From 85e8f97dbf5b738450bbdf0dc6cfe9e744c4a7c8 Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Mon, 5 Oct 2026 16:43:34 -0500 Subject: [PATCH] docs(plans): slice 1 brief accepted, S0 rely-on lines in S6; lead decisions 62-63 Co-Authored-By: Claude Opus 5.5 --- docs/plans/2026-09-26_lead-decisions.md | 52 +++++++++++++++++++++++++ docs/plans/2026-10-04_slice-1.md | 50 ++++++++++++++++++++++-- 2 files changed, 99 insertions(+), 3 deletions(-) diff --git a/docs/plans/2026-09-26_lead-decisions.md b/docs/plans/2026-09-26_lead-decisions.md index 126241ce..06fc2430 100644 --- a/docs/plans/2026-09-26_lead-decisions.md +++ b/docs/plans/2026-09-26_lead-decisions.md @@ -1034,3 +1034,55 @@ which stay with him. Each item names who decided it and what happened. it's done. - Jason hasn't said whether he accepts the slice 1 brief as a whole, so row 11's second accepted brief is still open. +62. **Jason's answers, rounds 2 and 3: the brief is accepted, merges are + gated, S7 is strict, and the human proof is cooperative + (2026-10-05).** Source: Jason's answers in Sage's thread 1ef1e4f8. + - Jason accepts the slice 1 brief as written, with no scope question. + That's row 11's second accepted brief, so row 11 closes. + - Every merge of a coder-bot pull request is a gated decision. Each + of S7's five pieces reaches Jason at least once for its merge, and + S7 counts that as expected, not as a failure. + - S7 is strict. If Jason steps in on a piece with a correction that + isn't a gated decision, the piece fails, the correction is logged + as a finding, and the count of five starts again. + - Vikunja tokens keep the runbook's 90-day lifetime. + - The human proof (REQ-DEC-3) is cooperative in slice 1. On one OS + user, an agent that deliberately escapes S2's /proc check gets a + human capability, as Darkwing showed with `setsid -f env -i` + (`agents/darkwing/work/slice1-s2-review/review-r2.md`). The proof + stops an agent that runs `mosaic decide` directly, and that is all + slice 1 claims for it. S6 closes the gap for managed agents: they + run in their own PID namespace or user, with no human socket + mounted. A T3 seat that runs the human CLI or works around the + proof breaks the rules, and the trail shows it. + - Darkwing's `npm install` on 2026-10-04 rewrote `~/package.json` and + `~/package-lock.json`. Jason says the old contents didn't matter. + Nothing gets restored. +63. **S1's extras, and two S2 rulings (2026-10-05).** Sources: Filbert's + S1 verdicts (#1518 comments 26724 and 26730), Darkwing's S2 reviews + (`agents/darkwing/work/slice1-s2-review/`, #1519). + - S1's extras are accepted. The action vocabulary lives in + `packages/business/src/vocabulary.mjs`, not `contracts/`, because + only host code reads it, and Filbert checked that the image copies + nothing that uses it. The example business file lives at + `packages/business/examples/mosaic-stack.example.json` and refuses + as shipped. `scripts/mosaic` gains a `business` branch, the same + way it carries `queue`. The runbook's section 4 should point to + that example when it is next revised. + - A cross-role decision raised by its own arbiter goes to the human, + and its class stays cross-role. Routing it to the other arbiter + would be a guess about who's qualified, and sending it to the + human fails closed. Rocko built this in S2 round 2. + - A gated approval is single-use. Today one resolved approval + authorizes the same action, target and run any number of times + (Darkwing's P3 deploys three times). `authorize` must record that + it consumed an approval, and a second use refuses. This doesn't + reopen S2's approved round 2. It comes in a new row owned by + Rocko and reviewed by Darkwing, and it has to land before S3 or + S6 calls `authorize` for a gated action. If it needs a schema + change, Darkwing writes a v3c. + - Dewey's list of what the views need beyond the Q1 verbs + (`agents/dewey/work/wui/SLICE1-VIEWS.md` section 9) goes to Rocko + for S4. Session events belong to S6, and credential events belong + to S3. Anything S4 doesn't add is labeled "not in the Q1 module" in + S5. diff --git a/docs/plans/2026-10-04_slice-1.md b/docs/plans/2026-10-04_slice-1.md index ae0773a3..5b4e04cd 100644 --- a/docs/plans/2026-10-04_slice-1.md +++ b/docs/plans/2026-10-04_slice-1.md @@ -1,8 +1,8 @@ # Slice 1: the first working system (2026-10-04) -Status: written by Sage, lead, for Jason's acceptance. Each `##` section -below is the brief for one queue row, in the shape set by -`docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the +Status: accepted by Jason as written, 2026-10-05 (lead decision 62). +Each `##` section below is the brief for one queue row, in the shape set +by `docs/plans/BRIEF-TEMPLATE.md`. This first section covers what all the rows share. ## What slice 1 is @@ -495,6 +495,50 @@ owns (REQ-CLI-2). session without a window, `mosaic talk` reaches it, and Sage's T3 thread hands over. After this step the product doesn't depend on T3. +### What S6 can rely on (row S0) + +Copied unchanged from `agents/filbert/work/slice1-probes/MATRIX.md` at +4b7405b8, which Darkwing approved in round 2 (#1516 comment 26729). No case +probes the N + K boundary in line 4, so leave a few seconds of margin +below the hook's timeout. + +One line per case. "Tool limit" means Pi `--tools` and Claude `--tools` or +`--disallowedTools`. These are rules the harness applies, not walls +(agents run as Jason's OS user). + +1. **A gate that blocks**: the hook, on both harnesses: a Pi `tool_call` + block, a Claude command hook (exit 2 or JSON deny, which holds under + `bypassPermissions`), or an SDK callback deny. The launcher must not + pass `--bare`, which turns Claude settings hooks off. +2. **A gate that crashes**: on Pi, the hook, because a throw blocks and a + `process.exit` ends the run. On Claude Code, a command hook wrapped as + ` || exit 2`, because the wrapper turns a crash into a block + (cc-7d); an unwrapped hook fails open (cc-2). An SDK callback fails + open; see line 6. +3. **A gate at a missing path**: on Pi, the hook, because a missing or + unloadable `-e` refuses to start. On Claude Code, a command hook wrapped + as ` || exit 2`, because `/bin/sh` fails on a missing or + non-executable command and the wrapper turns that into a block (cc-7e, + cc-7f); an unwrapped one is silently skipped (cc-3, cc-3b). +4. **A gate that times out**: + - On Pi, the hook, which never lets the tool run, but only with an + external wall clock and an `agent_end` check. Pi has no handler + timeout, and a gate whose pending promise holds nothing open lets Pi + exit 0 mid-turn. + - On Claude Code, a command hook wrapped as `timeout -k K N || + exit 2`, with the hook's `timeout` above N + K (cc-7g, cc-7h). An + unwrapped hook whose timeout expires (explicit, or the 600 s default) + lets the tool run, and so does a wrapped one without `-k` whose gate + ignores SIGTERM (cc-7i) or whose inner timeout is too long (cc-7j). + - For an SDK callback, the hook, because an expired timeout (explicit, + or the 600 s default) means the tool is not run. +5. **A `bash` route to the same action**: the tool limit, on both + harnesses. A hook keyed on a tool name doesn't stop the same effect + through `bash`. +6. **An Agent SDK callback that throws**: the tool limit; the callback + fails open. A callback is usable as a hook only if it catches its own + errors and returns deny, which is what sdk-6a shows. + ### Out of scope - Codex (after v1).