Repository navigation
perf: keep recursive warm-slot disk scans off foreground path - #13530
Merged
Merged
Conversation
|
Warning Review limit reachedNext included review available in 12 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
teamleaderleo
enabled auto-merge (squash)
September 22, 2026 00:36
This was referenced Sep 22, 2026
Closed
teamleaderleo
added a commit
that referenced
this pull request
Sep 22, 2026
Squashed onto current main after #13530 merged.
teamleaderleo
added a commit
that referenced
this pull request
Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps * Enforce Cloud display provenance and independent guest displays * Keep display creation compatible with baked Cloud images * Fix guest display target wiring and session supervision * Harden embedded display helper and Dock restore ownership * Close Cloud display lifecycle gaps * Harden display discovery and helper restart recovery * Finish Cloud display build and readiness guards * Preserve display state and bind guest listeners privately * Invalidate display catalogs when VM state changes * Preserve Dock display duplication identity * Preserve Cloud display refresh and browser locations * Run guest display service as the desktop user * Align Ghostty submodule with current main * Invalidate terminal Cloud navigation callbacks * Keep guest display ports out of forwarded resources * Complete additional display recovery paths * Synchronize guest profile and slow-route readiness * Finish guest display startup and restore routing * Keep unresolved display restores retryable * Fence guest discovery to provider lifetime * test: cover display transport recovery and duplication state * fix: preserve Cloud displays during transport recovery * test: preserve display identity across browser reconfiguration * fix: retain display identity across route reconfiguration * test: cover route observation after display reconfiguration * fix: retain Cloud restore lifecycle state * test: drop Cloud provenance after external navigation * fix: clear Cloud provenance on external browser navigation * test: cover display catalog and readiness cancellation * fix: fence display catalog and readiness lifecycles * test: cover delayed display restore and scoped helpers * fix: complete display restore and supervisor isolation * fix: require discovered guest display resources * test: cover guest component recovery * fix: preserve Cloud provenance and supervise displays * test: reject failed display catalog responses * fix: fence display discovery by response and auth * test: filter untrusted display restore targets * fix: fence display restore targets and VM kind * test: fence browser Cloud service identity * test: exercise recovered display supervision * fix: recover display supervisors and port identity * test: recover scoped display process commands * fix: recover scoped display processes by command * test: cover Cloud restore and destination comment fixes * fix: address Cloud display review comments * test: cover display port ownership and recovery * fix: harden Cloud display supervisor and route lifecycle * test: stay within Swift file budget * fix: sanitize display errors and readiness probes * fix: restore Cloud resources in Dock scopes * fix: recover global Dock projections and daemon readiness * fix: preserve Dock connections across Cloud route changes * fix: bound display startup and preserve duplicate URLs * fix: defer Cloud activation for hidden restores * fix: preserve ownership checks across latest main merge * fix: remove duplicate projection query declarations * fix: restore provider display lifecycle after main merge * fix: use merged hostname route API * fix: restore New Display hover button after main merge The latest origin/main merge moved CloudTreeRowHoverButtons into its own file, and the conflict resolution kept main's copy, which dropped the displays-pool New Display button and its hasButtons entry. Re-apply them in the new file, and restore the blank lines the resolution stripped from SurfaceCatalog.swift so the PR diff stays limited to behavior changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: keep SurfaceCatalog within its line budget The blank lines restored in the previous commit put the file seven lines over the Swift file-length budget, so drop them again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: route cloud desktop clicks through portal * chore: keep cloud fix within file budgets * ci: pin agent review checker to workflow commit * docs: record trusted agent review execution * test: lock agent review gate to trusted checker * #13531: retire and background-reap cold warm-slot task state Squashed onto current main after #13530 merged. * fix: separate terminal stream and viewport lease lifetimes * fix: keep viewport lease across UI output stream churn * ci: dispatch #13474 follow-up iOS test * ci: remove temporary #13474 follow-up dispatcher * ci: run direct #13474 ownership test * fix: request Greptile without GraphQL review capture * ci: remove temporary #13474 direct test workflow * test: decouple Greptile request from review GraphQL * docs: separate Greptile request from ledger capture * fix(iOS): preserve tagged App Group when signing supports it (#13541) * fix(ios): preserve supported tagged App Groups * ci: keep iOS-only tests off macOS runners * ci: run tagged iOS signing regression on Linux * ci: freeze legacy iOS test routing path * fix(ios): harden tagged signing fallback detection * fix(ios): fail closed on partial ASC signing credentials * fix(ios): validate ASC key path before device signing * chore(ios): report tagged device signing backend * docs(ios): keep cheap regressions off macOS routing * test(ios): bind fallback entitlements to retry build * ci: catch nested iOS-only test routing footguns * test(iOS): bind fallback entitlements to retry command * fix(iOS): correct retry assertion pattern * fix: keep cold-task cleanup moving past failures * test: cover resilient cold-task cleanup * fix(review): require proof for repaired findings * iOS: keep the composer bar out of the home-indicator band when the terminal disconnects (#13471) * iOS: add failing disconnected-composer-seat fixture and regression test (#13470) CMUX_UITEST_WORKSPACE_DETAIL_DISCONNECTED=1 mounts a workspace shell whose one retained terminal is Disconnected, with no Mac or sign-in; scenario drop-after-focus starts connected, focuses the composer at t+2s (real keyboard), and drops the Mac to unavailable at t+9s. The new XCUITest rides the dock probe through the raise and the blocked-input resign, waits for the settled keyboard-down rest, then asserts the dock's constraint-resolved bottom edge leaves the whole bottom safe area below it. On the iOS <=26 keyboard-guide seat the dock instead rests at the raw screen bottom, so this test fails until the fix. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * iOS: floor the keyboard-guide dock seat at the bottom safe area (#13470) With the keyboard up over a connected terminal, the Mac dropping to unavailable blocks input, which resigns the keyboard. After that show->hide cycle UIKeyboardLayoutGuide rests at the RAW host bottom instead of the bottom safe area (usesBottomSafeArea notwithstanding), so the accessory toolbar and composer bar land inside the home-indicator band - permanently, because blocked input means no keyboard event ever re-seats the guide. Add a required dock.bottom <= host.bottom - resolvedBottomSafeAreaInset floor, active only with the guide seat, and downgrade the guide equality to 999 so it yields exactly the clamped distance when the guide rests too low. The floor is slack whenever the keyboard holds the guide higher, follows the same resolved-inset sources as the plain seat, and deactivates with the guide in the chrome-hidden state (whose dock parks at the raw bottom by design). The iOS 27 notification seat already computes from the resolved inset and is unaffected. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix: restore working Greptile review trigger * fix: restore working Greptile review trigger * fix: restore working Greptile review trigger * fix: restore working Greptile review trigger * chore: preserve current Greptile trigger template * Split the release guard critical path (#13502) * ci: split release guards into parallel groups Squashed onto current main after #13501 merged. * test: include split release groups in guard matrix contract * test: include split release groups in guard matrix contract * fix: use current Greptile review mention * fix: use current Greptile review mention * fix: use current Greptile review mention * test: reject legacy Greptile app mention * ci: skip Linux preflight when macOS is unrouted (#13550) * ci: skip macOS preflight when macOS is unrouted * test(ci): cover skipped macOS preflight routing * test(ci): preserve preflight contract migration marker * ci: ignore unrelated review status comment churn * test: pin unrelated comment filtering * docs: record review comment filtering * fix: use documented Greptile review trigger * fix: use documented Greptile review trigger * fix: use documented Greptile review trigger * fix: use documented Greptile review trigger * Speed up CI critical path and remove obsolete review gate Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route. * docs: clarify eligible review gate triggers * test: exercise trusted review request path * CI: route tagged iOS entitlement guard to release-ios * ci: route tagged iOS entitlement guard to release-ios * test: own tagged iOS entitlement guard in release-ios --------- Co-authored-by: Austin Wang <austinwang115@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com> Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
teamleaderleo
added a commit
that referenced
this pull request
Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps * Enforce Cloud display provenance and independent guest displays * Keep display creation compatible with baked Cloud images * Fix guest display target wiring and session supervision * Harden embedded display helper and Dock restore ownership * Close Cloud display lifecycle gaps * Harden display discovery and helper restart recovery * Finish Cloud display build and readiness guards * Preserve display state and bind guest listeners privately * Invalidate display catalogs when VM state changes * Preserve Dock display duplication identity * Preserve Cloud display refresh and browser locations * Run guest display service as the desktop user * Align Ghostty submodule with current main * Invalidate terminal Cloud navigation callbacks * Keep guest display ports out of forwarded resources * Complete additional display recovery paths * Synchronize guest profile and slow-route readiness * Finish guest display startup and restore routing * Keep unresolved display restores retryable * Fence guest discovery to provider lifetime * test: cover display transport recovery and duplication state * fix: preserve Cloud displays during transport recovery * test: preserve display identity across browser reconfiguration * fix: retain display identity across route reconfiguration * test: cover route observation after display reconfiguration * fix: retain Cloud restore lifecycle state * test: drop Cloud provenance after external navigation * fix: clear Cloud provenance on external browser navigation * test: cover display catalog and readiness cancellation * fix: fence display catalog and readiness lifecycles * test: cover delayed display restore and scoped helpers * fix: complete display restore and supervisor isolation * fix: require discovered guest display resources * test: cover guest component recovery * fix: preserve Cloud provenance and supervise displays * test: reject failed display catalog responses * fix: fence display discovery by response and auth * test: filter untrusted display restore targets * fix: fence display restore targets and VM kind * test: fence browser Cloud service identity * test: exercise recovered display supervision * fix: recover display supervisors and port identity * test: recover scoped display process commands * fix: recover scoped display processes by command * test: cover Cloud restore and destination comment fixes * fix: address Cloud display review comments * test: cover display port ownership and recovery * fix: harden Cloud display supervisor and route lifecycle * test: stay within Swift file budget * fix: sanitize display errors and readiness probes * fix: restore Cloud resources in Dock scopes * fix: recover global Dock projections and daemon readiness * fix: preserve Dock connections across Cloud route changes * fix: bound display startup and preserve duplicate URLs * fix: defer Cloud activation for hidden restores * fix: preserve ownership checks across latest main merge * fix: remove duplicate projection query declarations * fix: restore provider display lifecycle after main merge * fix: use merged hostname route API * fix: restore New Display hover button after main merge The latest origin/main merge moved CloudTreeRowHoverButtons into its own file, and the conflict resolution kept main's copy, which dropped the displays-pool New Display button and its hasButtons entry. Re-apply them in the new file, and restore the blank lines the resolution stripped from SurfaceCatalog.swift so the PR diff stays limited to behavior changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: keep SurfaceCatalog within its line budget The blank lines restored in the previous commit put the file seven lines over the Swift file-length budget, so drop them again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: route cloud desktop clicks through portal * chore: keep cloud fix within file budgets * #13531: retire and background-reap cold warm-slot task state Squashed onto current main after #13530 merged. * fix: separate terminal stream and viewport lease lifetimes * fix: keep viewport lease across UI output stream churn * ci: dispatch #13474 follow-up iOS test * ci: remove temporary #13474 follow-up dispatcher * ci: run direct #13474 ownership test * ci: remove temporary #13474 direct test workflow * fix: keep cold-task cleanup moving past failures * test: cover resilient cold-task cleanup * fix(review): require proof for repaired findings * devex: add edit-weighted build graph health report Squashed onto current main. * ci: skip Linux preflight when macOS is unrouted (#13550) * ci: skip macOS preflight when macOS is unrouted * test(ci): cover skipped macOS preflight routing * test(ci): preserve preflight contract migration marker * devex: anchor build graph reports to an immutable ref * devex: keep build graph history tied to the selected commit * test: cover immutable build graph report inputs * Speed up CI critical path and remove obsolete review gate Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route. * CI: route tagged iOS entitlement guard to release-ios * ci: route tagged iOS entitlement guard to release-ios * test: own tagged iOS entitlement guard in release-ios * devex: distinguish history commits from source-touch commits * test: pin full-window and source-touch commit counts --------- Co-authored-by: Austin Wang <austinwang115@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
teamleaderleo
added a commit
that referenced
this pull request
Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps * Enforce Cloud display provenance and independent guest displays * Keep display creation compatible with baked Cloud images * Fix guest display target wiring and session supervision * Harden embedded display helper and Dock restore ownership * Close Cloud display lifecycle gaps * Harden display discovery and helper restart recovery * Finish Cloud display build and readiness guards * Preserve display state and bind guest listeners privately * Invalidate display catalogs when VM state changes * Preserve Dock display duplication identity * Preserve Cloud display refresh and browser locations * Run guest display service as the desktop user * Align Ghostty submodule with current main * Invalidate terminal Cloud navigation callbacks * Keep guest display ports out of forwarded resources * Complete additional display recovery paths * Synchronize guest profile and slow-route readiness * Finish guest display startup and restore routing * Keep unresolved display restores retryable * Fence guest discovery to provider lifetime * test: cover display transport recovery and duplication state * fix: preserve Cloud displays during transport recovery * test: preserve display identity across browser reconfiguration * fix: retain display identity across route reconfiguration * test: cover route observation after display reconfiguration * fix: retain Cloud restore lifecycle state * test: drop Cloud provenance after external navigation * fix: clear Cloud provenance on external browser navigation * test: cover display catalog and readiness cancellation * fix: fence display catalog and readiness lifecycles * test: cover delayed display restore and scoped helpers * fix: complete display restore and supervisor isolation * fix: require discovered guest display resources * test: cover guest component recovery * fix: preserve Cloud provenance and supervise displays * test: reject failed display catalog responses * fix: fence display discovery by response and auth * test: filter untrusted display restore targets * fix: fence display restore targets and VM kind * test: fence browser Cloud service identity * test: exercise recovered display supervision * fix: recover display supervisors and port identity * test: recover scoped display process commands * fix: recover scoped display processes by command * test: cover Cloud restore and destination comment fixes * fix: address Cloud display review comments * test: cover display port ownership and recovery * fix: harden Cloud display supervisor and route lifecycle * test: stay within Swift file budget * fix: sanitize display errors and readiness probes * fix: restore Cloud resources in Dock scopes * fix: recover global Dock projections and daemon readiness * fix: preserve Dock connections across Cloud route changes * fix: bound display startup and preserve duplicate URLs * fix: defer Cloud activation for hidden restores * fix: preserve ownership checks across latest main merge * fix: remove duplicate projection query declarations * fix: restore provider display lifecycle after main merge * fix: use merged hostname route API * fix: restore New Display hover button after main merge The latest origin/main merge moved CloudTreeRowHoverButtons into its own file, and the conflict resolution kept main's copy, which dropped the displays-pool New Display button and its hasButtons entry. Re-apply them in the new file, and restore the blank lines the resolution stripped from SurfaceCatalog.swift so the PR diff stays limited to behavior changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: keep SurfaceCatalog within its line budget The blank lines restored in the previous commit put the file seven lines over the Swift file-length budget, so drop them again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix: route cloud desktop clicks through portal * chore: keep cloud fix within file budgets * #13531: retire and background-reap cold warm-slot task state Squashed onto current main after #13530 merged. * fix: separate terminal stream and viewport lease lifetimes * fix: keep viewport lease across UI output stream churn * ci: dispatch #13474 follow-up iOS test * ci: remove temporary #13474 follow-up dispatcher * ci: trim unused workflow-guard setup and duplicate capture work Collapse #13483-#13486 onto the current split guard matrix. * ci: run direct #13474 ownership test * ci: remove temporary #13474 direct test workflow * fix(iOS): preserve tagged App Group when signing supports it (#13541) * fix(ios): preserve supported tagged App Groups * ci: keep iOS-only tests off macOS runners * ci: run tagged iOS signing regression on Linux * ci: freeze legacy iOS test routing path * fix(ios): harden tagged signing fallback detection * fix(ios): fail closed on partial ASC signing credentials * fix(ios): validate ASC key path before device signing * chore(ios): report tagged device signing backend * docs(ios): keep cheap regressions off macOS routing * test(ios): bind fallback entitlements to retry build * ci: catch nested iOS-only test routing footguns * test(iOS): bind fallback entitlements to retry command * fix(iOS): correct retry assertion pattern * fix: keep cold-task cleanup moving past failures * test: cover resilient cold-task cleanup * fix(review): require proof for repaired findings * iOS: keep the composer bar out of the home-indicator band when the terminal disconnects (#13471) * iOS: add failing disconnected-composer-seat fixture and regression test (#13470) CMUX_UITEST_WORKSPACE_DETAIL_DISCONNECTED=1 mounts a workspace shell whose one retained terminal is Disconnected, with no Mac or sign-in; scenario drop-after-focus starts connected, focuses the composer at t+2s (real keyboard), and drops the Mac to unavailable at t+9s. The new XCUITest rides the dock probe through the raise and the blocked-input resign, waits for the settled keyboard-down rest, then asserts the dock's constraint-resolved bottom edge leaves the whole bottom safe area below it. On the iOS <=26 keyboard-guide seat the dock instead rests at the raw screen bottom, so this test fails until the fix. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * iOS: floor the keyboard-guide dock seat at the bottom safe area (#13470) With the keyboard up over a connected terminal, the Mac dropping to unavailable blocks input, which resigns the keyboard. After that show->hide cycle UIKeyboardLayoutGuide rests at the RAW host bottom instead of the bottom safe area (usesBottomSafeArea notwithstanding), so the accessory toolbar and composer bar land inside the home-indicator band - permanently, because blocked input means no keyboard event ever re-seats the guide. Add a required dock.bottom <= host.bottom - resolvedBottomSafeAreaInset floor, active only with the guide seat, and downgrade the guide equality to 999 so it yields exactly the clamped distance when the guide rests too low. The floor is slack whenever the keyboard holds the guide higher, follows the same resolved-inset sources as the plain seat, and deactivates with the guide in the chrome-hidden state (whose dock parks at the raw bottom by design). The iOS 27 notification seat already computes from the resolved inset and is unaffected. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * Split the release guard critical path (#13502) * ci: split release guards into parallel groups Squashed onto current main after #13501 merged. * test: include split release groups in guard matrix contract * test: include split release groups in guard matrix contract * ci: skip Linux preflight when macOS is unrouted (#13550) * ci: skip macOS preflight when macOS is unrouted * test(ci): cover skipped macOS preflight routing * test(ci): preserve preflight contract migration marker * ci: install bashlex only in its release owner * test: pin release-only bashlex ownership * Speed up CI critical path and remove obsolete review gate Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route. * ci: port guard setup ownership to split release groups * test: pin split guard setup ownership * CI: route tagged iOS entitlement guard to release-ios * ci: route tagged iOS entitlement guard to release-ios * test: own tagged iOS entitlement guard in release-ios * ci(iOS): resolve manual test refs before checkout (#13566) * ci(ios): resolve manual test refs to full SHAs * test(ci): cover manual iOS short-SHA dispatches * test(ci): fix iOS workflow job parser * ci: run iOS dispatch-ref regression on Linux * iOS: allow all photo library task attachments (#13441) * iOS: allow all photo library task attachments * iOS: export Foundation for recovery API * iOS: accept video attachments in terminal composers * iOS: show videos in composer photo pickers * Clarify composer picker comments * Keep photo library attachment picker unfiltered * Bound Photos library attachment transfers * Make Photos attachment timeout authoritative * ci: route tagged iOS entitlement guard to release-ios * Add structured iOS connectivity diagnostics to Axiom (#13459) * Add structured iOS connectivity diagnostics to Axiom * refactor: move telemetry helper to file scope * refactor: keep diagnostic bounds in payload assembly * fix: bound event surface telemetry --------- Co-authored-by: Austin Wang <austinwang115@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com> Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Normal warm-slot
warm/task-runexecution recursively walked the entire cache tree before and after native work solely to populate disk-growth telemetry. As DerivedData grows, that observation cost can become foreground latency.This change:
--measure-disk;--measure-disk, so cache-growth evidence remains available where it is deliberately measured;No source/toolchain/generation/lease/recovery semantics change.
Related: #13091, teamleaderleo/glaeda#1095.
Summary by cubic
Moves recursive cache-size measurement off the foreground
warm/task-runpath so large DerivedData trees can't make routine telemetry a latency tax.warmandtask-runno longer walk the cache tree before/after native work by default. A new--measure-diskflag opts back into byte-growth measurement, and the physical benchmark passes it so cache-growth evidence stays available. Receipts omit disk fields unless measured; regression tests cover both default-off and opt-in behavior. Related: #13091.Written for commit caf6780. Summary will update on new commits.