Fix CodeRouter mappings for Base and fork provisioning - #12273
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughVM base and fork routes now pass model-plane gateways into VM workflows. Workflows provision edge rules before provider creation, revoke resources on failure, and use snapshot-based forks when model-plane configuration is present. Tests cover lifecycle, rollback, fork, and route wiring behavior. ChangesModel plane VM provisioning
Estimated code review effort: 2 (Simple) | ~10 minutes Sequence Diagram(s)sequenceDiagram
participant VMRoute
participant VMWorkflow
participant ModelPlaneGateway
participant VMProvider
VMRoute->>VMWorkflow: pass modelPlane gateway
VMWorkflow->>ModelPlaneGateway: provisionModelPlane
ModelPlaneGateway-->>VMWorkflow: return edgeRules
VMWorkflow->>VMProvider: create VM with edgeRules
VMProvider-->>VMWorkflow: return provider result
VMWorkflow->>ModelPlaneGateway: revokeModelPlane on failure
Suggested reviewers: Merge Risk: 🟡 Moderate · up to Base and fork provisioning now install VM-bound CodeRouter rules, but nine regression cases remain failing. Users may still encounter failed provisioning or unavailable CodeRouter access, so the change is not merge-ready until the failures are resolved or explicitly accepted. Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error, 1 warning)
✅ Passed checks (23 passed)
Full details: Cmux User-Facing Error PrivacyExplanation The PR activates a user-facing error path that exposes the internal service name Resolution Replace
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 Biome (2.5.10)web/app/api/vm/[id]/fork/route.tsBiome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins. web/app/api/vm/base/routeShared.tsBiome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins. web/services/vms/workflows.tsBiome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
db93233 Scope mobile Mac minimums by app build kind 61d5bd9 Fix sudo broker hangs when pam_tid is unavailable 6c9fe2a Fix CodeRouter mappings for Base and fork provisioning (manaflow-ai#12273) dacc589 Fix Cloud VM creation, snapshot refresh, and desktop restore (manaflow-ai#12268) c2a4da1 cmux-cloud-vm skill: the complete cmux Cloud CLI set, per-verb --help, drift check, router prune fix (manaflow-ai#10793)
…2273) * test: cover missing CodeRouter mappings in Base and fork provisioning * fix: provision VM-bound CodeRouter routes for Base machines and forks
Summary
Base open/reset and fork could allocate a Cloud VM without its CodeRouter TLS rule. The image still points Codex at
https://coderouter.cmux.internal/v1/responses, but the provider has no rule binding that source VM to the CodeRouter origin. A client retaining the alias address/CA then receives Freestyle's404 no VM is mapped to coderouter.cmux.internalon every reconnect.Related to #12271. The original report does not identify its VM, so this fixes a reproduced provisioning defect without claiming that the reporter's particular machine has been repaired.
Regression attribution
The first incomplete model-plane wiring is
a9207e460e(#11622): it added the provisioner to create and restore, omitting Base and fork.0f19be0471(#11813) then baked the internal alias into every image and added the alias destination host. The laterf838159173(#11897) native-fork branch also bypasses model-plane setup.Reviewed the requested suspects: #12144 (CLI bootstrap; #12139 is its issue), #12205 (browser login origin only; #12203 is its issue), #12111 (upstream provider selection), #12103 (dashboard accounts/team scope), and #11798 (CodeRouter telemetry/health). They do not create/delete the VM alias rule. The exact missing-mapping response is reproducible at the Freestyle edge before CodeRouter authentication. Removing the older startup probe (#11771/#11791) removed detection, but does not explain why a rule is absent.
Validation
61dcd1ca54: test-only commit. Hosted web CI passed typecheck and failed all 9 new regression cases. The remaining obsolete full-suite jobs were canceled after capturing this failure.0ff462c504: fix. 98 route/model-plane workflow tests pass; 136 additional provider, lifecycle, workflow adapter, and route-token authentication tests pass (57 database-only cases skipped locally). Typecheck and complexity pass. Scoped ESLint has no errors and one pre-existing unused-variable warning.Reconnecting... 1/5, reconnects, and completespong. Pause/resume retains the session; the fork resumes the same Codex conversation using a distinct VM-bound rule. A forged guestx-cmux-vm-idis overwritten by the edge and the correct binding is authenticated.0ff462c504: http://127.0.0.1:17320/issue-12271-coderouter-reconnectopen(scripts/ci/validate-cla-policy.rb:2472). CLA policy files are unchanged. This is not an all-required-checks-green result.Preview: https://cmux-ol6rchg24-manaflow.vercel.app — READY on the pushed commit; Base open responds 401 without authentication. CLI config returns 503 because no branch-applicable preview Stack credentials are configured. Authenticated preview dogfood remains unavailable; the reconnect evidence above comes from the real-VM controlled-origin harness. The automatic clone-project previews had no API routes.
GitHub records an external merge by austinywang at 2026-09-10 17:13:13 UTC, commit 6c9fe2a. This task issued no merge command. Existing user sessions and route rules were preserved. All verification VMs, snapshots, and networks were deleted.