Skip to content

Queen supervisor: two bees at once, and the two defects that only appear then - #10

Closed
gHashTag wants to merge 251 commits into
devfrom
feat/queen-supervisor
Closed

gHashTag wants to merge 251 commits into
devfrom
feat/queen-supervisor

Conversation

@gHashTag

Copy link
Copy Markdown
Owner

Two workers ran concurrently for the first time — browseros-ai#1093 from 10:21:16 to 10:23:18 and browseros-ai#1098 from 10:21:18 to 10:24:15, two minutes of genuine overlap. Each on its own branch, each with its own file boundary, each committing one file; both branches diffed against the base contain exactly their own file and nothing of the other's, and the working copy never left feat/queen-supervisor.

The green result is not the point. Running them in parallel exposed two defects that cannot occur any other way, which is why neither had ever been seen.

The ownership rule compared boundaries as strings

conflictingTasks used Set.isDisjoint, so docs and docs/live looked unrelated and both claims were admitted. A write, meanwhile, is judged by containment — so the bee owning docs was entitled to write docs/live/x.md, the file the other bee owned. Two writers, one file, and nothing complaining until the merge. The two rules had one notion of "path" each and disagreed.

They now share pathsOverlap, which compares by path component: nested boundaries clash, siblings do not, and a shared prefix (docs / docsite) is not containment. That last part matters — a rule that answered yes to everything would pass every clash test while quietly stopping all parallel work.

The Queen was losing bee reports

Six reports arriving at once persisted three. Not late — lost: the check now waits ten seconds and they never arrive. Every caller appends to the same main-actor buffer, so memory was always complete; then each passed its own whole-array snapshot to save, the saves raced, and the file kept whichever finished last rather than whichever held the most.

Writes to her chat are now queued, and each takes its snapshot when it runs rather than when it was queued.

The check that was hiding it

A fixed 300ms sleep. Enough on an idle machine, so the scenario passed every run I had ever done; it failed once in eight under a parallel build. The sleep is now a bounded wait, and the race has a deterministic check instead of a probabilistic one: the mock persister holds the first write to her chat open for two seconds while a second overtakes it. Verified from both sides — it fails with the fix removed and passes with it restored.

Also cleared: sixteen prototype exemptions naming files 939028c91 had already deleted. The gate had been failing on them and was right to.

Verification

  • make check — dev app built, cassette suite passed (4 cassettes)
  • SSE end-to-end suite: 455 checks, ratchet floor raised 437 → 455
  • 20 consecutive runs under a parallel build, no failures

Closes gHashTag/trios#1099

gHashTag and others added 30 commits July 23, 2026 23:48
…okens, HELLO auth, SafeFilePath, .aiignore

Cycle 8 autonomous hardening for /trios:
- KeychainSecrets.swift: generic macOS Keychain wrapper for small secrets.
- GitHubAPIClient.swift: remove GITHUB_TOKEN env fallback; read token from Keychain.
- MeshAuth.swift: remove TRIOS_MESH_API_TOKEN env fallback; read token from Keychain.
- trios-meshd (submodule): verify HELLO src, MAC, and freshness before accepting beacons.
- SafeFilePath.swift: default allowMissingBase to false.
- CladeGuard.swift: remove allowMissingBase: true from snapshot validation.
- .aiignore: exclude secrets, .trinity runtime state, build artifacts.
- Extend AGENT-V-WAIVER expiry from 2026-07-28 to 2026-12-31 across mesh BR-OUTPUT files.

Verification: cargo test (270+), cargo clippy -D warnings, build.sh OK.
- Add ./trios executable launcher: build, start backend, open app, health check
- Make ecosystem.config.js portable via TRIOS_ROOT / __dirname
- Update LAUNCH.md and QUICK_START.md with one-command usage

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Manifest integrity: SHA-256 + size per entry, verify on read
- Atomic import with rollback on partial failure
- Duplicate resolution: replace / merge / skip
- Large-file safety: 16 MiB cap for log/diagnostic files
- Progress overlay and cancellation hook
- Version compatibility: schemaVersion, minReaderVersion
- Expanded error taxonomy with LocalizedError descriptions
- ASCII-only sanitization across touched source files

Closes #T27-EPIC-001
…, A2A rings, and chat history

- Integrate SR-00/SR-01/SR-02 rings, BR-OUTPUT canon, and local-auth token-family store.
- Add BrowserOS server local-auth routes, chat-history service, task-queue, A2A registry, retry/CORS/request-auth hardening.
- Update build scripts, docs, and .gitignore; keep generated artifacts out of tracked tree.
- All server sources pass Biome lint/format gate.

Closes #TRIOS-PORTABLE-LAND-001
Mark task done in done.json and clear active.json.
Closes #TRIOS-PORTABLE-LAND-001

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add TRIOS_RELEASE_MANIFEST.md and .claude/plans/trios-portable-land-001-report.md
with verification results, clean-machine blockers, and three land variants.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add trios/docs/INSTALLATION_README.md with prerequisites, install steps,
permissions, troubleshooting, and migration warnings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Update TRIOS_RELEASE_MANIFEST.md and landing report with the discovery that
origin/dev has diverged via the agent-core extraction and trios switchover.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… /doctor --model

- Stop retrying fatal provider errors (402 balance, 401 auth, invalid model).
- Surface actionable chat error messages with fallback model hints.
- Add /doctor --model parsing and pass --model to the Claude CLI invocation.
- Pin doctor skill to claude-sonnet-4-6 to avoid stale claude-opus-4-6 access issues.
- Add ModelConfigurationStore fallback helpers and ChatFailureTests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add provider-aware fallback ordering with cheap floor model last.
- Send OpenRouter native  array for server-side failover.
- Refactor ChatViewModel.sendMessage to retry once on model-unavailable/invalid-model errors.
- Insert a user-visible banner when failover occurs; restore original model if retry fails.
- Clean up stale claude-opus-4-6 references in BrowserOS agent catalog and CLI provider.
- Add ChatViewModel failover tests and ChatRequestBuilder OpenRouter tests.

Closes TRIOS-AUTO-FAILOVER-011

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add .logs Trios999Destination with petal 2 (Cmd+3) and world LOGS.
- Create BR-OUTPUT/LogsTabView.swift showing next-loop variants + unified log viewer.
- Wire LogsTabView into QueenTabView hosted routes and build.sh LEAN_BR_OUTPUT.
- Update trinity QueenUILib TriangleLogo.swift: EXPLAIN -> LOGS.
- Update trinity_999_tab_map_test for 7 routes and .logs shortcut 3.

Verification:
- bash trios/build.sh passes (114 Swift files, QueenUILib rebuild).
- cargo test --workspace passes.
- cargo clippy --workspace --all-targets --all-features -- -D warnings clean.
- Standalone trinity_999_tab_map_test passes.
- trios.app relaunched; menu-bar logo process alive.

Co-Authored-By: Claude Opus 4.8
- Add ModelHealthService actor with cached TTL probes:
  - Cloud providers: tiny max_tokens:1 ping via chat completion endpoint.
  - Ollama: free /api/tags existence check.
  - Two-failure threshold before marking unavailable.
- Extend ModelConfigurationStore with unhealthyModels, healthStatus,
  refreshHealth, selectFirstHealthyModel, and invalidation on provider/URL/key changes.
- Preflight check in ChatViewModel.sendMessage switches to first healthy fallback
  with a visible system banner before burning a real request.
- Mark failing model unhealthy after any transport error for next preflight.
- Models tab: Health button, unavailable badges, disabled unhealthy rows,
  badge on active model.

Verification:
- bash trios/build.sh passes (115 Swift files).
- cargo test --workspace passes.
- cargo clippy clean.
- trinity_999_tab_map_test passes.
- trios.app relaunched; health endpoint ok.

Next loop options: background poller, persistent reliability scoring,
provider-native status feeds.

Co-Authored-By: Claude Opus 4.8
Add ModelHealthServiceProtocol so tests can mock probe results.

Add ChatFailureTests for preflight switching, error marking, and no-switch healthy path.

XCTest unavailable in this toolchain; production build, cargo test, and clippy pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add BackgroundHealthPoller actor that probes all available models every 60s.

Wire poller into ModelConfigurationStore lifecycle: start on init, restart after provider/URL/key changes.

Update ModelsTabView with Auto toggle and last-check timestamp.

Add XCTest coverage for poller, recovery detection, and start/stop toggle.

Clade audit + seal pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…og pre-check, UI badges, tests

- Add ProviderStatusService actor with cached /models checks for OpenAI/Anthropic/OpenRouter and /api/tags for Ollama.
- Inject ProviderStatusService into ModelHealthService to skip paid probes for missing/disabled models.
- ModelConfigurationStore owns ProviderStatusService, exposes providerStatus(for:), invalidates on endpoint/key/provider changes.
- Add hasProviderCatalog to ModelProvider.
- ModelsTabView shows 'disabled' / 'not in catalog' badges after Health refresh; refreshes badges on catalog change.
- XCTests: missing/disabled status skips paid probe, OpenRouter catalog parsing, status invalidation.

Closes TRIOS-CHAT-PROVIDER-FAILURE-014
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- ModelReliabilityService actor with EMA scoring and bounded outcome history
- MemoryStore v3 schema with encrypted model_outcomes table
- MemoryStoreReliabilityAdapter bridging outcomes into agent-memory.sqlite3
- Async, reliability-ranked fallbackModels/runtimeConfiguration in ModelConfigurationStore
- ChatViewModel records send/failover outcomes and awaits async runtime config
- XCTests for EMA, ranking, persistence, reset, and history limits
- Update E2E schema-version assertion and mock memory store stubs

Verification:
- ./build.sh passes (swift test skipped: no XCTest in CLI tools)
- cargo test --workspace passes
- cargo clippy --workspace clean
- clade-audit 0 findings
- clade-seal SEAL VALID
- trios.app relaunched and healthy

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add ModelCostService with ModelCostTier (any/free/cheap/premium)
- Extend ModelReliabilityService.bestModel() with tier filtering
- Add isPredictiveSelectionEnabled + preferredCostTier to ModelConfigurationStore
- Add Smart model selection UI to ModelsTabView
- Add ModelCostServiceTests and bestModel coverage
- Stop e2e keychain password dialogs via TRIOS_E2E_DISABLE_KEYCHAIN=1
- Fix clade-build LEAN_BR_OUTPUT whitelist drift for LogsTabView.swift

Closes #T27-EPIC-001

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add ModelContextService.largerOutputCandidates(...) for output-ceiling-first candidate search.
- Insert output-budget routing phase into resolveContextRoutingDecision before context-window routing.
- Surface routing cause via lastContextRoutingReason (output budget vs context window).
- Update ChatViewModel routing label to use the recorded reason.
- Add tests for effectiveOutputCeiling, isOutputBudgetSaturated, and output-budget routing.
- Run Trinity gates: build, mesh tests, clade-build, clade-audit (0 findings), clade-seal valid.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Closes gHashTag/trios#1086

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Limit build_*.log and chat_sse_e2e_build_*.log to 10 newest files in
.trinity/logs. Previously every build and chat-SSE e2e run created a
new log, flooding the LOGS tab with 120+ stale build artifacts.

Closes gHashTag/trios#1087

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add LogSourceCategory (runtime/service/build/test/artifact) and classify sources
- Default LOGS tab hides build/test artifacts; add Show build/test logs toggle
- Cap artifact log families at 10 files in build.sh, run_queen_autonomous_test.sh, clade-build
- Add XCTest coverage for classification and filtering
- Cleanup legacy cycle logs and stale archive

Closes browseros-ai#2046

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add scripts/cleanup_artifact_logs.sh dry-run-by-default cleaner
- Lower artifact cap from 10 to 5 files per family
- Add 7-day age eviction for artifact logs
- Scan .worktrees/*/trios/.trinity/logs for stale build logs
- Wire cleaner into build.sh, run_chat_sse_e2e.sh, run_queen_autonomous_test.sh
- Update clade-build binary to keep 5 logs and evict logs older than 7 days

Closes browseros-ai#2047

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Closes browseros-ai#2047

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Extend LogRotationPolicy with maxArchiveAgeSeconds and maxAgeBeforeRotationSeconds
- Add .audit, .security, .experience static policies
- Add rotateAuditLogs() for event_log, akashic-log, local-auth-audit, episodes
- Add cleanupOldArchives() to prune .archive.<ts>.zlib files older than retention
- Wire rotateAuditLogs() into AppDelegate.applicationDidFinishLaunching and loadLogSources
- Update LogsTabViewTests for age-based rotation and cleanup

Closes browseros-ai#2048

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gHashTag added 27 commits August 1, 2026 13:14
…sing bees of its own writes

Two bees in parallel, no code from me.

The signing keychain locks on sleep, and `codesign` then puts a password dialog
in front of every dev build. The stable certificate exists for the release,
which reaches the real Keychain at runtime; dev reads its secrets from
`~/.trios-dev/secrets` and never needed it. Dev signs ad-hoc now and cannot
raise that dialog at all.

The same step had a worse failure. Interrupt `codesign` - a timeout did it to me
twice - and it leaves a `.cstemp` beside the file it was signing. The bundle is
then signed but invalid, macOS silently refuses to launch it, and the cassette
gate reports `trios-dev never started` on all four cassettes with no way to guess
why from the message. Stale temp files are cleared before signing now. Proven by
planting one: the build cleans it and `codesign --verify --deep --strict`
returns zero.

The other bee closed the second false accusation in three cycles. A write
arrives as an absolute path and the boundary is written relative, so a bee
writing the one file it owns was reported for leaving its lane on every single
run. Paths are made relative to the repository root before the comparison.

Both directions driven rather than read: a bee writing inside its boundary now
produces no out-of-bounds event where it always produced one, and the cassette
that plants a genuine violation still catches it.

Closes gHashTag/trios#1114
Closes gHashTag/trios#1115
…s nothing behind

Two bees in parallel, no code from me.

The sidebar redrew on a state change and the master chat did not, so the two
surfaces disagreed about what the swarm was doing. The board now moves with the
registry: a bee that starts working leaves the Waiting section, a bee that
finishes joins it, and neither needs a reload or a chat switch.

Proven by driving a real transition rather than by reading the binding, and the
proof was broken to check it: inverting `needsQueenAttention` fails four
assertions by name - the bee moves to the wrong section, the Waiting section
loses it, the Working section keeps it, and rejected work stops asking for the
Queen. My first attempt at that mutation left an unbalanced brace, so the suite
failed to compile and proved nothing; that is the second time this week a break
test lied by not applying.

The other bee closed the case where a worker dies mid-edit and its writes stay
in the tree with no branch and no owner, which is how a later bee inherits
somebody else's half-finished lines and a person running `make` meets an error
nothing accounts for.

Ratchet 455 -> 473.

Closes gHashTag/trios#1098
Closes gHashTag/trios#1112
Five bees this cycle, no code from me.

The observer measured what moved in the shared working tree since a bee started.
With one bee that is its work; with two, each diff contains the other's, so last
cycle both bees were reported for leaving a boundary neither crossed. Measured
writes are filtered to the task's own lane now.

The first attempt at that was inert and the reason is worth recording: the bee
added the parameter to its own file and both call sites live in a file another
bee owned, so the filter defaulted to off and never ran. Third time this shape
has cost a cycle - a signature changes in one lane and the caller sits in
another, and nothing in a bee's own cycle compiles the pair. Verified by
re-running two bees after the wiring landed: zero accusations where every
previous parallel run produced them, each branch carrying only its own file.

The trade-off is real and is not swallowed: filtering by lane makes measured
writes blind to a genuine out-of-bounds write by that same bee, leaving only
tool names, which cannot see a shell write - the hole measurement was introduced
to close. Recorded on gHashTag/trios#1116 rather than quietly accepted.

Also landed: Accept and Cancel on each bee card, a collapse for the board, the
Queen bringing three options to her own chat after a self-audit, and two
documents a bee wrote about what a reviewer can judge and how an interface
drifts between lanes.

Ratchet 473 -> 504.

Closes gHashTag/trios#1116
A bee wrote the proof for gHashTag/trios#1097, which landed as code last cycle
with nothing exercising it. The suite now drives the arrival: each option
carries a subject, a reason and the command that starts it, the message says a
chat will not open without consent, and a second arrival does not repeat the
first.

Ratchet 504 -> 522.

The dashboard is a different story and it is written down rather than papered
over. Three bees have now been sent at gHashTag/trios#1118 and
`FullscreenChatWorkspace` still has no caller. The first added buttons to the
board instead; the second changed nothing and its reviewer scored the board's
toggle as the entry point; the third committed a test and not the thing the test
is about. The criterion is mechanical now - `git grep` must find a call outside
the file - and the fault is mine for writing it loosely enough that a nearby
surface satisfied a plausible reading three times.

Refs gHashTag/trios#1097, gHashTag/trios#1118
…e about it was wrong

The dashboard was never unwired. `FullscreenChatWorkspace` is the name of a
file, not a type: the only struct in it is `AdaptiveChatWorkspace` at line 6,
and `QueenTabView` presents it. So `git grep "FullscreenChatWorkspace("` found
nothing because there was nothing to find, and the mechanical criterion I wrote
demanded something impossible. Three bees were sent after that phantom; the one
that changed nothing was right.

What actually hides it is a width. `ChatWorkspaceLayout.expandedThreshold` is
760 points: below that the compact supervisor bar is shown, at or above it the
full `QueenDashboardView`. The app lives in a narrow panel, so the dashboard was
one window-resize away and nothing said so.

A bee added the control that opens it from the compact panel and the way back.

The guard for it does not work, and that is recorded rather than smoothed over.
Removing the call to `dashboardToggleButton` leaves the suite green: the test
greps the source for "Open Dashboard" and `isDashboardExpanded`, which are still
present in the declaration it no longer uses. A source-text check cannot tell
declared from used - the defect class this repository has closed three times
elsewhere and just reintroduced in its own test.

Ratchet 522 -> 526.

Refs gHashTag/trios#1118
Last cycle's guard greped the source for "Open Dashboard" and
`isDashboardExpanded`, so removing the call to `dashboardToggleButton` left the
suite green - the strings survive in a declaration nothing calls. It could not
tell declared from used, which is the defect class this repository has closed
three times elsewhere.

The machinery for the real question was already here.
`QueenSelfAudit.deadSymbols` counts occurrences against a threshold: a
declaration alone is one, a declaration plus a call is two. The guard now
demands two, and the failure says so - "dashboardToggleButton appears 1 times
(need >= 2: definition + body reference)".

Proven by the break that defeated the old one: remove the call from the compact
body and the suite fails.

Also landed: a bee's work on telling an empty reviewer answer apart from a
criterion nobody asked about. Its reviewer confirmed one of two criteria and
would not commit to the other, so gHashTag/trios#1117 stays open.

Refs gHashTag/trios#1117, gHashTag/trios#1118
…ks anyone

The user asked for Touch ID instead of typing the password. Touch ID cannot be
wired to that dialog: macOS offers biometrics for "allow access to this key" in
the login keychain, and a secondary keychain raises "enter the keychain
password", which has no biometric path.

The right repair was underneath it anyway. The password is not a secret and
never was - `scripts/create_dev_signing_identity.sh` hardcodes `trios-dev` and
explains why in its own header: the keychain holds one public self-signed
development certificate and nothing else. So the build can open it, and then
there is no dialog to put a fingerprint on.

Proven the hard way round: the keychain was locked deliberately with
`security lock-keychain`, `make release` was run, and it produced a real
signature that `codesign --verify` accepts with zero SecurityAgent processes
raised. Every release build tonight before this one stalled on that dialog, and
one of them left the bundle unlaunchable when a timeout killed codesign
mid-signature.

Also landed: the reviewer's brief now carries the files a criterion names rather
than only the files in the boundary, and a guard against a signature changing in
one lane while another lane's caller goes stale.

Closes gHashTag/trios#1120
Refs gHashTag/trios#1119, gHashTag/trios#1111
…a bold asterisk

Three defects in one chain, each hiding the next, each found only by driving the
same task again.

The brief carried the files in the boundary but not the files a criterion names,
so a task whose contract is about the application and whose lane is a test file
could not be judged at all. That was browseros-ai#1119.

Fixing it changed nothing, because criterion paths were resolved against the git
root while they are written against the project root: `BR-OUTPUT/...` became
`/Users/playra/BrowserOS/BR-OUTPUT/...`, which does not exist, and the miss was
swallowed by a `fileExists` guard. The contract had explicitly asked for a named
file that is missing to be reported as missing rather than skipped; had that
been honoured, the wrong root would have been visible immediately instead of
looking like a criterion with no paths in it. That was browseros-ai#1121.

With the right root the reviewer finally answered - 2733 characters instead of
198, four verdicts a person can read - and the parser reported zero. It requires
a line to begin with the criterion's number, and the model writes `**1. met**`.
Its own comment listed what it accepted, bare and checkbox, and markdown was
never in the list. That was browseros-ai#1122.

Driven the whole way: the same re-review that produced `parsed=0` three times
now produces `asked=4 parsed=4 recorded=4, unchecked=none`. Break test: removing
the markdown tolerance fails three assertions by name.

Ratchet 526 -> 538.

Closes gHashTag/trios#1119
Closes gHashTag/trios#1121
Closes gHashTag/trios#1122
…bout

Fourth link in the same chain, and the same shape as the three before it: the
question did not arrive, and the answer read as though the work were bad.

`ChatViewModel.swift` is 5,293 lines and the brief carried the first 500. The
reviewer said so plainly - "the file is truncated at 500 of 5293 lines, I can
see the data structure declarations near the top, but the actual logic that
implements the acceptance criteria is in the truncated portion" - and returned
"could not check" for everything. Declarations live at the top of a file and
behaviour lives below, and a criterion is always about behaviour.

The excerpt now follows the names a criterion mentions rather than the start of
the file. Driven on the case that failed: the same re-review returned two
verdicts of three, and the reviewer quoted the implementation rather than the
declaration. The remaining criterion is genuinely unmet, so
gHashTag/trios#1117 stays open on it.

Incidental proof of another fix: a worker died on a timeout mid-review and the
log recorded `queen.worker.died.clean` - died and changed no files, tree clean.
That is gHashTag/trios#1112 doing its job in a case nobody arranged.

Closes gHashTag/trios#1123
A bee proved the interface-drift guard correctly - assemble the combined tree,
confirm the build fails when a signature moves in one lane and the caller stays
stale in another - and put it in the logic suite, where it called
`verifyCombinedBuild` twice. Each call runs the compiler. A suite that used to
finish in about a minute stopped finishing at all: exit 124 at 580 seconds.

A gate that does not terminate is not a gate, and the mistake is an easy one to
repeat: the proof was right and its home was wrong. It lives behind
`make drift-guard` now, named in the help as slow and outside the fast suite.

The fast suite is measured, not assumed: 68 seconds, 538 checks, exit 0. The
slow target starts and compiles; I have not watched it to the end, because it
outlasts the ten minutes I can hold a command open, and I am not going to claim
a result I did not see.

Also this cycle, and it corrects me rather than a bee: I closed
gHashTag/trios#1123 on a single run. The excerpt follows the changed regions, so
it works when there is a diff and falls back to the first 500 lines when there
is not - and a re-review of finished work is always an empty diff, which is
exactly where the truncation hurts. Filed as gHashTag/trios#1124.

Closes gHashTag/trios#1125
Refs gHashTag/trios#1111, gHashTag/trios#1124
… reviewer argues against

Two weak spots found by reading the field rather than by breaking something, and
both were already costing this project.

A verdict was a claim with no expiry. `criterionVerdicts` is stored on the task,
so a `met` recorded against one state of the tree stayed `met` after the bee was
sent back and rewrote the code, and acceptance answered from a pile of
assertions of different ages. The literature names this exactly: persisted state
is not verification, because resuming a run that recorded "tests passed"
re-asserts the record without re-establishing that it describes the code being
merged. A verdict now carries the tree state it was derived against and reads
`.stale` against any other - told apart in the block reason from "never
checked", because those two ask different people for different work.

And the judge was the defendant. The worker runs on glm-5.2 and the reviewer the
Queen calls ran on glm-5.2, so the assumptions that wrote the code also graded
it. The reviewer is prompted as an adversary now: its job is to find why a
criterion is not met, and `met` is only what it failed to refute.

The stale rule shipped with no test - removing it left the suite green, exactly
as the dashboard guard did two cycles ago - so a bee was sent back for the
assertion. It now fails four ways by name: stale rather than met, acceptance
blocked, the reason saying it was checked against different code, and the reason
not calling it unchecked.

Fourth interface drift of the night on the way through: `.stale` is a new enum
case and the exhaustive switch over it lives in another lane. `make drift-guard`
exists for exactly this and I did not run it before building.

Ratchet 538 -> 552.

Closes gHashTag/trios#1126, gHashTag/trios#1127
The supervisor surface was opened and looked at for the first time tonight, and
it works. In the narrow panel: an OPEN DASHBOARD control at the top, a compact
line reading "1 needs you - 0/4 working", and the bee board below it with a
WAITING ON YOU section and a card carrying the state, the worker, the branch and
an Accept button. Widened, the same plus the full swarm strip with the issue,
the branch, awaitingReview and Review. gHashTag/trios#1118 closed on its last
criterion, which was readability and could only ever be answered this way.

Looking found a defect no test had: the issue number printed as `#1,124`. A
SwiftUI `Text` interpolating an Int formats it as a quantity, and an issue number
is an identifier - you cannot search for `#1,124` or paste it anywhere. Fixed on
both screens that print one.

The bee's own assertion for it could not pass: it compared lengths and claimed
the identifier was shorter, while `browseros-ai#1129` and `1,129` are both five characters.
A test that is false by construction fails the same way a real defect does, and
it was caught only because the gate went red. It asserts the shape now - the
rendered identifier carries no group separator.

Also this cycle: an empty diff no longer sends the reviewer the first 500 lines
of a file, and a verdict is bound to the tree state it was judged against.

Ratchet 552 -> 559.

Closes gHashTag/trios#1129
Refs gHashTag/trios#1118, gHashTag/trios#1124
…etry has a guard

Acceptance judged a branch that builds on its own. What lands is the branch
merged with everything else, and nothing built that - which is how four
interface drifts got through in one night, each one a bee changing a signature
in its lane while the caller sat in another. The combined state is assembled and
built before a task can be accepted, and a failure there is named apart from a
criterion failure: "does not build together" is not "criterion unmet".

gHashTag/trios#1117 turned out to be already done. The one-shot retry on an
empty reviewer answer has been in the code for cycles - two bees looked at the
task and correctly changed nothing, and I had counted their empty branches as
failures to deliver. What was missing was the assertion, and now removing the
retry fails by name: "the reviewer transport was called exactly twice (once +
one retry), not 1".

Ratchet 559 -> 571.

Closes gHashTag/trios#1117
Refs gHashTag/trios#1128
…nce is still shut

The staleness rule I added two cycles ago blocks every acceptance, and the cause
is the shape this repository keeps producing: `treeStateFingerprint` was declared
on the task and never written, so `isStale` compared nil against a real snapshot
and answered "checked against different code" for everything. Fifth time in a
day that a mechanism landed without its wiring, and the worst of the five - the
others dropped a result quietly, this one closes the gate.

The fingerprint is recorded with the verdicts now and a missing one is told
apart from a stale one. Acceptance is still blocked, and the honest reading is
that the snapshot is taken over the whole working tree while the Queen writes
her own state files between the review and the decision - the same confusion as
gHashTag/trios#1102, which cost a false accusation then and costs the whole
cycle now. Recorded on gHashTag/trios#1131 with the run that shows it.

So the third of tonight's three tasks did not finish: no task has gone through
to a merge since gHashTag/trios#1102, and it cannot until this is fixed.

Ratchet 571 -> 584.

Refs gHashTag/trios#1130, gHashTag/trios#1131
@github-actions github-actions Bot closed this Aug 2, 2026
@github-actions
github-actions Bot deleted the feat/queen-supervisor branch August 2, 2026 03:27
dmitrii-f-t27 added a commit that referenced this pull request Oct 2, 2026
… the next number

A key added without a name was stored as an empty label and shown as the
bare provider, so the owner's 25th NVIDIA key read "nvidia" above
"nvidia #1".."#24". Environment keys are now named by their place in their
pool (Z.ai's pool-2 keys become zai #1..#10 instead of #10001..#10010), a key
added unnamed or named only after its provider takes the next free number
under the add lock, and a managed key saved before numbering is numbered
once, compare-and-set, the first time the owner's keys are listed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Running two bees at once exposes two defects: string-compared ownership and lost bee reports

1 participant