Compare commits

..
Author SHA1 Message Date
jarvis 758659ddf9 docs(ri-050): session log — reviews 173/174, rebases, merge plan
ci/woodpecker/pr/ci Pipeline was successful
2026-08-17 20:19:49 -05:00
jarvisandjason.woltje 59e2c46076 docs(ri-050): resume under daily jarvis/fargo handoff protocol (#1275)
ci/woodpecker/pr/ci Pipeline was canceled
2026-08-17 20:12:20 -05:00
fargoandjason.woltje 9b4fb6b548 docs(ri-050): RI-2-001 independent review recorded — APPROVED (#1275)
Review 172 on PR #1278 (head 99b8f6ea): forge suite 116/116 executed at
head, workspace typecheck 45/45, consumer sweep clean, digest gate
before==after. CI red on the PR is the lane-wide fleet-test failure only
and carries no information about the change (fred, log-content analysis).
Continuation by fargo (sb-it-1-dt) per Jason; identity incident and fred's
ruling recorded in the scratchpad. Wave 2 (RI-2-002 + RI-4-001) next.
2026-08-17 20:12:20 -05:00
jarvisandjason.woltje 23204978e1 docs(ri-050): continuation handoff — state, blocker, mechanics, next actions (#1275) 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje bee24fbdd6 docs(ri-050): mark RI-1-001/RI-2-001 in-progress 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje 7d620ea288 docs(ri-050): wave 1 in-progress; lane-unblock dependency noted (#1275) 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje e1e70a9966 style(ri-050): prettier-format TASKS.md 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje e2a9b1ca59 docs(ri-050): bootstrap release-integrity workstream for 0.0.50 (#1275)
- PRD section: normative requirements RI-N1..RI-N5 (decisions SDLC-D-034..038)
- docs/release-integrity/TASKS.md: 10-card DAG, pi-glm-5.3 execution note
- scratchpad: mode, constraints, budget

Executed by jarvis (dragon-lin) with local pi workers per Jason's directive.
2026-08-17 20:12:20 -05:00
4 changed files with 319 additions and 73 deletions
+35
View File
@@ -1368,3 +1368,38 @@ All work is **alpha** (< 0.1.0) until Jason approves 0.1.0 beta release.
10. ASSUMPTION: **Conversations and messages get their own PG tables** (not stored in brain's entity model). They follow a chat-specific schema with proper foreign keys to users and projects. Rationale: Chat has different access patterns (streaming, pagination, search) than brain entities. 10. ASSUMPTION: **Conversations and messages get their own PG tables** (not stored in brain's entity model). They follow a chat-specific schema with proper foreign keys to users and projects. Rationale: Chat has different access patterns (streaming, pagination, search) than brain entities.
11. RESOLVED: **Pi handles all target LLM providers natively.** Anthropic, OpenAI/Codex, Z.ai, Ollama, LM Studio, and llama.cpp are all supported via Pi's built-in providers or `models.json` configuration with `openai-completions` API type. No custom provider adapters needed in @mosaicstack/agent — only configuration management. 11. RESOLVED: **Pi handles all target LLM providers natively.** Anthropic, OpenAI/Codex, Z.ai, Ollama, LM Studio, and llama.cpp are all supported via Pi's built-in providers or `models.json` configuration with `openai-completions` API type. No custom provider adapters needed in @mosaicstack/agent — only configuration management.
---
## Release Integrity Workstream (RI, #1275)
### Problem and objective
At `next` 476db12b (review of 2026-08-17), publication from `next` is not bound to the full verification pipeline for the same commit: the publish pipeline's publish steps depend on `build` only, while ordinary push CI excludes `next`. Public Forge/MACP paths contain false-success placeholders: a stub executor that reports `completed` with exit zero, planning/remediation gates that execute literal `true`, a review gate that echoes an approving verdict, and a gate runner that treats empty commands and unimplemented CI-provider gates as passing. Shipping UI surfaces can render a failed fetch as an empty, healthy collection.
Objective: for alpha 0.0.50, the release cannot publish, report, or display work state that the repository has not actually verified. Decisions SDLC-D-033 through SDLC-D-038 (Jason, 2026-08-17) scope this floor; full decision text and required-behavior lists live in jarvis-brain `docs/plans/2026-08-16_mosaic-stack-sdlc-protocol.md` and `data/decisions/mosaic-stack-sdlc-protocol.json`. This section restates only the normative requirements.
### Normative requirements
1. **RI-N1 Exact-commit publication verification (SDLC-D-034).** One canonical terminal verification command performs self-contained re-verification in the publish pipeline against the job's checked-out commit before any external publication effect. The command contains or invokes the complete mandatory verification set (semantic parity with the PR merge gate, including sanitization, upgrade-guard, typecheck, lint, format check, tests, and build); CI and publication do not maintain separate semantic checklists. Every publish step depends on the verification step in the executable pipeline DAG. Provider commit identity and `git rev-parse HEAD` must identify the same commit. Missing, skipped, cancelled, stale, or inconclusive checks fail closed. Documentation-only runs may skip publication but cannot bypass verification when a publication effect will occur. A negative control must prove that a broken check blocks every publish step.
2. **RI-N2 Fail-closed Forge/MACP with explicit simulation (SDLC-D-035).** Simulation requires explicit caller intent (e.g. `--simulate`) and produces a distinct typed `simulated` state that can never satisfy dependencies, acceptance criteria, gates, merge, or release. Normal execution exits nonzero with a typed capability failure when a required executor, reviewer, command, or CI provider is absent — no stub completion, no literal-`true` gates, no synthetic approvals, no empty-command passes. A manual gate with no automation enters a waiting state; it does not pass. Positive tests prove explicit simulation still works; negative controls prove simulation and every missing-provider case cannot advance lifecycle state.
3. **RI-N3 One transitional PRD authority (SDLC-D-036).** `@mosaicstack/prdy` structured storage under `docs/prdy/`, driven by `mosaic mission --plan`, is the authoritative PRD representation for the alpha. `mosaic prdy` either routes through the same application service or operates only as an explicit, named Markdown import/export adapter; `docs/PRD.md` is not a peer authority. `mission --plan` must persist the mission↔PRD linkage (mission id/version, PRD id/version, selected requirements). Markdown output is a generated view carrying source identity; editing it cannot mutate authority silently. Import is explicit, validated, and conflict-aware (proposed successor, never overwrite). Structural validity is separate from approval.
4. **RI-N4 One quality-rails evaluator (SDLC-D-037).** The TypeScript quality-rails package is the sole authoritative evaluator. A complete probe inventory maps every current TypeScript and shell check to one canonical check with disposition (preserve/strengthen/retire, each named). Effective shell enforcement probes are absorbed before their independent paths retire; expected-file presence alone is not parity. The evaluator returns typed results (`passed`/`failed`/`blocked`/`error`/`not-applicable`) with check version, subject, and reason; missing implementation, missing input, unknown check, process error, timeout, or malformed output can never become `passed` or an unqualified skip. Check definitions and policy are versioned and digested. Shell commands become thin adapters with no separate verdict logic. The canonical terminal verification command (RI-N1) invokes this evaluator rather than duplicating its logic. Contract, parity, and negative-control tests are required, plus independent review of probe equivalence.
5. **RI-N5 Consequence-aware stale UI (SDLC-D-038).** Mission Control distinguishes typed freshness states (`current`, `stale`, `partial`, `unknown`, `unavailable`) rather than inferring from empty arrays or null. A failed fetch never renders as an empty healthy collection. Last-known data may display for situational awareness only with source identity, version, and age visibly labeled; any derived completion/assurance/release verdict whose inputs are stale becomes `unknown`; all state-changing actions are disabled until fresh state loads and is revalidated. With no verified snapshot, surfaces show an explicit unavailable state. Cache corruption, cross-workspace data, schema mismatch, and version regression invalidate the snapshot. Tests cover the failure matrix (network, auth, malformed, partial, corruption, stale age, schema mismatch, recovery, stale-action rejection) with negative controls proving no case yields a current green verdict or enabled mutation.
### Acceptance criteria
- AC-RI-1: A push to `next` that fails any mandatory verification step publishes nothing (no npm package, no image), demonstrated by a checked-in negative control and by pipeline evidence on a real `next` publish run where the verification step is green and every publish step depends on it.
- AC-RI-2: With no executor/reviewer/CI provider wired, Forge and MACP normal runs exit nonzero with typed capability failures; with `--simulate`, runs complete but every result is typed `simulated` and cannot satisfy any gate, dependency, or completion state — proven by unit tests including negative controls.
- AC-RI-3: A PRD created or revised through either `mosaic mission --plan` or `mosaic prdy` resolves to one authority under `docs/prdy/` with stable identities and versions; the mission↔PRD linkage survives restart; a Markdown export is labeled as generated and cannot silently become a second writer; divergent legacy content blocks baseline claims until explicitly resolved — proven by contract tests.
- AC-RI-4: `quality-rails check` through any entry point (TS CLI, framework shell adapter) returns the same typed verdict for the same subject; the probe inventory names every legacy check's disposition; a deliberately broken probe fails closed — proven by contract/parity/negative-control tests and independent review of probe equivalence.
- AC-RI-5: No shipping surface renders a failed fetch as an empty healthy state; stale/partial/unavailable states are typed, labeled, and mutation-disabled — proven by the failure-matrix tests.
- AC-RI-6: All cards merged to `next` via squash PR with terminal-green CI; release evidence for 0.0.50 records commit, verification run, and published artifacts.
### Out of scope
The canonical dispatcher/control-plane vertical slice (work graph, execution attempts, fenced leases, typed check-in, independent verifier dispatch) is decided post-alpha (SDLC-D-033, option B). Multi-pipeline verification certificates (SDLC-D-034 option B) are post-alpha. Full AF-1..AF-4 objective matrices and Mission Control portfolio surfaces are post-alpha.
+42
View File
@@ -0,0 +1,42 @@
# Tasks — Release Integrity Workstream (RI-050, #1275)
> Single-writer: the RI-050 orchestrator (jarvis, dragon-lin) only. Workers read but never modify.
>
> **Mission:** alpha 0.0.50 release-integrity floor (decisions SDLC-D-033..038).
> **PRD:** [docs/PRD.md § Release Integrity Workstream](../PRD.md#release-integrity-workstream-ri-1275)
> **Issue:** #1275 (remains open until RI-V-001 closes)
> **Base branch:** `next` (all cards branch from `origin/next`, squash-merge via PR)
>
> **Execution note:** the `agent` column uses `pi-glm-5.3` — outside the pipeline-cron model
> table on purpose. This workstream is executed by jarvis on dragon-lin with local pi workers
> (`pi --model zai/glm-5.3:high`); pipeline crons must not auto-claim these rows.
>
> **Status values:** `not-started` | `in-progress` | `done` | `blocked` | `failed` | `needs-qa`
> `done` requires: repo quality gates green, independent review recorded, terminal-green CI on
> the PR head, squash merge to `next`, and acceptance evidence in notes.
| id | status | description | issue | agent | repo | branch | depends_on | estimate | notes |
| -------- | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- | ---------- | ----------------- | --------------------------------- | ---------------------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| RI-0-001 | in-progress | Bootstrap: issue #1275, PRD section, this DAG, scratchpad (docs only) | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-mission-bootstrap | — | 6K | |
| RI-1-001 | in-progress | RI-N1: canonical terminal verification command + publish-pipeline exact-commit gate (every publish step depends on verify; commit identity check; fail closed) | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-publish-gate | RI-0-001 | 25K | |
| RI-1-002 | not-started | RI-N1 negative control: checked-in tests proving a broken mandatory check blocks every publish step and that DAG edges cannot be bypassed | #1275 | pi-glm-5.3 | mosaicstack/stack | test/ri-050-publish-gate-negative | RI-1-001 | 12K | |
| RI-2-001 | in-progress | RI-N2 (Forge): remove stub-executor false success; `--simulate` typed `simulated` results that satisfy nothing; literal-`true` gates and echo-review replaced with real gates or typed waiting-for-authority | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-forge-fail-closed | RI-0-001 | 20K | Independent review APPROVED 2026-08-17 (Gitea review 172 on PR #1278, head 99b8f6ea; reviewing seat fargo — recorded under shared host principal mos-dt-0, provenance correction posted by fred; wrapper gap filed by fred). Executed at head: forge tests 116/116, lint green, typecheck green after building macp dist (minimal-install artifact, not a defect), workspace typecheck 45/45, no external type consumers of the changed interfaces. CI red = known lane-wide fleet-test failure only, carries no information about this change (fred, log-content analysis, pipelines 2456-2458). Non-blocking finding: README L141-143 + skills/mosaic-forge/SKILL.md document bare forge run/resume, which now fails closed — fast-follow docs touch. Merge queued behind #1270. |
| RI-2-002 | in-progress | RI-N2 (MACP): gate runner fails closed on empty commands, stub executors, and unimplemented CI-provider gates unless explicit simulate; typed capability failures | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-macp-fail-closed | RI-0-001 | 15K | |
| RI-3-001 | not-started | RI-N4: complete probe inventory mapping every TS and shell quality-rail check to one canonical check with disposition (preserve/strengthen/retire, each named) | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-qr-probe-inventory | RI-0-001 | 12K | |
| RI-3-002 | not-started | RI-N4: TS evaluator absorbs effective shell probes; typed results (passed/failed/blocked/error/not-applicable) with versioned digested check definitions; shell commands become thin adapters; contract/parity/negative-control tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-qr-evaluator | RI-3-001 | 30K | |
| RI-4-001 | in-progress | RI-N3: one PRD application service — `mission --plan` persists mission↔PRD linkage (ids/versions/selected requirements); `mosaic prdy` routes through the service or becomes a named import/export adapter; Markdown is a labeled generated view; explicit conflict-aware import | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-prd-authority | RI-0-001 | 35K | |
| RI-5-001 | not-started | RI-N5: typed freshness states (current/stale/partial/unknown/unavailable); no failed-fetch-renders-empty; stale derived verdicts → unknown; mutations disabled when stale; failure-matrix tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-web-stale-safety | RI-0-001 | 25K | |
| RI-V-001 | not-started | Final verification + release evidence: all cards verified merged, negative controls demonstrated, real `next` publish run green on exact commit, evidence pack recorded | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-release-evidence | RI-1-002, RI-2-001, RI-2-002, RI-3-002, RI-4-001, RI-5-001 | 10K | |
## Dispatch waves (max 2 parallel workers)
1. RI-1-001 + RI-2-001
2. RI-2-002 + RI-4-001
3. RI-3-001 + RI-5-001
4. RI-1-002 + RI-3-002
5. RI-V-001
## Budget
Derived soft cap: 250K tokens (no explicit cap given). Projected total: 190K.
Conservative mode (1 worker) above 70% projected; freeze above 90%.
+242
View File
@@ -0,0 +1,242 @@
# Scratchpad — RI-050 orchestrator (jarvis, dragon-lin)
Mission: alpha 0.0.50 release-integrity floor. Issue #1275. Base `next` @ 476db12b.
Design SSOT: jarvis-brain `docs/plans/2026-08-16_mosaic-stack-sdlc-protocol.md` (SDLC-D-033..038).
## Mode (Jason's directives)
- Orchestrator: jarvis (this session, dragon-lin). NOT mos-claude; work stays on this host.
- Workers: local pi headless — `pi --model zai/glm-5.3:high -p` in the card's worktree, tools read,bash,edit,write.
- Delegation override of stack AGENTS.md `agent` column: rows carry `pi-glm-5.3` (outside cron table so no auto-claim).
- Target branch: `next`. Cards branch from `origin/next`, squash-merge via PR.
## Operational constraints (measured this session)
- Main checkout at `/home/jwoltje/src/mosaic-stack` is a dirty diverged `main` (ahead 1139/behind 711) — NEVER touched. All work in `/home/jwoltje/src/mosaic-stack-worktrees/<branch>`.
- Disk: /home 187G free. /tmp only 8.7G — keep pnpm stores/node_modules under /home.
- `main` and `next` have DIVERGED; PRs target `next`.
- Identity: pin `GITEA_LOGIN=mosaicstack-jarvis` for all wrapper ops. Issue #1275 verified authored by @jarvis.
- `ci-queue-wait.sh` on this host is fail-open (board: fix #1032 not installed) — substitute SHA-status checks via `/commits/{sha}/status` and diff failing step names.
- CI on PRs runs `pull_request` pipelines (any branch) incl. ci-postgres service. Push CI runs on main only; publish runs on push/tag to next + manual.
- Wrapper gaps on this host per board (7 gaps; e.g. no pr-review-list, issue-assign broken, pr-merge makes no trailers): verify outcomes by reading back provider state, never trust rc alone.
- Publish pipeline currently: install → build → publish-npm/publish-next-npm (+image). No verify. CI steps: install, sanitization, upgrade-guard, typecheck, lint, format, test, ci-postgres.
## Budget
Soft cap 250K. Projected 190K across 10 cards. Track per-card used vs estimate in TASKS.md notes.
## Progress log
- 2026-08-16 23:52 — Issue #1275 created (@jarvis verified).
- 2026-08-16 23:5x — Bootstrap branch `docs/ri-050-mission-bootstrap` from origin/next@476db12b; PRD section + TASKS.md + this scratchpad written. RI-0-001 in-progress.
## Wave 1 dispatched (2026-08-17 00:35)
- RI-1-001 worker: pi glm-5.3:high, pid 2322125, worktree ri-1-001, log /var/tmp/ri-050/ri-1-001-run.log
- RI-2-001 worker: pi glm-5.3:high, pid 2322126, worktree ri-2-001, log /var/tmp/ri-050/ri-2-001-run.log
- Gotcha recorded: pi has no -f flag (that's pi-do.sh); pass brief as positional message. First launch died "Unknown option: -f" — relaunched.
- CI lane: PR #1276 (bootstrap) fails `test` at base like every next PR — fred's green #1270 unblocks (comms sent 2026-08-17T05:21Z, `comms/20260817T052148Z__from-jarvis__650fe8.md`). Merge gate for all RI PRs queues behind #1270.
- Live RI-N1 evidence posted to #1275 (comment 22915): pipeline 2439 publish-next-npm SUCCESS beside build-gateway FAILURE.
---
# HANDOFF — RI-050 continuation (written 2026-08-17 ~08:45 UTC, jarvis/dragon-lin)
You are taking over the alpha 0.0.50 release-integrity workstream in place. Everything you
need is on the remote. Read this whole file, then `docs/release-integrity/TASKS.md` (same
branch), then the PRD section (`docs/PRD.md` § Release Integrity Workstream, same branch).
## Identity / mode
- Orchestrator identity: `jarvis` (dragon-lin). You continue as the RI-050 orchestrator under
whatever identity Jason gives you — if you are NOT jarvis, say so in comms and PR bodies.
- Jason's standing directives for this mission: work happens on THIS repo (mosaicstack/stack),
PRs target `next` (NOT main), workers are local pi headless sessions on
`zai/glm-5.3:high`. Do not hand this to mos-claude. Do not borrow other seats' lanes.
- All wrapper ops: pin `GITEA_LOGIN=mosaicstack-jarvis` (issue #1275 was verified authored by
@jarvis; keep identity consistent or verify yours with issue-view and READ BACK user.login).
- CI substitution rule (this host's ci-queue-wait.sh is fail-open; fix #1032 not installed):
judge CI by SHA-status via `/api/v1/repos/mosaicstack/stack/commits/{sha}/status` or the
woodpecker API (`pipeline-status.sh -r mosaicstack/stack -n N -f json`), and DIFF THE
FAILING STEP NAMES rather than trusting rc.
## Mission state at handoff
Mission: alpha 0.0.50 release-integrity floor. Issue #1275 (open, has live-evidence comment).
Decisions SDLC-D-033..038 live in jarvis-brain
`docs/plans/2026-08-16_mosaic-stack-sdlc-protocol.md` (normative text also mirrored in the
PRD section on this branch, so this repo is self-sufficient).
Base: `origin/next` @ 476db12b. NOTE: `main` and `next` have DIVERGED — never base on main.
Branches (all pushed, all clean trees):
- `docs/ri-050-mission-bootstrap` @ 5114faa2 → PR #1276 (open, mergeable) — bootstrap docs +
this scratchpad + TASKS.md DAG. STATUS: CI red on `test` only, which is the known lane-wide
failure (see blocker below); own prettier issue already fixed.
- `feat/ri-050-publish-gate` @ 0aa5ed35 → PR #1277 (open, mergeable) — RI-1-001 COMPLETE
(worker reported success, orchestrator review PASSED: verify step asserts CI_COMMIT_SHA ==
git rev-parse HEAD then runs canonical `pnpm verify:release`; every publish/image step
depends_on verify directly, confirmed by parsing the DAG: publish-npm, publish-next-npm,
build-gateway/appservice/web all -> [build, verify]; invariant test
scripts/verify-release.test.mjs passes 7/7 locally with negative fixtures). CI: same known
lane-red `test` step only.
- `fix/ri-050-forge-fail-closed` @ 99b8f6ea → PR #1278 (open, mergeable) — RI-2-001 worker
reported success (typed `FORGE_*` capability errors, --simulate typed simulated everywhere,
vacuous true/echo gates replaced, closed ForgeOutcome set, 116 tests green incl. 16 new).
ORCHESTRATOR REVIEW NOT YET DONE — your first job. Review the diff
(1391 insertions across forge src), check the fail-closed paths and that simulated
results cannot satisfy any consumer, run `pnpm --filter @mosaicstack/forge test`.
## The one blocker
Every `next` PR pipeline is red on ONE assertion:
`packages/mosaic/framework/tools/fleet/test-start-agent-session.sh:103` ("host provides 'pi'
in the system path"). Pre-existing at base; affects PRs #1276/#1277/#1278 identically.
fred's PR #1270 ("unblocks every PR on next") is green and open — it is HIS to merge; do not
merge it yourself. jarvis sent comms (`comms/20260817T052148Z__from-jarvis__650fe8.md` in
jarvis-brain) asking merge timing; no reply yet as of handoff. Merge gates for ALL RI PRs
queue behind #1270 landing. Until then: review/develop freely, merge nothing that needs the
green gate (docs-only #1276 arguably could merge red-lane with Jason's explicit call — ask,
don't assume).
## Remaining DAG (docs/release-integrity/TASKS.md is canonical)
Wave 2 (next): RI-2-002 MACP fail-closed (brief pattern: mirror RI-2-001 for
packages/macp/src/gate-runner.ts — empty commands, stub executors, unimplemented CI-provider
gates fail closed; explicit simulate) and RI-4-001 PRD authority (one PRD service;
@mosaicstack/prdy docs/prdy authoritative via `mosaic mission --plan`; `mosaic prdy` routes
or becomes named Markdown adapter; mission<->PRD linkage persists — see PRD RI-N3).
Wave 3: RI-3-001 probe inventory (docs), RI-5-001 web stale-safety.
Wave 4: RI-1-002 negative-control tests, RI-3-002 TS evaluator absorbs shell probes.
Final: RI-V-001 evidence pack (real green next publish run post-gate + all cards verified).
## Worker mechanics (measured, reuse)
- Dispatch: create worktree `git -C /home/jwoltje/src/mosaic-stack worktree add
/home/jwoltje/src/mosaic-stack-worktrees/<id> -b <branch> origin/next`, write a brief to
/var/tmp/ri-050/, then run from INSIDE the worktree:
`pi -p --no-session --model zai/glm-5.3:high --tools read,bash,edit,write "$(cat brief.md)"`
(pi has NO -f flag — pass the brief as a positional message; first dispatch died on that).
- Briefs for 1-001/2-001 are at /var/tmp/ri-050/ on dragon-lin (may not survive; the
pattern is fully described above and in TASKS.md).
- Briefs must carry: worktree path, branch, base, requirements, known base-red list (so the
worker doesn't chase it), gates to run, PR creation command with GITEA_LOGIN pin, "do NOT
merge, do NOT touch docs/TASKS.md", and the JSON report format.
- Verify worker claims: read the PR, run their tests yourself, parse pipeline step names.
## Do-not-touch
- Main checkout at /home/jwoltje/src/mosaic-stack (dirty diverged main) — never touch.
- fred's open PRs (#1270 and others) — review evidence welcome, merging his is not yours.
- Other RI PRs' authors' lanes: #1277/#1278 are yours to gate and merge ONCE lane is green
and review is recorded.
- Never `--no-verify`; never bypass the wrapper-fails-closed rule (wrapper failure ⇒
`blocked + report exact command + stop`).
## Session-restore command sequence
1. `git -C /home/jwoltje/src/mosaic-stack-worktrees/ri-050 fetch origin --prune`
2. Read this file + `docs/release-integrity/TASKS.md` + PRD section.
3. Check PR states (#1270, #1276, #1277, #1278) and lane CI (SHA-status per above).
4. Review RI-2-001 (PR #1278) if not yet done; then dispatch wave 2.
— jarvis, 2026-08-17
---
# CONTINUATION — fargo (sb-it-1-dt)
Orchestrator seat is now **fargo** on sb-it-1-dt (Jason, 2026-08-17): Claude seat, worktree discipline
per fred's ruling (`~/agent-work/<slug>`, create → work → commit → push → remove as one act; the
helper's `/src` refusal is a web1 convention, does not bind here). fred supports; lane rulings are
his. Workers remain local pi `zai/glm-5.3:high` + limited Claude per Jason.
## 2026-08-17 — RI-2-001 independent review DONE
- **PR #1278 APPROVED** (Gitea review 172, pinned to head 99b8f6ea). Executed evidence, not read-only:
forge suite 116/116 at head (matches PR claim), forge lint green, forge typecheck green after
building `@mosaicstack/macp` dist (TS2307 on bare `pnpm install --frozen-lockfile` is a
minimal-install build-order artifact — the macp import is type-only, vitest passes unbuilt; CI
installs build workspace deps, hence green there), **workspace typecheck 45/45 at head**,
consumer sweep: no external type consumers of RunManifest/StageStatus/ForgeTaskResult/
TaskExecutor; only importer of the package is packages/mosaic via registerForgeCommand
(smoke test asserts registration/help only — cannot break). Digest gate (shaggy's) before==after
with both-arm reactivity controls.
- CI red on #1276/#1277/#1278: lane-wide `test` failure only
(test-start-agent-session.sh:103, fred's guard mis-wired; #1270 unwires it). Fred measured log
content: one real byte-identical failure per pipeline (2456/2457/2458); 13 of ~14 `FAIL` grep
hits are passing fail-loud test NAMES. **The red carries no information about the RI changes.**
- Non-blocking finding: README L141-143 + skills/mosaic-forge/SKILL.md document bare
`mosaic forge run`/`resume`, which now exits 1 FORGE_NO_EXECUTOR — fast-follow docs touch.
- **Identity incident, ruled on by fred:** review 172 recorded under shared host principal
mos-dt-0, not fargo. Mechanism (measured, wrapper source): pr-review.sh resolves its acting login
from the tea login list only; no fargo tea login on this host → silent host-default fallback;
MOSAIC_GIT_IDENTITY is only read in detect-platform.sh get_gitea_token's fallback arm, never
reached. Exact-id read-back verifies against the writing token, so it passed while attribution
was wrong — durable-provenance machinery proves the write, not the seat. Fred's ruling: review
172 stands (substance/verdict/pin correct; label wrong); NO re-approval (one approval,
annotated, is the stronger record); fred posts the provenance correction under @fred with
--login fred-ms (hard-fail path); no fargo tea login ever (freeze + Jason's to authorize);
tooling gap filed by fred. Also explains (does not reopen) #1228's mos-dt-0 attribution.
- Merge gate: all RI PRs queue behind fred's green #1270 (Jason's call).
## Next
1. Wave 2 dispatch: RI-2-002 (MACP fail-closed, mirror RI-2-001 pattern for
packages/macp/src/gate-runner.ts) + RI-4-001 (PRD authority). Two parallel workers max.
2. Docs fast-follow (README + mosaic-forge skill) — fold into #1276 or a tiny docs card.
3. RI-V-001 evidence at the end.
— fargo, 2026-08-17
---
# RESUMPTION + DAILY-HANDOFF PROTOCOL (Jason, 2026-08-17)
Orchestrator seat is back with **jarvis** (dragon-lin). Expect daily handoff between jarvis
and fargo. Protocol (both seats, every handoff):
1. **This file is the shared mission log.** Append a dated section per session: state
measured, actions taken, PR/review states, next actions. Never rewrite prior sections.
2. **TASKS.md stays current within one session** — status, PR number in notes, review
evidence. Stale rows are handoff debt.
3. **Cross-review rule (SDLC-D-011 in practice):** the reviewing seat must differ from the
producing seat. jarvis reviews fargo-dispatched PRs, fargo reviews jarvis-dispatched
PRs. Producers are always pi workers; dispatching seats verify before push; the other
seat records the Gitea review.
4. Handoff = append here + push + (optional) issue #1275 comment if a decision changed.
## RESUMED — jarvis/dragon-lin, 2026-08-17 (afternoon)
- Measured: next = 8199261c (#1270 merged — lane unblocked for new PRs). #1293/#1294
(fargo, wave 2) CI-green, mergeable, no recorded reviews. #1276/#1277/#1278 still based
on 476db12b with stale red CI → need rebase onto 8199261c. #1278 review pinned to old
head 99b8f6ea by @mos-dt-0 (fargo's, mis-attributed per his note) — rebase will dismiss
it; re-approval must come from fargo/fred (author is @jarvis, cannot self-approve).
- Live evidence #2: push pipeline 2462 (the #1270 merge itself) ran publish-next-npm
SUCCESS beside build-gateway FAILURE again.
- Plan: rebase the three original branches; independently review #1293/#1294; merge order
once green+reviewed: #1276 (docs) → #1277 (publish gate) → #1278/#1293/#1294 (code).
After #1277 merges, watch the next push pipeline prove the verify gate live.
- fargo's non-RI PRs (#1291/#1296/#1297/#1281) stay strictly his lane.
## jarvis session 2026-08-17 (evening) — reviews, rebases, merge plan
- Rebased #1276/#1277/#1278 onto 8199261c (heads 59e2c460 / 46784c8d / 4917df1f);
invariant tests 7/7 and forge 116/116 re-run green at new heads. #1270 touched
test-enumeration-exclusions.txt + package.json, NOT ci.yml — no semantic overlap with
#1277's ci.yml changes (checked, was a real concern).
- Independent reviews recorded: #1293 APPROVED (review 173; macp 109/109; fail-closed paths
+ aggregate state machine verified), #1294 APPROVED (review 174; prdy 20/20 + command
specs 9/9; single-writer + linkage persistence + labeled export + conflict-aware import
verified). Note: 19 unrelated mosaic suites fail on bare minimal install (known workspace
build-order artifact, documented by fargo) — not this change.
- Measured: `next` has NO branch protection (API: only main listed). Cross-seat review
discipline is protocol-enforced, not Gitea-enforced. Flagged to fargo for Jason: direct
pushes to next trigger ungated publishes; protection is Jason's call (#1231 adjacent).
- Merge order planned: #1276 (docs-only — no publish run) -> #1277 (first gated publish)
-> #1278 -> #1293 -> #1294. Sent fargo review requests with pinned head SHAs
(comms/20260818T011932Z__from-jarvis__a9c02b.md). Not merging #1293/#1294 before my three
clear fargo's review — order optimality beats speed; every pre-#1277 merge publishes ungated.
- CI on the three rebased heads: pending at time of this entry.
@@ -1,73 +0,0 @@
# 2026-08-17 — Fleet identity, comms delivery, and the ~/.mosaic tree (continuation record)
> **Status:** active continuation record | **Owner:** Jason (rulings) / fleet (delivery) | **Created:** 2026-08-17, sb-it-1-dt session with Jarvis (jarvis-brain)
> **Audience:** the homelab agents continuing this effort tonight. Read this whole file before acting; it supersedes nothing but preserves structure and decisions that must not be lost.
---
## Why this exists
A session on sb-it-1-dt (2026-08-17) produced three architecture decisions (two awaiting Jason's ruling), one incident postmortem (#1295), interim guardrail edits in the user-owned `~/.mosaic/` contract tree, and one new tool (`ensure-watcher.sh`). The work spans jarvis-brain (P0, not retained) and this repo (the product). **This file is the stack-side anchor so continuation does not depend on jarvis-brain surviving.**
## 1. The `~/.mosaic` tree model — as-built, preserve this structure
Three-tree split (this is design intent, not accident; keep it through all framework work):
| Tree | Owner | Rule |
| ------------------- | --------- | ------------------------------------------------------------------------------------------------------------- |
| `~/.config/mosaic/` | framework | upgrade-managed templates; NEVER user-edited; `mosaic upgrade` may overwrite |
| `~/.mosaic/` | user | working contracts, guides, fleet agents; upgrades reconcile with **deny-wins** (user edits never overwritten) |
| repo satellites | repos | bootstrapped per-repo `.mosaic/` state |
As-built inventory of `~/.mosaic` on sb-it-1-dt (2026-08-17):
- **Contract core:** `CONSTITUTION.md` (L0 law), `AGENTS.md` (dispatcher + guide router + Fleet Comms Watcher requirement), `SOUL.md` (generic base for ALL fleet agents, zero persona — includes the new **Fleet Boundaries** section), `STANDARDS.md` (universal standards — includes new **session identity** + **comms watcher hygiene** sections), `SYSTEM.md` (pure communication contract, byte-identical to jarvis-brain's prompt-testing `sr_opus_5_system_prompt.md`), `USER.md`, `TOOLS.md`.
- **`guides/`** — user-owned working copies (E2E-DELIVERY, ORCHESTRATOR(+PROTOCOL,+LEARNINGS), WAKE-DOCTRINE, VAULT-SECRETS, etc.).
- **`fleet/agents/`** — the per-agent store (this is MOSAIC-D-002's substrate, already in use):
- real agent dirs: `fargo/`, `orchestrator/`, `probe/`, `vision/`, `weekly-update/` — shape: `profile.json` (harness/account/overlay pointer) + `overlay.json` + `SOUL.md` (persona) + `scratch/` `work/` `notes/` subdirs (hygiene rules in root SOUL.md)
- `*.env.generated` launch overlays: `luna` `sol` `terra` (carry `MOSAIC_AGENT_NAME`, `_CLASS`, `_RUNTIME`, `_MODEL`, `_REASONING`, `_TOOL_POLICY`) — these are the mosaic-fleet seat launch envs; `inbox.env`, `itops.env` also present
- `probe/` is the validated layout proof: auth-bundle symlink chain, per-agent sessions, plugin-store symlink (from 2026-08-07)
- **`auth/`, `config/`, `memory/`, `plugins/`, `skills/`, `skills-local/`** — per-tree copies/links for runtime isolation.
- Related but outside the tree: watcher units at `~/.config/systemd/user/<agent>-comms-watcher.service`; watcher seen-state at `~/.local/state/comms-watcher-<agent>/`.
## 2. Decisions register (2026-08-17 session)
Full strict records live in jarvis-brain `docs/decisions/mosaic-stack/` (render on its dashboard); both are **Pending Jason's ruling**. Summaries so the content survives P0:
- **MOSAIC-D-001 — SYSTEM.md as canonical harness system prompt.** Static core (Constitution+AGENTS+USER+overlays) in one tracked file; launcher renders dynamic tail (mission/PRD/fleet/persona). Delivery: `--append-system-prompt` (repeatable) for pi/claude; symlinked core file for codex (`$CODEX_HOME/instructions.md`) and opencode (`AGENTS.md`); their dynamic tail via initial prompt (needs live verification). Static-first order is the cache win. `SYSTEM.md` in `~/.mosaic` today is the communication-contract file — D-001's SYSTEM.md is the broader composition; naming to reconcile at implementation.
- **MOSAIC-D-002 — per-agent harness homes + mechanical profiles.** Launch with targeted config-dir env vars (e.g. `PI_CODING_AGENT_DIR=~/.mosaic/fleet/agents/<name>/pi`), NOT literal HOME. SOUL.md identity mechanically generated from roster (single writer; kills the hand-copy drift measured in `agents/vision/SOUL.md` on jarvis-brain: declared Jarvis, answered Vision). Composes: SYSTEM core → per-agent SOUL → dynamic tail. `MOSAIC_AGENT_NAME` stays load-bearing for comms.
- **Comms delivery tooling belongs in the STACK framework, not jarvis-brain** (decided in discussion; supersedes the interim placement). jarvis-brain keeps only the transport _data_ (`comms/` tree) while it lives. Agents launch from their own repos (terra from `~/src/stack` etc.) — delivery is transport-repo-relative, so this works; but every installed watcher unit's ExecStart currently points into `~/src/jarvis-brain/scripts/` — that dependency is the P0 trap to remove. Migration = move tools + regenerate units, in one step.
- **Watcher provisioning is instantiation duty, never running-agent duty.** Interim landed as jarvis-brain `scripts/comms/ensure-watcher.sh` (idempotent ensure + `--status` boot check + interim identity warnings: missing target session, pane `MOSAIC_AGENT_NAME` mismatch via `/proc/<child>/environ`, bare-runtime NOTE). Framework move: fold into `mosaic agent --new` + fleet launch + `mosaic doctor` drift check.
- **Prose guardrails landed (interim fences until mechanical fixes):** `~/.mosaic/SOUL.md` Fleet Boundaries (wrong-session tripwire; comms ownership; cross-agent investigation requires tasking) · `STANDARDS.md` session identity + watcher hygiene · `AGENTS.md` Fleet Comms Watcher requirement (P0-interim script path marked transitional).
## 3. Incident → #1295 (already tracked here)
`https://git.mosaicstack.dev/mosaicstack/stack/issues/1295` — docs-seat incident: cwd-keyed session files served three lives (dev chat → goals seat → 22 watcher injections into a wedged process); name-based watcher delivery with no identity verification; wedge after pi 0.84.1→0.84.2 update passes every liveness instrument. Proposed fixes enumerated there; provisioning follow-up in comment ID 23027.
## 4. Open work queue (suggested sequence)
1. **Comms tooling migration PR** (lane `next`): move `comms-watcher.sh`, `install-watcher.sh`, `ensure-watcher.sh` into the framework tree → deploy `~/.config/mosaic/tools/comms/`; regenerate existing units' ExecStart to framework paths (one-command sweep); keep `COMMS_WATCH_REPO` per-host config (points at a brain checkout until the queue transport lands). Reference: jarvis-brain commit `701c353b1`.
2. **Ensure-on-instantiation**: `mosaic agent --new` / fleet launch call ensure semantics; `mosaic doctor` gains the drift check (`--status --all` semantics + `fred`'s hand-written unit as the known drift case; also note daphne/docs/happy/pepper/sanity/tiny/fargo currently have no watcher — cover or consciously exempt).
3. **MOSAIC-D-002 implementation** (after ruling): per-agent homes via targeted env vars; roster-generated SOUL.md single-writer; extend the existing `*.env.generated` pattern; launch ledger keeps `config_home` audit.
4. **MOSAIC-D-001 implementation** (after ruling): SYSTEM.md sourcing + per-harness delivery + `compose-contract` becomes render-core+tail with drift check; bench cache-ordering before/after (jarvis-brain `domains/software-dev/mosaic-stack/prompt-testing` has the bench).
5. **Queue transport + forced separation** (longer term): supersedes watcher path; identity-verification and wedge-detection remain valid regardless of transport.
6. **Docs inheritance**: jarvis-brain AGENTS.md's durable comms guidance (E7 pi-glyph delivery gotchas, capture-pane rules, comms protocol) must be inherited into stack docs before P0 retirement.
## 5. Rules for tonight's agents
- Lane: **`next`** only; nothing to `main` without Jason (standing ruling).
- Attribution caveat #1280: Gitea/git identity from this host may misattribute (issue #1295 showed as created by `@mos-dt-0`); prefer per-invocation `git -c user.name=<seat>` and verify what the remote recorded.
- Do not delete `sb-it-1-dt:docs]` (untracked file at repo root) — it is cited fleet-wide as incident evidence.
- Edit user contracts in `~/.mosaic/`, never the templates in `~/.config/mosaic/`.
- Do not restart other fleet seats unilaterally (goals/scrappy/sanity restart decisions are fred's/Jason's per the docs-seat report).
## 6. Artifact map
| Artifact | Where |
| ------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ |
| Decision records D-001/D-002 (strict, pending ruling) | jarvis-brain `docs/decisions/mosaic-stack/2026-08-17_mosaic-d-00{1,2}_*.md` |
| Incident issue + provisioning comment | stack #1295 + comment 23027 |
| ensure-watcher.sh (reference implementation) | jarvis-brain `scripts/comms/ensure-watcher.sh` (commit `701c353b1`) |
| Bench for prompt A/B (pi, thinking levels, footer-token semantics) | jarvis-brain `domains/software-dev/mosaic-stack/prompt-testing/` + `docs/reports/2026-08-17-prompt-testing-glm-bench.md` |
| Launcher inspection basis | `@mosaicstack/mosaic` 0.0.49 `dist/commands/launch.js` (composeContract / ensureRuntimeConfig / harness-home isolation) |
| Guardrail edits | `~/.mosaic/{SOUL,AGENTS,STANDARDS}.md` on sb-it-1-dt (2026-08-17 16:5317:04) |