fix: preserve supervision continuity and run attribution - #15
Merged
Merged
Conversation
added 6 commits
July 28, 2026 18:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Port the approved upstream supervision-continuity and AFK/current-run-attribution end state onto the current Firstmate fork. Add bounded one-owner successor cycles for Pi and OpenCode, Claude Stop-owned auto-arm with shared session-lock identity and bounded block cooperation, structured AFK terminal classification with independent wedge aging, and exact code/head-bound no-mistakes run attribution. Preserve PR #13/#14 security, authority, observer, delegation, signing, GitLab, and canonical FIRSTMATE_OP behavior; keep Codex and Grok continuity unchanged; include genuine secondmate primaries while excluding child task copies and observer/daemon/diagnostic/unrelated windows. Use the pre-calm Pi implementation and do not introduce unavailable calm dependencies or the rejected upstream command-gate change. Update ownership docs and add hermetic plus current-version live verification, reporting Claude authentication as a blocker rather than claiming success.
What Changed
Risk Assessment
✅ Low: The follow-up binds auto-arm ownership to process identity and scopes successor-cycle behavior to Pi, OpenCode, and Claude while preserving Grok’s default one-cycle semantics, with no remaining material source issue identified.
Testing
Completed 1 recorded test check.
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed ✅
bin/fm-turnend-guard.sh:180- The Claude guard treats any live process with the PID recorded in.claude-autoarm.lockas proof that recovery is underway. If an auto-arm process dies without releasing the lock and its PID is reused,fm_lock_try_acquirealso refuses the stale lock, while this guard indefinitely allows stops with no watcher. Bind generic lock ownership to process identity, as watcher locks already do, and verify that identity at this shared lock boundary.bin/fm-watch-arm.sh:261- The required criterion says to “keep Codex and Grok continuity unchanged,” but the shared arm wrapper used by Grok now follows successor watchers and converts an attached cycle ending without a successor from a clean completion into a nonzero failure. This changes Grok’s documented re-arm/notification behavior; scope the new successor semantics to Pi/OpenCode (and Claude where intended), or obtain explicit approval to change Grok continuity.🔧 Fix: Bind auto-arm identity and preserve Grok continuity
✅ Re-checked - no issues remain.
command -v tmux >/dev/null || { echo "tmux is required for e2e tests" >&2; exit 1; }; tmux -V; rc=0; for t in tests/*.test.sh; do echo "== $t =="; bash "$t" || rc=1; done; exit "$rc"🔧 Fix: Bound recursive lock stealing and stabilize identity mocks
1 error still open:
command -v tmux >/dev/null || { echo "tmux is required for e2e tests" >&2; exit 1; }; tmux -V; rc=0; for t in tests/*.test.sh; do echo "== $t =="; bash "$t" || rc=1; done; exit "$rc"✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.