Skip to content

fix(bin): prioritize active pipeline-owned crew runs - #3194

Merged
kunchenguid merged 2 commits into
mainfrom
fm/fm-startup-pr0-f10-crewstate-attribution-r1
Aug 27, 2026
Merged

kunchenguid merged 2 commits into
mainfrom
fm/fm-startup-pr0-f10-crewstate-attribution-r1

Conversation

@kunchenguid

Copy link
Copy Markdown
Owner

Intent

PR0 of the captain-approved Firstmate startup/Bearings redesign: the F10 crew-state run-attribution precedence HOTFIX, which ships first ahead of the rest of the staged plan (implement ONLY PR0; PR1-PR4 and parallel fixes are explicitly out of scope, and the home-summary invalidity model must NOT change in this PR - that is later follow-up; the hotfix alone stops the cascade's trigger). Problem (confirmed live): bin/fm-crew-state.sh binds a superseded FAILED no-mistakes run to a task instead of the LIVE replacement run, because the live run's pipeline-owned lane head is not a git object in the task worktree: fm_nm_head_matches_worktree rejects it, then the coarse fallback nm_runs_status_for_branch continues past the RUNNING row (head unresolvable) onto the older FAILED row whose head equals the stale worktree HEAD. Observed on task fm-actionable-update-escalation-misclassification-r1: failed run at d0bde839 chosen over the running run at a pipeline-owned head; the home summary then flips valid=false (terminal_in_flight) and Bearings hides the home's live work. Required precedence: (1) a daemon-attributed ACTIVE run for the task's branch (from axi status in the worktree, matching branch name) is AUTHORITATIVE - head equality is NOT required while branch_sync.state is pipeline_owned; report working with the run-step detail. (2) Otherwise the newest terminal run for the branch that no later run supersedes surfaces its terminal state; a genuinely-failed run with NO later run on the branch MUST still report failed - hiding real failures is equally wrong. (3) An unresolvable run head classifies as unknown attribution and must NEVER cause a silent fallback onto an older row; in the coarse no-mistakes runs scan, an ACTIVE row for this branch whose head cannot be resolved must not be skipped in favor of an older terminal row. (4) Scope is bin/fm-crew-state.sh plus bin/fm-nm-run-lib.sh only for genuinely needed helpers. Implementation decisions made deliberately: the new attribution helpers (fm_nm_head_resolvable, fm_nm_branch_sync_state, fm_nm_run_is_active, fm_nm_run_is_pipeline_owned_active) live in bin/fm-nm-run-lib.sh because that lib is the declared single owner of the run-attribution rule (one-owner rule from firstmate-coding-guidelines); the pipeline_owned exemption deliberately requires an ACTIVE run (a terminal run has released the branch, and binding one by branch name alone would recreate the historical reused-branch misattribution the head rule prevents); the coarse-scan guard stops on ANY unresolvable head for the task's branch (unknown attribution) while a resolvable-but-mismatched head keeps the existing historical reused-branch skip semantics; fm-teardown.sh's stricter head-equality use of the lib is deliberately unchanged in this PR. Acceptance tests (T1, both directions, required): fixture worktree at head H1 on branch B with a PATH-stubbed no-mistakes whose axi status answers a RUNNING run on B at unresolvable head H2 with branch_sync.state pipeline_owned and whose runs list shows newest running-B-H2 and older failed-B-H1 must report working with source run-step; the same fixture where the stub reports ONLY failed B H1 (no later run) must still report failed; existing crew-state tests stay green; tests exercise observable behavior through the real fm-crew-state.sh entrypoint with a PATH-stubbed no-mistakes, never implementation-string matching. The test fixture's branch_sync TOON shape was copied from the live incident run's real axi status output, and every fixture head is deliberately unresolvable so only the pipeline-owned exemption can attribute (guarding against accidental field grabs). Two extra negative-control tests pin that the exemption requires branch_sync.state=pipeline_owned specifically and never applies to a terminal run. All tests were verified to fail before the fix and pass after it.

What Changed

  • Attribute active pipeline_owned no-mistakes runs by branch without requiring their lane head to resolve in the task worktree.
  • Stop coarse run scans at an unresolvable newer head instead of falling through to a superseded terminal run, while preserving genuine terminal failures.
  • Add entrypoint regression coverage and update run-attribution documentation.

Risk Assessment

✅ Low: The change is narrowly scoped, preserves terminal-run attribution, and adds behavioral regression coverage for the pipeline-owned precedence and coarse-scan guard.

Testing

After inspecting the clean target diff, I ran the focused crew-state behavior suite, reproduced the original base-commit misattribution, and exercised the real CLI entrypoint end-to-end: an active pipeline-owned run now reports working despite an unresolvable head and older failed row, while a genuine unsuperseded failure still reports failed.

Evidence: F10 fixed behavior: active pipeline-owned run wins, genuine failure remains visible

Source: F10 fixed behavior: active pipeline-owned run wins, genuine failure remains visible

F10 end-to-end evidence (real bin/fm-crew-state.sh entrypoint, PATH-stubbed no-mistakes)
Scenario 1: newest ACTIVE pipeline-owned run has an unresolvable lane head; older row is failed at the worktree head.
state: working · source: run-step · validating (running)
Scenario 2: only the genuine failed run remains on the branch at the worktree head.
state: failed · source: run-step · run failed
Evidence: Base-commit regression reproduction: older failed run incorrectly surfaced

Source: Base-commit regression reproduction: older failed run incorrectly surfaced

Regression reproduction against base commit 4f89f5b (same real entrypoint logic, PATH-stubbed no-mistakes):
Newest row is ACTIVE pipeline-owned at an unresolvable head; older row is failed at the worktree head.
state: failed · source: run-step · run failed

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

✅ **Test** - passed

✅ No issues found.

  • Inspected the target diff and confirmed the worktree remained clean with git status --short.
  • Ran the focused behavior suite: tests/fm-crew-state.test.sh.
  • Executed bin/fm-crew-state.sh end-to-end with a PATH-stubbed no-mistakes for both required precedence directions and captured the CLI transcript.
  • Executed the base commit's crew-state logic against the live-run/older-failure fixture to reproduce the original false failed result.
  • Checked changed files for patch whitespace errors with git diff --check 4f89f5b5e235469d32c037b7792d6dba5bdc272d..002b0f98cd8e447f988059750b134d8e6f6cb000 -- bin/fm-crew-state.sh bin/fm-nm-run-lib.sh tests/fm-crew-state.test.sh.
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

kunchenguid added 2 commits August 27, 2026 14:26
…iled row

fm-crew-state.sh bound a superseded FAILED no-mistakes run to a task instead
of the LIVE replacement run: the live run's pipeline-owned lane head is not a
git object in the task worktree, so head-equality attribution rejected it and
the coarse runs-list fallback silently continued past the RUNNING row onto an
older failed row whose head equalled the stale worktree HEAD. The home summary
then flipped invalid and Bearings hid the home's live work (F10).

Attribution precedence now follows the daemon's own identity:
- An ACTIVE run for the task's branch binds without head equality while
  branch_sync.state is pipeline_owned (fm_nm_run_is_pipeline_owned_active);
  the pipeline owning the branch is itself the attribution.
- A genuinely failed run with no later run on the branch still reports failed
  through the unchanged head-equality path - real failures are not hidden.
- In the coarse runs scan, an unresolvable head is unknown attribution and
  stops the scan (fm_nm_head_resolvable) instead of falling through to an
  older row; a resolvable-but-mismatched head keeps the historical
  reused-branch skip.

The exemption never applies to a terminal run and requires pipeline_owned
specifically, both pinned by negative-control tests. Fixture shape verified
against the live incident run's real axi status output.
@greptile-apps

ghost commented Aug 27, 2026

Copy link
Copy Markdown

Confidence Score: 5/5

The PR appears safe to merge with no actionable defects identified.

The changed attribution path is narrowly gated to active pipeline-owned same-branch runs, preserves strict terminal attribution, and has behavioral coverage for both precedence directions and negative controls.

Reviews (1): Last reviewed commit: "no-mistakes(document): Updated run-attri..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant