Skip to content

Promote devbox images baked from main - #12127

Closed
lawrencecchen wants to merge 1 commit into
mainfrom
feat-devbox-bake-measure
Closed

lawrencecchen wants to merge 1 commit into
mainfrom
feat-devbox-bake-measure

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Rebakes both ladders so the image source that has been sitting on main finally reaches machines: the Option+Backspace word-delete fix (#12099) and the Dockerfile change that preceded it. The previous defaults were baked from 39bfc41fad, a commit that exists only on feat-vm-guest-trust-dead-code and never landed on main.

ladder baked from master snapshot
base 9cbdb7ca84 sh-4b2e52f8a9584e2c9ca878c6e387e734
desktop 5a16fbb6dc sh-b674df20b1534084bccec193e3e4ce18

The two sit on different commits because main moved during the run and the stale-checkout guard refused the second bake until the tree was updated. That commit touched no image inputs, so both ladders are content-current; kinds are promoted separately by design.

Every entry is verified: promotion boots a machine from the master snapshot and checks it, and the size derive boots and checks each derived snapshot before recording its id.

Agent pins are unchanged across this rebake (claude-code 2.1.252, codex 0.151.0, opencode 1.18.25, pi 0.84.4, agent-browser 0.35.2), so it carries no agent upgrade to review. That is the field worth reading on any future promotion, since a bake resolves those at build time.

Measured while producing this, on the base ladder: 784s end to end, of which bake 199s, verify 131s, and six serial size derives 453s. The config file drops that made this promotion necessary are under three seconds of that.

One known gap: the derive could not move the human-facing slugs (cmux-devbox-lg and friends still point at the old snapshots) because that needs --replace-slug. Production boots the immutable ids in this manifest, so machines are unaffected, but the convenience pointers are now stale.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Rebakes the base and desktop devbox images from main so the Option+Backspace word-delete fix and preceding Dockerfile change reach machines; the old defaults were baked from a commit that never landed on main.

Migration

  • The human-facing slugs (cmux-devbox-lg and friends) still point at the old snapshots and need a --replace-slug run; production machines are unaffected because they boot the immutable image ids.
  • Agent pins are unchanged across this rebake, so there is no agent upgrade to review.

Written for commit e02060a. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Updates
    • Updated the default development environment images to the latest base and desktop image versions.
    • Previous development environment images are no longer selected by default.

Both ladders rebaked so the shell config that has been sitting on main
reaches machines: Option+Backspace word delete (#12099) and the Dockerfile
change that preceded it. The old defaults were baked from 39bfc41, which
lives only on feat-vm-guest-trust-dead-code and never landed on main.

base    ladder from 9cbdb7c, master sh-4b2e52f8a9584e2c9ca878c6e387e734
desktop ladder from 5a16fbb, master sh-b674df20b1534084bccec193e3e4ce18

Each entry is verified: promote boots a machine from the snapshot, and the
size derive boots and checks every derived one. Agent pins are unchanged
across the rebake (claude 2.1.252, codex 0.151.0, opencode 1.18.25,
pi 0.84.4, agent-browser 0.35.2), so this carries no agent upgrade.
@vercel

vercel Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Ready Ready Preview Sep 8, 2026 12:57pm UTC
cmux41 Ready Ready Preview Sep 8, 2026 12:57pm UTC

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9d6f7a45-7c68-48eb-8ac1-feac2e17a852

📥 Commits

Reviewing files that changed from the base of the PR and between 5a16fbb and e02060a.

📒 Files selected for processing (1)
  • web/services/vms/images/manifest.json

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The image manifest removes default status from all trust4 devbox images and adds twelve timestamped base and desktop images as the new defaults. The smallest new base image is also marked as the local development default.

Changes

Devbox Image Defaults

Layer / File(s) Summary
Rotate default devbox images
web/services/vms/images/manifest.json
Trust4 base and desktop images no longer use defaultForKind. The new timestamped base and desktop images use defaultForKind: true. The new base-sm image also uses defaultForLocalDev: true.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to e0206

New Devbox base and desktop images become the defaults while preserving all size options and the local-development base default. No concrete current-head merge-blocking risk remains.

Suggested reviewers: austinywang, ben2w, theswerd

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: promoting devbox images baked from the main branch.
Description check ✅ Passed The description provides a detailed summary, explains why the images were rebaked, records the source commits and snapshots, documents verification, and identifies the stale convenience-slug limitatio…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS. The pull request changes only web/services/vms/images/manifest.json; the commit has no changed .swift files. The diff only updates image defaults and adds image metadata. Therefore, it intro…
Cmux Swift Blocking Runtime ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json (371 additions, 12 deletions). The diff contains image metadata and default flags only. It introduces no Swift source ch…
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json. The diff contains no Sources/TerminalController.swift, ControlCommandExecutionPolicy, worker-router, WebKit/AppKit, or …
Cmux Expensive Synchronous Load ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json. The diff contains image metadata and default flags, with no Swift files or agent-history loading code. Therefore the custom…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json (371 additions and 12 deletions). The diff contains image metadata and default flags only. It contains no Swift, TypeScr…
Cmux No Hacky Sleeps ✅ Passed PASS. The pull request changes only web/services/vms/images/manifest.json, which contains image metadata. The diff introduces no TypeScript, JavaScript, shell, or build/runtime code and no sleep, ti…
Cmux Algorithmic Complexity ✅ Passed The pull request changes only web/services/vms/images/manifest.json. The diff adds 12 image records and changes default flags on 12 existing records. JSON validation confirms no code, loops, scans, …
Cmux Swift Concurrency ✅ Passed PASS — The pull-request commit changes only web/services/vms/images/manifest.json (371 additions, 12 deletions). No Swift file or cmux-owned Swift code changed, so the diff does not introduce or exp…
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json (371 additions and 12 deletions). The diff contains no .swift files, Swift functions, annotations, or call-site change…
Cmux Swift Package Boundaries ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json. The commit diff contains no Swift source, Package.swift, or SwiftPM package path. Therefore it introduces no production S…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The pull-request diff contains one changed file: web/services/vms/images/manifest.json (+371/-12). It does not change Package.swift, Package.resolved, .gitignore, Xcode project files, wo…
Cmux Swift Logging ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json. The exact diff contains image metadata and defaultForKind/defaultForLocalDev changes only. It adds no Swift code or log…
Cmux User-Facing Error Privacy ✅ Passed PASS — The commit changes only web/services/vms/images/manifest.json. It flips default flags and adds 12 validated image metadata entries; it does not change user-facing error or recovery copy. Mani…
Cmux Full Internationalization ✅ Passed PASS. The PR changes only web/services/vms/images/manifest.json. It promotes snapshot identifiers, sizes, validation metadata, and default flags. These are operational/configuration values, not new …
Cmux Swiftui State Layout ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json, a JSON image manifest. The actual main...HEAD diff contains no SwiftUI source, ObservableObject, @Published, `@Observ…
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json; git diff HEAD^ HEAD reports no Swift files. The diff updates image default flags and adds image metadata. It introduces n…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull request changes only web/services/vms/images/manifest.json (+371/-12). The commit diff contains no Swift, Xcode project, or workspace changes. Therefore, it does not add or materially chang…
Cmux Source Artifacts ✅ Passed PASS. The only changed path is web/services/vms/images/manifest.json. It is the documented source of truth for promoted VM images and the sanctioned release manifest. The diff adds image configurati…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The pull request changes only web/services/vms/images/manifest.json. git diff HEAD^..HEAD contains no Swift files and no path under a production Sources/ directory. Therefore it cannot int…
Cmux No Ambient Global State ✅ Passed PASS: The PR changes only web/services/vms/images/manifest.json (+371/-12) and contains no changed .swift files. The custom check applies only to production Swift changes, so it is not applicable.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-devbox-bake-measure

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Superseded: the manifest moved past this rebake with #12125 (termid), #12243 (wsboot), #12250 (agents0910), all baked from main, and this branch now conflicts on manifest.json. The only leftover is the human-facing slug repoint (cmux-devbox-lg and friends), which needs a --replace-slug run, not this PR.

This branch was successfully deployed

2 active deployments
Preview – cmux166 — e02060ae Deployed Sep 8, 2026 by vercel[bot]
Preview – cmux41 — e02060ae Deployed Sep 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant