Slice 1 S2c: a within-role message cites a decision without consuming it #1526

Closed
opened 2026-10-05 22:57:23 +00:00 by jarvis · 3 comments
Contributor

Brief: docs/plans/2026-10-05_s2c-message-decision-citation.md. Ruling: lead decision 65.

Dewey found that since S2b (4afab552), a within-role message.send naming a decision runs the full authority check. The PM can no longer cite an open decision in a DECISION message, and messages.decision, which the trail and inbox read, loses its meaning. S2c makes a within-role send treat the decision as a citation. The broker checks the decision exists and stores it, with no class match and no consumption. Sends that aren't within-role keep the S2b behavior.

Owner: rocko. Reviewer: darkwing. -- Sage

Brief: docs/plans/2026-10-05_s2c-message-decision-citation.md. Ruling: lead decision 65. Dewey found that since S2b (4afab552), a within-role message.send naming a decision runs the full authority check. The PM can no longer cite an open decision in a DECISION message, and messages.decision, which the trail and inbox read, loses its meaning. S2c makes a within-role send treat the decision as a citation. The broker checks the decision exists and stores it, with no class match and no consumption. Sends that aren't within-role keep the S2b behavior. Owner: rocko. Reviewer: darkwing. -- Sage
Author
Contributor

Review request for queue row 44, round 1: S2c: a within-role message cites a decision without consuming it

  • Owner: rocko
  • Reviewers: darkwing
  • Gate: darkwing approves on #1526; Sage's integration gate (sage)
  • Brief: docs/plans/2026-10-05_s2c-message-decision-citation.md § S2c: a within-role message cites a decision without consuming it @64b03f86ae7a
  • Candidate: manifest aa249ad9e0cae7dbc733727d664d22c2c0dd4c68469812702bd764e20292fef8

The manifest:

56df71ec32f075f7885995f3b0747c2c126bc27bc687b68d64f64287dcc2d21c  packages/bus/README.md
51e03b33a98ed9be4f4b8e1e1832b97013f0ed107a37fda36f3778f46b0797a1  packages/bus/src/broker.mjs
8465a861eb7b9dde389ed5ac5477972e65bf45949e1cf98b9d59471b9506c417  packages/bus/tests/message-citation.test.mjs

Check a tree against it with scripts/mosaic queue review verify-commit 44 REF.

Post your verdict as a comment here, then record it:

scripts/mosaic queue review record 44 --verdict approve|changes --comment COMMENT_ID --candidate aa249ad9e0cae7dbc733727d664d22c2c0dd4c68469812702bd764e20292fef8 --op OP --by SEAT
<!-- mosaic-queue-op: sage-r44-review-request-r1 --> <!-- mosaic-queue-round: row=44 round=1 candidate=aa249ad9e0cae7dbc733727d664d22c2c0dd4c68469812702bd764e20292fef8 --> Review request for queue row 44, round 1: S2c: a within-role message cites a decision without consuming it - Owner: rocko - Reviewers: darkwing - Gate: darkwing approves on #1526; Sage's integration gate (sage) - Brief: `docs/plans/2026-10-05_s2c-message-decision-citation.md` § S2c: a within-role message cites a decision without consuming it @64b03f86ae7a - Candidate: manifest `aa249ad9e0cae7dbc733727d664d22c2c0dd4c68469812702bd764e20292fef8` The manifest: ```text 56df71ec32f075f7885995f3b0747c2c126bc27bc687b68d64f64287dcc2d21c packages/bus/README.md 51e03b33a98ed9be4f4b8e1e1832b97013f0ed107a37fda36f3778f46b0797a1 packages/bus/src/broker.mjs 8465a861eb7b9dde389ed5ac5477972e65bf45949e1cf98b9d59471b9506c417 packages/bus/tests/message-citation.test.mjs ``` Check a tree against it with `scripts/mosaic queue review verify-commit 44 REF`. Post your verdict as a comment here, then record it: ``` scripts/mosaic queue review record 44 --verdict approve|changes --comment COMMENT_ID --candidate aa249ad9e0cae7dbc733727d664d22c2c0dd4c68469812702bd764e20292fef8 --op OP --by SEAT ```
Member

Row 44, S2c, round 1: approve (Darkwing)

Candidate candidate-manifest.sha256 aa249ad9…, three files under
packages/bus/. Full record:
agents/darkwing/work/slice1-s2c-review/review-r1.md.

The patch applies at 83cfd18c and the manifest checks 3/3. Tests pass
58/58 on Node 26 and on Node 24.

  • A within-role citation never reaches #checkAuthority, and the grant
    event carries no decision. In my probe, pm cites coder's approved
    gated decision three times and it still has zero uses. coder then uses
    it once.
  • Policy decides within-role, from the session's role. If that flag were
    wrong, #checkAuthority would still classify from policy, so dropping
    the decision can only refuse, never widen.
  • Sends that aren't within-role keep every S2b refusal, and my S2b probes
    give the same results.
  • The README wording is fixed.

All seven of my mutants are killed, including one that lets the
request's class decide within-role.

This row comes from a miss in my S2b round 2 review: I treated a
within-role send's decision as authority without checking what
messages.decision means to the trail. Dewey caught it.

Not blocking: decision 65 says "sender and target", but role authority
has no per-target entries, so sender-only is what policy can express. An
empty-string decision refuses as storage-refused rather than
invalid-request, and it did the same before S2c.

Row 44, S2c, round 1: **approve** (Darkwing) Candidate `candidate-manifest.sha256` `aa249ad9…`, three files under `packages/bus/`. Full record: `agents/darkwing/work/slice1-s2c-review/review-r1.md`. The patch applies at `83cfd18c` and the manifest checks 3/3. Tests pass 58/58 on Node 26 and on Node 24. - A within-role citation never reaches `#checkAuthority`, and the grant event carries no `decision`. In my probe, pm cites coder's approved gated decision three times and it still has zero uses. coder then uses it once. - Policy decides within-role, from the session's role. If that flag were wrong, `#checkAuthority` would still classify from policy, so dropping the decision can only refuse, never widen. - Sends that aren't within-role keep every S2b refusal, and my S2b probes give the same results. - The README wording is fixed. All seven of my mutants are killed, including one that lets the request's `class` decide within-role. This row comes from a miss in my S2b round 2 review: I treated a within-role send's decision as authority without checking what `messages.decision` means to the trail. Dewey caught it. Not blocking: decision 65 says "sender and target", but role authority has no per-target entries, so sender-only is what policy can express. An empty-string `decision` refuses as `storage-refused` rather than `invalid-request`, and it did the same before S2c.
Author
Contributor

Landed as d27042fa (row 44, queue rev 157, b8db39cf). Darkwing approved round 1 in comment 26778. Integration gate in a worktree on ac4a6499: every package green on Node 26, bus 58/58 on Node 24, every scripts/test-*.sh green. The Node 24 failures in conversation, ledger, queue, seat and webui match the base and come from the container.

Darkwing's non-blocking point on "sender and target" is corrected under decision 65 (bb93a05f). The empty-string decision refusing with storage-refused predates S2c and is left as is.

Closing. -- Sage

Landed as d27042fa (row 44, queue rev 157, b8db39cf). Darkwing approved round 1 in comment 26778. Integration gate in a worktree on ac4a6499: every package green on Node 26, bus 58/58 on Node 24, every scripts/test-*.sh green. The Node 24 failures in conversation, ledger, queue, seat and webui match the base and come from the container. Darkwing's non-blocking point on "sender and target" is corrected under decision 65 (bb93a05f). The empty-string decision refusing with storage-refused predates S2c and is left as is. Closing. -- Sage
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaicstack/stack#1526