feat(bin): add verified Antigravity worker adapter - #3008
Closed
brybrydataguy wants to merge 28 commits into
Closed
brybrydataguy wants to merge 28 commits into
brybrydataguy wants to merge 28 commits into
Conversation
Confidence Score: 5/5The PR appears safe to merge. No blocking failure remains. Reviews (4): Last reviewed commit: "no-mistakes: apply CI fixes" | Re-trigger Greptile |
This was referenced Sep 2, 2026
|
Closed as superseded — this work already landed on main via #4200. — Kun's Firstmate |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Add verified Antigravity CLI (agy) worker adapter support to Firstmate with Gemini 3.7 Flash High default
What Changed
agycrewmate and scout launches with harness detection, isolated busy-state hooks, agemini-3.7-flash-highdefault, and model/effort validation while rejecting unsupported secondmate use.agytransitions.Risk Assessment
✅ Low: Captain, the latest fix preserves and validates the endpoint identity across the active-to-empty transition, covers both scope states without allowing foreign holders, and satisfies the agy adapter and Gemini 3.7 Flash High default intent.
Testing
The focused adapter regression passed, Firstmate spawned agy with Gemini 3.7 Flash High as its persisted default, and the real authenticated agy 1.1.19 CLI successfully completed a request using that exact model.
Evidence: Firstmate agy spawn transcript
Firstmate reported a successful agy worker spawn, persistedmodel=gemini-3.7-flash-high, and generated the autonomous interactive launch command.Evidence: Real Antigravity model smoke
The real agy 1.1.19 catalog listed Gemini 3.7 Flash High, then the model returned the expected smoke response.Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed (5) ✅
bin/fm-task-process-launch.sh:47-scope_agentrelies solely onBASHPID, but Bash 3.2, explicitly supported by the macOS CI lane, does not define it. Under stock/usr/bin/env bash, the background function exits before executing agy, so every scoped ship or scout launch fails after task metadata may already be published. Launch the child through a mechanism that obtains its real PID withoutBASHPID.bin/fm-teardown.sh:2860- Required contract: verified agy worker support. This closes the agy endpoint before the strictlsofproof and non-force worktree safety check at lines 2865 and 2888. A dirty or unlanded task, or a host withoutlsof, therefore loses its agent and terminal before teardown refuses; relaunch then rejects the missing endpoint. The test attests/fm-teardown.test.sh:1560deliberately forbids an earlier git safety read, so changing this challenges deliberate behavior. Recommend a read-only preliminary safety andlsofavailability pass before quiescence, while retaining the post-quiescence checks. This adds duplicate preflight work but keeps refused tasks operable; declining can strand them.🔧 Fix: Preserve agy workers across launches and teardown refusals
1 warning still open:
bin/fm-teardown.sh:2868- The established teardown path proves and removes stale Git locks, but this new agy preflight exits onTEARDOWN_WORKTREE_SAFETY_LOCK_BLOCKEDbefore reaching that recovery. Ifgit statusneeds an index refresh while an old, unheldindex.lockremains, every retry refuses at this branch. Choose between safe automatic stale-lock recovery before quiescence or explicit manual containment instead of promising that retry will work.🔧 Fix: Recover stale agy teardown locks before worker quiescence
1 warning still open:
bin/fm-teardown.sh:1461- The durable stale-lock fix still fails with an actual live agy worker. This pre-quiescence cleanup passes$WTtofm_lock_is_provably_stale, which treats any process holding the worktree directory open as a live lock holder; the agy scope anchor is launched from$WTand remains there until quiescence at line 2878. Consequently, a staleindex.lockplus a live worker refuses on every retry. The new regression test usesmark_agy_scope_empty, so it misses this path. I recommend an identity-bound pre-quiescence proof that excludes the known scope's expected cwd while still rejecting a true lock holder; otherwise document the preserved-worker refusal as manual containment.🔧 Fix: Recover stale locks around verified live agy scopes
1 warning still open:
bin/fm-teardown.sh:1290- The durable recovery still fails on the normal terminal-backed path. The endpoint shell enters$WTbefore launching agy and remains there waiting as the process-scope anchor's parent, but it is outside the recorded scope. Thereforelsof -Fp "$WT"returns that shell PID and this scope-only check rejects it on every retry. The regression starts the sleeper directly and fakes lsof to return only its PID, omitting the real endpoint shell. Another fix round must either identity-bind the verified endpoint shell as an allowed holder or adopt a lock-file-specific proof; the smaller alternative is explicit manual containment. I recommend resolving this at the endpoint or shared lock-ownership boundary, not adding another test-only exemption.🔧 Fix: Bind agy lock recovery to verified endpoints
1 warning still open:
bin/fm-task-process-launch.sh:137- The durable recovery still misses an already-exited agy worker: this transition replaces the active record without retaining its verified endpoint PID and identity. The treehouse endpoint shell remains in$WT, so a staleindex.lockmakes safety preflight see that shell vialsof, whileworktree_lock_has_only_expected_scope_holdersrejects the now-empty scope on every retry. Decide whether empty scopes should retain and validate the endpoint binding at this shared state transition, which I recommend, or explicitly require manual lock removal or--forceafter worker exit.🔧 Fix: Preserve endpoint identity across empty process scopes
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
tests/fm-agy-harness.test.shFocused re-run oftest_agy_default_model_and_launch_templatewith spawn output, task metadata, and generated launch command capturedagy --versionagy modelsagy --dangerously-skip-permissions --model gemini-3.7-flash-high --effort high --print 'Do not call tools or inspect files. Reply with exactly: AGY_GEMINI_3_7_FLASH_HIGH_OK'tests/fm-harness-liveness-drift-live-e2e.test.sh:103- The opt-in real-harness drift guard says every verified adapter belongs in its loop, but it omitsagy. The documented Antigravity liveness claim therefore cannot be refreshed, leaving only stubbed coverage for this vendor-controlled surface. Addagywhile retaining absent-harness and version reporting.🔧 Fix: Align agy adapter documentation
4 errors still open:
tests/fm-harness-liveness-drift-live-e2e.test.sh:103- The real-harness liveness guard promises to check every installed verified adapter but still omitsagy, so Antigravity process-identity drift cannot refresh its documented liveness evidence. Addagywhile retaining absent-harness, version, and non-vacuity reporting.tests/fm-composer-matrix-live-e2e.test.sh:120- The live composer guard promises coverage for every installed verified harness but omitsagy. Add it so Antigravity's vendor-rendered empty composer is checked after upgrades.tests/fm-send-inbox-doorbell-live-e2e.test.sh:189- The live steering guard promises coverage for every installed verified harness, butagyhas neither a launch recipe nor default-loop entry. Add both so real Antigravity workers must receive, act on, and acknowledge durable inbox steers.docs/verification/supervision.md:184- The verification record claims real AntigravityPreInvocation,Stop, and rendered delivery-footer observations, but its linked test only exercises fixtures and no opt-in real-agyrefresh command exists. Add a live guard with version, absence, and non-vacuity reporting, then record its command and bounded output here.🔧 Fix: Consolidate agy documentation ownership
4 errors still open:
tests/fm-harness-liveness-drift-live-e2e.test.sh:103- The real-harness liveness guard still omitsagy, so Antigravity process-identity drift cannot refresh its documented evidence. Addagywhile retaining absence, version, and non-vacuity reporting.tests/fm-composer-matrix-live-e2e.test.sh:120- The live composer guard still omitsagy. Add it so Antigravity's vendor-rendered empty composer is checked after upgrades.tests/fm-send-inbox-doorbell-live-e2e.test.sh:189- The live steering guard still lacks anagylaunch recipe and default-loop entry. Add both so real Antigravity workers must receive, act on, and acknowledge inbox steers.docs/verification/supervision.md:184- The verification record claims real Antigravity lifecycle observations, but only fixture coverage exists. Add an opt-in real-agyguard with version, absence, and non-vacuity reporting, then record its command and bounded output.🔧 Fix: Correct Antigravity verification evidence
4 errors still open:
tests/fm-harness-liveness-drift-live-e2e.test.sh:103- The real-harness liveness guard still omitsagy, so real Antigravity process-identity evidence cannot be refreshed. Addagywhile retaining absence, version, and non-vacuity reporting.tests/fm-composer-matrix-live-e2e.test.sh:120- The live composer guard still omitsagy. Add it so Antigravity's vendor-rendered empty composer is checked after upgrades.tests/fm-send-inbox-doorbell-live-e2e.test.sh:189- The live doorbell guard still lacks anagylaunch recipe and default-loop entry. Add both so real Antigravity workers must receive, act on, and acknowledge inbox steers.docs/verification/supervision.md:201- Only synthetic fixture coverage exists for agy's lifecycle hooks and delivery footer. Add an opt-in real-agy guard with version, absence, and non-vacuity reporting, then record its bounded output.🔧 Fix: Document Antigravity verification limits
4 errors still open:
tests/fm-harness-liveness-drift-live-e2e.test.sh:103- The real-harness liveness guard still omitsagy, so Antigravity process-identity evidence cannot be refreshed. Addagywhile retaining absence, version, and non-vacuity reporting.tests/fm-composer-matrix-live-e2e.test.sh:120- The live composer guard still omitsagy. Add it so Antigravity's vendor-rendered empty composer is checked after upgrades.tests/fm-send-inbox-doorbell-live-e2e.test.sh:189- The live doorbell guard still lacks anagylaunch recipe and default-loop entry. Add both so real Antigravity workers must receive, act on, and acknowledge inbox steers.docs/verification/supervision.md:201- Only synthetic fixture coverage exists for agy's lifecycle hooks and delivery footer. Add an opt-in real-agy guard with version, absence, and non-vacuity reporting, then record its bounded output.✅ **Push** - passed
✅ No issues found.