Repository navigation
fix(mothership): fail unclaimed desktop calls fast and stop dropping them silently - #8652
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
1 issue found across 14 files
Confidence score: 3/5
- In
desktop-pickup.ts, calls arriving near the end of pickup grace can time out before receiving their fulltimeoutMsexecution budget. Restart the wait with the full timeout after pickup grace.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="apps/sim/lib/mothership/request/tools/desktop-pickup.ts">
<violation number="1" location="apps/sim/lib/mothership/request/tools/desktop-pickup.ts:99">
P2: A call claimed near the end of the pickup grace gets only the original deadline’s remainder to execute, not its full `timeoutMs` budget. Restart the wait with the full timeout so pickup grace does not consume the execution allowance.</violation>
</file>
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
…them silently A desktop call reaches the user's machine only through the chat view showing that chat, so one issued while the user is elsewhere was never claimed and the turn waited out a 90-160 s watchdog that called it hung. One desktop wait now fails a call still unclaimed after a 15 s pickup grace as never started, with the inverse of the desktop's claim (pending -> failed) and a result sealed like any client completion. A call claimed in time keeps waiting, and a result that lands as the grace runs out is returned, not discarded. Local reads (read_local_file, user-local VFS reads) join them for a desktop that advertises localReadClaims: the desktop claims each read through authorize, as it already does for imports. Older desktops keep today's behaviour. The single "hung and was abandoned" result becomes two: notStarted for an unclaimed call, and outcomeUnknown/doNotRetry for one that started and lost its result. Both are settled through one sealed failure helper. A terminal run's server budget now follows the wait the desktop holds it for. A not-started report can settle only an unclaimed call. In the renderer, a running browser action is cancelled only by Stop: recovering the stream or leaving the chat view lets it finish and report. A terminal call delivered too late is reported as not started instead of being skipped.
…or each claimant The authorize and confirm routes classify desktop tools through lib/mothership/tools/desktop-tools.ts instead of inline checks. The Sim execution claim and the desktop claim share one run-admission lock but return their own outcome types, so a Sim caller can no longer receive the desktop-only awaiting_permission outcome. The terminal-status mapping moves to lifecycle as getTerminalConfirmationStatus, since confirm uses it for every client tool.
07cfc57 to
d9b5bc2
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 36 files
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Fix all with cubic | Re-trigger cubic
…ore the grace A wait shorter than the pickup grace ended with no result and left the call claimable; it now settles it as never started like any unclaimed call. The desktop E2E fixture models claims per call, the way the server accepts a local read's repeat claim and refuses a second import claim. The admission probe follows the claim rename.
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 38 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Re-trigger cubic
Summary
Builds on #8643 (merged). Only the chat view showing a chat starts that chat's desktop calls, so a call issued while the user is on another chat or page was claimed by nobody. The turn then waited 90 to 160 s for a watchdog that called it "hung".
request/tools/desktop-wait.ts). A desktop call the desktop claims on pickup that is still unclaimed after a 15 s grace is settled as never started, using the inverse of the claim (pending -> failed). Exactly one side wins: a late claim is refused, and a call claimed in time keeps waiting for its result.settleToolCallFailurethat the watchdog uses too.{ error, notStarted: true }: never started, the chat isn't open in the desktop app, safe to retry.read_local_file, user-local VFSread/grep/glob) are covered too, for a desktop that advertiseslocalReadClaims:pending;claim: true), as it already does for imports; later reads of the same call ride on that claim.runningbehaviour, which authorize still accepts.notStarted, for a desktop call nobody claimed;outcomeUnknown+doNotRetry, for one that started and lost its result.runbudget. The server budget now follows the wait the desktop holds a run for (waitSeconds, up to 120 s), plus headroom; it was a fixed 60 + 30 s.resolveRunWaitMsmoves into@sim/terminal-protocol, shared with the desktop.lib/mothership/tools/desktop-tools.tsis the only desktop-tool classifier; the authorize and confirm routes and the pickup path use it.awaiting_permission.success: falsefeeds its failure breaker as before.Type of Change
Testing
desktop-tool-pickup.integration.ts(real Postgres + Redis, production pre-persist and dispatch, authorize and confirm routes), 7 tests:stagingit hangs for the whole test budget;desktop-wait.test.tsforces a result to land inside the grace/abort window;executor.test.tscovers both abandoned shapes and the terminal budget;terminal-tool-execution.test.ts;use-chat.dom.test.tsx: recovery and unmount leave the action running, and Stop cancels it;ipc.test.tsclaim flag.bun run lint,bun run type-check,bun run check:audits,bun run test,bun run test:integration,bun run docs-manifest:check, block-registry check: all pass.Checklist
test-auditauthoring gate)