Files
stack/docs/remediation/BOARD.md
T
mos-dt-0andClaude Opus 5 52114dd4eb docs(remediation): bank D-44 — the anti-inert-gate registry was inert-able four distinct ways
rev-974 NO-GO at 83d2ecb2. A4/A5/A6 confirmed and three further blockers found, two of them outside my
registered set. Each is a silent-defeat path of the registry itself: the activation seam inerts the
history audit (seam=HEAD gives 0 prospective commits and no failures — and HEAD's parent and the
introduction commit also pass, so forbidding equality with HEAD does not close it); a misspelled
outputPattern silently reduces an assertion to exit-code-only because the closed schema is not
recursive; two provider records sharing pipeline number 7 certify two different commits; and the D-38
and D-40 criteria are absent, with blocker 4 a live instance of the very D-38 clause that is missing.

The headline: all four passed CI, passed the canonical gate:verify, and passed 38/38 focused tests.
Greens discharged nothing. My own AC set was incomplete too — A3 corrects the prospective range to
eight commits, not the seven I wrote; I omitted the seam commit itself.

Mos ruled ALL FOUR in this PR, no trim, and sizing does not help: a registry that ships with a known
way to be silently defeated IS the inert gate it exists to detect. There is no core registry that is
integrity-complete without these — they are not hardening on top of the deliverable, they are the
deliverable. Theme: the registry's own checks must not be silently defeatable. Each fix carries a
red-first must-fail control proving the specific defeat is now caught, and that control set IS the
D-38/D-40 coverage work rather than being additive to it.

Blocker 1's fix keeps the value and replaces the mechanism: derive the seam from non-author-controlled
history (parent of the first first-parent commit introducing gates/gates.manifest.json) rather than
asserting it in an author-editable field, plus must-fail controls for HEAD, HEAD's parent, and the
introduction commit. If the work balloons past reviewability the only acceptable split is by
integrity-complete stage, never by deferring a blocker.

Method note banked as a positive: I could not reproduce "full verifier exit 0", traced my first attempt
to my own instrumentation artifact (json.dump reformatting the manifest), and stated the divergence
rather than wielding non-reproduction as a refutation. The vacuity itself reproduced and blocker 3 was
confirmed by construction. Non-reproduction is not refutation. Open thread: why my gate:verify exits 1
on checkout-preflight with outcome 42.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 10:49:42 -05:00

7.7 KiB
Raw Blame History

mos-remediation — LIVE BOARD (keep < 8 KB)

Phase: EXECUTING — RM-03 at owner-merge; RM-61 MERGED; RM-02 keystone is the front. Updated: 2026-08-01 — seam crossed; successor seat resumed, attested from the files, and is driving. ⚠ That was a MANUAL pane respawn (prior seat ~803k tokens): it validates the checkpoint+rehydration design, NOT a lifecycle mechanism — P-LIFECYCLE rotation does not exist yet (D-41 / RM-62).

Head

  • Charter + 15 decisions + 4-build plan: MISSION.md. Backlog + all findings: TASKS.md.
  • Planning DONE (58 tasks, P0P5). DECISION-1/2/3 all RULED by Mos 2026-07-31 (TASKS.md §5) — nothing is waiting on a decision. D-2's availability target is Jason-pending and non-blocking.
  • Executing, not planning. RM-01 is MERGED; three lanes are live (see In-flight).
  • Orchestrator seat mos-remediation LIVE, owns the mission, resumed across the rotation seam 2026-08-01 and re-attested to Mos from the files. Residency attestation: PASS.

In-flight

Task Owner State
RM-01 checkout MERGED f58b3699 (#1027)
RM-03 queue guard Jason GO @ 78ec47cd (cmt 20392) — HELD FOR OWNER MERGE. Head unmoved; GO commit-bound, VOID if it moves — do not push #1032
RM-02 registry ★key f10-coder NO-GO @ 83d2ecb2 — FOUR silent-defeat paths (D-44). A4/A5/A6 confirmed. ALL FOUR in this PR, no trim (Mos): a registry with a known silent defeat IS the inert gate. Remediating, red-first
RM-61 CI exemption MERGED f4fd5967 (#1033). #1034 closed; #1000 stays OPEN (retirement trigger). Exemption is on main
RM-59 / RM-60 Jason (infra) tracked deps; RM-60 option B
#1023 queue attempt Jason SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do not merge

For the incoming orchestrator — read this before acting

  1. RM-02 is the front — NO-GO at 83d2ecb2, remediating four silent-defeat paths (D-44). RM-03 waits on Jason; RM-61 MERGED. ⚠ Re-derive any board claim from the provider before load-bearing use (D-43).
  2. docs/remediation/TASKS.md is authoritative, not the newest voice in a chat. It holds 45 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-44 + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
  3. MISSION.md carries five first-class principles, all earned by live failures — observe the property not the proxy · pre-registration prevents retrofitting and nothing else · never ship an integrity claim dressed as a property · when a property cannot exist at its layer, bound it and track the real guarantee · query for refutation, never for confirmation · redundant observation on evidence-bearing steps.
  4. Seat identity: export MOSAIC_GIT_IDENTITY=<seat> is stripped by a context reset (D-34) — every dispatch/rehydration brief must re-export it, or the seat cannot use its credentials.
  5. Scan CI from -f json, never default text — text mode omits clone (D-33). State counts.
  6. The queue guard is zero-information until RM-03 merges (D-23) — never cite its green.
  7. The bounded CI re-roll used on RM-02 was a one-time stopgap, NOT policy. A per-PR free re-roll is D-21 normalisation. Do not repeat it; RM-61 is the fix.

Delivery gates — REFERENCE, do not restate

Canonical: ~/.config/mosaic/fleet/roles.local/merge-gate.md (verdict authority) + ~/.config/mosaic/fleet/roles/validator.md. Order and the freeze/zero-information rules: MISSION.md and KICKSTART.md. Read them there — restating the gate from memory is how the merge-gate step went missing from mission setup twice, once inside the correction for it (D-26).

Fleet seats

  • mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket mosaic-fleet) — ACTIVE
  • planner-opus — adversarial planner (robustness), Opus 5, socket default — DELIVERED, idle
  • planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket default — DELIVERED, idle
  • rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
  • Mos (mos-claude) — lead coordinator, socket default — relay path to Jason

Gate status

  • Freeze: LIFTED for this workstream only.
  • Git identity: orchestrator runs MOSAIC_GIT_IDENTITY=mos-dt-0 INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
  • Capability is per-path (D-11b → superseded in part by D-13/D-15): a token file is necessary, not sufficient. Three layers — token file (raw-API), tea login (tea paths), repository permission (writes). Before dispatch, assert permissions.push == true as that seat, not token existence and not a 200 on a read. Mos owns provisioning; escalate missing pairs.
  • Seat identity (D-11a): token identity AND git config user.name/user.email must BOTH be set and agree. Exporting MOSAIC_GIT_IDENTITY alone does NOT fix commit authorship.
  • LIVE HAZARD (D-37) — one shared .git/config re-identifies EVERY worktree at once. Every seat, including rev-974's review worktree, currently authors as coder-mos1; MOSAIC_GIT_IDENTITY does not override it. STANDING ORDER: commit with explicit git -c user.name=<seat> -c user.email=<seat>@…, and NOBODY rewrites the shared config mid-flight. Real fix authorised, Mos owns it, sequenced at a quiet seam. #1024 implicated. Detail: D-37.
  • Standing worker-brief doctrine (mandatory in EVERY brief): re-export MOSAIC_GIT_IDENTITY (D-34); commit early/WIP (D-31); don't weaken a RED test to pass; if a check is unrunnable SAY SO, never substitute; agent-send -f never -m; artifacts off shared /tmp; scan CI from -f json (D-33); relay observations into an open review, NEVER your own conclusion on an open check (D-39); the author never adjudicates their own PR's blocker status — surface evidence, prepare the fix, hold.
  • Remote control: native /remote-control NOT wired in this runtime. Path is Mos-relay (Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.

Decisions log — full record in TASKS.md

All 45 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-44 + D-38c in TASKS.md) and every ruling with its rationale live there. Not duplicated here. The history of why this board must not restate — six stale copies across two seams — is rolled verbatim into BOARD-LEDGER.md.