Skip to content

membus P1 continuation brief (WT-75a4, 2026-07-10 ~16:20 CT)

Lean-resume brief. Epic spec: codex-harness-mirror/docs/POLYHARNESS-PARITY-SPEC.md (councilled).

State

  • Repo: C:\Users\fives\source\repos\membus, pushed → github.com/andrewjonesdev-tools/membus (private), commit 422a128.
  • 61/61 tests green. Publish exe at publish\MemBus.Cli.exe (70MB single-file win-x64).
  • Live verified: house-all send+recall round-trip against http://ANDYGREATROOMPC:37877 ✔; allowlist denial (ollama→house-all) exits 3 ✔; health ✔.
  • Server facts learned: claude-mem API keys bind to ONE project (403 on mismatch = server-side scope gate); projects = Postgres rows (team 4a6f4502-2b46-489c-922a-914b1b49c52a); 15 scope projects INSERTED (idempotent SQL in scripts/provision-scopes.ps1); api-key create has NO --help (creates key with defaults — revoke stray ids immediately); admin CLI: docker compose -p claude-mem-server exec -T claude-mem-server bun /opt/claude-mem/scripts/server-service.cjs server api-key create|list|revoke --name --scope --team --project.
  • Keyring: ~/.membus/keyring.json (gitignored; house-all + per-scope cmem_ keys), minted by detached task bhkizjh2b (was 8/15, writes incrementally — check file for final count; FAIL lines in task output need re-mint via provision script rerun).
  • Codex review of repo running detached (task b7375z1a5 output file) — findings pending, apply as follow-up commit. Full /council-code-review still owed before P1 called done.
  • Fleet: codex+agy+grok+ollama on all 4 PCs (codex auth copied to streaming via scp, verified); odysseus on all 4 (127.0.0.1-bound); BEDROOM-PC dispatch listener down.

Next steps (in order) — UPDATED after review cycle (@0e674f2)

DONE since first brief: keyring 16/16 ✔; derived-scope + grok-house live round-trips ✔; exe+keyring deployed to gaming/streaming/bedroom, all healthy ✔ (after fixing main-PC Wi-Fi drift to NSBE — see memory main-pc-wifi-drift-nsbe); codex review DONE (docs/codex-review-p1.txt; 2 hung/blind attempts first — needs stdin < NUL AND -c sandbox_mode="danger-full-access"); all findings fixed @0e674f2 (host allowlist, strict keyring custody, transport exceptions, contract-drift detection, ttl/machine validation, threat-model README section); 72 tests; fleet exes redeployed + healthy. 1. CI workflow (org home-ci runner, SHA-pinned) + BOARD.md + docs per ship-tools policy. 2. /council-code-review full gate; then mark P1 done in spec + memory. 3. P2 handoff ready: fleet-dispatch/docs/multi-harness-control-spec.md + probe JSON; fix unknown-kind→pwsh fallthrough FIRST. 4. P3 briefs: set MEMBUS_HARNESS per harness + membus usage rules in every brief pack.

Gates pending

council-code-review (standard), Stryker/mutation (policy), CI, board, fleet smoke tests.