Skip to content

DEV-6633: rebuild the fork on upstream v0.0.43 and release upstream previews as canary - #21

Merged
immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.43
Sep 29, 2026
Merged

immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.43

Conversation

@immakermatty

@immakermatty immakermatty commented Sep 29, 2026 •

Copy link
Copy Markdown

Status: ready for review — head 7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84, Lazurio Fork CI 4/4 green

How to read this PR: GitHub compares with today's main (v0.0.42 + overlay), so it also shows the whole upstream v0.0.42 → v0.0.43 change. The real review surface is only the 6 commits on top of the upstream tag v0.0.43: git diff v0.0.43...claude/DEV-6633-t3code-v0.0.43. This PR is not merged with the button: under the fork's rolling contract (docs/operations/lazurio-fork-release.md) the Organization Admin publishes it with --force-with-lease on main.

Mission Control: DEV-6633 (M2), linked to DEV-6624 and #20.

Why

Upstream released T3 Code v0.0.43. The desktop app connects to T3 on Lazurio Machines, so the fork servers have to catch up. This refresh is also the first real end-to-end test of the update pipeline: an upstream-shaped preview for Spectoda canary Machines → Matěj's test → public stable 0.0.43-lazurio.1 offered by the Update button. Only mechanisms T3 Code already has are used: upstream version-derived channels, t3 update, the launcher with trial and rollback, and the overlay already shipped in v0.0.42-lazurio.1.

Exact inputs

Upstream tag v0.0.43 → 27bdf1aa14e6b946b72fb7013062084ca70796a6 (lightweight tag, peeled = commit; published 2026-09-29 19:14Z)
Previous fork main b6a27feab300e336bda823dd7bbef040034a0b61 = immutable release v0.0.42-lazurio.1
Candidate head see the PR head (updated on every push)

Overlay: remove / retain / migrate

Upstream v0.0.43 offers no equivalent for any overlay capability, so nothing is removed. Every retained commit was re-applied on the new base and migrated to upstream's Effect v4 API names (Config.String, Config.Boolean, Config.mapEffect, …) and to upstream's new update progress UI.

Commit Decision Evidence
hosted: configurable client session TTL retain upstream still has a fixed 30-day DEFAULT_SESSION_TTL; Machines set 365d
hosted: serve behind an explicit HTTPS external origin retain no upstream equivalent for T3CODE_EXTERNAL_ORIGIN
hosted: explicit environment label retain upstream reads only PRETTY_HOSTNAME/hostname; Machines and Organization hosts set T3CODE_ENVIRONMENT_LABEL
feat: in-app update from the configured release channel retain + migrate upstream still hard-codes pingdotgg/t3code and takes the first release of a channel in publish order. The three v0.0.42 commits (configurable repository, advertised availableServerUpdate, whole-index/one-train fix) are one capability commit now; the t3 update path is merged with upstream's new progress output
release: Lazurio distribution retain CI pinned to v0.0.43, 0.0.43-lazurio.0 for the archive job, runbook overlay inventory with this table
release: publish upstream preview versions as canary pre-releases new, the only change beyond the refresh see next section

Allowlist allowed_upstream_changes re-checked: the overlay still changes exactly the same 8 client/shared files and each is still needed (git diff --name-only v0.0.43 HEAD | grep -E '^(apps/(web|mobile|desktop)|packages)/'). No file was added.

The one change beyond the refresh: upstream preview channel in lazurio-release.yml

  • accepts X.Y.Z-preview.YYYYMMDD.N next to X.Y.Z-lazurio.N; X.Y.Z must still equal the upstream tag;
  • the channel is derived from the version exactly as upstream cliReleaseChannelOf does (the contract test imports that function and checks the workflow expression against it);
  • "highest version" now applies within the version's channel, as upstream newestCliReleaseVersion works per channel. Without this, stable 0.0.43-lazurio.1 would be refused after 0.0.43-preview.… (SemVer: lazurio < preview);
  • a preview is published as a GitHub pre-release and never latest, re-checked after publishing; stable stays latest;
  • the reusable archive build (lazurio-cli-archives.yml) accepts the same two shapes; its launcher smoke runs t3 update in a pseudo-terminal and answers upstream's real preview consent prompt only for a preview (a stable target must not see it). The production consent gate is unchanged. (Review round 1: Pablo + Greptile found the archive validator and the TTY gate.)
  • runbook: both channels, canary procedure over SSH (T3CODE_RELEASE_REPOSITORY lives only in the service drop-in, so an SSH shell must export it), return from preview (t3 update --channel stable --allow-downgrade), how vanilla desktop/mobile behave against a fork server, and a correction: Machines set only T3CODE_RELEASE_REPOSITORY, not T3CODE_RELEASE_BASE_URL.

Upstream guarantees relied on (read in v0.0.43 source, to be proven live in the canary): a preview server never checks for updates, a preview is never offered, and t3 update <preview> asks for confirmation in a TTY.

Admin prerequisite before the first preview dispatch (DEV-6633 stop condition): ruleset 24037218 protects only refs/tags/v*-lazurio.* today. The Admin adds refs/tags/v*-preview.* — exact change and readback are in #20.

What deliberately does not change

  • No server or client behaviour beyond the refresh; no custom canary channel, no opt-in switch, no Machines change, no re-pin (the Machines pin is a minimum).
  • Clients, shared packages and wire contracts change only in the same 8 allowlisted files as in v0.0.42-lazurio.1.
  • Nothing is released, tagged or deployed by this PR.

Verification

Local (macOS arm64, pnpm 11.10.0):

  • pnpm install --frozen-lockfile, vp fmt --check, vp run --filter t3 typecheck, vp run --filter @t3tools/web typecheck: OK.
  • apps/server: src/cli/config.test.ts src/auth src/environment src/cloud src/cli/update.test.ts 32 files / 341 tests OK; src/server.test.ts 205/205 OK (one earlier run had 2 order-dependent failures in cloud-health/ws-ticket tests that pass in isolation and in a full rerun; vanilla v0.0.43 204/204).
  • apps/web src/versionSkew.test.ts 21/21, packages/shared src/cliRelease.test.ts 10/10, scripts/install-scripts.test.ts 4/4, node --test scripts/lazurio-release-contract.test.mjs 11/11.
  • The PTY smoke helper was run locally against the real t3 update from this source: preview target → prompt answered, download, SHA256SUMS, extract (a substituted archive then fails the version check as expected); stable target → no prompt; preview with EXPECT_PREVIEW_PROMPT=0 → refused.
  • The channel-scoped version check was run locally against the live release index of this repository: preview and stable 0.0.43 accepted, 0.0.42-lazurio.1 and lower previews refused, a stable after a published preview accepted.
  • Tree after squashing commits is byte-identical to the tested tree.

CI: the PR is CONFLICTING against today's main by design, so pull_request CI does not start; Lazurio Fork CI is dispatched on this branch: run 36634491799 on 7d5e3c2e4e — all 4 required checks green. The preview archive route itself first runs in the preview release's CLI archives job, which gates before the approval and publishes nothing if it fails.

Main swap (filled in before the push)

  • expected_old_main: b6a27feab300e336bda823dd7bbef040034a0b61 (= tag v0.0.42-lazurio.1, release immutable: verified)
  • candidate_head: 7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84 (Pablo APPROVED on this exact head; 4/4 required checks green in run 36634491799; 0 unresolved threads)
  • Command (Admin bypass of ruleset 21717536, one attempt, a failed lease is not retried):
    git push --force-with-lease=refs/heads/main:b6a27feab300e336bda823dd7bbef040034a0b61 origin 7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84:refs/heads/main

🤖 Generated with Claude Code

RetriggerConfidence Score: 4/5

The PR is not ready to merge because preview releases fail before publication.

Findings

  1. P1 Preview archive builds fail ▶

Summary

The PR rebuilds the Lazurio overlay on upstream v0.0.43 and adds preview releases for canary Machines.

  • It retains hosted configuration and the fork’s configured update channel.
  • Preview publication is blocked because the called archive workflow still rejects preview versions.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Dispatch[Preview release dispatch] --> Verify[Verify accepts preview]
  Verify --> Archives[Archive version gate]
  Archives -->|Stable-only pattern rejects preview| Stop[Build fails]
  Archives -->|Success required| Publish[Publish release]
Loading

Reviews (1) · Last reviewed commit: "release: publish upstream preview versio..."

@immakermatty

Copy link
Copy Markdown
Author

Lazurio Fork CI on the exact head c5f4ceb (workflow_dispatch, because the PR is CONFLICTING against today's main by design): https://github.com/Lazurio/t3code/actions/runs/36632741663

Comment thread .github/workflows/lazurio-cli-archives.yml Outdated

@agentrozjedemeai agentrozjedemeai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@immakermatty — exact-head review of c5f4ceb (upstream v0.0.43 + six overlay commits). REQUEST_CHANGES: the preview canary cannot pass the required archive pipeline.

  1. P1 — .github/workflows/lazurio-cli-archives.yml:60: the reusable build job still validates only X.Y.Z-lazurio.N, while lazurio-release.yml:133 passes it the new preview version. Reproduced locally: 0.0.43-preview.20260929.1 passes the release validator but fails the archive validator. Both archive builds stop before checkout/build. The green workflow_dispatch run used 0.0.43-lazurio.0, so it did not exercise this route. Extend the archive validator and cover both shapes at the caller/callee boundary.

  2. P1 — .github/workflows/lazurio-cli-archives.yml:195-197: even after fixing the regex, the launcher smoke executes node apps/server/src/bin.ts update "$VERSION" ... --yes in a non-interactive Actions shell. For a preview target, apps/server/src/cli/update.ts:325-340 requires a TTY and an explicit confirmation when starting from the unstamped stable 0.0.43 source; --yes covers only service restart, not preview consent. This job will fail before archive validation. Keep the real preview-consent safety gate; make the smoke exercise the interactive path with a controlled TTY/confirmation, or add an appropriate separately tested non-interactive preview fixture without weakening production behavior.

The local release contract test passes 9/9 despite both gaps. CI on this exact SHA is green (run 36632741663), but covers only the stable-shaped archive. git diff --check v0.0.43 HEAD is clean. Also before first preview dispatch, Admin must extend ruleset 24037218 to refs/tags/v*-preview.* and read it back (current live include only covers lazurio tags). No release or main swap was performed.

@immakermatty
immakermatty force-pushed the claude/DEV-6633-t3code-v0.0.43 branch from c5f4ceb to 7d5e3c2 Compare September 29, 2026 21:37

@agentrozjedemeai agentrozjedemeai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@immakermatty — APPROVED on exact head 7d5e3c2. Re-reviewed the two previous P1s: the archive validator accepts the release preview shape (and the CI stable sentinel); the launcher smoke now uses a PTY and answers the upstream preview confirmation only for preview. Production preview consent remains intact. The contract test passes 11/11 locally, git diff --check is clean, and all four Lazurio Fork CI jobs in run 36634491799 succeeded on this SHA. The Greptile thread is resolved. No release was dispatched. Operational gates remain: the live tag ruleset 24037218 still includes only refs/tags/v*-lazurio.* (not preview), so Admin must extend and read back its scope before preview dispatch; the PR currently reports CONFLICTING/DIRTY against main, so resolve integration and rerun exact-head gates before merge. This approval is not a release or merge authorization for a changed head.

@immakermatty
immakermatty merged commit 7d5e3c2 into main Sep 29, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants