open-swe/docs/upstream-sync/triage.md

139 lines
26 KiB
Markdown
Raw Normal View History

feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118) * docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00
<!-- GENERATED — do not hand-edit. Edit docs/upstream-sync/triage.jsonl, then run `make triage-render`. Staleness is enforced in CI by `make triage-check`. -->
# Upstream triage ledger
Commits on `upstream/main` (langchain-ai/open-swe) not yet in `dev`, and the decision on each.
Rows key on the **upstream SHA** (stable across local cherry-picks). Deferred rows are provisional
— re-inspect before picking. See the fork-maintenance runbook in `CLAUDE.md`.
**Last synced `upstream/main`:** `c9a193e2` (2026-07-17)
feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118) * docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00
| sha | pr | subject | decision | why | branch |
|---|---|---|---|---|---|
| `0b76afdc` | #1653 | reviews block agenda, sticky headers, diff scroll | Landed | | cherry-pick-upstream |
| `7530653b` | #1655 | ResizeObserver settle for review scroll-to | Landed | | cherry-pick-upstream |
| `23bd4a63` | #1660 | top padding to sticky review block header | Landed | | cherry-pick-upstream |
| `9e5a1924` | #1656 | purge expired thread_wakeup crons | Landed | | cherry-pick-upstream |
| `63eb9a08` | #1661 | sidebar filter popover border tokens | Landed | | cherry-pick-upstream |
| `bc7ce591` | #1668 | preserve dashboard redirect after login | Landed | | cherry-pick-upstream |
| `f32e492a` | #1637 | return to thread after plan approval | Landed | | cherry-pick-upstream |
| `7ee3e057` | #1636 | make plan view mobile friendly | Landed | | cherry-pick-upstream |
| `6575c327` | #1654 | disable React StrictMode | Landed | kept fork's `PwaUpdateProvider` | cherry-pick-upstream |
| `00906401` | #1610 | editable plan mode | Landed | re-implemented in fork via #130 (editable plan mode) | |
| `f5670f24` | #1639 | require bun for ui agent work | Landed | cherry-picked (-x) in this PR (#132) | PR1 |
feat: port durable dispatch hardening and startup latency improvements (#160) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * feat: port durable dispatch hardening and startup latency improvements Port five upstream PRs onto dev: - #1621 / #1658: durable dispatch with loopback webhook defense, create_durable_run helper, _config_with_prepare_run_id, degradation to None for relative/loopback completion webhook URLs - #1696: run-level completion webhook deduplication (replace claim-then-post with post-then-flag per run_id), DeferredErrorModel for graph-factory resilience, ToolRetryMiddleware for task subagents, TimeoutWrapupMiddleware for all three graphs - #1697: lazy-load __init__.py for agent.middleware, agent.tools, agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search, agent.webapp in request_pr_review, deepagents in sandbox.py); add ttl_cache.py with stale-while-revalidate for tool loaders Refs: #137 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary * fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache - Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__ (_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it. - Reroute E2E model patching to deferred_model.make_model so make_model_or_defer (used by all three graph factories) returns the scripted fake instead of building a real model with fake credentials. - Drop unused agent/utils/ttl_cache.py — no agent module imports it. - Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001). - Format tests/test_dispatch.py. * fix: claim-then-post run-level failure dedup; stop permanent suppression --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `209132d3` | #1621 | durable interrupt dispatch + completion webhook | Landed | investigate first — may be applied | durable-dispatch |
| `02bb4dfd` | #1658 | don't attach loopback run-complete webhooks | Landed | | durable-dispatch |
| `29015fad` | #1614 | gate workflow pushes with approval | Landed | | durable-dispatch |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `546042a4` | #1652 | add workflow approval UI | Landed | | plan-approval |
| `ae04b72b` | #1635 | publish plans from sandbox files | Landed | ported (adapted) in #128 (save_plan reads sandbox file) | plan-approval |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `c03a6be7` | #1634 | keep plan guidance high-level | Landed | | plan-approval |
| `96cceb74` | #1632 | notify Slack on plan approval | Landed | ported (adapted) in #128 | plan-approval |
| `2f56d754` | #1618 | omit plan link when no plan exists | Landed | already in dev via #81 (upstream-sync); ledger was stale (was: likely regression) | plan-approval |
| `ee224d3e` | #1650 | add Slack reaction tool | Landed | | slack-tooling |
| `747ce4bb` | #1638 | add Slack breakout thread tool | Landed | | slack-tooling |
| `27d90ef1` | #1633 | include Slack channel context in prompts | Landed | | slack-tooling |
| `92dbf6f9` | #1630 | update Slack trace reply on web handoff | Landed | ported in #128 (trace_message_ts on first-mention run mapping) | slack-tooling |
| `bb36448b` | #1627 | surface Slack thread errors | Landed | | slack-tooling |
feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155) * feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) Ports four upstream commits that add opt-in LLM call routing through the LangSmith Gateway, preserving fork conventions (Bedrock/Fireworks model IDs, no-agent-attribution, bun toolchain). - #1671 (e9dc6e01): opt-in gateway routing — new gateway.py, team-settings toggle, admin UI section, wired into make_model for all graph entrypoints - #1673 (702ef908): dedicated LANGSMITH_GATEWAY_API_KEY precedence over platform LANGSMITH_API_KEY - #1674 (5f7c2f46): fix Fireworks gateway base URL to /fireworks (bare host, SDK appends /v1/chat/completions) + SanitizeFireworksMessagesMiddleware - #1678 (73b7d1c0): fix OpenAI Responses reasoning replay — SanitizeOpenAIResponsesMiddleware, store/include config for encrypted reasoning content, reasoning_effort coercion for Chat Completions fallback Refs #134 * fix: downgrade gateway not-routed log to debug, add Bedrock UI note, add sanitizer parity - Downgrade logger.warning to logger.debug in gateway_overrides for not-routed providers and missing API key (Bedrock is the default provider in this fork, so these are expected steady states) - Add Bedrock to the LLMGatewaySection route-toggle description so admins know it is not routed through the gateway - Add SanitizeOpenAIResponsesMiddleware to chat.py for parity with server.py and reviewer.py - Restore the Bedrock region comment in model.py that explains the AWS_REGION / AWS_DEFAULT_REGION precedence Refs #138 --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-09 14:44:15 -04:00
| `73b7d1c0` | #1678 | fix OpenAI Responses reasoning replay | Landed | | gateway-routing |
| `5f7c2f46` | #1674 | fix Fireworks Gateway base URL | Landed | | gateway-routing |
| `702ef908` | #1673 | dedicated LangSmith gateway API key | Landed | | gateway-routing |
| `e9dc6e01` | #1671 | opt-in LangSmith LLM Gateway routing | Landed | | gateway-routing |
feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118) * docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00
| `289f5e3a` | #1651 | add Sonnet 5 to model picker | Landed | already in dev; added Bedrock family fallback fix (c16fb915) | gateway-routing |
| `5da3d0c6` | #1624 | post reviewer resolution notes verbatim | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `69148f54` | #1612 | add PR trace resolution | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `6d125526` | #1625 | stop wrapping installs in sfw | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
| `320bb39a` | #1657 | opt-in tracemalloc for aiohttp sessions | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `4f913198` | #1647 | widen split review diffs | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
| `20f63e8c` | #1646 | install missing deps before verification | Landed | already in dev via #81 (upstream-sync); ledger was stale | prompt-tweaks |
| `2f237b53` | #1626 | fall back to vision model for image threads | Landed | ported (adapted to Bedrock/Fireworks vision) in #128 | gateway-routing |
| `48217b68` | #1489 | feat(open-swe): add E2B sandbox provider (#1489) | Landed | re-implemented on fork's sync create_sandbox factory in #199 (E2B SDK is sync; async base not needed); langchain-e2b==0.0.4; dark-safe; GitHub proxy/App-token flow untouched | feat/port-1489-e2b-provider |
| `fbc6de85` | #1667 | chore(deps): bump fireworks-ai from 1.2.0a75 to 1.2.0a86 (#1667) | Landed | Superseded by #158 (fireworks-ai a85 -> a88, efeb6b12); dev already exceeds a86. No port needed. | deps |
feat: port model-fallback resilience from upstream (#1694, #1695) (#161) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * feat: port durable dispatch hardening and startup latency improvements Port five upstream PRs onto dev: - #1621 / #1658: durable dispatch with loopback webhook defense, create_durable_run helper, _config_with_prepare_run_id, degradation to None for relative/loopback completion webhook URLs - #1696: run-level completion webhook deduplication (replace claim-then-post with post-then-flag per run_id), DeferredErrorModel for graph-factory resilience, ToolRetryMiddleware for task subagents, TimeoutWrapupMiddleware for all three graphs - #1697: lazy-load __init__.py for agent.middleware, agent.tools, agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search, agent.webapp in request_pr_review, deepagents in sandbox.py); add ttl_cache.py with stale-while-revalidate for tool loaders Refs: #137 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * feat: port model-fallback resilience from upstream (#1694, #1695) - Add httpx.TransportError to the transient-exception set so incomplete chunked reads on streamed responses trigger a fallback instead of cancelling the run (#1694 / c9f6dd86). - Rewrite fallback to alternate primary/fallback with exponential backoff instead of a single failover, so the agent survives multi-minute gateway outages spanning both providers (#1695 / c9a9a7cd). - Default backoff schedule (0, 5, 15, 30, 45) reaches past the gateway's ~30s recovery window; jittered ±25%. - On exhaustion, surface a terminal AIMessage explaining the outage instead of crashing — progress is checkpointed so the user can retrigger to continue. - Preserve fork conventions: Bedrock ClientError retryability check, sync wrap_model_call (using time.sleep instead of asyncio.sleep), and existing access-error surfacing for Anthropic, OpenAI, and Bedrock (botocore) provider errors. - Update triage ledger (c9f6dd86, c9a9a7cd → landed) and re-render triage.md. Refs: #139 * fix: align workflow-push-guard tests with dev's transient-elevation impl The dev merge auto-combined dev's elevation tests with the stale passthrough tests inherited from the durable-dispatch branch; the passthrough tests contradict dev's restored _run_with_workflow_token impl. Take dev's test file. * fix: drop dead ttl_cache module; make fallback backoff jitter two-sided ttl_cache.py was re-introduced via the dev merge but dev/#160 deliberately removed it as dead code (no agent importer). Remove it to match dev. Also make _jittered_delay symmetric (±25%) to match its docstring. * chore(upstream-sync): triage 4 new upstream commits (#1708-#1713) Synced ledger to upstream/main (71e3b818). New rows all deferred: - #1708 add GPT-5.6 OpenAI models (FLAG-HUMAN: fork picker is Bedrock/Fireworks-only) - #1709 stale admin model defaults after upgrades - #1710 bump langchain-fireworks 1.4.4 - #1713 align reviewer eval with published findings --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 18:28:21 -04:00
| `c9f6dd86` | #1694 | fix: fall back on model stream transport errors (#1694) | Landed | adds httpx.TransportError to transient set; small conflict w/ dev's diverged Bedrock fallback | model-fallback |
| `c9a9a7cd` | #1695 | fix: retry model fallback exhaustion (#1695) | Landed | alternating retry+backoff rewrite; reconcile by hand w/ dev's Bedrock + sync wrap path | model-fallback |
feat: port durable dispatch hardening and startup latency improvements (#160) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * feat: port durable dispatch hardening and startup latency improvements Port five upstream PRs onto dev: - #1621 / #1658: durable dispatch with loopback webhook defense, create_durable_run helper, _config_with_prepare_run_id, degradation to None for relative/loopback completion webhook URLs - #1696: run-level completion webhook deduplication (replace claim-then-post with post-then-flag per run_id), DeferredErrorModel for graph-factory resilience, ToolRetryMiddleware for task subagents, TimeoutWrapupMiddleware for all three graphs - #1697: lazy-load __init__.py for agent.middleware, agent.tools, agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search, agent.webapp in request_pr_review, deepagents in sandbox.py); add ttl_cache.py with stale-while-revalidate for tool loaders Refs: #137 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary * fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache - Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__ (_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it. - Reroute E2E model patching to deferred_model.make_model so make_model_or_defer (used by all three graph factories) returns the scripted fake instead of building a real model with fake credentials. - Drop unused agent/utils/ttl_cache.py — no agent module imports it. - Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001). - Format tests/test_dispatch.py. * fix: claim-then-post run-level failure dedup; stop permanent suppression --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `e5dbc788` | #1696 | fix: Harden durable agent runs (#1696) | Landed | large durable-run hardening; 3 new modules dev lacks; rewrites fork dispatch/completion | durable-dispatch |
| `52fe2916` | #1698 | feat: add PR review link route (#1698) | Landed | cherry-picked (-x) in #127 (PR review link route) | reviewer-misc |
feat: port durable dispatch hardening and startup latency improvements (#160) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * feat: port durable dispatch hardening and startup latency improvements Port five upstream PRs onto dev: - #1621 / #1658: durable dispatch with loopback webhook defense, create_durable_run helper, _config_with_prepare_run_id, degradation to None for relative/loopback completion webhook URLs - #1696: run-level completion webhook deduplication (replace claim-then-post with post-then-flag per run_id), DeferredErrorModel for graph-factory resilience, ToolRetryMiddleware for task subagents, TimeoutWrapupMiddleware for all three graphs - #1697: lazy-load __init__.py for agent.middleware, agent.tools, agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search, agent.webapp in request_pr_review, deepagents in sandbox.py); add ttl_cache.py with stale-while-revalidate for tool loaders Refs: #137 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary * fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache - Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__ (_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it. - Reroute E2E model patching to deferred_model.make_model so make_model_or_defer (used by all three graph factories) returns the scripted fake instead of building a real model with fake credentials. - Drop unused agent/utils/ttl_cache.py — no agent module imports it. - Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001). - Format tests/test_dispatch.py. * fix: claim-then-post run-level failure dedup; stop permanent suppression --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `5f7f5fbd` | #1697 | fix: Reduce graph import and loader startup latency (#1697) | Landed | import-hygiene refactor; cross-cutting, references many deferred upstream-only modules | durable-dispatch |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `216cf181` | #1699 | fix: keep workflow HITL without token downscoping (#1699) | Landed | DIVERGES-FROM-UPSTREAM: fork deliberately does NOT adopt #1699's standing-token workflows:write broadening. Security review (#159) BLOCKed it — the standing ALWAYS-ON proxy token carrying workflows:write turns the HITL guard's git-push-parser gaps (obfuscated-expansion push, `gh api` REST contents PUT, cross-branch refspecs) into live unapproved-workflow-push exploits. Fork keeps BASE without workflows:write and restores the transient per-approval elevation (_run_with_workflow_token mints WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE): the token scope is the backstop the parser relies on, so a bypass hits GitHub 403. HITL diff-preview/approval-URL/Slack-card additions from #159 retained; token-model divergence only. | plan-approval |
feat: surface attributed PR creation failures (#180) * feat: surface attributed PR creation failures Port upstream #1659: adds PullRequestCreationGuardMiddleware that blocks shell fallbacks (gh pr create, gh api /pulls, curl) when open_pull_request fails, keeping failures visible. Also adds preflight branch/repo visibility checks in open_pull_request with structured failure payloads, and updates the prompt to forbid PR creation fallbacks. Refs: #134 * fix: fall back to core GitHub App scope when optional grants missing (#1701) * fix: fall back to core GitHub App scope when optional grants missing Proxy-token minting requested workflows:write and actions:read in the permission set used for every sandbox. GitHub 422s a token request that asks for a permission the installation hasn't granted, so any install without workflows:write failed to mint a token and every run died in before-agent setup with "GitHub App installation token is unavailable". _resolve_proxy_token now walks a permission ladder (full -> +workflows -> core) and returns the first scope that mints, recording the granted scope so hourly proxy refreshes stay consistent. A missing optional grant now degrades to the install-time core scope instead of failing the run; workflow-file HITL pushes still require workflows:write and fail at push time when it is absent. * refactor: flatten proxy-token ladder loop with continue --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935) Sea Haven fork deviation: upstream #1701 folds workflows:write into the standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write OUT of the standing permission ladder (RUNTIME = core + actions:read; LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push .github/workflows/* during normal operation. workflows:write is minted only transiently by WorkflowPushGuardMiddleware for an approved HITL push and dropped on restore, preserving token scope as a backstop for the workflow- push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross review); the standing-scope-carries-workflows:write bypass was blocked. * fix(open-swe): harden proxy-token restore and mint error handling Two low-severity follow-ups from the security review of the #1701 port. Restore the recorded baseline scope after a workflow-push elevation instead of a hardcoded RUNTIME. An install granted workflows:write but not actions:read resolves its standing token to core; hardcoding RUNTIME on restore requested the ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope" error on every approved workflow push before the core fallback recovered. The guard now captures the run's recorded scope before elevating (via the new get_recorded_proxy_permissions) and restores exactly that, falling back to the guaranteed core scope only when the baseline restore fails. Classify installation-token mint failures. get_github_app_installation_token_ with_expiry now treats HTTP 422 (a permission the installation hasn't granted) as the ladder's expected descend signal and keeps it at debug, while a non-422 failure (network/5xx/timeout) is surfaced at WARNING even when errors are otherwise suppressed — so a transient blip no longer silently downscopes a whole run under a debug-only trace. The reduced-scope warning no longer asserts a missing grant as the sole cause. * chore(triage): mark upstream #1701 landed on this branch Ported via PR #181 as Option A (workflows:write kept out of the standing proxy-token scope). Regenerated triage.md from triage.jsonl. * fix: restructure PR creation to POST-first with diagnose-on-failure Move preflight checks from an authoritative gate (before POST) to a diagnostic run after POST failure. This avoids false-positive failures when a just-pushed head branch is momentarily invisible to GitHub ref endpoints, and eliminates 2-3 extra serial API round-trips on the happy path. Also drop unused _PR_CREATED_FALSE indirection and add a docstring to pr_creation_guard acknowledging the fail-open detection design. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-13 14:45:19 -04:00
| `67abf5b0` | #1659 | fix: surface attributed PR creation failures (#1659) | Landed | PR-attribution-failure guard (new mw, safe imports); heavy conflict on diverged open_pull_request.py | pr-attribution |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `3dbc0282` | #1676 | fix: preserve plan redirects after login (#1676) | Landed | FLAG-HUMAN: follow-on to landed #1668 refining sanitize_redirect_to (open-redirect auth surface); not a dup | plan-approval |
| `c75cbb1f` | #1677 | feat: re-add Fable 5 with an admin toggle to disable it (#1677) | Landed | Ported + Bedrock-converted onto dev via feat/readd-fable5-bedrock; anthropic: Fable ID mapped to bedrock_converse:us.anthropic.claude-fable-5. | fable-admin-toggle |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `bb104d93` | #1679 | fix: submit plan comments with cmd enter (#1679) | Landed | applies clean but edits fork-diverged PlanReview.tsx (#130); needs UI/e2e validation — separate PR | plan-approval |
| `304032fa` | #1680 | chore: clarify question answering prompt (#1680) | Landed | reword Slack info-only answer guidance; conflicts w/ fork's customized Slack prompt | prompt-tweaks |
| `5003c953` | #1683 | feat: open Linear-triggered PRs as the triggering user (#1683) | Landed | FLAG-HUMAN: adds linear to resolve_github_token per-user OAuth branch (auth surface); depends on #1626 linear.py | feature/port-linear-pr-author |
| `feb7ac98` | #1689 | feat(web): surface thread sandbox ID with touch-friendly menu (#1689) | Landed | Ported to dev via feat/thread-sandbox-id-sidebar. | dashboard-ui |
| `7f7af715` | #1684 | feat: auto-load scoped AGENTS on reads (#1684) | Landed | ported in #129 (SubdirAgentsReadMiddleware) | subdir-agents |
| `88b62322` | #1685 | feat: add platform issue reporting tool (#1685) | Landed | ported in #129 (report_platform_issue tool) | small-tools |
feat: port plan-review & workflow-approval UX (#159) * feat: port plan-review & workflow-approval UX (#135) Port six upstream commits onto dev: - c03a6be7 (already ported): keep plan guidance high-level - 546042a4: add workflow approval UI with diff preview, approval URLs, web review links, and polling for approval status during active runs - 216cf181: remove workflow token elevation; approved pushes pass through directly without proxy token rewriting - 3dbc0282: preserve plan redirects after login by accepting relative same-origin redirect_to values and rejecting blocked paths - bb104d93: submit plan comments with cmd+enter - 90cb6caa: terse Slack replies, shared content via save_plan outside plan mode (PLAN_STATUS_SHARED), reject shared-content mutations Refs: #135 * fix: restore login page render and clear CI lint/format The plan-review port removed the authRedirectUrl import from login.tsx but left its call site, crashing the login page at runtime (blank page, no 'Sign in to open-swe'). Pass the relative path straight to loginUrl, matching the plan route and the backend relative-redirect handling. Also drop an unused os import in the guard test and reformat workflow_push_guard.py to satisfy ruff. * fix: carry workflows:write on the standing proxy token Complete the half-ported upstream 216cf181 cascade. The port dropped _run_with_workflow_token from the guard but missed the paired github_app change, so an approved .github/workflows push ran with the base token (no workflows:write) and GitHub 403'd it. Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the github_app and proxy_auth tests to match. The HITL approval gate in workflow_push_guard.py is unchanged — this only lets the standing token push once a human approves. * fix: restore transient workflow-token elevation (revert standing workflows:write) The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push guard the sole control over unapproved workflow pushes. The guard's git-push parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT, fully-qualified cross-branch refspecs); with a permanently workflows-scoped token those gaps become live unapproved-workflow-push exploits (1 critical, 2 high — security review BLOCK on #159). Restore dev's transient-elevation model: - Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write). - Re-introduce _run_with_workflow_token in the guard: it mints the workflows-scoped token via refresh_proxy_token around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a finally. Route the approval branch through it. - Restore the dev token/elevation tests. The standing token no longer carries workflows:write, so the three parser bypasses hit GitHub 403 again; an approved push still succeeds because the elevation grants workflows:write only around the normalized command. Keeps all of #159's diff-preview / approval-URL / Slack-card guard additions. * fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect) sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes same-origin, passing the origin check, but yields a path starting with `//`). ClientRedirect / login.tsx feed that path to window.location.replace, so it navigates cross-origin — an open redirect. Reject any resolved path that is not a single-leading-slash path (`^/[^/]`), falling back to the default. Adds coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`. * fix: log SECURITY error when workflow-token downscope fails The elevate->push->downscope finally block was silent on failure. If both refresh_proxy_token calls fail, the sandbox retains workflows:write for the rest of the run with no signal. Log a SECURITY error on the partial and full downscope-failure paths so the retention is observable. Addresses the GPT-4.1 cross-family review of the token-scope remediation. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `90cb6caa` | #1681 | feat: terse Slack replies, share long content via plan-review page (#1681) | Landed | terse Slack + long-content-via-plan-page; conflicts w/ fork prompt + diverged plan stack | plan-approval |
fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181) * fix: fall back to core GitHub App scope when optional grants missing (#1701) * fix: fall back to core GitHub App scope when optional grants missing Proxy-token minting requested workflows:write and actions:read in the permission set used for every sandbox. GitHub 422s a token request that asks for a permission the installation hasn't granted, so any install without workflows:write failed to mint a token and every run died in before-agent setup with "GitHub App installation token is unavailable". _resolve_proxy_token now walks a permission ladder (full -> +workflows -> core) and returns the first scope that mints, recording the granted scope so hourly proxy refreshes stay consistent. A missing optional grant now degrades to the install-time core scope instead of failing the run; workflow-file HITL pushes still require workflows:write and fail at push time when it is absent. * refactor: flatten proxy-token ladder loop with continue --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935) Sea Haven fork deviation: upstream #1701 folds workflows:write into the standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write OUT of the standing permission ladder (RUNTIME = core + actions:read; LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push .github/workflows/* during normal operation. workflows:write is minted only transiently by WorkflowPushGuardMiddleware for an approved HITL push and dropped on restore, preserving token scope as a backstop for the workflow- push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross review); the standing-scope-carries-workflows:write bypass was blocked. * fix(open-swe): harden proxy-token restore and mint error handling Two low-severity follow-ups from the security review of the #1701 port. Restore the recorded baseline scope after a workflow-push elevation instead of a hardcoded RUNTIME. An install granted workflows:write but not actions:read resolves its standing token to core; hardcoding RUNTIME on restore requested the ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope" error on every approved workflow push before the core fallback recovered. The guard now captures the run's recorded scope before elevating (via the new get_recorded_proxy_permissions) and restores exactly that, falling back to the guaranteed core scope only when the baseline restore fails. Classify installation-token mint failures. get_github_app_installation_token_ with_expiry now treats HTTP 422 (a permission the installation hasn't granted) as the ladder's expected descend signal and keeps it at debug, while a non-422 failure (network/5xx/timeout) is surfaced at WARNING even when errors are otherwise suppressed — so a transient blip no longer silently downscopes a whole run under a debug-only trace. The reduced-scope warning no longer asserts a missing grant as the sole cause. * chore(triage): mark upstream #1701 landed on this branch Ported via PR #181 as Option A (workflows:write kept out of the standing proxy-token scope). Regenerated triage.md from triage.jsonl. --------- Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
2026-07-13 14:24:37 -04:00
| `f53caff1` | #1701 | fix: fall back to core GitHub App scope when optional grants missing (#1701) | Landed | Ported as Option A: workflows:write kept OUT of standing scope, minted only transiently by the workflow-push guard (security-reviewed); PR #181 | chore/port-github-app-scope-fallback |
| `22e024cb` | #1704 | fix: link issue PRs and prompt repo conventions (#1704) | Landed | issue/PR linking + repo-convention prompt; clean but prompt-conflict risk vs #113 | chore/upstream-easy-picks |
| `62e0ca2d` | #1709 | fix: stale admin model defaults after model upgrades (#1709) | Landed | cherry-picked (-x) in #200; retired-model map converted to fork Bedrock/Fireworks IDs (Fable deliberately maps to Opus — provider-data-share gate; test-pinned); dropped #1708-entangled profile tests | fix/port-1709-stale-model-defaults |
| `138ab9ec` | #1710 | fix: bump langchain-fireworks to 1.4.4 (#1710) | Landed | langchain-fireworks 1.4.4 adopted via fork Dependabot group PR #190 (dev now resolves langchain-fireworks==1.4.4); upstream commit not cherry-picked | deps |
| `71e3b818` | #1713 | fix: align reviewer eval with published findings (#1713) | Landed | cherry-picked (-x) in #201; reviewer.py + publish_review.py hand-reconciled into fork structure (kept sandbox/skills/middleware stack, kebab-case workflow, Bedrock eval default); publish_review cap param removed (tool-facing only) | fix/port-1713-reviewer-eval-alignment |
| `092abafa` | #1717 | fix: enforce terse Slack tool messages (#1717) | Landed | cherry-picked (-x) in #197; one test conflict resolved by adopting upstream's test (fork prompt now contains upstream text); follow-up to landed #1681, not superseded by it | fix/port-1717-terse-slack-tool-msgs |
| `92d63170` | #1720 | fix: separate review access from automatic reviews (#1720) | Landed | cherry-picked (-x) in #198 + fork-only auto-fix gates renamed to _is_repo_auto_review_enabled (kept opt-in-gated); opt-in list now gates only AUTOMATIC reviews — manual/re-review/watch/finding-replies open to any App-installed repo. Adam signed off 2026-07-16; /sh-security-review explicitly waived by Adam 2026-07-16 | fix/port-1720-review-access-split |
| `8356eb34` | #1726 | refactor: organize repository by domain (#1726) | Landed | Adopted as a file-move exercise (fork content, upstream layout) on branch refactor/domain-reorg-adoption — gate-approved plan in docs/upstream-sync/domain-reorg/. New layout: agent/{graphs,runtime,api,review,resources}, agent/webhooks/*_routes.py (webapp.py split into api/ + per-source route modules; webapp.py now a shim), tests/<domain>/, ui/src/features/. Kills the per-pick path-remap tax and unblocks 8 deferred rows (#1732/#1761/#1744/#1748/#1742 clean; #1736/#1758/#1760 near-clean). | refactor/domain-reorg-adoption |
| `129ddcf9` | #1728 | chore: include ripgrep in sandbox image (#1728) | Landed | 1-line Dockerfile add (ripgrep); dev image lacks it; trivial pick | chore/upstream-easy-picks |
| `1ea03a43` | #1729 | feat: include Cargo in sandbox image (#1729) | Landed | 2-line Dockerfile add (Cargo); adopt with #1728 | chore/upstream-easy-picks |
| `09eaf94c` | #1730 | fix: let admins interrupt runaway agents (#1730) | Landed | admin interrupt for runaway agents (dashboard route + UI); useful ops control; UI half on post-reorg ui/src/features — remap to ui/src/components/agents | feat/admin-thread-interrupt |
| `c69459ad` | #1751 | fix: prefer LangSmith tools for trace links (#1751) | Landed | 1-line prompt: prefer LangSmith tools for trace links; trivial but edits fork-customized prompt.py | chore/upstream-easy-picks |
| `5cb2e2bb` | #1750 | fix: add trace link to error banner (#1750) | Landed | adds trace link to error banner (13 lines); remap AgentThreadView.tsx path (fork: ui/src/components/agents/) | chore/upstream-easy-picks |
feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118) * docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00
| `c3292d82` | #1611 | bake sfw binary into sandbox image | Won't merge | already in dev | |
| `48bf712b` | #1609 | show message timestamps | Won't merge | already in dev | |
| `85c0f63e` | #1620 | clickable shared PR header | Won't merge | already in dev | |
| `db2ae58e` | #1643 | pre-bundle shiki/@pierre deps | Won't merge | already in dev | |
| `1d9da064` | #1662 | bump astral-sh/setup-uv | Won't merge | dev ahead (v8.2.0, `checkout@v7`) | |
| `83cb40a0` | #1616 | update langsmith sdk to 0.9.3 | Won't merge | regression — dev has 0.9.6 | |
| `e5a29eca` | #1613 | plan links in PR descriptions | Won't merge | regression — dev has async plan-ref | |
| `e1d85526` | #1645 | switch ui to pnpm | Won't merge | tooling — fork keeps bun | |
| `4cd5fa5c` | #1629 | avoid recapping Slack replies | Won't merge | already in dev — landed via sync PR #81 (1f060f2a), then deliberately superseded by the fork's refined Slack no-duplication rule in PR #159 (f87847ba) | |
| `baf0c248` | #1617 | filter & grouping menu in threads sidebar | Won't merge | already in dev — full feature present (sidebarFilter/sidebarPrefs/SidebarFilterMenu + AgentsSidebar wiring); only deltas are the later-landed #1661 token restyle | |
| `f29868ff` | #1615 | recover thread work as patch | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — recovery-patch vertical byte-identical to upstream; 6 recovery tests pass on dev | |
| `8e0788dc` | #1631 | show queued dashboard follow-ups | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — full queued-follow-ups vertical (types, QueuedMessages UI, streaming de-dupe, e2e) present and since evolved | |
| `9c601ca1` | #1648 | add Stagehand-powered browser subagent | Won't merge | requires Browserbase/Stagehand creds or Chromium-in-server-image + hard stagehand dep; browser runs in server process outside the sandbox; against fork curated-tools policy, no fork use case | |
| `8c944381` | #1622 | restore forced tool call | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — ensure_no_empty_msg middleware/tests/wiring/prompt line byte-identical to 8c944381; squash hid it from ancestry | |
| `5dc360d8` | #1619 | bump langgraph-checkpoint 4.1.0→4.1.1 | Won't merge | already in dev — uv.lock already resolves langgraph-checkpoint 4.1.1 | |
| `89f886e2` | #1642 | request actions read for sandbox logs | Won't merge | already in dev — actions:read in RUNTIME_PROXY_TOKEN_PERMISSIONS + identical prompt line | |
| `27f987dc` | #1686 | refactor: remove dead sync-interface compatibility code (#1686) | Won't merge | pure dead-sync-path deletion committing to the async-only posture the fork rejects; fork still uses get_sandbox_backend_sync; no embedded fix | |
| `2503a2f4` | #1687 | refactor(open-swe): provision LangSmith sandboxes natively async (#1687) | Won't merge | async pivot of create_sandbox/_configure_github_proxy (auth surface) — fork keeps sync lifecycle; langsmith bump subsumed by fork's 0.10.5 pin; metadata-await fix moot on fork's to_thread path | |
| `2529b109` | #1690 | fix: checkpoint per-run graph setup (#1690) | Won't merge | fork's get_agent re-runs idempotent setup by design (stateless), so the un-checkpointed-setup bug doesn't exist; faithful adaptation is a 4-graph rewrite presupposing the deferred async base | |
| `c0a7e93e` | #1691 | fix: reconnect sandbox backend on resumed runs (#1691) | Won't merge | fixes a #1690-introduced regression (latched setup skips ensure on resume); fork unconditionally re-runs ensure_sandbox_for_thread (case-4 reconnect), so the gap doesn't exist | |
| `4f8bc2dd` | #1692 | refactor: simplify open-swe agent sandbox lifecycle (#1692) | Won't merge | structural rewrite deleting the fork's 4-case __creating__ sentinel; net diff is exactly the sentinel removal + rewritten test; collides with fork-only TID-COLLIDE-01 repo-binding guard | |
| `ab4eea4b` | #1663 | chore(deps): bump the major group across 1 directory with 3 updates (#1663) | Won't merge | already in dev — CI already on checkout@v7/setup-node@v6/upload-artifact@v7 | |
| `2bf207fb` | #1664 | chore(deps): bump python in the minor-and-patch group (#1664) | Won't merge | already in dev — Dockerfile already at python 3.14.6-slim-trixie | |
| `13b40113` | #1666 | chore(deps): bump cryptography from 48.0.1 to 49.0.0 in the major group (#1666) | Won't merge | already in dev — same 48->49 cryptography bump dev did via #105 | |
| `290d0fee` | #1669 | chore(deps): update langgraph-cli[inmem] requirement (#1669) | Won't merge | already in dev — langgraph-cli[inmem] at 0.4.30 | |
| `73a9e8b5` | #1693 | chore(deps): bump the minor-and-patch group across 1 directory with 19 updates (#1693) | Won't merge | dev at-or-ahead on 17/19; group fights dev's pinned langsmith==0.9.7 (#115) and carries an upstream plan-route test | |
| `9cd7e464` | #1700 | Fix workflow approval visibility (#1700) | Won't merge | superseded — dev's list_workflow_approvals_for_thread already enforces owner-only 403 | |
| `fd2541ce` | #1705 | fix: drop orphaned function_call items with stale OpenAI reasoning (#1705) | Won't merge | N/A — edits sanitize_openai_responses.py which dev deleted in the Bedrock/Fireworks migration (#62) | |
| `27b0ddeb` | #1708 | feat: add GPT-5.6 OpenAI models (#1708) | Won't merge | fork picker deliberately Bedrock/Fireworks-only — no-OpenAI-models product decision (consistent with #1725/#1727); options.py verified zero openai: IDs | |
| `35659177` | #1718 | fix: sanitize orphaned OpenAI tool results (#1718) | Won't merge | N/A — fork has no OpenAI Responses traffic path; middleware present is #155's leaner rewrite lacking the orphan machinery #1718 patches; langchain-openai>=1.3.4 already satisfied; superseded upstream by #1731 (re-evaluate #155 rewrite when triaging #1731). Note: fd2541ce row's '#62 deleted sanitize_openai_responses.py' is inaccurate — the path was added fresh by #155 | |
| `5136079d` | #1725 | chore: disable todos for GPT-5.6 Sol (#1725) | Won't merge | superseded — #1733 (136d28e6) rewrites the same todo-exclusion block to a global default-off with env opt-in; per-model GPT-5.6 Sol list moot (fork picker has no OpenAI models) | |
| `bfa67a7a` | #1711 | chore(deps): bump soupsieve from 2.8.3 to 2.8.4 (#1711) | Won't merge | already in dev — uv.lock resolves soupsieve 2.8.4 | |
| `f7d94ad3` | #1721 | docs: add e2b to sandbox provider lists in AGENTS.md and CLAUDE.md (#1721) | Won't merge | N/A — edits upstream AGENTS.md/CLAUDE.md, both fully fork-rewritten; E2B provider itself deferred (48217b68) — add a doc line if/when E2B lands | |
| `4773b336` | #1746 | chore: point basedpyright at uv's .venv (#1746) | Won't merge | tooling — fork does not use basedpyright (lint stack is ruff); nothing to point at .venv | |
| `697adaa7` | #1752 | fix: update PyJWT to 2.13.0 (#1752) | Won't merge | already in dev — uv.lock resolves PyJWT 2.13.0 | |
| `714ea4a2` | #1759 | fix: clear basedpyright standard-mode type errors (#1759) | Won't merge | tooling — basedpyright type-error cleanup across 123 post-reorg files; fork uses ruff and the pre-reorg layout | |
| `dccf6437` | #1769 | fix: tighten sandbox config test types (#1769) | Won't merge | test-only change in post-reorg path tests/sandbox/ — fork doesn't have this file (domain reorg #1726 deferred) | |
| `c9a193e2` | #1766 | chore(deps): bump mcp from 1.27.2 to 1.28.1 (#1766) | Won't merge | indirect dependency bump (mcp); fork's own Dependabot handles these | |
| `83abea26` | #1724 | fix: accept natural-language Slack plan approvals (#1724) | Deferred | natural-language Slack plan approvals; touches fork-diverged plan-mode + Slack webhook stack (#130); post-reorg test paths need remap | plan-approval |
| `ddbe457b` | #1727 | fix: restore GPT-5.5 as default model (#1727) | Deferred | restores GPT-5.5 default in options/team_settings; fork picker is Bedrock/Fireworks-only — rides the #1708 OpenAI-models product decision (27b0ddeb) | model-picker |
| `30832d29` | #1731 | fix: preserve OpenAI Responses tool history (#1731) | Deferred | deletes SanitizeOpenAIResponsesMiddleware in favor of replay-history preservation in utils/model.py; supersedes deferred #1718 (35659177) — triage the pair together against fork-diverged middleware + model.py | openai-sanitize |
| `1ea0e600` | #1736 | fix: bind cached GitHub tokens to users (#1736) | Deferred | FLAG-HUMAN: security fix — binds per-thread cached GitHub tokens to a user principal (closes cross-user token-reuse leak). Fork has github_token.py but not webhooks/common.py — hand-map; auth surface: GPT-4.1 cross-review + /sh-security-review on landing. Priority pick. Re-triage (post-reorg 8356eb34 landed): biggest beneficiary — agent/webhooks/common.py now exists, so the pick is near-clean against it; auth gates (GPT-4.1 cross-review + /sh-security-review) still apply. | github-token-binding |
| `3fcb27ce` | #1737 | fix: bound reviewer diff fetching (#1737) | Deferred | bounds reviewer diff fetching + new fetch_review_diff tool; reviewer.py fork-diverged — reconcile like #1713 (71e3b818) | reviewer-misc |
| `d714586c` | #1732 | fix: normalize dashboard label rendering (#1732) | Deferred | dashboard tool-label normalization; post-reorg ui/src/features paths — remap. Re-triage (post-reorg 8356eb34 landed): path-remap blocker removed — clean pick; ui/src/features/ now matches upstream. | dashboard-ui |
| `ef68c09b` | #1734 | fix: handle Slack DMs as mentions (#1734) | Deferred | treat Slack DMs as mentions; touches fork-diverged Slack webhook + e2e harness; post-reorg test paths | slack-tooling |
| `26828ff9` | #1745 | chore: upgrade deepagents to 0.7.0a7 (#1745) | Deferred | deepagents 0.6.12 -> 0.7.0a7 alpha + [tool.uv] override-dependencies to bypass sandbox integrations <0.7.0 bound; fork is built on create_deep_agent — dedicated validation (unit + e2e) before adopting an alpha | deps |
| `ef0ed5af` | #1741 | fix: centralize SSRF-safe image fetches (#1741) | Deferred | security hardening — centralizes image fetches through url_safety.py (SSRF); fork has url_safety.py/multimodal.py (diverged) — hand-reconcile; untrusted-input surface: /sh-security-review on landing | ssrf-hardening |
| `136d28e6` | #1733 | fix: disable todos by default (#1733) | Deferred | global write_todos/TodoListMiddleware default-off with OPEN_SWE_ENABLE_TODOS opt-in; edits fork-customized prompt.py — small hand-merge; supersedes #1725 | prompt-tweaks |
| `3e8089c3` | #1744 | fix: collapse git panel by default (#1744) | Deferred | collapse git panel by default (localStorage pref); post-reorg UI paths — remap to ui/src/components/agents. Re-triage (post-reorg 8356eb34 landed): path-remap blocker removed — clean pick; ui/src/features/ now matches upstream. | dashboard-ui |
| `5077e2c7` | #1735 | feat(open-swe): untagged two-party Slack replies + debounced interrupts (#1735) | Deferred | untagged two-party Slack replies + debounced interrupts (~620 LOC incl. e2e); rides fork-diverged Slack webhook stack; own branch + e2e validation | slack-untagged-replies |
| `8b26819f` | #1719 | fix: offload web tool results to sandbox (#1719) | Deferred | offloads large web tool results to sandbox files; touches fork-relevant web_search/http tools; check interplay with fork sandbox lifecycle | tool-offloading |
| `c34e04f4` | #1742 | fix: defensive copy in get_reviewer_agent and get_chat_agent [closes #1584] (#1742) | Deferred | defensive copy of config in get_reviewer_agent/get_chat_agent; small correctness fix; dev has chat.py + reviewer.py (diverged) — likely near-clean pick. Re-triage (post-reorg 8356eb34 landed): path-remap blocker removed — clean pick; reviewer.py/chat.py factories unmoved. | small-tools |
| `79df6b2f` | #1748 | feat: add Linear issue search tool (#1748) | Deferred | additive linear_search_issues tool + utils/linear.py search helper; fork ships Linear tools — straightforward port; post-reorg test path remap. Re-triage (post-reorg 8356eb34 landed): test-path blocker removed — clean pick; tests/<domain>/ now matches upstream. | small-tools |
| `b7c5dbd6` | #1747 | fix: simplify Slack run links (#1747) | Deferred | simplifies Slack run links; heavy churn on fork-diverged Slack context/prompt tests | slack-tooling |
| `22383033` | #1758 | feat: inject extra JSON fields into sandbox create via env var (#1758) | Deferred | additive: extra JSON fields into sandbox create via env var (integrations/langsmith.py); fork langsmith.py diverged (proxy config) — small reconcile. Re-triage (post-reorg 8356eb34 landed): near-clean — path-remap tax gone; remaining work is the additive reconcile against fork's diverged langsmith.py (integrations/ unmoved by reorg). | sandbox-config |
| `e826864d` | #1760 | feat: optional separate LangSmith key/endpoint for sandboxes (#1760) | Deferred | optional separate LangSmith key/endpoint for sandboxes; additive to langsmith.py + proxy auth; useful for fork LangSmith sandbox usage. Re-triage (post-reorg 8356eb34 landed): near-clean — path-remap tax gone; remaining work is the additive reconcile against fork's diverged langsmith.py + proxy auth (integrations/ unmoved). | sandbox-config |
| `dd5b7bec` | #1761 | fix: capitalize dashboard tool labels (#1761) | Deferred | capitalize dashboard tool labels; post-reorg UI paths; stacks on #1732 (d714586c). Re-triage (post-reorg 8356eb34 landed): path-remap blocker removed — clean pick after #1732. | dashboard-ui |
feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118) * docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00
_Maintenance: after a `git sync`, add new `dev..upstream/main` SHAs as **Untriaged** (edit `triage.jsonl`) and bump "Last synced". A successful `git cherry-pick -x` auto-moves the row to **Landed** via the `post-commit` journal + `make triage-reconcile`._