon/prerequisite transitions | +| R9 | Session/control | Authorized service launch and work-record recovery | +| R10 | Session/control | New exclusive scoped claim; scaling/budgets remain later-phase requirements | +| R11 | CLI/client | New shared operation interface; no client-owned task truth | +| R12 | Messaging | New explicit scoped addressing/delivery; not established by inspected launcher | +| R13 | Sandbox | Replace whole-root mount boundary and prove containment | +| R14 | Evidence | Expand run provenance into trusted classified action evidence | +| R15 | Governance | Retain explicit owner phase and user-test gates | +| R16 | Context | Replace shared SOUL materialization with immutable execution snapshot | +| R17 | Context | New comparable fingerprint and cross-interface notice flow | +| R18 | Scope/policy | New mission ownership/parent graph and reference checks | +| R19 | Work coordination | New bounded decomposition and non-author acceptance checks | +| R20 | Work coordination | Separate taskless read/chat from assigned changes | +| R21 | Session/control | New active-conflict response and explicit connection | +| R22 | Context | New transcript-specific visibility and handoff checks | +| R23 | Scope/policy | New revocation propagation linked to supervisor stopping | +| R24 | Session/control | New controller/observer generations and transfer | +| R25 | Session/control | New fenced, verified-safe replacement protocol | +| R26 | Recovery | Replace blind retry use for uncertainty with evidence-based reconciliation | +| R27 | Evidence | New fail-closed recording/admission and preauthorized fail-safe stop | +| R28 | Context | Replace blanket user Markdown inclusion with classification/selection | +| R29 | Retention | New retirement/reopen without deletion; protect required evidence | +| R30 | Session/control | New reviewed legacy adoption; preserve originals | +| R31 | Work coordination | New current-intent reconciliation and stale-action rejection | +| R32 | Scope/policy | Extend reviewed ceilings with standard scope roles and narrowing | +| R33 | Evidence/sandbox | New mediated invocation records plus actually enforced limits | +| R34 | CLI/client | New Mosaic-controlled terminal; retain Pi behind reviewed adapter | + +## Canonical placement matrix for Dewey reconciliation + +ROADMAP.md:127-166 records an owner decision, not just an optional legacy pattern: +post-M20 succession uses packages/*, with restructuring delayed until script +replacement to avoid two migrations. This corrects any reading of the initial +map as leaving the entire package target undecided. #55 extensions/** is current +canonical source, not an implicit repeal of that post-M20 destination. + +| Responsibility | Current source/input | Post-M20 proposed destination | Packaging/ownership boundary | +|---|---|---|---| +| User CLI and managed terminal | scripts/agent.sh and other wrappers | packages/mosaic/ | CLI consumes domain/runtime APIs; wrappers retire only after replacement acceptance. | +| Engine/session/control/supervision | src/, adapters/, launcher orchestration | packages/agent/ | Runtime owns process/session protocol; adapter internals do not own global role authority. | +| Strict records, references and policy intersection | scripts/mosaic-config.mjs, parts of mosaic-task.mjs; candidate schemas | packages/config/ | Pure validation/resolution separated from effectful publication; first inspector can exercise this boundary. | +| Provider/account materialization | #50 plan/current auth tooling | packages/auth/ | Credential ownership stays here; no credential migration or refresh experiment in mapping. | +| Evidence/work/recovery coordination | mosaic-task.mjs portions plus new responsibilities | Initially packages/agent/ internal modules | Separate trusted writer and policy interfaces; do not invent extra top-level packages without independent build needs. | +| Contracts/roles/missions/tasks/skills | Existing dedicated directories | Retain declarative directories | Packages consume reviewed resources; no promotion of drafts or workspace-written authority. | +| Goal extension and imported support | extensions/goal/, extensions/mosaic-core/lib/ | Current source retained pending explicit M20 extension packaging decision | Dewey owns inventory/provenance; whether to stage a package artifact or move source later remains a specific unresolved boundary. | +| Native development installation | .pi/extensions/, sync/test scripts | Generated installation remains separate | Never package .pi/state or treat native acceptance as managed-runtime proof. | + +ROADMAP's target also retains src/ while describing packages/agent as absorbing +src/adapters. The map must distinguish a retained container entry shim/build input +from absorbed runtime implementation; do not move both copies and create competing +sources. That exact shim boundary and extension distribution placement need Dewey's +reconciliation. No package-manager change or empty package scaffolding is authorized. + +## Earlier review-baseline gate (resolved below) + +Dewey's #55 reconciliation and ms-archify require commit-pinned code and plan +citations for a formal map. The accepted phase-2 plan and #55 work are currently +uncommitted. Current hashes make this preparatory inventory reproducible, but do +not satisfy the formal commit-pinned handoff gate. No commit/push is authorized +by this goal. Do not label this document an independently review-ready Archify map +yet or use HEAD to pretend it contains the dirty source. + +Remaining ready work: inspect config/auth/interface inventories read-only and +specify the first inspector's exact acceptance boundary. External dependencies: +Dewey's package/shim reconciliation and an owner-authorized baseline strategy +before formal independent review. Review dispatch itself is a separate gate. + +## Config/auth/interface inventory and first-increment boundary + +Read source only; no configuration, credential contents, auth status, login or +refresh operation was accessed/executed during this checkpoint. + +| Source | Finding | Disposition | +|---|---|---| +| scripts/mosaic-config.mjs:39-61,76-174 | Config path can be overridden by MOSAIC_CONFIG; regular-file/symlink and strict field checks; canonical data-root checks exclude root/home/config ancestors; lstat errors are treated as missing. | Reuse strict validation and protected-root principles; reconcile the override with sole-config canon rather than silently adopting a second config authority. Distinguish missing from unreadable/error where fail-closed diagnostics matter. | +| scripts/mosaic-config.mjs:194-239 | Bootstrap uses exclusive create, validates existing config without replacement; validate/env expose resolved non-secret fields and shell quoting. | Retain bootstrap-only creation and read-only resolution. Future domain validation must not bootstrap or load live config when running a synthetic inspector. | +| scripts/auth.sh:19-96 | Config-backed account directory and reporting of provider/type/permission metadata. Reads credential JSON when invoked; parse errors include parser text. | Preserve ownership separation, not a proven redaction guarantee. Do not reuse credential-reading report functions in the inspector. Error disclosure and account materialization belong to separate auth review. | +| scripts/agent.sh:28-64 | Per-launch named account checks readability, symlink and mode 0600, exports selected mount source; no project selection flag in this parser. | Reuse explicit refusal rather than account fallback. Replace flat account/path selection with #50 registry bindings at the later auth boundary; introduce full scope at the managed CLI, not by inferring it from cwd. | + +### Recommended increment: synthetic scope/permission inspector + +Purpose: let Jason see whether one agent's project/workspace membership and +permissions resolve as intended before any live state or worker can be affected. +This is a recommendation for a later charter, not an implementation task started. + +Input: one explicit local synthetic bundle containing a coherent graph of agent, +project, two workspaces, registrations, mission/task/assignment and declared mock +policy sources. No live registry, credential, engine history or data-root lookup. +Independent shape fixtures cannot simply be concatenated into this graph. + +Output: deterministic text plus structured result, identifying selected agent, +project and workspace, reference errors and the calculated least-privilege result. +Every successful output says preview only: no live registration or permission grant. +Unknown/missing policy is a refusal, never an empty layer skipped during intersection. + +Acceptance cases for the implementation charter: +1. Valid bundle resolves the explicitly named first workspace and its permitted read. +2. Same agent, second workspace without registration: refuse without revealing that + workspace's private payload or selecting the first workspace instead. +3. Missing parent, multiple/incorrect ownership, dependency cycle and stale revision: + report the violated rule; do not repair or invent references. +4. Broader task grant cannot widen mission/registration/agent ceilings; another + assignment cannot supply missing permission. Explicit empty grants allow nothing. +5. Ambiguous name, duplicate ID/revision, unknown field and malformed UTF-8/path: + reject before producing a permission preview that appears valid. +6. Source bundle stays byte-identical; no writes to config, data root, .pi/state, + roles or installations; no child engine, network, credential or migration action. +7. Jason runs the positive and negative examples and understands both the scope + display and the preview disclaimer before any dependent increment is chartered. + +Proposed exit classes (not installed): 0 valid preview, 2 malformed/invalid graph, +3 simulated permission refusal, 4 input/I/O failure. Final naming/packaging belongs +to the later charter, consistent with packages/config domain ownership and the +packages/mosaic CLI target. No npm/Turbo change is needed to approve this boundary. + +Deferred: authoritative publication, real authentication, sandbox tests, process +control, native/managed goal integration, OAuth refresh, live registration, session +adoption, reset/prune changes and repository restructuring. These require their +own dependencies, implementation tests and owner acceptance. + +### Config/auth/interface source identities +- `scripts/mosaic-config.mjs`: `430ee6bc4fcfbe4b9ac030aaa19cdb6fdc7407e1b17253b80178b9b0523b5a3a` +- `scripts/auth.sh`: `fe5d3e89272d3b04db687eabed30a95dde480a2f7bc784cd27e43fa9321f15a6` +- `scripts/agent.sh`: `1ad2270a02e5668ef126c2af71a7b70771c2da09842313bdbf6abba84e95b555` + +## Owner-reported cross-lane retasking scenario + +Jason reports that orch-01 in the separate ~/.mosaic environment redirected two +agents from their owner-set goals into supervisor work for another agent, outside +their lanes. This is owner-reported context, not an independently investigated +incident or a proven root-cause diagnosis. Jason explicitly prohibited involvement +in that environment's failure; no inspection, messaging or intervention there is +part of this goal. + +Map to R8/R12/R19/R23/R31/R32: current goal/mission/assignment and scope authority +must be checked when reassignment is requested. A coordinator title, message or +new role description is not authorization. A goal reminder is not an enforcement +boundary. Another workspace's permission cannot be borrowed, and changing a scope +role cannot silently replace reusable identity or the owner's approved intent. + +Add this adversarial case to the proposed inspector/implementation acceptance set: +- Agent A has an active owner-authorized assignment in workspace A. A coordinator + from workspace B requests reassignment into supervision for another goal. +- Without explicit applicable delegation and a valid recorded change within owner + intent, refuse the request; preserve A's goal/assignment and report the conflict. +- A message alone cannot mutate assignment, role, goal or acceptance state. +- If a properly authorized change is requested, account for underway effects and + follow reconciliation; never abandon old work merely because a new message arrived. +- Later runtime tests must prove original work remains selected and stale/cross-scope + actions are fenced. An offline preview alone cannot establish this behavior. + +## Integrated baseline and reconciled ownership + +Source and accepted-plan baseline: d4696d09eb1b5dcf1028f30db2cd63735f51cb16, +whose parent is foundation baseline 44f257cb06484feda3412d9382e3587393796353. +All source file:line citations in this map now refer to d4696d09 unless explicitly +labelled historical. Inspected legacy source bytes are unchanged from 69d1bb3. +The mapping revision is the separate commit containing this map and its handoff; +no circular claim that d4696d09 already contains these mapping documents is made. + +Jason authorized scoped local baseline commits. Dewey's MS55-DW-3 receipt was +verified locally: exact parent, 43 allowed paths and an empty released index. +The former baseline-authorization and coordination waits are resolved. No push, +implementation, migration or independent review is authorized by that resolution. + +Dewey's MS55-DW-2 qualifications are adopted: +- extensions/** remains current canonical source until explicitly chartered M20 + packaging; mosaic-core/lib remains internal support, not another entrypoint. +- Post-M20 src/ retains only unavoidable bootstrap/exec shims. Current material + context behavior migrates/replaces, never duplicates packages/agent logic. + Adapters also have one canonical post-M20 owner under packages/agent. +- packages/mosaic handles presentation/routing, not policy truth. packages/config + owns pure validation and deterministic policy calculation, not publication. +- packages/agent contains runtime coordination and separated writer/recovery + interfaces. A package is not a process trust boundary: engines must not inherit + publisher/supervisor privileges simply by importing the same package. +- packages/auth contains code/metadata, never packaged secrets. Declarative + top-level directories remain authoritative inputs, not generated installations. + +The initial inspector remains the recommended bounded increment. No independently +built packages, empty scaffold or package-manager migration is needed now. Exact +extension distribution packaging and any retained shim are implementation-charter +choices constrained by the reconciled ownership rules, not unresolved permission +to create duplicate sources. + +Next gate: owner review of the mapped baseline and separate authorization of a +non-author review. This mapping prepares that handoff; it does not supply the +reviewer's verdict or authorize the inspector implementation. diff --git a/docs/plans/CURRENT.md b/docs/plans/CURRENT.md index 5564fb83..788f9c32 100644 --- a/docs/plans/CURRENT.md +++ b/docs/plans/CURRENT.md @@ -7,11 +7,101 @@ update this file to the next action). No ambiguity, no re-planning. ## Next action -Review `docs/plans/2026-09-03_auth-provider-harness-registry.md` against its ten review gates; revise until owner-approved. No implementation starts before approval. +Owner review of the completed technical map and separate authorization of a +non-author review. Handoff: `docs/plans/2026-09-06_foundation-map-handoff.md` +(MAP-HANDOFF-2); map: `docs/plans/2026-09-06_foundation-technical-map.md`. +Source/accepted-plan baseline: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`, +parent `44f257cb06484feda3412d9382e3587393796353`. Mapping documents are pinned by +the separate commit containing this checkpoint, not falsely attributed to d4696d09. + +Dewey's MS55-DW-3 commit, 43-path scope, parent and index release were verified. +Jason's conditional resumption authorization is satisfied. R1-R34 coverage, +reconciled package/source ownership, source identities and the bounded inspector +recommendation are ready for owner review. Preparing that handoff does not imply +independent approval. No implementation, migration, source moves, push or issue +closure is authorized. No involvement in the reported ~/.mosaic failure. + +The extension owns the active mapping goal's lifecycle; this file records task +progress and the next approval gate. Earlier phase-2 acceptance remains valid. + +## Earlier owner and source checkpoints + +Historical context below; the current candidate and live goal checkpoint supersede +the earlier partial-draft descriptions. + +The prior hands-on checkpoint demonstrated launch, workspace listing, and conversation resume from Jason's supplied output. Fresh context and mission recovery were not tested. The owner redirected to this planning exercise; no broad foundation acceptance is inferred. + +Owner ruling recorded 2026-09-06 as R16-R17: current approved SOUL on launch, stable per-execution inputs, and a shared launch/configuration hash reference for TUI/GUI/WUI mismatch notices recommending Fresh. D10 is partly resolved. Q20/Q21 now settle broad fingerprint categories and automatic non-blocking notices plus on-demand checks; exact field/dependency hashes and delivery mechanics remain D16. This does not advance the phase or authorize implementation. + +Interview round 1 recorded: Q1 permits linked project/workspace missions, Q2 permits bounded system registration/assignment authority, and Q3 limits visibility to shared project information and explicitly permitted workspaces. Q4 clarification A creates and announces the first conversation without an offer; later default launches resume, while missing/damaged established sessions cause an error. Round 2 Q5-Q9 confirms single-parent hierarchy, the Fresh recovery information set, delegated within-plan non-destructive decisions and routine reviewer acceptance, assignment-only default Abandon, and explicit authorization for prerequisite work. Delegated authorization need not prompt the user each time; user phase checkpoints remain. Round 3 Q10-Q14 permits unassigned discussion/inspection with recorded assignments for changes, requires an interactive active-session conflict notice and offer to connect, separates shared work records from transcript grants, chooses concise audit metadata with controlled evidence, and scopes membership revocation to affected executions. Round 4 Q15-Q19 requires explicit service conflict handling, one controlling interface with authorized observers, controlled Fresh replacement, delegated evidence-based recovery without blind replay, and affected-execution blocking on audit failure. Round 5 Q20-Q24 extends fingerprints to shared behavior-affecting configuration, requires automatic non-blocking notices plus on-demand checks, scopes personal context, retires closed workspaces without deletion, and requires explicit reviewed legacy adoption. Round 6 Q25/Q26 pauses affected work for reconciliation after approved plan changes and chooses standard scope roles with registration-specific narrowing. Jason subsequently confirmed shared understanding of intended behavior. Jason then authorized phase 2. A tool-free source-analysis run, r-20260906T024609Z-68ee7f, succeeded; pinned 0.84.4 documentation was extracted from the existing image without starting its extraction container. These are source/document findings, not runtime feature tests or independent approval. The first contract candidate is partial. Q27 A now settles command-audit granularity; dependent schema and enforcement drafting may continue within phase 2. Full schema/plan approval remains pending. + +## Accepted phase-2 checkpoint (historical) + +- Goal: issue-53-phase2. Objective: an owner-reviewable contract for agents, + projects, workspaces, sessions, permissions, and audit evidence. Completion + owner: Jason. Author/workspace/session remain those recorded below. +- State: satisfied. Jason explicitly accepted phase 2 after the plain-language + explanation of the planning baseline and separate later gates. P2-7 is complete. + REVIEW.md retains D1-D16 and the unproved implementation mechanisms. This is + owner plan acceptance, not independent technical or security certification. +- Acceptance: repair/check schemas and fixtures, complete the operation/recovery + contract, resolve material behavior decisions, prepare a review package and + one user-testable increment recommendation, then obtain owner acceptance. +- Evidence: `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 command + and 38 record shape cases, 16 path cases, 7 restricted-domain hash vectors, + 155 runtime/control/artifact cases and 35 synthetic rule-model cases. Ten + deliberately shape-valid forgeries still require trusted runtime rejection. + These are not runtime security tests or independent acceptance. +- Reboot fixture defects were repaired, not discarded. Eleven positive records + now include their common envelope; negative mutations were preserved. Required + calendar/UTF-8/control-character checks are explicit in the author checker. +- Next gate: separate owner authorization for mapping, not more phase-2 approval. + No mapping or implementation started. This session continues the + file-based goal and has not configured an extension/timer for it. Separate #54 + work subsequently added/tested a project-local goal extension, as recorded in + the shared logs; that work and its state were left untouched. This session has + not migrated issue-53-phase2 into that runtime. Elapsed time never grants approval. +- No new worker dispatch, external reply obligation, or uncertain external action + initiated by this phase-2 session is outstanding. No numeric work budget supplied; + aggregate usage remains unavailable. +- Authority remains phase-2 planning and read-only investigation. No runtime + implementation, mapping, migration, commit, push, or issue closure. + +## Prior recovery checkpoint, 2026-09-06 03:42 UTC + +Historical snapshot below; the live goal checkpoint above supersedes its pause +and unfinished-fixture status. + +- Goal: issue-53-phase2. State: paused by owner steering. Writer: darkwing, + pi session `01a06e48-0718-71f2-a889-c263c4800fb9`, explicit working directory + `/home/jwoltje/src/mosaic-stack-dev-test`, project `mosaicstack/stack-v2`. + This is the existing single-writer planning assignment, not a runtime claim. +- HEAD remains `69d1bb3`. Preserved all uncommitted planning and unrelated skill + work. No reset, cleanup, commit, push, or implementation occurred. +- Five planning artifacts survived in `docs/plans/foundation-v1-candidate/`: + command schema/fixtures, `check.py`, and record schema/fixtures. The three + command-check file hashes match the pre-reboot checksums. +- `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 shape fixtures + and 5 deliberate shape-valid forgeries. This does not prove runtime security. +- The unfinished record checker is NOT integrated into check.py. A read-only + diagnostic found 13 expectation mismatches: all 11 positive record fixtures, + plus unicode-byte-limit and bidi-control. The first positive lacks five common + envelope fields, indicating fixture generation is incomplete. Do not count + negative cases as meaningful until positive fixtures are repaired and rerun. +- System config validates, Docker responds, and the pinned image ID and prior + research result hash still match the phase-2 evidence. No Mosaic worker + container was running at inspection. Pinned temporary docs remain available. +- Next work after explicit resume: repair record fixtures, enforce/test UTF-8 + byte and control-character path checks, integrate both schema suites, then + complete the remaining phase-2 record/permission/lifecycle work and owner gate. +- No outstanding assistant-initiated external action or reply is known. Wake is + manual: Jason sends a resume instruction. No timer or automatic continuation + is registered. Aggregate usage is unavailable; no numeric budget was supplied. ## Queue (ordered per docs/plans/ROADMAP.md) -1. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation +1. Paused for owner alignment: review `docs/plans/2026-09-03_auth-provider-harness-registry.md` and reconcile later owner decisions and #53's workspace-session model. Gate 7 remains unresolved. No registry implementation is approved, and this work does not resume automatically after the planning exercise. +2. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation ## Rules