feat(bin): report Herdr fleet role token for sidebar rules - #1
Merged
Merged
Conversation
added 2 commits
September 14, 2026 18:50
Herdr sidebar colour rules key on a $role metadata token. Firstmate now reports role=<firstmate|secondmate|crewmate|scout> with `herdr pane report-metadata --source firstmate --token role=<role>`. - Spawn and relaunch report crewmate, scout, or secondmate for the exact pane in the published task record. - A locked session start reports firstmate, or secondmate in a marked secondmate home, for its own pane after its socket identity matches the named session. - Reports need Herdr 0.7.4 or newer and skip silently below it. A failed report warns and never fails the spawn or the session start. - tests/lib.sh drops inherited Herdr pane identity so suites run from a Herdr pane cannot report metadata to the developer's live pane. Claude-Session: https://claude.ai/code/session_01XUEUUVFLABdU3vL4NoAe2f
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Captain (13 Sep 2026, from data/harness-inventory-13sep/report.md part D): Herdr sidebar colour rules are keyed on a
$rolemetadata token. Firstmate must report a role token (firstmate, crewmate, scout, secondmate) to Herdr at spawn so the rules can tell fleet roles apart.What Changed
fm_backend_herdr_report_roleandfm_backend_herdr_report_own_roletobin/backends/herdr.sh. They runherdr pane report-metadata <pane> --source firstmate --token role=<role>for an exact pane. Valid roles arefirstmate,secondmate,crewmate, andscout. The adapter checks both the Herdr client and a running server against a new version floor (Herdr 0.7.4 or protocol 17). Older releases are skipped silently. The existing release-floor classifier now accepts an optional protocol and version floor.bin/fm-spawn.shreports the role for the pane in the published task record on every Herdr spawn and relaunch (secondmate,scout, orcrewmate).bin/fm-session-start.shreports the session's own role (firstmate, orsecondmatefor a home with the secondmate marker) during locked bootstrap. It does this only after the pane's injected socket matches the selected Herdr session. A failed report prints a warning and never fails the spawn or the session start.docs/herdr-backend.md, and add live CLI evidence todocs/verification/runtime-backends.md. Add tests for exact-pane reports, the version floor, warning-only refusals, own-role detection, and the session start report.tests/lib.shnow unsets inheritedHERDR_*pane variables, so test suites do not report metadata to the developer's live pane.🤖 Generated with Claude Code
Risk Assessment
✅ Low: The change is additive and display-only. Every failure warns and never fails a spawn or session start. Pane identity is taken from the published task record or proved through the socket, and the tests check real Herdr state. The only finding is a small duplicated release check.
Testing
The baseline
bin/fm-test-run.sh --changed --exclude-family real-herdr-gatedexited 1. That selection is wide, and this step did not rerun it. The two changed suites were run on their own instead. The real-Herdr E2E test proved crewmate, scout, and secondmate tokens on exact panes. A new live driver ran the real session start inside a real Herdr lab pane with the lock held. It provedfirstmateandsecondmatetokens, that a later report replaces the value, that a wrong-session pane is refused with a warning, and that a read-only start reports nothing. Relaunch was not driven live. The one session-start suite failure was a timing test under load, and it passed on rerun. Herdr sidebar colours are a TUI, and this lab has no$rolecolour rules, so there is no screenshot.herdr pane getJSON is the evidence for the stored token. All lab sessions were torn down, and the worktree is clean.Evidence: Real Herdr spawn E2E transcript (crewmate/scout/secondmate role tokens)
Source: Real Herdr spawn E2E transcript (crewmate/scout/secondmate role tokens)
Evidence: Live session start in real Herdr pane, lock held (wrong-session refusal, firstmate, secondmate)
Source: Live session start in real Herdr pane, lock held (wrong-session refusal, firstmate, secondmate)
tokens before any session start: {} == foreign: warning: herdr role token 'firstmate' not reported: pane 'w1:p1' could not be proved to belong to herdr session 'fm-lab-notthisone'; pane tokens after: {} == primary: session start exit=0; pane tokens after: {"role":"firstmate"} == second: session start exit=0; pane tokens after: {"role":"secondmate"}Evidence: Session start digest, primary home (lock acquired)
Source: Session start digest, primary home (lock acquired)
Evidence: Session start digest, secondmate home (lock acquired)
Source: Session start digest, secondmate home (lock acquired)
Evidence: Session start digest, wrong-session pane (lock acquired, report refused)
Source: Session start digest, wrong-session pane (lock acquired, report refused)
Evidence: Read-only session start in real Herdr pane: no token reported
Source: Read-only session start in real Herdr pane: no token reported
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
bin/backends/herdr.sh:359- fm_backend_herdr_role_token_supported re-implements the client/server release composition that fm_backend_herdr_presentation_release_supported already owns, and the copy handles one case differently. It reads.server.running // emptyand treats any non-truevalue as 'no running server', returning the client-only verdict. The presentation composer returns 2 (indeterminate) when.server.runningis neither true nor false. Concrete input:{"client":{"version":"0.9.0","protocol":22},"server":{"version":"0.7.3","protocol":16}}, withrunningmissing. The role path returns 0 and sends report-metadata to a below-floor server. The presentation path reports indeterminate. The impact is small, because the token is display-only and a failed report only warns. Remedy: pass the min protocol and min version into the existing composer, the same way fm_backend_herdr_release_floor_verdict now takes them, and call it from the role path. That leaves one definition of the client/server floor rule.tests/fm-session-start.test.sh- tests/fm-session-start.test.sh failed with 'not ok - the digest waited 10s for inactive reconciliation's 8s state read'. It ran at the same time as the real-Herdr E2E test. The suite stops at that failure, so later tests did not run. A rerun alone passed all 51 cases. This timing test is flaky under host load. The configured baseline--changedrun also exited 1 for a cause this step did not isolate.bin/fm-test-run.sh --changed --exclude-family real-herdr-gatedbash tests/fm-backend-herdr-launcher-workspace-e2e.test.sh(real Herdr 0.9.0 in an isolated lab session: real bin/fm-spawn.sh sets role=crewmate, scout, secondmate, and a secondmate's own crewmate; pane tokens read withherdr pane get)ROOT=$PWD bash <evidence>/session-start-role-live.sh(real bin/fm-session-start.sh run inside a real Herdr lab pane under a shell namedclaude, so the session lock is really held: wrong-session case, primary home, secondmate home;herdr pane getread after each run)Same driver without a harness in the process tree (lock refused, read-only session start): pane tokens stay emptybash tests/fm-backend-herdr.test.sh(report_role / report_own_role unit cases: version floor, unknown role, missing pane, failed report, wrong-session socket)bash tests/fm-session-start.test.sh(first run failed one timing test while the real E2E ran at the same time; passed on rerun alone, including test_herdr_role_token_reported_for_own_pane)herdr session listafter teardown: no fm-lab sessions left, default session still running✅ **Document** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.