You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix: stage contribution snapshot input through files - #6235
Repair durable monitoring when actually stale or unavailable during full entrusted recovery, preserving contribution ownership and evidence.
What Changed
Stages --contribution-input backlog and task JSON through temporary files and jq --slurpfile, avoiding large JSON payloads on the command line.
Keeps the normal fleet snapshot path on the same temporary transport directory while preserving existing backlog/task file writes.
Adds a large-backlog contribution regression test that verifies ownership, evidence, and native observer trust stay unchanged across small and oversized inputs.
Risk Assessment
✅ Low: The change is narrowly scoped to replacing large JSON argv transport with slurpfile-backed temporary files for contribution input, with behavioral regression coverage for ownership, saved evidence, and observer identity.
Testing
Reran the focused contribution behavior suite against disposable fixture homes; it drove the real fleet snapshot, contribution, watcher, and bearings scripts and passed, including the new large-input regression plus the prior cross-home, unsupported-forge, and measured-child ownership failures. No linters or broad suites were run in this test phase.
Live validation: ✅ go - 3 of 3 scenarios driven live against the product
Scenario
Result
Live
Evidence
A large native contribution input whose canonical backlog exceeds the Linux per-argument limit is consumed through fm-fleet-snapshot.sh --contribution-input and fm-contributions.sh, preserving sha…
Parent recovery consumes child contribution summaries and preserves ownership classifications, including away/yolo merge-ready work as fleet work and fresh measured child coverage in the parent rollup…
✅ pass
live
bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines: ok - cross-home away yolo delivery is fleet work and `ok - parent consumes measured child coverage and refuses expired child s…
Unsupported, stale, or held unavailable contribution coverage is disclosed as unmeasured without inventing captain or fleet work.
✅ pass
live
bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines: ok - expired child unsupported-forge coverage remains unmeasured, `ok - unsupported forge coverage is disclosed without invent…
Command: bash bin/fm-test-run.sh tests/fm-contributions.test.sh
Result: exit=0
Relevant live scenario evidence from runner output:
ok - small and large native contribution inputs preserve ownership, evidence and authenticated observer
ok - cross-home away yolo delivery is fleet work
ok - expired child unsupported-forge coverage remains unmeasured
ok - parent consumes measured child coverage and refuses expired child silence
ok - unsupported forge coverage is disclosed without inventing fleet work
ok - held unsupported forge coverage remains unmeasured
Terminal summary:
FM_TEST_END 2026-10-01T14:56:41Z tests/fm-contributions.test.sh exit=0 duration_ms=143613 gate_skip=false
FM_TEST_SUMMARY total=1 failed=0 skipped_gate=0 duration_ms=143666
Live validation: ✅ go - 3 of 3 scenarios driven live against the product
Scenario
Result
Live
Evidence
User arms contribution monitoring from a canonical backlog whose JSON exceeds Linux per-argument limits; the native snapshot and contribution commands preserve shared URL owners, metadata-only owners,…
✅ pass
live
bash bin/fm-test-run.sh tests/fm-contributions.test.sh plus manual-large-contribution-summary.json: oversized backlog JSON was 1,282,570 bytes and small/large contribution coverage stayed equal.
User relies on durable contribution monitoring while observations are stale, unavailable, or budget-bound; the product records real outages once per episode, keeps stale/unmeasured states visible, and…
✅ pass
live
fm-contributions-test.log: stale verdict, unavailable forge, budget-refusal, late-owner, terminal-settlement, and repeated-poll scenarios all passed against disposable homes and fake forge endpoints…
User runs fm-contributions.sh arm --if-owned before and after the oversized input; the authenticated observer remains the same registered check with the same trust binding and no duplicate observer.
✅ pass
live
manual-large-contribution-summary.json: observer_and_trust_unchanged_after_large_input is true and both small/large arms registered state/contributions.check.sh.
Disposable-home manual check running real bin/fm-fleet-snapshot.sh --contribution-input, bin/fm-contributions.sh snapshot <input> --all, and bin/fm-contributions.sh arm --if-owned for both small and 1.28 MB canonical backlog inputs; wrote evidence JSON under ~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1
jq -e '.large_backlog_json_bytes > 131072 and .large_backlog_records == 1202 and .small_and_large_coverage_equal and .observer_and_trust_unchanged_after_large_input and .saved_contribution_records_unchanged and (.known_rows | length == 3)' manual-large-contribution-summary.json
🚨 tests/fm-contributions.test.sh:399 - The focused contribution regression runner reports tests/fm-contributions.test.sh exit=1. The new large contribution-input regression passed, but three existing contribution summary scenarios failed: cross-home away/yolo merge work remained captain work, expired child unsupported-forge coverage became fleet work, and measured child coverage did not reach the parent. Because these are contribution-monitoring behaviors in the same focused validation surface, the test phase cannot demonstrate the full entrusted recovery intent cleanly.
🚨 live validation verdict: no-go (4 of 4 scenarios were driven live against the product); failed: Parent bearings consumes a child home's away/yolo contribution summary and classifies merge-ready entrusted work as fleet work rather than captain work., Parent bearings consumes an expired child contribution summary with unsupported forge coverage and leaves it unmeasured instead of inventing fleet work., Parent bearings consumes a fresh measured child contribution summary and carries that measured coverage into the parent contribution rollup.
Live validation: ❌ no-go - 4 of 4 scenarios driven live against the product
Scenario
Result
Live
Evidence
User arms contribution monitoring from a canonical backlog whose JSON exceeds the Linux per-argument limit; ownership, saved evidence, shared URL owners, retired-row ownership, and the authenticated o…
✅ pass
live
~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.log contains `ok - small and large native contribution inputs preserve ownership, evidence and authentica…
Parent bearings consumes a child home's away/yolo contribution summary and classifies merge-ready entrusted work as fleet work rather than captain work.
❌ fail
live
~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.log contains not ok - cross-home away yolo delivery requiring a merge remained captain work.
Parent bearings consumes an expired child contribution summary with unsupported forge coverage and leaves it unmeasured instead of inventing fleet work.
❌ fail
live
~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.log contains not ok - expired child unsupported-forge coverage became fleet work.
Parent bearings consumes a fresh measured child contribution summary and carries that measured coverage into the parent contribution rollup.
❌ fail
live
~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.log contains not ok - measured child coverage did not reach parent.
TMPDIR="$PWD/.tmp-test" bash bin/fm-test-run.sh --json ~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.json tests/fm-contributions.test.sh | tee ~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.log
rm -rf .tmp-test && git status --short
🔧 Fix applied.
✅ Re-checked - no issues remain.
Live validation: ✅ go - 3 of 3 scenarios driven live against the product
Scenario
Result
Live
Evidence
A large native contribution input whose canonical backlog exceeds the Linux per-argument limit is consumed through fm-fleet-snapshot.sh --contribution-input and fm-contributions.sh, preserving sha…
Parent recovery consumes child contribution summaries and preserves ownership classifications, including away/yolo merge-ready work as fleet work and fresh measured child coverage in the parent rollup…
✅ pass
live
bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines: ok - cross-home away yolo delivery is fleet work and `ok - parent consumes measured child coverage and refuses expired child s…
Unsupported, stale, or held unavailable contribution coverage is disclosed as unmeasured without inventing captain or fleet work.
✅ pass
live
bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines: ok - expired child unsupported-forge coverage remains unmeasured, `ok - unsupported forge coverage is disclosed without invent…
Waiting on CI (workflows just approved for tip 232b13a1cb34bc7037499a605a6b5b9222295d84).
contract-class: restore — existing fm-fleet-snapshot.sh --contribution-input already owned contribution monitoring; this only moves large backlog/task JSON off argv onto the same file+--slurpfile transport the non-contribution path already used. Not a new always-on observer (cf #4627): no new wake/Bearings/bootstrap surface; ownership/evidence/trust bindings unchanged per regression.
VISION: (1–2) no new captain interface or inferred authority (3) script owns transport mechanics (4) restart non-event (5–6) spine/fleet unchanged (7) scoped to contribution-input JSON transport.
Attestation: MATCH. Firstmate flag: no (not otherwise-ready; CI pending).
maruthiprithivi
changed the title
fix: keep contribution monitoring working for large backlogs
fix: stage contribution snapshot input through files
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Repair durable monitoring when actually stale or unavailable during full entrusted recovery, preserving contribution ownership and evidence.
What Changed
--contribution-inputbacklog and task JSON through temporary files andjq --slurpfile, avoiding large JSON payloads on the command line.Risk Assessment
✅ Low: The change is narrowly scoped to replacing large JSON argv transport with slurpfile-backed temporary files for contribution input, with behavioral regression coverage for ownership, saved evidence, and observer identity.
Testing
Reran the focused contribution behavior suite against disposable fixture homes; it drove the real fleet snapshot, contribution, watcher, and bearings scripts and passed, including the new large-input regression plus the prior cross-home, unsupported-forge, and measured-child ownership failures. No linters or broad suites were run in this test phase.
fm-fleet-snapshot.sh --contribution-inputandfm-contributions.sh, preserving sha…bash bin/fm-test-run.sh tests/fm-contributions.test.sh; evidence filefm-contributions-focused-evidence.txtbash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines:ok - cross-home away yolo delivery is fleet workand `ok - parent consumes measured child coverage and refuses expired child s…bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines:ok - expired child unsupported-forge coverage remains unmeasured, `ok - unsupported forge coverage is disclosed without invent…Evidence: Focused contribution validation evidence
Source: Focused contribution validation evidence
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ No issues found.
✅ No issues found.
bash bin/fm-test-run.sh tests/fm-contributions.test.shplusmanual-large-contribution-summary.json: oversized backlog JSON was 1,282,570 bytes and small/large contribution coverage stayed equal.fm-contributions-test.log: stale verdict, unavailable forge, budget-refusal, late-owner, terminal-settlement, and repeated-poll scenarios all passed against disposable homes and fake forge endpoints…fm-contributions.sh arm --if-ownedbefore and after the oversized input; the authenticated observer remains the same registered check with the same trust binding and no duplicate observer.manual-large-contribution-summary.json:observer_and_trust_unchanged_after_large_inputis true and both small/large arms registeredstate/contributions.check.sh.TMPDIR=~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/tmp bash bin/fm-test-run.sh tests/fm-contributions.test.shDisposable-home manual check running realbin/fm-fleet-snapshot.sh --contribution-input,bin/fm-contributions.sh snapshot <input> --all, andbin/fm-contributions.sh arm --if-ownedfor both small and 1.28 MB canonical backlog inputs; wrote evidence JSON under~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1jq -e '.large_backlog_json_bytes > 131072 and .large_backlog_records == 1202 and .small_and_large_coverage_equal and .observer_and_trust_unchanged_after_large_input and .saved_contribution_records_unchanged and (.known_rows | length == 3)' manual-large-contribution-summary.json🚨
tests/fm-contributions.test.sh:399- The focused contribution regression runner reportstests/fm-contributions.test.shexit=1. The new large contribution-input regression passed, but three existing contribution summary scenarios failed: cross-home away/yolo merge work remained captain work, expired child unsupported-forge coverage became fleet work, and measured child coverage did not reach the parent. Because these are contribution-monitoring behaviors in the same focused validation surface, the test phase cannot demonstrate the full entrusted recovery intent cleanly.🚨 live validation verdict: no-go (4 of 4 scenarios were driven live against the product); failed: Parent bearings consumes a child home's away/yolo contribution summary and classifies merge-ready entrusted work as fleet work rather than captain work., Parent bearings consumes an expired child contribution summary with unsupported forge coverage and leaves it unmeasured instead of inventing fleet work., Parent bearings consumes a fresh measured child contribution summary and carries that measured coverage into the parent contribution rollup.
Live validation: ❌ no-go - 4 of 4 scenarios driven live against the product
~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.logcontains `ok - small and large native contribution inputs preserve ownership, evidence and authentica…~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.logcontainsnot ok - cross-home away yolo delivery requiring a merge remained captain work.~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.logcontainsnot ok - expired child unsupported-forge coverage became fleet work.~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.logcontainsnot ok - measured child coverage did not reach parent.TMPDIR="$PWD/.tmp-test" bash bin/fm-test-run.sh --json ~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.json tests/fm-contributions.test.sh | tee ~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-test.logrm -rf .tmp-test && git status --short🔧 Fix applied.
✅ Re-checked - no issues remain.
fm-fleet-snapshot.sh --contribution-inputandfm-contributions.sh, preserving sha…bash bin/fm-test-run.sh tests/fm-contributions.test.sh; evidence filefm-contributions-focused-evidence.txtbash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines:ok - cross-home away yolo delivery is fleet workand `ok - parent consumes measured child coverage and refuses expired child s…bash bin/fm-test-run.sh tests/fm-contributions.test.sh; runner lines:ok - expired child unsupported-forge coverage remains unmeasured, `ok - unsupported forge coverage is disclosed without invent…bash bin/fm-test-run.sh tests/fm-contributions.test.shgit status --shortafter validation to confirm the focused run left no working-tree residueCreated reviewer evidence at~/.no-mistakes/evidence/01M3S9M1FE4NDT8WJR7EEF31G1/fm-contributions-focused-evidence.txt✅ **Document** - passed
✅ No issues found.
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ No issues found.
✅ **Push** - passed
✅ No issues found.
✅ No issues found.