docs(prd): PRD draft 0.3; slice 1 addendum A; lead decision 49

Darkwing's addendum as a record. Broker verbs enforce field ownership,
broker push from a bare repo, polling without webhooks, Vikunja probes
before the adapter interface is fixed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-04 14:56:14 -05:00
co-authored by Claude Opus 5.5
parent c57998772d
commit d7723e2237
4 changed files with 508 additions and 9 deletions
+1
View File
@@ -472,3 +472,4 @@ are never rewritten or removed; corrections are new entries.
2026-10-04T19:26:12Z | Filbert (T3 Claude Code, thread 9cb9731e) | meta-harness survey done (slice 1 step 8) | agents/filbert/work/meta-harness-survey-2026-10-04.md sha256 05f83807…0989; Pi tool_call is the only fail-closed hook of the three, so hard lines are credential scope, verbs, tool ceiling and container; no commits
2026-10-04T19:26:50Z | Sage (T3 Claude Code, thread 1ef1e4f8) | meta-harness survey received | Filbert's survey (05f83807) committed as a record; lead decision 47 rules on its section 8; two DEFERRED items (host-seat --approve, worker provider-key exposure)
2026-10-04T19:48:15Z | Sage (T3 Claude Code, thread 1ef1e4f8) | PRDY round 2, PRD 0.2 | lead decision 48; PRD draft 0.2 with requirement ids; Researcher's Vikunja and Pocket ID report (fcfc970f) committed as a record (Researcher wrote no SESSIONS line, per its limits)
2026-10-04T19:56:14Z | Sage (T3 Claude Code, thread 1ef1e4f8) | slice 1 addendum A | Darkwing's addendum (0b36acb0) committed as a record; lead decision 49; PRD draft 0.3; assigned Researcher Vikunja probes P1-P7 on a scratch container and Darkwing the task_snapshots prototype extension
+30
View File
@@ -773,3 +773,33 @@ which stay with him. Each item names who decided it and what happened.
(`agents/researcher/work/2026-10-04_vikunja-pocketid.md`, sha256
fcfc970f…) was committed as a record with this entry. The PRD's
technical considerations draw on it.
49. **Sage's rulings on slice 1 addendum A (2026-10-04).** Source:
Darkwing (CTO), `agents/darkwing/work/slice1-data-model-addendum-2026-10-04.md`
(sha256 0b36acb0…). Where the addendum and the original note
disagree, the addendum wins.
- Vikunja token scopes cover whole route groups. So "one writing role
per field" is enforced by broker verbs, not by tokens. That works
only because agents never hold the tokens.
- A1, coder push: accepted. The broker fetches the branch into a bare
repository it owns and pushes from there with hooks off. Gitea branch
protection stays the server-side line.
- A2: no webhooks in slice 1. Poll every 30 seconds with a keyset
cursor and reconcile hourly. That removes the
`allownonroutableips` prerequisite.
- 6.8 stands, with an ETag check on GET and a PATCH of only the owned
fields. The brief will say the race window is still there.
- A3: accepted. A `task_snapshots` table, `decisions.blocking` and the
new event kinds. Darkwing extends the prototype before the brief.
- A4: accepted. Researcher runs probes P1 to P7 against a scratch
`vikunja/vikunja:2.7.0` container with SQLite, bound to
127.0.0.1, removed afterwards, test tokens only. P8 goes to whoever
builds the broker.
- A5: the one word stops new launches, and `mosaic stop` ends a running
session. Sage reads Jason's "revocable with one word" that way. If he
meant otherwise, he says so.
- The PM's `role.launch` needs a `launch` block in the business file.
Without that block the action is gated.
- The PM moving from T3 to a session the stack launches is a named step
in the slice 1 brief (REQ-CLI-2).
- PRD wording for REQ-VAR-2 and REQ-TASK-1 adopted in draft 0.3, with
REQ-TASK-2 updated for A2.
+12 -9
View File
@@ -1,13 +1,13 @@
# PRD: Mosaic Stack
- Status: draft, version 0.2. Jason approves it, and once approved it is
- Status: draft, version 0.3. Jason approves it, and once approved it is
never edited in place. Changes after approval are a new version.
- Owner: Jason. Sage writes it from the PRDY interview.
- Template: PRDY "software" (`v1/packages/prdy/src/templates.ts`), filled
by hand until PRDY is ported.
- Interview record: Sage's thread 1ef1e4f8. Round 1 is lead decision 45.
Round 2 is lead decision 48. Design inputs are lead decisions 43, 44,
46 and 47.
46, 47 and 49.
## Introduction
@@ -111,9 +111,10 @@ parent requirement is refused.
allowed in.
- **REQ-VAR-2.** `~/.config/mosaic-dev/config.json` stays the only system
config, and nothing writes it automatically. A secret appears only as a
reference, either a file path or an environment variable name. The
stack checks a referenced file with `stat` and never reads its
contents.
reference, either a file path or an environment variable name. Only
the broker reads a secret's contents. It holds them in memory and
never logs or writes them. Everything else checks a referenced file
with `stat`.
### Credentials
@@ -153,11 +154,13 @@ parent requirement is refused.
### Tasks
- **REQ-TASK-1.** Tasks live in Vikunja, reached through `/api/v2` with a
bot token for each role. Each task cites a requirement id. Only the
assigned role writes a task's mutable fields. A person's edits come in
as events.
bot token for each role. Each task cites a requirement id. Each task
field has one writing role, listed in the slice 1 brief's field table,
and the assigned role writes the task's state. Vikunja's token scopes
cover whole route groups, so the broker's verbs enforce this, not the
tokens. A person's edits come in as events.
- **REQ-TASK-2.** Polling for changes since the last check is the source
of truth, and webhooks only trigger a check sooner.
of truth, with an hourly full reconcile. Slice 1 uses no webhooks.
- **REQ-TASK-3.** The installer offers two choices: point at an existing
Vikunja, or deploy the bundled one. The bundled one is the unmodified
upstream image. No Vikunja code enters the repository.