Skip to content

fix(server): a slow typed address no longer freezes input in a server browser tab - #16691

Open
josephv123 wants to merge 1 commit into
pingdotgg:mainfrom
josephv123:fix/browser-nav-blocks-input
Open

josephv123 wants to merge 1 commit into
pingdotgg:mainfrom
josephv123:fix/browser-nav-blocks-input

Conversation

@josephv123

Copy link
Copy Markdown

Problem

In an environment-hosted (server runtime) browser tab, an address typed in the address bar whose host never answers holds back everything else the viewer does in that tab for up to 15 seconds. Clicks, scrolling, keys, Back, Reload, and a corrected address all wait behind it, then run at once. Chrome would abandon the slow load as soon as you navigate somewhere else.

The viewer's navigate, history, and soft reload awaited the commit (waitUntil: "commit", 15 s timeout) inside SessionControl's serialized input queue, so a navigation that never commits held the queue for the full timeout.

Change

  • ServerBrowser.dispatchViewerInput starts viewer navigations (goto, goBack/goForward, soft reload) without awaiting them inside the queue. The viewer's next input runs immediately, and a newer navigation replaces the slow one in Chromium, as it does in Chrome.
  • SessionControl.trackUntilHandoff records those navigations. Unlike track, which makes every later action wait (used by the agent's readiness: "none" path), it only makes release/disconnect wait. That keeps the existing guarantee that an agent acts only after the viewer's navigation settles (covered by the existing "release waits for viewer $method to commit before agent actions" test).
  • Hard reload (ignoreCache) and every other input are unchanged.

This is the human-navigation change from the maintainer's suggested fix direction on the issue. It does not add a per-action deadline to SessionControl, which is the separate problem in #16567.

Scope and approval

Fixes #16641, a bug triaged and confirmed on main by @juliusmarminge, with the suggested fix direction: #16641 (comment)

Verification

  • New focused test in ServerBrowser.test.ts, run for goto, goBack, goForward, and reload: a viewer navigation that never commits, followed by a corrected address and typed text. On main all 4 cases time out (the next input is stuck behind the hung navigation). With this change all 4 pass, and the corrected goto and Input.insertText both reach the page.
  • vp test run src/preview/ServerBrowser.test.ts src/preview/SessionControl.test.ts: 36 passed, including the existing release-waits-for-commit tests.
  • Checked the Chromium behavior this relies on with Playwright 1.60 and chrome-headless-shell 154 on Ubuntu 26.04, using the issue's unreachable https://10.255.255.1/. Starting a second goto while the first was pending aborted the first with net::ERR_ABORTED, and the replacement committed in about 10 ms. Back during a pending load landed on the previous page. Playwright rejects that goBack with ERR_ABORTED, which the tracked promise absorbs.
  • tsc --noEmit for apps/server passes. Lint is clean on the changed files.

Not checked: I did not drive the Browser panel end to end in a running app.

Claude Opus 5.5 via Claude Code in T3 Code

… browser tab

Viewer navigate, history, and reload no longer wait for the commit inside
SessionControl's input queue. A new SessionControl.trackUntilHandoff keeps
release waiting for them, so an agent still acts only after the viewer's
navigation settles.

Fixes pingdotgg#16641
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Oct 7, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at a2b8540

Macroscope's review found this PR approvable — This is a focused server-browser bug fix that unblocks subsequent viewer input during slow navigations while preserving navigation settlement before control returns to the agent. The affected paths are covered by targeted tests, with no product-default or static-analysis override changes.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c50e03b6-dd97-4c8e-8ac0-23eccd547566
📥 Commits

Reviewing files that changed from the base of the PR and between bfec238 and a2b8540.

📒 Files selected for processing (3)
  • apps/server/src/preview/ServerBrowser.test.ts
  • apps/server/src/preview/ServerBrowser.ts
  • apps/server/src/preview/SessionControl.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

Viewer navigation, history, and soft reload now track navigation promises without awaiting commit. SessionControl keeps this work separate from pending work and waits for handoff work before calling afterDrain. Tests cover follow-up navigation and text input while the initial navigation remains pending.

Changes

Viewer Navigation

Layer / File(s) Summary
Track navigation until handoff
apps/server/src/preview/SessionControl.ts
SessionControl adds a separate settled-work chain for handoff tracking. release waits for that chain before calling afterDrain.
Wire viewer navigation to handoff tracking
apps/server/src/preview/ServerBrowser.ts, apps/server/src/preview/ServerBrowser.test.ts
Viewer navigation, history, and soft reload pass navigation promises to trackUntilHandoff. Tests check that follow-up navigation and text input run while the initial navigation remains pending.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Bug fix · Severity of issue fixed: Low

Suggested reviewers: maria-rcks

Merge Risk: ⚪ Minimal · up to a2b85

Later viewer input can proceed while navigation is pending, and session release still waits for that navigation. No actionable merge-blocking risk was identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a2b85

Ownership checks and navigation handoff ordering remain intact, and no new authorization bypass was identified. Risk is limited, but interruption and shutdown behavior has not been validated against a real browser in this review.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed control path affects navigation and input timing on the selected browser tab. Its inspected authorization scope remains the controlling viewer and assigned agent; the new handoff method does not itself grant additional tab or service authority.

Security Findings and Attack Paths

  • inferred — A controlling viewer can now send further navigation or input before an earlier navigation settles. This newly permitted overlap does not establish a cross-owner attack path: capability checks, owner checks, and the queued release barrier remain enforced.

Trust Boundaries and Controls

  • observed — Viewer identities are generated server-side. Raw viewer messages reach navigation through the capability-gated input closure and human-owner check; strings supplied as addresses retain HTTP/HTTPS normalization. The upstream source of the operation capability was not assessed.

Resilience and Maintainability Implications

  • observed — Disconnect awaits owner-checked release before removing the viewer, and release cleanup clears pressed input state. Close marks the control closed without independently awaiting the handoff chain; terminal tab removal also removes the tab and closes its page or connection. This differs from transferring ownership to a live tab.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the fix: slow address navigation no longer blocks input in a server browser tab.
Description check ✅ Passed The description covers the problem, change, scope and approval, and verification. It reports focused tests and checks, and it states that end-to-end Browser panel testing was not done.
Linked Issues check ✅ Passed Issue [#16641] requires later viewer input to proceed while a slow server-browser navigation is pending. The PR starts viewer goto, history, and soft reload without holding the serialized input queue.…
Out of Scope Changes check ✅ Passed The reported changes are limited to viewer navigation handling, SessionControl handoff tracking, and focused tests. Each change supports issue [#16641] by allowing later input during a pending navig…
Approvability ✅ Passed The diff changes only ServerBrowser.ts, SessionControl.ts, and ServerBrowser.test.ts. It implements a focused fix for viewer navigation that blocks later input and adds regression coverage. It d…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: A slow typed navigation blocks all input in an environment-hosted browser tab for 15 seconds

1 participant