Skip to content

Fix main app-host shard regressions - #6580

Merged
austinywang merged 5 commits into
mainfrom
fix-main-ci-shard4
Jun 22, 2026
Merged

austinywang merged 5 commits into
mainfrom
fix-main-ci-shard4

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Fixes the current main CI app-host shard 4 regressions after the global font magnification merge.

Changes:

  • keep right-sidebar compact control height at 20pt at 100% magnification while still allowing growth above default magnification
  • promote visible side-docked WebKit inspectors synchronously, then let layout enforce adaptive bottom-docking after the managed container owns the split
  • reject PID-derived agent launch argv unless the PID actually classifies as the hook agent kind, preventing test-host/app argv from becoming persisted resume commands

Checks run locally:

  • git diff --check
  • scripts/lint-pbxproj-test-wiring.sh
  • swift test in Packages/macOS/CMUXAgentLaunch

Main failure context: https://github.com/manaflow-ai/cmux/actions/runs/27937219981


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Medium Risk
Agent launch trust changes affect persisted resume/fork commands across many agents; inspector and layout tweaks touch drag routing but are localized UI behavior.

Overview
Addresses main app-host CI shard 4 failures after global font magnification: UI metrics, hosted inspector docking, and agent resume capture.

Right sidebar chrome scales compact control text from 12pt (was 13pt) so height stays 20pt at 100% magnification while still growing above default.

Hosted WebKit inspector side-dock promotion no longer forces adaptive bottom dock during synchronous promotion; it activates the side dock immediately so divider/drag routing stays symmetric, with bottom-dock enforcement deferred to layout once the managed container owns the split.

Agent launch capture moves native process classification into AgentLaunchCaptureTrust (nativeProcessDescribesKind / nativeProcessDescribesKnownAgent with per-agent aliases). The CLI drops local Codex/Claude-only logic and rejects PID-derived argv unless the process matches the hook’s agent kind—blocking cmux app / Xcode test-host argv from becoming persisted resume commands.

Smaller aligned updates: SessionIndexModels resume commands use TerminalStartupWorkingDirectoryPrefix; remote relay awk uses \047 for quote stripping; tests expect updated resume strings, hook config assertions, symlink-resolved vault URLs, tmux overlay rects, and workspace rail color hex.

Reviewed by Cursor Bugbot for commit ecb20f1. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Fixes app-host CI shard 4 regressions from global font magnification. Stabilizes right-sidebar sizing, inspector docking, and agent resume command capture to unblock CI.

  • Bug Fixes

    • Keep right-sidebar compact control height ~20pt at 100% magnification by using 12pt scaled text; still grows above default.
    • Promote visible side-docked WebKit inspectors immediately; defer adaptive bottom-dock to layout so divider/drag routing stays stable.
    • Trust PID-derived argv only when the process matches the expected agent kind, with alias support (e.g. grok, kiro, rovodev, pi); persisted resume commands now use a safe working-directory prefix via TerminalStartupWorkingDirectoryPrefix.
  • Refactors

    • Moved native agent process classification into CMUXAgentLaunch (AgentLaunchCaptureTrust) with nativeProcessDescribesKind/nativeProcessDescribesKnownAgent; CLI uses these for PID fallback and ancestry checks with new unit tests.

Written for commit ecb20f1. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved native agent process identification by validating PID-derived process metadata against the expected agent kind before trusting it.
    • Updated hosted inspector docking to immediately activate the side dock on divider interaction, keeping routing consistent.
    • Improved remote relay listener token sanitization and resume command directory handling for more reliable launches.
  • Style
    • Fine-tuned right sidebar chrome sizing for better alignment.
  • Tests
    • Expanded PID/metadata trust coverage and refreshed several CLI/session/UI expectation checks.

@vercel

vercel Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jun 22, 2026 9:59am
cmux-staging Building Building Preview, Comment Jun 22, 2026 9:59am

@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Refactors native agent process kind validation from CLI into AgentLaunchCaptureTrust with new public helpers to infer and match process metadata against expected agent kinds, removing local enum logic. Adjusts inspector side-dock promotion to defer adaptive bottom-dock enforcement and reduces sidebar font scaling from 13 to 12. Updates resume command building to use a centralized working directory prefix helper, adds defensive directory checks and Pi vault session environment variables, and refines AWK token sanitization.

