34 KiB
Lead decisions, 2026-09-26
Written by Sage (lead). At 20:02Z Jason asked for my decision on the open items
("You are lead... Proactive movement and intelligent decisions"). I read that
as his say-so for the push and the local operational calls below. It does not
cover credentials, the ~/.mosaic restriction or the live Discord service,
which stay with him. Each item names who decided it and what happened.
Decided and done
- Push
refactor. Done at 20:03Z with the jarvis identity: origin/refactor43d7574d→42c08d52(21e3e908,af4203ca,0f5b7cb9,42c08d52). Fast-forward only. All eight suites were green at42c08d52. - No merge into
next.nextis the old monolith:apps/, Woodpecker CI and the npm packages behind the estatemosaicCLI that the live fleet still runs.refactoris 172 commits ahead of it, andnexthas one commit refactor lacks (2101c9b4, a v1 git-tools fix, #1502). A merge replaces the default branch's content, may trigger CI and publishing, and could break the fleet before it is retired. Merge conditions: row 8 (fleet retirement) done, a CI definition for the new root, and2101c9b4either carried intov1/or ruled moot. Until thenrefactoris the working branch and pushes stay fast-forward only. - Control board restarted at 20:03:52Z so #1512's relaunch notice runs
live. Old PID 3414098 (from 09-14) stopped on SIGTERM; new PID 3977979,
log
/tmp/control-board-20260926T200352Z.log, same flags (none), same port 7331. Before and after: 44 sessions, identical counts, seen state kept;relaunchedAtnow appears in/api/board. The WebUI (PID 1266267) reads files from disk and needed no restart.
Decided, work under way
- Queue as data (#1508). Section 8 of Filbert's plan is the
specification (sha256 124b6f9e…). Rocko reviews round 3.
- Q1: Gate G reads "run
scripts/mosaic queue nextand do it". - Q2: Gate G runs on a Pi launcher (
--fresh);nextrefuses without an identity. - Q3: the CLI never commits; the lead commits the queue files by explicit
path after
scripts/test-queue.sh. - Q4: D posts only with an explicit per-seat credential file and refuses the default. It is built and tested against a fake transport.
- J1, J2, J4, J5: as proposed in section 7.2. J6: closes = issues, not
narrowed without a logged reason. J8: E's budget is 12 Gitea calls at
most, 0 with
--no-issues. Reduced liveness gate: yes. E before D: yes. - J3 (every row has a brief), J7 (dropped), J9 (row 8 stub): decided earlier today.
- No separate journal file. The log lives inside
queue.json, written by temp file, fsync, rename and a directory fsync. The lock islink()of a complete record, with no automatic reclaim.
- Q1: Gate G reads "run
- Gate F waits for a T3 source. The ledger's Table 2 reads only Pi session logs. Filbert confirmed no Pi log carries T3 traffic, so the Human column cannot see T3 seats. Darkwing briefs a read-only T3 thread source after the #1509 engine fixes. When it exists, Sage picks Filbert's Gate F item and Jason sends nothing.
- Gate E "all seats" means every seat that registers on the board. T3 threads are listed as not covered until they carry identity.
- Sage launch files. Dewey reviewed them (revise, small). Sage made the
revisions:
sageis added to the launcher test, the README is rewritten for the lead role, and the seat reads but never writes the old DYOR records under~/.mosaic. It creates no new DYOR records until Jason names a location. Dewey re-reviews, then updates the other seats' persona files that still name Darkwing as lead.
Jason's rulings (walkthrough, 20:19Z to 20:31Z)
- Seat tokens for piece D's live round. Jason ruled at 20:19Z: yes, in
place. Piece D reads each seat's own Gitea token by path,
~/.mosaic/fleet/agents/<seat>/secrets/gitea-mosaicstack-<seat>.token(0600), read-only. It makes no copies and changes nothing under~/.mosaic. Sage's Gitea calls use jarvis. Darkwing and Dewey have write:repository, and Filbert and Rocko have write:issue only. - Discord connector restart. Jason ruled at 20:20Z: one restart, after
Rocko approves 6b and it is committed, and row 25 goes live in the same
restart. Steps: back up the binding to the Sage evidence directory, add the
setsparkkey (keyFile~/.config/setspark/keys/sage.json, never read), rundiscord.sh check, restart, then Jason's live check (one work item, one proposal approved by button). - Fleet retirement scope (row 8). Jason ruled at 20:21Z: dev seats only.
orch-01, plan-01, rev-code-01, rev-code-02, code-be-01 and code-dogfood-01
get no new work and retire because the T3 seats cover them (Sage leads,
Filbert plans, Rocko reviews, Darkwing and Dewey build). Jason stops each
process himself or tells Sage to, one seat at a time. The other eight live
fleet seats (jarvis, joe, huey, ricer, topher, velma, zane, resume) are
outside row 8. Credentials stay in place (see piece D above). The
~/.mosaicrestriction still stands. - DYOR records. Jason ruled at 20:23Z: DYOR work belongs in
/mnt/storage/src/dyor-stack-v4/, a separate project from SetSpark. Sage has moved from DYOR to SetSpark tasks. Sage's SOUL, CONTEXT, README and DISCORD-USER files change to match, and that commit lands before the next Discord restart so the Discord Sage picks it up. - One live reply test in the WebUI. Passed. Jason sent "ping" to
researcher at 20:10:57Z and "pong" came back at 20:11:06Z.
/api/boardshowed it at 20:15:18Z. Dewey went through 30 board sends to repo Pi seats. 29 got a final answer in the same session file, and the one miss was a seat relaunched mid-turn. No second return defect was found. Jason confirmed at 20:31Z that "pong" appeared in the inspector without Refresh. The 09-13 report was about the missing thread view, which CHAT-02 builds. skills/aws-*. Jason ruled at 20:25Z: add them to.git/info/exclude, a local ignore that is never committed. Done at 20:26Z. That covers the 20aws-*directories and two more from the same 09-21 install,launch-with-awsandsigning-in-to-aws. They stay where they are and no longer show ingit status.- Row 5 CHAT-02 to 08. Jason ruled at 20:31Z: go on CHAT-02 only, at
Dewey's brief 636b0fac (Filbert approved R4). CHAT-03 to 08 stay held, and
Sage takes CHAT-03 back to Jason before anyone starts it. Order: the board
Host and Origin guard (Rocko reviews), then the
packages/conversationbackend, then the Console. Filbert reviews the code, and Darkwing reviews the two board routes. CHAT-03 owns the Claude catalogue after B1.
Added later the same day
-
CHAT-02 brief (Dewey, sha256 314da8b0…). Sage ruled D1 to D4 at about 20:18Z:
- D1: the writer-claim record and R3-1 move to CHAT-03.
- D2: Pi only in CHAT-02. The Claude catalogue refuses
unsupported-harnessuntil B1 has evidence. This narrows the plan's "both harnesses". - D3:
packages/conversationis a library with no server. The board adds two read-only routes, and Darkwing reviews that change. - D4: Dewey writes the backend, then the Console. Filbert reviews.
- D5 (the go on CHAT-02 to 08) is still Jason's.
-
Discord connector restart held. Jason said to restart before 20:17Z. The unit runs from this checkout, and the tree holds Darkwing's uncommitted, unreviewed #1509 engine change (
engine-pi.mjs, the newengineBusy). A restart now would load it. The only committed Discord change since the 18 September restart is43d7574d(row 25), which does nothing until the binding gets asetsparkkey. So a restart today would change nothing except to pick up unreviewed code. Sage restarts once, after Rocko approves 6b and it is committed. If Jason wants row 25 live, the binding change goes in the same restart.discord.sh checkpassed at 20:17Z. The service was idle, with the last turn on 09-18. Rocko's 6b R1 verdict (about 20:34Z) was request changes. The high finding is that removing the grace lets delayed events from an old run resolve the next prompt (reportagents/rocko/work/discord-engine-busy-r1-review-2026-09-26.md, 047dbd8f). Darkwing is on R2, and the restart stays held. -
Board guard live. Rocko approved Dewey's Host and Origin guard (de9ff942), and Sage committed it as
d1629d61after the eight suites, control-board (121/121) and webui (9/9) passed on an index export. It was pushed. The board restarted at 20:40:43Z: old PID 3977979 stopped on SIGTERM, new PID 288909, log/tmp/control-board-20260926T204043Z.log, the same flags and port 7331, 44 sessions before and after. Live checks: a foreign Host on/api/boardreturns 403, a foreign Origin onPOST /api/replyreturns 403, and the WebUI proxy's/api/boardreturns 200. -
Row 25 was never live. Before 20:56Z
discord.sh checkpassed with the newsetsparkkey, but it listed no SetSpark verbs.resolveToolRootsdroppedtools.setspark, so pi never got the record verbs and the connector never built its SetSpark client. Passing the validated object through as-is would also fail, because the extension refuses itsmaxResponseBytesas an unknown key. Sage wrote the fix with a test that fails first (binding to extension round trip). The connector's client now uses the validated object, which keeps the response cap. The README now marksprincipalas required. The eight suites passed on an index export, and the check lists the eight verbs. Rocko reviews the staged diff (agents/sage/work/row25-setspark-fix.diff, 4dec1898…). The restart waits on that verdict and the commit. -
Gate F brief (Darkwing, 08959a05…). Sage ruled on the three questions Darkwing had marked for Jason:
- Gate F is on by default. A missing DB exits 1 and names
--no-t3. - The
t3:unmappedrow stays. - The 14 old Discord Bot headers stay as recorded and appear only in the JSON diagnostic.
The 6a uppercase-class fix rides in Gate F. Filbert reviews the brief, and no code starts before the verdict.
- Gate F is on by default. A missing DB exits 1 and names
-
Discord restarted with row 25 live. Rocko approved the fix, which is committed and pushed as
6c06a6f3. The restart ran at 20:58:03Z: PID 890894 was replaced by 499064, the gateway was READY at 20:58:04Z, and pi has the SetSpark verbs. Jason's live check comes next. -
Gate F brief approved. Filbert approved R2 (e8300cb6…); his review is at bb02d8d3…. He corrected one of his own facts: a cleanly stopped T3 database in a read-only directory fails with 1544, as Darkwing measured. Either way it exits 1. The three nits ride in the build. The JSON records which database file it read, so a fixture can't pass for Gate F evidence. Darkwing builds. Filbert reviews the code, and Sage commits.
-
Queue as data (#1508) plan approved. Rocko approved round 6 (282fabbb…, report 80cde839…). One ordering note goes to the builder: capture H before the step-1 canary that reads from it. Build order is the plan's section 1. Darkwing builds Gate F first, because row 6 closes on it, then Piece A. Sage splits A into A1 (journal, lock, CLI, verify) and A2 (migration, render, dispatch), each with its own Filbert review, so each round stays small. C ships inside A1. Gate F's code goes ahead on Filbert's verdict, without a separate look from Jason. The design calls are the lead's (item 12).
-
Row 25 approvals, second fix and restart. Jason's live check found no Approve button. DEC-009's approvers had been stored as names, and the connector refused them. Sage fixed it so the model writes user names, the connector maps them to Discord ids, and no id reaches tool text. Rocko approved R3, and the fix is
20ea5a0b, pushed. Sage restarted the connector at 21:30:21Z, the second restart today. It is a local dev service, and Jason was waiting on the check. Two design calls:- A user id or name change with
setsparkon needs a restart, not a reload. - Tool text drops every Discord user id, including ids the binding doesn't know. The SetSpark service accepting free-text approvers is reported to Jason as a shared-signals gap. Mosaic doesn't change it.
- A user id or name change with
-
CHAT-02 backend committed and live. Filbert approved the code at R2 (3b14d66c…), and Darkwing approved the route changes at R2 (b9d92003…). Sage committed the nine pinned files with the packet, the evidence and the three reviews as
a5beb6d9. The eight suites, conversation and control-board 153/153, and webui 9/9 passed on an index export. It was pushed. The board restarted at 21:36:29Z: PID 288909 stopped on SIGTERM, and the new PID is 1042473. The log is/tmp/control-board-20260926T213629Z.log, with the same flags and port 7331, and 44 sessions before and after. Live checks:/api/conversationsreturns 200 with 19 entries (18 Pi available, 1 Claude unsupported, as D2 rules).- One conversation returns 200 with a 10-entry page.
- An extra parameter returns 400, a foreign Host or Origin returns 403, and POST returns 405. The two nonblocking notes from Darkwing (the scan test checks keys, not status values, and it reads a fixed list of three files) go to Dewey as optional. The Console and its WebUI proxy allowlist are next.
-
Gate F committed. Filbert approved Darkwing's build (manifest ba73a163, review e47ec6da), with the U+2028 reader fix as its own item. Sage committed the eleven paths as
136958c9after the eight suites and ledger 47/47 passed on an index export. It was pushed. The live ledger had been refusing on HEAD because of that line split, and it reads again. Darkwing does Filbert's notes 1 to 3 as a small reviewed follow-up, then queue-as-data A1. Note 4 is in DEFERRED. -
Row 25 live check passed. Jason reported the button approval worked: DEC-010, request 2, approved at 21:38:58Z, confirmed in the approvals log. Jason named the SetSpark lead (T3 thread ac03938d), and Sage sent the approver validation request there. Mosaic needs no further change.
-
Queue as data splits into A1 and A2. Filbert's plan (282fabbb) §1 left the split to Sage. A1 is the journal, lock, CLI and verify. A2 is migration, render and dispatch. A1 lands first under five conditions:
- nothing runs against the canonical
.git; - QUEUE.md, AGENTS.md and TOOLS.md stay unedited;
scripts/test-queue.shis green at a HEAD with noqueue.json;- H is recorded before the canary;
- the fault layer is reachable only from tests.
Darkwing's A1 packet (build.md a1125ebd, manifest 4319695a) reports all
five met, and Filbert is reviewing it. When A1 lands,
queuejoins the suite list. Genesis and the hook install stay Sage's bootstrap steps 2 to 4, after A2.
- nothing runs against the canonical
-
The SetSpark approver fix is Mosaic's, through a Sage subagent. Jason delegated the owner choice. The SetSpark lead can't touch shared-signals. A Sage subagent writes the change in shared-signals
stack/api, Rocko reviews it, and Sage commits it to shared-signals main following that repo's AGENTS.md. The subagent stopped at the compatibility check. The strictdiscord:rule would refuse all 16 approvers on vault DEC-001 to DEC-008, which are sanctionedpending:<text>markers (RECORDS.md, the decision template,validate_vault.py), and that would block the cutover migration. Ruling: keep the records convention. An approver is either a Discord ID under the service's existing digit rule, shared withvalidate_vault.pyso the two can't disagree, or apending:marker. The status condition comes fromvalidate_vault.py. Any other value gets a 422 with the value not echoed. Opening an approval request is refused while any approver is still pending. No data migration: the README gets a read-only query for bad stored rows. DEC-009 stays as stored. If it was more than a test record, arecord_updatethrough the Discord Sage writes its approvers asdiscord:IDs, which bumpsproposal_version, and request 1 closes as stale on its next use. Deploying to VM 1022 is a host action and is not part of this; it goes to Jason when the commit is pushed. -
CHAT-03 chartered. Jason approved it on 2026-09-26. Dewey writes the brief, Filbert reviews it after A1, and Rocko does an adversarial pass on control races and recovery. The brief must settle D1 and R3-1 (item 8), the Claude catalogue after B1, and the board send that can become a Pi slash command. It names the CHAT-01/01C contracts by hash and keeps path authority clear of queue A1/A2 and the ledger. Following the plan page, Darkwing names the source author once the brief is approved. No real seat migration.
-
Queue A1 review rulings. Filbert asked for changes (review 6933b885): all five conditions met, three small fixes R1 to R3. He left two questions for Sage.
- The review issue: sorted issues make "the first issue" the lowest
number, so a row for #1508 that also lists #1495 would post reviews
on #1495. That is not the intent.
move in-reviewrefuses a row with no issues. A row with one issue uses it. A row with several needs--issue <n>, which must be one of the row's issues. Later rounds keep the previous round's issue unless--issuenames another. That also fixes R2. set pieceandset gateare privileged only. 8.7's field table didn't list them, and the reason for the default is that piece and gate change what a row is, not how far along it is. Filbert's N13 (the nestednode --testintest-foundation.shandtest-discord.sh) is added to the DEFERRED entry. It goes to Darkwing as a small reviewed item after the A1 delta, before A2.
- The review issue: sorted issues make "the first issue" the lowest
number, so a row for #1508 that also lists #1495 would post reviews
on #1495. That is not the intent.
-
SetSpark approver fix landed in shared-signals. Rocko approved R2 (41e735f4, review c190814b) after R1 found that rows stored before the fix could still open requests, collect approvals, seal and be superseded. Sage reran the suites on the checkout (188 with a test database, 131 without, vault 45 PASS) and committed it to shared-signals main as cc74d92 under the Sage identity, following that repo's AGENTS.md. It was pushed. Correction to item 21's reasoning about legacy Accepted rows with more than 16 approvers: I called them unlikely because sealing one needed more than 16 live approvals. Rocko points out that the old coordinator import could seal from supplied evidence, so imported sealed rows need the same survey. The ruling stands: they stay refused, and a one-off correction goes to Jason if the README query finds any. Deploying to VM 1022 and running that query on production are host actions for Jason.
-
CHAT-03 deviation V-1 accepted, with limits. Dewey's brief r2 (5c5b45a2) has no durable receipts. So an exact retry across a controller restart refuses
stale-incarnationinstead of returning the original receipt, which CHAT-01 line 145 and CHAT-01C line 212 promise. Sage accepts it for CHAT-03, because it replays nothing and fails closed. Three limits apply:- the client shows
stale-incarnationas "outcome unknown, check the transcript" and never resends on its own; - a fixture proves that no retry after a restart reaches the engine;
- CHAT-04's durable receipts must restore the contract behavior, and V-1 closes only then. CHAT-04's brief lists it as required. Rocko's R2 on the same brief (07b938fb) requests one change: an idle slot with empty clears does not prove an interrupted turn. Dewey separates receipt settlement from the stop proof in r3.
- the client shows
-
Queue A1 committed. A2 starts. Filbert approved r1 (e464be6c). He agrees with Darkwing's refusal of a later round whose kept issue has left the row until
--issuenames one; that detail belongs with item 23. Filbert's r1 notes all go into A2 before genesis, as Darkwing proposed (carry-forward b2a738f0): P1, the unguarded release on the gate paths, with a test; P2, each round records its own issue, which changes the round schema; P3, unlock returns the result and the warning separately. N13-a, having the check apply the patch instead of copying the suites, won't be done: the approval pins the patch and the suite hashes, and Filbert applied the patch himself. Darkwing starts A2 now. -
Goals review, and the SetSpark deploy decided. Jason asked Sage to decide instead of asking him. The SetSpark approver fix (cc74d92) deploys. Sage handed the deploy and the read-only production survey to the shared-signals stack operator seat (T3 thread 12fe8cda), which follows that repo's rules and host holds. Sage does not touch VM 1022. Jason also asked whether the north star and goals need a review. They do. The ledger shows human messages per closed issue at 47.7, then 33.0, against a goal of under 10, and one issue closed last week. See
docs/plans/2026-09-27_goals-review.md. In effect now:- CHAT-03 source work waits for a rescope against Gate E;
- briefs get two review rounds, then scope is cut;
- work for other repositories goes to their own seats;
- the ledger runs every Monday. Jason ratifies the north star sentence and the goal order.
-
SetSpark deploy result and DEC-009. The operations seat deployed cc74d92 to VM 1022 at 00:23Z on 2026-09-27 and verified it (hash, health, tunnel). The survey found one bad row, DEC-009 (Proposed), and no Accepted decision over 16 approvers, so Jason has no correction to make. DEC-009 stays as stored. It was the live-check record from item 16. The fixed service refuses to approve it, and correcting it would change production data for no gain. If someone wants it approved, a
record_updatethrough the Discord Sage writesdiscord:approvers and request 1 closes as stale. The deploy also recreated caddy throughdepends_on, about 20 s of edge downtime. I suggested--no-deps setspark-apito the operations seat. The procedure is theirs to change. -
Open items closed (goal 1). Jason said on 2026-09-27 that Sage had been distracted from mosaic-stack. Sage closed what the evidence supports:
- #1511 closed.
af4203cais pushed, Filbert approved R2, and Jason confirmed the live display on 2026-09-15. - #1503 closed. D-001's MVP was one page of running Pi sessions with a waiting-on-Jason flag. Gate A passed, and the attention status fix is operator-accepted (row 22). Cross-harness board work is Gate E's.
- Row 25 is done (item 19). Row 23 is done on its live write with web calls recorded. Its outside-root refusal rests on the offline suite.
- Row 24 is done without a live use. The Discord Sage has never called
commit or push. Records now go through row 25, and SetSpark cutover
freezes
vault/, so another Discord check from Jason isn't worth asking for. First real use is the check, and a failure opens a new issue. - #1509 closed. Gate H passed on 2026-09-13, and rows 14 to 25 are done. Its gaps stay in DEFERRED.
- Row 6 closed, and Gate F is recorded as not passed. The ledger counts 2 human messages in Filbert's T3 thread during #1512's life. One is Jason's 09-26 takeover message. The item's first 11 days also predate the T3 source, so a zero was never provable. Gate G (row 9) tests the same thing on the queue, so it carries the test and Gate F isn't rerun. Rows 9 to 13 no longer wait on row 6. Still open: #1507 (Gate E, row 5) and #1508 (Gate G, A2 in progress).
- #1511 closed.
-
CHAT-03 rescoped against Gate E. Dewey's r3 (BRIEF.md 2c5be6b4, 1,527 lines; packet e197b882, "Gate E map") marks each section for Gate E. Rulings:
- Goal: option (a). A seat bound to the Console runs without the goal extension, and Jason drives its turns. Goal continuation is a CHAT-06 item. Options (b) and (c) are refused: (b) is new machinery, and (c) makes interrupt useless. A launch without the Console keeps goal as it does today. The change is one launch flag and is reversible.
- Cut from CHAT-03: §7 Pi native dialogs, §5 H5–H8 on Pi dialogs, C-1, C-2 and C-4. No repository Pi seat raises dialogs, and the interim rule already counts unknown events.
- §2's idle drift check moves to CHAT-07. The live-session guard stays and keeps CHAT-03 off real sessions until CHAT-07 lifts it.
- C-5 moves to CHAT-04 with its own contract review. CHAT-04 comes before Gate E anyway. Without C-5, an interrupt that races a completion ends in a force stop, which costs time but is safe.
- C-3 only if B1 finds a gap. I3 (a recording that calls a model or reads Claude auth) still needs Jason's go. Sage asks when B1 is next, not before.
- Filbert and Rocko review r3 only on the sections Gate E needs. A finding in a cut section is not blocking. After r3, Dewey removes the cut sections instead of rewording them.
-
CHAT-03 seal: no explicit extensions. Rocko's r3 pass (report 19e3fcff) closed his R2 blocker and found one new one in the retained seal. An explicit extension can import a helper outside its hashed tree, and the helper can change after review with every hash still passing. Ruling: take his first cut. A Console-bound seat loads no explicit extensions. It launches with
--no-extensionsand no--extension, and binding refuses otherwise. Goal was the only explicit extension any repository seat loads (scripts/agent-host-dev.shline 137), and decision 30 already turns it off for bound seats, so nothing is lost. The seal covers only built-in code tied to the pinned Pi artifact. Reviewed extensions come back with goal in CHAT-06, which must pin their executable dependencies. No dependency crawler. Rocko's nonblocking note goes to the build: no-turn fence cleanup must not undo a concurrent force-stop, overlap or revocation fence. No round 4. -
CHAT-03 r3 closes. Filbert approved r3 on the sections Gate E keeps (review 48447592), with no blocking finding. Rocko's one blocker is closed by item 31. Two notes are rulings for the edit:
- n1:
pirunsdist/bundle, not thedist/coreanddist/extensionsfiles the brief pins. The seal pins thepackage-lock.jsonintegrity of@earendil-works/pi-coding-agent0.85.1 (sha512), which covers the whole tarball. There's no hand-made bundle manifest. - n2: Pi's own clear emits a
queue_updatebefore the clear response. O5 counts it, and a fixture proves that an ordinary Interrupt doesn't end uncertain because of it. Dewey makes one edit: remove the sections cut by item 30, apply items 31 and 32, and add Rocko's fence note to the build. Filbert checks that the diff only does that. That's a scope check, not a review round. Then Sage pins the hash, and CHAT-03 is ready for a source author.
- n1:
-
CHAT-03 brief pinned. Filbert's scope check passed. The final
agents/dewey/work/chat-03/BRIEF.md(sha256 1ef15ac0…, 1,451 lines, down from 1,527) differs from r3 (2c5be6b4) only by items 30 to 32 and what follows from them. Dewey's diff c6bd1f1e matched Filbert's own regeneration. His two observations are accepted as written. The P3 rule disables every Pi dialog, which is wider than CHAT-01, but no dialog can reach the controller without explicit extensions. Sage committed the brief, the earlier rounds and the six review reports. Sage names the source author after queue A2 lands, so Darkwing isn't split between them. The code may not start before then. -
CHAT-03 build note, Filbert n3. Under items 30 and 31, only the controller's
abortcan produceaborted. If the code ever seesabortedwith no stop in progress, it treats it as an overlap signal. It does not invent a stop link. This goes into the build and its tests, and the pinned brief stays as it is. -
Queue A2 lands, then genesis. Filbert approved A2 round 1 with no blocking finding (f167b85e). Sage commits it with both patches, then runs the dry run's order on the canonical checkout: map check, install the hook, genesis,
queue-commit.sh --genesis, then these logged ops:assign 10 sage(map choice 2).- Row 13's gate becomes "rows 9 to 12 done, then a Monday ledger run
with zero queue violations, or every one moved the same day". This is
Filbert's n1.
aftergates only the start of a row, so it can't stop row 13 going done before Gate G. The gate text does, and Sage owns that gate. It also drops the stale 2026-09-21 date. Map choices 1 to 8 are accepted as written. Row 16 stayswaiting-on-jasonat genesis. #1510 is checked after genesis, through the queue. Filbert's n2 (point the header at the goals review, reword AGENTS.md's priority line) is row 10's work, now Sage's. n3 (a README line sayingqueue-commit.shcallscli.mjsdirectly) rides with row 10.
-
Genesis done, row 10 landed, #1510 stays with Jason, CHAT-03 author. Genesis is
3377b877(rev 0, 30 rows). Item 35's two ops are in42f3f2d9. Row 10's source is5efe28ab: the AGENTS.md cadence, pointer and recovery rule namescripts/mosaic queue next <seat>and the goals review, the six seat CONTEXT files run the queue instead of reading CURRENT.md, and the queue README carries Filbert's n3. The QUEUE.md header now points at the goals review (n2,eae341d3). Row 10 waits on Gate G, which is Jason's gate.- #1510 (row 16). Its five acceptance items are met, and the
source is in
af4203caandd41f81aa, pushed. The queue lets Sage close awaiting-on-jasonrow only by citing Jason's approval. His 2026-09-26 ruling uses the team #1510 built, but it doesn't accept the issue, so citing it would stretch his words. Row 16 stays with him and needs one word. - CHAT-03 source author: Dewey. Dewey owns row 5 and wrote the pinned brief (1ef15ac0). Filbert reviews first, and Rocko reviews the controller binding and the extension-load refusal (item 31). Two rounds, as item 27 sets. Darkwing stays on queue rows 12 and 13, so goal 2 isn't split.
- Export recipe after genesis. An index export isn't the
canonical root, so
test-queue.sh's two live checks refuse there (24 pass, 2 fail). The canonical checkout passes 26/26. This goes to DEFERRED for Darkwing. Until it is fixed, read the queue suite's result in the canonical checkout.
- #1510 (row 16). Its five acceptance items are met, and the
source is in
-
Gitea helper reads the per-seat raw token files (row 12). Darkwing found that
scripts/gitea-api.shaccepts only the JSON credential file, while the per-seat files Jason ruled on hold a raw token (checked withstatonly: 41 bytes for four seats, 40 for jarvis, all 0600). Without a change every live Piece D attempt fails at the pre-sendGET user. Sage says yes to a separate helper patch with the D candidate, on these terms:- The JSON path is unchanged. The raw path applies only when the file isn't JSON.
- The raw path accepts exactly one line of token characters, with an optional trailing newline, and refuses anything else before any request.
- On the raw path the base URL is fixed at https://git.mosaicstack.dev, with no override.
- The file checks stay (regular file, no symlink, no group or other bits). The token goes only through the curl config stream. Tests use stubs and read no real token.
- A seat uses only its own file.
- Rocko reviews the patch as well as Filbert.
This doesn't widen access: each seat already has the token by Jason's
ruling, and the change only lets the helper read the file's actual
format. JSON wrapper files would need writes under
~/.mosaic, which are forbidden.
-
Gitea helper round 2: one blocker left, fixed under a lead check. Rocko closed the round 1 blocker (config is built and checked before curl starts) on helper.patch dd9e38bf. The round 2 report (2096b0a3) has one new blocker:
CFGkeeps an export attribute inherited from the caller, so an exportedCFGin the environment carries the secret config into curl and the body-file utilities. The fix is Rocko's:export -n CFGright after the checked assignment, before any child starts, plus inherited-CFGregressions for GET and POST with raw and JSON dummy credentials, and a mutation that removes the line and must fail them. Item 27 says scope is cut rather than opening round 3, and Sage told Darkwing the raw path would be cut. Sage departs from that here. The fix is one line and the reviewer has specified it and its test, while cutting the raw path would stall Piece D's live round and Gate G. Darkwing applies it. Sage checks it with Rocko's reproducer and the ledger tests. That is a lead check, not a review round. If the check fails, the raw path is cut. -
Lead check passed on helper.patch 48edd46b (decision 38), and C1 goes into D.
export -n CFGfollows the checked assignment directly. Darkwing also foundSHELLOPTS=allexportas a second route to the same leak, and the same line closes it.- Sage checked it with dummy credentials and stub
curlandgit: raw and JSON files, GET and POST, with an exportedCFG, withSHELLOPTS=allexport, and with both. On the patch all 12 cases keep the token out of curl's environment, argv, stdout and stderr, and the token appears only in the config stream. With theexport -nline removed, all 12 leak it into curl's environment. - Ledger tests pass 58/58 on the patch alone at
8efc0ff3. The helper ships with the D commit, together with Rocko's two reports (e896192f, 2096b0a3). - Filbert's D round 1 (a2dc2302) raised C1: on a comment round, in-review→waiting-on-jason needed no reviewer approvals, so an owner could move a Jason-gated row past its reviewers. It is fixed in D, not deferred: that move gets the approval and unresolved checks of in-review→done, plus a regression. No semantics-2 entry is logged yet, so the fix is cheap now.
- Filbert's plan correction (293747cd) goes into the D commit. Round 2 of D is Filbert's.