fix(bin): reclaim dead checkpoint session locks - #6182
Open
maruthiprithivi wants to merge 4 commits into
Open
maruthiprithivi wants to merge 4 commits into
maruthiprithivi wants to merge 4 commits into
Conversation
A Codex home that runs the supervision host loses supervision for good once
its harness process is replaced: state/.lock line 1 still records the
predecessor's anchor pid, which is no longer a live verified harness, so
bin/fm-supervision-host.sh refuses ownership before activation
("supervision-host stood down: this session does not own supervision"),
starts no watcher cycle, and every later checkpoint in that session repeats
the refusal. The watcher beacon cannot advance because nothing is beating,
and only a manual bin/fm-lock.sh run restores supervision.
The checkpoint is that home's arm owner, but it was the only shell arm owner
that neither reclaimed a provably dead owner nor named the recovery. The
Claude Stop auto-arm (bin/fm-claude-stop-autoarm.sh) and the Cursor stop hook
(bin/fm-turnend-guard-cursor.sh) both delegate a lock whose recorded pid is
not a live verified harness to bin/fm-lock.sh, the single acquisition owner,
before they touch supervision state. This change gives the Codex checkpoint
that same guarded step before it runs the host.
Fail-closed behavior is unchanged: a live owner this session does not own is
never reclaimed, an absent or malformed lock stays uncertain, and the reclaim
uses bin/fm-lock.sh's own claim lock so lock exclusion has one owner. Homes
without config/supervision-host have no ownership gate and are untouched.
Tests cover the replacement-session reclaim (fails before this change), that
a live session-lock owner is never stolen, and that an owned or absent lock
is never rewritten or claimed.
|
…ms only when `fm_session_lock_inspect` classifies the lock as `stale`, so absent, malformed, held, and unknown/live non-harness owners fail closed. Added a regression that writes a live unrelated process PID to `state/.lock`, runs the checkpoint through a fake Codex harness, and verifies the host stands down while the lock remains unchanged. Updated `docs/supervision-host.md` to distinguish absent/malformed/unknown/live-foreign stand-downs from provably dead-owner reclaim. Verified with `bash tests/fm-watch-checkpoint.test.sh`, `bash bin/fm-lint.sh`, and `bash bin/fm-doc-audience-check.sh`
| Grok's model-owned call relies on primary detection. | ||
| The host pins dispatched work to the primary's crew harness rather than the engine's. | ||
|
|
||
| The Claude auto-arm, the Cursor stop hook, and the Codex checkpoint own a home the way `bin/fm-lock.sh` records it, so before they run the host they reclaim a lock whose shared inspection proves a dead recorded owner through that same writer; absent, malformed, unknown, and live foreign locks are left untouched, and the OpenCode, omp, and Pi adapters instead refuse to arm a home with no live owner and name the recovery. |
There was a problem hiding this comment.
Unknown lock behavior misstated If a lock records a live non-harness PID, this paragraph says Claude Stop and Cursor leave it untouched. Both hooks instead pass any numeric PID that is not a live verified harness to
fm-lock.sh, which can reclaim the lock. Codex does leave it untouched. This difference matters when operators diagnose ownership or decide whether an unknown lock is safe from takeover.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Restore checkpoint supervision when the recorded session-lock owner is provably dead, while preserving exclusion of live owners and safe handling of uncertain lock state.
What Changed
fm-lock.shbefore supervision host activation.Risk Assessment
✅ Low: The change is narrowly scoped to Codex checkpoint stale-lock recovery, delegates mutation to the existing lock owner, preserves live-owner and absent/malformed-lock behavior, and the added tests exercise observable checkpoint behavior rather than source text.
Testing
Ran the targeted
fm-watch-checkpointproduct-level test script against isolated disposable homes, covering dead-owner reclaim, live-owner no-steal, absent/owned-lock no-op behavior, and existing supervision-host checkpoint behavior; all scenarios passed and the worktree stayed clean.tests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: a replacement session reclaims a provably dead session-lock ownertests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: a live session-lock owner is never reclaimed by the checkpointtests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: an owned or absent session lock is never rewritten or claimedtests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log: existing host checkpoint cases remained greenEvidence: Focused fm-watch-checkpoint test transcript
Source: Focused fm-watch-checkpoint test transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 1 issue found → auto-fixed ✅
bin/fm-watch-checkpoint.sh:75- The checkpoint now unconditionally sourcesfm-session-lock-lib.sh, but the host fixture used by the existingmake_host_hometests only copiesfm-watch-checkpoint.shandfm-supervision-engine-lib.shinto its fake root. A concrete run oftest_host_checkpoint_bounds_the_park_by_postureuses$hometask-local-workspace; before it can invoke the stub host, line 75 sources a file that is absent in that fixture root, so the test harness exits before exercising the behavior it is meant to cover. The same fixture affectstest_host_checkpoint_passes_a_handback_and_reports_a_stand_downandtest_host_checkpoint_needs_the_file_and_honors_offintests/fm-watch-checkpoint.test.sh:96. Copy the new sourced lock helper and its direct dependency, or keep the fixture using the repository script root for shared libs.🔧 Fix applied.
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
tests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: a replacement session reclaims a provably dead session-lock ownertests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: a live session-lock owner is never reclaimed by the checkpointtests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log:ok - checkpoint: an owned or absent session lock is never rewritten or claimedtests/fm-watch-checkpoint.test.shinfm-watch-checkpoint-targeted.log: existing host checkpoint cases remained greenmkdir -p ~/.no-mistakes/evidence/validation-run && tests/fm-watch-checkpoint.test.sh | tee ~/.no-mistakes/evidence/validation-run/fm-watch-checkpoint-targeted.loggit status --short✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.