Skip to content

Cherry-pick upstream supervision-robustness (10 commits) - #22

Merged
Amplify-Logic merged 11 commits into
mainfrom
fm/firstmate-upstream-cherrypick-m3
Jul 22, 2026
Merged

Amplify-Logic merged 11 commits into
mainfrom
fm/firstmate-upstream-cherrypick-m3

Conversation

@Amplify-Logic

Copy link
Copy Markdown
Owner

Summary

Cherry-picks the ordered supervision-robustness subset from kunchenguid/firstmate onto Amplify-Logic main, avoiding the conflict-heavy full merge (Herdr presentation family deferred).

Upstream picks (exact order, all applied, none skipped)

  1. 3729081 — watcher continuity across child cycles (foundation)
  2. ab8cea6 — bound stale wakes for parked/dead-agent crew
  3. 68c6110 — distinguish ordinary wakes from recovery
  4. c12bdea — x-mode: dedupe pending mention wakes
  5. 4ab61fa — enrich drained signals with bounded status context
  6. a26b37c — watcher process identity immune to Linux wall-clock changes
  7. 3f9e70e — spawn: require two stable reads before accepting worktree path
  8. c49f823 — send: treat opencode busy-queued composer state as submitted
  9. ea3ac2e — prevent AFK idle stalls and stale run attribution
  10. 916c8e2 — allow safe teardown during watcher recovery (depends on fix(herdr-lab): place --session before the child-argv delimiter and refuse ambiguous delimiter shapes #1)

Fork integration (extra commit)

  • Apply upstream's "repair missing watcher supervision" recovery wording to our Cursor/Kimi primary repair lines, and add ordinary-wake lines for those harnesses.
  • Keep watcher continuity attach-across-successors for arm mode while preserving our restart-only healthy ownership contract (restart never attaches).

Intentionally deferred

Herdr presentation-spaces commits (628292d, f9a89c3, c58cb0f) and other non-supervision upstream work — see scout report firstmate-upstream-drift-scout-e4.

Test plan

  • bash tests/fm-watcher-lock.test.sh
  • bash tests/fm-watch-triage.test.sh
  • bash tests/fm-continuity-pretool-check.test.sh
  • bash tests/fm-spawn-worktree-settle.test.sh (+ other fm-spawn*.test.sh)
  • bash tests/fm-crew-state.test.sh
  • bash tests/fm-daemon.test.sh
  • bash tests/fm-tmux-submit-busy.test.sh
  • bash tests/fm-supervision-instructions.test.sh
  • bin/fm-lint.sh

Note: the "must be raised via no-mistakes" CI check is expected to fail on this direct-PR path.

Made with Cursor

kunchenguid and others added 10 commits July 22, 2026 12:03
…nchenguid#693)

* fix: make watcher supervision continuous

* no-mistakes(review): Bound watcher retries and log attached signals

* no-mistakes(review): Add bounded successor-recovery wake fallbacks

* no-mistakes(review): Prevent overlapping successor-arm retries

* no-mistakes(review): Resume supervision after late arm closes

* no-mistakes(review): Bind OpenCode recovery to attempted arm

* no-mistakes(test): Synchronize peer beacon regression fixture

* no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures

* no-mistakes(document): Captain: document watcher successor protocol behavior

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes

* no-mistakes: apply CI fixes
* fix(watcher): bound stale wakes for exited paused crew

* no-mistakes(review): Gate pause suppression on confirmed agent death

* no-mistakes(test): Fixed stale pause cadence

* no-mistakes(document): Document dead-agent hold cadence
…id#744)

* fix(supervision): distinguish ordinary wakes from repair

* no-mistakes(review): Make passive guard follow-ups recovery-only

* no-mistakes(document): Clarify recovery-only turn-end guard documentation
* fix(x-mode): dedupe pending mention wakes

* no-mistakes(review): fix x-poll claim error deduplication

* no-mistakes(review): separate claim diagnostics from relay recovery

* no-mistakes(document): Document X-mode once-only mention wakes
…enguid#747)

* feat(wake): enrich drained signal context

* no-mistakes(review): Bound wake enrichment reads

* no-mistakes(document): Document wake-drain annotations

* docs(wake): explain at-least-once drain boundary

* no-mistakes(review): Prevent symlink races in wake annotations

* no-mistakes(review): Exercise wake symlink race regression

* test: document intentional AFK marker subprocesses

* fix(wake): isolate annotation marker state
…anges (kunchenguid#752)

* fix(watcher): stabilize Linux process identity

* no-mistakes(document): document FM_PROC_ROOT_OVERRIDE and Linux starttime identity rationale
…nchenguid#775)

* fix(send): treat opencode busy-queued composer state as submitted

When fm-send sends a message to a BUSY opencode crewmate on the tmux
backend, opencode accepts the Enter and queues the message for the next
turn, but leaves the typed text visible in the composer row.  The
submit-verification loop sees a pending composer, exhausts retries, and
reports a false "Enter swallowed" failure while the message is actually
delivered.

Fix: after Enter retries are exhausted and the composer still shows
pending, check fm_pane_is_busy.  If the pane is busy (agent mid-turn,
footer shows "esc interrupt"), the harness queued the message, so
return "empty" (accepted).  On an idle pane, keep returning "pending"
(genuine swallow detection preserved).

Regression tests cover four scenarios:
- busy pane + pending composer -> empty (message queued)
- idle pane + pending composer -> pending (genuine swallow)
- busy pane + composer clears on first Enter -> empty
- idle pane + composer clears on first Enter -> empty (existing path)

* docs: document busy-queued Enter exception across backend docs and skills

Add explanatory comments and backend documentation for the
busy-queued Enter fix (opencode 1.18.4 accepts Enter mid-turn
but keeps typed text in composer until the turn ends):

- bin/fm-tmux-lib.sh: document the busy-aware fallback in the
  file header and above fm_tmux_submit_enter_core
- .agents/skills/afk/SKILL.md: daemon-facing policy note
- .agents/skills/harness-adapters/SKILL.md: harness-specific fact
- docs/tmux-backend.md: submit-acknowledgement section with the
  busy-queue exception
- docs/herdr-backend.md: record the known gap
- docs/architecture.md: cross-reference in the daemon section

* test(tmux): fix SC2181 and make busy-submit test executable
* fix(supervision): verb-aware captain relevance, AFK wedge, head-bound state

Stop free-text tokens like "merged" from promoting nonterminal working: lines
to captain-relevant, so AFK no longer permanently suppresses idle recovery.
Defend wedge aging independently for nonterminal progress verbs, bind
no-mistakes current-state attribution to code identity (not branch alone),
and mark setup-complete as nonterminal in the ship brief scaffold.

* no-mistakes(review): Enforce nonterminal suppression and head-bound run attribution

* no-mistakes(document): Document current-code-bound run attribution

* no-mistakes(test): Wait for stable Herdr shell readiness

* no-mistakes(test): Make Herdr and watcher readiness tests deterministic

* no-mistakes(test): Make tmux capture and watcher lifecycle deterministic

* no-mistakes(document): Document corrected supervision contracts
* fix: allow safe teardown during watcher recovery

* no-mistakes(review): Distinguish unsafe-teardown deny guidance via policy reason code

* no-mistakes(document): Sync continuity-gate docs to allow teardown recovery

* test: mark dynamic teardown fixture literal

* no-mistakes(document): docs: add teardown to continuity gate allow list
Upstream kunchenguid#744 renamed guard repair guidance from "resume supervision" to
"repair missing watcher supervision". Keep that distinction on our
Cursor/Kimi primary harnesses and give them ordinary-wake lines.
@Amplify-Logic
Amplify-Logic force-pushed the fm/firstmate-upstream-cherrypick-m3 branch from e871ebb to c19e552 Compare July 22, 2026 10:56
The sequential suite now includes continuity and supervision regressions
from upstream cherry-picks. CI logs show steady progress with no long
gaps through ~15 minutes, so the job was cancelled mid-run rather than
hung. Keep a hard timeout, but give a healthy full pass room to finish.
@Amplify-Logic
Amplify-Logic merged commit 13fcb32 into main Jul 22, 2026
4 of 5 checks passed
@Amplify-Logic
Amplify-Logic deleted the fm/firstmate-upstream-cherrypick-m3 branch September 9, 2026 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants