Skip to content

fix(relay): offload bounded filesystem actions - #11568

Merged
lawrencecchen merged 7 commits into
mainfrom
feat-async-action-fs
Sep 2, 2026
Merged

lawrencecchen merged 7 commits into
mainfrom
feat-async-action-fs

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • run read, write, and directory-list path validation plus bounded file I/O in one Tokio blocking task
  • keep scoped file descriptors and security checks inside the blocking task
  • bound process-wide blocking file work to eight actions and retain permits until detached work ends
  • reject FIFOs and other non-regular files without a blocking open

Verification

  • regression commit fc634204df fails because synchronous file open prevents connection cancellation
  • fix commit 153c88d665 passes the same behavior test on an isolated Blacksmith Testbox
  • all 223 chatmux-relay tests pass on the Testbox
  • cargo fmt --all --check, git diff --check, and Package.resolved policy pass
  • exact-head hosted Linux, macOS, MSRV, and aarch64 artifact checks pass: https://github.com/manaflow-ai/cmux/actions/runs/33596950543
  • exact review against base 12f60191894b5f51121a2fe4e257a0008df83432 reports no findings and marks the patch correct with 0.82 confidence

Summary by CodeRabbit

  • Bug Fixes
    • File operations now safely refuse FIFOs and other special files instead of potentially blocking.
    • File reads, writes, searches, and directory listings remain responsive when many operations run concurrently.
    • Excess concurrent file operations now return a clear “busy” result instead of overloading the session.
    • Directory listings stop after a safe maximum and indicate when additional entries were omitted.
    • Improved cancellation handling for file operations that are waiting to open.

@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Canceled Canceled Sep 2, 2026 11:30pm UTC
cmux41 Canceled Canceled Sep 2, 2026 11:30pm UTC

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 4 seconds.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: 03b0bee4-17dc-42e6-b33f-b4fad37cc94f

📥 Commits

Reviewing files that changed from the base of the PR and between 3a82bf5 and 7eb60f8.

📒 Files selected for processing (1)
  • cmux-tui/crates/chatmux-relay/src/actions.rs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: dde83b2b-9a82-4113-8827-3fa116fde826

📥 Commits

Reviewing files that changed from the base of the PR and between 392f83d and 3a82bf5.

📒 Files selected for processing (2)
  • cmux-tui/crates/chatmux-relay/src/actions.rs
  • cmux-tui/crates/chatmux-relay/src/session.rs

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

File actions now run in bounded blocking tasks with shared session capacity. Reads and writes reject special files without blocking. Directory scans stop at a fixed limit and report omitted entries. Tests cover cancellation, FIFO refusal, capacity exhaustion, and listing truncation.

Changes

File-action safety and capacity

Layer / File(s) Summary
File access guards and bounded listings
cmux-tui/crates/chatmux-relay/src/actions.rs
Reads and writes use nonblocking opens and regular-file checks. Directory scans stop at MAX_LISTING_ENTRIES and report generic omission text.
Bounded file-operation execution
cmux-tui/crates/chatmux-relay/src/actions.rs
read, write, ls, and grep use shared semaphore capacity and blocking tasks. Scoped path resolution and error mapping use the shared operation path.
Session wiring and validation
cmux-tui/crates/chatmux-relay/src/session.rs, cmux-tui/crates/chatmux-relay/src/actions.rs
SessionRuntime initializes and passes shared file-action capacity. Tests validate cancellation, FIFO refusal, capacity exhaustion, and listing output.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: ⚪ Minimal · up to 3a82b

The change moves bounded filesystem work off the connection task while preserving path, trust, descriptor, and regular-file checks, and the supplied checks pass. No actionable merge-blocking risk remains beyond normal review.

Sequence Diagram(s)

sequenceDiagram
  participant ActionRequest
  participant perform_action
  participant file_slots
  participant spawn_blocking
  participant perform_bounded_file_operation
  ActionRequest->>perform_action: dispatch read, write, ls, or grep
  perform_action->>file_slots: acquire shared capacity
  perform_action->>spawn_blocking: run bounded file operation
  spawn_blocking->>perform_bounded_file_operation: resolve scoped path and execute
  perform_bounded_file_operation-->>spawn_blocking: return file result
  spawn_blocking-->>perform_action: return result or operation error
Loading
🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 24 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (14 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: bounded filesystem actions are offloaded in the relay.
Description check ✅ Passed The description explains what changed and why, and provides detailed verification results. It omits the template headings for Testing, Demo Video, Review Trigger, and Checklist, but the core summary a…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS: The pull request changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. The diff from the PR base contains no .swift changes, so it cannot introduce or …
Cmux Swift Blocking Runtime ✅ Passed PASS: The PR diff changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. It introduces no production Swift changes, so the Swift blocking-runtime check does not…
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The rule-scoped Swift files, Sources/TerminalController.swift and `ControlCommandExecutionPolicy.…
Cmux Expensive Synchronous Load ✅ Passed PASS — The pull request changes only Rust files: cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The complete range from the PR parent to HEAD contains no Swift files and no agent-h…
Cmux Cache Substitution Correctness ✅ Passed PASS: The relay PR diff changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. It introduces no production Swift, TypeScript, or JavaScript changes, so the cach…
Cmux No Hacky Sleeps ✅ Passed PASS: The PR's runtime implementation changes are in Rust (actions.rs and session.rs), which is outside this check's TypeScript, JavaScript, shell, and non-Swift build/runtime scope. The only adde…
Cmux Algorithmic Complexity ✅ Passed PASS: The pull-request change range is limited to cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. The custom check applies only to production Swift, TypeScript, JavaS…
Cmux Swift Concurrency ✅ Passed PASS: The PR range from 392f83d8c4 through HEAD changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The Swift-file diff is empty. Therefore, the PR introduces no cmux-own…
Cmux Swift @Concurrent ✅ Passed PASS: The PR-local range changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. It changes no Swift paths, async Swift functions, or Swift call sites. The Swift @concurrent ch…
Cmux Swift Package Boundaries ✅ Passed PASS — the pull-request change set covered by the summary changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The cumulative diff for the four relay commits contains no Swift…
Full details: Description check

Explanation

The description explains what changed and why, and provides detailed verification results. It omits the template headings for Testing, Demo Video, Review Trigger, and Checklist, but the core summary and testing information are complete.

Full details: Cmux Swift Actor Isolation

Explanation

PASS: The pull request changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. The diff from the PR base contains no .swift changes, so it cannot introduce or worsen the specified Swift actor-isolation issues.

Full details: Cmux Swift Blocking Runtime

Explanation

PASS: The PR diff changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. It introduces no production Swift changes, so the Swift blocking-runtime check does not apply. The Rust tokio::sync::Semaphore and spawn_blocking usage is outside this check's scope.

Full details: Cmux Browser Automation Off-Main

Explanation

PASS: The pull request changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The rule-scoped Swift files, Sources/TerminalController.swift and ControlCommandExecutionPolicy.swift, are unchanged. The patch adds no browser socket command, WebKit/AppKit access, worker routing, or related policy-test change.

Full details: Cmux Expensive Synchronous Load

Explanation

PASS — The pull request changes only Rust files: cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The complete range from the PR parent to HEAD contains no Swift files and no agent-history load changes. The Swift expensive synchronous load check is therefore not applicable.

Full details: Cmux Cache Substitution Correctness

Explanation

PASS: The relay PR diff changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. It introduces no production Swift, TypeScript, or JavaScript changes, so the cache-substitution failure condition does not apply.

Full details: Cmux No Hacky Sleeps

Explanation

PASS: The PR's runtime implementation changes are in Rust (actions.rs and session.rs), which is outside this check's TypeScript, JavaScript, shell, and non-Swift build/runtime scope. The only added timer/polling code found in covered files is in web/tests/vm-cmux-tui.test.ts, where a test waits for the fallback-watch-ready marker with a bounded deadline. The rule explicitly allows deterministic test-only scaffolding. No production hacky sleep was introduced or worsened.

Full details: Cmux Algorithmic Complexity

Explanation

PASS: The pull-request change range is limited to cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs, both Rust files. The custom check applies only to production Swift, TypeScript, JavaScript, shell, and runtime code. Therefore, it is not applicable.

Full details: Cmux Swift Concurrency

Explanation

PASS: The PR range from 392f83d8c4 through HEAD changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The Swift-file diff is empty. Therefore, the PR introduces no cmux-owned Swift concurrency pattern covered by the check.

Full details: Cmux Swift `@Concurrent`

Explanation

PASS: The PR-local range changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. It changes no Swift paths, async Swift functions, or Swift call sites. The Swift @concurrent check is therefore not applicable.

Full details: Cmux Swift Package Boundaries

Explanation

PASS — the pull-request change set covered by the summary changes only cmux-tui/crates/chatmux-relay/src/actions.rs and session.rs. The cumulative diff for the four relay commits contains no Swift, Xcode project, or Package.swift changes. Therefore, the Swift package-boundary rule is not applicable.

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-async-action-fs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@lawrencecchen
lawrencecchen force-pushed the feat-async-action-fs branch 3 times, most recently from c361dad to 153c88d Compare September 2, 2026 05:56
@lawrencecchen
lawrencecchen enabled auto-merge (squash) September 2, 2026 06:19
@lawrencecchen
lawrencecchen force-pushed the feat-async-action-fs branch 6 times, most recently from 4e86502 to 4d453a3 Compare September 2, 2026 08:45
@lawrencecchen
lawrencecchen merged commit d86d5f3 into main Sep 2, 2026
11 of 13 checks passed
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 2, 2026
c8ec44d Cloud VPC follow-ups: copyable machine IPs, working tree menu, no HTTP modal on private addresses (manaflow-ai#11626)
cbda3b0 ci: land base-controlled CLA policy guard (manaflow-ai#11606)
40d1dc6 CLI: return notification ids and support scoped clear (manaflow-ai#10336)
d86d5f3 fix(relay): offload bounded filesystem actions (manaflow-ai#11568)
9778ac7 Plus menu: one New Cloud VM item that opens the New Machine sheet (manaflow-ai#11603)
392f83d fix(web): retire provider rows as destroyed in the Blaxel and E2B/Daytona migrations (manaflow-ai#11623)
c1ce87c Cloud: create machines in the background; Create returns control immediately (manaflow-ai#11397) (manaflow-ai#11421)
lawrencecchen added a commit that referenced this pull request Sep 2, 2026
)

* fix(relay): own the grep pattern before spawning the runner task

The grep arm moved its process run into tokio::spawn in #11568, but the
task still captured `pattern`, a &str borrowed from the request frame, so
the 'static future held a borrow of `frame` and `empty_args`. chatmux-relay
has not compiled on main since that merge (E0597 and E0521 at the spawn).
Clone the pattern into an owned String before the spawn and move it into
the argv. No behavior change.

Claude-Session: https://claude.ai/code/session_01AvkeWizggvvUAngHyB7JUQ

* style(relay): wrap the owned grep pattern binding for rustfmt

Claude-Session: https://claude.ai/code/session_01AvkeWizggvvUAngHyB7JUQ
@vercel
vercel Bot temporarily deployed to Preview – cmux41 September 2, 2026 23:29 Inactive
@vercel
vercel Bot temporarily deployed to Preview – cmux166 September 2, 2026 23:30 Inactive

This branch was previously deployed

2 inactive deployments
Preview – cmux166 — 7eb60f85 Deployed Sep 2, 2026 by vercel[bot]
Preview – cmux41 — 7eb60f85 Deployed Sep 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant