Fix fail-closed fm-send delivery verification - #17
Merged
Merged
Conversation
…nchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes
* fix: prevent no-mistakes gate agents from driving the fleet (kunchenguid#518) * feat: contain no-mistakes gate agents from driving the fleet Add bin/fm-gate-refuse-lib.sh, sourced at the top of fm-spawn/fm-send/ fm-teardown before any fleet mutation. It fails closed when NO_MISTAKES_GATE is set, and via an unspoofable git-common-dir backstop when invoked from a no-mistakes gate worktree (.no-mistakes/repos/*.git) even with the marker unset. A normal firstmate session has neither signal and is unaffected. Set disable_project_settings: true in the tracked .no-mistakes.yaml so the installed pipeline neutralizes gate agents' project instructions for this repo (trusted-only, honored from the default branch). firstmate's own suite runs from a gate worktree during validation, so the shared test helpers set FM_GATE_REFUSE_BYPASS=1 to exempt it; the dedicated tests/fm-gate-refuse.test.sh strips it to verify real refusal. * no-mistakes(review): Captain, refuse empty no-mistakes gate markers * no-mistakes(document): Document no-mistakes gate authority boundary * fix: guard secondmate primary sessions from blind turn ends (kunchenguid#505) * fix: guard secondmate own-home turn ends Remove the .fm-secondmate-home early-exit in fm-turnend-guard.sh so the 'no turn ends blind' backstop fires in a secondmate's own primary session, matching the cd-guard's scope: the own home is guarded, child crew/scout worktrees stay exempt via the retained git-dir/git-common-dir test. This was pure scoping from the guard's primary-only origin and guarded against no secondmate-specific hazard. Add secondmate regression tests (blind-turn block, idle-by-default, stop_hook_active loop guard, deferred-death recovery loop, child-worktree exemption) and record the autonomous background-notify re-invoke measurement (Claude Code 2.1.207, 11s) in docs/turnend-guard.md. * no-mistakes(document): Correct secondmate guard documentation, captain * fix: force-include marked secondmate homes in turn-end guard The prior remove-only form (just deleting the .fm-secondmate-home check) left the DEFAULT secondmate topology unguarded: a treehouse-leased home is a linked git worktree (git-dir != git-common-dir), which the retained git-dir exemption still skipped, so its own primary session could still end a turn blind. Invert the marker: a genuinely-marked home is force-included as a guarded primary (treehouse-leased linked OR git-cloned plain), and the git-dir exemption applies only to UNMARKED child worktrees. Marker validation (regular non-symlink file, non-empty id-token content) blocks a stray or empty marker from spoofing inclusion. Add real linked-worktree regression tests: a treehouse-leased LINKED secondmate home is guarded, a stray/empty marker stays exempt, and the unmarked child worktree stays exempt - the topology the plain git-init fixtures masked. Predicates, in-flight gate, and loop guard untouched. * fix: force ASCII collation in secondmate marker validation Add a function-scoped local LC_ALL=C in fm_root_is_secondmate_home so the [A-Za-z0-9._-] id allowlist matches under C collation, not the ambient locale - a locale-crafted non-ASCII marker id can no longer slip through the range match and spoof force-inclusion of a linked child worktree. Add a regression test proving a non-ASCII marker id is rejected and the linked worktree stays exempt. * no-mistakes(test): fix backend baseline gate-refusal dependency * no-mistakes(document): Correct secondmate turn-end guard documentation * fix: make bootstrap diagnostics backend-aware (kunchenguid#519) * fix: make bootstrap required-tool detection backend-aware Bootstrap demanded tmux and treehouse for every backend except orca, so a herdr/zellij/cmux home with tmux absent was wrongly told MISSING: tmux. Required tools now follow the resolved backend via the single-owner fm_backend_required_tools helper (bin/fm-backend.sh): each backend's own session-provider CLI, jq for the JSON-emitting adapters (herdr/zellij/cmux), and treehouse for session-provider-only backends (orca owns its worktree). The treehouse lease-support check is gated to backends that use treehouse. Adds install hints for herdr/zellij/cmux, regression tests for the full backend dependency matrix (herdr-without-tmux repro plus each boundary), and updates the authoritative Toolchain docs. * no-mistakes(review): Captain, prevent executing Herdr install guidance * no-mistakes(review): Captain, harden backend-aware bootstrap diagnostics * no-mistakes(review): Captain, separate manual dependency remediation * no-mistakes(review): Captain, align bootstrap diagnostic consumers * no-mistakes(document): Align backend adapter dependency comments * fix: preserve follow-up platform context after inbox cleanup (kunchenguid#520) * fix: recover X/Discord follow-up platform after inbox cleanup A milestone follow-up posted directly by request_id after the inbox was drained - and with no task link, because one persistent secondmate's single x_request slot collides across concurrent requests - resolved platform only from the local inbox, so a >280 Discord reply silently defaulted to the X 280-char budget and threaded as (1/2). - fm-x-poll records a durable per-request reply context (state/x-context/<rid>.json) at stash time, keyed by request_id so concurrent requests never overwrite each other; it survives inbox cleanup and restart. - fm-x-reply resolves platform/budget through registry -> inbox -> relay (the relay lookup confined to a live follow-up), recovering the original platform independent of task-link availability. - Fail-safe: a follow-up whose platform/budget cannot be authoritatively resolved and that would split is refused (exit 8) and held for retry, never wrongly split; fm-x-followup keeps the link on that exit. - fm-x-dismiss clears the durable context for a dismissed mention. Refactors reply-context extraction into a single owner and adds regression coverage for all four cases. * no-mistakes(review): Captain, fail closed on incomplete follow-up context * no-mistakes(review): Captain, bound X context registry retention * no-mistakes(review): Captain, align context retention with answer binding * no-mistakes(document): Align X follow-up context documentation * no-mistakes(document): Align durable X follow-up documentation * fix: preserve secondmate routing markers in terminal sends (kunchenguid#533) * fix: preserve secondmate routing markers * no-mistakes(review): Captain, preserve trailing newlines in marked secondmate sends * no-mistakes(test): Captain, tolerate bootstrap timeout elapsed drift * no-mistakes(document): Refresh Herdr marker documentation * fix: align Grok effort handling with 0.2.99 (kunchenguid#527) * fix: align grok effort docs and spawn with 0.2.99 ceiling grok 0.2.99 accepts only low|medium|high for --reasoning-effort and rejects both xhigh and max. Omit unsupported values on spawn, flag them in crew-dispatch validation, and update harness-adapters. * no-mistakes(test): Captain: refresh gotmp teardown fixture dependencies * no-mistakes(document): Clarify Grok effort documentation ownership * fix: preserve declared pauses across watcher restarts * no-mistakes(review): Preserve unknown-state stale wake safety * no-mistakes(test): Stabilize PR review diffs --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com>
added 18 commits
July 19, 2026 05:06
added 6 commits
July 20, 2026 10:58
quinnbot-ai
pushed a commit
that referenced
this pull request
Jul 20, 2026
fork/main advanced by one PR while this branch's no-mistakes run was in flight. Resolved the one real conflict in tests/fm-brief.test.sh: PR #17 independently fixed the same fork/upstream secondmate-charter wording mismatch this branch's own no-mistakes test-fix round had already fixed, but in the opposite direction (kept fork's "secondmate: a persistent domain supervisor" wording and updated the test to match, rather than reverting to origin's older "second mate" phrasing). fork/main's resolution is authoritative since it already merged; took its wording for both bin/fm-brief.sh and the test, undoing this branch's own now-superseded reversion.
quinnbot-ai
added a commit
that referenced
this pull request
Jul 21, 2026
* fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: durable pause recognition across watcher restarts (#1) * fix: prevent no-mistakes gate agents from driving the fleet (kunchenguid#518) * feat: contain no-mistakes gate agents from driving the fleet Add bin/fm-gate-refuse-lib.sh, sourced at the top of fm-spawn/fm-send/ fm-teardown before any fleet mutation. It fails closed when NO_MISTAKES_GATE is set, and via an unspoofable git-common-dir backstop when invoked from a no-mistakes gate worktree (.no-mistakes/repos/*.git) even with the marker unset. A normal firstmate session has neither signal and is unaffected. Set disable_project_settings: true in the tracked .no-mistakes.yaml so the installed pipeline neutralizes gate agents' project instructions for this repo (trusted-only, honored from the default branch). firstmate's own suite runs from a gate worktree during validation, so the shared test helpers set FM_GATE_REFUSE_BYPASS=1 to exempt it; the dedicated tests/fm-gate-refuse.test.sh strips it to verify real refusal. * no-mistakes(review): Captain, refuse empty no-mistakes gate markers * no-mistakes(document): Document no-mistakes gate authority boundary * fix: guard secondmate primary sessions from blind turn ends (kunchenguid#505) * fix: guard secondmate own-home turn ends Remove the .fm-secondmate-home early-exit in fm-turnend-guard.sh so the 'no turn ends blind' backstop fires in a secondmate's own primary session, matching the cd-guard's scope: the own home is guarded, child crew/scout worktrees stay exempt via the retained git-dir/git-common-dir test. This was pure scoping from the guard's primary-only origin and guarded against no secondmate-specific hazard. Add secondmate regression tests (blind-turn block, idle-by-default, stop_hook_active loop guard, deferred-death recovery loop, child-worktree exemption) and record the autonomous background-notify re-invoke measurement (Claude Code 2.1.207, 11s) in docs/turnend-guard.md. * no-mistakes(document): Correct secondmate guard documentation, captain * fix: force-include marked secondmate homes in turn-end guard The prior remove-only form (just deleting the .fm-secondmate-home check) left the DEFAULT secondmate topology unguarded: a treehouse-leased home is a linked git worktree (git-dir != git-common-dir), which the retained git-dir exemption still skipped, so its own primary session could still end a turn blind. Invert the marker: a genuinely-marked home is force-included as a guarded primary (treehouse-leased linked OR git-cloned plain), and the git-dir exemption applies only to UNMARKED child worktrees. Marker validation (regular non-symlink file, non-empty id-token content) blocks a stray or empty marker from spoofing inclusion. Add real linked-worktree regression tests: a treehouse-leased LINKED secondmate home is guarded, a stray/empty marker stays exempt, and the unmarked child worktree stays exempt - the topology the plain git-init fixtures masked. Predicates, in-flight gate, and loop guard untouched. * fix: force ASCII collation in secondmate marker validation Add a function-scoped local LC_ALL=C in fm_root_is_secondmate_home so the [A-Za-z0-9._-] id allowlist matches under C collation, not the ambient locale - a locale-crafted non-ASCII marker id can no longer slip through the range match and spoof force-inclusion of a linked child worktree. Add a regression test proving a non-ASCII marker id is rejected and the linked worktree stays exempt. * no-mistakes(test): fix backend baseline gate-refusal dependency * no-mistakes(document): Correct secondmate turn-end guard documentation * fix: make bootstrap diagnostics backend-aware (kunchenguid#519) * fix: make bootstrap required-tool detection backend-aware Bootstrap demanded tmux and treehouse for every backend except orca, so a herdr/zellij/cmux home with tmux absent was wrongly told MISSING: tmux. Required tools now follow the resolved backend via the single-owner fm_backend_required_tools helper (bin/fm-backend.sh): each backend's own session-provider CLI, jq for the JSON-emitting adapters (herdr/zellij/cmux), and treehouse for session-provider-only backends (orca owns its worktree). The treehouse lease-support check is gated to backends that use treehouse. Adds install hints for herdr/zellij/cmux, regression tests for the full backend dependency matrix (herdr-without-tmux repro plus each boundary), and updates the authoritative Toolchain docs. * no-mistakes(review): Captain, prevent executing Herdr install guidance * no-mistakes(review): Captain, harden backend-aware bootstrap diagnostics * no-mistakes(review): Captain, separate manual dependency remediation * no-mistakes(review): Captain, align bootstrap diagnostic consumers * no-mistakes(document): Align backend adapter dependency comments * fix: preserve follow-up platform context after inbox cleanup (kunchenguid#520) * fix: recover X/Discord follow-up platform after inbox cleanup A milestone follow-up posted directly by request_id after the inbox was drained - and with no task link, because one persistent secondmate's single x_request slot collides across concurrent requests - resolved platform only from the local inbox, so a >280 Discord reply silently defaulted to the X 280-char budget and threaded as (1/2). - fm-x-poll records a durable per-request reply context (state/x-context/<rid>.json) at stash time, keyed by request_id so concurrent requests never overwrite each other; it survives inbox cleanup and restart. - fm-x-reply resolves platform/budget through registry -> inbox -> relay (the relay lookup confined to a live follow-up), recovering the original platform independent of task-link availability. - Fail-safe: a follow-up whose platform/budget cannot be authoritatively resolved and that would split is refused (exit 8) and held for retry, never wrongly split; fm-x-followup keeps the link on that exit. - fm-x-dismiss clears the durable context for a dismissed mention. Refactors reply-context extraction into a single owner and adds regression coverage for all four cases. * no-mistakes(review): Captain, fail closed on incomplete follow-up context * no-mistakes(review): Captain, bound X context registry retention * no-mistakes(review): Captain, align context retention with answer binding * no-mistakes(document): Align X follow-up context documentation * no-mistakes(document): Align durable X follow-up documentation * fix: preserve secondmate routing markers in terminal sends (kunchenguid#533) * fix: preserve secondmate routing markers * no-mistakes(review): Captain, preserve trailing newlines in marked secondmate sends * no-mistakes(test): Captain, tolerate bootstrap timeout elapsed drift * no-mistakes(document): Refresh Herdr marker documentation * fix: align Grok effort handling with 0.2.99 (kunchenguid#527) * fix: align grok effort docs and spawn with 0.2.99 ceiling grok 0.2.99 accepts only low|medium|high for --reasoning-effort and rejects both xhigh and max. Omit unsupported values on spawn, flag them in crew-dispatch validation, and update harness-adapters. * no-mistakes(test): Captain: refresh gotmp teardown fixture dependencies * no-mistakes(document): Clarify Grok effort documentation ownership * fix: preserve declared pauses across watcher restarts * no-mistakes(review): Preserve unknown-state stale wake safety * no-mistakes(test): Stabilize PR review diffs --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> * fix(herdr): distinguish submitted codex redraws * no-mistakes(review): Harden Herdr submit and nested inbox detection * no-mistakes(review): Harden Herdr confirmation and Codex activation * no-mistakes(review): Track all operations inbox events * no-mistakes(review): Captain: harden activation and bound inbox polling * no-mistakes(review): Captain: harden activation, cleanup, and inbox markers * no-mistakes(review): Harden activation and bound inbox scans * no-mistakes(review): Prevent capped inbox runners resetting deadlines * no-mistakes(review): Harden submit verification and cleanup recovery * no-mistakes(test): Preserve pause recheck grace * no-mistakes(document): Document operations-inbox scan bounds * no-mistakes(lint): Remove unused Herdr scan variable * test(orca): align abort cleanup fixture * no-mistakes(review): Fix Codex home cleanup identity arguments * no-mistakes(review): Harden failed-spawn cleanup safety * no-mistakes(review): Harden cleanup safety, captain * no-mistakes(review): Fail closed unknown Herdr preflight * no-mistakes(test): Fix teardown patch equivalence and OpenCode lock race * no-mistakes(test): Captain: align teardown tests with lock preflight * no-mistakes(document): Document submit and failed-spawn safeguards * fix(teardown): honor checkout default branch * no-mistakes(review): Harden teardown and inbox fingerprinting * no-mistakes(review): Bound ops inbox fingerprint scans * no-mistakes(review): Harden spawn cleanup and inbox overflow detection * no-mistakes(review): Stabilize overflowed inbox fingerprints * no-mistakes(review): Harden leased spawn cleanup and watcher reaping * no-mistakes(review): Captain: harden treehouse lease cleanup validation * no-mistakes(review): Guard treehouse leases against active worktree collisions * no-mistakes(test): Update spawn test fakes for verified treehouse leases * no-mistakes(document): Document strict spawn isolation and watcher timeout reaping * test(orca): preserve fixture default branch * no-mistakes(review): Captain: fail closed on unconfirmed submits * no-mistakes(review): Require confirmed Orca terminal absence before teardown * no-mistakes(review): Preserve Orca resources without terminal confirmation * no-mistakes(review): Captain: Preserve leases pending endpoint confirmation * no-mistakes(review): Preserve confirmed Orca terminal absence * no-mistakes(review): Honor confirmed Orca terminal absence * no-mistakes(review): Harden fm-send and Orca cleanup * no-mistakes(review): Harden backend agent liveness and Orca recovery * no-mistakes(review): Fail closed without native backend liveness * no-mistakes(review): Captain: harden explicit target liveness * no-mistakes(test): Fix fm-send test liveness fixtures * no-mistakes(test): Preserve endpoints on failed worktree cleanup * no-mistakes(test): Return lease before failed Codex activation cleanup * no-mistakes(document): Document fail-closed steering and teardown safety * no-mistakes(review): Fail closed on unverified Python liveness * fix(orca): retain abort cleanup state * fix(orca): preserve abort cleanup safety * test(send): model a live tmux agent * test(codex): keep activation fixture alive * fix(teardown): check locks before safety approval --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me>
quinnbot-ai
added a commit
that referenced
this pull request
Jul 21, 2026
…d guard (#16) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: fetch current PR head for review diffs (kunchenguid#722) * fix: always fetch PR head for review diffs Prefer a freshly fetched refs/pull/<n>/head over a reachable recorded pr_head= so reviewers never hold a merge over a "missing" fix that already landed on the remote PR. Recorded SHA is offline fallback only; local branch is last resort with a warning. Store the tip under refs/fm-review/ so a later base-branch fetch cannot clobber the compare tip via FETCH_HEAD. * no-mistakes(test): Isolate session-start nudge tests from gate state * no-mistakes(document): Correct review-diff documentation * docs: resolve five contract contradictions across AGENTS.md, README, and skills (kunchenguid#736) * docs: resolve five contract contradictions * no-mistakes(test): align owner-pointer assertions with reworded docs; skip absent shellcheck * docs(harness): correct Grok exit guidance (kunchenguid#742) * docs(harness): reverify grok exit command * no-mistakes(test): Correct Grok exit resume attribution * fix(watcher): bound stale wakes for parked crew (kunchenguid#743) * fix(watcher): bound stale wakes for exited paused crew * no-mistakes(review): Gate pause suppression on confirmed agent death * no-mistakes(test): Fixed stale pause cadence * no-mistakes(document): Document dead-agent hold cadence * fix: harden watcher arm relay leases * no-mistakes(review): Harden relay leases and cleanup identity * no-mistakes(review): Harden tmux ownership and review remote selection * no-mistakes(review): Harden watcher relay and tmux recovery safety * fix(supervision): distinguish ordinary wakes from recovery (kunchenguid#744) * fix(supervision): distinguish ordinary wakes from repair * no-mistakes(review): Make passive guard follow-ups recovery-only * no-mistakes(document): Clarify recovery-only turn-end guard documentation * fix(x-mode): dedupe pending mention wakes (kunchenguid#745) * fix(x-mode): dedupe pending mention wakes * no-mistakes(review): fix x-poll claim error deduplication * no-mistakes(review): separate claim diagnostics from relay recovery * no-mistakes(document): Document X-mode once-only mention wakes * no-mistakes(test): Fix strict target-validation test fixtures * no-mistakes(document): Document relay lease hardening * no-mistakes(lint): Fix relay lease lint warnings * fix: reject symlinked Codex roots before spawn metadata * fix: reject symlinked Codex root before metadata * no-mistakes(review): Harden relay leases and normalize PR remotes * feat(wake): enrich drained signals with bounded status context (kunchenguid#747) * feat(wake): enrich drained signal context * no-mistakes(review): Bound wake enrichment reads * no-mistakes(document): Document wake-drain annotations * docs(wake): explain at-least-once drain boundary * no-mistakes(review): Prevent symlink races in wake annotations * no-mistakes(review): Exercise wake symlink race regression * test: document intentional AFK marker subprocesses * fix(wake): isolate annotation marker state * no-mistakes(test): Fix malformed tangle guard test fixtures * no-mistakes(document): Document watcher and daemon lease lifecycle * fix: preserve pre-metadata spawn refusal * no-mistakes(test): Preserve failed lease metadata and attached arm lifecycle logs * no-mistakes(review): Fix shared PR review fetch ref * no-mistakes(review): Harden daemon lease ownership handoff * no-mistakes(review): Harden stale daemon lease recovery and arm tick validation * no-mistakes(review): Fence stale AFK lease recovery * no-mistakes(review): Fence watcher identity lease publication * no-mistakes(review): Guard reclaimed AFK launcher locks * no-mistakes(review): Harden relay and launcher lease races * no-mistakes(document): Document daemon lease recovery grace * no-mistakes(lint): Isolate lease test helper shells * fix: harden watcher arm relay leases * no-mistakes(review): Harden relay leases and cleanup identity * no-mistakes(review): Harden tmux ownership and review remote selection * no-mistakes(review): Harden watcher relay and tmux recovery safety * no-mistakes(test): Fix strict target-validation test fixtures * no-mistakes(document): Document relay lease hardening * no-mistakes(lint): Fix relay lease lint warnings * fix: reject symlinked Codex roots before spawn metadata * fix: reject symlinked Codex root before metadata * no-mistakes(review): Harden relay leases and normalize PR remotes * no-mistakes(test): Fix malformed tangle guard test fixtures * no-mistakes(document): Document watcher and daemon lease lifecycle * fix: preserve pre-metadata spawn refusal * no-mistakes(test): Preserve failed lease metadata and attached arm lifecycle logs * no-mistakes(review): Fix shared PR review fetch ref * no-mistakes(review): Harden daemon lease ownership handoff * no-mistakes(review): Harden stale daemon lease recovery and arm tick validation * no-mistakes(review): Fence stale AFK lease recovery * no-mistakes(review): Fence watcher identity lease publication * docs: retain wake drain annotations * fix: preserve spawn refusal metadata boundary * fix: retain prepublication spawn rollback * test: model stable tmux endpoint cleanup * fix: retain prelaunch endpoint recovery state * feat(herdr): add optional presentation spaces (kunchenguid#784) * feat(herdr): add optional presentation spaces * no-mistakes(review): Harden Herdr projection creation and spawn serialization * no-mistakes(review): Captain, disarm Herdr cleanup before launch submission * no-mistakes(test): Correct stale Orca metadata failure fixture * no-mistakes(document): Document Herdr presentation projection accurately * fix: preserve watcher lease handoffs * fix(spawn): isolated CODEX_HOME for crewmate codex spawns (#3) * fix: isolate Codex crewmate MCP config * no-mistakes(review): Harden Codex home cleanup failures * no-mistakes(review): Harden isolated Codex crewmate launches * fix: scope Codex trust to worktree * no-mistakes(review): Harden Codex crewmate launch isolation * no-mistakes(review): Record failed Codex endpoint cleanup * no-mistakes(review): Harden case-insensitive Codex launch isolation * no-mistakes(review): Harden Codex raw launch isolation * no-mistakes(review): Harden Codex spawn isolation * no-mistakes(review): Harden Codex launch isolation cleanup * no-mistakes(review): Harden Codex wrappers and Orca cleanup metadata * no-mistakes(review): Harden Codex isolation and cleanup * no-mistakes(review): Captain: Harden Codex spawn isolation * no-mistakes(review): Harden Codex launch isolation * no-mistakes(review): Captain: Harden Codex launch isolation * no-mistakes(review): Captain: harden Codex activation and backend cleanup * no-mistakes(review): Harden Codex launch isolation * no-mistakes(review): Captain: preserve raw custom shell launches * no-mistakes(review): Harden Codex isolation and Zellij cleanup * no-mistakes(review): Confirm strict Zellij cleanup closures * no-mistakes(review): Harden Codex activation result isolation * no-mistakes(review): Harden Codex launch isolation * fix: harden failed spawn teardown * fix: harden Codex launch cleanup * no-mistakes(review): Harden indirect Codex launch isolation * no-mistakes(review): Harden Codex activation and builtin dispatch * no-mistakes(review): Harden Orca cleanup and raw launch parsing * no-mistakes(review): Confirm Orca terminal absence before cleanup * no-mistakes(test): Disable external review diff drivers * no-mistakes(test): Fix spawn isolation test fixture * no-mistakes(review): Respect explicit CODEX_HOME overrides * no-mistakes(document): Document Codex crewmate isolation * no-mistakes(lint): Fix ShellCheck lint diagnostics --------- Co-authored-by: QuinnBot <quinnbot@proton.me> * fix: isolate review diffs and Herdr prompt parsing (#2) * fix(watcher): preserve coalesced pause tracking * no-mistakes(review): Preserve immediate gone-worker wake detection * no-mistakes(review): Preserve pause-only signal handoffs * no-mistakes(test): Fix C-locale Herdr composer detection * no-mistakes(document): Document coalesced pause recovery --------- Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> * feat: surface operations inbox events in session start and watcher wakes (#4) * feat: surface operations inbox events * no-mistakes(review): Harden ops inbox polling * no-mistakes(review): Bound operations inbox polling * no-mistakes(review): Harden operations inbox polling * no-mistakes(review): Harden operations inbox polling * no-mistakes(review): Captain: bound ops inbox marker traversal * no-mistakes(review): Bound escaped operations inbox command capture * no-mistakes(document): Document operations-inbox controls * test: align ops inbox digest baseline * fix: keep watcher dependencies fork-local * fix: keep ops inbox signal output clean --------- Co-authored-by: QuinnBot <quinnbot@proton.me> * fix(watcher): preserve coalesced pause handoffs * fix(spawn): restore isolated Codex homes * fix(spawn): resolve isolated CODEX_HOME to a real path for macOS (#6) * fix(spawn): resolve isolated CODEX_HOME to a real path for macOS * test(spawn): assert real-path CODEX_HOME activation contract * style: apply formatter pass to fm-codex-home.py --------- Co-authored-by: QuinnBot <quinnbot@proton.me> * Fix teardown landed-work safeguards (#7) * Fix teardown landed-work safeguards * no-mistakes(review): Harden teardown landing safeguards * no-mistakes(review): Harden teardown cleanup safety * no-mistakes(review): Captain: harden Orca spawn cleanup * no-mistakes(review): Captain: harden cleanup safety * no-mistakes(review): Fix cmux cross-window task discovery * no-mistakes(review): Harden teardown ownership and legacy cleanup * no-mistakes(test): Fix teardown lock and endpoint cleanup * no-mistakes(test): Fix Herdr composer detection under C locale * no-mistakes(document): Document teardown containment safeguards --------- Co-authored-by: QuinnBot <quinnbot@proton.me> * test: cover legacy teardown task temp paths (#8) Co-authored-by: QuinnBot <quinnbot@proton.me> * fix: absorb declared pauses at parked gates (#9) * fix: absorb declared pauses at parked gates * no-mistakes(document): Document parked-gate pause handling --------- Co-authored-by: QuinnBot <quinnbot@proton.me> * fix(spawn): pin worktree-local git identity with Epstein boundary (#14) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: fetch current PR head for review diffs (kunchenguid#722) * fix: always fetch PR head for review diffs Prefer a freshly fetched refs/pull/<n>/head over a reachable recorded pr_head= so reviewers never hold a merge over a "missing" fix that already landed on the remote PR. Recorded SHA is offline fallback only; local branch is last resort with a warning. Store the tip under refs/fm-review/ so a later base-branch fetch cannot clobber the compare tip via FETCH_HEAD. * no-mistakes(test): Isolate session-start nudge tests from gate state * no-mistakes(document): Correct review-diff documentation * Pin crew worktree git identities * no-mistakes(review): Captain: retry shared Git config initialization * no-mistakes(review): Normalize worktree config boolean handling * no-mistakes(test): Captain, isolate review diffs from external renderers * no-mistakes(lint): Silence unused retry loop variable * no-mistakes(lint): Remove unused ShellCheck local * test: align secondmate charter assertion --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * feat(watch): escalate busy-looking zero-progress crews (#12) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: fetch current PR head for review diffs (kunchenguid#722) * fix: always fetch PR head for review diffs Prefer a freshly fetched refs/pull/<n>/head over a reachable recorded pr_head= so reviewers never hold a merge over a "missing" fix that already landed on the remote PR. Recorded SHA is offline fallback only; local branch is last resort with a warning. Store the tip under refs/fm-review/ so a later base-branch fetch cannot clobber the compare tip via FETCH_HEAD. * no-mistakes(test): Isolate session-start nudge tests from gate state * no-mistakes(document): Correct review-diff documentation * Escalate busy crews with no progress * no-mistakes(review): Captain: escalate AFK busy-progress wedges * no-mistakes(review): Scope pane progress parsing to current footer * no-mistakes(review): Captain: Harden busy-progress watcher safeguards * no-mistakes(review): Captain: clear teardown busy-progress state * no-mistakes(review): Harden busy-progress marker recovery * fix: cache watcher busy state * test: bound watcher cache cleanup * no-mistakes(test): Captain: stabilize tmux smoke and review diffs * no-mistakes(test): Captain: fix Herdr UTF-8 prompt classification * no-mistakes(test): Captain: fix transient Herdr worktree detection * no-mistakes(test): Fix checkpoint cleanup and spawn isolation * no-mistakes(document): Document busy-progress watcher escalation * test(brief): restore portable charter assertion --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * fix(spawn): durable worktree leases prevent held-slot reallocation (#13) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: fetch current PR head for review diffs (kunchenguid#722) * fix: always fetch PR head for review diffs Prefer a freshly fetched refs/pull/<n>/head over a reachable recorded pr_head= so reviewers never hold a merge over a "missing" fix that already landed on the remote PR. Recorded SHA is offline fallback only; local branch is last resort with a warning. Store the tip under refs/fm-review/ so a later base-branch fetch cannot clobber the compare tip via FETCH_HEAD. * no-mistakes(test): Isolate session-start nudge tests from gate state * no-mistakes(document): Correct review-diff documentation * fix: hold treehouse worktrees until teardown * no-mistakes(review): rollback treehouse leases on spawn failures * no-mistakes(review): recover stranded treehouse lease handoffs * no-mistakes(review): Harden treehouse lease recovery * fix: serialize treehouse lease handoffs * fix: harden treehouse lease cleanup * no-mistakes(review): Tombstone returned treehouse lease handoffs * fix: harden treehouse teardown handoffs * fix: ignore transient lease handoffs * no-mistakes(test): Fix lease-aware test fixtures * no-mistakes(test): Fix locale-safe composer and watcher races * no-mistakes(test): Close AFK launcher signal race * no-mistakes(document): Document durable treehouse task leases * fix: preserve Orca abort cleanup through activation * fix: retain fork charter portability updates * test: model leased treehouse allocations in identity fixture * fix: close failed spawn endpoint before lease return * fix: retain committed lease on activation failure * fix: retain recovery metadata after lease commit * test: match durable lease handoff format * test: retain committed lease after endpoint closure * test: model absent endpoint in spawn abort fixture * test: initialize fixture repositories on main * fix: preserve durable returned lease tombstones * fix: make leased spawn setup failures deterministic * test: forward task temp failure injection * ci: trace tangle guard hang * test: make lease setup failure injection deterministic * ci: allow bounded watcher lifecycle tests to finish --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * fix(spawn): tolerate transient cwd reads and clean up refused spawns (#15) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * docs: resolve five contract contradictions across AGENTS.md, README, and skills (kunchenguid#736) * docs: resolve five contract contradictions * no-mistakes(test): align owner-pointer assertions with reworded docs; skip absent shellcheck * docs(harness): correct Grok exit guidance (kunchenguid#742) * docs(harness): reverify grok exit command * no-mistakes(test): Correct Grok exit resume attribution * fix(spawn): tolerate transient worktree cwd * no-mistakes(review): Guard leased worktree CWD resolution * no-mistakes(test): Captain: synchronize secondmate charter role assertion * no-mistakes(test): Stabilize Herdr heartbeat test waits * no-mistakes(document): Document spawn isolation safeguards * test: include lease helper in teardown fixture --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Israel Wilson <31997700+ICGNU3@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * Fix fail-closed fm-send delivery verification (#17) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: durable pause recognition across watcher restarts (#1) * fix: prevent no-mistakes gate agents from driving the fleet (kunchenguid#518) * feat: contain no-mistakes gate agents from driving the fleet Add bin/fm-gate-refuse-lib.sh, sourced at the top of fm-spawn/fm-send/ fm-teardown before any fleet mutation. It fails closed when NO_MISTAKES_GATE is set, and via an unspoofable git-common-dir backstop when invoked from a no-mistakes gate worktree (.no-mistakes/repos/*.git) even with the marker unset. A normal firstmate session has neither signal and is unaffected. Set disable_project_settings: true in the tracked .no-mistakes.yaml so the installed pipeline neutralizes gate agents' project instructions for this repo (trusted-only, honored from the default branch). firstmate's own suite runs from a gate worktree during validation, so the shared test helpers set FM_GATE_REFUSE_BYPASS=1 to exempt it; the dedicated tests/fm-gate-refuse.test.sh strips it to verify real refusal. * no-mistakes(review): Captain, refuse empty no-mistakes gate markers * no-mistakes(document): Document no-mistakes gate authority boundary * fix: guard secondmate primary sessions from blind turn ends (kunchenguid#505) * fix: guard secondmate own-home turn ends Remove the .fm-secondmate-home early-exit in fm-turnend-guard.sh so the 'no turn ends blind' backstop fires in a secondmate's own primary session, matching the cd-guard's scope: the own home is guarded, child crew/scout worktrees stay exempt via the retained git-dir/git-common-dir test. This was pure scoping from the guard's primary-only origin and guarded against no secondmate-specific hazard. Add secondmate regression tests (blind-turn block, idle-by-default, stop_hook_active loop guard, deferred-death recovery loop, child-worktree exemption) and record the autonomous background-notify re-invoke measurement (Claude Code 2.1.207, 11s) in docs/turnend-guard.md. * no-mistakes(document): Correct secondmate guard documentation, captain * fix: force-include marked secondmate homes in turn-end guard The prior remove-only form (just deleting the .fm-secondmate-home check) left the DEFAULT secondmate topology unguarded: a treehouse-leased home is a linked git worktree (git-dir != git-common-dir), which the retained git-dir exemption still skipped, so its own primary session could still end a turn blind. Invert the marker: a genuinely-marked home is force-included as a guarded primary (treehouse-leased linked OR git-cloned plain), and the git-dir exemption applies only to UNMARKED child worktrees. Marker validation (regular non-symlink file, non-empty id-token content) blocks a stray or empty marker from spoofing inclusion. Add real linked-worktree regression tests: a treehouse-leased LINKED secondmate home is guarded, a stray/empty marker stays exempt, and the unmarked child worktree stays exempt - the topology the plain git-init fixtures masked. Predicates, in-flight gate, and loop guard untouched. * fix: force ASCII collation in secondmate marker validation Add a function-scoped local LC_ALL=C in fm_root_is_secondmate_home so the [A-Za-z0-9._-] id allowlist matches under C collation, not the ambient locale - a locale-crafted non-ASCII marker id can no longer slip through the range match and spoof force-inclusion of a linked child worktree. Add a regression test proving a non-ASCII marker id is rejected and the linked worktree stays exempt. * no-mistakes(test): fix backend baseline gate-refusal dependency * no-mistakes(document): Correct secondmate turn-end guard documentation * fix: make bootstrap diagnostics backend-aware (kunchenguid#519) * fix: make bootstrap required-tool detection backend-aware Bootstrap demanded tmux and treehouse for every backend except orca, so a herdr/zellij/cmux home with tmux absent was wrongly told MISSING: tmux. Required tools now follow the resolved backend via the single-owner fm_backend_required_tools helper (bin/fm-backend.sh): each backend's own session-provider CLI, jq for the JSON-emitting adapters (herdr/zellij/cmux), and treehouse for session-provider-only backends (orca owns its worktree). The treehouse lease-support check is gated to backends that use treehouse. Adds install hints for herdr/zellij/cmux, regression tests for the full backend dependency matrix (herdr-without-tmux repro plus each boundary), and updates the authoritative Toolchain docs. * no-mistakes(review): Captain, prevent executing Herdr install guidance * no-mistakes(review): Captain, harden backend-aware bootstrap diagnostics * no-mistakes(review): Captain, separate manual dependency remediation * no-mistakes(review): Captain, align bootstrap diagnostic consumers * no-mistakes(document): Align backend adapter dependency comments * fix: preserve follow-up platform context after inbox cleanup (kunchenguid#520) * fix: recover X/Discord follow-up platform after inbox cleanup A milestone follow-up posted directly by request_id after the inbox was drained - and with no task link, because one persistent secondmate's single x_request slot collides across concurrent requests - resolved platform only from the local inbox, so a >280 Discord reply silently defaulted to the X 280-char budget and threaded as (1/2). - fm-x-poll records a durable per-request reply context (state/x-context/<rid>.json) at stash time, keyed by request_id so concurrent requests never overwrite each other; it survives inbox cleanup and restart. - fm-x-reply resolves platform/budget through registry -> inbox -> relay (the relay lookup confined to a live follow-up), recovering the original platform independent of task-link availability. - Fail-safe: a follow-up whose platform/budget cannot be authoritatively resolved and that would split is refused (exit 8) and held for retry, never wrongly split; fm-x-followup keeps the link on that exit. - fm-x-dismiss clears the durable context for a dismissed mention. Refactors reply-context extraction into a single owner and adds regression coverage for all four cases. * no-mistakes(review): Captain, fail closed on incomplete follow-up context * no-mistakes(review): Captain, bound X context registry retention * no-mistakes(review): Captain, align context retention with answer binding * no-mistakes(document): Align X follow-up context documentation * no-mistakes(document): Align durable X follow-up documentation * fix: preserve secondmate routing markers in terminal sends (kunchenguid#533) * fix: preserve secondmate routing markers * no-mistakes(review): Captain, preserve trailing newlines in marked secondmate sends * no-mistakes(test): Captain, tolerate bootstrap timeout elapsed drift * no-mistakes(document): Refresh Herdr marker documentation * fix: align Grok effort handling with 0.2.99 (kunchenguid#527) * fix: align grok effort docs and spawn with 0.2.99 ceiling grok 0.2.99 accepts only low|medium|high for --reasoning-effort and rejects both xhigh and max. Omit unsupported values on spawn, flag them in crew-dispatch validation, and update harness-adapters. * no-mistakes(test): Captain: refresh gotmp teardown fixture dependencies * no-mistakes(document): Clarify Grok effort documentation ownership * fix: preserve declared pauses across watcher restarts * no-mistakes(review): Preserve unknown-state stale wake safety * no-mistakes(test): Stabilize PR review diffs --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> * fix(herdr): distinguish submitted codex redraws * no-mistakes(review): Harden Herdr submit and nested inbox detection * no-mistakes(review): Harden Herdr confirmation and Codex activation * no-mistakes(review): Track all operations inbox events * no-mistakes(review): Captain: harden activation and bound inbox polling * no-mistakes(review): Captain: harden activation, cleanup, and inbox markers * no-mistakes(review): Harden activation and bound inbox scans * no-mistakes(review): Prevent capped inbox runners resetting deadlines * no-mistakes(review): Harden submit verification and cleanup recovery * no-mistakes(test): Preserve pause recheck grace * no-mistakes(document): Document operations-inbox scan bounds * no-mistakes(lint): Remove unused Herdr scan variable * test(orca): align abort cleanup fixture * no-mistakes(review): Fix Codex home cleanup identity arguments * no-mistakes(review): Harden failed-spawn cleanup safety * no-mistakes(review): Harden cleanup safety, captain * no-mistakes(review): Fail closed unknown Herdr preflight * no-mistakes(test): Fix teardown patch equivalence and OpenCode lock race * no-mistakes(test): Captain: align teardown tests with lock preflight * no-mistakes(document): Document submit and failed-spawn safeguards * fix(teardown): honor checkout default branch * no-mistakes(review): Harden teardown and inbox fingerprinting * no-mistakes(review): Bound ops inbox fingerprint scans * no-mistakes(review): Harden spawn cleanup and inbox overflow detection * no-mistakes(review): Stabilize overflowed inbox fingerprints * no-mistakes(review): Harden leased spawn cleanup and watcher reaping * no-mistakes(review): Captain: harden treehouse lease cleanup validation * no-mistakes(review): Guard treehouse leases against active worktree collisions * no-mistakes(test): Update spawn test fakes for verified treehouse leases * no-mistakes(document): Document strict spawn isolation and watcher timeout reaping * test(orca): preserve fixture default branch * no-mistakes(review): Captain: fail closed on unconfirmed submits * no-mistakes(review): Require confirmed Orca terminal absence before teardown * no-mistakes(review): Preserve Orca resources without terminal confirmation * no-mistakes(review): Captain: Preserve leases pending endpoint confirmation * no-mistakes(review): Preserve confirmed Orca terminal absence * no-mistakes(review): Honor confirmed Orca terminal absence * no-mistakes(review): Harden fm-send and Orca cleanup * no-mistakes(review): Harden backend agent liveness and Orca recovery * no-mistakes(review): Fail closed without native backend liveness * no-mistakes(review): Captain: harden explicit target liveness * no-mistakes(test): Fix fm-send test liveness fixtures * no-mistakes(test): Preserve endpoints on failed worktree cleanup * no-mistakes(test): Return lease before failed Codex activation cleanup * no-mistakes(document): Document fail-closed steering and teardown safety * no-mistakes(review): Fail closed on unverified Python liveness * fix(orca): retain abort cleanup state * fix(orca): preserve abort cleanup safety * test(send): model a live tmux agent * test(codex): keep activation fixture alive * fix(teardown): check locks before safety approval --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * fix(watch): sync fork with upstream through 4ab61fa, fix pause-liveness merge regression (#18) * fix(bin): keep watcher supervision continuous across child cycles (kunchenguid#693) * fix: make watcher supervision continuous * no-mistakes(review): Bound watcher retries and log attached signals * no-mistakes(review): Add bounded successor-recovery wake fallbacks * no-mistakes(review): Prevent overlapping successor-arm retries * no-mistakes(review): Resume supervision after late arm closes * no-mistakes(review): Bind OpenCode recovery to attempted arm * no-mistakes(test): Synchronize peer beacon regression fixture * no-mistakes(test): Synchronize Pi and OpenCode late-close lifecycle fixtures * no-mistakes(document): Captain: document watcher successor protocol behavior * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * no-mistakes: apply CI fixes * fix: fetch current PR head for review diffs (kunchenguid#722) * fix: always fetch PR head for review diffs Prefer a freshly fetched refs/pull/<n>/head over a reachable recorded pr_head= so reviewers never hold a merge over a "missing" fix that already landed on the remote PR. Recorded SHA is offline fallback only; local branch is last resort with a warning. Store the tip under refs/fm-review/ so a later base-branch fetch cannot clobber the compare tip via FETCH_HEAD. * no-mistakes(test): Isolate session-start nudge tests from gate state * no-mistakes(document): Correct review-diff documentation * docs: resolve five contract contradictions across AGENTS.md, README, and skills (kunchenguid#736) * docs: resolve five contract contradictions * no-mistakes(test): align owner-pointer assertions with reworded docs; skip absent shellcheck * docs(harness): correct Grok exit guidance (kunchenguid#742) * docs(harness): reverify grok exit command * no-mistakes(test): Correct Grok exit resume attribution * fix(watcher): bound stale wakes for parked crew (kunchenguid#743) * fix(watcher): bound stale wakes for exited paused crew * no-mistakes(review): Gate pause suppression on confirmed agent death * no-mistakes(test): Fixed stale pause cadence * no-mistakes(document): Document dead-agent hold cadence * fix(supervision): distinguish ordinary wakes from recovery (kunchenguid#744) * fix(supervision): distinguish ordinary wakes from repair * no-mistakes(review): Make passive guard follow-ups recovery-only * no-mistakes(document): Clarify recovery-only turn-end guard documentation * fix(x-mode): dedupe pending mention wakes (kunchenguid#745) * fix(x-mode): dedupe pending mention wakes * no-mistakes(review): fix x-poll claim error deduplication * no-mistakes(review): separate claim diagnostics from relay recovery * no-mistakes(document): Document X-mode once-only mention wakes * feat(wake): enrich drained signals with bounded status context (kunchenguid#747) * feat(wake): enrich drained signal context * no-mistakes(review): Bound wake enrichment reads * no-mistakes(document): Document wake-drain annotations * docs(wake): explain at-least-once drain boundary * no-mistakes(review): Prevent symlink races in wake annotations * no-mistakes(review): Exercise wake symlink race regression * test: document intentional AFK marker subprocesses * fix(wake): isolate annotation marker state * fix(watch): resolve fork/upstream pause-liveness merge conflict; add divergence runbook The fork/upstream sync merge (67c79e2) combined pause_state_class's parked-gate override (fork-local) with the new exited-agent liveness gate (upstream) in a way that was syntactically clean but behaviorally wrong: any class=paused verdict, including a plain authoritative "state: paused" read, was silently downgraded to none whenever the agent wasn't CONFIRMED dead - even for "unknown" liveness, which must never license an action on its own. Split crew_absorb_class into a line-based classifier shared with pause_state_class so the parked-gate-override case can bypass the liveness gate entirely (an explicit declaration is authoritative) while a confirmed-live agent at a plain "paused" read still gets a fresh surface, and unknown liveness keeps trusting whatever classification already stood. Full fm-watch-triage suite (56 tests) now passes clean. Also adds docs/fm-main-divergence/runbook.md: the verified, exercised command sequence for hard-aligning the primary checkout's local main to fork/main once this branch merges, plus the audit proving no local-only content is at risk and a root-cause note on why /updatefirstmate's base_mode="origin" never pulls fork-only merges. * no-mistakes(review): Captain: refresh fork tracking refs * no-mistakes(review): Reclaim orphaned Treehouse handoff writer files * no-mistakes(review): Recover X-mode wakes * docs: fail closed on runbook fetches * no-mistakes(test): Captain: restore second mate charter role * no-mistakes(document): Document paused wake recovery --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Israel Wilson <31997700+ICGNU3@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> * fix: harden watcher arm relay leases * no-mistakes(review): Harden relay leases and cleanup identity * no-mistakes(review): Harden tmux ownership and review remote selection * no-mistakes(review): Harden watcher relay and tmux recovery safety * no-mistakes(test): Fix strict target-validation test fixtures * no-mistakes(document): Document relay lease hardening * no-mistakes(lint): Fix relay lease lint warnings * fix: reject symlinked Codex roots before spawn metadata * fix: reject symlinked Codex root before metadata * no-mistakes(review): Harden relay leases and normalize PR remotes * no-mistakes(test): Fix malformed tangle guard test fixtures * no-mistakes(document): Document watcher and daemon lease lifecycle * fix: preserve pre-metadata spawn refusal * no-mistakes(test): Preserve failed lease metadata and attached arm lifecycle logs * no-mistakes(review): Fix shared PR review fetch ref * no-mistakes(review): Harden daemon lease ownership handoff * no-mistakes(review): Harden stale daemon lease recovery and arm tick validation * no-mistakes(review): Fence stale AFK lease recovery * no-mistakes(review): Fence watcher identity lease publication * docs: retain wake drain annotations * fix: preserve spawn refusal metadata boundary * fix: retain prepublication spawn rollback * test: model stable tmux endpoint cleanup * fix: retain prelaunch endpoint recovery state * fix: preserve watcher lease handoffs * no-mistakes(review): Harden tmux ownership and review remote selection * no-mistakes(test): Fix strict target-validation test fixtures * no-mistakes(document): Document relay lease hardening * no-mistakes(test): Fix malformed tangle guard test fixtures * fix: preserve pre-metadata spawn refusal * no-mistakes(test): Preserve failed lease metadata and attached arm lifecycle logs * no-mistakes(review): Harden stale daemon lease recovery and arm tick validation * no-mistakes(review): Fence stale AFK lease recovery * no-mistakes(review): Guard reclaimed AFK launcher locks * no-mistakes(review): Harden relay and launcher lease races * no-mistakes(document): Document daemon lease recovery grace * no-mistakes(lint): Isolate lease test helper shells * no-mistakes(review): Publish lease before watcher binding * no-mistakes(test): Fix watcher and Herdr teardown regressions * no-mistakes(test): Fix watcher and Codex activation test fixtures * no-mistakes(test): Preserve paused recovery across watcher restarts * no-mistakes(test): Remove duplicate pause-liveness test invocation * no-mistakes(test): Fix attached arm lifecycle ledger race * no-mistakes(document): Document lease and Git identity helpers * no-mistakes(lint): Resolve ShellCheck warnings in lease regression tests * no-mistakes(review): Reclaim reused watcher locks during normal arm * no-mistakes(review): Fence watcher lock reclaim race * fix: fence watcher restart reclaim * no-mistakes(review): Fence arm lease release by owner PID * no-mistakes(document): Correct operations inbox and relay lease docs * no-mistakes(lint): Remove unused treehouse lease assignment * no-mistakes(lint): Captain: remove unused treehouse lease assignment * fix(spawn): preserve prepublication refusal boundary * test(spawn): model stable tmux cleanup identity * test(spawn): cover stable data-root refusal cleanup * test(spawn): cover stable abort cleanup paths * test(spawn): model stable isolation cleanup * fix(watch): surface attached relay handoff failures --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: Israel Wilson <31997700+ICGNU3@users.noreply.github.com> Co-authored-by: QuinnBot <quinnbot@proton.me> Co-authored-by: nickespo7-del <261696157+nickespo7-del@users.noreply.github.com> Co-authored-by: Korallis <lee.barry84@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes fm-send delivery verification so steering is refused unless the target is a confirmed live agent, preventing text from landing in a dead shell. Preserves Orca worktrees and Codex homes until terminal absence is confirmed, hardens failed-spawn/teardown recovery, maintains bounded ops-inbox observability, and keeps default-branch handling portable across main/master fixtures.
Validated locally by no-mistakes: review, behavior tests, documentation, and lint are green. The pipeline push completed; its PR creation step hit the known fork-target token gap. The Require no-mistakes check on this manually opened PR is expected to show the known false-red; rely on the real CI checks.