Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
53 commits
Select commit Hold shift + click to select a range
244358a
feat: pin and restore fleet toolchain offline (#4)
juniorlovestmh Jul 30, 2026
d77916e
feat(mobile-mode): add verified Moshi Pro mobile review workflow (#6)
juniorlovestmh Jul 31, 2026
6b874ea
feat(brief): add self-authenticating launch provenance (#7)
juniorlovestmh Aug 1, 2026
d0a8bbc
feat: wake firstmate for Better Stack incidents
juniorlovestmh Aug 1, 2026
0cd4d4d
feat: standardize fleet secrets on Doppler (#3)
juniorlovestmh Jul 27, 2026
f49928d
docs: separate current guidance from verification evidence (#994)
kunchenguid Jul 24, 2026
2d1267b
fix: preserve Claude watcher continuity across Stop hooks (#997)
kunchenguid Jul 24, 2026
ae89c5c
fix(herdr): clean stale projections at session start (#996)
kunchenguid Jul 24, 2026
38a0693
fix: recover Claude supervision without watcher-status gate (#1001)
kunchenguid Jul 24, 2026
bd33b0e
fix: make quota-aware profile selection agent-owned (#1018)
kunchenguid Jul 25, 2026
dc16525
fix(bin): remove vestigial dispatch selector (#1026)
kunchenguid Jul 25, 2026
c7518d9
docs(agents): drop superseded interim quota-window rule (#1039)
kunchenguid Jul 25, 2026
86e6dd1
fix(tmux): scope busy detection and recognize current Claude turns (#…
kunchenguid Jul 26, 2026
9f9238b
feat: add verified Kimi crewmate adapter (#1047)
kunchenguid Jul 26, 2026
8870fc8
fix: harden Kimi submission and spinner matching (#1058)
kunchenguid Jul 26, 2026
2e0c1a9
feat(bin): add guarded Kimi turn-end wake (#1059)
kunchenguid Jul 26, 2026
c4a89f4
fix(tmux): classify bordered composers across all rows (#1066)
kunchenguid Jul 26, 2026
77bb8f5
feat(bin): add verified pi-signed runtime adapter (#1145)
kunchenguid Jul 27, 2026
82b785c
fix(pi): rearm watcher across session transitions (#1166)
kunchenguid Jul 28, 2026
717f87b
feat: route crew dispatch using quota-window pace (#1172)
kunchenguid Jul 28, 2026
f36b949
fix: adapt Grok Stop continuation and harden endpoint cleanup (#1171)
kunchenguid Jul 28, 2026
37e1692
fix: restore stock macOS Bash 3.2 brief scaffolding (#1093)
karotkriss Jul 28, 2026
3076512
test: stabilize tmux teardown conformance baseline (#1209)
kunchenguid Jul 28, 2026
a8a6843
docs: slim quota-array-dispatch to the pace selection core (#1197)
kunchenguid Jul 28, 2026
c53c9e9
feat(bin): inherit backend config into secondmate homes (#1219)
kunchenguid Jul 28, 2026
2ff4214
fix(pi): remove Calm's upper version ceiling (#1226)
kunchenguid Jul 29, 2026
8fc9706
fix(bin): allow session-local todo tools in the subagent guard (#1204)
danielkuykendall23-boop Jul 29, 2026
bf85eb9
fix(session-lock): resolve Claude bg-spare ancestry to the outermost …
trillium Jul 29, 2026
80ce74b
fix: conferma l'avvio del watcher su Windows/MSYS (#1212)
Unknownzed Jul 29, 2026
c5035f3
fix(spawn): forward CLAUDE_CONFIG_DIR to claude crewmates (#1195)
lucashalbert Jul 29, 2026
3faa411
fix: preserve dispatch identity across authentication checks (#1233)
kunchenguid Jul 29, 2026
833286d
fix(bin): normalize relative durable paths (#1256)
sparkus Jul 29, 2026
e878086
refactor(skills): make Bearings chat-only by default (#1136)
deeto15 Jul 29, 2026
32a588b
Clarify follow-up routing during validation (#1277)
kunchenguid Jul 30, 2026
0a89f13
fix: honor concrete approval for project operations (#1272)
kunchenguid Jul 30, 2026
5d939e0
fix(skills): route new project intake through secondmate scopes (#1275)
kunchenguid Jul 30, 2026
38c84db
fix: scope validation corrections by accepted behavior (#1281)
kunchenguid Jul 30, 2026
da2d2ca
test: replace source assertions with behavioral coverage (#1282)
kunchenguid Jul 30, 2026
b86c917
fix(watch): escalate busy workers with no completed turn (#1286)
kunchenguid Jul 30, 2026
9b8e4c4
fix(gitignore): ignore config/ as a directory, not by exact filename …
karotkriss Jul 30, 2026
a9ed0ca
fix(tests): replace source-content .gitignore assertion with behavior…
kunchenguid Jul 30, 2026
c41980f
feat: bound and consolidate startup memory during stow (#1303)
kunchenguid Jul 30, 2026
947a676
no-mistakes(review): Captain: restored ADHD coverage and Doppler CLI …
juniorlovestmh Jul 30, 2026
d00c0d4
fix: satisfy pinned shellcheck for merge tests
juniorlovestmh Jul 30, 2026
c811937
feat: wake firstmate for Better Stack incidents
juniorlovestmh Aug 1, 2026
6aa3f02
no-mistakes(review): Captain: fixed pagination, dedupe recovery, and …
juniorlovestmh Aug 1, 2026
c03efd3
no-mistakes(review): Captain: added receipt recovery and documented w…
juniorlovestmh Aug 1, 2026
9a6c6a6
no-mistakes(review): Captain, documentation now describes repeated po…
juniorlovestmh Aug 1, 2026
a37f15a
no-mistakes(document): Captain: document Better Stack incident monito…
juniorlovestmh Aug 1, 2026
1a5ac7b
no-mistakes(lint): Fix ShellCheck warnings in incident wake scripts
juniorlovestmh Aug 1, 2026
89a7d37
chore: reconcile validated history onto main
juniorlovestmh Aug 1, 2026
f29ab68
chore: reconcile Better Stack wake onto main
juniorlovestmh Aug 1, 2026
cf316da
test: keep Better Stack bootstrap hermetic
juniorlovestmh Aug 1, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,9 @@ When any diagnostic needs captain attention, report the plain consequence and re
- `FLEET_SYNC: <repo>: skipped: <reason>` - a benign one-off skip (offline, no origin, local-only); bootstrap continued, investigate only if it blocks work.
A skip can also report the bounded fleet-refresh timeout (`FM_FLEET_SYNC_BOOTSTRAP_TIMEOUT`, or a fleet-size-aware default with a 20 second floor); a timeout never blocks startup.
- `FLEET_SYNC: <repo>: recovered: <detail>` - the clone had drifted onto a clean detached HEAD holding no unique commits and the sync self-healed it (re-attached the default branch and fast-forwarded); no action needed, it is reported only so the self-heal is visible.
- `BETTER_STACK: incident monitoring on ...` - the home-scoped poll is registered at the default check cadence; no action is needed.
- `BETTER_STACK: incident monitoring off - removed ...` - the local presence flag was removed and bootstrap retired the runnable check while retaining incident dedupe state; no action is needed.
- Any other `BETTER_STACK:` line - follow its concrete dependency, unsafe flag, activation, or cleanup diagnostic before relying on incident monitoring.
- `FLEET_SYNC: <repo>: STUCK: on <state>, N commits behind <base> - needs attention` - the clone is dirty, on a non-default branch, detached with unique commits, or diverged, so the sync left it untouched (never forcing or discarding); it will keep falling behind until you look.
A loud STUCK, especially a growing N across bootstraps, means that clone needs hands-on attention; dispatch a crewmate or resolve it before it strands work.
- `PR_CHECK_MIGRATION: canonical polls rebuilt and armed; resume supervision for this home` - the non-executing migration rebuilt canonical task polls from validated metadata, and those polls are already armed.
Expand Down
1 change: 1 addition & 0 deletions .opencode/plugins/fm-primary-watch-arm.js
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,7 @@ async function isPrimaryRoot(root, home) {
function shouldArm(paths) {
if (existsSync(`${paths.state}/.afk`)) return false;
if (existsSync(`${paths.config}/x-mode.env`)) return true;
if (existsSync(`${paths.state}/better-stack-incidents.check.sh`)) return true;
try {
return readdirSync(paths.state).some((name) => name.endsWith(".meta"));
} catch {
Expand Down
20 changes: 14 additions & 6 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,7 @@ config/startup-memory-budget primary-authoritative per-home startup-memory b
config/herdr-presentation-spaces optional presence flag for Herdr's default-off disposable single-task visual projection; LOCAL, gitignored; inherited by secondmate homes; see docs/herdr-backend.md "Optional presentation spaces"
config/cmux-socket-password optional cmux control-socket password; LOCAL, gitignored; read fresh on every cmux CLI call and passed through without ever overriding an operator's own ambient CMUX_SOCKET_PASSWORD when absent (docs/cmux-backend.md "Setup")
config/wedge-alarm optional away-mode wedge-alarm active-alert directives; LOCAL, gitignored; absent means auto (macOS Notification Center when available); see docs/wedge-alarm.md
config/better-stack-incidents optional presence flag for the home-scoped Better Stack incident poll; LOCAL, gitignored, and not inherited; see docs/configuration.md "Better Stack incident monitoring"
config/x-mode.env generated X-mode watcher cadence; LOCAL, gitignored; source before arming watcher when present
data/ personal fleet records; LOCAL, gitignored as a whole
backlog.md task queue, dependencies, history
Expand Down Expand Up @@ -101,6 +102,8 @@ state/ volatile runtime signals; gitignored
.pr-check-migration.log private per-task outcomes distinguishing rebuilt or canonically registered replacement polls, quarantined unarmed polls, and incomplete migrations
.pr-check-migration-scan-v1 private marker proving the non-executing scan disabled every unsafe legacy check; .pr-check-migration-v1 separately records completed private repairs
x-watch.check.sh generated X-mode relay poll shim; present only when opted in (section 14)
better-stack-incidents.check.sh better-stack-incidents.check-trust generated and registered home-scoped Better Stack incident poll; present only when opted in
better-stack-incidents.seen/ better-stack-incidents.diagnostics/ private incident-ID and diagnostic dedupe state retained across poll disable/re-enable
pending-replies/ parent-owned secondmate pending-reply records (correlation id, delivery vs reply, recovery, escalation); fm-pending-reply-lib.sh
x-inbox/ generated X-mode pending mention payloads; fmx-respond drains it (section 14)
x-context/ generated X-mode durable per-request reply context and one-wake offer markers, keyed by request_id; survives inbox cleanup and expires within seven days (section 14; bin/fm-x-lib.sh)
Expand Down Expand Up @@ -138,7 +141,7 @@ A lock-refused session must not spawn, steer, merge, drain the wake queue, repai
1. **Lock** - acquires the per-home session lock first, before anything mutates shared state.
2. **Bootstrap** - detect-only checks (tool/version problems, GitHub auth, the worktree-tangle check, harness override, dispatch-profile validation, backlog-backend status) always run, but routine confirmations stay silent by default.
When the lock could not be acquired, the worktree-tangle check uses read-only advisory wording without a checkout repair command.
Home-local stale Herdr projection cleanup and the five bootstrap MUTATING sweeps - non-executing legacy PR-check migration, fleet sync, the local secondmate fast-forward sweep, the secondmate liveness sweep, and X-mode artifact writes - run only when this session actually holds the lock from step 1.
Home-local stale Herdr projection cleanup and the six bootstrap MUTATING sweeps - non-executing legacy PR-check migration, fleet sync, the local secondmate fast-forward sweep, the secondmate liveness sweep, X-mode artifact writes, and Better Stack incident-poll registration - run only when this session actually holds the lock from step 1.
The secondmate liveness sweep deterministically accounts for every registered secondmate: it relaunches only from the recovery-grade `dead` or `missing` states, preserves ambiguous or unreadable targets, and reports skipped or failed guarantees as `SECONDMATE_LIVENESS:` lines (`bin/fm-bootstrap.sh`; `bin/fm-backend.sh`'s `fm_backend_agent_state`).
3. **Wake queue** - when locked, drains the durable wake queue and prints the raw records prominently as this turn's first work queue; a bounded, clearly labeled historical status-event annotation may follow a valid `signal` record but never replaces it or current-state reconciliation, and a lapsed watcher chain still surfaces here via the same guard alarm.
When the lock could not be acquired and verified, the queue is left untouched because no session mutation is authorized, and the guard's tangle/watcher-liveness alarms still print in read-only advisory mode without drain, supervision repair, or checkout repair commands.
Expand All @@ -147,7 +150,7 @@ A lock-refused session must not spawn, steer, merge, drain the wake queue, repai
5. **Fleet-state digest** - the compact backlog listing owned by `bin/fm-session-start.sh`; every `state/<id>.meta`; a bounded tail of each task's `state/<id>.status` (labeled as wake-EVENT history, not current state, with the full log path printed for a deeper read); the `state/.afk` flag; and one cheap alive/dead read of each task's recorded backend endpoint.
That liveness line is a fast presence check only, not a full state read - when you need a crew's actual current state (a run-step, not just "is the pane there"), read it with `bin/fm-crew-state.sh <id>` as before; the digest deliberately skips that deeper, slower read for every task so it stays fast and bounded.
6. **Supervision operating instructions and next step** - after the wake queue and before context, the digest emits exactly one operating block for the detected primary harness.
The closing reminder points back to that emitted block and preserves only the lock, afk, X-mode, and read-once reminders.
The closing reminder points back to that emitted block and preserves only the lock, afk, home-monitoring, and read-once reminders.
The script itself never starts supervision; the emitted harness protocol owns the exact wait or wake mechanism.

Bootstrap detects first, asks for consent, and installs only after the captain approves in the current session.
Expand Down Expand Up @@ -337,7 +340,7 @@ The promoted worker must inventory scratch state, return to a clean default-bran
Fleet supervision is an always-loaded operational contract; `docs/architecture.md`, `docs/turnend-guard.md`, the emitted session-start block, and script help own mechanisms and harness-specific recipes.

Whenever work is under way, keep exactly one live supervision cycle using the emitted protocol for this primary harness.
X mode may require that same live cycle with no fleet work.
X mode or Better Stack incident monitoring may require that same live cycle with no fleet work.
Do not substitute another harness's wait shape, use shell `&`, or create a second cycle when a healthy one already exists.
For every actionable wake, follow the ordinary-wake continuation in the emitted protocol; use its repair action only when the live cycle is missing or failed.
No turn ends blind while work is under way, including turns described as holding or waiting.
Expand All @@ -351,9 +354,14 @@ Handle actionable wakes as follows:

1. For `signal:`, read the listed event lines first, then reconcile current state only where action depends on it.
2. For `stale:`, inspect the recorded endpoint and load `stuck-crewmate-recovery` for a stopped, looping, confused, or unresponsive worker; a deep-inspection reason also requires current-state and validation-log inspection.
3. For `check:`, act on the named poll result, including merges and X-mode events.
3. For `check:`, act on the named poll result, including merges, X-mode events, and Better Stack incidents or diagnostics.
4. For `heartbeat:`, review the whole fleet from the structured fleet view, reconcile suspicious tasks and PR state, update the backlog, and never report an unchanged fleet as progress.

For a `better-stack-incident opened ...` or `better-stack-incidents opened ...` result, load `diagnostic-reasoning` before scoping the response.
When the delivery ladder caused the breakage, restore service through the available rollback path first and investigate after recovery.
Page the captain immediately only for security-shaped, irreversible, or product-affecting incidents; otherwise carry the result and resolution in the next outcome digest.
Better Stack polling during `heartbeat:` handling was an interim practice and is retired; the registered home check is its only poll owner.

