Skip to content

build: move to Code - OSS 1.138.0 - #465

Merged
rmyndharis merged 1 commit into
mainfrom
build/code-oss-1.138.0
Sep 26, 2026
Merged

rmyndharis merged 1 commit into
mainfrom
build/code-oss-1.138.0

Conversation

@rmyndharis

@rmyndharis rmyndharis commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Moves the Code - OSS server from 1.133.0 to 1.138.0. The published server-1.138.0 prerelease was built from this branch by build-vscode-oss.yml.

1.138.0 still targets Node 24 (remote/.npmrc names 24.18.1; the bundled Termux runtime is 24.18.0, and no startup check refuses it). It also locks the same node-pty, @parcel/watcher and @vscode/sqlite3 the Bionic overlay builds, so the runtime and native addons stay as they are.

Changes:

  • VSCODE_VERSION and VSCODE_COMMIT name the 1.138.0 tag (7debcd0e).
  • 0001 and 0012 are rebased onto moved context; their added and removed lines are unchanged, and all 19 patches apply to 7debcd0e in order. patches/fingerprints.txt rows still match.
  • server.js: the 1.138 workbench page trusts inline scripts by a per-request nonce ({{WORKBENCH_SCRIPT_NONCE}}) instead of hashing bare <script> tags. The two scripts it adds (trusted link domains, extension recommendations) would have been refused without an error, so extendWorkbenchPage now writes the page's own nonce placeholder when the page uses one. test-server-bootstrap.js covers the 1.138-shaped page.
  • glibc-shim.c: the agent host's @github/copilot-linux-arm64 moves to 1.0.84-4, whose runtime.node imports malloc_trim@GLIBC_2.17. Bionic has no malloc_trim at any API level, so the forwarder would abort on the first call. It is now answered with mallopt(M_PURGE).
  • @microsoft/mxc-sdk 0.8.0 replaced its glibc linux-test-proxy with a Mach-O unix-test-proxy. That path leaves the ELF allowlist in verify-android-elf.py, whose stale-entry check would otherwise fail packaging, and LEGAL_NOTICES.md lists the thirteen binaries 0.8.0 ships.
  • VSCODE_LOC_COMMIT moves to Updated strings from microsoft/vscode-loc-drop@0d6c79fe1758ae1e79bf289e187c477e0bc439ec microsoft/vscode-loc#2412 (06b1c836), the first string drop after the 1.138.0 tag. It is one commit on top of the previous pin and is reachable through its pull request ref; vscode-loc's main has not moved since 2026-09-04. All 13 bundles build at 100%.

Verified on a Pixel 10 API 36 emulator, upgrading from a main build (1.133.0, versionCode 15) to this build (versionCode 16 locally), with the upgrade setup re-extracting the tree:

  • The server reports 1.138.0 / 7debcd0e, /version answers 200, and the workbench loads with the VSCodroid walkthrough (0011).
  • Both injected scripts carry the nonce and run: the page's configuration holds the trusted domains, including login.microsoftonline.com, and the Black Formatter recommendation.
  • Terminal (0003): node 24.18.0, python3 3.14.6, git 2.55.0, and vscodroid --version prints 1.138.0.
  • Extension host (0004). vscodroid --install-extension anthropic.claude-code installed anthropic.claude-code-2.1.283-alpine-arm64 (0001 + 0009). Its CLI printed 2.1.283 (Claude Code) through libclaude-launch.so, rc 0.
  • OAuth relay (0006, 0012, 0019): a Microsoft sign-in opened without a prompt. The Custom Tab's state decoded to the full callback on the new stable-7debcd0e route. Sent back with prompt=none, the callback reached the app and the extension got Microsoft's answer after 51 s.
  • Touch menus (0014, 0015, 0017): the main menu and the File submenu open on tap, and the submenu scrolls without closing.
  • Agent host: the Copilot backend runs with the glibc runtime.node 1.0.84-4 mapped through the libc.so.6 stub and libglibc-shim.so, with no glibc-shim log lines. The new stub exports malloc_trim@@GLIBC_2.17; the previous one did not.
  • A Japanese locale loads a translated workbench. Reloads show no failing requests besides the expected vsda 404s.
  • JVM suite, test-server-bootstrap.js, verify-android-elf.py --self-test, check-library-attribution.py and the packaging gates pass.

The same upgrade path on a Pixel 7 Pro API 33 emulator (minSdk): the server reports 1.138.0, the terminal tools and vscodroid --version answer, vscodroid --install-extension anthropic.claude-code installs the alpine-arm64 build, its CLI runs through the launcher and seccomp shim (rc 0), and both injected scripts run.

Not verified: a signed-in chat turn, which is what calls malloc_trim.

1.138.0 still targets Node 24 (remote/.npmrc names 24.18.1, the bundled
Termux runtime is 24.18.0) and locks the same node-pty, @parcel/watcher
and @vscode/sqlite3 that the Bionic overlay builds, so the runtime and
the native addons stay as they are.

- VSCODE_VERSION and VSCODE_COMMIT name the 1.138.0 tag and 7debcd0e.
- 0001 and 0012 are rebased onto moved context. Their added and removed
  lines are unchanged, and all nineteen patches apply to 7debcd0e in
  order.
- The workbench page's policy now trusts inline scripts by a nonce the
  server writes into each request, and no longer hashes bare <script>
  tags. The two scripts server.js adds to the page (trusted link domains
  and extension recommendations) would have been refused without a
  word, so they now carry the page's own nonce placeholder when the page
  uses one.
- The agent host's @github/copilot-linux-arm64 moves to 1.0.84-4, whose
  runtime.node imports malloc_trim@GLIBC_2.17. Bionic has none at any
  API level, so its forwarder would abort on the first call. The glibc
  shim now answers it with mallopt(M_PURGE); every other strong import
  is exported by Bionic at API 33 or already by the shim.
- @microsoft/mxc-sdk 0.8.0 replaced its glibc linux-test-proxy with a
  Mach-O unix-test-proxy, so that path leaves the ELF allowlist, whose
  stale-entry check would otherwise fail the packaging, and
  LEGAL_NOTICES.md lists the thirteen binaries 0.8.0 ships.
- VSCODE_LOC_COMMIT moves to the first vscode-loc string drop after the
  1.138.0 tag, microsoft/vscode-loc#2412, one commit on top of the
  previous pin and kept reachable by its pull request ref. vscode-loc's
  main has not moved since 2026-09-04: against the localize() keys in
  the 1.138 sources, that commit lacks about 5 percent of them and
  leaves about 2,800 more in English in each language.

The published server-1.133.0 no longer matches patches/, so a
server-1.138.0 build has to be published before an APK can be packaged.
@rmyndharis
rmyndharis merged commit 6c5dc84 into main Sep 26, 2026
4 checks passed
@rmyndharis
rmyndharis deleted the build/code-oss-1.138.0 branch September 26, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant