Files
stack/docs/remediation/BOARD.md
T
mos-dt-0andClaude Opus 5 d9207d4c1a docs(remediation): bank D-52 — the fifth arrival defeated both the orchestrator and the coordinator
coder-mos2 built blocker 2's "protected/base artifact" fix, ran independent code AND security review on
its own fix, and returned HIGH CWE-353 against its own work: the baseline is not protected because
verifier, manifest, baseline, tests and lifecycle code are all PR-controlled, so rewriting them
consistently self-certifies. It stopped rather than invent a fourth local anchor.

Both of us authored the error in the same turn. I dispatched blocker 2 as "must come from a
protected/base artifact"; Mos ruled blockers 2+3 fixable in-PR; and the same brief told the seat that
blocker 1 had no local fix because PR code executes before the gate. My own pre-registered P2 had
already named it — the seven required gate IDs are an anchor list, and if the author can edit it that
is D-45 one level in. I registered the check, rev-974 confirmed it as a blocker, and I dispatched a
remediation reproducing it one level down.

That is the strongest evidence the principle is real: it defeats the people who wrote it, every time,
until the anchor is external. Knowing the rule does not protect you from it.

Ruled (b) honest narrowing, and the sibling distinction is what makes it correct rather than a
climbdown. Blocker 1's local check can be vacuously passed — seam=HEAD certifies over nothing — so the
claim is REMOVED. Blocker 2's baseline genuinely detects accidental drift and fails only against an
adversary rewriting baseline, manifest and verifier consistently, so the claim is NARROWED and the
check kept. Accidental drift is most real-world drift.

The wording is the whole ruling, because this is D-48 territory and neither seat may repeat it: no
"protected" or "independently anchored" over a same-checkout baseline, positive claim and adversarial
gap in the same breath, plus a negative control that goes RED if the check ever claims protection it
does not have.

Increment trajectory surfaced to Jason: two RM-02 anchors now require RM-60 and each thins the
(d)-strict increment. If a third needs the same boundary the increment may thin past worth.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-01 14:43:09 -05:00

7.4 KiB
Raw Blame History

mos-remediation — LIVE BOARD (keep < 8 KB)

Phase: EXECUTING — RM-03 at owner-merge; RM-61 MERGED; RM-02 keystone is the front. Updated: 2026-08-01 — seam crossed; successor seat resumed, attested from the files, and is driving. ⚠ That was a MANUAL pane respawn (prior seat ~803k tokens): it validates the checkpoint+rehydration design, NOT a lifecycle mechanism — P-LIFECYCLE rotation does not exist yet (D-41 / RM-62).

Head

  • Charter + 15 decisions + 4-build plan: MISSION.md. Backlog + all findings: TASKS.md.
  • Planning DONE (58 tasks, P0P5). DECISION-1/2/3 all RULED by Mos 2026-07-31 (TASKS.md §5) — nothing is waiting on a decision. D-2's availability target is Jason-pending and non-blocking.
  • Executing, not planning. RM-01 is MERGED; three lanes are live (see In-flight).
  • Orchestrator seat mos-remediation LIVE, owns the mission, resumed across the rotation seam 2026-08-01 and re-attested to Mos from the files. Residency attestation: PASS.

In-flight

Task Owner State
RM-01 checkout MERGED f58b3699 (#1027)
RM-03 queue guard Jason (re-sync) MERGED 58b971ab (#1032), #1019 closed. ⚠ NOT DELIVERED: installed guard still the broken one (291 lines / 0 ASSERTED_NOT_READY vs main 482 / 5). Re-sync via mosaic upgrade, then prove it blocks a KNOWN-RED pipelineD-51
RM-02 registry ★key coder-mos2 Round 4 @ fbb61912. Blocker 2 hit RM-60 again (D-52, CWE-353) — seat stopped, both orchestrator AND coordinator had authored the error. Ruled (b) honest narrowing; blocker 3 + (d)-strict unchanged. 2 anchors now need RM-60
RM-61 CI exemption MERGED f4fd5967 (#1033). #1034 closed; #1000 stays OPEN (retirement trigger). Exemption is on main
RM-59 / RM-60 Jason (infra) tracked deps; RM-60 option B
#1023 queue attempt Jason SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do not merge

For the incoming orchestrator — read this before acting

  1. Lane state lives in the In-flight table above — this item does NOT restate it. It went stale three times in one session by duplicating that table (D-26's class). Read the table. ⚠ And re-derive any board claim from the provider before load-bearing use (D-43) — the board is sole-written and has no independent verifier.
  2. docs/remediation/TASKS.md is authoritative, not the newest voice in a chat. It holds 53 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-52 + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
  3. MISSION.md carries the first-class principles — read them there, they are not listed here. Two added 2026-08-01: the anchor must live outside the audited party's authority (D-19/D-25/D-45, third arrival) and no universally-quantified check may pass over an empty set (D-44/D-46).
  4. Seat identity: export MOSAIC_GIT_IDENTITY=<seat> is stripped by a context reset (D-34) — every dispatch/rehydration brief must re-export it, or the seat cannot use its credentials.
  5. Scan CI from -f json, never default text — text mode omits clone (D-33). State counts.
  6. The queue guard is zero-information until RM-03 merges (D-23) — never cite its green.
  7. The bounded CI re-roll used on RM-02 was a one-time stopgap, NOT policy. A per-PR free re-roll is D-21 normalisation. Do not repeat it; RM-61 is the fix.

Delivery gates — REFERENCE, do not restate

Canonical: ~/.config/mosaic/fleet/roles.local/merge-gate.md (verdict authority) + ~/.config/mosaic/fleet/roles/validator.md. Order and the freeze/zero-information rules: MISSION.md and KICKSTART.md. Read them there (why: D-26, in BOARD-LEDGER.md).

Fleet seats

Roster rolled verbatim to BOARD-LEDGER.md; live truth is mosaic fleet ps.

Gate status

  • Freeze: LIFTED for this workstream only.
  • Git identity: orchestrator runs MOSAIC_GIT_IDENTITY=mos-dt-0 INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
  • Capability + seat identity (D-11b / D-11a, incl. the false-NEGATIVE twin): authoritative in TASKS.md. Short form — assert the DIFFERENTIAL as that seat (authenticated push:true vs unauthenticated push:false); a single endpoint can be true for anyone or 403 for an unrelated scope. Full text rolled to BOARD-LEDGER.md.
  • LIVE HAZARD (D-37) — one shared .git/config re-identifies EVERY worktree at once. Every seat, including rev-974's review worktree, currently authors as coder-mos1; MOSAIC_GIT_IDENTITY does not override it. STANDING ORDER: commit with explicit git -c user.name=<seat> -c user.email=<seat>@…, and NOBODY rewrites the shared config mid-flight. Real fix authorised, Mos owns it, sequenced at a quiet seam. #1024 implicated. Detail: D-37.
  • Standing worker-brief doctrine (mandatory in EVERY brief): re-export MOSAIC_GIT_IDENTITY (D-34); commit early/WIP (D-31); don't weaken a RED test to pass; if a check is unrunnable SAY SO, never substitute; agent-send -f never -m; artifacts off shared /tmp; scan CI from -f json (D-33); relay observations into an open review, NEVER your own conclusion on an open check (D-39); the author never adjudicates their own PR's blocker status — surface evidence, prepare the fix, hold.
  • Remote control: native /remote-control NOT wired in this runtime. Path is Mos-relay (Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.

Decisions log — full record in TASKS.md

All 53 findings (D-1…D-6 in BOARD-LEDGER.md, D-7…D-52 + D-38c in TASKS.md) and every ruling with its rationale live there. Not duplicated here. The history of why this board must not restate — six stale copies across two seams — is rolled verbatim into BOARD-LEDGER.md.