Skip to content

Master Axiom cmux Cloud PR - #13151

Merged
austinywang merged 112 commits into
mainfrom
feat-axiom-cloud-coverage
Sep 24, 2026
Merged

austinywang merged 112 commits into
mainfrom
feat-axiom-cloud-coverage

Conversation

@austinywang

@austinywang austinywang commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Cloud diagnostics rejected valid placement failures and RC-client batches, then permanently dropped them on 400. Cloud reads could overlap or outlive their callers, auth refresh could exceed its original deadline, and guest installation failures could lose their rollback outcome. This master PR consolidates the scoped Cloud fixes after reconciling the current main branch.

Fixes #13138. Fixes #12625. Fixes #12626. Follow-up hardening for the already-merged #12624. Coverage and unresolved evidence: #13140.

Changes

  • Accept placement failures and RC metadata through sanitized ingestion, durable storage, and export while preserving trace, operation, span, and client-channel data.
  • Share auth refreshes with independent cancellation, session fencing, and one absolute deadline.
  • Coalesce list, stats, and usage reads with separate caller deadlines and a fixed transport cap; retain Retry-After, bound cooldown memory, invalidate only affected scopes and paths, enforce access gates, and cancel or replace panel work correctly.
  • Show a retryable offline state even when reachability changes during the first list request.
  • Validate staged guest CLI installation before publication; distinguish exit, missing-status, timeout, and cleanup outcomes while retaining unconfirmed provider allocations.
  • Keep the focused Cloud acceptance suites explicit in CI, with a nonzero execution guard for each selected suite.

Scale and regression evidence

The deterministic read-coordination fixture covers 1, 10, 100, and 1,000 machines with four owners and asserts one transport request per machine, independent caller deadlines, cancellation/teardown, offline rejection, bounded cooldowns, and stale-response replacement. This is normalized request/concurrency evidence for the changed path. The historical Axiom before/after numbers cannot be recomputed in this session because Query Read is denied for the supplied token; no live recurrence or latency claim is made.

Main reconciliation

The branch is clean, origin/main at 3337293da049b7be37bc67489710986c389f54e4 is an ancestor of the current head 6c95ef332e497f681f45d1e530d77c31d5f7e8de, and the latest pull was a conflict-free merge. No merge, deployment, production mutation, or billing change has been performed.

Evidence

  • Hosted validation immediately before the final reachability replay commit had green compile admission, Swift package tests, release build, web, guest-install, auth, and focused checks; the exact c3ec4d7 SHA was then compiled successfully by fleet. The app-host shards remain blocked by unrelated UI/WebKit/design-mode baseline failures after the permitted rerun; the Cloud identity/read tests pass on the rerun. The current c3ec4d7 PR CI macOS status is still pending.
  • Local validation completed for the focused web suites, bun run typecheck, Swift file budgets, PBX/project and test wiring, package grouping, package-resolved policy, and git diff --check. No local Swift/Xcode build was run.
  • Fleet job 8222beb98abbb1bccb62bdf2 verified the previous pre-main-sync head and is superseded by the current main merge; a new exact-head tagged build is required after the fresh checks stabilize.

Limits

Axiom Query Read remains denied with HTTP 403 for the supplied token. The source and ticket mapping is complete, but no live 24-hour, 7-day, or retention-window APL audit, production recurrence count, or runtime dogfood claim is made. Historical provider and daemon reports remain needs-repro in #13140. The coverage ledger is /Users/austinwang/.local/state/cmux-axiom-cloud-audit/coverage.md.

Review trigger

Full closeout review requested for the consolidated Cloud diagnostics, auth, read-coordination, guest-install, and cleanup changes. The current head is reviewed against origin/main; automatic review threads are replied to and resolved. The PR stays unmerged until hosted checks and the tagged fleet build are green.

Checklist

  • Focused Cloud telemetry, read ownership, auth transition, guest install, cleanup, and route-response coverage added.
  • Local web suites, typecheck, localization parity, PBX/test wiring, Swift budgets, package policy, and workspace grouping verified where supported.
  • Current origin/main reconciled conflict-free at 3337293da0; the Cloud read, reachability, guest-install, and current main changes were preserved.
  • Review findings have source-backed replies; intentional architecture/package/docstring findings are documented in the PR follow-up comment.
  • Demo video: not applicable to this backend/telemetry and test-contract consolidation; the tagged fleet artifact is built and awaits controller publish recovery.
  • Live Axiom recurrence audit: blocked until Query Read permission is granted (HTTP 403); no production log claim is made.

@austinywang austinywang self-assigned this Sep 20, 2026
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: eccc8743-5000-46dd-a77d-d73ae6976bcf

📥 Commits

Reviewing files that changed from the base of the PR and between ed62571 and c2a5e70.

📒 Files selected for processing (7)
  • Sources/Cloud/MachinesPanelViewModel.swift
  • cmuxTests/CloudReadRequestCoordinatorTests.swift
  • web/services/vms/drivers/freestyle.ts
  • web/services/vms/drivers/freestyleGuestCli.ts
  • web/services/vms/drivers/guestCliInstallCommand.ts
  • web/tests/vm-guest-install.test.ts
  • web/tests/vm-workflows.test.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The PR adds Cloud read coordination and bounded refresh behavior, atomic guest CLI installation with rollback handling, cleanup-pending VM recovery, expanded diagnostics support for placement and RC payloads, and related tests and CI workflows.

Changes

Cloud reliability and diagnostics

Layer / File(s) Summary
Authentication deadlines and Cloud reads
Packages/Shared/CmuxAuthRuntime/..., Sources/Cloud/..., Sources/Surfaces/..., cmuxTests/CloudRead*, cmuxTests/VMClientReadCoalescingTests.swift
Auth phases preserve inherited deadlines. Cloud reads share transports, enforce caller and transport deadlines, retain 429 cooldowns, react to network changes, and invalidate affected keys after mutations. Machine refresh and route recovery use the new coordination paths.
Guest CLI installation and rollback
web/services/vms/drivers/..., web/tests/vm-guest-install*.test.ts, web/tests/vm-freestyle-provider.test.ts
Guest installation validates uploads and targets, publishes files atomically, restores prior files after failure, propagates cancellation, and reports typed failure details. Provider rollback now distinguishes confirmed absence from unconfirmed cleanup.
Cleanup-pending VM workflow
web/services/vms/repository.ts, web/services/vms/workflows.ts, web/services/vms/routeHelpers.ts, web/services/vms/vmErrorMessages.ts, web/messages/*.json, web/tests/vm-workflows.test.ts, web/tests/vm-guest-create-response.test.ts
Unconfirmed provider cleanup keeps VM rows in provisioning with cleanup metadata. Reconciliation claims, retries, and resolves retained allocations. API responses expose a localized non-retryable cleanup-pending error.
Diagnostics contract
web/services/observability/*, web/tests/cloud-*.test.ts, cmuxTests/CloudOperationRecorderTests.swift
The web contract accepts placement failures and the rc channel. Tests cover parsing, durable persistence, receipt handling, and separate RC and production routing.
CI and project integration
.github/workflows/*, cmux.xcodeproj/project.pbxproj
The workflows select the pinned Xcode version, add guest-install regression coverage, and expand Cloud acceptance suites. New source and test files are registered in the Xcode target.

Priority: ⬆️ High

Estimated code review effort: 5 (Critical) | ~90 minutes

Change: Bug fix · Severity of issue fixed: High


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (3 errors, 2 warnings)

Check name Status Explanation Resolution
Cmux Swift Package Boundaries ❌ Error The diff adds independently testable Cloud read domain logic to the app target. Sources/Cloud/CloudReadRequestCoordinator.swift defines a Foundation-only actor with injected clock, deadlines, cancel… Create a small macOS SwiftPM target named CmuxCloudRead and make CloudReadRequestCoordinator its first public type. Move the coordinator, Key/Response/Entry/Pending/Waiter/Context, CloudReadMutation, `CloudReadCooldownStor…
Cmux Full Internationalization ❌ Error The PR adds GuestCliInstallError.message with English text such as guest cmux shim ${stage}: ${outcome}. Freestyle create now throws this error, VmProviderGateway wraps it, and `vmProviderOperat… Do not expose GuestCliInstallError.message or its stage/outcome diagnostics as API response copy. Detect this typed failure in the provider error response and return a locale-specific generic response, or add a locale-backed message key a…
Cmux Architecture Rethink ❌ Error The Swift diff introduces a new network NotificationCenter side channel and splits recovery ownership across multiple MainActor objects. VMClient.bootstrap converts CloudReadRequestCoordinator sta… Create one explicit Cloud read lifecycle owner at bootstrap. Keep network state, transition fencing, and the single recovery action in CloudReadRequestCoordinator or a dedicated CloudReadLifecycleCoordinator. Replace the two Notificatio…
Linked Issues check ⚠️ Warning #13138 is addressed. The contract accepts placement and rc, preserves the shared channel allowlist, stores and exports sanitized data, and tests authenticated acceptance, durable outbox handling, … For #12625, add reviewable scale evidence that compares the prior and current behavior. Normalize request count, peak concurrency, and latency by machine count, view-model count, and visibility. Include the 1, 10, 100, and 1,000 machine cas…
Docstring Coverage ⚠️ Warning Docstring coverage is 16.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 206 functions across 55 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (20 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The reviewed changes stay within the linked objectives. Auth deadline propagation and its workflow tests support bounded Cloud read lifetimes. Cloud read coordination, reachability, access gates, and …
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The diff does not introduce a persistent-session or early-input violation. No cmux-tui, Ghostty, PTY, ManualIO, ManualMirror, or CloudWorkspaceCreationHost implementation file changes. The route…
Cmux Swift Actor Isolation ✅ Passed No explicit actor-isolation failure was introduced. The new read coordinator is an actor, and its state stays actor-isolated. The new value models are plain Sendable structs/enums without MainActor is…
Cmux Swift Blocking Runtime ✅ Passed PASS. The production diff adds actor-owned Cloud read coordination and a cancellation-aware injected Clock for request deadlines. It does not add semaphores, blocking waits, main-queue sync, manual lo…
Cmux Browser Automation Off-Main ✅ Passed PASS: The review-scoped diff does not modify Sources/TerminalController.swift or Packages/macOS/CmuxControlSocket/Sources/CmuxControlSocket/Wire/ControlCommandExecutionPolicy.swift. These are the …
Cmux Expensive Synchronous Load ✅ Passed PASS. The pull-request diff does not add or move any agent-history loader. It has no changes to RestorableAgentSessionIndex, SharedLiveAgentIndex, agent hook/session stores, transcript or trajecto…
Cmux Cache Substitution Correctness ✅ Passed No changed-code match to the cache-substitution failure condition. The new Swift read coordinator shares in-flight /api/vm and /stats transports and retains only bounded 429 Retry-After cooldown…
Cmux No Hacky Sleeps ✅ Passed No custom-check failure condition is introduced. The changed TypeScript runtime code adds no raw sleep, setTimeout, setInterval, polling loop, or delayed dispatch. Guest installation and provider roll…
Cmux Algorithmic Complexity ✅ Passed No explicit algorithmic-complexity failure is introduced. MachinesPanelViewModel+Refresh.swift performs one linear filter/map over machines and one stats task per machine. `CloudReadRequestCoordinat…
Cmux Swift Concurrency ✅ Passed No explicit Swift concurrency modernization failure is introduced. The only new custom DispatchQueue is the delivery queue required by NWPathMonitor, which is an allowed OS callback boundary. New …
Cmux Swift @Concurrent ✅ Passed PASS. The Swift diff adds no new nonisolated async function and adds no @concurrent annotation. The new read coordinator is an actor; its async methods access actor-isolated state, which the rul…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The authoritative PR diff changes only cmux.xcodeproj/project.pbxproj source-file wiring; it adds no SwiftPM package-reference, repository URL, requirement, or product-dependency lines. No `Pa…
Cmux Swift Logging ✅ Passed PASS. The Swift diff adds no prohibited logging in app/runtime code. The only new print is in cmuxTests/CloudReadRequestCoordinatorTests.swift and reports test-scale data, which the rule allows fo…
Cmux User-Facing Error Privacy ✅ Passed PASS — The changed production response for cleanup-pending VM creation uses localized, generic Cloud VM copy. It exposes only operation: "create", cleanupPending, and retry state in details. The…
Cmux Swiftui State Layout ✅ Passed PASS. The PR does not introduce a SwiftUI state-layout violation. MachinesPanelViewModel remains the existing ObservableObject; its @Published declarations are identical at the base and head rev…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request does not add or materially change a standalone cmux-owned window. The changed Swift code covers auth, Cloud read coordination, view-model refresh logic, surface-provider routing…
Cmux Source Artifacts ✅ Passed PASS. The authoritative PR diff contains 84 ordinary tracked text paths only: Swift/TypeScript application source, tests and fixtures, localization catalogs, workflow configuration, and Xcode project …
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS. The authoritative diff adds no #if DEBUG or test-build-guarded member in production Swift, and no member uses the prohibited debug/test seam names. MachinesPanelViewModel widens state to int…
Title check ✅ Passed The title is related to the Cloud changes, but it is broad and emphasizes Axiom even though the PR also covers auth refresh, read coordination, and guest installation.
Description check ✅ Passed The description is complete and structured. It explains the changes and reasons, documents testing and limitations, addresses the demo-video requirement, includes review triggers, and provides checkli…
Full details: Linked Issues check

Explanation

#13138 is addressed. The contract accepts placement and rc, preserves the shared channel allowlist, stores and exports sanitized data, and tests authenticated acceptance, durable outbox handling, export, and uploader receipts. #12626 is addressed by typed guest-install outcomes, bounded execution, atomic publication, cleanup, rollback handling, retained allocations, localized cleanup-pending responses, and focused tests. #12625 is substantially addressed by read coalescing, caller and transport deadlines, cancellation and replacement, access gates, reachability state, mutation invalidation, Retry-After retention, and scale tests. The remaining requirement is the requested before-and-after normalized request, concurrency, and latency results by machine count, view-model count, and visibility. The reviewed scale test reports one request per machine for 1, 10, 100, and 1,000 machines with four owners, but it does not report those before-and-after concurrency and latency results.

Resolution

For #12625, add reviewable scale evidence that compares the prior and current behavior. Normalize request count, peak concurrency, and latency by machine count, view-model count, and visibility. Include the 1, 10, 100, and 1,000 machine cases or explain any omitted case.

Full details: Cmux Swift Package Boundaries

Explanation

The diff adds independently testable Cloud read domain logic to the app target. Sources/Cloud/CloudReadRequestCoordinator.swift defines a Foundation-only actor with injected clock, deadlines, cancellation, retry cooldowns, invalidation, and network state. Its support types (CloudReadMutation, CloudReadCooldownStore, CloudRequestClock, and the coordinator value types) also have no UI or app-lifecycle dependency. cmuxTests/CloudReadRequestCoordinatorTests.swift tests this logic directly with a manual clock and a response gate across many isolated cases. The Xcode diff registers these files in the cmux application Sources phase, and the diff adds no SwiftPM package target. The VMCapabilities and machine-usage value types are also app-target provider/domain models. This matches the rule's failure conditions for independently testable domain logic and provider/protocol/parsing logic kept in Sources/. UI composition in MachinesPanelViewModel, AppDelegate, and the existing CmuxAuthRuntime package changes do not change this finding.

Resolution

Create a small macOS SwiftPM target named CmuxCloudRead and make CloudReadRequestCoordinator its first public type. Move the coordinator, Key/Response/Entry/Pending/Waiter/Context, CloudReadMutation, CloudReadCooldownStore, CloudRequestClock, and the Network.framework monitor into that target with package unit tests. Move the pure VMCapabilities and machine-usage value models there as well, or place them in a separate small Cloud domain target if their provider model ownership requires it. Keep VMClient URLSession/auth composition, MachinesPanelViewModel, CloudReadRecoveryObserver, AppDelegate, and other AppKit/SwiftUI lifecycle glue in the app target. Add the package dependency to the app and test targets, then expose only the smallest public value/protocol API needed by those callers.

Full details: Cmux Full Internationalization

Explanation

The PR adds GuestCliInstallError.message with English text such as guest cmux shim ${stage}: ${outcome}. Freestyle create now throws this error, VmProviderGateway wraps it, and vmProviderOperationErrorResponse copies the nested message into the API response reason and details.providerMessage. The prior message was also English, but this PR materially changes that user-visible API copy without a locale-specific source. The new cleanup-pending response itself is correctly localized through next-intl and has entries in all 20 locales from web/i18n/routing.ts. The new Swift text also uses String(localized:defaultValue:) and the existing catalog key has translations.

Resolution

Do not expose GuestCliInstallError.message or its stage/outcome diagnostics as API response copy. Detect this typed failure in the provider error response and return a locale-specific generic response, or add a locale-backed message key and load it with the request locale. Keep the detailed stage, outcome, exit code, and cleanup data in telemetry/server diagnostics. If new web message keys are added, update web/messages/en.json, ja.json, zh-CN.json, zh-TW.json, ko.json, de.json, es.json, fr.json, it.json, da.json, pl.json, ru.json, bs.json, ar.json, no.json, pt-BR.json, th.json, tr.json, km.json, and uk.json.

Full details: Cmux Architecture Rethink

Explanation

The Swift diff introduces a new network NotificationCenter side channel and splits recovery ownership across multiple MainActor objects. VMClient.bootstrap converts CloudReadRequestCoordinator state into .cmuxCloudReadNetworkChanged and .cmuxCloudReadNetworkRecovered notifications. MachinesPanelViewModel observes the first notification and independently clears state, cancels work, and restarts polling. CmuxTuiSurfaceProviderRegistry observes the second notification and independently starts a refresh through CloudReadRecoveryObserver. The transport is coalesced, but the lifecycle actions are not. This leaves recovery, polling, and presentation state under separate owners and can cause stale or duplicate refresh transitions. The NWPathMonitor queue is a required platform callback, and the locks are test-only, but the added NotificationCenter bridge is not a required platform bridge and its Task { @mainactor ... } adds timing-dependent delivery. The structural root cause is that the coordinator owns isOnline, while the panel and registry each own separate reactions to that state. The single source of truth should own the network lifecycle transition and its recovery action, rather than broadcasting loosely typed notifications to independent refresh owners.

Resolution

Create one explicit Cloud read lifecycle owner at bootstrap. Keep network state, transition fencing, and the single recovery action in CloudReadRequestCoordinator or a dedicated CloudReadLifecycleCoordinator. Replace the two NotificationCenter notifications and CloudReadRecoveryObserver with a typed, injected state stream or MainActor callback carrying immutable network snapshots and an explicit recovery action. Remove the panel and registry network observers. Route panel presentation updates and registry refresh through that owner, with one owner deciding when a recovery refresh runs. Preserve the coordinator's transport coalescing and the NWPathMonitor platform bridge. Add tests that deliver one offline-to-online transition and verify one recovery action, no refresh after owner retirement, no stale result publication, and consistent panel/registry state. The first migration cut is to replace the notification posts and observers with the typed injected callback, then delete the legacy notification seam.

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Reuse the scoped implementation and regression suites from #12628 at 32155cf. Leave unrelated CI, signing, and Iroh changes on their original branch.
…m ownership

Adapt the read coordination and regression suites from #12636 at ec3f5bb to current main. Retain main resource-stat reconciliation, pinning, team-scope fences, and already-landed Cloud split routing. Exclude unrelated renderer, Iroh, and signing changes.
austinywang and others added 15 commits September 23, 2026 18:38
Cmd-Opt-= and Cmd-Opt-- must zoom the canvas when the focused panel is a
Markdown file in text mode. That editor is a SavingTextView but not a text
file preview, so the canvas layout clause should still allow canvas zoom.
Records the canvas zoom factors and checks the editor font is unchanged.

This test fails on the current branch: #12814 widened
filePreviewTextEditorFocused to every SavingTextView, which blocks
canvasLayoutOutsideFocusedContent (and Cmd-0, covered by
cmdZeroInCanvasResetsCanvasZoomWhenMarkdownSourceEditorIsFocused).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#7157 limited filePreviewTextEditorFocused to the focused text file
preview's editor, matching the command palette's
panelIsFilePreviewTextEditor, so Markdown source and Dock editors keep
Canvas zoom and do not take preview zoom. #12814 widened the flag to every
SavingTextView so word wrap works in those editors, which also turned off
canvasLayoutOutsideFocusedContent there: Cmd-0, Cmd-Opt-= and Cmd-Opt--
stopped reaching the canvas.

Keep both scopes. filePreviewTextEditorFocused is narrow again and drives
the shared shortcut context, preview zoom and Canvas routing. The new
fileEditorFocused covers every file editor and applies only to actions in
the .filePreviewTextEditor context (word wrap): whenClauseContext(for:)
projects it onto the file-editor atom for their `when` clause, both at the
keyDown gate and when arming chords, and isAvailable uses it for their menu
and palette state. FileEditorWordWrapShortcutTests.appShortcutRouting still
covers Opt-Z in a bare file editor.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
"Best-effort telemetry cannot monopolize resident delivery capacity"
enqueued three tool events back to back. Tool telemetry has one ingress
slot, so the second and third are admitted only if the drain task has
already moved the previous one into a lane. On a loaded app host it had
not: one tool event was dropped, tool-4 was then admitted in its place,
and the lifecycle event queued behind tool-4 in the surface-4 lane never
started, so waitUntilStarted(count: 3) timed out.

Wait for each of the first two tool deliveries to start before the next
enqueue. Tool-4 is then rejected by the three-event best-effort
reservation whether or not tool-3 has left ingress.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit f385fa6)
24 test helpers waited for a child process by queueing a blocking
waitUntilExit() on DispatchQueue.global() and waiting on a semaphore
with a timeout. Every queued waiter holds a pool thread until its child
exits. Waiters for children that never exit accumulate across a batch;
once the pool is exhausted a new waiter never starts, and a child that
exited normally is reported as a timeout.

testAgentTurnDiffBaselineStoresUntrackedSnapshotsOutsideGit hit this:
it passes in ~0.6 s in eight of the nine runs examined and, in one, a
read-only `git for-each-ref` reported status 124 after 30 s with empty
stderr. cd7d25c fixed the same failure in one Claude hook helper.

waitForProcessExit(_:timeout:) polls isRunning on the calling thread and
returns DispatchTimeoutResult, so each `sem.wait(timeout: .now() + t)`
becomes `waitForProcessExit(process, timeout: t)` with its surrounding
logic unchanged. No test in cmuxTests queues a waitUntilExit() anymore.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit dba68ec)
testSenderRelativeSidebarActionKeysItsOriginatingWindowBeforeMutation
gave AppKit one fixed 50 ms run-loop spin to move key status after
makeKeyAndOrderFront. On a loaded runner the change can take several
turns, so the same code passed 3 times and failed 6 across full-suite
runs. Wait for the transition with a 5 s deadline instead.

Also normalize project.pbxproj ordering for ProcessExitWait.swift.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit be5fa50)
foregroundAuthenticatedAttachUsesConfiguredRetryBudget runs the full
20-attempt fallback budget through fake ssh/cmux/sleep, which takes about
4.5 s per case on an idle runner, against a fixed 5 s process deadline.
Under shard load the harness SIGTERMed the script after 19 sleeps (status
143). The deadline now scales with the attempts the case expects; the
assertions are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit d2126d9)
#10564 moved reload surface fanout from RunLoop.main.perform onto
TerminalConfigurationApplyScheduler, which yields through
MainActorDeferredActionScheduler's Task { @mainactor }. The four reload
cases are synchronous main-actor tests that wait with a nested
RunLoop.main.run, which cannot run main-actor tasks while the test job
holds the main queue. The fanout never finished, so completions, the
reload notification, and the queued transaction never arrived.

Make the cases async and wait with waitWhileSuspended. Each first
settles any in-flight reload. An idle full reload now commits
synchronously, so the staged-appearance case holds one transaction
open to exercise the queued path it describes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

(cherry picked from commit 6733553)
…n yet

With the reload fanout on main-actor tasks, the notification arrives only
after later turns, so asserting it had not fired right after
reloadConfiguration proved nothing: an unblocked reload also reads false
at that instant. The case now asserts the coordinator is parked in
.waitingForFontWork, that five main-actor yields leave it there, and
that the commit callback has not run, before releasing the barrier.
Adds a DEBUG-only GhosttyApp.debugConfigurationReloadPhase for that.
Raised by CodeRabbit on #14006.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 38d9a9c)
testConfiguredWorkspaceTerminalFontSizeResetRestoresEverySplit failed in
the #13151 full-ci shard with twelve issues: four surfaces, each still
3 points below the configured size after Cmd+0 was accepted.

An earlier case in the same process left a configuration reload fanning
out. That reload holds the app-wide font-size work barrier
(GhosttyTerminalView reload transaction), and the arbiter retains font
mutations issued behind the barrier until reconciliation finishes, by
design. The reset was accepted and queued, so the synchronous checks ran
before it applied.

Settle any in-flight reload while suspended (the helper from #14057)
before issuing the reset, and assert no reload is active. The reset
assertions are unchanged: every split, the dock terminal, and the split
created after the zoom must still reset immediately.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts:
#	cmux.xcodeproj/project.pbxproj
The card-layout expectation in "Cloud failure controls stay above native
surfaces" fails in the full app-host shard with only
`overlay.frame.width > 100 -> false`. Record the card, source terminal,
content reference and window frames so the failing run names which one
was small.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 3499302)
Conflict in cmux.xcodeproj/project.pbxproj: keep both the PR's
CloudReadResponseGate.swift and main's SSHTuiMigrationTests.swift entries in
the cmuxTests group; normalized with scripts/normalize-pbxproj.py.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflict in .github/workflows/auth-refresh-tests.yml: keep the PR's dual-Xcode
overflow runner and pinned-Xcode step, prefixed with main's GitHub-hosted fork
branch (#14023), matching the pattern main already uses in ci-macos.yml.

cloud-vm-guest-install.yml (PR-only pull_request workflow) gains the same
'ubuntu-24.04' fork branch so tests/test_ci_fork_runner_routing.py passes on
the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@austinywang

Copy link
Copy Markdown
Contributor Author

Merged current origin/main into this branch (head is now ae95394c0c; the PR was CONFLICTING/DIRTY, so pull_request CI had not been running at all).

Two merge commits, 497209c472 (main 407ee86236) and ae95394c0c (main 5b646b7e33). Resolutions:

  • cmux.xcodeproj/project.pbxproj: keep both this PR's CloudReadResponseGate.swift and main's SSHTuiMigrationTests.swift in the cmuxTests group; normalized with scripts/normalize-pbxproj.py. check-pbxproj.sh, sync-test-wiring --check and lint-pbxproj-test-wiring.sh pass (1068 test files).
  • .github/workflows/auth-refresh-tests.yml: keep this PR's dual-Xcode overflow runner and "Select pinned Xcode" step, prefixed with main's GitHub-hosted fork branch from ci: run fork pull-request workflows on GitHub-hosted runners #14023 (same shape main already uses in ci-macos.yml).
  • .github/workflows/cloud-vm-guest-install.yml (a pull_request workflow only this PR adds): gained the ubuntu-24.04 fork branch so main's new tests/test_ci_fork_runner_routing.py passes on the merged tree.
  • Sources/CodexTurnRestoreIntentPolicy.swift: main's Fix main compile: import CmuxWorkspaces in CodexTurnRestoreIntentPolicy #14123 adds the same import CmuxWorkspaces as 054bd4b109; merged clean.

Also checked statically: main's SurfaceMachineID / RemoteTuiMachine provider reshape is compatible with this PR's registry (the summary: VMSummary call sites resolve through main's CmuxTuiSurfaceProvider+Hosting.swift overloads), the VMCapabilities memberwise init matches, and no declaration was added on both sides. tests/test_ci_fork_runner_routing.py, tests/test_ci_self_hosted_guard.sh, test_ci_queue_janitor.py, test_run_e2e.py, test_app_host_test_products.py pass locally on the merged tree.

Dev build of ae95394c0c submitted to the fleet as tag issue-13140-axiom-cloud-coverage for Cloud dogfood.

— Shardwright pending
run run_cmux_13151_ci_repair_20260924_fe1c6c33 · session claude-code-fe1c6c33-4112-4395-9e32-270b57e9fea1

@austinywang
austinywang merged commit 742f123 into main Sep 24, 2026
63 of 64 checks passed
@github-project-automation github-project-automation Bot moved this from Todo to Done in cmux backlog Sep 24, 2026
teamleaderleo added a commit to teamleaderleo/cmux that referenced this pull request Sep 24, 2026
ci.yml: main replaced the sleep-based macos-debounce job with
macos-admission-gate (job dependencies, no polling). The gate and the
macos caller keep this branch's cli route in their conditions.
ci-macos.yml: compile admission keeps this branch's condition and takes
main's fork-aware runs-on.

CLI tests moved to cmuxCLITests take main's waitForProcessExit waits
(manaflow-ai#13151). ProcessExitWait.swift moves to cmuxCLITestSupport and is
compiled into both test targets, since four moved suites now call it.
RemoteShellCWDRelayTests keeps main's pbxproj IDs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 24, 2026
#14228)

#13327 added single-flight stats reads inside VMResourceStatsStore. It was
written before #13151 landed CloudReadRequestCoordinator, which already
shares every concurrent /stats GET per account, team, and auth generation
and cancels the HTTP read once its last caller leaves. The store-level task
duplicated that sharing but ran unstructured, so a removed machine or a
hidden panel kept its stats request alive until the 30 s timeout. The
coordinator's waiter accounting also stopped seeing callers, and three
VMClientReadCoalescingTests cases timed out on every main run.

Stats reads now fence per caller with beginRead/finishRead, which keeps the
revision and sequence ordering from #13327's store, and share the network
request through the coordinator. The store's read(machineID:) and its tests
go away with it; VMClientReadCoalescingTests covers sharing, cancellation,
and resize invalidation at the client.

This reverts commit c72f659df746cfcabf1e5ab1b92b99ec8b09b38c.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

full-ci EXPENSIVE: full macOS tests/builds; overrides selective PR routing. Not needed for normal checks.

Projects

None yet

2 participants