fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(ssh): give each managed launch a fresh remote server log - #8930

Open
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate
Open

fix(ssh): give each managed launch a fresh remote server log#8930
marmar9615-cloud wants to merge 2 commits into
pingdotgg:mainfrom
marmar9615-cloud:fix/ssh-launch-log-truncate

Conversation

@marmar9615-cloud

@marmar9615-cloudmarmar9615-cloud commented Aug 31, 2026

Copy link
Copy Markdown

What changed

One line in the generated remote launch script, packages/ssh/src/tunnel.ts:

rm -f "$LOG_FILE"
nohup env T3CODE_NO_BROWSER=1 "$RUNNER_FILE" serve ... >>"$LOG_FILE"2>&1< /dev/null &

Why it should exist

The readiness failure branch tells two cases apart by file size:

if [ -s"$LOG_FILE" ];then
tail -n 80 "$LOG_FILE">&2elseprintf'It wrote nothing to %s, so it exited before producing any output.\n'"$LOG_FILE">&2fi

That empty-log arm came from #5132, to name the case where the remote server exits without
logging anything. The launch opens the log with >> and nothing clears it, so [ -s ] is true
from the first run that logs onward and the arm is unreachable after that. A server that dies
silently is reported with the previous run's error, which sends you after the wrong problem. The
file also grows without bound across managed restarts.

Why unlink and not truncate

wait_for_pid_exit gives up after 20 x 0.1s (tunnel.ts:495-502), so a server that ignores the
kill is still holding its descriptor when the next launch runs. Measured separately from the test,
with a survivor holding the append-mode descriptor the launch gave it:

launch doesresulting log[ -s ] takes
> truncate5 bytesthe tail branch
rm -f then >>0 bytesthe wrote-nothing branch

Truncating hands the new file to the old writer. Unlinking leaves it with the old one. The test
below passes under either form, so treat the table as the reason for the choice, not as something
the test proves.

Test

One executed case in packages/ssh/src/tunnel.test.ts. It seeds server.log with a marker,
installs a fake node that picks a port, fails readiness at once, and lets the runner exit
without writing a byte, then runs the real buildRemoteLaunchScript() output through a shell. It
asserts exit 1, stderr containing "It wrote nothing to", no marker in stderr, and a 0-byte log.

Against the append-only script it fails at the "It wrote nothing to" assertion. It follows the
executed-shell pattern already in apps/desktop/src/wsl/DesktopWslEnvironment.test.ts, including
the shell probe that skips where the tools are missing.

vp test run src/tunnel.test.ts: 1 file, 14 tests, all pass. tsgo --noEmit clean.

Nothing else reads this path. The only other reference is the on-demand tail script at
tunnel.ts:649, which opens by path per SSH invocation, so unlinking strands no descriptor.


Note

Low Risk
Small change to generated remote launch shell behavior and failure diagnostics only; no auth or data-path changes.

Overview
Each managed remote SSH launch now deletes the existing server.log before starting the server, so readiness failures can tell a silent new run from one that actually logged output.

Previously the log was only opened in append mode, so [ -s "$LOG_FILE" ] stayed true after the first run and a server that exited without writing anything could surface stale tail output instead of the "It wrote nothing to …" message.

Adds an executed test in tunnel.test.ts that runs the real buildRemoteLaunchScript() output under bash/WSL with a seeded stale log and a fake node; the suite skips when required POSIX tools are missing.

Reviewed by Cursor Bugbot for commit 9c84d1d. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix stale log tailing by deleting $LOG_FILE before nohup in SSH launch script

  • The generated remote launch script in tunnel.ts now runs rm -f "$LOG_FILE" immediately before starting the managed server, so readiness and output checks see only the current run's log.
  • Adds an end-to-end test suite in tunnel.test.ts that executes the generated script in a real POSIX shell, using a fake node binary and a seeded stale server.log to verify a silent launch is reported instead of old log content.
  • Tests conditionally skip when no suitable shell with nohup, mktemp, cmp, and tail is available.

Macroscope summarized 9c84d1d.

The managed remote launch appends to server.log, and the readiness
failure branch treats whatever is already in that file as this run's
output:
if [ -s "$LOG_FILE" ]; then
tail -n 80 "$LOG_FILE" >&2
else
printf 'It wrote nothing to %s, so it exited before producing any output.\n'
fi
The empty-log arm arrived in pingdotgg#5132 to name the case where the remote
server exits without logging anything. The log is opened in append mode
and never cleared, so [ -s ] is true from the first run that logs
onward. After that the empty-log arm is unreachable, a server that dies
silently is reported with the previous run's error, and the user is
pointed at the wrong remedy. The file also grows without bound across
managed restarts.
Unlink rather than truncate. wait_for_pid_exit gives up after two
seconds, so a previous server that ignores the kill is still holding its
descriptor when the next launch runs. Unlinking leaves it writing into
the old file; truncating leaves it writing into the new one, which puts
the size back above zero and sends the diagnostic down the tail branch
again.
The new test runs the real generated script through a shell against a
seeded stale log, with a fake node that picks a port, fails readiness at
once, and lets the runner exit without writing a byte. It fails on the
append-only script at the "It wrote nothing to" assertion.
@coderabbitai

coderabbitaiBot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 851f68bd-5f5b-4721-b0aa-dc3f09d540c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connectorBot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

ReviewStatusCommitReview trigger
📝 Code ReviewCompleted2026-08-31T18:18:22.742111Zbe1157ePR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 31, 2026
@macroscopeapp

macroscopeappBot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The production change is a small, isolated SSH launch fix that clears stale managed-server logs before starting a new process, with an end-to-end regression test. The test additionally introduces a line-scoped nodeBuiltinImport:off static-analysis suppression, which warrants human review.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

The executed suite needs node:child_process, which effect(nodeBuiltinImport)
rejects. The first version turned the rule off for the whole file, which also
covered the thirteen tests that were already there and had never needed it.
Use the next-line form instead, so the exemption reaches only the one import
that requires it. Verified against a patched tsgo: removing the directive
reports TS377057 at src/tunnel.test.ts(3,35), and the next-line form silences
exactly that.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@marmar9615-cloud