Repository navigation
cloud: let Cloud VMs notify the owning Mac over the private network - #11641
lawrencecchen wants to merge 4 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Review limit reachedNext included review available in 1 minute. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (33)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
The Mac listens on its WireGuard tunnel addresses only (VMHostListener), gated by a per-machine token, the VPC CIDRs, and an allow-list of notification and status verbs scoped to workspaces bound to the machine (VMHostAccessPolicy, TerminalController+VMHostClient). Off by default; Settings > Cloud and 'cmux vpn notifications on' turn it on. While listening, each linked machine receives /etc/cmux/host.env (endpoint, token, bound workspace) and a journal hook on its cmux-tui daemon that runs 'cmux-tui host-forward' per agent.* event. The guest command turns the event into workspace.status.set and notification.create on the Mac.
…n enable A Mac enrolled before network.json existed never listened (network_metadata_missing) until the user re-ran 'cmux vpn up' with sudo. The coordinator now re-asks the control plane once per tunnel-up episode through the idempotent enrollment call and writes only network.json, config untouched. Turning the feature on also refreshes the machine inventory so a stale 'not signed in' clears without another surface refreshing it. Tests import CmuxControlSocket for ControlRequest.
Until the first inventory fetch succeeds the coordinator only guesses at sign-in; a backend that cannot be reached now surfaces as cloud_unreachable with the client's error text, in the CLI and in vm.host_status.
5b4e726 to
38c426c
Compare
…loud Turning the feature on schedules a fresh inventory fetch, which cancels the one in flight; the cancellation surfaced as 'cancelled' and flipped the status to cloud_unreachable. Cancelled fetches now stay silent, and until the first fetch lands the status says it is still checking instead of guessing 'not signed in'.
|
Superseded. The design inverted: the Mac dials the VM over the existing state feed, and the VM's cmux-tui daemon owns notifications with per-client read state. Part 1 is #12108 (daemon side); the macOS consumer follows as part 2 and will be linked here. |
|
Part 2 (macOS consumer): #12112 |
Machines have no public ports and no path back to the Mac, so agent hooks inside a Cloud VM never reached the Mac's notifications. This adds the reverse path over the WireGuard private network the Mac already joins (
cmux vpn up, #11602), with no new Freestyle feature and no public listener.Mac side. Off by default; Settings > Cloud "Notifications from machines" or
cmux vpn notifications on. While on, signed in, tunnel up, and at least one machine owned, the app binds TCP on its tunnel addresses only (never a wildcard), so the port disappears with the utun. Each request must come from the network CIDRs, carry the per-machine token the Mac minted, use one of the notification/status verbs inVMHostAccessPolicy.allowedMethods, and name only workspaces bound to that machine. Same wire protocol as the local control socket, different gate (TerminalController+VMHostClient.swift).Machine side. On link connect the Mac writes
/etc/cmux/host.env(endpoint, token, bound workspace) and puts a journal hook on the daemon over the link. The hook runscmux-tui host-forwardperagent.*event, which maps the event toworkspace.status.setandnotification.createon the Mac. Exit 1 = Mac unreachable, dispatcher retries. Turning the feature off rewrites the env file with an empty endpoint.Tests:
VMHostAccessPolicyTests,VMHostListenerCoordinatorTests(Swift Testing),host_forwardunit tests in cmux-tui (9 pass on a Blacksmith testbox, clippy clean for touched files).Not covered: OSC 9 notifications from guest processes, surface-level verbs, and an offline Mac. See
docs/cloud-cmux-tui-daemon.md.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Lets Cloud VMs notify the owning Mac over the private WireGuard network, so VM agent notifications and status reach the Mac. Previously machines had no public ports and no path back; the Mac now listens only on its tunnel addresses, and the feature is off by default (Settings > Cloud or
cmux vpn notifications on).network.json.cloud_unreachablewith the error text in the CLI andvm.host_status, instead of a misleading "not signed in"; cancelled fetches stay silent, and until the first fetch lands the status reads "still checking"./etc/cmux/host.envand a journal hook that runscmux-tui host-forward, mappingagent.*events toworkspace.status.setandnotification.create; turning the feature off rewrites the env file with an empty endpoint.Written for commit 0ba128c. Summary will update on new commits.