chore: sync public mirror from internal - #1297
Conversation
|
Resolved 0 review-bot thread(s) on this generated public mirror PR. Review of mirrored code belongs on the mono source PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c8e6df11ac
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| let mut resolved = root.to_path_buf(); | ||
| for component in candidate.components() { | ||
| match component { | ||
| std::path::Component::Normal(part) => resolved.push(part), | ||
| std::path::Component::CurDir => {} |
There was a problem hiding this comment.
Resolve symlinks before allowing workspace file access
When MAESTRO_DEX_LOOP=1 is used in a workspace containing a file or directory symlink, this lexical join accepts paths such as linked/secret because they contain neither .. nor an absolute component, but read_to_string/write follows the symlink outside the workspace. That lets the model read arbitrary host files and, since run_local_turn auto-approves writes, overwrite their targets. Resolve the existing target (or its existing parent for new files) and verify it remains beneath the canonical workspace root before performing either operation.
Useful? React with 👍 / 👎.
| let active_turn_id = result | ||
| .snapshot_turns | ||
| .iter() | ||
| .rev() | ||
| .find(|turn| !matches!(turn.state, 6..=8)) | ||
| .map(|turn| turn.turn_id.clone()); |
There was a problem hiding this comment.
Exclude completed turns from active turn selection
TURN_STATE_COMPLETED is value 5 in the public protocol, but this predicate only rejects values 6 through 8. Consequently, an attach to a thread whose latest turn completed successfully reports that completed turn as active; attached_repl then replays its old events (and may print the prior answer) before presenting the prompt. Select only the explicitly nonterminal states instead of treating every value below 6 as active.
Useful? React with 👍 / 👎.
Summary
dx-corp/monodx-corp/codeas a generated public mirror of the private source of truth16426c3c3b3dc59f6817c9a2836fd714d17a55335bfbbeb575801b605b42755a5a1154849c56a75a64file(s) to copy/update and0stale file(s) to delete0sync-holdlabel to this PR; the sync workflow skips every push while it is setSource-of-truth status
Projection: deixic-code
Source: dx-corp/mono@16426c3c3b3dc59f6817c9a2836fd714d17a5533
Prior destination base: 5bfbbeb
Content SHA-256: 42be9fd04b572f4a3cf4bb0854bcac5ae498a5d48dc99cf8d129ade8a4ab0536
Result: drift_detected; 64 changed, 0 deleted
Destination-owned content is preserved. Destination CI is a separate health signal.
copy/update .repository-projection.json
copy/update CHANGELOG.md
copy/update Cargo.lock
copy/update Cargo.toml
copy/update Dockerfile
copy/update package-lock.json
copy/update package.json
copy/update packages/ai-rs/src/anthropic.rs
copy/update packages/ai-rs/src/client.rs
copy/update packages/ai-rs/src/google.rs
copy/update packages/ai-rs/src/lib.rs
copy/update packages/ai-rs/src/openai.rs
copy/update packages/ai-rs/src/sse.rs
copy/update packages/dex-host-rs/Cargo.toml
copy/update packages/dex-host-rs/src/effects.rs
copy/update packages/dex-host-rs/src/lease.rs
copy/update packages/dex-host-rs/src/lib.rs
copy/update packages/dex-host-rs/src/log.rs
copy/update packages/dex-host-rs/src/model.rs
copy/update packages/dex-host-rs/src/tools.rs
Drift sample
Public-only commits since last generated sync
Validation
Test Plan
maestro-sync-public-release-mirrorworkflow inpublic-treemoderequire-internal-prconfirms internal source PR lineageStaged Rollout
dx-corp/mono@16426c3c3b3dc59f6817c9a2836fd714d17a5533, including existing hidden/evaluation surfaces, and keeps public package parity behind the established public-source-provenance gate.