From cd4409abc3d5d332a522c68f01a331449a8d56de Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Mon, 10 Aug 2026 14:53:21 -0500 Subject: [PATCH] Move old docs into _old_structure dir. Create blank GETTING_STARTED.md document --- docs/GETTING_STARTED.md | 0 .../architecture/ADR-MOS-EGRESS-GATEWAYS.md | 0 .../architecture/channel-protocol.md | 0 .../architecture/compaction-revocation.md | 0 .../architecture/lease-broker-protocol.md | 0 .../architecture/lease-broker-security.md | 0 .../mos-runtime-portability-m1.md | 0 .../architecture/mutator-class-gate.md | 0 .../MISSION-MANIFEST.md | 0 .../cli-unification-20260404/TASKS.md | 0 .../harness-20260321/MISSION-MANIFEST.md | 0 .../archive/missions/harness-20260321/PRD.md | 0 .../MISSION-MANIFEST.md | 0 .../install-ux-hardening-20260405/TASKS.md | 0 .../MISSION-MANIFEST.md | 0 .../missions/install-ux-v2-20260405/TASKS.md | 0 .../install-ux-v2-20260405/iuv-m03-design.md | 0 .../install-ux-v2-20260405/scratchpad.md | 0 .../missions/storage-abstraction/TASKS.md | 0 .../AUDIT-2026-02-17-framework-consistency.md | 0 .../briefs/monorepo-consolidation.md | 0 .../probes/p5_receipt_replay.py | 0 .../probes/p6_constrained_recovery.py | 0 .../deploy/portainer/README.md | 0 .../deploy/portainer/federated-test.stack.yml | 0 .../design/791-upgrade-config-protection.md | 0 .../framework-constitution/ALPHA-DOD.md | 0 .../prerelease-next-dist-tag-pipeline.md | 0 .../design/storage-abstraction-middleware.md | 0 .../federation/ADMIN-CLI.md | 0 .../federation/MILESTONES.md | 0 .../federation/MISSION-MANIFEST.md | 0 docs/{ => _old_structure}/federation/PRD.md | 0 docs/{ => _old_structure}/federation/SETUP.md | 0 docs/{ => _old_structure}/federation/TASKS.md | 0 .../fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md | 0 .../fleet/FLEET-LAUNCH.md | 0 ...Y-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md | 0 docs/{ => _old_structure}/fleet/NORTH_STAR.md | 0 .../fleet/NORTH_STAR.yaml | 0 .../fleet/PRD-fleet-suite.md | 0 docs/{ => _old_structure}/fleet/PRD.md | 0 docs/{ => _old_structure}/fleet/README.md | 0 docs/{ => _old_structure}/fleet/TASKS.md | 0 .../fleet/backlog-conventions.md | 0 .../concepts/desired-vs-observed-state.md | 0 .../concepts/generated-env-launch-chain.md | 0 .../fleet/concepts/identity-class-runtime.md | 0 .../concepts/role-authority-and-leases.md | 0 .../fleet/examples/roster-v2.yaml | 0 .../fleet/f4-matrix-connector.md | 0 .../how-to/configure-tess-interaction.md | 0 .../how-to/configure-ultron-validator.md | 0 .../how-to/create-update-delete-agent.md | 0 .../fleet/how-to/customize-roles.md | 0 .../fleet/how-to/start-stop-restart.md | 0 .../migration/example-profile-disposition.md | 0 .../fleet/migration/legacy-class-aliases.md | 0 .../fleet/migration/v1-to-v2.md | 0 docs/{ => _old_structure}/fleet/north-star.md | 0 .../fleet/operations/backup-restore.md | 0 .../fleet/operations/env-quarantine.md | 0 .../fleet/operations/reconcile-and-recover.md | 0 .../systemd-tmux-troubleshooting.md | 0 .../fleet/operations/upgrade-assets.md | 0 .../fleet/reference/agent-mutations.md | 0 .../fleet/reference/cli.md | 0 .../fleet/reference/generated-env-boundary.md | 0 .../fleet/reference/lifecycle-transitions.md | 0 .../fleet/reference/role-classes.md | 0 .../fleet/reference/roster-v2-fields.md | 0 .../fleet/reference/roster-v2.schema.json | 0 .../fleet/reference/status-and-drift.md | 0 .../guides/admin-guide.md | 0 .../{ => _old_structure}/guides/deployment.md | 0 docs/{ => _old_structure}/guides/dev-guide.md | 0 .../guides/fleet-local-canary.md | 0 .../guides/lease-broker-operations.md | 0 .../guides/migrate-tier.md | 0 .../guides/mos-connector-lease-operations.md | 0 .../guides/upgrade-safety-and-recovery.md | 0 .../{ => _old_structure}/guides/user-guide.md | 0 .../mission-control/BOARD.md | 0 .../mission-control/MISSION-MANIFEST.md | 0 .../mission-control/PRD.md | 0 .../mission-control/TASKS.md | 0 .../DOCUMENTATION-CHECKLIST.md | 0 .../native-kanban-sot/INDEX.md | 0 .../KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md | 0 .../KBN-101-DB-ROLE-SPLIT.md | 0 .../native-kanban-sot/KBN-101-ENVELOPE-A.md | 0 .../native-kanban-sot/MISSION-MANIFEST.md | 0 .../native-kanban-sot/SHARED-CONTRACT.md | 0 .../native-kanban-sot/TASKS.md | 0 .../contracts/health-state.v1.ts | 0 .../contracts/kanban-schema.v1.ts | 0 .../contracts/mechanical-coordinator.v1.ts | 0 .../contracts/recovery-posture.v1.ts | 0 .../native-kanban-sot/tsconfig.json | 0 .../2026-03-13-gateway-security-hardening.md | 0 .../2026-03-15-agent-platform-architecture.md | 0 .../2026-03-15-wave2-tui-layout-navigation.md | 0 .../2026-05-06-hermes-mosaic-alignment.md | 0 .../2026-05-07-coordination-resilience.md | 0 .../2026-08-09-webui-fleet-claude-bridge.md | 0 .../plans/agent-reflection-loop-PRD.md | 0 .../plans/authentik-sso-setup.md | 0 .../plans/chroot-sandboxing.md | 0 .../plans/gatekeeper-service.md | 0 .../plans/gateway-token-recovery.md | 0 .../plans/task-queue-unification.md | 0 .../remediation/BOARD-LEDGER.md | 0 .../{ => _old_structure}/remediation/BOARD.md | 0 .../remediation/DECOMP-OPUS.md | 0 .../remediation/DECOMP-SOL.md | 0 .../remediation/KICKSTART.md | 0 .../remediation/MACP-WIRING-SCOUT.md | 0 .../remediation/MISSION.md | 0 .../{ => _old_structure}/remediation/TASKS.md | 0 .../reports/code-review/756-code-review.md | 0 .../code-review/gateway-security-20260313.md | 0 .../830-documentation-checklist.md | 0 .../deferred/758-fleet-config-deferrals.md | 0 .../756-discord-plugin-checklist.md | 0 .../758-fleet-config-ia-closure.md | 22 +++--- .../canon-final-rereview-go.md | 0 .../canon-initial-review-no-go.md | 0 ...bn-101-contract-security-review-82ce325.md | 42 ++++++------ .../native-kanban-sot/ultron-final-go.md | 0 .../reports/qa/gateway-security-20260313.md | 39 +++++++++++ .../reports/security/756-security-review.md | 37 ++++++++++ .../requirements/native-kanban-sot.md | 0 .../reviews/consolidation-board-memo.md | 0 .../rfcs/RFC-001-MACP-MATRIX-NATIVE.md | 0 .../rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md | 0 .../1000-rm-61-ci-contract-exemption.md | 0 .../2026-06-20-fleet-cli-local-canary.md | 0 .../2026-06-20-fleet-release-hardening.md | 0 .../387-updater-wrapper-gitea-20260404.md | 0 .../scratchpads/41-plugin-host.md | 0 .../462-fed-m3-04-scope-service.md | 0 .../scratchpads/462-fed-m3-06-get-verb.md | 0 .../scratchpads/536-wrapper-login-pin.md | 0 .../scratchpads/544-agent-reflection-loop.md | 0 .../559-560-wrapper-eval-login-20260620.md | 0 .../scratchpads/561-python-is-python3.md | 0 .../scratchpads/631-reseed-preserves-fleet.md | 0 .../scratchpads/633-comms-block-runbook.md | 0 .../scratchpads/672-fleet-personas-timeout.md | 0 .../703-wrapper-interactive-auth.md | 0 .../scratchpads/747-wsa-dehardcode.md | 0 .../scratchpads/751-native-kanban-canon.md | 0 .../scratchpads/753-kbn010-threat-gate.md | 0 .../755-mos-logical-identity-fencing.md | 0 .../756-official-discord-plugin.md | 0 .../758-fcm-m1-002-shared-role-resolution.md | 12 ++-- ...fcm-m1-003-example-profile-dispositions.md | 0 .../758-fcm-m2-002-fleet-agent-crud.md | 0 .../758-fcm-m3-001-local-reconciler.md | 0 ...8-fcm-m3-002-reconciler-lifecycle-gates.md | 22 +++--- .../758-fcm-m4-001-v1-v2-migrator.md | 0 .../scratchpads/771-kbn101-db-role-split.md | 0 .../791-upgrade-config-protection.md | 67 +++++++++++++------ .../scratchpads/804-install-unknown-flags.md | 16 ++--- .../scratchpads/807-glpi-partial-content.md | 10 +-- .../808-agent-send-sender-identity.md | 0 .../scratchpads/812-pr-review-comment.md | 0 .../scratchpads/824-mosaic-skill-cli.md | 16 ++--- .../scratchpads/828-lease-broker.md | 0 .../scratchpads/829-mutator-gate.md | 14 ++-- .../scratchpads/830-compaction-revoke.md | 0 .../832-receipt-challenge-protocol.md | 0 .../833-constrained-recovery-command.md | 0 .../838-broker-acceptance-flake.md | 0 .../B1-next-durable-publish-design.md | 0 .../scratchpads/B2-skills-sync-path.md | 0 .../B3-wizard-gateway-health-order.md | 0 .../scratchpads/B4-wizard-step-dedup.md | 0 .../scratchpads/BUG-CLI-scratchpad.md | 0 .../scratchpads/FED-M3-05-list-verb.md | 0 .../scratchpads/FED-M3-07-capabilities.md | 0 .../scratchpads/FED-M3-09-query-source.md | 0 .../FED-M3-10-integration-tests.md | 0 .../scratchpads/bug-196-admin-redirect.md | 0 .../scratchpads/ci-docker-publish-20260330.md | 0 .../scratchpads/cli-unification-20260404.md | 0 .../scratchpads/f3-m3-update-reseed.md | 0 .../scratchpads/f4-matrix-connector.md | 0 .../fcm-m2-001-generated-env-boundary.md | 0 .../fcm-m5-001-fleet-config-operator-docs.md | 0 .../scratchpads/fix-ci-migrations-20260330.md | 0 .../scratchpads/fix-turbo-env-passthrough.md | 0 .../fleet-cli-local-canary-review-fixes.md | 0 .../scratchpads/fleet-comms-onboarding.md | 0 .../scratchpads/fleet-enhancer-floor.md | 0 .../scratchpads/fleet-observability-phase2.md | 0 .../scratchpads/fleet-polish-bundle.md | 0 .../scratchpads/fleet-standup-fixes.md | 0 .../gateway-install-ux-20260404.md | 0 .../scratchpads/gateway-security-20260313.md | 0 .../git-wrapper-rollup-20260526.md | 0 .../scratchpads/h1-heartbeat-readiness.md | 0 .../scratchpads/h1b-pane-idle-signal.md | 0 .../scratchpads/h2-readiness-available.md | 0 .../scratchpads/harness-20260321.md | 0 .../install-ux-hardening-20260405.md | 0 .../installer-next-fast-npm-20260625.md | 0 .../installer-next-lane-20260624.md | 0 .../issue-766-exact-fleet-comms.md | 0 .../scratchpads/m3-001-provider-adapter.md | 0 .../scratchpads/macp-oc-bridge-20260330.md | 0 .../ms-792-fleet-enoent-installer.md | 0 .../scratchpads/mvp-20260312.md | 0 .../scratchpads/north-star-doctrine.md | 0 .../scratchpads/p5-003-telegram-plugin.md | 0 .../scratchpads/p5-004-authentik-sso.md | 0 .../scratchpads/p5-overlay-composer.md | 0 .../scratchpads/p6-docs-compliance-alpha.md | 0 .../scratchpads/p8-001-sso-providers.md | 0 .../scratchpads/p8-009-tui-slash-commands.md | 0 .../scratchpads/p8-010-command-registry.md | 0 .../p8-012-agent-provider-commands.md | 0 .../scratchpads/p8-016-tool-hardening.md | 0 .../scratchpads/p8-019-verify.md | 0 .../rm-01-reproducible-checkout.md | 0 .../scratchpads/rm-03-queue-guard.md | 26 +++---- .../t-a292e96f-gitea-pr-metadata.md | 0 .../t_301e4e3b-pr-merge-gitea-empty-uid.md | 0 .../t_5aab9cc8-pr-merge-eval-injection.md | 0 .../task-mission-ownership-20260313.md | 0 .../scratchpads/tess-20260712.md | 4 ++ .../tess-m1-002-provider-registry.md | 0 .../scratchpads/tess-m1-003-fleet-provider.md | 16 ++--- .../scratchpads/tess-m1-obs-001.md | 0 .../scratchpads/tess-m1-sec-001.md | 0 .../tess-m1-sec-004-discord-ingress.md | 0 .../tess-m1-sec-006-session-gc-scope.md | 0 .../scratchpads/tess-m2-001-pi-service.md | 0 .../scratchpads/tess-m2-002-durable-state.md | 14 ++-- .../tess-m4-001-mos-coordination.md | 0 .../tess-m4-003-operator-plugins.md | 0 .../scratchpads/tools-md-seeding-20260411.md | 0 .../update-checker-package-20260404.md | 0 .../scratchpads/webui-fleet-bridge-plan.md | 0 .../scratchpads/webui-p2-data-auth.md | 0 .../yolo-runtime-initial-arg-20260411.md | 0 .../tasks/544-agent-reflection-loop.md | 0 .../tasks/WP1-forge-package.md | 0 .../tasks/WP2-macp-package.md | 0 .../tasks/WP3-mosaic-framework-plugin.md | 0 docs/{ => _old_structure}/tess/ADMIN-GUIDE.md | 0 .../{ => _old_structure}/tess/ARCHITECTURE.md | 0 .../tess/DEVELOPER-GUIDE.md | 0 .../tess/M4-003-OPERATOR-PLUGIN-SKETCH.md | 0 .../tess/M5-003-DOCUMENTATION-CHECKLIST.md | 0 .../tess/M5-MIGRATION-CUTOVER.md | 0 .../tess/M5-MIGRATION-INVENTORY.md | 0 .../M5-MIGRATION-RETENTION-DEPRECATION.md | 0 .../tess/M5-MIGRATION-ROLLBACK.md | 0 .../tess/MIGRATION-INVENTORY.md | 0 .../tess/MISSION-MANIFEST.md | 0 .../tess/MOS-COORDINATION.md | 0 .../tess/OPERATIONS-GUIDE.md | 0 .../{ => _old_structure}/tess/PLUGIN-GUIDE.md | 0 docs/_old_structure/tess/TASKS.md | 46 +++++++++++++ .../{ => _old_structure}/tess/THREAT-MODEL.md | 0 docs/{ => _old_structure}/tess/USER-GUIDE.md | 0 .../tess/VERIFICATION-MATRIX.md | 0 .../tess/hermes-runtime-adapter-design.md | 0 .../2026-07-14-option2-runtime-portability.md | 0 docs/reports/qa/gateway-security-20260313.md | 39 ----------- docs/reports/security/756-security-review.md | 37 ---------- docs/tess/TASKS.md | 46 ------------- 273 files changed, 278 insertions(+), 247 deletions(-) create mode 100644 docs/GETTING_STARTED.md rename docs/{ => _old_structure}/architecture/ADR-MOS-EGRESS-GATEWAYS.md (100%) rename docs/{ => _old_structure}/architecture/channel-protocol.md (100%) rename docs/{ => _old_structure}/architecture/compaction-revocation.md (100%) rename docs/{ => _old_structure}/architecture/lease-broker-protocol.md (100%) rename docs/{ => _old_structure}/architecture/lease-broker-security.md (100%) rename docs/{ => _old_structure}/architecture/mos-runtime-portability-m1.md (100%) rename docs/{ => _old_structure}/architecture/mutator-class-gate.md (100%) rename docs/{ => _old_structure}/archive/missions/cli-unification-20260404/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/archive/missions/cli-unification-20260404/TASKS.md (100%) rename docs/{ => _old_structure}/archive/missions/harness-20260321/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/archive/missions/harness-20260321/PRD.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-hardening-20260405/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-hardening-20260405/TASKS.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-v2-20260405/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-v2-20260405/TASKS.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-v2-20260405/iuv-m03-design.md (100%) rename docs/{ => _old_structure}/archive/missions/install-ux-v2-20260405/scratchpad.md (100%) rename docs/{ => _old_structure}/archive/missions/storage-abstraction/TASKS.md (100%) rename docs/{ => _old_structure}/audits/AUDIT-2026-02-17-framework-consistency.md (100%) rename docs/{ => _old_structure}/briefs/monorepo-consolidation.md (100%) rename docs/{ => _old_structure}/compaction-refresh/probes/p5_receipt_replay.py (100%) rename docs/{ => _old_structure}/compaction-refresh/probes/p6_constrained_recovery.py (100%) rename docs/{ => _old_structure}/deploy/portainer/README.md (100%) rename docs/{ => _old_structure}/deploy/portainer/federated-test.stack.yml (100%) rename docs/{ => _old_structure}/design/791-upgrade-config-protection.md (100%) rename docs/{ => _old_structure}/design/framework-constitution/ALPHA-DOD.md (100%) rename docs/{ => _old_structure}/design/prerelease-next-dist-tag-pipeline.md (100%) rename docs/{ => _old_structure}/design/storage-abstraction-middleware.md (100%) rename docs/{ => _old_structure}/federation/ADMIN-CLI.md (100%) rename docs/{ => _old_structure}/federation/MILESTONES.md (100%) rename docs/{ => _old_structure}/federation/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/federation/PRD.md (100%) rename docs/{ => _old_structure}/federation/SETUP.md (100%) rename docs/{ => _old_structure}/federation/TASKS.md (100%) rename docs/{ => _old_structure}/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md (100%) rename docs/{ => _old_structure}/fleet/FLEET-LAUNCH.md (100%) rename docs/{ => _old_structure}/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md (100%) rename docs/{ => _old_structure}/fleet/NORTH_STAR.md (100%) rename docs/{ => _old_structure}/fleet/NORTH_STAR.yaml (100%) rename docs/{ => _old_structure}/fleet/PRD-fleet-suite.md (100%) rename docs/{ => _old_structure}/fleet/PRD.md (100%) rename docs/{ => _old_structure}/fleet/README.md (100%) rename docs/{ => _old_structure}/fleet/TASKS.md (100%) rename docs/{ => _old_structure}/fleet/backlog-conventions.md (100%) rename docs/{ => _old_structure}/fleet/concepts/desired-vs-observed-state.md (100%) rename docs/{ => _old_structure}/fleet/concepts/generated-env-launch-chain.md (100%) rename docs/{ => _old_structure}/fleet/concepts/identity-class-runtime.md (100%) rename docs/{ => _old_structure}/fleet/concepts/role-authority-and-leases.md (100%) rename docs/{ => _old_structure}/fleet/examples/roster-v2.yaml (100%) rename docs/{ => _old_structure}/fleet/f4-matrix-connector.md (100%) rename docs/{ => _old_structure}/fleet/how-to/configure-tess-interaction.md (100%) rename docs/{ => _old_structure}/fleet/how-to/configure-ultron-validator.md (100%) rename docs/{ => _old_structure}/fleet/how-to/create-update-delete-agent.md (100%) rename docs/{ => _old_structure}/fleet/how-to/customize-roles.md (100%) rename docs/{ => _old_structure}/fleet/how-to/start-stop-restart.md (100%) rename docs/{ => _old_structure}/fleet/migration/example-profile-disposition.md (100%) rename docs/{ => _old_structure}/fleet/migration/legacy-class-aliases.md (100%) rename docs/{ => _old_structure}/fleet/migration/v1-to-v2.md (100%) rename docs/{ => _old_structure}/fleet/north-star.md (100%) rename docs/{ => _old_structure}/fleet/operations/backup-restore.md (100%) rename docs/{ => _old_structure}/fleet/operations/env-quarantine.md (100%) rename docs/{ => _old_structure}/fleet/operations/reconcile-and-recover.md (100%) rename docs/{ => _old_structure}/fleet/operations/systemd-tmux-troubleshooting.md (100%) rename docs/{ => _old_structure}/fleet/operations/upgrade-assets.md (100%) rename docs/{ => _old_structure}/fleet/reference/agent-mutations.md (100%) rename docs/{ => _old_structure}/fleet/reference/cli.md (100%) rename docs/{ => _old_structure}/fleet/reference/generated-env-boundary.md (100%) rename docs/{ => _old_structure}/fleet/reference/lifecycle-transitions.md (100%) rename docs/{ => _old_structure}/fleet/reference/role-classes.md (100%) rename docs/{ => _old_structure}/fleet/reference/roster-v2-fields.md (100%) rename docs/{ => _old_structure}/fleet/reference/roster-v2.schema.json (100%) rename docs/{ => _old_structure}/fleet/reference/status-and-drift.md (100%) rename docs/{ => _old_structure}/guides/admin-guide.md (100%) rename docs/{ => _old_structure}/guides/deployment.md (100%) rename docs/{ => _old_structure}/guides/dev-guide.md (100%) rename docs/{ => _old_structure}/guides/fleet-local-canary.md (100%) rename docs/{ => _old_structure}/guides/lease-broker-operations.md (100%) rename docs/{ => _old_structure}/guides/migrate-tier.md (100%) rename docs/{ => _old_structure}/guides/mos-connector-lease-operations.md (100%) rename docs/{ => _old_structure}/guides/upgrade-safety-and-recovery.md (100%) rename docs/{ => _old_structure}/guides/user-guide.md (100%) rename docs/{ => _old_structure}/mission-control/BOARD.md (100%) rename docs/{ => _old_structure}/mission-control/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/mission-control/PRD.md (100%) rename docs/{ => _old_structure}/mission-control/TASKS.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/DOCUMENTATION-CHECKLIST.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/INDEX.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/KBN-101-ENVELOPE-A.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/SHARED-CONTRACT.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/TASKS.md (100%) rename docs/{ => _old_structure}/native-kanban-sot/contracts/health-state.v1.ts (100%) rename docs/{ => _old_structure}/native-kanban-sot/contracts/kanban-schema.v1.ts (100%) rename docs/{ => _old_structure}/native-kanban-sot/contracts/mechanical-coordinator.v1.ts (100%) rename docs/{ => _old_structure}/native-kanban-sot/contracts/recovery-posture.v1.ts (100%) rename docs/{ => _old_structure}/native-kanban-sot/tsconfig.json (100%) rename docs/{ => _old_structure}/plans/2026-03-13-gateway-security-hardening.md (100%) rename docs/{ => _old_structure}/plans/2026-03-15-agent-platform-architecture.md (100%) rename docs/{ => _old_structure}/plans/2026-03-15-wave2-tui-layout-navigation.md (100%) rename docs/{ => _old_structure}/plans/2026-05-06-hermes-mosaic-alignment.md (100%) rename docs/{ => _old_structure}/plans/2026-05-07-coordination-resilience.md (100%) rename docs/{ => _old_structure}/plans/2026-08-09-webui-fleet-claude-bridge.md (100%) rename docs/{ => _old_structure}/plans/agent-reflection-loop-PRD.md (100%) rename docs/{ => _old_structure}/plans/authentik-sso-setup.md (100%) rename docs/{ => _old_structure}/plans/chroot-sandboxing.md (100%) rename docs/{ => _old_structure}/plans/gatekeeper-service.md (100%) rename docs/{ => _old_structure}/plans/gateway-token-recovery.md (100%) rename docs/{ => _old_structure}/plans/task-queue-unification.md (100%) rename docs/{ => _old_structure}/remediation/BOARD-LEDGER.md (100%) rename docs/{ => _old_structure}/remediation/BOARD.md (100%) rename docs/{ => _old_structure}/remediation/DECOMP-OPUS.md (100%) rename docs/{ => _old_structure}/remediation/DECOMP-SOL.md (100%) rename docs/{ => _old_structure}/remediation/KICKSTART.md (100%) rename docs/{ => _old_structure}/remediation/MACP-WIRING-SCOUT.md (100%) rename docs/{ => _old_structure}/remediation/MISSION.md (100%) rename docs/{ => _old_structure}/remediation/TASKS.md (100%) rename docs/{ => _old_structure}/reports/code-review/756-code-review.md (100%) rename docs/{ => _old_structure}/reports/code-review/gateway-security-20260313.md (100%) rename docs/{ => _old_structure}/reports/compaction-refresh/830-documentation-checklist.md (100%) rename docs/{ => _old_structure}/reports/deferred/758-fleet-config-deferrals.md (100%) rename docs/{ => _old_structure}/reports/documentation/756-discord-plugin-checklist.md (100%) rename docs/{ => _old_structure}/reports/documentation/758-fleet-config-ia-closure.md (70%) rename docs/{ => _old_structure}/reports/native-kanban-sot/canon-final-rereview-go.md (100%) rename docs/{ => _old_structure}/reports/native-kanban-sot/canon-initial-review-no-go.md (100%) rename docs/{ => _old_structure}/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md (67%) rename docs/{ => _old_structure}/reports/native-kanban-sot/ultron-final-go.md (100%) create mode 100644 docs/_old_structure/reports/qa/gateway-security-20260313.md create mode 100644 docs/_old_structure/reports/security/756-security-review.md rename docs/{ => _old_structure}/requirements/native-kanban-sot.md (100%) rename docs/{ => _old_structure}/reviews/consolidation-board-memo.md (100%) rename docs/{ => _old_structure}/rfcs/RFC-001-MACP-MATRIX-NATIVE.md (100%) rename docs/{ => _old_structure}/rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md (100%) rename docs/{ => _old_structure}/scratchpads/1000-rm-61-ci-contract-exemption.md (100%) rename docs/{ => _old_structure}/scratchpads/2026-06-20-fleet-cli-local-canary.md (100%) rename docs/{ => _old_structure}/scratchpads/2026-06-20-fleet-release-hardening.md (100%) rename docs/{ => _old_structure}/scratchpads/387-updater-wrapper-gitea-20260404.md (100%) rename docs/{ => _old_structure}/scratchpads/41-plugin-host.md (100%) rename docs/{ => _old_structure}/scratchpads/462-fed-m3-04-scope-service.md (100%) rename docs/{ => _old_structure}/scratchpads/462-fed-m3-06-get-verb.md (100%) rename docs/{ => _old_structure}/scratchpads/536-wrapper-login-pin.md (100%) rename docs/{ => _old_structure}/scratchpads/544-agent-reflection-loop.md (100%) rename docs/{ => _old_structure}/scratchpads/559-560-wrapper-eval-login-20260620.md (100%) rename docs/{ => _old_structure}/scratchpads/561-python-is-python3.md (100%) rename docs/{ => _old_structure}/scratchpads/631-reseed-preserves-fleet.md (100%) rename docs/{ => _old_structure}/scratchpads/633-comms-block-runbook.md (100%) rename docs/{ => _old_structure}/scratchpads/672-fleet-personas-timeout.md (100%) rename docs/{ => _old_structure}/scratchpads/703-wrapper-interactive-auth.md (100%) rename docs/{ => _old_structure}/scratchpads/747-wsa-dehardcode.md (100%) rename docs/{ => _old_structure}/scratchpads/751-native-kanban-canon.md (100%) rename docs/{ => _old_structure}/scratchpads/753-kbn010-threat-gate.md (100%) rename docs/{ => _old_structure}/scratchpads/755-mos-logical-identity-fencing.md (100%) rename docs/{ => _old_structure}/scratchpads/756-official-discord-plugin.md (100%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m1-002-shared-role-resolution.md (86%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m1-003-example-profile-dispositions.md (100%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m2-002-fleet-agent-crud.md (100%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m3-001-local-reconciler.md (100%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md (55%) rename docs/{ => _old_structure}/scratchpads/758-fcm-m4-001-v1-v2-migrator.md (100%) rename docs/{ => _old_structure}/scratchpads/771-kbn101-db-role-split.md (100%) rename docs/{ => _old_structure}/scratchpads/791-upgrade-config-protection.md (96%) rename docs/{ => _old_structure}/scratchpads/804-install-unknown-flags.md (83%) rename docs/{ => _old_structure}/scratchpads/807-glpi-partial-content.md (79%) rename docs/{ => _old_structure}/scratchpads/808-agent-send-sender-identity.md (100%) rename docs/{ => _old_structure}/scratchpads/812-pr-review-comment.md (100%) rename docs/{ => _old_structure}/scratchpads/824-mosaic-skill-cli.md (85%) rename docs/{ => _old_structure}/scratchpads/828-lease-broker.md (100%) rename docs/{ => _old_structure}/scratchpads/829-mutator-gate.md (91%) rename docs/{ => _old_structure}/scratchpads/830-compaction-revoke.md (100%) rename docs/{ => _old_structure}/scratchpads/832-receipt-challenge-protocol.md (100%) rename docs/{ => _old_structure}/scratchpads/833-constrained-recovery-command.md (100%) rename docs/{ => _old_structure}/scratchpads/838-broker-acceptance-flake.md (100%) rename docs/{ => _old_structure}/scratchpads/B1-next-durable-publish-design.md (100%) rename docs/{ => _old_structure}/scratchpads/B2-skills-sync-path.md (100%) rename docs/{ => _old_structure}/scratchpads/B3-wizard-gateway-health-order.md (100%) rename docs/{ => _old_structure}/scratchpads/B4-wizard-step-dedup.md (100%) rename docs/{ => _old_structure}/scratchpads/BUG-CLI-scratchpad.md (100%) rename docs/{ => _old_structure}/scratchpads/FED-M3-05-list-verb.md (100%) rename docs/{ => _old_structure}/scratchpads/FED-M3-07-capabilities.md (100%) rename docs/{ => _old_structure}/scratchpads/FED-M3-09-query-source.md (100%) rename docs/{ => _old_structure}/scratchpads/FED-M3-10-integration-tests.md (100%) rename docs/{ => _old_structure}/scratchpads/bug-196-admin-redirect.md (100%) rename docs/{ => _old_structure}/scratchpads/ci-docker-publish-20260330.md (100%) rename docs/{ => _old_structure}/scratchpads/cli-unification-20260404.md (100%) rename docs/{ => _old_structure}/scratchpads/f3-m3-update-reseed.md (100%) rename docs/{ => _old_structure}/scratchpads/f4-matrix-connector.md (100%) rename docs/{ => _old_structure}/scratchpads/fcm-m2-001-generated-env-boundary.md (100%) rename docs/{ => _old_structure}/scratchpads/fcm-m5-001-fleet-config-operator-docs.md (100%) rename docs/{ => _old_structure}/scratchpads/fix-ci-migrations-20260330.md (100%) rename docs/{ => _old_structure}/scratchpads/fix-turbo-env-passthrough.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-cli-local-canary-review-fixes.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-comms-onboarding.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-enhancer-floor.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-observability-phase2.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-polish-bundle.md (100%) rename docs/{ => _old_structure}/scratchpads/fleet-standup-fixes.md (100%) rename docs/{ => _old_structure}/scratchpads/gateway-install-ux-20260404.md (100%) rename docs/{ => _old_structure}/scratchpads/gateway-security-20260313.md (100%) rename docs/{ => _old_structure}/scratchpads/git-wrapper-rollup-20260526.md (100%) rename docs/{ => _old_structure}/scratchpads/h1-heartbeat-readiness.md (100%) rename docs/{ => _old_structure}/scratchpads/h1b-pane-idle-signal.md (100%) rename docs/{ => _old_structure}/scratchpads/h2-readiness-available.md (100%) rename docs/{ => _old_structure}/scratchpads/harness-20260321.md (100%) rename docs/{ => _old_structure}/scratchpads/install-ux-hardening-20260405.md (100%) rename docs/{ => _old_structure}/scratchpads/installer-next-fast-npm-20260625.md (100%) rename docs/{ => _old_structure}/scratchpads/installer-next-lane-20260624.md (100%) rename docs/{ => _old_structure}/scratchpads/issue-766-exact-fleet-comms.md (100%) rename docs/{ => _old_structure}/scratchpads/m3-001-provider-adapter.md (100%) rename docs/{ => _old_structure}/scratchpads/macp-oc-bridge-20260330.md (100%) rename docs/{ => _old_structure}/scratchpads/ms-792-fleet-enoent-installer.md (100%) rename docs/{ => _old_structure}/scratchpads/mvp-20260312.md (100%) rename docs/{ => _old_structure}/scratchpads/north-star-doctrine.md (100%) rename docs/{ => _old_structure}/scratchpads/p5-003-telegram-plugin.md (100%) rename docs/{ => _old_structure}/scratchpads/p5-004-authentik-sso.md (100%) rename docs/{ => _old_structure}/scratchpads/p5-overlay-composer.md (100%) rename docs/{ => _old_structure}/scratchpads/p6-docs-compliance-alpha.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-001-sso-providers.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-009-tui-slash-commands.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-010-command-registry.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-012-agent-provider-commands.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-016-tool-hardening.md (100%) rename docs/{ => _old_structure}/scratchpads/p8-019-verify.md (100%) rename docs/{ => _old_structure}/scratchpads/rm-01-reproducible-checkout.md (100%) rename docs/{ => _old_structure}/scratchpads/rm-03-queue-guard.md (88%) rename docs/{ => _old_structure}/scratchpads/t-a292e96f-gitea-pr-metadata.md (100%) rename docs/{ => _old_structure}/scratchpads/t_301e4e3b-pr-merge-gitea-empty-uid.md (100%) rename docs/{ => _old_structure}/scratchpads/t_5aab9cc8-pr-merge-eval-injection.md (100%) rename docs/{ => _old_structure}/scratchpads/task-mission-ownership-20260313.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-20260712.md (99%) rename docs/{ => _old_structure}/scratchpads/tess-m1-002-provider-registry.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m1-003-fleet-provider.md (74%) rename docs/{ => _old_structure}/scratchpads/tess-m1-obs-001.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m1-sec-001.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m1-sec-004-discord-ingress.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m1-sec-006-session-gc-scope.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m2-001-pi-service.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m2-002-durable-state.md (76%) rename docs/{ => _old_structure}/scratchpads/tess-m4-001-mos-coordination.md (100%) rename docs/{ => _old_structure}/scratchpads/tess-m4-003-operator-plugins.md (100%) rename docs/{ => _old_structure}/scratchpads/tools-md-seeding-20260411.md (100%) rename docs/{ => _old_structure}/scratchpads/update-checker-package-20260404.md (100%) rename docs/{ => _old_structure}/scratchpads/webui-fleet-bridge-plan.md (100%) rename docs/{ => _old_structure}/scratchpads/webui-p2-data-auth.md (100%) rename docs/{ => _old_structure}/scratchpads/yolo-runtime-initial-arg-20260411.md (100%) rename docs/{ => _old_structure}/tasks/544-agent-reflection-loop.md (100%) rename docs/{ => _old_structure}/tasks/WP1-forge-package.md (100%) rename docs/{ => _old_structure}/tasks/WP2-macp-package.md (100%) rename docs/{ => _old_structure}/tasks/WP3-mosaic-framework-plugin.md (100%) rename docs/{ => _old_structure}/tess/ADMIN-GUIDE.md (100%) rename docs/{ => _old_structure}/tess/ARCHITECTURE.md (100%) rename docs/{ => _old_structure}/tess/DEVELOPER-GUIDE.md (100%) rename docs/{ => _old_structure}/tess/M4-003-OPERATOR-PLUGIN-SKETCH.md (100%) rename docs/{ => _old_structure}/tess/M5-003-DOCUMENTATION-CHECKLIST.md (100%) rename docs/{ => _old_structure}/tess/M5-MIGRATION-CUTOVER.md (100%) rename docs/{ => _old_structure}/tess/M5-MIGRATION-INVENTORY.md (100%) rename docs/{ => _old_structure}/tess/M5-MIGRATION-RETENTION-DEPRECATION.md (100%) rename docs/{ => _old_structure}/tess/M5-MIGRATION-ROLLBACK.md (100%) rename docs/{ => _old_structure}/tess/MIGRATION-INVENTORY.md (100%) rename docs/{ => _old_structure}/tess/MISSION-MANIFEST.md (100%) rename docs/{ => _old_structure}/tess/MOS-COORDINATION.md (100%) rename docs/{ => _old_structure}/tess/OPERATIONS-GUIDE.md (100%) rename docs/{ => _old_structure}/tess/PLUGIN-GUIDE.md (100%) create mode 100644 docs/_old_structure/tess/TASKS.md rename docs/{ => _old_structure}/tess/THREAT-MODEL.md (100%) rename docs/{ => _old_structure}/tess/USER-GUIDE.md (100%) rename docs/{ => _old_structure}/tess/VERIFICATION-MATRIX.md (100%) rename docs/{ => _old_structure}/tess/hermes-runtime-adapter-design.md (100%) rename docs/{ => _old_structure}/tess/qualification/2026-07-14-option2-runtime-portability.md (100%) delete mode 100644 docs/reports/qa/gateway-security-20260313.md delete mode 100644 docs/reports/security/756-security-review.md delete mode 100644 docs/tess/TASKS.md diff --git a/docs/GETTING_STARTED.md b/docs/GETTING_STARTED.md new file mode 100644 index 00000000..e69de29b diff --git a/docs/architecture/ADR-MOS-EGRESS-GATEWAYS.md b/docs/_old_structure/architecture/ADR-MOS-EGRESS-GATEWAYS.md similarity index 100% rename from docs/architecture/ADR-MOS-EGRESS-GATEWAYS.md rename to docs/_old_structure/architecture/ADR-MOS-EGRESS-GATEWAYS.md diff --git a/docs/architecture/channel-protocol.md b/docs/_old_structure/architecture/channel-protocol.md similarity index 100% rename from docs/architecture/channel-protocol.md rename to docs/_old_structure/architecture/channel-protocol.md diff --git a/docs/architecture/compaction-revocation.md b/docs/_old_structure/architecture/compaction-revocation.md similarity index 100% rename from docs/architecture/compaction-revocation.md rename to docs/_old_structure/architecture/compaction-revocation.md diff --git a/docs/architecture/lease-broker-protocol.md b/docs/_old_structure/architecture/lease-broker-protocol.md similarity index 100% rename from docs/architecture/lease-broker-protocol.md rename to docs/_old_structure/architecture/lease-broker-protocol.md diff --git a/docs/architecture/lease-broker-security.md b/docs/_old_structure/architecture/lease-broker-security.md similarity index 100% rename from docs/architecture/lease-broker-security.md rename to docs/_old_structure/architecture/lease-broker-security.md diff --git a/docs/architecture/mos-runtime-portability-m1.md b/docs/_old_structure/architecture/mos-runtime-portability-m1.md similarity index 100% rename from docs/architecture/mos-runtime-portability-m1.md rename to docs/_old_structure/architecture/mos-runtime-portability-m1.md diff --git a/docs/architecture/mutator-class-gate.md b/docs/_old_structure/architecture/mutator-class-gate.md similarity index 100% rename from docs/architecture/mutator-class-gate.md rename to docs/_old_structure/architecture/mutator-class-gate.md diff --git a/docs/archive/missions/cli-unification-20260404/MISSION-MANIFEST.md b/docs/_old_structure/archive/missions/cli-unification-20260404/MISSION-MANIFEST.md similarity index 100% rename from docs/archive/missions/cli-unification-20260404/MISSION-MANIFEST.md rename to docs/_old_structure/archive/missions/cli-unification-20260404/MISSION-MANIFEST.md diff --git a/docs/archive/missions/cli-unification-20260404/TASKS.md b/docs/_old_structure/archive/missions/cli-unification-20260404/TASKS.md similarity index 100% rename from docs/archive/missions/cli-unification-20260404/TASKS.md rename to docs/_old_structure/archive/missions/cli-unification-20260404/TASKS.md diff --git a/docs/archive/missions/harness-20260321/MISSION-MANIFEST.md b/docs/_old_structure/archive/missions/harness-20260321/MISSION-MANIFEST.md similarity index 100% rename from docs/archive/missions/harness-20260321/MISSION-MANIFEST.md rename to docs/_old_structure/archive/missions/harness-20260321/MISSION-MANIFEST.md diff --git a/docs/archive/missions/harness-20260321/PRD.md b/docs/_old_structure/archive/missions/harness-20260321/PRD.md similarity index 100% rename from docs/archive/missions/harness-20260321/PRD.md rename to docs/_old_structure/archive/missions/harness-20260321/PRD.md diff --git a/docs/archive/missions/install-ux-hardening-20260405/MISSION-MANIFEST.md b/docs/_old_structure/archive/missions/install-ux-hardening-20260405/MISSION-MANIFEST.md similarity index 100% rename from docs/archive/missions/install-ux-hardening-20260405/MISSION-MANIFEST.md rename to docs/_old_structure/archive/missions/install-ux-hardening-20260405/MISSION-MANIFEST.md diff --git a/docs/archive/missions/install-ux-hardening-20260405/TASKS.md b/docs/_old_structure/archive/missions/install-ux-hardening-20260405/TASKS.md similarity index 100% rename from docs/archive/missions/install-ux-hardening-20260405/TASKS.md rename to docs/_old_structure/archive/missions/install-ux-hardening-20260405/TASKS.md diff --git a/docs/archive/missions/install-ux-v2-20260405/MISSION-MANIFEST.md b/docs/_old_structure/archive/missions/install-ux-v2-20260405/MISSION-MANIFEST.md similarity index 100% rename from docs/archive/missions/install-ux-v2-20260405/MISSION-MANIFEST.md rename to docs/_old_structure/archive/missions/install-ux-v2-20260405/MISSION-MANIFEST.md diff --git a/docs/archive/missions/install-ux-v2-20260405/TASKS.md b/docs/_old_structure/archive/missions/install-ux-v2-20260405/TASKS.md similarity index 100% rename from docs/archive/missions/install-ux-v2-20260405/TASKS.md rename to docs/_old_structure/archive/missions/install-ux-v2-20260405/TASKS.md diff --git a/docs/archive/missions/install-ux-v2-20260405/iuv-m03-design.md b/docs/_old_structure/archive/missions/install-ux-v2-20260405/iuv-m03-design.md similarity index 100% rename from docs/archive/missions/install-ux-v2-20260405/iuv-m03-design.md rename to docs/_old_structure/archive/missions/install-ux-v2-20260405/iuv-m03-design.md diff --git a/docs/archive/missions/install-ux-v2-20260405/scratchpad.md b/docs/_old_structure/archive/missions/install-ux-v2-20260405/scratchpad.md similarity index 100% rename from docs/archive/missions/install-ux-v2-20260405/scratchpad.md rename to docs/_old_structure/archive/missions/install-ux-v2-20260405/scratchpad.md diff --git a/docs/archive/missions/storage-abstraction/TASKS.md b/docs/_old_structure/archive/missions/storage-abstraction/TASKS.md similarity index 100% rename from docs/archive/missions/storage-abstraction/TASKS.md rename to docs/_old_structure/archive/missions/storage-abstraction/TASKS.md diff --git a/docs/audits/AUDIT-2026-02-17-framework-consistency.md b/docs/_old_structure/audits/AUDIT-2026-02-17-framework-consistency.md similarity index 100% rename from docs/audits/AUDIT-2026-02-17-framework-consistency.md rename to docs/_old_structure/audits/AUDIT-2026-02-17-framework-consistency.md diff --git a/docs/briefs/monorepo-consolidation.md b/docs/_old_structure/briefs/monorepo-consolidation.md similarity index 100% rename from docs/briefs/monorepo-consolidation.md rename to docs/_old_structure/briefs/monorepo-consolidation.md diff --git a/docs/compaction-refresh/probes/p5_receipt_replay.py b/docs/_old_structure/compaction-refresh/probes/p5_receipt_replay.py similarity index 100% rename from docs/compaction-refresh/probes/p5_receipt_replay.py rename to docs/_old_structure/compaction-refresh/probes/p5_receipt_replay.py diff --git a/docs/compaction-refresh/probes/p6_constrained_recovery.py b/docs/_old_structure/compaction-refresh/probes/p6_constrained_recovery.py similarity index 100% rename from docs/compaction-refresh/probes/p6_constrained_recovery.py rename to docs/_old_structure/compaction-refresh/probes/p6_constrained_recovery.py diff --git a/docs/deploy/portainer/README.md b/docs/_old_structure/deploy/portainer/README.md similarity index 100% rename from docs/deploy/portainer/README.md rename to docs/_old_structure/deploy/portainer/README.md diff --git a/docs/deploy/portainer/federated-test.stack.yml b/docs/_old_structure/deploy/portainer/federated-test.stack.yml similarity index 100% rename from docs/deploy/portainer/federated-test.stack.yml rename to docs/_old_structure/deploy/portainer/federated-test.stack.yml diff --git a/docs/design/791-upgrade-config-protection.md b/docs/_old_structure/design/791-upgrade-config-protection.md similarity index 100% rename from docs/design/791-upgrade-config-protection.md rename to docs/_old_structure/design/791-upgrade-config-protection.md diff --git a/docs/design/framework-constitution/ALPHA-DOD.md b/docs/_old_structure/design/framework-constitution/ALPHA-DOD.md similarity index 100% rename from docs/design/framework-constitution/ALPHA-DOD.md rename to docs/_old_structure/design/framework-constitution/ALPHA-DOD.md diff --git a/docs/design/prerelease-next-dist-tag-pipeline.md b/docs/_old_structure/design/prerelease-next-dist-tag-pipeline.md similarity index 100% rename from docs/design/prerelease-next-dist-tag-pipeline.md rename to docs/_old_structure/design/prerelease-next-dist-tag-pipeline.md diff --git a/docs/design/storage-abstraction-middleware.md b/docs/_old_structure/design/storage-abstraction-middleware.md similarity index 100% rename from docs/design/storage-abstraction-middleware.md rename to docs/_old_structure/design/storage-abstraction-middleware.md diff --git a/docs/federation/ADMIN-CLI.md b/docs/_old_structure/federation/ADMIN-CLI.md similarity index 100% rename from docs/federation/ADMIN-CLI.md rename to docs/_old_structure/federation/ADMIN-CLI.md diff --git a/docs/federation/MILESTONES.md b/docs/_old_structure/federation/MILESTONES.md similarity index 100% rename from docs/federation/MILESTONES.md rename to docs/_old_structure/federation/MILESTONES.md diff --git a/docs/federation/MISSION-MANIFEST.md b/docs/_old_structure/federation/MISSION-MANIFEST.md similarity index 100% rename from docs/federation/MISSION-MANIFEST.md rename to docs/_old_structure/federation/MISSION-MANIFEST.md diff --git a/docs/federation/PRD.md b/docs/_old_structure/federation/PRD.md similarity index 100% rename from docs/federation/PRD.md rename to docs/_old_structure/federation/PRD.md diff --git a/docs/federation/SETUP.md b/docs/_old_structure/federation/SETUP.md similarity index 100% rename from docs/federation/SETUP.md rename to docs/_old_structure/federation/SETUP.md diff --git a/docs/federation/TASKS.md b/docs/_old_structure/federation/TASKS.md similarity index 100% rename from docs/federation/TASKS.md rename to docs/_old_structure/federation/TASKS.md diff --git a/docs/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md b/docs/_old_structure/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md similarity index 100% rename from docs/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md rename to docs/_old_structure/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md diff --git a/docs/fleet/FLEET-LAUNCH.md b/docs/_old_structure/fleet/FLEET-LAUNCH.md similarity index 100% rename from docs/fleet/FLEET-LAUNCH.md rename to docs/_old_structure/fleet/FLEET-LAUNCH.md diff --git a/docs/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md b/docs/_old_structure/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md similarity index 100% rename from docs/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md rename to docs/_old_structure/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md diff --git a/docs/fleet/NORTH_STAR.md b/docs/_old_structure/fleet/NORTH_STAR.md similarity index 100% rename from docs/fleet/NORTH_STAR.md rename to docs/_old_structure/fleet/NORTH_STAR.md diff --git a/docs/fleet/NORTH_STAR.yaml b/docs/_old_structure/fleet/NORTH_STAR.yaml similarity index 100% rename from docs/fleet/NORTH_STAR.yaml rename to docs/_old_structure/fleet/NORTH_STAR.yaml diff --git a/docs/fleet/PRD-fleet-suite.md b/docs/_old_structure/fleet/PRD-fleet-suite.md similarity index 100% rename from docs/fleet/PRD-fleet-suite.md rename to docs/_old_structure/fleet/PRD-fleet-suite.md diff --git a/docs/fleet/PRD.md b/docs/_old_structure/fleet/PRD.md similarity index 100% rename from docs/fleet/PRD.md rename to docs/_old_structure/fleet/PRD.md diff --git a/docs/fleet/README.md b/docs/_old_structure/fleet/README.md similarity index 100% rename from docs/fleet/README.md rename to docs/_old_structure/fleet/README.md diff --git a/docs/fleet/TASKS.md b/docs/_old_structure/fleet/TASKS.md similarity index 100% rename from docs/fleet/TASKS.md rename to docs/_old_structure/fleet/TASKS.md diff --git a/docs/fleet/backlog-conventions.md b/docs/_old_structure/fleet/backlog-conventions.md similarity index 100% rename from docs/fleet/backlog-conventions.md rename to docs/_old_structure/fleet/backlog-conventions.md diff --git a/docs/fleet/concepts/desired-vs-observed-state.md b/docs/_old_structure/fleet/concepts/desired-vs-observed-state.md similarity index 100% rename from docs/fleet/concepts/desired-vs-observed-state.md rename to docs/_old_structure/fleet/concepts/desired-vs-observed-state.md diff --git a/docs/fleet/concepts/generated-env-launch-chain.md b/docs/_old_structure/fleet/concepts/generated-env-launch-chain.md similarity index 100% rename from docs/fleet/concepts/generated-env-launch-chain.md rename to docs/_old_structure/fleet/concepts/generated-env-launch-chain.md diff --git a/docs/fleet/concepts/identity-class-runtime.md b/docs/_old_structure/fleet/concepts/identity-class-runtime.md similarity index 100% rename from docs/fleet/concepts/identity-class-runtime.md rename to docs/_old_structure/fleet/concepts/identity-class-runtime.md diff --git a/docs/fleet/concepts/role-authority-and-leases.md b/docs/_old_structure/fleet/concepts/role-authority-and-leases.md similarity index 100% rename from docs/fleet/concepts/role-authority-and-leases.md rename to docs/_old_structure/fleet/concepts/role-authority-and-leases.md diff --git a/docs/fleet/examples/roster-v2.yaml b/docs/_old_structure/fleet/examples/roster-v2.yaml similarity index 100% rename from docs/fleet/examples/roster-v2.yaml rename to docs/_old_structure/fleet/examples/roster-v2.yaml diff --git a/docs/fleet/f4-matrix-connector.md b/docs/_old_structure/fleet/f4-matrix-connector.md similarity index 100% rename from docs/fleet/f4-matrix-connector.md rename to docs/_old_structure/fleet/f4-matrix-connector.md diff --git a/docs/fleet/how-to/configure-tess-interaction.md b/docs/_old_structure/fleet/how-to/configure-tess-interaction.md similarity index 100% rename from docs/fleet/how-to/configure-tess-interaction.md rename to docs/_old_structure/fleet/how-to/configure-tess-interaction.md diff --git a/docs/fleet/how-to/configure-ultron-validator.md b/docs/_old_structure/fleet/how-to/configure-ultron-validator.md similarity index 100% rename from docs/fleet/how-to/configure-ultron-validator.md rename to docs/_old_structure/fleet/how-to/configure-ultron-validator.md diff --git a/docs/fleet/how-to/create-update-delete-agent.md b/docs/_old_structure/fleet/how-to/create-update-delete-agent.md similarity index 100% rename from docs/fleet/how-to/create-update-delete-agent.md rename to docs/_old_structure/fleet/how-to/create-update-delete-agent.md diff --git a/docs/fleet/how-to/customize-roles.md b/docs/_old_structure/fleet/how-to/customize-roles.md similarity index 100% rename from docs/fleet/how-to/customize-roles.md rename to docs/_old_structure/fleet/how-to/customize-roles.md diff --git a/docs/fleet/how-to/start-stop-restart.md b/docs/_old_structure/fleet/how-to/start-stop-restart.md similarity index 100% rename from docs/fleet/how-to/start-stop-restart.md rename to docs/_old_structure/fleet/how-to/start-stop-restart.md diff --git a/docs/fleet/migration/example-profile-disposition.md b/docs/_old_structure/fleet/migration/example-profile-disposition.md similarity index 100% rename from docs/fleet/migration/example-profile-disposition.md rename to docs/_old_structure/fleet/migration/example-profile-disposition.md diff --git a/docs/fleet/migration/legacy-class-aliases.md b/docs/_old_structure/fleet/migration/legacy-class-aliases.md similarity index 100% rename from docs/fleet/migration/legacy-class-aliases.md rename to docs/_old_structure/fleet/migration/legacy-class-aliases.md diff --git a/docs/fleet/migration/v1-to-v2.md b/docs/_old_structure/fleet/migration/v1-to-v2.md similarity index 100% rename from docs/fleet/migration/v1-to-v2.md rename to docs/_old_structure/fleet/migration/v1-to-v2.md diff --git a/docs/fleet/north-star.md b/docs/_old_structure/fleet/north-star.md similarity index 100% rename from docs/fleet/north-star.md rename to docs/_old_structure/fleet/north-star.md diff --git a/docs/fleet/operations/backup-restore.md b/docs/_old_structure/fleet/operations/backup-restore.md similarity index 100% rename from docs/fleet/operations/backup-restore.md rename to docs/_old_structure/fleet/operations/backup-restore.md diff --git a/docs/fleet/operations/env-quarantine.md b/docs/_old_structure/fleet/operations/env-quarantine.md similarity index 100% rename from docs/fleet/operations/env-quarantine.md rename to docs/_old_structure/fleet/operations/env-quarantine.md diff --git a/docs/fleet/operations/reconcile-and-recover.md b/docs/_old_structure/fleet/operations/reconcile-and-recover.md similarity index 100% rename from docs/fleet/operations/reconcile-and-recover.md rename to docs/_old_structure/fleet/operations/reconcile-and-recover.md diff --git a/docs/fleet/operations/systemd-tmux-troubleshooting.md b/docs/_old_structure/fleet/operations/systemd-tmux-troubleshooting.md similarity index 100% rename from docs/fleet/operations/systemd-tmux-troubleshooting.md rename to docs/_old_structure/fleet/operations/systemd-tmux-troubleshooting.md diff --git a/docs/fleet/operations/upgrade-assets.md b/docs/_old_structure/fleet/operations/upgrade-assets.md similarity index 100% rename from docs/fleet/operations/upgrade-assets.md rename to docs/_old_structure/fleet/operations/upgrade-assets.md diff --git a/docs/fleet/reference/agent-mutations.md b/docs/_old_structure/fleet/reference/agent-mutations.md similarity index 100% rename from docs/fleet/reference/agent-mutations.md rename to docs/_old_structure/fleet/reference/agent-mutations.md diff --git a/docs/fleet/reference/cli.md b/docs/_old_structure/fleet/reference/cli.md similarity index 100% rename from docs/fleet/reference/cli.md rename to docs/_old_structure/fleet/reference/cli.md diff --git a/docs/fleet/reference/generated-env-boundary.md b/docs/_old_structure/fleet/reference/generated-env-boundary.md similarity index 100% rename from docs/fleet/reference/generated-env-boundary.md rename to docs/_old_structure/fleet/reference/generated-env-boundary.md diff --git a/docs/fleet/reference/lifecycle-transitions.md b/docs/_old_structure/fleet/reference/lifecycle-transitions.md similarity index 100% rename from docs/fleet/reference/lifecycle-transitions.md rename to docs/_old_structure/fleet/reference/lifecycle-transitions.md diff --git a/docs/fleet/reference/role-classes.md b/docs/_old_structure/fleet/reference/role-classes.md similarity index 100% rename from docs/fleet/reference/role-classes.md rename to docs/_old_structure/fleet/reference/role-classes.md diff --git a/docs/fleet/reference/roster-v2-fields.md b/docs/_old_structure/fleet/reference/roster-v2-fields.md similarity index 100% rename from docs/fleet/reference/roster-v2-fields.md rename to docs/_old_structure/fleet/reference/roster-v2-fields.md diff --git a/docs/fleet/reference/roster-v2.schema.json b/docs/_old_structure/fleet/reference/roster-v2.schema.json similarity index 100% rename from docs/fleet/reference/roster-v2.schema.json rename to docs/_old_structure/fleet/reference/roster-v2.schema.json diff --git a/docs/fleet/reference/status-and-drift.md b/docs/_old_structure/fleet/reference/status-and-drift.md similarity index 100% rename from docs/fleet/reference/status-and-drift.md rename to docs/_old_structure/fleet/reference/status-and-drift.md diff --git a/docs/guides/admin-guide.md b/docs/_old_structure/guides/admin-guide.md similarity index 100% rename from docs/guides/admin-guide.md rename to docs/_old_structure/guides/admin-guide.md diff --git a/docs/guides/deployment.md b/docs/_old_structure/guides/deployment.md similarity index 100% rename from docs/guides/deployment.md rename to docs/_old_structure/guides/deployment.md diff --git a/docs/guides/dev-guide.md b/docs/_old_structure/guides/dev-guide.md similarity index 100% rename from docs/guides/dev-guide.md rename to docs/_old_structure/guides/dev-guide.md diff --git a/docs/guides/fleet-local-canary.md b/docs/_old_structure/guides/fleet-local-canary.md similarity index 100% rename from docs/guides/fleet-local-canary.md rename to docs/_old_structure/guides/fleet-local-canary.md diff --git a/docs/guides/lease-broker-operations.md b/docs/_old_structure/guides/lease-broker-operations.md similarity index 100% rename from docs/guides/lease-broker-operations.md rename to docs/_old_structure/guides/lease-broker-operations.md diff --git a/docs/guides/migrate-tier.md b/docs/_old_structure/guides/migrate-tier.md similarity index 100% rename from docs/guides/migrate-tier.md rename to docs/_old_structure/guides/migrate-tier.md diff --git a/docs/guides/mos-connector-lease-operations.md b/docs/_old_structure/guides/mos-connector-lease-operations.md similarity index 100% rename from docs/guides/mos-connector-lease-operations.md rename to docs/_old_structure/guides/mos-connector-lease-operations.md diff --git a/docs/guides/upgrade-safety-and-recovery.md b/docs/_old_structure/guides/upgrade-safety-and-recovery.md similarity index 100% rename from docs/guides/upgrade-safety-and-recovery.md rename to docs/_old_structure/guides/upgrade-safety-and-recovery.md diff --git a/docs/guides/user-guide.md b/docs/_old_structure/guides/user-guide.md similarity index 100% rename from docs/guides/user-guide.md rename to docs/_old_structure/guides/user-guide.md diff --git a/docs/mission-control/BOARD.md b/docs/_old_structure/mission-control/BOARD.md similarity index 100% rename from docs/mission-control/BOARD.md rename to docs/_old_structure/mission-control/BOARD.md diff --git a/docs/mission-control/MISSION-MANIFEST.md b/docs/_old_structure/mission-control/MISSION-MANIFEST.md similarity index 100% rename from docs/mission-control/MISSION-MANIFEST.md rename to docs/_old_structure/mission-control/MISSION-MANIFEST.md diff --git a/docs/mission-control/PRD.md b/docs/_old_structure/mission-control/PRD.md similarity index 100% rename from docs/mission-control/PRD.md rename to docs/_old_structure/mission-control/PRD.md diff --git a/docs/mission-control/TASKS.md b/docs/_old_structure/mission-control/TASKS.md similarity index 100% rename from docs/mission-control/TASKS.md rename to docs/_old_structure/mission-control/TASKS.md diff --git a/docs/native-kanban-sot/DOCUMENTATION-CHECKLIST.md b/docs/_old_structure/native-kanban-sot/DOCUMENTATION-CHECKLIST.md similarity index 100% rename from docs/native-kanban-sot/DOCUMENTATION-CHECKLIST.md rename to docs/_old_structure/native-kanban-sot/DOCUMENTATION-CHECKLIST.md diff --git a/docs/native-kanban-sot/INDEX.md b/docs/_old_structure/native-kanban-sot/INDEX.md similarity index 100% rename from docs/native-kanban-sot/INDEX.md rename to docs/_old_structure/native-kanban-sot/INDEX.md diff --git a/docs/native-kanban-sot/KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md b/docs/_old_structure/native-kanban-sot/KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md similarity index 100% rename from docs/native-kanban-sot/KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md rename to docs/_old_structure/native-kanban-sot/KBN-010-THREAT-AUTH-CONSTRAINT-GATE.md diff --git a/docs/native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md b/docs/_old_structure/native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md similarity index 100% rename from docs/native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md rename to docs/_old_structure/native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md diff --git a/docs/native-kanban-sot/KBN-101-ENVELOPE-A.md b/docs/_old_structure/native-kanban-sot/KBN-101-ENVELOPE-A.md similarity index 100% rename from docs/native-kanban-sot/KBN-101-ENVELOPE-A.md rename to docs/_old_structure/native-kanban-sot/KBN-101-ENVELOPE-A.md diff --git a/docs/native-kanban-sot/MISSION-MANIFEST.md b/docs/_old_structure/native-kanban-sot/MISSION-MANIFEST.md similarity index 100% rename from docs/native-kanban-sot/MISSION-MANIFEST.md rename to docs/_old_structure/native-kanban-sot/MISSION-MANIFEST.md diff --git a/docs/native-kanban-sot/SHARED-CONTRACT.md b/docs/_old_structure/native-kanban-sot/SHARED-CONTRACT.md similarity index 100% rename from docs/native-kanban-sot/SHARED-CONTRACT.md rename to docs/_old_structure/native-kanban-sot/SHARED-CONTRACT.md diff --git a/docs/native-kanban-sot/TASKS.md b/docs/_old_structure/native-kanban-sot/TASKS.md similarity index 100% rename from docs/native-kanban-sot/TASKS.md rename to docs/_old_structure/native-kanban-sot/TASKS.md diff --git a/docs/native-kanban-sot/contracts/health-state.v1.ts b/docs/_old_structure/native-kanban-sot/contracts/health-state.v1.ts similarity index 100% rename from docs/native-kanban-sot/contracts/health-state.v1.ts rename to docs/_old_structure/native-kanban-sot/contracts/health-state.v1.ts diff --git a/docs/native-kanban-sot/contracts/kanban-schema.v1.ts b/docs/_old_structure/native-kanban-sot/contracts/kanban-schema.v1.ts similarity index 100% rename from docs/native-kanban-sot/contracts/kanban-schema.v1.ts rename to docs/_old_structure/native-kanban-sot/contracts/kanban-schema.v1.ts diff --git a/docs/native-kanban-sot/contracts/mechanical-coordinator.v1.ts b/docs/_old_structure/native-kanban-sot/contracts/mechanical-coordinator.v1.ts similarity index 100% rename from docs/native-kanban-sot/contracts/mechanical-coordinator.v1.ts rename to docs/_old_structure/native-kanban-sot/contracts/mechanical-coordinator.v1.ts diff --git a/docs/native-kanban-sot/contracts/recovery-posture.v1.ts b/docs/_old_structure/native-kanban-sot/contracts/recovery-posture.v1.ts similarity index 100% rename from docs/native-kanban-sot/contracts/recovery-posture.v1.ts rename to docs/_old_structure/native-kanban-sot/contracts/recovery-posture.v1.ts diff --git a/docs/native-kanban-sot/tsconfig.json b/docs/_old_structure/native-kanban-sot/tsconfig.json similarity index 100% rename from docs/native-kanban-sot/tsconfig.json rename to docs/_old_structure/native-kanban-sot/tsconfig.json diff --git a/docs/plans/2026-03-13-gateway-security-hardening.md b/docs/_old_structure/plans/2026-03-13-gateway-security-hardening.md similarity index 100% rename from docs/plans/2026-03-13-gateway-security-hardening.md rename to docs/_old_structure/plans/2026-03-13-gateway-security-hardening.md diff --git a/docs/plans/2026-03-15-agent-platform-architecture.md b/docs/_old_structure/plans/2026-03-15-agent-platform-architecture.md similarity index 100% rename from docs/plans/2026-03-15-agent-platform-architecture.md rename to docs/_old_structure/plans/2026-03-15-agent-platform-architecture.md diff --git a/docs/plans/2026-03-15-wave2-tui-layout-navigation.md b/docs/_old_structure/plans/2026-03-15-wave2-tui-layout-navigation.md similarity index 100% rename from docs/plans/2026-03-15-wave2-tui-layout-navigation.md rename to docs/_old_structure/plans/2026-03-15-wave2-tui-layout-navigation.md diff --git a/docs/plans/2026-05-06-hermes-mosaic-alignment.md b/docs/_old_structure/plans/2026-05-06-hermes-mosaic-alignment.md similarity index 100% rename from docs/plans/2026-05-06-hermes-mosaic-alignment.md rename to docs/_old_structure/plans/2026-05-06-hermes-mosaic-alignment.md diff --git a/docs/plans/2026-05-07-coordination-resilience.md b/docs/_old_structure/plans/2026-05-07-coordination-resilience.md similarity index 100% rename from docs/plans/2026-05-07-coordination-resilience.md rename to docs/_old_structure/plans/2026-05-07-coordination-resilience.md diff --git a/docs/plans/2026-08-09-webui-fleet-claude-bridge.md b/docs/_old_structure/plans/2026-08-09-webui-fleet-claude-bridge.md similarity index 100% rename from docs/plans/2026-08-09-webui-fleet-claude-bridge.md rename to docs/_old_structure/plans/2026-08-09-webui-fleet-claude-bridge.md diff --git a/docs/plans/agent-reflection-loop-PRD.md b/docs/_old_structure/plans/agent-reflection-loop-PRD.md similarity index 100% rename from docs/plans/agent-reflection-loop-PRD.md rename to docs/_old_structure/plans/agent-reflection-loop-PRD.md diff --git a/docs/plans/authentik-sso-setup.md b/docs/_old_structure/plans/authentik-sso-setup.md similarity index 100% rename from docs/plans/authentik-sso-setup.md rename to docs/_old_structure/plans/authentik-sso-setup.md diff --git a/docs/plans/chroot-sandboxing.md b/docs/_old_structure/plans/chroot-sandboxing.md similarity index 100% rename from docs/plans/chroot-sandboxing.md rename to docs/_old_structure/plans/chroot-sandboxing.md diff --git a/docs/plans/gatekeeper-service.md b/docs/_old_structure/plans/gatekeeper-service.md similarity index 100% rename from docs/plans/gatekeeper-service.md rename to docs/_old_structure/plans/gatekeeper-service.md diff --git a/docs/plans/gateway-token-recovery.md b/docs/_old_structure/plans/gateway-token-recovery.md similarity index 100% rename from docs/plans/gateway-token-recovery.md rename to docs/_old_structure/plans/gateway-token-recovery.md diff --git a/docs/plans/task-queue-unification.md b/docs/_old_structure/plans/task-queue-unification.md similarity index 100% rename from docs/plans/task-queue-unification.md rename to docs/_old_structure/plans/task-queue-unification.md diff --git a/docs/remediation/BOARD-LEDGER.md b/docs/_old_structure/remediation/BOARD-LEDGER.md similarity index 100% rename from docs/remediation/BOARD-LEDGER.md rename to docs/_old_structure/remediation/BOARD-LEDGER.md diff --git a/docs/remediation/BOARD.md b/docs/_old_structure/remediation/BOARD.md similarity index 100% rename from docs/remediation/BOARD.md rename to docs/_old_structure/remediation/BOARD.md diff --git a/docs/remediation/DECOMP-OPUS.md b/docs/_old_structure/remediation/DECOMP-OPUS.md similarity index 100% rename from docs/remediation/DECOMP-OPUS.md rename to docs/_old_structure/remediation/DECOMP-OPUS.md diff --git a/docs/remediation/DECOMP-SOL.md b/docs/_old_structure/remediation/DECOMP-SOL.md similarity index 100% rename from docs/remediation/DECOMP-SOL.md rename to docs/_old_structure/remediation/DECOMP-SOL.md diff --git a/docs/remediation/KICKSTART.md b/docs/_old_structure/remediation/KICKSTART.md similarity index 100% rename from docs/remediation/KICKSTART.md rename to docs/_old_structure/remediation/KICKSTART.md diff --git a/docs/remediation/MACP-WIRING-SCOUT.md b/docs/_old_structure/remediation/MACP-WIRING-SCOUT.md similarity index 100% rename from docs/remediation/MACP-WIRING-SCOUT.md rename to docs/_old_structure/remediation/MACP-WIRING-SCOUT.md diff --git a/docs/remediation/MISSION.md b/docs/_old_structure/remediation/MISSION.md similarity index 100% rename from docs/remediation/MISSION.md rename to docs/_old_structure/remediation/MISSION.md diff --git a/docs/remediation/TASKS.md b/docs/_old_structure/remediation/TASKS.md similarity index 100% rename from docs/remediation/TASKS.md rename to docs/_old_structure/remediation/TASKS.md diff --git a/docs/reports/code-review/756-code-review.md b/docs/_old_structure/reports/code-review/756-code-review.md similarity index 100% rename from docs/reports/code-review/756-code-review.md rename to docs/_old_structure/reports/code-review/756-code-review.md diff --git a/docs/reports/code-review/gateway-security-20260313.md b/docs/_old_structure/reports/code-review/gateway-security-20260313.md similarity index 100% rename from docs/reports/code-review/gateway-security-20260313.md rename to docs/_old_structure/reports/code-review/gateway-security-20260313.md diff --git a/docs/reports/compaction-refresh/830-documentation-checklist.md b/docs/_old_structure/reports/compaction-refresh/830-documentation-checklist.md similarity index 100% rename from docs/reports/compaction-refresh/830-documentation-checklist.md rename to docs/_old_structure/reports/compaction-refresh/830-documentation-checklist.md diff --git a/docs/reports/deferred/758-fleet-config-deferrals.md b/docs/_old_structure/reports/deferred/758-fleet-config-deferrals.md similarity index 100% rename from docs/reports/deferred/758-fleet-config-deferrals.md rename to docs/_old_structure/reports/deferred/758-fleet-config-deferrals.md diff --git a/docs/reports/documentation/756-discord-plugin-checklist.md b/docs/_old_structure/reports/documentation/756-discord-plugin-checklist.md similarity index 100% rename from docs/reports/documentation/756-discord-plugin-checklist.md rename to docs/_old_structure/reports/documentation/756-discord-plugin-checklist.md diff --git a/docs/reports/documentation/758-fleet-config-ia-closure.md b/docs/_old_structure/reports/documentation/758-fleet-config-ia-closure.md similarity index 70% rename from docs/reports/documentation/758-fleet-config-ia-closure.md rename to docs/_old_structure/reports/documentation/758-fleet-config-ia-closure.md index 1bc424fb..25223408 100644 --- a/docs/reports/documentation/758-fleet-config-ia-closure.md +++ b/docs/_old_structure/reports/documentation/758-fleet-config-ia-closure.md @@ -14,18 +14,18 @@ ## Acceptance mapping -| Checklist area | Evidence | -| ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Roster authority and fail-closed legacy handling | Root PRD FCM-REQ-01/05/08; desired/observed and quarantine pages. | -| Classes and authority | Root PRD FCM-REQ-07; role authority concept/reference; configurable interaction/validator how-tos. | -| Lifecycle | Root PRD FCM-REQ-04; lifecycle transition table and operator lifecycle how-to. | -| Local-only generated launch boundary | Root PRD FCM-REQ-05/09; generated launch concept/reference. | -| Complete DAG and artifact inventory | `docs/TASKS.md`; M0 inventory; executable disposition tests. | -| IA pages | Every path named by the M0 checklist exists and is linked from `docs/fleet/README.md`. | -| Examples | `docs/fleet/examples/roster-v2.yaml` validates through production v2 compiler/shared resolver; shipped artifact dispositions validate through declared production readers. | -| Links | Deterministic local Markdown link test covers the entire fleet book and sitemap, including local heading-fragment resolution. | +| Checklist area | Evidence | +| ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Roster authority and fail-closed legacy handling | Root PRD FCM-REQ-01/05/08; desired/observed and quarantine pages. | +| Classes and authority | Root PRD FCM-REQ-07; role authority concept/reference; configurable interaction/validator how-tos. | +| Lifecycle | Root PRD FCM-REQ-04; lifecycle transition table and operator lifecycle how-to. | +| Local-only generated launch boundary | Root PRD FCM-REQ-05/09; generated launch concept/reference. | +| Complete DAG and artifact inventory | `docs/TASKS.md`; M0 inventory; executable disposition tests. | +| IA pages | Every path named by the M0 checklist exists and is linked from `docs/fleet/README.md`. | +| Examples | `docs/fleet/examples/roster-v2.yaml` validates through production v2 compiler/shared resolver; shipped artifact dispositions validate through declared production readers. | +| Links | Deterministic local Markdown link test covers the entire fleet book and sitemap, including local heading-fragment resolution. | | Sensitive/example safety | Validator scans backtick- and tilde-fenced fleet-book examples plus the canonical roster for sensitive-looking keys, common credential formats (including Anthropic, OpenAI project, and Stripe restricted keys), path-qualified privileged commands, package-manager/root commands, arbitrary command override, and hardcoded Tess/Ultron identities; findings report only file/block and violation kind, never matched values. | -| Holds | `docs/reports/deferred/758-fleet-config-deferrals.md` records M3-002, M4-002, M5-002, compatibility, and repository-structure boundaries. | +| Holds | `docs/reports/deferred/758-fleet-config-deferrals.md` records M3-002, M4-002, M5-002, compatibility, and repository-structure boundaries. | ## Documentation completion checklist diff --git a/docs/reports/native-kanban-sot/canon-final-rereview-go.md b/docs/_old_structure/reports/native-kanban-sot/canon-final-rereview-go.md similarity index 100% rename from docs/reports/native-kanban-sot/canon-final-rereview-go.md rename to docs/_old_structure/reports/native-kanban-sot/canon-final-rereview-go.md diff --git a/docs/reports/native-kanban-sot/canon-initial-review-no-go.md b/docs/_old_structure/reports/native-kanban-sot/canon-initial-review-no-go.md similarity index 100% rename from docs/reports/native-kanban-sot/canon-initial-review-no-go.md rename to docs/_old_structure/reports/native-kanban-sot/canon-initial-review-no-go.md diff --git a/docs/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md b/docs/_old_structure/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md similarity index 67% rename from docs/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md rename to docs/_old_structure/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md index 3fbfa55c..fb24e03f 100644 --- a/docs/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md +++ b/docs/_old_structure/reports/native-kanban-sot/kbn-101-contract-security-review-82ce325.md @@ -66,18 +66,18 @@ The contract rightly requires `pg_catalog, ` and reje ## Acceptance and threat traceability -| Requirement / threat | Review result | Evidence or blocking finding | -| --- | --- | --- | -| K101-REQ-01 / AC-K101-01 split runtime/migration URLs | Partial | Role/DTO boundary is coherent; HIGH DDL-path finding requires all current commands to be closed. | -| K101-REQ-02 / AC-K101-02 explicit migration/readiness | Blocked | HIGH ledger definition and HIGH DDL-bypass findings. | -| K101-REQ-03 / AC-K101-03 least privilege, TLS, grants | Partial | Role model, default privileges, ledger read-only, TEMP/function checks are well specified (`KBN-101...:47-56,70-79`); HIGH TLS bootstrap and MEDIUM identifier constraints remain. | -| K101-REQ-04 / AC-K101-04 immutable relations | Correctly deferred | KBN-101-09 after KBN-100 is the correct serial gate (`KBN-101...:58-66,115-118`); no synthetic-only certification claim found. | -| K101-REQ-05 / AC-K101-05 N-1, secrets, rollback | Partial | No owner-runtime exception and rollback keeps migration URL out of Gateway (`:83-95`); deployable TLS and full command inventory are missing. | -| K101-REQ-06 / AC-K101-07 KBN gates and DAG | Structurally sound | DAG is acyclic: 00→01/{03}; 02→06; 00/01/03→05; 00/04/05/06→07→08→KBN-100→09→KBN-105. KBN-100’s current branch contains docs-only baseline tracking, not schema implementation. | -| T: runtime DDL / migration fallback | Blocked | HIGH finding 1. Current Gateway/storage, CLI, direct Drizzle scripts, and integration DDL require explicit closure. | -| T: race/crash/readiness | Partial | Same-session nonblocking lock and replica-unready rules are present (`:34-38`); lock namespace remediation required. | -| T: immutable evidence rewrite | Correctly staged | Explicit INSERT/SELECT-only matrix and RESTRICT retention are retained; proof is properly after table creation. | -| T: secret leakage / TLS downgrade | Partial | Redaction and distinct Vault paths are specified (`:93-97`), but no server TLS/bootstrap implementation contract exists. | +| Requirement / threat | Review result | Evidence or blocking finding | +| ----------------------------------------------------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| K101-REQ-01 / AC-K101-01 split runtime/migration URLs | Partial | Role/DTO boundary is coherent; HIGH DDL-path finding requires all current commands to be closed. | +| K101-REQ-02 / AC-K101-02 explicit migration/readiness | Blocked | HIGH ledger definition and HIGH DDL-bypass findings. | +| K101-REQ-03 / AC-K101-03 least privilege, TLS, grants | Partial | Role model, default privileges, ledger read-only, TEMP/function checks are well specified (`KBN-101...:47-56,70-79`); HIGH TLS bootstrap and MEDIUM identifier constraints remain. | +| K101-REQ-04 / AC-K101-04 immutable relations | Correctly deferred | KBN-101-09 after KBN-100 is the correct serial gate (`KBN-101...:58-66,115-118`); no synthetic-only certification claim found. | +| K101-REQ-05 / AC-K101-05 N-1, secrets, rollback | Partial | No owner-runtime exception and rollback keeps migration URL out of Gateway (`:83-95`); deployable TLS and full command inventory are missing. | +| K101-REQ-06 / AC-K101-07 KBN gates and DAG | Structurally sound | DAG is acyclic: 00→01/{03}; 02→06; 00/01/03→05; 00/04/05/06→07→08→KBN-100→09→KBN-105. KBN-100’s current branch contains docs-only baseline tracking, not schema implementation. | +| T: runtime DDL / migration fallback | Blocked | HIGH finding 1. Current Gateway/storage, CLI, direct Drizzle scripts, and integration DDL require explicit closure. | +| T: race/crash/readiness | Partial | Same-session nonblocking lock and replica-unready rules are present (`:34-38`); lock namespace remediation required. | +| T: immutable evidence rewrite | Correctly staged | Explicit INSERT/SELECT-only matrix and RESTRICT retention are retained; proof is properly after table creation. | +| T: secret leakage / TLS downgrade | Partial | Redaction and distinct Vault paths are specified (`:93-97`), but no server TLS/bootstrap implementation contract exists. | ## Unresolved assumptions @@ -92,15 +92,15 @@ The contract rightly requires `pg_catalog, ` and reje Read-only checks run in this review: -| Check | Result | -| --- | --- | -| `git diff --check origin/main...da742ca2...` | PASS | -| `pnpm exec prettier --check` on all seven changed docs | PASS | -| `pnpm exec tsc --noEmit -p docs/native-kanban-sot/tsconfig.json` | PASS | -| `docker compose -f docker-compose.yml config --quiet` (isolated test ports) | PASS | -| `docker compose -f docker-compose.federated.yml --profile federated config --quiet` (isolated test ports) | PASS | -| Static journal inspection | FAILS the required monotonic ordering premise: 0008 → 0009 `when` decreases; current runner documents skipping behavior. | -| Static DDL-entrypoint inventory | Found direct Drizzle scripts, storage CLI shell-out, runtime extension/migration calls, fleet backlog migration, tier probe extension creation, and a direct-DLL federated integration test. | +| Check | Result | +| --------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `git diff --check origin/main...da742ca2...` | PASS | +| `pnpm exec prettier --check` on all seven changed docs | PASS | +| `pnpm exec tsc --noEmit -p docs/native-kanban-sot/tsconfig.json` | PASS | +| `docker compose -f docker-compose.yml config --quiet` (isolated test ports) | PASS | +| `docker compose -f docker-compose.federated.yml --profile federated config --quiet` (isolated test ports) | PASS | +| Static journal inspection | FAILS the required monotonic ordering premise: 0008 → 0009 `when` decreases; current runner documents skipping behavior. | +| Static DDL-entrypoint inventory | Found direct Drizzle scripts, storage CLI shell-out, runtime extension/migration calls, fleet backlog migration, tier probe extension creation, and a direct-DLL federated integration test. | No live database, Vault, CI, deployment, issue, PR, or repository mutation was performed. The pass results validate documentation syntax/contract compilation and compose syntax only; they do **not** certify the proposed security behavior. diff --git a/docs/reports/native-kanban-sot/ultron-final-go.md b/docs/_old_structure/reports/native-kanban-sot/ultron-final-go.md similarity index 100% rename from docs/reports/native-kanban-sot/ultron-final-go.md rename to docs/_old_structure/reports/native-kanban-sot/ultron-final-go.md diff --git a/docs/_old_structure/reports/qa/gateway-security-20260313.md b/docs/_old_structure/reports/qa/gateway-security-20260313.md new file mode 100644 index 00000000..b1365b16 --- /dev/null +++ b/docs/_old_structure/reports/qa/gateway-security-20260313.md @@ -0,0 +1,39 @@ +# QA Report — Gateway Security Hardening + +## Scope + +- Chat HTTP auth guard hardening +- Chat WebSocket session validation +- DTO validation rules for chat and conversation payloads +- Ownership regression coverage for by-id routes + +## TDD + +- Required: yes +- Applied: yes +- Red step: targeted tests failed on socket session reshaping and DTO role/length mismatches +- Green step: targeted tests passed after runtime and DTO alignment + +## Baseline Verification + +| Command | Result | Evidence | +| ------------------------------------------------------------------------------------------------------------------------------ | ------ | --------------------------------------------- | +| `pnpm --filter @mosaicstack/gateway test -- src/chat/__tests__/chat-security.test.ts src/__tests__/resource-ownership.test.ts` | pass | 3 test files passed, 20 tests passed | +| `pnpm typecheck` | pass | turbo completed 18/18 package typecheck tasks | +| `pnpm lint` | pass | turbo completed 18/18 package lint tasks | +| `pnpm format:check` | pass | `All matched files use Prettier code style!` | + +## Situational Verification + +| Acceptance Criterion | Verification Method | Evidence | +| ------------------------------------------------------ | ---------------------------------------- | ------------------------------------------------------------------------------------------------ | +| Chat controller requires auth and current-user context | source assertion test | `chat-security.test.ts` checks `@UseGuards(AuthGuard)` and `@CurrentUser() user: { id: string }` | +| WebSocket handshake requires Better Auth session | unit tests for `validateSocketSession()` | null handshake returns `null`; valid handshake returns original session object | +| Conversation messages reject non-user/assistant roles | class-validator test | `system` role fails validation | +| Conversation messages enforce a 32k max length | class-validator test | `32_001` chars fail validation | +| Chat request payload enforces a 10k max length | class-validator test | `10_001` chars fail validation | +| By-id routes reject cross-user access | ownership regression tests | conversations, projects, missions, tasks each raise `ForbiddenException` for non-owner access | + +## Residual Risk + +- No live HTTP or WebSocket smoke test against a running gateway process was executed in this session. diff --git a/docs/_old_structure/reports/security/756-security-review.md b/docs/_old_structure/reports/security/756-security-review.md new file mode 100644 index 00000000..dbd086a7 --- /dev/null +++ b/docs/_old_structure/reports/security/756-security-review.md @@ -0,0 +1,37 @@ +# Security Review — Issue #756 + +**Scope:** final current uncommitted Discord plugin, shared channel contract, gateway ingress, AgentService, and plugin registration delta +**Snapshot:** `plugins/discord/src/index.ts` SHA-256 `5ee6b6aa4e2ff349f137f76b918d02c1254e12066cb48b136048e57bef36fdb2` +**Verdict:** **APPROVE** + +## Final remediation verification + +| Area | Current evidence | Result | +| ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------ | +| Attachment confidentiality and integrity | Ingress accepts bounded attachment metadata only when URL is HTTPS, query-free, fragment-free, and credential-free. Count, aggregate size, field length, MIME, and finite non-negative size validation apply before dispatch; `sizeBytes` is signed and retained. | Pass | +| Trusted agent selection | Each binding names a required trusted `agentConfigId`; gateway resolves that config server-side and requires its configured name to equal the binding logical-agent ID. Client/provider input cannot select the agent for Discord ingress. | Pass | +| Privileged operation routing | Gateway revalidates the binding and requires the signed conversation identity to match the configured logical agent before approve/stop actions. Paired admin identity and one-time approval checks remain enforced. | Pass | +| Egress containment and delivery | Egress requires an aligned message/route, configured parent or exact observed thread target, and cleans response routes after completion, errors, typed-ingress failure, or bounded-map pressure. | Pass | +| Side-effect limits | Per guild/authorized-parent/user rolling message and thread limits execute before thread creation or dispatch. | Pass | + +## Security controls reviewed + +- Default-deny guild, parent-channel, user, configured pairing, and role checks precede rate consumption and all side effects. +- Gateway independently enforces Discord service authentication, HMAC integrity, allowlists, binding/role checks, attachment validation, and replay-ID rejection. +- Thread authorization uses only the Discord thread parent; category parents cannot authorize ingress. +- Agent-visible attachment references are explicitly labeled untrusted; binary content is not embedded. Persisted attachment name/URL values are redacted. +- Egress uses deterministic nonces, bounded transient retry, typed terminal errors, and does not send to forged targets. +- No secrets or message content were added to plugin logs. + +## Verification evidence + +| Command | Result | +| ---------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | +| `pnpm --filter @mosaicstack/discord-plugin test` | PASS — 44 tests; v8 coverage: 92.18% statements/lines, 86.55% branches, 100% functions | +| `pnpm --filter @mosaicstack/discord-plugin typecheck` | PASS | +| `pnpm --filter @mosaicstack/types typecheck` | PASS | +| `pnpm --filter @mosaicstack/gateway typecheck` | PASS | +| `pnpm --filter @mosaicstack/gateway exec vitest run src/plugin/discord-ingress.security.spec.ts src/agent/__tests__/agent-service-ownership.test.ts` | PASS — 29 tests | +| `git diff --check` | PASS | + +No unresolved critical, high, medium, or low security findings were identified in the reviewed final delta. diff --git a/docs/requirements/native-kanban-sot.md b/docs/_old_structure/requirements/native-kanban-sot.md similarity index 100% rename from docs/requirements/native-kanban-sot.md rename to docs/_old_structure/requirements/native-kanban-sot.md diff --git a/docs/reviews/consolidation-board-memo.md b/docs/_old_structure/reviews/consolidation-board-memo.md similarity index 100% rename from docs/reviews/consolidation-board-memo.md rename to docs/_old_structure/reviews/consolidation-board-memo.md diff --git a/docs/rfcs/RFC-001-MACP-MATRIX-NATIVE.md b/docs/_old_structure/rfcs/RFC-001-MACP-MATRIX-NATIVE.md similarity index 100% rename from docs/rfcs/RFC-001-MACP-MATRIX-NATIVE.md rename to docs/_old_structure/rfcs/RFC-001-MACP-MATRIX-NATIVE.md diff --git a/docs/rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md b/docs/_old_structure/rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md similarity index 100% rename from docs/rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md rename to docs/_old_structure/rfcs/RFC-002-INSTALL-CONFIG-TOPOLOGY.md diff --git a/docs/scratchpads/1000-rm-61-ci-contract-exemption.md b/docs/_old_structure/scratchpads/1000-rm-61-ci-contract-exemption.md similarity index 100% rename from docs/scratchpads/1000-rm-61-ci-contract-exemption.md rename to docs/_old_structure/scratchpads/1000-rm-61-ci-contract-exemption.md diff --git a/docs/scratchpads/2026-06-20-fleet-cli-local-canary.md b/docs/_old_structure/scratchpads/2026-06-20-fleet-cli-local-canary.md similarity index 100% rename from docs/scratchpads/2026-06-20-fleet-cli-local-canary.md rename to docs/_old_structure/scratchpads/2026-06-20-fleet-cli-local-canary.md diff --git a/docs/scratchpads/2026-06-20-fleet-release-hardening.md b/docs/_old_structure/scratchpads/2026-06-20-fleet-release-hardening.md similarity index 100% rename from docs/scratchpads/2026-06-20-fleet-release-hardening.md rename to docs/_old_structure/scratchpads/2026-06-20-fleet-release-hardening.md diff --git a/docs/scratchpads/387-updater-wrapper-gitea-20260404.md b/docs/_old_structure/scratchpads/387-updater-wrapper-gitea-20260404.md similarity index 100% rename from docs/scratchpads/387-updater-wrapper-gitea-20260404.md rename to docs/_old_structure/scratchpads/387-updater-wrapper-gitea-20260404.md diff --git a/docs/scratchpads/41-plugin-host.md b/docs/_old_structure/scratchpads/41-plugin-host.md similarity index 100% rename from docs/scratchpads/41-plugin-host.md rename to docs/_old_structure/scratchpads/41-plugin-host.md diff --git a/docs/scratchpads/462-fed-m3-04-scope-service.md b/docs/_old_structure/scratchpads/462-fed-m3-04-scope-service.md similarity index 100% rename from docs/scratchpads/462-fed-m3-04-scope-service.md rename to docs/_old_structure/scratchpads/462-fed-m3-04-scope-service.md diff --git a/docs/scratchpads/462-fed-m3-06-get-verb.md b/docs/_old_structure/scratchpads/462-fed-m3-06-get-verb.md similarity index 100% rename from docs/scratchpads/462-fed-m3-06-get-verb.md rename to docs/_old_structure/scratchpads/462-fed-m3-06-get-verb.md diff --git a/docs/scratchpads/536-wrapper-login-pin.md b/docs/_old_structure/scratchpads/536-wrapper-login-pin.md similarity index 100% rename from docs/scratchpads/536-wrapper-login-pin.md rename to docs/_old_structure/scratchpads/536-wrapper-login-pin.md diff --git a/docs/scratchpads/544-agent-reflection-loop.md b/docs/_old_structure/scratchpads/544-agent-reflection-loop.md similarity index 100% rename from docs/scratchpads/544-agent-reflection-loop.md rename to docs/_old_structure/scratchpads/544-agent-reflection-loop.md diff --git a/docs/scratchpads/559-560-wrapper-eval-login-20260620.md b/docs/_old_structure/scratchpads/559-560-wrapper-eval-login-20260620.md similarity index 100% rename from docs/scratchpads/559-560-wrapper-eval-login-20260620.md rename to docs/_old_structure/scratchpads/559-560-wrapper-eval-login-20260620.md diff --git a/docs/scratchpads/561-python-is-python3.md b/docs/_old_structure/scratchpads/561-python-is-python3.md similarity index 100% rename from docs/scratchpads/561-python-is-python3.md rename to docs/_old_structure/scratchpads/561-python-is-python3.md diff --git a/docs/scratchpads/631-reseed-preserves-fleet.md b/docs/_old_structure/scratchpads/631-reseed-preserves-fleet.md similarity index 100% rename from docs/scratchpads/631-reseed-preserves-fleet.md rename to docs/_old_structure/scratchpads/631-reseed-preserves-fleet.md diff --git a/docs/scratchpads/633-comms-block-runbook.md b/docs/_old_structure/scratchpads/633-comms-block-runbook.md similarity index 100% rename from docs/scratchpads/633-comms-block-runbook.md rename to docs/_old_structure/scratchpads/633-comms-block-runbook.md diff --git a/docs/scratchpads/672-fleet-personas-timeout.md b/docs/_old_structure/scratchpads/672-fleet-personas-timeout.md similarity index 100% rename from docs/scratchpads/672-fleet-personas-timeout.md rename to docs/_old_structure/scratchpads/672-fleet-personas-timeout.md diff --git a/docs/scratchpads/703-wrapper-interactive-auth.md b/docs/_old_structure/scratchpads/703-wrapper-interactive-auth.md similarity index 100% rename from docs/scratchpads/703-wrapper-interactive-auth.md rename to docs/_old_structure/scratchpads/703-wrapper-interactive-auth.md diff --git a/docs/scratchpads/747-wsa-dehardcode.md b/docs/_old_structure/scratchpads/747-wsa-dehardcode.md similarity index 100% rename from docs/scratchpads/747-wsa-dehardcode.md rename to docs/_old_structure/scratchpads/747-wsa-dehardcode.md diff --git a/docs/scratchpads/751-native-kanban-canon.md b/docs/_old_structure/scratchpads/751-native-kanban-canon.md similarity index 100% rename from docs/scratchpads/751-native-kanban-canon.md rename to docs/_old_structure/scratchpads/751-native-kanban-canon.md diff --git a/docs/scratchpads/753-kbn010-threat-gate.md b/docs/_old_structure/scratchpads/753-kbn010-threat-gate.md similarity index 100% rename from docs/scratchpads/753-kbn010-threat-gate.md rename to docs/_old_structure/scratchpads/753-kbn010-threat-gate.md diff --git a/docs/scratchpads/755-mos-logical-identity-fencing.md b/docs/_old_structure/scratchpads/755-mos-logical-identity-fencing.md similarity index 100% rename from docs/scratchpads/755-mos-logical-identity-fencing.md rename to docs/_old_structure/scratchpads/755-mos-logical-identity-fencing.md diff --git a/docs/scratchpads/756-official-discord-plugin.md b/docs/_old_structure/scratchpads/756-official-discord-plugin.md similarity index 100% rename from docs/scratchpads/756-official-discord-plugin.md rename to docs/_old_structure/scratchpads/756-official-discord-plugin.md diff --git a/docs/scratchpads/758-fcm-m1-002-shared-role-resolution.md b/docs/_old_structure/scratchpads/758-fcm-m1-002-shared-role-resolution.md similarity index 86% rename from docs/scratchpads/758-fcm-m1-002-shared-role-resolution.md rename to docs/_old_structure/scratchpads/758-fcm-m1-002-shared-role-resolution.md index 5c6943a1..0f44615f 100644 --- a/docs/scratchpads/758-fcm-m1-002-shared-role-resolution.md +++ b/docs/_old_structure/scratchpads/758-fcm-m1-002-shared-role-resolution.md @@ -124,12 +124,12 @@ exact-head gates remain required. ## Acceptance-evidence mapping -| Requirement / criterion | Verification evidence | -| --- | --- | -| `FCM-REQ-02` shared semantic resolver | Async/sync resolver parity; roster-v2 delegates batched scans and resolution; profiles/provision and launch reuse `fleet-personas.ts`; no second scanner or class-marker regex added. | -| `FCM-REQ-07` canonical classes and authority boundaries | Exact alias and non-alias tests; immutable authority invariant tests; all required canonical contracts resolve through the real role library. | -| `AC-FCM-01` structural + semantic roster validation | Synchronous parser/normalizer tests remain intact; async semantic tests cover aliases, custom roles, unreadable/unresolved roles, `LIBRARY`-only rejection, and bidirectional protected policy mismatch. | -| `AC-FCM-07` protected authority invariants | Denial tests prove merge-gate-only merge, validator certificate-only, orchestrator/team-leader/interaction limits, no implicit custom-role authority, and canonical tool-policy matching. | +| Requirement / criterion | Verification evidence | +| ------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `FCM-REQ-02` shared semantic resolver | Async/sync resolver parity; roster-v2 delegates batched scans and resolution; profiles/provision and launch reuse `fleet-personas.ts`; no second scanner or class-marker regex added. | +| `FCM-REQ-07` canonical classes and authority boundaries | Exact alias and non-alias tests; immutable authority invariant tests; all required canonical contracts resolve through the real role library. | +| `AC-FCM-01` structural + semantic roster validation | Synchronous parser/normalizer tests remain intact; async semantic tests cover aliases, custom roles, unreadable/unresolved roles, `LIBRARY`-only rejection, and bidirectional protected policy mismatch. | +| `AC-FCM-07` protected authority invariants | Denial tests prove merge-gate-only merge, validator certificate-only, orchestrator/team-leader/interaction limits, no implicit custom-role authority, and canonical tool-policy matching. | ## Documentation diff --git a/docs/scratchpads/758-fcm-m1-003-example-profile-dispositions.md b/docs/_old_structure/scratchpads/758-fcm-m1-003-example-profile-dispositions.md similarity index 100% rename from docs/scratchpads/758-fcm-m1-003-example-profile-dispositions.md rename to docs/_old_structure/scratchpads/758-fcm-m1-003-example-profile-dispositions.md diff --git a/docs/scratchpads/758-fcm-m2-002-fleet-agent-crud.md b/docs/_old_structure/scratchpads/758-fcm-m2-002-fleet-agent-crud.md similarity index 100% rename from docs/scratchpads/758-fcm-m2-002-fleet-agent-crud.md rename to docs/_old_structure/scratchpads/758-fcm-m2-002-fleet-agent-crud.md diff --git a/docs/scratchpads/758-fcm-m3-001-local-reconciler.md b/docs/_old_structure/scratchpads/758-fcm-m3-001-local-reconciler.md similarity index 100% rename from docs/scratchpads/758-fcm-m3-001-local-reconciler.md rename to docs/_old_structure/scratchpads/758-fcm-m3-001-local-reconciler.md diff --git a/docs/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md b/docs/_old_structure/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md similarity index 55% rename from docs/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md rename to docs/_old_structure/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md index 51d0bc14..6a005010 100644 --- a/docs/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md +++ b/docs/_old_structure/scratchpads/758-fcm-m3-002-reconciler-lifecycle-gates.md @@ -21,18 +21,18 @@ Add broad, behavior-oriented acceptance evidence around the shipped local reconc ## Acceptance mapping and evidence -| FCM-M3-002 acceptance concern | Delivered isolated evidence | -| --- | --- | -| Systemd/tmux lifecycle | `fleet-reconciler.acceptance.spec.ts` drives apply, reconcile, stop, restart, status, and recovery reconcile through one stateful injected fake host. The fake models exact systemd effects and tmux session observations; no host commands run. | -| Drift | Canonical roster-v2 YAML drives the Commander `fleet status` boundary and classifies `missing-session`, `unexpected-session`, and `disabled-running`, including combined drift, while asserting observation emits no lifecycle mutation. | +| FCM-M3-002 acceptance concern | Delivered isolated evidence | +| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Systemd/tmux lifecycle | `fleet-reconciler.acceptance.spec.ts` drives apply, reconcile, stop, restart, status, and recovery reconcile through one stateful injected fake host. The fake models exact systemd effects and tmux session observations; no host commands run. | +| Drift | Canonical roster-v2 YAML drives the Commander `fleet status` boundary and classifies `missing-session`, `unexpected-session`, and `disabled-running`, including combined drift, while asserting observation emits no lifecycle mutation. | | Exact default/named socket targeting | Canonical v2 requires an explicit non-empty named socket; the parser rejects missing/empty values and the Commander acceptance path asserts exact `-L mosaic-fleet` targeting. A separate canonical legacy-v1 roster loader plus runtime-transport path proves a socket-less compatibility roster targets the literal tmux default server with no `-L`. No unreachable empty-socket v2 fixture is used. | -| Unmanaged-session classification | Stateful fixtures report sorted `coder0-shadow`/`unmanaged` sessions, then prove an exact roster stop leaves both sessions and the near-collision service intact. | -| Crash/partial failure | Injected restart failure is applied after the fake effect to model crash/partial truth: result is `lifecycle: incomplete`, the roster is unchanged, and observed runtime may be active. | -| Rollback/recovery semantics | M3 has no rollback command and explicitly does not claim automatic rollback. The acceptance workflow proves the bounded recovery contract: inspect, then exact reconcile restores the persisted stopped target without a start or fuzzy effect. M4 migration/canary rollback remains outside this card. | -| Stopped-state preservation | Stateful apply and reconcile both stop an initially running observed agent whose persisted target is stopped; failed explicit restart leaves desired state stopped; recovery reconcile restores stopped state. No start call is emitted. | -| Zero fuzzy destructive targeting | Near-collision `coder0-shadow` service/session plus `unmanaged` session remain untouched. The recorded destructive calls contain only exact `mosaic-agent@coder0.service`; no tmux kill action is emitted. | -| Stable JSON/exit behavior | Temporary canonical roster fixture invokes the CLI boundary and asserts exactly one JSON line, exact partial-result shape, and exit code 1. Existing focused command specs continue to cover clean zero-exit and stable error JSON. | -| Redacted truthful recovery | Fake stderr includes `PASSWORD=acceptance-secret`; exact CLI JSON contains only bounded recovery metadata and excludes the key, value, and raw diagnostic. | +| Unmanaged-session classification | Stateful fixtures report sorted `coder0-shadow`/`unmanaged` sessions, then prove an exact roster stop leaves both sessions and the near-collision service intact. | +| Crash/partial failure | Injected restart failure is applied after the fake effect to model crash/partial truth: result is `lifecycle: incomplete`, the roster is unchanged, and observed runtime may be active. | +| Rollback/recovery semantics | M3 has no rollback command and explicitly does not claim automatic rollback. The acceptance workflow proves the bounded recovery contract: inspect, then exact reconcile restores the persisted stopped target without a start or fuzzy effect. M4 migration/canary rollback remains outside this card. | +| Stopped-state preservation | Stateful apply and reconcile both stop an initially running observed agent whose persisted target is stopped; failed explicit restart leaves desired state stopped; recovery reconcile restores stopped state. No start call is emitted. | +| Zero fuzzy destructive targeting | Near-collision `coder0-shadow` service/session plus `unmanaged` session remain untouched. The recorded destructive calls contain only exact `mosaic-agent@coder0.service`; no tmux kill action is emitted. | +| Stable JSON/exit behavior | Temporary canonical roster fixture invokes the CLI boundary and asserts exactly one JSON line, exact partial-result shape, and exit code 1. Existing focused command specs continue to cover clean zero-exit and stable error JSON. | +| Redacted truthful recovery | Fake stderr includes `PASSWORD=acceptance-secret`; exact CLI JSON contains only bounded recovery metadata and excludes the key, value, and raw diagnostic. | ## Plan diff --git a/docs/scratchpads/758-fcm-m4-001-v1-v2-migrator.md b/docs/_old_structure/scratchpads/758-fcm-m4-001-v1-v2-migrator.md similarity index 100% rename from docs/scratchpads/758-fcm-m4-001-v1-v2-migrator.md rename to docs/_old_structure/scratchpads/758-fcm-m4-001-v1-v2-migrator.md diff --git a/docs/scratchpads/771-kbn101-db-role-split.md b/docs/_old_structure/scratchpads/771-kbn101-db-role-split.md similarity index 100% rename from docs/scratchpads/771-kbn101-db-role-split.md rename to docs/_old_structure/scratchpads/771-kbn101-db-role-split.md diff --git a/docs/scratchpads/791-upgrade-config-protection.md b/docs/_old_structure/scratchpads/791-upgrade-config-protection.md similarity index 96% rename from docs/scratchpads/791-upgrade-config-protection.md rename to docs/_old_structure/scratchpads/791-upgrade-config-protection.md index 9e7199a7..e9a2aede 100644 --- a/docs/scratchpads/791-upgrade-config-protection.md +++ b/docs/_old_structure/scratchpads/791-upgrade-config-protection.md @@ -5,6 +5,7 @@ off `origin/main` `9745bc3f` (verified exact head). ## Mission prompt (verbatim intent) + Protect operator-owned config under `~/.config/mosaic` from framework-upgrade wipes. Ratified combination (Mos-approved, do NOT re-litigate): (b) strict ownership separation [PRIMARY] + (a) transactional pre-update snapshot [safety net] + (d) regeneration-from-SSOT [recovery]. (c) periodic @@ -14,6 +15,7 @@ Design-first: write design doc, send to MS-LEAD, WAIT for confirmation before im ## Session 1 (2026-07-16) — Phase 1 design ### Evidence gathered (wipe mechanism, file/line) + - `mosaic update` → `update-checker.ts:509` `buildReseedCommand` → `bash install.sh` (`MOSAIC_SYNC_ONLY=1`, `MOSAIC_INSTALL_MODE=keep`). - Wipe = `packages/mosaic/framework/install.sh:199` `rsync -a --delete` + `PRESERVE_PATHS` denylist @@ -30,6 +32,7 @@ Design-first: write design doc, send to MS-LEAD, WAIT for confirmation before im lifecycle → `mosaic fleet regen` = thin projection-only wrapper (no restart), no FCM-M4/M5 preemption. ### Design decisions + - **(b)** Invert to allow-list: shared `framework/framework-manifest.json` (framework globs + operatorReserved carve-outs); resolve per-path, deny-wins; **UNKNOWN ⇒ operator (fail-safe)**. Mechanism: drop `--delete`; non-deleting bulk copy + explicit manifest-scoped prune pass (iterate @@ -42,10 +45,13 @@ Design-first: write design doc, send to MS-LEAD, WAIT for confirmation before im regen+docs. PR2/PR3 depend on PR1. ### Status + Design doc written: `docs/design/791-upgrade-config-protection.md`. Sent to MS-LEAD. ## Session 1 (cont.) — MS-LEAD CONFIRMED → Phase 2 GO + All 4 asks approved. Binding conditions: + - TDD tests-first, red-first proof per PR; ≥85% new-code; co-located `*.spec.ts`; never `--no-verify`. - HARD GATE test (§2.4, unanticipated sentinel survives byte-identical + mtime unchanged) = MERGE-BLOCKING for PR1. - Manifest-completeness test (§6.2) required. @@ -65,6 +71,7 @@ tested" requirement is honored — `manifest-parity.spec.ts` drives the bash res and asserts byte-identical ownership vs the TS resolver over 34 probe paths spanning every class. ### PR1 artifacts + - SSOT: `packages/mosaic/framework/framework-manifest.txt` ([framework]/[operator], deny-wins, fail-safe). - TS resolver: `src/framework/manifest.ts` (pure: parse/matchGlob/resolveOwnership/frameworkSubtreeRoots/ planPrune) + `manifest.spec.ts` (18 tests incl. planPrune property test + §6.2 completeness). @@ -84,11 +91,13 @@ and asserts byte-identical ownership vs the TS resolver over 34 probe paths span - update-checker.ts reseed comment corrected to the manifest model. ### Gates (all green) + - `pnpm typecheck` ✓ · `pnpm lint` ✓ · `pnpm format:check` ✓ - Full mosaic vitest: 1062 passed (cli-smoke needs `pnpm build` first — build-artifact dep, not this change). - HARD GATE 48/48 · migration 21/21 · parity 3/3 · manifest 18/18 · file-adapter 8/8. ### PR opened + reported (2026-07-16) + - **PR #802** http://git.mosaicstack.dev/mosaicstack/stack/pulls/802 — base `main`@`9745bc3f`, head `34e55d4a` (commit `feat(mosaic): manifest-owned upgrade guard…`). 15 files, +1160/-142. - Reported PR head + red→green evidence to MS-LEAD (web1:mosaic-100); queued (lead busy). @@ -100,18 +109,20 @@ and asserts byte-identical ownership vs the TS resolver over 34 probe paths span - DO NOT start PR2/PR3 until PR1 merges (DAG; one PR at a time). ### MS-LEAD ruling → #797 ledger-survival sentinel folded into PR1 (2026-07-16) + MS-LEAD ruled both my decisions: (1) `.txt` format ACCEPTED (parity must be strict/merge-blocking incl. format edge cases + negative probe); (2) trailer `Fixes #791`→`Part of #791` APPROVED (patched PR #802 body via Gitea API — tracking issue no longer auto-closes on PR1 merge). Plus Mos-ELEVATED merge-blocker (spec `~/agent-work/planning/epic-796/791-ledger-survival-sentinel-SPEC.md`): #797 Runtime Session Ledger must survive upgrade. Two coupled deliverables landed in PR1: + - (i) Carve-out: `fleet/run/**` was ALREADY an explicit `[operator]` entry — glob matches the spec's pinned `fleet/run/**` EXACTLY, so NO divergence to route back to planner-opus. Strengthened its comment to name the ledger (`fleet/run/sessions/` events.ndjson + ledger.json) so it is unmistakably load-bearing. - (ii) HARD-GATE sentinel: seeded populated ledger (events.ndjson 3 events + ledger.json node+edge+gen, 0600 under 0700) into test-upgrade-manifest-guard.sh sentinels; asserts byte-identical + mtime-unchanged - + dir-perms unchanged. Negative control (retired framework file IS pruned) relabeled explicitly. - HARD GATE now 58/58 (was 48). + - dir-perms unchanged. Negative control (retired framework file IS pruned) relabeled explicitly. + HARD GATE now 58/58 (was 48). - Decision-1 parity hardening: format-edge fixtures (comments/blanks/whitespace, duplicate+overlapping globs deny-wins, section/glob-ordering independence) + explicit UNKNOWN→operator negative probe, driven through BOTH resolvers via MANIFEST_FILE override. Parity 7/7 (was 3). @@ -125,8 +136,10 @@ must survive upgrade. Two coupled deliverables landed in PR1: · migration 21/21. Committing FORWARD on the branch (NOT rebasing 34e55d4a out from under review). ### MS-LEAD REQUEST CHANGES @ 0a5e703a → B1/B2/B3 fixed red-first (2026-07-16) + MS-LEAD returned REQUEST CHANGES (routed merge-blockers satisfied; 2 CRITICAL reliability defects from the commissioned independent review). Fixed forward on the branch, red-first: + - **B1 (CRITICAL) — dead ERR trap.** install.sh had `set -euo pipefail` (no `-E`), so the `trap restore_snapshot ERR` never fired for a failure inside sync_framework_keep() (function body) — a mid-sync abort left a half-written target with NO rollback. Fix: `set -Eeuo pipefail` (errtrace) + @@ -140,19 +153,19 @@ the commissioned independent review). Fixed forward on the branch, red-first: fragilely (the `_manifest_compile` `"${MANIFEST_OPERATOR[@]:-}"` artifact returned 1 with no message) AND the CLI dispatch swallowed manifest_load's rc (no `|| exit`) so `resolve` exited 0 resolving everything operator. Fix (fail-loud + identical both langs): - * TS `parseManifest`: throw on zero framework entries; `loadManifest`: wrap read error → + - TS `parseManifest`: throw on zero framework entries; `loadManifest`: wrap read error → "Cannot read framework manifest …". - * bash `manifest_load`: explicit unreadable guard (`[[ ! -r ]]`) + zero-`[framework]` guard, both loud + - bash `manifest_load`: explicit unreadable guard (`[[ ! -r ]]`) + zero-`[framework]` guard, both loud stderr + return 1; `_manifest_compile` gets explicit `return 0` (kills the empty-array artifact); CLI dispatch `manifest_load … || exit 1`. - * `finalize.ts`: wrap syncFramework → `spin.stop('Framework sync aborted …')` + rethrow (never falls + - `finalize.ts`: wrap syncFramework → `spin.stop('Framework sync aborted …')` + rethrow (never falls through to "Installation complete"). - Tests: manifest.spec.ts +5 fail-closed (empty/comment-only/operator-only/empty-section/missing); - manifest-parity.spec.ts +7 failure-mode parity (both reject empty/comment-only/operator-only/ - empty-section/entry-before-header/unknown-header/missing — TS throws, bash CLI exits non-zero+stderr); - HARD GATE +4 end-to-end fail-closed matrices (empty/operator-only/malformed/missing → abort non-zero, - manifest error surfaced, every operator sentinel byte-identical). RED proven by reverting - manifest.ts+manifest.sh to HEAD → 12 new tests fail; restore → 40/40 green. + Tests: manifest.spec.ts +5 fail-closed (empty/comment-only/operator-only/empty-section/missing); + manifest-parity.spec.ts +7 failure-mode parity (both reject empty/comment-only/operator-only/ + empty-section/entry-before-header/unknown-header/missing — TS throws, bash CLI exits non-zero+stderr); + HARD GATE +4 end-to-end fail-closed matrices (empty/operator-only/malformed/missing → abort non-zero, + manifest error surfaced, every operator sentinel byte-identical). RED proven by reverting + manifest.ts+manifest.sh to HEAD → 12 new tests fail; restore → 40/40 green. - **Non-blocking addressed.** MEDIUM install.sh:222 find-empty now warns on a real failure instead of blanket `|| true`. LOW: corrected the "both destructive paths rsync vs cp" overstatement in the HARD GATE header + cp-fallback comment + ci.yml (keep mode is a single cp-based path; the rsync-present vs @@ -163,8 +176,10 @@ the commissioned independent review). Fixed forward on the branch, red-first: ci.yml upgrade-guard. Committing FORWARD (no rebase of 34e55d4a/0a5e703a). ### Codex round 2 (pre-push self-review) → blockers A/B + should-fix C fixed red-first (2026-07-16) + Before committing round 1 I re-ran codex on the change set; it surfaced two fresh reliability defects and one messaging defect on the SAME rollback/manifest path. Fixed forward, red-first: + - **Blocker-A (CRITICAL) — signal trap resumed instead of terminating.** A bash INT/TERM handler that merely `restore_snapshot` (returns) does NOT terminate the script — execution RESUMES past the interrupt, cleans the snapshot and reports success, leaving a partial post-interrupt update. Fix: @@ -192,7 +207,9 @@ and one messaging defect on the SAME rollback/manifest path. Fixed forward, red- manifest specs already counted) · HARD GATE 193/193 · rollback 14/14 · migration 21/21. ### Codex round 3 (pre-push self-review) → blockers D1/D2 fixed red-first (2026-07-16) + Re-ran codex again; it found two more rollback-path gaps `set -E` cannot catch. Fixed forward, red-first: + - **Blocker-D1 (CRITICAL) — `find` scan failures swallowed by process substitution.** Both the overlay copy and the scoped prune consumed `< <(find … -print0)`. Bash does NOT propagate the producer's exit status to the `while`, so an EACCES/I/O failure mid-scan truncates the file list yet leaves the loop @@ -207,7 +224,7 @@ Re-ran codex again; it found two more rollback-path gaps `set -E` cannot catch. possibly after `rm` deleted part of the target — the script exits immediately, skipping the cp AND the recovery pointer, leaving a half-removed target and an orphaned snapshot the operator can't locate. Fix: `if ! rm -rf … || ! mkdir -p …; then fail "Snapshot restore could not reset … preserved at: - $SNAPSHOT_DIR — copy it back …"; return 1; fi` (tested like the cp -a check; snapshot NOT deleted). +$SNAPSHOT_DIR — copy it back …"; return 1; fi` (tested like the cp -a check; snapshot NOT deleted). Rollback test Part E: cp-poison triggers restore + an `rm` shim fails `rm -rf ` → shipped emits the recovery pointer, the named snapshot dir survives, secret value never leaked; control deletes the recovery line → operator gets no pointer. RED: reverting D1+D2 → 7 shipped/control assertions fail. @@ -216,6 +233,7 @@ Re-ran codex again; it found two more rollback-path gaps `set -E` cannot catch. No --no-verify. Committing FORWARD (no rebase of 34e55d4a/0a5e703a). ## Session 3 (2026-07-16) — PR1 MERGED, starting PR2 (durable snapshot + restore + secrev) + PR1 (#802) squash-merged → main `32a0ffba`; issue #791 stays open (3-PR DAG umbrella). Independent Opus adversarial/security review APPROVED at head `af627e75` (Gitea RoR cmt 17892); lead ran rollback 28/28 + HARD GATE 193/193 green; CI #1877 green. PR2 UNBLOCKED. @@ -225,6 +243,7 @@ tests-first red-first, independent review + durable Gitea Reviewer-of-Record com the queue guard/merge. Report PR2 number + exact head when ready. PR body: `Part of #791` (NOT Fixes). ### PR2 scope (ratified §3/§5 of design doc, Mos-approved — do NOT re-litigate) + - **(a) Durable pre-update snapshot** to `${XDG_STATE_HOME:-~/.local/state}/mosaic/backups/pre-update-/` — OUTSIDE ~/.config/mosaic and any repo. Perms dir 0700 / files 0600 (umask 077 + explicit chmod). Scope = operator-owned surface that EXISTS (operatorReserved paths), not the framework tree. Taken @@ -234,10 +253,12 @@ the queue guard/merge. Report PR2 number + exact head when ready. PR body: `Part - **`mosaic restore`** (TS CLI): `--list` (default, dry-run) enumerates snapshots by ts; `--from ` restores over operator surface, confirmation-gated. Counts/paths only. - **Secret-safety (secrev)**: snapshot/restore NEVER emit file contents; only paths/counts. Tests assert - 0700/0600 AND that a secret value seeded in tools/_lib/credentials.json never appears in any output. + 0700/0600 AND that a secret value seeded in tools/\_lib/credentials.json never appears in any output. ### PR2 implementation status (2026-07-16, ready-for-review) + All three tasks implemented, red-first proven, unit-green: + - **Task #10 — durable snapshot (install.sh)**: `backup_root()`/`enumerate_operator_files()`/ `prune_durable_snapshots()`/`make_durable_snapshot()` wired into keep-mode main() after `manifest_load`, before any mutation. umask 077 + explicit chmod 700/600. UTC ts, collision suffix. FAIL-OPEN (a backup @@ -256,10 +277,11 @@ All three tasks implemented, red-first proven, unit-green: Est. new-code coverage ≈93% (only the interactive readline default + process.exit-on-error uncovered). - Regression fixed: PR2's `date`/`sort`/`mv` broke the rsync-absent manifest-guard PATH whitelist → made date/sort fail-open, replaced `mv` with in-place `sort -o`, added `date sort` to the test whitelist - + isolated `XDG_STATE_HOME`. All 193 manifest-guard assertions green under restricted PATH. + - isolated `XDG_STATE_HOME`. All 193 manifest-guard assertions green under restricted PATH. - Codex code-review + security-review (secrev) run on the uncommitted diff before commit. ### PR2 review round 1 — findings + remediations (2026-07-16, pre-PR) + Codex code-review returned **request-changes** (1 blocker + 3 should-fix); Codex security-review returned **high** (1 high + 1 medium). Deduped to 5 distinct defects, ALL legitimate, ALL fixed FORWARD, each with a red-first regression test whose control neuters exactly the guard under test: @@ -272,20 +294,20 @@ a red-first regression test whose control neuters exactly the guard under test: **Test:** Part 6 — v1 fixture with bin/; shipped keeps it removed + stamps v3; control (guard stripped) wrongly restores bin/tool.sh. - **B · HIGH (CWE-59) — restore/verify wrote secrets THROUGH a symlink (install.sh + restore.ts).** An - attacker swapping an operator path (e.g. tools/_lib/credentials.json) for a symlink after the snapshot + attacker swapping an operator path (e.g. tools/\_lib/credentials.json) for a symlink after the snapshot would make `cp`/`copyFileSync` write the snapshot's secret out through the link. **Fix (bash):** refuse a symlinked ancestor (`has_symlinked_parent`), drop a symlinked leaf before restore (`# SYMLINK-LEAF-GUARD`). **Fix (TS):** reuse audited `secure-file.ts` — `assertCanonicalContainment` - + `ensureManagedDirectory` on every dst, open the leaf `O_NOFOLLOW|O_CREAT|O_TRUNC` 0600 (ELOOP = - fail-closed). **Tests:** Part 7 (shipped leaves external exfil target untouched, restores a real 0600 - file; control leaks the secret through the link) + restore.spec symlinked-leaf/ancestor cases (red-first). + - `ensureManagedDirectory` on every dst, open the leaf `O_NOFOLLOW|O_CREAT|O_TRUNC` 0600 (ELOOP = + fail-closed). **Tests:** Part 7 (shipped leaves external exfil target untouched, restores a real 0600 + file; control leaks the secret through the link) + restore.spec symlinked-leaf/ancestor cases (red-first). - **C · MEDIUM/should-fix (CWE-22) — `--from` traversal escaped the backup root (restore.ts).** `join(root, from)` accepted `../poison`. **Fix:** validate the selector against `^\d{8}T\d{6}Z(?:-\d+)?$`, build exactly `join(root,'pre-update-'+ts)`, `lstat` (reject symlinked snap dir). **Test:** restore.spec `it.each` of 6 malformed selectors + `--from ../poison` fail-closed (red-first). - **D · should-fix — verify `mkdir -p` unguarded under set -e (install.sh).** A parent replaced by a regular file aborted the installer before the recovery pointer printed. **Fix:** guard `mkdir -p`, warn - + `continue` on failure (keeps healing remaining files). + - `continue` on failure (keeps healing remaining files). - **E · should-fix — snapshot `umask 077` leaked process-global (install.sh).** Later sync copies/dirs inherited 0600/0700. **Fix:** save `old_umask`, restore on EVERY return path (`# UMASK-RESTORE-NORMAL`). **Test:** Part 8 — synced framework file is 0644 while the secret backup stays 0600; control (restore @@ -298,6 +320,7 @@ anchor convention. NOTE: codex self-review does NOT satisfy the independent-revi (author≠reviewer) review + durable Gitea Reviewer-of-Record comment is still required before MS-LEAD merges. ## Session 4 (2026-07-16) — PR2 MERGED, PR3 built (fleet regen — recovery layer) + PR2 (#811) squash-merged → main `31607a4a`; issue #791 stays open (final PR of the 3-PR DAG). Independent exact-head RoR at `d12c5f78` APPROVE (Gitea cmt 17904); #1882 green; busybox-portable Part 7 control fix verified in-Alpine. PR3 UNBLOCKED. @@ -306,6 +329,7 @@ PR3 branch: `feat/791-pr3-fleet-regen` off `origin/main` 31607a4. Same disciplin independent review + durable Gitea RoR BEFORE MS-LEAD runs the queue guard/merge. PR body `Part of #791`. ### PR3 scope (ratified §4/§7 of design doc) — `mosaic fleet regen` + Projection-only recovery command: rebuilds each `fleet/agents/.env.generated` from `roster.yaml` (SSOT). Dry-run default; `--write` applies; `--json` machine output. Structural guarantee: NO code path to systemd lifecycle — **never restarts an agent**. Single-SSOT: reuses `projectRosterV2AgentGeneratedEnv` @@ -317,6 +341,7 @@ New files: `commands/fleet-regen-command.ts` (+ `.spec.ts`), guide `docs/guides/ runbook), regen reference added to `docs/guides/fleet-local-canary.md`. Wired in `commands/fleet.ts`. ### Independent review (3 reviewers: subagent code-reviewer + codex code-review + codex security) → 4 fixes, red-first + - **A · BLOCKER (codex) — regen mutated/deleted legacy operator env.** `applyPreparedAgentEnvironmentProjection` also writes `.env.local`/`.env.quarantine` and unlinks legacy `.env`. Violated projection-only contract. **Fix:** NEW generated-only boundary primitives `prepareGeneratedAgentEnvironmentProjection` + @@ -387,7 +412,9 @@ code/security re-run in flight. STOP at PR-open for MS-LEAD's exact-head review NOT self-merge; #791 umbrella stays OPEN; PR body `Part of #791`. ### Round 3 review (after M1/M2/M3) — independent review PASS + codex residual-TOCTOU disposition + Three reviewers on the post-M1/M2/M3 head: + - **Independent (subagent, author≠reviewer) — PASS.** Verified M1/M2/M3 all correctly fixed; "never restarts" is STRUCTURAL (runner never referenced in executable code); no secrets; no deadlock (only regen holds both locks); tests meaningful (assert inode preservation + exact lock-file names). Raised: @@ -510,7 +537,7 @@ confirming the test genuinely pins the fix; restored after. No lint/type issues; = the deferred follow-up. No new distinct finding; the wiring fix introduced nothing. - **Independent confirmation review of the persona-root wiring fix — PASS, no findings.** Reviewer mechanically reverted the two forwarded lines → RED (`Roster v2 agent "coder0" class "code" does not - resolve to a readable persona` → exit 1), restored → GREEN (26 regen + 204 fleet tests). Confirmed the +resolve to a readable persona` → exit 1), restored → GREEN (26 regen + 204 fleet tests). Confirmed the optional-chaining fallback preserves default-deployment behavior and no type/lint issue. **Review disposition for PR-open:** ALL actionable findings fixed red-first across rounds 3–6 (label diff --git a/docs/scratchpads/804-install-unknown-flags.md b/docs/_old_structure/scratchpads/804-install-unknown-flags.md similarity index 83% rename from docs/scratchpads/804-install-unknown-flags.md rename to docs/_old_structure/scratchpads/804-install-unknown-flags.md index d2f9e464..7e30fc5c 100644 --- a/docs/scratchpads/804-install-unknown-flags.md +++ b/docs/_old_structure/scratchpads/804-install-unknown-flags.md @@ -64,14 +64,14 @@ Implement Part 1 of Gitea issue #804 only: `tools/install.sh` must reject every ## Acceptance evidence -| Criterion | Evidence | -| --- | --- | -| Unknown input is named on STDERR | Process-level Vitest assertions for `--bogus`, including after `--ref` | -| Short usage hint is printed on STDERR | Vitest usage regex + manual process output | -| Exit is nonzero | Vitest status assertions and manual exit 2 | -| Installation does not proceed | Isolated npm shim marker remains absent | -| Recognized behavior is preserved | Parser cases are unchanged except validation of malformed `--ref`; full Mosaic package suite passed | -| Part 2 is excluded | No `--next`, `MOSAIC_NEXT`, dist-tag, or prerelease routing changes | +| Criterion | Evidence | +| ------------------------------------- | --------------------------------------------------------------------------------------------------- | +| Unknown input is named on STDERR | Process-level Vitest assertions for `--bogus`, including after `--ref` | +| Short usage hint is printed on STDERR | Vitest usage regex + manual process output | +| Exit is nonzero | Vitest status assertions and manual exit 2 | +| Installation does not proceed | Isolated npm shim marker remains absent | +| Recognized behavior is preserved | Parser cases are unchanged except validation of malformed `--ref`; full Mosaic package suite passed | +| Part 2 is excluded | No `--next`, `MOSAIC_NEXT`, dist-tag, or prerelease routing changes | ## Documentation checklist diff --git a/docs/scratchpads/807-glpi-partial-content.md b/docs/_old_structure/scratchpads/807-glpi-partial-content.md similarity index 79% rename from docs/scratchpads/807-glpi-partial-content.md rename to docs/_old_structure/scratchpads/807-glpi-partial-content.md index 492eacac..7cfdc823 100644 --- a/docs/scratchpads/807-glpi-partial-content.md +++ b/docs/_old_structure/scratchpads/807-glpi-partial-content.md @@ -49,11 +49,11 @@ Fix the shipped GLPI ticket, computer, and user list wrappers so ranged response ## Acceptance criteria mapping -| Criterion | Evidence | -| --- | --- | -| HTTP 206 succeeds and renders each ranged list | Focused test's three 206 render assertions pass | -| Genuine HTTP failures remain non-zero with existing diagnostics | Focused test's three HTTP 401 assertions pass | -| Only affected list wrappers change | Diff contains the three status predicates plus focused test/evidence; session and create wrappers untouched | +| Criterion | Evidence | +| --------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | +| HTTP 206 succeeds and renders each ranged list | Focused test's three 206 render assertions pass | +| Genuine HTTP failures remain non-zero with existing diagnostics | Focused test's three HTTP 401 assertions pass | +| Only affected list wrappers change | Diff contains the three status predicates plus focused test/evidence; session and create wrappers untouched | ## Documentation decision diff --git a/docs/scratchpads/808-agent-send-sender-identity.md b/docs/_old_structure/scratchpads/808-agent-send-sender-identity.md similarity index 100% rename from docs/scratchpads/808-agent-send-sender-identity.md rename to docs/_old_structure/scratchpads/808-agent-send-sender-identity.md diff --git a/docs/scratchpads/812-pr-review-comment.md b/docs/_old_structure/scratchpads/812-pr-review-comment.md similarity index 100% rename from docs/scratchpads/812-pr-review-comment.md rename to docs/_old_structure/scratchpads/812-pr-review-comment.md diff --git a/docs/scratchpads/824-mosaic-skill-cli.md b/docs/_old_structure/scratchpads/824-mosaic-skill-cli.md similarity index 85% rename from docs/scratchpads/824-mosaic-skill-cli.md rename to docs/_old_structure/scratchpads/824-mosaic-skill-cli.md index 47be56b3..c67572e8 100644 --- a/docs/scratchpads/824-mosaic-skill-cli.md +++ b/docs/_old_structure/scratchpads/824-mosaic-skill-cli.md @@ -84,15 +84,15 @@ A built-CLI temp-home smoke test (no real `~/.claude` or Mosaic config touched) ### Acceptance mapping -| Acceptance criterion | Evidence | -| --- | --- | -| register/unregister/list, idempotent | `skill.spec.ts` and built-CLI temp-home smoke | -| traversal/symlink-injection protection | invalid-name matrix, foreign file/dir/link tests, symlinked-root tests | -| list flags dangling and foreign entries | deterministic list status test | -| install and upgrade auto-sync every canonical directory | finalize + framework re-seed integration specs; two-skill built-module smoke | +| Acceptance criterion | Evidence | +| ---------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | +| register/unregister/list, idempotent | `skill.spec.ts` and built-CLI temp-home smoke | +| traversal/symlink-injection protection | invalid-name matrix, foreign file/dir/link tests, symlinked-root tests | +| list flags dangling and foreign entries | deterministic list status test | +| install and upgrade auto-sync every canonical directory | finalize + framework re-seed integration specs; two-skill built-module smoke | | newly added skill becomes discoverable without manual link | `added-after-setup` auto-sync creates exact Claude link; Claude can rescan with `/reload-skills` or a new session | -| Pi/Codex parity captured as scope note | user guide, developer guide, installed framework README | -| documentation gate | root README, user guide, developer guide, framework README, sitemap | +| Pi/Codex parity captured as scope note | user guide, developer guide, installed framework README | +| documentation gate | root README, user guide, developer guide, framework README, sitemap | ## Risks diff --git a/docs/scratchpads/828-lease-broker.md b/docs/_old_structure/scratchpads/828-lease-broker.md similarity index 100% rename from docs/scratchpads/828-lease-broker.md rename to docs/_old_structure/scratchpads/828-lease-broker.md diff --git a/docs/scratchpads/829-mutator-gate.md b/docs/_old_structure/scratchpads/829-mutator-gate.md similarity index 91% rename from docs/scratchpads/829-mutator-gate.md rename to docs/_old_structure/scratchpads/829-mutator-gate.md index 2c9c1f35..5ac35a7d 100644 --- a/docs/scratchpads/829-mutator-gate.md +++ b/docs/_old_structure/scratchpads/829-mutator-gate.md @@ -49,13 +49,13 @@ Carried authority chain also verified/read for the locked T-B gate contract: SPE ## Acceptance mapping -| Acceptance criterion | Evidence | -| --- | --- | -| No consequential mutator succeeds while UNVERIFIED after observer revoke or TTL | `observer revocation and monotonic TTL expiry deny the next mutator` real-socket acceptance test | -| T-B compromised-tool bypass is covered by the whole gate | `T-B raw and custom mutator tools are default-denied without shell parsing` across Claude/Pi built-ins, raw Bash class, MCP/custom/unknown tools | -| Revoke-first / promote-last is structural | `revoke-first and promote-last structurally bracket mutator authority`; direct promotion rejected, pending remains denied, token consumption commits before VERIFIED | -| Consume WI-1 auth/lease substrate | All transitions and decisions traverse merged peercred/ancestry authentication; promotion consumes the exact WI-1 CSPRNG cycle token | -| M1 Claude + Pi | Claude `.*` PreToolUse and Pi `tool_call` invoke the same broker gate; register-before-exec test proves broker-minted parent identity reaches runtime descendants | +| Acceptance criterion | Evidence | +| ------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| No consequential mutator succeeds while UNVERIFIED after observer revoke or TTL | `observer revocation and monotonic TTL expiry deny the next mutator` real-socket acceptance test | +| T-B compromised-tool bypass is covered by the whole gate | `T-B raw and custom mutator tools are default-denied without shell parsing` across Claude/Pi built-ins, raw Bash class, MCP/custom/unknown tools | +| Revoke-first / promote-last is structural | `revoke-first and promote-last structurally bracket mutator authority`; direct promotion rejected, pending remains denied, token consumption commits before VERIFIED | +| Consume WI-1 auth/lease substrate | All transitions and decisions traverse merged peercred/ancestry authentication; promotion consumes the exact WI-1 CSPRNG cycle token | +| M1 Claude + Pi | Claude `.*` PreToolUse and Pi `tool_call` invoke the same broker gate; register-before-exec test proves broker-minted parent identity reaches runtime descendants | ## Locked discipline diff --git a/docs/scratchpads/830-compaction-revoke.md b/docs/_old_structure/scratchpads/830-compaction-revoke.md similarity index 100% rename from docs/scratchpads/830-compaction-revoke.md rename to docs/_old_structure/scratchpads/830-compaction-revoke.md diff --git a/docs/scratchpads/832-receipt-challenge-protocol.md b/docs/_old_structure/scratchpads/832-receipt-challenge-protocol.md similarity index 100% rename from docs/scratchpads/832-receipt-challenge-protocol.md rename to docs/_old_structure/scratchpads/832-receipt-challenge-protocol.md diff --git a/docs/scratchpads/833-constrained-recovery-command.md b/docs/_old_structure/scratchpads/833-constrained-recovery-command.md similarity index 100% rename from docs/scratchpads/833-constrained-recovery-command.md rename to docs/_old_structure/scratchpads/833-constrained-recovery-command.md diff --git a/docs/scratchpads/838-broker-acceptance-flake.md b/docs/_old_structure/scratchpads/838-broker-acceptance-flake.md similarity index 100% rename from docs/scratchpads/838-broker-acceptance-flake.md rename to docs/_old_structure/scratchpads/838-broker-acceptance-flake.md diff --git a/docs/scratchpads/B1-next-durable-publish-design.md b/docs/_old_structure/scratchpads/B1-next-durable-publish-design.md similarity index 100% rename from docs/scratchpads/B1-next-durable-publish-design.md rename to docs/_old_structure/scratchpads/B1-next-durable-publish-design.md diff --git a/docs/scratchpads/B2-skills-sync-path.md b/docs/_old_structure/scratchpads/B2-skills-sync-path.md similarity index 100% rename from docs/scratchpads/B2-skills-sync-path.md rename to docs/_old_structure/scratchpads/B2-skills-sync-path.md diff --git a/docs/scratchpads/B3-wizard-gateway-health-order.md b/docs/_old_structure/scratchpads/B3-wizard-gateway-health-order.md similarity index 100% rename from docs/scratchpads/B3-wizard-gateway-health-order.md rename to docs/_old_structure/scratchpads/B3-wizard-gateway-health-order.md diff --git a/docs/scratchpads/B4-wizard-step-dedup.md b/docs/_old_structure/scratchpads/B4-wizard-step-dedup.md similarity index 100% rename from docs/scratchpads/B4-wizard-step-dedup.md rename to docs/_old_structure/scratchpads/B4-wizard-step-dedup.md diff --git a/docs/scratchpads/BUG-CLI-scratchpad.md b/docs/_old_structure/scratchpads/BUG-CLI-scratchpad.md similarity index 100% rename from docs/scratchpads/BUG-CLI-scratchpad.md rename to docs/_old_structure/scratchpads/BUG-CLI-scratchpad.md diff --git a/docs/scratchpads/FED-M3-05-list-verb.md b/docs/_old_structure/scratchpads/FED-M3-05-list-verb.md similarity index 100% rename from docs/scratchpads/FED-M3-05-list-verb.md rename to docs/_old_structure/scratchpads/FED-M3-05-list-verb.md diff --git a/docs/scratchpads/FED-M3-07-capabilities.md b/docs/_old_structure/scratchpads/FED-M3-07-capabilities.md similarity index 100% rename from docs/scratchpads/FED-M3-07-capabilities.md rename to docs/_old_structure/scratchpads/FED-M3-07-capabilities.md diff --git a/docs/scratchpads/FED-M3-09-query-source.md b/docs/_old_structure/scratchpads/FED-M3-09-query-source.md similarity index 100% rename from docs/scratchpads/FED-M3-09-query-source.md rename to docs/_old_structure/scratchpads/FED-M3-09-query-source.md diff --git a/docs/scratchpads/FED-M3-10-integration-tests.md b/docs/_old_structure/scratchpads/FED-M3-10-integration-tests.md similarity index 100% rename from docs/scratchpads/FED-M3-10-integration-tests.md rename to docs/_old_structure/scratchpads/FED-M3-10-integration-tests.md diff --git a/docs/scratchpads/bug-196-admin-redirect.md b/docs/_old_structure/scratchpads/bug-196-admin-redirect.md similarity index 100% rename from docs/scratchpads/bug-196-admin-redirect.md rename to docs/_old_structure/scratchpads/bug-196-admin-redirect.md diff --git a/docs/scratchpads/ci-docker-publish-20260330.md b/docs/_old_structure/scratchpads/ci-docker-publish-20260330.md similarity index 100% rename from docs/scratchpads/ci-docker-publish-20260330.md rename to docs/_old_structure/scratchpads/ci-docker-publish-20260330.md diff --git a/docs/scratchpads/cli-unification-20260404.md b/docs/_old_structure/scratchpads/cli-unification-20260404.md similarity index 100% rename from docs/scratchpads/cli-unification-20260404.md rename to docs/_old_structure/scratchpads/cli-unification-20260404.md diff --git a/docs/scratchpads/f3-m3-update-reseed.md b/docs/_old_structure/scratchpads/f3-m3-update-reseed.md similarity index 100% rename from docs/scratchpads/f3-m3-update-reseed.md rename to docs/_old_structure/scratchpads/f3-m3-update-reseed.md diff --git a/docs/scratchpads/f4-matrix-connector.md b/docs/_old_structure/scratchpads/f4-matrix-connector.md similarity index 100% rename from docs/scratchpads/f4-matrix-connector.md rename to docs/_old_structure/scratchpads/f4-matrix-connector.md diff --git a/docs/scratchpads/fcm-m2-001-generated-env-boundary.md b/docs/_old_structure/scratchpads/fcm-m2-001-generated-env-boundary.md similarity index 100% rename from docs/scratchpads/fcm-m2-001-generated-env-boundary.md rename to docs/_old_structure/scratchpads/fcm-m2-001-generated-env-boundary.md diff --git a/docs/scratchpads/fcm-m5-001-fleet-config-operator-docs.md b/docs/_old_structure/scratchpads/fcm-m5-001-fleet-config-operator-docs.md similarity index 100% rename from docs/scratchpads/fcm-m5-001-fleet-config-operator-docs.md rename to docs/_old_structure/scratchpads/fcm-m5-001-fleet-config-operator-docs.md diff --git a/docs/scratchpads/fix-ci-migrations-20260330.md b/docs/_old_structure/scratchpads/fix-ci-migrations-20260330.md similarity index 100% rename from docs/scratchpads/fix-ci-migrations-20260330.md rename to docs/_old_structure/scratchpads/fix-ci-migrations-20260330.md diff --git a/docs/scratchpads/fix-turbo-env-passthrough.md b/docs/_old_structure/scratchpads/fix-turbo-env-passthrough.md similarity index 100% rename from docs/scratchpads/fix-turbo-env-passthrough.md rename to docs/_old_structure/scratchpads/fix-turbo-env-passthrough.md diff --git a/docs/scratchpads/fleet-cli-local-canary-review-fixes.md b/docs/_old_structure/scratchpads/fleet-cli-local-canary-review-fixes.md similarity index 100% rename from docs/scratchpads/fleet-cli-local-canary-review-fixes.md rename to docs/_old_structure/scratchpads/fleet-cli-local-canary-review-fixes.md diff --git a/docs/scratchpads/fleet-comms-onboarding.md b/docs/_old_structure/scratchpads/fleet-comms-onboarding.md similarity index 100% rename from docs/scratchpads/fleet-comms-onboarding.md rename to docs/_old_structure/scratchpads/fleet-comms-onboarding.md diff --git a/docs/scratchpads/fleet-enhancer-floor.md b/docs/_old_structure/scratchpads/fleet-enhancer-floor.md similarity index 100% rename from docs/scratchpads/fleet-enhancer-floor.md rename to docs/_old_structure/scratchpads/fleet-enhancer-floor.md diff --git a/docs/scratchpads/fleet-observability-phase2.md b/docs/_old_structure/scratchpads/fleet-observability-phase2.md similarity index 100% rename from docs/scratchpads/fleet-observability-phase2.md rename to docs/_old_structure/scratchpads/fleet-observability-phase2.md diff --git a/docs/scratchpads/fleet-polish-bundle.md b/docs/_old_structure/scratchpads/fleet-polish-bundle.md similarity index 100% rename from docs/scratchpads/fleet-polish-bundle.md rename to docs/_old_structure/scratchpads/fleet-polish-bundle.md diff --git a/docs/scratchpads/fleet-standup-fixes.md b/docs/_old_structure/scratchpads/fleet-standup-fixes.md similarity index 100% rename from docs/scratchpads/fleet-standup-fixes.md rename to docs/_old_structure/scratchpads/fleet-standup-fixes.md diff --git a/docs/scratchpads/gateway-install-ux-20260404.md b/docs/_old_structure/scratchpads/gateway-install-ux-20260404.md similarity index 100% rename from docs/scratchpads/gateway-install-ux-20260404.md rename to docs/_old_structure/scratchpads/gateway-install-ux-20260404.md diff --git a/docs/scratchpads/gateway-security-20260313.md b/docs/_old_structure/scratchpads/gateway-security-20260313.md similarity index 100% rename from docs/scratchpads/gateway-security-20260313.md rename to docs/_old_structure/scratchpads/gateway-security-20260313.md diff --git a/docs/scratchpads/git-wrapper-rollup-20260526.md b/docs/_old_structure/scratchpads/git-wrapper-rollup-20260526.md similarity index 100% rename from docs/scratchpads/git-wrapper-rollup-20260526.md rename to docs/_old_structure/scratchpads/git-wrapper-rollup-20260526.md diff --git a/docs/scratchpads/h1-heartbeat-readiness.md b/docs/_old_structure/scratchpads/h1-heartbeat-readiness.md similarity index 100% rename from docs/scratchpads/h1-heartbeat-readiness.md rename to docs/_old_structure/scratchpads/h1-heartbeat-readiness.md diff --git a/docs/scratchpads/h1b-pane-idle-signal.md b/docs/_old_structure/scratchpads/h1b-pane-idle-signal.md similarity index 100% rename from docs/scratchpads/h1b-pane-idle-signal.md rename to docs/_old_structure/scratchpads/h1b-pane-idle-signal.md diff --git a/docs/scratchpads/h2-readiness-available.md b/docs/_old_structure/scratchpads/h2-readiness-available.md similarity index 100% rename from docs/scratchpads/h2-readiness-available.md rename to docs/_old_structure/scratchpads/h2-readiness-available.md diff --git a/docs/scratchpads/harness-20260321.md b/docs/_old_structure/scratchpads/harness-20260321.md similarity index 100% rename from docs/scratchpads/harness-20260321.md rename to docs/_old_structure/scratchpads/harness-20260321.md diff --git a/docs/scratchpads/install-ux-hardening-20260405.md b/docs/_old_structure/scratchpads/install-ux-hardening-20260405.md similarity index 100% rename from docs/scratchpads/install-ux-hardening-20260405.md rename to docs/_old_structure/scratchpads/install-ux-hardening-20260405.md diff --git a/docs/scratchpads/installer-next-fast-npm-20260625.md b/docs/_old_structure/scratchpads/installer-next-fast-npm-20260625.md similarity index 100% rename from docs/scratchpads/installer-next-fast-npm-20260625.md rename to docs/_old_structure/scratchpads/installer-next-fast-npm-20260625.md diff --git a/docs/scratchpads/installer-next-lane-20260624.md b/docs/_old_structure/scratchpads/installer-next-lane-20260624.md similarity index 100% rename from docs/scratchpads/installer-next-lane-20260624.md rename to docs/_old_structure/scratchpads/installer-next-lane-20260624.md diff --git a/docs/scratchpads/issue-766-exact-fleet-comms.md b/docs/_old_structure/scratchpads/issue-766-exact-fleet-comms.md similarity index 100% rename from docs/scratchpads/issue-766-exact-fleet-comms.md rename to docs/_old_structure/scratchpads/issue-766-exact-fleet-comms.md diff --git a/docs/scratchpads/m3-001-provider-adapter.md b/docs/_old_structure/scratchpads/m3-001-provider-adapter.md similarity index 100% rename from docs/scratchpads/m3-001-provider-adapter.md rename to docs/_old_structure/scratchpads/m3-001-provider-adapter.md diff --git a/docs/scratchpads/macp-oc-bridge-20260330.md b/docs/_old_structure/scratchpads/macp-oc-bridge-20260330.md similarity index 100% rename from docs/scratchpads/macp-oc-bridge-20260330.md rename to docs/_old_structure/scratchpads/macp-oc-bridge-20260330.md diff --git a/docs/scratchpads/ms-792-fleet-enoent-installer.md b/docs/_old_structure/scratchpads/ms-792-fleet-enoent-installer.md similarity index 100% rename from docs/scratchpads/ms-792-fleet-enoent-installer.md rename to docs/_old_structure/scratchpads/ms-792-fleet-enoent-installer.md diff --git a/docs/scratchpads/mvp-20260312.md b/docs/_old_structure/scratchpads/mvp-20260312.md similarity index 100% rename from docs/scratchpads/mvp-20260312.md rename to docs/_old_structure/scratchpads/mvp-20260312.md diff --git a/docs/scratchpads/north-star-doctrine.md b/docs/_old_structure/scratchpads/north-star-doctrine.md similarity index 100% rename from docs/scratchpads/north-star-doctrine.md rename to docs/_old_structure/scratchpads/north-star-doctrine.md diff --git a/docs/scratchpads/p5-003-telegram-plugin.md b/docs/_old_structure/scratchpads/p5-003-telegram-plugin.md similarity index 100% rename from docs/scratchpads/p5-003-telegram-plugin.md rename to docs/_old_structure/scratchpads/p5-003-telegram-plugin.md diff --git a/docs/scratchpads/p5-004-authentik-sso.md b/docs/_old_structure/scratchpads/p5-004-authentik-sso.md similarity index 100% rename from docs/scratchpads/p5-004-authentik-sso.md rename to docs/_old_structure/scratchpads/p5-004-authentik-sso.md diff --git a/docs/scratchpads/p5-overlay-composer.md b/docs/_old_structure/scratchpads/p5-overlay-composer.md similarity index 100% rename from docs/scratchpads/p5-overlay-composer.md rename to docs/_old_structure/scratchpads/p5-overlay-composer.md diff --git a/docs/scratchpads/p6-docs-compliance-alpha.md b/docs/_old_structure/scratchpads/p6-docs-compliance-alpha.md similarity index 100% rename from docs/scratchpads/p6-docs-compliance-alpha.md rename to docs/_old_structure/scratchpads/p6-docs-compliance-alpha.md diff --git a/docs/scratchpads/p8-001-sso-providers.md b/docs/_old_structure/scratchpads/p8-001-sso-providers.md similarity index 100% rename from docs/scratchpads/p8-001-sso-providers.md rename to docs/_old_structure/scratchpads/p8-001-sso-providers.md diff --git a/docs/scratchpads/p8-009-tui-slash-commands.md b/docs/_old_structure/scratchpads/p8-009-tui-slash-commands.md similarity index 100% rename from docs/scratchpads/p8-009-tui-slash-commands.md rename to docs/_old_structure/scratchpads/p8-009-tui-slash-commands.md diff --git a/docs/scratchpads/p8-010-command-registry.md b/docs/_old_structure/scratchpads/p8-010-command-registry.md similarity index 100% rename from docs/scratchpads/p8-010-command-registry.md rename to docs/_old_structure/scratchpads/p8-010-command-registry.md diff --git a/docs/scratchpads/p8-012-agent-provider-commands.md b/docs/_old_structure/scratchpads/p8-012-agent-provider-commands.md similarity index 100% rename from docs/scratchpads/p8-012-agent-provider-commands.md rename to docs/_old_structure/scratchpads/p8-012-agent-provider-commands.md diff --git a/docs/scratchpads/p8-016-tool-hardening.md b/docs/_old_structure/scratchpads/p8-016-tool-hardening.md similarity index 100% rename from docs/scratchpads/p8-016-tool-hardening.md rename to docs/_old_structure/scratchpads/p8-016-tool-hardening.md diff --git a/docs/scratchpads/p8-019-verify.md b/docs/_old_structure/scratchpads/p8-019-verify.md similarity index 100% rename from docs/scratchpads/p8-019-verify.md rename to docs/_old_structure/scratchpads/p8-019-verify.md diff --git a/docs/scratchpads/rm-01-reproducible-checkout.md b/docs/_old_structure/scratchpads/rm-01-reproducible-checkout.md similarity index 100% rename from docs/scratchpads/rm-01-reproducible-checkout.md rename to docs/_old_structure/scratchpads/rm-01-reproducible-checkout.md diff --git a/docs/scratchpads/rm-03-queue-guard.md b/docs/_old_structure/scratchpads/rm-03-queue-guard.md similarity index 88% rename from docs/scratchpads/rm-03-queue-guard.md rename to docs/_old_structure/scratchpads/rm-03-queue-guard.md index f2cc3d8c..2df9123f 100644 --- a/docs/scratchpads/rm-03-queue-guard.md +++ b/docs/_old_structure/scratchpads/rm-03-queue-guard.md @@ -30,19 +30,19 @@ Repair the mandatory CI queue guard so it reads provider payloads, blocks assert ## Test matrix -| Case | Required outcome | -| --- | --- | -| success | exit 0; terminal-success | -| pending | nonzero after bounded timeout | -| failure | nonzero | -| no-status | nonzero | -| malformed | nonzero | -| >=150 KiB payload | unchanged classification; never rc126 | -| provider unreachable on push | loud audited CANNOT_ASSERT; degraded exit 0 | -| provider unreachable on merge | loud audited CANNOT_ASSERT; retryable exit 75/HOLD | -| audit unavailable | nonzero | -| implicit push branch | provider URL uses checked-out feature branch | -| merge wrapper | queue guard receives exact PR head branch/repository/full SHA | +| Case | Required outcome | +| ----------------------------- | ------------------------------------------------------------- | +| success | exit 0; terminal-success | +| pending | nonzero after bounded timeout | +| failure | nonzero | +| no-status | nonzero | +| malformed | nonzero | +| >=150 KiB payload | unchanged classification; never rc126 | +| provider unreachable on push | loud audited CANNOT_ASSERT; degraded exit 0 | +| provider unreachable on merge | loud audited CANNOT_ASSERT; retryable exit 75/HOLD | +| audit unavailable | nonzero | +| implicit push branch | provider URL uses checked-out feature branch | +| merge wrapper | queue guard receives exact PR head branch/repository/full SHA | ## RED-first evidence diff --git a/docs/scratchpads/t-a292e96f-gitea-pr-metadata.md b/docs/_old_structure/scratchpads/t-a292e96f-gitea-pr-metadata.md similarity index 100% rename from docs/scratchpads/t-a292e96f-gitea-pr-metadata.md rename to docs/_old_structure/scratchpads/t-a292e96f-gitea-pr-metadata.md diff --git a/docs/scratchpads/t_301e4e3b-pr-merge-gitea-empty-uid.md b/docs/_old_structure/scratchpads/t_301e4e3b-pr-merge-gitea-empty-uid.md similarity index 100% rename from docs/scratchpads/t_301e4e3b-pr-merge-gitea-empty-uid.md rename to docs/_old_structure/scratchpads/t_301e4e3b-pr-merge-gitea-empty-uid.md diff --git a/docs/scratchpads/t_5aab9cc8-pr-merge-eval-injection.md b/docs/_old_structure/scratchpads/t_5aab9cc8-pr-merge-eval-injection.md similarity index 100% rename from docs/scratchpads/t_5aab9cc8-pr-merge-eval-injection.md rename to docs/_old_structure/scratchpads/t_5aab9cc8-pr-merge-eval-injection.md diff --git a/docs/scratchpads/task-mission-ownership-20260313.md b/docs/_old_structure/scratchpads/task-mission-ownership-20260313.md similarity index 100% rename from docs/scratchpads/task-mission-ownership-20260313.md rename to docs/_old_structure/scratchpads/task-mission-ownership-20260313.md diff --git a/docs/scratchpads/tess-20260712.md b/docs/_old_structure/scratchpads/tess-20260712.md similarity index 99% rename from docs/scratchpads/tess-20260712.md rename to docs/_old_structure/scratchpads/tess-20260712.md index 5f21ca9f..56b62ed0 100644 --- a/docs/scratchpads/tess-20260712.md +++ b/docs/_old_structure/scratchpads/tess-20260712.md @@ -9,6 +9,7 @@ **Budget:** No explicit cap provided. Original working estimate was 290K implementation/review tokens. That estimate is superseded after six security prerequisite tasks were added; revised arithmetic total is pending because the calculation tool was blocked by runtime consent. Run at most two workers; prefer one implementation lane plus one independent review/discovery lane. Re-estimate after planning approval and each milestone. **Evidence gathered:** + - Mosaic already provides Pi lifecycle hooks, fleet/tmux sessions, Matrix connector/controller pieces, typed chat events, Discord/Telegram channel plugins, and command/plugin registries. - Current `IProviderAdapter` is an LLM model/completion abstraction, not an external agent/session provider. - Required new seam is `AgentRuntimeProvider`: sessions, stream, message, terminate, hierarchy, attach, health, capabilities. @@ -16,6 +17,7 @@ - Project truth must remain in canonical project/Mosaic stores; semantic memory is retrieval/mirror. **Decisions:** + 1. Name: Tess (tessera). Stable machine key `tess`; display name configurable. 2. Mos owns orchestration; Tess delegates Mos-owned work through an explicit coordination contract. 3. Gateway owns ingress/auth/routing; Discord and CLI remain thin clients. @@ -24,6 +26,7 @@ 6. No unrestricted Discord shell. Privileged/destructive/customer-visible actions require authorization and approval. **Plan:** + 1. Land requirements/architecture/task graph. 2. Deliver runtime contracts and security model. 3. Deliver durable Pi service/state. @@ -42,6 +45,7 @@ **Blocking findings:** formal threat model absent; verification matrix absent; migration inventory implied but absent; non-existent task paths; AC-TESS-03 lacked a crisp test. Security review also identified command scope bypass, cross-tenant session attachment, MCP actor impersonation, unsafe Discord service ingress, pre-persistence/egress secret leakage, non-durable replay, and globally scoped GC. **Remediation applied:** + - Added `docs/tess/ARCHITECTURE.md`. - Added `docs/tess/THREAT-MODEL.md` with TM-01..12. - Added `docs/tess/VERIFICATION-MATRIX.md` mapping AC-TESS-01..11. diff --git a/docs/scratchpads/tess-m1-002-provider-registry.md b/docs/_old_structure/scratchpads/tess-m1-002-provider-registry.md similarity index 100% rename from docs/scratchpads/tess-m1-002-provider-registry.md rename to docs/_old_structure/scratchpads/tess-m1-002-provider-registry.md diff --git a/docs/scratchpads/tess-m1-003-fleet-provider.md b/docs/_old_structure/scratchpads/tess-m1-003-fleet-provider.md similarity index 74% rename from docs/scratchpads/tess-m1-003-fleet-provider.md rename to docs/_old_structure/scratchpads/tess-m1-003-fleet-provider.md index 25dae597..9967438f 100644 --- a/docs/scratchpads/tess-m1-003-fleet-provider.md +++ b/docs/_old_structure/scratchpads/tess-m1-003-fleet-provider.md @@ -59,15 +59,15 @@ The orchestrator corrected the initial brief: `feat/tess-interaction-agent` is a ## Acceptance Criteria to Evidence -| Acceptance criterion | Evidence target | -| --- | --- | -| Only roster-bound exact targets are operated | Provider abuse tests prove unknown/prefix targets yield typed denial and runner is untouched. | -| Socket and peer runtime identity are exact | Provider abuse tests prove wrong socket/no pane/runtime drift deny before send/attach/terminate. | -| Message sends are capability-safe and exact | Tests assert the maintained sender receives only the configured socket and exact roster session. | -| Fleet reads cannot cross an authority boundary | Tests prove list and read attach default-deny without a scope-aware read authority; per-target authority filtering is enforced. | -| Attach cannot grant control or replay across scope | Tests deny `control`; attachment handles are random, scoped, short-lived, single-use for detach, and pruned after expiry. | +| Acceptance criterion | Evidence target | +| -------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | +| Only roster-bound exact targets are operated | Provider abuse tests prove unknown/prefix targets yield typed denial and runner is untouched. | +| Socket and peer runtime identity are exact | Provider abuse tests prove wrong socket/no pane/runtime drift deny before send/attach/terminate. | +| Message sends are capability-safe and exact | Tests assert the maintained sender receives only the configured socket and exact roster session. | +| Fleet reads cannot cross an authority boundary | Tests prove list and read attach default-deny without a scope-aware read authority; per-target authority filtering is enforced. | +| Attach cannot grant control or replay across scope | Tests deny `control`; attachment handles are random, scoped, short-lived, single-use for detach, and pruned after expiry. | | Termination is exact and caller cannot select arbitrary target | Tests assert roster/identity validation precedes exact `tmux kill-session -t =`. Gateway tests from M1-002 cover approval consumption. | -| Documentation describes the boundary | `docs/tess/ARCHITECTURE.md` documents fleet capability, scope, and non-goals. | +| Documentation describes the boundary | `docs/tess/ARCHITECTURE.md` documents fleet capability, scope, and non-goals. | ## Risks / Decisions diff --git a/docs/scratchpads/tess-m1-obs-001.md b/docs/_old_structure/scratchpads/tess-m1-obs-001.md similarity index 100% rename from docs/scratchpads/tess-m1-obs-001.md rename to docs/_old_structure/scratchpads/tess-m1-obs-001.md diff --git a/docs/scratchpads/tess-m1-sec-001.md b/docs/_old_structure/scratchpads/tess-m1-sec-001.md similarity index 100% rename from docs/scratchpads/tess-m1-sec-001.md rename to docs/_old_structure/scratchpads/tess-m1-sec-001.md diff --git a/docs/scratchpads/tess-m1-sec-004-discord-ingress.md b/docs/_old_structure/scratchpads/tess-m1-sec-004-discord-ingress.md similarity index 100% rename from docs/scratchpads/tess-m1-sec-004-discord-ingress.md rename to docs/_old_structure/scratchpads/tess-m1-sec-004-discord-ingress.md diff --git a/docs/scratchpads/tess-m1-sec-006-session-gc-scope.md b/docs/_old_structure/scratchpads/tess-m1-sec-006-session-gc-scope.md similarity index 100% rename from docs/scratchpads/tess-m1-sec-006-session-gc-scope.md rename to docs/_old_structure/scratchpads/tess-m1-sec-006-session-gc-scope.md diff --git a/docs/scratchpads/tess-m2-001-pi-service.md b/docs/_old_structure/scratchpads/tess-m2-001-pi-service.md similarity index 100% rename from docs/scratchpads/tess-m2-001-pi-service.md rename to docs/_old_structure/scratchpads/tess-m2-001-pi-service.md diff --git a/docs/scratchpads/tess-m2-002-durable-state.md b/docs/_old_structure/scratchpads/tess-m2-002-durable-state.md similarity index 76% rename from docs/scratchpads/tess-m2-002-durable-state.md rename to docs/_old_structure/scratchpads/tess-m2-002-durable-state.md index c2e3b809..f47fc4d8 100644 --- a/docs/scratchpads/tess-m2-002-durable-state.md +++ b/docs/_old_structure/scratchpads/tess-m2-002-durable-state.md @@ -25,13 +25,13 @@ restart or context compaction without replaying a completed message or applied s ## Required Evidence -| Requirement | Primary evidence | -| --- | --- | -| Restart recovery | Test creates a second coordinator over unchanged durable store after simulated process death. | -| No duplicate side effects | Duplicate ingress and post-restart dispatch assert one handler/effect invocation. | -| Compaction survival | Checkpoint/handoff/reconstructed state preserve the same session identity and pending records. | -| Durable approvals | Existing `tess:command-approval` record is consumed only once and survives a new authorization service instance. | -| Handoff | Stored handoff is portable and reconstructed without live process state. | +| Requirement | Primary evidence | +| ------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| Restart recovery | Test creates a second coordinator over unchanged durable store after simulated process death. | +| No duplicate side effects | Duplicate ingress and post-restart dispatch assert one handler/effect invocation. | +| Compaction survival | Checkpoint/handoff/reconstructed state preserve the same session identity and pending records. | +| Durable approvals | Existing `tess:command-approval` record is consumed only once and survives a new authorization service instance. | +| Handoff | Stored handoff is portable and reconstructed without live process state. | ## Progress diff --git a/docs/scratchpads/tess-m4-001-mos-coordination.md b/docs/_old_structure/scratchpads/tess-m4-001-mos-coordination.md similarity index 100% rename from docs/scratchpads/tess-m4-001-mos-coordination.md rename to docs/_old_structure/scratchpads/tess-m4-001-mos-coordination.md diff --git a/docs/scratchpads/tess-m4-003-operator-plugins.md b/docs/_old_structure/scratchpads/tess-m4-003-operator-plugins.md similarity index 100% rename from docs/scratchpads/tess-m4-003-operator-plugins.md rename to docs/_old_structure/scratchpads/tess-m4-003-operator-plugins.md diff --git a/docs/scratchpads/tools-md-seeding-20260411.md b/docs/_old_structure/scratchpads/tools-md-seeding-20260411.md similarity index 100% rename from docs/scratchpads/tools-md-seeding-20260411.md rename to docs/_old_structure/scratchpads/tools-md-seeding-20260411.md diff --git a/docs/scratchpads/update-checker-package-20260404.md b/docs/_old_structure/scratchpads/update-checker-package-20260404.md similarity index 100% rename from docs/scratchpads/update-checker-package-20260404.md rename to docs/_old_structure/scratchpads/update-checker-package-20260404.md diff --git a/docs/scratchpads/webui-fleet-bridge-plan.md b/docs/_old_structure/scratchpads/webui-fleet-bridge-plan.md similarity index 100% rename from docs/scratchpads/webui-fleet-bridge-plan.md rename to docs/_old_structure/scratchpads/webui-fleet-bridge-plan.md diff --git a/docs/scratchpads/webui-p2-data-auth.md b/docs/_old_structure/scratchpads/webui-p2-data-auth.md similarity index 100% rename from docs/scratchpads/webui-p2-data-auth.md rename to docs/_old_structure/scratchpads/webui-p2-data-auth.md diff --git a/docs/scratchpads/yolo-runtime-initial-arg-20260411.md b/docs/_old_structure/scratchpads/yolo-runtime-initial-arg-20260411.md similarity index 100% rename from docs/scratchpads/yolo-runtime-initial-arg-20260411.md rename to docs/_old_structure/scratchpads/yolo-runtime-initial-arg-20260411.md diff --git a/docs/tasks/544-agent-reflection-loop.md b/docs/_old_structure/tasks/544-agent-reflection-loop.md similarity index 100% rename from docs/tasks/544-agent-reflection-loop.md rename to docs/_old_structure/tasks/544-agent-reflection-loop.md diff --git a/docs/tasks/WP1-forge-package.md b/docs/_old_structure/tasks/WP1-forge-package.md similarity index 100% rename from docs/tasks/WP1-forge-package.md rename to docs/_old_structure/tasks/WP1-forge-package.md diff --git a/docs/tasks/WP2-macp-package.md b/docs/_old_structure/tasks/WP2-macp-package.md similarity index 100% rename from docs/tasks/WP2-macp-package.md rename to docs/_old_structure/tasks/WP2-macp-package.md diff --git a/docs/tasks/WP3-mosaic-framework-plugin.md b/docs/_old_structure/tasks/WP3-mosaic-framework-plugin.md similarity index 100% rename from docs/tasks/WP3-mosaic-framework-plugin.md rename to docs/_old_structure/tasks/WP3-mosaic-framework-plugin.md diff --git a/docs/tess/ADMIN-GUIDE.md b/docs/_old_structure/tess/ADMIN-GUIDE.md similarity index 100% rename from docs/tess/ADMIN-GUIDE.md rename to docs/_old_structure/tess/ADMIN-GUIDE.md diff --git a/docs/tess/ARCHITECTURE.md b/docs/_old_structure/tess/ARCHITECTURE.md similarity index 100% rename from docs/tess/ARCHITECTURE.md rename to docs/_old_structure/tess/ARCHITECTURE.md diff --git a/docs/tess/DEVELOPER-GUIDE.md b/docs/_old_structure/tess/DEVELOPER-GUIDE.md similarity index 100% rename from docs/tess/DEVELOPER-GUIDE.md rename to docs/_old_structure/tess/DEVELOPER-GUIDE.md diff --git a/docs/tess/M4-003-OPERATOR-PLUGIN-SKETCH.md b/docs/_old_structure/tess/M4-003-OPERATOR-PLUGIN-SKETCH.md similarity index 100% rename from docs/tess/M4-003-OPERATOR-PLUGIN-SKETCH.md rename to docs/_old_structure/tess/M4-003-OPERATOR-PLUGIN-SKETCH.md diff --git a/docs/tess/M5-003-DOCUMENTATION-CHECKLIST.md b/docs/_old_structure/tess/M5-003-DOCUMENTATION-CHECKLIST.md similarity index 100% rename from docs/tess/M5-003-DOCUMENTATION-CHECKLIST.md rename to docs/_old_structure/tess/M5-003-DOCUMENTATION-CHECKLIST.md diff --git a/docs/tess/M5-MIGRATION-CUTOVER.md b/docs/_old_structure/tess/M5-MIGRATION-CUTOVER.md similarity index 100% rename from docs/tess/M5-MIGRATION-CUTOVER.md rename to docs/_old_structure/tess/M5-MIGRATION-CUTOVER.md diff --git a/docs/tess/M5-MIGRATION-INVENTORY.md b/docs/_old_structure/tess/M5-MIGRATION-INVENTORY.md similarity index 100% rename from docs/tess/M5-MIGRATION-INVENTORY.md rename to docs/_old_structure/tess/M5-MIGRATION-INVENTORY.md diff --git a/docs/tess/M5-MIGRATION-RETENTION-DEPRECATION.md b/docs/_old_structure/tess/M5-MIGRATION-RETENTION-DEPRECATION.md similarity index 100% rename from docs/tess/M5-MIGRATION-RETENTION-DEPRECATION.md rename to docs/_old_structure/tess/M5-MIGRATION-RETENTION-DEPRECATION.md diff --git a/docs/tess/M5-MIGRATION-ROLLBACK.md b/docs/_old_structure/tess/M5-MIGRATION-ROLLBACK.md similarity index 100% rename from docs/tess/M5-MIGRATION-ROLLBACK.md rename to docs/_old_structure/tess/M5-MIGRATION-ROLLBACK.md diff --git a/docs/tess/MIGRATION-INVENTORY.md b/docs/_old_structure/tess/MIGRATION-INVENTORY.md similarity index 100% rename from docs/tess/MIGRATION-INVENTORY.md rename to docs/_old_structure/tess/MIGRATION-INVENTORY.md diff --git a/docs/tess/MISSION-MANIFEST.md b/docs/_old_structure/tess/MISSION-MANIFEST.md similarity index 100% rename from docs/tess/MISSION-MANIFEST.md rename to docs/_old_structure/tess/MISSION-MANIFEST.md diff --git a/docs/tess/MOS-COORDINATION.md b/docs/_old_structure/tess/MOS-COORDINATION.md similarity index 100% rename from docs/tess/MOS-COORDINATION.md rename to docs/_old_structure/tess/MOS-COORDINATION.md diff --git a/docs/tess/OPERATIONS-GUIDE.md b/docs/_old_structure/tess/OPERATIONS-GUIDE.md similarity index 100% rename from docs/tess/OPERATIONS-GUIDE.md rename to docs/_old_structure/tess/OPERATIONS-GUIDE.md diff --git a/docs/tess/PLUGIN-GUIDE.md b/docs/_old_structure/tess/PLUGIN-GUIDE.md similarity index 100% rename from docs/tess/PLUGIN-GUIDE.md rename to docs/_old_structure/tess/PLUGIN-GUIDE.md diff --git a/docs/_old_structure/tess/TASKS.md b/docs/_old_structure/tess/TASKS.md new file mode 100644 index 00000000..970529e0 --- /dev/null +++ b/docs/_old_structure/tess/TASKS.md @@ -0,0 +1,46 @@ +# Tasks — Tess Interaction Agent + +> Mission: `tess-20260712` · Issue: #706 · PRD requirements: `TESS-*` +> Orchestrator is sole writer. Workers must not modify this file. +> `repo` contains one or more comma-separated repository-relative roots; every listed root must exist before dispatch. +> **BASE CONVENTION (Mos-locked 2026-07-12):** EVERY M1 dispatch targets `base=main` and branches from fresh `origin/main`. Do NOT base on `feat/tess-interaction-agent` — that is the STALE planning branch (merged via #712); basing on it yields `mergeable=False` + intervening-commit noise (cf. #723/SEC-005 re-base). Every dispatch brief must state base=main + branch-from-origin/main. + +| id | status | description | issue | agent | repo | branch | depends_on | estimate | notes | +| --------------- | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- | ----------------- | ---------------------------------------------------------------------------- | ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| TESS-PLAN-001 | done | Finalize PRD, architecture, authority boundary, threat model, migration inventory, and verification matrix | #706 | sonnet | docs, packages/types, apps/gateway | feat/tess-interaction-agent | — | 22K | Independent gate PASS after two remediation rounds; completion effective when planning PR merges | +| TESS-M1-SEC-001 | done | Enforce command scopes/roles and durable exact-action approval for privileged/destructive commands | #707 | codex | apps/gateway | fix/tess-command-authz | TESS-PLAN-001 | 25K | TESS-SEC-002; diskhygiene-terra; PR #718 head e3d98d73 MERGED (ROR 16829) | +| TESS-M1-SEC-002 | done | Enforce owner/tenant binding on session list/read/attach/send/terminate across REST and WS | #707 | codex | apps/gateway | fix/tess-session-ownership | TESS-PLAN-001 | 30K | TESS-SEC-003; coder0; PR #715 head 43ffbe7b MERGED (ROR 16808) | +| TESS-M1-SEC-003 | done | Bind MCP actor/tenant to authenticated context and add per-tool scopes | #707 | codex | apps/gateway | fix/tess-mcp-identity | TESS-PLAN-001 | 22K | TESS-SEC-004; coder1; PR #717 head 9ab776f9 MERGED (ROR 16819) | +| TESS-M1-SEC-004 | done | Add authenticated Discord service ingress, allowlists, correlation and replay protection | #707 | codex | plugins/discord, apps/gateway | fix/tess-discord-ingress | TESS-PLAN-001 | 28K | TESS-SEC-005; coder4; PR #716 head 55ae77b6 MERGED (ROR 16830) | +| TESS-M1-SEC-005 | done | Redact/classify secret and PII before persistence/egress; harden provider login flow | #707 | codex | apps/gateway, packages/log | fix/tess-redaction | TESS-PLAN-001 | 28K | TESS-SEC-006; coder1 (Mos-routed from blocked wrapfix-terra); mis-based #723 CLOSED superseded. MERGED to main: PR #725 head 726f7ab7 (ROR 16880). Verified chat persistence + egress redaction hooks; canary tests split-secret/private-key/overflow/persistence classification; provider login no auth URL/raw token in chat output | +| TESS-M1-SEC-006 | done | Scope session GC/retention or separate authorized global retention job | #707 | codex | apps/gateway, packages/log | fix/tess-session-gc-scope | TESS-PLAN-001 | 18K | TESS-SEC-009; coder4; PR #720 base=main. MERGED to main: head 37be090e (ROR 16861). Both blockers fixed: glob metachar sessionIds escaped+regression; durable approval survives GC pass (create→GC→key remains→authz succeeds); /gc disabled, per-session log demotion, no fullCollect/sweepOrphans entry, legacy repeatable GC schedule removed | +| TESS-M1-001 | done | Define AgentRuntimeProvider, capabilities, session tree, normalized stream events/errors, attach semantics | #707 | codex | packages/types, packages/agent | feat/tess-runtime-contract | TESS-PLAN-001 | 25K | TESS-ARP-001, TESS-TRN-001; wrapfix-terra; PR #719 head 5c42e67f MERGED (ROR 16813) | +| TESS-M1-002 | done | Implement provider registry/service with immutable actor scope, approval, audit and correlation boundaries | #707 | codex | apps/gateway, packages/agent | feat/tess-provider-registry | TESS-M1-001,TESS-M1-SEC-001,TESS-M1-SEC-002,TESS-M1-SEC-003 | 30K | TESS-SEC-001..004,007; coder0; PR #722 head c529022d MERGED (ROR 16849) | +| TESS-M1-003 | done | Implement tmux/fleet runtime provider and safe attach/message/terminate capability policy | #707 | codex | packages/mosaic, packages/agent | feat/tess-fleet-provider | TESS-M1-002 | 30K | TESS-FLT-001; coder0; PR #724 base=main. MERGED to main: head 355d814f (ROR 16868). HARD BOUNDARY verified: writes/control default-deny before tmux probing unless write authority permits; final exact-target authz after roster/socket/runtime verification; exact target/prefix/runtime-drift tests; read-only attach with immutable scope handles; empty-msg/default-deny/unverified-target tests; no credential material | +| TESS-M1-OBS-001 | done | Implement correlation propagation, structured runtime/provider/tool audit, health/readiness and safe effective-policy status | #707 | codex | apps/gateway, packages/agent, packages/log | feat/tess-observability-terra | TESS-M1-002 | 24K | TESS-OBS-001; SOLE owner=diskhygiene-terra. MERGED to main at REBASED head: PR #726 head 53f5414 (re-ROR comment 16886, prior 16881@adfa5c06 discarded after head move), CI 1723 green. Both @mosaicstack/log barrel exports coexist (redaction + runtime-audit), metadata-only/SHA-256 audit intact, fail-closed audit-before-side-effects intact, safe status/effective-policy/readiness | +| TESS-M1-V | done | Independent architecture/security review and complete contract/abuse-suite verification | #707 | mos-reviewer | apps/gateway, packages/agent, packages/log, plugins/discord | review/tess-m1 | TESS-M1-SEC-001,TESS-M1-SEC-002,TESS-M1-SEC-003,TESS-M1-SEC-004,TESS-M1-SEC-005,TESS-M1-SEC-006,TESS-M1-003,TESS-M1-OBS-001 | 20K | Gate M2 = PASS (Mos-owned independent non-author reviewer, 2026-07-12): all 5 priority seams verified live, 60+ tests green. M2 (#708) OPEN. Orchestrator did NOT run a competing lane (prior reviewer-lane dispatch recalled). Non-gating follow-up from this review captured as TESS-M1-FUP-001 (execute() authz-error mis-classification), scheduled to land before/with TESS-M3-001 — not now | +| TESS-M1-FUP-001 | not-started | RuntimeProviderService.execute() records provider-thrown authorization errors as failed/provider_error instead of denied/policy_denied | #707 | — | apps/gateway, packages/agent | — | — | 6K | NON-GATING follow-up from M1-V review (2026-07-12). Provider-thrown authz errors (e.g. FleetRuntimeProviderError 'forbidden' from M1-003 write-authority) mis-classify as outcome:'failed'/'provider_error' rather than 'denied'/'policy_denied'. Low-priority. Land BEFORE/WITH TESS-M3-001 fleet-provider registry wiring (#709), NOT now. UPDATE 2026-07-13: did NOT ride in #730; Mos FOLDED this into TESS-M3-003 C4 (authz-error classification + RuntimeApprovalDeniedError→403 filter) — tracked there, land with M3-003. | +| TESS-M2-001 | done | Add Tess roster/profile/service pinned to GPT-5.6 Sol high with fail-fast config and observable effective policy | #708 | coder0 | packages/mosaic | feat/tess-pi-service | TESS-M1-V | 22K | TESS-PI-001; AC-TESS-03. Mos-dispatched directly to coder0. MERGED to main by Mos (2026-07-12): PR #728 head c58e86e2, ROR comment 16905, CI 1728 green. NAME-AS-CONFIG invariant VERIFIED — identity via MOSAIC_AGENT_NAME/%i/roster data, no hardcoded tess identity in impl/service/schema/tool, Tess example-only; Nova distinct-name zero-code-change provisioning test; GPT-5.6 Sol high fail-fast; credential-safe effective-policy output; no live credential material | +| TESS-M2-002 | done | Implement durable session identity, inbox/outbox, approval, checkpoint, handoff, compaction and restart recovery | #708 | coder0 | apps/gateway, packages/agent, packages/db | feat/tess-durable-state | TESS-M2-001 | 38K | TESS-STA-001, TESS-SEC-007..008; recovery TDD. Mos-dispatched directly to coder0 (2026-07-12) — orchestrator tracks, no competing lane. Branch feat/tess-durable-state from fresh origin/main e3b5113b; first recovery TDD packages/agent/src/tess-durable-session.test.ts; reuses existing provider registry + durable approval store. base=main, PR-open-STOP, independent non-author ROR then Mos merges. Next gate after merge = TESS-M2-V (M2→M3 review). PR #729 OPEN (feat(tess): persist durable session state; base=main, mergeable=true, head 102a7b606bd492201e3d731a86397a9cfe4eb998); coder0 pnpm turbo typecheck/lint/test --force 88/88 cold-cache + format green + Codex code/security remediated; scope = durable identity/inbox-outbox idempotency/immutable checkpoints/portable handoffs/PGlite close-reopen recovery/exact one-time approvals/sealed-redacted payloads/scoped dispatch. ROR routed to reviewer lane (non-author) at exact head 102a7b60. CHANGES REQUESTED (reviewer comment 16917 @102a7b60, CI pipeline 1730 RED) — 3 blockers routed to coder0: (1) CI red: gateway PGlite close/reopen durable recovery test TIMEOUT; (2) idempotency compares REDACTED payloads so distinct secrets collapse/collide — key must be over pre-redaction canonical identity; (3) durable schema/approval NAMESPACE hardcoded to tess, violates name-as-config — must derive from configured agent name (Nova zero-code-change). coder0 remediating; head will move → re-ROR required at new exact head. REMEDIATED + re-pushed: new head 444988d23bada28d3cc9ce7e588e18e052f058ff — (1) recovery suite uses one shared PGlite fixture, close/reopen AC completes ~0.5s (was 30s timeout); (2) pre-redaction SHA-256 payload digest added to idempotency conflict checks (distinct secrets no longer collapse); (3) hardcoded tess durable DB objects/approval prefix replaced with generic interaction naming + agent-bound approval namespace. push-hook typecheck/lint/format green; CI pipeline 1731 GREEN on new head 444988d2. Head confirmed unchanged at green SHA; re-ROR routed to reviewer (non-author) at exact head 444988d2 — prior REQUEST CHANGES 16917 void at old head. RE-ROR = REQUEST CHANGES (reviewer comment 16925 @444988d2; CI 1731 green + recovery test passes 1515ms not skipped). 2 residual payload-digest blockers routed to coder0: (1) CHECKPOINT idempotency still collapses — pre-redaction digest fix reached inbox/outbox but NOT checkpoint path; distinct sensitive checkpoint payloads under same sessionId+checkpointId collapse; needs pre-redaction digest column on checkpoint conflict check; (2) digest is UNKEYED plaintext SHA-256 over sensitive payloads → allows offline plaintext confirmation; switch to KEYED HMAC-SHA256 with config-sourced fail-fast secret (never hardcoded/logged), applied to inbox/outbox + checkpoint. coder0 remediating; head will move → re-ROR at new exact head. ROUND-2 REMEDIATED + pushed: new head cbdc38af954d49016b5fdc4a6dab0497317b6a1c — checkpoint now persists pre-redaction HMAC digest; inbox/outbox switched to VERSIONED HMAC; distinct-secret + delimiter-collision regressions added; migration safe for pre-existing checkpoint rows and legacy checkpoints FAIL CLOSED (cannot prove original payload); Codex security review no findings; format/diff green, PGlite recovery executes 1.765s. CI pipeline 1732 TERMINAL GREEN (success) on cbdc38af. RE-ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head cbdc38af954d49016b5fdc4a6dab0497317b6a1c (visible Gitea comment 16933). Head confirmed unchanged at ROR target + PR mergeable=true. Reviewer verified checkpoint HMAC digest + collision regressions, recovery no-duplicate-side-effect, sealed/redacted at-rest payloads, scoped dispatch, agent-bound generic namespace; CI 1732 steps ci-postgres/install/sanitization/typecheck/lint/format/test all green; no merge by reviewer (pr-review wrapper self-approve blocked → recorded as verified PR comment). MERGED to main by Mos — merge_commit 99a2d0fc, final APPROVE at head cbdc38af (3-round reviewer loop 16917→16925→16933). M2 build phase CONVERGED (M2-001 #728 + M2-002 #729). TESS-M2-V (M2→M3 gate, AC-TESS-03/06) now running as Mos-owned independent Sonnet reviewer (same arrangement as M1-V) — orchestrator does NOT launch a competing review lane; Mos reports verdict. On M2-V PASS, M3 (#709) tasks TESS-M3-001/002 unblock. | +| TESS-M2-V | done | Clean-host Pi launch plus model/policy status and restart/compaction/duplicate-side-effect verification | #708 | mos-reviewer | apps/gateway/src/**tests**/integration, packages/mosaic/src | review/tess-m2 | TESS-M2-002 | 18K | Gate M3 = PASS (Mos-owned independent Sonnet reviewer at merged main 99a2d0fc, 2026-07-13). All 5 criteria verified with live test runs: model/policy fail-fast + credential-safe; restart recovery exactly-once; keyed-HMAC pre-redaction idempotency; compaction/handoff survival; name-as-config (interaction\_\* everywhere, Nova tests). Orchestrator did NOT run a competing lane (same as M1-V). M3 (#709) UNBLOCKED. Non-gating follow-ups from this review captured as TESS-M2-FUP-001/002/003 below. | +| TESS-M2-FUP-001 | not-started | Delete dead unkeyed-sha256 OR-branch in tess-durable-session.repository.ts matchesContentDigest (:417-422) to match strict matchesCheckpointDigest | #708 | — | apps/gateway | — | — | 4K | NON-GATING follow-up from M2-V review (2026-07-13). Dead OR-branch NOT exploitable (all writers hmac:v1:-prefixed, content_digest NOT NULL from migration 0012) but weakens exactness guarantee. Low-priority. SCHEDULE TO LAND WITH M3 work. | +| TESS-M2-FUP-002 | not-started | Add literal approval+compaction combined integration test | #708 | — | apps/gateway/src/**tests**/integration | — | — | 4K | NON-GATING follow-up from M2-V review (2026-07-13). Subsystems currently tested separately; what matters IS covered. OPTIONAL, low-priority. | +| TESS-M2-FUP-003 | not-started | Cosmetic rename pass: 'Tess' in class/file/log names (TessDurableSessionRepository etc.) so Nova deployment logs don't say Tess | #708 | — | apps/gateway, packages/agent | — | — | 5K | NON-GATING follow-up from M2-V review (2026-07-13). Cosmetic only — functional name-as-config already correct (interaction\_\* data path). Low-priority. SCHEDULE TO LAND WITH M3 work (now M3-003 window). Related cosmetic logged separately as TESS-M2-FUP-004. | +| TESS-M2-FUP-004 | not-started | Cosmetic: sourceLabel ?? 'tess' default literal @packages/agent/src/tmux-fleet-runtime-provider.ts:142 | #708 | — | packages/agent | — | — | 2K | NON-GATING cosmetic follow-up (pre-existing from #722/#724), logged per Mos 2026-07-13. Same class as TESS-M2-FUP-003 (name-as-config cosmetic; functional data path already generic). Low-priority — fold into a cosmetic-rename pass alongside M2-FUP-003. | +| TESS-M3-001 | done | Bind dedicated Tess Discord channel with streaming, threads, attachments, pairing/RBAC and approvals | #709 | coder4 | plugins/discord, apps/gateway | feat/tess-discord | TESS-M2-V,TESS-M1-SEC-004 | 35K | TESS-DSC-001. Mos DIRECT-DISPATCHED to coder4 on feat/tess-discord (base=main, 2026-07-13) — orchestrator is DYOR-loaded so Mos dispatched to avoid double-dispatch; orchestrator TRACKS only, no competing lane. PR-open-STOP, independent non-author ROR then Mos merges. Land TESS-M1-FUP-001 (execute() authz-error mapping) + TESS-M2-FUP-001/003 with this M3 work. PR #730 OPEN (feat(#709): add configured Discord interaction binding; base=main, mergeable=true, head 25ed3676550649d805737ddd97cec08d49873662; config-owned Discord bindings w/ pairing/RBAC, thread metadata, attachments, streaming correlation, authenticated ingress reuse). NOTE: coder4 did not report PR-open to orchestrator; picked up from reviewer ROR. CI pipeline 1734 GREEN on head. ROR = REQUEST CHANGES (reviewer comment 16951 @25ed3676) — 2 functional blockers routed to coder4: (1) THREAD/SUB-SESSION ROUTING: allowedChannelIds check tests the THREAD id before parent-channel binding resolution → thread messages in a bound channel are wrongly rejected; must resolve parent-channel binding FIRST then evaluate allowlist against bound parent + add bound-channel-thread test; (2) APPROVAL NOT WIRED TO M2 DURABLE STORE: Discord approval op defined but no path invokes the durable M2 exact-action approval store (only send wired) — must route Discord approval through the #729 durable exact-action approval surface (one-time/exact-action consume, no replay) + denial + exact-action approval tests. Root-cause fixes only (no allowlist-loosen, no approval stub). coder4 remediating; head will move → re-ROR required at new exact head after CI terminal green. ROUND-1 REMEDIATED + pushed: new head 689d5b68706fd5f5b190b0e4d988efc59fb51acb, CI pipeline 1736 GREEN. RE-ROR = REQUEST CHANGES (reviewer comment 16968 @689d5b68) — 2 residuals routed to coder4: (1) thread allowlist directionally fixed but REQUESTED regression test absent — add explicit 'message in thread of bound channel is ACCEPTED' test; (2) CORE BLOCKER: discord:approve still calls commandExecutor.createApproval (generic slash-command approval), NOT the M2 durable exact-action store — must call createRuntimeTerminationApproval writing agent::command-approval exact-action key (durable one-time consume, no replay), plus Discord one-shot tests: approval consumes exact action once + second attempt rejected, and denial-path rejection. Root-cause only (no aliasing generic path). coder4 remediating; head will move → re-ROR at new exact head after CI terminal green. ROUND-2 REMEDIATED + pushed: head moved (via 34b82bd2), CI green — but ROUND-3 RE-ROR = REQUEST CHANGES (reviewer comment 16973 @34b82bd257154ece2f51d29df698b01150cb9a2b, CI pipeline 1738 green). Progress: discord:approve now CALLS createRuntimeTerminationApproval — but STILL WRONG: it binds the approval to DISCORD_SERVICE_USER_ID + approval-message correlation/channel, making a Discord-SILO record NOT consumable by the CLI/runtime stop exact-action path. CORE M3 AC = ONE durable exact-action approval consumable cross-surface (Discord OR CLI OR runtime); exact-action KEY must be agent::command-approval for the specific pending command/termination action (same key CLI 'mosaic tess stop'/runtime-stop consumes); Discord actor + message correlation belong in METADATA, not the key. Routed to coder4 (round-3): re-key to agent+action; add tests (a) discord:approve happy consumes exact action, (b) SAME approval consumable cross-surface by CLI/runtime stop, (c) one-shot replay rejected, (d) denial rejects, (e) thread-under-parent accept. THIRD round on the same durable-approval seam (16951→16968→16973); reviewer holding cross-surface exact-action boundary firm. coder4 remediating; re-ROR at new exact head after CI terminal green. ROUND-3 REMEDIATED + pushed: head a4c70c5a71a4a73f24f04060a301703ba5ac7530, CI pipeline 1739 GREEN — but ROUND-4 RE-ROR = REQUEST CHANGES (reviewer comment 16978 @a4c70c5a). coder4 OVER-CORRECTED: removed actor/tenant/channel/correlation from runtimeActionDigest/consume (WEAKENS command-authorization exactness — the merged M2 contract digests all 7 fields), still NO Discord-origin consume/terminate path for the minted approval, required Discord-path tests still absent (approve happy+denial, one-shot replay, thread-under-parent accept). ROUND-5 ROUTED to coder4 with the FROZEN merged contract extracted from origin/main:apps/gateway/src/commands/command-authorization.service.ts: runtimeActionDigest is sha256 over EXACTLY {providerId,sessionId,actorId,tenantId,channelId,correlationId,agentName} — do NOT modify/strip (revert round-4 change); consume also re-checks actorId+tenantId, requires approver role=admin, one-shot redis.del; store key interaction:command-approval::. Cross-surface = Discord mint and CLI/runtime stop present the SAME 7 fields of the TARGET pending termination (NOT the Discord message's own channel/correlation, NOT DISCORD_SERVICE_USER_ID); actorId = approving admin's resolved user id. Add the missing Discord-origin consume/terminate invocation (via runtime-approval-verifier.ts adapter) + 5 tests. FOURTH round same seam (16951→16968→16973→16978); reviewer holding boundary firm. coder4 remediating; re-ROR at new exact head after CI terminal green. ROUND-5: writer RE-ROUTED coder4→coder0 (Mos-dispatched follow-up; coder0 is original author of the M2 durable approval store, so the ideal lane to wire the Discord path to it — orchestrator did not have this re-route tracked, flagged to Mos for confirmation, single-writer stand-down requested from coder4). coder0 pushed head 6af68e76de3657d837875b1c9d0f5c9678429e59 (branch tip confirmed), CI Woodpecker pipeline 1742 = SUCCESS (terminal green). Scope: approve-gated stop command (provider/session/approval args), one-shot durable approval consumption, explicit stop authorization (Discord-origin consume/terminate path now present), 4 security regressions; command-authorization.service.ts UNCHANGED (frozen 7-field runtimeActionDigest preserved — round-4 field-stripping reverted). ROUND-5 ROR routed to reviewer (non-author) at exact head 6af68e76; prior round-4 REQUEST CHANGES 16978 void at old head. ROUND-5 RE-ROR = REQUEST CHANGES (reviewer comment 16986 @6af68e76, CI 1742 green). PROGRESS: 7-field digest preserved, thread routing + tests present, no live creds. RESIDUAL (actor-identity seam) routed to coder0 (round-6): (1) approval/stop still binds actorId = DISCORD_SERVICE_USER_ID (bot) — must be the RESOLVED APPROVING ADMIN's mosaic user id at both mint and consume (consume requires approval.actorId===action.actorId AND resolveRole(actorId)==='admin'; bot is not the approver); (2) stop consumes as service actor — must present the same approving-admin actorId bound at mint; (3) approve→stop tests share one fixture correlation, masking production separate-message flow — must model approval message + stop command as separate correlations resolving to the SAME target action 7-field identity (admin A approves T → stop consumes T once as A → replay rejected). Root-cause only (do not make the bot admin). FIFTH round on the seam (16951→16968→16973→16978→16986); reviewer holding actor boundary firm. coder0 remediating; re-ROR at new exact head after CI terminal green. ROUND-6 REMEDIATED + pushed: head 533e9702591436810160dfb1cf8a42a222cfb7c7 (branch tip confirmed), CI Woodpecker pipeline 1743 = SUCCESS (terminal green). Scope: stable target correlation + real RuntimeProviderService consume coverage; approval agent binding matches MOSAIC_AGENT_NAME with explicit mismatch denial; command-authorization.service.ts unchanged. ROUND-6 ROR routed to reviewer (non-author) at exact head 533e9702; prior round-5 REQUEST CHANGES 16986 void at old head. ROUND-6 RE-ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head 533e9702591436810160dfb1cf8a42a222cfb7c7 (visible Gitea comment 16991, CI 1743 success). Reviewer verified: actorId mint+stop consume uses RESOLVED mosaic admin (not DISCORD_SERVICE_USER_ID, not bot-made-admin); RuntimeProviderService consumes via verifier adapter; separate ingress correlations map to stable target action + one-shot replay rejected; 7-field digest intact; thread-under-parent test present; no live creds. pr-review wrapper self-approve blocked → recorded as verified PR comment. Head confirmed UNCHANGED at ROR target 533e9702 + PR mergeable=true, base=main. SIX-round durable cross-surface exact-action approval seam CLOSED (16951→16968→16973→16978→16986→16991); writer re-routed coder4→coder0 (Mos-dispatched) mid-flight. #730 MERGEABLE (independent non-author ROR + green CI at exact head). HARD STOP — Mos owns merge. MERGED to main by Mos — squash commit 84d884b9, approved head 533e9702, branch feat/tess-discord deleted, independent Sonnet ROR APPROVE (16991). M3 BUILD PHASE CONVERGED (M3-001 #730 + M3-002 #731 both merged). Writer re-routed coder4→coder0 mid-flight (Mos-dispatched); coder0 confirmed stand-down cleanup (dropped superseded WIP stash), on clean main 84d884b9, idle. NOTE: M3-001 #730 scope was Discord binding + durable approval; TESS-M1-FUP-001 (execute() authz-error mapping) + TESS-M2-FUP-001/003 did NOT ride in this PR — they remain not-started follow-ups to schedule (flagged to Mos). TESS-M3-V (M3→M4 gate) now READY — Mos dispatching as Mos-owned independent Sonnet checkpoint against merged main; orchestrator tracks, no competing lane. | +| TESS-M3-002 | done | Implement `mosaic tess` chat/status/sessions/tree/attach/send/stop/health/recover CLI | #709 | diskhygiene-terra | packages/mosaic | feat/tess-cli | TESS-M2-V | 30K | TESS-CLI-001. Mos DIRECT-DISPATCHED to diskhygiene-terra on feat/tess-cli (base=main, 2026-07-13) — orchestrator TRACKS only, no competing lane. PR-open-STOP, independent non-author ROR then Mos merges. Intake initially blocked on wrapper (issue-view.sh bare positional → 'Unknown option: 709'); orchestrator relayed -i flag fix. PR #731 OPEN (feat(tess): add generic interaction CLI; base=main, mergeable=true, head de74e46a0640c44c6b7294c24669496980761c92, fresh origin/main base 99a2d0fc). Scope: generic mosaic interaction command chat/status/sessions/tree/attach/send/stop/health/recover (NO instance-specific literal); --agent/MOSAIC_AGENT_NAME + Nova name-as-config test; authenticated gateway durable/provider boundary — server-derived actor scope, required non-simple correlation header, identity binding, durable recovery, registry routing, exact-action approval stop; status/health safe. Terra: full cold-cache pnpm turbo typecheck/lint/test --force + gates green, Codex security clean after remediation. CI pipeline 1735 TERMINAL GREEN (success) on de74e46a. ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head de74e46a0640c44c6b7294c24669496980761c92 (visible Gitea comment 16959). Head confirmed unchanged at ROR target + mergeable=true. Reviewer verified generic mosaic interaction CLI verbs, --agent/MOSAIC_AGENT_NAME name-as-config, server-derived actor scope + required correlation, durable identity/recovery path, registry routing, exact-action approval stop, no live creds; no merge by reviewer (self-approve wrapper blocked → recorded as verified PR comment). MERGED to main by Mos — merge_commit 8246ee01 (independent Sonnet ROR 16959, all criteria + name-as-config Nova test verified). TESS-M3-002 DONE. TESS-M3-V (M3→M4 gate) advances once M3-001 #730 also merges — Mos-owned reviewer, no competing lane from orchestrator. | +| TESS-M3-003 | done | Cross-surface durable session integration + functional attach + denial/audit parity | #709 | coder0 | apps/gateway, plugins/discord, packages/mosaic, packages/agent | feat/tess-m3-integration | TESS-M3-001,TESS-M3-002 | 30K | Mos-DISPATCHED to coder0 (base=main, 2026-07-13) after M3-V gate = FAIL (integration unwired). Scope: C1 wire DurableSessionCoordinator.create into session-start + Discord resolves via durable snapshot + cross-surface E2E (AC-TESS-01); C2 expose streamSession over HTTP+CLI for functional attach + success test; C4 CLI denial spec + Discord mint-side durable audit + FOLD TESS-M1-FUP-001 (execute() authz-error classification) + RuntimeApprovalDeniedError→403 filter. PR-open-STOP, independent non-author ROR then Mos merges. M3-V RE-GATES after this lands. C1 design question raised by coder0 (origin/main has NO runtime-provider session-start/create op — only AgentService/Pi chat createSession, an LLM conversation, not a RuntimeProvider session carrying providerId/runtimeSessionId) — RESOLVED by Mos synthesis ruling (2026-07-13): conversationId is the durable handle; DurableSessionCoordinator.create happens at RUNTIME ENROLLMENT once providerId/runtimeSessionId are known; BOTH surfaces (Discord + CLI) snapshot it. coder0 PROCEEDING: C2/C4 in parallel now + implementing the C1 enrollment boundary per the ruling. PR-open-STOP; orchestrator serializes CI + routes independent non-author ROR at exact head; Mos merges. UPDATE 2026-07-13: **PR #732 OPEN** (base=main), head 451f7e04ec6c45adb12007dd7131da6a2b199962. coder0 stopped at PR creation, holding (no force-push). Local forced validation green (typecheck/lint/format:check/test: gateway 590 pass/11 skip, mosaic 640 pass), Codex code+security clean, command-authorization.service.ts byte-identical to origin/main. CI pipeline 1745 running — orchestrator serializing; on green-at-exact-head, independent non-author ROR routes to reviewer; HARD STOP for Mos merge. UPDATE 2026-07-13 (CI-GREEN): pipeline 1745 (event=pull_request, refs/pull/732/head, exact head 451f7e04) = SUCCESS; PR mergeable=true, head unmoved. Independent non-author ROR ROUTED to reviewer at exact head 451f7e04 (author coder0). Awaiting ROR verdict; HARD STOP for Mos merge; M3-V re-gates on merge. UPDATE 2026-07-13 (ROR round 1 = REQUEST CHANGES @ 451f7e04, Gitea comment 17007, CI 1745 green): ONE real blocker — Discord approve path UNREACHABLE in production. ChatGateway.handleDiscordApproval accepts only bare '/approve' (^/approve\\s\*$), but plugins/discord/src/index.ts routes to discord:approve only on startsWith('/approve ') — so bare /approve → normal message (dead), '/approve x' → gateway-rejected; AC-TESS-01 mint/cross-surface flow can't fire; tests bypass DiscordPlugin.handleDiscordMessage so they mask it (same integration-unwired class M3-V flagged). Positives HELD: command-authz byte-identical (hash a9f829e7), 7-field digest intact, actor=resolved admin (not DISCORD_SERVICE_USER_ID), durable/stream/denial/audit coverage present, no live creds. Root-cause routed to coder0: reconcile plugin-routing predicate ↔ gateway accept-grammar + add end-to-end test through real handleDiscordMessage (no bypass). Fix push MOVES head → invalidates ROR, re-serialize CI + re-ROR at new exact head. UPDATE 2026-07-13 (RESOLUTION — MERGED by Mos): before coder0's fix was pushed, Mos ran a combined M3-V re-review at the SAME head 451f7e04 ([W-jarvis:reviewer-sonnet], Gitea comment 17009 = VERIFIED APPROVE + M3-V GATE PASS) and MERGED #732 → main squash commit **0b621660** ("feat(tess): wire durable interaction surfaces"). Mos milestone signal: M3-001/002/003 done, M3-V PASS, M3 COMPLETE, advancing to M4. ⚠️ ORCHESTRATOR RECONCILIATION: the two independent ROR reads at 451f7e04 CONFLICT on one concrete mechanism — my reviewer (17007) flagged the Discord approve path unreachable; Mos's re-review (17009) validated the gateway handler + integration test but that test bypasses DiscordPlugin.handleDiscordMessage. Orchestrator VERIFIED against merged main 0b621660 (read-only git show/grep): the plugin-routing defect is STILL LIVE — see TESS-M3-FUP-005. Surfaced to Mos as a fast-follow; coder0's uncommitted fix held pending Mos disposition. | +| TESS-M3-V | pass | Discord+CLI same-session E2E, denial/approval tests, and operator-flow review | #709 | mos-sonnet | apps/gateway/src/**tests**/integration, plugins/discord, packages/mosaic/src | review/tess-m3 | TESS-M3-001,TESS-M3-002,TESS-M3-003 | 20K | Gate M4. FIRST RUN = FAIL (Mos-owned independent Sonnet checkpoint against merged main 84d884b9, 2026-07-13): integration UNWIRED — Discord/CLI not cross-surface functional against durable sessions; attach/denial/audit parity incomplete. Remediation = TESS-M3-003 (coder0). SECOND RUN = **PASS** (Mos-owned combined re-review+re-gate at head 451f7e04, [W-jarvis:reviewer-sonnet] Gitea comment 17009, 2026-07-13): C1 cross-surface durable session, C2 functional attach, C4 denial/audit parity all closed; hard constraint (command-authz byte-identical, 7-field digest untouched) intact; C3/C5 no regression. Mos MERGED #732 → main 0b621660 and declared M3 milestone COMPLETE, advancing to M4. ⚠️ CAVEAT (orchestrator-verified live defect, NON-GATING per Mos): the M3-V integration test does not exercise DiscordPlugin.handleDiscordMessage, so the production Discord approve-path routing defect survived the gate — logged as TESS-M3-FUP-005 (fast-follow, surfaced to Mos). M4 (#710) UNBLOCKED (dep TESS-M3-V met). | +| TESS-M3-FUP-005 | done | Discord approve/stop production routing predicate mismatch — approve path unreachable | #709 | coder0 | plugins/discord, apps/gateway | feat/tess-m3-integration (rebased onto 0b621660) | TESS-M3-003 | 8K | **MERGED by Mos** → main squash commit **f1c6b37b** ("fix(tess): route bare Discord approvals (#733)"), 2026-07-13; post-merge main CI pipeline 1750 = SUCCESS. Verified-live Discord approve-path defect CLOSED — merged cross-surface mint path now functional end-to-end. HISTORY: **PR #733 OPEN** (base=main), head ed1d985c90e24ca3046bd570a556802927d80ed8 (rebased onto merged main 0b621660 to clear a Gitea conflict, force-with-lease; supersedes pre-rebase a02f526d whose pipeline 1747 was killed). pr-diff confirms clean 2-file scope: plugins/discord/src/index.ts + tess-cross-surface.integration.test.ts. coder0: bare /approve now routes to discord:approve; E2E invokes the REAL DiscordPlugin.handleDiscordMessage proving approve→stop against the durable conversation handle; forced typecheck/lint/format + targeted 17/17 green; command-authz zero-diff from main. CI pipeline 1748 (pull_request, refs/pull/733/head, commit ed1d985c) = **SUCCESS**. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head ed1d985c (Gitea comment 17017) — command-authz byte-identical hash a9f829e7 + 7-field digest intact, bare /approve REAL DiscordPlugin route fixed, gateway uses durable getSnapshot(conversationId), anti-masking divergent test inputs present, no Tess literal, no live creds. Head UNMOVED (ed1d985c), base main, mergeable=true. **MERGEABLE — HARD STOP for Mos merge** (2026-07-13). On merge → FUP-005 done; makes the merged Discord approve surface functional end-to-end. | ⚠️ VERIFIED-LIVE DEFECT on merged main 0b621660 (orchestrator read-only git show/grep, 2026-07-13). Gateway apps/gateway/src/chat/chat.gateway.ts:670 accepts approval ONLY as bare '/approve' (regex /^\\/approve\\s\*$/i). Plugin plugins/discord/src/index.ts trims content (:339-341) then routes to discord:approve ONLY when content.startsWith('/approve ') (:385, requires a space+arg). NET: trimmed bare '/approve' fails the plugin predicate → emitted as normal message → gateway approval handler never fires (DEAD); '/approve x' passes the plugin but the gateway regex rejects it. So the production Discord approve path (AC-TESS-01 cross-surface mint) is UNREACHABLE end-to-end. M3-V PASSED because its integration test drives the gateway handler directly and bypasses DiscordPlugin.handleDiscordMessage, so the plugin predicate was never exercised (my reviewer 17007 caught it; Mos re-review 17009 validated the handler+test, not the plugin predicate). '/stop' likely same class (plugin needs startsWith('/stop ') args; confirm against gateway stop grammar). FIX: reconcile plugin routing predicate ↔ gateway accept-grammar (route bare '/approve' and snapshot-resolved '/stop ') + add an E2E test through the REAL DiscordPlugin.handleDiscordMessage (no bypass) proving mint fires. coder0 HAS this fix uncommitted in its worktree (from the round-1 remediation, pre-empted by the merge) — needs a fresh branch off main 0b621660 as a follow-up PR. AWAITING Mos disposition (fast-follow now vs after M4). Standard gates: PR-open-STOP, independent non-author ROR at exact head, Mos merges. | +| TESS-M4-001 | done | Implement Mos coordination handoff/observe/result contract with authority-boundary tests | #710 | coder0 | packages/coord, apps/gateway | feat/tess-mos-coordination | TESS-M3-V | 25K | **MERGED by Mos** → main squash **76325ca3** ("feat(tess): add Mos coordination boundary (#735)"), 2026-07-13 — merge = native-in-process transport ACCEPTED (contract transport-neutral). TESS-MOS-001. Mos-DISPATCHED 2026-07-13 to coder0 DESIGN-FIRST. UPDATE 2026-07-13: coder0 wrote docs/tess/MOS-COORDINATION.md; design checkpoint surfaced to Mos with the transport-adapter question (existing fleet/tmux Mos-authority channel vs dedicated native queue/HTTP). coder0 PROCEEDED (ahead of the Mos transport ruling) choosing a **native in-process adapter** and opened **PR #735** (base=main), head 7936e15d3ae137c91c88efdab4bb09b863a2195d. Impl: transport-NEUTRAL handoff/observe/result contract (MosCoordinationPort); deterministic native in-process InMemoryMosCoordinationPort; gateway derives actor/tenant/requester from trusted context/config; fail-closed for unconfigured-requester, self-delegation, target-drift, cross-tenant observe/result; NO public orchestrator verbs; **NO fleet/tmux transport, NO Mos-side consumer**; command-authorization byte-identical hash a9f829e7; no live creds; no hardcoded Tess identity. Local forced cold-cache typecheck/lint/format/test green (42 tasks); Codex security no findings. CI pipeline 1752 (pull_request, refs/pull/735/head, commit 7936e15d) = **SUCCESS**; head UNMOVED, mergeable=true. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 7936e15d (Gitea comment 17032) — verified MosCoordinationPort=handoff/observe/result only, gateway-derived authority, fail-closed denial coverage, native in-process port (no tmux/Mos consumer), command-authz byte-identical a9f829e7, no live creds, no Tess literal. ⚠️ HEAD MOVED 2026-07-13 (ROR 17032 INVALIDATED): coder0 pushed one post-ROR commit → new head **5022911f84dd7ac30f40df31a53f6cd31a51728f** (commit "docs(tess): record M4 verification", parent 7936e15d). Orchestrator-verified sole delta = a single scratchpad doc docs/scratchpads/tess-m4-001-mos-coordination.md, ZERO code/test diff. New CI pipeline 1754 (pull_request, refs/pull/735/head, commit 5022911f) = **SUCCESS**; mergeable=true, head now 5022911f. Comment 17032 @ 7936e15d no longer at exact head → re-serialize + re-ROR REQUIRED. Fast delta RE-ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 5022911f (Gitea comment 17036) — confirmed 5022911f is direct child of prior-reviewed 7936e15d, sole two-dot delta = the 3-line scratchpad doc, no code/test diff, command-authz byte-identical a9f829e7, CI 1754 success. Head UNMOVED (5022911f), mergeable=true. **MERGEABLE at 5022911f — HARD STOP for Mos merge** (2026-07-13). MERGE = Mos ACCEPTING the native-in-process transport choice (contract stays transport-neutral; a fleet/tmux or native-queue/HTTP consumer can be added later without contract churn); if Mos wants a different FIRST adapter, hold merge + route rework to coder0. | +| TESS-M4-002 | done | Implement transitional Hermes runtime/capability adapter | #710 | coder3 | packages/agent, apps/gateway | feat/tess-hermes-adapter | TESS-M3-V | 40K | **MERGED by Mos** → main squash **9e5b9188** ("feat(agent): add transitional Hermes runtime adapter (#734)"), 2026-07-13 — Mos merge = **option (a) ACCEPTED**; post-merge main CI 1753. TESS-HRM-001; no legacy schema in core contracts. Mos-DISPATCHED 2026-07-13 to coder3 DESIGN-FIRST (contract sketch + questions to Mos before build). Goes in-progress as PR opens; PR-open-STOP → serialize CI + independent non-author ROR at exact head → Mos merges. UPDATE 2026-07-13: coder3 ACTIVE — fresh worktree/branch feat/tess-hermes-adapter off origin/main; boundary sketch at docs/tess/hermes-runtime-adapter-design.md. DESIGN QUESTION surfaced to Mos (coder3 HELD at design-only until ruling): AC-TESS-05 wants approved capability across Kanban/skills/memory/tools/cron, but AgentRuntimeProvider models only SESSION capabilities. (a) adapter-local Hermes inventory/health marks those as explicit UNSUPPORTED, real ops deferred to their Mosaic-owned plugin contracts (coder3 default, preserves hard no-legacy-core-contract rule); vs (b) an existing Mosaic-owned non-runtime capability contract this adapter must implement. Orchestrator recommends (a) to Mos as the conservative boundary-preserving path. UPDATE 2026-07-13: coder3 PROCEEDED WITH (a) and opened **PR #734** (base=main), head 47b8a145ac43688499d275a54b434a52551c1abd — ahead of the Mos (a/b) ruling (design-hold was placed; coder3's original msg said it would proceed with (a) unless directed). Hermes adapter normalized behind packages/agent boundary; core types unchanged, unsupported ops fail-closed, tests prove no legacy field leak; focused tests/typecheck/lint pass; cold-cache turbo typecheck+build 46/46 0-cached. mergeable=true. CI pipeline 1751 (pull_request, refs/pull/734/head, commit 47b8a145) = **SUCCESS**; head UNMOVED, mergeable=true. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 47b8a145 (Gitea comment 17027) — verified core AgentRuntimeProvider/runtime types UNCHANGED, adapter normalizes Hermes legacy shapes behind packages/agent boundary, unsupported runtime ops FAIL CLOSED via capability_unsupported BEFORE transport side effects (Kanban/skills/memory/tools/cron deferred under option (a)), no live creds, no hardcoded Tess agent identifier. Head UNMOVED, mergeable=true. **MERGEABLE — HARD STOP for Mos merge** (2026-07-13). ⚠️ MERGE GATED on Mos confirming option (a) is accepted (implementation == (a)); if Mos rules (b), #734 needs rework. HARD STOP for Mos merge. | +| TESS-M4-003 | done | Implement memory/retrieval, state/inbox, runtime bootstrap, fleet diagnostics and GitOps plugin foundations | #710 | coder0 | packages/memory, packages/agent, packages/mosaic | feat/tess-operator-plugins | TESS-M3-V | 40K | **MERGED by Mos** → main squash **2363f155** ("feat(memory): add operator retrieval plugin (#736)"), 2026-07-13. ⚠️ SCOPE GAP surfaced by Mos: #736 delivered ONLY the leaf @mosaicstack/memory operator-retrieval slice; **TESS-PLG-001 (packages/mosaic catalog/registration) was silently DEFERRED by the author and never surfaced in MISSION-MANIFEST/VERIFICATION-MATRIX** → now tracked explicitly as its own row (see TESS-PLG-001 below) and folded into TESS-M4-W-001. State/inbox/runtime-bootstrap/fleet-diagnostics/GitOps foundations remain follow-on (not in #736). TESS-MEM-001, TESS-PLG-001. Mos HELD 1 beat (2026-07-13) for a well-conditioned lane. UPDATE 2026-07-13: coder0 TOOK OVER M4-003 (preserved coder4 WIP first, then rebased on latest main) and opened **PR #736** (base=main), head a1d63ca8ed07610828e9c51a213fffe9123b3de4. ⚠️ AUTHORIZATION FLAG to Mos: M4-003 was on Mos 1-beat HOLD; confirm this takeover/dispatch was Mos-authorized before merge. Scope delivered: LEAF @mosaicstack/memory operator retrieval plugin — config-injected adapter/namespace, runtime-validated server-derived tenant/owner/session scope, redaction-before-persist, provenance, bounded startup prioritization, wildcard adapter contract, namespace/different-instance tests. NO gateway/catalog/durable-inbox or command-authorization changes. Forced cold-cache typecheck/lint/format/test green (42 tasks); Woodpecker 1756 green; Codex code+security clean. CI pipeline 1756 (pull_request, refs/pull/736/head, commit a1d63ca8) = **SUCCESS**; mergeable=true. Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head a1d63ca8 (Gitea comment 17044) — leaf packages/memory/doc only (no gateway/catalog/durable-inbox), command-authz byte-identical a9f829e7, runtime scope validation before storage keying, config-injected adapter/namespace/instance metadata, redaction-before-persist + provenance, scoped wildcard adapter contract, namespace/different-instance tests, no live creds, no Tess literal. Head verified UNMOVED at a1d63ca8, base main, mergeable=true. **MERGEABLE — reported to Mos, HARD STOP for Mos merge.** NOTE: M4-003 scope here is the memory-plugin slice; state/inbox/runtime-bootstrap/fleet-diagnostics/GitOps foundations may be follow-on slices — confirm with Mos whether #736 fully closes M4-003 or is slice 1. | +| TESS-M4-W-001 | in-progress | M4-V remediation — gateway reachability SPINE: register runtime provider into AGENT_RUNTIME_PROVIDER_REGISTRY + wire Mos-coordination consumer + wire operator-memory-plugin consumer (make merged M4 deliverables reachable end-to-end); FOLDS IN minimal TESS-PLG-001 catalog/registration | #710 | coder0 | apps/gateway, packages/mosaic, packages/agent | feat/tess-m4w-reachability-spine | TESS-M4-003 | 30K | **Mos-DISPATCHED 2026-07-13** (remediation). Root cause: M4-V holistic review @ origin/main **2363f155** found the three merged M4 deliverables unit-green but NOT reachable end-to-end (no gateway wiring/consumers; providers never registered into the registry). **SPLIT into 3 sub-parts by coder0 (integrity-honest):** **(#2 Mos-coordination consumer) = DELIVERED as PR #737** (head f7b95f60, base main, "feat(gateway): expose Mos coordination boundary") — real AuthGuard Mos handoff/observe/result consumer, authenticated actor/tenant + required correlation derivation, service authority unchanged, gateway target test/typecheck/lint pass; **CI 1758 SUCCESS** (repo 47, commit==head); head verified UNMOVED at f7b95f60666a4abbbad9a08669637b19fa87c430, base main, mergeable=true. **Independent non-author ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head f7b95f60 (Gitea comment 17054) — clean partial scope confirmed (AuthGuard Mos handoff/observe/result controller + module registration only; no runtime-provider registration / operator-memory consumer; actor/tenant from CurrentUser/scopeFromUser + required X-Correlation-Id before service invocation; MosCoordinationService unchanged; command-authz byte-identical a9f829e7; no live creds/no Tess literal). **#737 MERGEABLE — reported to Mos, HARD STOP for Mos merge (partial slice; land-vs-hold-for-full-spine is Mos's disposition call).** **(#1 runtime-provider registration) + (operator-memory consumer) = BLOCKED, NOT in #737.** coder0 could not truthfully complete them in this slice and REFUSED to fake with deny/unavailable stubs: gateway has **no concrete Hermes transport** and **no gateway-side tmux transport/authority wiring** to register a real provider; OperatorMemory consumer needs **session tenant/owner/session propagation currently ABSENT from AgentService's memory-tools boundary**. ⚠️ **DESIGN RULING ESCALATED TO MOS** (architecture, not resolvable from repo): how to wire provider-registration + memory-scope propagation when no concrete transport exists yet — new remediation slice / re-scope / accept #737 as incremental. TESS-PLG-001 (folded here) is part of the blocked #1 registration path. Command-authz byte-identical a9f829e7. **UPDATE 2026-07-13: #737 MERGED by Mos → main e2376190 ("feat(gateway): expose Mos coordination boundary (#737)").** **Operator-memory consumer sub-part UNBLOCKED + DELIVERED as PR #739** ("feat(memory): bind operator plugin to agent sessions", base main off e2376190, live head 31a59738089f0784428833fc5a0192c6c7c43261, mergeable=true) — coder0 resolved the session-scope-propagation blocker WITHOUT stubbing: gateway bootstrap configures plugin only with MOSAIC_OPERATOR_MEMORY_INSTANCE_ID + MOSAIC_OPERATOR_MEMORY_NAMESPACE, AgentService derives {tenantId,ownerId,sessionId} server-side and binds search/capture tools. Cold-cache root typecheck/lint/format/test (42 tasks) green; security review clean (Codex Optional-import finding = false positive, pre-existing, typecheck passed). **CI 1764 SUCCESS** (repo 47, commit==head); head verified UNMOVED at 31a59738089f0784428833fc5a0192c6c7c43261, base main, mergeable=true. **Independent non-author ROR ROUTED to reviewer at exact head 31a59738089f** (coder0 authored → reviewer is non-author) — asked reviewer to confirm scope is server-derived/non-client-controllable + no cross-tenant leak, and to independently verify the Codex Optional-import finding is a false positive. (Head reconcile CLOSED: coder0 confirmed 31a597380c55… was a transcription typo; live+frozen head is 31a59738089f0784428833fc5a0192c6c7c43261, working tree clean.) **UPDATE 2026-07-13: reviewer REQUEST CHANGES at head 31a59738089f (Gitea comment 17069) — NOT mergeable.** Production code CONFIRMED correct (plugin route wired, config env namespace/instance only, no live creds/no Tess literal, command-authz byte-identical a9f829e7; Codex Optional-import finding = false positive, import present). **Two TEST-COVERAGE blockers:** (1) tests BYPASS production scope derivation — they call createMemoryTools with a PREBUILT scope, never exercising the real createSession→buildToolsForSandbox server-side {tenantId,ownerId,sessionId} derivation; (2) NO divergent cross-tenant/cross-owner ISOLATION/DENIAL test proving a foreign actor cannot reuse a session / reach another operator-memory scope before the plugin call. Routed back to coder0 (integrity: harden real coverage, do NOT weaken assertion). Any new commit MOVES head → invalidates ROR → re-serialize CI + re-ROR at new head. **UPDATE 2026-07-13 (remediated): coder0 pushed hardened tests, NEW frozen head c26b3b775279575276c6ebe8955a9146bfc61413** — added createSession→buildToolsForSandbox PRODUCTION-PATH assertion of derived {tenantId,ownerId,sessionId}; added foreign-actor reuse DENIAL test asserting rejection occurs BEFORE scope/tool construction and before any plugin call. Cold-cache root typecheck/lint/format/test green (42 tasks). Old ROR at 31a59738089f + CI 1764 SUPERSEDED. Re-serialized: **CI 1765 SUCCESS** at c26b3b775279 (ref refs/pull/739/head, commit==head); head verified UNMOVED at c26b3b775279575276c6ebe8955a9146bfc61413, base main, mergeable=true. **Fresh independent non-author ROR RE-ROUTED to reviewer at exact head c26b3b775279** — asked reviewer to confirm both 17069 blockers genuinely closed (prod-path derivation exercised + cross-tenant denial before plugin call, assertion not weakened). **Independent non-author re-ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head c26b3b775279 (Gitea comment 17074) — both 17069 blockers CONFIRMED closed: production createSession→buildToolsForSandbox scope-derivation test asserts {tenantId,ownerId,sessionId}; foreign-scope reuse rejects BEFORE tool construction and BEFORE plugin search/capture; production wiring reachable via MemoryModule env-configured plugin → AgentService injection → memory_search/memory_save_insight plugin path; command-authz byte-identical a9f829e7; Optional import present; no live creds/no Tess literal. Head verified UNMOVED at c26b3b775279, base main, mergeable=true. **#739 MERGEABLE — reported to Mos, HARD STOP for Mos merge.** This lands the operator-memory-consumer sub-part of W-001; REMAINING W-001 gap = only (#1) runtime-provider registration. **REMAINING blocked: (#1) runtime-provider registration into AGENT_RUNTIME_PROVIDER_REGISTRY** — still needs Mos A/B/C design ruling (no concrete Hermes transport yet). So after #739 lands, W-001 = Mos-consumer (#737 merged) + memory-consumer (#739) DONE; only the provider-registration linchpin remains. **UPDATE 2026-07-13: #739 MERGED by Mos → main squash 3378b857eb ("feat(memory): bind operator plugin to agent sessions (#739)"); post-merge main push pipeline 1766 running. W-001 spine now 2-of-3 sub-parts MERGED (Mos-consumer #737 e2376190 + operator-memory-consumer #739 3378b857); ONLY remaining W-001 gap = (#1) runtime-provider registration into AGENT_RUNTIME_PROVIDER_REGISTRY — still BLOCKED on Mos A/B/C design ruling (no concrete Hermes transport; TESS-PLG-001 folded here). coder0 idle/ready to build #1 on ruling.** **UPDATE 2026-07-13: (#1) DELIVERED as PR #740 "feat(gateway): register Hermes runtime provider"** (base main 3378b857, exact live head 127a69ea11ccc36516c78c2007cbe52fbf63ad30 verified unmoved, mergeable=true). coder0 resolved the A/B/C escalation by BUILDING a concrete transport (⚠️ design-direction flagged to Mos for confirm-before-merge): agent.module.ts explicit registry.register(new HermesRuntimeProvider(new GatewayHermesRuntimeTransport())); GatewayHermesRuntimeTransport = server-configured URL+service token, HTTPS-except-loopback, prefixed-URL preserving, forwards full scope incl channel; AuthGuard interaction transitional-capabilities route through RuntimeProviderService + live controller→service→registered-provider reachability test. Cold-cache typecheck/lint/format/test green (42 tasks); Codex path-prefix+channel-header findings remediated, security clean. **CI pipeline 1767 (repo 47, refs/pull/740/head, commit==head) = SUCCESS**; head verified UNMOVED at 127a69ea11ccc36516c78c2007cbe52fbf63ad30 post-CI, base main, mergeable=true. **Independent non-author ROR ROUTED to reviewer at exact head 127a69ea11cc** (coder0 authored → reviewer non-author) — asked reviewer to verify REAL E2E reachability (provider actually in registry + reachability test exercises registered provider, not mock), transport security (HTTPS-except-loopback, no token leak), command-authz byte-identical a9f829e7, no live creds/no Tess literal, Codex findings genuinely remediated. Awaiting reviewer disposition; any new commit moves head → re-serialize + re-ROR. **UPDATE 2026-07-13: reviewer REQUEST CHANGES at head 127a69ea11cc (Gitea comment 17088) — NOT mergeable.** CI 1767 green; command-authz byte-identical a9f829e7 CONFIRMED; production positives CONFIRMED (module factory registers Hermes provider; concrete transport HTTPS/prefix/channel headers; no live creds/no Tess literal). **Blocker (reachability-integrity):** the required live-guarded reachability proof is MISSING — test directly calls controller.transitionalCapabilities + manually constructs RuntimeProviderService/createGatewayRuntimeProviderRegistry; it does NOT exercise live GET /api/interaction/:agentName/transitional-capabilities, Nest DI through AgentModule, or the AuthGuard request path, so it can pass even if injected gateway registry/route wiring is broken (defeats the M4-V E2E-reachability point). Routed back to coder0 (integrity: add genuine Nest-e2e live-guarded reachability test through real DI+route+AuthGuard asserting reach of the registered Hermes provider; do NOT weaken/stub/mock around it; keep command-authz a9f829e7). Old ROR 17088 + CI 1767 will be SUPERSEDED by the remediation head → re-serialize CI + re-ROR at new head. **UPDATE 2026-07-13 (remediated): coder0 pushed the live-guarded reachability test, NEW frozen head a7e5d377e38b40275884a7df6ee35c55c5859e43** (live Gitea head independently verified, base main 3378b857, mergeable=true) — added apps/gateway/src/agent/hermes-runtime-reachability.e2e.test.ts: imports REAL AgentModule (preserves actual AGENT_RUNTIME_PROVIDER_REGISTRY factory + RuntimeProviderService), boots Fastify/Nest, unauth HTTP GET /api/interaction/Nova/transitional-capabilities?provider=runtime.hermes asserts 401 via ACTUAL AuthGuard, authed GET asserts 200 + all five Hermes entries, asserts DI registry resolves HermesRuntimeProvider; only unrelated peripheral modules harness-replaced to avoid DB/queue startup — NO route/guard/DI-registry/runtime-service/provider mock; existing controller unit test retained; command-authz untouched (byte-identical a9f829e7 remains). Cold-cache root typecheck/lint/format/test green 42/42 (gateway 53 files/606 tests). Old ROR 17088 + CI 1767 SUPERSEDED. Re-serializing: **CI 1768 (repo 47, refs/pull/740/head, commit==head a7e5d377) running** — poll in flight; on green → re-route non-author ROR at exact head a7e5d377. **UPDATE 2026-07-13: CI 1768 SETTLED SUCCESS** (repo 47, refs/pull/740/head, commit==head a7e5d377e38b40275884a7df6ee35c55c5859e43); head independently verified UNMOVED at a7e5d377 (live Gitea, NOT worker-reported), base main 3378b857, mergeable=true. **Independent non-author re-ROR COMPLETE: reviewer VERIFIED APPROVE at exact head a7e5d377e38b40275884a7df6ee35c55c5859e43 (Gitea comment 17094).** Prior 17088 blocker CONFIRMED closed — the new hermes-runtime-reachability.e2e.test.ts boots real Nest/Fastify AgentModule and exercises unauth 401 via the ACTUAL AuthGuard + authed HTTP GET /api/interaction/:agentName/transitional-capabilities through the live route→controller→RuntimeProviderService→registered Hermes provider, and asserts DI registry resolves HermesRuntimeProvider (no route/guard/DI/service/provider mock); transport concrete, HTTPS-except-loopback, path-prefix + channel header covered; command-authz byte-identical a9f829e7 CONFIRMED; no live creds/no Tess literal. Head verified UNMOVED at a7e5d377, base main, mergeable=true. **#740 MERGEABLE — the (#1) runtime-provider-registration linchpin — reported to Mos, HARD STOP for Mos merge.** ⚠️ Design-direction (concrete GatewayHermesRuntimeTransport built to resolve the A/B/C escalation) flagged to Mos for confirm-before-merge. On #740 merge, W-001 spine = 3-of-3 sub-parts landed (Mos-consumer #737 + memory-consumer #739 + provider-registration #740) → M4-V re-fire eligible. **UPDATE 2026-07-13: #740 MERGED by Mos → main b7b0f508 ("feat(gateway): register Hermes runtime provider (#740)"). W-001 SPINE NOW 3-OF-3 MERGED (Mos-consumer #737 e2376190 + operator-memory-consumer #739 3378b857 + provider-registration linchpin #740 b7b0f508) — the M4-V reachability remediation code work is COMPLETE. GATE: TESS-M4-V re-fire is now eligible and Mos-owned — this row stays in-progress until M4-V re-fires green (unit-green was never the bar; end-to-end reachability is). ⚠️ main push pipeline 1772 (for the #740 merge to main) FAILED at the `build` step — quality gates (typecheck/lint/format/test) all GREEN, failure is downstream at build/publish (recurring infra/ENOSPC pattern); flagged to Mos as Mos-owned, does not block docs-only PRs. Prior doc-sync ledger PR #741 MERGED → main f40e6ba3 ("docs(tess): sync M4 tracking to merged reality (M4 in-progress / gate-pending)"); ledger writes resumed on fresh branch docs/tess-ledger-sync-m2 off f40e6ba3. **UPDATE 2026-07-13: consolidated ledger-sync PR #743 (branch docs/tess-ledger-sync-m2, head aa3925510d06, reviewer VERIFIED APPROVE 17123, CI 1775 SUCCESS) MERGED by Mos → main c6e3cfbdf... ; ledger writes resumed on fresh branch docs/tess-ledger-sync-m3 off main 6345dbfc (post-#744 merge). **UPDATE 2026-07-13: ledger-sync m3 PR #745 MERGED by Mos → main e72388b2 ("docs(tess): ledger sync m3 — M5-001 + M5-002 done (#745)"); mission issue #706 preserved OPEN (Refs #706 non-closing). Ledger writes resumed on fresh branch docs/tess-ledger-sync-m4 off main bc8016c8 (post-#746 merge) recording M5-003 done.** | +| TESS-M4-W-002 | done | M4-V remediation — Hermes capability MATRIX (AC-TESS-05): approved-capability coverage across Kanban/skills/memory/tools/cron for the Hermes adapter | #710 | coder3 | packages/agent, apps/gateway | feat/tess-m4w-hermes-matrix | TESS-M4-002 | 22K | **Mos-DISPATCHED 2026-07-13** (remediation, in flight). Extends the M4-002 option-(a) adapter (merged 9e5b9188) with the AC-TESS-05 capability matrix. UPDATE 2026-07-13: coder3 STARTED — fresh worktree off origin/main 2363f155, TDD failing-matrix-tests-first. Orchestrator TRACKS; on PR-open → serialize CI + independent non-author ROR at EXACT head → HARD STOP for Mos merge. No legacy schema into core contracts; command-authz byte-identical a9f829e7. UPDATE 2026-07-13: **PR #738 OPENED** (base main, head 582c6db2088223fd8dd2105005391b5034c992ac, "feat(agent): add Hermes transitional capability matrix") — normalized exhaustive five-entry matrix (kanban/skills/memory/tools/cron), all explicit unsupported, fails CLOSED before transport; tests 4/4, security review clean, cold-cache 46 successful/0 cached, normalized optional TransitionalCapabilityInventoryProvider (no legacy schema). **CI 1759 SUCCESS** (repo 47, commit==head); head verified UNMOVED at 582c6db2, base main, mergeable=true. **Independent non-author ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head 582c6db2 (Gitea comment 17057) — normalized exhaustive five-entry transitional matrix (kanban/skills/memory/tools/cron) all unsupported; assertTransitionalCapability fails CLOSED with capability_unsupported before Hermes transport; only normalized optional TransitionalCapabilityInventoryProvider added to core (no legacy schema leak); command-authz byte-identical a9f829e7; no live creds/no Tess literal. Head verified UNMOVED at 582c6db2, base main, mergeable=true. **#738 MERGEABLE — reported to Mos, HARD STOP for Mos merge.** This is the COMPLETE matrix deliverable (unlike #737's partial spine). **UPDATE 2026-07-13: #738 MERGED by Mos → merge_commit cca6aaf9. TESS-M4-W-002 DONE.** | +| TESS-PLG-001 | in-progress | packages/mosaic plugin catalog / registration (operator plugins registered + discoverable) — was silently deferred by M4-003 author; now VISIBLE | #710 | coder0 | packages/mosaic | feat/tess-m4w-reachability-spine | TESS-M4-003 | (folded) | ⚠️ Surfaced by Mos 2026-07-13 as an invisible gap: M4-003/#736 delivered the memory plugin but NOT its catalog/registration in packages/mosaic; never appeared in MISSION-MANIFEST/VERIFICATION-MATRIX. PLACEMENT DECISION (orchestrator, per Mos "your call"): **FOLD minimal registration into TESS-M4-W-001** (coder0's reachability spine already does registry wiring — same author closes their own gap, keeps it in one lane). This row exists for LEDGER VISIBILITY so the gap is tracked, not re-hidden. If M4-W-001 scope grows too large, split back out as a standalone lane. Manifest/matrix update to follow. | +| TESS-M4-V | failed | Cross-provider capability, privacy, authority and failure-path qualification | #710 | sonnet | apps/gateway/src/**tests**/integration, packages/agent | review/tess-m4 | TESS-M4-001,TESS-M4-002,TESS-M4-003,TESS-M4-W-001,TESS-M4-W-002 | 22K | **FAILED 2026-07-13** — independent holistic review @ origin/main **2363f155**: all three M4 deliverables (#734/#735/#736) unit-green but **NOT reachable end-to-end** (providers never registered into AGENT_RUNTIME_PROVIDER_REGISTRY; Mos-coordination + operator-memory consumers unwired; TESS-PLG-001 catalog/registration silently deferred). Remediation TESS-M4-W (W-001 spine coder0 + W-002 Hermes matrix coder3) now in flight. **Mos re-fires M4-V ONLY after the spine + matrix land.** Gate M5 (M5 stays behind M4-V; live-deploy = Jason-reserved). | +| TESS-M5-001 | done | Implement Matrix/native runtime provider behind common contracts and parity suite | #711 | coder0 | packages/mosaic, packages/agent | feat/tess-matrix-provider | TESS-M4-V | 30K | TESS-TRN-001. **Mos-DISPATCHED to coder0 2026-07-13** (advancing to M5, same M4-V dependency-reconciliation caveat as M5-002). Design sketch (branch feat/tess-matrix-provider off origin/main b7b0f508): MatrixNativeRuntimeProvider in packages/agent over a narrow MatrixRuntimeTransport contract + MatrixNativeRuntimeTransport in packages/mosaic (Mosaic adapter owns Matrix HTTP/auth/identity/room mechanics; agent provider owns common provider behavior only). Parity suite runs the SAME provider-contract scenarios against factory fixtures for existing tmux/fleet AND Matrix/native; Matrix native declares only operations concretely wired (no fake reachability, no Matrix default promotion); no gateway/Discord changes; command-authz to remain byte-identical a9f829e7. **In TDD — no PR yet.** On PR-open: freeze head → serialize CI (one-at-a-time on repo 47) → independent non-author ROR at exact head → HARD STOP for Mos merge. **UPDATE 2026-07-13: DELIVERED as PR #744 (7 files packages/agent + packages/mosaic only) frozen head b4fcf139a73678e9e59c8f6b63c108c095a87b3a; CI pipeline 1776 SUCCESS (repo 47, refs/pull/744/head, commit==head); independent non-author ROR COMPLETE — reviewer VERIFIED APPROVE at exact head b4fcf139a736 (Gitea comment 17126): Matrix stays NON-DEFAULT (no gateway/Discord/registry wiring), default-deny read/write authority, immutable read handles, control-attach rejection, parity suite runs same scenarios against tmux/fleet AND Matrix/native, concrete Matrix CS-API HTTPS transport with whoami/remote-identity-filter/deterministic txns, no live creds, command-authz byte-identical a9f829e7. #744 MERGED by Mos → main 6345dbfcf262. Deliverable code LANDED. GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending (this row was dispatched ahead of M4-V passing).** | +| TESS-M5-002 | done | Complete migration inventory, cutover, rollback, retention and deprecation evidence | #711 | coder3 | docs/tess | feat/tess-migration-docs | TESS-M4-V | 18K | TESS-MIG-001. **Mos-DISPATCHED to coder3 2026-07-13** ("M4 complete; advancing to M5") — dispatched AHEAD of TESS-M4-V passing; the M4-V-status-vs-#710-CLOSED dependency reconciliation is pending Mos ruling (tracked, not orchestrator-decided). **DELIVERED as PR #742** — 4 new files docs/tess/M5-MIGRATION-{INVENTORY,CUTOVER,ROLLBACK,RETENTION-DEPRECATION}.md, base main b7b0f508, frozen head b5e9d0e528a50aae2e916cc7202bacc2e8db67dd. Docs-only; tracking-control trio (MISSION-MANIFEST/TASKS/VERIFICATION-MATRIX) UNTOUCHED; command-authz byte-identical a9f829e7; no live creds. **CI pipeline 1773 SUCCESS** (repo 47, refs/pull/742/head, commit==head). **Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head b5e9d0e528a50aae2e916cc7202bacc2e8db67dd (Gitea comment 17108)** — evidence claims verified to trace to landed Hermes adapter / capability matrix, gateway registry/reachability, operator-memory scope path, Mos coordination boundary; docs do NOT over-claim transcript/profile import, schema migration, unsupported-capability enablement, production cutover, or deprecation completion. Head independently verified UNMOVED at b5e9d0e528a5 post-ROR (live Gitea), base main, mergeable=true. **#742 MERGED by Mos → main 5789711e. Deliverable docs LANDED. GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending (this row was dispatched ahead of M4-V passing).** | +| TESS-M5-003 | done | Complete OpenAPI, user/admin/developer/plugin/operations docs and checklist | #711 | codex | docs | feat/tess-docs | TESS-M5-001,TESS-M5-002 | 22K | Documentation hard gate. **DELIVERED as PR #746** (branch feat/tess-docs, base main, 7 docs-only files: docs/openapi-tess.yaml + docs/tess/{ADMIN,DEVELOPER,OPERATIONS,PLUGIN,USER}-GUIDE.md + M5-003-DOCUMENTATION-CHECKLIST.md). 4-round revise-loop (heads 470eb911→c9f69300→7aea94e2→25b9d642) converged: OpenAPI covers interaction routes + SSE /sessions/{sessionId}/stream + Mos coord (/api/coord/mos/handoff,/observe,/result) + memory preferences/insights/search; request-body schemas aligned to real DTOs (Send requires content+idempotencyKey, Stop requires approvalRef, Insight requires only content, MosHandoff body requires idempotencyKey+summary); checklist accurate. **CI pipeline 1786 SUCCESS** (repo 47, refs/pull/746/head, commit==head 25b9d642). **Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head 25b9d642b939014b3efd61826e7524cafc6ffc2e (Gitea comment 17170)** — docs-only, tracking-trio untouched, command-authz byte-identical a9f829e7, no false coverage claims. Head verified UNMOVED at 25b9d642 (live Gitea, not worker-reported), base main, mergeable=true. **#746 MERGED by Mos → main bc8016c8314ec3a4b6ebc2fec5d9f276fca3327a. Documentation gate LANDED.** GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending. | +| TESS-M5-V | not-started | Full baseline, contract, integration, Discord/CLI E2E, security review, recovery drill and rollback qualification | #711 | sonnet | apps/gateway, packages/agent, plugins/discord, packages/mosaic | review/tess-final | TESS-M5-003 | 35K | Maps AC-TESS-01..11 to evidence | +| MOS-PORT-M1-001 | in-progress | Implement logical Mos identity, PostgreSQL connector lease, monotonic fencing, server-bound execution grants, audit, migrations, concurrency/restart/abuse/integration tests | #755 | codex | packages/types, packages/agent, packages/db, apps/gateway | feat/mos-logical-identity-fencing | — | 38K | Requirements MOS-PORT-ID-001, MOS-PORT-LEASE-001, MOS-PORT-FENCE-001..002, MOS-PORT-OBS-001, MOS-PORT-ARCH-001. One Sol/Pi worker; TDD; PR-open STOP; worker must not edit this ledger. | diff --git a/docs/tess/THREAT-MODEL.md b/docs/_old_structure/tess/THREAT-MODEL.md similarity index 100% rename from docs/tess/THREAT-MODEL.md rename to docs/_old_structure/tess/THREAT-MODEL.md diff --git a/docs/tess/USER-GUIDE.md b/docs/_old_structure/tess/USER-GUIDE.md similarity index 100% rename from docs/tess/USER-GUIDE.md rename to docs/_old_structure/tess/USER-GUIDE.md diff --git a/docs/tess/VERIFICATION-MATRIX.md b/docs/_old_structure/tess/VERIFICATION-MATRIX.md similarity index 100% rename from docs/tess/VERIFICATION-MATRIX.md rename to docs/_old_structure/tess/VERIFICATION-MATRIX.md diff --git a/docs/tess/hermes-runtime-adapter-design.md b/docs/_old_structure/tess/hermes-runtime-adapter-design.md similarity index 100% rename from docs/tess/hermes-runtime-adapter-design.md rename to docs/_old_structure/tess/hermes-runtime-adapter-design.md diff --git a/docs/tess/qualification/2026-07-14-option2-runtime-portability.md b/docs/_old_structure/tess/qualification/2026-07-14-option2-runtime-portability.md similarity index 100% rename from docs/tess/qualification/2026-07-14-option2-runtime-portability.md rename to docs/_old_structure/tess/qualification/2026-07-14-option2-runtime-portability.md diff --git a/docs/reports/qa/gateway-security-20260313.md b/docs/reports/qa/gateway-security-20260313.md deleted file mode 100644 index 9de49055..00000000 --- a/docs/reports/qa/gateway-security-20260313.md +++ /dev/null @@ -1,39 +0,0 @@ -# QA Report — Gateway Security Hardening - -## Scope - -- Chat HTTP auth guard hardening -- Chat WebSocket session validation -- DTO validation rules for chat and conversation payloads -- Ownership regression coverage for by-id routes - -## TDD - -- Required: yes -- Applied: yes -- Red step: targeted tests failed on socket session reshaping and DTO role/length mismatches -- Green step: targeted tests passed after runtime and DTO alignment - -## Baseline Verification - -| Command | Result | Evidence | -| --- | --- | --- | -| `pnpm --filter @mosaicstack/gateway test -- src/chat/__tests__/chat-security.test.ts src/__tests__/resource-ownership.test.ts` | pass | 3 test files passed, 20 tests passed | -| `pnpm typecheck` | pass | turbo completed 18/18 package typecheck tasks | -| `pnpm lint` | pass | turbo completed 18/18 package lint tasks | -| `pnpm format:check` | pass | `All matched files use Prettier code style!` | - -## Situational Verification - -| Acceptance Criterion | Verification Method | Evidence | -| --- | --- | --- | -| Chat controller requires auth and current-user context | source assertion test | `chat-security.test.ts` checks `@UseGuards(AuthGuard)` and `@CurrentUser() user: { id: string }` | -| WebSocket handshake requires Better Auth session | unit tests for `validateSocketSession()` | null handshake returns `null`; valid handshake returns original session object | -| Conversation messages reject non-user/assistant roles | class-validator test | `system` role fails validation | -| Conversation messages enforce a 32k max length | class-validator test | `32_001` chars fail validation | -| Chat request payload enforces a 10k max length | class-validator test | `10_001` chars fail validation | -| By-id routes reject cross-user access | ownership regression tests | conversations, projects, missions, tasks each raise `ForbiddenException` for non-owner access | - -## Residual Risk - -- No live HTTP or WebSocket smoke test against a running gateway process was executed in this session. diff --git a/docs/reports/security/756-security-review.md b/docs/reports/security/756-security-review.md deleted file mode 100644 index 8f124ccc..00000000 --- a/docs/reports/security/756-security-review.md +++ /dev/null @@ -1,37 +0,0 @@ -# Security Review — Issue #756 - -**Scope:** final current uncommitted Discord plugin, shared channel contract, gateway ingress, AgentService, and plugin registration delta -**Snapshot:** `plugins/discord/src/index.ts` SHA-256 `5ee6b6aa4e2ff349f137f76b918d02c1254e12066cb48b136048e57bef36fdb2` -**Verdict:** **APPROVE** - -## Final remediation verification - -| Area | Current evidence | Result | -|---|---|---| -| Attachment confidentiality and integrity | Ingress accepts bounded attachment metadata only when URL is HTTPS, query-free, fragment-free, and credential-free. Count, aggregate size, field length, MIME, and finite non-negative size validation apply before dispatch; `sizeBytes` is signed and retained. | Pass | -| Trusted agent selection | Each binding names a required trusted `agentConfigId`; gateway resolves that config server-side and requires its configured name to equal the binding logical-agent ID. Client/provider input cannot select the agent for Discord ingress. | Pass | -| Privileged operation routing | Gateway revalidates the binding and requires the signed conversation identity to match the configured logical agent before approve/stop actions. Paired admin identity and one-time approval checks remain enforced. | Pass | -| Egress containment and delivery | Egress requires an aligned message/route, configured parent or exact observed thread target, and cleans response routes after completion, errors, typed-ingress failure, or bounded-map pressure. | Pass | -| Side-effect limits | Per guild/authorized-parent/user rolling message and thread limits execute before thread creation or dispatch. | Pass | - -## Security controls reviewed - -- Default-deny guild, parent-channel, user, configured pairing, and role checks precede rate consumption and all side effects. -- Gateway independently enforces Discord service authentication, HMAC integrity, allowlists, binding/role checks, attachment validation, and replay-ID rejection. -- Thread authorization uses only the Discord thread parent; category parents cannot authorize ingress. -- Agent-visible attachment references are explicitly labeled untrusted; binary content is not embedded. Persisted attachment name/URL values are redacted. -- Egress uses deterministic nonces, bounded transient retry, typed terminal errors, and does not send to forged targets. -- No secrets or message content were added to plugin logs. - -## Verification evidence - -| Command | Result | -|---|---| -| `pnpm --filter @mosaicstack/discord-plugin test` | PASS — 44 tests; v8 coverage: 92.18% statements/lines, 86.55% branches, 100% functions | -| `pnpm --filter @mosaicstack/discord-plugin typecheck` | PASS | -| `pnpm --filter @mosaicstack/types typecheck` | PASS | -| `pnpm --filter @mosaicstack/gateway typecheck` | PASS | -| `pnpm --filter @mosaicstack/gateway exec vitest run src/plugin/discord-ingress.security.spec.ts src/agent/__tests__/agent-service-ownership.test.ts` | PASS — 29 tests | -| `git diff --check` | PASS | - -No unresolved critical, high, medium, or low security findings were identified in the reviewed final delta. diff --git a/docs/tess/TASKS.md b/docs/tess/TASKS.md deleted file mode 100644 index 6becd141..00000000 --- a/docs/tess/TASKS.md +++ /dev/null @@ -1,46 +0,0 @@ -# Tasks — Tess Interaction Agent - -> Mission: `tess-20260712` · Issue: #706 · PRD requirements: `TESS-*` -> Orchestrator is sole writer. Workers must not modify this file. -> `repo` contains one or more comma-separated repository-relative roots; every listed root must exist before dispatch. -> **BASE CONVENTION (Mos-locked 2026-07-12):** EVERY M1 dispatch targets `base=main` and branches from fresh `origin/main`. Do NOT base on `feat/tess-interaction-agent` — that is the STALE planning branch (merged via #712); basing on it yields `mergeable=False` + intervening-commit noise (cf. #723/SEC-005 re-base). Every dispatch brief must state base=main + branch-from-origin/main. - -| id | status | description | issue | agent | repo | branch | depends_on | estimate | notes | -| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| TESS-PLAN-001 | done | Finalize PRD, architecture, authority boundary, threat model, migration inventory, and verification matrix | #706 | sonnet | docs, packages/types, apps/gateway | feat/tess-interaction-agent | — | 22K | Independent gate PASS after two remediation rounds; completion effective when planning PR merges | -| TESS-M1-SEC-001 | done | Enforce command scopes/roles and durable exact-action approval for privileged/destructive commands | #707 | codex | apps/gateway | fix/tess-command-authz | TESS-PLAN-001 | 25K | TESS-SEC-002; diskhygiene-terra; PR #718 head e3d98d73 MERGED (ROR 16829) | -| TESS-M1-SEC-002 | done | Enforce owner/tenant binding on session list/read/attach/send/terminate across REST and WS | #707 | codex | apps/gateway | fix/tess-session-ownership | TESS-PLAN-001 | 30K | TESS-SEC-003; coder0; PR #715 head 43ffbe7b MERGED (ROR 16808) | -| TESS-M1-SEC-003 | done | Bind MCP actor/tenant to authenticated context and add per-tool scopes | #707 | codex | apps/gateway | fix/tess-mcp-identity | TESS-PLAN-001 | 22K | TESS-SEC-004; coder1; PR #717 head 9ab776f9 MERGED (ROR 16819) | -| TESS-M1-SEC-004 | done | Add authenticated Discord service ingress, allowlists, correlation and replay protection | #707 | codex | plugins/discord, apps/gateway | fix/tess-discord-ingress | TESS-PLAN-001 | 28K | TESS-SEC-005; coder4; PR #716 head 55ae77b6 MERGED (ROR 16830) | -| TESS-M1-SEC-005 | done | Redact/classify secret and PII before persistence/egress; harden provider login flow | #707 | codex | apps/gateway, packages/log | fix/tess-redaction | TESS-PLAN-001 | 28K | TESS-SEC-006; coder1 (Mos-routed from blocked wrapfix-terra); mis-based #723 CLOSED superseded. MERGED to main: PR #725 head 726f7ab7 (ROR 16880). Verified chat persistence + egress redaction hooks; canary tests split-secret/private-key/overflow/persistence classification; provider login no auth URL/raw token in chat output | -| TESS-M1-SEC-006 | done | Scope session GC/retention or separate authorized global retention job | #707 | codex | apps/gateway, packages/log | fix/tess-session-gc-scope | TESS-PLAN-001 | 18K | TESS-SEC-009; coder4; PR #720 base=main. MERGED to main: head 37be090e (ROR 16861). Both blockers fixed: glob metachar sessionIds escaped+regression; durable approval survives GC pass (create→GC→key remains→authz succeeds); /gc disabled, per-session log demotion, no fullCollect/sweepOrphans entry, legacy repeatable GC schedule removed | -| TESS-M1-001 | done | Define AgentRuntimeProvider, capabilities, session tree, normalized stream events/errors, attach semantics | #707 | codex | packages/types, packages/agent | feat/tess-runtime-contract | TESS-PLAN-001 | 25K | TESS-ARP-001, TESS-TRN-001; wrapfix-terra; PR #719 head 5c42e67f MERGED (ROR 16813) | -| TESS-M1-002 | done | Implement provider registry/service with immutable actor scope, approval, audit and correlation boundaries | #707 | codex | apps/gateway, packages/agent | feat/tess-provider-registry | TESS-M1-001,TESS-M1-SEC-001,TESS-M1-SEC-002,TESS-M1-SEC-003 | 30K | TESS-SEC-001..004,007; coder0; PR #722 head c529022d MERGED (ROR 16849) | -| TESS-M1-003 | done | Implement tmux/fleet runtime provider and safe attach/message/terminate capability policy | #707 | codex | packages/mosaic, packages/agent | feat/tess-fleet-provider | TESS-M1-002 | 30K | TESS-FLT-001; coder0; PR #724 base=main. MERGED to main: head 355d814f (ROR 16868). HARD BOUNDARY verified: writes/control default-deny before tmux probing unless write authority permits; final exact-target authz after roster/socket/runtime verification; exact target/prefix/runtime-drift tests; read-only attach with immutable scope handles; empty-msg/default-deny/unverified-target tests; no credential material | -| TESS-M1-OBS-001 | done | Implement correlation propagation, structured runtime/provider/tool audit, health/readiness and safe effective-policy status | #707 | codex | apps/gateway, packages/agent, packages/log | feat/tess-observability-terra | TESS-M1-002 | 24K | TESS-OBS-001; SOLE owner=diskhygiene-terra. MERGED to main at REBASED head: PR #726 head 53f5414 (re-ROR comment 16886, prior 16881@adfa5c06 discarded after head move), CI 1723 green. Both @mosaicstack/log barrel exports coexist (redaction + runtime-audit), metadata-only/SHA-256 audit intact, fail-closed audit-before-side-effects intact, safe status/effective-policy/readiness | -| TESS-M1-V | done | Independent architecture/security review and complete contract/abuse-suite verification | #707 | mos-reviewer | apps/gateway, packages/agent, packages/log, plugins/discord | review/tess-m1 | TESS-M1-SEC-001,TESS-M1-SEC-002,TESS-M1-SEC-003,TESS-M1-SEC-004,TESS-M1-SEC-005,TESS-M1-SEC-006,TESS-M1-003,TESS-M1-OBS-001 | 20K | Gate M2 = PASS (Mos-owned independent non-author reviewer, 2026-07-12): all 5 priority seams verified live, 60+ tests green. M2 (#708) OPEN. Orchestrator did NOT run a competing lane (prior reviewer-lane dispatch recalled). Non-gating follow-up from this review captured as TESS-M1-FUP-001 (execute() authz-error mis-classification), scheduled to land before/with TESS-M3-001 — not now | -| TESS-M1-FUP-001 | not-started | RuntimeProviderService.execute() records provider-thrown authorization errors as failed/provider_error instead of denied/policy_denied | #707 | — | apps/gateway, packages/agent | — | — | 6K | NON-GATING follow-up from M1-V review (2026-07-12). Provider-thrown authz errors (e.g. FleetRuntimeProviderError 'forbidden' from M1-003 write-authority) mis-classify as outcome:'failed'/'provider_error' rather than 'denied'/'policy_denied'. Low-priority. Land BEFORE/WITH TESS-M3-001 fleet-provider registry wiring (#709), NOT now. UPDATE 2026-07-13: did NOT ride in #730; Mos FOLDED this into TESS-M3-003 C4 (authz-error classification + RuntimeApprovalDeniedError→403 filter) — tracked there, land with M3-003. | -| TESS-M2-001 | done | Add Tess roster/profile/service pinned to GPT-5.6 Sol high with fail-fast config and observable effective policy | #708 | coder0 | packages/mosaic | feat/tess-pi-service | TESS-M1-V | 22K | TESS-PI-001; AC-TESS-03. Mos-dispatched directly to coder0. MERGED to main by Mos (2026-07-12): PR #728 head c58e86e2, ROR comment 16905, CI 1728 green. NAME-AS-CONFIG invariant VERIFIED — identity via MOSAIC_AGENT_NAME/%i/roster data, no hardcoded tess identity in impl/service/schema/tool, Tess example-only; Nova distinct-name zero-code-change provisioning test; GPT-5.6 Sol high fail-fast; credential-safe effective-policy output; no live credential material | -| TESS-M2-002 | done | Implement durable session identity, inbox/outbox, approval, checkpoint, handoff, compaction and restart recovery | #708 | coder0 | apps/gateway, packages/agent, packages/db | feat/tess-durable-state | TESS-M2-001 | 38K | TESS-STA-001, TESS-SEC-007..008; recovery TDD. Mos-dispatched directly to coder0 (2026-07-12) — orchestrator tracks, no competing lane. Branch feat/tess-durable-state from fresh origin/main e3b5113b; first recovery TDD packages/agent/src/tess-durable-session.test.ts; reuses existing provider registry + durable approval store. base=main, PR-open-STOP, independent non-author ROR then Mos merges. Next gate after merge = TESS-M2-V (M2→M3 review). PR #729 OPEN (feat(tess): persist durable session state; base=main, mergeable=true, head 102a7b606bd492201e3d731a86397a9cfe4eb998); coder0 pnpm turbo typecheck/lint/test --force 88/88 cold-cache + format green + Codex code/security remediated; scope = durable identity/inbox-outbox idempotency/immutable checkpoints/portable handoffs/PGlite close-reopen recovery/exact one-time approvals/sealed-redacted payloads/scoped dispatch. ROR routed to reviewer lane (non-author) at exact head 102a7b60. CHANGES REQUESTED (reviewer comment 16917 @102a7b60, CI pipeline 1730 RED) — 3 blockers routed to coder0: (1) CI red: gateway PGlite close/reopen durable recovery test TIMEOUT; (2) idempotency compares REDACTED payloads so distinct secrets collapse/collide — key must be over pre-redaction canonical identity; (3) durable schema/approval NAMESPACE hardcoded to tess, violates name-as-config — must derive from configured agent name (Nova zero-code-change). coder0 remediating; head will move → re-ROR required at new exact head. REMEDIATED + re-pushed: new head 444988d23bada28d3cc9ce7e588e18e052f058ff — (1) recovery suite uses one shared PGlite fixture, close/reopen AC completes ~0.5s (was 30s timeout); (2) pre-redaction SHA-256 payload digest added to idempotency conflict checks (distinct secrets no longer collapse); (3) hardcoded tess durable DB objects/approval prefix replaced with generic interaction naming + agent-bound approval namespace. push-hook typecheck/lint/format green; CI pipeline 1731 GREEN on new head 444988d2. Head confirmed unchanged at green SHA; re-ROR routed to reviewer (non-author) at exact head 444988d2 — prior REQUEST CHANGES 16917 void at old head. RE-ROR = REQUEST CHANGES (reviewer comment 16925 @444988d2; CI 1731 green + recovery test passes 1515ms not skipped). 2 residual payload-digest blockers routed to coder0: (1) CHECKPOINT idempotency still collapses — pre-redaction digest fix reached inbox/outbox but NOT checkpoint path; distinct sensitive checkpoint payloads under same sessionId+checkpointId collapse; needs pre-redaction digest column on checkpoint conflict check; (2) digest is UNKEYED plaintext SHA-256 over sensitive payloads → allows offline plaintext confirmation; switch to KEYED HMAC-SHA256 with config-sourced fail-fast secret (never hardcoded/logged), applied to inbox/outbox + checkpoint. coder0 remediating; head will move → re-ROR at new exact head. ROUND-2 REMEDIATED + pushed: new head cbdc38af954d49016b5fdc4a6dab0497317b6a1c — checkpoint now persists pre-redaction HMAC digest; inbox/outbox switched to VERSIONED HMAC; distinct-secret + delimiter-collision regressions added; migration safe for pre-existing checkpoint rows and legacy checkpoints FAIL CLOSED (cannot prove original payload); Codex security review no findings; format/diff green, PGlite recovery executes 1.765s. CI pipeline 1732 TERMINAL GREEN (success) on cbdc38af. RE-ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head cbdc38af954d49016b5fdc4a6dab0497317b6a1c (visible Gitea comment 16933). Head confirmed unchanged at ROR target + PR mergeable=true. Reviewer verified checkpoint HMAC digest + collision regressions, recovery no-duplicate-side-effect, sealed/redacted at-rest payloads, scoped dispatch, agent-bound generic namespace; CI 1732 steps ci-postgres/install/sanitization/typecheck/lint/format/test all green; no merge by reviewer (pr-review wrapper self-approve blocked → recorded as verified PR comment). MERGED to main by Mos — merge_commit 99a2d0fc, final APPROVE at head cbdc38af (3-round reviewer loop 16917→16925→16933). M2 build phase CONVERGED (M2-001 #728 + M2-002 #729). TESS-M2-V (M2→M3 gate, AC-TESS-03/06) now running as Mos-owned independent Sonnet reviewer (same arrangement as M1-V) — orchestrator does NOT launch a competing review lane; Mos reports verdict. On M2-V PASS, M3 (#709) tasks TESS-M3-001/002 unblock. | -| TESS-M2-V | done | Clean-host Pi launch plus model/policy status and restart/compaction/duplicate-side-effect verification | #708 | mos-reviewer | apps/gateway/src/__tests__/integration, packages/mosaic/src | review/tess-m2 | TESS-M2-002 | 18K | Gate M3 = PASS (Mos-owned independent Sonnet reviewer at merged main 99a2d0fc, 2026-07-13). All 5 criteria verified with live test runs: model/policy fail-fast + credential-safe; restart recovery exactly-once; keyed-HMAC pre-redaction idempotency; compaction/handoff survival; name-as-config (interaction_* everywhere, Nova tests). Orchestrator did NOT run a competing lane (same as M1-V). M3 (#709) UNBLOCKED. Non-gating follow-ups from this review captured as TESS-M2-FUP-001/002/003 below. | -| TESS-M2-FUP-001 | not-started | Delete dead unkeyed-sha256 OR-branch in tess-durable-session.repository.ts matchesContentDigest (:417-422) to match strict matchesCheckpointDigest | #708 | — | apps/gateway | — | — | 4K | NON-GATING follow-up from M2-V review (2026-07-13). Dead OR-branch NOT exploitable (all writers hmac:v1:-prefixed, content_digest NOT NULL from migration 0012) but weakens exactness guarantee. Low-priority. SCHEDULE TO LAND WITH M3 work. | -| TESS-M2-FUP-002 | not-started | Add literal approval+compaction combined integration test | #708 | — | apps/gateway/src/__tests__/integration | — | — | 4K | NON-GATING follow-up from M2-V review (2026-07-13). Subsystems currently tested separately; what matters IS covered. OPTIONAL, low-priority. | -| TESS-M2-FUP-003 | not-started | Cosmetic rename pass: 'Tess' in class/file/log names (TessDurableSessionRepository etc.) so Nova deployment logs don't say Tess | #708 | — | apps/gateway, packages/agent | — | — | 5K | NON-GATING follow-up from M2-V review (2026-07-13). Cosmetic only — functional name-as-config already correct (interaction_* data path). Low-priority. SCHEDULE TO LAND WITH M3 work (now M3-003 window). Related cosmetic logged separately as TESS-M2-FUP-004. | -| TESS-M2-FUP-004 | not-started | Cosmetic: sourceLabel ?? 'tess' default literal @packages/agent/src/tmux-fleet-runtime-provider.ts:142 | #708 | — | packages/agent | — | — | 2K | NON-GATING cosmetic follow-up (pre-existing from #722/#724), logged per Mos 2026-07-13. Same class as TESS-M2-FUP-003 (name-as-config cosmetic; functional data path already generic). Low-priority — fold into a cosmetic-rename pass alongside M2-FUP-003. | -| TESS-M3-001 | done | Bind dedicated Tess Discord channel with streaming, threads, attachments, pairing/RBAC and approvals | #709 | coder4 | plugins/discord, apps/gateway | feat/tess-discord | TESS-M2-V,TESS-M1-SEC-004 | 35K | TESS-DSC-001. Mos DIRECT-DISPATCHED to coder4 on feat/tess-discord (base=main, 2026-07-13) — orchestrator is DYOR-loaded so Mos dispatched to avoid double-dispatch; orchestrator TRACKS only, no competing lane. PR-open-STOP, independent non-author ROR then Mos merges. Land TESS-M1-FUP-001 (execute() authz-error mapping) + TESS-M2-FUP-001/003 with this M3 work. PR #730 OPEN (feat(#709): add configured Discord interaction binding; base=main, mergeable=true, head 25ed3676550649d805737ddd97cec08d49873662; config-owned Discord bindings w/ pairing/RBAC, thread metadata, attachments, streaming correlation, authenticated ingress reuse). NOTE: coder4 did not report PR-open to orchestrator; picked up from reviewer ROR. CI pipeline 1734 GREEN on head. ROR = REQUEST CHANGES (reviewer comment 16951 @25ed3676) — 2 functional blockers routed to coder4: (1) THREAD/SUB-SESSION ROUTING: allowedChannelIds check tests the THREAD id before parent-channel binding resolution → thread messages in a bound channel are wrongly rejected; must resolve parent-channel binding FIRST then evaluate allowlist against bound parent + add bound-channel-thread test; (2) APPROVAL NOT WIRED TO M2 DURABLE STORE: Discord approval op defined but no path invokes the durable M2 exact-action approval store (only send wired) — must route Discord approval through the #729 durable exact-action approval surface (one-time/exact-action consume, no replay) + denial + exact-action approval tests. Root-cause fixes only (no allowlist-loosen, no approval stub). coder4 remediating; head will move → re-ROR required at new exact head after CI terminal green. ROUND-1 REMEDIATED + pushed: new head 689d5b68706fd5f5b190b0e4d988efc59fb51acb, CI pipeline 1736 GREEN. RE-ROR = REQUEST CHANGES (reviewer comment 16968 @689d5b68) — 2 residuals routed to coder4: (1) thread allowlist directionally fixed but REQUESTED regression test absent — add explicit 'message in thread of bound channel is ACCEPTED' test; (2) CORE BLOCKER: discord:approve still calls commandExecutor.createApproval (generic slash-command approval), NOT the M2 durable exact-action store — must call createRuntimeTerminationApproval writing agent::command-approval exact-action key (durable one-time consume, no replay), plus Discord one-shot tests: approval consumes exact action once + second attempt rejected, and denial-path rejection. Root-cause only (no aliasing generic path). coder4 remediating; head will move → re-ROR at new exact head after CI terminal green. ROUND-2 REMEDIATED + pushed: head moved (via 34b82bd2), CI green — but ROUND-3 RE-ROR = REQUEST CHANGES (reviewer comment 16973 @34b82bd257154ece2f51d29df698b01150cb9a2b, CI pipeline 1738 green). Progress: discord:approve now CALLS createRuntimeTerminationApproval — but STILL WRONG: it binds the approval to DISCORD_SERVICE_USER_ID + approval-message correlation/channel, making a Discord-SILO record NOT consumable by the CLI/runtime stop exact-action path. CORE M3 AC = ONE durable exact-action approval consumable cross-surface (Discord OR CLI OR runtime); exact-action KEY must be agent::command-approval for the specific pending command/termination action (same key CLI 'mosaic tess stop'/runtime-stop consumes); Discord actor + message correlation belong in METADATA, not the key. Routed to coder4 (round-3): re-key to agent+action; add tests (a) discord:approve happy consumes exact action, (b) SAME approval consumable cross-surface by CLI/runtime stop, (c) one-shot replay rejected, (d) denial rejects, (e) thread-under-parent accept. THIRD round on the same durable-approval seam (16951→16968→16973); reviewer holding cross-surface exact-action boundary firm. coder4 remediating; re-ROR at new exact head after CI terminal green. ROUND-3 REMEDIATED + pushed: head a4c70c5a71a4a73f24f04060a301703ba5ac7530, CI pipeline 1739 GREEN — but ROUND-4 RE-ROR = REQUEST CHANGES (reviewer comment 16978 @a4c70c5a). coder4 OVER-CORRECTED: removed actor/tenant/channel/correlation from runtimeActionDigest/consume (WEAKENS command-authorization exactness — the merged M2 contract digests all 7 fields), still NO Discord-origin consume/terminate path for the minted approval, required Discord-path tests still absent (approve happy+denial, one-shot replay, thread-under-parent accept). ROUND-5 ROUTED to coder4 with the FROZEN merged contract extracted from origin/main:apps/gateway/src/commands/command-authorization.service.ts: runtimeActionDigest is sha256 over EXACTLY {providerId,sessionId,actorId,tenantId,channelId,correlationId,agentName} — do NOT modify/strip (revert round-4 change); consume also re-checks actorId+tenantId, requires approver role=admin, one-shot redis.del; store key interaction:command-approval::. Cross-surface = Discord mint and CLI/runtime stop present the SAME 7 fields of the TARGET pending termination (NOT the Discord message's own channel/correlation, NOT DISCORD_SERVICE_USER_ID); actorId = approving admin's resolved user id. Add the missing Discord-origin consume/terminate invocation (via runtime-approval-verifier.ts adapter) + 5 tests. FOURTH round same seam (16951→16968→16973→16978); reviewer holding boundary firm. coder4 remediating; re-ROR at new exact head after CI terminal green. ROUND-5: writer RE-ROUTED coder4→coder0 (Mos-dispatched follow-up; coder0 is original author of the M2 durable approval store, so the ideal lane to wire the Discord path to it — orchestrator did not have this re-route tracked, flagged to Mos for confirmation, single-writer stand-down requested from coder4). coder0 pushed head 6af68e76de3657d837875b1c9d0f5c9678429e59 (branch tip confirmed), CI Woodpecker pipeline 1742 = SUCCESS (terminal green). Scope: approve-gated stop command (provider/session/approval args), one-shot durable approval consumption, explicit stop authorization (Discord-origin consume/terminate path now present), 4 security regressions; command-authorization.service.ts UNCHANGED (frozen 7-field runtimeActionDigest preserved — round-4 field-stripping reverted). ROUND-5 ROR routed to reviewer (non-author) at exact head 6af68e76; prior round-4 REQUEST CHANGES 16978 void at old head. ROUND-5 RE-ROR = REQUEST CHANGES (reviewer comment 16986 @6af68e76, CI 1742 green). PROGRESS: 7-field digest preserved, thread routing + tests present, no live creds. RESIDUAL (actor-identity seam) routed to coder0 (round-6): (1) approval/stop still binds actorId = DISCORD_SERVICE_USER_ID (bot) — must be the RESOLVED APPROVING ADMIN's mosaic user id at both mint and consume (consume requires approval.actorId===action.actorId AND resolveRole(actorId)==='admin'; bot is not the approver); (2) stop consumes as service actor — must present the same approving-admin actorId bound at mint; (3) approve→stop tests share one fixture correlation, masking production separate-message flow — must model approval message + stop command as separate correlations resolving to the SAME target action 7-field identity (admin A approves T → stop consumes T once as A → replay rejected). Root-cause only (do not make the bot admin). FIFTH round on the seam (16951→16968→16973→16978→16986); reviewer holding actor boundary firm. coder0 remediating; re-ROR at new exact head after CI terminal green. ROUND-6 REMEDIATED + pushed: head 533e9702591436810160dfb1cf8a42a222cfb7c7 (branch tip confirmed), CI Woodpecker pipeline 1743 = SUCCESS (terminal green). Scope: stable target correlation + real RuntimeProviderService consume coverage; approval agent binding matches MOSAIC_AGENT_NAME with explicit mismatch denial; command-authorization.service.ts unchanged. ROUND-6 ROR routed to reviewer (non-author) at exact head 533e9702; prior round-5 REQUEST CHANGES 16986 void at old head. ROUND-6 RE-ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head 533e9702591436810160dfb1cf8a42a222cfb7c7 (visible Gitea comment 16991, CI 1743 success). Reviewer verified: actorId mint+stop consume uses RESOLVED mosaic admin (not DISCORD_SERVICE_USER_ID, not bot-made-admin); RuntimeProviderService consumes via verifier adapter; separate ingress correlations map to stable target action + one-shot replay rejected; 7-field digest intact; thread-under-parent test present; no live creds. pr-review wrapper self-approve blocked → recorded as verified PR comment. Head confirmed UNCHANGED at ROR target 533e9702 + PR mergeable=true, base=main. SIX-round durable cross-surface exact-action approval seam CLOSED (16951→16968→16973→16978→16986→16991); writer re-routed coder4→coder0 (Mos-dispatched) mid-flight. #730 MERGEABLE (independent non-author ROR + green CI at exact head). HARD STOP — Mos owns merge. MERGED to main by Mos — squash commit 84d884b9, approved head 533e9702, branch feat/tess-discord deleted, independent Sonnet ROR APPROVE (16991). M3 BUILD PHASE CONVERGED (M3-001 #730 + M3-002 #731 both merged). Writer re-routed coder4→coder0 mid-flight (Mos-dispatched); coder0 confirmed stand-down cleanup (dropped superseded WIP stash), on clean main 84d884b9, idle. NOTE: M3-001 #730 scope was Discord binding + durable approval; TESS-M1-FUP-001 (execute() authz-error mapping) + TESS-M2-FUP-001/003 did NOT ride in this PR — they remain not-started follow-ups to schedule (flagged to Mos). TESS-M3-V (M3→M4 gate) now READY — Mos dispatching as Mos-owned independent Sonnet checkpoint against merged main; orchestrator tracks, no competing lane. | -| TESS-M3-002 | done | Implement `mosaic tess` chat/status/sessions/tree/attach/send/stop/health/recover CLI | #709 | diskhygiene-terra | packages/mosaic | feat/tess-cli | TESS-M2-V | 30K | TESS-CLI-001. Mos DIRECT-DISPATCHED to diskhygiene-terra on feat/tess-cli (base=main, 2026-07-13) — orchestrator TRACKS only, no competing lane. PR-open-STOP, independent non-author ROR then Mos merges. Intake initially blocked on wrapper (issue-view.sh bare positional → 'Unknown option: 709'); orchestrator relayed -i flag fix. PR #731 OPEN (feat(tess): add generic interaction CLI; base=main, mergeable=true, head de74e46a0640c44c6b7294c24669496980761c92, fresh origin/main base 99a2d0fc). Scope: generic mosaic interaction command chat/status/sessions/tree/attach/send/stop/health/recover (NO instance-specific literal); --agent/MOSAIC_AGENT_NAME + Nova name-as-config test; authenticated gateway durable/provider boundary — server-derived actor scope, required non-simple correlation header, identity binding, durable recovery, registry routing, exact-action approval stop; status/health safe. Terra: full cold-cache pnpm turbo typecheck/lint/test --force + gates green, Codex security clean after remediation. CI pipeline 1735 TERMINAL GREEN (success) on de74e46a. ROR = APPROVE — canonical VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head de74e46a0640c44c6b7294c24669496980761c92 (visible Gitea comment 16959). Head confirmed unchanged at ROR target + mergeable=true. Reviewer verified generic mosaic interaction CLI verbs, --agent/MOSAIC_AGENT_NAME name-as-config, server-derived actor scope + required correlation, durable identity/recovery path, registry routing, exact-action approval stop, no live creds; no merge by reviewer (self-approve wrapper blocked → recorded as verified PR comment). MERGED to main by Mos — merge_commit 8246ee01 (independent Sonnet ROR 16959, all criteria + name-as-config Nova test verified). TESS-M3-002 DONE. TESS-M3-V (M3→M4 gate) advances once M3-001 #730 also merges — Mos-owned reviewer, no competing lane from orchestrator. | -| TESS-M3-003 | done | Cross-surface durable session integration + functional attach + denial/audit parity | #709 | coder0 | apps/gateway, plugins/discord, packages/mosaic, packages/agent | feat/tess-m3-integration | TESS-M3-001,TESS-M3-002 | 30K | Mos-DISPATCHED to coder0 (base=main, 2026-07-13) after M3-V gate = FAIL (integration unwired). Scope: C1 wire DurableSessionCoordinator.create into session-start + Discord resolves via durable snapshot + cross-surface E2E (AC-TESS-01); C2 expose streamSession over HTTP+CLI for functional attach + success test; C4 CLI denial spec + Discord mint-side durable audit + FOLD TESS-M1-FUP-001 (execute() authz-error classification) + RuntimeApprovalDeniedError→403 filter. PR-open-STOP, independent non-author ROR then Mos merges. M3-V RE-GATES after this lands. C1 design question raised by coder0 (origin/main has NO runtime-provider session-start/create op — only AgentService/Pi chat createSession, an LLM conversation, not a RuntimeProvider session carrying providerId/runtimeSessionId) — RESOLVED by Mos synthesis ruling (2026-07-13): conversationId is the durable handle; DurableSessionCoordinator.create happens at RUNTIME ENROLLMENT once providerId/runtimeSessionId are known; BOTH surfaces (Discord + CLI) snapshot it. coder0 PROCEEDING: C2/C4 in parallel now + implementing the C1 enrollment boundary per the ruling. PR-open-STOP; orchestrator serializes CI + routes independent non-author ROR at exact head; Mos merges. UPDATE 2026-07-13: **PR #732 OPEN** (base=main), head 451f7e04ec6c45adb12007dd7131da6a2b199962. coder0 stopped at PR creation, holding (no force-push). Local forced validation green (typecheck/lint/format:check/test: gateway 590 pass/11 skip, mosaic 640 pass), Codex code+security clean, command-authorization.service.ts byte-identical to origin/main. CI pipeline 1745 running — orchestrator serializing; on green-at-exact-head, independent non-author ROR routes to reviewer; HARD STOP for Mos merge. UPDATE 2026-07-13 (CI-GREEN): pipeline 1745 (event=pull_request, refs/pull/732/head, exact head 451f7e04) = SUCCESS; PR mergeable=true, head unmoved. Independent non-author ROR ROUTED to reviewer at exact head 451f7e04 (author coder0). Awaiting ROR verdict; HARD STOP for Mos merge; M3-V re-gates on merge. UPDATE 2026-07-13 (ROR round 1 = REQUEST CHANGES @ 451f7e04, Gitea comment 17007, CI 1745 green): ONE real blocker — Discord approve path UNREACHABLE in production. ChatGateway.handleDiscordApproval accepts only bare '/approve' (^/approve\\s*$), but plugins/discord/src/index.ts routes to discord:approve only on startsWith('/approve ') — so bare /approve → normal message (dead), '/approve x' → gateway-rejected; AC-TESS-01 mint/cross-surface flow can't fire; tests bypass DiscordPlugin.handleDiscordMessage so they mask it (same integration-unwired class M3-V flagged). Positives HELD: command-authz byte-identical (hash a9f829e7), 7-field digest intact, actor=resolved admin (not DISCORD_SERVICE_USER_ID), durable/stream/denial/audit coverage present, no live creds. Root-cause routed to coder0: reconcile plugin-routing predicate ↔ gateway accept-grammar + add end-to-end test through real handleDiscordMessage (no bypass). Fix push MOVES head → invalidates ROR, re-serialize CI + re-ROR at new exact head. UPDATE 2026-07-13 (RESOLUTION — MERGED by Mos): before coder0's fix was pushed, Mos ran a combined M3-V re-review at the SAME head 451f7e04 ([W-jarvis:reviewer-sonnet], Gitea comment 17009 = VERIFIED APPROVE + M3-V GATE PASS) and MERGED #732 → main squash commit **0b621660** ("feat(tess): wire durable interaction surfaces"). Mos milestone signal: M3-001/002/003 done, M3-V PASS, M3 COMPLETE, advancing to M4. ⚠️ ORCHESTRATOR RECONCILIATION: the two independent ROR reads at 451f7e04 CONFLICT on one concrete mechanism — my reviewer (17007) flagged the Discord approve path unreachable; Mos's re-review (17009) validated the gateway handler + integration test but that test bypasses DiscordPlugin.handleDiscordMessage. Orchestrator VERIFIED against merged main 0b621660 (read-only git show/grep): the plugin-routing defect is STILL LIVE — see TESS-M3-FUP-005. Surfaced to Mos as a fast-follow; coder0's uncommitted fix held pending Mos disposition. | -| TESS-M3-V | pass | Discord+CLI same-session E2E, denial/approval tests, and operator-flow review | #709 | mos-sonnet | apps/gateway/src/__tests__/integration, plugins/discord, packages/mosaic/src | review/tess-m3 | TESS-M3-001,TESS-M3-002,TESS-M3-003 | 20K | Gate M4. FIRST RUN = FAIL (Mos-owned independent Sonnet checkpoint against merged main 84d884b9, 2026-07-13): integration UNWIRED — Discord/CLI not cross-surface functional against durable sessions; attach/denial/audit parity incomplete. Remediation = TESS-M3-003 (coder0). SECOND RUN = **PASS** (Mos-owned combined re-review+re-gate at head 451f7e04, [W-jarvis:reviewer-sonnet] Gitea comment 17009, 2026-07-13): C1 cross-surface durable session, C2 functional attach, C4 denial/audit parity all closed; hard constraint (command-authz byte-identical, 7-field digest untouched) intact; C3/C5 no regression. Mos MERGED #732 → main 0b621660 and declared M3 milestone COMPLETE, advancing to M4. ⚠️ CAVEAT (orchestrator-verified live defect, NON-GATING per Mos): the M3-V integration test does not exercise DiscordPlugin.handleDiscordMessage, so the production Discord approve-path routing defect survived the gate — logged as TESS-M3-FUP-005 (fast-follow, surfaced to Mos). M4 (#710) UNBLOCKED (dep TESS-M3-V met). | -| TESS-M3-FUP-005 | done | Discord approve/stop production routing predicate mismatch — approve path unreachable | #709 | coder0 | plugins/discord, apps/gateway | feat/tess-m3-integration (rebased onto 0b621660) | TESS-M3-003 | 8K | **MERGED by Mos** → main squash commit **f1c6b37b** ("fix(tess): route bare Discord approvals (#733)"), 2026-07-13; post-merge main CI pipeline 1750 = SUCCESS. Verified-live Discord approve-path defect CLOSED — merged cross-surface mint path now functional end-to-end. HISTORY: **PR #733 OPEN** (base=main), head ed1d985c90e24ca3046bd570a556802927d80ed8 (rebased onto merged main 0b621660 to clear a Gitea conflict, force-with-lease; supersedes pre-rebase a02f526d whose pipeline 1747 was killed). pr-diff confirms clean 2-file scope: plugins/discord/src/index.ts + tess-cross-surface.integration.test.ts. coder0: bare /approve now routes to discord:approve; E2E invokes the REAL DiscordPlugin.handleDiscordMessage proving approve→stop against the durable conversation handle; forced typecheck/lint/format + targeted 17/17 green; command-authz zero-diff from main. CI pipeline 1748 (pull_request, refs/pull/733/head, commit ed1d985c) = **SUCCESS**. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head ed1d985c (Gitea comment 17017) — command-authz byte-identical hash a9f829e7 + 7-field digest intact, bare /approve REAL DiscordPlugin route fixed, gateway uses durable getSnapshot(conversationId), anti-masking divergent test inputs present, no Tess literal, no live creds. Head UNMOVED (ed1d985c), base main, mergeable=true. **MERGEABLE — HARD STOP for Mos merge** (2026-07-13). On merge → FUP-005 done; makes the merged Discord approve surface functional end-to-end. | ⚠️ VERIFIED-LIVE DEFECT on merged main 0b621660 (orchestrator read-only git show/grep, 2026-07-13). Gateway apps/gateway/src/chat/chat.gateway.ts:670 accepts approval ONLY as bare '/approve' (regex /^\\/approve\\s*$/i). Plugin plugins/discord/src/index.ts trims content (:339-341) then routes to discord:approve ONLY when content.startsWith('/approve ') (:385, requires a space+arg). NET: trimmed bare '/approve' fails the plugin predicate → emitted as normal message → gateway approval handler never fires (DEAD); '/approve x' passes the plugin but the gateway regex rejects it. So the production Discord approve path (AC-TESS-01 cross-surface mint) is UNREACHABLE end-to-end. M3-V PASSED because its integration test drives the gateway handler directly and bypasses DiscordPlugin.handleDiscordMessage, so the plugin predicate was never exercised (my reviewer 17007 caught it; Mos re-review 17009 validated the handler+test, not the plugin predicate). '/stop' likely same class (plugin needs startsWith('/stop ') args; confirm against gateway stop grammar). FIX: reconcile plugin routing predicate ↔ gateway accept-grammar (route bare '/approve' and snapshot-resolved '/stop ') + add an E2E test through the REAL DiscordPlugin.handleDiscordMessage (no bypass) proving mint fires. coder0 HAS this fix uncommitted in its worktree (from the round-1 remediation, pre-empted by the merge) — needs a fresh branch off main 0b621660 as a follow-up PR. AWAITING Mos disposition (fast-follow now vs after M4). Standard gates: PR-open-STOP, independent non-author ROR at exact head, Mos merges. | -| TESS-M4-001 | done | Implement Mos coordination handoff/observe/result contract with authority-boundary tests | #710 | coder0 | packages/coord, apps/gateway | feat/tess-mos-coordination | TESS-M3-V | 25K | **MERGED by Mos** → main squash **76325ca3** ("feat(tess): add Mos coordination boundary (#735)"), 2026-07-13 — merge = native-in-process transport ACCEPTED (contract transport-neutral). TESS-MOS-001. Mos-DISPATCHED 2026-07-13 to coder0 DESIGN-FIRST. UPDATE 2026-07-13: coder0 wrote docs/tess/MOS-COORDINATION.md; design checkpoint surfaced to Mos with the transport-adapter question (existing fleet/tmux Mos-authority channel vs dedicated native queue/HTTP). coder0 PROCEEDED (ahead of the Mos transport ruling) choosing a **native in-process adapter** and opened **PR #735** (base=main), head 7936e15d3ae137c91c88efdab4bb09b863a2195d. Impl: transport-NEUTRAL handoff/observe/result contract (MosCoordinationPort); deterministic native in-process InMemoryMosCoordinationPort; gateway derives actor/tenant/requester from trusted context/config; fail-closed for unconfigured-requester, self-delegation, target-drift, cross-tenant observe/result; NO public orchestrator verbs; **NO fleet/tmux transport, NO Mos-side consumer**; command-authorization byte-identical hash a9f829e7; no live creds; no hardcoded Tess identity. Local forced cold-cache typecheck/lint/format/test green (42 tasks); Codex security no findings. CI pipeline 1752 (pull_request, refs/pull/735/head, commit 7936e15d) = **SUCCESS**; head UNMOVED, mergeable=true. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 7936e15d (Gitea comment 17032) — verified MosCoordinationPort=handoff/observe/result only, gateway-derived authority, fail-closed denial coverage, native in-process port (no tmux/Mos consumer), command-authz byte-identical a9f829e7, no live creds, no Tess literal. ⚠️ HEAD MOVED 2026-07-13 (ROR 17032 INVALIDATED): coder0 pushed one post-ROR commit → new head **5022911f84dd7ac30f40df31a53f6cd31a51728f** (commit "docs(tess): record M4 verification", parent 7936e15d). Orchestrator-verified sole delta = a single scratchpad doc docs/scratchpads/tess-m4-001-mos-coordination.md, ZERO code/test diff. New CI pipeline 1754 (pull_request, refs/pull/735/head, commit 5022911f) = **SUCCESS**; mergeable=true, head now 5022911f. Comment 17032 @ 7936e15d no longer at exact head → re-serialize + re-ROR REQUIRED. Fast delta RE-ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 5022911f (Gitea comment 17036) — confirmed 5022911f is direct child of prior-reviewed 7936e15d, sole two-dot delta = the 3-line scratchpad doc, no code/test diff, command-authz byte-identical a9f829e7, CI 1754 success. Head UNMOVED (5022911f), mergeable=true. **MERGEABLE at 5022911f — HARD STOP for Mos merge** (2026-07-13). MERGE = Mos ACCEPTING the native-in-process transport choice (contract stays transport-neutral; a fleet/tmux or native-queue/HTTP consumer can be added later without contract churn); if Mos wants a different FIRST adapter, hold merge + route rework to coder0. | -| TESS-M4-002 | done | Implement transitional Hermes runtime/capability adapter | #710 | coder3 | packages/agent, apps/gateway | feat/tess-hermes-adapter | TESS-M3-V | 40K | **MERGED by Mos** → main squash **9e5b9188** ("feat(agent): add transitional Hermes runtime adapter (#734)"), 2026-07-13 — Mos merge = **option (a) ACCEPTED**; post-merge main CI 1753. TESS-HRM-001; no legacy schema in core contracts. Mos-DISPATCHED 2026-07-13 to coder3 DESIGN-FIRST (contract sketch + questions to Mos before build). Goes in-progress as PR opens; PR-open-STOP → serialize CI + independent non-author ROR at exact head → Mos merges. UPDATE 2026-07-13: coder3 ACTIVE — fresh worktree/branch feat/tess-hermes-adapter off origin/main; boundary sketch at docs/tess/hermes-runtime-adapter-design.md. DESIGN QUESTION surfaced to Mos (coder3 HELD at design-only until ruling): AC-TESS-05 wants approved capability across Kanban/skills/memory/tools/cron, but AgentRuntimeProvider models only SESSION capabilities. (a) adapter-local Hermes inventory/health marks those as explicit UNSUPPORTED, real ops deferred to their Mosaic-owned plugin contracts (coder3 default, preserves hard no-legacy-core-contract rule); vs (b) an existing Mosaic-owned non-runtime capability contract this adapter must implement. Orchestrator recommends (a) to Mos as the conservative boundary-preserving path. UPDATE 2026-07-13: coder3 PROCEEDED WITH (a) and opened **PR #734** (base=main), head 47b8a145ac43688499d275a54b434a52551c1abd — ahead of the Mos (a/b) ruling (design-hold was placed; coder3's original msg said it would proceed with (a) unless directed). Hermes adapter normalized behind packages/agent boundary; core types unchanged, unsupported ops fail-closed, tests prove no legacy field leak; focused tests/typecheck/lint pass; cold-cache turbo typecheck+build 46/46 0-cached. mergeable=true. CI pipeline 1751 (pull_request, refs/pull/734/head, commit 47b8a145) = **SUCCESS**; head UNMOVED, mergeable=true. Independent non-author ROR **COMPLETE**: reviewer [W-jarvis:reviewer] VERIFIED APPROVE at exact head 47b8a145 (Gitea comment 17027) — verified core AgentRuntimeProvider/runtime types UNCHANGED, adapter normalizes Hermes legacy shapes behind packages/agent boundary, unsupported runtime ops FAIL CLOSED via capability_unsupported BEFORE transport side effects (Kanban/skills/memory/tools/cron deferred under option (a)), no live creds, no hardcoded Tess agent identifier. Head UNMOVED, mergeable=true. **MERGEABLE — HARD STOP for Mos merge** (2026-07-13). ⚠️ MERGE GATED on Mos confirming option (a) is accepted (implementation == (a)); if Mos rules (b), #734 needs rework. HARD STOP for Mos merge. | -| TESS-M4-003 | done | Implement memory/retrieval, state/inbox, runtime bootstrap, fleet diagnostics and GitOps plugin foundations | #710 | coder0 | packages/memory, packages/agent, packages/mosaic | feat/tess-operator-plugins | TESS-M3-V | 40K | **MERGED by Mos** → main squash **2363f155** ("feat(memory): add operator retrieval plugin (#736)"), 2026-07-13. ⚠️ SCOPE GAP surfaced by Mos: #736 delivered ONLY the leaf @mosaicstack/memory operator-retrieval slice; **TESS-PLG-001 (packages/mosaic catalog/registration) was silently DEFERRED by the author and never surfaced in MISSION-MANIFEST/VERIFICATION-MATRIX** → now tracked explicitly as its own row (see TESS-PLG-001 below) and folded into TESS-M4-W-001. State/inbox/runtime-bootstrap/fleet-diagnostics/GitOps foundations remain follow-on (not in #736). TESS-MEM-001, TESS-PLG-001. Mos HELD 1 beat (2026-07-13) for a well-conditioned lane. UPDATE 2026-07-13: coder0 TOOK OVER M4-003 (preserved coder4 WIP first, then rebased on latest main) and opened **PR #736** (base=main), head a1d63ca8ed07610828e9c51a213fffe9123b3de4. ⚠️ AUTHORIZATION FLAG to Mos: M4-003 was on Mos 1-beat HOLD; confirm this takeover/dispatch was Mos-authorized before merge. Scope delivered: LEAF @mosaicstack/memory operator retrieval plugin — config-injected adapter/namespace, runtime-validated server-derived tenant/owner/session scope, redaction-before-persist, provenance, bounded startup prioritization, wildcard adapter contract, namespace/different-instance tests. NO gateway/catalog/durable-inbox or command-authorization changes. Forced cold-cache typecheck/lint/format/test green (42 tasks); Woodpecker 1756 green; Codex code+security clean. CI pipeline 1756 (pull_request, refs/pull/736/head, commit a1d63ca8) = **SUCCESS**; mergeable=true. Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head a1d63ca8 (Gitea comment 17044) — leaf packages/memory/doc only (no gateway/catalog/durable-inbox), command-authz byte-identical a9f829e7, runtime scope validation before storage keying, config-injected adapter/namespace/instance metadata, redaction-before-persist + provenance, scoped wildcard adapter contract, namespace/different-instance tests, no live creds, no Tess literal. Head verified UNMOVED at a1d63ca8, base main, mergeable=true. **MERGEABLE — reported to Mos, HARD STOP for Mos merge.** NOTE: M4-003 scope here is the memory-plugin slice; state/inbox/runtime-bootstrap/fleet-diagnostics/GitOps foundations may be follow-on slices — confirm with Mos whether #736 fully closes M4-003 or is slice 1. | -| TESS-M4-W-001 | in-progress | M4-V remediation — gateway reachability SPINE: register runtime provider into AGENT_RUNTIME_PROVIDER_REGISTRY + wire Mos-coordination consumer + wire operator-memory-plugin consumer (make merged M4 deliverables reachable end-to-end); FOLDS IN minimal TESS-PLG-001 catalog/registration | #710 | coder0 | apps/gateway, packages/mosaic, packages/agent | feat/tess-m4w-reachability-spine | TESS-M4-003 | 30K | **Mos-DISPATCHED 2026-07-13** (remediation). Root cause: M4-V holistic review @ origin/main **2363f155** found the three merged M4 deliverables unit-green but NOT reachable end-to-end (no gateway wiring/consumers; providers never registered into the registry). **SPLIT into 3 sub-parts by coder0 (integrity-honest):** **(#2 Mos-coordination consumer) = DELIVERED as PR #737** (head f7b95f60, base main, "feat(gateway): expose Mos coordination boundary") — real AuthGuard Mos handoff/observe/result consumer, authenticated actor/tenant + required correlation derivation, service authority unchanged, gateway target test/typecheck/lint pass; **CI 1758 SUCCESS** (repo 47, commit==head); head verified UNMOVED at f7b95f60666a4abbbad9a08669637b19fa87c430, base main, mergeable=true. **Independent non-author ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head f7b95f60 (Gitea comment 17054) — clean partial scope confirmed (AuthGuard Mos handoff/observe/result controller + module registration only; no runtime-provider registration / operator-memory consumer; actor/tenant from CurrentUser/scopeFromUser + required X-Correlation-Id before service invocation; MosCoordinationService unchanged; command-authz byte-identical a9f829e7; no live creds/no Tess literal). **#737 MERGEABLE — reported to Mos, HARD STOP for Mos merge (partial slice; land-vs-hold-for-full-spine is Mos's disposition call).** **(#1 runtime-provider registration) + (operator-memory consumer) = BLOCKED, NOT in #737.** coder0 could not truthfully complete them in this slice and REFUSED to fake with deny/unavailable stubs: gateway has **no concrete Hermes transport** and **no gateway-side tmux transport/authority wiring** to register a real provider; OperatorMemory consumer needs **session tenant/owner/session propagation currently ABSENT from AgentService's memory-tools boundary**. ⚠️ **DESIGN RULING ESCALATED TO MOS** (architecture, not resolvable from repo): how to wire provider-registration + memory-scope propagation when no concrete transport exists yet — new remediation slice / re-scope / accept #737 as incremental. TESS-PLG-001 (folded here) is part of the blocked #1 registration path. Command-authz byte-identical a9f829e7. **UPDATE 2026-07-13: #737 MERGED by Mos → main e2376190 ("feat(gateway): expose Mos coordination boundary (#737)").** **Operator-memory consumer sub-part UNBLOCKED + DELIVERED as PR #739** ("feat(memory): bind operator plugin to agent sessions", base main off e2376190, live head 31a59738089f0784428833fc5a0192c6c7c43261, mergeable=true) — coder0 resolved the session-scope-propagation blocker WITHOUT stubbing: gateway bootstrap configures plugin only with MOSAIC_OPERATOR_MEMORY_INSTANCE_ID + MOSAIC_OPERATOR_MEMORY_NAMESPACE, AgentService derives {tenantId,ownerId,sessionId} server-side and binds search/capture tools. Cold-cache root typecheck/lint/format/test (42 tasks) green; security review clean (Codex Optional-import finding = false positive, pre-existing, typecheck passed). **CI 1764 SUCCESS** (repo 47, commit==head); head verified UNMOVED at 31a59738089f0784428833fc5a0192c6c7c43261, base main, mergeable=true. **Independent non-author ROR ROUTED to reviewer at exact head 31a59738089f** (coder0 authored → reviewer is non-author) — asked reviewer to confirm scope is server-derived/non-client-controllable + no cross-tenant leak, and to independently verify the Codex Optional-import finding is a false positive. (Head reconcile CLOSED: coder0 confirmed 31a597380c55… was a transcription typo; live+frozen head is 31a59738089f0784428833fc5a0192c6c7c43261, working tree clean.) **UPDATE 2026-07-13: reviewer REQUEST CHANGES at head 31a59738089f (Gitea comment 17069) — NOT mergeable.** Production code CONFIRMED correct (plugin route wired, config env namespace/instance only, no live creds/no Tess literal, command-authz byte-identical a9f829e7; Codex Optional-import finding = false positive, import present). **Two TEST-COVERAGE blockers:** (1) tests BYPASS production scope derivation — they call createMemoryTools with a PREBUILT scope, never exercising the real createSession→buildToolsForSandbox server-side {tenantId,ownerId,sessionId} derivation; (2) NO divergent cross-tenant/cross-owner ISOLATION/DENIAL test proving a foreign actor cannot reuse a session / reach another operator-memory scope before the plugin call. Routed back to coder0 (integrity: harden real coverage, do NOT weaken assertion). Any new commit MOVES head → invalidates ROR → re-serialize CI + re-ROR at new head. **UPDATE 2026-07-13 (remediated): coder0 pushed hardened tests, NEW frozen head c26b3b775279575276c6ebe8955a9146bfc61413** — added createSession→buildToolsForSandbox PRODUCTION-PATH assertion of derived {tenantId,ownerId,sessionId}; added foreign-actor reuse DENIAL test asserting rejection occurs BEFORE scope/tool construction and before any plugin call. Cold-cache root typecheck/lint/format/test green (42 tasks). Old ROR at 31a59738089f + CI 1764 SUPERSEDED. Re-serialized: **CI 1765 SUCCESS** at c26b3b775279 (ref refs/pull/739/head, commit==head); head verified UNMOVED at c26b3b775279575276c6ebe8955a9146bfc61413, base main, mergeable=true. **Fresh independent non-author ROR RE-ROUTED to reviewer at exact head c26b3b775279** — asked reviewer to confirm both 17069 blockers genuinely closed (prod-path derivation exercised + cross-tenant denial before plugin call, assertion not weakened). **Independent non-author re-ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head c26b3b775279 (Gitea comment 17074) — both 17069 blockers CONFIRMED closed: production createSession→buildToolsForSandbox scope-derivation test asserts {tenantId,ownerId,sessionId}; foreign-scope reuse rejects BEFORE tool construction and BEFORE plugin search/capture; production wiring reachable via MemoryModule env-configured plugin → AgentService injection → memory_search/memory_save_insight plugin path; command-authz byte-identical a9f829e7; Optional import present; no live creds/no Tess literal. Head verified UNMOVED at c26b3b775279, base main, mergeable=true. **#739 MERGEABLE — reported to Mos, HARD STOP for Mos merge.** This lands the operator-memory-consumer sub-part of W-001; REMAINING W-001 gap = only (#1) runtime-provider registration. **REMAINING blocked: (#1) runtime-provider registration into AGENT_RUNTIME_PROVIDER_REGISTRY** — still needs Mos A/B/C design ruling (no concrete Hermes transport yet). So after #739 lands, W-001 = Mos-consumer (#737 merged) + memory-consumer (#739) DONE; only the provider-registration linchpin remains. **UPDATE 2026-07-13: #739 MERGED by Mos → main squash 3378b857eb ("feat(memory): bind operator plugin to agent sessions (#739)"); post-merge main push pipeline 1766 running. W-001 spine now 2-of-3 sub-parts MERGED (Mos-consumer #737 e2376190 + operator-memory-consumer #739 3378b857); ONLY remaining W-001 gap = (#1) runtime-provider registration into AGENT_RUNTIME_PROVIDER_REGISTRY — still BLOCKED on Mos A/B/C design ruling (no concrete Hermes transport; TESS-PLG-001 folded here). coder0 idle/ready to build #1 on ruling.** **UPDATE 2026-07-13: (#1) DELIVERED as PR #740 "feat(gateway): register Hermes runtime provider"** (base main 3378b857, exact live head 127a69ea11ccc36516c78c2007cbe52fbf63ad30 verified unmoved, mergeable=true). coder0 resolved the A/B/C escalation by BUILDING a concrete transport (⚠️ design-direction flagged to Mos for confirm-before-merge): agent.module.ts explicit registry.register(new HermesRuntimeProvider(new GatewayHermesRuntimeTransport())); GatewayHermesRuntimeTransport = server-configured URL+service token, HTTPS-except-loopback, prefixed-URL preserving, forwards full scope incl channel; AuthGuard interaction transitional-capabilities route through RuntimeProviderService + live controller→service→registered-provider reachability test. Cold-cache typecheck/lint/format/test green (42 tasks); Codex path-prefix+channel-header findings remediated, security clean. **CI pipeline 1767 (repo 47, refs/pull/740/head, commit==head) = SUCCESS**; head verified UNMOVED at 127a69ea11ccc36516c78c2007cbe52fbf63ad30 post-CI, base main, mergeable=true. **Independent non-author ROR ROUTED to reviewer at exact head 127a69ea11cc** (coder0 authored → reviewer non-author) — asked reviewer to verify REAL E2E reachability (provider actually in registry + reachability test exercises registered provider, not mock), transport security (HTTPS-except-loopback, no token leak), command-authz byte-identical a9f829e7, no live creds/no Tess literal, Codex findings genuinely remediated. Awaiting reviewer disposition; any new commit moves head → re-serialize + re-ROR. **UPDATE 2026-07-13: reviewer REQUEST CHANGES at head 127a69ea11cc (Gitea comment 17088) — NOT mergeable.** CI 1767 green; command-authz byte-identical a9f829e7 CONFIRMED; production positives CONFIRMED (module factory registers Hermes provider; concrete transport HTTPS/prefix/channel headers; no live creds/no Tess literal). **Blocker (reachability-integrity):** the required live-guarded reachability proof is MISSING — test directly calls controller.transitionalCapabilities + manually constructs RuntimeProviderService/createGatewayRuntimeProviderRegistry; it does NOT exercise live GET /api/interaction/:agentName/transitional-capabilities, Nest DI through AgentModule, or the AuthGuard request path, so it can pass even if injected gateway registry/route wiring is broken (defeats the M4-V E2E-reachability point). Routed back to coder0 (integrity: add genuine Nest-e2e live-guarded reachability test through real DI+route+AuthGuard asserting reach of the registered Hermes provider; do NOT weaken/stub/mock around it; keep command-authz a9f829e7). Old ROR 17088 + CI 1767 will be SUPERSEDED by the remediation head → re-serialize CI + re-ROR at new head. **UPDATE 2026-07-13 (remediated): coder0 pushed the live-guarded reachability test, NEW frozen head a7e5d377e38b40275884a7df6ee35c55c5859e43** (live Gitea head independently verified, base main 3378b857, mergeable=true) — added apps/gateway/src/agent/hermes-runtime-reachability.e2e.test.ts: imports REAL AgentModule (preserves actual AGENT_RUNTIME_PROVIDER_REGISTRY factory + RuntimeProviderService), boots Fastify/Nest, unauth HTTP GET /api/interaction/Nova/transitional-capabilities?provider=runtime.hermes asserts 401 via ACTUAL AuthGuard, authed GET asserts 200 + all five Hermes entries, asserts DI registry resolves HermesRuntimeProvider; only unrelated peripheral modules harness-replaced to avoid DB/queue startup — NO route/guard/DI-registry/runtime-service/provider mock; existing controller unit test retained; command-authz untouched (byte-identical a9f829e7 remains). Cold-cache root typecheck/lint/format/test green 42/42 (gateway 53 files/606 tests). Old ROR 17088 + CI 1767 SUPERSEDED. Re-serializing: **CI 1768 (repo 47, refs/pull/740/head, commit==head a7e5d377) running** — poll in flight; on green → re-route non-author ROR at exact head a7e5d377. **UPDATE 2026-07-13: CI 1768 SETTLED SUCCESS** (repo 47, refs/pull/740/head, commit==head a7e5d377e38b40275884a7df6ee35c55c5859e43); head independently verified UNMOVED at a7e5d377 (live Gitea, NOT worker-reported), base main 3378b857, mergeable=true. **Independent non-author re-ROR COMPLETE: reviewer VERIFIED APPROVE at exact head a7e5d377e38b40275884a7df6ee35c55c5859e43 (Gitea comment 17094).** Prior 17088 blocker CONFIRMED closed — the new hermes-runtime-reachability.e2e.test.ts boots real Nest/Fastify AgentModule and exercises unauth 401 via the ACTUAL AuthGuard + authed HTTP GET /api/interaction/:agentName/transitional-capabilities through the live route→controller→RuntimeProviderService→registered Hermes provider, and asserts DI registry resolves HermesRuntimeProvider (no route/guard/DI/service/provider mock); transport concrete, HTTPS-except-loopback, path-prefix + channel header covered; command-authz byte-identical a9f829e7 CONFIRMED; no live creds/no Tess literal. Head verified UNMOVED at a7e5d377, base main, mergeable=true. **#740 MERGEABLE — the (#1) runtime-provider-registration linchpin — reported to Mos, HARD STOP for Mos merge.** ⚠️ Design-direction (concrete GatewayHermesRuntimeTransport built to resolve the A/B/C escalation) flagged to Mos for confirm-before-merge. On #740 merge, W-001 spine = 3-of-3 sub-parts landed (Mos-consumer #737 + memory-consumer #739 + provider-registration #740) → M4-V re-fire eligible. **UPDATE 2026-07-13: #740 MERGED by Mos → main b7b0f508 ("feat(gateway): register Hermes runtime provider (#740)"). W-001 SPINE NOW 3-OF-3 MERGED (Mos-consumer #737 e2376190 + operator-memory-consumer #739 3378b857 + provider-registration linchpin #740 b7b0f508) — the M4-V reachability remediation code work is COMPLETE. GATE: TESS-M4-V re-fire is now eligible and Mos-owned — this row stays in-progress until M4-V re-fires green (unit-green was never the bar; end-to-end reachability is). ⚠️ main push pipeline 1772 (for the #740 merge to main) FAILED at the `build` step — quality gates (typecheck/lint/format/test) all GREEN, failure is downstream at build/publish (recurring infra/ENOSPC pattern); flagged to Mos as Mos-owned, does not block docs-only PRs. Prior doc-sync ledger PR #741 MERGED → main f40e6ba3 ("docs(tess): sync M4 tracking to merged reality (M4 in-progress / gate-pending)"); ledger writes resumed on fresh branch docs/tess-ledger-sync-m2 off f40e6ba3. **UPDATE 2026-07-13: consolidated ledger-sync PR #743 (branch docs/tess-ledger-sync-m2, head aa3925510d06, reviewer VERIFIED APPROVE 17123, CI 1775 SUCCESS) MERGED by Mos → main c6e3cfbdf... ; ledger writes resumed on fresh branch docs/tess-ledger-sync-m3 off main 6345dbfc (post-#744 merge). **UPDATE 2026-07-13: ledger-sync m3 PR #745 MERGED by Mos → main e72388b2 ("docs(tess): ledger sync m3 — M5-001 + M5-002 done (#745)"); mission issue #706 preserved OPEN (Refs #706 non-closing). Ledger writes resumed on fresh branch docs/tess-ledger-sync-m4 off main bc8016c8 (post-#746 merge) recording M5-003 done.** | -| TESS-M4-W-002 | done | M4-V remediation — Hermes capability MATRIX (AC-TESS-05): approved-capability coverage across Kanban/skills/memory/tools/cron for the Hermes adapter | #710 | coder3 | packages/agent, apps/gateway | feat/tess-m4w-hermes-matrix | TESS-M4-002 | 22K | **Mos-DISPATCHED 2026-07-13** (remediation, in flight). Extends the M4-002 option-(a) adapter (merged 9e5b9188) with the AC-TESS-05 capability matrix. UPDATE 2026-07-13: coder3 STARTED — fresh worktree off origin/main 2363f155, TDD failing-matrix-tests-first. Orchestrator TRACKS; on PR-open → serialize CI + independent non-author ROR at EXACT head → HARD STOP for Mos merge. No legacy schema into core contracts; command-authz byte-identical a9f829e7. UPDATE 2026-07-13: **PR #738 OPENED** (base main, head 582c6db2088223fd8dd2105005391b5034c992ac, "feat(agent): add Hermes transitional capability matrix") — normalized exhaustive five-entry matrix (kanban/skills/memory/tools/cron), all explicit unsupported, fails CLOSED before transport; tests 4/4, security review clean, cold-cache 46 successful/0 cached, normalized optional TransitionalCapabilityInventoryProvider (no legacy schema). **CI 1759 SUCCESS** (repo 47, commit==head); head verified UNMOVED at 582c6db2, base main, mergeable=true. **Independent non-author ROR COMPLETE**: reviewer VERIFIED APPROVE at exact head 582c6db2 (Gitea comment 17057) — normalized exhaustive five-entry transitional matrix (kanban/skills/memory/tools/cron) all unsupported; assertTransitionalCapability fails CLOSED with capability_unsupported before Hermes transport; only normalized optional TransitionalCapabilityInventoryProvider added to core (no legacy schema leak); command-authz byte-identical a9f829e7; no live creds/no Tess literal. Head verified UNMOVED at 582c6db2, base main, mergeable=true. **#738 MERGEABLE — reported to Mos, HARD STOP for Mos merge.** This is the COMPLETE matrix deliverable (unlike #737's partial spine). **UPDATE 2026-07-13: #738 MERGED by Mos → merge_commit cca6aaf9. TESS-M4-W-002 DONE.** | -| TESS-PLG-001 | in-progress | packages/mosaic plugin catalog / registration (operator plugins registered + discoverable) — was silently deferred by M4-003 author; now VISIBLE | #710 | coder0 | packages/mosaic | feat/tess-m4w-reachability-spine | TESS-M4-003 | (folded) | ⚠️ Surfaced by Mos 2026-07-13 as an invisible gap: M4-003/#736 delivered the memory plugin but NOT its catalog/registration in packages/mosaic; never appeared in MISSION-MANIFEST/VERIFICATION-MATRIX. PLACEMENT DECISION (orchestrator, per Mos "your call"): **FOLD minimal registration into TESS-M4-W-001** (coder0's reachability spine already does registry wiring — same author closes their own gap, keeps it in one lane). This row exists for LEDGER VISIBILITY so the gap is tracked, not re-hidden. If M4-W-001 scope grows too large, split back out as a standalone lane. Manifest/matrix update to follow. | -| TESS-M4-V | failed | Cross-provider capability, privacy, authority and failure-path qualification | #710 | sonnet | apps/gateway/src/__tests__/integration, packages/agent | review/tess-m4 | TESS-M4-001,TESS-M4-002,TESS-M4-003,TESS-M4-W-001,TESS-M4-W-002 | 22K | **FAILED 2026-07-13** — independent holistic review @ origin/main **2363f155**: all three M4 deliverables (#734/#735/#736) unit-green but **NOT reachable end-to-end** (providers never registered into AGENT_RUNTIME_PROVIDER_REGISTRY; Mos-coordination + operator-memory consumers unwired; TESS-PLG-001 catalog/registration silently deferred). Remediation TESS-M4-W (W-001 spine coder0 + W-002 Hermes matrix coder3) now in flight. **Mos re-fires M4-V ONLY after the spine + matrix land.** Gate M5 (M5 stays behind M4-V; live-deploy = Jason-reserved). | -| TESS-M5-001 | done | Implement Matrix/native runtime provider behind common contracts and parity suite | #711 | coder0 | packages/mosaic, packages/agent | feat/tess-matrix-provider | TESS-M4-V | 30K | TESS-TRN-001. **Mos-DISPATCHED to coder0 2026-07-13** (advancing to M5, same M4-V dependency-reconciliation caveat as M5-002). Design sketch (branch feat/tess-matrix-provider off origin/main b7b0f508): MatrixNativeRuntimeProvider in packages/agent over a narrow MatrixRuntimeTransport contract + MatrixNativeRuntimeTransport in packages/mosaic (Mosaic adapter owns Matrix HTTP/auth/identity/room mechanics; agent provider owns common provider behavior only). Parity suite runs the SAME provider-contract scenarios against factory fixtures for existing tmux/fleet AND Matrix/native; Matrix native declares only operations concretely wired (no fake reachability, no Matrix default promotion); no gateway/Discord changes; command-authz to remain byte-identical a9f829e7. **In TDD — no PR yet.** On PR-open: freeze head → serialize CI (one-at-a-time on repo 47) → independent non-author ROR at exact head → HARD STOP for Mos merge. **UPDATE 2026-07-13: DELIVERED as PR #744 (7 files packages/agent + packages/mosaic only) frozen head b4fcf139a73678e9e59c8f6b63c108c095a87b3a; CI pipeline 1776 SUCCESS (repo 47, refs/pull/744/head, commit==head); independent non-author ROR COMPLETE — reviewer VERIFIED APPROVE at exact head b4fcf139a736 (Gitea comment 17126): Matrix stays NON-DEFAULT (no gateway/Discord/registry wiring), default-deny read/write authority, immutable read handles, control-attach rejection, parity suite runs same scenarios against tmux/fleet AND Matrix/native, concrete Matrix CS-API HTTPS transport with whoami/remote-identity-filter/deterministic txns, no live creds, command-authz byte-identical a9f829e7. #744 MERGED by Mos → main 6345dbfcf262. Deliverable code LANDED. GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending (this row was dispatched ahead of M4-V passing).** | -| TESS-M5-002 | done | Complete migration inventory, cutover, rollback, retention and deprecation evidence | #711 | coder3 | docs/tess | feat/tess-migration-docs | TESS-M4-V | 18K | TESS-MIG-001. **Mos-DISPATCHED to coder3 2026-07-13** ("M4 complete; advancing to M5") — dispatched AHEAD of TESS-M4-V passing; the M4-V-status-vs-#710-CLOSED dependency reconciliation is pending Mos ruling (tracked, not orchestrator-decided). **DELIVERED as PR #742** — 4 new files docs/tess/M5-MIGRATION-{INVENTORY,CUTOVER,ROLLBACK,RETENTION-DEPRECATION}.md, base main b7b0f508, frozen head b5e9d0e528a50aae2e916cc7202bacc2e8db67dd. Docs-only; tracking-control trio (MISSION-MANIFEST/TASKS/VERIFICATION-MATRIX) UNTOUCHED; command-authz byte-identical a9f829e7; no live creds. **CI pipeline 1773 SUCCESS** (repo 47, refs/pull/742/head, commit==head). **Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head b5e9d0e528a50aae2e916cc7202bacc2e8db67dd (Gitea comment 17108)** — evidence claims verified to trace to landed Hermes adapter / capability matrix, gateway registry/reachability, operator-memory scope path, Mos coordination boundary; docs do NOT over-claim transcript/profile import, schema migration, unsupported-capability enablement, production cutover, or deprecation completion. Head independently verified UNMOVED at b5e9d0e528a5 post-ROR (live Gitea), base main, mergeable=true. **#742 MERGED by Mos → main 5789711e. Deliverable docs LANDED. GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending (this row was dispatched ahead of M4-V passing).** | -| TESS-M5-003 | done | Complete OpenAPI, user/admin/developer/plugin/operations docs and checklist | #711 | codex | docs | feat/tess-docs | TESS-M5-001,TESS-M5-002 | 22K | Documentation hard gate. **DELIVERED as PR #746** (branch feat/tess-docs, base main, 7 docs-only files: docs/openapi-tess.yaml + docs/tess/{ADMIN,DEVELOPER,OPERATIONS,PLUGIN,USER}-GUIDE.md + M5-003-DOCUMENTATION-CHECKLIST.md). 4-round revise-loop (heads 470eb911→c9f69300→7aea94e2→25b9d642) converged: OpenAPI covers interaction routes + SSE /sessions/{sessionId}/stream + Mos coord (/api/coord/mos/handoff,/observe,/result) + memory preferences/insights/search; request-body schemas aligned to real DTOs (Send requires content+idempotencyKey, Stop requires approvalRef, Insight requires only content, MosHandoff body requires idempotencyKey+summary); checklist accurate. **CI pipeline 1786 SUCCESS** (repo 47, refs/pull/746/head, commit==head 25b9d642). **Independent non-author ROR COMPLETE: reviewer VERIFIED APPROVE at exact head 25b9d642b939014b3efd61826e7524cafc6ffc2e (Gitea comment 17170)** — docs-only, tracking-trio untouched, command-authz byte-identical a9f829e7, no false coverage claims. Head verified UNMOVED at 25b9d642 (live Gitea, not worker-reported), base main, mergeable=true. **#746 MERGED by Mos → main bc8016c8314ec3a4b6ebc2fec5d9f276fca3327a. Documentation gate LANDED.** GATE: TESS-M4-V/M5-V verification-gate reconciliation remains Mos-owned/pending. | -| TESS-M5-V | not-started | Full baseline, contract, integration, Discord/CLI E2E, security review, recovery drill and rollback qualification | #711 | sonnet | apps/gateway, packages/agent, plugins/discord, packages/mosaic | review/tess-final | TESS-M5-003 | 35K | Maps AC-TESS-01..11 to evidence | -| MOS-PORT-M1-001 | in-progress | Implement logical Mos identity, PostgreSQL connector lease, monotonic fencing, server-bound execution grants, audit, migrations, concurrency/restart/abuse/integration tests | #755 | codex | packages/types, packages/agent, packages/db, apps/gateway | feat/mos-logical-identity-fencing | — | 38K | Requirements MOS-PORT-ID-001, MOS-PORT-LEASE-001, MOS-PORT-FENCE-001..002, MOS-PORT-OBS-001, MOS-PORT-ARCH-001. One Sol/Pi worker; TDD; PR-open STOP; worker must not edit this ledger. |