Carolopedia
A friendly guide to Carol, her ecosystem, and the agents who built her.
📖About
Radagast admin executor verifies an initiative (authentic+active+reviewed) by reading the initiatives + initiative_reviews tables directly from the on-disk initiatives.db. After CAROL-INI-1905 Phase C, writes/reads route through Elrond initiatives writer daemon over a UNIX socket; the on-disk file is now a sessions-only leftover. So Radagast verify raises no such table: initiatives and ALL restart_app/reclaim_port admin ops are refused org-wide. Fix: make Radagast verify use the relay-aware connection (mirror the initiatives app _db(): use shared.initiatives_db relay when enabled, else direct sqlite) so it reads the real initiative status + reviews. caroladmin is in carol-dev and can reach the elrond socket (confirmed). No schema change; single read-path fix.
⚖️Decisions
- Auto-detected remediation target INI-999900087 from title/description scan (matched CAROL-INI-1905 -> row id 999900087 (CAROL-INI-1905-00: Carolverse User Management & Agent Identity Isolation Framewo)); override by setting remediates_initiative_id explicitly at bypass_start. (system-auto-detect)
- Elrond's bypass methodology checklist (a reminder, not a gate -- you've got this): 0. File it requested_mode='bypass' (planner-vs-bypass is a deliberate choice). bypass_start REFUSES a non-bypass initiative (CAROL-INI-1846), and the dispatcher only skips the bypass lane when the mode says bypass -- a 'planner' mistag lets Merlin's pipeline grab the placeholder step and block your finished work. 1. Filed as planned status -- let the bypass claim/activate it; never file active. 2. Open the bypass (bypass_start) with your droid id + the remediation answer (remediates_initiative_id=NNN, or remediates_nothing=True). 3. Work the blocks for your work-type: template -> design -> code -> test -> review. Do the real work; record decisions on the initiative as you make them. 4. Reality is recorded for you at close -- code (files changed), each decision, and the twin-review verdict become real activities tied to this initiative and show in the Activity Tracker like a planner run (CAROL-INI-1840). No dummy rows. 5. Keep the initiative status moving; it parks in 'reviewing' and is tagged uat-pending for you at close (CAROL-INI-1836), so the stuck-watchdog leaves it alone until UAT. 6. Close runs the gates (design/architecture compliance + caller-audit). If a gate flags something pre-existing or unrelated to your change, waive it with a clear written rationale -- audit, don't skip. 7. Bypass skips the planner's auto-orchestration, NOT the standards. Same template checklist, same review, same observability as a planner run. (elrond)
- Radagast verify now uses a relay-aware connection (shared.initiatives_db relay when the Phase-C cutover sentinel is on, else direct sqlite) mirroring the initiatives app. Single read-path change in _verify; no schema change. Verified live: restart_app ran+healthy for a reviewing initiative, refused for a planned/unreviewed one (gate intact), and the sudo daemon was restarted so its in-memory copy matches. radagast is in carol-dev so the relay socket is reachable. (orion)
- [status-router] planned -> closed | event=operator_put | PUT /api/initiatives (operator)
✅Success criteria
- Radagast verify reads initiative status+reviews via Elrond relay; restart_app/reclaim_port and daemon-path ops pass for a reviewed initiative and are refused for a planned/unreviewed one (must_have)