Repository navigation
feat: add opt-in session launch restrictions - #29
Merged
Merged
Conversation
MrGTV-love
force-pushed
the
fm/fm-session-launch-runtime-restriction
branch
from
October 6, 2026 23:02
2cc0228 to
0c8cf0c
Compare
MrGTV-love
force-pushed
the
fm/fm-session-launch-runtime-restriction
branch
from
October 7, 2026 00:04
0c8cf0c to
6d0c03d
Compare
MrGTV-love
force-pushed
the
fm/fm-session-launch-runtime-restriction
branch
from
October 7, 2026 04:59
fb2f486 to
1bedc97
Compare
… supervision loops
… supervision hosts
…d recovery documentation
…e3bbdf3c4fe001d19afde5c592716: 19 checks pass and the two reported behavior jobs fail. The prior DNS failure required no product, credential, or configuration change. Scanned both complete job logs and verdict ledgers; both CI failures are test defects. Updated tests/fm-supervision-instructions.test.sh to remove prose-heading extraction and incidental wording assertions while retaining executable renderer state, block preservation, tag/placeholder filtering, and command ownership coverage. Updated tests/fm-remote-transport-lanes.test.sh to include the policy library and its verified transitive dependencies. Production policy, default-off compatibility, protections, ownership, and truthful documentation remain unchanged. Verification: all 12 supervision checks pass; canonical lint passes for both changed tests with pinned ShellCheck 0.11.0. A focused executable smoke using the corrected remote dependency set proved fm-on → worker → control state returns missing with open stdin and that --stdin preserves payload bytes; the throwaway script was removed. The full remote test was attempted twice but stopped before the corrected scenario at its existing cross-home timing assertion (4s and 7s against a 3s bound); that assertion was not weakened. Provider CI is not yet green and is not waived. Return these changes to the SAME outer run for its owned revalidation, publication, and CI provider retry; no pipeline control or push was performed
…n fallback documentation
…anged session generations
… actionable wake contract
…-refusal delivery
… restoring monitoring
… lifecycle handoffs
…ublish refusal receipts
…ransport assertion
… launch and recovery
MrGTV-love
force-pushed
the
fm/fm-session-launch-runtime-restriction
branch
from
October 7, 2026 13:26
1bedc97 to
be616b8
Compare
…runtime-restriction
The secondmate recovery admission called fm-harness.sh through FM_ROOT/bin, which a home whose bin directory is a partial copy does not have, so recovery refused a respawn it should have admitted. Use the library's own directory, as its other sourcing does.
…ree checks. Behavior portable parallel 1 failed because its runner regression invokes the same duration-hint guard as Test coverage guard. Added successful CI-derived measurements for all three new policy tests and documented their provenance; coverage now passes with 31/214 unmeasured scripts, below the unchanged 15% limit. For Lint 1, removed duplicate inheritance imports from spawn, control, and remote relaunch, and applied the existing canonical-owner analysis boundary to the policy library's lazy wake import. Runtime admission behavior and CI resource limits remain unchanged. Verification passed: coverage guard; complete fm-test-run regression; complete launch-policy, inheritance, receipt, and remote-relaunch regressions; executable lazy-notification/deduplication smoke; cold full source-aware ShellCheck 0.11.0 for all six relevant roots; documentation audience check. Linux bounded lint passed for control, remote relaunch, policy, and wake owners. Spawn's Linux memory-envelope result remains unverified: the available 7.75 GiB Docker VM, shared with unrelated services, killed the analyzer. Spawn passed cold macOS lint. Shorter initial regression runs timed out; subsequent complete runs passed. Temporary verification files were removed. No real agent sessions, pipeline controls, pushes, or remote CI reruns were invoked
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
please do not invoke codex sessions. invoke only
tc runorompsessions please.The rationale is that there are two GPT accounts and omp can switch between them; direct Codex sessions burn credits.
why is native claude required?
why not use tc run?
tc run is operational
firstmate, the official firstmate repo has updated and we should pull it. also the latest no-mistakes repo has updated and we should pull it as well
Proceed as recommended. Merge the official changes
The approved recommendation is to merge official changes into integration branches, preserving fork and private changes, and validate before updating running copies.
Scott is working on observiablity and needs that to complete. He is waiting on it.
why has that update not installed yet?
It has been the same status for several hours.
Regarding whether upstream installation truly depends on custom launch/recovery repairs:
I strongly suspect not.
are we pulling the latest upstream repo?
What Changed
config/session-launch-policy=omp-or-tcto restrict worker and secondmate launches to the canonical omp adapter, rejecting standalone Codex, other runtimes, and opaque raw commands. Nativetc runsupport remains unimplemented; absent configuration preserves existing behavior.Risk Assessment
Testing
Commit-diff and tool-availability checks were followed by isolated live CLI, Herdr, actual omp launch/recovery, session-end, and remote admission scenarios; after correcting lab provisioning, readiness, and direct-relaunch fixture assumptions, all scenarios passed, evidence was saved, and disposable worktree fixtures and lab sessions were removed. No Codex session, full test suite, linter, formatter, static analyzer, installation, or other pipeline phase was invoked.
omp --model anything, andtc runrequests were refused.Evidence: Fresh-launch and malformed-policy refusal transcripts
Source: Fresh-launch and malformed-policy refusal transcripts
Evidence: Fresh retained-child policy refusal
Source: Fresh retained-child policy refusal
Evidence: Actual recovered omp session and model reply
Source: Actual recovered omp session and model reply
Evidence: Ship and scout session-end refusal proof
Source: Ship and scout session-end refusal proof
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
omp --model anything, andtc runrequests were refused.Inspectedgit diff --stat fe1570232a91db1a9bfa482b90005df1eac77475 ace9c5a1b00da77007388a8fa864c34be6a5a824and the scoped launch/recovery implementation diff; checked runtime tools withcommand -v.Drovebin/fm-spawn.shthrough explicit ship, configured scout, configured secondmate, batch, Claude, opaque omp, andtc runrefusal requests in a disposable marked FM_HOME; verified no task records or project resources were created.Requested canonical omp launches with empty, unknown, trailing-space, extra-newline, and dangling-symlink policy files; verified fail-closed CLI diagnostics.Usedbin/fm-herdr-lab.sh name,provision,run, andteardownfor named non-default sessions, routing product backend operations through the lab helper.Launched actual omp secondmates withopenai-codex/gpt-6.1-soland low effort; observed model replies throughfm-peek.shand real omp registration through Herdragent list.Drovefm-control.sh <id> relaunch --harness codexand configured relaunch against a running omp secondmate; verified refusal, preserved metadata/work/policy, no relaunch checkpoint, and a surviving omp agent.Drove fresh and agent-free directfm-spawn.sh --relaunchrequests for Codex and opaque omp commands against a guarded retained child policy with no primary policy.Exercisedfm_secondmate_liveness_probeandfm_secondmate_liveness_relaunchagainst real agent-free Herdr endpoints; checked refusal deduplication, endpoint preservation, untouched attempt accounting, and immediate actual omp recovery after profile repair.Usedfm-busy-event.sh armandapply ... --event session-end, then the production session-end recovery consumer, for persisted ship/scout records naming Codex against a real agent-free Herdr pane.Drovefm-remote-secondmate-relaunch.sh remote-policy codex default default, destinationfm-remote-secondmate-control.sh launch remote-policy codex - - herdr, and the realfm-remote-inherit.sh put/absentprotocol consumer.Captured CLI transcripts, native agent inventory, terminal output, and complete command history; tore down all provisioned lab sessions and confirmed no.fm-live-*fixtures remained in the worktree.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.