Skip to content

fix(bin): keep Herdr lab session selection before passthrough arguments - #5470

Merged
kunchenguid merged 2 commits into
kunchenguid:mainfrom
yasuhito:fm/firstmate-herdr-lab-double-dash-scope-v1
Sep 23, 2026
Merged

kunchenguid merged 2 commits into
kunchenguid:mainfrom
yasuhito:fm/firstmate-herdr-lab-double-dash-scope-v1

Conversation

@yasuhito

Copy link
Copy Markdown
Contributor

Intent

隔離 Herdr ラボで、agent start ... -- <Pi 引数> を試したところ、Firstmate のラボ用コマンドがセッション指定を -- の後ろへ付けてしまい、既定セッション側を参照した可能性がある。既定セッションを変えずに、安全にラボへ固定する修正と隔離環境での回帰試験を進めてよいとの回答は「go」。対象は Firstmate のラボ用コマンドで、Pions 製品の実装は変更しない。

What Changed

  • Place the lab’s explicit --session option before the first -- delimiter so agent start passthrough arguments stay in the isolated session. Calls without a delimiter retain the trailing session option.
  • Update the generated lab brief and Herdr documentation to describe the option placement.
  • Add regression coverage for both argument forms and for rejecting caller-supplied session options.

Risk Assessment

✅ Low: The change is narrowly scoped to placing the lab session option before a passthrough delimiter, and the added behavioral test covers the reported argument sequence.

Testing

Both targeted scripts passed. In a real named Herdr lab, Pi started with the supplied passthrough arguments; unsafe session inputs were rejected, and teardown verified the default session was unchanged. A generated brief showed the corrected instruction. An initial redundant prepare call was refused by the helper; its tripwire was cleaned up before the successful run. Test-created worktree files were removed.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Start Pi with arguments after --; Herdr starts it in the named lab and passes those arguments to Pi. ✅ pass live Live Herdr lab transcript
Supply a caller session flag after -- or a leading delimiter; the helper rejects the command. ✅ pass live Live Herdr lab transcript
Tear down the named lab; it is removed and the default session tripwire remains unchanged. ✅ pass live Live Herdr lab transcript
Scaffold a --herdr-lab brief; it instructs the worker to place the session option before any -- delimiter. ✅ pass live Generated Herdr lab brief excerpt
Evidence: Live Herdr lab transcript

Source: Live Herdr lab transcript

lab: fm-lab-dd-live-1144877-32723
lab pane: w1:p1
start Pi with arguments after --
{"id":"cli:agent:start","result":{"agent":{"agent":"pi","agent_status":"idle","cwd":"~/.no-mistakes/worktrees/38526edaf053/01M385JE3KRKMW1VVSYK9KE688","focused":true,"foreground_cwd":"~/.no-mistakes/worktrees/38526edaf053/01M385JE3KRKMW1VVSYK9KE688","interactive_ready":true,"name":"dd-probe","pane_id":"w1:p1","revision":2,"state_change_seq":1,"tab_id":"w1:t1","terminal_id":"term_65c2de75bdc4c1","terminal_title":"π - 01M385JE3KRKMW1VVSYK9KE688","terminal_title_stripped":"π - 01M385JE3KRKMW1VVSYK9KE688","workspace_id":"w1"},"argv":["pi","--no-session","--offline","--no-extensions","--no-skills","--no-context-files"],"type":"agent_started"}}
lab agent list:
{"id":"cli:agent:list","result":{"agents":[{"agent":"pi","agent_status":"idle","cwd":"~/.no-mistakes/worktrees/38526edaf053/01M385JE3KRKMW1VVSYK9KE688","focused":true,"foreground_cwd":"~/.no-mistakes/worktrees/38526edaf053/01M385JE3KRKMW1VVSYK9KE688","interactive_ready":true,"name":"dd-probe","pane_id":"w1:p1","revision":2,"state_change_seq":1,"tab_id":"w1:t1","terminal_id":"term_65c2de75bdc4c1","terminal_title":"π - 01M385JE3KRKMW1VVSYK9KE688","terminal_title_stripped":"π - 01M385JE3KRKMW1VVSYK9KE688","workspace_id":"w1"}],"type":"agent_list"}}
reject caller session after --:
fm-herdr-lab: run forbids caller-supplied --session; the helper supplies the lab session
caller session rejected
reject leading --:
fm-herdr-lab: run forbids a leading option before the Herdr subcommand; it could shift a server or session lifecycle operation past the guard or subvert session isolation
leading delimiter rejected
teardown: lab removed; default session tripwire unchanged
Evidence: Generated Herdr lab brief excerpt

Source: Generated Herdr lab brief excerpt

# Herdr isolation - HARD SAFETY CONTRACT
This brief was explicitly scaffolded with `--herdr-lab` because the task will drive Herdr lifecycle behavior.
On Herdr 0.7.3 the API socket is not relocatable by `HERDR_CONFIG_PATH`, `XDG_CONFIG_HOME`, or `HOME`.
A named non-`default` session plus an explicit `--session <name>` Herdr option on every call is the only viable local isolation.

1. Set `HERDR_LAB_HELPER='~/.no-mistakes/worktrees/38526edaf053/01M385JE3KRKMW1VVSYK9KE688/bin/fm-herdr-lab.sh'` and generate the session name with `HERDR_LAB_SESSION=$("$HERDR_LAB_HELPER" name lab-dd-brief)`.
   Install `trap '"$HERDR_LAB_HELPER" teardown "$HERDR_LAB_SESSION"' EXIT` before provisioning, then provision only with `"$HERDR_LAB_HELPER" provision "$HERDR_LAB_SESSION"`.
2. Run every task-specific non-lifecycle Herdr command through `"$HERDR_LAB_HELPER" run "$HERDR_LAB_SESSION" <arguments...>`.
   The helper supplies the required `--session "$HERDR_LAB_SESSION"` as a Herdr option, before any `--` delimiter; `HERDR_SESSION` alone is never accepted as isolation.
3. Teardown only through `"$HERDR_LAB_HELPER" teardown "$HERDR_LAB_SESSION"`.
   It re-checks refuse-default immediately before stop and again immediately before delete, and fails closed on ambiguity.
4. If an experiment requires a deliberate mid-run session stop, use only `"$HERDR_LAB_HELPER" stop "$HERDR_LAB_SESSION"`; it performs the same immediate refuse-default check.
5. Forbidden commands: direct `herdr server stop`, every other server-global operation such as `herdr server live-handoff` or reload/update operations, direct `herdr session stop`, direct `herdr session delete`, and any Herdr call scoped only by ambient or inline `HERDR_SESSION`.
6. The helper records the live default session before provisioning and verifies the identical fleet state after teardown.
   A missing, stopped, or changed default session is a hard tripwire failure, never a cleanup warning to ignore.

Never bypass the helper, even for a read-only lifecycle probe or cleanup after failure.
The captain fleet uses the running `default` session.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Start Pi with arguments after --; Herdr starts it in the named lab and passes those arguments to Pi. ✅ pass live Live Herdr lab transcript
Supply a caller session flag after -- or a leading delimiter; the helper rejects the command. ✅ pass live Live Herdr lab transcript
Tear down the named lab; it is removed and the default session tripwire remains unchanged. ✅ pass live Live Herdr lab transcript
Scaffold a --herdr-lab brief; it instructs the worker to place the session option before any -- delimiter. ✅ pass live Generated Herdr lab brief excerpt
  • bash tests/fm-herdr-lab.test.sh
  • bash tests/fm-brief.test.sh
  • bin/fm-herdr-lab.sh provision &#34;$lab&#34;, run &#34;$lab&#34; agent start dd-probe --kind pi --pane &#34;$pane&#34; -- --no-session --offline --no-extensions --no-skills --no-context-files, guarded rejection checks, and teardown &#34;$lab&#34;
  • FM_HOME="$brief_home" bin/fm-brief.sh lab-dd-brief firstmate --mode no-mistakes --herdr-lab
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.
@kunchenguid
kunchenguid merged commit 5bbb978 into kunchenguid:main Sep 23, 2026
19 checks passed

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: this is merged. Thank you @yasuhito — really appreciate you taking the time on this.

Contract-class: restore — lab helper already promised an explicit --session Herdr option on every call; trailing placement after a -- delimiter made that option a passthrough arg and broke the specified isolation path. Tip places --session before the first -- (or trailing when no delimiter).

VISION: One captain/one interface aligns (no new captain surface). Authority aligns (no new consent). Scripts-own-mechanics aligns (fm_herdr_lab_raw deterministic placement). Restart non-event aligns. Delegation aligns (lab isolation holds under passthrough). Fleet-outlives-vendor aligns (Herdr option semantics). Scope aligns (helper + docs/tests).

Attestation MATCH 7cd1bd97604e6a4dd8f3bf39f1459b9bd4b4f013. CI 35928115373 SUCCESS / NM 35928115367 SUCCESS. workflow-zero. Squash 5bbb978ce0fc.

@yasuhito
yasuhito deleted the fm/firstmate-herdr-lab-double-dash-scope-v1 branch September 24, 2026 01:18
mituso89 pushed a commit to mituso89/firstmate that referenced this pull request Sep 26, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
mehulbhagwani pushed a commit to mehulbhagwani/firstmate that referenced this pull request Sep 26, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
mehulbhagwani pushed a commit to mehulbhagwani/firstmate that referenced this pull request Sep 26, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
mehulbhagwani pushed a commit to mehulbhagwani/firstmate that referenced this pull request Sep 27, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
mehulbhagwani pushed a commit to mehulbhagwani/firstmate that referenced this pull request Sep 27, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
mehulbhagwani pushed a commit to mehulbhagwani/firstmate that referenced this pull request Sep 27, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
RooseveltAdvisors pushed a commit to RooseveltAdvisors/firstmate that referenced this pull request Sep 29, 2026
…ts (kunchenguid#5470)

* fix(bin): keep the Herdr lab session option before a -- delimiter

fm-herdr-lab.sh run appended --session <lab> after every argument, so a
command with a passthrough delimiter such as agent start ... -- <agent args>
handed the session flag to the agent and Herdr routed the call by the
caller's ambient socket instead of the lab.
The helper now inserts --session <lab> immediately before the first --
delimiter and keeps the trailing form otherwise.

* no-mistakes(document): Clarify Herdr lab session option placement
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants