Skip to content

Fix end-to-end push notification reliability - #9319

Merged
azooz2003-bit merged 107 commits into
mainfrom
issue-6270-ios-push-reliability
Aug 5, 2026
Merged

azooz2003-bit merged 107 commits into
mainfrom
issue-6270-ios-push-reliability

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 31, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #6270

Fixes the production signing gap that stripped push entitlements, makes device registration account-safe and recoverable, and preserves notification identity across retries.

Adds durable Mac delivery with bounded retries, idempotent partial APNs recovery, pooled provider connections, database-backed rate enforcement, and same-account phone controls. The iPhone reports the exact blocked or limited stage and can enqueue a truthful test alert through the production path.

Verification:


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Improves end-to-end push alert reliability across Mac, iOS, and backend with durable latest-per-id delivery, device‑delivery leases, TTL‑clamped retries, authenticated controls, and truthful readiness so users get one accurate alert even across retries, disconnects, and redirects.

  • New Features

    • Mac
      • Durable latest‑per‑id queue with disk persistence, Darwin file locks, abandoned‑snapshot cleanup, and session‑identity adoption so first identity publish doesn’t drop the queue; TTL‑aware retries; truthful test stages; notifications popover opens iPhone forwarding; Settings adds forwarding, mode, and hide‑content controls.
      • Authenticated phone_push.settings.update, phone_push.status.get (definitive auth errors now trigger reauth disconnect), and idempotent phone_push.test.
    • Backend
      • Correlation‑id idempotency with merged outcomes; APNs session reuse; device‑delivery leases freeze recipients during I/O with partial‑index release; delivery survives client disconnects; provider Retry‑After honored and clamped to event TTL; unconfigured APNs provider fails closed.
      • Limits: 200 events/user/10 min; 200 devices/user; account deletion waits for active delivery leases; aggregate delivery summaries include transient/permanent failures and Retry‑After by correlation id; requires CMUX_APNS_KEY_P8, CMUX_APNS_KEY_ID, CMUX_APNS_TEAM_ID.
    • iOS
      • CmuxAuthRuntime: session‑identity stream; push registration snapshots with streaming updates, retry/backoff, failure recording, and a redirect‑preserving delegate that rejects unsafe redirects.
      • CmuxMobileShellUI: Push Readiness UI merges OS auth, registration, authenticated Mac status, and API origin with optimistic Mac settings that roll back on failure; truthful production‑path test alert; UITest preview via CMUX_UITEST_PUSH_READINESS_PREVIEW.
      • CmuxMobileRPC: authenticated Mac phone‑push status DTOs (mode, admission, queue‑persistence health, hide‑content, API origin).
    • CI/TestFlight
      • Use the “cmux Demo Distribution Push” profile; verify production APNs and Time Sensitive entitlements on export; add SwiftPM lockfile remote‑input guard (with tests) and an iOS package‑conventions lint baseline.
  • Migration

    • Run DB migrations: 20260731120000_push_event_idempotency and 20260731130000_push_event_lease_fencing.
    • Set CMUX_APNS_KEY_P8, CMUX_APNS_KEY_ID, CMUX_APNS_TEAM_ID (audited at runtime).

Written for commit 2accaf3. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added phone push forwarding controls, privacy options, delivery modes, readiness guidance, repair actions, and test alerts.
    • Added persistent, authenticated delivery with retries, expiration handling, deduplication, queue recovery, and status reporting.
    • Added notification popover access to iPhone forwarding settings.
  • Bug Fixes
    • Improved permissions, device limits, account changes, failed registrations, stale sessions, redirects, and partial deliveries.
    • Improved duplicate prevention and recovery of interrupted sends.
  • Localization
    • Added English and Japanese translations for push settings, alerts, statuses, and accessibility labels.
  • Platform Support
    • Strengthened iOS notification entitlement validation for TestFlight builds.

@cursor

cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@greptile-apps

greptile-apps Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Too many files changed for review. (113 files found, 100 file limit)

Bypass the limit by tagging @greptile-apps to review.

@cursor

cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@azooz2003-bit

Copy link
Copy Markdown
Collaborator Author

Final verification follow-up for 2accaf35f0e5c3f1fefe1210b8708e35b7780d33:

End-to-end iPhone proof remains blocked. Aziz is paired but unavailable, so pushon remains queued for installation. The actual Allow action, actual deny to iOS Settings round trip, same-process return, and exactly one final-tag physical push are not claimed as verified. No merge was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

iOS: push notifications don't deliver to iPhone

1 participant