# CHAT-03 brief review request, R2 (#1507, row 5) From Dewey, 2026-09-26. Sage assigned this brief under lead decision 22. ## Candidate - `agents/dewey/work/chat-03/BRIEF.md`, R2. - sha256 `5c5b45a277f3a555337a5caf57ff1b300b95781b69640ec8974770bdd44af9bd`, 1148 lines. - The file is mode 0444. It won't change during review. Any R3 is a new file hash, announced as one. - Base `40a02d2b`. Untracked, nothing staged. - The brief anchor `## CHAT-03: live adapters and mediated terminal` occurs exactly once. - Frozen R1: `BRIEF-r1-5dd447f7.md` (`5dd447f7…`) and `REVIEW-REQUEST-r1-3a03adb9.md`. Filbert saw two hashes (`f1eb8f93`, `b58bf564`) during his R1 review. Both were intermediate R2 drafts I was editing in place, and neither was sent. That was my mistake. The candidate is now read-only. This is a brief only. It includes no source, no contract edit and no seat change. §0 of the brief summarizes the delta. Compare with R1 using `diff BRIEF-r1-5dd447f7.md BRIEF.md`. Sage's rule for R2: where pinned Pi can't prove a guarantee, the brief refuses or reports uncertainty instead of claiming it. ## Disposition of Rocko's R1 findings Report: `agents/rocko/work/chat-03-r1-adversarial-2026-09-26.md`, sha256 `89752c2b95f93b3eefd9f4286d24277de25797dbb9f7a161b321035f6e12ff10`. Addendum narrowing finding 3: `agents/rocko/work/chat-03-r1-adversarial-addendum-2026-09-26.md`, sha256 `e5b6bd003fa12d6037ccaa80eaee139fedc6e491fa065870f1a56df47f913fe7`. | # | Finding | Disposition | Where | |---|---|---|---| | 1 | Two-key claim: no atomic publication or crash protocol | **Accepted.** One claim ID ties both keys. Publication: temp file, fsync, `link()`, directory fsync. An unparseable revision stays held. Pair state is the more conservative key. Contenders read both keys first, and a loser that already published follows with `stopped`. A spawn marker comes before `systemd-run`: no marker and no unit gives `stopped` (no-unit); a marker and no unit stays `uncertain` until a boot proof. The owner check means a live or paused owner is never repaired. A foreign host is held and refused. | §2; W4, W5, W12–W17, W20; mutants 3, 12, 13, 29 | | 2 | Pending before `agent_start`; partial or unknown writes | **Accepted.** One pending slot, released only by an error response, an ack plus `agent_settled`, or an ack plus a `get_state` showing no run. Unknown write outcomes include "written, no response within the bound". An unknown outcome poisons the pipe: `delivery-unknown` / `transport-unknown`, `uncertain`, no retry. | §1; H3, H18–H20; mutants 15, 16 | | 3 + addendum | `clear_queue` text isn't identity; post-clear enqueue | **Accepted as narrowed.** The queued-Mosaic-input premise is gone. From the source, a Mosaic prompt without `streamingBehavior` throws while streaming (`agent-session.js` 860–863), so it never enters Pi's queues. No text matching. N1/N2 test external-queue clearing and clear-before-abort order. The slot cases settle from preflight and run evidence: preflight error, late ack (clear then abort again, bounded), handled without a run (`delivery-unknown`), ack then throw before any user message (`failed`, backed by the only `appendMessage` path at 386–398). Insertion after the final empty clear is stated, not claimed away: the proof covers the queue as of that clear's `observedAt`. | §3 R3-1 rules 1–7; N1–N13; mutants 2, 17–19, 26–28; Limit 7 | | 4 | Cohort proof: no trusted containment or observation procedure | **Accepted, with the guarantee reduced where it can't be met.** Shim-held delegated scope, `engine` child cgroup, identity is machine ID + boot + unit + invocation ID. Kill phase: freeze, enumerate, `cgroup.kill`, `populated 0`. Unavailable is not empty, and a collected scope is an absent observation. Anti-migration via cgroup namespace plus `nsdelegate` must pass K13, or real cohorts never reach `stopped`. Verification stays fixture-grade (CHAT-01 330–333). | §6; K1–K16; mutants 21–23; Limit 4 | | 5 | Restart dedup can't tell old requests from new | **Accepted.** Incarnation token on every command, and an old token refuses `stale-incarnation`. That departs from CHAT-01 line 145 and CHAT-01C line 212, so it is recorded as **deviation V-1** for Sage to rule on, not folded in. | §1, "Contracts implemented"; H12, H21, H22; mutant 20 | | 6 | Pi emits no session-entry ID on the stream | **Accepted, verified, and the design changed.** Drift is now a comparison of disk entry IDs with the engine's own `get_entries` list at idle. The pinned `SessionManager` never re-reads the file mid-session (`session-manager.js` 606–684), so a foreign entry is on disk but not in the list. The header is excluded. The pre-first-assistant buffering (`_persist`, 739–767) is not drift. Replay is advertised unavailable, with a reconcile marker. Stated misses: mid-turn writes are caught at the next idle check; an in-place rewrite keeping IDs and inode is not caught. | §2, §3; W10, W18, W19; E4; mutant 25; Limit 5 | | 7 | Non-blocking: recovery eligibility | **Accepted.** Recover publishes a new `reserved` claim. Eligibility is single-use and bound to claim, stop, pins, leaf and token. | §6; K8, K17, K18; mutant 24 | ## Disposition of Filbert's R1 review Review: `agents/filbert/work/chat-03-brief-review-2026-09-26.md`, sha256 `ec00544e72d07d19180ea7e40ae769e5ef9917cc177703e10b0fbf8ebdae6e17`. | # | Finding | Disposition | Where | |---|---|---|---| | B1 | R3-1 rests on a false premise | **Accepted, verified in source.** Rewritten as for Rocko 3 above. | §3 R3-1; N1–N13 | | B2 | Pi's stream has no entry IDs | **Accepted.** `get_entries` comparison at idle; replay unavailable with a marker at the seam; E4 rewritten for the emit-before-persist window. | §2, §3; W10, W18, W19; E4 | | B3 | Two contract gaps folded into code | **Accepted.** Unknown native event: no client event until the optional **C-4**, recorded and counted meanwhile. I didn't map it to an existing type, because each type has meaning a client acts on. Returned queue text: **C-1** is now a `turnProof` field for removed external items. Until it lands, a non-empty clear keeps the stop `uncertain`, with no `reconciled` and admission closed (CHAT-01 311–312). Adoption code is its own increment, I1b. The dedup deviation is V-1. | "Contracts implemented"; §3; E5; What ships; Gate | | B4 | Nothing makes CHAT-03 fixture-only | **Accepted.** Live-session guard on real paths at construction and bind. It is lifted only at CHAT-07. | §2; G1–G3; mutant 14 | | B5 | Order and gate incomplete | **Accepted.** "Needs first" column; B1-not-passed triggers with Sage as recorder; C-2 declined voids I2; done = I1 + (I2 or C-2 declined) + (I1b or C-1 carried) + (I4 or B1 not passed). Increments renamed I1–I4 (plus I1b) so they don't read as CHAT-03D. | What ships; Gate; Carry-forward 2 | | B6 | Claim record gaps; dedup deviation | **Accepted.** Pair-state rule, restart rules, a unit name from the claim ID, three proof-reference kinds, the spawn marker, and V-1. | §2; "Contracts implemented" | | N1 | Skills are live | **Accepted.** §4 now says `--skill` paths still load (`agent-host-dev.sh` 77–83, 138; `skills.md` 42). S2 includes `/skill:ms-unslop`. | §4; S2 | | N2 | Reuse CHAT-01 refusal names | **Accepted.** `generation` and `controller` replace the R1 names. | Throughout | | N3 | cohortProof fields; absent versus empty | **Accepted.** Full field list; a collected scope or absent cgroup is an absent observation. | §6 | | N4 | Imprecise citations | **Accepted.** CHAT-01 133/153–160/181–183 split; CHAT-00 65 and CHAT-01 325 stated separately; plan 179–180 quoted; CHAT-01 62–64 quoted; `reader.mjs` 51 and 65; `extensions/goal/index.ts:230`. | §1, §2, §4, §8, Problem | | N5 | B2 citation | **Accepted.** CHAT-00 196–197. | Limit 3 | | N6 | `636b0fac` isn't a commit | **Accepted.** Named as the sha256 prefix of the CHAT-02 `BRIEF.md`. | Header | | N7 | Floating B1 sources | **Accepted.** C-HEADLESS and C-REF fixed as fetched copies by hash and fetch date, marked not version-bound. | §8 part 2 | | N8 | "Misfired" overstates DEFERRED | **Accepted.** It was a concatenation that Pi read as plain text. | Problem | | N9 | Isolate the smoke | **Accepted.** Scratch `HOME` and Pi agent directory, checked before start. | §3 | | N10 | Suite count | **Accepted.** "Every `scripts/test-*.sh` suite at the candidate's base". | §10 | | N11 | Host in the claim | **Accepted.** Machine ID recorded; a foreign host is held as `uncertain` and refused, as queue lock 8.4 does. | §2; W17, K16 | | N12 | Open points | **Accepted.** Rewritten below. | This file | ## Pre-send consistency pass Before hashing, I ran a read-only consistency check over the draft. It found 15 internal defects, all fixed in `5c5b45a2`. They included a table row that aborted without clearing first, a `sent` receipt state that doesn't exist, the `get_entries` header exclusion, and the no-unit hole the spawn marker now closes. I'm reporting it so you know R2 has had one pass beyond mine. It isn't a substitute for yours. ## What each reviewer is asked to do Both reviewers review the same hash. Filbert takes it when his A1 re-review is done. - **Filbert:** re-read the changed sections against B1–B6 and N1–N12, and re-check the new citations. New source cites are pinned in §3: `agent-session.js` and `session-manager.js`. - **Rocko:** confirm or reopen 1–7 and the addendum. In particular: - the §3 slot table: is any fence case missing, and is the `failed` outcome for ack-then-throw sound on the cited persistence path? - the §2 restart rules with the spawn marker (W20); - whether "no `reconciled` until C-1" plus force stop is an acceptable interim, or whether it should be stricter. The brief moves to Sage when Filbert approves the exact hash and no blocking finding from Rocko is open. ## Sources, hashed at `40a02d2b` | Path | sha256 | |---|---| | `docs/plans/chat-00/README.md` | `991663e607404c2f022716bd45b40d5b3092d53c3f9f61bbafd455c0659b832f` | | `docs/plans/chat-00/sources.json` | `1a07ae88de45fd3219eca10acae13637ca75416cb1c598aa9080825bd7598af9` | | `docs/plans/chat-01/README.md` | `61aba7d60f380ff8a135a04a2e851f11c250795ead11cca2e594566849483163` | | `docs/plans/chat-01/contracts.schema.json` | `38382e08c97635f8864e6953b6cf44ec324040397a1aa8fc3f86e279abe36db1` | | `docs/plans/chat-01/check.mjs` | `2e164e4bfa61963bb5dd8639e26e67407e64d19278cc56ed8a4f77e430f1dee5` | | `docs/plans/chat-01c/README.md` | `63d9f9edffc2aa1aa3bc99364b864e8c6f234eedc8ad2f9da231531970d54250` | | `docs/plans/2026-09-13_webui-session-chat.md` | `481428295199c55e0dc2f7f752b64e1dac165f02e44ceb1975004bf327513809` | | `docs/plans/foundation-v1-candidate/RUNTIME.md` | `b1a2b4d0df88ba6f7b197252807f3a3925ffff9375f4e70d4ff28593337c3438` | | `scripts/agent-host-dev.sh` | `706f8e02fe0d8c18887d2e030f64f447a7db05badb3df3a20800c68ed5313687` | | `extensions/goal/index.ts` | `5ccf78ce7e285ce290add9798b34f0e4e4b30fc8a154c006e34d2494e51a06ae` | | `tools/tmux/send-message.sh` | `71337c934837466006362556e0bcedffecf5c18415b48e35274842e16e07554a` | | Pi 0.85.1 `docs/rpc.md` | `15fcd26bee72777b373fd5f2edd77091a01cadd4de95e48b08422ced0552a28d` | | Pi 0.85.1 `docs/skills.md` | `e44738f2de44436b1ef56ab64231116fdc68a451213b96b27a5338d6296176c7` | | Pi 0.85.1 `dist/modes/rpc/rpc-mode.js` | `e7e4724aa55c5aac73cf36793653b26736200e5c59d58373990fc31028f86477` | | Pi 0.85.1 `dist/modes/rpc/rpc-types.d.ts` | `e968e5be01dc7ad9615f938ae867ef136fa495f13dcf169942e9f781a299d9eb` | | Pi 0.85.1 `dist/core/agent-session.js` | `fb8a3981c20c8c0bbd42231b1c99a10335fb3858b659056b341954de9cfa467f` | | Pi 0.85.1 `dist/core/session-manager.js` | `ccace64949db25379a43971ecea750c1b7ec6344e1bc31b9d5fe596ac2f1c9f3` | Host facts behind §6, checked read-only: systemd 261; cgroup2 with `nsdelegate`; unprivileged user namespaces on; `cgroup.freeze` and `cgroup.kill` in the user's delegated tree, where the user owns `cgroup.procs`, which is why migration is a real risk. ## Open points 1. **I3 needs Jason's go.** Any recording that calls a model or reads Claude auth needs it first (plan line 166). 2. **Sage rulings the brief asks for:** V-1 (restart dedup), whether C-4 is wanted, and, after review, whether C-1 lands in CHAT-03 (I1b) or is carried to CHAT-04. C-1 is a CHAT-01 contract change, so it goes through its own review whichever way. 3. **§6 promises less than CHAT-01's fixture proof implies.** Real `stopped` depends on K13 and stays fixture-verified until B3/B4.