Head triple verified independently twice (orchestrator + f10-coder): local = origin = PR #1030 = pipeline #2182. Full step scan rather than a tests-complete inference. Queue guard not offered as evidence. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
112 lines
7.4 KiB
Markdown
112 lines
7.4 KiB
Markdown
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
||
|
||
**Phase:** EXECUTING — RM-02 FROZEN at `9b4d4beb`, CI green, review in flight; RM-03 implementing.
|
||
**Updated:** 2026-07-31 (mos-remediation orchestrator; seat active on `mosaic-fleet`).
|
||
|
||
## Head
|
||
|
||
- Mission charter + 15 decisions + 4-build plan: PERSISTED (`docs/remediation/MISSION.md`).
|
||
- HOLD lifted for this workstream (Jason 2026-07-31). Nothing implemented yet — planning first.
|
||
- Orchestrator seat `mos-remediation` is LIVE and owns the mission. Residency attestation: PASS.
|
||
- **TASK-0 DONE** — checkout repaired, all three gates green HONESTLY (no `--no-verify`), branch pushed.
|
||
- **TASK-1 DONE** — both planners delivered independently on clean context; reconciled into `TASKS.md`
|
||
(58 tasks across P0–P5, 7 convergences, 7 adjudicated disagreements, 3 escalated decisions).
|
||
- **NEXT ACTION IS NOT MINE:** DECISION-1/2/3 (`TASKS.md` §5) must be ruled before P0 dispatch.
|
||
RM-01 is dispatchable immediately regardless — it depends on nothing and blocks everything.
|
||
|
||
## In-flight
|
||
|
||
| Task | Owner | State |
|
||
| ------------------------------- | ------------- | --------------------------------------------------------------------------- |
|
||
| RM-01 reproducible checkout | — | **MERGED** `f58b3699` (#1027) |
|
||
| RM-02 gate registry ★keystone | rev-974 | **FROZEN** @ `9b4d4beb`; CI #2182 SUCCESS 8/8 functional; review in flight |
|
||
| RM-03 queue guard | coder-mos1 | implementing; CANNOT_ASSERT ruled **B**; build to READY then HOLD for Jason |
|
||
| RM-59 D-19 residual risk | — | blocked on RM-12/21/25 |
|
||
| RM-60 / #1031 CI trust boundary | Jason (infra) | option **B**; A does not fix the ordering defect |
|
||
| #1023 queue-guard attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES; do **not** merge |
|
||
|
||
**RM-02 head-triple verified (twice, independently — orchestrator + f10-coder):** local = origin =
|
||
PR #1030 = pipeline #2182 = `9b4d4beb0e0a…`. `Closes #1029` present. Full step scan, not a
|
||
tests-complete inference. `ci-postgres` FAIL read as the D-21 teardown artifact (test log shows
|
||
PostgreSQL accepting connections; test step OK). Queue guard **not** offered as evidence.
|
||
|
||
## Delivery gates — DOCTRINE CHANGE 2026-08-01
|
||
|
||
**The gate definition was incomplete from mission setup: the merge-gate verdict step was missing.**
|
||
Root cause (**D-26**): the gates were **restated from memory** into `MISSION.md`/`KICKSTART.md` instead of
|
||
**referenced**, and the omission propagated into every worker brief issued since. It then recurred _inside
|
||
the correction_ — which dropped five details including a security precondition and cited a file that does
|
||
not exist.
|
||
|
||
**Fix is render-not-restate, mechanically.** `MISSION.md` and `KICKSTART.md` now **reference**
|
||
`~/.config/mosaic/fleet/roles.local/merge-gate.md` and `~/.config/mosaic/fleet/roles/validator.md` and
|
||
state only the gate **order**:
|
||
|
||
> independent review (author ≠ reviewer) → remediation → **CI terminal-green at the exact head, full step
|
||
> scan** → **merge-gate verdict `GO`/`NO-GO`/`HOLD`** (commit-bound; **VOID on head move**; posted durably
|
||
> with enumerated evidence under its own minted identity) → **coordinator head-pinned merge**
|
||
|
||
- **After a `GO`, pushes freeze** — a doc tweak voids the verdict. Gate-ready is a **freeze point**.
|
||
- The coordinator assigns the gate seat; the orchestrator owns getting a PR _gate-ready_.
|
||
- **Queue guard is ZERO-INFORMATION until RM-03 lands** (D-23) — record it as
|
||
`queue-guard: ZERO-INFORMATION (inert, D-23, owner RM-03)`. _A mandated field must not become a
|
||
manufactured one._
|
||
- Gate seat identity: `gitea-mosaicstack-merge-gate` minted least-privilege, verified `push=False` —
|
||
it structurally cannot merge.
|
||
|
||
## Fleet seats
|
||
|
||
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
|
||
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
|
||
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
|
||
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
|
||
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
|
||
|
||
## Gate status
|
||
|
||
- Delivery gates active: author≠reviewer, diff-blind pre-registered checks, CI-green, merged-PR completion.
|
||
- Freeze: LIFTED for this workstream only.
|
||
- Git identity: `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
|
||
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
|
||
- Capability check (D-11b): before dispatching seat X to provider Y, verify
|
||
`~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token` exists. Token-file set = authoritative
|
||
capability registry. Mos owns provisioning; escalate missing pairs to him.
|
||
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
||
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
||
- Standing worker-brief doctrine (accreted, mandatory in every brief): don't weaken a RED test to make
|
||
it pass; if a check is unrunnable as written SAY SO, never silently substitute; `agent-send -f` never
|
||
`-m`; heavy artifacts off shared `/tmp`.
|
||
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
|
||
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
|
||
|
||
## Sequencing (from MISSION.md)
|
||
|
||
1. Spine + choke-point service (MACP wiring @ mosaic_orchestrator.py::run_single_task) + PG/Redis
|
||
⚠ **CONTESTED — see DECISION-1.** Both planners independently reject this wire-in point: that
|
||
controller is `"enabled": false` and references a dispatcher that does not exist here. Charter text
|
||
left UNCHANGED pending Mos/Jason ruling; do not treat it as settled.
|
||
2. Rotation daemon (finish Mission Control Plane, reuse packages/coord)
|
||
3. Comms service (envelope→service→PG/Redis→adapters)
|
||
4. Hygiene + conformance harness
|
||
Cross-cutting retirements: flat-file tracking, 3 MACP islands, silent MOSAIC BYPASS.
|
||
|
||
## Dogfood evidence — live failure classes, not hypotheticals
|
||
|
||
> Newest first. Oldest entries roll to `BOARD-LEDGER.md` via `board-roll.sh` when this file
|
||
> exceeds its 8 KB cap. Keystone detail is duplicated in `TASKS.md` §1a, so rolling loses nothing.
|
||
|
||
<!-- BOARD-ROLL:START -->
|
||
|
||
<!-- BOARD-ROLL:END -->
|
||
|
||
## Decisions log
|
||
|
||
- 2026-07-31 — Mission set up by Mos post-postmortem (15/15 decided). Dogfood posture active.
|
||
- 2026-07-31 — Mos: stale `.mosaic/orchestrator/mission.json` is RESIDUE of the disabled Python
|
||
orchestrator rail that this plan RETIRES. Do NOT invest in it; do NOT build on that rail. The 0/0
|
||
milestone banner is cosmetic. (Supersedes any plan to repair it.)
|
||
- 2026-07-31 — Mos: planners must be dispatched with GUARANTEED clean context, not requested-clean.
|
||
Prior default-socket planner sessions predate this mission; dirty context is the indicted hygiene.
|
||
- 2026-07-31 — mos-remediation: worker briefs forbid all git ops and restrict each worker to a single
|
||
named output file, so two planners can share one checkout without a branch race (M2-era incident doctrine).
|