Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
169 commits
Select commit Hold shift + click to select a range
9aabe3b
feat(bin): defer the wedge escalation for a lane parked at a supervis…
aminry Sep 20, 2026
1b1b3cd
fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
RooseveltAdvisors Sep 20, 2026
a09090d
feat(bin): stamp status events with their emission time (#3764)
tiago-peixoto Sep 20, 2026
c443d8c
fix(bin): unify Lavish host and disconnect handling (#5060)
kunchenguid Sep 20, 2026
dee119b
feat: act on captain's away words during AFK supervision (#5076)
kunchenguid Sep 20, 2026
804394e
fix(bin): render the remote charter's steering-inbox path host-local …
kesslerio Sep 21, 2026
bd65e4a
feat: route Lavish feedback directly to owning workers (#5099)
kunchenguid Sep 21, 2026
b8ab735
fix(bin): fit pull observation within the contribution poll budget (#…
sdivanl Sep 21, 2026
631bc26
feat(bin): add idempotent inbox capture, replies, receipts, and readi…
cliflacata-svg Sep 21, 2026
d08e327
fix(bin): stop harness footer rows below a composer from reading as p…
puntkoen Sep 21, 2026
fcbaa73
feat(bin): append optional home-local include to briefs (#5115)
guanchengh-lgtm Sep 21, 2026
43bf6d3
fix(bin): report a branch with no validation run as absent instead of…
Authentis Sep 21, 2026
dbc0bc4
fix(bin): require a non-draft pull request before a PR-based done rep…
mremond Sep 21, 2026
259a669
fix: support quota-axi schema 6 snapshots (#4904)
pedromuller-del Sep 21, 2026
aec043c
test: fix Claude session-start drain live E2E (#5165)
kunchenguid Sep 21, 2026
8c1cdb7
ci: pin the no-mistakes required check to v1.80.1 (#5195)
kunchenguid Sep 21, 2026
3fcbc6c
fix(bin): retain Pi watcher predecessor to stop false down alarms (#5…
sdivanl Sep 22, 2026
da9607d
fix(bin): allow cleanup of windowless legacy task records (#5236)
kunchenguid Sep 22, 2026
f9f74a1
ci: exempt kunchenguid from the no-mistakes required check (#5256)
kunchenguid Sep 22, 2026
6f0f139
fix(bin): surface launches parked on an interactive prompt as not-sta…
sdivanl Sep 22, 2026
f5735dc
fix: record away posture immediately on /afk (#5260)
kunchenguid Sep 22, 2026
c5131a3
fix(bin): recognize passed-with-override as a passing outcome (#5294)
mremond Sep 22, 2026
ada21f5
fix: clean up workers after their pull requests land (#5317)
kunchenguid Sep 22, 2026
d92cea0
fix: surface green no-mistakes PRs awaiting merge (#5327)
kunchenguid Sep 22, 2026
884d76b
fix: derive Lavish polling route from board session (#5334)
kunchenguid Sep 22, 2026
dd9f2b4
fix(bin): stop secondmate relaunch failing when watcher scratch files…
tiago-peixoto Sep 22, 2026
39f4c2a
fix(bin): stop each keyed answer from re-waking this home (#4907)
tiago-peixoto Sep 22, 2026
706254d
fix: deliver failed public follow-ups with updated AXI floors (#5350)
kunchenguid Sep 23, 2026
a8a2959
fix(bin): refuse ship done: when the named head exists only in the wo…
tiago-peixoto Sep 23, 2026
82dec2e
fix(bin): ring a proven-idle secondmate before raising a wake-loop st…
tiago-peixoto Sep 23, 2026
a5d78f8
test(watch-arm): size re-arm waits off the real loaded recovery cost …
tiago-peixoto Sep 23, 2026
52fca51
fix: stop watchers reliably during blocked polls (#5362)
kunchenguid Sep 23, 2026
c576c2b
fix: submit stuck inbox doorbells instead of skipping them (#5374)
kunchenguid Sep 23, 2026
f2ab14a
feat: add opt-in fleet activity ledger (#5375)
kunchenguid Sep 23, 2026
e7cb23e
fix: validate public follow-up deliverables and wake on rejection (#5…
kunchenguid Sep 23, 2026
697d94d
feat: add Devin CLI crewmate and scout adapter (#5380)
kunchenguid Sep 23, 2026
7c8f9ee
fix(bin): recognize passed-with-skips as a passing outcome (#5322)
mremond Sep 23, 2026
2efa581
fix(bin): refuse unavailable backend adapters before sourcing (#5382)
Lakescape Sep 23, 2026
77e5af9
test: repair base-red liveness, export-DOM, and wake-queue self-tests…
blackxwhite88 Sep 23, 2026
fef37b9
fix: keep watcher status classification bounded to new log spans (#5383)
kunchenguid Sep 23, 2026
f0da72c
test: close pr-check watcher test gaps (original flake already fixed …
kunchenguid Sep 23, 2026
c00d5e1
feat: record fleet status immediately and emit PR-ready events (#5385)
kunchenguid Sep 23, 2026
1e0e773
test: synchronize foreign queue stall checks with watcher progress (#…
kunchenguid Sep 23, 2026
8c47279
test: isolate the bearings render fixture from the shared Lavish stor…
kunchenguid Sep 23, 2026
7e0e60a
fix(bin): prune a torn-down task's wake rows at teardown (#5390)
blackxwhite88 Sep 23, 2026
9296f9b
test: align portable test expectations with resolved host paths and f…
sandeepsalwan1 Sep 23, 2026
5df1294
test: make sibling secondmate stall tests wait for watcher observatio…
kunchenguid Sep 23, 2026
1d3ac67
fix(bin): refuse a Herdr Claude submit that would send only a message…
tiago-peixoto Sep 23, 2026
fdd3687
feat(bin): publish and watch Gerrit changes on forge-bound projects (…
slnkjthien Sep 23, 2026
0afc6b4
feat(bin): opt-in per-home Claude and Pi worker account pin (#5358)
tiago-peixoto Sep 23, 2026
5bbb978
fix(bin): keep Herdr lab session selection before passthrough argumen…
yasuhito Sep 23, 2026
ac2ed3b
fix: enforce supervision guards across harnesses (#5471)
kunchenguid Sep 23, 2026
67130f1
feat(bin): make the ship-branch prefix configurable per project (#2648)
wesleymatosdev Sep 24, 2026
795e4b5
feat(bin): send dispatch router only the brief's task sections and ad…
zachlandes Sep 24, 2026
9284978
feat: add opt-in Claude away supervision host (#5488)
kunchenguid Sep 24, 2026
d4f3b78
docs: correct the Grok harness reference on folder trust, training op…
Courtneyezra Sep 24, 2026
5842d42
fix(bin): bound the startup-network worker's lock waits by its budget…
karotkriss Sep 24, 2026
e1d6cf9
fix(bin): make the ps-fallback watcher identity immune to terminal wi…
karotkriss Sep 24, 2026
474c6ee
fix(bin): ignore fenced and indented Captain lines when extracting au…
karotkriss Sep 24, 2026
0d983d2
fix(bin): forbid administering the shared worktree pool in crewmate b…
karotkriss Sep 24, 2026
977a81e
fix(bin): refuse tasks-axi add/create --start so In flight always has…
karotkriss Sep 24, 2026
e1b7f4f
feat: extend opt-in away supervision to non-Pi primaries (#5503)
kunchenguid Sep 24, 2026
d1ce6b6
fix: auto-relaunch dead secondmates during supervision (#5496)
kunchenguid Sep 24, 2026
31c47af
fix(bin): start a successor when the Claude Stop-hook arm's attached …
karotkriss Sep 24, 2026
b42d4fa
fix(bin): report a Lavish source armed only after its listener is run…
tiago-peixoto Sep 24, 2026
52e679b
fix(bin): stop repeating unknown-wake escalations that were already d…
tiago-peixoto Sep 25, 2026
c6e816f
fix(bin): keep a stated default-key retraction from cancelling a keyl…
tiago-peixoto Sep 25, 2026
a8572f6
fix(bin): terminate a remote job worker that lost ownership on TERM (…
tiago-peixoto Sep 25, 2026
4be8a40
docs: make configuration settings easier to find and understand (#5589)
tmchow Sep 25, 2026
b52d401
fix: limit project memory edits to factual corrections (#5636)
kunchenguid Sep 25, 2026
ca8c293
feat: permit gate lifecycle calls against disposable lab homes (#5635)
kunchenguid Sep 25, 2026
b575497
fix(bin): evict a watcher whose beacon stalls past a hard bound inste…
karotkriss Sep 25, 2026
5cec4e2
fix(pi): hide queued Firstmate inputs under Calm only when the sessio…
tiago-peixoto Sep 25, 2026
756f64e
fix(bin): refuse teardown when a required source disappears (#5548)
tiago-peixoto Sep 25, 2026
4e99de7
docs: make supervision-host easier to read (#5605)
tmchow Sep 25, 2026
660fa4a
docs: make the Herdr backend guide easier to read (#5606)
tmchow Sep 25, 2026
5323582
docs: make pi-supervision-branch easier to read (#5607)
tmchow Sep 25, 2026
d18a220
docs: make watcher-continuity easier to read (#5608)
tmchow Sep 25, 2026
70e41a8
docs: make sessionstart-nudge easier to read (#5609)
tmchow Sep 25, 2026
7c501a1
docs: make captain-hold-lifecycle easier to read (#5610)
tmchow Sep 25, 2026
c60f0ab
docs: make remote-secondmates easier to read (#5612)
tmchow Sep 25, 2026
683b3eb
fix(bin): bound the away digest and log why a delivery failed (#5554)
Sophylax Sep 25, 2026
dbe124d
test: add a gated harness seam and stabilize lifecycle fixtures (#5638)
kunchenguid Sep 25, 2026
1a814e4
fix(bin): refuse watchers from disposable checkouts and exit when the…
karotkriss Sep 25, 2026
84362f6
fix(bin): surface unrecognized status prefixes instead of reading the…
tiago-peixoto Sep 25, 2026
e97390a
fix(bin): report the failing item when remote inheritance fails (#5658)
karotkriss Sep 25, 2026
c643b57
fix(bin): stand down the Claude Stop auto-arm on pi-code-delivered pa…
karotkriss Sep 25, 2026
d1abcd6
fix(bin): match whole multi-word project names in the registry lookup…
karotkriss Sep 25, 2026
b805823
fix(bin): classify shell stdin payloads after -s operands (#5546)
coreldh Sep 25, 2026
83a4bbd
fix(bin): strip AI co-author trailers from fleet-launched commits (#5…
tiago-peixoto Sep 25, 2026
67f6c27
fix(bin): treat Pi's dollar-first cost footer as furniture (#5683)
tiago-peixoto Sep 25, 2026
8d2ee29
fix(bin): refuse merges with unreported required checks (#5534)
mremond Sep 25, 2026
0154324
fix: keep persistent secondmates out of landed-work cleanup (#5696)
kunchenguid Sep 25, 2026
f54aa00
fix: reject invalid X reply and follow-up arguments before posting (#…
kunchenguid Sep 25, 2026
3c14a54
fix: pause broken supervision-host sessions between engine probes (#5…
kunchenguid Sep 25, 2026
97365aa
fix(bin): absorb routine secondmate working and paused status appends…
karotkriss Sep 25, 2026
c4c9d63
fix(bin): use gh-axi for the ship DoD draft check (#5519)
karotkriss Sep 25, 2026
f1ea9ed
fix(bin): bind inactive-outcome receipt identity to structured fields…
karotkriss Sep 25, 2026
4299683
feat: record the Claude and Cursor dialog for the supervision host (#…
kunchenguid Sep 25, 2026
c33b3f6
fix(bin): retire check-row receipts on branch acknowledgement so away…
kunchenguid Sep 26, 2026
1fe1a67
fix(bin): deliver Claude-bound operational input as a record-backed d…
kunchenguid Sep 26, 2026
ef595d8
test: isolate lint fixture from tracked suite (#5727)
kunchenguid Sep 26, 2026
e789e52
fix(bin): republish parent metadata after a remote secondmate relaunc…
tiago-peixoto Sep 26, 2026
9a4cfbb
fix(bin): give slow watcher suites headroom under the changed-suite b…
karotkriss Sep 26, 2026
df4ae5d
fix(bin): stop nested steal-lock recursion and mid-steal watcher TERM…
kunchenguid Sep 26, 2026
873c923
test: make supervision-host park-boundary tests deterministic (#5710)
kunchenguid Sep 26, 2026
ea7c7f7
fix: stage remote home clones before publication (#5733)
kunchenguid Sep 26, 2026
920a7d9
fix: preserve Herdr status on Pi relaunch (#5161)
sdivanl Sep 26, 2026
65c53fb
Seed the relaunch-ordering PR poll fixture without fm-pr-check.sh (#5…
kunchenguid Sep 26, 2026
9b52cf5
feat: add attended supervision for Claude and Cursor hosts (#5748)
kunchenguid Sep 26, 2026
72b63ee
fix(bin): dedup directed source expansions in fm-pending-reply-lib (#…
kunchenguid Sep 26, 2026
d1a332c
fix(bin): avoid bash 5.2 sibling $() in recovery mint and delivery lo…
Lakescape Sep 26, 2026
3948170
fix(bin): name the recovery for a declined Claude imports dialog and …
karotkriss Sep 26, 2026
062d7a8
fix(bin): report the newest status event in the voice status reader (…
karotkriss Sep 26, 2026
e9a6675
fix(bin): gate a self-announcing tool's update-available report on a …
karotkriss Sep 26, 2026
cf20836
fix(bin): pass the dispatch profile effort to OpenCode workers throug…
karotkriss Sep 26, 2026
9d56cf6
fix: stop cancelled validation runs from reporting false failures (#5…
mremond Sep 26, 2026
bb69be6
fix: require declared waits for workers awaiting their own work (#5812)
mremond Sep 26, 2026
503ba82
fix: bound ShellCheck to one canonical root per process (#5770)
kunchenguid Sep 26, 2026
5700baa
fix: bound watcher cleanup wait on the downtime-marker lock (#5732)
kunchenguid Sep 26, 2026
62d643c
test: stop the remote secondmate e2e watcher before temp-root cleanup…
aminry Sep 26, 2026
30ef650
fix(bin): stop reporting untouched shared-captain copies as drift (#4…
tiago-peixoto Sep 26, 2026
f62a7d9
docs: restructure calm.md for readability (#5604)
tmchow Sep 27, 2026
3b68997
docs: restructure turnend-guard.md for readability (#5611)
tmchow Sep 27, 2026
49a218b
docs: move situational AGENTS.md sections into on-demand skills (#5872)
kunchenguid Sep 27, 2026
5a9880b
fix: route second-mate signal wakes by presented status span (#5879)
kunchenguid Sep 27, 2026
fd88ea0
fix(bin): take the source lock before the lifecycle lock in register-…
FocalFactotum Sep 27, 2026
b4561ad
fix: chain repository hooks under git -c overrides (#5877)
FocalFactotum Sep 27, 2026
fba81cb
fix(bin): withhold never-send values from dispatch resolver requests …
zachlandes Sep 27, 2026
6839202
feat(jev): add the guard framework contract and the memory RSS/swap t…
RooseveltAdvisors Sep 27, 2026
d051e6f
fix: prevent contribution poll starvation on slow GitHub reads (#5900)
0x7067 Sep 27, 2026
bff6454
feat(bin): add config/keep-ai-trailers opt-out to keep AI co-author t…
kiatng Sep 27, 2026
050a446
fix(bin): capture the full viewport for Herdr composer reads so a sla…
andrewesweet Sep 27, 2026
8a18fe2
fix(bin): isolate per-task endpoint reads in bounded children with a …
andrewesweet Sep 27, 2026
f93f0d3
fix: keep lab tmux sockets private and short under deep worktrees (#5…
kunchenguid Sep 27, 2026
ade7133
fix: silence routine no-change supervision outcomes (#5808)
jcpoyser Sep 27, 2026
8c5493a
feat: make /quiet a statement when attended supervision is ready (#5928)
kunchenguid Sep 27, 2026
c19c240
fix: grant Claude workers access to Firstmate task channels (#5884)
kunchenguid Sep 27, 2026
90e88d7
fix(bin): prevent idle recovery loops without stranding wakes (#4819)
jokim1 Sep 27, 2026
3d14792
fix: reduce remote worker and polling helper process churn (#5889)
kunchenguid Sep 27, 2026
022250d
fix: keep remote reply listeners and watcher cycles running (#5941)
kunchenguid Sep 27, 2026
3c2a91d
fix: make attended cutover outcome re-presentation check-first (#5925)
kunchenguid Sep 28, 2026
1b82b77
fix: restore primary rewakes after attended main-only closes (#5961)
kunchenguid Sep 28, 2026
9096504
Clarify live Claude login for opted-in tests (#5975)
kunchenguid Sep 28, 2026
fa48367
fix(bin): ensure resumed worker launches enter their recorded worktre…
mehulbhagwani Sep 28, 2026
6b0f5a0
fix(bin): retire task-keyed watcher markers and orphan journals at te…
karotkriss Sep 28, 2026
29213a0
test: guard the live harness gate against Claude Code's auto-updater …
karotkriss Sep 28, 2026
d5c2507
fix(bin): ring the worker inbox doorbell only for a newly written pro…
karotkriss Sep 28, 2026
b3dbc67
fix: prevent manual Claude Stop hook calls from arming supervision (#…
kunchenguid Sep 28, 2026
a256cb5
feat(firstmate-calm): show supervision notes in Claude Code (#6039)
kunchenguid Sep 28, 2026
4e158e6
fix: stop quiet mode from holding requested actions for return (#6033)
kunchenguid Sep 28, 2026
d9a89b2
Say ahoy impact order is the first mate's pick. (#6065)
kunchenguid Sep 28, 2026
eb219c8
fix(bin): accept a task's next PR after its bound PR merges in fm-pr-…
karotkriss Sep 28, 2026
2d833ff
fix: treat quiet records as attended across supervision (#6064)
kunchenguid Sep 29, 2026
00679ae
fix: report supervision host latches accurately in away return briefs…
kunchenguid Sep 29, 2026
40e981d
fix: shorten Claude Code Calm supervision note label (#6086)
kunchenguid Sep 29, 2026
b5fdf74
feat(bin): add a disposable live supervision lab builder (#6037)
kunchenguid Sep 29, 2026
46d58d6
fix: keep watcher arms and reply listeners alive through slow cycles …
kunchenguid Sep 29, 2026
c5f48e4
fix(bin): retry fm-pr-merge a bounded number of times when GitHub mer…
karotkriss Sep 29, 2026
260c4f0
fix(bin): converge every open owner onto a known terminal contributio…
karotkriss Sep 29, 2026
0a2cdf9
feat: enable supervision host by default for Claude primaries (#6124)
kunchenguid Sep 29, 2026
5bddfc4
fix(bin): create the state dir on a fresh primary before the session-…
karotkriss Sep 29, 2026
1f2c954
fix(bin): measure pending-reply grace from turn completion, not deliv…
karotkriss Sep 29, 2026
a774c44
fix(bin): stop provider-table lookup from writing broken-pipe errors …
tiago-peixoto Sep 29, 2026
e2668de
fix: restore portable CI behavior across Pi rendering and remote prov…
kunchenguid Sep 30, 2026
b3d4133
fix: confirm Lavish board replies before worker handoff (#6169)
kunchenguid Sep 30, 2026
12e90e1
fix: inherit supervision host opt-out across secondmates (#6154)
kunchenguid Sep 30, 2026
c35b9a6
fix: reduce supervision exit latency and stabilize host tests (#6179)
kunchenguid Sep 30, 2026
e1eb261
Merge upstream kunchenguid/firstmate main into the fork (#6154 #6179)
keenvc Sep 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ Hold-for-return is the default and the only reach profile this release records:
The away daemon is no longer launched on Pi; the ordinary supervision session (`docs/pi-supervision-branch.md`) keeps running with the record present, and `bin/fm-afk-launch.sh start` refuses on these harnesses.
With the record present main is parked: the supervision branch takes every safe actionable wake, captain outcomes accumulate for the return brief, and main's standing authority relocates to the branch through the guarded scripts (`docs/pi-supervision-branch.md` "Postures"); only a wake the branch declines (including a broken branch or unsafe scan) or a watcher failure wakes main.
`/quiet` needs nothing extra on Pi: the attended branch already keeps routine wakes out of this conversation, so quiet-while-present is the attended posture's own shape there.
- **A home that runs the supervision host** (a Claude home unless `config/supervision-host` says `off`, or a Cursor, OpenCode, omp, Grok, or Codex home with that file; `docs/configuration.md` "Supervision host"): nothing to launch for `/afk`; go on to the announcement.
- **A home that runs the supervision host** (a Claude home unless `config/supervision-host-off` opts it out, or a Cursor, OpenCode, omp, Grok, or Codex home with `config/supervision-host` and no opt-out; `docs/configuration.md` "Supervision host"): nothing to launch for `/afk`; go on to the announcement.
The supervision host (`docs/supervision-host.md`) is the away session there: it runs the branch's contract on a headless engine under the record while main is parked, and `bin/fm-afk-launch.sh start` and `start-native` refuse the away daemon on that home.
If `enter` printed a `Supervision host: no engine ...` line, every away wake reaches this conversation instead; say so in the announcement.
`/quiet` enters nothing there where the attended host runs, and otherwise still launches the daemon below (the quiet skill's `quiet-check` decides).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ Hooks still run through cwd-sensitive `/bin/sh`, so tracked commands anchor thro

The Stop-owned watcher hook runs every Stop, foregrounds `../../../bin/fm-watch-arm.sh` only when eligible, and uses exit-2 async reawakening as notification.
The model handles notifications but never routine re-arm.
Unless `config/supervision-host` says `off`, the hook foregrounds the supervision host instead, which also runs Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md#engines) owns the verified engine facts.
Unless `config/supervision-host-off` opts the home out, the hook foregrounds the supervision host instead, which also runs Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md#engines) owns the verified engine facts.
Claude's PreToolUse seatbelt blocks directly, and its deny is honored only with empty stdout; `../../../docs/arm-pretool-check.md` owns that contract.

### Delegation guard
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ The tracked hook anchors to `pwd -P`, verifies that root is Firstmate-shaped and

Codex's primary watcher protocol is `../../../bin/fm-watch-checkpoint.sh --seconds "${FM_CODEX_WATCH_CHECKPOINT:-180}"`, not `../../../bin/fm-watch-arm.sh`.
Codex cannot reason while a foreground tool call is running, so the checkpoint is deliberately foreground and bounded to return control regularly for user messages and queued notifications.
In a home with `config/supervision-host` (not `off`) the checkpoint runs the supervision host instead of the watcher, with Claude's print mode as its headless engine, and holds for at least an hour while away; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host and that bound.
In a home with `config/supervision-host` and no `config/supervision-host-off` the checkpoint runs the supervision host instead of the watcher, with Claude's print mode as its headless engine, and holds for at least an hour while away; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host and that bound.
Codex's PreToolUse watcher-arm seatbelt blocks directly through its project hook.
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ Example: `../../../bin/fm-spawn.sh <task-id> <project> --scout --harness cursor
## Primary integration

Primary supervision is the stop-hook park in `../../../docs/supervision-protocols/cursor.md` through tracked `.cursor/hooks.json`; primary and secondmate launches require `--trust` or hooks do not load.
In a home with `config/supervision-host` (not `off`) the park runs the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
In a home with `config/supervision-host` and no `config/supervision-host-off` the park runs the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
Cursor exposes 20 project events plus a Claude-Code compatibility map that loads `.claude/settings.json`.
Tracked hooks register `stop`, `sessionStart`, and two `preToolUse` seatbelts through `$CURSOR_PROJECT_DIR`; Claude entries stand down on Cursor payloads under `../../../docs/turnend-guard.md`.

Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/harness-adapters/references/harness/grok.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,5 +90,5 @@ The exact running Stop payload selects same-process continuation on 0.2.112; 0.2
Grok also loads Claude project settings, so Claude entries for Grok-covered events stand down under `GROK_AGENT` or `GROK_HOOK_EVENT`; that owner records the exact set and why `GROK_SESSION_ID` is excluded.
Project-local hooks require launch-time `--trust`; without it the guard steps aside and `../../../bin/fm-guard.sh` is the next-command alarm.
Watcher supervision remains tracked background notification around `../../../bin/fm-watch-arm.sh`, not Pi-style extension ownership.
In a home with `config/supervision-host` (not `off`) the session-start block renders that background call as `../../../bin/fm-supervision-host.sh park`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
In a home with `config/supervision-host` and no `config/supervision-host-off` the session-start block renders that background call as `../../../bin/fm-supervision-host.sh park`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
PreToolUse blocks directly, but every `$VAR` in a hook command needs inline `:-default` or Grok refuses the hook.
2 changes: 1 addition & 1 deletion .agents/skills/harness-adapters/references/harness/omp.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ There is no `agent_settled` event; `agent_end` plus `willContinue` replaces it.
The omp primary follows the Pi extension-owned watcher model through `../../../docs/supervision-protocols/omp.md`: `.omp/extensions/fm-primary-omp-watch.ts` arms `bin/fm-watch-arm.sh --restart` through the `fm_watch_arm_omp` tool and owns every successor, and `.omp/extensions/fm-primary-turnend-guard.ts` answers omp's blocking `session_stop` hook by forcing one continuation when `../../../bin/fm-turnend-guard.sh` returns 2, bounded per turn by omp's `stop_hook_active` flag.
The same file ports the `tool_call` seatbelts and delivers the session-start digest through `before_agent_start` on the Run tier; omp's `session_start` carries no reason, so the source is derived (first start `startup` or `resume` from the launch line, later in-process starts `clear`, `session_compact` as `compact`).
omp has no asynchronous Stop-hook equivalent, so the Claude auto-arm model does not apply; `fm_supervision_model` classifies omp as `extension`, and `fm_omp_extension_owns_supervision` in `../../../bin/fm-wake-lib.sh` is the ownership proof that tolerates the extension's own watcher hand-off.
The Pi supervision branch does not run on omp; without the supervision host every actionable wake is delivered to main, and in a home with `config/supervision-host` (not `off`) the watch extension spawns the host instead of the arm, with Claude's print mode as its headless engine ([`supervision-host.md`](../../../../../docs/supervision-host.md)).
The Pi supervision branch does not run on omp; without the supervision host every actionable wake is delivered to main, and in a home with `config/supervision-host` and no `config/supervision-host-off` the watch extension spawns the host instead of the arm, with Claude's print mode as its headless engine ([`supervision-host.md`](../../../../../docs/supervision-host.md)).
Launch a primary with plain `omp` inside the home (`FM_OMP_HARNESS=omp omp` when starting from a Claude pane); `../../../bin/fm-session-start.sh` prints `OMP_WATCH_EXTENSION: not loaded` when the running session has not loaded both tracked extensions.
`FM_OMP_LIVE_E2E=1 ../../../tests/fm-omp-primary-live-e2e.test.sh` is the opt-in live guard; `../../../tests/fm-omp-harness.test.sh` is the portable regression.
A secondmate registered with `remote=1` in `data/secondmates.md`, spawned through the ordinary `../../../bin/fm-spawn.sh <id> <home> --secondmate` path, is refused on omp until a remote host verifies it, as is `../../../bin/fm-remote-secondmate-control.sh launch`; there is no `--remote` flag.
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ The primary integration was verified on 2026-07-08 with OpenCode 1.17.6.
`.opencode/plugins/fm-primary-turnend-guard.js` listens for `session.idle`.
Throwing from `session.idle` does not block `opencode run`, so the primary adapter treats the event as passive and uses `client.session.promptAsync` to force one follow-up turn when `../../../bin/fm-turnend-guard.sh` returns 2.
The follow-up was verified in the interactive TUI.
In a home with `config/supervision-host` (not `off`) the watch-arm plugin spawns the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
In a home with `config/supervision-host` and no `config/supervision-host-off` the watch-arm plugin spawns the supervision host instead of `../../../bin/fm-watch-arm.sh`, with Claude's print mode as its headless engine; [`supervision-host.md`](../../../../../docs/supervision-host.md) owns the host.
`opencode run` can exit before displaying a queued follow-up, so the adapter steps aside in headless mode.
On native Windows, the operational-input adapter runs its Bash helper through `bash`; macOS and Linux invoke it directly.

Expand Down
3 changes: 2 additions & 1 deletion .agents/skills/operational-home-layout/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,8 @@ config/backend runtime session-provider backend override for new tasks; LOCAL,
config/calm Calm presentation preference shared by the Pi extension and the Claude Code mod; LOCAL, gitignored, and not inherited; see docs/configuration.md "Calm preference"
config/keep-ai-trailers optional presence flag to keep AI co-author trailers in this home's fleet commits; LOCAL, gitignored; inherited by secondmate homes; see docs/configuration.md "Commit attribution"
config/supervision-branch-model config/supervision-branch-effort Pi supervision-branch model and reasoning-effort pins written by /supervision-model; LOCAL, gitignored, independently settable, and not inherited; see docs/configuration.md "Pi supervision branch model and effort"
config/supervision-host optional supervision-host setting: the host runs the supervision branch's contract on a headless engine beside a non-Pi primary, away and, on a Claude or Cursor primary, attended; absent runs it on a Claude primary and nowhere else, "off" opts any home out; LOCAL, gitignored, not inherited; see docs/configuration.md "Supervision host"
config/supervision-host optional supervision-host engine setting: the host runs the supervision branch's contract on a headless engine beside a non-Pi primary, away and, on a Claude or Cursor primary, attended; absent runs it on a Claude primary and nowhere else; LOCAL, gitignored, not inherited; see docs/configuration.md "Supervision host"
config/supervision-host-off optional presence flag opting this home out of the supervision host on every primary; LOCAL, gitignored; inherited by secondmate homes under the primary-authoritative contract; see docs/configuration.md "Supervision host"
config/startup-memory-budget primary-authoritative per-home startup-memory budget; LOCAL, gitignored, materialized as 7,500 estimated tokens by locked primary bootstrap and inherited into secondmate homes; see docs/configuration.md "Startup memory budget"
config/stow-pass-horizon optional presence flag opting this home in to /stow's default-off pass-count decay horizon; LOCAL, gitignored, and not inherited; see docs/configuration.md "Stow pass horizon"
config/herdr-presentation-spaces optional "off" opt-out from, or "on" opt-in to, Herdr's default-on disposable single-task visual projection, which is unconfigured-default-on only at or above a Herdr version floor; LOCAL, gitignored; inherited by secondmate homes; see docs/herdr-backend.md "Presentation spaces"
Expand Down
2 changes: 2 additions & 0 deletions .agents/skills/secondmate-provisioning/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,8 @@ Inheritance copies the literal `config/crew-harness` file, so a secondmate's own
Inherited `config/backend` becomes that secondmate home's local runtime-backend default for future spawns only; it never retargets, rewrites, migrates, stops, or restarts an already-live worker endpoint.
A present primary value always converges byte-exact into validated secondmate homes, and primary absence removes the destination so those homes keep runtime auto-detection.
Explicit per-spawn `--backend` and `FM_BACKEND` remain stronger than every home's local `config/backend`, including an inherited default.
The declared `config/supervision-host-off` opt-out follows the same primary-authoritative propagation: its presence opts secondmate homes out even if they have their own engine setting, and its absence removes their copy at convergence.
`config/supervision-host` itself is not inherited; each home selects its own engine.
`config/secondmate-harness` is not inherited because it is only the primary's knob for launching secondmate agents.
`config/claude-account` and `config/pi-account` are not inherited: a local secondmate agent launches on the launching home's worker account pin, and a secondmate home that should pin its own workers needs its own file ([`docs/configuration.md`](../../../docs/configuration.md) "Worker account pin").
`data/captain-shared.md` is main-authoritative in the primary home and read-only in secondmate homes.
Expand Down
2 changes: 1 addition & 1 deletion .omp/extensions/fm-primary-omp-watch.ts
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
// /fm-watch-arm-omp; the loaded-build marker is state/.omp-watch-extension-loaded.
// - Supervision host: a home opted in with config/supervision-host
// (docs/configuration.md "Supervision host" owns the gate, which
// bin/fm-supervision-engine-lib.sh enabled answers; an `off` file opts out) spawns
// bin/fm-supervision-engine-lib.sh enabled answers; config/supervision-host-off opts out) spawns
// bin/fm-supervision-host.sh park --restart in the arm's place, which
// takes away-posture wakes itself and closes only when main is needed; its
// header owns the output read here. A "supervision-host:" line is
Expand Down
2 changes: 1 addition & 1 deletion .opencode/plugins/fm-primary-watch-arm.js
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ import { encodeFirstmateOperationalInput } from "./lib/fm-operational-input.js";

// Supervision host: a home opted in with config/supervision-host
// (docs/configuration.md "Supervision host" owns the gate, which
// bin/fm-supervision-engine-lib.sh enabled answers; an `off` file opts out) spawns
// bin/fm-supervision-engine-lib.sh enabled answers; config/supervision-host-off opts out) spawns
// bin/fm-supervision-host.sh park --restart in the arm's place, which takes
// away-posture wakes itself and closes only when main is needed; its header
// owns the output read here. A "supervision-host:" line is actionable like a
Expand Down
2 changes: 1 addition & 1 deletion bin/fm-claude-stop-autoarm.sh
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@
# host owns its own successors, so its path is unchanged.
# - Supervision host: a home that runs it (by default on this Claude
# primary; docs/configuration.md "Supervision host" owns the gate and its
# `off` opt-out) runs bin/fm-supervision-host.sh in the arm's place, bound
# opt-out) runs bin/fm-supervision-host.sh in the arm's place, bound
# to this generation.
# To this hook it is an arm that also takes away-posture wakes itself and
# ends its own park before the hook timeout with a "supervision-host:"
Expand Down
5 changes: 4 additions & 1 deletion bin/fm-config-inherit-lib.sh
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@
# secondmate's own claude crewmates launch on the same permission posture.
# Primary config/keep-ai-trailers is a home-wide commit-attribution choice, so
# a secondmate's own crewmates keep AI co-author trailers too.
# Primary config/supervision-host-off is the fleet's supervision-host opt-out,
# so a primary that opts out opts every secondmate home out too, while each
# home's config/supervision-host engine line stays its own.
# It also pushes
# the one primary-authoritative shared captain-preference file,
# data/captain-shared.md, into each secondmate home's data/ as a read-only copy.
Expand Down Expand Up @@ -79,7 +82,7 @@ FM_SHARED_CAPTAIN_MODE="444"
# The declared inheritable set (space-separated, config-dir-relative item paths).
# Extend here to inherit more of the primary's local config; override via the
# environment only in tests. Items must not contain whitespace.
FM_INHERITABLE_CONFIG="${FM_INHERITABLE_CONFIG:-crew-dispatch.json dispatch-never-send crew-harness backlog-backend backend herdr-presentation-spaces startup-memory-budget trace-context launch-env-allowlist claude-permission-mode lavish-axi-host keep-ai-trailers}"
FM_INHERITABLE_CONFIG="${FM_INHERITABLE_CONFIG:-crew-dispatch.json dispatch-never-send crew-harness backlog-backend backend herdr-presentation-spaces startup-memory-budget trace-context launch-env-allowlist claude-permission-mode lavish-axi-host keep-ai-trailers supervision-host-off}"

# Items whose value is a home-SESSION enablement decision rather than durable
# local configuration. They are inherited at the launch convergence point, where
Expand Down
Loading
Loading