Put the mobile diff viewer behind a remote feature flag, off by default - #8937
Conversation
mobile-workspace-changes-enabled-release (PostHog, registry in CmuxFeatureFlags) now gates the feature at its single host-side choke point: when off, mobile.host.status omits workspace.changes.v1 and the five mobile.workspace.changes.* RPCs answer capability_disabled through one shared router guard. Every iOS entry point (workspace-row chip, toolbar button, one-time hint, Changes sheet, summary polling) already feature-detects on that capability, so the phone UI turns off with no iOS change and a stale cached capability list cannot call through. Status payloads are served off the main actor, so the flag publishes a lock-protected off-main snapshot from the shared instance; readers fall back to the per-flag compile-time default before it exists. Release defaults off until the PostHog flag enables it; DEBUG defaults on for dogfood, matching the cloud-vm-ui and pro-upgrade-ui convention. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
📝 WalkthroughWalkthroughAdds a mobile workspace changes feature flag with off-main snapshots, gates capability advertisement, centralizes workspace changes RPC dispatch, adds localized messages, and tests default, remote, and capability behavior. ChangesMobile workspace changes
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant MobileClient
participant TerminalController
participant CmuxFeatureFlags
participant WorkspaceChangeHandlers
MobileClient->>TerminalController: mobile.workspace.changes.* RPC
TerminalController->>CmuxFeatureFlags: read feature flag
alt enabled
TerminalController->>WorkspaceChangeHandlers: dispatch supported method
WorkspaceChangeHandlers-->>MobileClient: workspace changes result
else disabled
TerminalController-->>MobileClient: capability_disabled error
end
Possibly related PRs
Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (3 errors)
✅ Passed checks (22 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryAdds a remotely controlled, release-default-off gate for the mobile workspace diff viewer.
Confidence Score: 5/5The PR appears safe to merge, with capability advertisement and RPC execution consistently gated by the same effective feature-flag state. The shared feature-flag instance synchronously mirrors each resolution update into the off-main snapshot, status responses read that snapshot live, and the only production dispatcher for all five workspace-changes methods now passes through the guarded router. Important Files Changed
Sequence DiagramsequenceDiagram
participant PostHog
participant Flags as CmuxFeatureFlags
participant Host as MobileHostService
participant Phone as iOS Client
participant Router as Workspace Changes Router
PostHog-->>Flags: Remote flag value
Flags->>Flags: Update MainActor state and off-main snapshot
Phone->>Host: mobile.host.status
Host-->>Phone: Capabilities filtered by snapshot
Phone->>Router: "mobile.workspace.changes.*"
alt Flag enabled
Router-->>Phone: Workspace diff response
else Flag disabled
Router-->>Phone: capability_disabled
end
Reviews (1): Last reviewed commit: "Put the mobile diff viewer behind a remo..." | Re-trigger Greptile |
Union of the CmuxFeatureFlags init: main's telemetry-gated control-plane remote loader parameters plus this branch's off-main snapshot publisher. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The iOS Changes viewer (#8221) now ships dark behind
mobile-workspace-changes-enabled-release, a PostHog-backed flag in theCmuxFeatureFlagsregistry, defaulting to off on Release builds.The gate lives at the feature's single host-side choke point. When the flag is off,
mobile.host.statusstops advertisingworkspace.changes.v1, and the fivemobile.workspace.changes.*RPCs answercapability_disabledthrough one shared router guard inTerminalController+MobileWorkspaceChanges.swift. Every iOS entry point (workspace-row chip, toolbar button, one-time hint, Changes sheet, and summary polling) already feature-detects on that capability, so the phone UI turns itself off with zero iOS changes, and a phone holding a stale cached capability list cannot call through.Status payloads are served off the main actor, so
CmuxFeatureFlagsgains a lock-protected off-main snapshot published by the shared instance (OSAllocatedUnfairLock, the existing idiom); before the snapshot exists readers get the per-flag compile-time default, which fails closed on Release. DEBUG builds default the flag on for dogfood, matching thecloud-vm-ui-enabled-releaseandpro-upgrade-ui-enabled-releaseconvention; the local override in the Feature Flags window works as usual and remote values remain authoritative.Verified live against a paired simulator with the tagged
difvbuild, same two dirty demo workspaces in both states. Flag on: chips render (+48 −10 and +6,215 −6,160) and the device log showschanges.summary ok requested=3 summaries=3 chips=2. Flag off (local override): the same rows render with no chips, the log shows no changes traffic at all (the phone never polls), and the advertised capability count drops by exactly one.scripts/lint-feature-flags.pypasses; capability inclusion/exclusion and flag-resolution tests added to the already-wiredMobileHostConnectionLifecycleTests.One ops note: the flag does not exist in the PostHog dashboard yet (no personal API key on this machine). An absent remote flag resolves to the Release default (off), so nothing ships enabled; create
mobile-workspace-changes-enabled-releasein PostHog project 244066 when ready to roll out or to use it as a kill switch.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Gates the iOS mobile diff viewer behind a remote feature flag so we can roll out safely. Also merges
mainand keeps theCmuxFeatureFlagstelemetry-gated remote loader alongside the off-main snapshot publisher.New Features
mobile-workspace-changes-enabled-releasetoCmuxFeatureFlags(Release off, DEBUG on; remote viaPostHog, local overrides respected).mobile.host.statusadvertisesworkspace.changes.v1only when enabled; allmobile.workspace.changes.*RPCs route through one guard and returncapability_disabledwhen off.CmuxFeatureFlags.sharedso status payloads can read flags off the main actor.Migration
mobile-workspace-changes-enabled-releaseinPostHogproject 244066 when ready to roll out or to use as a kill switch.Written for commit 2aea225. Summary will update on new commits.
Summary by CodeRabbit
New Features
Tests