Repository navigation
Conversation
|
|
Filed the design discussion as #6757 so this change has an issue-first trail; the reproduction and expected behavior live there. |
|
Speaking as Kun's firstmate: thanks, @kesslerio. This is a careful change, and opening #6757 alongside it made the motivation easy to follow. I read the whole diff of head What I checked:
The no-mistakes attestation matches this head. CI is fully green, including "PR must be raised via no-mistakes", and the merge state is CLEAN. Contract-class: new-default. On main an unconfigured home never wakes MAIN or escalates on a heartbeat just because queued work is ready. The daemon force-self-handles heartbeats and the attended watcher absorbs them. This PR adds a readiness-driven wake and escalation to both by default. It also changes the away contract in Things Kun will weigh (no action needed from you unless you want to address them):
VISION.md, rule by rule
Next step: this is otherwise ready, so it now waits on Kun's merge-or-leave decision. That's on him, not on you. Related: #6757. |
a5dffea to
3eff668
Compare
|
Speaking as Kun's firstmate: thanks for the new round, @kesslerio. I re-reviewed head What changed, and it helps:
Why this isn't otherwise ready right now (waiting on you):
Contract-class: new-default (no change). On main, an unconfigured home never wakes MAIN or escalates on a heartbeat just because queued work is ready. With this PR, both the daemon and the attended watcher wake on ready (or unreadable) readiness by default, and the attended handoff rules change. The away widening is now gone, which narrows what Kun has to decide, but the heartbeat wake class is still a new default-on surface. VISION.md, rule by rule
Next step: you, for the rebase (and a serial 2 that finishes). Once it's otherwise ready again, it goes back to Kun for merge-or-leave. |
Hardening the section 10 backlog rule so a re-evaluation that finds ready work must dispatch it in the same turn: a note without a live worker leaves the item queued, ready siblings launch while another lane is paused or held, captain-owned waits stay waiting, and only an empty ready set permits silence. Adds one cross-reference on the section 8 heartbeat bullet.
A fleet check or teardown handled by an actor with no spawn authority now records a durable handoff that the actor which may launch must act on in the same turn it receives it, before the check or the cleanup counts as handled, so a rule that can only be noted cannot silently become a miss. The teardown path points at that duty instead of carrying a weaker copy of it.
…and owner pointers
…le teardown output assertions. Default and focused lint pass; all 11 ready-queue cases pass. Teardown passed 103 cases, including both corrected assertions, before missing lsof blocked process-reaping verification
…r summaries preserve older pending handoffs. Added a regression that failed before the fix and passes afterward. All 15 focused drain cases, 18 backstop cases, lint, documentation checks, and diff checks pass. The cancelled behavior check requires no source change
The maintainer's issue names a real widening: as written, an away branch launched any queued unblocked work, so standing autonomy grew beyond what the captain's away words granted. Away dispatch now reaches only work the recorded away words name or a standing grant covers, every other ready unit waits for MAIN with its reason recorded, and the attended handoff behavior is unchanged. Covered by a new case on the emitted supervision prompt, which is the surface that delivers this gate.
…and stale evidence
…tive owner pointers
…it empty backlogs and corrected the shared ShellCheck source boundary causing both lint failures. Verified portable serial shard 1 (141 cases), 17 ready-queue cases, default lint, source-aware lint for all reported roots, and git diff --check. All passed
b884daa to
d09b0fe
Compare
|
Speaking as Kun's firstmate: thanks @kesslerio. The rebase kept both meanings in I re-read head State: the attestation matches this head. CI is fully green: run 37850896719, including serial 2, plus "PR must be raised via no-mistakes". The merge state is Since Contract-class: new-default (unchanged). On main, an unconfigured home never wakes MAIN or escalates on a heartbeat just because queued work is ready. With this PR, the daemon and the attended watcher both wake when ready work exists or readiness can't be read. That's a new default-on wake class, so it doesn't auto-merge. What Kun is weighing (nothing needed from you):
VISION.md, rule by rule
Next step: this is now with Kun for a merge-or-leave decision. It isn't waiting on you. Please hold the head where it is, since a new push would restart the review. |
|
@kunchenguid, field data on the open noise question, in case it helps the merge-or-leave call. Over the night of 2026-10-09 to 10-10, a secondmate home on this host kept its watcher alive the whole night. That watcher logged "absorbed heartbeat (no captain-relevant change)" at 03:16, 05:16 and 07:16, and its interval backed off toward the cap, while its backlog held ready units. One of them, a fix that had been ready since 22:58, was first dispatched at 07:32. The previous three nights show the same shape: quiet logs of 7 to 10 hours with ready work queued. That is the case this PR's (The root home's own gap that night had a different cause: its supervising session was stopped by the host app, so no watcher-side change would have helped there. That is tracked separately.) To measure the noise side, this branch is now running locally on that host at head |
|
Speaking as Kun's firstmate: thanks @kesslerio for the field data — the overnight secondmate log (heartbeats absorbed at 03:16/05:16/07:16 while a unit ready since 22:58 waited until 07:32) is a concrete instance of the gap Delta since my 2026-10-09 stamp: no new push; head is still This remains with Kun for a merge-or-leave decision, not waiting on you. One new note for that call: #7031 splits |
Intent
Finish the requested fix on upstream firstmate PR #6753 within the week, per the captain's order 2026-10-08: rebase it onto current main, complete the CI that was cancelled, and push through the custody gate so the maintainer can re-review.
The maintainer's latest review of head 3eff668 (read in full from the PR conversation): the away-scope point is closed (1c7c056), the drain never truncates a captain outcome (e35b652, 3eff668), and the branch persists and reads back each away stop (a4e557e). Two things keep it from ready: (1) an AGENTS.md merge conflict - upstream #5343 (project capacity) landed and rewrote the section 10 sentence to "Re-evaluate queued work after every teardown and heartbeat, and also after a recorded PR-ready handoff when
config/project-capacitycaps that project..."; the PR's own edit to that sentence now conflicts. (2) Behavior portable serial 2 was CANCELLED (not failing): every test that ran passed, but tests/fm-supervision-host.test.sh alone hit the 1-hour shard timeout. The maintainer's named next step: "you, for the rebase (and a serial 2 that finishes). Once it's otherwise ready again, it goes back to Kun for merge-or-leave."Deliverable: the rebased PR head with the conflict resolved in the maintainer's spirit (both the #5343 capacity sentence and this PR's ready-queue re-evaluation wording stand together), CI serial 2 finished green, and the head pushed through
git push no-mistakesas an update to the OPEN PR - never to the fork remote, nevergh pr create, and no push without the guard's clearance.What Changed
Risk Assessment
✅ Low: The changes preserve the required capacity and dispatch restrictions, address readiness and handoff loss at existing boundaries, and split the host suite without dropping cases; no material new defect was substantiated.
Testing
Four focused test scripts, shard-selection inspection, and ten live scenarios passed with CLI transcripts and persisted-state evidence. Labs were cleaned up. Remote CI and delivery remain outer-executor phases.
Evidence: Live readiness, daemon handoff, and outcome drain
Source: Live readiness, daemon handoff, and outcome drain
Evidence: Successful Codex worker processing
Source: Successful Codex worker processing
Evidence: Real away engine records denied dispatch
Source: Real away engine records denied dispatch
Evidence: Capacity deferral and teardown
Source: Capacity deferral and teardown
Evidence: Empty queue and failed-handoff protection
Source: Empty queue and failed-handoff protection
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
timeout -k 5s 180s bash tests/fm-watch-ready-queue.test.shtimeout -k 5s 1800s bash tests/fm-supervision-host.test.shtimeout -k 5s 900s bash tests/fm-supervision-host-late.test.shtimeout -k 5s 180s bash tests/fm-branch-supervision.test.shbin/fm-test-run.sh --list --lane portable-serial-<1..9>of9: confirmed separate host-group shardsPrivate tmux Codex primary and publicfm-spawn.sh; answered worker folder-trust dialog with Enter and verified committed outputLive CLI driver:live-core-driver.shin the evidence directoryReal Claude supervision engine:live-away-driver.shin the evidence directoryCapacity and teardown driver:live-capacity-driver.shin the evidence directoryAdversarial driver:live-adversarial-driver.shin the evidence directoryStopped private lab server, verified owned descendants exited, removed disposable worktree files, and confirmed clean git status✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.