Conversation
…, and state artifacts
…unknown branch; dedupe identity
…efuse path; matrix rerun still in flight, doc transcript not yet replaced
…provenance and pointers
Treat OMP's spinner-backed Waiting tool footer as an active turn alongside Running while preserving the existing Working signature and exact row anchoring. Add regression fixtures for both active tool states and an idle model status bar.
Make the live Herdr role matrix verify the shared supervision beacon by mtime within the guard grace period and drain the blocked escalation wake before the next guarded send. Keep the diagnostic scope limited to the existing fixture.
Make the OMP watcher tool report success only after a fresh owner is ready, and bind the live Herdr matrix drains to the exact watcher notifications they consume.
Record the clean 17-script tmux and Herdr matrix at the final source head, including event-bound watcher delivery and the observed backend limits.
…readiness contract
Author
|
Closing this no-mistakes-created duplicate. The authorized delivery PR for this work is #1376; its existing source branch will be fast-forwarded without force-pushing after final-head validation. Nothing from this duplicate is being merged. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Complete and publish the verified OMP support contract for issues #6 and #7 on the existing fork PR without merging or deploying, preserving exact OMP identity, Pi behavior, and validated tmux and Herdr lifecycle coverage.
What Changed
bin/fm-omp-capabilities.shandbin/fm-omp-process-lib.sh, OMP branches inbin/fm-harness.sh,bin/fm-spawn.sh,bin/fm-send.sh,bin/fm-session-start.sh, and the.omp/extensions/fm-primary-omp.tswatcher extension, covering primary, secondmate, and worker roles.bin/fm-primary-watch-core.tsthat.pi/extensions/fm-primary-pi-watch.tsand the new OMP extension both consume; arm now waits for watcher readiness before reporting success, and the watcher signal scan distinguishes same-second turn-end markers.bin/backends/herdr.shgains OMP pane/composer handling,bin/fm-tmux-lib.shrecognizes the OMP waiting busy footer,bin/fm-composer-lib.shstrips prompt glyphs independent of locale, and OMP spawn abort cleanup now confirms the endpoint stopped before destructive teardown.tests/fm-omp-*.test.sh, expanded Herdr/tmux/spawn fixtures) plus OMP docs underdocs/supervision-protocols/omp.mdand refreshed backend verification records.Risk Assessment
✅ Low: The only change since the last round is a test fixture made stateful plus a new targeted regression test for herdr's refused-close shape; it restores reachability of the previously covered destructive-cleanup path and pins the preservation path, with no production code touched.
Testing
Reran the OMP contract at the branch tip against real omp 17.1.8, herdr, and tmux: all five live lifecycle owners (Herdr role matrix, Herdr /exit, tmux worker/scout, primary, secondmate) pass, alongside the fixture contract for OMP identity/refusal, marker publication, secondmate durability, Herdr backend, spawn dispatch, tmux busy footer, and watcher lock/arm. Beyond pass/fail I captured the live OMP tmux pane an operator actually sees, showing exact FM_OMP_HARNESS=omp identity, the launch brief delivered once, idle and busy steering, interrupt, a real /skill turn, clean /exit, and omp --resume restoring the remembered session token; this is a terminal/CLI change with no rendered UI surface, so a pane transcript is the genuine end-user artifact rather than a screenshot stand-in. Two failures appeared (fm-pi-primary-types typecheck of the untouched fm-calm.ts, and one OpenCode session-lock assertion in fm-pi-watch-extension) but both reproduce identically at base commit 1e24757 in files outside this branch's diff, so they are pre-existing local environment drift, not regressions; the branch's new adapter typecheck over the extracted fm-primary-watch-core.ts passes cleanly. Worth noting for the PR: docs/verification/runtime-backends.md pins its combined-runner evidence to head ce9ad11, two review commits below the tip, and my rerun at the tip confirms that claim still holds.
Evidence: Live OMP worker pane transcript (real omp 17.1.8 in tmux: exact identity, once-only brief, idle/busy steering, interrupt, skill turn, exit, resume with restored token)
bash-5.1$ FM_OMP_HARNESS=omp '/home/dnth/.bun/bin/bun' '.../pi-coding-agent/dist/cli.js' --session-dir '/tmp/fm-omp-live-worker/omp-sessions' --resume '...jsonl' --auto-approve -e '.../omp-live-worker.omp-ext.ts' ╭─── omp v17.1.8 ───────────────────────────────╮ │ Welcome back! │ Recent sessions │ │ │ • FIRSTMATE_OP: ... │ ╰───────────────────────────────────────────────╯ FIRSTMATE_OP: v1 launch-brief: Remember the token OMP_CONTEXT_TOKEN_73 for this session. Respond exactly OMP_INITIAL_DONE and do nothing else. OMP_INITIAL_DONE Respond exactly OMP_IDLE_STEER_DONE. OMP_IDLE_STEER_DONE Run this exact command with bash: sleep 5. Then respond exactly OMP_BUSY_FIRST_DONE. ╭─ $ sleep 5 ───────────────────────────────────╮ │ Skipped due to queued user message. ... │ ╰───────────────────────────────────────────────╯ After the current tool finishes, respond exactly OMP_BUSY_STEER_DONE. OMP_BUSY_STEER_DONE ╭─ ✦ skill fm-omp-probe ────────────────────────╮ │ .../worker-wt/.omp/skills/fm-omp-probe/SKILL.md │ ╰───────────────────────────────────────────────╯ OMP_SKILL_DONE Closing session… Resume this session with omp --resume 019fbd44-1e36-7000-9d73-2ce15ad432a2 Reply with the remembered session token only. ╭── ⬢ GPT-5.6-Sol++ · ◔ low ▶ 🌳 project/worker-wt ▶ ⑂ fm/omp-live-worker ▶──╮Evidence: Live OMP lifecycle results at branch tip (real omp + herdr + tmux)
OMP support contract - live lifecycle reruns at head 15a09a8 (branch tip) ok - real Herdr OMP role matrix: primary, worker/scout idle and busy steering, blocked escalation, secondmate, normal exits, recovery, duplicate refusal, and guarded teardown ok - real tmux OMP worker/scout lifecycle: launch, exact identity, worker and scout idle/busy steering, interrupt, skill, exit, and resume ok - real Herdr OMP /exit: exact native identity, post-offset normal session_exit, pane absence, and guarded tripwire teardown ok - OMP omp/17.1.8 primary E2E proved fresh no-state and ordinary native discovery, exact ownership, once-only startup, guarded watcher startup, /new continuity, shutdown, resume, and away-mode delivery ok - real isolated tmux OMP secondmate launch, idle health, marked replies, exit, same-session resume, context, and duplicate refusalEvidence: Herdr live role matrix runner log
Evidence: Remaining four live OMP lanes runner log
Evidence: Live tmux pane inventory during the OMP worker lane
firstmate:fixture zsh firstmate:fm-omp-live-worker bun/tmp/no-mistakes-evidence/01KYYJF7WYM0QRTXGTS1GH6VPZ/omp-contract-rest.log)Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
⏭️ **Rebase** - skipped
Step was skipped.
bin/fm-spawn.sh:329- OMP spawn abort cleanup trusts fm_backend_kill's exit status as proof the endpoint stopped, but fm_backend_herdr_kill returns 0 even when it refuses the close (bin/backends/herdr.sh:3013-3020 prints "herdr task kill could not acquire its session presentation lock; refusing an unlocked pane close" and falls through to an implicit success). Failure sequence: an OMP spawn on backend=herdr creates the pane, the launch acknowledgement poll fails (bin/fm-spawn.sh:2057/2071 exit 1), the trap runs OMP cleanup with ownership proven, another spawn/teardown holds the session presentation lock for the full 5s retry window (this refusal is present in the branch's own recorded live run, docs/verification/runtime-backends.md), so the pane is never closed yet theelif ! fm_backend_killguard passes. Cleanup then force-returns the worktree (treehouse return --force) and deletes $ID.meta/$ID.status/$ID.omp-* while a live OMP process still runs in that pane, leaving an untracked agent with no task metadata and no worktree. Note this block also runs before the presentation-lock acquisition used by the HERDR_PROJECTION_ABORT_CLEANUP block below, so it competes for the same lock. Fix at the call site by re-checking endpoint state after the kill before the destructive branch, mirroring the existing OMP_POST_KILL_STATE check at bin/fm-spawn.sh:204-209; the earliest shared boundary alternative is making fm_backend_herdr_kill return nonzero when it refuses the close.bin/fm-primary-watch-core.ts:532- armAndWait mostly delivers the commit's claimed invariant (tool success only after a ready owner), but two residual paths remain. (1) When startArm returns the ok "unchanged - already owns a scheduled continuity retry" result, owner.child is null, soif (!armChild || ...) return resultreports success with no watcher running and none yet ready. (2) On readiness timeout it returns FAILED but leaves the unready arm child occupying owner.child, unlike restoreAfterActionableClose (line 339), which explicitly retires an unready successor for exactly that reason; a repeat repair call then only re-awaits the same child. Both are self-correcting through the close handler's retry/restore path, so this is a note, not a defect.bin/fm-spawn.sh:2047- The secondmate session-pointer validation is expressed as an inverted short-circuit chain ([ parent != dir ] || [ -L file ] || [ ! -f file ] || OMP_ACK_SESSION_OK=1). It is correct, but it reads as the opposite of its intent; a positiveif [ parent = dir ] && [ ! -L file ] && [ -f file ]form would match the surrounding validation style in prepare_omp_secondmate_session (lines 314-322).bin/fm-tmux-lib.sh:342- fm_tmux_omp_composer_state derives composer content from the already-ANSI-stripped pane and never applies fm_composer_strip_ghost, unlike every sibling path (fm_tmux_classify_composer_row line 154, and the Herdr OMP branch at bin/backends/herdr.sh:2620 which does strip ghost before classifying). If OMP renders de-emphasized placeholder text inside its╰─ ... ─╯input row, that row classifies aspendingon tmux, which would make fm_pane_input_pending always true and cause the away-mode daemon to defer every injection into an OMP supervisor pane. No fixture in this branch exercises an OMP composer with dim text, so this is flagged as an untested asymmetry rather than a proven failure.🔧 Fix: confirm OMP abort endpoint stop before destructive cleanup
1 error still open:
tests/fm-spawn-dispatch-profile.test.sh:119- The new post-kill confirmation gate (bin/fm-spawn.sh:322 spawn_omp_abort_endpoint_stopped) requires fm_backend_agent_state to reportmissing, but the herdr fake in this file is stateless, so the pre-existing herdr abort test can no longer reach the destructive branch. Concrete sequence for test_omp_herdr_unacked_launch_cleans_owned_endpoint_worktree_and_artifacts (line 881): the launch ack fails, OMP cleanup proves ownership, fm_backend_kill logspane close w1:p2and returns 0, then fm_backend_agent_state herdr calls fm_backend_herdr_pane_presence_state ->herdr pane get w1:p2, which the fake (line 101) always answers with a live pane, so presence ispresent,agent get(line 122) returns omp/idle ->live-> agent_statealive.aliveis not in {missing,unverified}, so the helper returns 1, cleanup prints "could not confirm its owned endpoint stopped", and the test then fails its assertions at lines 895-899:return --force $WT_DIRis never logged and $id.meta, $id.omp-ext.ts, and /tmp/fm-$id are all still present. (The tmux fake is unaffected:list-windows) exit 0yields an empty inventory, which fm_backend_tmux_agent_state classifies asmissing.) Fix the fixture the same way tests/fm-omp-secondmate.test.sh already does: havepane closeclear a pane-presence flag and havepane getreturn {"error":{"code":"pane_not_found"}} once that flag is gone, so a real close is distinguishable from herdr's refused close.🔧 Fix: make herdr spawn fixture pane presence stateful
1 info still open:
tests/fm-spawn-dispatch-profile.test.sh:125- The new presence flag is a single global file, so the fake'spane closeclears it for any pane id even though the same handler logs the specific id it was asked to close. No current case in this file closes a second pane (the fake has noworkspace createhandler, so fm_backend_herdr_workspace_prune_seeded_default_tab never runs, and projection cleanup is not exercised), so this is not reachable today. If a future herdr case ever closes the seeded default tab or a projection pane, the task pane would be reported gone as well and would silently satisfy the confirmed-stop gate. A per-pane flag path (e.g. "$FM_FAKE_HERDR_PANE_FLAG.$3") would keep the fixture faithful.✅ **Test** - passed
✅ No issues found.
bin/fm-test-run.sh tests/fm-omp-harness.test.sh tests/fm-omp-primary.test.sh tests/fm-omp-secondmate.test.sh tests/fm-pi-compatible-family.test.sh— greenbin/fm-test-run.sh tests/fm-backend-herdr.test.sh tests/fm-spawn-dispatch-profile.test.sh tests/fm-tmux-submit-busy.test.sh tests/fm-secondmate-liveness.test.sh tests/fm-watcher-lock.test.sh— green (covers the two final review commits: stateful Herdr spawn fixture pane presence, abort-endpoint stop before destructive cleanup, watcher readiness before arm success)FM_OMP_HERDR_LIVE_E2E=1 bin/fm-test-run.sh tests/fm-omp-herdr-live-e2e.test.sh— real herdr + omp role matrix, green (477s)FM_OMP_TMUX_LIVE_E2E=1 FM_OMP_HERDR_EXIT_LIVE_E2E=1 FM_OMP_PRIMARY_LIVE_E2E=1 FM_OMP_SECONDMATE_LIVE_E2E=1 bin/fm-test-run.sh tests/fm-omp-worker-tmux-live-e2e.test.sh tests/fm-omp-herdr-exit-live-e2e.test.sh tests/fm-omp-primary-live-e2e.test.sh tests/fm-omp-secondmate-live-e2e.test.sh— four live lanes, greenManual evidence capture:tmux -L fm-omp-worker-live-864967 capture-pane -p -S -120 -t firstmate:fm-omp-live-workeragainst the live OMP worker pane during the tmux lanebin/fm-test-run.sh tests/fm-bootstrap.test.sh tests/fm-session-start.test.sh tests/fm-send-strict.test.sh tests/fm-fleet-snapshot-view.test.sh tests/fm-pi-primary-types.test.sh tests/fm-pi-watch-extension.test.sh tests/fm-calm-pi-extension.test.sh tests/fm-composer-lib.test.sh— 6 green, 2 pre-existing failuresPre-existing-failure control:git archive 1e24757 | tar -x -C /tmp/...thenbash tests/fm-pi-watch-extension.test.shandbash tests/fm-pi-primary-types.test.shat base — both fail identically to HEADStandalone repro of the OpenCode session-lock assertion against the unchanged.opencode/plugins/fm-primary-watch-arm.js— fails at phase 2 on both headsgit status --short --branchafter cleanup — worktree clean, transient /tmp lab dirs removed🔧 **Document** - 1 issue found → auto-fixed ✅
docs/verification/runtime-backends.md:101- The recorded OMP tmux+Herdr matrix evidence in docs/verification/runtime-backends.md is bound to head ce9ad11, but two later commits on this branch change covered behavior: 5df7a43 makes the OMP spawn abort path require a backend agent-state confirmation before destructive cleanup (bin/fm-spawn.sh), and 15a09a8 changes the herdr spawn dispatch fixture. I corrected the doc so it no longer claims the runs happened at the final source head, but I cannot rerun the live OMP/Herdr matrices from the documentation phase. Before publishing the support contract, rerun the combined runner at the final head and replace the transcript.🔧 Fix: point Pi generation-owner docs at shared watcher core
✅ Re-checked - no issues remain.
🔧 Fix: bind and drain secondmate recovery wake before resumed exit
1 warning still open:
🔧 Fix: bind OMP submit snapshot offset to complete JSONL boundary
1 warning still open:
🔧 Fix: quarantine native OMP agent read probe form
1 warning still open:
🔧 Fix: bind primary wake drain and route blocked answer via captain
1 warning still open:
🔧 Fix: accept structured ask selectedOptions for routed worker choice
1 warning still open:
🔧 Fix: accept idle-captain path for blocked worker answer
1 warning still open:
🔧 Fix: harden Herdr matrix JSONL offsets and event predicates
1 warning still open:
🔧 Fix: reuse production JSONL offset owner and tolerate ask-close race
1 warning still open:
🔧 Fix: drop duplicate secondmate status wake requirement
1 warning still open:
🔧 Fix: replace fixture wake drain with primary-owned settle wait
1 warning still open:
🔧 Fix: confirm OMP blocked-ask answers via structured selectedOptions
1 warning still open:
🔧 Fix: require exact structured ask result for blocked OMP answers
1 warning still open:
🔧 Fix: distinguish same-second turn-end markers in watcher signal scan
1 warning still open:
🔧 Fix: add same-second turn-end marker regression test
1 warning still open:
🔧 Fix: order watcher signal signature as inode:size:mtime
1 warning still open:
🔧 Fix: bind OMP session offset newline check to recorded size
1 warning still open:
🔧 Fix: add deterministic OMP offset TOCTOU regression test
1 warning still open:
🔧 Fix: omit explicit deliverAs for OMP watcher notifications
1 warning still open:
✅ **Push** - passed
✅ No issues found.