docs(plans): slice 1 brief accepted, S0 rely-on lines in S6; lead decisions 62-63

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-05 16:43:34 -05:00
co-authored by Claude Opus 5.5
parent 1e3c06c78b
commit 85e8f97dbf
2 changed files with 99 additions and 3 deletions
+52
View File
@@ -1034,3 +1034,55 @@ which stay with him. Each item names who decided it and what happened.
it's done. it's done.
- Jason hasn't said whether he accepts the slice 1 brief as a whole, - Jason hasn't said whether he accepts the slice 1 brief as a whole,
so row 11's second accepted brief is still open. so row 11's second accepted brief is still open.
62. **Jason's answers, rounds 2 and 3: the brief is accepted, merges are
gated, S7 is strict, and the human proof is cooperative
(2026-10-05).** Source: Jason's answers in Sage's thread 1ef1e4f8.
- Jason accepts the slice 1 brief as written, with no scope question.
That's row 11's second accepted brief, so row 11 closes.
- Every merge of a coder-bot pull request is a gated decision. Each
of S7's five pieces reaches Jason at least once for its merge, and
S7 counts that as expected, not as a failure.
- S7 is strict. If Jason steps in on a piece with a correction that
isn't a gated decision, the piece fails, the correction is logged
as a finding, and the count of five starts again.
- Vikunja tokens keep the runbook's 90-day lifetime.
- The human proof (REQ-DEC-3) is cooperative in slice 1. On one OS
user, an agent that deliberately escapes S2's /proc check gets a
human capability, as Darkwing showed with `setsid -f env -i`
(`agents/darkwing/work/slice1-s2-review/review-r2.md`). The proof
stops an agent that runs `mosaic decide` directly, and that is all
slice 1 claims for it. S6 closes the gap for managed agents: they
run in their own PID namespace or user, with no human socket
mounted. A T3 seat that runs the human CLI or works around the
proof breaks the rules, and the trail shows it.
- Darkwing's `npm install` on 2026-10-04 rewrote `~/package.json` and
`~/package-lock.json`. Jason says the old contents didn't matter.
Nothing gets restored.
63. **S1's extras, and two S2 rulings (2026-10-05).** Sources: Filbert's
S1 verdicts (#1518 comments 26724 and 26730), Darkwing's S2 reviews
(`agents/darkwing/work/slice1-s2-review/`, #1519).
- S1's extras are accepted. The action vocabulary lives in
`packages/business/src/vocabulary.mjs`, not `contracts/`, because
only host code reads it, and Filbert checked that the image copies
nothing that uses it. The example business file lives at
`packages/business/examples/mosaic-stack.example.json` and refuses
as shipped. `scripts/mosaic` gains a `business` branch, the same
way it carries `queue`. The runbook's section 4 should point to
that example when it is next revised.
- A cross-role decision raised by its own arbiter goes to the human,
and its class stays cross-role. Routing it to the other arbiter
would be a guess about who's qualified, and sending it to the
human fails closed. Rocko built this in S2 round 2.
- A gated approval is single-use. Today one resolved approval
authorizes the same action, target and run any number of times
(Darkwing's P3 deploys three times). `authorize` must record that
it consumed an approval, and a second use refuses. This doesn't
reopen S2's approved round 2. It comes in a new row owned by
Rocko and reviewed by Darkwing, and it has to land before S3 or
S6 calls `authorize` for a gated action. If it needs a schema
change, Darkwing writes a v3c.
- Dewey's list of what the views need beyond the Q1 verbs
(`agents/dewey/work/wui/SLICE1-VIEWS.md` section 9) goes to Rocko
for S4. Session events belong to S6, and credential events belong
to S3. Anything S4 doesn't add is labeled "not in the Q1 module" in
S5.
+47 -3
View File
@@ -1,8 +1,8 @@
# Slice 1: the first working system (2026-10-04) # Slice 1: the first working system (2026-10-04)
Status: written by Sage, lead, for Jason's acceptance. Each `##` section Status: accepted by Jason as written, 2026-10-05 (lead decision 62).
below is the brief for one queue row, in the shape set by Each `##` section below is the brief for one queue row, in the shape set
`docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the by `docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the
rows share. rows share.
## What slice 1 is ## What slice 1 is
@@ -495,6 +495,50 @@ owns (REQ-CLI-2).
session without a window, `mosaic talk` reaches it, and Sage's T3 session without a window, `mosaic talk` reaches it, and Sage's T3
thread hands over. After this step the product doesn't depend on T3. thread hands over. After this step the product doesn't depend on T3.
### What S6 can rely on (row S0)
Copied unchanged from `agents/filbert/work/slice1-probes/MATRIX.md` at
4b7405b8, which Darkwing approved in round 2 (#1516 comment 26729). No case
probes the N + K boundary in line 4, so leave a few seconds of margin
below the hook's timeout.
One line per case. "Tool limit" means Pi `--tools` and Claude `--tools` or
`--disallowedTools`. These are rules the harness applies, not walls
(agents run as Jason's OS user).
1. **A gate that blocks**: the hook, on both harnesses: a Pi `tool_call`
block, a Claude command hook (exit 2 or JSON deny, which holds under
`bypassPermissions`), or an SDK callback deny. The launcher must not
pass `--bare`, which turns Claude settings hooks off.
2. **A gate that crashes**: on Pi, the hook, because a throw blocks and a
`process.exit` ends the run. On Claude Code, a command hook wrapped as
`<gate> || exit 2`, because the wrapper turns a crash into a block
(cc-7d); an unwrapped hook fails open (cc-2). An SDK callback fails
open; see line 6.
3. **A gate at a missing path**: on Pi, the hook, because a missing or
unloadable `-e` refuses to start. On Claude Code, a command hook wrapped
as `<gate> || exit 2`, because `/bin/sh` fails on a missing or
non-executable command and the wrapper turns that into a block (cc-7e,
cc-7f); an unwrapped one is silently skipped (cc-3, cc-3b).
4. **A gate that times out**:
- On Pi, the hook, which never lets the tool run, but only with an
external wall clock and an `agent_end` check. Pi has no handler
timeout, and a gate whose pending promise holds nothing open lets Pi
exit 0 mid-turn.
- On Claude Code, a command hook wrapped as `timeout -k K N <gate> ||
exit 2`, with the hook's `timeout` above N + K (cc-7g, cc-7h). An
unwrapped hook whose timeout expires (explicit, or the 600 s default)
lets the tool run, and so does a wrapped one without `-k` whose gate
ignores SIGTERM (cc-7i) or whose inner timeout is too long (cc-7j).
- For an SDK callback, the hook, because an expired timeout (explicit,
or the 600 s default) means the tool is not run.
5. **A `bash` route to the same action**: the tool limit, on both
harnesses. A hook keyed on a tool name doesn't stop the same effect
through `bash`.
6. **An Agent SDK callback that throws**: the tool limit; the callback
fails open. A callback is usable as a hook only if it catches its own
errors and returns deny, which is what sdk-6a shows.
### Out of scope ### Out of scope
- Codex (after v1). - Codex (after v1).