docs: lead decision 77, row 41 (S6) may change packages/bus and packages/cli; launcher in the trusted host accepted

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 18:03:11 -05:00
co-authored by Claude Opus 5.5
parent b6d2fe2b28
commit be65cff380
+23
View File
@@ -1572,3 +1572,26 @@ which stay with him. Each item names who decided it and what happened.
PM through the broker.
- Stop: `systemctl --user stop mosaic-bus@mosaic-stack`. Data:
`~/.mosaic-dev/bus/`.
77. **Row 41 (S6) may change packages/bus and packages/cli (2026-10-09).**
Filbert's plan (agents/filbert/work/s6/PLAN.md) puts the session
launcher in the trusted bus host, because only the host holds the IPC
channel that binds a launch. That reaches past the brief's file list.
Sage accepts it.
- packages/bus gains IPC ops (identity, authorize, refuse, endLaunch,
credentialStatus) and `Broker.endLaunch`. packages/cli gains a host
launch socket and `mosaic bus start <business> --pm <harness>:<model>`.
No broker socket verb, no event kind, no schema change. If review
finds one, it comes back to Sage first.
- Darkwing's review on #1523 covers the new IPC ops as a trust
boundary, not only the harness and seat packages.
- The capability file (0600, in the run directory) is removed once the
runner reads it.
- The PID namespace per session narrows the decision 62 gap. Its limits
go in the package README as limits.
- A model in no `launch.max` family is refused. That's the fail-closed
reading and it stands.
- The live `mosaic-bus@mosaic-stack` unit runs `scripts/mosaic` from
this checkout, so it picks up S6 on its next restart. Sage restarts
it after S6 lands and records the restart. The recorded PM→coder run
stays on a scratch data root.