This repository was archived by the owner on Aug 25, 2026. It is now read-only.
fix: reserve Grok watcher follower ownership - #86
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix the captain-visible Grok Watcher badge gap by reserving the per-home follower wait for Grok's tracked background-notify arm. Document the status-to-badge contract, make fm-watch-session start/restart refuse unsafe overlap when GROK_AGENT=1 while preserving non-Grok fallback behavior, allow only the explicit FM_ALLOW_WATCH_SESSION_WITH_GROK=1 emergency override, add behavior coverage, ship through no-mistakes to a JTInventory/firstmate PR, and never merge.
What Changed
fm-watch-sessionstart/restart refuse unsafe overlap whenGROK_AGENT=1, with only the explicit emergency override allowed.Risk Assessment
✅ Low: The follow-up commit addresses both prior findings: the badge table now distinguishes tracked Grok output from fallback inner-arm output, and restart refusal coverage verifies the existing fallback is not stopped.
Testing
The provided baseline command was rerun successfully; all 90 behavior tests passed. Focused watcher tests passed twice, and the CLI transcript directly demonstrates the requested end-user behavior. The worktree remained clean and no linters or formatters were run.
Evidence: End-user CLI transcript
Evidence: Focused watcher behavior tests
Evidence: Aggregate behavior test log
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed ✅
docs/supervision-protocols/grok.md:28- The badge table treats anywatcher: started/attachedline as proof of a tracked Grok task, but the tmux fallback also prints those inner-arm lines. Clarify that the badge mapping applies only to output from Grok's tracked background call, and mark fallback arm output as non-badge.tests/fm-watch-session.test.sh:260- Coverage tests only thestartrefusal and override. Add arestartcase proving refusal happens beforestop_runnerand leaves the existing fallback intact.🔧 Fix: Clarified Grok badge provenance; added restart refusal coverage
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
bash bin/fm-run-behavior-tests.shbash tests/fm-watch-session.test.shbash tests/fm-watch-session.test.sh(rerun)Manual private-tmux CLI verification of Grok refusal, override, restart preservation, and non-Grok fallbackbash bin/fm-run-behavior-tests.sh✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.