This repository was archived by the owner on Aug 25, 2026. It is now read-only.
fix: isolate Herdr crew sessions from captain workspace - #96
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Make firstmate crews appear in Herdr again without touching the captain's live CAPTAIN workspace. Host Herdr is 0.8.0 / protocol 19 and has no pane.close_bound, so spawn crews into a dedicated Herdr session named firstmate (not default and not CAPTAIN/w1), keep config/backend as herdr without requiring FM_BACKEND=tmux, and close only after PID plus start-time match on the recorded pane. If identity is unproven, refuse and leave the pane; never bypass pane.close_bound inside the captain default session. Prove with focused tests that spawn records session=firstmate plus exact workspace/tab/pane, teardown refuses mismatched PID, and CAPTAIN/w1 is never a mutation target. Build on main including #95 f0899b8/bin/backends/herdr.sh diagnostics. Do not run the full 96-suite and do not merge; deliver through JTInventory/firstmate no-mistakes. Lint was attempted and failed only because the host daemon shut down under memory exhaustion; skip lint only for this recovery run.
What Changed
firstmatesession, record exact session/workspace/tab/pane metadata, and reject captain-owneddefaulttargets.pane.close_bound, matchingpane.process-infoPID and/procstart time while keeping non-dedicated targets fail-closed.CAPTAIN/w1state, mismatched-PID teardown, and uncertain cleanup.Risk Assessment
Testing
The four configured focused tests were rerun successfully, and the Herdr presentation E2E test provided direct CLI evidence from real Herdr 0.8.0/protocol-19 plus behavioral spawn/teardown fixtures. Evidence proves dedicated
firstmaterouting, exact workspace/tab/pane recording, protectedCAPTAIN/w1, refusal on unproven identity and mismatched PID, and close only after PID/start-time proof. No UI artifact was applicable because this is a CLI/backend change.Evidence: Herdr isolation E2E transcript
ok - installed Herdr 0.8.0 protocol-19 accepts the isolated firstmate session without mutation ok - real Herdr spawn records firstmate and exact workspace/tab/pane without touching CAPTAIN/w1 ok - Herdr teardown refuses a mismatched PID without closing the pane ok - Herdr teardown closes only the exact recorded firstmate pane after PID/start-time proofEvidence: Configured focused-test transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed ✅
bin/backends/herdr.sh:319- Required: “spawn crews into a dedicated Herdr session named firstmate.” The changedlocal session=${HERDR_SESSION:-$FM_BACKEND_HERDR_DEDICATED_SESSION}still permits any non-defaultHERDR_SESSION, andfm-spawn.shuses it directly, so an ambient override can spawn into another session. Force normal spawns tofirstmateor explicitly authorize this override.bin/backends/herdr.sh:348- Required: “close only after PID plus start-time match on the recorded pane. If identity is unproven, refuse and leave the pane.” When bound tab close is unavailable, this new fallback checks only workspace/tab/pane structure, then callstab close; failed workspace/task-tab reconciliation can therefore close a pane without PID/start-time proof. Require identity proof at this shared fallback boundary or refuse and retain the pane.🔧 Fix: Herdr session isolation and identity-gated teardown fixed
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
bash tests/fm-worker-isolation.test.sh && bash tests/fm-watch-session.test.sh && bash tests/fm-slot-occupant-proof.test.sh && FM_TEARDOWN_TEST_FOCUS=s1 bash tests/fm-teardown.test.shbash tests/fm-backend-herdr-presentation-e2e.test.shbash tests/fm-worker-isolation.test.shbash tests/fm-watch-session.test.shbash tests/fm-slot-occupant-proof.test.shFM_TEARDOWN_TEST_FOCUS=s1 bash tests/fm-teardown.test.sh✅ **Document** - passed
✅ No issues found.
⏭️ **Lint** - skipped
Step was skipped.
✅ **Push** - passed
✅ No issues found.