Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .agents/skills/operational-home-layout/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,7 @@ state/ volatile runtime signals; gitignored
.<id>.open-decisions-cursor per-task byte cursor and folded open-decision set bounding the OPEN DECISIONS scan's cost to new status-log appends; written only by fm-classify-lib.sh's status_open_decisions_incremental, removed by teardown, safe to delete (forces one full re-fold)
.status-presentation-cursor .status-presentation-lock fleet-wide per-task status identity/byte-offset manifest (including the separate STATUS OUTCOME BACKSTOP delivered-frontier offset) and serialization lock preventing already-presented status lines from being replayed as new; owned by fm-classify-lib.sh, with each task's row retired by teardown
.runpod-lifecycle-<id>.lock per-secondmate RunPod provider lifecycle lock; never touch
.<id>.pr-publication.lock per-task PR registration transaction lock held by fm-pr-check.sh while it publishes poll artifacts and replaces pr=/pr_head=/nm_run_id=; fm-watch.sh defers a pre-metadata poll only while it is fresh; never touch
runpod-omp-auth/ workstation OMP broker, read-only facade, and per-pod tunnel supervisor records and logs; never touch
.afk durable away-mode flag; present = sub-supervisor may inject escalations (set by /afk, cleared on user return)
.watch.lock .wake-queue.lock watcher singleton and queue serialization locks
Expand Down
5 changes: 3 additions & 2 deletions .agents/skills/ship-landing/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,9 @@ metadata:
# Ship landing

For PR-based ship tasks, the ready signal depends on mode: `no-mistakes` reports `done: PR <url> checks green` after CI is green, while `direct-PR` reports `done: PR <url>` after opening the PR.
On every PR-ready signal, immediately run `bin/fm-pr-check.sh <id> <PR url>` before reporting the result - it records `pr=` and the forge's `pr_head=` when available in the task's meta and arms the watcher's merge poll, while lock-owning reconciliation through `bin/fm-todo-project.sh --check --reconcile` is the recovery backstop for a skipped arm.
Tell the captain the PR's full URL, always the complete `https://...` link rather than a bare `#number`, a concise outcome summary, and the no-mistakes risk level when applicable.
On every PR-ready signal, immediately run `bin/fm-pr-check.sh <id> <PR url>` before reporting the result - it owns the PR-ready gates, metadata publication, and merge-poll arming, while lock-owning reconciliation through `bin/fm-todo-project.sh --check --reconcile` is the recovery backstop for a skipped arm.
When it refuses, relay its named reason (missing criteria, a run on another branch or PR, a head the pipeline did not validate, an unfinished run, or an unmatched ask-user decision) and steer the worker or decide the finding; never hand-edit task metadata to pass it.
Tell the captain the PR's full URL, always the complete `https://...` link rather than a bare `#number`, a concise outcome summary, and the observed CI result when applicable.
A captain instruction to merge is explicit authority; `yolo` is the only standing routine merge authority.
For any custom `state/<id>.check.sh` you write yourself, keep it an ordinary single-link mode-`0700` file, print one line only when firstmate should wake, print nothing otherwise, finish before `FM_CHECK_TIMEOUT`, then bind its current bytes with `bin/fm-check-register.sh <id>` before the watcher may execute it.
Retire a custom check only through `bin/fm-check-unregister.sh <id>` (or `bin/fm-teardown.sh` for a spawned task); never hand-compose an `rm` with `$STATE`/`$ID`.
Expand Down
18 changes: 8 additions & 10 deletions .agents/skills/validation-supervision/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

# Validation supervision

On a ship worker's implementation-complete `done:`, follow the evidence and validation lifecycle owned by `bin/fm-receipt-check.sh` before accepting completion, returning missing or invalid criteria to the same worker.
Follow its durably recorded path, keep uncertain classifications high, and keep `direct-PR` and `local-only` outside No-Mistakes.
For high-risk `no-mistakes` work, trigger full validation on the same worker using the harness invocation owned by `harness-adapters`.
On a ship worker's implementation-complete `done:`, run `bin/fm-receipt-check.sh <id>` and return missing or invalid criteria to the same worker before anything else; receipts establish only that every declared acceptance criterion was accounted for and certify nothing about review, CI, No-Mistakes completion, or merge readiness.
The delivery mode fixed at intake owns what follows: `direct-PR` and `local-only` stay outside No-Mistakes, and every `no-mistakes` task gets full validation.
For `no-mistakes` work, trigger full validation on the same worker using the harness invocation owned by `harness-adapters`.
The task worker that starts a no-mistakes run drives the pipeline and owns every `no-mistakes axi run` and `no-mistakes axi respond` call through the next gate or outcome.
Firstmate never invokes `no-mistakes axi respond` for a crew-owned run.
Once validation starts, prefer routing new requirements to follow-up work rather than expanding the current task, unless a new requirement completely invalidates the work being validated; however, the smallest downstream changes needed to keep already accepted product or engineering behavior correct, add behavioral tests where an executable contract exists, or keep documentation accurate remain within the current task even when they touch files not named at intake, and corrections required to satisfy already accepted intent are not new requirements.
Expand All @@ -26,17 +26,15 @@ Once ownership is settled, validate exactly once against that final head so no o
An ask-user finding returns as `needs-decision` under the canonical key owned by `bin/fm-nm-run-lib.sh`; firstmate loads `ask-user-authority` and either decides or escalates per that skill.
Send the same worker one exact decision naming the decision key, step, action, affected finding IDs, instructions where needed, and exact response command, passing `--resolve-key` so the worker's open decision record closes at answer time.
Require the matching `resolved` event, forbid `--yes`, and require the worker to process every synchronous return until completion or a genuinely new escalation.
PR-ready and completion apply the bound-run decision check owned by `bin/fm-nm-run-lib.sh`, with the process-evidence limitation owned by `bin/fm-classify-lib.sh`.
Follow the PR-ready and done-acceptance gates owned by `bin/fm-pr-check.sh` and `bin/fm-crew-state.sh`, including their use of the decision check owned by `bin/fm-nm-run-lib.sh` and the process-evidence limitation owned by `bin/fm-classify-lib.sh`.
When that check refuses, decide each named finding per `ask-user-authority` and record the answer through `fm-send`, using the fallback append documented in `bin/fm-nm-run-lib.sh` when no open decision record remains.
Resume fleet supervision immediately after the decision lands.

For ordinary findings from any No-Mistakes tier, steer the original worker to return branch custody through the supported abort and sync sequence, fix the findings itself, and update receipts.
When a finding invalidates a receipt or acceptance claim, use the receipt checker owner to record it before returning branch custody.
After the original worker's fix, return high-risk work to full validation with the updated receipts and delta context.
For ordinary findings, steer the original worker to return branch custody through the supported abort and sync sequence, fix the findings itself, and update receipts.
When a finding shows a criterion unsatisfied, have the worker record a failure receipt for that criterion before the fix and a fresh success after it; the latest receipt per criterion decides it.
After the original worker's fix, return the work to full validation with the updated receipts and delta context.

When a validating run cannot bind because the plan postdates it or the base moved mid-run, keep the current plan and use the receipt checker's supported recovery procedure, owned by the header and help of `bin/fm-receipt-check.sh`.
Use its read-only binding verdict before steering the worker to retry binding the same run.
If the lane diverged, have the worker follow the pipeline's guarded branch-reconciliation guidance before retrying; preserve pipeline custody throughout recovery.
At PR-ready, `bin/fm-pr-check.sh` proves the run from No-Mistakes' own status (task branch, PR URL, full head SHA, passed or CI-green) and records `nm_run_id`; when it refuses a head mismatch, have the worker follow the pipeline's guarded branch-reconciliation guidance and re-report rather than reconciling heads in firstmate.

Judge validation by the currently attributed run step through `bin/fm-crew-state.sh`, not by shell liveness or the last status event.
Running, fixing, or CI states remain working; parked approval or fix-review states require the worker to follow the active gate help; passed or checks-passed is done; failed or cancelled is failed.
Expand Down
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -223,7 +223,7 @@ Supervise all live work under section 8.
### Selected delivery path and merge authority

The selected delivery path owns its own rigor.
Every ship mode keeps the evidence gate, while `bin/fm-receipt-check.sh` owns the binary low/high classifier and validation-path mechanics used inside `no-mistakes` mode.
Every ship mode keeps the evidence gate owned by `bin/fm-receipt-check.sh`, which establishes only that every declared acceptance criterion was accounted for; `no-mistakes` mode always runs full validation, and `bin/fm-pr-check.sh` proves the run and PR identity from No-Mistakes' own status at PR-ready.
Never hold work outside no-mistakes for a manual clean verdict, stack serial manual reviews, or infer authority for one from security, architecture, or risk alone.
A separate review or audit is allowed only when the captain explicitly requests that deliverable or the authorized task is a knowledge-only review; one named question remains scoped to that question.
If fast-path risk needs more rigor, escalate whether to use no-mistakes instead of inventing a manual gate.
Expand All @@ -245,7 +245,7 @@ After an autonomous merge, give the captain a one-line full-URL or local-main ou

### Validate

Load `validation-supervision` on a ship worker's implementation-complete `done:`, whenever a ship starts or already has an active no-mistakes validation run, including a mid-run requirement change or finding, and before deciding or answering any ask-user finding; it owns the evidence gate, run ownership, supersession, finding return, and validation-state judgment.
Load `validation-supervision` on a ship worker's implementation-complete `done:`, whenever a ship starts or already has an active no-mistakes validation run, including a mid-run requirement change or finding, and before deciding or answering any ask-user finding; it owns the evidence-gate handoff, run ownership, supersession, finding return, and validation-state judgment.
Firstmate never invokes `no-mistakes axi respond` for a crew-owned run.

### PR ready, landing, and teardown
Expand Down Expand Up @@ -389,7 +389,7 @@ Preserve durable structured identifiers, dependencies, and completion artifact l
## 11. Crewmate briefs

`bin/fm-brief.sh` and its help own scaffold syntax, generated variants, status protocol, delivery-mode definitions of done, and exact safety mechanics.
Every new ship brief declares stable acceptance-criterion ids and receives an append-only `evidence.jsonl`; `bin/fm-receipt-schema.sh` owns the receipt schema, `bin/fm-receipt-check.sh` owns criterion parsing and completion checking, and scout/report behavior remains separate.
Every new ship brief declares stable acceptance-criterion ids and receives an append-only `evidence.jsonl`; `bin/fm-receipt-schema.sh` owns the receipt schema, `bin/fm-receipt-check.sh` owns criterion parsing and acceptance-evidence accounting, and scout/report behavior remains separate.
Use its scaffold as the contract, then replace every `{TASK}` placeholder with a clear task description, acceptance criteria, constraints, and necessary context before dispatch or seeding.
Keep additions task-specific rather than repeating lifecycle instructions, and alter generated sections only when the task genuinely differs from the standard shape.

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@ The preference persists for the effective Firstmate home, and toggling it off re
# Minutes later:

PR ready for review, captain: https://github.com/you/xyz/pull/42
(fix flaky login test - risk: low - CI green)
(fix flaky login test - CI green)

> alright merge it
```
Expand Down
Loading
Loading