Skip to content

Harden workspace-todo CLI targeting, panel moves, caps, and shortcut defaults - #7748

Closed
azooz2003-bit wants to merge 1 commit into
mainfrom
todo-review-hardening
Closed

azooz2003-bit wants to merge 1 commit into
mainfrom
todo-review-hardening

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator

Review-hardening for the workspaces-as-todos feature merged in #7216 — these fixes were driven by the structured review loop and pushed while that PR was being merged, so they missed the squash.

Blank or valueless --workspace/--window selectors on cmux todo and cmux workspace status commands now fail with usage errors instead of silently targeting the selected workspace (destructive commands could mistarget). Workspace-todo panes refuse cross-workspace and Dock transfers: the panel binds its owning workspace at creation, and moving it previously left it displaying and mutating the source workspace's checklist. workspace.todo.set rejects over-cap arrays before parsing on the main actor, sharing the app-side error contract. The new status shortcut defaults move from Cmd+;/Cmd+Shift+; (the standard macOS spelling shortcuts, which they hijacked globally) to Ctrl+Cmd combos. toggleChecklistItemComplete is marked non-chordable since its matcher is view-local. Expired manual status overrides now reconcile at the agent-lifecycle and PR/git cache write funnels, closing the pin-revival window (first item of #7744). The sidebar checklist section renders independently of the status glyph, so "None (hide status)" no longer hides existing checklist items.

Verification: tagged build green; swift test green in CmuxControlSocket (226 tests, incl. new pre-cap coverage) and CmuxWorkspaces; file-length gate green vs main.

🤖 Generated with Claude Code


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Medium Risk
Changes surface-move eligibility, workspace status override timing, and default keyboard bindings; mistakes could block legitimate moves or surprise users on upgrade, but scope is localized to workspace-todo flows.

Overview
Follow-up hardening for workspace todos: CLI and control socket now reject empty --workspace / --window values on cmux todo and cmux workspace status instead of falling back to the ambient workspace. workspace.todo.set enforces the shared WorkspaceChecklistItem.maxChecklistItems cap before item parsing (with tests), via a new CmuxWorkspaces dependency.

Workspace-todo panels are treated as non-transferable: canTransferSurfaceAcrossWorkspaceBoundary blocks moves to other workspaces, new workspaces, and the Dock; attach paths only allow todo panels when sourceWorkspaceId matches the destination workspace.

Shortcuts and docs move mark-done / cycle-status defaults to Ctrl+Cmd+; and Ctrl+Cmd+Shift+; to avoid macOS spelling shortcuts; toggleChecklistItemComplete is excluded from chord binding. Sidebar shows the checklist section when items exist (or add-field is active), not only when a status glyph is shown.

Status overrides call reconcileExpiredTaskStatusOverride() when agent lifecycle, git branch, or PR metadata is updated, so manual pins clear when inference changes.

Reviewed by Cursor Bugbot for commit a195541. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Hardens workspace-todo targeting and movement, enforces checklist caps, and updates status shortcut defaults to avoid macOS conflicts. Prevents mistargeted CLI actions, cross-workspace todo pane moves, and stale status pins while keeping the checklist visible when status is hidden.

  • Bug Fixes

    • CLI: cmux todo and cmux workspace status now error on blank --workspace/--window values instead of defaulting.
    • Movement: workspace-todo panes are bound to their workspace and cannot move across workspaces or to Dock; move targets and detach paths enforce this.
    • Caps: workspace.todo.set rejects over-cap item arrays up front with a consistent error; tests added.
    • Shortcuts: default markWorkspaceDone and cycleWorkspaceStatus moved to Ctrl+Cmd combos; toggleChecklistItemComplete is non-chordable.
    • Status: expired manual status overrides now reconcile on agent lifecycle and PR/Git updates to prevent pin revival.
    • UI: the sidebar checklist renders even when status is hidden.
  • Dependencies

    • Added CmuxWorkspaces to CmuxControlSocket targets and tests.

Written for commit a195541. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features

    • Workspace todo actions now use updated keyboard shortcuts, including Control plus Command combinations.
    • The workspace checklist section appears more consistently when checklist items exist or are being added.
  • Bug Fixes

    • Improved validation for workspace and window command arguments, including empty or malformed values.
    • Prevented oversized checklist updates and blocked invalid workspace panel moves or attachments across workspaces.
    • Refreshed task status handling so workspace sidebar state stays in sync more reliably.

Blank or valueless --workspace/--window selectors on todo and status
commands now fail with usage errors instead of silently targeting the
selected workspace; workspace-todo panes refuse cross-workspace and
Dock transfers (the panel binds its owning workspace at creation);
workspace.todo.set rejects over-cap arrays before parsing on the main
actor, sharing the app-side error shape; the new status shortcuts
default to ctrl+cmd combos instead of colliding with the macOS spelling
shortcuts; toggleChecklistItemComplete is marked non-chordable (its
matcher is view-local); expired status overrides now reconcile at the
agent-lifecycle and PR/git cache write funnels, closing the pin-revival
window; the sidebar checklist section renders independently of the
status glyph so None hides only the status.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jul 9, 2026 9:22pm
cmux-staging Building Building Preview, Comment Jul 9, 2026 9:22pm

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR adds CLI validation for workspace/window selector options, enforces a checklist item cap in the control socket coordinator with a new error helper and test, restricts cross-workspace transfer of workspace-todo panels across Dock/tab move and detached-surface attach paths, adds task-status reconciliation after lifecycle/metadata updates, and updates default keyboard shortcuts (adding Control modifier) with matching docs and web data.

Changes

Workspace Todo Feature Updates

Layer / File(s) Summary
CLI selector validation
CLI/CMUXCLI+WorkspaceTodo.swift
Adds validation for --workspace/--window option values before parsing, throwing CLIError when missing, blank, or another flag.
Checklist item cap enforcement
Packages/macOS/CmuxControlSocket/Package.swift, .../ControlCommandCoordinator+WorkspaceTodoSetOpen.swift, .../ControlCommandCoordinatorWorkspaceTodoSetOpenTests.swift
Adds CmuxWorkspaces dependency, rejects workspace.todo.set requests exceeding maxChecklistItems via a centralized error helper, and adds a test for the rejection.
Cross-workspace transfer restrictions
Sources/AppDelegate+DockSurfaceMove.swift, Sources/AppDelegate+MoveTabToNewWorkspace.swift, Sources/DockSplitStore+SurfaceTransfer.swift, Sources/Workspace.swift, Sources/ContentView.swift
Adds canTransferSurfaceAcrossWorkspaceBoundary guards to block moving workspace-todo panels across workspaces via Dock, tab moves, and detached-surface reattachment; simplifies checklist section render condition in ContentView.
Task status reconciliation
Sources/Workspace+PanelLifecycle.swift, Sources/Workspace.swift
Adds reconcileExpiredTaskStatusOverride() calls after agent lifecycle state and sidebar metadata setters run.
Keyboard shortcut updates
Packages/macOS/CmuxSettings/Sources/CmuxSettings/Values/ShortcutAction+Defaults.swift, .../ShortcutAction.swift, Sources/KeyboardShortcutSettings.swift, docs/configuration.md, web/data/cmux-shortcuts.ts
Adds Control modifier to markWorkspaceDone/cycleWorkspaceStatus default shortcuts, excludes toggleChecklistItemComplete from chord shortcuts, and updates docs and web shortcut data accordingly.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant ControlCommandCoordinator
  participant WorkspaceChecklistItem

  Client->>ControlCommandCoordinator: workspace.todo.set(items)
  ControlCommandCoordinator->>WorkspaceChecklistItem: compare items.count to maxChecklistItems
  alt over cap
    ControlCommandCoordinator->>ControlCommandCoordinator: build invalid_params error via workspaceTodoSetTooManyItemsError
    ControlCommandCoordinator-->>Client: return invalid_params error
  else within cap
    ControlCommandCoordinator->>ControlCommandCoordinator: parse and apply items
    ControlCommandCoordinator-->>Client: return success
  end
Loading

Possibly related issues

Possibly related PRs

  • manaflow-ai/cmux#3744: Both PRs modify attachDetachedSurface in Sources/Workspace.swift, this PR adding early guards for .workspaceTodo detached reattachment.
  • manaflow-ai/cmux#7144: Both PRs modify Dock cross-container move eligibility logic in AppDelegate+DockSurfaceMove.swift.
  • manaflow-ai/cmux#7536: Both PRs modify docking eligibility/transfer logic including canMoveSurfaceIntoDock in Sources/AppDelegate+DockSurfaceMove.swift.

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux Full Internationalization ❌ Error PR adds new plain-English CLI and socket error strings; they aren't routed through String(localized:) and no xcstrings keys exist for them. Localize the new --workspace/--window and workspace.todo.set cap errors with catalog keys and translated entries for existing locales.
Docstring Coverage ⚠️ Warning Docstring coverage is 29.17% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Title check ✅ Passed The title concisely captures the main hardening areas changed in this PR.
Description check ✅ Passed The description covers the summary and verification well, though some template sections like Demo Video and Checklist are not fully filled out.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS: edits stay within @MainActor UI/control seams; new helpers are pure value checks, with no new background access or mutable Sendable refs.
Cmux Swift Blocking Runtime ✅ Passed The diff only adds validation/guards and shortcut/default updates; no new blocking waits, sleeps, syncs, locks, or asyncAfter calls were introduced.
Cmux Browser Automation Off-Main ✅ Passed No browser socket-automation files changed; diff is limited to workspace-todo, shortcuts, docking, and sidebar behavior, so the off-main browser rule isn’t implicated.
Cmux Expensive Synchronous Load ✅ Passed No changed path adds a synchronous agent-history load; the new setter hook is lightweight, and the existing load() stays behind the cached cold-start fallback.
Cmux Cache Substitution Correctness ✅ Passed The diff adds validation, transfer guards, and event-driven reconciliation; it does not replace a fresh authoritative read with a cache in any snapshot/history path.
Cmux No Hacky Sleeps ✅ Passed Diff only updates shortcuts/docs/package manifest; no added sleeps, timers, polling, or backoff in changed TS/JS/shell files.
Cmux Algorithmic Complexity ✅ Passed Added loops are on tiny CLI arg lists or cap-50 checklist arrays; transfer checks are constant-time guards, and no new batch rescans or repeated sorts appeared.
Cmux Swift Concurrency ✅ Passed Diff adds validation/guards and shortcut tweaks only; no new DispatchQueue, Combine, completion-handler, or unscoped Task patterns appear in added Swift lines.
Cmux Swift @Concurrent ✅ Passed Touched Swift changes are synchronous guards/setters only; no new @concurrent, nonisolated async, or UI-isolated heavy async call sites were added.
Cmux Swift File And Package Boundaries ✅ Passed PASS: changes are small, focused edits in existing oversized app-glue/state files; the core todo parsing/cap logic lives in CmuxControlSocket/CmuxWorkspaces, with no new large mixed-responsibility...
Cmux Swiftpm Lockfiles ✅ Passed Only a local path dependency was added to CmuxControlSocket; no Package.resolved or Xcode project files changed, so the lockfile rule isn’t triggered.
Cmux Swift Logging ✅ Passed No added or changed logging appears in the HEAD^..HEAD diff; CLI prints are user-facing output, and existing Workspace NSLog calls are #if DEBUG and untouched.
Cmux User-Facing Error Privacy ✅ Passed New errors are generic; the only internal-sounding "TabManager not available" text pre-existed in HEAD^ and wasn’t added by this diff.
Cmux Swiftui State Layout ✅ Passed The only SwiftUI change is a checklist visibility condition in ContentView; no new ObservableObject/@published state, GeometryReader, lazy-row store refs, or render-time mutation.
Cmux Architecture Rethink ✅ Passed The patch is a set of local invariant checks and shared helpers; it adds no sleeps, polling, locks, or split ownership and keeps clear state owners.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The PR only hardens workspace-todo pane/popover behavior; no diff hunks add standalone NSWindow/NSPanel/WindowGroup code or touch cmuxAuxiliaryWindowIdentifiers.
Cmux Source Artifacts ✅ Passed All changed paths are source, tests, docs, config, or checked-in data; no logs, build output, caches, temp folders, or other artifact paths appear.
Cmux No Test Or Debug Seam In Production Source ✅ Passed No touched production Swift file adds a test/debug seam; the delta only tightens production validation and transfer rules.
Cmux No Ambient Global State ✅ Passed PASS: new code stays inside extensions as private helpers; the only new file-scope type is a private enum with cases, and no new singleton/global mutable state was added.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch todo-review-hardening

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR hardens workspace-todo targeting and movement behavior. The main changes are:

  • Rejects blank CLI workspace and window selectors.
  • Enforces the checklist item cap before socket parsing.
  • Blocks workspace-todo panels from crossing workspace and Dock boundaries.
  • Updates default status shortcuts away from macOS spelling shortcuts.
  • Reconciles expired manual status overrides from lifecycle and git/PR updates.
  • Shows checklist items even when the status glyph is hidden.

Confidence Score: 5/5

This looks safe to merge after checking the Dock attach edge case.

  • No blocking issues found in the changed code.
  • One Dock attach path can mishandle an already-detached workspace-todo panel in an edge state.

Sources/DockSplitStore+SurfaceTransfer.swift

Important Files Changed

Filename Overview
CLI/CMUXCLI+WorkspaceTodo.swift Adds validation for empty workspace and window selector values before parsing workspace-todo command targets.
Packages/macOS/CmuxControlSocket/Package.swift Adds CmuxWorkspaces as a local dependency for checklist cap sharing.
Packages/macOS/CmuxControlSocket/Sources/CmuxControlSocket/Coordinator/WorkspaceTodo/ControlCommandCoordinator+WorkspaceTodoSetOpen.swift Rejects over-cap workspace.todo.set arrays before item-level parsing.
Sources/AppDelegate+DockSurfaceMove.swift Adds workspace-todo transfer checks to Dock and workspace move paths.
Sources/AppDelegate+MoveTabToNewWorkspace.swift Centralizes the workspace-todo boundary check and applies it to move targets and new-workspace moves.
Sources/DockSplitStore+SurfaceTransfer.swift Rejects workspace-todo panels when attaching detached surfaces into Dock.
Sources/Workspace.swift Reconciles expired status overrides on git and PR metadata writes and rejects cross-workspace todo reattachment.
Sources/Workspace+PanelLifecycle.swift Reconciles expired status overrides after agent lifecycle state updates.
Sources/ContentView.swift Lets the sidebar checklist render independently from the workspace status glyph.
Packages/macOS/CmuxSettings/Sources/CmuxSettings/Values/ShortcutAction+Defaults.swift Updates package shortcut defaults and disables chording for checklist toggles.
Sources/KeyboardShortcutSettings.swift Mirrors shortcut default and chording changes in the app shortcut table.
docs/configuration.md Updates configuration docs for the new status shortcut defaults.
web/data/cmux-shortcuts.ts Updates localized web shortcut data for the new status shortcut defaults.

Reviews (1): Last reviewed commit: "Harden todo CLI targeting, panel moves, ..." | Re-trigger Greptile

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@Sources/DockSplitStore`+SurfaceTransfer.swift:
- Around line 210-211: The workspace-transfer eligibility rule for workspaceTodo
is duplicated across DockSplitStore, AppDelegate, and Workspace. Move the shared
base check onto a common symbol such as PanelType or Panel (for example a
transferability property/method), then update DockSplitStore+SurfaceTransfer,
AppDelegate.canTransferSurfaceAcrossWorkspaceBoundary(panel:), and
Workspace.attachDetachedSurface to delegate to that single definition, keeping
Workspace’s same-workspace exception separate if needed.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 63e6011a-e91f-4dae-a3db-d74a6c768ff6

📥 Commits

Reviewing files that changed from the base of the PR and between cfb8ba2 and a195541.

📒 Files selected for processing (15)
  • CLI/CMUXCLI+WorkspaceTodo.swift
  • Packages/macOS/CmuxControlSocket/Package.swift
  • Packages/macOS/CmuxControlSocket/Sources/CmuxControlSocket/Coordinator/WorkspaceTodo/ControlCommandCoordinator+WorkspaceTodoSetOpen.swift
  • Packages/macOS/CmuxControlSocket/Tests/CmuxControlSocketTests/ControlCommandCoordinatorWorkspaceTodoSetOpenTests.swift
  • Packages/macOS/CmuxSettings/Sources/CmuxSettings/Values/ShortcutAction+Defaults.swift
  • Packages/macOS/CmuxSettings/Sources/CmuxSettings/Values/ShortcutAction.swift
  • Sources/AppDelegate+DockSurfaceMove.swift
  • Sources/AppDelegate+MoveTabToNewWorkspace.swift
  • Sources/ContentView.swift
  • Sources/DockSplitStore+SurfaceTransfer.swift
  • Sources/KeyboardShortcutSettings.swift
  • Sources/Workspace+PanelLifecycle.swift
  • Sources/Workspace.swift
  • docs/configuration.md
  • web/data/cmux-shortcuts.ts

Comment on lines 210 to +211
guard bonsplitController.allPaneIds.contains(paneId), panels[detached.panelId] == nil else { return nil }
guard detached.panel.panelType != .workspaceTodo else { return nil }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win

Duplicated workspaceTodo eligibility check — consider centralizing.

This inline detached.panel.panelType != .workspaceTodo re-implements the same rule as AppDelegate.canTransferSurfaceAcrossWorkspaceBoundary(panel:) (Sources/AppDelegate+MoveTabToNewWorkspace.swift:15-17), and Workspace.attachDetachedSurface (Sources/Workspace.swift:9407-9409) has yet another inline copy with a same-workspace exception. Since DockSplitStore/Workspace can't call the AppDelegate extension method directly, the rule ends up duplicated three times. If the eligibility rule ever changes (e.g. another panel type becomes non-transferable), it's easy to update one site and miss the others.

Consider moving the base rule onto PanelType/Panel (e.g. panel.isTransferableAcrossWorkspaces) so all three call sites share one definition, with AppDelegate.canTransferSurfaceAcrossWorkspaceBoundary and Workspace's same-workspace exception both delegating to it.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Sources/DockSplitStore`+SurfaceTransfer.swift around lines 210 - 211, The
workspace-transfer eligibility rule for workspaceTodo is duplicated across
DockSplitStore, AppDelegate, and Workspace. Move the shared base check onto a
common symbol such as PanelType or Panel (for example a transferability
property/method), then update DockSplitStore+SurfaceTransfer,
AppDelegate.canTransferSurfaceAcrossWorkspaceBoundary(panel:), and
Workspace.attachDetachedSurface to delegate to that single definition, keeping
Workspace’s same-workspace exception separate if needed.

@vercel
vercel Bot temporarily deployed to Preview – cmux July 9, 2026 21:22 Inactive
@lawrencecchen lawrencecchen added the stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening. label Sep 23, 2026
@github-project-automation github-project-automation Bot moved this from Todo to Done in cmux backlog Sep 23, 2026

This branch was previously deployed

1 inactive deployment
Preview – cmux — a1955418 Deployed Jul 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants