Skip to content

[firstmate#1214] feat(bin): add inert private Telegram bridge with enforced publish ... #1853

Description

@github-actions

Decision needed - firstmate#1214

PR review by yelenplays · merge-ready

feat(bin): add inert private Telegram bridge with enforced publish gate

Situation

  • Compliance: pass
  • Tests: green
  • Configured checks: PR must be raised via no-mistakes (compliance: pass), Behavior portable parallel 1 (informational: pass), Behavior portable parallel 2 (informational: pass), Behavior portable serial (informational: pass), Behavior timing aggregate (informational: pass), Lint shell scripts (informational: pass), Repo invariants (informational: pass), Stock macOS Bash snapshot compatibility (informational: pass), Test coverage guard (informational: pass), Behavior tests (Herdr) (test: pass)
  • Freshness: complete target observation as of 2026-07-29T12:18:45Z
  • Notes: compliance=pass tests=green

Related work

Note

Related-work context is truncated (comparison_incomplete): comparison across open pull requests is incomplete, so a relation may be missed; this says nothing about the target itself. The candidate list, shared paths, and references are advisory display only and never an overlap or action gate.

Wheelhouse cannot claim that no related work exists.

Auto-merge criteria

Note

Read-only preflight from the authoritative auto-merge evaluator. A displayed MET result never authorizes a merge: Wheelhouse re-evaluates every gate and performs G7 immediately before acting.

Scope

  • MET Scope - merge-ready PR review - kind=pr-review bucket=merge-ready

Safety

  • MET Safety - complete healthy scan - candidate came from a complete healthy scan
  • MET Safety - target PR is open - target PR is open and unmerged
  • MET Safety - no per-PR auto-merge opt-out - wheelhouse:no-auto-merge is absent
  • MET Safety - head SHA unchanged - scan and live head 032932d6

G0 (repo)

  • MET G0 - repository auto-merge enabled - enabled by effective repository policy
  • UNAVAILABLE G0 - default-branch VISION.md present - VISION.md missing or unreadable on the default branch

G1 (card)

G2 (files)

  • MET G2 - complete immutable file list - 48 immutable changed path entries read
  • MET G2 - workflow and security exclusions clear - no unconditional workflow/security/governance exclusions

G3 (author)

  • MET G3 - non-maintainer human contributor - yelenplays is a non-maintainer human
  • UNMET G3 - prior merged contribution in this repo - G3 author yelenplays has no prior merged PR in firstmate

G4 (checks)

  • MET G4 - configured checks green - comp=pass tests=green (merge-ready)
  • MET G4 - PR mergeable - live mergeable is MERGEABLE
  • MET G4 - merge state clean - live merge state is CLEAN

G5 (size)

  • UNMET G5 - changed-file limit - 48 changed files > 20
  • UNMET G5 - changed-line limit - 7749 changed lines > 1000

G6 (triage + behavior)

  • MET G6 - automatic triage credential configured - model credential is configured; card triage eligibility is evaluated separately
  • MET G6 - successful triage for current head - successful triage for head 032932d6
  • MET G6 - top-level recommendation is merge - explicit merge recommendation
  • UNMET G6 - eligible behavior class - behavior class 'INELIGIBLE' is not an eligible A/B/C class
  • UNMET G6 - existing/default behavior unchanged - existing/default behavior change not ruled out
  • UNAVAILABLE G6 - class C is opt-in and default-off - not evaluated because behavior class is invalid
  • VISION.md-dependent checks - needs VISION.md
    • UNAVAILABLE G6 - behavior aligns with VISION.md - not evaluated because a trusted default-branch VISION.md is required
    • UNAVAILABLE G6 - behavior verdict recommends merge - not evaluated because a trusted default-branch VISION.md is required
    • UNAVAILABLE G6 - verdict uses current VISION.md revision - not evaluated because a trusted default-branch VISION.md is required
    • UNAVAILABLE G6 - verdict uses current base revision - not evaluated because a trusted default-branch VISION.md is required

G7 (final gate)

  • UNAVAILABLE G7 - immediate live recheck and manual merge gate - runs only immediately before merge: card claim, VISION, head/base, mergeability, checks, opt-out label, and unchanged manual workflow gate

Triage

  • Summary: Adds an inert-by-default private Telegram bridge (five new bin/ scripts, a new skill, three new shared libraries, an 82-check test suite, docs, and a two-step publish gate) while simultaneously moving X-mode's watcher cadence from a sourced config/x-mode.env to a byte-authenticated shim derivation, tightening the arm seatbelt to bless no source nodes at all.
  • Product implications: Owner discussion warranted: the Telegram bridge itself is strictly opt-in and inert without FM_TELEGRAM_BOT_TOKEN, but the coordinated X-mode cadence change (config/x-mode.env content, fm-arm-command-policy.mjs seatbelt, fm-claude-stop-autoarm.sh, fm-watch.sh) changes the mechanism for an existing opted-in feature and will reject previously-allowed arm commands that include 'source config/x-mode.env' until the user re-runs bootstrap to regenerate them.

Warning

Primary model validation failed (output.schema_invalid), and its single correction passed complete trusted validation.
Recommendation authority comes from that corrected result for this exact revision.

Recommended action

  • Agent recommendation: merge
  • Reason: Four adversarial review rounds closed all findings; two revert-and-rebreak proofs confirm non-vacuous test coverage; 82 telegram-bridge, 20 fm-pr-merge, and 102 fm-x-mode checks all pass; the X-mode mechanism change is a coordinated security hardening that removes the shell-execution vector the sourced cadence file created while preserving the 30s cadence end behavior via shim validation; no open findings remain.

From the current admitted automatic triage assessment for this exact revision. Tick Accept recommendation to apply it - it is advisory and never an auto-merge authorization.

Your decision

Tick one box for a quick call, or reply with a slash-command (/merge, /close, /decline <reason>, /hold, /comment <text>, /request-changes <text>):

  • Accept recommendation
  • Merge it
  • Close / decline
  • Investigate - deep code-grounded review (leaves this card open)
  • Hold - I'll handle this manually

Only the repository owner can drive this decision - everyone else's edits and comments are ignored.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions