Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
d5c2507
fix(bin): ring the worker inbox doorbell only for a newly written pro…
karotkriss Sep 28, 2026
b3dbc67
fix: prevent manual Claude Stop hook calls from arming supervision (#…
kunchenguid Sep 28, 2026
a256cb5
feat(firstmate-calm): show supervision notes in Claude Code (#6039)
kunchenguid Sep 28, 2026
4e158e6
fix: stop quiet mode from holding requested actions for return (#6033)
kunchenguid Sep 28, 2026
d9a89b2
Say ahoy impact order is the first mate's pick. (#6065)
kunchenguid Sep 28, 2026
eb219c8
fix(bin): accept a task's next PR after its bound PR merges in fm-pr-…
karotkriss Sep 28, 2026
2d833ff
fix: treat quiet records as attended across supervision (#6064)
kunchenguid Sep 29, 2026
00679ae
fix: report supervision host latches accurately in away return briefs…
kunchenguid Sep 29, 2026
40e981d
fix: shorten Claude Code Calm supervision note label (#6086)
kunchenguid Sep 29, 2026
b5fdf74
feat(bin): add a disposable live supervision lab builder (#6037)
kunchenguid Sep 29, 2026
46d58d6
fix: keep watcher arms and reply listeners alive through slow cycles …
kunchenguid Sep 29, 2026
c5f48e4
fix(bin): retry fm-pr-merge a bounded number of times when GitHub mer…
karotkriss Sep 29, 2026
0446e4c
Merge remote-tracking branch 'upstream/main' into fm/firstmate-upstre…
Hozzy02 Sep 29, 2026
260c4f0
fix(bin): converge every open owner onto a known terminal contributio…
karotkriss Sep 29, 2026
0a2cdf9
feat: enable supervision host by default for Claude primaries (#6124)
kunchenguid Sep 29, 2026
5bddfc4
fix(bin): create the state dir on a fresh primary before the session-…
karotkriss Sep 29, 2026
1f2c954
fix(bin): measure pending-reply grace from turn completion, not deliv…
karotkriss Sep 29, 2026
a774c44
fix(bin): stop provider-table lookup from writing broken-pipe errors …
tiago-peixoto Sep 29, 2026
e2668de
fix: restore portable CI behavior across Pi rendering and remote prov…
kunchenguid Sep 30, 2026
b3d4133
fix: confirm Lavish board replies before worker handoff (#6169)
kunchenguid Sep 30, 2026
12e90e1
fix: inherit supervision host opt-out across secondmates (#6154)
kunchenguid Sep 30, 2026
c35b9a6
fix: reduce supervision exit latency and stabilize host tests (#6179)
kunchenguid Sep 30, 2026
eb77f02
ci: rebalance portable test groups and enforce a packing budget (#6192)
kunchenguid Sep 30, 2026
bd74468
fix(bin): run no repository hook when core.hooksPath is empty (#6216)
karotkriss Sep 30, 2026
65c75b0
fix(bin): let a stale record on a reassigned slot retire records-only…
karotkriss Sep 30, 2026
23e5584
fix(bin): keep the steering doorbell short under deep homes (#6240)
karotkriss Sep 30, 2026
fd325b1
feat(bin): add opt-in config/wait-no-turns so a waiting worker spends…
tiago-peixoto Sep 30, 2026
aedb7bb
fix(bin): close Gerrit-landed backlog items with the change URL as a …
slnkjthien Oct 1, 2026
549e07f
fix: reduce remote-job and supervision polling churn (#6255)
kunchenguid Oct 1, 2026
589ccec
fix(bin): load backend sibling libraries when sourced under zsh (#6221)
guanchengh-lgtm Oct 1, 2026
f593060
fix(bin): exclude a remote mate's own parent channel from self-home s…
kesslerio Oct 1, 2026
b5d9061
fix(bin): document accepted contribution verdict actors (#6307)
mremond Oct 1, 2026
8f756bb
fix(bin): recognize clone roots across path spelling differences (#6306)
mremond Oct 1, 2026
349e189
test: preserve Pi calm transcript captures with Pi 1.0 (#6338)
kunchenguid Oct 1, 2026
6af8331
fix(bin): preserve hold reasons and reject invalid completion invento…
mremond Oct 1, 2026
8690c41
fix: reclaim orphaned watcher arms on the next park (#6335)
kunchenguid Oct 2, 2026
241d461
fix(bin): restore downtime on supervision-host hand-back when the suc…
tiago-peixoto Oct 2, 2026
65e2aa4
fix: reduce remote-job polling process churn (#6363)
kunchenguid Oct 2, 2026
06be3ce
Merge remote-tracking branch 'upstream/main' into fm/firstmate-upstre…
Hozzy02 Oct 2, 2026
bec37a0
Merge origin/main into fm/firstmate-upstream-sync-0929
Hozzy02 Oct 2, 2026
62871bb
fix(lint): raise ShellCheck root address-space cap to 14 GiB
Hozzy02 Oct 2, 2026
08d87c2
fix(bin): disable nested herdr RPC bound in home-summary worker call
Hozzy02 Oct 2, 2026
7b34e01
fix(ci): raise the Normal timeout tier from 30 to 45 minutes
Hozzy02 Oct 3, 2026
e20c5dd
no-mistakes(ci): The failing check was a flake in tests/fm-remote-del…
Hozzy02 Oct 3, 2026
e824c7c
no-mistakes(ci): The failing check was tests/fm-remote-delta-read.tes…
Hozzy02 Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: afk
description: >-
Enter the away posture when the captain invokes /afk, says they are going afk, `state/.afk-contract` or `state/.afk` exists, an incoming message starts with `FM_INJECT_MARK`, or any `state/.subsuper-*` marker is involved.
It writes the durable away-posture record with the captain's away words verbatim as the whole mandate in the same turn as /afk, before any other work and without waiting for a further go, reads the words back in plain sentences after entry, announces hold-for-return only at entry, keeps the one supervision session running in the away posture (on Pi the supervision branch acts on the words by its own judgment and takes every safe actionable wake with main parked, as the supervision host does on a non-Pi home that opted into it; the daemon still delivers batched digests elsewhere for now), and on the first unmarked message renders the return brief from durable records before ordinary work resumes.
It writes the durable away-posture record with the captain's away words verbatim as the whole mandate in the same turn as /afk, before any other work and without waiting for a further go, reads the words back in plain sentences after entry, announces hold-for-return only at entry, keeps the one supervision session running in the away posture (on Pi the supervision branch acts on the words by its own judgment and takes every safe actionable wake with main parked, as the supervision host does on a non-Pi home that runs it; the daemon still delivers batched digests elsewhere for now), and on the first unmarked message renders the return brief from durable records before ordinary work resumes.
user-invocable: true
metadata:
internal: true
Expand All @@ -14,6 +14,7 @@ Away mode is a POSTURE of the one supervision session, not a second architecture
Being away changes exactly two things: how the captain is informed, and what happens at a captain-owned decision point (hold for return, or the answer the captain's away words already gave).
It never changes the authority set.
The posture is a file, `state/.afk-contract`, written only by `bin/fm-afk-contract.sh` in the same turn as `/afk`; nothing infers the posture from chat.
A record carrying quiet mode (`bin/fm-afk-contract.sh mode`) is not this posture: the captain is present, so none of this skill's holds for a return apply to it (the `quiet` skill owns it).
Typing `/afk` is itself the go: the captain may not look at the screen again, so entry never waits for a further human response, and no read-back gates it or asks for a go.
Hold-for-return is the default and the only reach profile this release records: there is no phone channel, and the entry announcement says so aloud every time.

Expand All @@ -31,15 +32,15 @@ Hold-for-return is the default and the only reach profile this release records:
The away daemon is no longer launched on Pi; the ordinary supervision session (`docs/pi-supervision-branch.md`) keeps running with the record present, and `bin/fm-afk-launch.sh start` refuses on these harnesses.
With the record present main is parked: the supervision branch takes every safe actionable wake, captain outcomes accumulate for the return brief, and main's standing authority relocates to the branch through the guarded scripts (`docs/pi-supervision-branch.md` "Postures"); only a wake the branch declines (including a broken branch or unsafe scan) or a watcher failure wakes main.
`/quiet` needs nothing extra on Pi: the attended branch already keeps routine wakes out of this conversation, so quiet-while-present is the attended posture's own shape there.
- **Claude, Cursor, OpenCode, omp, Grok, or Codex with `config/supervision-host`**: nothing to launch for `/afk`; go on to the announcement.
- **A home that runs the supervision host** (a Claude home unless `config/supervision-host-off` opts it out, or a Cursor, OpenCode, omp, Grok, or Codex home with `config/supervision-host` and no opt-out; `docs/configuration.md` "Supervision host"): nothing to launch for `/afk`; go on to the announcement.
The supervision host (`docs/supervision-host.md`) is the away session there: it runs the branch's contract on a headless engine under the record while main is parked, and `bin/fm-afk-launch.sh start` and `start-native` refuse the away daemon on that home.
If `enter` printed a `Supervision host: no engine ...` line, every away wake reaches this conversation instead; say so in the announcement.
`/quiet` enters nothing there where the attended host runs, and otherwise still launches the daemon below (the quiet skill's `quiet-check` decides).
- **Harness WITH a native in-pane tracked-background tool** (claude's and grok's, without the supervision host): run `bin/fm-afk-launch.sh start-native`, then run `FM_AFK_STATE_PREPARED=1 bin/fm-afk-start.sh` through that native tool.
- **Harness WITH a native in-pane tracked-background tool** (claude's and grok's, on a home that does not run the supervision host): run `bin/fm-afk-launch.sh start-native`, then run `FM_AFK_STATE_PREPARED=1 bin/fm-afk-start.sh` through that native tool.
This is a deliberate no-separate-terminal exception because the harness-hosted job creates no terminal or layout mutation, and a shell launcher cannot invoke a harness-native background tool.
If the native launch fails, run `bin/fm-afk-launch.sh stop` to roll back the prepared lifecycle.
Do not wrap it in `nohup ... &` (Codex/herdr can reap fire-and-forget shell children after a tool call returns).
- **Every other harness** (codex, opencode, omp, and cursor without the supervision host, and kimi): run `bin/fm-afk-launch.sh start`.
- **Every other harness** (codex, opencode, omp, and cursor on a home that does not run the supervision host, and kimi): run `bin/fm-afk-launch.sh start`.
It is the single owner of the daemon terminal: it creates a NON-VISIBLE tracked terminal for the current backend and passes the captain pane in as `FM_SUPERVISOR_TARGET` so the daemon injects into the captain, not its own new pane (docs/herdr-backend.md "Away-mode supervisor support").
Both daemon paths require the record `enter` wrote and share `bin/fm-afk-start.sh` as the daemon entry.
The daemon is **presence-gated**: it injects escalations only while `state/.afk` exists, and stays quiet otherwise.
Expand All @@ -60,7 +61,7 @@ Hold-for-return is the default and the only reach profile this release records:
Destructive, irreversible, and security-sensitive actions are never pre-authorizable whatever the words say, and ask-user findings keep the `ask-user-authority` policy unless the words pre-answer the exact decision; anything else that needs the captain holds for their return.
- On Pi, main is parked and the supervision branch handles every safe actionable wake under main's standing authority, through the same guarded scripts main would use: any pull request green at its live head may merge (which one the words meant is the branch's reading), queued work whose blockers cleared - already queued, or filed by the branch because the words explicitly call for it - dispatches within the spend cap, and a decision is answered with the captain's own pre-stated answer or under `ask-user-authority`.
Anything else holds for the return, a red merge never proceeds while away, local-only landing always waits for the captain, and only a wake the branch declines (including a broken branch or unsafe scan) or a watcher failure wakes main (`docs/pi-supervision-branch.md` "Postures").
- On a non-Pi home with `config/supervision-host`, the host's engine is that branch under the same rules, and a wake it hands back reaches main through that harness's own wake path (`Stop hook feedback` on Claude, a `watcher` follow-up on Cursor, OpenCode, and omp, the arm's background-task-completed notification on Grok, the checkpoint's output on Codex) with a `supervision-host:` line: that is automatic supervision, never the captain's return, so handle it under the away posture ([supervision protocol](../../../docs/supervision-protocols/supervision-host.md)).
- On a non-Pi home that runs the supervision host, the host's engine is that branch under the same rules, and a wake it hands back reaches main through that harness's own wake path (`Stop hook feedback` on Claude, a `watcher` follow-up on Cursor, OpenCode, and omp, the arm's background-task-completed notification on Grok, the checkpoint's output on Codex) with a `supervision-host:` line: that is automatic supervision, never the captain's return, so handle it under the away posture ([supervision protocol](../../../docs/supervision-protocols/supervision-host.md)).
- The session-start digest reports the posture under its AFK subsection, so a restart re-enters the posture from the record, not from memory.

## How to exit: the return
Expand Down Expand Up @@ -94,15 +95,15 @@ afk changes how the captain is informed and what happens at a captain-owned deci
A PR ready for merge keeps the merge authority from `AGENTS.md` section 7, and a needs-decision finding keeps the `ask-user-authority` policy; anything requiring the captain still waits for the captain's explicit word.
While the away-posture record exists, any pull request green at its live head may merge under away authority; which one the captain's words meant is the away session's reading, and a merge the words do not call for holds for the return.
Away authority never releases a captain hold, and it expires when the away record is archived.
`--allow-red` and `--allow-missing` remain attended-only and are refused while the record exists.
A merge under away authority must be synchronous; `fm-pr-merge.sh` refuses auto-merge and any GitHub queue state that cannot prove an immediate merge while the record exists.
The same gates bind whichever actor performs the action: on Pi the parked main's standing authority relocates to the supervision branch, which meets exactly these rules, and the spend cap recorded at entry is enforced by `fm-spawn.sh` for both actors while the record exists.
`--allow-red` and `--allow-missing` remain attended-only and are refused while the away record exists.
A merge under away authority must be synchronous; `fm-pr-merge.sh` refuses auto-merge and any GitHub queue state that cannot prove an immediate merge while the away record exists.
The same gates bind whichever actor performs the action: on Pi the parked main's standing authority relocates to the supervision branch, which meets exactly these rules, and the spend cap recorded at entry is enforced by `fm-spawn.sh` for both actors while the away record exists.
The captain's away words are their explicit instruction given before leaving, recorded verbatim and acted on by the away session's judgment at the moment an event makes them relevant; the words cover nothing they do not say, are never applied by analogy, and die at archive.
Destructive, irreversible, and security-sensitive actions are never pre-authorizable whatever the words say.

## The daemon, where it still runs

On the harnesses that still launch the daemon (every verified harness except Pi and pi-signed, and except away mode on a home with `config/supervision-host`), the mechanics below are unchanged.
On the harnesses that still launch the daemon (every verified harness except Pi and pi-signed, and except away mode on a home that runs the supervision host), the mechanics below are unchanged.

### Operational prefix contract

Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/ahoy/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Give the captain a concise session-only recap without gathering fresh state.
If neither ordinary events nor visibly open decisions exist, say directly in one sentence that nothing happened after the previous captain message.

8. After the normal recap, when the existing visibly open decision inventory contains decisions, begin a guided decision-clearing flow by presenting only the single open decision judged most impactful by the first mate.
Make clear that impact ordering is the first mate's judgment rather than a mechanical score.
Say the ordering is the first mate's pick.
Give enough escalation-quality context to decide easily: the decision, why it matters, the options, and a recommendation.
9. When the captain answers the presented decision, present the next highest-impact decision from that existing inventory in the same form.
Continue one decision at a time until none remain, without starting this flow when the inventory is empty.
Expand Down
6 changes: 4 additions & 2 deletions .agents/skills/away-quiet-supervision/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,15 @@ metadata:

# Away and quiet supervision safety

The `/afk` and `/quiet` skills each own their daemon procedure, which is otherwise identical; these safety facts apply to both:
The `/afk` and `/quiet` skills own their respective entry procedures and share the daemon machinery; [architecture](../../../docs/architecture.md) owns the captain-held recheck difference between their postures.
These safety facts apply to both:

- Every current daemon injection uses the `away-supervisor` kind from `bin/fm-operational-input.sh` after `FM_OPERATIONAL_PREFIX` (U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), except that a Claude Code primary, which strips U+2063, receives that owner's record-backed doorbell and it counts as marked only when `bin/fm-operational-input.sh open <path>` verifies its record; the `/afk` skill owns legacy bare-marker compatibility.
- `state/.afk-contract` is the away posture, written in the same turn as `/afk` before any other work, because `/afk` is itself the go: no read-back gates entry or waits for a go; entry announces hold-for-return only, and the away session acts on those words by its own judgment through the guarded scripts under standing authority, holding for the return on doubt.
A record carrying quiet mode (`bin/fm-afk-contract.sh mode`) is quiet mode's instead: the captain is present, it holds nothing for a return, and requested actions proceed under ordinary attended authority.
- While `state/.afk` exists, the daemon owns supervision; do not arm a separate watcher.
The daemon is never launched on Pi, where the ordinary supervision session continues under the record with main parked: the branch takes every safe actionable wake it can, and only a declined wake (including a broken branch or unsafe scan) or a watcher failure wakes main.
Away mode on a non-Pi home with `config/supervision-host` works the same way with the supervision host as the branch; a wake it hands back arrives through that harness's own wake path and is never the captain's return.
Away mode on a non-Pi home that runs the supervision host (by default on Claude; `docs/configuration.md` "Supervision host") works the same way with the supervision host as the branch; a wake it hands back arrives through that harness's own wake path and is never the captain's return.
- A marked message while away or quiet mode is active is internal escalation and does not exit that mode.
- A message beginning `/afk` refreshes away mode; a message beginning `/quiet` refreshes quiet mode.
- Any other unmarked message means the captain returned in away mode (load `/afk`, run the return owner, and do not process that message as ordinary work until its durable catch-up gate clears), or, in quiet mode, is simply answered as ordinary work with the flag and daemon left untouched until an explicit `/quiet off`.
Expand Down
2 changes: 2 additions & 0 deletions .agents/skills/captain-hold-lifecycle/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,9 @@ The agent performs the semantic inventory because scripts must not infer captain
## Policy

Every unresolved question that belongs to the captain and is discovered while producing, reading, presenting, or ending an investigation or visual review must be carried by a captain-held task in the authoritative backlog of the home that owns the originating work before that work or review may be treated as complete.
For a Lavish board-backed handoff, pass the reply through `bin/fm-procevent-lavish.sh arm --agent-reply-file` before appending the status; the adapter owns version-specific acceptance ordering.
Prefer holding the work item the question gates over minting a new row; create a new task only when no work item exists to hold.
The originating investigation or review is never its own inventory entry, so hold a separate task for the call and pass `--origin <origin-id>` so `complete` can check it.
Put the question and its options in the hold reason, and keep one held task per genuine gate: a multi-question review is one held task pointing at its report, not a row per question. Represent that task with exactly one board card that consolidates its questions and options; never fan one task id into duplicate same-key cards.
Register or re-hold through `bin/fm-captain-hold.sh hold`, which is idempotent per task id.
After inventorying the whole report and review surface, run `bin/fm-captain-hold.sh complete` with every captain-held task id, or with `--none` only when the reviewed surface leaves nothing waiting on the captain.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ Hooks still run through cwd-sensitive `/bin/sh`, so tracked commands anchor thro

The Stop-owned watcher hook runs every Stop, foregrounds `../../../bin/fm-watch-arm.sh` only when eligible, and uses exit-2 async reawakening as notification.
The model handles notifications but never routine re-arm.
In a home with `config/supervision-host` the hook foregrounds the supervision host instead, which also runs Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md#engines) owns the verified engine facts.
Unless `config/supervision-host-off` opts the home out, the hook foregrounds the supervision host instead, which also runs Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md#engines) owns the verified engine facts.
Claude's PreToolUse seatbelt blocks directly, and its deny is honored only with empty stdout; `../../../docs/arm-pretool-check.md` owns that contract.

### Delegation guard
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ The tracked hook anchors to `pwd -P`, verifies that root is Firstmate-shaped and

Codex's primary watcher protocol is `../../../bin/fm-watch-checkpoint.sh --seconds "${FM_CODEX_WATCH_CHECKPOINT:-180}"`, not `../../../bin/fm-watch-arm.sh`.
Codex cannot reason while a foreground tool call is running, so the checkpoint is deliberately foreground and bounded to return control regularly for user messages and queued notifications.
In a home with `config/supervision-host` the checkpoint runs the supervision host instead of the watcher, with Claude's print mode as its headless engine, and holds for at least an hour while away; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host and that bound.
In a home with `config/supervision-host` and no `config/supervision-host-off` the checkpoint runs the supervision host instead of the watcher, with Claude's print mode as its headless engine, and holds for at least an hour while away; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host and that bound.
Codex's PreToolUse watcher-arm seatbelt blocks directly through its project hook.
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ Example: `../../../bin/fm-spawn.sh <task-id> <project> --scout --harness cursor
## Primary integration

Primary supervision is the stop-hook park in `../../../docs/supervision-protocols/cursor.md` through tracked `.cursor/hooks.json`; primary and secondmate launches require `--trust` or hooks do not load.
In a home with `config/supervision-host` the park runs the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
In a home with `config/supervision-host` and no `config/supervision-host-off` the park runs the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
Cursor exposes 20 project events plus a Claude-Code compatibility map that loads `.claude/settings.json`.
Tracked hooks register `stop`, `sessionStart`, and two `preToolUse` seatbelts through `$CURSOR_PROJECT_DIR`; Claude entries stand down on Cursor payloads under `../../../docs/turnend-guard.md`.

Expand Down
Loading
Loading