One cumulative control-board, webui and seat state. The four rows edit the
same files (scan.mjs, page.html, README.md, app.js), so they land together,
each on its own receipt:
- Row 18, Discord connector rows on the board (#1509): R3 approved by
Darkwing and Dewey, Gitea comment 26257, manifest 254403b8. Jason
accepted the visual test.
- Row 22, board attention status (#1503): Filbert approved R1, comment
26248, manifest e40b58ec; restart receipt 26249.
- #1511, task attribution (row 6 code phase): R2 approved by Filbert and
Dewey, manifest d4c96395. docs/TOOLS.md carries the approved --by usage
line (tools-usage.patch 86bcba3c).
- #1512, relaunch activity (row 6 pilot): R1 approved by Darkwing and
Dewey, candidate manifest 47769fad. All seven source files match it.
Row 16, internal development bootstrap (#1510): the seven files outside
shared records match Filbert's R1 pins, receipt 26204 (agents/researcher/*,
scripts/test-darkwing-launch.mjs, the bootstrap plan).
packages/webui/src/public/app.js is committed at its #1512 R1 pin ce7d79a4.
The working copy holds Dewey's unreviewed return-flow candidate on top of
that, and it stays uncommitted.
Also: the four row briefs and Darkwing's evidence records under
agents/darkwing/work, including the 2026-09-26 tree manifest and the #1512
re-run against 21e3e908. Serial acceptance command: 397/397, three runs.
The failures that only show when tests run concurrently are in #1509 engine
tests, and they reproduce on clean HEAD.
Suites on the exact staged tree: config 24, task 90, foundation 43,
conductor 17, release 14, auth 15, discord 63; package union 397/397
(serial); test-darkwing-launch 5/5.
Shared records (BUILD-LOG, QUEUE, CURRENT, DEFERRED, SESSIONS, AGENTS.md,
agents/README.md) follow in Sage's records commit.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
66 lines
3.6 KiB
Markdown
66 lines
3.6 KiB
Markdown
# Discord connector board row
|
|
|
|
Current authorized queue item: row 18, #1509, pilot plan section 11. Jason
|
|
assigned this to Darkwing and now explicitly requires automatic continuation to
|
|
the next authorized item after each accepted iteration. This starts row 18,
|
|
not unrelated gated work. Preserve the accepted row-22 attention correction.
|
|
|
|
## Ownership and scope
|
|
|
|
Filbert implements in the canonical checkout on refactor. Darkwing independently
|
|
reviews the exact candidate; Dewey reviews any visible presentation change.
|
|
Single writer for this implementation: Filbert. Existing dirty files remain
|
|
owned by their authors and must not be reset, adopted or overwritten.
|
|
|
|
Allowed implementation paths: packages/control-board source/tests/README and
|
|
minimal packages/webui source/tests changes needed to display the connector
|
|
and refuse replies. No connector source, bindings, secrets, launchers, systemd
|
|
units, live service changes or files under ~/.mosaic. No commits or publication
|
|
by the implementer. Darkwing owns shared tracking records.
|
|
|
|
## Existing contract to implement
|
|
|
|
The original accepted connector brief supplies the interface:
|
|
|
|
- Discover one row per <dataRoot>/discord/<binding>.json, with 0600 regular
|
|
non-symlink files. Project fleet, agent `<seat> (discord: <binding>)`.
|
|
Validate only safe name/seat identity for discovery; never dereference or
|
|
expose token paths, Discord/user/channel IDs, or the rest of the binding.
|
|
- Sessions are under <dataRoot>/sessions/discord-<binding>.
|
|
- Reuse the connector's read-only readPid/ownerState identity checks from
|
|
packages/discord/src/journal.mjs. A positive live PID plus matching start
|
|
tick and boot ID is necessary. Missing, corrupt, dead or unverifiable owners
|
|
cannot be reported live. Do not signal, recover, unlock or rewrite anything.
|
|
- Show STOP presence as braked without interpreting its private contents.
|
|
Liveness and braking must be distinguishable. Existing completed-reply idle
|
|
semantics still apply to session activity.
|
|
- Refuse board replies server-side for connector rows even if a stale or
|
|
forged registration claims a tmux destination. The UI must not offer reply.
|
|
- Avoid filesystem traversal, symlink reads and disclosure of private binding
|
|
fields. A malformed binding must not manufacture an actionable row. Report
|
|
discovery failures safely rather than dumping private content or credentials.
|
|
|
|
Daily counters are optional in the original brief and excluded from this first
|
|
row. No new ingress, controller, Discord API calls or engine/model calls.
|
|
|
|
## Acceptance and handoff
|
|
|
|
Implement and test discovery/privacy, positive and negative process identity,
|
|
STOP/braked display, ordinary session state, server-side reply refusal and
|
|
unchanged ordinary-agent replies. Test both board and WebUI integration with
|
|
isolated fixtures. Preserve the accepted attention regression coverage.
|
|
|
|
Return an exact frozen candidate, changed paths and reproducible test results.
|
|
The author does not self-approve. Darkwing and Dewey return scoped independent
|
|
verdicts before integration. Source tests do not prove live service transitions.
|
|
A read-only observation of the running connector is allowed after source review;
|
|
no live service stop/brake/restart or backend replacement is inferred. Existing
|
|
protected-operation and operator-acceptance gates remain in force.
|
|
|
|
## Continuation correction
|
|
|
|
Darkwing previously said he was continuing to this item but performed no action
|
|
before ending the turn. Jason called out the violation. This entry records the
|
|
actual start and ownership; a promise or dispatch is not completion. While the
|
|
author works, Darkwing prepares independent acceptance and reconciles records.
|