Skip to content

Forward CMUX_SOCKET_CAPABILITY to Pi hook children - #9460

Open
mrohan-sq wants to merge 1 commit into
manaflow-ai:mainfrom
mrohan-sq:fix-pi-autoname-socket-capability
Open

mrohan-sq wants to merge 1 commit into
manaflow-ai:mainfrom
mrohan-sq:fix-pi-autoname-socket-capability

Conversation

@mrohan-sq

@mrohan-sq mrohan-sq commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Context

Workspace auto-naming never fires for Pi sessions, even with automation.workspaceAutoNaming enabled and healthy Stop hooks. The detached naming pass exits silently before its first socket call.

Summary

  • Forward CMUX_SOCKET_CAPABILITY to cmux CLI hook children in the Pi extension.
  • The orphaned auto-name pass (sh -c '... &') fails ancestry-based socket auth without it.
  • Verified end-to-end: probe rejected without the capability, rename succeeds with it forwarded.

Dependencies

None.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Forward CMUX_SOCKET_CAPABILITY to Pi hook children of the cmux CLI so the detached auto-name pass can authenticate. Restores workspace auto-naming for Pi sessions that previously exited before the first probe due to missing credentials.

Written for commit 0955941. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved socket authentication for detached and automatically named command-line processes by forwarding the required socket capability information alongside existing credentials.

The Pi extension's hook environment scrubber dropped CMUX_SOCKET_CAPABILITY.
The detached auto-name pass spawned from the stop hook is orphaned
(sh -c '... &'), so ancestry-based socket auth fails and the inherited
capability is its only credential. Without it, the naming pass exits
silently at its first workspace.set_auto_title probe and Pi workspaces
are never auto-named.
@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: a807caa5-213a-4a18-8f4c-ef2dbb885c80

📥 Commits

Reviewing files that changed from the base of the PR and between 249d0ff and 0955941.

📒 Files selected for processing (1)
  • CLI/CMUXCLI+PiExtensionSourcePart1.swift

📝 Walkthrough

Walkthrough

Changes

Socket authentication

Layer / File(s) Summary
Forward socket credentials
CLI/CMUXCLI+PiExtensionSourcePart1.swift
hookEnvironment now forwards CMUX_SOCKET_CAPABILITY with CMUX_SOCKET_PASSWORD to authenticated cmux CLI child processes.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: austinywang, lawrencecchen

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: forwarding CMUX_SOCKET_CAPABILITY to Pi hook children.
Description check ✅ Passed The description clearly explains the problem, fix, rationale, dependencies, and end-to-end verification, but it omits several template sections.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed The diff only changes JavaScript text inside the existing Swift raw-string property; it adds no Swift models, protocols, Sendable references, UI access, or actor-isolation boundary.
Cmux Swift Blocking Runtime ✅ Passed The patch only forwards CMUX_SOCKET_CAPABILITY and updates comments in an embedded TypeScript source string; it adds no semaphore, wait, sleep, polling, sync, timer, or lock.
Cmux Browser Automation Off-Main ✅ Passed The PR only changes Pi hook environment forwarding in CLI/CMUXCLI+PiExtensionSourcePart1.swift; it adds no browser.* command or WebKit/AppKit routing change.
Cmux Expensive Synchronous Load ✅ Passed The commit only forwards CMUX_SOCKET_CAPABILITY in embedded Pi TypeScript; it adds no agent-history load, large-file parse, directory scan, or main-actor synchronous work.
Cmux Cache Substitution Correctness ✅ Passed The diff only forwards CMUX_SOCKET_CAPABILITY in hookEnvironment; it does not replace an authoritative read with a cache or alter persistence, history, undo, or snapshot logic.
Cmux No Hacky Sleeps ✅ Passed The diff only forwards CMUX_SOCKET_CAPABILITY and updates comments. It adds no sleep, timer, polling, fixed delay, or wall-clock synchronization.
Cmux Algorithmic Complexity ✅ Passed The diff adds only two constant-time environment lookups and assignments inside existing hook setup; it adds no collection scan, sort, filter, join, or batch algorithm.
Cmux Swift Concurrency ✅ Passed The diff only forwards CMUX_SOCKET_CAPABILITY beside CMUX_SOCKET_PASSWORD and updates comments; it adds no Dispatch, Combine, completion-handler, or fire-and-forget Task pattern.
Cmux Swift @Concurrent ✅ Passed The only Swift file change is embedded TypeScript in synchronous hookEnvironment; it adds environment forwarding and changes no async isolation, @concurrent, actor, or UI call site.
Cmux Swift Package Boundaries ✅ Passed The diff only updates embedded Pi hook child-process environment forwarding in CLI/CMUXCLI+PiExtensionSourcePart1.swift; it adds no reusable or independently testable Swift domain logic.
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only CLI/CMUXCLI+PiExtensionSourcePart1.swift; it does not modify Package.swift, package references, .gitignore, workflows, dependencies, or any Package.resolved lockfile.
Cmux Swift Logging ✅ Passed The diff adds only comments and CMUX_SOCKET_CAPABILITY environment forwarding; it adds no logging, diagnostics, or secret output.
Cmux User-Facing Error Privacy ✅ Passed The diff only forwards CMUX_SOCKET_CAPABILITY and updates developer comments; it adds no user-facing error, alert, command output, API body, or recovery copy.
Cmux Full Internationalization ✅ Passed The diff adds only CMUX_SOCKET_CAPABILITY environment handling and developer comments; no user-facing text, localization keys, catalogs, or locale-specific web content changed.
Cmux Swiftui State Layout ✅ Passed The only diff adds CMUX_SOCKET_CAPABILITY forwarding and comments inside embedded TypeScript; it introduces no SwiftUI state, layout, row-store, or render-time mutation pattern.
Cmux Architecture Rethink ✅ Passed The diff makes a small local credential-forwarding fix in the existing hookEnvironment path. It adds no timing, polling, locks, observers, duplicate wiring, or new state owner.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The diff only forwards CMUX_SOCKET_CAPABILITY in embedded Pi hook code; it adds no NSWindow, NSPanel, controller, SwiftUI Window, identifier, or close-shortcut logic. The lint also passes.
Cmux Source Artifacts ✅ Passed The only changed path is the tracked hand-written Swift source file CLI/CMUXCLI+PiExtensionSourcePart1.swift; no prohibited artifact directory or generated output appears in the diff.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The only changed file is CLI/CMUXCLI+PiExtensionSourcePart1.swift, outside /Sources/; its additions only forward CMUX_SOCKET_CAPABILITY and add comments, with no test/debug seam.
Cmux No Ambient Global State ✅ Passed The diff only edits the existing embedded TypeScript in CMUXCLI.piExtensionSourcePart1; it adds no Swift free function, mutable global, static-helper namespace, or singleton.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mrohan-sq

Copy link
Copy Markdown
Contributor Author

🤖 Evidence chain from the diagnosis (cmux 0.64.22, macOS):

Symptom. automation.workspaceAutoNaming on, Pi Stop hooks acknowledged in ~/.cmuxterm/events.jsonl, autoNameRecentMessages cached in ~/.cmuxterm/pi-hook-sessions.json, workspace not user-owned — yet no rename, and no autoNameLastAttemptAt/autoNameInFlightAt markers were ever written. So the detached pass exited before beginAutoNaming.

Socket auth isolation. The pre-beginAutoNaming gate is the workspace.set_auto_title probe:

1. child process, capability kept:      {"enabled":true,...}
2. child process, capability removed:   {"enabled":true,...}      # ancestry auth still works
3. orphaned process, capability removed: ERROR: Access denied - only processes started inside cmux can connect
4. orphaned process, capability kept:    {"enabled":true,...}

spawnDetachedAgentAutoName orphans the pass via /bin/sh -c '... &' (case 3/4). The Pi extension's shouldPreserveEnvKey scrubber drops CMUX_SOCKET_CAPABILITY, so the real flow is case 3: the probe fails and the pass returns silently.

Fix verification. Replaying a Pi stop hook with the extension's exact scrubbed env plus the forwarded capability renamed the previously-unnamed workspace within ~5s and wrote the throttle markers. The same replay without the capability never renamed.

Scope. Only Pi is affected: the OMP and Campfire extensions pass { ...process.env } through unscrubbed, and Claude/Codex hooks inherit the terminal env directly. The fix forwards the capability only to cmux CLI children, mirroring the existing CMUX_SOCKET_PASSWORD handling, so it stays out of the generic allowlist.

@mrohan-sq
mrohan-sq marked this pull request as ready for review August 3, 2026 16:27
@cursor

cursor Bot commented Aug 3, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo teamleaderleo added area: agents Agent integrations (Claude Code, Codex, ACP), agent chat, hooks, status S3: minor Wrong behavior with a workaround ready-to-land Reviewed and ready to land when CI is green labels Sep 30, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator

This is ready for a maintainer land once the CLA is recorded. Please comment: I have read the CLA Document v2.2 and I hereby sign the CLA :)

@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document v2.2 and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: agents Agent integrations (Claude Code, Codex, ACP), agent chat, hooks, status ready-to-land Reviewed and ready to land when CI is green S3: minor Wrong behavior with a workaround

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants