# CURRENT — narrative log of the work in flight The task list is `docs/plans/QUEUE.md`: one table, one row per piece, with owner, state and gate. Read that first; it says what is next for you. This file holds the narrative behind the rows and the completed log, and it does not always name one action any more. If the two disagree, QUEUE.md wins. This file historically named exactly one next action. Any "continue" / "next" / "proceed" message means: execute the action below, fully (implement → test → verify against its acceptance criteria → commit → push → close the issue → update this file to the next action). No ambiguity, no re-planning. ## Next action Current owner priority: #1512, QUEUE row 6 prescribed Filbert relaunch-activity pilot. Filbert acknowledged sole source ownership; Darkwing reviews backend and Dewey acknowledged UX review. Charter: `2026-09-15_relaunch-activity.md`. Darkwing created/read back #1512 as authenticated Darkwing, set the owning native seat's task through Piece5 step3 with identity preserved, and independently reproduced old assistant text still presented after a newer live registration in an isolated fixture. Evidence: `agents/darkwing/work/relaunch-activity/baseline.json`. R1 arrived with seven pinned source files. Darkwing approved backend/source; Dewey approved scoped UX with eight frozen targeted tests. Darkwing's first full serialized run failed an inherited Discord engine tool-turn test then hung120s. A later full frozen TAP run with a15s test deadline passed351/351 without force-exit. Rocko diagnosed a test busy/settled-event race and success-only cleanup hang; Darkwing independently reproduced the busy assertion with a 50ms event split and finally cleanup. A separate timeout-log timing flaw and a potential engine followUp-after-timeout defect were also reported. The latter belongs to row21; no live incident is claimed. orch-01 was notified on its verified named socket. Evidence: `agents/darkwing/work/relaunch-activity/engine-diagnosis.md`. Darkwing verified 31 frozen Discord dependency files match commit1ac812d3. Filbert confirmed his archive used moving HEAD and the old HANDOFF label was wrong. He supplied an append-only correction outside R1; Darkwing verified its hash and all89 frozen dependency pins. Local copies are `r1-provenance-correction.json` and `r1-dependencies.sha256` under the relaunch-activity work directory. Provenance hold resolved; original R1 and all seven source pins remain unchanged. 2026-09-26: 1685deb4 fixed the engine test race. A re-run of the frozen candidate against 21e3e908 passed the serial acceptance command 397/397 three times. Failures that only show when tests run concurrently are #1509 engine tests and reproduce on clean HEAD (`relaunch-activity/rerun-2026-09-26.md`). Sage ruled that #1512 integrates on the serial evidence. #1511 and #1512 are committed locally in af4203ca with rows 18 and 22, and not pushed. The engine defects are a DEFERRED entry against #1509. #1512 closes after Sage's records commit. The board restart that shows #1512 live and the Gate F live assignment both wait on Jason. Next for Darkwing: the #1506 ledger fix for T3 headers (Filbert reviews), then the #1509 engine test and `busy` fixes (Rocko reviews, source only). No live action, publication, operator acceptance or GateF claim. Standing owner mandate: after each accepted iteration, automatically execute the next ready authorized item, without a routine next-step prompt. Existing scope, review, access, acceptance and protected-operation gates still apply. Jason accepted row 18 with "parfait". The newer standing continuation instruction supplies the start for the next already-briefed row 6, replacing its historical Sunday start-message scheduling, without waiving dependencies or protected gates. Rocko's existing native repository context was verified and he acknowledged sole source ownership under `2026-09-14_task-attribution.md`. Filbert and Dewey both acknowledged independent review ownership. Darkwing reproduced the current CLI refusing --by with exit 4 using no live configuration or registration. Evidence: `agents/darkwing/work/task-attribution/baseline.json`. R1 arrived and all 15 working/frozen pins matched. Filbert approved backend source, reporting independent 141/141 working/overlay tests and six launcher checks. Dewey requested R1-U1: WebUI inspector conflates null/inapplicable attribution with legacy registered unknown. Both lanes returned before Rocko received the bounded R2 correction, including a misleading privacy-syntax comment correction. Review record: `agents/darkwing/work/task-attribution/r1-review.md`. Darkwing added only the missing --by usage flag to dirty `docs/TOOLS.md`, preserving other changes; that additive documentation also requires independent review. R2 has now passed both exact source review lanes. R1-U1 and the comment finding are closed; Filbert also approved the separate TOOLS usage patch. Darkwing ran 344/344 broader serialized tests. Evidence and limits: `agents/darkwing/work/task-attribution/r2-review.md`. Old strict-v1 readers reject the new field, independently reproduced with synthetic records. No live setter write may precede the authorized reader update. Jason authorized that envelope with yes. On 2026-09-15, backend PID 3769124 exited gracefully; replacement 3414098 is healthy and serves the exact reviewed board page. API exposes the new attribution field; two legacy registered rows show unknown and non-registration tasks have null attribution. The Rocko write was blocked before mutation: its registration names dead PID 185602, actual native lock owner is 3707667, and its discovery directory is absent, so there is no Rocko board row. This existing Claude-board gap remains separate; no identity repair or discovery expansion was attempted. All registration bytes, five agent pane identities and connector identity stayed unchanged. Receipts: `agents/darkwing/work/task-attribution/backend-restart.jsonl` and `backend-live-verification.json`. Jason authorized Filbert instead and confirmed Claude console integration is not yet implemented. Filbert's native registration identity was reverified; the authorized task update passed live API verification at 2026-09-15T00:36Z: task '#1511 task attribution user test', source registration, setter darkwing. Only task/taskSetBy/updatedAt changed; identity fields and startedAt were preserved. All other registrations and agent/connector/backend identities stayed unchanged. Original registration is backed up privately outside the repository. Receipt: `agents/darkwing/work/task-attribution/live-test.jsonl`. Jason supplied the table screenshot and inspector text confirming darkwing with 'as claimed by the caller, not verified'. Bounded local attribution delivery is operator-confirmed. Publication remains separate. The standing continuation mandate now advances the prescribed Filbert assignment above, after this local acceptance. Gate F is not claimed or backdated. #1508 still depends on row 6 completion. ## Completed bounded row 18 delivery Actual start: Filbert acknowledged sole implementation ownership under `2026-09-14_discord-board-row.md`; Darkwing independently reviews backend/privacy and Dewey acknowledged read-only UX review. Darkwing prepared acceptance checks and reproduced the missing reply refusal with a synthetic connector plus forged registration: current handler returned 200 and called fake transport once, with zero real sends. Evidence: `agents/darkwing/work/discord-board/reply-baseline.json`. Exact R3 source approvals from Darkwing and Dewey are persisted in 26257. Nine working/frozen pins and three-file R2 delta independently verified; full serialized suite 322/322 passed, plus Dewey's eight targeted tests. R1-B1 and R2-B2 closed: inaccessible STOP is unknown and connector Task is fixed safe metadata, not a routing envelope. Prior attention/UI assets are preserved. Read-only live observation after approval found shared-signals alive/idle, not braked, owner matching systemd MainPID, fixed Task and no registration. Evidence: `agents/darkwing/work/discord-board/r3-live-observation.json`. Owner approved the backend-only restart. Old PID 3204655 exited gracefully; replacement PID 3769124 is healthy on 7331. Live API now shows the shared-signals connector idle/live/not braked with safe Task metadata; actual connector reply POST was refused with 409 before transport. All five agent pane identities and the connector service PID/start identity are unchanged. Evidence: `agents/darkwing/work/discord-board/backend-live-verification.json`. Jason accepted the operator visual test with "parfait". This bounded local row delivery is complete, without publication or live brake/offline transition claims. No connector service/binding/STOP/home changes. Concurrent R1 timeouts remain unresolved/not green and are recorded in DEFERRED.md; no general transcript redaction or broader runtime conformance claimed. Standing continuation has advanced to row 6 above. Filbert remains the row-18 source author; frozen R3 evidence remains unchanged. Prior accepted correction: #1503, QUEUE row 22, board attention status correction. Jason passed internal-team checks 1-4 and reported Researcher's false waiting status in step 5. He approved ordinary completion becoming idle and reserving waiting for explicit human-input requests. Filbert approved exact R1, receipt 26248. Author 144 and reviewer 193 covered different package sets; the combined five-package author rerun passes 213 tests. Read-only actual Researcher scan returns idle and waitingOnYou:false. Owner approved backend-only restart, now completed and live-verified in receipt 26249: old PID 1265952 exited gracefully, replacement PID 3204655 is healthy on loopback 7331. Live API shows Researcher idle/not waiting at the original screenshot activity timestamp. All five agent process identities are unchanged. Jason confirmed both targeted tests: ordinary completion shows idle; an explicit input request shows waiting, Seen removes it from attention without resolving waiting, and the subsequent completion returns to idle. The full targeted status sequence is operator accepted. This is not broader MVP/cross-harness acceptance or publication; do not resume another queue item by inference. Brief: `2026-09-13_board-attention-status.md`. Prior bootstrap checkpoint: #1510, QUEUE row 16. Darkwing coordinates direct coding, review and research through the five repository-native agents. Keep source changes in `/mnt/storage/src/mosaic-stack`; no `~/.mosaic` launcher/provisioning changes and no live fleet stop or migration. Researcher's missing native entry and recovery files are added. Six isolated launcher tests and all five real `--check` runs pass without launching engines. Internal Filbert approved exact R1 as source; attributed receipt 26204, independently rerunning six tests in both working and frozen copies. Source setup is approved. Owner-authorized live smoke passed for Researcher, which returned the exact expected model response, receipt 26216. Rocko startup correctly refused an existing native lock; its running repository-native Sonnet process is on the mosaic-fleet socket and was left intact, not retested with a model prompt. No existing sessions restarted, home launchers modified or broader MVP/user acceptance or publication claimed. Brief: `2026-09-13_internal-development-bootstrap.md`. The historical MVP queue and CHAT-01C publication gate below remain separate; this direction does not resume #1508 or authorize external provisioning. Gaps found and not fixed go to `docs/plans/DEFERRED.md`, one line each; check it at every gate. Jason decided on 2026-09-12 (MOSAIC-STACK-D-001) that the MVP is the control board: one web page listing running agent sessions across projects, showing each one's status, and flagging which ones are waiting on him. Plan page: `docs/plans/2026-09-12_control-board-mvp.md`. Tracking: #1503. Steps 1 and 2 are done in this checkout: `packages/control-board` scans every Pi agent (repo `.pi/state/*` and `~/.mosaic/fleet`) and serves the page. Start it with `node packages/control-board/src/cli.mjs serve` and open http://127.0.0.1:7331/ (loopback only, no auth, no daemon; Ctrl-C stops it). First step-3 refinement landed 2026-09-12: liveness follows the tmux pane (killed pi sessions show offline) and a "Seen" button drops read rows out of "Waiting on you" until the agent writes again (`docs/plans/reviews/2026-09-12_control-board-step3-seen-marks.md`). Gate A (task, active project, workspace per row) passed on 2026-09-12 and Jason's go on the professor session's brief opened #1504: seat registration. `scripts/mosaic launch ` runs a seat's launch script unchanged and leaves one record at `/seats///registration.json` that the board reads instead of guessing; `scripts/mosaic seat task ` changes the task. The four repository launch scripts register themselves. Package: `packages/seat`. Fleet seats stay on their own launchers (Jason's ruling, 2026-09-12); only `agents/` seats register. A record whose pid is gone is stale and does not override the derived values. Gate B passed 2026-09-12 (seat registration shown and used on the board). Piece 2, reply-from-board (#1505; brief in the plan page, section "Piece 2: reply-from-board", approved by Jason 2026-09-12), is built and pushed 2026-09-12: a text box and Send in the detail of registered, live rows; `POST /api/reply` runs `tools/tmux/agent-send.sh -s -S ":control-board" [-L ] -m ` and returns the exit code, stdout and stderr; the page shows `delivered` or `failed` with the stderr. No send-keys, queue, history or broadcast; no change to `packages/seat` or `agent-send.sh`. Board suite 98/98. Gate C passed 2026-09-12 on 867619dc (logged by Jason at 4f830680): "pizza?" from the board to filbert arrived with the trailer, the seat answered in its own session with no send attempt, and the row showed the answer on the next scan. #1505 is closed. Gate D (2026-09-12, Jason's run of the ledger for 2026-09-06 to 2026-09-12): **18.9 human messages per closed issue.** That is the number to move next week: every message Jason types to a seat is a nudge the rails did not absorb. Target for the week of 2026-09-13: under 10, by assignment through `mosaic seat task` and the board instead of the terminal, then the orchestrator seat. Companion numbers from the same run, for context only: 8 issues closed, median 2.7 hours open, 1.9 follow-up commits per issue. Next action: piece 4, the WebUI on Dewey's Console design (MOSAIC-STACK-D-002). Brief on the plan page, section "Piece 4: WebUI first screen (Console)". Owner: dewey, issue #1507 opened HTTP 201 on 2026-09-13 UTC. Implementation in `packages/webui`; Darkwing confirmed no source overlap and released tracking at fab40f25. Filbert is the independent reviewer. Board files stay unchanged; any needed board edit requires exact ownership coordination first. Published to refactor at ea00ec66d93d1d554463f94711c343c9c8df20c4, exact remote verified. Filbert APPROVED WEBUI-1507-R1, manifest 509f20e5; all 21 hashes reverified. Committed-tree regressions 208/208 include six WebUI tests, Chromium at 320..2560px and 330 passing rendered contrast samples. Receipt: `reviews/2026-09-13_webui-publication.md`. Jason's 2026-09-13 feedback supersedes readiness for the workday test: Gate E is blocked on refinement. He needs project/session navigation in the left sidebar and independent two-way chat interfaces, not dashboard cards and an inspector send box. He reports the return flow is missing in actual use; this needs reproduction. The current inspector's latest assistant text is not a conversation history. Restore relative activity age too; board `ageSeconds` is time since last activity, not session lifetime. Durable feedback and screenshot descriptions: #1507 comment 26082. Refined brief and decomposition: `2026-09-13_webui-session-chat.md`, CHAT-00..08. Jason settled Q1-Q22: all seats, full chat/tools/attachments/native approvals, enforced controller transfer, durable drafts/queue, interrupt/force-stop and explicit recovery. Old accepted foundation requirements were recovered rather than re-invented. Jason confirmed shared understanding and authorized bounded CHAT-00 preparation on 2026-09-13. CHAT-00 charter is #1507 comment 26094; research deliverable `chat-00/README.md` is independently APPROVED by Filbert in comment 26100. Four exact research files published at 370823b3, remote identity verified; 48 synthetic/source checks also pass from the committed research copy. Jason approved CHAT-01 contract drafting; active bounded charter is comment 26103. R1 request 26105 received REQUEST CHANGES in 26106/26107/26108. All R2 verdicts were collected before R3 edits. Filbert 26119, Dewey 26120 and Rocko via agent-send requested changes and accepted the named companion gates. R3 fixes cursor binding, disconnected-browser scheduler authority and visible dispatch refusal, NEW message roles, corrupt-queue recovery without control deadlock, and non-destructive revocation reconciliation. It also tests current retry dispositions, superseded stops, native resolution evidence, stop-context confirmations and second-actor draft privacy. R3 exact review 26124 is APPROVED AS BOUNDED DRAFT by Filbert 26126, Dewey 26127 and Rocko via agent-send, recorded with follow-ups in 26128. Only the four reviewed files published at 28d4e98ad8b406ca84b30170558bee22402f1e55; remote ref verified, committed copy byte-identical to reviewed snapshot and checks green: 98 shapes, 322 omissions, 76 reference cases, 17 lifecycle sequences plus regressions; CHAT-00 48/48. Receipt 26131 read back. Shared dirty planning/logs and other owners' files were excluded from the commit. CHAT-01 bounded delivery is complete, not runtime/security/all-seat acceptance. Jason approved CHAT-01C proposal 26131 with performing-agent attribution. Darkwing authored the four `chat-01c/` contract/model files and froze R1 for review in 26137, posted and read back as actual Gitea darkwing, account 104. Seat credentials at the operator-specified location work; no minting needed. Never use the legacy helper's default Jason identity. Future Git commits use explicit performing-agent author/committer and seat-authenticated publication, without changing shared config or rewriting published history. R1 findings were corrected and both Filbert and Dewey APPROVED exact R2 through agent-send; attributed receipts persisted as darkwing in 26152. Candidate request 26149, clean copy /tmp/chat-01c-r2-frozen-lujze3oe. Eleven closed examples/187 omission-extra cases and models/base regressions pass. Locally committed b023841c8a44d08677dc388043997eb4277b0545 with verified author AND committer Darkwing ; only four reviewed files. Committed-copy checks pass. Published: Dewey confirmed on 2026-09-26 that b023841c is on origin/refactor (`git branch -r --contains`). The HTTP 403 blocker (26154) is resolved. From 2026-09-26, pushes go through Sage with the jarvis identity, and each push needs Jason's word. CHAT-02..08 are not chartered. They are held until Jason rules, through Sage, on what "all seats" means with the fleet retiring, on row 5's priority against row 6 and #1508, and on charters and backend authors. Only small Console fixes are approved now (return-flow regression, relative Age; Filbert reviews). No runtime work or other queue item has started. CHAT-03I/03D, B1-B6/Q22 and #1507 acceptance remain open. Carry Rocko R3-1 native dispatched-input reconciliation into CHAT-02, R3-2 into CHAT-01C and R3-3 observer-revocation coverage into a later fixture revision, per 26128. No peer reviews remain pending for CHAT-01. No other queue/runtime/live start. Rocko architecture findings are incorporated with accepted evidence corrections. Actual Claude protocol compatibility, tool isolation, access and cutover remain unverified; no runtime implementation or live cutover yet. Q20 cancels ordinary-Interrupt follow-ups into drafts; Q21 authorizes reviewed/green scoped refactor publication; Q22 preserves piece-5/#1508/fleet ordering. Dependent fleet work remains held. Darkwing/Filbert planning corrections are incorporated, including explicit remote implementation and publication gates. Live one-seat cutover requires separate Jason approval after both harness fixtures and exact rollback plan. Keep #1507 open; original tests are not new-scope approval. No code or live effects started. Darkwing closed #1506 (Gate D written, comment 26067) and #1504 (registration shipped, Gate B passed, comment 26069) on 2026-09-13 UTC. Darkwing holds for piece 5 (darkwing on point; brief on the plan page, section "Piece 5") until Jason sends the start message, planned Sunday 2026-09-13. #1503 stays open until Jason rules on "who is waiting on me". `packages/ledger` is implemented: read-only local refactor subjects, one Gitea issue request, repo seats' user messages, two tables and JSON. Ledger fixtures 20/20; ledger, board, seat and registry suites 202/202, also checked in a clean candidate copy. Filbert independently APPROVED all six pinned source/test/doc files in `reviews/2026-09-12_ledger-verdict.md`. The helper's no-body GET cleanup exit defect is fixed and regression-tested. Counting rules, one-page refusal and unknown metadata limits are in the package README. Published to refactor at cd0aa5fb; Gate D accepted and #1506 closed. The brief remains in the plan page under "Piece 3: ledger (numbers for the rails)". After Gate D, the WebUI on Dewey's Console design absorbs the board as its first screen. Close #1503 when Jason says the page answers "who is waiting on me" without him opening a terminal. Out of scope until he asks: auth or provider registry, roster schema changes, hooks/plugins, comms, memory, multiple sessions per seat, stopping seats, new root files. The registry line (increment 3, headless identity-env leak) stays parked; #1500 is closed. ## Completed checkpoint: #1500 increment 2 (historical) Registry plan review is complete. All ten gates carry owner rulings (2026-09-10, ms-grill-me + Q15); gate 7 closed via PI-REFRESH-ROCKO-1 investigation and GATE7-FINAL-FILBERT-1 APPROVED. Published: 224147ec, b8008eda, d5307d2b, 86e009dde52bd588b4ade344bc292d5518843e1d (remote verified). #1500 prerequisite correction complete: independently APPROVED af97b5be, source 6335342873985538da3e7dc80cf9e9505e758832 pushed and remote verified. Committed-tree package/launcher fixtures passed 48/48; source and test limits: `docs/plans/reviews/2026-09-10_m20-correction-completion.md`. Jason subsequently APPROVED the fixture-only materialization/refresh increment. Fixture-only resolution, generation and fake refresh are implemented locally. Filbert APPROVED the complete increment at manifest11255dd4 in `docs/plans/reviews/2026-09-10_m20-refresh-final-verdict.md`. Darkwing verified all21 reviewed bytes match the live tree and independently reran74/74 tests in a clean baseline-plus-reviewed-overlay copy. Jason approved the increment-specific task/release applicability disposition. Source published at3daee5ad89dc6a006ca554ad7fda2b23eb96bb03; exact remote verified. Clean committed-tree checks: package/launcher74, config24, auth15, foundation43, conductor17 all pass. Task/release not run or claimed passing. Next action: present the two-test fixture demonstration for Jason's acceptance; keep #1500 open pending that response. Demo attempt 2026-09-11 failed only because Jason's terminal was a pre-cutover shell whose cwd followed the retired v1 copy (`git rev-parse HEAD` 5d277000, later pulled to next 2101c9b4); the canonical checkout at 5abbabb7 reruns the demo 2/2 (jarvis, 2026-09-12). Rerun after `cd /mnt/storage/src/mosaic-stack` in a fresh shell. Publication and demo receipt: `docs/plans/reviews/2026-09-10_m20-increment2-publication.md`. Headless identity-env fix is separate intake in the owner disposition record. No production refresh, live-suite effects or increment3 authority inferred. Charter: `docs/plans/2026-09-10_m20-increment2-charter.md`. No live refresh, real credentials, service installation or deployment authorized. Increment 1 and pi 0.85.1 were published through b3fa2210; passing original tests is not evidence that these newly identified prerequisites are satisfied. Owner goal #1498 completed: independently approved skill/launcher repair published at f3dce3208877626043c521c6ef5076f9559309b0; fresh remote identity verified and committed-tree offline fixtures 5/5 passed. Completion evidence: `docs/plans/reviews/2026-09-08_skill-launcher-completion.md`. No live restart, timer arming or deployment. Other new skills and private/WUI artifacts remain untouched. This closes the bounded goal, not a new registry mandate. Jason accepted the bounded #1497 publication/recovery trial following the plain- language brief and said "Proceed." Issue #1497 is closed; acceptance receipt: `docs/plans/reviews/2026-09-08_publication-trial-owner-acceptance.md`. Source publication 29c1defe and reviewed closeout 10448e41 remain the evidence pins. No WUI design acceptance, production readiness or held-queue expansion is inferred. ## Completed trial checkpoint, before owner acceptance The following preserves the publication-stage state; the acceptance above supersedes its pending-acceptance and registry-deferral statements. Execute Jason's approved publication and planned-restart recovery trial (#1497). Plan: `docs/plans/2026-09-08_publication-recovery-trial.md`. Publish remaining reviewed changes, temporarily including agent definitions and labeled drafts; exclude private runtime/session/auth state. Jason performed Rocko's planned restart and issued neutral continue; PUB-REC-ROCKO-1 returned its reserved test PASS. Filbert independently SUPPORTS bounded checkpoint recovery and APPROVES the pinned privacy-safe summary (0e17757c); raw records stay local. No reliability or overall trial acceptance inferred. WUI exact 53-file draft publication is independently APPROVED with pending-acceptance label; source/default revisions remain unimplemented. PUB-REC-FILBERT-LAUNCHER-1 APPROVED 23 source/publication candidates at frozen manifest 8900faf1. Jason then changed Rocko's launcher to Sonnet. PUB-REC-FILBERT-SONNET-2 APPROVED the six revised candidates at c5ad6306; coordinator verified all seven R2 snapshot/live files unchanged. Remaining original candidate approvals stand. Independent combined fixtures passed 5/5. Preserve R1 REQUEST CHANGES and the historical Fable recovery evidence unchanged. Publication completed at 29c1defe29e5793022e1d3820b265bfc0f7f628a on refactor; 92 exact approved units committed, committed-tree fixtures 5/5 passed, push succeeded and fresh origin/refactor identity matched. Final aggregation APPROVED at 3f8e765b. Next action: present the bounded publication/recovery trial to Jason for acceptance. Do not close #1497 or resume the registry queue before that acceptance. Newer executive-update skill edits, local ms-agent-watch deletion and additional untracked skills are outside the pinned trial candidate. Preserve them uncommitted; exclude both executive-update files rather than publish unreviewed or stale bytes. Verify the prospective publication tree separately; live native launch would refuse because its required ms-agent-watch file is now locally absent. No live launch or unrelated skill migration is part of this trial. No further restart or re-briefing requested. C1 remains HELD. Registry review alignment is deferred behind this newly prioritized owner trial. No registry implementation, agent relocation, main/next merge or deployment authorized. Completed commit/push wave: R5 transport-only tmux correction independently APPROVED by Filbert, published on refactor at `69f10a40623bf1809e7cda1f800bce3a5d80fb51` with all 17 milestone tags; remote identities verified. Exit 0 means transport dispatched, application acceptance unknown. Earlier rejected confirmation candidates remain historical evidence. Jason's A9 acceptance and suite results are recorded in `docs/plans/reviews/2026-09-07_a9-owner-acceptance.md`. #53 published planning inclusion is verified in `docs/plans/reviews/2026-09-07_issue53-closeout.md`; Jason retains issue closure. No main/next merge, deployment, or adoption of newer relocation work occurred. Correction (2026-09-07): the following conversion/A9 text is a historical pre-wave checkpoint, not a competing pending acceptance or test-deferral gate. Use the canonical checkout `/mnt/storage/src/mosaic-stack`, branch `refactor`, origin `mosaicstack/stack`. New foundation is at root; `v1/` is the legacy archive. The old `~/src/mosaic-stack-dev-test` path is only a compatibility symlink. Jason's requested local conversion (#1495) is completed at commit `127a54fdff1fe6ae56c3197edddf957481465db4`, preserving both parent histories and all pending work. Conversion record: `docs/plans/2026-09-07_repository-consolidation-completed.md`. Pre/post-commit tests and source identity checks passed; no push or live change. The index is clean. Existing uncommitted work was preserved, not blanket staged. Owner confirmation that no work was active superseded the earlier index hold for this conversion; no new writer assignment or permission grant is inferred. Inspector: FI-FILBERT-8 APPROVED at r6 manifest `a4a4493000aff5905337a643886ca36e7c5377d52deed77b8aeab7174ca73dcf`. All 382 file identities and pins remain unchanged. Demo guide: `docs/plans/reviews/2026-09-07_foundation-inspector-demo.md` (its old checkout path still resolves through the compatibility link; prefer the canonical path above). Four examples reran successfully after conversion. A9 remains owner acceptance, not an automatic consequence of tests or migration. Task/release coverage remains NOT RUN/DEFERRED, not deployment green. Native-parser/equality qualifications remain. Historical instructions below describe earlier checkpoints, not competing current assignments or authority over the archived v1 implementation. ## Earlier owner and source checkpoints Historical context below; the current candidate and live goal checkpoint supersede the earlier partial-draft descriptions. The prior hands-on checkpoint demonstrated launch, workspace listing, and conversation resume from Jason's supplied output. Fresh context and mission recovery were not tested. The owner redirected to this planning exercise; no broad foundation acceptance is inferred. Owner ruling recorded 2026-09-06 as R16-R17: current approved SOUL on launch, stable per-execution inputs, and a shared launch/configuration hash reference for TUI/GUI/WUI mismatch notices recommending Fresh. D10 is partly resolved. Q20/Q21 now settle broad fingerprint categories and automatic non-blocking notices plus on-demand checks; exact field/dependency hashes and delivery mechanics remain D16. This does not advance the phase or authorize implementation. Interview round 1 recorded: Q1 permits linked project/workspace missions, Q2 permits bounded system registration/assignment authority, and Q3 limits visibility to shared project information and explicitly permitted workspaces. Q4 clarification A creates and announces the first conversation without an offer; later default launches resume, while missing/damaged established sessions cause an error. Round 2 Q5-Q9 confirms single-parent hierarchy, the Fresh recovery information set, delegated within-plan non-destructive decisions and routine reviewer acceptance, assignment-only default Abandon, and explicit authorization for prerequisite work. Delegated authorization need not prompt the user each time; user phase checkpoints remain. Round 3 Q10-Q14 permits unassigned discussion/inspection with recorded assignments for changes, requires an interactive active-session conflict notice and offer to connect, separates shared work records from transcript grants, chooses concise audit metadata with controlled evidence, and scopes membership revocation to affected executions. Round 4 Q15-Q19 requires explicit service conflict handling, one controlling interface with authorized observers, controlled Fresh replacement, delegated evidence-based recovery without blind replay, and affected-execution blocking on audit failure. Round 5 Q20-Q24 extends fingerprints to shared behavior-affecting configuration, requires automatic non-blocking notices plus on-demand checks, scopes personal context, retires closed workspaces without deletion, and requires explicit reviewed legacy adoption. Round 6 Q25/Q26 pauses affected work for reconciliation after approved plan changes and chooses standard scope roles with registration-specific narrowing. Jason subsequently confirmed shared understanding of intended behavior. Jason then authorized phase 2. A tool-free source-analysis run, r-20260906T024609Z-68ee7f, succeeded; pinned 0.84.4 documentation was extracted from the existing image without starting its extraction container. These are source/document findings, not runtime feature tests or independent approval. The first contract candidate is partial. Q27 A now settles command-audit granularity; dependent schema and enforcement drafting may continue within phase 2. Full schema/plan approval remains pending. ## Accepted phase-2 checkpoint (historical) - Goal: issue-53-phase2. Objective: an owner-reviewable contract for agents, projects, workspaces, sessions, permissions, and audit evidence. Completion owner: Jason. Author/workspace/session remain those recorded below. - State: satisfied. Jason explicitly accepted phase 2 after the plain-language explanation of the planning baseline and separate later gates. P2-7 is complete. REVIEW.md retains D1-D16 and the unproved implementation mechanisms. This is owner plan acceptance, not independent technical or security certification. - Acceptance: repair/check schemas and fixtures, complete the operation/recovery contract, resolve material behavior decisions, prepare a review package and one user-testable increment recommendation, then obtain owner acceptance. - Evidence: `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 command and 38 record shape cases, 16 path cases, 7 restricted-domain hash vectors, 155 runtime/control/artifact cases and 35 synthetic rule-model cases. Ten deliberately shape-valid forgeries still require trusted runtime rejection. These are not runtime security tests or independent acceptance. - Reboot fixture defects were repaired, not discarded. Eleven positive records now include their common envelope; negative mutations were preserved. Required calendar/UTF-8/control-character checks are explicit in the author checker. - Next gate: separate owner authorization for mapping, not more phase-2 approval. No mapping or implementation started. This session continues the file-based goal and has not configured an extension/timer for it. Separate #54 work subsequently added/tested a project-local goal extension, as recorded in the shared logs; that work and its state were left untouched. This session has not migrated issue-53-phase2 into that runtime. Elapsed time never grants approval. - No new worker dispatch, external reply obligation, or uncertain external action initiated by this phase-2 session is outstanding. No numeric work budget supplied; aggregate usage remains unavailable. - Authority remains phase-2 planning and read-only investigation. No runtime implementation, mapping, migration, commit, push, or issue closure. ## Prior recovery checkpoint, 2026-09-06 03:42 UTC Historical snapshot below; the live goal checkpoint above supersedes its pause and unfinished-fixture status. - Goal: issue-53-phase2. State: paused by owner steering. Writer: darkwing, pi session `01a06e48-0718-71f2-a889-c263c4800fb9`, explicit working directory `/home/jwoltje/src/mosaic-stack-dev-test`, project `mosaicstack/stack-v2`. This is the existing single-writer planning assignment, not a runtime claim. - HEAD remains `69d1bb3`. Preserved all uncommitted planning and unrelated skill work. No reset, cleanup, commit, push, or implementation occurred. - Five planning artifacts survived in `docs/plans/foundation-v1-candidate/`: command schema/fixtures, `check.py`, and record schema/fixtures. The three command-check file hashes match the pre-reboot checksums. - `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 shape fixtures and 5 deliberate shape-valid forgeries. This does not prove runtime security. - The unfinished record checker is NOT integrated into check.py. A read-only diagnostic found 13 expectation mismatches: all 11 positive record fixtures, plus unicode-byte-limit and bidi-control. The first positive lacks five common envelope fields, indicating fixture generation is incomplete. Do not count negative cases as meaningful until positive fixtures are repaired and rerun. - System config validates, Docker responds, and the pinned image ID and prior research result hash still match the phase-2 evidence. No Mosaic worker container was running at inspection. Pinned temporary docs remain available. - Next work after explicit resume: repair record fixtures, enforce/test UTF-8 byte and control-character path checks, integrate both schema suites, then complete the remaining phase-2 record/permission/lifecycle work and owner gate. - No outstanding assistant-initiated external action or reply is known. Wake is manual: Jason sends a resume instruction. No timer or automatic continuation is registered. Aggregate usage is unavailable; no numeric budget was supplied. ## Queue (ordered per docs/plans/ROADMAP.md) 1. Paused for owner alignment: review `docs/plans/2026-09-03_auth-provider-harness-registry.md` and reconcile later owner decisions and #53's workspace-session model. Gate 7 remains unresolved. No registry implementation is approved, and this work does not resume automatically after the planning exercise. 2. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation ## Rules - One action in flight. Update this file at the END of every action. - Blocked? Move the item to "Blocked" below with the reason and stop. - Completed actions move to the log at the bottom (date + issue + result). - Corrected entries are marked, never silently rewritten (see 2026-09-03 dedup note). ## Blocked (none) ## Completed log - 2026-09-12 — #1500 closed: owner accepted the fixture-only increment by rerunning the two-test demo on 5abbabb7 (2/2). Records-only closure; no source, suite or live effect. Next: re-plan against MOSAIC-STACK-D-001 before increment 3. - 2026-09-08 — Owner-corrected Sage setup: `agents/sage/` now owns the DYOR business/strategy persona, context, launcher, and working records. Native cwd is this checkout, private history is `.pi/state/sage/sessions/`, and the prior brain command forwards here. Six offline launcher tests and both real configuration checks pass; current registry alignment queue unchanged. - 2026-09-08 — Owner-requested development team: Rocko launches Claude Code with Fable; Filbert launches Pi with `openai-codex/gpt-6-astra:low`; Darkwing is the development team lead and Dewey remains frontend/UX owner. Five offline launcher tests and both new agents’ local configuration checks pass. No model session started; inspector acceptance queue unchanged. - 2026-09-08 — Owner-requested Dewey frontend/UX agent: `agents/dewey/launch.sh` uses the shared native launcher with its own persona, context and session history. Offline launcher checks pass for both agents and real Dewey `--check` passes; no model session started. Current inspector acceptance queue unchanged. - 2026-09-07 — Owner-directed concept annexation: [Mosaic concepts](../concepts/README.md) now owns the adapted pages; source/license metadata moved to docs/reference/concepts. Test-package links and content hashes updated; preparation checks pass. Documentation ownership changed, not runtime behavior or the demo queue. - 2026-09-07 — Owner-requested ACT-04 groundwork: [Darkwing concept test package](act-1-tests/README.md) prepared with twelve pinned OpenClaw references, synthetic cases, candidate SOUL and offline preparation utility. Import checks and existing isolated launcher tests passed; behavioral cases NOT_RUN and runtime features deferred. Current demo queue unchanged. - 2026-09-07 — Owner-requested shared planning capture: [ACT-1 — Agent context, templates, and staged migration](2026-09-07_agent-context-templates-and-migration.md) records single-agent SOUL authority, bootstrap templates, evaluation work, demo gates, and deferred structural migration. Runtime tasks remain unassigned; current demo queue unchanged. - 2026-09-07 — Owner-requested naming cleanup: native helper is now `scripts/agent-host-dev.sh`; callers and documentation updated, empty `scripts/tui/` removed, launcher checks passed. Historical log paths retain their original names. - 2026-09-07 — Owner-requested entry-point consolidation: `scripts/agent.sh --host-dev darkwing` delegates to the native helper; default container execution retained. Host and isolated container routing/refusal checks passed; inspector queue unchanged. - 2026-09-07 — Owner-requested launcher follow-up: Darkwing's launch.sh now delegates to `scripts/tui/launch.sh darkwing`; existing session/context regression checks pass. - 2026-09-07 — Separate owner-requested Darkwing launcher: `agents/darkwing/launch.sh` provides a native development TUI with explicit context, skills, coding tools and `/goal`; offline launcher tests and no-model TUI smoke passed. Inspector queue and approval gates unchanged; no commit/push. Note (2026-09-03): this log was deduplicated after editor-session races appended duplicate blocks. The dedup removed repeated lines only; every distinct action appears exactly once, in completion order. Ground truth: git history + Gitea issues. - 2026-09-03 — POC: containerized pi hello-world (poc-container-hello-v0) - 2026-09-03 — M1 configuration-driven hello world (#1–#4; config-hello-v1); hotfix #5 stdin detach - 2026-09-03 — M2 mission/task abstraction (#6–#9; mission-task-v1); hotfix #14 release identity in task path - 2026-09-03 — M3 release model + safe updates (#10–#13; release-model-v1); drills: update/refusal/rollback - 2026-09-03 — M14 live user context layer (user/ dispatched to all launches; 0.0.9 built) - 2026-09-03 — M15 agent seats: per-agent SOUL + role contracts (#36; agent-seats-v1); roles/ convention (root = bootstrap-only) - 2026-09-03 — M13 interactive TUI agent + TOOLS.md (#35; interactive-agent-v1); release 0.0.8 activated - 2026-09-03 — M12 conductor auto-apply policy (#34; auto-apply-v1); 17 conductor selftests - 2026-09-03 — M11 session forking (#33; session-fork-v1); child recalls ancestor, base untouched - 2026-09-03 — M10 run-record retention (#32; retention-v1); prune keep-N, dry-run default, receipt - 2026-09-03 — M9 mission capability policy (#30; mission-policy-v1); least-privilege intersection - 2026-09-03 — test UX: green OK/red FAIL status colors; NO_COLOR-aware - 2026-09-03 — M10-era hotfix: retry lineage (#28) + AGENTS.md/SESSIONS.md recovery shim - 2026-09-03 — release 0.0.10 packaged and health-gated activated (user context + agent seats live) - 2026-09-03 — release 0.0.11 shipped (onboarding + live user context); ROADMAP.md agreed (M16–M19); CI deferred by owner - 2026-09-03 — M16 release self-determination (#38; `release.sh ensure` at launch, drift warnings, recursion guard) — logged late: CURRENT.md had gone stale while M16/M17 shipped; ground truth = git history - 2026-09-03 — M17 skill lifecycle + ms-* skill set completion (#40–#42; skill-lifecycle-v1); release 0.0.12 packaged, health-gated active — logged late, same staleness correction - 2026-09-03 — conductor-loop calibration with live collaborator (#43): dispatch via agent-send.sh → receipt → line-by-line diff review → suite-gated integration; docs/TOOLS.md gains Tools (host-side) section + corrected suite counts - 2026-09-03 — skill revisions adjudicated (#44): ms-communications integrated as-authored; ms-conductor redraft + conductor remediation (refusal vs outage); TOOLS.md release.sh ensure row - 2026-09-03 — M18 seat-role progressive capability restriction (#45; roles resolve to contracts, ceiling ∩ seat grant, fail-closed refusals, roles/researcher.json); task suite 74 → 88 - 2026-09-03 — M18 follow-up: fail-closed seat resolution under MOSAIC_AGENTS_DIR override (#46, owner decision after live verification); task suite 88 → 90; next action M19 - 2026-09-03 — M19 harness auth tooling (#47; auth.sh status/accounts, agent.sh --auth per-launch injection via PI_AUTH_FILE, test-auth suite 13 cases with secret-never-printed assertions); agreed sequence M16–M19 complete, M20 owner-gated - 2026-09-03 — M19 correction: auth ownership moved to the data root (#48, owner direction — the stack never writes to default harness config locations; ROADMAP standing decision); auth.sh config-driven, accounts at /auth, 0600 enforced; test-auth 13 → 15 - 2026-09-03 — harness/provider/auth registry specification drafted (#49): agent.json harness declaration, central provider/account/settings registries, runtime seat selection, mechanical per-harness materialization, centralized OAuth refresh, Ollama endpoints, CLI contract; implementation blocked pending ten-gate review - 2026-09-13 — Discord connector pilot for the Sage seat (#1509; QUEUE rows 14–15; brief `2026-09-13_discord-connector-pilot.md`): nine review rounds with rev-code-02, live pilot steps 1–8 with private receipts, Gate H passed (Jason: the replies read as Sage). Commits 786e379c, 788515dc (pushed). MVP iteration 1, eyes reaction as a read receipt, committed 93d6b624 (local); live check pending. Connector stays up in tmux `discord-sage`; binding and token live outside the repo. - 2026-09-13 — Discord connector iteration 2 (#1509, QUEUE row 17): systemd user service `mosaic-discord@` with a supervised run that clears a dead lock and never retries a brake (exit 3). Sage seat now runs under systemd, not tmux. Next: control board row. - 2026-09-13 — Discord connector iterations 4 and 5 (#1509, QUEUE rows 19–20): `reload` verb and `systemctl --user reload` apply channels, users, limits and guildName to the running connector, fixed keys refused, attempts journaled in `reloads.jsonl`; per-user channel allowlist; Carmen enrolled live by a reload at 00:03 UTC (all listed rooms except #sage-admin). Suite 41/41, 101 node tests. Commit caaef941 plus records. Row 18 (board row) is darkwing's by Jason's ruling. - 2026-09-14 — Discord connector iteration 6 (#1509, QUEUE row 21): read-only tools through a Mosaic pi extension confined to declared roots (Jason's R1–R7: repo `docs/` and `agents/sage/`, every listed user including Carmen, 8 calls a message, 400 lines a read, 256 KiB a file, refusals said plainly, `tools` a fixed key). rev-code-02 approved round 2 (26276). Suite 41 → 48, node tests 101 → 116. Next: live check in #sage-admin, then attachments. - 2026-09-16 — Discord Sage ops (#1509), Jason's word: every text channel of Shared Signals added in mention mode (#sage-admin stays open, Carmen's one-channel allowlist unchanged), and `/mnt/storage/src/shared-signals` added as a third read-only root. Threads had been silent because their parent #ideas was unlisted, not a code defect. Private binding only; check passed, service restarted; receipt in the Sage evidence dir. New channels created later need adding by reload. - 2026-09-16 (coordinator, #1509 row 23): part 1 writes built: `write_file`/`edit_file` for roots marked `write: true`, temp file plus rename, same fences as reads plus parent-must-exist, no dot paths, no credential shapes; `enabledToolNames` drives `--tools`, the extension and the check line; suite 49/49. Pinned for rev-code-02 round 1 (tree in the #1509 comment). Live finding: after the prompt fix Sage still repeated "ruling Q16" and "two read-only folders" with zero tool calls, because pi resumed the session that held every earlier refusal; the old session file was archived to the sage evidence dir and the service restarted with a fresh session. Writes and web reach Sage only after row 23 lands in the binding. - 2026-09-16 (coordinator, #1509 row 23): part 2 web built: `src/web.mjs` with `webFetch` (https only, public addresses only, connection pinned to the vetted address, three re-vetted redirects, 1 MiB cap, html to text) and `webSearch` (SearXNG json, ten results); enabled only when the binding `tools.web` key is set. The full-suite hang was a race in `tests/engine.test.mjs` (busy asserted before `agent_settled`, fake pi never stopped); the test now waits for the settle and stops in `finally`. Suite 52/52, node 128. Round 2 pinned for rev-code-02 (comment 26358, aggregate 287af5da, tree 1721584c). Next: verdict, local commit of my 17 paths only, then SearXNG container on 127.0.0.1:8888 and the live check. - 2026-09-16 (coordinator, #1509 row 23): part 3 live: SearXNG container `mosaic-searxng` (image searxng/searxng:latest, settings in the data root, formats html and json, limiter off) on 127.0.0.1:8888; binding `tools.web` added (backup in the sage evidence dir); check ok; service restarted. Jason's first turn in #sage-admin searched, fetched who.is, listed the folder and wrote `vault/Businesses/naming.md`. Defect seen in the same exchange: his second message during the turn went to pi as a follow-up, pi folded it into the same run, the first answer was never posted and the second failed as settled-without-turn. Fixed in `engine-pi.mjs` (held prompts, one run each), fake pi now models real follow-up semantics, suite 52/52 node 129, round 3 pinned (comment 26361, aggregate e30c2319, tree dbd2ce9a), service restarted with the fix. Row 24 rulings: D5 seat identity with `sage@mosaicstack.dev`, D6 push every commit (Jason: not pushing means stale data), D7 rev-code-02. - 2026-09-18 (coordinator, #1509 rows 23–24): row 23 committed as 1685deb4 and pushed (`90cb31f5..1685deb4`) at Jason's word. Row 24 built: `src/git.mjs` (git_status, git_commit with explicit paths, seat author and `Requested-by:` trailer, push after every commit per D6, git_pull ff-only, git_push one branch; guard for branch, detached head, in-progress operations and conflicts; index must be empty so Jason's terminal work is never swept), `bin/git-credential.mjs` (the package's own helper: `get` over https from the 0600 token file, since `git-credential-mosaic` serves only the Gitea hosts and the global config routes github.com to Jason's `gh`), git children run with no host config; vault protocol (`protocol: "vault"`): per-write clone lock, `check` and `validate_vault.py` before a commit, `reserve_id`; the connector writes `requester=""` into the envelope and the extension reads it on `before_agent_start`. Suite 58/58, node 143. Review requested from rev-code-02; binding change and live check follow the verdict. - 2026-09-20 (coordinator, #1509 row 25): part 2b built against shared-signals a5425a2. Eight fixed verbs for the model (record_list, record_get, record_create, record_update, resolve_id, open_approval_request, get_approval_request, create_document), the connector's own client for bind and add_approval, the envelope's author and message ids read by the extension for per-turn write keys. Button evidence per the SetSpark coordinator: the connector posts a confirmation line and submits its url and text; a reply is its own evidence. Sage's key is minted (id sage-3ff47150, file outside the repo, never read here). Suite 63/63, node 162. Review candidate frozen for rev-code-02 (aggregate 09140edc, tree 7872d8c5); Gitea answered 503 when the request was posted, so the post is queued and retried. Slip: a stray `git stash` during doc checks stashed the tree for under a minute; popped at once and verified, 44 files back, tests green. - 2026-09-26 (sage, lead): Jason's ruling: Sage leads the project, Darkwing is a collaborating seat, more seats to follow, development stays in T3 for now. The fleet Sage seat that took Invoice Ninja coordination outside Jason's instructions is being decommissioned; moving work onto the new stack is the fix. Suites all green. Rows 24 and 25 pushed (1685deb4..43d7574d). Open: about 11 days of uncommitted agent work in the tree (row 16 launch files, row 22, #1512, WUI evidence), 23 untracked aws-* skill directories in skills/ from 2026-09-21, and Jason's target for the next phase.