Conversation
coreldh
marked this pull request as draft
August 2, 2026 16:26
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Firstmate supervision and record integrity, plus a hardening of the watcher arm guard.
43 files, +2658/−104, in four commits. This is not a small change and should not be reviewed as one.
What is actually in here
1.
fix: reconcile retained supervision state— 43 files, +2522/−104. The bulk of the PR. Addssix new scripts and their suites:
bin/fm-record-reconcile.shbin/fm-custody-lib.shbin/fm-model-capacity-hold.sh+-lib.shbin/fm-bearings-report.shbin/fm-process-progress.shand touches ~20 existing
bin/scripts, largest beingbin/fm-decision-hold.sh(+473/−25) andbin/fm-watch.sh(+166/−1).2.
fix: reconcile terminal wakes immediately— 7 files, +94/−16.3.
fix: fail closed on watcher syntax checks— 3 files, +78/−24. The arm-guard allow-list.4.
docs: disclose bash -s watcher guard gap— 1 file, +5/−1.The load-bearing design choice (commit 3)
The watcher syntax-check exception is an allow-list, not patterns bolted onto a deny-list. Three
holes have been found in this guard —
--rcfile,--init-file,-s— all argument-consuming orpayload-hiding invocation forms. The class is demonstrably not exhausted, so the structure must fail
closed on the fourth form nobody has found yet. A deny-list would not.
One pre-existing gap is deliberately NOT closed
bash -swith an operand hides a heredoc/here-string payload from shell-invocation analysis and canexecute
bin/fm-watch.shend to end. It is pre-existing onmain, not introduced here. Trackedas #1489;
docs/arm-pretool-check.mdnow names it and limits the coverage claim to staticallyrecognized shell invocations rather than overstating what the guard catches.
Verification
Rebased onto
8c21b10;origin/mainis an ancestor, so this fast-forwards.git range-diffaccounts for all four commits — none squashed or dropped; three patch-identical, one
integration-adjusted where an
AGENTS.mdconflict retained both this branch's correction and newmain's process-event clause.
Thirteen-case arm-guard matrix across Codex, Claude, Grok, OpenCode and Pi transports: 12/13.
A13 is expected red and is not this branch's defect — attribution was controlled by running it
against
origin/mainat8c21b10, which returns the identicaldeny watcher-bundled. Trackedseparately.
Security-property matrix:
bash -n/bash --noexecallowed; nested execution,--rcfile,--init-fileand all three redirection forms denied.Suites green:
fm-arm-pretool-check,fm-procevent,fm-turnend-guard,fm-supervision-events,fm-watch-triage;fm-lintwith pinned ShellCheck 0.11.0; documentation-audience check;git diff --check.Not independently verified: the guard matrix was produced by the authoring agent. It could not be
re-run by the supervising agent, because commands naming the watcher script are themselves denied by
the guard under test.
Review note
Opened for @kunchenguid. Merge authority is not ours.