Files
stack/packages/mosaic
mosaic-coder 009e78a190
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
fix(wake): #932 stop reconciler re-enumerating already-CONSUMED detector state
Wake-pilot finding #7 (safe-but-noisy G2a alarm-hygiene): after
consume-truncation a consumed detector-observed state matched NO accounting
record — the inbox was truncated, the reconciler's seen-ledger only covers its
OWN enumerations, and the detector hash-file is correctly DISTRUSTED — so the
reconciler treated it as UNACCOUNTED and re-enumerated it: one DUPLICATE
orientation wake + one SPURIOUS rc=1 CRITICAL per detector-active window per
cycle (functionally safe, no lost obligation, but cry-wolf erosion at fleet
scale).

Fix (Mos ruling, built exactly):
1. store.sh records the last-consumed observed_hash per (kind,id) at
   consume-truncation into a NEW store-owned durable record
   consumed-hashes.jsonl (atomic write; ADDITIVE — existing on-disk format
   unchanged/read-compatible; #908 allocator untouched).
2. reconcile.sh adds a THIRD accounting source alongside the inbox and its
   seen-ledger: a detector-observed state whose observed_hash MATCHES the
   store's recorded last-consumed hash for that (kind,id) is ACCOUNTED — not
   re-enumerated (no dup wake, no spurious CRITICAL).
3. Trust boundary (load-bearing): the 3rd check consults ONLY the
   store-written record. Its existence implies the state was durably
   enqueued+consumed, so it structurally cannot exhibit the §5
   hash-advance-without-enqueue swallow signature. Trusting DETECTOR
   hash-files STAYS REJECTED.
4. G3 not weakened: only states the store RECORDED as consumed are
   suppressed. A genuinely-unaccounted state (enqueued-but-unconsumed, still
   in the inbox, OR a real gap) still re-enumerates + alarms.

Red-first tests:
- store-ack T12: consume writes the store-owned last-consumed record
  (per-(kind,id), monotonic last-seq wins, lazily created).
- reconcile R10: a consumed state is ACCOUNTED (rc=0, UNACCOUNTED=0, no
  re-enumeration).
- reconcile R11: pilot repro — consumed state SUPPRESSED while a distinct
  unconsumed/gap state STILL re-enumerates (G3 teeth intact; no
  over-suppression).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0158NZqN2n2ymKFeJAZ4GUCb
2026-07-26 10:34:39 -05:00
..

@mosaicstack/mosaic

CLI package for the Mosaic self-hosted AI agent platform.

Usage

mosaic wizard           # First-run setup wizard
mosaic gateway install  # Install the gateway daemon
mosaic config show      # View current configuration
mosaic config hooks list  # Manage Claude hooks

Headless / CI Installation

Set MOSAIC_ASSUME_YES=1 (or ensure stdin is not a TTY) to skip all interactive prompts. The following environment variables control the install:

Gateway configuration (mosaic gateway install)

Variable Default Required
MOSAIC_STORAGE_TIER local No
MOSAIC_GATEWAY_PORT 14242 No
MOSAIC_DATABASE_URL (none) Yes if tier=team
MOSAIC_VALKEY_URL (none) Yes if tier=team
MOSAIC_ANTHROPIC_API_KEY (none) No
MOSAIC_CORS_ORIGIN http://localhost:3000 No

Admin user bootstrap

Variable Default Required
MOSAIC_ADMIN_NAME (none) Yes (headless)
MOSAIC_ADMIN_EMAIL (none) Yes (headless)
MOSAIC_ADMIN_PASSWORD (none) Yes (headless)

MOSAIC_ADMIN_PASSWORD must be at least 8 characters. In headless mode a missing or too-short password causes a non-zero exit.

Example: Docker / CI install

export MOSAIC_ASSUME_YES=1
export MOSAIC_ADMIN_NAME="Admin"
export MOSAIC_ADMIN_EMAIL="admin@example.com"
export MOSAIC_ADMIN_PASSWORD="securepass123"

mosaic gateway install

Runtime launchers

mosaic claude            # Launch Claude Code with Mosaic injection
mosaic yolo claude       # …with --dangerously-skip-permissions
mosaic codex | opencode | pi

mosaic claudex (EXPERIMENTAL)

Runs GPT models inside the Claude Code harness by pointing Claude Code at a local claude-code-proxy that translates the Anthropic Messages API to a ChatGPT-subscription (Codex OAuth) backend. This is not Anthropic Claude — model behavior, tool use, and output quality may differ. Intended for evaluation, not production delivery.

mosaic claudex           # launch (prompts through the proxy readiness gate)
mosaic yolo claudex      # …with --dangerously-skip-permissions
mosaic claudex --print "hello"   # trailing args are forwarded to Claude Code

Prerequisite: the claude-code-proxy binary must be installed and authenticated (claude-code-proxy codex auth …). mosaic claudex runs a preflight that verifies the binary, the OAuth state (triggering a device re-auth if needed), and a trusted local listener before launching; it fails closed if the proxy cannot be brought up with a verified identity.

Isolation (never touches your real Claude state). claudex always launches against an isolated CLAUDE_CONFIG_DIR (default ~/.config/mosaic/claudex/home). The ambient CLAUDE_CONFIG_DIR is deliberately ignored, and a guard proves the resolved dir can never be — or live under — the real ~/.claude. A claudex session therefore cannot mutate your normal Claude Code config.

No token leakage. claudex never reads the proxy's credential file. Claude Code is handed only ANTHROPIC_AUTH_TOKEN=unused pointed at the loopback proxy; the entire credential-bearing env family (ANTHROPIC_*, AWS_*, GOOGLE_CLOUD_*, GOOGLE_APPLICATION_CREDENTIALS, *_TOKEN, *_KEY, *_SECRET, …) is stripped from the composed environment. The Bedrock/Vertex routing switches (CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, and the _SKIP_*_AUTH pair) are force-removed regardless of value — otherwise their mere presence would route Claude Code to the real Anthropic API via AWS/GCP and bypass the proxy. The proxy holds the real OAuth credential.

Model tiers (override via env).

Tier Env var Default
primary (opus/sonnet) ANTHROPIC_MODEL gpt-5.6-sol
small/fast (haiku) ANTHROPIC_SMALL_FAST_MODEL gpt-5.6-luna

Operator-provided values win over the defaults. Additional overrides: MOSAIC_CLAUDEX_CONFIG_DIR (isolated config dir), ANTHROPIC_BASE_URL (proxy endpoint).

Hooks management

After running mosaic wizard, Claude hooks are installed in ~/.claude/hooks-config.json.

mosaic config hooks list              # Show all hooks and enabled/disabled status
mosaic config hooks disable PostToolUse  # Disable a hook (reversible)
mosaic config hooks enable PostToolUse   # Re-enable a disabled hook

Set CLAUDE_HOME to override the default ~/.claude directory.