Files
stack/docs/remediation/BOARD.md
T
mos-dt-0andClaude Opus 5 08cb73fde3 docs(remediation): bank D-45/D-46/D-47 — the fix moved the author's control point instead of removing it
Second NO-GO on the keystone at 32b490a7. The pattern is the finding, not the three blockers.

D-45: round 1 the author set activationCommit as a field, so we derived it; round 2 the derivation
depends on WHEN the author introduces gates/gates.manifest.json. rev-974 committed a gate change before
adding the manifest — deriveHistoryBoundary picked that commit as activation, the prospective list held
only the later introduction, and verifyHistory returned no failures. The three registered seam controls
cannot catch it because they compare candidates against whatever introduction the author selected: they
validate the choice, not the choosing. You cannot fix "the author controls X" by deriving X from
something the author also controls. That is D-19/D-25 verbatim — the anchor must live outside the
audited party's authority — arriving a third time, now inside the keystone, and it is exactly why
Builds 1-2 are forced rather than preferred.

D-46: I reproduced it myself. Emptying criteria, gates, proseClaims and compatibilityScenarios — 17, 7,
8 and 2 entries — and pointing gateRoots at an empty directory yields EXIT 0, reporting "all registered
cases ran from this checkout" and "open behavior deltas: 0". "All registered cases ran" is vacuously
true over an empty set. The registry can be reduced to nothing and still report green.

D-45 and D-46 are the same defect at two levels: vacuity through emptiness. Empty the commit range or
empty the registry population — either way a universally-quantified check over an empty set passes.
seam=HEAD was the first instance and we fixed it AS an instance; the principle was never extracted, so
it came back one level up. Proposed general clause pending Mos: no universally-quantified registry
check may pass over an empty set — non-emptiness and anchoring are preconditions, not properties.

D-47: the new criteria are still instance-scoped. RM02-EVIDENCE-SUBJECT-BINDING covers only provider
evidence identity, not whether every registered gate binds evidence to its subject; RM02-TYPE-STRICT-
SCHEMA covers registry schema fields, not each gate's own discriminators. Do not relabel the
originating instances as the general clauses.

Dispatch PAUSED for the first time this session: the fix needs a non-author-controlled anchor, which
touches the provider/merge-base boundary and is adjacent to RM-60, which Mos and Jason own. Asked Mos
whether that anchoring is in scope for f10-coder here or crosses into RM-60, and whether the empty-set
principle becomes a general clause now.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 12:04:13 -05:00

8.5 KiB
Raw Blame History

mos-remediation — LIVE BOARD (keep < 8 KB)

Phase: EXECUTING — RM-03 at owner-merge; RM-61 MERGED; RM-02 keystone is the front. Updated: 2026-08-01 — seam crossed; successor seat resumed, attested from the files, and is driving. ⚠ That was a MANUAL pane respawn (prior seat ~803k tokens): it validates the checkpoint+rehydration design, NOT a lifecycle mechanism — P-LIFECYCLE rotation does not exist yet (D-41 / RM-62).

Head

  • Charter + 15 decisions + 4-build plan: MISSION.md. Backlog + all findings: TASKS.md.
  • Planning DONE (58 tasks, P0P5). DECISION-1/2/3 all RULED by Mos 2026-07-31 (TASKS.md §5) — nothing is waiting on a decision. D-2's availability target is Jason-pending and non-blocking.
  • Executing, not planning. RM-01 is MERGED; three lanes are live (see In-flight).
  • Orchestrator seat mos-remediation LIVE, owns the mission, resumed across the rotation seam 2026-08-01 and re-attested to Mos from the files. Residency attestation: PASS.

In-flight

Task Owner State
RM-01 checkout MERGED f58b3699 (#1027)
RM-03 queue guard Jason GO @ 78ec47cd (cmt 20392) — HELD FOR OWNER MERGE. Head unmoved; GO commit-bound, VOID if it moves — do not push #1032
RM-02 registry ★key MOS 2nd NO-GO @ 32b490a7. D-44's four closed as instances; D-45 (derivation still author-controlled via introduction timing) + D-46 (empty registry passes green) + D-47 (clauses instance-scoped). DISPATCH PAUSED — fix needs a non-author anchor, may cross RM-60
RM-61 CI exemption MERGED f4fd5967 (#1033). #1034 closed; #1000 stays OPEN (retirement trigger). Exemption is on main
RM-59 / RM-60 Jason (infra) tracked deps; RM-60 option B
#1023 queue attempt Jason SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do not merge

For the incoming orchestrator — read this before acting

  1. Lane state lives in the In-flight table above — this item does NOT restate it. It went stale three times in one session by duplicating that table (D-26's class). Read the table. ⚠ And re-derive any board claim from the provider before load-bearing use (D-43) — the board is sole-written and has no independent verifier.
  2. docs/remediation/TASKS.md is authoritative, not the newest voice in a chat. It holds 48 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-47 + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
  3. MISSION.md carries five first-class principles, all earned by live failures — observe the property not the proxy · pre-registration prevents retrofitting and nothing else · never ship an integrity claim dressed as a property · when a property cannot exist at its layer, bound it and track the real guarantee · query for refutation, never for confirmation · redundant observation on evidence-bearing steps.
  4. Seat identity: export MOSAIC_GIT_IDENTITY=<seat> is stripped by a context reset (D-34) — every dispatch/rehydration brief must re-export it, or the seat cannot use its credentials.
  5. Scan CI from -f json, never default text — text mode omits clone (D-33). State counts.
  6. The queue guard is zero-information until RM-03 merges (D-23) — never cite its green.
  7. The bounded CI re-roll used on RM-02 was a one-time stopgap, NOT policy. A per-PR free re-roll is D-21 normalisation. Do not repeat it; RM-61 is the fix.

Delivery gates — REFERENCE, do not restate

Canonical: ~/.config/mosaic/fleet/roles.local/merge-gate.md (verdict authority) + ~/.config/mosaic/fleet/roles/validator.md. Order and the freeze/zero-information rules: MISSION.md and KICKSTART.md. Read them there — restating the gate from memory is how the merge-gate step went missing from mission setup twice, once inside the correction for it (D-26).

Fleet seats

  • mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket mosaic-fleet) — ACTIVE
  • planner-opus — adversarial planner (robustness), Opus 5, socket default — DELIVERED, idle
  • planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket default — DELIVERED, idle
  • rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
  • Mos (mos-claude) — lead coordinator, socket default — relay path to Jason

Gate status

  • Freeze: LIFTED for this workstream only.
  • Git identity: orchestrator runs MOSAIC_GIT_IDENTITY=mos-dt-0 INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
  • Capability is per-path (D-11b → superseded in part by D-13/D-15): a token file is necessary, not sufficient. Three layers — token file (raw-API), tea login (tea paths), repository permission (writes). Before dispatch, assert permissions.push == true as that seat, not token existence and not a 200 on a read. Mos owns provisioning; escalate missing pairs.
  • Seat identity (D-11a): token identity AND git config user.name/user.email must BOTH be set and agree. Exporting MOSAIC_GIT_IDENTITY alone does NOT fix commit authorship.
  • LIVE HAZARD (D-37) — one shared .git/config re-identifies EVERY worktree at once. Every seat, including rev-974's review worktree, currently authors as coder-mos1; MOSAIC_GIT_IDENTITY does not override it. STANDING ORDER: commit with explicit git -c user.name=<seat> -c user.email=<seat>@…, and NOBODY rewrites the shared config mid-flight. Real fix authorised, Mos owns it, sequenced at a quiet seam. #1024 implicated. Detail: D-37.
  • Standing worker-brief doctrine (mandatory in EVERY brief): re-export MOSAIC_GIT_IDENTITY (D-34); commit early/WIP (D-31); don't weaken a RED test to pass; if a check is unrunnable SAY SO, never substitute; agent-send -f never -m; artifacts off shared /tmp; scan CI from -f json (D-33); relay observations into an open review, NEVER your own conclusion on an open check (D-39); the author never adjudicates their own PR's blocker status — surface evidence, prepare the fix, hold.
  • Remote control: native /remote-control NOT wired in this runtime. Path is Mos-relay (Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.

Decisions log — full record in TASKS.md

All 48 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-47 + D-38c in TASKS.md) and every ruling with its rationale live there. Not duplicated here. The history of why this board must not restate — six stale copies across two seams — is rolled verbatim into BOARD-LEDGER.md.