Skip to content

chore: sync public mirror from internal - #1329

Merged
evalops-mirror[bot] merged 1 commit into
mainfrom
sync/public-release-mirror
Oct 3, 2026
Merged

evalops-mirror[bot] merged 1 commit into
mainfrom
sync/public-release-mirror

Conversation

@evalops-mirror

@evalops-mirror evalops-mirror Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • sync the sanitized public tree from dx-corp/mono
  • keep dx-corp/code as a generated public mirror of the private source of truth
  • preserve public-owned CI and trusted-publishing workflows from the public checkout
  • internal source SHA: 518c4d79c54135d51a4d885f38cf4f4e701e44a0
  • last generated public sync base: bac6ed17bdc31b56dfdc9d7740103300965fec5c
  • previewed public-tree drift: 23 file(s) to copy/update and 0 stale file(s) to delete
  • public-only commits since last generated sync: 0
  • to pause generated syncs while hand-editing this branch, apply the sync-hold label to this PR; the sync workflow skips every push while it is set

Source-of-truth status

Projection: deixic-code

  • Source: dx-corp/mono@518c4d79c54135d51a4d885f38cf4f4e701e44a0

  • Prior destination base: bac6ed1

  • Content SHA-256: 00d6e14ad707b1d000be9e241309bd5d6a63d5aaa0c95f61c30df1be063723ef

  • Result: drift_detected; 23 changed, 0 deleted

  • Destination-owned content is preserved. Destination CI is a separate health signal.

  • copy/update .repository-projection.json

  • copy/update Cargo.lock

  • copy/update packages/dex-host-rs/Cargo.toml

  • copy/update packages/dex-host-rs/src/host_tools.rs

  • copy/update packages/dex-host-rs/src/lib.rs

  • copy/update packages/dex-host-rs/tests/host_tools.rs

  • copy/update packages/local-host-rs/src/agent/mod.rs

  • copy/update packages/local-host-rs/src/headless/supervisor/tests.rs

  • copy/update packages/local-host-rs/src/headless/supervisor/tests/delayed_ack.rs

  • copy/update packages/local-host-rs/src/headless_server.rs

  • copy/update packages/runtime-gateway-rs/src/chat.rs

  • copy/update packages/runtime-gateway-rs/src/codex_bridge.rs

  • copy/update packages/runtime-gateway-rs/src/sessions.rs

  • copy/update packages/runtime-gateway-rs/src/tests.rs

  • copy/update packages/runtime-rs/src/agent/mod.rs

  • copy/update packages/runtime-rs/src/agent/native.rs

  • copy/update packages/runtime-rs/src/agent/native/loop_policy.rs

  • copy/update packages/tui-rs/src/app.rs

  • copy/update packages/tui-rs/src/app/prompt_queue.rs

  • copy/update packages/tui-rs/src/app/tests.rs

Drift sample

  • copy/update .repository-projection.json
  • copy/update Cargo.lock
  • copy/update packages/dex-host-rs/Cargo.toml
  • copy/update packages/dex-host-rs/src/host_tools.rs
  • copy/update packages/dex-host-rs/src/lib.rs
  • copy/update packages/dex-host-rs/tests/host_tools.rs
  • copy/update packages/local-host-rs/src/agent/mod.rs
  • copy/update packages/local-host-rs/src/headless/supervisor/tests.rs
  • copy/update packages/local-host-rs/src/headless/supervisor/tests/delayed_ack.rs
  • copy/update packages/local-host-rs/src/headless_server.rs
  • copy/update packages/runtime-gateway-rs/src/chat.rs
  • copy/update packages/runtime-gateway-rs/src/codex_bridge.rs
  • copy/update packages/runtime-gateway-rs/src/sessions.rs
  • copy/update packages/runtime-gateway-rs/src/tests.rs
  • copy/update packages/runtime-rs/src/agent/mod.rs
  • copy/update packages/runtime-rs/src/agent/native.rs
  • copy/update packages/runtime-rs/src/agent/native/loop_policy.rs
  • copy/update packages/tui-rs/src/app.rs
  • copy/update packages/tui-rs/src/app/prompt_queue.rs
  • copy/update packages/tui-rs/src/app/tests.rs

Public-only commits since last generated sync

  • none detected since last generated sync

Validation

  • generated by the sync-public-release-mirror workflow in public-tree mode

Test Plan

  • generated by the maestro-sync-public-release-mirror workflow in public-tree mode
  • public-source-provenance require-internal-pr confirms internal source PR lineage
  • generated mirror PRs use the slim public CI path (fmt/clippy/smoke + provenance); full cargo test/evals already ran on internal main for this SHA
  • bot review threads on generated mirror PRs are advisory and do not block the next sync update

Staged Rollout

  • Staging is unnecessary for this generated mirror PR: it does not independently promote user-visible behavior. It mirrors already-reviewed internal source from dx-corp/mono@518c4d79c54135d51a4d885f38cf4f4e701e44a0, including existing hidden/evaluation surfaces, and keeps public package parity behind the established public-source-provenance gate.

@evalops-mirror
evalops-mirror Bot requested a review from a team as a code owner October 3, 2026 20:26
@evalops-mirror

evalops-mirror Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Resolved 0 review-bot thread(s) on this generated public mirror PR.
Left 0 human-started thread(s) unresolved.

Review of mirrored code belongs on the mono source PR.
See https://github.com/dx-corp/mono/issues/9100 for the triage pattern.

@evalops-mirror
evalops-mirror Bot enabled auto-merge (squash) October 3, 2026 20:26
@evalops-mirror
evalops-mirror Bot merged commit 256415b into main Oct 3, 2026
22 checks passed
@evalops-mirror
evalops-mirror Bot deleted the sync/public-release-mirror branch October 3, 2026 20:28

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d9e2dd1c1d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

NativeHookResult::Block { reason } => {
return ToolResult::error(format!("blocked by hook: {reason}"));
}
NativeHookResult::ModifyInput { new_input } => args = new_input,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Re-run policy after hook-rewritten arguments

When a PreToolUse hook returns ModifyInput, this path executes new_input after policy has already admitted the original arguments. For example, an otherwise auto-approved bash {"command":"ls"} can be rewritten to a mutating command and will bypass the Selective-mode approval check; execute_tool only rechecks hard firewall blocks. The native actor runs PreToolUse before its firewall and approval classification in native/tool_batch.rs, so re-run validation, firewall, and approval policy against the rewritten arguments before dispatch.

Useful? React with 👍 / 👎.

Comment on lines +321 to +324
let required =
loop_policy::approval_required(self.mode, false, &firewall, &self.host, name, &args);
if !required {
return Verdict::Allow;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Honor PermissionRequest hooks before creating a preview

For a tool that requires approval, the native actor invokes hook_permission_request before presenting any approval UI and treats a Block result as a denial. This implementation goes directly from required to a confirmation preview, so a configured PermissionRequest hook that blocks (for example, an organization policy hook) is ignored and the action executes once the user confirms. Invoke that hook in this branch and return Verdict::Deny on Block to retain the host's approval policy.

Useful? React with 👍 / 👎.

Comment on lines +393 to +396
if let NativeHookResult::Block { reason } = self
.host
.hook_post_tool_use(name, call_id, &args, output, is_error, elapsed)
.await

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run EvalGate hooks for completed tool calls

This only runs the PostToolUse hook, so configured EvalGate hooks never see results on the dex-loop path. The native actor's run_post_execution_hooks invokes hook_eval_gate after PostToolUse and reports its rejection to the model; skipping it here makes result-validation hooks ineffective for every HostTools call. Run the eval gate with the same sanitized output and propagate its rejection/context into the returned result.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants