# CURRENT — single source of "what happens next" This file always names exactly one next action. Any "continue" / "next" / "proceed" message means: execute the action below, fully (implement → test → verify against its acceptance criteria → commit → push → close the issue → update this file to the next action). No ambiguity, no re-planning. ## Next action Owner review of the completed technical map and separate authorization of a non-author review. Handoff: `docs/plans/2026-09-06_foundation-map-handoff.md` (MAP-HANDOFF-2); map: `docs/plans/2026-09-06_foundation-technical-map.md`. Source/accepted-plan baseline: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`, parent `44f257cb06484feda3412d9382e3587393796353`. Mapping documents are pinned by the separate commit containing this checkpoint, not falsely attributed to d4696d09. Dewey's MS55-DW-3 commit, 43-path scope, parent and index release were verified. Jason's conditional resumption authorization is satisfied. R1-R34 coverage, reconciled package/source ownership, source identities and the bounded inspector recommendation are ready for owner review. Preparing that handoff does not imply independent approval. No implementation, migration, source moves, push or issue closure is authorized. No involvement in the reported ~/.mosaic failure. The extension owns the active mapping goal's lifecycle; this file records task progress and the next approval gate. Earlier phase-2 acceptance remains valid. ## Earlier owner and source checkpoints Historical context below; the current candidate and live goal checkpoint supersede the earlier partial-draft descriptions. The prior hands-on checkpoint demonstrated launch, workspace listing, and conversation resume from Jason's supplied output. Fresh context and mission recovery were not tested. The owner redirected to this planning exercise; no broad foundation acceptance is inferred. Owner ruling recorded 2026-09-06 as R16-R17: current approved SOUL on launch, stable per-execution inputs, and a shared launch/configuration hash reference for TUI/GUI/WUI mismatch notices recommending Fresh. D10 is partly resolved. Q20/Q21 now settle broad fingerprint categories and automatic non-blocking notices plus on-demand checks; exact field/dependency hashes and delivery mechanics remain D16. This does not advance the phase or authorize implementation. Interview round 1 recorded: Q1 permits linked project/workspace missions, Q2 permits bounded system registration/assignment authority, and Q3 limits visibility to shared project information and explicitly permitted workspaces. Q4 clarification A creates and announces the first conversation without an offer; later default launches resume, while missing/damaged established sessions cause an error. Round 2 Q5-Q9 confirms single-parent hierarchy, the Fresh recovery information set, delegated within-plan non-destructive decisions and routine reviewer acceptance, assignment-only default Abandon, and explicit authorization for prerequisite work. Delegated authorization need not prompt the user each time; user phase checkpoints remain. Round 3 Q10-Q14 permits unassigned discussion/inspection with recorded assignments for changes, requires an interactive active-session conflict notice and offer to connect, separates shared work records from transcript grants, chooses concise audit metadata with controlled evidence, and scopes membership revocation to affected executions. Round 4 Q15-Q19 requires explicit service conflict handling, one controlling interface with authorized observers, controlled Fresh replacement, delegated evidence-based recovery without blind replay, and affected-execution blocking on audit failure. Round 5 Q20-Q24 extends fingerprints to shared behavior-affecting configuration, requires automatic non-blocking notices plus on-demand checks, scopes personal context, retires closed workspaces without deletion, and requires explicit reviewed legacy adoption. Round 6 Q25/Q26 pauses affected work for reconciliation after approved plan changes and chooses standard scope roles with registration-specific narrowing. Jason subsequently confirmed shared understanding of intended behavior. Jason then authorized phase 2. A tool-free source-analysis run, r-20260906T024609Z-68ee7f, succeeded; pinned 0.84.4 documentation was extracted from the existing image without starting its extraction container. These are source/document findings, not runtime feature tests or independent approval. The first contract candidate is partial. Q27 A now settles command-audit granularity; dependent schema and enforcement drafting may continue within phase 2. Full schema/plan approval remains pending. ## Accepted phase-2 checkpoint (historical) - Goal: issue-53-phase2. Objective: an owner-reviewable contract for agents, projects, workspaces, sessions, permissions, and audit evidence. Completion owner: Jason. Author/workspace/session remain those recorded below. - State: satisfied. Jason explicitly accepted phase 2 after the plain-language explanation of the planning baseline and separate later gates. P2-7 is complete. REVIEW.md retains D1-D16 and the unproved implementation mechanisms. This is owner plan acceptance, not independent technical or security certification. - Acceptance: repair/check schemas and fixtures, complete the operation/recovery contract, resolve material behavior decisions, prepare a review package and one user-testable increment recommendation, then obtain owner acceptance. - Evidence: `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 command and 38 record shape cases, 16 path cases, 7 restricted-domain hash vectors, 155 runtime/control/artifact cases and 35 synthetic rule-model cases. Ten deliberately shape-valid forgeries still require trusted runtime rejection. These are not runtime security tests or independent acceptance. - Reboot fixture defects were repaired, not discarded. Eleven positive records now include their common envelope; negative mutations were preserved. Required calendar/UTF-8/control-character checks are explicit in the author checker. - Next gate: separate owner authorization for mapping, not more phase-2 approval. No mapping or implementation started. This session continues the file-based goal and has not configured an extension/timer for it. Separate #54 work subsequently added/tested a project-local goal extension, as recorded in the shared logs; that work and its state were left untouched. This session has not migrated issue-53-phase2 into that runtime. Elapsed time never grants approval. - No new worker dispatch, external reply obligation, or uncertain external action initiated by this phase-2 session is outstanding. No numeric work budget supplied; aggregate usage remains unavailable. - Authority remains phase-2 planning and read-only investigation. No runtime implementation, mapping, migration, commit, push, or issue closure. ## Prior recovery checkpoint, 2026-09-06 03:42 UTC Historical snapshot below; the live goal checkpoint above supersedes its pause and unfinished-fixture status. - Goal: issue-53-phase2. State: paused by owner steering. Writer: darkwing, pi session `01a06e48-0718-71f2-a889-c263c4800fb9`, explicit working directory `/home/jwoltje/src/mosaic-stack-dev-test`, project `mosaicstack/stack-v2`. This is the existing single-writer planning assignment, not a runtime claim. - HEAD remains `69d1bb3`. Preserved all uncommitted planning and unrelated skill work. No reset, cleanup, commit, push, or implementation occurred. - Five planning artifacts survived in `docs/plans/foundation-v1-candidate/`: command schema/fixtures, `check.py`, and record schema/fixtures. The three command-check file hashes match the pre-reboot checksums. - `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 shape fixtures and 5 deliberate shape-valid forgeries. This does not prove runtime security. - The unfinished record checker is NOT integrated into check.py. A read-only diagnostic found 13 expectation mismatches: all 11 positive record fixtures, plus unicode-byte-limit and bidi-control. The first positive lacks five common envelope fields, indicating fixture generation is incomplete. Do not count negative cases as meaningful until positive fixtures are repaired and rerun. - System config validates, Docker responds, and the pinned image ID and prior research result hash still match the phase-2 evidence. No Mosaic worker container was running at inspection. Pinned temporary docs remain available. - Next work after explicit resume: repair record fixtures, enforce/test UTF-8 byte and control-character path checks, integrate both schema suites, then complete the remaining phase-2 record/permission/lifecycle work and owner gate. - No outstanding assistant-initiated external action or reply is known. Wake is manual: Jason sends a resume instruction. No timer or automatic continuation is registered. Aggregate usage is unavailable; no numeric budget was supplied. ## Queue (ordered per docs/plans/ROADMAP.md) 1. Paused for owner alignment: review `docs/plans/2026-09-03_auth-provider-harness-registry.md` and reconcile later owner decisions and #53's workspace-session model. Gate 7 remains unresolved. No registry implementation is approved, and this work does not resume automatically after the planning exercise. 2. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation ## Rules - One action in flight. Update this file at the END of every action. - Blocked? Move the item to "Blocked" below with the reason and stop. - Completed actions move to the log at the bottom (date + issue + result). - Corrected entries are marked, never silently rewritten (see 2026-09-03 dedup note). ## Blocked (none) ## Completed log Note (2026-09-03): this log was deduplicated after editor-session races appended duplicate blocks. The dedup removed repeated lines only; every distinct action appears exactly once, in completion order. Ground truth: git history + Gitea issues. - 2026-09-03 — POC: containerized pi hello-world (poc-container-hello-v0) - 2026-09-03 — M1 configuration-driven hello world (#1–#4; config-hello-v1); hotfix #5 stdin detach - 2026-09-03 — M2 mission/task abstraction (#6–#9; mission-task-v1); hotfix #14 release identity in task path - 2026-09-03 — M3 release model + safe updates (#10–#13; release-model-v1); drills: update/refusal/rollback - 2026-09-03 — M14 live user context layer (user/ dispatched to all launches; 0.0.9 built) - 2026-09-03 — M15 agent seats: per-agent SOUL + role contracts (#36; agent-seats-v1); roles/ convention (root = bootstrap-only) - 2026-09-03 — M13 interactive TUI agent + TOOLS.md (#35; interactive-agent-v1); release 0.0.8 activated - 2026-09-03 — M12 conductor auto-apply policy (#34; auto-apply-v1); 17 conductor selftests - 2026-09-03 — M11 session forking (#33; session-fork-v1); child recalls ancestor, base untouched - 2026-09-03 — M10 run-record retention (#32; retention-v1); prune keep-N, dry-run default, receipt - 2026-09-03 — M9 mission capability policy (#30; mission-policy-v1); least-privilege intersection - 2026-09-03 — test UX: green OK/red FAIL status colors; NO_COLOR-aware - 2026-09-03 — M10-era hotfix: retry lineage (#28) + AGENTS.md/SESSIONS.md recovery shim - 2026-09-03 — release 0.0.10 packaged and health-gated activated (user context + agent seats live) - 2026-09-03 — release 0.0.11 shipped (onboarding + live user context); ROADMAP.md agreed (M16–M19); CI deferred by owner - 2026-09-03 — M16 release self-determination (#38; `release.sh ensure` at launch, drift warnings, recursion guard) — logged late: CURRENT.md had gone stale while M16/M17 shipped; ground truth = git history - 2026-09-03 — M17 skill lifecycle + ms-* skill set completion (#40–#42; skill-lifecycle-v1); release 0.0.12 packaged, health-gated active — logged late, same staleness correction - 2026-09-03 — conductor-loop calibration with live collaborator (#43): dispatch via agent-send.sh → receipt → line-by-line diff review → suite-gated integration; docs/TOOLS.md gains Tools (host-side) section + corrected suite counts - 2026-09-03 — skill revisions adjudicated (#44): ms-communications integrated as-authored; ms-conductor redraft + conductor remediation (refusal vs outage); TOOLS.md release.sh ensure row - 2026-09-03 — M18 seat-role progressive capability restriction (#45; roles resolve to contracts, ceiling ∩ seat grant, fail-closed refusals, roles/researcher.json); task suite 74 → 88 - 2026-09-03 — M18 follow-up: fail-closed seat resolution under MOSAIC_AGENTS_DIR override (#46, owner decision after live verification); task suite 88 → 90; next action M19 - 2026-09-03 — M19 harness auth tooling (#47; auth.sh status/accounts, agent.sh --auth per-launch injection via PI_AUTH_FILE, test-auth suite 13 cases with secret-never-printed assertions); agreed sequence M16–M19 complete, M20 owner-gated - 2026-09-03 — M19 correction: auth ownership moved to the data root (#48, owner direction — the stack never writes to default harness config locations; ROADMAP standing decision); auth.sh config-driven, accounts at /auth, 0600 enforced; test-auth 13 → 15 - 2026-09-03 — harness/provider/auth registry specification drafted (#49): agent.json harness declaration, central provider/account/settings registries, runtime seat selection, mechanical per-harness materialization, centralized OAuth refresh, Ollama endpoints, CLI contract; implementation blocked pending ten-gate review