Repository navigation
Fix notification hook descriptor inheritance - #11649
teamleaderleo merged 4 commits into
Conversation
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
@chapati23 is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
|
All contributors have signed the CLA ✍️ ✅ |
|
To use Codex here, create an environment for this repo. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughNotification hooks now use ChangesNotification hook isolation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Hooks retain their standard-stream input and output while unrelated app descriptors are excluded. No concrete merge-blocking issue is established, so the change is ready for normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change reduces notification hooks’ access to unrelated app resources while preserving their intended input and output streams. No new security concern was identified in the reviewed change, though validation remains limited. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
I have read the CLA Document v2.2 and I hereby sign the CLA |
|
@codex review |
@chapati23 cubic can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 282,776 of the 280,000 allowed lines of code this month. Reviews resume on 1 October 2026 (in 28 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
59aa759 to
6049a5c
Compare
|
Thanks @chapati23! This is picked up in #14789 with your two commits and the conflict with main's signal-mask reset resolved. Your new isolation test passes there; it'll close out once that merges. |
Resolve the spawnHook conflict with main's signal-mask reset by keeping both: POSIX_SPAWN_SETSIGMASK with the empty mask, plus POSIX_SPAWN_CLOEXEC_DEFAULT so unrelated app descriptors stay out of hooks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Merged, thanks @chapati23! Nice catch on the leaked descriptors, and the /dev/fd probe test is a neat way to pin it. |
|
Merge receipt for |
82c26b3 ci: take the gui token in the app-host shard's restore, not at job start (manaflow-ai#15012) 3761671 iOS: fix stale team nightly floor expectation in What's New copy test (manaflow-ai#14917) 5e19a98 docs: focus custom sidebar tabs by surfaceId in the actions example (manaflow-ai#15002) 294ee6e sidebar: Strip inline Markdown from notification previews (manaflow-ai#12030) ceb3030 Keep detached workspace process titles updateable (manaflow-ai#4947) 8be7364 test: kill hosted test shells before freeing their terminals (manaflow-ai#14957) da291df cmux-tui: do not query the host terminal when the reply cannot be read (manaflow-ai#12419) 98767c8 ci: keep earlier reviewed CLA policies valid for branches behind main (manaflow-ai#15008) 7167b77 feat(custom-sidebars): fixedSize and reactive frame specs for JS sidebars (manaflow-ai#14845) 716bbb5 Fix notification hook descriptor inheritance (manaflow-ai#11649) 03b191d cmux-tui: pass the zig target on a native windows-gnu host (manaflow-ai#12416) c9a6a0e docs: load the deep review protocol only when needed (manaflow-ai#15007) e5af879 Match pane indicator strokes and the file path header to shared chrome metrics (manaflow-ai#14982) 0def9e1 Show one fixed subtitle for each Settings row and fix localized labels (manaflow-ai#14883) 1921636 ci: route picker-less macOS lanes to the owned minis for trusted events (manaflow-ai#14794) # Conflicts: # .github/workflows/app-host-test-rerun.yml # .github/workflows/auth-refresh-tests.yml # .github/workflows/ci-health-report.yml # .github/workflows/ci-macos.yml # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/ci-repo-variables.yml # .github/workflows/cloud-command-deadlines.yml # .github/workflows/cloud-machine-tests.yml # .github/workflows/cloud-task-local-tests.yml # .github/workflows/cmux-tui.yml # .github/workflows/iroh-v2.yml # .github/workflows/relay-tls.yml # .github/workflows/reload-build.yml # .github/workflows/remote-daemon.yml # .github/workflows/resolve-dispatch-ref.yml # .github/workflows/terminal-hang-diagnostics.yml
tl;dr
Notification hooks could inherit unrelated open pipes and wait until timeout. That could cause hook-failure alerts and false approval banners. This change closes those pipes when a hook starts. The regression test checks that hooks still receive their intended input.
Summary
Testing
Head
6049a5cb4b(rebased onbb03a252a0). Gates: tagged Debug build with Xcode 27 passed; focusedcmux-unitpassed (16 policy tests and 1 descriptor-isolation test);git diff --checkpassed.Manual: the signed
notification-fd-mainapp launched and its isolated socket listed a workspace. The bundled Ghostty, computer-use, and command-palette helpers are present.Local build setup: Rust 1.88, Zig 0.16, and Apple's Metal Toolchain. macOS 27 required a Rust build-dependency strip override and a temporary verifier command that selected Apple's
dwarfdump; the temporary source edit was removed.Not run: the full test suite (focused first-pass scope).
Not proven: CI on the repository-pinned Xcode 26 and daily notification behavior on the new tag.
Demo Video
Review Trigger (Copy/Paste as PR comment)
Checklist
Summary by CodeRabbit
Changelog
Fixed: Notification hooks no longer inherit cmux's open file descriptors, so a hook can't hang on a pipe it never used and raise a false failure or approval alert