Conversation
coreldh
force-pushed
the
fix/supervisor-target-refuse-fallback
branch
from
September 26, 2026 03:35
6dc5c9f to
74653e1
Compare
…andle With no FM_SUPERVISOR_TARGET, no $TMUX_PANE, and no herdr pane, supervisor target discovery printed the constant firstmate:0 and the away daemon armed pane escalation against it whenever a pane of that name existed, which can be an unrelated crew or login shell. Discovery now returns no target in that case, and the daemon refuses to arm, naming target_source=UNAVAILABLE on stderr and in its durable log, instead of reporting a guessed target. The script-owned launcher's existing refusal names the same verdict. Explicit override, tmux pane, and herdr pane resolution are unchanged. Refs kunchenguid#1506 (defect A)
`bin/fm-afk-launch.sh start` refused without an operator pane handle only on stderr, so a later look at the home could not tell that refusal from a launch that was never attempted. It now appends the same `startup refused ... target_source=UNAVAILABLE` line the daemon writes to state/.supervise-daemon.log, keeping the stderr refusal. Refs kunchenguid#1506 (defect A)
FM_SUPERVISOR_TARGET_DEFAULT is no longer printed by discovery, but the daemon's inject and wedge-alarm helpers still read it after sourcing this library as the unset fallback for FM_SUPERVISOR_TARGET. Full cross-file ShellCheck therefore reported it as unused (SC2034). Mark it with the repository's sourced-global directive instead of changing behavior. Also restore the paragraph break before the unsupported-backend sentence in docs/configuration.md. Refs kunchenguid#1506 (defect A)
coreldh
force-pushed
the
fix/supervisor-target-refuse-fallback
branch
from
September 29, 2026 15:18
bc4b779 to
1ae07a1
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix defect A of #1506: away mode must not arm pane escalation against the constant
firstmate:0when no operator pane can be identified.Today
discover_supervisor_targetreturns the defaultfirstmate:0when there is noFM_SUPERVISOR_TARGET, noTMUX_PANEand no herdr pane, and the supervise daemon logstarget_source=FALLBACK(firstmate:0)and arms anyway. On a machine where the primary runs outside tmux, that target is a crew or login shell, so escalations are deferred forever while away mode looks armed.Following the triage ("identity-or-refuse is simpler than a new discovery heuristic"), this change refuses instead of guessing:
target_source=UNAVAILABLEon stderr and instate/.supervise-daemon.log, releases its lock and pidfile, and never logs a successful start.fm-afk-launch.sh startalready refused on this path; its message now names the same verdict, and it appends the same refusal line tostate/.supervise-daemon.logso the home keeps a durable record.FM_SUPERVISOR_TARGET,TMUX_PANEand herdr pane resolution are unchanged. The launcher's existing guards still run first.Out of scope, by design: no terminal-specific (Ghostty/TTY) identity resolver, no change to the composer guard (defect B), and no new independent alarm channel (defect C). Known limitation: on the native Claude/Grok start path,
state/.afkis written before the daemon refuses; the turn-end guard then blocks the away turn loudly because no daemon owns supervision, so the failure is visible, not silent.Supersedes #2217, which no longer rebases onto main and bundled the terminal-specific resolver.
What Changed
target_source=UNAVAILABLEand releases its lock and pidfile.fm-afk-launch.sh startreports and logs the same refusal before launch. Explicit target, tmux, and Herdr pane resolution remain supported.Risk Assessment
✅ Low: Captain, low risk: the change adds a bounded refusal when no operator pane handle exists and preserves the explicit, tmux, and herdr target paths.
Testing
Prior focused daemon and launcher runs were reviewed; an initial private tmux socket path exceeded the socket pathname limit, so the live checks were rerun in the runbook’s short disposable lab path and demonstrated the no-handle refusals, guard order, explicit/tmux controls, and Herdr identity composition, while a successful Herdr-pane start remained untestable because lab preparation found no running default session; transcript saved as
supervisor-target-live.txt.firstmate:0pane exists; it exits withtarget_source=UNAVAILABLE, releases its pidfile and lock, and never logs a successful start.startbefore entering away mode; the required-record guard refuses before target discovery.firstmate:0and releases its lock and pidfile on shutdown.TMUX_PANE; it arms against that pane and releases its lock and pidfile on shutdown.session:paneidentity and refuses the nonexistent pane instead of guessing a fallback target.bin/fm-herdr-lab.sh prepare fm-lab-supervisor-targetwith its state directory inside the worktree; it refused because exactly one running default session is required. The live daemon did com…Evidence: Live supervisor target validation transcript
Source: Live supervisor target validation transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
🔧 **Test** - 2 issues found → no changes applied ✅
git -C ~/.no-mistakes/worktrees/57ee2c16a82d/01M3PRH3F96ETGQX19HBHPZXDX statusandgit -C ~/.no-mistakes/worktrees/57ee2c16a82d/01M3PRH3F96ETGQX19HBHPZXDX diff). Respond with fix to validate it, or abort.🔧 No changes applied.
✅ Re-checked - no issues remain.
firstmate:0pane exists; it exits withtarget_source=UNAVAILABLE, releases its pidfile and lock, and never logs a successful start.startbefore entering away mode; the required-record guard refuses before target discovery.firstmate:0and releases its lock and pidfile on shutdown.TMUX_PANE; it arms against that pane and releases its lock and pidfile on shutdown.session:paneidentity and refuses the nonexistent pane instead of guessing a fallback target.bin/fm-herdr-lab.sh prepare fm-lab-supervisor-targetwith its state directory inside the worktree; it refused because exactly one running default session is required. The live daemon did com…bin/fm-lab-home.sh create "$LAB"and a private tmux server with an unrelatedfirstmate:0paneLivebin/fm-supervise-daemon.shno-handle startup withTMUX,TMUX_PANE, Herdr markers, and target overrides unsetLivebin/fm-afk-launch.sh startbefore and afterenterwith all pane handles unsetLive daemon startup withFM_SUPERVISOR_TARGET=firstmate:0and with the isolated pane ID inTMUX_PANE, followed by signal shutdownLive daemon startup withHERDR_ENV=1,HERDR_SESSION=fm-lab-absent-validation, andHERDR_PANE_ID=w1:p9bin/fm-herdr-lab.sh prepare fm-lab-supervisor-target(preflight refused because no running default session was available)Reviewed prior focused runs recorded fortests/fm-daemon.test.shandtests/fm-afk-launch.test.sh; the launcher run was repeated after an isolated tmux setup failure✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.