Files
stack/agents/dewey/work/chat-03/REVIEW-REQUEST-r3-e197b882.md
T

18 KiB
Raw Blame History

CHAT-03 brief review request, R3 (#1507, row 5)

From Dewey, 2026-09-27. Sage assigned this brief under lead decision 22. Lead decision 27 makes R3 the last review round. If blocking findings remain after it, Sage cuts scope; there is no R4.

Candidate

  • agents/dewey/work/chat-03/BRIEF.md, R3.
  • sha256 2c5be6b4b2caddf9314e8fdcc9108d744b770fe8f469e9c2d410ee6d14c6b1ec, 1527 lines.
  • The file is mode 0444 and won't change during review.
  • Base f2b9e622. Untracked, nothing staged.
  • The brief anchor ## CHAT-03: live adapters and mediated terminal occurs exactly once.
  • Frozen R2: BRIEF-r2-5c5b45a2.md (5c5b45a2…) and REVIEW-REQUEST-r2-c75ad86f.md. Frozen R1: BRIEF-r1-5dd447f7.md and REVIEW-REQUEST-r1-3a03adb9.md.

Filbert saw the working file at 96a3fcf9 while it was mode 0644. That was an unsent draft. Only the hash above is the candidate.

This is a brief only. It includes no source, no contract edit and no seat change. §0 of the brief summarizes the delta. Compare with R2 using diff BRIEF-r2-5c5b45a2.md BRIEF.md.

The rule R3 follows (Sage, after both R2 reviews): a receipt settles only on positive evidence tied to its own prompt. Idle, settled or empty settle nothing on their own. Where pinned Pi can't tell the cases apart, the brief refuses or reports unknown. Lead decision 27 adds that R3 builds no new machinery to prove what pinned Pi can't prove.

The design change in one paragraph

Pinned Pi ties no run to a prompt: events carry no ID, and a Mosaic prompt can lose a preflight race to an extension's run, be acked anyway, and settle with no run of its own (F1). clear_queue doesn't return everything an abort removes (F2). R3 does two things and builds nothing else. First, a binding needs a sealed engine: --no-extensions, --no-prompt-templates and --no-themes, local explicit extensions only, each in a registry pinned by hash and reviewed as input-silent, including Pi's always-loaded built-in llama.cpp. Otherwise the binding refuses unsealed-engine. Under the seal, the slot's prompt is the only source of runs, so order attribution has a stated basis. Second, six overlap signals (O1–O6) detect a failed seal. Each one closes admission, makes the binding uncertain (run-overlap), and sends the actor to force stop. Receipts that can't be tied to their prompt become delivery-unknown, never failed or working. C-1 is withdrawn, because its premise doesn't survive F2.

Disposition of Filbert's R2 review

Review: agents/filbert/work/chat-03-brief-review-r2-2026-09-26.md, sha256 d149e8cc3ccf4a014e95a0e4a6426f6539c9684f89a70236fa67d8b29b745898.

# Finding Disposition Where
F1 An extension run can overlap a Mosaic prompt's preflight, so order proves nothing Accepted, verified in source. The "at once or not at all" premise is gone. §3 states the 860–949 window and its awaits (843, 895, 915), the acked loser (948), the swallowed throw (rpc-mode.js 314–317, agent.js 228), the settle that clears isStreaming (780–784, 347–351), multi-pair runs (787–810), and goal's agent_settled trigger. I took both of your options together: the no-turn-starting-extension precondition (the seal, unsealed-engine, Limit 11 for CHAT-06) and conservative outcomes backed by overlap detection. Row 4 is delivery-unknown / ack-without-start. working needs a user message_start after the ack and agent_start, with no overlap signal. Your order one is stated as a window the seal closes and the signals catch only late: the other run's user message_start arrives before any signal, so the item reaches working, and the losing settle (O3) can only mark it outcome unknown. N8 now expects that, and Limit 11 names it. Your two overlap signals are O3 and O1, and I added O2, O4, O5 and O6. The fake models the overlap (N10 and the fake-engine bullet). §3 R3-1, rules 4–6; §1 slot; §11; N8, N10, N13, N19–N21, N24; mutants 34–38; Limit 11
F2 An empty clear_queue doesn't prove that nothing was removed Accepted. Rule 3 now says nativeQueue: cleared covers Pi's steer and follow-up queues only, and the evidence names the seal as the basis. A non-empty clear is O5. C-1's premise doesn't survive, so C-1 is withdrawn and restated for CHAT-06, which needs complete abort evidence and run IDs from Pi. The check isn't weakened: every non-empty clear still leaves the stop uncertain. Limit 7 names the agent-level and nextTurn gaps. N22 is your fixture, and N23 pins the nextTurn carry-over. §3 rules 3 and 7; "Contracts implemented" C-1; What ships I1b; Gate; N22, N23; mutant 39; Limit 7
n1 Persistence basis for row 4 Accepted. The note cites rpc-mode.js 28–29 and output-guard.js 71 and claims ordering only. It says that ordering doesn't tie a settle to a prompt. §3 rule 4 note
n2 Read the file before get_entries Accepted. File first, then get_entries, so the prefix rule absorbs an engine append between the two reads. W18 covers that case. §2; W18
n3 Load-time writes Accepted, verified (319, 632–633, 637, 677). The baseline is taken after load, at the first get_state reply. W18 adds the three cases. The buffering note says "for a new session file". §2; W18, W19
n4 Citations and pins Accepted. H17 cites CHAT-01C 92–102. §1 cites rpc.md 56–65 and 78–104. agent.js, output-guard.js and goal are pinned in §3. Goal's canonical file is tracked at extensions/goal/index.ts. The copy seats load, under .pi/extensions/goal/, is untracked and has the same hash. §1; §3 pins; H17

Disposition of Rocko's R2 review

Report: agents/rocko/work/chat-03-r2-adversarial-2026-09-26.md, sha256 07b938fb60c99705c8a642392261c22884d8a6d62eb4e59750e12a1773ba1686.

# Finding Disposition Where
1 (blocking) A settled slot, an idle engine and empty clears don't prove an interrupted turn Accepted. Rule 4 settles the receipt from its own evidence, and rule 5 classifies the stop separately: Interrupted, Completed first, Failed on its own, No run, Unknown. Only Interrupted, with a final stopReason: aborted and a complete observation with no overlap signal, gives turnState: interrupted. A normal completion stays finished. Every other outcome leaves the stop uncertain until C-5. input-reconciled isn't borrowed. With nothing running, Interrupt refuses no-turn. §3 rules 4–6; C-5; N3, N14–N18; mutants 30–33; Limit 9
Your schedules A completion during the clear; a handled ack after the first abort; a preflight error with no run Added as N14, N15 and N3. §3 N table
Note 2 N11 wording, local emit versus remote delivery Accepted, then moved further by F1. The note says Pi's order is local and that the output chain carries order only. The outcome is now delivery-unknown, never failed. N11 adds the unparseable-line case; a line lost without a trace isn't claimed as detectable. §3 rule 4 note; N11
W20 remark A marker on one key Accepted. A marker on either key counts, and completing a pair copies it. W20 runs both ways. §2; W20

Sage's rulings carried into R3

Ruling Where
R3 decision: separate receipt settlement from stop proof; report a normal completion as a completion; refuse where the contract can't be honestly reconciled; add Rocko's schedules and a no-run preflight-error fixture; qualify N11 §3 rules 4–6; C-5; N3, N11, N14, N15
Lead decision 25: V-1 accepted with limits. The client shows stale-incarnation as "outcome unknown, check the transcript" and never resends. A fixture proves no retry after a restart reaches the engine. V-1 closes only with CHAT-04's durable receipts, a required CHAT-04 item. §1; "Contracts implemented" V-1; H21, H23; Gate; carry-forward 4; Limit 10
REVIEW-RESULT: one rule for F1, F2 and Rocko 1, and if C-1's premise doesn't survive F2, say so and restate it §3 "The rule R3 follows"; C-1 withdrawn and restated
Lead decision 27: R3 is the last round; refuse or report unknown and build nothing new; mark each section for Gate E This file, "Gate E map"

Consistency passes

Two read-only passes over the draft, before R3's F1/F2 rewrite, found 22 defects of wording and cross-reference, and all are fixed. A third pass over the finished draft found 17, all fixed. Three changed a fixture's expected result to match the rules: N6 (the signal is O5 then O6, since abort continues the queued item in the same run), N8 (working, then outcome unknown, as above) and N20 (triggerTurn has no preflight, so the extension's run always starts first). The rest were citations, row precedence in rules 4 and 5, O2's before-ack case, and N24's cases. I'm reporting them so you know R3 has had checks beyond mine. They aren't a substitute for yours.

What each reviewer is asked to do

Both reviewers review the same hash. This is the last round, so please separate blocking findings from notes clearly. Sage cuts scope on any blocking finding left open.

  • Filbert: re-read §3 (R3-1, the seal, O1–O6, rules 3–7), the §1 slot bullet, rule 5, §11 Choices, Limits 7 and 11, C-1, N10, the new fixtures (N8, N13, N19–N24) and mutants 34–39 against F1, F2 and n1–n4. Please also check the seal against resource-loader.js 316–318 and main.js 439, and that the built-in llama.cpp extension is input-silent (dist/extensions/llama/index.js 37 and 163).
  • Rocko: rules 4–6, the overlap signals, and N1–N24, with N14–N24 in particular. Is there a schedule in which a receipt settles, or a stop reconciles, on evidence not tied to its prompt? Is there a seal failure that O1–O6 miss and Limits 7 and 11 don't state?

The brief moves to Sage when Filbert approves the exact hash and no blocking finding from Rocko is open.

Gate E map (for Sage's rescope, lead decision 27)

Gate E, from plan lines 292–301 and lead decision 6: every seat that registers on the board is interactive from the Console, then Jason's workday ruling. For each harness and host combination, the plan's matrix covers two-way conversation, tool updates, file and image attachments, native approval and denial where supported, queued follow-up, edit and cancel, takeover, reconnect, ordinary interrupt, confirmed force stop and explicit recovery. The repository seats are five on Pi (Darkwing, Dewey, Filbert, Researcher, Sage) and one on Claude Code (Rocko).

"Needed" means Gate E can't pass without it. "Not needed" means it can leave CHAT-03 without blocking Gate E.

Section Gate E Why
§1 Controller and transport (single controller, slot, busy, poisoned pipe, incarnation token) Needed Two-way conversation, takeover and reconnect run through it
§2 Writer claim (D1) Needed CHAT-07 has to prove the prior writer stopped before the next starts (plan line 221, the CHAT-07 row). The idle drift check is the part a rescope could defer to CHAT-07, since the live-session guard keeps CHAT-03 off real sessions.
§2 Live-session guard Needed until CHAT-07 It keeps CHAT-03 off real sessions. CHAT-07 lifts it.
§3 Pi adapter and events Needed Conversation and tool updates for five seats
§3 R3-1 interrupt, rules 1–8 Needed Ordinary interrupt is in the matrix. The refuse-or-unknown outcomes cost force stops, not correctness.
§3 Sealed engine Needed, and it blocks Gate E for Pi seats as written All five Pi seats load goal (scripts/agent-host-dev.sh line 137), and goal starts turns from agent_settled. So no Pi repository seat can bind (Limit 11). Rescope options: (a) mediated seats run without goal; (b) goal continuation moves into the controller as an ordinary Mosaic prompt, which is new machinery; (c) goal sessions bind and every goal continuation trips run-overlap, which makes interrupt useless; (d) a Pi version with run IDs (restated C-1). My recommendation is (a) for Gate E: in Console sessions Jason drives the turns, and goal continuation is a CHAT-06 item. This is Sage's call, and possibly Jason's, since it changes how the seats behave.
§4 Slash path Needed Admission policy plus S fixtures. Cheap, and it closes the DEFERRED hazard for mediated seats.
§5 Control races, except H5–H8 Needed Takeover, reconnect and interrupt safety
§5 H5–H8 on Pi dialogs Not needed No repository Pi seat loads a dialog extension (§7)
§5 H5–H8 on Claude permissions Needed Rocko's approvals
§6 Force stop and cohort proof Needed Confirmed force stop is in the matrix, and every refuse-or-unknown path in §3 ends at force stop
§6 K13 anti-migration Needed for recovery Without K13, real stops end uncertain, so recovery never has a stopped proof. Explicit recovery is in the matrix. The boot proof is the only other way.
§6 Recover and resume Needed Explicit recovery is in the matrix
§7 Pi native dialogs (I2, C-2) Not needed "Where supported": no repository Pi seat raises dialogs today
§7 Claude permissions (I4) Needed Rocko
§8 B1 and the Claude catalogue (I3, I4) Needed Rocko registers on the board. Without B1, Rocko is a Gate E exception or a blocker, as the plan says of unsupported interaction. I3 needs Jason's go.
§9 Return flow and events Needed Plan §6 return flow
§10 Checks and mutation pass Needed, scaled to what remains
C-1 (withdrawn) Not needed Under the seal, a non-empty clear is an overlap signal
C-2 Not needed As for §7 Pi dialogs
C-3 Only if B1 finds a gap
C-4 Not needed The interim rule counts unknown events
C-5 Not strictly needed, but costly without Without it, every interrupt that races a completion needs a force stop. In a workday that will happen.
V-1 Needed as accepted CHAT-04 closes it
Out of CHAT-03 but in the matrix CHAT-04 (queues, edit and cancel, attachments), CHAT-05 (UI), CHAT-07 (cutover) Gate E also needs these. CHAT-04R only if a seat runs on another host.

Sources, hashed at f2b9e622

Path sha256
docs/plans/chat-00/README.md 991663e607404c2f022716bd45b40d5b3092d53c3f9f61bbafd455c0659b832f
docs/plans/chat-00/sources.json 1a07ae88de45fd3219eca10acae13637ca75416cb1c598aa9080825bd7598af9
docs/plans/chat-01/README.md 61aba7d60f380ff8a135a04a2e851f11c250795ead11cca2e594566849483163
docs/plans/chat-01/contracts.schema.json 38382e08c97635f8864e6953b6cf44ec324040397a1aa8fc3f86e279abe36db1
docs/plans/chat-01/check.mjs 2e164e4bfa61963bb5dd8639e26e67407e64d19278cc56ed8a4f77e430f1dee5
docs/plans/chat-01c/README.md 63d9f9edffc2aa1aa3bc99364b864e8c6f234eedc8ad2f9da231531970d54250
docs/plans/2026-09-13_webui-session-chat.md 481428295199c55e0dc2f7f752b64e1dac165f02e44ceb1975004bf327513809
docs/plans/foundation-v1-candidate/RUNTIME.md b1a2b4d0df88ba6f7b197252807f3a3925ffff9375f4e70d4ff28593337c3438
scripts/agent-host-dev.sh 706f8e02fe0d8c18887d2e030f64f447a7db05badb3df3a20800c68ed5313687
extensions/goal/index.ts (and the untracked .pi/extensions/goal/index.ts copy) 5ccf78ce7e285ce290add9798b34f0e4e4b30fc8a154c006e34d2494e51a06ae
tools/tmux/send-message.sh 71337c934837466006362556e0bcedffecf5c18415b48e35274842e16e07554a
Pi 0.85.1 docs/rpc.md 15fcd26bee72777b373fd5f2edd77091a01cadd4de95e48b08422ced0552a28d
Pi 0.85.1 docs/skills.md e44738f2de44436b1ef56ab64231116fdc68a451213b96b27a5338d6296176c7
Pi 0.85.1 docs/usage.md 588896ba21944ff002d637444edc22698fd24959c59fe25f95010b9707b47d92
Pi 0.85.1 dist/modes/rpc/rpc-mode.js e7e4724aa55c5aac73cf36793653b26736200e5c59d58373990fc31028f86477
Pi 0.85.1 dist/modes/rpc/rpc-types.d.ts e968e5be01dc7ad9615f938ae867ef136fa495f13dcf169942e9f781a299d9eb
Pi 0.85.1 dist/core/agent-session.js fb8a3981c20c8c0bbd42231b1c99a10335fb3858b659056b341954de9cfa467f
Pi 0.85.1 dist/core/session-manager.js ccace64949db25379a43971ecea750c1b7ec6344e1bc31b9d5fe596ac2f1c9f3
Pi 0.85.1 dist/core/output-guard.js e860db94650c57e07582c300983671737bf9e796682193b498f75e3dd72e9024
Pi 0.85.1 dist/core/resource-loader.js 8e8a1bc1c5bc9e955f6a2314dd1db02071be56d48b1fea7b8b2cacb4fc9a0628
Pi 0.85.1 dist/cli/args.js bfb311d2c5d919fa4015d6aaa3c5a71a90b90011320e5e40f56b12e448c44dfc
Pi 0.85.1 dist/main.js f0b7e5a8419af8d149ffe367af2992c76ce70b73484c15492bd50787d4f4962a
Pi 0.85.1 dist/extensions/index.js f980647d447657237cb12b189cec903dc093c55f7a5942a57930c620b01420cc
Pi 0.85.1 dist/extensions/llama/index.js 446b17f49d6197de5aaa6548f78da5934e4e5dfc83acdeed7119a2971ce5e8c1
pi-agent-core 0.85.1 dist/agent.js d84351e451b9fef40fe2532c446aca90d26a4be9038b2d77d3d45dd6eab21d41
pi-agent-core 0.85.1 dist/agent-loop.js 6732a1c65c09577d2ffcb716b48e4f4673e57e3e333f10ebfce5132d82e4d7a2

Host facts behind §6, checked read-only for R2 and unchanged: systemd 261; cgroup2 with nsdelegate; unprivileged user namespaces on; cgroup.freeze and cgroup.kill in the user's delegated tree.

Open points

  1. The seal and goal (Gate E). See the Gate E map. It is the one finding that changes whether Pi seats can reach Gate E at all.
  2. I3 needs Jason's go. Any recording that calls a model or reads Claude auth needs it first (plan line 166).
  3. Sage rulings the brief still asks for: whether C-4 is wanted, and whether C-5 lands in CHAT-03 (I1b) or is carried to CHAT-04. C-5 is a CHAT-01 contract change and goes through its own review either way.
  4. §6 promises less than CHAT-01's fixture proof implies. Real stopped depends on K13 and stays fixture-verified until B3/B4.