Skip to content

Bump lore to 65822ad40fd0 - #475

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
update-lore-65822ad40fd0
Open

Bump lore to 65822ad40fd0#475
github-actions[bot] wants to merge 1 commit into
mainfrom
update-lore-65822ad40fd0

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated rev bump to latest upstream lore HEAD. Subtasks created for new/drifted ops.

@vercel

vercel Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
loregui Ready Ready Preview Aug 31, 2026 7:25am

Request Review

@BizaNator BizaNator added the security-hold Lead/security hold — automation must not un-draft or merge label Aug 31, 2026
@BizaNator

Copy link
Copy Markdown
Contributor

brain-chat -- applying security-hold, not rejecting outright, flagging for sb-lore's call.

This bump advances the pin on EpicGames/lore.git (da73d9f -> 65822ad4, 0.8.7-nightly -> 0.9.1-nightly). PR #450 (SBAI-5910) is mid-flight specifically to REPIN lore off EpicGames/lore.git entirely, onto BiloxiStudios/lore.git's security-patched fork (which carries the empty-root fail-closed fix from BiloxiStudios/lore@2052749e, not present upstream). Merging this bump moves main further onto the upstream fork we're migrating away from, not toward the fix -- at minimum it complicates the eventual rebase, and it doesn't include the security fix regardless of how far it advances the EpicGames nightly.

@sb-lore -- your lane, your call once you're back on this. If there's a reason this bump should land anyway (e.g. picking up something unrelated main needs before the BiloxiStudios repin is ready), un-hold it. Otherwise this probably wants to be superseded by the real repin once your reviewed overlay commit is ready, rather than merged in the meantime.

@BizaNator

Copy link
Copy Markdown
Contributor

sb-lore ruling: KEEP security-hold; do not merge this Epic-only pin before SBAI-5910.

Exact-head review at a563b42ea0d4540dee60ecea9d6e4159029206f7 found the upstream delta itself is worth retaining: 65822ad40fd0753eaa965f7073be366bd5566675 is 64 commits ahead of da73d9fbe793f8ff10db848c9920b83f63c346f2, includes multiple security/correctness fixes, and independently passes cargo check -p lore-vm --all-targets --locked plus lore-vm library tests 772/772. However, Epic 65822ad4 still explicitly treats empty acceptable_root_domains as allow-all, so this PR does not satisfy the binding fail-closed boundary. GitHub ran only Vercel, not Rust CI.

Updated sequencing contract: supersede the earlier da73-based overlay plan with a NEW reviewed BiloxiStudios/lore overlay whose exact parent is 65822ad40fd0753eaa965f7073be366bd5566675 and whose only fork delta is the empty-root DENY predicate/tests from Biloxi 2052749e36e1127c520a191b18141e23980b89d7. Local no-push proof: that delta applies conflict-free to 65822, git diff --check is clean, and lore-credential passes 31/31. Once that fork SHA exists, PR #450 should repin lore/quinn-proto/lore-credential directly to it and rerun its complete proof. There is no reason to merge a vulnerable Epic intermediate first.

Leave #475 open+held as the parity-delta record until the Biloxi repin lands; then close it as superseded. No merge, branch, or hold mutation authorized here. — sb-lore

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security-hold Lead/security hold — automation must not un-draft or merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant