Records Jason's 2026-09-26 ruling: Sage leads the project, Darkwing is a collaborating seat, development stays in T3, and the old ~/.mosaic fleet is being retired. The lead role adds no push, merge or deploy authority. - QUEUE rows 23-25 show their commits and pushes; row 8 links a parked stub brief listing the rulings Jason must make before fleet seats move. - Shared records from Darkwing (rows 6, 16, 18, 22, #1511, #1512) and Dewey (row 5) that were waiting on one owner for the shared files. - DEFERRED: T3 headers counted as human in the ledger (#1506), #1509 engine test leak and busy gap, #1512 re-run outcome. - BUILD-LOG.md rebuilt as HEAD plus the uncommitted entries; the working copy had dropped the row 23-25 entries. Diff against HEAD is additions only. All eight suites green. Not pushed. Co-Authored-By: Claude Opus 5.5 <[email protected]>
588 lines
52 KiB
Markdown
588 lines
52 KiB
Markdown
# CURRENT — narrative log of the work in flight
|
||
|
||
The task list is `docs/plans/QUEUE.md`: one table, one row per piece, with
|
||
owner, state and gate. Read that first; it says what is next for you. This
|
||
file holds the narrative behind the rows and the completed log, and it does
|
||
not always name one action any more. If the two disagree, QUEUE.md wins.
|
||
|
||
This file historically named exactly one next action. Any "continue" / "next" /
|
||
"proceed" message means: execute the action below, fully (implement → test →
|
||
verify against its acceptance criteria → commit → push → close the issue →
|
||
update this file to the next action). No ambiguity, no re-planning.
|
||
|
||
## Next action
|
||
|
||
Current owner priority: #1512, QUEUE row 6 prescribed Filbert relaunch-activity pilot.
|
||
Filbert acknowledged sole source ownership; Darkwing reviews backend and Dewey
|
||
acknowledged UX review. Charter: `2026-09-15_relaunch-activity.md`.
|
||
Darkwing created/read back #1512 as authenticated Darkwing, set the owning native
|
||
seat's task through Piece5 step3 with identity preserved, and independently
|
||
reproduced old assistant text still presented after a newer live registration
|
||
in an isolated fixture. Evidence: `agents/darkwing/work/relaunch-activity/baseline.json`.
|
||
R1 arrived with seven pinned source files. Darkwing approved backend/source;
|
||
Dewey approved scoped UX with eight frozen targeted tests. Darkwing's first full
|
||
serialized run failed an inherited Discord engine tool-turn test then hung120s.
|
||
A later full frozen TAP run with a15s test deadline passed351/351 without force-exit.
|
||
Rocko diagnosed a test busy/settled-event race and success-only cleanup hang;
|
||
Darkwing independently reproduced the busy assertion with a 50ms event split and
|
||
finally cleanup. A separate timeout-log timing flaw and a potential engine
|
||
followUp-after-timeout defect were also reported. The latter belongs to row21;
|
||
no live incident is claimed. orch-01 was notified on its verified named socket.
|
||
Evidence: `agents/darkwing/work/relaunch-activity/engine-diagnosis.md`.
|
||
Darkwing verified 31 frozen Discord dependency files match commit1ac812d3.
|
||
Filbert confirmed his archive used moving HEAD and the old HANDOFF label was wrong.
|
||
He supplied an append-only correction outside R1; Darkwing verified its hash and
|
||
all89 frozen dependency pins. Local copies are `r1-provenance-correction.json`
|
||
and `r1-dependencies.sha256` under the relaunch-activity work directory.
|
||
Provenance hold resolved; original R1 and all seven source pins remain unchanged.
|
||
2026-09-26: 1685deb4 fixed the engine test race. A re-run of the frozen candidate
|
||
against 21e3e908 passed the serial acceptance command 397/397 three times.
|
||
Failures that only show when tests run concurrently are #1509 engine tests and
|
||
reproduce on clean HEAD (`relaunch-activity/rerun-2026-09-26.md`). Sage ruled that
|
||
#1512 integrates on the serial evidence. #1511 and #1512 are committed locally in
|
||
af4203ca with rows 18 and 22, and not pushed. The engine defects are a DEFERRED
|
||
entry against #1509. #1512 closes after Sage's records commit. The board restart
|
||
that shows #1512 live and the Gate F live assignment both wait on Jason.
|
||
Next for Darkwing: the #1506 ledger fix for T3 headers (Filbert reviews), then
|
||
the #1509 engine test and `busy` fixes (Rocko reviews, source only).
|
||
No live action, publication, operator acceptance or GateF claim.
|
||
Standing owner mandate: after each accepted iteration, automatically execute the
|
||
next ready authorized item, without a routine next-step prompt. Existing scope,
|
||
review, access, acceptance and protected-operation gates still apply.
|
||
|
||
Jason accepted row 18 with "parfait". The newer standing continuation instruction
|
||
supplies the start for the next already-briefed row 6, replacing its historical
|
||
Sunday start-message scheduling, without waiving dependencies or protected gates.
|
||
Rocko's existing native repository context was verified and he acknowledged sole
|
||
source ownership under `2026-09-14_task-attribution.md`. Filbert and Dewey both
|
||
acknowledged independent review ownership. Darkwing reproduced the current CLI
|
||
refusing --by with exit 4 using no live configuration or registration.
|
||
Evidence: `agents/darkwing/work/task-attribution/baseline.json`.
|
||
R1 arrived and all 15 working/frozen pins matched. Filbert approved backend source,
|
||
reporting independent 141/141 working/overlay tests and six launcher checks.
|
||
Dewey requested R1-U1: WebUI inspector conflates null/inapplicable attribution
|
||
with legacy registered unknown. Both lanes returned before Rocko received the
|
||
bounded R2 correction, including a misleading privacy-syntax comment correction.
|
||
Review record: `agents/darkwing/work/task-attribution/r1-review.md`.
|
||
Darkwing added only the missing --by usage flag to dirty `docs/TOOLS.md`, preserving
|
||
other changes; that additive documentation also requires independent review.
|
||
R2 has now passed both exact source review lanes. R1-U1 and the comment finding
|
||
are closed; Filbert also approved the separate TOOLS usage patch. Darkwing ran
|
||
344/344 broader serialized tests. Evidence and limits:
|
||
`agents/darkwing/work/task-attribution/r2-review.md`.
|
||
Old strict-v1 readers reject the new field, independently reproduced with synthetic
|
||
records. No live setter write may precede the authorized reader update.
|
||
Jason authorized that envelope with yes. On 2026-09-15, backend PID 3769124
|
||
exited gracefully; replacement 3414098 is healthy and serves the exact reviewed
|
||
board page. API exposes the new attribution field; two legacy registered rows
|
||
show unknown and non-registration tasks have null attribution.
|
||
The Rocko write was blocked before mutation: its registration names dead PID
|
||
185602, actual native lock owner is 3707667, and its discovery directory is
|
||
absent, so there is no Rocko board row. This existing Claude-board gap remains
|
||
separate; no identity repair or discovery expansion was attempted.
|
||
All registration bytes, five agent pane identities and connector identity stayed
|
||
unchanged. Receipts: `agents/darkwing/work/task-attribution/backend-restart.jsonl`
|
||
and `backend-live-verification.json`.
|
||
Jason authorized Filbert instead and confirmed Claude console integration is
|
||
not yet implemented. Filbert's native registration identity was reverified;
|
||
the authorized task update passed live API verification at 2026-09-15T00:36Z:
|
||
task '#1511 task attribution user test', source registration, setter darkwing.
|
||
Only task/taskSetBy/updatedAt changed; identity fields and startedAt were preserved.
|
||
All other registrations and agent/connector/backend identities stayed unchanged.
|
||
Original registration is backed up privately outside the repository. Receipt:
|
||
`agents/darkwing/work/task-attribution/live-test.jsonl`.
|
||
Jason supplied the table screenshot and inspector text confirming darkwing with
|
||
'as claimed by the caller, not verified'. Bounded local attribution delivery is
|
||
operator-confirmed. Publication remains separate. The standing continuation mandate
|
||
now advances the prescribed Filbert assignment above, after this local acceptance.
|
||
Gate F is not claimed or backdated. #1508 still depends on row 6 completion.
|
||
|
||
## Completed bounded row 18 delivery
|
||
|
||
Actual start: Filbert acknowledged sole implementation ownership under
|
||
`2026-09-14_discord-board-row.md`; Darkwing independently reviews backend/privacy
|
||
and Dewey acknowledged read-only UX review. Darkwing prepared acceptance checks
|
||
and reproduced the missing reply refusal with a synthetic connector plus forged
|
||
registration: current handler returned 200 and called fake transport once, with
|
||
zero real sends. Evidence: `agents/darkwing/work/discord-board/reply-baseline.json`.
|
||
Exact R3 source approvals from Darkwing and Dewey are persisted in 26257.
|
||
Nine working/frozen pins and three-file R2 delta independently verified; full
|
||
serialized suite 322/322 passed, plus Dewey's eight targeted tests. R1-B1 and
|
||
R2-B2 closed: inaccessible STOP is unknown and connector Task is fixed safe
|
||
metadata, not a routing envelope. Prior attention/UI assets are preserved.
|
||
Read-only live observation after approval found shared-signals alive/idle,
|
||
not braked, owner matching systemd MainPID, fixed Task and no registration.
|
||
Evidence: `agents/darkwing/work/discord-board/r3-live-observation.json`.
|
||
Owner approved the backend-only restart. Old PID 3204655 exited gracefully;
|
||
replacement PID 3769124 is healthy on 7331. Live API now shows the shared-signals
|
||
connector idle/live/not braked with safe Task metadata; actual connector reply
|
||
POST was refused with 409 before transport. All five agent pane identities and
|
||
the connector service PID/start identity are unchanged. Evidence:
|
||
`agents/darkwing/work/discord-board/backend-live-verification.json`.
|
||
Jason accepted the operator visual test with "parfait". This bounded local row
|
||
delivery is complete, without publication or live brake/offline transition claims.
|
||
No connector service/binding/STOP/home changes. Concurrent R1 timeouts remain unresolved/not green and
|
||
are recorded in DEFERRED.md; no general transcript redaction or broader runtime
|
||
conformance claimed. Standing continuation has advanced to row 6 above. Filbert
|
||
remains the row-18 source author; frozen R3 evidence remains unchanged.
|
||
|
||
Prior accepted correction: #1503, QUEUE row 22, board attention status correction.
|
||
Jason passed internal-team checks 1-4 and reported Researcher's false waiting
|
||
status in step 5. He approved ordinary completion becoming idle and reserving
|
||
waiting for explicit human-input requests. Filbert approved exact R1, receipt
|
||
26248. Author 144 and reviewer 193 covered different package sets; the combined
|
||
five-package author rerun passes 213 tests. Read-only actual Researcher scan
|
||
returns idle and waitingOnYou:false. Owner approved backend-only restart, now
|
||
completed and live-verified in receipt 26249: old PID 1265952 exited gracefully,
|
||
replacement PID 3204655 is healthy on loopback 7331. Live API shows Researcher
|
||
idle/not waiting at the original screenshot activity timestamp. All five agent
|
||
process identities are unchanged. Jason confirmed both targeted tests: ordinary
|
||
completion shows idle; an explicit input request shows waiting, Seen removes it
|
||
from attention without resolving waiting, and the subsequent completion returns
|
||
to idle. The full targeted status sequence is operator accepted. This is not
|
||
broader MVP/cross-harness acceptance or publication; do not resume another queue
|
||
item by inference. Brief: `2026-09-13_board-attention-status.md`.
|
||
|
||
Prior bootstrap checkpoint: #1510, QUEUE row 16. Darkwing coordinates direct coding,
|
||
review and research through the five repository-native agents. Keep source
|
||
changes in `/mnt/storage/src/mosaic-stack`; no `~/.mosaic` launcher/provisioning
|
||
changes and no live fleet stop or migration. Researcher's missing native entry
|
||
and recovery files are added. Six isolated launcher tests and all five real
|
||
`--check` runs pass without launching engines. Internal Filbert approved exact R1
|
||
as source; attributed receipt 26204, independently rerunning six tests in both
|
||
working and frozen copies. Source setup is approved. Owner-authorized live smoke passed for Researcher,
|
||
which returned the exact expected model response, receipt 26216. Rocko startup
|
||
correctly refused an existing native lock; its running repository-native Sonnet
|
||
process is on the mosaic-fleet socket and was left intact, not retested with a
|
||
model prompt. No existing sessions restarted, home launchers modified or broader
|
||
MVP/user acceptance or publication claimed. Brief: `2026-09-13_internal-development-bootstrap.md`.
|
||
The historical MVP queue and CHAT-01C publication gate below remain separate;
|
||
this direction does not resume #1508 or authorize external provisioning.
|
||
|
||
Gaps found and not fixed go to `docs/plans/DEFERRED.md`, one line each; check it at every gate.
|
||
|
||
Jason decided on 2026-09-12 (MOSAIC-STACK-D-001) that the MVP is the control
|
||
board: one web page listing running agent sessions across projects, showing each
|
||
one's status, and flagging which ones are waiting on him. Plan page:
|
||
`docs/plans/2026-09-12_control-board-mvp.md`. Tracking: #1503. Steps 1 and 2
|
||
are done in this checkout: `packages/control-board` scans every Pi agent
|
||
(repo `.pi/state/*` and `~/.mosaic/fleet`) and serves the page.
|
||
|
||
Start it with `node packages/control-board/src/cli.mjs serve` and open
|
||
http://127.0.0.1:7331/ (loopback only, no auth, no daemon; Ctrl-C stops it).
|
||
|
||
First step-3 refinement landed 2026-09-12: liveness follows the tmux pane
|
||
(killed pi sessions show offline) and a "Seen" button drops read rows out of
|
||
"Waiting on you" until the agent writes again
|
||
(`docs/plans/reviews/2026-09-12_control-board-step3-seen-marks.md`).
|
||
|
||
Gate A (task, active project, workspace per row) passed on 2026-09-12 and
|
||
Jason's go on the professor session's brief opened #1504: seat registration.
|
||
`scripts/mosaic launch <seat>` runs a seat's launch script unchanged and
|
||
leaves one record at `<dataRoot>/seats/<layout>/<seat>/registration.json` that the
|
||
board reads instead of guessing; `scripts/mosaic seat task <seat> <text>`
|
||
changes the task. The four repository launch scripts register themselves.
|
||
Package: `packages/seat`. Fleet seats stay on their own launchers (Jason's
|
||
ruling, 2026-09-12); only `agents/` seats register. A record whose pid is
|
||
gone is stale and does not override the derived values.
|
||
|
||
Gate B passed 2026-09-12 (seat registration shown and used on the board).
|
||
|
||
Piece 2, reply-from-board (#1505; brief in the plan page, section "Piece
|
||
2: reply-from-board", approved by Jason 2026-09-12), is built and pushed
|
||
2026-09-12: a text box and Send in the detail of registered, live rows;
|
||
`POST /api/reply` runs `tools/tmux/agent-send.sh -s <session> -S
|
||
"<host>:control-board" [-L <socket>] -m <text>` and returns the exit code,
|
||
stdout and stderr; the page shows `delivered` or `failed` with the stderr.
|
||
No send-keys, queue, history or broadcast; no change to `packages/seat` or
|
||
`agent-send.sh`. Board suite 98/98.
|
||
|
||
Gate C passed 2026-09-12 on 867619dc (logged by Jason at 4f830680):
|
||
"pizza?" from the board to filbert arrived with the trailer, the seat
|
||
answered in its own session with no send attempt, and the row showed the
|
||
answer on the next scan. #1505 is closed.
|
||
|
||
Gate D (2026-09-12, Jason's run of the ledger for 2026-09-06 to 2026-09-12):
|
||
**18.9 human messages per closed issue.** That is the number to move next
|
||
week: every message Jason types to a seat is a nudge the rails did not
|
||
absorb. Target for the week of 2026-09-13: under 10, by assignment through
|
||
`mosaic seat task` and the board instead of the terminal, then the
|
||
orchestrator seat. Companion numbers from the same run, for context only:
|
||
8 issues closed, median 2.7 hours open, 1.9 follow-up commits per issue.
|
||
|
||
Next action: piece 4, the WebUI on Dewey's Console design (MOSAIC-STACK-D-002).
|
||
Brief on the plan page, section "Piece 4: WebUI first screen (Console)".
|
||
Owner: dewey, issue #1507 opened HTTP 201 on 2026-09-13 UTC. Implementation
|
||
in `packages/webui`; Darkwing confirmed no source overlap and released tracking
|
||
at fab40f25. Filbert is the independent reviewer. Board files stay unchanged;
|
||
any needed board edit requires exact ownership coordination first. Published to
|
||
refactor at ea00ec66d93d1d554463f94711c343c9c8df20c4, exact remote verified.
|
||
Filbert APPROVED WEBUI-1507-R1, manifest 509f20e5; all 21 hashes reverified.
|
||
Committed-tree regressions 208/208 include six WebUI tests, Chromium at
|
||
320..2560px and 330 passing rendered contrast samples. Receipt:
|
||
`reviews/2026-09-13_webui-publication.md`.
|
||
Jason's 2026-09-13 feedback supersedes readiness for the workday test: Gate E
|
||
is blocked on refinement. He needs project/session navigation in the left
|
||
sidebar and independent two-way chat interfaces, not dashboard cards and an
|
||
inspector send box. He reports the return flow is missing in actual use; this
|
||
needs reproduction. The current inspector's latest assistant text is not a
|
||
conversation history. Restore relative activity age too; board `ageSeconds`
|
||
is time since last activity, not session lifetime. Durable feedback and
|
||
screenshot descriptions: #1507 comment 26082.
|
||
Refined brief and decomposition: `2026-09-13_webui-session-chat.md`, CHAT-00..08.
|
||
Jason settled Q1-Q22: all seats, full chat/tools/attachments/native approvals,
|
||
enforced controller transfer, durable drafts/queue, interrupt/force-stop and
|
||
explicit recovery. Old accepted foundation requirements were recovered rather
|
||
than re-invented. Jason confirmed shared understanding and authorized bounded CHAT-00 preparation
|
||
on 2026-09-13. CHAT-00 charter is #1507 comment 26094; research deliverable
|
||
`chat-00/README.md` is independently APPROVED by Filbert in comment 26100.
|
||
Four exact research files published at 370823b3, remote identity verified;
|
||
48 synthetic/source checks also pass from the committed research copy.
|
||
Jason approved CHAT-01 contract drafting; active bounded charter is comment
|
||
26103. R1 request 26105 received REQUEST CHANGES in 26106/26107/26108.
|
||
All R2 verdicts were collected before R3 edits. Filbert 26119, Dewey 26120
|
||
and Rocko via agent-send requested changes and accepted the named companion
|
||
gates. R3 fixes cursor binding, disconnected-browser scheduler authority and
|
||
visible dispatch refusal, NEW message roles, corrupt-queue recovery without
|
||
control deadlock, and non-destructive revocation reconciliation. It also tests
|
||
current retry dispositions, superseded stops, native resolution evidence,
|
||
stop-context confirmations and second-actor draft privacy.
|
||
R3 exact review 26124 is APPROVED AS BOUNDED DRAFT by Filbert 26126,
|
||
Dewey 26127 and Rocko via agent-send, recorded with follow-ups in 26128.
|
||
Only the four reviewed files published at 28d4e98ad8b406ca84b30170558bee22402f1e55;
|
||
remote ref verified, committed copy byte-identical to reviewed snapshot and
|
||
checks green: 98 shapes, 322 omissions, 76 reference cases, 17 lifecycle
|
||
sequences plus regressions; CHAT-00 48/48. Receipt 26131 read back. Shared
|
||
dirty planning/logs and other owners' files were excluded from the commit.
|
||
CHAT-01 bounded delivery is complete, not runtime/security/all-seat acceptance.
|
||
Jason approved CHAT-01C proposal 26131 with performing-agent attribution.
|
||
Darkwing authored the four `chat-01c/` contract/model files and froze R1 for
|
||
review in 26137, posted and read back as actual Gitea darkwing, account 104.
|
||
Seat credentials at the operator-specified location work; no minting needed.
|
||
Never use the legacy helper's default Jason identity. Future Git commits use
|
||
explicit performing-agent author/committer and seat-authenticated publication,
|
||
without changing shared config or rewriting published history.
|
||
R1 findings were corrected and both Filbert and Dewey APPROVED exact R2
|
||
through agent-send; attributed receipts persisted as darkwing in 26152.
|
||
Candidate request 26149, clean copy /tmp/chat-01c-r2-frozen-lujze3oe. Eleven
|
||
closed examples/187 omission-extra cases and models/base regressions pass.
|
||
Locally committed b023841c8a44d08677dc388043997eb4277b0545 with verified author
|
||
AND committer Darkwing <darkwing@mosaicstack.dev>; only four reviewed files.
|
||
Committed-copy checks pass. Published: Dewey confirmed on 2026-09-26 that
|
||
b023841c is on origin/refactor (`git branch -r --contains`). The HTTP 403
|
||
blocker (26154) is resolved. From 2026-09-26, pushes go through Sage with the
|
||
jarvis identity, and each push needs Jason's word. CHAT-02..08 are not
|
||
chartered. They are held until Jason rules, through Sage, on what "all seats"
|
||
means with the fleet retiring, on row 5's priority against row 6 and #1508,
|
||
and on charters and backend authors. Only small Console fixes are approved
|
||
now (return-flow regression, relative Age; Filbert reviews). No runtime work
|
||
or other queue item has started.
|
||
CHAT-03I/03D, B1-B6/Q22 and #1507 acceptance remain open. Carry Rocko R3-1
|
||
native dispatched-input reconciliation into CHAT-02, R3-2 into CHAT-01C and
|
||
R3-3 observer-revocation coverage into a later fixture revision, per 26128.
|
||
No peer reviews remain pending for CHAT-01. No other queue/runtime/live start.
|
||
Rocko architecture findings are incorporated with accepted evidence corrections.
|
||
Actual Claude protocol compatibility, tool isolation, access and cutover remain
|
||
unverified; no runtime implementation or live cutover yet. Q20 cancels ordinary-Interrupt
|
||
follow-ups into drafts; Q21 authorizes reviewed/green scoped refactor publication;
|
||
Q22 preserves piece-5/#1508/fleet ordering. Dependent fleet work remains held. Darkwing/Filbert planning corrections are
|
||
incorporated, including explicit remote implementation and publication gates. Live one-seat cutover requires separate
|
||
Jason approval after both harness fixtures and exact rollback plan. Keep #1507
|
||
open; original tests are not new-scope approval. No code or live effects started.
|
||
Darkwing closed #1506 (Gate D written, comment 26067) and
|
||
#1504 (registration shipped, Gate B passed, comment 26069) on 2026-09-13 UTC.
|
||
Darkwing holds for piece 5 (darkwing on point; brief on the plan page, section "Piece 5") until Jason sends the start message, planned Sunday 2026-09-13. #1503 stays open until Jason rules on "who is waiting on me".
|
||
|
||
`packages/ledger` is implemented: read-only local refactor subjects, one
|
||
Gitea issue request, repo seats' user messages, two tables and JSON. Ledger
|
||
fixtures 20/20; ledger, board, seat and registry suites 202/202, also checked
|
||
in a clean candidate copy. Filbert independently APPROVED all six pinned
|
||
source/test/doc files in `reviews/2026-09-12_ledger-verdict.md`. The helper's
|
||
no-body GET cleanup exit defect is fixed and regression-tested. Counting
|
||
rules, one-page refusal and unknown metadata limits are in the package README.
|
||
Published to refactor at cd0aa5fb; Gate D accepted and #1506 closed.
|
||
The brief remains in the plan page under "Piece 3: ledger (numbers for the rails)".
|
||
After Gate D, the WebUI on Dewey's Console design absorbs the board as its
|
||
first screen. Close #1503 when Jason says the page answers "who
|
||
is waiting on me" without him opening a terminal. Out of scope until he
|
||
asks: auth or provider registry, roster schema changes, hooks/plugins, comms,
|
||
memory, multiple sessions per seat, stopping seats, new root files. The
|
||
registry line (increment 3, headless identity-env leak) stays parked; #1500
|
||
is closed.
|
||
|
||
## Completed checkpoint: #1500 increment 2 (historical)
|
||
|
||
Registry plan review is complete. All ten gates carry owner rulings
|
||
(2026-09-10, ms-grill-me + Q15); gate 7 closed via PI-REFRESH-ROCKO-1
|
||
investigation and GATE7-FINAL-FILBERT-1 APPROVED. Published: 224147ec,
|
||
b8008eda, d5307d2b, 86e009dde52bd588b4ade344bc292d5518843e1d (remote verified).
|
||
#1500 prerequisite correction complete: independently APPROVED af97b5be,
|
||
source 6335342873985538da3e7dc80cf9e9505e758832 pushed and remote verified.
|
||
Committed-tree package/launcher fixtures passed 48/48; source and test limits:
|
||
`docs/plans/reviews/2026-09-10_m20-correction-completion.md`.
|
||
Jason subsequently APPROVED the fixture-only materialization/refresh increment.
|
||
Fixture-only resolution, generation and fake refresh are implemented locally.
|
||
Filbert APPROVED the complete increment at manifest11255dd4 in
|
||
`docs/plans/reviews/2026-09-10_m20-refresh-final-verdict.md`.
|
||
Darkwing verified all21 reviewed bytes match the live tree and independently
|
||
reran74/74 tests in a clean baseline-plus-reviewed-overlay copy.
|
||
Jason approved the increment-specific task/release applicability disposition.
|
||
Source published at3daee5ad89dc6a006ca554ad7fda2b23eb96bb03; exact remote verified.
|
||
Clean committed-tree checks: package/launcher74, config24, auth15, foundation43,
|
||
conductor17 all pass. Task/release not run or claimed passing.
|
||
Next action: present the two-test fixture demonstration for Jason's acceptance;
|
||
keep #1500 open pending that response. Demo attempt 2026-09-11 failed only because
|
||
Jason's terminal was a pre-cutover shell whose cwd followed the retired v1 copy
|
||
(`git rev-parse HEAD` 5d277000, later pulled to next 2101c9b4); the canonical
|
||
checkout at 5abbabb7 reruns the demo 2/2 (jarvis, 2026-09-12). Rerun after
|
||
`cd /mnt/storage/src/mosaic-stack` in a fresh shell. Publication and demo receipt:
|
||
`docs/plans/reviews/2026-09-10_m20-increment2-publication.md`.
|
||
Headless identity-env fix is separate intake in the owner disposition record.
|
||
No production refresh, live-suite effects or increment3 authority inferred. Charter: `docs/plans/2026-09-10_m20-increment2-charter.md`.
|
||
No live refresh, real credentials, service installation or deployment authorized.
|
||
Increment 1 and pi 0.85.1 were published through b3fa2210; passing original tests
|
||
is not evidence that these newly identified prerequisites are satisfied.
|
||
|
||
Owner goal #1498 completed: independently approved skill/launcher repair published
|
||
at f3dce3208877626043c521c6ef5076f9559309b0; fresh remote identity verified and
|
||
committed-tree offline fixtures 5/5 passed. Completion evidence:
|
||
`docs/plans/reviews/2026-09-08_skill-launcher-completion.md`.
|
||
No live restart, timer arming or deployment. Other new skills and private/WUI
|
||
artifacts remain untouched. This closes the bounded goal, not a new registry mandate.
|
||
|
||
Jason accepted the bounded #1497 publication/recovery trial following the plain-
|
||
language brief and said "Proceed." Issue #1497 is closed; acceptance receipt:
|
||
`docs/plans/reviews/2026-09-08_publication-trial-owner-acceptance.md`.
|
||
Source publication 29c1defe and reviewed closeout 10448e41 remain the evidence pins.
|
||
No WUI design acceptance, production readiness or held-queue expansion is inferred.
|
||
|
||
## Completed trial checkpoint, before owner acceptance
|
||
|
||
The following preserves the publication-stage state; the acceptance above
|
||
supersedes its pending-acceptance and registry-deferral statements.
|
||
|
||
Execute Jason's approved publication and planned-restart recovery trial (#1497).
|
||
Plan: `docs/plans/2026-09-08_publication-recovery-trial.md`. Publish remaining
|
||
reviewed changes, temporarily including agent definitions and labeled drafts;
|
||
exclude private runtime/session/auth state. Jason performed Rocko's planned restart
|
||
and issued neutral continue; PUB-REC-ROCKO-1 returned its reserved test PASS.
|
||
Filbert independently SUPPORTS bounded checkpoint recovery and APPROVES the pinned
|
||
privacy-safe summary (0e17757c); raw records stay local. No reliability or overall
|
||
trial acceptance inferred. WUI exact 53-file draft publication is independently
|
||
APPROVED with pending-acceptance label; source/default revisions remain unimplemented.
|
||
PUB-REC-FILBERT-LAUNCHER-1 APPROVED 23 source/publication candidates at
|
||
frozen manifest 8900faf1. Jason then changed Rocko's launcher to Sonnet.
|
||
PUB-REC-FILBERT-SONNET-2 APPROVED the six revised candidates at c5ad6306;
|
||
coordinator verified all seven R2 snapshot/live files unchanged. Remaining original
|
||
candidate approvals stand. Independent combined fixtures passed 5/5. Preserve
|
||
R1 REQUEST CHANGES and the historical Fable recovery evidence unchanged.
|
||
Publication completed at 29c1defe29e5793022e1d3820b265bfc0f7f628a on refactor;
|
||
92 exact approved units committed, committed-tree fixtures 5/5 passed, push succeeded
|
||
and fresh origin/refactor identity matched. Final aggregation APPROVED at 3f8e765b.
|
||
Next action: present the bounded publication/recovery trial to Jason for acceptance.
|
||
Do not close #1497 or resume the registry queue before that acceptance.
|
||
Newer executive-update skill edits, local ms-agent-watch deletion and additional
|
||
untracked skills are outside the pinned trial candidate. Preserve them uncommitted;
|
||
exclude both executive-update files rather than publish unreviewed or stale bytes.
|
||
Verify the prospective publication tree separately; live native launch would refuse
|
||
because its required ms-agent-watch file is now locally absent. No live launch or
|
||
unrelated skill migration is part of this trial.
|
||
No further restart or re-briefing requested. C1 remains HELD.
|
||
|
||
Registry review alignment is deferred behind this newly prioritized owner trial.
|
||
No registry implementation, agent relocation, main/next merge or deployment authorized.
|
||
|
||
Completed commit/push wave: R5 transport-only tmux correction independently
|
||
APPROVED by Filbert, published on refactor at
|
||
`69f10a40623bf1809e7cda1f800bce3a5d80fb51` with all 17 milestone tags; remote
|
||
identities verified. Exit 0 means transport dispatched, application acceptance
|
||
unknown. Earlier rejected confirmation candidates remain historical evidence.
|
||
Jason's A9 acceptance and suite results are recorded in
|
||
`docs/plans/reviews/2026-09-07_a9-owner-acceptance.md`.
|
||
#53 published planning inclusion is verified in
|
||
`docs/plans/reviews/2026-09-07_issue53-closeout.md`; Jason retains issue closure.
|
||
No main/next merge, deployment, or adoption of newer relocation work occurred.
|
||
|
||
Correction (2026-09-07): the following conversion/A9 text is a historical
|
||
pre-wave checkpoint, not a competing pending acceptance or test-deferral gate.
|
||
Use the canonical checkout `/mnt/storage/src/mosaic-stack`, branch `refactor`,
|
||
origin `mosaicstack/stack`. New foundation is at root; `v1/` is the legacy archive.
|
||
The old `~/src/mosaic-stack-dev-test` path is only a compatibility symlink.
|
||
|
||
Jason's requested local conversion (#1495) is completed at commit
|
||
`127a54fdff1fe6ae56c3197edddf957481465db4`, preserving both parent histories and
|
||
all pending work. Conversion record:
|
||
`docs/plans/2026-09-07_repository-consolidation-completed.md`.
|
||
Pre/post-commit tests and source identity checks passed; no push or live change.
|
||
The index is clean. Existing uncommitted work was preserved, not blanket staged.
|
||
Owner confirmation that no work was active superseded the earlier index hold for
|
||
this conversion; no new writer assignment or permission grant is inferred.
|
||
|
||
Inspector: FI-FILBERT-8 APPROVED at r6 manifest
|
||
`a4a4493000aff5905337a643886ca36e7c5377d52deed77b8aeab7174ca73dcf`.
|
||
All 382 file identities and pins remain unchanged. Demo guide:
|
||
`docs/plans/reviews/2026-09-07_foundation-inspector-demo.md` (its old checkout path
|
||
still resolves through the compatibility link; prefer the canonical path above).
|
||
Four examples reran successfully after conversion. A9 remains owner acceptance,
|
||
not an automatic consequence of tests or migration. Task/release coverage remains
|
||
NOT RUN/DEFERRED, not deployment green. Native-parser/equality qualifications remain.
|
||
|
||
Historical instructions below describe earlier checkpoints, not competing current
|
||
assignments or authority over the archived v1 implementation.
|
||
|
||
## Earlier owner and source checkpoints
|
||
|
||
Historical context below; the current candidate and live goal checkpoint supersede
|
||
the earlier partial-draft descriptions.
|
||
|
||
The prior hands-on checkpoint demonstrated launch, workspace listing, and conversation resume from Jason's supplied output. Fresh context and mission recovery were not tested. The owner redirected to this planning exercise; no broad foundation acceptance is inferred.
|
||
|
||
Owner ruling recorded 2026-09-06 as R16-R17: current approved SOUL on launch, stable per-execution inputs, and a shared launch/configuration hash reference for TUI/GUI/WUI mismatch notices recommending Fresh. D10 is partly resolved. Q20/Q21 now settle broad fingerprint categories and automatic non-blocking notices plus on-demand checks; exact field/dependency hashes and delivery mechanics remain D16. This does not advance the phase or authorize implementation.
|
||
|
||
Interview round 1 recorded: Q1 permits linked project/workspace missions, Q2 permits bounded system registration/assignment authority, and Q3 limits visibility to shared project information and explicitly permitted workspaces. Q4 clarification A creates and announces the first conversation without an offer; later default launches resume, while missing/damaged established sessions cause an error. Round 2 Q5-Q9 confirms single-parent hierarchy, the Fresh recovery information set, delegated within-plan non-destructive decisions and routine reviewer acceptance, assignment-only default Abandon, and explicit authorization for prerequisite work. Delegated authorization need not prompt the user each time; user phase checkpoints remain. Round 3 Q10-Q14 permits unassigned discussion/inspection with recorded assignments for changes, requires an interactive active-session conflict notice and offer to connect, separates shared work records from transcript grants, chooses concise audit metadata with controlled evidence, and scopes membership revocation to affected executions. Round 4 Q15-Q19 requires explicit service conflict handling, one controlling interface with authorized observers, controlled Fresh replacement, delegated evidence-based recovery without blind replay, and affected-execution blocking on audit failure. Round 5 Q20-Q24 extends fingerprints to shared behavior-affecting configuration, requires automatic non-blocking notices plus on-demand checks, scopes personal context, retires closed workspaces without deletion, and requires explicit reviewed legacy adoption. Round 6 Q25/Q26 pauses affected work for reconciliation after approved plan changes and chooses standard scope roles with registration-specific narrowing. Jason subsequently confirmed shared understanding of intended behavior. Jason then authorized phase 2. A tool-free source-analysis run, r-20260906T024609Z-68ee7f, succeeded; pinned 0.84.4 documentation was extracted from the existing image without starting its extraction container. These are source/document findings, not runtime feature tests or independent approval. The first contract candidate is partial. Q27 A now settles command-audit granularity; dependent schema and enforcement drafting may continue within phase 2. Full schema/plan approval remains pending.
|
||
|
||
## Accepted phase-2 checkpoint (historical)
|
||
|
||
- Goal: issue-53-phase2. Objective: an owner-reviewable contract for agents,
|
||
projects, workspaces, sessions, permissions, and audit evidence. Completion
|
||
owner: Jason. Author/workspace/session remain those recorded below.
|
||
- State: satisfied. Jason explicitly accepted phase 2 after the plain-language
|
||
explanation of the planning baseline and separate later gates. P2-7 is complete.
|
||
REVIEW.md retains D1-D16 and the unproved implementation mechanisms. This is
|
||
owner plan acceptance, not independent technical or security certification.
|
||
- Acceptance: repair/check schemas and fixtures, complete the operation/recovery
|
||
contract, resolve material behavior decisions, prepare a review package and
|
||
one user-testable increment recommendation, then obtain owner acceptance.
|
||
- Evidence: `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 command
|
||
and 38 record shape cases, 16 path cases, 7 restricted-domain hash vectors,
|
||
155 runtime/control/artifact cases and 35 synthetic rule-model cases. Ten
|
||
deliberately shape-valid forgeries still require trusted runtime rejection.
|
||
These are not runtime security tests or independent acceptance.
|
||
- Reboot fixture defects were repaired, not discarded. Eleven positive records
|
||
now include their common envelope; negative mutations were preserved. Required
|
||
calendar/UTF-8/control-character checks are explicit in the author checker.
|
||
- Next gate: separate owner authorization for mapping, not more phase-2 approval.
|
||
No mapping or implementation started. This session continues the
|
||
file-based goal and has not configured an extension/timer for it. Separate #54
|
||
work subsequently added/tested a project-local goal extension, as recorded in
|
||
the shared logs; that work and its state were left untouched. This session has
|
||
not migrated issue-53-phase2 into that runtime. Elapsed time never grants approval.
|
||
- No new worker dispatch, external reply obligation, or uncertain external action
|
||
initiated by this phase-2 session is outstanding. No numeric work budget supplied;
|
||
aggregate usage remains unavailable.
|
||
- Authority remains phase-2 planning and read-only investigation. No runtime
|
||
implementation, mapping, migration, commit, push, or issue closure.
|
||
|
||
## Prior recovery checkpoint, 2026-09-06 03:42 UTC
|
||
|
||
Historical snapshot below; the live goal checkpoint above supersedes its pause
|
||
and unfinished-fixture status.
|
||
|
||
- Goal: issue-53-phase2. State: paused by owner steering. Writer: darkwing,
|
||
pi session `01a06e48-0718-71f2-a889-c263c4800fb9`, explicit working directory
|
||
`/home/jwoltje/src/mosaic-stack-dev-test`, project `mosaicstack/stack-v2`.
|
||
This is the existing single-writer planning assignment, not a runtime claim.
|
||
- HEAD remains `69d1bb3`. Preserved all uncommitted planning and unrelated skill
|
||
work. No reset, cleanup, commit, push, or implementation occurred.
|
||
- Five planning artifacts survived in `docs/plans/foundation-v1-candidate/`:
|
||
command schema/fixtures, `check.py`, and record schema/fixtures. The three
|
||
command-check file hashes match the pre-reboot checksums.
|
||
- `python3 docs/plans/foundation-v1-candidate/check.py` passes 38 shape fixtures
|
||
and 5 deliberate shape-valid forgeries. This does not prove runtime security.
|
||
- The unfinished record checker is NOT integrated into check.py. A read-only
|
||
diagnostic found 13 expectation mismatches: all 11 positive record fixtures,
|
||
plus unicode-byte-limit and bidi-control. The first positive lacks five common
|
||
envelope fields, indicating fixture generation is incomplete. Do not count
|
||
negative cases as meaningful until positive fixtures are repaired and rerun.
|
||
- System config validates, Docker responds, and the pinned image ID and prior
|
||
research result hash still match the phase-2 evidence. No Mosaic worker
|
||
container was running at inspection. Pinned temporary docs remain available.
|
||
- Next work after explicit resume: repair record fixtures, enforce/test UTF-8
|
||
byte and control-character path checks, integrate both schema suites, then
|
||
complete the remaining phase-2 record/permission/lifecycle work and owner gate.
|
||
- No outstanding assistant-initiated external action or reply is known. Wake is
|
||
manual: Jason sends a resume instruction. No timer or automatic continuation
|
||
is registered. Aggregate usage is unavailable; no numeric budget was supplied.
|
||
|
||
## Queue (ordered per docs/plans/ROADMAP.md)
|
||
|
||
1. Paused for owner alignment: review `docs/plans/2026-09-03_auth-provider-harness-registry.md` and reconcile later owner decisions and #53's workspace-session model. Gate 7 remains unresolved. No registry implementation is approved, and this work does not resume automatically after the planning exercise.
|
||
2. Deferred by owner: CI runners (Gitea hardware slow); second real adapter; push automation
|
||
|
||
## Rules
|
||
|
||
- One action in flight. Update this file at the END of every action.
|
||
- Blocked? Move the item to "Blocked" below with the reason and stop.
|
||
- Completed actions move to the log at the bottom (date + issue + result).
|
||
- Corrected entries are marked, never silently rewritten (see 2026-09-03 dedup note).
|
||
|
||
## Blocked
|
||
|
||
(none)
|
||
|
||
## Completed log
|
||
|
||
- 2026-09-12 — #1500 closed: owner accepted the fixture-only increment by rerunning the two-test demo on 5abbabb7 (2/2). Records-only closure; no source, suite or live effect. Next: re-plan against MOSAIC-STACK-D-001 before increment 3.
|
||
|
||
- 2026-09-08 — Owner-corrected Sage setup: `agents/sage/` now owns the DYOR business/strategy persona, context, launcher, and working records. Native cwd is this checkout, private history is `.pi/state/sage/sessions/`, and the prior brain command forwards here. Six offline launcher tests and both real configuration checks pass; current registry alignment queue unchanged.
|
||
|
||
- 2026-09-08 — Owner-requested development team: Rocko launches Claude Code with Fable; Filbert launches Pi with `openai-codex/gpt-6-astra:low`; Darkwing is the development team lead and Dewey remains frontend/UX owner. Five offline launcher tests and both new agents’ local configuration checks pass. No model session started; inspector acceptance queue unchanged.
|
||
|
||
- 2026-09-08 — Owner-requested Dewey frontend/UX agent: `agents/dewey/launch.sh` uses the shared native launcher with its own persona, context and session history. Offline launcher checks pass for both agents and real Dewey `--check` passes; no model session started. Current inspector acceptance queue unchanged.
|
||
|
||
- 2026-09-07 — Owner-directed concept annexation: [Mosaic concepts](../concepts/README.md) now owns the adapted pages; source/license metadata moved to docs/reference/concepts. Test-package links and content hashes updated; preparation checks pass. Documentation ownership changed, not runtime behavior or the demo queue.
|
||
|
||
- 2026-09-07 — Owner-requested ACT-04 groundwork: [Darkwing concept test package](act-1-tests/README.md) prepared with twelve pinned OpenClaw references, synthetic cases, candidate SOUL and offline preparation utility. Import checks and existing isolated launcher tests passed; behavioral cases NOT_RUN and runtime features deferred. Current demo queue unchanged.
|
||
|
||
- 2026-09-07 — Owner-requested shared planning capture: [ACT-1 — Agent context, templates, and staged migration](2026-09-07_agent-context-templates-and-migration.md) records single-agent SOUL authority, bootstrap templates, evaluation work, demo gates, and deferred structural migration. Runtime tasks remain unassigned; current demo queue unchanged.
|
||
|
||
- 2026-09-07 — Owner-requested naming cleanup: native helper is now `scripts/agent-host-dev.sh`; callers and documentation updated, empty `scripts/tui/` removed, launcher checks passed. Historical log paths retain their original names.
|
||
|
||
- 2026-09-07 — Owner-requested entry-point consolidation: `scripts/agent.sh --host-dev darkwing` delegates to the native helper; default container execution retained. Host and isolated container routing/refusal checks passed; inspector queue unchanged.
|
||
|
||
- 2026-09-07 — Owner-requested launcher follow-up: Darkwing's launch.sh now delegates to `scripts/tui/launch.sh darkwing`; existing session/context regression checks pass.
|
||
|
||
- 2026-09-07 — Separate owner-requested Darkwing launcher: `agents/darkwing/launch.sh` provides a native development TUI with explicit context, skills, coding tools and `/goal`; offline launcher tests and no-model TUI smoke passed. Inspector queue and approval gates unchanged; no commit/push.
|
||
|
||
Note (2026-09-03): this log was deduplicated after editor-session races
|
||
appended duplicate blocks. The dedup removed repeated lines only; every
|
||
distinct action appears exactly once, in completion order. Ground truth:
|
||
git history + Gitea issues.
|
||
|
||
- 2026-09-03 — POC: containerized pi hello-world (poc-container-hello-v0)
|
||
- 2026-09-03 — M1 configuration-driven hello world (#1–#4; config-hello-v1); hotfix #5 stdin detach
|
||
- 2026-09-03 — M2 mission/task abstraction (#6–#9; mission-task-v1); hotfix #14 release identity in task path
|
||
- 2026-09-03 — M3 release model + safe updates (#10–#13; release-model-v1); drills: update/refusal/rollback
|
||
- 2026-09-03 — M14 live user context layer (user/ dispatched to all launches; 0.0.9 built)
|
||
- 2026-09-03 — M15 agent seats: per-agent SOUL + role contracts (#36; agent-seats-v1); roles/ convention (root = bootstrap-only)
|
||
- 2026-09-03 — M13 interactive TUI agent + TOOLS.md (#35; interactive-agent-v1); release 0.0.8 activated
|
||
- 2026-09-03 — M12 conductor auto-apply policy (#34; auto-apply-v1); 17 conductor selftests
|
||
- 2026-09-03 — M11 session forking (#33; session-fork-v1); child recalls ancestor, base untouched
|
||
- 2026-09-03 — M10 run-record retention (#32; retention-v1); prune keep-N, dry-run default, receipt
|
||
- 2026-09-03 — M9 mission capability policy (#30; mission-policy-v1); least-privilege intersection
|
||
- 2026-09-03 — test UX: green OK/red FAIL status colors; NO_COLOR-aware
|
||
- 2026-09-03 — M10-era hotfix: retry lineage (#28) + AGENTS.md/SESSIONS.md recovery shim
|
||
- 2026-09-03 — release 0.0.10 packaged and health-gated activated (user context + agent seats live)
|
||
- 2026-09-03 — release 0.0.11 shipped (onboarding + live user context); ROADMAP.md agreed (M16–M19); CI deferred by owner
|
||
- 2026-09-03 — M16 release self-determination (#38; `release.sh ensure` at launch, drift warnings, recursion guard) — logged late: CURRENT.md had gone stale while M16/M17 shipped; ground truth = git history
|
||
- 2026-09-03 — M17 skill lifecycle + ms-* skill set completion (#40–#42; skill-lifecycle-v1); release 0.0.12 packaged, health-gated active — logged late, same staleness correction
|
||
- 2026-09-03 — conductor-loop calibration with live collaborator (#43): dispatch via agent-send.sh → receipt → line-by-line diff review → suite-gated integration; docs/TOOLS.md gains Tools (host-side) section + corrected suite counts
|
||
- 2026-09-03 — skill revisions adjudicated (#44): ms-communications integrated as-authored; ms-conductor redraft + conductor remediation (refusal vs outage); TOOLS.md release.sh ensure row
|
||
- 2026-09-03 — M18 seat-role progressive capability restriction (#45; roles resolve to contracts, ceiling ∩ seat grant, fail-closed refusals, roles/researcher.json); task suite 74 → 88
|
||
- 2026-09-03 — M18 follow-up: fail-closed seat resolution under MOSAIC_AGENTS_DIR override (#46, owner decision after live verification); task suite 88 → 90; next action M19
|
||
- 2026-09-03 — M19 harness auth tooling (#47; auth.sh status/accounts, agent.sh --auth per-launch injection via PI_AUTH_FILE, test-auth suite 13 cases with secret-never-printed assertions); agreed sequence M16–M19 complete, M20 owner-gated
|
||
- 2026-09-03 — M19 correction: auth ownership moved to the data root (#48, owner direction — the stack never writes to default harness config locations; ROADMAP standing decision); auth.sh config-driven, accounts at <dataRoot>/auth, 0600 enforced; test-auth 13 → 15
|
||
- 2026-09-03 — harness/provider/auth registry specification drafted (#49): agent.json harness declaration, central provider/account/settings registries, runtime seat selection, mechanical per-harness materialization, centralized OAuth refresh, Ollama endpoints, CLI contract; implementation blocked pending ten-gate review
|
||
- 2026-09-13 — Discord connector pilot for the Sage seat (#1509; QUEUE rows 14–15; brief `2026-09-13_discord-connector-pilot.md`): nine review rounds with rev-code-02, live pilot steps 1–8 with private receipts, Gate H passed (Jason: the replies read as Sage). Commits 786e379c, 788515dc (pushed). MVP iteration 1, eyes reaction as a read receipt, committed 93d6b624 (local); live check pending. Connector stays up in tmux `discord-sage`; binding and token live outside the repo.
|
||
- 2026-09-13 — Discord connector iteration 2 (#1509, QUEUE row 17): systemd user service `mosaic-discord@<binding>` with a supervised run that clears a dead lock and never retries a brake (exit 3). Sage seat now runs under systemd, not tmux. Next: control board row.
|
||
- 2026-09-13 — Discord connector iterations 4 and 5 (#1509, QUEUE rows 19–20): `reload` verb and `systemctl --user reload` apply channels, users, limits and guildName to the running connector, fixed keys refused, attempts journaled in `reloads.jsonl`; per-user channel allowlist; Carmen enrolled live by a reload at 00:03 UTC (all listed rooms except #sage-admin). Suite 41/41, 101 node tests. Commit caaef941 plus records. Row 18 (board row) is darkwing's by Jason's ruling.
|
||
- 2026-09-14 — Discord connector iteration 6 (#1509, QUEUE row 21): read-only tools through a Mosaic pi extension confined to declared roots (Jason's R1–R7: repo `docs/` and `agents/sage/`, every listed user including Carmen, 8 calls a message, 400 lines a read, 256 KiB a file, refusals said plainly, `tools` a fixed key). rev-code-02 approved round 2 (26276). Suite 41 → 48, node tests 101 → 116. Next: live check in #sage-admin, then attachments.
|
||
- 2026-09-16 — Discord Sage ops (#1509), Jason's word: every text channel of Shared Signals added in mention mode (#sage-admin stays open, Carmen's one-channel allowlist unchanged), and `/mnt/storage/src/shared-signals` added as a third read-only root. Threads had been silent because their parent #ideas was unlisted, not a code defect. Private binding only; check passed, service restarted; receipt in the Sage evidence dir. New channels created later need adding by reload.
|
||
- 2026-09-16 (coordinator, #1509 row 23): part 1 writes built: `write_file`/`edit_file` for roots marked `write: true`, temp file plus rename, same fences as reads plus parent-must-exist, no dot paths, no credential shapes; `enabledToolNames` drives `--tools`, the extension and the check line; suite 49/49. Pinned for rev-code-02 round 1 (tree in the #1509 comment). Live finding: after the prompt fix Sage still repeated "ruling Q16" and "two read-only folders" with zero tool calls, because pi resumed the session that held every earlier refusal; the old session file was archived to the sage evidence dir and the service restarted with a fresh session. Writes and web reach Sage only after row 23 lands in the binding.
|
||
- 2026-09-16 (coordinator, #1509 row 23): part 2 web built: `src/web.mjs` with `webFetch` (https only, public addresses only, connection pinned to the vetted address, three re-vetted redirects, 1 MiB cap, html to text) and `webSearch` (SearXNG json, ten results); enabled only when the binding `tools.web` key is set. The full-suite hang was a race in `tests/engine.test.mjs` (busy asserted before `agent_settled`, fake pi never stopped); the test now waits for the settle and stops in `finally`. Suite 52/52, node 128. Round 2 pinned for rev-code-02 (comment 26358, aggregate 287af5da, tree 1721584c). Next: verdict, local commit of my 17 paths only, then SearXNG container on 127.0.0.1:8888 and the live check.
|
||
- 2026-09-16 (coordinator, #1509 row 23): part 3 live: SearXNG container `mosaic-searxng` (image searxng/searxng:latest, settings in the data root, formats html and json, limiter off) on 127.0.0.1:8888; binding `tools.web` added (backup in the sage evidence dir); check ok; service restarted. Jason's first turn in #sage-admin searched, fetched who.is, listed the folder and wrote `vault/Businesses/naming.md`. Defect seen in the same exchange: his second message during the turn went to pi as a follow-up, pi folded it into the same run, the first answer was never posted and the second failed as settled-without-turn. Fixed in `engine-pi.mjs` (held prompts, one run each), fake pi now models real follow-up semantics, suite 52/52 node 129, round 3 pinned (comment 26361, aggregate e30c2319, tree dbd2ce9a), service restarted with the fix. Row 24 rulings: D5 seat identity with `[email protected]`, D6 push every commit (Jason: not pushing means stale data), D7 rev-code-02.
|
||
- 2026-09-18 (coordinator, #1509 rows 23–24): row 23 committed as 1685deb4 and pushed (`90cb31f5..1685deb4`) at Jason's word. Row 24 built: `src/git.mjs` (git_status, git_commit with explicit paths, seat author and `Requested-by:` trailer, push after every commit per D6, git_pull ff-only, git_push one branch; guard for branch, detached head, in-progress operations and conflicts; index must be empty so Jason's terminal work is never swept), `bin/git-credential.mjs` (the package's own helper: `get` over https from the 0600 token file, since `git-credential-mosaic` serves only the Gitea hosts and the global config routes github.com to Jason's `gh`), git children run with no host config; vault protocol (`protocol: "vault"`): per-write clone lock, `check` and `validate_vault.py` before a commit, `reserve_id`; the connector writes `requester="<server name>"` into the envelope and the extension reads it on `before_agent_start`. Suite 58/58, node 143. Review requested from rev-code-02; binding change and live check follow the verdict.
|
||
- 2026-09-20 (coordinator, #1509 row 25): part 2b built against shared-signals a5425a2. Eight fixed verbs for the model (record_list, record_get, record_create, record_update, resolve_id, open_approval_request, get_approval_request, create_document), the connector's own client for bind and add_approval, the envelope's author and message ids read by the extension for per-turn write keys. Button evidence per the SetSpark coordinator: the connector posts a confirmation line and submits its url and text; a reply is its own evidence. Sage's key is minted (id sage-3ff47150, file outside the repo, never read here). Suite 63/63, node 162. Review candidate frozen for rev-code-02 (aggregate 09140edc, tree 7872d8c5); Gitea answered 503 when the request was posted, so the post is queued and retried. Slip: a stray `git stash` during doc checks stashed the tree for under a minute; popped at once and verified, 44 files back, tests green.
|
||
|
||
- 2026-09-26 (sage, lead): Jason's ruling: Sage leads the project, Darkwing is a collaborating seat, more seats to follow, development stays in T3 for now. The fleet Sage seat that took Invoice Ninja coordination outside Jason's instructions is being decommissioned; moving work onto the new stack is the fix. Suites all green. Rows 24 and 25 pushed (1685deb4..43d7574d). Open: about 11 days of uncommitted agent work in the tree (row 16 launch files, row 22, #1512, WUI evidence), 23 untracked aws-* skill directories in skills/ from 2026-09-21, and Jason's target for the next phase.
|