Files
stack/docs/remediation/DECOMP-SOL.md
T
ba98f88891 docs(remediation): reconciled execution backlog from two independent decompositions
TASK-1 complete. planner-opus (robustness, 38 tasks/8 dissents) and planner-sol
(pragmatic, 25 tasks/10 defers/7 dissents) each decomposed the 4-build plan without
seeing the other's work. Both decomps are committed alongside the reconciliation so
the disagreements stay auditable rather than being flattened into a consensus.

Reconciled into 58 tasks across P0-P5 (docs/remediation/TASKS.md):
- 7 independent convergences, treated as settled because neither planner could see
  the other. The headline: BOTH reject the charter's wire-in point
  (mosaic_orchestrator.py::run_single_task) because that controller is disabled and
  references a dispatcher absent from this checkout — wiring it would produce a
  stranded executor, the same built-but-unwired disease one layer up.
- 7 genuine disagreements ADJUDICATED, not averaged. The cost estimates are ~18x
  apart; rather than split the difference, the plan adopts sol's scope with opus's
  rigor and treats the first-dogfood gate as a hard budget checkpoint.
- 3 decisions escalated (wire-in point, rollback artifact + availability trade,
  queue-guard ownership vs parked PR #1023). No task blocked on them is dispatched.

Keystone dogfood case recorded (TASKS.md 1a): merged PR #868 shipped a file failing
pnpm format:check, then an unrelated PR reformatted it as a side effect, so main went
green and the gate's failure to fire left no trace. Detection must therefore be
per-merge-commit against that commit's own tree.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-31 17:25:04 -05:00

30 KiB
Raw Blame History

Adversarial Decomposition — Pragmatic / Shortest-Path Side

Planner: planner-sol
Bias: make one real fleet task pass through one enforced path as early as possible; reuse before building.
Scope source: MISSION.md, MACP-WIRING-SCOUT.md, BOARD.md, existing @mosaicstack/macp, packages/coord, PG/Valkey, Tess durable inbox/outbox, and the Mission Control PRD.

Executive position

The first useful milestone is not “complete Builds 1 and 2.” It is this narrow vertical slice:

A DB-backed mission task is atomically claimed by packages/coord, executed by one Node @mosaicstack/macp TaskExecutor, gated, and terminally recorded with identity-bound events and a tri-state mutation result. No docs/TASKS.md, mission.json, tasks.json, Python gate loop, or NDJSON ledger participates.

That slice is SOL-03 → SOL-04 → SOL-05 → SOL-06 → SOL-07 → SOL-08, estimated at 72K tokens, mostly Codex. PG polling is acceptable for this first proof. Redis acceleration follows only after correctness is observable. This is the shortest path that is both dogfoodable and not throwaway work.

Cost posture

  • 25 PR tasks, ~294K tokens total: ~164K Codex, ~130K Sonnet, 0K Opus.
  • First live choke-point dogfood: ~72K on the hard path; SOL-01 and SOL-02 can run beside it.
  • Opus is not justified for planned implementation. Escalate only if an independent security review finds an unresolved architecture-level authority flaw.
  • Every row is one PR. Estimates include implementation, focused tests, docs affected by that PR, and one remediation pass—not orchestration/reviewer overhead.

Gates and critical path

gate opens when proof required before downstream work
G0 — trustworthy launch gates SOL-01, SOL-02 non-root checkout works; queue status cannot become false-green
G1 — first dogfood / minimum viable cut SOL-08 one live fleet task completes DB → MACP executor → gates → DB with no flat-file state
G2 — Builds 1+2 closed SOL-09..SOL-12 all producers use the executor; duplicate islands retired; Redis loss is recoverable from PG
G3 — rotation real SOL-13..SOL-16 stale generation cannot mutate; fresh session resumes typed state; Pi-brick recovery works without broker
G4 — sole-path comms real SOL-17..SOL-22 roster identity is stable; bounced/stale messages converge through PG/Redis and adapters
G5 — mission proof SOL-23..SOL-25 workflow sweep cannot capture unknown files; fault bank passes, including 100 rotations

Critical path: 03 → 04 → 05 → 06 → 08 → 10 → 12 → 13 → 14 → 15 → 16 → 17 → 18 → 19 → 20 → 21 → 22 → 24 → 25.

Ordered task list

SOL-01 — Repair activation coherence and non-root checkout hygiene

  • build: 5 (hygiene; pulled forward)
  • depends_on:
  • acceptance criteria (diff-blind testable):
    1. A clean non-root checkout can run dependency/bootstrap preparation without accessing /root.
    2. A root CI checkout still uses an isolated writable pnpm store.
    3. Activation installs CLI, hooks, broker/runtime assets, and version manifest transactionally: induced failure leaves the prior complete generation active.
    4. Launch with a deliberately skewed component version is rejected with the exact repair command; diagnostics remain usable.
    5. No test uses --no-verify or suppresses hooks.
  • dogfood seed: BOARD D-1 root-pinned .npmrc and D-2 root-owned Husky path.
  • est. tokens: 6K
  • suggested runtime tier: codex

SOL-02 — Make queue guard fail-safe with exit-asserting tests

  • build: 1
  • depends_on:
  • acceptance criteria (diff-blind testable):
    1. Fixture responses pending, success, failure, no-status, malformed JSON, provider error, and unknown status produce explicitly asserted process exits.
    2. Only terminal success/no-active-queue returns 0; unknown, malformed, and transport failure return non-zero with actionable output.
    3. A payload larger than 150 KiB is consumed without argv expansion or truncation.
    4. At least one mutant changes unknown→success and is killed by the test suite.
  • dogfood seed: inert gate-6 and recursive #1019 failure (unknown→exit 0; ARG_MAX).
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-03 — Complete the canonical MACP contract, not another protocol

  • build: 1
  • depends_on:
  • acceptance criteria (diff-blind testable):
    1. @mosaicstack/macp validates typed Task, TaskResult, lifecycle Event, state Claim, and verified | written-unverified | failed mutation outcome records.
    2. Claims require source, confidence, issued-at, TTL/expiry, refresh instruction, and HMAC integrity; tamper/expiry returns a typed refusal, never partial data.
    3. Lifecycle events include launch, mission generation, checkpoint, rotation, recovery, inbox receipt, and terminal disposition while preserving existing task events.
    4. MOSAIC_AGENT_NAME is required for mutating execution and appears in credential/actor binding; missing identity fails closed.
    5. Target metadata requires repository identity, task/record ID, and head or generation where applicable.
  • dogfood seed: rev-974 identity drift plus the three observed write outcomes.
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-04 — Add the narrow PG orchestration spine schema

  • build: 2
  • depends_on: SOL-03
  • acceptance criteria (diff-blind testable):
    1. Migration up creates mission, task, dependency, task-claim, MACP event, typed state-claim, session-generation, and dispatch-outbox records with tenant/mission keys and uniqueness constraints.
    2. The database rejects a task without a mission, a dependency outside its mission, duplicate idempotency keys, and terminal→running regression.
    3. Event and claim records reference canonical mission/task/generation identities; claims store integrity metadata.
    4. Migration rollback on an empty test DB succeeds; rerunning migration is safe.
    5. No comms-specific “universal message” schema is invented here; Build 4 reuses/extends existing interaction inbox/outbox tables.
  • dogfood seed: mission convention existed but a lane could act with no mechanically valid mission/task.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-05 — Implement atomic PG task claims, transitions, ledger, and outbox

  • build: 2
  • depends_on: SOL-04
  • acceptance criteria (diff-blind testable):
    1. Two concurrent claimers for one runnable task yield exactly one lease owner.
    2. Dependencies are evaluated transactionally; an unmet dependency can never be claimed.
    3. Claim, state transition, MACP event, and dispatch-outbox append commit atomically or all roll back.
    4. Expired leases are reclaimable with a higher fencing generation; stale owners cannot complete or mutate.
    5. Querying mission status is derived solely from PG and returns the next runnable task deterministically.
  • dogfood seed: model-maintained live board and stale claims surviving session changes.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-06 — Build the one production Node MACP TaskExecutor

  • build: 1
  • depends_on: SOL-03, SOL-05
  • acceptance criteria (diff-blind testable):
    1. A public Node executor accepts only a claimed canonical MACP Task, resolves credentials/identity, runs the worker, runs structured gates, and persists terminal result/events through SOL-05.
    2. Worker exit 0 plus a failed gate cannot produce completed; worker failure cannot skip terminal ledger emission.
    3. Claude, Codex, and Pi fixture backends emit the same runtime-neutral lifecycle sequence.
    4. Every mutation returns one mandatory tri-state outcome; callers cannot compile while discarding it.
    5. Crash after worker success but before terminal commit leaves a recoverable fenced claim and no false completion.
  • dogfood seed: stranded MACP, gate-6 inert completion, and written-unverified being treated as success.
  • est. tokens: 16K
  • suggested runtime tier: sonnet

SOL-07 — Provide one-shot flat-file import and cutover readiness audit

  • build: 2
  • depends_on: SOL-05
  • acceptance criteria (diff-blind testable):
    1. A dry-run parses existing mission/TASKS artifacts, reports unsupported/ambiguous rows, and performs zero writes.
    2. Apply is idempotent and records source digests; repeated apply creates no duplicates.
    3. Unknown status, dangling dependency, duplicate task ID, and malformed table block import with row-level diagnostics.
    4. Readiness reports “cutover-ready” only when imported PG projections exactly match source counts/dependencies/statuses.
    5. This command is migration-only; it exposes no dual-write or ongoing sync mode.
  • dogfood seed: current remediation board/TASKS state needs a clean DB landing without silently losing tasks.
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-08 — Hard-cut packages/coord to PG and dogfood one live task

  • build: 1
  • depends_on: SOL-06, SOL-07
  • acceptance criteria (diff-blind testable):
    1. mosaic coord run/status/continue reads and mutates PG only; absent/unmigrated DB state fails with the SOL-07 repair path.
    2. No fallback reads/writes docs/TASKS.md, mission JSON, task JSON, state JSON, results JSON, or events NDJSON.
    3. A live canary task assigned to a fleet seat travels PG claim → TaskExecutor → worker → gate → terminal PG result/event and closes only after gate success.
    4. Killing the coordinator after claim and restarting it neither duplicates execution nor allows the stale lease to close the task.
    5. Evidence query shows actor seat, mission/task, target metadata, gate results, and tri-state outcome.
  • dogfood seed: this remediation mission itself; reproduce a gate-6-style non-null task and identity-bound write.
  • est. tokens: 16K
  • suggested runtime tier: sonnet

G1 FIRST-DOGFOOD: stop and validate here before broadening. If SOL-08 cannot carry a real task, do not build Redis, rotation, comms, or UI.

SOL-09 — Route Forge and OpenClaw/MACP producers through TaskExecutor

  • build: 1
  • depends_on: SOL-08
  • acceptance criteria (diff-blind testable):
    1. Forge and the OpenClaw MACP runtime submit the canonical Task type to SOL-06; neither executes a worker or gate itself.
    2. Their success callbacks are derived from canonical terminal results, not local/stub completion.
    3. A failed canonical gate is observed identically from Coord, Forge, and OpenClaw fixtures.
    4. Repository search plus an executable import boundary test finds no production-local redefinition of Task/TaskResult/GateResult on these paths.
  • dogfood seed: Forges immediate empty-gate completion and the plugins redefined MACP-shaped result.
  • est. tokens: 10K
  • suggested runtime tier: codex

SOL-10 — Retire flat-file orchestration and the disabled duplicate rail

  • build: 1
  • depends_on: SOL-09
  • acceptance criteria (diff-blind testable):
    1. The Python controller execution/gate/event path, tasks_md_sync, plugin-local protocol types, orphaned context loader, and production flat-file orchestration writers/readers are absent from shipped assets.
    2. Framework guides/templates/startup context point to DB mission commands, not docs/TASKS.md as orchestration SoR.
    3. A regression scan fails CI if production code reintroduces events.ndjson, tasks.json, mission.json, or docs/TASKS.md orchestration mutation.
    4. jarvis-brain PDA flat files and unrelated project docs remain untouched.
    5. Upgrade removes/quarantines obsolete generated rail files without deleting user source/docs.
  • dogfood seed: three parallel islands and stale .mosaic/orchestrator/mission.json 0/0 residue.
  • est. tokens: 14K
  • suggested runtime tier: sonnet

SOL-11 — Add Redis hot dispatch as a derived outbox consumer

  • build: 2
  • depends_on: SOL-08
  • acceptance criteria (diff-blind testable):
    1. Task creation commits mission/task/outbox in PG before any Redis enqueue.
    2. Induced Redis failure leaves the task durable and pending; a sweeper later enqueues it exactly once logically.
    3. Deleting the Redis queue and rebuilding from PG restores all non-terminal dispatches without reviving terminal tasks.
    4. Duplicate delivery is neutralized by PG claim fencing/idempotency.
    5. Existing packages/queue adapter/config is reused; no second broker API is introduced.
  • dogfood seed: inert/unknown queue transport and broker outage during task dispatch.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-12 — Lock Builds 1+2 with black-box failure cases

  • build: 2
  • depends_on: SOL-02, SOL-10, SOL-11
  • acceptance criteria (diff-blind testable):
    1. A black-box suite proves: unknown queue status blocks; malformed task blocks; gate failure blocks completion; dropped identity blocks mutation; HMAC corruption forces refresh; Redis loss recovers from PG; stale lease cannot close.
    2. The suite invokes shipped CLI/service boundaries, not internal mocks.
    3. Every asserted failure checks process/result status and durable terminal/non-terminal state.
    4. The same canary task succeeds under Claude, Codex, and Pi adapters or a documented unavailable-runtime fixture fails explicitly.
  • dogfood seed: gate-6/#1019, identity drift, and built-but-unwired MACP.
  • est. tokens: 8K
  • suggested runtime tier: sonnet

SOL-13 — Bind session authority to contract hash and generation

  • build: 3
  • depends_on: SOL-12
  • acceptance criteria (diff-blind testable):
    1. Launch computes a stable hash over the effective Constitution/AGENTS/runtime/skills set and stores it with session generation.
    2. Policy change or compaction detection marks the generation stale before any subsequent mutation.
    3. A stale/mismatched generation can read diagnostics but cannot claim, write task state, acknowledge comms, merge, or close.
    4. Re-attestation creates a new generation; old credentials/leases remain fenced.
    5. Hash input order/path normalization is deterministic across two clean launches.
  • dogfood seed: compacted orchestrator losing directives and D-4 ignoring an in-message reset.
  • est. tokens: 12K
  • suggested runtime tier: sonnet

SOL-14 — Persist compact typed rotation checkpoints using Coord primitives

  • build: 3
  • depends_on: SOL-13
  • acceptance criteria (diff-blind testable):
    1. Checkpoint contains mission/task, completed/blocked state, next three actions, constraints, claims, contract hash/generation, and cursors—never transcript text.
    2. Checkpoint is HMAC-verified before rehydration; corrupt/expired/missing required claims refuse resume and request deterministic refresh.
    3. Writing checkpoint and rotation-intent event is atomic in PG.
    4. Existing Coord continuation capsule semantics are reused; no competing handoff schema/file is created.
  • dogfood seed: manual MOS-ORCHESTRATION-BOARD checkpoint and incomplete-rehydration risk.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-15 — Finish the deterministic coordinator rotation daemon

  • build: 3
  • depends_on: SOL-14
  • acceptance criteria (diff-blind testable):
    1. Configured token threshold triggers checkpoint → revoke old authority → terminate → launch fresh → verify rehydration in that order.
    2. Compaction-detected is a backstop that forces the same rotation path; it never requests recursive compaction.
    3. A launch failure leaves the mission recoverable and visibly paused, not assigned to two active generations.
    4. Ephemeral seats die/respawn without mission checkpoint; persistent/orchestrator seats rotate.
    5. The implementation extends packages/coord; untracked apps/coordinator residue is not revived.
  • dogfood seed: planner-sol dirty-context dispatch and the old coordinators log-only _check_context() behavior.
  • est. tokens: 16K
  • suggested runtime tier: sonnet

SOL-16 — Add broker-independent recovery and remove silent MOSAIC BYPASS

  • build: 3
  • depends_on: SOL-15
  • acceptance criteria (diff-blind testable):
    1. With Redis/broker unavailable, a diagnostic/bootstrap command can inspect PG mission state, repair broker configuration, and resume without traversing the broker gate.
    2. Normal recovery remains broker-gated and is labeled as such.
    3. Break-glass requires explicit scope and expiry, emits a durable event, displays a loud banner, and auto-expires; permanent/silent bypass text or behavior is absent.
    4. The Pi-brick fixture recovers the broker, then returns to normal gated operation without editing source/config by hand.
    5. Orchestrator guidance removes “/compact and continue” only after the rotation command is available; ephemeral guidance remains explicit.
  • dogfood seed: Pi brick and silent MOSAIC BYPASS 2026-07-22.
  • est. tokens: 12K
  • suggested runtime tier: sonnet

SOL-17 — Converge each host on one roster-owned lifecycle domain

  • build: 5 (hygiene; hard prerequisite for addressed comms)
  • depends_on: SOL-16
  • acceptance criteria (diff-blind testable):
    1. Reconcile establishes exactly one roster-declared tmux socket/lifecycle domain per host.
    2. Unknown sessions are reported and quarantined; they are never killed without positive unmanaged classification.
    3. Max-age/max-context stale sessions invoke SOL-15 rotation for persistent seats or reap for ephemerals.
    4. Seat identity survives respawn and equals the roster/MOSAIC_AGENT_NAME binding.
    5. A fixture matching the current four unmanaged remediation seats converges them or produces explicit quarantine actions.
  • dogfood seed: scout-bounce and BOARD D-3 seats split between default and mosaic-fleet sockets.
  • est. tokens: 14K
  • suggested runtime tier: codex

SOL-18 — Publish authenticated comms/v1 envelope and compatibility rules

  • build: 4
  • depends_on: SOL-13, SOL-17
  • acceptance criteria (diff-blind testable):
    1. Envelope validates protocol version, message/idempotency ID, sender/recipient seat identity, class, ordering/coalesce key, creation/expiry, correlation, payload digest, and authentication.
    2. Current and immediately previous supported protocol versions are accepted; unsupported versions are rejected loudly with supported range.
    3. Framework/runtime version is diagnostic metadata and never the compatibility key.
    4. Forged sender, changed recipient/payload, expired envelope, and replay with conflicting content fail closed.
  • dogfood seed: wrong-socket bare tmux message with no authoritative sender/recipient receipt.
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-19 — Build the logical PG-first comms service with tmux adapter

  • build: 4
  • depends_on: SOL-18
  • acceptance criteria (diff-blind testable):
    1. Sending commits envelope/payload and PENDING state in PG before adapter delivery.
    2. State machine enforces PENDING → RECEIVED → CONSUMED or DEAD-LETTER; illegal regressions are rejected.
    3. Recipient-filtered claims and append/coalesce policy are deterministic by message class.
    4. tmux is a dumb adapter: delivery failure changes no PG authority state and is retryable.
    5. Existing Tess durable repository/state-machine patterns are extended or generalized; no new deployable microservice or second inbox framework appears.
  • dogfood seed: MACP scout bounce that was discovered only by manual liveness check.
  • est. tokens: 16K
  • suggested runtime tier: sonnet

SOL-20 — Make agent-send use the sole path and prove stale-message handling

  • build: 4
  • depends_on: SOL-19
  • acceptance criteria (diff-blind testable):
    1. Normal agent-send creates a comms/v1 record and observes RECEIVED/CONSUMED; it cannot directly invoke tmux.
    2. A wrong/missing socket leaves PENDING with retry diagnostics, then reaches RECEIVED after roster repair without resending.
    3. A stale coalescible message arriving after a newer terminal message is marked superseded/consumed and is not surfaced as live work.
    4. Duplicate identical send is idempotent; same ID with changed content is rejected.
    5. Inbox receipt/terminal disposition emits canonical MACP lifecycle events.
  • dogfood seed: scout-bounce and #1018 stale-consumed message arriving after merge.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-21 — Add Redis Streams hot delivery and PG reconciliation

  • build: 4
  • depends_on: SOL-11, SOL-20
  • acceptance criteria (diff-blind testable):
    1. PG commit precedes XADD; induced XADD failure is repaired by sweeper.
    2. Consumer uses a PEL; ack sequence is PG CONSUMED commit before XACK.
    3. Redis flush/restart rebuilds pending delivery from PG without duplicating consumed messages.
    4. Pending, abandoned, and dead-letter transitions are observable with bounded retry/backoff.
    5. Existing Redis/queue connection/configuration is reused.
  • dogfood seed: delivery bounce plus broker loss between durable write and hot enqueue.
  • est. tokens: 12K
  • suggested runtime tier: codex

SOL-22 — Prove adapter pluggability with the existing Matrix connector

  • build: 4
  • depends_on: SOL-21
  • acceptance criteria (diff-blind testable):
    1. Existing Matrix connector consumes/produces comms/v1 through SOL-19 without owning authority state.
    2. The same envelope can fail tmux and later deliver through Matrix while producing one logical message lifecycle.
    3. Matrix retry/reconnect cannot regress PG state or duplicate CONSUMED work.
    4. Removing Matrix availability leaves PG/Redis/tmux behavior intact.
  • dogfood seed: cross-socket scout notification bounce; alternate reach must not become alternate authority.
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-23 — Constrain auto-sync and agent writes by allowlist and lease

  • build: 5
  • depends_on: SOL-10
  • acceptance criteria (diff-blind testable):
    1. Auto-sync stages only an explicit allowlist; an unknown modified/untracked docs/source file remains unstaged and is reported.
    2. Agent source/docs writes require the correct worktree/lease; two seats cannot acquire the same mutable target concurrently.
    3. Generated files are positively identified, not inferred by denylist.
    4. The measured annotation/index mid-write fixture cannot be swept into an unrelated commit.
    5. DB orchestration state is absent from repository staging concerns.
  • dogfood seed: auto-sync sweep commit 517bd5c26 capturing agent-authored docs mid-write.
  • est. tokens: 8K
  • suggested runtime tier: codex

SOL-24 — Build the real-artifact lifecycle conformance harness

  • build: 5
  • depends_on: SOL-16, SOL-17, SOL-22, SOL-23
  • acceptance criteria (diff-blind testable):
    1. Harness launches shipped CLI/runtime artifacts and fault-injects compaction, broker outage, delivery bounce, identity drop, stale contract hash, queue unknown/malformed, Redis loss, and auto-sync collision.
    2. One deterministic test executes 100 sequential rotations with no lost/duplicated task, claim, receipt, or terminal disposition.
    3. Tests assert DB state/event order and process exits, not log substrings alone.
    4. Harness runs against isolated PG/Redis namespaces and cleans only resources it created.
    5. Every banked dogfood seed has a named case and evidence output suitable for CI/release attachment.
  • dogfood seed: the complete failure bank: Pi brick, scout-bounce, gate-6/#1019, identity drift, auto-sync, #1018 stale-consumed, D-4 dirty context.
  • est. tokens: 18K
  • suggested runtime tier: sonnet

SOL-25 — Complete operator cutover docs and activation proof

  • build: 5
  • depends_on: SOL-01, SOL-02, SOL-10, SOL-16, SOL-22, SOL-24
  • acceptance criteria (diff-blind testable):
    1. Operator docs give exact DB import/cutover, rollback-before-cutover, recovery, break-glass expiry, rotation, comms, quarantine, and conformance commands.
    2. Link/command checks find no orchestrator instruction to mutate flat-file mission/tasks, use silent bypass, direct-tmux normal comms, or “compact and continue” a persistent seat.
    3. A clean non-root install activates one coherent version and runs the conformance smoke subset.
    4. Release evidence maps all 15 decisions and every live seed to a passing check or an explicit deferred item below.
  • dogfood seed: activation skew plus the tendency to leave built fixes unwired or undocumented.
  • est. tokens: 6K
  • suggested runtime tier: codex

Explicit DEFER list (10)

These are not rejected; they are past first dogfood and should not delay G1/G2. Each is gold-plating unless a live failure makes it necessary.

  1. DEFER — Mission dashboard/TUI views. CLI/DB queries are enough to operate and prove the spine.
  2. DEFER — PRD-to-board automatic decomposition. This is LLM/judgment-heavy and unrelated to enforcing already-decided tasks.
  3. DEFER — General heuristic churn scoring. Implement token threshold + compaction sensor first; repeated-tool-loop inference can follow measured need.
  4. DEFER — Discord comms adapter. Existing plugin reach remains; migrate only after tmux+Matrix prove the service contract.
  5. DEFER — Slack comms adapter. No current dogfood dependency.
  6. DEFER — Telegram comms adapter. No current dogfood dependency.
  7. DEFER — Public MCP comms surface. agent-send and service API are sufficient for the mission proof.
  8. DEFER — Protocol-v2 features/general negotiation framework. Ship v1 with a bounded current/previous acceptance window; do not predict v2.
  9. DEFER — Multi-region/HA PG or Redis. Existing in-stack PG+Redis and rebuildability satisfy current failure classes.
  10. DEFER — Event analytics/search UI and long-term warehouse. Indexed PG evidence plus CLI queries is enough for audit/conformance.

Suspect abstractions register

proposed thing verdict
Canonical Node TaskExecutor JUSTIFIED: explicitly required single choke point; wraps existing MACP functions rather than replacing them.
PG repository methods JUSTIFIED but narrow: ordinary adapters around existing Drizzle/DB patterns, not a new “state platform.”
Rotation daemon JUSTIFIED: finishes packages/coord; do not revive apps/coordinator or create another service.
Comms service JUSTIFIED only as a logical in-process boundary: reuse Tess durable inbox/outbox and existing connectors; no new deployable microservice this cycle.
Universal queue/broker abstraction SUSPECT / DO NOT BUILD: reuse packages/queue, PG outbox, and Redis Streams/BullMQ configuration already present.
Universal envelope/state framework SUSPECT / DO NOT BUILD: MACP Task/Claim/Event and comms/v1 have different bounded purposes.
Generic compatibility-negotiation engine SUSPECT / DEFER: a small supported-version check meets v1 needs.

Dissent (7)

  1. Do not wire new production behavior into mosaic_orchestrator.py::run_single_task. The scout correctly identified the duplicated block, but BOARDs later ruling says the disabled Python rail is residue and must be retired. Building a Node bridge only to delete it is throwaway. Put the Node TaskExecutor in @mosaicstack/macp, route the live Coord path to it at SOL-08, migrate remaining producers at SOL-09, then delete the Python block at SOL-10.
  2. Redis is not on the first-dogfood critical path. PG claim/polling is sufficient for one real task and exposes correctness earlier. Add Redis only after G1; otherwise queue debugging obscures whether the choke point works.
  3. “One choke-point service” does not justify a new deployable service. An exported executor plus Coord daemon is enough. A new Nest app, RPC protocol, deployment, auth layer, and health plane would be greenfield.
  4. The Mission Control PRDs file-first and board-regeneration assumptions are superseded. Keep its mission/rotation semantics, but obey the accepted hard DB cutover; do not implement its file-first milestones or PRD-to-board generator now.
  5. Do not gate every interactive runtime launch as if it were a mission task. Enforce every tracked task/data mutation at the executor/DB authority boundary. Ephemeral interactive shells may launch, but receive no task mutation authority unless attached to a valid claim.
  6. Do not implement broad “churn intelligence.” Token threshold and compaction-detected are deterministic sensors. Repeated-loop semantic detection is expensive, noisy, and premature until telemetry demonstrates a gap.
  7. The 100-rotation test is a final conformance bar, not an early unit-test tax. First prove one rotation, then fault cases, then 100 repetitions in SOL-24. Requiring 100 before G3 would delay feedback without changing the design.

Orchestrator reconciliation notes

  • Pre-register each tasks acceptance checks from this document before showing implementation diffs to its reviewer. Author and reviewer remain different seats.
  • SOL-07 permits a one-time import, not an interim store: no shadow writes, dual reads, or sync daemon.
  • G1 is the budget escape hatch. If the 72K hard-path slice does not work, stop and remediate instead of spending the remaining ~222K.
  • Docs belong in each behavior-changing PR where required; SOL-25 is cross-link/cutover validation, not permission to postpone essential docs.