Changes

Native agent kind validation in AgentLaunchCaptureTrust

Layer / File(s) Summary
Agent kind mapping and inference helpers
Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/AgentLaunchCaptureTrust.swift
Adds nativeProcessAliasesByKind mapping agent kinds to executable aliases; nativeProcessDescribesKind validates process metadata against expected kind with direct/alias/suffix matching; nativeProcessDescriptors infers descriptors from basenames with special node/bun handling; helpers normalizedAgentName and processBasename normalize hook kinds and extract executable basenames.
Native process kind validation tests
Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/AgentLaunchCaptureTrustTests.swift
Tests nativeProcessDescribesKind and nativeProcessDescribesKnownAgent across positive matches for known agents (codex, claude), negative cases with wrong kinds, incomplete metadata, and unrelated executables.
CLI agent discovery and fallback validation
CLI/cmux.swift
Removes local HookAgentProcessKind enum. Replaces nativeAgentProcessKind(for:) != nil with delegation to nativeProcessDescribesKnownAgent(for:) for agent candidate counting. Gates fallback PID argument assignment on nativeProcessDescribesKind validation instead of unconditionally accepting candidate arguments. Introduces new nativeProcessDescribesKnownAgent(for:) helper delegating to AgentLaunchCaptureTrust.
Hook persistence test update
cmuxTests/CLIRovoDevHookPersistenceTests.swift
Updates testRovoAliasCreatesConfigDirAndInstallsRovoDevHooksFromSetup to assert hooks rovodev prompt-submit and CMUX_BUNDLED_CLI_PATH as separate checks within config.yml instead of a combined string.

Inspector dock promotion and sidebar metrics

Layer / File(s) Summary
Inspector side-dock promotion and sidebar control height
Sources/Panels/BrowserPanelView.swift, Sources/WindowChromeMetrics.swift
Removes the shouldForceHostedInspectorBottomDock early-return branch from promoteHostedInspectorSideDockFromCurrentLayoutIfNeeded so adaptive bottom-dock enforcement is deferred to later layout. Reduces RightSidebarChromeMetrics.controlHeight font scale from scaledSize(13) to scaledSize(12).
Layout test geometry and color assertions
cmuxTests/WorkspaceContentViewVisibilityTests.swift, cmuxTests/WorkspaceUnitTests.swift
Updates expected overlay rectangle y/height values in testTmuxWorkspacePaneOverlayRectReturnsMatchingPaneFrame and unread-rect geometry in testTmuxWorkspacePaneUnreadRectsIncludeFocusedReadIndicator from y: 30, height: 290 to y: 28, height: 292 due to sidebar metrics adjustment. Updates expected left-rail color hex string from #C0392B to #D13929 in custom-colored workspace row assertion.

Session command and resume handling updates

Layer / File(s) Summary
Resume command building abstraction
Sources/SessionIndexModels.swift
Delegates guarded launch directory prefix construction to TerminalStartupWorkingDirectoryPrefix.prefix(command, workingDirectory: cwd) instead of inline cd <cwd> && <command> string building.
Defensive resume command and Pi vault session updates
cmuxTests/CLIGenericHookPersistenceTests.swift, cmuxTests/PiVaultAgentPersistenceTests.swift
Updates Kiro resume command assertion to use defensive cd -- ... 2>/dev/null || [ ! -d ... ] form with directory existence check. Adds env PI_CODING_AGENT_SESSION_DIR prefix and --session-dir argument to expected Pi vault agent resumeCommand. Updates Grok vault test to compare symlink-resolved file paths instead of raw URLs.
AWK token sanitization in relay provisioning
Packages/macOS/CmuxRemoteSession/Sources/CmuxRemoteSession/Session/RemoteSessionCoordinator+RelayProvisioning.swift
Updates AWK clean_token function to remove the escaped octal single-quote form (\047) instead of the literal escape pattern during token sanitization in the relay listener cleanup script.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐇 The agent kind now validates with trust most true,
Process metadata checked from and through.
The dock springs to its rightful place with grace,
And sidebar fonts dance tighter in their space.
Sessions resume with defensive care, and everything aligns—one hop to victory! ✨


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux Algorithmic Complexity ❌ Error AgentLaunchCaptureTrust.swift line 102 reconstructs a static Set on every nativeProcessDescribesKnownAgent() call in a 32-iteration ancestor-walk loop called on every session interaction, violating... Cache knownNames as a static let instead of reconstructing it per-call: private static let knownNames = Set(...).union(...) at the enum level.
Docstring Coverage ⚠️ Warning Docstring coverage is 16.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (21 passed)
Check name Status Explanation
Title check ✅ Passed The PR title 'Fix main app-host shard regressions' accurately reflects the primary objective of addressing CI failures in the main app-host shard 4 after the global font magnification merge.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed All production Swift changes pass Swift 6 actor isolation review. New public APIs in AgentLaunchCaptureTrust are pure static functions on an enum with no instance state. UI changes in BrowserPanelV...
Cmux Swift Blocking Runtime ✅ Passed Production changes introduce no new blocking or timing-based synchronization. Changes refactor agent process classification into AgentLaunchCaptureTrust, improve inspector docking logic, adjust UI...
Cmux Expensive Synchronous Load ✅ Passed PR adds no expensive synchronous agent-history loads on main app's main actor/interactive paths. CLI sysctl calls are in separate executable process. SessionIndexModels change to use TerminalStartu...
Cmux Cache Substitution Correctness ✅ Passed No cache substitution detected. Changes add validation to fresh PID reads, delegate to deterministic functions, and don't replace authoritative reads with cached values in persistence paths.
Cmux No Hacky Sleeps ✅ Passed PR contains no production non-Swift runtime changes with hacky sleeps. Swift code is covered by separate check. Only AWK script change sanitizes tokens, not adds delays.
Cmux Swift Concurrency ✅ Passed PR introduces no legacy async patterns (no background DispatchQueues, Combine, completion handlers, or fire-and-forget Tasks) in cmux-owned Swift code; all changes are synchronous helper functions...
Cmux Swift @Concurrent ✅ Passed No Swift @concurrent annotation violations detected. All new public APIs in AgentLaunchCaptureTrust are synchronous static functions with no async/actor isolation requirements.
Cmux Swift File And Package Boundaries ✅ Passed PR extracts native process classification logic from CLI into CMUXAgentLaunch package (158 lines, focused domain logic), shrinks CLI/cmux.swift by 47 lines, and makes incidental small fixes to exis...
Cmux Swiftpm Lockfiles ✅ Passed PR makes no changes to Package.swift, Package.resolved, or .gitignore files. CMUXAgentLaunch has no external dependencies (only internal target). No SwiftPM/package configuration changes require lo...
Cmux Swift Logging ✅ Passed All production code changes comply with swift-logging.md: no print/NSLog/debugPrint/dump in app code (CLI output is allowed), no file logging, no MainActor logger issues, and no secrets exposed.
Cmux User-Facing Error Privacy ✅ Passed PR contains no user-facing error text, credential exposure, upstream vendor names, or privacy violations. Changes are: (1) internal APIs for PID classification in AgentLaunchCaptureTrust; (2) refac...
Cmux Full Internationalization ✅ Passed PR contains no user-facing text changes requiring localization. Changes include internal agent classification logic with literal tokens (process names, config keys), UI timing adjustments, font met...
Cmux Swiftui State Layout ✅ Passed No SwiftUI state/layout violations. BrowserPanelView changes use existing state with properly deferred mutations via Task.yield(). WindowChromeMetrics changes are metric constants. Other changes ar...
Cmux Architecture Rethink ✅ Passed PR contains only small correctness fixes: (1) AgentLaunchCaptureTrust adds pure stateless classification functions; (2) CLI validates PID-derived argv synchronously; (3) BrowserPanelView promotes i...
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains no new NSWindow, NSPanel, NSWindowController, or SwiftUI Window/WindowGroup declarations. Changes are logic-only (inspector docking, control heights) and test assertions. Lint script pa...
Cmux Source Artifacts ✅ Passed All 12 changed files are legitimate hand-written source code, tests, or package implementations with no source control artifact violations.
Cmux No Test Or Debug Seam In Production Source ✅ Passed No test/debug seams introduced. New public APIs in AgentLaunchCaptureTrust have legitimate production callers in CLI/cmux.swift; no visibility was widened for test access only.
Description check ✅ Passed The PR description adequately covers the main changes, rationale, and testing approach aligned with the template.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-main-ci-shard4

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread CLI/cmux.swift
@greptile-apps

greptile-apps Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Three targeted CI regression fixes from the global font magnification merge: agent PID trust classification moved into CMUXAgentLaunch, inspector side-dock timing corrected, and right-sidebar font basis reduced from 13pt to 12pt.

  • Agent trust refactor: nativeProcessDescribesKind and nativeProcessDescribesKnownAgent replace the inline HookAgentProcessKind helpers in CLI/cmux.swift. PID fallback for resume commands now gates on the live process actually matching the hook's agent kind, preventing Xcode test hosts and the cmux app itself from being persisted as resume commands.
  • Inspector side-dock promotion: Removes the premature synchronous requestAdaptiveHostedInspectorBottomDock call; bottom-dock enforcement is now deferred to layout once the managed container owns the split.
  • WindowChromeMetrics: Drops scaled text basis from 13pt to 12pt so controlHeight lands at exactly 20pt at 100% magnification.

Confidence Score: 5/5

All three fixes are tightly scoped, fully tested, and address specific CI failures without introducing new state or timing dependencies.

The agent trust logic is cleanly extracted into a testable package with comprehensive coverage of alias resolution, node/bun path detection, and negative cases. The inspector docking change removes a known-bad synchronous call. The font-size and shell-quoting changes are mechanical and verified by updated snapshot tests.

No files require special attention.

Important Files Changed

Filename Overview
Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/AgentLaunchCaptureTrust.swift Adds nativeProcessDescribesKind / nativeProcessDescribesKnownAgent with a static alias map covering 15 agent kinds; logic correctly extracted from cmux.swift with equivalent semantics and wider agent coverage.
CLI/cmux.swift Removes inline HookAgentProcessKind and the two nativeAgentProcessKind helpers, delegating to AgentLaunchCaptureTrust; PID fallback now validates against hookKind before trusting argv.
Sources/Panels/BrowserPanelView.swift Removes premature synchronous requestAdaptiveHostedInspectorBottomDock call from promoteHostedInspectorSideDockFromCurrentLayoutIfNeeded; bottom-dock enforcement now deferred to layout once managed container owns the split.
Sources/WindowChromeMetrics.swift Reduces right-sidebar scaled text basis from 13pt to 12pt so controlHeight equals exactly 20pt at 100% magnification, while still growing above default.
Sources/SessionIndexModels.swift Replaces ad-hoc cd shell-quoting with TerminalStartupWorkingDirectoryPrefix.prefix, producing the robust { cd -- '...' 2>/dev/null
Packages/macOS/CmuxRemoteSession/Sources/CmuxRemoteSession/Session/RemoteSessionCoordinator+RelayProvisioning.swift Replaces single-quote embedding in awk regex with \047 (octal), avoiding shell interpretation issues when the awk script is embedded in a Swift string literal.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Hook fires with fallbackPID + hookKind] --> B{envCaptureIsTrusted?}
    B -- yes --> C[Use CMUX_AGENT_LAUNCH_ARGV_B64]
    B -- no --> D[envArguments = nil]
    D --> E[processArguments = fallbackPID.flatMap]
    E --> F[Read processName + argv for PID]
    F --> G{nativeProcessDescribesKind
processName, argv, hookKind?}
    G -- no --> H[processArguments = nil]
    G -- yes --> I{argvLooksLikeShellWrapper?}
    I -- yes --> J[Walk child PIDs for agent process]
    I -- no --> K[Use PID argv as resume command]
    H --> L[environmentOnlyRecord]
    C --> M{argvLooksLikeShellWrapper?}
    M -- yes --> J
    M -- no --> N[Use env argv as resume command]
    J --> O{found agent child?}
    O -- yes --> P[Use child argv]
    O -- no --> L
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[Hook fires with fallbackPID + hookKind] --> B{envCaptureIsTrusted?}
    B -- yes --> C[Use CMUX_AGENT_LAUNCH_ARGV_B64]
    B -- no --> D[envArguments = nil]
    D --> E[processArguments = fallbackPID.flatMap]
    E --> F[Read processName + argv for PID]
    F --> G{nativeProcessDescribesKind
processName, argv, hookKind?}
    G -- no --> H[processArguments = nil]
    G -- yes --> I{argvLooksLikeShellWrapper?}
    I -- yes --> J[Walk child PIDs for agent process]
    I -- no --> K[Use PID argv as resume command]
    H --> L[environmentOnlyRecord]
    C --> M{argvLooksLikeShellWrapper?}
    M -- yes --> J
    M -- no --> N[Use env argv as resume command]
    J --> O{found agent child?}
    O -- yes --> P[Use child argv]
    O -- no --> L
Loading

Reviews (5): Last reviewed commit: "Merge remote-tracking branch 'origin/mai..." | Re-trigger Greptile

Comment thread CLI/cmux.swift Outdated
Comment on lines +26405 to +26414
private static func nativeAgentProcessKind(for hookKind: String) -> HookAgentProcessKind? {
switch hookKind.trimmingCharacters(in: .whitespacesAndNewlines).lowercased() {
case "codex":
return .codex
case "claude":
return .claude
default:
return nil
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Ambiguous overload name with existing nativeAgentProcessKind(for pid:) instance method

The new static method nativeAgentProcessKind(for hookKind: String) shares the for external label with the existing instance method nativeAgentProcessKind(for pid: pid_t) at line 26355. Swift resolves them correctly by type and static/instance distinction, and the Self. call-site prefix makes the intent clear. However, a more distinctive label — e.g., nativeAgentProcessKind(matchingKind:) — would eliminate the need for readers to mentally disambiguate two identically-named selectors with different semantics (string kind → enum vs. PID → enum).

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Comment thread CLI/cmux.swift Outdated
Comment on lines +26586 to +26598
var processArguments: [String]?
if let fallbackPID {
let pid = pid_t(fallbackPID)
let candidate = self.processArguments(for: pid)
if let expectedKind = Self.nativeAgentProcessKind(for: fallbackKind),
let candidate,
Self.nativeAgentProcessKind(
processName: processName(for: pid),
arguments: candidate
) == expectedKind {
processArguments = candidate
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 PID fallback now silently disabled for omx / omc hook kinds

nativeAgentProcessKind(for: fallbackKind) returns nil for any kind that is not literally "codex" or "claude", so processArguments stays nil for omx and omc hooks even when a valid PID is provided and the live process would correctly classify as .claude. If an omx/omc hook fires without CMUX_AGENT_LAUNCH_ARGV_B64 (e.g., an unmanaged Claude invocation) and env capture is untrusted, the launcher now falls through to environmentOnlyRecord() where it previously had a full argv. Is this intentional — i.e., are omx/omc hooks guaranteed to always carry the env-capture argv? Are omx and omc hook kinds always expected to have CMUX_AGENT_LAUNCH_ARGV_B64 available in the environment, making the PID fallback unnecessary for those kinds? Or is there a scenario where they'd rely on PID fallback for resume-command construction?

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/AgentLaunchCaptureTrustTests.swift`:
- Around line 45-90: The test testPIDProcessMetadataMustMatchHookKind lacks
comprehensive edge case coverage for the AgentLaunchCaptureTrust validation
logic. Add additional test cases using XCTAssertTrue and XCTAssertFalse with
calls to nativeProcessDescribesKind and nativeProcessDescribesKnownAgent to
cover: nil or empty processName values, empty arguments arrays, the bun runtime
similar to how node is currently tested, and path-based detection patterns such
as "/codex/codex" and "/.claude/" to ensure the inference logic correctly
handles these scenarios.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: df64b164-bfdb-404e-94f7-9df474eb93c4

📥 Commits

Reviewing files that changed from the base of the PR and between 6ac5fa2 and 4c6483c.

📒 Files selected for processing (6)
  • CLI/cmux.swift
  • Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/AgentLaunchCaptureTrust.swift
  • Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/AgentLaunchCaptureTrustTests.swift
  • Sources/Panels/BrowserPanelView.swift
  • Sources/WindowChromeMetrics.swift
  • cmuxTests/CLIRovoDevHookPersistenceTests.swift

Comment on lines +45 to +90
func testPIDProcessMetadataMustMatchHookKind() {
XCTAssertTrue(
AgentLaunchCaptureTrust.nativeProcessDescribesKind(
processName: "codex",
arguments: ["/opt/homebrew/bin/codex", "--sandbox", "workspace-write"],
kind: "codex"
)
)
XCTAssertTrue(
AgentLaunchCaptureTrust.nativeProcessDescribesKnownAgent(
processName: "codex",
arguments: ["/opt/homebrew/bin/codex", "--sandbox", "workspace-write"]
)
)
XCTAssertTrue(
AgentLaunchCaptureTrust.nativeProcessDescribesKind(
processName: "node",
arguments: ["node", "/Users/alice/.claude/local/claude.js"],
kind: "claude"
)
)
XCTAssertFalse(
AgentLaunchCaptureTrust.nativeProcessDescribesKind(
processName: "cmux DEV",
arguments: [
"/tmp/cmux-tests/Build/Products/Debug/cmux DEV.app/Contents/MacOS/cmux DEV",
"-NSTreatUnknownArgumentsAsOpen",
],
kind: "codex"
)
)
XCTAssertFalse(
AgentLaunchCaptureTrust.nativeProcessDescribesKind(
processName: "codex",
arguments: ["/opt/homebrew/bin/codex"],
kind: "claude"
)
)
XCTAssertFalse(
AgentLaunchCaptureTrust.nativeProcessDescribesKind(
processName: "agy",
arguments: ["/usr/local/bin/agy"],
kind: "antigravity"
)
)
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial | 💤 Low value

Consider adding edge case test coverage.

The current test covers the main validation scenarios from the PR objective (rejecting test-host/app arguments, matching native kinds). Consider adding tests for:

  • nil processName
  • Empty arguments array []
  • bun runtime (currently only tests node)
  • Path-based detection patterns ("/codex/codex", "/.claude/")

These additions would provide more comprehensive coverage of the inference logic, but the current test suite adequately validates the core requirement.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/AgentLaunchCaptureTrustTests.swift`
around lines 45 - 90, The test testPIDProcessMetadataMustMatchHookKind lacks
comprehensive edge case coverage for the AgentLaunchCaptureTrust validation
logic. Add additional test cases using XCTAssertTrue and XCTAssertFalse with
calls to nativeProcessDescribesKind and nativeProcessDescribesKnownAgent to
cover: nil or empty processName values, empty arguments arrays, the bun runtime
similar to how node is currently tested, and path-based detection patterns such
as "/codex/codex" and "/.claude/" to ensure the inference logic correctly
handles these scenarios.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit ecb20f1. Configure here.

descriptor == expectedKind
|| nativeProcessAliasesByKind[expectedKind]?.contains(descriptor) == true
|| descriptor == "\(expectedKind)-cli"
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Teams wrapper PID trust missing

Medium Severity

nativeProcessDescribesKind does not treat codexteams / claudeteams as matching codex / claude, unlike launcherDescribesKind. When inherited CMUX_AGENT_LAUNCH_* env is distrusted and PID fallback runs, argv from those wrapper processes is dropped and resume capture may fall back to env-only or fail.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit ecb20f1. Configure here.

@austinywang
austinywang merged commit f2123dc into main Jun 22, 2026
36 of 38 checks passed
@austinywang
austinywang deleted the fix-main-ci-shard4 branch June 22, 2026 09:47
azooz2003-bit added a commit that referenced this pull request Jul 3, 2026
…e silently dropped — #6518 (terminal input after window key restore), #6508 (defer restored WebViews until visible), #6559 (avoid DevTools teardown on redock), #6583 (gate idle port scanning to active workspace), #6528 (canvas scroll-hint debug menu), #6580 (drop re-introduced sideDock promote block). #6582/#6517 deferred (see merge-deferred-gaps)
@lawrencecchen
lawrencecchen restored the fix-main-ci-shard4 branch July 18, 2026 10:19

This branch was successfully deployed

1 active deployment
Preview – cmux — ecb20f11 Deployed Jun 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants