Skip to content

Rename v2 Workers and preserve legacy hostnames - #13768

Closed
azooz2003-bit wants to merge 5 commits into
mainfrom
feat-cmux-v2-worker-names
Closed

azooz2003-bit wants to merge 5 commits into
mainfrom
feat-cmux-v2-worker-names

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

The v2 Workers were named after IROH even though the backend also owns tickets, registration, directory, dashboard, and team control. This renames the canonical Workers to cmux-v2, cmux-v2-staging, and cmux-v2-development, updates client and dashboard origins, and keeps the old hostnames as Cloudflare service-binding aliases.

The live Workers were renamed in place before alias deployment, preserving their Durable Object namespaces and data. Old aliases forward to the canonical Worker, so old app builds continue to reach the same storage. The temporary rename proof also verified SQLite data and an open WebSocket survived the operation.

Validation:

  • v2 boundary, generated contracts, types, typecheck, and unit tests passed in the first run.
  • Worker name/config test passed.
  • Staging and production Wrangler dry-runs passed.
  • Live probes returned matching error.v1/unsupported_method responses from old and new URLs in all three environments.
  • The focused compatibility alias tests pass. The full runtime suite was not green in the local Bun 1.3.14 environment because its concurrent deployment test timed out; GitHub backend and client checks passed.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Renames the v2 Workers from cmux-iroh-v2* to cmux-v2, cmux-v2-staging, and cmux-v2-development since the backend also owns tickets, registration, directory, dashboard, and team control. Old hostnames stay as Cloudflare service-binding aliases, so existing app builds keep reaching the same storage.

  • Workers were renamed in place, preserving Durable Object namespaces and SQLite data.
  • Updates client and dashboard origins across Swift, TypeScript, and deploy scripts; the dashboard keeps accepting legacy hostnames during migration.
  • Alias deployment guards verify the canonical Workers' storage bindings and refuse to overwrite a Worker that still owns Durable Object namespaces.

Written for commit d504b48. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Updates
    • Mobile apps, dashboards, and development defaults now use the cmux-v2 addresses for production, staging, and development.
    • Existing cmux-iroh-v2 addresses continue to work and forward requests to the corresponding cmux-v2 service, including WebSocket connections.
  • Documentation
    • Updated deployment guidance for the renamed services and their legacy addresses.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4ebcde2b-e306-4510-8ca1-15b65c965483

📥 Commits

Reviewing files that changed from the base of the PR and between 302217b and d504b48.

📒 Files selected for processing (4)
  • cmuxTests/MobileHostIrxSettingsMappingTests.swift
  • scripts/reload.sh
  • workers/iroh-v2/README.md
  • workers/iroh-v2/e2e/control-runtime.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The canonical IROH v2 Worker hostnames and application origins now use the cmux-v2 prefix. The change adds forwarding Workers for the former hostnames, checks their bindings before deployment, and updates related tests and documentation.

Changes

Worker rename and compatibility

Layer / File(s) Summary
Canonical Worker names and deployment
docs/iroh-v2/IMPLEMENTATION.md, workers/iroh-v2/e2e/control-wrangler.jsonc, workers/iroh-v2/scripts/deploy-dev.sh, workers/iroh-v2/e2e/control-runtime.test.ts
Worker names and control-test endpoints use the cmux-v2 hostname family. The implementation notes list the renamed shared Workers.
Legacy hostname forwarding
workers/iroh-v2/aliases/index.ts, workers/iroh-v2/scripts/check-compatibility-aliases.ts, workers/iroh-v2/scripts/deploy-compatibility-aliases.sh, workers/iroh-v2/test/compatibility-alias.test.ts, workers/iroh-v2/tsconfig.json, workers/iroh-v2/README.md
A compatibility Worker forwards requests to a canonical Worker through a CANONICAL service binding. The checker validates Worker bindings before the deploy script refreshes aliases. Tests cover binding checks and request forwarding.
Application origins and validation
Sources/Mobile/MobileHostV2Installation.swift, ios/cmuxPackage/Sources/cmuxFeature/MobileIrohV2Configuration.swift, web/app/[locale]/dashboard/mobile-devices/*, scripts/reload.sh, Packages/Shared/CmuxIrxTransport/Tests/CmuxIrxTransportTests/IrxStateLocationTests.swift, cmuxTests/MobileHostIrxSettingsMappingTests.swift, web/tests/iroh-dashboard-controller.test.ts
Mobile, web, reload, and transport defaults use cmux-v2 origins. The dashboard accepts both cmux-v2 and cmux-iroh-v2 origins. Related tests use the renamed endpoints.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant LegacyClient
  participant AliasWorker
  participant CanonicalWorker
  LegacyClient->>AliasWorker: Send request to former hostname
  AliasWorker->>CanonicalWorker: Forward request through CANONICAL.fetch
  CanonicalWorker-->>AliasWorker: Return response
  AliasWorker-->>LegacyClient: Return response
Loading

Merge Risk: ⚪ Minimal · up to d504b

Clients use the renamed Worker origins, while legacy hostnames continue forwarding and the deployment guard protects Workers that still have Durable Object bindings. No actionable merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to d504b

Legacy clients are intended to reach the same service and stored state through the old hostnames. The forwarding path retains the service’s authentication checks, but the alias deployment check cannot itself confirm that the renamed Workers still own the original storage. The reported live rename provides reassurance; its storage-identity evidence is not available here.

Retained concerns

  • Medium · security · inferred: The alias cutover verifies that canonical Workers have the expected storage classes, but not that those bindings retain the pre-rename namespace identities. If a canonical Worker were recreated rather than renamed in place, the check could expose old clients to fresh state, potentially losing stored registration or revocation history. This is a conditional rollout-control gap, not evidence that replacement occurred.
Security review details

Security Blast Radius

  • inferred — Both hostname families provide public ingress to the same per-environment canonical service. The possible storage-continuity impact reaches clients of an affected environment; the inspected alias configuration does not add a separate data store or grant a caller deployment authority.

Security Findings and Attack Paths

  • inferred — No direct unauthenticated path into a Durable Object is shown by the alias: it forwards attacker-supplied requests to existing canonical admission checks. The unresolved risk is an authorized but incorrect storage-identity cutover, not an established request-level exploit.

Trust Boundaries and Controls

  • observed — Deployment preflight requires the expected Cloudflare account and an API token, fails on settings errors, and refuses to replace an existing old Worker unless its only binding is the expected forwarding binding.

Resilience and Maintainability Implications

  • inferred — A partial alias rollout primarily threatens legacy-client availability in unfinished environments; the guard on existing storage-owning Workers limits destructive replacement. Neither property proves continuity of the canonical namespaces at the initial rename.

Hardening Proposals

  • proposed — Record and compare pre-rename and canonical namespace IDs for each environment before alias publication, and document how operators verify and resume an interrupted alias rollout.
🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 11.11% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 15 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: renaming the v2 Workers and preserving legacy hostnames.
Description check ✅ Passed The description provides a clear summary, implementation details, validation results, and the known runtime-suite limitation. It omits the template's explicit Testing, Demo Video, and Checklist sectio…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The diff changes Worker hostnames, dashboard origin allowlisting, and adds a fixed Cloudflare service-binding compatibility forwarder. It does not add per-request cmux-tui clients, event sockets…
Cmux Swift Actor Isolation ✅ Passed PASS: The Swift production diff changes only Worker URL string literals inside existing @MainActor methods. The existing Sendable structs, MobileHostV2Installation actor, and actor boundaries re…
Cmux Swift Blocking Runtime ✅ Passed PASS. The Swift diff only changes Worker hostname string literals in two production configuration files and matching test URLs. It adds no semaphores, blocking waits, sleeps, delayed dispatch, polling…
Cmux Browser Automation Off-Main ✅ Passed The pull request does not change either file in scope for this check: Sources/TerminalController.swift and `Packages/macOS/CmuxControlSocket/Sources/CmuxControlSocket/Wire/ControlCommandExecutionPol…
Cmux Expensive Synchronous Load ✅ Passed PASS: The pull request changes only Worker hostname string literals in the two production Swift files. The diff adds no agent-history loader, large-file parsing, directory scan, interactive-path call,…
Cmux Cache Substitution Correctness ✅ Passed The diff does not replace any authoritative read with a cache. Swift and TypeScript production changes only rename Worker URLs, update origin validation, and add a service-binding forwarding entrypoin…
Cmux No Hacky Sleeps ✅ Passed PASS. The diff introduces no hacky sleep, delayed dispatch, polling loop, or fixed lifecycle wait. The only new timing API is AbortSignal.timeout(15_000) in the Cloudflare settings request; it is a …
Cmux Algorithmic Complexity ✅ Passed No algorithmic-complexity violation is introduced. The production UI and controller changes only replace hostnames and extend a regex. The new alias worker forwards one request directly. The new verif…
Cmux Swift Concurrency ✅ Passed The Swift diff only changes Worker hostname string literals in two configuration files and related test fixtures. It adds no Dispatch queues/groups, Combine state, completion-handler APIs, or fire-and…
Cmux Swift @Concurrent ✅ Passed PASS. The Swift diff only replaces Worker hostname string literals in four files. It does not add or remove @concurrent, nonisolated, async, actor isolation, or call sites. Existing @MainActor…
Cmux Swift Package Boundaries ✅ Passed PASS: The Swift diff only renames Worker URL string literals in existing configuration code. The other Swift changes update test fixtures and expectations. It introduces no independently testable doma…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The PR changes no Package.swift, Package.resolved, .gitignore, workflow, or Xcode project files. The Swift changes are source and test edits only in existing package areas, so no SwiftPM depende…
Cmux Swift Logging ✅ Passed PASS. The Swift diff only changes Worker host strings in Sources/Mobile/MobileHostV2Installation.swift and updates matching test fixtures. The other Swift changes are test host updates. It adds or c…
Cmux User-Facing Error Privacy ✅ Passed The diff does not add a user-facing error that exposes prohibited details. The new compatibility Worker forwards requests to the canonical Worker, whose public error boundary emits only allowlisted er…
Cmux Full Internationalization ✅ Passed PASS. The diff changes Worker hostnames, protocol/config tokens, tests, compatibility scripts, comments, and operational documentation. It adds no Swift UI text, localization keys, string-catalog entr…
Cmux Swiftui State Layout ✅ Passed PASS. The reviewed Swift changes only rename Worker URL string literals in configuration and tests. They do not add or expand SwiftUI state, GeometryReader measurement, lazy/list row store references,…
Cmux Architecture Rethink ✅ Passed PASS. The Swift changes only replace legacy Worker hostname string literals in configuration and tests. The diff adds no timing repair, blocking, polling, locks, observers, mutable state, side channel…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS. The PR's four changed Swift files only update Worker host URL strings in configuration and tests. The diff adds no NSWindow, NSPanel, NSWindowController, SwiftUI Window, WindowGroup, close-short…
Cmux Source Artifacts ✅ Passed All 18 changed paths are intentional source, test, script, configuration, or documentation files. The added Worker alias entrypoint, deployment scripts, compatibility checks, and tests are product and…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS. The only changed Swift files under production Sources/ paths are Sources/Mobile/MobileHostV2Installation.swift and ios/cmuxPackage/Sources/cmuxFeature/MobileIrohV2Configuration.swift. Thei…
Full details: Docstring Coverage

Explanation

Docstring coverage is 11.11% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 15 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

teamleaderleo pushed a commit to teamleaderleo/cmux that referenced this pull request Sep 25, 2026
Target the existing canonical Workers, retain schema 6 on activation while reading v7, require verified staging and compatible rollback metadata, and require explicit Mac admission support. Canonical deployment names follow the existing rename work in manaflow-ai#13768.

Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Automatic catch-up: main is green again and this branch needed it.

I tried to catch this branch up with main (6f3af0a69ffb), but these files need a person:

  • workers/iroh-v2/README.md: not a generated file; needs a person
  • workers/iroh-v2/scripts/deploy-production.sh: not a generated file; needs a person

Nothing was pushed. Merge main locally, fix those, and push; /catch-up is there again whenever you want it.

Automatic catch-up will not try this head again; a new push or /catch-up does.
Label the pull request no-auto-catch-up to opt out.

Catch-up run

…ames

# Conflicts:
#	workers/iroh-v2/README.md
#	workers/iroh-v2/scripts/deploy-production.sh
@github-actions

Copy link
Copy Markdown
Contributor

Automatic catch-up couldn't merge main (e0263f46a669): web/app/[locale]/dashboard/mobile-devices/v2-dashboard-controller.ts (both sides changed the same lines). Nothing was pushed; merge it by hand. A new push or /catch-up tries again.

Label no-auto-catch-up to opt out · Catch-up run

@azooz2003-bit

Copy link
Copy Markdown
Collaborator Author

Superseded by the merged rename and compatibility work in #14936. Canonical Workers are now cmux-v2, cmux-v2-staging, and cmux-v2-development; the old cmux-iroh-v2 hostnames remain forwarding aliases for existing clients.

@github-project-automation github-project-automation Bot moved this from Todo to Done in cmux backlog Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants