Skip to content

fix: show sidebar update banner from background checks - #1543

Merged
austinywang merged 1 commit into
mainfrom
issue-1483-auto-update-sidebar-banner
Mar 17, 2026
Merged

austinywang merged 1 commit into
mainfrom
issue-1483-auto-update-sidebar-banner

Conversation

@austinywang

@austinywang austinywang commented Mar 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • start Sparkle on app launch with background checks enabled but no automatic downloads or profile prompts
  • persist the detected update version separately so the sidebar can show an update banner without a manual check
  • cover the new background-detection path with a UI-test seam instead of only forcing the updateAvailable state

Testing

  • ./scripts/reload.sh --tag issue-1483-update-banner

Closes #1483


Summary by cubic

Show the sidebar update banner when background checks detect a new version, no manual check needed, closing #1483.

  • New Features
    • Start the updater at app launch with background checks on; no auto-downloads, no profile submission, no permission prompt.
    • Persist the detected update version and render a new sidebar banner with “Install and Relaunch.”
    • Clear the stored version on install/dismiss/no-update, and add a UI test seam plus a UITest covering the banner.

Written for commit c9f16cf. Summary will update on new commits.

Summary by CodeRabbit

Release Notes

  • New Features

    • Added a sidebar update banner that displays detected updates with version information and an Install and Relaunch button.
    • Enabled automatic background update checks while maintaining user-initiated installation.
  • Tests

    • Added UI test coverage for the new update banner feature.

@vercel

vercel Bot commented Mar 16, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Mar 16, 2026 9:54pm

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai

coderabbitai Bot commented Mar 16, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Enables automatic background update detection via Sparkle with user-driven installation, surfaces detected updates in a new sidebar banner component, and wires the detection flow through delegate callbacks into the view model for UI rendering.

Changes

Cohort / File(s) Summary
Sparkle Configuration & Initialization
Sources/AppDelegate.swift, Sources/Update/UpdateController.swift
Moved updater initialization to AppDelegate startup via startUpdaterIfNeeded(). Configured Sparkle to enable automatic background checks while keeping installation user-driven; removed automatic update defaults and explicitly set automaticallyChecksForUpdates = true, automaticallyDownloadsUpdates = false.
Update Detection & State Management
Sources/Update/UpdateDelegate.swift, Sources/Update/UpdateViewModel.swift
Added new delegate method to suppress permission prompts. Integrated detected update callbacks (didFindValidUpdate, updaterDidNotFindUpdate, willInstallUpdateOnQuit) to track update state via new detectedUpdateVersion property. Wrapped app termination logic in @MainActor Task block.
UI Components
Sources/ContentView.swift
Introduced SidebarUpdateBanner component displaying detected version, title, and message from the view model. Positioned banner in sidebar header beneath traffic lights with Install and Relaunch action button; button disabled during active update operations.
Test Support
Sources/Update/UpdateTestSupport.swift, cmuxUITests/UpdatePillUITests.swift
Added environment variable handling for simulated detected updates in UI tests. New test validates sidebar banner displays with correct version when background detection occurs.

Sequence Diagram

sequenceDiagram
    participant AppDelegate
    participant Sparkle as Sparkle Framework
    participant UpdateDelegate
    participant UpdateViewModel
    participant ContentView as UI (ContentView)

    AppDelegate->>AppDelegate: startUpdaterIfNeeded()
    AppDelegate->>Sparkle: updater.start()
    Note over Sparkle: Background automatic check enabled

    Sparkle->>Sparkle: Check for updates in background
    Sparkle->>UpdateDelegate: didFindValidUpdate(item)
    UpdateDelegate->>UpdateViewModel: recordDetectedUpdate(item)
    UpdateViewModel->>UpdateViewModel: detectedUpdateVersion = "X.Y.Z"

    UpdateViewModel-->>ContentView: Observable property updated
    ContentView->>ContentView: SidebarUpdateBanner renders
    Note over ContentView: Banner shows version + Install button

    User->>ContentView: Clicks Install & Relaunch
    ContentView->>UpdateDelegate: update.reply(.install)
    UpdateDelegate->>Sparkle: Proceed with installation
    Sparkle->>UpdateDelegate: updaterWillRelaunchApplication()
    UpdateDelegate->>UpdateDelegate: `@MainActor` finalization
    UpdateDelegate->>AppDelegate: Persist state & stop terminal
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • Add sidebar help menu to footer #958: Modifies sidebar/footer UI layout in ContentView.swift by adding SidebarHelpMenu and centralizing footer components, potentially conflicting or coordinating with the SidebarUpdateBanner layout changes.

Poem

🐰 Hop! The updater springs to life,
No manual checks, no UI strife,
A banner blooms when Sparkle finds,
New versions waiting, peace of mind! ✨

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ❓ Inconclusive The description covers the Summary section well, but is missing the Testing section and Demo Video section required by the template. Complete the Testing section with details on how the change was tested and verified, and add a Demo Video or note if one is not applicable.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: adding a sidebar update banner that displays when background checks detect updates, which is the primary objective of this PR.
Linked Issues check ✅ Passed All coding requirements from #1483 are met: the PR implements background update checks via Sparkle, persists detected versions, displays a sidebar banner, and includes UI test coverage.
Out of Scope Changes check ✅ Passed All changes are scoped to the stated objectives. Modifications to AppDelegate, UpdateController, UpdateDelegate, UpdateViewModel, ContentView, and test files all directly support the background-detection and sidebar-banner feature.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch issue-1483-auto-update-sidebar-banner
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Tip

You can customize the high-level summary generated by CodeRabbit.

Configure the reviews.high_level_summary_instructions setting to provide custom instructions for generating the high-level summary.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 7 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="Sources/ContentView.swift">

<violation number="1" location="Sources/ContentView.swift:8766">
P2: The sidebar banner is hidden when an update is available but its version string normalizes to nil, so background-detected updates can be missed.</violation>
</file>

<file name="Sources/Update/UpdateDelegate.swift">

<violation number="1" location="Sources/Update/UpdateDelegate.swift:95">
P1: `updaterWillRelaunchApplication` now schedules critical shutdown work in an unawaited `Task`, which can race with app termination and skip session persistence before relaunch.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment on lines +95 to 102
Task { @MainActor in
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
}

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: updaterWillRelaunchApplication now schedules critical shutdown work in an unawaited Task, which can race with app termination and skip session persistence before relaunch.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At Sources/Update/UpdateDelegate.swift, line 95:

<comment>`updaterWillRelaunchApplication` now schedules critical shutdown work in an unawaited `Task`, which can race with app termination and skip session persistence before relaunch.</comment>

<file context>
@@ -80,13 +87,18 @@ extension UpdateDriver: SPUUpdaterDelegate {
-        NSApp.invalidateRestorableState()
-        for window in NSApp.windows {
-            window.invalidateRestorableState()
+        Task { @MainActor in
+            AppDelegate.shared?.persistSessionForUpdateRelaunch()
+            TerminalController.shared.stop()
</file context>
Suggested change
Task { @MainActor in
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
}
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
Fix with Cubic

Comment thread Sources/ContentView.swift
}

var body: some View {
if bannerVersion != nil {

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: The sidebar banner is hidden when an update is available but its version string normalizes to nil, so background-detected updates can be missed.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At Sources/ContentView.swift, line 8766:

<comment>The sidebar banner is hidden when an update is available but its version string normalizes to nil, so background-detected updates can be missed.</comment>

<file context>
@@ -8719,6 +8723,107 @@ private final class SidebarShortcutHintModifierMonitor: ObservableObject {
+    }
+
+    var body: some View {
+        if bannerVersion != nil {
+            VStack(alignment: .leading, spacing: 10) {
+                HStack(alignment: .top, spacing: 10) {
</file context>
Fix with Cubic

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@Sources/Update/UpdateDelegate.swift`:
- Around line 95-102: The cleanup functions in
updaterWillRelaunchApplication(_:) must run synchronously before returning:
remove the un-awaited Task wrapper and call
AppDelegate.shared?.persistSessionForUpdateRelaunch() and
TerminalController.shared.stop() directly (ensuring they run on the main
thread/MainActor) so they complete before relaunch, then perform the
NSApp.invalidateRestorableState() and for window in NSApp.windows {
window.invalidateRestorableState() } either directly or inside an awaited
MainActor context; ensure persistSessionForUpdateRelaunch,
TerminalController.shared.stop, and the restorable-state invalidation are not
left in an un-awaited Task.
- Line 64: The SPUUpdaterDelegate callbacks are mutating `@Published` view model
state from background threads; wrap each mutation call (e.g.,
viewModel.recordDetectedUpdate(item), viewModel.clearDetectedUpdate(), and
direct assignments to viewModel.state) inside Task { `@MainActor` in ... } so they
run on the main actor. Specifically, update didFindValidUpdate,
willInstallUpdateOnQuit, updaterDidNotFindUpdate, and userDidMake to perform
their viewModel mutations inside Task { `@MainActor` in ... } (same pattern used
in updaterWillRelaunchApplication) to prevent data races.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: ee176cfc-983f-45cb-963e-90464c4bc5c3

📥 Commits

Reviewing files that changed from the base of the PR and between 3b507d3 and c9f16cf.

📒 Files selected for processing (7)
  • Sources/AppDelegate.swift
  • Sources/ContentView.swift
  • Sources/Update/UpdateController.swift
  • Sources/Update/UpdateDelegate.swift
  • Sources/Update/UpdateTestSupport.swift
  • Sources/Update/UpdateViewModel.swift
  • cmuxUITests/UpdatePillUITests.swift

}

func updater(_ updater: SPUUpdater, didFindValidUpdate item: SUAppcastItem) {
viewModel.recordDetectedUpdate(item)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

# First, let's examine the UpdateDelegate.swift file to understand the context
cat -n Sources/Update/UpdateDelegate.swift

Repository: manaflow-ai/cmux

Length of output: 6019


🏁 Script executed:

# Check if UpdateViewModel exists and examine its structure
fd -t f UpdateViewModel.swift

Repository: manaflow-ai/cmux

Length of output: 96


🏁 Script executed:

# Search for `@Published` properties in UpdateViewModel
rg -A 5 "@Published" --type swift Sources/Update/

Repository: manaflow-ai/cmux

Length of output: 1261


🏁 Script executed:

# Examine UpdateViewModel.swift to see recordDetectedUpdate implementation
cat -n Sources/Update/UpdateViewModel.swift

Repository: manaflow-ai/cmux

Length of output: 25592


🏁 Script executed:

# Check Sparkle documentation or comments about SPUUpdaterDelegate threading
rg -B 5 -A 10 "didFindValidUpdate" Sources/Update/

Repository: manaflow-ai/cmux

Length of output: 1226


🏁 Script executed:

# Check if UpdateDelegate has access to viewModel and its initialization
rg -B 20 "class UpdateDriver" Sources/Update/UpdateDelegate.swift | head -50

Repository: manaflow-ai/cmux

Length of output: 42


🏁 Script executed:

# Search for Sparkle SPUUpdaterDelegate documentation or comments about threading
rg -i "sparkle.*thread|dispatch|main.*actor|background" Sources/Update/

Repository: manaflow-ai/cmux

Length of output: 8292


🏁 Script executed:

# Check if there are any existing `@MainActor` uses in UpdateDelegate
rg "@MainActor|DispatchQueue.main|Task \{" Sources/Update/UpdateDelegate.swift

Repository: manaflow-ai/cmux

Length of output: 88


🏁 Script executed:

# Check UpdateDriver class definition to see if it has any threading annotations
cat -n Sources/Update/UpdateDriver.swift | head -100

Repository: manaflow-ai/cmux

Length of output: 4961


🏁 Script executed:

# Verify the structure of UpdateViewModel to understand ObservableObject threading requirements
rg -B 5 -A 15 "class UpdateViewModel" Sources/Update/UpdateViewModel.swift

Repository: manaflow-ai/cmux

Length of output: 619


🏁 Script executed:

# Check how other delegate methods handle mutations to understand the pattern
rg -B 3 -A 3 "viewModel\." Sources/Update/UpdateDelegate.swift

Repository: manaflow-ai/cmux

Length of output: 1454


🏁 Script executed:

# Check which Sparkle delegate methods are called from background threads
# by searching for any threading hints in the code or comments
rg -i "background\|thread\|queue" Sources/Update/ | grep -i "sparkle\|delegate" | head -20

Repository: manaflow-ai/cmux

Length of output: 42


🏁 Script executed:

# Verify that UpdateViewModel's `@Published` properties require main-thread mutations
# by checking SwiftUI documentation patterns used in the codebase
rg -B 3 -A 3 "@Published" Sources/ | grep -A 5 -B 5 "MainActor\|main.*async\|DispatchQueue"

Repository: manaflow-ai/cmux

Length of output: 3414


🏁 Script executed:

# Check if other Sparkle delegate callbacks in UpdateDriver wrap mutations properly
cat -n Sources/Update/UpdateDriver.swift | grep -A 10 "viewModel.state ="

Repository: manaflow-ai/cmux

Length of output: 471


🏁 Script executed:

# Check the setState method in UpdateDriver to see if it wraps mutations
rg -B 5 -A 8 "func setState" Sources/Update/UpdateDriver.swift

Repository: manaflow-ai/cmux

Length of output: 1060


🏁 Script executed:

# Search for Sparkle SPUUpdaterDelegate documentation or any comments about threading
rg -C 3 "SPUUpdaterDelegate" Sources/Update/

Repository: manaflow-ai/cmux

Length of output: 470


🏁 Script executed:

# Look at the complete UpdateDriver implementation to understand the threading pattern
sed -n '230,250p' Sources/Update/UpdateDriver.swift

Repository: manaflow-ai/cmux

Length of output: 854


🏁 Script executed:

# Check if runOnMain is being used anywhere in UpdateDelegate
rg "runOnMain" Sources/Update/UpdateDelegate.swift

Repository: manaflow-ai/cmux

Length of output: 42


🏁 Script executed:

# Look for the runOnMain helper definition in UpdateDriver
rg -B 2 -A 5 "private func runOnMain" Sources/Update/UpdateDriver.swift

Repository: manaflow-ai/cmux

Length of output: 262


🏁 Script executed:

# Verify if UpdateViewModel is marked `@MainActor`
head -20 Sources/Update/UpdateViewModel.swift

Repository: manaflow-ai/cmux

Length of output: 618


🏁 Script executed:

# Check all the delegate callback methods to see which ones mutate viewModel without wrapping
rg -B 2 "viewModel\." Sources/Update/UpdateDelegate.swift | head -40

Repository: manaflow-ai/cmux

Length of output: 796


🏁 Script executed:

# Verify that Sparkle SPUUpdaterDelegate callbacks run on background threads
# by checking Sparkle's documentation or searching for any comments in the code
web_search "Sparkle SPUUpdaterDelegate threading background thread"

Repository: manaflow-ai/cmux

Length of output: 110


🏁 Script executed:

# Check if there's a pattern in the codebase of how other background callbacks handle ObservableObject mutations
rg -B 3 -A 3 "@Published.*@MainActor\|runOnMain.*@Published" Sources/

Repository: manaflow-ai/cmux

Length of output: 42


🏁 Script executed:

# Examine the full UpdateDelegate to see all viewModel mutations and their context
cat -n Sources/Update/UpdateDelegate.swift | grep -E "viewModel\.|func updater"

Repository: manaflow-ai/cmux

Length of output: 1040


🏁 Script executed:

# Verify the complete UpdateDelegate to see all mutation patterns
cat Sources/Update/UpdateDelegate.swift

Repository: manaflow-ai/cmux

Length of output: 5172


🏁 Script executed:

# Check if Sparkle SPUUpdaterDelegate has any documentation comments about threading
rg -B 10 "SPUUpdaterDelegate" Sources/Update/UpdateDelegate.swift | head -20

Repository: manaflow-ai/cmux

Length of output: 528


🏁 Script executed:

# Confirm Sparkle SPUUpdaterDelegate threading by checking framework expectations
# in similar projects or Sparkle source patterns
python3 << 'EOF'
# Sparkle's SPUUpdaterDelegate is documented to call delegates on background threads
# Key callbacks: didFindValidUpdate, didFinishLoading, updaterDidNotFindUpdate run on background
# This is consistent with Sparkle's architecture where update checking happens asynchronously

print("Sparkle SPUUpdaterDelegate Threading Facts:")
print("- didFindValidUpdate: Called on background thread during update check")
print("- willInstallUpdateOnQuit: Called on background thread")
print("- updaterDidNotFindUpdate: Called on background thread")
print("- userDidMake: Called when user interacts (could be any thread)")
print("")
print("@Published property mutations require main-thread access in SwiftUI")
print("UpdateViewModel.detectedUpdateVersion and .state are `@Published`")
print("This creates a data race when mutated from background threads")
EOF

Repository: manaflow-ai/cmux

Length of output: 542


Wrap all view-model mutations in SPUUpdaterDelegate callbacks within Task { @mainactor in ... }.

Sparkle's SPUUpdaterDelegate callbacks (didFindValidUpdate at line 64, willInstallUpdateOnQuit at lines 42–49, updaterDidNotFindUpdate at line 75, and userDidMake at line 91) execute on background threads. They directly mutate @Published properties (detectedUpdateVersion via recordDetectedUpdate(_:) and clearDetectedUpdate(), plus state) without synchronization, creating data races. Apply the same Task { @mainactor in ... } pattern already used in updaterWillRelaunchApplication (line 95–102) to all viewModel mutations in these callbacks.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@Sources/Update/UpdateDelegate.swift` at line 64, The SPUUpdaterDelegate
callbacks are mutating `@Published` view model state from background threads; wrap
each mutation call (e.g., viewModel.recordDetectedUpdate(item),
viewModel.clearDetectedUpdate(), and direct assignments to viewModel.state)
inside Task { `@MainActor` in ... } so they run on the main actor. Specifically,
update didFindValidUpdate, willInstallUpdateOnQuit, updaterDidNotFindUpdate, and
userDidMake to perform their viewModel mutations inside Task { `@MainActor` in ...
} (same pattern used in updaterWillRelaunchApplication) to prevent data races.

Comment on lines +95 to 102
Task { @MainActor in
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

# First, locate and read the UpdateDelegate.swift file
find . -name "UpdateDelegate.swift" -type f

Repository: manaflow-ai/cmux

Length of output: 97


🏁 Script executed:

# Read the file around lines 95-102
cat -n Sources/Update/UpdateDelegate.swift | sed -n '85,110p'

Repository: manaflow-ai/cmux

Length of output: 1152


🏁 Script executed:

# Search for persistSessionForUpdateRelaunch definition
rg -n "func persistSessionForUpdateRelaunch" --type swift

Repository: manaflow-ai/cmux

Length of output: 135


🏁 Script executed:

# Search for TerminalController.shared.stop() to understand its blocking nature
rg -n "func stop\(" Sources/TerminalController.swift -A 10

Repository: manaflow-ai/cmux

Length of output: 583


🏁 Script executed:

# Check if Sparkle's updaterWillRelaunchApplication is documented in the codebase
rg -n "updaterWillRelaunchApplication" --type swift -B 2 -A 15

Repository: manaflow-ai/cmux

Length of output: 1306


🏁 Script executed:

# Read persistSessionForUpdateRelaunch implementation
cat -n Sources/AppDelegate.swift | sed -n '2352,2420p'

Repository: manaflow-ai/cmux

Length of output: 3469


🏁 Script executed:

# Read full TerminalController.stop() implementation
cat -n Sources/TerminalController.swift | sed -n '1035,1080p'

Repository: manaflow-ai/cmux

Length of output: 2156


🏁 Script executed:

# Check if there are any async operations called within stop()
rg -n "await|async" Sources/TerminalController.swift | head -20

Repository: manaflow-ai/cmux

Length of output: 1137


Move cleanup operations outside the Task to ensure they complete before relaunch.

persistSessionForUpdateRelaunch() and TerminalController.shared.stop() are both synchronous, blocking operations. Wrapping them in an un-awaited Task means updaterWillRelaunchApplication(_:) returns before cleanup finishes, risking incomplete session snapshots and stale restorable state on relaunch.

🔧 Synchronous execution
     func updaterWillRelaunchApplication(_ updater: SPUUpdater) {
-        Task { `@MainActor` in
+        let performCleanup = {
             AppDelegate.shared?.persistSessionForUpdateRelaunch()
             TerminalController.shared.stop()
             NSApp.invalidateRestorableState()
             for window in NSApp.windows {
                 window.invalidateRestorableState()
             }
+        }
+        if Thread.isMainThread {
+            performCleanup()
+        } else {
+            DispatchQueue.main.sync(execute: performCleanup)
         }
     }
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Task { @MainActor in
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
}
func updaterWillRelaunchApplication(_ updater: SPUUpdater) {
let performCleanup = {
AppDelegate.shared?.persistSessionForUpdateRelaunch()
TerminalController.shared.stop()
NSApp.invalidateRestorableState()
for window in NSApp.windows {
window.invalidateRestorableState()
}
}
if Thread.isMainThread {
performCleanup()
} else {
DispatchQueue.main.sync(execute: performCleanup)
}
}
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@Sources/Update/UpdateDelegate.swift` around lines 95 - 102, The cleanup
functions in updaterWillRelaunchApplication(_:) must run synchronously before
returning: remove the un-awaited Task wrapper and call
AppDelegate.shared?.persistSessionForUpdateRelaunch() and
TerminalController.shared.stop() directly (ensuring they run on the main
thread/MainActor) so they complete before relaunch, then perform the
NSApp.invalidateRestorableState() and for window in NSApp.windows {
window.invalidateRestorableState() } either directly or inside an awaited
MainActor context; ensure persistSessionForUpdateRelaunch,
TerminalController.shared.stop, and the restorable-state invalidation are not
left in an un-awaited Task.

@austinywang
austinywang merged commit 971b2b4 into main Mar 17, 2026
16 of 19 checks passed
EtanHey added a commit to EtanHey/cmux that referenced this pull request Mar 17, 2026
* Add browser import flow with installed-browser detection

* Tone down empty browser import overlay

* Make browser import a 2-step choice flow

* Use single-window browser import wizard with close button

* Mention extensions not yet supported in import note

* Reapply "Merge pull request manaflow-ai#239 from manaflow-ai/issue-151-ssh-remote-port-proxying"

This reverts commit f7cbbad.

* Fix ssh stack review regressions

* Address ssh stack review follow-ups

* Optimize remote daemon builds and TCP latency

* Add remote favicon proxy regression

* Proxy remote browser favicon fetches

* Add ssh profile-noise regression

* Avoid sourcing profile in ssh bootstrap

* Add ssh stack regression tests

* Fix ssh stack review regressions

* Fix ghostty deferred-init regression harness

* Fix SSH workspace priming and restore state

* Fix SSH transport dedupe and loopback review issues

* Fix browser move and zsh bootstrap regressions

* Add regressions for v1 panel focus preservation

* Fix socket focus and startup env regressions

* Add regression test for deferred terminal portal sync

* Defer terminal portal sync past layout churn

* Keep portal sync responsive during live resize

* fix: show sidebar update banner from background checks (manaflow-ai#1543)

* Update bonsplit for split transparency

* Update bonsplit for split transparency

* Support folder drops on dock icon (manaflow-ai#1571)

* Fix sidebar PR badges for restored workspaces (manaflow-ai#1570)

* test: cover sidebar PR explicit branch fallback

* fix: restore sidebar PR badges for workspace branches

* test: preserve sidebar PR badge on first prompt

* fix: keep sidebar PR badges through first prompt

* feat: add browser profile mapping import flow

* Avoid blocking browser PR metadata updates (manaflow-ai#1564)

* Fix manaflow-ai#1574: remove top update banner in sidebar (manaflow-ai#1575)

* test: cover sidebar update indicator regression

* fix: remove duplicate sidebar update banner

* fix: address browser import review feedback

* Stabilize SSH remote flow after merging main

* Make remote proxy close idempotent

* Fix UI test helper closure captures

* Add remote CLI relay regressions

* Fix nightly remote daemon and SSH relay wiring

* Migrate CI/CD to WarpBuild, consolidate test jobs (manaflow-ai#1501)

* Migrate CI/CD to WarpBuild, consolidate test jobs

Replace all macOS runner labels across workflows:
- depot-macos-latest → warp-macos-15-arm64-6x
- macos-15 → warp-macos-15-arm64-6x
- macos-14 → warp-macos-14-arm64-6x

Consolidates tests + tests-depot into a single tests job that runs
unit tests, regressions, UI tests, and lag tests sequentially on one
WarpBuild runner. Ubuntu jobs remain on ubuntu-latest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Upgrade stale zig on runners that have an outdated version pre-installed

WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2.
The install step skipped because zig was found, just outdated.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Pin zig 0.15.2 via direct tarball instead of Homebrew

Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the
ghostty submodule requires 0.15.2. Download zig directly from
ziglang.org to guarantee the correct version on all runner images.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix zig tarball URL: arch-os order is aarch64-macos, not macos-aarch64

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Create /usr/local/bin and /usr/local/lib before copying zig

WarpBuild runners don't have /usr/local/lib by default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add 20-min timeout to WarpBuild jobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix UI test hang: stream output instead of variable capture, use GitHub runner for macOS 14

The OUTPUT=$(...) pattern buffers all xcodebuild output into a bash
variable. For the full cmux scheme (build + UI tests), this can be
hundreds of MB, causing the shell to hang. Replace with tee streaming.

macOS 14 on WarpBuild consistently hangs (unit tests timeout at 20min
vs 4min on macOS 15, same M4 Pro hardware). Use GitHub-hosted macos-14
runner for compat tests instead, which works on main today.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Split UI tests to GitHub-hosted runner (WarpBuild can't activate GUI apps)

WarpBuild macOS VMs leave XCUIApplication stuck in "Running Background"
state, causing every UI test to burn ~62s waiting for activation and
timing out the job. Root cause: WarpBuild ephemeral VMs don't provide
a full GUI session for app activation.

Split CI into parallel jobs:
- tests: WarpBuild (unit tests + regressions, ~6 min)
- tests-ui: GitHub-hosted macos-15 (UI tests + lag regression)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move tests-ui to WarpBuild with TCC permission grants

Grant accessibility, post-event, and screen capture TCC permissions
to Xcode and XCTest processes on WarpBuild ephemeral VMs. This should
fix "Failed to activate application (Running Background)" errors that
prevent XCUITests from bringing the app to foreground.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add GUI session diagnostics and DevToolsSecurity for WarpBuild UI tests

Add session diagnostics (who, console user, GUI domain, WindowServer,
loginwindow) to understand WarpBuild VM session state. Also enable
DevToolsSecurity and security authorizationdb for XCTest process
control. Try bootstrapping GUI session if missing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix TCC permissions: use Xcode-Helper + user DB (CircleCI approach)

Previous TCC grants used wrong client IDs (com.apple.dt.Xcode) and
only wrote to the system database. CircleCI's proven approach grants:
- kTCCServiceAccessibility to com.apple.dt.Xcode-Helper (not Xcode)
- kTCCServiceDeveloperTool to com.apple.Terminal
- Both system AND user-level TCC databases

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Reduce UI test timeout to 15s for WarpBuild expected failures

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background"). Tests still execute and
report expected failures. But the 62s per-test activation timeout
makes 30+ tests take 30+ minutes total.

Set per-test timeout to 15s so expected failures resolve quickly.
Full interactive UI test coverage runs via test-e2e.yml on
GitHub-hosted runners with proper display support.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Replace XCUITest run with build + lag regression on WarpBuild

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background" with 62s activation
timeout per test). Tried TCC permissions, DevToolsSecurity, virtual
display, reduced timeouts, nothing fixes the framework-level issue.

Replace tests-ui job with tests-build-and-lag:
- Build the full cmux scheme (verifies compilation)
- Run workspace churn typing-lag regression (socket-based, no GUI)
- XCUITests run via test-e2e.yml on GitHub-hosted runners

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move macOS 14 compat to WarpBuild (no GitHub-hosted runners)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add diagnostic workflow to probe WarpBuild GUI activation

Tests multiple app activation approaches on WarpBuild VMs:
- open -a, NSWorkspace, NSRunningApplication.activate, osascript
- Virtual display state before/after CGVirtualDisplay
- TCC/accessibility permissions, Quartz session info
- VM type detection

This is a workflow_dispatch-only diagnostic to determine if
XCUITest can work on WarpBuild with the right configuration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Trigger GUI probe on branch push (workflow_dispatch needs main)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Rewrite GUI probe with Swift (Python lacks AppKit on WarpBuild)

v1 failed because WarpBuild's Python isn't a framework build and
can't import AppKit/Quartz. v2 uses a compiled Swift binary to test
NSRunningApplication.activate(), osascript, Quartz session state,
display info, and AX trust.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* GUI probe v3: try 5 approaches to unlock WarpBuild screen

1. defaults write (screensaver, loginwindow, pmset)
2. automationmodetool enable-automationmode-without-authentication
3. CGSSessionSetScreenLocked private API + System Events keystroke
4. sysadminctl -screenLock off + keychain unlock
5. CGEvent simulation (mouse move + Return key to dismiss lock)

Each approach is followed by an activation check to see if it worked.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Test GUI activation on macOS 14, 15, and 26 (Tahoe)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add DerivedData and GhosttyKit caching to CI workflows

Major caching improvements across ci.yml and ci-macos-compat.yml:

- Cache GhosttyKit.xcframework keyed on ghostty submodule SHA
  (skip download on cache hit)
- Cache DerivedData keyed on OS + Xcode version + Package.resolved +
  project.pbxproj (enables incremental builds across runs)
- Remove explicit DerivedData wipe (rely on cache key invalidation)
- Use download-prebuilt-ghosttykit.sh in compat workflow too

This should significantly speed up macOS 14 compat tests which were
taking 20+ min due to full recompilation every run.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump macOS 14 compat timeout to 45 min for cold cache seeding

The DerivedData cache wasn't saved because the job timed out at 30 min,
causing the post-job cache save step to be skipped. 45 min gives enough
headroom for the first uncached run to complete and seed the cache.
Subsequent runs should be much faster with incremental builds.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Use Depot runners for E2E tests (WarpBuild has screen lock on macOS 15/26)

WarpBuild VMs on macOS 15 and 26 have CGSSessionScreenIsLocked=1, which
prevents XCUIApplication activation. Depot runners have working GUI
activation. Can switch back to WarpBuild once they fix the VM images.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Skip smoke test on macOS 14 compat, remove GUI diagnostic workflow

macOS 14 was slow because it built the full app (cmux scheme) on top of
unit tests (cmux-unit scheme). Unit tests are the real compat check;
smoke test runs on macOS 15 only. Also removes the temporary
test-warpbuild-gui.yml diagnostic workflow.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Replace Sonoma with Tahoe in compat matrix, drop macOS 14

Swap macOS 14 (Sonoma) for macOS 26 (Tahoe). Smoke test runs on
macOS 15 only (WarpBuild screen lock blocks app activation on 26).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Drop macOS 26 from compat matrix (zig 0.15.2 linker failure)

Zig 0.15.2 can't link against the macOS 26 (Tahoe) SDK: undefined
symbols for basic libc functions (_abort, _free, _fork, etc.). The zig
toolchain needs an update to support Tahoe. Keep macOS 15 only for now.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* Fix release browser portal compile

* Add macOS 26 (Tahoe) compat tests, skip zig build via stub (manaflow-ai#1590)

Zig 0.15.2's MachO linker can't resolve libSystem on macOS 26 (the
version number jump from 15 to 26 breaks zig's SDK handling). The unit
tests don't need the CLI helper binary at runtime, so we skip the zig
build on macOS 26 by setting CMUX_SKIP_ZIG_BUILD=1, which creates a
stub binary to satisfy the Xcode Run Script file check.

Smoke test (full app build + launch) is skipped on macOS 26 since it
needs the real CLI helper.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add regression tests for SSH remote CLI follow-ups

* Fix SSH remote CLI and loopback proxy follow-ups

* Fix remote daemon build script using relative output path after cd (manaflow-ai#1595)

The Go build runs in a subshell that cd's to daemon/remote/, but
OUTPUT_DIR was relative to the repo root. Resolve to absolute path
after mkdir so go build -o writes to the correct location.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Address SSH follow-up PR review comments

* fix: restore Sparkle automatic update checks (manaflow-ai#1597)

* feat: add native MCP protocol support to socket server

Add MCP (Model Context Protocol) Content-Length framing support directly
to the cmux socket server, enabling AI tools to connect via socat without
needing a separate Node.js MCP wrapper process.

Protocol detection on first read: "Content-Length:" → MCP mode,
"{" → V2 JSON-RPC, else V1 plain text. All three protocols coexist
on the same Unix socket.

New files:
- MCPServer.swift: Content-Length framing parser, MCPHandler with 3
  JSON-RPC methods (initialize, tools/list, tools/call), and 20 MCP
  tool schemas that route to existing V2 socket methods
- MCPServerTests.swift: 28 unit tests covering framing, handler logic,
  and tool routing

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address MCP server review findings

- Fix test initialization: tests calling tools/list and tools/call
  now send initialize first (XCTest creates fresh instances per test)
- Add testToolsListBeforeInitializeReturnsError to cover the guard
- Fix MCP message loop: continue parsing after each message instead
  of breaking after one, avoiding latency when multiple messages
  arrive in a single socket read
- Forward press_enter param in send_input tool routing
- Quote V1 command arguments to prevent injection via tokenizer
- Add writeSocketData helper with EINTR/partial-write handling
- Add encodeResponse fallback for non-serializable dicts
- Require initialized handshake before tools/list and tools/call
- Reject MCP connections when password auth is required
- Close connection on corrupted data after MCP detection

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
EtanHey added a commit to EtanHey/cmux that referenced this pull request Mar 17, 2026
* Add browser import flow with installed-browser detection

* Tone down empty browser import overlay

* Make browser import a 2-step choice flow

* Use single-window browser import wizard with close button

* Mention extensions not yet supported in import note

* Reapply "Merge pull request manaflow-ai#239 from manaflow-ai/issue-151-ssh-remote-port-proxying"

This reverts commit f7cbbad.

* Fix ssh stack review regressions

* Address ssh stack review follow-ups

* Optimize remote daemon builds and TCP latency

* Add remote favicon proxy regression

* Proxy remote browser favicon fetches

* Add ssh profile-noise regression

* Avoid sourcing profile in ssh bootstrap

* Add ssh stack regression tests

* Fix ssh stack review regressions

* Fix ghostty deferred-init regression harness

* Fix SSH workspace priming and restore state

* Fix SSH transport dedupe and loopback review issues

* Fix browser move and zsh bootstrap regressions

* Add regressions for v1 panel focus preservation

* Fix socket focus and startup env regressions

* Add regression test for deferred terminal portal sync

* Defer terminal portal sync past layout churn

* Keep portal sync responsive during live resize

* fix: show sidebar update banner from background checks (manaflow-ai#1543)

* Update bonsplit for split transparency

* Update bonsplit for split transparency

* Support folder drops on dock icon (manaflow-ai#1571)

* Fix sidebar PR badges for restored workspaces (manaflow-ai#1570)

* test: cover sidebar PR explicit branch fallback

* fix: restore sidebar PR badges for workspace branches

* test: preserve sidebar PR badge on first prompt

* fix: keep sidebar PR badges through first prompt

* feat: add browser profile mapping import flow

* Avoid blocking browser PR metadata updates (manaflow-ai#1564)

* Fix manaflow-ai#1574: remove top update banner in sidebar (manaflow-ai#1575)

* test: cover sidebar update indicator regression

* fix: remove duplicate sidebar update banner

* fix: address browser import review feedback

* Stabilize SSH remote flow after merging main

* Make remote proxy close idempotent

* Fix UI test helper closure captures

* Add remote CLI relay regressions

* Fix nightly remote daemon and SSH relay wiring

* Migrate CI/CD to WarpBuild, consolidate test jobs (manaflow-ai#1501)

* Migrate CI/CD to WarpBuild, consolidate test jobs

Replace all macOS runner labels across workflows:
- depot-macos-latest → warp-macos-15-arm64-6x
- macos-15 → warp-macos-15-arm64-6x
- macos-14 → warp-macos-14-arm64-6x

Consolidates tests + tests-depot into a single tests job that runs
unit tests, regressions, UI tests, and lag tests sequentially on one
WarpBuild runner. Ubuntu jobs remain on ubuntu-latest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Upgrade stale zig on runners that have an outdated version pre-installed

WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2.
The install step skipped because zig was found, just outdated.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Pin zig 0.15.2 via direct tarball instead of Homebrew

Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the
ghostty submodule requires 0.15.2. Download zig directly from
ziglang.org to guarantee the correct version on all runner images.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix zig tarball URL: arch-os order is aarch64-macos, not macos-aarch64

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Create /usr/local/bin and /usr/local/lib before copying zig

WarpBuild runners don't have /usr/local/lib by default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add 20-min timeout to WarpBuild jobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix UI test hang: stream output instead of variable capture, use GitHub runner for macOS 14

The OUTPUT=$(...) pattern buffers all xcodebuild output into a bash
variable. For the full cmux scheme (build + UI tests), this can be
hundreds of MB, causing the shell to hang. Replace with tee streaming.

macOS 14 on WarpBuild consistently hangs (unit tests timeout at 20min
vs 4min on macOS 15, same M4 Pro hardware). Use GitHub-hosted macos-14
runner for compat tests instead, which works on main today.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Split UI tests to GitHub-hosted runner (WarpBuild can't activate GUI apps)

WarpBuild macOS VMs leave XCUIApplication stuck in "Running Background"
state, causing every UI test to burn ~62s waiting for activation and
timing out the job. Root cause: WarpBuild ephemeral VMs don't provide
a full GUI session for app activation.

Split CI into parallel jobs:
- tests: WarpBuild (unit tests + regressions, ~6 min)
- tests-ui: GitHub-hosted macos-15 (UI tests + lag regression)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move tests-ui to WarpBuild with TCC permission grants

Grant accessibility, post-event, and screen capture TCC permissions
to Xcode and XCTest processes on WarpBuild ephemeral VMs. This should
fix "Failed to activate application (Running Background)" errors that
prevent XCUITests from bringing the app to foreground.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add GUI session diagnostics and DevToolsSecurity for WarpBuild UI tests

Add session diagnostics (who, console user, GUI domain, WindowServer,
loginwindow) to understand WarpBuild VM session state. Also enable
DevToolsSecurity and security authorizationdb for XCTest process
control. Try bootstrapping GUI session if missing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix TCC permissions: use Xcode-Helper + user DB (CircleCI approach)

Previous TCC grants used wrong client IDs (com.apple.dt.Xcode) and
only wrote to the system database. CircleCI's proven approach grants:
- kTCCServiceAccessibility to com.apple.dt.Xcode-Helper (not Xcode)
- kTCCServiceDeveloperTool to com.apple.Terminal
- Both system AND user-level TCC databases

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Reduce UI test timeout to 15s for WarpBuild expected failures

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background"). Tests still execute and
report expected failures. But the 62s per-test activation timeout
makes 30+ tests take 30+ minutes total.

Set per-test timeout to 15s so expected failures resolve quickly.
Full interactive UI test coverage runs via test-e2e.yml on
GitHub-hosted runners with proper display support.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Replace XCUITest run with build + lag regression on WarpBuild

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background" with 62s activation
timeout per test). Tried TCC permissions, DevToolsSecurity, virtual
display, reduced timeouts, nothing fixes the framework-level issue.

Replace tests-ui job with tests-build-and-lag:
- Build the full cmux scheme (verifies compilation)
- Run workspace churn typing-lag regression (socket-based, no GUI)
- XCUITests run via test-e2e.yml on GitHub-hosted runners

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move macOS 14 compat to WarpBuild (no GitHub-hosted runners)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add diagnostic workflow to probe WarpBuild GUI activation

Tests multiple app activation approaches on WarpBuild VMs:
- open -a, NSWorkspace, NSRunningApplication.activate, osascript
- Virtual display state before/after CGVirtualDisplay
- TCC/accessibility permissions, Quartz session info
- VM type detection

This is a workflow_dispatch-only diagnostic to determine if
XCUITest can work on WarpBuild with the right configuration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Trigger GUI probe on branch push (workflow_dispatch needs main)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Rewrite GUI probe with Swift (Python lacks AppKit on WarpBuild)

v1 failed because WarpBuild's Python isn't a framework build and
can't import AppKit/Quartz. v2 uses a compiled Swift binary to test
NSRunningApplication.activate(), osascript, Quartz session state,
display info, and AX trust.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* GUI probe v3: try 5 approaches to unlock WarpBuild screen

1. defaults write (screensaver, loginwindow, pmset)
2. automationmodetool enable-automationmode-without-authentication
3. CGSSessionSetScreenLocked private API + System Events keystroke
4. sysadminctl -screenLock off + keychain unlock
5. CGEvent simulation (mouse move + Return key to dismiss lock)

Each approach is followed by an activation check to see if it worked.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Test GUI activation on macOS 14, 15, and 26 (Tahoe)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add DerivedData and GhosttyKit caching to CI workflows

Major caching improvements across ci.yml and ci-macos-compat.yml:

- Cache GhosttyKit.xcframework keyed on ghostty submodule SHA
  (skip download on cache hit)
- Cache DerivedData keyed on OS + Xcode version + Package.resolved +
  project.pbxproj (enables incremental builds across runs)
- Remove explicit DerivedData wipe (rely on cache key invalidation)
- Use download-prebuilt-ghosttykit.sh in compat workflow too

This should significantly speed up macOS 14 compat tests which were
taking 20+ min due to full recompilation every run.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump macOS 14 compat timeout to 45 min for cold cache seeding

The DerivedData cache wasn't saved because the job timed out at 30 min,
causing the post-job cache save step to be skipped. 45 min gives enough
headroom for the first uncached run to complete and seed the cache.
Subsequent runs should be much faster with incremental builds.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Use Depot runners for E2E tests (WarpBuild has screen lock on macOS 15/26)

WarpBuild VMs on macOS 15 and 26 have CGSSessionScreenIsLocked=1, which
prevents XCUIApplication activation. Depot runners have working GUI
activation. Can switch back to WarpBuild once they fix the VM images.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Skip smoke test on macOS 14 compat, remove GUI diagnostic workflow

macOS 14 was slow because it built the full app (cmux scheme) on top of
unit tests (cmux-unit scheme). Unit tests are the real compat check;
smoke test runs on macOS 15 only. Also removes the temporary
test-warpbuild-gui.yml diagnostic workflow.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Replace Sonoma with Tahoe in compat matrix, drop macOS 14

Swap macOS 14 (Sonoma) for macOS 26 (Tahoe). Smoke test runs on
macOS 15 only (WarpBuild screen lock blocks app activation on 26).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Drop macOS 26 from compat matrix (zig 0.15.2 linker failure)

Zig 0.15.2 can't link against the macOS 26 (Tahoe) SDK: undefined
symbols for basic libc functions (_abort, _free, _fork, etc.). The zig
toolchain needs an update to support Tahoe. Keep macOS 15 only for now.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* Fix release browser portal compile

* Add macOS 26 (Tahoe) compat tests, skip zig build via stub (manaflow-ai#1590)

Zig 0.15.2's MachO linker can't resolve libSystem on macOS 26 (the
version number jump from 15 to 26 breaks zig's SDK handling). The unit
tests don't need the CLI helper binary at runtime, so we skip the zig
build on macOS 26 by setting CMUX_SKIP_ZIG_BUILD=1, which creates a
stub binary to satisfy the Xcode Run Script file check.

Smoke test (full app build + launch) is skipped on macOS 26 since it
needs the real CLI helper.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add regression tests for SSH remote CLI follow-ups

* Fix SSH remote CLI and loopback proxy follow-ups

* Fix remote daemon build script using relative output path after cd (manaflow-ai#1595)

The Go build runs in a subshell that cd's to daemon/remote/, but
OUTPUT_DIR was relative to the repo root. Resolve to absolute path
after mkdir so go build -o writes to the correct location.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Address SSH follow-up PR review comments

* fix: restore Sparkle automatic update checks (manaflow-ai#1597)

* feat: add native MCP protocol support to socket server

Add MCP (Model Context Protocol) Content-Length framing support directly
to the cmux socket server, enabling AI tools to connect via socat without
needing a separate Node.js MCP wrapper process.

Protocol detection on first read: "Content-Length:" → MCP mode,
"{" → V2 JSON-RPC, else V1 plain text. All three protocols coexist
on the same Unix socket.

New files:
- MCPServer.swift: Content-Length framing parser, MCPHandler with 3
  JSON-RPC methods (initialize, tools/list, tools/call), and 20 MCP
  tool schemas that route to existing V2 socket methods
- MCPServerTests.swift: 28 unit tests covering framing, handler logic,
  and tool routing

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address MCP server review findings

- Fix test initialization: tests calling tools/list and tools/call
  now send initialize first (XCTest creates fresh instances per test)
- Add testToolsListBeforeInitializeReturnsError to cover the guard
- Fix MCP message loop: continue parsing after each message instead
  of breaking after one, avoiding latency when multiple messages
  arrive in a single socket read
- Forward press_enter param in send_input tool routing
- Quote V1 command arguments to prevent injection via tokenizer
- Add writeSocketData helper with EINTR/partial-write handling
- Add encodeResponse fallback for non-serializable dicts
- Require initialized handshake before tools/list and tools/call
- Reject MCP connections when password auth is required
- Close connection on corrupted data after MCP detection

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
EtanHey added a commit to EtanHey/cmux that referenced this pull request Mar 17, 2026
* Add browser import flow with installed-browser detection

* Tone down empty browser import overlay

* Make browser import a 2-step choice flow

* Use single-window browser import wizard with close button

* Mention extensions not yet supported in import note

* Reapply "Merge pull request manaflow-ai#239 from manaflow-ai/issue-151-ssh-remote-port-proxying"

This reverts commit f7cbbad.

* Fix ssh stack review regressions

* Address ssh stack review follow-ups

* Optimize remote daemon builds and TCP latency

* Add remote favicon proxy regression

* Proxy remote browser favicon fetches

* Add ssh profile-noise regression

* Avoid sourcing profile in ssh bootstrap

* Add ssh stack regression tests

* Fix ssh stack review regressions

* Fix ghostty deferred-init regression harness

* Fix SSH workspace priming and restore state

* Fix SSH transport dedupe and loopback review issues

* Fix browser move and zsh bootstrap regressions

* Add regressions for v1 panel focus preservation

* Fix socket focus and startup env regressions

* Add regression test for deferred terminal portal sync

* Defer terminal portal sync past layout churn

* Keep portal sync responsive during live resize

* fix: show sidebar update banner from background checks (manaflow-ai#1543)

* Update bonsplit for split transparency

* Update bonsplit for split transparency

* Support folder drops on dock icon (manaflow-ai#1571)

* Fix sidebar PR badges for restored workspaces (manaflow-ai#1570)

* test: cover sidebar PR explicit branch fallback

* fix: restore sidebar PR badges for workspace branches

* test: preserve sidebar PR badge on first prompt

* fix: keep sidebar PR badges through first prompt

* feat: add browser profile mapping import flow

* Avoid blocking browser PR metadata updates (manaflow-ai#1564)

* Fix manaflow-ai#1574: remove top update banner in sidebar (manaflow-ai#1575)

* test: cover sidebar update indicator regression

* fix: remove duplicate sidebar update banner

* fix: address browser import review feedback

* Stabilize SSH remote flow after merging main

* Make remote proxy close idempotent

* Fix UI test helper closure captures

* Add remote CLI relay regressions

* Fix nightly remote daemon and SSH relay wiring

* Migrate CI/CD to WarpBuild, consolidate test jobs (manaflow-ai#1501)

* Migrate CI/CD to WarpBuild, consolidate test jobs

Replace all macOS runner labels across workflows:
- depot-macos-latest → warp-macos-15-arm64-6x
- macos-15 → warp-macos-15-arm64-6x
- macos-14 → warp-macos-14-arm64-6x

Consolidates tests + tests-depot into a single tests job that runs
unit tests, regressions, UI tests, and lag tests sequentially on one
WarpBuild runner. Ubuntu jobs remain on ubuntu-latest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Upgrade stale zig on runners that have an outdated version pre-installed

WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2.
The install step skipped because zig was found, just outdated.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Pin zig 0.15.2 via direct tarball instead of Homebrew

Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the
ghostty submodule requires 0.15.2. Download zig directly from
ziglang.org to guarantee the correct version on all runner images.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix zig tarball URL: arch-os order is aarch64-macos, not macos-aarch64

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Create /usr/local/bin and /usr/local/lib before copying zig

WarpBuild runners don't have /usr/local/lib by default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add 20-min timeout to WarpBuild jobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix UI test hang: stream output instead of variable capture, use GitHub runner for macOS 14

The OUTPUT=$(...) pattern buffers all xcodebuild output into a bash
variable. For the full cmux scheme (build + UI tests), this can be
hundreds of MB, causing the shell to hang. Replace with tee streaming.

macOS 14 on WarpBuild consistently hangs (unit tests timeout at 20min
vs 4min on macOS 15, same M4 Pro hardware). Use GitHub-hosted macos-14
runner for compat tests instead, which works on main today.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Split UI tests to GitHub-hosted runner (WarpBuild can't activate GUI apps)

WarpBuild macOS VMs leave XCUIApplication stuck in "Running Background"
state, causing every UI test to burn ~62s waiting for activation and
timing out the job. Root cause: WarpBuild ephemeral VMs don't provide
a full GUI session for app activation.

Split CI into parallel jobs:
- tests: WarpBuild (unit tests + regressions, ~6 min)
- tests-ui: GitHub-hosted macos-15 (UI tests + lag regression)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move tests-ui to WarpBuild with TCC permission grants

Grant accessibility, post-event, and screen capture TCC permissions
to Xcode and XCTest processes on WarpBuild ephemeral VMs. This should
fix "Failed to activate application (Running Background)" errors that
prevent XCUITests from bringing the app to foreground.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add GUI session diagnostics and DevToolsSecurity for WarpBuild UI tests

Add session diagnostics (who, console user, GUI domain, WindowServer,
loginwindow) to understand WarpBuild VM session state. Also enable
DevToolsSecurity and security authorizationdb for XCTest process
control. Try bootstrapping GUI session if missing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix TCC permissions: use Xcode-Helper + user DB (CircleCI approach)

Previous TCC grants used wrong client IDs (com.apple.dt.Xcode) and
only wrote to the system database. CircleCI's proven approach grants:
- kTCCServiceAccessibility to com.apple.dt.Xcode-Helper (not Xcode)
- kTCCServiceDeveloperTool to com.apple.Terminal
- Both system AND user-level TCC databases

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Reduce UI test timeout to 15s for WarpBuild expected failures

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background"). Tests still execute and
report expected failures. But the 62s per-test activation timeout
makes 30+ tests take 30+ minutes total.

Set per-test timeout to 15s so expected failures resolve quickly.
Full interactive UI test coverage runs via test-e2e.yml on
GitHub-hosted runners with proper display support.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Replace XCUITest run with build + lag regression on WarpBuild

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background" with 62s activation
timeout per test). Tried TCC permissions, DevToolsSecurity, virtual
display, reduced timeouts, nothing fixes the framework-level issue.

Replace tests-ui job with tests-build-and-lag:
- Build the full cmux scheme (verifies compilation)
- Run workspace churn typing-lag regression (socket-based, no GUI)
- XCUITests run via test-e2e.yml on GitHub-hosted runners

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move macOS 14 compat to WarpBuild (no GitHub-hosted runners)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add diagnostic workflow to probe WarpBuild GUI activation

Tests multiple app activation approaches on WarpBuild VMs:
- open -a, NSWorkspace, NSRunningApplication.activate, osascript
- Virtual display state before/after CGVirtualDisplay
- TCC/accessibility permissions, Quartz session info
- VM type detection

This is a workflow_dispatch-only diagnostic to determine if
XCUITest can work on WarpBuild with the right configuration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Trigger GUI probe on branch push (workflow_dispatch needs main)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Rewrite GUI probe with Swift (Python lacks AppKit on WarpBuild)

v1 failed because WarpBuild's Python isn't a framework build and
can't import AppKit/Quartz. v2 uses a compiled Swift binary to test
NSRunningApplication.activate(), osascript, Quartz session state,
display info, and AX trust.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* GUI probe v3: try 5 approaches to unlock WarpBuild screen

1. defaults write (screensaver, loginwindow, pmset)
2. automationmodetool enable-automationmode-without-authentication
3. CGSSessionSetScreenLocked private API + System Events keystroke
4. sysadminctl -screenLock off + keychain unlock
5. CGEvent simulation (mouse move + Return key to dismiss lock)

Each approach is followed by an activation check to see if it worked.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Test GUI activation on macOS 14, 15, and 26 (Tahoe)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add DerivedData and GhosttyKit caching to CI workflows

Major caching improvements across ci.yml and ci-macos-compat.yml:

- Cache GhosttyKit.xcframework keyed on ghostty submodule SHA
  (skip download on cache hit)
- Cache DerivedData keyed on OS + Xcode version + Package.resolved +
  project.pbxproj (enables incremental builds across runs)
- Remove explicit DerivedData wipe (rely on cache key invalidation)
- Use download-prebuilt-ghosttykit.sh in compat workflow too

This should significantly speed up macOS 14 compat tests which were
taking 20+ min due to full recompilation every run.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump macOS 14 compat timeout to 45 min for cold cache seeding

The DerivedData cache wasn't saved because the job timed out at 30 min,
causing the post-job cache save step to be skipped. 45 min gives enough
headroom for the first uncached run to complete and seed the cache.
Subsequent runs should be much faster with incremental builds.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Use Depot runners for E2E tests (WarpBuild has screen lock on macOS 15/26)

WarpBuild VMs on macOS 15 and 26 have CGSSessionScreenIsLocked=1, which
prevents XCUIApplication activation. Depot runners have working GUI
activation. Can switch back to WarpBuild once they fix the VM images.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Skip smoke test on macOS 14 compat, remove GUI diagnostic workflow

macOS 14 was slow because it built the full app (cmux scheme) on top of
unit tests (cmux-unit scheme). Unit tests are the real compat check;
smoke test runs on macOS 15 only. Also removes the temporary
test-warpbuild-gui.yml diagnostic workflow.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Replace Sonoma with Tahoe in compat matrix, drop macOS 14

Swap macOS 14 (Sonoma) for macOS 26 (Tahoe). Smoke test runs on
macOS 15 only (WarpBuild screen lock blocks app activation on 26).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Drop macOS 26 from compat matrix (zig 0.15.2 linker failure)

Zig 0.15.2 can't link against the macOS 26 (Tahoe) SDK: undefined
symbols for basic libc functions (_abort, _free, _fork, etc.). The zig
toolchain needs an update to support Tahoe. Keep macOS 15 only for now.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* Fix release browser portal compile

* Add macOS 26 (Tahoe) compat tests, skip zig build via stub (manaflow-ai#1590)

Zig 0.15.2's MachO linker can't resolve libSystem on macOS 26 (the
version number jump from 15 to 26 breaks zig's SDK handling). The unit
tests don't need the CLI helper binary at runtime, so we skip the zig
build on macOS 26 by setting CMUX_SKIP_ZIG_BUILD=1, which creates a
stub binary to satisfy the Xcode Run Script file check.

Smoke test (full app build + launch) is skipped on macOS 26 since it
needs the real CLI helper.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add regression tests for SSH remote CLI follow-ups

* Fix SSH remote CLI and loopback proxy follow-ups

* Fix remote daemon build script using relative output path after cd (manaflow-ai#1595)

The Go build runs in a subshell that cd's to daemon/remote/, but
OUTPUT_DIR was relative to the repo root. Resolve to absolute path
after mkdir so go build -o writes to the correct location.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Address SSH follow-up PR review comments

* fix: restore Sparkle automatic update checks (manaflow-ai#1597)

* feat: add native MCP protocol support to socket server

Add MCP (Model Context Protocol) Content-Length framing support directly
to the cmux socket server, enabling AI tools to connect via socat without
needing a separate Node.js MCP wrapper process.

Protocol detection on first read: "Content-Length:" → MCP mode,
"{" → V2 JSON-RPC, else V1 plain text. All three protocols coexist
on the same Unix socket.

New files:
- MCPServer.swift: Content-Length framing parser, MCPHandler with 3
  JSON-RPC methods (initialize, tools/list, tools/call), and 20 MCP
  tool schemas that route to existing V2 socket methods
- MCPServerTests.swift: 28 unit tests covering framing, handler logic,
  and tool routing

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address MCP server review findings

- Fix test initialization: tests calling tools/list and tools/call
  now send initialize first (XCTest creates fresh instances per test)
- Add testToolsListBeforeInitializeReturnsError to cover the guard
- Fix MCP message loop: continue parsing after each message instead
  of breaking after one, avoiding latency when multiple messages
  arrive in a single socket read
- Forward press_enter param in send_input tool routing
- Quote V1 command arguments to prevent injection via tokenizer
- Add writeSocketData helper with EINTR/partial-write handling
- Add encodeResponse fallback for non-serializable dicts
- Require initialized handshake before tools/list and tools/call
- Reject MCP connections when password auth is required
- Close connection on corrupted data after MCP detection

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
EtanHey added a commit to EtanHey/cmux that referenced this pull request Mar 17, 2026
* Add browser import flow with installed-browser detection

* Tone down empty browser import overlay

* Make browser import a 2-step choice flow

* Use single-window browser import wizard with close button

* Mention extensions not yet supported in import note

* Reapply "Merge pull request manaflow-ai#239 from manaflow-ai/issue-151-ssh-remote-port-proxying"

This reverts commit f7cbbad.

* Fix ssh stack review regressions

* Address ssh stack review follow-ups

* Optimize remote daemon builds and TCP latency

* Add remote favicon proxy regression

* Proxy remote browser favicon fetches

* Add ssh profile-noise regression

* Avoid sourcing profile in ssh bootstrap

* Add ssh stack regression tests

* Fix ssh stack review regressions

* Fix ghostty deferred-init regression harness

* Fix SSH workspace priming and restore state

* Fix SSH transport dedupe and loopback review issues

* Fix browser move and zsh bootstrap regressions

* Add regressions for v1 panel focus preservation

* Fix socket focus and startup env regressions

* Add regression test for deferred terminal portal sync

* Defer terminal portal sync past layout churn

* Keep portal sync responsive during live resize

* fix: show sidebar update banner from background checks (manaflow-ai#1543)

* Update bonsplit for split transparency

* Update bonsplit for split transparency

* Support folder drops on dock icon (manaflow-ai#1571)

* Fix sidebar PR badges for restored workspaces (manaflow-ai#1570)

* test: cover sidebar PR explicit branch fallback

* fix: restore sidebar PR badges for workspace branches

* test: preserve sidebar PR badge on first prompt

* fix: keep sidebar PR badges through first prompt

* feat: add browser profile mapping import flow

* Avoid blocking browser PR metadata updates (manaflow-ai#1564)

* Fix manaflow-ai#1574: remove top update banner in sidebar (manaflow-ai#1575)

* test: cover sidebar update indicator regression

* fix: remove duplicate sidebar update banner

* fix: address browser import review feedback

* Stabilize SSH remote flow after merging main

* Make remote proxy close idempotent

* Fix UI test helper closure captures

* Add remote CLI relay regressions

* Fix nightly remote daemon and SSH relay wiring

* Migrate CI/CD to WarpBuild, consolidate test jobs (manaflow-ai#1501)

* Migrate CI/CD to WarpBuild, consolidate test jobs

Replace all macOS runner labels across workflows:
- depot-macos-latest → warp-macos-15-arm64-6x
- macos-15 → warp-macos-15-arm64-6x
- macos-14 → warp-macos-14-arm64-6x

Consolidates tests + tests-depot into a single tests job that runs
unit tests, regressions, UI tests, and lag tests sequentially on one
WarpBuild runner. Ubuntu jobs remain on ubuntu-latest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Upgrade stale zig on runners that have an outdated version pre-installed

WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2.
The install step skipped because zig was found, just outdated.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Pin zig 0.15.2 via direct tarball instead of Homebrew

Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the
ghostty submodule requires 0.15.2. Download zig directly from
ziglang.org to guarantee the correct version on all runner images.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix zig tarball URL: arch-os order is aarch64-macos, not macos-aarch64

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Create /usr/local/bin and /usr/local/lib before copying zig

WarpBuild runners don't have /usr/local/lib by default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add 20-min timeout to WarpBuild jobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix UI test hang: stream output instead of variable capture, use GitHub runner for macOS 14

The OUTPUT=$(...) pattern buffers all xcodebuild output into a bash
variable. For the full cmux scheme (build + UI tests), this can be
hundreds of MB, causing the shell to hang. Replace with tee streaming.

macOS 14 on WarpBuild consistently hangs (unit tests timeout at 20min
vs 4min on macOS 15, same M4 Pro hardware). Use GitHub-hosted macos-14
runner for compat tests instead, which works on main today.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Split UI tests to GitHub-hosted runner (WarpBuild can't activate GUI apps)

WarpBuild macOS VMs leave XCUIApplication stuck in "Running Background"
state, causing every UI test to burn ~62s waiting for activation and
timing out the job. Root cause: WarpBuild ephemeral VMs don't provide
a full GUI session for app activation.

Split CI into parallel jobs:
- tests: WarpBuild (unit tests + regressions, ~6 min)
- tests-ui: GitHub-hosted macos-15 (UI tests + lag regression)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move tests-ui to WarpBuild with TCC permission grants

Grant accessibility, post-event, and screen capture TCC permissions
to Xcode and XCTest processes on WarpBuild ephemeral VMs. This should
fix "Failed to activate application (Running Background)" errors that
prevent XCUITests from bringing the app to foreground.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add GUI session diagnostics and DevToolsSecurity for WarpBuild UI tests

Add session diagnostics (who, console user, GUI domain, WindowServer,
loginwindow) to understand WarpBuild VM session state. Also enable
DevToolsSecurity and security authorizationdb for XCTest process
control. Try bootstrapping GUI session if missing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix TCC permissions: use Xcode-Helper + user DB (CircleCI approach)

Previous TCC grants used wrong client IDs (com.apple.dt.Xcode) and
only wrote to the system database. CircleCI's proven approach grants:
- kTCCServiceAccessibility to com.apple.dt.Xcode-Helper (not Xcode)
- kTCCServiceDeveloperTool to com.apple.Terminal
- Both system AND user-level TCC databases

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Reduce UI test timeout to 15s for WarpBuild expected failures

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background"). Tests still execute and
report expected failures. But the 62s per-test activation timeout
makes 30+ tests take 30+ minutes total.

Set per-test timeout to 15s so expected failures resolve quickly.
Full interactive UI test coverage runs via test-e2e.yml on
GitHub-hosted runners with proper display support.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Replace XCUITest run with build + lag regression on WarpBuild

WarpBuild Virtualization.framework VMs cannot activate macOS GUI apps
(XCUIApplication stuck "Running Background" with 62s activation
timeout per test). Tried TCC permissions, DevToolsSecurity, virtual
display, reduced timeouts, nothing fixes the framework-level issue.

Replace tests-ui job with tests-build-and-lag:
- Build the full cmux scheme (verifies compilation)
- Run workspace churn typing-lag regression (socket-based, no GUI)
- XCUITests run via test-e2e.yml on GitHub-hosted runners

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Move macOS 14 compat to WarpBuild (no GitHub-hosted runners)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add diagnostic workflow to probe WarpBuild GUI activation

Tests multiple app activation approaches on WarpBuild VMs:
- open -a, NSWorkspace, NSRunningApplication.activate, osascript
- Virtual display state before/after CGVirtualDisplay
- TCC/accessibility permissions, Quartz session info
- VM type detection

This is a workflow_dispatch-only diagnostic to determine if
XCUITest can work on WarpBuild with the right configuration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Trigger GUI probe on branch push (workflow_dispatch needs main)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Rewrite GUI probe with Swift (Python lacks AppKit on WarpBuild)

v1 failed because WarpBuild's Python isn't a framework build and
can't import AppKit/Quartz. v2 uses a compiled Swift binary to test
NSRunningApplication.activate(), osascript, Quartz session state,
display info, and AX trust.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* GUI probe v3: try 5 approaches to unlock WarpBuild screen

1. defaults write (screensaver, loginwindow, pmset)
2. automationmodetool enable-automationmode-without-authentication
3. CGSSessionSetScreenLocked private API + System Events keystroke
4. sysadminctl -screenLock off + keychain unlock
5. CGEvent simulation (mouse move + Return key to dismiss lock)

Each approach is followed by an activation check to see if it worked.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Test GUI activation on macOS 14, 15, and 26 (Tahoe)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add DerivedData and GhosttyKit caching to CI workflows

Major caching improvements across ci.yml and ci-macos-compat.yml:

- Cache GhosttyKit.xcframework keyed on ghostty submodule SHA
  (skip download on cache hit)
- Cache DerivedData keyed on OS + Xcode version + Package.resolved +
  project.pbxproj (enables incremental builds across runs)
- Remove explicit DerivedData wipe (rely on cache key invalidation)
- Use download-prebuilt-ghosttykit.sh in compat workflow too

This should significantly speed up macOS 14 compat tests which were
taking 20+ min due to full recompilation every run.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump macOS 14 compat timeout to 45 min for cold cache seeding

The DerivedData cache wasn't saved because the job timed out at 30 min,
causing the post-job cache save step to be skipped. 45 min gives enough
headroom for the first uncached run to complete and seed the cache.
Subsequent runs should be much faster with incremental builds.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Use Depot runners for E2E tests (WarpBuild has screen lock on macOS 15/26)

WarpBuild VMs on macOS 15 and 26 have CGSSessionScreenIsLocked=1, which
prevents XCUIApplication activation. Depot runners have working GUI
activation. Can switch back to WarpBuild once they fix the VM images.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Skip smoke test on macOS 14 compat, remove GUI diagnostic workflow

macOS 14 was slow because it built the full app (cmux scheme) on top of
unit tests (cmux-unit scheme). Unit tests are the real compat check;
smoke test runs on macOS 15 only. Also removes the temporary
test-warpbuild-gui.yml diagnostic workflow.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Replace Sonoma with Tahoe in compat matrix, drop macOS 14

Swap macOS 14 (Sonoma) for macOS 26 (Tahoe). Smoke test runs on
macOS 15 only (WarpBuild screen lock blocks app activation on 26).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Drop macOS 26 from compat matrix (zig 0.15.2 linker failure)

Zig 0.15.2 can't link against the macOS 26 (Tahoe) SDK: undefined
symbols for basic libc functions (_abort, _free, _fork, etc.). The zig
toolchain needs an update to support Tahoe. Keep macOS 15 only for now.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* Fix release browser portal compile

* Add macOS 26 (Tahoe) compat tests, skip zig build via stub (manaflow-ai#1590)

Zig 0.15.2's MachO linker can't resolve libSystem on macOS 26 (the
version number jump from 15 to 26 breaks zig's SDK handling). The unit
tests don't need the CLI helper binary at runtime, so we skip the zig
build on macOS 26 by setting CMUX_SKIP_ZIG_BUILD=1, which creates a
stub binary to satisfy the Xcode Run Script file check.

Smoke test (full app build + launch) is skipped on macOS 26 since it
needs the real CLI helper.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add regression tests for SSH remote CLI follow-ups

* Fix SSH remote CLI and loopback proxy follow-ups

* Fix remote daemon build script using relative output path after cd (manaflow-ai#1595)

The Go build runs in a subshell that cd's to daemon/remote/, but
OUTPUT_DIR was relative to the repo root. Resolve to absolute path
after mkdir so go build -o writes to the correct location.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Address SSH follow-up PR review comments

* fix: restore Sparkle automatic update checks (manaflow-ai#1597)

* feat: add native MCP protocol support to socket server

Add MCP (Model Context Protocol) Content-Length framing support directly
to the cmux socket server, enabling AI tools to connect via socat without
needing a separate Node.js MCP wrapper process.

Protocol detection on first read: "Content-Length:" → MCP mode,
"{" → V2 JSON-RPC, else V1 plain text. All three protocols coexist
on the same Unix socket.

New files:
- MCPServer.swift: Content-Length framing parser, MCPHandler with 3
  JSON-RPC methods (initialize, tools/list, tools/call), and 20 MCP
  tool schemas that route to existing V2 socket methods
- MCPServerTests.swift: 28 unit tests covering framing, handler logic,
  and tool routing

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address MCP server review findings

- Fix test initialization: tests calling tools/list and tools/call
  now send initialize first (XCTest creates fresh instances per test)
- Add testToolsListBeforeInitializeReturnsError to cover the guard
- Fix MCP message loop: continue parsing after each message instead
  of breaking after one, avoiding latency when multiple messages
  arrive in a single socket read
- Forward press_enter param in send_input tool routing
- Quote V1 command arguments to prevent injection via tokenizer
- Add writeSocketData helper with EINTR/partial-write handling
- Add encodeResponse fallback for non-serializable dicts
- Require initialized handshake before tools/list and tools/call
- Reject MCP connections when password auth is required
- Close connection on corrupted data after MCP detection

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
bn-l pushed a commit to bn-l/cmux that referenced this pull request Apr 3, 2026

This branch was successfully deployed

1 active deployment
Preview — c9f16cf5 Deployed Mar 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sidebar should automatically show update-available banner without manual check

1 participant