Skip to content

feat(bin): add a disposable live supervision lab builder - #6037

Merged
kunchenguid merged 19 commits into
mainfrom
fm/fm-live-lab-builder-r1
Sep 29, 2026
Merged

kunchenguid merged 19 commits into
mainfrom
fm/fm-live-lab-builder-r1

Conversation

@kunchenguid

@kunchenguid kunchenguid commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Intent

convert decided plan to an implementation plan in md file and pass that back to firstmate for implementation

Context: that closed the captain's review of the AFK revamp audit, in which the captain selected "Sequence and 3d scope: approve-claude-only-3d1" (the audit's proposed execution sequence approved; the first default-on flip is Claude-only), "3e non-Claude scope: build-3d2-first", all twelve backlog dispositions, and "Sailboat and anchor on Claude: build-now-always-on". The resulting plan is data/fm-afk-revamp-audit-s1/implementation-plan.md in the Firstmate home ~/fm-homes/fmdev-f1, with its evidence in report.md beside it. The AFK revamp's standing words also apply: "2 should be done by opus crewmates" and "this is a major architectural revamp so i want it to do very careful live validation including regression in isolated live environments with some real complex sessions before calling it done. it's ok to use my real llm tokens here".

This task is L in that plan (an accelerator the Claude default-on flip's lab validation uses): a one-command tested lab builder for live supervision validation. Its earlier approval ("yes", via main) rested on this evidence: the signal-span lane spent about 5 hours, of which the code change was about 20 minutes; the rest was hand-built lab misses (Claude workspace-trust prompt in the lab copy, attended mirror feed not wired, a preflight only on an unmerged branch, Pi lab missing the branch extension, a Codex model the account rejects), each forcing a rebuild. Scope as approved: one command standing up a disposable lab main session on Claude or Pi with the supervision host or branch fully wired (hooks, mirror feed, all extensions, lab-only trust), optionally a real seeded local second mate and a gated worker, verifying readiness itself before returning, and tearing everything down cleanly (tmux servers, lab dirs, lab ~/.claude.json entries by atomic replace, no treehouse residue). Addendum, exact words: "(and make sure it references what this long session had done, not literally redoing the whole thing all over again)".

What Changed

  • Add fm-live-lab.sh to build, check, interact with, and tear down isolated Claude or Pi supervision labs, with optional seeded second mate and gated worker.
  • Add lab-home trust registration for Claude and readiness checks for the primary, supervision wiring, extensions, and lab isolation.
  • Document the command and add behavior tests for readiness failures, trust registration, and teardown.

Risk Assessment

🚨 High: Teardown can kill another lab's processes and break a supported Claude configuration layout, so this should not merge without correction or explicit approval.

Testing

Targeted behavioral tests passed. Real Pi and Claude primaries launched in disposable labs, but neither reached a probe-ready turn because the isolated homes lacked login setup; both labs were torn down successfully. CLI transcripts were captured as evidence.

  • Live validation: ⚠️ inconclusive - 1 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Build a Pi lab and receive verified primary, extension, and probe readiness ⏸️ untested no A real Pi primary launched in an isolated worktree home, but its pane reported no openai-codex API key, so it could not answer the probe. The isolated home cannot use the operator's login under the cr…
Build a Claude lab with supervision host and verified mirror readiness ⏸️ untested no A real Claude primary launched in an isolated worktree home but stopped at its first-run theme dialog before session startup or a probe. The authorized operator login cannot be copied or changed for t…
Seed a real second mate and gated worker and observe both become ready ⏸️ untested no Both optional agents require a working Claude login. Isolated Pi and Claude launch attempts could not complete a primary turn; spawning the real agents with the isolated credentials would likewise not…
Reject unsafe teardown targets and remove only a lab's processes, trust entries, and directories ✅ pass live bash tests/fm-live-lab.test.sh drives the real CLI against private tmux servers and processes; both real-primary attempts also ended with successful down
Evidence: Pi launch, readiness refusal, and teardown

Source: Pi launch, readiness refusal, and teardown

lab: ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab (tear down with: bin/fm-live-lab.sh down ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab)
tree: 45785881ee87f05b6445963b0850507f6143ac14 from ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R
primary: pi --approve --session-dir ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab/pi-sessions --model openai-codex/gpt-6-luna --thinking medium
ok primary: pi pid 88262 in ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab/home
fail probe: no LABREADY-1e82deb1 reply in window main (model refused, turn still running, or a dialog is open)
ok trust: Pi trust store unchanged (session-only --approve)
fail extensions: fm-branch-supervision.ts is not loaded by the lock holder
ok watcher: skipped (empty fleet)
ok treehouse: ~/.treehouse unchanged
not ready after 45s; the lab is left up for inspection: bin/fm-live-lab.sh pane ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab, then bin/fm-live-lab.sh down ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab

up exit: 1
Warning: Model "gpt-6-luna" not found for provider "openai-codex". Using custom model id.
 pi v0.82.0                                                                                                                                                                                                                 
 escape interrupt · ctrl+c/ctrl+d clear/exit · / commands · ! bash · ctrl+o more                                                                                                                                            
 Press ctrl+o to show full startup help and loaded resources.                                                                                                                                                               
 Pi can explain its own features and look up its docs. Ask it how to use or extend Pi.                                                                                                                                      
[Context]                                                                                                                                                                                                                   
  ~/AGENTS.md, ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/AGENTS.md, AGENTS.md                                                                                              
[Skills]                                                                                                                                                                                                                    
  afk, agent-skill-trigger-index, ahoy, ask-user-authority, away-quiet-supervision, bearings, bootstrap-diagnostics, captain-hold-lifecycle, decision-hold-lifecycle, diagnostic-reasoning, firstmate-codexapp,             
firstmate-coding-guidelines, firstmate-orca, fmx-respond, harness-adapters, operational-home-layout, process-event-sources, project-management, quiet, quota-array-dispatch, scout-completion, secondmate-provisioning,     
session-start-recovery, ship-landing, stow, stuck-crewmate-recovery, updatefirstmate, validation-supervision                                                                                                                
[Extensions]                                                                                                                                                                                                                
  fm-branch-supervision.ts, fm-calm.ts, fm-primary-pi-watch.ts, fm-primary-turnend-guard.ts                                                                                                                                 
 Warning: tmux extended-keys is off. Modified Enter keys may not work. Add `set -g extended-keys on` to ~/.tmux.conf and restart tmux.                                                                                      
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 Update Available                                                                                                                                                                                                           
 New version 0.87.1 is available. Run pi update                                                                                                                                                                             
 Changelog: https://pi.dev/changelog                                                                                                                                                                                        
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 Error: No API key found for openai-codex.                                                                                                                                                                                  
 Use /login to log into a provider via OAuth or API key. See:                                                                                                                                                               
   /Applications/Pi Launcher.app/Contents/Resources/pi/docs/providers.md                                                                                                                                                    
   /Applications/Pi Launcher.app/Contents/Resources/pi/docs/models.md                                                                                                                                                       
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab/home (main)
0.0%/272k (auto)                                                                                                                                                                                         gpt-6-luna • medium
stopped: lab tmux server and lab processes
removed: 0 Claude project entries under ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab
removed: ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-live-test-85340/lab
down exit: 0
Evidence: Claude first-run dialog and teardown

Source: Claude first-run dialog and teardown

lab: ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-claude-test-63607/lab (tear down with: bin/fm-live-lab.sh down ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-claude-test-63607/lab)
tree: 45785881ee87f05b6445963b0850507f6143ac14 from ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R
primary: claude --setting-sources project,local --model sonnet --effort medium --permission-mode auto
Welcome to Claude Code v2.1.284
..........................................................
     *                                       █████▓▓░
                                 *         ███▓░     ░░
            ░░░░░░                        ███▓░
    ░░░   ░░░░░░░░░░                      ███▓░
   ░░░░░░░░░░░░░░░░░░░    *                ██▓░░      ▓
                                             ░▓▓███▓▓░
 *                                 ░░░░
                                 ░░░░░░░░
                               ░░░░░░░░░░░░░░░░
       █████████                                        *
      ██▄█████▄██                        *
       █████████      *
.......█ █   █ █..........................................
 Let's get started.
 Choose the text style that looks best with your terminal
 To change this later, run /theme
   1. Auto (match terminal)
 ❯ 2. Dark mode ✔
   3. Light mode
   4. Dark mode (colorblind-friendly)
   5. Light mode (colorblind-friendly)
   6. Dark mode (ANSI colors only)
   7. Light mode (ANSI colors only)
 ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌
  1  function greet() {
  2 -  console.log("Hello, World!");                                                                                                                                                                                   
  2 +  console.log("Hello, Claude!");                                                                                                                                                                                  
  3  }
 ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌
  Syntax theme: Monokai Extended (ctrl+t to disable)
stopped: lab tmux server and lab processes
removed: 1 Claude project entries under ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-claude-test-63607/lab
removed: ~/.no-mistakes/worktrees/52b07e9083e7/01M3MK88C405E8RS8C7H42534R/.fm-claude-test-63607/lab
down exit: 0
- Outcome: ⚠️ 2 warnings across 1 run (4m54s)

Live validation with real logins

The pipeline's own live attempts above ran in a credential-less sandbox (Pi had no Codex key; Claude stopped at its first-run theme picker), so the implementer drove the real harnesses with real logins on macOS arm64 (Claude Code 2.1.283 sonnet, Pi 0.82.0 openai-codex/gpt-6-luna).

Run Head Lab Result
c2 4f23477c Claude --mate --worker All nine readiness checks ok. Driven end to end: the worker opened its gate, implemented count_notes(), and reported done; the supervision host took the combined wake (handled ... posture=attended reports=2), recorded the worker's finish as captain outcome 1 and a staged second-mate row as routine outcome 2, and the lab main woke through the real Stop-hook rewake and drained BRANCH OUTCOMES.
p1 530ff2e4 Pi --mate Ready; a staged routine second-mate row got Pi branch outcome verdict routine within about a minute.
c4 + p4 17c4c9bf Claude --mate and Pi, concurrently Both ready (host, verified mirror, watcher, mate; Pi primary, probe, all three extensions); both torn down with no residue.
c5 + p5 caa0e0a4 (pipeline head, after the review fixes) Claude --mate --worker and Pi --mate, concurrently, builder and lab tree both from this head All checks ok, both ready; down exit 0 for both. Against snapshots taken just before: no lab process left, ~/.treehouse identical, Pi trust store byte-identical, ~/.claude.json project keys added none and lost none, no private tmux dir left, the lab tasks' /tmp/fm-<id> and /tmp/fm-<id>+<home-sha> dirs removed.
c6 e2dc0e56 Claude --mate --worker Failed: the running mate and worker Claude processes rewrote ~/.claude.json and dropped the primary's new trust entry, so the primary hit the trust dialog; down did not wait for exiting Claude processes, so the mate re-added its entry. Both fixed in later rounds.
c7 89023211 Claude --mate --worker Failed: the pre-primary settle wait required a parked worker, and the worker polled its gate in a foreground loop. Fixed by waiting only for the worker's first status line and by having the worker declare its paused wait and end its turn. down was clean.
c8 eeb406a3 Claude --mate --worker Ready (trust present at primary launch, worker parked); down exit 0 with no residue, including the detached supervision-host chain.
c9 c7a65940 Claude --mate --worker Ready; down exit 0, every pre-down lab process gone, no residue.
c10 95d7b2b9 (final pipeline head) Claude --mate --worker, builder and lab tree both from this head All checks ok (primary, probe, trust, mirror, host, watcher, mate, worker parked, treehouse), ready; down exit 0: none of the 7 pre-down lab processes alive afterwards, 4 Claude entries removed, ~/.claude.json project keys added none and lost none, Pi trust store identical, no new ~/.treehouse entry, no new /tmp/fm-* or /tmp/fml.*.

Earlier runs also found and fixed, before review: vacuous window checks (tmux resolves a missing window name, even =name, to the current window), teardown matching its own subshells, orphaned descendants of lab processes, per-spawn /tmp dirs outside the lab, Claude's auto-updater replacing the shared binary under a lab, and the user's tmux plugins running in the lab server.

A marker-based teardown (every lab process carrying a lab-unique environment variable) was evaluated in a live lab and rejected: macOS ps does not expose the environment of Apple platform binaries such as the caffeinate every Claude process starts or the watcher's sleep, so those lab children would be invisible to it. Teardown instead tracks pre-kill pid+start-time pairs, their descendants, and live members of recorded process groups while those groups stay non-empty.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 1 warning
  • 🚨 bin/fm-live-lab.sh:159 - With CLAUDE_CONFIG_DIR set, lab_run drops it, so Claude trust registration and launches use $HOME/.claude.json, while check_trust (line 237) and down (line 571) inspect the configured store. Readiness fails and teardown leaves the lab's trust entries behind. Preserve one selected store across up, check, and down, including invocations from a later shell.
  • 🚨 bin/fm-live-lab.sh:597 - fm-claude-trust.sh explicitly supports a symlinked .claude.json by writing its resolved target, but down renames over the symlink. For a user with that supported layout, teardown replaces their link and leaves the target containing lab entries. Resolve and validate the target before the atomic replacement, as trust registration does.
  • 🚨 bin/fm-live-lab.sh:560 - lab_pids matches the lab root as an unbounded substring of any process command. If explicit lab roots are /tmp/lab and /tmp/lab2, down /tmp/lab selects and kills processes for /tmp/lab2 at line 620. Restrict process ownership to this lab's endpoints or path-bounded arguments before sending signals.
  • ⚠️ bin/fm-live-lab.sh:630 - A spawn can create /tmp/fm-<id> at fm-spawn.sh:4369 and fail before publishing state/<id>.meta. Because down discovers task temp directories only through metadata, a failed --mate or --worker up leaves that directory behind. Clean the recorded lab IDs even when their metadata was never published.
  • ⚠️ bin/fm-live-lab.sh:447 - The new --env option is not required by the stated lab-builder scope. At line 519 it can override FM_HOME or HOME after the lab values, making the primary operate on a non-lab home before readiness detects the mismatch. Remove this unrequired arbitrary environment-override component rather than hardening it.
  • ⚠️ bin/fm-live-lab.sh:458 - The Claude --supervision-host none / --expect-host no path introduced at lines 443–444 and 501, with checks skipped at line 332, builds a lab without the supervision host. No stated requirement needs a hostless Claude mode; the requested lab has the host fully wired. Remove this opt-out path while retaining selection of a host line.

🔧 Fix applied.
7 issues (3 errors, 4 warnings) still open:

  • 🚨 bin/fm-live-lab.sh:159 - With CLAUDE_CONFIG_DIR set, lab_run drops it, so Claude trust registration and launches use $HOME/.claude.json, while check_trust (line 237) and down (line 571) inspect the configured store. Readiness fails and teardown leaves the lab's trust entries behind. Preserve one selected store across up, check, and down, including invocations from a later shell.
  • 🚨 bin/fm-live-lab.sh:597 - fm-claude-trust.sh explicitly supports a symlinked .claude.json by writing its resolved target, but down renames over the symlink. For a user with that supported layout, teardown replaces their link and leaves the target containing lab entries. Resolve and validate the target before the atomic replacement, as trust registration does.
  • 🚨 bin/fm-live-lab.sh:560 - lab_pids matches the lab root as an unbounded substring of any process command. If explicit lab roots are /tmp/lab and /tmp/lab2, down /tmp/lab selects and kills processes for /tmp/lab2 at line 620. Restrict process ownership to this lab's endpoints or path-bounded arguments before sending signals.
  • ⚠️ bin/fm-live-lab.sh:630 - A spawn can create /tmp/fm-<id> at fm-spawn.sh:4369 and fail before publishing state/<id>.meta. Because down discovers task temp directories only through metadata, a failed --mate or --worker up leaves that directory behind. Clean the recorded lab IDs even when their metadata was never published.
  • ⚠️ bin/fm-live-lab.sh:447 - The new --env option is not required by the stated lab-builder scope. At line 519 it can override FM_HOME or HOME after the lab values, making the primary operate on a non-lab home before readiness detects the mismatch. Remove this unrequired arbitrary environment-override component rather than hardening it.
  • ⚠️ bin/fm-live-lab.sh:458 - The Claude --supervision-host none / --expect-host no path introduced at lines 443–444 and 501, with checks skipped at line 332, builds a lab without the supervision host. No stated requirement needs a hostless Claude mode; the requested lab has the host fully wired. Remove this opt-out path while retaining selection of a host line.
  • ⚠️ bin/fm-live-lab.sh:497 - The round-1 trust-store fix records an empty claude_config_dir when CLAUDE_CONFIG_DIR is unset. If up runs with HOME=A and down runs later with HOME=B, claude_store (line 159) checks B/.claude.json, leaving the lab trust entries in A/.claude.json; check has the same sibling failure at line 247. Record the absolute store selected at up, including the default, without changing the primary's default Claude environment.

🔧 Fix applied.
1 warning still open:

  • ⚠️ bin/fm-live-lab.sh:458 - The Claude --supervision-host none / --expect-host no path introduced at lines 443–444 and 501, with checks skipped at line 332, builds a lab without the supervision host. No stated requirement needs a hostless Claude mode; the requested lab has the host fully wired. Remove this opt-out path while retaining selection of a host line.
⚠️ **Test** - 2 warnings
  • ⚠️ Full live readiness could not be demonstrated with an isolated home: Pi reported no openai-codex API key, and Claude stopped at first-run theme selection. Completing either login or using the operator's credential store would cross this test's workspace and credential boundary. Re-run the lab builder with an authorized disposable login to validate probe, supervision, mate, and worker readiness.
  • ⚠️ live validation verdict: inconclusive (1 of 4 scenarios were driven live against the product); untested: Build a Pi lab and receive verified primary, extension, and probe readiness, Build a Claude lab with supervision host and verified mirror readiness, Seed a real second mate and gated worker and observe both become ready
  • Live validation: ⚠️ inconclusive - 1 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Build a Pi lab and receive verified primary, extension, and probe readiness ⏸️ untested no A real Pi primary launched in an isolated worktree home, but its pane reported no openai-codex API key, so it could not answer the probe. The isolated home cannot use the operator's login under the cr…
Build a Claude lab with supervision host and verified mirror readiness ⏸️ untested no A real Claude primary launched in an isolated worktree home but stopped at its first-run theme dialog before session startup or a probe. The authorized operator login cannot be copied or changed for t…
Seed a real second mate and gated worker and observe both become ready ⏸️ untested no Both optional agents require a working Claude login. Isolated Pi and Claude launch attempts could not complete a primary turn; spawning the real agents with the isolated credentials would likewise not…
Reject unsafe teardown targets and remove only a lab's processes, trust entries, and directories ✅ pass live bash tests/fm-live-lab.test.sh drives the real CLI against private tmux servers and processes; both real-primary attempts also ended with successful down
  • bash tests/fm-live-lab.test.sh
  • bin/fm-live-lab.sh up --harness pi --timeout 45 &lt;isolated-worktree-lab&gt;; inspected its pane and ran down
  • bin/fm-live-lab.sh up --harness claude --supervision-host none --expect-host no --timeout 15 &lt;isolated-worktree-lab&gt;; inspected its pane and ran down
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[High risk] Adds new shell scripts for lab environment setup and testing.

The PR does not appear safe to merge while teardown can signal unrelated work through a reused process-group ID.

Reviews (12) · Last reviewed commit: "no-mistakes(ci): Fixed down’s teardown w..."

Comment thread bin/fm-live-lab.sh Outdated
Comment thread bin/fm-live-lab.sh Outdated
Comment thread bin/fm-live-lab.sh Outdated
Comment thread bin/fm-live-lab.sh Outdated
… root before looking up the harness executable. The affected behavioral test and shell syntax check pass; the refusal also works with Claude absent from PATH
…nly recorded lab processes and their descendants; the worker gate is in its granted task directory and its path is exposed; readiness uses current crew state; and mate and worker IDs use 12 nonce hex digits. The CLI behavior tests pass, as do shell syntax, ShellCheck, and diff checks. The Claude no-host path is unchanged
Comment thread bin/fm-live-lab.sh Outdated
Comment thread bin/fm-live-lab.sh
…e binary by supplying a test-local stub. The full fm-live-lab test, shell syntax check, and diff check pass
….sh: down waits for recorded processes and escalates before cleanup, PID roots are checked against recorded start times, and Claude primary trust is rechecked after mate/worker readiness. Added behavioral tests in tests/fm-live-lab.test.sh. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass
Comment thread bin/fm-live-lab.sh Outdated
…uctions, unused retry variable, and teardown PID revalidation in bin/fm-live-lab.sh. Added behavioral tests in tests/fm-live-lab.test.sh. Both requested commands pass: tests/fm-live-lab.test.sh and bin/fm-lint.sh
…D and start time, including children orphaned when a root exits. Up now rejects an empty pane PID before calling ps. Added regression tests and a Linux-safe worker fixture. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass
Comment thread bin/fm-live-lab.sh
…shutdown and made the worker fixture verify its exact window with a Linux-available shell. Both requested checks pass. The lab test takes about 66 seconds locally, so the under-one-minute target remains unmet
…fm-live-lab.test.sh. Teardown now tracks identity-checked members of captured lab process groups, including children orphaned during shutdown, without signaling the caller’s group or unrelated processes. Lint passed, and the lab test passed four times
Comment thread bin/fm-live-lab.sh
… permanently dropped, preventing a reused group ID from signalling unrelated work. Added a ps-shim regression test. The lab test, lint, and diff checks pass
…ab.test.sh. The TERM-born-child fixture now waits until its handler is installed before calling down. Down sends SIGKILL to identity-valid survivors on every pass from pass 20 onward and includes survivor process details if it must refuse cleanup. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass locally; Linux CI remains to be verified
…tity-checked scans separated by 0.5 seconds, and removed the unused test loop variable without changing the TERM-born-child test. The lab test, lint, and diff check pass locally
@kunchenguid
kunchenguid merged commit b5fdf74 into main Sep 29, 2026
20 of 21 checks passed
@kunchenguid
kunchenguid deleted the fm/fm-live-lab-builder-r1 branch September 29, 2026 05:28
andrewesweet pushed a commit to andrewesweet/firstmate that referenced this pull request Sep 30, 2026
…#6037)

* feat(bin): add fm-live-lab.sh, a one-command live supervision lab builder

* fix(bin): exact lab windows, per-lab task ids, self-safe teardown

* fix(bin): target lab windows by id, stop lab descendants, add readiness tests

* fix(bin): keep Claude's auto-updater off in live labs; list fm-live-lab.sh

* fix(bin): start the lab tmux server without user config

* no-mistakes(review): Scope lab teardown to its store, root, and task ids

* no-mistakes(review): Record selected user stores at up for check and down

* no-mistakes(document): Clarify live lab documentation and remove stale narratives

* no-mistakes(ci): Fixed the CI failure by checking for an existing lab root before looking up the harness executable. The affected behavioral test and shell syntax check pass; the refusal also works with Claude absent from PATH

* no-mistakes(ci): Fixed all four Greptile findings: teardown signals only recorded lab processes and their descendants; the worker gate is in its granted task directory and its path is exposed; readiness uses current crew state; and mate and worker IDs use 12 nonce hex digits. The CLI behavior tests pass, as do shell syntax, ShellCheck, and diff checks. The Claude no-host path is unchanged

* no-mistakes(ci): Fixed the CI test’s dependence on an installed Claude binary by supplying a test-local stub. The full fm-live-lab test, shell syntax check, and diff check pass

* no-mistakes(ci): Fixed all three selected findings in bin/fm-live-lab.sh: down waits for recorded processes and escalates before cleanup, PID roots are checked against recorded start times, and Claude primary trust is rechecked after mate/worker readiness. Added behavioral tests in tests/fm-live-lab.test.sh. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass

* no-mistakes(ci): Fixed the pre-primary settle wait, worker gate instructions, unused retry variable, and teardown PID revalidation in bin/fm-live-lab.sh. Added behavioral tests in tests/fm-live-lab.test.sh. Both requested commands pass: tests/fm-live-lab.test.sh and bin/fm-lint.sh

* no-mistakes(ci): Fixed teardown to track pre-kill lab processes by PID and start time, including children orphaned when a root exits. Up now rejects an empty pane PID before calling ps. Added regression tests and a Linux-safe worker fixture. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass

* no-mistakes(ci): Fixed teardown tracking for children spawned during shutdown and made the worker fixture verify its exact window with a Linux-available shell. Both requested checks pass. The lab test takes about 66 seconds locally, so the under-one-minute target remains unmet

* no-mistakes(ci): Fixed ci-2 and ci-4 in bin/fm-live-lab.sh and tests/fm-live-lab.test.sh. Teardown now tracks identity-checked members of captured lab process groups, including children orphaned during shutdown, without signaling the caller’s group or unrelated processes. Lint passed, and the lab test passed four times

* no-mistakes(ci): Fixed teardown so an observed-empty process group is permanently dropped, preventing a reused group ID from signalling unrelated work. Added a ps-shim regression test. The lab test, lint, and diff checks pass

* no-mistakes(ci): Fixed ci-1 in bin/fm-live-lab.sh and tests/fm-live-lab.test.sh. The TERM-born-child fixture now waits until its handler is installed before calling down. Down sends SIGKILL to identity-valid survivors on every pass from pass 20 onward and includes survivor process details if it must refuse cleanup. bin/fm-lint.sh and tests/fm-live-lab.test.sh pass locally; Linux CI remains to be verified

* no-mistakes(ci): Fixed down’s teardown wait to require two empty identity-checked scans separated by 0.5 seconds, and removed the unused test loop variable without changing the TERM-born-child test. The lab test, lint, and diff check pass locally
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant