Conversation
Contributor
Author
|
Closing in favor of #5591, a fresh and smaller fix for defect A of #1506 against current main. This branch fell far behind main, and its rewrite of |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Publish the captain-approved local fix for defect A of #1506. The change must stop absent TMUX_PANE from becoming the fabricated firstmate:0 target, identify the real non-tmux Ghostty operator session from stable existing session-lock process and controlling-TTY evidence, preserve strict composer identity by refusing a plain TTY as an injectable endpoint, report blind discovery as explicit UNVERIFIED rather than confidently absent, and make refused/unavailable delivery observable through a durable marker, stderr, and an independent configured alarm path with firing and negative controls. The pull request body must reference #1506 and clearly say it fixes defect A: fabricated operator-session identity silently disabling away-mode escalation delivery. Push only to the configured coreldh/firstmate fork, open exactly one PR against kunchenguid/firstmate:main, and do not merge, self-approve, force-push, comment on the issue, or contact the maintainer.
What Changed
Risk Assessment
✅ Low: Captain, the change cleanly replaces the fabricated fallback with fail-closed discovery and covers the required refusal, marker, and alarm paths.
Testing
Reviewed the target diff, ran the focused daemon and away-launch tests, and captured a direct blind-discovery CLI refusal artifact; the required fail-closed delivery path works end-to-end, while the optional Herdr topology E2E is not verifiable in this shared environment because its lab-session tripwire failed.
Evidence: Blind-delivery refusal CLI transcript
Evidence: Focused daemon test log
Evidence: Focused launcher test log
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
tests/fm-afk-launch.test.sh- The optional Herdr topology E2E could not prepare its isolated lab because the shared Herdr environment failed its required default-session tripwire. The tmux topology E2E and the targeted Ghostty-shaped delivery-preflight controls completed; this worktree-local test phase cannot safely alter shared Herdr state.git diff --stat b5d430d6fdcd961ce9b681bf196f365c1825c284 cb8711e4bc5397a21b1a993e0c33e1af6f38f7f2and targeted source/test inspectionbash tests/fm-daemon.test.sh(focused supervisor discovery, Ghostty lock/TTY identity, strict composer refusal, delivery-unavailable marker/alarm controls)bash tests/fm-afk-launch.test.sh(focused launch preflight firing and negative controls; tmux topology E2E)Direct end-user CLI check:bin/fm-afk-start.shwith TMUX/Herdr and supervisor overrides empty plus a configured command alarm; captured refusal, durable marker, alarm output, and absent away flag✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.