Skip to content

cmux ssh --via tsh: interactive Teleport transport (CLI + deep links) - #6125

Open
4thel00z wants to merge 3 commits into
manaflow-ai:mainfrom
4thel00z:ssh-via-tsh
Open

4thel00z wants to merge 3 commits into
manaflow-ai:mainfrom
4thel00z:ssh-via-tsh

Conversation

@4thel00z

@4thel00z 4thel00z commented Jun 14, 2026 •

Copy link
Copy Markdown

Summary

Adds an explicit, opt-in Teleport (tsh) SSH transport to cmux ssh, exposed consistently across every shared entrypoint. --via tsh (default ssh) opens a workspace whose terminal execs tsh ssh <dest> directly — interactive-only, with no cmux remote daemon (no relay, no cmuxd-remote, no workspace.remote.configure).

tsh cannot honor the OpenSSH options the relay depends on (RemoteCommand, ControlMaster, SetEnv, LocalCommand, -i, -tt), so the emitted command is minimal: binary, -p, -A (when ForwardAgent), -o passthroughs, destination, and any -- remote args. The OpenSSH path is left completely untouched.

Entrypoints (one shared path)

  • CLI: cmux ssh --via <ssh|tsh> user@node + runInteractiveTeleportSSH (localized --via help).
  • Deep links: via query param on the cmux scheme (cmux://ssh?host=…&via=tsh) and standard ssh://admin@node?via=tsh, emitting --via tsh through CmuxSSHURLRequest.cliArguments. New localized invalidTransport parse error.
  • Web docs: --via flag row + via deep-link param (en/ja messages).
  • Sidebar: no SSH-connect action exists to wire (sidebar.showSSH is display-only); noted, not silently built.

Commits (red → green)

  1. Failing test only — the CLI integration test; red because the pre-impl CLI rejects the unknown --via flag.
  2. Implementation — turns it green; adds URL-scheme parsing tests too.

Testing

cmux-unit locally: CLI integration test + 4 new CmuxSSHURLRequestTests pass (57 in that class, 0 failures).

Notes / limitations

  • Interactive-only: no port-forward detection, browser egress, reconnect, or shipped terminfo for --via tsh workspaces.
  • docs/ssh-teleport.md documents a future tsh ssh -R relay path — the key open question is whether the target Teleport version/cluster supports remote (-R) forwarding (verify empirically first).

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Summary by cubic

Adds an opt‑in Teleport SSH transport to cmux ssh via --via tsh and deep links. It opens a workspace that execs tsh ssh for an interactive session with no relay or cmuxd-remote, and now fails fast if --identity is passed.

  • New Features

    • CLI: --via <ssh|tsh> (default ssh). --via tsh builds a minimal tsh ssh command (-p, -A when requested, -o passthroughs, destination, -- args); OpenSSH path is unchanged.
    • Deep links: support via=tsh in cmux://ssh and ssh:// URLs; invalid values show a localized error. All links funnel through CmuxSSHURLRequest.cliArguments which emits --via tsh.
    • Docs/UI: add --via and via param to SSH docs and web messages (en/ja); new docs/ssh-teleport.md explains behavior and future -R investigation.
    • Tests: add CLI integration and URL parsing tests for tsh (use of tsh ssh, no workspace.remote.configure/relay); add regression test asserting --via tsh rejects --identity.
    • Limitations: interactive-only (no port-forward detection, browser egress, or reconnect).
  • Bug Fixes

    • --via tsh rejects --identity with a clear error and performs no RPC, avoiding silent auth mismatches.

Written for commit bf95a8b. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added SSH transport selection via --via <ssh|tsh> (default ssh) to route connections via OpenSSH or Teleport’s tsh.
    • Added support for via in SSH deep links.
    • Teleport-based SSH now runs as an interactive session when selected.
  • Bug Fixes
    • Improved error handling for invalid via/transport values with localized messaging.
  • Documentation
    • Added/expanded SSH Teleport guide and CLI help examples.
  • Localization
    • Updated localized SSH help/flag text and added new via/deep-link strings.
  • Tests
    • Added unit and integration coverage for the ssh --via tsh flows.

4thel00z added 2 commits June 14, 2026 19:11
The test drives the bundled CLI with `ssh --via tsh --no-focus` and asserts
it opens a workspace running `tsh ssh` with no relay wiring (single
workspace.create, no workspace.remote.configure, no OpenSSH-only options in
initial_command). Without the implementation the CLI rejects the unknown
--via flag and exits non-zero, so this commit is red on CI.
…links

Adds an explicit, opt-in Teleport transport to cmux ssh. --via tsh (default
ssh) opens a workspace whose terminal execs `tsh ssh <dest>` directly:
interactive-only, with no cmux remote daemon (no relay, no cmuxd-remote, no
workspace.remote.configure). tsh cannot honor the OpenSSH options the relay
depends on (RemoteCommand, ControlMaster, SetEnv, LocalCommand, -i, -tt), so
the emitted command is minimal: binary, -p, -A (when ForwardAgent), -o
passthroughs, destination, and any -- remote args.

Wired through every shared entrypoint:
- CLI: --via <ssh|tsh> flag + runInteractiveTeleportSSH (CLI/cmux.swift),
  localized --via help text.
- Deep links: via query param on the cmux scheme (cmux://ssh?...&via=tsh) and
  the standard ssh:// scheme, emitting --via tsh through CmuxSSHURLRequest's
  shared cliArguments path. New invalidTransport parse error (localized).
- Web docs: --via flag row + via deep-link param (en/ja messages).

The sidebar has no SSH-connect action to wire (sidebar.showSSH is a
display-only toggle for already-remote workspaces).

Tests: URL-scheme parsing (cmux + standard schemes, default, invalid value);
the prior commit's CLI integration test goes green here. See
docs/ssh-teleport.md for the tsh ssh -R relay investigation.
Copilot AI review requested due to automatic review settings June 14, 2026 17:37
@vercel

vercel Bot commented Jun 14, 2026

Copy link
Copy Markdown

@4thel00z is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Jun 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: aceabec3-f607-427e-946d-76bf7b0c56f0

📥 Commits

Reviewing files that changed from the base of the PR and between 320f541 and bf95a8b.

📒 Files selected for processing (2)
  • CLI/cmux.swift
  • cmuxTests/VMSSHCommandTests.swift

📝 Walkthrough

Walkthrough

Adds Teleport tsh SSH transport support to cmux via a new --via <ssh|tsh> CLI flag and via URL query parameter. When --via tsh is selected, the existing OpenSSH relay pipeline is bypassed and a new runInteractiveTeleportSSH path creates a workspace with tsh ssh as the command. Includes URL parsing, error handling, localization, tests, and documentation.

Changes

Teleport tsh SSH Transport

Layer / File(s) Summary
Transport type contracts and SSHCommandOptions field
Sources/CmuxSSHURLRequest.swift, CLI/cmux.swift
CmuxSSHURLTransport (openssh/teleport), SSHTransport enum, CmuxSSHURLParseError.invalidTransport, and SSHCommandOptions.transport field with initialization are introduced.
URL via query parsing and CLI argument generation
Sources/CmuxSSHURLRequest.swift
via is added to both cmux and ssh:// URL query allowlists; parsedTransport(in:) maps tsh/teleport and ssh/openssh values (case-insensitive) and fails on unknown inputs; CmuxSSHURLRequest stores the result and emits --via tsh in generated CLI arguments when transport is .teleport.
--via flag parsing and routing to Teleport path
CLI/cmux.swift
--via argument parsing validates and maps ssh|openssh to .openssh and tsh|teleport to .teleport; wires transport into SSHCommandOptions; when transport is .teleport, early branching routes to runInteractiveTeleportSSH instead of the relay pipeline.
Teleport workspace execution and payload construction
CLI/cmux.swift
runInteractiveTeleportSSH calls workspace.create with ssh_command/ssh_startup_command set to exec tsh ssh <destination>, conditionally selects the workspace unless --no-focus, sets transport=tsh in the payload, prints JSON or formatted success line, and rejects --identity flag.
Error message handling and localization
Sources/AppDelegate+CmuxSSHURL.swift, Resources/Localizable.xcstrings, CLI/cmux.swift
cmuxSSHURLParseErrorMessage handles invalidTransport with a localized formatted string; the dialog.sshURL.error.invalidTransport key with en/ja translations is added; cmux ssh help text across locales gains the --via flag documentation and a tsh example.
URL parsing and CLI integration tests
cmuxTests/CmuxSSHURLRequestTests.swift, cmuxTests/VMSSHCommandTests.swift
Four CmuxSSHURLRequestTests cases cover via=tsh recognition, default .openssh, standard ssh:// transport, and invalid via rejection. testSSHViaTshRejectsIdentityOption verifies early failure with --identity. testSSHViaTshOpensInteractiveWorkspaceWithoutRelay verifies workspace.create is the only RPC, initial_command contains tsh ssh, and OpenSSH-only arguments are absent.
Developer documentation and web UI i18n
docs/ssh-teleport.md, web/app/[locale]/docs/ssh/page.tsx, web/messages/en.json, web/messages/ja.json
docs/ssh-teleport.md describes the interactive-only tsh path, its limitations, and a future relay design. Web SSH docs gain --via and via rows in flag and deep-link parameter tables, with en/ja flagVia and deepLinkVia translation strings.

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant CLI as cmux ssh
  participant Parser as Argument Parser
  participant Router as Transport Router
  participant Teleport as runInteractiveTeleportSSH
  participant RPC as workspace.create RPC

  User->>CLI: cmux ssh user@host --via tsh
  CLI->>Parser: parse --via tsh
  Parser-->>CLI: SSHCommandOptions{transport: .teleport}
  CLI->>Router: check transport value
  Router->>Teleport: runInteractiveTeleportSSH(options)
  Teleport->>RPC: workspace.create(ssh_command="tsh ssh user@host", transport="tsh")
  RPC-->>Teleport: workspace ID + response
  Teleport-->>User: print formatted success or JSON
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • manaflow-ai/cmux#4935: Modifies Sources/CmuxSSHURLRequest.swift ssh:// URL parsing with query parameter restrictions that overlaps with this PR's via query parameter handling.
  • manaflow-ai/cmux#5301: Extends SSHCommandOptions and modifies workspace payload construction in CLI/cmux.swift for agent forwarding, similar to how this PR adds transport support.

Suggested reviewers

  • lawrencecchen

Poem

🐇 Hop hop, a new tunnel appears,
--via tsh now shifts the gears!
No OpenSSH relay, just tsh in line,
A Teleport workspace, fresh and fine.
The bunny types fast, the workspace is made—
Interactive sessions, all freshly displayed! 🌿


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (2 errors, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error The error message in CLI/cmux.swift line 8030 "ssh: --via tsh does not support --identity (Teleport authenticates via 'tsh login')..." exposes provider auth implementation details, violating the ru... Remove the parenthetical auth implementation detail. Use: "ssh: --via tsh does not support --identity. Remove --identity or use --via ssh."
Cmux Full Internationalization ❌ Error Web UI strings docs.ssh.flagVia and docs.ssh.deepLinkVia added to en.json and ja.json only, missing in 18 other locales (ar, bs, da, de, es, fr, it, km, ko, no, pl, pt-BR, ru, th, tr, uk, zh-CN... Add flagVia and deepLinkVia translations to all 20 locale files in web/messages/ matching the en/ja values or provide translations.
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (18 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding an interactive Teleport transport via --via tsh to cmux ssh with support for CLI and deep links.
Description check ✅ Passed The description covers the Summary and Testing sections well with clear explanations of what changed and how it was tested. However, the Demo Video section is missing, which is recommended for UI/behavior changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed New types (SSHTransport enum, SSHCommandOptions struct, CmuxSSHURLTransport enum) are value types with immutable properties only, inherently Sendable in Swift 6. No actor isolation mistakes introdu...
Cmux Swift Blocking Runtime ✅ Passed No blocking/timing synchronization patterns (semaphores, locks, sleep, polling) found in production Swift code changes: SSH/Teleport functions in CLI/cmux.swift, transport parsing in CmuxSSHURLRequ...
Cmux Expensive Synchronous Load ✅ Passed PR adds SSH transport via --via tsh flag. The new runInteractiveTeleportSSH function uses only RPC calls (client.sendV2) and text building—no expensive synchronous loaders like RestorableAgentS...
Cmux Cache Substitution Correctness ✅ Passed Transport field is always derived from fresh inputs (CLI args or URL query params), never from workspace state or cache. No authoritative read is replaced with a cached value.
Cmux No Hacky Sleeps ✅ Passed PR contains only Swift files (excluded), documentation, and localization changes. The single TypeScript file modified (web/app/[locale]/docs/ssh/page.tsx) is a static docs page with no problematic...
Cmux Algorithmic Complexity ✅ Passed PR adds Teleport SSH transport via small bounded collections (SSH options ~5 items, URL query params ~15 max); no nested loops over workspaces/sessions/panes, no per-item rescans of user-scalable d...
Cmux Swift Concurrency ✅ Passed PR introduces Teleport SSH transport feature without any legacy async patterns: no fire-and-forget Tasks, background Dispatch queues, Combine usage, or completion handlers. All new code is synchron...
Cmux Swift @Concurrent ✅ Passed PR adds 3 new synchronous functions to CLI.swift with no async/concurrent violations: pure string helpers and RPC callers invoked from sync CLI context, not UI isolation.
Cmux Swift File And Package Boundaries ✅ Passed PR respects Swift boundaries: CLI/cmux.swift+216-633 (net -572), shrinking below 200-line extraction threshold; CmuxSSHURLRequest +48 (parsing only); AppDelegate+CmuxSSHURL +5 (error handling); bud...
Cmux Swift Logging ✅ Passed No logging rule violations found. The print statements in runInteractiveTeleportSSH are allowed CLI output, not runtime diagnostics. No NSLog, debugPrint, dump, or Logger violations detected.
Cmux Swiftui State Layout ✅ Passed No SwiftUI state changes found; PR adds SSH transport enums/parsing to data model layer only (CLI/cmux.swift, CmuxSSHURLRequest.swift, etc.), with no @Observable, @Published, @State, ObservableObje...
Cmux Architecture Rethink ✅ Passed PR introduces clean architecture: single transport decision point, immutable value-based state, no timing/blocking repairs, no duplicate entrypoint wiring, clear invariants, and proper test-only sy...
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR adds Teleport SSH transport via RPC workspace creation without creating new NSWindow, NSPanel, NSWindowController, or SwiftUI Window/WindowGroup instances; no new cmux.* identifiers or cmuxAuxil...
Cmux Source Artifacts ✅ Passed All changed files are legitimate source code (.swift), tests, localization catalogs (.xcstrings, .json), web source (.tsx), or documentation (.md). No artifacts, generated logs, build output, cache...
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adds Teleport (tsh) as an alternative SSH transport across CLI and deep links, with docs/UI updates and tests to validate the new behavior.

Changes:

  • Added --via <ssh|tsh> to cmux ssh, implementing an interactive-only tsh ssh workspace path.
  • Added via=tsh support in SSH deep links / URL parsing, including error handling and localization.
  • Updated web docs/messages and added test coverage for both CLI behavior and URL parsing.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
web/messages/ja.json Adds Japanese UI strings for the new --via / deep-link via parameter.
web/messages/en.json Adds English UI strings for the new --via / deep-link via parameter.
web/app/[locale]/docs/ssh/page.tsx Documents the new --via flag and via deep-link parameter in the web docs table.
docs/ssh-teleport.md Adds a new Teleport (tsh) SSH support doc describing interactive-only behavior and future relay ideas.
cmuxTests/VMSSHCommandTests.swift Adds an integration regression test ensuring --via tsh creates an interactive workspace without relay RPCs.
cmuxTests/CmuxSSHURLRequestTests.swift Adds unit tests for parsing via=tsh (and rejecting invalid values) in deep links.
Sources/CmuxSSHURLRequest.swift Introduces transport parsing (via) and includes transport in generated CLI arguments.
Sources/AppDelegate+CmuxSSHURL.swift Adds user-facing error string mapping for invalid via transport.
Resources/Localizable.xcstrings Updates cmux ssh usage text to include --via and adds a new localized error key.
CLI/cmux.swift Implements the --via flag, adds Teleport interactive execution path, and updates CLI help text.
Comments suppressed due to low confidence (2)

CLI/cmux.swift:1

  • tsh ssh agent forwarding is currently enabled based on parsing ForwardAgent from options.sshOptions. If agent forwarding is enabled via a non--o path (e.g., an explicit -A/--forward-agent flag or other internal resolution that yields options.agentSocketPath), this may fail to append -A even though SSH_AUTH_SOCK is set in the workspace env. Consider deriving the -A decision from the resolved forwarding outcome (e.g., options.agentSocketPath != nil or a dedicated boolean) instead of re-parsing SSH options.
    Resources/Localizable.xcstrings:1
  • Several non-English localizations now include new --via help text in English and are marked needs_review. If these strings are user-facing, consider providing translations for the added --via lines (or keeping the prior translations and omitting the new lines until translated) to avoid mixed-language CLI help in localized builds.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docs/ssh-teleport.md
Comment on lines +9 to +14
| Surface | How |
| --- | --- |
| CLI | `cmux ssh --via tsh user@node` (default `--via ssh`) |
| Deep link (cmux scheme) | `cmux://ssh?host=node&user=admin&via=tsh` |
| Deep link (standard) | `ssh://admin@node?via=tsh` |
| Web fallback | `https://cmux.com/deeplink/ssh?host=node&user=admin&via=tsh` |
Comment on lines 189 to +203
let sshOptions: [String]
switch structuredSSHOptions(from: queryItems) {
case .success(let options):
sshOptions = options
case .failure(let error):
return .failure(error)
}

let transport: CmuxSSHURLTransport
switch parsedTransport(in: queryItems) {
case .success(let value):
transport = value
case .failure(let error):
return .failure(error)
}
Comment on lines +1015 to +1019
case .invalidTransport(let parameter):
return String(
format: String(localized: "dialog.sshURL.error.invalidTransport", defaultValue: "The SSH link included an invalid transport for parameter: %@. Use ssh or tsh."),
parameter
)
@greptile-apps

greptile-apps Bot commented Jun 14, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds an opt-in Teleport (tsh) SSH transport to cmux ssh via --via tsh and a matching via deep-link query parameter. The new path opens an interactive-only workspace that execs tsh ssh directly — no cmux relay, no cmuxd-remote bootstrap — and is consistently wired through CLI parsing, URL scheme parsing, and web docs.

  • CLI (CLI/cmux.swift): new SSHTransport enum and --via flag; runInteractiveTeleportSSH builds a minimal tsh ssh command and creates a plain workspace, with an explicit fast-fail if --identity is passed.
  • URL parsing (Sources/CmuxSSHURLRequest.swift): CmuxSSHURLTransport enum + parsedTransport helper handle the via query param on both cmux:// and ssh:// deep links; cliArguments emits --via tsh for the .teleport case.
  • Localization: dialog.sshURL.error.invalidTransport is new in Localizable.xcstrings (en/ja only — 18 locales missing); flagVia/deepLinkVia web message keys are also only in en.json and ja.json (18 web locales missing).

Confidence Score: 4/5

Safe to merge for the functional SSH transport changes; the localization gaps mean users on 18 non-English/non-Japanese locales will see English copy in the web docs and a potentially empty or English alert for invalid deep-link transport values.

The Swift transport logic, URL parsing, and integration tests are all well-structured. The outstanding gap is localization: flagVia/deepLinkVia are absent from 18 web locale files, and the dialog.sshURL.error.invalidTransport alert string has only en/ja entries in the string catalog. These are real gaps for shipped user-facing surfaces — the web docs page and the deep-link error alert — not theoretical future issues.

Resources/Localizable.xcstrings (invalidTransport key missing 18 locales; help-text blobs for 18 locales are needs_review with untranslated English --via copy) and all web/messages/*.json files other than en.json and ja.json (flagVia and deepLinkVia keys absent).

Important Files Changed

Filename Overview
CLI/cmux.swift Adds SSHTransport enum, --via flag parsing, teleportSSHCommandArguments helper, and runInteractiveTeleportSSH path; logic is sound and the identity-file fast-fail guard is deliberate.
Resources/Localizable.xcstrings New dialog.sshURL.error.invalidTransport key has only en/ja entries — 18 supported locales are missing. Help-text blobs for all non-ja locales are set to needs_review with untranslated English --via copy appended.
Sources/CmuxSSHURLRequest.swift Adds CmuxSSHURLTransport enum, parsedTransport helper, and transport field on CmuxSSHURLRequest; logic is clean and consistent with existing parse pattern.
Sources/AppDelegate+CmuxSSHURL.swift Adds invalidTransport case to the error-description switch; uses localized String API correctly and mirrors existing patterns.
web/messages/en.json Adds flagVia and deepLinkVia keys; translations present in en and ja only — 18 other web locales are missing these keys.
web/app/[locale]/docs/ssh/page.tsx Adds --via and via parameter rows to the CLI flags and deep-link tables using t() correctly.
cmuxTests/VMSSHCommandTests.swift Adds integration tests for tsh identity rejection and the interactive workspace path; assertions are thorough and no relay RPCs are expected.
cmuxTests/CmuxSSHURLRequestTests.swift Adds four URL parse tests covering teleport transport, default openssh, standard ssh:// URL, and invalid via value rejection.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["cmux ssh …"] --> B{--via flag}
    DL["Deep link\n(cmux:// or ssh://)"] --> C["CmuxSSHURLRequest.parse\n(parsedTransport)"]
    C -->|"via=tsh"| E["cliArguments → --via tsh"]
    C -->|"via=ssh / absent"| F["cliArguments → (no --via)"]
    E --> A
    F --> A
    B -->|"tsh / teleport"| G["runInteractiveTeleportSSH"]
    B -->|"ssh / openssh (default)"| H["runSSH (OpenSSH relay pipeline)"]
    G --> I{"--identity present?"}
    I -->|yes| J["CLIError: fast-fail"]
    I -->|no| K["teleportSSHCommandArguments\n(tsh ssh -p -A -o …)"]
    K --> L["workspace.create\ninitial_command: exec tsh ssh …"]
    H --> M["generateRemoteRelayPort\ncmuxd-remote bootstrap\nworkspace.remote.configure\n…"]
Loading

Comments Outside Diff (1)

  1. web/messages/en.json

    P1 Missing web locale translations for flagVia and deepLinkVia

    flagVia and deepLinkVia were added to en.json and ja.json, but the other 18 locales registered in web/i18n/routing.ts — ar, bs, da, de, es, fr, it, km, ko, no, pl, pt-BR, ru, th, tr, uk, zh-CN, zh-TW — have no entry for either key. next-intl will fall back to the default locale string at runtime, so every non-English/non-Japanese user will see the English copy rather than a translated description in the SSH docs page.

    Rule Used: Flag production user-facing text that is not fully... (source)

Reviews (2): Last reviewed commit: "Reject --identity for cmux ssh --via tsh..." | Re-trigger Greptile

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CLI/cmux.swift`:
- Around line 7991-8006: The teleportSSHCommandArguments function currently
drops unsupported OpenSSH-only options like identity without warning, causing
the session to be created with different settings than requested. Add validation
logic at the start of the teleportSSHCommandArguments function to detect when
unsupported first-class OpenSSH options have been set in the SSHCommandOptions
parameter (such as identity), and throw an error or return a failure result
before attempting to build the command arguments. This ensures the function
fails fast rather than silently ignoring critical options that the user
explicitly requested.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 39352621-5304-45e8-9d73-e6e3899bf2ff

📥 Commits

Reviewing files that changed from the base of the PR and between 249a1d4 and 320f541.

📒 Files selected for processing (10)
  • CLI/cmux.swift
  • Resources/Localizable.xcstrings
  • Sources/AppDelegate+CmuxSSHURL.swift
  • Sources/CmuxSSHURLRequest.swift
  • cmuxTests/CmuxSSHURLRequestTests.swift
  • cmuxTests/VMSSHCommandTests.swift
  • docs/ssh-teleport.md
  • web/app/[locale]/docs/ssh/page.tsx
  • web/messages/en.json
  • web/messages/ja.json

Comment thread CLI/cmux.swift
Per code review (CodeRabbit): teleportSSHCommandArguments forwarded only port,
agent forwarding, -o passthroughs, destination, and trailing args, so a
first-class OpenSSH option like --identity was silently discarded for the tsh
transport — opening a session with a different auth path than requested. tsh
authenticates via 'tsh login' certificates, so an identity file is meaningless.

runInteractiveTeleportSSH now fails fast with a clear error before any RPC when
--identity is set, rather than ignoring it. Adds a CLI regression test asserting
the rejection sends no workspace.create.

Other review findings were verified and intentionally skipped (forwarded -o
options surface tsh's own error rather than being dropped; -A reflects explicit
ForwardAgent intent; needs_review locale strings follow the existing help-text
convention).
@4thel00z

Copy link
Copy Markdown
Author

Reviewed all CodeRabbit/Copilot findings against the current code. Fixed the one still-valid issue; skipping the rest with reasons.

Fixed (bf95a8b09)

  • CodeRabbit (Major): --via tsh silently dropped first-class OpenSSH options like --identity. runInteractiveTeleportSSH now fails fast with a clear error before any RPC when --identity is set (tsh authenticates via tsh login certs). Added a CLI regression test asserting no workspace.create is sent. Both tsh tests green locally.

Verified & skipped

  • Copilot — derive -A from agentSocketPath: current code keys -A off explicit ForwardAgent=yes (the -A/--forward-agent intent). agentSocketPath can be non-nil from an ambient SSH_AUTH_SOCK the user didn't ask to forward, so that change would over-forward.
  • Copilot — via=tsh still emits ConnectTimeout/ServerAlive*/StrictHostKeyChecking as -o: those are forwarded to tsh as -o (tsh surfaces its own error), not silently dropped. The only silent-drop case was --identity, now fixed.
  • Copilot — mixed-language cli.help.ssh: that string already carries English Usage:/Example: lines in every locale; the non-en/ja locales are outside the repo's supported set and are flagged needs_review for the translation pipeline.
  • Copilot — docs/ssh-teleport.md table uses ||: false positive; the table uses single-pipe syntax (diff + prefix likely misread).
  • Copilot — error message omits openssh/teleport aliases: "Use ssh or tsh" intentionally guides to the canonical values; the aliases remain accepted.

@teamleaderleo teamleaderleo added area: remote cmux ssh, remote daemon, tunnels, device pairing S3: minor Wrong behavior with a workaround needs a call Finished and held for a team design or product decision (see #13742 and the gallery in #15427) labels Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: remote cmux ssh, remote daemon, tunnels, device pairing needs a call Finished and held for a team design or product decision (see #13742 and the gallery in #15427) S3: minor Wrong behavior with a workaround

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants