Skip to content

fix(bin): enter and verify recorded worktree before every worker launch - #21

Closed
mehulbhagwani wants to merge 7 commits into
upstream-mainfrom
fm/fm-4991-upstream-pr
Closed

mehulbhagwani wants to merge 7 commits into
upstream-mainfrom
fm/fm-4991-upstream-pr

Conversation

@mehulbhagwani

Copy link
Copy Markdown
Owner

Intent

Upstream PR kunchenguid#5916 fixes issue kunchenguid#4991: resumed and fresh worker launches must enter and verify the recorded isolated worktree. The PR had diverged from current upstream main with unrelated fork history, hooks, skills, and AGENTS churn, and lacked a closing reference to kunchenguid#4991. Slim the PR onto current upstream main to retain only the worktree-enter, cwd-verify, Orca-compatibility change, its tests and docs, while retaining the greptile P1 fixes for cwd probes reaching agent prompts on Zellij/cmux and PR-relaunch BRANCH unset, then re-attest and re-run CI and no-mistakes.

What Changed

  • bin/fm-spawn.sh: added spawn_enter_recorded_worktree (explicit cd into the recorded task worktree) and spawn_assert_agent_worktree (pre-launch cwd verification, polling up to 20 times), invoked for every fresh ship/scout launch and relaunch before trust setup and brief delivery; both are skipped for secondmates, and the cwd assertion is also skipped for Orca since it owns its own task worktree with no current-path probe.
  • Relaunch path now branches explicitly: Orca relaunches validate the spawn worktree via validate_spawn_worktree, while all other backends reuse the existing adopted-endpoint verification flow.
  • docs/agent-control.md updated to describe the new universal cd + pre-launch path-read contract instead of the old tmux-refuses/Herdr-cd-only description.
  • Added tests/fm-spawn-orca-worktree.test.sh covering Orca spawn/relaunch worktree carve-outs, and extended tests/fm-spawn-dispatch-profile.test.sh, tests/fm-control-relaunch.test.sh, and tests/fm-spawn-worktree-settle.test.sh for the new behavior.

🤖 Generated with Claude Code

Risk Assessment

🚨 High: The final slimming commit silently drops a required, previously-implemented and tested fix (PR-relaunch branch preservation) that the user intent explicitly says must be retained, so the change as it stands contradicts its own acceptance criteria.

Testing

The prior payload's six automated regression suites reportedly passed, but none of the seven scenarios were driven live against the running product (all recorded live=false), so per the validation contract every scenario must be downgraded to untested rather than pass/fail. No live coverage exists for this round; the same live-session gap (real tmux/Herdr/Pi session driving) already flagged in the rejected payload remains the reason.

  • Live validation: ⚠️ inconclusive - 0 of 7 scenarios driven live against the product
Scenario Result Live Evidence
A fresh ship/scout launch is verified to enter and confirm the recorded isolated worktree before trust setup and brief delivery ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established, so it is downgraded per the validation contract. Only non-live regression-suite output (tests/fm-spawn-worktree-s…
A relaunch refuses to start a replacement agent outside the copy holding its work ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-control-relaunch.test.sh) supports this.
An Orca-backed fresh spawn enters the worktree Orca created for it instead of hard-refusing on the post-launch proof ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-orca-worktree.test.sh) supports this.
A relaunch against an Orca-backed task is refused before the RELAUNCH+orca worktree carve-out branch can run ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-orca-worktree.test.sh) supports this.
Claude worker launches (fresh spawn and secondmate) grant exactly the task-channel directories the cwd probe needs, in both bypass and auto permission modes ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-dispatch-profile.test.sh) supports this.
A same-harness tmux/Herdr relaunch sends cd -- <recorded-worktree> to the endpoint and a real launched pane lands in that worktree ⏸️ untested no Requires standing up a real tmux/Herdr session through bin/fm-herdr-lab.sh with a live harness CLI and login; already flagged untested in prior rounds and not re-attempted.
A Pi scout launch sends cd -- <recorded-worktree> to its pane before the agent starts ⏸️ untested no Same live-session constraint as above; already flagged untested and declined in a prior round on this identical change.
  • Outcome: ⚠️ 1 warning across 1 run (30m11s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

⚠️ **Rebase** - 5 warnings
  • ⚠️ AGENTS.md - merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/fm-4991-upstream-pr
  • ⚠️ bin/fm-project-mode.sh - merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/fm-4991-upstream-pr
  • ⚠️ bin/fm-spawn.sh - merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/fm-4991-upstream-pr
  • ⚠️ tests/fm-brief.test.sh - merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/fm-4991-upstream-pr
  • ⚠️ tests/fm-task-delivery.test.sh - merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/fm-4991-upstream-pr
⚠️ **Review** - 1 error
  • 🚨 bin/fm-spawn.sh:1776 - User intent requires: 'retaining the greptile P1 fixes for cwd probes reaching agent prompts on Zellij/cmux and PR-relaunch BRANCH unset'. Commit 5696664 added the PR-relaunch BRANCH-unset fix (PR_URL/PR_HEAD/PR_ACTIVE parsing from relaunch metadata, prepare_existing_pr_branch call, BRANCH=PR_BRANCH, and the appended brief instructions telling the relaunched worker to keep working on the existing PR branch instead of creating a new fm/<id> branch) plus its regression test test_pr_relaunch_preserves_the_existing_branch_name in tests/fm-control-relaunch.test.sh. The final 'slim' commit f199b61 deletes all of this (both the fm-spawn.sh logic block at former line ~1776-1786 and ~4309-4327, and the test), fully reverting the PR-relaunch BRANCH-unset fix the intent explicitly marks as required to retain. As it stands, a relaunch against a task whose meta records an active PR (pr=/pr_head=) will fall through to the generic BRANCH=fm/$ID default and never checks out or continues on the existing PR branch, reintroducing the exact bug the retained fix was supposed to keep fixed.
⚠️ **Test** - 1 warning
  • ⚠️ live validation verdict: inconclusive (0 of 7 scenarios were driven live against the product); untested: A fresh ship/scout launch is verified to enter and confirm the recorded isolated worktree before trust setup and brief delivery, A relaunch refuses to start a replacement agent outside the copy holding its work, An Orca-backed fresh spawn enters the worktree Orca created for it instead of hard-refusing on the post-launch proof, A relaunch against an Orca-backed task is refused before the RELAUNCH+orca worktree carve-out branch can run, Claude worker launches (fresh spawn and secondmate) grant exactly the task-channel directories the cwd probe needs, in both bypass and auto permission modes, A same-harness tmux/Herdr relaunch sends cd -- &lt;recorded-worktree&gt; to the endpoint and a real launched pane lands in that worktree, A Pi scout launch sends cd -- &lt;recorded-worktree&gt; to its pane before the agent starts
  • Live validation: ⚠️ inconclusive - 0 of 7 scenarios driven live against the product
Scenario Result Live Evidence
A fresh ship/scout launch is verified to enter and confirm the recorded isolated worktree before trust setup and brief delivery ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established, so it is downgraded per the validation contract. Only non-live regression-suite output (tests/fm-spawn-worktree-s…
A relaunch refuses to start a replacement agent outside the copy holding its work ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-control-relaunch.test.sh) supports this.
An Orca-backed fresh spawn enters the worktree Orca created for it instead of hard-refusing on the post-launch proof ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-orca-worktree.test.sh) supports this.
A relaunch against an Orca-backed task is refused before the RELAUNCH+orca worktree carve-out branch can run ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-orca-worktree.test.sh) supports this.
Claude worker launches (fresh spawn and secondmate) grant exactly the task-channel directories the cwd probe needs, in both bypass and auto permission modes ⏸️ untested no Prior payload recorded this as pass with live=false; no live evidence was established. Only non-live regression-suite output (tests/fm-spawn-dispatch-profile.test.sh) supports this.
A same-harness tmux/Herdr relaunch sends cd -- &lt;recorded-worktree&gt; to the endpoint and a real launched pane lands in that worktree ⏸️ untested no Requires standing up a real tmux/Herdr session through bin/fm-herdr-lab.sh with a live harness CLI and login; already flagged untested in prior rounds and not re-attempted.
A Pi scout launch sends cd -- &lt;recorded-worktree&gt; to its pane before the agent starts ⏸️ untested no Same live-session constraint as above; already flagged untested and declined in a prior round on this identical change.
  • bash tests/fm-spawn-orca-worktree.test.sh
  • bash tests/fm-spawn-worktree-settle.test.sh
  • bash tests/fm-control-relaunch.test.sh
  • bash tests/fm-spawn-dispatch-profile.test.sh
  • bash tests/fm-watch-arm.test.sh
  • bash tests/fm-fork-free-helpers.test.sh
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@mehulbhagwani

Copy link
Copy Markdown
Owner Author

Stray fork-side validation PR; the canonical upstream change remains kunchenguid#5916.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant