Repository navigation
Batch approval and prefix generalization for surface resume command alerts - #9028
Conversation
📝 WalkthroughWalkthroughResume approval now supports generalized command-prefix scopes, localized batch prompt actions, and sticky run-all or skip-all decisions. Approval persistence, workspace prompting, project wiring, and session persistence tests were updated. ChangesSurface resume approval flow
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (5 errors, 1 warning)
✅ Passed checks (19 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@cmuxTests/SessionPersistenceTests.swift`:
- Around line 4883-4895: Update
SurfaceResumeCommandCanonicalizer.generalizedApprovalPrefix and its test
expectations so removing the session ID preserves trailing non-session arguments
such as --yolo in the normalized approval scope. Ensure matching does not widen
to every command sharing only codex resume; if the session ID cannot be removed
safely, fail closed instead.
In `@Sources/SessionPersistence.swift`:
- Around line 655-700: Update generalizedApprovalPrefix(forCommand:) to fail
closed unless the entire command matches the supported resume grammar. Reject
shell-composition syntax such as separators, redirections, substitutions, or
opaque trailing tokens, and reject unsupported env flags so commands like env -i
do not produce a prefix. Return nil whenever parsing cannot reliably identify
only the approved executable, supported options, and environment assignments.
In `@Sources/SurfaceResumeRunPromptBatch.swift`:
- Around line 3-17: Make SurfaceResumeRunPromptBatch constructable by removing
its global shared singleton and private-only initialization, while preserving
its app-lifetime sticky-decision behavior. Create and retain one
coordinator-owned instance at app lifecycle scope, then update Workspace prompt
handling to consume that instance’s decision and reset/action methods instead of
SurfaceResumeRunPromptBatch.shared; use the injected owner in tests as well.
Apply the corresponding change at Sources/Workspace.swift lines 2657-2665, with
no direct change needed elsewhere.
In `@Sources/Workspace.swift`:
- Around line 2710-2714: Update the suppression handling around the approval
prompt so it uses the active approval-store context rather than
`SurfaceResumeApprovalStore` defaults. When `alert.suppressionButton?.state ==
.on`, create and validate an auto-approval record if `binding.approvalRecordId`
is absent; otherwise update the existing record in that same store and handle
the update result.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: a6408b5a-1f83-4ad2-bdde-bca8577b0573
📒 Files selected for processing (7)
Resources/Localizable.xcstringsSources/ControlSurfaceResumeTarget.swiftSources/SessionPersistence.swiftSources/SurfaceResumeRunPromptBatch.swiftSources/Workspace.swiftcmux.xcodeproj/project.pbxprojcmuxTests/SessionPersistenceTests.swift
…batch # Conflicts: # Sources/ControlSurfaceResumeTarget.swift
Regressions for the round-four review findings: env -i / env -u / nested env wrappers must not become the scoped command, and commands with arguments after the session id (codex resume <id> --yolo) must not generalize to a wider prefix scope. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
generalizedApprovalPrefix now rejects a command whose executable slot is an option token or another env wrapper (env -i FOO=1 claude ... scoped approval to bare 'env -i'), and only generalizes when the session id is the sole unmatched token, so prefix matching can never re-authorize a session launched with different trailing options. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Absorb HQ broadcast baseline: iPhone install queue, phone-plus-simulator mandate, Xcode 26.3 warning gate fix, resume alert batching (#9028).
Restoring many closed agent sessions fired one modal alert per session. Prompt-created approval records covered the full command tokens, including the per-session id (
claude --resume <id>), plus exact cwd and environment, so no stored approval ever matched the next session and every session prompted again.Three changes, all on the existing signed approval-record store (matching and signing semantics untouched):
"Apply to all" checkbox on the "Allow Resume Command?" proposal alert.
SurfaceResumeCommandCanonicalizer.generalizedApprovalPrefix(forCommand:)trims the session-specific tail (claude --resume 5f0c…→claude --resume,codex resume 0197…→codex resume, handling cd-guards and env assignments). Checking the box writes the approval record with that generalized prefix, so the first answered alert silences the remaining queued proposals for the same agent in the same cwd/environment.Run All / Skip All on the "Run Resume Command?" restore alert. A sticky decision (
SurfaceResumeRunPromptBatch, MainActor, app-lifetime) answers the remaining restore prompts without showing them. Scope is deliberately until app quit, no timers."Don't ask again for this command" checkbox on the restore alert. On Run/Run All it promotes the binding's existing approval record to Auto-Restore, so later relaunches skip the prompt for that record entirely.
All four new strings are localized (en + ja). Tests extended in
cmuxTests/SessionPersistenceTests.swift: prefix generalization cases, cross-session record matching with generalized prefixes, cwd rejection, proposal-prompt suppression via generalized.autorecords, and sticky batch semantics.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Batch-approve and batch-run resume commands to stop repeated alerts when restoring many sessions. Approvals are folder-scoped, local-only, and shell-safe; prefixes generalize only when the session id is the sole unmatched token. Run prompts support Run All/Skip All and “Don’t ask again,” with decisions scoped to nested restore passes.
New Features
Bug Fixes
envflags/nestedenv, subshells/backticks/history controls, control operators, unquoted glob/brace/tilde/leading “=”; never generalize if trailing args follow the session id.Written for commit 8d84339. Summary will update on new commits.
Summary by CodeRabbit
New Features
Bug Fixes