Skip to content

chore: sync upstream main e7742b052be2 - #18

Open
harley wants to merge 17 commits into
coderpush-deployfrom
sync/upstream-e7742b052be2-2b2e56813d02
Open

harley wants to merge 17 commits into
coderpush-deployfrom
sync/upstream-e7742b052be2-2b2e56813d02

Conversation

@harley

@harley harley commented Oct 10, 2026

Copy link
Copy Markdown

What does this PR do?

Merge pinned upstream main e7742b052be2b2340609b9d7dbd32aabcb3e9fb7 into the accepted deployment branch. Fork main remains an upstream-only fast-forward mirror. This PR preserves merge ancestry and is never auto-merged.

Risks

Review product overlays and new migrations before accepting. Acceptance authorizes production build and deployment after exact-commit CI passes and backup restore rehearsal succeeds. Image rollback alone does not reverse database migrations.

How to Test

Product CI runs on this PR and the accepted merge commit. Private operations CI builds immutable images and verifies migrations on a restored production backup before cutover.

Type of Change

  • CI / infrastructure

AI Disclosure

AI tool used: Codex. Automated upstream merge; acceptance stays with the reviewer.

27Bslash6 and others added 17 commits October 6, 2026 23:15
…ca-ai#9088)

fetchFirstPages sent one listIssues call per status category, but
ApiClient.listIssues never puts status_category on the query string, so
all four went out as the same GET /api/issues?limit=50. Each ran the
list query and a COUNT(*), and every bucket held the same unfiltered
first page with the workspace-wide total. Writers find an issue in the
first bucket that holds it, so a deleted issue stayed in three buckets
and a loaded issue moved to done left stale copies behind.

The list now makes one request and groups its rows into the category
buckets client-side. Every reader of the cache looks an issue up by id
and none pages a bucket, so one shared window serves them all, and the
request is the same as before. A custom status the server did not
resolve lands in issueColumnCategory's bucket, so no row is dropped.
Each bucket's total is its own row count.
… off (multica-ai#8983)

antigravityCompletedDespiteTrailingNetworkError exists to preserve a finished
answer when agy fails a follow-up round trip after producing it, but it
recognised exactly one error spelling. agy also reports an exhausted retry as
`API error (attempt N): request failed: Post "...": EOF`, which fell through and
discarded a response already sitting in result.response with its agent_response
step at DONE.

Match the transport cause rather than one sentence. The classifier stays narrow
on purpose: reportTaskResult documents failing closed so a provider 429 or
out-of-credit run can never be shown as Completed, and quota, capacity,
overload, policy and auth rejections all arrive as an HTTP response rather than
a failed round trip. agy's own `request failed:` prefix is excluded too — only
one spelling has been observed and nothing rules out agy reusing it for a
status error.
…-7496) (multica-ai#8559)

* feat(issues): add multi_text and multi_url custom property types

Workspaces could only hold list-shaped values as preset option lists
(multi_select) or member references (multi_actor). There was no way to
keep a list of free-form strings or links on an issue, so teams with
"related docs / spec links / aliases" needs had to either cram them into
one text field (no structure, nothing clickable) or burn one select
option per link.

This adds two property types:

- multi_text: an ordered list of free-form text entries
- multi_url: an ordered list of http(s) URLs

Each entry is validated exactly like a single text / url value
(length caps, http(s)-only for URLs), duplicates are dropped, insertion
order is preserved, and values are capped at 20 entries to respect the
16KB properties-bag budget. Values ride the existing jsonb bag, so the
jsonb_path_ops GIN index, the @> containment filter, and the client
value schema all keep working unchanged.

Filtering matches any single list element exactly (equality) plus "No
value" — the containment form the filter compiler already emits for
array elements, so no new server predicate is needed. List types
deliberately get no sort order and cannot group, like the other
multi-value types.

On the web, list values render as chips; multi_url chips are clickable
and open in a new tab, and the editor popover offers a per-entry open
button, so several related documents or links stay directly reachable
from the issue. The filter menu reuses the scalar input (equality-only
plus "No value"). CLI: comma-separated --value form for both types,
element-equality --property filtering, and display_values rows.

Server-side allowlist widened by migration 500 (check constraint
re-added NOT VALID then validated, same pattern as migration 341).

* fix(properties): address list property review nits

Co-authored-by: multica-agent <github@multica.ai>

* fix(properties): scope list drafts to the edited issue

Co-authored-by: multica-agent <github@multica.ai>

* test(agent): avoid fork races when writing zeroclaw fixtures

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: Bohan-J <bhjiang@outlook.com>
Co-authored-by: multica-agent <github@multica.ai>
…a-ai#9091)

* fix(docs): cite the compose lines that pin MULTICA_IMAGE_TAG

The self-host upgrade warning pointed at a volume mount and a GitHub key comment, so a reader checking the pin looked at the wrong lines.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(docs): use stable self-host upgrade references

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Bohan <bohan@devv.ai>
Co-authored-by: multica-agent <github@multica.ai>
…paths (multica-ai#9101)

Co-authored-by: multica-agent <github@multica.ai>
…301) (multica-ai#9065)

* fix(daemon): resume Hermes sessions across task worktrees

Co-authored-by: multica-agent <github@multica.ai>

* fix(hermes): preserve unreadable history during migration

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: multica-agent <github@multica.ai>
Co-authored-by: multica-agent <github@multica.ai>
…9093)

multi_text and multi_url entries were resolved through the member directory, so a stored string that matched a member reference displayed as that person's name.

Co-authored-by: Cursor <cursoragent@cursor.com>
…turn (multica-ai#9057)

* fix(agent): fail kimi runs whose wire log records a failed turn

kimi's ACP adapter can answer session/prompt successfully while its own
turn failed: the session wire log carries a
{"type":"agent.turn.ended","outcome":"failed",...} record (e.g. a bare
"OAuthConnectionError: OAuth request to https://auth.kimi.com/api/oauth/
token failed" that matches none of the stderr sniffer's terminal
signatures). The run then kept status=completed and published the
intermediate narration as a successfully delivered result, so the daemon
sent no failure signal and retry/continuation policy never saw the
failure (multica-ai#9054).

Fix: after the run, scan the session wire logs - the same source,
turn-boundary rules, and tolerant-line policy as the usage scan
(scanKimiSessionUsage) - for the main agent's failed agent.turn.ended
record, and promote completed->failed carrying kimi's sanitized
diagnostic. Only the structured outcome verdict counts, so conversation
text echoing failure words cannot flip a healthy run; a delegated
agent's failed turn stays that agent's own task path; timeout, abort,
and already-failed runs keep their own terminal semantics.

Complementary to multica-ai#8573's zero-output guard: that incident shape had 26
tool calls and nonempty narration, which a zero-output guard
deliberately preserves.

Fixes multica-ai#9054

Generated-by: GLM-5.3-Flash (ZCode)

* fix(kimi): sanitize the wire diagnostic and scan past oversized records

Review fixes for multica-ai#9057 (CHANGES_REQUESTED, both repros offline with a
fake ACP; no live provider requests):

P1: kimiWireTurnFailure copied the record's errorMessage into the run's
diagnostic unsanitized. The failure path persists Result.Error, and the
shared redact.Text does not redact a quoted JSON credential shape
(request={"api_key":...}) — the sanitized diagnostic the PR described
was not actually provided. The diagnostic now goes through the same
sanitizeAgentDiagnostic pass as every child-process diagnostic before
it reaches Result.Error.

P2: the scan loop used newAgentStreamScanner, whose bufio.Scanner ends
its scan for good at a line beyond agentStreamMaxLineBytes, and the
loop never checked scanner.Err() — a valid but oversized context.append
record ahead of the terminal event hid the failed outcome and kept the
run completed. kimiWireTurnFailure now reads through
readAgentStreamLine, which consumes and discards an over-bound record
whole and keeps the later records readable, and ends the walk
explicitly on any other read failure (keeping what was read, the same
best-effort policy as a truncated tail).

Regressions, all red before the fix and green after:
- TestScanKimiMainTurnFailureSanitizesWireDiagnostic (P1)
- TestScanKimiMainTurnFailureReadsPastOversizedRecord (P2, scan level)
- TestKimiBackendWireTurnFailurePastOversizedRecord (P2, backend e2e
  with the fake ACP: red as got "completed" (error=""), the review's
  exact repro shape)
- TestReadAgentStreamLineSkipsOversizedAndContinues /
  TestReadAgentStreamLineReturnsUnterminatedTail (helper contract; the
  first caught a boundary miss where the cap was crossed only on the
  final buffer chunk)

Generated-by: GLM-5.3-Flash (ZCode)
Co-authored-by: multica-agent <github@multica.ai>
…cess state (multica-ai#8656)

* fix(lark): persist and reconcile typing cleanup across replicas

- preserve terminal trigger targets and per-input cleanup ownership
- reconcile late Adds and source deletion without delaying replies
- recover interrupted ledger indexes and cover lifecycle boundaries

Refs: multica-ai#8655

* fix(lark): restrict typing cleanup to the current application

- match both app operator type and the current App ID
- preserve foreign-app, human and unknown-owner reactions
- cover ownership filtering in fast and durable cleanup paths

Refs: multica-ai#8655

* fix(lark): bound typing recovery and credential retention

- recover taskless indicators after lost debounce timers
- cap workspace ledger admission and redact terminal credentials
- isolate maintenance budgets and test retention and quota boundaries

Refs: multica-ai#8655

* docs(lark): document typing cleanup recovery and rollout limits

- explain ownership, retention, quota and observable terminal outcomes
- document migration upgrades and safe application rollback

Refs: multica-ai#8655

* fix(deps): require patched Go 1.26.9 and x/net 0.60

- Require the patched Go standard library to clear reachable vulnerabilities.
- Upgrade x/net to the matching HTTP/2 security release.
- Align local development prerequisites with the minimum Go version.
Co-authored-by: multica-agent <github@multica.ai>
…I in zh template (multica-ai#9142)

* fix(onboarding): replace archived Kimi CLI with Kimi Code CLI in zh template

Kimi CLI (Python-based) has been archived. Update the Chinese onboarding
issue template to recommend Kimi Code CLI instead, using the new install
endpoints (curl -fsSL / irm). Keep the original official docs link.

* fix(onboarding): document Kimi Code Windows prerequisites

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: xiaoxiang <xx266218@alibaba-inc.com>
Co-authored-by: Bohan-J <bhjiang@outlook.com>
Co-authored-by: multica-agent <github@multica.ai>
* fix: patch Next.js GHSA-vcvr-r3jv-pc5j

* fix(web): require Next.js 16.3.8 security floor (MUL-7842)

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: Yushen <yushen@devv.ai>
Co-authored-by: multica-agent <github@multica.ai>
…tica-ai#8944)

* fix(daemon): detect the Codex CLI nested in ChatGPT.app

ChatGPT.app 26.924 moved the bundled CLI to Resources/codex-cli/bin/codex. Probe that path first and keep the older flat path and Codex.app so existing installs still resolve.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(daemon): require executable Codex bundle CLI

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Yushen <yushen@devv.ai>
Co-authored-by: multica-agent <github@multica.ai>
…ultica-ai#8905)

* fix(api): stop returning raw error text in 500 responses

39 handlers answered a 500 with the message followed by err.Error(),
sending database and store errors (constraint names, SQL states, Redis
errors) to API clients, while the other 720 500 responses in the handler
package send a fixed message. These now send their fixed message too and
log the error with the request's attributes, as the handlers that already
logged it do.

* fix(api): drop raw error text from the task callbacks and skill import 500s

completeTask and failTask sent err.Error() as the whole 500 message, and
the structured skill import put it in the result's Reason on its three
500s. They now send fixed messages and log the error. The task callbacks
keep their 500, so the daemon still retries them: isTransientError reads
the status code, never the body.

* fix(api): close remaining raw error leaks

Co-authored-by: multica-agent <github@multica.ai>

---------

Co-authored-by: Yushen <yushen@devv.ai>
Co-authored-by: multica-agent <github@multica.ai>

@amazon-q-developer amazon-q-developer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This upstream sync PR merges 17 commits adding new features including multi_text/multi_url property types and Lark typing indicator cleanup improvements.

The changes have been reviewed with focus on merge-blocking defects. The code demonstrates solid engineering practices including proper database migration patterns (NOT VALID + VALIDATE for constraint changes), intentional design decisions (documented lack of foreign keys for cleanup resilience), comprehensive error handling, and appropriate concurrency controls.

Key additions:

  • New issue property types (multi_text, multi_url) with validation and deduplication
  • Durable typing indicator cleanup system with retry logic and credential management
  • Multiple database migrations for schema evolution (564-572)

No critical defects found that would block merge. The implementation includes proper bounds checking, error handling, and follows established patterns in the codebase.


You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.


⚠️ This PR contains more than 30 files. Amazon Q is better at reviewing smaller PRs, and may miss issues in larger changesets.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.