Cloud sidebar: restore Desktop/VNC and Ports surfaces - #12051
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
All contributors have signed the CLA ✍️ ✅ |
|
Warning Review limit reachedNext included review available in 4 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (16)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5f973b7 to
ce6c0ac
Compare
|
Smoke verification after rebase: opened a right split in task workspace |
c3216e9 Cloud sidebar: restore Desktop/VNC and Ports surfaces (manaflow-ai#12051)
…sableCloud main landed its own DisableCloud in #12051. Keep one implementation and close the gaps the issue lists for the primary control: - one teardown path shared with sign-out (AppDelegate.endCloudVMAccess) after the surface registry drops providers and links; lifting the policy restarts Cloud discovery without a relaunch - VMClient refuses every Cloud VM API call under the policy before auth, telemetry, or the network (access revocation stays exempt); the tunnel coordinator refuses enroll/start/reconnect while down/revoke remain - session restore drops Cloud workspaces of both transports - socket verbs: one cloud_disabled code; vm.tunnel_status/down/revoke stay reachable for cleanup - Settings: the Beta "Cloud Machines" toggle shows "Managed by your organization" and locks; the Cloud pane stays hidden under the policy - docs (repo + web, en/ja): merged key row, tunnel cleanup verbs, the entitlement limitation - Localizable.xcstrings: re-open the strings container so the ~140 entries appended after it (including cloud.managed.disabled) are part of the catalog again; add a structure guard test to CI - tests: tunnel coordinator under the policy, observer transitions, service-boundary refusal, restore normalization Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sscqbg3w632eCEp43XwxRV
…ee and catalog Four tests in the app-host shard were stale against main: - a sleeping or broken machine now keeps a Ports group whose status row explains how to discover ports (#12051), and an unregistered machine shows a Connecting placeholder instead of no children; - display rows placed inside a remote workspace carry their tab id like every other placement; - the catalog drops writes for a cloud machine with no registered provider, so the two workspace-group tests register the file's GroupFakeProvider before replacing resources. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa
* test: cover creation initial command plumbing * test: isolate creation command regression * feat: add initial commands to terminal creation * test: require creation request dispatch * test(web): preserve hosted config overrides * test(cli): expect OMP restore path * test(session): expect codex wrapper shim * docs(cli): sync restore help contract * test(cli): preserve interactive shell for creation command * fix(cli): inject creation commands into interactive shells * fix(cli): preserve terminal creation command text * test(cli): reject invalid creation command input * fix(cli): validate terminal creation input boundaries * fix(cli): resolve creation validation in app context * test(cli): cover review-found creation boundaries * test(cli): import welcome setting contract * test(cli): wait for terminal readiness before welcome assertion * test(cli): exercise focused workspace welcome path * fix(cli): close terminal creation review gaps * test: cover app-host temp path aliases * ci: accept validated macOS temp aliases * Fix Xcode 26 warning regressions * test: keep install command fixture inert * test: repair app-host CLI fixtures * fix: remove duplicate dock initial input plumbing * test: bound workspace readiness regression wait * fix: order dock creation arguments * fix: order dock input after startup options * fix: preserve null terminal creation types * fix: keep readiness wait actor-safe * test: isolate creation command socket environment * test: keep cloud splits local for initial input * fix: keep initial input out of cloud split routing * ci: route browser skill contract through linux runner * test: isolate cloud routing fixture from local surfaces * refactor: keep terminal creation checks within file budgets * fix: wire terminal creation helpers into app target * fix: repair current main compile errors * docs: document --command on terminal creation commands Cover the new --command flag on new-split, new-pane, and new-surface (and the existing one on new-workspace) in the cmux and cmux-workspace skills, the CLI contract (table rows, an Initial terminal command section, and --help probes), and the web API docs in English and Japanese. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: silence unmutated payload warning in browser key replay CI's Swift warning budget fails on main because the delivered-key payload in TerminalController.swift is declared var but never mutated. Use let so the tests-build-and-lag job can pass on this branch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix(web): keep devbox reachability script typechecking without bun-types `import.meta.main` (added on main in #12132) fails `tsgo --noEmit` because the web tsconfig does not include bun-types, which turns the CI cheap layer red and skips every macOS job. Cast the meta object so Bun's runtime flag still gates main() while the typecheck passes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: repair package test import and Swift warnings inherited from main - FakeTerminalEngine.swift (from #10564) uses UUID without importing Foundation, which breaks `swift test` for CmuxTerminal in the swift-package-tests job. - Parenthesize the two compactMap trailing closures in the pane memory guardrail guard and hop onto the main actor before reconcilePresentation in the session index table observer; both were new warnings over the cmux-owned Swift warning budget in tests-build-and-lag. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: clear two more Swift warnings inherited from main Drop the unreachable default branch in the cmux-tui snapshot parser's exhaustive resource-kind switch and stop binding the unused rowID shadow in SurfaceCatalogModel, so the cmux-owned warning budget passes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: bring MachinesPanelModelTests in line with the current cloud tree and catalog Four tests in the app-host shard were stale against main: - a sleeping or broken machine now keeps a Ports group whose status row explains how to discover ports (#12051), and an unregistered machine shows a Connecting placeholder instead of no children; - display rows placed inside a remote workspace carry their tab id like every other placement; - the catalog drops writes for a cloud machine with no registered provider, so the two workspace-group tests register the file's GroupFakeProvider before replacing resources. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * chore: normalize project.pbxproj after main merges The auto-merged project file drifted from scripts/normalize-pbxproj.py output, which fails the workflow-guard pbxproj check and gates every macOS CI job behind it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: assert pane re-homing through the journal event for started turns #11976 moved the pane-scoped notification clear for UserPromptSubmit and PreToolUse out of the Claude hook and into the app's journal reconciler (clearInvalidatedNotifications keys off the event's workspace and surface). The two moved-pane tests still looked for the hook's old clear_notifications send and turned the focused notification-routing step red on main. They now assert the agent_journal_append event carries the re-homed workspace and surface (and, for PreToolUse, the running phase), and keep the guards against whole-workspace or stale-workspace clears. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: bound WebKit page-load waits in the design-mode screenshot suite On CI app hosts the WebContent process sometimes disappears mid-batch ("Could not signal service com.apple.WebKit.WebContent"), after which a loadHTMLString navigation never reports didFinish. The screenshot evaluator tests awaited that signal without a bound, so one lost process wedged the whole app-host batch until the 30-minute timeout (shard 4 on runs 34232451577 and 34235694241 both stalled in smoothScrollingPageCapturesRequestedRegionAndRestoresOffset). Race every real page-load wait against a 30-second budget and fail the test fast instead, so the rest of the batch still runs and reports. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: tolerate an already-closed socket when bounding PTY bridge reads testPTYBridgeDefersHalfCloseUntilAttachCompletes half-closes its bridge socket, and the bridge answers and closes so quickly that the follow-up SO_RCVTIMEO setsockopt sees a torn-down connection and fails with EINVAL. That thrown error is counted as an unexpected failure and fails the whole app-host batch (it reproduces on main's own shard 6 run 34221588627). The timeout only bounds the read that follows, which returns EOF at once on such a socket, so skip the option instead of throwing. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * ci: sample the wedged app host before killing a timed-out unit-test batch App-host unit-test batches on main and on PRs intermittently sit at the 30-minute batch timeout with only "started" lines for whichever tests were in flight, which says nothing about what blocked the main actor. Sample the app host process before terminating xcodebuild and print the leading call graph in a log group, so the next hang names its stuck frames. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: queue the first Codex prompt before asserting the second is rejected testCodexInputQueueBeforeThreadIsBounded spawned the first submit in a Task and immediately submitted a second prompt on the same main actor. The second call ran first, took the single pre-thread queue slot, and then awaited a thread the test only starts afterwards, so the test hung until the 30-minute app-host batch timeout (shard 2 on runs 34235694241 and 34245949340, and main's own shard 2). Yield to the spawned task before the second submit so the first prompt holds the slot and the second is rejected as intended. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: gate the concurrent file-preview save on isSaving instead of a FIFO testSaveTextContentIgnoresConcurrentSaveRequest replaced the previewed file with a FIFO so the first write would stay in flight. Since the preview panel re-opens its watched path for change monitoring, a FIFO with no writer can block the app host's main thread, and this test was the unfinished XCTest in two hung app-host shards (shard 1 on run 34232451577, shard 5 on run 34245949340). saveTextContent() sets isSaving synchronously and completes on a later main-actor hop, so the second request is always observed while the first is still saving without any FIFO. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * ci: match the app host for hang sampling even when launched with arguments Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: wait for the Codex thread/start request before answering it; per-test CI allowance Every CodexAppServerSessionTests case fed the thread/start response after a single Task.yield() following the initialize response. The session sends `initialized` and then `thread/start` from a spawned main-actor task, so when that task had not reached the request yet the response was dropped as unknown, every later submit waited for a thread forever, and the reentrant turn test spun on Task.yield() until the batch timeout (shard 2 on runs 34245949340 and 34256455336; main shows the same). - CodexAppServerSession gains two read-only test seams (isAwaitingThreadStart, hasThread). - The tests wait for the request before feeding its response, and the pending-write spin loop is bounded. - CI passes XCTest's per-test execution allowance (300s by default) to the app-host batches so a single parked test fails with a spindump instead of taking the batch to its 30-minute timeout, and the hang sample prints more threads. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: replace mobile lane timing wait with completion signal --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
…ow, cloud-only default Stale tests. Three product changes landed without these expectations ever executing (the classifier tolerated them; PR #12090's own app-test runs failed on unrelated compile errors before its cloud tests ran): - Since c8098d7 (2026-09-04) and #12090, a resource row under a workspace is a placement: its id carries the daemon tab (`.../resource:.../tab:<id>`), so expansion, selection, drag, and rename never collapse onto one row. - Since #12051 a connected machine always shows its Ports group with a status row, even before any port is discovered. - Since #10918 (2026-08-26) `CloudTreeNodeBuilder.includesLocalMachine` is off: the Machines panel is the cloud fleet and this Mac stays one flip away. Updated to the shipped shape: - CloudTreeOneMachineManyWorkspacesTests (singleWorkspaceKeepsItsGroupRow, workspacesPortsDisplaysThenTerminals, emptyMachineKeepsItsGroups, aTerminalOutOfTheLayoutLeavesTheWorkspaceFolder) - CloudPortOpenRegressionTests (discoveredPortIsGroupedAndRetainedByIdentity, localhost browser view folded into the canonical port) - CloudTreeScopeAndSignatureTests.testTreeShowsThisMacByDefaultAndCloudOnlyStaysOneFlipAway, renamed testTreeIsCloudOnlyByDefaultAndThisMacStaysOneFlipAway; the mixed tree is now requested explicitly and the default is asserted cloud-only. Evidence: run 34342638735 jobs 102640655659/102640655833, fleet triage on cmux-austin-mini-1 (2026-09-09) with the same ids. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018m2GS6xeD1P3ZLiYwDtQaM
* test: cover creation initial command plumbing * test: isolate creation command regression * feat: add initial commands to terminal creation * test: require creation request dispatch * test(web): preserve hosted config overrides * test(cli): expect OMP restore path * test(session): expect codex wrapper shim * docs(cli): sync restore help contract * test(cli): preserve interactive shell for creation command * fix(cli): inject creation commands into interactive shells * fix(cli): preserve terminal creation command text * test(cli): reject invalid creation command input * fix(cli): validate terminal creation input boundaries * fix(cli): resolve creation validation in app context * test(cli): cover review-found creation boundaries * test(cli): import welcome setting contract * test(cli): wait for terminal readiness before welcome assertion * test(cli): exercise focused workspace welcome path * fix(cli): close terminal creation review gaps * test: cover app-host temp path aliases * ci: accept validated macOS temp aliases * Fix Xcode 26 warning regressions * test: keep install command fixture inert * test: repair app-host CLI fixtures * fix: remove duplicate dock initial input plumbing * test: bound workspace readiness regression wait * fix: order dock creation arguments * fix: order dock input after startup options * fix: preserve null terminal creation types * fix: keep readiness wait actor-safe * test: isolate creation command socket environment * test: keep cloud splits local for initial input * fix: keep initial input out of cloud split routing * ci: route browser skill contract through linux runner * test: isolate cloud routing fixture from local surfaces * refactor: keep terminal creation checks within file budgets * fix: wire terminal creation helpers into app target * fix: repair current main compile errors * docs: document --command on terminal creation commands Cover the new --command flag on new-split, new-pane, and new-surface (and the existing one on new-workspace) in the cmux and cmux-workspace skills, the CLI contract (table rows, an Initial terminal command section, and --help probes), and the web API docs in English and Japanese. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: silence unmutated payload warning in browser key replay CI's Swift warning budget fails on main because the delivered-key payload in TerminalController.swift is declared var but never mutated. Use let so the tests-build-and-lag job can pass on this branch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix(web): keep devbox reachability script typechecking without bun-types `import.meta.main` (added on main in manaflow-ai#12132) fails `tsgo --noEmit` because the web tsconfig does not include bun-types, which turns the CI cheap layer red and skips every macOS job. Cast the meta object so Bun's runtime flag still gates main() while the typecheck passes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: repair package test import and Swift warnings inherited from main - FakeTerminalEngine.swift (from manaflow-ai#10564) uses UUID without importing Foundation, which breaks `swift test` for CmuxTerminal in the swift-package-tests job. - Parenthesize the two compactMap trailing closures in the pane memory guardrail guard and hop onto the main actor before reconcilePresentation in the session index table observer; both were new warnings over the cmux-owned Swift warning budget in tests-build-and-lag. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * fix: clear two more Swift warnings inherited from main Drop the unreachable default branch in the cmux-tui snapshot parser's exhaustive resource-kind switch and stop binding the unused rowID shadow in SurfaceCatalogModel, so the cmux-owned warning budget passes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: bring MachinesPanelModelTests in line with the current cloud tree and catalog Four tests in the app-host shard were stale against main: - a sleeping or broken machine now keeps a Ports group whose status row explains how to discover ports (manaflow-ai#12051), and an unregistered machine shows a Connecting placeholder instead of no children; - display rows placed inside a remote workspace carry their tab id like every other placement; - the catalog drops writes for a cloud machine with no registered provider, so the two workspace-group tests register the file's GroupFakeProvider before replacing resources. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * chore: normalize project.pbxproj after main merges The auto-merged project file drifted from scripts/normalize-pbxproj.py output, which fails the workflow-guard pbxproj check and gates every macOS CI job behind it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: assert pane re-homing through the journal event for started turns manaflow-ai#11976 moved the pane-scoped notification clear for UserPromptSubmit and PreToolUse out of the Claude hook and into the app's journal reconciler (clearInvalidatedNotifications keys off the event's workspace and surface). The two moved-pane tests still looked for the hook's old clear_notifications send and turned the focused notification-routing step red on main. They now assert the agent_journal_append event carries the re-homed workspace and surface (and, for PreToolUse, the running phase), and keep the guards against whole-workspace or stale-workspace clears. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: bound WebKit page-load waits in the design-mode screenshot suite On CI app hosts the WebContent process sometimes disappears mid-batch ("Could not signal service com.apple.WebKit.WebContent"), after which a loadHTMLString navigation never reports didFinish. The screenshot evaluator tests awaited that signal without a bound, so one lost process wedged the whole app-host batch until the 30-minute timeout (shard 4 on runs 34232451577 and 34235694241 both stalled in smoothScrollingPageCapturesRequestedRegionAndRestoresOffset). Race every real page-load wait against a 30-second budget and fail the test fast instead, so the rest of the batch still runs and reports. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: tolerate an already-closed socket when bounding PTY bridge reads testPTYBridgeDefersHalfCloseUntilAttachCompletes half-closes its bridge socket, and the bridge answers and closes so quickly that the follow-up SO_RCVTIMEO setsockopt sees a torn-down connection and fails with EINVAL. That thrown error is counted as an unexpected failure and fails the whole app-host batch (it reproduces on main's own shard 6 run 34221588627). The timeout only bounds the read that follows, which returns EOF at once on such a socket, so skip the option instead of throwing. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * ci: sample the wedged app host before killing a timed-out unit-test batch App-host unit-test batches on main and on PRs intermittently sit at the 30-minute batch timeout with only "started" lines for whichever tests were in flight, which says nothing about what blocked the main actor. Sample the app host process before terminating xcodebuild and print the leading call graph in a log group, so the next hang names its stuck frames. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: queue the first Codex prompt before asserting the second is rejected testCodexInputQueueBeforeThreadIsBounded spawned the first submit in a Task and immediately submitted a second prompt on the same main actor. The second call ran first, took the single pre-thread queue slot, and then awaited a thread the test only starts afterwards, so the test hung until the 30-minute app-host batch timeout (shard 2 on runs 34235694241 and 34245949340, and main's own shard 2). Yield to the spawned task before the second submit so the first prompt holds the slot and the second is rejected as intended. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: gate the concurrent file-preview save on isSaving instead of a FIFO testSaveTextContentIgnoresConcurrentSaveRequest replaced the previewed file with a FIFO so the first write would stay in flight. Since the preview panel re-opens its watched path for change monitoring, a FIFO with no writer can block the app host's main thread, and this test was the unfinished XCTest in two hung app-host shards (shard 1 on run 34232451577, shard 5 on run 34245949340). saveTextContent() sets isSaving synchronously and completes on a later main-actor hop, so the second request is always observed while the first is still saving without any FIFO. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * ci: match the app host for hang sampling even when launched with arguments Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: wait for the Codex thread/start request before answering it; per-test CI allowance Every CodexAppServerSessionTests case fed the thread/start response after a single Task.yield() following the initialize response. The session sends `initialized` and then `thread/start` from a spawned main-actor task, so when that task had not reached the request yet the response was dropped as unknown, every later submit waited for a thread forever, and the reentrant turn test spun on Task.yield() until the batch timeout (shard 2 on runs 34245949340 and 34256455336; main shows the same). - CodexAppServerSession gains two read-only test seams (isAwaitingThreadStart, hasThread). - The tests wait for the request before feeding its response, and the pending-write spin loop is bounded. - CI passes XCTest's per-test execution allowance (300s by default) to the app-host batches so a single parked test fails with a spindump instead of taking the batch to its 30-minute timeout, and the hang sample prints more threads. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXS7towgxy33eJ4ZTMeQHa * test: replace mobile lane timing wait with completion signal --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Summary
Cloud machines now keep their Desktop/VNC and Ports surfaces visible and usable in the right sidebar across provider reconnects and refresh races.
DisableCloudpolicy across feature visibility, discovery, socket/CLI operations, provider teardown, and managed workspace cleanup.The implementation favors one shared provider/catalog path over sidebar-only network calls so transport, authentication, private-network gating, and CLI behavior cannot drift. The explicit refresh may wait for authoritative provider discovery, which avoids showing a false empty tree.
Validation
cmux vm exec vm-239f448bfd474f968de19350c4d59eee echo freestyle-terminal-split-oksucceeded in a newly opened split in workspaceworkspace:143.python3 scripts/check-package-resolved-policy.pypython3 scripts/check-workspace-package-groups.py --checkgit diff --checkswiftc -parseon changed Swift files.Full Xcode app/test builds were intentionally not run per the task instruction; the existing authenticated cmux instance and Freestyle VM CLI path were used for the smoke test.
Closes #12044
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Restores Cloud sidebar Desktop/VNC and Ports surfaces so they remain visible and usable across provider reconnects and refresh races.
DisableCloudMDM policy: when enforced, Cloud Machines are hidden, socket/CLI commands fail, and open Cloud workspaces and providers are torn down.Written for commit ce6c0ac. Summary will update on new commits.