feat: act on captain's away words during AFK supervision - #5076
Merged
Merged
Conversation
Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words.
dscott98
added a commit
to dscott98/firstmate
that referenced
this pull request
Sep 21, 2026
* fix(bin): preserve Claude lock ownership after helper recycling (kunchenguid#4894) * fix(bin): let a background Claude session keep owning its session lock Session-lock ownership was decided by process ancestry alone. Under an unattended Claude session the model loop runs in a transient bg-spare bridged to the front-end by a shared daemon; when that bridge is recycled the contiguous claude-named ancestry from a hook to the recorded owner breaks while the owner pid stays alive, so the Stop auto-arm stood down as a foreign live owner, the turn-end guard ended every turn with its read-only diagnostic, and fm-lock.sh refused - a self-sustaining outage until restart. Ownership is now ancestry membership OR a trusted same-session id, never id-first: - fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when CLAUDE_PID is a Claude-shaped member of the current contiguous run, compares it against the id recorded in state/.lock-session, and requires the recorded pid to still be a live harness. No id, no sidecar, an untrusted id, a different id, or a dead recorded pid leaves the ancestry verdict unchanged. Ids are never read from ps argv. - fm-lock.sh accepts a same-session holder at both refusal sites, writes, refreshes, and clears the sidecar only under its claim lock (including the early already-mine exit, skipped only while the deferred startup sweep leases that lock), keeps it byte-identical across a same-session confirmation, records CLAUDE_PID on lock line 1 for a session with a trusted id so a shared daemon or front-end that outlives the session never keeps a dead session's lock alive, never rewrites a live line 1 on a same-session confirmation, and names the recorded id in the live-owner refusal. - The .lock line-1 format is unchanged, so every reader that takes the whole first line as the pid keeps working; the guard's foreign-owner exit is unchanged and inherits the fix through the shared predicate. Tests: the ancestry suite drives the ancestry and id signals apart in a deterministic process table (asserting the divergence) and runs a real orphaned front-end/daemon/pty-host/spare tree through six phases with the real lock, auto-arm, and guard scripts; the foreign-owner repro keeps its negative control and adds a same-id positive control. Disclosure: no live unattended Claude background session ran on the verifying machine. The topology is documented by the real process listings in kunchenguid#3902, kunchenguid#2314, kunchenguid#3398, and kunchenguid#4066; coverage is the structural predicate plus the executable fixtures, not a live pass. Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry walk (it only decides whether to print a nudge) and may nudge on a resume in the recycled case. Out of scope, deliberately: no structured lock format, no guard budget changes, no daemon-identity rejection, no fork lineage. * no-mistakes(review): Wait for claim lock; revert failed sidecars * no-mistakes(review): Revalidate ownership after wait; restore sidecars * no-mistakes(review): Roll back sidecar by publication phase * no-mistakes(review): Restore sidecar only if lock line is unchanged * no-mistakes(review): Trust session ids without a spelling allowlist * no-mistakes(review): Disarm sidecar rollback before backup cleanup * no-mistakes(document): Updated session-lock ownership documentation * feat: park main under the away posture on Pi (kunchenguid#4889) * feat: park main under the away posture on Pi While the away-posture record exists on a Pi primary, the supervision branch takes every actionable wake, no processing turn opens on main, captain rows accumulate for the return brief, and main's standing authority relocates to the branch through the existing guarded scripts. - lib/fm-branch-dispatch.ts: read the record at every routing decision; while it exists claim check, decision-owned, and heartbeat rows too, keeping the two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task scoping. - fm-primary-pi-watch.ts: offer every actionable row under the record; a declined wake and every watcher-failure alarm still reach main. - fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no processing request while the record exists, re-checked immediately before a request would open and at every run boundary; present the accumulated rows at the first run boundary after archive. - fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in actions only while fm-afk-contract.sh validate succeeds on a confirmed live record; PR merge, fresh spawn, and decision answer opt in, local landing never does. - fm-send.sh: a --resolve-key naming an open needs-decision or captain-held task is a decision answer and meets the partition; blocked: keys stay steering. - fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by either actor; relaunches and secondmates exempt. - fm-branch-prompt.sh: fixed Postures section and the verbatim ask-user-authority policy; the prefix stays byte-stable. - fm-afk-return.sh: count what the away session handled from the store. - docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate absolute while away. - tests: watcher and branch extension suites, fleet-record, merge, and decision-answer suites cover the relocation, the vetoes, the tail, the parked processing turn, the cancellation, the re-presentation, and the spend cap; dated live-guard evidence recorded. * no-mistakes(review): Refuse branch merge after preflight archive race * no-mistakes(review): Fix away wake, spawn, and processing races * no-mistakes(review): Suppress parked processing; narrow away-only rejection * no-mistakes(review): Abort dedicated processing; gate branch spawn once * no-mistakes(review): Stamp away-only on the dispatch offer * no-mistakes(review): Treat invalid away records as spend-cap absence * no-mistakes(review): Drop spawn test hook; abort processing-opened runs * no-mistakes(review): Bind abort to opening prompt; cap-read absence * no-mistakes(review): Limit away branch spawn to queued work only * no-mistakes(document): Correct AFK posture documentation * ci: standardize workflow timeouts into three tiers (kunchenguid#4910) * ci: simplify CI job timeouts to a three-tier policy Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m serial, 10m macOS) with three readable tiers, each a hang tripwire with headroom rather than a packing estimate: - fast (5m): coverage guard, repo invariants, timing aggregate - normal (30m, one shared budget): lint partitions, portable parallel shards, portable serial shards, macOS stock Bash - heavy (Herdr only): 20m step tripwire on the family run so always() cleanup still runs, under a 75m job-level last-resort backstop The workflow's header comment states the policy and points at docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh asserts the policy against the parsed workflow instead of the old per-job minute values: every job joins exactly one tier, exactly three distinct job-level values exist, the fast tier stays within 5-10 minutes, the normal budget stays at least double the modeled parallel lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step tripwire stays below its job backstop with an always() cleanup after it. Concurrency supersession, shard counts, lane membership, and fail-fast settings are unchanged. * no-mistakes(review): Decouple the normal timeout from packing estimates * no-mistakes(review): Assert Herdr teardown follows the family run * no-mistakes(review): Pin Herdr family-run timeout to 20 minutes * no-mistakes(review): Ignore comments when identifying Herdr steps * no-mistakes(review): Identify Herdr steps by declarative ids * no-mistakes(document): Clarify authoritative three-tier timeout policy * fix(bin): keep supervisor status closes from waking the same home (kunchenguid#4895) * fix(bin): keep supervisor status closes from waking the same home A drain that already folded OPEN DECISIONS has presented those bytes even when the watcher has no matching seen marker. Treat that fold, and the presentation cursor, as known so the bookkeeping close stays quiet while later worker lines still signal. * no-mistakes(review): Keep folded worker failures waking past supervisor closes * no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes * no-mistakes(review): Stop folded worker resolved lines from counting as already read * no-mistakes(document): Correct self-announced close marker contract in docs * fix(bin): stop labeling Herdr as experimental (kunchenguid#4972) * Stop steering operators away from Herdr * no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording * fix(bin): treat a live no-mistakes run as current after rebase (kunchenguid#4973) * fix(bin): treat a live no-mistakes run as current after rebase A running run on the task's branch is authoritative regardless of head. Matching only the local head made a rebased in-flight run look failed. * no-mistakes(review): restrict coarse live-any-head to foreign-branch answers * no-mistakes(review): reject gate-parked runs from the executing predicate * no-mistakes(review): hoist gate-marker patterns into single run-lib owner * no-mistakes(review): require live daemon for head-free run binding * no-mistakes(review): require answered daemon-down before unbinding live runs * no-mistakes(review): extend daemon guard to anchored continuation routes * no-mistakes(review): delete live-any-head; restore dead-daemon verdict * no-mistakes(review): keep parked gates parked; name dead daemon everywhere * no-mistakes(review): set dead-daemon verdict instead of emitting early * no-mistakes(review): align selected route with legacy dead-daemon handling * no-mistakes(review): drop unproven-record binds; narrow coarse gate reading * no-mistakes(review): narrow header, drop vestigial guard, retarget tests * no-mistakes(review): revert coarse gate override; require answered-down probe * no-mistakes(review): cache one daemon probe; stop duplicating run id * no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows * no-mistakes(review): delete coarse dead-daemon extension and gate note * no-mistakes(review): delete remaining coarse dead-daemon block and stale docs * no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict * fix(bin): prevent long worker launch command truncation (kunchenguid#4994) * fix(bin): stage the launch command in a private file and type a short source line A long launch line typed while the fresh pane shell is still busy waits in the terminal's canonical line buffer, which drops input past about 1,024 bytes on macOS, so the pane was left at an unfinished command with no agent running. fm-spawn now writes the assembled command to the task's own temp root under umask 077 and types only a short line that sources it. Refs kunchenguid#4559 * fix(bin): keep the per-task temp root private before staging the launch command The root lives at a predictable path under /tmp and now holds the whole launch command. Create it with mode 0700, refuse one that already exists as anything but a directory owned by this user that nobody else can write, and tighten an owned one, so no other local user can plant or swap the staged file. Refs kunchenguid#4559 * fix(bin): enforce private staged launch file mode * test(spawn): cover long staged Claude launches * no-mistakes(review): Namespace launch files and prove truncation staging * no-mistakes(review): Use immutable per-spawn launch filenames * no-mistakes(document): Document staged launch delivery safeguards * no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass --------- Co-authored-by: Vytautas Stankus <svycka@gmail.com> * test: authorize isolated Herdr lab validation (kunchenguid#4998) * Add isolated Herdr runbook to test instructions * no-mistakes(review): Drop substring matching from test.instructions contract * no-mistakes(review): Assert commands.test key absence in YAML * Drop unit-first sentence and instructions contract test Captain-scoped follow-up on the Herdr-lab test.instructions ship: keep the lab safety runbook only, and leave the no-mistakes contract test focused on commands.test absence. * docs(vision): accept vendor-semantics and 9k AGENTS ceiling (kunchenguid#4873) (kunchenguid#5001) * docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (kunchenguid#4873) Replace the pixels-of-today's-UI rule with a quarantined, version-pinned surface-adapter exception recorded as standing debt. Cap the always-loaded contract at 9,000 words and require prune-or-trigger before a crossing change lands. Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> * docs(vision): restore accepted three-sentence vendor-semantics form (kunchenguid#4873) Replace the compressed paraphrase with the issue's accepted wording: a named quarantined version-pinned adapter, expected to break, recorded as standing debt that never hardens into a shared contract. Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> * feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (kunchenguid#4974) * fix(watch): recheck a gate awaiting a human instead of wedge-escalating it A lane whose validation run is parked at a gate waiting on a human decision is correctly quiet, but nothing in its status line says so: the evidence is the pipeline's own gate state rather than anything the worker wrote. The wedge timer read that silence as a suspected wedge and climbed the escalation ladder for as long as the wait lasted, and each escalation cost a supervising turn. The landed declared-wait consult does not reach it, because a live ordinary crewmate never reports a declared pause, and raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for every lane by the same amount. The threshold now reads a second, independent record when the status line accounts for nothing: whether the crew's current state is a gate whose answer is owed by a human. That is minted only from the gate's own findings table, by a row whose `action` column is exactly `ask-user`, located by position out of the table header the way nm_gate_step_row already reads its row - never searched for over the run payload, where a finding's free-text description or a branch name satisfies a search just as well. A gate awaiting the CREWMATE's own answer keeps the unchanged escalation schedule, reason and demand-deep-inspection wording, because a crewmate that goes quiet before answering its own gate is exactly the wedge the ladder exists to catch. Each kind of wait now carries the human it is on, the action that clears it, and whether that human is the captain as data alongside the verdict, rather than as wording chosen per branch where the recheck is written, so the deferral cannot word one kind of wait as another and a new kind cannot ship without deciding all of them. A parked gate has no written record of when its wait began, so its recheck publishes no wait age at all rather than one read from the quiet window this deferral resets on every pass, which would report the same small number for a gate of any age. Like every other captain-facing recheck here it is absorbed in silence while the away-posture record exists, arming no throttle, so the recheck is owed in full the moment the record is archived. The consult runs only in the at-threshold branch that was about to escalate, beside the worktree walk already there, and only for lanes whose status line explained nothing. Closes kunchenguid#3055 * no-mistakes(review): require an unanswered decision before deferring a parked gate * no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records * test(watch): pass the pane hash wedge_timer_check now takes Upstream gave wedge_timer_check a sixth <pane-hash> argument for its dead-record probe. The malformed-wait-record rounds drive the real function directly, so they pass one, and stub fm_backend_agent_state to a live agent so the probe that runs after a refused deferral keeps the unchanged ladder rather than reading a backend the child shell has none of. * no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate * no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling * feat(watch): make the parked-gate wait deferral opt-in The wedge timer deferring a lane parked at a validation gate is new supervision behaviour rather than a restored one, and it decides which lanes give up the escalation ladder, so it now ships as a default-off per-home option instead of changing every home on upgrade. config/wedge-defer-parked-gate arms it. The flag is read before the decision fold, so an unconfigured home spends no fold or current-state read, writes no record, and keeps the unchanged escalation schedule, reasons and demand-deep-inspection wording; a test counts the reader calls in both directions to pin that. It is not inherited by secondmate homes: each home supervises its own crew and owns that trade separately, the same reason config/turnend-churn-absorb is home-local. The away-posture absorb returns to leaving the idle timer alone, which it had restarted only because the costly consult could reach it. A parked-gate wait is owed to the supervisor rather than the captain, so it never enters that branch, and the recheck owed on return is again owed in full the moment the record is archived. * test(watch): pin that the away-silenced hold leaves the idle timer alone The absorb no longer restarts the timer, so the recheck owed on return is owed in full rather than a cadence into the return. Nothing asserted that, so a restart could be reintroduced silently. * no-mistakes(review): document away-silence rationale, pin captured gate component * no-mistakes(test): anchor gate row scan to the braced findings header * no-mistakes(document): pin same-block gate row invariant in crew-state comment * fix(bin): reclaim a task whose herdr endpoint was destroyed (kunchenguid#5007) * fix(control): let the owning seat reclaim a task whose endpoint is gone A destroyed pane or workspace made `missing` a terminal state. Relaunch accepted only `dead` and said to stop the agent first; exit refused `missing` and said to reconcile the task first; there is no reconcile verb. Each command named the other as its prerequisite, so a task whose terminal went away could not be reclaimed by anything, and a no-mistakes approval it was parked on had no seat left to answer it. `missing` is agent-free a fortiori: there is no endpoint, so there is no agent in it. Widen the existing guards rather than add a verb. - fm-spawn --relaunch accepts a positively proven `missing` and creates one fresh endpoint in the recorded worktree; the record it already republishes rebinds the task to it. A `dead` endpoint is still adopted in place. - fm-control exit reports `endpoint-gone` instead of dying, so the relaunch transaction's stop step no longer dead-ends, and re-resolves the endpoint from the record before verifying the replacement. The duplicate-agent refusal is untouched: both verdicts come from the same recovery-grade classifier, which claims `missing` only from positive absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The backends' own create paths refuse a live same-labeled endpoint as a second independent guard. The worktree, its branch, commits, uncommitted changes, armed poll and registration, record rows, and status log are all untouched - a reclaim is a recovery, never a teardown. A secondmate is excluded: its gone-endpoint recovery already has one owner in the session-start liveness sweep, so relaunch refuses and names it rather than becoming a second path to the same outcome. Tests reproduce both halves of the deadlock, the reclaim succeeding, unlanded work surviving it, and the refusals that still hold. * no-mistakes(review): prove endpoint absence per backend before reclaim rebinds * no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session * no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly * no-mistakes(review): stop refusals and docs asserting unestablished causes * no-mistakes(review): stop herdr fixture helper losing tmp-root registration * no-mistakes(review): document workspace drift and absence-probe server residue * no-mistakes(review): correct rebind limitation to its one reachable case * no-mistakes(review): stop claiming reclaim leaves instructions untouched * no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage * no-mistakes(rebase): read the staged launch file in the herdr fixture Rebasing onto main picked up kunchenguid#4994, which stages a long worker launch command into a script and delivers the short `. '<path>'` line instead of the literal command. The tmux fake and tests/fixtures.sh were updated for that; the herdr fake this branch adds was written before it and still keyed "an agent now exists on this pane" off the literal `encode launch-brief` text, so after the rebase it never marked the rebound pane live and the reclaim's alive-wait read `dead`. Dereference the staged file first, exactly as the tmux fake above does. Test-fixture only; no production path changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(document): note reclaim placement in herdr and scripts inventories --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(bin): stamp status events with their emission time (kunchenguid#3764) * test(status): reproduce missing event emission time * wip(status): preserve optional event emission time * test(status): document indirect clock stub invocation * no-mistakes(review): Preserve historical status bytes during reply recovery * no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies * no-mistakes(review): Preserve captain regex overrides for timestamped status events * no-mistakes(document): Clarify status event timing and publication contracts * no-mistakes(lint): Quote literal done to satisfy ShellCheck * no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed * no-mistakes(test): Preserve terminal notifications with malformed timestamp tags * no-mistakes(test): Stamp Rovo spawn failures with emission time * no-mistakes(document): Verify status event documentation * no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests * no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed * no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed * no-mistakes(review): Stamp remote escalations at call sites, drop new flag * no-mistakes(review): Accept stamped escalation and close lines in test assertions * no-mistakes(review): Restore reserved-key answered-note guard for stamped closes * test(status): accept optional emission time in PR-provenance assertions The kunchenguid#4148 provenance test landed on main with exact unstamped greps. Parent-channel lines from this branch carry [at=<epoch>], so strip only that tag before the same exact match. No production change. * no-mistakes(review): Accept stamped ready signal in PR fallback scrape * no-mistakes(review): Drop relay flag, stamp parent events at call sites * no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture * no-mistakes(review): Accept optional stamp in live cmux drift guard * no-mistakes(review): Restore original test invocation order in two suites * no-mistakes(review): Strip only well-formed numeric status time tags * no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc * no-mistakes(review): Stamp agy spawn-failure status lines with event time * fix(bin): normalize status event times in-shell and freeze the budget test clock Two paths made a status event's emission time cost more than it should. The captain-relevance fallback piped every line through awk to drop a well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a fork per line just to prepare a regex match. Shell parameter expansion does the same strip with no fork, and the retry-dedup scan now reuses that one helper instead of carrying a second copy of the rule in awk. The copies had already drifted: the shell side stripped tags from lines with no colon, which the awk rule left whole, so a colonless line could be mistaken for one already recorded. One definition, checked against the awk rule it replaces over the edge cases and a 4000-line fuzz. tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In hang mode the poll set DEADLINE to the real now plus a one-second budget, and when the second ticked before the first forge call the loop broke without ever calling gh: forge/calls was never written and the assertion failed reading a missing file. Freezing the clock in both modes removes the dependence on wall time; the bounded call is still cut by the real timeout, so the observation the test asserts still starts. Emission time stays optional on new status records, and legacy or malformed lines keep an unknown age. * no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion * no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs * test: fold emission-time snapshot coverage into the fixture case Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer touches workflows. Keep every emission-time assertion by folding it into test_fixture_snapshot_json. * no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch * no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape * no-mistakes(review): strip undelimited at-tags; correct brief stamp header * no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness * no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles * no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb * no-mistakes(review): read note and key past colon-bearing stamps * test(status): keep inactive reconcile assertions stamp-tolerant These two oracles were made stamp-tolerant while resolving one of the branch's merges from main. The rebase drops merge commits, so that adaptation was lost and both assertions went back to matching an exact substring that a stamped line no longer contains: the tag lands before the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...". Strip a well-formed tag before matching, as the branch's other oracles do. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap * no-mistakes(document): correct stale unstamped status-line spellings in docs * no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments * no-mistakes(ci): rename subshell-local epoch in delivery-race stub The serialization test overrides fm_pending_reply_mark_delivered inside a (..) subshell. Its `epoch` local collided with the same name in status_line_at_epoch/status_stamp_line, which this branch added and this suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and failed Lint 2. The stub already prefixes its other locals with `pending_` for the same reason; `epoch` was the leftover. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bin): unify Lavish host and disconnect handling (kunchenguid#5060) * fix: ship clean Lavish host fixes * no-mistakes(review): Fix Lavish classifications and fail-closed host loading * no-mistakes(review): Restore Lavish host state across retries and launches * no-mistakes(review): Preserve destination Lavish host when configuration is absent * no-mistakes(document): Document Lavish status and host guarantees * feat: act on captain's away words during AFK supervision (kunchenguid#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation * fix(bin): render the remote charter's steering-inbox path host-local (kunchenguid#5049) * fix(bin): render the remote charter's steering-inbox path host-local A freshly provisioned remote secondmate read a parent-home absolute steering-inbox path in its charter - a location that exists on no route - and spent its first turn discovering the gap and filing a blocked decision for what was a render defect. The seed's remote-copy rewrite now maps the inbox to the route's host-local parent-route inbox, exactly as it already maps the reply-log path, so every mention - bare path, listing, and handled/ acknowledgement - lands host-local. Both rewrites also become plain assignments, because a quoted substitution nested inside a double-quoted printf argument leaks literal quotes into the replacement text on stock macOS bash. The lifecycle suite pins the corrected render both directions against the real seed, provisioning, and delivery route, sharing one fixture value between the render truth and the delivery truth. Closes kunchenguid#5012 * no-mistakes(document): document remote charter's host-local steering inbox * no-mistakes(document): Correct quiet-mode guidance and launch environment documentation --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Tiago <tiagop@hey.com> Co-authored-by: rovermike <mike@rovertown.com> Co-authored-by: Vytautas Stankus <svycka@gmail.com> Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> Co-authored-by: Amin Roudaki <roudaky@gmail.com> Co-authored-by: Jon Roosevelt <rooseveltadvisors@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Martin Kessler <kesslerio@users.noreply.github.com>
haris-siddiqui-1
pushed a commit
to haris-siddiqui-1/firstmate
that referenced
this pull request
Sep 21, 2026
…#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation
haris-siddiqui-1
pushed a commit
to haris-siddiqui-1/firstmate
that referenced
this pull request
Sep 21, 2026
…#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation
andrewesweet
pushed a commit
to andrewesweet/firstmate
that referenced
this pull request
Sep 21, 2026
…#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation
bcriswell
added a commit
to bcriswell/firstmate
that referenced
this pull request
Sep 23, 2026
* feat(bin): add opt-in typed dispatch resolution (#4692)
* feat(bin): add opt-in typed dispatch resolution through typesafe.ai
Add bin/fm-dispatch-resolve.sh, which resolves one concrete crewmate or
scout profile from a written brief with typesafe.ai's System One model:
one Choice question over the rules' `when` texts, then the confidence
floor, the rule's `approval` and `floor`, each profile's `provider` and
`floor`, one quota-axi snapshot, and the spendPriority argmax all in code.
It is off unless TYPESAFE_API_KEY is in the environment or the home's
gitignored .env; off means one stderr line, exit 0, and no network call,
so firstmate dispatches exactly as before. The key reaches curl on a file
descriptor, never argv.
Extract fmx_env_get into bin/fm-env-lib.sh as the one .env accessor and
the harness-to-provider table into bin/fm-quota-axi-lib.sh so the new
tool and bin/fm-quota-choose.sh share one owner each. Bootstrap validates
the four new optional dispatch fields. Document the schema, the operator
contract, the AGENTS.md intake step, and the live and benchmark evidence.
* no-mistakes(review): Harden typed dispatch resolution and quota bounds
* no-mistakes(review): Validate dispatch floors and ranking evidence
* no-mistakes(review): Tighten dispatch response and floor evidence
* no-mistakes(review): Neutralize none matching and resolve defaults locally
* no-mistakes(review): Preserve providerless profiles outside typed resolution
* no-mistakes(review): Validate response usage and reject duplicate profiles
* no-mistakes(review): Escalate unverifiable floors and validate probabilities
* no-mistakes(review): Validate probability mass and unknown profile floors
* no-mistakes(review): Simplify resolver interface and preserve fallback routing
* no-mistakes(review): Fix constants and rank partial quota evidence
* no-mistakes(review): Add authoritative provider mapping and enforce explicit providers
* no-mistakes(review): Declare provider for documented Pi profile
* no-mistakes(review): Validate provider identifiers and support Gemini dispatch
* no-mistakes(review): Strictly anchor provider identifiers
* no-mistakes(review): Validate selectors and preserve fallback candidate evidence
* no-mistakes(review): Gate typed validation and harden resolver evidence
* no-mistakes(review): Preserve opt-in routing and harden candidate evidence
* no-mistakes(review): Prioritize known exhaustion over quota uncertainty
* no-mistakes(review): Isolate API secrets and preserve no-key diagnostics
* no-mistakes(review): Fallback safely when dispatch rules are absent
* no-mistakes(review): Prioritize quota vetoes and isolate bootstrap secrets
* no-mistakes(document): Document typed dispatch safety and fallback behavior
* fix(bin): read the latest status event so buried declarations and open decisions aren't lost (#3753)
* test: reproduce buried status declarations in shared readers
* fix: share status event reads and preserve open blockers
* fix: retain terminal scout and ship status declarations
* no-mistakes(review): Fix status chronology, legacy completions, and reader performance
* no-mistakes(review): Share terminal decision reconciliation across fleet snapshots
* no-mistakes(review): Unify terminal supersession across cached folds and consumers
* no-mistakes(review): Filter per-key status history while preserving terminal chronology
* no-mistakes(test): Preserve parent lock ownership in Bash 3.2 subshells
* no-mistakes(review): Anchor legacy status tokens so prose cannot hide pauses
* no-mistakes(document): Document latest-event status read and kind-scoped fold cursor
* no-mistakes(lint): Quote literal done in test for-lists for SC1010
* ci: expect 19 snapshot/fleet-view tests
This branch adds a fleet-snapshot regression, so the stock macOS Bash
lane's hardcoded guard of 18 'ok - ' lines fails on the new count.
Bump the guard and its message to 19.
* no-mistakes(review): Restore multiline child outcome reporting
* no-mistakes(review): Select ledger terminal events through bounded shared reader
* no-mistakes(review): Report newest open decision instead of preferring blocked
* no-mistakes(review): Require colon before ship/scout terminal supersession in fold
* no-mistakes(review): Gate socket-down override on latest event; drop lock matrix
* no-mistakes(review): Fold only colon-bearing or keyed lines as decision transitions
* no-mistakes(review): Pre-select candidate lines before per-key closing-verb fold
* no-mistakes(test): Update fleet-view expectations to newest-open-decision rule
* no-mistakes(document): Align status-read docs with fold-resolved crew state
* no-mistakes(document): Correct status-reader contracts in classify-lib and crew-state headers
* no-mistakes(ci): Greptile P1 (bin/fm-crew-state.sh:729, "Stale socket blocker survives") was a real defect introduced by commit b7c2183 on this branch, and is fixed. Root cause: the daemon-socket-down override took its verb check from `last_status_line "$LOG"` but its evidence and emitted detail from `$LOG_LINE` (status_current_line = the fold's newest still-open decision). Those are different lines whenever a later recognized `blocked:` event is one the decision fold declines. Reproduced by sourcing bin/fm-classify-lib.sh on `blocked: no-mistakes daemon socket is missing` followed by `blocked [key=pending-reply-t3]: still waiting on the answer` (reserved-namespace key whose note does not speak that vocabulary, so _fm_decision_key_transition_allowed rejects it): open set still holds the socket blocker, last_status_line returns the newer line, its verb is blocked, so the gate passed and the stale daemon-down evidence overrode a healthy attributed run. Fix (bin/fm-crew-state.sh): capture LOG_LATEST=$(last_status_line "$LOG") once and read verb, socket-down evidence, and the emitted note all off that same line, so the override fires only while the socket-down declaration is itself the log's latest recognized event — preserving the narrow override the prior round's user instruction asked for. Comment updated to state that contract. No new machinery; the two-line conflation was removed rather than papered over. Regression: extended tests/fm-crew-state.test.sh:test_socket_refusal_override_expires_when_the_crew_moves_on with the reproduced sequence, asserting the run-step reading (state: working, source: run-step) and absence of the override detail. It fails before the fix ("not ok - a later unfolded blocked event also hands the reading back to the run (missing: 'state: working')") and passes after. Verified locally: tests/fm-crew-state.test.sh, tests/fm-fleet-snapshot-view.test.sh, tests/fm-classify-decision-key.test.sh, tests/fm-watch-triage.test.sh, tests/fm-captain-hold-lifecycle.test.sh all pass; bin/fm-lint.sh (shellcheck 0.11.0 + actionlint) exits 0. Changes left uncommitted in the worktree
* test: fold terminal-cleanup snapshot coverage into the completed-scout case
Keep the ship/scout/secondmate supersession assertions without adding a
nineteenth top-level fleet-view test, so CI can stay at the upstream suite count.
* no-mistakes(document): Clarify socket-down override expiry in architecture doc
* ci: retrigger flaky contribution check
* fix(bin): launch codex crewmates with codex's hook layer disabled (#4689)
* fix(spawn): launch codex crewmates with codex's hook layer disabled
A freshly launched Codex worker never reached its instructions. Codex
stopped it on an interactive "Hooks need review" modal whose selection
sits on "Review hooks", which is neither trusting nor declining.
Firstmate's key plane carries only Enter, Escape and Ctrl-C with no arrow
navigation, so the selection cannot be moved, and pre-accepting the
prompt by writing Codex's own trust store would record an operator
consent that was never given.
The hooks are the machine's own ~/.codex/hooks.json plus any project's
.codex/hooks.json. A crewmate needs neither: its turn-end signal is the
-c notify= program on the same launch, and Firstmate's project hooks are
primary-session infrastructure that stands down in a child worktree.
Crewmate and scout launches now pass --disable hooks. That is the
opposite of --dangerously-bypass-hook-trust, which RUNS the untrusted
hooks; disabling the feature runs none of them and leaves the operator's
~/.codex untouched. An unknown feature name is a hard Codex error, so a
release that drops the flag fails the launch loudly instead of silently
restoring the modal. A secondmate is a primary in its own home and keeps
the project hooks its turn-end guard and session-start digest ride on.
Verified on codex-cli 0.151.0: the modal is gone and the turn-end
notification still lands.
This unblocks the second review that every finished pull request is supposed to get.
Fixes kunchenguid/firstmate#4673
* no-mistakes(review): Fix contradictory hook count in Codex verification record
* fix(bin): settle terminal contribution observations (Fixes #4669, Fixes #4670) (#4710)
* fix(bin): settle terminal contributions and wake once per read-failure episode
A contribution whose last good observation is merged or closed is final:
poll no longer re-reads it, projection keeps it fresh, and a stale error
recorded beside it is cleared once. A genuine forge-read failure on an open
contribution still records its error on every cycle but prints the
unavailable wake only when it starts a failure episode; a successful read
ends the episode. Open PRs linked from done tasks keep being observed.
The false unavailable beside a complete observation was budget exhaustion
mid-observation, already fixed by #4661.
* fix(review): Settle terminal contribution owners
* fix(review): Deduplicate shared contribution failure episodes
* fix(test): Preserve settled terminal contribution records
* fix: select authoritative no-mistakes runs (#4476)
* fix(crew-state): select authoritative validation runs by identity
Use the AXI run overview and id-addressed status reads to preserve replacement review gates, report competing live runs as unknown, and retain newer failures. Keep the coarse ledger in creation order rather than preferring an older live row.
Refs: https://github.com/kunchenguid/firstmate/issues/3215
* fix(review): Resolve same-branch run identities beyond capped history
* fix(review): Fix run-selection compatibility, races, and worker-state fallbacks
* fix(review): Limit run validation to the requested branch
* fix(test): Anchor AXI fixtures and document remaining live evidence gaps
* fix(document): Clarify run selection documentation and capture ownership
* fix(lint): Fix ShellCheck diagnostics while preserving fixture isolation
* fix: distinguish captain outcomes from no-op updates (#4738)
* fix(AGENTS): send a captain-facing outcome instead of shipshape for finished requested work
MAIN answered a supervision-branch outcome for completed captain-requested
work (implementation done, PR ready for review and merge approval) with
"Captain, shipshape.", reading section 9's no-action reply as covering it
and reading the Pi protocol's "do not re-emit the anchor verbatim" as "no
captain-facing response is owed".
Section 9 now limits the shipshape reply to true no-ops (idle re-read,
empty heartbeat, consequence-free acknowledgement) and requires a short
outcome response naming what finished and what word is needed whenever
requested work finishes or a result needs the captain's word, even when a
transcript entry already shows the substance. The Pi protocol's re-emit
rule now says it bounds repetition only, and carries a worked example of
the ready-for-review outcome whose correct processing turn a shipshape
reply fails.
No executable contract evaluates the content of MAIN's captain-facing
reply, so the regression is the protocol example in the owner doc rather
than a text-match test.
* no-mistakes(document): Clarify captain-facing outcomes versus no-ops
* docs(pi): restore the ready-for-review regression example as a preserved-verbatim contract line
The document step condensed the Pi protocol's re-emit rule and dropped the
worked example of a finished, ready-for-review outcome whose correct
processing turn a "Captain, shipshape." reply fails. That example is the
contract's regression: no executable contract evaluates the content of
MAIN's captain-facing reply, so the owner doc's example is the test case.
Restore it directly under the re-emit rule, prefixed as a regression
example that is kept verbatim and never condensed or summarized away.
* no-mistakes(review): Clarify captain outcome and decision-word requirements
* no-mistakes(document): Clarify captain-facing completion outcomes
* docs(pi): require the PR URL in the visible captain-facing outcome reply
Captain review on the regression example: drop the sample reply string
and say only that the ready-for-review outcome requires relaying a
captain-facing outcome response, not just "Captain, shipshape.".
Fold in the visible-PR-handoff failure seen this session: after the
branch outcome reporting this fix green, MAIN's visible reply was only
"Awaiting your merge call." with no PR URL, leaning on the dim anchor.
Section 9's URL rule now also covers a review or merge ask and names the
visible reply as where the URL goes, sourced from the ready status, pr=
metadata, or the supervision branch's summary and never left to a
transcript entry. The Pi protocol adds the same-way failure and places
the captain-facing text in the final visible assistant reply after the
fm_branch_processed call, because Calm hides assistant text emitted in
the same step as a tool call as a working note.
Investigation verdict, evidence in the PR comment: no recent PR caused
the handoff failure; Pi has hidden same-step pre-tool assistant text
since #2339 (2026-08-13), #4655 changed only the Claude Code mod, and
#4658 touched only remote report transfer.
* no-mistakes(review): Restore safe outcome ordering and consolidate PR URLs
* no-mistakes(document): Clarify captain-facing supervision outcomes
* docs(AGENTS): keep the whenever-a-PR-is-mentioned trigger on the consolidated URL rule
The consolidated section 9 URL rule narrowed its trigger to a review or
merge ask, dropping the "whenever a PR is mentioned" catch-all from
#3648 that keeps every PR URL copied from a durable record and never
assembled from memory. Restore that trigger as a union with the review
or merge ask so the one consolidated rule covers both.
* fix(bin): let non-owner Claude Stops exit safely (#4777)
* Fix foreign-owner turn-end supervision loop
* no-mistakes(review): Scope foreign-owner safe exit to Claude guard
* no-mistakes(document): Document Claude foreign-owner safe exit
* fix(bin): survive bash 3.2 empty-array expansion in watcher churn absorb (#4778)
Under set -u, stock macOS bash 3.2.57 treats "${arr[@]}" on an empty
indexed array as an unbound variable and aborts the shell. In
signal_turnend_panes_churned() the missing_keys loop was reachable with
an empty array whenever every churned key already held a fresh
.churn-since-* marker (a second churning turn-end inside an open
deferral window), so each watcher cycle died about half a minute in and
supervision restarted endlessly. The created_keys rollback loops had the
same latent crash on their error paths.
Audit of bin/ for the same pattern found one more confirmed-reachable
case: remote_handoff's noncanonical-body scan iterates to_move, which is
empty when a retried remote handoff finds every key already staged in
the outbox. All other "${arr[@]}" sites are either count-guarded,
guaranteed non-empty by construction, or unreachable while empty.
Guard the three reachable expansions with the repo's existing
"${arr[@]+...}" idiom. New regression test drives a real watcher
through the all-marked churn path; the macos-stock-bash CI lane runs it
under real /bin/bash 3.2 via FM_TEST_ONLY.
* Make the foreign-owner turn-end repro create a Linux-readable session lock. (#4783)
The synthetic harness was named synthetic-claude, which Linux procps truncates to synthetic-claud so fm-lock.sh never matched a harness or wrote state/.lock before the test read it.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: require complete captain-facing final responses (#4779)
* docs: require complete final responses across harnesses
* no-mistakes(document): Document complete final replies for Grok Bot
* docs: point Grok replies to the shared contract owner
* no-mistakes(review): Clarify final recap without batching decision asks
* fix: preserve substantive mid-turn text in Pi Calm (#4788)
* fix(calm): preserve substantive Pi mid-turn text
* no-mistakes(review): Preserve substantive Pi Calm text per block
* no-mistakes(test): Cover shared Calm preservation boundaries behaviorally
* no-mistakes(document): Consolidate Calm preservation documentation
* fix: harden mail checks and rebalance full-coverage CI (#4800)
* Improve CI reliability and rebalance full-coverage validation
* no-mistakes(document): Clarify lint partition documentation
* fix(bin): answer Kimi 2.0.0 folder-trust dialog during spawn (#4799)
* Handle Kimi workspace trust dialog
* no-mistakes(review): Retry Kimi trust Enter and gate ready on dialog markers
* no-mistakes(review): Gate Kimi ready on any trust marker and clean captures
* no-mistakes(review): Read visible pane for Kimi trust and ready gates
* no-mistakes(review): Add per-backend visible-pane capture for Kimi trust gate
* no-mistakes(review): Harden Kimi viewport capture and trust dialog detection
* no-mistakes(document): Document Kimi spawn refusal on cmux and Orca
* fix(bin): report a dead-agent record once instead of escalating forever (#4775)
* fix(bin): report a record whose agent is gone once instead of escalating forever
The wedge escalation path never asked whether there was still an agent to be
wedged. A wedge is something stuck that might recover, so re-alarming it earns
its cost; an agent that is gone never moves again, its pane never churns, the
idle timer never resets, and the escalate path clears its own timer and re-arms
with nothing bounding the count.
Observed on a live fleet: two finished lanes reached 226 and 203 consecutive
escalations, roughly one every FM_STALE_ESCALATE_SECS, indefinitely - about 400
notifications a day from two lanes with no agent running at all. On one,
fm-control.sh exit answered already-stopped and fm-crew-state.sh read
"failed - run failed". Closing the Herdr pane did not stop it either: with the
pane genuinely gone and herdr pane read returning pane_not_found, the count kept
climbing, because the poll is driven by the record's window= line rather than by
the pane. The cost is not the repetition but that it drowns the alarms that
matter.
fm_backend_agent_state already separates a thinking agent from a gone one at
process level. In the branch that was about to escalate, read it once and treat
only its two recovery-grade verdicts - dead (endpoint present, no agent in it)
and missing (endpoint authoritatively absent) - as proof, reporting that record
once and not re-escalating it while it stays that way. Every other verdict,
including alive, ambiguous, unreadable, unverified, and a read that failed
outright, keeps the identical schedule, reason, and escalation count, so a
genuinely wedged live agent is unaffected. The probe costs at most one backend
read per window per threshold, the same budget the declared-wait consult and the
worktree write probe already take.
The report decides nothing about the record's fate: both lanes still held
unlanded work and teardown refusing them was correct, so retiring, relaunching,
or cleaning up stays with the supervisor. The once-only marker is owned entirely
by that function and is dropped by the same read the moment the endpoint stops
reading gone, so a replacement launched into the same window escalates normally
and its own later death is reported again.
Related, and not closed by this: #4412, #4482, #4316.
Tests drive the real watcher against a record whose endpoint does not exist and
pin both directions: dead and missing report once and never advance the count
across later thresholds, while alive, ambiguous, and unreadable endpoints keep
escalating with the identical reason and a climbing count.
* fix(bin): bind the once-only dead report to the pane it reported
Review of the parent commit found a reachable sequence where a later death in
the same window lost its promised report. The marker was keyed on the verdict
string alone and dropped only when a threshold probe read a non-gone verdict,
but probes run only at thresholds: a replacement launched into the same window
that dies without ever being probed alive - it crashes at startup, or works and
then crashes - was absorbed by the previous death's marker. The pane's first
sight yielded only the generic stale wake and every later threshold matched the
stale marker, so the second death never got the detailed once-report that both
the function's own comment and docs/architecture.md promise.
Record the verdict together with the pane hash it was reported for, and absorb a
repeat only while both still match. A replacement churns the pane, which resets
the stale suppressor, wedge timer, and escalation count while no reset site
touches this marker, so the pane half is what tells the second death apart from
the first. The live-probe drop stays as it was.
Clearing the marker at those reset sites instead would re-open unbounded
re-alarming for a dead pane whose display ever ticks, which is the exact defect
the parent commit exists to close.
The noise bound is unchanged: an unchanged dead pane still absorbs on every
later threshold and never advances the escalation count, and every verdict short
of proof still escalates exactly as before.
* no-mistakes(review): Key the dead-record once-marker on the busy incarnation token
* no-mistakes(document): Document dead-record escalation cap in stale-pane config entry
* no-mistakes(document): Add busy-state inventory line to AGENTS.md
* no-mistakes(document): Document dead-record probe on busy-turn-bound wedge path
* fix(bin): create captain-hold rows when Beads requires due (#4854)
Captain holds have no due semantics and are a hold kind, not a Beads issue
type. The create path now waives due.required and maps to native type task.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: disable compact adviser for spawned agents (#4877)
* feat(bin): launch every spawned agent with the compact adviser disabled
Every crewmate, scout, and secondmate Firstmate launches now starts with
COMPACT_ADVISER_DISABLE=1, on a fresh spawn and on a relaunch alike, so an
unattended session never activates the compact adviser.
The value is unconditional: no configuration file gates it and there is no
override, unlike the trace carrier beside it.
Three carriers deliver it, because no single one covers every launch shape.
The pane shell receives an export beside GOTMPDIR, so the agent's own children
inherit it too.
The launch command carries an explicit assignment, prepended outermost so it
wins over any ambient value the pane already held.
The cleared launch environment sets it again at the `env -i` boundary and keeps
COMPACT_ADVISER_DISABLE in the fixed operational floor, which is what preserves
the switch when config/launch-env-allowlist empties the environment, and what
delivers it on a remote host that never had the value.
bin/fm-control.sh relaunch, the bootstrap secondmate relaunch, and the remote
secondmate transport all rebuild their launch through bin/fm-spawn.sh, so they
inherit the same floor.
The captain's own primary session is untouched.
The two new suites drive the real spawn and then execute the launch command the
pane actually received, with the harness replaced by a probe that prints its own
environment, rather than matching script text.
They cover ship and secondmate launches with the allowlist absent and enabled,
the pane export and its ordering, fm-control.sh relaunch, and the full parent to
remote-host chain.
* no-mistakes(review): Export compact-adviser disable across compound launches
* no-mistakes(document): Document spawned-agent compact-adviser environment guarantee
* fix(bin): preserve Claude lock ownership after helper recycling (#4894)
* fix(bin): let a background Claude session keep owning its session lock
Session-lock ownership was decided by process ancestry alone. Under an
unattended Claude session the model loop runs in a transient bg-spare
bridged to the front-end by a shared daemon; when that bridge is
recycled the contiguous claude-named ancestry from a hook to the
recorded owner breaks while the owner pid stays alive, so the Stop
auto-arm stood down as a foreign live owner, the turn-end guard ended
every turn with its read-only diagnostic, and fm-lock.sh refused - a
self-sustaining outage until restart.
Ownership is now ancestry membership OR a trusted same-session id,
never id-first:
- fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when
CLAUDE_PID is a Claude-shaped member of the current contiguous run,
compares it against the id recorded in state/.lock-session, and
requires the recorded pid to still be a live harness. No id, no
sidecar, an untrusted id, a different id, or a dead recorded pid
leaves the ancestry verdict unchanged. Ids are never read from ps
argv.
- fm-lock.sh accepts a same-session holder at both refusal sites,
writes, refreshes, and clears the sidecar only under its claim lock
(including the early already-mine exit, skipped only while the
deferred startup sweep leases that lock), keeps it byte-identical
across a same-session confirmation, records CLAUDE_PID on lock line 1
for a session with a trusted id so a shared daemon or front-end that
outlives the session never keeps a dead session's lock alive, never
rewrites a live line 1 on a same-session confirmation, and names the
recorded id in the live-owner refusal.
- The .lock line-1 format is unchanged, so every reader that takes the
whole first line as the pid keeps working; the guard's foreign-owner
exit is unchanged and inherits the fix through the shared predicate.
Tests: the ancestry suite drives the ancestry and id signals apart in a
deterministic process table (asserting the divergence) and runs a real
orphaned front-end/daemon/pty-host/spare tree through six phases with
the real lock, auto-arm, and guard scripts; the foreign-owner repro
keeps its negative control and adds a same-id positive control.
Disclosure: no live unattended Claude background session ran on the
verifying machine. The topology is documented by the real process
listings in #3902, #2314, #3398, and #4066; coverage is the structural
predicate plus the executable fixtures, not a live pass.
Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry
walk (it only decides whether to print a nudge) and may nudge on a
resume in the recycled case.
Out of scope, deliberately: no structured lock format, no guard budget
changes, no daemon-identity rejection, no fork lineage.
* no-mistakes(review): Wait for claim lock; revert failed sidecars
* no-mistakes(review): Revalidate ownership after wait; restore sidecars
* no-mistakes(review): Roll back sidecar by publication phase
* no-mistakes(review): Restore sidecar only if lock line is unchanged
* no-mistakes(review): Trust session ids without a spelling allowlist
* no-mistakes(review): Disarm sidecar rollback before backup cleanup
* no-mistakes(document): Updated session-lock ownership documentation
* feat: park main under the away posture on Pi (#4889)
* feat: park main under the away posture on Pi
While the away-posture record exists on a Pi primary, the supervision branch
takes every actionable wake, no processing turn opens on main, captain rows
accumulate for the return brief, and main's standing authority relocates to
the branch through the existing guarded scripts.
- lib/fm-branch-dispatch.ts: read the record at every routing decision; while
it exists claim check, decision-owned, and heartbeat rows too, keeping the
two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task
scoping.
- fm-primary-pi-watch.ts: offer every actionable row under the record; a
declined wake and every watcher-failure alarm still reach main.
- fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed
POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no
processing request while the record exists, re-checked immediately before a
request would open and at every run boundary; present the accumulated rows
at the first run boundary after archive.
- fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in
actions only while fm-afk-contract.sh validate succeeds on a confirmed live
record; PR merge, fresh spawn, and decision answer opt in, local landing
never does.
- fm-send.sh: a --resolve-key naming an open needs-decision or captain-held
task is a decision answer and meets the partition; blocked: keys stay
steering.
- fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by
either actor; relaunches and secondmates exempt.
- fm-branch-prompt.sh: fixed Postures section and the verbatim
ask-user-authority policy; the prefix stays byte-stable.
- fm-afk-return.sh: count what the away session handled from the store.
- docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate
absolute while away.
- tests: watcher and branch extension suites, fleet-record, merge, and
decision-answer suites cover the relocation, the vetoes, the tail, the
parked processing turn, the cancellation, the re-presentation, and the
spend cap; dated live-guard evidence recorded.
* no-mistakes(review): Refuse branch merge after preflight archive race
* no-mistakes(review): Fix away wake, spawn, and processing races
* no-mistakes(review): Suppress parked processing; narrow away-only rejection
* no-mistakes(review): Abort dedicated processing; gate branch spawn once
* no-mistakes(review): Stamp away-only on the dispatch offer
* no-mistakes(review): Treat invalid away records as spend-cap absence
* no-mistakes(review): Drop spawn test hook; abort processing-opened runs
* no-mistakes(review): Bind abort to opening prompt; cap-read absence
* no-mistakes(review): Limit away branch spawn to queued work only
* no-mistakes(document): Correct AFK posture documentation
* ci: standardize workflow timeouts into three tiers (#4910)
* ci: simplify CI job timeouts to a three-tier policy
Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m
serial, 10m macOS) with three readable tiers, each a hang tripwire with
headroom rather than a packing estimate:
- fast (5m): coverage guard, repo invariants, timing aggregate
- normal (30m, one shared budget): lint partitions, portable parallel
shards, portable serial shards, macOS stock Bash
- heavy (Herdr only): 20m step tripwire on the family run so always()
cleanup still runs, under a 75m job-level last-resort backstop
The workflow's header comment states the policy and points at
docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each
job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh
asserts the policy against the parsed workflow instead of the old
per-job minute values: every job joins exactly one tier, exactly three
distinct job-level values exist, the fast tier stays within 5-10
minutes, the normal budget stays at least double the modeled parallel
lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step
tripwire stays below its job backstop with an always() cleanup after it.
Concurrency supersession, shard counts, lane membership, and fail-fast
settings are unchanged.
* no-mistakes(review): Decouple the normal timeout from packing estimates
* no-mistakes(review): Assert Herdr teardown follows the family run
* no-mistakes(review): Pin Herdr family-run timeout to 20 minutes
* no-mistakes(review): Ignore comments when identifying Herdr steps
* no-mistakes(review): Identify Herdr steps by declarative ids
* no-mistakes(document): Clarify authoritative three-tier timeout policy
* fix(bin): keep supervisor status closes from waking the same home (#4895)
* fix(bin): keep supervisor status closes from waking the same home
A drain that already folded OPEN DECISIONS has presented those bytes even
when the watcher has no matching seen marker. Treat that fold, and the
presentation cursor, as known so the bookkeeping close stays quiet while
later worker lines still signal.
* no-mistakes(review): Keep folded worker failures waking past supervisor closes
* no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes
* no-mistakes(review): Stop folded worker resolved lines from counting as already read
* no-mistakes(document): Correct self-announced close marker contract in docs
* fix(bin): stop labeling Herdr as experimental (#4972)
* Stop steering operators away from Herdr
* no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording
* fix(bin): treat a live no-mistakes run as current after rebase (#4973)
* fix(bin): treat a live no-mistakes run as current after rebase
A running run on the task's branch is authoritative regardless of head.
Matching only the local head made a rebased in-flight run look failed.
* no-mistakes(review): restrict coarse live-any-head to foreign-branch answers
* no-mistakes(review): reject gate-parked runs from the executing predicate
* no-mistakes(review): hoist gate-marker patterns into single run-lib owner
* no-mistakes(review): require live daemon for head-free run binding
* no-mistakes(review): require answered daemon-down before unbinding live runs
* no-mistakes(review): extend daemon guard to anchored continuation routes
* no-mistakes(review): delete live-any-head; restore dead-daemon verdict
* no-mistakes(review): keep parked gates parked; name dead daemon everywhere
* no-mistakes(review): set dead-daemon verdict instead of emitting early
* no-mistakes(review): align selected route with legacy dead-daemon handling
* no-mistakes(review): drop unproven-record binds; narrow coarse gate reading
* no-mistakes(review): narrow header, drop vestigial guard, retarget tests
* no-mistakes(review): revert coarse gate override; require answered-down probe
* no-mistakes(review): cache one daemon probe; stop duplicating run id
* no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows
* no-mistakes(review): delete coarse dead-daemon extension and gate note
* no-mistakes(review): delete remaining coarse dead-daemon block and stale docs
* no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict
* fix(bin): prevent long worker launch command truncation (#4994)
* fix(bin): stage the launch command in a private file and type a short source line
A long launch line typed while the fresh pane shell is still busy waits in the
terminal's canonical line buffer, which drops input past about 1,024 bytes on
macOS, so the pane was left at an unfinished command with no agent running.
fm-spawn now writes the assembled command to the task's own temp root under
umask 077 and types only a short line that sources it.
Refs #4559
* fix(bin): keep the per-task temp root private before staging the launch command
The root lives at a predictable path under /tmp and now holds the whole launch
command. Create it with mode 0700, refuse one that already exists as anything but
a directory owned by this user that nobody else can write, and tighten an owned
one, so no other local user can plant or swap the staged file.
Refs #4559
* fix(bin): enforce private staged launch file mode
* test(spawn): cover long staged Claude launches
* no-mistakes(review): Namespace launch files and prove truncation staging
* no-mistakes(review): Use immutable per-spawn launch filenames
* no-mistakes(document): Document staged launch delivery safeguards
* no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass
---------
Co-authored-by: Vytautas Stankus <svycka@gmail.com>
* test: authorize isolated Herdr lab validation (#4998)
* Add isolated Herdr runbook to test instructions
* no-mistakes(review): Drop substring matching from test.instructions contract
* no-mistakes(review): Assert commands.test key absence in YAML
* Drop unit-first sentence and instructions contract test
Captain-scoped follow-up on the Herdr-lab test.instructions ship:
keep the lab safety runbook only, and leave the no-mistakes contract
test focused on commands.test absence.
* docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (#5001)
* docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (#4873)
Replace the pixels-of-today's-UI rule with a quarantined, version-pinned
surface-adapter exception recorded as standing debt. Cap the always-loaded
contract at 9,000 words and require prune-or-trigger before a crossing change
lands.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* docs(vision): restore accepted three-sentence vendor-semantics form (#4873)
Replace the compressed paraphrase with the issue's accepted wording:
a named quarantined version-pinned adapter, expected to break, recorded
as standing debt that never hardens into a shared contract.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974)
* fix(watch): recheck a gate awaiting a human instead of wedge-escalating it
A lane whose validation run is parked at a gate waiting on a human
decision is correctly quiet, but nothing in its status line says so: the
evidence is the pipeline's own gate state rather than anything the worker
wrote. The wedge timer read that silence as a suspected wedge and climbed
the escalation ladder for as long as the wait lasted, and each escalation
cost a supervising turn. The landed declared-wait consult does not reach
it, because a live ordinary crewmate never reports a declared pause, and
raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for
every lane by the same amount.
The threshold now reads a second, independent record when the status line
accounts for nothing: whether the crew's current state is a gate whose
answer is owed by a human. That is minted only from the gate's own
findings table, by a row whose `action` column is exactly `ask-user`,
located by position out of the table header the way nm_gate_step_row
already reads its row - never searched for over the run payload, where a
finding's free-text description or a branch name satisfies a search just
as well. A gate awaiting the CREWMATE's own answer keeps the unchanged
escalation schedule, reason and demand-deep-inspection wording, because a
crewmate that goes quiet before answering its own gate is exactly the
wedge the ladder exists to catch.
Each kind of wait now carries the human it is on, the action that clears
it, and whether that human is the captain as data alongside the verdict,
rather than as wording chosen per branch where the recheck is written, so
the deferral cannot word one kind of wait as another and a new kind
cannot ship without deciding all of them. A parked gate has no written
record of when its wait began, so its recheck publishes no wait age at
all rather than one read from the quiet window this deferral resets on
every pass, which would report the same small number for a gate of any
age. Like every other captain-facing recheck here it is absorbed in
silence while the away-posture record exists, arming no throttle, so the
recheck is owed in full the moment the record is archived.
The consult runs only in the at-threshold branch that was about to
escalate, beside the worktree walk already there, and only for lanes
whose status line explained nothing.
Closes #3055
* no-mistakes(review): require an unanswered decision before deferring a parked gate
* no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records
* test(watch): pass the pane hash wedge_timer_check now takes
Upstream gave wedge_timer_check a sixth <pane-hash> argument for its
dead-record probe. The malformed-wait-record rounds drive the real function
directly, so they pass one, and stub fm_backend_agent_state to a live agent so
the probe that runs after a refused deferral keeps the unchanged ladder rather
than reading a backend the child shell has none of.
* no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate
* no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling
* feat(watch): make the parked-gate wait deferral opt-in
The wedge timer deferring a lane parked at a validation gate is new
supervision behaviour rather than a restored one, and it decides which
lanes give up the escalation ladder, so it now ships as a default-off
per-home option instead of changing every home on upgrade.
config/wedge-defer-parked-gate arms it. The flag is read before the
decision fold, so an unconfigured home spends no fold or current-state
read, writes no record, and keeps the unchanged escalation schedule,
reasons and demand-deep-inspection wording; a test counts the reader
calls in both directions to pin that.
It is not inherited by secondmate homes: each home supervises its own
crew and owns that trade separately, the same reason
config/turnend-churn-absorb is home-local.
The away-posture absorb returns to leaving the idle timer alone, which
it had restarted only because the costly consult could reach it. A
parked-gate wait is owed to the supervisor rather than the captain, so
it never enters that branch, and the recheck owed on return is again
owed in full the moment the record is archived.
* test(watch): pin that the away-silenced hold leaves the idle timer alone
The absorb no longer restarts the timer, so the recheck owed on return is
owed in full rather than a cadence into the return. Nothing asserted
that, so a restart could be reintroduced silently.
* no-mistakes(review): document away-silence rationale, pin captured gate component
* no-mistakes(test): anchor gate row scan to the braced findings header
* no-mistakes(document): pin same-block gate row invariant in crew-state comment
* fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
* fix(control): let the owning seat reclaim a task whose endpoint is gone
A destroyed pane or workspace made `missing` a terminal state. Relaunch
accepted only `dead` and said to stop the agent first; exit refused
`missing` and said to reconcile the task first; there is no reconcile
verb. Each command named the other as its prerequisite, so a task whose
terminal went away could not be reclaimed by anything, and a no-mistakes
approval it was parked on had no seat left to answer it.
`missing` is agent-free a fortiori: there is no endpoint, so there is no
agent in it. Widen the existing guards rather than add a verb.
- fm-spawn --relaunch accepts a positively proven `missing` and creates
one fresh endpoint in the recorded worktree; the record it already
republishes rebinds the task to it. A `dead` endpoint is still adopted
in place.
- fm-control exit reports `endpoint-gone` instead of dying, so the
relaunch transaction's stop step no longer dead-ends, and re-resolves
the endpoint from the record before verifying the replacement.
The duplicate-agent refusal is untouched: both verdicts come from the
same recovery-grade classifier, which claims `missing` only from positive
absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The
backends' own create paths refuse a live same-labeled endpoint as a
second independent guard. The worktree, its branch, commits, uncommitted
changes, armed poll and registration, record rows, and status log are all
untouched - a reclaim is a recovery, never a teardown.
A secondmate is excluded: its gone-endpoint recovery already has one
owner in the session-start liveness sweep, so relaunch refuses and names
it rather than becoming a second path to the same outcome.
Tests reproduce both halves of the deadlock, the reclaim succeeding,
unlanded work surviving it, and the refusals that still hold.
* no-mistakes(review): prove endpoint absence per backend before reclaim rebinds
* no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session
* no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly
* no-mistakes(review): stop refusals and docs asserting unestablished causes
* no-mistakes(review): stop herdr fixture helper losing tmp-root registration
* no-mistakes(review): document workspace drift and absence-probe server residue
* no-mistakes(review): correct rebind limitation to its one reachable case
* no-mistakes(review): stop claiming reclaim leaves instructions untouched
* no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage
* no-mistakes(rebase): read the staged launch file in the herdr fixture
Rebasing onto main picked up #4994, which stages a long worker launch
command into a script and delivers the short `. '<path>'` line instead of
the literal command. The tmux fake and tests/fixtures.sh were updated for
that; the herdr fake this branch adds was written before it and still
keyed "an agent now exists on this pane" off the literal
`encode launch-brief` text, so after the rebase it never marked the
rebound pane live and the reclaim's alive-wait read `dead`.
Dereference the staged file first, exactly as the tmux fake above does.
Test-fixture only; no production path changes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(document): note reclaim placement in herdr and scripts inventories
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(bin): stamp status events with their emission time (#3764)
* test(status): reproduce missing event emission time
* wip(status): preserve optional event emission time
* test(status): document indirect clock stub invocation
* no-mistakes(review): Preserve historical status bytes during reply recovery
* no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies
* no-mistakes(review): Preserve captain regex overrides for timestamped status events
* no-mistakes(document): Clarify status event timing and publication contracts
* no-mistakes(lint): Quote literal done to satisfy ShellCheck
* no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed
* no-mistakes(test): Preserve terminal notifications with malformed timestamp tags
* no-mistakes(test): Stamp Rovo spawn failures with emission time
* no-mistakes(document): Verify status event documentation
* no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests
* no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed
* no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed
* no-mistakes(review): Stamp remote escalations at call sites, drop new flag
* no-mistakes(review): Accept stamped escalation and close lines in test assertions
* no-mistakes(review): Restore reserved-key answered-note guard for stamped closes
* test(status): accept optional emission time in PR-provenance assertions
The #4148 provenance test landed on main with exact unstamped greps.
Parent-channel lines from this branch carry [at=<epoch>], so strip only
that tag before the same exact match. No production change.
* no-mistakes(review): Accept stamped ready signal in PR fallback scrape
* no-mistakes(review): Drop relay flag, stamp parent events at call sites
* no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture
* no-mistakes(review): Accept optional stamp in live cmux drift guard
* no-mistakes(review): Restore original test invocation order in two suites
* no-mistakes(review): Strip only well-formed numeric status time tags
* no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc
* no-mistakes(review): Stamp agy spawn-failure status lines with event time
* fix(bin): normalize status event times in-shell and freeze the budget test clock
Two paths made a status event's emission time cost more than it should.
The captain-relevance fallback piped every line through awk to drop a
well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a
fork per line just to prepare a regex match. Shell parameter expansion does the
same strip with no fork, and the retry-dedup scan now reuses that one helper
instead of carrying a second copy of the rule in awk. The copies had already
drifted: the shell side stripped tags from lines with no colon, which the awk
rule left whole, so a colonless line could be mistaken for one already
recorded. One definition, checked against the awk rule it replaces over the
edge cases and a 4000-line fuzz.
tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In
hang mode the poll set DEADLINE to the real now plus a one-second budget, and
when the second ticked before the first forge call the loop broke without ever
calling gh: forge/calls was never written and the assertion failed reading a
missing file. Freezing the clock in both modes removes the dependence on wall
time; the bounded call is still cut by the real timeout, so the observation the
test asserts still starts.
Emission time stays optional on new status records, and legacy or malformed
lines keep an unknown age.
* no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion
* no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs
* test: fold emission-time snapshot coverage into the fixture case
Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer
touches workflows. Keep every emission-time assertion by folding it
into test_fixture_snapshot_json.
* no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch
* no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape
* no-mistakes(review): strip undelimited at-tags; correct brief stamp header
* no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness
* no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles
* no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb
* no-mistakes(review): read note and key past colon-bearing stamps
* test(status): keep inactive reconcile assertions stamp-tolerant
These two oracles were made stamp-tolerant while resolving one of the
branch's merges from main. The rebase drops merge commits, so that
adaptation was lost and both assertions went back to matching an exact
substring that a stamped line no longer contains: the tag lands before
the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...".
Strip a well-formed tag before matching, as the branch's other oracles do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap
* no-mistakes(document): correct stale unstamped status-line spellings in docs
* no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments
* no-mistakes(ci): rename subshell-local epoch in delivery-race stub
The serialization test overrides fm_pending_reply_mark_delivered inside a
(..) subshell. Its `epoch` local collided with the same name in
status_line_at_epoch/status_stamp_line, which this branch added and this
suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and
failed Lint 2. The stub already prefixes its other locals with `pending_`
for the same reason; `epoch` was the leftover.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(bin): unify Lavish host and disconnect handling (#5060)
* fix: ship clean Lavish host fixes
* no-mistakes(review): Fix Lavish classifications and fail-closed host loading
* no-mistakes(review): Restore Lavish host state across retries and launches
* no-mistakes(review): Preserve destination Lavish host when configuration is absent
* no-mistakes(document): Document Lavish status and host guarantees
* feat: act on captain's away words during AFK supervision (#5076)
* feat(afk): make the captain's away words the whole mandate
Retire the clause fields, verb list, never-set scan, refused records, and
the per-task merge-grant list from the away-posture record. The record is
now version 2: the captain's words verbatim plus expected return, spend
cap, and reach line; a version 1 record still validates, reads, and
archives so a live away window is never broken by the upgrade.
The supervision branch reads the words at the tail of every wake and acts
on them by its own judgment through the guarded scripts under standing
authority, never by analogy, holding for the return on doubt, and opens
each such outcome summary with "per your away instructions:" so the
return brief can render the words beside the session's account. While the
record exists any green merge runs under away authority (ledger tag
"away"); red merges, --allow-red, asynchronous and queued merges, and
local-only landing stay refused. The branch may file a backlog item the
words explicitly call for before dispatching it under the spend cap.
Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and
fm-pr-merge.sh as commands: version 2 written, version 1 read, retired
flags and subcommands refused by name, green merges landing under the
record, red and waived-red refused, the record lock still closing the
authority-read window, and the Pi away tail carrying the words.
* no-mistakes(review): carry the away read-back to the session verbatim
* no-mistakes(review): match the exact away-action marker in the return brief
* no-mistakes(review): refuse a words block truncated by a damaged line
* no-mistakes(document): Refresh away-role contract documentation
* fix(bin): render the remote charter's steering-inbox path host-local (#5049)
* fix(bin): render the remote charter's steering-inbox path host-local
A freshly provisioned remote secondmate read a parent-home absolute
steering-inbox path in its charter - a location that exists on no route -
and spent its first turn discovering the gap and filing a blocked
decision for what was a render defect. The seed's remote-copy rewrite now
maps the inbox to the route's host-local parent-route inbox, exactly as
it already maps the reply-log path, so every mention - bare path, listing,
and handled/ acknowledgement - lands host-local.
Both rewrites also become plain assignments, because a quoted substitution
nested inside a double-quoted printf argument leaks literal quotes into
the replacement text on stock macOS bash. The lifecycle suite pins the
corrected render both directions against the real seed, provisioning,
and delivery route, sharing one fixture value between the render truth
and the delivery truth.
Closes #5012
* no-mistakes(document): document remote charter's host-local steering inbox
* feat: route Lavish feedback directly to owning workers (#5099)
* feat(procevent): route worker-owned Lavish rounds
* no-mistakes(review): drop duplicate artifact field from task-owned registration
* no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic
* no-mistakes(review): keep worker board owned until terminal round acknowledged
* no-mistakes(review): refuse every retirement of an open worker-owned round
* no-mistakes(review): use real lavish reply flag, isolate reply generations
* no-mistakes(review): drop .posted marker for best-effort reply posting
* no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures
* no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms
* no-mistakes(review): re-arm only to acknowledge an open round
* no-mistakes(review): conclude only a still-open terminal round
* no-mistakes(review): record the acknowledgement before retiring the board
* no-mistakes(review): retain the registration across a conclude, qualify terminal docs
* no-mistakes(document): Document worker-owned Lavish round lifecycle
* fix(bin): fit pull observation within the contribution poll budget (#5107)
* fix(bin): reserve contribution observation budget
* no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget
* feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103)
* feat(bin): add idempotent inbox orders, receipts, replies, and readiness
Let a caller supply a request id when publishing a captain inbox note so a
retry returns the original note instead of creating a second one, including
across the crash window between save and wake announcement. Separate saved
from announced so a failed wake is repairable without enqueueing again.
Add bounded receipts JSON with omission disclosure, a durable primary reply
against a note id, and a read-only readiness projection that can say
unknown instead of inferring liveness from a lock file.
* no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict
* fix(bin): resolve ready from lock-holder ancestry; drop lock status --json
Remove the extra JSON surface from fm-lock.sh so its human status still
always exits zero. Have the readiness projection classify the inspected
home from the lock-holder pid via fm-harness.sh ancestry, with an explicit
FM_SUPERVISION_MODEL still winning and an unknown model when there is no
holder. Prove the yes path when that ancestry names a known harness.
* no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor
* no-mistakes(document): Note read-only lock inspection in scripts inventory
* no-mistakes(lint): Pass missing id argument to malformed-reply test printf
---------
Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com>
* fix(bin): stop harness footer rows below a composer from reading as pending text (#5118)
* fix(composer): stop a harness footer row from reading as a composer holding text
A harness draws its own furniture below the composer - a user statusLine, a
permission-mode hint - and the cursorless "bottom-most shape wins" rule looks
exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text
everywhere else, so a statusLine opening with `→` was selected as a bare
composer, swallowed the hint row beneath it as wrapped input, and answered
`pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that
verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first
doorbell and every retry were skipped and the worker never saw the steer.
Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on
Herdr 0.8.0 had genuinely empty composers and every one of them was refused.
A separator pair that closed over a bare agent-glyph row is a proven composer
container, so the contiguous non-blank rows below its closing rule are that
composer's footer and are no longer composer candidates. The demotion is bounded
by all three of its own preconditions: a blank row ends the zone, a pair that
closed over no glyph row demotes nothing, and a shape with no separator pair at
all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same
composer, including a stray SGR mouse report left by a click in the pane, still
reads `pending`.
Pinned by two portable regressions and by a new cursorless arm on the live
composer-matrix guard, which re-reads each harness's already-proven-idle pane
the way every non-tmux backend reads it and fails naming the harness and
version when that read is `pending`.
* no-mistakes(review): make composer footer-zone demotion shape-independent
* no-mistakes(review): make footer-zone demotion refuse-only and drop rescan
* no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100
---------
Co-authored-by: Koen Muller <koen@catapult.nl>
* feat(bin): append optional home-local include to briefs (#5115)
Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com>
* fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114)
* fix(bin): stop misreading a no-run branch as an unreadable runs table
Defect: when `no-mistakes axi status`'s overview is truncated (a task's
own branch has zero rows among the shown ones), fm_nm_select_run's
Python fallback derived the repo identity for its direct SQLite query
from a `repo: <path>` line it expected in the overview text. The real
CLI never emits that line, truncated or not (see the genuine capture at
tests/captures/no-mistakes-v1.70.1/overview.toon, which has only
`count:`/`runs[...]:`), so the lookup always failed and reported
"unreadable runs table" for a task that simply has no run on its
branch. On a fleet with many concurrent runs, every idle-branch task
hits the truncated-overview path routinely, so this fired every few
minutes and drowned genuine unreadable/blocked verdicts in noise.
Fix: derive the repo identity from the task worktree path instead,
which is exactly the value `no-mistakes` records as a repo's
`working_path` (confirmed against the existing capped-overview test
fixtures, which already register repos by worktree path). A worktree
path that is not absolute cannot be matched and still reads as
unreadable rather than being guessed at. Also raise the reader's
SQLite busy timeout from 1s to 30s so ordinary lock contention on a
busy fleet cannot masquerade as an unreadable database.
Safety: every other verdict byte-for-byte unchanged - the repo lookup
still requires exactly one matching row (a genuinely corrupt or
mismatched repos table still reports unreadable, per the existing
`repo` failure-mode test), the branch query and row validation are
untouched, and a zero-row result for the branch still flows through
the same recursive re-parse that already turns an empty `runs[0]{...}`
table into `absent`. Added a regression test
(test_capped_overview_without_repo_line_and_no_runs_reports_absent)
that reproduces the real overview shape - capped, zero rows for the
task's branch, no `repo: ` line - and asserts the crew state falls
through to the pane/busy verdict instead of reporting unknown or
"unreadable". Full fm-crew-state.test.sh suite passes unchanged
otherwise.
* fix: recovered same-branch inventory awk misreads empty result as unreadable
fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:`
overview and re-runs it through the same awk selection pass. When that
rebuilt inventory has zero rows for the branch, the row-matching loop never
executes, so its counters (`seen`) stay at awk's uninitialized empty string
while `expected` and `shown` are plain strings parsed from the header text.
Comparing an uninitialized value against a non-numeric string uses string
comparison, so "" != "0" is true, and the END block takes the "unreadable
runs table" branch instead of falling through to the correct "absent"
verdict for a branch with genuinely zero runs.
Coerce the affected END comparisons with `+0` so they are always numeric,
matching seen/expected/shown/total regardless of whether awk classified
them as strings or numeric strings. A truncated or genuinely malformed
inventory still differs numerically and still reports unreadable.
* no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup
* no-mistakes(review): match recorded repo path first, tolerate duplicate spellings
* no-mistakes(review): revert repo lookup to exact working_path match
* no-mistakes(document): note state-db inventory read under crew-state nm timeout
* fix(bin): require a non-draft pull request before a PR-based done report (#5141)
* fix(bin): require a no…
BohnBawerick
added a commit
to BohnBawerick/firstmate
that referenced
this pull request
Sep 23, 2026
* fix: harden mail checks and rebalance full-coverage CI (#4800)
* Improve CI reliability and rebalance full-coverage validation
* no-mistakes(document): Clarify lint partition documentation
* fix(bin): answer Kimi 2.0.0 folder-trust dialog during spawn (#4799)
* Handle Kimi workspace trust dialog
* no-mistakes(review): Retry Kimi trust Enter and gate ready on dialog markers
* no-mistakes(review): Gate Kimi ready on any trust marker and clean captures
* no-mistakes(review): Read visible pane for Kimi trust and ready gates
* no-mistakes(review): Add per-backend visible-pane capture for Kimi trust gate
* no-mistakes(review): Harden Kimi viewport capture and trust dialog detection
* no-mistakes(document): Document Kimi spawn refusal on cmux and Orca
* fix(bin): report a dead-agent record once instead of escalating forever (#4775)
* fix(bin): report a record whose agent is gone once instead of escalating forever
The wedge escalation path never asked whether there was still an agent to be
wedged. A wedge is something stuck that might recover, so re-alarming it earns
its cost; an agent that is gone never moves again, its pane never churns, the
idle timer never resets, and the escalate path clears its own timer and re-arms
with nothing bounding the count.
Observed on a live fleet: two finished lanes reached 226 and 203 consecutive
escalations, roughly one every FM_STALE_ESCALATE_SECS, indefinitely - about 400
notifications a day from two lanes with no agent running at all. On one,
fm-control.sh exit answered already-stopped and fm-crew-state.sh read
"failed - run failed". Closing the Herdr pane did not stop it either: with the
pane genuinely gone and herdr pane read returning pane_not_found, the count kept
climbing, because the poll is driven by the record's window= line rather than by
the pane. The cost is not the repetition but that it drowns the alarms that
matter.
fm_backend_agent_state already separates a thinking agent from a gone one at
process level. In the branch that was about to escalate, read it once and treat
only its two recovery-grade verdicts - dead (endpoint present, no agent in it)
and missing (endpoint authoritatively absent) - as proof, reporting that record
once and not re-escalating it while it stays that way. Every other verdict,
including alive, ambiguous, unreadable, unverified, and a read that failed
outright, keeps the identical schedule, reason, and escalation count, so a
genuinely wedged live agent is unaffected. The probe costs at most one backend
read per window per threshold, the same budget the declared-wait consult and the
worktree write probe already take.
The report decides nothing about the record's fate: both lanes still held
unlanded work and teardown refusing them was correct, so retiring, relaunching,
or cleaning up stays with the supervisor. The once-only marker is owned entirely
by that function and is dropped by the same read the moment the endpoint stops
reading gone, so a replacement launched into the same window escalates normally
and its own later death is reported again.
Related, and not closed by this: #4412, #4482, #4316.
Tests drive the real watcher against a record whose endpoint does not exist and
pin both directions: dead and missing report once and never advance the count
across later thresholds, while alive, ambiguous, and unreadable endpoints keep
escalating with the identical reason and a climbing count.
* fix(bin): bind the once-only dead report to the pane it reported
Review of the parent commit found a reachable sequence where a later death in
the same window lost its promised report. The marker was keyed on the verdict
string alone and dropped only when a threshold probe read a non-gone verdict,
but probes run only at thresholds: a replacement launched into the same window
that dies without ever being probed alive - it crashes at startup, or works and
then crashes - was absorbed by the previous death's marker. The pane's first
sight yielded only the generic stale wake and every later threshold matched the
stale marker, so the second death never got the detailed once-report that both
the function's own comment and docs/architecture.md promise.
Record the verdict together with the pane hash it was reported for, and absorb a
repeat only while both still match. A replacement churns the pane, which resets
the stale suppressor, wedge timer, and escalation count while no reset site
touches this marker, so the pane half is what tells the second death apart from
the first. The live-probe drop stays as it was.
Clearing the marker at those reset sites instead would re-open unbounded
re-alarming for a dead pane whose display ever ticks, which is the exact defect
the parent commit exists to close.
The noise bound is unchanged: an unchanged dead pane still absorbs on every
later threshold and never advances the escalation count, and every verdict short
of proof still escalates exactly as before.
* no-mistakes(review): Key the dead-record once-marker on the busy incarnation token
* no-mistakes(document): Document dead-record escalation cap in stale-pane config entry
* no-mistakes(document): Add busy-state inventory line to AGENTS.md
* no-mistakes(document): Document dead-record probe on busy-turn-bound wedge path
* fix(bin): create captain-hold rows when Beads requires due (#4854)
Captain holds have no due semantics and are a hold kind, not a Beads issue
type. The create path now waives due.required and maps to native type task.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: disable compact adviser for spawned agents (#4877)
* feat(bin): launch every spawned agent with the compact adviser disabled
Every crewmate, scout, and secondmate Firstmate launches now starts with
COMPACT_ADVISER_DISABLE=1, on a fresh spawn and on a relaunch alike, so an
unattended session never activates the compact adviser.
The value is unconditional: no configuration file gates it and there is no
override, unlike the trace carrier beside it.
Three carriers deliver it, because no single one covers every launch shape.
The pane shell receives an export beside GOTMPDIR, so the agent's own children
inherit it too.
The launch command carries an explicit assignment, prepended outermost so it
wins over any ambient value the pane already held.
The cleared launch environment sets it again at the `env -i` boundary and keeps
COMPACT_ADVISER_DISABLE in the fixed operational floor, which is what preserves
the switch when config/launch-env-allowlist empties the environment, and what
delivers it on a remote host that never had the value.
bin/fm-control.sh relaunch, the bootstrap secondmate relaunch, and the remote
secondmate transport all rebuild their launch through bin/fm-spawn.sh, so they
inherit the same floor.
The captain's own primary session is untouched.
The two new suites drive the real spawn and then execute the launch command the
pane actually received, with the harness replaced by a probe that prints its own
environment, rather than matching script text.
They cover ship and secondmate launches with the allowlist absent and enabled,
the pane export and its ordering, fm-control.sh relaunch, and the full parent to
remote-host chain.
* no-mistakes(review): Export compact-adviser disable across compound launches
* no-mistakes(document): Document spawned-agent compact-adviser environment guarantee
* fix(bin): preserve Claude lock ownership after helper recycling (#4894)
* fix(bin): let a background Claude session keep owning its session lock
Session-lock ownership was decided by process ancestry alone. Under an
unattended Claude session the model loop runs in a transient bg-spare
bridged to the front-end by a shared daemon; when that bridge is
recycled the contiguous claude-named ancestry from a hook to the
recorded owner breaks while the owner pid stays alive, so the Stop
auto-arm stood down as a foreign live owner, the turn-end guard ended
every turn with its read-only diagnostic, and fm-lock.sh refused - a
self-sustaining outage until restart.
Ownership is now ancestry membership OR a trusted same-session id,
never id-first:
- fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when
CLAUDE_PID is a Claude-shaped member of the current contiguous run,
compares it against the id recorded in state/.lock-session, and
requires the recorded pid to still be a live harness. No id, no
sidecar, an untrusted id, a different id, or a dead recorded pid
leaves the ancestry verdict unchanged. Ids are never read from ps
argv.
- fm-lock.sh accepts a same-session holder at both refusal sites,
writes, refreshes, and clears the sidecar only under its claim lock
(including the early already-mine exit, skipped only while the
deferred startup sweep leases that lock), keeps it byte-identical
across a same-session confirmation, records CLAUDE_PID on lock line 1
for a session with a trusted id so a shared daemon or front-end that
outlives the session never keeps a dead session's lock alive, never
rewrites a live line 1 on a same-session confirmation, and names the
recorded id in the live-owner refusal.
- The .lock line-1 format is unchanged, so every reader that takes the
whole first line as the pid keeps working; the guard's foreign-owner
exit is unchanged and inherits the fix through the shared predicate.
Tests: the ancestry suite drives the ancestry and id signals apart in a
deterministic process table (asserting the divergence) and runs a real
orphaned front-end/daemon/pty-host/spare tree through six phases with
the real lock, auto-arm, and guard scripts; the foreign-owner repro
keeps its negative control and adds a same-id positive control.
Disclosure: no live unattended Claude background session ran on the
verifying machine. The topology is documented by the real process
listings in #3902, #2314, #3398, and #4066; coverage is the structural
predicate plus the executable fixtures, not a live pass.
Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry
walk (it only decides whether to print a nudge) and may nudge on a
resume in the recycled case.
Out of scope, deliberately: no structured lock format, no guard budget
changes, no daemon-identity rejection, no fork lineage.
* no-mistakes(review): Wait for claim lock; revert failed sidecars
* no-mistakes(review): Revalidate ownership after wait; restore sidecars
* no-mistakes(review): Roll back sidecar by publication phase
* no-mistakes(review): Restore sidecar only if lock line is unchanged
* no-mistakes(review): Trust session ids without a spelling allowlist
* no-mistakes(review): Disarm sidecar rollback before backup cleanup
* no-mistakes(document): Updated session-lock ownership documentation
* feat: park main under the away posture on Pi (#4889)
* feat: park main under the away posture on Pi
While the away-posture record exists on a Pi primary, the supervision branch
takes every actionable wake, no processing turn opens on main, captain rows
accumulate for the return brief, and main's standing authority relocates to
the branch through the existing guarded scripts.
- lib/fm-branch-dispatch.ts: read the record at every routing decision; while
it exists claim check, decision-owned, and heartbeat rows too, keeping the
two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task
scoping.
- fm-primary-pi-watch.ts: offer every actionable row under the record; a
declined wake and every watcher-failure alarm still reach main.
- fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed
POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no
processing request while the record exists, re-checked immediately before a
request would open and at every run boundary; present the accumulated rows
at the first run boundary after archive.
- fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in
actions only while fm-afk-contract.sh validate succeeds on a confirmed live
record; PR merge, fresh spawn, and decision answer opt in, local landing
never does.
- fm-send.sh: a --resolve-key naming an open needs-decision or captain-held
task is a decision answer and meets the partition; blocked: keys stay
steering.
- fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by
either actor; relaunches and secondmates exempt.
- fm-branch-prompt.sh: fixed Postures section and the verbatim
ask-user-authority policy; the prefix stays byte-stable.
- fm-afk-return.sh: count what the away session handled from the store.
- docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate
absolute while away.
- tests: watcher and branch extension suites, fleet-record, merge, and
decision-answer suites cover the relocation, the vetoes, the tail, the
parked processing turn, the cancellation, the re-presentation, and the
spend cap; dated live-guard evidence recorded.
* no-mistakes(review): Refuse branch merge after preflight archive race
* no-mistakes(review): Fix away wake, spawn, and processing races
* no-mistakes(review): Suppress parked processing; narrow away-only rejection
* no-mistakes(review): Abort dedicated processing; gate branch spawn once
* no-mistakes(review): Stamp away-only on the dispatch offer
* no-mistakes(review): Treat invalid away records as spend-cap absence
* no-mistakes(review): Drop spawn test hook; abort processing-opened runs
* no-mistakes(review): Bind abort to opening prompt; cap-read absence
* no-mistakes(review): Limit away branch spawn to queued work only
* no-mistakes(document): Correct AFK posture documentation
* ci: standardize workflow timeouts into three tiers (#4910)
* ci: simplify CI job timeouts to a three-tier policy
Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m
serial, 10m macOS) with three readable tiers, each a hang tripwire with
headroom rather than a packing estimate:
- fast (5m): coverage guard, repo invariants, timing aggregate
- normal (30m, one shared budget): lint partitions, portable parallel
shards, portable serial shards, macOS stock Bash
- heavy (Herdr only): 20m step tripwire on the family run so always()
cleanup still runs, under a 75m job-level last-resort backstop
The workflow's header comment states the policy and points at
docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each
job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh
asserts the policy against the parsed workflow instead of the old
per-job minute values: every job joins exactly one tier, exactly three
distinct job-level values exist, the fast tier stays within 5-10
minutes, the normal budget stays at least double the modeled parallel
lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step
tripwire stays below its job backstop with an always() cleanup after it.
Concurrency supersession, shard counts, lane membership, and fail-fast
settings are unchanged.
* no-mistakes(review): Decouple the normal timeout from packing estimates
* no-mistakes(review): Assert Herdr teardown follows the family run
* no-mistakes(review): Pin Herdr family-run timeout to 20 minutes
* no-mistakes(review): Ignore comments when identifying Herdr steps
* no-mistakes(review): Identify Herdr steps by declarative ids
* no-mistakes(document): Clarify authoritative three-tier timeout policy
* fix(bin): keep supervisor status closes from waking the same home (#4895)
* fix(bin): keep supervisor status closes from waking the same home
A drain that already folded OPEN DECISIONS has presented those bytes even
when the watcher has no matching seen marker. Treat that fold, and the
presentation cursor, as known so the bookkeeping close stays quiet while
later worker lines still signal.
* no-mistakes(review): Keep folded worker failures waking past supervisor closes
* no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes
* no-mistakes(review): Stop folded worker resolved lines from counting as already read
* no-mistakes(document): Correct self-announced close marker contract in docs
* fix(bin): stop labeling Herdr as experimental (#4972)
* Stop steering operators away from Herdr
* no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording
* fix(bin): treat a live no-mistakes run as current after rebase (#4973)
* fix(bin): treat a live no-mistakes run as current after rebase
A running run on the task's branch is authoritative regardless of head.
Matching only the local head made a rebased in-flight run look failed.
* no-mistakes(review): restrict coarse live-any-head to foreign-branch answers
* no-mistakes(review): reject gate-parked runs from the executing predicate
* no-mistakes(review): hoist gate-marker patterns into single run-lib owner
* no-mistakes(review): require live daemon for head-free run binding
* no-mistakes(review): require answered daemon-down before unbinding live runs
* no-mistakes(review): extend daemon guard to anchored continuation routes
* no-mistakes(review): delete live-any-head; restore dead-daemon verdict
* no-mistakes(review): keep parked gates parked; name dead daemon everywhere
* no-mistakes(review): set dead-daemon verdict instead of emitting early
* no-mistakes(review): align selected route with legacy dead-daemon handling
* no-mistakes(review): drop unproven-record binds; narrow coarse gate reading
* no-mistakes(review): narrow header, drop vestigial guard, retarget tests
* no-mistakes(review): revert coarse gate override; require answered-down probe
* no-mistakes(review): cache one daemon probe; stop duplicating run id
* no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows
* no-mistakes(review): delete coarse dead-daemon extension and gate note
* no-mistakes(review): delete remaining coarse dead-daemon block and stale docs
* no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict
* fix(bin): prevent long worker launch command truncation (#4994)
* fix(bin): stage the launch command in a private file and type a short source line
A long launch line typed while the fresh pane shell is still busy waits in the
terminal's canonical line buffer, which drops input past about 1,024 bytes on
macOS, so the pane was left at an unfinished command with no agent running.
fm-spawn now writes the assembled command to the task's own temp root under
umask 077 and types only a short line that sources it.
Refs #4559
* fix(bin): keep the per-task temp root private before staging the launch command
The root lives at a predictable path under /tmp and now holds the whole launch
command. Create it with mode 0700, refuse one that already exists as anything but
a directory owned by this user that nobody else can write, and tighten an owned
one, so no other local user can plant or swap the staged file.
Refs #4559
* fix(bin): enforce private staged launch file mode
* test(spawn): cover long staged Claude launches
* no-mistakes(review): Namespace launch files and prove truncation staging
* no-mistakes(review): Use immutable per-spawn launch filenames
* no-mistakes(document): Document staged launch delivery safeguards
* no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass
---------
Co-authored-by: Vytautas Stankus <svycka@gmail.com>
* test: authorize isolated Herdr lab validation (#4998)
* Add isolated Herdr runbook to test instructions
* no-mistakes(review): Drop substring matching from test.instructions contract
* no-mistakes(review): Assert commands.test key absence in YAML
* Drop unit-first sentence and instructions contract test
Captain-scoped follow-up on the Herdr-lab test.instructions ship:
keep the lab safety runbook only, and leave the no-mistakes contract
test focused on commands.test absence.
* docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (#5001)
* docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (#4873)
Replace the pixels-of-today's-UI rule with a quarantined, version-pinned
surface-adapter exception recorded as standing debt. Cap the always-loaded
contract at 9,000 words and require prune-or-trigger before a crossing change
lands.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* docs(vision): restore accepted three-sentence vendor-semantics form (#4873)
Replace the compressed paraphrase with the issue's accepted wording:
a named quarantined version-pinned adapter, expected to break, recorded
as standing debt that never hardens into a shared contract.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974)
* fix(watch): recheck a gate awaiting a human instead of wedge-escalating it
A lane whose validation run is parked at a gate waiting on a human
decision is correctly quiet, but nothing in its status line says so: the
evidence is the pipeline's own gate state rather than anything the worker
wrote. The wedge timer read that silence as a suspected wedge and climbed
the escalation ladder for as long as the wait lasted, and each escalation
cost a supervising turn. The landed declared-wait consult does not reach
it, because a live ordinary crewmate never reports a declared pause, and
raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for
every lane by the same amount.
The threshold now reads a second, independent record when the status line
accounts for nothing: whether the crew's current state is a gate whose
answer is owed by a human. That is minted only from the gate's own
findings table, by a row whose `action` column is exactly `ask-user`,
located by position out of the table header the way nm_gate_step_row
already reads its row - never searched for over the run payload, where a
finding's free-text description or a branch name satisfies a search just
as well. A gate awaiting the CREWMATE's own answer keeps the unchanged
escalation schedule, reason and demand-deep-inspection wording, because a
crewmate that goes quiet before answering its own gate is exactly the
wedge the ladder exists to catch.
Each kind of wait now carries the human it is on, the action that clears
it, and whether that human is the captain as data alongside the verdict,
rather than as wording chosen per branch where the recheck is written, so
the deferral cannot word one kind of wait as another and a new kind
cannot ship without deciding all of them. A parked gate has no written
record of when its wait began, so its recheck publishes no wait age at
all rather than one read from the quiet window this deferral resets on
every pass, which would report the same small number for a gate of any
age. Like every other captain-facing recheck here it is absorbed in
silence while the away-posture record exists, arming no throttle, so the
recheck is owed in full the moment the record is archived.
The consult runs only in the at-threshold branch that was about to
escalate, beside the worktree walk already there, and only for lanes
whose status line explained nothing.
Closes #3055
* no-mistakes(review): require an unanswered decision before deferring a parked gate
* no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records
* test(watch): pass the pane hash wedge_timer_check now takes
Upstream gave wedge_timer_check a sixth <pane-hash> argument for its
dead-record probe. The malformed-wait-record rounds drive the real function
directly, so they pass one, and stub fm_backend_agent_state to a live agent so
the probe that runs after a refused deferral keeps the unchanged ladder rather
than reading a backend the child shell has none of.
* no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate
* no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling
* feat(watch): make the parked-gate wait deferral opt-in
The wedge timer deferring a lane parked at a validation gate is new
supervision behaviour rather than a restored one, and it decides which
lanes give up the escalation ladder, so it now ships as a default-off
per-home option instead of changing every home on upgrade.
config/wedge-defer-parked-gate arms it. The flag is read before the
decision fold, so an unconfigured home spends no fold or current-state
read, writes no record, and keeps the unchanged escalation schedule,
reasons and demand-deep-inspection wording; a test counts the reader
calls in both directions to pin that.
It is not inherited by secondmate homes: each home supervises its own
crew and owns that trade separately, the same reason
config/turnend-churn-absorb is home-local.
The away-posture absorb returns to leaving the idle timer alone, which
it had restarted only because the costly consult could reach it. A
parked-gate wait is owed to the supervisor rather than the captain, so
it never enters that branch, and the recheck owed on return is again
owed in full the moment the record is archived.
* test(watch): pin that the away-silenced hold leaves the idle timer alone
The absorb no longer restarts the timer, so the recheck owed on return is
owed in full rather than a cadence into the return. Nothing asserted
that, so a restart could be reintroduced silently.
* no-mistakes(review): document away-silence rationale, pin captured gate component
* no-mistakes(test): anchor gate row scan to the braced findings header
* no-mistakes(document): pin same-block gate row invariant in crew-state comment
* fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
* fix(control): let the owning seat reclaim a task whose endpoint is gone
A destroyed pane or workspace made `missing` a terminal state. Relaunch
accepted only `dead` and said to stop the agent first; exit refused
`missing` and said to reconcile the task first; there is no reconcile
verb. Each command named the other as its prerequisite, so a task whose
terminal went away could not be reclaimed by anything, and a no-mistakes
approval it was parked on had no seat left to answer it.
`missing` is agent-free a fortiori: there is no endpoint, so there is no
agent in it. Widen the existing guards rather than add a verb.
- fm-spawn --relaunch accepts a positively proven `missing` and creates
one fresh endpoint in the recorded worktree; the record it already
republishes rebinds the task to it. A `dead` endpoint is still adopted
in place.
- fm-control exit reports `endpoint-gone` instead of dying, so the
relaunch transaction's stop step no longer dead-ends, and re-resolves
the endpoint from the record before verifying the replacement.
The duplicate-agent refusal is untouched: both verdicts come from the
same recovery-grade classifier, which claims `missing` only from positive
absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The
backends' own create paths refuse a live same-labeled endpoint as a
second independent guard. The worktree, its branch, commits, uncommitted
changes, armed poll and registration, record rows, and status log are all
untouched - a reclaim is a recovery, never a teardown.
A secondmate is excluded: its gone-endpoint recovery already has one
owner in the session-start liveness sweep, so relaunch refuses and names
it rather than becoming a second path to the same outcome.
Tests reproduce both halves of the deadlock, the reclaim succeeding,
unlanded work surviving it, and the refusals that still hold.
* no-mistakes(review): prove endpoint absence per backend before reclaim rebinds
* no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session
* no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly
* no-mistakes(review): stop refusals and docs asserting unestablished causes
* no-mistakes(review): stop herdr fixture helper losing tmp-root registration
* no-mistakes(review): document workspace drift and absence-probe server residue
* no-mistakes(review): correct rebind limitation to its one reachable case
* no-mistakes(review): stop claiming reclaim leaves instructions untouched
* no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage
* no-mistakes(rebase): read the staged launch file in the herdr fixture
Rebasing onto main picked up #4994, which stages a long worker launch
command into a script and delivers the short `. '<path>'` line instead of
the literal command. The tmux fake and tests/fixtures.sh were updated for
that; the herdr fake this branch adds was written before it and still
keyed "an agent now exists on this pane" off the literal
`encode launch-brief` text, so after the rebase it never marked the
rebound pane live and the reclaim's alive-wait read `dead`.
Dereference the staged file first, exactly as the tmux fake above does.
Test-fixture only; no production path changes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(document): note reclaim placement in herdr and scripts inventories
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(bin): stamp status events with their emission time (#3764)
* test(status): reproduce missing event emission time
* wip(status): preserve optional event emission time
* test(status): document indirect clock stub invocation
* no-mistakes(review): Preserve historical status bytes during reply recovery
* no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies
* no-mistakes(review): Preserve captain regex overrides for timestamped status events
* no-mistakes(document): Clarify status event timing and publication contracts
* no-mistakes(lint): Quote literal done to satisfy ShellCheck
* no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed
* no-mistakes(test): Preserve terminal notifications with malformed timestamp tags
* no-mistakes(test): Stamp Rovo spawn failures with emission time
* no-mistakes(document): Verify status event documentation
* no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests
* no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed
* no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed
* no-mistakes(review): Stamp remote escalations at call sites, drop new flag
* no-mistakes(review): Accept stamped escalation and close lines in test assertions
* no-mistakes(review): Restore reserved-key answered-note guard for stamped closes
* test(status): accept optional emission time in PR-provenance assertions
The #4148 provenance test landed on main with exact unstamped greps.
Parent-channel lines from this branch carry [at=<epoch>], so strip only
that tag before the same exact match. No production change.
* no-mistakes(review): Accept stamped ready signal in PR fallback scrape
* no-mistakes(review): Drop relay flag, stamp parent events at call sites
* no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture
* no-mistakes(review): Accept optional stamp in live cmux drift guard
* no-mistakes(review): Restore original test invocation order in two suites
* no-mistakes(review): Strip only well-formed numeric status time tags
* no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc
* no-mistakes(review): Stamp agy spawn-failure status lines with event time
* fix(bin): normalize status event times in-shell and freeze the budget test clock
Two paths made a status event's emission time cost more than it should.
The captain-relevance fallback piped every line through awk to drop a
well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a
fork per line just to prepare a regex match. Shell parameter expansion does the
same strip with no fork, and the retry-dedup scan now reuses that one helper
instead of carrying a second copy of the rule in awk. The copies had already
drifted: the shell side stripped tags from lines with no colon, which the awk
rule left whole, so a colonless line could be mistaken for one already
recorded. One definition, checked against the awk rule it replaces over the
edge cases and a 4000-line fuzz.
tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In
hang mode the poll set DEADLINE to the real now plus a one-second budget, and
when the second ticked before the first forge call the loop broke without ever
calling gh: forge/calls was never written and the assertion failed reading a
missing file. Freezing the clock in both modes removes the dependence on wall
time; the bounded call is still cut by the real timeout, so the observation the
test asserts still starts.
Emission time stays optional on new status records, and legacy or malformed
lines keep an unknown age.
* no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion
* no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs
* test: fold emission-time snapshot coverage into the fixture case
Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer
touches workflows. Keep every emission-time assertion by folding it
into test_fixture_snapshot_json.
* no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch
* no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape
* no-mistakes(review): strip undelimited at-tags; correct brief stamp header
* no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness
* no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles
* no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb
* no-mistakes(review): read note and key past colon-bearing stamps
* test(status): keep inactive reconcile assertions stamp-tolerant
These two oracles were made stamp-tolerant while resolving one of the
branch's merges from main. The rebase drops merge commits, so that
adaptation was lost and both assertions went back to matching an exact
substring that a stamped line no longer contains: the tag lands before
the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...".
Strip a well-formed tag before matching, as the branch's other oracles do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap
* no-mistakes(document): correct stale unstamped status-line spellings in docs
* no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments
* no-mistakes(ci): rename subshell-local epoch in delivery-race stub
The serialization test overrides fm_pending_reply_mark_delivered inside a
(..) subshell. Its `epoch` local collided with the same name in
status_line_at_epoch/status_stamp_line, which this branch added and this
suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and
failed Lint 2. The stub already prefixes its other locals with `pending_`
for the same reason; `epoch` was the leftover.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(bin): unify Lavish host and disconnect handling (#5060)
* fix: ship clean Lavish host fixes
* no-mistakes(review): Fix Lavish classifications and fail-closed host loading
* no-mistakes(review): Restore Lavish host state across retries and launches
* no-mistakes(review): Preserve destination Lavish host when configuration is absent
* no-mistakes(document): Document Lavish status and host guarantees
* feat: act on captain's away words during AFK supervision (#5076)
* feat(afk): make the captain's away words the whole mandate
Retire the clause fields, verb list, never-set scan, refused records, and
the per-task merge-grant list from the away-posture record. The record is
now version 2: the captain's words verbatim plus expected return, spend
cap, and reach line; a version 1 record still validates, reads, and
archives so a live away window is never broken by the upgrade.
The supervision branch reads the words at the tail of every wake and acts
on them by its own judgment through the guarded scripts under standing
authority, never by analogy, holding for the return on doubt, and opens
each such outcome summary with "per your away instructions:" so the
return brief can render the words beside the session's account. While the
record exists any green merge runs under away authority (ledger tag
"away"); red merges, --allow-red, asynchronous and queued merges, and
local-only landing stay refused. The branch may file a backlog item the
words explicitly call for before dispatching it under the spend cap.
Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and
fm-pr-merge.sh as commands: version 2 written, version 1 read, retired
flags and subcommands refused by name, green merges landing under the
record, red and waived-red refused, the record lock still closing the
authority-read window, and the Pi away tail carrying the words.
* no-mistakes(review): carry the away read-back to the session verbatim
* no-mistakes(review): match the exact away-action marker in the return brief
* no-mistakes(review): refuse a words block truncated by a damaged line
* no-mistakes(document): Refresh away-role contract documentation
* fix(bin): render the remote charter's steering-inbox path host-local (#5049)
* fix(bin): render the remote charter's steering-inbox path host-local
A freshly provisioned remote secondmate read a parent-home absolute
steering-inbox path in its charter - a location that exists on no route -
and spent its first turn discovering the gap and filing a blocked
decision for what was a render defect. The seed's remote-copy rewrite now
maps the inbox to the route's host-local parent-route inbox, exactly as
it already maps the reply-log path, so every mention - bare path, listing,
and handled/ acknowledgement - lands host-local.
Both rewrites also become plain assignments, because a quoted substitution
nested inside a double-quoted printf argument leaks literal quotes into
the replacement text on stock macOS bash. The lifecycle suite pins the
corrected render both directions against the real seed, provisioning,
and delivery route, sharing one fixture value between the render truth
and the delivery truth.
Closes #5012
* no-mistakes(document): document remote charter's host-local steering inbox
* feat: route Lavish feedback directly to owning workers (#5099)
* feat(procevent): route worker-owned Lavish rounds
* no-mistakes(review): drop duplicate artifact field from task-owned registration
* no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic
* no-mistakes(review): keep worker board owned until terminal round acknowledged
* no-mistakes(review): refuse every retirement of an open worker-owned round
* no-mistakes(review): use real lavish reply flag, isolate reply generations
* no-mistakes(review): drop .posted marker for best-effort reply posting
* no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures
* no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms
* no-mistakes(review): re-arm only to acknowledge an open round
* no-mistakes(review): conclude only a still-open terminal round
* no-mistakes(review): record the acknowledgement before retiring the board
* no-mistakes(review): retain the registration across a conclude, qualify terminal docs
* no-mistakes(document): Document worker-owned Lavish round lifecycle
* fix(bin): fit pull observation within the contribution poll budget (#5107)
* fix(bin): reserve contribution observation budget
* no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget
* feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103)
* feat(bin): add idempotent inbox orders, receipts, replies, and readiness
Let a caller supply a request id when publishing a captain inbox note so a
retry returns the original note instead of creating a second one, including
across the crash window between save and wake announcement. Separate saved
from announced so a failed wake is repairable without enqueueing again.
Add bounded receipts JSON with omission disclosure, a durable primary reply
against a note id, and a read-only readiness projection that can say
unknown instead of inferring liveness from a lock file.
* no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict
* fix(bin): resolve ready from lock-holder ancestry; drop lock status --json
Remove the extra JSON surface from fm-lock.sh so its human status still
always exits zero. Have the readiness projection classify the inspected
home from the lock-holder pid via fm-harness.sh ancestry, with an explicit
FM_SUPERVISION_MODEL still winning and an unknown model when there is no
holder. Prove the yes path when that ancestry names a known harness.
* no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor
* no-mistakes(document): Note read-only lock inspection in scripts inventory
* no-mistakes(lint): Pass missing id argument to malformed-reply test printf
---------
Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com>
* fix(bin): stop harness footer rows below a composer from reading as pending text (#5118)
* fix(composer): stop a harness footer row from reading as a composer holding text
A harness draws its own furniture below the composer - a user statusLine, a
permission-mode hint - and the cursorless "bottom-most shape wins" rule looks
exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text
everywhere else, so a statusLine opening with `→` was selected as a bare
composer, swallowed the hint row beneath it as wrapped input, and answered
`pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that
verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first
doorbell and every retry were skipped and the worker never saw the steer.
Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on
Herdr 0.8.0 had genuinely empty composers and every one of them was refused.
A separator pair that closed over a bare agent-glyph row is a proven composer
container, so the contiguous non-blank rows below its closing rule are that
composer's footer and are no longer composer candidates. The demotion is bounded
by all three of its own preconditions: a blank row ends the zone, a pair that
closed over no glyph row demotes nothing, and a shape with no separator pair at
all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same
composer, including a stray SGR mouse report left by a click in the pane, still
reads `pending`.
Pinned by two portable regressions and by a new cursorless arm on the live
composer-matrix guard, which re-reads each harness's already-proven-idle pane
the way every non-tmux backend reads it and fails naming the harness and
version when that read is `pending`.
* no-mistakes(review): make composer footer-zone demotion shape-independent
* no-mistakes(review): make footer-zone demotion refuse-only and drop rescan
* no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100
---------
Co-authored-by: Koen Muller <koen@catapult.nl>
* feat(bin): append optional home-local include to briefs (#5115)
Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com>
* fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114)
* fix(bin): stop misreading a no-run branch as an unreadable runs table
Defect: when `no-mistakes axi status`'s overview is truncated (a task's
own branch has zero rows among the shown ones), fm_nm_select_run's
Python fallback derived the repo identity for its direct SQLite query
from a `repo: <path>` line it expected in the overview text. The real
CLI never emits that line, truncated or not (see the genuine capture at
tests/captures/no-mistakes-v1.70.1/overview.toon, which has only
`count:`/`runs[...]:`), so the lookup always failed and reported
"unreadable runs table" for a task that simply has no run on its
branch. On a fleet with many concurrent runs, every idle-branch task
hits the truncated-overview path routinely, so this fired every few
minutes and drowned genuine unreadable/blocked verdicts in noise.
Fix: derive the repo identity from the task worktree path instead,
which is exactly the value `no-mistakes` records as a repo's
`working_path` (confirmed against the existing capped-overview test
fixtures, which already register repos by worktree path). A worktree
path that is not absolute cannot be matched and still reads as
unreadable rather than being guessed at. Also raise the reader's
SQLite busy timeout from 1s to 30s so ordinary lock contention on a
busy fleet cannot masquerade as an unreadable database.
Safety: every other verdict byte-for-byte unchanged - the repo lookup
still requires exactly one matching row (a genuinely corrupt or
mismatched repos table still reports unreadable, per the existing
`repo` failure-mode test), the branch query and row validation are
untouched, and a zero-row result for the branch still flows through
the same recursive re-parse that already turns an empty `runs[0]{...}`
table into `absent`. Added a regression test
(test_capped_overview_without_repo_line_and_no_runs_reports_absent)
that reproduces the real overview shape - capped, zero rows for the
task's branch, no `repo: ` line - and asserts the crew state falls
through to the pane/busy verdict instead of reporting unknown or
"unreadable". Full fm-crew-state.test.sh suite passes unchanged
otherwise.
* fix: recovered same-branch inventory awk misreads empty result as unreadable
fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:`
overview and re-runs it through the same awk selection pass. When that
rebuilt inventory has zero rows for the branch, the row-matching loop never
executes, so its counters (`seen`) stay at awk's uninitialized empty string
while `expected` and `shown` are plain strings parsed from the header text.
Comparing an uninitialized value against a non-numeric string uses string
comparison, so "" != "0" is true, and the END block takes the "unreadable
runs table" branch instead of falling through to the correct "absent"
verdict for a branch with genuinely zero runs.
Coerce the affected END comparisons with `+0` so they are always numeric,
matching seen/expected/shown/total regardless of whether awk classified
them as strings or numeric strings. A truncated or genuinely malformed
inventory still differs numerically and still reports unreadable.
* no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup
* no-mistakes(review): match recorded repo path first, tolerate duplicate spellings
* no-mistakes(review): revert repo lookup to exact working_path match
* no-mistakes(document): note state-db inventory read under crew-state nm timeout
* fix(bin): require a non-draft pull request before a PR-based done report (#5141)
* fix(bin): require a non-draft pull request before a PR-based done report
A PR-based ship could report done, and merge monitoring could be armed, while the pull request was still a draft. A draft cannot be merged, so the poll waited for an event that could not occur and nobody was asked to merge.
The PR-based definitions of done now require reading the pull request back from the forge and confirming it is not a draft, and a lane that deliberately holds a draft declares a wait instead of done.
bin/fm-pr-check.sh refuses to arm merge monitoring on a draft, naming the draft state, and treats an unreadable draft state as before.
The draft reading now lives in bin/fm-pr-lib.sh and bin/fm-pr-merge.sh uses it, with its refusal to merge a draft unchanged.
Closes #4757
* fix(review): Skip arm-time draft refusal when fm-pr-merge records metadata
* fix: support quota-axi schema 6 snapshots (#4904)
* fix(bin): accept quota-axi schema 6 snapshots keyed by provider + accountKey
quota-axi 0.1.47 emits schemaVersion 6 once a provider expands to more
than one account: every provider row carries an accountKey and one
provider id may appear on several rows. fm_quota_json_valid accepted
only schema 5 with unique provider ids, so fm-dispatch-resolve.sh,
fm-quota-choose.sh, and fm-procevent-quota.sh all rejected the live
snapshot and quota-informed dispatch was dead against the current tool.
- bin/fm-quota-axi-lib.sh: the validator accepts schema 6 with
accountKey required on every row and uniqueness on
provider + accountKey; schema 5 keeps its exact rules. FM_QUOTA_ROW_JQ
is the one join every consumer uses: schema 5 binds by provider alone,
schema 6 binds to the row keyed by the candidate's Pi lane, else the
provider's default row, else no row (unmeasured, never blocked, never
by position or summed across accounts).
- bin/fm-quota-choose.sh: accepts schema 6 JSON and the TOON accountKey
column, and joins through the shared function.
- bin/fm-dispatch-resolve.sh and bin/fm-procevent-quota.sh: join through
the shared function; an expanded provider with no row for the
candidate's account is reported as such.
- tests: schema 6 fixtures shaped like the real snapshot, each paired
with a schema 5 case on the same path; every new case fails on the
previous scripts and passes now.
- docs: the two sentences naming the row join describe the schema 6 key.
* no-mistakes(review): Fix native Codex quota and expanded provider watches
* no-mistakes(review): Align native Codex account matching across dispatch paths
* no-mistakes(document): Align quota documentation with account-aware snapshots
* no-mistakes(document): Align quota dispatch documentation with account matching
* fix(bin): keep CI lint and the quota watch test portable
- bin/fm-quota-axi-lib.sh: FM_QUOTA_ROW_JQ is read only by the scripts
that source this library, so full-mode ShellCheck reported SC2034 on
the assignment; mark it alongside the existing SC2016 disable.
- tests/fm-procevent-quota.test.sh: the schema 6 provider-watch
assertions used rg, which CI runners do not install, so the case
failed with 'rg: command not found' rather than on behavior; use grep
like the rest of the file.
* no-mistakes(document): Documented schema-version account-row compatibility
* test: fix Claude session-start drain live E2E (#5165)
* test: repair Claude live auto-arm regression
* no-mistakes(review): Assert SessionStart digest completeness within its hook_response event
* no-mistakes(document): Consolidate Claude live verification references
* ci: pin the no-mistakes required check to v1.80.1 (#5195)
Roll the shared require-no-mistakes action to the tagged v1.80.1 SHA and grant pull-requests: read so the check can read PR bodies.
* fix(bin): retain Pi watcher predecessor to stop false down alarms (#5174)
* fix: preserve Pi watcher ownership across session replacement
* no-mistakes(document): Scope Pi predecessor retention away from omp
* no-mistakes(ci): Diagnosed all three failing checks; only one was code-caused. (ci-3, genuine) Stock macOS Bash snapshot compatibility: `tests/fm-pi-watch-extension.test.sh` failed the macOS Bash 3.2 `bash -n` parse sweep with `line 4265: unexpected EOF while looking for matching '`. I built GNU Bash 3.2.0 from source locally and reproduced it. Root cause: the PR added a comment containing an apostrophe (`// Replacement shutdown deliberately retains module 2's established arm until`) inside a quoted here-document (`<<'EOF'`) nested inside a `$(...)` command substitution. Bash 3.2 has a parser bug (fixed in later bash) where an unmatched single quote inside such a here-doc body is treated as opening a shell quote and never closed, aborting the whole file parse. The base commit parses cleanly under Bash 3.2, confirming this PR introduced the break. Minimal fix: reworded the comment to remove the apostrophe (`... retains the established module-2 arm until`), preserving meaning. Verified `bin/fm-lint.sh --list-files` (the 6 changed shell files) now all pass `/tmp/bash-3.2/bash -n`; Bash 5 also parses. (ci-1, infrastructure) Behavior portable serial 8: GitHub API shows the `Run portable serial shard 8` step conclusion=success; only `Upload portable serial shard 8 timing artifact` failed with `Failed to FinalizeArtifact ... (403) Forbidden`. This is a transient artifact-service/cancellation failure, not a test or code failure. No change. (ci-2, infrastructure) Lint 1: fetched the job log via the GitHub API; it ends with `##[error]The runner has received a shutdown signal...` then exit 143. The step was cancelled mid-run, not a ShellCheck finding. Independently ran `bin/fm-lint.sh --partition 1of2 --telemetry ...` locally with pinned ShellCheck 0.11.0 and actionlint 1.7.12: exited rc=0 (no findings). No change. The only code change is the apostrophe removal in tests/fm-pi-watch-extension.test.sh; no other files modified
* fix(bin): allow cleanup of windowless legacy task records (#5236)
* fix(bin): retire windowless leftovers and stop claiming a Pi daemon teardown
Catch-up correctly refuses while a leftover task record has no status file.
Cleanup used to deadlock on those same records when they also had no spawn_gen and no window, so they lingered and wedged every later away-mode return. Teardown now treats a windowless leftover as a missing-endpoint legacy record, and stop reports that no daemon terminal was running when none was launched.
Co-authored-by: Cursor <cursoragent@cursor.com>
* no-mistakes(review): Narrow windowless teardown exception to tmux legacy leftovers
* no-mistakes(review): Validate windowless leftover identity via shared endpoint validator
* no-mistakes(review): Refuse windowless leftovers carrying other backends' endpoint identity
* no-mistakes(document): Clarify windowless teardown retry documentation
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* ci: exempt kunchenguid from the no-mistakes required check (#5256)
* fix(bin): surface launches parked on an interactive prompt as not-started (#5250)
* fix: surface parked launch prompts as not started
* no-mistakes(document): docs: record launch-prompt busy backstop classification
* no-mistakes(document): docs: align tail40 and rendered-text comments with launch-prompt backstop
* fix: record away posture immediately on /afk (#5260)
* feat(afk): make /afk itself the go with a same-turn record write
Collapse the propose-then-confirm away entry into one 'enter' step that
writes state/.afk-contract immediately and prints the announcement and
read-back after the record exists, never asking for a go. The retired
propose, confirm, and --proposal inputs are refused by name, and a stale
proposal left by an older version is removed rather than promoted.
Refresh and replace semantics, verbatim words, the single writer, the
never-set, and per-harness launch behavior are unchanged.
* no-mistakes(document): Refresh away-entry documentation evidence
* fix(bin): recognize passed-with-override as a passing outcome (#5294)
* fix(bin): map passed-with-override to done instead of unknown
no-mistakes' axi status emits outcome: passed-with-override for a run
that finished with an explicitly approved Test or CI exception. Both
bin/fm-crew-state.sh's outcome resolver and bin/fm-teardown.sh's
pre-teardown terminal-run check only matched the literal passed and
checks-passed tokens, so this outcome fell through to unknown/parked
and a finished worker awaiting merge kept getting re-alerted as stale,
while an abort race during teardown could also leave a finished run
misreported as still parked.
Map passed-with-override to the same done/terminal handling as a
clean passed in both places.
* fix(document): Replace stale outcome mapping with authoritative pointer
* fix(ci): Fixed a pre-existing mock-clock race in tests/fm-contributions.test.sh by advancing time only during the serial issue read. Reproduced the exact CI failure before fixing it. Forced-race replay, all 38 contribution scenarios, scoped ShellCheck, Bash syntax, and diff checks pass. Only the test fixture changed; CI rerun remains with the outer executor
* fix: clean up workers after their pull requests land (#5317)
* fix: close landed workers from supervision in both postures and at return
During the 2026-09-22 away window every exemption worker whose pull request
had merged was left sitting for nine hours. The supervision branch received
the stale wake, the merge-landed check, and the hourly inactive-outcome row
for each of them, ran the recovery playbook, found nothing to recover, and
reported "no further action". The branch prompt granted ordinary teardown of
a confirmed-landed task without ever naming the moment or the command, and
the playbook has no landed exit, so the stale path ended at "nothing to
recover". The return brief then listed only blockers, decisions, and the
latest five routine outcomes, so the landed workers stayed invisible after
the captain came back.
- bin/fm-branch-prompt.sh: name the merge-landed wake, and any later stale,
inactive-outcome, or heartbeat row on a done task with a merged PR, as the
moment to claim the lease and run bin/fm-teardown.sh with no flags; a
refusal is reported, never forced or worked around. Add teardown to the
handling tool list.
- stuck-crewmate-recovery: a landed worker is not a recovery case; point at
the ordinary teardown owner for each actor.
- bin/fm-afk-return.sh: render a "Landed, cleanup due" section from durable
records only (a live task record whose recorded PR carries the
merge-notification marker), between could-not-fix and handled, without
holding the gate; the afk skill's return step closes each listed task
through ordinary teardown once the check clears.
- tests: pin the prompt rule in fm-branch-supervision and the brief section
in fm-afk-return through the real marker writer.
* no-mistakes(document): Document landed-task cleanup ownership
* fix: surface green no-mistakes PRs awaiting merge (#5327)
* fix(bin): surface a green no-mistakes PR still in ci merge monitoring
A green PR could sit unreported because neither the worker nor the
supervisor could observe checks-green while the ci step kept monitoring
for the merge.
Supervisor read: fm_nm_select_run's capped-overview inventory reader looked
the repository up by the task worktree path, but no-mistakes registers a
repository once by its main clone path and resolves every linked worktree
to it, so on every task copy of a busy repo the lookup matched no row and
each read reported "complete same-branch run inventory unreadable". Key the
lookup on the overview's own top-level `repo:` line, which every axi
release emits as the resolved working_path.
Even with a readable run, the ci-log classifier treated "base branch
advanced ..., re-arming CI monitor timeout" as not-ready. The monitor logs
a checks state only when it changes and a base advance does not clear
readiness, so a green PR read as still validating for as long as main kept
advancing. Stop treating that line as a marker, matching no-mistakes' own
ci-log parser, and name the run's PR URL in the held-for-merge reading so
the existing inactive-outcome path can act on it without a worker report.
Worker contract: `axi status` never reports checks-passed while the ci
step monitors for merge, so the definition of done no longer makes a
status poll the wait for the next gate or outcome; the drive call's own
return is the green signal, reattached with `no-mistakes axi run` after a
bounded return.
* no-mistakes(review): read the full ci log when checking checks-green
* no-mistakes(review): correct stale ci log tail wording in docs
* no-mistakes(document): Document checks-green supervisor fallback
* fix: derive Lavish polling route from board session (#5334)
* fix: derive Lavish polling server from its board session
* no-mistakes(document): Document session-derived Lavish polling
* no-mistakes(document): Correct Lavish routing verification claims
* fix(bin): stop secondmate relaunch failing when watcher scratch files vanish (#4900)
* fix(bin): ignore vanished state scratch files on secondmate relaunch
Relaunch refused when find(1) exited non-zero while listing a secondmate
home's state directory. A live watcher can delete scratch files between
readdir and processing, which is not evidence that child *.meta records
are unreadable.
Prove the directory is listable from its mode and keep the existing
readable-meta loop as the child-record guarantee. Fixes #4765.
* no-mistakes(review): Skip chmod-000 unlistable-state relaunch test when running as root
* fix(bin): stop each keyed answer from re-waking this home (#4907)
* fix(bin): treat home-owned status closes as already read
Self-announced bookkeeping appends now record their exact byte ranges.
Later drains and signal scans skip those ranges, so two distinct
--resolve-key answers after an OPEN DECISIONS fold do not each wake the
supervisor. Worker-authored lines outside that ledger still signal.
* no-mistakes(review): Keep owned closes in unread status; lock ledger writes
* no-mistakes(review): Drop fold-lag wake suppression so folded worker decisions still wake
* no-mistakes(review): Require real owned growth before ledger marks status seen
* no-mistakes(document): Clarify home-appends ledger scope versus UNREAD STATUS
* no-mistakes(review): Restore fold-lag path, drop owned-range filters, fix test
* no-mistakes(review): Align ledger docs and scope ledger to wake path only
* no-mistakes(review): Restore stranded historical-annotation test comment to its function
* no-mistakes(review): Retire the home-appends lock alongside its ledger
* no-mistakes(document): Note ledger's lock-helper dependency in classify library
* no-mistakes(review): Append-and-coalesce home-appends ledger; fix stamped-line assertions
* no-mistakes(review): Drop redundant empty-span branch; make owned test pin ledger
* no-mistakes(document): Document covers' ascending-order dependency on home-appends ledger
* no-mistakes(document): Note owned-append skip in watcher signal-scan comment
* fix: deliver failed public follow-ups with updated AXI floors (#5350)
* chore(bin): raise tasks-axi, quota-axi, and lavish-axi floors to latest
Raise the minimum versions to tasks-axi 0.2.6, quota-axi 0.1.50, and
lavish-axi 0.1.77, pin CI's tasks-axi install to 0.2.6, and move the
floor-boundary test fixtures to the new versions.
tasks-axi 0.2.6 makes a failed relation deliverable for a promised-final
expecting pr-merged, so add the regression test: a bound work that ends
failed reports its honest outcome text through fm-public-followup-emit.sh,
consume marks the commitment ready, and deliver posts that text exactly
once.
Also make two hang-guard tests in fm-backlog-atomicity portable to hosts
without coreutils timeout, and stop an installed herdr from leaking into
the secondmate-liveness husk classifier test.
* no-mistakes(review): drop out-of-scope bounded_run hang-guard helper from atomicity test
* no-mistakes(review): pin quota-axi floor at 0.1.49 across fixtures
* no-mistakes(document): Document failed public-followup delivery behavior
* no-mistakes(ci): Updated quota-axi floor and all 0.1.49 fixtures to 0.1.51, corrected bootstrap boundaries to 0.1.51/0.1.52/0.1.50, and bumped the bearings lavish-axi stub to 0.1.77. Bearings, quota procevent, quota chooser, startup budget, and bootstrap floor coverage passed; the full bootstrap suite exceeded the 240-second local command limit after relevant checks passed. git diff --check passed
* fix(bin): refuse ship done: when the named head exists only in the worker copy (#4878)
* fix(bin): refuse ship done: when the named head lives only in the worker copy
A ship done: is not current-state done until that exact commit is reachable
outside the disposable copy. The check tests t…
mituso89
pushed a commit
to mituso89/firstmate
that referenced
this pull request
Sep 26, 2026
…#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation
Boxyboxy
added a commit
to Boxyboxy/firstmate
that referenced
this pull request
Sep 26, 2026
* fix(bin): create captain-hold rows when Beads requires due (#4854)
Captain holds have no due semantics and are a hold kind, not a Beads issue
type. The create path now waives due.required and maps to native type task.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: disable compact adviser for spawned agents (#4877)
* feat(bin): launch every spawned agent with the compact adviser disabled
Every crewmate, scout, and secondmate Firstmate launches now starts with
COMPACT_ADVISER_DISABLE=1, on a fresh spawn and on a relaunch alike, so an
unattended session never activates the compact adviser.
The value is unconditional: no configuration file gates it and there is no
override, unlike the trace carrier beside it.
Three carriers deliver it, because no single one covers every launch shape.
The pane shell receives an export beside GOTMPDIR, so the agent's own children
inherit it too.
The launch command carries an explicit assignment, prepended outermost so it
wins over any ambient value the pane already held.
The cleared launch environment sets it again at the `env -i` boundary and keeps
COMPACT_ADVISER_DISABLE in the fixed operational floor, which is what preserves
the switch when config/launch-env-allowlist empties the environment, and what
delivers it on a remote host that never had the value.
bin/fm-control.sh relaunch, the bootstrap secondmate relaunch, and the remote
secondmate transport all rebuild their launch through bin/fm-spawn.sh, so they
inherit the same floor.
The captain's own primary session is untouched.
The two new suites drive the real spawn and then execute the launch command the
pane actually received, with the harness replaced by a probe that prints its own
environment, rather than matching script text.
They cover ship and secondmate launches with the allowlist absent and enabled,
the pane export and its ordering, fm-control.sh relaunch, and the full parent to
remote-host chain.
* no-mistakes(review): Export compact-adviser disable across compound launches
* no-mistakes(document): Document spawned-agent compact-adviser environment guarantee
* fix(bin): preserve Claude lock ownership after helper recycling (#4894)
* fix(bin): let a background Claude session keep owning its session lock
Session-lock ownership was decided by process ancestry alone. Under an
unattended Claude session the model loop runs in a transient bg-spare
bridged to the front-end by a shared daemon; when that bridge is
recycled the contiguous claude-named ancestry from a hook to the
recorded owner breaks while the owner pid stays alive, so the Stop
auto-arm stood down as a foreign live owner, the turn-end guard ended
every turn with its read-only diagnostic, and fm-lock.sh refused - a
self-sustaining outage until restart.
Ownership is now ancestry membership OR a trusted same-session id,
never id-first:
- fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when
CLAUDE_PID is a Claude-shaped member of the current contiguous run,
compares it against the id recorded in state/.lock-session, and
requires the recorded pid to still be a live harness. No id, no
sidecar, an untrusted id, a different id, or a dead recorded pid
leaves the ancestry verdict unchanged. Ids are never read from ps
argv.
- fm-lock.sh accepts a same-session holder at both refusal sites,
writes, refreshes, and clears the sidecar only under its claim lock
(including the early already-mine exit, skipped only while the
deferred startup sweep leases that lock), keeps it byte-identical
across a same-session confirmation, records CLAUDE_PID on lock line 1
for a session with a trusted id so a shared daemon or front-end that
outlives the session never keeps a dead session's lock alive, never
rewrites a live line 1 on a same-session confirmation, and names the
recorded id in the live-owner refusal.
- The .lock line-1 format is unchanged, so every reader that takes the
whole first line as the pid keeps working; the guard's foreign-owner
exit is unchanged and inherits the fix through the shared predicate.
Tests: the ancestry suite drives the ancestry and id signals apart in a
deterministic process table (asserting the divergence) and runs a real
orphaned front-end/daemon/pty-host/spare tree through six phases with
the real lock, auto-arm, and guard scripts; the foreign-owner repro
keeps its negative control and adds a same-id positive control.
Disclosure: no live unattended Claude background session ran on the
verifying machine. The topology is documented by the real process
listings in #3902, #2314, #3398, and #4066; coverage is the structural
predicate plus the executable fixtures, not a live pass.
Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry
walk (it only decides whether to print a nudge) and may nudge on a
resume in the recycled case.
Out of scope, deliberately: no structured lock format, no guard budget
changes, no daemon-identity rejection, no fork lineage.
* no-mistakes(review): Wait for claim lock; revert failed sidecars
* no-mistakes(review): Revalidate ownership after wait; restore sidecars
* no-mistakes(review): Roll back sidecar by publication phase
* no-mistakes(review): Restore sidecar only if lock line is unchanged
* no-mistakes(review): Trust session ids without a spelling allowlist
* no-mistakes(review): Disarm sidecar rollback before backup cleanup
* no-mistakes(document): Updated session-lock ownership documentation
* feat: park main under the away posture on Pi (#4889)
* feat: park main under the away posture on Pi
While the away-posture record exists on a Pi primary, the supervision branch
takes every actionable wake, no processing turn opens on main, captain rows
accumulate for the return brief, and main's standing authority relocates to
the branch through the existing guarded scripts.
- lib/fm-branch-dispatch.ts: read the record at every routing decision; while
it exists claim check, decision-owned, and heartbeat rows too, keeping the
two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task
scoping.
- fm-primary-pi-watch.ts: offer every actionable row under the record; a
declined wake and every watcher-failure alarm still reach main.
- fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed
POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no
processing request while the record exists, re-checked immediately before a
request would open and at every run boundary; present the accumulated rows
at the first run boundary after archive.
- fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in
actions only while fm-afk-contract.sh validate succeeds on a confirmed live
record; PR merge, fresh spawn, and decision answer opt in, local landing
never does.
- fm-send.sh: a --resolve-key naming an open needs-decision or captain-held
task is a decision answer and meets the partition; blocked: keys stay
steering.
- fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by
either actor; relaunches and secondmates exempt.
- fm-branch-prompt.sh: fixed Postures section and the verbatim
ask-user-authority policy; the prefix stays byte-stable.
- fm-afk-return.sh: count what the away session handled from the store.
- docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate
absolute while away.
- tests: watcher and branch extension suites, fleet-record, merge, and
decision-answer suites cover the relocation, the vetoes, the tail, the
parked processing turn, the cancellation, the re-presentation, and the
spend cap; dated live-guard evidence recorded.
* no-mistakes(review): Refuse branch merge after preflight archive race
* no-mistakes(review): Fix away wake, spawn, and processing races
* no-mistakes(review): Suppress parked processing; narrow away-only rejection
* no-mistakes(review): Abort dedicated processing; gate branch spawn once
* no-mistakes(review): Stamp away-only on the dispatch offer
* no-mistakes(review): Treat invalid away records as spend-cap absence
* no-mistakes(review): Drop spawn test hook; abort processing-opened runs
* no-mistakes(review): Bind abort to opening prompt; cap-read absence
* no-mistakes(review): Limit away branch spawn to queued work only
* no-mistakes(document): Correct AFK posture documentation
* ci: standardize workflow timeouts into three tiers (#4910)
* ci: simplify CI job timeouts to a three-tier policy
Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m
serial, 10m macOS) with three readable tiers, each a hang tripwire with
headroom rather than a packing estimate:
- fast (5m): coverage guard, repo invariants, timing aggregate
- normal (30m, one shared budget): lint partitions, portable parallel
shards, portable serial shards, macOS stock Bash
- heavy (Herdr only): 20m step tripwire on the family run so always()
cleanup still runs, under a 75m job-level last-resort backstop
The workflow's header comment states the policy and points at
docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each
job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh
asserts the policy against the parsed workflow instead of the old
per-job minute values: every job joins exactly one tier, exactly three
distinct job-level values exist, the fast tier stays within 5-10
minutes, the normal budget stays at least double the modeled parallel
lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step
tripwire stays below its job backstop with an always() cleanup after it.
Concurrency supersession, shard counts, lane membership, and fail-fast
settings are unchanged.
* no-mistakes(review): Decouple the normal timeout from packing estimates
* no-mistakes(review): Assert Herdr teardown follows the family run
* no-mistakes(review): Pin Herdr family-run timeout to 20 minutes
* no-mistakes(review): Ignore comments when identifying Herdr steps
* no-mistakes(review): Identify Herdr steps by declarative ids
* no-mistakes(document): Clarify authoritative three-tier timeout policy
* fix(bin): keep supervisor status closes from waking the same home (#4895)
* fix(bin): keep supervisor status closes from waking the same home
A drain that already folded OPEN DECISIONS has presented those bytes even
when the watcher has no matching seen marker. Treat that fold, and the
presentation cursor, as known so the bookkeeping close stays quiet while
later worker lines still signal.
* no-mistakes(review): Keep folded worker failures waking past supervisor closes
* no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes
* no-mistakes(review): Stop folded worker resolved lines from counting as already read
* no-mistakes(document): Correct self-announced close marker contract in docs
* fix(bin): stop labeling Herdr as experimental (#4972)
* Stop steering operators away from Herdr
* no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording
* fix(bin): treat a live no-mistakes run as current after rebase (#4973)
* fix(bin): treat a live no-mistakes run as current after rebase
A running run on the task's branch is authoritative regardless of head.
Matching only the local head made a rebased in-flight run look failed.
* no-mistakes(review): restrict coarse live-any-head to foreign-branch answers
* no-mistakes(review): reject gate-parked runs from the executing predicate
* no-mistakes(review): hoist gate-marker patterns into single run-lib owner
* no-mistakes(review): require live daemon for head-free run binding
* no-mistakes(review): require answered daemon-down before unbinding live runs
* no-mistakes(review): extend daemon guard to anchored continuation routes
* no-mistakes(review): delete live-any-head; restore dead-daemon verdict
* no-mistakes(review): keep parked gates parked; name dead daemon everywhere
* no-mistakes(review): set dead-daemon verdict instead of emitting early
* no-mistakes(review): align selected route with legacy dead-daemon handling
* no-mistakes(review): drop unproven-record binds; narrow coarse gate reading
* no-mistakes(review): narrow header, drop vestigial guard, retarget tests
* no-mistakes(review): revert coarse gate override; require answered-down probe
* no-mistakes(review): cache one daemon probe; stop duplicating run id
* no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows
* no-mistakes(review): delete coarse dead-daemon extension and gate note
* no-mistakes(review): delete remaining coarse dead-daemon block and stale docs
* no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict
* fix(bin): prevent long worker launch command truncation (#4994)
* fix(bin): stage the launch command in a private file and type a short source line
A long launch line typed while the fresh pane shell is still busy waits in the
terminal's canonical line buffer, which drops input past about 1,024 bytes on
macOS, so the pane was left at an unfinished command with no agent running.
fm-spawn now writes the assembled command to the task's own temp root under
umask 077 and types only a short line that sources it.
Refs #4559
* fix(bin): keep the per-task temp root private before staging the launch command
The root lives at a predictable path under /tmp and now holds the whole launch
command. Create it with mode 0700, refuse one that already exists as anything but
a directory owned by this user that nobody else can write, and tighten an owned
one, so no other local user can plant or swap the staged file.
Refs #4559
* fix(bin): enforce private staged launch file mode
* test(spawn): cover long staged Claude launches
* no-mistakes(review): Namespace launch files and prove truncation staging
* no-mistakes(review): Use immutable per-spawn launch filenames
* no-mistakes(document): Document staged launch delivery safeguards
* no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass
---------
Co-authored-by: Vytautas Stankus <svycka@gmail.com>
* test: authorize isolated Herdr lab validation (#4998)
* Add isolated Herdr runbook to test instructions
* no-mistakes(review): Drop substring matching from test.instructions contract
* no-mistakes(review): Assert commands.test key absence in YAML
* Drop unit-first sentence and instructions contract test
Captain-scoped follow-up on the Herdr-lab test.instructions ship:
keep the lab safety runbook only, and leave the no-mistakes contract
test focused on commands.test absence.
* docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (#5001)
* docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (#4873)
Replace the pixels-of-today's-UI rule with a quarantined, version-pinned
surface-adapter exception recorded as standing debt. Cap the always-loaded
contract at 9,000 words and require prune-or-trigger before a crossing change
lands.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* docs(vision): restore accepted three-sentence vendor-semantics form (#4873)
Replace the compressed paraphrase with the issue's accepted wording:
a named quarantined version-pinned adapter, expected to break, recorded
as standing debt that never hardens into a shared contract.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974)
* fix(watch): recheck a gate awaiting a human instead of wedge-escalating it
A lane whose validation run is parked at a gate waiting on a human
decision is correctly quiet, but nothing in its status line says so: the
evidence is the pipeline's own gate state rather than anything the worker
wrote. The wedge timer read that silence as a suspected wedge and climbed
the escalation ladder for as long as the wait lasted, and each escalation
cost a supervising turn. The landed declared-wait consult does not reach
it, because a live ordinary crewmate never reports a declared pause, and
raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for
every lane by the same amount.
The threshold now reads a second, independent record when the status line
accounts for nothing: whether the crew's current state is a gate whose
answer is owed by a human. That is minted only from the gate's own
findings table, by a row whose `action` column is exactly `ask-user`,
located by position out of the table header the way nm_gate_step_row
already reads its row - never searched for over the run payload, where a
finding's free-text description or a branch name satisfies a search just
as well. A gate awaiting the CREWMATE's own answer keeps the unchanged
escalation schedule, reason and demand-deep-inspection wording, because a
crewmate that goes quiet before answering its own gate is exactly the
wedge the ladder exists to catch.
Each kind of wait now carries the human it is on, the action that clears
it, and whether that human is the captain as data alongside the verdict,
rather than as wording chosen per branch where the recheck is written, so
the deferral cannot word one kind of wait as another and a new kind
cannot ship without deciding all of them. A parked gate has no written
record of when its wait began, so its recheck publishes no wait age at
all rather than one read from the quiet window this deferral resets on
every pass, which would report the same small number for a gate of any
age. Like every other captain-facing recheck here it is absorbed in
silence while the away-posture record exists, arming no throttle, so the
recheck is owed in full the moment the record is archived.
The consult runs only in the at-threshold branch that was about to
escalate, beside the worktree walk already there, and only for lanes
whose status line explained nothing.
Closes #3055
* no-mistakes(review): require an unanswered decision before deferring a parked gate
* no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records
* test(watch): pass the pane hash wedge_timer_check now takes
Upstream gave wedge_timer_check a sixth <pane-hash> argument for its
dead-record probe. The malformed-wait-record rounds drive the real function
directly, so they pass one, and stub fm_backend_agent_state to a live agent so
the probe that runs after a refused deferral keeps the unchanged ladder rather
than reading a backend the child shell has none of.
* no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate
* no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling
* feat(watch): make the parked-gate wait deferral opt-in
The wedge timer deferring a lane parked at a validation gate is new
supervision behaviour rather than a restored one, and it decides which
lanes give up the escalation ladder, so it now ships as a default-off
per-home option instead of changing every home on upgrade.
config/wedge-defer-parked-gate arms it. The flag is read before the
decision fold, so an unconfigured home spends no fold or current-state
read, writes no record, and keeps the unchanged escalation schedule,
reasons and demand-deep-inspection wording; a test counts the reader
calls in both directions to pin that.
It is not inherited by secondmate homes: each home supervises its own
crew and owns that trade separately, the same reason
config/turnend-churn-absorb is home-local.
The away-posture absorb returns to leaving the idle timer alone, which
it had restarted only because the costly consult could reach it. A
parked-gate wait is owed to the supervisor rather than the captain, so
it never enters that branch, and the recheck owed on return is again
owed in full the moment the record is archived.
* test(watch): pin that the away-silenced hold leaves the idle timer alone
The absorb no longer restarts the timer, so the recheck owed on return is
owed in full rather than a cadence into the return. Nothing asserted
that, so a restart could be reintroduced silently.
* no-mistakes(review): document away-silence rationale, pin captured gate component
* no-mistakes(test): anchor gate row scan to the braced findings header
* no-mistakes(document): pin same-block gate row invariant in crew-state comment
* fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
* fix(control): let the owning seat reclaim a task whose endpoint is gone
A destroyed pane or workspace made `missing` a terminal state. Relaunch
accepted only `dead` and said to stop the agent first; exit refused
`missing` and said to reconcile the task first; there is no reconcile
verb. Each command named the other as its prerequisite, so a task whose
terminal went away could not be reclaimed by anything, and a no-mistakes
approval it was parked on had no seat left to answer it.
`missing` is agent-free a fortiori: there is no endpoint, so there is no
agent in it. Widen the existing guards rather than add a verb.
- fm-spawn --relaunch accepts a positively proven `missing` and creates
one fresh endpoint in the recorded worktree; the record it already
republishes rebinds the task to it. A `dead` endpoint is still adopted
in place.
- fm-control exit reports `endpoint-gone` instead of dying, so the
relaunch transaction's stop step no longer dead-ends, and re-resolves
the endpoint from the record before verifying the replacement.
The duplicate-agent refusal is untouched: both verdicts come from the
same recovery-grade classifier, which claims `missing` only from positive
absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The
backends' own create paths refuse a live same-labeled endpoint as a
second independent guard. The worktree, its branch, commits, uncommitted
changes, armed poll and registration, record rows, and status log are all
untouched - a reclaim is a recovery, never a teardown.
A secondmate is excluded: its gone-endpoint recovery already has one
owner in the session-start liveness sweep, so relaunch refuses and names
it rather than becoming a second path to the same outcome.
Tests reproduce both halves of the deadlock, the reclaim succeeding,
unlanded work surviving it, and the refusals that still hold.
* no-mistakes(review): prove endpoint absence per backend before reclaim rebinds
* no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session
* no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly
* no-mistakes(review): stop refusals and docs asserting unestablished causes
* no-mistakes(review): stop herdr fixture helper losing tmp-root registration
* no-mistakes(review): document workspace drift and absence-probe server residue
* no-mistakes(review): correct rebind limitation to its one reachable case
* no-mistakes(review): stop claiming reclaim leaves instructions untouched
* no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage
* no-mistakes(rebase): read the staged launch file in the herdr fixture
Rebasing onto main picked up #4994, which stages a long worker launch
command into a script and delivers the short `. '<path>'` line instead of
the literal command. The tmux fake and tests/fixtures.sh were updated for
that; the herdr fake this branch adds was written before it and still
keyed "an agent now exists on this pane" off the literal
`encode launch-brief` text, so after the rebase it never marked the
rebound pane live and the reclaim's alive-wait read `dead`.
Dereference the staged file first, exactly as the tmux fake above does.
Test-fixture only; no production path changes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(document): note reclaim placement in herdr and scripts inventories
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(bin): stamp status events with their emission time (#3764)
* test(status): reproduce missing event emission time
* wip(status): preserve optional event emission time
* test(status): document indirect clock stub invocation
* no-mistakes(review): Preserve historical status bytes during reply recovery
* no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies
* no-mistakes(review): Preserve captain regex overrides for timestamped status events
* no-mistakes(document): Clarify status event timing and publication contracts
* no-mistakes(lint): Quote literal done to satisfy ShellCheck
* no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed
* no-mistakes(test): Preserve terminal notifications with malformed timestamp tags
* no-mistakes(test): Stamp Rovo spawn failures with emission time
* no-mistakes(document): Verify status event documentation
* no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests
* no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed
* no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed
* no-mistakes(review): Stamp remote escalations at call sites, drop new flag
* no-mistakes(review): Accept stamped escalation and close lines in test assertions
* no-mistakes(review): Restore reserved-key answered-note guard for stamped closes
* test(status): accept optional emission time in PR-provenance assertions
The #4148 provenance test landed on main with exact unstamped greps.
Parent-channel lines from this branch carry [at=<epoch>], so strip only
that tag before the same exact match. No production change.
* no-mistakes(review): Accept stamped ready signal in PR fallback scrape
* no-mistakes(review): Drop relay flag, stamp parent events at call sites
* no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture
* no-mistakes(review): Accept optional stamp in live cmux drift guard
* no-mistakes(review): Restore original test invocation order in two suites
* no-mistakes(review): Strip only well-formed numeric status time tags
* no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc
* no-mistakes(review): Stamp agy spawn-failure status lines with event time
* fix(bin): normalize status event times in-shell and freeze the budget test clock
Two paths made a status event's emission time cost more than it should.
The captain-relevance fallback piped every line through awk to drop a
well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a
fork per line just to prepare a regex match. Shell parameter expansion does the
same strip with no fork, and the retry-dedup scan now reuses that one helper
instead of carrying a second copy of the rule in awk. The copies had already
drifted: the shell side stripped tags from lines with no colon, which the awk
rule left whole, so a colonless line could be mistaken for one already
recorded. One definition, checked against the awk rule it replaces over the
edge cases and a 4000-line fuzz.
tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In
hang mode the poll set DEADLINE to the real now plus a one-second budget, and
when the second ticked before the first forge call the loop broke without ever
calling gh: forge/calls was never written and the assertion failed reading a
missing file. Freezing the clock in both modes removes the dependence on wall
time; the bounded call is still cut by the real timeout, so the observation the
test asserts still starts.
Emission time stays optional on new status records, and legacy or malformed
lines keep an unknown age.
* no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion
* no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs
* test: fold emission-time snapshot coverage into the fixture case
Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer
touches workflows. Keep every emission-time assertion by folding it
into test_fixture_snapshot_json.
* no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch
* no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape
* no-mistakes(review): strip undelimited at-tags; correct brief stamp header
* no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness
* no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles
* no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb
* no-mistakes(review): read note and key past colon-bearing stamps
* test(status): keep inactive reconcile assertions stamp-tolerant
These two oracles were made stamp-tolerant while resolving one of the
branch's merges from main. The rebase drops merge commits, so that
adaptation was lost and both assertions went back to matching an exact
substring that a stamped line no longer contains: the tag lands before
the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...".
Strip a well-formed tag before matching, as the branch's other oracles do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap
* no-mistakes(document): correct stale unstamped status-line spellings in docs
* no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments
* no-mistakes(ci): rename subshell-local epoch in delivery-race stub
The serialization test overrides fm_pending_reply_mark_delivered inside a
(..) subshell. Its `epoch` local collided with the same name in
status_line_at_epoch/status_stamp_line, which this branch added and this
suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and
failed Lint 2. The stub already prefixes its other locals with `pending_`
for the same reason; `epoch` was the leftover.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(bin): unify Lavish host and disconnect handling (#5060)
* fix: ship clean Lavish host fixes
* no-mistakes(review): Fix Lavish classifications and fail-closed host loading
* no-mistakes(review): Restore Lavish host state across retries and launches
* no-mistakes(review): Preserve destination Lavish host when configuration is absent
* no-mistakes(document): Document Lavish status and host guarantees
* feat: act on captain's away words during AFK supervision (#5076)
* feat(afk): make the captain's away words the whole mandate
Retire the clause fields, verb list, never-set scan, refused records, and
the per-task merge-grant list from the away-posture record. The record is
now version 2: the captain's words verbatim plus expected return, spend
cap, and reach line; a version 1 record still validates, reads, and
archives so a live away window is never broken by the upgrade.
The supervision branch reads the words at the tail of every wake and acts
on them by its own judgment through the guarded scripts under standing
authority, never by analogy, holding for the return on doubt, and opens
each such outcome summary with "per your away instructions:" so the
return brief can render the words beside the session's account. While the
record exists any green merge runs under away authority (ledger tag
"away"); red merges, --allow-red, asynchronous and queued merges, and
local-only landing stay refused. The branch may file a backlog item the
words explicitly call for before dispatching it under the spend cap.
Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and
fm-pr-merge.sh as commands: version 2 written, version 1 read, retired
flags and subcommands refused by name, green merges landing under the
record, red and waived-red refused, the record lock still closing the
authority-read window, and the Pi away tail carrying the words.
* no-mistakes(review): carry the away read-back to the session verbatim
* no-mistakes(review): match the exact away-action marker in the return brief
* no-mistakes(review): refuse a words block truncated by a damaged line
* no-mistakes(document): Refresh away-role contract documentation
* fix(bin): render the remote charter's steering-inbox path host-local (#5049)
* fix(bin): render the remote charter's steering-inbox path host-local
A freshly provisioned remote secondmate read a parent-home absolute
steering-inbox path in its charter - a location that exists on no route -
and spent its first turn discovering the gap and filing a blocked
decision for what was a render defect. The seed's remote-copy rewrite now
maps the inbox to the route's host-local parent-route inbox, exactly as
it already maps the reply-log path, so every mention - bare path, listing,
and handled/ acknowledgement - lands host-local.
Both rewrites also become plain assignments, because a quoted substitution
nested inside a double-quoted printf argument leaks literal quotes into
the replacement text on stock macOS bash. The lifecycle suite pins the
corrected render both directions against the real seed, provisioning,
and delivery route, sharing one fixture value between the render truth
and the delivery truth.
Closes #5012
* no-mistakes(document): document remote charter's host-local steering inbox
* feat: route Lavish feedback directly to owning workers (#5099)
* feat(procevent): route worker-owned Lavish rounds
* no-mistakes(review): drop duplicate artifact field from task-owned registration
* no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic
* no-mistakes(review): keep worker board owned until terminal round acknowledged
* no-mistakes(review): refuse every retirement of an open worker-owned round
* no-mistakes(review): use real lavish reply flag, isolate reply generations
* no-mistakes(review): drop .posted marker for best-effort reply posting
* no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures
* no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms
* no-mistakes(review): re-arm only to acknowledge an open round
* no-mistakes(review): conclude only a still-open terminal round
* no-mistakes(review): record the acknowledgement before retiring the board
* no-mistakes(review): retain the registration across a conclude, qualify terminal docs
* no-mistakes(document): Document worker-owned Lavish round lifecycle
* fix(bin): fit pull observation within the contribution poll budget (#5107)
* fix(bin): reserve contribution observation budget
* no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget
* feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103)
* feat(bin): add idempotent inbox orders, receipts, replies, and readiness
Let a caller supply a request id when publishing a captain inbox note so a
retry returns the original note instead of creating a second one, including
across the crash window between save and wake announcement. Separate saved
from announced so a failed wake is repairable without enqueueing again.
Add bounded receipts JSON with omission disclosure, a durable primary reply
against a note id, and a read-only readiness projection that can say
unknown instead of inferring liveness from a lock file.
* no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict
* fix(bin): resolve ready from lock-holder ancestry; drop lock status --json
Remove the extra JSON surface from fm-lock.sh so its human status still
always exits zero. Have the readiness projection classify the inspected
home from the lock-holder pid via fm-harness.sh ancestry, with an explicit
FM_SUPERVISION_MODEL still winning and an unknown model when there is no
holder. Prove the yes path when that ancestry names a known harness.
* no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor
* no-mistakes(document): Note read-only lock inspection in scripts inventory
* no-mistakes(lint): Pass missing id argument to malformed-reply test printf
---------
Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com>
* fix(bin): stop harness footer rows below a composer from reading as pending text (#5118)
* fix(composer): stop a harness footer row from reading as a composer holding text
A harness draws its own furniture below the composer - a user statusLine, a
permission-mode hint - and the cursorless "bottom-most shape wins" rule looks
exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text
everywhere else, so a statusLine opening with `→` was selected as a bare
composer, swallowed the hint row beneath it as wrapped input, and answered
`pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that
verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first
doorbell and every retry were skipped and the worker never saw the steer.
Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on
Herdr 0.8.0 had genuinely empty composers and every one of them was refused.
A separator pair that closed over a bare agent-glyph row is a proven composer
container, so the contiguous non-blank rows below its closing rule are that
composer's footer and are no longer composer candidates. The demotion is bounded
by all three of its own preconditions: a blank row ends the zone, a pair that
closed over no glyph row demotes nothing, and a shape with no separator pair at
all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same
composer, including a stray SGR mouse report left by a click in the pane, still
reads `pending`.
Pinned by two portable regressions and by a new cursorless arm on the live
composer-matrix guard, which re-reads each harness's already-proven-idle pane
the way every non-tmux backend reads it and fails naming the harness and
version when that read is `pending`.
* no-mistakes(review): make composer footer-zone demotion shape-independent
* no-mistakes(review): make footer-zone demotion refuse-only and drop rescan
* no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100
---------
Co-authored-by: Koen Muller <koen@catapult.nl>
* feat(bin): append optional home-local include to briefs (#5115)
Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com>
* fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114)
* fix(bin): stop misreading a no-run branch as an unreadable runs table
Defect: when `no-mistakes axi status`'s overview is truncated (a task's
own branch has zero rows among the shown ones), fm_nm_select_run's
Python fallback derived the repo identity for its direct SQLite query
from a `repo: <path>` line it expected in the overview text. The real
CLI never emits that line, truncated or not (see the genuine capture at
tests/captures/no-mistakes-v1.70.1/overview.toon, which has only
`count:`/`runs[...]:`), so the lookup always failed and reported
"unreadable runs table" for a task that simply has no run on its
branch. On a fleet with many concurrent runs, every idle-branch task
hits the truncated-overview path routinely, so this fired every few
minutes and drowned genuine unreadable/blocked verdicts in noise.
Fix: derive the repo identity from the task worktree path instead,
which is exactly the value `no-mistakes` records as a repo's
`working_path` (confirmed against the existing capped-overview test
fixtures, which already register repos by worktree path). A worktree
path that is not absolute cannot be matched and still reads as
unreadable rather than being guessed at. Also raise the reader's
SQLite busy timeout from 1s to 30s so ordinary lock contention on a
busy fleet cannot masquerade as an unreadable database.
Safety: every other verdict byte-for-byte unchanged - the repo lookup
still requires exactly one matching row (a genuinely corrupt or
mismatched repos table still reports unreadable, per the existing
`repo` failure-mode test), the branch query and row validation are
untouched, and a zero-row result for the branch still flows through
the same recursive re-parse that already turns an empty `runs[0]{...}`
table into `absent`. Added a regression test
(test_capped_overview_without_repo_line_and_no_runs_reports_absent)
that reproduces the real overview shape - capped, zero rows for the
task's branch, no `repo: ` line - and asserts the crew state falls
through to the pane/busy verdict instead of reporting unknown or
"unreadable". Full fm-crew-state.test.sh suite passes unchanged
otherwise.
* fix: recovered same-branch inventory awk misreads empty result as unreadable
fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:`
overview and re-runs it through the same awk selection pass. When that
rebuilt inventory has zero rows for the branch, the row-matching loop never
executes, so its counters (`seen`) stay at awk's uninitialized empty string
while `expected` and `shown` are plain strings parsed from the header text.
Comparing an uninitialized value against a non-numeric string uses string
comparison, so "" != "0" is true, and the END block takes the "unreadable
runs table" branch instead of falling through to the correct "absent"
verdict for a branch with genuinely zero runs.
Coerce the affected END comparisons with `+0` so they are always numeric,
matching seen/expected/shown/total regardless of whether awk classified
them as strings or numeric strings. A truncated or genuinely malformed
inventory still differs numerically and still reports unreadable.
* no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup
* no-mistakes(review): match recorded repo path first, tolerate duplicate spellings
* no-mistakes(review): revert repo lookup to exact working_path match
* no-mistakes(document): note state-db inventory read under crew-state nm timeout
* fix(bin): require a non-draft pull request before a PR-based done report (#5141)
* fix(bin): require a non-draft pull request before a PR-based done report
A PR-based ship could report done, and merge monitoring could be armed, while the pull request was still a draft. A draft cannot be merged, so the poll waited for an event that could not occur and nobody was asked to merge.
The PR-based definitions of done now require reading the pull request back from the forge and confirming it is not a draft, and a lane that deliberately holds a draft declares a wait instead of done.
bin/fm-pr-check.sh refuses to arm merge monitoring on a draft, naming the draft state, and treats an unreadable draft state as before.
The draft reading now lives in bin/fm-pr-lib.sh and bin/fm-pr-merge.sh uses it, with its refusal to merge a draft unchanged.
Closes #4757
* fix(review): Skip arm-time draft refusal when fm-pr-merge records metadata
* fix: support quota-axi schema 6 snapshots (#4904)
* fix(bin): accept quota-axi schema 6 snapshots keyed by provider + accountKey
quota-axi 0.1.47 emits schemaVersion 6 once a provider expands to more
than one account: every provider row carries an accountKey and one
provider id may appear on several rows. fm_quota_json_valid accepted
only schema 5 with unique provider ids, so fm-dispatch-resolve.sh,
fm-quota-choose.sh, and fm-procevent-quota.sh all rejected the live
snapshot and quota-informed dispatch was dead against the current tool.
- bin/fm-quota-axi-lib.sh: the validator accepts schema 6 with
accountKey required on every row and uniqueness on
provider + accountKey; schema 5 keeps its exact rules. FM_QUOTA_ROW_JQ
is the one join every consumer uses: schema 5 binds by provider alone,
schema 6 binds to the row keyed by the candidate's Pi lane, else the
provider's default row, else no row (unmeasured, never blocked, never
by position or summed across accounts).
- bin/fm-quota-choose.sh: accepts schema 6 JSON and the TOON accountKey
column, and joins through the shared function.
- bin/fm-dispatch-resolve.sh and bin/fm-procevent-quota.sh: join through
the shared function; an expanded provider with no row for the
candidate's account is reported as such.
- tests: schema 6 fixtures shaped like the real snapshot, each paired
with a schema 5 case on the same path; every new case fails on the
previous scripts and passes now.
- docs: the two sentences naming the row join describe the schema 6 key.
* no-mistakes(review): Fix native Codex quota and expanded provider watches
* no-mistakes(review): Align native Codex account matching across dispatch paths
* no-mistakes(document): Align quota documentation with account-aware snapshots
* no-mistakes(document): Align quota dispatch documentation with account matching
* fix(bin): keep CI lint and the quota watch test portable
- bin/fm-quota-axi-lib.sh: FM_QUOTA_ROW_JQ is read only by the scripts
that source this library, so full-mode ShellCheck reported SC2034 on
the assignment; mark it alongside the existing SC2016 disable.
- tests/fm-procevent-quota.test.sh: the schema 6 provider-watch
assertions used rg, which CI runners do not install, so the case
failed with 'rg: command not found' rather than on behavior; use grep
like the rest of the file.
* no-mistakes(document): Documented schema-version account-row compatibility
* test: fix Claude session-start drain live E2E (#5165)
* test: repair Claude live auto-arm regression
* no-mistakes(review): Assert SessionStart digest completeness within its hook_response event
* no-mistakes(document): Consolidate Claude live verification references
* ci: pin the no-mistakes required check to v1.80.1 (#5195)
Roll the shared require-no-mistakes action to the tagged v1.80.1 SHA and grant pull-requests: read so the check can read PR bodies.
* fix(bin): retain Pi watcher predecessor to stop false down alarms (#5174)
* fix: preserve Pi watcher ownership across session replacement
* no-mistakes(document): Scope Pi predecessor retention away from omp
* no-mistakes(ci): Diagnosed all three failing checks; only one was code-caused. (ci-3, genuine) Stock macOS Bash snapshot compatibility: `tests/fm-pi-watch-extension.test.sh` failed the macOS Bash 3.2 `bash -n` parse sweep with `line 4265: unexpected EOF while looking for matching '`. I built GNU Bash 3.2.0 from source locally and reproduced it. Root cause: the PR added a comment containing an apostrophe (`// Replacement shutdown deliberately retains module 2's established arm until`) inside a quoted here-document (`<<'EOF'`) nested inside a `$(...)` command substitution. Bash 3.2 has a parser bug (fixed in later bash) where an unmatched single quote inside such a here-doc body is treated as opening a shell quote and never closed, aborting the whole file parse. The base commit parses cleanly under Bash 3.2, confirming this PR introduced the break. Minimal fix: reworded the comment to remove the apostrophe (`... retains the established module-2 arm until`), preserving meaning. Verified `bin/fm-lint.sh --list-files` (the 6 changed shell files) now all pass `/tmp/bash-3.2/bash -n`; Bash 5 also parses. (ci-1, infrastructure) Behavior portable serial 8: GitHub API shows the `Run portable serial shard 8` step conclusion=success; only `Upload portable serial shard 8 timing artifact` failed with `Failed to FinalizeArtifact ... (403) Forbidden`. This is a transient artifact-service/cancellation failure, not a test or code failure. No change. (ci-2, infrastructure) Lint 1: fetched the job log via the GitHub API; it ends with `##[error]The runner has received a shutdown signal...` then exit 143. The step was cancelled mid-run, not a ShellCheck finding. Independently ran `bin/fm-lint.sh --partition 1of2 --telemetry ...` locally with pinned ShellCheck 0.11.0 and actionlint 1.7.12: exited rc=0 (no findings). No change. The only code change is the apostrophe removal in tests/fm-pi-watch-extension.test.sh; no other files modified
* fix(bin): allow cleanup of windowless legacy task records (#5236)
* fix(bin): retire windowless leftovers and stop claiming a Pi daemon teardown
Catch-up correctly refuses while a leftover task record has no status file.
Cleanup used to deadlock on those same records when they also had no spawn_gen and no window, so they lingered and wedged every later away-mode return. Teardown now treats a windowless leftover as a missing-endpoint legacy record, and stop reports that no daemon terminal was running when none was launched.
Co-authored-by: Cursor <cursoragent@cursor.com>
* no-mistakes(review): Narrow windowless teardown exception to tmux legacy leftovers
* no-mistakes(review): Validate windowless leftover identity via shared endpoint validator
* no-mistakes(review): Refuse windowless leftovers carrying other backends' endpoint identity
* no-mistakes(document): Clarify windowless teardown retry documentation
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* ci: exempt kunchenguid from the no-mistakes required check (#5256)
* fix(bin): surface launches parked on an interactive prompt as not-started (#5250)
* fix: surface parked launch prompts as not started
* no-mistakes(document): docs: record launch-prompt busy backstop classification
* no-mistakes(document): docs: align tail40 and rendered-text comments with launch-prompt backstop
* fix: record away posture immediately on /afk (#5260)
* feat(afk): make /afk itself the go with a same-turn record write
Collapse the propose-then-confirm away entry into one 'enter' step that
writes state/.afk-contract immediately and prints the announcement and
read-back after the record exists, never asking for a go. The retired
propose, confirm, and --proposal inputs are refused by name, and a stale
proposal left by an older version is removed rather than promoted.
Refresh and replace semantics, verbatim words, the single writer, the
never-set, and per-harness launch behavior are unchanged.
* no-mistakes(document): Refresh away-entry documentation evidence
* fix(bin): recognize passed-with-override as a passing outcome (#5294)
* fix(bin): map passed-with-override to done instead of unknown
no-mistakes' axi status emits outcome: passed-with-override for a run
that finished with an explicitly approved Test or CI exception. Both
bin/fm-crew-state.sh's outcome resolver and bin/fm-teardown.sh's
pre-teardown terminal-run check only matched the literal passed and
checks-passed tokens, so this outcome fell through to unknown/parked
and a finished worker awaiting merge kept getting re-alerted as stale,
while an abort race during teardown could also leave a finished run
misreported as still parked.
Map passed-with-override to the same done/terminal handling as a
clean passed in both places.
* fix(document): Replace stale outcome mapping with authoritative pointer
* fix(ci): Fixed a pre-existing mock-clock race in tests/fm-contributions.test.sh by advancing time only during the serial issue read. Reproduced the exact CI failure before fixing it. Forced-race replay, all 38 contribution scenarios, scoped ShellCheck, Bash syntax, and diff checks pass. Only the test fixture changed; CI rerun remains with the outer executor
* fix: clean up workers after their pull requests land (#5317)
* fix: close landed workers from supervision in both postures and at return
During the 2026-09-22 away window every exemption worker whose pull request
had merged was left sitting for nine hours. The supervision branch received
the stale wake, the merge-landed check, and the hourly inactive-outcome row
for each of them, ran the recovery playbook, found nothing to recover, and
reported "no further action". The branch prompt granted ordinary teardown of
a confirmed-landed task without ever naming the moment or the command, and
the playbook has no landed exit, so the stale path ended at "nothing to
recover". The return brief then listed only blockers, decisions, and the
latest five routine outcomes, so the landed workers stayed invisible after
the captain came back.
- bin/fm-branch-prompt.sh: name the merge-landed wake, and any later stale,
inactive-outcome, or heartbeat row on a done task with a merged PR, as the
moment to claim the lease and run bin/fm-teardown.sh with no flags; a
refusal is reported, never forced or worked around. Add teardown to the
handling tool list.
- stuck-crewmate-recovery: a landed worker is not a recovery case; point at
the ordinary teardown owner for each actor.
- bin/fm-afk-return.sh: render a "Landed, cleanup due" section from durable
records only (a live task record whose recorded PR carries the
merge-notification marker), between could-not-fix and handled, without
holding the gate; the afk skill's return step closes each listed task
through ordinary teardown once the check clears.
- tests: pin the prompt rule in fm-branch-supervision and the brief section
in fm-afk-return through the real marker writer.
* no-mistakes(document): Document landed-task cleanup ownership
* fix: surface green no-mistakes PRs awaiting merge (#5327)
* fix(bin): surface a green no-mistakes PR still in ci merge monitoring
A green PR could sit unreported because neither the worker nor the
supervisor could observe checks-green while the ci step kept monitoring
for the merge.
Supervisor read: fm_nm_select_run's capped-overview inventory reader looked
the repository up by the task worktree path, but no-mistakes registers a
repository once by its main clone path and resolves every linked worktree
to it, so on every task copy of a busy repo the lookup matched no row and
each read reported "complete same-branch run inventory unreadable". Key the
lookup on the overview's own top-level `repo:` line, which every axi
release emits as the resolved working_path.
Even with a readable run, the ci-log classifier treated "base branch
advanced ..., re-arming CI monitor timeout" as not-ready. The monitor logs
a checks state only when it changes and a base advance does not clear
readiness, so a green PR read as still validating for as long as main kept
advancing. Stop treating that line as a marker, matching no-mistakes' own
ci-log parser, and name the run's PR URL in the held-for-merge reading so
the existing inactive-outcome path can act on it without a worker report.
Worker contract: `axi status` never reports checks-passed while the ci
step monitors for merge, so the definition of done no longer makes a
status poll the wait for the next gate or outcome; the drive call's own
return is the green signal, reattached with `no-mistakes axi run` after a
bounded return.
* no-mistakes(review): read the full ci log when checking checks-green
* no-mistakes(review): correct stale ci log tail wording in docs
* no-mistakes(document): Document checks-green supervisor fallback
* fix: derive Lavish polling route from board session (#5334)
* fix: derive Lavish polling server from its board session
* no-mistakes(document): Document session-derived Lavish polling
* no-mistakes(document): Correct Lavish routing verification claims
* fix(bin): stop secondmate relaunch failing when watcher scratch files vanish (#4900)
* fix(bin): ignore vanished state scratch files on secondmate relaunch
Relaunch refused when find(1) exited non-zero while listing a secondmate
home's state directory. A live watcher can delete scratch files between
readdir and processing, which is not evidence that child *.meta records
are unreadable.
Prove the directory is listable from its mode and keep the existing
readable-meta loop as the child-record guarantee. Fixes #4765.
* no-mistakes(review): Skip chmod-000 unlistable-state relaunch test when running as root
* fix(bin): stop each keyed answer from re-waking this home (#4907)
* fix(bin): treat home-owned status closes as already read
Self-announced bookkeeping appends now record their exact byte ranges.
Later drains and signal scans skip those ranges, so two distinct
--resolve-key answers after an OPEN DECISIONS fold do not each wake the
supervisor. Worker-authored lines outside that ledger still signal.
* no-mistakes(review): Keep owned closes in unread status; lock ledger writes
* no-mistakes(review): Drop fold-lag wake suppression so folded worker decisions still wake
* no-mistakes(review): Require real owned growth before ledger marks status seen
* no-mistakes(document): Clarify home-appends ledger scope versus UNREAD STATUS
* no-mistakes(review): Restore fold-lag path, drop owned-range filters, fix test
* no-mistakes(review): Align ledger docs and scope ledger to wake path only
* no-mistakes(review): Restore stranded historical-annotation test comment to its function
* no-mistakes(review): Retire the home-appends lock alongside its ledger
* no-mistakes(document): Note ledger's lock-helper dependency in classify library
* no-mistakes(review): Append-and-coalesce home-appends ledger; fix stamped-line assertions
* no-mistakes(review): Drop redundant empty-span branch; make owned test pin ledger
* no-mistakes(document): Document covers' ascending-order dependency on home-appends ledger
* no-mistakes(document): Note owned-append skip in watcher signal-scan comment
* fix: deliver failed public follow-ups with updated AXI floors (#5350)
* chore(bin): raise tasks-axi, quota-axi, and lavish-axi floors to latest
Raise the minimum versions to tasks-axi 0.2.6, quota-axi 0.1.50, and
lavish-axi 0.1.77, pin CI's tasks-axi install to 0.2.6, and move the
floor-boundary test fixtures to the new versions.
tasks-axi 0.2.6 makes a failed relation deliverable for a promised-final
expecting pr-merged, so add the regression test: a bound work that ends
failed reports its honest outcome text through fm-public-followup-emit.sh,
consume marks the commitment ready, and deliver posts that text exactly
once.
Also make two hang-guard tests in fm-backlog-atomicity portable to hosts
without coreutils timeout, and stop an installed herdr from leaking into
the secondmate-liveness husk classifier test.
* no-mistakes(review): drop out-of-scope bounded_run hang-guard helper from atomicity test
* no-mistakes(review): pin quota-axi floor at 0.1.49 across fixtures
* no-mistakes(document): Document failed public-followup delivery behavior
* no-mistakes(ci): Updated quota-axi floor and all 0.1.49 fixtures to 0.1.51, corrected bootstrap boundaries to 0.1.51/0.1.52/0.1.50, and bumped the bearings lavish-axi stub to 0.1.77. Bearings, quota procevent, quota chooser, startup budget, and bootstrap floor coverage passed; the full bootstrap suite exceeded the 240-second local command limit after relevant checks passed. git diff --check passed
* fix(bin): refuse ship done: when the named head exists only in the worker copy (#4878)
* fix(bin): refuse ship done: when the named head lives only in the worker copy
A ship done: is not current-state done until that exact commit is reachable
outside the disposable copy. The check tests the named head, not whether
some branch moved.
* fix(bin): gate CI-ready ship done: on named-head reachability, not handoff
Keep no-mistakes' first done: as the pipeline handoff, apply the same shared
check when registering a PR and when a secondmate publishes ledger-first,
treat a recorded merged PR as landed after prune, and name the PR head
instead of scanning free-text SHAs.
* no-mistakes(review): Bind named-head gate to recorded PR and forge heads
* no-mistakes(review): Gate direct-PR forge heads and keep pending ledger deliveries
* no-mistakes(review): Align worker done wording, test mapping, pending-retry test
* no-mistakes(test): Raise watcher test time limit to stop load flake
* no-mistakes(document): Restore ledger-path fact and name named-head gate coverage
* ci: re-attest named-head ship-done gate for a fresh serial-3 verdict
* no-mistakes(review): Simplify local-only gate, gate keyed done lines, document recovery
* no-mistakes(document): Name fm-crew-state among named-head gate callers
* fix(bin): ring a proven-idle secondmate before raising a wake-loop stall alarm (#5204)
* fix(bin): ring a proven-idle secondmate before a wake-loop stall alarm
A leftover foreign-queue row on an idle, alive, ring-safe mate is still drainable in that home. Ring once, reset the observation interval, and keep the parent alarm for unknown, busy, or still-frozen rows.
* no-mistakes(review): Mark drain steer with from-firstmate fire-and-forget carrier
* test(watch-arm): size re-arm waits off the real loaded recovery cost (#5335)
The re-arm recovery cases judged "the watcher stayed live instead of
surfacing recovery" with fixed budgets below what a real stale-lock
recovery costs on a contended host: the arm's default 10s confirmation
deadline, a start helper that returned after about 4s whether or not the
arm had confirmed its watcher, and an 80-poll exit wait.
A changed-suite run beside other suites starves the recovery's many
short-lived processes while this suite's sleeping poll loops keep their
pace, so a watcher still surfacing its recovery read as one that stayed
live (issue #3793).
The original 0.25s window after confirmation was widened to 80 polls in
#3837, which left the same race at a larger size.
Following the CONTRIBUTING.md fixture-budget rule, the re-arm helper now
gives the arm an explicit 30s confirmation budget and waits for its
confirmation or exit within a ceiling that outlasts it, and every wait on
a re-armed watcher uses one named iteration-counted ceiling that outlasts
the same budget.
A passing case returns as soon as the arm reports or exits, and a watcher
that never surfaces its recovery still fails.
A new case delays every mktemp and readlink the re-armed watcher runs
after it publishes its beacon, so its first poll and exit take about 13s
on any host.
It fails with the reported symptom on the previous budgets and passes now.
No bin/ change.
* fix: stop watchers reliably during blocked polls (#5362)
* fix(bin): let one TERM always stop the watcher on bash 5.2
Bash 5.2 runs a pending trap from the parser entry of the next command
substitution it expands, where the trap body is parsed as the inside of
that substitution and fails ("trap: line 2: unexpected EOF while looking
for matching `)'") or is dropped silently, consuming the signal. The
watcher's `trap 'exit 1' HUP INT TERM` could therefore ignore a TERM and
keep polling while its stopper waited: the triage suite's reap waited
forever (CI jobs cancelled at 30 minutes), and the arm's signal path and
the away-mode daemon's shutdown wait for the watcher the same way.
Bash 5.3 fixed the parser; 5.2 is the stock bash on Ubuntu 24.04.
HUP and TERM now keep bash's native fatal-signal handling, which runs the
EXIT trap (watcher_cleanup) and exits on bash 3.2, 5.2, and 5.3. INT keeps
its trap because bash ignores a direct SIGINT while a child runs. The
check-spawn deferral window no longer contains a command substitution.
The triage suite's reap is now bounded and fails the case within 10s with
process evidence instead of hanging the job, and a new regression test
proves TERM stops a watcher blocked inside a poll's pane capture and still
releases its lock and records an acknowledgeable stop.
* no-mistakes(document): Clarify watcher stop-signal documentation
* fix: submit stuck inbox doorbells instead of skipping them (#5374)
* fix(bin): submit our own stuck doorbell instead of skipping every later ring
* no-mistakes(review): Confirm and retry Enter once on stuck-doorbell submit
* no-mistakes(document): Clarify doorbell retry and pending-composer documentation
* feat: add opt-in fleet activity ledger (#5375)
* feat(bin): add the opt-in fleet activity ledger
Homes that create config/fleet-ledger get an append-only JSONL file,
state/fleet-ledger.jsonl, recording task.dispatched, task.status,
task.merged, and task.cleaned_up so outside tools can follow a fleet.
With the flag absent each producer does one file test and nothing else.
docs/fleet-ledger.md owns the record contract and its documented limits.
* no-mistakes(review): Record task.status text verbatim after the first colon
* no-mistakes(document): Clarify fleet ledger status and setup documentation
* no-mistakes(ci): Fixed a timing race in tests/fm-pi-branch-extension.te…
jjtylr
added a commit
to jjtylr/firstmate
that referenced
this pull request
Sep 27, 2026
* fix(bin): create captain-hold rows when Beads requires due (#4854)
Captain holds have no due semantics and are a hold kind, not a Beads issue
type. The create path now waives due.required and maps to native type task.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: disable compact adviser for spawned agents (#4877)
* feat(bin): launch every spawned agent with the compact adviser disabled
Every crewmate, scout, and secondmate Firstmate launches now starts with
COMPACT_ADVISER_DISABLE=1, on a fresh spawn and on a relaunch alike, so an
unattended session never activates the compact adviser.
The value is unconditional: no configuration file gates it and there is no
override, unlike the trace carrier beside it.
Three carriers deliver it, because no single one covers every launch shape.
The pane shell receives an export beside GOTMPDIR, so the agent's own children
inherit it too.
The launch command carries an explicit assignment, prepended outermost so it
wins over any ambient value the pane already held.
The cleared launch environment sets it again at the `env -i` boundary and keeps
COMPACT_ADVISER_DISABLE in the fixed operational floor, which is what preserves
the switch when config/launch-env-allowlist empties the environment, and what
delivers it on a remote host that never had the value.
bin/fm-control.sh relaunch, the bootstrap secondmate relaunch, and the remote
secondmate transport all rebuild their launch through bin/fm-spawn.sh, so they
inherit the same floor.
The captain's own primary session is untouched.
The two new suites drive the real spawn and then execute the launch command the
pane actually received, with the harness replaced by a probe that prints its own
environment, rather than matching script text.
They cover ship and secondmate launches with the allowlist absent and enabled,
the pane export and its ordering, fm-control.sh relaunch, and the full parent to
remote-host chain.
* no-mistakes(review): Export compact-adviser disable across compound launches
* no-mistakes(document): Document spawned-agent compact-adviser environment guarantee
* fix(bin): preserve Claude lock ownership after helper recycling (#4894)
* fix(bin): let a background Claude session keep owning its session lock
Session-lock ownership was decided by process ancestry alone. Under an
unattended Claude session the model loop runs in a transient bg-spare
bridged to the front-end by a shared daemon; when that bridge is
recycled the contiguous claude-named ancestry from a hook to the
recorded owner breaks while the owner pid stays alive, so the Stop
auto-arm stood down as a foreign live owner, the turn-end guard ended
every turn with its read-only diagnostic, and fm-lock.sh refused - a
self-sustaining outage until restart.
Ownership is now ancestry membership OR a trusted same-session id,
never id-first:
- fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when
CLAUDE_PID is a Claude-shaped member of the current contiguous run,
compares it against the id recorded in state/.lock-session, and
requires the recorded pid to still be a live harness. No id, no
sidecar, an untrusted id, a different id, or a dead recorded pid
leaves the ancestry verdict unchanged. Ids are never read from ps
argv.
- fm-lock.sh accepts a same-session holder at both refusal sites,
writes, refreshes, and clears the sidecar only under its claim lock
(including the early already-mine exit, skipped only while the
deferred startup sweep leases that lock), keeps it byte-identical
across a same-session confirmation, records CLAUDE_PID on lock line 1
for a session with a trusted id so a shared daemon or front-end that
outlives the session never keeps a dead session's lock alive, never
rewrites a live line 1 on a same-session confirmation, and names the
recorded id in the live-owner refusal.
- The .lock line-1 format is unchanged, so every reader that takes the
whole first line as the pid keeps working; the guard's foreign-owner
exit is unchanged and inherits the fix through the shared predicate.
Tests: the ancestry suite drives the ancestry and id signals apart in a
deterministic process table (asserting the divergence) and runs a real
orphaned front-end/daemon/pty-host/spare tree through six phases with
the real lock, auto-arm, and guard scripts; the foreign-owner repro
keeps its negative control and adds a same-id positive control.
Disclosure: no live unattended Claude background session ran on the
verifying machine. The topology is documented by the real process
listings in #3902, #2314, #3398, and #4066; coverage is the structural
predicate plus the executable fixtures, not a live pass.
Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry
walk (it only decides whether to print a nudge) and may nudge on a
resume in the recycled case.
Out of scope, deliberately: no structured lock format, no guard budget
changes, no daemon-identity rejection, no fork lineage.
* no-mistakes(review): Wait for claim lock; revert failed sidecars
* no-mistakes(review): Revalidate ownership after wait; restore sidecars
* no-mistakes(review): Roll back sidecar by publication phase
* no-mistakes(review): Restore sidecar only if lock line is unchanged
* no-mistakes(review): Trust session ids without a spelling allowlist
* no-mistakes(review): Disarm sidecar rollback before backup cleanup
* no-mistakes(document): Updated session-lock ownership documentation
* feat: park main under the away posture on Pi (#4889)
* feat: park main under the away posture on Pi
While the away-posture record exists on a Pi primary, the supervision branch
takes every actionable wake, no processing turn opens on main, captain rows
accumulate for the return brief, and main's standing authority relocates to
the branch through the existing guarded scripts.
- lib/fm-branch-dispatch.ts: read the record at every routing decision; while
it exists claim check, decision-owned, and heartbeat rows too, keeping the
two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task
scoping.
- fm-primary-pi-watch.ts: offer every actionable row under the record; a
declined wake and every watcher-failure alarm still reach main.
- fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed
POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no
processing request while the record exists, re-checked immediately before a
request would open and at every run boundary; present the accumulated rows
at the first run boundary after archive.
- fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in
actions only while fm-afk-contract.sh validate succeeds on a confirmed live
record; PR merge, fresh spawn, and decision answer opt in, local landing
never does.
- fm-send.sh: a --resolve-key naming an open needs-decision or captain-held
task is a decision answer and meets the partition; blocked: keys stay
steering.
- fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by
either actor; relaunches and secondmates exempt.
- fm-branch-prompt.sh: fixed Postures section and the verbatim
ask-user-authority policy; the prefix stays byte-stable.
- fm-afk-return.sh: count what the away session handled from the store.
- docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate
absolute while away.
- tests: watcher and branch extension suites, fleet-record, merge, and
decision-answer suites cover the relocation, the vetoes, the tail, the
parked processing turn, the cancellation, the re-presentation, and the
spend cap; dated live-guard evidence recorded.
* no-mistakes(review): Refuse branch merge after preflight archive race
* no-mistakes(review): Fix away wake, spawn, and processing races
* no-mistakes(review): Suppress parked processing; narrow away-only rejection
* no-mistakes(review): Abort dedicated processing; gate branch spawn once
* no-mistakes(review): Stamp away-only on the dispatch offer
* no-mistakes(review): Treat invalid away records as spend-cap absence
* no-mistakes(review): Drop spawn test hook; abort processing-opened runs
* no-mistakes(review): Bind abort to opening prompt; cap-read absence
* no-mistakes(review): Limit away branch spawn to queued work only
* no-mistakes(document): Correct AFK posture documentation
* ci: standardize workflow timeouts into three tiers (#4910)
* ci: simplify CI job timeouts to a three-tier policy
Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m
serial, 10m macOS) with three readable tiers, each a hang tripwire with
headroom rather than a packing estimate:
- fast (5m): coverage guard, repo invariants, timing aggregate
- normal (30m, one shared budget): lint partitions, portable parallel
shards, portable serial shards, macOS stock Bash
- heavy (Herdr only): 20m step tripwire on the family run so always()
cleanup still runs, under a 75m job-level last-resort backstop
The workflow's header comment states the policy and points at
docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each
job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh
asserts the policy against the parsed workflow instead of the old
per-job minute values: every job joins exactly one tier, exactly three
distinct job-level values exist, the fast tier stays within 5-10
minutes, the normal budget stays at least double the modeled parallel
lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step
tripwire stays below its job backstop with an always() cleanup after it.
Concurrency supersession, shard counts, lane membership, and fail-fast
settings are unchanged.
* no-mistakes(review): Decouple the normal timeout from packing estimates
* no-mistakes(review): Assert Herdr teardown follows the family run
* no-mistakes(review): Pin Herdr family-run timeout to 20 minutes
* no-mistakes(review): Ignore comments when identifying Herdr steps
* no-mistakes(review): Identify Herdr steps by declarative ids
* no-mistakes(document): Clarify authoritative three-tier timeout policy
* fix(bin): keep supervisor status closes from waking the same home (#4895)
* fix(bin): keep supervisor status closes from waking the same home
A drain that already folded OPEN DECISIONS has presented those bytes even
when the watcher has no matching seen marker. Treat that fold, and the
presentation cursor, as known so the bookkeeping close stays quiet while
later worker lines still signal.
* no-mistakes(review): Keep folded worker failures waking past supervisor closes
* no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes
* no-mistakes(review): Stop folded worker resolved lines from counting as already read
* no-mistakes(document): Correct self-announced close marker contract in docs
* fix(bin): stop labeling Herdr as experimental (#4972)
* Stop steering operators away from Herdr
* no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording
* fix(bin): treat a live no-mistakes run as current after rebase (#4973)
* fix(bin): treat a live no-mistakes run as current after rebase
A running run on the task's branch is authoritative regardless of head.
Matching only the local head made a rebased in-flight run look failed.
* no-mistakes(review): restrict coarse live-any-head to foreign-branch answers
* no-mistakes(review): reject gate-parked runs from the executing predicate
* no-mistakes(review): hoist gate-marker patterns into single run-lib owner
* no-mistakes(review): require live daemon for head-free run binding
* no-mistakes(review): require answered daemon-down before unbinding live runs
* no-mistakes(review): extend daemon guard to anchored continuation routes
* no-mistakes(review): delete live-any-head; restore dead-daemon verdict
* no-mistakes(review): keep parked gates parked; name dead daemon everywhere
* no-mistakes(review): set dead-daemon verdict instead of emitting early
* no-mistakes(review): align selected route with legacy dead-daemon handling
* no-mistakes(review): drop unproven-record binds; narrow coarse gate reading
* no-mistakes(review): narrow header, drop vestigial guard, retarget tests
* no-mistakes(review): revert coarse gate override; require answered-down probe
* no-mistakes(review): cache one daemon probe; stop duplicating run id
* no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows
* no-mistakes(review): delete coarse dead-daemon extension and gate note
* no-mistakes(review): delete remaining coarse dead-daemon block and stale docs
* no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict
* fix(bin): prevent long worker launch command truncation (#4994)
* fix(bin): stage the launch command in a private file and type a short source line
A long launch line typed while the fresh pane shell is still busy waits in the
terminal's canonical line buffer, which drops input past about 1,024 bytes on
macOS, so the pane was left at an unfinished command with no agent running.
fm-spawn now writes the assembled command to the task's own temp root under
umask 077 and types only a short line that sources it.
Refs #4559
* fix(bin): keep the per-task temp root private before staging the launch command
The root lives at a predictable path under /tmp and now holds the whole launch
command. Create it with mode 0700, refuse one that already exists as anything but
a directory owned by this user that nobody else can write, and tighten an owned
one, so no other local user can plant or swap the staged file.
Refs #4559
* fix(bin): enforce private staged launch file mode
* test(spawn): cover long staged Claude launches
* no-mistakes(review): Namespace launch files and prove truncation staging
* no-mistakes(review): Use immutable per-spawn launch filenames
* no-mistakes(document): Document staged launch delivery safeguards
* no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass
---------
Co-authored-by: Vytautas Stankus <svycka@gmail.com>
* test: authorize isolated Herdr lab validation (#4998)
* Add isolated Herdr runbook to test instructions
* no-mistakes(review): Drop substring matching from test.instructions contract
* no-mistakes(review): Assert commands.test key absence in YAML
* Drop unit-first sentence and instructions contract test
Captain-scoped follow-up on the Herdr-lab test.instructions ship:
keep the lab safety runbook only, and leave the no-mistakes contract
test focused on commands.test absence.
* docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (#5001)
* docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (#4873)
Replace the pixels-of-today's-UI rule with a quarantined, version-pinned
surface-adapter exception recorded as standing debt. Cap the always-loaded
contract at 9,000 words and require prune-or-trigger before a crossing change
lands.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* docs(vision): restore accepted three-sentence vendor-semantics form (#4873)
Replace the compressed paraphrase with the issue's accepted wording:
a named quarantined version-pinned adapter, expected to break, recorded
as standing debt that never hardens into a shared contract.
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com>
* feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974)
* fix(watch): recheck a gate awaiting a human instead of wedge-escalating it
A lane whose validation run is parked at a gate waiting on a human
decision is correctly quiet, but nothing in its status line says so: the
evidence is the pipeline's own gate state rather than anything the worker
wrote. The wedge timer read that silence as a suspected wedge and climbed
the escalation ladder for as long as the wait lasted, and each escalation
cost a supervising turn. The landed declared-wait consult does not reach
it, because a live ordinary crewmate never reports a declared pause, and
raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for
every lane by the same amount.
The threshold now reads a second, independent record when the status line
accounts for nothing: whether the crew's current state is a gate whose
answer is owed by a human. That is minted only from the gate's own
findings table, by a row whose `action` column is exactly `ask-user`,
located by position out of the table header the way nm_gate_step_row
already reads its row - never searched for over the run payload, where a
finding's free-text description or a branch name satisfies a search just
as well. A gate awaiting the CREWMATE's own answer keeps the unchanged
escalation schedule, reason and demand-deep-inspection wording, because a
crewmate that goes quiet before answering its own gate is exactly the
wedge the ladder exists to catch.
Each kind of wait now carries the human it is on, the action that clears
it, and whether that human is the captain as data alongside the verdict,
rather than as wording chosen per branch where the recheck is written, so
the deferral cannot word one kind of wait as another and a new kind
cannot ship without deciding all of them. A parked gate has no written
record of when its wait began, so its recheck publishes no wait age at
all rather than one read from the quiet window this deferral resets on
every pass, which would report the same small number for a gate of any
age. Like every other captain-facing recheck here it is absorbed in
silence while the away-posture record exists, arming no throttle, so the
recheck is owed in full the moment the record is archived.
The consult runs only in the at-threshold branch that was about to
escalate, beside the worktree walk already there, and only for lanes
whose status line explained nothing.
Closes #3055
* no-mistakes(review): require an unanswered decision before deferring a parked gate
* no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records
* test(watch): pass the pane hash wedge_timer_check now takes
Upstream gave wedge_timer_check a sixth <pane-hash> argument for its
dead-record probe. The malformed-wait-record rounds drive the real function
directly, so they pass one, and stub fm_backend_agent_state to a live agent so
the probe that runs after a refused deferral keeps the unchanged ladder rather
than reading a backend the child shell has none of.
* no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate
* no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling
* feat(watch): make the parked-gate wait deferral opt-in
The wedge timer deferring a lane parked at a validation gate is new
supervision behaviour rather than a restored one, and it decides which
lanes give up the escalation ladder, so it now ships as a default-off
per-home option instead of changing every home on upgrade.
config/wedge-defer-parked-gate arms it. The flag is read before the
decision fold, so an unconfigured home spends no fold or current-state
read, writes no record, and keeps the unchanged escalation schedule,
reasons and demand-deep-inspection wording; a test counts the reader
calls in both directions to pin that.
It is not inherited by secondmate homes: each home supervises its own
crew and owns that trade separately, the same reason
config/turnend-churn-absorb is home-local.
The away-posture absorb returns to leaving the idle timer alone, which
it had restarted only because the costly consult could reach it. A
parked-gate wait is owed to the supervisor rather than the captain, so
it never enters that branch, and the recheck owed on return is again
owed in full the moment the record is archived.
* test(watch): pin that the away-silenced hold leaves the idle timer alone
The absorb no longer restarts the timer, so the recheck owed on return is
owed in full rather than a cadence into the return. Nothing asserted
that, so a restart could be reintroduced silently.
* no-mistakes(review): document away-silence rationale, pin captured gate component
* no-mistakes(test): anchor gate row scan to the braced findings header
* no-mistakes(document): pin same-block gate row invariant in crew-state comment
* fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
* fix(control): let the owning seat reclaim a task whose endpoint is gone
A destroyed pane or workspace made `missing` a terminal state. Relaunch
accepted only `dead` and said to stop the agent first; exit refused
`missing` and said to reconcile the task first; there is no reconcile
verb. Each command named the other as its prerequisite, so a task whose
terminal went away could not be reclaimed by anything, and a no-mistakes
approval it was parked on had no seat left to answer it.
`missing` is agent-free a fortiori: there is no endpoint, so there is no
agent in it. Widen the existing guards rather than add a verb.
- fm-spawn --relaunch accepts a positively proven `missing` and creates
one fresh endpoint in the recorded worktree; the record it already
republishes rebinds the task to it. A `dead` endpoint is still adopted
in place.
- fm-control exit reports `endpoint-gone` instead of dying, so the
relaunch transaction's stop step no longer dead-ends, and re-resolves
the endpoint from the record before verifying the replacement.
The duplicate-agent refusal is untouched: both verdicts come from the
same recovery-grade classifier, which claims `missing` only from positive
absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The
backends' own create paths refuse a live same-labeled endpoint as a
second independent guard. The worktree, its branch, commits, uncommitted
changes, armed poll and registration, record rows, and status log are all
untouched - a reclaim is a recovery, never a teardown.
A secondmate is excluded: its gone-endpoint recovery already has one
owner in the session-start liveness sweep, so relaunch refuses and names
it rather than becoming a second path to the same outcome.
Tests reproduce both halves of the deadlock, the reclaim succeeding,
unlanded work surviving it, and the refusals that still hold.
* no-mistakes(review): prove endpoint absence per backend before reclaim rebinds
* no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session
* no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly
* no-mistakes(review): stop refusals and docs asserting unestablished causes
* no-mistakes(review): stop herdr fixture helper losing tmp-root registration
* no-mistakes(review): document workspace drift and absence-probe server residue
* no-mistakes(review): correct rebind limitation to its one reachable case
* no-mistakes(review): stop claiming reclaim leaves instructions untouched
* no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage
* no-mistakes(rebase): read the staged launch file in the herdr fixture
Rebasing onto main picked up #4994, which stages a long worker launch
command into a script and delivers the short `. '<path>'` line instead of
the literal command. The tmux fake and tests/fixtures.sh were updated for
that; the herdr fake this branch adds was written before it and still
keyed "an agent now exists on this pane" off the literal
`encode launch-brief` text, so after the rebase it never marked the
rebound pane live and the reclaim's alive-wait read `dead`.
Dereference the staged file first, exactly as the tmux fake above does.
Test-fixture only; no production path changes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(document): note reclaim placement in herdr and scripts inventories
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(bin): stamp status events with their emission time (#3764)
* test(status): reproduce missing event emission time
* wip(status): preserve optional event emission time
* test(status): document indirect clock stub invocation
* no-mistakes(review): Preserve historical status bytes during reply recovery
* no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies
* no-mistakes(review): Preserve captain regex overrides for timestamped status events
* no-mistakes(document): Clarify status event timing and publication contracts
* no-mistakes(lint): Quote literal done to satisfy ShellCheck
* no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed
* no-mistakes(test): Preserve terminal notifications with malformed timestamp tags
* no-mistakes(test): Stamp Rovo spawn failures with emission time
* no-mistakes(document): Verify status event documentation
* no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests
* no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed
* no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed
* no-mistakes(review): Stamp remote escalations at call sites, drop new flag
* no-mistakes(review): Accept stamped escalation and close lines in test assertions
* no-mistakes(review): Restore reserved-key answered-note guard for stamped closes
* test(status): accept optional emission time in PR-provenance assertions
The #4148 provenance test landed on main with exact unstamped greps.
Parent-channel lines from this branch carry [at=<epoch>], so strip only
that tag before the same exact match. No production change.
* no-mistakes(review): Accept stamped ready signal in PR fallback scrape
* no-mistakes(review): Drop relay flag, stamp parent events at call sites
* no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture
* no-mistakes(review): Accept optional stamp in live cmux drift guard
* no-mistakes(review): Restore original test invocation order in two suites
* no-mistakes(review): Strip only well-formed numeric status time tags
* no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc
* no-mistakes(review): Stamp agy spawn-failure status lines with event time
* fix(bin): normalize status event times in-shell and freeze the budget test clock
Two paths made a status event's emission time cost more than it should.
The captain-relevance fallback piped every line through awk to drop a
well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a
fork per line just to prepare a regex match. Shell parameter expansion does the
same strip with no fork, and the retry-dedup scan now reuses that one helper
instead of carrying a second copy of the rule in awk. The copies had already
drifted: the shell side stripped tags from lines with no colon, which the awk
rule left whole, so a colonless line could be mistaken for one already
recorded. One definition, checked against the awk rule it replaces over the
edge cases and a 4000-line fuzz.
tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In
hang mode the poll set DEADLINE to the real now plus a one-second budget, and
when the second ticked before the first forge call the loop broke without ever
calling gh: forge/calls was never written and the assertion failed reading a
missing file. Freezing the clock in both modes removes the dependence on wall
time; the bounded call is still cut by the real timeout, so the observation the
test asserts still starts.
Emission time stays optional on new status records, and legacy or malformed
lines keep an unknown age.
* no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion
* no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs
* test: fold emission-time snapshot coverage into the fixture case
Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer
touches workflows. Keep every emission-time assertion by folding it
into test_fixture_snapshot_json.
* no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch
* no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape
* no-mistakes(review): strip undelimited at-tags; correct brief stamp header
* no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness
* no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles
* no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb
* no-mistakes(review): read note and key past colon-bearing stamps
* test(status): keep inactive reconcile assertions stamp-tolerant
These two oracles were made stamp-tolerant while resolving one of the
branch's merges from main. The rebase drops merge commits, so that
adaptation was lost and both assertions went back to matching an exact
substring that a stamped line no longer contains: the tag lands before
the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...".
Strip a well-formed tag before matching, as the branch's other oracles do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap
* no-mistakes(document): correct stale unstamped status-line spellings in docs
* no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments
* no-mistakes(ci): rename subshell-local epoch in delivery-race stub
The serialization test overrides fm_pending_reply_mark_delivered inside a
(..) subshell. Its `epoch` local collided with the same name in
status_line_at_epoch/status_stamp_line, which this branch added and this
suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and
failed Lint 2. The stub already prefixes its other locals with `pending_`
for the same reason; `epoch` was the leftover.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(bin): unify Lavish host and disconnect handling (#5060)
* fix: ship clean Lavish host fixes
* no-mistakes(review): Fix Lavish classifications and fail-closed host loading
* no-mistakes(review): Restore Lavish host state across retries and launches
* no-mistakes(review): Preserve destination Lavish host when configuration is absent
* no-mistakes(document): Document Lavish status and host guarantees
* feat: act on captain's away words during AFK supervision (#5076)
* feat(afk): make the captain's away words the whole mandate
Retire the clause fields, verb list, never-set scan, refused records, and
the per-task merge-grant list from the away-posture record. The record is
now version 2: the captain's words verbatim plus expected return, spend
cap, and reach line; a version 1 record still validates, reads, and
archives so a live away window is never broken by the upgrade.
The supervision branch reads the words at the tail of every wake and acts
on them by its own judgment through the guarded scripts under standing
authority, never by analogy, holding for the return on doubt, and opens
each such outcome summary with "per your away instructions:" so the
return brief can render the words beside the session's account. While the
record exists any green merge runs under away authority (ledger tag
"away"); red merges, --allow-red, asynchronous and queued merges, and
local-only landing stay refused. The branch may file a backlog item the
words explicitly call for before dispatching it under the spend cap.
Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and
fm-pr-merge.sh as commands: version 2 written, version 1 read, retired
flags and subcommands refused by name, green merges landing under the
record, red and waived-red refused, the record lock still closing the
authority-read window, and the Pi away tail carrying the words.
* no-mistakes(review): carry the away read-back to the session verbatim
* no-mistakes(review): match the exact away-action marker in the return brief
* no-mistakes(review): refuse a words block truncated by a damaged line
* no-mistakes(document): Refresh away-role contract documentation
* fix(bin): render the remote charter's steering-inbox path host-local (#5049)
* fix(bin): render the remote charter's steering-inbox path host-local
A freshly provisioned remote secondmate read a parent-home absolute
steering-inbox path in its charter - a location that exists on no route -
and spent its first turn discovering the gap and filing a blocked
decision for what was a render defect. The seed's remote-copy rewrite now
maps the inbox to the route's host-local parent-route inbox, exactly as
it already maps the reply-log path, so every mention - bare path, listing,
and handled/ acknowledgement - lands host-local.
Both rewrites also become plain assignments, because a quoted substitution
nested inside a double-quoted printf argument leaks literal quotes into
the replacement text on stock macOS bash. The lifecycle suite pins the
corrected render both directions against the real seed, provisioning,
and delivery route, sharing one fixture value between the render truth
and the delivery truth.
Closes #5012
* no-mistakes(document): document remote charter's host-local steering inbox
* feat: route Lavish feedback directly to owning workers (#5099)
* feat(procevent): route worker-owned Lavish rounds
* no-mistakes(review): drop duplicate artifact field from task-owned registration
* no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic
* no-mistakes(review): keep worker board owned until terminal round acknowledged
* no-mistakes(review): refuse every retirement of an open worker-owned round
* no-mistakes(review): use real lavish reply flag, isolate reply generations
* no-mistakes(review): drop .posted marker for best-effort reply posting
* no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures
* no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms
* no-mistakes(review): re-arm only to acknowledge an open round
* no-mistakes(review): conclude only a still-open terminal round
* no-mistakes(review): record the acknowledgement before retiring the board
* no-mistakes(review): retain the registration across a conclude, qualify terminal docs
* no-mistakes(document): Document worker-owned Lavish round lifecycle
* fix(bin): fit pull observation within the contribution poll budget (#5107)
* fix(bin): reserve contribution observation budget
* no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget
* feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103)
* feat(bin): add idempotent inbox orders, receipts, replies, and readiness
Let a caller supply a request id when publishing a captain inbox note so a
retry returns the original note instead of creating a second one, including
across the crash window between save and wake announcement. Separate saved
from announced so a failed wake is repairable without enqueueing again.
Add bounded receipts JSON with omission disclosure, a durable primary reply
against a note id, and a read-only readiness projection that can say
unknown instead of inferring liveness from a lock file.
* no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict
* fix(bin): resolve ready from lock-holder ancestry; drop lock status --json
Remove the extra JSON surface from fm-lock.sh so its human status still
always exits zero. Have the readiness projection classify the inspected
home from the lock-holder pid via fm-harness.sh ancestry, with an explicit
FM_SUPERVISION_MODEL still winning and an unknown model when there is no
holder. Prove the yes path when that ancestry names a known harness.
* no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor
* no-mistakes(document): Note read-only lock inspection in scripts inventory
* no-mistakes(lint): Pass missing id argument to malformed-reply test printf
---------
Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com>
* fix(bin): stop harness footer rows below a composer from reading as pending text (#5118)
* fix(composer): stop a harness footer row from reading as a composer holding text
A harness draws its own furniture below the composer - a user statusLine, a
permission-mode hint - and the cursorless "bottom-most shape wins" rule looks
exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text
everywhere else, so a statusLine opening with `→` was selected as a bare
composer, swallowed the hint row beneath it as wrapped input, and answered
`pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that
verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first
doorbell and every retry were skipped and the worker never saw the steer.
Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on
Herdr 0.8.0 had genuinely empty composers and every one of them was refused.
A separator pair that closed over a bare agent-glyph row is a proven composer
container, so the contiguous non-blank rows below its closing rule are that
composer's footer and are no longer composer candidates. The demotion is bounded
by all three of its own preconditions: a blank row ends the zone, a pair that
closed over no glyph row demotes nothing, and a shape with no separator pair at
all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same
composer, including a stray SGR mouse report left by a click in the pane, still
reads `pending`.
Pinned by two portable regressions and by a new cursorless arm on the live
composer-matrix guard, which re-reads each harness's already-proven-idle pane
the way every non-tmux backend reads it and fails naming the harness and
version when that read is `pending`.
* no-mistakes(review): make composer footer-zone demotion shape-independent
* no-mistakes(review): make footer-zone demotion refuse-only and drop rescan
* no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100
---------
Co-authored-by: Koen Muller <koen@catapult.nl>
* feat(bin): append optional home-local include to briefs (#5115)
Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com>
* fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114)
* fix(bin): stop misreading a no-run branch as an unreadable runs table
Defect: when `no-mistakes axi status`'s overview is truncated (a task's
own branch has zero rows among the shown ones), fm_nm_select_run's
Python fallback derived the repo identity for its direct SQLite query
from a `repo: <path>` line it expected in the overview text. The real
CLI never emits that line, truncated or not (see the genuine capture at
tests/captures/no-mistakes-v1.70.1/overview.toon, which has only
`count:`/`runs[...]:`), so the lookup always failed and reported
"unreadable runs table" for a task that simply has no run on its
branch. On a fleet with many concurrent runs, every idle-branch task
hits the truncated-overview path routinely, so this fired every few
minutes and drowned genuine unreadable/blocked verdicts in noise.
Fix: derive the repo identity from the task worktree path instead,
which is exactly the value `no-mistakes` records as a repo's
`working_path` (confirmed against the existing capped-overview test
fixtures, which already register repos by worktree path). A worktree
path that is not absolute cannot be matched and still reads as
unreadable rather than being guessed at. Also raise the reader's
SQLite busy timeout from 1s to 30s so ordinary lock contention on a
busy fleet cannot masquerade as an unreadable database.
Safety: every other verdict byte-for-byte unchanged - the repo lookup
still requires exactly one matching row (a genuinely corrupt or
mismatched repos table still reports unreadable, per the existing
`repo` failure-mode test), the branch query and row validation are
untouched, and a zero-row result for the branch still flows through
the same recursive re-parse that already turns an empty `runs[0]{...}`
table into `absent`. Added a regression test
(test_capped_overview_without_repo_line_and_no_runs_reports_absent)
that reproduces the real overview shape - capped, zero rows for the
task's branch, no `repo: ` line - and asserts the crew state falls
through to the pane/busy verdict instead of reporting unknown or
"unreadable". Full fm-crew-state.test.sh suite passes unchanged
otherwise.
* fix: recovered same-branch inventory awk misreads empty result as unreadable
fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:`
overview and re-runs it through the same awk selection pass. When that
rebuilt inventory has zero rows for the branch, the row-matching loop never
executes, so its counters (`seen`) stay at awk's uninitialized empty string
while `expected` and `shown` are plain strings parsed from the header text.
Comparing an uninitialized value against a non-numeric string uses string
comparison, so "" != "0" is true, and the END block takes the "unreadable
runs table" branch instead of falling through to the correct "absent"
verdict for a branch with genuinely zero runs.
Coerce the affected END comparisons with `+0` so they are always numeric,
matching seen/expected/shown/total regardless of whether awk classified
them as strings or numeric strings. A truncated or genuinely malformed
inventory still differs numerically and still reports unreadable.
* no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup
* no-mistakes(review): match recorded repo path first, tolerate duplicate spellings
* no-mistakes(review): revert repo lookup to exact working_path match
* no-mistakes(document): note state-db inventory read under crew-state nm timeout
* fix(bin): require a non-draft pull request before a PR-based done report (#5141)
* fix(bin): require a non-draft pull request before a PR-based done report
A PR-based ship could report done, and merge monitoring could be armed, while the pull request was still a draft. A draft cannot be merged, so the poll waited for an event that could not occur and nobody was asked to merge.
The PR-based definitions of done now require reading the pull request back from the forge and confirming it is not a draft, and a lane that deliberately holds a draft declares a wait instead of done.
bin/fm-pr-check.sh refuses to arm merge monitoring on a draft, naming the draft state, and treats an unreadable draft state as before.
The draft reading now lives in bin/fm-pr-lib.sh and bin/fm-pr-merge.sh uses it, with its refusal to merge a draft unchanged.
Closes #4757
* fix(review): Skip arm-time draft refusal when fm-pr-merge records metadata
* fix: support quota-axi schema 6 snapshots (#4904)
* fix(bin): accept quota-axi schema 6 snapshots keyed by provider + accountKey
quota-axi 0.1.47 emits schemaVersion 6 once a provider expands to more
than one account: every provider row carries an accountKey and one
provider id may appear on several rows. fm_quota_json_valid accepted
only schema 5 with unique provider ids, so fm-dispatch-resolve.sh,
fm-quota-choose.sh, and fm-procevent-quota.sh all rejected the live
snapshot and quota-informed dispatch was dead against the current tool.
- bin/fm-quota-axi-lib.sh: the validator accepts schema 6 with
accountKey required on every row and uniqueness on
provider + accountKey; schema 5 keeps its exact rules. FM_QUOTA_ROW_JQ
is the one join every consumer uses: schema 5 binds by provider alone,
schema 6 binds to the row keyed by the candidate's Pi lane, else the
provider's default row, else no row (unmeasured, never blocked, never
by position or summed across accounts).
- bin/fm-quota-choose.sh: accepts schema 6 JSON and the TOON accountKey
column, and joins through the shared function.
- bin/fm-dispatch-resolve.sh and bin/fm-procevent-quota.sh: join through
the shared function; an expanded provider with no row for the
candidate's account is reported as such.
- tests: schema 6 fixtures shaped like the real snapshot, each paired
with a schema 5 case on the same path; every new case fails on the
previous scripts and passes now.
- docs: the two sentences naming the row join describe the schema 6 key.
* no-mistakes(review): Fix native Codex quota and expanded provider watches
* no-mistakes(review): Align native Codex account matching across dispatch paths
* no-mistakes(document): Align quota documentation with account-aware snapshots
* no-mistakes(document): Align quota dispatch documentation with account matching
* fix(bin): keep CI lint and the quota watch test portable
- bin/fm-quota-axi-lib.sh: FM_QUOTA_ROW_JQ is read only by the scripts
that source this library, so full-mode ShellCheck reported SC2034 on
the assignment; mark it alongside the existing SC2016 disable.
- tests/fm-procevent-quota.test.sh: the schema 6 provider-watch
assertions used rg, which CI runners do not install, so the case
failed with 'rg: command not found' rather than on behavior; use grep
like the rest of the file.
* no-mistakes(document): Documented schema-version account-row compatibility
* test: fix Claude session-start drain live E2E (#5165)
* test: repair Claude live auto-arm regression
* no-mistakes(review): Assert SessionStart digest completeness within its hook_response event
* no-mistakes(document): Consolidate Claude live verification references
* ci: pin the no-mistakes required check to v1.80.1 (#5195)
Roll the shared require-no-mistakes action to the tagged v1.80.1 SHA and grant pull-requests: read so the check can read PR bodies.
* fix(bin): retain Pi watcher predecessor to stop false down alarms (#5174)
* fix: preserve Pi watcher ownership across session replacement
* no-mistakes(document): Scope Pi predecessor retention away from omp
* no-mistakes(ci): Diagnosed all three failing checks; only one was code-caused. (ci-3, genuine) Stock macOS Bash snapshot compatibility: `tests/fm-pi-watch-extension.test.sh` failed the macOS Bash 3.2 `bash -n` parse sweep with `line 4265: unexpected EOF while looking for matching '`. I built GNU Bash 3.2.0 from source locally and reproduced it. Root cause: the PR added a comment containing an apostrophe (`// Replacement shutdown deliberately retains module 2's established arm until`) inside a quoted here-document (`<<'EOF'`) nested inside a `$(...)` command substitution. Bash 3.2 has a parser bug (fixed in later bash) where an unmatched single quote inside such a here-doc body is treated as opening a shell quote and never closed, aborting the whole file parse. The base commit parses cleanly under Bash 3.2, confirming this PR introduced the break. Minimal fix: reworded the comment to remove the apostrophe (`... retains the established module-2 arm until`), preserving meaning. Verified `bin/fm-lint.sh --list-files` (the 6 changed shell files) now all pass `/tmp/bash-3.2/bash -n`; Bash 5 also parses. (ci-1, infrastructure) Behavior portable serial 8: GitHub API shows the `Run portable serial shard 8` step conclusion=success; only `Upload portable serial shard 8 timing artifact` failed with `Failed to FinalizeArtifact ... (403) Forbidden`. This is a transient artifact-service/cancellation failure, not a test or code failure. No change. (ci-2, infrastructure) Lint 1: fetched the job log via the GitHub API; it ends with `##[error]The runner has received a shutdown signal...` then exit 143. The step was cancelled mid-run, not a ShellCheck finding. Independently ran `bin/fm-lint.sh --partition 1of2 --telemetry ...` locally with pinned ShellCheck 0.11.0 and actionlint 1.7.12: exited rc=0 (no findings). No change. The only code change is the apostrophe removal in tests/fm-pi-watch-extension.test.sh; no other files modified
* fix(bin): allow cleanup of windowless legacy task records (#5236)
* fix(bin): retire windowless leftovers and stop claiming a Pi daemon teardown
Catch-up correctly refuses while a leftover task record has no status file.
Cleanup used to deadlock on those same records when they also had no spawn_gen and no window, so they lingered and wedged every later away-mode return. Teardown now treats a windowless leftover as a missing-endpoint legacy record, and stop reports that no daemon terminal was running when none was launched.
Co-authored-by: Cursor <cursoragent@cursor.com>
* no-mistakes(review): Narrow windowless teardown exception to tmux legacy leftovers
* no-mistakes(review): Validate windowless leftover identity via shared endpoint validator
* no-mistakes(review): Refuse windowless leftovers carrying other backends' endpoint identity
* no-mistakes(document): Clarify windowless teardown retry documentation
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* ci: exempt kunchenguid from the no-mistakes required check (#5256)
* fix(bin): surface launches parked on an interactive prompt as not-started (#5250)
* fix: surface parked launch prompts as not started
* no-mistakes(document): docs: record launch-prompt busy backstop classification
* no-mistakes(document): docs: align tail40 and rendered-text comments with launch-prompt backstop
* fix: record away posture immediately on /afk (#5260)
* feat(afk): make /afk itself the go with a same-turn record write
Collapse the propose-then-confirm away entry into one 'enter' step that
writes state/.afk-contract immediately and prints the announcement and
read-back after the record exists, never asking for a go. The retired
propose, confirm, and --proposal inputs are refused by name, and a stale
proposal left by an older version is removed rather than promoted.
Refresh and replace semantics, verbatim words, the single writer, the
never-set, and per-harness launch behavior are unchanged.
* no-mistakes(document): Refresh away-entry documentation evidence
* fix(bin): recognize passed-with-override as a passing outcome (#5294)
* fix(bin): map passed-with-override to done instead of unknown
no-mistakes' axi status emits outcome: passed-with-override for a run
that finished with an explicitly approved Test or CI exception. Both
bin/fm-crew-state.sh's outcome resolver and bin/fm-teardown.sh's
pre-teardown terminal-run check only matched the literal passed and
checks-passed tokens, so this outcome fell through to unknown/parked
and a finished worker awaiting merge kept getting re-alerted as stale,
while an abort race during teardown could also leave a finished run
misreported as still parked.
Map passed-with-override to the same done/terminal handling as a
clean passed in both places.
* fix(document): Replace stale outcome mapping with authoritative pointer
* fix(ci): Fixed a pre-existing mock-clock race in tests/fm-contributions.test.sh by advancing time only during the serial issue read. Reproduced the exact CI failure before fixing it. Forced-race replay, all 38 contribution scenarios, scoped ShellCheck, Bash syntax, and diff checks pass. Only the test fixture changed; CI rerun remains with the outer executor
* fix: clean up workers after their pull requests land (#5317)
* fix: close landed workers from supervision in both postures and at return
During the 2026-09-22 away window every exemption worker whose pull request
had merged was left sitting for nine hours. The supervision branch received
the stale wake, the merge-landed check, and the hourly inactive-outcome row
for each of them, ran the recovery playbook, found nothing to recover, and
reported "no further action". The branch prompt granted ordinary teardown of
a confirmed-landed task without ever naming the moment or the command, and
the playbook has no landed exit, so the stale path ended at "nothing to
recover". The return brief then listed only blockers, decisions, and the
latest five routine outcomes, so the landed workers stayed invisible after
the captain came back.
- bin/fm-branch-prompt.sh: name the merge-landed wake, and any later stale,
inactive-outcome, or heartbeat row on a done task with a merged PR, as the
moment to claim the lease and run bin/fm-teardown.sh with no flags; a
refusal is reported, never forced or worked around. Add teardown to the
handling tool list.
- stuck-crewmate-recovery: a landed worker is not a recovery case; point at
the ordinary teardown owner for each actor.
- bin/fm-afk-return.sh: render a "Landed, cleanup due" section from durable
records only (a live task record whose recorded PR carries the
merge-notification marker), between could-not-fix and handled, without
holding the gate; the afk skill's return step closes each listed task
through ordinary teardown once the check clears.
- tests: pin the prompt rule in fm-branch-supervision and the brief section
in fm-afk-return through the real marker writer.
* no-mistakes(document): Document landed-task cleanup ownership
* fix: surface green no-mistakes PRs awaiting merge (#5327)
* fix(bin): surface a green no-mistakes PR still in ci merge monitoring
A green PR could sit unreported because neither the worker nor the
supervisor could observe checks-green while the ci step kept monitoring
for the merge.
Supervisor read: fm_nm_select_run's capped-overview inventory reader looked
the repository up by the task worktree path, but no-mistakes registers a
repository once by its main clone path and resolves every linked worktree
to it, so on every task copy of a busy repo the lookup matched no row and
each read reported "complete same-branch run inventory unreadable". Key the
lookup on the overview's own top-level `repo:` line, which every axi
release emits as the resolved working_path.
Even with a readable run, the ci-log classifier treated "base branch
advanced ..., re-arming CI monitor timeout" as not-ready. The monitor logs
a checks state only when it changes and a base advance does not clear
readiness, so a green PR read as still validating for as long as main kept
advancing. Stop treating that line as a marker, matching no-mistakes' own
ci-log parser, and name the run's PR URL in the held-for-merge reading so
the existing inactive-outcome path can act on it without a worker report.
Worker contract: `axi status` never reports checks-passed while the ci
step monitors for merge, so the definition of done no longer makes a
status poll the wait for the next gate or outcome; the drive call's own
return is the green signal, reattached with `no-mistakes axi run` after a
bounded return.
* no-mistakes(review): read the full ci log when checking checks-green
* no-mistakes(review): correct stale ci log tail wording in docs
* no-mistakes(document): Document checks-green supervisor fallback
* fix: derive Lavish polling route from board session (#5334)
* fix: derive Lavish polling server from its board session
* no-mistakes(document): Document session-derived Lavish polling
* no-mistakes(document): Correct Lavish routing verification claims
* fix(bin): stop secondmate relaunch failing when watcher scratch files vanish (#4900)
* fix(bin): ignore vanished state scratch files on secondmate relaunch
Relaunch refused when find(1) exited non-zero while listing a secondmate
home's state directory. A live watcher can delete scratch files between
readdir and processing, which is not evidence that child *.meta records
are unreadable.
Prove the directory is listable from its mode and keep the existing
readable-meta loop as the child-record guarantee. Fixes #4765.
* no-mistakes(review): Skip chmod-000 unlistable-state relaunch test when running as root
* fix(bin): stop each keyed answer from re-waking this home (#4907)
* fix(bin): treat home-owned status closes as already read
Self-announced bookkeeping appends now record their exact byte ranges.
Later drains and signal scans skip those ranges, so two distinct
--resolve-key answers after an OPEN DECISIONS fold do not each wake the
supervisor. Worker-authored lines outside that ledger still signal.
* no-mistakes(review): Keep owned closes in unread status; lock ledger writes
* no-mistakes(review): Drop fold-lag wake suppression so folded worker decisions still wake
* no-mistakes(review): Require real owned growth before ledger marks status seen
* no-mistakes(document): Clarify home-appends ledger scope versus UNREAD STATUS
* no-mistakes(review): Restore fold-lag path, drop owned-range filters, fix test
* no-mistakes(review): Align ledger docs and scope ledger to wake path only
* no-mistakes(review): Restore stranded historical-annotation test comment to its function
* no-mistakes(review): Retire the home-appends lock alongside its ledger
* no-mistakes(document): Note ledger's lock-helper dependency in classify library
* no-mistakes(review): Append-and-coalesce home-appends ledger; fix stamped-line assertions
* no-mistakes(review): Drop redundant empty-span branch; make owned test pin ledger
* no-mistakes(document): Document covers' ascending-order dependency on home-appends ledger
* no-mistakes(document): Note owned-append skip in watcher signal-scan comment
* fix: deliver failed public follow-ups with updated AXI floors (#5350)
* chore(bin): raise tasks-axi, quota-axi, and lavish-axi floors to latest
Raise the minimum versions to tasks-axi 0.2.6, quota-axi 0.1.50, and
lavish-axi 0.1.77, pin CI's tasks-axi install to 0.2.6, and move the
floor-boundary test fixtures to the new versions.
tasks-axi 0.2.6 makes a failed relation deliverable for a promised-final
expecting pr-merged, so add the regression test: a bound work that ends
failed reports its honest outcome text through fm-public-followup-emit.sh,
consume marks the commitment ready, and deliver posts that text exactly
once.
Also make two hang-guard tests in fm-backlog-atomicity portable to hosts
without coreutils timeout, and stop an installed herdr from leaking into
the secondmate-liveness husk classifier test.
* no-mistakes(review): drop out-of-scope bounded_run hang-guard helper from atomicity test
* no-mistakes(review): pin quota-axi floor at 0.1.49 across fixtures
* no-mistakes(document): Document failed public-followup delivery behavior
* no-mistakes(ci): Updated quota-axi floor and all 0.1.49 fixtures to 0.1.51, corrected bootstrap boundaries to 0.1.51/0.1.52/0.1.50, and bumped the bearings lavish-axi stub to 0.1.77. Bearings, quota procevent, quota chooser, startup budget, and bootstrap floor coverage passed; the full bootstrap suite exceeded the 240-second local command limit after relevant checks passed. git diff --check passed
* fix(bin): refuse ship done: when the named head exists only in the worker copy (#4878)
* fix(bin): refuse ship done: when the named head lives only in the worker copy
A ship done: is not current-state done until that exact commit is reachable
outside the disposable copy. The check tests the named head, not whether
some branch moved.
* fix(bin): gate CI-ready ship done: on named-head reachability, not handoff
Keep no-mistakes' first done: as the pipeline handoff, apply the same shared
check when registering a PR and when a secondmate publishes ledger-first,
treat a recorded merged PR as landed after prune, and name the PR head
instead of scanning free-text SHAs.
* no-mistakes(review): Bind named-head gate to recorded PR and forge heads
* no-mistakes(review): Gate direct-PR forge heads and keep pending ledger deliveries
* no-mistakes(review): Align worker done wording, test mapping, pending-retry test
* no-mistakes(test): Raise watcher test time limit to stop load flake
* no-mistakes(document): Restore ledger-path fact and name named-head gate coverage
* ci: re-attest named-head ship-done gate for a fresh serial-3 verdict
* no-mistakes(review): Simplify local-only gate, gate keyed done lines, document recovery
* no-mistakes(document): Name fm-crew-state among named-head gate callers
* fix(bin): ring a proven-idle secondmate before raising a wake-loop stall alarm (#5204)
* fix(bin): ring a proven-idle secondmate before a wake-loop stall alarm
A leftover foreign-queue row on an idle, alive, ring-safe mate is still drainable in that home. Ring once, reset the observation interval, and keep the parent alarm for unknown, busy, or still-frozen rows.
* no-mistakes(review): Mark drain steer with from-firstmate fire-and-forget carrier
* test(watch-arm): size re-arm waits off the real loaded recovery cost (#5335)
The re-arm recovery cases judged "the watcher stayed live instead of
surfacing recovery" with fixed budgets below what a real stale-lock
recovery costs on a contended host: the arm's default 10s confirmation
deadline, a start helper that returned after about 4s whether or not the
arm had confirmed its watcher, and an 80-poll exit wait.
A changed-suite run beside other suites starves the recovery's many
short-lived processes while this suite's sleeping poll loops keep their
pace, so a watcher still surfacing its recovery read as one that stayed
live (issue #3793).
The original 0.25s window after confirmation was widened to 80 polls in
#3837, which left the same race at a larger size.
Following the CONTRIBUTING.md fixture-budget rule, the re-arm helper now
gives the arm an explicit 30s confirmation budget and waits for its
confirmation or exit within a ceiling that outlasts it, and every wait on
a re-armed watcher uses one named iteration-counted ceiling that outlasts
the same budget.
A passing case returns as soon as the arm reports or exits, and a watcher
that never surfaces its recovery still fails.
A new case delays every mktemp and readlink the re-armed watcher runs
after it publishes its beacon, so its first poll and exit take about 13s
on any host.
It fails with the reported symptom on the previous budgets and passes now.
No bin/ change.
* fix: stop watchers reliably during blocked polls (#5362)
* fix(bin): let one TERM always stop the watcher on bash 5.2
Bash 5.2 runs a pending trap from the parser entry of the next command
substitution it expands, where the trap body is parsed as the inside of
that substitution and fails ("trap: line 2: unexpected EOF while looking
for matching `)'") or is dropped silently, consuming the signal. The
watcher's `trap 'exit 1' HUP INT TERM` could therefore ignore a TERM and
keep polling while its stopper waited: the triage suite's reap waited
forever (CI jobs cancelled at 30 minutes), and the arm's signal path and
the away-mode daemon's shutdown wait for the watcher the same way.
Bash 5.3 fixed the parser; 5.2 is the stock bash on Ubuntu 24.04.
HUP and TERM now keep bash's native fatal-signal handling, which runs the
EXIT trap (watcher_cleanup) and exits on bash 3.2, 5.2, and 5.3. INT keeps
its trap because bash ignores a direct SIGINT while a child runs. The
check-spawn deferral window no longer contains a command substitution.
The triage suite's reap is now bounded and fails the case within 10s with
process evidence instead of hanging the job, and a new regression test
proves TERM stops a watcher blocked inside a poll's pane capture and still
releases its lock and records an acknowledgeable stop.
* no-mistakes(document): Clarify watcher stop-signal documentation
* fix: submit stuck inbox doorbells instead of skipping them (#5374)
* fix(bin): submit our own stuck doorbell instead of skipping every later ring
* no-mistakes(review): Confirm and retry Enter once on stuck-doorbell submit
* no-mistakes(document): Clarify doorbell retry and pending-composer documentation
* feat: add opt-in fleet activity ledger (#5375)
* feat(bin): add the opt-in fleet activity ledger
Homes that create config/fleet-ledger get an append-only JSONL file,
state/fleet-ledger.jsonl, recording task.dispatched, task.status,
task.merged, and task.cleaned_up so outside tools can follow a fleet.
With the flag absent each producer does one file test and nothing else.
docs/fleet-ledger.md owns the record contract and its documented limits.
* no-mistakes(review): Record task.status text verbatim after the first colon
* no-mistakes(document): Clarify fleet ledger status and setup documentation
* no-mistakes(ci): Fixed a timing race in tests/fm…
RooseveltAdvisors
pushed a commit
to RooseveltAdvisors/firstmate
that referenced
this pull request
Sep 29, 2026
…#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation
keenvc
added a commit
to keenvc/firstmate
that referenced
this pull request
Sep 30, 2026
* feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974)
* fix(watch): recheck a gate awaiting a human instead of wedge-escalating it
A lane whose validation run is parked at a gate waiting on a human
decision is correctly quiet, but nothing in its status line says so: the
evidence is the pipeline's own gate state rather than anything the worker
wrote. The wedge timer read that silence as a suspected wedge and climbed
the escalation ladder for as long as the wait lasted, and each escalation
cost a supervising turn. The landed declared-wait consult does not reach
it, because a live ordinary crewmate never reports a declared pause, and
raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for
every lane by the same amount.
The threshold now reads a second, independent record when the status line
accounts for nothing: whether the crew's current state is a gate whose
answer is owed by a human. That is minted only from the gate's own
findings table, by a row whose `action` column is exactly `ask-user`,
located by position out of the table header the way nm_gate_step_row
already reads its row - never searched for over the run payload, where a
finding's free-text description or a branch name satisfies a search just
as well. A gate awaiting the CREWMATE's own answer keeps the unchanged
escalation schedule, reason and demand-deep-inspection wording, because a
crewmate that goes quiet before answering its own gate is exactly the
wedge the ladder exists to catch.
Each kind of wait now carries the human it is on, the action that clears
it, and whether that human is the captain as data alongside the verdict,
rather than as wording chosen per branch where the recheck is written, so
the deferral cannot word one kind of wait as another and a new kind
cannot ship without deciding all of them. A parked gate has no written
record of when its wait began, so its recheck publishes no wait age at
all rather than one read from the quiet window this deferral resets on
every pass, which would report the same small number for a gate of any
age. Like every other captain-facing recheck here it is absorbed in
silence while the away-posture record exists, arming no throttle, so the
recheck is owed in full the moment the record is archived.
The consult runs only in the at-threshold branch that was about to
escalate, beside the worktree walk already there, and only for lanes
whose status line explained nothing.
Closes #3055
* no-mistakes(review): require an unanswered decision before deferring a parked gate
* no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records
* test(watch): pass the pane hash wedge_timer_check now takes
Upstream gave wedge_timer_check a sixth <pane-hash> argument for its
dead-record probe. The malformed-wait-record rounds drive the real function
directly, so they pass one, and stub fm_backend_agent_state to a live agent so
the probe that runs after a refused deferral keeps the unchanged ladder rather
than reading a backend the child shell has none of.
* no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate
* no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling
* feat(watch): make the parked-gate wait deferral opt-in
The wedge timer deferring a lane parked at a validation gate is new
supervision behaviour rather than a restored one, and it decides which
lanes give up the escalation ladder, so it now ships as a default-off
per-home option instead of changing every home on upgrade.
config/wedge-defer-parked-gate arms it. The flag is read before the
decision fold, so an unconfigured home spends no fold or current-state
read, writes no record, and keeps the unchanged escalation schedule,
reasons and demand-deep-inspection wording; a test counts the reader
calls in both directions to pin that.
It is not inherited by secondmate homes: each home supervises its own
crew and owns that trade separately, the same reason
config/turnend-churn-absorb is home-local.
The away-posture absorb returns to leaving the idle timer alone, which
it had restarted only because the costly consult could reach it. A
parked-gate wait is owed to the supervisor rather than the captain, so
it never enters that branch, and the recheck owed on return is again
owed in full the moment the record is archived.
* test(watch): pin that the away-silenced hold leaves the idle timer alone
The absorb no longer restarts the timer, so the recheck owed on return is
owed in full rather than a cadence into the return. Nothing asserted
that, so a restart could be reintroduced silently.
* no-mistakes(review): document away-silence rationale, pin captured gate component
* no-mistakes(test): anchor gate row scan to the braced findings header
* no-mistakes(document): pin same-block gate row invariant in crew-state comment
* fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
* fix(control): let the owning seat reclaim a task whose endpoint is gone
A destroyed pane or workspace made `missing` a terminal state. Relaunch
accepted only `dead` and said to stop the agent first; exit refused
`missing` and said to reconcile the task first; there is no reconcile
verb. Each command named the other as its prerequisite, so a task whose
terminal went away could not be reclaimed by anything, and a no-mistakes
approval it was parked on had no seat left to answer it.
`missing` is agent-free a fortiori: there is no endpoint, so there is no
agent in it. Widen the existing guards rather than add a verb.
- fm-spawn --relaunch accepts a positively proven `missing` and creates
one fresh endpoint in the recorded worktree; the record it already
republishes rebinds the task to it. A `dead` endpoint is still adopted
in place.
- fm-control exit reports `endpoint-gone` instead of dying, so the
relaunch transaction's stop step no longer dead-ends, and re-resolves
the endpoint from the record before verifying the replacement.
The duplicate-agent refusal is untouched: both verdicts come from the
same recovery-grade classifier, which claims `missing` only from positive
absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The
backends' own create paths refuse a live same-labeled endpoint as a
second independent guard. The worktree, its branch, commits, uncommitted
changes, armed poll and registration, record rows, and status log are all
untouched - a reclaim is a recovery, never a teardown.
A secondmate is excluded: its gone-endpoint recovery already has one
owner in the session-start liveness sweep, so relaunch refuses and names
it rather than becoming a second path to the same outcome.
Tests reproduce both halves of the deadlock, the reclaim succeeding,
unlanded work surviving it, and the refusals that still hold.
* no-mistakes(review): prove endpoint absence per backend before reclaim rebinds
* no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session
* no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly
* no-mistakes(review): stop refusals and docs asserting unestablished causes
* no-mistakes(review): stop herdr fixture helper losing tmp-root registration
* no-mistakes(review): document workspace drift and absence-probe server residue
* no-mistakes(review): correct rebind limitation to its one reachable case
* no-mistakes(review): stop claiming reclaim leaves instructions untouched
* no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage
* no-mistakes(rebase): read the staged launch file in the herdr fixture
Rebasing onto main picked up #4994, which stages a long worker launch
command into a script and delivers the short `. '<path>'` line instead of
the literal command. The tmux fake and tests/fixtures.sh were updated for
that; the herdr fake this branch adds was written before it and still
keyed "an agent now exists on this pane" off the literal
`encode launch-brief` text, so after the rebase it never marked the
rebound pane live and the reclaim's alive-wait read `dead`.
Dereference the staged file first, exactly as the tmux fake above does.
Test-fixture only; no production path changes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(document): note reclaim placement in herdr and scripts inventories
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(bin): stamp status events with their emission time (#3764)
* test(status): reproduce missing event emission time
* wip(status): preserve optional event emission time
* test(status): document indirect clock stub invocation
* no-mistakes(review): Preserve historical status bytes during reply recovery
* no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies
* no-mistakes(review): Preserve captain regex overrides for timestamped status events
* no-mistakes(document): Clarify status event timing and publication contracts
* no-mistakes(lint): Quote literal done to satisfy ShellCheck
* no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed
* no-mistakes(test): Preserve terminal notifications with malformed timestamp tags
* no-mistakes(test): Stamp Rovo spawn failures with emission time
* no-mistakes(document): Verify status event documentation
* no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests
* no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed
* no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed
* no-mistakes(review): Stamp remote escalations at call sites, drop new flag
* no-mistakes(review): Accept stamped escalation and close lines in test assertions
* no-mistakes(review): Restore reserved-key answered-note guard for stamped closes
* test(status): accept optional emission time in PR-provenance assertions
The #4148 provenance test landed on main with exact unstamped greps.
Parent-channel lines from this branch carry [at=<epoch>], so strip only
that tag before the same exact match. No production change.
* no-mistakes(review): Accept stamped ready signal in PR fallback scrape
* no-mistakes(review): Drop relay flag, stamp parent events at call sites
* no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture
* no-mistakes(review): Accept optional stamp in live cmux drift guard
* no-mistakes(review): Restore original test invocation order in two suites
* no-mistakes(review): Strip only well-formed numeric status time tags
* no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc
* no-mistakes(review): Stamp agy spawn-failure status lines with event time
* fix(bin): normalize status event times in-shell and freeze the budget test clock
Two paths made a status event's emission time cost more than it should.
The captain-relevance fallback piped every line through awk to drop a
well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a
fork per line just to prepare a regex match. Shell parameter expansion does the
same strip with no fork, and the retry-dedup scan now reuses that one helper
instead of carrying a second copy of the rule in awk. The copies had already
drifted: the shell side stripped tags from lines with no colon, which the awk
rule left whole, so a colonless line could be mistaken for one already
recorded. One definition, checked against the awk rule it replaces over the
edge cases and a 4000-line fuzz.
tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In
hang mode the poll set DEADLINE to the real now plus a one-second budget, and
when the second ticked before the first forge call the loop broke without ever
calling gh: forge/calls was never written and the assertion failed reading a
missing file. Freezing the clock in both modes removes the dependence on wall
time; the bounded call is still cut by the real timeout, so the observation the
test asserts still starts.
Emission time stays optional on new status records, and legacy or malformed
lines keep an unknown age.
* no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion
* no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs
* test: fold emission-time snapshot coverage into the fixture case
Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer
touches workflows. Keep every emission-time assertion by folding it
into test_fixture_snapshot_json.
* no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch
* no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape
* no-mistakes(review): strip undelimited at-tags; correct brief stamp header
* no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness
* no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles
* no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb
* no-mistakes(review): read note and key past colon-bearing stamps
* test(status): keep inactive reconcile assertions stamp-tolerant
These two oracles were made stamp-tolerant while resolving one of the
branch's merges from main. The rebase drops merge commits, so that
adaptation was lost and both assertions went back to matching an exact
substring that a stamped line no longer contains: the tag lands before
the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...".
Strip a well-formed tag before matching, as the branch's other oracles do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap
* no-mistakes(document): correct stale unstamped status-line spellings in docs
* no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments
* no-mistakes(ci): rename subshell-local epoch in delivery-race stub
The serialization test overrides fm_pending_reply_mark_delivered inside a
(..) subshell. Its `epoch` local collided with the same name in
status_line_at_epoch/status_stamp_line, which this branch added and this
suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and
failed Lint 2. The stub already prefixes its other locals with `pending_`
for the same reason; `epoch` was the leftover.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(bin): unify Lavish host and disconnect handling (#5060)
* fix: ship clean Lavish host fixes
* no-mistakes(review): Fix Lavish classifications and fail-closed host loading
* no-mistakes(review): Restore Lavish host state across retries and launches
* no-mistakes(review): Preserve destination Lavish host when configuration is absent
* no-mistakes(document): Document Lavish status and host guarantees
* feat: act on captain's away words during AFK supervision (#5076)
* feat(afk): make the captain's away words the whole mandate
Retire the clause fields, verb list, never-set scan, refused records, and
the per-task merge-grant list from the away-posture record. The record is
now version 2: the captain's words verbatim plus expected return, spend
cap, and reach line; a version 1 record still validates, reads, and
archives so a live away window is never broken by the upgrade.
The supervision branch reads the words at the tail of every wake and acts
on them by its own judgment through the guarded scripts under standing
authority, never by analogy, holding for the return on doubt, and opens
each such outcome summary with "per your away instructions:" so the
return brief can render the words beside the session's account. While the
record exists any green merge runs under away authority (ledger tag
"away"); red merges, --allow-red, asynchronous and queued merges, and
local-only landing stay refused. The branch may file a backlog item the
words explicitly call for before dispatching it under the spend cap.
Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and
fm-pr-merge.sh as commands: version 2 written, version 1 read, retired
flags and subcommands refused by name, green merges landing under the
record, red and waived-red refused, the record lock still closing the
authority-read window, and the Pi away tail carrying the words.
* no-mistakes(review): carry the away read-back to the session verbatim
* no-mistakes(review): match the exact away-action marker in the return brief
* no-mistakes(review): refuse a words block truncated by a damaged line
* no-mistakes(document): Refresh away-role contract documentation
* fix(bin): render the remote charter's steering-inbox path host-local (#5049)
* fix(bin): render the remote charter's steering-inbox path host-local
A freshly provisioned remote secondmate read a parent-home absolute
steering-inbox path in its charter - a location that exists on no route -
and spent its first turn discovering the gap and filing a blocked
decision for what was a render defect. The seed's remote-copy rewrite now
maps the inbox to the route's host-local parent-route inbox, exactly as
it already maps the reply-log path, so every mention - bare path, listing,
and handled/ acknowledgement - lands host-local.
Both rewrites also become plain assignments, because a quoted substitution
nested inside a double-quoted printf argument leaks literal quotes into
the replacement text on stock macOS bash. The lifecycle suite pins the
corrected render both directions against the real seed, provisioning,
and delivery route, sharing one fixture value between the render truth
and the delivery truth.
Closes #5012
* no-mistakes(document): document remote charter's host-local steering inbox
* feat: route Lavish feedback directly to owning workers (#5099)
* feat(procevent): route worker-owned Lavish rounds
* no-mistakes(review): drop duplicate artifact field from task-owned registration
* no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic
* no-mistakes(review): keep worker board owned until terminal round acknowledged
* no-mistakes(review): refuse every retirement of an open worker-owned round
* no-mistakes(review): use real lavish reply flag, isolate reply generations
* no-mistakes(review): drop .posted marker for best-effort reply posting
* no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures
* no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms
* no-mistakes(review): re-arm only to acknowledge an open round
* no-mistakes(review): conclude only a still-open terminal round
* no-mistakes(review): record the acknowledgement before retiring the board
* no-mistakes(review): retain the registration across a conclude, qualify terminal docs
* no-mistakes(document): Document worker-owned Lavish round lifecycle
* fix(bin): fit pull observation within the contribution poll budget (#5107)
* fix(bin): reserve contribution observation budget
* no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget
* feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103)
* feat(bin): add idempotent inbox orders, receipts, replies, and readiness
Let a caller supply a request id when publishing a captain inbox note so a
retry returns the original note instead of creating a second one, including
across the crash window between save and wake announcement. Separate saved
from announced so a failed wake is repairable without enqueueing again.
Add bounded receipts JSON with omission disclosure, a durable primary reply
against a note id, and a read-only readiness projection that can say
unknown instead of inferring liveness from a lock file.
* no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict
* fix(bin): resolve ready from lock-holder ancestry; drop lock status --json
Remove the extra JSON surface from fm-lock.sh so its human status still
always exits zero. Have the readiness projection classify the inspected
home from the lock-holder pid via fm-harness.sh ancestry, with an explicit
FM_SUPERVISION_MODEL still winning and an unknown model when there is no
holder. Prove the yes path when that ancestry names a known harness.
* no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor
* no-mistakes(document): Note read-only lock inspection in scripts inventory
* no-mistakes(lint): Pass missing id argument to malformed-reply test printf
---------
Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com>
* fix(bin): stop harness footer rows below a composer from reading as pending text (#5118)
* fix(composer): stop a harness footer row from reading as a composer holding text
A harness draws its own furniture below the composer - a user statusLine, a
permission-mode hint - and the cursorless "bottom-most shape wins" rule looks
exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text
everywhere else, so a statusLine opening with `→` was selected as a bare
composer, swallowed the hint row beneath it as wrapped input, and answered
`pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that
verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first
doorbell and every retry were skipped and the worker never saw the steer.
Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on
Herdr 0.8.0 had genuinely empty composers and every one of them was refused.
A separator pair that closed over a bare agent-glyph row is a proven composer
container, so the contiguous non-blank rows below its closing rule are that
composer's footer and are no longer composer candidates. The demotion is bounded
by all three of its own preconditions: a blank row ends the zone, a pair that
closed over no glyph row demotes nothing, and a shape with no separator pair at
all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same
composer, including a stray SGR mouse report left by a click in the pane, still
reads `pending`.
Pinned by two portable regressions and by a new cursorless arm on the live
composer-matrix guard, which re-reads each harness's already-proven-idle pane
the way every non-tmux backend reads it and fails naming the harness and
version when that read is `pending`.
* no-mistakes(review): make composer footer-zone demotion shape-independent
* no-mistakes(review): make footer-zone demotion refuse-only and drop rescan
* no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100
---------
Co-authored-by: Koen Muller <koen@catapult.nl>
* feat(bin): append optional home-local include to briefs (#5115)
Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com>
* fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114)
* fix(bin): stop misreading a no-run branch as an unreadable runs table
Defect: when `no-mistakes axi status`'s overview is truncated (a task's
own branch has zero rows among the shown ones), fm_nm_select_run's
Python fallback derived the repo identity for its direct SQLite query
from a `repo: <path>` line it expected in the overview text. The real
CLI never emits that line, truncated or not (see the genuine capture at
tests/captures/no-mistakes-v1.70.1/overview.toon, which has only
`count:`/`runs[...]:`), so the lookup always failed and reported
"unreadable runs table" for a task that simply has no run on its
branch. On a fleet with many concurrent runs, every idle-branch task
hits the truncated-overview path routinely, so this fired every few
minutes and drowned genuine unreadable/blocked verdicts in noise.
Fix: derive the repo identity from the task worktree path instead,
which is exactly the value `no-mistakes` records as a repo's
`working_path` (confirmed against the existing capped-overview test
fixtures, which already register repos by worktree path). A worktree
path that is not absolute cannot be matched and still reads as
unreadable rather than being guessed at. Also raise the reader's
SQLite busy timeout from 1s to 30s so ordinary lock contention on a
busy fleet cannot masquerade as an unreadable database.
Safety: every other verdict byte-for-byte unchanged - the repo lookup
still requires exactly one matching row (a genuinely corrupt or
mismatched repos table still reports unreadable, per the existing
`repo` failure-mode test), the branch query and row validation are
untouched, and a zero-row result for the branch still flows through
the same recursive re-parse that already turns an empty `runs[0]{...}`
table into `absent`. Added a regression test
(test_capped_overview_without_repo_line_and_no_runs_reports_absent)
that reproduces the real overview shape - capped, zero rows for the
task's branch, no `repo: ` line - and asserts the crew state falls
through to the pane/busy verdict instead of reporting unknown or
"unreadable". Full fm-crew-state.test.sh suite passes unchanged
otherwise.
* fix: recovered same-branch inventory awk misreads empty result as unreadable
fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:`
overview and re-runs it through the same awk selection pass. When that
rebuilt inventory has zero rows for the branch, the row-matching loop never
executes, so its counters (`seen`) stay at awk's uninitialized empty string
while `expected` and `shown` are plain strings parsed from the header text.
Comparing an uninitialized value against a non-numeric string uses string
comparison, so "" != "0" is true, and the END block takes the "unreadable
runs table" branch instead of falling through to the correct "absent"
verdict for a branch with genuinely zero runs.
Coerce the affected END comparisons with `+0` so they are always numeric,
matching seen/expected/shown/total regardless of whether awk classified
them as strings or numeric strings. A truncated or genuinely malformed
inventory still differs numerically and still reports unreadable.
* no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup
* no-mistakes(review): match recorded repo path first, tolerate duplicate spellings
* no-mistakes(review): revert repo lookup to exact working_path match
* no-mistakes(document): note state-db inventory read under crew-state nm timeout
* fix(bin): require a non-draft pull request before a PR-based done report (#5141)
* fix(bin): require a non-draft pull request before a PR-based done report
A PR-based ship could report done, and merge monitoring could be armed, while the pull request was still a draft. A draft cannot be merged, so the poll waited for an event that could not occur and nobody was asked to merge.
The PR-based definitions of done now require reading the pull request back from the forge and confirming it is not a draft, and a lane that deliberately holds a draft declares a wait instead of done.
bin/fm-pr-check.sh refuses to arm merge monitoring on a draft, naming the draft state, and treats an unreadable draft state as before.
The draft reading now lives in bin/fm-pr-lib.sh and bin/fm-pr-merge.sh uses it, with its refusal to merge a draft unchanged.
Closes #4757
* fix(review): Skip arm-time draft refusal when fm-pr-merge records metadata
* fix: support quota-axi schema 6 snapshots (#4904)
* fix(bin): accept quota-axi schema 6 snapshots keyed by provider + accountKey
quota-axi 0.1.47 emits schemaVersion 6 once a provider expands to more
than one account: every provider row carries an accountKey and one
provider id may appear on several rows. fm_quota_json_valid accepted
only schema 5 with unique provider ids, so fm-dispatch-resolve.sh,
fm-quota-choose.sh, and fm-procevent-quota.sh all rejected the live
snapshot and quota-informed dispatch was dead against the current tool.
- bin/fm-quota-axi-lib.sh: the validator accepts schema 6 with
accountKey required on every row and uniqueness on
provider + accountKey; schema 5 keeps its exact rules. FM_QUOTA_ROW_JQ
is the one join every consumer uses: schema 5 binds by provider alone,
schema 6 binds to the row keyed by the candidate's Pi lane, else the
provider's default row, else no row (unmeasured, never blocked, never
by position or summed across accounts).
- bin/fm-quota-choose.sh: accepts schema 6 JSON and the TOON accountKey
column, and joins through the shared function.
- bin/fm-dispatch-resolve.sh and bin/fm-procevent-quota.sh: join through
the shared function; an expanded provider with no row for the
candidate's account is reported as such.
- tests: schema 6 fixtures shaped like the real snapshot, each paired
with a schema 5 case on the same path; every new case fails on the
previous scripts and passes now.
- docs: the two sentences naming the row join describe the schema 6 key.
* no-mistakes(review): Fix native Codex quota and expanded provider watches
* no-mistakes(review): Align native Codex account matching across dispatch paths
* no-mistakes(document): Align quota documentation with account-aware snapshots
* no-mistakes(document): Align quota dispatch documentation with account matching
* fix(bin): keep CI lint and the quota watch test portable
- bin/fm-quota-axi-lib.sh: FM_QUOTA_ROW_JQ is read only by the scripts
that source this library, so full-mode ShellCheck reported SC2034 on
the assignment; mark it alongside the existing SC2016 disable.
- tests/fm-procevent-quota.test.sh: the schema 6 provider-watch
assertions used rg, which CI runners do not install, so the case
failed with 'rg: command not found' rather than on behavior; use grep
like the rest of the file.
* no-mistakes(document): Documented schema-version account-row compatibility
* test: fix Claude session-start drain live E2E (#5165)
* test: repair Claude live auto-arm regression
* no-mistakes(review): Assert SessionStart digest completeness within its hook_response event
* no-mistakes(document): Consolidate Claude live verification references
* ci: pin the no-mistakes required check to v1.80.1 (#5195)
Roll the shared require-no-mistakes action to the tagged v1.80.1 SHA and grant pull-requests: read so the check can read PR bodies.
* fix(bin): retain Pi watcher predecessor to stop false down alarms (#5174)
* fix: preserve Pi watcher ownership across session replacement
* no-mistakes(document): Scope Pi predecessor retention away from omp
* no-mistakes(ci): Diagnosed all three failing checks; only one was code-caused. (ci-3, genuine) Stock macOS Bash snapshot compatibility: `tests/fm-pi-watch-extension.test.sh` failed the macOS Bash 3.2 `bash -n` parse sweep with `line 4265: unexpected EOF while looking for matching '`. I built GNU Bash 3.2.0 from source locally and reproduced it. Root cause: the PR added a comment containing an apostrophe (`// Replacement shutdown deliberately retains module 2's established arm until`) inside a quoted here-document (`<<'EOF'`) nested inside a `$(...)` command substitution. Bash 3.2 has a parser bug (fixed in later bash) where an unmatched single quote inside such a here-doc body is treated as opening a shell quote and never closed, aborting the whole file parse. The base commit parses cleanly under Bash 3.2, confirming this PR introduced the break. Minimal fix: reworded the comment to remove the apostrophe (`... retains the established module-2 arm until`), preserving meaning. Verified `bin/fm-lint.sh --list-files` (the 6 changed shell files) now all pass `/tmp/bash-3.2/bash -n`; Bash 5 also parses. (ci-1, infrastructure) Behavior portable serial 8: GitHub API shows the `Run portable serial shard 8` step conclusion=success; only `Upload portable serial shard 8 timing artifact` failed with `Failed to FinalizeArtifact ... (403) Forbidden`. This is a transient artifact-service/cancellation failure, not a test or code failure. No change. (ci-2, infrastructure) Lint 1: fetched the job log via the GitHub API; it ends with `##[error]The runner has received a shutdown signal...` then exit 143. The step was cancelled mid-run, not a ShellCheck finding. Independently ran `bin/fm-lint.sh --partition 1of2 --telemetry ...` locally with pinned ShellCheck 0.11.0 and actionlint 1.7.12: exited rc=0 (no findings). No change. The only code change is the apostrophe removal in tests/fm-pi-watch-extension.test.sh; no other files modified
* fix(bin): allow cleanup of windowless legacy task records (#5236)
* fix(bin): retire windowless leftovers and stop claiming a Pi daemon teardown
Catch-up correctly refuses while a leftover task record has no status file.
Cleanup used to deadlock on those same records when they also had no spawn_gen and no window, so they lingered and wedged every later away-mode return. Teardown now treats a windowless leftover as a missing-endpoint legacy record, and stop reports that no daemon terminal was running when none was launched.
Co-authored-by: Cursor <cursoragent@cursor.com>
* no-mistakes(review): Narrow windowless teardown exception to tmux legacy leftovers
* no-mistakes(review): Validate windowless leftover identity via shared endpoint validator
* no-mistakes(review): Refuse windowless leftovers carrying other backends' endpoint identity
* no-mistakes(document): Clarify windowless teardown retry documentation
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* ci: exempt kunchenguid from the no-mistakes required check (#5256)
* fix(bin): surface launches parked on an interactive prompt as not-started (#5250)
* fix: surface parked launch prompts as not started
* no-mistakes(document): docs: record launch-prompt busy backstop classification
* no-mistakes(document): docs: align tail40 and rendered-text comments with launch-prompt backstop
* fix: record away posture immediately on /afk (#5260)
* feat(afk): make /afk itself the go with a same-turn record write
Collapse the propose-then-confirm away entry into one 'enter' step that
writes state/.afk-contract immediately and prints the announcement and
read-back after the record exists, never asking for a go. The retired
propose, confirm, and --proposal inputs are refused by name, and a stale
proposal left by an older version is removed rather than promoted.
Refresh and replace semantics, verbatim words, the single writer, the
never-set, and per-harness launch behavior are unchanged.
* no-mistakes(document): Refresh away-entry documentation evidence
* fix(bin): recognize passed-with-override as a passing outcome (#5294)
* fix(bin): map passed-with-override to done instead of unknown
no-mistakes' axi status emits outcome: passed-with-override for a run
that finished with an explicitly approved Test or CI exception. Both
bin/fm-crew-state.sh's outcome resolver and bin/fm-teardown.sh's
pre-teardown terminal-run check only matched the literal passed and
checks-passed tokens, so this outcome fell through to unknown/parked
and a finished worker awaiting merge kept getting re-alerted as stale,
while an abort race during teardown could also leave a finished run
misreported as still parked.
Map passed-with-override to the same done/terminal handling as a
clean passed in both places.
* fix(document): Replace stale outcome mapping with authoritative pointer
* fix(ci): Fixed a pre-existing mock-clock race in tests/fm-contributions.test.sh by advancing time only during the serial issue read. Reproduced the exact CI failure before fixing it. Forced-race replay, all 38 contribution scenarios, scoped ShellCheck, Bash syntax, and diff checks pass. Only the test fixture changed; CI rerun remains with the outer executor
* fix: clean up workers after their pull requests land (#5317)
* fix: close landed workers from supervision in both postures and at return
During the 2026-09-22 away window every exemption worker whose pull request
had merged was left sitting for nine hours. The supervision branch received
the stale wake, the merge-landed check, and the hourly inactive-outcome row
for each of them, ran the recovery playbook, found nothing to recover, and
reported "no further action". The branch prompt granted ordinary teardown of
a confirmed-landed task without ever naming the moment or the command, and
the playbook has no landed exit, so the stale path ended at "nothing to
recover". The return brief then listed only blockers, decisions, and the
latest five routine outcomes, so the landed workers stayed invisible after
the captain came back.
- bin/fm-branch-prompt.sh: name the merge-landed wake, and any later stale,
inactive-outcome, or heartbeat row on a done task with a merged PR, as the
moment to claim the lease and run bin/fm-teardown.sh with no flags; a
refusal is reported, never forced or worked around. Add teardown to the
handling tool list.
- stuck-crewmate-recovery: a landed worker is not a recovery case; point at
the ordinary teardown owner for each actor.
- bin/fm-afk-return.sh: render a "Landed, cleanup due" section from durable
records only (a live task record whose recorded PR carries the
merge-notification marker), between could-not-fix and handled, without
holding the gate; the afk skill's return step closes each listed task
through ordinary teardown once the check clears.
- tests: pin the prompt rule in fm-branch-supervision and the brief section
in fm-afk-return through the real marker writer.
* no-mistakes(document): Document landed-task cleanup ownership
* fix: surface green no-mistakes PRs awaiting merge (#5327)
* fix(bin): surface a green no-mistakes PR still in ci merge monitoring
A green PR could sit unreported because neither the worker nor the
supervisor could observe checks-green while the ci step kept monitoring
for the merge.
Supervisor read: fm_nm_select_run's capped-overview inventory reader looked
the repository up by the task worktree path, but no-mistakes registers a
repository once by its main clone path and resolves every linked worktree
to it, so on every task copy of a busy repo the lookup matched no row and
each read reported "complete same-branch run inventory unreadable". Key the
lookup on the overview's own top-level `repo:` line, which every axi
release emits as the resolved working_path.
Even with a readable run, the ci-log classifier treated "base branch
advanced ..., re-arming CI monitor timeout" as not-ready. The monitor logs
a checks state only when it changes and a base advance does not clear
readiness, so a green PR read as still validating for as long as main kept
advancing. Stop treating that line as a marker, matching no-mistakes' own
ci-log parser, and name the run's PR URL in the held-for-merge reading so
the existing inactive-outcome path can act on it without a worker report.
Worker contract: `axi status` never reports checks-passed while the ci
step monitors for merge, so the definition of done no longer makes a
status poll the wait for the next gate or outcome; the drive call's own
return is the green signal, reattached with `no-mistakes axi run` after a
bounded return.
* no-mistakes(review): read the full ci log when checking checks-green
* no-mistakes(review): correct stale ci log tail wording in docs
* no-mistakes(document): Document checks-green supervisor fallback
* fix: derive Lavish polling route from board session (#5334)
* fix: derive Lavish polling server from its board session
* no-mistakes(document): Document session-derived Lavish polling
* no-mistakes(document): Correct Lavish routing verification claims
* fix(bin): stop secondmate relaunch failing when watcher scratch files vanish (#4900)
* fix(bin): ignore vanished state scratch files on secondmate relaunch
Relaunch refused when find(1) exited non-zero while listing a secondmate
home's state directory. A live watcher can delete scratch files between
readdir and processing, which is not evidence that child *.meta records
are unreadable.
Prove the directory is listable from its mode and keep the existing
readable-meta loop as the child-record guarantee. Fixes #4765.
* no-mistakes(review): Skip chmod-000 unlistable-state relaunch test when running as root
* fix(bin): stop each keyed answer from re-waking this home (#4907)
* fix(bin): treat home-owned status closes as already read
Self-announced bookkeeping appends now record their exact byte ranges.
Later drains and signal scans skip those ranges, so two distinct
--resolve-key answers after an OPEN DECISIONS fold do not each wake the
supervisor. Worker-authored lines outside that ledger still signal.
* no-mistakes(review): Keep owned closes in unread status; lock ledger writes
* no-mistakes(review): Drop fold-lag wake suppression so folded worker decisions still wake
* no-mistakes(review): Require real owned growth before ledger marks status seen
* no-mistakes(document): Clarify home-appends ledger scope versus UNREAD STATUS
* no-mistakes(review): Restore fold-lag path, drop owned-range filters, fix test
* no-mistakes(review): Align ledger docs and scope ledger to wake path only
* no-mistakes(review): Restore stranded historical-annotation test comment to its function
* no-mistakes(review): Retire the home-appends lock alongside its ledger
* no-mistakes(document): Note ledger's lock-helper dependency in classify library
* no-mistakes(review): Append-and-coalesce home-appends ledger; fix stamped-line assertions
* no-mistakes(review): Drop redundant empty-span branch; make owned test pin ledger
* no-mistakes(document): Document covers' ascending-order dependency on home-appends ledger
* no-mistakes(document): Note owned-append skip in watcher signal-scan comment
* fix: deliver failed public follow-ups with updated AXI floors (#5350)
* chore(bin): raise tasks-axi, quota-axi, and lavish-axi floors to latest
Raise the minimum versions to tasks-axi 0.2.6, quota-axi 0.1.50, and
lavish-axi 0.1.77, pin CI's tasks-axi install to 0.2.6, and move the
floor-boundary test fixtures to the new versions.
tasks-axi 0.2.6 makes a failed relation deliverable for a promised-final
expecting pr-merged, so add the regression test: a bound work that ends
failed reports its honest outcome text through fm-public-followup-emit.sh,
consume marks the commitment ready, and deliver posts that text exactly
once.
Also make two hang-guard tests in fm-backlog-atomicity portable to hosts
without coreutils timeout, and stop an installed herdr from leaking into
the secondmate-liveness husk classifier test.
* no-mistakes(review): drop out-of-scope bounded_run hang-guard helper from atomicity test
* no-mistakes(review): pin quota-axi floor at 0.1.49 across fixtures
* no-mistakes(document): Document failed public-followup delivery behavior
* no-mistakes(ci): Updated quota-axi floor and all 0.1.49 fixtures to 0.1.51, corrected bootstrap boundaries to 0.1.51/0.1.52/0.1.50, and bumped the bearings lavish-axi stub to 0.1.77. Bearings, quota procevent, quota chooser, startup budget, and bootstrap floor coverage passed; the full bootstrap suite exceeded the 240-second local command limit after relevant checks passed. git diff --check passed
* fix(bin): refuse ship done: when the named head exists only in the worker copy (#4878)
* fix(bin): refuse ship done: when the named head lives only in the worker copy
A ship done: is not current-state done until that exact commit is reachable
outside the disposable copy. The check tests the named head, not whether
some branch moved.
* fix(bin): gate CI-ready ship done: on named-head reachability, not handoff
Keep no-mistakes' first done: as the pipeline handoff, apply the same shared
check when registering a PR and when a secondmate publishes ledger-first,
treat a recorded merged PR as landed after prune, and name the PR head
instead of scanning free-text SHAs.
* no-mistakes(review): Bind named-head gate to recorded PR and forge heads
* no-mistakes(review): Gate direct-PR forge heads and keep pending ledger deliveries
* no-mistakes(review): Align worker done wording, test mapping, pending-retry test
* no-mistakes(test): Raise watcher test time limit to stop load flake
* no-mistakes(document): Restore ledger-path fact and name named-head gate coverage
* ci: re-attest named-head ship-done gate for a fresh serial-3 verdict
* no-mistakes(review): Simplify local-only gate, gate keyed done lines, document recovery
* no-mistakes(document): Name fm-crew-state among named-head gate callers
* fix(bin): ring a proven-idle secondmate before raising a wake-loop stall alarm (#5204)
* fix(bin): ring a proven-idle secondmate before a wake-loop stall alarm
A leftover foreign-queue row on an idle, alive, ring-safe mate is still drainable in that home. Ring once, reset the observation interval, and keep the parent alarm for unknown, busy, or still-frozen rows.
* no-mistakes(review): Mark drain steer with from-firstmate fire-and-forget carrier
* test(watch-arm): size re-arm waits off the real loaded recovery cost (#5335)
The re-arm recovery cases judged "the watcher stayed live instead of
surfacing recovery" with fixed budgets below what a real stale-lock
recovery costs on a contended host: the arm's default 10s confirmation
deadline, a start helper that returned after about 4s whether or not the
arm had confirmed its watcher, and an 80-poll exit wait.
A changed-suite run beside other suites starves the recovery's many
short-lived processes while this suite's sleeping poll loops keep their
pace, so a watcher still surfacing its recovery read as one that stayed
live (issue #3793).
The original 0.25s window after confirmation was widened to 80 polls in
#3837, which left the same race at a larger size.
Following the CONTRIBUTING.md fixture-budget rule, the re-arm helper now
gives the arm an explicit 30s confirmation budget and waits for its
confirmation or exit within a ceiling that outlasts it, and every wait on
a re-armed watcher uses one named iteration-counted ceiling that outlasts
the same budget.
A passing case returns as soon as the arm reports or exits, and a watcher
that never surfaces its recovery still fails.
A new case delays every mktemp and readlink the re-armed watcher runs
after it publishes its beacon, so its first poll and exit take about 13s
on any host.
It fails with the reported symptom on the previous budgets and passes now.
No bin/ change.
* fix: stop watchers reliably during blocked polls (#5362)
* fix(bin): let one TERM always stop the watcher on bash 5.2
Bash 5.2 runs a pending trap from the parser entry of the next command
substitution it expands, where the trap body is parsed as the inside of
that substitution and fails ("trap: line 2: unexpected EOF while looking
for matching `)'") or is dropped silently, consuming the signal. The
watcher's `trap 'exit 1' HUP INT TERM` could therefore ignore a TERM and
keep polling while its stopper waited: the triage suite's reap waited
forever (CI jobs cancelled at 30 minutes), and the arm's signal path and
the away-mode daemon's shutdown wait for the watcher the same way.
Bash 5.3 fixed the parser; 5.2 is the stock bash on Ubuntu 24.04.
HUP and TERM now keep bash's native fatal-signal handling, which runs the
EXIT trap (watcher_cleanup) and exits on bash 3.2, 5.2, and 5.3. INT keeps
its trap because bash ignores a direct SIGINT while a child runs. The
check-spawn deferral window no longer contains a command substitution.
The triage suite's reap is now bounded and fails the case within 10s with
process evidence instead of hanging the job, and a new regression test
proves TERM stops a watcher blocked inside a poll's pane capture and still
releases its lock and records an acknowledgeable stop.
* no-mistakes(document): Clarify watcher stop-signal documentation
* fix: submit stuck inbox doorbells instead of skipping them (#5374)
* fix(bin): submit our own stuck doorbell instead of skipping every later ring
* no-mistakes(review): Confirm and retry Enter once on stuck-doorbell submit
* no-mistakes(document): Clarify doorbell retry and pending-composer documentation
* feat: add opt-in fleet activity ledger (#5375)
* feat(bin): add the opt-in fleet activity ledger
Homes that create config/fleet-ledger get an append-only JSONL file,
state/fleet-ledger.jsonl, recording task.dispatched, task.status,
task.merged, and task.cleaned_up so outside tools can follow a fleet.
With the flag absent each producer does one file test and nothing else.
docs/fleet-ledger.md owns the record contract and its documented limits.
* no-mistakes(review): Record task.status text verbatim after the first colon
* no-mistakes(document): Clarify fleet ledger status and setup documentation
* no-mistakes(ci): Fixed a timing race in tests/fm-pi-branch-extension.test.sh: the replacement-wake test now waits for the prompt to start before releasing it. The focused test passed twice, and git diff --check passed
* fix: validate public follow-up deliverables and wake on rejection (#5352)
* fix(bin): format, validate, and surface public-followup deliverables
brief pre-fills report_path=data/<work-id>/report.md and states the accepted
format of every value it cannot know instead of a bare <value> placeholder.
fm-public-followup-emit.sh refuses a deliverable tasks-axi would refuse, in
both the direct and staged destinations, naming the key, value, and format.
consume records the specific deliverable, outcome, or missing key behind a
tasks-axi refusal, and each refusal wakes the owning home once through the
existing relay poll.
* no-mistakes(review): refuse emits missing a required deliverable in both destinations
* no-mistakes(review): require promised deliverables and keep rejections recoverable
* no-mistakes(review): mirror tasks-axi's canonical pull request URL rule
* no-mistakes(review): keep a rejection wake whose line cannot be read
* no-mistakes(review): key emit-time rules on the promise, not the outcome
* no-mistakes(review): bound deliverable keys and values as tasks-axi does
* no-mistakes(review): state rejection wakes as at-least-once and pin it
* no-mistakes(review): enforce the promised contract tasks-axi holds at emit
* no-mistakes(review): stop inferring a staged promise from its outcome
* no-mistakes(document): Refresh public follow-up documentation
* no-mistakes(ci): Fixed both CI flakes. Watcher cleanup is now installed before singleton acquisition, preventing timeout races from leaving stale locks while preserving recovery-failure evidence. Bearings render fixtures now publish a valid isolated Lavish session store and retire each listener after rendering, eliminating false unowned-source races. Verified with checkpoint stress, fm-watch-checkpoint, fm-watcher-lock, repeated fm-bearings-board-render runs, project lint, syntax checks, and git diff checks
* Revert unrelated CI auto-fix edits to the watcher and bearings board test
The CI step's automatic repair changed bin/fm-watch.sh and
tests/fm-bearings-board-render.test.sh to chase two intermittent CI
failures that also occur on main and are not part of this change. Restore
both files so this branch carries only the public-followup deliverable fix.
* no-mistakes(review): Refuse a repeated --deliverable key at emit argument parsing
* no-mistakes(document): Clarify public-followup validation and rejection-wake documentation
* feat: add Devin CLI crewmate and scout adapter (#5380)
* Add verified Devin CLI worker adapter
* no-mistakes(review): Drop Devin resolver refusal and launch marker
* no-mistakes(review): Verify devin in bootstrap, fold kind rule, update docs
* no-mistakes(document): Document Devin sidecar, resume, and worker-only facts
* no-mistakes(document): Document Devin interrupt, liveness anchor, composer signals
* fix(control): never pair Devin interrupt presses on an idle agent
A fast double Escape on an idle Devin opens its /revert picker, where Enter
reverts file changes. fm-control now sends the second press only after the
first renders Devin's 'esc again to interrupt' armed hint, never sooner than
0.5 s, closes a revert picker a mistimed press opened with one Escape, and
refuses to type the exit command while that picker is open. An unarmed
interrupt reports cancel=not-running and leaves the busy record untouched.
* fix(devin): disable Claude hook import and commit attribution for workers
The per-task Devin config now forces read_config_from.claude=false, so a
worker no longer runs the user's or project's Claude Code hooks (including
Herdr's Claude agent-state hook), and attribution=false, so Devin adds no
Co-Authored-By trailer or Generated-with line to commits and PRs.
* test(devin): extend live guard and record Herdr and revert-picker evidence
The credentialed live guard now fails if an imported Claude Code hook runs,
if the worker's commit carries Devin attribution, if an idle interrupt sends
more than one press or opens the revert picker, or if an open picker lets
exit through or is closed with a revert. The Devin reference, agent-control
doc, and verification records carry the 2026-09-22 tmux and Herdr lab results,
including the Herdr exit refusal.
* no-mistakes(document): Correct Devin documentation links and lifecycle guidance
---------
Co-authored-by: Denis Beliaev <battler73@yandex.ru>
* fix(bin): recognize passed-with-skips as a passing outcome (#5322)
fm-crew-state classifies the no-mistakes outcome 'passed-with-skips' as
unknown, so a finished worker awaiting merge is re-alerted as stale. The
same blind spot lets fm-teardown's pre-teardown terminal-run check refuse
a legitimate abort race that lands on this outcome.
Map passed-with-skips to done in crew-state resolution, keeping the
skipped publication/CI verification visible in the detail rather than
reporting a clean pass, and recognize it as terminal during teardown.
* fix(bin): refuse unavailable backend adapters before sourcing (#5382)
* fix: refuse missing backend adapter before source
* no-mistakes(review): Gate backend precheck under stock Bash
* no-mistakes(document): Clarify adapter precheck docs
* no-mistakes(lint): Suppress intentional child Bash ShellCheck warning
* test: repair base-red liveness, export-DOM, and wake-queue self-tests (#5338)
* fix(test): repair tmux liveness and calm follow-up loaded_off regressions
Both self-tests fail on untouched main on a host whose coreutils are a
multicall binary and whose Chrome has no pre-warmed profile, and each failure
masks the other's file.
tests/fm-tmux-agent-liveness.test.sh - the stand-in harness processes were
symlinks to the host's `sleep`. A single-purpose `sleep` runs happily under
another name, but a multicall coreutils binary (uutils or busybox) resolves its
applet from argv[0]: `claude-link -> sleep` invoked under the harness name runs
the wrong applet and exits immediately, so no foreground process exists and
every positive case reads not-alive ("last verdict for liveness:agent was
missing (expected alive); title=sh comms=[sh ]"). Build a dedicated spinner as
the stand-in target, exactly the way the version-string case already builds its
executable, and require the fallback target to demonstrably survive the rename
before using it. Every assertion is untouched; the stand-in identity signal is
unchanged (the kernel still records the symlink name as the executable
identity).
tests/fm-calm-pi-extension.test.sh - render_export_dom pinned a brand-new
`--user-data-dir` per attempt. On Google Chrome for Testing 151.0.7922.34 that
pristine profile makes Chrome's first-run initialization never complete: the
browser and its renderers start, but --dump-dom never returns, so all three
bounded attempts end exit=0 timed_out=yes bytes=0 and the DOM assertions never
run ("could not render calm-mode HTML export DOM"). Chrome's own profile
creation under a fresh HOME renders the same document in about a second, so the
helper now gives Chrome a private per-attempt HOME instead of the explicit
profile flag. Each attempt still gets an isolated profile, and every DOM
assertion is unchanged.
Root-cause evidence: a pristine --user-data-dir with `--headless=new
--dump-dom` had not returned after 150s, while the same command with an empty
HOME and no --user-data-dir returned the full DOM in ~1s, and reusing an
already-populated profile also returned it in ~1s. The render failure masked
the rest of the file: with it repaired, the Pi follow-up loaded_off case passes
unmodified against an installed @earendil-works/pi-coding-agent package.
These two failures block downstream validation of every lane on hosts with
multicall coreutils or a fresh Chrome profile.
Verification:
- timeout 300 bash tests/fm-tmux-agent-liveness.test.sh -> exit 0, 16 assertions ok
- timeout 700 bash tests/fm-calm-pi-extension.test.sh -> exit 0, 13 assertions ok,
including the Pi operational follow-up loaded_off case
- bash -n and shellcheck clean on both touched files
- rest of tests/: bin/fm-test-run.sh --all bounded by timeout 900 completed 17 files with 0 failures (fm-afk-contract.test.sh through fm-backend-herdr-launcher-workspace-e2e.test.sh), then the bound cut off the 18th (fm-backend-herdr-presentation-e2e.test.sh, a real-herdr-gated lab test) with no failure recorded
* fix(test): give wake-queue observation checkpoints the alerting ceiling
tests/fm-wake-queue.test.sh's secondmate stall case runs bounded foreground
watcher checkpoints whose job is to record an observation, with the alerting
checkpoint that follows asserting the stall. A checkpoint's exit publishes a
downtime marker, and the next checkpoint consumes it only by reaching the end of
the watcher's poll loop, where the recovery surfacing runs after the stall tick;
the observation itself is recorded by that same stall tick. On a loaded host a
1s ceiling sits under the cost of that iteration (which includes a pane capture
in the active-turn gate), so the observation was never recorded, the downtime
marker stayed pending, and the alerting checkpoint surfaced
`check: rearm-resurface` instead of the stall it asserts:
not ok - a foreign queue with no progress did not alert: check: rearm-resurface
not ok - a frozen reprovisioned queue generation was hidden: check: rearm-resurface
Give the observation checkpoints that feed a later alert the same 4s ceiling the
file already documents for alerting checkpoints. The ceiling is only a bound - a
checkpoint still returns on its first actionable wake - so no assertion is
weakened, and the quiet windows get longer, not shorter.
* no-mistakes(document): docs: correct export-DOM Chrome render root cause
* no-mistakes(review): Isolate Chrome profile on macOS, dedupe tmux CC_BIN lookup
* chore: re-trigger fork workflow approval for triage
---------
Co-authored-by: Captain <blackxwhite88@users.noreply.github.com>
Co-authored-by: kunchenguid <kunchenguid@users.noreply.github.com>
* fix: keep watcher status classification bounded to new log spans (#5383)
* fix(bin): classify a status span without re-folding the whole log
A watcher poll could take minutes, so its liveness beacon aged past the
guard's 300s grace and the Stop auto-arm reported the watcher down. On the
main home, cycles ended with beacon_age 91-235s while healthy and 534-706s
while the laptop was CPU-starved.
Cause: whenever a newly appended status span held a keyed needs-decision
or blocked line, status_span_first_actionable_record re-read and re-folded
the ENTIRE log to decide whether that opening was still live, forking
several subshells per line. On a remote second mate's mirrored parent
channel (1.2MB, ~2300 lines) that is 13-20k subshells, about 17s per log
per classification when idle, paid by every signal and heartbeat scan.
Nothing regressed recently: subshell counts per classification were
20,272 from #3268 (2026-08-29, which introduced the whole-log fold) and
13,188 from #3753 onward through HEAD. The cost grew with log size, since
parent-channel logs only grow.
Fix: fold only the captured span. An accepted opening does not depend on
earlier lines and only later lines close or supersede it, and every later
line lies inside the span, so the span fold names the same live openings
at a cost bounded by the span. Old and new classification outputs are
byte-identical across 51 span offsets of real-shaped secondmate and ship
logs.
A real-watcher regression test records every read the classification
makes through the span-reader seam and asserts none reaches before the
classified offset; it fails on the old code (5,157 bytes read from
offset 0 to classify an 84-byte span).
* no-mistakes(document): Clarify span classification and watcher regression coverage
* test: close pr-check watcher test gaps (original flake already fixed by #5362 and #4878) (#5381)
* test: fix watcher timing flakes in fm-pr-check-security
The bounded watcher's hang guard now counts only the watcher's own time: a
case marks the intervals where it holds the watcher on injected work or makes
it wait on concurrent work, and those no longer count against its budget. The
budget itself stays at main's sixty seconds. The helper also stops forcing a
one-second per-check timeout, which killed a correct merged poll whenever that
poll took longer than a second, so the watcher only retried it or exited on a
later check's wake without the merge.
The concurrent-publication case pauses the guard while its arming is in
flight, and its task now sorts before the contributions observer the arming
also registers, so the watcher stops on the poll under test before running
that unrelated fleet snapshot. The case also prints the watcher's stderr when
it fails.
The replacement case pauses the guard while the re-arm runs inside the
watcher, runs that injected arming with the fixture root every other arming
here uses, and waits on the replacement merge's process instead of a
two-second cap. Merged-poll runs retire the contributions observer before the
watcher starts, since no case here exercises it.
The returned-descendant case no longer races a four-second sleep or a TERM
landing at an arbitrary point in the watcher's idle loop: its descendant holds
until killed, and a second check in the same cycle witnesses that it was
drained and stops the watcher.
* no-mistakes(ci): Reproduced the intermittent board-render failure. Its Lavish stub listed an open session but omitted the session-state record required by the listener, so the build could race the listener’s exit. Added matching fixture state; the affected suite passed three consecutive runs, and shell syntax and diff checks passed
* Revert "no-mistakes(ci): Reproduced the intermittent board-render failure. Its Lavish stub listed an open session but omitted the session-state record required by the listener, so the build could race the listener’s exit. Added matching fixture state; the affected suite passed three consecutive runs, and shell syntax and diff checks passed"
This reverts commit 6a59859b2e2a3778f9b46faeea42d6de37468cd6.
* feat: record fleet status immediately and emit PR-ready events (#5385)
* feat: record task.pr_ready in the fleet ledger when a task PR is registered
* feat: record worker status lines in the fleet ledger as they are written
* no-mistakes(review): Keep worker status append failures and pass the resolved config to the ledger
* no-mistakes(review): Resolve relative config override before embedding in worker command
* no-mistakes(document): Clarify fleet ledger status capture timing
* test: synchronize foreign queue stall checks with watcher progress (#5386)
* test: synchronize foreign secondmate stall legs on the watcher's recorded observation
Each leg of test_secondmate_foreign_queue_stall_tracks_progress_and_alerts_once
ran the watcher under a 1s or 4s wall-clock checkpoint, but every later leg
depends on the progress observation the previous leg's watcher recorded. Under
load the watcher was killed before its first stall tick, the observation was
never written, and the next leg treated its own sighting as the first one, so
the stall alert never fired.
Run the watcher directly and end each leg on its observable outcome: the
progress marker recording the expected observation, or the watcher's own first
wake. Also move a comment orphaned above this test back to the drain liveness
test it describes.
* no-mistakes(review): Wait for full stall reset before stopping watcher leg
* test: isolate the bearings render fixture from the shared Lavish store (#5391)
The listener resolves its server from that store before it polls. Without a session for this bo…
gk-io-dev
added a commit
to gk-io-dev/firstmate
that referenced
this pull request
Sep 30, 2026
…bility fixes (#3) * feat(bin): add opt-in typed dispatch resolution (#4692) * feat(bin): add opt-in typed dispatch resolution through typesafe.ai Add bin/fm-dispatch-resolve.sh, which resolves one concrete crewmate or scout profile from a written brief with typesafe.ai's System One model: one Choice question over the rules' `when` texts, then the confidence floor, the rule's `approval` and `floor`, each profile's `provider` and `floor`, one quota-axi snapshot, and the spendPriority argmax all in code. It is off unless TYPESAFE_API_KEY is in the environment or the home's gitignored .env; off means one stderr line, exit 0, and no network call, so firstmate dispatches exactly as before. The key reaches curl on a file descriptor, never argv. Extract fmx_env_get into bin/fm-env-lib.sh as the one .env accessor and the harness-to-provider table into bin/fm-quota-axi-lib.sh so the new tool and bin/fm-quota-choose.sh share one owner each. Bootstrap validates the four new optional dispatch fields. Document the schema, the operator contract, the AGENTS.md intake step, and the live and benchmark evidence. * no-mistakes(review): Harden typed dispatch resolution and quota bounds * no-mistakes(review): Validate dispatch floors and ranking evidence * no-mistakes(review): Tighten dispatch response and floor evidence * no-mistakes(review): Neutralize none matching and resolve defaults locally * no-mistakes(review): Preserve providerless profiles outside typed resolution * no-mistakes(review): Validate response usage and reject duplicate profiles * no-mistakes(review): Escalate unverifiable floors and validate probabilities * no-mistakes(review): Validate probability mass and unknown profile floors * no-mistakes(review): Simplify resolver interface and preserve fallback routing * no-mistakes(review): Fix constants and rank partial quota evidence * no-mistakes(review): Add authoritative provider mapping and enforce explicit providers * no-mistakes(review): Declare provider for documented Pi profile * no-mistakes(review): Validate provider identifiers and support Gemini dispatch * no-mistakes(review): Strictly anchor provider identifiers * no-mistakes(review): Validate selectors and preserve fallback candidate evidence * no-mistakes(review): Gate typed validation and harden resolver evidence * no-mistakes(review): Preserve opt-in routing and harden candidate evidence * no-mistakes(review): Prioritize known exhaustion over quota uncertainty * no-mistakes(review): Isolate API secrets and preserve no-key diagnostics * no-mistakes(review): Fallback safely when dispatch rules are absent * no-mistakes(review): Prioritize quota vetoes and isolate bootstrap secrets * no-mistakes(document): Document typed dispatch safety and fallback behavior * fix(bin): read the latest status event so buried declarations and open decisions aren't lost (#3753) * test: reproduce buried status declarations in shared readers * fix: share status event reads and preserve open blockers * fix: retain terminal scout and ship status declarations * no-mistakes(review): Fix status chronology, legacy completions, and reader performance * no-mistakes(review): Share terminal decision reconciliation across fleet snapshots * no-mistakes(review): Unify terminal supersession across cached folds and consumers * no-mistakes(review): Filter per-key status history while preserving terminal chronology * no-mistakes(test): Preserve parent lock ownership in Bash 3.2 subshells * no-mistakes(review): Anchor legacy status tokens so prose cannot hide pauses * no-mistakes(document): Document latest-event status read and kind-scoped fold cursor * no-mistakes(lint): Quote literal done in test for-lists for SC1010 * ci: expect 19 snapshot/fleet-view tests This branch adds a fleet-snapshot regression, so the stock macOS Bash lane's hardcoded guard of 18 'ok - ' lines fails on the new count. Bump the guard and its message to 19. * no-mistakes(review): Restore multiline child outcome reporting * no-mistakes(review): Select ledger terminal events through bounded shared reader * no-mistakes(review): Report newest open decision instead of preferring blocked * no-mistakes(review): Require colon before ship/scout terminal supersession in fold * no-mistakes(review): Gate socket-down override on latest event; drop lock matrix * no-mistakes(review): Fold only colon-bearing or keyed lines as decision transitions * no-mistakes(review): Pre-select candidate lines before per-key closing-verb fold * no-mistakes(test): Update fleet-view expectations to newest-open-decision rule * no-mistakes(document): Align status-read docs with fold-resolved crew state * no-mistakes(document): Correct status-reader contracts in classify-lib and crew-state headers * no-mistakes(ci): Greptile P1 (bin/fm-crew-state.sh:729, "Stale socket blocker survives") was a real defect introduced by commit b7c2183 on this branch, and is fixed. Root cause: the daemon-socket-down override took its verb check from `last_status_line "$LOG"` but its evidence and emitted detail from `$LOG_LINE` (status_current_line = the fold's newest still-open decision). Those are different lines whenever a later recognized `blocked:` event is one the decision fold declines. Reproduced by sourcing bin/fm-classify-lib.sh on `blocked: no-mistakes daemon socket is missing` followed by `blocked [key=pending-reply-t3]: still waiting on the answer` (reserved-namespace key whose note does not speak that vocabulary, so _fm_decision_key_transition_allowed rejects it): open set still holds the socket blocker, last_status_line returns the newer line, its verb is blocked, so the gate passed and the stale daemon-down evidence overrode a healthy attributed run. Fix (bin/fm-crew-state.sh): capture LOG_LATEST=$(last_status_line "$LOG") once and read verb, socket-down evidence, and the emitted note all off that same line, so the override fires only while the socket-down declaration is itself the log's latest recognized event — preserving the narrow override the prior round's user instruction asked for. Comment updated to state that contract. No new machinery; the two-line conflation was removed rather than papered over. Regression: extended tests/fm-crew-state.test.sh:test_socket_refusal_override_expires_when_the_crew_moves_on with the reproduced sequence, asserting the run-step reading (state: working, source: run-step) and absence of the override detail. It fails before the fix ("not ok - a later unfolded blocked event also hands the reading back to the run (missing: 'state: working')") and passes after. Verified locally: tests/fm-crew-state.test.sh, tests/fm-fleet-snapshot-view.test.sh, tests/fm-classify-decision-key.test.sh, tests/fm-watch-triage.test.sh, tests/fm-captain-hold-lifecycle.test.sh all pass; bin/fm-lint.sh (shellcheck 0.11.0 + actionlint) exits 0. Changes left uncommitted in the worktree * test: fold terminal-cleanup snapshot coverage into the completed-scout case Keep the ship/scout/secondmate supersession assertions without adding a nineteenth top-level fleet-view test, so CI can stay at the upstream suite count. * no-mistakes(document): Clarify socket-down override expiry in architecture doc * ci: retrigger flaky contribution check * fix(bin): launch codex crewmates with codex's hook layer disabled (#4689) * fix(spawn): launch codex crewmates with codex's hook layer disabled A freshly launched Codex worker never reached its instructions. Codex stopped it on an interactive "Hooks need review" modal whose selection sits on "Review hooks", which is neither trusting nor declining. Firstmate's key plane carries only Enter, Escape and Ctrl-C with no arrow navigation, so the selection cannot be moved, and pre-accepting the prompt by writing Codex's own trust store would record an operator consent that was never given. The hooks are the machine's own ~/.codex/hooks.json plus any project's .codex/hooks.json. A crewmate needs neither: its turn-end signal is the -c notify= program on the same launch, and Firstmate's project hooks are primary-session infrastructure that stands down in a child worktree. Crewmate and scout launches now pass --disable hooks. That is the opposite of --dangerously-bypass-hook-trust, which RUNS the untrusted hooks; disabling the feature runs none of them and leaves the operator's ~/.codex untouched. An unknown feature name is a hard Codex error, so a release that drops the flag fails the launch loudly instead of silently restoring the modal. A secondmate is a primary in its own home and keeps the project hooks its turn-end guard and session-start digest ride on. Verified on codex-cli 0.151.0: the modal is gone and the turn-end notification still lands. This unblocks the second review that every finished pull request is supposed to get. Fixes kunchenguid/firstmate#4673 * no-mistakes(review): Fix contradictory hook count in Codex verification record * fix(bin): settle terminal contribution observations (Fixes #4669, Fixes #4670) (#4710) * fix(bin): settle terminal contributions and wake once per read-failure episode A contribution whose last good observation is merged or closed is final: poll no longer re-reads it, projection keeps it fresh, and a stale error recorded beside it is cleared once. A genuine forge-read failure on an open contribution still records its error on every cycle but prints the unavailable wake only when it starts a failure episode; a successful read ends the episode. Open PRs linked from done tasks keep being observed. The false unavailable beside a complete observation was budget exhaustion mid-observation, already fixed by #4661. * fix(review): Settle terminal contribution owners * fix(review): Deduplicate shared contribution failure episodes * fix(test): Preserve settled terminal contribution records * fix: select authoritative no-mistakes runs (#4476) * fix(crew-state): select authoritative validation runs by identity Use the AXI run overview and id-addressed status reads to preserve replacement review gates, report competing live runs as unknown, and retain newer failures. Keep the coarse ledger in creation order rather than preferring an older live row. Refs: https://github.com/kunchenguid/firstmate/issues/3215 * fix(review): Resolve same-branch run identities beyond capped history * fix(review): Fix run-selection compatibility, races, and worker-state fallbacks * fix(review): Limit run validation to the requested branch * fix(test): Anchor AXI fixtures and document remaining live evidence gaps * fix(document): Clarify run selection documentation and capture ownership * fix(lint): Fix ShellCheck diagnostics while preserving fixture isolation * fix: distinguish captain outcomes from no-op updates (#4738) * fix(AGENTS): send a captain-facing outcome instead of shipshape for finished requested work MAIN answered a supervision-branch outcome for completed captain-requested work (implementation done, PR ready for review and merge approval) with "Captain, shipshape.", reading section 9's no-action reply as covering it and reading the Pi protocol's "do not re-emit the anchor verbatim" as "no captain-facing response is owed". Section 9 now limits the shipshape reply to true no-ops (idle re-read, empty heartbeat, consequence-free acknowledgement) and requires a short outcome response naming what finished and what word is needed whenever requested work finishes or a result needs the captain's word, even when a transcript entry already shows the substance. The Pi protocol's re-emit rule now says it bounds repetition only, and carries a worked example of the ready-for-review outcome whose correct processing turn a shipshape reply fails. No executable contract evaluates the content of MAIN's captain-facing reply, so the regression is the protocol example in the owner doc rather than a text-match test. * no-mistakes(document): Clarify captain-facing outcomes versus no-ops * docs(pi): restore the ready-for-review regression example as a preserved-verbatim contract line The document step condensed the Pi protocol's re-emit rule and dropped the worked example of a finished, ready-for-review outcome whose correct processing turn a "Captain, shipshape." reply fails. That example is the contract's regression: no executable contract evaluates the content of MAIN's captain-facing reply, so the owner doc's example is the test case. Restore it directly under the re-emit rule, prefixed as a regression example that is kept verbatim and never condensed or summarized away. * no-mistakes(review): Clarify captain outcome and decision-word requirements * no-mistakes(document): Clarify captain-facing completion outcomes * docs(pi): require the PR URL in the visible captain-facing outcome reply Captain review on the regression example: drop the sample reply string and say only that the ready-for-review outcome requires relaying a captain-facing outcome response, not just "Captain, shipshape.". Fold in the visible-PR-handoff failure seen this session: after the branch outcome reporting this fix green, MAIN's visible reply was only "Awaiting your merge call." with no PR URL, leaning on the dim anchor. Section 9's URL rule now also covers a review or merge ask and names the visible reply as where the URL goes, sourced from the ready status, pr= metadata, or the supervision branch's summary and never left to a transcript entry. The Pi protocol adds the same-way failure and places the captain-facing text in the final visible assistant reply after the fm_branch_processed call, because Calm hides assistant text emitted in the same step as a tool call as a working note. Investigation verdict, evidence in the PR comment: no recent PR caused the handoff failure; Pi has hidden same-step pre-tool assistant text since #2339 (2026-08-13), #4655 changed only the Claude Code mod, and #4658 touched only remote report transfer. * no-mistakes(review): Restore safe outcome ordering and consolidate PR URLs * no-mistakes(document): Clarify captain-facing supervision outcomes * docs(AGENTS): keep the whenever-a-PR-is-mentioned trigger on the consolidated URL rule The consolidated section 9 URL rule narrowed its trigger to a review or merge ask, dropping the "whenever a PR is mentioned" catch-all from #3648 that keeps every PR URL copied from a durable record and never assembled from memory. Restore that trigger as a union with the review or merge ask so the one consolidated rule covers both. * fix(bin): let non-owner Claude Stops exit safely (#4777) * Fix foreign-owner turn-end supervision loop * no-mistakes(review): Scope foreign-owner safe exit to Claude guard * no-mistakes(document): Document Claude foreign-owner safe exit * fix(bin): survive bash 3.2 empty-array expansion in watcher churn absorb (#4778) Under set -u, stock macOS bash 3.2.57 treats "${arr[@]}" on an empty indexed array as an unbound variable and aborts the shell. In signal_turnend_panes_churned() the missing_keys loop was reachable with an empty array whenever every churned key already held a fresh .churn-since-* marker (a second churning turn-end inside an open deferral window), so each watcher cycle died about half a minute in and supervision restarted endlessly. The created_keys rollback loops had the same latent crash on their error paths. Audit of bin/ for the same pattern found one more confirmed-reachable case: remote_handoff's noncanonical-body scan iterates to_move, which is empty when a retried remote handoff finds every key already staged in the outbox. All other "${arr[@]}" sites are either count-guarded, guaranteed non-empty by construction, or unreachable while empty. Guard the three reachable expansions with the repo's existing "${arr[@]+...}" idiom. New regression test drives a real watcher through the all-marked churn path; the macos-stock-bash CI lane runs it under real /bin/bash 3.2 via FM_TEST_ONLY. * Make the foreign-owner turn-end repro create a Linux-readable session lock. (#4783) The synthetic harness was named synthetic-claude, which Linux procps truncates to synthetic-claud so fm-lock.sh never matched a harness or wrote state/.lock before the test read it. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: require complete captain-facing final responses (#4779) * docs: require complete final responses across harnesses * no-mistakes(document): Document complete final replies for Grok Bot * docs: point Grok replies to the shared contract owner * no-mistakes(review): Clarify final recap without batching decision asks * fix: preserve substantive mid-turn text in Pi Calm (#4788) * fix(calm): preserve substantive Pi mid-turn text * no-mistakes(review): Preserve substantive Pi Calm text per block * no-mistakes(test): Cover shared Calm preservation boundaries behaviorally * no-mistakes(document): Consolidate Calm preservation documentation * fix: harden mail checks and rebalance full-coverage CI (#4800) * Improve CI reliability and rebalance full-coverage validation * no-mistakes(document): Clarify lint partition documentation * fix(bin): answer Kimi 2.0.0 folder-trust dialog during spawn (#4799) * Handle Kimi workspace trust dialog * no-mistakes(review): Retry Kimi trust Enter and gate ready on dialog markers * no-mistakes(review): Gate Kimi ready on any trust marker and clean captures * no-mistakes(review): Read visible pane for Kimi trust and ready gates * no-mistakes(review): Add per-backend visible-pane capture for Kimi trust gate * no-mistakes(review): Harden Kimi viewport capture and trust dialog detection * no-mistakes(document): Document Kimi spawn refusal on cmux and Orca * fix(bin): report a dead-agent record once instead of escalating forever (#4775) * fix(bin): report a record whose agent is gone once instead of escalating forever The wedge escalation path never asked whether there was still an agent to be wedged. A wedge is something stuck that might recover, so re-alarming it earns its cost; an agent that is gone never moves again, its pane never churns, the idle timer never resets, and the escalate path clears its own timer and re-arms with nothing bounding the count. Observed on a live fleet: two finished lanes reached 226 and 203 consecutive escalations, roughly one every FM_STALE_ESCALATE_SECS, indefinitely - about 400 notifications a day from two lanes with no agent running at all. On one, fm-control.sh exit answered already-stopped and fm-crew-state.sh read "failed - run failed". Closing the Herdr pane did not stop it either: with the pane genuinely gone and herdr pane read returning pane_not_found, the count kept climbing, because the poll is driven by the record's window= line rather than by the pane. The cost is not the repetition but that it drowns the alarms that matter. fm_backend_agent_state already separates a thinking agent from a gone one at process level. In the branch that was about to escalate, read it once and treat only its two recovery-grade verdicts - dead (endpoint present, no agent in it) and missing (endpoint authoritatively absent) - as proof, reporting that record once and not re-escalating it while it stays that way. Every other verdict, including alive, ambiguous, unreadable, unverified, and a read that failed outright, keeps the identical schedule, reason, and escalation count, so a genuinely wedged live agent is unaffected. The probe costs at most one backend read per window per threshold, the same budget the declared-wait consult and the worktree write probe already take. The report decides nothing about the record's fate: both lanes still held unlanded work and teardown refusing them was correct, so retiring, relaunching, or cleaning up stays with the supervisor. The once-only marker is owned entirely by that function and is dropped by the same read the moment the endpoint stops reading gone, so a replacement launched into the same window escalates normally and its own later death is reported again. Related, and not closed by this: #4412, #4482, #4316. Tests drive the real watcher against a record whose endpoint does not exist and pin both directions: dead and missing report once and never advance the count across later thresholds, while alive, ambiguous, and unreadable endpoints keep escalating with the identical reason and a climbing count. * fix(bin): bind the once-only dead report to the pane it reported Review of the parent commit found a reachable sequence where a later death in the same window lost its promised report. The marker was keyed on the verdict string alone and dropped only when a threshold probe read a non-gone verdict, but probes run only at thresholds: a replacement launched into the same window that dies without ever being probed alive - it crashes at startup, or works and then crashes - was absorbed by the previous death's marker. The pane's first sight yielded only the generic stale wake and every later threshold matched the stale marker, so the second death never got the detailed once-report that both the function's own comment and docs/architecture.md promise. Record the verdict together with the pane hash it was reported for, and absorb a repeat only while both still match. A replacement churns the pane, which resets the stale suppressor, wedge timer, and escalation count while no reset site touches this marker, so the pane half is what tells the second death apart from the first. The live-probe drop stays as it was. Clearing the marker at those reset sites instead would re-open unbounded re-alarming for a dead pane whose display ever ticks, which is the exact defect the parent commit exists to close. The noise bound is unchanged: an unchanged dead pane still absorbs on every later threshold and never advances the escalation count, and every verdict short of proof still escalates exactly as before. * no-mistakes(review): Key the dead-record once-marker on the busy incarnation token * no-mistakes(document): Document dead-record escalation cap in stale-pane config entry * no-mistakes(document): Add busy-state inventory line to AGENTS.md * no-mistakes(document): Document dead-record probe on busy-turn-bound wedge path * fix(bin): create captain-hold rows when Beads requires due (#4854) Captain holds have no due semantics and are a hold kind, not a Beads issue type. The create path now waives due.required and maps to native type task. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: disable compact adviser for spawned agents (#4877) * feat(bin): launch every spawned agent with the compact adviser disabled Every crewmate, scout, and secondmate Firstmate launches now starts with COMPACT_ADVISER_DISABLE=1, on a fresh spawn and on a relaunch alike, so an unattended session never activates the compact adviser. The value is unconditional: no configuration file gates it and there is no override, unlike the trace carrier beside it. Three carriers deliver it, because no single one covers every launch shape. The pane shell receives an export beside GOTMPDIR, so the agent's own children inherit it too. The launch command carries an explicit assignment, prepended outermost so it wins over any ambient value the pane already held. The cleared launch environment sets it again at the `env -i` boundary and keeps COMPACT_ADVISER_DISABLE in the fixed operational floor, which is what preserves the switch when config/launch-env-allowlist empties the environment, and what delivers it on a remote host that never had the value. bin/fm-control.sh relaunch, the bootstrap secondmate relaunch, and the remote secondmate transport all rebuild their launch through bin/fm-spawn.sh, so they inherit the same floor. The captain's own primary session is untouched. The two new suites drive the real spawn and then execute the launch command the pane actually received, with the harness replaced by a probe that prints its own environment, rather than matching script text. They cover ship and secondmate launches with the allowlist absent and enabled, the pane export and its ordering, fm-control.sh relaunch, and the full parent to remote-host chain. * no-mistakes(review): Export compact-adviser disable across compound launches * no-mistakes(document): Document spawned-agent compact-adviser environment guarantee * fix(bin): preserve Claude lock ownership after helper recycling (#4894) * fix(bin): let a background Claude session keep owning its session lock Session-lock ownership was decided by process ancestry alone. Under an unattended Claude session the model loop runs in a transient bg-spare bridged to the front-end by a shared daemon; when that bridge is recycled the contiguous claude-named ancestry from a hook to the recorded owner breaks while the owner pid stays alive, so the Stop auto-arm stood down as a foreign live owner, the turn-end guard ended every turn with its read-only diagnostic, and fm-lock.sh refused - a self-sustaining outage until restart. Ownership is now ancestry membership OR a trusted same-session id, never id-first: - fm-session-lock-lib.sh accepts CLAUDE_CODE_SESSION_ID only when CLAUDE_PID is a Claude-shaped member of the current contiguous run, compares it against the id recorded in state/.lock-session, and requires the recorded pid to still be a live harness. No id, no sidecar, an untrusted id, a different id, or a dead recorded pid leaves the ancestry verdict unchanged. Ids are never read from ps argv. - fm-lock.sh accepts a same-session holder at both refusal sites, writes, refreshes, and clears the sidecar only under its claim lock (including the early already-mine exit, skipped only while the deferred startup sweep leases that lock), keeps it byte-identical across a same-session confirmation, records CLAUDE_PID on lock line 1 for a session with a trusted id so a shared daemon or front-end that outlives the session never keeps a dead session's lock alive, never rewrites a live line 1 on a same-session confirmation, and names the recorded id in the live-owner refusal. - The .lock line-1 format is unchanged, so every reader that takes the whole first line as the pid keeps working; the guard's foreign-owner exit is unchanged and inherits the fix through the shared predicate. Tests: the ancestry suite drives the ancestry and id signals apart in a deterministic process table (asserting the divergence) and runs a real orphaned front-end/daemon/pty-host/spare tree through six phases with the real lock, auto-arm, and guard scripts; the foreign-owner repro keeps its negative control and adds a same-id positive control. Disclosure: no live unattended Claude background session ran on the verifying machine. The topology is documented by the real process listings in #3902, #2314, #3398, and #4066; coverage is the structural predicate plus the executable fixtures, not a live pass. Residual: bin/fm-sessionstart-nudge.sh keeps its own private ancestry walk (it only decides whether to print a nudge) and may nudge on a resume in the recycled case. Out of scope, deliberately: no structured lock format, no guard budget changes, no daemon-identity rejection, no fork lineage. * no-mistakes(review): Wait for claim lock; revert failed sidecars * no-mistakes(review): Revalidate ownership after wait; restore sidecars * no-mistakes(review): Roll back sidecar by publication phase * no-mistakes(review): Restore sidecar only if lock line is unchanged * no-mistakes(review): Trust session ids without a spelling allowlist * no-mistakes(review): Disarm sidecar rollback before backup cleanup * no-mistakes(document): Updated session-lock ownership documentation * feat: park main under the away posture on Pi (#4889) * feat: park main under the away posture on Pi While the away-posture record exists on a Pi primary, the supervision branch takes every actionable wake, no processing turn opens on main, captain rows accumulate for the return brief, and main's standing authority relocates to the branch through the existing guarded scripts. - lib/fm-branch-dispatch.ts: read the record at every routing decision; while it exists claim check, decision-owned, and heartbeat rows too, keeping the two broken-queue vetoes; expose checkSeqs so a claimed check row lifts task scoping. - fm-primary-pi-watch.ts: offer every actionable row under the record; a declined wake and every watcher-failure alarm still reach main. - fm-branch-supervision.ts: drop the legacy .afk decline; append a fixed POSTURE: AWAY tail carrying the record's read-back verbatim per wake; open no processing request while the record exists, re-checked immediately before a request would open and at every run boundary; present the accumulated rows at the first run boundary after archive. - fm-lease-lib.sh: fm_lease_forbid_branch passes the branch for opted-in actions only while fm-afk-contract.sh validate succeeds on a confirmed live record; PR merge, fresh spawn, and decision answer opt in, local landing never does. - fm-send.sh: a --resolve-key naming an open needs-decision or captain-held task is a decision answer and meets the partition; blocked: keys stay steering. - fm-spawn.sh: enforce the record's spend cap for a fresh ordinary spawn by either actor; relaunches and secondmates exempt. - fm-branch-prompt.sh: fixed Postures section and the verbatim ask-user-authority policy; the prefix stays byte-stable. - fm-afk-return.sh: count what the away session handled from the store. - docs, afk skill, AGENTS.md stub: main parked on Pi, green merge gate absolute while away. - tests: watcher and branch extension suites, fleet-record, merge, and decision-answer suites cover the relocation, the vetoes, the tail, the parked processing turn, the cancellation, the re-presentation, and the spend cap; dated live-guard evidence recorded. * no-mistakes(review): Refuse branch merge after preflight archive race * no-mistakes(review): Fix away wake, spawn, and processing races * no-mistakes(review): Suppress parked processing; narrow away-only rejection * no-mistakes(review): Abort dedicated processing; gate branch spawn once * no-mistakes(review): Stamp away-only on the dispatch offer * no-mistakes(review): Treat invalid away records as spend-cap absence * no-mistakes(review): Drop spawn test hook; abort processing-opened runs * no-mistakes(review): Bind abort to opening prompt; cap-read absence * no-mistakes(review): Limit away branch spawn to queued work only * no-mistakes(document): Correct AFK posture documentation * ci: standardize workflow timeouts into three tiers (#4910) * ci: simplify CI job timeouts to a three-tier policy Replace the scattered per-job timeout values (10m parallel, 25m lint, 30m serial, 10m macOS) with three readable tiers, each a hang tripwire with headroom rather than a packing estimate: - fast (5m): coverage guard, repo invariants, timing aggregate - normal (30m, one shared budget): lint partitions, portable parallel shards, portable serial shards, macOS stock Bash - heavy (Herdr only): 20m step tripwire on the family run so always() cleanup still runs, under a 75m job-level last-resort backstop The workflow's header comment states the policy and points at docs/fm-test-portable-shards.md "Timeouts", which now owns it, and each job names its tier beside timeout-minutes. tests/fm-ci-workflow.test.sh asserts the policy against the parsed workflow instead of the old per-job minute values: every job joins exactly one tier, exactly three distinct job-level values exist, the fast tier stays within 5-10 minutes, the normal budget stays at least double the modeled parallel lane sum reported by fm-test-run.sh --check-coverage, and the Herdr step tripwire stays below its job backstop with an always() cleanup after it. Concurrency supersession, shard counts, lane membership, and fail-fast settings are unchanged. * no-mistakes(review): Decouple the normal timeout from packing estimates * no-mistakes(review): Assert Herdr teardown follows the family run * no-mistakes(review): Pin Herdr family-run timeout to 20 minutes * no-mistakes(review): Ignore comments when identifying Herdr steps * no-mistakes(review): Identify Herdr steps by declarative ids * no-mistakes(document): Clarify authoritative three-tier timeout policy * fix(bin): keep supervisor status closes from waking the same home (#4895) * fix(bin): keep supervisor status closes from waking the same home A drain that already folded OPEN DECISIONS has presented those bytes even when the watcher has no matching seen marker. Treat that fold, and the presentation cursor, as known so the bookkeeping close stays quiet while later worker lines still signal. * no-mistakes(review): Keep folded worker failures waking past supervisor closes * no-mistakes(review): Wake on unlisted folded worker lines; batch multi-key closes * no-mistakes(review): Stop folded worker resolved lines from counting as already read * no-mistakes(document): Correct self-announced close marker contract in docs * fix(bin): stop labeling Herdr as experimental (#4972) * Stop steering operators away from Herdr * no-mistakes(review): Neutralize remaining Herdr opt-out documentation wording * fix(bin): treat a live no-mistakes run as current after rebase (#4973) * fix(bin): treat a live no-mistakes run as current after rebase A running run on the task's branch is authoritative regardless of head. Matching only the local head made a rebased in-flight run look failed. * no-mistakes(review): restrict coarse live-any-head to foreign-branch answers * no-mistakes(review): reject gate-parked runs from the executing predicate * no-mistakes(review): hoist gate-marker patterns into single run-lib owner * no-mistakes(review): require live daemon for head-free run binding * no-mistakes(review): require answered daemon-down before unbinding live runs * no-mistakes(review): extend daemon guard to anchored continuation routes * no-mistakes(review): delete live-any-head; restore dead-daemon verdict * no-mistakes(review): keep parked gates parked; name dead daemon everywhere * no-mistakes(review): set dead-daemon verdict instead of emitting early * no-mistakes(review): align selected route with legacy dead-daemon handling * no-mistakes(review): drop unproven-record binds; narrow coarse gate reading * no-mistakes(review): narrow header, drop vestigial guard, retarget tests * no-mistakes(review): revert coarse gate override; require answered-down probe * no-mistakes(review): cache one daemon probe; stop duplicating run id * no-mistakes(review): restrict coarse dead-daemon verdict to moved-off rows * no-mistakes(review): delete coarse dead-daemon extension and gate note * no-mistakes(review): delete remaining coarse dead-daemon block and stale docs * no-mistakes(document): document rebase-safe live-run bind and unverified-record verdict * fix(bin): prevent long worker launch command truncation (#4994) * fix(bin): stage the launch command in a private file and type a short source line A long launch line typed while the fresh pane shell is still busy waits in the terminal's canonical line buffer, which drops input past about 1,024 bytes on macOS, so the pane was left at an unfinished command with no agent running. fm-spawn now writes the assembled command to the task's own temp root under umask 077 and types only a short line that sources it. Refs #4559 * fix(bin): keep the per-task temp root private before staging the launch command The root lives at a predictable path under /tmp and now holds the whole launch command. Create it with mode 0700, refuse one that already exists as anything but a directory owned by this user that nobody else can write, and tighten an owned one, so no other local user can plant or swap the staged file. Refs #4559 * fix(bin): enforce private staged launch file mode * test(spawn): cover long staged Claude launches * no-mistakes(review): Namespace launch files and prove truncation staging * no-mistakes(review): Use immutable per-spawn launch filenames * no-mistakes(document): Document staged launch delivery safeguards * no-mistakes(ci): Updated eight behavior tests/fakes to execute or inspect immutable staged launch files instead of expecting inline launch commands. This restores Muse, secondmate lifecycle/restart, remote trace/parent binding, compact-adviser, and Orca coverage. All affected tests, dispatch-profile regression, fixture tests, syntax checks, ShellCheck, and git diff checks pass --------- Co-authored-by: Vytautas Stankus <svycka@gmail.com> * test: authorize isolated Herdr lab validation (#4998) * Add isolated Herdr runbook to test instructions * no-mistakes(review): Drop substring matching from test.instructions contract * no-mistakes(review): Assert commands.test key absence in YAML * Drop unit-first sentence and instructions contract test Captain-scoped follow-up on the Herdr-lab test.instructions ship: keep the lab safety runbook only, and leave the no-mistakes contract test focused on commands.test absence. * docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (#5001) * docs(vision): accept vendor-semantics and 9k contract-ceiling amendments (#4873) Replace the pixels-of-today's-UI rule with a quarantined, version-pinned surface-adapter exception recorded as standing debt. Cap the always-loaded contract at 9,000 words and require prune-or-trigger before a crossing change lands. Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> * docs(vision): restore accepted three-sentence vendor-semantics form (#4873) Replace the compressed paraphrase with the issue's accepted wording: a named quarantined version-pinned adapter, expected to break, recorded as standing debt that never hardens into a shared contract. Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kun Chen <kunchenguid@users.noreply.github.com> * feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974) * fix(watch): recheck a gate awaiting a human instead of wedge-escalating it A lane whose validation run is parked at a gate waiting on a human decision is correctly quiet, but nothing in its status line says so: the evidence is the pipeline's own gate state rather than anything the worker wrote. The wedge timer read that silence as a suspected wedge and climbed the escalation ladder for as long as the wait lasted, and each escalation cost a supervising turn. The landed declared-wait consult does not reach it, because a live ordinary crewmate never reports a declared pause, and raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for every lane by the same amount. The threshold now reads a second, independent record when the status line accounts for nothing: whether the crew's current state is a gate whose answer is owed by a human. That is minted only from the gate's own findings table, by a row whose `action` column is exactly `ask-user`, located by position out of the table header the way nm_gate_step_row already reads its row - never searched for over the run payload, where a finding's free-text description or a branch name satisfies a search just as well. A gate awaiting the CREWMATE's own answer keeps the unchanged escalation schedule, reason and demand-deep-inspection wording, because a crewmate that goes quiet before answering its own gate is exactly the wedge the ladder exists to catch. Each kind of wait now carries the human it is on, the action that clears it, and whether that human is the captain as data alongside the verdict, rather than as wording chosen per branch where the recheck is written, so the deferral cannot word one kind of wait as another and a new kind cannot ship without deciding all of them. A parked gate has no written record of when its wait began, so its recheck publishes no wait age at all rather than one read from the quiet window this deferral resets on every pass, which would report the same small number for a gate of any age. Like every other captain-facing recheck here it is absorbed in silence while the away-posture record exists, arming no throttle, so the recheck is owed in full the moment the record is archived. The consult runs only in the at-threshold branch that was about to escalate, beside the worktree walk already there, and only for lanes whose status line explained nothing. Closes #3055 * no-mistakes(review): require an unanswered decision before deferring a parked gate * no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records * test(watch): pass the pane hash wedge_timer_check now takes Upstream gave wedge_timer_check a sixth <pane-hash> argument for its dead-record probe. The malformed-wait-record rounds drive the real function directly, so they pass one, and stub fm_backend_agent_state to a live agent so the probe that runs after a refused deferral keeps the unchanged ladder rather than reading a backend the child shell has none of. * no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate * no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling * feat(watch): make the parked-gate wait deferral opt-in The wedge timer deferring a lane parked at a validation gate is new supervision behaviour rather than a restored one, and it decides which lanes give up the escalation ladder, so it now ships as a default-off per-home option instead of changing every home on upgrade. config/wedge-defer-parked-gate arms it. The flag is read before the decision fold, so an unconfigured home spends no fold or current-state read, writes no record, and keeps the unchanged escalation schedule, reasons and demand-deep-inspection wording; a test counts the reader calls in both directions to pin that. It is not inherited by secondmate homes: each home supervises its own crew and owns that trade separately, the same reason config/turnend-churn-absorb is home-local. The away-posture absorb returns to leaving the idle timer alone, which it had restarted only because the costly consult could reach it. A parked-gate wait is owed to the supervisor rather than the captain, so it never enters that branch, and the recheck owed on return is again owed in full the moment the record is archived. * test(watch): pin that the away-silenced hold leaves the idle timer alone The absorb no longer restarts the timer, so the recheck owed on return is owed in full rather than a cadence into the return. Nothing asserted that, so a restart could be reintroduced silently. * no-mistakes(review): document away-silence rationale, pin captured gate component * no-mistakes(test): anchor gate row scan to the braced findings header * no-mistakes(document): pin same-block gate row invariant in crew-state comment * fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007) * fix(control): let the owning seat reclaim a task whose endpoint is gone A destroyed pane or workspace made `missing` a terminal state. Relaunch accepted only `dead` and said to stop the agent first; exit refused `missing` and said to reconcile the task first; there is no reconcile verb. Each command named the other as its prerequisite, so a task whose terminal went away could not be reclaimed by anything, and a no-mistakes approval it was parked on had no seat left to answer it. `missing` is agent-free a fortiori: there is no endpoint, so there is no agent in it. Widen the existing guards rather than add a verb. - fm-spawn --relaunch accepts a positively proven `missing` and creates one fresh endpoint in the recorded worktree; the record it already republishes rebinds the task to it. A `dead` endpoint is still adopted in place. - fm-control exit reports `endpoint-gone` instead of dying, so the relaunch transaction's stop step no longer dead-ends, and re-resolves the endpoint from the record before verifying the replacement. The duplicate-agent refusal is untouched: both verdicts come from the same recovery-grade classifier, which claims `missing` only from positive absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The backends' own create paths refuse a live same-labeled endpoint as a second independent guard. The worktree, its branch, commits, uncommitted changes, armed poll and registration, record rows, and status log are all untouched - a reclaim is a recovery, never a teardown. A secondmate is excluded: its gone-endpoint recovery already has one owner in the session-start liveness sweep, so relaunch refuses and names it rather than becoming a second path to the same outcome. Tests reproduce both halves of the deadlock, the reclaim succeeding, unlanded work surviving it, and the refusals that still hold. * no-mistakes(review): prove endpoint absence per backend before reclaim rebinds * no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session * no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly * no-mistakes(review): stop refusals and docs asserting unestablished causes * no-mistakes(review): stop herdr fixture helper losing tmp-root registration * no-mistakes(review): document workspace drift and absence-probe server residue * no-mistakes(review): correct rebind limitation to its one reachable case * no-mistakes(review): stop claiming reclaim leaves instructions untouched * no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage * no-mistakes(rebase): read the staged launch file in the herdr fixture Rebasing onto main picked up #4994, which stages a long worker launch command into a script and delivers the short `. '<path>'` line instead of the literal command. The tmux fake and tests/fixtures.sh were updated for that; the herdr fake this branch adds was written before it and still keyed "an agent now exists on this pane" off the literal `encode launch-brief` text, so after the rebase it never marked the rebound pane live and the reclaim's alive-wait read `dead`. Dereference the staged file first, exactly as the tmux fake above does. Test-fixture only; no production path changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(document): note reclaim placement in herdr and scripts inventories --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(bin): stamp status events with their emission time (#3764) * test(status): reproduce missing event emission time * wip(status): preserve optional event emission time * test(status): document indirect clock stub invocation * no-mistakes(review): Preserve historical status bytes during reply recovery * no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies * no-mistakes(review): Preserve captain regex overrides for timestamped status events * no-mistakes(document): Clarify status event timing and publication contracts * no-mistakes(lint): Quote literal done to satisfy ShellCheck * no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed * no-mistakes(test): Preserve terminal notifications with malformed timestamp tags * no-mistakes(test): Stamp Rovo spawn failures with emission time * no-mistakes(document): Verify status event documentation * no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests * no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed * no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed * no-mistakes(review): Stamp remote escalations at call sites, drop new flag * no-mistakes(review): Accept stamped escalation and close lines in test assertions * no-mistakes(review): Restore reserved-key answered-note guard for stamped closes * test(status): accept optional emission time in PR-provenance assertions The #4148 provenance test landed on main with exact unstamped greps. Parent-channel lines from this branch carry [at=<epoch>], so strip only that tag before the same exact match. No production change. * no-mistakes(review): Accept stamped ready signal in PR fallback scrape * no-mistakes(review): Drop relay flag, stamp parent events at call sites * no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture * no-mistakes(review): Accept optional stamp in live cmux drift guard * no-mistakes(review): Restore original test invocation order in two suites * no-mistakes(review): Strip only well-formed numeric status time tags * no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc * no-mistakes(review): Stamp agy spawn-failure status lines with event time * fix(bin): normalize status event times in-shell and freeze the budget test clock Two paths made a status event's emission time cost more than it should. The captain-relevance fallback piped every line through awk to drop a well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a fork per line just to prepare a regex match. Shell parameter expansion does the same strip with no fork, and the retry-dedup scan now reuses that one helper instead of carrying a second copy of the rule in awk. The copies had already drifted: the shell side stripped tags from lines with no colon, which the awk rule left whole, so a colonless line could be mistaken for one already recorded. One definition, checked against the awk rule it replaces over the edge cases and a 4000-line fuzz. tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In hang mode the poll set DEADLINE to the real now plus a one-second budget, and when the second ticked before the first forge call the loop broke without ever calling gh: forge/calls was never written and the assertion failed reading a missing file. Freezing the clock in both modes removes the dependence on wall time; the bounded call is still cut by the real timeout, so the observation the test asserts still starts. Emission time stays optional on new status records, and legacy or malformed lines keep an unknown age. * no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion * no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs * test: fold emission-time snapshot coverage into the fixture case Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer touches workflows. Keep every emission-time assertion by folding it into test_fixture_snapshot_json. * no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch * no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape * no-mistakes(review): strip undelimited at-tags; correct brief stamp header * no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness * no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles * no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb * no-mistakes(review): read note and key past colon-bearing stamps * test(status): keep inactive reconcile assertions stamp-tolerant These two oracles were made stamp-tolerant while resolving one of the branch's merges from main. The rebase drops merge commits, so that adaptation was lost and both assertions went back to matching an exact substring that a stamped line no longer contains: the tag lands before the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...". Strip a well-formed tag before matching, as the branch's other oracles do. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap * no-mistakes(document): correct stale unstamped status-line spellings in docs * no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments * no-mistakes(ci): rename subshell-local epoch in delivery-race stub The serialization test overrides fm_pending_reply_mark_delivered inside a (..) subshell. Its `epoch` local collided with the same name in status_line_at_epoch/status_stamp_line, which this branch added and this suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and failed Lint 2. The stub already prefixes its other locals with `pending_` for the same reason; `epoch` was the leftover. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bin): unify Lavish host and disconnect handling (#5060) * fix: ship clean Lavish host fixes * no-mistakes(review): Fix Lavish classifications and fail-closed host loading * no-mistakes(review): Restore Lavish host state across retries and launches * no-mistakes(review): Preserve destination Lavish host when configuration is absent * no-mistakes(document): Document Lavish status and host guarantees * feat: act on captain's away words during AFK supervision (#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation * fix(bin): render the remote charter's steering-inbox path host-local (#5049) * fix(bin): render the remote charter's steering-inbox path host-local A freshly provisioned remote secondmate read a parent-home absolute steering-inbox path in its charter - a location that exists on no route - and spent its first turn discovering the gap and filing a blocked decision for what was a render defect. The seed's remote-copy rewrite now maps the inbox to the route's host-local parent-route inbox, exactly as it already maps the reply-log path, so every mention - bare path, listing, and handled/ acknowledgement - lands host-local. Both rewrites also become plain assignments, because a quoted substitution nested inside a double-quoted printf argument leaks literal quotes into the replacement text on stock macOS bash. The lifecycle suite pins the corrected render both directions against the real seed, provisioning, and delivery route, sharing one fixture value between the render truth and the delivery truth. Closes #5012 * no-mistakes(document): document remote charter's host-local steering inbox * feat: route Lavish feedback directly to owning workers (#5099) * feat(procevent): route worker-owned Lavish rounds * no-mistakes(review): drop duplicate artifact field from task-owned registration * no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic * no-mistakes(review): keep worker board owned until terminal round acknowledged * no-mistakes(review): refuse every retirement of an open worker-owned round * no-mistakes(review): use real lavish reply flag, isolate reply generations * no-mistakes(review): drop .posted marker for best-effort reply posting * no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures * no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms * no-mistakes(review): re-arm only to acknowledge an open round * no-mistakes(review): conclude only a still-open terminal round * no-mistakes(review): record the acknowledgement before retiring the board * no-mistakes(review): retain the registration across a conclude, qualify terminal docs * no-mistakes(document): Document worker-owned Lavish round lifecycle * fix(bin): fit pull observation within the contribution poll budget (#5107) * fix(bin): reserve contribution observation budget * no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget * feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103) * feat(bin): add idempotent inbox orders, receipts, replies, and readiness Let a caller supply a request id when publishing a captain inbox note so a retry returns the original note instead of creating a second one, including across the crash window between save and wake announcement. Separate saved from announced so a failed wake is repairable without enqueueing again. Add bounded receipts JSON with omission disclosure, a durable primary reply against a note id, and a read-only readiness projection that can say unknown instead of inferring liveness from a lock file. * no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict * fix(bin): resolve ready from lock-holder ancestry; drop lock status --json Remove the extra JSON surface from fm-lock.sh so its human status still always exits zero. Have the readiness projection classify the inspected home from the lock-holder pid via fm-harness.sh ancestry, with an explicit FM_SUPERVISION_MODEL still winning and an unknown model when there is no holder. Prove the yes path when that ancestry names a known harness. * no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor * no-mistakes(document): Note read-only lock inspection in scripts inventory * no-mistakes(lint): Pass missing id argument to malformed-reply test printf --------- Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com> * fix(bin): stop harness footer rows below a composer from reading as pending text (#5118) * fix(composer): stop a harness footer row from reading as a composer holding text A harness draws its own furniture below the composer - a user statusLine, a permission-mode hint - and the cursorless "bottom-most shape wins" rule looks exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text everywhere else, so a statusLine opening with `→` was selected as a bare composer, swallowed the hint row beneath it as wrapped input, and answered `pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first doorbell and every retry were skipped and the worker never saw the steer. Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on Herdr 0.8.0 had genuinely empty composers and every one of them was refused. A separator pair that closed over a bare agent-glyph row is a proven composer container, so the contiguous non-blank rows below its closing rule are that composer's footer and are no longer composer candidates. The demotion is bounded by all three of its own preconditions: a blank row ends the zone, a pair that closed over no glyph row demotes nothing, and a shape with no separator pair at all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same composer, including a stray SGR mouse report left by a click in the pane, still reads `pending`. Pinned by two portable regressions and by a new cursorless arm on the live composer-matrix guard, which re-reads each harness's already-proven-idle pane the way every non-tmux backend reads it and fails naming the harness and version when that read is `pending`. * no-mistakes(review): make composer footer-zone demotion shape-independent * no-mistakes(review): make footer-zone demotion refuse-only and drop rescan * no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100 --------- Co-authored-by: Koen Muller <koen@catapult.nl> * feat(bin): append optional home-local include to briefs (#5115) Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com> * fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114) * fix(bin): stop misreading a no-run branch as an unreadable runs table Defect: when `no-mistakes axi status`'s overview is truncated (a task's own branch has zero rows among the shown ones), fm_nm_select_run's Python fallback derived the repo identity for its direct SQLite query from a `repo: <path>` line it expected in the overview text. The real CLI never emits that line, truncated or not (see the genuine capture at tests/captures/no-mistakes-v1.70.1/overview.toon, which has only `count:`/`runs[...]:`), so the lookup always failed and reported "unreadable runs table" for a task that simply has no run on its branch. On a fleet with many concurrent runs, every idle-branch task hits the truncated-overview path routinely, so this fired every few minutes and drowned genuine unreadable/blocked verdicts in noise. Fix: derive the repo identity from the task worktree path instead, which is exactly the value `no-mistakes` records as a repo's `working_path` (confirmed against the existing capped-overview test fixtures, which already register repos by worktree path). A worktree path that is not absolute cannot be matched and still reads as unreadable rather than being guessed at. Also raise the reader's SQLite busy timeout from 1s to 30s so ordinary lock contention on a busy fleet cannot masquerade as an unreadable database. Safety: every other verdict byte-for-byte unchanged - the repo lookup still requires exactly one matching row (a genuinely corrupt or mismatched repos table still reports unreadable, per the existing `repo` failure-mode test), the branch query and row validation are untouched, and a zero-row result for the branch still flows through the same recursive re-parse that already turns an empty `runs[0]{...}` table into `absent`. Added a regression test (test_capped_overview_without_repo_line_and_no_runs_reports_absent) that reproduces the real overview shape - capped, zero rows for the task's branch, no `repo: ` line - and asserts the crew state falls through to the pane/busy verdict instead of reporting unknown or "unreadable". Full fm-crew-state.test.sh suite passes unchanged otherwise. * fix: recovered same-branch inventory awk misreads empty result as unreadable fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:` overview and re-runs it through the same awk selection pass. When that rebuilt inventory has zero rows for the branch, the row-matching loop never executes, so its counters (`seen`) stay at awk's uninitialized empty string while `expected` and `shown` are plain strings parsed from the header text. Comparing an uninitialized value against a non-numeric string uses string comparison, so "" != "0" is true, and the END block takes the "unreadable runs table" branch instead of falling through to the correct "absent" verdict for a branch with genuinely zero runs. Coerce the affected END comparisons with `+0` so they are always numeric, matching seen/expected/shown/total regardless of whether awk classified them as strings or numeric strings. A truncated or genuinely malformed inventory still differs numerically and still reports unreadable. * no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup * no-mistakes(review): match recorded repo path first, tolerate duplicate spellings * no-mistakes(review): revert repo lookup to exact working_path match * no-mistakes(document): note state-db inventory read under crew-state nm timeout --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.c…
keenvc
added a commit
to keenvc/firstmate
that referenced
this pull request
Sep 30, 2026
…ession start (#12) * feat(bin): defer the wedge escalation for a lane parked at a supervisor-owed gate (#4974) * fix(watch): recheck a gate awaiting a human instead of wedge-escalating it A lane whose validation run is parked at a gate waiting on a human decision is correctly quiet, but nothing in its status line says so: the evidence is the pipeline's own gate state rather than anything the worker wrote. The wedge timer read that silence as a suspected wedge and climbed the escalation ladder for as long as the wait lasted, and each escalation cost a supervising turn. The landed declared-wait consult does not reach it, because a live ordinary crewmate never reports a declared pause, and raising FM_STALE_ESCALATE_SECS would delay genuine wedge detection for every lane by the same amount. The threshold now reads a second, independent record when the status line accounts for nothing: whether the crew's current state is a gate whose answer is owed by a human. That is minted only from the gate's own findings table, by a row whose `action` column is exactly `ask-user`, located by position out of the table header the way nm_gate_step_row already reads its row - never searched for over the run payload, where a finding's free-text description or a branch name satisfies a search just as well. A gate awaiting the CREWMATE's own answer keeps the unchanged escalation schedule, reason and demand-deep-inspection wording, because a crewmate that goes quiet before answering its own gate is exactly the wedge the ladder exists to catch. Each kind of wait now carries the human it is on, the action that clears it, and whether that human is the captain as data alongside the verdict, rather than as wording chosen per branch where the recheck is written, so the deferral cannot word one kind of wait as another and a new kind cannot ship without deciding all of them. A parked gate has no written record of when its wait began, so its recheck publishes no wait age at all rather than one read from the quiet window this deferral resets on every pass, which would report the same small number for a gate of any age. Like every other captain-facing recheck here it is absorbed in silence while the away-posture record exists, arming no throttle, so the recheck is owed in full the moment the record is archived. The consult runs only in the at-threshold branch that was about to escalate, beside the worktree walk already there, and only for lanes whose status line explained nothing. Closes #3055 * no-mistakes(review): require an unanswered decision before deferring a parked gate * no-mistakes(review): reset the away-silenced timer, fail-safe findings parse, US-joined wait records * test(watch): pass the pane hash wedge_timer_check now takes Upstream gave wedge_timer_check a sixth <pane-hash> argument for its dead-record probe. The malformed-wait-record rounds drive the real function directly, so they pass one, and stub fm_backend_agent_state to a live agent so the probe that runs after a refused deferral keeps the unchanged ladder rather than reading a backend the child shell has none of. * no-mistakes(review): Bind parked-gate wait to its run, owe it firstmate * no-mistakes(document): correct wait-kind count, crew-state reader scope, gate-key coupling * feat(watch): make the parked-gate wait deferral opt-in The wedge timer deferring a lane parked at a validation gate is new supervision behaviour rather than a restored one, and it decides which lanes give up the escalation ladder, so it now ships as a default-off per-home option instead of changing every home on upgrade. config/wedge-defer-parked-gate arms it. The flag is read before the decision fold, so an unconfigured home spends no fold or current-state read, writes no record, and keeps the unchanged escalation schedule, reasons and demand-deep-inspection wording; a test counts the reader calls in both directions to pin that. It is not inherited by secondmate homes: each home supervises its own crew and owns that trade separately, the same reason config/turnend-churn-absorb is home-local. The away-posture absorb returns to leaving the idle timer alone, which it had restarted only because the costly consult could reach it. A parked-gate wait is owed to the supervisor rather than the captain, so it never enters that branch, and the recheck owed on return is again owed in full the moment the record is archived. * test(watch): pin that the away-silenced hold leaves the idle timer alone The absorb no longer restarts the timer, so the recheck owed on return is owed in full rather than a cadence into the return. Nothing asserted that, so a restart could be reintroduced silently. * no-mistakes(review): document away-silence rationale, pin captured gate component * no-mistakes(test): anchor gate row scan to the braced findings header * no-mistakes(document): pin same-block gate row invariant in crew-state comment * fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007) * fix(control): let the owning seat reclaim a task whose endpoint is gone A destroyed pane or workspace made `missing` a terminal state. Relaunch accepted only `dead` and said to stop the agent first; exit refused `missing` and said to reconcile the task first; there is no reconcile verb. Each command named the other as its prerequisite, so a task whose terminal went away could not be reclaimed by anything, and a no-mistakes approval it was parked on had no seat left to answer it. `missing` is agent-free a fortiori: there is no endpoint, so there is no agent in it. Widen the existing guards rather than add a verb. - fm-spawn --relaunch accepts a positively proven `missing` and creates one fresh endpoint in the recorded worktree; the record it already republishes rebinds the task to it. A `dead` endpoint is still adopted in place. - fm-control exit reports `endpoint-gone` instead of dying, so the relaunch transaction's stop step no longer dead-ends, and re-resolves the endpoint from the record before verifying the replacement. The duplicate-agent refusal is untouched: both verdicts come from the same recovery-grade classifier, which claims `missing` only from positive absence, so `alive`, `ambiguous`, and `unreadable` all still refuse. The backends' own create paths refuse a live same-labeled endpoint as a second independent guard. The worktree, its branch, commits, uncommitted changes, armed poll and registration, record rows, and status log are all untouched - a reclaim is a recovery, never a teardown. A secondmate is excluded: its gone-endpoint recovery already has one owner in the session-start liveness sweep, so relaunch refuses and names it rather than becoming a second path to the same outcome. Tests reproduce both halves of the deadlock, the reclaim succeeding, unlanded work surviving it, and the refusals that still hold. * no-mistakes(review): prove endpoint absence per backend before reclaim rebinds * no-mistakes(review): give exit and relaunch one absence proof; pin herdr rebind session * no-mistakes(review): narrow endpoint reclaim to herdr; tmux refuses honestly * no-mistakes(review): stop refusals and docs asserting unestablished causes * no-mistakes(review): stop herdr fixture helper losing tmp-root registration * no-mistakes(review): document workspace drift and absence-probe server residue * no-mistakes(review): correct rebind limitation to its one reachable case * no-mistakes(review): stop claiming reclaim leaves instructions untouched * no-mistakes(document): scope fm-control-lib purity claim, note reclaim coverage * no-mistakes(rebase): read the staged launch file in the herdr fixture Rebasing onto main picked up #4994, which stages a long worker launch command into a script and delivers the short `. '<path>'` line instead of the literal command. The tmux fake and tests/fixtures.sh were updated for that; the herdr fake this branch adds was written before it and still keyed "an agent now exists on this pane" off the literal `encode launch-brief` text, so after the rebase it never marked the rebound pane live and the reclaim's alive-wait read `dead`. Dereference the staged file first, exactly as the tmux fake above does. Test-fixture only; no production path changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(document): note reclaim placement in herdr and scripts inventories --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(bin): stamp status events with their emission time (#3764) * test(status): reproduce missing event emission time * wip(status): preserve optional event emission time * test(status): document indirect clock stub invocation * no-mistakes(review): Preserve historical status bytes during reply recovery * no-mistakes(test): Fix timestamped status assertions and remote fixture dependencies * no-mistakes(review): Preserve captain regex overrides for timestamped status events * no-mistakes(document): Clarify status event timing and publication contracts * no-mistakes(lint): Quote literal done to satisfy ShellCheck * no-mistakes(ci): Captain, updated .github/workflows/ci.yml to expect 19 snapshot tests instead of 18, matching the PR’s added regression. Reproduced the failure before the fix. Stock Bash 3.2.57 verification passed: parse sweep, 19 snapshot tests, 53 Bearings tests, and the public-followup regression. Workflow lint and diff checks passed * no-mistakes(test): Preserve terminal notifications with malformed timestamp tags * no-mistakes(test): Stamp Rovo spawn failures with emission time * no-mistakes(document): Verify status event documentation * no-mistakes(lint): Fix ShellCheck quoting in status emission-time tests * no-mistakes(ci): Captain, fixed four lifecycle assertions to accept emission timestamps while preserving publication and retry checks. Reproduced the CI failure before the fix. The lifecycle suite now passes with six Beads capability skips; syntax, targeted ShellCheck, and diff checks passed * no-mistakes(ci): Captain, fixed malformed timestamp colons hiding actionable events using shared normalization. Original bytes and unknown ages are preserved. Regression reproduced before the fix; classifier and remote-reply suites, targeted lint, syntax, and diff checks passed * no-mistakes(review): Stamp remote escalations at call sites, drop new flag * no-mistakes(review): Accept stamped escalation and close lines in test assertions * no-mistakes(review): Restore reserved-key answered-note guard for stamped closes * test(status): accept optional emission time in PR-provenance assertions The #4148 provenance test landed on main with exact unstamped greps. Parent-channel lines from this branch carry [at=<epoch>], so strip only that tag before the same exact match. No production change. * no-mistakes(review): Accept stamped ready signal in PR fallback scrape * no-mistakes(review): Drop relay flag, stamp parent events at call sites * no-mistakes(review): Stamp worker terminal-signal instructions, revert fm-on fixture * no-mistakes(review): Accept optional stamp in live cmux drift guard * no-mistakes(review): Restore original test invocation order in two suites * no-mistakes(review): Strip only well-formed numeric status time tags * no-mistakes(document): Drop stale unstamped PR-ready line spelling from channel doc * no-mistakes(review): Stamp agy spawn-failure status lines with event time * fix(bin): normalize status event times in-shell and freeze the budget test clock Two paths made a status event's emission time cost more than it should. The captain-relevance fallback piped every line through awk to drop a well-formed `[at=<epoch>]` tag before matching, so a supervisor sweep paid a fork per line just to prepare a regex match. Shell parameter expansion does the same strip with no fork, and the retry-dedup scan now reuses that one helper instead of carrying a second copy of the rule in awk. The copies had already drifted: the shell side stripped tags from lines with no colon, which the awk rule left whole, so a colonless line could be mistaken for one already recorded. One definition, checked against the awk rule it replaces over the edge cases and a 4000-line fuzz. tests/fm-contributions.test.sh froze its fixture clock only in exhaust mode. In hang mode the poll set DEADLINE to the real now plus a one-second budget, and when the second ticked before the first forge call the loop broke without ever calling gh: forge/calls was never written and the assertion failed reading a missing file. Freezing the clock in both modes removes the dependence on wall time; the bounded call is still cut by the real timeout, so the observation the test asserts still starts. Emission time stays optional on new status records, and legacy or malformed lines keep an unknown age. * no-mistakes(review): Stamp ask-user escalation line and fix Kimi status assertion * no-mistakes(document): Drop stale unstamped done-line spelling from watcher docs * test: fold emission-time snapshot coverage into the fixture case Drop the incidental ci.yml 18-to-19 count hunk so the PR no longer touches workflows. Keep every emission-time assertion by folding it into test_fixture_snapshot_json. * no-mistakes(review): replace brief date substitution with epoch placeholder; drop emitted_at_epoch * no-mistakes(review): align untimed normalizer with epoch parser; tolerate placeholder stamp in PR scrape * no-mistakes(review): strip undelimited at-tags; correct brief stamp header * no-mistakes(review): normalize stamps at both captain-regex sites; restore mtime freshness * no-mistakes(review): strip colon-bearing stamps for relevance; fix headers and test oracles * no-mistakes(review): narrow escalation match to stamp tolerance; pin note verb * no-mistakes(review): read note and key past colon-bearing stamps * test(status): keep inactive reconcile assertions stamp-tolerant These two oracles were made stamp-tolerant while resolving one of the branch's merges from main. The rebase drops merge commits, so that adaptation was lost and both assertions went back to matching an exact substring that a stamped line no longer contains: the tag lands before the colon, so "failed [key=k]: ..." is now "failed [key=k] [at=N]: ...". Strip a well-formed tag before matching, as the branch's other oracles do. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * no-mistakes(review): unstamp fold colon tests; reserve stamp width in cap * no-mistakes(document): correct stale unstamped status-line spellings in docs * no-mistakes(document): quote brief-test literals for lint; correct stamp-helper contract comments * no-mistakes(ci): rename subshell-local epoch in delivery-race stub The serialization test overrides fm_pending_reply_mark_delivered inside a (..) subshell. Its `epoch` local collided with the same name in status_line_at_epoch/status_stamp_line, which this branch added and this suite now calls at top level, so ShellCheck 0.11.0 reported SC2030 and failed Lint 2. The stub already prefixes its other locals with `pending_` for the same reason; `epoch` was the leftover. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bin): unify Lavish host and disconnect handling (#5060) * fix: ship clean Lavish host fixes * no-mistakes(review): Fix Lavish classifications and fail-closed host loading * no-mistakes(review): Restore Lavish host state across retries and launches * no-mistakes(review): Preserve destination Lavish host when configuration is absent * no-mistakes(document): Document Lavish status and host guarantees * feat: act on captain's away words during AFK supervision (#5076) * feat(afk): make the captain's away words the whole mandate Retire the clause fields, verb list, never-set scan, refused records, and the per-task merge-grant list from the away-posture record. The record is now version 2: the captain's words verbatim plus expected return, spend cap, and reach line; a version 1 record still validates, reads, and archives so a live away window is never broken by the upgrade. The supervision branch reads the words at the tail of every wake and acts on them by its own judgment through the guarded scripts under standing authority, never by analogy, holding for the return on doubt, and opens each such outcome summary with "per your away instructions:" so the return brief can render the words beside the session's account. While the record exists any green merge runs under away authority (ledger tag "away"); red merges, --allow-red, asynchronous and queued merges, and local-only landing stay refused. The branch may file a backlog item the words explicitly call for before dispatching it under the spend cap. Tests drive fm-afk-contract.sh, fm-afk-launch.sh, fm-afk-return.sh, and fm-pr-merge.sh as commands: version 2 written, version 1 read, retired flags and subcommands refused by name, green merges landing under the record, red and waived-red refused, the record lock still closing the authority-read window, and the Pi away tail carrying the words. * no-mistakes(review): carry the away read-back to the session verbatim * no-mistakes(review): match the exact away-action marker in the return brief * no-mistakes(review): refuse a words block truncated by a damaged line * no-mistakes(document): Refresh away-role contract documentation * fix(bin): render the remote charter's steering-inbox path host-local (#5049) * fix(bin): render the remote charter's steering-inbox path host-local A freshly provisioned remote secondmate read a parent-home absolute steering-inbox path in its charter - a location that exists on no route - and spent its first turn discovering the gap and filing a blocked decision for what was a render defect. The seed's remote-copy rewrite now maps the inbox to the route's host-local parent-route inbox, exactly as it already maps the reply-log path, so every mention - bare path, listing, and handled/ acknowledgement - lands host-local. Both rewrites also become plain assignments, because a quoted substitution nested inside a double-quoted printf argument leaks literal quotes into the replacement text on stock macOS bash. The lifecycle suite pins the corrected render both directions against the real seed, provisioning, and delivery route, sharing one fixture value between the render truth and the delivery truth. Closes #5012 * no-mistakes(document): document remote charter's host-local steering inbox * feat: route Lavish feedback directly to owning workers (#5099) * feat(procevent): route worker-owned Lavish rounds * no-mistakes(review): drop duplicate artifact field from task-owned registration * no-mistakes(review): post worker reply once, fix ring label, keep re-arm atomic * no-mistakes(review): keep worker board owned until terminal round acknowledged * no-mistakes(review): refuse every retirement of an open worker-owned round * no-mistakes(review): use real lavish reply flag, isolate reply generations * no-mistakes(review): drop .posted marker for best-effort reply posting * no-mistakes(review): consume staged reply after listener setup, refuse orphaned captures * no-mistakes(review): require a reachable owner, redeliver open rounds, roll back failed re-arms * no-mistakes(review): re-arm only to acknowledge an open round * no-mistakes(review): conclude only a still-open terminal round * no-mistakes(review): record the acknowledgement before retiring the board * no-mistakes(review): retain the registration across a conclude, qualify terminal docs * no-mistakes(document): Document worker-owned Lavish round lifecycle * fix(bin): fit pull observation within the contribution poll budget (#5107) * fix(bin): reserve contribution observation budget * no-mistakes(review): Strengthen slow-read regression test to exceed the poll budget * feat(bin): add idempotent inbox capture, replies, receipts, and readiness JSON (#5103) * feat(bin): add idempotent inbox orders, receipts, replies, and readiness Let a caller supply a request id when publishing a captain inbox note so a retry returns the original note instead of creating a second one, including across the crash window between save and wake announcement. Separate saved from announced so a failed wake is repairable without enqueueing again. Add bounded receipts JSON with omission disclosure, a durable primary reply against a note id, and a read-only readiness projection that can say unknown instead of inferring liveness from a lock file. * no-mistakes(review): fix(bin): honest inbox announce, reply cursor, and readiness verdict * fix(bin): resolve ready from lock-holder ancestry; drop lock status --json Remove the extra JSON surface from fm-lock.sh so its human status still always exits zero. Have the readiness projection classify the inspected home from the lock-holder pid via fm-harness.sh ancestry, with an explicit FM_SUPERVISION_MODEL still winning and an unknown model when there is no holder. Prove the yes path when that ancestry names a known harness. * no-mistakes(review): Harden inbox announce, receipts reads, and reply sequence cursor * no-mistakes(document): Note read-only lock inspection in scripts inventory * no-mistakes(lint): Pass missing id argument to malformed-reply test printf --------- Co-authored-by: cliflacata-svg <304148223+cliflacata-svg@users.noreply.github.com> * fix(bin): stop harness footer rows below a composer from reading as pending text (#5118) * fix(composer): stop a harness footer row from reading as a composer holding text A harness draws its own furniture below the composer - a user statusLine, a permission-mode hint - and the cursorless "bottom-most shape wins" rule looks exactly there. `→` (U+2192) is Cursor's prompt glyph but ordinary text everywhere else, so a statusLine opening with `→` was selected as a bare composer, swallowed the hint row beneath it as wrapped input, and answered `pending` on a visibly empty pane. `fm_task_inbox_ring` defers on exactly that verdict, and `bin/fm-watch.sh`'s re-ring calls the same function, so the first doorbell and every retry were skipped and the worker never saw the steer. Measured live on 2026-09-20: three of five Claude Code 2.1.236 worker panes on Herdr 0.8.0 had genuinely empty composers and every one of them was refused. A separator pair that closed over a bare agent-glyph row is a proven composer container, so the contiguous non-blank rows below its closing rule are that composer's footer and are no longer composer candidates. The demotion is bounded by all three of its own preconditions: a blank row ends the zone, a pair that closed over no glyph row demotes nothing, and a shape with no separator pair at all (Cursor's half-block rules) is untouched. Real unsubmitted text in that same composer, including a stray SGR mouse report left by a click in the pane, still reads `pending`. Pinned by two portable regressions and by a new cursorless arm on the live composer-matrix guard, which re-reads each harness's already-proven-idle pane the way every non-tmux backend reads it and fails naming the harness and version when that read is `pending`. * no-mistakes(review): make composer footer-zone demotion shape-independent * no-mistakes(review): make footer-zone demotion refuse-only and drop rescan * no-mistakes(lint): quote probe-absent sentinel to clear ShellCheck SC2100 --------- Co-authored-by: Koen Muller <koen@catapult.nl> * feat(bin): append optional home-local include to briefs (#5115) Co-authored-by: guanchengh-lgtm <271917158+guanchengh-lgtm@users.noreply.github.com> * fix(bin): report a branch with no validation run as absent instead of an unreadable runs table (#5114) * fix(bin): stop misreading a no-run branch as an unreadable runs table Defect: when `no-mistakes axi status`'s overview is truncated (a task's own branch has zero rows among the shown ones), fm_nm_select_run's Python fallback derived the repo identity for its direct SQLite query from a `repo: <path>` line it expected in the overview text. The real CLI never emits that line, truncated or not (see the genuine capture at tests/captures/no-mistakes-v1.70.1/overview.toon, which has only `count:`/`runs[...]:`), so the lookup always failed and reported "unreadable runs table" for a task that simply has no run on its branch. On a fleet with many concurrent runs, every idle-branch task hits the truncated-overview path routinely, so this fired every few minutes and drowned genuine unreadable/blocked verdicts in noise. Fix: derive the repo identity from the task worktree path instead, which is exactly the value `no-mistakes` records as a repo's `working_path` (confirmed against the existing capped-overview test fixtures, which already register repos by worktree path). A worktree path that is not absolute cannot be matched and still reads as unreadable rather than being guessed at. Also raise the reader's SQLite busy timeout from 1s to 30s so ordinary lock contention on a busy fleet cannot masquerade as an unreadable database. Safety: every other verdict byte-for-byte unchanged - the repo lookup still requires exactly one matching row (a genuinely corrupt or mismatched repos table still reports unreadable, per the existing `repo` failure-mode test), the branch query and row validation are untouched, and a zero-row result for the branch still flows through the same recursive re-parse that already turns an empty `runs[0]{...}` table into `absent`. Added a regression test (test_capped_overview_without_repo_line_and_no_runs_reports_absent) that reproduces the real overview shape - capped, zero rows for the task's branch, no `repo: ` line - and asserts the crew state falls through to the pane/busy verdict instead of reporting unknown or "unreadable". Full fm-crew-state.test.sh suite passes unchanged otherwise. * fix: recovered same-branch inventory awk misreads empty result as unreadable fm_nm_select_run's deep SQLite reader rebuilds a `count:`/`runs[...]:` overview and re-runs it through the same awk selection pass. When that rebuilt inventory has zero rows for the branch, the row-matching loop never executes, so its counters (`seen`) stay at awk's uninitialized empty string while `expected` and `shown` are plain strings parsed from the header text. Comparing an uninitialized value against a non-numeric string uses string comparison, so "" != "0" is true, and the END block takes the "unreadable runs table" branch instead of falling through to the correct "absent" verdict for a branch with genuinely zero runs. Coerce the affected END comparisons with `+0` so they are always numeric, matching seen/expected/shown/total regardless of whether awk classified them as strings or numeric strings. A truncated or genuinely malformed inventory still differs numerically and still reports unreadable. * no-mistakes(review): bound capped-overview inventory reader and canonicalize worktree lookup * no-mistakes(review): match recorded repo path first, tolerate duplicate spellings * no-mistakes(review): revert repo lookup to exact working_path match * no-mistakes(document): note state-db inventory read under crew-state nm timeout * fix(bin): require a non-draft pull request before a PR-based done report (#5141) * fix(bin): require a non-draft pull request before a PR-based done report A PR-based ship could report done, and merge monitoring could be armed, while the pull request was still a draft. A draft cannot be merged, so the poll waited for an event that could not occur and nobody was asked to merge. The PR-based definitions of done now require reading the pull request back from the forge and confirming it is not a draft, and a lane that deliberately holds a draft declares a wait instead of done. bin/fm-pr-check.sh refuses to arm merge monitoring on a draft, naming the draft state, and treats an unreadable draft state as before. The draft reading now lives in bin/fm-pr-lib.sh and bin/fm-pr-merge.sh uses it, with its refusal to merge a draft unchanged. Closes #4757 * fix(review): Skip arm-time draft refusal when fm-pr-merge records metadata * fix: support quota-axi schema 6 snapshots (#4904) * fix(bin): accept quota-axi schema 6 snapshots keyed by provider + accountKey quota-axi 0.1.47 emits schemaVersion 6 once a provider expands to more than one account: every provider row carries an accountKey and one provider id may appear on several rows. fm_quota_json_valid accepted only schema 5 with unique provider ids, so fm-dispatch-resolve.sh, fm-quota-choose.sh, and fm-procevent-quota.sh all rejected the live snapshot and quota-informed dispatch was dead against the current tool. - bin/fm-quota-axi-lib.sh: the validator accepts schema 6 with accountKey required on every row and uniqueness on provider + accountKey; schema 5 keeps its exact rules. FM_QUOTA_ROW_JQ is the one join every consumer uses: schema 5 binds by provider alone, schema 6 binds to the row keyed by the candidate's Pi lane, else the provider's default row, else no row (unmeasured, never blocked, never by position or summed across accounts). - bin/fm-quota-choose.sh: accepts schema 6 JSON and the TOON accountKey column, and joins through the shared function. - bin/fm-dispatch-resolve.sh and bin/fm-procevent-quota.sh: join through the shared function; an expanded provider with no row for the candidate's account is reported as such. - tests: schema 6 fixtures shaped like the real snapshot, each paired with a schema 5 case on the same path; every new case fails on the previous scripts and passes now. - docs: the two sentences naming the row join describe the schema 6 key. * no-mistakes(review): Fix native Codex quota and expanded provider watches * no-mistakes(review): Align native Codex account matching across dispatch paths * no-mistakes(document): Align quota documentation with account-aware snapshots * no-mistakes(document): Align quota dispatch documentation with account matching * fix(bin): keep CI lint and the quota watch test portable - bin/fm-quota-axi-lib.sh: FM_QUOTA_ROW_JQ is read only by the scripts that source this library, so full-mode ShellCheck reported SC2034 on the assignment; mark it alongside the existing SC2016 disable. - tests/fm-procevent-quota.test.sh: the schema 6 provider-watch assertions used rg, which CI runners do not install, so the case failed with 'rg: command not found' rather than on behavior; use grep like the rest of the file. * no-mistakes(document): Documented schema-version account-row compatibility * test: fix Claude session-start drain live E2E (#5165) * test: repair Claude live auto-arm regression * no-mistakes(review): Assert SessionStart digest completeness within its hook_response event * no-mistakes(document): Consolidate Claude live verification references * ci: pin the no-mistakes required check to v1.80.1 (#5195) Roll the shared require-no-mistakes action to the tagged v1.80.1 SHA and grant pull-requests: read so the check can read PR bodies. * fix(bin): retain Pi watcher predecessor to stop false down alarms (#5174) * fix: preserve Pi watcher ownership across session replacement * no-mistakes(document): Scope Pi predecessor retention away from omp * no-mistakes(ci): Diagnosed all three failing checks; only one was code-caused. (ci-3, genuine) Stock macOS Bash snapshot compatibility: `tests/fm-pi-watch-extension.test.sh` failed the macOS Bash 3.2 `bash -n` parse sweep with `line 4265: unexpected EOF while looking for matching '`. I built GNU Bash 3.2.0 from source locally and reproduced it. Root cause: the PR added a comment containing an apostrophe (`// Replacement shutdown deliberately retains module 2's established arm until`) inside a quoted here-document (`<<'EOF'`) nested inside a `$(...)` command substitution. Bash 3.2 has a parser bug (fixed in later bash) where an unmatched single quote inside such a here-doc body is treated as opening a shell quote and never closed, aborting the whole file parse. The base commit parses cleanly under Bash 3.2, confirming this PR introduced the break. Minimal fix: reworded the comment to remove the apostrophe (`... retains the established module-2 arm until`), preserving meaning. Verified `bin/fm-lint.sh --list-files` (the 6 changed shell files) now all pass `/tmp/bash-3.2/bash -n`; Bash 5 also parses. (ci-1, infrastructure) Behavior portable serial 8: GitHub API shows the `Run portable serial shard 8` step conclusion=success; only `Upload portable serial shard 8 timing artifact` failed with `Failed to FinalizeArtifact ... (403) Forbidden`. This is a transient artifact-service/cancellation failure, not a test or code failure. No change. (ci-2, infrastructure) Lint 1: fetched the job log via the GitHub API; it ends with `##[error]The runner has received a shutdown signal...` then exit 143. The step was cancelled mid-run, not a ShellCheck finding. Independently ran `bin/fm-lint.sh --partition 1of2 --telemetry ...` locally with pinned ShellCheck 0.11.0 and actionlint 1.7.12: exited rc=0 (no findings). No change. The only code change is the apostrophe removal in tests/fm-pi-watch-extension.test.sh; no other files modified * fix(bin): allow cleanup of windowless legacy task records (#5236) * fix(bin): retire windowless leftovers and stop claiming a Pi daemon teardown Catch-up correctly refuses while a leftover task record has no status file. Cleanup used to deadlock on those same records when they also had no spawn_gen and no window, so they lingered and wedged every later away-mode return. Teardown now treats a windowless leftover as a missing-endpoint legacy record, and stop reports that no daemon terminal was running when none was launched. Co-authored-by: Cursor <cursoragent@cursor.com> * no-mistakes(review): Narrow windowless teardown exception to tmux legacy leftovers * no-mistakes(review): Validate windowless leftover identity via shared endpoint validator * no-mistakes(review): Refuse windowless leftovers carrying other backends' endpoint identity * no-mistakes(document): Clarify windowless teardown retry documentation --------- Co-authored-by: Cursor <cursoragent@cursor.com> * ci: exempt kunchenguid from the no-mistakes required check (#5256) * fix(bin): surface launches parked on an interactive prompt as not-started (#5250) * fix: surface parked launch prompts as not started * no-mistakes(document): docs: record launch-prompt busy backstop classification * no-mistakes(document): docs: align tail40 and rendered-text comments with launch-prompt backstop * fix: record away posture immediately on /afk (#5260) * feat(afk): make /afk itself the go with a same-turn record write Collapse the propose-then-confirm away entry into one 'enter' step that writes state/.afk-contract immediately and prints the announcement and read-back after the record exists, never asking for a go. The retired propose, confirm, and --proposal inputs are refused by name, and a stale proposal left by an older version is removed rather than promoted. Refresh and replace semantics, verbatim words, the single writer, the never-set, and per-harness launch behavior are unchanged. * no-mistakes(document): Refresh away-entry documentation evidence * fix(bin): recognize passed-with-override as a passing outcome (#5294) * fix(bin): map passed-with-override to done instead of unknown no-mistakes' axi status emits outcome: passed-with-override for a run that finished with an explicitly approved Test or CI exception. Both bin/fm-crew-state.sh's outcome resolver and bin/fm-teardown.sh's pre-teardown terminal-run check only matched the literal passed and checks-passed tokens, so this outcome fell through to unknown/parked and a finished worker awaiting merge kept getting re-alerted as stale, while an abort race during teardown could also leave a finished run misreported as still parked. Map passed-with-override to the same done/terminal handling as a clean passed in both places. * fix(document): Replace stale outcome mapping with authoritative pointer * fix(ci): Fixed a pre-existing mock-clock race in tests/fm-contributions.test.sh by advancing time only during the serial issue read. Reproduced the exact CI failure before fixing it. Forced-race replay, all 38 contribution scenarios, scoped ShellCheck, Bash syntax, and diff checks pass. Only the test fixture changed; CI rerun remains with the outer executor * fix: clean up workers after their pull requests land (#5317) * fix: close landed workers from supervision in both postures and at return During the 2026-09-22 away window every exemption worker whose pull request had merged was left sitting for nine hours. The supervision branch received the stale wake, the merge-landed check, and the hourly inactive-outcome row for each of them, ran the recovery playbook, found nothing to recover, and reported "no further action". The branch prompt granted ordinary teardown of a confirmed-landed task without ever naming the moment or the command, and the playbook has no landed exit, so the stale path ended at "nothing to recover". The return brief then listed only blockers, decisions, and the latest five routine outcomes, so the landed workers stayed invisible after the captain came back. - bin/fm-branch-prompt.sh: name the merge-landed wake, and any later stale, inactive-outcome, or heartbeat row on a done task with a merged PR, as the moment to claim the lease and run bin/fm-teardown.sh with no flags; a refusal is reported, never forced or worked around. Add teardown to the handling tool list. - stuck-crewmate-recovery: a landed worker is not a recovery case; point at the ordinary teardown owner for each actor. - bin/fm-afk-return.sh: render a "Landed, cleanup due" section from durable records only (a live task record whose recorded PR carries the merge-notification marker), between could-not-fix and handled, without holding the gate; the afk skill's return step closes each listed task through ordinary teardown once the check clears. - tests: pin the prompt rule in fm-branch-supervision and the brief section in fm-afk-return through the real marker writer. * no-mistakes(document): Document landed-task cleanup ownership * fix: surface green no-mistakes PRs awaiting merge (#5327) * fix(bin): surface a green no-mistakes PR still in ci merge monitoring A green PR could sit unreported because neither the worker nor the supervisor could observe checks-green while the ci step kept monitoring for the merge. Supervisor read: fm_nm_select_run's capped-overview inventory reader looked the repository up by the task worktree path, but no-mistakes registers a repository once by its main clone path and resolves every linked worktree to it, so on every task copy of a busy repo the lookup matched no row and each read reported "complete same-branch run inventory unreadable". Key the lookup on the overview's own top-level `repo:` line, which every axi release emits as the resolved working_path. Even with a readable run, the ci-log classifier treated "base branch advanced ..., re-arming CI monitor timeout" as not-ready. The monitor logs a checks state only when it changes and a base advance does not clear readiness, so a green PR read as still validating for as long as main kept advancing. Stop treating that line as a marker, matching no-mistakes' own ci-log parser, and name the run's PR URL in the held-for-merge reading so the existing inactive-outcome path can act on it without a worker report. Worker contract: `axi status` never reports checks-passed while the ci step monitors for merge, so the definition of done no longer makes a status poll the wait for the next gate or outcome; the drive call's own return is the green signal, reattached with `no-mistakes axi run` after a bounded return. * no-mistakes(review): read the full ci log when checking checks-green * no-mistakes(review): correct stale ci log tail wording in docs * no-mistakes(document): Document checks-green supervisor fallback * fix: derive Lavish polling route from board session (#5334) * fix: derive Lavish polling server from its board session * no-mistakes(document): Document session-derived Lavish polling * no-mistakes(document): Correct Lavish routing verification claims * fix(bin): stop secondmate relaunch failing when watcher scratch files vanish (#4900) * fix(bin): ignore vanished state scratch files on secondmate relaunch Relaunch refused when find(1) exited non-zero while listing a secondmate home's state directory. A live watcher can delete scratch files between readdir and processing, which is not evidence that child *.meta records are unreadable. Prove the directory is listable from its mode and keep the existing readable-meta loop as the child-record guarantee. Fixes #4765. * no-mistakes(review): Skip chmod-000 unlistable-state relaunch test when running as root * fix(bin): stop each keyed answer from re-waking this home (#4907) * fix(bin): treat home-owned status closes as already read Self-announced bookkeeping appends now record their exact byte ranges. Later drains and signal scans skip those ranges, so two distinct --resolve-key answers after an OPEN DECISIONS fold do not each wake the supervisor. Worker-authored lines outside that ledger still signal. * no-mistakes(review): Keep owned closes in unread status; lock ledger writes * no-mistakes(review): Drop fold-lag wake suppression so folded worker decisions still wake * no-mistakes(review): Require real owned growth before ledger marks status seen * no-mistakes(document): Clarify home-appends ledger scope versus UNREAD STATUS * no-mistakes(review): Restore fold-lag path, drop owned-range filters, fix test * no-mistakes(review): Align ledger docs and scope ledger to wake path only * no-mistakes(review): Restore stranded historical-annotation test comment to its function * no-mistakes(review): Retire the home-appends lock alongside its ledger * no-mistakes(document): Note ledger's lock-helper dependency in classify library * no-mistakes(review): Append-and-coalesce home-appends ledger; fix stamped-line assertions * no-mistakes(review): Drop redundant empty-span branch; make owned test pin ledger * no-mistakes(document): Document covers' ascending-order dependency on home-appends ledger * no-mistakes(document): Note owned-append skip in watcher signal-scan comment * fix: deliver failed public follow-ups with updated AXI floors (#5350) * chore(bin): raise tasks-axi, quota-axi, and lavish-axi floors to latest Raise the minimum versions to tasks-axi 0.2.6, quota-axi 0.1.50, and lavish-axi 0.1.77, pin CI's tasks-axi install to 0.2.6, and move the floor-boundary test fixtures to the new versions. tasks-axi 0.2.6 makes a failed relation deliverable for a promised-final expecting pr-merged, so add the regression test: a bound work that ends failed reports its honest outcome text through fm-public-followup-emit.sh, consume marks the commitment ready, and deliver posts that text exactly once. Also make two hang-guard tests in fm-backlog-atomicity portable to hosts without coreutils timeout, and stop an installed herdr from leaking into the secondmate-liveness husk classifier test. * no-mistakes(review): drop out-of-scope bounded_run hang-guard helper from atomicity test * no-mistakes(review): pin quota-axi floor at 0.1.49 across fixtures * no-mistakes(document): Document failed public-followup delivery behavior * no-mistakes(ci): Updated quota-axi floor and all 0.1.49 fixtures to 0.1.51, corrected bootstrap boundaries to 0.1.51/0.1.52/0.1.50, and bumped the bearings lavish-axi stub to 0.1.77. Bearings, quota procevent, quota chooser, startup budget, and bootstrap floor coverage passed; the full bootstrap suite exceeded the 240-second local command limit after relevant checks passed. git diff --check passed * fix(bin): refuse ship done: when the named head exists only in the worker copy (#4878) * fix(bin): refuse ship done: when the named head lives only in the worker copy A ship done: is not current-state done until that exact commit is reachable outside the disposable copy. The check tests the named head, not whether some branch moved. * fix(bin): gate CI-ready ship done: on named-head reachability, not handoff Keep no-mistakes' first done: as the pipeline handoff, apply the same shared check when registering a PR and when a secondmate publishes ledger-first, treat a recorded merged PR as landed after prune, and name the PR head instead of scanning free-text SHAs. * no-mistakes(review): Bind named-head gate to recorded PR and forge heads * no-mistakes(review): Gate direct-PR forge heads and keep pending ledger deliveries * no-mistakes(review): Align worker done wording, test mapping, pending-retry test * no-mistakes(test): Raise watcher test time limit to stop load flake * no-mistakes(document): Restore ledger-path fact and name named-head gate coverage * ci: re-attest named-head ship-done gate for a fresh serial-3 verdict * no-mistakes(review): Simplify local-only gate, gate keyed done lines, document recovery * no-mistakes(document): Name fm-crew-state among named-head gate callers * fix(bin): ring a proven-idle secondmate before raising a wake-loop stall alarm (#5204) * fix(bin): ring a proven-idle secondmate before a wake-loop stall alarm A leftover foreign-queue row on an idle, alive, ring-safe mate is still drainable in that home. Ring once, reset the observation interval, and keep the parent alarm for unknown, busy, or still-frozen rows. * no-mistakes(review): Mark drain steer with from-firstmate fire-and-forget carrier * test(watch-arm): size re-arm waits off the real loaded recovery cost (#5335) The re-arm recovery cases judged "the watcher stayed live instead of surfacing recovery" with fixed budgets below what a real stale-lock recovery costs on a contended host: the arm's default 10s confirmation deadline, a start helper that returned after about 4s whether or not the arm had confirmed its watcher, and an 80-poll exit wait. A changed-suite run beside other suites starves the recovery's many short-lived processes while this suite's sleeping poll loops keep their pace, so a watcher still surfacing its recovery read as one that stayed live (issue #3793). The original 0.25s window after confirmation was widened to 80 polls in #3837, which left the same race at a larger size. Following the CONTRIBUTING.md fixture-budget rule, the re-arm helper now gives the arm an explicit 30s confirmation budget and waits for its confirmation or exit within a ceiling that outlasts it, and every wait on a re-armed watcher uses one named iteration-counted ceiling that outlasts the same budget. A passing case returns as soon as the arm reports or exits, and a watcher that never surfaces its recovery still fails. A new case delays every mktemp and readlink the re-armed watcher runs after it publishes its beacon, so its first poll and exit take about 13s on any host. It fails with the reported symptom on the previous budgets and passes now. No bin/ change. * fix: stop watchers reliably during blocked polls (#5362) * fix(bin): let one TERM always stop the watcher on bash 5.2 Bash 5.2 runs a pending trap from the parser entry of the next command substitution it expands, where the trap body is parsed as the inside of that substitution and fails ("trap: line 2: unexpected EOF while looking for matching `)'") or is dropped silently, consuming the signal. The watcher's `trap 'exit 1' HUP INT TERM` could therefore ignore a TERM and keep polling while its stopper waited: the triage suite's reap waited forever (CI jobs cancelled at 30 minutes), and the arm's signal path and the away-mode daemon's shutdown wait for the watcher the same way. Bash 5.3 fixed the parser; 5.2 is the stock bash on Ubuntu 24.04. HUP and TERM now keep bash's native fatal-signal handling, which runs the EXIT trap (watcher_cleanup) and exits on bash 3.2, 5.2, and 5.3. INT keeps its trap because bash ignores a direct SIGINT while a child runs. The check-spawn deferral window no longer contains a command substitution. The triage suite's reap is now bounded and fails the case within 10s with process evidence instead of hanging the job, and a new regression test proves TERM stops a watcher blocked inside a poll's pane capture and still releases its lock and records an acknowledgeable stop. * no-mistakes(document): Clarify watcher stop-signal documentation * fix: submit stuck inbox doorbells instead of skipping them (#5374) * fix(bin): submit our own stuck doorbell instead of skipping every later ring * no-mistakes(review): Confirm and retry Enter once on stuck-doorbell submit * no-mistakes(document): Clarify doorbell retry and pending-composer documentation * feat: add opt-in fleet activity ledger (#5375) * feat(bin): add the opt-in fleet activity ledger Homes that create config/fleet-ledger get an append-only JSONL file, state/fleet-ledger.jsonl, recording task.dispatched, task.status, task.merged, and task.cleaned_up so outside tools can follow a fleet. With the flag absent each producer does one file test and nothing else. docs/fleet-ledger.md owns the record contract and its documented limits. * no-mistakes(review): Record task.status text verbatim after the first colon * no-mistakes(document): Clarify fleet ledger status and setup documentation * no-mistakes(ci): Fixed a timing race in tests/fm-pi-branch-extension.test.sh: the replacement-wake test now waits for the prompt to start before releasing it. The focused test passed twice, and git diff --check passed * fix: validate public follow-up deliverables and wake on rejection (#5352) * fix(bin): format, validate, and surface public-followup deliverables brief pre-fills report_path=data/<work-id>/report.md and states the accepted format of every value it cannot know instead of a bare <value> placeholder. fm-public-followup-emit.sh refuses a deliverable tasks-axi would refuse, in both the direct and staged destinations, naming the key, value, and format. consume records the specific deliverable, outcome, or missing key behind a tasks-axi refusal, and each refusal wakes the owning home once through the existing relay poll. * no-mistakes(review): refuse emits missing a required deliverable in both destinations * no-mistakes(review): require promised deliverables and keep rejections recoverable * no-mistakes(review): mirror tasks-axi's canonical pull request URL rule * no-mistakes(review): keep a rejection wake whose line cannot be read * no-mistakes(review): key emit-time rules on the promise, not the outcome * no-mistakes(review): bound deliverable keys and values as tasks-axi does * no-mistakes(review): state rejection wakes as at-least-once and pin it * no-mistakes(review): enforce the promised contract tasks-axi holds at emit * no-mistakes(review): stop inferring a staged promise from its outcome * no-mistakes(document): Refresh public follow-up documentation * no-mistakes(ci): Fixed both CI flakes. Watcher cleanup is now installed before singleton acquisition, preventing timeout races from leaving stale locks while preserving recovery-failure evidence. Bearings render fixtures now publish a valid isolated Lavish session store and retire each listener after rendering, eliminating false unowned-source races. Verified with checkpoint stress, fm-watch-checkpoint, fm-watcher-lock, repeated fm-bearings-board-render runs, project lint, syntax checks, and git diff checks * Revert unrelated CI auto-fix edits to the watcher and bearings board test The CI step's automatic repair changed bin/fm-watch.sh and tests/fm-bearings-board-render.test.sh to chase two intermittent CI failures that also occur on main and are not part of this change. Restore both files so this branch carries only the public-followup deliverable fix. * no-mistakes(review): Refuse a repeated --deliverable key at emit argument parsing * no-mistakes(document): Clarify public-followup validation and rejection-wake documentation * feat: add Devin CLI crewmate and scout adapter (#5380) * Add verified Devin CLI worker adapter * no-mistakes(review): Drop Devin resolver refusal and launch marker * no-mistakes(review): Verify devin in bootstrap, fold kind rule, update docs * no-mistakes(document): Document Devin sidecar, resume, and worker-only facts * no-mistakes(document): Document Devin interrupt, liveness anchor, composer signals * fix(control): never pair Devin interrupt presses on an idle agent A fast double Escape on an idle Devin opens its /revert picker, where Enter reverts file changes. fm-control now sends the second press only after the first renders Devin's 'esc again to interrupt' armed hint, never sooner than 0.5 s, closes a revert picker a mistimed press opened with one Escape, and refuses to type the exit command while that picker is open. An unarmed interrupt reports cancel=not-running and leaves the busy record untouched. * fix(devin): disable Claude hook import and commit attribution for workers The per-task Devin config now forces read_config_from.claude=false, so a worker no longer runs the user's or project's Claude Code hooks (including Herdr's Claude agent-state hook), and attribution=false, so Devin adds no Co-Authored-By trailer or Generated-with line to commits and PRs. * test(devin): extend live guard and record Herdr and revert-picker evidence The credentialed live guard now fails if an imported Claude Code hook runs, if the worker's commit carries Devin attribution, if an idle interrupt sends more than one press or opens the revert picker, or if an open picker lets exit through or is closed with a revert. The Devin reference, agent-control doc, and verification records carry the 2026-09-22 tmux and Herdr lab results, including the Herdr exit refusal. * no-mistakes(document): Correct Devin documentation links and lifecycle guidance --------- Co-authored-by: Denis Beliaev <battler73@yandex.ru> * fix(bin): recognize passed-with-skips as a passing outcome (#5322) fm-crew-state classifies the no-mistakes outcome 'passed-with-skips' as unknown, so a finished worker awaiting merge is re-alerted as stale. The same blind spot lets fm-teardown's pre-teardown terminal-run check refuse a legitimate abort race that lands on this outcome. Map passed-with-skips to done in crew-state resolution, keeping the skipped publication/CI verification visible in the detail rather than reporting a clean pass, and recognize it as terminal during teardown. * fix(bin): refuse unavailable backend adapters before sourcing (#5382) * fix: refuse missing backend adapter before source * no-mistakes(review): Gate backend precheck under stock Bash * no-mistakes(document): Clarify adapter precheck docs * no-mistakes(lint): Suppress intentional child Bash ShellCheck warning * test: repair base-red liveness, export-DOM, and wake-queue self-tests (#5338) * fix(test): repair tmux liveness and calm follow-up loaded_off regressions Both self-tests fail on untouched main on a host whose coreutils are a multicall binary and whose Chrome has no pre-warmed profile, and each failure masks the other's file. tests/fm-tmux-agent-liveness.test.sh - the stand-in harness processes were symlinks to the host's `sleep`. A single-purpose `sleep` runs happily under another name, but a multicall coreutils binary (uutils or busybox) resolves its applet from argv[0]: `claude-link -> sleep` invoked under the harness name runs the wrong applet and exits immediately, so no foreground process exists and every positive case reads not-alive ("last verdict for liveness:agent was missing (expected alive); title=sh comms=[sh ]"). Build a dedicated spinner as the stand-in target, exactly the way the version-string case already builds its executable, and require the fallback target to demonstrably survive the rename before using it. Every assertion is untouched; the stand-in identity signal is unchanged (the kernel still records the symlink name as the executable identity). tests/fm-calm-pi-extension.test.sh - render_export_dom pinned a brand-new `--user-data-dir` per attempt. On Google Chrome for Testing 151.0.7922.34 that pristine profile makes Chrome's first-run initialization never complete: the browser and its renderers start, but --dump-dom never returns, so all three bounded attempts end exit=0 timed_out=yes bytes=0 and the DOM assertions never run ("could not render calm-mode HTML export DOM"). Chrome's own profile creation under a fresh HOME renders the same document in about a second, so the helper now gives Chrome a private per-attempt HOME instead of the explicit profile flag. Each attempt still gets an isolated profile, and every DOM assertion is unchanged. Root-cause evidence: a pristine --user-data-dir with `--headless=new --dump-dom` had not returned after 150s, while the same command with an empty HOME and no --user-data-dir returned the full DOM in ~1s, and reusing an already-populated profile also returned it in ~1s. The render failure masked the rest of the file: with it repaired, the Pi follow-up loaded_off case passes unmodified against an installed @earendil-works/pi-coding-agent package. These two failures block downstream validation of every lane on hosts with multicall coreutils or a fresh Chrome profile. Verification: - timeout 300 bash tests/fm-tmux-agent-liveness.test.sh -> exit 0, 16 assertions ok - timeout 700 bash tests/fm-calm-pi-extension.test.sh -> exit 0, 13 assertions ok, including the Pi operational follow-up loaded_off case - bash -n and shellcheck clean on both touched files - rest of tests/: bin/fm-test-run.sh --all bounded by timeout 900 completed 17 files with 0 failures (fm-afk-contract.test.sh through fm-backend-herdr-launcher-workspace-e2e.test.sh), then the bound cut off the 18th (fm-backend-herdr-presentation-e2e.test.sh, a real-herdr-gated lab test) with no failure recorded * fix(test): give wake-queue observation checkpoints the alerting ceiling tests/fm-wake-queue.test.sh's secondmate stall case runs bounded foreground watcher checkpoints whose job is to record an observation, with the alerting checkpoint that follows asserting the stall. A checkpoint's exit publishes a downtime marker, and the next checkpoint consumes it only by reaching the end of the watcher's poll loop, where the recovery surfacing runs after the stall tick; the observation itself is recorded by that same stall tick. On a loaded host a 1s ceiling sits under the cost of that iteration (which includes a pane capture in the active-turn gate), so the observation was never recorded, the downtime marker stayed pending, and the alerting checkpoint surfaced `check: rearm-resurface` instead of the stall it asserts: not ok - a foreign queue with no progress did not alert: check: rearm-resurface not ok - a frozen reprovisioned queue generation was hidden: check: rearm-resurface Give the observation checkpoints that feed a later alert the same 4s ceiling the file already documents for alerting checkpoints. The ceiling is only a bound - a checkpoint still returns on its first actionable wake - so no assertion is weakened, and the quiet windows get longer, not shorter. * no-mistakes(document): docs: correct export-DOM Chrome render root cause * no-mistakes(review): Isolate Chrome profile on macOS, dedupe tmux CC_BIN lookup * chore: re-trigger fork workflow approval for triage --------- Co-authored-by: Captain <blackxwhite88@users.noreply.github.com> Co-authored-by: kunchenguid <kunchenguid@users.noreply.github.com> * fix: keep watcher status classification bounded to new log spans (#5383) * fix(bin): classify a status span without re-folding the whole log A watcher poll could take minutes, so its liveness beacon aged past the guard's 300s grace and the Stop auto-arm reported the watcher down. On the main home, cycles ended with beacon_age 91-235s while healthy and 534-706s while the laptop was CPU-starved. Cause: whenever a newly appended status span held a keyed needs-decision or blocked line, status_span_first_actionable_record re-read and re-folded the ENTIRE log to decide whether that opening was still live, forking several subshells per line. On a remote second mate's mirrored parent channel (1.2MB, ~2300 lines) that is 13-20k subshells, about 17s per log per classification when idle, paid by every signal and heartbeat scan. Nothing regressed recently: subshell counts per classification were 20,272 from #3268 (2026-08-29, which introduced the whole-log fold) and 13,188 from #3753 onward through HEAD. The cost grew with log size, since parent-channel logs only grow. Fix: fold only the captured span. An accepted opening does not depend on earlier lines and only later lines close or supersede it, and every later line lies inside the span, so the span fold names the same live openings at a cost bounded by the span. Old and new classification outputs are byte-identical across 51 span offsets of real-shaped secondmate and ship logs. A real-watcher regression test records every read the classification makes through the span-reader seam and asserts none reaches before the classified offset; it fails on the old code (5,157 bytes read from offset 0 to classify an 84-byte span). * no-mistakes(document): Clarify span classification and watcher regression coverage * test: close pr-check watcher test gaps (original flake already fixed by #5362 and #4878) (#5381) * test: fix watcher timing flakes in fm-pr-check-security The bounded watcher's hang guard now counts only the watcher's own time: a case marks the intervals where it holds the watcher on injected work or makes it wait on concurrent work, and those no longer count against its budget. The budget itself stays at main's sixty seconds. The helper also stops forcing a one-second per-check timeout, which killed a correct merged poll whenever that poll took longer than a second, so the watcher only retried it or exited on a later check's wake without the merge. The concurrent-publication case pauses the guard while its arming is in flight, and its task now sorts before the contributions observer the arming also registers, so the watcher stops on the poll under test before running that unrelated fleet snapshot. The case also prints the watcher's stderr when it fails. The replacement case pauses the guard while the re-arm runs inside the watcher, runs that injected arming with the fixture root every other arming here uses, and waits on the replacement merge's process instead of a two-second cap. Merged-poll runs retire the contributions observer before the watcher starts, since no case here exercises it. The returned-descendant case no longer races a four-second sleep or a TERM landing at an arbitrary point in the watcher's idle loop: its descendant holds until killed, and a second check in the same cycle witnesses that it was drained and stops the watcher. * no-mistakes(ci): Reproduced the intermittent board-render failure. Its Lavish stub listed an open session but omitted the session-state record required by the listener, so the build could race the listener’s exit. Added matching fixture state; the affected suite passed three consecutive runs, and shell syntax and diff checks passed * Revert "no-mistakes(ci): Reproduced the intermittent board-render failure. Its Lavish stub listed an open session but omitted the session-state record required by the listener, so the build could race the listener’s exit. Added matching fixture state; the affected suite passed three consecutive runs, and shell syntax and diff checks passed" This reverts commit 6a59859b2e2a3778f9b46faeea42d6de37468cd6. * feat: record fleet status immediately and emit PR-ready events (#5385) * feat: record task.pr_ready in the fleet ledger when a task PR is registered * feat: record worker status lines in the fleet ledger as they are written * no-mistakes(review): Keep worker status append failures and pass the resolved config to the ledger * no-mistakes(review): Resolve relative config override before embedding in worker command * no-mistakes(document): Clarify fleet ledger status capture timing * test: synchronize foreign queue stall checks with watcher progress (#5386) * test: synchronize foreign secondmate stall legs on the watcher's recorded observation Each leg of test_secondmate_foreign_queue_stall_tracks_progress_and_alerts_once ran the watcher under a 1s or 4s wall-clock checkpoint, but every later leg depends on the progress observation the previous leg's watcher recorded. Under load the watcher was killed before its first stall tick, the observation was never written, and the next leg treated its own sighting as the first one, so the stall alert never fired. Run the watcher directly and end each leg on its observable outcome: the progress marker recording the expected observation, or the watcher's own first wake. Also move a comment orphaned above this test back to the drain liveness test it describes. * no-mistakes(review): Wait for full stall reset before stopping watcher leg * test: isolate the bearings render fixture from the shared Lavish store (#5391) The listener resolves its server from that store before it polls…
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Rework AFK away-mode so the captain's away words are the whole mandate: recorded verbatim, restated back in plain sentences at entry, and acted on by the away supervision session's own judgment at the moment an event makes them relevant - instead of the current clause/grant apparatus. This is slice 2 of the captain-approved AFK revamp, decided on a Lavish review board on 2026-09-20.
The captain's verbatim decisions that shape this task:
The full, authoritative design is in data/fm-afk-slices23-plan-s1/report.md (this file survived the plan scout's teardown). Section 4 is the slice-2 spec, 4.2 is the file-by-file change, 4.4 is the one engineering default described below, 4.6 is the non-goals, and 7 is the test strategy. Read it before starting; treat it as the acceptance shape for this task.
The substance of the referenced report sections, in the captain's terms:
Section 4 principle: the away words are the whole mandate. Words in, words out: /afk records the words verbatim, firstmate restates them back in plain sentences (its own reading) so the captain can catch a misreading before saying go; no verbs, no fields, no ids, no refusals; plain /afk with no words stays a valid entry with no mandate. Judgment at execution: on every wake under the record the session reads the words at the tail, decides whether the moment has come, acts through the authority it already has, and holds with verdict captain when unsure; a mirrored captain sentence still authorizes nothing new once the record exists. Mechanical only where words are not needed: a script keeps enforcing exactly what it can check without reading words - green at the live head and head-bound, synchronous merge only under the record lock, the spend cap for fresh spawns, the never-set, no --allow-red while away, local-only landing never relocated. The task-id merge-grant list is retired: while the record exists any green PR may merge, and which one the words meant is the session's reading.
Section 4.2, file by file, one PR: bin/fm-afk-contract.sh retires --action/--object/--when/--stop, the verb list, the never-set scan, clauses: and refused: records, merge_grants: and --grant, and the clauses, flags, refused, grants subcommands; keeps words, expected_return, spend_max_concurrent_workers, reach_, confirmed, validate, readback (now the words verbatim plus the spend cap, expected return, and reach line), archive, the proposal flow, and the cross-subsystem lock; bumps to version 2 while a v1 record still validates and reads with its clause and grant sections ignored, so a live away window is never broken by an upgrade; header rewritten: the record is the words, execution is the session's judgment. bin/fm-afk-launch.sh propose takes only --words-file/--words, --expected-return, --spend. The afk skill: entering records the words, runs propose, relays firstmate's own plain-sentence restatement (not a numbered field list), confirms on go; while away the session acts on the words; announcement is hold-for-return, no phone, "your instructions are recorded and the away session will carry them out where it can; anything it is unsure of, or that needs you, waits for your return"; remove "recorded clauses are not executed". bin/fm-branch-prompt.sh Postures section replaces "a recorded clause is a fact, not authority" with the execution rules: the words are the captain's explicit instruction given before leaving; act on them through the guarded scripts under standing authority; a merge the words call for proceeds when green; work the words call for is dispatched; a run the words say to abort is steered; a decision the words pre-answer is answered through --resolve-key under ask-user-authority; never by analogy; hold on doubt with verdict captain; the never-set is absolute; the words die at archive; log every action taken under the words in the outcome summary ("per your away instructions: ..."). bin/fm-pr-merge.sh removes require_away_merge_grant and the grant read; require_current_away_authority keeps the record lock, the synchronous-only rule, the --allow-red refusal, and the queue refusal; the ledger tag becomes away instead of away-grant/yolo. bin/fm-afk-return.sh: the clause section becomes "your instructions" (the words verbatim) followed by the session's account: every outcome-store row from the window whose summary cites the instructions, then what is waiting, failed, handled, cost, unchanged. bin/fm-lease-lib.sh: no change. docs/pi-supervision-branch.md Postures, docs/architecture.md, and the AGENTS.md section 8 stub: wording; reword the three "deferred to phase 4" comments to "deferred, no owner". Tests: the contract test (v2 record, v1 still validates, no clause subcommands), the launch test, the return test, the merge test (the away matrix becomes record-present-and-green merges, record-present-and-red refuses, --allow-red refused, archive restores attended), the Pi branch extension test (the tail carries the words), the branch supervision prompt byte-identity test, and the pr-check-security and contributions grant fixtures.
Section 4.4 engineering default (the recommended option): the away session may file a backlog work item when the words explicitly call for that work (for example "cut a prerelease after the merge"), writing the brief's intent from the words for that step, then dispatch it under the spend cap; fm-spawn's queued-only rule for the branch becomes "queued, or filed by the branch from the away words", a one-line relaxation plus a backlog note citing the words. Filing the item the captain explicitly asked for is not inventing work.
Section 4.6 non-goals: no parser, tokenizer, classifier, or grammar over the words; no fields, verbs, ids, or clause log; no named-check red merge while away, no local-only landing relocation, no discard, no phone reach; no fm_lease_justify, --clause, --posture, --citation, fm-afk-alarm.sh; no change to bin/fm-lease-lib.sh; no mechanical gate that tries to tell a never-set decision from an ordinary one; the three "phase 4" deferrals in landed comments (archive-chain identity, same-second session identity, per-blocker decision provenance in the return gate) are not adopted, and the PR rewords those comments so the code stops naming a task that will not exist.
Section 7 test strategy: behavioral, through public entrypoints only, per the repo rule against source-text tests. Drive fm-afk-contract.sh and fm-afk-return.sh as commands and assert records and rendered output (v2 written, v1 still read); drive fm-pr-merge.sh with the existing forge mocks for the record-present matrix (green merges, red refuses, --allow-red refused, archive restores attended); pin the prompt through the existing byte-identity test and the Pi extension's tail test.
What Changed
Risk Assessment
✅ Low: The approved authority-model change is consistently implemented across record parsing, wake delivery, merge gating, return reporting, documentation, and behavioral tests, with the prior fix-round regressions correctly addressed.
Testing
Live evidence supports multiline entry, corruption refusal, return accounting, and the real Pi/Herdr away-return lifecycle. The remaining four scenarios were supported only by automated tests in the prior payload, not live product interaction, so the overall result is inconclusive.
0a 0aand the confirmation announces hold-for-return behavior.invalid words block, and archive exits nonzero while retaining the record.tests/fm-afk-contract.test.sh, which did not establish a live product result. Drive a legacy v1 record through the real public product entrypoint and capture its rendere…FM_AFK_PI_HERDR_E2E=1 tests/fm-afk-pi-herdr-return-e2e.test.shin a guarded non-default Herdr lab.tests/fm-pr-merge.test.shwith isolated fixtures, which did not establish a live product result. Exercise the merge matrix through the real public merge entrypoint with…Evidence: Real Pi/Herdr away-return lifecycle
Evidence: AFK live product transcript
Source: AFK live product transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 1 issue found → auto-fixed (3) ✅
.pi/extensions/fm-branch-supervision.ts:1448- Intent requires the wake tail to carry the captain's words verbatim, but.trim()removes trailing spaces and blank lines from the rendered read-back. For example, words recorded asdeploy A\n\nreach the away session asdeploy A, altering the whole mandate it must judge. Preserverendered.stdoutunchanged; the remedy needs confirmation because this contradicts the authoritative verbatim requirement.🔧 Fix applied.
1 warning still open:
bin/fm-afk-return.sh:395- The return brief accepts a case-insensitive prefix without the required colon, exceeding the exactper your away instructions:marker contract. For example, a non-action summaryper your away instructions were unclear, so I heldis incorrectly reported as an action. The unnecessary case-insensitive alias is also encoded at tests/fm-afk-return.test.sh:401. Remove the alias and match the complete canonical marker exactly.🔧 Fix applied.
1 error still open:
bin/fm-afk-contract.sh:256- A damaged multi-line words block can validate while silently dropping the rest of the captain's mandate. For example, if the stored second line loses its two-space prefix,words: |-\n merge A\nhold Bis parsed as onlymerge A: the generic top-level match exits successfully once one line was read, so validation passes and the truncated read-back reaches the away session at .pi/extensions/fm-branch-supervision.ts:1448. This can omit a hold or condition before an otherwise mechanically permitted merge. Make the boundary version-aware (only recognized v1 legacy sections may terminate v1 words; v2 words run to EOF) and reject every other unprefixed line. Related changed paths also suppress word-reader failures with a sentinel and must propagate them: bin/fm-afk-contract.sh:328, bin/fm-afk-contract.sh:342, and bin/fm-afk-return.sh:380.🔧 Fix applied.
✅ Re-checked - no issues remain.
0a 0aand the confirmation announces hold-for-return behavior.invalid words block, and archive exits nonzero while retaining the record.tests/fm-afk-contract.test.sh, which did not establish a live product result. Drive a legacy v1 record through the real public product entrypoint and capture its rendere…FM_AFK_PI_HERDR_E2E=1 tests/fm-afk-pi-herdr-return-e2e.test.shin a guarded non-default Herdr lab.tests/fm-pr-merge.test.shwith isolated fixtures, which did not establish a live product result. Exercise the merge matrix through the real public merge entrypoint with…tests/fm-afk-contract.test.shtests/fm-afk-return.test.shtests/fm-pr-merge.test.shbash tests/fm-pi-branch-extension.test.shbash tests/fm-branch-supervision.test.shtests/fm-afk-launch.test.shrerun from a detached neutral tmux session; the direct invocation inherited Pi ancestry and correctly refused daemon-only casesFM_AFK_PI_HERDR_E2E=1 tests/fm-afk-pi-herdr-return-e2e.test.shbash tests/fm-contributions.test.shbash tests/fm-pr-check-security.test.shManual isolated product flow throughbin/fm-afk-contract.sh,bin/fm-branch-outcome.sh, andbin/fm-afk-return.shcapturing entry, corruption refusal, archival refusal, and return rendering✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.