fix: harden endpoint cleanup and enable Jev review assist - #12
Merged
Ivory2024 merged 16 commits intoSep 21, 2026
Merged
Conversation
added 9 commits
September 21, 2026 07:03
Verified against no-mistakes v1.79.0's own e2e tests and upstream PR kunchenguid#1120: jev.review_assist is global-only and has no effect when set in a repo's tracked .no-mistakes.yaml. Revert that no-op change and document the real activation path, data sent, and data-boundary guidance instead.
Ivory2024
force-pushed
the
fm/firstmate-nomistakes-jev-review-assist-20260920
branch
from
September 20, 2026 22:12
5af8f41 to
e9e9ec8
Compare
added 6 commits
September 21, 2026 11:00
…t.sh by making the Herdr fixture provide session-lock metadata and model pane-close disappearance, allowing respawn metadata to rotate. Verified with the targeted sync test, fm-backend-herdr.test.sh, bash -n, and git diff --check
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Harden self-hosted Discord relay cleanup and quota dispatch resolution; enable Jev review-assist advisory pre-brief in .no-mistakes.yaml. Deliver to Ivory2024/firstmate fork only.
What Changed
.no-mistakes.yamland documented their fallback and data boundaries.Risk Assessment
🚨 High: The required Jev configuration is absent, and the Herdr cleanup change introduces a concrete return-contract regression that can fail existing adapter usage; documentation also overstates cleanup ordering.
Testing
Focused dispatch-resolution, backend cleanup, and Herdr-lab guard tests passed. The real resolver safely no-oped without credentials. Real Herdr validation was blocked because
herdris absent from PATH. Jev review validation was not driven because this phase cannot invoke no-mistakes pipeline controls and requires the external Jev daemon credential and audit-log authority. No visual artifact was applicable for these CLI/backend scenarios.herdrexecutable is absent from PATH. Provide the Herdr CLI, then rerun the guardedfm-lab-*scenario throughbin/fm-herdr-lab.sh.TYPESAFE_API_KEY, and authorized review-step audit logs; those controls are outside this phase.Evidence: dispatch resolution tests
Source: dispatch resolution tests
Evidence: backend cleanup tests
Source: backend cleanup tests
Evidence: Herdr lab guard tests
Source: Herdr lab guard tests
Evidence: live tool attempts
Source: live tool attempts
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
docs/configuration.md:245- The authoritative intent requires “enable Jev review-assist advisory pre-brief in .no-mistakes.yaml,” but the target explicitly documents thatjev.review_assistis global-only atdocs/configuration.md:245and the final.no-mistakes.yamlhas nojevblock. The required tracked opt-in is therefore absent; decide whether the intent or the verified configuration boundary should govern.bin/backends/herdr.sh:3398- The new return propagation breaks the existing best-effort contract of direct Herdr adapter calls: close failure now returns nonzero atbin/backends/herdr.sh:3398, and lock/target refusal also returns nonzero at:3377and:3401. Existing callers/tests rely on this adapter remaining best-effort (tests/fm-backend-herdr.test.sh:2804,2836,2869,3667), whilebin/fm-backend.sh:813already performs the independent endpoint proof. Preserve the adapter's 0 return and let the shared wrapper carry the cleanup refusal.docs/secondmate-parent-channel.md:31- The changed documentation claims silent-child outcomes are published after endpoint cleanup is confirmed, but the actual path reports first atbin/fm-inactive-reconcile.sh:556-557, then callsreap_terminal_child_lockedat:562; that helper swallowsfm_backend_killfailure at:510. A failed close can therefore leave the endpoint live while the parent has already received the outcome. Narrow the documentation to the actual ordering unless the source is intentionally changed to enforce cleanup before publication.🔧 Fix applied.
3 issues (2 errors, 1 warning) still open:
docs/secondmate-parent-channel.md:31- The changed documentation claims silent-child outcomes are published after endpoint cleanup is confirmed, but the actual path reports first atbin/fm-inactive-reconcile.sh:556-557, then callsreap_terminal_child_lockedat:562; that helper swallowsfm_backend_killfailure at:510. A failed close can therefore leave the endpoint live while the parent has already received the outcome. Narrow the documentation to the actual ordering unless the source is intentionally changed to enforce cleanup before publication..no-mistakes.yaml:12- The final restore commit reintroduces the unsupported tracked opt-in at.no-mistakes.yaml:12-13. History (5d4de6c) verified that no-mistakes v1.79 treatsjev.review_assistas global-only, and this range adds no daemon support;docs/configuration.md:246therefore claims behavior that is unreachable. This contradicts the required criterion “enable Jev review-assist advisory pre-brief in .no-mistakes.yaml.” Choose a supported operator-local configuration or authorize a daemon/configuration change.bin/fm-bootstrap.sh:831- The 6366fec cleanup fix added a Zellij-specific recovery path that passesfm-$idbut runs under the primaryFM_HOMEatbin/fm-bootstrap.sh:831. A dead secondmate's tab is titled with the child home's scoped tag;bin/backends/zellij.sh:604-613therefore refuses to close it, and the new proof at:624-638also computes the wrong scoped title and sees the pane still present. Startup logs “endpoint cleanup could not be confirmed” and never respawns the dead secondmate. Run this cleanup under the recorded child home/root context, as the existing child teardown path does atbin/fm-teardown.sh:3078.tests/fm-backend.test.sh:971- tests/fm-backend.test.sh snapshots git archive HEAD, so it still exercised the pre-fix wrapper in this uncommitted worktree. Re-run after the source fix is committed.herdris absent from PATH and no repository-local binary is supplied. Provide the Herdr CLI, then rerun the guarded prepare/provision/run/teardown flow.bash tests/fm-discord-selfhosted.test.shbash tests/fm-quota-choose.test.shbash tests/fm-dispatch-resolve.test.shbash tests/fm-backend-herdr.test.shbash tests/fm-test-run.test.shbash tests/fm-herdr-lab.test.shbash tests/fm-backend.test.sh(historical HEAD fixture still observed the pre-fix wrapper)Direct backend compatibility driverSemantic YAML configuration checkbin/fm-herdr-lab.sh prepare fm-lab-70582-test🔧 Fix applied.
1 warning still open:
herdrexecutable is absent from PATH. Provide the Herdr CLI, then rerun the guardedfm-lab-*scenario throughbin/fm-herdr-lab.sh.TYPESAFE_API_KEY, and authorized review-step audit logs; those controls are outside this phase.bash tests/fm-dispatch-resolve.test.shbash tests/fm-backend.test.shbash tests/fm-herdr-lab.test.shFM_HERDR_LAB_STATE_DIR=/tmp/... bash bin/fm-herdr-lab.sh prepare fm-lab-jev-review-testenv -u TYPESAFE_API_KEY -u TYPESAFE_API_PRIVATE FM_HOME=/tmp/... bin/fm-dispatch-resolve.sh <brief>no-mistakes --version✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.