Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
222 commits
Select commit Hold shift + click to select a range
7a863f7
clarify PR ready review checks
ruby-dlee Jul 10, 2026
88ab966
Harden session lock identity
ruby-dlee Jul 10, 2026
50f0841
no-mistakes(document): document two-line session lock format in AGENT…
ruby-dlee Jul 10, 2026
732d4d4
feat: isolate browser sessions per spawn
ruby-dlee Jul 10, 2026
7d08b4c
fix: harden browser isolation lifecycle
ruby-dlee Jul 10, 2026
ff0936c
merge: sync official upstream through cb6e8ed
ruby-dlee Jul 12, 2026
d444db6
test: include composer helper in gotmp teardown fixture
ruby-dlee Jul 12, 2026
8df5ef7
Revert "fix: harden browser isolation lifecycle"
ruby-dlee Jul 12, 2026
11a2cc2
Revert "feat: isolate browser sessions per spawn"
ruby-dlee Jul 12, 2026
6bfac2c
Revert "clarify PR ready review checks"
ruby-dlee Jul 12, 2026
09769ac
no-mistakes(review): fix lock test cleanup and legacy one-line lock l…
ruby-dlee Jul 12, 2026
e1a6efb
no-mistakes(test): skip Pi TypeScript extension tests on older node
ruby-dlee Jul 12, 2026
2d8143f
no-mistakes(document): document node .ts-import test skip gate in CON…
ruby-dlee Jul 12, 2026
19427c4
merge: sync official upstream through 9ecd7c4
ruby-dlee Jul 12, 2026
4490693
no-mistakes(document): document six missing bin scripts in docs/scrip…
ruby-dlee Jul 12, 2026
07044d1
no-mistakes(ci): restore executable bit on tests/fm-lock.test.sh
ruby-dlee Jul 12, 2026
dad99f5
Merge pull request #1 from ruby-dlee/codex/firstmate-ready-20260712
ruby-dlee Jul 12, 2026
fda33a0
merge: sync official upstream through 8c0d9eb
ruby-dlee Jul 15, 2026
055868c
Merge pull request #3 from ruby-dlee/sync/upstream-8c0d9eb
ruby-dlee Jul 15, 2026
55c512b
feat: add default-off agent account routing
ruby-dlee Jul 14, 2026
28a6d3f
no-mistakes(review): Captain: harden Agent Fleet routing and continua…
ruby-dlee Jul 14, 2026
415ae98
no-mistakes(review): Captain: harden Agent Fleet lifecycle ownership
ruby-dlee Jul 14, 2026
ca8f735
no-mistakes(review): Captain: harden managed recovery lifecycle owner…
ruby-dlee Jul 14, 2026
33bc9e0
no-mistakes(review): Captain, harden managed account routing lifecycle
ruby-dlee Jul 14, 2026
fa81be8
no-mistakes(review): Captain, harden agent routing lifecycle invariants
ruby-dlee Jul 14, 2026
06f5ca0
feat: add durable completion report stack
ruby-dlee Jul 14, 2026
d3ddd4c
no-mistakes(review): Captain, harden agent lifecycle and report retries
ruby-dlee Jul 14, 2026
82cce4c
no-mistakes(review): Captain, harden fleet lifecycle and audit durabi…
ruby-dlee Jul 14, 2026
81f93c4
no-mistakes(review): Captain, harden fleet lifecycle and report publi…
ruby-dlee Jul 14, 2026
e43523f
no-mistakes(review): Captain, harden fleet locks and report safety
ruby-dlee Jul 14, 2026
e02b47d
no-mistakes(review): Captain, preserve respawn metadata and reject st…
ruby-dlee Jul 14, 2026
1810367
no-mistakes(review): Captain, harden fleet recovery and control-plane…
ruby-dlee Jul 14, 2026
115161a
no-mistakes(review): Captain, harden fleet lifecycle and report safety
ruby-dlee Jul 14, 2026
4f9d47f
no-mistakes(review): Captain, harden fleet recovery, locks, timeouts,…
ruby-dlee Jul 14, 2026
7cf6afe
fix: complete fleet recovery and report enforcement
ruby-dlee Jul 14, 2026
43a506e
no-mistakes(review): Captain, harden fleet lifecycle safety and porta…
ruby-dlee Jul 14, 2026
5b9ef61
no-mistakes(review): Captain, harden fleet lifecycle and report safety
ruby-dlee Jul 14, 2026
c61812d
no-mistakes(review): Captain, harden fleet and report crash recovery
ruby-dlee Jul 14, 2026
0a56edd
no-mistakes(review): Captain, serialize metadata writes and cmux reco…
ruby-dlee Jul 14, 2026
3c5ebdc
no-mistakes(review): Captain, move PR lookup outside metadata lock
ruby-dlee Jul 15, 2026
fedddbf
no-mistakes(review): Captain, preserve ship completion reports across…
ruby-dlee Jul 15, 2026
cb59312
no-mistakes(review): Captain, fix Herdr absent-pane recovery
ruby-dlee Jul 15, 2026
033522e
no-mistakes(review): Captain, harden lifecycle locking and endpoint r…
ruby-dlee Jul 15, 2026
8fb36b1
no-mistakes(review): Captain, harden Herdr identity and AFK gate safety
ruby-dlee Jul 15, 2026
4ee95e6
no-mistakes(review): Captain, harden fleet lifecycle safety boundaries
ruby-dlee Jul 15, 2026
560ac1c
no-mistakes(review): Captain, harden AFK and secondmate recovery life…
ruby-dlee Jul 15, 2026
747b016
no-mistakes(review): Captain, harden fleet lifecycle and continuation…
ruby-dlee Jul 15, 2026
61f2033
no-mistakes(review): Captain, bound continuation snapshots before ass…
ruby-dlee Jul 15, 2026
950a546
no-mistakes(review): Captain, harden continuation and report teardown…
ruby-dlee Jul 15, 2026
f3eea14
no-mistakes(review): Captain, harden backend creation rollback safety
ruby-dlee Jul 15, 2026
b42adcd
no-mistakes(review): Captain, harden fleet lifecycle and reporting sa…
ruby-dlee Jul 15, 2026
fbcc0c9
no-mistakes(review): Captain, harden fleet lifecycle and reporting sa…
ruby-dlee Jul 15, 2026
c327e57
no-mistakes(review): Captain, harden fleet lifecycle and artifact safety
ruby-dlee Jul 15, 2026
8b37225
no-mistakes(review): Captain, harden rollback, context, and wake stag…
ruby-dlee Jul 15, 2026
8eff6be
no-mistakes(review): Captain, harden recovery locks and native launch…
ruby-dlee Jul 15, 2026
5ca9e5c
no-mistakes(review): Captain, harden recovery locks and bounded state…
ruby-dlee Jul 15, 2026
df364aa
no-mistakes(review): Captain, harden lifecycle, AFK, and artifact safety
ruby-dlee Jul 15, 2026
e235bfe
no-mistakes(review): Captain, harden fleet controls and artifact safety
ruby-dlee Jul 15, 2026
2ec66a7
no-mistakes(review): Captain, harden X context and report reads
ruby-dlee Jul 15, 2026
9f1ff4e
no-mistakes(review): Captain, harden lifecycle locks and artifact pro…
ruby-dlee Jul 15, 2026
e905064
no-mistakes(review): Captain, harden lifecycle locks and AFK safety
ruby-dlee Jul 15, 2026
4124837
no-mistakes(review): Captain, harden AFK marker validation and preser…
ruby-dlee Jul 15, 2026
39d56a9
no-mistakes(review): Captain, reject malformed Herdr verification rec…
ruby-dlee Jul 15, 2026
3ed15e6
no-mistakes(test): Captain: fix teardown ordering and refresh endpoin…
ruby-dlee Jul 15, 2026
264b7c4
no-mistakes(test): Captain: fix AFK reclaim race and stale fixtures
ruby-dlee Jul 15, 2026
2eb4224
no-mistakes(test): Captain: fix Herdr tripwire and stale e2e fixtures
ruby-dlee Jul 15, 2026
a3e7374
no-mistakes(test): Captain: guard account-routing failures against er…
ruby-dlee Jul 15, 2026
d787792
no-mistakes(document): Document Agent Fleet and completion reports
ruby-dlee Jul 15, 2026
f31b88a
no-mistakes(lint): Captain: Fix secondmate liveness lint conditional
ruby-dlee Jul 15, 2026
49b8cc6
no-mistakes: apply CI fixes
ruby-dlee Jul 15, 2026
7910fce
no-mistakes: apply CI fixes
ruby-dlee Jul 15, 2026
288c3bf
fix report section fence parsing
ruby-dlee Jul 15, 2026
29a71ac
no-mistakes(review): Captain, harden report parsing and contract writes
ruby-dlee Jul 15, 2026
37a0178
no-mistakes(review): Captain, harden report parsing and steering pers…
ruby-dlee Jul 15, 2026
d999046
no-mistakes(review): Captain, harden report and steering race handling
ruby-dlee Jul 15, 2026
a3cf22e
no-mistakes(review): Captain, harden reports and lifecycle transactions
ruby-dlee Jul 15, 2026
fcbf49d
no-mistakes(review): Captain, harden lease, visual, and steering safety
ruby-dlee Jul 15, 2026
8f26f11
no-mistakes(review): Captain, harden recovery, continuation, sync, an…
ruby-dlee Jul 16, 2026
891005d
no-mistakes(review): Captain, harden continuation, sync, parsing, and…
ruby-dlee Jul 16, 2026
9257ad3
no-mistakes(review): Captain, harden containment, sync fairness, and …
ruby-dlee Jul 16, 2026
ab0a5fd
no-mistakes(review): Captain, harden fleet lifecycle and report reten…
ruby-dlee Jul 16, 2026
c93f08f
no-mistakes(review): Captain, harden retention, artifacts, and fleet …
ruby-dlee Jul 16, 2026
efa6c7e
no-mistakes(review): Captain, harden fleet recovery and report retent…
ruby-dlee Jul 16, 2026
e54209f
no-mistakes(review): Captain, harden retention and recovery race safety
ruby-dlee Jul 16, 2026
4230a09
no-mistakes(review): Captain, harden fleet recovery and retention tra…
ruby-dlee Jul 16, 2026
a0acb47
no-mistakes(review): Captain, harden continuation and fleet recovery …
ruby-dlee Jul 16, 2026
bd453fd
no-mistakes(review): Captain, harden fleet recovery and retention safety
ruby-dlee Jul 16, 2026
3d65620
no-mistakes(review): Captain, harden fleet lifecycle and retention tr…
ruby-dlee Jul 16, 2026
7fc86d2
no-mistakes(review): Captain, harden retention and tmux lifecycle safety
ruby-dlee Jul 16, 2026
69fb52f
no-mistakes(review): Captain, harden retention fencing and continuati…
ruby-dlee Jul 16, 2026
d1c6adc
no-mistakes(review): Captain, harden fleet identity, continuation, an…
ruby-dlee Jul 16, 2026
3c7d373
no-mistakes(review): Captain, harden fleet continuation and retention…
ruby-dlee Jul 16, 2026
38c32e0
no-mistakes(review): Captain, harden retention and lifecycle race safety
ruby-dlee Jul 16, 2026
264a43f
no-mistakes(review): Captain, harden retention and artifact provenanc…
ruby-dlee Jul 16, 2026
ae23fb3
no-mistakes(review): Captain: fix fleet continuation and retention de…
ruby-dlee Jul 16, 2026
6e18561
no-mistakes(review): Captain, enforce retention minimums and legacy P…
ruby-dlee Jul 16, 2026
7ab8f86
no-mistakes(review): Captain, harden continuation transport and reten…
ruby-dlee Jul 16, 2026
f7a0b5f
test: preserve expected routing failure under errexit
ruby-dlee Jul 16, 2026
7b0cbc2
fix: complete managed spawn rollback
ruby-dlee Jul 16, 2026
0d91cc4
test: isolate routing behavior cases
ruby-dlee Jul 16, 2026
428bd68
fix: bound AFK signal cleanup tests
ruby-dlee Jul 16, 2026
e78af11
no-mistakes(review): Bound retention drift and continuation repositor…
ruby-dlee Jul 16, 2026
aa09956
no-mistakes(review): Bound continuation child-process cleanup
ruby-dlee Jul 16, 2026
2336d55
no-mistakes(test): Captain, bound continuation cleanup and refresh te…
ruby-dlee Jul 16, 2026
9f76f8d
no-mistakes(test): Captain, stabilize fleet teardown and report lifec…
ruby-dlee Jul 17, 2026
de1030c
no-mistakes(document): Document fleet routing and report lifecycle
ruby-dlee Jul 17, 2026
221f686
no-mistakes(lint): Suppress intentional ShellCheck single-quote warning
ruby-dlee Jul 17, 2026
648c73f
no-mistakes: apply CI fixes
ruby-dlee Jul 17, 2026
407752b
no-mistakes: apply CI fixes
ruby-dlee Jul 17, 2026
a7e7c20
fix: close agent fleet finalization blockers
ruby-dlee Jul 17, 2026
949fc85
no-mistakes(review): Harden agent fleet lifecycle and report safety
ruby-dlee Jul 17, 2026
40748cb
no-mistakes(test): Restore serialized continuation endpoint revalidation
ruby-dlee Jul 17, 2026
411c5a0
no-mistakes(document): Align fleet routing and report documentation
ruby-dlee Jul 17, 2026
f42a5b4
no-mistakes: apply CI fixes
ruby-dlee Jul 17, 2026
367b699
no-mistakes: apply CI fixes
ruby-dlee Jul 17, 2026
6c9b383
no-mistakes: apply CI fixes
ruby-dlee Jul 17, 2026
acb8906
fix: harden agent fleet lock recovery
ruby-dlee Jul 17, 2026
3fee4bb
no-mistakes(review): Enforce actionable reports and native continuati…
ruby-dlee Jul 17, 2026
9d243ea
no-mistakes(document): Align fleet routing and report documentation
ruby-dlee Jul 17, 2026
d9c4b0c
fix: complete fleet report and tmux contracts
ruby-dlee Jul 17, 2026
8b93512
no-mistakes(review): Reject bare Markdown container markers in comple…
ruby-dlee Jul 17, 2026
c5f00a0
no-mistakes(document): Align fleet report and Orca documentation
ruby-dlee Jul 17, 2026
ec2da0b
Merge pull request #2 from ruby-dlee/codex/agent-fleet-integration
ruby-dlee Jul 17, 2026
7fec6dc
fix: detach Herdr server lifecycle from caller
ruby-dlee Jul 17, 2026
08202f3
no-mistakes(review): Fix Herdr preflight and single-parent baseline r…
ruby-dlee Jul 17, 2026
8d9f534
no-mistakes(review): Gate baseline fallback and guide Herdr dependenc…
ruby-dlee Jul 17, 2026
ea5f7b3
no-mistakes(test): Fix baseline fixture helper dependencies
ruby-dlee Jul 17, 2026
c08098d
no-mistakes(document): Refresh Herdr detached lifecycle documentation
ruby-dlee Jul 17, 2026
94d74ee
no-mistakes(lint): Captain: fix detached Herdr lint findings
ruby-dlee Jul 17, 2026
906f9c8
Merge pull request #4 from ruby-dlee/codex/herdr-server-detach
ruby-dlee Jul 17, 2026
ac74baa
feat(agent-fleet): add crash-safe Bridge account cutover (#6)
ruby-dlee Jul 19, 2026
4860464
fix(bridge-cutover): unblock preparer planning against real git-backe…
ruby-dlee Jul 19, 2026
6b67114
test(bridge-cutover): gate synthetic agent_fleet fixture against the …
ruby-dlee Jul 20, 2026
b4b1603
fix(bridge-cutover): accept the pinned post-cutover state so worker-s…
ruby-dlee Jul 20, 2026
bf7c5ad
feat(bridge-cutover): refresh runtime-switched bundle identity in pla…
ruby-dlee Jul 22, 2026
ac3094f
docs: sharpen learnings skill boundary (#14)
ruby-dlee Jul 22, 2026
39ab99c
feat: add operating fundamentals for pure orchestration (#10)
ruby-dlee Jul 22, 2026
184bd29
docs: add safe EKS usage guidance (#13)
ruby-dlee Jul 22, 2026
6be4c7c
docs(agents): add fleet-wide skill authoring standard (#12)
ruby-dlee Jul 22, 2026
609cf8b
feat: add safe actionable Lavish decision boards (#11)
ruby-dlee Jul 22, 2026
10f2156
docs: preserve captain goal fidelity (#16)
ruby-dlee Jul 22, 2026
27b635c
Add private memory hygiene discipline (#17)
ruby-dlee Jul 22, 2026
22090c3
fix: wake native away mode on captain-relevant events (#18)
ruby-dlee Jul 22, 2026
ca4e068
feat: surface permission-blocked crews (#19)
ruby-dlee Jul 22, 2026
7fe76a0
feat: preserve Firstmate continuity across Claude context compaction …
ruby-dlee Jul 22, 2026
44b764e
feat: add macOS permission diagnostics and guidance (#21)
ruby-dlee Jul 22, 2026
2f2fec9
fix: strengthen goal fidelity and live-state freshness (#22)
ruby-dlee Jul 23, 2026
610f55d
Launch crews from account directories
ruby-dlee Jul 23, 2026
9ceada3
Make bootstrap backend tests hermetic
ruby-dlee Jul 23, 2026
4cb474a
no-mistakes(review): Fix direct account routing and secondmate recovery
ruby-dlee Jul 23, 2026
c264874
no-mistakes(review): Complete direct account routing cutover fixes
ruby-dlee Jul 23, 2026
feb6c44
no-mistakes(review): Preserve direct recovery context and actionable …
ruby-dlee Jul 23, 2026
4e0d3c4
no-mistakes(review): Harden direct recovery identity and retained end…
ruby-dlee Jul 23, 2026
8dee67e
no-mistakes(review): Harden direct recovery worktree identity validation
ruby-dlee Jul 23, 2026
98a9bb7
no-mistakes(review): Harden direct routing recovery identity and reta…
ruby-dlee Jul 23, 2026
18fd38d
no-mistakes(review): Finalize direct recovery identity and cleanup li…
ruby-dlee Jul 23, 2026
359f9d0
no-mistakes(review): Defer direct secondmate sync to guarded recovery
ruby-dlee Jul 23, 2026
a4dbcaf
no-mistakes(review): Restore legacy secondmate routing scope
ruby-dlee Jul 23, 2026
295ec04
no-mistakes(test): Fix legacy continuation missing-brief fixture
ruby-dlee Jul 23, 2026
f036ae7
Fix account launch shell lint
ruby-dlee Jul 23, 2026
478f9ec
Keep worktree seeds fresh
ruby-dlee Jul 23, 2026
b176e90
no-mistakes(review): Harden checkout freshness and acquisition rollback
ruby-dlee Jul 23, 2026
172e7a0
no-mistakes(review): Harden checkout acquisition and refresh safety
ruby-dlee Jul 23, 2026
d3ceac3
no-mistakes(review): Protect dirty Treehouse worktrees with durable l…
ruby-dlee Jul 23, 2026
82a902a
no-mistakes(review): Harden Treehouse coverage and rollback verification
ruby-dlee Jul 23, 2026
f85ffb2
no-mistakes(review): Harden checkout discovery and synchronization in…
ruby-dlee Jul 23, 2026
4af9932
no-mistakes(review): Harden checkout acquisition and teardown safety
ruby-dlee Jul 23, 2026
f53483f
no-mistakes(review): Harden checkout discovery and teardown proof
ruby-dlee Jul 23, 2026
4b7e3a2
no-mistakes(review): Serialize all Treehouse return paths
ruby-dlee Jul 23, 2026
db2cc99
no-mistakes(review): Harden locked Treehouse return safety
ruby-dlee Jul 23, 2026
8c82e56
no-mistakes(review): Harden Treehouse return failure cleanup
ruby-dlee Jul 23, 2026
83b1c2b
no-mistakes(review): Harden bounded process-group cleanup
ruby-dlee Jul 23, 2026
e762206
no-mistakes(review): Harden checkout lock and process ownership protocol
ruby-dlee Jul 23, 2026
2a8dc76
no-mistakes(review): Document deferred checkout ownership edges
ruby-dlee Jul 23, 2026
9b04f20
no-mistakes(review): Separate scheduler liveness from coverage health
ruby-dlee Jul 23, 2026
41357ba
no-mistakes(review): Separate checkout coverage from scheduler liveness
ruby-dlee Jul 23, 2026
413219d
no-mistakes(review): Require exact roots during checkout reinspection
ruby-dlee Jul 23, 2026
578eba4
no-mistakes(review): Harden bounded process-group cleanup
ruby-dlee Jul 23, 2026
c60126a
no-mistakes(review): Harden checkout lock and process ownership protocol
ruby-dlee Jul 23, 2026
ef31ec0
no-mistakes(review): Harden checkout refresh and teardown safety
ruby-dlee Jul 23, 2026
b778217
no-mistakes(review): Harden refresh coverage and teardown ownership
ruby-dlee Jul 23, 2026
cd14c34
no-mistakes(review): Harden refresh, teardown, and Orca safety
ruby-dlee Jul 23, 2026
6a1930f
no-mistakes(review): Harden refresh and teardown lifecycle safety
ruby-dlee Jul 23, 2026
80cd343
no-mistakes(review): Harden checkout refresh and lifecycle safety
ruby-dlee Jul 23, 2026
d88cc0b
no-mistakes(review): Harden checkout and teardown authority boundaries
ruby-dlee Jul 23, 2026
91a252e
no-mistakes(review): Harden durable refresh and secondmate lifecycle …
ruby-dlee Jul 23, 2026
f41cd95
no-mistakes(review): Captain: harden refresh migration and secondmate…
ruby-dlee Jul 23, 2026
1299fc6
no-mistakes(review): Captain: harden refresh migration and retirement…
ruby-dlee Jul 23, 2026
072d08a
no-mistakes(review): Captain: harden scheduler identity and retiremen…
ruby-dlee Jul 23, 2026
f6fe92e
no-mistakes(review): Harden scheduler identity and teardown data safety
ruby-dlee Jul 24, 2026
5ad1194
no-mistakes(review): Harden teardown authority and scheduler validation
ruby-dlee Jul 24, 2026
28dba4b
Harden destructive teardown boundaries
ruby-dlee Jul 24, 2026
50b1356
fix(herdr): keep peek/steer working when firstmate runs inside herdr
ruby-dlee Jul 24, 2026
40b2f8e
fix(checkout-refresh): do not fail pool-preflight on an uninspectable…
ruby-dlee Jul 24, 2026
9858e76
fix(herdr): allow spawning into an occupied adapter-owned drifted server
ruby-dlee Jul 24, 2026
cc0c56c
feat(herdr): launch crews through herdr's native agent API
ruby-dlee Jul 25, 2026
8a92a35
fix(teardown): stop refusing a worktree that merely contains symlinks
ruby-dlee Jul 25, 2026
52ffbf8
perf(checkout-refresh): stop paying a fleet-wide scan on every spawn
ruby-dlee Jul 25, 2026
6bcd539
perf(checkout-refresh): make the pool sweep scale linearly, not quadr…
ruby-dlee Jul 25, 2026
d31db10
fix(spawn): hand crewmates a PATH that can actually see the toolchain
ruby-dlee Jul 25, 2026
6f15e5e
fix(spawn): quote the empty local so shellcheck stops reading it as a…
ruby-dlee Jul 25, 2026
b6873f5
brief: require using the feature before calling it done
ruby-dlee Jul 25, 2026
3e9d45f
report-contract: state the heading level crews must use
ruby-dlee Jul 25, 2026
32c8606
test(account-directory): repair three stale spawn fixtures
ruby-dlee Jul 25, 2026
44d25e4
fix(spawn): clean up failed direct spawns
ruby-dlee Jul 25, 2026
460f6be
fix: restore green shell and rollback checks
ruby-dlee Jul 25, 2026
c3cb1b6
test(account-routing): assert the report sections, not the sentence l…
ruby-dlee Jul 25, 2026
4854842
test(account-routing): bound metadata gate waits
ruby-dlee Jul 25, 2026
4579966
Clarify crew vocabulary in prose
ruby-dlee Jul 25, 2026
e8e12bc
no-mistakes(document): Correct stale crewmate doc comments
ruby-dlee Jul 25, 2026
8ddc00a
no-mistakes: apply CI fixes
ruby-dlee Jul 25, 2026
61471eb
no-mistakes: apply CI fixes
ruby-dlee Jul 25, 2026
1035d76
no-mistakes: apply CI fixes
ruby-dlee Jul 25, 2026
fe94d84
Keep vocabulary sweep within prose scope
ruby-dlee Jul 25, 2026
3e597f4
fix: prevent failed direct spawns from leaking worktrees (#32)
ruby-dlee Jul 26, 2026
6d55427
fix: verify passed-run PR state against GitHub (#37)
ruby-dlee Jul 27, 2026
18f29ab
fix(herdr): preserve routing through occupied servers (#39)
ruby-dlee Jul 27, 2026
793de9e
docs: add safe Lavish repair skill
ruby-dlee Jul 28, 2026
6518920
no-mistakes(lint): Fix ShellCheck quoting in lavish repair assertions
ruby-dlee Jul 28, 2026
fd94a5d
no-mistakes: apply CI fixes
ruby-dlee Jul 28, 2026
b634bf4
no-mistakes: apply CI fixes
ruby-dlee Jul 28, 2026
8e6030c
Remove unrelated routing test assertions
ruby-dlee Jul 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
320 changes: 100 additions & 220 deletions .agents/skills/afk/SKILL.md

Large diffs are not rendered by default.

9 changes: 6 additions & 3 deletions .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: bootstrap-diagnostics
description: >-
Agent-only handling playbook for session-start bootstrap diagnostics.
Use whenever the session-start digest's bootstrap section prints any diagnostic or capability line - MISSING, MISSING_MANUAL, BACKEND_INVALID, NEEDS_GH_AUTH, TANGLE, CREW_HARNESS_OVERRIDE, CREW_DISPATCH, FLEET_SYNC, SECONDMATE_SYNC, SECONDMATE_LIVENESS, TASKS_AXI, NUDGE_SECONDMATES, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one.
Use whenever the session-start digest's bootstrap section prints any diagnostic or capability line - MISSING, MISSING_MANUAL, BACKEND_INVALID, ACCOUNT_ROUTING, NEEDS_GH_AUTH, TANGLE, CREW_HARNESS_OVERRIDE, CREW_DISPATCH, FLEET_SYNC, SECONDMATE_SYNC, SECONDMATE_LIVENESS, TASKS_AXI, NUDGE_SECONDMATES, REPORT_RETENTION, or FMX - or when a standalone bin/fm-bootstrap.sh run prints one.
A silent bootstrap section means all good and needs no skill load.
user-invocable: false
metadata:
Expand All @@ -22,6 +22,7 @@ The inline rules in `AGENTS.md` section 3 still bind: detect, then consent, then
For `quota-axi`, bootstrap requires it because crew-dispatch `quota-balanced` may call it; `bin/fm-dispatch-select.sh` still degrades at runtime when quota data is unavailable.
- `MISSING_MANUAL: <tool> (instructions: <url>)` - tell the captain why the tool is required and give them the printed instructions URL, but do not pass the tool to `bin/fm-bootstrap.sh install`; wait for the captain to complete the manual installation, then rerun session start to confirm the dependency is present.
- `BACKEND_INVALID: <name> (known: <names>)` - the resolved runtime backend has no verified dependency or lifecycle contract, so do not dispatch work until the invalid `FM_BACKEND` or `config/backend` value is corrected to one of the listed backends.
- `ACCOUNT_ROUTING: invalid routing policy - <reason>` - the environment or `config/account-routing-mode` cannot resolve to exactly one of `off`, `observe`, or `enforce`; fix the reported source before dispatch because managed spawns will fail closed on the same policy error.
- `NEEDS_GH_AUTH` - ask the captain to run `! gh auth login` (interactive; you cannot run it for them).
- `TANGLE: <remediation>` - the primary checkout is stranded on a feature branch instead of its default branch; `AGENTS.md` section 8 explains why this guard exists and what it protects.
The work is safe on that branch ref; restore the primary to its default branch with the printed `git -C <root> checkout <default>`, then re-validate that branch in a proper worktree.
Expand All @@ -36,14 +37,16 @@ The inline rules in `AGENTS.md` section 3 still bind: detect, then consent, then
- `FLEET_SYNC: <repo>: STUCK: on <state>, N commits behind <base> - needs attention` - the clone is dirty, on a non-default branch, detached with unique commits, or diverged, so the sync left it untouched (never forcing or discarding); it will keep falling behind until you look.
A loud STUCK, especially a growing N across bootstraps, means that clone needs hands-on attention; dispatch a crewmate or resolve it before it strands work.
- `SECONDMATE_SYNC: secondmate <id>: skipped: <reason>` - the local-HEAD secondmate sync left a live secondmate home on its existing checkout because the home was dirty, diverged, unsafe, on the wrong branch, missing the primary target commit, or otherwise not fast-forwardable, or because inheritable-config propagation failed; bootstrap continued, but inspect the reason because the secondmate's tracked instructions or inherited settings may be stale after a primary update.
- `SECONDMATE_LIVENESS: secondmate <id>: already-live|respawned|skipped: <reason>|respawn failed: <reason>` - the session-start liveness sweep checked a live secondmate's recorded endpoint for a real agent process.
Treat `already-live` and `respawned` as handled; investigate `skipped` or `respawn failed` because that secondmate is not guaranteed live.
- `SECONDMATE_LIVENESS: secondmate <id>: <outcome>` - the session-start liveness sweep checked a live secondmate's recorded endpoint for a real agent process.
Treat `already-live`, `respawned`, and `rollback reconciled and respawned` as handled; investigate `skipped` or `respawn failed`, and load `secondmate-provisioning` for any `respawn deferred` outcome because its "Recovery" section owns the required routing decision.
- `TASKS_AXI: available` - a default-backend capability fact, not a problem; record it silently and use `AGENTS.md` section 10 for backlog mutations.
It prints only when `config/backlog-backend` is absent or set to `tasks-axi` and the shared compatibility probe passes (`docs/configuration.md` "Backlog backend").
If the backend is not opted out and `tasks-axi` is missing or incompatible, bootstrap reports the `MISSING: tasks-axi` line but firstmate still hand-edits routine backlog updates and never blocks work.
If `config/backlog-backend=manual`, firstmate hand-edits routine backlog updates and bootstrap does not suggest installing `tasks-axi`.
- `NUDGE_SECONDMATES: fm-<id>...` - the secondmate sweep fast-forwarded one or more *running* secondmate homes to firstmate's current version and their instruction surface (`AGENTS.md`, `bin/`, or `.agents/skills/`) actually changed; send a one-line re-read nudge with `FM_HOME=<this-firstmate-home> bin/fm-send.sh <id> 'firstmate was updated to the latest - please re-read your AGENTS.md to pick up the new instructions.'` unless `FM_HOME` is already set to the active firstmate home.
This mirrors `/updatefirstmate`'s `nudge-secondmates:` report: it is a gentle steer, never an interruption, and the fast-forward already landed safely.
A secondmate that was skipped, already current, or whose advance changed no instructions is not listed and must not be disturbed.
- `REPORT_RETENTION: unavailable: <reason>` - the machine-global report-retention LaunchAgent is absent, stale, unloaded, or has not reported a recent successful prune, so opportunistic bounded pruning remains available but post-minimum-age cleanup is not guaranteed to run while Firstmate is idle.
Surface the failure, wait for the captain's consent, then run `bin/fm-bootstrap.sh install report-retention`; never install or activate it without that consent.
- `FMX: X mode on ...` / `FMX: X mode off ...` - bootstrap confirmed or removed the local X-mode poll artifacts (`docs/configuration.md` "X mode (.env)").
Only when a running watcher needs the cadence transition applied immediately, restart the home-scoped watcher through the emitted harness supervision protocol; bootstrap deliberately never restarts the watcher itself.
51 changes: 51 additions & 0 deletions .agents/skills/crew-steering/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
---
name: crew-steering
description: >-
Agent-only practice for holding crewmates to the captain's bar.
Use before writing or materially revising a crewmate or secondmate brief and before live-steering a crewmate.
Applies ownership, evidence, premise-checking, quality, goal-fidelity, and directness without duplicating their authoritative contracts.
user-invocable: false
metadata:
internal: true
---

# Crewmate steering

Steer every crewmate to the same bar the captain holds firstmate to.
Apply this skill both while writing the initial brief and while live-steering work already in flight.
Keep each brief or steer proportional: name the outcome, constraint, evidence, and next action, then stop.

## Apply it in both modes

When writing a brief, make the expected result, authority boundaries, verification, and definition of done unmistakable.
When live-steering, correct the smallest load-bearing mistake early and require the crewmate to carry the fix through implementation and proof.
In both modes, preserve the captain's actual goal and use the existing owner for detail instead of copying its contract.

## 1. Demand ownership

Require the crewmate to solve and implement the task: it never stops solely because work is hard or failing, it preserves mandated safety `blocked` stops such as unsafe or non-isolated worktree placement, and it exhausts its capability before following the solve-first escalation bar owned by `AGENTS.md` section 9.

## 2. Reject vague or optimistic claims

Treat `almost there` as unfinished, require real evidence because work is not done until proven, and review adversarially rather than rubber-stamping; `AGENTS.md` section 9 owns truthful outcome reporting and section 7's active delivery gate owns proof.

## 3. Fact-check the load-bearing premise

Cheaply test the crewmate's one load-bearing assumption before it acts, rejecting a shallow-false premise without overcorrecting; `operating-fundamentals` section 7 owns the premise-check rule.

## 4. Prefer quality and robustness

Apply the captain's technical-decision bias and reject preserving a leaky component merely to save development cost or sunk work.

## 5. Preserve goal fidelity

Reject any quiet reframing of the task into a smaller win; prime directive 5 and `AGENTS.md` section 9 own the fixed-goal guardrail.

## 6. Be direct and early

Write specific, un-bloated briefs and steers, and correct a wrong path before it is built; `AGENTS.md` section 11 owns the brief contract.

## Finish the steer

End with the concrete result the crewmate must produce, the evidence that will prove it, and the next action it should take.
Do not add motivational padding, duplicate background, or a second copy of an existing procedure.
75 changes: 75 additions & 0 deletions .agents/skills/eks-usage/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
---
name: eks-usage
description: >-
Agent-only operating guide for safe Amazon EKS context verification, kubeconfig setup, authentication diagnosis, and connectivity retries.
Use before running kubectl or EKS commands, when an EKS IAM, authenticator, Unauthorized, Forbidden, TLS, i/o, or connectivity error appears, or when the active cluster or context is uncertain.
user-invocable: false
metadata:
internal: true
---

# EKS usage

This skill owns generic EKS client access and diagnosis, not permission to change a cluster or deploy an application.
Project runbooks and deployment skills remain authoritative for the intended cluster, lane, namespace, and allowed mutations.

## During deployments

Before contacting the cluster control plane during a deploy, read the project's deployment map or runbook and confirm that direct cluster access belongs to the documented lane.
Most managed production deploys use CI, declarative synchronization, or a platform release lane and do not contact the raw cluster API.
If transient TLS, i/o, DNS, or network failures repeat after kubeconfig refresh during a deploy, treat them as a likely wrong-path signal, stop direct cluster retries, and switch to the documented deploy lane.
Reserve the bounded retry procedure below for a confirmed correct direct-access path, because a wrong deploy path is resolved by switching lanes rather than by retrying or escalating it as a connectivity blocker.

## Establish identity and context

1. Run `aws sts get-caller-identity` and confirm the expected AWS account and principal without exposing credentials.
2. Run `kubectl config current-context` and `kubectl config view --minify` to inspect the active cluster, user, and namespace or its default.
3. Before any mutating command, state the intended cluster, context, and namespace and stop if they do not match or cannot be proved.
4. Treat a context change as safety-significant, because `aws eks update-kubeconfig` sets the written file's current context to the selected cluster.
5. Bind mutations to the verified context and namespace instead of relying on ambient defaults.

## Understand `update-kubeconfig`

`aws eks update-kubeconfig --name <cluster> --region <region>` retrieves the cluster endpoint and certificate authority from the EKS control plane and creates or merges kubeconfig entries for the cluster, context, and AWS-backed user.
The AWS identity used for that metadata lookup must be allowed to describe the cluster, while any configured authentication role governs later `kubectl` token generation.
It writes the explicitly selected kubeconfig path, otherwise the first path in `KUBECONFIG`, otherwise the default kubeconfig file.
It replaces an existing entry for the same EKS cluster in that file and makes the generated context current.
The user entry invokes AWS to obtain short-lived authentication when `kubectl` runs; the file does not contain a reusable static Kubernetes bearer token.
Use dry-run when the destination or merge effect is uncertain, and consult `aws eks update-kubeconfig help` for current flags and precedence.
Refreshing kubeconfig fixes stale endpoint, certificate, or generated-entry state, but it cannot grant IAM, EKS access-entry, Kubernetes RBAC, or network access.

## Classify the exact failure

| Signal | Layer | Response |
| --- | --- | --- |
| `AccessDeniedException` from EKS describe or kubeconfig update | AWS IAM before the Kubernetes API | Confirm the AWS identity and intended role, then escalate an actual missing IAM grant instead of debugging the network. |
| `ExpiredToken`, `InvalidClientTokenId`, or missing credentials | Local AWS credential chain before the Kubernetes request | Refresh or select the intended profile or role, then re-run the identity check without printing a token. |
| A generic exec-plugin failure | Local exec invocation or a wrapped nested failure | Classify the nested error first; check for a missing AWS executable, malformed exec stanza, or unsupported exec `apiVersion`, and refresh credentials only when the nested error identifies a credential failure. |
| `Unauthorized` or a server request for credentials from `kubectl` | Kubernetes API authentication after reaching the endpoint | Confirm the generated user role and the cluster's authorized IAM principal or access entry. |
| `Forbidden` from `kubectl` | Kubernetes authorization after successful authentication | Check the verb, resource, and namespace with `kubectl auth can-i`, then escalate the RBAC change if it is outside authority. |
| `dial tcp`, `i/o timeout`, `TLS handshake timeout`, `no route`, or `connection refused` | DNS, route, proxy, firewall, or API-endpoint reachability | Follow the bounded connectivity retry path below rather than requesting IAM. |
| `x509` or certificate validation failure | Kubeconfig CA, clock, or TLS-intercepting proxy | Refresh kubeconfig and inspect clock and proxy state, but never disable certificate verification as a workaround. |

Messages such as `couldn't get current server API group list` are wrappers, so classify the nested final error rather than the wrapper.
A successful `aws eks describe-cluster` proves AWS control-plane authorization and cluster metadata access, not Kubernetes endpoint reachability or workload authorization.
A certificate-verified HTTPS response from the cluster endpoint, including HTTP 401, proves DNS, routing, and TLS reached the API server, but it does not prove `kubectl` authentication.

## Troubleshoot in cheapest-first order

1. Capture the exact command and full error, then verify AWS identity, region, `KUBECONFIG`, current context, cluster, and namespace.
2. For an isolated TLS or transport timeout, retry the same non-mutating probe once after a short pause; a single transient timeout is never a blocker.
3. Confirm the intended target, refresh kubeconfig, recheck the now-current context, and retry a harmless version or namespace read once more after a short bounded backoff.
4. Use EKS describe to confirm that the cluster is active and inspect its endpoint-access mode without changing it.
5. If transport still fails, test DNS and HTTPS reachability to the configured endpoint and inspect VPN, proxy, firewall, private-endpoint routing, and allowed-source requirements.
6. If the endpoint is reachable, return to the IAM, token, access-entry, and RBAC classification instead of continuing network changes.
7. Use `aws eks`, `aws sts`, `aws eks get-token`, `kubectl config`, `kubectl auth`, and `kubectl get --help` for current flags rather than copying stale invocations from old incidents.

## Retry and escalation line

Continue when any bounded retry succeeds, and record the transient only when it affects operational evidence or repeats.
Apply the three-probe budget only to transient connectivity failures such as TLS handshake timeout, i/o timeout, or transient DNS or network errors; escalate when identity and context checks, kubeconfig refresh, and three total non-mutating attempts still fail.
Correct an expired or misselected local credential or role first, because those caller-controlled authentication failures do not require escalation.
Escalate immediately when the intended target cannot be proved or classification confirms an owner-controlled AWS IAM, Kubernetes authentication, EKS access-entry, RBAC, or certificate failure, without spending the connectivity retry budget.
Also escalate persistent evidence of a non-active control plane, private-route or allowlist boundary, or owner-controlled proxy fault.
Include the redacted exact commands and errors, timestamps and attempt count, current context and namespace, AWS identity and region, cluster status and endpoint-access mode, and DNS or HTTPS observations.
Never self-grant IAM or RBAC, edit access entries, expose a private endpoint, widen endpoint CIDRs or security groups, disable TLS verification, or mutate an uncertain context merely to get past an access failure.
2 changes: 2 additions & 0 deletions .agents/skills/firstmate-coding-guidelines/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ metadata:
# firstmate-coding-guidelines

Load this before changing firstmate's shared, tracked material, as defined by `AGENTS.md` section 1.
Load `skill-authoring-standard` before authoring or substantially editing a skill; this skill remains the owner of placement and ownership rules specific to firstmate changes.
It exists because `AGENTS.md` grew from 585 to 958 lines between its last two restructures, entirely from conditional detail added inline instead of routed to its right home.
Applying the rules below on every change is what keeps that from happening again.

Expand All @@ -23,6 +24,7 @@ Before writing a new fact anywhere in this repo, ask where it belongs, in this o
If yes: `AGENTS.md`, inline.
2. Does the agent need it only in a nameable situation - a spawn, a recovery, a specific wake type, a specific lifecycle step?
If yes: an agent-only skill under `.agents/skills/`, plus a one-line trigger pointer left inline in `AGENTS.md` (usually section 13).
For the load-before-doing versus be-aware boundary, use the tie-break owned by `AGENTS.md` section 6's knowledge-routing table.
3. Is it human/reference detail - a wire format, a verification record, a mechanism narrative, an incident writeup?
If yes: `docs/`.
4. Is it mechanics - exact flags, exact commands, exact paths?
Expand Down
Loading