Commit Graph
1212 Commits
Author SHA1 Message Date
jason.woltjeandClaude Opus 5.5 d2813a4b6b docs(records): lead decision 37, raw per-seat token files in the Gitea helper (row 12)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:25:02 -05:00
jason.woltjeandClaude Opus 5.5 8ffbd73b76 docs(records): lead decision 36, row 10 build note, export recipe limit (#1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:24:24 -05:00
jason.woltjeandClaude Opus 5.5 eae341d3ca chore(queue): row 10 to Jason's gate, row 16 check, header points at the goals review (#1508)
Includes Darkwing's revs 3 to 8 (row 9 to waiting-on-jason, row 12 started).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:23:47 -05:00
jason.woltjeandClaude Opus 5.5 5efe28ab01 docs(agents): seats read the queue, not CURRENT.md (row 10, #1508)
AGENTS.md cadence, pointer and recovery rule name `scripts/mosaic queue
next <seat>` and the ratified goal order. The six seat CONTEXT files run
the queue instead of reading CURRENT.md for ownership and gates. The
queue README says why queue-commit.sh calls cli.mjs directly (Filbert
A2 r1 n3).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:23:20 -05:00
jason.woltjeandClaude Opus 5.5 9e23705724 chore(queue): row 9 to waiting-on-jason for Gate G, review round 1 on A2 6ca116b7 (#1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:19:07 -05:00
jason.woltjeandClaude Opus 5.5 c8236f7b78 docs(records): queue genesis build note and session line (#1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:17:18 -05:00
jason.woltjeandClaude Opus 5.5 42f3f2d94f chore(queue): assign row 10 to sage, row 13 gate after rows 9 to 12 (lead decision 35, #1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:17:06 -05:00
jason.woltjeandClaude Opus 5.5 3377b877ba chore(queue): genesis from reviewed map (#1508)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:16:10 -05:00
jason.woltjeandClaude Opus 5.5 6ca116b7ba feat(queue): queue as data A2, migration, render and dispatch (#1508)
Filbert approved round 1 (f167b85e). Manifest 782bcb62, 21 files, plus
the QUEUE.md markers and the TOOLS.md section. Lead decision 35.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 20:14:09 -05:00
jason.woltjeandClaude Opus 5.5 c9539baa0f docs(records): CHAT-03 build note for unexplained aborted, lead decision 34
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:45:26 -05:00
jason.woltjeandClaude Opus 5.5 8a465e891a docs(chat-03): brief pinned at 1ef15ac0 after r3 and scope check, lead decision 33 (#1507)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:45:04 -05:00
jason.woltjeandClaude Opus 5.5 93ee5054f4 docs(plans): north star and goal order ratified by Jason, AGENTS.md pointer
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:40:05 -05:00
jason.woltjeandClaude Opus 5.5 77680e0b22 docs(records): CHAT-03 r3 closed with two rulings, lead decision 32
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:39:00 -05:00
jason.woltjeandClaude Opus 5.5 8dba3ff797 docs(records): CHAT-03 seal loads no explicit extensions, lead decision 31
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:34:06 -05:00
jason.woltjeandClaude Opus 5.5 f0296e7763 docs(records): CHAT-03 rescoped against Gate E, lead decision 30
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:31:38 -05:00
jason.woltjeandClaude Opus 5.5 4bdd3fc3b0 docs(queue): close rows 1, 6, 23, 24, 25 and issues 1503, 1509, 1511, lead decision 29
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:28:13 -05:00
jason.woltjeandClaude Opus 5.5 a11e1153d7 docs(records): fix lead decision reference in DEFERRED SetSpark line
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:24:28 -05:00
jason.woltjeandClaude Opus 5.5 9da0d0895f docs(records): SetSpark approver fix deployed and surveyed, lead decision 28
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:24:20 -05:00
jason.woltjeandClaude Opus 5.5 4d999e2f61 docs(queue): row 5 CHAT-03 rescope hold, row 7 ledger owner and numbers
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:22:49 -05:00
jason.woltjeandClaude Opus 5.5 f2b9e622da docs(plans): goals review with ledger evidence, lead decision 27
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:21:33 -05:00
jason.woltjeandClaude Opus 5.5 4bbacf63ae docs(queue): rows 9 and 11, queue A1 committed, A2 in progress
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:10:39 -05:00
jason.woltjeandClaude Opus 5.5 08bd3a4cc5 fix(tests): clear NODE_TEST_CONTEXT for nested node --test in two suites (#1508)
test-foundation.sh and test-discord.sh ran a nested node --test that would
exit 0 on failure under a parent runner. Both clear the variable now, and
each has a check that fails the suite if it comes back. Darkwing wrote it,
Filbert approved it (e464be6c). Nine suites green on an index export.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:10:31 -05:00
jason.woltjeandClaude Opus 5.5 34a72af912 feat(queue): queue as data A1, journal, lock, CLI and verify (#1508)
packages/queue, scripts/queue-commit.sh, scripts/git-hooks and
scripts/test-queue.sh, plus docs/plans/BRIEF-TEMPLATE.md. There is no
queue.json yet, so verify skips until the genesis commit after A2.

Darkwing built it, and Filbert reviewed R0 (6933b885, changes requested)
and r1 (e464be6c, approved). The 20 files match manifest 85a8a453. The
nine suites passed on an index export, including the new queue suite.
test-queue.sh joins the suite list in AGENTS.md. Lead decisions 20, 23
and 26.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 19:07:48 -05:00
jason.woltjeandClaude Opus 5.5 91df7d6b54 docs(records): CHAT-03 deviation V-1 accepted with limits, lead decision 25
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:58:22 -05:00
jason.woltjeandClaude Opus 5.5 f87cd6e201 docs(records): SetSpark approver fix landed in shared-signals cc74d92, lead decision 24
Packet, Rocko's R1 and R2 reviews, DEFERRED outcome and SESSIONS.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:52:04 -05:00
jason.woltjeandClaude Opus 5.5 40a02d2bcb docs(records): queue A1 review rulings, lead decision 23
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:25:52 -05:00
jason.woltjeandClaude Opus 5.5 556772ceb2 docs(records): CHAT-03 chartered, SetSpark approver owner, lead decisions 20 to 22
Jason approved CHAT-03 and gave Sage the SetSpark approver owner choice.
Decision 20 records the queue A1/A2 split. Decision 21 makes the SetSpark
fix Mosaic's through a Sage subagent and keeps the sanctioned pending:
approver markers so the cutover migration still works. Decision 22 charters
CHAT-03 with Dewey writing the brief. QUEUE row 5, DEFERRED and SESSIONS
updated.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:14:02 -05:00
jason.woltjeandClaude Opus 5.5 bc73482045 docs(records): CHAT-02 Console live check passed, WebUI restarted
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:07:27 -05:00
jason.woltjeandClaude Opus 5.5 c9e771cf59 feat(webui): CHAT-02 Console, read-only conversation view (#1507)
History opens a seat's conversation from the Waiting card, table row
and inspector. It pages the whole branch through the CHAT-02 board
routes, renders untrusted text inert, polls with the follow cursor, and
marks every switch (branch, newer, reconcile, gone). The WebUI proxy
passes only the two conversation routes' queries upstream.

Dewey authored it. Filbert asked for changes on r1 (24b046af) and
approved r2 (d06de6a7) in review 160dd68d. A relaunch shows 'newer',
not 'reconcile', a deviation from brief 2.3 item 6 that Filbert
accepted.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 18:05:11 -05:00
jason.woltjeandClaude Opus 5.5 3a209eeafe fix(ledger): Gate F follow-up, Filbert's notes 1 to 3 (#1506)
Darkwing's follow-up to the T3 thread source: manifest 382f5bb0 pins
t3.mjs, ledger.test.mjs and README.md. Filbert approved it (review
6fd693b6). Ledger 51/51; the eight suites pass on the index.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:57:51 -05:00
jason.woltjeandClaude Opus 5.5 a4d38a3d93 docs(records): row 25 live check passed, SetSpark approver gap has no owner
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:42:17 -05:00
jason.woltjeandClaude Opus 5.5 a68dc1740a docs(records): CHAT-02 build log, Gate F commit, snapshot isolation gap
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:40:23 -05:00
jason.woltjeandClaude Opus 5.5 136958c98b feat(ledger): Gate F, the ledger's T3 thread source (#1506)
packages/ledger/src/t3.mjs reads ~/.t3/userdata/state.sqlite read-only,
in one transaction. It maps each thread to a seat by title and checks
self-addressed headers. Unmatched threads go in a t3:unmapped row. A
missing or locked database exits 1 and names --no-t3. Gate F is on by
default (lead decision 12). The 6a uppercase-class fix rides here.

Separate item: the Pi session reader splits lines only on \n, so a raw
U+2028 or U+2029 in a string no longer splits a record. Node 26.8.1's
readline split there, and the live ledger refused on HEAD.

Darkwing built to brief R3 (f3c05c1b); manifest ba73a163. Filbert
approved the build (e47ec6da) and the U+2028 fix as its own item; brief
review be1aa414. On an index export: the eight suites
24/90/43/17/14/15/63/18, ledger 47/47. Four nonblocking notes go to a
small follow-up.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:39:56 -05:00
jason.woltjeandClaude Opus 5.5 e58783d278 docs(records): CHAT-02 backend commit and board restart
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:37:07 -05:00
jason.woltjeandClaude Opus 5.5 a5beb6d97d feat(conversation): CHAT-02 read-only Pi history reader and two board routes (#1507)
packages/conversation is a library with no server: safe-fs, the Pi session
parser, CHAT-01 pages, pinned snapshots, cursors and follow. The control
board adds GET /api/conversations and /api/conversation behind the Host
and Origin guard. Both are read-only, their queries are validated, and
each refusal code maps to a status.

Dewey authored it (packet 0cf177b1, revision 2). Filbert reviewed the code:
R1 revise (branch ids moving on append, the assumed-link bridge merging
branches, one unreadable seat directory turning the catalogue into a 500),
then R2 approve (3b14d66c). Darkwing reviewed the routes: R1 approve
(07b10ad1), R2 approve (b9d92003). The package lands with the routes,
because serve.mjs imports the reader at load.

On an index export: the eight suites 24/90/43/17/14/15/63/18,
conversation and control-board 153/153, webui 9/9.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:36:20 -05:00
jason.woltjeandClaude Opus 5.5 c5db8c8819 docs(records): row 25 approver fix, second Discord restart, SetSpark approver and docker network gaps
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:31:11 -05:00
jason.woltjeandClaude Opus 5.5 20ea5a0b64 fix(discord): row 25 approvers are user names, never Discord ids in tool text (#1509)
Jason's live check after the 20:58Z restart posted no Approve button. The
Discord Sage wrote DEC-009's required_approvers as names; the SetSpark
service stores approvers as discord:<id> and accepted the names, and the
connector correctly refused the approval request ("bad approver id").

- binding.mjs derives setspark.approvers from the binding's users (name to
  id); a binding-set approvers key and duplicate names are refused. With
  setspark set, a user id or name change refuses the reload (pi's approvers
  are fixed at start).
- setspark.mjs: record_create/record_update map required_approvers names to
  discord:<id> and refuse unknown names, ids, duplicates and non-lists
  before any request, without echoing the value. hideIds turns mentions,
  discord: values and standalone 17-20 digit runs into the user's name or
  "unknown user" in every verb's text and refusal, including the service
  message and code before they are cut. The connector's approval request
  keeps the bare ids.
- tests: boundary test over nested, keyed, numeric, mention and cut ids;
  a local contract fixture from create through validateRequest, with the
  old name-stored shape still refused.

Rocko: R1 revise, R2 revise, R3 approve (81379830..., report da75219f...).
Suites on an index export: 24/90/43/17/14/15/63/18; Discord node tests 173/173.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:30:11 -05:00
jason.woltjeandClaude Opus 5.5 1c5f6bc3a0 docs(queue): queue-as-data plan round 6, Rocko approved (#1508)
Plan 282fabbb (Filbert) and the six adversarial rounds (Rocko, r6 80cde839).
Lead item 15: Gate F first, then A1 and A2 as separate reviewed commits.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:05:16 -05:00
jason.woltjeandClaude Opus 5.5 ffc22c04c6 docs(ledger): Gate F T3 thread source brief R2, Filbert approved (#1506)
Brief e8300cb6 (Darkwing), review bb02d8d3 (Filbert, approve with three
nits), R1 record and R1-to-R2 diff. Lead rulings in item 14.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:04:56 -05:00
jason.woltjeandClaude Opus 5.5 34777c56bc docs(records): row 25 SetSpark fix, Discord restart receipt, Gate F rulings
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:58:59 -05:00
jason.woltjeandClaude Opus 5.5 6c06a6f358 fix(discord): row 25 SetSpark key reaches pi and the connector (#1509)
resolveToolRoots dropped tools.setspark, so the record verbs never reached
pi's --tools list and the connector never built its SetSpark client. The
resolved config now carries only baseUrl, keyFile, principal and timeoutMs,
the keys the extension's loadSetsparkConfig accepts; the extension restores
the response cap. The connector's client uses the validated binding object,
which keeps the cap. README: principal is required, timeoutMs is optional.

Test (failing first): binding -> resolveToolRoots -> JSON -> loadToolsConfig
gives the binding's config, and the verbs reach enabledToolNames. Eight
suites green on an index export. Rocko approved
(agents/rocko/work/row25-setspark-fix-review-2026-09-26.md, a28df89e).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:57:55 -05:00
jason.woltjeandClaude Opus 5.5 84d0965142 docs(deferred): 6b closes the leaked fake pi and concurrent hang entries; wedge-restart and startup-source follow-ups
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:51:05 -05:00
jason.woltjeandClaude Opus 5.5 3edb15eb96 fix(discord): engine tests stop in finally; a turn pi never started stops pi instead of guessing (#1509)
Every engine test stops its engine in finally, and commands() tolerates a
log that doesn't exist yet, so a failed assertion no longer leaks a fake pi
and hangs the six-package union. A turn that failed client-side stays at
the front of the queue and holds the next prompt. If pi has sent no
agent_start ABORT_GRACE_MS (30 s) after the failure, the engine marks
itself wedged, fails held prompts with engine-wedged, refuses new ones with
engine-down, and stops pi. The exit reaches onExit, the connector exits 1,
and the unit restarts it. Pi's events carry no prompt id, so R1's approach,
dropping the turn and sending on, let a late run answer the next prompt.
Rocko rejected R1 and approved R2.

Tests: engine 17/17 (R1 fails 4, HEAD fails 5). Union 408/408 and the eight
suites green on the committed index. Record:
agents/darkwing/work/discord-engine-busy/.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:50:37 -05:00
jason.woltjeandClaude Opus 5.5 f55b94e866 docs(records): board guard live, restart receipt
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:40:56 -05:00
jason.woltjeandClaude Opus 5.5 d1629d610d fix(board): refuse foreign Host and Origin on every control-board route (#1507)
After a DNS rebind, a web page could read /api/board and POST /api/reply,
which pastes into a live seat pane. foreignRequest() now runs first and
returns 403 for a non-loopback Host, a wrong port, userinfo or a path in
Host, or any Origin other than http://<Host>. A missing Origin still passes,
which covers the WebUI proxy. Dewey authored it; Rocko approved de9ff942
(review 5a12f08e) with one low wording finding, now fixed in the notes.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:40:34 -05:00
jason.woltjeandClaude Opus 5.5 401cc850bb docs(records): correct walkthrough ruling times from the transcript, note 6b R1 verdict
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:36:03 -05:00
jason.woltjeandClaude Opus 5.5 993673865a docs(records): Jason's walkthrough rulings, Sage moved to SetSpark, CHAT-02 go
Jason ruled on seven open items (20:27Z-20:45Z): seat Gitea tokens read in
place, one Discord restart after 6b with row 25 live, row 8 limited to the
dev seats, DYOR in dyor-stack-v4 with Sage moved to SetSpark, skills/aws-*
excluded locally, no second WebUI return defect, and go on CHAT-02 only.

Sage persona files name SetSpark as its business work. Darkwing's SOUL drops
harness names that were wrong for T3. DEFERRED adds the slash-prefix paste
hazard and the board Host/Origin gap, and moves the ledger T3 item to Done.
Dewey's approved CHAT-02 brief (636b0fac) and Filbert's review are recorded.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:35:15 -05:00
jason.woltjeandClaude Opus 5.5 ef0020ad85 fix(ledger): count the T3 header as agent, control-board sender as board (#1506)
messageKind knew only the tmux preamble, so a prompt opening with the T3
header [from: role (id) -> to: role (id)] counted as human in Table 2. The
first line now matches either form; anything short of the full header stays
human. Filbert approved R1 against the frozen hashes.

Proof: packages/ledger/tests/ledger.test.mjs, 22/22; against HEAD's
ledger.mjs it fails exactly the two new tests. No suite runs it. Eight
suites green on the staged tree.

The fix changes zero current counts: no Pi log under .pi/state contains a
T3 header, and the ledger does not read T3 transcripts. Gate F waits on a
T3 thread source.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:16:55 -05:00
jason.woltjeandClaude Opus 5.5 d41f81aafe feat(agents): Sage launch files, lead text across seat personas, lead decision record
- agents/sage/ launch files committed after Dewey's review (R1 revise, R2
  approve). The launcher test now covers sage with its zai/glm-5.3 high pin.
  The README states the lead role and its limits, and the seat reads but
  never writes the old DYOR records under ~/.mosaic.
- N6 (Dewey authored, Sage reviewed against pins): seat personas and the
  Rocko launcher name Sage as project lead and Darkwing as a collaborating
  engineering seat, per Jason's 2026-09-26 ruling.
- docs/plans/2026-09-26_lead-decisions.md: the push, no merge into next and
  its conditions, the board restart, queue-as-data rulings, Gate F waiting
  on a T3 source, and what stays with Jason.

Launcher tests 6/6 and 1/1, eight suites green. Not pushed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:11:10 -05:00
jason.woltjeandClaude Opus 5.5 42c08d5285 fix(webui): pending reply notice until the seat answers, relative Age (#1507)
Dewey's return-flow candidate on the #1512 R1 baseline. The inspector used to
show the previous answer while a seat worked on a reply, which looked like the
reply; it now shows a pending notice that clears on the new final answer.
Age shows a relative time beside the ISO time. Filbert approved R2, source
only; the patch reproduces the pinned hashes (app.js d1a51646,
return-flow.test.mjs a598c0d4). webui tests 9/9, all eight suites green.
Known limits are in agents/dewey/work/return-flow-age/NOTES.md. Not pushed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:00:59 -05:00