First genuine gate-ready of the mission. Head triple equal at 78ec47cd, latest review
APPROVED at the current head, CI 9/9 by JSON scan with two-observer agreement.
Recorded the shape worth remembering: the queue guard is still inert for this merge
because RM-03 is the fix — the last merge to pass through the broken gate is the one
that fixes it.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
118 lines
7.9 KiB
Markdown
118 lines
7.9 KiB
Markdown
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
||
|
||
**Phase:** EXECUTING — RM-03 **GATE-READY**, merge-gate assigned, HELD for Jason. RM-02 CI in flight.
|
||
**Updated:** 2026-07-31 (mos-remediation orchestrator; seat active on `mosaic-fleet`).
|
||
|
||
## Head
|
||
|
||
- Mission charter + 15 decisions + 4-build plan: PERSISTED (`docs/remediation/MISSION.md`).
|
||
- HOLD lifted for this workstream (Jason 2026-07-31). Nothing implemented yet — planning first.
|
||
- Orchestrator seat `mos-remediation` is LIVE and owns the mission. Residency attestation: PASS.
|
||
- **TASK-0 DONE** — checkout repaired, all three gates green HONESTLY (no `--no-verify`), branch pushed.
|
||
- **TASK-1 DONE** — both planners delivered independently on clean context; reconciled into `TASKS.md`
|
||
(58 tasks across P0–P5, 7 convergences, 7 adjudicated disagreements, 3 escalated decisions).
|
||
- **NEXT ACTION IS NOT MINE:** DECISION-1/2/3 (`TASKS.md` §5) must be ruled before P0 dispatch.
|
||
RM-01 is dispatchable immediately regardless — it depends on nothing and blocks everything.
|
||
|
||
## In-flight
|
||
|
||
| Task | Owner | State |
|
||
| ------------------------------ | ------------- | ------------------------------------------------------------------------------------ |
|
||
| RM-01 reproducible checkout | — | **MERGED** `f58b3699` (#1027) |
|
||
| RM-03 queue guard | merge-gate | **GATE-READY** @ `78ec47cd` — rev-974 APPROVED (id 66) + CI 9/9 JSON; HELD for Jason |
|
||
| RM-02 gate registry ★keystone | f10-coder | masking blocker fixed @ `f9746b23`; CI #2187 running; **not** gate-ready |
|
||
| RM-61 terminal-green exemption | unassigned | ruled B; negative control FIRST, then adopt — or fall to A |
|
||
| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** |
|
||
| #1023 queue-guard attempt | Jason | SUPERSEDED-PENDING-JASON — RM-03 supersedes it |
|
||
|
||
**RM-03 gate-ready evidence** (each element observed, not relayed): head triple all equal at
|
||
`78ec47cd97bf0abc49334401f08c5b86e5be3a1a`; latest review **id 66 APPROVED at the current head** (id 64
|
||
`REQUEST_CHANGES` correctly superseded); `Closes #1019`; CI #2186 **9/9 JSON child-step scan**, confirmed
|
||
independently by two observers whose counts **agreed**. Reviewer attacked rather than read — real-failure
|
||
payload → exit 3 `ASSERTED_NOT_READY`, bypass re-attack rejected, 170 KiB payload rc0, both tri-state arms.
|
||
|
||
> ⚠ **The queue guard is still inert for this merge** — RM-03 _is_ the fix and is not merged. The gate
|
||
> records `queue-guard: ZERO-INFORMATION (inert, D-23, owner RM-03)`.
|
||
> **The last merge to pass through the broken gate is the one that fixes it.** After #1032 lands, that
|
||
> field becomes real evidence for the first time since it was written.
|
||
|
||
## Delivery gates — DOCTRINE CHANGE 2026-08-01
|
||
|
||
**The gate definition was incomplete from mission setup: the merge-gate verdict step was missing.**
|
||
Root cause (**D-26**): the gates were **restated from memory** into `MISSION.md`/`KICKSTART.md` instead of
|
||
**referenced**, and the omission propagated into every worker brief issued since. It then recurred _inside
|
||
the correction_ — which dropped five details including a security precondition and cited a file that does
|
||
not exist.
|
||
|
||
**Fix is render-not-restate, mechanically.** `MISSION.md` and `KICKSTART.md` now **reference**
|
||
`~/.config/mosaic/fleet/roles.local/merge-gate.md` and `~/.config/mosaic/fleet/roles/validator.md` and
|
||
state only the gate **order**:
|
||
|
||
> independent review (author ≠ reviewer) → remediation → **CI terminal-green at the exact head, full step
|
||
> scan** → **merge-gate verdict `GO`/`NO-GO`/`HOLD`** (commit-bound; **VOID on head move**; posted durably
|
||
> with enumerated evidence under its own minted identity) → **coordinator head-pinned merge**
|
||
|
||
- **After a `GO`, pushes freeze** — a doc tweak voids the verdict. Gate-ready is a **freeze point**.
|
||
- The coordinator assigns the gate seat; the orchestrator owns getting a PR _gate-ready_.
|
||
- **Queue guard is ZERO-INFORMATION until RM-03 lands** (D-23) — record it as
|
||
`queue-guard: ZERO-INFORMATION (inert, D-23, owner RM-03)`. _A mandated field must not become a
|
||
manufactured one._
|
||
- Gate seat identity: `gitea-mosaicstack-merge-gate` minted least-privilege, verified `push=False` —
|
||
it structurally cannot merge.
|
||
|
||
## Fleet seats
|
||
|
||
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
|
||
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
|
||
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
|
||
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
|
||
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
|
||
|
||
## Gate status
|
||
|
||
- Delivery gates active: author≠reviewer, diff-blind pre-registered checks, CI-green, merged-PR completion.
|
||
- Freeze: LIFTED for this workstream only.
|
||
- Git identity: `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
|
||
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
|
||
- Capability check (D-11b): before dispatching seat X to provider Y, verify
|
||
`~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token` exists. Token-file set = authoritative
|
||
capability registry. Mos owns provisioning; escalate missing pairs to him.
|
||
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
||
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
||
- Standing worker-brief doctrine (accreted, mandatory in every brief): don't weaken a RED test to make
|
||
it pass; if a check is unrunnable as written SAY SO, never silently substitute; `agent-send -f` never
|
||
`-m`; heavy artifacts off shared `/tmp`.
|
||
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
|
||
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
|
||
|
||
## Sequencing (from MISSION.md)
|
||
|
||
1. Spine + choke-point service (MACP wiring @ mosaic_orchestrator.py::run_single_task) + PG/Redis
|
||
⚠ **CONTESTED — see DECISION-1.** Both planners independently reject this wire-in point: that
|
||
controller is `"enabled": false` and references a dispatcher that does not exist here. Charter text
|
||
left UNCHANGED pending Mos/Jason ruling; do not treat it as settled.
|
||
2. Rotation daemon (finish Mission Control Plane, reuse packages/coord)
|
||
3. Comms service (envelope→service→PG/Redis→adapters)
|
||
4. Hygiene + conformance harness
|
||
Cross-cutting retirements: flat-file tracking, 3 MACP islands, silent MOSAIC BYPASS.
|
||
|
||
## Dogfood evidence — live failure classes, not hypotheticals
|
||
|
||
> Newest first. Oldest entries roll to `BOARD-LEDGER.md` via `board-roll.sh` when this file
|
||
> exceeds its 8 KB cap. Keystone detail is duplicated in `TASKS.md` §1a, so rolling loses nothing.
|
||
|
||
<!-- BOARD-ROLL:START -->
|
||
|
||
<!-- BOARD-ROLL:END -->
|
||
|
||
## Decisions log
|
||
|
||
- 2026-07-31 — Mission set up by Mos post-postmortem (15/15 decided). Dogfood posture active.
|
||
- 2026-07-31 — Mos: stale `.mosaic/orchestrator/mission.json` is RESIDUE of the disabled Python
|
||
orchestrator rail that this plan RETIRES. Do NOT invest in it; do NOT build on that rail. The 0/0
|
||
milestone banner is cosmetic. (Supersedes any plan to repair it.)
|
||
- 2026-07-31 — Mos: planners must be dispatched with GUARANTEED clean context, not requested-clean.
|
||
Prior default-socket planner sessions predate this mission; dirty context is the indicted hygiene.
|
||
- 2026-07-31 — mos-remediation: worker briefs forbid all git ops and restrict each worker to a single
|
||
named output file, so two planners can share one checkout without a branch race (M2-era incident doctrine).
|