Files
stack/docs/remediation/BOARD.md
T
mos-dt-0andClaude Opus 5 eddf718a5c docs(remediation): board — RM-02 frozen at 38f1b249 with a fully clean 9/9 scan
First run on this branch where ci-postgres passed, so no exemption question arises.
Recorded that the artifact's intermittency is evidence FOR RM-61's negative-control
requirement: intermittent means delivery is a coin flip until the signature is proven to
discriminate from a real database failure.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 00:35:51 -05:00

7.5 KiB
Raw Blame History

mos-remediation — LIVE BOARD (keep < 8 KB)

Phase: EXECUTING — RM-02 FROZEN @ 38f1b249 (CI 9/9 clean, review in flight); RM-03 fixing 1 blocker. Updated: 2026-07-31 (mos-remediation orchestrator; seat active on mosaic-fleet).

Head

  • Mission charter + 15 decisions + 4-build plan: PERSISTED (docs/remediation/MISSION.md).
  • HOLD lifted for this workstream (Jason 2026-07-31). Nothing implemented yet — planning first.
  • Orchestrator seat mos-remediation is LIVE and owns the mission. Residency attestation: PASS.
  • TASK-0 DONE — checkout repaired, all three gates green HONESTLY (no --no-verify), branch pushed.
  • TASK-1 DONE — both planners delivered independently on clean context; reconciled into TASKS.md (58 tasks across P0P5, 7 convergences, 7 adjudicated disagreements, 3 escalated decisions).
  • NEXT ACTION IS NOT MINE: DECISION-1/2/3 (TASKS.md §5) must be ruled before P0 dispatch. RM-01 is dispatchable immediately regardless — it depends on nothing and blocks everything.

In-flight

Task Owner State
RM-01 reproducible checkout MERGED f58b3699 (#1027)
RM-02 gate registry ★keystone rev-974 FROZEN @ 38f1b249; CI #2184 9/9 ALL OK; 3rd review, reset context
RM-03 queue guard coder-mos1 PR #1032 @ 44ffa99a; 1 blocker — --skip-queue-guard (D-32)
RM-61 terminal-green exemption unassigned ruled B; negative control first, then adopt — or fall to A
RM-59 / RM-60 Jason (infra) tracked deps; RM-60 option B
#1023 queue-guard attempt Jason SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES

RM-02 head-triple verified twice independently (orchestrator + f10-coder): local = origin = PR #1030 = pipeline #2184 = 38f1b249ccf8…. First fully clean scan on this branchci-postgres OK, so no exemption question arises here. That the artifact appears on some runs and not others is evidence for RM-61's negative-control requirement, not against it: intermittent means delivery is a coin flip until the signature is proven to discriminate.

Delivery gates — DOCTRINE CHANGE 2026-08-01

The gate definition was incomplete from mission setup: the merge-gate verdict step was missing. Root cause (D-26): the gates were restated from memory into MISSION.md/KICKSTART.md instead of referenced, and the omission propagated into every worker brief issued since. It then recurred inside the correction — which dropped five details including a security precondition and cited a file that does not exist.

Fix is render-not-restate, mechanically. MISSION.md and KICKSTART.md now reference ~/.config/mosaic/fleet/roles.local/merge-gate.md and ~/.config/mosaic/fleet/roles/validator.md and state only the gate order:

independent review (author ≠ reviewer) → remediation → CI terminal-green at the exact head, full step scanmerge-gate verdict GO/NO-GO/HOLD (commit-bound; VOID on head move; posted durably with enumerated evidence under its own minted identity) → coordinator head-pinned merge

  • After a GO, pushes freeze — a doc tweak voids the verdict. Gate-ready is a freeze point.
  • The coordinator assigns the gate seat; the orchestrator owns getting a PR gate-ready.
  • Queue guard is ZERO-INFORMATION until RM-03 lands (D-23) — record it as queue-guard: ZERO-INFORMATION (inert, D-23, owner RM-03). A mandated field must not become a manufactured one.
  • Gate seat identity: gitea-mosaicstack-merge-gate minted least-privilege, verified push=False — it structurally cannot merge.

Fleet seats

  • mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket mosaic-fleet) — ACTIVE
  • planner-opus — adversarial planner (robustness), Opus 5, socket default — DELIVERED, idle
  • planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket default — DELIVERED, idle
  • rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
  • Mos (mos-claude) — lead coordinator, socket default — relay path to Jason

Gate status

  • Delivery gates active: author≠reviewer, diff-blind pre-registered checks, CI-green, merged-PR completion.
  • Freeze: LIFTED for this workstream only.
  • Git identity: MOSAIC_GIT_IDENTITY=mos-dt-0 INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
  • Capability check (D-11b): before dispatching seat X to provider Y, verify ~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token exists. Token-file set = authoritative capability registry. Mos owns provisioning; escalate missing pairs to him.
  • Seat identity (D-11a): token identity AND git config user.name/user.email must BOTH be set and agree. Exporting MOSAIC_GIT_IDENTITY alone does NOT fix commit authorship.
  • Standing worker-brief doctrine (accreted, mandatory in every brief): don't weaken a RED test to make it pass; if a check is unrunnable as written SAY SO, never silently substitute; agent-send -f never -m; heavy artifacts off shared /tmp.
  • Remote control: native /remote-control NOT wired in this runtime. Path is Mos-relay (Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.

Sequencing (from MISSION.md)

  1. Spine + choke-point service (MACP wiring @ mosaic_orchestrator.py::run_single_task) + PG/Redis ⚠ CONTESTED — see DECISION-1. Both planners independently reject this wire-in point: that controller is "enabled": false and references a dispatcher that does not exist here. Charter text left UNCHANGED pending Mos/Jason ruling; do not treat it as settled.
  2. Rotation daemon (finish Mission Control Plane, reuse packages/coord)
  3. Comms service (envelope→service→PG/Redis→adapters)
  4. Hygiene + conformance harness Cross-cutting retirements: flat-file tracking, 3 MACP islands, silent MOSAIC BYPASS.

Dogfood evidence — live failure classes, not hypotheticals

Newest first. Oldest entries roll to BOARD-LEDGER.md via board-roll.sh when this file exceeds its 8 KB cap. Keystone detail is duplicated in TASKS.md §1a, so rolling loses nothing.

Decisions log

  • 2026-07-31 — Mission set up by Mos post-postmortem (15/15 decided). Dogfood posture active.
  • 2026-07-31 — Mos: stale .mosaic/orchestrator/mission.json is RESIDUE of the disabled Python orchestrator rail that this plan RETIRES. Do NOT invest in it; do NOT build on that rail. The 0/0 milestone banner is cosmetic. (Supersedes any plan to repair it.)
  • 2026-07-31 — Mos: planners must be dispatched with GUARANTEED clean context, not requested-clean. Prior default-socket planner sessions predate this mission; dirty context is the indicted hygiene.
  • 2026-07-31 — mos-remediation: worker briefs forbid all git ops and restrict each worker to a single named output file, so two planners can share one checkout without a branch race (M2-era incident doctrine).