Repository navigation
Keep unrelated file descriptors out of notification hooks - #14789
teamleaderleo wants to merge 4 commits into
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughNotification hooks now launch with ChangesNotification hook process isolation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The notification-hook descriptor isolation change is ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrows what notification hooks inherit from the app while preserving their standard input and output. No new security exposure was identified, but the available evidence does not establish complete end-to-end coverage. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Conflict with main's signal-mask reset resolved by Leo: flags are SETPGROUP | SETSIGMASK | CLOEXEC_DEFAULT. Co-authored-by: Leo <cheerleaderleo@outlook.com>
c1d3e63 to
87034e4
Compare
…14800) * test(ime): install option-as-alt right before the dead-key dispatch testOptionDeadKeyUsesGhosttyTranslationInsteadOfStartingComposition swapped a macos-option-as-alt = true config into GhosttyApp before creating its surface, then pumped the run loop for up to 5 s waiting for the surface. A configuration reload queued earlier in the shared test host (appearance sync, theme, settings) could run during that pump: #14789's failing log reads the theme and user config files mid-test, before the surface's io starts. The reload replaced the app config, so the surface was created without option-as-alt, Option was never stripped, and the assertion saw Option set. The config is now installed after the surface exists, on both the app and the live surface, with no run-loop turn before the synchronous keyDown dispatch, and restored right after it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(ime): restore the surface config while the surface is alive Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…shot (#14801) #14788 made the session policy drop phantom windows (no workspaces, no window Dock) on every save. TabManagerChildExitCloseTests still expected buildSessionSnapshot to keep a window whose only workspace is a non-restorable remote one, so it failed with a nil snapshot on every run that selects it (first seen on #14789 after merging main). Assert the new policy instead. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
Closing in favor of #11649, which landed the same fix with credit to @chapati23. |
Lands #11649 by @chapati23: notification hooks are spawned with
POSIX_SPAWN_CLOEXEC_DEFAULT, so they no longer inherit unrelated app file descriptors (an inherited pipe write end could keep a reader waiting until the hook timed out). The dup2 file actions still give the hook its stdin, stdout and stderr. Their two commits are kept; the only change is the conflict resolution, which keeps main's signal-mask reset and combines the flags asSETPGROUP | SETSIGMASK | CLOEXEC_DEFAULT.Includes their regression test (
NotificationHookProcessIsolationTests), which opens an unrelated pipe and checks the hook can't see it.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Notification hooks are now spawned with
POSIX_SPAWN_CLOEXEC_DEFAULT, so they no longer inherit unrelated app file descriptors. Previously an inherited pipe write end could keep a reader waiting until the hook timed out; the dup2 file actions still give the hook its stdin, stdout, and stderr. Adds a regression test that opens an unrelated pipe and verifies the hook cannot see it.Written for commit d2e9835. Summary will update on new commits.
Summary by CodeRabbit
Changelog
Fixed: Notification hooks no longer inherit unrelated app file descriptors.