Repository navigation
fix(worktree-seed): budget each pattern and refuse dangling escapes - #15860
Conversation
…ink escapes Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nks out of the repository Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 7 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
|
Merge receipt for |
0e44675 test: bound remote bootstrap subprocess waits (manaflow-ai#15608) a192a14 fix(agent-chat): show ACP plans as structured step lists (manaflow-ai#15889) d7f59a3 ci: place attempt 2 like attempt 1, owned minis first (manaflow-ai#15406) d87c3be feat(agent-chat): register Cursor Agent as an ACP provider (manaflow-ai#15877) 1bd5083 fix: preserve Codex provider for workspace auto-naming (manaflow-ai#15635) 03e1245 fix(worktree-seed): budget each pattern and refuse dangling escapes (manaflow-ai#15860) 5c28fcb fix(agent-chat): stop a disposed ACP session from resurrecting its agent (manaflow-ai#15872) 11216d2 Fix Codex Agent Chat Stop interrupt request (manaflow-ai#15837) d6b8c15 ci: watch Unix cmux-tui installer changes (manaflow-ai#15874) 0fc35d6 feat(agent-chat): register goose as an ACP provider (manaflow-ai#15871) 7f27bfc cmux ssh: security hardening from the ssh audit (manaflow-ai#15768) 8599250 fix(agent-chat): launch gemini with --experimental-acp (manaflow-ai#15868) 849376a docs: classify contributor issue difficulty (manaflow-ai#15627) 2761cc9 Keep agents with live background work out of hibernation (manaflow-ai#15278) eae02a6 Cloud: rebake the devbox ladder with cmux-tui 02dac3c (manaflow-ai#15866) 7ed2f6b ci: bound open pull-request media revisions (manaflow-ai#15861) 13c417c Notify on SubagentStop in the notifications hook docs (manaflow-ai#15854) 5cfc6a6 fix: make cmux-tui installs immutable across release uploads (manaflow-ai#15859) 4eee1b1 fix: preserve longest Claude upstream cooldown (manaflow-ai#15856) 204b936 Pin Cloud panes to the daemon's terminal grid (manaflow-ai#15792) fc13b7c cmux-tui: fix the replay row scroll and stale hook fence tests breaking the full gate (manaflow-ai#15240) 87d66af Add Cloud to the menu bar extra and a main-menu Cloud menu (manaflow-ai#15822) # Conflicts: # .github/workflows/ci-failure-attribution.yml # .github/workflows/ci-macos.yml # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/ci-queue-janitor.yml # .github/workflows/ci.yml # .github/workflows/cmux-tui-artifacts.yml # .github/workflows/cmux-tui-build-package.yml # .github/workflows/cmux-tui-sdks.yml # .github/workflows/pr-media-prune.yml # .github/workflows/remote-daemon.yml
What this is
A follow-up to #15413 carrying two review findings that did not make the merge.
The two defects
WorktreeSeedPlanner.planshared one directory-visit budget across the whole file. A greedy**pattern could spend the budget, leaving later patterns with no walk and reporting them as unmatched.aPatternAfterABudgetExhaustingOneIsStillTriedandaBudgetExhaustingPatternIsNotReportedAsMatchingNothingfail without the fix.WorktreeSeedRepository.isInsideresolved only the selected symlink, so dangling links and chained links whose targets were outside the repository could look safe.aDanglingSymlinkOutOfTheRepositoryIsAnEscapeand the review-addedaChainedSymlinkOutOfTheRepositoryIsAnEscapefail without the boundary fix;aDanglingSymlinkInsideTheRepositoryIsNotAnEscapeverifies that missing targets under the repository remain allowed.Red and green
The focused command is
swift testin an extracted scratch package because CMUXAgentLaunch does not build on Linux. The test-only baseline ran 81 tests with three red test names:aPatternAfterABudgetExhaustingOneIsStillTried,aBudgetExhaustingPatternIsNotReportedAsMatchingNothing, andaDanglingSymlinkOutOfTheRepositoryIsAnEscape. The primary fix then ran 81 tests with 0 failures. The review repair added the chained-link regression, and the final run passed all 82 tests.Test quality
The budget assertion now requires exactly 5 directory listings, the question-mark test reuses its existing repository local, the filename constant assertion was removed under the cmux-testing regression-and-quality rule against source-shape tests, and the blank/comment parser test now propagates errors instead of using
try!.Not in this PR
The review also asked for shadow-before-triage reordering, so a path inside a wholesale-selected directory would be reported as shadowed rather than excluded, refused, or already present.
mainnow hasaNegatedPositiveMatchInsideASelectedDirectoryIsStillIneffective, which asserts the current both-lists behavior on purpose. Changing that behavior is a design change, not a fix, so it is left for a separate proposal.Changelog
none
🤖 Generated with Claude Code