Skip to content

fix: suppress socat stdout in _cmux_send to prevent OK leak - #1619

Merged
lawrencecchen merged 1 commit into
manaflow-ai:mainfrom
fvallenilla:fix/socat-stdout-leak
Mar 18, 2026
Merged

lawrencecchen merged 1 commit into
manaflow-ai:mainfrom
fvallenilla:fix/socat-stdout-leak

Conversation

@fvallenilla

@fvallenilla fvallenilla commented Mar 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Redirect socat stdout/stderr to /dev/null in _cmux_send for both zsh and bash shell integrations
  • The ncat path uses --send-only and the nc path already redirects — the socat path was the only one leaking the socket response to the terminal

Root cause

The cmux socket responds with OK to every message. socat reads bidirectionally by default, so without output suppression it prints that response to stdout. On systems where ncat is absent but socat is installed (common on macOS via Homebrew), this causes a spurious OK to appear on every new tab, directory change, and shell prompt.

Fixes #1618

Test plan

  • On a system with socat but no ncat, open a new terminal tab — no OK should appear
  • Run cd /tmp && cd - — no OK should appear
  • Verify sidebar still updates (pwd, git branch, PR badge) since the socket send itself is unaffected

Generated with Claude Code


Summary by cubic

Stop the cmux socket OK from appearing in the terminal by redirecting socat stdout/stderr to /dev/null in _cmux_send for both bash and zsh. This aligns the socat path with ncat --send-only/nc and prevents stray OK on new tabs, cd, and prompts when ncat is missing.

Written for commit aae07c2. Summary will update on new commits.

Summary by CodeRabbit

  • Bug Fixes
    • Suppressed extraneous output from shell integration commands for a cleaner user experience.

The socat path in _cmux_send did not redirect stdout/stderr, causing
the cmux socket's "OK" response to print to the user's terminal on
every shell integration event (new tab, cd, precmd, preexec).

The ncat path avoids this via --send-only, and the nc path already
redirects to /dev/null. This aligns the socat path with both.

Fixes manaflow-ai#1618

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Mar 17, 2026

Copy link
Copy Markdown

@fvallenilla is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@coderabbitai

coderabbitai Bot commented Mar 17, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0a45b1ff-7b0f-4d69-99d9-bd44ecea36ed

📥 Commits

Reviewing files that changed from the base of the PR and between 8d8fadb and aae07c2.

📒 Files selected for processing (2)
  • Resources/shell-integration/cmux-bash-integration.bash
  • Resources/shell-integration/cmux-zsh-integration.zsh

📝 Walkthrough

Walkthrough

Both bash and zsh shell integration scripts add output redirection to the socat fallback path in the _cmux_send function, suppressing stdout and stderr to prevent socket responses from leaking to the terminal.

Changes

Cohort / File(s) Summary
Shell Integration Socket Transport
Resources/shell-integration/cmux-bash-integration.bash, Resources/shell-integration/cmux-zsh-integration.zsh
Redirect stdout and stderr to /dev/null in socat command invocation to suppress socket response output that was previously leaked to the terminal.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

🐰 Whispers the quiet rabbit to the socat stream:

Hush now, dear socket, your "OK" must not gleam,
Into /dev/null it flows, silent and clean,
No more stray output upon the bright screen!
✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: suppressing socat stdout to prevent OK output leakage in the _cmux_send function.
Description check ✅ Passed The description includes a comprehensive summary of changes and root cause, but the testing section lacks details on how the change was tested locally and which tests were added or verified.
Linked Issues check ✅ Passed The code changes directly address issue #1618 by redirecting socat stdout/stderr to /dev/null in both shell integrations, matching the ncat and nc implementations.
Out of Scope Changes check ✅ Passed All changes are scoped to the socat output suppression in _cmux_send for both bash and zsh integrations, directly addressing the linked issue with no extraneous modifications.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
📝 Coding Plan
  • Generate coding plan for human review comments

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Tip

CodeRabbit can use TruffleHog to scan for secrets in your code with verification capabilities.

Add a TruffleHog config file (e.g. trufflehog-config.yml, trufflehog.yml) to your project to customize detectors and scanning behavior. The tool runs only when a config file is present.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files


Since this is your first cubic review, here's how it works:

  • cubic automatically reviews your code and comments on bugs and improvements
  • Teach cubic by replying to its comments. cubic learns from your replies and gets better over time
  • Add one-off context when rerunning by tagging @cubic-dev-ai with guidance or docs links (including llms.txt)
  • Ask questions if you need clarification on any suggestion

@lawrencecchen
lawrencecchen merged commit aefb776 into manaflow-ai:main Mar 18, 2026
3 of 4 checks passed
bn-l pushed a commit to bn-l/cmux that referenced this pull request Apr 3, 2026
…ow-ai#1619)

The socat path in _cmux_send did not redirect stdout/stderr, causing
the cmux socket's "OK" response to print to the user's terminal on
every shell integration event (new tab, cd, precmd, preexec).

The ncat path avoids this via --send-only, and the nc path already
redirects to /dev/null. This aligns the socat path with both.

Fixes manaflow-ai#1618

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Shell integration: socat path in _cmux_send leaks socket response to stdout

2 participants