Selective intake cycle over the post-baseline upstream delta. Provenance:
- Upstream remote:
https://github.com/tdlib/td.git - Baseline (lower bound):
upstream-baseline-2026-05-24-e0943d068ce9→e0943d068ce90b5010f1aea946e6901e25b43bf6(tdlib 1.8.64) - New tip (upper bound):
upstream-baseline-2026-06-15-a17f87c4cff7→a17f87c4cff7b90b278d12b91ba0614383aaee82 - Comparison range:
e0943d068ce9..a17f87c4cff7— 247 commits (2026-05-19 → 2026-06-13)
Plan and evidence: docs/Plans/UPSTREAM_BACKPORT_PLAN_2026-06-15.md and its Wave A addendum docs/Plans/UPSTREAM_BACKPORT_PLAN_2026-06-15_WAVE_A_ADDENDUM.md.
| Upstream SHA | Mode | Fork file | Summary |
|---|---|---|---|
84f21a1d8 |
exact | td/telegram/MessageContent.cpp |
add_message_content_dependencies resolves bot_user_id for ManagedBotCreated |
a74cc9af8 |
local-equivalent | td/telegram/DraftMessage.hpp |
clear persisted-draft reply to local/yet-unsent same-chat message |
dc73b3ca3 |
local-equivalent | td/telegram/MessagesManager.cpp |
DB-dialog repair re-fetches messages + reloads full dialog info |
c3759d5c5 |
exact | td/telegram/CallActor.cpp |
pending-call notification posted via send_closure_later |
e95e1fd0d |
local-equivalent | td/telegram/DialogAction.h |
operator== also compares random_id_ and text_ |
1a8d24176 |
exact (default-param) | td/telegram/VideosManager.{cpp,h}, MessageContent.cpp |
repair video duration/thumbnail from alternative (HLS) videos |
Of the 8 Wave-A accept_with_repair candidates: 5 landed above (84f21a1d8, a74cc9af8,
dc73b3ca3, e95e1fd0d, 1a8d24176); 39ea84dff is already-present (the fork already uses the
correct option name pending_text_message_period); d78ceefc7 (niche ToDo constructor signature
change) and 4e59e82d0 (include churn touching files absent in the fork) are deferred/dropped.
c3759d5c5 was an additional safe fix surfaced by the feasibility sweep.
Wave A (provenance/inventory) is complete; gate tally over the 247 (all downstream-status missing):
defer_pending_context 207 · reject_not_relevant 28 · accept_with_repair 8 ·
local_equivalent_adaptation 4. No stealth-transport (td/mtproto, tdnet, TlsInit) commit in
the delta. The W11-AI2 deferral is unchanged.
Wave B (minimal correctness backports) is implemented in the tree — TDD-first contract tests then
minimal fix; full build/ctest/sanitizer matrix runs on Linux CI. Landed:
84f21a1d8exact backport:add_message_content_dependenciesnow resolves thebot_user_iddependency forManagedBotCreatedcontent (td/telegram/MessageContent.cpp).a74cc9af8local-equivalent: persisted-draft parse clears same-chat replies that are yet-unsent or local, preserving the fork's existingis_valid_scheduled()guard (td/telegram/DraftMessage.hpp).dc73b3ca3local-equivalent: repair of DB-loaded dialogs re-fetches unresolved messages and reloads full dialog info on failed dependency resolution, keeping the fork's caller-sourceprovenance (td/telegram/MessagesManager.cpp).
Wave B-2 (after a dry-run cherry-pick feasibility sweep of all 244 remaining commits — 55 apply cleanly, 189 conflict — only 2 are safe standalone fixes):
c3759d5c5exact: pending-call notification posted viasend_closure_laterinstead ofsend_closure(reentrancy/ordering hardening) (td/telegram/CallActor.cpp).e95e1fd0dlocal-equivalent:DialogAction::operator==now also comparesrandom_id_andtext_; the upstreamRichMessage message_field is intentionally dropped (feature absent in the fork) (td/telegram/DialogAction.h).
Remaining ~239 commits stay deferred/rejected — product epics (rich-message, instant-view, WebBrowser,
PollMedia, chat-join, live-location, …) requiring td_api.tl + new files + layer-227, which would
violate fork policy "No bulk sync"; not safely backportable standalone.
Contract tests: test/managed_bot_created_dependency_contract.cpp,
test/draft_local_reply_ignore_contract.cpp, test/parse_dialog_repair_refetch_contract.cpp,
test/call_notification_send_closure_later_contract.cpp, test/dialog_action_equality_fields_contract.cpp.
Closeout: docs/Plans/UPSTREAM_BACKPORT_PLAN_2026-06-15_WAVE_B_CLOSEOUT.md.
The product epics flagged "deferred" above were subsequently integrated, epic-by-epic, on
feat/upstream-backport-bulk (not a bulk sync — semantic per-commit detection, dependency-ordered
cherry-picks, fork hardening preserved, contract tests, Linux build GREEN per epic).
- Phase 1 — clean/tractable commits (layer-227 schema, instant-view/PageBlock type additions, managed-bot, etc.): ~101 cherry-picks + 4 local build-fixes. Closeout: docs/Plans/UPSTREAM_BACKPORT_PHASE1_CLOSEOUT_2026-06-16.md.
- Phase 2 — feature epics: chat-join/guard-bot, search-type-filter, in-app web browser,
instant-view RichText/PageBlock (render), poll-media (render), and misc (incl.
checkAuthenticationWebToken, tonsite→in-app-browser). 46 cherry-picks + 8 contract-test/fix commits. Two tightly-coupled, non-mission SEND/content clusters (messageRichMessagecontent type and poll-media links/web-pages-in-polls) are deferred for fork-safety — they would require hand-reconstructing a new content subsystem with wire-serialization risk. Full SHA manifest + verification: docs/Plans/UPSTREAM_BACKPORT_PHASE2_CLOSEOUT_2026-06-18.md.
Verification at Phase-2 tip (799657fd1): stealth/DPI suite 239/239, SonarBlocker 51/51, Phase-1 3/3,
Phase-2 16/16, W3-P poll voter-visibility 9/9, RestrictedRights 12/12 — all GREEN. No td/mtproto
stealth-transport file was modified by the intake.
This section is maintained by this fork and supplements the upstream changelog, which is not currently maintained for fork-specific selective backports and hardening work.
tdlib-obf is maintained as a vendor/security fork of TDLib: master is downstream reality,
while exact upstream provenance and selective intake decisions are tracked separately.
Canonical provenance and audit records:
- docs/Plans/UPSTREAM_BACKPORT_MANIFEST_2026-05-08.md
- docs/Plans/UPSTREAM_BACKPORT_GATING_PLAN_2026-05-08.md
Important: GitHub ahead/behind counters are ancestry-based. A change can be documented here as
backported or locally adapted without reducing the reported behind count unless the exact
upstream commits are ancestors of this branch.
-
W2-Cexact or accept-with-repair backports:a09adfc63,386eca6fe,1a9ef3d68,5340472b0. Local adaptation: topic reply normalization, least-privilege administrator-rights repair, rank-preserving load normalization, and lifetime hardening for use-after-move paths. -
W2Bbounded local-equivalent backports:8fc2344f3,d5714b0b8,bcbe2f309,84d2ea0d8,a96365b5f,9c62782dc,562bce098,aeddf8ca3,336504954. Local adaptation: basic-group rights normalization, reply-to-invalid-message fail-closed cleanup, username error handling repair, and related reply/draft semantics hardening. -
W3-Ppoll hardening: direct merged slice21275249c,c81e6da9f,3e78ebcd8; repository-resident local-equivalent slice084707e99,bb6574d9f,7d56f9c58,bcd2c683c,f654c5c81,1eaf2481e,d6ef00fa9,04498cfbb,1f68a4a84,271c71136,978979edb,ca82791de,b00c67763,0b9e9829b,b5c87eb91,e7cbde50c,d51464eb2,c6411b9c9,dc470c164,1574780ca,02473d316,aaea672ae. Local adaptation: member-only and country-restricted polls, poll vote statistics, explicit unread-poll-vote state and update fanout, fail-closed voter visibility, restriction-reason hardening, quick-reply poll media guards, and poll media send guards. -
W4-Gguest-query and guest-bot capability bundle:57259ff9e,49e592ccc,7aed695bf,339ff0c6c,3fc0b253d,9175d061a,3fbbd52ff,64d4cea86. Local adaptation: guest caller provenance is preserved through parse or object or update paths, guest-query dispatch runs throughdispatch_guest_query_qts_update(...), result parsing remains fail-closed, guest-bot top-dialog selection is isolated, and invalid identifiers are rejected on strict-positive checks before update emission. -
W5-AIbounded text-composition slice currently accounted in the local tree:c3a6ecea6,d747885cb,528988dd9,0c6ea7e09,9571c262f,ff051c4dc,df4bfee0d,c96e67c38,58d72a0e8,a26ccb8c5,990b821c8. Local adaptation: input-text plumbing, shared style-slug validation at the link boundary, promise-safeupdateAiComposeToneshandling, and config-surface baseline hardening. Remaining exact-scope owner or product expansion stays intentionally deferred inW11-AI2. -
W6-Mbounded managed-bot token and access-settings backports:3819fded5,19292458f,b6aa479a9,83506493e. Local adaptation: compatibility-preservinggetManagedBotTokenaliasing, typedbotAccessSettingsread or write surfaces, and shared bot-session or ownership fail-closed dispatch viadispatch_get_managed_bot_token(...),dispatch_managed_bot_access_settings_read(...), anddispatch_managed_bot_access_settings_write(...). -
W7-Dtooling and documentation deltas:3bde4782c,f3713bba0,ed87ce103. Local adaptation: iOS reproducibility controls are already present locally,tdl-coroutineswas already listed, and the fork addsreact-native-tdlibplus an explicit third-party wrapper dependency-audit note inexample/README.md. -
W8-Xbounded residual hardening:13003156a,05600741a. AdditionalW8-Xrows already incorporated or semantically consumed elsewhere in the local tree:3d38fb7aa,bc79a6d2d,528988dd9,c96e67c38,0c6ea7e09,ff051c4dc,df4bfee0d,a26ccb8c5. Local adaptation: targetedMessageContentnull guards, invalid-file-id fail-closed handling, and accounting that consumes some residual rows via the boundedW5-AIbaseline rather than separate cherry-picks.
This section intentionally does not claim full upstream-exact parity. For research-only rows, ignored rows, and exact-scope deferred bundles that are not treated as landed backports, use the manifest and gating plan above.