Skip to content

[pull] main from LibreChat-AI:main - #60

Merged
pull[bot] merged 2 commits into
innFactory:mainfrom
LibreChat-AI:main
Sep 30, 2026
Merged

pull[bot] merged 2 commits into
innFactory:mainfrom
LibreChat-AI:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

danny-avila and others added 2 commits September 30, 2026 06:30
…Matching (#271)

* 🎯 feat: Diagnose Every Failing Workspace Edit and Negotiate Tolerant Matching

A rejected edit batch now reports every failing edit by position: missing
edits name the nearest candidate line and flag elided, line-numbered,
whitespace-only or CRLF mismatches, and ambiguous edits give their match
count and line numbers. Two negotiated edit features add tolerant matching
(line-trimmed, indentation-flexible, whitespace-normalized) and replaceAll,
with per-edit match reporting only for requests that opt in.

* fix: Honor Edit Boundaries and Negotiated Capabilities

* fix: Preserve Matched Line Endings in Tolerant Edits

* fix: Reject Unrepresentable Tolerant Edit Boundaries

* fix: Require Tolerant Edit Boundary Line Breaks

* fix: Bound Edit Matching and Redact Edit-Only Diagnostics

* fix: Stream Workspace Replace-All Results Within Memory Bounds

* fix: Preserve Extra Blank Lines in Tolerant Edits

* fix: Honor Full Edit Wrappers and Linear Candidate Budgets

* fix: Retain Every Failed Edit Position in Bounded Diagnostics

---------

Co-authored-by: Lia <lia@librechat.ai>
…dbox (#276)

* 🛡️ fix: Deny a Non-Lane Root's Own Git Metadata in the Native SRT Sandbox

A trusted-vm command in a native (non-lane) SRT workspace could write the
registered root's own `.git/hooks/*` and `.git/config`, planting a hook or a
`core.fsmonitor` / `filter.*` entry that then runs unsandboxed the next time
the user — or trusted worker code — invokes Git in that checkout.

The non-lane config relied on SRT's mandatory `.git/hooks` and `.git/config`
denies, which on Linux are computed from the worker *process's* current
directory (see `sandbox/linux-sandbox-utils.js`). The worker's cwd is its home
(the systemd user unit sets no WorkingDirectory), never the registered root, so
those denies landed elsewhere and the root's `.git` was writable. macOS was
unaffected because it applies global `**/.git/hooks/**` and `**/.git/config`
Seatbelt patterns.

`NativeSrtWorkspaceCommandSandbox` now adds explicit `denyWrite` entries for the
registered root's own Git metadata when `<root>/.git` is a directory (lanes are
untouched — they already keep the whole common Git directory read-only):

- `<root>/.git/hooks` and `<root>/.git/config` unconditionally;
- `<root>/.git/config.worktree` and `<root>/.git/commondir` where they exist;
- the same files for every submodule Git directory under `.git/modules/**`
  (including nested submodules) and every `.git/worktrees/*`.

`commondir` and `config.worktree` are denied only where present: Git reads them
strictly and SRT would otherwise mask an absent target with an empty `/dev/null`
bind Git cannot parse, breaking ordinary commands. Denied files that exist are
re-bound read-only, so `.git/config` stays readable (remotes keep working) while
writes fail; a benign `git commit` in the workspace is unaffected.

Tests: a live SRT test gated on `LIBRECHAT_CODE_LIVE_SRT_TESTS=1` runs the
sandbox with `process.cwd()` outside the root and asserts hooks, config, an
existing per-worktree config, a submodule config, and a linked-worktree
commondir cannot be tampered while a normal commit still succeeds; wired into
the Linux native-sandbox CI job. A fast unit test asserts the computed
`denyWrite` set. `packages/code/README.md` documents the guarantee and the
residual writable-`.git` vectors (whole-`.git` replacement, a fresh top-level
commondir, a nested repo) that the personal-machine SRT trust model accepts.

* 🔁 fix: Refresh Root Git Metadata Denies per Command and Fail Closed

The root's Git metadata denies were a snapshot taken at sandbox
initialization, but the worker is long-lived: a repository, submodule, or
linked worktree created on the host afterwards stayed writable until restart.
Ordinary root commands now recompute the set and pass it as a per-command
`denyWrite` override (every other filesystem field is the session policy),
the way SRT recomputes its own mandatory denies on every wrap. Native Windows
keeps the initialization snapshot because srt-win rejects per-command
allowRead/allowWrite.

Inspecting the metadata now treats only ENOENT/ENOTDIR as absence; any other
failure propagates, so an unreadable `.git` fails the command closed
(COMMAND_UNAVAILABLE) instead of silently dropping a deny.

Corrects the `config.worktree` comment: in a repository that already enables
`worktreeConfig`, a missing per-worktree config stays creatable, because
denying an absent file makes every Git command fail. The README lists it with
the other writable-workspace residuals.
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit 836d001 into innFactory:main Sep 30, 2026
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant