Skip to content

DEV-6633: move the fork to upstream v0.0.44 - #24

Merged
immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.44
Sep 29, 2026
Merged

immakermatty merged 0 commit into
mainfrom
claude/DEV-6633-t3code-v0.0.44

Conversation

@immakermatty

@immakermatty immakermatty commented Sep 29, 2026 •

Copy link
Copy Markdown

Status: ready for review — head 0d7c12f456c64a8a2d149d89dcc7bc25a316c417, Lazurio Fork CI in the comments

How to read this PR: the real review surface is git diff v0.0.44...claude/DEV-6633-t3code-v0.0.44 (6 commits). GitHub also shows the upstream v0.0.43 → v0.0.44 change. Published by the Admin main swap under the rolling contract, not by the merge button.

Mission Control: DEV-6633 (updated to v0.0.44 in a follow-up plan PR). Supersedes the v0.0.43 base of #21 before anything was released from it.

Why

Matěj decided on 2026-09-30 to go straight to upstream v0.0.44 (published 2026-09-29 20:48Z, 1.5 h after v0.0.43). The official desktop app updates itself to the newest upstream; a desktop on 0.0.44 against a server on 0.0.43-lazurio.1 would offer "Update to 0.0.44", which our channel does not have. Upstream v0.0.43 → v0.0.44 is three commits: one Codex fix (fix(codex): Pro Max accounts load, so Ultrafast shows up, pingdotgg#14304), a model manifest update, and release preparation. Closes #23.

Exact inputs

Upstream tag v0.0.44 → 451afcb22d93f06cb24f9bc16703404564952553 (lightweight; v0.0.43 is its ancestor)
Current fork main 7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84 = v0.0.43 + overlay (#21), never released
Candidate head 0d7c12f456c64a8a2d149d89dcc7bc25a316c417

What changed against #21

  • Review round 1 (Pablo + Greptile) found two real defects in the retained hosted: serve behind an explicit HTTPS external origin commit, present since v0.0.42-lazurio.1, both fixed and folded into that commit with tests that fail without the fix: (1) the external-origin check ignored the legacy t3_session cookie that a remote-bound server still accepts, so a same-site sibling could ride it; (2) migrating a legacy cookie set __Host-t3_session without Secure, which browsers reject. Lazurio Machines bind T3 to 127.0.0.1, where the legacy cookie does not exist, so deployed servers were not exposed. Three other Greptile findings are answered in their threads as by design or known limits (web-client skew fallback, fail-closed release retry, installer first-match).
    git range-diff v0.0.43..7d5e3c2e4e v0.0.44..5d7361dd54:
  • commits 1–4 (session TTL, external origin, environment label, in-app update channel): identical patches (=), cherry-picked without conflicts;
  • release: Lazurio distribution: CI pinned to v0.0.44 / 451afcb2…, archive job 0.0.44-lazurio.0, contract-test pins, inventory column renamed to v0.0.44 (decisions unchanged: upstream v0.0.44 adds no equivalent for any overlay capability);
  • release: publish upstream preview versions as canary pre-releases: only runbook examples moved to 0.0.44 and the desktop paragraph generalised (a self-updated desktop ahead of our refresh sees the same failed offer).

The remove/retain/migrate table, the preview-channel change and its review history are in #21 (Pablo APPROVED on its exact head after two P1 fixes).

Main swap: Admin exception granted

The runbook requires the current main to be captured by an immutable -lazurio.N release before it is replaced. 7d5e3c2e4e (v0.0.43 + overlay) was never released and runs on no Machine; its commits stay reachable in refs/pull/21/head and in the branch claude/DEV-6633-t3code-v0.0.43. Matěj (Admin) granted a one-time exception on 2026-09-30 in the DEV-6633 thread: swap main to this candidate without that capture. The runbook rule is unchanged. All other gates stay: Pablo APPROVED on the exact head, 4/4 required checks green, zero unresolved threads, one --force-with-lease attempt, a failed lease is not retried.

  • expected_old_main: 7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84 (never released; reachable in refs/pull/21/head: verified)
  • candidate_head: 0d7c12f456c64a8a2d149d89dcc7bc25a316c417 (Pablo APPROVED on this exact head; 4/4 required checks green in run 36639201503; 0 unresolved threads)
  • Command (one attempt): git push --force-with-lease=refs/heads/main:7d5e3c2e4e769fbb6c4b9249d28fb9c91424ef84 origin 0d7c12f456c64a8a2d149d89dcc7bc25a316c417:refs/heads/main

Verification

Local (macOS arm64, pnpm 11.10.0): frozen install, vp fmt --check, server and web typecheck OK; server tests (config, auth, environment, cloud, update) OK and server.test.ts 206/206 alone (a combined parallel run showed the known order/load flakes in two stream tests that pass alone); the two new auth tests fail without the fix; web versionSkew 21/21; shared cliRelease 10/10; install-scripts 4/4; release contract 11/11. No merge commits in v0.0.44..HEAD; the overlay still changes the same 8 allowlisted client/shared files.

What deliberately does not change

No server or client behaviour beyond #21; no custom canary channel, no Machines change, no re-pin. Nothing is released, tagged or deployed by this PR.

🤖 Generated with Claude Code

RetriggerConfidence Score: 0/5

This PR is not safe to merge until the hosted authentication, update-target, installer-selection, and partial-publication failures are addressed.

Findings

  1. P1 Security Legacy cookie bypasses origin check ▶
  2. P1 Migrated cookie lacks Secure ▶
  3. P1 Unavailable client update remains offered ▶
  4. P1 Partial release blocks retry ▶
  5. P1 Installer can choose older release ▶

Summary

This PR rebases the Lazurio distribution on upstream v0.0.44 and adds hosted authentication settings, fork-channel updates, installers, and release workflows.

  • The origin check misses accepted legacy-cookie credentials, and migration to the new secure-cookie name is incomplete.
  • The update UI can still offer an unpublished client version when no fork release is advertised.
  • Release publication can leave an unrecoverable partial run, while fresh installs can select a different version from runtime update discovery.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Repo[Configured GitHub releases] --> Check[Server release check]
  Check --> Descriptor[availableServerUpdate]
  Descriptor --> UI[Client Update target]
  UI --> Install[Launcher archive install]
  Repo --> Install
  Repo --> Scripts[Fresh-install scripts]
  Build[Release workflow] --> Image[OCI image push]
  Image --> Tag[Source tag]
  Tag --> Release[GitHub Release and archives]
Loading

Reviews (1) · Last reviewed commit: "release: publish upstream preview versio..."

@immakermatty

Copy link
Copy Markdown
Author

Lazurio Fork CI on exact head 5d7361d (workflow_dispatch): https://github.com/Lazurio/t3code/actions/runs/36637081212

Comment thread apps/server/src/auth/EnvironmentAuth.ts Outdated
Comment thread apps/server/src/auth/utils.ts
Comment thread apps/web/src/versionSkew.ts
Comment thread .github/workflows/lazurio-release.yml
Comment thread scripts/install.sh

@agentrozjedemeai agentrozjedemeai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@immakermatty — CHANGES_REQUESTED on exact head 5d7361d. The v0.0.44 rebase itself matches the previous six-patch overlay (commits 1–4 identical; only release pins and runbook examples changed); the upstream tag resolves to 451afcb. Release contract 11/11, diff --check clean, and Lazurio Fork CI run 36637081212 passed all four jobs on this SHA. No release dispatched.

Two concrete blockers remain in the retained overlay, newly surfaced by the five unresolved review threads on this head:

  1. P1, apps/server/src/auth/EnvironmentAuth.ts:615–622 and :668–682: requireExternalOriginForCookie checks only sessions.cookieName, but selectRequestCredential also accepts sessions.legacyCookieName on a production web server bound to a remotely reachable host. A legacy-cookie-authenticated mutation or WebSocket handshake can therefore skip the configured external-origin check. Cover the accepted legacy cookie and add a negative sibling-origin test for HTTP and WS.
  2. P1, apps/server/src/auth/http.ts:174–181, :244–258: migration from t3_session to __Host-t3_session via appendSessionCookie omits Secure. The __Host cookie is rejected by browsers, so remote-host legacy sessions do not migrate. Set Secure for that path and test the emitted Set-Cookie attributes.

Please reconcile all five open Greptile threads with evidence or repairs and request a new exact-head review; the other findings include a known planned desktop-version limitation, which should not silently expand this PR scope. The current PR also reports CONFLICTING/DIRTY against main because this rolling candidate requires the separately authorized Admin swap, not an ordinary merge. The unreleased prior-main exception is Matěj’s decision; this review neither grants it nor dispatches a release.

@immakermatty
immakermatty force-pushed the claude/DEV-6633-t3code-v0.0.44 branch from 5d7361d to 0d7c12f Compare September 29, 2026 22:22
@immakermatty

Copy link
Copy Markdown
Author

@agentrozjedemeai agentrozjedemeai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@immakermatty — APPROVED on exact head 0d7c12f; the prior CHANGES_REQUESTED on 5d7361d is not reused. Range-diff from upstream v0.0.44 proves commits 1 and 3–6 patch-identical and commit 2 alone changed. The origin gate now covers both the current and accepted legacy cookie on POST and WS (valid origin succeeds; absent/sibling origins fail); the migration emits Secure on the __Host- cookie. Local EnvironmentAuth 18/18 and targeted migration 1/1 passed, as did web versionSkew 21/21, release contract 11/11, server/web typechecks, format, and diff --check. The exact-head Lazurio Fork CI run 36639201503 completed 4/4 green on Node 24.13.1, including the full server.test.ts. Local Node 22.22.3 is outside the root Node ^24.13.1 engine: full server.test.ts was unstable (202/206, then 204/206; unrelated static-cache and intermittent bootstrap JSON/"ok" fixture responses). I do not present it as a local 206/206 pass. All five Greptile threads are resolved; the three pushbacks match the web-client-only, fail-closed release, and per-channel monotonic installer contracts. The exact upstream tag resolves to 451afcb and the overlay contains six commits without merges. PR mergeability DIRTY/CONFLICTING against old main 7d5e3c2 is expected for the rolling patch-stack: this is approval of the candidate, NOT approval of an ordinary merge or permission to dispatch a release. The documented one-time Admin exception is restricted to that unreleased old-main SHA; the separately authorized Admin must verify live lease and perform any swap, then repeat main CI and preview-tag ruleset gates. No release, tag, swap, or merge performed.

@immakermatty
immakermatty merged commit 0d7c12f into main Sep 29, 2026
7 checks passed
@agentrozjedemeai
agentrozjedemeai deployed to lazurio-t3code-release September 30, 2026 07:22 — with GitHub Actions Active
@agentrozjedemeai
agentrozjedemeai deployed to lazurio-t3code-release September 30, 2026 08:12 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
lazurio-t3code-release — 0d7c12f4 Deployed Sep 30, 2026 by agentrozjedemeai via Publish release and image #13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Refresh forku na upstream v0.0.44

2 participants