Repository navigation
Harden SSH LocalCommand fish reconnect regression - #3534
Conversation
The fake OpenSSH harness now executes the generated LocalCommand through fish instead of sh, so the regression covers the same local-login-shell failure mode reported in issue #3533. The existing shell-neutral OpenSSH wrapper remains the production invariant; this commit locks that behavior at the harness boundary before production cleanup. Constraint: Repository policy prefers behavior-level tests over source-text assertions Constraint: Keep WorkspaceSSHFishShellTests.swift below the untracked Swift file length threshold Confidence: high Scope-risk: narrow Directive: Keep LocalCommand regressions exercising the login-shell execution path, not only parser checks Tested: git diff --check Tested: python3 scripts/swift_file_length_budget.py --budget .github/swift-file-length-budget.tsv Tested: swiftc -typecheck CLI command files Not-tested: Local XCTest suite per repository policy
The reconnect and timing helpers build raw POSIX script bodies, while CMUXCLI+SSHCommandSupport owns the final OpenSSH LocalCommand value and wraps it with /bin/sh -c. Rename the local variables and helpers to make that boundary explicit so future reconnect work does not treat a script body as shell-neutral LocalCommand output. Constraint: OpenSSH may execute LocalCommand through the user's login shell, including fish Rejected: Wrap individual reconnect snippets again | the centralized OpenSSH helper already wraps LocalCommand and RemoteCommand values exactly once Confidence: high Scope-risk: narrow Directive: Future LocalCommand additions should pass script bodies to openSSHLocalCommandValue rather than emitting final OpenSSH option strings directly Tested: git diff --check Tested: python3 scripts/swift_file_length_budget.py --budget .github/swift-file-length-budget.tsv Tested: swiftc -typecheck CLI command files Not-tested: Local XCTest suite per repository policy
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
📝 WalkthroughWalkthroughThe PR updates SSH local command generation in ChangesFish Shell SSH LocalCommand Compatibility
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 12 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (12 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR hardens the SSH LocalCommand fish-shell reconnect path with two changes: the production code renames Confidence Score: 4/5Safe to merge — production changes are pure renames with no logic delta, and the test change correctly simulates fish login-shell execution of LocalCommand. The production code is a mechanical rename with no behavioral change. The test improvement is well-reasoned: moving the fish lookup to the top avoids running expensive setup before discovering fish is absent, and switching the fake SSH runner from /bin/sh to fish closes the gap between the test harness and real OpenSSH behavior. The one note is that the fix for this regression landed in a prior merged PR, so the failing-test-first commit structure required by the repo policy could not be demonstrated in CI. No files require special attention — cmux.swift changes are rename-only and the test change is straightforward. Important Files Changed
Sequence DiagramsequenceDiagram
participant CLI as cmux CLI
participant SR as deferredRemoteReconnectLocalCommandScript
participant ST as sshConnectionTimingLocalCommandScript
participant CLS as combinedLocalShellScript
participant LC as openSSHLocalCommandValue
participant SSH as OpenSSH
participant Fish as fish (login shell)
participant Sh as /bin/sh
CLI->>SR: build POSIX reconnect script body
SR-->>CLI: String (POSIX snippet)
CLI->>ST: build timing script body
ST-->>CLI: String (POSIX snippet)
CLI->>CLS: join snippets
CLS-->>CLI: combined POSIX body
CLI->>LC: wrap with /bin/sh -c + %% escape
LC-->>CLI: LocalCommand= value
CLI->>SSH: pass -o LocalCommand=...
SSH->>Fish: fish -c "/bin/sh -c '...'"
Fish->>Sh: exec /bin/sh -c '...'
Sh-->>Fish: exit
Fish-->>SSH: exit
Reviews (1): Last reviewed commit: "Make SSH LocalCommand script ownership e..." | Re-trigger Greptile |
Closes #3533.
Summary
openSSHLocalCommandValueowns the final/bin/sh -cwrapped LocalCommandRegression-test note
Current
mainalready includes the centralized/bin/sh -cOpenSSH LocalCommand wrapper from #3506, so the new test-hardening commit cannot demonstrate a red-first CI proof window against this base. This PR closes the remaining coverage gap by making the fake OpenSSH harness execute LocalCommand through fish instead of/bin/sh.Verification
git diff --checkpython3 scripts/swift_file_length_budget.py --budget .github/swift-file-length-budget.tsvswiftc -typecheck CLI command filesSHELL=$(command -v fish)with barecmux_localcommand_probe=okfails withfish: Unsupported use of =/bin/sh -c 'cmux_localcommand_probe=ok; ...'printslocal-command-ok\n- Tagged dev app:./scripts/reload.sh --tag issue-3533-ssh-localcommand-fish --launch\n- Tagged dev CLI/socket:CMUX_SOCKET_PATH=/tmp/cmux-debug-issue-3533-ssh-localcommand-fish.sock /tmp/cmux-cli ssh ... austinywang@Austins-MacBook-Pro, then remote command returnedCMUX_DEV_SSH_OK user=austinywang host=Austins-MacBook-Pro.local shell=/bin/zsh\n- Tagged dev log:remote.bootstrap.ready,remote.tty.bootstrap.ready, andremote.proxy.ready; nofish: Unsupported use of =orcmux_reconnect_cli=LocalCommand assignment errors\n\n## Not tested\n- Local XCTest suite per repo policy\n- CI still in progress; live dogfood was prioritized per latest request