Skip to content

ci: force relay rollover renewal in release gate - #15212

Merged
azooz2003-bit merged 1 commit into
mainfrom
fix-release-gate-renewal
Sep 28, 2026
Merged

azooz2003-bit merged 1 commit into
mainfrom
fix-release-gate-renewal

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The relay-only release gate runs a 330-second rollover probe, but its debug renewal interval was never forwarded to the simulator. Both staging and production therefore completed the one-hour soak and then failed before credential rollover.

The gate now requests renewal after 180 seconds for the relay-rollover scenario, and the mobile simulator launcher forwards that value into the app. Normal app launches do not set the variable and keep their production renewal schedule.

Validation

  • bash -n scripts/run-iroh-release-gate.sh scripts/mobile-dev-launch.sh
  • git diff --check
  • Staging and production runs 36384655451 and 36384655490 completed the 3,600-second workload, then exposed the missing renewal wiring.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes the relay-only release gate so credential rollover completes after the soak instead of failing.

The gate previously completed the one-hour soak without forwarding the debug renewal interval to the simulator, so staging and production then failed before credential rollover. The gate now requests renewal after 180 seconds for the relay-rollover scenario, and the mobile simulator launcher forwards that value. Normal launches leave it unset and keep the production renewal schedule.

Written for commit 32b23b3. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Mobile simulator launches now pass through the configured verification renewal interval, using a default when none is provided.
    • Release-gate runs use a 180-second interval for relay rollover scenarios; other scenarios continue without a specified interval.

@cursor

cursor Bot commented Sep 28, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 69a4619a-780d-4be3-98b3-0d91db8c89da

📥 Commits

Reviewing files that changed from the base of the PR and between 0bb41fa and 32b23b3.

📒 Files selected for processing (2)
  • scripts/mobile-dev-launch.sh
  • scripts/run-iroh-release-gate.sh

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

The simulator launcher forwards CMUX_IROH_V2_VERIFY_RENEW_INTERVAL_SECONDS. The release-gate launcher sets it to 180 seconds for relay_rollover and to an empty value for other scenarios.

Changes

Renewal interval launch configuration

Layer / File(s) Summary
Configure the renewal interval
scripts/mobile-dev-launch.sh, scripts/run-iroh-release-gate.sh
The simulator launch forwards the caller's value or an empty default. The release-gate launch uses 180 seconds for relay_rollover and an empty value for other scenarios.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: lawrencecchen

Merge Risk: ⚪ Minimal · up to 32b23

The relay-rollover gate receives the intended early renewal interval, and other scenarios retain their normal schedule. No actionable merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 32b23

The new timing control is limited to simulator launches, uses a fixed value in the relay-rollover gate, and is bounded by the app. The gate checks a rollover result. No attacker path or security regression was established, but successful operation after the change has not been demonstrated by the supplied validation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The independently controllable new path is a caller-authorized Debug simulator launch, potentially including one configured for production authentication. The checked gate invocation fixes the interval at 180 seconds; the evidence does not establish an unauthenticated route to that launcher or a change to release-build scheduling.

Trust Boundaries and Controls

  • observed — The simulator environment crosses into the app’s maintenance scheduler, but the app bounds the value and compiles the override only in DEBUG. The gate’s scenario selection supplies a fixed value rather than passing through an arbitrary interval.

Resilience and Maintainability Implications

  • observed — The gate fails when its relay-rollover report lacks required rollover or continuity results, limiting the chance that a completed soak alone is treated as a successful credential-rollover test.
🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the primary change: forcing relay rollover renewal in the release gate.
Description check ✅ Passed The description clearly explains the failure, resulting behavior, implementation, and validation commands. It uses a Validation heading instead of Testing and omits the Changelog, Checklist, and Demo …
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The pull request adds only two environment-variable forwards for the iOS Iroh relay rollover release gate. The diff does not create Cloud terminals, spawn cmux-tui clients or event sockets, add …
Cmux Swift Actor Isolation ✅ Passed The pull request changes only scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff contains no Swift files or Swift code, so it does not introduce or worsen Swift 6 actor is…
Cmux Swift Blocking Runtime ✅ Passed PASS: The pull request changes only two shell scripts. The authoritative diff contains no Swift files or Swift runtime code, so it does not introduce or expand the specified Swift blocking or timing s…
Cmux Browser Automation Off-Main ✅ Passed The pull request changes only two shell launch scripts. The added lines forward CMUX_IROH_V2_VERIFY_RENEW_INTERVAL_SECONDS to the simulator and set it for the relay rollover scenario. No browser.*…
Cmux Expensive Synchronous Load ✅ Passed PASS: The pull request changes only scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff contains no Swift changes and does not add or move any synchronous agent-history loa…
Cmux Cache Substitution Correctness ✅ Passed PASS: The review range changes only two shell scripts, scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. No Swift, TypeScript, or JavaScript files changed. The diff only forwards …
Cmux No Hacky Sleeps ✅ Passed The diff adds only environment-variable forwarding and sets 180 seconds for the relay-rollover renewal scenario. It adds no sleep, polling loop, timer, delayed dispatch, or wall-clock wait in the chan…
Cmux Algorithmic Complexity ✅ Passed PASS. The PR changes only two shell environment assignments. scripts/run-iroh-release-gate.sh:1000 selects a fixed interval with a scenario test, and scripts/mobile-dev-launch.sh:406 forwards the …
Cmux Swift Concurrency ✅ Passed PASS: The pull request changes only two shell scripts and adds two environment-variable assignments. It changes no cmux-owned Swift code and introduces no listed legacy Swift concurrency pattern.
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only two shell scripts. The authoritative diff contains no Swift files or Swift declarations, so .github/review-bot-rules/swift-concurrent-annotation.md does not apply…
Cmux Swift Package Boundaries ✅ Passed The pull request changes only two shell scripts: scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff contains no Swift production changes, so it cannot violate the Swift pa…
Cmux Swiftpm Lockfiles ✅ Passed The pull request changes only scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff contains no SwiftPM package, Xcode project, .gitignore, workflow, dependency, or `Packag…
Cmux Swift Logging ✅ Passed PASS: The pull request changes only two shell scripts, scripts/run-iroh-release-gate.sh and scripts/mobile-dev-launch.sh. The diff adds environment-variable forwarding and does not add or material…
Cmux User-Facing Error Privacy ✅ Passed PASS — the pull request adds only internal CI/launcher environment assignments. scripts/run-iroh-release-gate.sh sets the interval for the relay_rollover release-gate scenario, and `scripts/mobile…
Cmux Full Internationalization ✅ Passed PASS: The pull request changes only two shell launch scripts. It forwards the configuration variable CMUX_IROH_V2_VERIFY_RENEW_INTERVAL_SECONDS and sets it to 180 for the relay_rollover release-…
Cmux Swiftui State Layout ✅ Passed The pull request changes only scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff contains no Swift or SwiftUI changes, so the SwiftUI state-layout failure conditions do no…
Cmux Architecture Rethink ✅ Passed The check is not applicable to this diff. The PR changes only two shell scripts and adds environment-variable forwarding. It changes no Swift file and introduces no sleeps, delayed dispatch, polling, …
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The diff adds two shell environment assignments and contains no Swift or user-visible auxilia…
Cmux Source Artifacts ✅ Passed The diff changes only two existing hand-written shell scripts: scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. The additions forward and set an environment variable for the rele…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The pull request changes only two shell scripts, scripts/mobile-dev-launch.sh and scripts/run-iroh-release-gate.sh. It does not change any Swift file under a production Sources/ path, so t…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Dogfood build of 32b23b3d441168118cf6359b6f4d3a5a48bfa880

cmux DEV pr-15212-32b23b3d.app

The link opens this exact commit in the cmux dev menu bar app. The build starts on each push and the page waits until it is ready; a newer push replaces it. It signs in against production, so Cloud or backend changes still need a tagged build with a development backend.

@azooz2003-bit
azooz2003-bit merged commit 0e1ab96 into main Sep 28, 2026
67 checks passed
@azooz2003-bit
azooz2003-bit deleted the fix-release-gate-renewal branch September 28, 2026 08:04
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 32b23b3d44: every check was green at merge (16 verified; 16 skipped by policy). Full suite runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 28, 2026
1b55596 Move saved sessions between cmux installs: restore-session --from / --export (manaflow-ai#14861)
0e1ab96 ci: force relay rollover renewal in release gate (manaflow-ai#15212)
a3d6070 Fix Cloud projection reads mutating observation state (manaflow-ai#15126)
5171e34 docs: say Cloud turns on per Mac through a staged rollout (manaflow-ai#15194)
53395a8 Recover a missing team scope instead of failing Mac pairing (manaflow-ai#15083)
454f191 ci: read the gui backlog eight runs at a time in late placement (manaflow-ai#15207)
147a616 ci: cmux-tui's release-path macOS builds take the owned side lane first (manaflow-ai#15184)
c74b646 License the cmux server software under the Business Source License 1.1 (manaflow-ai#15206)
0bb41fa test: restore the first responder before the dictation paste test's Cmd+V (manaflow-ai#15201)
b17bc18 ui-tests: empty Diagnostics Reporter's queue before closing it (manaflow-ai#15189)
d5f71c5 ci: iOS picker charges runs by their live jobs, not their titles (manaflow-ai#15188)
3c2cb96 Pane focus memory and New Pane (Auto Layout) (manaflow-ai#15125)
89519d8 ci: expand an empty E2E -only-testing list under bash 3.2 (manaflow-ai#15208)
f225777 Ghostty config live reload: keep saves during a reload, reload a theme preview once, watch XDG_CONFIG_HOME (manaflow-ai#15191)
714ec53 ci: stop at a full disk on clonefile, and never nest a seed clone (manaflow-ai#15199)
48d662a ci: ui-tests dispatches UI tests with main's dispatcher (manaflow-ai#15193)
3412812 Restore the Cloud template terminal in place after a daemon restart (manaflow-ai#15200)

# Conflicts:
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci.yml
#	.github/workflows/cmux-tui-build-package.yml
#	.github/workflows/cmux-tui.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant