Skip to content

fix(brief): give the ship-brief isolation assertion real path operands - #74

Merged
quinnbot-ai merged 6 commits into
mainfrom
fm/fm-isolation-assert-false-positive
Aug 2, 2026
Merged

quinnbot-ai merged 6 commits into
mainfrom
fm/fm-isolation-assert-false-positive

Conversation

@quinnbot-ai

Copy link
Copy Markdown
Owner

Implements the fix recommended by the fm-isolation-assert-false-positive scout report: the worktree-isolation assertion in generated ship briefs asked workers to compare against "the primary checkout" and "the worktree you were launched in" without ever stating either path, so a careful worker in a firstmate-repo task could only fail closed - a false refusal on a correctly isolated worker (observed 2026-07-26, task opsinbox-loop-integration).

  • bin/fm-brief.sh: assertion rewritten as a total, decidable rule with {FM_WORKTREE} and {FM_PRIMARY_CHECKOUT} placeholders; third-path and command-failure outcomes report the actual reading.
  • bin/fm-spawn.sh: substitutes both resolved paths after validate_spawn_worktree (including the Orca branch) and refuses to launch a ship brief that still carries either placeholder.
  • Safety preserved and strengthened: a worker genuinely in the primary checkout still stops, and wrong-worktree placement is now caught exactly instead of by judgment.

Validation: no-mistakes run 01KZ1VEFGD8270RTX1XEHVW4M1 green through review (one fix round accepted), test, document, lint, and push; PR step failed only on the known quinnbot-ai fine-grained PAT createPullRequest limitation, so this PR is opened by firstmate per standing practice. The "Require no-mistakes" check will show the known false-red for manually-opened PRs; merge authority per the recorded merge policy is CI green.

🤖 Generated with Claude Code

@quinnbot-ai quinnbot-ai closed this Aug 2, 2026
@quinnbot-ai quinnbot-ai reopened this Aug 2, 2026
QuinnBot added 5 commits August 2, 2026 12:52
The ship brief tells a worker to stop unless its top level is "the
disposable task worktree you were launched in" rather than "the primary
checkout firstmate operates from", and states neither path. Both operands
are unbound, and the rule's default on any failure to confirm is STOP, so
the check is a judgment call rather than a comparison. It refused a
correctly isolated worker in the live fleet: a firstmate-repo crewmate
reads the primary checkout's absolute path four times in its own brief and
its own worktree path nowhere, and git rev-parse --git-common-dir - the one
command that names another checkout - points at the primary checkout too.

fm-brief.sh now emits the two paths as {FM_WORKTREE} and
{FM_PRIMARY_CHECKOUT} isolation facts, and fm-spawn.sh fills them in from
the worktree it has already verified, on both the treehouse and Orca paths,
immediately after validate_spawn_worktree. The values are the physically
resolved paths because git rev-parse --show-toplevel always reports the
resolved one. The rewrite matches on the fact-line prefix rather than
swapping the placeholder once, so a relaunch into a different worktree
corrects a stale path instead of pinning the brief to the first slot it
used. A brief holding a placeholder the fill cannot reach refuses to
launch: a worker reading a literal {FM_WORKTREE} has no isolation check at
all. Briefs scaffolded before this contract carry neither placeholder nor
fact line and are left untouched, so in-flight tasks still relaunch.

The safety property is preserved and strengthened: a worker genuinely in
the primary checkout compares equal to a named path and stops, and a worker
in an unexpected third tree now reports what it actually read instead of
being pushed onto the same refusal.
The isolation-facts suite was written against a base without the
launch-delivery verification fm-spawn now performs, so its fake tmux
answered send-keys with a bare exit 0 and every spawn in the suite failed
with "launch command delivery could not be verified after 3 attempts".

Source the shared pane shell from tests/lib.sh and answer capture-pane and
send-keys through fm_fake_pane_capture and fm_fake_pane_send, the same owner
tests/fm-spawn-worktree-settle.test.sh uses. That owner executes the
submitted checksum against the bytes the pane actually accumulated, so this
suite exercises the real delivery contract instead of a local imitation that
could report success on corrupt staging.
@quinnbot-ai
quinnbot-ai force-pushed the fm/fm-isolation-assert-false-positive branch from 63a3e6e to c40d7e3 Compare August 2, 2026 19:57
The tangle guard pinned the literal sentence "The path check is
authoritative", which the isolation assertion no longer contains: the check
is now an exact comparison against two paths fm-spawn.sh fills in at launch,
rather than prose the crewmate has to interpret.

Assert the property instead of the removed phrasing - both operands present,
and the git-dir/common-dir output explicitly not evidence of being in the
primary checkout. That is strictly more than the old assertion checked,
since it now requires the operands the comparison needs, and it keeps the
existing guards against presenting the git-dir shortcut as decisive.
@quinnbot-ai
quinnbot-ai merged commit 8d76cbd into main Aug 2, 2026
10 of 11 checks passed
quinnbot-ai added a commit that referenced this pull request Aug 10, 2026
#74)

* fix(brief): give the worktree-isolation assertion real paths

The ship brief tells a worker to stop unless its top level is "the
disposable task worktree you were launched in" rather than "the primary
checkout firstmate operates from", and states neither path. Both operands
are unbound, and the rule's default on any failure to confirm is STOP, so
the check is a judgment call rather than a comparison. It refused a
correctly isolated worker in the live fleet: a firstmate-repo crewmate
reads the primary checkout's absolute path four times in its own brief and
its own worktree path nowhere, and git rev-parse --git-common-dir - the one
command that names another checkout - points at the primary checkout too.

fm-brief.sh now emits the two paths as {FM_WORKTREE} and
{FM_PRIMARY_CHECKOUT} isolation facts, and fm-spawn.sh fills them in from
the worktree it has already verified, on both the treehouse and Orca paths,
immediately after validate_spawn_worktree. The values are the physically
resolved paths because git rev-parse --show-toplevel always reports the
resolved one. The rewrite matches on the fact-line prefix rather than
swapping the placeholder once, so a relaunch into a different worktree
corrects a stale path instead of pinning the brief to the first slot it
used. A brief holding a placeholder the fill cannot reach refuses to
launch: a worker reading a literal {FM_WORKTREE} has no isolation check at
all. Briefs scaffolded before this contract carry neither placeholder nor
fact line and are left untouched, so in-flight tasks still relaunch.

The safety property is preserved and strengthened: a worker genuinely in
the primary checkout compares equal to a named path and stops, and a worker
in an unexpected third tree now reports what it actually read instead of
being pushed onto the same refusal.

* no-mistakes(review): Reject partial isolation fact blocks before spawn

* no-mistakes(document): Document named isolation operands

* chore: trigger CI

* test(spawn): drive isolation-facts spawns through the shared pane owner

The isolation-facts suite was written against a base without the
launch-delivery verification fm-spawn now performs, so its fake tmux
answered send-keys with a bare exit 0 and every spawn in the suite failed
with "launch command delivery could not be verified after 3 attempts".

Source the shared pane shell from tests/lib.sh and answer capture-pane and
send-keys through fm_fake_pane_capture and fm_fake_pane_send, the same owner
tests/fm-spawn-worktree-settle.test.sh uses. That owner executes the
submitted checksum against the bytes the pane actually accumulated, so this
suite exercises the real delivery contract instead of a local imitation that
could report success on corrupt staging.

* test(brief): guard the isolation assertion by its named operands

The tangle guard pinned the literal sentence "The path check is
authoritative", which the isolation assertion no longer contains: the check
is now an exact comparison against two paths fm-spawn.sh fills in at launch,
rather than prose the crewmate has to interpret.

Assert the property instead of the removed phrasing - both operands present,
and the git-dir/common-dir output explicitly not evidence of being in the
primary checkout. That is strictly more than the old assertion checked,
since it now requires the operands the comparison needs, and it keeps the
existing guards against presenting the git-dir shortcut as decisive.

---------

Co-authored-by: QuinnBot <quinnbot@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant