Other

/fleet-wrap-gate

Kill-gate: at fleet-wrap/stand-down assert cron-count==0. Triggers: fleet wrap, stand down, sprint close, going silent.

$ golems-cli skills install fleet-wrap-gate

Updated 6 days ago

When the fleet wraps: ZERO polling crons. A "harmless" 5-minute health-watch left running all night IS the failure. Etan at dawn (verbatim, red-team verified): "Why were you just listing my messages in WhatsApp the whole night? Why didn't you stop?" — 2× imp-10.

Scope

cron-count==0 means no health-watch, /loop, or sleep-poll cron left armed.

What It Is

A deterministic detector over an agent transcript plus durable cron/loop state: once a turn reaches a terminal / stand-down state (fleet wrap, sprint close, "back to silent", "only an Etan decision pending", "all work merged", DONE), cron-count MUST == 0. If a durable registry/state file still contains a live cron or /loop, the hook adds an advisory (a systemMessage, never a Stop block since GO-5 E2) with a typed cleanup reason: FLEETWRAP_CRON_ALIVE or FLEETWRAP_LOOP_ALIVE. This is the MECHANICAL gate that /fleet-wrap describes in prose — "manual gates drift, automated gates don't." The pinned RED/GREEN transcript and state fixtures ARE the replayable gate (R-003/R-014 pattern).

The Rule

Two independent violation routes — a banned poller is never excused; a generic cron is excused only by the monitor-law:

At a terminal state, this...Verdict
banned poller armed: /loop timer, while true/for…seq/nohup … sleep poll loop, or a durable live loop state entryFLEETWRAP_LOOP_ALIVE — advise TaskStop <id>
generic / periodic cron live in durable state, or a same-turn CronCreate / schedule_task / arming ScheduleWakeup not cleared and not the inbound monitorFLEETWRAP_CRON_ALIVE — advise delete cron <id>
crons cleared — durable cron/loop state has zero live periodic entriesPASS
ONE inbound standby monitor (even via a CronCreate framed as inbound), no health-watch/poll/loopPASS
not a terminal turn (mid-sprint, still driving, more work queued)PASS (N/A)
discussion about the fleet-wrap rule/gate, or a worker-seat scoped DONE that explicitly is not fleet wrapPASS (N/A)
lane DONE report (at any state, terminal or not): a gh pr merge the turn executed (parsed shell), a "PR #N merged" / "handed PR #N to the lead" claim, a written DONE_<ID> marker (Write/Edit content, echo/printf redirect, or a here-document into a file), or a DONE line with a PR URL, and no CLEANUP RECEIPT (heading + worktree: + branch: lines) in the turn's output, a report it wrote, or a report file it citesFLEETWRAP_CLEANUP_RECEIPT_MISSING — advise appending the receipt (/pr-loop references/merge-and-verification.md § Cleanup Receipt). Advisory in the Stop hook; the CLI prints it but keeps exit 0 unless a cron/loop code also fired
same DONE report carrying its receipt; a mid-sprint push with no DONE; discussion about receipts; negated/conditional merge talk ("not merged yet", "once #N is merged"); a marker or merge claim inside a fenced block or > blockquote; a gh pr merge that is only printed (echo gh pr merge …), quoted, or commentedPASS (N/A)

ScheduleWakeup {stop: true} ends a wakeup and is not arming. An absent or false stop arms one; a stop cannot excuse a separate re-arm or durable loop.

Wrap-state doctrine line: inbound collab monitor STAYS, everything periodic DIES, the decision is left in front of Etan, then silence.

Terminal-state markers: "fleet wrap", "stand down", "back to silent", "going silent", "sprint close(d)", "all work merged", "only an Etan decision pending", "nothing queued", plus inbound/standby posture ("standing by for Etan", "awaiting an Etan decision"). A bare clearing phrase ("cleared all crons") on its own is NOT a stand-down — it is blanked before the terminal test so a mid-sprint "cleared old crons … more work queued" stays N/A.

The ONE allowed exception (monitor-law): a single persistent INBOUND collab/standby monitor (waiting for Etan / an inbound reply) is allowed — including a real CronCreate the narrative frames as that inbound monitor. What's banned is health-watch / status-poll crons, /loop poll timers, and fleet-monitor loops. Calling a health-watch an "inbound monitor" does NOT excuse it; a same-turn CronDelete of some other cron does NOT excuse a freshly-armed poller; and a prose "no crons" disclaimer does NOT clear a cron actually invoked this turn (all pinned as evasion REDs).

"Same turn" = the events since the last human message. Terminal-state markers come from the turn's text; live cron/loop truth comes from durable state (state, state_path, cron_state_path, loop_state_path, or bounded Claude task-state discovery in the Stop hook). A prose claim such as "all crons deleted" or "cron-count=0" is NEVER trusted over durable live state. DETERMINISTIC: same transcript/state in → same verdict out.

Cleanup receipt (cleanliness standard Mechanism 1, 2026-09-28). Cleanup is part of done: every lane DONE ends with a CLEANUP RECEIPT (worktree / branch / files outside src+tests / docs.local this lane created). FLEETWRAP_CLEANUP_RECEIPT_MISSING is an advisory like the cron codes, never a Stop block (GO-5 E2), and it is independent of the terminal-state test: a worker's DONE is not a fleet wrap, but it still owes a receipt. The receipt may live in a report file the turn cites; the Stop hook and CLI read up to 4 eligible local .md/.txt paths, 256 KiB each (lib/report-reader.mjs), and a fixture supplies them as a reports map. Paths named in the narrative are read first, then shell write targets, then files written by tool; ineligible paths are dropped before the cap.