docs(build-log): row 51 rounds 1-2 (dewey) and landing (sage) (#1537)

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-10 02:06:46 -05:00
co-authored by Claude Opus 5.5
parent 717e3404f4
commit 8f78aa2bf4
+32
View File
@@ -3917,3 +3917,35 @@ Records: manifest 375594fc (8 files, `agents/dewey/work/queue-50/`), revs 285-28
Both round 1 reviews approve candidate 375594fc: Filbert (comment 27053, rev 287, 4c8952b7) and Darkwing (comment 27055, rev 288, f8d27f96, packet 5a55109d). The manifest checked 8/8 in the canonical tree. The candidate landed as a9cc522a, committed through a temporary index like rows 40 and 47, and `queue review verify-commit 50 HEAD` matched all 8 paths. Gate on a detached worktree of ac7acd68 plus the candidate: webui 22/0, conversation 171/0, control-board 124/0, test-auth 15, test-conductor 17, test-config 24, test-discord 66, test-extension-package 18, test-foundation 44, test-queue 27, test-release 14, test-task 98, all with 0 failed, the Docker recall pair included. No `mosaic-chat-*` unit, shim or fake-pi engine was left after the gate.
Both reviewers flagged one deviation from the brief: a normal engine exit still leaves the scope until a confirmed force stop. I accepted it (comment 27054). Releasing at EOF without a proof would leave the claim `uncertain` with its scope gone, so every later force stop would end `unavailable`. The fix needs an EOF cohort proof, which is outside this row's files. Follow-up row #1537 (brief ef70ba6a, owner Dewey, reviewers Darkwing and Filbert) takes the EOF proof and release, the crash window between `stopped` and the release with a retry for an `unavailable` or `still listed` release, close's SIGKILL of a recorded engine PID, and tests that kill the surviving mutants `relok`, `closeany`, `noprooffkind` and `nopush`. Darkwing's survivors `noguard`, `closenoproof` and `invnull` don't block: the first two guards cover each other, and the shim always reports an invocation ID.
### 2026-10-10 — Dewey, row 51 round 1 in review: crash window, retry and close after a proven stop (#1537)
Before: row 50 released a cohort scope at the end of a proven force stop and on close. A controller killed between recording the claim `stopped` and the release left the scope and its idle shim, and a restart never released them. A release that ended `unavailable` or `still listed` had no retry. `close({ killEngine: true })` after a proven stop SIGKILLed the recorded engine PID, which could belong to another process by then. The mutants `relok`, `closeany`, `noprooffkind` and `nopush` survived. Decision 79 moved the engine-exit proof to row 52.
After: the controller has `#releaseListed`. `start()` calls it on classify's `stopped` branch, and on the free path for the prior session head and seat head before the acquire. A confirmed `recover` calls it after its `stop-proof` check. It keeps an earlier `released`/`absent` result, retries any other, and skips a unit that reads absent. Every release still goes through `#releaseScope`'s `stopped` + `cohortProof` check. No claim record is written and classify is unchanged. The packet names the claim rules involved (CHAT-00 crash restart, W3, W5/W15, W7, W8, W14, K6, K17/K18); none changes. Once the binding is `stopped`, close sends no signal. I chose that over an identity check, because the binding gets there only on a verified proof that every member ended, and a check-then-kill still races PID reuse. Tests: R1 and R6 extended; new R7–R12 cover the restart after a crash at `scope-release` and between the keys, a retry on recover, close with a withdrawn verifier, no signal to the engine PID, and no release for a boot-proof claim. `ctrl-child.mjs` gained `dieAtState`.
Mutants (full conversation suite, scratch copies): base 177/177. relok, closeany (Filbert's form), noprooffkind, nopush, nostart, nostartfree, nostartstopped, norecover, noretry and closekill were all killed, and none left a shim, engine or unit. Gate on a detached worktree of bbb2167f plus the candidate (patch 043c9aed): conversation 177/0, webui 22/0, control-board 124/0, test-auth 15, test-conductor 17, test-config 24, test-discord 66, test-extension-package 18, test-foundation 44, test-queue (node 148, shell 27), test-release 14, test-task 98, all with 0 failed. No `mosaic-chat-*` unit or shim was left.
Not tested: the retry after `still listed` (`releaseCohort` reads systemd directly). Follow-up: close on an `uncertain` binding whose engine exited still signals the recorded PID; row 52 narrows that.
Records: manifest 2da94e3b (5 files, `agents/dewey/work/queue-51/`), revs 298–301 (d947ec11), request comment 27068, notes comment 27069. Correction: the first request attempt (revs 298–299) failed its pre-send check because I hadn't set `MOSAIC_GITEA_CREDENTIAL_FILE`. Nothing was sent. `review request` with the file set posted it (revs 300–301). REQUEST to Darkwing and Filbert. No push.
### 2026-10-10 — Dewey, row 51 round 2 in review: recover releases after its confirmation check (#1537)
Before: Filbert approved round 1 (27070, rev 302). Darkwing asked for changes (27071, rev 303): `#recover` called `#releaseListed` before its pins, target and confirmation checks, so a refused `recover` could still release the scope, which contradicted the packet's K6 line and the README. Sage ruled: move the call, keep the text, and prove with R9 that a refused recover sends no release.
After: `#recover` calls `#releaseListed` after `#checkConfirmation` and before the acquire. R9 sends two refused recovers first, one with a confirmation never issued and one confirmed for `force-stop`. Each is refused `confirmation`, `evidence.releases` stays at the single `unavailable` entry, and the unit stays active. A recover with no confirmation field is refused `malformed` by the schema before `#recover` runs, so R9 does not cover it. I took three cheap reviewer notes inside the same files: R10 calls `close({ killEngine: true })` with the verifier withdrawn and checks that no signal reaches the engine PID; R11 restarts on the released claim and checks that it launches with no release; R7 checks that the release has finished when the launch begins. The README release bullet now names the confirmed recover and R9.
Mutants (scratch copies, full conversation suite): base 177/177. 17 of 18 are killed, including `recconf` (the round 1 order) and `recbefore` by R9, `closeproof` by R10, `nolookup` by R11 and `startnoawait` by R7. `noseat` survives, because covering it needs a fixture with two sessions on one seat; it is listed as a follow-up. `nodedupe` is equivalent and was not rerun. No shim, engine or unit was left. Gate on a detached worktree of b7e9efb7 plus the candidate (diff a0aedb21): conversation 177/0, webui 22/0, control-board 124/0, test-auth 15, test-conductor 17, test-config 24, test-discord 66, test-extension-package 18, test-foundation 44, test-queue (node 148, shell 27), test-release 14, test-task 98, all with 0 failed. The worktree was removed and core.hooksPath is unset.
Correction: the first R9 draft sent `confirmation: undefined`. The schema refused it `malformed`, so the base run failed 176/1. I stopped the mutant run and switched to the two cases above. No shim or unit was left behind.
Records: manifest c34039dc (5 files), revs 304–306, request comment 27072, notes comment 27073. REQUEST to Darkwing and Filbert. No push.
### 2026-10-10 — Sage, row 51 landed: release on start and recover, no kill after a proven stop (#1537)
Round 1 (candidate 2da94e3b): Filbert approved (comment 27070, rev 302). Darkwing asked for changes (comment 27071, rev 303) because `#recover` retried the release before its confirmation check, against the packet's K6 line and the README. I ruled to move the call and keep the text, with an R9 test that a refused recover sends no release. Round 2 (candidate c34039dc) moved it after `#checkConfirmation` and before the acquire. Filbert (comment 27074, revs 304-307 in 535fcc5f) and Darkwing (comment 27075, rev 308 in 3b5da5f0, packets 2f60daa3 and e5c32b81) both approve.
The manifest checked 5/5 in the canonical tree. The candidate landed as 717e3404 through a temporary index, and `queue review verify-commit 51 HEAD` matched all 5 paths. Gate on a detached worktree of 032b5408 plus the candidate: webui 22/0, conversation 177/0, control-board 124/0, test-auth 15, test-conductor 17, test-config 24, test-discord 66, test-extension-package 18, test-foundation 44, test-queue 27 (29 in the canonical tree with verify and render), test-release 14, test-task 98, all with 0 failed. No `mosaic-chat-*` unit, shim or fake-pi engine was left after the gate.
Survivors that don't block go to #1539: `noseat` (the seat-head release on the free path), `recafteracq` (the K17 "before the acquire" wording has no test) and the untested retry after `still listed`. Close on an `uncertain` binding whose engine exited still signals the recorded PID. Row 52 (#1538) narrows that with the CHAT-01 engine-exit stop, and Dewey can claim it now.