Skip to content

fix(worktree-seed): budget each pattern and refuse dangling escapes - #15860

Merged
teamleaderleo merged 2 commits into
manaflow-ai:mainfrom
teamleaderleo:parity/worktree-seed-review
Sep 30, 2026
Merged

teamleaderleo merged 2 commits into
manaflow-ai:mainfrom
teamleaderleo:parity/worktree-seed-review

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

What this is

A follow-up to #15413 carrying two review findings that did not make the merge.

The two defects

WorktreeSeedPlanner.plan shared one directory-visit budget across the whole file. A greedy ** pattern could spend the budget, leaving later patterns with no walk and reporting them as unmatched. aPatternAfterABudgetExhaustingOneIsStillTried and aBudgetExhaustingPatternIsNotReportedAsMatchingNothing fail without the fix.

WorktreeSeedRepository.isInside resolved only the selected symlink, so dangling links and chained links whose targets were outside the repository could look safe. aDanglingSymlinkOutOfTheRepositoryIsAnEscape and the review-added aChainedSymlinkOutOfTheRepositoryIsAnEscape fail without the boundary fix; aDanglingSymlinkInsideTheRepositoryIsNotAnEscape verifies that missing targets under the repository remain allowed.

Red and green

The focused command is swift test in an extracted scratch package because CMUXAgentLaunch does not build on Linux. The test-only baseline ran 81 tests with three red test names: aPatternAfterABudgetExhaustingOneIsStillTried, aBudgetExhaustingPatternIsNotReportedAsMatchingNothing, and aDanglingSymlinkOutOfTheRepositoryIsAnEscape. The primary fix then ran 81 tests with 0 failures. The review repair added the chained-link regression, and the final run passed all 82 tests.

Test quality

The budget assertion now requires exactly 5 directory listings, the question-mark test reuses its existing repository local, the filename constant assertion was removed under the cmux-testing regression-and-quality rule against source-shape tests, and the blank/comment parser test now propagates errors instead of using try!.

Not in this PR

The review also asked for shadow-before-triage reordering, so a path inside a wholesale-selected directory would be reported as shadowed rather than excluded, refused, or already present. main now has aNegatedPositiveMatchInsideASelectedDirectoryIsStillIneffective, which asserts the current both-lists behavior on purpose. Changing that behavior is a design change, not a fix, so it is left for a separate proposal.

Changelog

none

🤖 Generated with Claude Code

teamleaderleo and others added 2 commits September 30, 2026 01:07
…ink escapes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nks out of the repository

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 7 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7c8fd739-faec-42f2-ab35-b1225d5edcda

📥 Commits

Reviewing files that changed from the base of the PR and between fc13b7c and 6fbc221.

📒 Files selected for processing (7)
  • Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/WorktreeSeed/WorktreeSeedPlan.swift
  • Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/WorktreeSeed/WorktreeSeedPlanner.swift
  • Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/WorktreeSeed/WorktreeSeedRepository.swift
  • Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/WorktreeSeedFileTests.swift
  • Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/WorktreeSeedPatternTests.swift
  • Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/WorktreeSeedPlannerTests.swift
  • Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/WorktreeSeedRepositoryTests.swift

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 30, 2026 08:13
@teamleaderleo
teamleaderleo merged commit 03e1245 into manaflow-ai:main Sep 30, 2026
73 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 6fbc221daa: every check was green at merge (23 verified; 21 skipped by policy). Full suite runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 30, 2026
0e44675 test: bound remote bootstrap subprocess waits (manaflow-ai#15608)
a192a14 fix(agent-chat): show ACP plans as structured step lists (manaflow-ai#15889)
d7f59a3 ci: place attempt 2 like attempt 1, owned minis first (manaflow-ai#15406)
d87c3be feat(agent-chat): register Cursor Agent as an ACP provider (manaflow-ai#15877)
1bd5083 fix: preserve Codex provider for workspace auto-naming (manaflow-ai#15635)
03e1245 fix(worktree-seed): budget each pattern and refuse dangling escapes (manaflow-ai#15860)
5c28fcb fix(agent-chat): stop a disposed ACP session from resurrecting its agent (manaflow-ai#15872)
11216d2 Fix Codex Agent Chat Stop interrupt request (manaflow-ai#15837)
d6b8c15 ci: watch Unix cmux-tui installer changes (manaflow-ai#15874)
0fc35d6 feat(agent-chat): register goose as an ACP provider (manaflow-ai#15871)
7f27bfc cmux ssh: security hardening from the ssh audit (manaflow-ai#15768)
8599250 fix(agent-chat): launch gemini with --experimental-acp (manaflow-ai#15868)
849376a docs: classify contributor issue difficulty (manaflow-ai#15627)
2761cc9 Keep agents with live background work out of hibernation (manaflow-ai#15278)
eae02a6 Cloud: rebake the devbox ladder with cmux-tui 02dac3c (manaflow-ai#15866)
7ed2f6b ci: bound open pull-request media revisions (manaflow-ai#15861)
13c417c Notify on SubagentStop in the notifications hook docs (manaflow-ai#15854)
5cfc6a6 fix: make cmux-tui installs immutable across release uploads (manaflow-ai#15859)
4eee1b1 fix: preserve longest Claude upstream cooldown (manaflow-ai#15856)
204b936 Pin Cloud panes to the daemon's terminal grid (manaflow-ai#15792)
fc13b7c cmux-tui: fix the replay row scroll and stale hook fence tests breaking the full gate (manaflow-ai#15240)
87d66af Add Cloud to the menu bar extra and a main-menu Cloud menu (manaflow-ai#15822)

# Conflicts:
#	.github/workflows/ci-failure-attribution.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci-owned-pool-rescue.yml
#	.github/workflows/ci-queue-janitor.yml
#	.github/workflows/ci.yml
#	.github/workflows/cmux-tui-artifacts.yml
#	.github/workflows/cmux-tui-build-package.yml
#	.github/workflows/cmux-tui-sdks.yml
#	.github/workflows/pr-media-prune.yml
#	.github/workflows/remote-daemon.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant