Skip to content

DEV-6633: move the fork to upstream v0.0.45 - #29

Merged
immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.45
Oct 2, 2026
Merged

immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.45

Conversation

@immakermatty

@immakermatty immakermatty commented Oct 2, 2026 •

Copy link
Copy Markdown

Status: ready for review — head 79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb, Lazurio Fork CI in the checks

How to read this PR: the real review surface is git range-diff v0.0.44..3e29f93179 v0.0.45..claude/DEV-6633-t3code-v0.0.45 plus the one new docs commit. GitHub also shows the upstream v0.0.44 → v0.0.45 change (66 commits). Published by the Admin main swap under the rolling contract, not by the merge button.

Mission Control: DEV-6633 (plan update follows in a mission-control-data PR). Tracking: #20.

Why

Upstream published v0.0.45 on 2026-10-02. Matěj asked to refresh the fork on it and use the release as the first full pipeline run where operators pull the stable update themselves with the in-app Update button, instead of a Machines rollout. Every launcher-managed Machine now runs 0.0.44-lazurio.1 under launcher protocol 3. v0.0.45 does not change SERVICE_LAUNCHER_PROTOCOL or any file under apps/server/src/cloud or apps/server/src/cli. So the button's preflight accepts the update and runs it through the launcher trial and database snapshot (the path that #25 blocked from 0.0.42).

Exact inputs

Upstream tag v0.0.45 → 6c8fed35dded9ff71c5b46807125457acbb76be6 (v0.0.44 is its ancestor)
Current fork main 3e29f93179861967aea024cdc557c5c4d0acb72c = v0.0.44-lazurio.1 (0d7c12f456) + one runbook commit
Candidate head 79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb

What changed against current main

git range-diff v0.0.44..3e29f93179 v0.0.45..79eb9c95d9~1:

  • commits 1–5 (session TTL, external origin, environment label, in-app update channel, Lazurio distribution): identical patches (=), cherry-picked without conflicts;
  • release: publish upstream preview versions as canary pre-releases: CI pinned to v0.0.45 / 6c8fed35…, archive job 0.0.45-lazurio.0, contract-test pins;
  • docs: record what the first preview canary taught the release runbook: overlay inventory column renamed to v0.0.45. Upstream v0.0.45 adds no equivalent for any overlay capability: T3CODE_CLIENT_SESSION_TTL, T3CODE_EXTERNAL_ORIGIN, T3CODE_ENVIRONMENT_LABEL, T3CODE_RELEASE_REPOSITORY and availableServerUpdate all appear nowhere upstream. All five stay retain. The allowlist allowed_upstream_changes is unchanged: the overlay still touches the same 8 client/shared files.

New commit docs: a docs-only main tip counts as captured by the last release: the main swap gate now accepts a capture release whose tag is an ancestor of the old main when everything between them is under docs/. Before, a runbook commit after a release forced a second stable with identical code, which shows every Machine an Update banner for nothing. Matěj (Admin) chose this on 2026-10-02 in the DEV-6633 thread. The matching Organization rule (HumanAndMachine-ai_GEN3 AGENTS.md §6) is amended in a separate PR before the swap.

Main swap

Gate per the amended runbook step 5, all verified live:

  • capture: v0.0.44-lazurio.1 → 0d7c12f456c64a8a2d149d89dcc7bc25a316c417, release immutable: true;
  • git merge-base --is-ancestor 0d7c12f456 3e29f93179: OK;
  • git diff --quiet 0d7c12f456 3e29f93179 -- . ':(exclude)docs/': OK. The only difference is docs/operations/lazurio-fork-release.md, carried forward here.

Swap after Pablo APPROVED on the exact head, all required checks green and zero unresolved threads. One attempt only; a failed lease is not retried:

  • expected_old_main: 3e29f93179861967aea024cdc557c5c4d0acb72c
  • candidate_head: 79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb (updated here if review changes the head)
  • git push --force-with-lease=refs/heads/main:3e29f93179861967aea024cdc557c5c4d0acb72c origin 79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb:refs/heads/main

Release plan after the swap (separate states)

  1. Preview 0.0.45-preview.20261002.1 from the new main, dispatched by Pablo and approved in lazurio-t3code-release. Check SHA256SUMS, attestations and the OCI digest.
  2. Canary: Spectoda VM101 only, over SSH (t3 update <preview> with TTY, after a SQLite backup), with the full runbook checks. Matěj tests it there.
  3. Stable 0.0.45-lazurio.1 only after Matěj's explicit green.
  4. Operator-pulled update: Matěj's personal Machine stays on 0.0.44-lazurio.1 on purpose. It must show the banner, and his click must go through the launcher trial and DB snapshot. Other operators then update themselves. There is no Machines re-pin: Machines treats artifacts.t3.version as a minimum (workloads/workspace-vm/README.md), so a newer version from the button stays conformant.

Verification

Local (macOS arm64, pnpm 11.10.0):

  • frozen install, vp fmt --check, server and web typecheck: OK;
  • server config/auth/environment/cloud: 339/339; shared cliRelease 10/10; web versionSkew 21/21; release contract 11/11;
  • server.test.ts: two load/order flakes in a full run, a different pair on each run; the flaking tests pass alone. This is the same pattern as on v0.0.44 and vanilla upstream.

There are no merge commits in v0.0.45..HEAD.

What deliberately does not change

  • No server or client behaviour change beyond the existing overlay.
  • No custom canary channel, no Machines change, no re-pin.
  • Nothing is released, tagged or deployed by this PR.

🤖 Generated with Claude Code

RetriggerConfidence Score: 1/5

This PR is not safe to merge until the partial-release, preview-download, and Android widget tap regressions are addressed.

Findings

  1. P1 Security Unbounded silent preview downloads ▶
  2. P1 Image published before release ▶
  3. P1 Widget taps require running app ▶

Summary

This PR rebases the Lazurio fork onto upstream v0.0.45 while retaining its hosted-server and update-channel overlay and adding upstream application changes.

  • The release workflow can strand a published OCI image without its corresponding tag and GitHub Release.
  • New desktop preview download handling permits unbounded silent saves, and the Android widget loses its native tap-to-open path.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Verify source and version] --> B[Build and test CLI archives]
  B --> C[Environment approval]
  C --> D[Push versioned OCI image]
  D --> E[Recheck main and create protected tag]
  E --> F[Publish GitHub Release]
  E -. failure leaves image published .-> G[Existing-image guard blocks retry]
Loading

Reviews (1) · Last reviewed commit: "docs: a docs-only main tip counts as cap..."

Comment thread apps/desktop/src/preview/Manager.ts
Comment thread .github/workflows/lazurio-release.yml
Comment thread apps/mobile/src/widgets/publishSubscriptionUsage.android.ts

@agentrozjedemeai agentrozjedemeai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head Steward review (79eb9c9): APPROVED. Independently verified the upstream v0.0.45 tag SHA and no upstream changes under server cloud/cli; range-diff confirms overlay commits 1–5 are patch-identical and the later changes are CI/version pins, inventory, and the docs-only capture rule. The prior immutable release tag is an ancestor of old main, with one docs-only intervening commit carried into the candidate. Local release contract tests 11/11 and diff --check pass. Lazurio Fork CI run 37048990198 succeeded on this exact head, all four jobs green; no unresolved threads. This is QA approval only: PR #29 must not be merged via the merge button, and the Admin main swap and any release require their separate gates.

@immakermatty
immakermatty merged commit 79eb9c9 into main Oct 2, 2026
8 checks passed
@agentrozjedemeai
agentrozjedemeai deployed to lazurio-t3code-release October 2, 2026 19:08 — with GitHub Actions Active
@agentrozjedemeai
agentrozjedemeai deployed to lazurio-t3code-release October 2, 2026 20:10 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
lazurio-t3code-release — 79eb9c95 Deployed Oct 2, 2026 by agentrozjedemeai via Publish release and image #15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants