One cumulative control-board, webui and seat state. The four rows edit the
same files (scan.mjs, page.html, README.md, app.js), so they land together,
each on its own receipt:
- Row 18, Discord connector rows on the board (#1509): R3 approved by
Darkwing and Dewey, Gitea comment 26257, manifest 254403b8. Jason
accepted the visual test.
- Row 22, board attention status (#1503): Filbert approved R1, comment
26248, manifest e40b58ec; restart receipt 26249.
- #1511, task attribution (row 6 code phase): R2 approved by Filbert and
Dewey, manifest d4c96395. docs/TOOLS.md carries the approved --by usage
line (tools-usage.patch 86bcba3c).
- #1512, relaunch activity (row 6 pilot): R1 approved by Darkwing and
Dewey, candidate manifest 47769fad. All seven source files match it.
Row 16, internal development bootstrap (#1510): the seven files outside
shared records match Filbert's R1 pins, receipt 26204 (agents/researcher/*,
scripts/test-darkwing-launch.mjs, the bootstrap plan).
packages/webui/src/public/app.js is committed at its #1512 R1 pin ce7d79a4.
The working copy holds Dewey's unreviewed return-flow candidate on top of
that, and it stays uncommitted.
Also: the four row briefs and Darkwing's evidence records under
agents/darkwing/work, including the 2026-09-26 tree manifest and the #1512
re-run against 21e3e908. Serial acceptance command: 397/397, three runs.
The failures that only show when tests run concurrently are in #1509 engine
tests, and they reproduce on clean HEAD.
Suites on the exact staged tree: config 24, task 90, foundation 43,
conductor 17, release 14, auth 15, discord 63; package union 397/397
(serial); test-darkwing-launch 5/5.
Shared records (BUILD-LOG, QUEUE, CURRENT, DEFERRED, SESSIONS, AGENTS.md,
agents/README.md) follow in Sage's records commit.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
3.6 KiB
Discord connector board row
Current authorized queue item: row 18, #1509, pilot plan section 11. Jason assigned this to Darkwing and now explicitly requires automatic continuation to the next authorized item after each accepted iteration. This starts row 18, not unrelated gated work. Preserve the accepted row-22 attention correction.
Ownership and scope
Filbert implements in the canonical checkout on refactor. Darkwing independently reviews the exact candidate; Dewey reviews any visible presentation change. Single writer for this implementation: Filbert. Existing dirty files remain owned by their authors and must not be reset, adopted or overwritten.
Allowed implementation paths: packages/control-board source/tests/README and minimal packages/webui source/tests changes needed to display the connector and refuse replies. No connector source, bindings, secrets, launchers, systemd units, live service changes or files under ~/.mosaic. No commits or publication by the implementer. Darkwing owns shared tracking records.
Existing contract to implement
The original accepted connector brief supplies the interface:
- Discover one row per /discord/.json, with 0600 regular
non-symlink files. Project fleet, agent
<seat> (discord: <binding>). Validate only safe name/seat identity for discovery; never dereference or expose token paths, Discord/user/channel IDs, or the rest of the binding. - Sessions are under /sessions/discord-.
- Reuse the connector's read-only readPid/ownerState identity checks from packages/discord/src/journal.mjs. A positive live PID plus matching start tick and boot ID is necessary. Missing, corrupt, dead or unverifiable owners cannot be reported live. Do not signal, recover, unlock or rewrite anything.
- Show STOP presence as braked without interpreting its private contents. Liveness and braking must be distinguishable. Existing completed-reply idle semantics still apply to session activity.
- Refuse board replies server-side for connector rows even if a stale or forged registration claims a tmux destination. The UI must not offer reply.
- Avoid filesystem traversal, symlink reads and disclosure of private binding fields. A malformed binding must not manufacture an actionable row. Report discovery failures safely rather than dumping private content or credentials.
Daily counters are optional in the original brief and excluded from this first row. No new ingress, controller, Discord API calls or engine/model calls.
Acceptance and handoff
Implement and test discovery/privacy, positive and negative process identity, STOP/braked display, ordinary session state, server-side reply refusal and unchanged ordinary-agent replies. Test both board and WebUI integration with isolated fixtures. Preserve the accepted attention regression coverage.
Return an exact frozen candidate, changed paths and reproducible test results. The author does not self-approve. Darkwing and Dewey return scoped independent verdicts before integration. Source tests do not prove live service transitions. A read-only observation of the running connector is allowed after source review; no live service stop/brake/restart or backend replacement is inferred. Existing protected-operation and operator-acceptance gates remain in force.
Continuation correction
Darkwing previously said he was continuing to this item but performed no action before ending the turn. Jason called out the violation. This entry records the actual start and ownership; a promise or dispatch is not completion. While the author works, Darkwing prepares independent acceptance and reconciles records.