Conversation
Co-Authored-By: Epinephrine <luvs01@hanmail.net>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe link listener now exposes whether it owns a reverse-forward target. Optional startup uses that status to decide whether to start the supervisor. Link issuance starts the supervisor after confirming that the listener is listening. ChangesLink listener and supervisor startup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Link issuance can recover the listener before returning credentials, with no established user-visible regression in the changed startup flow. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new startup order reduces the chance of starting tunnels without a listener this process owns. An issuance and removal happening at the same time may still produce a successful response for a link that has already been removed; no new unauthorized access was established. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 5 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
리뷰 · 우선순위 22 / 80허브가 켜질 때 링크 포트를 이 프로그램이 못 열어도, 터널은 바로 시작됐습니다. 터널은 파일에 적힌 포트로 들어갑니다. 그 포트는 다른 프로그램이 이미 열고 있을 수 있습니다. 이 PR은 이 프로그램이 포트를 연 뒤에만 터널을 시작합니다. 상태는 라인 - 라인 - 메인테이너의 판단이 필요한 지점 시작할 때 포트를 못 열면, 이미 있던 허브 터널은 다음 너의 추천 포트를 연 뒤에만 터널을 켜는 시작 조건은 맞습니다. 발급이 포트를 복구한 뒤 365줄에서 터널을 켜는 순서도 테스트와 맞습니다. 머지 전에 438줄은 포트가 열린 뒤에만 이 댓글은 grok-bot이 작성했습니다 |
| PR | Change | Author | | --- | --- | --- | | #5968 | Revalidate context relay admission against the live hub-link key policy before dispatch. | luvs01 | | #5966 | Start the link tunnel supervisor only after the listener owns a bound target, and start it after issue recovery. | luvs01 | | #5933 | Honor an explicitly configured Devin reset wait while preserving stream heartbeats and bounded retry behavior. | luvs01 | | #5952 | Expand measured Command Code effort ladders. | codingbooo | | #5942 | Project Claude input estimates onto the settled wire and canonical combo target. | moseoridev | | #5943 | Retry a quota-summary 403 once on the same fixed Antigravity endpoint with the legacy User-Agent. | codingbooo | Integration commits add a real delayed-body hub-link revocation regression; a failed-bind and recovered-bind supervisor regression; the first rejected Command Code send retry; and explicit layout registrations for the Devin cooldown and Claude projection tests. The Claude source PR already records `targetRoute.modelId` and includes the combo-alias regression; reverting that line makes the alias case fail. Review follow-up: the DeepSeek V4 Flash DSH/ZCode export expectations now match all five calibrated efforts. Devin combo children now bypass the optional stated-reset wait and surface their pre-output refusal, so the combo can advance promptly; standalone opted-in turns retain reset waiting and heartbeats. The delayed-reset combo and real Devin adapter regressions were red before the fix and green after it. The alternate Antigravity 403 PR (#5976) was left out because the included implementation covers the same retry with more extensive tests for bearer/project identity, cancellation failure, retry bounds, redirects, and fallback. No code was taken from that alternative. Independent security review is requested before merge for link admission and tunnel startup (`src/server/index/serve-options.ts`, `src/server/index/optional-listeners.ts`, `src/server/index/link-listener.ts`, `src/server/management/link-routes.ts`), Devin wait/replay (`src/adapters/devin.ts`, `src/adapters/devin/cloud-direct/stated-reset-retry.ts`, `src/adapters/run-turn-queue.ts`, `src/server/responses/run-turn-execution.ts`), and the credential-bearing Antigravity retry (`src/providers/quota/antigravity.ts`). Co-authored-by: Epinephrine <luvs01@hanmail.net> Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: codingbo <cnsdbo@163.com> Co-authored-by: moseoridev <sjssjs1344@gmail.com>
|
Thanks! This landed on |
Summary
linkListenerOwnsTargetnow gates supervisor startup on an owned, bound listener, andissue()callssupervisor.ensureStarted()so a listener that binds later still recovers the supervisor before issuing a link.src/server/management/link-routes.ts, where this adds one line inissue()away from fix(link): Remote Link loads and probes SSH hosts from the local dashboard #5928's probing changes.Verification
tests/server/link-listener-lifecycle.test.tsandtests/server/link-management-routes.test.tscover the owned-listener gate and theensureStartedrecovery path.codex/fix-link-tunnels-startup-on-bind-failure(test shards 1-4, hygiene, structure gate all SUCCESS).Checklist
Summary by CodeRabbit