From c69445386125533499164671df2d4df89b27e21f Mon Sep 17 00:00:00 2001 From: Onyx Date: Fri, 11 Sep 2026 16:02:23 +0800 Subject: [PATCH 1/6] fix(bin): pin the no-mistakes completion signal to the pipeline PR The no-mistakes Definition of done opened by declaring the task complete at commit time and asking for `done: {summary}`, so workers read a commit as delivery and stopped without ever running the pipeline; three tasks were chased for it in one day. The block now opens by naming the pipeline's PR as the only completion, says outright that a commit, a clean branch, or "ready for the run" is not completion, makes running the pipeline the worker's own step, states the first-run doctor/init step, requires the PR URL, head, and CI result on completion, and keeps the completion claim as the last status line. direct-PR and local-only keep their own distinct signals. tests/fm-brief.test.sh pins the new no-mistakes wording, the absent commit-is-complete sentence, and the mode separation. --- bin/fm-dod-lib.sh | 13 +++++++--- tests/fm-brief.test.sh | 59 ++++++++++++++++++++++++++++++++++++++++-- 2 files changed, 67 insertions(+), 5 deletions(-) diff --git a/bin/fm-dod-lib.sh b/bin/fm-dod-lib.sh index 925408f7ae3..531dab570cd 100755 --- a/bin/fm-dod-lib.sh +++ b/bin/fm-dod-lib.sh @@ -13,6 +13,9 @@ # mode is refused rather than silently rendered as the pipeline contract. # The block opens with the fixed machine-readable "Delivery contract: mode=" # line that bin/fm-spawn.sh checks a ship brief against. +# The no-mistakes branch owns the mode's completion signal: that block opens by +# naming the pipeline's PR as the completion and saying outright that a commit is +# not one, because workers were reading a commit as "done" and stopping there. # This file is the one owner of the no-mistakes `--intent` contract: only the # brief's `## Captain's intent` subsection plus later captain words, never # `## Firstmate spec` and never the worker's own tradeoffs. @@ -238,9 +241,13 @@ EOF cat </\`, never after it. You drive no-mistakes by responding to its gates, not by implementing fixes. Follow the guidance no-mistakes itself provides for the mechanics: it loads when you invoke /no-mistakes, and \`no-mistakes axi run --help\` plus the \`help\` lines in each \`axi\` response are authoritative and version-matched to the installed binary. diff --git a/tests/fm-brief.test.sh b/tests/fm-brief.test.sh index 2fe9a440b45..d72973adf3a 100755 --- a/tests/fm-brief.test.sh +++ b/tests/fm-brief.test.sh @@ -260,8 +260,8 @@ test_ship_mode_is_explicit_not_registry() { brief="$home/data/brief-explicit-a5/brief.md" grep -qx "Delivery contract: mode=no-mistakes" "$brief" \ || fail "registered direct-PR posture overrode the explicit --mode" - assert_grep "Firstmate will then instruct you to run /no-mistakes" "$brief" \ - "explicit no-mistakes brief did not render the pipeline definition of done" + assert_grep "Completion for mode=no-mistakes is a PR the no-mistakes pipeline pushed and opened, never a commit." "$brief" \ + "explicit no-mistakes brief did not render the pipeline completion signal" # An unregistered project is not a blocker either, because nothing is looked up. FM_HOME="$home" "$ROOT/bin/fm-brief.sh" brief-explicit-a6 never-registered --mode local-only >/dev/null 2>&1 \ @@ -372,6 +372,60 @@ test_no_mistakes_dod_wording() { pass "fm-brief.sh: no-mistakes DOD keeps its apostrophe prose and bans --yes outright" } +# Regression pin for the delivered-then-abandoned failure: three no-mistakes +# workers committed, read a commit as completion, and stopped without ever +# running the pipeline. The generated no-mistakes brief must name the PR as the +# completion signal, say a commit is not one, and keep the other modes' signals +# distinct from it. +test_no_mistakes_completion_is_a_pr_not_a_commit() { + local home id brief + home="$TMP_ROOT/completion-signal-home" + write_registry "$home" + + id="brief-completion-c1" + FM_HOME="$home" "$ROOT/bin/fm-brief.sh" "$id" some-proj --mode no-mistakes >/dev/null 2>&1 + brief="$home/data/$id/brief.md" + assert_present "$brief" "no-mistakes brief was not scaffolded" + assert_grep "Completion for mode=no-mistakes is a PR the no-mistakes pipeline pushed and opened, never a commit." "$brief" \ + "no-mistakes brief must say the pipeline PR, not a commit, is the completion signal" + assert_grep 'A commit, a clean branch, or "ready for the run" is NOT completion' "$brief" \ + "no-mistakes brief must say plainly that committed work is not completion" + # shellcheck disable=SC2016 # single quotes are deliberate: the backticks must stay literal + assert_grep 'The one completion claim is `done: PR {url} checks green`' "$brief" \ + "no-mistakes brief must pin the one completion claim" + assert_grep "Running the pipeline belongs to this task, not to a later instruction" "$brief" \ + "no-mistakes brief must make running the pipeline the worker's own step" + assert_grep "if it reports the repo is not initialized here" "$brief" \ + "no-mistakes brief must carry the first-run initialization step" + assert_grep "report all three: the PR's full" "$brief" \ + "no-mistakes brief must require URL, head, and CI result on completion" + assert_grep "The completion line is the LAST line in the status log" "$brief" \ + "no-mistakes brief must keep the completion claim as the last status line" + assert_no_grep "The task is complete only when committed on your branch." "$brief" \ + "no-mistakes brief still declares a commit as the completion bar" + + # Mode separation: direct-PR and local-only complete on different artifacts, + # so the no-mistakes pipeline claim must not leak into either of them. + local mode + for mode in direct-PR local-only; do + id="brief-completion-c2-$mode" + FM_HOME="$home" "$ROOT/bin/fm-brief.sh" "$id" some-proj --mode "$mode" >/dev/null 2>&1 + brief="$home/data/$id/brief.md" + assert_no_grep "Completion for mode=no-mistakes" "$brief" \ + "$mode brief received the no-mistakes completion signal" + assert_no_grep 'done: PR {url} checks green' "$brief" \ + "$mode brief received the no-mistakes CI-green completion claim" + done + brief="$home/data/brief-completion-c2-direct-PR/brief.md" + # shellcheck disable=SC2016 # single quotes are deliberate: the backticks must stay literal + assert_grep 'then append `done: PR {url}` to the status file and stop.' "$brief" \ + "direct-PR brief lost its own opening-a-PR completion signal" + brief="$home/data/brief-completion-c2-local-only/brief.md" + assert_grep 'When it is implemented and committed, append `done: ready in branch fm/' "$brief" \ + "local-only brief lost its ready-branch completion signal" + pass "fm-brief.sh: no-mistakes completion is the pipeline PR, and the other modes stay distinct" +} + test_ask_user_escalation_format() { local home id brief mode other_id other_brief home="$TMP_ROOT/ask-user-home" @@ -1050,6 +1104,7 @@ test_ship_mode_is_explicit_not_registry test_delivery_flags_are_refused_where_they_do_not_apply test_faster_paths_use_configured_authority_without_stacked_review test_no_mistakes_dod_wording +test_no_mistakes_completion_is_a_pr_not_a_commit test_ask_user_escalation_format test_ship_project_memory_wording test_herdr_lab_contract_is_explicit_and_complete From 8d3c5506df4b4736bce8f4bdc6704b8b411d73ba Mon Sep 17 00:00:00 2001 From: Onyx Date: Fri, 11 Sep 2026 16:20:44 +0800 Subject: [PATCH 2/6] no-mistakes(review): Align validation trigger ownership and pin single no-mistakes completion claim --- AGENTS.md | 3 ++- bin/fm-dod-lib.sh | 5 ++++- tests/fm-brief.test.sh | 11 ++++++++++- 3 files changed, 16 insertions(+), 3 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 244764b75f8..d991ee513f0 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -356,7 +356,8 @@ After an autonomous merge, give the captain a one-line full-URL or local-main ou ### Validate -For a no-mistakes ship, trigger validation on the same worker after its implementation commit, using the harness invocation owned by `harness-adapters`. +For a no-mistakes ship, the task's own worker starts validation itself after its implementation commit, using the harness invocation owned by `harness-adapters`. +Sending that worker `/no-mistakes` is firstmate's fallback nudge for a worker that has not started its run, never a second start for one already driving it. The task worker that starts a no-mistakes run drives the pipeline and owns every `no-mistakes axi run` and `no-mistakes axi respond` call through the next gate or outcome. Firstmate never invokes `no-mistakes axi respond` for a crew-owned run. When the captain adds or changes an ask mid-task, append the captain's words to that brief's `## Captain's intent` and steer the worker; Firstmate build constraints stay in `## Firstmate spec` or the steer. diff --git a/bin/fm-dod-lib.sh b/bin/fm-dod-lib.sh index 531dab570cd..0196ec2d0e4 100755 --- a/bin/fm-dod-lib.sh +++ b/bin/fm-dod-lib.sh @@ -243,8 +243,11 @@ EOF Delivery contract: mode=no-mistakes **Completion for mode=no-mistakes is a PR the no-mistakes pipeline pushed and opened, never a commit.** A commit, a clean branch, or "ready for the run" is NOT completion; stopping there leaves the task unfinished and firstmate has to chase it. -The one completion claim is \`done: PR {url} checks green\`, written with the PR's full \`https://\` URL once the run reports CI green (state the honest real result instead of "checks green" when the repo has no CI). +The one completion claim is \`done: PR {url} checks green\`, written with the PR's full \`https://\` URL once the run reports CI green. Running the pipeline belongs to this task, not to a later instruction: invoke /no-mistakes yourself as soon as your implementation is committed, and keep driving its gates until that green result or a terminal failure. +Never start a second validation run while one is already active on this branch. +A firstmate /no-mistakes delivery that arrives mid-run is a nudge to reattach and poll, not a second start. +If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked. First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\` if it reports the repo is not initialized here, before the first run. When you claim completion, report all three: the PR's full \`https://\` URL, the head commit it validated, and the CI result. The completion line is the LAST line in the status log: put any supplementary explanation before it, or in \`data//\`, never after it. diff --git a/tests/fm-brief.test.sh b/tests/fm-brief.test.sh index d72973adf3a..f7aeb4724f7 100755 --- a/tests/fm-brief.test.sh +++ b/tests/fm-brief.test.sh @@ -376,7 +376,8 @@ test_no_mistakes_dod_wording() { # workers committed, read a commit as completion, and stopped without ever # running the pipeline. The generated no-mistakes brief must name the PR as the # completion signal, say a commit is not one, and keep the other modes' signals -# distinct from it. +# distinct from it. It must also hand the worker its own run to start, without +# letting a firstmate nudge collide with one already active. test_no_mistakes_completion_is_a_pr_not_a_commit() { local home id brief home="$TMP_ROOT/completion-signal-home" @@ -393,8 +394,16 @@ test_no_mistakes_completion_is_a_pr_not_a_commit() { # shellcheck disable=SC2016 # single quotes are deliberate: the backticks must stay literal assert_grep 'The one completion claim is `done: PR {url} checks green`' "$brief" \ "no-mistakes brief must pin the one completion claim" + assert_no_grep 'state the honest real result instead of "checks green"' "$brief" \ + "no-mistakes brief must keep the single pinned completion claim instead of accepting a second spelling" assert_grep "Running the pipeline belongs to this task, not to a later instruction" "$brief" \ "no-mistakes brief must make running the pipeline the worker's own step" + assert_grep "Never start a second validation run while one is already active on this branch." "$brief" \ + "no-mistakes brief must forbid a duplicate validation run on the branch" + assert_grep "A firstmate /no-mistakes delivery that arrives mid-run is a nudge to reattach and poll, not a second start." "$brief" \ + "no-mistakes brief must treat a mid-run firstmate delivery as a nudge, not a second start" + assert_grep "If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked." "$brief" \ + "no-mistakes brief must route a pipeline-ownership refusal to the active run's status rather than a blocked report" assert_grep "if it reports the repo is not initialized here" "$brief" \ "no-mistakes brief must carry the first-run initialization step" assert_grep "report all three: the PR's full" "$brief" \ From b4a5719283065d4b3c4117dea9c73b3ee04127b0 Mon Sep 17 00:00:00 2001 From: Onyx Date: Fri, 11 Sep 2026 16:43:59 +0800 Subject: [PATCH 3/6] =?UTF-8?q?no-mistakes(review):=20=E7=94=A8=20DOD=20?= =?UTF-8?q?=E7=8B=AC=E6=9C=89=E7=9A=84=20pin=20=E6=8F=AD=E5=BC=80=20DOD=20?= =?UTF-8?q?first-run=20brief=20=E6=96=AD=E8=A8=80?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- tests/fm-brief.test.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/fm-brief.test.sh b/tests/fm-brief.test.sh index f7aeb4724f7..94e686fecbb 100755 --- a/tests/fm-brief.test.sh +++ b/tests/fm-brief.test.sh @@ -404,8 +404,8 @@ test_no_mistakes_completion_is_a_pr_not_a_commit() { "no-mistakes brief must treat a mid-run firstmate delivery as a nudge, not a second start" assert_grep "If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked." "$brief" \ "no-mistakes brief must route a pipeline-ownership refusal to the active run's status rather than a blocked report" - assert_grep "if it reports the repo is not initialized here" "$brief" \ - "no-mistakes brief must carry the first-run initialization step" + assert_grep "First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\`" "$brief" \ + "no-mistakes Definition of done must carry its own first-run initialization step" assert_grep "report all three: the PR's full" "$brief" \ "no-mistakes brief must require URL, head, and CI result on completion" assert_grep "The completion line is the LAST line in the status log" "$brief" \ From 3b9ec37c2e117fcdf6c1258ab4b18d3b3b277e1a Mon Sep 17 00:00:00 2001 From: Onyx Date: Fri, 11 Sep 2026 17:03:15 +0800 Subject: [PATCH 4/6] =?UTF-8?q?no-mistakes(review):=20=E5=B0=86=20brief=20?= =?UTF-8?q?=E5=90=AF=E5=8A=A8=E6=94=B9=E4=B8=BA=E4=B8=8E=20harness=20?= =?UTF-8?q?=E6=97=A0=E5=85=B3=EF=BC=8C=E5=B9=B6=E4=BF=9D=E6=8C=81=E5=AE=8C?= =?UTF-8?q?=E6=88=90=20claim=20=E5=AE=8C=E6=95=B4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- AGENTS.md | 2 +- bin/fm-dod-lib.sh | 13 +++++++------ tests/fm-brief.test.sh | 18 +++++++++++++----- tests/fm-task-delivery.test.sh | 2 +- 4 files changed, 22 insertions(+), 13 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index d991ee513f0..ba19aaad177 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -357,7 +357,7 @@ After an autonomous merge, give the captain a one-line full-URL or local-main ou ### Validate For a no-mistakes ship, the task's own worker starts validation itself after its implementation commit, using the harness invocation owned by `harness-adapters`. -Sending that worker `/no-mistakes` is firstmate's fallback nudge for a worker that has not started its run, never a second start for one already driving it. +Sending that worker this task's no-mistakes skill invocation, in the harness-specific form `harness-adapters` owns, is firstmate's fallback nudge for a worker that has not started its run, never a second start for one already driving it. The task worker that starts a no-mistakes run drives the pipeline and owns every `no-mistakes axi run` and `no-mistakes axi respond` call through the next gate or outcome. Firstmate never invokes `no-mistakes axi respond` for a crew-owned run. When the captain adds or changes an ask mid-task, append the captain's words to that brief's `## Captain's intent` and steer the worker; Firstmate build constraints stay in `## Firstmate spec` or the steer. diff --git a/bin/fm-dod-lib.sh b/bin/fm-dod-lib.sh index 0196ec2d0e4..042395b2d4d 100755 --- a/bin/fm-dod-lib.sh +++ b/bin/fm-dod-lib.sh @@ -223,7 +223,7 @@ Delivery contract: mode=direct-PR This task ships **direct-PR**: you raise the PR yourself, without the no-mistakes pipeline. The task is complete only when committed on your branch. When it is implemented and committed, push your branch and open a PR with \`gh-axi\`, then append \`done: PR {url}\` to the status file and stop. -Do NOT run /no-mistakes. The configured merge authority decides whether to merge the PR; firstmate relays the outcome. +Do NOT start the no-mistakes pipeline. The configured merge authority decides whether to merge the PR; firstmate relays the outcome. EOF ;; local-only) @@ -244,16 +244,17 @@ Delivery contract: mode=no-mistakes **Completion for mode=no-mistakes is a PR the no-mistakes pipeline pushed and opened, never a commit.** A commit, a clean branch, or "ready for the run" is NOT completion; stopping there leaves the task unfinished and firstmate has to chase it. The one completion claim is \`done: PR {url} checks green\`, written with the PR's full \`https://\` URL once the run reports CI green. -Running the pipeline belongs to this task, not to a later instruction: invoke /no-mistakes yourself as soon as your implementation is committed, and keep driving its gates until that green result or a terminal failure. +Running the pipeline belongs to this task, not to a later instruction: once your implementation is committed, start this task's no-mistakes pipeline yourself in your own harness's skill-invocation form, and keep driving its gates until that green result or a terminal failure. +The exact skill-invocation form is harness-specific and owned by \`harness-adapters\`; when you are unsure of it, state the action in natural language and proceed. Never start a second validation run while one is already active on this branch. -A firstmate /no-mistakes delivery that arrives mid-run is a nudge to reattach and poll, not a second start. +A firstmate delivery of this task's no-mistakes skill that arrives mid-run is a nudge to reattach and poll, not a second start. If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked. First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\` if it reports the repo is not initialized here, before the first run. -When you claim completion, report all three: the PR's full \`https://\` URL, the head commit it validated, and the CI result. +Write the completion line as the pinned claim first, then the validated head commit and the CI result on that same line, leaving the claim itself intact. The completion line is the LAST line in the status log: put any supplementary explanation before it, or in \`data//\`, never after it. You drive no-mistakes by responding to its gates, not by implementing fixes. -Follow the guidance no-mistakes itself provides for the mechanics: it loads when you invoke /no-mistakes, and \`no-mistakes axi run --help\` plus the \`help\` lines in each \`axi\` response are authoritative and version-matched to the installed binary. +Follow the guidance no-mistakes itself provides for the mechanics: it loads when you start the skill, and \`no-mistakes axi run --help\` plus the \`help\` lines in each \`axi\` response are authoritative and version-matched to the installed binary. When starting no-mistakes, pass \`--intent\` as only this brief's \`## Captain's intent\` subsection plus any later words the captain actually said. For a legacy brief with no such subsection, include only words explicitly labeled \`Captain:\`, \`Captain's words:\`, \`Captain's ask:\`, or \`Captain's intent:\`; never copy its mixed \`# Task\` wholesale. If it has no provenance-marked captain words, stop and ask firstmate instead of starting no-mistakes. Do not include \`## Firstmate spec\`, later Firstmate build constraints, or your own decisions and tradeoffs. @@ -275,7 +276,7 @@ Two firstmate-specific rules layer on top of that guidance: - NEVER pass \`--yes\` (or \`-y\`) to \`no-mistakes axi run\` or \`no-mistakes axi respond\`. It is banned fleet-wide. It auto-resolves every gate including ask-user findings with no escalation, and answering your own ask-user finding is a hard rule violation. -After /no-mistakes reports CI green (the CI-ready return point - do not wait for it to keep monitoring in the background until merge), append \`done: PR {url} checks green\` and stop. You are finished. +After the pipeline reports CI green (the CI-ready return point - do not wait for it to keep monitoring in the background until merge), append \`done: PR {url} checks green\` and stop. You are finished. EOF ;; *) diff --git a/tests/fm-brief.test.sh b/tests/fm-brief.test.sh index 94e686fecbb..bbfce7fe69e 100755 --- a/tests/fm-brief.test.sh +++ b/tests/fm-brief.test.sh @@ -376,8 +376,8 @@ test_no_mistakes_dod_wording() { # workers committed, read a commit as completion, and stopped without ever # running the pipeline. The generated no-mistakes brief must name the PR as the # completion signal, say a commit is not one, and keep the other modes' signals -# distinct from it. It must also hand the worker its own run to start, without -# letting a firstmate nudge collide with one already active. +# distinct from it. It must also hand the worker its own start in a harness-agnostic +# form, without letting a firstmate nudge collide with one already active. test_no_mistakes_completion_is_a_pr_not_a_commit() { local home id brief home="$TMP_ROOT/completion-signal-home" @@ -398,16 +398,24 @@ test_no_mistakes_completion_is_a_pr_not_a_commit() { "no-mistakes brief must keep the single pinned completion claim instead of accepting a second spelling" assert_grep "Running the pipeline belongs to this task, not to a later instruction" "$brief" \ "no-mistakes brief must make running the pipeline the worker's own step" + assert_grep "start this task's no-mistakes pipeline yourself in your own harness's skill-invocation form" "$brief" \ + "no-mistakes brief must hand the worker its own start in a harness-agnostic form" + assert_grep "when you are unsure of it, state the action in natural language and proceed" "$brief" \ + "no-mistakes brief must let a worker unsure of the invocation form proceed in natural language" + assert_no_grep "/no-mistakes" "$brief" \ + "no-mistakes brief handed the worker a harness-specific slash invocation" assert_grep "Never start a second validation run while one is already active on this branch." "$brief" \ "no-mistakes brief must forbid a duplicate validation run on the branch" - assert_grep "A firstmate /no-mistakes delivery that arrives mid-run is a nudge to reattach and poll, not a second start." "$brief" \ + assert_grep "A firstmate delivery of this task's no-mistakes skill that arrives mid-run is a nudge to reattach and poll, not a second start." "$brief" \ "no-mistakes brief must treat a mid-run firstmate delivery as a nudge, not a second start" assert_grep "If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked." "$brief" \ "no-mistakes brief must route a pipeline-ownership refusal to the active run's status rather than a blocked report" assert_grep "First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\`" "$brief" \ "no-mistakes Definition of done must carry its own first-run initialization step" - assert_grep "report all three: the PR's full" "$brief" \ - "no-mistakes brief must require URL, head, and CI result on completion" + assert_grep "Write the completion line as the pinned claim first, then the validated head commit and the CI result on that same line, leaving the claim itself intact." "$brief" \ + "no-mistakes brief must keep the pinned claim intact and append head and CI after it on the same line" + assert_no_grep "report all three" "$brief" \ + "no-mistakes brief still asks for a second shape of the completion claim" assert_grep "The completion line is the LAST line in the status log" "$brief" \ "no-mistakes brief must keep the completion claim as the last status line" assert_no_grep "The task is complete only when committed on your branch." "$brief" \ diff --git a/tests/fm-task-delivery.test.sh b/tests/fm-task-delivery.test.sh index 6416fea2889..ef1f437c843 100755 --- a/tests/fm-task-delivery.test.sh +++ b/tests/fm-task-delivery.test.sh @@ -405,7 +405,7 @@ STUB "promoted worker lost the scout protocols and safety rules that still apply" # The faster paths keep their own contracts rather than inheriting the pipeline's. - assert_grep "Do NOT run /no-mistakes" "$payload" \ + assert_grep "Do NOT start the no-mistakes pipeline" "$payload" \ "promoted direct-PR worker lost its no-pipeline contract" assert_grep "Do NOT push, do NOT open a PR, do NOT merge" "$TMP_ROOT/promote-dod/payload-promote-dod-local-only" \ "promoted local-only worker lost its no-remote contract" From 2dd40449f208716e9dced09c45743ead2a5751d8 Mon Sep 17 00:00:00 2001 From: Onyx Date: Fri, 11 Sep 2026 17:46:38 +0800 Subject: [PATCH 5/6] no-mistakes(test): narrow no-mistakes DoD claims to what live evidence supports --- AGENTS.md | 2 +- bin/fm-dod-lib.sh | 4 ++-- tests/fm-brief.test.sh | 11 ++++++++--- 3 files changed, 11 insertions(+), 6 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index ba19aaad177..36a8cdd2877 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -357,7 +357,7 @@ After an autonomous merge, give the captain a one-line full-URL or local-main ou ### Validate For a no-mistakes ship, the task's own worker starts validation itself after its implementation commit, using the harness invocation owned by `harness-adapters`. -Sending that worker this task's no-mistakes skill invocation, in the harness-specific form `harness-adapters` owns, is firstmate's fallback nudge for a worker that has not started its run, never a second start for one already driving it. +Sending that worker this task's no-mistakes skill invocation, in the harness-specific form `harness-adapters` owns, is firstmate's fallback nudge for a worker that has not started its run; never send it as a second start to a worker already driving its run. The task worker that starts a no-mistakes run drives the pipeline and owns every `no-mistakes axi run` and `no-mistakes axi respond` call through the next gate or outcome. Firstmate never invokes `no-mistakes axi respond` for a crew-owned run. When the captain adds or changes an ask mid-task, append the captain's words to that brief's `## Captain's intent` and steer the worker; Firstmate build constraints stay in `## Firstmate spec` or the steer. diff --git a/bin/fm-dod-lib.sh b/bin/fm-dod-lib.sh index 042395b2d4d..ef1949106ed 100755 --- a/bin/fm-dod-lib.sh +++ b/bin/fm-dod-lib.sh @@ -247,8 +247,8 @@ The one completion claim is \`done: PR {url} checks green\`, written with the PR Running the pipeline belongs to this task, not to a later instruction: once your implementation is committed, start this task's no-mistakes pipeline yourself in your own harness's skill-invocation form, and keep driving its gates until that green result or a terminal failure. The exact skill-invocation form is harness-specific and owned by \`harness-adapters\`; when you are unsure of it, state the action in natural language and proceed. Never start a second validation run while one is already active on this branch. -A firstmate delivery of this task's no-mistakes skill that arrives mid-run is a nudge to reattach and poll, not a second start. -If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked. +Treat a firstmate delivery of this task's no-mistakes skill that arrives mid-run as a nudge to reattach and poll, not as a second start. +If a start is refused because a run is already active on this branch, follow the pipeline's own status and help lines instead of reporting the task blocked. First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\` if it reports the repo is not initialized here, before the first run. Write the completion line as the pinned claim first, then the validated head commit and the CI result on that same line, leaving the claim itself intact. The completion line is the LAST line in the status log: put any supplementary explanation before it, or in \`data//\`, never after it. diff --git a/tests/fm-brief.test.sh b/tests/fm-brief.test.sh index bbfce7fe69e..26bdbb28fb5 100755 --- a/tests/fm-brief.test.sh +++ b/tests/fm-brief.test.sh @@ -406,10 +406,15 @@ test_no_mistakes_completion_is_a_pr_not_a_commit() { "no-mistakes brief handed the worker a harness-specific slash invocation" assert_grep "Never start a second validation run while one is already active on this branch." "$brief" \ "no-mistakes brief must forbid a duplicate validation run on the branch" - assert_grep "A firstmate delivery of this task's no-mistakes skill that arrives mid-run is a nudge to reattach and poll, not a second start." "$brief" \ + assert_grep "Treat a firstmate delivery of this task's no-mistakes skill that arrives mid-run as a nudge to reattach and poll, not as a second start." "$brief" \ "no-mistakes brief must treat a mid-run firstmate delivery as a nudge, not a second start" - assert_grep "If a start is refused for pipeline ownership, check whether the active run is this task's own run and follow its status and help lines instead of reporting the task blocked." "$brief" \ - "no-mistakes brief must route a pipeline-ownership refusal to the active run's status rather than a blocked report" + assert_grep "If a start is refused because a run is already active on this branch, follow the pipeline's own status and help lines instead of reporting the task blocked." "$brief" \ + "no-mistakes brief must route an already-active-run refusal to the pipeline's own status rather than a blocked report" + # The brief must not assert a refusal surface or an ownership check the repo cannot verify. + assert_no_grep "pipeline ownership" "$brief" \ + "no-mistakes brief must not assert a pipeline-ownership refusal the repo cannot verify" + assert_no_grep "check whether the active run is this task's own run" "$brief" \ + "no-mistakes brief must not tell the worker to certify run ownership it cannot check" assert_grep "First run in a repo the pipeline has never seen: run \`no-mistakes doctor\`, then \`no-mistakes init\`" "$brief" \ "no-mistakes Definition of done must carry its own first-run initialization step" assert_grep "Write the completion line as the pinned claim first, then the validated head commit and the CI result on that same line, leaving the claim itself intact." "$brief" \ From 0a8ba2796269b1049493b02fde5c9611e37c2eef Mon Sep 17 00:00:00 2001 From: Onyx Date: Sat, 12 Sep 2026 06:08:57 +0800 Subject: [PATCH 6/6] no-mistakes(document): correct delivery-mode definitions-of-done ownership --- AGENTS.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/AGENTS.md b/AGENTS.md index 36a8cdd2877..b947e6b982e 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -536,7 +536,7 @@ Preserve durable structured identifiers, dependencies, and completion artifact l ## 11. Crewmate briefs -`bin/fm-brief.sh` and its help own scaffold syntax, generated variants, status protocol, artifact placement, delivery-mode definitions of done, and exact safety mechanics. +`bin/fm-brief.sh` and its help own scaffold syntax, generated variants, status protocol, artifact placement, and exact safety mechanics, while `bin/fm-dod-lib.sh` is the single owner of the delivery-mode definitions of done. Use its scaffold as the contract, then fill `## Captain's intent` (`{TASK}`) with the captain's own ask plus the context needed to read it, including the substance of any report, decision, or PR the ask refers to, and fill `## Firstmate spec` (`{FIRSTMATE_SPEC}`) with Firstmate's build instructions. `bin/fm-dod-lib.sh` owns what a no-mistakes worker may pass as `--intent` and its rule that the string must be self-sufficient. Keep additions task-specific rather than repeating lifecycle instructions, and alter generated sections only when the task genuinely differs from the standard shape.