TASK-1 complete. planner-opus (robustness, 38 tasks/8 dissents) and planner-sol (pragmatic, 25 tasks/10 defers/7 dissents) each decomposed the 4-build plan without seeing the other's work. Both decomps are committed alongside the reconciliation so the disagreements stay auditable rather than being flattened into a consensus. Reconciled into 58 tasks across P0-P5 (docs/remediation/TASKS.md): - 7 independent convergences, treated as settled because neither planner could see the other. The headline: BOTH reject the charter's wire-in point (mosaic_orchestrator.py::run_single_task) because that controller is disabled and references a dispatcher absent from this checkout — wiring it would produce a stranded executor, the same built-but-unwired disease one layer up. - 7 genuine disagreements ADJUDICATED, not averaged. The cost estimates are ~18x apart; rather than split the difference, the plan adopts sol's scope with opus's rigor and treats the first-dogfood gate as a hard budget checkpoint. - 3 decisions escalated (wire-in point, rollback artifact + availability trade, queue-guard ownership vs parked PR #1023). No task blocked on them is dispatched. Keystone dogfood case recorded (TASKS.md 1a): merged PR #868 shipped a file failing pnpm format:check, then an unrelated PR reformatted it as a side effect, so main went green and the gate's failure to fire left no trace. Detection must therefore be per-merge-commit against that commit's own tree. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
30 KiB
Adversarial Decomposition — Pragmatic / Shortest-Path Side
Planner: planner-sol
Bias: make one real fleet task pass through one enforced path as early as possible; reuse before building.
Scope source: MISSION.md, MACP-WIRING-SCOUT.md, BOARD.md, existing @mosaicstack/macp, packages/coord, PG/Valkey, Tess durable inbox/outbox, and the Mission Control PRD.
Executive position
The first useful milestone is not “complete Builds 1 and 2.” It is this narrow vertical slice:
A DB-backed mission task is atomically claimed by
packages/coord, executed by one Node@mosaicstack/macpTaskExecutor, gated, and terminally recorded with identity-bound events and a tri-state mutation result. Nodocs/TASKS.md,mission.json,tasks.json, Python gate loop, or NDJSON ledger participates.
That slice is SOL-03 → SOL-04 → SOL-05 → SOL-06 → SOL-07 → SOL-08, estimated at 72K tokens, mostly Codex. PG polling is acceptable for this first proof. Redis acceleration follows only after correctness is observable. This is the shortest path that is both dogfoodable and not throwaway work.
Cost posture
- 25 PR tasks, ~294K tokens total: ~164K Codex, ~130K Sonnet, 0K Opus.
- First live choke-point dogfood: ~72K on the hard path; SOL-01 and SOL-02 can run beside it.
- Opus is not justified for planned implementation. Escalate only if an independent security review finds an unresolved architecture-level authority flaw.
- Every row is one PR. Estimates include implementation, focused tests, docs affected by that PR, and one remediation pass—not orchestration/reviewer overhead.
Gates and critical path
| gate | opens when | proof required before downstream work |
|---|---|---|
| G0 — trustworthy launch gates | SOL-01, SOL-02 | non-root checkout works; queue status cannot become false-green |
| G1 — first dogfood / minimum viable cut | SOL-08 | one live fleet task completes DB → MACP executor → gates → DB with no flat-file state |
| G2 — Builds 1+2 closed | SOL-09..SOL-12 | all producers use the executor; duplicate islands retired; Redis loss is recoverable from PG |
| G3 — rotation real | SOL-13..SOL-16 | stale generation cannot mutate; fresh session resumes typed state; Pi-brick recovery works without broker |
| G4 — sole-path comms real | SOL-17..SOL-22 | roster identity is stable; bounced/stale messages converge through PG/Redis and adapters |
| G5 — mission proof | SOL-23..SOL-25 | workflow sweep cannot capture unknown files; fault bank passes, including 100 rotations |
Critical path: 03 → 04 → 05 → 06 → 08 → 10 → 12 → 13 → 14 → 15 → 16 → 17 → 18 → 19 → 20 → 21 → 22 → 24 → 25.
Ordered task list
SOL-01 — Repair activation coherence and non-root checkout hygiene
- build: 5 (hygiene; pulled forward)
- depends_on: —
- acceptance criteria (diff-blind testable):
- A clean non-root checkout can run dependency/bootstrap preparation without accessing
/root. - A root CI checkout still uses an isolated writable pnpm store.
- Activation installs CLI, hooks, broker/runtime assets, and version manifest transactionally: induced failure leaves the prior complete generation active.
- Launch with a deliberately skewed component version is rejected with the exact repair command; diagnostics remain usable.
- No test uses
--no-verifyor suppresses hooks.
- A clean non-root checkout can run dependency/bootstrap preparation without accessing
- dogfood seed: BOARD D-1 root-pinned
.npmrcand D-2 root-owned Husky path. - est. tokens: 6K
- suggested runtime tier: codex
SOL-02 — Make queue guard fail-safe with exit-asserting tests
- build: 1
- depends_on: —
- acceptance criteria (diff-blind testable):
- Fixture responses
pending,success,failure, no-status, malformed JSON, provider error, and unknown status produce explicitly asserted process exits. - Only terminal success/no-active-queue returns 0; unknown, malformed, and transport failure return non-zero with actionable output.
- A payload larger than 150 KiB is consumed without argv expansion or truncation.
- At least one mutant changes unknown→success and is killed by the test suite.
- Fixture responses
- dogfood seed: inert gate-6 and recursive #1019 failure (unknown→exit 0; ARG_MAX).
- est. tokens: 8K
- suggested runtime tier: codex
SOL-03 — Complete the canonical MACP contract, not another protocol
- build: 1
- depends_on: —
- acceptance criteria (diff-blind testable):
@mosaicstack/macpvalidates typed Task, TaskResult, lifecycle Event, state Claim, andverified | written-unverified | failedmutation outcome records.- Claims require source, confidence, issued-at, TTL/expiry, refresh instruction, and HMAC integrity; tamper/expiry returns a typed refusal, never partial data.
- Lifecycle events include launch, mission generation, checkpoint, rotation, recovery, inbox receipt, and terminal disposition while preserving existing task events.
MOSAIC_AGENT_NAMEis required for mutating execution and appears in credential/actor binding; missing identity fails closed.- Target metadata requires repository identity, task/record ID, and head or generation where applicable.
- dogfood seed: rev-974 identity drift plus the three observed write outcomes.
- est. tokens: 8K
- suggested runtime tier: codex
SOL-04 — Add the narrow PG orchestration spine schema
- build: 2
- depends_on: SOL-03
- acceptance criteria (diff-blind testable):
- Migration up creates mission, task, dependency, task-claim, MACP event, typed state-claim, session-generation, and dispatch-outbox records with tenant/mission keys and uniqueness constraints.
- The database rejects a task without a mission, a dependency outside its mission, duplicate idempotency keys, and terminal→running regression.
- Event and claim records reference canonical mission/task/generation identities; claims store integrity metadata.
- Migration rollback on an empty test DB succeeds; rerunning migration is safe.
- No comms-specific “universal message” schema is invented here; Build 4 reuses/extends existing interaction inbox/outbox tables.
- dogfood seed: mission convention existed but a lane could act with no mechanically valid mission/task.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-05 — Implement atomic PG task claims, transitions, ledger, and outbox
- build: 2
- depends_on: SOL-04
- acceptance criteria (diff-blind testable):
- Two concurrent claimers for one runnable task yield exactly one lease owner.
- Dependencies are evaluated transactionally; an unmet dependency can never be claimed.
- Claim, state transition, MACP event, and dispatch-outbox append commit atomically or all roll back.
- Expired leases are reclaimable with a higher fencing generation; stale owners cannot complete or mutate.
- Querying mission status is derived solely from PG and returns the next runnable task deterministically.
- dogfood seed: model-maintained live board and stale claims surviving session changes.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-06 — Build the one production Node MACP TaskExecutor
- build: 1
- depends_on: SOL-03, SOL-05
- acceptance criteria (diff-blind testable):
- A public Node executor accepts only a claimed canonical MACP Task, resolves credentials/identity, runs the worker, runs structured gates, and persists terminal result/events through SOL-05.
- Worker exit 0 plus a failed gate cannot produce
completed; worker failure cannot skip terminal ledger emission. - Claude, Codex, and Pi fixture backends emit the same runtime-neutral lifecycle sequence.
- Every mutation returns one mandatory tri-state outcome; callers cannot compile while discarding it.
- Crash after worker success but before terminal commit leaves a recoverable fenced claim and no false completion.
- dogfood seed: stranded MACP, gate-6 inert completion, and
written-unverifiedbeing treated as success. - est. tokens: 16K
- suggested runtime tier: sonnet
SOL-07 — Provide one-shot flat-file import and cutover readiness audit
- build: 2
- depends_on: SOL-05
- acceptance criteria (diff-blind testable):
- A dry-run parses existing mission/TASKS artifacts, reports unsupported/ambiguous rows, and performs zero writes.
- Apply is idempotent and records source digests; repeated apply creates no duplicates.
- Unknown status, dangling dependency, duplicate task ID, and malformed table block import with row-level diagnostics.
- Readiness reports “cutover-ready” only when imported PG projections exactly match source counts/dependencies/statuses.
- This command is migration-only; it exposes no dual-write or ongoing sync mode.
- dogfood seed: current remediation board/TASKS state needs a clean DB landing without silently losing tasks.
- est. tokens: 8K
- suggested runtime tier: codex
SOL-08 — Hard-cut packages/coord to PG and dogfood one live task
- build: 1
- depends_on: SOL-06, SOL-07
- acceptance criteria (diff-blind testable):
mosaic coord run/status/continuereads and mutates PG only; absent/unmigrated DB state fails with the SOL-07 repair path.- No fallback reads/writes
docs/TASKS.md, mission JSON, task JSON, state JSON, results JSON, or events NDJSON. - A live canary task assigned to a fleet seat travels PG claim → TaskExecutor → worker → gate → terminal PG result/event and closes only after gate success.
- Killing the coordinator after claim and restarting it neither duplicates execution nor allows the stale lease to close the task.
- Evidence query shows actor seat, mission/task, target metadata, gate results, and tri-state outcome.
- dogfood seed: this remediation mission itself; reproduce a gate-6-style non-null task and identity-bound write.
- est. tokens: 16K
- suggested runtime tier: sonnet
G1 FIRST-DOGFOOD: stop and validate here before broadening. If SOL-08 cannot carry a real task, do not build Redis, rotation, comms, or UI.
SOL-09 — Route Forge and OpenClaw/MACP producers through TaskExecutor
- build: 1
- depends_on: SOL-08
- acceptance criteria (diff-blind testable):
- Forge and the OpenClaw MACP runtime submit the canonical Task type to SOL-06; neither executes a worker or gate itself.
- Their success callbacks are derived from canonical terminal results, not local/stub completion.
- A failed canonical gate is observed identically from Coord, Forge, and OpenClaw fixtures.
- Repository search plus an executable import boundary test finds no production-local redefinition of Task/TaskResult/GateResult on these paths.
- dogfood seed: Forge’s immediate empty-gate completion and the plugin’s redefined MACP-shaped result.
- est. tokens: 10K
- suggested runtime tier: codex
SOL-10 — Retire flat-file orchestration and the disabled duplicate rail
- build: 1
- depends_on: SOL-09
- acceptance criteria (diff-blind testable):
- The Python controller execution/gate/event path,
tasks_md_sync, plugin-local protocol types, orphaned context loader, and production flat-file orchestration writers/readers are absent from shipped assets. - Framework guides/templates/startup context point to DB mission commands, not
docs/TASKS.mdas orchestration SoR. - A regression scan fails CI if production code reintroduces
events.ndjson,tasks.json,mission.json, ordocs/TASKS.mdorchestration mutation. - jarvis-brain PDA flat files and unrelated project docs remain untouched.
- Upgrade removes/quarantines obsolete generated rail files without deleting user source/docs.
- The Python controller execution/gate/event path,
- dogfood seed: three parallel islands and stale
.mosaic/orchestrator/mission.json0/0 residue. - est. tokens: 14K
- suggested runtime tier: sonnet
SOL-11 — Add Redis hot dispatch as a derived outbox consumer
- build: 2
- depends_on: SOL-08
- acceptance criteria (diff-blind testable):
- Task creation commits mission/task/outbox in PG before any Redis enqueue.
- Induced Redis failure leaves the task durable and pending; a sweeper later enqueues it exactly once logically.
- Deleting the Redis queue and rebuilding from PG restores all non-terminal dispatches without reviving terminal tasks.
- Duplicate delivery is neutralized by PG claim fencing/idempotency.
- Existing
packages/queueadapter/config is reused; no second broker API is introduced.
- dogfood seed: inert/unknown queue transport and broker outage during task dispatch.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-12 — Lock Builds 1+2 with black-box failure cases
- build: 2
- depends_on: SOL-02, SOL-10, SOL-11
- acceptance criteria (diff-blind testable):
- A black-box suite proves: unknown queue status blocks; malformed task blocks; gate failure blocks completion; dropped identity blocks mutation; HMAC corruption forces refresh; Redis loss recovers from PG; stale lease cannot close.
- The suite invokes shipped CLI/service boundaries, not internal mocks.
- Every asserted failure checks process/result status and durable terminal/non-terminal state.
- The same canary task succeeds under Claude, Codex, and Pi adapters or a documented unavailable-runtime fixture fails explicitly.
- dogfood seed: gate-6/#1019, identity drift, and built-but-unwired MACP.
- est. tokens: 8K
- suggested runtime tier: sonnet
SOL-13 — Bind session authority to contract hash and generation
- build: 3
- depends_on: SOL-12
- acceptance criteria (diff-blind testable):
- Launch computes a stable hash over the effective Constitution/AGENTS/runtime/skills set and stores it with session generation.
- Policy change or compaction detection marks the generation stale before any subsequent mutation.
- A stale/mismatched generation can read diagnostics but cannot claim, write task state, acknowledge comms, merge, or close.
- Re-attestation creates a new generation; old credentials/leases remain fenced.
- Hash input order/path normalization is deterministic across two clean launches.
- dogfood seed: compacted orchestrator losing directives and D-4 ignoring an in-message reset.
- est. tokens: 12K
- suggested runtime tier: sonnet
SOL-14 — Persist compact typed rotation checkpoints using Coord primitives
- build: 3
- depends_on: SOL-13
- acceptance criteria (diff-blind testable):
- Checkpoint contains mission/task, completed/blocked state, next three actions, constraints, claims, contract hash/generation, and cursors—never transcript text.
- Checkpoint is HMAC-verified before rehydration; corrupt/expired/missing required claims refuse resume and request deterministic refresh.
- Writing checkpoint and rotation-intent event is atomic in PG.
- Existing Coord continuation capsule semantics are reused; no competing handoff schema/file is created.
- dogfood seed: manual MOS-ORCHESTRATION-BOARD checkpoint and incomplete-rehydration risk.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-15 — Finish the deterministic coordinator rotation daemon
- build: 3
- depends_on: SOL-14
- acceptance criteria (diff-blind testable):
- Configured token threshold triggers checkpoint → revoke old authority → terminate → launch fresh → verify rehydration in that order.
- Compaction-detected is a backstop that forces the same rotation path; it never requests recursive compaction.
- A launch failure leaves the mission recoverable and visibly paused, not assigned to two active generations.
- Ephemeral seats die/respawn without mission checkpoint; persistent/orchestrator seats rotate.
- The implementation extends
packages/coord; untrackedapps/coordinatorresidue is not revived.
- dogfood seed: planner-sol dirty-context dispatch and the old coordinator’s log-only
_check_context()behavior. - est. tokens: 16K
- suggested runtime tier: sonnet
SOL-16 — Add broker-independent recovery and remove silent MOSAIC BYPASS
- build: 3
- depends_on: SOL-15
- acceptance criteria (diff-blind testable):
- With Redis/broker unavailable, a diagnostic/bootstrap command can inspect PG mission state, repair broker configuration, and resume without traversing the broker gate.
- Normal recovery remains broker-gated and is labeled as such.
- Break-glass requires explicit scope and expiry, emits a durable event, displays a loud banner, and auto-expires; permanent/silent bypass text or behavior is absent.
- The Pi-brick fixture recovers the broker, then returns to normal gated operation without editing source/config by hand.
- Orchestrator guidance removes “/compact and continue” only after the rotation command is available; ephemeral guidance remains explicit.
- dogfood seed: Pi brick and silent
MOSAIC BYPASS 2026-07-22. - est. tokens: 12K
- suggested runtime tier: sonnet
SOL-17 — Converge each host on one roster-owned lifecycle domain
- build: 5 (hygiene; hard prerequisite for addressed comms)
- depends_on: SOL-16
- acceptance criteria (diff-blind testable):
- Reconcile establishes exactly one roster-declared tmux socket/lifecycle domain per host.
- Unknown sessions are reported and quarantined; they are never killed without positive unmanaged classification.
- Max-age/max-context stale sessions invoke SOL-15 rotation for persistent seats or reap for ephemerals.
- Seat identity survives respawn and equals the roster/MOSAIC_AGENT_NAME binding.
- A fixture matching the current four unmanaged remediation seats converges them or produces explicit quarantine actions.
- dogfood seed: scout-bounce and BOARD D-3 seats split between default and
mosaic-fleetsockets. - est. tokens: 14K
- suggested runtime tier: codex
SOL-18 — Publish authenticated comms/v1 envelope and compatibility rules
- build: 4
- depends_on: SOL-13, SOL-17
- acceptance criteria (diff-blind testable):
- Envelope validates protocol version, message/idempotency ID, sender/recipient seat identity, class, ordering/coalesce key, creation/expiry, correlation, payload digest, and authentication.
- Current and immediately previous supported protocol versions are accepted; unsupported versions are rejected loudly with supported range.
- Framework/runtime version is diagnostic metadata and never the compatibility key.
- Forged sender, changed recipient/payload, expired envelope, and replay with conflicting content fail closed.
- dogfood seed: wrong-socket bare tmux message with no authoritative sender/recipient receipt.
- est. tokens: 8K
- suggested runtime tier: codex
SOL-19 — Build the logical PG-first comms service with tmux adapter
- build: 4
- depends_on: SOL-18
- acceptance criteria (diff-blind testable):
- Sending commits envelope/payload and PENDING state in PG before adapter delivery.
- State machine enforces PENDING → RECEIVED → CONSUMED or DEAD-LETTER; illegal regressions are rejected.
- Recipient-filtered claims and append/coalesce policy are deterministic by message class.
- tmux is a dumb adapter: delivery failure changes no PG authority state and is retryable.
- Existing Tess durable repository/state-machine patterns are extended or generalized; no new deployable microservice or second inbox framework appears.
- dogfood seed: MACP scout bounce that was discovered only by manual liveness check.
- est. tokens: 16K
- suggested runtime tier: sonnet
SOL-20 — Make agent-send use the sole path and prove stale-message handling
- build: 4
- depends_on: SOL-19
- acceptance criteria (diff-blind testable):
- Normal
agent-sendcreates a comms/v1 record and observes RECEIVED/CONSUMED; it cannot directly invoke tmux. - A wrong/missing socket leaves PENDING with retry diagnostics, then reaches RECEIVED after roster repair without resending.
- A stale coalescible message arriving after a newer terminal message is marked superseded/consumed and is not surfaced as live work.
- Duplicate identical send is idempotent; same ID with changed content is rejected.
- Inbox receipt/terminal disposition emits canonical MACP lifecycle events.
- Normal
- dogfood seed: scout-bounce and #1018 stale-consumed message arriving after merge.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-21 — Add Redis Streams hot delivery and PG reconciliation
- build: 4
- depends_on: SOL-11, SOL-20
- acceptance criteria (diff-blind testable):
- PG commit precedes XADD; induced XADD failure is repaired by sweeper.
- Consumer uses a PEL; ack sequence is PG CONSUMED commit before XACK.
- Redis flush/restart rebuilds pending delivery from PG without duplicating consumed messages.
- Pending, abandoned, and dead-letter transitions are observable with bounded retry/backoff.
- Existing Redis/queue connection/configuration is reused.
- dogfood seed: delivery bounce plus broker loss between durable write and hot enqueue.
- est. tokens: 12K
- suggested runtime tier: codex
SOL-22 — Prove adapter pluggability with the existing Matrix connector
- build: 4
- depends_on: SOL-21
- acceptance criteria (diff-blind testable):
- Existing Matrix connector consumes/produces comms/v1 through SOL-19 without owning authority state.
- The same envelope can fail tmux and later deliver through Matrix while producing one logical message lifecycle.
- Matrix retry/reconnect cannot regress PG state or duplicate CONSUMED work.
- Removing Matrix availability leaves PG/Redis/tmux behavior intact.
- dogfood seed: cross-socket scout notification bounce; alternate reach must not become alternate authority.
- est. tokens: 8K
- suggested runtime tier: codex
SOL-23 — Constrain auto-sync and agent writes by allowlist and lease
- build: 5
- depends_on: SOL-10
- acceptance criteria (diff-blind testable):
- Auto-sync stages only an explicit allowlist; an unknown modified/untracked docs/source file remains unstaged and is reported.
- Agent source/docs writes require the correct worktree/lease; two seats cannot acquire the same mutable target concurrently.
- Generated files are positively identified, not inferred by denylist.
- The measured annotation/index mid-write fixture cannot be swept into an unrelated commit.
- DB orchestration state is absent from repository staging concerns.
- dogfood seed: auto-sync sweep commit
517bd5c26capturing agent-authored docs mid-write. - est. tokens: 8K
- suggested runtime tier: codex
SOL-24 — Build the real-artifact lifecycle conformance harness
- build: 5
- depends_on: SOL-16, SOL-17, SOL-22, SOL-23
- acceptance criteria (diff-blind testable):
- Harness launches shipped CLI/runtime artifacts and fault-injects compaction, broker outage, delivery bounce, identity drop, stale contract hash, queue unknown/malformed, Redis loss, and auto-sync collision.
- One deterministic test executes 100 sequential rotations with no lost/duplicated task, claim, receipt, or terminal disposition.
- Tests assert DB state/event order and process exits, not log substrings alone.
- Harness runs against isolated PG/Redis namespaces and cleans only resources it created.
- Every banked dogfood seed has a named case and evidence output suitable for CI/release attachment.
- dogfood seed: the complete failure bank: Pi brick, scout-bounce, gate-6/#1019, identity drift, auto-sync, #1018 stale-consumed, D-4 dirty context.
- est. tokens: 18K
- suggested runtime tier: sonnet
SOL-25 — Complete operator cutover docs and activation proof
- build: 5
- depends_on: SOL-01, SOL-02, SOL-10, SOL-16, SOL-22, SOL-24
- acceptance criteria (diff-blind testable):
- Operator docs give exact DB import/cutover, rollback-before-cutover, recovery, break-glass expiry, rotation, comms, quarantine, and conformance commands.
- Link/command checks find no orchestrator instruction to mutate flat-file mission/tasks, use silent bypass, direct-tmux normal comms, or “compact and continue” a persistent seat.
- A clean non-root install activates one coherent version and runs the conformance smoke subset.
- Release evidence maps all 15 decisions and every live seed to a passing check or an explicit deferred item below.
- dogfood seed: activation skew plus the tendency to leave built fixes unwired or undocumented.
- est. tokens: 6K
- suggested runtime tier: codex
Explicit DEFER list (10)
These are not rejected; they are past first dogfood and should not delay G1/G2. Each is gold-plating unless a live failure makes it necessary.
- DEFER — Mission dashboard/TUI views. CLI/DB queries are enough to operate and prove the spine.
- DEFER — PRD-to-board automatic decomposition. This is LLM/judgment-heavy and unrelated to enforcing already-decided tasks.
- DEFER — General heuristic churn scoring. Implement token threshold + compaction sensor first; repeated-tool-loop inference can follow measured need.
- DEFER — Discord comms adapter. Existing plugin reach remains; migrate only after tmux+Matrix prove the service contract.
- DEFER — Slack comms adapter. No current dogfood dependency.
- DEFER — Telegram comms adapter. No current dogfood dependency.
- DEFER — Public MCP comms surface.
agent-sendand service API are sufficient for the mission proof. - DEFER — Protocol-v2 features/general negotiation framework. Ship v1 with a bounded current/previous acceptance window; do not predict v2.
- DEFER — Multi-region/HA PG or Redis. Existing in-stack PG+Redis and rebuildability satisfy current failure classes.
- DEFER — Event analytics/search UI and long-term warehouse. Indexed PG evidence plus CLI queries is enough for audit/conformance.
Suspect abstractions register
| proposed thing | verdict |
|---|---|
Canonical Node TaskExecutor |
JUSTIFIED: explicitly required single choke point; wraps existing MACP functions rather than replacing them. |
| PG repository methods | JUSTIFIED but narrow: ordinary adapters around existing Drizzle/DB patterns, not a new “state platform.” |
| Rotation daemon | JUSTIFIED: finishes packages/coord; do not revive apps/coordinator or create another service. |
| Comms service | JUSTIFIED only as a logical in-process boundary: reuse Tess durable inbox/outbox and existing connectors; no new deployable microservice this cycle. |
| Universal queue/broker abstraction | SUSPECT / DO NOT BUILD: reuse packages/queue, PG outbox, and Redis Streams/BullMQ configuration already present. |
| Universal envelope/state framework | SUSPECT / DO NOT BUILD: MACP Task/Claim/Event and comms/v1 have different bounded purposes. |
| Generic compatibility-negotiation engine | SUSPECT / DEFER: a small supported-version check meets v1 needs. |
Dissent (7)
- Do not wire new production behavior into
mosaic_orchestrator.py::run_single_task. The scout correctly identified the duplicated block, but BOARD’s later ruling says the disabled Python rail is residue and must be retired. Building a Node bridge only to delete it is throwaway. Put the Node TaskExecutor in@mosaicstack/macp, route the live Coord path to it at SOL-08, migrate remaining producers at SOL-09, then delete the Python block at SOL-10. - Redis is not on the first-dogfood critical path. PG claim/polling is sufficient for one real task and exposes correctness earlier. Add Redis only after G1; otherwise queue debugging obscures whether the choke point works.
- “One choke-point service” does not justify a new deployable service. An exported executor plus Coord daemon is enough. A new Nest app, RPC protocol, deployment, auth layer, and health plane would be greenfield.
- The Mission Control PRD’s file-first and board-regeneration assumptions are superseded. Keep its mission/rotation semantics, but obey the accepted hard DB cutover; do not implement its file-first milestones or PRD-to-board generator now.
- Do not gate every interactive runtime launch as if it were a mission task. Enforce every tracked task/data mutation at the executor/DB authority boundary. Ephemeral interactive shells may launch, but receive no task mutation authority unless attached to a valid claim.
- Do not implement broad “churn intelligence.” Token threshold and compaction-detected are deterministic sensors. Repeated-loop semantic detection is expensive, noisy, and premature until telemetry demonstrates a gap.
- The 100-rotation test is a final conformance bar, not an early unit-test tax. First prove one rotation, then fault cases, then 100 repetitions in SOL-24. Requiring 100 before G3 would delay feedback without changing the design.
Orchestrator reconciliation notes
- Pre-register each task’s acceptance checks from this document before showing implementation diffs to its reviewer. Author and reviewer remain different seats.
- SOL-07 permits a one-time import, not an interim store: no shadow writes, dual reads, or sync daemon.
- G1 is the budget escape hatch. If the 72K hard-path slice does not work, stop and remediate instead of spending the remaining ~222K.
- Docs belong in each behavior-changing PR where required; SOL-25 is cross-link/cutover validation, not permission to postpone essential docs.