Conversation
* fix: file authorized gated work when it is authorized, not at dispatch AGENTS.md section 10 told supervisors to file a backlog item before dispatch, so a later phase authorized behind another item or a date was never filed and stayed invisible to the teardown and session-start re-evaluation. The secondmate charter's "act only on routed tasks" line also read as needing a fresh route for each already-authorized phase. File each item as soon as its work is authorized, including every later phase gated on another item (blocked-by) or a date, and state in the charter that authorized later phases are routed work to file on arrival and dispatch when ready. The generated-charter test asserts the new rule. * no-mistakes(document): Align secondmate routing guidance with authorized phases * no-mistakes(ci): Restored AGENTS.md section 7 to its exact pre-b7fe1d5e routing sentence. No other files changed. git diff --check and fm-doc-audience-check passed. The two CI failures are unrelated pre-existing flakes being handled separately
* fix(bin): keep pending-reply sender and lab viewer identity stable across clock steps The pending-reply recovery sender check and the Herdr lab viewer ownership check identified processes by ps lstart text, which on Linux is the wall-clock-derived boot time plus start ticks. A host clock step (WSL2 steps about every 30 seconds) re-renders it, so a live recovery sender read as dead and a running lab viewer pair read as not owned. Both now use /proc/<pid>/stat start ticks where readable, like fm_pid_identity and task_process_identity, and keep the ps form elsewhere. Records already written in the legacy lstart form are still compared through ps, so an upgrade does not strand an in-flight recovery or a running viewer. * no-mistakes(document): Document clock-stable process identity and legacy records
…#46) * fix(bin): keep Linux remote job worker identity stable across clock steps The remote job worker identified its own processes (lock owner, staging owner, job claims, lanes, command groups) by `ps -o lstart=` text. On Linux, procps renders lstart from the current boot time, which moves whenever the wall clock is stepped (NTP, VM or WSL2 time sync, resume). After a step a healthy worker no longer matched its own lock record, so every remote call started another detached supervisor beside it, the losers restarted for minutes, the serving loop blocked on live lanes it thought had exited, a competing worker reclaimed the live lock, and running jobs were published as "remote job worker stopped before this job completed". - Record Linux process identity as starttime=<stat field 22>, which no clock step moves; Darwin keeps ps lstart, unchanged. - Keep records written by earlier workers comparable: an lstart record is compared as lstart, and a Linux lock owner still recorded as lstart is identified by pid and exact command, so an update replaces it in place and drains supervisors already piled beside it instead of stranding it. - A serving worker that has lost its ownership lock now stops its own active execution and exits on a stop signal instead of re-arming, and never writes quarantine into a lock it does not own. * no-mistakes(document): Document Linux remote worker identity and shutdown behavior
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Bring the firstmate fork (knowttl/firstmate) fully up to date with upstream (kunchenguid/firstmate), keeping the fork fixes that are still needed and dropping the ones that are not.
The captain's decision, following the fork drift review report: keep #44 (authorized follow-on phases: AGENTS.md section 10 tells firstmate to file each item as soon as its work is authorized, including later phases gated on another item or a date, and the secondmate charter treats later phases authorized in a routed message as routed work to file and dispatch), #45 (pending-reply and Herdr-lab process identity uses the Linux /proc start ticks instead of ps lstart so a host clock step does not make a live process read as dead) and #46 (Linux remote job worker process identity uses /proc start ticks, still comparing pre-upgrade lstart records); discard #48 (ready gated backlog work) and discard #49 with its revert (already a no-op).
The captain approved the review's recommended route: reset onto upstream and re-apply only the kept fixes, then fix up the fork's main with a force-push, which is a separate step that needs his explicit word.
What Changed
/procstart ticks for pending-reply senders and Herdr-lab viewers, while continuing to recognize existingps lstartrecords./procstart ticks for remote job worker identity, preserve comparisons with older records, and recognize older workers for in-place replacement.Risk Assessment
Testing
All four targeted test scripts passed. A real named Herdr lab attached and detached a viewer with start-tick ownership, and the remote-job test exercised live worker recovery from a drifted legacy record. Live host clock adjustment was outside the workspace boundary; repository history established the upstream relationship. No UI layout changed, so no screenshot was captured.
bash tests/fm-brief.test.shgenerated and checked the secondmate charterprovision,viewer start,viewer stop, andteardowncompleted; the live ownership record contained/procstart ticksbash tests/fm-remote-job.test.shstarted real workers, injected a drifted legacy lock record, verified one supervisor remained, replaced the worker, and ran a jobEvidence: Live Herdr viewer ownership
Base and landing
This PR targets
upstream-base(a fork branch equal to upstream2d833ff147cd26a5c461e914e06854e0eb2707ce) so it shows exactly the three retained fork commits on top of upstream.The fork's
main(eda9e3f2e72bcf9f0e2228e25853c176680cbb16) is untouched.Landing is a separate step: a
--force-with-leasepush of the validated head to forkmain, naming that SHA, after explicit approval.Nothing in this PR merges or rewrites
main.The fork's CI workflows trigger only for pull requests to
main, so no CI checks register on this base.The pipeline's CI step was therefore skipped by ending its wait (run aborted after push and PR), and the green local validation (rebase, review, test, document, lint, push, PR, all with no findings) is the accepted evidence.
This was decided by the supervising firstmate under the captain's away instructions, because waiting out the four-hour CI timeout could never produce a check.
Kept and dropped
worker_shutdown, with its own tests.worker_lane_identity_matchesnow compares throughfm_remote_job_process_start_for_record, so a pre-upgradeps lstartlane record stays comparable.fm-brief,fm-herdr-lab,fm-pending-reply,fm-remote-job.Known limitation
A legacy Linux lock record written before this change carries no start ticks.
During the one-time upgrade, such a lock that outlives its worker could be mistaken for a PID-reused worker launched with the same command, and that other worker's process tree could be stopped.
This is rare and applies only across the upgrade.
It is #46's existing behavior and was deliberately not redesigned here; it is tracked as a separate follow-up.
How running homes converge after the force-push
The guarded paths never force, so each home needs one manual reset after the force-push.
bin/fm-ff-lib.shadvances only bygit merge --ff-only.A home on the old fork history reports
skipped: diverged.reset --keep) applies only to secondmate homes and only when their whole local result is already in the target.It fails here because fix: surface newly ready gated backlog work #48 is dropped, so those homes stay put and keep a
state/.secondmate-update-reconcile/<id>.pendingrecord.bin/fm-update.shprintsfirstmate: skipped: diverged from origin/main.bin/fm-fleet-sync.shcovers onlyprojects/clones, and/updatefirstmateinherits all of the above.git fetch origin && git reset --keep origin/main, first, because secondmate local sync follows the primary'smain.nextrade-mate-d7,flex-mate-x1):git -C <home> checkout --detach origin/main, clear the stale reconcile marker, thenbin/fm-secondmate-restart.sh.nx-remote-b1on Brytton-Desktop: reset the code root first (bin/fm-remote-secondmate-control.sh updaterefuses on the divergence), then the home, then restart; confirm both are clean and at the old head before resetting.mainafter fix: surface newly ready gated backlog work #48 must be rebased so it does not bring fix: surface newly ready gated backlog work #48 back.fm-ready-work.shdisappears; leftoverstate/.ready-work*files are inert.Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
bash tests/fm-brief.test.shgenerated and checked the secondmate charterprovision,viewer start,viewer stop, andteardowncompleted; the live ownership record contained/procstart ticksbash tests/fm-remote-job.test.shstarted real workers, injected a drifted legacy lock record, verified one supervisor remained, replaced the worker, and ran a jobbash tests/fm-brief.test.shbash tests/fm-pending-reply.test.shbash tests/fm-herdr-lab.test.shbash tests/fm-remote-job.test.shReal named Herdr lab:provision,viewer start, inspect ownership record,viewer stop,teardownLive/procand legacy identity reads throughfm_pending_reply_pid_identityandfm_pending_reply_ps_identitygit merge-base HEAD origin/upstream-base,git diff --name-only origin/upstream-base..HEAD, andgit log origin/upstream-base..HEADgit status --short✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.