DEV-6633: move the fork to upstream v0.0.45 - #29
Conversation
agentrozjedemeai
left a comment
There was a problem hiding this comment.
Exact-head Steward review (79eb9c9): APPROVED. Independently verified the upstream v0.0.45 tag SHA and no upstream changes under server cloud/cli; range-diff confirms overlay commits 1–5 are patch-identical and the later changes are CI/version pins, inventory, and the docs-only capture rule. The prior immutable release tag is an ancestor of old main, with one docs-only intervening commit carried into the candidate. Local release contract tests 11/11 and diff --check pass. Lazurio Fork CI run 37048990198 succeeded on this exact head, all four jobs green; no unresolved threads. This is QA approval only: PR #29 must not be merged via the merge button, and the Admin main swap and any release require their separate gates.
Status: ready for review — head
79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb,Lazurio Fork CIin the checksMission Control: DEV-6633 (plan update follows in a mission-control-data PR). Tracking: #20.
Why
Upstream published v0.0.45 on 2026-10-02. Matěj asked to refresh the fork on it and use the release as the first full pipeline run where operators pull the stable update themselves with the in-app Update button, instead of a Machines rollout. Every launcher-managed Machine now runs
0.0.44-lazurio.1under launcher protocol 3. v0.0.45 does not changeSERVICE_LAUNCHER_PROTOCOLor any file underapps/server/src/cloudorapps/server/src/cli. So the button's preflight accepts the update and runs it through the launcher trial and database snapshot (the path that #25 blocked from 0.0.42).Exact inputs
v0.0.45→6c8fed35dded9ff71c5b46807125457acbb76be6(v0.0.44is its ancestor)main3e29f93179861967aea024cdc557c5c4d0acb72c=v0.0.44-lazurio.1(0d7c12f456) + one runbook commit79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eebWhat changed against current main
git range-diff v0.0.44..3e29f93179 v0.0.45..79eb9c95d9~1:=), cherry-picked without conflicts;release: publish upstream preview versions as canary pre-releases: CI pinned tov0.0.45/6c8fed35…, archive job0.0.45-lazurio.0, contract-test pins;docs: record what the first preview canary taught the release runbook: overlay inventory column renamed to v0.0.45. Upstream v0.0.45 adds no equivalent for any overlay capability:T3CODE_CLIENT_SESSION_TTL,T3CODE_EXTERNAL_ORIGIN,T3CODE_ENVIRONMENT_LABEL,T3CODE_RELEASE_REPOSITORYandavailableServerUpdateall appear nowhere upstream. All five stayretain. The allowlistallowed_upstream_changesis unchanged: the overlay still touches the same 8 client/shared files.New commit
docs: a docs-only main tip counts as captured by the last release: the main swap gate now accepts a capture release whose tag is an ancestor of the oldmainwhen everything between them is underdocs/. Before, a runbook commit after a release forced a second stable with identical code, which shows every Machine an Update banner for nothing. Matěj (Admin) chose this on 2026-10-02 in the DEV-6633 thread. The matching Organization rule (HumanAndMachine-ai_GEN3AGENTS.md§6) is amended in a separate PR before the swap.Main swap
Gate per the amended runbook step 5, all verified live:
capture:v0.0.44-lazurio.1→0d7c12f456c64a8a2d149d89dcc7bc25a316c417, releaseimmutable: true;git merge-base --is-ancestor 0d7c12f456 3e29f93179: OK;git diff --quiet 0d7c12f456 3e29f93179 -- . ':(exclude)docs/': OK. The only difference isdocs/operations/lazurio-fork-release.md, carried forward here.Swap after Pablo APPROVED on the exact head, all required checks green and zero unresolved threads. One attempt only; a failed lease is not retried:
expected_old_main:3e29f93179861967aea024cdc557c5c4d0acb72ccandidate_head:79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb(updated here if review changes the head)git push --force-with-lease=refs/heads/main:3e29f93179861967aea024cdc557c5c4d0acb72c origin 79eb9c95d9fb3ff0d3ff5ccf478abe9ea1695eeb:refs/heads/mainRelease plan after the swap (separate states)
0.0.45-preview.20261002.1from the newmain, dispatched by Pablo and approved inlazurio-t3code-release. Check SHA256SUMS, attestations and the OCI digest.t3 update <preview>with TTY, after a SQLite backup), with the full runbook checks. Matěj tests it there.0.0.45-lazurio.1only after Matěj's explicit green.0.0.44-lazurio.1on purpose. It must show the banner, and his click must go through the launcher trial and DB snapshot. Other operators then update themselves. There is no Machines re-pin: Machines treatsartifacts.t3.versionas a minimum (workloads/workspace-vm/README.md), so a newer version from the button stays conformant.Verification
Local (macOS arm64, pnpm 11.10.0):
vp fmt --check, server and web typecheck: OK;cliRelease10/10; webversionSkew21/21; release contract 11/11;server.test.ts: two load/order flakes in a full run, a different pair on each run; the flaking tests pass alone. This is the same pattern as on v0.0.44 and vanilla upstream.There are no merge commits in
v0.0.45..HEAD.What deliberately does not change
🤖 Generated with Claude Code
This PR is not safe to merge until the partial-release, preview-download, and Android widget tap regressions are addressed.
Findings
Summary
This PR rebases the Lazurio fork onto upstream v0.0.45 while retaining its hosted-server and update-channel overlay and adding upstream application changes.
Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Verify source and version] --> B[Build and test CLI archives] B --> C[Environment approval] C --> D[Push versioned OCI image] D --> E[Recheck main and create protected tag] E --> F[Publish GitHub Release] E -. failure leaves image published .-> G[Existing-image guard blocks retry]Reviews (1) · Last reviewed commit: "docs: a docs-only main tip counts as cap..."