Cloud: honor enrolled address families when selecting private routes - #12269
Closed
austinywang wants to merge 1 commit into
Closed
austinywang wants to merge 1 commit into
austinywang wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Superseded by merged #12266. Its shared resolver covers the sole enrolled family, all-candidate eligibility, and stored-address fallback implemented here. Closing this stacked duplicate; #12268 owns the separate live provider-network reachability fix.
Cloud connections could keep an old IPv4 route even when the WireGuard hub enrolled only IPv6 (or vice versa). Select the sole enrolled address after filtering, and check all known candidates before rejecting a connection. Repeated
vm tuiconnections also reuse the registry's saved address candidates when their endpoint payload omitsnetwork_addresses.Stacked on #12267. This follow-up contains the route eligibility fix; the parent contains the dual-stack connection work and the failing regression tests.
Validation:
d7cdb3d322ec39583fb4731d72dfe843bfed02d7was cancelled after confirming that merged Fix Cloud discovery stalls and private address fallback #12266 supersedes this implementation: https://github.com/manaflow-ai/cmux/actions/runs/34480011525git diff --checkpassed.d7cdb3d322ec39583fb4731d72dfe843bfed02d7; the downloaded bundle recordsCMUXCommit=d7cdb3d32. Build. The default development backend hostname does not resolve, so backend provisioning was disabled. Live Cloud connection dogfood remains pending.Localization audit: no user-facing strings changed.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Note
Cursor Bugbot is generating a summary for commit d7cdb3d. Configure here.
Summary by cubic
Fixes cloud private route selection so connections no longer keep a route for an address family the WireGuard hub didn't enroll. Now selects the sole enrolled candidate after filtering, and rejects only when no candidate matches.
vm tuiconnections reuse the registry's saved address candidates when the endpoint payload omitsnetwork_addresses.Written for commit d7cdb3d. Summary will update on new commits.
Latest investigation (Nightly
02d75978e4, September 10): the new VM daemon was running from creation, but the Nightly client dialed IPv4 only. Read-only probes through that same running WireGuard hub timed out after 8 seconds on IPv4 ports 1337 and 6901; IPv6 returned daemon HTTP 404 in 20 ms and desktop HTTP 200 in 48 ms. The UI subsequently reported the 60-second link timeout.Upstream coordination: #12266 merged at 12:51 UTC and already includes a broader shared route resolver plus independent discovery. This stacked PR overlaps that merged work and should not be merged as a replacement. #12268 tracks the separate provider-network announcement fix and documents the interventions that restored the earlier VMs. The installed Nightly predates both changes.