Skip to content

chore: sync public mirror from internal - #1297

Merged
evalops-mirror[bot] merged 1 commit into
mainfrom
sync/public-release-mirror
Sep 29, 2026
Merged

evalops-mirror[bot] merged 1 commit into
mainfrom
sync/public-release-mirror

Conversation

@evalops-mirror

Copy link
Copy Markdown
Contributor

Summary

  • sync the sanitized public tree from dx-corp/mono
  • keep dx-corp/code as a generated public mirror of the private source of truth
  • preserve public-owned CI and trusted-publishing workflows from the public checkout
  • internal source SHA: 16426c3c3b3dc59f6817c9a2836fd714d17a5533
  • last generated public sync base: 5bfbbeb575801b605b42755a5a1154849c56a75a
  • previewed public-tree drift: 64 file(s) to copy/update and 0 stale file(s) to delete
  • public-only commits since last generated sync: 0
  • to pause generated syncs while hand-editing this branch, apply the sync-hold label to this PR; the sync workflow skips every push while it is set

Source-of-truth status

Projection: deixic-code

  • Source: dx-corp/mono@16426c3c3b3dc59f6817c9a2836fd714d17a5533

  • Prior destination base: 5bfbbeb

  • Content SHA-256: 42be9fd04b572f4a3cf4bb0854bcac5ae498a5d48dc99cf8d129ade8a4ab0536

  • Result: drift_detected; 64 changed, 0 deleted

  • Destination-owned content is preserved. Destination CI is a separate health signal.

  • copy/update .repository-projection.json

  • copy/update CHANGELOG.md

  • copy/update Cargo.lock

  • copy/update Cargo.toml

  • copy/update Dockerfile

  • copy/update package-lock.json

  • copy/update package.json

  • copy/update packages/ai-rs/src/anthropic.rs

  • copy/update packages/ai-rs/src/client.rs

  • copy/update packages/ai-rs/src/google.rs

  • copy/update packages/ai-rs/src/lib.rs

  • copy/update packages/ai-rs/src/openai.rs

  • copy/update packages/ai-rs/src/sse.rs

  • copy/update packages/dex-host-rs/Cargo.toml

  • copy/update packages/dex-host-rs/src/effects.rs

  • copy/update packages/dex-host-rs/src/lease.rs

  • copy/update packages/dex-host-rs/src/lib.rs

  • copy/update packages/dex-host-rs/src/log.rs

  • copy/update packages/dex-host-rs/src/model.rs

  • copy/update packages/dex-host-rs/src/tools.rs

Drift sample

  • copy/update .repository-projection.json
  • copy/update CHANGELOG.md
  • copy/update Cargo.lock
  • copy/update Cargo.toml
  • copy/update Dockerfile
  • copy/update package-lock.json
  • copy/update package.json
  • copy/update packages/ai-rs/src/anthropic.rs
  • copy/update packages/ai-rs/src/client.rs
  • copy/update packages/ai-rs/src/google.rs
  • copy/update packages/ai-rs/src/lib.rs
  • copy/update packages/ai-rs/src/openai.rs
  • copy/update packages/ai-rs/src/sse.rs
  • copy/update packages/dex-host-rs/Cargo.toml
  • copy/update packages/dex-host-rs/src/effects.rs
  • copy/update packages/dex-host-rs/src/lease.rs
  • copy/update packages/dex-host-rs/src/lib.rs
  • copy/update packages/dex-host-rs/src/log.rs
  • copy/update packages/dex-host-rs/src/model.rs
  • copy/update packages/dex-host-rs/src/tools.rs

Public-only commits since last generated sync

  • none detected since last generated sync

Validation

  • generated by the sync-public-release-mirror workflow in public-tree mode

Test Plan

  • generated by the maestro-sync-public-release-mirror workflow in public-tree mode
  • public-source-provenance require-internal-pr confirms internal source PR lineage
  • generated mirror PRs use the slim public CI path (fmt/clippy/smoke + provenance); full cargo test/evals already ran on internal main for this SHA
  • bot review threads on generated mirror PRs are advisory and do not block the next sync update

Staged Rollout

  • Staging is unnecessary for this generated mirror PR: it does not independently promote user-visible behavior. It mirrors already-reviewed internal source from dx-corp/mono@16426c3c3b3dc59f6817c9a2836fd714d17a5533, including existing hidden/evaluation surfaces, and keeps public package parity behind the established public-source-provenance gate.

@evalops-mirror
evalops-mirror Bot requested review from a team as code owners September 29, 2026 21:20
@evalops-mirror

Copy link
Copy Markdown
Contributor Author

Resolved 0 review-bot thread(s) on this generated public mirror PR.
Left 0 human-started thread(s) unresolved.

Review of mirrored code belongs on the mono source PR.
See https://github.com/dx-corp/mono/issues/9100 for the triage pattern.

@evalops-mirror
evalops-mirror Bot enabled auto-merge (squash) September 29, 2026 21:20
@evalops-mirror
evalops-mirror Bot merged commit 9ee0b79 into main Sep 29, 2026
13 of 23 checks passed
@evalops-mirror
evalops-mirror Bot deleted the sync/public-release-mirror branch September 29, 2026 21:22

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c8e6df11ac

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +74 to +78
let mut resolved = root.to_path_buf();
for component in candidate.components() {
match component {
std::path::Component::Normal(part) => resolved.push(part),
std::path::Component::CurDir => {}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve symlinks before allowing workspace file access

When MAESTRO_DEX_LOOP=1 is used in a workspace containing a file or directory symlink, this lexical join accepts paths such as linked/secret because they contain neither .. nor an absolute component, but read_to_string/write follows the symlink outside the workspace. That lets the model read arbitrary host files and, since run_local_turn auto-approves writes, overwrite their targets. Resolve the existing target (or its existing parent for new files) and verify it remains beneath the canonical workspace root before performing either operation.

Useful? React with 👍 / 👎.

Comment on lines +414 to +419
let active_turn_id = result
.snapshot_turns
.iter()
.rev()
.find(|turn| !matches!(turn.state, 6..=8))
.map(|turn| turn.turn_id.clone());

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exclude completed turns from active turn selection

TURN_STATE_COMPLETED is value 5 in the public protocol, but this predicate only rejects values 6 through 8. Consequently, an attach to a thread whose latest turn completed successfully reports that completed turn as active; attached_repl then replays its old events (and may print the prior answer) before presenting the prompt. Select only the explicitly nonterminal states instead of treating every value below 6 as active.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants