Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
70 commits
Select commit Hold shift + click to select a range
6237eb9
feat(harness): add cursor + agy as crew-only, herdr-only adapters
Jul 23, 2026
7e2cfa0
fix(harness): close the 4 cursor/agy review blockers (B1-B4) + failur…
Jul 23, 2026
553a862
test(harness): mark new cursor/agy test scripts executable (review N1)
Jul 23, 2026
4571ab1
fix(harness): close re-review B1/B3 + add S2 bootstrap backend warning
Jul 23, 2026
65b2dd4
fix(harness): close B1 variable-indirection bypass + fix 2 regressed …
Jul 23, 2026
7b60904
test: green the 3 environment-sensitive full-suite failures
Jul 23, 2026
ae5aab2
fix(harness): harden B1 with an exec-time PATH guard for raw cursor/a…
Jul 23, 2026
2df62e3
Merge origin/main into fm/cursor-agy-build (overlay, per captain Opti…
Jul 23, 2026
52f816e
no-mistakes(review): Fix native identity and trust teardown ordering
Jul 23, 2026
6159bad
no-mistakes(test): Guard launch rendering against unresolved placehol…
Jul 23, 2026
2d0c4c2
no-mistakes(document): Document restricted cursor and agy harness ada…
Jul 23, 2026
912dad5
Merge origin/main into fm/cursor-agy-build
Jul 23, 2026
46680c5
test: conform the cursor/agy tests to main's tightened contracts
Jul 23, 2026
f446c89
no-mistakes(review): Re-arm native completion and clean smoke trust
Jul 24, 2026
41b71b6
no-mistakes(review): Gate credentialed smoke outside portable tests
Jul 24, 2026
640fd60
no-mistakes(document): Align cursor and agy documentation ownership
Jul 24, 2026
d50dcca
Merge pull request #1 from HelloWorldSungin/fm/cursor-agy-build
HelloWorldSungin Jul 24, 2026
7b32a51
Wire GitHub issues into task delivery
Jul 29, 2026
8a97167
Stabilize locale and Calm regression checks
Jul 29, 2026
19f6c91
no-mistakes(review): Add exact no-issue brief golden coverage
Jul 29, 2026
433b66e
no-mistakes(document): Document GitHub issue delivery lifecycle
Jul 29, 2026
c6ba037
no-mistakes(lint): Suppress literal backtick fixture ShellCheck warning
Jul 29, 2026
38951b1
test(session-start): make the MISSING-tool fixture independent of the…
Aug 1, 2026
d7c1660
fix(pi): hand supervision to the away daemon while away mode is active
Aug 1, 2026
6c60252
no-mistakes(document): Document Pi away-mode supervision handoff
Aug 1, 2026
3db0341
fix(tests): wait for the TERM-resistant peer before restarting the wa…
Aug 1, 2026
dc107ba
fix(watch): honor TERM and HUP without waiting out the poll interval
Aug 1, 2026
c46e3b1
fix(tests): wait for the TERM-resistant peer before restarting the wa…
Aug 1, 2026
c50b2ce
no-mistakes(document): docs: correct interruptible poll-path description
Aug 1, 2026
343bb9f
fix(dispatch): resolve pi surfaces from the harness catalog
Aug 2, 2026
2aca111
no-mistakes(document): Clarify catalog-backed authentication evidence
Aug 2, 2026
c93ab0b
fix(brief): close three status-reporting gaps in the crewmate scaffold
Aug 1, 2026
1ea1c2d
no-mistakes(document): Clarify brief status-protocol header scope
Aug 1, 2026
fd39d53
no-mistakes: apply CI fixes
Aug 3, 2026
ca99120
fix(snapshot): stop passing fleet-sized JSON to jq through argv
Aug 1, 2026
9018941
no-mistakes: apply CI fixes
Aug 1, 2026
c1b74c6
fix(bin): migrate legacy non-tmux endpoint records so they stay clean…
Aug 2, 2026
0246f94
revert: drop the test-runner locale fix from this branch
Aug 2, 2026
e174818
no-mistakes(review): Refuse concurrent endpoint metadata rewrites
Aug 2, 2026
890bd37
no-mistakes(document): Document endpoint-binding migration behavior
Aug 2, 2026
e9eefb3
fix(tests): run coverage-guard set operations under the C collation
Aug 2, 2026
a473c4e
no-mistakes(document): Clarify coverage-guard collation documentation
Aug 2, 2026
05058ac
Merge upstream/main into the fork, preserving the cursor/agy adapters
Aug 3, 2026
f1a8979
Merge fm/fm-issue-lifecycle-wiring (upstream PR 1271)
Aug 3, 2026
7a18213
Merge fm/fm-bearings-snapshot-arg-too-long (upstream PR 1442)
Aug 3, 2026
b7a413a
Merge fm/fm-session-start-e2e-failure (upstream PR 1476)
Aug 3, 2026
de00adc
Merge fm/fm-pi-afk-dual-supervision
Aug 3, 2026
3d5d952
Merge fm/fm-brief-status-protocol-gaps
Aug 3, 2026
b8c5c34
Merge fm/firstmate-watcher-lock-flake
Aug 3, 2026
5777773
Merge fm/fm-watcher-term-hup-latency
Aug 3, 2026
e45fb62
Merge fm/fm-test-run-comm-sort-exit (upstream PR 1490)
Aug 3, 2026
5cd2fc8
Merge fm/fm-pi-auth-surface-unresolved (upstream PR 1491)
Aug 3, 2026
26a9bff
Merge fm/fm-endpoint-binding-migration (upstream PR 1492)
Aug 3, 2026
20b879f
Keep one window_harness definition after the upstream merge
Aug 3, 2026
e4a3787
Restore teardown functions dropped by my merge resolution
Aug 3, 2026
cc840d8
Complete two test fixtures for the merged tree
Aug 3, 2026
07a281f
Conform the cursor/agy adapter test to upstream's tightened contracts
Aug 4, 2026
149c812
Merge pull request #17 from HelloWorldSungin/fm/fm-fork-upstream-reco…
HelloWorldSungin Aug 4, 2026
b45b811
feat(bin): surface documentation-vault drift during bootstrap (#22)
HelloWorldSungin Aug 4, 2026
e24c1b7
fix(bin): prevent idle composer injection wedges (#23)
HelloWorldSungin Aug 4, 2026
58022b2
fix(watch): prevent repeated parked-decision wakes (#24)
HelloWorldSungin Aug 4, 2026
3035e74
fix: preserve crew run attribution during validation (#25)
HelloWorldSungin Aug 4, 2026
3df0ac3
docs: record GPU reranker endpoint (#26)
HelloWorldSungin Aug 4, 2026
c0b32da
feat(gbrain): add local embedding endpoint artifacts (#28)
HelloWorldSungin Aug 4, 2026
0b5e1dc
feat(bin): add project-scoped work-item linkage (#30)
HelloWorldSungin Aug 4, 2026
8967ff1
feat(bin): record durable task outcomes and extend fleet telemetry (#27)
HelloWorldSungin Aug 4, 2026
a6d1719
feat(bin): verify the model a dispatched worker actually ran on (#29)
HelloWorldSungin Aug 4, 2026
7245fae
feat(dashboard): add read-only fleet kanban
Aug 4, 2026
dc98129
no-mistakes(review): Captain, correct dashboard liveness, actions, an…
Aug 4, 2026
20e75ab
no-mistakes(document): Document current fleet dashboard behavior
Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,8 +49,8 @@ batched digest rather than per-wake injections.
The daemon is **presence-gated**: it injects escalations only while
`state/.afk` exists, and stays quiet otherwise.

3. **Do not separately arm `fm-watch.sh`.** The daemon manages the watcher as
its child; the singleton lock no-ops a stray arm harmlessly.
3. **Do not separately arm `fm-watch.sh`.**
The daemon manages the watcher as its child; [`docs/watcher-continuity.md`](../../../docs/watcher-continuity.md) owns the adapter hand-off contract.

4. **Acknowledge** in `AGENTS.md` section 9 language: "Captain, away mode is active; I will batch routine updates and surface only decisions, failures, credentials, or review-ready work until you return."

Expand Down
16 changes: 14 additions & 2 deletions .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: bootstrap-diagnostics
description: >-
Agent-only handling playbook for session-start bootstrap diagnostics.
Use whenever the session-start digest's bootstrap section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, STARTUP_MEMORY_BUDGET, CREW_DISPATCH invalid, FLEET_SYNC, PR_CHECK_MIGRATION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, SECONDMATE_HANDOFF, NUDGE_SECONDMATES, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one of those lines.
Use whenever the session-start digest's bootstrap section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, VAULT_DRIFT, STARTUP_MEMORY_BUDGET, CREW_DISPATCH (invalid or backend mismatch), FLEET_SYNC, PR_CHECK_MIGRATION, ENDPOINT_BINDING_MIGRATION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, SECONDMATE_HANDOFF, NUDGE_SECONDMATES, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one of those lines.
A silent bootstrap section, or a BOOTSTRAP_INFO fact, means no skill load.
user-invocable: false
metadata:
Expand All @@ -12,7 +12,7 @@ metadata:
# bootstrap-diagnostics

Handle each printed line as below, before dispatching work that depends on it.
The line formats themselves are owned by `bin/fm-bootstrap.sh`'s header; this playbook owns the response to actionable lines.
The top-level diagnostic vocabulary is owned by `bin/fm-bootstrap.sh`'s header, delegated detector headers own their exact subtype wording, and this playbook owns the response to actionable lines.
The inline rules in `AGENTS.md` section 3 still bind: detect, then consent, then install - never install anything the captain has not approved in this session - and no work is dispatched until the tools it needs are present and GitHub auth is good.
When any diagnostic needs captain attention, report the plain consequence and requested action using `AGENTS.md` section 9's captain-facing translation contract; do not name the diagnostic label unless the captain needs to paste it into a command or issue.

Expand All @@ -27,9 +27,16 @@ When any diagnostic needs captain attention, report the plain consequence and re
- `TANGLE: <remediation>` - the primary checkout is stranded on a feature branch instead of its default branch; `AGENTS.md` section 8 explains why this guard exists and what it protects.
The work is safe on that branch ref; restore the primary to its default branch with the printed `git -C <root> checkout <default>`, then re-validate that branch in a proper worktree.
This is the only sanctioned firstmate-initiated git write to the primary, and it is a non-destructive branch switch that strands nothing.
- `VAULT_DRIFT: <project>: <vault problem and remedy>` - a project's documentation vault is stale or its declared external location cannot be measured, and the line names the shape and problem because they need different remedies.
An `in-repo vault stale` line is ordinary project work: brief a crewmate to refresh that vault in its own worktree through the project's selected delivery path.
An `external vault stale` line names a vault that lives in a SEPARATE repo, which an isolated project worktree structurally cannot write; dispatch that work against the vault repo's own clone instead, and never tell a crewmate to write the captain's live copy.
An `external vault link absent` or `link broken` line means drift cannot be measured there at all - the exact blindness this check exists to end - so treat restoring the link (or registering the vault repo as its own project) as the fix, and do not read the missing measurement as "the vault is current".
An `external vault target invalid` line means a declared location lacks the OKF marker or a recognized bundle is not backed by a separate Git repository; correct the target or declaration before treating it as a measurable vault.
The check is detection only by design: a vault is curated knowledge, so never auto-write one, and never modify a project clone to silence the line.
- `STARTUP_MEMORY_BUDGET: invalid config/startup-memory-budget - <reason>` - the visible startup-memory budget is not a safe one-line positive decimal file; do not infer the default or propagate it.
Correct the local primary file, then rerun session start so the normal convergence path can deliver the validated value to secondmate homes.
- `CREW_DISPATCH: invalid config/crew-dispatch.json - <reason>` - the optional dispatch profile file exists but failed low-cost bootstrap validation; stop profile-based dispatch, report the actionable error, and require correction of the malformed schema, unverified harness name, or invalid harness/effort pair rather than falling back around it or selecting a bad profile.
- `CREW_DISPATCH: backend mismatch - ...` - the dispatch profile is valid but selects the crew-only, herdr-only `cursor`/`agy` harness while the resolved runtime backend is not herdr, so every matching task would be refused at spawn; either select the herdr backend (`config/backend`) or drop cursor/agy from the dispatch rules, and until then route matching work to a verified harness.
- `FLEET_SYNC: <repo>: skipped: <reason>` - a benign one-off skip (offline, no origin, local-only); bootstrap continued, investigate only if it blocks work.
A skip can also report the bounded fleet-refresh timeout (`FM_FLEET_SYNC_BOOTSTRAP_TIMEOUT`, or a fleet-size-aware default with a 20 second floor); a timeout never blocks startup.
- `FLEET_SYNC: <repo>: recovered: <detail>` - the clone had drifted onto a clean detached HEAD holding no unique commits and the sync self-healed it (re-attached the default branch and fast-forwarded); no action needed, it is reported only so the self-heal is visible.
Expand All @@ -45,6 +52,11 @@ When any diagnostic needs captain attention, report the plain consequence and re
Resume the emitted supervision protocol after finishing the session-start wake handling.
- Any other `PR_CHECK_MIGRATION:` refusal means migration did not complete safely, whether because watcher exclusion, a private path, a diagnostic, quarantine validation, or marker publication could not be proved.
Keep each affected poll unavailable, inspect the named private state path, and do not bypass the migration or execute a quarantined artifact; a completed safe-scan marker allows unrelated authenticated polls to continue while private repair remains pending.
- `ENDPOINT_BINDING_MIGRATION: task <id> (<backend>): <reason>; record left unchanged` - this non-tmux task record lacks its cleanup binding, and the one-shot migration could not verify that the recorded endpoint still belongs to this task, so cleanup will keep refusing it.
This is correct and deliberate: an unproven binding would let cleanup destroy another task's endpoint, so never hand-write the binding, relax `fm_backend_validate_task_endpoint`, or force cleanup past the refusal.
A `gone` reason means the endpoint no longer exists, and a label or identity mismatch means the recorded task identity failed verification.
No work is at risk and supervision, peeking, and steering are unaffected; the task simply cannot be cleaned up.
When the recorded endpoint is live again with the expected task identity, the sweep converges it on the next locked session start with no action; otherwise treat retiring the record as a captain decision.
- `SECONDMATE_SYNC: secondmate <id>: skipped: <reason>` - secondmate convergence left a live home on its existing checkout because the home was dirty, diverged, unsafe, on the wrong branch, missing its placement-specific target commit, unreachable, or otherwise not fast-forwardable, or because inherited local-material propagation failed; bootstrap continued, but inspect the reason because the secondmate's tracked instructions, inherited settings, or shared captain preferences may be stale after a primary update.
- `SECONDMATE_LIVENESS: secondmate <id>: skipped: <reason>|respawn failed after <cause>: <reason>` - the session-start liveness sweep could not guarantee that the registered secondmate is running a real agent process.
Investigate the reason because that secondmate is not guaranteed live.
Expand Down
Loading