When any wake reports a merged PR for a project cloned in this home, refresh that clone through the guarded fleet-sync path.
When X-linked work reaches a milestone or terminal state, load `fmx-respond`; before terminal teardown, always post the final completion follow-up so the link clears even if earlier follow-ups were spent.

Expand Down Expand Up @@ -477,7 +485,7 @@ It performs guarded fast-forward updates of firstmate and registered secondmate

These skills are not captain-invocable; load them only at their precise triggers.

- `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `STARTUP_MEMORY_BUDGET:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `PR_CHECK_MIGRATION:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `NUDGE_SECONDMATES:`, or `FMX:`); silence and `BOOTSTRAP_INFO:` need no load.
- `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `STARTUP_MEMORY_BUDGET:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `PR_CHECK_MIGRATION:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `NUDGE_SECONDMATES:`, `FMX:`, or `BETTER_STACK:`); silence and `BOOTSTRAP_INFO:` need no load.
- `diagnostic-reasoning` - load before scoping a reported bug and before acting on a diagnostic report.
- `ask-user-authority` - load before deciding any ask-user finding, regardless of the project's `yolo` posture.
- `quota-array-dispatch` - load before choosing among a matched crew-dispatch profile array from current quota-axi output.
Expand All @@ -499,7 +507,7 @@ X mode ships inert and causes no behavior change until the home opts in by placi
That token is consent for public replies and normal reversible lifecycle actions from eligible mentions, not authority for destructive, irreversible, or security-sensitive action; those still require trusted-channel confirmation.
`docs/configuration.md` owns activation, generated state, cadence, wire protocol, and opt-out mechanics.

An X-only home still requires the live supervision cycle so mentions can wake it without fleet work.
A home with X mode or Better Stack incident monitoring still requires the live supervision cycle without fleet work.
On an `x-mention <request_id>` or `x-mode-error ...` check wake, load `fmx-respond`, which owns classification, public-safety policy, reply or dismissal, task linking, and follow-ups.
For every X-linked terminal outcome, load that owner and post the final completion follow-up before teardown, regardless of earlier milestone follow-ups.

Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ Launching a supported harness inside it instantiates your first mate - and makes
- **Explicit project modes** - each project ships via `no-mistakes`, `direct-PR`, or `local-only`, with an optional `+yolo` autonomy flag.
- **Optional secondmates** - opt in to persistent second mates that run from isolated firstmate homes with their own `FM_HOME`, state, projects, and session lock, supervising project clones or a project-less firstmate-repo domain, kept on the primary firstmate version by guarded local fast-forwards and checked for live agent processes at session start.
- **Event-driven, zero-token supervision** - a bash watcher sleeps on the fleet and wakes the first mate only when something needs you; verified primary harnesses also get a turn-end backstop that blocks or follows up on a blind stop when work is under way and supervision is not live.
- **Optional Better Stack incident monitoring** - opt one home into unresolved-incident polling through the registered custom-check path; runtime-only Doppler injection, private incident dedupe, and one visible diagnostic per failure keep the alert path bounded.
- **Optional X mode** - opt in with one local `.env` token so firstmate can answer your public `@myfirstmate` mentions, act on normal reversible mention requests through the same lifecycle as chat requests, acknowledge spawned work, and post up to three public-safe completion follow-ups within seven days for genuine milestones and the final outcome without changing non-X behavior; dry-run preview records would-be replies and dismissals locally before go-live.
- **Strict project boundary** - the first mate is read-only over your projects except for the narrow guarded and captain-approved operations authorized by [hard rule 1](AGENTS.md#1-identity-and-prime-directives), including fleet sync's guarded safe branch pruning; crewmates make every other project change behind the configured merge authority.
- **Doppler by default** - the conditional [secrets-management policy](.agents/skills/secrets-management/SKILL.md) prefers secretless provider identity, otherwise scopes Doppler by project and environment, and validates declarations and rollout data through `bin/fm-secrets-check.sh`.
Expand Down
Loading
Loading