Skip to content

Fix Iroh release-gate readiness race - #8493

Merged
azooz2003-bit merged 2 commits into
mainfrom
fix-iroh-release-gate-readiness
Jul 19, 2026
Merged

azooz2003-bit merged 2 commits into
mainfrom
fix-iroh-release-gate-readiness

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 19, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • revalidate ticket minting after launching or relaunching the tagged Mac
  • require the release gate to observe a trusted Iroh route before launching iOS
  • preserve a red-then-green behavioral regression test

Verification

  • node --test scripts/lib/mobile-attach.test.mjs (30/30)
  • bash -n scripts/lib/mobile-attach.sh scripts/run-iroh-release-gate.sh
  • git diff --check

The previous current-main hosted run failed automatic and relay-only because the Mac debug socket appeared before broker registration could mint a trusted Iroh ticket.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Summary by cubic

Fix release-gate readiness race by waiting for a trusted Iroh ticket after the tagged Mac app launches or relaunches. This prevents the gate from proceeding when only the debug socket exists.

  • Bug Fixes
    • Revalidate minting in cmux_attach_ensure_mac before reporting Mac ready; add bounded retries via CMUX_ATTACH_MINT_MAX_ATTEMPTS.
    • In scripts/run-iroh-release-gate.sh, require a trusted route before proceeding and set CMUX_ATTACH_MINT_MAX_ATTEMPTS=120; switch to physical_device.
    • Add regression test to confirm readiness is rechecked after relaunch and that transient empty mints are retried.

Written for commit 259b4e6. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved Mac app readiness checks after relaunches.
    • Attach operations now wait for a usable connection ticket before reporting success.
    • Added clearer failure handling and target-specific warnings when attachment setup cannot complete.
    • Improved reliability for physical-device attachment workflows, including configurable retry behavior.

@coderabbitai

coderabbitai Bot commented Jul 19, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: bd68b7e5-0a4a-43f3-a0cc-96d94620f8d9

📥 Commits

Reviewing files that changed from the base of the PR and between b468f06 and 259b4e6.

📒 Files selected for processing (3)
  • scripts/lib/mobile-attach.sh
  • scripts/lib/mobile-attach.test.mjs
  • scripts/run-iroh-release-gate.sh

📝 Walkthrough

Walkthrough

Mac attach readiness now validates attach-ticket minting after the tagged socket appears. A relaunch test covers delayed minting, and the Iroh release gate passes the physical-device target.

Changes

Mac attach readiness

Layer / File(s) Summary
Attach-ticket readiness validation
scripts/lib/mobile-attach.sh
cmux_attach_ensure_mac retries ticket minting after tagged socket readiness when repo_root is set, using a configurable attempt limit and target-specific warnings.
Relaunch and release-gate coverage
scripts/lib/mobile-attach.test.mjs, scripts/run-iroh-release-gate.sh
The relaunch test verifies ticket minting succeeds on the second call, while the release gate invokes Mac ensuring with the physical_device target.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseGate
  participant cmux_attach_ensure_mac
  participant TaggedMacSocket
  participant cmux_attach_mint_url
  ReleaseGate->>cmux_attach_ensure_mac: Ensure physical-device Mac attach
  cmux_attach_ensure_mac->>TaggedMacSocket: Poll for tagged socket
  TaggedMacSocket-->>cmux_attach_ensure_mac: Socket becomes ready
  cmux_attach_ensure_mac->>cmux_attach_mint_url: Mint attach URL
  cmux_attach_mint_url-->>cmux_attach_ensure_mac: Return usable URL
  cmux_attach_ensure_mac-->>ReleaseGate: Return success
Loading

Possibly related PRs

  • manaflow-ai/cmux#7864: Introduces target-aware attach-ticket creation and selection used by the updated Mac attach flow.
  • manaflow-ai/cmux#8462: Covers overlapping Iroh release-gate attach and relaunch orchestration.

Suggested reviewers: lawrencecchen


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux No Hacky Sleeps ❌ Error cmux_attach_ensure_mac now calls the polling cmux_attach_mint_url after socket-up; that helper sleeps 0.5s and retries to wait for broker readiness. Replace the wall-clock polling with an event-driven readiness signal or a cancellation-aware timeout abstraction; keep mint validation but avoid sleep-based retries.
Description check ⚠️ Warning It covers summary and verification, but omits the required Review Trigger and Checklist sections from the template. Add the Review Trigger block, Checklist section, and a demo video link; rename Verification to Testing to match the template.
✅ Passed checks (23 passed)
Check name Status Explanation
Title check ✅ Passed It clearly summarizes the main fix: preventing the Iroh release-gate readiness race.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed The diff only changes shell scripts; no .swift files or Swift UI/service code were modified, so Swift actor-isolation rules are not implicated.
Cmux Swift Blocking Runtime ✅ Passed No Swift files were changed; the blocking-runtime rule only applies to non-test Swift code, so this PR doesn’t introduce Swift blocking sync.
Cmux Browser Automation Off-Main ✅ Passed PASS: The PR only changes shell scripts/tests; the rule targets TerminalController.swift and ControlCommandExecutionPolicy.swift, so no browser-automation routing change is present.
Cmux Expensive Synchronous Load ✅ Passed The PR diff only changes two shell scripts; no Swift files or agent-history load paths were added or moved.
Cmux Cache Substitution Correctness ✅ Passed The PR adds freshness checks for Mac attach readiness; it does not swap an authoritative persistence/history/snapshot read for a cached value.
Cmux Algorithmic Complexity ✅ Passed No scalable collection scan was introduced; the only new scan is over a single ticket's route list, and the retry loops are bounded by explicit attempt caps.
Cmux Swift Concurrency ✅ Passed No Swift files were changed; the diff only touches shell scripts and a JS test, so the Swift concurrency rule is not applicable.
Cmux Swift @Concurrent ✅ Passed No Swift files were changed in the PR diff, so the @concurrent review rule is not applicable.
Cmux Swift Package Boundaries ✅ Passed Diff touches only shell scripts and a JS test; no Swift sources or app-target package-boundary changes are present.
Cmux Swiftpm Lockfiles ✅ Passed Diff only changes shell scripts; no Package.swift, Package.resolved, .gitignore, workflow, or Xcode package-reference files were touched.
Cmux Swift Logging ✅ Passed No .swift files or logging changes are present in the diff, so the Swift logging rule is not triggered.
Cmux User-Facing Error Privacy ✅ Passed The patch only adds a generic readiness warning about an Iroh ticket; it doesn’t introduce new env vars, secrets, raw upstream messages, or other private details.
Cmux Full Internationalization ✅ Passed Diff only touches shell scripts/tests; no Swift/UI/web localization assets or locale catalogs were added or changed.
Cmux Swiftui State Layout ✅ Passed No SwiftUI files or state/layout changes are in the diff; only shell scripts/tests were modified, so the rule doesn't apply.
Cmux Architecture Rethink ✅ Passed PR touches only shell scripts/tests; no Swift files or Swift architecture changes are present, so the Swift rethink rule is not applicable.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The PR only changes shell and test JS files; no Swift window/controller code or cmuxAuxiliaryWindowIdentifiers changes are present.
Cmux Source Artifacts ✅ Passed Touched paths are hand-written scripts/tests, which the rule explicitly allows; no artifact directories or generated outputs are present.
Cmux No Test Or Debug Seam In Production Source ✅ Passed Only two shell scripts changed; no Swift files under production Sources/ were added or modified, so no test/debug seam was introduced there.
Cmux No Ambient Global State ✅ Passed PASS: The PR only changes shell/JS scripts; no production Swift files or new ambient-global-state surfaces were introduced.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-iroh-release-gate-readiness

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR fixes a race condition in the Iroh release gate where the Mac debug socket could appear before the broker completed registration, causing cmux_attach_ensure_mac to return success with a Tailscale-only (untrusted) ticket while iOS was then launched expecting a working Iroh route.

  • mobile-attach.sh: After the app launches and the socket appears, the post-launch polling path now calls cmux_attach_mint_url with the full retry budget (controlled by CMUX_ATTACH_MINT_MAX_ATTEMPTS) before returning 0, instead of returning immediately on socket presence. If repo_root is absent (backward-compat callers), the old fast-return behavior is preserved.
  • run-iroh-release-gate.sh: The target is corrected from simulator_injection (no Iroh requirement) to physical_device (Iroh route required), and the retry budget is expanded to 120 attempts (≈60 s) to give the broker enough time to register. A companion regression test validates the red-then-green relaunch scenario.

Confidence Score: 5/5

Safe to merge. The change correctly gates Mac readiness on Iroh route presence and is well-covered by new and existing tests.

The post-launch path in cmux_attach_ensure_mac now delegates readiness to the already-tested cmux_attach_mint_url abstraction, which is the same approach used by the pre-existing early-probe. The target correction from simulator_injection to physical_device in the release gate aligns the probe with what the gate actually needs to verify. The retry budget increase to 120 attempts (≈60 s) is proportionate to the async broker registration window described in the bug report. No new sleep primitives are introduced and the backward-compat path (repo_root absent) is preserved.

No files require special attention.

Important Files Changed

Filename Overview
scripts/lib/mobile-attach.sh Post-launch socket-ready path now requires a successful cmux_attach_mint_url call (with configurable retry budget) before returning 0; backward compat preserved when repo_root is empty. Logic is consistent with the pre-existing early-probe pattern on lines 167-182.
scripts/lib/mobile-attach.test.mjs Adds ensureMacAfterRelaunch test that stubs cmux_attach_mint_url to fail on the first call and succeed on the second, correctly asserting status=0 and callCount=2 to validate the red-then-green relaunch scenario.
scripts/run-iroh-release-gate.sh Corrects the Mac relaunch call from simulator_injection (no Iroh requirement) to physical_device (Iroh route required) and sets CMUX_ATTACH_MINT_MAX_ATTEMPTS=120 to give the broker ≈60 s to register before the gate proceeds to iOS launch.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[cmux_attach_ensure_mac called] --> B{Socket exists?}
    B -- yes --> C[Quick probe: cmux_attach_mint_url\n2 attempts]
    C -- URL returned --> D[return 0 ✓]
    C -- empty --> E{CMUX_ATTACH_ALLOW_RELAUNCH=1?}
    E -- no --> F[warn + return 1 ✗]
    E -- yes --> G[pkill tagged app\nwait for socket to clear]
    G --> H[open tagged app]
    B -- no --> H
    H --> I{Socket appears\nwithin 60 × 0.2 s?}
    I -- no --> J[warn: socket never appeared\nreturn 1 ✗]
    I -- yes --> K{repo_root set?}
    K -- no --> D
    K -- yes --> L[cmux_attach_mint_url\nMINT_MAX_ATTEMPTS attempts\n0.5 s each]
    L -- URL returned --> D
    L -- empty after all attempts --> M[warn: Iroh ticket not ready\nreturn 1 ✗]
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[cmux_attach_ensure_mac called] --> B{Socket exists?}
    B -- yes --> C[Quick probe: cmux_attach_mint_url\n2 attempts]
    C -- URL returned --> D[return 0 ✓]
    C -- empty --> E{CMUX_ATTACH_ALLOW_RELAUNCH=1?}
    E -- no --> F[warn + return 1 ✗]
    E -- yes --> G[pkill tagged app\nwait for socket to clear]
    G --> H[open tagged app]
    B -- no --> H
    H --> I{Socket appears\nwithin 60 × 0.2 s?}
    I -- no --> J[warn: socket never appeared\nreturn 1 ✗]
    I -- yes --> K{repo_root set?}
    K -- no --> D
    K -- yes --> L[cmux_attach_mint_url\nMINT_MAX_ATTEMPTS attempts\n0.5 s each]
    L -- URL returned --> D
    L -- empty after all attempts --> M[warn: Iroh ticket not ready\nreturn 1 ✗]
Loading

Reviews (1): Last reviewed commit: "fix(iroh): await trusted Mac route after..." | Re-trigger Greptile

@azooz2003-bit
azooz2003-bit merged commit 23d7185 into main Jul 19, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant