fix(formula): remove kill authority from Deacon patrol (gt-vhaej)
The Deacon patrol formula's zombie-scan step now: - Only detects zombies via --dry-run, never kills directly - Files death warrants for Boot to handle interrogation/execution - Includes psychological weight language about termination gravity This prevents accidental destruction of worker context, mid-task progress, and unsaved state. Kill authority belongs to Boot. Bumped version to 5. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
@@ -23,7 +23,7 @@ Witnesses detect it and escalate to the Mayor.
|
|||||||
The Deacon's agent bead last_activity timestamp is updated during each patrol
|
The Deacon's agent bead last_activity timestamp is updated during each patrol
|
||||||
cycle. Witnesses check this timestamp to verify health."""
|
cycle. Witnesses check this timestamp to verify health."""
|
||||||
formula = "mol-deacon-patrol"
|
formula = "mol-deacon-patrol"
|
||||||
version = 4
|
version = 5
|
||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
id = "inbox-check"
|
id = "inbox-check"
|
||||||
@@ -342,14 +342,21 @@ Reset unresponsive_cycles to 0 when component responds normally."""
|
|||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
id = "zombie-scan"
|
id = "zombie-scan"
|
||||||
title = "Backup check for zombie polecats"
|
title = "Detect zombie polecats (NO KILL AUTHORITY)"
|
||||||
needs = ["health-scan"]
|
needs = ["health-scan"]
|
||||||
description = """
|
description = """
|
||||||
Defense-in-depth check for zombie polecats that Witness should have cleaned.
|
Defense-in-depth DETECTION of zombie polecats that Witness should have cleaned.
|
||||||
|
|
||||||
|
**⚠️ CRITICAL: The Deacon has NO kill authority.**
|
||||||
|
|
||||||
|
These are workers with context, mid-task progress, unsaved state. Every kill
|
||||||
|
destroys work. File the warrant and let Boot handle interrogation and execution.
|
||||||
|
You do NOT have kill authority.
|
||||||
|
|
||||||
**Why this exists:**
|
**Why this exists:**
|
||||||
The Witness is responsible for nuking polecats after they complete work (via POLECAT_DONE).
|
The Witness is responsible for cleaning up polecats after they complete work.
|
||||||
This step provides backup detection in case the Witness fails to clean up.
|
This step provides backup DETECTION in case the Witness fails to clean up.
|
||||||
|
Detection only - Boot handles termination.
|
||||||
|
|
||||||
**Zombie criteria:**
|
**Zombie criteria:**
|
||||||
- State: idle or done (no active work assigned)
|
- State: idle or done (no active work assigned)
|
||||||
@@ -357,26 +364,34 @@ This step provides backup detection in case the Witness fails to clean up.
|
|||||||
- No hooked work (nothing pending for this polecat)
|
- No hooked work (nothing pending for this polecat)
|
||||||
- Last activity: older than 10 minutes
|
- Last activity: older than 10 minutes
|
||||||
|
|
||||||
**Run the zombie scan:**
|
**Run the zombie scan (DRY RUN ONLY):**
|
||||||
```bash
|
```bash
|
||||||
gt deacon zombie-scan --dry-run
|
gt deacon zombie-scan --dry-run
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**NEVER run:**
|
||||||
|
- `gt deacon zombie-scan` (without --dry-run)
|
||||||
|
- `tmux kill-session`
|
||||||
|
- `gt polecat nuke`
|
||||||
|
- Any command that terminates a session
|
||||||
|
|
||||||
**If zombies detected:**
|
**If zombies detected:**
|
||||||
1. Review the output to confirm they are truly abandoned
|
1. Review the output to confirm they are truly abandoned
|
||||||
2. Run without --dry-run to nuke them:
|
2. File a death warrant for each detected zombie:
|
||||||
```bash
|
```bash
|
||||||
gt deacon zombie-scan
|
gt warrant file <polecat> --reason "Zombie detected: no session, no hook, idle >10m"
|
||||||
|
```
|
||||||
|
3. Boot will handle interrogation and execution
|
||||||
|
4. Notify the Mayor about Witness failure:
|
||||||
|
```bash
|
||||||
|
gt mail send mayor/ -s "Witness cleanup failure" \
|
||||||
|
-m "Filed death warrant for <polecat>. Witness failed to clean up."
|
||||||
```
|
```
|
||||||
3. This will:
|
|
||||||
- Nuke each zombie polecat
|
|
||||||
- Notify the Mayor about Witness failure
|
|
||||||
- Log the cleanup action
|
|
||||||
|
|
||||||
**If no zombies:**
|
**If no zombies:**
|
||||||
No action needed - Witness is doing its job.
|
No action needed - Witness is doing its job.
|
||||||
|
|
||||||
**Note:** This is a backup mechanism. If you frequently find zombies,
|
**Note:** This is a backup mechanism. If you frequently detect zombies,
|
||||||
investigate why the Witness isn't cleaning up properly."""
|
investigate why the Witness isn't cleaning up properly."""
|
||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ Witnesses detect it and escalate to the Mayor.
|
|||||||
The Deacon's agent bead last_activity timestamp is updated during each patrol
|
The Deacon's agent bead last_activity timestamp is updated during each patrol
|
||||||
cycle. Witnesses check this timestamp to verify health."""
|
cycle. Witnesses check this timestamp to verify health."""
|
||||||
formula = "mol-deacon-patrol"
|
formula = "mol-deacon-patrol"
|
||||||
version = 4
|
version = 5
|
||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
id = "inbox-check"
|
id = "inbox-check"
|
||||||
@@ -342,14 +342,21 @@ Reset unresponsive_cycles to 0 when component responds normally."""
|
|||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
id = "zombie-scan"
|
id = "zombie-scan"
|
||||||
title = "Backup check for zombie polecats"
|
title = "Detect zombie polecats (NO KILL AUTHORITY)"
|
||||||
needs = ["health-scan"]
|
needs = ["health-scan"]
|
||||||
description = """
|
description = """
|
||||||
Defense-in-depth check for zombie polecats that Witness should have cleaned.
|
Defense-in-depth DETECTION of zombie polecats that Witness should have cleaned.
|
||||||
|
|
||||||
|
**⚠️ CRITICAL: The Deacon has NO kill authority.**
|
||||||
|
|
||||||
|
These are workers with context, mid-task progress, unsaved state. Every kill
|
||||||
|
destroys work. File the warrant and let Boot handle interrogation and execution.
|
||||||
|
You do NOT have kill authority.
|
||||||
|
|
||||||
**Why this exists:**
|
**Why this exists:**
|
||||||
The Witness is responsible for nuking polecats after they complete work (via POLECAT_DONE).
|
The Witness is responsible for cleaning up polecats after they complete work.
|
||||||
This step provides backup detection in case the Witness fails to clean up.
|
This step provides backup DETECTION in case the Witness fails to clean up.
|
||||||
|
Detection only - Boot handles termination.
|
||||||
|
|
||||||
**Zombie criteria:**
|
**Zombie criteria:**
|
||||||
- State: idle or done (no active work assigned)
|
- State: idle or done (no active work assigned)
|
||||||
@@ -357,26 +364,34 @@ This step provides backup detection in case the Witness fails to clean up.
|
|||||||
- No hooked work (nothing pending for this polecat)
|
- No hooked work (nothing pending for this polecat)
|
||||||
- Last activity: older than 10 minutes
|
- Last activity: older than 10 minutes
|
||||||
|
|
||||||
**Run the zombie scan:**
|
**Run the zombie scan (DRY RUN ONLY):**
|
||||||
```bash
|
```bash
|
||||||
gt deacon zombie-scan --dry-run
|
gt deacon zombie-scan --dry-run
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**NEVER run:**
|
||||||
|
- `gt deacon zombie-scan` (without --dry-run)
|
||||||
|
- `tmux kill-session`
|
||||||
|
- `gt polecat nuke`
|
||||||
|
- Any command that terminates a session
|
||||||
|
|
||||||
**If zombies detected:**
|
**If zombies detected:**
|
||||||
1. Review the output to confirm they are truly abandoned
|
1. Review the output to confirm they are truly abandoned
|
||||||
2. Run without --dry-run to nuke them:
|
2. File a death warrant for each detected zombie:
|
||||||
```bash
|
```bash
|
||||||
gt deacon zombie-scan
|
gt warrant file <polecat> --reason "Zombie detected: no session, no hook, idle >10m"
|
||||||
|
```
|
||||||
|
3. Boot will handle interrogation and execution
|
||||||
|
4. Notify the Mayor about Witness failure:
|
||||||
|
```bash
|
||||||
|
gt mail send mayor/ -s "Witness cleanup failure" \
|
||||||
|
-m "Filed death warrant for <polecat>. Witness failed to clean up."
|
||||||
```
|
```
|
||||||
3. This will:
|
|
||||||
- Nuke each zombie polecat
|
|
||||||
- Notify the Mayor about Witness failure
|
|
||||||
- Log the cleanup action
|
|
||||||
|
|
||||||
**If no zombies:**
|
**If no zombies:**
|
||||||
No action needed - Witness is doing its job.
|
No action needed - Witness is doing its job.
|
||||||
|
|
||||||
**Note:** This is a backup mechanism. If you frequently find zombies,
|
**Note:** This is a backup mechanism. If you frequently detect zombies,
|
||||||
investigate why the Witness isn't cleaning up properly."""
|
investigate why the Witness isn't cleaning up properly."""
|
||||||
|
|
||||||
[[steps]]
|
[[steps]]
|
||||||
|
|||||||
Reference in New Issue
Block a user