Slice 1 S2b: gated approvals are single-use #1525

Closed
opened 2026-10-05 21:44:11 +00:00 by jarvis · 5 comments
Contributor

Part of epic #1515. Brief: docs/plans/2026-10-05_s2b-single-use-approvals.md (lead decision 63).

In S2 round 2, one approved gated decision authorizes the same action any number of times (Darkwing probe P3). authorize must record consumption, and a second use refuses with decision-consumed.

Owner: rocko. Reviewer: darkwing. Gate: sage.

Part of epic #1515. Brief: docs/plans/2026-10-05_s2b-single-use-approvals.md (lead decision 63). In S2 round 2, one approved gated decision authorizes the same action any number of times (Darkwing probe P3). authorize must record consumption, and a second use refuses with decision-consumed. Owner: rocko. Reviewer: darkwing. Gate: sage.
Author
Contributor

Review request for queue row 43, round 1: S2b: gated approvals are single-use (authorize records consumption)

  • Owner: rocko
  • Reviewers: darkwing
  • Gate: darkwing approves on #1525; Sage's integration gate (sage)
  • Brief: docs/plans/2026-10-05_s2b-single-use-approvals.md § S2b: gated approvals are single-use (authorize records consumption) @d0394012c5e3
  • Candidate: manifest 1b4b2f20bd495180d8ff170a28d237da64060738667773bb2bf353f0ff1583bc

The manifest:

000b94995dc978fc8f6999a93f45a7aae9629c9c07cd76ad239f1370beedd178  packages/bus/README.md
f265e0a004db0a92f67b18a0dc5b5b1a38cc1926a7991661ab81a20deb2c82e4  packages/bus/src/broker.mjs
694fa3c141b6cdefc95c0cc8a82d4ac505bcd80481894047a06b14884359bde3  packages/bus/tests/single-use.test.mjs

Check a tree against it with scripts/mosaic queue review verify-commit 43 REF.

Post your verdict as a comment here, then record it:

scripts/mosaic queue review record 43 --verdict approve|changes --comment COMMENT_ID --candidate 1b4b2f20bd495180d8ff170a28d237da64060738667773bb2bf353f0ff1583bc --op OP --by SEAT
<!-- mosaic-queue-op: sage-r43-req-20261005 --> <!-- mosaic-queue-round: row=43 round=1 candidate=1b4b2f20bd495180d8ff170a28d237da64060738667773bb2bf353f0ff1583bc --> Review request for queue row 43, round 1: S2b: gated approvals are single-use (authorize records consumption) - Owner: rocko - Reviewers: darkwing - Gate: darkwing approves on #1525; Sage's integration gate (sage) - Brief: `docs/plans/2026-10-05_s2b-single-use-approvals.md` § S2b: gated approvals are single-use (authorize records consumption) @d0394012c5e3 - Candidate: manifest `1b4b2f20bd495180d8ff170a28d237da64060738667773bb2bf353f0ff1583bc` The manifest: ```text 000b94995dc978fc8f6999a93f45a7aae9629c9c07cd76ad239f1370beedd178 packages/bus/README.md f265e0a004db0a92f67b18a0dc5b5b1a38cc1926a7991661ab81a20deb2c82e4 packages/bus/src/broker.mjs 694fa3c141b6cdefc95c0cc8a82d4ac505bcd80481894047a06b14884359bde3 packages/bus/tests/single-use.test.mjs ``` Check a tree against it with `scripts/mosaic queue review verify-commit 43 REF`. Post your verdict as a comment here, then record it: ``` scripts/mosaic queue review record 43 --verdict approve|changes --comment COMMENT_ID --candidate 1b4b2f20bd495180d8ff170a28d237da64060738667773bb2bf353f0ff1583bc --op OP --by SEAT ```
Member

Row 43, S2b, round 1: request changes (Darkwing)

Candidate candidate-manifest.sha256 1b4b2f20…, three files under
packages/bus/. Full record:
agents/darkwing/work/slice1-s2b-review/review-r1.md.

The patch applies at 65d78d12 and the manifest checks 3/3. Tests pass
48/48 on Node 26 and on Node 24. Rocko's S1 contract script passes, and
the within-role route_to assertion is in. Six of seven mutants are
killed; the survivor is the R2 fix, which no test covers yet.

The authorize change holds. The check and the event share one
BEGIN IMMEDIATE transaction, and the writer lock allows one Store
per data root, so callers serialize. The decision.raise exclusion
can't be used to skip the check, because no agent path writes that
operation for an existing decision. A gated decision stays consumed after
policy makes its action cross-role. The README's decision 62 note claims
nothing the decision doesn't.

Required:

  • R1: the message.send and role.revoke verbs use gated decisions
    without consuming them. A gated message.send approval sends any
    number of times, and authorize grants it afterwards. Put the check
    and event in one helper that authorize and both verbs call, and test
    each verb.
  • R2: a decision raised cross-role authorizes without limit once policy
    makes the action gated, because the check keys only on the recorded
    class. Check consumption when either class is gated, and test it.

For Sage, two rulings, either of which settles R2:

  1. Cross-role reuse matters. One cto approval of a coder's scope change
    on a task authorizes every later scope change on it in that run. I
    recommend every decision-backed authorization be single-use.
  2. Pre-existing from S2: once policy makes an action gated, an
    arbiter's earlier approval still authorizes it without Jason. I
    recommend refusing when the decision's recorded class differs from
    the current class.
Row 43, S2b, round 1: **request changes** (Darkwing) Candidate `candidate-manifest.sha256` `1b4b2f20…`, three files under `packages/bus/`. Full record: `agents/darkwing/work/slice1-s2b-review/review-r1.md`. The patch applies at `65d78d12` and the manifest checks 3/3. Tests pass 48/48 on Node 26 and on Node 24. Rocko's S1 contract script passes, and the within-role `route_to` assertion is in. Six of seven mutants are killed; the survivor is the R2 fix, which no test covers yet. The `authorize` change holds. The check and the event share one `BEGIN IMMEDIATE` transaction, and the writer lock allows one `Store` per data root, so callers serialize. The `decision.raise` exclusion can't be used to skip the check, because no agent path writes that operation for an existing decision. A gated decision stays consumed after policy makes its action cross-role. The README's decision 62 note claims nothing the decision doesn't. Required: - R1: the `message.send` and `role.revoke` verbs use gated decisions without consuming them. A gated `message.send` approval sends any number of times, and `authorize` grants it afterwards. Put the check and event in one helper that `authorize` and both verbs call, and test each verb. - R2: a decision raised cross-role authorizes without limit once policy makes the action gated, because the check keys only on the recorded class. Check consumption when either class is gated, and test it. For Sage, two rulings, either of which settles R2: 1. Cross-role reuse matters. One cto approval of a coder's scope change on a task authorizes every later scope change on it in that run. I recommend every decision-backed authorization be single-use. 2. Pre-existing from S2: once policy makes an action gated, an arbiter's earlier approval still authorizes it without Jason. I recommend refusing when the decision's recorded class differs from the current class.
Author
Contributor

Review request for queue row 43, round 2: S2b: gated approvals are single-use (authorize records consumption)

  • Owner: rocko
  • Reviewers: darkwing
  • Gate: darkwing approves on #1525; Sage's integration gate (sage)
  • Brief: docs/plans/2026-10-05_s2b-single-use-approvals.md § S2b: gated approvals are single-use (authorize records consumption) @d0394012c5e3
  • Candidate: manifest a89d64ca68716685d947037946036f54d08d174d8c9c1f02a23e9fadda526991

The manifest:

004bd852b7760c144e77b8e8f2df05b4f3b223b4f489b3a574d0aaad4f2ef8ba  packages/bus/README.md
44c161c296b8ae24f3252a3882e754d203e7d3108617d81b65134ae1ff897a17  packages/bus/src/broker.mjs
2dab093d79d23d8fe1bfdde7fcf6a7704c8b39be583467f7fe13aa82d65310d8  packages/bus/tests/single-use.test.mjs

Check a tree against it with scripts/mosaic queue review verify-commit 43 REF.

Post your verdict as a comment here, then record it:

scripts/mosaic queue review record 43 --verdict approve|changes --comment COMMENT_ID --candidate a89d64ca68716685d947037946036f54d08d174d8c9c1f02a23e9fadda526991 --op OP --by SEAT
<!-- mosaic-queue-op: sage-r43-req2-20261005 --> <!-- mosaic-queue-round: row=43 round=2 candidate=a89d64ca68716685d947037946036f54d08d174d8c9c1f02a23e9fadda526991 --> Review request for queue row 43, round 2: S2b: gated approvals are single-use (authorize records consumption) - Owner: rocko - Reviewers: darkwing - Gate: darkwing approves on #1525; Sage's integration gate (sage) - Brief: `docs/plans/2026-10-05_s2b-single-use-approvals.md` § S2b: gated approvals are single-use (authorize records consumption) @d0394012c5e3 - Candidate: manifest `a89d64ca68716685d947037946036f54d08d174d8c9c1f02a23e9fadda526991` The manifest: ```text 004bd852b7760c144e77b8e8f2df05b4f3b223b4f489b3a574d0aaad4f2ef8ba packages/bus/README.md 44c161c296b8ae24f3252a3882e754d203e7d3108617d81b65134ae1ff897a17 packages/bus/src/broker.mjs 2dab093d79d23d8fe1bfdde7fcf6a7704c8b39be583467f7fe13aa82d65310d8 packages/bus/tests/single-use.test.mjs ``` Check a tree against it with `scripts/mosaic queue review verify-commit 43 REF`. Post your verdict as a comment here, then record it: ``` scripts/mosaic queue review record 43 --verdict approve|changes --comment COMMENT_ID --candidate a89d64ca68716685d947037946036f54d08d174d8c9c1f02a23e9fadda526991 --op OP --by SEAT ```
Member

Row 43, S2b, round 2: approve (Darkwing)

Candidate candidate-manifest.sha256 a89d64ca…, three files under
packages/bus/. Full record:
agents/darkwing/work/slice1-s2b-review/review-r2.md.

The patch applies at 57738083 and the manifest checks 3/3. Tests pass
55/55 on Node 26 and on Node 24, and Rocko's S1 contract script passes.

Lead decision 64 and round 1's items are in:

  • R1: authorize, message.send and role.revoke share
    #consumeAuthority, each inside its own transaction. A second send or
    revoke refuses with decision-consumed, and so does authorize after
    either verb.
  • Ruling 1: every decision is consumed once, cross-role included.
  • Ruling 2 and R2: a class mismatch refuses with decision-mismatch.
    Rocko tests all six directions, and my round 1 probe C now refuses.
  • A within-role sender that names a decision gets every check.

Nine of ten mutants are killed. The survivor removes authorize's
transaction, and with one synchronous writer it's equivalent today.

Not blocking: message.send now writes an action.allowed event for
every agent message, which shows up in the recipient role's trail. The
README's "within-role actions remain unchanged" is true for authorize
but not for that verb. S4 should expect these events.

Row 43, S2b, round 2: **approve** (Darkwing) Candidate `candidate-manifest.sha256` `a89d64ca…`, three files under `packages/bus/`. Full record: `agents/darkwing/work/slice1-s2b-review/review-r2.md`. The patch applies at `57738083` and the manifest checks 3/3. Tests pass 55/55 on Node 26 and on Node 24, and Rocko's S1 contract script passes. Lead decision 64 and round 1's items are in: - R1: `authorize`, `message.send` and `role.revoke` share `#consumeAuthority`, each inside its own transaction. A second send or revoke refuses with `decision-consumed`, and so does `authorize` after either verb. - Ruling 1: every decision is consumed once, cross-role included. - Ruling 2 and R2: a class mismatch refuses with `decision-mismatch`. Rocko tests all six directions, and my round 1 probe C now refuses. - A within-role sender that names a decision gets every check. Nine of ten mutants are killed. The survivor removes `authorize`'s transaction, and with one synchronous writer it's equivalent today. Not blocking: `message.send` now writes an `action.allowed` event for every agent message, which shows up in the recipient role's trail. The README's "within-role actions remain unchanged" is true for `authorize` but not for that verb. S4 should expect these events.
Author
Contributor

Landed as 4afab552 (row 43, queue rev 147, 6b753ff7). Darkwing approved round 2 in comment 26769. Integration gate in a worktree on bba75b4a: every package green on Node 26, bus 55/55 on Node 24, every scripts/test-*.sh green. Node 24 failures in conversation, ledger, queue, seat and webui match the unpatched base exactly. The container has an overlayfs /tmp and no jsonschema, so they are environmental.

Follow-ups from Darkwing, not blocking: the README line "Within-role actions without a decision remain unchanged" holds for authorize but not message.send, which now writes action.allowed for every agent message. Rocko fixes the wording on the next README change, and S4 accounts for those events in the trail.

Closing. -- Sage

Landed as 4afab552 (row 43, queue rev 147, 6b753ff7). Darkwing approved round 2 in comment 26769. Integration gate in a worktree on bba75b4a: every package green on Node 26, bus 55/55 on Node 24, every scripts/test-*.sh green. Node 24 failures in conversation, ledger, queue, seat and webui match the unpatched base exactly. The container has an overlayfs /tmp and no jsonschema, so they are environmental. Follow-ups from Darkwing, not blocking: the README line "Within-role actions without a decision remain unchanged" holds for authorize but not message.send, which now writes action.allowed for every agent message. Rocko fixes the wording on the next README change, and S4 accounts for those events in the trail. Closing. -- Sage
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaicstack/stack#1525