Skip to content

fix(remote): evict stale persistent SSH bridge leases - #16558

Merged
teamleaderleo merged 2 commits into
mainfrom
fix/10367-stale-bridge-lease
Oct 2, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
fix/10367-stale-bridge-lease

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #10367

When an SSH channel goes half-open, its remote serve --stdio --persistent bridge can stay authenticated forever and hold the slot. A reconnect then cannot reach the persistent daemon until the stale bridge is killed manually.

This adds a fresh authenticated bridge_lease_id to each persistent stdio bridge. The persistent daemon tracks accepted connections and lets the newest bridge evict older and legacy connections while preserving the shared PTY hub and sessions. Authentication failures remain sanitized, and socket dials use context-aware timeouts.

Regression-first commits:

  1. 9519943540d adds TestPersistentDaemonBridgeLeaseTakeoverClosesStaleConnection. On current main, it fails because the stale bridge read reaches its deadline.
  2. 7f7b179c704 adds lease takeover and coverage that preserves PTY reattach behavior.

Verification:

  • go test ./cmd/cmuxd-remote -run 'TestPersistentDaemon(AuthenticatedBridgeLeaseTakeoverEvictsStaleHolder|BridgeLeaseTakeoverEvictsLegacyAuthenticatedConnection)' -count=1
  • go test -race ./cmd/cmuxd-remote -run 'TestPersistentDaemon.*(BridgeLease|PTYReattachSurvivesClientDisconnect)' -count=1
  • git diff --check

The package-wide Go run still has an unrelated existing failure in TestTmuxStaleInheritedSurfaceCannotRetarget.

— Cattail g1 🔸


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Closes #10367. A half-open SSH channel keeps the remote persistent bridge authenticated forever, holding the slot and blocking reconnects from reaching the daemon. Each persistent stdio bridge now sends a fresh authenticated bridge_lease_id so the newest bridge evicts stale and legacy connections while preserving the shared PTY hub and sessions.

  • Takeover closes older connections without touching persistent PTY sessions; authentication failures stay sanitized and socket dials use context-aware timeouts.

Written for commit 7f7b179. Summary will update on new commits.

Review in cubic

teamleaderleo and others added 2 commits October 1, 2026 17:10
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cursor

cursor Bot commented Oct 2, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 39d24146-e276-4c1b-8fd8-e62b1e05311a

📥 Commits

Reviewing files that changed from the base of the PR and between 8b8762a and 7f7b179.

📒 Files selected for processing (5)
  • daemon/remote/README.md
  • daemon/remote/cmd/cmuxd-remote/main.go
  • daemon/remote/cmd/cmuxd-remote/persistent_bridge_lease.go
  • daemon/remote/cmd/cmuxd-remote/persistent_bridge_lease_test.go
  • docs/remote-daemon-spec.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

You’re at about 90% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.

Re-trigger cubic

@teamleaderleo teamleaderleo added the full-ci EXPENSIVE: full macOS tests/builds; overrides selective PR routing. Not needed for normal checks. label Oct 2, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Current upstream/main (8b8762a) still fails TestTmuxStaleInheritedSurfaceCannotRetarget in both send-keys and kill-pane: a stale CMUX_SURFACE_ID=surface:missing is retargeted to surface 44444444-4444-4444-8444-444444444444, causing surface.send_text/surface.close RPCs. #16558 has the same failure, so I will open a separate fix PR and leave this PR focused on the bridge lease change.\n\n— Teakettle g2

@teamleaderleo
teamleaderleo merged commit 7d57a03 into main Oct 2, 2026
97 checks passed
@teamleaderleo
teamleaderleo deleted the fix/10367-stale-bridge-lease branch October 2, 2026 00:32
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Merge receipt for 7f7b179c70, merged 2026-10-02 00:32:36 UTC

  • Not verified at merge: remote-daemon-macos-tests (in progress)
  • Verified: ci-status, CI fast guards, CI timing, Fast static checks, full-suite-coverage, GhosttyKit release check, guards (19), remote-daemon-admission, remote-daemon-tests, tests, Web complexity, web-validation
  • Skipped by policy: browser, Claude request, Claude wrapper regressions, Dogfood build #​${{ github.event.pull_request.number }}, linux-preflight, macos, macOS admission gate, suite-coverage, ui-tests, web, web-build, web-database-tests, and 1 more
  • Full suite: runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Oct 2, 2026
0bfd027 test(cloud): fix the Cloud header and moved-panel focus tests that never ran (manaflow-ai#16539)
c5c4345 localization: accept numbered placeholders in any order (manaflow-ai#16376)
456edeb fix(settings): replace custom sidebar mockups with real previews (manaflow-ai#16569)
98dc3ab Prototype: cmux Cloud as a remote MCP server (manaflow-ai#16568)
6c22525 test(remote): isolate tmux stale-surface fixture (manaflow-ai#16566)
3ec9918 Re-land "fix(coderouter): initialize Cloud VM account pools (manaflow-ai#16397)" (manaflow-ai#16572)
2b895a5 Fix browser paste routing with terminal text box beta (manaflow-ai#6380) (manaflow-ai#16560)
2bd3455 localization: check Swift defaultValue literals against their catalog en value (manaflow-ai#16396)
c43086e test(cli): expect --mark-read to mark every listed inbox message (manaflow-ai#16537)
fcda4f0 test(feed): wait for zero-wait Codex permission acceptance before checking attention (manaflow-ai#16536)
7d57a03 fix(remote): evict stale persistent SSH bridge leases (manaflow-ai#16558)
d630cb8 docs: add protected-folder diagnostics for tmux sessions (manaflow-ai#12219)
7dceaac test: create cwd fixtures that new terminals now resolve on disk (manaflow-ai#16538)
28cc575 docs: cover surface resume binding CLI contract (manaflow-ai#16473)
5c7dca1 Fix idle zsh PR probes triggering chpwd hooks (manaflow-ai#16553)

# Conflicts:
#	.github/workflows/ci-guards.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

full-ci EXPENSIVE: full macOS tests/builds; overrides selective PR routing. Not needed for normal checks.

Projects

None yet

1 participant