Skip to content

Fix CodeRouter mappings for Base and fork provisioning - #12273

Merged
austinywang merged 2 commits into
mainfrom
issue-12271-coderouter-reconnect
Sep 10, 2026
Merged

austinywang merged 2 commits into
mainfrom
issue-12271-coderouter-reconnect

Conversation

@austinywang

@austinywang austinywang commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Base open/reset and fork could allocate a Cloud VM without its CodeRouter TLS rule. The image still points Codex at https://coderouter.cmux.internal/v1/responses, but the provider has no rule binding that source VM to the CodeRouter origin. A client retaining the alias address/CA then receives Freestyle's 404 no VM is mapped to coderouter.cmux.internal on every reconnect.

Related to #12271. The original report does not identify its VM, so this fixes a reproduced provisioning defect without claiming that the reporter's particular machine has been repaired.

  • Pass the existing team/user-scoped model-plane gateway through Base open/reset and fork.
  • Base creation issues the new row's token before provider allocation, passes the inline rule, fails closed/refunds on provisioning failure, and revokes on provider or database-finalization rollback.
  • Model-plane forks use the existing snapshot/create path, which provisions a rule bound to the copy's row. Trade-off: this takes a snapshot instead of using the native-fork interface, which cannot accept new edge rules. The current Freestyle driver does not implement native fork.
  • Existing mappings, client retry policy, login origins, provider selection, and the guest's placeholder-only credential contract are unchanged. This does not automatically repair a previously allocated machine whose rule is missing.

Regression attribution

The first incomplete model-plane wiring is a9207e460e (#11622): it added the provisioner to create and restore, omitting Base and fork. 0f19be0471 (#11813) then baked the internal alias into every image and added the alias destination host. The later f838159173 (#11897) native-fork branch also bypasses model-plane setup.

Reviewed the requested suspects: #12144 (CLI bootstrap; #12139 is its issue), #12205 (browser login origin only; #12203 is its issue), #12111 (upstream provider selection), #12103 (dashboard accounts/team scope), and #11798 (CodeRouter telemetry/health). They do not create/delete the VM alias rule. The exact missing-mapping response is reproducible at the Freestyle edge before CodeRouter authentication. Removing the older startup probe (#11771/#11791) removed detection, but does not explain why a rule is absent.

Validation

  • 61dcd1ca54: test-only commit. Hosted web CI passed typecheck and failed all 9 new regression cases. The remaining obsolete full-suite jobs were canceled after capturing this failure.
  • 0ff462c504: fix. 98 route/model-plane workflow tests pass; 136 additional provider, lifecycle, workflow adapter, and route-token authentication tests pass (57 database-only cases skipped locally). Typecheck and complexity pass. Scoped ESLint has no errors and one pre-existing unused-variable warning.
  • Live Freestyle reproduction: on an isolated VM, retain the client's CA/address and delete its rule; three requests return the exact reported 404. Re-create the rule; the request reaches CodeRouter again.
  • Live patched workflows: Base creation and snapshot/fork use real Freestyle allocation, inline TLS rules, and guest Codex 0.154.0. The controlled HTTPS origin uses the production route-token authenticator with an in-memory token store and a synthetic Responses stream. It deliberately truncates the first stream: Codex prints Reconnecting... 1/5, reconnects, and completes pong. Pause/resume retains the session; the fork resumes the same Codex conversation using a distinct VM-bound rule. A forged guest x-cmux-vm-id is overwritten by the edge and the correct binding is authenticated.
  • Production read-only probes: 11 existing mapped machines reach CodeRouter over HTTP/1.1 and HTTP/2. A real model completion was blocked by the connected upstream account's usage limit; synthetic streaming isolates routing/reconnect from that quota.
  • Fixed-head hosted web CI: 2,767 pass, 242 skip, 0 fail; all 8 browser checks pass. Database-migration and workflow guards pass. Extra macOS jobs from the manual full-suite run are asynchronous.
  • Tagged fleet build succeeded on 0ff462c504: http://127.0.0.1:17320/issue-12271-coderouter-reconnect
  • The post-merge CLA policy guard fails because its live-PR validation requires state open (scripts/ci/validate-cla-policy.rb:2472). CLA policy files are unchanged. This is not an all-required-checks-green result.
  • No user-facing strings changed; localization audit found no new catalog entries required.

Preview: https://cmux-ol6rchg24-manaflow.vercel.app — READY on the pushed commit; Base open responds 401 without authentication. CLI config returns 503 because no branch-applicable preview Stack credentials are configured. Authenticated preview dogfood remains unavailable; the reconnect evidence above comes from the real-VM controlled-origin harness. The automatic clone-project previews had no API routes.

GitHub records an external merge by austinywang at 2026-09-10 17:13:13 UTC, commit 6c9fe2a. This task issued no merge command. Existing user sessions and route rules were preserved. All verification VMs, snapshots, and networks were deleted.

@vercel

vercel Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Ready Ready Preview Sep 10, 2026 5:24pm UTC
cmux41 Ready Ready Preview Sep 10, 2026 5:24pm UTC

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d4bf602a-d36b-4972-8985-c5f484c9d854

📥 Commits

Reviewing files that changed from the base of the PR and between dacc589 and 0ff462c.

📒 Files selected for processing (5)
  • web/app/api/vm/[id]/fork/route.ts
  • web/app/api/vm/base/routeShared.ts
  • web/services/vms/workflows.ts
  • web/tests/vm-model-plane-workflow.test.ts
  • web/tests/vm-route-auth.test.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

VM base and fork routes now pass model-plane gateways into VM workflows. Workflows provision edge rules before provider creation, revoke resources on failure, and use snapshot-based forks when model-plane configuration is present. Tests cover lifecycle, rollback, fork, and route wiring behavior.

Changes

Model plane VM provisioning

Layer / File(s) Summary
Route gateway wiring
web/app/api/vm/[id]/fork/route.ts, web/app/api/vm/base/routeShared.ts
Base and fork routes construct modelPlane gateways from billing team and stack user identifiers.
Workflow model-plane lifecycle
web/services/vms/workflows.ts
Base workflows and fork workflows accept modelPlane, provision edge rules before provider creation, revoke resources during failures, and bypass native forks when model-plane configuration is present.
Workflow and route validation
web/tests/vm-model-plane-workflow.test.ts, web/tests/vm-route-auth.test.ts
Tests cover provisioning order, refunds, revocation, fork behavior, and gateway wiring across paid provisioning routes.

Estimated code review effort: 2 (Simple) | ~10 minutes

Sequence Diagram(s)

sequenceDiagram
  participant VMRoute
  participant VMWorkflow
  participant ModelPlaneGateway
  participant VMProvider
  VMRoute->>VMWorkflow: pass modelPlane gateway
  VMWorkflow->>ModelPlaneGateway: provisionModelPlane
  ModelPlaneGateway-->>VMWorkflow: return edgeRules
  VMWorkflow->>VMProvider: create VM with edgeRules
  VMProvider-->>VMWorkflow: return provider result
  VMWorkflow->>ModelPlaneGateway: revokeModelPlane on failure
Loading

Suggested reviewers: lawrencecchen, theswerd

Merge Risk: 🟡 Moderate · up to 0ff46

Base and fork provisioning now install VM-bound CodeRouter rules, but nine regression cases remain failing. Users may still encounter failed provisioning or unavailable CodeRouter access, so the change is not merge-ready until the failures are resolved or explicitly accepted.


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error The PR activates a user-facing error path that exposes the internal service name coderouter. routeShared.ts and the fork route now pass a model-plane gateway, and workflows.ts can fail with `VmM… Replace coderouter in the public model-plane error response with safe product terms such as Cloud VM service or Cloud VM access service in all user-visible fields. Keep the service name and raw causes only in sanitized logs or interna…
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 5 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: fixing CodeRouter mappings for Base and fork provisioning.
Description check ✅ Passed The description provides a detailed summary, explains the failure and rollback behavior, and documents testing results and remaining validation work. The template's Demo Video, Review Trigger, and Che…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS: The authoritative pull-request diff changes five .ts files only: two API routes, one workflow file, and two test files. It contains no .swift files or production Swift declarations, so the S…
Cmux Swift Blocking Runtime ✅ Passed The reviewed range changes five TypeScript files and no Swift files. The custom check applies only to production Swift changes, so its blocking or timing synchronization failure conditions are not int…
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only VM API/workflow code and VM tests. No changed path is in Sources/TerminalController.swift or ControlCommandExecutionPolicy.swift, and the patch contains no `bro…
Cmux Expensive Synchronous Load ✅ Passed PASS: The reviewed pull-request range changes only five TypeScript files under web/ and contains no Swift production changes. The custom check applies only to production Swift changes that add or mo…
Cmux Cache Substitution Correctness ✅ Passed PASS: The reviewed TypeScript diff does not replace any fresh authoritative read with a cached or opportunistic value. It adds model-plane provisioning and rollback handling, and it routes model-plane…
Cmux No Hacky Sleeps ✅ Passed The diff does not introduce or expand any hacky sleep or fixed wall-clock synchronization. Production additions only wire vmModelPlaneGatewayFor, provision/revoke model-plane materials, pass `edgeRu…
Cmux Algorithmic Complexity ✅ Passed PASS: The production diff only injects the model-plane gateway, provisions edge-rule materials, adds rollback calls, and disables native fork only when a model plane is present. It adds no scalable co…
Cmux Swift Concurrency ✅ Passed The reviewed range changes only five TypeScript test and VM workflow files. It contains no .swift files and no Swift concurrency constructs in the diff. Therefore, this Swift-specific check is not a…
Cmux Swift @Concurrent ✅ Passed PASS: The authoritative pull-request diff changes only five .ts files and contains no changed Swift paths or Swift concurrency annotations. The swift-concurrent-annotation.md check applies to Swif…
Cmux Swift Package Boundaries ✅ Passed PASS: The authoritative pull-request diff changes only five TypeScript files under web/ and contains no .swift or Package.swift changes. The Swift package-boundary check therefore does not apply…
Cmux Swiftpm Lockfiles ✅ Passed PASS: The pull request changes only five TypeScript files. It does not change a Package.swift file, Package.resolved file, Xcode project, .gitignore file, workflow, or dependency declaration. Therefor…
Cmux Swift Logging ✅ Passed PASS: The pull-request range changes five TypeScript files and zero Swift files. The added lines contain no print, debugPrint, dump, NSLog, Logger, stdout, stderr, or file-logging diagnostics. The Swi…
Cmux Full Internationalization ✅ Passed PASS: The production diff only wires an existing model-plane provisioner into VM routes and workflows. It adds no Swift text, web UI copy, API response copy, metadata, markdown, changelog text, or loc…
Cmux Swiftui State Layout ✅ Passed PASS — The reviewed range changes only five TypeScript files under web/ and contains no Swift or SwiftUI changes. The diff introduces no ObservableObject, @Published, @Observable, `GeometryRea…
Cmux Architecture Rethink ✅ Passed PASS: The reviewed diff changes only TypeScript files under web/app, web/services, and web/tests. It contains no Swift, SwiftUI, AppKit, or Swift lifecycle code, and none of the Swift architectural fa…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The authoritative pull-request diff changes five TypeScript test/application files and no Swift files. Therefore, it does not add or materially change a Swift auxiliary window, and the `swift-auxiliar…
Cmux Source Artifacts ✅ Passed The diff changes only five existing tracked TypeScript source and test files under web/. The additions are hand-written workflow wiring and regression fixtures/tests for the model-plane behavior. No…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The authoritative pull-request diff changes only five TypeScript files under web/. It contains no Swift file and no path under a production Sources/ directory, so the specified Swift product…
Cmux No Ambient Global State ✅ Passed PASS: The reviewed range changes five TypeScript files and contains no Swift files. This check applies only to production Swift changes, so the ambient global state criteria are not applicable.
Full details: Cmux User-Facing Error Privacy

Explanation

The PR activates a user-facing error path that exposes the internal service name coderouter. routeShared.ts and the fork route now pass a model-plane gateway, and workflows.ts can fail with VmModelPlaneError during provisioning. runVmRoute dispatches that error to the existing public response, whose message, reason, action, ui.title, and ui.message contain coderouter. The response text is pre-existing, but the PR exposes it on Base open/reset and fork requests. This violates the rule against upstream or internal service names in user-facing text. Tests and internal logs do not affect this finding.

Resolution

Replace coderouter in the public model-plane error response with safe product terms such as Cloud VM service or Cloud VM access service in all user-visible fields. Keep the service name and raw causes only in sanitized logs or internal telemetry. Add route-level regression assertions for the model-plane failure response to ensure its body and UI copy contain no internal service names or raw upstream messages.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch issue-12271-coderouter-reconnect

Warning

Some tools did not complete. Review the errors below.

🔧 Biome (2.5.10)
web/app/api/vm/[id]/fork/route.ts

Biome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins.

web/app/api/vm/base/routeShared.ts

Biome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins.

web/services/vms/workflows.ts

Biome could not lint this file: nested root configuration. Check the repository's Biome configuration and plugins.

  • 2 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@austinywang
austinywang marked this pull request as ready for review September 10, 2026 17:09
@austinywang
austinywang merged commit 6c9fe2a into main Sep 10, 2026
30 of 36 checks passed
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 10, 2026
db93233 Scope mobile Mac minimums by app build kind
61d5bd9 Fix sudo broker hangs when pam_tid is unavailable
6c9fe2a Fix CodeRouter mappings for Base and fork provisioning (manaflow-ai#12273)
dacc589 Fix Cloud VM creation, snapshot refresh, and desktop restore (manaflow-ai#12268)
c2a4da1 cmux-cloud-vm skill: the complete cmux Cloud CLI set, per-verb --help, drift check, router prune fix (manaflow-ai#10793)
aerickson pushed a commit to aerickson/cmux that referenced this pull request Sep 13, 2026
…2273)

* test: cover missing CodeRouter mappings in Base and fork provisioning

* fix: provision VM-bound CodeRouter routes for Base machines and forks

This branch was successfully deployed

2 active deployments
Preview – cmux166 — 0ff462c5 Deployed Sep 10, 2026 by vercel[bot]
Preview – cmux41 — 0ff462c5 Deployed Sep 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant