Repository navigation
fix(coderouter): initialize Cloud VM account pools - #16397
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughVM authorization now records initialization for a qualifying team default pool and grants it team-visible native and Claude accounts when the marker is new. A migration marks existing pools as initialized. A database test checks VM visibility for shared Codex accounts. ChangesCodeRouter VM pool initialization
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant VMAuthorization
participant Repository
participant Database
participant TokenSigner
VMAuthorization->>Repository: Request VM authorization token
Repository->>Database: Insert initialization marker for qualifying default pool
alt Marker is new
Repository->>Database: Grant team-visible native and Claude accounts
end
Repository->>TokenSigner: Sign VM authorization token
Merge Risk: ⚪ Minimal · up to The change initializes new eligible VM pools while preserving private-account exclusions and later revocations. No concrete merge-blocking issue was identified; normal database validation should complete before deployment. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change keeps account access tied to the VM’s owning team and preserves deliberate grant removals after initialization. No introduced security violation was established. Concurrent pool reassignment and production rollout behavior remain incompletely verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
All reported issues were addressed across 4 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Review auditHead audited:
All actionable review findings are addressed or resolved. No merge or controller build is requested for this web-only change. |
|
Merge receipt for |
6aa6343 fix(coderouter): initialize Cloud VM account pools (manaflow-ai#16397)
…16405) Production outage: every Cloud VM create fails with model_plane_unavailable since 2026-10-01 08:44 UTC. #16397 inserts into coderouter_pool_initializations, but its migration 20261001000000 was never applied to staging or production. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Reverted by #16405 to stop a production outage: every Cloud VM create failed with model_plane_unavailable from 2026-10-01 08:44 UTC (30 of 30 creates), because migration 20261001000000_coderouter_vm_pool_initialization was never applied to staging or production. To re-land: apply that migration to staging, then production, and only then merge the code again. |
…#16572) Reverts #16405. #16397 was reverted because its migration 20261001000000_coderouter_vm_pool_initialization was never applied to staging or production, so every Cloud VM create failed. This re-land merges only after that migration is applied to staging and production. Co-authored-by: austinywang <austinywang@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
0bfd027 test(cloud): fix the Cloud header and moved-panel focus tests that never ran (manaflow-ai#16539) c5c4345 localization: accept numbered placeholders in any order (manaflow-ai#16376) 456edeb fix(settings): replace custom sidebar mockups with real previews (manaflow-ai#16569) 98dc3ab Prototype: cmux Cloud as a remote MCP server (manaflow-ai#16568) 6c22525 test(remote): isolate tmux stale-surface fixture (manaflow-ai#16566) 3ec9918 Re-land "fix(coderouter): initialize Cloud VM account pools (manaflow-ai#16397)" (manaflow-ai#16572) 2b895a5 Fix browser paste routing with terminal text box beta (manaflow-ai#6380) (manaflow-ai#16560) 2bd3455 localization: check Swift defaultValue literals against their catalog en value (manaflow-ai#16396) c43086e test(cli): expect --mark-read to mark every listed inbox message (manaflow-ai#16537) fcda4f0 test(feed): wait for zero-wait Codex permission acceptance before checking attention (manaflow-ai#16536) 7d57a03 fix(remote): evict stale persistent SSH bridge leases (manaflow-ai#16558) d630cb8 docs: add protected-folder diagnostics for tmux sessions (manaflow-ai#12219) 7dceaac test: create cwd fixtures that new terminals now resolve on disk (manaflow-ai#16538) 28cc575 docs: cover surface resume binding CLI contract (manaflow-ai#16473) 5c7dca1 Fix idle zsh PR probes triggering chpwd hooks (manaflow-ai#16553) # Conflicts: # .github/workflows/ci-guards.yml
Fixes #16389
Cloud CodeRouter sessions can report healthy team accounts on the host while a VM's default pool has never been initialized, leaving the VM's Codex selector empty. This change snapshots the selected team's shared accounts into the VM's default pool before the first signed model-plane token is persisted. A durable pool-initialization marker makes the snapshot one-time, so later token refreshes preserve deliberate pool revocations; native and Claude account families seed independently.
Impact map
cloud_vms.owner_team_id, its defaultcoderouter_pool_id, team-visible CodeRouter account rows, and the newcoderouter_pool_initializationsmarker.issueVmAuthorizationTokenis called by VM model-plane provisioning; guest account listing and Codex selection consume the resulting pool throughaccountAccessPredicate. Existing account-import, sharing, token revocation, and destroy paths remain unchanged.Validation
git diff --checkpassed.python3 scripts/verify-local.py --only feature-flagspassed.web/node_modules(effectwas missing after the disk-full install).web-validationrun is executing the DB behavior suite for the current head.a20ed74ca17b759af39fc53be8227078e8387f6d4730d22703290415bbc55e3f0035f174bd6d3afdCONFLICT CHECK: PASSon the prior head; rerun required after this push.Summary by CodeRabbit