Skip to content

Add devbox.new creator - #5677

Open
lawrencecchen wants to merge 3 commits into
mainfrom
feature-devbox-new
Open

lawrencecchen wants to merge 3 commits into
mainfrom
feature-devbox-new

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add a standalone /devbox creator page for devbox.new.
  • Rewrite devbox.new and www.devbox.new homepage requests to /devbox while preserving existing cmux proxy behavior.
  • Submit prompt text to POST /api/vm with a source marker and show the created VM id plus attach commands.

Verification

  • bun test tests/devbox-proxy.test.ts
  • bun run lint (passes with existing warnings outside this change)
  • VERCEL_ENV=preview bun run build
  • curl -fsS -H 'Host: devbox.new' http://localhost:4117/ renders devbox.new and the create form
  • unauthenticated POST /api/vm returns 401, which the page maps to sign-in guidance

Notes

The Cloud VM backend currently ignores initialPrompt; this page sends it for forward compatibility, but the current shipped behavior is create-first and attach from cmux with cmux vm attach <id> or cmux vm ssh <id>.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Medium Risk
Touches request routing for a new production host and triggers authenticated VM provisioning via /api/vm; scope is limited but mis-routing could affect devbox.new traffic.

Overview
Adds a devbox.new landing experience: a standalone /devbox route with its own layout/metadata and a client DevboxCreator form that POSTs to the existing /api/vm endpoint (optional initialPrompt, source: "devbox.new", idempotency header), surfaces auth/errors, and shows attach/SSH CLI hints after success.

Host routing is extended via shouldRewriteToDevbox and an early rewrite in proxy: requests to devbox.new / www.devbox.new on / or /devbox are rewritten to /devbox, while /api/* and sign-in paths are left alone. Unit tests cover the routing helper.

Reviewed by Cursor Bugbot for commit 1fed97b. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Adds a standalone /devbox creator and changes devbox.new and www.devbox.new homepages from the localized cmux site to it, while leaving /api/* and sign-in paths untouched. Users can optionally provide a prompt, create an authenticated Cloud VM, and receive its ID with cmux attach and SSH commands.

  • Sends POST /api/vm with an idempotency key and source: "devbox.new"; 401 responses link to sign-in and other errors are shown in the form.
  • The backend currently ignores initialPrompt, so the prompt is forwarded for compatibility but does not affect provisioning yet.
  • Adds canonical page metadata and middleware tests covering host rewrites, query preservation, auth paths, and existing redirects.

Written for commit 592efd1. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

Release Notes

  • New Features
    • Launched a new devbox creation experience on devbox.new domain where users can submit a form to create a devbox and receive connection commands upon successful creation.

@vercel

vercel Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jun 9, 2026 5:09am
cmux-staging Building Building Preview, Comment Jun 9, 2026 5:09am

@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 5 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e81d9f96-0c57-414d-9b10-b166d1554393

📥 Commits

Reviewing files that changed from the base of the PR and between 1fed97b and 592efd1.

📒 Files selected for processing (4)
  • web/app/devbox/devbox-creator.tsx
  • web/app/devbox/layout.tsx
  • web/proxy.ts
  • web/tests/devbox-proxy.test.ts
📝 Walkthrough

Walkthrough

The PR introduces a new devbox.new domain and page that lets users create devboxes through a web form. It adds client-side routing logic to detect devbox.new requests and rewrite them to /devbox, integrates this check into the Next.js middleware, mounts a new page route with metadata and layout, and implements an interactive DevboxCreator form that submits to /api/vm with error handling and success confirmation.

Changes

Devbox.new feature

Layer / File(s) Summary
Devbox host routing detection
web/devbox-routing.ts
Exports shouldRewriteToDevbox(host, pathname) that normalizes the host (removing port and lowercasing), allowlists devbox.new and www.devbox.new, and returns true only for / and /devbox paths.
Middleware integration of devbox routing
web/proxy.ts
Integrates shouldRewriteToDevbox into the proxy middleware to rewrite matching requests to /devbox before other redirect logic. Comment describing the changelog redirect path is also updated for consistency.
Routing verification tests
web/tests/devbox-proxy.test.ts
Test suite validates that devbox.new host variants rewrite / requests, that non-devbox hosts and protected paths (/api/vm, /handler/sign-in) do not rewrite, and that :443 port suffix is properly stripped.
Devbox page route structure
web/app/devbox/layout.tsx, web/app/devbox/page.tsx
Next.js layout exports metadata (title, OG tags, canonical URL) and global styling with Geist fonts; page renders a centered layout with internal home link, external cmux.com link, and DevboxCreator component mount.
DevboxCreator form and submission
web/app/devbox/devbox-creator.tsx
React component that renders a textarea form for devbox creation, manages prompt, isCreating, created, and error state, generates per-request idempotency keys, submits trimmed prompt and source: "devbox.new" to /api/vm, parses responses and maps HTTP errors to user-facing messages (special-case for 401), and displays devbox ID, optional provider, and copyable cmux vm attach/cmux vm ssh commands on success.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (2 errors, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error Lines 34-36 expose unsanitized backend error fields (body?.message, body?.action, body?.reason) to users, violating the rule against raw upstream error messages. Map all non-401 errors to safe generic messages like "Devbox creation failed. Try again." and log backend details only to internal telemetry, not user-facing text.
Cmux Full Internationalization ❌ Error The PR adds hardcoded English user-facing strings in devbox components without next-intl and no message entries in web/messages/ for any of the 20 supported locales. Use next-intl in DevboxCreator, page, and layout; add localized message entries to all web/messages/*.json files for every supported locale.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (18 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Add devbox.new creator' accurately and concisely describes the main feature introduced in the pull request: a new creator page for the devbox.new domain.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PR contains only TypeScript/React web changes; no Swift code present. Custom check for Swift actor isolation is not applicable to this PR.
Cmux Swift Blocking Runtime ✅ Passed This PR contains only TypeScript/JavaScript files (web/.tsx, web/.ts) and no Swift files. The check for Swift blocking runtime does not apply.
Cmux Expensive Synchronous Load ✅ Passed PR contains only TypeScript/web files (devbox creator, routing, proxy); custom check targets Swift expensive sync loaders—not applicable here.
Cmux Cache Substitution Correctness ✅ Passed PR contains no cache substitution, persistence, history, undo, or snapshot logic. All changes are transient UI state and routing logic with fresh API calls; check not applicable.
Cmux No Hacky Sleeps ✅ Passed No hacky sleeps, fixed delays, polling, or wall-clock waits found in any non-test TypeScript/JavaScript code. All async operations use proper event-driven patterns, and animation is CSS-based.
Cmux Algorithmic Complexity ✅ Passed New code uses fixed-size Set (2 hosts) with O(1) lookups, simple state management, and no collection iteration or batch rescans.
Cmux Swift Concurrency ✅ Passed This PR contains only TypeScript/JavaScript/React web code (6 files in web/ directory). No Swift code is modified; Swift concurrency check does not apply.
Cmux Swift @Concurrent ✅ Passed PR contains only TypeScript/React web files (.tsx, .ts) in web/app/devbox/ and web/ directories; no Swift code changes to evaluate against swift-concurrent-annotation.md rule.
Cmux Swift File And Package Boundaries ✅ Passed PR contains only TypeScript/React web code (no Swift files); check for Swift file/package boundaries is not applicable.
Cmux Swift Logging ✅ Passed Swift logging check is not applicable: PR contains only TypeScript/JavaScript web UI changes with no Swift code modifications.
Cmux Swiftui State Layout ✅ Passed Check requires SwiftUI code review; PR contains only web React/TypeScript files (devbox-creator.tsx, layout.tsx, page.tsx, devbox-routing.ts, proxy.ts, devbox-proxy.test.ts). Not applicable.
Cmux Architecture Rethink ✅ Passed PR contains no Swift code changes; all modifications are in TypeScript/React (web/ directory). Swift architecture check does not apply.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed This PR contains only web application code (TypeScript/React) and no Swift changes, so the Swift auxiliary window close shortcuts check is not applicable.
Cmux Source Artifacts ✅ Passed All changed files are intentional source code and tests: React components, Next.js layouts/pages, utility modules, and test files. None match the artifact patterns specified in the rule.
Description check ✅ Passed Pull request description addresses the required template sections: Summary (what changed and why), Verification (how tested), but lacks Demo Video link, Review Trigger comment block, and explicit Checklist completion.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature-devbox-new

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1fed97b. Configure here.


setIsCreating(true);
setError(null);
setCreated(null);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Duplicate create race on submit

Medium Severity

The create handler only blocks repeat submits with isCreating state, which updates on the next render. A second submit in the same tick (for example a quick double-click) can run before that update and send another POST /api/vm with a fresh idempotency-key, provisioning two devboxes for one action.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 1fed97b. Configure here.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1fed97bb9e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

<div className="w-full">
<div className="mb-8 text-center">
<h1 className="text-3xl font-semibold tracking-tight sm:text-5xl">
Create a devbox

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Localize the devbox creator copy

AGENTS.md requires every user-facing web string to be localized across the supported message catalogs (web/messages/en.json and web/messages/ja.json). This new devbox page hard-codes visible copy such as the heading, prompt text, labels, buttons, errors, and metadata, so the Japanese surface cannot be translated and the required localization audit cannot pass; please move the copy into localized messages and add both locales.

Useful? React with 👍 / 👎.

@greptile-apps

greptile-apps Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds a standalone /devbox creator page served under the devbox.new hostname, wiring up host-based rewriting in the Next.js 16 proxy layer and migrating the proxy function export to the correct Next.js 16 export function proxy convention.

  • devbox-routing.ts + proxy.ts: A new shouldRewriteToDevbox helper rewrites devbox.new/ and devbox.new/devbox to the /devbox route before any existing redirect or i18n logic runs. The host normalisation (port-strip, lowercase) is correct and well-tested.
  • devbox-creator.tsx: Client component that POSTs to /api/vm with an idempotency key, maps the 401 response to a sign-in prompt, and displays the VM id with attach commands on success.
  • layout.tsx + page.tsx: Standalone root layout for the /devbox segment, isolated from the main app's providers and i18n setup — none of the new user-visible strings are routed through next-intl or present in any of the 20 locale message files under web/messages/.

Confidence Score: 4/5

The routing and proxy wiring are solid, but the new page ships every user-visible string as hardcoded English with no next-intl integration, leaving all 20 non-English locales with an untranslated UI.

The devbox-routing logic, the proxy rewrite ordering, idempotency key handling, and the export rename are all correct. The one concrete gap is that devbox-creator.tsx, layout.tsx, and page.tsx introduce a production user-facing surface with no entries in any of the 20 locale message files and no useTranslations calls — a pattern the project requires for every new web surface.

web/app/devbox/devbox-creator.tsx and web/app/devbox/layout.tsx — all new user-visible strings and metadata need next-intl keys added across every locale in web/messages/.

Important Files Changed

Filename Overview
web/app/devbox/devbox-creator.tsx New client component for the devbox creation form; all user-visible strings are hardcoded in English with no next-intl integration, violating the project's full-internationalization rule across 20 supported locales.
web/app/devbox/layout.tsx Standalone root layout for the /devbox route segment; sets up fonts and metadata. Metadata title and description are hardcoded English and not present in locale message files.
web/app/devbox/page.tsx Simple page shell that renders DevboxCreator; link text is static English but minimal.
web/devbox-routing.ts Pure routing helper; correctly normalises the host (strips port, lowercases) and matches devbox.new / www.devbox.new for / and /devbox paths. Well-tested.
web/proxy.ts Next.js 16 proxy (middleware) file; adds the devbox rewrite before existing redirect logic. The rename from export default function middleware to export function proxy is the correct Next.js 16 codemod convention.
web/tests/devbox-proxy.test.ts Unit tests for shouldRewriteToDevbox covering the devbox.new, www.devbox.new, port-qualified, and non-matching host cases. Good coverage.

Sequence Diagram

sequenceDiagram
    participant Browser
    participant Proxy as proxy.ts (Next.js 16 middleware)
    participant DevboxPage as /devbox page
    participant API as /api/vm

    Browser->>Proxy: GET devbox.new/
    Proxy->>Proxy: shouldRewriteToDevbox("devbox.new", "/") → true
    Proxy-->>DevboxPage: rewrite to /devbox (host unchanged)
    DevboxPage-->>Browser: Render DevboxCreator

    Browser->>API: POST devbox.new/api/vm (excluded from matcher)
    API-->>Browser: "200 { id, provider, ... } or 401"

    Browser->>Browser: Display VM id + attach commands
Loading

Reviews (1): Last reviewed commit: "feat: add devbox.new creator" | Re-trigger Greptile

Comment on lines +29 to +38
function userMessage(status: number, body: VmErrorBody | null) {
if (status === 401) {
return "Sign in first, then create the devbox again.";
}

const pieces = [body?.message, body?.action ?? body?.reason].filter(
Boolean,
);
return pieces.join(" ") || `Devbox create failed with status ${status}.`;
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Hardcoded English strings not routed through next-intl

Every user-visible string in this file — the heading ("Create a devbox"), the subheading, the textarea placeholder ("What should this devbox work on?"), the button labels ("Create devbox", "Creating..."), the sign-in link, the success section heading ("Devbox created"), the field labels ("ID", "Provider"), and the two error messages — are hardcoded in English with no call to useTranslations or any next-intl API. The project already supports 20 locales defined in web/i18n/routing.ts, and no corresponding keys were added to any file under web/messages/. The same applies to the <title> and description metadata in layout.tsx. A visitor whose browser language is Japanese, Arabic, or any non-English locale will receive a fully English UI, which violates the cmux-full-internationalization rule that applies to every new production user-facing surface.

Rule Used: Flag production user-facing text that is not fully... (source)

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/app/devbox/devbox-creator.tsx`:
- Around line 29-38: Replace hardcoded strings in userMessage with localized
messages: import and call useTranslations("devbox") in the component that calls
userMessage, change userMessage(status: number, body: VmErrorBody | null) to
accept a translator (or move its logic into the component) and map status/body
to locale keys (e.g. t("errors.unauthenticated") for 401,
t("errors.<mapped_key>") for known API error codes or body.action/body.reason),
avoid directly surface body.message/action/reason to users, and fall back to
t("errors.generic", { status }) when no mapping exists; ensure translation keys
(errors.unauthenticated, errors.generic, and specific mapped keys) are added to
the devbox namespace in your i18n messages and routing.

In `@web/app/devbox/layout.tsx`:
- Around line 15-29: The exported metadata object (metadata) and the hardcoded
lang="en" in web/app/devbox/layout.tsx must be made locale-aware: load the
current locale from your routing helper (web/i18n/routing.ts) or next/navigation
params, fetch localized title/description from web/messages/<locale> (or the app
i18n utility), and build metadata (title, description,
openGraph.url/siteName/alternates) and the html lang attribute dynamically using
those localized strings and the active locale; update the Layout component
(where metadata and lang are used) and ensure you populate
metadata.alternates/metadataBase per-locale and cover all locales listed in
web/i18n/routing.ts and corresponding web/messages/* entries.

In `@web/app/devbox/page.tsx`:
- Around line 8-18: The header currently hardcodes user-facing strings
("devbox.new" inside the Link and "cmux" inside the anchor) in
web/app/devbox/page.tsx; replace these literals by loading the locale messages
and using the appropriate message keys (e.g., a key for the page title and one
for the partner link) via your i18n helper used elsewhere in the app, update
web/i18n/routing.ts to include the new route’s message keys if required, and add
the corresponding translations in every file under web/messages/ for each locale
so the Link and anchor render locale-backed text instead of hardcoded strings.

In `@web/tests/devbox-proxy.test.ts`:
- Around line 5-15: The test suite for shouldRewriteToDevbox is missing coverage
for the explicit "/devbox" allowlist branch in web/devbox-routing.ts; add
positive assertions that shouldRewriteToDevbox("devbox.new", "/devbox") (and
similarly for "www.devbox.new" and "devbox.new:443") return true so the explicit
branch is exercised and protected from regression.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 1d597cbe-d71e-4bc9-bbee-6014583a7994

📥 Commits

Reviewing files that changed from the base of the PR and between 69a93a5 and 1fed97b.

📒 Files selected for processing (6)
  • web/app/devbox/devbox-creator.tsx
  • web/app/devbox/layout.tsx
  • web/app/devbox/page.tsx
  • web/devbox-routing.ts
  • web/proxy.ts
  • web/tests/devbox-proxy.test.ts

Comment on lines +29 to +38
function userMessage(status: number, body: VmErrorBody | null) {
if (status === 401) {
return "Sign in first, then create the devbox again.";
}

const pieces = [body?.message, body?.action ?? body?.reason].filter(
Boolean,
);
return pieces.join(" ") || `Devbox create failed with status ${status}.`;
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

Localize all form/error/success copy and map API errors to locale keys.

Line 31, Line 37, Line 79, and Line 89-Line 155 hardcode user-visible strings. Also, Line 34-Line 37 directly surfaces backend message/action/reason, which are not locale-resolved in this client flow. This route should read UI copy from next-intl (or equivalent) and map API error codes to localized keys for every supported locale.

Suggested direction
const t = useTranslations("devbox");

setError(t("errors.unauthenticated"));
// map body.error/status => t("errors.<key>")
<h1>{t("title")}</h1>
<textarea placeholder={t("promptPlaceholder")} />
<button>{isCreating ? t("creating") : t("create")}</button>

As per coding guidelines: “Web UI, API response copy, and user-facing web data must use locale-specific sources and be represented across all locales in web/i18n/routing.ts and web/messages/.”

Also applies to: 79-79, 85-159

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/app/devbox/devbox-creator.tsx` around lines 29 - 38, Replace hardcoded
strings in userMessage with localized messages: import and call
useTranslations("devbox") in the component that calls userMessage, change
userMessage(status: number, body: VmErrorBody | null) to accept a translator (or
move its logic into the component) and map status/body to locale keys (e.g.
t("errors.unauthenticated") for 401, t("errors.<mapped_key>") for known API
error codes or body.action/body.reason), avoid directly surface
body.message/action/reason to users, and fall back to t("errors.generic", {
status }) when no mapping exists; ensure translation keys
(errors.unauthenticated, errors.generic, and specific mapped keys) are added to
the devbox namespace in your i18n messages and routing.

Source: Coding guidelines

Comment thread web/app/devbox/layout.tsx
Comment on lines +15 to +29
export const metadata: Metadata = {
title: "devbox.new",
description: "Create a new cmux devbox from a prompt.",
metadataBase: new URL("https://devbox.new"),
alternates: {
canonical: "https://devbox.new",
},
openGraph: {
title: "devbox.new",
description: "Create a new cmux devbox from a prompt.",
url: "https://devbox.new",
siteName: "devbox.new",
type: "website",
},
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

Localize route metadata and language attributes.

Line 16-Line 27 and Line 37 hardcode English metadata and lang="en", so this route cannot reflect active locale. For web/** user-facing surfaces, metadata and language context should come from locale-specific sources and be covered across all locales configured in web/i18n/routing.ts and web/messages/*.

As per coding guidelines: “Web UI, API responses, and user-facing data must use locale-specific sources … update all locales listed in web/i18n/routing.ts and every matching file in web/messages/,” and “All user-facing strings must be localized.”

Also applies to: 37-37

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/app/devbox/layout.tsx` around lines 15 - 29, The exported metadata object
(metadata) and the hardcoded lang="en" in web/app/devbox/layout.tsx must be made
locale-aware: load the current locale from your routing helper
(web/i18n/routing.ts) or next/navigation params, fetch localized
title/description from web/messages/<locale> (or the app i18n utility), and
build metadata (title, description, openGraph.url/siteName/alternates) and the
html lang attribute dynamically using those localized strings and the active
locale; update the Layout component (where metadata and lang are used) and
ensure you populate metadata.alternates/metadataBase per-locale and cover all
locales listed in web/i18n/routing.ts and corresponding web/messages/* entries.

Source: Coding guidelines

Comment thread web/app/devbox/page.tsx
Comment on lines +8 to +18
<header className="flex items-center justify-between gap-4 text-sm">
<Link href="/" className="font-semibold tracking-tight">
devbox.new
</Link>
<a
href="https://cmux.com"
className="text-muted transition-colors hover:text-foreground"
>
cmux
</a>
</header>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

Move page header copy to locale-backed messages.

Line 10 and Line 16 introduce user-facing text as hardcoded literals in JSX. This bypasses the locale message source and leaves the new /devbox page incomplete for non-default locales.

As per coding guidelines: “Web UI … must use locale-specific sources … and update all locales listed in web/i18n/routing.ts and every matching file in web/messages/.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/app/devbox/page.tsx` around lines 8 - 18, The header currently hardcodes
user-facing strings ("devbox.new" inside the Link and "cmux" inside the anchor)
in web/app/devbox/page.tsx; replace these literals by loading the locale
messages and using the appropriate message keys (e.g., a key for the page title
and one for the partner link) via your i18n helper used elsewhere in the app,
update web/i18n/routing.ts to include the new route’s message keys if required,
and add the corresponding translations in every file under web/messages/ for
each locale so the Link and anchor render locale-backed text instead of
hardcoded strings.

Source: Coding guidelines

Comment on lines +5 to +15
test("rewrites the devbox.new homepage to the devbox creator", () => {
expect(shouldRewriteToDevbox("devbox.new", "/")).toBe(true);
expect(shouldRewriteToDevbox("www.devbox.new", "/")).toBe(true);
expect(shouldRewriteToDevbox("devbox.new:443", "/")).toBe(true);
});

test("does not rewrite cmux.com or API paths", () => {
expect(shouldRewriteToDevbox("cmux.com", "/")).toBe(false);
expect(shouldRewriteToDevbox("devbox.new", "/api/vm")).toBe(false);
expect(shouldRewriteToDevbox("devbox.new", "/handler/sign-in")).toBe(false);
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial | ⚡ Quick win

Add coverage for the explicit /devbox allowlist branch.

Line 6-9 only verifies /, but shouldRewriteToDevbox also explicitly returns true for /devbox (web/devbox-routing.ts Line 6). Add a positive assertion for that branch to prevent silent regression.

Suggested test diff
 describe("devbox.new host routing", () => {
   test("rewrites the devbox.new homepage to the devbox creator", () => {
     expect(shouldRewriteToDevbox("devbox.new", "/")).toBe(true);
     expect(shouldRewriteToDevbox("www.devbox.new", "/")).toBe(true);
     expect(shouldRewriteToDevbox("devbox.new:443", "/")).toBe(true);
+    expect(shouldRewriteToDevbox("devbox.new", "/devbox")).toBe(true);
   });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/tests/devbox-proxy.test.ts` around lines 5 - 15, The test suite for
shouldRewriteToDevbox is missing coverage for the explicit "/devbox" allowlist
branch in web/devbox-routing.ts; add positive assertions that
shouldRewriteToDevbox("devbox.new", "/devbox") (and similarly for
"www.devbox.new" and "devbox.new:443") return true so the explicit branch is
exercised and protected from regression.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Fleet instruction update for head b6184d955914e13dcc253946a69f5d4ef60e8b04: this PR is classified other. No macOS build tag is claimed. The current controller app recipe does not establish iOS/test readiness; that requires the appropriate validated recipe. Use cmux-ci for supported jobs, retain the returned ID and receipt, and wait on the same ID after any timeout. Do not use retired maclease allocation or post credentials. Exact-head tags will be posted only after the applicable build succeeds.

@teamleaderleo teamleaderleo added area: cloud Cloud machines and workspaces, relay transport ready-to-land Reviewed and ready to land when CI is green S2: major A crash, hang, lost state, broken connection, or a regression on a path people use labels Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

CI failure attribution

CI passes on 592efd1f05 (run 36746079667 attempt 1).

Written by scripts/ci/classify_failures.py (ci-failure-attribution.yml); signatures are its SIGNATURES table. A machine verdict is the runner's fault, not this PR's.

@teamleaderleo

Copy link
Copy Markdown
Collaborator

This is red for a reason that has nothing to do with the change. Both this and #5341 fail only guards / workflow-guard-tests / preflight, on the same ten files, none of which either pull request touches:

Python test execution registry validation failed:
  - tests/test_cli_current.py: newly added tests may not enter the legacy migration lane
  - tests/test_cli_glaeda_execution.py: ...
  ... eight more
warning: could not read the base registry at 9bf6cb8c9421:
  Command '['git','show','9bf6cb8c9421:tests/test-execution.toml']' returned non-zero exit status 128

Those ten files and tests/test-execution.toml all arrived together on main in 224327b55a07 on 2026-09-24. They are main's, in main's legacy lane.

The cause is .github/workflows/ci-guards.yml:262, which passes github.event.pull_request.base.sha as the baseline. That field is not main's current tip, it is the base tip recorded when the branch was last synchronized, and here it is thirteen days stale:

value date
base.sha reported for this PR 9bf6cb8c9421 2026-09-17
origin/main 6d7ad149121a 2026-09-30

This PR was updated today, so that is not staleness from sitting idle. And because the branch has merged main in since, 9bf6cb8c9421 is an ancestor of its head, so git merge-base base_sha HEAD collapses to base.sha itself and the guard ends up diffing 2026-09-17 to HEAD. Everything main added in that window, including 224327b55a07, is attributed to this pull request.

Verified against the real module in a scratch repo, driving it from both inputs:

newly_added_tests(stale base.sha) -> ['tests/test_mine.py', 'tests/test_theirs.py']   wrong
newly_added_tests(main tip)       -> ['tests/test_mine.py']                            right

So the validator is correct and is being handed a bad baseline. A fix is in flight on fix/registry-newly-added-after-catch-up: resolve base.ref at run time and pass what it resolves to, plus a workflow-level test so nobody puts base.sha back. Once it lands, this PR should go green without you touching anything. Nothing for you to do here, and worth not chasing it as a problem with your change.

Note ci-status and guards / Guard status are just the cascade from that one step. web-validation on #5341 is a separate and much older failure.

— Raindrop g2 🫧 / Run: run_worker_20260930_3fc64ba6

This branch was successfully deployed

1 active (outdated) deployment
Preview – cmux — 1fed97bb Deployed Jun 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: cloud Cloud machines and workspaces, relay transport ready-to-land Reviewed and ready to land when CI is green S2: major A crash, hang, lost state, broken connection, or a regression on a path people use

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants