Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
869ae90
fix(bin): rebalance portable parallel test lanes using CI timings (#4…
mremond Sep 11, 2026
0a4e4a2
fix(bin): stop claiming prose-mentioned PR URLs as a task's delivered…
karotkriss Sep 11, 2026
8a61b50
fix(procevent): confirm reconcile launches and reclaim provably dead …
christophmeise Sep 11, 2026
e0d269e
fix(herdr): verify agent liveness at process level before trusting re…
pablontiv Sep 11, 2026
31f062d
feat: add live-head merge gates and away task grants (#4199)
kunchenguid Sep 11, 2026
9074f9d
fix(bin): bound the Claude turn-end re-block against a frozen auto-ar…
christophmeise Sep 11, 2026
ff5c7af
feat(herdr): add guarded foreground viewer for live validation (#4242)
kunchenguid Sep 11, 2026
dee156f
fix(bin): let nonvisual work proceed when lavish-axi is unavailable (…
tiago-peixoto Sep 11, 2026
eb0ea3a
test: isolate fixture Git config from host global and system settings…
tiago-peixoto Sep 11, 2026
2c1017e
feat(bin): add config/claude-permission-mode to launch Claude workers…
sreekarans Sep 11, 2026
7d14fc1
fix(teardown): leave a Treehouse pool slot reassigned to another task…
christophmeise Sep 11, 2026
9e1e85e
docs(AGENTS): keep brief-fill from widening the captain's ask (#4247)
kunchenguid Sep 11, 2026
46ff99c
fix: identify underway tasks and sort charted work (#4245)
kunchenguid Sep 11, 2026
ad14a8d
fix(bearings): surface return catch-up without blocking snapshots (#4…
kunchenguid Sep 12, 2026
a27646c
fix(bin): address the home's backlog from any directory and detect a …
Shazellb Sep 12, 2026
92856fd
fix: pre-register Claude trust for secondmate homes (#4262)
kunchenguid Sep 12, 2026
c191eac
fix: ignore superseded failed GitHub check runs (#4258)
kunchenguid Sep 12, 2026
de00521
fix(bin): persist merge authority for poll-detected outcomes (#4266)
kunchenguid Sep 12, 2026
83c63cc
ci: supersede superseded PR CI and bound unbounded jobs (#4281)
kunchenguid Sep 12, 2026
fa65b5d
test(watch): gate backlog-hold away-record fixture on tasks-axi (#4288)
cipherholdingsllc Sep 12, 2026
fb19dd9
fix(backlog): bound per-item backlog row reads so a wedged backend ca…
RooseveltAdvisors Sep 12, 2026
76d4405
fix(merge): serialize away authority with synchronous merges (#4285)
kunchenguid Sep 12, 2026
3576148
feat(bin): add Antigravity CLI (agy) as third worker/scout adapter (#…
AnPod Sep 12, 2026
b518a25
feat(afk): add quiet supervision mode for a present captain (#4337)
NewAiCoder-bot Sep 13, 2026
0962d4a
fix(bin): let verified harness ancestry outrank retained markers (#3)…
NewAiCoder Sep 13, 2026
305dfff
fix(bin): pre-approve external CLAUDE.md import dialog for spawned wo…
NewAiCoder-bot Sep 13, 2026
ecfe071
fix(afk-return): treat an acked watcher-down marker as no gap (#4355)
NewAiCoder-bot Sep 13, 2026
b182d0f
fix(bin): rebind fm-procevent-when trust bindings after a self-update…
NewAiCoder-bot Sep 13, 2026
6617379
Merge upstream Firstmate through b182d0f908b7
Sep 14, 2026
4107a18
fix(sync): bind expected policy exception to reviewed merge ancestry
Sep 14, 2026
f515d1e
fix(ci): overlap isolated tests and settle fixture maintenance
Sep 14, 2026
66da6fb
test(procevent): settle completed poll before retirement assertion
Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,10 @@ Hold-for-return is the default and the only reach profile this release records:
Write only clauses the words actually support; a wish with no object or no stated precondition is not a clause.
Plain `/afk` with no words has no clauses.
2. **Propose and read back.**
Run `bin/fm-afk-launch.sh propose --words-file <path> [--action <verb> --object <text> --when <text> [--stop <text>]]... [--expected-return <UTC ISO 8601>] [--spend <n>]` (or `--words <text>`), and relay its read-back to the captain in `AGENTS.md` section 9 language: the accepted clauses as a numbered list, every refused clause with the part it is missing, the expected return, the spend cap, and the one-sentence reach announcement.
Run `bin/fm-afk-launch.sh propose --words-file <path> [--action <verb> --object <text> --when <text> [--stop <text>]]... [--expected-return <UTC ISO 8601>] [--spend <n>] [--grant <task-id>]...` (or `--words <text>`), and relay its read-back to the captain in `AGENTS.md` section 9 language: the accepted clauses as a numbered list, every refused clause with the part it is missing, the expected return, the spend cap, any merge-when-green task ids, and the one-sentence reach announcement.
When the captain names task ids that may merge while green, pass `--grant <id>` for each named id.
Never infer task ids from clause prose, object text, or the away words.
Red-check exceptions stay in the words or clause `when` text and are not executed.
A refused clause does not fail the proposal; the captain can restate it or leave it refused.
Exit 3 only means a clause was refused; the proposal stands.
3. **Confirm on the captain's go.**
Expand Down Expand Up @@ -65,17 +68,23 @@ No `/back` is needed. The first genuine message is the return signal:
The gate keeps every open `blocked:` event until that blocker's own resolution is proven: remediate each immediately through the normal lifecycle, or explicitly reclassify it with a durable reason and close its decision key with `resolved [key=...]`, then run `bin/fm-afk-return.sh check`.
Captain-verdict outcomes are listed under "waiting on you", but do not exempt open blockers because per-blocker provenance is deferred to phase 4.
Once the record is archived, resume full per-wake responsiveness through the emitted primary-harness supervision protocol while blocker handling proceeds, so the gate never creates a blind wait.
Do not answer a Bearings request or perform any other ordinary captain work until the check exits successfully.
A Bearings request may be answered while the gate is open, and the digest surfaces the catch-up state as a Charted Next `(return-catchup)` warning row naming what still holds it.
Acting on the fleet - dispatching, steering, merging, or any other ordinary captain work - still waits until the check exits successfully.
- A message **with** the current operational prefix (`FM_OPERATIONAL_PREFIX`, U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), or a legacy bare `FM_INJECT_MARK` daemon escalation -> stay away and process it.
- Re-invoking `/afk` while already away -> stay away (refresh); this does **not** trigger an exit.

Bias ambiguous cases toward exit: a present captain beats token savings, and a false exit is self-correcting (the captain re-runs `/afk`).
When the captain wants this same token-saving supervision while staying present and chatting - ordinary messages should NOT exit it - that is `/quiet` (kunchenguid/firstmate#2356), not `/afk`.

## Orthogonal to approval authority

afk changes how the captain is informed and what happens at a captain-owned decision point, **not who approves what**.
"Away" never means "approves more" or "approves less."
A PR ready for merge keeps the merge authority from `AGENTS.md` section 7, and a needs-decision finding keeps the `ask-user-authority` policy; anything requiring the captain still waits for the captain's explicit word.
While the away-posture record exists, a merge proceeds only when that task's recorded yolo posture is on or its id is in the record's merge-grant list; otherwise it is held for the captain's return.
A merge grant never releases a captain hold, and it expires when the away record is archived.
`--allow-red` remains attended-only and is refused while the record exists.
A merge under away authority must be synchronous; `fm-pr-merge.sh` refuses auto-merge and any GitHub queue state that cannot prove an immediate merge while the record exists.
A mandate clause is the captain's explicit instruction given before leaving, recorded with its named object and condition; a clause is never inferred, never applied by analogy, and expires at return.
Forbidden, destructive, irreversible, and security-sensitive actions are never pre-authorizable regardless of clause text, and no recorded clause is authority by itself.
This release records clauses and does not execute them.
Expand Down
9 changes: 8 additions & 1 deletion .agents/skills/bearings/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,8 @@ Board answers are acted on later under the normal authority rules; this skill's
The `(main-inventory)` gate is an action-free integrity warning rather than queued work.
Render it under Charted Next with the related `omitted` disclosure, never invent an Underway row from backlog-only state, and never move it into Captain's Call.
The same holds for a secondmate home whose current state is unavailable, and for a readable home whose `invalidity` reports a backlog-vs-metadata mismatch: the mismatch is a repair notice about that home's own books, not a reason to drop its separately projected decisions, queued, landed, or live work.
The `(return-catchup)` gate is the same shape: an action-free notice that an away-return catch-up is still open, naming the blockers left to clear or the reason the catch-up was retained.
Render it under Charted Next like any other warning row: reporting is not ordinary work, while acting on the fleet still waits for `bin/fm-afk-return.sh check` (`/afk`).

2. **Record a later reconcile notification for any home whose own books disagree.**
When the snapshot reports a secondmate home whose `invalidity` is `orphan_in_flight`, `unowned_current`, or `terminal_in_flight`, that home's backlog and its own task metadata disagree and only that home may fix it.
Expand Down Expand Up @@ -99,8 +101,13 @@ Compose the payload from the same snapshot with the same ranking judgment as the
- Decision cards carry agent-authored copy: a short noun-phrase title, one-line `about` and `decide` context rows, and option labels with hints, with the recommended option marked.
- Card `type` (decision, merge, credential) is your composing judgment from the row's content; no backlog field types a card for you.
- When the card's task is a captain-gated WORK item (the answer should free it to proceed rather than complete it), set the card's `close: "release"` so the answer lifts the hold instead of closing the task; question-shaped items omit it.
- A Charted Next row's optional `kind` separates work from alarms: omit it (or set `"queued"`) for real queued work, and set `"warning"` on every action-free fleet-integrity notice - the `(main-inventory)` gate, an unavailable secondmate home, and an inventory-mismatch repair notice. The board badges a warning row `needs repair` instead of `waiting` and leaves it out of the Charted Next count, so those rows never read as dispatchable queued work.
- A Charted Next row's optional `kind` separates work from alarms: omit it (or set `"queued"`) for real queued work, and set `"warning"` on every action-free fleet-integrity notice - the `(main-inventory)` gate, the `(return-catchup)` gate, an unavailable secondmate home, and an inventory-mismatch repair notice. The board badges a warning row `needs repair` instead of `waiting` and leaves it out of the Charted Next count, so those rows never read as dispatchable queued work.
- `charted_more` counts omitted queued rows only, while `charted_warning_more` counts omitted warning rows only; keep both counts separate whenever the board payload truncates Charted Next.
- Every Underway row copies the task-identifying `in_flight.name` from the snapshot into an explicit `name` field, which the board leads with while keeping the run status on its second line.
The snapshot command's header owns its durable-title-or-id normalization; never replace the projected label with run status or invent another label.
- Every Charted Next row copies the snapshot gate's durable filed date into `filed`, and the board orders the section by it, newest filed first.
Follow `bin/fm-bearings-board.sh`'s payload contract for the accepted format.
Omit it or pass null for a row with no durable filed date - the main-inventory or return-catchup warning, an unavailable secondmate home, or a queued row filed before dates were recorded - and the board keeps those rows in payload order after every dated row.
- Every Captain's Call item and every Underway, Recently Landed, and Charted Next row carries an explicit `repo` field. Fill it from the snapshot and task records wherever known; use null or an empty string only as the deliberate genuinely-no-repo marker, in which case the template may show the internal id. Ids otherwise stay in the payload only as the routing channel, and composed reasons name blockers in plain words.

Run `build` once after composing the payload.
Expand Down
20 changes: 17 additions & 3 deletions .agents/skills/bearings/assets/board-template.html
Original file line number Diff line number Diff line change
Expand Up @@ -439,6 +439,17 @@
so every count of queued work excludes them. */
function isWarning(t) { return t && t.kind === "warning"; }
function chartedQueued(rows) { return (rows || []).filter(function (t) { return !isWarning(t); }); }
/* Charted Next reads newest filed first, so the most recently filed upcoming
work is at the top. ISO filed dates compare as text; a row with no
comparable date keeps its payload order after every dated row. */
function chartedOrder(rows) {
var dated = [], undated = [];
(rows || []).forEach(function (t) {
if (t && typeof t.filed === "string" && t.filed) dated.push(t); else undated.push(t);
});
dated.sort(function (a, b) { return a.filed < b.filed ? 1 : (a.filed > b.filed ? -1 : 0); });
return dated.concat(undated);
}
var chartedMoreQueued = data.charted_more || 0;
var chartedMoreWarnings = data.charted_warning_more || 0;
function utf8ByteLength(text) { return new TextEncoder().encode(text).length; }
Expand Down Expand Up @@ -617,10 +628,13 @@
var row = el("div", "bb-row");
row.appendChild(badge(t.state === "working" ? "online" : "info", t.state));
var main = el("div", "bb-row__main");
main.appendChild(el("div", "bb-row__title", t.doing));
/* the snapshot's durable name-or-id label leads the row so a scan says
WHICH task this is; the run status keeps its place on the second line */
main.appendChild(el("div", "bb-row__title", t.name));
/* captain-facing rows name the repo; the internal task id shows only when
no repo is known */
main.appendChild(el("div", "bb-row__sub", t.kind + " · " + (t.repo || t.id)));
main.appendChild(el("div", "bb-row__sub",
t.doing + " · " + t.kind + " · " + (t.repo || t.id)));
row.appendChild(main);
uw.appendChild(row);
});
Expand Down Expand Up @@ -664,7 +678,7 @@
if (!chartedQueued(data.charted).length && !chartedMoreQueued) {
ch.appendChild(el("div", "bb-empty", "Nothing is queued."));
}
data.charted.forEach(function (t) {
chartedOrder(data.charted).forEach(function (t) {
var row = el("div", "bb-row");
if (t.dispatchable && !isWarning(t)) {
anyPickable = true;
Expand Down
10 changes: 8 additions & 2 deletions .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: bootstrap-diagnostics
description: >-
Agent-only handling playbook for session-start bootstrap diagnostics.
Use whenever the session-start digest's bootstrap or network-checks section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, VAULT_DRIFT, UPSTREAM, GBRAIN_SERVING_CREDENTIAL, GBRAIN_PIN, GBRAIN_CAPTURE, STARTUP_MEMORY_BUDGET, CREW_DISPATCH (invalid or backend mismatch), FLEET_SYNC, BOARD_SWEEP, NETWORK_CHECKS, HOME_SUMMARY, BACKLOG_RECONCILE, ENDPOINT_BINDING_MIGRATION, RUN_ATTRIBUTION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, SECONDMATE_HANDOFF, NUDGE_SECONDMATES, USAGE_STORE, or FMX - or reports that an interrupted backlog cleanup may have left an endpoint or local copy, or when a standalone bin/fm-bootstrap.sh or bin/fm-startup-network.sh run prints one of those lines.
Use whenever the session-start digest's bootstrap or network-checks section prints an actionable diagnostic line - MISSING, MISSING_MANUAL, PRESENTATION_UNAVAILABLE, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, VAULT_DRIFT, UPSTREAM, GBRAIN_SERVING_CREDENTIAL, GBRAIN_PIN, GBRAIN_CAPTURE, STARTUP_MEMORY_BUDGET, CREW_DISPATCH (invalid or backend mismatch), FLEET_SYNC, BOARD_SWEEP, NETWORK_CHECKS, HOME_SUMMARY, BACKLOG_RECONCILE, ENDPOINT_BINDING_MIGRATION, RUN_ATTRIBUTION, SECONDMATE_SYNC, SECONDMATE_LIVENESS, SECONDMATE_HANDOFF, NUDGE_SECONDMATES, USAGE_STORE, or FMX - or reports that an interrupted backlog cleanup may have left an endpoint or local copy, or when a standalone bin/fm-bootstrap.sh or bin/fm-startup-network.sh run prints one of those lines.
A silent bootstrap section, or any other BOOTSTRAP_INFO fact, means no skill load.
user-invocable: false
metadata:
Expand All @@ -19,9 +19,12 @@ When any diagnostic needs captain attention, report the plain consequence and re
- `MISSING: <tool> (install: <command>)` - list the missing tools to the captain with a one-line purpose each plus the printed install commands, wait for consent (one approval may cover the list), then run `bin/fm-bootstrap.sh install <approved tools...>`.
For `treehouse`, this also covers an installed version whose `treehouse get` lacks `--lease`; treat it as an upgrade request.
For `no-mistakes`, this also covers an installed version older than 1.46.0, because this repo's PR gate requires structured pipeline attestation that older builds do not write.
For any axi-family tool - `gh-axi`, `lavish-axi`, `tasks-axi`, `quota-axi` - an installed version below its floor is a plain upgrade request; [`bin/fm-bootstrap.sh`](../../../bin/fm-bootstrap.sh) owns the floor policy, and never argue the floor down to whatever the home happens to have installed.
For essential axi-family tools - `gh-axi`, `tasks-axi`, `quota-axi` - an installed version below its floor is a plain upgrade request; [`bin/fm-bootstrap.sh`](../../../bin/fm-bootstrap.sh) owns the floor policy, and never argue the floor down to whatever the home happens to have installed.
For `tasks-axi`, this additionally covers an installed build that fails the separate feature probe (`bin/fm-tasks-axi-lib.sh` owns the definition); `config/backlog-backend=manual` only suppresses the verbose `BOOTSTRAP_INFO: tasks-axi available` fact, not this missing-tool report.
For `quota-axi`, bootstrap requires it because firstmate reads its current output directly before resolving every crew-dispatch profile array; without it, report the missing requirement and do not choose around an unexamined candidate.
- `PRESENTATION_UNAVAILABLE: lavish-axi ...` - explain that visual presentation is unavailable and continue nonvisual work with plain-text decisions and reports; do not hold unrelated dispatch for installation consent.
Do not use Lavish until it satisfies the floor owned by `bin/fm-bootstrap.sh`; when visual work needs it, request consent for the printed install or upgrade command, then rerun bootstrap to confirm compatibility before using it.
Scout briefs check the same floor when scaffolded and ask for a text report instead of a Lavish loop, so scaffold a visual scout only after that rerun confirms compatibility.
- `MISSING_MANUAL: <tool> (instructions: <url>)` - tell the captain why the tool is required and give them the printed instructions URL, but do not pass the tool to `bin/fm-bootstrap.sh install`; wait for the captain to complete the manual installation, then rerun session start to confirm the dependency is present.
- `BACKEND_INVALID: <name> (known: <names>)` - the resolved runtime backend has no verified dependency or lifecycle contract, so do not dispatch work until the invalid `FM_BACKEND` or `config/backend` value is corrected to one of the listed backends.
- `NEEDS_GH_AUTH` - ask the captain to run `! gh auth login` (interactive; you cannot run it for them).
Expand Down Expand Up @@ -88,6 +91,9 @@ When any diagnostic needs captain attention, report the plain consequence and re
Treat the task's run state as unreadable rather than absent, and reconstruct any urgent supervision decision from the recorded worktree's git state plus `no-mistakes axi status` before allowing branch edits or commits.
Never hand-write `branch=` from the checked-out branch, an `fm/<task-id>` naming match, a run listing, or a work item; those are the same unproven inferences the attribution guard refuses.
A future locked startup may converge a GitHub task only when its recorded PR URL and recorded PR-head SHA still match the forge's current PR head, while every other task remains diagnosed until cleanup.
- `BACKLOG_RECONCILE: code-root <file> is not this home's <file>; ...` - a tasks-axi write addressed the code root instead of this home, so the queue has already forked and either copy may hold rows the other lacks; [`docs/configuration.md`](../../../docs/configuration.md) ("Backlog backend") owns why.
Neither copy is a safe winner: union-merge them into this home's file by task id, resolve each conflicting id to its most recent real transition, check this home's archive before treating a missing Done row as lost, and verify the merged id set equals the union of both inputs before installing it.
Then move the code-root file aside rather than deleting it, tell the captain which rows were recovered, and run every later backlog command through `bin/fm-tasks-axi.sh`; re-linking the code-root copy is never the fix, because the next cwd-relative tasks-axi write replaces the link again.
- `SECONDMATE_SYNC: secondmate <id>: skipped: <reason>` - secondmate convergence left a live home on its existing checkout because the home was dirty, diverged, unsafe, on the wrong branch, missing its placement-specific target commit, unreachable, or otherwise not fast-forwardable, or because inherited local-material propagation failed; bootstrap continued, but inspect the reason because the secondmate's tracked instructions, inherited settings, or shared captain preferences may be stale after a primary update.
- `SECONDMATE_LIVENESS: secondmate <id>: skipped: <reason>|respawn failed after <cause>: <reason>` - the session-start liveness sweep could not guarantee that the registered secondmate is running a real agent process.
Investigate the reason because that secondmate is not guaranteed live.
Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/firstmate-coding-guidelines/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ That is the trigger condition for loading the skill, plus any safety-critical fa
Everything else - the procedure, the mechanism, the surrounding detail - moves out completely.
Do not leave a partial restatement behind "just in case".
A partial copy is exactly the duplication the one-owner rule forbids.
The model to copy is `AGENTS.md` section 8's "Away-mode stub": it keeps only the marker format, the ownership-transfer rule, and the exit condition inline, and points everything else at the `/afk` skill.
The model to copy is `AGENTS.md` section 8's "Away-mode and quiet-mode stub": it keeps only the marker format, the ownership-transfer rule, and the exit condition inline, and points everything else at the `/afk` and `/quiet` skills.

## Size discipline

Expand Down
Loading
Loading