Files
stack/packages/mosaic
Jason Woltje b648079fad
ci/woodpecker/pr/ci Pipeline was successful
docs(wake): bound the fd-9 lock claim at detector.sh:534 — refused for one interval, not forever
rev-974's round-3 CHANGES-REQUIRED (comment 20040) is correct. The sentence I
wrote to make the fix honest over-claimed in the opposite direction:

  "...and no replacement instance can ever acquire it."

That is false. The orphaned sleep holds the last copy of fd 9 only until it
exits, which is bounded by one poll interval (WAKE_DETECTOR_INTERVAL, default
30s at :510-513). After it exits the fd closes and the next start succeeds.
pepper's M3 measured exactly this boundary: refused, then granted.

Corrected to state the bound, and sharpened on one point rev-974 did not have
to spell out: the lock is taken with `flock -n` (:503), so a replacement is
REFUSED AND EXITS rather than queueing. The operational cost is therefore a
restart window in which every supervisor retry fails outright — which is a real
harm and a sufficient reason for the fix, without needing the false claim that
the lock is permanently unreclaimable. A justification that overstates the
failure it prevents invites the reader to discount the fix when they discover
the overstatement.

The neighbouring sentence — "`9>&-` closes ONLY the child's copy; the parent's
lock is unaffected" — was confirmed accurate by three instruments and is kept
VERBATIM.

MECHANICAL PROOF, comment-only (same instrument as the parent proof, so the
numbers are directly comparable):

  noncomment lines   397 -> 397          equal
  stripped sha256    d6ec8993 -> d6ec8993 IDENTICAL
  file lines         576 -> 582          +7/-1, all comment

The stripped SHA is the SAME VALUE recorded in the parent proof, so executable
content is unchanged not merely against the previous commit but against the
content already verified at da0cf001.

VERIFICATION: framework/tools/wake/test-wake-detector.sh rc=0, all 13 invariant
groups, including D4 "single-instance flock (2nd instance refuses)" — the
invariant the corrected wording describes.

NOTE ON THE VERDICT: this commit VOIDS rev-974's verdict at da0cf001 by the
standing verdict-at-head rule. Re-verdict required at the new head before merge;
I am not treating the prior mechanical proof as carrying forward.

Refs #993, #966
2026-07-31 07:39:50 -05:00
..

@mosaicstack/mosaic

CLI package for the Mosaic self-hosted AI agent platform.

Usage

mosaic wizard           # First-run setup wizard
mosaic gateway install  # Install the gateway daemon
mosaic config show      # View current configuration
mosaic config hooks list  # Manage Claude hooks

Headless / CI Installation

Set MOSAIC_ASSUME_YES=1 (or ensure stdin is not a TTY) to skip all interactive prompts. The following environment variables control the install:

Gateway configuration (mosaic gateway install)

Variable Default Required
MOSAIC_STORAGE_TIER local No
MOSAIC_GATEWAY_PORT 14242 No
MOSAIC_DATABASE_URL (none) Yes if tier=team
MOSAIC_VALKEY_URL (none) Yes if tier=team
MOSAIC_ANTHROPIC_API_KEY (none) No
MOSAIC_CORS_ORIGIN http://localhost:3000 No

Admin user bootstrap

Variable Default Required
MOSAIC_ADMIN_NAME (none) Yes (headless)
MOSAIC_ADMIN_EMAIL (none) Yes (headless)
MOSAIC_ADMIN_PASSWORD (none) Yes (headless)

MOSAIC_ADMIN_PASSWORD must be at least 8 characters. In headless mode a missing or too-short password causes a non-zero exit.

Example: Docker / CI install

export MOSAIC_ASSUME_YES=1
export MOSAIC_ADMIN_NAME="Admin"
export MOSAIC_ADMIN_EMAIL="[email protected]"
export MOSAIC_ADMIN_PASSWORD="securepass123"

mosaic gateway install

Runtime launchers

mosaic claude            # Launch Claude Code with Mosaic injection
mosaic yolo claude       # …with --dangerously-skip-permissions
mosaic codex | opencode | pi

mosaic claudex (EXPERIMENTAL)

Runs GPT models inside the Claude Code harness by pointing Claude Code at a local claude-code-proxy that translates the Anthropic Messages API to a ChatGPT-subscription (Codex OAuth) backend. This is not Anthropic Claude — model behavior, tool use, and output quality may differ. Intended for evaluation, not production delivery.

mosaic claudex           # launch (prompts through the proxy readiness gate)
mosaic yolo claudex      # …with --dangerously-skip-permissions
mosaic claudex --print "hello"   # trailing args are forwarded to Claude Code

Prerequisite: the claude-code-proxy binary must be installed and authenticated (claude-code-proxy codex auth …). mosaic claudex runs a preflight that verifies the binary, the OAuth state (triggering a device re-auth if needed), and a trusted local listener before launching; it fails closed if the proxy cannot be brought up with a verified identity.

Isolation (never touches your real Claude state). claudex always launches against an isolated CLAUDE_CONFIG_DIR (default ~/.config/mosaic/claudex/home). The ambient CLAUDE_CONFIG_DIR is deliberately ignored, and a guard proves the resolved dir can never be — or live under — the real ~/.claude. A claudex session therefore cannot mutate your normal Claude Code config.

No token leakage. claudex never reads the proxy's credential file. Claude Code is handed only ANTHROPIC_AUTH_TOKEN=unused pointed at the loopback proxy; the entire credential-bearing env family (ANTHROPIC_*, AWS_*, GOOGLE_CLOUD_*, GOOGLE_APPLICATION_CREDENTIALS, *_TOKEN, *_KEY, *_SECRET, …) is stripped from the composed environment. The Bedrock/Vertex routing switches (CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, and the _SKIP_*_AUTH pair) are force-removed regardless of value — otherwise their mere presence would route Claude Code to the real Anthropic API via AWS/GCP and bypass the proxy. The proxy holds the real OAuth credential.

Model tiers (override via env).

Tier Env var Default
primary (opus/sonnet) ANTHROPIC_MODEL gpt-5.6-sol
small/fast (haiku) ANTHROPIC_SMALL_FAST_MODEL gpt-5.6-luna

Operator-provided values win over the defaults. Additional overrides: MOSAIC_CLAUDEX_CONFIG_DIR (isolated config dir), ANTHROPIC_BASE_URL (proxy endpoint).

Hooks management

After running mosaic wizard, Claude hooks are installed in ~/.claude/hooks-config.json.

mosaic config hooks list              # Show all hooks and enabled/disabled status
mosaic config hooks disable PostToolUse  # Disable a hook (reversible)
mosaic config hooks enable PostToolUse   # Re-enable a disabled hook

Set CLAUDE_HOME to override the default ~/.claude directory.