Skip to content

Isolate app-host tests from runner user config - #9716

Merged
lawrencecchen merged 82 commits into
mainfrom
fix-app-host-user-config-isolation
Aug 7, 2026
Merged

lawrencecchen merged 82 commits into
mainfrom
fix-app-host-user-config-isolation

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • preserve the console user's real Xcode, SwiftPM, Cargo, and Rustup configuration while injecting isolated HOME, Core Foundation, XDG, Ghostty, and SSH state only into the launched app host
  • derive app-host paths and version-3 cleanup authority from repository ID, run ID, attempt, and shard
  • publish version-2 process receipts atomically, retain their write-only descriptor, and require the receipt path, PID, executable vnode, descriptor, and aw access mode to agree before signaling
  • serialize recovery through the machine lock, recover an authenticated prior owner immediately, protect the authenticated newest scope, and retain the six-hour grace only for process-free filesystem deletion
  • fail closed before signaling or deleting when identity, ownership, permissions, liveness, or scope topology changes during preflight

Regression proof

Validation

  • python3 tests/test_ci_app_host_home_isolation.py
  • bash tests/test_ci_app_host_identity.sh
  • bash tests/test_ci_app_host_processes.sh
  • bash tests/test_ci_app_host_home_cleanup.sh
  • bash tests/test_ci_app_host_xcodebuild_retry.sh
  • bash tests/test_ci_app_host_xcodebuild_attempts.sh
  • Bash 3.2 syntax, ShellCheck, git diff --check
  • real macOS lsof proof: machine output for a write-only descriptor is f9, then aw, then the canonical path
  • final tagged build, exact-head review, dispatched CI, and speculative merge gate run on 276101a2cb

Review triage

The policy checker names two existing XCTest files. CLIGenericHookPersistenceTests.swift extends its existing hook-persistence behavior suite, and CLINotifyProcessTestSupport.swift is that suite's shared process helper. Moving only the new assertions to Swift Testing would split one behavior suite, so this PR uses the repository's documented XCTest exception.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

CI now creates run-scoped app-host homes, records process receipts, forwards isolation variables through console and Xcode wrappers, validates configuration evidence, and performs authenticated cleanup with workflow and integration guards.

Changes

App-host CI isolation

Layer / File(s) Summary
Derive and prepare isolated app-host state
scripts/ci/app-host-isolation.sh, scripts/ci/prepare-app-host-home.sh, tests/test_ci_app_host_identity.sh
Run-scoped paths, identity values, receipt directories, and cleanup confirmations are derived and validated. Preparation creates protected directories and publishes the environment.
Apply isolation in console sessions
scripts/ci/run-in-console-session.sh, cmuxTests/CLINotifyProcessTestSupport.swift, cmuxTests/CLIGenericHookPersistenceTests.swift
Console sessions validate paths, apply ownership and permissions, clear SSH_AUTH_SOCK, and forward isolated configuration variables.
Record and authenticate app-host processes
Sources/AppHostProcessReceipt.swift, Sources/cmuxApp.swift, cmuxTests/CmuxTestWindowReleaseGuard.m, scripts/ci/app-host-processes.sh, cmux.xcodeproj/project.pbxproj, tests/test_ci_app_host_processes.sh
Application and test processes write restricted receipts. Shared helpers authenticate receipts against executable vnodes and terminate verified processes.
Enforce xcodebuild configuration isolation
scripts/ci/run-app-host-xcodebuild.sh, tests/test_ci_app_host_xcodebuild_retry.sh, cmuxTests/MacSentryStartupPolicyTests.swift
The Xcode wrapper forwards isolation settings, preserves the console home, validates Ghostty configuration evidence, and rejects leaked paths. Startup tests validate Foundation and environment path resolution.
Validate workflow wiring and clean isolated state
scripts/ci/cleanup-app-host-home.sh, .github/workflows/ci.yml, tests/test_ci_app_host_home_cleanup.sh, tests/test_ci_app_host_home_isolation.py
Cleanup validates identity, confirmation data, directory identity, and DerivedData containment before removing isolated artifacts. Workflow and end-to-end tests validate the full contract.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CI
  participant Preparation
  participant ConsoleSession
  participant Xcodebuild
  participant AppHost
  participant Cleanup
  CI->>Preparation: create run-scoped isolated home
  Preparation-->>CI: publish isolation paths and confirmation
  CI->>ConsoleSession: launch isolated command
  ConsoleSession->>Xcodebuild: forward TEST_RUNNER isolation settings
  Xcodebuild->>AppHost: start app-host process
  AppHost->>AppHost: write process receipt
  CI->>Cleanup: invoke cleanup after tests
  Cleanup->>AppHost: authenticate and terminate verified processes
  Cleanup-->>CI: remove isolated home and confirmation artifacts
Loading

Possibly related PRs

Suggested reviewers: azooz2003-bit


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (5 errors, 1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Cmux No Hacky Sleeps ❌ Error New production shell code polls lsof 50 times with fixed /bin/sleep 0.1 after TERM/KILL in app-host-processes.sh:428-451, for process teardown synchronization. Replace the fixed sleep loop with a process-owned exit event or a tested, cancellation-aware deadline abstraction that provides the termination signal.
Cmux Algorithmic Complexity ❌ Error scripts/ci/app-host-processes.sh:826-831 rescans receipt scopes via the glob at 740-741 for every runner target, yielding O(T×R) cleanup with no bound or measurement. Enumerate receipt files once and build a PID/executable index, then authenticate targets from that index; avoid the per-target receipt glob.
Cmux Swift Package Boundaries ❌ Error The new 57-line root-Sources AppHostProcessReceipt owns Foundation/Darwin receipt validation, serialization, filesystem writes, and chmod; it is not UI glue and has no SwiftPM boundary. Extract receipt validation and atomic writing into a small macOS package target such as CmuxAppHostSupport, exposing AppHostProcessReceipt; keep only the startup call in CmuxMain.
Cmux Swift Logging ❌ Error Sources/AppHostProcessReceipt.swift:53 adds unguarded production fputs to stderr for diagnostics; this violates the rule's prohibition on ad hoc stdout/stderr logging. Replace the stderr diagnostic with the app's unified Logger or existing cmux logging path, while preserving the failure exit status.
Cmux No Ambient Global State ❌ Error Sources/AppHostProcessReceipt.swift adds a top-level caseless enum used only as a static-function namespace; writeIfRequired is internal, so the production Swift diff violates the rule. Move receipt behavior to a constructable, injectable owning type, or keep file-scope helpers private/fileprivate and call them from the app seam.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Cmux Swift Actor Isolation ❓ Inconclusive Initial repository query shows no diff; production Swift changes cannot yet be compared against the pull request baseline. Provide the PR diff or a repository checkout with the changed commit and its parent.
✅ Passed checks (18 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Blocking Runtime ✅ Passed Production Swift adds receipt validation, atomic file output, and an early call only; the diff adds no semaphore, wait, sleep, delayed dispatch, polling, main sync, or lock primitive. Swift test ch...
Cmux Browser Automation Off-Main ✅ Passed The cumulative PR diff changes only CI/app-host isolation files; TerminalController.swift, the worker policy, and policy tests are unchanged, so no browser automation routing debt is introduced.
Cmux Expensive Synchronous Load ✅ Passed The PR adds only a bounded startup receipt check/write in production Swift; it adds no agent-history loader, transcript/JSON scan, directory walk, or synchronous syscall loop.
Cmux Cache Substitution Correctness ✅ Passed The production Swift diff only adds a current-process receipt and calls it at startup; it does not replace an authoritative read with a cache in persistence, history, undo, or snapshot code.
Cmux Swift Concurrency ✅ Passed The Swift diff adds synchronous receipt and environment-path logic; DispatchGroup/global queues are unchanged test synchronization, and no new Combine, completion-handler, or fire-and-forget Task p...
Cmux Swift @Concurrent ✅ Passed The Swift diff adds only synchronous receipt, environment, and validation helpers; it introduces no @concurrent, nonisolated async, or changed UI-bound async work.
Cmux Swiftpm Lockfiles ✅ Passed PR changes CI wiring and registers a Swift source only; no Package.swift, Package.resolved, or .gitignore changed, and cmux.xcodeproj has no SwiftPM package-reference change.
Cmux User-Facing Error Privacy ✅ Passed Production output is an opt-in CI receipt diagnostic with generic failure text; the diff exposes no vendor/provider names, credentials, tokens, IDs, environment names, or raw upstream payloads.
Cmux Full Internationalization ✅ Passed The diff adds CI isolation/receipt logic and tests only; no user-facing UI, web, metadata, or catalog/message changes. Swift literals are protocol tokens or CI stderr diagnostics.
Cmux Swiftui State Layout ✅ Passed The Swift diff adds only startup receipt wiring plus Foundation/test helpers; it adds no prohibited SwiftUI state, GeometryReader, lazy-row store, or render-time mutation patterns.
Cmux Architecture Rethink ✅ Passed Swift changes add no new timing, polling, locks, observers, or UI lifecycle owners; the receipt is a synchronous launch-boundary CI bridge with explicit identity checks, and test synchronization re...
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The Swift diff adds receipt and test environment logic only; the NSWindow code is test-only. The shared lint script passed and cmuxApp.swift registry/routing is unchanged.
Cmux Source Artifacts ✅ Passed The PR adds only workflow/config files, Swift/Objective-C source, CI scripts, and shell/Python tests; no prohibited artifact directories or generated artifact files appear in the diff.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The only production Swift additions are AppHostProcessReceipt and its CmuxMain call; the receipt writes CI cleanup metadata, adds no test/debug accessor or guard, and has a production entrypoint ca...
Title check ✅ Passed The title clearly identifies the main change: isolating app-host tests from reused runner user configuration.
Description check ✅ Passed The description explains the changes, rationale, validation steps, regression proof, and review context in sufficient detail.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-app-host-user-config-isolation

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_ci_app_host_home_isolation.py`:
- Around line 20-37: Update the test assertions around the requirements loop to
parse WORKFLOW as YAML and scope validation to the
jobs.app-host-unit-tests.steps and workflow-guard-tests.steps structures. Verify
the home-preparation command and related environment settings within
app-host-unit-tests, and verify the guard invocation within
workflow-guard-tests, rather than searching the complete workflow text.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 98e6889c-1b36-4a0f-976e-07cbf7c249ac

📥 Commits

Reviewing files that changed from the base of the PR and between 95ef75b and 56aa78d.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • scripts/ci/run-in-console-session.sh
  • tests/test_ci_app_host_home_isolation.py

Comment thread tests/test_ci_app_host_home_isolation.py Outdated
@cursor

cursor Bot commented Aug 6, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_ci_app_host_home_isolation.py`:
- Around line 22-41: Update require_step to validate that WORKFLOW is a mapping
before calling .get(), and validate each step is a mapping before accessing its
name. Raise contextual SystemExit messages beginning with “FAIL:” for malformed
top-level workflows or steps, while preserving the existing job, steps-list, and
exactly-one-match checks.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: da0de0dd-42aa-45ba-b845-296e507530e8

📥 Commits

Reviewing files that changed from the base of the PR and between 56aa78d and 5beeaa3.

📒 Files selected for processing (1)
  • tests/test_ci_app_host_home_isolation.py

Comment thread tests/test_ci_app_host_home_isolation.py Outdated
@cursor

cursor Bot commented Aug 6, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
tests/test_ci_app_host_home_isolation.py (1)

81-81: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Do not make app-host home writable by all local users.

chmod -R a+rwX "$APP_HOST_HOME" grants every local account write access to isolated CI app-host state. Keep access limited to the runner account by adjusting ownership/group permissions or another narrow access control. Update both the guard and the workflow setup together.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test_ci_app_host_home_isolation.py` at line 81, Replace the broad
permissions in the app-host home setup and its corresponding guard in the test
with runner-only ownership or group access. Update both the workflow setup and
the expected command in tests/test_ci_app_host_home_isolation.py together,
ensuring other local users cannot write to APP_HOST_HOME.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/ci/run-app-host-xcodebuild.sh`:
- Line 40: Sanitize app-host isolation failures: in
scripts/ci/run-app-host-xcodebuild.sh lines 40-40, replace the
environment-variable-specific output with a generic product-level failure and
safe recovery guidance; at lines 83-84, remove the vendor name and raw echo
"$line", retaining raw details only in sanitized internal diagnostics. Update
tests/test_ci_app_host_xcodebuild_retry.sh lines 113-118 to assert the new
sanitized message.
- Around line 88-91: The log-scanning loop in the script must fail closed when
the attempt log cannot be read. Validate that log_path is readable before
scanning, and handle grep’s status explicitly: allow status 1 for no matches,
but propagate statuses greater than 1 as scan failures instead of masking them
with || true.
- Line 81: Update the path-prefix case pattern in the configuration-root
validation to require a trailing slash after expected_root, matching only
path=$expected_root/ as a literal prefix and rejecting sibling roots such as
app-host-home-other.

In `@tests/test_ci_app_host_xcodebuild_retry.sh`:
- Line 23: Replace the fixed sleep 10 delay in the mock with a completion-event
wait that remains blocked until the wrapper terminates it. Update the mock in
the retry test to use the existing termination/completion signaling mechanism,
preserving the timeout scenario without relying on wall-clock duration.

---

Outside diff comments:
In `@tests/test_ci_app_host_home_isolation.py`:
- Line 81: Replace the broad permissions in the app-host home setup and its
corresponding guard in the test with runner-only ownership or group access.
Update both the workflow setup and the expected command in
tests/test_ci_app_host_home_isolation.py together, ensuring other local users
cannot write to APP_HOST_HOME.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d1e973cc-b368-4563-9700-fa192a9c8461

📥 Commits

Reviewing files that changed from the base of the PR and between 2ef782f and 468bf90.

📒 Files selected for processing (5)
  • cmux.xcodeproj/project.pbxproj
  • cmux.xcodeproj/xcshareddata/xcschemes/cmux-unit.xcscheme
  • scripts/ci/run-app-host-xcodebuild.sh
  • tests/test_ci_app_host_home_isolation.py
  • tests/test_ci_app_host_xcodebuild_retry.sh

Comment thread scripts/ci/run-app-host-xcodebuild.sh Outdated
Comment thread scripts/ci/run-app-host-xcodebuild.sh Outdated
Comment thread scripts/ci/run-app-host-xcodebuild.sh Outdated
Comment thread tests/test_ci_app_host_xcodebuild_retry.sh
@lawrencecchen

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Head commit changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

♻️ Duplicate comments (2)
tests/test_ci_app_host_xcodebuild_retry.sh (1)

31-54: 🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift

Remove the real wall-clock dependency from this test.

The mock uses sleep 10, and the assertion depends on a real 0.1 second idle timeout. Inject a controllable timeout source into the noninteractive wrapper, then advance it from the test.

As per coding guidelines, “Test code must avoid real wall-clock dependencies.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test_ci_app_host_xcodebuild_retry.sh` around lines 31 - 54, Remove the
real-time dependency from the retry test’s mock and invocation: update the
noninteractive wrapper’s timeout source to be injectable, then control or
advance that source within the test to trigger the idle-timeout behavior
deterministically. Replace the mock’s sleep-based delay and
CMUX_XCODEBUILD_NONINTERACTIVE_IDLE_TIMEOUT_SECONDS=0.1 usage while preserving
the existing retry assertions.

Source: Coding guidelines

scripts/ci/run-app-host-xcodebuild.sh (1)

40-41: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Remove implementation details from app-host failure output.

The output exposes internal environment-variable names, the Ghostty provider name, and a raw configuration log line. Emit a generic isolation failure with safe recovery guidance. Update the expected test text.

  • scripts/ci/run-app-host-xcodebuild.sh#L40-L41: replace the variable-specific failure text.
  • scripts/ci/run-app-host-xcodebuild.sh#L102-L107: remove the provider name and echo "$line".
  • tests/test_ci_app_host_xcodebuild_retry.sh#L129-L131: assert the sanitized outside-root failure.
  • tests/test_ci_app_host_xcodebuild_retry.sh#L137-L170: assert the sanitized missing-log failure.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/ci/run-app-host-xcodebuild.sh` around lines 40 - 41, Sanitize
app-host isolation failure output: in scripts/ci/run-app-host-xcodebuild.sh
lines 40-41, replace the environment-variable-specific message with generic
isolation failure and safe recovery guidance; in lines 102-107, remove the
provider name and raw echo "$line" output. Update
tests/test_ci_app_host_xcodebuild_retry.sh lines 129-131 and 137-170 to assert
the sanitized outside-root and missing-log messages.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/ci/run-in-console-session.sh`:
- Around line 37-66: Bind XDG_CONFIG_HOME to the isolated app-host configuration
directory: in scripts/ci/run-in-console-session.sh lines 37-66, resolve and
require it to equal $CFFIXED_USER_HOME/.config; in
scripts/ci/run-app-host-xcodebuild.sh lines 39-52, reject any different XDG root
before forwarding TEST_RUNNER_*; in tests/test_ci_app_host_xcodebuild_retry.sh
lines 112-171, add an external-XDG case asserting the wrapper fails before
launching xcodebuild.

In `@tests/test_ci_app_host_home_isolation.py`:
- Around line 124-134: Update the key lookup in the validation loop to search
for EnvironmentVariable entries using the TEST_RUNNER_ prefix, matching the
variables reported by the failure message and preventing scheme overrides of the
wrapper values.

In `@tests/test_ci_app_host_xcodebuild_retry.sh`:
- Around line 88-96: Update the test around the xcodebuild invocation to capture
the inherited HOME value before running the wrapper, then pass it into the awk
validation and require the logged original HOME field ($1) to equal that value.
Retain the existing checks rejecting app-host-specific redirects in $2 and $3.

---

Duplicate comments:
In `@scripts/ci/run-app-host-xcodebuild.sh`:
- Around line 40-41: Sanitize app-host isolation failure output: in
scripts/ci/run-app-host-xcodebuild.sh lines 40-41, replace the
environment-variable-specific message with generic isolation failure and safe
recovery guidance; in lines 102-107, remove the provider name and raw echo
"$line" output. Update tests/test_ci_app_host_xcodebuild_retry.sh lines 129-131
and 137-170 to assert the sanitized outside-root and missing-log messages.

In `@tests/test_ci_app_host_xcodebuild_retry.sh`:
- Around line 31-54: Remove the real-time dependency from the retry test’s mock
and invocation: update the noninteractive wrapper’s timeout source to be
injectable, then control or advance that source within the test to trigger the
idle-timeout behavior deterministically. Replace the mock’s sleep-based delay
and CMUX_XCODEBUILD_NONINTERACTIVE_IDLE_TIMEOUT_SECONDS=0.1 usage while
preserving the existing retry assertions.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 64ba7573-6797-443b-9824-02dfff2ab750

📥 Commits

Reviewing files that changed from the base of the PR and between 2ef782f and ba91848.

📒 Files selected for processing (5)
  • .github/workflows/ci.yml
  • scripts/ci/run-app-host-xcodebuild.sh
  • scripts/ci/run-in-console-session.sh
  • tests/test_ci_app_host_home_isolation.py
  • tests/test_ci_app_host_xcodebuild_retry.sh

Comment thread scripts/ci/run-in-console-session.sh
Comment thread tests/test_ci_app_host_home_isolation.py Outdated
Comment thread tests/test_ci_app_host_xcodebuild_retry.sh
Comment thread tests/test_ci_app_host_processes.sh
Comment thread tests/test_ci_app_host_processes.sh
Comment thread tests/test_ci_app_host_processes.sh
Comment thread scripts/ci/app-host-processes.sh

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4a290ce. Configure here.

Comment thread tests/test_ci_app_host_identity.sh
Comment thread tests/test_ci_app_host_home_isolation.py Outdated
Comment thread tests/test_ci_app_host_processes.sh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant