Skip to content

Fix cross-platform CI failures and async request races - #1

Merged
beiwei30 merged 11 commits into
mainfrom
codex/fix-unix-shell-fallback
Jul 28, 2026
Merged

beiwei30 merged 11 commits into
mainfrom
codex/fix-unix-shell-fallback

Conversation

@beiwei30

@beiwei30 beiwei30 commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • make Unix process launch, cancellation, and socket transports portable across Linux, macOS, and Windows
  • remove host-specific assumptions from CI and tests, including shell, ripgrep, glyph, Git identity, and PTY branding expectations
  • prevent fast permission responses and terminal stream events from racing ahead of the state or deltas they depend on
  • keep Linux bubblewrap validation strict while preparing the ephemeral Ubuntu runner for its AppArmor user-namespace policy

Changes

Cross-platform runtime behavior

  • fall back to /bin/sh when SHELL is absent on Unix
  • pass an option separator before a negative process-group ID when terminating Unix background commands
  • compile Unix-socket implementations only on Unix and return a clear unsupported-platform error elsewhere

Request and stream reliability

  • register pending permission responses before publishing the permission event, with cleanup when notification fails
  • route queued best-effort deltas before lossless terminal events in the in-process transport
  • continue draining one transport queue after the other closes

Self-contained CI and tests

  • replace the environment source-audit dependency on host rg with direct Rust source traversal
  • simulate successful ripgrep metadata in the focused test instead of requiring the executable
  • make the dynamic-skill fixture command POSIX-compatible with dash
  • use the platform-specific production tool marker in TUI expectations, normalize layout wrapping, and provide disposable Git commit identity
  • update PTY expectations to the current Orb Code header
  • prepare the Ubuntu release runner for forced bubblewrap host validation under AppArmor

Why

The original ACP failure came from a cleared environment with no SHELL, where the previous zsh fallback was unavailable on Ubuntu. Follow-up jobs exposed additional assumptions inherited from a macOS developer environment: procps kill parsing, missing rg, unconditional Unix-socket imports, dash behavior, platform-specific glyphs, and global Git configuration.

Two independent async races were also exposed. A fast headless client could respond before a permission request was registered, leaving the turn blocked. Separately, the in-process transport could deliver TurnFinished before an already queued AssistantDelta, closing the ACP route before the final answer text was forwarded.

Verification

Focused and stress validation:

  • scripts/check.sh --quick
  • complete orbcode-app-server-client suite: 39 passed
  • Linux Docker acp_server_request_e2e: 48 passed
  • Linux Docker orbcode-tools --lib: 328 passed without host rg
  • orbcode-tui --lib: 938 passed on both macOS and Linux Docker
  • PTY e2e: 3 passed
  • 200 consecutive Linux Docker runs of the stream-json permission scenarios
  • 200 consecutive Linux Docker runs of the multi-session AskUser scenario
  • 50 consecutive Linux Docker runs of the POSIX dynamic-skill scenario

Final GitHub Actions results for 75305f4:

CI failure history used during diagnosis

@beiwei30
beiwei30 marked this pull request as ready for review July 28, 2026 01:35
Copilot AI review requested due to automatic review settings July 28, 2026 01:35
@beiwei30 beiwei30 changed the title Use POSIX shell fallback on Unix Fix cross-platform CI failures and async request races Jul 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens cross-platform behavior across the Orb Code workspace by removing implicit host assumptions (shell, ripgrep, git config, Unix sockets), improving Unix process-group termination correctness, and fixing/strengthening several concurrency- and ordering-sensitive streaming paths so CI and real clients behave deterministically across Linux/macOS/Windows.

Changes:

  • Make Unix execution and tests more portable (POSIX /bin/sh fallback, POSIX-safe printf, deterministic git identity in tests, platform-normalized TUI glyph assertions).
  • Remove external executable assumptions in tests (source audit no longer depends on host rg; tools tests can deterministically simulate ripgrep success).
  • Improve reliability/order guarantees (permission request registration-before-notification; in-process stream ordering changes; Unix socket APIs gated by platform with clear unsupported errors elsewhere).

Reviewed changes

Copilot reviewed 22 out of 23 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
tui/src/tests/support/mod.rs Re-exports black_circle_glyph so test helpers can normalize platform glyphs.
tui/src/tests/support/assertions.rs Adds platform-aware tool-line helper and normalizes fixtures for macOS vs non-mac glyph differences.
tui/src/tests/slash_command/session_commands.rs Makes git commit in tests independent of global user.name/user.email config.
tui/src/tests/render/tool_cards.rs Updates tool-card rendering expectations to be platform-glyph independent.
tui/src/tests/render/activity_groups.rs Updates activity-group rendering assertions to be platform-glyph independent.
tui/src/tests/permission/overview_picker.rs Normalizes whitespace in transcript assertion to avoid layout-wrapping sensitivity.
tools/src/tests/support.rs Adds deterministic “ripgrep success” simulation helper for tests.
tools/src/tests/search.rs Uses simulated ripgrep success to test metadata path without requiring host rg.
tools/src/process.rs Fixes Linux kill parsing by adding -- before negative PGID argument.
tools/src/grep_tool.rs Extends test-only ripgrep simulator with a Success variant and corresponding outcome wiring.
tools/src/bash.rs Falls back to /bin/sh on Unix when SHELL is absent.
core/src/session_manager/tests/context_refresh.rs Makes dynamic-skill refresh test POSIX sh/dash-safe by avoiding printf option parsing.
core/src/session_manager/session_tool_runtime.rs Registers permission request before publishing the PermissionRequested event to avoid response races.
core/src/permission_state.rs Adds registration-before-notification hook and cleans up pending state on failed notification; adds regression test.
config/src/env_compat.rs Replaces rg-based source audit with a walkdir + in-process Rust-source scan.
config/Cargo.toml Adds walkdir as a dev-dependency for the source audit test.
cli/tests/tui_remote_pty_e2e.rs Updates PTY smoke test header expectation from “Claude Code” to “Orb Code”.
cli/src/main.rs Gates Unix-socket server/client paths on Unix and returns clear unsupported/invalid-input errors elsewhere.
Cargo.lock Locks the new walkdir dev dependency.
app-server-transport/src/lib.rs Compiles Unix socket module/exports only on Unix targets.
app-server-client/src/lib.rs Compiles socket transport implementation only on Unix; returns explicit unsupported error otherwise.
app-server-client/src/in_process.rs Adjusts in-process routing to address event ordering under load; adds regression test.
.github/workflows/release.yml Updates Linux bubblewrap installation step and disables Ubuntu 24.04 AppArmor unprivileged-userns restriction for CI runner compatibility.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +223 to +244
let mut lossless_open = true;
let mut best_effort_open = true;
while lossless_open || best_effort_open {
tokio::select! {
biased;
msg = best_effort_rx.recv(), if best_effort_open => {
if let Some(msg) = msg {
route_message(msg, &pending, &notif_tx, &srv_req_tx, false).await;
} else {
best_effort_open = false;
}
}
msg = lossless_rx.recv(), if lossless_open => {
if let Some(msg) = msg {
route_message(msg, &pending, &notif_tx, &srv_req_tx, true).await;
} else {
lossless_open = false;
}
}
}
}
}
@beiwei30
beiwei30 merged commit 053e86d into main Jul 28, 2026
8 checks passed
@beiwei30
beiwei30 deleted the codex/fix-unix-shell-fallback branch July 28, 2026 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants