feat(board): session attention, Discord rows, task attribution and relaunch activity (rows 18, 22, #1511, #1512)

One cumulative control-board, webui and seat state. The four rows edit the
same files (scan.mjs, page.html, README.md, app.js), so they land together,
each on its own receipt:

- Row 18, Discord connector rows on the board (#1509): R3 approved by
  Darkwing and Dewey, Gitea comment 26257, manifest 254403b8. Jason
  accepted the visual test.
- Row 22, board attention status (#1503): Filbert approved R1, comment
  26248, manifest e40b58ec; restart receipt 26249.
- #1511, task attribution (row 6 code phase): R2 approved by Filbert and
  Dewey, manifest d4c96395. docs/TOOLS.md carries the approved --by usage
  line (tools-usage.patch 86bcba3c).
- #1512, relaunch activity (row 6 pilot): R1 approved by Darkwing and
  Dewey, candidate manifest 47769fad. All seven source files match it.

Row 16, internal development bootstrap (#1510): the seven files outside
shared records match Filbert's R1 pins, receipt 26204 (agents/researcher/*,
scripts/test-darkwing-launch.mjs, the bootstrap plan).

packages/webui/src/public/app.js is committed at its #1512 R1 pin ce7d79a4.
The working copy holds Dewey's unreviewed return-flow candidate on top of
that, and it stays uncommitted.

Also: the four row briefs and Darkwing's evidence records under
agents/darkwing/work, including the 2026-09-26 tree manifest and the #1512
re-run against 21e3e908. Serial acceptance command: 397/397, three runs.
The failures that only show when tests run concurrently are in #1509 engine
tests, and they reproduce on clean HEAD.

Suites on the exact staged tree: config 24, task 90, foundation 43,
conductor 17, release 14, auth 15, discord 63; package union 397/397
(serial); test-darkwing-launch 5/5.

Shared records (BUILD-LOG, QUEUE, CURRENT, DEFERRED, SESSIONS, AGENTS.md,
agents/README.md) follow in Sage's records commit.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-09-26 14:54:18 -05:00
co-authored by Claude Opus 5.5
parent 21e3e908b6
commit af4203ca92
67 changed files with 2417 additions and 78 deletions
@@ -0,0 +1,28 @@
# Independent acceptance checklist, row 18
Darkwing reviews Filbert's implementation without editing its source candidate.
Dewey reviews visible connector presentation. No live connector manipulation.
- Discovery accepts only safe matching binding name/seat from private regular
files, never dereferences a token path and never serializes private fields.
- Path traversal, symlinked binding/runtime/session paths and malformed records
cannot cause arbitrary reads or an actionable/live row.
- No owner, malformed owner, dead PID, missing identity, reused PID and boot
mismatch are non-live. A positively matching live process is live.
- STOP presence is visible as braked independently of process liveness. Its
contents are not read or exposed; no STOP or lock is created or changed.
- Ordinary completed messages remain idle. No false human attention regression.
- Connector rows cannot borrow a native agent's registration for replies.
Exercise replyToRow and HTTP using a fake executable hook; every connector
attempt must be refused before that hook runs, including with forged tmux
registration. Normal-agent reply tests must still pass.
- Both existing board and WebUI distinguish the connector and brake state and
omit reply controls. Preserve escaping, including hostile binding fixtures.
- Discovery errors disclose no private JSON fields or raw contents. One bad
binding must not silently manufacture a healthy row.
- Candidate pins match before and after tests. Existing dirty attention changes
remain intact; no unrelated source integration or live operation is inferred.
After source approval, measure the real row read-only. Offline/braked behavior
uses isolated fixtures unless the operator separately approves a live-service
transition. Board replacement is its own protected gate.
@@ -0,0 +1,23 @@
{
"at": "2026-09-14T13:51:10.530662+00:00",
"backendPid": 3769124,
"health": "ok",
"row": {
"agent": "sage (discord: shared-signals)",
"project": "fleet",
"state": "idle",
"alive": true,
"connector": {
"binding": "shared-signals",
"braked": false,
"ownerState": "live",
"alive": true
},
"task": "Discord connector",
"taskSource": "connector"
},
"replyStatus": 409,
"replyError": "board replies are disabled for Discord connectors",
"fiveAgentPaneIdentitiesUnchanged": true,
"connectorServiceIdentityUnchanged": true
}
@@ -0,0 +1,2 @@
{"at": "2026-09-14T13:50:24.078636+00:00", "event": "owner-authorized-restart-intent", "oldPid": 3204655, "agents": {"default/darkwing": [["2733924", "12863634"]], "default/dewey": [["934346", "466065"]], "default/filbert": [["72183", "100870"]], "default/researcher": [["173699", "66404285"]], "mosaic-fleet/rocko": [["90599", "128275"]]}, "connectorService": [3022843, "67887873"], "manifest": "254403b89c0a2330da53e8dbad1cbeba3b1b06cf4f3efddc18451e04cb78f6de"}
{"at": "2026-09-14T13:50:24.503231+00:00", "event": "replacement-started", "oldExitedGracefully": true, "newPid": 3769124, "log": "/tmp/discord-board-backend-ovk_cahk.log"}
@@ -0,0 +1,18 @@
{
"at": "2026-09-14T01:10:19.375709+00:00",
"candidate": "/tmp/discord-board-r1-KbMrGQWF",
"manifestSha256": "5c92acc90d202727d790f3fb8d74387db1c9e5c3e43d4f4b56b40e5ae503a56a",
"verdict": "CHANGES REQUIRED",
"independentSerializedTests": 320,
"finding": {
"id": "R1-B1",
"severity": "P2",
"file": "packages/control-board/src/discord.mjs",
"issue": "STOP metadata access errors collapse to absence, falsely projecting not braked",
"reproduction": "Synthetic journal directory contains STOP, chmod directory to 000 as uid 1000, inspectDiscord returns braked:false, ownerState:invalid, alive:false. Restore permissions and remove fixture.",
"expected": "braked:null/unknown when STOP existence cannot be established; false only for verified absence",
"required": "Distinguish missing metadata from access errors and add non-root unreadable-directory regression."
},
"ux": "Dewey APPROVE on exact R1; three independent serialized browser tests passed, source/automation limitations retained",
"parallelQualification": "Two author concurrent frozen timeouts remain unresolved and are not green; serialized independent run passed."
}
@@ -0,0 +1,7 @@
{
"candidate": "R2",
"syntheticOnly": true,
"taskContainsEnvelopeAuthorId": true,
"taskContainsEnvelopeMessageId": true,
"taskSource": "first-user-message"
}
@@ -0,0 +1,18 @@
{
"at": "2026-09-14T01:26:42.688410+00:00",
"candidate": "/tmp/discord-board-r3-U9vVrlQu",
"manifestSha256": "254403b89c0a2330da53e8dbad1cbeba3b1b06cf4f3efddc18451e04cb78f6de",
"reviewer": "Darkwing",
"backendVerdict": "APPROVE AS SOURCE",
"verified": "Nine working/frozen pins, exact three-file R2-to-R3 delta, inherited attention pins and full serialized six-package suite 322/322",
"findingsClosed": [
"R1-B1: inaccessible STOP is unknown, non-root regression passes",
"R2-B2: canonical routing envelope no longer becomes connector Task; ordinary fallback retained"
],
"limitations": [
"No generalized transcript redaction",
"R1 concurrent combined frozen timeouts unresolved/not green",
"No live observation, backend restart, connector change or publication in this review"
],
"uxGate": "Await exact R3 confirmation from Dewey via agent-send"
}
@@ -0,0 +1,20 @@
{
"at": "2026-09-14T01:28:17.695Z",
"sourceApproval": 26257,
"readOnly": true,
"agent": "sage (discord: shared-signals)",
"project": "fleet",
"state": "idle",
"alive": true,
"connector": {
"binding": "shared-signals",
"braked": false,
"ownerState": "live",
"alive": true
},
"task": "Discord connector",
"taskSource": "connector",
"registrationAbsent": true,
"ownerMatchesService": true,
"discoveryErrorCount": 0
}
@@ -0,0 +1,9 @@
{
"at": "2026-09-14T00:50:35.339Z",
"sourceSha256": "dfbb7ab9374c0ac9fafa0503f495abd938f499f5d6227233de03a60ea3022927",
"fixture": "connector row with forged native registration",
"status": 200,
"fakeTransportCalls": 1,
"realTransportCalls": 0,
"gatePassed": false
}