open-swe/docs/upstream-sync/triage.md
Adam Moussa 5350b63c85
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172)
* feat(models): re-add Fable 5 with admin disable toggle (port of upstream #1677)

* refactor(models): convert re-added Fable 5 to Bedrock model IDs

* fix(open-swe): correct Fable copy to describe provider data sharing, not ZDR

The ported admin toggle description and code comments described Fable 5 as
incompatible with Zero Data Retention. That is backwards: Fable 5 requires
the account to opt into Bedrock provider_data_share — prompts/completions are
retained and shared with Anthropic (up to 30 days, incl. human review). The
old UI copy would lead an admin to believe the opposite of what enabling the
toggle does. Reword the toggle description and the gate_fable_model /
team_settings comments accordingly. Still off by default. Refs #171.
2026-07-10 14:05:20 -04:00

15 KiB

Upstream triage ledger

Commits on upstream/main (langchain-ai/open-swe) not yet in dev, and the decision on each. Rows key on the upstream SHA (stable across local cherry-picks). Deferred rows are provisional — re-inspect before picking. See the fork-maintenance runbook in CLAUDE.md.

Last synced upstream/main: 92d63170 (2026-07-10)

sha pr subject decision why branch
0b76afdc #1653 reviews block agenda, sticky headers, diff scroll Landed cherry-pick-upstream
7530653b #1655 ResizeObserver settle for review scroll-to Landed cherry-pick-upstream
23bd4a63 #1660 top padding to sticky review block header Landed cherry-pick-upstream
9e5a1924 #1656 purge expired thread_wakeup crons Landed cherry-pick-upstream
63eb9a08 #1661 sidebar filter popover border tokens Landed cherry-pick-upstream
bc7ce591 #1668 preserve dashboard redirect after login Landed cherry-pick-upstream
f32e492a #1637 return to thread after plan approval Landed cherry-pick-upstream
7ee3e057 #1636 make plan view mobile friendly Landed cherry-pick-upstream
6575c327 #1654 disable React StrictMode Landed kept fork's PwaUpdateProvider cherry-pick-upstream
00906401 #1610 editable plan mode Landed re-implemented in fork via #130 (editable plan mode)
f5670f24 #1639 require bun for ui agent work Landed cherry-picked (-x) in this PR (#132) PR1
209132d3 #1621 durable interrupt dispatch + completion webhook Landed investigate first — may be applied durable-dispatch
02bb4dfd #1658 don't attach loopback run-complete webhooks Landed durable-dispatch
29015fad #1614 gate workflow pushes with approval Landed durable-dispatch
546042a4 #1652 add workflow approval UI Landed plan-approval
ae04b72b #1635 publish plans from sandbox files Landed ported (adapted) in #128 (save_plan reads sandbox file) plan-approval
c03a6be7 #1634 keep plan guidance high-level Landed plan-approval
96cceb74 #1632 notify Slack on plan approval Landed ported (adapted) in #128 plan-approval
2f56d754 #1618 omit plan link when no plan exists Landed already in dev via #81 (upstream-sync); ledger was stale (was: likely regression) plan-approval
ee224d3e #1650 add Slack reaction tool Landed slack-tooling
747ce4bb #1638 add Slack breakout thread tool Landed slack-tooling
27d90ef1 #1633 include Slack channel context in prompts Landed slack-tooling
92dbf6f9 #1630 update Slack trace reply on web handoff Landed ported in #128 (trace_message_ts on first-mention run mapping) slack-tooling
bb36448b #1627 surface Slack thread errors Landed slack-tooling
73b7d1c0 #1678 fix OpenAI Responses reasoning replay Landed gateway-routing
5f7c2f46 #1674 fix Fireworks Gateway base URL Landed gateway-routing
702ef908 #1673 dedicated LangSmith gateway API key Landed gateway-routing
e9dc6e01 #1671 opt-in LangSmith LLM Gateway routing Landed gateway-routing
289f5e3a #1651 add Sonnet 5 to model picker Landed already in dev; added Bedrock family fallback fix (c16fb915) gateway-routing
5da3d0c6 #1624 post reviewer resolution notes verbatim Landed cherry-picked (-x) in #127 reviewer-misc
69148f54 #1612 add PR trace resolution Landed cherry-picked (-x) in #127 reviewer-misc
6d125526 #1625 stop wrapping installs in sfw Landed already present in dev; empty pick confirmed in #127 reviewer-misc
320bb39a #1657 opt-in tracemalloc for aiohttp sessions Landed cherry-picked (-x) in #127 reviewer-misc
4f913198 #1647 widen split review diffs Landed already present in dev; empty pick confirmed in #127 reviewer-misc
20f63e8c #1646 install missing deps before verification Landed already in dev via #81 (upstream-sync); ledger was stale prompt-tweaks
2f237b53 #1626 fall back to vision model for image threads Landed ported (adapted to Bedrock/Fireworks vision) in #128 gateway-routing
fbc6de85 #1667 chore(deps): bump fireworks-ai from 1.2.0a75 to 1.2.0a86 (#1667) Landed Superseded by #158 (fireworks-ai a85 -> a88, efeb6b12); dev already exceeds a86. No port needed. deps
c9f6dd86 #1694 fix: fall back on model stream transport errors (#1694) Landed adds httpx.TransportError to transient set; small conflict w/ dev's diverged Bedrock fallback model-fallback
c9a9a7cd #1695 fix: retry model fallback exhaustion (#1695) Landed alternating retry+backoff rewrite; reconcile by hand w/ dev's Bedrock + sync wrap path model-fallback
e5dbc788 #1696 fix: Harden durable agent runs (#1696) Landed large durable-run hardening; 3 new modules dev lacks; rewrites fork dispatch/completion durable-dispatch
52fe2916 #1698 feat: add PR review link route (#1698) Landed cherry-picked (-x) in #127 (PR review link route) reviewer-misc
5f7f5fbd #1697 fix: Reduce graph import and loader startup latency (#1697) Landed import-hygiene refactor; cross-cutting, references many deferred upstream-only modules durable-dispatch
216cf181 #1699 fix: keep workflow HITL without token downscoping (#1699) Landed DIVERGES-FROM-UPSTREAM: fork deliberately does NOT adopt #1699's standing-token workflows:write broadening. Security review (#159) BLOCKed it — the standing ALWAYS-ON proxy token carrying workflows:write turns the HITL guard's git-push-parser gaps (obfuscated-expansion push, gh api REST contents PUT, cross-branch refspecs) into live unapproved-workflow-push exploits. Fork keeps BASE without workflows:write and restores the transient per-approval elevation (_run_with_workflow_token mints WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE): the token scope is the backstop the parser relies on, so a bypass hits GitHub 403. HITL diff-preview/approval-URL/Slack-card additions from #159 retained; token-model divergence only. plan-approval
3dbc0282 #1676 fix: preserve plan redirects after login (#1676) Landed FLAG-HUMAN: follow-on to landed #1668 refining sanitize_redirect_to (open-redirect auth surface); not a dup plan-approval
c75cbb1f #1677 feat: re-add Fable 5 with an admin toggle to disable it (#1677) Landed Ported + Bedrock-converted onto dev via feat/readd-fable5-bedrock; anthropic: Fable ID mapped to bedrock_converse:us.anthropic.claude-fable-5. fable-admin-toggle
bb104d93 #1679 fix: submit plan comments with cmd enter (#1679) Landed applies clean but edits fork-diverged PlanReview.tsx (#130); needs UI/e2e validation — separate PR plan-approval
feb7ac98 #1689 feat(web): surface thread sandbox ID with touch-friendly menu (#1689) Landed Ported to dev via feat/thread-sandbox-id-sidebar. dashboard-ui
7f7af715 #1684 feat: auto-load scoped AGENTS on reads (#1684) Landed ported in #129 (SubdirAgentsReadMiddleware) subdir-agents
88b62322 #1685 feat: add platform issue reporting tool (#1685) Landed ported in #129 (report_platform_issue tool) small-tools
90cb6caa #1681 feat: terse Slack replies, share long content via plan-review page (#1681) Landed terse Slack + long-content-via-plan-page; conflicts w/ fork prompt + diverged plan stack plan-approval
c3292d82 #1611 bake sfw binary into sandbox image Won't merge already in dev
48bf712b #1609 show message timestamps Won't merge already in dev
85c0f63e #1620 clickable shared PR header Won't merge already in dev
db2ae58e #1643 pre-bundle shiki/@pierre deps Won't merge already in dev
1d9da064 #1662 bump astral-sh/setup-uv Won't merge dev ahead (v8.2.0, checkout@v7)
83cb40a0 #1616 update langsmith sdk to 0.9.3 Won't merge regression — dev has 0.9.6
e5a29eca #1613 plan links in PR descriptions Won't merge regression — dev has async plan-ref
e1d85526 #1645 switch ui to pnpm Won't merge tooling — fork keeps bun
5dc360d8 #1619 bump langgraph-checkpoint 4.1.0→4.1.1 Won't merge already in dev — uv.lock already resolves langgraph-checkpoint 4.1.1
89f886e2 #1642 request actions read for sandbox logs Won't merge already in dev — actions:read in RUNTIME_PROXY_TOKEN_PERMISSIONS + identical prompt line
ab4eea4b #1663 chore(deps): bump the major group across 1 directory with 3 updates (#1663) Won't merge already in dev — CI already on checkout@v7/setup-node@v6/upload-artifact@v7
2bf207fb #1664 chore(deps): bump python in the minor-and-patch group (#1664) Won't merge already in dev — Dockerfile already at python 3.14.6-slim-trixie
13b40113 #1666 chore(deps): bump cryptography from 48.0.1 to 49.0.0 in the major group (#1666) Won't merge already in dev — same 48->49 cryptography bump dev did via #105
290d0fee #1669 chore(deps): update langgraph-cli[inmem] requirement (#1669) Won't merge already in dev — langgraph-cli[inmem] at 0.4.30
73a9e8b5 #1693 chore(deps): bump the minor-and-patch group across 1 directory with 19 updates (#1693) Won't merge dev at-or-ahead on 17/19; group fights dev's pinned langsmith==0.9.7 (#115) and carries an upstream plan-route test
9cd7e464 #1700 Fix workflow approval visibility (#1700) Won't merge superseded — dev's list_workflow_approvals_for_thread already enforces owner-only 403
fd2541ce #1705 fix: drop orphaned function_call items with stale OpenAI reasoning (#1705) Won't merge N/A — edits sanitize_openai_responses.py which dev deleted in the Bedrock/Fireworks migration (#62)
4cd5fa5c #1629 avoid recapping Slack replies Deferred slack-tooling
baf0c248 #1617 filter & grouping menu in threads sidebar Deferred ~998 LOC own branch
f29868ff #1615 recover thread work as patch Deferred ~495 LOC own branch
8e0788dc #1631 show queued dashboard follow-ups Deferred own branch
9c601ca1 #1648 add Stagehand-powered browser subagent Deferred own branch
8c944381 #1622 restore forced tool call Deferred own branch
27f987dc #1686 refactor: remove dead sync-interface compatibility code (#1686) Deferred chain head: dead-code removal (get_sandbox_backend_sync); pointless alone sandbox-refactor
2503a2f4 #1687 refactor(open-swe): provision LangSmith sandboxes natively async (#1687) Deferred FLAG-HUMAN: load-bearing async pivot of create_sandbox + _configure_github_proxy (GitHub-App auth surface) sandbox-refactor
2529b109 #1690 fix: checkpoint per-run graph setup (#1690) Deferred per-run graph-setup checkpoint; built on async server.py; entangled sandbox-refactor
c0a7e93e #1691 fix: reconnect sandbox backend on resumed runs (#1691) Deferred reconnect proxy (has_backend/reconnect); assumes async create_sandbox sandbox-refactor
4f8bc2dd #1692 refactor: simplify open-swe agent sandbox lifecycle (#1692) Deferred FLAG-HUMAN: structural rewrite of ensure_sandbox_for_thread (drops creating 4-case sentinel) sandbox-refactor
48217b68 #1489 feat(open-swe): add E2B sandbox provider (#1489) Deferred additive E2B provider; separable but ships on the async sandbox.py base sandbox-refactor
67abf5b0 #1659 fix: surface attributed PR creation failures (#1659) Deferred PR-attribution-failure guard (new mw, safe imports); heavy conflict on diverged open_pull_request.py pr-attribution
304032fa #1680 chore: clarify question answering prompt (#1680) Deferred reword Slack info-only answer guidance; conflicts w/ fork's customized Slack prompt prompt-tweaks
5003c953 #1683 feat: open Linear-triggered PRs as the triggering user (#1683) Deferred FLAG-HUMAN: adds linear to resolve_github_token per-user OAuth branch (auth surface); depends on #1626 linear.py linear-pr-as-user
f53caff1 #1701 fix: fall back to core GitHub App scope when optional grants missing (#1701) Deferred FLAG-HUMAN: GitHub-App permission-ladder degrade (auth surface); heavy conflict on diverged github_app.py/_resolve_proxy_token github-app-scope
22e024cb #1704 fix: link issue PRs and prompt repo conventions (#1704) Deferred issue/PR linking + repo-convention prompt; clean but prompt-conflict risk vs #113 webhook-issue-linking
27b0ddeb #1708 feat: add GPT-5.6 OpenAI models (#1708) Deferred FLAG-HUMAN: adds OpenAI GPT-5.6 to the model picker; fork's picker is Bedrock/Fireworks-only — needs a product decision before adopting OpenAI models. Gateway (#155) can route OpenAI if adopted. model-picker
62e0ca2d #1709 fix: stale admin model defaults after model upgrades (#1709) Deferred stale admin model-default cleanup in team_settings after model upgrades; applies to fork's default-model resolution. model-picker
138ab9ec #1710 fix: bump langchain-fireworks to 1.4.4 (#1710) Deferred langchain-fireworks 1.4.4 bump; fork uses Fireworks as a primary provider — adopt with a lockfile refresh. deps
71e3b818 #1713 fix: align reviewer eval with published findings (#1713) Deferred reviewer-eval/judge alignment; touches reviewer.py + add_finding/publish_review which are fork-diverged — reconcile against fork's reviewer before porting. reviewer-eval
35659177 #1718 fix: sanitize orphaned OpenAI tool results (#1718) Deferred Correctness fix for orphaned OpenAI tool results before Responses API calls. Fork already wires SanitizeOpenAIResponsesMiddleware and uses OpenAI, so relevant - adopt, but the middleware file and pyproject conflict (fork copy diverged from an earlier pick); hand-resolve and refresh uv.lock. openai-sanitize
092abafa #1717 fix: enforce terse Slack tool messages (#1717) Deferred Terse Slack tool-message UX fix. Impl (prompt.py + slack_thread_reply.py) auto-merges; only tests/test_github_comment_prompts.py conflicts against the fork prompt customizations - adopt and resolve that one test. slack-terse
92d63170 #1720 fix: separate review access from automatic reviews (#1720) Deferred Separates review access from automatic reviews; touches fork-diverged webapp.py + webhooks/github.py auto-review flow + review UI. Cherry-picks clean textually but is an access-control change on the fork-customized opened/ready_for_review auto-review surface - re-inspect semantics and get human sign-off before picking. reviewer-access

Maintenance: after a git sync, add new dev..upstream/main SHAs as Untriaged (edit triage.jsonl) and bump "Last synced". A successful git cherry-pick -x auto-moves the row to Landed via the post-commit journal + make triage-reconcile.