Reject bundled agent runtimes from app artifacts - #6971
austinywang wants to merge 16 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughAdds a Bash verifier for bundled runtimes in ChangesBundled runtime verification
Estimated code review effort: 3 (Moderate) | ~20 minutes Related issue: Suggested reviewers: lawrencecchen 🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@codex review |
@austinywang I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 241,260 of the 240,000 allowed lines of code this month. Reviews resume on 1 July 2026 (in 5 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
To use Codex here, create a Codex account and connect to github. |
|
✅ Action performedReview finished.
|
Greptile SummaryThis PR adds a
Confidence Score: 5/5Safe to merge; all changes are additive CI guard scripts and tests with no production Swift or runtime code modified. The verifier script is logically sound, covering forbidden names, Bun-signature detection, and byte-for-byte grok verification. The test suite closes all previously flagged gaps. The only observation is a minor quality gap in the symlink executable check with no realistic impact on actual builds. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[CI / Nightly / Release Workflow] --> B[Build cmux.app universal bundle]
B --> C[verify-no-bundled-agent-runtimes.sh]
C --> D{For each file/symlink in Contents/Resources/bin}
D --> E{Name in allowlist?}
E -- No --> F[FAIL: unexpected bundled bin entry]
E -- Yes --> G{Is executable?}
G -- No --> H[FAIL: allowed bin entry not executable]
G -- Yes --> I{Name == grok?}
I -- Yes --> J{Matches checked-in Resources/bin/grok?}
J -- No --> K[FAIL: grok wrapper mismatch]
J -- Yes --> L{strings -a: Bun signature?}
I -- No --> L
L -- Yes --> M[FAIL: Bun standalone runtime signature]
L -- No --> D
D -- All files pass --> N[PASS: verified no bundled provider runtimes]
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
A[CI / Nightly / Release Workflow] --> B[Build cmux.app universal bundle]
B --> C[verify-no-bundled-agent-runtimes.sh]
C --> D{For each file/symlink in Contents/Resources/bin}
D --> E{Name in allowlist?}
E -- No --> F[FAIL: unexpected bundled bin entry]
E -- Yes --> G{Is executable?}
G -- No --> H[FAIL: allowed bin entry not executable]
G -- Yes --> I{Name == grok?}
I -- Yes --> J{Matches checked-in Resources/bin/grok?}
J -- No --> K[FAIL: grok wrapper mismatch]
J -- Yes --> L{strings -a: Bun signature?}
I -- No --> L
L -- Yes --> M[FAIL: Bun standalone runtime signature]
L -- No --> D
D -- All files pass --> N[PASS: verified no bundled provider runtimes]
Reviews (14): Last reviewed commit: "Handle Bun signature scan SIGPIPE" | Re-trigger Greptile |
Greptile SummaryAdds a regression guard (
Confidence Score: 4/5Safe to merge; the verifier and workflow placement are correct and improve artifact hygiene across all three release pipelines. The core verifier logic, allowlist, and workflow wiring are all sound. The only gap is that the test never writes Bun marker strings into an allowed binary, so the looks_like_bun_standalone branch has zero test coverage. If that detection silently broke, the verifier would miss a Bun runtime disguised under an allowed name. The fix is a straightforward additional test case. tests/test_bundled_provider_runtime_guard.sh — needs a test case that triggers the Bun standalone signature detection path. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[find BIN_DIR executables] --> B{is_allowed_binary_name?}
B -- No --> C[violation: unexpected executable]
C --> G[continue to next file]
B -- Yes --> D{looks_like_bun_standalone?}
D -- Yes --> E[violation: Bun standalone signature]
D -- No --> F[file is clean]
E --> H[next file]
F --> H
H --> B
subgraph TEST_COVERAGE["Test Coverage"]
TC1["✅ Tested: unexpected binary name\n(claude, opencode, codex, pi, bun, bunx)"]
TC2["❌ NOT tested: Bun signature\nin allowed binary name\n(e.g. cmux with StandaloneExecutable strings)"]
end
C -.->|covered| TC1
E -.->|not covered| TC2
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
A[find BIN_DIR executables] --> B{is_allowed_binary_name?}
B -- No --> C[violation: unexpected executable]
C --> G[continue to next file]
B -- Yes --> D{looks_like_bun_standalone?}
D -- Yes --> E[violation: Bun standalone signature]
D -- No --> F[file is clean]
E --> H[next file]
F --> H
H --> B
subgraph TEST_COVERAGE["Test Coverage"]
TC1["✅ Tested: unexpected binary name\n(claude, opencode, codex, pi, bun, bunx)"]
TC2["❌ NOT tested: Bun signature\nin allowed binary name\n(e.g. cmux with StandaloneExecutable strings)"]
end
C -.->|covered| TC1
E -.->|not covered| TC2
Reviews (2): Last reviewed commit: "Address bundled runtime guard review" | Re-trigger Greptile |
Greptile SummaryThis PR introduces a regression guard that blocks bundled provider executables and Bun standalone runtimes from shipping inside
Confidence Score: 4/5Safe to merge; the guard correctly blocks unlisted executables in all three workflow targets and introduces no changes to production Swift or app behavior. The verifier and CI integration work correctly for the primary name-allowlist check, but the test never calls looks_like_bun_standalone, so the Bun signature detection path is entirely unvalidated. Additionally, strings without -a on macOS may silently skip non-standard Mach-O sections where a Bun binary could embed its markers. tests/test_bundled_provider_runtime_guard.sh and scripts/verify-no-bundled-agent-runtimes.sh warrant a second look — the test coverage of the Bun detection path and the strings -a flag are the two points worth addressing before the guard is relied on in production releases. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[CI / Nightly / Release workflow] --> B[Build cmux.app universal bundle]
B --> C[verify-no-bundled-agent-runtimes.sh]
C --> D{For each executable in bin dir}
D --> E{Name in allowlist?}
E -- No --> F[FAIL: unexpected executable]
E -- Yes --> G{Bun standalone signature?}
G -- Yes --> H[FAIL: Bun runtime detected]
G -- No --> D
D -- All pass --> I[PASS: verified no bundled runtimes]
I --> J[Continue artifact validation]
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
A[CI / Nightly / Release workflow] --> B[Build cmux.app universal bundle]
B --> C[verify-no-bundled-agent-runtimes.sh]
C --> D{For each executable in bin dir}
D --> E{Name in allowlist?}
E -- No --> F[FAIL: unexpected executable]
E -- Yes --> G{Bun standalone signature?}
G -- Yes --> H[FAIL: Bun runtime detected]
G -- No --> D
D -- All pass --> I[PASS: verified no bundled runtimes]
I --> J[Continue artifact validation]
Reviews (3): Last reviewed commit: "Address bundled runtime guard review" | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/verify-no-bundled-agent-runtimes.sh`:
- Around line 56-68: The bundled-runtime check is skipping non-executable
regular files, which lets a copied bun/bunx binary or an allowlisted file like
cmux pass if packaging strips the execute bit. Update
verify-no-bundled-agent-runtimes.sh so the scan in the while/read loop and
looks_like_bun_standalone path checks every file and symlink under BIN_DIR
regardless of mode, then add a separate permission failure for allowlisted
entries that are expected to be executable. Use is_allowed_binary_name,
looks_like_bun_standalone, and the current violation collection to keep the
behavior consistent.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: e8012693-3b67-4729-9f7f-3634beb5bb62
📒 Files selected for processing (5)
.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/release.ymlscripts/verify-no-bundled-agent-runtimes.shtests/test_bundled_provider_runtime_guard.sh
…n-1-3-14-segfaults-use-after-free-i
…n-1-3-14-segfaults-use-after-free-i
…n-1-3-14-segfaults-use-after-free-i
…n-1-3-14-segfaults-use-after-free-i
…n-1-3-14-segfaults-use-after-free-i
Fixes #5674
Summary
Tests
Note: no local dev build or reload was run per issue instructions.
Summary by CodeRabbit
cmux.appbundles do not include bundled agent runtimes.Contents/Resources/binfor unexpected executables/symlinks, missing/exact wrapper matches, and embedded runtime signature indicators.Contents/Resources/bin/...path.