Repository navigation
Conversation
String.replaceAll treats $$ in a string replacement as an escaped $, so the runner embedded in the SSH launch script wrote a literal $ as the archive lock owner. A replacer function keeps the value literal.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This is a narrowly scoped, well-tested fix for incorrect PID interpolation in SSH archive locking. Because it changes security-sensitive SSH remote-execution code, the change requires human review despite its small size. Notes:
You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthrough
ChangesTunnel script placeholder handling
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change preserves dollar-sign sequences in generated tunnel scripts and adds a regression check. No concrete issue currently blocks merging. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Dismissing prior approval to re-evaluate ae64a68
Problem
The SSH launch script embeds the remote runner through
applyScriptPlaceholders, which usedString.replaceAllwith a string replacement. In a replacement string,$$means a literal$, so the runner's archive lock lineprintf '%s\n' "$$" > "$T3_LOCK/pid"reached the remote host asprintf '%s\n' "$".The lock then records
$as its owner. A second launch waiting on the lock runskill -0 "$", which always fails, so it treats the owner as dead, deletes the lock, and installs the same release archive at the same time as the first launch. The deployed runner also never matchesbuildRemoteT3RunnerScript, which breaks any test that compares them.Change
applyScriptPlaceholderspasses a replacer function, so$patterns in the value stay literal. The$$in the launch script's ownRUNNER_NEXTname was never affected, since templates are not replacement values.Scope and approval
Small, focused fix for an obvious bug: the archive lock is meant to serialize concurrent installs and currently cannot, because the owner PID it records is not a PID. One line of production code plus a regression test. Found while rebasing #10951, whose reconnect fixture depends on the deployed runner matching
buildRemoteT3RunnerScript; this was split out so that PR stays on one problem.Verification
embeds the runner in the launch script byte for byteinpackages/ssh/src/tunnel.test.ts: fails onmain(the launch script does not contain the runner), passes with the fix.vp test run src/inpackages/ssh: 5 files, 36 tests passed.vp fmt --checkandvp linton the two changed files: clean.Made with Claude Opus 5.5 in Claude Code.