Compare commits

..
Author SHA1 Message Date
f10-coder fbb6191298 fix(quality): anchor quantified registry populations
ci/woodpecker/pr/ci Pipeline was successful
2026-08-01 12:39:49 -05:00
f10-coder 32b490a712 fix(quality): close registry silent-defeat paths
ci/woodpecker/pr/ci Pipeline was successful
2026-08-01 11:28:28 -05:00
f10-coder 83d2ecb224 chore(quality): advance registry activation seam
ci/woodpecker/pr/ci Pipeline was successful
2026-08-01 10:06:09 -05:00
coder-mos1andf10-coder 9e1a7a44b7 fix(quality): preserve binding diagnostics 2026-08-01 09:58:47 -05:00
coder-mos1andf10-coder 8b1b873056 fix(quality): prove criterion binding semantics 2026-08-01 09:58:47 -05:00
coder-mos1andf10-coder d119635265 fix(test): preserve sandbox refusal provenance 2026-08-01 09:58:47 -05:00
coder-mos1andf10-coder abaed0c103 test(ci): classify Bubblewrap EPERM exactly 2026-08-01 09:58:47 -05:00
f10-coder 04cc031774 fix(quality): record current-tree trust boundary 2026-08-01 09:58:47 -05:00
f10-coder e89599758b fix(ci): unshallow gate replay history 2026-08-01 09:58:46 -05:00
f10-coder 0b4aa4751a feat(quality): add anti-inert gate registry 2026-08-01 09:58:46 -05:00
coder-mos1andmos-dt-0 f4fd5967fc RM-61: prove ci-postgres teardown discrimination (#1033)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
Co-authored-by: coder-mos1 <[email protected]>
2026-08-01 14:54:04 +00:00
mos-dt-0andMos f65e9ea656 docs(remediation): mission-state snapshot at the RM-01 seam (#1028)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
Co-authored-by: mos-dt-0 <[email protected]>
2026-08-01 01:08:11 +00:00
mos-dt-0andMos f58b3699a6 RM-01: reproducible checkout — the pre-push gate fails on code, not environment (#1027)
ci/woodpecker/push/publish Pipeline failed
ci/woodpecker/push/ci Pipeline was successful
Co-authored-by: mos-dt-0 <[email protected]>
2026-08-01 00:50:12 +00:00
mos-dt-0andMos 01e966f36d docs(remediation): mission charter + reconciled execution backlog (#1026)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
Co-authored-by: mos-dt-0 <[email protected]>
2026-07-31 22:47:03 +00:00
mos-dt-0andMos 524146055d fix(hygiene): .prettierignore must exclude Python build/test artifacts (#1025)
ci/woodpecker/push/publish Pipeline failed
ci/woodpecker/push/ci Pipeline was successful
Co-authored-by: mos-dt-0 <[email protected]>
2026-07-31 22:24:49 +00:00
54 changed files with 9970 additions and 240 deletions
+1
View File
@@ -8,6 +8,7 @@ coverage
.env.local
*.tsbuildinfo
.pnpm-store
__pycache__/
docs/reports/
# Step-CA dev password — real file is gitignored; commit only the .example
+1 -1
View File
@@ -1 +1 @@
pnpm typecheck && pnpm lint && pnpm format:check
pnpm preflight && pnpm typecheck && pnpm lint && pnpm format:check
+4 -4
View File
@@ -1,5 +1,5 @@
@mosaicstack:registry=https://git.mosaicstack.dev/api/packages/mosaicstack/npm/
# Pin the pnpm store to the same path the ci-base image warms (Dockerfile.ci),
# so the pipeline `pnpm install --prefer-offline` consumes the baked store
# instead of repopulating a fresh one.
store-dir=/root/.local/share/pnpm/store
# HOME resolves to /root in the ci-base image, preserving its warmed-store path.
# Non-root checkouts use their own HOME. Override without editing this file via
# NPM_CONFIG_STORE_DIR (pnpm's environment form of the store-dir setting).
store-dir=${HOME}/.local/share/pnpm/store
+8
View File
@@ -4,6 +4,14 @@ pnpm-lock.yaml
**/node_modules
**/drizzle
**/.next
# Python build/test artifacts — same category as node_modules/dist/.next above.
# Prettier must never scan generated trees; without these a local venv poisons
# `pnpm format:check` with thousands of third-party files.
**/venv
**/__pycache__
**/.mypy_cache
**/.pytest_cache
**/htmlcov
.claude/
docs/tess/TASKS.md
docs/scratchpads/
+17 -3
View File
@@ -68,15 +68,29 @@ steps:
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
# Anti-inert-gate registry. Deliberately unconditional: no path filter and no
# step-level `when`, because a gate can be disabled by changes outside its own path.
gate-verify:
image: *node_image
# Woodpecker's shallow marker makes merge-base reject even present parents;
# full history is required for activation ancestry and manifest provenance.
commands:
- *enable_pnpm
- apk add --no-cache bubblewrap
- if [ -f .git/shallow ]; then git fetch --unshallow --no-tags origin; fi
- pnpm gate:verify
depends_on:
- install
- sanitization
- upgrade-guard
typecheck:
image: *node_image
commands:
- *enable_pnpm
- pnpm typecheck
depends_on:
- install
- sanitization
- upgrade-guard
- gate-verify
# lint, format, and test are independent — run in parallel after typecheck
lint:
+14
View File
@@ -201,8 +201,21 @@ git clone [email protected]:mosaicstack/stack.git
cd stack
# Install dependencies. The local tier uses in-process PGlite; leave DATABASE_URL unset.
# The pnpm store defaults to $HOME/.local/share/pnpm/store. Override it without
# editing the checkout with NPM_CONFIG_STORE_DIR=$HOME/another-store if needed.
pnpm install
# Verify dependencies and generated state before running source-quality gates.
# Missing dependencies exit 42; stale/foreign apps/web/.next state exits 43.
# The web build certifies its exact standalone symlink manifest; added, removed,
# retargeted, or manifest-only-tampered generated links also exit 43. This detects
# accidental, independent, stale, and foreign-residue mutation—the class exposed by
# a five-month-stale .next that produced 19 phantom TS2307 errors.
# It does NOT defend against a same-UID actor that can rewrite both manifest and
# marker consistently (CWE-345). RM-59 tracks the required executor/spine-side
# trust anchor outside worktree authority.
pnpm preflight
# Optional local queue service only. This does not start PostgreSQL.
docker compose up -d valkey
@@ -230,6 +243,7 @@ Gateway start command until KBN-101-02 makes that state fail closed.
### Quality Gates
```bash
pnpm preflight # Checkout/dependency/generated-state validation
pnpm typecheck # TypeScript type checking (all packages)
pnpm lint # ESLint (all packages)
pnpm test # Vitest (all packages)
+1 -1
View File
@@ -3,7 +3,7 @@
"version": "0.0.2",
"private": true,
"scripts": {
"build": "next build",
"build": "node ../../scripts/build-web.mjs",
"dev": "next dev",
"lint": "eslint src",
"typecheck": "tsc --noEmit",
+3
View File
@@ -0,0 +1,3 @@
# Administrator Guide
- [Gate registry operations](quality-gate-registry.md)
+39
View File
@@ -0,0 +1,39 @@
# Gate Registry Operations
## Routine verification
Run `pnpm gate:verify` from a dependency-installed checkout. Exit zero means registry observations matched their declared `actual` values; it does **not** assert required-behavior conformance while deltas remain. Open `DEFECT` records are checked descriptions of current behavior with tracked owners, never successful gate outcomes.
Investigate any of these immediately:
- `GATE VERIFY FAILED` — registry structure, observed behavior, provenance, claim binding, source/deployment identity, or negative-control detection changed. The verifier aggregates independent phase failures, so repair the responsible stable-ID diagnostics as well as any accompanying stale-fixture error; do not treat the generic error as a substitute.
- `unregistered gate` — an executable appeared under a declared gate root without a registry entry.
- `no negative control` — a gate has no must-fail case.
- `DEPLOYED IDENTITY UNAVAILABLE` — the runner cannot reach the installed enforcing copy. The pinned observation is checked, but live equality is not asserted.
- `PROVIDER EVIDENCE ... ABSENT` — retained external history was unavailable; do not infer merge-time success.
## Updating a gate
1. Add or change the criterion, its exact criterion-side `caseRefs`, and matching case-side `criterionIds`. Preserve recursive closed-schema validation for every nested object; new fields require explicit key and type handling.
2. Observe the must-fail case fail for its own stated reason; moving the binding to any undeclared case must fail verification.
3. Declare an exact inerting mutation and observe the verifier detect it.
4. If required and actual behavior differ, add a tracked remediation owner and justification.
5. If meaning changed, append provenance; never replace the original silently.
6. For an installed counterpart, verify live byte identity and update the observed digest only from measured evidence.
7. Run focused verifier tests, `pnpm gate:verify`, and the repository baseline gates.
Do not add an ownerless exception or describe an open delta as pass/green/OK.
## CI behavior
Woodpecker runs `gate-verify` on every pull request and protected-main push without path filtering. This is deliberate: changes outside gate files can make a gate inert. The step unshallows the checkout so activation ancestry and historical manifest provenance can be checked; a shallow boundary must never be interpreted as non-ancestry.
Provider evidence input is an optional JSON array of normalized pipeline records containing `commit`, globally unique integer pipeline `number`, pipeline `status`, and a `gate-verify` step status. Collection-wide identity/type validation occurs before commit filtering; a duplicate number across two commits fails subject binding. The highest numbered valid rerun for one commit is authoritative. Its retention window is provider-controlled and is not overstated by this repository.
Do not add or update an activation SHA in the manifest. The verifier derives the audited feature range from Git's merge-base with provider target `refs/remotes/origin/main`, so commits before a delayed registry introduction remain covered. HEAD, HEAD's parent, the introduction commit, and delayed introduction after a gate change are registered rejected constructions.
**DOES:** The merge-base is outside branch-author control when main cannot be rewritten. **DOES NOT:** This bootstrap cannot protect a compromised or rewritten main; Builds 1-2 own that residual. Production verification also requires non-empty criteria/gates/prose/scenario populations and anchors the seven required gate IDs to canonical sources before any “all registered” claim.
PR CI executes current-tree verification only, unprivileged and fail-closed. It does not execute isolated own-tree replay: RM-60 must provide a protected launcher or runner-level rootless sandbox before any PR-controlled executable/configuration is evaluated. Repo-only code cannot safely grant itself the capability intended to contain itself.
The deferred replay implementation remains hard-fail when its sandbox cannot be established; it is not silently skipped as a successful replay. Tests recognize unavailability only from parent-generated Bubblewrap-launch provenance combined with proof that the sandbox entry command did not run. A denial-looking string from child-controlled output is not evidence. When RM-60 activates replay under protected authority, it uses frozen own-tree dependencies, namespace/environment isolation, and archived-file identity checks. A post-merge failure triggers quarantine and revert. This is detection, not pre-merge prevention.
+3
View File
@@ -0,0 +1,3 @@
# Developer Guide
- [Gate registry and negative controls](quality-gate-registry.md)
@@ -0,0 +1,51 @@
# Gate Registry and Negative Controls
`gates/gates.manifest.json` is the machine-readable registry for the initial RM-02 gate slice. Run:
```bash
pnpm gate:verify
```
## Registered slice
The registry covers root typecheck, lint, and format checks; RM-01 checkout preflight; the Mosaic CI queue guard; and root Husky pre-commit/pre-push hooks. It does not imply repository-wide coverage. Framework scripts, package-local build/test scripts, templates, and deployment/release scripts remain assigned to RM-54.
Every gate declares exact invocations, an evidence subject equal to its stable gate ID, observed and required outcomes, criterion bindings, and a single exact inerting mutation. Every must-fail case requires a non-empty reason diagnostic. The verifier rejects a stale, ambiguous, crashing, or ineffective mutation. Fixture and mutation writes reject path traversal and final-component symlinks. Every nested manifest object used by outcomes, mutations, fixtures, deployments, defects, compatibility, provenance, coverage, and merge assertions has closed keys and strict field types; a misspelling cannot silently turn a required comparison into an absent optional field. Independent validation phases collect labeled failures instead of letting one thrown fixture, claim, discovery, deployment, mutation, or compatibility error mask already-known stable-ID diagnostics. This proves detection of the **declared** inerting mutation, not every possible semantic weakening.
## Required versus actual
A case may record different `required` and `actual` outcomes only with a tracked owner. The verifier checks current reality against `actual`, prints each difference as `DEFECT (owner: ...)`, and fails when behavior changes without a matching registry update. A defect is never described as passing, green, or OK.
The queue guard currently has RM-03-owned deltas. In particular, its stdin/heredoc classifier does not consume piped status JSON, so terminal-success, no-status, and terminal-failure payloads become `unknown`; unknown and malformed states exit zero; push purpose defaults to `main`. RM-02 records these observations and does not edit the guard.
## Criteria, prose, and compatibility
Each criterion declares exact `caseRefs`; the verifier compares those semantic declarations bidirectionally with case-side `criterionIds` and requires at least one must-fail case. Moving a criterion ID to an unrelated case therefore fails as both a missing declared exercising case and an undeclared binding. Registered meta-negative controls misbind a criterion, remove meaning provenance, and misbind a prose claim, and each must make structure verification red for its stated reason.
Designated governing prose uses `GATE-CLAIM:<id>` markers. Each claim also names the exact must-fail `caseRef` that exercises its criterion; unknown, positive-only, unrelated, unbound, or registered-but-missing claims fail. Orchestrator-owned claims from `TASKS.md` are bound through `docs/remediation/GATE-CLAIMS.md`, which records source headings and anchored text without changing task tracking. Marker completeness still requires RM-54 review because arbitrary English claims cannot be inferred safely.
Compatibility checks detect direct contradictions in declared finite constructions. The verifier combines referenced case fixtures and environments in one isolated tree, rejects conflicting fixture/environment values, executes the construction's exact invocation, and checks its exact outcome. They do not prove semantic consistency of arbitrary natural language.
Restatements preserve original text, current text, reason, finding/task, and date.
## Source and deployed identity
A gate with an external installed counterpart declares it explicitly. When the installed queue guard is reachable, its bytes must equal repository source and an internal drift control is observed red. In CI the operator-home installation may be outside the container; the verifier checks the pinned observed source digest, reports `DEPLOYED IDENTITY UNAVAILABLE (owner: RM-04)`, and does not infer live equality.
## Commit and provider boundary
**DOES:** Every PR evaluates the current checkout's registered gates and declared inerting mutations directly, unprivileged and fail-closed.
**DOES NOT:** Repository-controlled PR CI does not execute a commit's own verifier in an isolated replay. Doing so safely would require granting namespace capability before PR-controlled configuration or code runs; that same PR could consume the capability directly. This is an absent trust boundary, not unfinished hardening. RM-60 owns a runner-level rootless sandbox or protected immutable launcher; RM-59 owns the parallel artifact-integrity anchor.
The replay implementation and abuse-case tests remain fail-closed: when invoked by a future protected authority, inability to establish Bubblewrap is terminal nonzero; controls are never omitted or treated as replay success. On an unprivileged CI runner, sandbox integration tests pass only when the result carries parent-generated Bubblewrap-launch provenance and proves the sandbox entry command never ran. Child-controlled text that merely reproduces a Bubblewrap denial is not accepted. Capable local/protected environments exercise the full abuse cases. Historical installs use frozen lockfiles, isolated network/PID/IPC/UTS and environment/home boundaries, and authoritative-file snapshots that detect lifecycle rewrites.
Retained provider evidence can assert terminal-success **current-tree** records for prior commits when supplied through `GATE_PROVIDER_EVIDENCE_FILE`. Each normalized record contains `commit`, globally unique integer pipeline `number`, pipeline `status`, and exactly one `gate-verify` step; the highest-numbered rerun for a commit is authoritative. The full collection is validated before commit filtering, so one pipeline identity cannot certify two commit subjects. Ambiguous duplicates fail. Absent, expired, or currently-running evidence is reported explicitly and never inferred as success.
The history seam is not a manifest field and is not derived from an author-positioned registry path. `gate-history.mjs` derives the feature range from Git's merge-base with the provider target `refs/remotes/origin/main`; a gate change committed before delayed registry introduction therefore remains in range and fails because its own tree has no registry. Registered controls reject HEAD, HEAD's parent, the introduction commit, and delayed introduction after a gate change.
**DOES:** This bootstrap is sound against a branch author who cannot rewrite main: reordering or splitting commits cannot move the target merge-base. **DOES NOT:** It does not establish integrity if main itself is compromised or rewritten. Builds 1-2 own that residual main-integrity dependency.
Universal checks first prove populations non-empty. The production profile anchors the required seven gate IDs to their canonical sources, while `gateRefs` on the D-38/D-40 criteria must exactly span every registered gate. Population controls mutate evidence-subject and type-strict comparison inputs one gate at a time and require rejection across the complete inventory.
Once RM-60 supplies the external pre-execution anchor, protected post-merge/main replay is detection, not pre-merge prevention. A failed replay requires quarantine of the affected result and revert of the offending merge. It must never be represented as proof that CI blocked that merge. RM-25 tracks provider enforcement.
+58
View File
@@ -14,6 +14,64 @@
---
## RM-02 Gate Registry and Negative-Control Verifier (#1029)
### Problem and objective
Existing deterministic gates can return success without enforcing their stated property. RM-02 introduces a machine-readable registry and an unconditional CI verifier that distinguishes required behavior from observed behavior, proves every registered negative control can detect its own failure reason, and makes source/deployment drift visible.
### Scope
**In scope:** root typecheck, lint, and format gates; RM-01 checkout preflight; the Mosaic CI queue guard; root Husky pre-commit and pre-push hooks; criterion bindings; modeled compatibility; meaning-change provenance; security/integrity prose claim markers; source-versus-deployed identity; unprivileged current-tree PR verification; retained provider CI evidence where available; and explicit deferral of isolated per-commit replay to RM-60's protected external authority.
**Out of scope:** fixing the queue guard (RM-03); exhaustive registration of every repository executable (RM-54); semantic proof that arbitrary English criteria are mutually satisfiable (RM-54/RM-55); a same-authority trust anchor for repository-authored evidence (RM-25/RM-59).
### Normative requirements
1. `RM02-REQ-01`: The JSON registry SHALL give every gate and criterion a stable ID and SHALL declare exact invocation, input classes, cases, exact observed and required exit codes, reason diagnostics, and criterion bindings.
2. `RM02-REQ-02`: Every gate SHALL have at least one observed-red must-fail case. The verifier SHALL reject missing, stale, ambiguous, or ineffective declared inert mutations and SHALL name an externally inerted gate.
3. `RM02-REQ-03`: Every acceptance criterion SHALL declare exact criterion-side `caseRefs` that match case-side `criterionIds` bidirectionally and include a case that can fail for that criterion's stated reason. Moving a binding to an unrelated case SHALL fail verification. Security/integrity prose claims in the designated governing documents SHALL carry bound `GATE-CLAIM:<id>` markers and declare the exact must-fail case exercising the claim criterion.
4. `RM02-REQ-04`: Declared finite compatibility scenarios SHALL execute together and direct modeled contradictions SHALL fail. This does not claim semantic consistency of arbitrary English.
5. `RM02-REQ-05`: Restated criteria SHALL retain original text, current text, reason, finding/task, and dated meaning-change history.
6. `RM02-REQ-06`: An observed behavior differing from required behavior SHALL be reported as `DEFECT` with a tracked owner; an ownerless delta SHALL fail verification. Such a gate SHALL never be described as passing, green, or OK.
7. `RM02-REQ-07`: Executables under declared gate roots SHALL fail with `unregistered gate` when absent from the registry. The initial coverage boundary SHALL explicitly list exclusions and bind the broader inventory to RM-54.
8. `RM02-REQ-08`: Every gate with a deployed counterpart SHALL register source/deployed byte identity and a must-fail drift control. Gates without a deployed counterpart SHALL say so explicitly.
9. `RM02-REQ-09`: CI SHALL run `pnpm gate:verify` on every pull request without path filtering and on protected-main pushes.
10. `RM02-REQ-10` (restated): PR CI SHALL perform unprivileged, fail-closed current-tree verification only. Isolated per-commit replay SHALL remain deferred to RM-60's protected post-merge/main authority, cross-referenced with RM-59. That future replay is detection with a quarantine/revert response, not pre-merge prevention; inability to establish its sandbox is terminal nonzero, never skip/pass. Retained provider evidence SHALL remain distinct and SHALL never be inferred when absent.
11. `RM02-REQ-11`: The audited branch range SHALL begin at the Git merge-base with the provider target `origin/main`, not at a manifest-authored value or author-selected introduction path. A gate-affecting commit before delayed registry introduction SHALL remain in range and fail on its missing own-tree registry. This bootstrap is sound against a branch author who cannot rewrite main; it is not sound against compromise or rewrite of main, whose integrity is the Builds 1-2 dependency.
12. `RM02-REQ-12` (`D-38`): For every gate in the mechanically anchored required inventory, evidence SHALL be bound to exactly that gate subject under review. Provider pipeline shape, gate-step cardinality, and identity uniqueness SHALL be validated over the full evidence collection before commit filtering; a duplicate pipeline number across different commits SHALL fail.
13. `RM02-REQ-13` (`D-40`): For every gate in the mechanically anchored required inventory, each discriminator and comparison input SHALL have a recursively closed, type-strict schema. Unknown, misspelled, wrong-type, or present-but-empty nested assertion fields SHALL fail rather than disabling an assertion.
14. `RM02-REQ-14` (`D-46`): No universally quantified registry check SHALL run until its population is proven non-empty and anchored. The required seven-gate inventory, criteria, prose claims, and compatibility scenarios SHALL reject empty populations before reporting that all registered cases ran.
#### RM02-REQ-10 meaning-change provenance
- **Original:** “assert that every merged commit passed every required gate, evaluated AGAINST THAT COMMIT'S OWN TREE — not against current main.”
- **Restatement:** PR CI performs unprivileged, fail-closed current-tree verification only. Isolated per-commit replay is deferred to a protected post-merge/main authority, where it is detection with a defined quarantine/revert response — explicitly not a pre-merge gate. Inability to establish the sandbox is hard nonzero, never a skip.
- **Reason:** Isolated replay on PR CI would require granting namespace capability to PR-controlled configuration, which the same PR could use directly before containment. The trust boundary is impossible at the repository layer, not merely expensive. RM-60 owns the external pre-execution anchor; RM-59 tracks the corresponding artifact-integrity anchor.
### Acceptance criteria
1. `RM02-AC-01`: A healthy current tree returns zero while prominently reporting the queue guard's required-versus-actual `DEFECT (owner: RM-03)` delta.
2. `RM02-AC-02`: Externally mutate any registered gate at its declared inerting point so its failure path succeeds; verification returns nonzero and names that gate. The verifier's internal meta-control is observed red before its healthy result is trusted.
3. `RM02-AC-03`: An executable added under a declared gate root without an entry returns nonzero and includes `unregistered gate`.
4. `RM02-AC-04`: A gate with zero must-fail cases returns nonzero and includes `no negative control`.
5. `RM02-AC-05`: Unbound or semantically misbound criteria, prose claims bound to unrelated cases, unbound governing prose markers, ownerless behavior deltas, stale mutations, source/deployed drift, and modeled compatibility conflicts each return nonzero with the responsible stable ID. A simultaneous stale fixture or independent phase error SHALL NOT mask responsible stable-ID diagnostics. Registered meta-negative controls move a criterion binding, remove meaning provenance, and redirect a prose claim to an unrelated case; each is observed red for its stated reason.
6. `RM02-AC-06`: CI configuration invokes the verifier unconditionally on every pull request.
7. `RM02-AC-07`: PR output states adjacent `DOES`/`DOES NOT` boundaries: current-tree gates and inerting mutations execute unprivileged and fail-closed; isolated own-tree replay does not execute in repository-controlled PR CI. RM-60/RM-59 are named, retained provider evidence is never inferred, and future protected post-merge detection specifies quarantine/revert rather than claiming pre-merge prevention.
8. `RM02-AC-08`: Registered must-fail controls reject history seam candidates at HEAD, HEAD's parent, and the registry introduction; delayed registry introduction after an earlier gate change; an emptied registry; a cross-commit duplicate provider pipeline identity; a misspelled nested outcome field; a wrong outcome field type; and a present-but-empty outcome pattern.
9. `RM02-AC-09`: Population controls iterate every gate in the anchored inventory and prove evidence-subject mismatch and wrong-type comparison input are rejected for each gate. `RM02-EVIDENCE-SUBJECT-BINDING`, `RM02-TYPE-STRICT-SCHEMA`, `RM02-HISTORY-BOUNDARY`, and `RM02-NONEMPTY-ANCHORED-QUANTIFICATION` are bidirectionally bound to their must-fail controls.
### Risks, dependencies, and verification boundary
- The repository verifier proves declared controls, modeled scenarios, bidirectional declared criterion/case relationships, source/deployed equality at execution time, and unprivileged current-tree behavior. It does **not** infer arbitrary-English semantics, execute isolated per-commit replay, or defend against an actor able to rewrite the gate, registry, verifier, and sandbox entry consistently.
- Sandbox refusal tests require parent-generated Bubblewrap-launch provenance and proof that the sandbox entry command never ran; child-controlled denial-looking text alone cannot establish unavailability.
- Repo-only code cannot both grant namespace capability to PR configuration and prevent that same PR from using the capability directly. RM-60 owns a runner/provider-controlled pre-execution boundary; RM-59 owns the parallel artifact-integrity anchor.
- Protected post-merge replay, once RM-60 exists, is detection only. Failure requires immediate quarantine of the affected result and revert of the offending merge; it is not equivalent to a pre-merge gate.
- External branch protection and provider CI history supply merge-time current-tree evidence where retained. RM-25 tracks provider-side enforcement.
- `ASSUMPTION:` RM-54 is the owner for expanding registration and prose-marker coverage beyond this approved seven-gate slice; rationale: the remediation task graph already assigns the fleet-wide inert-gate audit there.
---
## Problem Statement
Jarvis (v0.2.0) is a self-hosted AI assistant with a Python FastAPI backend and Next.js frontend. It handles chat, projects, tasks, and LLM routing but lacks orchestration depth, agent coordination, shared memory, and remote access. The Mosaic framework (`~/.config/mosaic`) provides agent guides, shell-based orchestration tools, and quality rails — but these are loose scripts, not an integrated platform. The `@mosaicstack/*` packages in mosaic-mono-v0 began consolidating these into TypeScript packages (brain, queue, coord, cli, prdy, quality-rails) but have no UI, no auth, and no agent runtime integration.
+6
View File
@@ -1,5 +1,11 @@
# Documentation Sitemap
## Gate verification
- [Developer gate registry guide](DEVELOPER-GUIDE/quality-gate-registry.md) — manifest schema, negative controls, defect deltas, modeled boundaries, and commit/provider evidence.
- [Gate registry operations](ADMIN-GUIDE/quality-gate-registry.md) — routine verification, failure interpretation, registry updates, and unconditional CI behavior.
- [RM-02 governing claim index](remediation/GATE-CLAIMS.md) — marker bindings for orchestrator-owned remediation claims without modifying task tracking.
## Compaction refresh lease broker
- [Internal broker protocol](architecture/lease-broker-protocol.md) — kernel identity, ancestry and generation invariants, framed requests, responses, and persisted cycle bindings.
@@ -0,0 +1,94 @@
# RM-02 Gate Registry Implementation Plan
> **For Pi:** Use test-driven development and execute each task RED → GREEN → refactor.
**Goal:** Build a machine-readable seven-gate registry and an unconditional CI verifier that detects inert gates, binds criteria to observed negative controls, records defects honestly, and verifies the current PR tree unprivileged and fail-closed.
**Architecture:** A dependency-free Node CLI reads `gates/gates.manifest.json`, validates its closed schema and references, then runs typed cases in isolated main-disk fixtures. Gate-specific fixture setup remains declarative; exact invocations and exact observed/required exits stay in JSON. A separate history module checks activation/manifest provenance and retained external current-tree CI evidence without inferring missing evidence. Isolated own-tree execution remains fail-closed code for RM-60's future protected authority; repository-controlled PR CI does not invoke it.
**Tech Stack:** Node.js ESM, `node:test`, JSON, shell gates, pnpm, Woodpecker CI.
---
### Task 1: Meta-negative-control kernel
**Files:**
- Create: `scripts/gate-verify.test.mjs`
- Create: `scripts/gate-verify.mjs`
1. Write a black-box fixture whose gate failure branch has already been changed to success.
2. Run `node --test scripts/gate-verify.test.mjs`; require failure because the absent verifier does not name the inert gate.
3. Implement manifest loading, exact process execution, and named mismatch reporting only.
4. Re-run and require the external inert mutation to produce verifier nonzero while the test passes.
5. Add an internally applied declared mutation and require a healthy fixture to report its negative control armed.
### Task 2: Registry structural clauses
**Files:**
- Modify: `scripts/gate-verify.test.mjs`
- Modify: `scripts/gate-verify.mjs`
Add failing tests, one behavior at a time, for: `unregistered gate`; `no negative control`; unbound criterion; unbound `GATE-CLAIM`; ownerless required/actual delta; stale/ambiguous/ineffective mutation; direct modeled conflict; missing meaning-change provenance. Implement the minimum validator after each observed RED.
### Task 3: Gate fixtures and seven-gate manifest
**Files:**
- Create: `gates/gates.manifest.json`
- Create: `gates/fixtures/quality-case.mjs`
- Create: `gates/fixtures/preflight-case.mjs`
- Create: `gates/fixtures/queue-case.sh`
- Create: `gates/fixtures/hook-case.sh`
- Modify: `scripts/gate-verify.test.mjs`
Register typecheck, lint, format, RM-01 preflight, queue guard, pre-commit, and pre-push. For each, first run its known-bad case against an intentionally inert fixture and observe verifier RED; then restore the real gate behavior and require its exact observed exit/reason. Record queue defects as required/actual deltas owned by RM-03, never as pass/green/OK.
### Task 4: Source-versus-deployed identity
**Files:**
- Modify: `gates/gates.manifest.json`
- Modify: `scripts/gate-verify.test.mjs`
- Modify: `scripts/gate-verify.mjs`
Write and observe a failing test with a byte-mutated deployed counterpart. Implement byte equality and internal drift mutation controls. Declare `none` explicitly for gates without deployed counterparts.
### Task 5: Prose claims and compatibility constructions
**Files:**
- Modify: `docs/remediation/MISSION.md`
- Modify: `docs/remediation/TASKS.md` only if coordinator authorization overrides the worker prohibition; otherwise place markers in an RM-02 claim index that references immutable source anchors.
- Modify: `gates/gates.manifest.json`
- Modify: verifier tests/implementation.
Enumerate current security/integrity claims, bind each marker/id to a negative case, and reject unbound markers. Execute finite compatibility scenarios and clearly document that arbitrary English consistency is outside the model.
### Task 6: Current-tree boundary, deferred replay, and provider evidence
**Files:**
- Create: `scripts/gate-history.mjs`
- Create: `scripts/gate-history.test.mjs`
- Modify: `scripts/gate-verify.mjs`
- Modify: `gates/gates.manifest.json`
Test with a synthetic git repository containing two commits whose manifests differ. PR verification must state adjacent `DOES`/`DOES NOT` boundaries and must not execute the intermediate commit's verifier. Preserve isolated replay as a direct fail-closed primitive for RM-60's future protected pre-execution authority; sandbox failure remains nonzero. Add bounded Gitea/Woodpecker current-tree status lookup for prior commits when credentials/history are available. Missing, expired, and currently-running evidence must be explicit states, never inferred success. Protected post-merge replay is detection with quarantine/revert, never pre-merge prevention.
### Task 7: CI and documentation
**Files:**
- Modify: `package.json`
- Modify: `.woodpecker/ci.yml`
- Create/update: `docs/DEVELOPER-GUIDE/quality-gate-registry.md`
- Create/update: `docs/ADMIN-GUIDE/quality-gate-registry.md`
- Modify: `docs/SITEMAP.md`
Add `gate:verify`; run it in an unconditional PR/main CI step. Document invocation, defect semantics, coverage/exclusions, marker syntax, replay/provider boundaries, and source/deployed identity.
### Task 8: Verification and delivery
Run focused tests, `pnpm gate:verify`, checkout tests, typecheck, lint, format, and applicable integration tests. Run Codex code and security review; remediate and re-review. Verify authorship, commit, execute queue guard before push, push, create PR via Mosaic wrapper, and send exact-head review request to rev-974 through the coordinator. Do not merge without coordinator authorization.
+25
View File
@@ -0,0 +1,25 @@
<!-- board-roll: 1 entry rolled from BOARD.md -->
### **D-1 / P-ACTIVATION + hygiene — committed `.npmrc` hard-pins `store-dir=/root/.local/share/pnpm/store`.**
Correct for the CI container (runs as root), fatal for EVERY non-root local checkout: `EACCES` on `/root/.local/share/pnpm/store/v10/server/server.json`. A committed config that only works on one runtime is exactly the activation-skew class. Fix candidate: make store-dir env-overridable, not hardcoded.
<!-- board-roll: 2 entries rolled from BOARD.md -->
### **D-3 / P-FLEET-001 — the seats running this mission are UNMANAGED.** `mos-remediation`, `rev-974`,
`planner-opus`, `planner-sol` appear in NO roster (`~/.config/mosaic/fleet/roster.yaml`, `agents/`). Planners run on socket `default`; the roster declares `mosaic-fleet`. This is the exact "one roster-owned socket/host + quarantine unmanaged + stale GC" failure P-FLEET-001 indicts — observed on the remediation mission's own fleet. Prerequisite for INBOX identity-addressing.
### **D-2 / hygiene — husky `prepare` fails `EPERM` copying into root-owned `.husky/_/`.** Repo working
tree has root-owned dirs (`.husky/`, repo root) under a non-root agent. Worked around with the intended `HUSKY=0` escape hatch (does NOT disable the existing pre-commit/pre-push hooks).
<!-- board-roll: 2 entries rolled from BOARD.md -->
### **D-5 / P-QUEUE-001 + P-CONFORMANCE-001 — KEYSTONE: an inert gate that erased its own evidence.**
Merged PR #868 (`b79336a8`) shipped a file that FAILS `pnpm format:check` ⇒ the CI format gate did not block. An unrelated later PR (#872) then reformatted that file via its own `lint-staged`, so `main` went green again and nobody learned the gate had failed to fire. Verified blob-level under the repo's own config. **Detection must be per-merge-commit against that commit's own tree** — a "is main green today" check reports all-clear on this exact defect. Binding on RM-02/RM-55. Full chain in `TASKS.md` §1a. NOT quiet-patched, by Mos's ruling: patching the symptom destroys the signal.
### **D-4 / P-LIFECYCLE + hygiene — a dispatched agent silently IGNORED an in-message context reset.**
planner-sol was at 64.3%/372k; the brief asked it to reset first; it began work on dirty context anyway. Only an out-of-band `/new` driven by the orchestrator guaranteed clean state. Confirms the postmortem thesis: **instructions are not enforcement.** Reset must be a mechanical pre-dispatch step, not a request.
+93
View File
@@ -0,0 +1,93 @@
# mos-remediation — LIVE BOARD (keep < 8 KB)
**Phase:** EXECUTING — P0 open. RM-01 MERGED; RM-02 (keystone gate registry) is next.
**Updated:** 2026-07-31 (mos-remediation orchestrator; seat active on `mosaic-fleet`).
## Head
- Mission charter + 15 decisions + 4-build plan: PERSISTED (`docs/remediation/MISSION.md`).
- HOLD lifted for this workstream (Jason 2026-07-31). Nothing implemented yet — planning first.
- Orchestrator seat `mos-remediation` is LIVE and owns the mission. Residency attestation: PASS.
- **TASK-0 DONE** — checkout repaired, all three gates green HONESTLY (no `--no-verify`), branch pushed.
- **TASK-1 DONE** — both planners delivered independently on clean context; reconciled into `TASKS.md`
(58 tasks across P0P5, 7 convergences, 7 adjudicated disagreements, 3 escalated decisions).
- **NEXT ACTION IS NOT MINE:** DECISION-1/2/3 (`TASKS.md` §5) must be ruled before P0 dispatch.
RM-01 is dispatchable immediately regardless — it depends on nothing and blocks everything.
## In-flight
| Task | Owner | State |
| ----------------------------------- | --------------- | ------------------------------------------------------------------------- |
| RM-01 reproducible checkout | — | **MERGED** `f58b3699` (PR #1027) — rev-974 APPROVE + CI #2172 8/8 green |
| RM-02 gate registry ★keystone | unassigned | **READY** — depends only on RM-01; not held by RM-03 |
| RM-03 queue guard (3 defects) | — | HOLD — #1023 SUPERSEDED-PENDING-JASON |
| RM-59 close D-19 residual risk | — | BLOCKED by RM-12/RM-21/RM-25 (spine + executor) — tracked edge, not prose |
| `remediation/state` snapshot → main | mos-remediation | opening at this mission seam |
## Fleet seats
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
## Gate status
- Delivery gates active: author≠reviewer, diff-blind pre-registered checks, CI-green, merged-PR completion.
- Freeze: LIFTED for this workstream only.
- Git identity: `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
- Capability check (D-11b): before dispatching seat X to provider Y, verify
`~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token` exists. Token-file set = authoritative
capability registry. Mos owns provisioning; escalate missing pairs to him.
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
- Standing worker-brief doctrine (accreted, mandatory in every brief): don't weaken a RED test to make
it pass; if a check is unrunnable as written SAY SO, never silently substitute; `agent-send -f` never
`-m`; heavy artifacts off shared `/tmp`.
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
## Sequencing (from MISSION.md)
1. Spine + choke-point service (MACP wiring @ mosaic_orchestrator.py::run_single_task) + PG/Redis
**CONTESTED — see DECISION-1.** Both planners independently reject this wire-in point: that
controller is `"enabled": false` and references a dispatcher that does not exist here. Charter text
left UNCHANGED pending Mos/Jason ruling; do not treat it as settled.
2. Rotation daemon (finish Mission Control Plane, reuse packages/coord)
3. Comms service (envelope→service→PG/Redis→adapters)
4. Hygiene + conformance harness
Cross-cutting retirements: flat-file tracking, 3 MACP islands, silent MOSAIC BYPASS.
## Dogfood evidence — live failure classes, not hypotheticals
> Newest first. Oldest entries roll to `BOARD-LEDGER.md` via `board-roll.sh` when this file
> exceeds its 8 KB cap. Keystone detail is duplicated in `TASKS.md` §1a, so rolling loses nothing.
<!-- BOARD-ROLL:START -->
### **D-8 / P-CONFORMANCE-001 — a PRE-REGISTERED acceptance check that was not runnable as written.**
PR #1025 AC2's fixture `mkdir -p apps/*/venv/lib` creates a literal `apps/*/venv/lib` dir when the glob is unmatched — it did not test what it claimed. rev-974 ran it exactly as written, caught it, re-ran the intended assertion at an explicit path, and **disclosed** rather than silently substituting a working fixture and reporting PASS. **Pre-registration protects a check from being retrofitted to the implementation; it does not make the check correct.** An unverified gate appeared inside the mechanism built to catch unverified gates. Hard requirement on RM-02: the registry must self-verify that every registered case runs AND can fail — presence is not evidence.
### **D-7 / P-FLEET-001 — stale-GC-on-disk: shared 30G /tmp hit 100% ENOSPC, degrading two seats.**
~5.2G was session scratch dead 8-9 days (this session's own footprint: 88K). Same missing capability as orphaned-tmux-session GC, applied to disk — not a quota or discipline problem. Resolved manually by Mos (lead coordinator) after independent verification; `/tmp` now 79%. **The gap IS the finding:** the authority to reap exists, the deterministic reaper does not. Folded into RM-50 with explicit requirements (mechanical liveness, age threshold, dry-run, audit event per reap — never a heuristic sweep). Refusing to unilaterally delete another session's scratch was correct doctrine; the fix is a reaper, not braver agents.
### **D-6 / P-QUEUE-001 — the mandated queue guard returned PASS on an UNKNOWN state, live, today.**
Running the required `ci-queue-wait.sh --purpose push` before pushing produced `state=unknown ... exit 0` — the exact defect at `ci-queue-wait.sh:282-288` that PR #1023 is parked on. It also evaluated `branch=main` rather than the branch being pushed. The mission's own required pre-push gate passed me on an indeterminate result. Third independent live instance of the class.
<!-- BOARD-ROLL:END -->
## Decisions log
- 2026-07-31 — Mission set up by Mos post-postmortem (15/15 decided). Dogfood posture active.
- 2026-07-31 — Mos: stale `.mosaic/orchestrator/mission.json` is RESIDUE of the disabled Python
orchestrator rail that this plan RETIRES. Do NOT invest in it; do NOT build on that rail. The 0/0
milestone banner is cosmetic. (Supersedes any plan to repair it.)
- 2026-07-31 — Mos: planners must be dispatched with GUARANTEED clean context, not requested-clean.
Prior default-socket planner sessions predate this mission; dirty context is the indicted hygiene.
- 2026-07-31 — mos-remediation: worker briefs forbid all git ops and restrict each worker to a single
named output file, so two planners can share one checkout without a branch race (M2-era incident doctrine).
File diff suppressed because it is too large Load Diff
+424
View File
@@ -0,0 +1,424 @@
# Adversarial Decomposition — Pragmatic / Shortest-Path Side
**Planner:** `planner-sol`
**Bias:** make one real fleet task pass through one enforced path as early as possible; reuse before building.
**Scope source:** `MISSION.md`, `MACP-WIRING-SCOUT.md`, `BOARD.md`, existing `@mosaicstack/macp`, `packages/coord`, PG/Valkey, Tess durable inbox/outbox, and the Mission Control PRD.
## Executive position
The first useful milestone is **not** “complete Builds 1 and 2.” It is this narrow vertical slice:
> A DB-backed mission task is atomically claimed by `packages/coord`, executed by one Node `@mosaicstack/macp` TaskExecutor, gated, and terminally recorded with identity-bound events and a tri-state mutation result. No `docs/TASKS.md`, `mission.json`, `tasks.json`, Python gate loop, or NDJSON ledger participates.
That slice is **SOL-03 → SOL-04 → SOL-05 → SOL-06 → SOL-07 → SOL-08**, estimated at **72K tokens**, mostly Codex. PG polling is acceptable for this first proof. Redis acceleration follows only after correctness is observable. This is the shortest path that is both dogfoodable and not throwaway work.
### Cost posture
- **25 PR tasks, ~294K tokens total:** ~164K Codex, ~130K Sonnet, **0K Opus**.
- First live choke-point dogfood: ~72K on the hard path; SOL-01 and SOL-02 can run beside it.
- Opus is not justified for planned implementation. Escalate only if an independent security review finds an unresolved architecture-level authority flaw.
- Every row is one PR. Estimates include implementation, focused tests, docs affected by that PR, and one remediation pass—not orchestration/reviewer overhead.
## Gates and critical path
| gate | opens when | proof required before downstream work |
| ------------------------------------------- | -------------- | --------------------------------------------------------------------------------------------------------- |
| **G0 — trustworthy launch gates** | SOL-01, SOL-02 | non-root checkout works; queue status cannot become false-green |
| **G1 — first dogfood / minimum viable cut** | SOL-08 | one live fleet task completes DB → MACP executor → gates → DB with no flat-file state |
| **G2 — Builds 1+2 closed** | SOL-09..SOL-12 | all producers use the executor; duplicate islands retired; Redis loss is recoverable from PG |
| **G3 — rotation real** | SOL-13..SOL-16 | stale generation cannot mutate; fresh session resumes typed state; Pi-brick recovery works without broker |
| **G4 — sole-path comms real** | SOL-17..SOL-22 | roster identity is stable; bounced/stale messages converge through PG/Redis and adapters |
| **G5 — mission proof** | SOL-23..SOL-25 | workflow sweep cannot capture unknown files; fault bank passes, including 100 rotations |
**Critical path:** `03 → 04 → 05 → 06 → 08 → 10 → 12 → 13 → 14 → 15 → 16 → 17 → 18 → 19 → 20 → 21 → 22 → 24 → 25`.
## Ordered task list
### SOL-01 — Repair activation coherence and non-root checkout hygiene
- **build:** 5 (hygiene; pulled forward)
- **depends_on:** —
- **acceptance criteria (diff-blind testable):**
1. A clean non-root checkout can run dependency/bootstrap preparation without accessing `/root`.
2. A root CI checkout still uses an isolated writable pnpm store.
3. Activation installs CLI, hooks, broker/runtime assets, and version manifest transactionally: induced failure leaves the prior complete generation active.
4. Launch with a deliberately skewed component version is rejected with the exact repair command; diagnostics remain usable.
5. No test uses `--no-verify` or suppresses hooks.
- **dogfood seed:** BOARD D-1 root-pinned `.npmrc` and D-2 root-owned Husky path.
- **est. tokens:** 6K
- **suggested runtime tier:** codex
### SOL-02 — Make queue guard fail-safe with exit-asserting tests
- **build:** 1
- **depends_on:** —
- **acceptance criteria (diff-blind testable):**
1. Fixture responses `pending`, `success`, `failure`, no-status, malformed JSON, provider error, and unknown status produce explicitly asserted process exits.
2. Only terminal success/no-active-queue returns 0; unknown, malformed, and transport failure return non-zero with actionable output.
3. A payload larger than 150 KiB is consumed without argv expansion or truncation.
4. At least one mutant changes unknown→success and is killed by the test suite.
- **dogfood seed:** inert gate-6 and recursive #1019 failure (unknown→exit 0; ARG_MAX).
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-03 — Complete the canonical MACP contract, not another protocol
- **build:** 1
- **depends_on:** —
- **acceptance criteria (diff-blind testable):**
1. `@mosaicstack/macp` validates typed Task, TaskResult, lifecycle Event, state Claim, and `verified | written-unverified | failed` mutation outcome records.
2. Claims require source, confidence, issued-at, TTL/expiry, refresh instruction, and HMAC integrity; tamper/expiry returns a typed refusal, never partial data.
3. Lifecycle events include launch, mission generation, checkpoint, rotation, recovery, inbox receipt, and terminal disposition while preserving existing task events.
4. `MOSAIC_AGENT_NAME` is required for mutating execution and appears in credential/actor binding; missing identity fails closed.
5. Target metadata requires repository identity, task/record ID, and head or generation where applicable.
- **dogfood seed:** rev-974 identity drift plus the three observed write outcomes.
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-04 — Add the narrow PG orchestration spine schema
- **build:** 2
- **depends_on:** SOL-03
- **acceptance criteria (diff-blind testable):**
1. Migration up creates mission, task, dependency, task-claim, MACP event, typed state-claim, session-generation, and dispatch-outbox records with tenant/mission keys and uniqueness constraints.
2. The database rejects a task without a mission, a dependency outside its mission, duplicate idempotency keys, and terminal→running regression.
3. Event and claim records reference canonical mission/task/generation identities; claims store integrity metadata.
4. Migration rollback on an empty test DB succeeds; rerunning migration is safe.
5. No comms-specific “universal message” schema is invented here; Build 4 reuses/extends existing interaction inbox/outbox tables.
- **dogfood seed:** mission convention existed but a lane could act with no mechanically valid mission/task.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-05 — Implement atomic PG task claims, transitions, ledger, and outbox
- **build:** 2
- **depends_on:** SOL-04
- **acceptance criteria (diff-blind testable):**
1. Two concurrent claimers for one runnable task yield exactly one lease owner.
2. Dependencies are evaluated transactionally; an unmet dependency can never be claimed.
3. Claim, state transition, MACP event, and dispatch-outbox append commit atomically or all roll back.
4. Expired leases are reclaimable with a higher fencing generation; stale owners cannot complete or mutate.
5. Querying mission status is derived solely from PG and returns the next runnable task deterministically.
- **dogfood seed:** model-maintained live board and stale claims surviving session changes.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-06 — Build the one production Node MACP TaskExecutor
- **build:** 1
- **depends_on:** SOL-03, SOL-05
- **acceptance criteria (diff-blind testable):**
1. A public Node executor accepts only a claimed canonical MACP Task, resolves credentials/identity, runs the worker, runs structured gates, and persists terminal result/events through SOL-05.
2. Worker exit 0 plus a failed gate cannot produce `completed`; worker failure cannot skip terminal ledger emission.
3. Claude, Codex, and Pi fixture backends emit the same runtime-neutral lifecycle sequence.
4. Every mutation returns one mandatory tri-state outcome; callers cannot compile while discarding it.
5. Crash after worker success but before terminal commit leaves a recoverable fenced claim and no false completion.
- **dogfood seed:** stranded MACP, gate-6 inert completion, and `written-unverified` being treated as success.
- **est. tokens:** 16K
- **suggested runtime tier:** sonnet
### SOL-07 — Provide one-shot flat-file import and cutover readiness audit
- **build:** 2
- **depends_on:** SOL-05
- **acceptance criteria (diff-blind testable):**
1. A dry-run parses existing mission/TASKS artifacts, reports unsupported/ambiguous rows, and performs zero writes.
2. Apply is idempotent and records source digests; repeated apply creates no duplicates.
3. Unknown status, dangling dependency, duplicate task ID, and malformed table block import with row-level diagnostics.
4. Readiness reports “cutover-ready” only when imported PG projections exactly match source counts/dependencies/statuses.
5. This command is migration-only; it exposes no dual-write or ongoing sync mode.
- **dogfood seed:** current remediation board/TASKS state needs a clean DB landing without silently losing tasks.
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-08 — Hard-cut `packages/coord` to PG and dogfood one live task
- **build:** 1
- **depends_on:** SOL-06, SOL-07
- **acceptance criteria (diff-blind testable):**
1. `mosaic coord run/status/continue` reads and mutates PG only; absent/unmigrated DB state fails with the SOL-07 repair path.
2. No fallback reads/writes `docs/TASKS.md`, mission JSON, task JSON, state JSON, results JSON, or events NDJSON.
3. A live canary task assigned to a fleet seat travels PG claim → TaskExecutor → worker → gate → terminal PG result/event and closes only after gate success.
4. Killing the coordinator after claim and restarting it neither duplicates execution nor allows the stale lease to close the task.
5. Evidence query shows actor seat, mission/task, target metadata, gate results, and tri-state outcome.
- **dogfood seed:** this remediation mission itself; reproduce a gate-6-style non-null task and identity-bound write.
- **est. tokens:** 16K
- **suggested runtime tier:** sonnet
> **G1 FIRST-DOGFOOD:** stop and validate here before broadening. If SOL-08 cannot carry a real task, do not build Redis, rotation, comms, or UI.
### SOL-09 — Route Forge and OpenClaw/MACP producers through TaskExecutor
- **build:** 1
- **depends_on:** SOL-08
- **acceptance criteria (diff-blind testable):**
1. Forge and the OpenClaw MACP runtime submit the canonical Task type to SOL-06; neither executes a worker or gate itself.
2. Their success callbacks are derived from canonical terminal results, not local/stub completion.
3. A failed canonical gate is observed identically from Coord, Forge, and OpenClaw fixtures.
4. Repository search plus an executable import boundary test finds no production-local redefinition of Task/TaskResult/GateResult on these paths.
- **dogfood seed:** Forges immediate empty-gate completion and the plugins redefined MACP-shaped result.
- **est. tokens:** 10K
- **suggested runtime tier:** codex
### SOL-10 — Retire flat-file orchestration and the disabled duplicate rail
- **build:** 1
- **depends_on:** SOL-09
- **acceptance criteria (diff-blind testable):**
1. The Python controller execution/gate/event path, `tasks_md_sync`, plugin-local protocol types, orphaned context loader, and production flat-file orchestration writers/readers are absent from shipped assets.
2. Framework guides/templates/startup context point to DB mission commands, not `docs/TASKS.md` as orchestration SoR.
3. A regression scan fails CI if production code reintroduces `events.ndjson`, `tasks.json`, `mission.json`, or `docs/TASKS.md` orchestration mutation.
4. jarvis-brain PDA flat files and unrelated project docs remain untouched.
5. Upgrade removes/quarantines obsolete generated rail files without deleting user source/docs.
- **dogfood seed:** three parallel islands and stale `.mosaic/orchestrator/mission.json` 0/0 residue.
- **est. tokens:** 14K
- **suggested runtime tier:** sonnet
### SOL-11 — Add Redis hot dispatch as a derived outbox consumer
- **build:** 2
- **depends_on:** SOL-08
- **acceptance criteria (diff-blind testable):**
1. Task creation commits mission/task/outbox in PG before any Redis enqueue.
2. Induced Redis failure leaves the task durable and pending; a sweeper later enqueues it exactly once logically.
3. Deleting the Redis queue and rebuilding from PG restores all non-terminal dispatches without reviving terminal tasks.
4. Duplicate delivery is neutralized by PG claim fencing/idempotency.
5. Existing `packages/queue` adapter/config is reused; no second broker API is introduced.
- **dogfood seed:** inert/unknown queue transport and broker outage during task dispatch.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-12 — Lock Builds 1+2 with black-box failure cases
- **build:** 2
- **depends_on:** SOL-02, SOL-10, SOL-11
- **acceptance criteria (diff-blind testable):**
1. A black-box suite proves: unknown queue status blocks; malformed task blocks; gate failure blocks completion; dropped identity blocks mutation; HMAC corruption forces refresh; Redis loss recovers from PG; stale lease cannot close.
2. The suite invokes shipped CLI/service boundaries, not internal mocks.
3. Every asserted failure checks process/result status and durable terminal/non-terminal state.
4. The same canary task succeeds under Claude, Codex, and Pi adapters or a documented unavailable-runtime fixture fails explicitly.
- **dogfood seed:** gate-6/#1019, identity drift, and built-but-unwired MACP.
- **est. tokens:** 8K
- **suggested runtime tier:** sonnet
### SOL-13 — Bind session authority to contract hash and generation
- **build:** 3
- **depends_on:** SOL-12
- **acceptance criteria (diff-blind testable):**
1. Launch computes a stable hash over the effective Constitution/AGENTS/runtime/skills set and stores it with session generation.
2. Policy change or compaction detection marks the generation stale before any subsequent mutation.
3. A stale/mismatched generation can read diagnostics but cannot claim, write task state, acknowledge comms, merge, or close.
4. Re-attestation creates a new generation; old credentials/leases remain fenced.
5. Hash input order/path normalization is deterministic across two clean launches.
- **dogfood seed:** compacted orchestrator losing directives and D-4 ignoring an in-message reset.
- **est. tokens:** 12K
- **suggested runtime tier:** sonnet
### SOL-14 — Persist compact typed rotation checkpoints using Coord primitives
- **build:** 3
- **depends_on:** SOL-13
- **acceptance criteria (diff-blind testable):**
1. Checkpoint contains mission/task, completed/blocked state, next three actions, constraints, claims, contract hash/generation, and cursors—never transcript text.
2. Checkpoint is HMAC-verified before rehydration; corrupt/expired/missing required claims refuse resume and request deterministic refresh.
3. Writing checkpoint and rotation-intent event is atomic in PG.
4. Existing Coord continuation capsule semantics are reused; no competing handoff schema/file is created.
- **dogfood seed:** manual MOS-ORCHESTRATION-BOARD checkpoint and incomplete-rehydration risk.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-15 — Finish the deterministic coordinator rotation daemon
- **build:** 3
- **depends_on:** SOL-14
- **acceptance criteria (diff-blind testable):**
1. Configured token threshold triggers checkpoint → revoke old authority → terminate → launch fresh → verify rehydration in that order.
2. Compaction-detected is a backstop that forces the same rotation path; it never requests recursive compaction.
3. A launch failure leaves the mission recoverable and visibly paused, not assigned to two active generations.
4. Ephemeral seats die/respawn without mission checkpoint; persistent/orchestrator seats rotate.
5. The implementation extends `packages/coord`; untracked `apps/coordinator` residue is not revived.
- **dogfood seed:** planner-sol dirty-context dispatch and the old coordinators log-only `_check_context()` behavior.
- **est. tokens:** 16K
- **suggested runtime tier:** sonnet
### SOL-16 — Add broker-independent recovery and remove silent MOSAIC BYPASS
- **build:** 3
- **depends_on:** SOL-15
- **acceptance criteria (diff-blind testable):**
1. With Redis/broker unavailable, a diagnostic/bootstrap command can inspect PG mission state, repair broker configuration, and resume without traversing the broker gate.
2. Normal recovery remains broker-gated and is labeled as such.
3. Break-glass requires explicit scope and expiry, emits a durable event, displays a loud banner, and auto-expires; permanent/silent bypass text or behavior is absent.
4. The Pi-brick fixture recovers the broker, then returns to normal gated operation without editing source/config by hand.
5. Orchestrator guidance removes “/compact and continue” only after the rotation command is available; ephemeral guidance remains explicit.
- **dogfood seed:** Pi brick and silent `MOSAIC BYPASS 2026-07-22`.
- **est. tokens:** 12K
- **suggested runtime tier:** sonnet
### SOL-17 — Converge each host on one roster-owned lifecycle domain
- **build:** 5 (hygiene; hard prerequisite for addressed comms)
- **depends_on:** SOL-16
- **acceptance criteria (diff-blind testable):**
1. Reconcile establishes exactly one roster-declared tmux socket/lifecycle domain per host.
2. Unknown sessions are reported and quarantined; they are never killed without positive unmanaged classification.
3. Max-age/max-context stale sessions invoke SOL-15 rotation for persistent seats or reap for ephemerals.
4. Seat identity survives respawn and equals the roster/MOSAIC_AGENT_NAME binding.
5. A fixture matching the current four unmanaged remediation seats converges them or produces explicit quarantine actions.
- **dogfood seed:** scout-bounce and BOARD D-3 seats split between default and `mosaic-fleet` sockets.
- **est. tokens:** 14K
- **suggested runtime tier:** codex
### SOL-18 — Publish authenticated `comms/v1` envelope and compatibility rules
- **build:** 4
- **depends_on:** SOL-13, SOL-17
- **acceptance criteria (diff-blind testable):**
1. Envelope validates protocol version, message/idempotency ID, sender/recipient seat identity, class, ordering/coalesce key, creation/expiry, correlation, payload digest, and authentication.
2. Current and immediately previous supported protocol versions are accepted; unsupported versions are rejected loudly with supported range.
3. Framework/runtime version is diagnostic metadata and never the compatibility key.
4. Forged sender, changed recipient/payload, expired envelope, and replay with conflicting content fail closed.
- **dogfood seed:** wrong-socket bare tmux message with no authoritative sender/recipient receipt.
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-19 — Build the logical PG-first comms service with tmux adapter
- **build:** 4
- **depends_on:** SOL-18
- **acceptance criteria (diff-blind testable):**
1. Sending commits envelope/payload and PENDING state in PG before adapter delivery.
2. State machine enforces PENDING → RECEIVED → CONSUMED or DEAD-LETTER; illegal regressions are rejected.
3. Recipient-filtered claims and append/coalesce policy are deterministic by message class.
4. tmux is a dumb adapter: delivery failure changes no PG authority state and is retryable.
5. Existing Tess durable repository/state-machine patterns are extended or generalized; no new deployable microservice or second inbox framework appears.
- **dogfood seed:** MACP scout bounce that was discovered only by manual liveness check.
- **est. tokens:** 16K
- **suggested runtime tier:** sonnet
### SOL-20 — Make `agent-send` use the sole path and prove stale-message handling
- **build:** 4
- **depends_on:** SOL-19
- **acceptance criteria (diff-blind testable):**
1. Normal `agent-send` creates a comms/v1 record and observes RECEIVED/CONSUMED; it cannot directly invoke tmux.
2. A wrong/missing socket leaves PENDING with retry diagnostics, then reaches RECEIVED after roster repair without resending.
3. A stale coalescible message arriving after a newer terminal message is marked superseded/consumed and is not surfaced as live work.
4. Duplicate identical send is idempotent; same ID with changed content is rejected.
5. Inbox receipt/terminal disposition emits canonical MACP lifecycle events.
- **dogfood seed:** scout-bounce and #1018 stale-consumed message arriving after merge.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-21 — Add Redis Streams hot delivery and PG reconciliation
- **build:** 4
- **depends_on:** SOL-11, SOL-20
- **acceptance criteria (diff-blind testable):**
1. PG commit precedes XADD; induced XADD failure is repaired by sweeper.
2. Consumer uses a PEL; ack sequence is PG CONSUMED commit before XACK.
3. Redis flush/restart rebuilds pending delivery from PG without duplicating consumed messages.
4. Pending, abandoned, and dead-letter transitions are observable with bounded retry/backoff.
5. Existing Redis/queue connection/configuration is reused.
- **dogfood seed:** delivery bounce plus broker loss between durable write and hot enqueue.
- **est. tokens:** 12K
- **suggested runtime tier:** codex
### SOL-22 — Prove adapter pluggability with the existing Matrix connector
- **build:** 4
- **depends_on:** SOL-21
- **acceptance criteria (diff-blind testable):**
1. Existing Matrix connector consumes/produces comms/v1 through SOL-19 without owning authority state.
2. The same envelope can fail tmux and later deliver through Matrix while producing one logical message lifecycle.
3. Matrix retry/reconnect cannot regress PG state or duplicate CONSUMED work.
4. Removing Matrix availability leaves PG/Redis/tmux behavior intact.
- **dogfood seed:** cross-socket scout notification bounce; alternate reach must not become alternate authority.
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-23 — Constrain auto-sync and agent writes by allowlist and lease
- **build:** 5
- **depends_on:** SOL-10
- **acceptance criteria (diff-blind testable):**
1. Auto-sync stages only an explicit allowlist; an unknown modified/untracked docs/source file remains unstaged and is reported.
2. Agent source/docs writes require the correct worktree/lease; two seats cannot acquire the same mutable target concurrently.
3. Generated files are positively identified, not inferred by denylist.
4. The measured annotation/index mid-write fixture cannot be swept into an unrelated commit.
5. DB orchestration state is absent from repository staging concerns.
- **dogfood seed:** auto-sync sweep commit `517bd5c26` capturing agent-authored docs mid-write.
- **est. tokens:** 8K
- **suggested runtime tier:** codex
### SOL-24 — Build the real-artifact lifecycle conformance harness
- **build:** 5
- **depends_on:** SOL-16, SOL-17, SOL-22, SOL-23
- **acceptance criteria (diff-blind testable):**
1. Harness launches shipped CLI/runtime artifacts and fault-injects compaction, broker outage, delivery bounce, identity drop, stale contract hash, queue unknown/malformed, Redis loss, and auto-sync collision.
2. One deterministic test executes 100 sequential rotations with no lost/duplicated task, claim, receipt, or terminal disposition.
3. Tests assert DB state/event order and process exits, not log substrings alone.
4. Harness runs against isolated PG/Redis namespaces and cleans only resources it created.
5. Every banked dogfood seed has a named case and evidence output suitable for CI/release attachment.
- **dogfood seed:** the complete failure bank: Pi brick, scout-bounce, gate-6/#1019, identity drift, auto-sync, #1018 stale-consumed, D-4 dirty context.
- **est. tokens:** 18K
- **suggested runtime tier:** sonnet
### SOL-25 — Complete operator cutover docs and activation proof
- **build:** 5
- **depends_on:** SOL-01, SOL-02, SOL-10, SOL-16, SOL-22, SOL-24
- **acceptance criteria (diff-blind testable):**
1. Operator docs give exact DB import/cutover, rollback-before-cutover, recovery, break-glass expiry, rotation, comms, quarantine, and conformance commands.
2. Link/command checks find no orchestrator instruction to mutate flat-file mission/tasks, use silent bypass, direct-tmux normal comms, or “compact and continue” a persistent seat.
3. A clean non-root install activates one coherent version and runs the conformance smoke subset.
4. Release evidence maps all 15 decisions and every live seed to a passing check or an explicit deferred item below.
- **dogfood seed:** activation skew plus the tendency to leave built fixes unwired or undocumented.
- **est. tokens:** 6K
- **suggested runtime tier:** codex
## Explicit DEFER list (10)
These are not rejected; they are **past first dogfood** and should not delay G1/G2. Each is gold-plating unless a live failure makes it necessary.
1. **DEFER — Mission dashboard/TUI views.** CLI/DB queries are enough to operate and prove the spine.
2. **DEFER — PRD-to-board automatic decomposition.** This is LLM/judgment-heavy and unrelated to enforcing already-decided tasks.
3. **DEFER — General heuristic churn scoring.** Implement token threshold + compaction sensor first; repeated-tool-loop inference can follow measured need.
4. **DEFER — Discord comms adapter.** Existing plugin reach remains; migrate only after tmux+Matrix prove the service contract.
5. **DEFER — Slack comms adapter.** No current dogfood dependency.
6. **DEFER — Telegram comms adapter.** No current dogfood dependency.
7. **DEFER — Public MCP comms surface.** `agent-send` and service API are sufficient for the mission proof.
8. **DEFER — Protocol-v2 features/general negotiation framework.** Ship v1 with a bounded current/previous acceptance window; do not predict v2.
9. **DEFER — Multi-region/HA PG or Redis.** Existing in-stack PG+Redis and rebuildability satisfy current failure classes.
10. **DEFER — Event analytics/search UI and long-term warehouse.** Indexed PG evidence plus CLI queries is enough for audit/conformance.
## Suspect abstractions register
| proposed thing | verdict |
| ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Canonical Node `TaskExecutor` | **JUSTIFIED:** explicitly required single choke point; wraps existing MACP functions rather than replacing them. |
| PG repository methods | **JUSTIFIED but narrow:** ordinary adapters around existing Drizzle/DB patterns, not a new “state platform.” |
| Rotation daemon | **JUSTIFIED:** finishes `packages/coord`; do not revive `apps/coordinator` or create another service. |
| Comms service | **JUSTIFIED only as a logical in-process boundary:** reuse Tess durable inbox/outbox and existing connectors; no new deployable microservice this cycle. |
| Universal queue/broker abstraction | **SUSPECT / DO NOT BUILD:** reuse `packages/queue`, PG outbox, and Redis Streams/BullMQ configuration already present. |
| Universal envelope/state framework | **SUSPECT / DO NOT BUILD:** MACP Task/Claim/Event and comms/v1 have different bounded purposes. |
| Generic compatibility-negotiation engine | **SUSPECT / DEFER:** a small supported-version check meets v1 needs. |
## Dissent (7)
1. **Do not wire new production behavior into `mosaic_orchestrator.py::run_single_task`.** The scout correctly identified the duplicated block, but BOARDs later ruling says the disabled Python rail is residue and must be retired. Building a Node bridge only to delete it is throwaway. Put the Node TaskExecutor in `@mosaicstack/macp`, route the live Coord path to it at SOL-08, migrate remaining producers at SOL-09, then delete the Python block at SOL-10.
2. **Redis is not on the first-dogfood critical path.** PG claim/polling is sufficient for one real task and exposes correctness earlier. Add Redis only after G1; otherwise queue debugging obscures whether the choke point works.
3. **“One choke-point service” does not justify a new deployable service.** An exported executor plus Coord daemon is enough. A new Nest app, RPC protocol, deployment, auth layer, and health plane would be greenfield.
4. **The Mission Control PRDs file-first and board-regeneration assumptions are superseded.** Keep its mission/rotation semantics, but obey the accepted hard DB cutover; do not implement its file-first milestones or PRD-to-board generator now.
5. **Do not gate every interactive runtime launch as if it were a mission task.** Enforce every tracked task/data mutation at the executor/DB authority boundary. Ephemeral interactive shells may launch, but receive no task mutation authority unless attached to a valid claim.
6. **Do not implement broad “churn intelligence.”** Token threshold and compaction-detected are deterministic sensors. Repeated-loop semantic detection is expensive, noisy, and premature until telemetry demonstrates a gap.
7. **The 100-rotation test is a final conformance bar, not an early unit-test tax.** First prove one rotation, then fault cases, then 100 repetitions in SOL-24. Requiring 100 before G3 would delay feedback without changing the design.
## Orchestrator reconciliation notes
- Pre-register each tasks acceptance checks from this document before showing implementation diffs to its reviewer. Author and reviewer remain different seats.
- SOL-07 permits a one-time import, **not** an interim store: no shadow writes, dual reads, or sync daemon.
- G1 is the budget escape hatch. If the 72K hard-path slice does not work, stop and remediate instead of spending the remaining ~222K.
- Docs belong in each behavior-changing PR where required; SOL-25 is cross-link/cutover validation, not permission to postpone essential docs.
+32
View File
@@ -0,0 +1,32 @@
# RM-02 Governing Claim Index
This index binds remediation claims that live in orchestrator-owned `TASKS.md` without modifying that file. The source heading and quoted text are the reviewable anchor; `gate:verify` enforces each marker-to-criterion binding. Marker completeness beyond this approved slice remains RM-54.
## Prose is an enforceable claim
<!-- GATE-CLAIM:PROSE-IS-A-CLAIM -->
- Source: `docs/remediation/TASKS.md`, heading `D-20 — the orchestrator's own documentation overclaimed, and a reviewer disproved it empirically`.
- Anchored text: “The defect was not in the code — it was in this file.”
## Generated-state verification scope
<!-- GATE-CLAIM:GENERATED-STATE-SCOPE -->
- Source: `docs/remediation/TASKS.md`, heading `D-19 — an integrity property that cannot exist at the layer it was specified`.
- Anchored text: “a verifier that cannot detect the attack is not a verifier.”
## Execution trust boundary
<!-- GATE-CLAIM:EXECUTION-TRUST-BOUNDARY -->
- Source: RM-02 ruling recorded under `docs/remediation/TASKS.md`, RM-02 clause 4, D-25.
- Anchored text: “SELF-VERIFICATION BY THE AUDITED PARTY IS NOT VERIFICATION.”
- Dependency: RM-60/#1031, cross-referenced with RM-59.
## Criterion restatement provenance
<!-- GATE-CLAIM:CRITERION-RESTATEMENT -->
- Source: `docs/remediation/TASKS.md`, heading `D-18 — two pre-registered criteria were mutually unsatisfiable, discoverable only at implementation`.
- Anchored text: “Both criteria were pre-registered. They cannot both be satisfied.”
+49
View File
@@ -0,0 +1,49 @@
# mos-remediation — Orchestrator Kickstart / Compaction-Survival Resume
**You are `mos-remediation`, the project orchestrator for the Mosaic Stack remediation, launched in `/src/mosaic-stack`.**
This file is your fail-closed resume procedure. Read it on EVERY fresh/cleared session and on the FIRST turn
after any compaction. This mission's whole point is that manual compaction-survival is fragile — so follow this
mechanically until Build 3 (rotation) makes it automatic.
## On resume (do in order, before any orchestration action)
1. `cd /src/mosaic-stack`, then **`git fetch origin remediation/state`**.
**The live board is on the rolling branch `remediation/state`, NOT on `main`.** `main` carries only
periodic snapshots, so reading the board from `main` will silently give you a STALE tick. Read the
live files at `origin/remediation/state` (e.g. `git show origin/remediation/state:docs/remediation/BOARD.md`),
or check that branch out. Every tick is pushed there immediately, so its HEAD is always the newest state.
2. Read `docs/remediation/MISSION.md` — the charter (goal, 4 builds, 15 decisions, sequencing, directives).
3. Read `docs/remediation/BOARD.md` **at `origin/remediation/state`** — the LIVE state: current phase,
in-flight tasks, fleet seat assignments, gate status. Single source of in-flight truth (kept < 8 KB;
older entries roll to `BOARD-LEDGER.md` via `board-roll.sh`).
4. Read the discussion checkpoint for full rationale if needed:
`../jarvis-brain/docs/scratchpads/postmortem/REMEDIATION-DISCUSSION-STATE.md` (or the jarvis-brain repo path).
5. **Residency attestation (fail-closed):** restate from the reloaded files — (a) the goal in one line, (b) the
current build/phase, (c) the BOARD head (in-flight tasks + who owns them). If you cannot, HALT and re-read.
Do NOT act on memory alone; a compaction may have dropped context silently.
## Standing invariants (never violate)
- **North star:** deterministic-right-answer → code/gate; LLM only for judgment.
- **Delivery gates:** author≠reviewer; PRE-REGISTERED diff-blind checks committed before reading the diff;
CI terminal-green; completion = merged PR + closed issue. rev-974 = the mosaicstack reviewer identity.
- **Dogfooding:** every fix validated against its live seed case (MISSION.md lists them).
- **Tracking → DB** (hard cutover); do NOT re-invest in flat-file tracking. jarvis-brain PDA is off-limits.
- **Git identity:** export `MOSAIC_GIT_IDENTITY=<your-seat>` so wrappers author correctly and survive respawn.
## After every significant event
Overwrite stale lines in `BOARD.md`, keep it < 8 KB, commit + push. The board IS your checkpoint until the
DB-backed rotation daemon (Build 3) exists. Persist typed state (phase, tasks, owners, gates) — never the transcript.
## Fleet
- Adversarial planners: `planner-opus` (robustness), `planner-sol` (pragmatic) — dispatch for task decomposition; reconcile their oppositional decomps.
- Coders/reviewers: dispatch per roster + delivery gates. Comms: `~/.config/mosaic/tools/tmux/agent-send.sh`
(`-L <socket> -s <dst> -S <yourhost>:<yourseat> --class <class>`); always pass `-S`.
- Lead coordinator: Mos (`mos-claude`). Escalate only on the Constitution's escalation triggers.
## Remote control
On first startup, activate remote control for this session (`/remote-control`) so Jason can reach/drive you while
away. If the command is unavailable in this runtime, report it to Mos and continue — it is not a blocker.
+98
View File
@@ -0,0 +1,98 @@
# MACP wiring investigation
**Scope:** `/src/mosaic-stack` inspected at HEAD `b79336a8c11e2a4646a47ff8d295a226e0c71404`; read-only. Existing dirty/untracked state was not touched.
## Verdict
**(c) STRANDED.** `packages/macp` is exported, unit-tested, and registered as a CLI command group, but no production dispatch/execution code invokes its credential resolver, gate runner, or event emitter.
A separate MACP-named OpenClaw/orchestrator rail exists, but it redefines task/result types and gate/event logic instead of importing `@mosaicstack/macp`; direct `mosaic yolo|claude|codex|opencode|pi` also bypasses it.
## 1. Production call sites vs tests
### Production references to `@mosaicstack/macp`
| Surface | Evidence | Actual use |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Unified CLI | `packages/mosaic/src/cli.ts:8,385` | Imports and registers `registerMacpCommand`; no task/gate/event execution. |
| Forge | `packages/forge/src/types.ts:1,17,68,79` | **Type-only** imports of `GateEntry` and `TaskResult`. Pipeline calls an injected abstract executor at `packages/forge/src/pipeline-runner.ts:189-190,299-300`, not MACP. |
| Mosaic package metadata | `packages/mosaic/package.json:36`; `packages/mosaic/src/runtime/update-checker.ts:172` | Dependency/update inventory only. |
| Agent | No match under production `packages/agent/src/**` | No MACP import/call. |
| Coord | No match under production `packages/coord/src/**`; dependency list is only `@mosaicstack/types` at `packages/coord/package.json:25-27` | No MACP import/call. |
| Plugins | No `@mosaicstack/macp` import under `plugins/**` | No package use; the MACP-named plugin is an independent implementation (below). |
**Repository-wide production call-site search result:** excluding `packages/macp/**`, tests, worktrees, and build output, there are **zero** calls to `runGate`, `runGates`, `emitEvent`, `appendEvent`, or `resolveCredentials`.
### `packages/macp` implementation is internally connected only
- Public exports: `packages/macp/src/index.ts:1-48` exports Task/GateEntry/MACPEvent/TaskResult, credential resolution, `runGate(s)`, risk-floor, and event emission.
- Gate runner calls its own event emitter: `packages/macp/src/gate-runner.ts:187-236`.
- Event persistence implementation appends NDJSON to a caller-supplied path: `packages/macp/src/event-emitter.ts:11-27`.
- There is **no exported programmatic `submit` implementation** in `packages/macp/src/index.ts:1-48`; only the CLI placeholder named `submit`.
### Test-only invocations
- Gate runner: `packages/macp/__tests__/gate-runner.test.ts:96-242` invokes `runGate/runGates`.
- Event ledger: `packages/macp/__tests__/event-emitter.test.ts:46-133` invokes `appendEvent/emitEvent` against temporary `events.ndjson` files.
- Credential resolver: `packages/macp/__tests__/credential-resolver.test.ts` exercises resolver behavior.
- CLI tests only verify command registration: `packages/macp/src/cli.spec.ts:37-73`; `packages/mosaic/src/cli-smoke.spec.ts:8` imports registration.
## 2. Gate on the live dispatch path
### Direct Mosaic runtime launch bypasses MACP
- Runtime commands dispatch directly to harness launch: `packages/mosaic/src/commands/launch.ts:730-801`.
- Claude/Pi go through the lease broker, then spawn the runtime: `packages/mosaic/src/commands/launch.ts:817-843`.
- Commander wiring sends `mosaic yolo <runtime>` and direct runtime commands to `launchRuntime`: `packages/mosaic/src/commands/launch.ts:1102-1157,1165-1167`.
- None of those ranges imports/calls `@mosaicstack/macp`, `runGates`, or `emitEvent`.
**Result:** a direct `mosaic yolo`, `mosaic claude/codex/opencode/pi`, or underlying exec does not create a typed MACP Task, run the package gate-runner, or append a package MACPEvent.
### Coord bypasses MACP
- Coord reads/updates `docs/TASKS.md`: `packages/coord/src/runner.ts:6,306-386`; parser/writer is `packages/coord/src/tasks-file.ts:326-377`.
- Coord launches a child process directly: `packages/coord/src/runner.ts:397-427`.
- Mission state is its own `.mosaic/orchestrator/mission.json`/`next-task.json`: `packages/coord/src/mission.ts:8-12`; `packages/coord/src/runner.ts:15-16,355-384`.
**Result:** Coord task execution has no MACP Task validation, package gate runner, or event append.
### Forge bypasses MACP execution
- Forge defines its own `ForgeTask` and abstract `TaskExecutor`: `packages/forge/src/types.ts:48-80`.
- The production CLI injects a **stub executor** that immediately reports completion with empty gates: `packages/forge/src/cli.ts:13-31,167,185`.
**Result:** even `mosaic forge run` does not execute MACP gates or persist MACP events.
### Separate MACP-named rail is not `packages/macp`
- OpenClaw plugin registers an ACP backend named `macp`: `plugins/macp/src/index.ts:1-18,72-102`.
- It locally redefines `OrchestratorTask`, `TaskResult`, and gate-result shapes instead of importing package types: `plugins/macp/src/macp-runtime.ts:43-77`.
- It appends directly to `.mosaic/orchestrator/tasks.json`, triggers an external controller, and polls `results/<task>.json`: `plugins/macp/src/macp-runtime.ts:290-329,437-483`.
- The controller independently implements `append_event`, `emit_event`, shell execution, gate execution, and results: `packages/mosaic/framework/tools/orchestrator-matrix/controller/mosaic_orchestrator.py:29-91,126-276`.
- Its gate loop runs raw string gates after worker success: `mosaic_orchestrator.py:213-235`; it does not support the package's structured `GateEntry`/AI-review behavior.
- Current checkout disables this controller: `.mosaic/orchestrator/config.json:2` (`"enabled": false`).
- Plugin references `tools/macp/dispatcher/pi_runner.ts` at `plugins/macp/src/macp-runtime.ts:85-91`, but `tools/macp/` does not exist in this checkout.
**Result:** there is a parallel, optionally enabled MACP-shaped rail, not package integration. It cannot make `packages/macp` the enforced path.
## 3. Event ledger status
- Package persistence exists only as a library primitive: `packages/macp/src/event-emitter.ts:11-27` appends JSON lines to an arbitrary `eventsPath`.
- Package event emission is reached only from package `runGates`: `packages/macp/src/gate-runner.ts:204-236`.
- No production caller invokes package `runGates/emitEvent/appendEvent`; therefore no runtime destination path is configured for the package ledger.
- Test-only ledgers use temp paths: `packages/macp/__tests__/event-emitter.test.ts:35-133`; gate tests use temp `events.ndjson`: `packages/macp/__tests__/gate-runner.test.ts:171-242`.
- The separate Python controller writes `.mosaic/orchestrator/events.ndjson`: `mosaic_orchestrator.py:129-133,159-161,219-235`; the Mosaic Framework plugin only **reads** that file for context at `plugins/mosaic-framework/src/index.ts:279-316,430-438`.
- In this checkout, `.mosaic/orchestrator/events.ndjson` is absent and the controller is disabled (`.mosaic/orchestrator/config.json:2`).
**Conclusion:** `MACPEvent` from `packages/macp` is defined/tested but not emitted or persisted by live production call sites. The similarly shaped Python ledger is a duplicate island.
## 4. Coord link
- `packages/coord` has no `@mosaicstack/macp` dependency/import: `packages/coord/package.json:25-27`; no matches in `packages/coord/src/**`.
- Coord's task model is Markdown `docs/TASKS.md` plus mission/session JSON: `packages/coord/src/tasks-file.ts:1-10,257-377`; `packages/coord/src/mission.ts:8-12`; `packages/coord/src/runner.ts:306-427`.
- It does not consume `.mosaic/orchestrator/events.ndjson`, MACP Task, MACPEvent, GateEntry, or TaskResult.
**Conclusion:** Coord and `packages/macp` are disconnected islands.
## Shortest wiring gap
**Single integration point:** replace the duplicated execution/gate/event block in `mosaic_orchestrator.py::run_single_task` (`:126-276`) with one production Node `TaskExecutor` backed by `@mosaicstack/macp` (typed Task validation + `resolveCredentials` + `runGates` + `emitEvent`), and make Coord/Forge/OpenClaw submit through that executor. This queue/controller choke point is where `yolo|acp|exec` worker outcomes can be gated and journaled before completion is recorded.
+174
View File
@@ -0,0 +1,174 @@
# Mosaic Stack Remediation — Mission Charter
**Owner:** project orchestrator `mos-remediation` (Claude, launched in `/src/mosaic-stack`).
**Origin:** 2026-07-16..31 fleet lifecycle postmortem. **Status:** EXECUTING (planning complete; RM-01 in flight).
**HOLD lifted** for this workstream by Jason, 2026-07-31 — "begin full mosaic fleet operation on this."
## Goal
Convert the 15 accepted postmortem remediation proposals into a working, **dogfooded** implementation.
**North star:** anything with a deterministic right answer moves OUT of the LLM into a deterministic
gate/program; the LLM handles only genuine judgment.
### First-class principle — observe the property, not the exit code
<!-- GATE-CLAIM:OBSERVE-PROPERTY -->
> **No write is done until the requested PROPERTY is observed. A success exit code is not evidence.**
>
> **Success output is designed to be believed.** That is the whole reason the inert-gate class exists
> and why P-WRAPPER-001's tri-state (`verified` / `written-unverified` / `failed`) is not optional. The
> failure is not carelessness — a green is _engineered_ to be trusted, so trusting it is the default
> behaviour of a competent operator, not a lapse.
>
> Promoted to the charter by Mos (2026-07-31) after the orchestrator committed this exact error: a
> `--draft` flag was silently dropped by a wrapper fallback that still exited 0, and the PR was reported
> as a draft on the strength of the exit code rather than an observed `draft: true` (D-12). Twelve
> failure instances were banked in that session; **three of them were the orchestrator's own.** That
> ratio is the point — the mechanism must catch the mechanic too, or it is not a mechanism.
>
> Operationally: after any write, read back the property you required. Applies to gates, wrappers, PR
> flags, commit authorship, file installs, and message delivery alike.
### First-class principle — pre-registration prevents retrofitting, and nothing else
<!-- GATE-CLAIM:PREREGISTRATION-BOUNDARY -->
> **A pre-registered check set can fail in three distinct ways:**
>
> | mode | the set is… | found as |
> | --------------------------- | ------------------------------------------------- | -------- |
> | **WRONG** | a check does not test what it claims | D-8 |
> | **INCOMPLETE** | green while a criterion's requirement is untested | D-17 |
> | **INTERNALLY INCONSISTENT** | two criteria cannot both hold | D-18 |
>
> **Pre-registration protects against exactly one thing: retrofitting a check to fit the implementation
> it is supposed to judge.** It confers neither correctness, nor coverage, nor consistency. "We
> pre-registered the checks" has been treated as though it settled the question — it settles one of
> three.
>
> Promoted to the charter by Mos (2026-07-31). All three modes were found on this mission's own **first
> delivery**, by the machinery applied to its own work — not by inspection, and not by looking for them.
>
> **Enforceable form — RM-02's four clauses.** The registry must establish that: (1) each check is
> **right** — proven red for its own stated reason before its green counts; (2) the set **covers** —
> every criterion bound to a case that actually exercises it; (3) no two criteria **conflict** —
> mutual unsatisfiability is a registry defect discoverable by construction; (4) when a criterion's
> meaning changes, the registry **retains original text, restatement, and reason**, so evolution stays
> auditable. A criterion with no case that can fail for its own reason is unregistered in substance,
> however it reads in the manifest.
### Corollary — never ship an integrity claim dressed as a property
<!-- GATE-CLAIM:ARTIFACT-INTEGRITY-BOUNDARY -->
> A verification artifact that can be forged by whoever it is meant to catch verifies nothing. If a
> manifest, marker, ledger, or receipt is writable by the same actor whose behaviour it certifies, it
> **certifies the attack.** Such an artifact must sit inside the integrity envelope it belongs to,
> publish atomically, and carry a **tamper negative-control observed red** — otherwise its integrity is
> a _claim_, not a _property_.
>
> **If it cannot be made tamper-evident, say so and reconsider the approach.** Laundering foreign
> content as certified is the only unacceptable outcome; an honest "this cannot be verified" is always
> available and always preferable.
### First-class principle — when a property cannot exist at the layer it was specified
<!-- GATE-CLAIM:IMPOSSIBLE-LAYER-BOUNDARY -->
> Some required properties are **impossible at the layer that asked for them** — not hard, impossible.
> A local check cannot defend against an actor who can rewrite the check itself. When that happens,
> there are exactly three honest moves, and all three are mandatory:
>
> 1. **Implement what the layer _can_ guarantee.** Partial protection against the class it was actually
> born from is worth having.
> 2. **State the boundary precisely, in BOTH directions.** What it does _not_ defend, **and** beside it
> what it _does_. A reader who sees only the negative dismisses the check as worthless; one who sees
> only the positive over-trusts it. **Both together is the honest artifact** — either alone misleads.
> 3. **Record where the real guarantee will come from — as a TRACKED DEPENDENCY, not prose.** It must
> name a task that someone must close. _A documented gap with no owner becomes a permanent gap that
> reads as intentional._
>
> **A written-down gap is acceptable engineering. An implied-fixed gap is this mission's core failure in
> a new costume** — a verification artifact that verifies nothing, with a green to prove it.
>
> Promoted to the charter by Mos (2026-07-31) from D-19. Origin: the RM-01 symlink manifest could not be
> made tamper-evident against a same-UID actor (CWE-345), because the manifest and its marker share one
> writable tree. The implementing seat **escalated rather than relabelling self-authentication as
> tamper-resistance** — the corollary above firing on its first real adversarial test, on the cheapest
> seat in the loop. Residual risk bound to **RM-59** (`depends_on: RM-12, RM-21, RM-25`), where the
> choke-point executor and spine verify from _outside_ the worktree's authority.
## Decision record (authoritative, immutable)
- **15/15 proposals decided: 13 accept, 2 modify (P-AUTHORITY-001, P-INBOX-001), 0 reject.**
- Site + `annotations.json`: `jarvis-brain/docs/postmortem-spec/site/` (committed, origin/main).
- Discussion checkpoint (rich rationale per proposal): `jarvis-brain/docs/scratchpads/postmortem/REMEDIATION-DISCUSSION-STATE.md`.
- Postmortem report: mosaicstack/stack PR #107 (merged 88f4ee04).
- MACP wiring scout (verdict c=STRANDED): [`MACP-WIRING-SCOUT.md`](./MACP-WIRING-SCOUT.md) (copied into this dir; TODO discharged). Its findings are sound; its _recommended wire-in point_ is superseded by DECISION-1.
## The plan — 15 proposals collapse to 4 builds + hygiene
| Build | Absorbs | What it is |
| ------------------------------------------------------------ | --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **1. One choke-point service** (mechanical enforcer) | MISSION, STATE, AUDIT, WRAPPER, QUEUE | Deterministic program every task/data mutation flows through. **Wire the stranded `@mosaicstack/macp`** — typed tasks, gate-runner, event ledger, credential binding, tri-state write outcomes. ⚠ **Target CORRECTED 2026-07-31 (DECISION-1, Mos):** a new production Node `TaskExecutor` on the **live** dispatch path (`packages/mosaic` launch + `packages/coord`), which Coord/Forge/live-dispatch submit through. **NOT** `mosaic_orchestrator.py::run_single_task` — that controller is `"enabled": false` and references a dispatcher absent from this checkout; wiring it would strand the executor, reproducing this mission's own disease. The Python rail is **deleted**, not ported. Both planners reached this independently. |
| **2. One durable spine + hot path** | (storage under everything) | **PG system-of-record + Redis hot queue** (transactional-outbox). Mission/tasks/state-claims/audit-ledger/comms-inbox all land here. |
| **3. Rotation lifecycle** (finish the Mission Control Plane) | LIFECYCLE, CONTRACT, GUIDE, RECOVERY | Coordinator daemon: contract-hash binding, compaction-detected → rotate-not-compact, checkpoint→fresh-session→rehydrate, broker-independent recovery. Deterministic, not an LLM. Reuse `packages/coord`; existing PRD at `docs/mission-control/`. |
| **4. Comms service** | AUTHORITY, INBOX (+ versioning roadmap) | Envelope (comms/v1) → sole-path service → PG/Redis → pluggable adapters (tmux→Matrix/Discord/Slack/Telegram). Version the protocol, not participants. |
| **+ Hygiene & proof** | FLEET, WORKFLOW, CONFORMANCE | One roster-owned socket/host + stale GC; allowlist auto-sync; the conformance harness that fault-injects the failure classes and proves builds 14 hold. |
## The finding that sets the cost
**Built-but-unwired disease.** `@mosaicstack/macp` is stranded (nothing calls it); `packages/coord` primitives
exist; the Mission Control PRD exists; PG + Redis already run in-stack. Three duplicate MACP islands, an
orphaned context loader, a fail-open bypass. **Work = wire + consolidate + retire, NOT greenfield. "Finish, don't re-spec."**
## Sequencing (skeleton — adversarial decomposition refines this)
1. **Spine + choke-point service** (builds 1+2) — foundation; unlocks MISSION/STATE/AUDIT/WRAPPER/QUEUE at one integration point.
(Per DECISION-1, a P0 phase of provable-gate + activation work precedes this; see `TASKS.md` §3.)
2. **Rotation daemon** (build 3) on that spine — the drift fix proper.
3. **Comms service** (build 4) — envelope → service → PG/Redis → adapters; retire direct-tmux.
4. **Hygiene + conformance** (build 5) — fleet convergence, allowlist sync, dogfood harness.
- **Cross-cutting retirements:** flat-file orchestration tracking (hard cutover to DB), the 3 duplicate MACP islands, the silent `MOSAIC BYPASS`.
## Standing directives (Jason, 2026-07-31)
- **Dogfooding:** validate EACH fix against the live fleet failure that motivated it. Seed acceptance tests:
Pi brick (RECOVERY), scout-bounce (INBOX/FLEET), gate-6 inert + #1019 recursion (QUEUE), identity drift
(WRAPPER), auto-sync sweep (WORKFLOW), #1018 stale-consumed (INBOX). The fleet is its own test bed.
- **Orchestration tracking → DB**, hard cutover ("rip off the bandaid"), NO flat-file interim. jarvis-brain
PDA flat-files untouched. Current flat-file tracking runs as-is/unhardened until DB tracking is real, then one clean replace.
-**QUALIFIED 2026-07-31 (DECISION-2, Mos):** the DB spine **must NOT be a single-point hard-stop.**
A broker-independent / degraded mode **and** a rehearsed rollback artifact are **design requirements**
(P-RECOVERY-001), binding now on RM-12, RM-13, RM-23, RM-36 and RM-53. This **supersedes** the earlier
orchestrator recommendation to pre-commit "no DB ⇒ the fleet stops" — that answer is _not_ on record.
Only the specific availability _target_ remains open, queued for Jason; it does **not** block current work.
## The 15 decisions (one-line; full rationale in the checkpoint)
1. **P-ACTIVATION-001** accept — transactional CLI+hooks+broker+version release; block launch on skew, fail-SAFE.
2. **P-AUTHORITY-001** MODIFY — structured authenticated inbox; envelope carries comms-PROTOCOL version; version the protocol not participants; N-version window.
3. **P-LIFECYCLE-001** accept — rotation not recursive compaction; pre-empt at token threshold; enforcer = deterministic coordinator; = finish Mission Control Plane.
4. **P-MISSION-001** accept — bind lanes to mission+task ledger; convention exists, ENFORCEMENT is the gap; mission+tasks → DB spine (hard cutover).
5. **P-QUEUE-001** accept — repair queue transport + exit-asserting non-null-case tests (gate-6 was INERT fleet-wide; #1019 fix recursed the same bug).
6. **P-STATE-001** accept — typed claims (source/confidence/TTL) not prose blob; MACP typed record; integrity fail-closed HMAC; don't fork a 4th island.
7. **P-AUDIT-001** accept — MACPEvent lifecycle ledger; EXTEND enum to lifecycle events; runtime-neutral (executor-emitted); retire duplicate Python ledger.
8. **P-WRAPPER-001** accept — identity derives from seat name + survives respawn; tri-state write outcomes MANDATORY; name safe target metadata.
9. **P-CONTRACT-001** accept — bind session to contract hash; re-anchor on policy-change OR compaction-detected; stale generation loses authority MECHANICALLY.
10. **P-INBOX-001** MODIFY — sole-path comms SERVICE; PG durable SoR + Redis hot queue (outbox, reconciliation sweeper); pluggable adapters; protocol-first, PG-first-then-Redis.
11. **P-RECOVERY-001** accept — broker-independent bootstrap recovery; honest capability labeling; break-glass LOUD+AUDITED+TEMPORARY not silent permanent bypass.
12. **P-GUIDE-001** accept — delete `/compact and continue` from orchestrator path (keep for ephemeral); removal = substitution (wire rotation trigger).
13. **P-FLEET-001** accept — one roster-owned socket/host; quarantine unmanaged; stale-session GC; prerequisite for INBOX identity-addressing.
14. **P-WORKFLOW-001** accept — auto-sync ALLOWLIST not denylist; worktree/lease isolation for agent docs/source; DB-tracking obviates the flat-file-sweep criterion.
15. **P-CONFORMANCE-001** accept — fleet lifecycle harness on REAL runtime artifacts + fault injection; the 100-rotations-lossless bar is a test; target the DB substrate.
## Fleet operating model
- **Project orchestrator** `mos-remediation` (this seat) owns the mission; coordinates under Mos (lead).
- **Adversarial task decomposition:** `planner-opus` (robustness) + `planner-sol` (pragmatic) each decompose
the plan independently; orchestrator reconciles into `TASKS.md`/DB tasks. Oppositional by design.
- **Delivery gates (non-negotiable):** author≠reviewer, PRE-REGISTERED diff-blind acceptance checks committed
before reading the diff, CI terminal-green, completion = merged PR + closed issue. rev-974 = mosaicstack reviewer.
- **Compaction survival:** see `KICKSTART.md` in this dir — the resume procedure. Persist typed state, not transcript.
+894
View File
@@ -0,0 +1,894 @@
# Remediation Backlog — Reconciled Execution Plan
**Owner:** `mos-remediation` (sole writer). Workers read; they never modify this file.
**Sources:** [`DECOMP-OPUS.md`](./DECOMP-OPUS.md) (robustness, 38 tasks / 8 dissents) and
[`DECOMP-SOL.md`](./DECOMP-SOL.md) (pragmatic, 25 tasks / 10 defers / 7 dissents), produced
**independently** — neither planner read the other. Charter: [`MISSION.md`](./MISSION.md).
**Status:** EXECUTING — all three blocking decisions RULED by Mos on 2026-07-31 (§5). **RM-01 is
dispatched.** RM-03 is held pending Jason's disposition of PR #1023; nothing else is blocked.
> **Provenance of the inputs (both clean).** `planner-opus` ran in a fresh session throughout.
> `planner-sol` initially began work at 64.3% dirty context despite a brief instructing it to reset;
> that run was **interrupted and discarded before it produced any output**, the seat was reset
> out-of-band to 0.0%, and the brief was re-dispatched. `DECOMP-SOL.md` is the product of the clean
> run only (it peaked at ~26% context). Both decompositions are therefore clean-context artifacts and
> are weighted equally here. The discarded dirty run is banked as dogfood seed D-4 and as task RM-58 —
> the failure it demonstrates is that _asking_ an agent to reset is not enforcement.
---
## 1. What the two planners agreed on without collusion
Independent convergence is the strongest signal available here, because neither planner could see the
other's file. Where both arrived at the same conclusion from opposite biases, I treat it as settled.
| # | Convergent finding | OPUS | SOL |
| --- | --------------------------------------------------------------------------------------------------------------------- | ------------------- | -------------- |
| C1 | **The charter's wire-in point is wrong.** Do NOT wire the choke point into `mosaic_orchestrator.py::run_single_task`. | D2 (headline) | Dissent 1 |
| C2 | P0 hygiene/gate work must precede the spine, not follow it. | D1, phase P0 | G0, SOL-01/02 |
| C3 | No new deployable microservice; the executor is a library + the coord daemon. | implicit throughout | Dissent 3 |
| C4 | Comms adapters beyond tmux are out of scope for this mission. | D7 | DEFER 4/5/6 |
| C5 | The "100 rotations lossless" bar is a late conformance gate, not an early tax. | D4 | Dissent 7 |
| C6 | Redis is a derived hot path, never an authority; PG commits first. | R-013, R-054 | SOL-11, SOL-21 |
| C7 | Reuse `packages/coord`; do NOT revive the untracked `apps/coordinator` residue. | R-042 | SOL-15 AC5 |
**C1 is the single most consequential output of this exercise.** The charter (`MISSION.md`) and my
kickoff instruction both name `mosaic_orchestrator.py::run_single_task:126-276` as the integration
point. Both planners independently rejected it on the same evidence: that controller is
`"enabled": false` (`.mosaic/orchestrator/config.json:2`) and references a dispatcher path
(`tools/macp/dispatcher/pi_runner.ts`) that does not exist in this checkout. Wiring the new choke
point into a disabled rail produces **a stranded executor — the identical built-but-unwired disease,
one layer up, that would look "done" in a PR.** The live paths are
`packages/mosaic/src/commands/launch.ts` and `packages/coord/src/runner.ts`.
This contradicted the charter and was escalated as DECISION-1 — **now RULED in the planners' favour by
Mos (§5)**. The corrected target is a new production Node `TaskExecutor` on the live dispatch path
(`packages/mosaic` launch + `packages/coord`) that Coord/Forge/live dispatch submit through; the
Python rail is deleted, not ported.
---
## 1a. ★ KEYSTONE DOGFOOD CASE — an inert gate that erased its own evidence
**A merged commit shipped past `pnpm format:check` — and then the evidence quietly erased itself.**
Verified chain (blob-level, under the repo's own prettier config, at the file's real path):
| commit | state of `packages/mosaic/framework/tools/orchestrator/README.md` |
| ------------------------------------------------------------------- | ----------------------------------------------------------------------------- |
| `b79336a8`**merged PR #868** | blob `3ee7f104`**FAILS** `pnpm format:check` |
| `48fd1df2` — merged PR #872 (unrelated: ci-queue-wait 404 handling) | blob `3d3bb132` — passes; incidentally reformatted by that PR's `lint-staged` |
| current `origin/main` (`06e0d403`) | passes — **the gate now looks green** |
So: PR #868 merged a file that fails a required gate ⇒ **the CI format gate did not block it.** The
gate was inert for that merge. Then an unrelated later PR's pre-commit hook reformatted the file as a
side effect, so `main` went green again **without anyone ever learning the gate had failed to fire.**
> **Correction on record:** my first report to Mos said "format:check is RED on main _now_." That was
> true of the `main` my checkout was pinned to (`b79336a8`) and is **no longer true of current `main`**,
> which advanced mid-session. The inert-gate finding itself is unchanged and verified; only its
> present-tense framing was wrong. The hygiene PR therefore carries the `.prettierignore` fix only —
> the README needs no fix today.
### Third live instance, same class — the queue guard, hit by this orchestrator
Running the **mandated** pre-push guard during TASK-0:
```
$ ~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push
[ci-queue-wait] platform=gitea purpose=push branch=main sha=06e0d403…
[ci-queue-wait] state=unknown purpose=push branch=main
$ echo $? → 0
```
**Two distinct defects in one tool**, both feeding RM-03:
1. **Wrong exit**`state=unknown``exit 0`. The defect at `ci-queue-wait.sh:282-288` that OPUS
documented and that PR #1023 is parked on. A required gate returned PASS on an indeterminate result.
2. **Wrong branch** — it evaluated `branch=main`, not the branch actually being pushed. Even a
correctly-exiting guard would have been answering the wrong question.
**Standing doctrine (Mos):** until RM-03 lands, a green from this guard carries **zero information**
and must not be cited as merge evidence. Rely on reviewer clearance + real CI.
Three independent live instances in a single session — format gate, agent context reset, queue guard —
is the class confirmed, not anecdote.
### D-20 — the orchestrator's own documentation overclaimed, and a reviewer disproved it empirically
`rev-974` blocked PR #1027 a second time. **The defect was not in the code — it was in this file**, at
D-18's entry, written by the orchestrator.
Two faults, both mine:
1. **D-18's AC2 restatement omitted the scope clause** that D-19 later established as mandatory
("within an accidental/independent-mutation threat model").
2. **D-18 asserted that the tampered-manifest control turns integrity "from a claim into a property."**
It does not, and _cannot_. That sentence was written **before** D-19 proved the property impossible
at this layer, and was never revised when D-19 landed.
**The reviewer did not merely read it — it disproved it.** It performed a **same-UID consistent
manifest + marker rewrite**, and **preflight passed**. My documented claim was falsified by experiment.
Code, README, scratchpad and PR body all stated both threat-model directions correctly; **this file was
the only place still overclaiming.**
**This is two banked findings firing on the orchestrator at once:**
- **The integrity-claim corollary** — I wrote an integrity _claim_ in the voice of an integrity
_property_, in the very document that defines the rule against doing so.
- **D-14 (propagation)** — D-19 superseded D-18's assertion. I propagated the consequence into the
charter and the delivery conditions, but **not back into D-18 itself.** A ruling that fails to
propagate _backwards_ into the finding it supersedes is the same defect as one that fails to
propagate forwards, and I did not audit for that direction.
**Corrected in place**, with the original wording quoted and the empirical disproof recorded, rather
than silently rewritten — the same standard demanded of any restated criterion.
**Requirement on RM-02 (fifth clause).** Documentation asserting a _security or integrity_ property is
itself a claim requiring a negative control. Where a document states "X is guaranteed", the registry
must hold a case that **fails if X is not guaranteed** — and that case must have been observed red.
**Prose is not exempt from the mission's own evidentiary standard**, and prose in the _governing_
document least of all: it is the artifact most likely to be quoted as authority long after the code has
moved on.
**Reviewer credit.** rev-974 was briefed that its highest-priority check was "confirm the PR claims no
more than it can deliver, and a softened or omitted boundary is a finding even though the code works."
It applied that instruction **to the orchestrator's own governing document** and produced an experiment
to settle it. That is the review standard this mission is trying to make ordinary.
### D-19 — an integrity property that cannot exist at the layer it was specified
Implementing D-18's manifest, the seat + a Codex security review reached **CWE-345**: the symlink
manifest and the source-hash marker both live in the **same same-UID writable generated tree**, so an
actor with that UID can plant a rogue link, regenerate _both_, retain the fingerprint, and pass. **No
local cryptographic construction fixes self-authentication** without a key outside that actor's
authority; relocating the marker changes the path, not the authority.
The seat **escalated rather than describing self-authentication as tamper-resistant** — the explicit
failure mode the charter corollary demands. That is the corollary working, on its first real test.
**Ruling — Option A: scope AC2 to accidental / independent / stale mutation; retain the design.**
Rationale, recorded so it can be challenged:
1. **The undefendable boundary is not the weak link.** An actor with same-UID write can already edit the
source, the tests, `scripts/preflight.mjs` itself, and `.husky/*`. If they have that, _nothing_ in the
local checkout is trustworthy — hardening the manifest buys no real security while **implying
protection that does not exist**, which is worse than the gap.
2. **What AC2 is actually for.** These checks exist because a five-month-stale `.next` produced 19
phantom `TS2307` errors indistinguishable from real ones (**D-5**). That is staleness, drift and
foreign residue — and against that class the design demonstrably works.
3. **A real trust anchor arrives later, from this mission's own architecture.** An anchor must live
outside the actor's authority; for a fleet running as one user that means a separate service —
precisely the **choke-point executor + PG spine** of Builds 12, which verify outside the worktree's
authority. Hand-rolling key distribution for a local preflight now would duplicate that work badly.
4. Option C (structural policy, no manifest) is strictly worse — it cannot detect a **removed** expected link.
**Option A is acceptable only with honest labelling**, or it becomes the disease it is meant to cure.
Conditions (last two added/sharpened by Mos):
- Threat model stated verbatim in the code **and** the PR; the words _tamper-proof / tamper-evident /
secure_ **barred** from that context; the scope carried in AC2's restatement; every control kept
RED-first including manifest-only tamper.
- **State the boundary in BOTH directions.** Not only what it does _not_ defend (same-UID write; no
local construction can) but, beside it, what it **does** defend: accidental / independent / stale /
foreign-residue mutation — the **D-5** class it was born from (the five-month `.next` and its 19
phantom `TS2307`s). _A reader who sees only the negative dismisses the check as worthless; one who
sees only the positive over-trusts it. Both together is the honest artifact._
- **The residual risk is a HARD TRACKED DEPENDENCY EDGE, not a comment.** It is **RM-59**, owned by the
choke-point executor + spine work (`depends_on: RM-12, RM-21, RM-25`), and the AC2 scope note must
cite that id. _"Record where the real guarantee comes from" only holds if the record is a live
dependency someone must close._ **A documented gap with no owner becomes a permanent gap that reads
as intentional.**
**The generalizable rule.** When a required property **cannot exist at the layer where it was
specified**, the honest moves are: implement what the layer _can_ guarantee, **state the boundary
precisely**, and record where the real guarantee will come from. **A known gap that is written down is
acceptable; a gap that is implied fixed is not.** Silence here would have shipped a verification
artifact that verifies nothing — with a green to prove it.
### D-18 — two pre-registered criteria were mutually unsatisfiable, discoverable only at implementation
Implementing D-17's fix surfaced a conflict **between** pre-registered criteria:
- **AC2** (as written) — reject symlinked generated state.
- **AC4** — the canonical `pnpm -w build` succeeds and leaves no residue.
Verified independently rather than taken on report: `apps/web/next.config.ts:4` sets
`output: 'standalone'`, and the built tree contains **42 legitimate pnpm dependency symlinks** under
`.next/standalone/node_modules`. A blanket descendant-symlink rejection makes the canonical build fail
its own preflight with exit 43. **AC2 read literally is unsatisfiable alongside AC4 under this
configuration**, and nothing short of building the tree would have revealed it.
**Third distinct failure mode of a pre-registered check set**, completing the chain:
| finding | a pre-registered check set can be… |
| ------- | ------------------------------------------------------------------ |
| D-8 | **wrong** — a check that does not test what it claims |
| D-17 | **incomplete** — green while a criterion's requirement is untested |
| D-18 | **internally inconsistent** — two criteria that cannot both hold |
The implementing seat escalated instead of silently picking a winner. That matters: **quietly resolving
a conflict between pre-registered criteria destroys the point of pre-registering them** — the registration
exists so that changes of meaning are auditable rather than absorbed.
**Resolution (orchestrator ruling).** Approved a **build-certified symlink manifest**: `.next` itself is
still rejected as a symlink; descendants are rejected unless _exactly_ certified by a manifest the build
publishes atomically. Strictly **stronger** than blanket rejection — it also catches a **retargeted**
symlink, which blanket rejection cannot distinguish from a legitimate one.
**AC2 restated (recorded, not absorbed).** _Generated state must reject `.next` itself being a symlink
or non-directory, and must reject any descendant symlink not exactly certified by the build manifest —
added, removed, retargeted, or manifest-only-tampered all fail with exit 43 — **within an accidental /
independent-mutation threat model.**_
> ⚠ **This entry is superseded in part by [D-19](#d-19). Do not read D-18 standalone.** The scope clause
> above is load-bearing: the design **cannot** defend against a same-UID actor, which can rewrite the
> manifest and the marker consistently (CWE-345). D-18 was written **before** that impossibility was
> established.
**Hardening required before this counts.** The manifest is itself generated state, so **a manifest
writable by whoever plants a rogue symlink certifies the attack** — that is the one way this design
fails. It must sit inside the same ownership/fingerprint envelope, published atomically via the existing
marker mechanism, with negative controls **observed red first** for: added, removed, retargeted,
**manifest-only-tampered**, plus a positive control that the canonical build passes.
> ⚠ **CORRECTED (D-20).** This paragraph originally ended: _"without it, integrity is a claim rather
> than a property."_ **That overclaimed**, by implying the control makes integrity a _property_. It does
> not, and cannot. The manifest-only-tamper control detects **independent** mutation of the manifest;
> it confers **no authenticity** against an actor who rewrites manifest _and_ marker together.
> `rev-974` disproved the original wording empirically — a same-UID consistent manifest+marker rewrite
> **passed preflight**. Integrity here remains a scoped **drift-detection** property, never an
> authenticity one. See D-19 and the charter principle on properties that cannot exist at their
> specified layer.
**Requirement on RM-02 (fourth clause).** The registry must detect **conflicts between registered
criteria**, not only wrongness and coverage. Two criteria that cannot simultaneously hold is a registry
defect discoverable by construction — and when a criterion is restated, the registry must retain the
original text, the restatement, and the reason, so the evolution stays auditable.
### D-17 — a pre-registered criterion passed a green suite without being satisfied
`rev-974` returned **CHANGES REQUESTED** on PR #1027 with one blocking finding, and it is the sharpest
instance of the session's theme because it occurred **inside our own verification machinery**.
**AC2** was pre-registered before any code was written, and explicitly required that **symlinked
generated state be rejected**. The implementation does not do it:
```sh
ln -s /etc/hosts apps/web/.next/reviewer-symlink
pnpm preflight # → "checkout preflight passed", exit 0
# → required: generated-state exit 43
```
The acceptance suite was **21/21 green** throughout. Confirmed independently rather than relayed:
`scripts/preflight.mjs:82-92` rejects symlinks on the **source** path; `:28` merely _skips_ symlinked
directories rather than rejecting them; and the **generated-state** path at `:141-163` `lstat`s and
checks `uid` (ownership) but **never** calls `isSymbolicLink()`. The suite's only symlink cases
(`preflight.test.mjs:59`, `:115`) cover the turbo binary and a _source_ file. No generated-state case
exists anywhere.
**So: criterion pre-registered, suite green, requirement unmet.** Nobody was careless — the coverage gap
is _invisible from a green_, which is the entire problem.
**This sharpens D-8 rather than repeating it.** D-8 established that pre-registration does not confer
_correctness_ (a check can be wrong when written). D-17 establishes the adjacent failure:
**pre-registration does not confer _coverage_** — a suite can be green, and every registered criterion
can appear satisfied, while a criterion's actual requirement is untested. The two together mean a
registry of checks needs **two** properties, not one: each check must be _right_, and the set must
_actually exercise_ what it claims.
**Requirement on RM-02 (third clause).** The registry must bind each acceptance criterion to the
**specific case that exercises it**, and prove that case red before trusting its green. A criterion with
no case that can fail for _that criterion's stated reason_ is unregistered in substance however it
appears in the manifest. This is mutation testing pointed at the **criterion-to-case mapping**, not
merely at the gate.
**Credit where due:** the reviewer also declined to re-run AC8, stating plainly that the PR carried it
forward with no runnable command rather than silently substituting a different boundary test. That is
the D-8 clause working a second time, in the same review that produced D-17.
### D-16 — the local test gate and the CI test gate disagree by environment
Mos flagged a shape worth chasing: if `pnpm test` exits non-zero on a _pre-existing_ guard, then either
`main` is red and merges step around it (the #868 shape again), or CI does not run that path. **Both
branches turned out wrong, and the truth is a third thing.** Established by running it, not by asking:
CI runs **exactly** `pnpm test` (`.woodpecker/ci.yml`, `test` step) — the same command. So the path _is_
exercised. Yet:
| environment | result |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CI container | `test` step **green** (#2158, #2167) |
| this host, clean worktree | **exit 97**`WAKE-ASSERT INIT ABORT: BASH_LINENO convention violated on bash 5.2.15(1)-release … expected [3 4], probe reported [3 5] (#973)`, after `PASS=18 FAIL=0` |
| this host, main checkout | **exit 1** — a _different_, second defect (below) |
The guard is **environment-dependent**: it aborts on this host's bash and not in CI's container. `git
diff origin/main...` confirms PR #1027 touches **zero** files under `packages/mosaic`, so the guard is
genuinely pre-existing and unrelated — **f10-coder's report was accurate in every particular**, and
`main` is equally affected on this host.
**So it is not "merges step around a red" — it is worse in one specific way: the local gate and the CI
gate do not agree about what passing means.** No agent on this host can obtain a green `pnpm test` at
all, on any branch, including `main`. A gate an operator cannot run is a gate that only CI enforces,
and a gate only CI enforces cannot be a pre-push gate. This is the hermeticity/portability class
already live as #1007 (PR #1024).
**Second, independent defect found while establishing the above.** In the main checkout the same
package fails differently — exit 1 — because a test **scans the working tree** and asserts on files it
finds, picking up `apps/coordinator/venv/**` (third-party `site-packages`: `pi = math.pi` in `rich`,
`setuptools`, `mypy`). **A test whose result depends on untracked files present in the tree is not
hermetic.** This is the _same_ contamination source that made `pnpm format:check` unpassable (D-1/D-7
hygiene) — one untracked foreign tree silently breaking two independent gates.
**Requirements.** RM-01/RM-04: a gate must produce the same verdict on a developer host and in CI, or
declare loudly that it cannot run here — never diverge silently. RM-02 registers both as cases: the
environment-divergence guard, and a hermeticity control asserting a suite's verdict is unchanged by the
presence of untracked directories. Coordinate with #1007/#1024 rather than opening a third lane.
**Ownership (Mos, 2026-07-31).** The hermeticity fix **is** PR #1024, which sits in **Jason's parked
delivery stack** — so, like #1023, its disposition is Jason's. Marked `SUPERSEDED-PENDING-JASON`
alongside #1023. D-16 strengthens the urgency but does not transfer ownership: **we do not open a third
lane on a parked PR.** The one-line escalation for Jason: _two independent gates
(`format:check`, `pnpm test`) were broken by a single untracked directory, and a third
(`pnpm test`) disagrees between host and CI — non-hermetic gates make every green host-dependent._
**Sharpened statement of the class (Mos).** A pre-push gate an operator _cannot run locally_ is a gate
only CI enforces — so pointing `.husky/pre-push` at it **misrepresents where the gate lives**. Combined
with the shared root cause across two gates, the finding is: **non-hermetic gates make every green
host-dependent.** A gate that only appears to pass depending on which host runs it is this mission's
exact subject, one meta-level up.
**#1027 disposition (Mos):** proceeds on **CI-green**. CI is the authoritative gate; the local exit-97
is a known host-specific guard abort, irrelevant to the merge decision.
### D-15 — token scope is not repository permission (a THIRD capability layer)
`f10-coder` was provisioned with `gitea-mosaicstack-f10-coder.token`, scopes `write:repository` +
`write:issue`, and the mint was verified by "repo access returns 200". It then failed to push:
```
remote: error: User permission denied for writing.
remote: error: pre-receive hook declined
```
Verified objectively rather than inferred (per the charter principle):
| probe | result |
| ------------------------------------------------------ | ------------------------------------------- |
| `GET /repos/mosaicstack/stack/collaborators/f10-coder` | **404** — not a collaborator |
| repo permissions as seen by **its own token** | `admin: false`, `push: false`, `pull: true` |
**Capability has at least three independent layers, and satisfying two proves nothing about the third:**
1. **Token file exists** → raw-API authentication works (D-11b).
2. **`tea` login exists** → tea-dependent wrapper paths work (D-13).
3. **Repository permission granted** (collaborator/team membership) → _writes_ are actually authorised.
A token can carry `write:repository` scope and still be refused, because **scope bounds what a token
may attempt; repository permission decides what the user may do.** They are different systems.
**This is the charter principle failing on the very check meant to confirm capability.** The mint was
validated by an HTTP 200 on a _read_. A 200 proves reachability; it does not prove the property that
was required, which was **write**. Both the provisioner and I accepted it — the same
`written-unverified` treated as `verified` as D-12, one layer up, on a check whose entire purpose was
verification.
**Requirements.** RM-50's pre-dispatch capability check must probe the **effective permission for the
operation intended** — for push authority, assert `permissions.push == true` as that seat, not token
existence and not a 200 on a read. RM-04's registry reconciliation covers all three layers, with a
must-fail control for each. A capability check that cannot fail on a seat lacking write permission is
itself an inert gate.
### D-14 — a ruled decision did not propagate to the authoritative record
DECISION-1 (the corrected choke-point wire-in target) was ruled by the coordinator and applied to
`TASKS.md`. **`MISSION.md` — the charter, the document a cold-starting seat reads first — kept the
superseded target for hours.** It was flagged `CONTESTED` in a board note, then the ruling landed and
nobody edited the charter. A seat resuming from the charter would have read the _rejected_ target as
authoritative and wired the choke point into a disabled rail — the precise failure the ruling existed
to prevent.
Caught by hand, during an unrelated edit. Nothing would have caught it otherwise.
**This is P-MISSION-001 turned on ourselves.** The mission's own thesis is that convention exists and
_enforcement_ is the gap: a decision that lives in a chat ruling and a board note, but not in the
source of truth, has not actually been made — it has been _agreed_. The two are different, and the
difference is exactly what this mission is about.
> ⚠ **AMENDED by D-20 — propagation is BIDIRECTIONAL.** As first written, this requirement was read by
> both the orchestrator and the coordinator as _forward_ propagation only: a ruling reaches the
> documents that state the new rule. **D-20 proved that insufficient.** When D-19 superseded part of
> D-18, the consequence propagated forward into the charter and the delivery conditions but **never
> backward into D-18 itself**, which went on asserting a withdrawn claim — and a reviewer disproved it
> by experiment. **A supersession must update BOTH the documents that render the new rule AND the
> finding it retires, with the retired wording quoted rather than deleted.** Backward propagation is
> the same defect as forward; neither of us audited that direction until it bit.
**Requirement (not merely a fix).** A ruled decision must propagate **mechanically** to the
authoritative record; it must not depend on someone remembering to edit a second file. Concretely, once
mission state is DB-backed (RM-53 / the P-MISSION cutover):
- a decision is a **record**, not prose duplicated across documents;
- documents _render_ decisions rather than restating them, so there is one place to be wrong;
- and where duplication is unavoidable, a check asserts the authoritative record and the derived
document agree — with a must-fail control proving divergence is detected.
Until then, the interim rule: **the same commit that records a ruling updates every document that
states it — and every finding it supersedes.** Interim rules are exactly what the DB cutover exists to replace.
**The rule found a second instance within minutes of being written.** Auditing the charter against all
rulings to date (rather than waiting to be bitten again) surfaced that **DECISION-2 had also not
propagated**: `MISSION.md`'s standing directives still stated the DB hard-cutover with no mention of
Mos's binding qualification that _the spine must not be a single-point hard-stop_ (degraded mode +
rollback artifact required). A seat reading the charter would have designed toward an availability
posture the coordinator had explicitly rejected — and would have found the superseded
"no DB ⇒ the fleet stops" recommendation nowhere contradicted. Now corrected in place.
**Two un-propagated rulings out of two rulings that touched charter text.** The propagation gap is not
an oversight that happened once; without a mechanism it is the _default outcome_. That is the argument
for making this a requirement rather than a discipline.
### D-13 — two credential registries that can disagree (why the `--draft` fallback fired at all)
Diagnosing D-12's root cause surfaced a distinct defect. There are **two parallel credential
registries**, and capability in one does not imply capability in the other:
| registry | contents for identity `mos-dt-0` on `mosaicstack` |
| ------------------------------------------------------ | -------------------------------------------------------------------------------------------- |
| token files — `~/.config/mosaic/secrets/gitea-tokens/` | `gitea-mosaicstack-mos-dt-0.token` **EXISTS** |
| `tea login list` | **NO** `mosaicstack` login for `mos-dt-0` (only `mosaicstack-mos` and `mosaicstack-rev-974`) |
So `get_gitea_token` succeeds and every raw-API path works, while every **tea-dependent** wrapper path
fails its login validation and silently degrades to the API fallback — which is exactly what dropped
`--draft`. **tea is not "stale"; the login simply does not exist for that identity.**
This matters beyond one flag: capability was declared authoritative by the token-file set (D-11b), but
that registry does not govern the tea path. A seat can be _fully provisioned_ by the authoritative
registry and still lose functionality with no error — only a warning, and only on the degraded path.
**Requirements.** RM-04 (activation coherence): the two registries must be reconciled — one source of
truth, or a startup check asserting they agree, with a must-fail control proving disagreement is
detected. RM-50: the pre-dispatch capability check must verify capability for the **path actually
used**, not merely token-file presence.
**Confirmed working despite the gap** (so this is degradation, not outage): pushes, `pr-merge.sh`,
PR/issue creation via API fallback, comment posting, and all reads. Impact is confined to
tea-only features — `--draft`, `--labels`, `--milestone`.
**Reconciliation run by Mos (the manual form of RM-04's assert-agreement, done once by hand).** For
`git.mosaicstack.dev`, the token-file registry holds **six** seats; `tea` holds logins for **two**:
| state | seats |
| ------------------------------------------------ | -------------------------------------------------------- |
| token file present, **no** mosaicstack tea login | `f10-coder`, `jarvis`, `mos-admin`, `mos-dt-0`, `pepper` |
| token file present **and** tea login present | `rev-974` (only) |
**Five of six provisioned seats are silently degraded on tea-only features.** This is _systemic_, not
a one-off — which is why the fix is registry reconciliation (RM-04) and not a per-seat mint. Minting
one seat would clear a symptom and leave the class live.
Mos deliberately deferred the mint: it is not on RM-01's critical path, and additively editing shared
`tea` config underneath running work is a change he declined to make without cause. Full remediation —
mint the five missing logins **and** wire the startup must-fail assertion that _detects_ disagreement —
lands as RM-04 at a non-critical seam, or immediately if any seat needs a tea-only feature to progress.
**Correction of record:** this supersedes D-11(b)'s claim that the token-file set is _the_ authoritative
capability registry. It is **necessary but not sufficient**. Capability is **per-path**: the token file
governs the raw-API path, the tea login governs the tea path, and the two can disagree silently.
### D-12 — a requested SAFETY flag was silently degraded, and I did not check
I created PR #1027 with `pr-create.sh ... -d` (draft) because it carries **partial, unproven work**.
`tea` authentication was stale, so the wrapper fell back to its raw-API path — which cannot set draft —
and emitted:
```
Warning: API fallback applies title/body/head/base only; labels/milestone/draft require authenticated tea setup.
```
The PR was created **not-draft**. I read the success output, saw the PR number, and moved on. I then
reported to the coordinator that the PR was "opened as draft". **It was open, mergeable, and marked
ready for ~25 minutes**, protected only by the words "DRAFT" and "do not merge" in its title and body —
i.e. by prose a human might read, not by the platform control I asked for. Detected only because a
watcher polled `draft:` and the value disagreed with my belief. Corrected by setting the `WIP:` title
prefix (Gitea's draft mechanism); `draft: True` verified after.
**Three distinct failures, and the third is mine:**
1. **Silent degradation of a safety flag.** The fallback path dropped `--draft` and still exited 0. A
fallback that cannot honour a _safety_ argument must fail, not proceed — degrading `--labels` is a
nuisance; degrading `--draft` publishes unproven work as ready to merge.
2. **The warning went to stderr and nothing consumed it.** It was correct, specific, and ignored — a
warning nobody acts on is indistinguishable from no warning.
3. **I did not verify the flag took effect.** I checked that the PR existed, not that it had the
property I required. This is the mission's own thesis turned on me: **I trusted a success exit code
over an observed state**, on exactly the class of tool this mission exists to distrust.
**Requirements.** RM-02: a wrapper that cannot honour a safety-relevant argument must exit non-zero —
registered with a must-fail control asserting `--draft` on a degraded path fails rather than proceeds.
RM-24 (tri-state write outcomes): this is precisely `written-unverified` being treated as `verified`
the PR write succeeded, the _requested property_ was never confirmed, and no one looked.
### D-11 — seat identity did not survive into git, and seat capability is invisible at dispatch
Two defects, one dispatch (RM-01 → `f10-coder`):
**(a) Identity drift — P-WRAPPER-001, reproduced on our own delivery.** The seat's commits are
authored `mosaic-coder <[email protected]>` — the generic fallback. **You cannot tell from
git history which seat did this work.** Recorded, not rewritten: the drift is the evidence.
> **Mechanism, corrected (Mos).** My original framing here was wrong, and the error was in the brief
> before it was in the finding. `MOSAIC_GIT_IDENTITY` resolves the **token** (which per-slot credential
> the wrappers act with). The **commit author** comes from `git config user.name` / `user.email`, which
> is a **separate setting** — it fell back to the generic value because nothing set it. Exporting the
> identity could never have fixed authorship. **My worker brief instructed only the export, so the
> seat did exactly what it was told and the commits were still mis-attributed.**
>
> **The requirement is coherence: token and authorship must agree.** A seat acting with
> `gitea-mosaicstack-f10-coder` must also commit as `f10-coder <[email protected]>`.
> Either half alone is identity drift — one produces the right credential with the wrong author, the
> other the reverse. That coherence _is_ P-WRAPPER-001, and it belongs in seat setup, not in prose
> instructions a seat may follow correctly and still end up wrong.
**(b) Capability opacity.** Nothing at dispatch time revealed that `f10-coder` had no credential for
the target provider. Per-slot tokens live at `~/.config/mosaic/secrets/gitea-tokens/`; the seat holds
`gitea-usc-f10-coder` but not `gitea-mosaicstack-f10-coder`. This surfaced only when the seat failed
**mid-task, after ~$9 and 69% of its context.** The orchestrator (me) selected a seat without any way
to check it could act on the target repo — and there was no way to check.
`get_gitea_token` behaved **correctly**: it refused to fall through and borrow another slot's token,
failing loud precisely to protect gate-16 attribution. The tooling was right; the _dispatch-time
information_ did not exist.
**This is P-RECOVERY-001's "honest capability labeling" applied to seats rather than services.** A seat
should declare what it can actually do — which providers, which repos, which credentials — and that
declaration must be **checkable before dispatch**, not discovered by failure after the budget is spent.
**Requirements.**
- **RM-04 (activation coherence)** gains the identity-binding half: seat setup must set **both** the
token identity **and** `git config user.name`/`user.email`, coherently. Verified by an
exit-asserting test that makes a commit and asserts its author — never assumed from an instruction
in a brief.
- **RM-50 (roster ownership)** gains per-seat capability declaration plus a **pre-dispatch capability
check**. Mos (who owns provisioning) confirms the check is mechanically trivial: **capability is
token-file existence.** Before dispatching seat `X` to provider `Y`, test that
`~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token` exists; if absent, provision it or pick a
provisioned seat. **The token-file set is the authoritative capability registry.** A one-second check
would have replaced a mid-task failure that cost ~$9 and 69% of a seat's context.
### D-10 — the queue guard's failure modes are exactly backwards
`ci-queue-wait.sh` — a **required** pre-push/pre-merge gate — was observed this session doing both of
these:
- **Fails OPEN on an unknown result.** `state=unknown ⇒ exit 0`, five times, during real pushes and
real merges. It also evaluates `branch=main` rather than the branch being acted on.
- **Fails CLOSED on credential resolution.** In a worker seat it aborted with
`Gitea token not found`, hard-blocking a legitimate push of completed, tested work. The worker
correctly stopped (Constitution gate 8). The identical command run from that worker's _own worktree_
in another shell succeeded, so the checkout and remote were fine — the difference was the worker's
process environment.
**A gate that waves through work it never checked, and blocks work that is ready, has its failure
modes inverted.** Availability failures (cannot reach the provider, cannot resolve a credential)
should degrade to a loud, auditable _inability to assert_ — never to a hard stop on delivery, and
never to a silent pass. Correctness failures (unknown, malformed, terminal-failure) are what must
block.
This is also the **Pi-brick shape** (P-RECOVERY-001): a gate whose own unavailability prevents the
work needed to recover from it.
**Requirement on RM-03, extending its existing two defects:** the guard must distinguish
`CANNOT_ASSERT` (credential/transport/provider unavailable — loud, audited, does not silently pass and
does not permanently block) from `ASSERTED_NOT_READY` (a real non-green CI state — blocks). Both are
registered R-002 cases with must-fail controls; neither may exit 0 silently.
### D-9 — the comms path shell-interprets message bodies (injection-shaped, found by accident)
Sending a status message with `agent-send.sh -m "...`backticks`..."` caused bash to **execute** the
backticked text as command substitution. The recipient received a mangled body plus a
`No such file or directory` error; the intended sentence never arrived. The message was reported as
delivered.
This is the **same class** as the already-noted `pr-create.sh` backtick-quoting bug (M2 scratchpad):
**two tools in the comms path treat a message body as shell input.** A body that can execute on the
sender is a _correctness_ bug before it is ever a security one — and note the failure mode: the
send reported success while silently transmitting something other than what was written. Silent
corruption with a success receipt is precisely the pattern this mission exists to eliminate.
**Requirement on RM-40 / RM-42 (comms/v1), hardened by Mos.** The envelope must carry its payload
**verbatim** and must not be subject to shell interpretation at **any** hop — sender, transport, or
adapter. Concretely: **file/stdin transport, never argv interpolation.**
**Standing interim rule, effective now (Mos).** Until the envelope lands, use `agent-send.sh -f
<file>` for any message body containing special characters — **never `-m`**. Passing a file sidesteps
argv interpolation entirely. **This rule is mandatory in every worker brief this mission issues**,
alongside the D-8 "if a check is unrunnable, say so" clause. Round-trip fidelity (send a body containing backticks, `$(…)`, quotes, and newlines; assert
byte-identical receipt) is a required registered test case under RM-02, including a must-fail control
proving the assertion can detect corruption.
### D-8 — a PRE-REGISTERED acceptance check that was not runnable as written
On PR #1025 the author (me) pre-registered AC2 with the fixture snippet `mkdir -p apps/*/venv/lib`.
In bash, when no `venv` exists the glob is unmatched and passes through literally, creating a
directory named `apps/*/venv/lib` rather than one per workspace. The check as written did not test
what it claimed to test.
`rev-974` ran it **exactly as written**, observed the wrong behaviour, then re-ran the intended
assertion at an explicit path — **and said so in the review** rather than silently substituting a
working fixture and reporting PASS.
Two things this establishes:
1. **The instruction "do not adjust a check to fit the diff; if it is unrunnable, say so explicitly"
worked.** A silent substitution here would have produced a green AC2 that proved nothing, on the
exact task whose subject is gates that appear to work. The disclosure is what made the PASS
meaningful.
2. **Pre-registration does not confer correctness.** A pre-registered check is protected from being
retrofitted to the implementation; it is not protected from being _wrong when written_. This is a
small instance of the mission's own class — an unverified gate — occurring inside the mechanism
built to catch unverified gates.
**Requirement on RM-02 (non-negotiable, sharpened by Mos).** The registry must **self-verify** that
every registered case demonstrably **runs** and demonstrably **fails on a known-bad input**.
Presence in the registry is **not** evidence. **A check is not trusted until it has been shown to
fail.** This is mutation testing / negative control applied _at the registry level_ — meaning
**the conformance harness must itself be conformance-tested.** A registered case that cannot fail, or
cannot run, is exactly as inert as an unregistered one, and the registry check must detect that
itself rather than assume it.
**Requirement on RM-55.** The same recursion applies to the harness: it must be observed red before
its green is worth anything (OPUS R-063 AC1 already states this; D-8 is the empirical case for it).
**Second, equally load-bearing lesson — reviewer disclosure is what makes a review trustworthy.**
rev-974 could have silently swapped in a working fixture and reported `AC2 PASS`. Nothing in the
process would have caught it, and the resulting green would have certified nothing — on the very task
whose subject is gates that only appear to work. The brief's instruction — _"do not adjust a check to
fit the diff; if it is genuinely unrunnable as specified, say so explicitly and explain why rather
than silently substituting your own"_ — is therefore not boilerplate. It is the clause that makes a
PASS mean something, and it must appear in **every** reviewer brief this mission issues.
### D-7 — shared-tmpfs contention → cascading ENOSPC (live incident, 2026-07-31)
The shared 30 G `/tmp` hit **100% ENOSPC** mid-session. It broke tool calls in **two different seats**
(mine and Mos's) — a single full disk degrades every agent on the host at once. Recurring: prior
incidents 2026-06-18 and 2026-07-17.
Attribution matters, because the wrong owner cleans the wrong thing. Measured:
| path | size | last modified | owner |
| ---------------------------------------------- | --------- | ---------------------------- | ------------------------------------------------- |
| `…/-src-mosaic-stack/6d2faee6…` (this session) | **88 K** | live | mos-remediation |
| `…/-src-mosaic-stack/c743185d…` | **3.6 G** | **2026-07-22** (9 days dead) | abandoned session, same project path |
| `…/claude-1001/pnpm-store` | **1.6 G** | **2026-07-23** (8 days dead) | abandoned; the live store is correctly on `$HOME` |
So ~5.2 G — the bulk of the pressure — is **dead session scratch that nothing will ever read again**.
This is not a quota problem; it is **P-FLEET-001's stale-session GC, applied to disk instead of tmux
sessions.** The same missing capability (nothing owns reaping dead ephemeral state) produces both the
orphaned-session failure and this one. Reaping dead-session scratch belongs in RM-50 alongside stale
tmux-session GC.
**Added to RM-01 as acceptance criteria:** heavy build artifacts (node_modules, package stores, build
output) must land on the main disk in the worktree, never on the shared 30 G `/tmp`.
**Resolution, and the part that is actually the finding.** Mos verified the attribution independently
(mtimes, no process or `lsof` holding either path, no live session maps) and reaped both as lead
coordinator: `/tmp` went to 79%, 6.0 G free. But note _how_ it was resolved — **a human-authority seat
did it by hand, because the authority exists and the reaper does not.** That gap is the finding, not
the disk usage.
Two doctrine points fall out, both binding on RM-50:
1. **The fix is not "agents should tidy up."** Asking each seat to clean its own scratch is
`instructions are not enforcement` (D-4) wearing a different hat. A deterministic reaper must own
it — same conclusion the north star reaches for every other class in this mission.
2. **Refusing to unilaterally delete another session's scratch was correct, and the resolution is not
"be braver about deleting."** An agent guessing that someone else's state is garbage is exactly the
unreviewed destructive act the Constitution forbids. The resolution is that _ownership and liveness
become mechanically decidable_, so reaping is a determination rather than a judgement call.
**Reaper requirements for RM-50:** liveness determined mechanically (process/`lsof`/session-map, not
mtime alone); an age threshold; a dry-run that reports what it would reap and why; and an audit event
per reap. Never a heuristic sweep — that would reintroduce the P-WORKFLOW-001 auto-sync failure in a
more destructive form.
**The self-erasure is the important part.** An inert gate that is masked by unrelated downstream
commits produces no lasting artifact, which is precisely why this class survives for months. Detection
cannot rely on "is `main` currently red" — it must be per-merge-commit.
This matters more than the one-line fix:
- It is the **P-QUEUE-001 / P-CONFORMANCE-001 class** ("gate-6 was inert fleet-wide"), reproduced in
the repository this mission is remediating, discovered incidentally.
- It independently **validates OPUS premise A1** ("every gate is inert until proven otherwise") with
live evidence rather than argument — which is why RM-02 is adopted as the keystone (§2, X2).
- The file fix rides in its own hygiene PR. **The inert gate itself is NOT quiet-patched.** Per Mos:
it stays a first-class backlog item, because patching the symptom would destroy the signal.
**Binding requirement on RM-02 and RM-55:** the gate registry and the conformance harness must assert
**"every merged commit passed every required gate"** — evaluated **per merge commit, against that
commit's own tree**, not against current `main`. As the table above proves, a "is main green today"
check would have reported all-clear. A merged-commit-that-fails-a-required-gate is the exact detection
signal, and it must be a registered must-fail case. A gate that cannot prove it blocked something has
not been shown to work.
---
## 2. Where they genuinely disagree (not averaged — adjudicated)
| # | Axis | OPUS | SOL | My ruling |
| --- | ------------------------------------------- | ---------------------------------------------------------- | --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| X1 | **Total cost** | 38 tasks, ~5.3M tok | 25 tasks, ~294K tok | **~18× apart.** Not reconcilable by splitting. They measure different things: SOL explicitly excludes orchestration/review/iteration overhead and assumes one remediation pass; OPUS prices the full loop. Adopt **SOL's scope** with **OPUS's rigor**, and treat SOL's G1 as a hard budget checkpoint (§4). Re-estimate empirically after the first three merged PRs rather than trusting either number. |
| X2 | **Gate registry (OPUS R-002)** | Keystone; blocks all P2 | Absent; only a queue-guard fix | **ADOPT OPUS.** Empirically validated in this very session: I found `pnpm format:check` red on `main` via merged PR #868 — a required gate that did not block. OPUS's premise A1 ("every gate is inert until proven otherwise") is not theoretical; it reproduced today, unprompted. Scope it tighter than 120K. |
| X3 | **Drizzle PG first-install defect (R-010)** | Hidden blocker; everything downstream depends on it | Not mentioned | **ADOPT OPUS.** `packages/db/src/migrate.ts:30-38` carries a TODO admitting postgres-tier first-install fails today. The spine has only ever been proven on PGlite. Every later migration silently depends on this. SOL missed it. |
| X4 | **Rollback artifact for the hard cutover** | D3: hard cutover needs a rehearsed rollback snapshot | SOL-07: import-only, explicitly no dual-write | Both obey "no flat-file interim." OPUS wants a one-directional snapshot nothing reads as authority. I read that as compatible with the directive, but it is Jason's call → **DECISION-2** (§5). |
| X5 | **Where the queue guard sits** | P0, independent of spine | SOL-02, also early | Agree it is P0. But ownership collides with **parked PR #1023****DECISION-3** (§5). |
| X6 | **Report-only rollout** | D5: only with a hard expiry, else withdraw | not raised | **ADOPT OPUS.** A report-only gate is by definition inert; expiry is the mechanism that stops it becoming the new fail-open. |
| X7 | **Availability trade (FC-7/FC-11)** | D8: "no DB ⇒ fleet stops" must be pre-committed in writing | not raised | Genuine availability regression, correctly identified. Needs Jason → folded into **DECISION-2**. |
---
## 3. Reconciled DAG
Phases run in order; `⛔` marks a hard barrier. `src` shows lineage (`O`=opus, `S`=sol, `O+S`=both).
Estimates are given as a **range** (SOL low / OPUS high) rather than a fabricated midpoint — the
spread is itself information, and X1 says we calibrate on real merged PRs.
### P0 — Make gates provable, and stop the fleet re-bricking
_No gate-introducing task in any later phase may merge before RM-02._
| id | task | src | depends_on | est (S/O) | tier |
| --------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------ | ---------------- | ------ |
| RM-01 | Reproducible non-root checkout; gate fails on **code, not env**; heavy artifacts OFF shared `/tmp` (banks D-1/D-2/D-5/D-7) | O+S+live | — | 6K / 60K | codex |
| RM-02 | **Gate registry + negative-control CI check** (anti-inert-gate harness) ★keystone | O | RM-01 | — / 120K | opus |
| RM-03 ⏸**HOLD** | Queue-guard: **two** defects — (a) `unknown`/`no-status`/malformed ⇒ ≠0, (b) guard evaluates `branch=main` instead of the branch being pushed | O+S+live | RM-02 | 8K / 100K | sonnet |
| RM-04 | Activation/version coherence; block launch on skew, fail SAFE; honest `doctor` labels | O+S | RM-01 | (in S-01) / 140K | sonnet |
| RM-05 | Break-glass replaces the three silent `MOSAIC BYPASS` fail-opens | O | RM-04, RM-02 | — / 120K | opus |
> ⚠ **RM-05 must not merge before RM-04.** The bypasses exist because the lease-broker daemon was
> never _deployed_ on this host — removing the fail-open before deployment coherence is real
> re-creates the 2026-07-22 bricking incident. Hard edge, from OPUS.
### P1 — Durable spine (PG)
_No migration may merge before RM-10._
| id | task | src | depends_on | est (S/O) | tier |
| ----- | --------------------------------------------------------------------------------------------- | --- | ---------- | ---------- | ------ |
| RM-10 | **Fix the Drizzle postgres-tier first-install defect** ★hidden blocker | O | RM-01 | — / 90K | sonnet |
| RM-11 | Orchestration spine schema (tasks, attempts, gate_results, hash-chained ledger, typed claims) | O+S | RM-10 | 12K / 160K | opus |
| RM-12 | Spine client, fail-closed connection (no silent PGlite in prod) | O | RM-11 | — / 80K | sonnet |
| RM-13 | Atomic claims/transitions + transactional outbox + reconciliation sweeper | O+S | RM-12 | 12K / 140K | opus |
### P2 — The single choke point
_RM-25 (no-second-path) lands in the same milestone as RM-20, or the choke point is optional._
| id | task | src | depends_on | est (S/O) | tier |
| ----- | ---------------------------------------------------------------------------------------------- | --- | ------------------- | ---------------- | ------ |
| RM-20 | Canonical MACP contract completion (Task/Result/Event/Claim/tri-state outcome) | S | — | 8K / (in R-020) | codex |
| RM-21 | **Production `TaskExecutor`** backed by `@mosaicstack/macp` ★keystone | O+S | RM-12, RM-02, RM-20 | 16K / 220K | opus |
| RM-22 | Gate-runner hardening: `fail_on`, timeouts, **empty gate set = failure** | O | RM-21 | — / 120K | sonnet |
| RM-23 | Hash-chained MACPEvent ledger in PG + lifecycle EventType extension | O+S | RM-21, RM-11 | — / 160K | opus |
| RM-24 | Seat identity from `MOSAIC_AGENT_NAME` + **mandatory** tri-state write outcomes | O+S | RM-21 | (in S-03) / 150K | opus |
| RM-25 | **No-second-path gate:** terminal status writable only by the executor | O | RM-21, RM-23 | — / 140K | opus |
| RM-26 | `packages/coord` submits through the executor (retire direct spawn) | O+S | RM-21 | 16K / 140K | sonnet |
| RM-27 | `mosaic yolo/claude/codex/pi` launch path records typed Task + events | O | RM-21, RM-23 | — / 160K | sonnet |
| RM-28 | Delete the Forge stub executor (empty-gate-list "success"); Forge submits through the real one | O+S | RM-21 | 10K / 90K | codex |
| RM-29 | One-shot flat-file import + cutover readiness audit (dry-run, idempotent, no dual-write) | S | RM-13 | 8K / (in R-062) | codex |
> **★ G1 — FIRST DOGFOOD. Stop here and prove it.** One live fleet task travels
> PG claim → TaskExecutor → worker → gates → terminal PG result/event, with **no** flat-file state.
> Adopted from SOL wholesale. If G1 cannot carry a real task, **do not build Redis, rotation, comms,
> or conformance** — remediate instead. This is the budget escape hatch (§4).
### P3 — Rotation lifecycle (finish the Mission Control Plane)
| id | task | src | depends_on | est (S/O) | tier |
| ----- | -------------------------------------------------------------------------------------------- | --- | ------------ | ---------------- | ------ |
| RM-30 | Typed state claims (source/confidence/TTL) with HMAC integrity, fail-closed | O+S | RM-11, RM-21 | (in S-03) / 170K | opus |
| RM-31 | Contract-hash binding; stale generation loses mutation authority **mechanically** | O+S | RM-21, RM-30 | 12K / 180K | opus |
| RM-32 | Durable compaction/token sensor (per-runtime thresholds, PreCompact event) | O | RM-23, RM-31 | — / 130K | sonnet |
| RM-33 | Typed checkpoint writer (structured claims, never transcript) + digest | O+S | RM-30, RM-32 | 12K / 150K | opus |
| RM-34 | **Rotation daemon:** watch → checkpoint → revoke → kill → relaunch → rehydrate | O+S | RM-33, RM-26 | 16K / 240K | opus |
| RM-35 | Rehydration attestation gate: refuse to act on an incomplete claim set | O | RM-33 | — / 130K | opus |
| RM-36 | Broker-independent recovery; remove silent bypass; honest capability labels | S | RM-34 | 12K / (in R-004) | sonnet |
| RM-37 | Delete `/compact and continue` from the persistent-seat path (**substitution**, not removal) | O+S | RM-34, RM-44 | (in S-16) / 60K | codex |
### P4 — Comms service
_RM-50 (one roster-owned socket per host) precedes identity-addressed delivery._
| id | task | src | depends_on | est (S/O) | tier |
| ----- | ---------------------------------------------------------------------------- | --- | ------------ | ---------------- | ------ |
| RM-40 | `comms/v1` envelope + protocol-version negotiation, LOUD reject | O+S | RM-11, RM-31 | 8K / 140K | opus |
| RM-41 | Comms service: PG state machine PENDING→RECEIVED→CONSUMED→DEAD-LETTER | O+S | RM-40, RM-13 | 16K / 200K | opus |
| RM-42 | tmux transport as a **dumb adapter**; durable retry before cursor advance | O+S | RM-41, RM-50 | (in S-19) / 160K | sonnet |
| RM-43 | Per-class coalescing + supersede (the stale-consumed-as-live fix) | O+S | RM-41 | 12K / 130K | sonnet |
| RM-44 | Redis Streams hot delivery + provenance guard (**Redis is never authority**) | O+S | RM-41, RM-13 | 12K / 170K | opus |
| RM-45 | Retire direct tmux sends; only the service may write a pane | O+S | RM-42, RM-43 | (in S-20) / 100K | codex |
### P5 — Retirements, hygiene, conformance
| id | task | src | depends_on | est (S/O) | tier |
| ----- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- | -------------------------- | ---------------- | ------ |
| RM-50 | One roster-owned socket/host; quarantine unmanaged; **deterministic reaper for stale sessions AND dead-session disk scratch** (D-7) | O+S+live | RM-04 | 14K / 150K | sonnet |
| RM-51 | Auto-sync **allowlist** (never auto-stage unknown paths) + worktree/lease isolation | O+S | RM-02 | 8K / 110K | sonnet |
| RM-52 | Retire the Python controller + duplicate MACP islands (3 → 1) | O+S | RM-26, RM-27, RM-25, RM-28 | 14K / 110K | codex |
| RM-53 | Flat-file orchestration → DB hard cutover, with rehearsed rollback artifact | O+S | RM-27, RM-30, RM-34, RM-29 | (in S-10) / 200K | opus |
| RM-54 | Fleet-wide inert-gate audit against the RM-02 registry | O | RM-02 | — / 120K | sonnet |
| RM-55 | **Conformance harness:** fault-inject the live failure classes on real artifacts | O+S | RM-35, RM-41, RM-53 | 18K / 260K | opus |
| RM-56 | Retirement proof: CI asserts all three retirements are complete **and stay complete** | O | RM-52, RM-45, RM-53 | — / 90K | codex |
| RM-57 | Operator cutover docs + activation proof; map all 15 decisions to evidence | S | RM-04, RM-36, RM-45, RM-55 | 6K / — | codex |
| RM-59 | **Close the D-19 residual risk** — generated-state verification anchored **outside** the worktree's authority (executor/spine-side attestation), retiring the same-UID self-authentication gap | mos-remediation (D-19) | RM-12, RM-21, RM-25 | 20K | opus |
| RM-58 | **Mechanical pre-dispatch context reset** — the orchestrator resets a seat out-of-band and verifies it, rather than asking the agent to reset itself | mos-remediation (D-4) | RM-31, RM-50 | 8K | sonnet |
**Critical path:** `RM-01 → RM-02 → RM-10 → RM-11 → RM-12 → RM-21 → RM-23 → RM-31 → RM-33 → RM-34 → RM-53 → RM-55`.
---
## 4. Execution discipline
- **Every row is one PR.** Author ≠ reviewer; `rev-974` is the mosaicstack reviewer identity.
- **Pre-registered, diff-blind acceptance checks are committed BEFORE the reviewer reads the diff.**
Both decomps wrote their ACs in runnable `⇒0` / `⇒≠0` form specifically to make this possible.
- **Every gate-introducing task carries at least one registered must-fail negative control.** This is
RM-02's whole purpose; a gate with no proven failure path manufactures evidence.
- **Cost tiers:** codex for mechanical/unambiguous, sonnet for normal feature work, opus reserved for
security/integrity/cross-cutting-invariant tasks. SOL priced 0 opus tokens; OPUS priced 14 opus
tasks. I am keeping opus only where the failure is _integrity_, not merely complexity.
- **G1 is the budget checkpoint.** If the first-dogfood slice overruns SOL's estimate by >3×, stop and
re-plan rather than spending the remainder. X1 says neither estimate is trustworthy until calibrated.
- **Defer list adopted from SOL** (10 items): mission dashboard/TUI, PRD-to-board auto-decomposition,
heuristic churn scoring, Discord/Slack/Telegram adapters, public MCP comms surface, protocol-v2
negotiation, multi-region PG/Redis, event analytics UI.
---
## 5. Decisions — all three ruled by Mos, 2026-07-31
**DECISION-1 — the wire-in point. ✅ RULED: accept the planners (Mos, 2026-07-31).**
The charter's `mosaic_orchestrator.py::run_single_task` target is the **disabled Python controller
this mission retires**; wiring the new choke point into the rail we are deleting is wrong.
> **Corrected target (authoritative):** a **new production Node `TaskExecutor`** sitting on the
> **live dispatch path** — `packages/mosaic` launch + `packages/coord` — which Coord, Forge, and live
> dispatch all **submit through**. This is the MACP scout's _full_ recommendation ("replace the block
> **with** a Node executor **and** make Coord/Forge submit through it"), not a resurrection of the
> Python controller. RM-52 is therefore a **deletion** task, and Build 1's acceptance is measured on a
> live `mosaic yolo` invocation.
Mos ruled this resolvable from the already-accepted retire-the-Python-rail decision — his authority,
not a Jason escalation. RM-21/RM-26/RM-27/RM-52 all take the corrected target.
**DECISION-2 — rollback artifact + availability trade. ⏸ JASON-PENDING — NOT BLOCKING.**
The DB build is phases away, so this is queued for Jason's next session rather than escalated now.
**Binding requirement in the meantime (Mos, from P-RECOVERY-001):** the DB spine **must NOT be a
single-point hard-stop.** Design for a broker-independent / degraded mode **plus** a rollback
artifact. Jason finalises only the specific availability target. This reverses my earlier reading of
OPUS D8 ("the fallback is: the fleet stops") — that answer is **not** pre-committed; a degraded mode
is now a design requirement on RM-12, RM-13, RM-23, RM-36 and RM-53.
**DECISION-3 — RM-03 vs. parked PR #1023. ✅ RULED: HOLD RM-03 (Mos, 2026-07-31).**
Do **not** open a third gate-6 lane — that is the postmortem's own anti-pattern performed by the
remediation. PR #1023 sits in Jason's **parked delivery stack**; its disposition (close, or supersede
by RM-03) is Jason's at his next session.
- **PR #1023`SUPERSEDED-PENDING-JASON`.** RM-03 stays `HOLD`; when Jason rules, RM-03 proceeds as
the single correct lane.
- **RM-02 and RM-55 proceed independently and are NOT held.** The per-merge-commit gate-assertion
requirement is the _conformance_ capability, not the gate-6 fix itself — different scope, no
ownership collision.
---
## 6. Status
| phase | state |
| ------------------ | ------------------------------------------------------------------------------------------------------------ |
| Decomposition | DONE — both planners delivered independently |
| Reconciliation | DONE — this document |
| Blocking decisions | **RULED** — all 3 closed by Mos 2026-07-31 (§5); D-2's availability target is Jason-pending but non-blocking |
| Dispatch | **RM-01 IN FLIGHT** — f10-coder (codex), worktree-isolated, AC1AC8 pre-registered |
| Review | PR #1025 with rev-974; ACs pre-registered 22:12:26Z before diff exposure |
@@ -0,0 +1,118 @@
# RM-61 — CI contract exemption for #1000 teardown artifact
**Tracking:** RM-61 / issue #1000
**Branch:** `fix/rm-61-ci-contract-exemption`
**Owner:** `coder-mos1`
## Objective
Determine, by red-first provider controls, whether the `ci-postgres` pod-not-found teardown signature discriminates from a real PostgreSQL failure. Only if it discriminates may a named, bounded CI-contract exemption be implemented. The exemption must retire when #1000 is fixed; fixing #1000 is the closure path.
## Pre-registered kill criterion
If an injected real `ci-postgres` failure also yields `pods "wp-svc-<ULID>-ci-postgres" not found` as the service's provider-visible failure, the signature does not discriminate. Option B is unsafe; stop exemption implementation and fall to Option A (#1000).
## Plan
1. Capture full `-f json` records for the 11 supplied observations and state counts.
2. Run one startup-failure control using the real pgvector/PostgreSQL image with an invalid `initdb` argument.
3. Run one post-readiness crash control using real PostgreSQL, `pg_isready`, and a deliberate postmaster kill while a DB-dependent probe is active.
4. Compare the raw `ci-postgres` service record independently of failures in dependent steps.
5. Investigate runner/time/head clustering only as a hypothesis; never encode incidental correlates or retries into policy.
6. If and only if the controls discriminate, implement and test the exact exemption, document its two-way boundary, and track retirement at #1000.
## Budget
No explicit token cap supplied. Working estimate: 20K30K tokens. Limit provider controls to the two pre-registered runs; no retries or re-roll policy.
## Initial evidence
Historical JSON saved locally under `.evidence/rm-61/` (not for commit). Supplied pipelines: 11 total. Child-step counts: five pipelines with 9 children and six with 10 children. Seven contain the `ci-postgres` pod-not-found failure (#2170, #2175, #2180, #2181, #2182, #2187, #2188); four do not (#2158, #2167, #2184, #2186). Every observed workflow reports `agent_id=44`, so the available JSON does not separate clean and artifact runs by runner. This refutes runner identity as a discriminator in the sampled record.
## Progress
- [x] Requirements and kill criterion recorded before control implementation.
- [x] Historical full-JSON records captured.
- [x] Startup-failure control observed terminal.
- [x] Post-readiness crash control observed terminal.
- [x] Discrimination verdict recorded: Option B may proceed.
- [x] Conditional exemption implementation.
## Tests / evidence
### Control 1 — real startup failure
- Commit: `3931b0e29eb834914f7b17e4db7e221481d436fa`
- Pipeline: #2189, exact commit match.
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
- `ci-postgres`: `state=failure`, `exit_code=1`, `error=null`, with a five-second execution window.
- `test`: `state=failure`, `exit_code=1` after the readiness budget expired.
- Pipeline/workflow: terminal `failure`.
This control is red and its service record differs from #1000 (`exit_code=0` plus pod-not-found). It proves the startup-failure direction only. It does not settle the dangerous post-readiness crash/garbage-collection path.
### Control 2 — real post-readiness crash
- Commit: `25ac59715a94dd1b52ef42577472eb44ecc4b446`
- Pipeline: #2191, exact commit match.
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
- Service log proves PostgreSQL reached `database system is ready to accept connections`, the test created the arm table, and the service then killed postmaster PID 7.
- Test log proves a successful `SELECT 1` followed by `Connection refused`; it exited the pre-registered control code 61.
- `ci-postgres`: `state=failure`, `exit_code=137`, `error=null`, with a 203-second execution window.
- `test`: `state=failure`, `exit_code=61`.
- Pipeline/workflow: terminal `failure`.
This is the dangerous post-readiness crash path. Its service record is not pod-not-found and therefore differs from #1000 independently of the dependent test failure.
### Discrimination verdict
Both real failures are provider-visible as process exits (`exit_code=1` startup; `exit_code=137` crash) with no pod-not-found error. The seven observed #1000 artifacts are provider reconciliation misses (`exit_code=0` plus the exact pod-not-found error). The declared kill criterion did not fire, so Option B may proceed with a matcher requiring the full conjunction. This evidence does **not** prove every future Kubernetes failure is distinguishable; it proves these two concrete real-failure classes remain blocking and bounds the exemption to the observed reconciliation shape.
### Unit red-first checkpoint
The nine-case contract harness was written before the verifier. First execution exited 1 because `verify-terminal-green.py` did not exist; no exemption implementation was live. Cases pre-register ordinary green, the exact artifact, both provider controls, near-miss signatures, an independent failure, and a skipped step.
### Control 2 setup attempt — invalid, excluded from evidence
- Commit: `9455cd6a2650b2b7e70f746c07933d96e5cb3d20`
- Pipeline: #2190, exact commit match.
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
- Service log: `/bin/sh: 0: -c requires an argument`.
- Root cause: Woodpecker service `commands` did not become the third `sh -c` argument. PostgreSQL never started, so this run is **not** the post-readiness crash control and provides no discrimination evidence.
- Focused remediation: place the script directly in the third `entrypoint` element and supply `PGPASSWORD` for the marker query. This is a control-fixture correction, not a retry of #1000 and not evidence for either verdict.
## Implementation evidence
- `verify-terminal-green.py` consumes only the full JSON/API record; it performs no fetch, retry, or trigger.
- Exact #2188 record: exit 0, 10 children, 9 success + 1 named exemption.
- Historical set: #2158/#2167/#2184/#2186 pass with no exemption; #2170/#2175/#2182/#2187/#2188 pass with one named exemption; #2180/#2181 remain red because independent failures exist.
- Provider controls: #2189 and #2191 both exit 1 under the verifier; neither is exempted.
- Unit harness: initial 9/9 cases passed after the red-first checkpoint; review remediation expands this to 12 cases with expected-head match/missing/mismatch coverage.
- Test-membership guard: PASS, population 45; 26 enumerated, 19 signed exclusions; all 39 surface paths present.
- Python compile: PASS.
- `pnpm typecheck`: PASS, 45/45 tasks.
- `pnpm lint`: PASS, 25/25 tasks.
- `pnpm format:check`: PASS after moving local evidence outside the repository tree.
- `test:framework-shell`: RM-61 and all preceding suites passed, then the pre-existing wake assertion aborted with exit 97 because this host's Bash 5.2.15 reports `BASH_LINENO [3 5]` where that suite requires `[3 4]`. RM-61 does not modify the wake suite; the command is not fully runnable on this host as written and no substitute result is claimed.
## Independent review
- Review 67 / comment 20403 at exact head `e7b29219e11efd0a19395156ac0b154bec0c3a73`: **REQUEST CHANGES**.
- Blocker: the verifier echoed the pipeline commit but did not bind it to the current PR head; mutating only #2188's commit still returned terminal-green.
- Remediation: require `--expect-commit <full-40>`, add a pipeline anomaly on missing/mismatched record commits, emit expected and observed values, wire both CI documentation and the merge-gate baseline to pass provider PR head, and add match/missing/mismatch tests.
- This binding is not prohibited head-based clustering policy: it proves the evidence belongs to the commit under verdict. Runner/node/time/head correlation remains excluded from the teardown signature itself.
- Review 69 later approved the commit-binding remediation at exact head `033b2ffb46674b2c0bcc5197273c109b461f62d9`; pipeline #2193 was 9/9 success. Before merge-gate, an independent adjudicator found that Python treats JSON `false == 0`, allowing a non-integer exit value to match. The prior gate-ready state was withdrawn. The type-strict set distinguishes genuine red-first controls (`false`, `0.0`, which wrongly exempted) from regression guards (`true`, `"0"`, `null`, which already blocked). Remediation requires the decoded type to be exactly `int` and excludes `bool` explicitly.
## Documentation checklist
- [x] CI contract documented in the canonical framework CI/CD guide.
- [x] Operator command documented in the Woodpecker tool README.
- [x] Merge-gate baseline points to the deterministic verifier and named retirement.
- [x] Tracking and retirement cite issue #1000.
- [x] Both positive and negative guarantee boundaries are stated.
- [x] No API/auth/schema/user-facing navigation change; OpenAPI, user guide, and sitemap are not applicable.
## Risks
The controls establish discrimination for deterministic startup failure and an armed post-readiness postmaster crash on the current Woodpecker Kubernetes provider. They cannot prove that every future Kubernetes failure mode will preserve a non-zero exit before reconciliation. The exact matcher minimizes that residual risk, and issue #1000 remains the mandatory provider-seam closure and retirement trigger.
@@ -0,0 +1,90 @@
# RM-02 Gate Registry Scratchpad (#1029)
## Objective
Deliver the seven-gate registry and RED-first anti-inert verifier on `feat/rm-02-gate-registry`, preserving required-versus-actual defects without laundering them as success.
## Constraints and boundaries
- Do not modify `ci-queue-wait.sh`; RM-03 owns that fix.
- Do not modify `docs/remediation/TASKS.md`; workers cannot edit orchestrator tracking.
- Every declared behavior must be observed, not inferred from an exit code.
- Repository-local evidence does not establish same-authority tamper resistance; RM-25/RM-59 own the external trust anchor.
- Coverage is seven logical gates; broader inventory is RM-54.
- Budget assumption: no explicit token ceiling was supplied. Keep implementation dependency-free (stock Node), avoid repeated full monorepo installs, and keep generated test artifacts under the worktree/main disk.
## Plan
1. Update PRD and tracking references.
2. Write black-box meta-negative-control first and observe it fail for the missing verifier behavior.
3. Implement minimal manifest parser/case runner/mutation detector; observe meta-control succeed.
4. Add schema, coverage, provenance, prose marker, compatibility, discovery, deployment identity, and defect-delta tests RED-first.
5. Register seven gates with exact cases and run each case.
6. Add prospective per-commit replay and bounded provider-evidence reporting.
7. Wire unconditional Woodpecker CI and update developer/admin documentation.
8. Run situational and baseline verification, independent Codex review, remediate, commit, queue guard, push, PR, coordinator/reviewer handoff.
## Progress
- 2026-08-01: Design approved by `mos-remediation`; rulings A-E and source/deployed identity addition incorporated.
- 2026-08-01: Isolated worktree created from `origin/main` f65e9ea6; RM-01 f58b3699 verified as ancestor.
- 2026-08-01: Git author set to `f10-coder <[email protected]>`; provider issue #1029 created with `MOSAIC_GIT_IDENTITY=f10-coder`.
- 2026-08-01: Source/deployed queue-guard SHA-256 observed equal (`19cda2f...`); this observation is not yet an enforced property.
## Tests and RED-first evidence
- Meta-negative RED first: `node --test scripts/gate-verify.test.mjs` failed because the absent verifier did not name externally inerted `meta-fixture`.
- Structural RED: nine tests failed before implementation for internal mutation, unregistered executable, missing negative control, ownerless delta, unbound criterion/claim, modeled conflict, missing provenance, and deployment drift.
- Clause hardening RED: positive-only security criterion and missing registered claim marker both passed incorrectly before validation was added.
- CI wiring RED: package script and unconditional Woodpecker step tests both failed before wiring.
- History RED: history test failed with missing module before own-tree manifest selection/provider classification was implemented.
- `pnpm gate:verify`: exit 0; seven gates each reported `META-NEGATIVE-CONTROL ... observed red`; queue source/deployed drift control observed red; six queue behavior deltas printed as `DEFECT (owner: RM-03)`.
- Focused Node tests: 54/54 pass after third-round hardening (36 verifier/wiring plus 18 history/provider tests).
- `pnpm typecheck`: pass (45/45 Turbo tasks).
- `pnpm lint`: pass (25/25 Turbo tasks).
- `pnpm format:check`: pass.
- `pnpm test`: repository suites reached 45/46 Turbo tasks; all application/package tests shown passed, then the known host-specific wake assertion aborted exit 97 (`BASH_LINENO convention violated`, #973/D-16). No test was edited or bypassed. CI remains the authoritative full-suite environment.
## Self-surfaced defect
The queue guard's `get_state_from_status_json` runs `python3 - <<'PY'` while provider JSON is piped to the shell function. The heredoc owns stdin, so Python never reads provider JSON. Terminal success, no-status, terminal failure, and malformed payloads all classify as `unknown`; the associated fail-open outcomes are recorded under RM-03. No queue-guard source was modified.
## Independent review remediation
- Final pre-commit Codex code review found three blockers: a tautological deployment drift control, independently observed rather than combined compatibility cases, and unauthorized edits to orchestrator-owned `TASKS.md`.
- Deployment identity now uses one shared file comparator for both live equality and a temporary drifted deployed copy; a test makes that comparator inert and proves the meta-control fails.
- Compatibility scenarios now merge referenced fixtures/environments into one isolated construction and execute an exact scenario invocation; a test proves two independently valid fixtures coexist in the combined run.
- `TASKS.md` changes were reverted. `docs/remediation/GATE-CLAIMS.md` binds source headings and anchored text without editing orchestrator tracking.
- Codex security review found the Bubblewrap replay shared the runner PID namespace. Replay now unshares PID, IPC, and UTS namespaces, and an abuse-case test proves a sibling runner PID is invisible.
- Second review found empty reason diagnostics, final-symlink fixture writes, and lifecycle-script mutation of authoritative history files. Must-fail cases now require a reason pattern; writes use no-follow semantics; and replay snapshots every archived file before install and rejects any changed, deleted, or type/mode-shifted source before executing the verifier. Dedicated negative tests cover all three.
- Third code review found ambiguous duplicate provider steps and order-sensitive JSON outcome comparison. Provider evidence now requires exactly one `gate-verify` step in the authoritative rerun, and structural equality normalizes object keys. Both regressions have RED-first tests. Third security review reported no findings.
- Initial PR pipeline #2177 exposed Woodpecker's shallow boundary: the activation parent object was present but marked shallow, so `merge-base --is-ancestor` correctly refused to infer ancestry. The unconditional gate step now unshallows before ancestry/provenance checks; its wiring test was observed RED before the CI fix.
- Pipeline #2178 then proved the unprivileged Docker runner cannot establish Bubblewrap namespaces. A privileged experiment remained uncommitted and was rejected after Codex correctly rated it CRITICAL: PR-controlled code executes before an in-repository sandbox and could directly use the granted capability.
- `mos-remediation` and `rev-974` independently ruled Option C. RM02-REQ-10 now retains its original text, restatement, and reason: PR CI verifies only the current tree, unprivileged and fail-closed; isolated own-tree replay is deferred to RM-60/#1031's external pre-execution authority, cross-referenced with RM-59. Future protected post-merge replay is detection with quarantine/revert, never pre-merge prevention.
- RED-first boundary test proved the old path executed an inert intermediate verifier. The revised path states adjacent `DOES`/`DOES NOT` claims, validates historical manifest provenance without executing it, and infers no replay success. Direct sandbox tests remain hard-fail; unprivileged CI asserts terminal refusal instead of treating replay as success. Pipelines #2179/#2180/#2181 exposed two runner refusal forms: namespace denial as `spawnSync bwrap` with `error.code=EPERM`, and a test image without Bubblewrap as `error.code=ENOENT`. The replay diagnostic now preserves spawn errors. Parent-generated launcher/entry metadata distinguishes refusal before sandbox entry from child-controlled output; the detector recognizes exact `spawnSync bwrap` provenance for `EPERM`/`EACCES`/`ENOENT` and known namespace-refusal text only when the entry command provably did not run. Focused negative assertions reject unrelated `spawnSync git EPERM`, verifier output that merely says `bwrap ENOENT`, and exact namespace-denial impersonation without provenance or after sandbox entry.
- Exact-head independent review at `38f1b249` found one valid diagnostic-masking blocker: canonical verification knew four stable-ID rebinding failures but a thrown stale fixture replacement reached the outer catch first and emitted only the generic error. RED-first reproduction confirmed the canonical path omitted both responsible criterion IDs. Verification now collects labeled failures independently across claims, discovery, deployment, case execution/outcome checks, mutation, and compatibility, preserving structural stable-ID failures alongside the stale-fixture signal. The canonical regression test requires both missing-binding IDs and the generic fixture error.
- Exact-head independent review at `9b4d4beb` found two valid blockers. RED-first controls reproduced both: denial-looking child stderr was accepted as sandbox unavailability, and moving meaning/prose criterion IDs to an unrelated type-error case left `gate:verify` green. Bubblewrap execution now emits a parent-generated random entry marker and returns parent-owned launcher/entry metadata; unavailability requires Bubblewrap launcher provenance plus proof entry never ran, so exact denial impersonation from plain or entered-child results is rejected. Criterion objects now declare exact `caseRefs`, checked bidirectionally against case-side `criterionIds`; prose claims declare an exact must-fail `caseRef`. Registered must-fail cases move a criterion binding, remove meaning provenance, and redirect a prose claim, each producing its stable reason. The review freeze was deliberately lifted before remediation.
- Option C security review reported no findings. Code review rejected an initial unrelated typecheck binding for the new security criterion. It was replaced with a dedicated registered `privileged-pr-gate` case: the fixture injects a privilege key into the gate step, the wiring control rejects it for that exact reason, and `gate:verify` observes the boundary negative control. Follow-up hardening uses a closed exact gate-step construction, rejects privilege across the entire pipeline, rejects non-canonical/merged YAML keys, and pins the unrestricted PR/main trigger block; quoted/escaped/alias/merge/duplicate/filter bypass tests pass. Final Codex code review approved with no findings.
- Exact-head review at `83d2ecb2` found four silent-defeat paths. Genuine RED-first tests on the pre-fix code proved: author-controlled HEAD/parent/introduction seams produced no boundary failure; cross-commit duplicate pipeline number 7 returned terminal-success; and misspelling `outputPattern` as `outputPatern` in required/actual left canonical verification green. Fixes derive the seam from Git, validate provider identity globally before subject filtering, and recursively close/type-check nested schemas. New registry criteria `RM02-EVIDENCE-SUBJECT-BINDING`, `RM02-TYPE-STRICT-SCHEMA`, and `RM02-HISTORY-BOUNDARY` are bidirectionally bound to eight registered must-fail controls. The broad nested-object typo table and exact derived-boundary test are regression guards added after implementation, not claimed as RED-first. Pre-commit Codex review then found that global evidence failure was only observed—not failed—when HEAD was the sole prospective commit, and that non-object collection entries threw before normalization. Both were reproduced RED-first, then fixed by one collection validator used before iteration and by per-commit assessment. Follow-up review found collection validation still omitted exactly-one-gate-step cardinality for unrelated subjects; a focused test reproduced terminal-success RED-first, and collection validation now rejects that ambiguity globally. Security review then found present-but-empty outcome patterns were truthy-optional assertion bypasses; a reason-specific test reproduced that they lacked the required schema diagnostic, and present pattern fields now require non-whitespace content.
- Exact-head review at `32b490a7` found three population-level blockers. Genuine RED-first tests proved a gate change before author-delayed registry introduction fell outside the range, and empty criteria/gates/prose/scenario populations returned zero. History now anchors at the provider target merge-base; delayed introduction is a registered must-fail control. Production verification requires non-empty populations and a hardcoded seven-gate ID/source inventory before quantified checks. D-38/D-40 criteria now quantify over `gateRefs` exactly spanning every registered gate; each gate declares its evidence subject, and population controls mutate evidence subject and comparison type for every gate. The history record states both bootstrap directions: sound against a branch author unable to rewrite main, not sound against compromised/rewritten main, with residual owned by Builds 1-2. Pre-commit review rejected an initial production CLI `--fixture-profile` test relaxation as a vacuity bypass. That flag was removed; synthetic fixtures now use a non-executable test-support runner, while regression tests prove the shipped CLI rejects the flag and production population checks remain mandatory. Follow-up review then proved deleting `gateRefs` skipped population validation; a RED-first loop reproduced all three deletions, and the three general criterion IDs now require the field before exact-span validation.
## Documentation checklist
- PRD, developer guide, admin guide, governing claim index, sitemap, plan, and scratchpad updated.
- User/API documentation not applicable: no user workflow or API changed.
- Independent review documentation check pending rev-974 at the revised exact head.
- Canonical documentation remains in-repository; no external publication requested.
## Rebase onto RM-61
- Rebasing `f9746b23` onto main `f4fd5967` completed mechanically with no conflicts.
- The first post-rebase `pnpm gate:verify` correctly failed because the old activation seam `f65e9ea6` made the newly merged pre-registry RM-61 commit part of prospective history even though that commit predates the registry. An initial manifest update to `f4fd5967` had the right value but retained an author-controlled mechanism. Independent mutation proved HEAD, HEAD's parent, and the introduction commit could each make history coverage vacuous or partial. The manifest field is now forbidden; the verifier derives the boundary as the parent of the first first-parent registry-introduction commit, and registered must-fail controls reject all three unsafe candidates.
## Risks/blockers
- Current queue guard intentionally has required-versus-actual deltas owned by RM-03.
- Provider CI cannot report the currently executing pipeline as terminal success; current-commit evidence must be labeled pending and becomes historical current-tree evidence only after provider completion.
- Isolated per-commit execution requires RM-60/#1031. Until that external authority exists, no replay success is claimed. A future protected post-merge failure requires quarantine/revert.
- CI containers may not expose the operator-home deployed queue guard. In that layer the verifier checks the pinned observed digest and reports live identity unavailable under RM-04; it does not infer live equality.
@@ -0,0 +1,58 @@
# RM-01 — Reproducible checkout
- Task/ref: RM-01 (`docs/remediation/TASKS.md`, internal mission tracking)
- Objective: make checkout/install/typecheck hooks fail on code rather than environmental residue, for root CI and non-root seats.
- Scope: pnpm store configuration, transactional Husky installation, dependency/generated-state preflight, checkout regression tests, developer documentation.
- Constraints: isolated worktree; no skip-switch fixes; no writes under `/root` or `/tmp`; workers do not edit `docs/remediation/TASKS.md`; author does not review or merge.
- Acceptance: AC1AC8 from the orchestrator dispatch/addendum.
- Plan:
1. Add RED-first tests for missing dependencies, stale/foreign `.next`, and interrupted hook installation.
2. Implement environment-overridable HOME-based pnpm store defaults, deterministic preflight, and transactional hook installation.
3. Run focused tests, install/build/baseline gates, and explicit AC negative controls.
4. Obtain independent review, push after queue guard, open PR, and send evidence to `mos-remediation`.
- Budget: orchestrator estimate 6K/60K; no explicit hard token cap. Keep scope to RM-01 and avoid unrelated cleanup.
- Risks: 97%-full shared `/tmp`; native dependency install size; root-owned fixtures may require Docker for realistic verification.
## Progress / evidence
- Worktree created at `/home/hermes/agent-work/rm-01` from `origin/main` `06e0d403`.
- `/tmp` baseline: 28G used, 889M available (97%); worktree and planned store are on `/home`.
- Root causes confirmed from source: committed `.npmrc` pins `/root`; `prepare` invokes Husky directly; web typecheck includes generated `.next` types without validating ownership/freshness.
## Checkpoint evidence (c45e5e19)
- AC1 IN PROGRESS: non-root `pnpm install --frozen-lockfile --store-dir "$HOME/.local/share/pnpm/store"` exited 0; `pnpm exec turbo run typecheck --force` exited 0 (45/45 uncached). Clean CI-container run not performed.
- AC2 DONE: with `node_modules` absent, `pnpm preflight` exited 42 with `MOSAIC_PREFLIGHT_MISSING_DEPS` and `run pnpm install`; after install it exited 0.
- AC3 DONE: appending `export const x: number = "s"` to `packages/types/src/index.ts` made `pnpm -w typecheck` exit 2 with TS2322; reverting made it exit 0.
- AC4 IN PROGRESS: local `pnpm -w build` exited 0 and `git status --porcelain` showed no generated residue beyond the intended RM-01 source changes. Fresh-clone proof not performed.
- AC5 DONE: non-root install exited 0; `pnpm store path` resolved `/home/hermes/.local/share/pnpm/store/v10`; no `/root` write was attempted.
- AC6 IN PROGRESS: focused failure/rollback tests passed, but final review found a concurrent-install race. Two installers can both observe `.husky/_` absent; after one installs successfully, the losing install's catch path can quarantine the winner's active hooks and restore stale Git config (`scripts/install-hooks.mjs`, activation/catch transaction). A RED regression is committed after the checkpoint.
- AC7 DONE: install/store/worktree were on `/home`; full `pnpm -w build` exited 0; `/tmp` usage changed by 4096 bytes during the build (23,805,173,760 → 23,805,177,856 bytes), not materially.
- AC8 DONE for the implemented path: store resolves under `$HOME`; test/quarantine/build state resolves under the worktree; no implemented component requires a writable path outside `$HOME` or the worktree.
## Continuation evidence
- AC6 DONE: the committed race reproducer was observed RED (`node --test --test-name-pattern='a competing successful installer is not removed by the losing process' scripts/install-hooks.test.mjs`, exit 1/ENOENT), then passed after cleanup became ownership-safe. The losing installer never removes an active hook set or restores Git configuration it did not activate. `pnpm test:checkout` passes 21/21, exit 0, including the original race and a post-rename peer-replacement regression.
- Generated-state remediation: replaced mtime inference with a source/build-input fingerprint, written only after a serialized successful Next build with unchanged inputs. Failed/interrupted/overlapping builds leave no trusted marker. The fingerprint uses Next's own environment loader, covers resolved `NEXT_PUBLIC_*` values, inherited TypeScript configuration, lock/workspace inputs, and rejects symlink inputs.
- Baseline: `pnpm typecheck`, `pnpm lint`, and `pnpm format:check` each exit 0. Local `pnpm test` still exits 97 only at the pre-existing Bash `BASH_LINENO` convention guard (#973/#1003), after checkout tests and package tests pass; this is not reported as a green full-suite result.
- Automated review remediation: resolved findings for peer-hook ownership, stale/failed build markers, build-input changes, expanded environment inputs, inherited TypeScript config, symlink inputs, and overlapping build serialization. Independent PR review remains assigned to rev-974.
- AC1 DONE at `0f706119`: a clean clone created inside `git.mosaicstack.dev/mosaicstack/stack/ci-base:latest` ran the exact acceptance sequence `pnpm install --frozen-lockfile && pnpm -w typecheck`; exit 0 with 45/45 uncached typecheck tasks successful. An earlier bind-mounted clone attempt exited 1 because root in the container rejected the host-owned Git directory; that failed attempt is not counted as evidence.
- AC4 DONE at `0f706119`: in that same fresh clone and CI image, `pnpm -w build` completed 25/25 tasks and the immediately following `git status --porcelain` was empty; combined assertion exit 0.
- Push BLOCKED after the required queue guard: `git push origin fix/rm-01-reproducible-checkout` was rejected by Gitea with `User permission denied for writing` / `pre-receive hook declined`, despite `MOSAIC_GIT_IDENTITY=f10-coder` resolving username `f10-coder` from the provisioned `gitea-mosaicstack-f10-coder.token`.
## Review remediation — restated AC2
- Independent review correctly found that an added symlink under a successfully built `.next` tree passed preflight. The exact reviewer control, `ln -s /etc/hosts apps/web/.next/reviewer-symlink && pnpm preflight`, was observed passing before remediation.
- The original blanket symlink wording conflicts with AC4 because canonical Next `output: 'standalone'` emits legitimate pnpm dependency symlinks. The coordinator independently verified 42 such links and approved the operative restatement: `.next` itself must not be a symlink; descendant symlinks must exactly match the successful build's certified manifest.
- RED-first controls were observed failing together against the prior implementation (exit 1): `.next` root, added, removed, retargeted, tampered-manifest, and canonical-style certified-link cases. The build now publishes the manifest atomically before the existing source certification commit marker; that marker binds the manifest SHA-256. Missing/partial/modified manifests remain untrusted.
- GREEN evidence: the six-case symlink control passes; the exact reviewer-added link exits 43; removing it restores preflight exit 0. The added RED-first build-publication control also proves a symlinked `.next` cannot redirect certification writes outside the checkout. `pnpm test:checkout` passes 23 top-level tests / 29 including subtests. Canonical `pnpm --filter @mosaicstack/web build` and the following `pnpm preflight` both exit 0.
- Threat-model ruling: the manifest detects accidental, independent, stale, and foreign-residue mutation—the class exposed by the five-month-stale `.next` that produced 19 phantom TS2307 errors. It does not defend against a same-UID actor able to rewrite both manifest and marker consistently (CWE-345); no local worktree construction can without an external trust anchor. RM-59 tracks the residual: executor/spine-side attestation outside worktree authority, dependent on RM-12, RM-21, and RM-25.
- AC8 concrete proof at `df7530ae`: a clean clone ran in `ci-base:latest` with Docker `--read-only`; its only writable mounts were `/workspace` (the worktree) and `/home/ci` (`HOME`, with `NPM_CONFIG_STORE_DIR=/home/ci/store`). `pnpm install --frozen-lockfile && pnpm -w typecheck` exited 0 with 45/45 uncached tasks. This proves the implemented checkout path requires no writable location outside `$HOME` and the worktree. An initial fixture attempt failed only because Git required `/workspace` safe-directory setup; it is not counted as evidence.
## Handoff
1. Keep the newly committed RED tests red until implementing: (a) source-fingerprint marker support for valid incremental `.next` output, and (b) ownership-safe concurrent hook activation.
2. The latest automated review rejected oldest-generated-file mtime as a false positive for valid incremental Next output. Use a source-content fingerprint marker written only after successful `next build`; do not continue tuning mtimes.
3. For Husky, generation in an isolated temporary Git repo avoids mutating real `core.hooksPath` during staging. Preserve that design. Fix the losing concurrent process so it never removes a peer's completed hook set or restores stale config.
4. Codex review runs in a read-only sandbox, so its attempts to run the fixture-writing Node tests report opaque test-file failures. The same tests run normally in the worktree.
5. Full `pnpm test` is not green on this host: it exits 97 at the pre-existing Bash `BASH_LINENO` convention guard (#1003), after the changed checkout tests and package tests pass. Do not weaken that gate.
File diff suppressed because it is too large Load Diff
+7 -3
View File
@@ -6,11 +6,15 @@
"build": "turbo run build",
"dev": "turbo run dev",
"lint": "turbo run lint",
"typecheck": "turbo run typecheck",
"test": "turbo run test",
"gate:verify": "node scripts/gate-verify.mjs",
"preflight": "node scripts/preflight.mjs",
"clean:generated": "node scripts/clean-generated.mjs",
"typecheck": "pnpm preflight && turbo run typecheck",
"test:checkout": "node --test scripts/*.test.mjs",
"test": "pnpm test:checkout && turbo run test",
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
"prepare": "husky"
"prepare": "node scripts/install-hooks.mjs"
},
"devDependencies": {
"@typescript-eslint/eslint-plugin": "^8.0.0",
@@ -13,7 +13,14 @@ It is a **gate** role: the one and only merge path.
2. **Use the wrapped scripts as the ONLY merge path** — the merge-gate merges
**exclusively** by calling **`pr-merge.sh`** (the merge action, which carries the
authoritative forbidden-path guard) and **`pr-ci-wait.sh`** (to wait for green
CI before merging). These two scripts are the _only_ sanctioned merge path.
CI before merging). Before issuing a verdict, scan the full JSON/API child-step
record (including `clone`) with **`verify-terminal-green.py --expect-commit
<current-provider-PR-head>`** and record the equal expected/observed full-40
commits, exact step count, anomalies, and named exemptions. Missing or mismatched
commit binding is a hard refusal. The verifier's sole interim
exemption is `WP-K8S-1000-CI-POSTGRES-TEARDOWN`; it is signature-scoped, tracked
by #1000, and retires when #1000 is fixed. These scripts are the _only_
sanctioned merge path.
3. **Never call the raw API** — the merge-gate **does NOT** call `tea`, the raw
Gitea/forge HTTP API, or any other merge mechanism directly. Only `pr-merge.sh`
and `pr-ci-wait.sh`.
@@ -868,6 +868,38 @@ steps:
7. **Test on a short-lived non-main branch first** — open a PR and verify quality gates before merging to `main`
8. **Verify images appear** in Gitea Packages tab after successful pipeline
## Terminal-Green Full-Step Contract
A successful pipeline summary is not sufficient: verification MUST consume the full JSON/API child-step record, including `clone`.
```bash
PR_HEAD=<full-40-hex-provider-head>
~/.config/mosaic/tools/woodpecker/pipeline-status.sh \
-r mosaicstack/stack -n <pipeline-number> -f json \
| ~/.config/mosaic/tools/woodpecker/verify-terminal-green.py \
--expect-commit "$PR_HEAD" -
```
`PR_HEAD` MUST come from the current provider PR metadata and MUST be the full 40-hex head, not a local branch guess. The verifier fails if the argument is missing, malformed, absent from the pipeline record, or differs from that record.
The verifier reports the expected and observed commits, total step count, state counts, anomalies, and any applied exemption. Exit `0` means the record satisfies the contract; exit `1` means the commit binding or at least one pipeline, workflow, or child-step state blocks terminal-green; exit `2` means the invocation or JSON input could not be verified.
### Named interim exemption: `WP-K8S-1000-CI-POSTGRES-TEARDOWN`
Only this exact conjunction is exempted:
- pipeline and workflow state are `success`;
- exactly one non-success child exists;
- its name is `ci-postgres` and type is `service`;
- its state is `failure`, exit code is the JSON integer `0` (not boolean, float, string, or null); and
- its error exactly matches `pods "wp-svc-<ULID>-ci-postgres" not found`.
Every near miss remains blocking, including non-zero service exits, startup failures, post-readiness crashes, connection errors, image-pull errors, skipped steps, another failed child, malformed pod names, duplicate matches, or a non-success pipeline/workflow.
**Boundary in both directions:** this exemption recognizes the observed Woodpecker Kubernetes reconciliation miss after an otherwise-successful run. It does not prove that every future PostgreSQL or Kubernetes failure is distinguishable. It does prove, through provider controls, that a deterministic startup failure (`exit_code=1`) and an armed post-readiness postmaster crash (`exit_code=137`, dependent probe `Connection refused`) do not match and remain red.
**Tracking and retirement:** [mosaicstack/stack#1000](https://git.mosaicstack.dev/mosaicstack/stack/issues/1000) owns the provider-seam fix. This exemption MUST be removed when #1000 is fixed. It is not authority to retry or re-trigger a pipeline, and no per-PR re-roll is part of the contract.
## Post-Merge CI Monitoring (Hard Rule)
For source-code delivery, completion is not allowed at "PR opened" stage.
@@ -34,18 +34,12 @@ EOF
# get_remote_host and get_gitea_token are provided by detect-platform.sh
get_state_from_status_json() {
# Capture piped JSON BEFORE invoking `python3 - <<PY`. The heredoc binds
# stdin to the Python program text — so json.load(sys.stdin) inside would
# try to re-read stdin after `-` already consumed it for the program,
# yielding EOF and returning "unknown" every time. Pass payload via env.
local payload
payload=$(cat)
CI_QUEUE_STATUS_JSON="$payload" python3 - <<'PY'
python3 - <<'PY'
import json
import os
import sys
try:
payload = json.loads(os.environ.get("CI_QUEUE_STATUS_JSON", ""))
payload = json.load(sys.stdin)
except Exception:
print("unknown")
raise SystemExit(0)
@@ -89,15 +83,12 @@ PY
}
print_pending_contexts() {
# Same stdin hazard as get_state_from_status_json above — pass payload via env.
local payload
payload=$(cat)
CI_QUEUE_STATUS_JSON="$payload" python3 - <<'PY'
python3 - <<'PY'
import json
import os
import sys
try:
payload = json.loads(os.environ.get("CI_QUEUE_STATUS_JSON", ""))
payload = json.load(sys.stdin)
except Exception:
print("[ci-queue-wait] unable to decode status payload")
raise SystemExit(0)
@@ -1,205 +0,0 @@
#!/usr/bin/env bash
# Regression suite for #1019: ci-queue-wait.sh's status parser must return a
# state DERIVED FROM ITS INPUT.
#
# The defect this pins: both python sites piped a payload into `python3 - <<'PY'`.
# The heredoc binds stdin to the Python program text, so json.load(sys.stdin) saw
# EOF, the bare `except` fired, and the function returned "unknown" for every input
# — success, pending and failure alike. "unknown" then reaches an `exit 0` arm, so
# the gate-6 queue guard passed unconditionally on both the gitea and github paths.
#
# Every assertion below is on the RETURNED STATE STRING. A test that asserted only
# `rc=0` would have passed against the broken build, which is why this bug survived.
#
# The functions are extracted from the shipped wrapper rather than reimplemented, so
# this suite measures the code that actually runs.
set -uo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# Overridable so a mutation test can point the suite at a deliberately-broken copy
# without touching the tracked file. The earlier version of this suite required
# `git stash` + `git checkout` to do that, which left a repo-global stash entry
# that any sibling worktree could have popped onto an unrelated branch.
WRAPPER="${CI_QUEUE_WAIT_WRAPPER:-$SCRIPT_DIR/ci-queue-wait.sh}"
PASS=0
FAIL=0
pass() { printf ' PASS %s\n' "$1"; PASS=$((PASS + 1)); }
fail() { printf ' FAIL %s\n' "$1"; FAIL=$((FAIL + 1)); }
if [[ ! -f "$WRAPPER" ]]; then
printf 'FATAL: wrapper not found at %s\n' "$WRAPPER" >&2
exit 1
fi
TMPDIR_T="$(mktemp -d)"
trap 'rm -rf "$TMPDIR_T"' EXIT
extract_fn() {
# $1 = function name, $2 = source file, $3 = destination
sed -n "/^$1()/,/^}/p" "$2" > "$3"
[[ -s "$3" ]] || { printf 'FATAL: could not extract %s from %s\n' "$1" "$2" >&2; exit 1; }
}
extract_fn get_state_from_status_json "$WRAPPER" "$TMPDIR_T/state.sh"
extract_fn print_pending_contexts "$WRAPPER" "$TMPDIR_T/contexts.sh"
state_of() {
# shellcheck disable=SC1091
( source "$TMPDIR_T/state.sh"; printf '%s' "$1" | get_state_from_status_json )
}
expect_state() {
local label="$1" payload="$2" want="$3" got
got="$(state_of "$payload")"
if [[ "$got" == "$want" ]]; then
pass "$label -> $want"
else
fail "$label -> got '$got', want '$want'"
fi
}
echo "=== parser returns a state derived from its input (#1019) ==="
expect_state "success payload" \
'{"state":"success","statuses":[{"status":"success","context":"ci/build"}]}' \
'terminal-success'
expect_state "pending payload" \
'{"state":"pending","statuses":[{"status":"pending","context":"ci/build"}]}' \
'pending'
expect_state "failure payload" \
'{"state":"failure","statuses":[{"status":"failure","context":"ci/build"}]}' \
'terminal-failure'
expect_state "mixed success+pending is pending" \
'{"state":"pending","statuses":[{"status":"success"},{"status":"pending"}]}' \
'pending'
expect_state "running counts as pending" \
'{"state":"pending","statuses":[{"status":"running"}]}' \
'pending'
expect_state "error counts as failure" \
'{"state":"failure","statuses":[{"status":"error"}]}' \
'terminal-failure'
expect_state "empty status set is no-status" \
'{"state":"","statuses":[]}' \
'no-status'
# Control. This is the ONE input for which "unknown" is correct. Without it, a
# regression that hardcoded "unknown" again would still fail the cases above but
# the suite would give no signal that "unknown" remains reachable when it should be.
expect_state "undecodable payload stays unknown" \
'not json at all' \
'unknown'
expect_state "unrecognised status vocabulary is unknown" \
'{"state":"weird","statuses":[{"status":"weird"}]}' \
'unknown'
echo "=== pending contexts are reported to the operator ==="
contexts_of() {
# shellcheck disable=SC1091
( source "$TMPDIR_T/contexts.sh"; printf '%s' "$1" | print_pending_contexts )
}
out="$(contexts_of '{"statuses":[{"status":"pending","context":"ci/alpha"},{"status":"pending","context":"ci/beta"}]}')"
if grep -q 'ci/alpha' <<<"$out" && grep -q 'ci/beta' <<<"$out"; then
pass "both pending contexts emitted"
else
fail "pending contexts not emitted; got: $out"
fi
out="$(contexts_of '{"statuses":[{"status":"success","context":"ci/alpha"}]}')"
# Assert the POSITIVE message, not merely the absence of the context name. Absence
# alone is satisfied by total silence — and the pre-fix build was silent, so an
# absence-only assertion passed against the very defect this suite exists to catch.
if grep -q 'ci/alpha' <<<"$out"; then
fail "a non-pending context was emitted; got: $out"
elif grep -q 'no pending contexts' <<<"$out"; then
pass "non-pending context suppressed, and reported as 'no pending contexts'"
else
fail "expected an explicit 'no pending contexts' report; got: $out"
fi
echo "=== needle: the broken construct is caught, not merely absent today ==="
# Rebuild the pre-fix form and assert this suite would have failed against it.
# Without this, the suite proves the current file is correct but not that it can
# detect the defect returning.
BROKEN="$TMPDIR_T/broken.sh"
cat > "$BROKEN" <<'BROKEN_EOF'
get_state_from_status_json() {
python3 - <<'PY'
import json
import sys
try:
payload = json.load(sys.stdin)
except Exception:
print("unknown")
raise SystemExit(0)
print("terminal-success" if (payload.get("state") or "") == "success" else "pending")
PY
}
BROKEN_EOF
broken_got="$( ( source "$BROKEN"; printf '%s' '{"state":"success","statuses":[]}' | get_state_from_status_json ) )"
if [[ "$broken_got" == "unknown" ]]; then
pass "[NEEDLE ] pre-fix construct reproduces the defect (returns 'unknown' for a success payload)"
else
fail "[NEEDLE ] pre-fix construct did NOT reproduce the defect; got '$broken_got' — the needle no longer pins anything"
fi
# And assert the shipped wrapper does not contain that construct.
#
# The check must have HEREDOC SEMANTICS, not merely match the text. `json.load(sys.stdin)`
# is perfectly correct under `python3 -c '...'` — there the program comes from argv, so
# stdin really is the payload, and ci-queue-wait.sh uses that form legitimately in
# gitea_get_branch_head_sha. Only `python3 - <<DELIM` is defective, because `-` has
# already bound stdin to the program text.
#
# A flat `grep json\.load\(sys\.stdin\)` therefore fails on correct code. It did: the
# first version of this needle flagged the innocent `python3 -c` site. Same shape as
# #1018 F1 (a regex over raw text has no syntax semantics) reproduced inside the needle
# written to pin a different instance of it.
heredoc_stdin_sites() {
awk '
/python3[[:space:]]+-[[:space:]]*<</ {
d = $0
sub(/.*<<[[:space:]]*/, "", d)
gsub(/['"'"'"]/, "", d)
delim = d; inhd = 1; next
}
inhd && $0 == delim { inhd = 0; next }
inhd {
line = $0
sub(/[[:space:]]*#.*$/, "", line)
if (line ~ /sys\.stdin/) printf "%d: %s\n", FNR, $0
}
' "$1"
}
# Positive control FIRST. An empty result from a broken scanner looks exactly like a
# clean file, so the scanner is proven to fire before its silence is trusted.
if [[ -n "$(heredoc_stdin_sites "$BROKEN")" ]]; then
pass "[NEEDLE ] scanner detects a stdin read inside a python3-heredoc"
else
fail "[NEEDLE ] scanner did NOT fire on the known-broken form — its silence proves nothing"
fi
sites="$(heredoc_stdin_sites "$WRAPPER")"
if [[ -n "$sites" ]]; then
fail "[NEEDLE ] wrapper reads stdin inside a python3-heredoc at: $sites"
else
pass "[NEEDLE ] wrapper has no stdin read inside any python3-heredoc"
fi
printf '\nci-queue-wait parse: %d passed, %d failed\n' "$PASS" "$FAIL"
[[ "$FAIL" -eq 0 ]] || exit 1
@@ -26,12 +26,13 @@ A Woodpecker API token is required. To configure:
## Scripts
| Script | Purpose |
| --------------------- | -------------------------------------------- |
| `pipeline-list.sh` | List recent pipelines for a repo |
| `pipeline-status.sh` | Get status of a specific or latest pipeline |
| `pipeline-trigger.sh` | Trigger a new pipeline build |
| `ci-wait.sh` | Block until pipeline(s) reach terminal state |
| Script | Purpose |
| -------------------------- | -------------------------------------------------------------- |
| `pipeline-list.sh` | List recent pipelines for a repo |
| `pipeline-status.sh` | Get status of a specific or latest pipeline |
| `pipeline-trigger.sh` | Trigger a new pipeline build |
| `ci-wait.sh` | Block until pipeline(s) reach terminal state |
| `verify-terminal-green.py` | Verify every JSON/API child step under the bounded CI contract |
## Common Options
@@ -59,4 +60,9 @@ A Woodpecker API token is required. To configure:
# Block until one or more pipelines finish (event-driven CI wait)
~/.config/mosaic/tools/woodpecker/ci-wait.sh -r usc/uconnect -n 3917 -n 3918
# Verify the full JSON child-step record; do not use the text summary for this gate
PR_HEAD=<full-40-hex-provider-head>
~/.config/mosaic/tools/woodpecker/pipeline-status.sh -r mosaicstack/stack -n 2188 -f json \
| ~/.config/mosaic/tools/woodpecker/verify-terminal-green.py --expect-commit "$PR_HEAD" -
```
@@ -0,0 +1,109 @@
#!/usr/bin/env bash
# Red-first contract harness for RM-61 / #1000.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
VERIFIER="$SCRIPT_DIR/verify-terminal-green.py"
EXPECTED_COMMIT=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
TMP=$(mktemp -d)
trap 'rm -rf "$TMP"' EXIT
write_fixture() {
local file="$1" pipeline_status="$2" postgres_state="$3" postgres_exit="$4" postgres_error="$5" test_state="$6"
python3 - "$file" "$pipeline_status" "$postgres_state" "$postgres_exit" "$postgres_error" "$test_state" <<'PY'
import json, sys
path, pipeline_status, pg_state, pg_exit, pg_error, test_state = sys.argv[1:]
steps = [
{"name": "clone", "type": "clone", "state": "success", "exit_code": 0, "error": None},
{"name": "ci-postgres", "type": "service", "state": pg_state, "exit_code": int(pg_exit), "error": pg_error or None},
{"name": "test", "type": "commands", "state": test_state, "exit_code": 0 if test_state == "success" else 1, "error": None},
]
json.dump({
"number": 9999,
"status": pipeline_status,
"commit": "a" * 40,
"workflows": [{"name": "ci", "state": pipeline_status, "children": steps}],
}, open(path, "w"))
PY
}
expect_exit() {
local expected_exit="$1" label="$2" file="$3" expected_commit="${4:-$EXPECTED_COMMIT}"
set +e
output=$(python3 "$VERIFIER" --expect-commit "$expected_commit" "$file" 2>&1)
actual=$?
set -e
if [[ "$actual" -ne "$expected_exit" ]]; then
printf 'FAIL %s: expected exit %s, got %s\n%s\n' "$label" "$expected_exit" "$actual" "$output" >&2
exit 1
fi
printf 'PASS %s\n' "$label"
printf '%s' "$output"
}
# Ordinary terminal green.
write_fixture "$TMP/green.json" success success 0 '' success
out=$(expect_exit 0 green "$TMP/green.json")
grep -q '"total_steps": 3' <<<"$out"
grep -q '"exempted_steps": 0' <<<"$out"
# Exact, named #1000 teardown artifact: the only permitted non-success child.
artifact='pods "wp-svc-01kyxzjhdf6w81swsnbfzh85z9-ci-postgres" not found'
write_fixture "$TMP/artifact.json" success failure 0 "$artifact" success
out=$(expect_exit 0 exact-artifact "$TMP/artifact.json")
grep -q '"exemption_id": "WP-K8S-1000-CI-POSTGRES-TEARDOWN"' <<<"$out"
grep -q '"exempted_steps": 1' <<<"$out"
# Negative controls: both real PostgreSQL failures must remain red.
write_fixture "$TMP/startup.json" failure failure 1 '' failure
expect_exit 1 startup-failure "$TMP/startup.json" >/dev/null
write_fixture "$TMP/crash.json" failure failure 137 '' failure
expect_exit 1 post-readiness-crash "$TMP/crash.json" >/dev/null
# The exemption is signature-scoped, not step-scoped.
write_fixture "$TMP/wrong-error.json" success failure 0 'connection refused' success
expect_exit 1 other-postgres-error "$TMP/wrong-error.json" >/dev/null
write_fixture "$TMP/wrong-pod.json" success failure 0 'pods "other-ci-postgres" not found' success
expect_exit 1 wrong-pod-signature "$TMP/wrong-pod.json" >/dev/null
write_fixture "$TMP/nonzero-artifact.json" success failure 137 "$artifact" success
expect_exit 1 nonzero-with-artifact-text "$TMP/nonzero-artifact.json" >/dev/null
# JSON booleans and non-integer zero look equal to 0 in Python but are not exit codes.
python3 - "$TMP/artifact.json" "$TMP" <<'PY'
import json, os, sys
record = json.load(open(sys.argv[1]))
for label, value in (("false", False), ("true", True), ("float", 0.0), ("string", "0"), ("null", None)):
changed = json.loads(json.dumps(record))
changed["workflows"][0]["children"][1]["exit_code"] = value
json.dump(changed, open(os.path.join(sys.argv[2], f"exit-{label}.json"), "w"))
PY
for label in false true float string null; do
expect_exit 1 "non-integer-exit-$label" "$TMP/exit-$label.json" >/dev/null
done
# Exact artifact cannot mask any independent failure or non-success pipeline.
write_fixture "$TMP/artifact-plus-failure.json" failure failure 0 "$artifact" failure
expect_exit 1 artifact-plus-real-failure "$TMP/artifact-plus-failure.json" >/dev/null
write_fixture "$TMP/skipped.json" success success 0 '' skipped
expect_exit 1 skipped-step "$TMP/skipped.json" >/dev/null
# The scanned pipeline must be bound to an explicit, full PR-head commit.
set +e
missing_output=$(python3 "$VERIFIER" "$TMP/artifact.json" 2>&1)
missing_rc=$?
set -e
if [[ "$missing_rc" -ne 2 ]] || ! grep -q -- '--expect-commit' <<<"$missing_output"; then
printf 'FAIL missing-expected-commit: expected usage exit 2\n%s\n' "$missing_output" >&2
exit 1
fi
expect_exit 1 mismatched-expected-commit "$TMP/artifact.json" bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb >/dev/null
python3 - "$TMP/artifact.json" "$TMP/missing-record-commit.json" <<'PY'
import json, sys
record = json.load(open(sys.argv[1]))
record.pop("commit")
json.dump(record, open(sys.argv[2], "w"))
PY
expect_exit 1 missing-record-commit "$TMP/missing-record-commit.json" >/dev/null
printf 'terminal-green contract harness: PASS (17 cases)\n'
@@ -0,0 +1,230 @@
#!/usr/bin/env python3
"""Verify Mosaic's full-step Woodpecker terminal-green contract.
RM-61 permits one named, signature-scoped exception for issue #1000. The
exception retires when #1000 is fixed; all other non-success states block.
This program consumes the JSON/API record emitted by pipeline-status.sh -f json.
It does not fetch, retry, or re-trigger pipelines.
"""
from __future__ import annotations
import argparse
import json
import re
import sys
from collections import Counter
from pathlib import Path
from typing import Any
EXEMPTION_ID = "WP-K8S-1000-CI-POSTGRES-TEARDOWN"
EXEMPTION_ISSUE = "https://git.mosaicstack.dev/mosaicstack/stack/issues/1000"
POD_NOT_FOUND = re.compile(
r'^pods "wp-svc-[0-9a-hjkmnp-tv-z]{26}-ci-postgres" not found$'
)
def fail_usage(message: str) -> int:
print(f"terminal-green contract input error: {message}", file=sys.stderr)
return 2
def load_record(argument: str | None) -> dict[str, Any]:
if argument in (None, "-"):
value = json.load(sys.stdin)
else:
with Path(argument).open(encoding="utf-8") as handle:
value = json.load(handle)
if not isinstance(value, dict):
raise ValueError("pipeline record must be a JSON object")
return value
def is_issue_1000_artifact(step: dict[str, Any]) -> bool:
error = step.get("error")
exit_code = step.get("exit_code")
return (
step.get("name") == "ci-postgres"
and step.get("type") == "service"
and step.get("state") == "failure"
and type(exit_code) is int
and not isinstance(exit_code, bool)
and exit_code == 0
and isinstance(error, str)
and POD_NOT_FOUND.fullmatch(error) is not None
)
def verify(record: dict[str, Any], expected_commit: str) -> tuple[int, dict[str, Any]]:
anomalies: list[dict[str, Any]] = []
candidates: list[dict[str, Any]] = []
steps: list[dict[str, Any]] = []
pipeline_status = record.get("status")
actual_commit = record.get("commit")
if actual_commit != expected_commit:
anomalies.append(
{
"scope": "pipeline",
"name": str(record.get("number", "unknown")),
"state": pipeline_status,
"reason": "pipeline commit does not equal the expected PR head",
"expected_commit": expected_commit,
"actual_commit": actual_commit,
}
)
if pipeline_status != "success":
anomalies.append(
{
"scope": "pipeline",
"name": str(record.get("number", "unknown")),
"state": pipeline_status,
"reason": "pipeline status is not success",
}
)
workflows = record.get("workflows")
if not isinstance(workflows, list) or not workflows:
anomalies.append(
{
"scope": "pipeline",
"name": str(record.get("number", "unknown")),
"state": pipeline_status,
"reason": "workflows are missing or empty",
}
)
workflows = []
for workflow_index, workflow in enumerate(workflows):
if not isinstance(workflow, dict):
anomalies.append(
{
"scope": "workflow",
"name": str(workflow_index),
"state": None,
"reason": "workflow is not an object",
}
)
continue
workflow_name = str(workflow.get("name", workflow_index))
if workflow.get("state") != "success":
anomalies.append(
{
"scope": "workflow",
"name": workflow_name,
"state": workflow.get("state"),
"reason": "workflow state is not success",
}
)
children = workflow.get("children")
if not isinstance(children, list) or not children:
anomalies.append(
{
"scope": "workflow",
"name": workflow_name,
"state": workflow.get("state"),
"reason": "child-step list is missing or empty",
}
)
continue
for child_index, child in enumerate(children):
if not isinstance(child, dict):
anomalies.append(
{
"scope": "step",
"name": f"{workflow_name}[{child_index}]",
"state": None,
"reason": "step is not an object",
}
)
continue
steps.append(child)
if child.get("state") == "success":
continue
if is_issue_1000_artifact(child):
candidates.append(child)
continue
anomalies.append(
{
"scope": "step",
"name": child.get("name"),
"type": child.get("type"),
"state": child.get("state"),
"exit_code": child.get("exit_code"),
"error": child.get("error"),
"reason": "non-success step does not match the #1000 teardown signature",
}
)
if len(candidates) > 1:
anomalies.append(
{
"scope": "exemption",
"name": EXEMPTION_ID,
"state": "invalid",
"reason": "the #1000 exemption may apply to exactly one step",
}
)
exemption_applies = len(candidates) == 1 and not anomalies
state_counts = Counter(str(step.get("state", "missing")) for step in steps)
result: dict[str, Any] = {
"schema_version": "mosaic-terminal-green/v1",
"verdict": "terminal-green" if not anomalies else "not-terminal-green",
"pipeline_number": record.get("number"),
"commit": actual_commit,
"expected_commit": expected_commit,
"pipeline_status": pipeline_status,
"total_steps": len(steps),
"state_counts": dict(sorted(state_counts.items())),
"exempted_steps": 1 if exemption_applies else 0,
"anomalies": anomalies,
}
if exemption_applies:
candidate = candidates[0]
result["exemptions"] = [
{
"exemption_id": EXEMPTION_ID,
"step": candidate.get("name"),
"signature": candidate.get("error"),
"tracking_issue": EXEMPTION_ISSUE,
"retires_when": "issue #1000 is fixed",
}
]
else:
result["exemptions"] = []
return (0 if not anomalies else 1), result
def parse_arguments() -> argparse.Namespace:
parser = argparse.ArgumentParser(
description="verify the full Woodpecker terminal-green child-step contract"
)
parser.add_argument(
"--expect-commit",
required=True,
metavar="FULL_SHA",
help="full 40-hex PR-head commit that the pipeline record must match",
)
parser.add_argument("record", nargs="?", default="-", help="pipeline JSON file or -")
arguments = parser.parse_args()
if re.fullmatch(r"[0-9a-fA-F]{40}", arguments.expect_commit) is None:
parser.error("--expect-commit must be a full 40-hex commit")
arguments.expect_commit = arguments.expect_commit.lower()
return arguments
def main() -> int:
arguments = parse_arguments()
try:
record = load_record(arguments.record)
except (OSError, ValueError, json.JSONDecodeError) as error:
return fail_usage(str(error))
code, result = verify(record, arguments.expect_commit)
print(json.dumps(result, indent=2, sort_keys=True))
return code
if __name__ == "__main__":
raise SystemExit(main())
+1 -1
View File
@@ -25,7 +25,7 @@
"lint": "eslint src",
"typecheck": "tsc --noEmit",
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-parse.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
},
"dependencies": {
"@mosaicstack/brain": "workspace:*",
+146
View File
@@ -0,0 +1,146 @@
#!/usr/bin/env node
import { spawn } from 'node:child_process';
import { createHash, randomUUID } from 'node:crypto';
import { lstat, mkdir, readFile, rename, rm, writeFile } from 'node:fs/promises';
import { fileURLToPath } from 'node:url';
import path from 'node:path';
import { generatedSymlinkManifest, sourceFingerprint } from './preflight.mjs';
const scriptRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
function run(command, args, options) {
return new Promise((resolve, reject) => {
const child = spawn(command, args, options);
child.once('error', reject);
child.once('exit', (code, signal) => {
if (code === 0) resolve();
else
reject(
new Error(signal ? `next build terminated by ${signal}` : `next build exited ${code}`),
);
});
});
}
const delay = (milliseconds) => new Promise((resolve) => setTimeout(resolve, milliseconds));
async function requireRealDirectory(target, { allowMissing = false } = {}) {
try {
const stats = await lstat(target);
if (!stats.isDirectory() || stats.isSymbolicLink()) {
throw new Error(`${target} must be a real directory, not a symbolic link.`);
}
} catch (error) {
if (allowMissing && error.code === 'ENOENT') return;
throw error;
}
}
async function acquireBuildLock(root) {
const workRoot = path.join(root, '.mosaic-test-work');
const lock = path.join(workRoot, 'web-build.lock');
const nonce = randomUUID();
const owner = JSON.stringify({ pid: process.pid, nonce });
const deadline = Date.now() + 120_000;
await mkdir(workRoot, { recursive: true });
while (Date.now() < deadline) {
try {
await mkdir(lock);
await writeFile(path.join(lock, 'owner.json'), owner, { mode: 0o600 });
return async () => {
const current = await readFile(path.join(lock, 'owner.json'), 'utf8');
if (current !== owner) throw new Error('Web build lock ownership changed before release.');
const released = `${lock}.released-${nonce}`;
await rename(lock, released);
await rm(released, { recursive: true, force: true });
};
} catch (error) {
if (error.code !== 'EEXIST') throw error;
let lockOwner;
try {
lockOwner = JSON.parse(await readFile(path.join(lock, 'owner.json'), 'utf8'));
} catch (ownerError) {
if (ownerError.code === 'ENOENT') {
await delay(25);
continue;
}
throw new Error(`Web build lock is unreadable at ${lock}.`, { cause: ownerError });
}
try {
process.kill(lockOwner.pid, 0);
} catch (processError) {
if (processError.code !== 'ESRCH') throw processError;
const stale = `${lock}.stale-${nonce}`;
try {
await rename(lock, stale);
await rm(stale, { recursive: true, force: true });
} catch (renameError) {
if (renameError.code !== 'ENOENT') throw renameError;
}
continue;
}
await delay(25);
}
}
throw new Error(`Timed out waiting for the web build lock at ${lock}.`);
}
export async function buildWeb({
root = scriptRoot,
fingerprint = sourceFingerprint,
runBuild = async (webDir) =>
run(path.join(webDir, 'node_modules', '.bin', 'next'), ['build'], {
cwd: webDir,
stdio: 'inherit',
}),
} = {}) {
const releaseLock = await acquireBuildLock(root);
try {
const webDir = path.join(root, 'apps', 'web');
const nextDir = path.join(webDir, '.next');
const certificationMarker = path.join(nextDir, '.mosaic-source-hash');
const symlinkManifest = path.join(nextDir, '.mosaic-symlink-manifest');
const certificationTemporary = `${certificationMarker}.${randomUUID()}.tmp`;
const manifestTemporary = `${symlinkManifest}.${randomUUID()}.tmp`;
const before = await fingerprint(root);
await requireRealDirectory(nextDir, { allowMissing: true });
await Promise.all([
rm(certificationMarker, { force: true }),
rm(symlinkManifest, { force: true }),
]);
await runBuild(webDir);
await requireRealDirectory(nextDir);
const after = await fingerprint(root);
if (after !== before) {
throw new Error(
'Web build inputs changed during next build; generated output was not certified.',
);
}
const manifestContents = await generatedSymlinkManifest(nextDir);
const certificationContents = `${JSON.stringify({
version: 1,
sourceFingerprint: before,
symlinkManifestHash: createHash('sha256').update(manifestContents).digest('hex'),
})}\n`;
await Promise.all([
writeFile(certificationTemporary, certificationContents, { mode: 0o600 }),
writeFile(manifestTemporary, manifestContents, { mode: 0o600 }),
]);
// The certification marker is the commit point. Publishing the manifest first
// leaves interrupted builds untrusted because the marker remains absent.
await rename(manifestTemporary, symlinkManifest);
await rename(certificationTemporary, certificationMarker);
} finally {
await releaseLock();
}
}
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
await buildWeb();
}
+149
View File
@@ -0,0 +1,149 @@
import assert from 'node:assert/strict';
import { access, mkdir, readFile, rm, symlink, writeFile } from 'node:fs/promises';
import path from 'node:path';
import test from 'node:test';
import { buildWeb } from './build-web.mjs';
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `build-web-${process.pid}`);
async function fixture(name) {
const root = path.join(fixtureRoot, name);
await mkdir(path.join(root, 'apps', 'web', '.next'), { recursive: true });
return root;
}
async function exists(target) {
try {
await access(target);
return true;
} catch {
return false;
}
}
test.after(async () => {
await rm(fixtureRoot, { recursive: true, force: true });
});
test('a successful web build atomically publishes its source and symlink certification', async () => {
const root = await fixture('success');
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
await buildWeb({ root, fingerprint: async () => 'certified', runBuild: async () => {} });
assert.deepEqual(JSON.parse(await readFile(marker, 'utf8')), {
version: 1,
sourceFingerprint: 'certified',
symlinkManifestHash: '8a5a375cea6a55d24bd5f875856da63feba33adbefb15a92a0007719b84bcf11',
});
assert.equal(await readFile(manifest, 'utf8'), '{"version":1,"links":[]}\n');
});
test('a failed web build leaves no certification marker', async () => {
const root = await fixture('failure');
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
await writeFile(marker, 'stale\n');
await writeFile(manifest, 'stale\n');
await assert.rejects(
buildWeb({
root,
fingerprint: async () => 'before',
runBuild: async () => {
throw new Error('build failed');
},
}),
/build failed/,
);
assert.equal(await exists(marker), false);
assert.equal(await exists(manifest), false);
});
test('overlapping web builds are serialized while the marker remains absent', async () => {
const root = await fixture('overlap');
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
await writeFile(marker, 'stale\n');
await writeFile(manifest, 'stale\n');
let releaseFirst;
let secondEntered = false;
const firstEntered = new Promise((resolve) => {
releaseFirst = resolve;
});
let markFirstEntered;
const firstStarted = new Promise((resolve) => {
markFirstEntered = resolve;
});
const first = buildWeb({
root,
fingerprint: async () => 'certified',
runBuild: async () => {
markFirstEntered();
await firstEntered;
},
});
await firstStarted;
const second = buildWeb({
root,
fingerprint: async () => 'certified',
runBuild: async () => {
secondEntered = true;
},
});
await new Promise((resolve) => setTimeout(resolve, 75));
assert.equal(secondEntered, false);
assert.equal(await exists(marker), false);
assert.equal(await exists(manifest), false);
releaseFirst();
await Promise.all([first, second]);
assert.equal(secondEntered, true);
assert.equal(JSON.parse(await readFile(marker, 'utf8')).sourceFingerprint, 'certified');
assert.equal(await readFile(manifest, 'utf8'), '{"version":1,"links":[]}\n');
});
test('a build that replaces .next with a symbolic link cannot publish outside the checkout', async () => {
const root = await fixture('symbolic-next');
const nextDir = path.join(root, 'apps', 'web', '.next');
const outside = path.join(root, 'outside-generated');
await mkdir(outside);
await assert.rejects(
buildWeb({
root,
fingerprint: async () => 'certified',
runBuild: async () => {
await rm(nextDir, { recursive: true });
await symlink(outside, nextDir);
},
}),
/must be a real directory/,
);
assert.equal(await exists(path.join(outside, '.mosaic-source-hash')), false);
assert.equal(await exists(path.join(outside, '.mosaic-symlink-manifest')), false);
});
test('inputs changed during a web build are not certified', async () => {
const root = await fixture('changed-inputs');
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
const fingerprints = ['before', 'after'];
await assert.rejects(
buildWeb({
root,
fingerprint: async () => fingerprints.shift(),
runBuild: async () => {},
}),
/inputs changed during next build/,
);
assert.equal(await exists(marker), false);
assert.equal(await exists(manifest), false);
});
+34
View File
@@ -0,0 +1,34 @@
#!/usr/bin/env node
import { access, mkdir, rename, rm } from 'node:fs/promises';
import path from 'node:path';
const root = process.cwd();
const generated = path.join(root, 'apps', 'web', '.next');
const quarantineRoot = path.join(root, '.mosaic-test-work', 'generated-quarantine');
try {
await access(generated);
} catch (error) {
if (error.code === 'ENOENT') process.exit(0);
throw error;
}
await mkdir(quarantineRoot, { recursive: true });
const quarantine = path.join(quarantineRoot, `web-next-${Date.now()}-${process.pid}`);
try {
await rename(generated, quarantine);
} catch (error) {
console.error(
`MOSAIC_GENERATED_CLEAN_FAILED: could not quarantine apps/web/.next. Fix: sudo rm -rf '${generated}', then rerun pnpm preflight`,
);
throw error;
}
try {
await rm(quarantine, { recursive: true, force: true });
} catch {
console.warn(
`Generated state was deactivated but could not be deleted; quarantined at ${quarantine}`,
);
}
@@ -0,0 +1,56 @@
#!/usr/bin/env node
import { mkdtemp, mkdir, rm, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { spawnSync } from 'node:child_process';
import { verifyHistory } from './gate-history.mjs';
const root = await mkdtemp(path.join(os.tmpdir(), 'gate-delayed-introduction-'));
function git(...args) {
const result = spawnSync(
'git',
['-c', 'user.name=gate-control', '-c', '[email protected]', ...args],
{ cwd: root, encoding: 'utf8' },
);
if (result.status !== 0) throw new Error(result.stderr || result.stdout);
return result.stdout.trim();
}
try {
git('init', '-q');
await writeFile(path.join(root, 'baseline.txt'), 'baseline\n');
git('add', '.');
git('commit', '-m', 'provider target baseline');
const baseline = git('rev-parse', 'HEAD');
git('update-ref', 'refs/remotes/origin/main', baseline);
await mkdir(path.join(root, 'scripts'), { recursive: true });
await writeFile(path.join(root, 'scripts', 'preflight.mjs'), 'process.exit(0);\n');
git('add', '.');
git('commit', '-m', 'gate change before registry');
const unregisteredCommit = git('rev-parse', 'HEAD');
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
git('add', '.');
git('commit', '-m', 'delayed registry introduction');
const previousBranch = process.env.CI_COMMIT_BRANCH;
process.env.CI_COMMIT_BRANCH = 'feature/delayed-introduction-control';
let result;
try {
result = await verifyHistory({ root, manifest: { schemaVersion: 1 } });
} finally {
if (previousBranch === undefined) delete process.env.CI_COMMIT_BRANCH;
else process.env.CI_COMMIT_BRANCH = previousBranch;
}
const detail = result.failures.join('\n');
if (detail.includes(unregisteredCommit) && /own-tree registry cannot be read/i.test(detail)) {
process.stderr.write(`delayed registry introduction rejected: ${detail}\n`);
process.exitCode = 1;
} else {
process.stdout.write('delayed registry introduction was not rejected\n');
}
} finally {
await rm(root, { recursive: true, force: true });
}
+45
View File
@@ -0,0 +1,45 @@
#!/usr/bin/env node
import { mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { verifyRegistry } from './gate-verify.mjs';
const root = process.cwd();
const manifest = JSON.parse(await readFile(path.join(root, 'gates/gates.manifest.json'), 'utf8'));
manifest.gateRoots = ['.mosaic-empty-gate-root'];
manifest.criteria = [];
manifest.gates = [];
manifest.proseClaims = [];
manifest.compatibilityScenarios = [];
const directory = await mkdtemp(path.join(os.tmpdir(), 'gate-empty-population-'));
try {
const manifestPath = path.join(directory, 'manifest.json');
await writeFile(manifestPath, `${JSON.stringify(manifest)}\n`);
const result = await verifyRegistry({
root,
manifest: manifestPath,
skipHistory: true,
structureOnly: true,
fixtureProfile: false,
});
const required = ['criteria', 'gates', 'proseClaims', 'compatibilityScenarios'];
const missing = required.filter(
(population) =>
!result.failures.some((failure) =>
failure.includes(`${population} population must be non-empty and anchored`),
),
);
if (missing.length > 0) {
process.stdout.write(`empty populations were not rejected: ${missing.join(', ')}\n`);
process.exitCode = 0;
} else {
process.stderr.write(
'empty universally quantified registry populations rejected before evaluation\n',
);
process.exitCode = 1;
}
} finally {
await rm(directory, { recursive: true, force: true });
}
+40
View File
@@ -0,0 +1,40 @@
#!/usr/bin/env node
import { spawnSync } from 'node:child_process';
import { deriveHistoryBoundary } from './gate-history.mjs';
const candidateKind = process.argv[2];
const root = process.cwd();
const boundary = deriveHistoryBoundary(root);
function revParse(revision) {
const result = spawnSync('git', ['rev-parse', revision], {
cwd: root,
encoding: 'utf8',
});
if (result.status !== 0) {
process.stderr.write(`history boundary control could not resolve ${revision}\n`);
process.exit(2);
}
return result.stdout.trim();
}
const candidates = {
head: revParse('HEAD'),
parent: revParse('HEAD^'),
introduction: boundary.introductionCommit,
};
if (!Object.hasOwn(candidates, candidateKind)) {
process.stderr.write(`unknown history boundary candidate ${String(candidateKind)}\n`);
process.exit(2);
}
const candidate = candidates[candidateKind];
if (candidate === boundary.activationCommit) {
process.stdout.write(`history boundary candidate ${candidateKind} matched derived activation\n`);
process.exit(0);
}
process.stderr.write(
`history boundary candidate ${candidateKind} rejected: derived activation is provider target merge-base\n`,
);
process.exit(1);
+432
View File
@@ -0,0 +1,432 @@
import { existsSync } from 'node:fs';
import { createHash, randomUUID } from 'node:crypto';
import { access, lstat, mkdir, mkdtemp, readFile, readdir, readlink, rm } from 'node:fs/promises';
import { spawnSync } from 'node:child_process';
import path from 'node:path';
function git(root, args, { allowFailure = false } = {}) {
const result = spawnSync('git', args, { cwd: root, encoding: 'utf8' });
if (result.status !== 0 && !allowFailure) {
throw new Error(`git ${args.join(' ')} failed: ${(result.stderr || result.stdout).trim()}`);
}
return result;
}
export async function listProspectiveCommits(root, activationCommit, head = 'HEAD') {
const result = git(root, [
'rev-list',
'--first-parent',
'--reverse',
`${activationCommit}..${head}`,
]);
return result.stdout.trim() ? result.stdout.trim().split('\n') : [];
}
export function deriveHistoryBoundary(root, head = 'HEAD') {
const targetRef = 'refs/remotes/origin/main';
const target = git(root, ['rev-parse', '--verify', targetRef], { allowFailure: true });
if (target.status !== 0 || !target.stdout.trim()) {
throw new Error(`history boundary cannot be derived: provider target ${targetRef} is absent`);
}
const introductions = git(root, [
'log',
'--first-parent',
'--diff-filter=A',
'--format=%H',
'--reverse',
head,
'--',
'gates/gates.manifest.json',
])
.stdout.trim()
.split('\n')
.filter(Boolean);
if (introductions.length === 0) {
throw new Error('history boundary cannot be derived: registry introduction is absent');
}
const introductionCommit = introductions[0];
const headOnTarget = git(root, ['merge-base', '--is-ancestor', head, targetRef], {
allowFailure: true,
});
const activation =
headOnTarget.status === 0
? git(root, ['rev-parse', `${head}^`], { allowFailure: true })
: git(root, ['merge-base', head, targetRef], { allowFailure: true });
if (activation.status !== 0 || !activation.stdout.trim()) {
throw new Error(
`history boundary cannot be derived: provider target merge-base for ${head} is unavailable`,
);
}
return {
activationCommit: activation.stdout.trim(),
introductionCommit,
targetRef,
};
}
export async function readManifestAtCommit(root, commit) {
const result = git(root, ['show', `${commit}:gates/gates.manifest.json`]);
return JSON.parse(result.stdout);
}
async function snapshotAuthoritativeTree(root) {
const snapshot = new Map();
async function walk(current) {
for (const child of await readdir(current, { withFileTypes: true })) {
if (['.git', '.home', 'node_modules'].includes(child.name)) continue;
const absolute = path.join(current, child.name);
const relative = path.relative(root, absolute).split(path.sep).join('/');
const stats = await lstat(absolute);
if (stats.isDirectory()) {
await walk(absolute);
} else if (stats.isSymbolicLink()) {
snapshot.set(relative, `symlink:${stats.mode}:${await readlink(absolute)}`);
} else if (stats.isFile()) {
const digest = createHash('sha256')
.update(await readFile(absolute))
.digest('hex');
snapshot.set(relative, `file:${stats.mode}:${digest}`);
}
}
}
await walk(root);
return snapshot;
}
async function authoritativeTreeChanges(root, snapshot) {
const changes = [];
for (const [relative, expected] of snapshot) {
const absolute = path.join(root, relative);
let actual;
try {
const stats = await lstat(absolute);
if (stats.isSymbolicLink()) {
actual = `symlink:${stats.mode}:${await readlink(absolute)}`;
} else if (stats.isFile()) {
const digest = createHash('sha256')
.update(await readFile(absolute))
.digest('hex');
actual = `file:${stats.mode}:${digest}`;
} else {
actual = `other:${stats.mode}`;
}
} catch (error) {
if (error.code !== 'ENOENT') throw error;
actual = 'missing';
}
if (actual !== expected) changes.push(relative);
}
return changes;
}
function bubblewrap(root, command, args, { storePath, timeout = 300_000 } = {}) {
const sandboxArgs = [
'--unshare-net',
'--unshare-pid',
'--unshare-ipc',
'--unshare-uts',
'--die-with-parent',
'--new-session',
'--clearenv',
];
for (const systemPath of ['/usr', '/bin', '/lib', '/lib64', '/etc']) {
if (existsSync(systemPath)) sandboxArgs.push('--ro-bind', systemPath, systemPath);
}
sandboxArgs.push('--dev', '/dev', '--proc', '/proc', '--tmpfs', '/tmp', '--bind', root, '/work');
if (storePath) sandboxArgs.push('--ro-bind', storePath, '/pnpm-store');
const corepackHome = path.join(process.env.HOME ?? '', '.cache', 'node', 'corepack');
if (existsSync(corepackHome)) sandboxArgs.push('--ro-bind', corepackHome, '/corepack');
sandboxArgs.push(
'--chdir',
'/work',
'--setenv',
'HOME',
'/work/.home',
'--setenv',
'PATH',
'/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin',
'--setenv',
'LANG',
'C.UTF-8',
'--setenv',
'CI',
'true',
);
if (storePath) sandboxArgs.push('--setenv', 'NPM_CONFIG_STORE_DIR', '/pnpm-store');
if (existsSync(corepackHome)) sandboxArgs.push('--setenv', 'COREPACK_HOME', '/corepack');
const enteredMarker = `__MOSAIC_BWRAP_ENTERED_${randomUUID()}__`;
sandboxArgs.push(
'/bin/sh',
'-c',
'printf "%s\\n" "$1"; shift; exec "$@"',
'mosaic-bwrap-entry',
enteredMarker,
command,
...args,
);
const result = spawnSync('bwrap', sandboxArgs, { encoding: 'utf8', timeout });
const sandboxEntered = result.stdout?.includes(enteredMarker) === true;
return {
...result,
stdout: (result.stdout ?? '').replace(`${enteredMarker}\n`, ''),
sandboxLauncher: 'bwrap',
sandboxEntered,
};
}
export async function replayCommit(root, commit) {
const replayRoot = await mkdtemp(
path.join(path.dirname(root), `.gate-history-${commit.slice(0, 12)}-`),
);
const archive = `${replayRoot}.tar`;
try {
git(root, ['archive', '--format=tar', `--output=${archive}`, commit]);
const extract = spawnSync('tar', ['-xf', archive, '-C', replayRoot], { encoding: 'utf8' });
if (extract.status !== 0) {
return { status: extract.status, stdout: extract.stdout, stderr: extract.stderr };
}
const authoritativeSnapshot = await snapshotAuthoritativeTree(replayRoot);
await mkdir(path.join(replayRoot, '.home'), { recursive: true });
let storePath;
try {
await access(path.join(replayRoot, 'package.json'));
const init = spawnSync('git', ['init', '--quiet', replayRoot], { encoding: 'utf8' });
if (init.status !== 0) return init;
const store = spawnSync('pnpm', ['store', 'path'], { encoding: 'utf8' });
if (store.status !== 0) return store;
storePath = store.stdout.trim();
const install = bubblewrap(
replayRoot,
'pnpm',
['install', '--frozen-lockfile', '--offline'],
{ storePath, timeout: 600_000 },
);
if (install.status !== 0 || install.error || install.signal) {
return {
...install,
stderr: `historical frozen dependency install failed: ${install.error?.message || install.stderr || install.stdout || ''}`,
};
}
const authoritativeChanges = await authoritativeTreeChanges(
replayRoot,
authoritativeSnapshot,
);
if (authoritativeChanges.length > 0) {
return {
status: 1,
stdout: '',
stderr: `authoritative archived file changed during historical install: ${authoritativeChanges.join(', ')}`,
};
}
} catch (error) {
if (error.code !== 'ENOENT') throw error;
}
return bubblewrap(
replayRoot,
process.execPath,
[
'/work/scripts/gate-verify.mjs',
'--root',
'/work',
'--manifest',
'gates/gates.manifest.json',
'--skip-history',
],
{ storePath },
);
} finally {
await rm(archive, { force: true });
await rm(replayRoot, { recursive: true, force: true });
}
}
export function validateProviderEvidenceCollection(pipelines) {
if (!Array.isArray(pipelines)) return 'provider evidence collection is malformed';
const pipelineStates = new Set(['success', 'failure', 'error', 'pending', 'running', 'queued']);
const stepStates = new Set([
'success',
'failure',
'error',
'pending',
'running',
'queued',
'skipped',
]);
const malformed = pipelines.some(
(candidate) =>
!candidate ||
typeof candidate !== 'object' ||
Array.isArray(candidate) ||
typeof candidate.commit !== 'string' ||
candidate.commit.length === 0 ||
!Number.isInteger(candidate.number) ||
!pipelineStates.has(candidate.status) ||
!Array.isArray(candidate.steps) ||
candidate.steps.some(
(step) =>
!step ||
typeof step !== 'object' ||
Array.isArray(step) ||
typeof step.name !== 'string' ||
typeof step.status !== 'string' ||
!stepStates.has(step.status),
),
);
if (malformed) return 'provider records are malformed';
const ambiguousGateRecord = pipelines.find(
(candidate) => candidate.steps.filter((step) => step.name === 'gate-verify').length !== 1,
);
if (ambiguousGateRecord) {
const count = ambiguousGateRecord.steps.filter((step) => step.name === 'gate-verify').length;
return `provider record ${ambiguousGateRecord.number} has ambiguous gate-verify step count ${count}`;
}
const numbers = pipelines.map((candidate) => candidate.number);
if (new Set(numbers).size !== numbers.length) {
return 'duplicate pipeline identity across commits in provider evidence collection';
}
return undefined;
}
export function assessProviderEvidence(commit, pipelines) {
const collectionFailure = validateProviderEvidenceCollection(pipelines);
if (collectionFailure) {
return {
state: 'terminal-failure',
detail: collectionFailure,
};
}
const matches = pipelines.filter((candidate) => candidate.commit === commit);
if (matches.length === 0) {
return {
state: 'absent',
detail:
'no retained provider record was supplied; retention expiry and never-ran are not inferred',
};
}
const pipeline = [...matches].sort((left, right) => right.number - left.number)[0];
const gateSteps = (pipeline.steps ?? []).filter((step) => step.name === 'gate-verify');
if (gateSteps.length !== 1) {
return {
state: 'terminal-failure',
detail: `provider record has ambiguous gate-verify step count ${gateSteps.length}`,
};
}
const [gateStep] = gateSteps;
if (pipeline.status === 'success' && gateStep.status === 'success') {
return { state: 'terminal-success', detail: 'pipeline and gate-verify step succeeded' };
}
if (['pending', 'running', 'queued'].includes(pipeline.status)) {
return { state: 'current-running', detail: `pipeline is ${pipeline.status}` };
}
return {
state: 'terminal-failure',
detail: `pipeline=${pipeline.status ?? 'unknown'}, gate-verify=${gateStep?.status ?? 'absent'}`,
};
}
async function loadProviderEvidence() {
const evidenceFile = process.env.GATE_PROVIDER_EVIDENCE_FILE;
if (!evidenceFile) return [];
const parsed = JSON.parse(await readFile(evidenceFile, 'utf8'));
if (!Array.isArray(parsed)) throw new Error('provider evidence file must contain a JSON array');
return parsed;
}
function isMainCommit(root, head) {
if (process.env.CI_COMMIT_BRANCH === 'main') return true;
const result = git(root, ['merge-base', '--is-ancestor', head, 'refs/remotes/origin/main'], {
allowFailure: true,
});
return result.status === 0;
}
export async function verifyHistory({ root, manifest }) {
const failures = [];
const observations = [];
const head = git(root, ['rev-parse', 'HEAD']).stdout.trim();
if (Object.hasOwn(manifest, 'activationCommit')) {
failures.push(
'author-controlled activationCommit is forbidden; history boundary is derived from the registry introduction',
);
}
let boundary;
try {
boundary = deriveHistoryBoundary(root, head);
} catch (error) {
failures.push(error.message);
return { failures, observations };
}
const onMain = isMainCommit(root, head);
// RM-02 history bootstrap boundary (Builds 1-2), kept adjacent in both directions:
// DOES: anchor feature history to the provider target merge-base, sound against an author who
// cannot rewrite main.
// DOES NOT: establish integrity when main itself is compromised; Builds 1-2 own that residual.
observations.push(
`RM-02 HISTORY BOOTSTRAP BOUNDARY ${head}: DOES: anchor the audited range to provider target ${boundary.targetRef} at merge-base ${boundary.activationCommit}, sound against a branch author who cannot rewrite main; DOES NOT: protect against compromise or rewrite of main; residual owner Builds 1-2`,
);
// RM-02 execution boundary (RM-60, cross-reference RM-59), kept adjacent in both directions:
// DOES: run every registered current-tree gate and declared inerting mutation on PR CI,
// unprivileged and fail-closed.
// DOES NOT: execute a commit's own verifier in an isolated PR replay. PR-controlled code would
// otherwise need the namespace capability intended to contain that same code. That external
// trust boundary must be runner/provider-owned before any PR executable or config is evaluated.
observations.push(
`RM-02 EXECUTION BOUNDARY ${head}: DOES: verify the current tree and declared inerting mutations on every PR, unprivileged and fail-closed; DOES NOT: execute isolated per-commit verifier replay in repository-controlled CI; owner RM-60, cross-reference RM-59`,
);
if (!onMain) {
observations.push(
`PROVIDER ASSERTION DEFERRED ${head}: commit is not yet on main; retained provider evidence starts after merge and no replay success is inferred`,
);
}
const pipelines = onMain ? await loadProviderEvidence() : [];
const collectionFailure = validateProviderEvidenceCollection(pipelines);
if (collectionFailure) {
failures.push(`provider evidence collection invalid: ${collectionFailure}`);
}
const commits = await listProspectiveCommits(root, boundary.activationCommit, head);
for (const commit of commits) {
let commitManifest;
try {
commitManifest = await readManifestAtCommit(root, commit);
} catch (error) {
failures.push(`${commit}: own-tree registry cannot be read: ${error.message}`);
continue;
}
if (commitManifest.schemaVersion !== manifest.schemaVersion) {
failures.push(`${commit}: own-tree registry schema is not supported`);
continue;
}
const evidence = assessProviderEvidence(commit, pipelines);
if (commit === head) {
observations.push(
`CURRENT TREE EVALUATED ${commit}: all registered cases ran from this checkout; provider evidence=${evidence.state} (${evidence.detail})`,
);
continue;
}
observations.push(
`INTERMEDIATE REPLAY DEFERRED ${commit}: isolated own-tree execution is not performed by repository-controlled CI; owner RM-60, cross-reference RM-59; no success is inferred`,
);
if (!onMain) {
observations.push(
`PROVIDER EVIDENCE ${commit}: DEFERRED until the commit is on main; no success is inferred`,
);
continue;
}
observations.push(
`POST-MERGE DETECTION BOUNDARY ${commit}: protected isolated replay awaits RM-60; when available, a failure requires quarantine/revert and is detection, not pre-merge prevention`,
);
if (evidence.state === 'terminal-failure') {
failures.push(
`${commit}: retained provider evidence is not terminal-success (${evidence.detail})`,
);
} else if (evidence.state === 'terminal-success') {
observations.push(`PROVIDER EVIDENCE ${commit}: terminal-success (${evidence.detail})`);
} else {
observations.push(
`PROVIDER EVIDENCE ${commit}: ${evidence.state.toUpperCase()} (${evidence.detail}); no merge-time success is inferred`,
);
}
}
return { failures, observations };
}
+615
View File
@@ -0,0 +1,615 @@
import assert from 'node:assert/strict';
import { mkdir, rm, writeFile } from 'node:fs/promises';
import path from 'node:path';
import { spawn, spawnSync } from 'node:child_process';
import test from 'node:test';
import {
assessProviderEvidence,
deriveHistoryBoundary,
listProspectiveCommits,
readManifestAtCommit,
replayCommit,
verifyHistory,
} from './gate-history.mjs';
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `gate-history-${process.pid}`);
function sandboxUnavailable(result) {
if (result.sandboxLauncher !== 'bwrap' || result.sandboxEntered === true) return false;
const detail = `${result.stdout ?? ''}${result.stderr ?? ''}${result.error?.message ?? ''}`;
const bubblewrapSpawnDenied =
['EPERM', 'EACCES', 'ENOENT'].includes(result.error?.code) &&
/spawnSync bwrap/i.test(result.error?.message ?? '');
if (
!bubblewrapSpawnDenied &&
!/bwrap:.*(?:Operation not permitted|Creating new namespace failed)/i.test(detail)
) {
return false;
}
assert.notEqual(result.status, 0, 'sandbox unavailability must remain terminal nonzero');
return true;
}
function git(root, ...args) {
const result = spawnSync('git', args, { cwd: root, encoding: 'utf8' });
assert.equal(result.status, 0, result.stderr);
return result.stdout.trim();
}
async function commitManifest(root, marker) {
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(
path.join(root, 'gates', 'gates.manifest.json'),
`${JSON.stringify({ schemaVersion: 1, marker })}\n`,
);
git(root, 'add', '.');
git(root, 'commit', '-m', marker);
return git(root, 'rev-parse', 'HEAD');
}
test.after(async () => {
await rm(fixtureRoot, { recursive: true, force: true });
});
test('sandbox refusal classification requires Bubblewrap provenance', () => {
for (const code of ['EPERM', 'EACCES', 'ENOENT']) {
assert.equal(
sandboxUnavailable({
status: null,
error: { code, message: `spawnSync bwrap ${code}` },
sandboxLauncher: 'bwrap',
sandboxEntered: false,
}),
true,
);
}
assert.equal(
sandboxUnavailable({
status: null,
error: { code: 'EPERM', message: 'spawnSync git EPERM' },
}),
false,
);
assert.equal(
sandboxUnavailable({ status: 1, stderr: 'historical verifier said bwrap ENOENT' }),
false,
);
assert.equal(
sandboxUnavailable({
status: 1,
stderr: 'bwrap: Creating new namespace failed: Operation not permitted',
sandboxLauncher: 'bwrap',
sandboxEntered: false,
}),
true,
);
assert.equal(
sandboxUnavailable({
status: 1,
stderr: 'bwrap: Creating new namespace failed: Operation not permitted',
}),
false,
);
assert.equal(
sandboxUnavailable({
status: 1,
stderr: 'bwrap: Creating new namespace failed: Operation not permitted',
sandboxLauncher: 'bwrap',
sandboxEntered: true,
}),
false,
);
});
test('prospective history reads each commit own manifest rather than the current tree', async () => {
await rm(fixtureRoot, { recursive: true, force: true });
await mkdir(fixtureRoot, { recursive: true });
git(fixtureRoot, 'init', '-q');
git(fixtureRoot, 'config', 'user.name', 'gate-test');
git(fixtureRoot, 'config', 'user.email', '[email protected]');
await writeFile(path.join(fixtureRoot, 'activation.txt'), 'activation\n');
git(fixtureRoot, 'add', '.');
git(fixtureRoot, 'commit', '-m', 'activation');
const activation = git(fixtureRoot, 'rev-parse', 'HEAD');
const first = await commitManifest(fixtureRoot, 'FIRST');
const second = await commitManifest(fixtureRoot, 'SECOND');
assert.deepEqual(await listProspectiveCommits(fixtureRoot, activation, second), [first, second]);
assert.equal((await readManifestAtCommit(fixtureRoot, first)).marker, 'FIRST');
assert.equal((await readManifestAtCommit(fixtureRoot, second)).marker, 'SECOND');
});
test('historical replay executes each selected commit verifier from that commit tree', async () => {
const root = `${fixtureRoot}-replay`;
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'scripts'), { recursive: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"process.stderr.write('OLD TREE INERT\\n'); process.exitCode = 1;\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'inert historical verifier');
const inert = git(root, 'rev-parse', 'HEAD');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"process.stdout.write('NEW TREE VERIFIED\\n');\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'fixed historical verifier');
const fixed = git(root, 'rev-parse', 'HEAD');
const inertResult = await replayCommit(root, inert);
const fixedResult = await replayCommit(root, fixed);
if (sandboxUnavailable(inertResult) || sandboxUnavailable(fixedResult)) return;
assert.notEqual(inertResult.status, 0);
assert.match(inertResult.stderr, /OLD TREE INERT/);
assert.equal(fixedResult.status, 0);
assert.match(fixedResult.stdout, /NEW TREE VERIFIED/);
});
test('historical install lifecycle cannot replace an authoritative verifier', async () => {
const root = `${fixtureRoot}-install-tamper`;
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'scripts'), { recursive: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"process.stderr.write('ORIGINAL VERIFIER RAN\\n'); process.exitCode = 7;\n",
);
await writeFile(path.join(root, 'forged.mjs'), "process.stdout.write('FORGED SUCCESS\\n');\n");
await writeFile(
path.join(root, 'package.json'),
`${JSON.stringify({
name: 'historical-install-tamper',
version: '1.0.0',
scripts: { postinstall: 'cp forged.mjs scripts/gate-verify.mjs' },
})}\n`,
);
await writeFile(
path.join(root, 'pnpm-lock.yaml'),
"lockfileVersion: '9.0'\nsettings:\n autoInstallPeers: true\n excludeLinksFromLockfile: false\nimporters:\n .: {}\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'tampering lifecycle fixture');
const commit = git(root, 'rev-parse', 'HEAD');
const result = await replayCommit(root, commit);
assert.notEqual(result.status, 0);
if (sandboxUnavailable(result)) return;
assert.match(result.stderr, /authoritative archived file changed.*scripts\/gate-verify\.mjs/i);
assert.doesNotMatch(result.stdout, /FORGED SUCCESS/);
});
test('historical verifier receives no current-process secret environment', async () => {
const root = `${fixtureRoot}-secretless`;
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'scripts'), { recursive: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"if (process.env.REPLAY_SENTINEL) { process.stderr.write('SECRET LEAKED\\n'); process.exitCode = 9; } else { process.stdout.write('SECRETLESS\\n'); }\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'secretless replay fixture');
const commit = git(root, 'rev-parse', 'HEAD');
process.env.REPLAY_SENTINEL = 'must-not-cross-boundary';
try {
const result = await replayCommit(root, commit);
if (sandboxUnavailable(result)) return;
assert.equal(result.status, 0, result.stderr);
assert.match(result.stdout, /SECRETLESS/);
assert.doesNotMatch(
`${result.stdout}${result.stderr}`,
/SECRET LEAKED|must-not-cross-boundary/,
);
} finally {
delete process.env.REPLAY_SENTINEL;
}
});
test('historical replay cannot observe a sibling process in the runner PID namespace', async () => {
const root = `${fixtureRoot}-pidless`;
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'scripts'), { recursive: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
const sleeper = spawn('sleep', ['30'], {
env: { ...process.env, REPLAY_PID_SENTINEL: 'must-not-be-visible' },
});
try {
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
`import { existsSync } from 'node:fs';\nif (existsSync('/proc/${sleeper.pid}/environ')) { process.stderr.write('HOST PID VISIBLE\\n'); process.exitCode = 9; } else { process.stdout.write('PIDLESS\\n'); }\n`,
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'pid-isolated replay fixture');
const commit = git(root, 'rev-parse', 'HEAD');
const result = await replayCommit(root, commit);
if (sandboxUnavailable(result)) return;
assert.equal(result.status, 0, result.stderr);
assert.match(result.stdout, /PIDLESS/);
assert.doesNotMatch(`${result.stdout}${result.stderr}`, /HOST PID VISIBLE/);
} finally {
sleeper.kill('SIGTERM');
}
});
test('PR verification states the RM-60 boundary without executing an intermediate verifier', async () => {
const root = `${fixtureRoot}-feature`;
await rm(root, { recursive: true, force: true });
await mkdir(root, { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'activation.txt'), 'activation\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'activation');
const activation = git(root, 'rev-parse', 'HEAD');
git(root, 'update-ref', 'refs/remotes/origin/main', activation);
await mkdir(path.join(root, 'scripts'), { recursive: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"process.stderr.write('INTERMEDIATE INERT\\n'); process.exitCode = 1;\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'inert intermediate');
await writeFile(
path.join(root, 'scripts', 'gate-verify.mjs'),
"process.stdout.write('HEAD HEALTHY\\n');\n",
);
git(root, 'add', '.');
git(root, 'commit', '-m', 'healthy head');
const previousBranch = process.env.CI_COMMIT_BRANCH;
process.env.CI_COMMIT_BRANCH = 'feature/rm-02';
try {
const result = await verifyHistory({
root,
manifest: { schemaVersion: 1 },
});
assert.deepEqual(result.failures, []);
assert.ok(
result.observations.some((observation) =>
/HISTORY BOOTSTRAP BOUNDARY.*DOES:.*provider target.*sound.*cannot rewrite main.*DOES NOT:.*compromise.*main.*Builds 1-2/i.test(
observation,
),
),
);
assert.ok(
result.observations.some((observation) =>
/DOES:.*current tree.*DOES NOT:.*isolated.*RM-60.*RM-59/i.test(observation),
),
);
assert.ok(
result.observations.some((observation) =>
/INTERMEDIATE REPLAY DEFERRED.*RM-60.*no success is inferred/i.test(observation),
),
);
assert.ok(result.observations.every((observation) => !/INTERMEDIATE INERT/.test(observation)));
} finally {
if (previousBranch === undefined) delete process.env.CI_COMMIT_BRANCH;
else process.env.CI_COMMIT_BRANCH = previousBranch;
}
});
test('target merge-base includes gate changes committed before registry introduction', async () => {
const root = `${fixtureRoot}-delayed-introduction`;
await rm(root, { recursive: true, force: true });
await mkdir(root, { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'baseline.txt'), 'baseline\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'target baseline');
const baseline = git(root, 'rev-parse', 'HEAD');
git(root, 'update-ref', 'refs/remotes/origin/main', baseline);
await mkdir(path.join(root, 'scripts'), { recursive: true });
await writeFile(path.join(root, 'scripts', 'preflight.mjs'), 'process.exit(0);\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'gate change before registry');
const preRegistryGateChange = git(root, 'rev-parse', 'HEAD');
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'delayed registry introduction');
const previousBranch = process.env.CI_COMMIT_BRANCH;
process.env.CI_COMMIT_BRANCH = 'feature/delayed-introduction';
try {
const result = await verifyHistory({ root, manifest: { schemaVersion: 1 } });
assert.match(
result.failures.join('\n'),
new RegExp(`${preRegistryGateChange}.*own-tree registry cannot be read`, 'i'),
);
} finally {
if (previousBranch === undefined) delete process.env.CI_COMMIT_BRANCH;
else process.env.CI_COMMIT_BRANCH = previousBranch;
}
});
test('derived history boundary includes the registry-introduction commit', async () => {
const root = `${fixtureRoot}-derived-boundary`;
await rm(root, { recursive: true, force: true });
await mkdir(root, { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'baseline.txt'), 'baseline\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'baseline');
const baseline = git(root, 'rev-parse', 'HEAD');
git(root, 'update-ref', 'refs/remotes/origin/main', baseline);
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'registry introduction');
const introduction = git(root, 'rev-parse', 'HEAD');
await writeFile(path.join(root, 'later.txt'), 'later\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'later');
const head = git(root, 'rev-parse', 'HEAD');
assert.deepEqual(deriveHistoryBoundary(root, head), {
activationCommit: baseline,
introductionCommit: introduction,
targetRef: 'refs/remotes/origin/main',
});
assert.deepEqual(await listProspectiveCommits(root, baseline, head), [introduction, head]);
});
test('author-controlled activation seams cannot omit registry-era history', async () => {
const root = `${fixtureRoot}-activation-seam`;
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'registry introduction');
const introduction = git(root, 'rev-parse', 'HEAD');
await writeFile(path.join(root, 'one.txt'), 'one\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'one');
await writeFile(path.join(root, 'two.txt'), 'two\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'two');
const head = git(root, 'rev-parse', 'HEAD');
const parent = git(root, 'rev-parse', 'HEAD^');
const previousBranch = process.env.CI_COMMIT_BRANCH;
process.env.CI_COMMIT_BRANCH = 'feature/activation-seam';
try {
for (const candidate of [head, parent, introduction]) {
const result = await verifyHistory({
root,
manifest: { schemaVersion: 1, activationCommit: candidate },
});
assert.match(result.failures.join('\n'), /author-controlled activationCommit.*forbidden/i);
}
} finally {
if (previousBranch === undefined) delete process.env.CI_COMMIT_BRANCH;
else process.env.CI_COMMIT_BRANCH = previousBranch;
}
});
test('globally invalid provider evidence fails when HEAD is the only prospective commit', async () => {
const root = `${fixtureRoot}-head-only-evidence`;
await rm(root, { recursive: true, force: true });
await mkdir(root, { recursive: true });
git(root, 'init', '-q');
git(root, 'config', 'user.name', 'gate-test');
git(root, 'config', 'user.email', '[email protected]');
await writeFile(path.join(root, 'baseline.txt'), 'baseline\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'baseline');
git(root, 'update-ref', 'refs/remotes/origin/main', git(root, 'rev-parse', 'HEAD'));
await mkdir(path.join(root, 'gates'), { recursive: true });
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), '{"schemaVersion":1}\n');
git(root, 'add', '.');
git(root, 'commit', '-m', 'registry introduction');
const head = git(root, 'rev-parse', 'HEAD');
const evidenceFile = path.join(root, 'provider-evidence.json');
await writeFile(
evidenceFile,
JSON.stringify([
{
commit: head,
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'other-subject',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
]),
);
const previousBranch = process.env.CI_COMMIT_BRANCH;
const previousEvidence = process.env.GATE_PROVIDER_EVIDENCE_FILE;
process.env.CI_COMMIT_BRANCH = 'main';
process.env.GATE_PROVIDER_EVIDENCE_FILE = evidenceFile;
try {
const result = await verifyHistory({ root, manifest: { schemaVersion: 1 } });
assert.match(result.failures.join('\n'), /duplicate pipeline identity across commits/i);
} finally {
if (previousBranch === undefined) delete process.env.CI_COMMIT_BRANCH;
else process.env.CI_COMMIT_BRANCH = previousBranch;
if (previousEvidence === undefined) delete process.env.GATE_PROVIDER_EVIDENCE_FILE;
else process.env.GATE_PROVIDER_EVIDENCE_FILE = previousEvidence;
}
});
test('collection-wide validation rejects ambiguous gate steps on unrelated commits', () => {
const records = [
{
commit: 'target',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'unrelated',
number: 8,
status: 'success',
steps: [
{ name: 'gate-verify', status: 'success' },
{ name: 'gate-verify', status: 'failure' },
],
},
];
const result = assessProviderEvidence('target', records);
assert.equal(result.state, 'terminal-failure');
assert.match(result.detail, /ambiguous gate-verify step count/i);
});
test('provider evidence rejects non-object collection entries without crashing', () => {
for (const record of [null, [], 'text', 42]) {
const result = assessProviderEvidence('aaa', [record]);
assert.equal(result.state, 'terminal-failure');
assert.match(result.detail, /malformed/i);
}
});
test('provider evidence rejects duplicate pipeline identity across commits', () => {
const records = [
{
commit: 'aaa',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'bbb',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
];
const result = assessProviderEvidence('aaa', records);
assert.equal(result.state, 'terminal-failure');
assert.match(result.detail, /duplicate pipeline.*across.*commit|global.*pipeline.*identity/i);
});
test('provider evidence distinguishes retained success, failure, and absent history', () => {
const pipelines = [
{
commit: 'aaa',
number: 1,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'bbb',
number: 2,
status: 'failure',
steps: [{ name: 'gate-verify', status: 'failure' }],
},
];
assert.deepEqual(assessProviderEvidence('aaa', pipelines), {
state: 'terminal-success',
detail: 'pipeline and gate-verify step succeeded',
});
assert.equal(assessProviderEvidence('bbb', pipelines).state, 'terminal-failure');
assert.equal(assessProviderEvidence('ccc', pipelines).state, 'absent');
});
test('duplicate gate-verify steps cannot establish provider success', () => {
const result = assessProviderEvidence('aaa', [
{
commit: 'aaa',
number: 7,
status: 'success',
steps: [
{ name: 'gate-verify', status: 'success' },
{ name: 'gate-verify', status: 'failure' },
],
},
]);
assert.equal(result.state, 'terminal-failure');
assert.match(result.detail, /ambiguous.*gate-verify/i);
});
test('a malformed single provider record cannot establish success', () => {
assert.equal(
assessProviderEvidence('aaa', [
{ commit: 'aaa', status: 'success', steps: [{ name: 'gate-verify', status: 'success' }] },
]).state,
'terminal-failure',
);
assert.equal(
assessProviderEvidence('bbb', [
{
commit: 'bbb',
number: 1,
status: 'surprising',
steps: [{ name: 'gate-verify', status: 'success' }],
},
]).state,
'terminal-failure',
);
});
test('provider evidence selects the highest numbered rerun deterministically', () => {
const failedThenSucceeded = [
{
commit: 'aaa',
number: 10,
status: 'failure',
steps: [{ name: 'gate-verify', status: 'failure' }],
},
{
commit: 'aaa',
number: 11,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
];
const succeededThenFailed = [
{
commit: 'bbb',
number: 21,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'bbb',
number: 22,
status: 'failure',
steps: [{ name: 'gate-verify', status: 'failure' }],
},
];
assert.equal(assessProviderEvidence('aaa', failedThenSucceeded).state, 'terminal-success');
assert.equal(assessProviderEvidence('bbb', succeededThenFailed).state, 'terminal-failure');
assert.equal(
assessProviderEvidence('ccc', [
{ commit: 'ccc', status: 'success', steps: [{ name: 'gate-verify', status: 'success' }] },
{ commit: 'ccc', status: 'failure', steps: [{ name: 'gate-verify', status: 'failure' }] },
]).state,
'terminal-failure',
);
});
+72
View File
@@ -0,0 +1,72 @@
#!/usr/bin/env node
import { mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { verifyRegistry } from './gate-verify.mjs';
const mode = process.argv[2];
const root = process.cwd();
const source = JSON.parse(await readFile(path.join(root, 'gates/gates.manifest.json'), 'utf8'));
const expectedGateIds = source.gates.map((gate) => gate.id);
if (expectedGateIds.length === 0) {
process.stderr.write('gate population control requires a non-empty anchored inventory\n');
process.exit(2);
}
async function rejectedForEveryGate(mutate, diagnostic) {
for (const gateId of expectedGateIds) {
const manifest = structuredClone(source);
const gate = manifest.gates.find((candidate) => candidate.id === gateId);
mutate(gate);
const directory = await mkdtemp(path.join(os.tmpdir(), 'gate-population-control-'));
const manifestPath = path.join(directory, 'manifest.json');
try {
await writeFile(manifestPath, `${JSON.stringify(manifest)}\n`);
const result = await verifyRegistry({
root,
manifest: manifestPath,
skipHistory: true,
structureOnly: true,
fixtureProfile: false,
});
if (!result.failures.some((failure) => diagnostic(failure, gateId))) return false;
} finally {
await rm(directory, { recursive: true, force: true });
}
}
return true;
}
let rejected;
if (mode === 'evidence-subject') {
rejected = await rejectedForEveryGate(
(gate) => {
gate.evidenceSubject = 'different-gate-subject';
},
(failure, gateId) =>
failure.includes(`gate ${gateId}: evidence subject`) &&
failure.includes('does not match gate id'),
);
} else if (mode === 'type-strict') {
rejected = await rejectedForEveryGate(
(gate) => {
gate.cases[0].actual.exitCode = '0';
},
(failure, gateId) =>
failure.includes(
`${gateId}/${source.gates.find((gate) => gate.id === gateId).cases[0].id}.actual.exitCode`,
) && failure.includes('expected an integer'),
);
} else {
process.stderr.write(`unknown gate population control ${String(mode)}\n`);
process.exit(2);
}
if (!rejected) {
process.stdout.write(`${mode} population control did not reject every registered gate\n`);
process.exit(0);
}
process.stderr.write(`${mode} population control rejected every registered gate\n`);
process.exit(1);
+30
View File
@@ -0,0 +1,30 @@
#!/usr/bin/env node
import { assessProviderEvidence } from './gate-history.mjs';
const records = [
{
commit: 'subject-a',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
{
commit: 'subject-b',
number: 7,
status: 'success',
steps: [{ name: 'gate-verify', status: 'success' }],
},
];
const result = assessProviderEvidence('subject-a', records);
if (
result.state === 'terminal-failure' &&
/duplicate pipeline identity across commits/i.test(result.detail)
) {
process.stderr.write(`${result.detail}\n`);
process.exit(1);
}
process.stdout.write(
`cross-commit duplicate was not rejected: ${result.state} (${result.detail})\n`,
);
process.exit(0);
File diff suppressed because it is too large Load Diff
+783
View File
@@ -0,0 +1,783 @@
import assert from 'node:assert/strict';
import { chmod, copyFile, mkdir, readFile, rm, symlink, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { spawnSync } from 'node:child_process';
import test from 'node:test';
const verifier = path.join(process.cwd(), 'scripts', 'gate-verify.mjs');
const fixtureRunner = path.join(
process.cwd(),
'scripts',
'test-support',
'gate-verify-fixture-runner.mjs',
);
const fixtureBase = path.join(process.cwd(), '.mosaic-test-work', `gate-verify-${process.pid}`);
async function fixture(name = 'case') {
const root = path.join(fixtureBase, name);
await rm(root, { recursive: true, force: true });
await mkdir(path.join(root, 'gates'), { recursive: true });
return root;
}
function baseManifest() {
return {
schemaVersion: 1,
gateRoots: ['gates'],
governingClaimFiles: [],
coverageBoundary: { included: ['meta fixture'], excluded: [], trackedBy: 'RM-54' },
criteria: [
{
id: 'META-CRIT-1',
originalText: 'The fixture rejects its bad input.',
currentText: 'The fixture rejects its bad input.',
claimType: 'integrity',
source: 'fixture',
meaningChanges: [],
caseRefs: ['meta-fixture/rejects-bad-input'],
},
],
compatibilityScenarios: [],
proseClaims: [],
gates: [
{
id: 'meta-fixture',
source: 'gates/meta-fixture.sh',
evidenceSubject: 'meta-fixture',
invocation: ['gates/meta-fixture.sh'],
deployment: { kind: 'none', reason: 'test fixture only' },
inertMutation: {
file: 'gates/meta-fixture.sh',
find: 'exit 7',
replace: 'exit 0',
expected: { exitCode: 0 },
},
cases: [
{
id: 'rejects-bad-input',
criterionIds: ['META-CRIT-1'],
mustFail: true,
invocation: ['gates/meta-fixture.sh'],
required: { exitCode: 7 },
actual: { exitCode: 7 },
reasonPattern: 'META_REJECT',
},
],
},
],
};
}
async function writeGate(root, contents = '#!/bin/sh\necho META_REJECT >&2\nexit 7\n') {
const target = path.join(root, 'gates', 'meta-fixture.sh');
await writeFile(target, contents);
await chmod(target, 0o755);
}
async function writeManifest(root, manifest) {
await writeFile(path.join(root, 'gates', 'gates.manifest.json'), `${JSON.stringify(manifest)}\n`);
}
function verify(root, extraArgs = []) {
return spawnSync(
process.execPath,
[fixtureRunner, '--root', root, '--manifest', 'gates/gates.manifest.json', ...extraArgs],
{ cwd: root, encoding: 'utf8', env: { ...process.env, HOME: os.homedir() } },
);
}
function verifyProductionStructure(root, extraArgs = []) {
return spawnSync(
process.execPath,
[
verifier,
'--root',
root,
'--manifest',
'gates/gates.manifest.json',
'--skip-history',
'--structure-only',
...extraArgs,
],
{ cwd: root, encoding: 'utf8', env: { ...process.env, HOME: os.homedir() } },
);
}
function output(result) {
return `${result.stdout}\n${result.stderr}`;
}
test.after(async () => {
await rm(fixtureBase, { recursive: true, force: true });
});
test('universally quantified registry checks reject empty populations before evaluation', async () => {
const root = await fixture('empty-registry-populations');
await mkdir(path.join(root, 'empty-gate-root'), { recursive: true });
const manifest = baseManifest();
manifest.gateRoots = ['empty-gate-root'];
manifest.criteria = [];
manifest.proseClaims = [];
manifest.compatibilityScenarios = [];
manifest.gates = [];
await writeManifest(root, manifest);
const result = verifyProductionStructure(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /criteria population.*non-empty.*anchored/i);
assert.match(output(result), /gates population.*non-empty.*anchored/i);
assert.match(output(result), /proseClaims population.*non-empty.*anchored/i);
assert.match(output(result), /compatibilityScenarios population.*non-empty.*anchored/i);
});
test('production verifier exposes no fixture-profile population bypass', async () => {
const root = await fixture('no-production-fixture-profile');
const result = verifyProductionStructure(root, ['--fixture-profile']);
assert.notEqual(result.status, 0);
assert.match(output(result), /unknown option: --fixture-profile/i);
});
test('anchored gate inventory and population criteria cannot shrink together', async () => {
const source = JSON.parse(
await readFile(path.join(process.cwd(), 'gates', 'gates.manifest.json'), 'utf8'),
);
const root = await fixture('shrunken-gate-population');
source.gates = source.gates.filter((gate) => gate.id !== 'hook-pre-push');
for (const criterion of source.criteria) {
if (criterion.gateRefs) {
criterion.gateRefs = criterion.gateRefs.filter((gateId) => gateId !== 'hook-pre-push');
}
criterion.caseRefs = criterion.caseRefs.filter(
(caseRef) => !caseRef.startsWith('hook-pre-push/'),
);
}
await writeManifest(root, source);
const result = verifyProductionStructure(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /gates population is not anchored.*hook-pre-push/i);
});
test('general population criteria cannot delete their gateRefs binding', async () => {
const requiredCriteria = [
'RM02-EVIDENCE-SUBJECT-BINDING',
'RM02-TYPE-STRICT-SCHEMA',
'RM02-NONEMPTY-ANCHORED-QUANTIFICATION',
];
for (const criterionId of requiredCriteria) {
const source = JSON.parse(
await readFile(path.join(process.cwd(), 'gates', 'gates.manifest.json'), 'utf8'),
);
const root = await fixture(`missing-gate-refs-${criterionId}`);
delete source.criteria.find((criterion) => criterion.id === criterionId).gateRefs;
await writeManifest(root, source);
const result = verifyProductionStructure(root);
assert.notEqual(result.status, 0);
assert.match(
output(result),
new RegExp(`${criterionId}.*gateRefs.*required`, 'i'),
criterionId,
);
}
});
test('general population criteria must span every registered gate', async () => {
const source = JSON.parse(
await readFile(path.join(process.cwd(), 'gates', 'gates.manifest.json'), 'utf8'),
);
const root = await fixture('incomplete-gate-refs');
source.criteria.find((criterion) => criterion.id === 'RM02-EVIDENCE-SUBJECT-BINDING').gateRefs =
source.criteria
.find((criterion) => criterion.id === 'RM02-EVIDENCE-SUBJECT-BINDING')
.gateRefs.filter((gateId) => gateId !== 'quality-lint');
await writeManifest(root, source);
const result = verifyProductionStructure(root);
assert.notEqual(result.status, 0);
assert.match(
output(result),
/RM02-EVIDENCE-SUBJECT-BINDING.*gate population binding is missing quality-lint/i,
);
});
test('an externally inerted failure branch makes verification nonzero and names the gate', async () => {
const root = await fixture('external-inert');
await writeGate(root, '#!/bin/sh\nexit 0\n');
await writeManifest(root, baseManifest());
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture/);
});
test('the verifier applies the declared inert mutation and observes its own control red', async () => {
const root = await fixture('internal-meta');
await writeGate(root);
await writeManifest(root, baseManifest());
const result = verify(root);
assert.equal(result.status, 0, output(result));
assert.match(output(result), /META-NEGATIVE-CONTROL.*meta-fixture.*observed red/i);
});
test('a mutation crash is rejected instead of counted as an observed-red control', async () => {
const root = await fixture('mutation-crash');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].inertMutation.replace = 'this is not valid shell (';
manifest.gates[0].inertMutation.expected = { exitCode: 0 };
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*mutation.*unexpected outcome/i);
assert.doesNotMatch(output(result), /META-NEGATIVE-CONTROL.*observed red/i);
});
test('a stale declared mutation case id is rejected instead of falling back', async () => {
const root = await fixture('stale-case-id');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].inertMutation.caseId = 'case-that-does-not-exist';
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*case-that-does-not-exist.*not found/i);
});
test('duplicate stable ids and unsupported schema versions are rejected', async () => {
const root = await fixture('closed-schema');
await writeGate(root);
const manifest = baseManifest();
manifest.schemaVersion = 99;
manifest.criteria.push({ ...manifest.criteria[0] });
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /unsupported schemaVersion 99/i);
assert.match(output(result), /duplicate criterion id META-CRIT-1/i);
});
test('misspelled nested assertion fields are rejected instead of becoming optional', async () => {
const root = await fixture('nested-schema-typo');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].required.outputPatern = 'META_REJECT';
manifest.gates[0].cases[0].actual.outputPatern = 'META_REJECT';
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /required.*unknown field outputPatern/i);
assert.match(output(result), /actual.*unknown field outputPatern/i);
});
test('present outcome patterns cannot be empty assertion bypasses', async () => {
const root = await fixture('nested-schema-empty-patterns');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].required.outputPattern = '';
manifest.gates[0].cases[0].actual.notOutputPattern = ' ';
await writeManifest(root, manifest);
const result = verify(root, ['--structure-only']);
assert.notEqual(result.status, 0);
assert.match(output(result), /required.outputPattern: expected a non-empty pattern/i);
assert.match(output(result), /actual.notOutputPattern: expected a non-empty pattern/i);
});
test('nested discriminator and comparison fields reject wrong types', async () => {
const root = await fixture('nested-schema-types');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].mustFail = 'true';
manifest.gates[0].cases[0].required.exitCode = '7';
manifest.gates[0].cases[0].actual.outputPattern = 7;
await writeManifest(root, manifest);
const result = verify(root, ['--structure-only']);
assert.notEqual(result.status, 0);
assert.match(output(result), /mustFail: expected a boolean/i);
assert.match(output(result), /required.exitCode: expected an integer/i);
assert.match(output(result), /actual.outputPattern: expected a string/i);
});
test('recursive closed-schema guards reject unknown fields in every nested assertion object', async () => {
const source = JSON.parse(
await readFile(path.join(process.cwd(), 'gates', 'gates.manifest.json'), 'utf8'),
);
const checkout = source.gates.find((gate) => gate.id === 'checkout-preflight');
const stale = checkout.cases.find((gateCase) => gateCase.id === 'stale-build-lock');
const queue = source.gates.find((gate) => gate.id === 'ci-queue-wait');
const queueCase = queue.cases.find((gateCase) => gateCase.id === 'terminal-success');
const targets = [
['coverageBoundary', (manifest) => manifest.coverageBoundary],
['mergeAssertions', (manifest) => manifest.mergeAssertions],
[
'meaningChanges',
(manifest) =>
manifest.criteria.find((criterion) => criterion.meaningChanges.length).meaningChanges[0],
],
['proseClaims', (manifest) => manifest.proseClaims[0]],
['compatibility expected', (manifest) => manifest.compatibilityScenarios[0].expected],
[
'deployment',
(manifest) => manifest.gates.find((gate) => gate.id === 'ci-queue-wait').deployment,
],
['inertMutation', (manifest) => manifest.gates[0].inertMutation],
['inert expected', (manifest) => manifest.gates[0].inertMutation.expected],
['required', (manifest) => manifest.gates[0].cases[0].required],
['actual', (manifest) => manifest.gates[0].cases[0].actual],
[
'fixture',
(manifest) =>
manifest.gates
.find((gate) => gate.id === 'checkout-preflight')
.cases.find((gateCase) => gateCase.id === 'stale-build-lock').fixture,
],
[
'write entry',
(manifest) =>
manifest.gates
.find((gate) => gate.id === 'checkout-preflight')
.cases.find((gateCase) => gateCase.id === 'stale-build-lock').fixture.writeFiles[0],
],
[
'replace entry',
(manifest) =>
manifest.gates
.find((gate) => gate.id === 'checkout-preflight')
.cases.find((gateCase) => gateCase.id === 'criterion-misbinding').fixture.replaceFiles[0],
],
[
'defect',
(manifest) =>
manifest.gates
.find((gate) => gate.id === 'ci-queue-wait')
.cases.find((gateCase) => gateCase.id === 'terminal-success').defect,
],
];
assert.ok(stale.fixture && queueCase.defect);
for (const [name, select] of targets) {
const root = await fixture(`recursive-${name.replaceAll(' ', '-')}`);
const manifest = structuredClone(source);
select(manifest).unexpectedNestedField = true;
await writeManifest(root, manifest);
const result = verify(root, ['--structure-only']);
assert.notEqual(result.status, 0, `${name}: ${output(result)}`);
assert.match(output(result), /unknown field unexpectedNestedField/i, name);
}
});
test('manifest-controlled fixture paths cannot escape the sandbox', async () => {
const root = await fixture('path-traversal');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].fixture = {
writeFiles: [{ path: '../../escaped-by-manifest', content: 'bad' }],
};
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /path escapes sandbox/i);
});
test('fixture writes reject a final symlink and preserve its outside target', async () => {
const root = await fixture('final-symlink');
await writeGate(root);
const outside = path.join(fixtureBase, 'outside-sentinel');
await writeFile(outside, 'preserve-me\n');
const linked = path.join(root, 'linked-sentinel');
await symlink(outside, linked);
const manifest = baseManifest();
manifest.gates[0].cases[0].fixture = {
writeFiles: [{ path: 'linked-sentinel', content: 'overwritten\n' }],
};
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /fixture write.*symbolic link/i);
assert.equal(await readFile(outside, 'utf8'), 'preserve-me\n');
});
test('an executable below a gate root without an entry is rejected', async () => {
const root = await fixture('unregistered');
await writeGate(root);
const extra = path.join(root, 'gates', 'forgotten.sh');
await writeFile(extra, '#!/bin/sh\nexit 1\n');
await chmod(extra, 0o755);
await writeManifest(root, baseManifest());
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /unregistered gate.*forgotten\.sh/i);
});
test('a must-fail case without a reason diagnostic is rejected', async () => {
const root = await fixture('missing-reason');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].reasonPattern = '';
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*rejects-bad-input.*reasonPattern/i);
});
test('a gate with zero must-fail cases is rejected', async () => {
const root = await fixture('no-negative');
await writeGate(root, '#!/bin/sh\nexit 0\n');
const manifest = baseManifest();
manifest.gates[0].inertMutation = {
file: 'gates/meta-fixture.sh',
find: 'exit 0',
replace: 'exit 1',
};
manifest.gates[0].cases = [
{
id: 'positive',
criterionIds: ['META-CRIT-1'],
mustFail: false,
invocation: ['gates/meta-fixture.sh'],
required: { exitCode: 0 },
actual: { exitCode: 0 },
reasonPattern: '',
},
];
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*no negative control/i);
});
test('reordered but equivalent outcome fields do not create a false behavior delta', async () => {
const root = await fixture('reordered-outcomes');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases[0].required = { exitCode: 7, outputPattern: 'META_REJECT' };
manifest.gates[0].cases[0].actual = { outputPattern: 'META_REJECT', exitCode: 7 };
await writeManifest(root, manifest);
const result = verify(root);
assert.equal(result.status, 0, output(result));
assert.doesNotMatch(output(result), /behavior delta requires|DEFECT \(owner:/);
});
test('a required-versus-actual delta without a tracked owner is rejected', async () => {
const root = await fixture('ownerless-delta');
await writeGate(root, '#!/bin/sh\nexit 0\n');
const manifest = baseManifest();
manifest.gates[0].inertMutation.find = 'exit 0';
manifest.gates[0].inertMutation.replace = 'exit 7';
manifest.gates[0].cases[0].actual.exitCode = 0;
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*delta.*tracked owner/i);
});
test('moving criterion bindings to unrelated cases is rejected', async () => {
const root = await fixture('semantic-misbinding');
await writeGate(root);
const manifest = baseManifest();
manifest.criteria.push({
id: 'META-CRIT-2',
originalText: 'The fixture reports the second rejection reason.',
currentText: 'The fixture reports the second rejection reason.',
claimType: 'integrity',
source: 'fixture',
meaningChanges: [],
caseRefs: ['meta-fixture/rejects-second-input'],
});
manifest.gates[0].cases.push({
...manifest.gates[0].cases[0],
id: 'rejects-second-input',
criterionIds: ['META-CRIT-1'],
});
manifest.gates[0].cases[0].criterionIds = ['META-CRIT-2'];
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /META-CRIT-1.*rejects-bad-input.*not bound/i);
assert.match(output(result), /META-CRIT-2.*rejects-second-input.*not bound/i);
});
test('canonical verification preserves binding diagnostics when a case fixture is also stale', async () => {
const root = await fixture('misbinding-plus-stale-fixture');
await writeGate(root);
const manifest = baseManifest();
manifest.criteria.push({
id: 'META-CRIT-2',
originalText: 'The second case rejects its own bad input.',
currentText: 'The second case rejects its own bad input.',
claimType: 'integrity',
source: 'fixture',
meaningChanges: [],
caseRefs: ['meta-fixture/rejects-second-input'],
});
manifest.gates[0].cases.push({
...manifest.gates[0].cases[0],
id: 'rejects-second-input',
criterionIds: ['META-CRIT-1'],
});
manifest.gates[0].cases[0].criterionIds = ['META-CRIT-2'];
manifest.gates[0].cases[0].fixture = {
replaceFiles: [
{
path: 'gates/meta-fixture.sh',
find: 'text that is not present',
replace: 'irrelevant',
},
],
};
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /META-CRIT-1.*rejects-bad-input.*not bound/i);
assert.match(output(result), /META-CRIT-2.*rejects-second-input.*not bound/i);
assert.match(output(result), /fixture replace.*stale or ambiguous/i);
});
test('moving meaning and prose criteria to an unrelated type error is rejected', async () => {
const root = await fixture('real-manifest-misbinding');
const manifest = JSON.parse(
await readFile(path.join(process.cwd(), 'gates', 'gates.manifest.json'), 'utf8'),
);
for (const gate of manifest.gates) {
for (const gateCase of gate.cases) {
gateCase.criterionIds = gateCase.criterionIds.filter(
(id) => !['RM02-MEANING-PROVENANCE', 'RM02-PROSE-CONTROL'].includes(id),
);
}
}
const typeError = manifest.gates
.find((gate) => gate.id === 'quality-typecheck')
.cases.find((gateCase) => gateCase.id === 'type-error');
typeError.criterionIds.push('RM02-MEANING-PROVENANCE', 'RM02-PROSE-CONTROL');
await writeManifest(root, manifest);
const result = verify(root, ['--structure-only']);
assert.notEqual(result.status, 0);
assert.match(output(result), /RM02-MEANING-PROVENANCE.*missing-meaning-provenance.*not bound/i);
assert.match(output(result), /RM02-PROSE-CONTROL.*prose-claim-misbinding.*not bound/i);
assert.match(
output(result),
/RM02-(?:MEANING-PROVENANCE|PROSE-CONTROL).*undeclared exercising case quality-typecheck\/type-error/i,
);
});
test('a criterion with no bound case is rejected', async () => {
const root = await fixture('unbound-criterion');
await writeGate(root);
const manifest = baseManifest();
manifest.criteria.push({
id: 'ORPHAN',
originalText: 'This criterion is not exercised.',
currentText: 'This criterion is not exercised.',
claimType: 'quality',
source: 'fixture',
meaningChanges: [],
});
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /ORPHAN.*no bound case/i);
});
test('an unbound governing prose marker is rejected', async () => {
const root = await fixture('unbound-prose');
await writeGate(root);
await mkdir(path.join(root, 'docs'), { recursive: true });
await writeFile(path.join(root, 'docs', 'governing.md'), 'GATE-CLAIM:UNBOUND\n');
const manifest = baseManifest();
manifest.governingClaimFiles = ['docs/governing.md'];
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /GATE-CLAIM:UNBOUND.*unbound/i);
});
test('directly contradictory modeled scenarios are rejected', async () => {
const root = await fixture('conflict');
await writeGate(root);
const manifest = baseManifest();
manifest.compatibilityScenarios = [
{
id: 'ONE',
construction: 'same-input',
caseRefs: ['meta-fixture/rejects-bad-input'],
invocation: ['sh', '-c', 'exit 0'],
expected: { exitCode: 0 },
},
{
id: 'TWO',
construction: 'same-input',
caseRefs: ['meta-fixture/rejects-bad-input'],
invocation: ['sh', '-c', 'exit 1'],
expected: { exitCode: 1 },
},
];
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /ONE.*TWO.*conflict/i);
});
test('compatibility scenarios execute referenced conditions as one construction', async () => {
const root = await fixture('combined-compatibility');
await writeGate(root);
const manifest = baseManifest();
manifest.gates[0].cases.push({
id: 'second-condition',
criterionIds: ['META-CRIT-1'],
mustFail: true,
invocation: ['sh', '-c', 'echo "$SECOND_REASON" >&2; exit 7'],
fixture: { writeFiles: [{ path: 'conditions/second', content: 'present\n' }] },
required: { exitCode: 7 },
actual: { exitCode: 7 },
reasonPattern: 'SECOND_REASON',
environment: { SECOND_REASON: 'SECOND_REASON' },
});
manifest.criteria[0].caseRefs.push('meta-fixture/second-condition');
manifest.gates[0].cases[0].fixture = {
writeFiles: [{ path: 'conditions/first', content: 'present\n' }],
};
manifest.compatibilityScenarios = [
{
id: 'BOTH-CONDITIONS',
construction: 'both-fixtures',
caseRefs: ['meta-fixture/rejects-bad-input', 'meta-fixture/second-condition'],
invocation: ['sh', '-c', 'test -f conditions/first && test -f conditions/second'],
expected: { exitCode: 0 },
},
];
await writeManifest(root, manifest);
const result = verify(root);
assert.equal(result.status, 0, output(result));
assert.match(output(result), /COMPATIBILITY BOTH-CONDITIONS: observed expected outcome/i);
});
test('a restated criterion without provenance is rejected', async () => {
const root = await fixture('provenance');
await writeGate(root);
const manifest = baseManifest();
manifest.criteria[0].currentText = 'The fixture rejects only malformed input.';
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /META-CRIT-1.*meaning-change provenance/i);
});
test('a security criterion bound only to a positive case is unregistered in substance', async () => {
const root = await fixture('positive-only-criterion');
await writeGate(root);
const manifest = baseManifest();
manifest.criteria.push({
id: 'POSITIVE-ONLY',
originalText: 'A security property.',
currentText: 'A security property.',
claimType: 'security',
source: 'fixture',
meaningChanges: [],
});
manifest.gates[0].cases.push({
id: 'positive-only',
criterionIds: ['POSITIVE-ONLY'],
mustFail: false,
invocation: ['gates/meta-fixture.sh'],
required: { exitCode: 7 },
actual: { exitCode: 7 },
reasonPattern: '',
});
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /POSITIVE-ONLY.*no must-fail case/i);
});
test('a registered prose claim whose marker is absent is rejected', async () => {
const root = await fixture('missing-prose-marker');
await writeGate(root);
await mkdir(path.join(root, 'docs'), { recursive: true });
await writeFile(path.join(root, 'docs', 'governing.md'), 'No marker here.\n');
const manifest = baseManifest();
manifest.governingClaimFiles = ['docs/governing.md'];
manifest.proseClaims = [{ id: 'MISSING-MARKER', criterionId: 'META-CRIT-1' }];
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /GATE-CLAIM:MISSING-MARKER.*missing/i);
});
test('source-versus-deployed byte drift is rejected and names the gate', async () => {
const root = await fixture('deployment-drift');
await writeGate(root);
await mkdir(path.join(root, 'deployed'), { recursive: true });
await writeFile(path.join(root, 'deployed', 'meta-fixture.sh'), '#!/bin/sh\nexit 0\n');
const manifest = baseManifest();
manifest.gates[0].deployment = { kind: 'file', path: 'deployed/meta-fixture.sh' };
await writeManifest(root, manifest);
const result = verify(root);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*source.*deployed.*drift/i);
});
test('deployment drift meta-control fails if the shared comparator is made inert', async () => {
const root = await fixture('deployment-comparator-inert');
await writeGate(root);
await mkdir(path.join(root, 'deployed'), { recursive: true });
await copyFile(
path.join(root, 'gates', 'meta-fixture.sh'),
path.join(root, 'deployed', 'meta-fixture.sh'),
);
const manifest = baseManifest();
manifest.gates[0].deployment = { kind: 'file', path: 'deployed/meta-fixture.sh' };
await writeManifest(root, manifest);
const alteredScripts = path.join(root, 'verifier-scripts');
await mkdir(alteredScripts, { recursive: true });
const verifierSource = await readFile(verifier, 'utf8');
const inertSource = verifierSource.replace(
'return source.equals(deployed);',
'return true; // deliberate test-only inert comparator',
);
assert.notEqual(inertSource, verifierSource, 'shared deployment comparator mutation went stale');
await writeFile(path.join(alteredScripts, 'gate-verify.mjs'), inertSource);
await copyFile(
path.join(process.cwd(), 'scripts', 'gate-history.mjs'),
path.join(alteredScripts, 'gate-history.mjs'),
);
const result = spawnSync(
process.execPath,
[
path.join(alteredScripts, 'gate-verify.mjs'),
'--root',
root,
'--manifest',
'gates/gates.manifest.json',
'--skip-history',
],
{ cwd: root, encoding: 'utf8', env: { ...process.env, HOME: os.homedir() } },
);
assert.notEqual(result.status, 0);
assert.match(output(result), /meta-fixture.*drift negative control was ineffective/i);
});
+104
View File
@@ -0,0 +1,104 @@
import assert from 'node:assert/strict';
import { readFile } from 'node:fs/promises';
import test from 'node:test';
const root = process.cwd();
const expectedTriggers = `when:
# PR + manual CI run on any branch the pull_request pipeline is the merge gate.
# push CI is restricted to protected branches (main) so a feature-branch push no
# longer fires a redundant SECOND pipeline alongside its PR pipeline. This ~halves
# CI load on the storage-constrained runner with zero loss of gating (branch
# protection requires no push/ci status context; main still gets full push CI).
- event: [pull_request, manual]
- event: push
branch: main`;
const expectedGateStep = ` image: *node_image
# Woodpecker's shallow marker makes merge-base reject even present parents;
# full history is required for activation ancestry and manifest provenance.
commands:
- *enable_pnpm
- apk add --no-cache bubblewrap
- if [ -f .git/shallow ]; then git fetch --unshallow --no-tags origin; fi
- pnpm gate:verify
depends_on:
- install
- sanitization
- upgrade-guard`;
export function assertUnprivilegedGateStep(pipeline) {
assert.doesNotMatch(
pipeline,
/privileged/i,
'no pull-request pipeline step may declare privilege',
);
for (const line of pipeline.split('\n')) {
const candidate = line.trimStart().replace(/^-\s+/, '');
if (/^(?:["'!<].*|[A-Za-z_][A-Za-z0-9_-]*\s+):(?:\s|$)/.test(candidate)) {
assert.fail(`non-canonical or merged YAML key is forbidden: ${candidate}`);
}
}
const triggerMatches = [...pipeline.matchAll(/^when:\n([\s\S]*?)(?=\n\n)/gm)];
assert.equal(triggerMatches.length, 1, 'exactly one top-level trigger is required');
assert.equal(
`when:\n${triggerMatches[0][1].trimEnd()}`,
expectedTriggers,
'top-level triggers must match closed PR/main construction',
);
const matches = [
...pipeline.matchAll(/\n gate-verify:\n([\s\S]*?)(?=\n [a-z][a-z0-9-]+:|\nservices:|$)/g),
];
assert.equal(matches.length, 1, 'exactly one gate-verify step is required');
// Closed textual construction by design: accepting arbitrary YAML syntax here
// would require a duplicate-key-preserving parser. Exact equality rejects all
// extra keys, quoted/escaped key spellings, aliases, and mapping merges.
assert.equal(matches[0][1].trimEnd(), expectedGateStep, 'gate-verify step must match closed unprivileged construction');
}
test('package.json exposes the canonical gate:verify command', async () => {
const packageJson = JSON.parse(await readFile(`${root}/package.json`, 'utf8'));
assert.equal(packageJson.scripts['gate:verify'], 'node scripts/gate-verify.mjs');
});
test('Woodpecker runs the closed unprivileged gate construction on every pipeline', async () => {
const pipeline = await readFile(`${root}/.woodpecker/ci.yml`, 'utf8');
assertUnprivilegedGateStep(pipeline);
});
test('gate wiring rejects privilege syntax, merges, duplicate keys, and trigger narrowing', async () => {
const pipeline = await readFile(`${root}/.woodpecker/ci.yml`, 'utf8');
const additions = [
' privileged: *enabled\n',
' "privileged": true\n',
" 'privileged': true\n",
' privileged : true\n',
' "priv\\u0069leged": true\n',
' <<: *privileged-step\n',
' "<<": *privileged-step\n',
];
for (const addition of additions) {
const changed = pipeline.replace(' gate-verify:\n image:', ` gate-verify:\n${addition} image:`);
assert.throws(() => assertUnprivilegedGateStep(changed));
}
const privilegedInstall = pipeline.replace(
' install:\n image:',
' install:\n privileged: true\n image:',
);
const duplicate = `${pipeline}\n gate-verify:\n image: *node_image\n`;
const noPullRequest = pipeline.replace(
' - event: [pull_request, manual]',
' - event: manual',
);
const filteredPullRequest = pipeline.replace(
' - event: [pull_request, manual]',
' - event: [pull_request, manual]\n path: [scripts/**]',
);
assert.throws(() => assertUnprivilegedGateStep(privilegedInstall), /privilege/i);
assert.throws(() => assertUnprivilegedGateStep(duplicate), /exactly one gate-verify/);
assert.throws(() => assertUnprivilegedGateStep(noPullRequest), /closed PR\/main construction/);
assert.throws(
() => assertUnprivilegedGateStep(filteredPullRequest),
/closed PR\/main construction/,
);
});
+146
View File
@@ -0,0 +1,146 @@
#!/usr/bin/env node
import { access, lstat, mkdir, readFile, readdir, rename, rm } from 'node:fs/promises';
import { execFile, spawn } from 'node:child_process';
import { promisify } from 'node:util';
import { fileURLToPath } from 'node:url';
import path from 'node:path';
const execFileAsync = promisify(execFile);
function run(command, args, options) {
return new Promise((resolve, reject) => {
const child = spawn(command, args, options);
child.once('error', reject);
child.once('exit', (code, signal) => {
if (code === 0) resolve();
else reject(new Error(signal ? `husky terminated by ${signal}` : `husky exited ${code}`));
});
});
}
async function pathExists(target) {
try {
await access(target);
return true;
} catch (error) {
if (error.code === 'ENOENT') return false;
throw error;
}
}
async function directorySnapshot(root) {
const snapshot = [];
async function walk(current) {
const children = await readdir(current, { withFileTypes: true });
for (const child of children.sort((left, right) => left.name.localeCompare(right.name))) {
const target = path.join(current, child.name);
const relative = path.relative(root, target);
const stats = await lstat(target);
if (child.isDirectory()) {
snapshot.push([relative, 'directory', stats.mode & 0o777]);
await walk(target);
} else {
snapshot.push([
relative,
'file',
stats.mode & 0o777,
(await readFile(target)).toString('base64'),
]);
}
}
}
await walk(root);
return JSON.stringify(snapshot);
}
async function directoriesMatch(left, right) {
return (await directorySnapshot(left)) === (await directorySnapshot(right));
}
export async function installHooks({
root = process.cwd(),
disabled = process.env.HUSKY === '0',
quarantineRoot = path.join(root, '.mosaic-test-work', 'husky-quarantine'),
runHusky = async (_stagingHooks, stagingRepo) => {
await execFileAsync('git', ['init', '--quiet', stagingRepo]);
await run(path.join(root, 'node_modules', '.bin', 'husky'), ['.husky'], {
cwd: stagingRepo,
stdio: 'inherit',
});
},
activateHooks = async () => {
await run('git', ['config', 'core.hooksPath', '.husky/_'], { cwd: root, stdio: 'inherit' });
},
} = {}) {
if (disabled) return;
const huskyDir = path.join(root, '.husky');
const active = path.join(huskyDir, '_');
const nonce = `${Date.now()}-${process.pid}`;
const stagingRepo = path.join(root, '.mosaic-test-work', `husky-stage-${nonce}`);
const stagingHooks = path.join(stagingRepo, '.husky');
const quarantined = path.join(quarantineRoot, `${path.basename(root)}-${nonce}`);
await mkdir(huskyDir, { recursive: true });
await mkdir(quarantineRoot, { recursive: true });
const previousComplete = (await pathExists(active)) && (await pathExists(path.join(active, 'h')));
let previousQuarantined = false;
try {
if ((await pathExists(active)) && !previousComplete) {
await rename(active, quarantined);
previousQuarantined = true;
}
await mkdir(stagingRepo, { recursive: true });
await runHusky(stagingHooks, stagingRepo);
const staged = path.join(stagingHooks, '_');
if (!(await pathExists(path.join(staged, 'h')))) {
throw new Error('husky did not produce its required h shim');
}
if (previousComplete) {
if (!(await directoriesMatch(active, staged))) {
throw new Error('existing complete hook set differs from the installed Husky version');
}
await rm(stagingRepo, { recursive: true, force: true });
} else {
await rename(staged, active);
await rm(stagingRepo, { recursive: true, force: true });
}
await activateHooks();
if (previousQuarantined) {
try {
await rm(quarantined, { recursive: true, force: true });
} catch {
console.warn(
`Previous hook state was deactivated but remains quarantined at ${quarantined}`,
);
}
}
} catch (error) {
const cleanupFailures = [];
try {
if (await pathExists(stagingRepo)) {
await rename(stagingRepo, `${quarantined}-staging`);
}
} catch (cleanupError) {
cleanupFailures.push(`staging hooks: ${cleanupError.message}`);
}
const cleanup =
cleanupFailures.length === 0
? 'No partial hook set was activated.'
: `Automatic cleanup was incomplete (${cleanupFailures.join('; ')}).`;
throw new Error(
`Hook installation failed: ${error.message}. ${cleanup} Fix: rm -rf .husky/_ && git config core.hooksPath .husky/_ && pnpm install --frozen-lockfile`,
{ cause: error },
);
}
}
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
try {
await installHooks();
} catch (error) {
console.error(error.message);
process.exitCode = 1;
}
}
+208
View File
@@ -0,0 +1,208 @@
import assert from 'node:assert/strict';
import { access, mkdir, readFile, readdir, rm, writeFile } from 'node:fs/promises';
import path from 'node:path';
import test from 'node:test';
import { installHooks } from './install-hooks.mjs';
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `hooks-${process.pid}`);
const quarantineRoot = path.join(fixtureRoot, 'quarantine');
async function fixture(name) {
const root = path.join(fixtureRoot, name);
await mkdir(path.join(root, '.husky'), { recursive: true });
return root;
}
async function exists(target) {
try {
await access(target);
return true;
} catch {
return false;
}
}
test.after(async () => {
await rm(fixtureRoot, { recursive: true, force: true });
});
test('an interrupted install quarantines the partial active hook set and fails loudly', async () => {
const root = await fixture('interrupted');
let restoredHooksPath = 'not-called';
await assert.rejects(
installHooks({
root,
quarantineRoot,
runHusky: async (stagingHooks) => {
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
await writeFile(path.join(stagingHooks, '_', 'h'), 'partial');
throw new Error('simulated interruption');
},
activateHooks: async () => {},
readHooksPath: async () => null,
restoreHooksPath: async (value) => {
restoredHooksPath = value;
},
}),
(error) => {
assert.match(error.message, /Hook installation failed/);
assert.match(error.message, /pnpm install --frozen-lockfile/);
return true;
},
);
assert.equal(await exists(path.join(root, '.husky', '_')), false);
assert.equal(restoredHooksPath, 'not-called');
const quarantined = await readdir(quarantineRoot);
assert.equal(quarantined.length, 1);
});
test('a failed replacement restores a previously complete active hook set', async () => {
const root = await fixture('rollback');
const activeShim = path.join(root, '.husky', '_', 'h');
await mkdir(path.dirname(activeShim), { recursive: true });
await writeFile(activeShim, 'previous-complete');
let previousRemainedActiveDuringStaging = false;
await assert.rejects(
installHooks({
root,
quarantineRoot: path.join(fixtureRoot, 'rollback-quarantine'),
runHusky: async () => {
previousRemainedActiveDuringStaging =
(await readFile(activeShim, 'utf8')) === 'previous-complete';
throw new Error('simulated replacement failure');
},
activateHooks: async () => {},
readHooksPath: async () => '.husky/_',
restoreHooksPath: async () => {},
}),
/Hook installation failed/,
);
assert.equal(previousRemainedActiveDuringStaging, true);
assert.equal(await readFile(activeShim, 'utf8'), 'previous-complete');
});
test('a mismatched complete hook set fails loudly instead of reporting a stale install as current', async () => {
const root = await fixture('mismatch');
const activeShim = path.join(root, '.husky', '_', 'h');
await mkdir(path.dirname(activeShim), { recursive: true });
await writeFile(activeShim, 'old-complete');
await assert.rejects(
installHooks({
root,
quarantineRoot: path.join(fixtureRoot, 'mismatch-quarantine'),
runHusky: async (stagingHooks) => {
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
await writeFile(path.join(stagingHooks, '_', 'h'), 'new-complete');
},
activateHooks: async () => {},
readHooksPath: async () => '.husky/_',
restoreHooksPath: async () => {},
}),
/Hook installation failed.*pnpm install --frozen-lockfile/,
);
assert.equal(await readFile(activeShim, 'utf8'), 'old-complete');
});
test('a competing successful installer is not removed by the losing process', async () => {
const root = await fixture('concurrent');
const activeShim = path.join(root, '.husky', '_', 'h');
let restored = false;
await assert.rejects(
installHooks({
root,
quarantineRoot: path.join(fixtureRoot, 'concurrent-quarantine'),
runHusky: async (stagingHooks) => {
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
await writeFile(path.join(stagingHooks, '_', 'h'), 'ours');
await mkdir(path.dirname(activeShim), { recursive: true });
await writeFile(activeShim, 'peer');
},
activateHooks: async () => {},
readHooksPath: async () => null,
restoreHooksPath: async () => {
restored = true;
},
}),
/Hook installation failed/,
);
assert.equal(await readFile(activeShim, 'utf8'), 'peer');
assert.equal(restored, false);
});
test("a competing installer that replaces this installer's active set is preserved", async () => {
const root = await fixture('concurrent-after-rename');
const active = path.join(root, '.husky', '_');
const activeShim = path.join(active, 'h');
let restored = false;
await assert.rejects(
installHooks({
root,
quarantineRoot: path.join(fixtureRoot, 'concurrent-after-rename-quarantine'),
runHusky: async (stagingHooks) => {
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
await writeFile(path.join(stagingHooks, '_', 'h'), 'ours');
},
activateHooks: async () => {
await rm(active, { recursive: true, force: true });
await mkdir(active, { recursive: true });
await writeFile(activeShim, 'peer');
throw new Error('our activation lost to peer');
},
readHooksPath: async () => null,
restoreHooksPath: async () => {
restored = true;
},
}),
/Hook installation failed/,
);
assert.equal(await readFile(activeShim, 'utf8'), 'peer');
assert.equal(restored, false);
});
test('an explicit interactive HUSKY=0 opt-out preserves existing hooks without running installer', async () => {
const root = await fixture('disabled');
const activeShim = path.join(root, '.husky', '_', 'h');
await mkdir(path.dirname(activeShim), { recursive: true });
await writeFile(activeShim, 'preserved');
let ran = false;
await installHooks({
root,
disabled: true,
runHusky: async () => {
ran = true;
},
});
assert.equal(ran, false);
assert.equal(await readFile(activeShim, 'utf8'), 'preserved');
});
test('a successful install leaves a complete active hook set', async () => {
const root = await fixture('success');
await installHooks({
root,
quarantineRoot,
runHusky: async (stagingHooks) => {
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
await writeFile(path.join(stagingHooks, '_', 'h'), 'complete');
},
activateHooks: async () => {},
readHooksPath: async () => null,
restoreHooksPath: async () => {},
});
assert.equal(await exists(path.join(root, '.husky', '_', 'h')), true);
});
+254
View File
@@ -0,0 +1,254 @@
#!/usr/bin/env node
import { constants } from 'node:fs';
import { access, lstat, readFile, readdir, readlink } from 'node:fs/promises';
import { createHash } from 'node:crypto';
import { createRequire } from 'node:module';
import { fileURLToPath } from 'node:url';
import path from 'node:path';
export const MISSING_DEPS_EXIT = 42;
export const GENERATED_STATE_EXIT = 43;
const scriptRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
async function entries(root) {
const result = [];
async function walk(current) {
let children;
try {
children = await readdir(current, { withFileTypes: true });
} catch (error) {
if (error.code === 'ENOENT') return;
throw error;
}
for (const child of children) {
const target = path.join(current, child.name);
result.push(target);
if (child.isDirectory() && !child.isSymbolicLink()) await walk(target);
}
}
await walk(root);
return result;
}
export async function generatedSymlinkManifest(nextDir) {
const links = [];
for (const target of (await entries(nextDir)).sort()) {
const stats = await lstat(target);
if (!stats.isSymbolicLink()) continue;
links.push({
path: path.relative(nextDir, target).split(path.sep).join('/'),
target: await readlink(target),
});
}
return `${JSON.stringify({ version: 1, links })}\n`;
}
const webSourceRoots = (root) => [
path.join(root, 'apps', 'web', 'src'),
path.join(root, 'apps', 'web', 'public'),
path.join(root, 'apps', 'web', 'next-env.d.ts'),
path.join(root, 'apps', 'web', 'next.config.ts'),
path.join(root, 'apps', 'web', 'postcss.config.mjs'),
path.join(root, 'apps', 'web', 'package.json'),
path.join(root, 'apps', 'web', 'tsconfig.json'),
path.join(root, 'packages', 'design-tokens', 'src'),
path.join(root, 'packages', 'design-tokens', 'package.json'),
path.join(root, 'packages', 'design-tokens', 'tsconfig.json'),
path.join(root, 'package.json'),
path.join(root, 'tsconfig.base.json'),
path.join(root, 'pnpm-lock.yaml'),
path.join(root, 'pnpm-workspace.yaml'),
path.join(root, 'turbo.json'),
];
// next.config.ts currently reads no server-only environment. Add any future
// server-side build inputs here; all resolved NEXT_PUBLIC_* inputs are automatic.
const serverBuildEnvironmentKeys = [];
function publicBuildEnvironment(root) {
const webDir = path.join(root, 'apps', 'web');
const requireFromWeb = createRequire(path.join(scriptRoot, 'apps', 'web', 'package.json'));
const requireFromNext = createRequire(requireFromWeb.resolve('next/package.json'));
const { loadEnvConfig, resetEnv, updateInitialEnv } = requireFromNext('@next/env');
const originalEnvironment = { ...process.env };
updateInitialEnv(originalEnvironment);
try {
const { combinedEnv } = loadEnvConfig(webDir, false, { info() {}, error() {} }, true);
return Object.fromEntries(
Object.entries(combinedEnv).filter(
([key, value]) =>
value !== undefined &&
(key.startsWith('NEXT_PUBLIC_') || serverBuildEnvironmentKeys.includes(key)),
),
);
} finally {
resetEnv();
}
}
export async function sourceFingerprint(root = process.cwd()) {
const files = [];
for (const sourceRoot of webSourceRoots(root)) {
try {
const stats = await lstat(sourceRoot);
if (stats.isSymbolicLink()) {
throw new Error(
`Web build input must not be a symbolic link: ${path.relative(root, sourceRoot)}`,
);
}
if (stats.isFile()) files.push(sourceRoot);
if (stats.isDirectory()) {
for (const target of await entries(sourceRoot)) {
const targetStats = await lstat(target);
if (targetStats.isSymbolicLink()) {
throw new Error(
`Web build input must not be a symbolic link: ${path.relative(root, target)}`,
);
}
if (targetStats.isFile()) files.push(target);
}
}
} catch (error) {
if (error.code !== 'ENOENT') throw error;
}
}
const digest = createHash('sha256');
for (const [key, value] of Object.entries(publicBuildEnvironment(root)).sort()) {
digest.update(`env:${key}\0${value.length}\0${value}\0`);
}
for (const target of files.sort()) {
const contents = await readFile(target);
digest.update(path.relative(root, target).split(path.sep).join('/'));
digest.update('\0');
digest.update(String(contents.length));
digest.update('\0');
digest.update(contents);
digest.update('\0');
}
return digest.digest('hex');
}
export async function runPreflight({ root = process.cwd(), uid = process.getuid?.() } = {}) {
const binDir = path.join(root, 'node_modules', '.bin');
const requiredBinaries = ['eslint', 'husky', 'prettier', 'tsc', 'turbo', 'vitest'];
const missingBinaries = [];
for (const binary of requiredBinaries) {
try {
await access(path.join(binDir, binary), constants.X_OK);
} catch {
missingBinaries.push(binary);
}
}
if (missingBinaries.length > 0) {
return {
code: MISSING_DEPS_EXIT,
message: `MOSAIC_PREFLIGHT_MISSING_DEPS: dependency installation is missing ${missingBinaries.join(', ')}; run pnpm install --frozen-lockfile`,
};
}
const buildLock = path.join(root, '.mosaic-test-work', 'web-build.lock');
try {
await lstat(buildLock);
return {
code: GENERATED_STATE_EXIT,
message: `MOSAIC_PREFLIGHT_GENERATED_STATE: web build is in progress or interrupted at ${buildLock}; wait for it to finish or rerun pnpm build to recover the stale lock`,
};
} catch (error) {
if (error.code !== 'ENOENT') throw error;
}
const nextDir = path.join(root, 'apps', 'web', '.next');
let generated = [];
try {
const nextStats = await lstat(nextDir);
if (!nextStats.isDirectory() || nextStats.isSymbolicLink()) {
return {
code: GENERATED_STATE_EXIT,
message:
'MOSAIC_PREFLIGHT_GENERATED_STATE: apps/web/.next must be a real directory, not a symbolic link, and is not trustworthy; run pnpm clean:generated, then rerun the gate',
};
}
generated = [nextDir, ...(await entries(nextDir))];
} catch (error) {
if (error.code !== 'ENOENT') throw error;
}
if (generated.length > 0) {
const foreign = [];
for (const target of generated) {
const stats = await lstat(target);
if (uid !== undefined && stats.uid !== uid) foreign.push(path.relative(root, target));
}
// Detects accidental, independent, stale, and foreign-residue mutation of
// generated state: the class this check was born from was a five-month-stale
// .next whose validator referenced deleted pages and produced 19 phantom TS2307
// errors indistinguishable from real type errors.
//
// Does NOT defend against an actor with same-UID write access to the generated
// tree, which can regenerate both the manifest and marker consistently
// (CWE-345). No local construction can, absent a trust anchor outside that
// actor's authority. RM-59 tracks executor/spine-side attestation.
let certification = null;
let certifiedManifest = null;
try {
const [certificationContents, manifestContents] = await Promise.all([
readFile(path.join(nextDir, '.mosaic-source-hash'), 'utf8'),
readFile(path.join(nextDir, '.mosaic-symlink-manifest'), 'utf8'),
]);
try {
const parsed = JSON.parse(certificationContents);
if (
parsed.version === 1 &&
typeof parsed.sourceFingerprint === 'string' &&
typeof parsed.symlinkManifestHash === 'string'
) {
certification = parsed;
certifiedManifest = manifestContents;
}
} catch {
// Invalid certification is handled as untrusted generated state below.
}
} catch (error) {
if (error.code !== 'ENOENT') throw error;
}
const stale = certification?.sourceFingerprint !== (await sourceFingerprint(root));
const actualManifest = await generatedSymlinkManifest(nextDir);
const certifiedManifestHash =
certifiedManifest === null
? null
: createHash('sha256').update(certifiedManifest).digest('hex');
const changedSymlinks =
certification?.symlinkManifestHash !== certifiedManifestHash ||
certifiedManifest !== actualManifest;
if (foreign.length > 0 || stale || changedSymlinks) {
const reasons = [
foreign.length > 0 ? `foreign-owned paths: ${foreign.slice(0, 3).join(', ')}` : '',
stale ? 'generated source fingerprint does not match web source/configuration' : '',
changedSymlinks
? 'generated symbolic-link manifest does not match the certified build'
: '',
].filter(Boolean);
return {
code: GENERATED_STATE_EXIT,
message: `MOSAIC_PREFLIGHT_GENERATED_STATE: apps/web/.next is not trustworthy (${reasons.join('; ')}); run pnpm clean:generated, then rerun the gate`,
};
}
}
return { code: 0, message: 'checkout preflight passed' };
}
async function main() {
const result = await runPreflight();
const stream = result.code === 0 ? process.stdout : process.stderr;
stream.write(`${result.message}\n`);
process.exitCode = result.code;
}
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
await main();
}
+274
View File
@@ -0,0 +1,274 @@
import assert from 'node:assert/strict';
import { createHash } from 'node:crypto';
import { chmod, mkdir, rm, symlink, utimes, writeFile } from 'node:fs/promises';
import path from 'node:path';
import test from 'node:test';
import { runPreflight, sourceFingerprint } from './preflight.mjs';
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `preflight-${process.pid}`);
const requiredBins = ['eslint', 'husky', 'prettier', 'tsc', 'turbo', 'vitest'];
async function fixture(name) {
const root = path.join(fixtureRoot, name);
await mkdir(path.join(root, 'apps', 'web', 'src', 'app'), { recursive: true });
await writeFile(path.join(root, 'apps', 'web', 'src', 'app', 'page.tsx'), 'export default 1;\n');
return root;
}
async function installRequiredBins(root) {
const binDir = path.join(root, 'node_modules', '.bin');
await mkdir(binDir, { recursive: true });
await Promise.all(
requiredBins.map(async (name) => {
const target = path.join(binDir, name);
await writeFile(target, '');
await chmod(target, 0o755);
}),
);
}
async function certifyGeneratedState(root, links = []) {
const nextDir = path.join(root, 'apps', 'web', '.next');
await mkdir(nextDir, { recursive: true });
const manifest = `${JSON.stringify({ version: 1, links })}\n`;
const manifestHash = createHash('sha256').update(manifest).digest('hex');
await writeFile(path.join(nextDir, '.mosaic-symlink-manifest'), manifest);
await writeFile(
path.join(nextDir, '.mosaic-source-hash'),
`${JSON.stringify({
version: 1,
sourceFingerprint: await sourceFingerprint(root),
symlinkManifestHash: manifestHash,
})}\n`,
);
}
test.after(async () => {
await rm(fixtureRoot, { recursive: true, force: true });
});
test('missing dependencies have a dedicated exit code and install remediation', async () => {
const root = await fixture('missing-deps');
const result = await runPreflight({ root });
assert.equal(result.code, 42);
assert.match(result.message, /MOSAIC_PREFLIGHT_MISSING_DEPS/);
assert.match(result.message, /run pnpm install/i);
});
test('a partial dependency install keeps the dedicated missing-deps result', async () => {
const root = await fixture('partial-deps');
await mkdir(path.join(root, 'node_modules', '.bin'), { recursive: true });
await writeFile(path.join(root, 'node_modules', '.bin', 'tsc'), '', { mode: 0o755 });
const result = await runPreflight({ root });
assert.equal(result.code, 42);
assert.match(result.message, /turbo/);
});
test('a dangling required dependency shim keeps the dedicated missing-deps result', async () => {
const root = await fixture('dangling-deps');
await installRequiredBins(root);
const turbo = path.join(root, 'node_modules', '.bin', 'turbo');
await rm(turbo);
await symlink(path.join(root, 'node_modules', 'missing-turbo'), turbo);
const result = await runPreflight({ root });
assert.equal(result.code, 42);
assert.match(result.message, /turbo/);
});
test('installed dependencies pass when generated state is absent', async () => {
const root = await fixture('clean');
await installRequiredBins(root);
assert.deepEqual(await runPreflight({ root }), { code: 0, message: 'checkout preflight passed' });
});
test('foreign-owned generated Next state is identified separately from source errors', async () => {
const root = await fixture('foreign-next');
await installRequiredBins(root);
const generated = path.join(root, 'apps', 'web', '.next', 'types', 'validator.ts');
await mkdir(path.dirname(generated), { recursive: true });
await writeFile(generated, 'generated output');
const result = await runPreflight({ root, uid: (process.getuid?.() ?? 0) + 1 });
assert.equal(result.code, 43);
assert.match(result.message, /MOSAIC_PREFLIGHT_GENERATED_STATE/);
assert.match(result.message, /foreign-owned/);
});
test('a generated marker mismatch is identified separately from source errors', async () => {
const root = await fixture('stale-next');
await installRequiredBins(root);
const generated = path.join(root, 'apps', 'web', '.next', 'types', 'validator.ts');
await mkdir(path.dirname(generated), { recursive: true });
await writeFile(generated, 'stale generated output');
await writeFile(path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash'), 'old-source');
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /MOSAIC_PREFLIGHT_GENERATED_STATE/);
assert.match(result.message, /apps\/web\/\.next/);
assert.match(result.message, /pnpm clean:generated/);
});
test('generated-state symbolic links are accepted only when exactly build-certified', async (t) => {
await t.test('apps/web/.next itself is rejected when it is a symbolic link', async () => {
const root = await fixture('symbolic-next-root');
await installRequiredBins(root);
await writeFile(path.join(root, 'outside-generated'), 'not a Next build\n');
await symlink(path.join(root, 'outside-generated'), path.join(root, 'apps', 'web', '.next'));
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /MOSAIC_PREFLIGHT_GENERATED_STATE/);
assert.match(result.message, /symbolic link/);
});
await t.test('apps/web/.next is rejected when it is not a directory', async () => {
const root = await fixture('non-directory-next-root');
await installRequiredBins(root);
await writeFile(path.join(root, 'apps', 'web', '.next'), 'not a Next build\n');
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /MOSAIC_PREFLIGHT_GENERATED_STATE/);
assert.match(result.message, /real directory/);
});
await t.test('an added descendant symlink is rejected', async () => {
const root = await fixture('symbolic-next-added');
await installRequiredBins(root);
await certifyGeneratedState(root);
await symlink('/etc/hosts', path.join(root, 'apps', 'web', '.next', 'reviewer-symlink'));
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /symbolic-link manifest/);
});
await t.test('a removed certified descendant symlink is rejected', async () => {
const root = await fixture('symbolic-next-removed');
await installRequiredBins(root);
const link = path.join(root, 'apps', 'web', '.next', 'dependency-link');
await mkdir(path.dirname(link), { recursive: true });
await symlink('../dependency-one', link);
await certifyGeneratedState(root, [{ path: 'dependency-link', target: '../dependency-one' }]);
await rm(link);
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /symbolic-link manifest/);
});
await t.test('a retargeted certified descendant symlink is rejected', async () => {
const root = await fixture('symbolic-next-retargeted');
await installRequiredBins(root);
const link = path.join(root, 'apps', 'web', '.next', 'dependency-link');
await mkdir(path.dirname(link), { recursive: true });
await symlink('../dependency-one', link);
await certifyGeneratedState(root, [{ path: 'dependency-link', target: '../dependency-one' }]);
await rm(link);
await symlink('../dependency-two', link);
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /symbolic-link manifest/);
});
await t.test('a manifest edited to whitelist a rogue symlink is rejected', async () => {
const root = await fixture('symbolic-next-tampered-manifest');
await installRequiredBins(root);
await certifyGeneratedState(root);
const nextDir = path.join(root, 'apps', 'web', '.next');
await symlink('/etc/hosts', path.join(nextDir, 'reviewer-symlink'));
await writeFile(
path.join(nextDir, '.mosaic-symlink-manifest'),
`${JSON.stringify({
version: 1,
links: [{ path: 'reviewer-symlink', target: '/etc/hosts' }],
})}\n`,
);
const result = await runPreflight({ root });
assert.equal(result.code, 43);
assert.match(result.message, /symbolic-link manifest/);
});
await t.test('unchanged canonical-style descendant symlinks are accepted', async () => {
const root = await fixture('symbolic-next-certified');
await installRequiredBins(root);
const link = path.join(
root,
'apps',
'web',
'.next',
'standalone',
'node_modules',
'dependency',
);
await mkdir(path.dirname(link), { recursive: true });
await symlink('../.pnpm/dependency', link);
await certifyGeneratedState(root, [
{ path: 'standalone/node_modules/dependency', target: '../.pnpm/dependency' },
]);
assert.deepEqual(await runPreflight({ root }), {
code: 0,
message: 'checkout preflight passed',
});
});
});
test('the source fingerprint includes inherited TypeScript configuration', async () => {
const root = await fixture('inherited-typescript-config');
const config = path.join(root, 'tsconfig.base.json');
await writeFile(config, '{"compilerOptions":{"strict":true}}\n');
const first = await sourceFingerprint(root);
await writeFile(config, '{"compilerOptions":{"strict":false}}\n');
const second = await sourceFingerprint(root);
assert.notEqual(first, second);
});
test('the source fingerprint rejects symbolic-link build inputs', async () => {
const root = await fixture('symbolic-source');
await writeFile(path.join(root, 'outside.ts'), 'export default 1;\n');
await symlink(path.join(root, 'outside.ts'), path.join(root, 'apps', 'web', 'src', 'linked.ts'));
await assert.rejects(sourceFingerprint(root), /must not be a symbolic link/);
});
test('the source fingerprint includes expanded public web build environment', async () => {
const root = await fixture('public-build-environment');
const envFile = path.join(root, 'apps', 'web', '.env.production');
await writeFile(
envFile,
'RM01_GATEWAY_URL=https://one.example\nNEXT_PUBLIC_RM01_URL=$RM01_GATEWAY_URL\n',
);
const first = await sourceFingerprint(root);
await writeFile(
envFile,
'RM01_GATEWAY_URL=https://two.example\nNEXT_PUBLIC_RM01_URL=$RM01_GATEWAY_URL\n',
);
const second = await sourceFingerprint(root);
assert.notEqual(first, second);
});
test('a matching generation marker accepts incremental output with mixed mtimes', async () => {
const root = await fixture('incremental-next');
await installRequiredBins(root);
const generated = path.join(root, 'apps', 'web', '.next', 'types', 'validator.ts');
await mkdir(path.dirname(generated), { recursive: true });
await writeFile(generated, 'unchanged generated output');
await utimes(generated, new Date('2020-01-01T00:00:00Z'), new Date('2020-01-01T00:00:00Z'));
const fresh = path.join(root, 'apps', 'web', '.next', 'types', 'routes.ts');
await writeFile(fresh, 'fresh generated output');
await certifyGeneratedState(root);
assert.deepEqual(await runPreflight({ root }), { code: 0, message: 'checkout preflight passed' });
});
@@ -0,0 +1,28 @@
#!/usr/bin/env node
import path from 'node:path';
import { verifyRegistry } from '../gate-verify.mjs';
let root;
let manifest = 'gates/gates.manifest.json';
let structureOnly = false;
for (let index = 0; index < process.argv.slice(2).length; index += 1) {
const args = process.argv.slice(2);
const value = args[index];
if (value === '--root') root = path.resolve(args[++index]);
else if (value === '--manifest') manifest = args[++index];
else if (value === '--structure-only') structureOnly = true;
else throw new Error(`unknown fixture-runner option: ${value}`);
}
if (!root) throw new Error('fixture runner requires --root');
const { failures, observations } = await verifyRegistry({
root,
manifest,
skipHistory: true,
structureOnly,
fixtureProfile: true,
});
for (const observation of observations) process.stdout.write(`${observation}\n`);
for (const failure of failures) process.stderr.write(`GATE VERIFY FAILED: ${failure}\n`);
if (failures.length > 0) process.exitCode = 1;