Skip to content

[pull] main from LibreChat-AI:main - #59

Merged
pull[bot] merged 2 commits into
innFactory:mainfrom
LibreChat-AI:main
Sep 29, 2026
Merged

pull[bot] merged 2 commits into
innFactory:mainfrom
LibreChat-AI:main

Conversation

@pull

@pull pull Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

lia-by-librechat Bot and others added 2 commits September 29, 2026 12:05
)

* feat: Schedule Linked Worktrees as Their Own Workspace Lanes

* fix: Refuse quarantined-parent lanes before enqueue, forward lane policy, reset lane fences

- Check the parent checkout fence before the assignment is stored or queued.
- Forward the linked worktree policy to the forked native sandbox.
- Protect shared Git config, hooks and info even before they exist.
- Reset a lane fence with --reset-workspace-worktree.

* fix: Grant lanes an explicit Git write allowlist, hold checkouts on quarantined lanes, release stale lanes

- A lane writes only shared objects, refs, ref logs, LFS storage and its own
  worktree metadata; the checkout HEAD, index, operation state, config and
  hooks stay read-only without per-path denies.
- A checkout assignment waits on any quarantined lane beneath it.
- Lane registrations are released when their worktree disappears and capped
  at 32, dropping command roots and credential routes.

* fix: Refuse a checkout while a lane keeps a stuck fence; let lane probes read shared Git

- Code API indexes the lane fences enqueued beneath each checkout. A checkout
  reaches enqueue only once no lane holds a slot, so an indexed fence that
  still exists is stuck and the checkout is refused, surviving worker restarts.
- Replay probes of a lane may read its common Git directory (read-only).

* fix: Guard linked-worktree Git grants and unresolved actions

* fix: Guard linked-worktree lanes against accidental Git pruning

* fix: Refuse Git Aliases and Allow Pathspec Flags in Worktree Lanes

* fix: Guard Worktree Git Against Indirect Pruning

* fix: Refuse Git Repository Dispatchers in Worktree Lanes

---------

Co-authored-by: Danny Avila <danny@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
…e Worker Home (#274)

* fix: Grant lane Git reads entry by entry so write binds survive a read-denied home

A read grant on the whole common Git directory masked the write binds
beneath it whenever the checkout lived inside the worker home, which SRT
re-binds under a tmpfs (writes first, then reads). Lanes could not create
their own index.lock or ref locks. Grant each entry off the writable paths
instead, and add a real-SRT regression test with a Linux CI job.

* fix: Re-bind lane Git writes after the common read bind instead of granting entries

Per-entry read grants left the common Git directory as a writable tmpfs
placeholder inside the worker home (pack-refs could strand refs there) and
pinned replaced files to stale inodes. Grant the whole directory read-only
again and, on Linux, list each existing writable Git directory as a deeper
read-deny so SRT re-binds its write mount after the ancestor read bind.
@pull pull Bot locked and limited conversation to collaborators Sep 29, 2026
@pull pull Bot added the ⤵️ pull label Sep 29, 2026
@pull
pull Bot merged commit 3189cfd into innFactory:main Sep 29, 2026
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant