D-39: I contaminated an open independent review. RR12 was an open registered check and I sent rev-974
my CONCLUSION, not just my observation. rev-974 then downgraded an automated Codex review that had
flagged RR12 as a blocker, in line with my framing. The bias sat in my instrument, not the reviewer's
diligence — a subordinate is agreeable by construction, and the divergence instruction I attached
cannot undo having named the answer first. Mos adopted the rule fleet-wide: a dispatcher may relay
observations and reproductions into an open review, never its own verdict on an open check.
Re-adjudicated by a mechanically fresh seat with no access to my framing: NON-BLOCKING, independently,
on stronger evidence than either prior pass (accept-set matrix proving the accepted set is a strict
subset of a correct case-insensitive comparison's, so it cannot false-certify; exploit path hunted and
ruled out; all 0x110000 codepoints scanned for a fold that could smuggle non-hex onto a valid SHA).
So contamination did not change the answer, and the finding stands anyway — a correct answer reached
by a contaminated process still corrupts the process.
D-40: that same fresh seat looked outside its question and found a type confusion inside the exact
conjunction the exemption rests on. `step.get("exit_code") == 0` is True for JSON false, and
coder-mos1 added the float case. Verified by me on the real #2188 record: false and 0.0 both yield
exit 0 with exempted_steps 1 — the exemption GRANTED; "0" and null correctly block. Two of four
near-miss types satisfy a conjunction whose whole justification is that it is exactly scoped.
Consequence: I reported #1033 gate-ready at 033b2ffb (RR1-RR12 pass, review 69 APPROVED, CI #2193
success 9/9) and then had to hand Mos a finding that may disqualify what I had just certified. Better
that than defending the report. Disposition is Mos's; coder-mos1 escalated it to blocker unilaterally
and moved to push — held, because the author does not adjudicate their own PR and does not void a live
APPROVED review plus terminal-green CI by pushing. Head frozen, fix prepared and unpushed, ACKed.
Board doctrine now carries both rules: never relay a conclusion into an open review, and the author
never adjudicates their own blocker status.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
102 lines
8.0 KiB
Markdown
102 lines
8.0 KiB
Markdown
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
||
|
||
**Phase:** EXECUTING — RM-03 at owner-merge; RM-02 blocked on RM-61; RM-61 **HELD on D-40 disposition (Mos)**.
|
||
**Updated:** 2026-08-01 — rotation seam CROSSED; successor seat resumed, attested, and is driving.
|
||
(Prior seat rotated at ~803k tokens, ~4x threshold.)
|
||
|
||
## Head
|
||
|
||
- Charter + 15 decisions + 4-build plan: `MISSION.md`. Backlog + all findings: `TASKS.md`.
|
||
- Planning DONE (58 tasks, P0–P5). **DECISION-1/2/3 all RULED by Mos 2026-07-31** (`TASKS.md` §5) —
|
||
nothing is waiting on a decision. D-2's availability _target_ is Jason-pending and non-blocking.
|
||
- **Executing, not planning.** RM-01 is MERGED; three lanes are live (see In-flight).
|
||
- Orchestrator seat `mos-remediation` LIVE, owns the mission, resumed across the rotation seam
|
||
2026-08-01 and re-attested to Mos from the files. Residency attestation: PASS.
|
||
|
||
## In-flight
|
||
|
||
| Task | Owner | State |
|
||
| ------------------- | ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||
| RM-01 checkout | — | **MERGED** `f58b3699` (#1027) |
|
||
| RM-03 queue guard | **Jason** | **GO** @ `78ec47cd` (cmt 20392) — HELD FOR OWNER MERGE. Head unmoved; GO commit-bound, VOID if it moves — **do not push #1032** |
|
||
| RM-02 registry ★key | — | **BLOCKED on RM-61.** Complete @ `f9746b23`, head FROZEN, 2 live REQUEST_CHANGES. `ci-postgres` FAIL on #2187 **and** #2188 |
|
||
| RM-61 CI exemption | coder-mos1 | **HELD @ frozen `033b2ffb`** (#1033). Gate-ready was reached (RR1–RR12 PASS, review 69 APPROVED, CI #2193 9/9) — then **D-40** landed. Mos rules; fix ready, unpushed |
|
||
| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** |
|
||
| #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge |
|
||
|
||
### For the incoming orchestrator — read this before acting
|
||
|
||
1. **Nothing is waiting on you that is urgent.** RM-03 waits on Jason; RM-02 waits on RM-61; RM-61
|
||
waits on Mos's D-40 ruling with its head frozen. Read the record before touching any lane.
|
||
2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 40 findings
|
||
(D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-40 in TASKS.md), every ruling with its rationale, and the
|
||
requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
|
||
3. **`MISSION.md` carries five first-class principles**, all earned by live failures — observe the
|
||
property not the proxy · pre-registration prevents retrofitting and nothing else · never ship an
|
||
integrity claim dressed as a property · when a property cannot exist at its layer, bound it and track
|
||
the real guarantee · query for refutation, never for confirmation · redundant observation on
|
||
evidence-bearing steps.
|
||
4. **Seat identity:** `export MOSAIC_GIT_IDENTITY=<seat>` is stripped by a context reset (**D-34**) —
|
||
every dispatch/rehydration brief must re-export it, or the seat cannot use its credentials.
|
||
5. **Scan CI from `-f json`, never default text** — text mode omits `clone` (**D-33**). State counts.
|
||
6. **The queue guard is zero-information until RM-03 merges** (**D-23**) — never cite its green.
|
||
7. **The bounded CI re-roll used on RM-02 was a one-time stopgap, NOT policy.** A per-PR free re-roll is
|
||
D-21 normalisation. Do not repeat it; RM-61 is the fix.
|
||
|
||
## Delivery gates — REFERENCE, do not restate
|
||
|
||
Canonical: `~/.config/mosaic/fleet/roles.local/merge-gate.md` (verdict authority) and
|
||
`~/.config/mosaic/fleet/roles/validator.md`. Order + the freeze/zero-information rules are stated once in
|
||
[`MISSION.md`](./MISSION.md) and [`KICKSTART.md`](./KICKSTART.md) — **read them there.**
|
||
|
||
This board deliberately does **not** repeat the gate definition: restating it from memory is exactly how
|
||
the merge-gate step went missing from mission setup in the first place (**D-26**), twice, including once
|
||
inside the correction for it.
|
||
|
||
## Fleet seats
|
||
|
||
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
|
||
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
|
||
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
|
||
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
|
||
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
|
||
|
||
## Gate status
|
||
|
||
- Freeze: LIFTED for this workstream only.
|
||
- Git identity: orchestrator runs `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
|
||
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
|
||
- Capability is **per-path** (D-11b → **superseded in part by D-13/D-15**): a token file is **necessary,
|
||
not sufficient**. Three layers — token file (raw-API), `tea` login (tea paths), **repository permission**
|
||
(writes). Before dispatch, assert `permissions.push == true` **as that seat**, not token existence and
|
||
not a 200 on a read. Mos owns provisioning; escalate missing pairs.
|
||
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
||
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
||
- ⚠ **LIVE HAZARD (D-37) — one shared `.git/config` re-identifies EVERY worktree at once.** Every seat,
|
||
including `rev-974`'s review worktree, currently authors as **`coder-mos1`**; `MOSAIC_GIT_IDENTITY`
|
||
does **not** override it. **STANDING ORDER: commit with explicit
|
||
`git -c user.name=<seat> -c user.email=<seat>@…`, and NOBODY rewrites the shared config mid-flight.**
|
||
Real fix authorised, Mos owns it, sequenced at a quiet seam. **#1024 implicated.** Detail: D-37.
|
||
- Standing worker-brief doctrine (mandatory in EVERY brief): re-export `MOSAIC_GIT_IDENTITY` (**D-34**);
|
||
commit early/WIP (**D-31**); don't weaken a RED test to pass; if a check is unrunnable SAY SO, never
|
||
substitute; `agent-send -f` never `-m`; artifacts off shared `/tmp`; scan CI from `-f json` (**D-33**);
|
||
**relay observations into an open review, NEVER your own conclusion on an open check (D-39)**; the
|
||
**author never adjudicates their own PR's blocker status** — surface evidence, prepare the fix, hold.
|
||
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
|
||
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
|
||
|
||
## Sequencing — see [`MISSION.md`](./MISSION.md)
|
||
|
||
Builds 1-5, the cross-cutting retirements, and DECISION-1's corrected wire-in target are stated once in
|
||
the charter and `TASKS.md` §5. **Not repeated here** — the previous copy of DECISION-1's status on this
|
||
board is one of the six stale restatements below.
|
||
|
||
## Decisions log — full record in [`TASKS.md`](./TASKS.md)
|
||
|
||
All 40 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-40 in `TASKS.md`) and every ruling with its
|
||
rationale live there. **Not duplicated here** — a second copy is a second thing to go stale, which this
|
||
board had done three times in one night (gate list, capability registry, DECISION-1 status), and three
|
||
more times by the next rotation seam (RM-61 "building", "nothing implemented yet", DECISION-1/2/3
|
||
"must be ruled"). The rulings a fresh seat needs are items 4–7 above; they are **not** repeated here,
|
||
because that repetition is what went stale.
|