Skip to content

fix: require merge evidence for passed crew runs - #39

Closed
bingb0t5 wants to merge 7 commits into
mainfrom
fm/fm-crew-state-open-pr-truth-r1
Closed

bingb0t5 wants to merge 7 commits into
mainfrom
fm/fm-crew-state-open-pr-truth-r1

Conversation

@bingb0t5

@bingb0t5 bingb0t5 commented Sep 8, 2026 •

Copy link
Copy Markdown
Owner

CEO overview

  • What is changing: Firstmate only reports a worker's pull request as merged when it has matching merge evidence.
  • Why it matters: A finished worker could previously appear to have landed its work while its pull request was still open.
  • Customer or business impact: The captain can distinguish work ready for review from work already merged, reducing the risk of overlooking unfinished delivery.
  • Risk and rollout: Low risk; this delivery stops when CI is ready for review, with merging reserved for the captain's approval.
    Active workers keep their current status, and safeguards still refuse to remove unlanded work.
    Older runs without matching evidence may now show that their merge is unverified.

What changed technically

  • Passed crew runs require matching current-run PR identity, task metadata, and owned PR-poll merge evidence before displaying PR merged/closed.
  • Missing or conflicting evidence produces PR merge unverified; runs without valid PR metadata retain plain run passed.
  • Regression coverage exercises the public crew-state interface and teardown refusal, including stale evidence for a different PR on the same branch and head.
  • The decision re-arm test uses changing pane output and waits for observed captures so an independent idle-pane wake cannot be mistaken for a duplicate decision.

Validation

  • Checks passed: The preceding pipeline phases passed targeted crew-state, PR-poll, teardown, shell portability, lint, and documentation checks.
    CI also passed both portable parallel shards, serial shards 1, 3, and 4, Herdr, stock macOS Bash compatibility, coverage, repository invariants, and the no-mistakes requirement.
    After the CI repair, the full inactive-reconciliation and PR communication suites, both PR-body checkers, targeted ShellCheck, Bash syntax, documentation audience checks, and diff checks passed locally.
  • Checks not run: Hosted communication checks have not passed against this replacement narrative; the live PR description still uses the rejected legacy headings.
    The outer executor must compose this narrative with the latest live body using bin/fm-pr-body-compose.sh, publish the result while preserving the machine-owned Pipeline section, and verify the resulting hosted checks.
    No live forge mutation or merge was performed.
  • Evidence and limitations: Isolated public-script fixtures reproduced the false merge claim and verified the corrected open, merged, and closed-unmerged paths, while teardown preserved unlanded work.
    The live PR body reproduces all nine missing-field failures locally; replacing only its narrative with this file passes both executable body checkers while preserving the existing Pipeline suffix.
    Committing this file alone does not update the live body that GitHub Actions assesses.
    The crew-state transcript, poll-to-watcher transcript, and teardown transcript use controlled forge responses rather than live GitHub state.

Module-boundary decision

Current module retained: crew-state owns the displayed run verdict and reuses the existing PR identity and owned merge-evidence helpers.
No new merge authority or cleanup path is introduced.

Decision needed

No implementation decision required.
Merge approval remains with the captain; this validation run does not authorize merging.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

🔧 **Review** - 1 issue found → auto-fixed ✅

🔧 Fix: Bind crew merge evidence to the current run’s PR
✅ Re-checked - no issues remain.

✅ **Test** - passed

✅ No issues found.

  • TMPDIR="$PWD/.phase-test-tmp" bash tests/fm-crew-state.test.sh
  • Executed existing PR-poll selectors: test_static_poll_contract, test_merged_poll_retires_once, test_merged_poll_reregistration_after_notification_is_absorbed, test_different_merged_pr_for_same_task_is_not_absorbed, and test_retirement_refuses_replacement_and_nonterminal_results.
  • Executed existing teardown selectors: test_no_mistakes_passed_open_pr_still_refuses, test_squash_merged_branch_deleted_allows, test_merged_pr_with_later_local_commit_refuses, test_dirty_worktree_refuses, and test_gh_error_and_content_absent_refuses.
  • Confirmed regression tests fail as expected against base 757f81d and pre-R1 2dd4831, with the actual false PR merged/closed output.
  • Executed temporary evidence scripts through public crew-state, PR-poll, watcher, and teardown interfaces using isolated homes, real Git fixtures, and controlled forge responses.
  • Removed temporary fixtures and verified git status --short is empty.
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@bingb0t5 bingb0t5 changed the title fix: require merge evidence for passed crew runs fix: require merge evidence for passed crew runs [communication check] Sep 10, 2026
@bingb0t5 bingb0t5 changed the title fix: require merge evidence for passed crew runs [communication check] fix: require merge evidence for passed crew runs Sep 10, 2026
@bingb0t5 bingb0t5 changed the title fix: require merge evidence for passed crew runs fix: require merge evidence for passed crew runs [refresh] Sep 10, 2026
@bingb0t5 bingb0t5 changed the title fix: require merge evidence for passed crew runs [refresh] fix: require merge evidence for passed crew runs Sep 10, 2026
@bingb0t5 bingb0t5 closed this Sep 10, 2026
@bingb0t5 bingb0t5 reopened this Sep 10, 2026
…iant PR narrative `.github/pr-bodies/39.md`. Full inactive-reconciliation and communication suites, both body checkers, targeted lint, syntax, documentation, and diff checks pass. Outer executor must apply the narrative using `bin/fm-pr-body-compose.sh`, preserving the live Pipeline section, then rerun hosted CI. No push, PR mutation, or pipeline control performed
…e evidence and the required publication handoff. Live body reproduces all nine failures; composed replacement passes both checkers and preserves the Pipeline suffix. Communication suite, documentation checks, and diff checks pass. Outer executor must publish the composed body and verify hosted CI; committing the file alone cannot fix this live-body check
…ain’s merge-approval boundary. Reproduced all nine failures against the live PR body; the composed replacement passes both checkers and preserves the Pipeline suffix. Communication suite, documentation checks, and diff checks pass. Hosted CI remains unresolved: the outer executor must publish the narrative using bin/fm-pr-body-compose.sh with the latest live body. Another source-only commit cannot fix this check. No PR mutation, push, or pipeline control performed
@bingb0t5
bingb0t5 force-pushed the fm/fm-crew-state-open-pr-truth-r1 branch from db6195d to c39d954 Compare September 10, 2026 22:50
@bingb0t5

Copy link
Copy Markdown
Owner Author

Rebased onto current main; no-mistakes attestation parked until Codex reset 2026-09-15 08:24 ICT.

@bingb0t5

Copy link
Copy Markdown
Owner Author

Closed on the owner's decision during the 2026-09-30 review of open proposals (superseded or no longer needed). Branch kept for reference.

@bingb0t5 bingb0t5 closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant