Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
295 commits
Select commit Hold shift + click to select a range
96244f4
fix: reconcile existing AGENTS.md safely (#405)
kunchenguid Jul 10, 2026
08453f9
feat: support project-less secondmate homes (#409)
kunchenguid Jul 10, 2026
31afb8c
fix: delegate backlog handoffs to tasks-axi (#411)
kunchenguid Jul 10, 2026
171207c
fix: ignore secondmate home marker during sync (#417)
kunchenguid Jul 10, 2026
a955a05
fix(composer): prevent dead-shell message injection (#416)
kunchenguid Jul 10, 2026
7788fa3
feat(watcher): add paused external-wait supervision (#421)
kunchenguid Jul 10, 2026
5f808cc
fix: preserve X-mode follow-up platform limits (#425)
kunchenguid Jul 10, 2026
0eaf293
fix(composer): handle ANSI ghost text safely (#429)
kunchenguid Jul 10, 2026
6d90240
fix(spawn): make tmux window handling robust under non-default config…
Deeds67 Jul 10, 2026
3e3dff6
test: isolate session-start suite from ambient harness markers (#432)
kunchenguid Jul 10, 2026
38086ea
fix(teardown): retry transient index locks during worktree return (#435)
kunchenguid Jul 10, 2026
492c937
fix: complete brief help and consolidate documentation (#438)
kunchenguid Jul 10, 2026
bc558c6
fix: detect Git and centralize backend configuration (#445)
kunchenguid Jul 10, 2026
52241a5
feat(daemon): add backend-independent wedge alerts (#444)
kunchenguid Jul 10, 2026
8cd90fe
docs: centralize firstmate operating contracts (#447)
kunchenguid Jul 11, 2026
3f549c1
fix(cmux): close last workspace during teardown (#449)
kunchenguid Jul 11, 2026
0daf674
fix: recover orphaned packed-refs locks during fleet sync (#453)
kunchenguid Jul 11, 2026
1fb1e30
feat(herdr): escalate blocked panes immediately (#472)
kunchenguid Jul 11, 2026
ad39e49
docs(readme): reposition firstmate as an agent distro (#473)
kunchenguid Jul 11, 2026
a6508b7
feat: add deterministic bounded bearings snapshots (#475)
kunchenguid Jul 11, 2026
78f9cce
fix: enforce deterministic ShellCheck parity (#481)
kunchenguid Jul 11, 2026
88e38ea
feat: guard primary shells from persistent cd commands (#483)
kunchenguid Jul 12, 2026
cb6e8ed
brief: add no-mistakes shared-daemon rule to ship and scout scaffolds…
mielyemitchell Jul 12, 2026
9ecd7c4
feat: make bearings concise and accurate (#485)
kunchenguid Jul 12, 2026
ad9f3a7
fix: harden away-mode daemon lifecycle (#490)
kunchenguid Jul 12, 2026
6556882
fix: prevent no-mistakes gate agents from driving the fleet (#518)
kunchenguid Jul 13, 2026
2364817
fix: guard secondmate primary sessions from blind turn ends (#505)
kunchenguid Jul 13, 2026
547acd7
fix: make bootstrap diagnostics backend-aware (#519)
kunchenguid Jul 13, 2026
b708731
fix: preserve follow-up platform context after inbox cleanup (#520)
kunchenguid Jul 13, 2026
85b7a29
fix: preserve secondmate routing markers in terminal sends (#533)
kunchenguid Jul 13, 2026
8c0d9eb
fix: align Grok effort handling with 0.2.99 (#527)
korallis Jul 13, 2026
8934c17
fix: derive bearings from authoritative secondmate state (#555)
kunchenguid Jul 14, 2026
eb9ee2f
fix: restore fleet snapshots on stock macOS Bash (#578)
kunchenguid Jul 14, 2026
1811b89
fix(afk): make Pi escalation and return catch-up reliable (#587)
kunchenguid Jul 15, 2026
f8c5941
feat: support Pi max reasoning profiles (#537)
korallis Jul 15, 2026
e063ca5
chore: no-mistakes(document): Clarify yolo response ownership (#595)
kunchenguid Jul 15, 2026
fcb9e8a
feat: establish instruction ownership foundation (#619)
kunchenguid Jul 15, 2026
71db4be
fix: compress Firstmate contract and enforce delivery rigor ownership…
kunchenguid Jul 16, 2026
cd218f2
feat: add durable captain decision holds (#593)
kunchenguid Jul 16, 2026
064aa67
fix(bin): harden PR check artifacts (#556)
kunchenguid Jul 16, 2026
815f7af
fix(bin): compact session-start backlog digest (#636)
kunchenguid Jul 16, 2026
2406354
fix: dedupe stale watcher guard banners (#637)
kunchenguid Jul 16, 2026
c115561
fix(bin): balance bearings landed baseline (#640)
kunchenguid Jul 16, 2026
a5d3652
fix: clarify captain-facing translation contract (#644)
kunchenguid Jul 16, 2026
1346ff7
fix(bin): make bootstrap output and nudges deterministic (#646)
kunchenguid Jul 16, 2026
508a6b7
docs(secondmate-provisioning): clarify concise registry ownership (#649)
kunchenguid Jul 16, 2026
024b96b
fix(bin): strip quoted blocked_by values during decision hold resolve…
kunchenguid Jul 17, 2026
e6f240c
feat(secondmate): inherit shared captain preferences (#656)
kunchenguid Jul 17, 2026
c27135c
feat: gate local agent secret injection (#658)
kunchenguid Jul 17, 2026
85643ee
test: isolate Herdr autodetect smoke sessions (#662)
kunchenguid Jul 17, 2026
5bf59ba
docs: adopt under way for active work (#666)
kunchenguid Jul 17, 2026
6de9278
Revert "feat: gate local agent secret injection (#658)" (#668)
kunchenguid Jul 17, 2026
46e4201
fix(pi): distinguish stale locks when arming watcher (#681)
kunchenguid Jul 17, 2026
1182883
fix: accept secondmate house vocabulary (#685)
kunchenguid Jul 18, 2026
d939c49
fix(bin): parse handoff homes after registry parentheticals (#686)
kunchenguid Jul 18, 2026
3ebb219
feat: add native session-start nudges (#687)
kunchenguid Jul 18, 2026
6bdeb3a
docs: call built-in defaults the firstmate repo, not template (#688)
kunchenguid Jul 18, 2026
bc1a21b
fix(bin): repair fm-brief.sh parse error and harden set -u array expa…
Ballestar Jul 18, 2026
3729081
fix(bin): keep watcher supervision continuous across child cycles (#693)
kunchenguid Jul 19, 2026
b2bf95f
fix: fetch current PR head for review diffs (#722)
kunchenguid Jul 19, 2026
7a9b4dd
docs: resolve five contract contradictions across AGENTS.md, README, …
ICGNU3 Jul 19, 2026
15b0fb9
docs(harness): correct Grok exit guidance (#742)
kunchenguid Jul 19, 2026
ab8cea6
fix(watcher): bound stale wakes for parked crew (#743)
kunchenguid Jul 19, 2026
68c6110
fix(supervision): distinguish ordinary wakes from recovery (#744)
kunchenguid Jul 20, 2026
c12bdea
fix(x-mode): dedupe pending mention wakes (#745)
kunchenguid Jul 20, 2026
4ab61fa
feat(wake): enrich drained signals with bounded status context (#747)
kunchenguid Jul 20, 2026
628292d
feat(herdr): add optional presentation spaces (#784)
kunchenguid Jul 21, 2026
c49f823
fix(send): treat opencode busy-queued composer state as submitted (#775)
KostadinP Jul 21, 2026
3f9e70e
fix(spawn): require two stable reads before accepting worktree path (…
Freudator86 Jul 21, 2026
a26b37c
fix(bin): make watcher process identity immune to Linux wall-clock ch…
vvizlan Jul 21, 2026
ea3ac2e
fix: prevent AFK idle stalls and stale run attribution (#758)
jjames27th-eng Jul 21, 2026
916c8e2
fix(bin): allow safe teardown during watcher recovery (#750)
nithingm Jul 21, 2026
f9a89c3
feat(herdr): order presentation spaces while preserving focus (#790)
kunchenguid Jul 21, 2026
b4316be
fix(bin): send literal config reread nudges after pushes (#809)
kunchenguid Jul 21, 2026
59ece45
feat(watch): follow GitLab merge requests to merge (#797)
karotkriss Jul 21, 2026
c58cb0f
fix(herdr): group projected children beneath owning parents (#821)
kunchenguid Jul 22, 2026
b843c66
fix: keep local no-mistakes tests intent-targeted (#823)
kunchenguid Jul 22, 2026
f02eef1
feat: add canonical timed test runner (#825)
kunchenguid Jul 22, 2026
f61e65c
fix: surface main inventory gaps in Bearings (#830)
kunchenguid Jul 22, 2026
622d467
feat: add bounded concurrent test isolation proof (#832)
kunchenguid Jul 22, 2026
14c0d5f
feat: guard against missed secondmate reports (#834)
kunchenguid Jul 22, 2026
f6c281a
feat: require pinned real-Herdr CI coverage (#838)
kunchenguid Jul 22, 2026
673b6ad
feat: shard portable tests and add bounded local parallelism (#841)
kunchenguid Jul 22, 2026
50cc24a
fix: block primary-session delegation outside the fleet (#854)
ItsFlow Jul 22, 2026
f5bdea3
fix: install tasks-axi in portable CI shards (#866)
kunchenguid Jul 22, 2026
5140413
feat(bin): make dispatch profiles quota aware (#867)
kunchenguid Jul 22, 2026
593e3a2
Add built-in ahoy recap skill (#873)
kunchenguid Jul 22, 2026
5549834
fix: preserve trustworthy Bearings data in partial snapshots (#875)
kunchenguid Jul 22, 2026
4497181
feat(pi): add session-local calm mode (#884)
kunchenguid Jul 23, 2026
82a7943
fix(pi): prevent redundant watcher re-arms (#885)
kunchenguid Jul 23, 2026
6db3b09
fix(pi): clean up Calm transcript rendering (#895)
kunchenguid Jul 23, 2026
bd43c73
fix: execute every PR body compliance event (#898)
kunchenguid Jul 23, 2026
6bcb381
fix: exclude operational injections from ahoy boundaries (#899)
kunchenguid Jul 23, 2026
68ed7ed
fix: canonically classify operational inputs across harnesses (#909)
kunchenguid Jul 23, 2026
a7e01bc
fix: avoid generic secondmate start acknowledgements (#926)
kunchenguid Jul 23, 2026
ca4be1c
fix(pi): make calm mode persistent and gapless (#927)
kunchenguid Jul 23, 2026
b24e72c
fix(watch): retire merged PR polls after durable notification (#932)
kunchenguid Jul 23, 2026
792174d
fix: refine scout intake and parallel dispatch (#934)
kunchenguid Jul 23, 2026
65ad47b
fix(pi): prevent duplicate assistant replies in Calm (#936)
kunchenguid Jul 23, 2026
d89a1b6
perf(bin): shrink the ShellCheck source graph (#939)
kunchenguid Jul 23, 2026
6b0d21d
fix(pi): remove Calm hidden-block gaps (#942)
kunchenguid Jul 23, 2026
ec09871
fix: enforce contract boundaries for ask-user findings (#945)
kunchenguid Jul 24, 2026
587f591
docs: prefer direct operational paths (#946)
kunchenguid Jul 24, 2026
1c4d210
fix(pi): hide operational user rows in Calm mode (#948)
kunchenguid Jul 24, 2026
f017572
fix: relaunch missing second mates at session start (#950)
kunchenguid Jul 24, 2026
3eca8ff
fix(herdr): reclaim resumed task projections after restart (#967)
kunchenguid Jul 24, 2026
cb3aa7b
Teach Ahoy to surface open decisions (#968)
kunchenguid Jul 24, 2026
10ee779
Require shipshape routine acknowledgement (#969)
kunchenguid Jul 24, 2026
861b1f8
docs: separate current guidance from verification evidence (#994)
kunchenguid Jul 24, 2026
418ab78
fix: preserve Claude watcher continuity across Stop hooks (#997)
kunchenguid Jul 24, 2026
2b7cd66
fix(herdr): clean stale projections at session start (#996)
kunchenguid Jul 24, 2026
b05eb24
fix: recover Claude supervision without watcher-status gate (#1001)
kunchenguid Jul 24, 2026
5c89d36
fix: make quota-aware profile selection agent-owned (#1018)
kunchenguid Jul 25, 2026
3f71cdd
fix(bin): remove vestigial dispatch selector (#1026)
kunchenguid Jul 25, 2026
34213e6
docs(agents): drop superseded interim quota-window rule (#1039)
kunchenguid Jul 25, 2026
aca3ad1
fix(tmux): scope busy detection and recognize current Claude turns (#…
kunchenguid Jul 26, 2026
c64ad1c
feat: add verified Kimi crewmate adapter (#1047)
kunchenguid Jul 26, 2026
39b450b
fix: harden Kimi submission and spinner matching (#1058)
kunchenguid Jul 26, 2026
4d6992a
feat(bin): add guarded Kimi turn-end wake (#1059)
kunchenguid Jul 26, 2026
a5fe1bc
fix(tmux): classify bordered composers across all rows (#1066)
kunchenguid Jul 26, 2026
b29621b
feat(bin): add verified pi-signed runtime adapter (#1145)
kunchenguid Jul 27, 2026
9ea1a1a
fix(pi): rearm watcher across session transitions (#1166)
kunchenguid Jul 28, 2026
fa0d85d
feat: route crew dispatch using quota-window pace (#1172)
kunchenguid Jul 28, 2026
fbece9c
fix: adapt Grok Stop continuation and harden endpoint cleanup (#1171)
kunchenguid Jul 28, 2026
514f0ab
fix: restore stock macOS Bash 3.2 brief scaffolding (#1093)
karotkriss Jul 28, 2026
2459f77
test: stabilize tmux teardown conformance baseline (#1209)
kunchenguid Jul 28, 2026
b6e351d
docs: slim quota-array-dispatch to the pace selection core (#1197)
kunchenguid Jul 28, 2026
e5bd082
feat(bin): inherit backend config into secondmate homes (#1219)
kunchenguid Jul 28, 2026
c0c0881
fix(pi): remove Calm's upper version ceiling (#1226)
kunchenguid Jul 29, 2026
7cbb3f6
fix(bin): allow session-local todo tools in the subagent guard (#1204)
danielkuykendall23-boop Jul 29, 2026
a117b41
fix(session-lock): resolve Claude bg-spare ancestry to the outermost …
trillium Jul 29, 2026
a323c2b
fix: conferma l'avvio del watcher su Windows/MSYS (#1212)
Unknownzed Jul 29, 2026
41ffd45
fix(spawn): forward CLAUDE_CONFIG_DIR to claude crewmates (#1195)
lucashalbert Jul 29, 2026
99533c5
fix: preserve dispatch identity across authentication checks (#1233)
kunchenguid Jul 29, 2026
6ec5e08
fix(bin): normalize relative durable paths (#1256)
sparkus Jul 29, 2026
c21bf54
refactor(skills): make Bearings chat-only by default (#1136)
deeto15 Jul 29, 2026
96e027e
Clarify follow-up routing during validation (#1277)
kunchenguid Jul 30, 2026
a24eac1
fix: honor concrete approval for project operations (#1272)
kunchenguid Jul 30, 2026
0bbb27b
fix(skills): route new project intake through secondmate scopes (#1275)
kunchenguid Jul 30, 2026
daf6dce
fix: scope validation corrections by accepted behavior (#1281)
kunchenguid Jul 30, 2026
a2d5f26
test: replace source assertions with behavioral coverage (#1282)
kunchenguid Jul 30, 2026
56a7ac6
fix(watch): escalate busy workers with no completed turn (#1286)
kunchenguid Jul 30, 2026
e595611
fix(gitignore): ignore config/ as a directory, not by exact filename …
karotkriss Jul 30, 2026
a53ffc1
fix(tests): replace source-content .gitignore assertion with behavior…
kunchenguid Jul 30, 2026
79e62b8
feat: bound and consolidate startup memory during stow (#1303)
kunchenguid Jul 30, 2026
f0d7cbe
fix(herdr): place workers in the launching workspace (#1328)
kunchenguid Jul 30, 2026
3a112a1
fix(calm): refine Calm working boat animation (#1339)
kunchenguid Jul 31, 2026
28b02d2
fix(dispatch): preflight candidate auth before quota escalation (#1349)
kunchenguid Jul 31, 2026
5fca47f
feat(x-mode): reconcile promised public replies deterministically (#1…
kunchenguid Jul 31, 2026
96542a4
feat(bin): replace busy heuristics with semantic lifecycle state (#1327)
kunchenguid Jul 31, 2026
621299a
fix: preserve Calm boat continuity across working periods (#1356)
kunchenguid Jul 31, 2026
f7d0d0a
fix: restore evidence-based dispatch eligibility (#1358)
kunchenguid Jul 31, 2026
3772964
docs: define captain instruction precedence (#1362)
kunchenguid Jul 31, 2026
9fdef64
docs: define validation supersession sequence (#1407)
kunchenguid Jul 31, 2026
000c1db
fix: bind backend overrides to exact-task authority (#1413)
kunchenguid Jul 31, 2026
66b0f77
fix(herdr): prevent focus flashes during projected workspace cleanup …
kunchenguid Jul 31, 2026
a805766
fix: prioritize completion runway in quota-aware dispatch (#1431)
kunchenguid Jul 31, 2026
68641a3
fix(bin): preserve full task contract in no-mistakes intent (#1447)
kunchenguid Aug 1, 2026
1e24757
fix(bin): parse punctuated secondmate registry entries safely (#1452)
kunchenguid Aug 1, 2026
8c21b10
feat(bin): add durable process-event supervision (#1483)
kunchenguid Aug 2, 2026
cd73e75
fix(bin): retire terminal process events and surface queued wakes (#1…
kunchenguid Aug 2, 2026
f5ab708
perf: shard portable serial tests across CI runners (#1544)
kunchenguid Aug 2, 2026
88b2a94
fix(bin): correct session lock and attached watcher supervision (#1545)
kunchenguid Aug 2, 2026
33a4287
fix(bin): harden Claude supervision auto-arm recovery (#1495)
kunchenguid Aug 2, 2026
4ee4a0a
feat(bin): require an explicit per-task delivery contract (#1563)
kunchenguid Aug 3, 2026
7809ab9
feat(bin): support remote secondmate homes (#1576)
kunchenguid Aug 3, 2026
976d97f
feat: add per-task trace context propagation (#995)
allstargg Aug 3, 2026
cf95112
fix(bin): harden tmux agent liveness across harnesses (#1577)
kunchenguid Aug 3, 2026
3d9d12d
feat(bin): propagate trace context to remote secondmates (#1609)
kunchenguid Aug 3, 2026
733a504
feat(bin): preflight remote runtime tool paths (#1623)
kunchenguid Aug 4, 2026
e5e8a67
feat: gate remote second mates on Herdr readiness (#1639)
kunchenguid Aug 4, 2026
c8edff3
fix: isolate remote secondmates in shared Herdr session (#1659)
kunchenguid Aug 4, 2026
a83be60
feat: route remote commands through an Aqua job worker (#1660)
kunchenguid Aug 4, 2026
fc3684a
fix: clarify remote doctor bootstrap path (#1691)
kunchenguid Aug 4, 2026
1939785
fix(bin): bound remote SSH dead-peer detection (#1699)
kunchenguid Aug 4, 2026
4a9979a
fix: report stale AXI tools during bootstrap (#1701)
kunchenguid Aug 4, 2026
d0461e4
fix: prevent false watcher-down alarms in Claude sessions (#1661)
karotkriss Aug 4, 2026
1cd97c0
test: prevent fixture temporary directory leaks (#1704)
kunchenguid Aug 4, 2026
3089a57
feat(herdr): enable presentation spaces by default (#1708)
kunchenguid Aug 4, 2026
bb352e7
fix(bin): surface fleet-wide open decisions on every wake drain (#1711)
kunchenguid Aug 5, 2026
7ef26c4
fix(bin): abort parked runs and reap leaked processes before teardown…
kunchenguid Aug 5, 2026
bea3d23
fix: resolve fm-remote-entrypoint.sh SCRIPT_DIR through a PATH symlin…
kunchenguid Aug 5, 2026
71f0b3f
fix(pi): gate Calm built-in overrides by activation state (#1724)
kunchenguid Aug 5, 2026
30b18b9
fix(bin): persist secondmate parent bindings for cleanup (#1727)
kunchenguid Aug 5, 2026
ef2c3a2
feat(bin): enforce latest AXI-family tool floors (#1733)
kunchenguid Aug 5, 2026
bf01a42
fix(bin): bound open decision scans with incremental cursors (#1737)
kunchenguid Aug 5, 2026
6f0f87f
fix(bin): prevent remote polls from blocking session startup (#1754)
kunchenguid Aug 5, 2026
3a8d63e
docs: present X mode as the X and Discord public surface (#1778)
kunchenguid Aug 6, 2026
3b6ee03
fix(bin): run session start deterministically from hooks (#1781)
kunchenguid Aug 6, 2026
5d77b48
fix: rename X mode to Relay in user-facing docs (#1784)
kunchenguid Aug 6, 2026
930ca76
feat: add Muse Code crewmate adapter (#1786)
kunchenguid Aug 6, 2026
8387039
fix(herdr): require 0.8.0 for default presentation spaces (#1787)
kunchenguid Aug 6, 2026
8ec3e94
fix(bin): classify settled Muse session logs as idle (#1788)
kunchenguid Aug 6, 2026
2cf0283
docs(agents): read the persisted digest when only a preview is shown …
kunchenguid Aug 6, 2026
345de4e
fix: preserve fleet state in truncated session-start digests (#1798)
kunchenguid Aug 6, 2026
6c206ed
feat(send): close answered decisions at answer time via --resolve-key…
kunchenguid Aug 6, 2026
fb368dc
fix(bin): seed remote secondmates from supplied origins (#1836)
kunchenguid Aug 7, 2026
91fa548
fix(tests): restore reliable fm-send backend parity coverage (#1851)
kunchenguid Aug 7, 2026
990753a
fix(bin): mirror remote secondmate status streams (#1846)
kunchenguid Aug 7, 2026
199cb79
docs(agents): describe the digest's fleet-state-before-context order …
kunchenguid Aug 7, 2026
4cdd0bd
fix(bin): fail closed on NUL bytes in the durable parent binding (#1847)
kunchenguid Aug 7, 2026
8398d31
fix(skills): reconcile inherited secondmate plans with shipped state …
kunchenguid Aug 7, 2026
4b6b89d
fix: move network checks off the session-start blocking path (#1860)
kunchenguid Aug 7, 2026
d8bb074
fix(procevent): apply remote replies during capture (#1831)
kunchenguid Aug 7, 2026
073cb30
feat(skills): port internal stow curation disciplines to the public s…
kunchenguid Aug 7, 2026
70aeba8
chore(bootstrap): raise lavish-axi version floor to 0.1.46 (#1865)
kunchenguid Aug 7, 2026
06b33aa
fix(bin): keep tracked Claude hook entries inert under grok 1.0.0 (#1…
jayjongcheolpark Aug 7, 2026
60eb534
feat(startup-network): record per-step elapsed times for the deferred…
kunchenguid Aug 7, 2026
167ff42
feat(stow): cascade the internal /stow to every registered secondmate…
kunchenguid Aug 8, 2026
be32879
fix(remote-job): stop workers abandoned by a pruned code root (#1927)
kunchenguid Aug 8, 2026
833a9a2
feat(bin): lint only the changed shard locally, full lint in CI (#1925)
kunchenguid Aug 8, 2026
2d2be63
feat(bin): add deterministic agent lifecycle control (#1568)
kunchenguid Aug 9, 2026
5ade9ef
feat(stow): add tiered decaying memory management (#1984)
kunchenguid Aug 9, 2026
74230fc
docs: add project vision (#1997)
kunchenguid Aug 9, 2026
fffe91e
fix(spawn): force regular Pi TUI for crews (#2005)
roelofb Aug 9, 2026
85e750a
fix(cmux): classify borderless Claude composers (#2029)
kunchenguid Aug 10, 2026
53ecbc7
docs(stow): generalize read-before-write in the public stow skill (#2…
kunchenguid Aug 10, 2026
f9b9d43
fix: resurface durable supervision work after re-arm (#2065)
kunchenguid Aug 10, 2026
9068958
ci: measure Herdr automation on Windows runners (#2100)
kunchenguid Aug 10, 2026
f74d9e4
feat(ahoy): guide captains through open decisions (#2099)
kunchenguid Aug 10, 2026
7f828ea
fix(stow): enforce startup-memory budget decisions (#2110)
kunchenguid Aug 11, 2026
fc5f164
fix(spawn): refresh pooled worktrees from origin before launch (#2116)
kunchenguid Aug 11, 2026
7f05100
fix(composer): unify safe classification across backends (#2102)
kunchenguid Aug 11, 2026
e836a7f
fix(spawn): gate Pi TUI mode by CLI capability (#2117)
kunchenguid Aug 11, 2026
76355e2
docs(vision): elevate experience, pain narrative, and distro virtues …
kunchenguid Aug 11, 2026
2d550fe
feat(bin): reconcile inactive terminal crew outcomes (#2167)
kunchenguid Aug 11, 2026
07450b9
ci: raise Herdr test timeout (#2191)
kunchenguid Aug 11, 2026
e8c7645
fix: refresh stale Pi instructions after compaction (#2163)
kunchenguid Aug 11, 2026
81ce6dc
feat: add deterministic condition-to-action watcher (#2200)
kunchenguid Aug 11, 2026
614fae6
fix(bin): honor a decision key stated after the verb colon (#2202)
kunchenguid Aug 11, 2026
c42cfe0
fix(bin): prevent watcher recovery acknowledgement livelock (#2212)
kunchenguid Aug 12, 2026
b5d430d
feat(fmx-respond): consume Relay conversation chains (#2206)
kunchenguid Aug 12, 2026
b91016f
fix: parse decision verbs before status metadata tags (#2280)
kunchenguid Aug 12, 2026
b0ad61e
fix(bin): collapse duplicate supervision wakes (#2287)
kunchenguid Aug 13, 2026
4930d2c
feat: add Cursor CLI crew harness (#2238)
kunchenguid Aug 13, 2026
96876db
fix(bin): require quota-axi 0.1.25 (#2300)
kunchenguid Aug 13, 2026
85cefa9
fix(bin): prevent false Pi watcher alarms during hand-offs (#2304)
kunchenguid Aug 13, 2026
81f7020
feat: support Cursor Agent CLI as a primary harness (#2305)
kunchenguid Aug 13, 2026
5521323
feat(bin): add decline and repair paths for decision holds (#2330)
kunchenguid Aug 13, 2026
db0280f
fix(bin): surface buried wake status lines once (#2331)
kunchenguid Aug 13, 2026
88d0f2e
feat: add max Calm presentation level (#2334)
kunchenguid Aug 13, 2026
9823ff8
feat(calm): hide mid-turn working notes by default (#2339)
kunchenguid Aug 13, 2026
1238402
chore: store no-mistakes test evidence in the repo (#2355)
kunchenguid Aug 14, 2026
6789876
chore: ignore scratchpad/ at the repo root (#2359)
kunchenguid Aug 14, 2026
f1a4af4
fix(ci): fail hung Herdr behavior runs in 20 minutes (#2413)
kunchenguid Aug 15, 2026
544d4d7
merge: finalize reconciled upstream sync
DereKk8 Aug 15, 2026
8d6d3a7
fix: restore upstream sync regression coverage
DereKk8 Aug 15, 2026
73da59c
test: align restored sync coverage with merged contracts
DereKk8 Aug 15, 2026
6ea9ffe
test: supply valid project metadata for PR guard
DereKk8 Aug 15, 2026
af17e2b
test: align stow contract with upstream lifecycle
DereKk8 Aug 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 20 additions & 21 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ No `/back` is needed. The first genuine message is the return signal:

- A message **without** the current operational prefix or a legacy bare marker, and **not** starting with `/afk` -> the captain is back.
Run `bin/fm-afk-return.sh` before acting on the message that brought the captain back.
That script owns correct-ordered daemon shutdown, durable wake draining, escalation and wedge evidence, and the return-catch-up gate.
That script owns correct-ordered daemon shutdown, durable wake presentation and post-handling acknowledgement, escalation and wedge evidence, and the return-catch-up gate.
If it reports a firstmate-actionable `blocked:` event, remediate it immediately through the normal lifecycle, or explicitly reclassify it with a durable reason and close its decision key with `resolved [key=...]`, then run `bin/fm-afk-return.sh check`.
Once the daemon stops, resume full per-wake responsiveness through the emitted primary-harness supervision protocol while blocker handling proceeds, so the gate never creates a blind wait.
Do not answer a Bearings request or perform any other ordinary captain work until the check exits successfully.
Expand Down Expand Up @@ -94,11 +94,11 @@ backend (tmux or herdr; see "Auto-discovered supervisor pane" below):

- **Primary-pane busy guard** - `pane_is_busy` trusts Herdr native `busy` when available, otherwise matches rendered output against only the detected primary harness's signature.
This narrow delivery guard never classifies a recorded worker task and never uses a global union of vendor patterns.
- **Composer-state guard** - `inject_msg` reads the full `empty`/`pending`/`unknown` verdict from `fm_backend_composer_state` and injects only when it is affirmatively `empty`.
`pending` means real unsubmitted text, while `unknown` includes an unreadable pane and a bare shell prompt left after the agent exits, so both defer.
The shared `bin/fm-composer-lib.sh` owns the content decision after each backend captures and structurally identifies its own composer row.
It preserves idle bordered composers such as claude's `│ > … │` and bare agent glyphs as empty, but a bare shell glyph is unknown unless inside a genuine bordered composer box; see `docs/herdr-backend.md` "Composer and injection safety" for the complete contract.
`pane_input_pending` remains the tested predicate for callers that only need to know whether real unsubmitted text is present, but it is insufficient for an injection-safety decision because it cannot distinguish `empty` from `unknown`.
- **Composer-state guard** - `inject_msg` reads the full `empty`/`pending`/`pending-unproven`/`unknown` verdict from `fm_backend_composer_state` and injects only when it is affirmatively `empty`.
Every other or future verdict defers, including an unreadable pane, ambiguous geometry, a blank unidentified row, and a bare shell prompt left after the agent exits.
Each adapter contributes only capture and capability facts to the fleet-wide screen classifier in `bin/fm-composer-lib.sh`, which owns every shape and verdict.
It preserves proven idle composers as empty but requires a genuine container around shell glyphs; see `docs/herdr-backend.md` "Composer and injection safety" for the operator contract.
`pane_input_pending` is the tested fail-closed predicate for callers that need to know whether the composer is unsafe: it treats every result except exact `empty` as pending.

A busy primary pane, or any composer verdict other than `empty`, defers the injection; the buffered escalation survives in `state/.subsuper-escalations` and is retried on the next housekeeping tick.
In afk mode the composer guard is belt-and-suspenders (no human is typing), but it protects against the race window between the captain returning and their message landing, a dead shell, and the daemon's own previous injection sitting unsent.
Expand All @@ -121,9 +121,9 @@ herdr - both literal, non-submitting sends), then submitted with Enter and
**verified** through the selected backend's submit primitive.
Enter is retried (Enter only, never a retype) until the backend confirms the
submit landed.
For tmux that confirmation is a cleared composer, using the same corrected,
border-aware detector as the composer guard.
For herdr, normal idle-baseline submits are confirmed by native agent-state showing a real turn started; the ANSI-aware composer classifier remains the affirmative-empty pre-injection guard and conservative fallback for non-idle or unreadable baselines.
For tmux that confirmation is normally a proven cleared composer from the shared classifier; an idle baseline transitioning to busy across this submit's own Enter also confirms that the turn started when a working harness hides its composer.
Without that baseline, busy state never converts an `unknown` composer into confirmation.
For herdr, normal idle-baseline submits are confirmed by native agent-state showing a real turn started; the shared classifier remains the affirmative-empty pre-injection guard and conservative fallback for non-idle or unreadable baselines.
A bordered-empty or ghost-only composer is recognized as empty where that backend uses composer confirmation, rather than mistaken for a swallowed Enter.
`fm-send.sh` uses the same primitive and exits non-zero
when a steer's Enter is positively swallowed, so firstmate learns an instruction
Expand All @@ -146,9 +146,8 @@ behavior but needs a separate fix; the gap is recorded in

## Classification policy

The daemon wraps `fm-watch.sh`, runs the watcher as a child, classifies each
wake reason in bash, and self-handles the routine majority without consuming a
firstmate turn.
The daemon wraps `fm-watch.sh`, runs the watcher as a child, presents every durable wake after each actionable watcher close, classifies each presented record in bash, and acknowledges the presented generation only after routing completes.
It self-handles the routine majority without consuming a firstmate turn.
Captain-relevant events, plus a bounded recheck of a declared external wait that remains idle, escalate to firstmate's context as one pre-read, single-line, batched digest.
The classification predicates (the captain-relevant verb set, declared-pause vocabulary, signal/stale tests, and fleet-scan) live in the shared `bin/fm-classify-lib.sh`, the same library the always-on watcher uses for its own triage when afk is off, so the two modes apply one identical policy.
While `state/.afk` exists the daemon owns the watcher, so the watcher reverts to one-shot and lets the daemon do the triage - the two never run their triage at the same time.
Expand Down Expand Up @@ -185,11 +184,12 @@ the operational prefix lets firstmate distinguish it from a real captain message
- **Busy and composer guards on the supervisor pane** - before injecting, the daemon runs the detected-primary-harness rendered busy guard and reads `fm_backend_composer_state` directly.
Only `empty` permits injection; `pending` protects half-typed or swallowed input, and `unknown` protects unreadable panes and bare dead-shell prompts.
Every other result preserves the buffer for retry, so the daemon never merges its digest into the captain's half-typed line or types it into a shell.
- The shared composer classifier receives a candidate row only after the active backend performs its own capture and structural row recognition.
tmux and herdr route their raw styled candidate rows through the shared `fm_composer_strip_ghost` extractor, which removes dim/faint and dark-TRUECOLOR ghost/placeholder text before classification.
They read the composer shape from a separately ANSI-stripped plain row because a dark TRUECOLOR border can be stripped with ghost content.
- The active backend passes its capture plus declarative styled, cursor, identity, and row capabilities to the shared screen classifier; all structural recognition and verdict logic remains in `bin/fm-composer-lib.sh`.
Styled captures let that owner remove dim/faint and dark-TRUECOLOR ghost or placeholder text while shape detection uses the ANSI-stripped screen, so a dark border is not lost with ghost content.
A ghost-only or idle bordered composer such as claude's `│ > ... │` therefore reads empty without allowing an unbordered shell prompt to do the same.
`FM_COMPOSER_IDLE_RE` still overrides tmux empty-composer matching after shared ghost and border stripping, and `FM_BUSY_REGEX` overrides the rendered delivery guards plus Grok's isolated task-state fallback.
`FM_COMPOSER_IDLE_RE` overrides the shared idle-placeholder regex, but a match alone never bypasses the classifier's shape-specific position and ANSI de-emphasis safety gates.
`FM_BUSY_REGEX` overrides the rendered delivery guards plus Grok's isolated task-state fallback.
A blank or otherwise unidentified input row carries no positive container proof and defers injection, so a modal dialog or a mid-redraw pane is never an injection target.
- **Max-defer escape** - the daemon must never silently wedge. If anything stays
buffered past `FM_MAX_DEFER_SECS` (default 300s), the daemon attempts one
normal flush, which still requires an idle pane and an affirmatively empty composer. If that
Expand All @@ -202,9 +202,8 @@ the operational prefix lets firstmate distinguish it from a real captain message
on tmux, `pane send-text` on herdr), then submitted with Enter and verified.
Enter is retried, Enter only and never a retype, until the backend submit
primitive reports `empty` as its caller-facing success verdict.
For tmux that verdict means the shared-ghost-aware and border-aware composer
cleared.
For herdr's normal idle-baseline path it means native agent-state observed a real turn start; herdr uses the ANSI-aware structural classifier for the pre-injection composer guard and fallback paths.
For tmux that verdict normally means the shared classifier proved the composer cleared; a baseline-gated idle-to-busy transition may instead prove this Enter started the turn.
For herdr's normal idle-baseline path it means native agent-state observed a real turn start; herdr uses the shared classifier for the pre-injection composer guard and fallback paths.
This lets ghost-only or bordered-empty composers count as empty where a composer read is the active confirmation signal.
- **Marker strip** - `strip_injection_marker` removes the current operational
prefix or legacy bare marker before classification or relay, so the digest
Expand Down Expand Up @@ -239,8 +238,8 @@ Always exit through `bin/fm-afk-launch.sh stop`, which keeps `state/.afk` presen

These properties must hold:

- Nothing is lost. The durable queue plus `fm-wake-drain.sh` recover any missed
or crashed injection.
- Nothing is lost after queue publication.
The daemon leaves every presented wake durable until routing completes and post-handling acknowledgement succeeds, so interruption replays the same work to the daemon or its successor.
- Wedge detection is bounded-latency, not lossy.
- Declared external waits are rechecked on a separate, bounded cadence rather than being mislabeled as wedges.
- The catch-all scan backs up the keyword classifier.
Expand Down
8 changes: 7 additions & 1 deletion .agents/skills/ahoy/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: ahoy
description: Recap visible session events since the prior real captain message plus visibly unanswered captain decisions when the captain explicitly invokes /ahoy, with a Bearings fallback when /ahoy is the session's first real captain message.
description: Recap visible session events and guide the captain through visibly unanswered decisions when the captain explicitly invokes /ahoy, with a Bearings fallback when /ahoy is the session's first real captain message.
user-invocable: true
metadata:
internal: true
Expand Down Expand Up @@ -43,6 +43,12 @@ Give the captain a concise session-only recap without gathering fresh state.
7. If no ordinary events occurred after the previous captain message but an older visibly open decision exists, report that decision instead of claiming nothing happened.
If neither ordinary events nor visibly open decisions exist, say directly in one sentence that nothing happened after the previous captain message.

8. After the normal recap, when the existing visibly open decision inventory contains decisions, begin a guided decision-clearing flow by presenting only the single open decision judged most impactful by the first mate.
Make clear that impact ordering is the first mate's judgment rather than a mechanical score.
Give enough escalation-quality context to decide easily: the decision, why it matters, the options, and a recommendation.
9. When the captain answers the presented decision, present the next highest-impact decision from that existing inventory in the same form.
Continue one decision at a time until none remain, without starting this flow when the inventory is empty.

The current `/ahoy` message is outside the recap interval.
A previous `/ahoy` is a real captain message and may be the next interval boundary.
If context compaction makes the prior boundary unavailable, state that the exact session boundary is unavailable and summarize only visibly supported events.
Expand Down
10 changes: 6 additions & 4 deletions .agents/skills/decision-hold-lifecycle/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,9 @@ After inventorying the whole report and review surface, run `bin/fm-decision-hol
A completed investigation and an ended visual review use this same owner and completion command; a visual tool, including Lavish, never owns a parallel completion policy.
Run the command in the originating work's authoritative `FM_HOME`; main-home work creates main-home holds, and secondmate-owned work creates holds in that secondmate home's backlog rather than copying them into the main backlog.
Do not close a hold merely because the originating investigation completed, its report was archived, its visual review ended, or its task was torn down.
The hold remains the authoritative Captain's Call item until the captain's answer is durably recorded, dependent work is created in the same backlog and blocked by that hold, and `bin/fm-decision-hold.sh resolve` routes the answer by clearing those dependency edges before closing the hold.
When the captain's answer authorizes follow-up work, the hold remains the authoritative Captain's Call item until that answer is durably recorded, dependent work is created in the same backlog and blocked by the hold, and `bin/fm-decision-hold.sh resolve` routes the answer by clearing those dependency edges before closing the hold.
When the captain's answer routes no follow-up work at all, such as a declined proposal, `bin/fm-decision-hold.sh decline` records that answer and closes the hold; it never substitutes for routing work the captain did authorize.
A hold closed outside this owner leaves no durable answer, so the completion gate keeps failing until `bin/fm-decision-hold.sh repair` records the decision the captain actually gave; neither unrouted path may stand in for an answer the captain has not given.
Resolved findings, recommendations that need no captain choice, and prose that merely sounds decision-like do not create holds.
Bearings reads the resulting structured state and must never compensate by scraping historical reports, visual-review artifacts, terminal output, chat, or other prose.

Expand All @@ -32,9 +34,9 @@ Bearings reads the resulting structured state and must never compensate by scrap
3. For each choice, choose a stable key and use the script's `hold` command with a concise title, reason, and repository.
4. Run the script's `complete` command with the full unresolved-key inventory for that review pass.
5. Relay the choices to the captain as decisions from Bearings' Captain's Call section under `AGENTS.md` section 9; do not use the word hold in captain chat.
6. After the captain decides, record dependent work with normal tasks-axi commands and block it by the hold identity.
7. Put the captain's exact durable decision in a file and use the script's `resolve` command with every routed task.
8. Confirm Bearings no longer shows the closed hold and that routed work remains in structured backlog state.
6. If the captain authorizes dependent work, record it with normal tasks-axi commands and block it by the hold identity.
7. Put the captain's exact durable decision in a file and close the hold with the script's `resolve` command and every routed task, its `decline` command when the answer routes no work, or its `repair` command when the hold was already closed outside the script.
8. Confirm Bearings no longer shows the closed hold and that any routed work remains in structured backlog state.

`bin/fm-decision-hold.sh --help` owns command syntax, identity construction, completion attestation, retry behavior, and close ordering.
`docs/decision-hold-lifecycle.md` records the mechanism and regression evidence without restating this policy.
Loading
Loading