Skip to content

fix(watch): fence watcher arm and cycles to the session-lock owner - #56

Merged
quinnbot-ai merged 3 commits into
mainfrom
fm/supervision-session-owner-guard
Jul 28, 2026
Merged

quinnbot-ai merged 3 commits into
mainfrom
fm/supervision-session-owner-guard

Conversation

@quinnbot-ai

Copy link
Copy Markdown
Owner

Fences watcher arm and cycle ownership to the session-lock owner: stable process-identity token (PID-reuse safe), owner-check serialized with lock acquisition, ownership rechecked after successor waits. Closes the two-owner arm conflict that manufactured false watcher-failure alarms.

Validated by no-mistakes run 01KYMTCCDPBDMR48MK5W666MJ3 (review with three authorized concurrency corrections, tests, docs, lint, push all green); PR opened manually due to the fork-target token gap.

QuinnBot added 3 commits July 28, 2026 09:37
An orphaned watcher from a dead harness session retained the supervision
singleton (fresh beacon, held watch.lock) while a new harness session held
state/.lock, so completed-crewmate wakes were absorbed into a dead stdout
and the active session was never woken.

Add fm_session_owner_fence to bin/fm-session-lock-lib.sh, the one owner of
the may-this-process-supervise decision, and enforce it at watcher startup,
every watcher cycle, arm start, and every arm attach iteration. A live
foreign harness holding state/.lock fences supervision with a typed
watcher: FAILED line; no lock, a malformed lock, a dead or non-harness
holder, the owning session's own descendants, and away mode all pass, so
recovery arming, adapter arms, and the afk daemon are unchanged.

tests/fm-session-owner-fence.test.sh reproduces the cross-harness takeover
end to end and covers the refusal, restart, dead-owner, and afk paths.
@quinnbot-ai
quinnbot-ai merged commit 4d10def into main Jul 28, 2026
9 of 10 checks passed
quinnbot-ai added a commit that referenced this pull request Aug 10, 2026
* fix(watch): fence watcher arm and cycles to the session-lock owner

An orphaned watcher from a dead harness session retained the supervision
singleton (fresh beacon, held watch.lock) while a new harness session held
state/.lock, so completed-crewmate wakes were absorbed into a dead stdout
and the active session was never woken.

Add fm_session_owner_fence to bin/fm-session-lock-lib.sh, the one owner of
the may-this-process-supervise decision, and enforce it at watcher startup,
every watcher cycle, arm start, and every arm attach iteration. A live
foreign harness holding state/.lock fences supervision with a typed
watcher: FAILED line; no lock, a malformed lock, a dead or non-harness
holder, the owning session's own descendants, and away mode all pass, so
recovery arming, adapter arms, and the afk daemon are unchanged.

tests/fm-session-owner-fence.test.sh reproduces the cross-harness takeover
end to end and covers the refusal, restart, dead-owner, and afk paths.

* no-mistakes(review): Captain, harden session-owner fencing against handoff races

* no-mistakes(document): Document supervision session-owner fence

---------

Co-authored-by: QuinnBot <quinnbot@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant