Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
88b2a94
fix(bin): correct session lock and attached watcher supervision (#1545)
kunchenguid Aug 2, 2026
33a4287
fix(bin): harden Claude supervision auto-arm recovery (#1495)
kunchenguid Aug 2, 2026
4ee4a0a
feat(bin): require an explicit per-task delivery contract (#1563)
kunchenguid Aug 3, 2026
7809ab9
feat(bin): support remote secondmate homes (#1576)
kunchenguid Aug 3, 2026
976d97f
feat: add per-task trace context propagation (#995)
allstargg Aug 3, 2026
cf95112
fix(bin): harden tmux agent liveness across harnesses (#1577)
kunchenguid Aug 3, 2026
3d9d12d
feat(bin): propagate trace context to remote secondmates (#1609)
kunchenguid Aug 3, 2026
733a504
feat(bin): preflight remote runtime tool paths (#1623)
kunchenguid Aug 4, 2026
e5e8a67
feat: gate remote second mates on Herdr readiness (#1639)
kunchenguid Aug 4, 2026
c8edff3
fix: isolate remote secondmates in shared Herdr session (#1659)
kunchenguid Aug 4, 2026
a83be60
feat: route remote commands through an Aqua job worker (#1660)
kunchenguid Aug 4, 2026
fc3684a
fix: clarify remote doctor bootstrap path (#1691)
kunchenguid Aug 4, 2026
1939785
fix(bin): bound remote SSH dead-peer detection (#1699)
kunchenguid Aug 4, 2026
4a9979a
fix: report stale AXI tools during bootstrap (#1701)
kunchenguid Aug 4, 2026
d0461e4
fix: prevent false watcher-down alarms in Claude sessions (#1661)
karotkriss Aug 4, 2026
1cd97c0
test: prevent fixture temporary directory leaks (#1704)
kunchenguid Aug 4, 2026
3089a57
feat(herdr): enable presentation spaces by default (#1708)
kunchenguid Aug 4, 2026
bb352e7
fix(bin): surface fleet-wide open decisions on every wake drain (#1711)
kunchenguid Aug 5, 2026
7ef26c4
fix(bin): abort parked runs and reap leaked processes before teardown…
kunchenguid Aug 5, 2026
bea3d23
fix: resolve fm-remote-entrypoint.sh SCRIPT_DIR through a PATH symlin…
kunchenguid Aug 5, 2026
71f0b3f
fix(pi): gate Calm built-in overrides by activation state (#1724)
kunchenguid Aug 5, 2026
30b18b9
fix(bin): persist secondmate parent bindings for cleanup (#1727)
kunchenguid Aug 5, 2026
ef2c3a2
feat(bin): enforce latest AXI-family tool floors (#1733)
kunchenguid Aug 5, 2026
bf01a42
fix(bin): bound open decision scans with incremental cursors (#1737)
kunchenguid Aug 5, 2026
6f0f87f
fix(bin): prevent remote polls from blocking session startup (#1754)
kunchenguid Aug 5, 2026
3a8d63e
docs: present X mode as the X and Discord public surface (#1778)
kunchenguid Aug 6, 2026
3b6ee03
fix(bin): run session start deterministically from hooks (#1781)
kunchenguid Aug 6, 2026
5d77b48
fix: rename X mode to Relay in user-facing docs (#1784)
kunchenguid Aug 6, 2026
930ca76
feat: add Muse Code crewmate adapter (#1786)
kunchenguid Aug 6, 2026
8387039
fix(herdr): require 0.8.0 for default presentation spaces (#1787)
kunchenguid Aug 6, 2026
8ec3e94
fix(bin): classify settled Muse session logs as idle (#1788)
kunchenguid Aug 6, 2026
2cf0283
docs(agents): read the persisted digest when only a preview is shown …
kunchenguid Aug 6, 2026
345de4e
fix: preserve fleet state in truncated session-start digests (#1798)
kunchenguid Aug 6, 2026
6c206ed
feat(send): close answered decisions at answer time via --resolve-key…
kunchenguid Aug 6, 2026
e50a918
Merge upstream kunchenguid/firstmate main (6c206ed) into knowttl fork
knowttl Aug 7, 2026
710dffe
test(brief): supply the now-required ship --mode in the context-first…
knowttl Aug 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion .agents/skills/ahoy/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,11 @@ metadata:

Give the captain a concise session-only recap without gathering fresh state.

0. Before anything else, check whether this session has already taken the helm: a `SESSION START` digest for this home must be visible in the session history.
If it is not, run `bin/fm-session-start.sh` once and read its digest before producing any recap.
Run-tier harness surfaces run it automatically at session open, so this step is normally already satisfied and costs one glance; it is the safety net for surfaces that cannot run it on a hook, and for any path where a skill would otherwise act first.
Taking the helm always precedes this skill's own logic, and the digest it produces is operational input, never a captain message or a recap event.

1. Inspect only conversation or session history already visible to the current first mate.
2. Find the most recent real captain-authored message before the current `/ahoy` invocation.
A captain boundary is an ordinary user-role message unless it matches one of the narrow operational exclusions below.
Expand All @@ -32,7 +37,7 @@ Give the captain a concise session-only recap without gathering fresh state.
A later unrelated captain message establishes a recap boundary but does not close an earlier decision.
Treat a decision as closed only when a later visible response substantively resolves it, chooses an option, declines it, grants or denies the requested approval, or otherwise directly addresses that decision.
Include every visibly supported open decision once, and deduplicate by the decision's substance when the ordinary interval recap already represents it or its wording differs.
6. The normal recap branch is session-history-only.
6. The normal recap branch is session-history-only, apart from the step 0 helm check.
Do not call Bearings, shell commands, fleet snapshots, status readers, GitHub or browser APIs, tools, or file reads or writes.
Create no report, persist nothing, and do not guess current live state beyond the last visible event.
7. If no ordinary events occurred after the previous captain message but an older visibly open decision exists, report that decision instead of claiming nothing happened.
Expand Down
19 changes: 12 additions & 7 deletions .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: bootstrap-diagnostics
description: >-
Agent-only handling playbook for session-start bootstrap diagnostics.
Use whenever the session-start digest's bootstrap section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, STARTUP_MEMORY_BUDGET, CREW_DISPATCH invalid, FLEET_SYNC, PR_CHECK_MIGRATION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, NUDGE_SECONDMATES, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one of those lines.
Use whenever the session-start digest's bootstrap section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, STARTUP_MEMORY_BUDGET, CREW_DISPATCH invalid, FLEET_SYNC, PR_CHECK_MIGRATION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, SECONDMATE_HANDOFF, NUDGE_SECONDMATES, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one of those lines.
A silent bootstrap section, or a BOOTSTRAP_INFO fact, means no skill load.
user-invocable: false
metadata:
Expand All @@ -19,15 +19,17 @@ When any diagnostic needs captain attention, report the plain consequence and re
- `MISSING: <tool> (install: <command>)` - list the missing tools to the captain with a one-line purpose each plus the printed install commands, wait for consent (one approval may cover the list), then run `bin/fm-bootstrap.sh install <approved tools...>`.
For `treehouse`, this also covers an installed version whose `treehouse get` lacks `--lease`; treat it as an upgrade request.
For `no-mistakes`, this also covers an installed version older than 1.31.2, because crewmate validation briefs delegate gate mechanics to no-mistakes' version-matched guidance.
For `tasks-axi`, this also covers an installed build that fails the compatibility probe (`docs/configuration.md` "Backlog backend" owns the definition); `config/backlog-backend=manual` only suppresses the verbose `BOOTSTRAP_INFO: tasks-axi available` fact, not this missing-tool report.
For any axi-family tool - `gh-axi`, `lavish-axi`, `tasks-axi`, `quota-axi` - an installed version below its floor is a plain upgrade request; [`bin/fm-bootstrap.sh`](../../../bin/fm-bootstrap.sh) owns the floor policy, and never argue the floor down to whatever the home happens to have installed.
For `tasks-axi`, this additionally covers an installed build that fails the separate feature probe (`bin/fm-tasks-axi-lib.sh` owns the definition); `config/backlog-backend=manual` only suppresses the verbose `BOOTSTRAP_INFO: tasks-axi available` fact, not this missing-tool report.
For `quota-axi`, bootstrap requires it because firstmate reads its current output directly before resolving every crew-dispatch profile array; without it, report the missing requirement and do not choose around an unexamined candidate.
- `MISSING_MANUAL: <tool> (instructions: <url>)` - tell the captain why the tool is required and give them the printed instructions URL, but do not pass the tool to `bin/fm-bootstrap.sh install`; wait for the captain to complete the manual installation, then rerun session start to confirm the dependency is present.
- `BACKEND_INVALID: <name> (known: <names>)` - the resolved runtime backend has no verified dependency or lifecycle contract, so do not dispatch work until the invalid `FM_BACKEND` or `config/backend` value is corrected to one of the listed backends.
- `NEEDS_GH_AUTH` - ask the captain to run `! gh auth login` (interactive; you cannot run it for them).
- `TANGLE: <remediation>` - the primary checkout is stranded on a feature branch instead of its default branch; `AGENTS.md` section 8 explains why this guard exists and what it protects.
The work is safe on that branch ref; restore the primary to its default branch with the printed `git -C <root> checkout <default>`, then re-validate that branch in a proper worktree.
This is the only sanctioned firstmate-initiated git write to the primary, and it is a non-destructive branch switch that strands nothing.
- `STARTUP_MEMORY_BUDGET: invalid config/startup-memory-budget - <reason>` - the visible startup-memory budget is not a safe one-line positive decimal file; do not infer the default or propagate it. Correct the local primary file, then rerun session start so the normal convergence path can deliver the validated value to secondmate homes.
- `STARTUP_MEMORY_BUDGET: invalid config/startup-memory-budget - <reason>` - the visible startup-memory budget is not a safe one-line positive decimal file; do not infer the default or propagate it.
Correct the local primary file, then rerun session start so the normal convergence path can deliver the validated value to secondmate homes.
- `CREW_DISPATCH: invalid config/crew-dispatch.json - <reason>` - the optional dispatch profile file exists but failed low-cost bootstrap validation; stop profile-based dispatch, report the actionable error, and require correction of the malformed schema, unverified harness name, or invalid harness/effort pair rather than falling back around it or selecting a bad profile.
- `FLEET_SYNC: <repo>: skipped: <reason>` - a benign one-off skip (offline, no origin, local-only); bootstrap continued, investigate only if it blocks work.
A skip can also report the bounded fleet-refresh timeout (`FM_FLEET_SYNC_BOOTSTRAP_TIMEOUT`, or a fleet-size-aware default with a 20 second floor); a timeout never blocks startup.
Expand All @@ -44,10 +46,13 @@ When any diagnostic needs captain attention, report the plain consequence and re
Resume the emitted supervision protocol after finishing the session-start wake handling.
- Any other `PR_CHECK_MIGRATION:` refusal means migration did not complete safely, whether because watcher exclusion, a private path, a diagnostic, quarantine validation, or marker publication could not be proved.
Keep each affected poll unavailable, inspect the named private state path, and do not bypass the migration or execute a quarantined artifact; a completed safe-scan marker allows unrelated authenticated polls to continue while private repair remains pending.
- `SECONDMATE_SYNC: secondmate <id>: skipped: <reason>` - the local-HEAD secondmate sync left a live secondmate home on its existing checkout because the home was dirty, diverged, unsafe, on the wrong branch, missing the primary target commit, or otherwise not fast-forwardable, or because inherited local-material propagation failed; bootstrap continued, but inspect the reason because the secondmate's tracked instructions, inherited settings, or shared captain preferences may be stale after a primary update.
- `SECONDMATE_SYNC: secondmate <id>: skipped: <reason>` - secondmate convergence left a live home on its existing checkout because the home was dirty, diverged, unsafe, on the wrong branch, missing its placement-specific target commit, unreachable, or otherwise not fast-forwardable, or because inherited local-material propagation failed; bootstrap continued, but inspect the reason because the secondmate's tracked instructions, inherited settings, or shared captain preferences may be stale after a primary update.
- `SECONDMATE_LIVENESS: secondmate <id>: skipped: <reason>|respawn failed after <cause>: <reason>` - the session-start liveness sweep could not guarantee that the registered secondmate is running a real agent process.
Investigate the reason because that secondmate is not guaranteed live.
- `NUDGE_SECONDMATES: secondmate <id>: send failed: <reason>` - the secondmate sweep fast-forwarded a running secondmate home and its loaded instruction surface (`AGENTS.md`, `bin/`, or `.agents/skills/`) changed, but the deterministic `fm-send.sh fm-<id>` re-read nudge failed.
Inspect the reason, keep the pending marker under `state/.secondmate-nudge-pending/` intact, and rerun session start after the endpoint or metadata issue is fixed so bootstrap can retry the exact same marked send.
- `FMX: X mode on ...` / `FMX: X mode off ...` - bootstrap confirmed or removed the local X-mode poll artifacts (`docs/configuration.md` "X mode (.env)").
- `SECONDMATE_HANDOFF: secondmate <id>: pending delivery: <n> item(s)` - queued work has already left the main dispatchable backlog and remains safe in the named remote route's backlog-format outbox.
Preserve that outbox and rerun `bin/fm-backlog-handoff.sh --resume-pending` after same-host connectivity returns; never re-add or dispatch the items from the main backlog.
An unsafe-outbox variant requires path and file-type inspection before any retry.
- `NUDGE_SECONDMATES: secondmate <id>: send failed: <reason>` - secondmate convergence changed a running home's loaded instructions or inherited config, but the deterministic `fm-send.sh fm-<id>` re-read nudge failed.
Inspect the reason, keep the pending marker under `state/.secondmate-nudge-pending/` intact, and rerun session start after the endpoint or metadata issue is fixed so bootstrap can retry the exact same marked send on the same local or remote route.
- `FMX: X mode on ...` / `FMX: X mode off ...` - bootstrap confirmed or removed the local Relay poll artifacts (`docs/configuration.md` "Relay (.env)"); the emitted line still carries Relay's former `X mode` wording.
Only when a running watcher needs the cadence transition applied immediately, restart the home-scoped watcher through the emitted harness supervision protocol; bootstrap deliberately never restarts the watcher itself.
23 changes: 23 additions & 0 deletions .agents/skills/firstmate-coding-guidelines/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,29 @@ Mark an axis not applicable only after inspecting its integration surface, and u
For critical safety, routing, startup, and supervision infrastructure, prefer deterministic and idempotent enforcement over relying on agent memory alone.
Keep instructions as the authority and discovery layer, but make repeated execution converge safely and make invalid or unsafe states fail closed wherever the runtime can enforce them.

### Harness-dependent checks

This section is the single owner of the rule and of how to satisfy it.

A check is harness-dependent when its verdict comes from something the vendor emits: a process name, rendered output, a spinner or keybind glyph, a banner, or a key the harness binds.
Anything in that class must be proven end to end against the real harness, because a stub or fake agent can only confirm the assumption already written into the stub.
That proof is authorized to spend tokens; the cost is small against a check that silently stops working.

Build the check on the most structural signal that answers the question, and prefer a kernel or protocol fact over anything a release note could change.
When a rendered surface is genuinely the only source, read more than one independent signal and let any of them carry a positive verdict, so no single vendor string is load-bearing.
Where a surface signal is unavoidable, back it with a guard that fails loudly naming the harness and version rather than degrading quietly.

Every such check needs two tests, because they fail for different reasons:

- A portable regression in `tests/` that pins the logic with real processes and no harness, so CI enforces the classifier everywhere it runs tmux.
Drive the signals apart deliberately and assert the verdict survives losing one; assert the divergence itself so the case cannot go quietly vacuous.
Confirm which signal a given construction actually blinds on each supported platform rather than assuming, because the same trick can break different sources on macOS and Linux.
- A live guard in the `live-harness-optin` family (`bin/fm-test-run.sh`), env-gated and self-skipping, that exercises every INSTALLED harness for real and fails naming the harness and version.
Report an absent harness explicitly rather than passing silently over it, and refuse a pass that checked nothing.
This guard is opt-in and on-demand because standard CI has neither harness binaries nor credentials; run it after every harness upgrade and before trusting refreshed per-harness evidence.

Record the dated per-harness result in `docs/verification/runtime-backends.md`, and point at the live guard as the command that refreshes it, rather than leaving a version-scoped observation to rot into a false claim.

## Documentation change review

For every changed maintained prose surface, identify its inventory audience, authoritative owner, current-behavior relevance, destination for supporting evidence, and any unique safety fact that removal could lose.
Expand Down
Loading