From be65cff380bd85f9455d19c98333d9848a81938b Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Fri, 9 Oct 2026 18:03:11 -0500 Subject: [PATCH] docs: lead decision 77, row 41 (S6) may change packages/bus and packages/cli; launcher in the trusted host accepted Co-Authored-By: Claude Opus 5.5 --- docs/plans/2026-09-26_lead-decisions.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/docs/plans/2026-09-26_lead-decisions.md b/docs/plans/2026-09-26_lead-decisions.md index ee024ffd..c5c576c6 100644 --- a/docs/plans/2026-09-26_lead-decisions.md +++ b/docs/plans/2026-09-26_lead-decisions.md @@ -1572,3 +1572,26 @@ which stay with him. Each item names who decided it and what happened. PM through the broker. - Stop: `systemctl --user stop mosaic-bus@mosaic-stack`. Data: `~/.mosaic-dev/bus/`. + +77. **Row 41 (S6) may change packages/bus and packages/cli (2026-10-09).** + Filbert's plan (agents/filbert/work/s6/PLAN.md) puts the session + launcher in the trusted bus host, because only the host holds the IPC + channel that binds a launch. That reaches past the brief's file list. + Sage accepts it. + - packages/bus gains IPC ops (identity, authorize, refuse, endLaunch, + credentialStatus) and `Broker.endLaunch`. packages/cli gains a host + launch socket and `mosaic bus start --pm :`. + No broker socket verb, no event kind, no schema change. If review + finds one, it comes back to Sage first. + - Darkwing's review on #1523 covers the new IPC ops as a trust + boundary, not only the harness and seat packages. + - The capability file (0600, in the run directory) is removed once the + runner reads it. + - The PID namespace per session narrows the decision 62 gap. Its limits + go in the package README as limits. + - A model in no `launch.max` family is refused. That's the fail-closed + reading and it stands. + - The live `mosaic-bus@mosaic-stack` unit runs `scripts/mosaic` from + this checkout, so it picks up S6 on its next restart. Sage restarts + it after S6 lands and records the restart. The recorded PM→coder run + stays on a scratch data root.