Commit Graph
71 Commits
Author SHA1 Message Date
jason.woltjeandClaude Opus 5.5 4ac133dd8a docs(slice1): row 38 S3 build packet, probes and live rehearsal (darkwing)
Candidate for #1520 against 81339889: packages/tasks and the bus task
verbs. Live run rehearsed on a scratch v2.7.0 container; the estate run
waits for T236's base URL.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-08 18:33:50 -05:00
jason.woltjeandClaude Opus 5.5 bee89d107d docs: lead decision 69, Rocko moves to a Claude thread under R26 (sage)
Jason's R26 via Mos: Claude first, Codex only on gpt-6.1-sol, never
Astra. Rocko's Codex thread ran gpt-6-astra; the seat now runs as T3
thread b84bb264 on Opus 5.5, because its only row, S4, builds mosaic
decide and the gated decision DM. Roster updated. Filbert's launcher
still pins Astra; recorded as a follow-up, unused while Filbert runs in T3.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-08 17:21:03 -05:00
jason.woltjeandClaude Opus 5.5 ac4a6499f2 review(bus): darkwing S2c round 1, approve (row 44, #1526)
Verdict comment 26778, queue rev 156. Within-role citations never reach
the authority check or the grant event; other sends keep S2b. 58/58 on
Node 24 and 26, seven of seven mutants killed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-05 18:06:47 -05:00
jason.woltjeandClaude Opus 5.5 e250933de7 docs(records): 2026-10-05 weekly ledger run, refused on a T3 header conflict (row 7, #1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-05 18:05:19 -05:00
jason.woltjeandClaude Opus 5.5 bba75b4a4f review(bus): darkwing S2b round 2, approve (row 43, #1525)
Verdict comment 26769, queue rev 146. R1, R2 and both lead decision 64
rulings are in; round 1 probes now refuse. 55/55 on Node 24 and 26,
nine of ten mutants killed, the survivor equivalent.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-05 17:43:09 -05:00
jason.woltjeandClaude Opus 5.5 4f28c09069 review(bus): darkwing S2b round 1, changes (row 43, #1525)
Verdict comment 26765, queue rev 140. R1: message.send and role.revoke
verbs use gated decisions without consuming them. R2: a cross-role
decision authorizes without limit once policy makes the action gated.
Two rulings for Sage on cross-role reuse and class drift.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-05 17:35:15 -05:00
jason.woltjeandClaude Opus 5.5 1e3c06c78b docs(review): row 37 S2 round 2, approve (darkwing)
Round 2 of #1519: R1 to R5 fixed and reproduced, 43/43 on Node 26 and
Node 24, 22 of 23 mutants killed against a clean baseline. Records a
reparented-CLI path past the human proof for Sage's ruling.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 23:31:49 -05:00
jason.woltjeandClaude Opus 5.5 79699c143b docs(review): row 37 S2 round 1, changes (darkwing)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 23:13:35 -05:00
jason.woltjeandClaude Opus 5.5 17481148e2 docs(review): row 36 S1 round 2, approve (filbert)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 23:10:26 -05:00
jason.woltjeandClaude Opus 5.5 95c65b5d06 docs(review): row 34 S0 round 2, approve (darkwing)
Record for #1516 comment 26729: a and b fixed, c to f fixed, ten cc-7
cases reproduce 10/10.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 23:02:20 -05:00
jason.woltjeandClaude Opus 5.5 d9568cec98 docs(slice1): row 36 S1 round 2 packet (darkwing)
Answers Filbert's round 1 (#1518 comment 26724): launch.by must hold
role.launch, launch is null when limits.authority drops it, a test for
cross-role narrowing, and the business file checked on its open
descriptor.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:55:37 -05:00
jason.woltjeandClaude Opus 5.5 4b7405b86d probes(slice1): row 34 S0 round 2, wrapped command hooks (filbert)
Adds ten cc-7 cases (Darkwing's six wrapper cases plus allow, block,
SIGTERM-ignoring gate and inner timeout above the hook timeout), amends
rely-on lines 2 to 4, removes the stale cc-1d-block-bare evidence, adds
compare.sh, reads SDK_ENTRY from the environment, fixes the cc-5c row and
the Pi exit-code sentence.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:54:10 -05:00
jason.woltjeandClaude Opus 5.5 1abebe5321 docs(review): row 34 S0 round 1, changes (darkwing)
Record for #1516 comment 26725: 34/34 cases reproduce, and a wrapped
Claude command hook fails closed on crash, missing path, noexec and hang.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:51:00 -05:00
jason.woltjeandClaude Opus 5.5 7cbf78dab9 docs(review): row 36 S1 round 1, changes (filbert)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:40:19 -05:00
jason.woltjeandClaude Opus 5.5 48d76de7c6 docs(slice1): schema v3b, current snapshot view (darkwing)
Lead decision 59. task_current picks each task's current snapshot,
skipping a poll row whose read_at is at or before the latest self row's
at; tasks_open reads it. Prototype on Node 24 and 26, two mutants
caught, and Dewey's fixture replayed: tasks_open now differs from v3a
only on #42 (in-progress). The notes add an S3 poller rule: compare a
read against task_current, not the raw latest row.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:33:09 -05:00
jason.woltjeandClaude Opus 5.5 b851f83c39 docs(slice1): row 36 S1 build packet, v3a trigger count correction (darkwing)
S1 candidate for Filbert's review on #1518: build.md, build.patch and
build-manifest.sha256 (34 files at base fef4b362). The candidate itself
is not committed.

proto-v3a-notes-correction: the schema has 36 triggers; the printed 35 is
counted after the tamper check's DROP TRIGGER. Found by Rocko.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:28:30 -05:00
jason.woltjeandClaude Opus 5.5 771fc3d270 docs(slice1): row 34 S0 harness probe matrix (filbert)
Pi 0.85.1 and Claude Code 2.1.289 (Agent SDK 0.3.289), 34 cases against a
scripted local model in a loopback-only network namespace. MATRIX.md has
the command, outcome, model-visible message and fail-closed column per
case, and one rely-on line per case. Evidence under evidence/.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:25:41 -05:00
jason.woltjeandClaude Opus 5.5 8619d36bc4 docs(slice1): row 35 SR round 3 review record (darkwing)
Verdict approve, #1517 comment 26715.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:16:10 -05:00
jason.woltjeandClaude Opus 5.5 ee82aa5e4f docs(slice1): row 35 SR round 2 review record (darkwing)
Verdict changes, #1517 comment 26712: the Vikunja rotation removes the
owner header before the revoke that needs it.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:13:33 -05:00
jason.woltjeandClaude Opus 5.5 4d51c1304d docs(slice1): row 35 SR round 1 review record (darkwing)
Verdict changes, #1517 comment 26709. Gitea 1.27.1 and Vikunja 2.7.0
source checks for Sage's three questions; two mint defects.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:09:21 -05:00
jason.woltjeandClaude Opus 5.5 29daa48216 docs(slice1): schema v3a, task event rules (lead decision 56, Q3)
Two triggers: every task.* event names its task in subject, and
task.created cites a human.input event and a requirement id. The task
ref pattern is tightened on snapshots, decisions and subjects. Runs on
Node 24.21.0 and 26.8.1 match apart from the version line.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 22:02:31 -05:00
jason.woltjeandClaude Opus 5.5 b02aade221 docs(rocko): slice 1 S2 preparation packet (record)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 21:56:11 -05:00
jason.woltjeandClaude Opus 5.5 7ed831781b docs(slice1): schema v3 prototype, addendum B section 5
task_snapshots gains via and read_at, an integer-bucket CHECK with a
tombstone exception, the read-ordering rule in task_external_changes and
the tasks_open view. task.missing names its task and a reason. Prototype
rerun on Node 24.21.0 and 26.8.1; a mutant without the read_at rule
reports the broker's own move as external. Lead decision 52 (B3).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 21:55:17 -05:00
jason.woltjeandClaude Opus 5.5 b6631e6b4f docs(plans): slice 1 addendum B; lead decision 52
Real Vikunja scope map, a read-only sync bot, a two-request poll that
sees column moves and deletions, and task_snapshots changes.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 18:42:31 -05:00
jason.woltjeandClaude Opus 5.5 5175ca10f2 docs(plans): Vikunja probe record; lead decision 51
Researcher ran P1-P7 on a scratch Vikunja 2.7.0. Scope names in
addendum A are wrong, polling on updated misses column moves and
deletions, and If-Match isn't enforced. Decision 51 rules on each.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 18:31:47 -05:00
jason.woltjeandClaude Opus 5.5 243e153c8b feat(conversation): CHAT-03 I1, mediated control of a sealed headless Pi (#1507)
Controller, claim store, live-session guard, engine link and seal,
turn tracker, cohort force stop and recovery, client library,
transcript and mediated terminal, with the fake engine and tests.
Fixtures only; no live cutover.

Dewey built it. Darkwing (comment 26690) and Filbert (comment 26694)
approved round 2. Manifest I1-r2-manifest.sha256 (2b48e333, 27 files).
Suites on an export: conversation 152/152, control-board 124, webui 14,
seat 19, chat-00/01/01c checks, and all nine scripts/test-*.sh green.
Follow-ups for I3 are in DEFERRED. Gate E stays with Jason.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 15:47:53 -05:00
jason.woltjeandClaude Opus 5.5 b846c44dba docs(review): Darkwing's CHAT-03 I1 round 2 review record
Approve, no blockers; follow-ups F1-F3 for I3. Comment 26690 on #1507.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 15:33:21 -05:00
jason.woltjeandClaude Opus 5.5 f2b8c92a84 docs(plans): slice 1 prototype v2 records; lead decision 50
Darkwing's schema-v2 adds task_snapshots, decisions.blocking and a
closed events.kind list. Sage reran proto-v2 on Node 26 with matching
output. Decision 50 accepts the five choices beyond addendum A.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:59:33 -05:00
jason.woltjeandClaude Opus 5.5 d7723e2237 docs(prd): PRD draft 0.3; slice 1 addendum A; lead decision 49
Darkwing's addendum as a record. Broker verbs enforce field ownership,
broker push from a bare repo, polling without webhooks, Vikunja probes
before the adapter interface is fixed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:56:14 -05:00
jason.woltjeandClaude Opus 5.5 c57998772d docs(prd): PRD draft 0.2 with requirement ids; lead decision 48
PRDY round 2 answers, and Researcher's Vikunja and Pocket ID report as
a record.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:48:15 -05:00
jason.woltjeandClaude Opus 5.5 df9e036214 docs(plans): meta-harness survey; lead decision 47
Filbert's survey of Pi, Claude Code and Codex hooks as a record. No hook
is a hard block alone; credential scope, verbs, tool ceiling and a
container are. Two DEFERRED items.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:26:50 -05:00
jason.woltjeandClaude Opus 5.5 bb7e37dda2 docs(plans): slice 1 data model note and prototype; lead decision 46
Darkwing's design note and SQLite prototype as records. Sage accepts
seven of eight open questions; the PM launching sessions goes to Jason.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:19:14 -05:00
jason.woltjeandClaude Opus 5.5 8a3e672f4a docs(records): row 5 round 1 review files, record-issue gap in DEFERRED
Both reviewers requested changes (26681, 26683). Darkwing's verdict
landed on #1508; pointer 26685 on #1507.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 14:01:37 -05:00
jason.woltjeandClaude Opus 5.5 1c72495815 docs(records): row 33 landed, cold-start failure reopened (#1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 01:26:07 -05:00
jason.woltjeandClaude Opus 5.5 6fb50cc0a8 fix(queue): genesis owner-not-reviewer check, assign wording, queue-commit HEAD-moved message, calendar dates (row 33, #1508)
Built by filbert, approved by darkwing in round 1 (#1508 comment 26651).
Manifest fe7da3ef, 10 paths. Suites green on an index export.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-04 01:25:06 -05:00
jason.woltjeandClaude Opus 5.5 0d6658b57d docs(records): 2026-09-28 weekly ledger output (row 7, #1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-28 08:26:12 -05:00
jason.woltjeandClaude Opus 5.5 fd72d26899 feat(ledger): Piece E, queue section in the weekly ledger (row 13, #1508)
The ledger prints a queue section above the weekly table. It checks four
things:
- open issues named by done rows;
- owner registrations for active rows;
- closed issues for done rows;
- the age of required rows.
The result is fail, incomplete or reduced pass. It uses its own Gitea
budget of the open list plus at most 10 lookups. A full open page counts
only while an issue in some row's closes has no known state (lead
decision 40). T3 seats are exempt per run with --unsupported-runtime.
The weekly routine is in packages/ledger/README.md.

Built by Darkwing (build.patch ab1f12ca, manifest 0b20bbca). Filbert
reviewed it: round 1 81f26f2e asked for changes (C1, ISO requiredSince
never aged); round 2 ce8ce150 approved. Also carries Filbert's plan
amendment for decision 40 (68a25ffe).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-27 11:33:44 -05:00
jason.woltjeandClaude Opus 5.5 f539466fcb feat(queue): Piece D, reviews as issue comments, raw per-seat token helper (row 12, #1508)
queue move ID in-review posts the review request as a Gitea comment and
review record reads verdicts back, so reviews stop being files in
docs/plans/reviews/. On a comment round, in-review to waiting-on-jason
now needs every listed reviewer's approval for the current round, the
same as in-review to done (Filbert r1 C1). scripts/gitea-api.sh reads
the raw per-seat token files (lead decisions 37 to 39): config built and
checked before curl starts, export attribute cleared, fixed base URL.
test-queue.sh skips its live checks outside the canonical root.

Darkwing authored. Filbert approved D r2 (cf1d3fd0) after r1 (a2dc2302)
and corrected the plan (293747cd). Rocko reviewed the helper (e896192f,
2096b0a3), and Sage's lead check passed under decision 38. Manifest
b402fb38, 19 files.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-27 10:07:29 -05:00
jason.woltjeandClaude Opus 5.5 5efe28ab01 docs(agents): seats read the queue, not CURRENT.md (row 10, #1508)
AGENTS.md cadence, pointer and recovery rule name `scripts/mosaic queue
next <seat>` and the ratified goal order. The six seat CONTEXT files run
the queue instead of reading CURRENT.md for ownership and gates. The
queue README says why queue-commit.sh calls cli.mjs directly (Filbert
A2 r1 n3).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:23:20 -05:00
jason.woltjeandClaude Opus 5.5 6ca116b7ba feat(queue): queue as data A2, migration, render and dispatch (#1508)
Filbert approved round 1 (f167b85e). Manifest 782bcb62, 21 files, plus
the QUEUE.md markers and the TOOLS.md section. Lead decision 35.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:14:09 -05:00
jason.woltjeandClaude Opus 5.5 8a465e891a docs(chat-03): brief pinned at 1ef15ac0 after r3 and scope check, lead decision 33 (#1507)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:45:04 -05:00
jason.woltjeandClaude Opus 5.5 08bd3a4cc5 fix(tests): clear NODE_TEST_CONTEXT for nested node --test in two suites (#1508)
test-foundation.sh and test-discord.sh ran a nested node --test that would
exit 0 on failure under a parent runner. Both clear the variable now, and
each has a check that fails the suite if it comes back. Darkwing wrote it,
Filbert approved it (e464be6c). Nine suites green on an index export.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:10:31 -05:00
jason.woltjeandClaude Opus 5.5 34a72af912 feat(queue): queue as data A1, journal, lock, CLI and verify (#1508)
packages/queue, scripts/queue-commit.sh, scripts/git-hooks and
scripts/test-queue.sh, plus docs/plans/BRIEF-TEMPLATE.md. There is no
queue.json yet, so verify skips until the genesis commit after A2.

Darkwing built it, and Filbert reviewed R0 (6933b885, changes requested)
and r1 (e464be6c, approved). The 20 files match manifest 85a8a453. The
nine suites passed on an index export, including the new queue suite.
test-queue.sh joins the suite list in AGENTS.md. Lead decisions 20, 23
and 26.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:07:48 -05:00
jason.woltjeandClaude Opus 5.5 f87cd6e201 docs(records): SetSpark approver fix landed in shared-signals cc74d92, lead decision 24
Packet, Rocko's R1 and R2 reviews, DEFERRED outcome and SESSIONS.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:52:04 -05:00
jason.woltjeandClaude Opus 5.5 bc73482045 docs(records): CHAT-02 Console live check passed, WebUI restarted
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:07:27 -05:00
jason.woltjeandClaude Opus 5.5 c9e771cf59 feat(webui): CHAT-02 Console, read-only conversation view (#1507)
History opens a seat's conversation from the Waiting card, table row
and inspector. It pages the whole branch through the CHAT-02 board
routes, renders untrusted text inert, polls with the follow cursor, and
marks every switch (branch, newer, reconcile, gone). The WebUI proxy
passes only the two conversation routes' queries upstream.

Dewey authored it. Filbert asked for changes on r1 (24b046af) and
approved r2 (d06de6a7) in review 160dd68d. A relaunch shows 'newer',
not 'reconcile', a deviation from brief 2.3 item 6 that Filbert
accepted.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:05:11 -05:00
jason.woltjeandClaude Opus 5.5 3a209eeafe fix(ledger): Gate F follow-up, Filbert's notes 1 to 3 (#1506)
Darkwing's follow-up to the T3 thread source: manifest 382f5bb0 pins
t3.mjs, ledger.test.mjs and README.md. Filbert approved it (review
6fd693b6). Ledger 51/51; the eight suites pass on the index.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:57:51 -05:00
jason.woltjeandClaude Opus 5.5 136958c98b feat(ledger): Gate F, the ledger's T3 thread source (#1506)
packages/ledger/src/t3.mjs reads ~/.t3/userdata/state.sqlite read-only,
in one transaction. It maps each thread to a seat by title and checks
self-addressed headers. Unmatched threads go in a t3:unmapped row. A
missing or locked database exits 1 and names --no-t3. Gate F is on by
default (lead decision 12). The 6a uppercase-class fix rides here.

Separate item: the Pi session reader splits lines only on \n, so a raw
U+2028 or U+2029 in a string no longer splits a record. Node 26.8.1's
readline split there, and the live ledger refused on HEAD.

Darkwing built to brief R3 (f3c05c1b); manifest ba73a163. Filbert
approved the build (e47ec6da) and the U+2028 fix as its own item; brief
review be1aa414. On an index export: the eight suites
24/90/43/17/14/15/63/18, ledger 47/47. Four nonblocking notes go to a
small follow-up.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:39:56 -05:00
jason.woltjeandClaude Opus 5.5 a5beb6d97d feat(conversation): CHAT-02 read-only Pi history reader and two board routes (#1507)
packages/conversation is a library with no server: safe-fs, the Pi session
parser, CHAT-01 pages, pinned snapshots, cursors and follow. The control
board adds GET /api/conversations and /api/conversation behind the Host
and Origin guard. Both are read-only, their queries are validated, and
each refusal code maps to a status.

Dewey authored it (packet 0cf177b1, revision 2). Filbert reviewed the code:
R1 revise (branch ids moving on append, the assumed-link bridge merging
branches, one unreadable seat directory turning the catalogue into a 500),
then R2 approve (3b14d66c). Darkwing reviewed the routes: R1 approve
(07b10ad1), R2 approve (b9d92003). The package lands with the routes,
because serve.mjs imports the reader at load.

On an index export: the eight suites 24/90/43/17/14/15/63/18,
conversation and control-board 153/153, webui 9/9.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:36:20 -05:00
jason.woltjeandClaude Opus 5.5 20ea5a0b64 fix(discord): row 25 approvers are user names, never Discord ids in tool text (#1509)
Jason's live check after the 20:58Z restart posted no Approve button. The
Discord Sage wrote DEC-009's required_approvers as names; the SetSpark
service stores approvers as discord:<id> and accepted the names, and the
connector correctly refused the approval request ("bad approver id").

- binding.mjs derives setspark.approvers from the binding's users (name to
  id); a binding-set approvers key and duplicate names are refused. With
  setspark set, a user id or name change refuses the reload (pi's approvers
  are fixed at start).
- setspark.mjs: record_create/record_update map required_approvers names to
  discord:<id> and refuse unknown names, ids, duplicates and non-lists
  before any request, without echoing the value. hideIds turns mentions,
  discord: values and standalone 17-20 digit runs into the user's name or
  "unknown user" in every verb's text and refusal, including the service
  message and code before they are cut. The connector's approval request
  keeps the bare ids.
- tests: boundary test over nested, keyed, numeric, mention and cut ids;
  a local contract fixture from create through validateRequest, with the
  old name-stored shape still refused.

Rocko: R1 revise, R2 revise, R3 approve (81379830..., report da75219f...).
Suites on an index export: 24/90/43/17/14/15/63/18; Discord node tests 173/173.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:30:11 -05:00