From 35761484e9f0a692ebec86532ff4dd252b224cf9 Mon Sep 17 00:00:00 2001 From: AnPod Date: Sun, 13 Sep 2026 00:50:23 +0200 Subject: [PATCH 001/247] feat(bin): add Antigravity CLI (agy) as third worker/scout adapter (#4200) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * feat(agy): verify Antigravity CLI as third worker/scout adapter Detection by anchored ancestry in fm-harness.sh (no marker of its own); bootstrap harness and effort validation; launch template with model and effort mapping plus reachable-catalog model validation; rendered-tail busy fallback in fm-busy-lib.sh with delivery footer in fm-composer-lib.sh; control mechanics with crewmate/scout-only refusal; tmux liveness naming; router entry with concise adapter reference; dated verification record; portable regression plus opt-in live drift guard. Verified live on agy 1.2.0: supervised spawn, durable steering, same-copy relaunch, and exit, with Herdr-native busy agreement. * no-mistakes(review): bound agy model probe, gate trust dialog, narrow busy signature * no-mistakes(review): pre-register agy workspace trust, make readiness gate strict * no-mistakes(review): Close Orca terminal on gate failure; isolate live-guard HOME; tighten agy matching * no-mistakes(document): Document agy adapter in stale harness enumerations * no-mistakes(review): Clamp non-positive FM_AGY_MODELS_TIMEOUT to the default bound * no-mistakes(document): Fix stale test-shard snapshots after agy lane additions * no-mistakes(ci): Fixed ci-3 (tests/fm-agy-harness.test.sh:519). Root cause: the agy spawn fixture's default base PATH (/usr/bin:/bin:/usr/sbin:/sbin) omits node's directory, but the spawn drives the real bin/fm-agy-trust.sh (which hard-requires node to record trust) and the fixture's fake tmux trust lookup (node -e) under that PATH. On the ubuntu-latest CI runner node lives in the toolcache (/usr/local/bin), so trust pre-registration failed on portable serial 2; on typical Arch hosts node is in /usr/bin, masking the defect. Fix (smallest, following the existing tests/fm-kimi-harness.test.sh precedent of carrying the interpreter's resolved directory): resolve node from the invoking environment (failing the test with 'test needs node' if absent, as kimi does for python3) and prepend its directory to the fixture's default base PATH; the FM_TEST_BASE_PATH override contract is untouched. Verified locally: (1) pre-fix reproduction with a CI-shaped base PATH (system bins minus node) produced exactly the reported failure — 'node is required to record workspace trust and was not found on PATH' plus the fake tmux 'node: command not found'; (2) post-fix, all 29 tests in the file pass both with node available only via a leading non-standard dir in the base PATH (CI's shape) and with the default base PATH on this host. bash -n clean; ShellCheck is not installed in this worktree (previously recorded as environmental) * no-mistakes(test): Give agy typed sends a longer submit-confirm budget * no-mistakes(document): Document agy send budget, trust gate, and control coverage * no-mistakes(document): Document agy busy fallback inventory and send-timing evidence --- .agents/skills/harness-adapters/SKILL.md | 7 +- .../references/common/control-and-recovery.md | 1 + .../references/harness/agy.md | 55 ++ AGENTS.md | 2 +- CONTRIBUTING.md | 2 +- bin/fm-agent-process-lib.sh | 5 + bin/fm-agy-trust.sh | 185 ++++ bin/fm-bootstrap.sh | 3 +- bin/fm-busy-lib.sh | 55 +- bin/fm-composer-lib.sh | 17 +- bin/fm-control-lib.sh | 26 +- bin/fm-harness.sh | 11 +- bin/fm-send.sh | 25 +- bin/fm-spawn.sh | 203 +++- bin/fm-test-run.sh | 6 +- docs/agent-control.md | 6 +- docs/architecture.md | 4 +- docs/configuration.md | 3 +- docs/documentation-audiences.json | 8 + docs/fm-test-portable-shards.md | 18 +- docs/tmux-backend.md | 3 +- docs/trace-context.md | 2 +- docs/verification/agy.md | 170 ++++ tests/fm-agy-harness.test.sh | 905 ++++++++++++++++++ tests/fm-agy-signals-live-e2e.test.sh | 193 ++++ tests/fm-bootstrap.test.sh | 4 + tests/fm-send-agy-confirm.test.sh | 165 ++++ 27 files changed, 2012 insertions(+), 72 deletions(-) create mode 100644 .agents/skills/harness-adapters/references/harness/agy.md create mode 100755 bin/fm-agy-trust.sh create mode 100644 docs/verification/agy.md create mode 100755 tests/fm-agy-harness.test.sh create mode 100755 tests/fm-agy-signals-live-e2e.test.sh create mode 100755 tests/fm-send-agy-confirm.test.sh diff --git a/.agents/skills/harness-adapters/SKILL.md b/.agents/skills/harness-adapters/SKILL.md index be447a41d7a..0c3a0353411 100644 --- a/.agents/skills/harness-adapters/SKILL.md +++ b/.agents/skills/harness-adapters/SKILL.md @@ -3,7 +3,7 @@ name: harness-adapters description: >- Agent-only reference for firstmate harness operations. Use before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter. - Contains verified facts for claude, codex, opencode, pi, pi-signed, grok, kimi, cursor, gemini, muse, rovo, and omp. + Contains verified facts for claude, codex, opencode, pi, pi-signed, grok, kimi, cursor, gemini, muse, rovo, omp, and agy. user-invocable: false metadata: internal: true @@ -35,7 +35,7 @@ For recovery and control, use the exact `harness=` in `state/.meta`; never i Deliver lifecycle actions only through `../../../bin/fm-control.sh interrupt|exit|relaunch`. Never type an interrupt key or exit command through `fm-send`, where routing-marked lifecycle text becomes chat. Trust handling is complete only when inspection proves the target started processing its instructions; delivery success alone is not proof. -Muse and Gemini are verified only for crewmate and scout work, never a secondmate or primary. +Muse, Gemini, and AGY are verified only for crewmate and scout work, never a secondmate or primary. ## Detection @@ -93,7 +93,8 @@ A new tool remains undispatchable until the `verify` plan, its harness entry, ev "gemini": "references/harness/gemini.md", "muse": "references/harness/muse.md", "rovo": "references/harness/rovo.md", - "omp": "references/harness/omp.md" + "omp": "references/harness/omp.md", + "agy": "references/harness/agy.md" } } ``` diff --git a/.agents/skills/harness-adapters/references/common/control-and-recovery.md b/.agents/skills/harness-adapters/references/common/control-and-recovery.md index 78115e47174..4223b63b895 100644 --- a/.agents/skills/harness-adapters/references/common/control-and-recovery.md +++ b/.agents/skills/harness-adapters/references/common/control-and-recovery.md @@ -18,6 +18,7 @@ No observed dialog proves only that launch. Each supported harness handles its folder-trust gate differently, and the tool reference owns the detail. For Claude, load `references/harness/claude.md`; its workspace-trust section owns the non-key-answerable gate and spawn-time pre-registration for every spawn kind. +agy gates every fresh worktree too; the spawn pre-registers it in agy's own store the same way, and a strict post-launch gate answers any dialog that still renders before the spawn reports success. Cursor suppresses its dialog with launch-time `--trust`, and Muse suppresses its own with `--yolo`. Grok dodges its gate instead of granting trust, because its project picker appears only outside a project and the spawn starts in the isolated git root. Pi gates the fresh-worktree case too, but unlike Claude its dialog is answered with Enter, and `references/harness/pi.md` owns that recipe and where the decision persists. diff --git a/.agents/skills/harness-adapters/references/harness/agy.md b/.agents/skills/harness-adapters/references/harness/agy.md new file mode 100644 index 00000000000..0f38ca16ba6 --- /dev/null +++ b/.agents/skills/harness-adapters/references/harness/agy.md @@ -0,0 +1,55 @@ +# Antigravity CLI + +Antigravity's `agy` TUI, verified end to end on 2026-09-10 with agy 1.2.0 on Linux through the Herdr backend. +Verified as a CREWMATE and SCOUT adapter only; `../../../../../bin/fm-spawn.sh` refuses a secondmate launch on it because `../../../../../docs/supervision-protocols/` carries no agy wake protocol. +`../../../../../docs/verification/agy.md` owns how every fact below was established and what is still unproven. + +## Operating facts + +| Fact | Value | +|---|---| +| Binary | Absolute `agy` from `PATH`, refused if absent; a Go-compiled single binary, so the live process name is exactly `agy` with `argv[0]=agy`. | +| Launch | `agy --prompt-interactive "" --model --effort --dangerously-skip-permissions`, with the resolved absolute binary; the brief auto-submits with no extra Enter. The spawn pre-registers the worktree in agy's trust store first, then waits for a busy turn (answering the folder-trust dialog if it renders anyway) before reporting success. | +| Busy state | No hook or plugin writer, so nothing is armed and no record is seeded; on Herdr the native `working` status classifies busy, and everywhere else the `agy-regex` rendered-tail fallback in `../../../../../bin/fm-busy-lib.sh` does. | +| Rendered tail | Busy status row carries `esc to cancel` on the left; the idle row shows `? for shortcuts` instead. The `Generating...` word beside the braille spinner is free-floating output and is not a signal. | +| Turn end | No turn-end hook or notification touch exists; completion arrives through the worker status protocol and, on Herdr, the native return to `idle`. | +| Exit | `/quit`, one Enter; the process exits. | +| Interrupt | Single `Escape`, which prints the Interrupted row and leaves an idle composer with no repollution, so no clear key follows. | +| Skill | No verified slash-skill form; use natural language. | +| Autonomy | `--dangerously-skip-permissions` auto-approves tool calls for the run. | +| Marker | None; a live TUI carries no `AGY_*` or `ANTIGRAVITY_*` variable. | +| Resume | `--continue` and `--conversation` exist but carry no verified pane-resume contract; use deterministic relaunch. | +| Model | `--model ` with the bare catalog id from `agy models` (for example `gemini-3.8-flash-high`); `bin/fm-spawn.sh` refuses a requested id a reachable listing omits. The listing is a remote fetch, so the probe runs stdin-detached under the shared hard bound and an unreachable or hung listing launches unvalidated with a notice. | +| Effort | `--effort low\|medium\|high`; `xhigh` and `max` stay in task metadata under the record-and-omit contract. | +| Composer | Borderless bare `>` row, which the shared classifier reads as `unknown` under the dead-shell rule, never `empty`; steering confirms delivery through native agent-state and the delivery footer instead, the cursor precedent. | + +## Trust, and where the decision persists + +Every task worktree is a path agy has never seen, so an unregistered launch stops on `Do you trust the contents of this project?` with the safe choice `Yes, I trust this folder` preselected, and an unanswered dialog sends the turn into agy's scratch directory instead of the worktree. +There is no launch flag that suppresses the dialog, but agy honours a `trustedWorkspaces` entry in the captain's own `~/.gemini/antigravity-cli/settings.json` written ahead of launch (verified live), so `../../../../../bin/fm-spawn.sh` pre-registers the worktree through `../../../../../bin/fm-agy-trust.sh` before launch, the claude shape: the helper refuses anything but a linked worktree of the spawning project, records both the logical pane path and its resolved form because agy compares the logical cwd, and preserves every other key in the store. +The post-launch readiness gate is the backstop: it answers a dialog that renders anyway with a single Enter, then requires a busy verdict (Herdr's native `working` status or the pinned `esc to cancel` row) before the spawn reports success, and on a path that was not pre-registered it never counts a busy verdict as ready until the dialog has been answered, because Herdr's native verdict can precede the dialog. +A pane whose brief cannot be confirmed to run in the worktree fails the spawn, records the failure in the task status, and closes the endpoint. +Never steer into a pane still showing the dialog; a spawn that reported success has already cleared it. + +## Credential precondition + +A verified agy worker ran under a signed-in Google account with no key export and no dialog. +The unauthenticated failure mode was not observed, so treat any auth prompt or refusal as a credential blocker under `../../../../../AGENTS.md` section 9, fix the environment, and retire the endpoint rather than typing into it. + +## Detection + +Detected by ancestry alone: `../../../../../bin/fm-harness.sh` matches the anchored process name `agy`, never `*agy*`. +No environment marker is promoted: `AGENT=1` observed on a live TUI is an inherited launcher value, not an agy identity, and agy does not clear an inherited `CLAUDECODE`, so the spawn clears foreign markers at the launch boundary and the ancestry arm decides. +agy is deliberately absent from the session-lock name vocabulary in `../../../../../bin/fm-session-lock-lib.sh`, where muse, gemini, and rovo are also absent: a crewmate-only adapter must never own a home session lock. + +## Worker busy state and turn end + +`../../../../../bin/fm-spawn.sh` arms no busy generation for agy and writes no sidecar, exactly because no writer could ever clear a seeded record. +`fm_busy_agy_tail_busy` matches the pinned `esc to cancel` status row alone, hardcoded with no environment override, and `fm_busy_classify` reports `unknown agy-regex` rather than idle when it is absent, because a long turn can scroll the marker out of the captured tail. +Teardown removes nothing agy-specific because the spawn leaves nothing behind. + +## Primary integration + +Unsupported and unverified. +`../../../../../docs/supervision-protocols/` carries no agy protocol, no turn-end guard adapter exists for it, and this adapter verified only the crewmate-side launch, busy state, interrupt, and exit. +`references/common/primary-hooks.md`'s unsupported-boundary rule applies: never invent a wake protocol from a similar TUI. diff --git a/AGENTS.md b/AGENTS.md index 135831d62f5..7d58297bb07 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -209,7 +209,7 @@ A silent bootstrap section needs no action; for any printed actionable diagnosti ## 4. Harness and runtime dispatch Load `harness-adapters` before every spawn or recovery and before trust handling, skill invocation, interrupt, exit, resume, or adapter verification. -The verified harnesses are `claude`, `codex`, `opencode`, `pi`, `pi-signed`, `grok`, `kimi`, `cursor`, and `omp`, plus `muse`, `gemini`, and `rovo` for crewmates and scouts only; never dispatch on an unverified adapter. +The verified harnesses are `claude`, `codex`, `opencode`, `pi`, `pi-signed`, `grok`, `kimi`, `cursor`, and `omp`, plus `muse`, `gemini`, `rovo`, and `agy` for crewmates and scouts only; never dispatch on an unverified adapter. If static `config/crew-harness` or `config/secondmate-harness` names an unverified adapter, report it and fall back only to a verified adapter rather than launching it. `docs/configuration.md` owns dispatch-profile and runtime-backend schemas, `bin/fm-harness.sh` owns static resolution, and `bin/fm-spawn.sh` owns launch flags and fail-closed validation. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 87317bd5c45..de4cc759a35 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -52,7 +52,7 @@ See the [no-mistakes quick start](https://kunchenguid.github.io/no-mistakes/star It pins one exact shellcheck version and one exact actionlint version and refuses to run under any other. Print the shellcheck pin with `bin/fm-lint.sh --required-version` and the actionlint pin with `bin/fm-lint-workflows.sh --required-version`. Use `bin/fm-install-shellcheck.sh` and `bin/fm-install-actionlint.sh` to install those exact builds locally; each installer's header owns its destination usage and supported platforms. -- Harness-adapter ownership spans detection in `bin/fm-harness.sh`, launch and hook mechanics in `bin/fm-spawn.sh`, spawn-time Claude workspace-trust pre-registration in `bin/fm-claude-trust.sh`, semantic busy sources and trust gates in `bin/fm-busy-lib.sh`, delivery-only rendered guards in `bin/fm-composer-lib.sh`, cleanup in `bin/fm-teardown.sh`, and facts in the skill tree rooted at `.agents/skills/harness-adapters/SKILL.md`; the `firstmate-coding-guidelines` skill owns the validation policy for checks that depend on those harnesses. +- Harness-adapter ownership spans detection in `bin/fm-harness.sh`, launch and hook mechanics in `bin/fm-spawn.sh`, spawn-time workspace-trust pre-registration in `bin/fm-claude-trust.sh` and `bin/fm-agy-trust.sh`, semantic busy sources and trust gates in `bin/fm-busy-lib.sh`, delivery-only rendered guards in `bin/fm-composer-lib.sh`, cleanup in `bin/fm-teardown.sh`, and facts in the skill tree rooted at `.agents/skills/harness-adapters/SKILL.md`; the `firstmate-coding-guidelines` skill owns the validation policy for checks that depend on those harnesses. - Changes to runtime session backends (`bin/fm-backend.sh`, `bin/backends/`, and the scripts that dispatch through them) keep current setup and limits in the relevant backend guide and active empirical evidence in [`docs/verification/runtime-backends.md`](docs/verification/runtime-backends.md). - [`docs/documentation-audiences.md`](docs/documentation-audiences.md) and its machine-consumed inventory own prose classification; run `bin/fm-doc-audience-check.sh` after documentation changes. - In Markdown, put each full sentence on its own line. diff --git a/bin/fm-agent-process-lib.sh b/bin/fm-agent-process-lib.sh index 5943f1b2749..dcf4b59ff4e 100644 --- a/bin/fm-agent-process-lib.sh +++ b/bin/fm-agent-process-lib.sh @@ -41,6 +41,11 @@ fm_agent_process_classify_name() { # [argv0] -> agent|shell|other # name is the bare word `omp` (verified, omp 18.1.11) and a glob would claim # unrelated commands such as ompd or comp. *claude*|*codex*|*opencode*|*grok*|*kimi*|*rovo*|pi|pi-signed|pi-launcher|Pi|omp) printf 'agent' ;; + # agy (Antigravity CLI) is anchored for the same reason as muse and omp: its + # live process name is the bare word `agy` (verified, agy 1.2.0: a Go-compiled + # single binary, comm=agy with argv[0]=agy), and a glob would claim + # unrelated commands containing that fragment. + agy) printf 'agent' ;; zsh|bash|sh|dash|ash|ksh|mksh|tcsh|csh|fish) printf 'shell' ;; *) if fm_harness_path_name "$path" >/dev/null || fm_harness_path_name "$argv0" >/dev/null; then diff --git a/bin/fm-agy-trust.sh b/bin/fm-agy-trust.sh new file mode 100755 index 00000000000..627d892da2f --- /dev/null +++ b/bin/fm-agy-trust.sh @@ -0,0 +1,185 @@ +#!/usr/bin/env bash +# Pre-register Antigravity CLI's workspace trust for the isolated task worktree +# a ship/scout spawn is about to launch an agy crewmate into, so the worker +# reaches its brief in the worktree instead of parking on the folder-trust +# dialog and running its turn in agy's own scratch directory. +# +# Usage: fm-agy-trust.sh +# the isolated task worktree this spawn launches into +# the primary checkout that worktree belongs to +# Prints one line naming what it registered; refuses loudly on anything else. +# +# WHY THIS EXISTS. agy 1.2.0 gates a folder it has never seen behind +# "Do you trust the contents of this project?" and no launch flag suppresses +# it (`agy --help` lists none). Answering appends the folder to the +# `trustedWorkspaces` array of ${HOME}/.gemini/antigravity-cli/settings.json, +# and agy honours an entry written there ahead of launch: verified live under a +# throwaway HOME, a pre-registered folder launched straight into its turn while +# an unregistered sibling parked on the dialog (docs/verification/agy.md). agy +# compares the pane's LOGICAL working directory, not its resolved path (a +# symlinked cwd with only the real path registered still parked), so both the +# logical path and its resolved form are recorded when they differ. +# +# bin/fm-spawn.sh keeps a post-launch gate as the backstop: it answers the +# dialog if one renders anyway and never counts a busy turn as ready on a path +# that was neither pre-registered here nor answered there. +# +# THE SCOPE TEST IS THE SAFETY PROPERTY and mirrors bin/fm-claude-trust.sh: +# must be a LINKED git worktree - its own git dir, sharing +# 's common dir - whose top level is exactly the resolved argument. A +# primary checkout, a worktree of an unrelated repo, a subdirectory of a +# worktree, a plain directory, and a home directory are each refused with a +# non-zero exit, never a warning and never a silent skip. Only the launching +# user's own store is written, it must be a regular file this uid owns, every +# unrelated key and entry is preserved, and the replacement is atomic. +set -u +unset CDPATH \ + GIT_DIR GIT_WORK_TREE GIT_COMMON_DIR GIT_OBJECT_DIRECTORY GIT_INDEX_FILE \ + GIT_ALTERNATE_OBJECT_DIRECTORIES GIT_CEILING_DIRECTORIES GIT_NAMESPACE \ + GIT_DISCOVERY_ACROSS_FILESYSTEM GIT_CONFIG GIT_CONFIG_GLOBAL \ + GIT_CONFIG_SYSTEM GIT_CONFIG_NOSYSTEM GIT_CONFIG_COUNT + +[ "$#" -eq 2 ] || { echo "usage: fm-agy-trust.sh " >&2; exit 2; } +WT_ARG=$1 +PROJ_ARG=$2 + +refuse() { echo "error: refusing to pre-register agy trust: $1" >&2; exit 1; } + +real_dir() { (cd -P -- "$1" 2>/dev/null && pwd -P); } +logical_dir() { (cd -- "$1" 2>/dev/null && pwd -L); } +real_file() { node -e 'process.stdout.write(require("node:fs").realpathSync(process.argv[1]))' "$1" 2>/dev/null; } + +common_dir_of() { + local dir=$1 common + common=$(git -C "$dir" rev-parse --git-common-dir 2>/dev/null) || return 1 + (cd -P -- "$dir" && real_dir "$common") +} + +WT_REAL=$(real_dir "$WT_ARG") || true +[ -n "$WT_REAL" ] || refuse "worktree '$WT_ARG' is not an accessible directory" +WT_LOGICAL=$(logical_dir "$WT_ARG") || true +[ -n "$WT_LOGICAL" ] || WT_LOGICAL=$WT_REAL +PROJ_REAL=$(real_dir "$PROJ_ARG") || true +[ -n "$PROJ_REAL" ] || refuse "project '$PROJ_ARG' is not an accessible directory" + +[ -n "${HOME:-}" ] || refuse "HOME is not set, so agy's settings store cannot be located" +HOME_REAL=$(real_dir "$HOME") || true +[ -n "$HOME_REAL" ] || refuse "HOME '$HOME' is not an accessible directory" +[ "$WT_REAL" != "$HOME_REAL" ] || refuse "'$WT_REAL' is the home directory, not a task worktree" + +WT_TOP=$(git -C "$WT_REAL" rev-parse --show-toplevel 2>/dev/null) || true +[ -n "$WT_TOP" ] || refuse "'$WT_REAL' is not inside a git repository" +WT_TOP_REAL=$(real_dir "$WT_TOP") || true +[ "$WT_TOP_REAL" = "$WT_REAL" ] || refuse "'$WT_REAL' is not a worktree root (its root is '${WT_TOP_REAL:-unresolvable}')" + +WT_GIT_DIR=$(git -C "$WT_REAL" rev-parse --absolute-git-dir 2>/dev/null) || true +[ -n "$WT_GIT_DIR" ] || refuse "'$WT_REAL' has no resolvable git directory" +WT_GIT_DIR=$(real_dir "$WT_GIT_DIR") || true +[ -n "$WT_GIT_DIR" ] || refuse "'$WT_REAL' has an unresolvable git directory" +WT_COMMON=$(common_dir_of "$WT_REAL") || true +[ -n "$WT_COMMON" ] || refuse "'$WT_REAL' has no resolvable git common directory" +[ "$WT_GIT_DIR" != "$WT_COMMON" ] || refuse "'$WT_REAL' is a primary checkout, not an isolated worktree" + +PROJ_COMMON=$(common_dir_of "$PROJ_REAL") || true +[ -n "$PROJ_COMMON" ] || refuse "project '$PROJ_REAL' is not inside a git repository" +[ "$WT_COMMON" = "$PROJ_COMMON" ] || refuse "'$WT_REAL' is not a worktree of project '$PROJ_REAL'" + +command -v node >/dev/null 2>&1 || refuse "node is required to record workspace trust and was not found on PATH" + +STORE_DIR="$HOME_REAL/.gemini/antigravity-cli" +mkdir -p "$STORE_DIR" 2>/dev/null || true +STORE_DIR_REAL=$(real_dir "$STORE_DIR") || true +[ -n "$STORE_DIR_REAL" ] || refuse "agy settings directory '$STORE_DIR' does not exist and could not be created" +STORE="$STORE_DIR_REAL/settings.json" +if [ -L "$STORE" ]; then + STORE_REAL=$(real_file "$STORE") || true + [ -n "$STORE_REAL" ] || refuse "'$STORE' is a symlink whose target cannot be resolved" + STORE=$STORE_REAL +fi +if [ -e "$STORE" ]; then + [ -f "$STORE" ] || refuse "'$STORE' is not a regular file" + [ -O "$STORE" ] || refuse "'$STORE' is not owned by this user" + [ -w "$STORE" ] || refuse "'$STORE' is not writable" +fi + +# Read-modify-write with a fingerprint check before the rename and a readback +# after it, the bin/fm-claude-trust.sh shape: agy itself rewrites this file +# when a worker answers a dialog or changes a setting, so a store that moved +# under us is retried once and then refused rather than clobbered. +if ! node - "$STORE" "$WT_LOGICAL" "$WT_REAL" <<'NODE' +const fs = require("node:fs"); +const path = require("node:path"); +const crypto = require("node:crypto"); +const [store, ...wanted] = process.argv.slice(2); +const paths = [...new Set(wanted)]; +const readStore = () => { + try { + return fs.readFileSync(store); + } catch (err) { + if (err.code === "ENOENT") return null; + throw err; + } +}; +const fingerprint = (buf) => + buf === null ? "absent" : crypto.createHash("sha256").update(buf).digest("hex"); +const listed = (root) => + Array.isArray(root.trustedWorkspaces) && paths.every((p) => root.trustedWorkspaces.includes(p)); +const attempt = () => { + const original = readStore(); + const before = fingerprint(original); + let root = {}; + if (original !== null) { + const raw = original.toString("utf8"); + if (raw.trim() !== "") { + root = JSON.parse(raw); + if (root === null || typeof root !== "object" || Array.isArray(root)) { + throw new Error(`${store} is not a JSON object`); + } + } + } + if (root.trustedWorkspaces === undefined || root.trustedWorkspaces === null) root.trustedWorkspaces = []; + if (!Array.isArray(root.trustedWorkspaces)) { + throw new Error(`${store} has a non-array "trustedWorkspaces" value`); + } + if (listed(root)) return "recorded"; + for (const p of paths) { + if (!root.trustedWorkspaces.includes(p)) root.trustedWorkspaces.push(p); + } + const unique = `${process.pid}.${crypto.randomBytes(8).toString("hex")}`; + const tmp = path.join(path.dirname(store), `.settings.json.fm-trust.${unique}`); + fs.writeFileSync(tmp, `${JSON.stringify(root, null, 2)}\n`, { mode: 0o600, flag: "wx" }); + let renamed = false; + try { + if (fingerprint(readStore()) !== before) return "moved"; + fs.renameSync(tmp, store); + renamed = true; + } finally { + if (!renamed) fs.rmSync(tmp, { force: true }); + } + return listed(JSON.parse(fs.readFileSync(store, "utf8"))) ? "recorded" : "dropped"; +}; +try { + for (let i = 0; i < 3; i += 1) { + const result = attempt(); + if (result === "recorded") process.exit(0); + if (result === "moved" && i >= 1) { + console.error(`error: ${store} was modified while trust was being recorded; refusing to overwrite it`); + process.exit(1); + } + } +} catch (err) { + console.error(`error: ${err.message}`); + process.exit(1); +} +console.error(`error: ${store} did not retain trust for ${paths.join(", ")} after 3 attempts`); +process.exit(1); +NODE +then + refuse "could not record trust for '$WT_LOGICAL' in '$STORE'" +fi + +if [ "$WT_LOGICAL" != "$WT_REAL" ]; then + echo "trusted: $WT_LOGICAL ($WT_REAL)" +else + echo "trusted: $WT_REAL" +fi diff --git a/bin/fm-bootstrap.sh b/bin/fm-bootstrap.sh index b5e010905cf..98b791e52f7 100755 --- a/bin/fm-bootstrap.sh +++ b/bin/fm-bootstrap.sh @@ -1114,7 +1114,7 @@ crew_dispatch_validate() { return 0 fi err=$(jq -r ' - def verified($h): ["claude","codex","opencode","pi","pi-signed","grok","kimi","cursor","muse","rovo","omp"] | index($h); + def verified($h): ["claude","codex","opencode","pi","pi-signed","grok","kimi","cursor","agy","muse","rovo","omp"] | index($h); def effort_ok($h; $m; $e): if $e == null then true elif ($e | type) != "string" then false @@ -1122,6 +1122,7 @@ crew_dispatch_validate() { elif $h == "claude" then (["low","medium","high","xhigh","max"] | index($e)) elif $h == "codex" then (["low","medium","high","xhigh"] | index($e)) elif $h == "grok" then (["low","medium","high"] | index($e)) + elif $h == "agy" then (["low","medium","high"] | index($e)) elif $h == "pi" or $h == "pi-signed" or $h == "omp" then (["low","medium","high","xhigh","max"] | index($e)) elif $h == "muse" then (["low","medium","high","xhigh","max"] | index($e)) elif $h == "rovo" then (["low","medium","high","max"] | index($e)) diff --git a/bin/fm-busy-lib.sh b/bin/fm-busy-lib.sh index dce79a17941..d8f7a0ee111 100755 --- a/bin/fm-busy-lib.sh +++ b/bin/fm-busy-lib.sh @@ -42,7 +42,7 @@ # fm-interrupt the legacy Claude fm-send --key Escape idle event # fm-recovery a documented recovery reset after relaunch # Classifier-only sources (never written into a record): -# endpoint-gone, herdr-native, grok-regex, rovo-regex, muse-session-log, +# endpoint-gone, herdr-native, grok-regex, rovo-regex, agy-regex, muse-session-log, # cursor-transcript, missing, malformed, gen-mismatch, source-mismatch, # kimi-unverified, codex-unverified, capture-failed, no-target # @@ -53,14 +53,15 @@ # 3. a valid, gen-matching, source-trusted record -> its state and source # 4. no record at all: herdr's native busy verdict is trusted as busy # (generation state is sufficient for busy, not for idle), then the -# muse session-log and cursor transcript pull sources, then the Grok/Rovo -# temporary regex fallbacks classify a grok or rovo task from its -# rendered tail, then unknown missing +# muse session-log and cursor transcript pull sources, then the +# Grok/Rovo/AGY temporary regex fallbacks classify a grok, rovo, or agy +# task from its rendered tail, then unknown missing # 5. malformed, stale, or untrusted records -> unknown, never a fallback -# Grok and Rovo are the ONLY rendered-text classifications that survive the -# redesign, because neither's structured lifecycle was credited-live-verified +# Grok, Rovo, and AGY are the ONLY rendered-text classifications that survive the +# redesign, because none of their structured lifecycles was credited-live-verified # in the approved audit (Rovo's clean ACP stopReason lives outside the TUI -# path firstmate drives, see references/harness/rovo.md); each is scoped to +# path firstmate drives, see references/harness/rovo.md; agy 1.2.0 exposes no +# hook surface at all, see references/harness/agy.md); each is scoped to # its own harness= and can never classify another adapter. The delivery # guards in bin/fm-composer-lib.sh match rendered footers for submit # acknowledgement and away-mode supervisor injection only; neither is a @@ -851,12 +852,27 @@ fm_busy_rovo_tail_busy() { | grep -qiE "${FM_BUSY_ROVO_REGEX:-Rovo is thinking}" } +# fm_busy_agy_tail_busy: the AGY-only temporary rendered-tail fallback. +# Consumes the tail on stdin; 0 when AGY's verified busy signature matches: +# the `esc to cancel` token in the status row the TUI pins to the bottom of +# the pane while a turn runs (verified live on agy 1.2.0; the idle status row +# shows `? for shortcuts` instead). The `Generating...` spinner word that +# renders beside it is deliberately NOT matched: it is a free-floating output +# line, so ordinary worker output echoing the word would classify an idle +# worker as busy. agy exposes no hook surface, so this fallback is the only +# pane-side source; it is never armed as a semantic writer +# (fm_busy_sources_for_harness trusts nothing for agy). +fm_busy_agy_tail_busy() { + grep -v '^[[:space:]]*$' | tail -12 \ + | grep -qiE 'esc[[:space:]]+to[[:space:]]+cancel' +} + # fm_busy_classify: semantic classification for a task whose endpoint the # caller has already established as present. Prints " ": # busy|idle|unknown plus the producing source (see header). Never probes # process state. is optional pre-captured plain output used only by -# the Grok arm; when absent the Grok arm captures through fm_backend_capture -# if available, else reports unknown capture-failed. +# the grok, rovo, and agy arms; when absent each captures through +# fm_backend_capture if available, else reports unknown capture-failed. fm_busy_classify() { # [tail40] local backend=$1 target=$2 harness=$3 id=$4 state=$5 tail40=${6-} local out rc r_state r_source native log @@ -979,6 +995,27 @@ fm_busy_classify() { # [tail40] fi return 0 ;; + agy) + if [ -z "$tail40" ]; then + if command -v fm_backend_capture >/dev/null 2>&1; then + tail40=$(fm_backend_capture "$backend" "$target" 40 2>/dev/null) || { + printf 'unknown capture-failed' + return 0 + } + else + printf 'unknown capture-failed' + return 0 + fi + fi + # Best-effort like rovo: a long turn can scroll the busy marker out of + # the captured tail, so its absence means "can't tell," never idle. + if printf '%s' "$tail40" | fm_busy_agy_tail_busy; then + printf 'busy agy-regex' + else + printf 'unknown agy-regex' + fi + return 0 + ;; esac printf 'unknown missing' } diff --git a/bin/fm-composer-lib.sh b/bin/fm-composer-lib.sh index cdea8d98abd..058dadc7293 100644 --- a/bin/fm-composer-lib.sh +++ b/bin/fm-composer-lib.sh @@ -290,7 +290,7 @@ fm_composer_strip_ghost() { # Matching a footer to confirm a keystroke landed is a different question from # asking what a worker is doing, and the two must not be conflated. # Delivery-only rendered busy footers per harness. claude/codex: "esc to -# interrupt"; opencode: "esc interrupt"; pi: "Working..."; omp: "Working…"; grok: "Ctrl+c:cancel". +# interrupt"; opencode: "esc interrupt"; pi: "Working..."; omp: "Working…"; grok: "Ctrl+c:cancel"; agy: "esc to cancel". # Claude's current spinner has a rotating glyph and word, but every active-turn # line has an ellipsis followed by a parenthesized elapsed duration. Keep this # signature separate from the shared default because that shape is not generic @@ -311,7 +311,11 @@ fm_composer_strip_ghost() { # part of that union for the same reason the others are: without it a cursor # submit could never be acknowledged, because cursor parks its terminal cursor # outside its composer and the composer verdict is therefore always `unknown`. -FM_DELIVERY_BUSY_REGEX_DEFAULT='esc (to )?interrupt|Working(\.\.\.|…)|Ctrl\+c:cancel|ctrl\+c to stop' +# agy's `esc to cancel` is part of the union for the same reason: an explicit +# tmux agy endpoint reaches the submit core with no recorded harness, and its +# bare `>` composer verdict is `unknown`, so the busy footer is the only +# turn-started acknowledgement that path can read. +FM_DELIVERY_BUSY_REGEX_DEFAULT='esc (to )?interrupt|Working(\.\.\.|…)|Ctrl\+c:cancel|ctrl\+c to stop|esc[[:space:]]+to[[:space:]]+cancel' FM_DELIVERY_CLAUDE_BUSY_REGEX_DEFAULT='esc to interrupt|…[[:space:]]+\([0-9]+[smh]' FM_DELIVERY_CODEX_BUSY_REGEX_DEFAULT='esc to interrupt' FM_DELIVERY_OPENCODE_BUSY_REGEX_DEFAULT='esc interrupt' @@ -342,6 +346,14 @@ FM_DELIVERY_GROK_BUSY_REGEX_DEFAULT='Ctrl\+c:cancel' # injection. Cursor's recorded worker state comes from its transcript fold in # bin/fm-busy-lib.sh, never from this row. FM_DELIVERY_CURSOR_BUSY_REGEX_DEFAULT='ctrl\+c to stop' +# agy (Antigravity CLI) renders a pinned status row while a turn runs: the +# `esc to cancel` token on the left and the model cell on the right (verified +# live, agy 1.2.0; the idle row shows `? for shortcuts` instead). The +# `Generating...` spinner word beside it is a free-floating output line and is +# deliberately not matched, so echoed worker output cannot fake an +# acknowledgement. Delivery guard only; recorded worker state comes from the +# agy-regex fold in bin/fm-busy-lib.sh. +FM_DELIVERY_AGY_BUSY_REGEX_DEFAULT='esc[[:space:]]+to[[:space:]]+cancel' FM_DELIVERY_KIMI_BUSY_REGEX_DEFAULT='^[[:space:]]*(🌑|🌒|🌓|🌔|🌕|🌖|🌗|🌘)[[:space:]]+·[[:space:]]+' fm_busy_lines_match() { # [harness] @@ -357,6 +369,7 @@ fm_busy_lines_match() { # [harness] pi|pi-signed) regex=$FM_DELIVERY_PI_BUSY_REGEX_DEFAULT ;; omp) regex=$FM_DELIVERY_OMP_BUSY_REGEX_DEFAULT ;; grok) regex=$FM_DELIVERY_GROK_BUSY_REGEX_DEFAULT ;; + agy) regex=$FM_DELIVERY_AGY_BUSY_REGEX_DEFAULT ;; kimi) regex=$FM_DELIVERY_KIMI_BUSY_REGEX_DEFAULT ;; cursor) regex=$FM_DELIVERY_CURSOR_BUSY_REGEX_DEFAULT ;; '') regex=$FM_DELIVERY_BUSY_REGEX_DEFAULT ;; diff --git a/bin/fm-control-lib.sh b/bin/fm-control-lib.sh index 96a7abc4860..516a00b4364 100644 --- a/bin/fm-control-lib.sh +++ b/bin/fm-control-lib.sh @@ -63,7 +63,7 @@ fm_control_verb_allowed() { # # than guessed at, exactly as a spawn on it would be. fm_control_harness_supported() { # case "${1-}" in - claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp) return 0 ;; + claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp|agy) return 0 ;; esac return 1 } @@ -74,13 +74,15 @@ fm_control_harness_supported() { # # harness= that way), which is why the spawn adapters match `claude*`, `muse*`, # and friends. This is the one place that prefix rule is stated. `pi` and # `pi-signed` are exact because a `pi*` prefix would swallow the signed adapter, -# `omp` is exact because an `omp*` prefix would claim unrelated commands, and an +# `omp` is exact because an `omp*` prefix would claim unrelated commands, `agy` +# is exact for the same reason on an even shorter name, and an # unrecognized value returns nonzero rather than being guessed into a family. fm_control_harness_family() { # case "${1-}" in pi) printf 'pi' ;; pi-signed) printf 'pi-signed' ;; omp) printf 'omp' ;; + agy) printf 'agy' ;; claude*) printf 'claude' ;; codex*) printf 'codex' ;; opencode*) printf 'opencode' ;; @@ -94,8 +96,8 @@ fm_control_harness_family() { # esac } -# Which task kinds an adapter is verified to run. muse, gemini, and rovo are -# crewmate/scout adapters only: none has a primary supervision protocol, +# Which task kinds an adapter is verified to run. muse, gemini, rovo, and agy +# are crewmate/scout adapters only: none has a primary supervision protocol, # and bin/fm-spawn.sh refuses a --secondmate launch on any of them. The control # plane asks this BEFORE it stops anything, so an incompatible relaunch target is # refused while the current agent is still running rather than after it has @@ -104,7 +106,7 @@ fm_control_harness_supports_kind() { # local harness=${1-} kind=${2-} fm_control_harness_supported "$harness" || return 1 case "$harness" in - muse|gemini|rovo) [ "$kind" != secondmate ] || return 1 ;; + muse|gemini|rovo|agy) [ "$kind" != secondmate ] || return 1 ;; esac return 0 } @@ -114,12 +116,14 @@ fm_control_harness_supports_kind() { # # gemini names its own key in the running turn's status row # (`(esc to cancel, s)`), and a single Escape was verified to cancel it. # rovo cancels on a single Escape too, printing "Agent cancelled" (verified, -# 202609.1.2). omp (Oh My Pi) shares Pi's single Escape, empty composer +# 202609.1.2). agy cancels on a single Escape, printing the Interrupted row +# with an idle composer and no repollution (verified live, agy 1.2.0 through +# Herdr). omp (Oh My Pi) shares Pi's single Escape, empty composer # afterwards, and /quit exit (verified omp 18.1.2 in a PTY, re-verified 18.1.11 # through Herdr). fm_control_interrupt_key() { # case "${1-}" in - claude|codex|opencode|pi|pi-signed|omp|kimi|cursor|gemini|muse|rovo) printf 'Escape' ;; + claude|codex|opencode|pi|pi-signed|omp|kimi|cursor|gemini|muse|rovo|agy) printf 'Escape' ;; grok) printf 'C-c' ;; *) return 1 ;; esac @@ -130,7 +134,7 @@ fm_control_interrupt_key() { # fm_control_interrupt_repeat() { # case "${1-}" in opencode) printf '2' ;; - claude|codex|pi|pi-signed|omp|grok|kimi|cursor|gemini|muse|rovo) printf '1' ;; + claude|codex|pi|pi-signed|omp|grok|kimi|cursor|gemini|muse|rovo|agy) printf '1' ;; *) return 1 ;; esac } @@ -151,7 +155,7 @@ fm_control_interrupt_repeat() { # fm_control_interrupt_clear_key() { # case "${1-}" in muse) printf 'C-u' ;; - claude|codex|opencode|pi|pi-signed|omp|grok|kimi|cursor|gemini|rovo) ;; + claude|codex|opencode|pi|pi-signed|omp|grok|kimi|cursor|gemini|rovo|agy) ;; *) return 1 ;; esac } @@ -166,7 +170,7 @@ fm_control_interrupt_ack_source() { # # rovo's TUI prints "Agent cancelled" on Escape, but for parity with # claude/cursor this stays 'none': the ack is a rendered string, not a # recorded state source, and rovo has no busy wiring to confirm against. - claude|codex|opencode|pi|pi-signed|omp|grok|kimi|cursor|gemini|rovo) printf 'none' ;; + claude|codex|opencode|pi|pi-signed|omp|grok|kimi|cursor|gemini|rovo|agy) printf 'none' ;; *) return 1 ;; esac } @@ -175,7 +179,7 @@ fm_control_interrupt_ack_source() { # fm_control_exit_command() { # case "${1-}" in claude|opencode|grok|kimi|cursor|muse|rovo) printf '/exit' ;; - codex|pi|pi-signed|omp|gemini) printf '/quit' ;; + codex|pi|pi-signed|omp|gemini|agy) printf '/quit' ;; *) return 1 ;; esac } diff --git a/bin/fm-harness.sh b/bin/fm-harness.sh index 96443cf60c9..ecc19935197 100755 --- a/bin/fm-harness.sh +++ b/bin/fm-harness.sh @@ -1,6 +1,6 @@ #!/usr/bin/env bash # Detect the agent harness this process tree runs on. -# Usage: fm-harness.sh print own harness: claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp|unknown +# Usage: fm-harness.sh print own harness: claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp|agy|unknown # fm-harness.sh crew print the effective CREWMATE harness # (config/crew-harness; "default" resolves to own) # fm-harness.sh secondmate print the harness the PRIMARY uses to launch @@ -167,6 +167,15 @@ detect_own() { # named `claude` with its own node child, and that fallback's *claude* # args glob would otherwise claim it if that subtree were ever walked. omp) echo omp; return ;; + # agy (Antigravity CLI) is a Go-compiled single binary whose process name + # is exactly `agy` (verified, agy 1.2.0: `ps -o comm=` reports agy and + # Herdr's process-info reports name agy with argv[0] agy). Anchored, never + # *agy*, so unrelated commands cannot be misread as this harness. agy + # publishes no harness-identity marker of its own (a live 1.2.0 TUI + # carries no AGY_* or ANTIGRAVITY_* variable; AGENT=1 seen there is an + # inherited launcher value, not an agy identity), so like muse it is + # detected by ancestry alone. + agy) echo agy; return ;; node*|python*) # Bare interpreter: match the harness name in its script path. args=$(ps -o args= -p "$pid" 2>/dev/null) diff --git a/bin/fm-send.sh b/bin/fm-send.sh index aa74940c08e..885efff7002 100755 --- a/bin/fm-send.sh +++ b/bin/fm-send.sh @@ -70,10 +70,11 @@ # failure); any other nonzero = the send failed and nothing may be assumed # delivered. Submission dispatches through the target's recorded backend; the # tmux adapter shares its composer/submit core with the away-mode daemon via -# bin/fm-tmux-lib.sh. Tune with FM_SEND_RETRIES (default 3) / FM_SEND_SLEEP -# (0.4). Slash commands, and codex `$...` skill invocations resolved through -# harness meta, get a longer pre-Enter settle so completion popups do not -# swallow Enter. A remote secondmate target has no typed text plane at all: +# bin/fm-tmux-lib.sh. Tune with FM_SEND_RETRIES (default 3; agy typed targets +# default to 20 for agy's late busy render) / FM_SEND_SLEEP (0.4). Slash +# commands, and codex `$...` skill invocations resolved through harness meta, +# get a longer pre-Enter settle so completion popups do not swallow Enter. +# A remote secondmate target has no typed text plane at all: # every remote text steer rides the inbox (a marked secondmate request already # reaches the harness as marker-prefixed chat rather than a parser command, so # routing a remote "/..." or "$..." through the record changes nothing the @@ -1030,7 +1031,21 @@ else ;; *) settle=0.3 ;; esac - retries=${FM_SEND_RETRIES:-3} + # Per-harness submit-confirm budget. agy's bare `>` composer verdict is + # `unknown`, so a landed submit is acknowledged only by the idle-to-busy + # transition poll, and agy renders its verified busy footer well after the + # shared budget expires: ~1.5s after Enter for a short steer, ~4-5s for a + # realistic longer brief (live-measured, agy 1.2.1), against the shared + # default's 3 x 0.4s. With the shared default a typed steer to an agy + # endpoint was reported exit-1 non-delivery for a message that landed and + # ran, inviting a duplicate resend. agy typed targets get a longer default + # budget (~8s at the default cadence, twice the worst measured render); an + # explicit FM_SEND_RETRIES still wins, and every other harness keeps the + # shared 3-retry default untouched. + case "$TARGET_HARNESS" in + agy) retries=${FM_SEND_RETRIES:-20} ;; + *) retries=${FM_SEND_RETRIES:-3} ;; + esac sleep_s=${FM_SEND_SLEEP:-0.4} # Type once, submit, verify. Only exact empty confirms delivery; every other # verdict preserves the loud refusal boundary. Only LOCAL targets reach this diff --git a/bin/fm-spawn.sh b/bin/fm-spawn.sh index 13aaad7df50..2188298b37e 100755 --- a/bin/fm-spawn.sh +++ b/bin/fm-spawn.sh @@ -133,7 +133,7 @@ # profile consultation. A --secondmate spawn is exempt and resolves the SECONDMATE # harness (config/secondmate-harness -> config/crew-harness -> own), so the # secondmate-vs-crewmate split is DURABLE across every respawn (recovery, -# /updatefirstmate, restart). A bare adapter name (claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp) +# /updatefirstmate, restart). A bare adapter name (claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp|agy) # overrides it for this spawn (either kind). A non-flag string containing # whitespace is treated as a RAW launch command - the escape hatch for verifying # new adapters. For pi and pi-signed, fm-spawn resolves the selected executable @@ -281,6 +281,7 @@ # __CURSORBIN__ resolved, cursor-verified executable for a cursor launch # __GEMINISETTINGS__ firstmate-owned per-task gemini settings file (busy-state hooks) # __ROVOBIN__ resolved, rovo-verified executable for a rovo launch +# __AGYBIN__ resolved, agy-verified executable for an agy launch # Verified per-harness turn-end hooks are installed automatically where enabled; some live outside the worktree. # Kimi uses one surgically installed Firstmate region in $HOME/.kimi-code/config.toml, # a firstmate-owned global hook and registry, and a gitignored per-task pointer. @@ -288,7 +289,7 @@ # plus a gitignored .fm-grok-turnend worktree pointer and a state token. # muse installs no hook at all - its plugin engine is off in the default build - so # it writes state/.muse-session to bind the pane to muse's own session event -# log; muse and gemini are crewmate/scout only and are refused for --secondmate. +# log; muse, gemini, and agy are crewmate/scout only and are refused for --secondmate. # rovo installs no hook either - its eventHooks fire at tool granularity only, # never turn-end - so it carries no busy-source wiring at all and no turn-end # hook. A positional brief is dead-on-arrival (rovo loads, never works, and drops @@ -296,6 +297,14 @@ # only after a TUI readiness gate, then a delivery-confirmation gate - the same # launch-then-send shape as kimi. Its busy state is a screen-scrape fallback like # grok. rovo is crewmate/scout only and is refused for --secondmate, like muse. +# agy installs no hook either - it exposes no hook surface at all - so it +# carries no busy-source wiring and no turn-end hook. Its brief rides the launch +# command, but a fresh worktree would park it on a folder-trust dialog, so the +# spawn pre-registers the worktree in agy's own trust store through +# bin/fm-agy-trust.sh (the claude shape, but non-fatal) and then waits for a +# busy turn - answering the dialog first if it renders anyway - before +# reporting success (the rovo/kimi launch-then-confirm shape). Its busy state +# is a screen-scrape fallback like grok and rovo, and it is crewmate/scout only. # cursor installs no per-task hook either: it writes state/.cursor-session to # bind the pane to cursor's own conversation transcript (projects root, the exact # workspace path cursor records in .workspace-trusted, and the conversations that @@ -481,6 +490,8 @@ fm_backlog_directory_present "$STATE" "state directory" || { . "$SCRIPT_DIR/fm-trace-context-lib.sh" # shellcheck source=bin/fm-remote-readiness-lib.sh . "$SCRIPT_DIR/fm-remote-readiness-lib.sh" +# shellcheck source=bin/fm-timeout-lib.sh +. "$SCRIPT_DIR/fm-timeout-lib.sh" # Fail closed before any fleet mutation: a no-mistakes gate agent must never spawn # a direct report (see bin/fm-gate-refuse-lib.sh). fm_refuse_if_gate_agent @@ -1389,7 +1400,7 @@ if [ "$RELAUNCH" -eq 1 ]; then } elif [ "$KIND" = secondmate ]; then case "${POS[1]:-}" in - ''|claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp) + ''|claude|codex|opencode|pi|pi-signed|grok|kimi|cursor|gemini|muse|rovo|omp|agy) ARG3=${POS[1]:-} ;; *' '*) @@ -1467,6 +1478,37 @@ omp_model_validate() { # return 1 } +# agy pre-launch model validation. `agy models` (agy 1.2.0) prints one model per +# line as "\t