Skip to content

merge: upstream weekly syncs 2026-09-14 (v1.18.30) + 09-21 (v1.18.31) + 09-28 (v1.18.33) + 10-05 (v1.18.34) - #46

Open
lacymorrow wants to merge 161 commits into
lashfrom
LAC-3879/upstream-sync-2026-09-14
Open

lacymorrow wants to merge 161 commits into
lashfrom
LAC-3879/upstream-sync-2026-09-14

Conversation

@lacymorrow

@lacymorrow lacymorrow commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

Weekly upstream syncs from anomalyco/opencode dev into lash. This PR now carries four weeks:

  • 2026-09-14 (LAC-3879): upstream v1.18.30 merge (e43330c27e).
  • 2026-09-21 (LAC-3962): upstream v1.18.31 merge (1c2471149e) — 47 commits (228e9095ba..70a24697ea). Also merged origin/lash (v1.7.14 release + install fix 16e3ca300b) to keep the branch current.
  • 2026-09-28 (LAC-4045): upstream v1.18.33 merge (44308f12c8) — 38 commits (70a24697ea..03e67171ab).
  • 2026-10-05 (LAC-4139): upstream v1.18.34 merge (cf62c6b690) — 39 commits (03e67171ab..907b3bc518), mostly stats/console/docs plus macOS code-signing and namespaced session-identity headers.

Conflict resolution (2026-09-21)

  • 18 package.json version-line conflicts resolved in-place keeping lash 1.7.14 (no checkout --ours, per the pin-drop gotcha).
  • @ai-sdk/togetherai 2.0.41 → 2.0.68 bump auto-merged outside the hunks; verified present after resolution.
  • bun.lock restored from upstream base then bun install; float check clean (delta is internal versions only).
  • Complex files (prompt.ts, app.tsx, prompt/index.tsx, types.gen.ts, keybind.ts) untouched by upstream this week — no escalation.

Conflict resolution (2026-09-28)

  • 19 conflicts, all standard. 18 package.json version-line hunks resolved in place keeping lash versions (1.7.14; console/* stay 1.7.13). No checkout --ours, so no pin-drop.
  • bun.lock restored from the upstream base then bun install (never bun install over conflict markers — UPSTREAM_SYNC.md §13). Float check clean: the only delta vs upstream's lockfile is our 19 internal workspace version lines. Zero third-party drift.
  • Upstream dependency changes verified present after resolution (diffing merge-base → upstream/dev per conflicted file, since files reverted to ours vanish from git diff --cached):
    • packages/core: gitlab-ai-provider 6.15.0 → 6.18.0, open 11.0.4 added
    • packages/opencode: gitlab-ai-provider 6.15.0 → 6.18.0, open 10.1.2 removed
  • Complex files (prompt.ts, app.tsx, prompt/index.tsx, types.gen.ts, keybind.ts, bash.ts) untouched by upstream this window — no escalation.

Conflict resolution (2026-10-05)

  • 20 conflicts. 18 package.json version-line hunks resolved in place keeping lash versions (1.7.14; console/* stay 1.7.13). No checkout --ours, so no pin-drop.
  • Upstream dependency changes verified present after resolution (diffing merge-base → upstream/dev, since files reverted to ours vanish from git diff --cached). This window upstream removed things as part of retiring the S3 data lake, and the removals landed: ./athena export and @aws-sdk/client-athena gone from packages/stats/core, @aws-sdk/client-firehose gone, and packages/stats/server main/exports/start renamed to src/stat-sync.ts.
  • bun.lock restored from the upstream base then bun install. Float check clean: the only delta vs upstream's lockfile is our 19 internal workspace version lines. Zero third-party drift.
  • packages/opencode/test/cli/run/run-process.test.ts — a new conflict class worth reading. Both sides were independently fixing the same flake: the #27371 regression test asserts durationMs < 30_000, which gets noisy on loaded CI runners. Lash (LAC-2386) had widened the explanatory comment and kept cliIt.concurrent. Upstream switched the test to cliIt.live, which runs it serially so competing subprocess spawns stop charging against its wall clock — that fixes the cause rather than padding the budget, so I took upstream's version. I kept lash's observed >15s cold-start figure as a note against anyone later tightening the 30s number, since that datapoint still holds on 2-core runners. Verified by running the file: 13/13 pass.
  • Complex files (prompt.ts, app.tsx, prompt/index.tsx, types.gen.ts, keybind.ts, bash.ts) untouched by upstream this window — no escalation.

Invariants (verified)

  • agent_cycle: shift+tab (packages/tui/src/config/keybind.ts:130)
  • EventCwdUpdated present in types.gen.ts
  • getCwd(ctx.directory) (4 call sites), setCwd + cwd sentinel, detectNaturalLanguage in session/prompt.ts
  • prompt.mode.toggle binding in packages/tui/src/component/prompt/index.tsx

Testing

  • bun turbo typecheck: 30/30 tasks green (re-run after the 2026-10-05 merge).
  • bun test test/cli/run/run-process.test.ts: 13 pass / 0 fail — covers the hand-resolved cliIt.live conflict.

CI

All 8 checks were green on a4806697de (the 2026-09-28 head), including e2e (windows) (21m57s). CI for the 2026-10-05 merge is running on 0375bcaf8c.

Two upstream packages/app Playwright specs (open-file-expand-folder "trailing Windows separator", file-browser-sidebar-tab-switch "when switching file tabs") failed the Windows job on this branch's 2026-09-14 and 2026-09-21 runs and pass now. Upstream changed nothing in packages/app/src or either spec in the merged window (only version-sync commits), so the code under test is unchanged and these are flaky on Windows, not broken. Tracked as LAC-4138 so the flake gets fixed rather than re-diagnosed every sync. It is not a reason to hold this PR.

Not yet verified (why this is not self-merged)

Everything checkable without a terminal is checked: CI 8/8, typecheck 30/30, and the lash invariants verified in source, including the double-left-border row layout that regressed once before (LAC-163) — outer border={["left"]} with the ╹ connector, then flexDirection="row" wrapping a width={1} alignSelf="stretch" inner bar, at packages/tui/src/component/prompt/index.tsx:1442-1455.

What is not verified is the interactive half of the UPSTREAM_SYNC.md post-merge QA checklist: rendered border colors and equal bar heights, Tab vs Shift+Tab routing under real keypresses, execution-mode colors, and shell-mode cd updating the footer cwd. Those need a real terminal driving the OpenTUI app and cannot be done headlessly. That pass is tracked in LAC-3268 (todo, unassigned). One known open defect already sits in that area: LAC-3732, cd not updating the footer cwd, which predates this sync.

lash is the branch your daily shell runs from and this PR carries 161 commits, so I am leaving the merge to you rather than self-merging a four-week backlog that the mandated visual pass has not covered. Nothing technical is blocking it.

Paperclip: LAC-3879, LAC-3962, LAC-4045, LAC-4139. Process: UPSTREAM_SYNC.md.

🤖 Generated with Claude Code

vglafirov and others added 30 commits September 7, 2026 11:03
Co-authored-by: yeqisong <yeqisong@authing.com>
Co-authored-by: Frank <frank@anoma.ly>
Co-authored-by: Aljosha Friemann <1730315+afriemann@users.noreply.github.com>
…#48225)

Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
Co-authored-by: rekram1-node <rekram1-node@users.noreply.github.com>
- Merge upstream/dev (v1.18.30, 29 commits) into lash
- Keep lash package versions (1.7.x) across all packages
- Preserve shell-mode features: getCwd, setCwd, cwd sentinel, ExecutionModeProvider, EventCwdUpdated
- Regenerate bun.lock after merge
- agent_cycle=shift+tab invariant preserved

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
vaprdev and others added 24 commits September 28, 2026 15:55
Cross-compiled darwin binaries ship with an invalid Bun signature, which breaks codesign verification and publisher-based allowlists. Sign them on macOS with the Developer ID certificate and hardened runtime, matching V2, then repack the release zips and publish the signed binaries to npm and Homebrew.

Refs anomalyco#46313
…52415)

Co-authored-by: rekram1-node <rekram1-node@users.noreply.github.com>
Merges 38 upstream commits (70a2469..03e6717) from anomalyco/opencode dev
into the lash branch.

Conflicts (19, all standard):
- 18 package.json version-line hunks resolved in place, keeping lash versions
  (1.7.14; console/* stay 1.7.13). No `checkout --ours`, so no pin-drop.
- bun.lock regenerated from the upstream base per UPSTREAM_SYNC.md section 13.
  Float check clean: the only delta vs upstream's lockfile is our 19 internal
  workspace version lines. Zero third-party drift.

Upstream dependency changes verified present (LAC-3413 gotcha check, diffing
merge-base -> upstream/dev per conflicted file):
- packages/core: gitlab-ai-provider 6.15.0 -> 6.18.0, open 11.0.4 added
- packages/opencode: gitlab-ai-provider 6.15.0 -> 6.18.0, open 10.1.2 removed

Invariants verified: agent_cycle=shift+tab, EventCwdUpdated, getCwd(ctx.directory),
setCwd + cwd sentinel, detectNaturalLanguage, prompt.mode.toggle.
Upstream touched none of the flagged complex files (prompt.ts, app.tsx,
prompt/index.tsx, types.gen.ts, keybind.ts, bash.ts) this window, so no escalation.
@lacymorrow lacymorrow changed the title merge: upstream weekly syncs 2026-09-14 (v1.18.30) + 2026-09-21 (v1.18.31) merge: upstream weekly syncs 2026-09-14 (v1.18.30) + 2026-09-21 (v1.18.31) + 2026-09-28 (v1.18.33) Oct 4, 2026
@lacymorrow

Copy link
Copy Markdown
Owner Author

e2e (windows) is pre-existing upstream breakage, not from these syncs

This PR has sat at UNSTABLE since 2026-09-21 on a single red check. Mergeability itself is fine (mergeable: MERGEABLE, no conflicts). The red check is e2e (windows), failing on two Playwright tests:

  • packages/app/e2e/regression/open-file-expand-folder.spec.ts — "trailing Windows separator"
  • packages/app/e2e/regression/file-browser-sidebar-tab-switch.spec.ts — "when switching file tabs"

Both fail the same way: expect(locator).toBeVisible() → element(s) not found after 10s, then the 60s test timeout, through all retries.

Why it isn't ours:

  1. Both files are upstream's, added in July, before any commit in this PR's range:
    • open-file-expand-folder.spec.ts → 237e694df0 fix(app): expand Windows file tree folders (#39249), 2026-07-28
    • file-browser-sidebar-tab-switch.spec.ts → d595c7e265 feat(app): review panel updates (#36240), 2026-07-13
  2. git log origin/lash..HEAD -- <each file> returns 0 commits — nothing in this PR touches either test or, by extension, the merge resolutions near them.
  3. The same two tests already failed on this branch's 2026-09-14 run (run 34831976605), alongside several more upstream packages/app tests that upstream has since fixed. The 2026-09-21 run narrowed to just these two. The trend is upstream repairing its own Windows suite, not a lash regression accumulating.
  4. These are packages/app (upstream's web app) tests. They touch none of the lash fork surface — shell mode, cwd tracking, TUI prompt, keybinds.

The reason this never showed up as red on lash itself is that the test workflow is PR-triggered; the lash branch only runs beta / compliance-close on schedule, so upstream's Windows e2e state is invisible until a sync PR opens.

Per Rule 28 I'm not fixing upstream's packages/app Windows suite inside a sync PR — that would mix unrelated change into a merge commit that needs to stay auditable. Filing it separately.

The sync work itself is verified green: bun turbo typecheck 30/30, all lash invariants checked, zero third-party lockfile drift. Merge decision is yours.

@lacymorrow

Copy link
Copy Markdown
Owner Author

Correction: e2e (windows) passed. Those two specs are flaky, not broken.

My comment above called this pre-existing upstream breakage. The "not caused by these syncs" part holds. The "broken" part does not: the re-run on a4806697de came back green, all 8 checks, with e2e (windows) passing in 21m57s.

The two specs fail and pass on identical code. Across the merged window (70a24697ea..03e67171ab), upstream touched packages/app only with the two sync release versions commits for v1.18.32 and v1.18.33 — no change to packages/app/src, and no change to either spec file. Same app under test, fail on 2026-09-14 and 2026-09-21, pass on 2026-10-04. That is flake, most likely a timing-sensitive toBeVisible() on the slower Windows runner, not a defect the syncs exposed.

I've rewritten the PR description accordingly and will re-scope LAC-4138 from "permanently red, consider skipping" to "deflake these two specs." Skipping them would have been the wrong fix, and worth catching before someone acted on it.

PR is CLEAN and MERGEABLE with no outstanding review comments.

39 upstream commits (03e6717..907b3bc), mostly stats/console/docs plus
macOS code-signing and session-identity-header fixes.

Conflicts, all standard:
- 18 package.json version lines: resolved in place keeping lash 1.7.14
  (console/* 1.7.13). No `checkout --ours`, so no dropped upstream dep pins
  (LAC-3413 gotcha). Verified upstream's S3-lake retirement landed: athena
  export + @aws-sdk/client-athena/firehose removed, stats/server renamed to
  src/stat-sync.ts.
- bun.lock: regenerated from the upstream base. Float check clean — only our
  19 internal workspace version lines differ from upstream's lockfile, zero
  third-party drift.
- packages/opencode/test/cli/run/run-process.test.ts: both sides were fixing
  the same wall-clock flake in the anomalyco#27371 regression test. Took upstream's
  `cliIt.live` (serializes the test, removing the competing-spawn pressure at
  the root) over lash's comment-only budget widening, and kept lash's
  observed >15s cold-start note from LAC-2386 as a warning against tightening
  the 30s budget.

Complex files (prompt.ts, app.tsx, prompt/index.tsx, types.gen.ts,
keybind.ts, bash.ts) untouched by upstream this window — no escalation.

Invariants verified: agent_cycle=shift+tab, EventCwdUpdated in SDK types,
getCwd(ctx.directory) + setCwd + cwd sentinel + detectNaturalLanguage in
prompt.ts, prompt.mode.toggle on ctrl+space.
@lacymorrow lacymorrow changed the title merge: upstream weekly syncs 2026-09-14 (v1.18.30) + 2026-09-21 (v1.18.31) + 2026-09-28 (v1.18.33) merge: upstream weekly syncs 2026-09-14 (v1.18.30) + 09-21 (v1.18.31) + 09-28 (v1.18.33) + 10-05 (v1.18.34) Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.