docs(plans): slice 1 brief accepted, S0 rely-on lines in S6; lead decisions 62-63
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -1034,3 +1034,55 @@ which stay with him. Each item names who decided it and what happened.
|
||||
it's done.
|
||||
- Jason hasn't said whether he accepts the slice 1 brief as a whole,
|
||||
so row 11's second accepted brief is still open.
|
||||
62. **Jason's answers, rounds 2 and 3: the brief is accepted, merges are
|
||||
gated, S7 is strict, and the human proof is cooperative
|
||||
(2026-10-05).** Source: Jason's answers in Sage's thread 1ef1e4f8.
|
||||
- Jason accepts the slice 1 brief as written, with no scope question.
|
||||
That's row 11's second accepted brief, so row 11 closes.
|
||||
- Every merge of a coder-bot pull request is a gated decision. Each
|
||||
of S7's five pieces reaches Jason at least once for its merge, and
|
||||
S7 counts that as expected, not as a failure.
|
||||
- S7 is strict. If Jason steps in on a piece with a correction that
|
||||
isn't a gated decision, the piece fails, the correction is logged
|
||||
as a finding, and the count of five starts again.
|
||||
- Vikunja tokens keep the runbook's 90-day lifetime.
|
||||
- The human proof (REQ-DEC-3) is cooperative in slice 1. On one OS
|
||||
user, an agent that deliberately escapes S2's /proc check gets a
|
||||
human capability, as Darkwing showed with `setsid -f env -i`
|
||||
(`agents/darkwing/work/slice1-s2-review/review-r2.md`). The proof
|
||||
stops an agent that runs `mosaic decide` directly, and that is all
|
||||
slice 1 claims for it. S6 closes the gap for managed agents: they
|
||||
run in their own PID namespace or user, with no human socket
|
||||
mounted. A T3 seat that runs the human CLI or works around the
|
||||
proof breaks the rules, and the trail shows it.
|
||||
- Darkwing's `npm install` on 2026-10-04 rewrote `~/package.json` and
|
||||
`~/package-lock.json`. Jason says the old contents didn't matter.
|
||||
Nothing gets restored.
|
||||
63. **S1's extras, and two S2 rulings (2026-10-05).** Sources: Filbert's
|
||||
S1 verdicts (#1518 comments 26724 and 26730), Darkwing's S2 reviews
|
||||
(`agents/darkwing/work/slice1-s2-review/`, #1519).
|
||||
- S1's extras are accepted. The action vocabulary lives in
|
||||
`packages/business/src/vocabulary.mjs`, not `contracts/`, because
|
||||
only host code reads it, and Filbert checked that the image copies
|
||||
nothing that uses it. The example business file lives at
|
||||
`packages/business/examples/mosaic-stack.example.json` and refuses
|
||||
as shipped. `scripts/mosaic` gains a `business` branch, the same
|
||||
way it carries `queue`. The runbook's section 4 should point to
|
||||
that example when it is next revised.
|
||||
- A cross-role decision raised by its own arbiter goes to the human,
|
||||
and its class stays cross-role. Routing it to the other arbiter
|
||||
would be a guess about who's qualified, and sending it to the
|
||||
human fails closed. Rocko built this in S2 round 2.
|
||||
- A gated approval is single-use. Today one resolved approval
|
||||
authorizes the same action, target and run any number of times
|
||||
(Darkwing's P3 deploys three times). `authorize` must record that
|
||||
it consumed an approval, and a second use refuses. This doesn't
|
||||
reopen S2's approved round 2. It comes in a new row owned by
|
||||
Rocko and reviewed by Darkwing, and it has to land before S3 or
|
||||
S6 calls `authorize` for a gated action. If it needs a schema
|
||||
change, Darkwing writes a v3c.
|
||||
- Dewey's list of what the views need beyond the Q1 verbs
|
||||
(`agents/dewey/work/wui/SLICE1-VIEWS.md` section 9) goes to Rocko
|
||||
for S4. Session events belong to S6, and credential events belong
|
||||
to S3. Anything S4 doesn't add is labeled "not in the Q1 module" in
|
||||
S5.
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
# Slice 1: the first working system (2026-10-04)
|
||||
|
||||
Status: written by Sage, lead, for Jason's acceptance. Each `##` section
|
||||
below is the brief for one queue row, in the shape set by
|
||||
`docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the
|
||||
Status: accepted by Jason as written, 2026-10-05 (lead decision 62).
|
||||
Each `##` section below is the brief for one queue row, in the shape set
|
||||
by `docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the
|
||||
rows share.
|
||||
|
||||
## What slice 1 is
|
||||
@@ -495,6 +495,50 @@ owns (REQ-CLI-2).
|
||||
session without a window, `mosaic talk` reaches it, and Sage's T3
|
||||
thread hands over. After this step the product doesn't depend on T3.
|
||||
|
||||
### What S6 can rely on (row S0)
|
||||
|
||||
Copied unchanged from `agents/filbert/work/slice1-probes/MATRIX.md` at
|
||||
4b7405b8, which Darkwing approved in round 2 (#1516 comment 26729). No case
|
||||
probes the N + K boundary in line 4, so leave a few seconds of margin
|
||||
below the hook's timeout.
|
||||
|
||||
One line per case. "Tool limit" means Pi `--tools` and Claude `--tools` or
|
||||
`--disallowedTools`. These are rules the harness applies, not walls
|
||||
(agents run as Jason's OS user).
|
||||
|
||||
1. **A gate that blocks**: the hook, on both harnesses: a Pi `tool_call`
|
||||
block, a Claude command hook (exit 2 or JSON deny, which holds under
|
||||
`bypassPermissions`), or an SDK callback deny. The launcher must not
|
||||
pass `--bare`, which turns Claude settings hooks off.
|
||||
2. **A gate that crashes**: on Pi, the hook, because a throw blocks and a
|
||||
`process.exit` ends the run. On Claude Code, a command hook wrapped as
|
||||
`<gate> || exit 2`, because the wrapper turns a crash into a block
|
||||
(cc-7d); an unwrapped hook fails open (cc-2). An SDK callback fails
|
||||
open; see line 6.
|
||||
3. **A gate at a missing path**: on Pi, the hook, because a missing or
|
||||
unloadable `-e` refuses to start. On Claude Code, a command hook wrapped
|
||||
as `<gate> || exit 2`, because `/bin/sh` fails on a missing or
|
||||
non-executable command and the wrapper turns that into a block (cc-7e,
|
||||
cc-7f); an unwrapped one is silently skipped (cc-3, cc-3b).
|
||||
4. **A gate that times out**:
|
||||
- On Pi, the hook, which never lets the tool run, but only with an
|
||||
external wall clock and an `agent_end` check. Pi has no handler
|
||||
timeout, and a gate whose pending promise holds nothing open lets Pi
|
||||
exit 0 mid-turn.
|
||||
- On Claude Code, a command hook wrapped as `timeout -k K N <gate> ||
|
||||
exit 2`, with the hook's `timeout` above N + K (cc-7g, cc-7h). An
|
||||
unwrapped hook whose timeout expires (explicit, or the 600 s default)
|
||||
lets the tool run, and so does a wrapped one without `-k` whose gate
|
||||
ignores SIGTERM (cc-7i) or whose inner timeout is too long (cc-7j).
|
||||
- For an SDK callback, the hook, because an expired timeout (explicit,
|
||||
or the 600 s default) means the tool is not run.
|
||||
5. **A `bash` route to the same action**: the tool limit, on both
|
||||
harnesses. A hook keyed on a tool name doesn't stop the same effect
|
||||
through `bash`.
|
||||
6. **An Agent SDK callback that throws**: the tool limit; the callback
|
||||
fails open. A callback is usable as a hook only if it catches its own
|
||||
errors and returns deny, which is what sdk-6a shows.
|
||||
|
||||
### Out of scope
|
||||
|
||||
- Codex (after v1).
|
||||
|
||||
Reference in New Issue
Block a user