fix(bin): make supervision recovery owner-aware and durable - #5
Merged
tiago-peixoto merged 9 commits intoAug 15, 2026
Merged
Conversation
…ged wake recovery
…rd-starves-autoarm-fork # Conflicts: # AGENTS.md # bin/fm-claude-stop-autoarm.sh # bin/fm-guard.sh # bin/fm-turnend-guard.sh # bin/fm-wake-lib.sh # docs/architecture.md # docs/turnend-guard.md # docs/verification/supervision.md # tests/fm-turnend-guard.test.sh
tiago-peixoto
deleted the
fm/firstmate-stop-guard-starves-autoarm-fork
branch
September 5, 2026 18:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix the Claude primary-session supervision failure observed on 2026-08-14, where work was in flight, no watcher was live, and the turn-end guard could repeat forever while the Stop auto-arm did not claim recovery.
First add a durable, bounded, self-trimming, best-effort state trace that records every auto-arm entry and selected pre-claim gate without changing hook output, status, or failure behavior.
Reproduce only in a throwaway home with real Claude, let the evidence choose among sibling starvation, the foreign live session-lock owner gate, and discarded asyncRewake, and deliberately seek falsification: no entry on the blocked Stop would falsify the identity-gate diagnosis, while an owner claim without delivered Stop feedback would support discarded rewake.
The evidence showed the hook ran and took gate-live-session-owner, while lock-owner asyncRewake worked, so preserve the identity gate and its prevention of two sessions arming one home; do not weaken the guard, arm from the read-only session, reorder hooks, or teach the falsified short-circuit mechanism.
Align the guard with session ownership so the read-only competing session can finish and the lock-owning session remains the sole mutable supervision owner and restores supervision on its next Stop.
Add a portable real-process regression and an env-gated real-Claude live guard, and prove both RED against unfixed code and green after the fix.
After two genuinely identical guard blocks, terminate the exchange in exactly one captain-facing question, reset the identical-block count when evidence changes, and suppress repeated escalation.
Update the authoritative continuity, turn-end, operating-protocol, volatile-state, and dated verification records, including exact commands and output; keep the private learning corrected to the proven mechanism.
Require bin/fm-lint.sh and documentation checks to pass.
What Changed
Causal Evidence
event=entryfollowed byevent=gate-live-session-owner; an absent entry would have falsified the identity-gate diagnosis and supported sibling starvation.event=claimed, recordedoutcome=rewake, and delivered realStop hook feedback; a claim without that delivery would have supported the discarded-asyncRewake candidate.Risk Assessment
Testing
bin/fm-lint.shbin/fm-doc-audience-check.shbin/fm-test-run.sh tests/fm-claude-stop-autoarm.test.sh tests/fm-turnend-guard.test.sh tests/fm-supervision-instructions.test.sh tests/fm-guard-stale-banner.test.shFM_CLAUDE_LIVE_E2E=1 tests/fm-claude-stop-autoarm-live-e2e.test.shread-only Claude session was trapped by the blind-turn guard.Pipeline
Updates from git push no-mistakes
The no-mistakes run completed intent, review, targeted test, document, lint, and push validation.
Its original CI monitor was stopped only because GitHub opened the first PR against the fork parent instead of this repository; this replacement PR carries the same six validated supervision commits on a clean
origin/mainbase.