Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 11 additions & 10 deletions VENDORED.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ never a convenience.
| `apps/sidecar` | Derived from upstream's own `apps/sidecar`: of 38 tracked `src/` modules, 5 are byte-identical to upstream (`default-harness.ts`, `source-asset-delivery.ts`, `workflow-closure-apply.ts`, `workflow-probe-handler.ts`, `workflow-run-pack-restore.ts`), 10 are substantially rewritten under the same name (`atomic-write.ts`, `config.ts`, `conversation-state.ts`, `index.ts`, `run-grants.ts`, `signing-keypair.ts`, `step-agent-tools.ts`, `tool-materialization.ts`, `workflow-closure-materialization.ts`, `workflow-run-pack-client.ts`), and the remaining 23 are workbench-only, including the `workflow-host-wiring/` and `workflow-substrate-factory/` module splits of upstream's single-file `workflow-host-wiring.ts` and `workflow-substrate-factory.ts`. A living fork, not a frozen copy, so this row carries no tree hash. | [faremeter/interchange](https://github.com/faremeter/interchange) @ `b5580a02` (v0.3.0) | An app is never npm-published, so no publish can cover the execution host; retired by consuming an upstream-published host, or by renewing this row deliberately | sawyer | 2026-09-19 | `check:killdates` |
| `vendor/intx/agent` | `@intx/agent` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 predates the operator-configurable doom-loop threshold (`afd0c82b`, `c421c092`) the re-vendored `workflow-host` configures; no local delta; retired by the next `@intx/agent` publish | sawyer | 2026-10-26 | `check:killdates` |
| `vendor/intx/db` | `@intx/db` source (`src/`, `migrations/`, drizzle config, manifest, tsconfigs) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 covers the base package but not the `wire_projection` column/loader delta (CL-6324) or the `workflow_definition.origin` column separating a definition from the per-run record of one folded run's deploy (CL-6452), shipped as migrations `0086`/`0087` behind upstream's `0085_add_approval_run_idx`, plus `0088` rewriting the retired `onBodyFailure: "continue"` literal to upstream's `"tolerate"` in stored wire projections; retired when upstream absorbs the deltas | sawyer | 2026-10-26 | `check:killdates` |
| `vendor/intx/hub-api` | `@intx/hub-api` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `b5580a02` (v0.3.0) | npm 0.3.0 covers the base package but not the exported null-principal `resolveApproval` (CL-6345) or the bearer-authenticated workflow-deploy mirror (`middleware/workflow-run-deploy-auth.ts`, CL-workflow-deploy-bearer); retired when upstream absorbs the deltas | sawyer | 2026-09-19 | `check:killdates` |
| `vendor/intx/hub-api` | `@intx/hub-api` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 covers the base package but not the null-principal `resolveApproval` for policy-resolved decisions (CL-6345) or the bearer-authenticated workflow-deploy mirror (`middleware/workflow-run-deploy-auth.ts`, CL-workflow-deploy-bearer); retired when upstream absorbs the deltas | sawyer | 2026-10-26 | `check:killdates` |
| `vendor/intx/hub-sessions` | `@intx/hub-sessions` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 covers the base package but not the pack-acceptance fixes (`ownsWorkflowRunRepo`, `anchorAddressForPackSource`, `decideTerminalRunFlip`), the adopted deploy front + `sourceRef` (CL-6324), the wire-projection writer (CL-6324), malformed tool-call-name sanitization (CL-6478) or the sealed-run terminal-status backfill (CL-6595); retired when upstream absorbs the deltas | sawyer | 2026-10-26 | `check:killdates` |
| `vendor/intx/inference` | `@intx/inference` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 predates doom-loop detection (`8da4c827`, `afd0c82b`, `c421c092`); one local delta: `providers/google-genai-files.ts` builds its upload body as `new Uint8Array(bytes)` because TS 6's lib.dom `BodyInit` rejects `Uint8Array<ArrayBufferLike>` (upstream compiles ESNext-only under TS 5.9); retired by the next publish | sawyer | 2026-10-26 | `check:killdates` |
| `vendor/intx/mail-memory` | `@intx/mail-memory` source (`src/`, manifest, tsconfig) | [faremeter/interchange](https://github.com/faremeter/interchange) @ `a8bc06ae` (origin/main, 2026-08-27) | npm 0.3.0 predates the `@intx/mailbox` extraction (`af03bb90`), on-demand body reads (`54f7c239`) and `expunge` returning the swept uids (`bcabb1f8`) that the re-vendored `workflow-host` binds against; no local delta; retired by the next publish | sawyer | 2026-10-26 | `check:killdates` |
Expand Down Expand Up @@ -60,7 +60,7 @@ crash-loop guard latches, credential/wallet deletion guards with
per-credential grant cleanup (and the removal of the dead `bindingGrants`
construction from `buildCredentialDelivery`), and an orphaned-grant cleanup
migration (upstream `0084`, which took the number our `wire_projection`
migration held — ours is renumbered `0085`).
migration held — ours is now `0086`, behind upstream's later `0085`).

v0.3.0 is also the first release whose `@intx/*` npm publishes cover the
folded model, so the fifteen previously vendored trees that carried no local
Expand All @@ -69,20 +69,21 @@ delta — `agent`, `authz`, `crypto`, `harness`, `hub-agent`, `hub-common`,
`pack-transport`, `storage-isogit`, `tool-packaging`, `types` — are retired:
deleted and consumed as published `@intx/*@0.3.0` packages. The rows
above survive because each carries a local delta the publish lacks, or is
imported at a newer API by a tree that does. The root `package.json` `overrides` pin every `@intx/*`
name to `0.3.0` so external dependencies' older exact pins collapse onto the
same resolution workbench uses: the npm publish for retired names, the
vendored workspace copy for surviving ones.
imported at a newer API by a tree that does. The root `package.json` `overrides` pin every npm-consumed `@intx/*`
name to `0.3.0` and every vendored name to `workspace:*`, so external
dependencies' own `@intx/*` pins collapse onto the same resolution workbench
uses: the npm publish for retired names, the vendored workspace copy for
surviving ones.

Local modifications (all surviving `vendor/intx/*` rows): each package's
exports map is repointed from the upstream `intx-src` resolve condition to
direct TypeScript source resolution (`types`/`default` → `./src/...`), with
`dist/` references and the `customConditions` entry in the shared tsconfig
removed — workbench forbids custom resolve conditions — and each tsconfig
carries `types: ["bun"]`; `vendor/intx/hub-api`
adds a `@types/ssri` devDependency that bun's isolated linker does not hoist
from tool-packaging the way upstream's install does.
`vendor/intx/hub-api` (CL-workflow-deploy-bearer) also adds
carries `types: ["bun"]`. `vendor/intx/hub-api` (CL-6345) accepts
`principalId: null` on `resolveApproval` for a decision a standing-grant
allowance already authorized, skipping the per-principal resolve gate the
HTTP routes still enforce. `vendor/intx/hub-api` (CL-workflow-deploy-bearer) adds
`middleware/workflow-run-deploy-auth.ts`, an optional bearer-authenticated
mirror onto the SAME session-cookie `POST/GET .../workflows/deployments`
route `routes/workflows.ts` already mounts (that route file is otherwise
Expand Down
2 changes: 1 addition & 1 deletion scripts/checks/kill-dates.txt
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
apps/sidecar | sawyer | 2026-09-19
vendor/intx/agent | sawyer | 2026-10-26 | d0d56d9f452b78f4b541ad8f4e89f975e8069446bb98f2c8097b90de4b020243
vendor/intx/db | sawyer | 2026-09-19 | 0a4cdb9a8a6ff19d5d4713cbc4f5cc9257aad839b1fa393b2026e6d5afd828b9
vendor/intx/hub-api | sawyer | 2026-09-19 | f93a383cb5d6acdf50a461b43e4c8991dbdf7e13d34a4e5598e556eaee66308b
vendor/intx/hub-api | sawyer | 2026-09-19 | 42ee33e027559b236065382cb94f393bbcfee69625615894f82be778f34f7aa1
vendor/intx/hub-sessions | sawyer | 2026-09-19 | 53addc3090ad9f54bc4bac8fb50ad8d567ccf46f30bb5403d447351cb16b4fb6
vendor/intx/inference | sawyer | 2026-10-26 | 77fec29b078e8d03e686747c70e6b62ac1fd1434db0fb2c1e12e84b6dc71465f
vendor/intx/mail-memory | sawyer | 2026-10-26 | 9f3601a7fb22e2d1c63daa976f3afccbd79af2187c155a0080c0d60c82450b92
Expand Down
4 changes: 2 additions & 2 deletions vendor/intx/hub-api/VENDORED-FROM
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
Source: https://github.com/faremeter/interchange (packages/hub-api)
Commit: b5580a02fb918eebccc33ded7727ffee781ffbd1 (tag v0.3.0)
Commit: a8bc06ae38661c5e0ed91ded8559bf09f502213d (origin/main, 2026-08-27)
License: LGPL-2.1-only (see vendor/intx/LICENSE)
Local modifications: exports map repointed from the upstream intx-src condition to direct TypeScript source resolution (types/default -> ./src/...); dist references removed. adds a @types/ssri devDependency that bun's isolated linker does not hoist from tool-packaging the way upstream's install does. resolveApproval is exported (with its args/result types and readDurableWorkflowRunLifecycles) and accepts principalId: null for policy-resolved (grant-allowance) decisions, which skip the per-principal approval:<anchorRunId>/resolve gate the HTTP routes still enforce (CL-6345). workflow-run-deploy-auth.test.ts's header comment no longer cites the deleted packages/approvals/test/needs-you.test.ts.
Local modifications: exports map repointed from the upstream intx-src condition to direct TypeScript source resolution (types/default -> ./src/...); dist references removed. CL-6345: resolveApproval's ResolveApprovalRequest accepts principalId: null for policy-resolved (grant-allowance) decisions, which skip the per-principal approval:<anchorRunId>/resolve gate the HTTP routes still enforce; readDurableWorkflowRunLifecycles is re-exported from the barrel for the hub's grant-allowance gate. CL-workflow-deploy-bearer: middleware/workflow-run-deploy-auth.ts (+ test) is a bearer-authenticated mirror onto the session-cookie POST/GET .../workflows/deployments route; MountHubRoutesDeps and CreateAppOpts gain an optional workflowRunAuthenticator that mounts it ahead of resolveTenant, and src/index.ts exports the middleware and its types. Retired at this pin: the @types/ssri devDependency (upstream d86c341b carries it via the catalog), the bare resolveApproval export (upstream ba4359b6) and the needs-you route reservation (CL-7113).
8 changes: 4 additions & 4 deletions vendor/intx/hub-api/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,16 +15,16 @@
},
"dependencies": {
"@hono/standard-validator": "^0.2.2",
"@intx/agent": "0.3.0",
"@intx/agent": "workspace:*",
"@intx/authz": "0.3.0",
"@intx/crypto": "0.3.0",
"@intx/db": "workspace:*",
"@intx/hub-common": "0.3.0",
"@intx/hub-sessions": "workspace:*",
"@intx/log": "0.3.0",
"@intx/mime": "0.3.0",
"@intx/mime": "workspace:*",
"@intx/storage-isogit": "0.3.0",
"@intx/types": "0.3.0",
"@intx/types": "workspace:*",
"@intx/workflow-deploy": "workspace:*",
"arktype": "catalog:",
"better-auth": "catalog:",
Expand All @@ -37,7 +37,7 @@
"devDependencies": {
"@intx/workflow": "workspace:*",
"@types/bun": "catalog:",
"@types/ssri": "^7.1.5",
"@types/ssri": "catalog:",
"openapi-types": "^12.1.3",
"tar": "catalog:",
"typescript": "catalog:"
Expand Down
1 change: 1 addition & 0 deletions vendor/intx/hub-api/src/app.ts
Original file line number Diff line number Diff line change
Expand Up @@ -323,6 +323,7 @@ export function mountHubRoutes(
grantStore,
conditionRegistry,
requireGrant,
approvalStore,
}),
);

Expand Down
29 changes: 15 additions & 14 deletions vendor/intx/hub-api/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,6 @@ export {
type CreateRequireGrantDeps,
type RequireGrant,
} from "./middleware/grant";
export {
createWorkflowRunDeployAuth,
type CreateWorkflowRunDeployAuthDeps,
type WorkflowRunAuthenticator,
type WorkflowRunDeployScope,
} from "./middleware/workflow-run-deploy-auth";
export {
createResolveTenant,
requireAuth,
Expand All @@ -31,19 +25,26 @@ export {
resolveWorkflowPrincipalNames,
resolveWorkflowPrincipalLabels,
} from "./routes/workflow-principal-name";
export {
resolveApproval,
type CreateApprovalRoutesDeps,
type ReadRunLifecycles,
type ResolveApprovalArgs,
type ResolveApprovalResult,
} from "./routes/approvals";
export { readDurableWorkflowRunLifecycles } from "./workflow-run-lifecycle";
export {
createMailTriggeredRunGrantsMaterializer,
setRunToolGrantEffect,
type MailTriggeredRunGrantsDeps,
} from "./run-grant-materialization";
export {
resolveDefinitionSources,
type DefinitionSourceResolution,
} from "./run-source-resolution";
export {
resolveApproval,
type ResolveApprovalRequest,
type ResolveApprovalOutcome,
type CreateApprovalRoutesDeps,
type ReadRunLifecycles,
} from "./routes/approvals";
export { readDurableWorkflowRunLifecycles } from "./workflow-run-lifecycle";
export {
createWorkflowRunDeployAuth,
type CreateWorkflowRunDeployAuthDeps,
type WorkflowRunAuthenticator,
type WorkflowRunDeployScope,
} from "./middleware/workflow-run-deploy-auth";
Loading
Loading