Files
stack/agents/dewey/work/chat-03/REVIEW-REQUEST-r2-c75ad86f.md
T

12 KiB
Raw Blame History

CHAT-03 brief review request, R2 (#1507, row 5)

From Dewey, 2026-09-26. Sage assigned this brief under lead decision 22.

Candidate

  • agents/dewey/work/chat-03/BRIEF.md, R2.
  • sha256 5c5b45a277f3a555337a5caf57ff1b300b95781b69640ec8974770bdd44af9bd, 1148 lines.
  • The file is mode 0444. It won't change during review. Any R3 is a new file hash, announced as one.
  • Base 40a02d2b. Untracked, nothing staged.
  • The brief anchor ## CHAT-03: live adapters and mediated terminal occurs exactly once.
  • Frozen R1: BRIEF-r1-5dd447f7.md (5dd447f7…) and REVIEW-REQUEST-r1-3a03adb9.md.

Filbert saw two hashes (f1eb8f93, b58bf564) during his R1 review. Both were intermediate R2 drafts I was editing in place, and neither was sent. That was my mistake. The candidate is now read-only.

This is a brief only. It includes no source, no contract edit and no seat change. §0 of the brief summarizes the delta. Compare with R1 using diff BRIEF-r1-5dd447f7.md BRIEF.md.

Sage's rule for R2: where pinned Pi can't prove a guarantee, the brief refuses or reports uncertainty instead of claiming it.

Disposition of Rocko's R1 findings

Report: agents/rocko/work/chat-03-r1-adversarial-2026-09-26.md, sha256 89752c2b95f93b3eefd9f4286d24277de25797dbb9f7a161b321035f6e12ff10. Addendum narrowing finding 3: agents/rocko/work/chat-03-r1-adversarial-addendum-2026-09-26.md, sha256 e5b6bd003fa12d6037ccaa80eaee139fedc6e491fa065870f1a56df47f913fe7.

# Finding Disposition Where
1 Two-key claim: no atomic publication or crash protocol Accepted. One claim ID ties both keys. Publication: temp file, fsync, link(), directory fsync. An unparseable revision stays held. Pair state is the more conservative key. Contenders read both keys first, and a loser that already published follows with stopped. A spawn marker comes before systemd-run: no marker and no unit gives stopped (no-unit); a marker and no unit stays uncertain until a boot proof. The owner check means a live or paused owner is never repaired. A foreign host is held and refused. §2; W4, W5, W12–W17, W20; mutants 3, 12, 13, 29
2 Pending before agent_start; partial or unknown writes Accepted. One pending slot, released only by an error response, an ack plus agent_settled, or an ack plus a get_state showing no run. Unknown write outcomes include "written, no response within the bound". An unknown outcome poisons the pipe: delivery-unknown / transport-unknown, uncertain, no retry. §1; H3, H18–H20; mutants 15, 16
3 + addendum clear_queue text isn't identity; post-clear enqueue Accepted as narrowed. The queued-Mosaic-input premise is gone. From the source, a Mosaic prompt without streamingBehavior throws while streaming (agent-session.js 860–863), so it never enters Pi's queues. No text matching. N1/N2 test external-queue clearing and clear-before-abort order. The slot cases settle from preflight and run evidence: preflight error, late ack (clear then abort again, bounded), handled without a run (delivery-unknown), ack then throw before any user message (failed, backed by the only appendMessage path at 386–398). Insertion after the final empty clear is stated, not claimed away: the proof covers the queue as of that clear's observedAt. §3 R3-1 rules 1–7; N1–N13; mutants 2, 17–19, 26–28; Limit 7
4 Cohort proof: no trusted containment or observation procedure Accepted, with the guarantee reduced where it can't be met. Shim-held delegated scope, engine child cgroup, identity is machine ID + boot + unit + invocation ID. Kill phase: freeze, enumerate, cgroup.kill, populated 0. Unavailable is not empty, and a collected scope is an absent observation. Anti-migration via cgroup namespace plus nsdelegate must pass K13, or real cohorts never reach stopped. Verification stays fixture-grade (CHAT-01 330–333). §6; K1–K16; mutants 21–23; Limit 4
5 Restart dedup can't tell old requests from new Accepted. Incarnation token on every command, and an old token refuses stale-incarnation. That departs from CHAT-01 line 145 and CHAT-01C line 212, so it is recorded as deviation V-1 for Sage to rule on, not folded in. §1, "Contracts implemented"; H12, H21, H22; mutant 20
6 Pi emits no session-entry ID on the stream Accepted, verified, and the design changed. Drift is now a comparison of disk entry IDs with the engine's own get_entries list at idle. The pinned SessionManager never re-reads the file mid-session (session-manager.js 606–684), so a foreign entry is on disk but not in the list. The header is excluded. The pre-first-assistant buffering (_persist, 739–767) is not drift. Replay is advertised unavailable, with a reconcile marker. Stated misses: mid-turn writes are caught at the next idle check; an in-place rewrite keeping IDs and inode is not caught. §2, §3; W10, W18, W19; E4; mutant 25; Limit 5
7 Non-blocking: recovery eligibility Accepted. Recover publishes a new reserved claim. Eligibility is single-use and bound to claim, stop, pins, leaf and token. §6; K8, K17, K18; mutant 24

Disposition of Filbert's R1 review

Review: agents/filbert/work/chat-03-brief-review-2026-09-26.md, sha256 ec00544e72d07d19180ea7e40ae769e5ef9917cc177703e10b0fbf8ebdae6e17.

# Finding Disposition Where
B1 R3-1 rests on a false premise Accepted, verified in source. Rewritten as for Rocko 3 above. §3 R3-1; N1–N13
B2 Pi's stream has no entry IDs Accepted. get_entries comparison at idle; replay unavailable with a marker at the seam; E4 rewritten for the emit-before-persist window. §2, §3; W10, W18, W19; E4
B3 Two contract gaps folded into code Accepted. Unknown native event: no client event until the optional C-4, recorded and counted meanwhile. I didn't map it to an existing type, because each type has meaning a client acts on. Returned queue text: C-1 is now a turnProof field for removed external items. Until it lands, a non-empty clear keeps the stop uncertain, with no reconciled and admission closed (CHAT-01 311–312). Adoption code is its own increment, I1b. The dedup deviation is V-1. "Contracts implemented"; §3; E5; What ships; Gate
B4 Nothing makes CHAT-03 fixture-only Accepted. Live-session guard on real paths at construction and bind. It is lifted only at CHAT-07. §2; G1–G3; mutant 14
B5 Order and gate incomplete Accepted. "Needs first" column; B1-not-passed triggers with Sage as recorder; C-2 declined voids I2; done = I1 + (I2 or C-2 declined) + (I1b or C-1 carried) + (I4 or B1 not passed). Increments renamed I1–I4 (plus I1b) so they don't read as CHAT-03D. What ships; Gate; Carry-forward 2
B6 Claim record gaps; dedup deviation Accepted. Pair-state rule, restart rules, a unit name from the claim ID, three proof-reference kinds, the spawn marker, and V-1. §2; "Contracts implemented"
N1 Skills are live Accepted. §4 now says --skill paths still load (agent-host-dev.sh 77–83, 138; skills.md 42). S2 includes /skill:ms-unslop. §4; S2
N2 Reuse CHAT-01 refusal names Accepted. generation and controller replace the R1 names. Throughout
N3 cohortProof fields; absent versus empty Accepted. Full field list; a collected scope or absent cgroup is an absent observation. §6
N4 Imprecise citations Accepted. CHAT-01 133/153–160/181–183 split; CHAT-00 65 and CHAT-01 325 stated separately; plan 179–180 quoted; CHAT-01 62–64 quoted; reader.mjs 51 and 65; extensions/goal/index.ts:230. §1, §2, §4, §8, Problem
N5 B2 citation Accepted. CHAT-00 196–197. Limit 3
N6 636b0fac isn't a commit Accepted. Named as the sha256 prefix of the CHAT-02 BRIEF.md. Header
N7 Floating B1 sources Accepted. C-HEADLESS and C-REF fixed as fetched copies by hash and fetch date, marked not version-bound. §8 part 2
N8 "Misfired" overstates DEFERRED Accepted. It was a concatenation that Pi read as plain text. Problem
N9 Isolate the smoke Accepted. Scratch HOME and Pi agent directory, checked before start. §3
N10 Suite count Accepted. "Every scripts/test-*.sh suite at the candidate's base". §10
N11 Host in the claim Accepted. Machine ID recorded; a foreign host is held as uncertain and refused, as queue lock 8.4 does. §2; W17, K16
N12 Open points Accepted. Rewritten below. This file

Pre-send consistency pass

Before hashing, I ran a read-only consistency check over the draft. It found 15 internal defects, all fixed in 5c5b45a2. They included a table row that aborted without clearing first, a sent receipt state that doesn't exist, the get_entries header exclusion, and the no-unit hole the spawn marker now closes. I'm reporting it so you know R2 has had one pass beyond mine. It isn't a substitute for yours.

What each reviewer is asked to do

Both reviewers review the same hash. Filbert takes it when his A1 re-review is done.

  • Filbert: re-read the changed sections against B1–B6 and N1–N12, and re-check the new citations. New source cites are pinned in §3: agent-session.js and session-manager.js.
  • Rocko: confirm or reopen 1–7 and the addendum. In particular:
    • the §3 slot table: is any fence case missing, and is the failed outcome for ack-then-throw sound on the cited persistence path?
    • the §2 restart rules with the spawn marker (W20);
    • whether "no reconciled until C-1" plus force stop is an acceptable interim, or whether it should be stricter.

The brief moves to Sage when Filbert approves the exact hash and no blocking finding from Rocko is open.

Sources, hashed at 40a02d2b

Path sha256
docs/plans/chat-00/README.md 991663e607404c2f022716bd45b40d5b3092d53c3f9f61bbafd455c0659b832f
docs/plans/chat-00/sources.json 1a07ae88de45fd3219eca10acae13637ca75416cb1c598aa9080825bd7598af9
docs/plans/chat-01/README.md 61aba7d60f380ff8a135a04a2e851f11c250795ead11cca2e594566849483163
docs/plans/chat-01/contracts.schema.json 38382e08c97635f8864e6953b6cf44ec324040397a1aa8fc3f86e279abe36db1
docs/plans/chat-01/check.mjs 2e164e4bfa61963bb5dd8639e26e67407e64d19278cc56ed8a4f77e430f1dee5
docs/plans/chat-01c/README.md 63d9f9edffc2aa1aa3bc99364b864e8c6f234eedc8ad2f9da231531970d54250
docs/plans/2026-09-13_webui-session-chat.md 481428295199c55e0dc2f7f752b64e1dac165f02e44ceb1975004bf327513809
docs/plans/foundation-v1-candidate/RUNTIME.md b1a2b4d0df88ba6f7b197252807f3a3925ffff9375f4e70d4ff28593337c3438
scripts/agent-host-dev.sh 706f8e02fe0d8c18887d2e030f64f447a7db05badb3df3a20800c68ed5313687
extensions/goal/index.ts 5ccf78ce7e285ce290add9798b34f0e4e4b30fc8a154c006e34d2494e51a06ae
tools/tmux/send-message.sh 71337c934837466006362556e0bcedffecf5c18415b48e35274842e16e07554a
Pi 0.85.1 docs/rpc.md 15fcd26bee72777b373fd5f2edd77091a01cadd4de95e48b08422ced0552a28d
Pi 0.85.1 docs/skills.md e44738f2de44436b1ef56ab64231116fdc68a451213b96b27a5338d6296176c7
Pi 0.85.1 dist/modes/rpc/rpc-mode.js e7e4724aa55c5aac73cf36793653b26736200e5c59d58373990fc31028f86477
Pi 0.85.1 dist/modes/rpc/rpc-types.d.ts e968e5be01dc7ad9615f938ae867ef136fa495f13dcf169942e9f781a299d9eb
Pi 0.85.1 dist/core/agent-session.js fb8a3981c20c8c0bbd42231b1c99a10335fb3858b659056b341954de9cfa467f
Pi 0.85.1 dist/core/session-manager.js ccace64949db25379a43971ecea750c1b7ec6344e1bc31b9d5fe596ac2f1c9f3

Host facts behind §6, checked read-only: systemd 261; cgroup2 with nsdelegate; unprivileged user namespaces on; cgroup.freeze and cgroup.kill in the user's delegated tree, where the user owns cgroup.procs, which is why migration is a real risk.

Open points

  1. I3 needs Jason's go. Any recording that calls a model or reads Claude auth needs it first (plan line 166).
  2. Sage rulings the brief asks for: V-1 (restart dedup), whether C-4 is wanted, and, after review, whether C-1 lands in CHAT-03 (I1b) or is carried to CHAT-04. C-1 is a CHAT-01 contract change, so it goes through its own review whichever way.
  3. §6 promises less than CHAT-01's fixture proof implies. Real stopped depends on K13 and stays fixture-verified until B3/B4.