fix: restore numeric helper library - #2271
Closed
JTInventory wants to merge 86 commits into
Closed
JTInventory wants to merge 86 commits into
JTInventory wants to merge 86 commits into
Conversation
Adopt upstream baseline and active watcher fix
feat: adopt deterministic route resolver
* feat(cognee): add local lookup manifest checker * feat(cognee): verify local source hints
* fix: harden Cognee policy and shell lint * no-mistakes(review): Captain, harden Cognee supervision checks * no-mistakes(document): Sync Cognee policy docs * no-mistakes(review): Treat stale CI checks as failures * no-mistakes(document): Sync Cognee and supervision docs * ci: run shell tests with bash
* feat(x-mode): add X mention completion follow-ups (kunchenguid#113) * feat(x-mode): X-mention completion follow-up flow Acknowledge an actionable X mention first, do the work, then post one follow-up reply when it completes. - fm-x-reply.sh: add --followup mode posting to the relay's /connector/followup endpoint; reuses thread-split, payload shape, dry-run (with a self-describing endpoint marker), and never-inline safety. Answer path unchanged. - fm-x-link.sh: link a spawned task to its originating mention via x_request/x_request_ts in state/<id>.meta (atomic, preserves other lines). - fm-x-followup.sh: --check detection plus post-and-clear on terminal completion; honors the 24h window (skip+prune past it), keeps the link on a failed post for retry. - fm-x-lib.sh: shared meta link get/set/clear helpers. - Docs: fmx-respond reads as one ack-first -> act -> follow-up flow; AGENTS.md §14 + supervision pointer document the link, completion follow-up, and 24h public-safe window. - Tests: cover --followup endpoint/payload/dry-run, link, and the followup helper; shellcheck clean. * no-mistakes(review): Captain, fix atomic X meta rewrites * no-mistakes(document): Document X completion follow-ups * feat(x-mode): dismiss skipped X mentions through the relay (kunchenguid#120) * feat(x-mode): dismiss skipped mentions at the relay The relay now exposes POST /connector/dismiss: acknowledge a pending mention without replying - it drops the request, posts nothing, and stops re-offering it. Wire firstmate to use it on the skip path so a deliberately unanswered mention no longer churns every poll and times out to the relay's "offline" auto-reply. - bin/fm-x-dismiss.sh: new client modeled on fm-x-reply.sh. POSTs {request_id} (no body) to /connector/dismiss with the bearer; echoes the request_id on 2xx, exits non-zero on non-2xx/transport failure. Honors FMX_DRY_RUN (records the would-be POST to state/x-outbox/ with an endpoint:"dismiss" marker, posts nothing) and rejects unsafe request_ids. - fmx-respond skill: the skip path now calls bin/fm-x-dismiss.sh before clearing the inbox file; answer and follow-up paths unchanged. - AGENTS.md section 14: documents that a skipped mention is dismissed at the relay, not just locally cleared. - tests: dismiss posts {request_id} to /connector/dismiss with the bearer and echoes it; dry-run records and posts nothing; non-2xx and transport failures exit non-zero; unsafe id and bad args rejected. * chore(no-mistakes): run the bash suite directly as the test step The test step had no configured test command, so it delegated to an agent; that agent-driven run crashed the no-mistakes daemon mid-step on this repo. Configure commands.test to run the firstmate behavior suite deterministically instead, mirroring .github/workflows/ci.yml: iterate every tests/*.test.sh, run each, and fail the step if any exits non-zero. This removes the agent from the test step entirely (no crash) and makes the gate's test baseline match CI. Same pattern myfirstmate uses (commands.test: mix deps.get && mix test). * no-mistakes(review): Fix X dismiss docs and gate preflight * no-mistakes(document): Document X dismiss and gate tests * feat(watcher): absorb wakes only when the crew is provably working (kunchenguid#126) * feat(watcher): absorb wakes only when the crew is provably working The no-verb triage path (a bare turn-end, a working: note, a non-terminal stale) used to be benign by default and surfaced only on a captain-relevant status verb. A crew that finished but reported through interactive pane menus (no done: status) had its final turn-end absorbed, so firstmate was never woken and the finish was missed. Invert the rule: absorb a no-verb turn-end or non-terminal stale ONLY when the crew shows positive evidence it is still working - its no-mistakes run for its branch is in an actively-running step, or its pane shows the harness busy signature. Otherwise surface it so firstmate peeks (done, waiting, or wedged). - fm-classify-lib.sh: add crew_is_provably_working (reuses fm-crew-state.sh, no run-step duplication) and signal_crew_provably_working; FM_CREW_STATE_BIN override for tests. - fm-watch.sh: signal path surfaces a no-verb wake whose crew is not provably working (costly check runs only on the no-verb, non-afk path); non-terminal stale surfaces immediately when not provably working, else absorbs with the wedge timer (run-step read only on first sight of a stale hash). - afk path unchanged: the watcher stays one-shot and skips the provably-working read; the daemon keeps its bounded-latency stale backstop. - tests: cover every required semantic (mid-pipeline absorb, finished/parked surface, no-running-pipeline idle surface, busy absorb, captain-verb surface) as classifier unit tests and behavioral watcher runs; queue-safety test for the new immediate-surface stale path. - AGENTS.md section 8: document absorb-only-when-provably-working. * no-mistakes(document): Sync watcher documentation * feat: add grok crewmate harness support (kunchenguid#143) * feat(harness): add grok (Grok Build) as a verified crewmate adapter Empirically verified against grok 0.2.73 and encoded across the machinery: - fm-harness.sh: detect grok via GROK_AGENT=1 env marker (grok does not set CLAUDECODE) and `grok` command-name ancestry. - fm-spawn.sh: grok launch template (`grok --always-approve "$(cat BRIEF)"`, fully autonomous, no permission gate) and a turn-end Stop hook. grok only loads project hooks after a manual folder-trust grant, so the hook is a single firstmate-owned global hook (~/.grok/hooks/fm-turn-end.json, always trusted) that is a guarded no-op unless the workspace holds a per-task .fm-grok-turnend pointer; fm-spawn drops that gitignored pointer naming state/<id>.turn-ended. Hook stays outside the worktree, needs no trust grant. - fm-watch.sh + fm-tmux-lib.sh: grok busy signature `Ctrl+c:cancel` (the mid-turn cancel hint; ASCII, present iff a turn runs). - harness-adapters skill: grok facts section (busy, exit=Ctrl+Q x2, interrupt=Ctrl+C, skill invocation /<skill>, resume) and /no-mistakes form. Gating question confirmed: grok invokes /no-mistakes and drives a real no-mistakes axi run, so grok is usable for no-mistakes-mode tasks. End-to-end verified through fm-spawn: autonomous launch past the dir picker into the worktree, brief processed, busy->idle and turn-end signal detected, fm-send steer lands, clean Ctrl+Q exit and teardown. config/crew-harness is left unchanged; this only makes grok available as a verified option. * no-mistakes(review): Captain, harden Grok hook lifecycle * no-mistakes(review): Captain, make Grok harness test executable * no-mistakes(review): Captain, bound Grok pointer reads * no-mistakes(test): Captain, harden crew-state and watcher-lock timing * no-mistakes(document): Document Grok harness support * feat(harness): split secondmate harness configuration (kunchenguid#144) * feat(harness): split secondmate harness and inherit primary config into secondmate homes Add config/secondmate-harness so secondmates can run on a different adapter than crewmates. fm-harness.sh gains a `secondmate` mode resolving the chain config/secondmate-harness -> config/crew-harness -> own; `crew` mode is unchanged. fm-spawn resolves a --secondmate launch through that mode (durable: every respawn re-resolves), while an explicit per-spawn harness arg still wins and the unverified-adapter guard still holds. Add a generic, extensible inheritable-config mechanism (fm-config-inherit-lib.sh) that pushes the primary's declared LOCAL config into each secondmate home's config/ at secondmate spawn and on the bootstrap secondmate sweep. Exactly one item is wired today: config/crew-harness, so a secondmate's own crewmates use the primary's setting. Primary-authoritative (re-pushed every convergence, mirrors absence); config/secondmate-harness is deliberately not inherited since secondmates never spawn secondmates. config/ is gitignored, so this is a copy separate from the tracked-files fast-forward. Update AGENTS.md (layout, bootstrap, harness, spawn), the harness-adapters skill, docs/scripts.md, and .gitignore. New tests cover secondmate resolution and fallback, spawn/respawn honoring config/secondmate-harness, config propagation on spawn and sweep, the unverified-adapter guard, and backward compatibility. * no-mistakes(review): Surface inherited config propagation failures * no-mistakes(review): Harden inherited config propagation * no-mistakes(review): Document literal harness inheritance requirement * no-mistakes(document): Document secondmate harness config * feat(backlog): default backlog operations to tasks-axi (kunchenguid#145) * feat(backlog): default to tasks-axi backend * no-mistakes(document): Sync backlog backend docs * fix(spawn): set per-task GOTMPDIR so interrupted Go builds don't leak /tmp (#36) * fix(spawn): set per-task GOTMPDIR so interrupted Go builds don't leak /tmp Go's GOTMPDIR is unset, so every go build/test creates numbered /tmp/go-build* dirs. Go cleans them on a clean exit but LEAVES THEM when interrupted (signal, timeout, OOM, full disk), accumulating and filling the disk over time. Give each task its own temp root at /tmp/fm-<id>/ with Go's build temp nested at gotmp/. fm-spawn creates the dir (Go won't mkdir GOTMPDIR), exports GOTMPDIR into the crewmate pane so the agent and child processes inherit it, and records tasktmp= in meta. fm-teardown reads tasktmp= and removes the whole root on cleanup, deterministically. GOTMPDIR (not TMPDIR) is the targeted knob: TMPDIR is too broad (affects every program's temp). The nested root is extensible: other per-task temp can live under /tmp/fm-<id>/ later. Backward compat: tasks spawned before this change have no tasktmp= in meta; teardown tolerates the empty value as a no-op. The daily fm-disk-cleanup.sh cron remains a safety net for any pre-fix stray dirs. * fix(tests): silence SC2016 for literal grep -F patterns in fm-gotmp test The structural grep -F assertions deliberately match literal $TASK_TMP in the fm-spawn source; add per-line shellcheck disable=SC2016 (the codebase's existing pattern, e.g. bin/fm-spawn.sh) so CI lint passes. * no-mistakes(document): docs: document tasktmp= meta field for per-task GOTMPDIR --------- Co-authored-by: e-jung <8334081+e-jung@users.noreply.github.com> * fix: accept landed squash-merged PR heads (kunchenguid#149) * fix(teardown): accept landed squash-merge PR heads * no-mistakes(document): Document teardown landing behavior * no-mistakes: apply CI fixes * fix(test): pass explicit teardown git identity * feat(dispatch): add dynamic crew profiles (kunchenguid#154) * feat(dispatch): add dynamic crew profiles * no-mistakes(review): Captain, document dispatch profile inheritance * no-mistakes(review): Captain, guard stale dispatch inheritance * no-mistakes(document): Sync dispatch profile docs * no-mistakes: apply CI fixes * fix: harden crew dispatch profile enforcement (kunchenguid#159) * Harden crew dispatch profile enforcement * no-mistakes(document): Captain, synced crew dispatch docs * feat: add live secondmate config push (kunchenguid#161) * feat(config): add live secondmate config push * no-mistakes(document): Document config push behavior * no-mistakes(lint): Clean changed shell lint * no-mistakes: apply CI fixes * feat: support image attachments in X replies (kunchenguid#162) * feat(x): add image attachments to reply helpers * no-mistakes(review): Stream X image replies safely * no-mistakes(review): Captain, clean X reply temp tracking * no-mistakes(document): Document X reply image support * Harden cleanup and image payload limits * no-mistakes(review): Captain, validate spawn task IDs * no-mistakes(document): Document X image cap --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: e-jung <e-jung@users.noreply.github.com> Co-authored-by: e-jung <8334081+e-jung@users.noreply.github.com>
* fix: settle codex secondmate sends before submit * no-mistakes(document): Sync fm-send docs * chore: refresh no-mistakes checks * no-mistakes(document): Document codex secondmate settle path
* Guard no-mistakes CI monitor gh compatibility * no-mistakes(document): Document gh checks compatibility
* fix: guard firstmate no-mistakes pr target * no-mistakes(review): Check every PR target URL * no-mistakes(review): Captain, verify no-mistakes remote targets * no-mistakes(review): Fail closed on targetless local gates * no-mistakes(review): Captain, pin PR target guard * no-mistakes(document): Document PR target guard
* fix: retry codex secondmate submit after pending * no-mistakes(document): Document fm-send retry behavior
* test(afk): wait on injection events * no-mistakes(review): Stabilize AFK duplicate waits * no-mistakes(review): Captain, stabilize AFK wait clocks * no-mistakes(document): Document AFK injection test waits
* feat: add durable secondmate profile defaults * no-mistakes(document): Sync secondmate profile docs
* fix(supervision): detach watcher from reaped arms * Fix detached watcher follower ownership * Harden legacy watcher cleanup and stop handling * Fix watcher regression lint * Harden watcher health and stop races * Harden legacy cleanup and lock compatibility * Fail closed on legacy watcher cleanup * Wait for detached target exec before returning * Require post-exec detached watcher identity * fix(supervision): scope legacy follower ownership * fix(supervision): fail closed on unpinned watcher stop * fix(supervision): clean detached spawn failures * fix(supervision): harden detached spawn cleanup * fix(supervision): return failed detach pid * fix(supervision): pin timeout cleanup identity early * no-mistakes(test): Captain: fix wake-queue fixture with pid-start proof
* feat: ship Phase A upstream safety train * no-mistakes(review): Captain: remove bypass; checks pass; PR receipt blocked * no-mistakes(review): Captain: gate, runner, Grok fixes pass; PR receipt unavailable * no-mistakes(review): Captain: fix gate, lock, runner; PR receipt blocked * no-mistakes(review): Captain: gate-lock fixes pass; trusted config and PR blocked * no-mistakes(review): Captain: lock signature fixed; trusted config and PR blocked * no-mistakes(document): Refresh docs and clear shell lint warnings * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes
* feat: harden secondmate routing and spawn containment * no-mistakes(review): Harden turn-end guard and ignore secondmate markers * no-mistakes(review): Widen no-jq stop payload parsing safely * no-mistakes(review): Restrict fallback parser to JSON whitespace * no-mistakes(review): Reject multi-document stop payloads * no-mistakes(review): Reject duplicate stop-hook keys * no-mistakes(test): Fix watcher test concurrency races * no-mistakes(document): Captain: refreshed stale spawn docs and cleared lint * no-mistakes(review): Hardened no-jq key parsing and added regression coverage * no-mistakes(review): Rejected NUL-tainted guard input before JSON parsing * no-mistakes(review): Rejected invalid UTF-8 before no-jq JSON parsing * no-mistakes(review): Removed iconv dependency from jq-less UTF-8 validation * no-mistakes(test): Fix AFK e2e startup race * no-mistakes(document): Captain: refreshed stale docs; changed-file ShellCheck passes
* feat: adopt paused gate absorb and AFK detach * no-mistakes(review): Captain: fixed pause-gate scope and AFK return state * no-mistakes(review): Captain: fixed pause gate and AFK return safety * no-mistakes(review): Captain: guarded stale AFK records with absence proof * no-mistakes(review): Captain: fail-closed AFK status now proves daemon absence * no-mistakes(review): Captain: hardened AFK transitions and lock-safe cleanup * no-mistakes(review): Captain: serialized AFK transitions against replacement races * no-mistakes(review): Bounded AFK transition lock acquisition * no-mistakes(review): Preserve contention status during AFK lock handoff * no-mistakes(review): Retry AFK lock handoffs as bounded contention * no-mistakes(document): Fixed stale AFK docs and ShellCheck findings
* feat: add selective operator comfort tools * no-mistakes(review): Captain fixed review findings; focused verification passes * no-mistakes(document): Captain: refreshed Phase D docs and lint inventory
* feat: extract tmux session-provider backend * no-mistakes(review): Refuse force teardown for unsupported child backends * no-mistakes(review): Propagate backend failures and preserve watcher supervision * no-mistakes(review): Fail closed teardown and verify session creation attempts * no-mistakes(review): Order teardown safely, handle absent windows, hermeticize GOTMP tests * no-mistakes(review): Add teardown kill-failure state regression coverage * no-mistakes(review): Exercise teardown kill failures with real worktree ownership * no-mistakes(document): Document runtime backend abstraction * no-mistakes(lint): Captain: fix ShellCheck assignment warnings
* feat: add experimental herdr session backend * no-mistakes(review): Harden Herdr teardown, isolation, guards, and supervision * no-mistakes(review): Harden Herdr cleanup, locking, submission, and supervision health * no-mistakes(review): Harden Herdr validation, locks, cleanup, and submission * no-mistakes(review): Harden Herdr acknowledgements, session health, locks, and version gating * no-mistakes(review): Recover legacy locks and validate Herdr session health * no-mistakes(review): Harden legacy lock recovery without PID start identity * no-mistakes(review): Preserve live legacy locks lacking start identity * no-mistakes(review): Fail closed on ambiguous legacy workspace locks * no-mistakes(document): Refresh Herdr backend documentation * no-mistakes: apply CI fixes
* feat: support Herdr AFK supervisor injection * no-mistakes(review): Fixed Herdr target resolution and backend-aware AFK rechecks * no-mistakes(document): Document Herdr AFK supervisor support
* feat: deepen experimental Herdr adapter * no-mistakes(review): Fixed all four Herdr review findings * no-mistakes(review): Route Herdr socket discovery through explicit sessions * no-mistakes(review): Close created tabs on Herdr post-create failures * no-mistakes(review): Fail closed on malformed Herdr tab cleanup * no-mistakes(review): Fail closed on unobserved malformed Herdr tabs * no-mistakes(review): Protect live tabs and verify Herdr workspace rollback * no-mistakes(review): Rollback malformed Herdr workspace creations safely * no-mistakes(test): Update stale AFK defer assertion * no-mistakes(document): Stale Herdr documentation corrected * no-mistakes(lint): Captain: export Herdr event capability marker
* test: add Herdr real-lab e2e coverage * no-mistakes(review): Hardened Herdr E2E cleanup, isolation, and inventory assertions * no-mistakes(document): Document opt-in Herdr lab coverage * no-mistakes(lint): Captain: quote Herdr lab ID to clear SC2100
* fix(tests): scrub ambient Herdr env in hermetic behavior suite Running behavior tests from a live Herdr pane exported HERDR_ENV=1, so secondmate fixtures auto-selected the herdr backend and created real 2ndmate-* workspaces on the captain default session. Scrub ambient HERDR_* markers in the suite runner and tests/lib.sh, pin hermetic FM_BACKEND=tmux, and document the isolation contract. * no-mistakes(review): Fixed Herdr isolation and ambient opt-in handling * no-mistakes(document): Captain: clarified Herdr test isolation documentation * no-mistakes(lint): Fix ShellCheck SC1007 empty FM_BACKEND assignments
* feat(herdr): add readable task tab labels * no-mistakes(review): Harden Herdr label recovery and spawn serialization * no-mistakes(review): Harden Herdr crash recovery and label reservations * no-mistakes(review): Fix secondmate recovery and backlog title parsing * no-mistakes(review): Complete Herdr recovery and backlog title parsing * no-mistakes(review): Prioritize label recovery and clean Done titles * no-mistakes(review): Validate legacy Herdr recovery labels * no-mistakes(review): Block newline-forged Herdr recovery rows * no-mistakes(review): Harden encoded Herdr inventory parsing * no-mistakes(review): Assert empty Herdr inventory success * no-mistakes(review): Document Herdr display and machine identity * no-mistakes(document): Align Herdr label documentation ownership * no-mistakes(lint): Captain, fix ShellCheck local variable declaration
#77) * feat(herdr): add optional presentation spaces (kunchenguid#784) * feat(herdr): add optional presentation spaces * no-mistakes(review): Harden Herdr projection creation and spawn serialization * no-mistakes(review): Captain, disarm Herdr cleanup before launch submission * no-mistakes(test): Correct stale Orca metadata failure fixture * no-mistakes(document): Document Herdr presentation projection accurately * feat(herdr): order presentation spaces while preserving focus (kunchenguid#790) * feat(herdr): order presentation worker spaces * fix(herdr): preserve focus during projected cleanup * no-mistakes(review): Serialize Herdr cleanup and protect active seeded tabs * no-mistakes(review): Serialize Herdr aborts with guarded focus regressions * no-mistakes(review): Fall back flat when Herdr serialization is unavailable * no-mistakes(test): Stabilize watcher startup and AFK handoff tests * no-mistakes(document): Correct Herdr ordering and focus documentation * fix(herdr): group projected children beneath owning parents (kunchenguid#821) * feat(herdr): correct all-home child presentation topology Inherit the presentation opt-in to secondmate homes, label new projected spaces with the approved corner format, insert each child under its owning parent under one session-scoped lock, and keep flat non-destructive fallback. * no-mistakes(review): Exclude secondmates from Herdr presentation projection * no-mistakes(review): Harden shared Herdr locks and ambiguous child ordering * no-mistakes(review): Use adjacency-only Herdr child ownership * no-mistakes(review): Reject foreign legacy projections safely * no-mistakes(review): Validate Herdr session sockets before projection * no-mistakes(test): Fix Herdr teardown fixture session socket metadata * fix(herdr): canonicalize presentation lock socket paths Always resolve the session socket parent directory so symlink parents such as /tmp -> /private/tmp cannot split the shared cross-home lock identity. Refuse relative socket paths. Clarify lock-unavailable warnings. * no-mistakes(test): Fix Bash-compatible GitLab merge request URL parsing * no-mistakes(document): Document all-home Herdr child topology * no-mistakes(lint): Quote fallback provenance string for ShellCheck * feat: require pinned real-Herdr CI coverage (kunchenguid#838) * feat: add required pinned Herdr CI lane Install exact Herdr 0.7.4 and Treehouse 2.0.1 with official assets and SHA-256 pins, run the real-herdr-gated family serially through fm-test-run with hard-fail on herdr-not-found, and keep portable Behavior free of claimed Herdr coverage. * no-mistakes(document): Consolidate real-Herdr CI documentation ownership * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix(herdr): reclaim resumed task projections after restart (kunchenguid#967) * fix(herdr): reclaim resumed task projections safely * no-mistakes(review): Enforce safe Herdr reclaim close boundaries * no-mistakes(document): docs: clarify Herdr restart projection contract * fix(herdr): clean stale projections at session start (kunchenguid#996) * Clean stale Herdr projections at session start * no-mistakes(document): Document stale Herdr session-start projection cleanup * no-mistakes(review): Enforce locked exact Herdr projection cleanup * no-mistakes(review): Fail closed on unverified session lock ownership * no-mistakes(review): Serialize session lock acquisition atomically * no-mistakes(document): Align session-start and Herdr cleanup documentation * no-mistakes(document): Generalize lock-refusal diagnostics * no-mistakes(lint): Avoid reserved keyword in concurrency test * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix(send): treat opencode busy-queued composer state as submitted (kunchenguid#775) * fix(send): treat opencode busy-queued composer state as submitted When fm-send sends a message to a BUSY opencode crewmate on the tmux backend, opencode accepts the Enter and queues the message for the next turn, but leaves the typed text visible in the composer row. The submit-verification loop sees a pending composer, exhausts retries, and reports a false "Enter swallowed" failure while the message is actually delivered. Fix: after Enter retries are exhausted and the composer still shows pending, check fm_pane_is_busy. If the pane is busy (agent mid-turn, footer shows "esc interrupt"), the harness queued the message, so return "empty" (accepted). On an idle pane, keep returning "pending" (genuine swallow detection preserved). Regression tests cover four scenarios: - busy pane + pending composer -> empty (message queued) - idle pane + pending composer -> pending (genuine swallow) - busy pane + composer clears on first Enter -> empty - idle pane + composer clears on first Enter -> empty (existing path) * docs: document busy-queued Enter exception across backend docs and skills Add explanatory comments and backend documentation for the busy-queued Enter fix (opencode 1.18.4 accepts Enter mid-turn but keeps typed text in composer until the turn ends): - bin/fm-tmux-lib.sh: document the busy-aware fallback in the file header and above fm_tmux_submit_enter_core - .agents/skills/afk/SKILL.md: daemon-facing policy note - .agents/skills/harness-adapters/SKILL.md: harness-specific fact - docs/tmux-backend.md: submit-acknowledgement section with the busy-queue exception - docs/herdr-backend.md: record the known gap - docs/architecture.md: cross-reference in the daemon section * test(tmux): fix SC2181 and make busy-submit test executable * fix: prevent AFK idle stalls and stale run attribution (kunchenguid#758) * fix(supervision): verb-aware captain relevance, AFK wedge, head-bound state Stop free-text tokens like "merged" from promoting nonterminal working: lines to captain-relevant, so AFK no longer permanently suppresses idle recovery. Defend wedge aging independently for nonterminal progress verbs, bind no-mistakes current-state attribution to code identity (not branch alone), and mark setup-complete as nonterminal in the ship brief scaffold. * no-mistakes(review): Enforce nonterminal suppression and head-bound run attribution * no-mistakes(document): Document current-code-bound run attribution * no-mistakes(test): Wait for stable Herdr shell readiness * no-mistakes(test): Make Herdr and watcher readiness tests deterministic * no-mistakes(test): Make tmux capture and watcher lifecycle deterministic * no-mistakes(document): Document corrected supervision contracts * fix(herdr): preserve fork labels across upstream reliability series * fix(bin): send literal config reread nudges after pushes (kunchenguid#809) * Send literal config reread after inherited config push When declared inherited config changes under an already-running secondmate, build a per-home instruction from validated destination post-write bytes and deliver it on the routed secondmate path. Unchanged config sends nothing; ABSENT represents removal; captain-shared is never inlined. Covers mid-session config-push and the locked bootstrap convergence path without hardening spawn against deliberate runtime choice. * no-mistakes(review): Fix config reread framing, partial propagation, and respawn order * no-mistakes(review): Send config rereads via durable single-line pointers * no-mistakes(review): Make failed config rereads retryable * no-mistakes(review): Make config reread retries generation-safe * no-mistakes(review): Make config rereads durable and ordered * no-mistakes(review): Drain retries, bound history, preserve detect-only read-only mode * no-mistakes(review): Retain write retries and quarantine stale respawn generations * no-mistakes(review): Preserve exact config reread retries and delivery order * no-mistakes(review): Preserve exact retry bytes and bounded quarantine pruning * no-mistakes(document): Consolidated config-reread documentation * fix(herdr): reconcile upstream reliability with fork contracts * no-mistakes(review): Harden Herdr lifecycle and real-CI coverage * no-mistakes(review): Harden Herdr lifecycle, delivery, and CI contracts * no-mistakes(review): Harden Herdr lifecycle, inheritance, and CI * no-mistakes(review): Harden Herdr recovery, teardown, and inheritance contracts * no-mistakes(review): Harden Herdr send and lifecycle uncertainty handling * no-mistakes(review): Harden Herdr mutation and teardown failure handling * no-mistakes(review): Enforce Herdr identity and truthful pending verdicts * no-mistakes(review): Implement truthful Herdr final Enter submission * no-mistakes(review): Harden Herdr final Enter ownership verification * no-mistakes(review): Require idle proof for Herdr final Enter * no-mistakes(review): Order Herdr ownership before idle proof * no-mistakes(test): Restore flat Herdr spawning without presentation locks * no-mistakes(document): Correct Herdr documentation and proof references * no-mistakes(document): Isolate Herdr routing test from gate refusal * no-mistakes(lint): Remove unused Herdr lint variables * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Kostadin Pop-Kochev <kostadin.popkocev@gmail.com> Co-authored-by: jjames27th-eng <jjames27th@gmail.com>
* fix: execute every PR body compliance event * no-mistakes(review): Captain: make compliance replay hermetic
* fix(watch): retire merged PR polls after durable notification (kunchenguid#932) * fix: retire merged PR polls after notification * no-mistakes(review): Decouple PR retirement recovery from template updates * no-mistakes(review): Recover pending PR retirements before poll migration * no-mistakes(document): Document merged PR poll retirement contracts * no-mistakes(review): Preserve legacy custom checks through secure migration * no-mistakes(review): Protect reserved X watcher identity during migration * no-mistakes(test): Captain, fix watcher migration lock diagnostics * no-mistakes(test): Synchronize watcher singleton test on heartbeat * no-mistakes(document): Clarify legacy watcher check migration documentation --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com>
* feat: guard against missed secondmate reports * no-mistakes(review): Harden secondmate pending-reply lifecycle * no-mistakes(review): Preserve pending replies through forced teardown * no-mistakes(review): Make forced retirement failure-safe * no-mistakes(review): Bind retirement handoffs to source state * no-mistakes(review): Promote resolved history before receipt cleanup * no-mistakes(review): Serialize pending-reply handoff transactions * no-mistakes(review): Harden pending-reply transaction recovery * no-mistakes(review): Harden pending-reply takeover and finalization * no-mistakes(review): Harden pending-reply ownership and handoff retries * no-mistakes(review): Drain legacy locks and require explicit correlation reuse * no-mistakes(review): Enforce watcher restart barrier for legacy locks * no-mistakes(review): Enforce verified watcher protocol migration * no-mistakes(review): Harden watcher migration and pending-reply protocol gates * no-mistakes(review): Harden watcher migration and replay update obligations * no-mistakes(review): Make update obligations durable and explicitly acknowledged * no-mistakes(review): Make update obligations generation-safe across protocol migration * no-mistakes(review): Make update obligation claims atomic and replayable * no-mistakes(review): Make update obligations immutable and crash-safe * no-mistakes(review): Keep ancestor update acknowledgements replayable * no-mistakes(review): Preserve future legacy update obligations * no-mistakes(review): Recover future-only obligations on first retry * no-mistakes(test): Fix pending-reply teardown test fixtures * no-mistakes(document): Document Phase 2 secondmate resilience * no-mistakes(lint): Fix ShellCheck warnings in secondmate resilience scripts * no-mistakes: apply CI fixes
* fix: release Codex session locks cleanly Track Codex locks by stable thread identity so isolated tool calls preserve ownership and matching SessionEnd hooks release only their own home's lock. Preserve Grok precedence, legacy numeric owners, and JT's existing PreToolUse hook. * no-mistakes(review): Fix Codex session-lock lifecycle compatibility * no-mistakes(document): Document Codex session-lock lifecycle ownership * no-mistakes: apply CI fixes
* fix: refine scout intake and parallel dispatch * no-mistakes(review): Fix intake authority and direct-PR reconciliation contracts * no-mistakes(review): Teach direct-PR briefs to reconcile parallel conflicts * no-mistakes(review): Harden direct-PR rebase and completion workflow * no-mistakes(review): Fetch authoritative refs for direct-PR reconciliation * no-mistakes(review): Bind direct-PR pushes to fetched feature OIDs * no-mistakes(review): Block divergent direct-PR feature histories * no-mistakes(review): Preserve direct-PR lease state across retries * no-mistakes(review): Persist direct-PR lease checkpoints across recovery * no-mistakes(review): Bind direct-PR recovery to validated task state * no-mistakes(review): Make direct-PR rebase transitions safely recoverable * no-mistakes(review): Bind direct-PR recovery to immutable refs * no-mistakes(review): Harden direct-PR completed and active rebase recovery * no-mistakes(review): Harden direct-PR proof and retry handling * no-mistakes(review): Bind direct-PR recovery to complete publication workflow * no-mistakes(review): Harden direct-PR checkpoint hydration and workflow routing * no-mistakes(review): Make direct-PR recovery fresh-shell and phase safe * no-mistakes(review): Make direct-PR retry exhaustion durable across recovery * no-mistakes(review): Complete direct-PR atomic checkpoint transition contracts * no-mistakes(review): Captain, harden direct-PR recovery, cleanup, and authorization tests * no-mistakes(review): Captain, harden published direct-PR recovery and reconciliation * no-mistakes(review): Bind direct-PR recovery to durable remote identity * no-mistakes(review): Bind direct-PR operations to validated push endpoint * no-mistakes(review): Isolate direct-PR refs and activate reconciliation handoff * no-mistakes(review): Bind direct-PR receipts and retire private refs * no-mistakes(review): Captain, integrate recoverable receipts and atomic cleanup * no-mistakes(review): Guard direct-PR artifact generation replacement * fix: make guarded PR replacement recoverable * test: cover guarded PR replacement crashes * test: restore PR recovery CI fixtures
* feat: add shared idea evaluation scope contracts * no-mistakes(review): Captain, harden scope-contract advisory ledger handling * no-mistakes(document): Document scope marker enforcement
* feat: bind PR approval to presented head * no-mistakes(review): Bind merge approvals to serialized PR presentations * no-mistakes(review): Bind merge approvals to immutable presentation identity * no-mistakes(review): Harden merge leases and presentation compatibility * no-mistakes(review): Bound post-merge branch deletion execution * no-mistakes(review): Harden portable branch deletion timeouts * no-mistakes(review): Synchronize Perl timeout process supervision * no-mistakes(document): Document hardened PR presentation and scope ledger * fix: make PR merge parsing lint-clean * no-mistakes(review): Harden Markdown fence parsing * no-mistakes(review): Require contiguous scope ledger tables * no-mistakes(review): Require valid GFM table separators * no-mistakes(review): Reject scope ledgers inside raw HTML * no-mistakes(review): Harden inline HTML comment parsing * no-mistakes(document): Document exact-head approval and convergence controls * no-mistakes: apply CI fixes
* fix(supervision): bind stale recovery to task state Adapt owner PR kunchenguid#758 onto current JT main without replaying its mixed history. Preserve the already-landed AFK wedge fix, make nonterminal suppression override-safe, bind no-mistakes state to compatible HEAD ancestry, and protect multi-stage working gates. Source commits: 80e4b9c, fad734e, 4ddb731. * no-mistakes(test): Bind CI-ready fixture to worktree HEAD * no-mistakes(document): Align supervision docs with current-state contracts * no-mistakes(review): Captain, preserve terminal escalation and compatible run attribution * no-mistakes(review): Captain, preserve legacy signals with custom vocabulary * no-mistakes(test): Wait for watcher readiness before legacy lock migration * no-mistakes(document): Document additive captain relevance overrides * no-mistakes(lint): Quote terminal status token for ShellCheck
* fix(supervision): reserve Grok watcher follower for background arm * no-mistakes(review): Clarified Grok badge provenance; added restart refusal coverage * no-mistakes(document): Document Grok watcher follower ownership
* fix: fleet-sync follows branch upstream on controlled forks Prefer the local default branch's configured upstream (e.g. fork/main) as the sync base instead of hardcoding origin/<default>. Controlled-fork homes keep origin fetching the upstream owner while main tracks fork; comparing only to origin/main false-STUCK a delivery-current clone. Also fetch the delivery remote when it differs from origin. * no-mistakes(review): Refresh fork upstream before fleet sync; focused tests pass * no-mistakes(review): Align fetch remote with resolved base; prune after refresh * no-mistakes(review): Separate upstream refs, refresh branches, and budget bootstrap * no-mistakes(review): Avoid origin refetches and force-update delivery refs * no-mistakes(document): Document fleet-sync delivery-base behavior, captain --------- Co-authored-by: tests <tests@example.invalid>
* fix: treat passed runs with skipped delivery as unlanded * no-mistakes(document): Document skipped-delivery passed-run semantics --------- Co-authored-by: tests <tests@example.invalid>
* fix: isolate task workers and pooled slots * fix: hold task worktrees on durable leases Keep each ordinary task's Treehouse slot leased after worker exit so only ownership-gated teardown can return it. This prevents stale ownership stamps from being exposed on a prematurely recycled pooled slot. * fix: fail closed on isolated worker slot ownership * no-mistakes(review): Fixed fail-closed isolation teardown, rollback, and bootstrap gating * no-mistakes(review): Fixed transactional slot ownership and fail-closed session isolation * no-mistakes(review): Hardened lease provenance and fail-closed slot teardown * no-mistakes(review): Hardened serialized pooled-slot teardown and return recovery * no-mistakes(review): Fix slot-return brick, unresolved leases, and scoped isolation gate * no-mistakes(review): Make failed-return and unresolved-lease recovery paths reachable * no-mistakes(test): Fix teardown slot gating and stale S1 isolation test fixtures * no-mistakes(test): Make watcher test bounds load-tolerant and scrub harness marker * no-mistakes(test): Run watcher-timing behavior tests in a serial phase * no-mistakes(test): Run Herdr lab e2e tests in the serial phase * no-mistakes(review): Fix spawn cleanup set -e abort, sweep diagnostics, and lock spin * no-mistakes(review): Hardened selected S1 worker and slot isolation findings * no-mistakes(review): Hardened residual isolation and semantic workflow tests * no-mistakes(review): Hardened override, sweep, census, and contract isolation checks * no-mistakes(review): Closed pending-reply, process-identity, and census gaps * no-mistakes(review): Closed unproven spawn and worker identity paths * no-mistakes(review): Hardened markerless worker and watcher entrypoint isolation * no-mistakes(review): Refused markerless workers without authoritative primary proof * no-mistakes(review): Restored primary proof and cross-home ownership checks * no-mistakes(review): Hardened primary ancestry and complete pooled-home discovery * no-mistakes(review): Closed forgeable primary, registry, and update guard paths * no-mistakes(review): Seeded complete census for clean isolation slot fixture * no-mistakes(review): Hardened endpoint occupancy against PID reuse * no-mistakes(document): S1 worker-isolation documentation corrected * no-mistakes(review): Fixed fail-closed process scan and ancestry proof; regressions pass * no-mistakes(review): Hardened worker, scan, and pooled-slot ownership gates * no-mistakes(review): Preserved post-close retained-lease recovery verdict * no-mistakes(review): Replaced source-only checks with runtime regressions * no-mistakes(review): Strengthened registry and workspace lookup regressions * no-mistakes(review): Removed redundant source-only workflow contract test * no-mistakes(review): Hardened isolation and verified spawn cleanup lifecycles * no-mistakes(review): Hardened ownership locks, worker guards, and test runner * no-mistakes(review): Hardened secondmate provenance and spawn cleanup * no-mistakes(review): Hardened parent locks and primary provenance guards * no-mistakes(review): Hardened primary provenance, teardown identity, and skip detection * no-mistakes(review): Hardened primary attestation, nested locks, and artifact ownership * no-mistakes(review): Hardened primary bootstrap and worker ownership proofs * no-mistakes(review): Hardened S1 bootstrap attestation and NUL-safe process identity * no-mistakes(review): Hardened primary bootstrap and watcher attestation replay checks * no-mistakes(review): Hardened session-bound isolation and proof coverage * no-mistakes(review): Add fail-closed portable process-environment fallback * no-mistakes(review): Explicitly gate process identity proof to Linux procfs * no-mistakes(review): Fix PID-less endpoint occupancy teardown proof * no-mistakes(review): Require complete task PID index for marker proof * no-mistakes(review): Treat empty environments as complete scans * no-mistakes(review): Harden hook ownership and process-proof efficiency * no-mistakes(review): Preserve Grok hooks and validate current ownership snapshots * no-mistakes(review): Make Grok hook provisioning transactional and symlink-safe * no-mistakes(review): Harden Grok rollback and teardown ownership * no-mistakes(review): Harden spawn rollback and teardown ownership * no-mistakes(review): Harden spawn rollback and teardown ownership * no-mistakes(review): Harden hook ownership recovery * no-mistakes(review): Harden recovery ownership and retry safety * no-mistakes(review): Harden lease recovery and child endpoint identity * no-mistakes(review): Harden unresolved cleanup and endpoint identity * no-mistakes(review): Harden unresolved endpoint retirement and stable-ID coverage * no-mistakes(review): Harden retry recovery and endpoint ownership proofs * no-mistakes(review): Preserve ambiguity and census child homes * no-mistakes(review): Record tmux endpoint ownership before setup * no-mistakes(review): Harden slot stamp publication safely * no-mistakes(review): Harden stamp publication and remove prose-only test * no-mistakes(review): Guard live Herdr teardown with exact endpoint identity * no-mistakes(review): Harden lease recovery and endpoint ownership * no-mistakes(review): Hardened spawn and Herdr teardown ownership * no-mistakes(review): Harden Herdr close and secondmate recovery * no-mistakes(review): Harden Herdr close and secondmate recovery * no-mistakes(review): Restore lock-bound Herdr teardown close * no-mistakes(review): Add Herdr session fixture and identity refusal coverage * no-mistakes(review): Harden lease recovery and Herdr teardown ownership * no-mistakes(review): Harden Herdr close, recovery IDs, and temp cleanup * no-mistakes(review): Harden Herdr close and tmux recovery uncertainty * no-mistakes(review): Bind Herdr teardown and preserve endpoint recovery * no-mistakes(review): Hardened Herdr close and pending tmux recovery * no-mistakes(review): Hardened S1 ownership and focused recovery validation * no-mistakes(review): Hardened Herdr cleanup and slot scan fail-closed * no-mistakes(review): Retain on malformed pooled-slot metadata * no-mistakes(review): Implement atomic expected-PID Herdr close gating * no-mistakes(review): Hardened focused S1 ownership and Herdr cleanup * no-mistakes(review): Hardened Herdr abort cleanup and seeded-tab ownership * no-mistakes(review): Hardened Herdr teardown and focused slot ownership * no-mistakes(review): Hardened seeded pruning and exact Herdr cleanup * no-mistakes(review): Hardened Herdr ownership and narrowed S1 validation scope * no-mistakes(review): Closed markerless bypass, removed S4 path, narrowed S1 CI * no-mistakes(review): Require attestation before lock acquisition; isolate bootstrap * no-mistakes(review): Validated attestations before lock; narrowed configured S1 tests * no-mistakes(review): Hardened S1 ownership and narrowed out-of-scope surfaces * no-mistakes(review): Focused teardown now reaches fixture bootstrap but returns code 3; I’m isolating that harness mismatch * no-mistakes(test): Fix stable endpoint recovery status handling * test: make worker isolation CI fixtures portable * test: isolate platform-specific process fixtures * fix: support slot census on stock bash * test: guard procfs-only isolation fixtures * test: tolerate incomplete stale-endpoint census * test: make watcher harness fixtures deterministic * test: make teardown harness fixtures deterministic * fix: clear shellcheck warnings in isolation gates * test: isolate teardown return retry fixture * test: stabilize focused teardown slot returns --------- Co-authored-by: tests <tests@example.invalid>
JTInventory
force-pushed
the
fm/firstmate-fix-numeric-lib-0812
branch
from
August 12, 2026 15:55
9338beb to
fb01f25
Compare
Author
|
Closing without merge. This was an accidental upstream twin. The real ship is JTInventory#92. Not a merge target. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Restore bin/fm-numeric-lib.sh that was accidentally deleted by the S1 isolation squash merge (JT PR #91 / merge commit 3921e3a). Recover the exact pre-#91 implementation of fm_nonnegative_integer_or_default from cc7718c or equivalent history. Ensure fm-crew-state.sh has no missing-library or helper errors on a live task or dry fixture, and bash -n bin/fm-numeric-lib.sh bin/fm-crew-state.sh passes. Keep this to the minimal one-file restore with no S1 isolation rework or behavior change beyond restoring the deleted helper. Deliver through no-mistakes to JTInventory/firstmate on branch fm/firstmate-fix-numeric-lib-0812; update PR JTInventory#92 with the Pipeline body marker; do not merge and do not target kunchenguid.
What Changed
bin/fm-numeric-lib.shand its shared non-negative-integer default helper.bin/, with related CI and pipeline workflow updates.Risk Assessment
✅ Low: The target commit restores one non-executable library with the exact pre-#91 blob, matching the existing fm-crew-state.sh callers without additional behavior changes.
Testing
Exercised syntax, focused behavior, end-user CLI output, helper edge cases, captured reviewer-visible evidence, and final worktree hygiene; no actionable failures or missing evidence were found.
Evidence: fm-crew-state CLI transcript
state: working · source: run-step · validating (running) stderr: <empty>Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
⏭️ **Rebase** - skipped
.agents/skills/afk/SKILL.md- branch carries 85 commit(s) that exist on your local main branch but were never pushed to origin/main; rebasing would bundle this unrelated work (408 file(s)) into the PR:Push main to origin, or rebase your branch onto origin/main, before gating.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
bash -n bin/fm-numeric-lib.sh bin/fm-crew-state.shbash tests/fm-crew-state.test.shManual dry-fixture execution ofbin/fm-crew-state.sh live-fixturewith a throwaway git worktree and fake backendsDirect execution offm_nonnegative_integer_or_defaultwith valid, over-limit, and invalid inputsgit status --short --branchand target diff cleanliness check⏭️ **Document** - skipped
Step was skipped.
✅ **Push** - passed
✅ No issues found.