Skip to content

fix(gallery): link PR comment thumbnails by the name pr-media.py stores - #18301

Merged
teamleaderleo merged 2 commits into
feat-cmux-nextfrom
fix/gallery-thumb-media-names
Oct 7, 2026
Merged

teamleaderleo merged 2 commits into
feat-cmux-nextfrom
fix/gallery-thumb-media-names

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The gallery PR comment's inline thumbnails 404 on every PR (seen on #18152 and #18224). The comment links <prefix><key>, for example agent-pane.docked-chat--working--en--Apple_System_Colors--w400-webkit.png. The publisher uploads that file through scripts/pr-media.py, whose sanitize() collapses each run of dashes, so pr-media holds agent-pane.docked-chat-working-en-Apple_System_Colors-w400-webkit.png.

The poster side changed. sanitize() has collapsed dashes since pr-media.py was added (#15295). The gallery diff (#18205) introduced entry--variant keys and linked them as given.

The fix is in report.ts: thumbUrl names the stored file by collapsing dash runs in the key, as sanitize() does. SAFE_KEY now also requires the key to start with a letter or digit, so prefix plus key can't form a new dash run. The uploader and the workflow are unchanged. The publish job runs the base branch's scripts, so comments are fixed from the first PR run after this lands.

Verification

The new test, thumbnail links name the file pr-media.py stores, calls the real pr-media.py sanitize() and checks both the comment link and the feed thumbnail against it. This ties the link to the uploader instead of to a copy of its rule.

Changelog

none

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes gallery PR comment thumbnails 404ing because comment links used keys with dash runs (for example agent-pane.docked-chat--working--en-...) while scripts/pr-media.py stores files under its sanitize() name with those runs collapsed, so every inline thumbnail broke (#18152, #18224).

Bug Fixes

  • Adds a test that runs the real pr-media.py sanitize() and asserts both the comment link and the feed thumbnail name the file the uploader actually stores.
  • Uploader and workflow are unchanged, so comments are fixed from the first PR run after this lands.

Written for commit 1ca6605. Summary will update on new commits.

Review in cubic Turn on auto-fix


Note

Low Risk
Scoped to gallery report URL generation and tests; uploader/workflow unchanged and no auth or data-path changes.

Overview
Fixes gallery PR comment thumbnail 404s by building raw URLs from the filename scripts/pr-media.py actually stores, not the raw outcome key.

thumbUrl in report.ts now applies a storedName step that collapses runs of dashes (matching sanitize() on upload), so keys like entry--variant no longer produce links with -- while pr-media holds a single-dash name. SAFE_KEY also requires keys to start with a letter or digit so thumbBase + key cannot introduce an extra dash run.

Tests update expected URLs and add thumbnail links name the file pr-media.py stores, which runs the real Python sanitize() and asserts both the comment <img> and feed thumbnail URLs match.

Reviewed by Cursor Bugbot for commit 1ca6605. Bugbot is set up for automated code reviews on this repo. Configure here.

The gallery PR comment links <prefix><key> (agent-pane.docked-chat--working--...),
but pr-media.py's sanitize() collapses each run of dashes, so the stored file is
agent-pane.docked-chat-working-... and every inline thumbnail 404s (#18152, #18224).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 667f8c0d-d343-412d-aee8-55c56500e72b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

thumbUrl collapses dash runs in the key the way pr-media.py's sanitize() does,
so the comment's inline thumbnails point at the uploaded files. SAFE_KEY also
requires a leading letter or digit, so prefix plus key cannot form a new run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@teamleaderleo
teamleaderleo merged commit 247e140 into feat-cmux-next Oct 7, 2026
40 of 41 checks passed
@teamleaderleo
teamleaderleo deleted the fix/gallery-thumb-media-names branch October 7, 2026 08:38
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37597620459 at e39f213 failed: cmux-next checks (god files, concurrency, crash safety, l10n).
Those jobs last passed at 1aa7972. This pull request is one of 3 merged since: #18311, #18301, #18317.
If the failure is in your change, fix forward on feat-cmux-next. Pull requests run only the tiers their paths reach (docs/ci/cmux-next-tiers.md); label a batch PR full-ci to run them all before merging.

teamleaderleo added a commit that referenced this pull request Oct 7, 2026
* test(cmux-next): require no lone space dot at rest

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(cmux-next): draw no lone space dot at rest

With one space the sidebar drew a single dot above the footer. The bar
stays mounted, but a lone dot now draws only with the + on hover.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(cmux-next): Cmd-K under the open palette must not clear the terminal (red, cx-6so.46)

AppKit offers a key equivalent the key panel did not handle to the main
window too. The palette keeps the terminal's context bits, so the shell
window hook resolves Cmd-K to terminal.clear and runs it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test(cmux-next): a shell completion past its deadline answers a timeout (red, cx-6so.47)

respondToShellComplete maps timedOut to spawnFailed(0) ("Could not
start"). The completion gets an injectable timeout and the model holds
its completion, so a fake bash that sleeps proves the mapping.

The candidate tests use the shared 30 s test timeout: on a loaded fleet
Mac (aws-m4pro-3, load 56) a login bash passed the 4 s app deadline and
bashCompletesCommandsAndFiles failed with .timedOut on base 880b1a3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test(cmux-next): Cmd-Shift-G in a focused terminal is Ghostty's previous match

BrowserChromeKeysTests.shiftCommandGIsFindPreviousInABrowser was red on
the trunk since f28642f (bisect: green on 89e0a3e, red on
9bcce34). That commit made groupSelectedWorkspaces yield to a
focused terminal on purpose (decision K1 follow-up); the test still
expected the cmux action there. The test follows the decision.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(cmux-next): a key the open palette does not handle stays the palette's (cx-6so.46)

AppKit offers a key equivalent the key panel did not handle to the main
window behind it too. The palette keeps its terminal's context bits (its
commands act on that terminal), so the shell window hook ran Cmd-K as
terminal.clear, and the terminal, still its window's first responder,
could run its Ghostty cmd+k keybind.

KeyRouter.overlayHasKeys(focus): while any overlay (palette, sheet,
rename prompt, group editor) is open, the window hook runs no content
action, and ShellWindow passes on key equivalents while it is not the
key window, so nothing below the overlay takes the key. Menu items keep
their tier gate (system and navigation actions still work).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(cmux-next): a shell completion past its deadline answers shell.timed_out (cx-6so.47)

respondToShellComplete answered every failure but a missing folder as
spawnFailed(0), "Could not start", also when the shell started and only
passed the 4 s deadline. A timeout now answers code shell.timed_out with
"Completion timed out" (21 languages); folder and spawn failures keep
shell.failed with their own messages.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Home harness: the oracle builds the catalyst files upstream's appkit-native/project.yml lists (new upstream files no longer break the oracle)

* MessagesLab pin d5d6a18: Markdown rendering, selection model and custom rows (their catalyst files vendored), container-motion and tail-only updates; TranscriptAccess stays at bd65bbf (its rewrite needs unvendored drivers); new strings in all 21 app languages (needs_review); the oracle builds upstream's project.yml file list; the flight recorder test waits for the off-main frames file

* cmux-rd: red tests for the viewer's upstream media sender (C4b)

Core: UpstreamSender sends UpMedia frames the host reassembles, drops a
dependent frame without a keyframe, resends NACKed shards until the ack,
refuses other streams' feedback, lowers its target on a growing queue,
adds parity on loss, paces at the target and breaks the chain on a drop,
falls to the floor when the host is silent; audio packets are independent
and a lone shard is not padded. Engine: the sender recovers a lost shard
through the host's NACK. rd-ffi: the CmuxRdUpstream C ABI (ABI 3) on both
carriers.

* cmux-rd: the viewer's upstream media sender with congestion control (C4b)

cmux-rd-core::upstream::UpstreamSender sends microphone, camera and
screen share frames as UpMedia shards; the host's upstream feedback
drives the delay-gradient CongestionController (arrival times), loss
measurement (LossMeter moves from cmux-rd-engine to cmux-rd-core so both
directions share it) and adaptive parity, NACK resends from a bounded
history (32 frames, 2 MiB, 64 resends per feedback), acks that trim the
history, and keyframe requests on host recovery. A pacing budget at the
target bitrate (100 ms burst) drops frames instead of queueing; a drop
breaks the reference chain, so dependent frames wait for an independent
one. A host silent for 500 ms with a frame unacked drops the target to
the floor. Block FEC is optional (off for Opus audio).

The packetizer no longer pads a lone shard without parity (wire
compatible: receivers accept any length for a frame's only shard), so a
120-byte Opus packet costs 152 bytes instead of a full datagram.

cmux-rd-ffi ABI 3: CmuxRdUpstream (cmux_rd_upstream_new, free,
send_frame, on_datagram, pop_datagram, target_bps, set_path, stats),
CMUX_RD_PATH_*, CMUX_RD_UPSTREAM_MAX_QUEUED (4 MiB of untaken datagrams,
then new frames are dropped). Host feedback reaches Swift as a session's
datagram message and is offered to each sender.

* cmux-rd-ffi: red tests for per-kind upstream consent (C4b privacy condition)

A sender is created for one media kind (mic, camera, screen) and sends
nothing until the app grants that kind's consent: send_frame and
on_datagram return CMUX_RD_ERR_CONSENT and emit nothing; consent for
another kind is refused; revoking drops untaken datagrams; a new sender
starts without consent.

* cmux-rd-ffi: per-kind upstream consent; doc the unpadded lone-shard wire rule (C4b)

cmux_rd_upstream_new takes a media kind (CMUX_RD_MEDIA_MIC, CAMERA,
SCREEN) and starts without consent. cmux_rd_upstream_set_consent(kind,
granted) is the app's switch after an explicit user action; another
kind is CMUX_RD_ERR_INVALID. Without consent send_frame and on_datagram
return CMUX_RD_ERR_CONSENT (-8) and queue nothing (feedback still
updates the controller); revoking drops untaken datagrams; consent dies
with the handle. CmuxRdUpstreamStats gains consent (still 32 bytes).

plans/cmux-next/remote-desktop.md: a frame of one data shard and no
parity is sent unpadded; receivers accept it. Lane note: the C4b line
with the Swift slice's consent contract (user action per kind and
session, macOS permission prompt, visible indicator with stop, revoke at
session end, up_media cap only).

* images/cmux-vm: development boots agenttools5 (agent tools, cua-video refused); credential audit

Dev Worker CLOUD_FREESTYLE_SNAPSHOT auto8 -> cmuxnp-dev-vmimg-agenttools5
(sh-e64294bf57394cd397ba37951eeb6a52), Worker version 41e53360, dev-e2e
19/19 including the booted snapshot. Rollback to auto8 recorded in
channels/dev.json, cloud-automation.md 33 and the backend lane file.
Section 33 also records the credential audit and the cua-video check.

* test(acpmux): a chats_watch sent before the chat index starts gets served once it starts (red)

The app connects at launch; the daemon answered ready:false and never subscribed that connection, so the sidebar Chats list stayed empty.

* fix(acpmux): serve a chats_watch that arrives before the chat index starts

chats_watch without a running index registers a ready waiter (Hub::when_chats_ready). start_chats runs the waiters right after the index is set: each subscribes its connection and sends _acpmux/chats_lagged, so the client lists again. Found by the all-chats GUI proof: the app's feed connected at launch and stayed empty.

* ci: install web dependencies before the Cloud VM image lock tests (#18311)

The lock test imports smoke.ts, which reaches guest.ts and its freestyle
import, so every feat-cmux-next push run since db3743e failed with
"Cannot find package 'freestyle'". The job assumed no web dependency.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(gallery): link PR comment thumbnails by the name pr-media.py stores (#18301)

* test: gallery thumbnail links must name the file pr-media.py stores

The gallery PR comment links <prefix><key> (agent-pane.docked-chat--working--...),
but pr-media.py's sanitize() collapses each run of dashes, so the stored file is
agent-pane.docked-chat-working-... and every inline thumbnail 404s (#18152, #18224).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(gallery): link PR comment thumbnails by the name pr-media.py stores

thumbUrl collapses dash runs in the key the way pr-media.py's sanitize() does,
so the comment's inline thumbnails point at the uploaded files. SAFE_KEY also
requires a leading letter or digit, so prefix plus key cannot form a new run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(webviews): keep base green on the ui-rules ratchet growth from 7f67cf1 and eb59615 (#18317)

7f67cf1 added task checkbox roles in conversation/Markdown.tsx and
pages/markdown/editor.ts, and eb59615 added a keydown handler in
changes/treeMotionDom.ts, so "migrated page code has no raw roles..." fails
on feat-cmux-next. The two acpmux files go on the pending list for their
owners to clear. pages/markdown may not be pending (a migrated page), so the
editor's read-only ProseMirror task mark gets a ui-allow reason instead.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant