Skip to content

iroh transport P2: cmux-iroh FFI packaging (crate + xcframework + CI toolchain) - #7813

Closed
azooz2003-bit wants to merge 4 commits into
mainfrom
feat-iroh-p2-packaging
Closed

azooz2003-bit wants to merge 4 commits into
mainfrom
feat-iroh-p2-packaging

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 10, 2026 •

Copy link
Copy Markdown
Collaborator

Implements delivery-plan step 2 of https://github.com/manaflow-ai/cmux/blob/main/plans/feat-ios-iroh/DESIGN.md (iroh as the default iOS-to-Mac transport; decision 2026-06-09).

Graduates the FFI spike to native/cmux-iroh/ (iroh pinned =1.0.2, blocking C API: keygen, bind with caller-provided secret key, id, route JSON, online, accept, connect, recv, send, close; stable error-kind codes for CmxConnectFailureKind mapping; ALPN dev.cmux.mobile.terminal/0). Adds scripts/ensure-cmux-iroh.sh building CmuxIrohFFI.xcframework (macOS arm64+x86_64 universal, iOS device arm64, iOS sim arm64) mirroring the GhosttyKit ensure pattern, wires it into reload/setup/ios scripts, adds iOS Rust targets to scripts/install-rust-ci.sh, and provisions the toolchain across CI workflows. The xcframework links into both apps but is referenced by no code: zero behavior change.

Verified: cargo build on all 4 targets; cargo test echo self-test; xcframework slice check (macOS x86_64+arm64, iOS device arm64, sim arm64); macOS compile-only tagged build; iOS arm64-sim compile-only build; pbxproj + workspace-groups + Package.resolved lints.

Part of a stacked series: P3 phone dial lane and P4 Mac host lane follow on top of this branch.

🤖 Generated with Claude Code


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Medium Risk
Large new native dependency (iroh) and broad CI/build changes affect every macOS/iOS compile; the terminal resync change touches mobile replay lifecycle but is localized and tested.

Overview
Adds native/cmux-iroh (iroh =1.0.2) with a blocking C API for endpoint bind/connect, route JSON, and bidirectional streams, plus scripts/ensure-cmux-iroh.sh to build and cache CmuxIrohFFI.xcframework (macOS universal, iOS device/sim) like GhosttyKit. macOS and iOS Xcode projects link the xcframework and add SystemConfiguration / Security / Network (iOS) / CoreWLAN (macOS); the artifact is gitignored.

CI and local builds call ensure-cmux-iroh.sh after Rust install; install-rust-ci.sh gains iOS Rust targets; release drops inline rustup in favor of that script; setup/reload and iOS TestFlight scripts provision the FFI.

Mobile shell: introduces requestTerminalResync so sync resyncs defer when a replay barrier owns the surface (avoids racing stale replays); the iOS test is tightened around subscribe ordering and replay ordinals.

No Swift call sites into the FFI yet—link-only packaging for the iroh transport lane.

Reviewed by Cursor Bugbot for commit ff23697. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Packages the new native/cmux-iroh Rust FFI into CmuxIrohFFI.xcframework and wires it into scripts/CI for macOS and iOS builds. Adds a terminal replay ownership fix; the iroh framework is linked but unused, so transport behavior is unchanged.

  • New Features

    • Added native/cmux-iroh crate (iroh =1.0.2) with a blocking C API: keygen, bind, id/route JSON, online, accept/connect, recv/send, close; stable error codes; ALPN dev.cmux.mobile.terminal/0.
    • Built CmuxIrohFFI.xcframework (macOS arm64+x86_64, iOS arm64 device, iOS arm64 sim) via scripts/ensure-cmux-iroh.sh with caching; linked into macOS and iOS Xcode projects.
    • Provisioned across CI/local flows: scripts/setup.sh, scripts/reload.sh, reload-build, test (test-ios, test-e2e, test-depot), nightly, perf, macOS compat, ios-testflight, ios-app-store, and release (now uses scripts/install-rust-ci.sh); iOS lanes provision the FFI before Xcode resolves frameworks. Added Rust targets in scripts/install-rust-ci.sh (aarch64-apple-ios, aarch64-apple-ios-sim).
    • Linked system frameworks: macOS SystemConfiguration, CoreWLAN, Security; iOS SystemConfiguration, Security, Network; ignored CmuxIrohFFI.xcframework in git.
  • Bug Fixes

    • Serialized terminal resync ownership to avoid racing an in-flight replay barrier; added requestTerminalResync and routed resyncs through it.
    • Made the terminal resync test deterministic by gating on initial subscribe and tracking replay ordinals with stream tokens.

Written for commit ff23697. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features

    • Added a native networking layer integration for iOS and macOS, including endpoint setup, connection send/receive, and structured error reporting.
    • Improved terminal replay recovery by introducing a resync request for terminal output.
  • Build Improvements

    • Automated provisioning and caching of the required native Apple binaries across CI workflows and local setup, including release builds.
    • Expanded CI Rust target installation for iOS and simulators.
  • Bug Fixes

    • Improved iOS/e2e terminal resync test reliability by removing race-prone behavior and making token handling deterministic.

@vercel

vercel Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jul 11, 2026 1:34am
cmux-staging Building Building Preview, Comment Jul 11, 2026 1:34am

@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This change adds a Rust-based cmux-iroh C FFI library, packages it into an Apple XCFramework, links it into macOS and iOS projects, provisions it across local and CI build paths, and updates terminal resync handling and deterministic test coverage.

Changes

cmux-iroh FFI

Layer / File(s) Summary
Rust FFI API and validation
native/cmux-iroh/*
Defines iroh endpoint, connection, error, blocking I/O, lifecycle, and string-management APIs with an end-to-end exchange test.
Apple XCFramework packaging
scripts/ensure-cmux-iroh.sh, scripts/install-rust-ci.sh, native/cmux-iroh/*, .gitignore
Builds Apple static libraries, caches output by source hash, merges archives, and creates the XCFramework.
Xcode and local build wiring
cmux.xcodeproj/project.pbxproj, ios/cmux-ios.xcodeproj/project.pbxproj, scripts/*, ios/scripts/*
Links the XCFramework and system frameworks, and provisions it before reload and archive flows.
CI and release provisioning
.github/workflows/*
Adds cmux-iroh provisioning to macOS, iOS, test, nightly, performance, release, and reload-build jobs.

Terminal resync determinism

Layer / File(s) Summary
Replay-aware terminal resync
Packages/iOS/CmuxMobileShell/Sources/CmuxMobileShell/*
Adds deferred resync behavior when a replay barrier is owned and routes output recovery through the new resync method.
Deterministic resync test
ios/cmuxPackage/Tests/cmuxFeatureTests/cmuxFeatureTests.swift
Coordinates stream acknowledgements and replay request ordinals to verify the expected follow-up replay.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related issues

Possibly related PRs

Suggested reviewers: lawrencecchen


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (2 errors, 1 warning)

Check name Status Explanation Resolution
Cmux No Hacky Sleeps ❌ Error scripts/ensure-cmux-iroh.sh adds a sleep 1 poll while waiting for the cache lock to clear, using fixed-delay synchronization for build-cache readiness. Replace the 1s polling loop with a blocking lock or real completion signal (e.g. flock/wait on lock owner) so cache readiness isn’t inferred by sleeping.
Cmux User-Facing Error Privacy ❌ Error Public FFI errors pass through raw iroh details via format!("{error:#}"), exposing upstream internals in caller-visible messages. Sanitize CmuxIrohError.message to cmux-level text (e.g. transport unavailable) and keep raw iroh diagnostics in internal logs only.
Docstring Coverage ⚠️ Warning Docstring coverage is 32.50% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (22 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS: The only production Swift diff is on an existing @MainActor @Observable store, and the new resync helper plus call stay on that actor; no new Sendable/UI background access.
Cmux Swift Blocking Runtime ✅ Passed PASS: Production Swift changes add a non-blocking resync helper/call site only; the new sleep/polling logic is confined to test scaffolding and allowed by the rule.
Cmux Browser Automation Off-Main ✅ Passed PR only changes iOS terminal replay lifecycle code; no browser.*, WebKit/AppKit, processV2Command, or socketWorkerMethods paths are touched.
Cmux Expensive Synchronous Load ✅ Passed No diff hunk added a sync load; touched Swift files only adjust terminal replay logic/tests, with no RestorableAgentSessionIndex.load() or file/JSON parsing on main-actor paths.
Cmux Cache Substitution Correctness ✅ Passed The diff only redirects resyncs to a helper that either replays fresh output or defers to an active barrier; no authoritative read was replaced by a cached value.
Cmux Algorithmic Complexity ✅ Passed PASS: The change adds only O(1) per-surface dictionary/set checks in requestTerminalResync and reuses the existing surface loop; no nested rescans or repeated filters were introduced.
Cmux Swift Concurrency ✅ Passed Only two Swift files changed; the diff adds a synchronous resync helper and swaps one call site, with no new DispatchQueue, Combine, completion-handler, or fire-and-forget Task patterns.
Cmux Swift @Concurrent ✅ Passed Swift diff only adds a sync resync wrapper and swaps one call; no @concurrent, nonisolated async, or actor-hop violations appear.
Cmux Swift File And Package Boundaries ✅ Passed Only incidental 1-line change hit the oversized app file; the added 442-line Swift extension is a focused terminal-replay lifecycle package file, not mixed app-target feature logic.
Cmux Swiftpm Lockfiles ✅ Passed The added cmux-iroh ignore file only ignores target/, and the project changes are xcframework/framework linkages, not SwiftPM package references.
Cmux Swift Logging ✅ Passed New log uses MobileDebugLog.anchormux, which is #if DEBUG-wrapped cmux logging; no print/debugPrint/dump/NSLog or problematic Logger changes were introduced.
Cmux Full Internationalization ✅ Passed No user-facing localized copy changed; touched Swift edits are tests/comments/debug logs and workflow/script/config changes only, with no xcstrings or locale files modified.
Cmux Swiftui State Layout ✅ Passed Only MobileShellComposite store/lifecycle files changed; no new SwiftUI views, state wrappers, GeometryReader, or row-bound store refs were introduced.
Cmux Architecture Rethink ✅ Passed The new resync path reuses existing barrier/dropped-output ownership with a clear invariant; no sleeps, polling, locks, or split owners were added.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The Swift diffs are terminal replay logic and tests only; no NSWindow/NSPanel/WindowGroup additions or cmuxAuxiliaryWindowIdentifiers changes.
Cmux Source Artifacts ✅ Passed All changed paths are source/config/scripts or ignore rules; no generated logs, caches, build output, or checked-in xcframework artifacts were added.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The only new production member, requestTerminalResync, is called by resyncTerminalOutput and has no test/debug-only shape.
Cmux No Ambient Global State ✅ Passed The only new Swift API is requestTerminalResync on MobileShellComposite; no new file-scope funcs, globals, or singletons were added.
Title check ✅ Passed The title accurately summarizes the main change: packaging cmux-iroh FFI into an xcframework and wiring CI toolchain support.
Description check ✅ Passed The description covers the summary and testing details, though it omits the template's demo video, checklist, and review-trigger sections.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-iroh-p2-packaging

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

socket-security Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​iroh@​1.0.21310093100100

View full report

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 221c7cb. Configure here.

exit 0
fi
sleep 1
done

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale build lock hangs forever

High Severity

The xcframework cache lock wait loop never times out or reclaims a stale lock directory. If a prior ensure-cmux-iroh.sh run is killed after creating the lock but before finishing, later runs spin forever waiting to acquire the lock while the cache artifact never appears.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 221c7cb. Configure here.

build_number="$(date -u +%Y%m%d%H%M%S)"
ARCHIVE_PATH="$out/cmux-ios-beta.xcarchive"
[[ -x "$REPO_ROOT/scripts/ensure-ghosttykit.sh" ]] && ( cd "$REPO_ROOT" && ./scripts/ensure-ghosttykit.sh ) || true
[[ -x "$REPO_ROOT/scripts/ensure-cmux-iroh.sh" ]] && ( cd "$REPO_ROOT" && ./scripts/ensure-cmux-iroh.sh ) || true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Local archive ignores iroh provision

Medium Severity

Local TestFlight archive builds now call ensure-cmux-iroh.sh but append || true, so a non-zero exit from provisioning is ignored. The script continues to xcodebuild archive without CmuxIrohFFI.xcframework, producing a confusing link error instead of surfacing the provisioning failure.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 221c7cb. Configure here.

@greptile-apps

greptile-apps Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR packages the new iroh transport FFI for Apple builds. The main changes are:

  • Added the native/cmux-iroh Rust crate and C header.
  • Added an xcframework build/cache script for macOS, iOS device, and iOS simulator slices.
  • Linked CmuxIrohFFI.xcframework into the macOS and iOS Xcode projects.
  • Wired provisioning into local reload/setup scripts and CI workflows.
  • Updated iOS terminal replay resync handling and its test coverage.

Confidence Score: 5/5

This looks safe to merge from the latest reviewed changes.

  • No blocking issues found in the changed code.

Important Files Changed

Filename Overview
native/cmux-iroh/src/lib.rs Adds the blocking Rust/C endpoint and connection API for the iroh transport.
scripts/ensure-cmux-iroh.sh Builds and links the generated CmuxIrohFFI.xcframework from cached Rust artifacts.
Packages/iOS/CmuxMobileShell/Sources/CmuxMobileShell/MobileShellComposite+TerminalReplayLifecycle.swift Adds barrier-aware terminal resync requests for replay ownership.
Packages/iOS/CmuxMobileShell/Sources/CmuxMobileShell/MobileShellComposite.swift Routes terminal sync resyncs through the new replay-aware helper.
cmux.xcodeproj/project.pbxproj Links the generated iroh xcframework and required system frameworks into the macOS app.
ios/cmux-ios.xcodeproj/project.pbxproj Links the generated iroh xcframework and required system frameworks into the iOS app.

Reviews (3): Last reviewed commit: "Fix iOS lane identity guard provisioning" | Re-trigger Greptile

if connection.is_null() {
return;
}
let connection = unsafe { Box::from_raw(connection) };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Raw Handle Freed During Calls

When Swift closes a connection while another queue is blocked in cmux_iroh_connection_recv() or cmux_iroh_connection_send(), this reconstructs and drops the Box<CmuxIrohConnection> even though those functions may still hold references into the same allocation. The handle API exposes blocking calls and per-stream mutexes, so teardown needs shared lifetime ownership or a closed state instead of freeing the raw pointer while in-flight operations can still use it.

if endpoint.is_null() {
return;
}
let endpoint = unsafe { Box::from_raw(endpoint) };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Endpoint Freed During Waits

When an endpoint is closed from teardown while accept, online, connect, or route_json is already running, this drops the boxed endpoint after those functions have converted the raw pointer with endpoint.as_ref(). A concurrent close can free the allocation backing an in-flight blocking call, so callers can get undefined behavior instead of a clean endpoint-closed result.

Comment on lines +110 to +117
while ! mkdir "${LOCK_DIR}" 2>/dev/null; do
if [ -d "${CACHE_XCFRAMEWORK}" ]; then
link_local_xcframework "${CACHE_XCFRAMEWORK}"
echo "using cached ${LOCAL_XCFRAMEWORK}"
exit 0
fi
sleep 1
done

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Stale Lock Hangs Builds

If the first ensure-cmux-iroh.sh process is killed after creating ${LOCK_DIR} but before the trap removes it, later setup.sh, reload.sh, or CI provisioning runs for the same source hash loop here forever because the cached xcframework never appears. This new build prerequisite needs stale-lock recovery or a bounded wait so interrupted Rust builds do not permanently wedge app builds until the hidden lock directory is deleted by hand.

Rule Used: Flag fixed sleeps, delayed dispatch, timers, polli... (source)

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ios-testflight.yml:
- Around line 369-374: Update the iosPathPattern path gate to include
native/cmux-iroh/** and scripts/ensure-cmux-iroh.sh, ensuring scheduled runs
with only cmux-iroh FFI or provisioning changes set needsBuild=true and archive
the newly provisioned framework.

In `@scripts/ensure-cmux-iroh.sh`:
- Around line 109-117: Replace the unbounded mkdir polling loop around LOCK_DIR
with an event-driven flock acquisition when available, or a bounded retry
mechanism with a maximum attempt count and explicit failure handling. Preserve
the cached CACHE_XCFRAMEWORK fast path and ensure lock cleanup/release is
handled correctly.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 94bf8464-ddbc-4928-a316-f65d1caf1183

📥 Commits

Reviewing files that changed from the base of the PR and between 9190ac6 and 221c7cb.

⛔ Files ignored due to path filters (1)
  • native/cmux-iroh/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (26)
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/ci.yml
  • .github/workflows/ios-app-store.yml
  • .github/workflows/ios-testflight.yml
  • .github/workflows/nightly.yml
  • .github/workflows/perf-activation.yml
  • .github/workflows/release.yml
  • .github/workflows/reload-build.yml
  • .github/workflows/test-depot.yml
  • .github/workflows/test-e2e.yml
  • .github/workflows/test-ios.yml
  • .github/workflows/tmux-corpus.yml
  • .gitignore
  • cmux.xcodeproj/project.pbxproj
  • ios/cmux-ios.xcodeproj/project.pbxproj
  • ios/scripts/cloud-testflight.sh
  • ios/scripts/reload.sh
  • ios/scripts/upload-testflight.sh
  • native/cmux-iroh/.gitignore
  • native/cmux-iroh/Cargo.toml
  • native/cmux-iroh/include/cmux_iroh_ffi.h
  • native/cmux-iroh/src/lib.rs
  • scripts/ensure-cmux-iroh.sh
  • scripts/install-rust-ci.sh
  • scripts/reload.sh
  • scripts/setup.sh

Comment on lines +369 to +374
- name: Provision cmux-iroh FFI
run: |
./scripts/install-rust-ci.sh
export PATH="$HOME/.cargo/bin:$PATH"
./scripts/ensure-cmux-iroh.sh

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Include the cmux-iroh inputs in the scheduled-upload path gate.

The iosPathPattern at Line 244 does not match native/cmux-iroh/** or scripts/ensure-cmux-iroh.sh. A scheduled run containing only an FFI or packaging change can therefore set needsBuild=false and skip archiving the newly provisioned framework.

Proposed fix
- const iosPathPattern = /^(ios\/|Packages\/Shared\/|Packages\/iOS\/|Sources\/Mobile\/|vendor\/stack-auth-swift-sdk-prerelease\/|ghostty$|scripts\/ensure-ghosttykit\.sh$|scripts\/ghosttykit-checksums\.txt$|scripts\/install-zig-ci\.sh$|\.github\/workflows\/ios-testflight\.yml$)/;
+ const iosPathPattern = /^(ios\/|native\/cmux-iroh\/|Packages\/Shared\/|Packages\/iOS\/|Sources\/Mobile\/|vendor\/stack-auth-swift-sdk-prerelease\/|ghostty$|scripts\/ensure-cmux-iroh\.sh$|scripts\/ensure-ghosttykit\.sh$|scripts\/ghosttykit-checksums\.txt$|scripts\/install-zig-ci\.sh$|\.github\/workflows\/ios-testflight\.yml$)/;
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: Provision cmux-iroh FFI
run: |
./scripts/install-rust-ci.sh
export PATH="$HOME/.cargo/bin:$PATH"
./scripts/ensure-cmux-iroh.sh
const iosPathPattern = /^(ios\/|native\/cmux-iroh\/|Packages\/Shared\/|Packages\/iOS\/|Sources\/Mobile\/|vendor\/stack-auth-swift-sdk-prerelease\/|ghostty$|scripts\/ensure-cmux-iroh\.sh$|scripts\/ensure-ghosttykit\.sh$|scripts\/ghosttykit-checksums\.txt$|scripts\/install-zig-ci\.sh$|\.github\/workflows\/ios-testflight\.yml$)/;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ios-testflight.yml around lines 369 - 374, Update the
iosPathPattern path gate to include native/cmux-iroh/** and
scripts/ensure-cmux-iroh.sh, ensuring scheduled runs with only cmux-iroh FFI or
provisioning changes set needsBuild=true and archive the newly provisioned
framework.

Comment on lines +109 to +117
LOCK_DIR="${CACHE_ROOT}/.${BUILD_KEY}.lock"
while ! mkdir "${LOCK_DIR}" 2>/dev/null; do
if [ -d "${CACHE_XCFRAMEWORK}" ]; then
link_local_xcframework "${CACHE_XCFRAMEWORK}"
echo "using cached ${LOCAL_XCFRAMEWORK}"
exit 0
fi
sleep 1
done

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Replace sleep 1 polling loop with a bounded or event-driven lock mechanism.

The sleep 1 inside the while loop is a fixed delay used as synchronization in a polling loop, which the coding guidelines prohibit in shell scripts. If the building process hangs indefinitely, this loop spins forever with no timeout. Consider using flock for blocking lock acquisition, or add a bounded retry count to prevent unbounded spinning.

♻️ Proposed fix: bounded retry with flock fallback
 LOCK_DIR="${CACHE_ROOT}/.${BUILD_KEY}.lock"
-MAX_WAIT=3600  # 1 hour max wait for another build
-WAITED=0
-while ! mkdir "${LOCK_DIR}" 2>/dev/null; do
-  if [ -d "${CACHE_XCFRAMEWORK}" ]; then
-    link_local_xcframework "${CACHE_XCFRAMEWORK}"
-    echo "using cached ${LOCAL_XCFRAMEWORK}"
-    exit 0
-  fi
-  sleep 1
-done
+MAX_WAIT=3600
+WAITED=0
+while ! mkdir "${LOCK_DIR}" 2>/dev/null; do
+  if [ -d "${CACHE_XCFRAMEWORK}" ]; then
+    link_local_xcframework "${CACHE_XCFRAMEWORK}"
+    echo "using cached ${LOCAL_XCFRAMEWORK}"
+    exit 0
+  fi
+  WAITED=$((WAITED + 1))
+  if [ "$WAITED" -ge "$MAX_WAIT" ]; then
+    echo "error: timed out after ${MAX_WAIT}s waiting for build lock" >&2
+    exit 1
+  fi
+  sleep 1
+done
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/ensure-cmux-iroh.sh` around lines 109 - 117, Replace the unbounded
mkdir polling loop around LOCK_DIR with an event-driven flock acquisition when
available, or a bounded retry mechanism with a maximum attempt count and
explicit failure handling. Preserve the cached CACHE_XCFRAMEWORK fast path and
ensure lock cleanup/release is handled correctly.

Sources: Coding guidelines, Path instructions

@blacksmith-sh

This comment has been minimized.

@azooz2003-bit

Copy link
Copy Markdown
Collaborator Author

Closing because the implementation is architecturally superseded by current main at 22f9e5e; merging this old head would restore obsolete transport code, and no unique required capability remains.

This branch was successfully deployed

1 active deployment
Preview – cmux — ff236970 Deployed Jul 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant