Commit Graph
756 Commits
Author SHA1 Message Date
mos-dt-0andClaude Opus 5 4430e60d84 docs(remediation): RM-02 round 3 dispatched — board de-staled, under budget
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 12:09:58 -05:00
mos-dt-0andClaude Opus 5 4520d2f672 docs(remediation): promote two first-class principles to the charter; dispatch RM-02 round 3
Mos ruled both open questions and promoted the pattern to the charter.

PRINCIPLE 1 — the anchor must live outside the audited party's authority. You cannot fix "the author
controls X" by deriving X from something the author also controls; deriving only MOVES the control
point. Third independent arrival of one conclusion, each reached while shipping something else and each
from a different direction: the manifest certifying its own tree (D-19), the sandbox evaluating code
that enters before the boundary exists (D-25), and now the registry seam derived from a path the author
also places (D-45). Three impossibility-derivations of the same conclusion is the strongest
architectural evidence this mission has produced, and it is what forces Builds 1-2 rather than making
them a preference.

PRINCIPLE 2 — no universally-quantified check may pass over an empty set. "All registered cases ran" is
vacuously true when there are none. Non-emptiness and anchoring are preconditions asserted before the
quantified check runs, not properties hoped for after. The identical vacuity appeared twice at two
levels — seam=HEAD emptied the commit range, an emptied manifest emptied the registry population — and
the first was fixed as an instance, so it returned one level up. Corollary, same disease: a clause
written for the instance that produced it is not a clause.

Q1 ruled: the merge-base anchor IS in scope for f10-coder in this PR. It is git-computable against
main, which the author does not control, so reordering or splitting within the branch cannot move it —
an existing non-author-controlled reference, no new infrastructure. RM-60's execution boundary is a
sibling under the same principle but a different mechanism (where gate-verify runs, not what the anchor
is) and stays with Mos and Jason. Honesty required in both directions: the merge-base anchors to main,
whose integrity rests on the merge discipline this registry enforces — a bootstrap, sound against an
author who cannot rewrite main and NOT sound against an attacker who can, with that residual bound to
the Builds 1-2 dependency rather than implied.

Q2 ruled: state the empty-set principle as a general clause now, and generalize the D-38/D-40 criteria
the same way — quantify over the population instead of relabeling the originating instances.

Round 3 dispatched to f10-coder: merge-base anchor plus delayed-introduction must-fail; empty-set
precondition as a general clause with an emptied-registry must-fail; generalized clauses bound across
the gate inventory; each red-first. Number.isInteger accepting zero/negative/unsafe pipeline numbers
banked as a non-blocking follow-up.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 12:08:21 -05:00
mos-dt-0andClaude Opus 5 09875143c0 docs(remediation): roll D-11 capability/identity bullets to the ledger (D-43: roll out, never reword)
Third application of D-43's rule today. Those two bullets restated D-11/D-11a/D-11b, which live
authoritatively in TASKS.md, so they were a second copy waiting to go stale. Rolled verbatim; the board
keeps a pointer plus the one operational line that is not a restatement — assert the differential as
that seat, because a single endpoint can be true for anyone or 403 for an unrelated scope.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 12:05:07 -05:00
mos-dt-0andClaude Opus 5 08cb73fde3 docs(remediation): bank D-45/D-46/D-47 — the fix moved the author's control point instead of removing it
Second NO-GO on the keystone at 32b490a7. The pattern is the finding, not the three blockers.

D-45: round 1 the author set activationCommit as a field, so we derived it; round 2 the derivation
depends on WHEN the author introduces gates/gates.manifest.json. rev-974 committed a gate change before
adding the manifest — deriveHistoryBoundary picked that commit as activation, the prospective list held
only the later introduction, and verifyHistory returned no failures. The three registered seam controls
cannot catch it because they compare candidates against whatever introduction the author selected: they
validate the choice, not the choosing. You cannot fix "the author controls X" by deriving X from
something the author also controls. That is D-19/D-25 verbatim — the anchor must live outside the
audited party's authority — arriving a third time, now inside the keystone, and it is exactly why
Builds 1-2 are forced rather than preferred.

D-46: I reproduced it myself. Emptying criteria, gates, proseClaims and compatibilityScenarios — 17, 7,
8 and 2 entries — and pointing gateRoots at an empty directory yields EXIT 0, reporting "all registered
cases ran from this checkout" and "open behavior deltas: 0". "All registered cases ran" is vacuously
true over an empty set. The registry can be reduced to nothing and still report green.

D-45 and D-46 are the same defect at two levels: vacuity through emptiness. Empty the commit range or
empty the registry population — either way a universally-quantified check over an empty set passes.
seam=HEAD was the first instance and we fixed it AS an instance; the principle was never extracted, so
it came back one level up. Proposed general clause pending Mos: no universally-quantified registry
check may pass over an empty set — non-emptiness and anchoring are preconditions, not properties.

D-47: the new criteria are still instance-scoped. RM02-EVIDENCE-SUBJECT-BINDING covers only provider
evidence identity, not whether every registered gate binds evidence to its subject; RM02-TYPE-STRICT-
SCHEMA covers registry schema fields, not each gate's own discriminators. Do not relabel the
originating instances as the general clauses.

Dispatch PAUSED for the first time this session: the fix needs a non-author-controlled anchor, which
touches the provider/merge-base boundary and is adjacent to RM-60, which Mos and Jason own. Asked Mos
whether that anchoring is in scope for f10-coder here or crosses into RM-60, and whether the empty-set
principle becomes a general clause now.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 12:04:13 -05:00
mos-dt-0andClaude Opus 5 24a7915633 docs(remediation): stop item 1 restating the In-flight table — it went stale 3x by duplicating it
Item 1 has now gone stale three separate times in one session, every time for the same reason: it
restated lane state that the In-flight table already owns. That is D-26's class (restatement is lossy
every time) and D-43's mechanism (a second copy is a second thing to go stale). Fixing the wording a
fourth time would just buy another few hours.

So it no longer carries lane state at all — it points at the table and keeps only the two things that
are NOT restatements: read the table, and re-derive any board claim from the provider before
load-bearing use, because the board is sole-written and has no independent verifier.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 11:49:32 -05:00
mos-dt-0andClaude Opus 5 e1a3806292 docs(remediation): RM-02 re-review dispatched at 32b490a7; RM-61 exemption load-bearing for the first time
All four D-44 silent-defeat paths remediated in one hardening pass. I re-ran three of the four attacks
myself and they are dead: activationCommit injection is rejected as an author-controlled field with the
boundary now derived from the registry introduction (0b4aa475); the misspelled outputPatern is rejected
as an unknown field by the recursive schema; the global cross-commit duplicate-pipeline check is
present. Three new criteria registered with bound cases.

Exact-head CI 2197 is the notable one: pipeline success with 10 children, 9 success and 1 genuine
FAILURE — ci-postgres, type service, exit_code 0, exact #1000 teardown signature. The RM-61 exemption
fired for real on a gate-ready decision for the first time. I ran the machine check myself (exit 0,
terminal-green, exempted_steps 1, correct exemption id) and a negative control on the same record with
a wrong expected head (exit 1, not-terminal-green, exempted_steps 0). Both halves of RM-61 — the
signature-scoped exemption and the subject binding — demonstrated in a single run.

The pre-registered ACs deliberately do not re-check what I reproduced; they attack the FIX, because
every round on this mission the remediation introduced the next hole. H1 asks whether the new
derivation's inputs are author-controlled, S1 whether the schema closure is a class or an enumeration,
C2 whether the new criteria are clauses or just their originating instances.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 11:48:33 -05:00
mos-dt-0andClaude Opus 5 72b577eb85 docs(remediation): pre-register the RM-02 hardening re-review — attack the FIX, not the original bug
Registered at 32b490a7 before any reviewer read the diff. I verified three of the four attacks are dead
by re-running them myself: injecting activationCommit=HEAD now yields "author-controlled
activationCommit is forbidden; history boundary is derived from the registry introduction"; the
misspelled outputPatern is rejected as an unknown field by the recursive schema; the global
cross-commit duplicate check is present. The three criteria are registered with caseRefs 1/3/3.

So the AC set does not spend itself re-checking what I already reproduced. Every round on this mission
the remediation introduced the next hole — the commit-binding fix shipped a type confusion, the
type-strict fix was clean but the registry around it had four defeats — so the value is in whether the
NEW mechanism is defeatable.

Blocker 1's fix replaced an author-settable field with a derivation, and a derivation has inputs. H1
asks who controls them: can an author move the derived boundary by adding, renaming, deleting-and-
recreating or symlinking gates/gates.manifest.json, or by planting a second manifest earlier in
history? If so, blocker 1 is relocated rather than fixed. H2-H4 ask what first-parent traversal,
shallow clones, and path deletion do — fail closed or silently derive a wrong boundary.

S1 asks whether the schema closure is complete or merely enumerated: find a nested object the author
did not list and inject an unknown key there. C2 asks whether the new criteria express D-38 and D-40
generally or only their originating instances — a clause that covers only the instance that produced it
is not a clause.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 11:32:35 -05:00
mos-dt-0andClaude Opus 5 52114dd4eb docs(remediation): bank D-44 — the anti-inert-gate registry was inert-able four distinct ways
rev-974 NO-GO at 83d2ecb2. A4/A5/A6 confirmed and three further blockers found, two of them outside my
registered set. Each is a silent-defeat path of the registry itself: the activation seam inerts the
history audit (seam=HEAD gives 0 prospective commits and no failures — and HEAD's parent and the
introduction commit also pass, so forbidding equality with HEAD does not close it); a misspelled
outputPattern silently reduces an assertion to exit-code-only because the closed schema is not
recursive; two provider records sharing pipeline number 7 certify two different commits; and the D-38
and D-40 criteria are absent, with blocker 4 a live instance of the very D-38 clause that is missing.

The headline: all four passed CI, passed the canonical gate:verify, and passed 38/38 focused tests.
Greens discharged nothing. My own AC set was incomplete too — A3 corrects the prospective range to
eight commits, not the seven I wrote; I omitted the seam commit itself.

Mos ruled ALL FOUR in this PR, no trim, and sizing does not help: a registry that ships with a known
way to be silently defeated IS the inert gate it exists to detect. There is no core registry that is
integrity-complete without these — they are not hardening on top of the deliverable, they are the
deliverable. Theme: the registry's own checks must not be silently defeatable. Each fix carries a
red-first must-fail control proving the specific defeat is now caught, and that control set IS the
D-38/D-40 coverage work rather than being additive to it.

Blocker 1's fix keeps the value and replaces the mechanism: derive the seam from non-author-controlled
history (parent of the first first-parent commit introducing gates/gates.manifest.json) rather than
asserting it in an author-editable field, plus must-fail controls for HEAD, HEAD's parent, and the
introduction commit. If the work balloons past reviewability the only acceptable split is by
integrity-complete stage, never by deferring a blocker.

Method note banked as a positive: I could not reproduce "full verifier exit 0", traced my first attempt
to my own instrumentation artifact (json.dump reformatting the manifest), and stated the divergence
rather than wielding non-reproduction as a refutation. The vacuity itself reproduced and blocker 3 was
confirmed by construction. Non-reproduction is not refutation. Open thread: why my gate:verify exits 1
on checkout-preflight with outcome 42.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:49:42 -05:00
mos-dt-0andClaude Opus 5 8f70b1bc63 docs(remediation): pre-position the RM-02 activation-seam disposition so it survives a rotation
Mos ruled the disposition BEFORE the verdict, contingent on rev-974's independent A4/A5/A6. Recorded
here — not in the frozen AC file, which would be retrofitting, and not relayed to the reviewer, who
must reach A4 themselves or refute it.

The concern: activationCommit is the lower bound of the range required to carry own-tree registry
provenance, advancing it shrinks the audited set, the author advanced it to turn the author's own gate
green, and the only validation is --is-ancestor, which a commit satisfies against itself. The registry
built to detect gates that silently stopped enforcing may contain a field by which its own author can
make it stop enforcing, validated by a tautology.

A6 is the crux and stands alone from A4: even if f4fd5967 is the correct value — and it plausibly is,
since a pre-registry commit cannot carry a registry manifest — the mechanism question is independent.
If the audited party can relax its own audit behind a tautological check, the value being right today
is irrelevant and the next value need not be right.

If confirmed: BLOCKING at D-40's standard, and the fix is NOT reverting the value. It is making the
field non-author-relaxable — activationCommit independently derivable, equal to the real pre-registry
seam by construction rather than assertion — plus a must-fail negative control that a HEAD-valued or
over-advanced seam is REJECTED. The registry must be able to fail on its own seam being gamed.
If refuted: bounded, value stands, hardening tracked as a registry clause, and the refutation is itself
a finding worth having.

f10-coder commended with the distinction stated: it verified identity before committing and disclosed
the non-mechanical change unprompted, which is the only reason this is visible at all. But disclosure
is not sufficiency — an honest author flagging a self-relaxing change still made one. Honesty surfaced
it; the mechanism must catch it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:29:20 -05:00
mos-dt-0andClaude Opus 5 32384dab02 docs(remediation): board under budget by ROLLING OUT (D-43), not rewording; item 1 de-staled
Sequencing section rolled verbatim to BOARD-LEDGER — it was a pointer to a pointer, and MISSION.md
plus TASKS.md 5 remain canonical. Item 1 said RM-02 'needs rebase+CI+review'; rebase and CI are done
and it is in review at 83d2ecb2.

Second application of D-43's rule today: delete-and-reference, never paraphrase-to-save-bytes.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:27:28 -05:00
mos-dt-0andClaude Opus 5 777a8f7f5b docs(remediation): RM-02 in review at 83d2ecb2; crux is the activation-seam question (A4)
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:26:11 -05:00
mos-dt-0andClaude Opus 5 995f8b6a24 docs(remediation): pre-register RM-02 keystone review ACs before the reviewer reads the diff
Registered at head 83d2ecb2 before dispatch. Prior reviews 63/65 are superseded and this head carries
no live review of any kind, so the keystone gets a full independent review.

The crux is the one non-mechanical change, which f10-coder disclosed unprompted: activationCommit
advanced f65e9ea6 -> f4fd5967 so that the newly merged pre-registry RM-61 commit is no longer treated
as prospective. activationCommit sets the lower bound of the commit range required to carry own-tree
registry provenance, so advancing it SHRINKS that set. The value is plausibly correct — a pre-registry
commit cannot carry a registry manifest — but the change was made by the author to turn the author's
own gate from red to green, which is the self-verification shape the charter warns about.

Registered as A1-A6 without a verdict from me (D-39). A4 is the sharp one: the only validation on the
field is merge-base --is-ancestor activationCommit head, and a commit is its own ancestor, so setting
activationCommit = HEAD would empty the prospective range and the per-commit provenance loop would
iterate zero times. Whether that makes the history check pass VACUOUSLY is for rev-974 to determine and
report — an author-settable field that can inert the anti-inert-gate registry's own history check would
be the disease inside the cure again. A5 asks whether a must-fail negative control exists for it, since
RM-02's own founding rule is that a gate with no proven failure path manufactures evidence.

B1/B2 carry Mos's scope ruling that the D-38 bind-to-subject and D-40 type-strict clauses land in THIS
PR; B3 confirms D-42's clause is deliberately absent rather than forgotten.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:24:24 -05:00
mos-dt-0andClaude Opus 5 d0a510d28d docs(remediation): scope rulings banked; D-43 elevated onto RM-34 — the control plane has no verifier
SCOPE (Mos): D-38 (bind evidence to subject) and D-40 (type-strict discriminator inputs) land IN the
RM-02 PR — cheap registry-coverage clauses, satisfiable now, and RM-02 literally IS the registry, so
codifying what its own delivery learned about how gates fail is the coherent move.

D-42 splits, and the reason is sharper than "needs experimentation": landing its clause in-PR today
would give the registry a clause with NOTHING to satisfy it, so the registry would go red on its own
clause and couple the keystone's landing to infra work. Wrong coupling. So (a) the infra experiment
proving the pin enforces via the negative case, in Mos's D-37/D-41/D-42 cluster; (b) the registry
clause "provider-side enforcement requires an OBSERVED negative control", in a follow-up RM-02
increment once (a) gives it something to check. Named owner, not a vacuous check and not a silent
omission.

D-43 point 3 elevated to the PRIMARY requirement on RM-34, with the table that makes it plain: code has
rev-974, gates have the merge-gate, CI has the JSON scan, and the control plane has NOTHING. Every
other layer earned a verifier from a live failure; the board never did, and it is the artifact every
other decision is staged from. "Validate the checkpoint" must mean re-derive the board's claims from
ground truth — not that the file parses or that a successor can read it. It belongs to the
coordinator-daemon deliverable: the control plane needs its own verifier the way every other layer got
one. Today's catch was discipline, not mechanism.

Interim rule binding on BOTH seats until that mechanism exists, and Mos adopted it against himself:
re-derive a board claim from ground truth before any load-bearing use. The orchestrator does it before
dispatch; the coordinator does it before acting on or relaying a board claim that gates a decision.

D-11b addendum: the false-NEGATIVE twin. /user returns 403 on a least-privilege seat token (no
read:user) and reads exactly like an unprovisioned seat. The real assertion is the DIFFERENTIAL —
authenticated push=true vs unauthenticated push=false proves the token caused the difference. A single
endpoint can be true for anyone or refused for an unrelated scope reason. Would have escalated a
working seat as unprovisioned and stalled the keystone on a phantom.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:02:19 -05:00
mos-dt-0andClaude Opus 5 8cef39f924 docs(remediation): RM-61 MERGED; bank D-43 — I inverted a board fact while compressing to fit the budget
#1033 merged f4fd5967, verified by property: merged=true + merge commit, #1034 (delivery) CLOSED,
#1000 (retirement trigger) still OPEN. The exemption is on main and RM-02 is unblocked.

D-43 is mine. Compressing RM-02's board row to meet the 8KB budget, I turned "2 reviews clear" into
"2 live REQUEST_CHANGES" — an inversion. Provider truth: reviews 63 and 65 are at superseded heads and
live REQUEST_CHANGES at f9746b23 is empty. The real state is subtler than either wording: no live
blocker AND no live approval, because the head carries no review at all.

Caught only by re-deriving RM-02's state from the provider before dispatching, not by re-reading the
board. I was one message from briefing f10-coder to remediate two blocking reviews that do not exist.

The transferable part: this board carries a hard <8KB budget, it exceeded that budget four times in one
session, and each time I shaved prose to fit. Compression IS restatement, and this board's own rule is
"REFERENCE, do not restate" (D-26) because restatement is lossy every time. The budget therefore forces
the exact operation the board forbids, on its most load-bearing table. I flagged that as a risk earlier
in the session; it then materialised as an actual error.

Rule banked: meet a size budget by ROLLING content out to BOARD-LEDGER.md, never by rewording what
stays. Deleting a row and pointing at its authoritative home is safe; paraphrasing to save bytes is not.
Applied immediately — this commit rolls the Decisions-log narrative out verbatim rather than trimming
it, and the board is back under budget at 8096.

And the deeper one, onto RM-34: the orchestrator is the board's sole writer, so nothing external checks
the board against reality. Code has rev-974, gates have the merge-gate, CI has the JSON scan — the
control plane has no independent verifier. Handoff validation must include re-deriving the board's
claims from the provider, not merely confirming a successor can read the file.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:56:44 -05:00
mos-dt-0andClaude Opus 5 f3c100f814 docs(remediation): bank D-42 — the head-pin's negative control has never been observed
merge-gate.md says it outright: a successful merge is NOT evidence the pin worked, only the negative
case is. On mosaicstack Gitea a merge against a WRONG head_commit_id has never been attempted, so every
head-pinned merge to date is equally consistent with the pin working and with the pin being ignored.

That is D-23's class — the queue guard "ran" and returned pass for every possible input; the pin
"holds" on every merge that would have succeeded anyway. By the mission's own standard (every
gate-introducing task carries a registered must-fail negative control; a gate with no proven failure
path manufactures evidence) the head-pin is unregistered in substance however it reads in the runbook.

Not blocking #1033: that head is coordinator-frozen with both the orchestrator and coder-mos1 holding,
so there is no concurrent pusher for the pin to defend against — its protection is only load-bearing on
a contested head. Raised by Mos while assigning the merge; Mos owns it and has filed it as an infra
task in the D-37/D-41 cluster, to be proven before any contested-head merge.

Requirement on RM-02: the negative-control clause must cover provider-side enforcement mechanisms, not
only in-repo checks. "The API accepted our parameter" is not evidence the API honours it — the same
true-answer-to-a-different-question shape as D-24 and D-38.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:52:01 -05:00
mos-dt-0andClaude Opus 5 2750cc4842 docs(remediation): D-38c — PR metadata failed a THIRD time on #1033; delivery-issue gap ruled
Merge-gate NO-GO with every code and CI gate verified, including the --expect-commit machine-check it
was told to exercise (9/9 JSON, exempted_steps 0, expected_commit == commit). The blocker was the body:
only "Refs #1000", no "Closes #N", and Mosaic completion requires a linked issue closed.

Third distinct metadata failure on one PR — missing commit binding, then a stale DO-NOT-MERGE body
describing a dead head, now an incomplete link. Each time the code was fine and the metadata was
unbound, stale, or incomplete. Nothing re-binds PR metadata to the head or checks it for completeness
until a gate does, and by then it costs a round trip.

The subtlety that makes it a real ruling: #1033 must NOT Closes #1000. The teardown defect stays open,
and #1000 is the exemption's own retirement trigger — auto-closing it would delete the retirement
trigger for the workaround being merged, turning a bounded exemption into a permanent one by side
effect. Hence a delivery issue distinct from the defect issue: #1034, with Closes #1034 added and
Refs #1000 kept.

Metadata-only, head never moved: verified by read-back that head is still 57cae04f, Closes #1034
present, Refs #1000 present, Closes #1000 ABSENT, review 70 still CURRENT with zero live
REQUEST_CHANGES, #1034 open. coder-mos1 stayed parked; nobody pushed.

Process gap ruled by Mos: every remediation delivery PR needs a delivery issue to Close, created at
OPEN-TIME rather than discovered at gate-time. #1032 already Closes #1019; #1033 had none.

Both provider writes went through the tea->API fallback — the same path that silently dropped #1033's
draft property at creation — so both were read back and verified by property, not by exit code.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:49:23 -05:00
mos-dt-0andClaude Opus 5 553474e4c8 docs(remediation): RM-61 GATE-READY at 57cae04f — review 70 APPROVED, CI 2194 9/9, D-40 closed
rev-974 approved at the exact head with no blocking and no non-blocking findings. Verified by me from
the provider rather than relayed: head unmoved, review 70 bound to 57cae04f, pipeline 2194 terminal
success at that commit, 9 children all success including clone (a 9-of-9 scan, not the 8-of-9 D-33 was
banked for). Queue guard run for the push gate and NOT cited — state=unknown exit 0 on branch=main,
D-23 verbatim.

The redundant-clause question I handed rev-974 without a conclusion came back answered by mutation
testing, and I re-ran both mutations myself: deleting the bool clause alone leaves the 17-case harness
green (not load-bearing), deleting the exact-type clause alone fails it (load-bearing, mutation
killed). So the exact-type clause carries the protection and the bool clause is inert-but-defensive
against a future type()->isinstance() edit, which the true/false cases would catch. Removing it alone
cannot reopen D-40. Better answer than either of us had, obtained by asking rather than telling —
D-39 paid for itself on the first review after adoption.

Disclosed to Mos rather than absorbed: JSON `-0` decodes to Python integer zero and passes. rev-974
ruled it not a type confusion because it is a valid JSON integer numerically equal to zero. I agree on
the merits, but it is a reviewer judgement inside the exemption and belongs in front of the gate.

Gate steps 1-3 are satisfied. Steps 4 and 5 — merge-gate verdict and head-pinned merge — are Mos's.
Head frozen; coder-mos1 parked idle per ruling (c) and will not push; neither will I.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:40:15 -05:00
mos-dt-0andClaude Opus 5 0de8ccb52c docs(remediation): RM-62 — fleet management is a PREREQUISITE, and the rotation claim is corrected
Mos ruled (c): coder-mos1 stays idle/parked, not manually rotated. It holds no in-flight work, so
there is nothing to rotate FOR, and a manual in-pane restart would dress a missing mechanism as a
lifecycle operation — the D-41 overclaim itself. It stays AVAILABLE through RM-61's re-review in case
that review needs its context; the next NEW lane goes to a fresh seat, not to a seat at 67%.

RM-62 filed, because a dependency stated as prose with no owner becomes the permanent gap the charter
warns about. Bringing the execution fleet under roster/systemd management BLOCKS RM-50, RM-58 and
P-LIFECYCLE-001 — each is unsatisfiable against its real population until it lands. Banked explicitly
that both would FAIL against their real target today: RM-50 applied now quarantines the seat
implementing RM-50, and RM-58 has no mechanical reset path for any seat that needs one. RM-50 and
RM-58 now carry RM-62 as a hard depends_on edge, and RM-50 carries the requirement that acceptance be
proved against the unmanaged execution fleet rather than the roster-managed canaries.

RECORD CORRECTION, initiated by Mos and banked here: this session's opening rotation validated the
checkpoint+rehydration DESIGN losslessly — the residency attestation genuinely passed from the files —
but the MECHANISM was a manual pane respawn. "The handoff rehydrated losslessly" is earned; "rotation
worked" overclaims a mechanism that does not exist, and that overclaim is D-41. Same distinction as
D-23's inert guard: the step ran, one property was observed, the mechanism was not. Board header now
says so rather than implying a lifecycle rotation occurred.

D-37 and D-41 are one cluster — the execution fleet lacks both its shared-infrastructure and its
lifecycle management. Mos owns both, sequenced at a seam, never mid-lane.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:34:10 -05:00
mos-dt-0andClaude Opus 5 37402e9770 docs(remediation): bank D-41 — the whole execution fleet is UNMANAGED, so RM-50/RM-58 have no surface
Went to rotate coder-mos1 mechanically; `mosaic fleet restart` cannot reach it. Every seat executing
this mission is systemd inactive/disabled and flagged UNMANAGED — coder-mos1, rev-974, f10-coder,
merge-gate, the pm-scouts, rev-3107b, ultron-3107, and mos-remediation itself. The roster-managed
population is a different set of seats from the ones doing the work.

RM-50 applied today would quarantine the entire remediation fleet including the seat implementing it.
RM-58's mechanical out-of-band reset cannot be performed at all, so the only rotation available is what
D-4 says does not count: asking the agent, or killing a pane by hand. Requirement banked on both: their
acceptance must be demonstrated against the UNMANAGED execution population, because a criterion proved
only on roster-managed canaries is tested on the wrong population — D-17's coverage class one layer up.

Today's rotation is therefore labelled honestly as a manual pane restart with a hand-verified handoff,
not as a lifecycle operation. The step ran; the property was not observed (cf. D-23).

Did not run fleet restart against a disabled unit while the live pane held RM-61 and RM-03 state.
Disposition escalated to Mos.

Also records the handoff artifact as the positive control: typed state, and it surfaced D-12 recurring
live (PR #1033's draft property silently dropped by a wrapper fallback), an unrunnable check declared
rather than substituted, and suspicions labelled as suspicions.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:31:17 -05:00
mos-dt-0andClaude Opus 5 01831814b6 docs(remediation): board — D-40 ruled BLOCKING, RM-61 rebuilding, TS1-TS12 pre-registered
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:25:54 -05:00
mos-dt-0andClaude Opus 5 86cd1a0f46 docs(remediation): D-40 RULED BLOCKING; pre-register type-strict ACs before the fix is pushed
Mos ruled BLOCKING on the exit_code type confusion. Both of us had leaned non-blocking on the
unreachability argument and neither shipped it. The two decisive grounds: the direction is
wrong-ACCEPT (false and 0.0 GRANT the exemption), which is this mission's disqualifying direction and
exactly why RR12 was tolerable; and "Woodpecker is Go with an int type" is structurally the same
incidental-correlate argument RM-61 itself forbade for the signature — you cannot certify the
discriminator against infra-shift and then defend a hole in it with an infra-stability assumption.

Generalised into an RM-02 standing clause, which is the real prize: discriminator and comparison
inputs must be TYPE-STRICT. A comparison that accepts a type it should not is a wrong-ACCEPT hole by
construction; `== 0` matching False and 0.0 is one instance of a class. D-40 is the instance, the
clause is the fix. It sits alongside the D-38 clause (does this gate bind its evidence to its subject).

D-39b banks the roles-swapped half: the author does not adjudicate its own PR's blocker status and
does not move the head to enforce it. Symmetric with D-39 — a seat with a stake in the answer does not
settle the question, and a conservative motive exempts neither direction.

ACs are registered NOW, before coder-mos1 pushes and before any reviewer reads a diff; at registration
the fix exists only as an unpushed local commit I have not read, so there is no diff to retrofit to.
They also state explicitly which cases are genuine RED-FIRST (false, 0.0 — currently wrongly exempting)
and which are only regression guards ("0", null — already blocking), because demanding an impossible
red for the latter two invites weakening something real to manufacture it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:23:16 -05:00
mos-dt-0andClaude Opus 5 249335e515 docs(remediation): bank D-39/D-40 — gate-ready reached, then withdrawn on a finding I disclosed
D-39: I contaminated an open independent review. RR12 was an open registered check and I sent rev-974
my CONCLUSION, not just my observation. rev-974 then downgraded an automated Codex review that had
flagged RR12 as a blocker, in line with my framing. The bias sat in my instrument, not the reviewer's
diligence — a subordinate is agreeable by construction, and the divergence instruction I attached
cannot undo having named the answer first. Mos adopted the rule fleet-wide: a dispatcher may relay
observations and reproductions into an open review, never its own verdict on an open check.
Re-adjudicated by a mechanically fresh seat with no access to my framing: NON-BLOCKING, independently,
on stronger evidence than either prior pass (accept-set matrix proving the accepted set is a strict
subset of a correct case-insensitive comparison's, so it cannot false-certify; exploit path hunted and
ruled out; all 0x110000 codepoints scanned for a fold that could smuggle non-hex onto a valid SHA).
So contamination did not change the answer, and the finding stands anyway — a correct answer reached
by a contaminated process still corrupts the process.

D-40: that same fresh seat looked outside its question and found a type confusion inside the exact
conjunction the exemption rests on. `step.get("exit_code") == 0` is True for JSON false, and
coder-mos1 added the float case. Verified by me on the real #2188 record: false and 0.0 both yield
exit 0 with exempted_steps 1 — the exemption GRANTED; "0" and null correctly block. Two of four
near-miss types satisfy a conjunction whose whole justification is that it is exactly scoped.

Consequence: I reported #1033 gate-ready at 033b2ffb (RR1-RR12 pass, review 69 APPROVED, CI #2193
success 9/9) and then had to hand Mos a finding that may disqualify what I had just certified. Better
that than defending the report. Disposition is Mos's; coder-mos1 escalated it to blocker unilaterally
and moved to push — held, because the author does not adjudicate their own PR and does not void a live
APPROVED review plus terminal-green CI by pushing. Head frozen, fix prepared and unpushed, ACKed.

Board doctrine now carries both rules: never relay a conclusion into an open review, and the author
never adjudicates their own blocker status.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:20:15 -05:00
mos-dt-0andClaude Opus 5 d9ab6026c8 docs(remediation): RM-61 tick — twelve checks pass, blocker moved to metadata, head never moved
rev-974 review 68 @ 033b2ffb: RR1-RR12 all PASS. RR7 is the strong one — all four binding predicates
proved RED against the old e7b29219 verifier, and the original attack under the old interface returned
exit 0 with exempted_steps=1, proving the PRIOR DEFECT rather than merely unsupported syntax.

The remaining blocker was metadata, not code: the live PR body still said "DO NOT MERGE" and "the
exemption will not be implemented", describing an earlier head. Verified independently — the controls
were injected in 3931b0e2/9455cd6a/25ac5971/ef9d23ab and the final delta does not touch
.woodpecker/ci.yml at all. The body was true when written and went stale as the branch evolved. That
is D-38 one layer out: the PR that binds evidence to its subject shipped a description that was not
bound to its subject, and D-36's staleness class on provider metadata rather than a repo file.

Fixed as metadata only. Head confirmed unmoved at 033b2ffb from both provider and git, body SHA-256
b0198d98 matched the author's reported digest byte-for-byte, both stale strings absent. Because the
commit never moved, the twelve results stand and no third review round is owed — only the discharge
of the finding by the reviewer who raised it.

Exact-head CI #2193: success, 9 children, 9/9 success including clone, read from -f json (D-33).

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 09:10:32 -05:00
mos-dt-0andClaude Opus 5 50c0340add docs(remediation): bank D-37/D-38, pre-register RM-61 re-review, rebuild board for a cold read
D-38 — RM-61's terminal-green verifier certified the right RECORD for the wrong COMMIT. rev-974
mutated only #2188's commit field and the gate still exited 0. Confirmed by construction: at
e7b29219 the whole verifier had exactly one "commit" line (159), no expected-head parameter, no
comparison, no failure path. D-24 at the gate layer — a true answer to a different question.
The transferable half is the AC set, not the verifier: AC1-AC8 ALL PASSED and the PR was still
NO GO, because every registered check tested whether the signature discriminates and none tested
whether the evidence was bound to its subject (coverage-failure-mode-2, D-17 class). Mos ruled a
STANDING clause into RM-02 coverage: "does this gate bind its evidence to the subject under
review?" — every gate can fail this way and pass its own ACs.

D-37 — one shared .git/config silently re-identified EVERY worktree. extensions.worktreeConfig is
unset, so a worker's repo-local identity write rebinds all linked worktrees at once; the
orchestrator checkout and rev-974's review worktree both authored as coder-mos1. Distinct from
D-34, not an instance: MOSAIC_GIT_IDENTITY was exported and correct and still resolved wrong.
Sharp edge is gate-16 defeated in the artifact — the reviewer would author its pre-registered ACs
as the author of the code under review. No contamination occurred. Containment (explicit -c, no
shared-config rewrites mid-flight) is the standing order; the real fix is authorised and owned by
Mos, sequenced at a quiet seam. #1024 is implicated: repo-local pinning is the colliding mechanism.

Also pre-registers the twelve RM-61 re-review checks at exact head 033b2ffb BEFORE the reviewer
reads the diff, and rebuilds the board for a cold read — RM-61 "building", "nothing implemented
yet", and DECISION-1/2/3 "must be ruled" were all stale, the D-36 class again at the same seam.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 08:59:40 -05:00
mos-dt-0andClaude Opus 5 345d152790 docs(remediation): RM-61 result — kill criterion NOT triggered, signature discriminates structurally
coder-mos1 ran two real ci-postgres failure controls; the orchestrator verified the JSON
records independently. #2189 (startup failure) exit 1 and #2191 (post-readiness crash,
log proves ready then postmaster killed) exit 137 both take the workflow and the test
step down — terminal red. #2188, the genuine artifact, carries exit_code 0 under a
SUCCESSFUL workflow.

So the discriminator is structural — a failed service step with exit 0 under a successful
workflow — not the message string and not an incidental correlate like node or timestamp,
which were explicitly forbidden because they pass today and mask a real failure the moment
infrastructure shifts.

Verifier: exit 0 with one named exemption on the artifact; exit 1 with exempted_steps 0 on
BOTH real controls. No fetch, trigger, retry or re-roll — the coin flip is removed, not
codified.

PR #1033 dispatched to rev-974 with eight acceptance checks pre-registered before the diff
was read; AC2 (both real failures must NOT be exempted) is the crux and a REJECT if it fails.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 08:44:46 -05:00
mos-dt-0andClaude Opus 5 f11f257368 docs(remediation): bank D-36 — rotation-seam audit found three stale restatements on the board
Preparing the checkpoint for a cold read surfaced three stale sections, each a copy of
text owned elsewhere, each of which would have misled the incoming orchestrator: a
delivery-gate list still omitting the merge-gate step (D-26's own defect, still on the
board after MISSION.md was fixed); a capability rule superseded by D-13/D-15; and
DECISION-1 still marked CONTESTED hours after it was ruled.

None were wrong when written. All three drifted because they were copies — D-14 three
times in one artifact. The failure is not that someone forgot to update three lines; it
is that three lines existed to forget.

The rotation seam is what surfaced it. A familiar section is skimmed for the line you
came for; preparing state to be read cold by a stranger is a different act from
maintaining it, and catches a class ordinary use cannot.

RM-34: a handoff must VALIDATE the checkpoint, not merely write it. RM-02 registers the
general form with a must-fail on divergence. Interim: audit the board against its
sources at every rotation seam.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 08:14:04 -05:00
mos-dt-0andClaude Opus 5 6c779595e1 docs(remediation): rotation checkpoint — board rebuilt for a cold read, three stale restatements removed
Orchestrator rotating at ~803k tokens (~4x threshold). A mission built on
rotation-not-compaction should not run its own coordinator past it.

Board rewritten as the rehydration artifact: in-flight state, a read-this-first block
for the incoming seat, and the live rulings it most needs. Under the 8KB cap.

AUDIT AT THE SEAM found THREE stale restatements on this board, each of which would have
misled the incoming orchestrator:
  1. the delivery-gate list still OMITTED the merge-gate verdict step (the D-26 defect
     itself, still sitting on the board after MISSION.md was corrected);
  2. capability described as 'token-file set = authoritative registry', superseded by
     D-13/D-15 (capability is per-path; assert permissions.push as that seat);
  3. Sequencing still said DECISION-1 was CONTESTED and 'do not treat it as settled'
     hours after it was RULED — an incoming seat would have re-litigated a closed decision.

All three were restatements of text owned elsewhere. Replaced with references, per the
mission's own render-not-restate principle: a second copy is a second thing to go stale,
and this board proved it three times in one night.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 08:13:12 -05:00
mos-dt-0andClaude Opus 5 cc097f36c5 docs(remediation): re-run failed; RM-02 blocked on RM-61, declared bound honoured
Pipeline #2188 at the same head: ci-postgres the sole failure, everything else success
including gate-verify. f10-coder independently confirmed and applied the pre-registered
rule itself.

RM-02 blocked. No ad-hoc exemption, no third roll. Recorded why: two failures against one
earlier clean run makes 'best of five' feel reasonable, and the point of declaring the
bound in advance is that it binds when the result is inconvenient. A third roll would
have been indistinguishable from diligence, including to the person doing it.

Data for RM-61: the artifact hit twice consecutively at f9746b23 while #2184 was clean at
38f1b249, so it may cluster rather than be uniformly random — which makes a one-shot
re-roll close to worthless and strengthens the ruling that it must not become policy.

And the illustration: the anti-inert-gate registry is blocked by an artifact that makes
gate evidence unreliable. The thesis demonstrating itself on its own keystone.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 01:34:20 -05:00
mos-dt-0andClaude Opus 5 56d8e8a3d5 docs(remediation): record the bounded re-trigger as a stopgap; mark the first end-to-end merge stack
The re-trigger guardrail, recorded so it cannot become practice: one bounded,
pre-declared attempt at the same head with the response to each outcome fixed before
triggering. Re-running until the desired answer appears is p-hacking the pipeline, and
silently nobody can tell it from diligence — including the person doing it. Per Mos: a
per-PR free re-roll would be D-21 normalisation wearing a new hat. RM-61 must make the
re-roll unnecessary, not codify it, and a clean re-run does not retire RM-61.

Milestone: RM-03/#1032 completed independent review -> CI terminal-green -> merge-gate GO
-> coordinator -> held for owner, the first time end-to-end. GO posted under the gate's
own minted identity by a seat that structurally cannot merge. Head verified unmoved after
the verdict, so the commit-bound GO stands.

The first delivery through the complete stack is also the last one gated by a check that
could not fail — RM-03 is that check's fix.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 01:22:32 -05:00
mos-dt-0andClaude Opus 5 4589659bc1 docs(remediation): board — RM-03 GATE-READY, merge-gate assigned, held for Jason
First genuine gate-ready of the mission. Head triple equal at 78ec47cd, latest review
APPROVED at the current head, CI 9/9 by JSON scan with two-observer agreement.

Recorded the shape worth remembering: the queue guard is still inert for this merge
because RM-03 is the fix — the last merge to pass through the broken gate is the one
that fixes it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 01:15:05 -05:00
mos-dt-0andClaude Opus 5 357a636a3a docs(remediation): promote redundant-observation to charter; bank D-35 (tool caught what attention could not)
Charter gains a fifth principle from D-33: two observers of the same evidence,
disagreeing, catch what neither catches alone — applied to evidence GATHERING, not just
judgement. A summary that resembles an enumeration is more dangerous than one that
obviously summarises; prefer the machine-readable record and state counts so divergence
is detectable.

D-35: while editing merge-gate.md to fix D-33, the coordinator recalled the mandate
string instead of reading it and the Edit tool's exact-match REJECTED it. Third instance
for that author, inside the turn fixing another instance of the same class — and the
only one that did not reach a document, because a mechanism caught it.

A rule that fails in its authors but is caught by a tool has told you where it belongs.
RM-02 should enforce verbatim citation by construction, as the Edit tool did by accident
of design.

Fix landed by annotating the source: merge-gate.md mandates 3 and 4 now require the
scan and count from the JSON record. The shared wrapper was deliberately NOT modified
mid-flight — three lanes are reading it; fix at a seam.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:53:27 -05:00
mos-dt-0andClaude Opus 5 9e205e8201 docs(remediation): bank D-34 — a context reset silently strips a seat's credential identity
rev-974 finished its RM-02 review and could not post it: pr-review.sh failed with
'Gitea token not found'. Verified — with MOSAIC_GIT_IDENTITY unset the token does not
resolve; with it set it resolves. The token file was correct throughout.

My own context reset wiped the seat's exported identity and my rehydration brief did not
re-establish it. git config mosaic.gitIdentity is persistent and per-worktree;
MOSAIC_GIT_IDENTITY is ephemeral and per-context. rev-974 works from ~/agent-work with no
git-config fallback, so it had no warning and the loss surfaced only when it next needed
a credential.

Intersection of two banked findings, created by acting on one: D-31 prescribes rotation,
D-11a requires identity coherence, and nothing said rotation is a credential-affecting
operation. The fix for one failure introduced another.

RM-34: rotation must re-establish AND verify seat identity before handing over work.
RM-50: prefer the durable binding (mosaic.gitIdentity in the seat's repo) so identity
survives a reset by construction. Interim: every rehydration brief re-exports identity.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:51:21 -05:00
mos-dt-0andClaude Opus 5 73a313301b docs(remediation): bank D-33 — the full-step-scan tool prunes a step in default output
coder-mos1 scanned pipeline #2186 with -f json and found 9/9 child steps; my scan of the
same pipeline in the wrapper's default text mode showed 8. Verified: text mode omits
clone (JSON shows the ci workflow entry, clone, and the 8 visible ones).

Every full step scan performed tonight enumerated 8 of 9 real child steps and reported
it as complete. clone succeeded throughout so no verdict changes — but the method was
incomplete and its user did not know.

The merge-gate mandate requires a FULL step scan and requires verdicts to enumerate the
step count. A verdict citing 8 where 9 exist is non-conforming evidence, and a gate using
this wrapper's default output would produce exactly that while believing it complied.

The shape is the session's thesis aimed at the detection tool: the doc says read the
artifact not the summary, and text mode IS a summary that looks like an artifact. Compare
D-24 — mergeable was a true answer to a different question; this is a true answer to a
smaller one.

Caught only because two observers' counts disagreed; neither alone would have found it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:49:01 -05:00
mos-dt-0andClaude Opus 5 eddf718a5c docs(remediation): board — RM-02 frozen at 38f1b249 with a fully clean 9/9 scan
First run on this branch where ci-postgres passed, so no exemption question arises.
Recorded that the artifact's intermittency is evidence FOR RM-61's negative-control
requirement: intermittent means delivery is a coin flip until the signature is proven to
discriminate from a real database failure.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:35:51 -05:00
mos-dt-0andClaude Opus 5 c83a3cd3e2 docs(remediation): bank D-32 — the repaired gate shipped with a documented switch to skip it
rev-974 blocked RM-03: pr-merge.sh still ships --skip-queue-guard at five sites
including a worked example. It proved this rather than reading it — stubbed the guard to
exit 99, ran a real fixture merge with the flag, and observed the guard never called,
provider payload created, 'merged successfully', exit 0.

Disqualifying because RM-03 repairs a mandatory gate that has never been able to fail;
shipping that repair with a documented bypass means the gate merely requires one flag
instead of zero, and every merge-side CANNOT_ASSERT/HOLD semantic is skipped. L0 bars
equivalent skip switches, and the merge-gate role doc names this exact hazard about
force_merge — adjacent to the field you came to edit, at the moment you are most
motivated to reach for it.

Generalizable: repairing a gate is incomplete while any supported path skips it. The
failure changes from 'cannot block' to 'can be told not to' — the same outcome one
keystroke later. Removing the bypass is part of the repair.

Everything else passed independently, including the 160 KiB stdin transport where #1023
regressed.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:33:18 -05:00
mos-dt-0andClaude Opus 5 bf8c6f4a89 docs(remediation): bank D-31 — seat ran past 100% context with 28 uncommitted files
coder-mos1 hit 102.5%/372k on RM-03 with 28 modified files uncommitted and its branch
still at base — a full context window spent with nothing durable. Caught by polling seat
state, not by any system signal. Nothing warned anyone: no threshold alert, no
pre-compaction hook.

The founding failure mode of this mission — compaction destroying in-flight work —
nearly hit the mission's own delivery twice in one night. RM-01 survived because it had
committed work when checkpointed; this one had none. Commit-then-rotate works;
rotate-without-commit loses everything.

RM-34: a context threshold is not enough — rotation must force a durable checkpoint and
refuse to rotate a seat with uncommitted work. RM-50: seat context is observable state
and must be monitored; relying on an orchestrator to poll is instructions-not-enforcement
applied to lifecycle. Brief doctrine: commit early, commit WIP.

Adjacent: the diff spans 5 guides and 11 templates against a brief scoped to one script.
Queried, not assumed — but a 28-file diff from a one-script brief is a scope signal
regardless of the answer.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:07:59 -05:00
mos-dt-0andClaude Opus 5 bdf8932328 docs(remediation): RM-61 terminal-green exemption ruled B, with sequencing correction
Condition 1 tested: the signature is stable — pods "wp-svc-<ULID>-ci-postgres" not
found across all five observed failures, an orchestration-layer lookup miss structurally
unlike a service-level failure.

But discrimination is UNPROVEN: every observation co-occurs with a demonstrably working
database, and we have never seen a real ci-postgres failure on this provider. If
PostgreSQL crashes and the pod is GC'd, the status query may also return pod-not-found —
the exemption would over-match and mask a real failure.

So conditions 1 and 2 are not independent: 2 is the evidence for 1. Build the negative
control first, prove a real failure produces a different signature, then adopt the
exemption. Kill criterion stated in advance: if an injected real failure also yields
pod-not-found, B is unsafe and we do A.

Filed as RM-61, unassigned — no free write-capable seat; flagged rather than stacked
onto a busy lane.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:04:32 -05:00
mos-dt-0andClaude Opus 5 16d11cd6cd docs(remediation): bank D-29 (syntactic criterion binding) and D-30 (false comparator, mine)
D-29: rev-974 moved two criterion bindings to an unrelated case, reformatted the
manifest, and gate:verify still exited 0. The registry verifies a criterion HAS a
binding, not that the bound case can fail for that criterion's stated reason —
RM02-REQ-03 unsatisfied. The keystone reproduced the defect it exists to eliminate, in
its own coverage check. Caught only by mutating and re-running; inspection would have
passed it.

D-30: my review brief claimed the ci-postgres FAIL appeared on #2167 — it did not
(#2167 is OK). My own banked D-21 says so explicitly; I restated from memory instead of
reading my record. D-26 recurring, in a reviewer brief, hours after promoting
render-not-restate to the charter.

The harm is not the inaccuracy but that I supplied a reviewer with fabricated supporting
evidence for my own reading. It refuted me — query-for-refutation paying for itself in
the same document that introduced it.

Requirement: briefs cite evidence from the record with identifiers, never from recall.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:59:25 -05:00
mos-dt-0andClaude Opus 5 8ce77fcb0d docs(remediation): board — RM-02 frozen at 9b4d4beb, CI green, review in flight
Head triple verified independently twice (orchestrator + f10-coder): local = origin =
PR #1030 = pipeline #2182. Full step scan rather than a tests-complete inference.
Queue guard not offered as evidence.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:41:52 -05:00
mos-dt-0andClaude Opus 5 cdd5568adb docs(remediation): promote query-for-refutation to charter doctrine
Per Mos. A subordinate asked to confirm a hypothesis will agree — the bias is induced by
the query, not by the answerer's diligence. 'The DB flaked, please confirm' and 'confirm
or refute, with the log line that proves it' are different instruments returning
different answers to the same question.

This matters most with agent subordinates, which are agreeable by construction, so the
discipline cannot rest on the answerer being rigorous — it must be built into how the
question is asked.

Origin: the orchestrator's ci-postgres hypothesis was refuted by the implementing seat
with log evidence and then settled by reproduction. Phrased for confirmation, it would
have returned agreement and D-21 would have been re-classified on a false premise,
silently corrupting a banked finding.

Operational form: state the hypothesis as yours, ask for evidence that kills it, say
what would change your mind, and reproduce when the answer is consequential. Added to
KICKSTART's standing invariants so it survives compaction.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:21:15 -05:00
mos-dt-0andClaude Opus 5 ff4b45b025 docs(remediation): RM-03 CANNOT_ASSERT semantics ruled (option B)
Resolves an ambiguity in the orchestrator's own brief, which required CANNOT_ASSERT to
neither silently pass nor permanently block without distinguishing push from merge.
coder-mos1 stopped and asked rather than inferring authorisation; Codex security
independently flagged CWE-693.

Ruled B: merge fails CLOSED (proceeding without exact-head CI evidence is D-23's
condition in a narrower costume), push degrades AUDITED (blocking during an outage
bricks delivery — the Pi-brick class we already banked). A temporary block pending
evidence is not a permanent block, and merge is separately gated by the merge-gate and
coordinator, so nothing is stranded.

Conditions: distinct exit code or the tri-state is destroyed; the audit record asserted
by a registered case, not assumed, or 'audited' is a claim dressed as a property;
retryable and self-clearing; cases observed RED first; no silent degraded merge path —
break-glass belongs to RM-05.

Option C rejected: it bricks push during an outage and defers the degraded path, which
in this codebase means a silent bypass appears under incident pressure. Three are
already on the books.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:17:01 -05:00
mos-dt-0andClaude Opus 5 f47cf45b0c docs(remediation): bank D-28 — a swallowed diagnostic destroyed a fail-closed check's evidence
RM-02 CI failed on four sandbox tests. Bubblewrap is installed by the gate step but not
the test step, so spawnSync returned ENOENT; replayCommit replaced the spawn diagnostic
with an empty string, so the classifier could not prove Bubblewrap provenance and
correctly refused to treat it as expected sandbox unavailability.

The refusal was right; the information loss was the bug. For a classifier, error text is
not decoration — it is the input. Widening acceptance to make the test pass would be a
finding, not a fix.

Linkages: D-16 again (local has bwrap, CI does not — local and CI disagree a third
time), and diagnostic-preservation registered as an RM-02 gate requirement with a
must-fail control proving a swallowed message is detected.

Process note: the orchestrator's hypothesis that the coincident ci-postgres FAIL caused
this was WRONG and was refuted with log evidence. D-21 stands unchanged as a teardown
artifact and is NOT upgraded — it was about to be re-classified on a false premise.
Asking the seat to confirm or refute rather than accept is what prevented that.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:10:53 -05:00
mos-dt-0andClaude Opus 5 e7c9160c7b docs(remediation): board — delivery-gate doctrine change recorded with render-vs-restate root cause
Per Mos's item 4. The gate definition was incomplete from setup because the gates were
restated from memory rather than referenced, and the omission propagated into every
worker brief since — then recurred inside the correction itself (D-26).

Board now carries the referenced sources, the gate order, freeze-after-GO, the
coordinator/orchestrator split, and the queue-guard zero-information field form.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 23:01:07 -05:00
mos-dt-0andClaude Opus 5 2d58779675 docs(remediation): bank D-27 — role file certifies the inert queue guard as enforced
rev-974 found this while loading the canonical gate sources, i.e. because we switched
from restating to reading. Verified in roles.local/merge-gate.md: mandate 3 requires
verifying 'CI queue guard clear', mandate 4 requires enumerating 'the queue-guard
outcome' in every durable verdict, the merge path annotates it 'real', and the control
table at :290 certifies it ' enforced … genuinely aborts'.

The document is correct about the WIRING and wrong about the CONTROL: set -euo pipefail
with an unguarded exit does abort, but the guard cannot produce a non-zero exit for any
input (D-23). A mechanism correctly wired to a sensor that never fires, certified as
enforced.

Compounding: the verdict format REQUIRES the queue-guard outcome as evidence, so a
conforming verdict must include a meaningless field — the role file instructs the gate
to manufacture evidence, in the mandate that exists to stop bare conclusions.

Interim: record the field labelled ZERO-INFORMATION (inert, owner RM-03) rather than
omitting it — omission makes the verdict non-conforming; silent citation is worse.

Escalated: operator-owned file, coordinator's to fix. Recommend annotation not deletion
— the requirement is correct once RM-03 lands.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 22:55:28 -05:00
mos-dt-0andClaude Opus 5 cbbe3e1ce2 docs(remediation): gate definition now REFERENCES canonical roles; bank D-26
The delivery-gate definition was incomplete from setup — the merge-gate verdict step
was missing because the gates were restated from memory rather than referenced, and the
omission propagated into every worker brief since.

Then it recurred inside the correction: the correcting message was itself a restatement
and dropped five things, including a security precondition (an unminted gate seat fails
open to the owner's admin account — the #3084 breach mechanism) and a citation to a file
that does not exist.

D-26 is the definitive case because every condition favoured success: attention maximal,
actor knew the rule best, subject was the rule itself. A rule its own enforcer cannot
follow while enforcing it is not a discipline — it is a requirement for a mechanism.

MISSION.md and KICKSTART.md now reference fleet/roles.local/merge-gate.md and
fleet/roles/validator.md and state only the gate ORDER. Every reference resolves; a
dangling pointer is worse than a restatement.

Precondition independently verified: merge-gate token is least-privilege,
pull=True push=False admin=False — structurally cannot merge.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 22:53:13 -05:00
mos-dt-0andClaude Opus 5 9a7ab73952 docs(remediation): charter — Builds 1-2 justified by two independent impossibility proofs; RM-60 option analysis
Per Mos. The choke-point executor and PG spine are not a design preference — they are
forced. Twice during the mission's own first deliveries, work stopped against a security
property that cannot exist at the layer needing it: D-19 (audited party controls the
manifest certifying it — artifact integrity) and D-25 (audited party controls the code
entering the sandbox — execution integrity). Both reduce to self-verification by the
audited party is not verification, and both resolve only via an authority outside its
control.

Neither proof was sought; both arrived while shipping something else, from different
directions, at different layers. An architecture forced by two independent impossibility
proofs is stronger evidence than one argued for.

RM-60 records Mos's sharper option analysis: A (unprivileged userns) does NOT fix the
vulnerability — it grants a capability and leaves the ORDERING defect untouched, so B is
required regardless; A without B is kernel exposure bought for nothing. B is the correct
primitive, generalises to RM-59 and the choke-point executor, and may not need A at all.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 22:09:38 -05:00
mos-dt-0andClaude Opus 5 2b85afe4ea docs(remediation): bank D-25, accept RM02-REQ-10 revision, open RM-60
RM-02's per-commit replay needs isolation; the privileged CI step was correctly refused
because PR-controlled code executes before Bubblewrap establishes any boundary — the
untrusted party would obtain the capability meant to contain it. Ordering defect, not a
hardening problem.

D-25 is D-19 one layer down: audited party controls the manifest (artifact integrity)
became audited party controls the code entering the sandbox (execution integrity). Both
reduce to self-verification by the audited party is not verification, and both resolve
via an authority outside its control — twice now this mission has derived Builds 1-2
from a security impossibility rather than design preference.

Option C ruled independently by the orchestrator and rev-974 before either saw the
other. rev-974 added the condition I missed and it matters most: post-merge replay is
DETECTION, not PREVENTION, with a defined quarantine/revert response, and must never be
presented as equivalent to a pre-merge gate.

RM02-REQ-10 revision formally recorded and accepted under RM-02's own clause 4 —
original text, restatement, reason — discharging rev-974's review-readiness condition.
RM-60 opened for the external pre-execution trust boundary, cross-referenced with RM-59.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 22:05:50 -05:00
mos-dt-0andClaude Opus 5 eabe04bc5e docs(remediation): bank D-24 — mergeable:true cited as merge-readiness; D-23 corrected backward
Mos verified #1023 before relaying and corrected my framing. Verified independently:
review id-58 REQUEST_CHANGES at f6334080, the current head — the block is live, and its
findings are that #1023's own fix is defective (unknown still exits 0, payload-as-argv
hits ARG_MAX, tests do not assert exits).

mergeable:true is git-mergeability, not readiness. The charter's first principle
committed by the orchestrator inside an escalation about proxies. Fifth instance of mine.

The mechanism, named because it will recur: mergeable is not a lie, it is a true answer
to a different question. A false field would have been caught; a true-but-adjacent field
passes every sniff test — which is why the discipline must be mechanical, not attentive.

D-23 corrected backward per D-14-as-amended, original framing quoted.

RM-02: readiness cases must assert the decision-relevant property — latest review state,
CI terminal status on the exact head, required approvals — never a structural proxy.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 20:50:46 -05:00
mos-dt-0andClaude Opus 5 36018be8d1 docs(remediation): bank D-23 — the mandatory queue guard has never worked, for any input
RM-02's registered fixtures found this before the registry was built. Worse than the
banked unknown=>exit 0: ci-queue-wait.sh:266 pipes the payload into a classifier
starting 'python3 - <<PY', so python reads its PROGRAM from stdin and json.load never
sees the JSON. Proven empirically — success, failure, pending and malformed all
classify as unknown, and unknown exits 0.

The mandatory pre-push/pre-merge guard therefore returns PASS for every possible input,
including a genuinely failing CI. The six observed meaningless greens were not an edge
case; they are the only output it can produce.

PR #1023 is exactly this fix, open and parked, and its body diagnoses it precisely.
Two aggravating details from that body: pr-ci-wait.sh:38 documented the bug and remedy
and it was never backported to the mandatory sibling (D-14 propagation with a
security-adjacent blast radius); and the fix was opened without re-verification.

Escalated for Jason's #1023 disposition. RM-02 records required-vs-actual with
DEFECT (owner: RM-03); no RM-03 lane opened, guard not edited.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 20:44:34 -05:00
mos-dt-0andClaude Opus 5 8c496993e4 docs(remediation): bank D-22 — the registry would have verified the wrong artifact
The gate that actually runs is the installed copy at ~/.config/mosaic/tools/git/;
a repo-scoped registry would test packages/mosaic/framework/tools/git/. Byte-identical
today (sha256 19cda2f7009c536e both) but nothing asserts it.

A registry that verifies the wrong artifact is worse than none — it manufactures
confidence, and the divergence would be invisible from every signal we have: registry
green, CI green, deployed gate arbitrarily different.

D-1/P-ACTIVATION applied to the enforcement mechanism itself rather than to config.

RM-02 gains: for every registered gate with a deployed counterpart, assert
repo-source == deployed-copy with a must-fail control; where none exists, record that
explicitly.

Found by design review before implementation — the only finding tonight not found by
execution, which is the design-first gate on keystone tasks paying for itself.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 20:14:13 -05:00