diff --git a/docs/SESSIONS.md b/docs/SESSIONS.md index eea6a344..22280baf 100644 --- a/docs/SESSIONS.md +++ b/docs/SESSIONS.md @@ -10,3 +10,4 @@ are never rewritten or removed; corrections are new entries. | 2026-09-03 | assistant (conductor) | User layer: profile updates (pets, family), ms-user skill review/revision (confirmation rules merged, propose-not-apply, missing-file flow, privacy scope, dispatch = all of user/, rule 9 scratch-file constraint), USER.md.bak removed | skills/ms-user/SKILL.md rewritten; ~/.mosaic-dev/user/USER.md updated (Family, Pets); USER.md.bak deleted | | 2026-09-03 | assistant | ms-communications skill: inter-agent messaging protocol consolidated from tools/tmux/README.md and agent-send.sh (channel, preamble grammar, flip-on-reply, triage classes, etiquette, receiving protocol, delivery mechanics) | skills/ms-communications/SKILL.md created; unslop-check clean | | 2026-09-03 | assistant (conductor) + ms-test collaborator (worker, glm-5.3-flash) | Conductor-loop calibration (#43): decompose → dispatch via agent-send.sh → receipt → line-by-line diff review (claims verified vs tool source) → suite-gated integration; CURRENT.md staleness corrected (M16/M17 late-logged, next action → M18) | docs/TOOLS.md tools/ section + suite-count fix; issue #43 closed; suites 24/74/14/17 + verify green | +| 2026-09-03 | owner + assistant (conductor) + ms-test collaborator | Skill revisions adjudicated (#44): ms-communications integrated as-authored (owner preamble restructure + collaborator delivery-discipline hunks); ms-conductor collaborator redraft integrated with conductor remediation (step 3 refusal-vs-outage distinction; preserves owner's outage-dispatch intent inside fail-closed canon); TOOLS.md gains release.sh ensure row | skills/ms-communications/SKILL.md, skills/ms-conductor/SKILL.md, docs/TOOLS.md; suites 24/74/14/17 + verify green; unslop clean ×3 | diff --git a/docs/TOOLS.md b/docs/TOOLS.md index 7196f495..401d9604 100644 --- a/docs/TOOLS.md +++ b/docs/TOOLS.md @@ -56,6 +56,7 @@ persistent named session, optional workspace. Exit with `/quit`. | `scripts/release.sh activate` | Health gate → atomic pointer swap | `--fault-injection` proves the refusal path | | `scripts/release.sh rollback` | Health-gated return to previous | Refuses if image missing | | `scripts/release.sh status` | Release, tag, active pointer, log | Safe on empty state | +| `scripts/release.sh ensure` | Self-determination: align active pointer to `RELEASE` | Fast path restores a missing/mismatched pointer without a gate; slow path packages + health-gates first. Invoked automatically at launch | ## Conductor (worker patches) diff --git a/skills/ms-communications/SKILL.md b/skills/ms-communications/SKILL.md index 9a42aa1d..8081140b 100644 --- a/skills/ms-communications/SKILL.md +++ b/skills/ms-communications/SKILL.md @@ -16,24 +16,35 @@ SESSIONS.md, never in a pane that scrolls away. submits reliably (bracketed paste, Enter flush, draft detection), and ships itself over ssh for remote targets. Never raw `tmux send-keys`; that is how messages die as unsubmitted drafts. -- Non-Fleet seats use the default docket. -- Fleet seats use the named socket: `-L mosaic-fleet` (or `MOSAIC_TMUX_SOCKET`). - Fleet traffic stays off the user's default tmux server. -- Address durable fleet seats exactly: `=coder0`, not a prefix that might match - two sessions. -- Tool spec and internals: `tools/tmux/README.md`. +- Your own session output is not a send path either. A reply composed as + assistant prose, however well formatted, delivers nothing to the + recipient's pane; a hand-written preamble in prose is decoration, not + delivery. A reply exists only once `agent-send.sh` has run, and its exit + code is the delivery receipt. No rc, no send. -## Preamble (required) +### Preamble +Preamble is prepended to the message when using the `agent-send.sh` script. +Check the script for usage instructions. ``` [: -> :] [ -> class=] # with triage class ``` -`host` is `hostname -s` of the sender's machine; `session` is the tmux session -name. `agent-send.sh` writes the preamble for you. Two rules carry the protocol: +- Non-Fleet seats use the default docket. +- Fleet seats use the named socket: `-L mosaic-fleet` (or `MOSAIC_TMUX_SOCKET`). + Fleet traffic stays off the user's default tmux server. +- Address durable fleet seats exactly: `=coder0`, not a prefix that might match + two sessions. +- Tool spec and internals: `tools/tmux/README.md` + +- `host` is `hostname -s` of the sender's machine; `session` is the tmux session + name. `agent-send.sh` writes the preamble for you. Two rules carry the protocol: 1. Replying? Flip it: `[ -> ] ...`. Answer under your own lane. + The tool performs the flip: aim your send at the original sender's session + (`agent-send.sh -s -C `) and it writes the flipped + preamble for you. Never write the bracket line yourself. 2. A preamble-less cross-agent message is malformed. If you receive one, ask the sender to resend before acting on it. @@ -66,7 +77,10 @@ Class honestly. Never downgrade a question you want answered to `terminal-log`. 1. Read the preamble first. Confirm you are the `dst`. Note the `src`. 2. Triage by class (table above). `actionable` or absent: act now, or reply why not. -3. Reply with the preamble flipped. Cite the run id or issue you acted on. +3. Reply by sending: invoke `agent-send.sh` aimed at the sender's session; the + tool writes the flipped preamble. Cite the run id or issue you acted on. + Formatting the reply into your own output without running the tool leaves + the sender with nothing; that is a dropped reply, not a late one. ## Delivery mechanics diff --git a/skills/ms-conductor/SKILL.md b/skills/ms-conductor/SKILL.md index 9eb7559e..7729e8df 100644 --- a/skills/ms-conductor/SKILL.md +++ b/skills/ms-conductor/SKILL.md @@ -10,12 +10,43 @@ Conducting discipline: direct workers without being one. ## Order of operations -1. Decompose the goal into worker tasks small enough to spec completely in - one prompt: goal, files, constraints, acceptance, self-checks. -2. Dispatch through the task runner. Never raw pi; never a shell one-liner. -3. Extract the worker's diff. Review it line by line before integration. -4. Verify with the suites. A failure reverts; the refusal is recorded. -5. Integrate with attribution. Update the plan and registry. +1. Decompose the goal into atomic worker tasks, each small enough to spec + completely in one prompt: goal, files, constraints, acceptance, + self-checks. Recursive decomposition is "fail → smaller task", never hope. +2. Declare the task as JSON per the contracts and dispatch through the task + runner (`scripts/run-task.sh run `). Never raw pi; never a + shell one-liner. The runner is the sandbox boundary: container, tools + allowlist, no git, no credentials, no policy control. +3. Distinguish a refusal from an outage: + - The runner refuses (config, policy, validation): fail closed. Diagnose, + report blocked, stop. Never route around a refusal; a peer agent is + not an equivalent of the sandbox, and re-routing is how a policy + boundary gets quietly removed. + - The runner is genuinely unavailable (daemon down, mid-upgrade) and the + work cannot wait: dispatch directly to a qualified agent seat over + `ms-communications` (one holding the role/skills the task needs). + Record the degradation loudly: no sandbox, no run record. Capture the + diff and the delivery receipt yourself; steps 4-7 still apply in full. +4. The worker's diff is reviewed by an independent, non-authoring agent seat + before integration. The seat that authored a change never reviews it. + Bad output goes back: refine the prompt, re-dispatch, same session. +5. Verify with the suites. A failure reverts; the refusal is recorded. +6. Integrate with attribution (`scripts/conductor-apply.sh`). Commit only + after suites are green; push stays an explicit act. +7. Record in the repo's canon surfaces only: `docs/plans/CURRENT.md` (the + one next action), `BUILD-LOG.md` (phase entries), `docs/SESSIONS.md` + (session registration). There is no TASKS.md or STATE.md here; do not + invent scratch tracking files. +8. Send status updates with `ms-communications`; its triage classes apply. + +## Cadence + +One action in flight. Read `docs/plans/CURRENT.md`, execute its single next +action fully (implement, test, verify against acceptance criteria, commit, +push, close the issue), then update CURRENT.md and register in SESSIONS.md. +A batch mandate ("run the queue") repeats the loop until green or blocked. +Blocked means stop and report, never improvise. Waiting on a long worker run? +Arm `agent-watch` on the condition; never poll a colleague's pane. ## Gotcha ledger