Repository navigation
Delete dead iroh control-plane code - #10765
lawrencecchen wants to merge 7 commits into
Conversation
POST /api/devices/iroh/relay-token has zero callers: repo-wide grep for the path and its relay_token operation hits only the route file and web tests, and full-history git log -S over Packages/ Sources/ ios/ CLI/ cmux-tui/ daemon/ returns no commit in which any client referenced it. The Swift client has fetched relay credentials from POST /api/relay/token since the route was introduced in #7908. Removes the route dir, the relay_token IrohRouteOperation and dispatch, the public broker issueRelayToken (issueRelayTokenForBinding stays for the register bootstrap), its tests, and the stale README sentence.
Production has never set CMUX_IROH_MINT_URL / CMUX_IROH_MINT_HMAC_SECRET_B64, so every registration already took the mint-unconfigured branch and returned relay.status="unavailable"; clients get endpoint-bound fleet credentials from POST /api/relay/token instead. The only importers of the minter client (web/services/iroh/relayMinter.ts, minterUrlPolicy.ts) were trustBroker.ts, env.ts, and their tests; the Rust service services/iroh-relay-minter/ is in no Cargo workspace, package.json, or vercel config, and its only external reference was its own dispatch-only GitHub workflow. register now returns relay unavailable/not_requested directly, preserving the env-unset behavior exactly (minus the failed-issuance audit row). This deliberately removes the dormant n0-hosted fallback option; the registry / relay allow-hook path is the go-forward. Operational follow-up outside this repo: decommission the minter Vercel project and drop the two env vars from the web project.
…rror With the legacy relay-token route and the n0 minter gone, nothing calls IrohRepository.reserveRelayIssuance/completeRelayIssuance/failRelayIssuance (grep: definitions and their direct tests only), and the model constants IROH_RELAY_TOKEN_LIFETIME_SECONDS/IROH_RELAY_TOKEN_REFRESH_SECONDS have zero remaining users. IrohQuotaExceededError has had no producer since #9269 removed the broker quotas (grep for 'new IrohQuotaExceededError' hits nothing); its 429 mappings in the iroh and connectivity route handlers were unreachable. The iroh_relay_token_issuances table, its migrations, and the retention cleanup that drains historical rows all stay: production still holds rows.
…d iroh exports createOfflinePairSessionRecord / verifyAndConsumeOfflineSameAccountPair and their private helpers and types were added in #7908 but no route, broker method, or repository call ever reached them; repo-wide grep hits only crypto.ts and their unit test. The Swift offline-pairing feature verifies attestations peer-to-peer and never calls a server session endpoint. Also removes the constants that existed only for that subgraph (IROH_OFFLINE_PAIR_SESSION_*), serverPublishedIrohPathHints (zero references, not even tests), IROH_SIGNED_PATH_HINT_UPDATE_FOLLOWUP (its only occurrence is its definition; the literal string appears nowhere else, including Swift), and bindingMatchesDiscoveryScope from production (used only by the trust-broker test's in-memory repository, where it now lives as a local fixture helper).
The struct's only occurrence in the entire repo (all Swift under Packages/, Sources/, ios/, CLI/, daemon/, Native/, tests) is its own definition; no code constructs, returns, or names it, including the package's tests. swift build and swift test on the package pass after removal (615 tests in 66 suites; CmxConnectivityPeerSessionTests skipped because it deadlocks on current main independent of this change - the fix is in flight on origin/fix-peer-session-test-deadlock).
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (33)
💤 Files with no reviewable changes (24)
Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthroughThe PR removes the Rust relay-minter service and hosted relay-token flow. It removes related configuration, errors, repository state, trust-broker APIs, offline pairing support, deployment artifacts, and tests. Registration now reports relay credentials as unavailable. ChangesIroh capability retirement
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: ⚪ Minimal · up to The PR removes unused legacy control-plane code with documented validation and no actionable merge-blocking risk remains beyond normal checks and review. Suggested reviewers: 🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 10.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 7 files. (2 skipped: 2 unsupported.) Full details: Cmux Swift Actor IsolationExplanation PASS: The complete pull-request diff contains one Swift production change, and it is deletion-only: Full details: Cmux Swift Blocking RuntimeExplanation PASS: The pull-request diff contains one Swift path, and it only deletes Full details: Cmux Browser Automation Off-MainExplanation PASS: The PR diff contains no changes to Full details: Cmux Expensive Synchronous LoadExplanation PASS: The PR changes only one Swift path, deleting Full details: Cmux Cache Substitution CorrectnessExplanation PASS. The production Swift/TypeScript diff removes relay, offline-pair, and configuration code. It does not replace a fresh authoritative read with a cached or opportunistic value. Added production code contains no cache, stale, snapshot, history, undo, or persistence signals. Retained Iroh persistence paths still read from the database through Full details: Cmux No Hacky SleepsExplanation PASS: The PR introduces no fixed sleeps, timers, polling, delayed dispatch, or wall-clock synchronization in covered TypeScript, JavaScript, shell, or build/runtime code. The PR diff contains only deletions plus comments, configuration cleanup, an immediate Full details: Cmux Algorithmic ComplexityExplanation PASS: The pull-request diff is predominantly deletions (72 additions, 7,401 deletions). The added production TypeScript lines only restore union members, comments, and a constant-status branch; they add no loops, collection scans, sorting, filtering, joins, or rescans. The only added collection lookup ( Full details: Cmux Swift ConcurrencyExplanation PASS: The PR changes only one Swift file, and the diff deletes Full details: Cmux Swift `@Concurrent`Explanation PASS — The PR’s only Swift change deletes Full details: Cmux Swift Package BoundariesExplanation PASS — The only Swift change deletes Full details: Cmux Swiftpm LockfilesExplanation PASS. The changed Full details: Cmux Swift LoggingExplanation The isolated PR diff contains one Swift change: deletion of Full details: Cmux User-Facing Error PrivacyExplanation PASS. The pull-request diff does not add a user-facing error or diagnostic that exposes a prohibited implementation detail. The retained API responses use generic values such as Full details: Cmux Full InternationalizationExplanation PASS: The PR introduces no new user-facing Swift text, web UI copy, localized metadata, or locale message keys. The only surviving production additions are developer comments and the internal Full details: Cmux Swiftui State LayoutExplanation PASS: The PR has no SwiftUI state-layout change. The only changed Swift path deletes Full details: Cmux Architecture RethinkExplanation PASS — The only Swift change deletes the unreferenced Full details: Cmux Swift Auxiliary Window Close ShortcutsExplanation PASS: The only Swift change deletes the unused Full details: Cmux Source ArtifactsExplanation PASS. The diff from origin/main to HEAD adds no files and adds no artifact-like paths. It removes the dormant relay-minter service, its Cargo.lock, workflow, fixture, and related source. The remaining additions are hand-written source, configuration, documentation, and tests. No logs, screenshots, recordings, temporary directories, caches, build output, dependency checkouts, or broad scratch directories enter source control. The .gitignore change removes ignore rules with the deleted service. Full details: Cmux No Test Or Debug Seam In Production SourceExplanation PASS. The only changed Swift production source is the deletion of Full details: Cmux No Ambient Global StateExplanation PASS: The pull request has one production Swift change, and it deletes Full details: Description checkExplanation The description is detailed and directly aligned with the pull request. It explains what changed, why the code was safe to remove, preserved components, testing results, and rollback steps. It does not include the template checklist, review-trigger comment, or demo-video section, but these omissions are non-critical because the change is not a UI change and the required summary and testing information are present.
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Autoreview P1 (429 mapping removal) refuted with evidence at the PR base (3f98f5d): the only construction of IrohQuotaExceededError in the entire tree is web/tests/iroh-route-handler.test.ts:368, mocking issueRelayToken, which this PR deletes. Production code never constructs it: repository.ts carries only the import, an error-union member, and a tag type-guard, and no challenge or pair-grant deny site produces the error (cmux#9269 removed every broker quota on 2026-07-31; the README text claiming otherwise was stale and is corrected in cmux#10731). The 429 arms in connectivity/routeHandler.ts and iroh/routeHandler.ts were therefore unreachable, and deleting them changes no client-observable behavior. |
|
Still live; this broad dead-code removal currently conflicts with main, so leaving it for owner review. |
Deletes provably dead iroh control-plane code left behind by the migration from client-minted broker credentials to registry-based relay admission: 7,467 lines removed, 80 added, across five single-cluster commits. Every deletion was verified by repo-wide grep,
tsgo --noEmit, and the full relay/iroh web test files; the Swift deletion byswift build+swift teston the package.Clusters and evidence
1. Legacy broker relay-token route (721d8bc, 130 lines).
POST /api/devices/iroh/relay-tokenhad zero callers: grep for the path,relay_token, andissueRelayTokenacrossPackages/,Sources/,ios/,CLI/,cmux-tui/,daemon/,scripts/,tests_v2/hits only the route file and web tests, and full-historygit log -Sshows no client ever referenced it. The Swift client has fetched relay credentials fromPOST /api/relay/tokensince #7908; #10731 documents the same finding. Removed the route dir, therelay_tokenoperation, the brokerissueRelayTokenAPI, and their tests.2. n0-hosted relay minter compatibility path (017a52e, 6,549 lines). Production has never set
CMUX_IROH_MINT_URL/CMUX_IROH_MINT_HMAC_SECRET_B64, so every registration already took the unconfigured branch and returnedrelay.status = "unavailable". The only importers ofweb/services/iroh/relayMinter.tsandminterUrlPolicy.tsweretrustBroker.ts,env.ts, and tests; the Rust serviceservices/iroh-relay-minter/(929-line lib.rs plus a 4,590-line Cargo.lock) belongs to no workspace and was referenced only by its own dispatch-only workflow.registernow returnsunavailable/not_requesteddirectly, byte-identical to today's production responses (minus afailedissuance audit row nobody read). This removes the dormant n0-hosted fallback option deliberately: the registry / relay allow-hook path is the go-forward. Operational follow-up outside the repo: retire the minter Vercel project and delete the two env vars.3. Orphaned relay-issuance plumbing (226af47, 363 lines). With clusters 1-2 gone,
reserveRelayIssuance/completeRelayIssuance/failRelayIssuancehad no callers outside their tests, the twoIROH_RELAY_TOKEN_*constants had none at all, andIrohQuotaExceededErrorhas had no producer since #9269 removed the broker quotas (grep fornew IrohQuotaExceededErroris empty), making both 429 mappings unreachable. Theiroh_relay_token_issuancestable, its migrations, and retention cleanup stay: production still holds rows.4. Never-wired offline-pair server subgraph and unreferenced exports (2b5b6c4, 340 lines).
createOfflinePairSessionRecord/verifyAndConsumeOfflineSameAccountPairplus private helpers, types, and constants were reachable from no route, broker method, or repository call; the shipping Swift offline-pairing feature verifies attestations peer-to-peer and never calls a server session endpoint. AlsoserverPublishedIrohPathHints(zero references, not even tests),IROH_SIGNED_PATH_HINT_UPDATE_FOLLOWUP(definition-only), andbindingMatchesDiscoveryScopemoved from production into the trust-broker test that uses it as fixture logic.5. Unreferenced Swift struct (51198c1, 18 lines).
CmxIrohInboundStream's only occurrence in any Swift source is its own definition.Spared
Packages/Shared/CmuxIrohTransportotherwise untouched: every other candidate file has live references (the package ships).iroh_relay_token_issuancesschema, migrations, retention SQL, and the account-deletion fence coverage: production data still drains through them.IROH_ENDPOINT_ATTESTATION_SCOPE = "cmux.offline-pair.same-account": live in endpoint attestations, kept despite the name.Tests
cd web && bun run typecheck(tsgo) green after every commit.iroh-model-crypto,iroh-route-handler,iroh-trust-broker,relay-policy,relay-preferences-route,relay-token-route,relay-token,relay-workflows,client-config-env,connectivity-authority).iroh-db-behavior33 pass / 0 fail.swift test --package-path Packages/Shared/CmuxIrohTransport: 615 tests in 66 suites pass.CmxConnectivityPeerSessionTestswas skipped because it deadlocks on currentmainregardless of this change; the fix is onorigin/fix-peer-session-test-deadlock.Revert
Each cluster is one commit;
git revert <sha>restores it independently. Two later commits sit on top: defdffe (merge of origin/main, no manual edits) and 7bd2a24 (drops two stale env.ts/.env.example comments that referenced the deleted minter; revert independently). Revert order for a full rollback: 51198c1, 2b5b6c4, 226af47, 017a52e, 721d8bc (clusters 3-4 depend on 1-2 being gone, so partial reverts of 017a52e or 721d8bc also need 226af47 and 2b5b6c4 reverted first).Dictionary:
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
Breaking Changes
Documentation
Review-gate P1 refutation (429 quota mapping)
At the PR base (3f98f5d) the only construction of
IrohQuotaExceededErrorin the entire tree isweb/tests/iroh-route-handler.test.ts:368, mockingissueRelayToken, which this PR deletes. No production code constructs the error:repository.tscarries only the import, an error-union member, and a tag type-guard. No challenge or pair-grant deny site produces it; cmux#9269 removed every broker quota on 2026-07-31 (the stale README text is corrected in cmux#10731). The 429 arms inconnectivity/routeHandler.tsandiroh/routeHandler.tswere unreachable, so their removal changes no client-observable behavior.