Repository navigation
fix(shared): bound cloudflared download with 10-minute timeout - #14139
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughCloudflared release asset requests and response body reads now time out after 10 minutes. A stalled-download test verifies that installation fails with the ChangesCloudflared download timeout
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change is mergeable with normal checks. The new test covers a stalled request, though it does not verify a stalled body read. 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Full details: Description checkExplanation The description clearly explains the problem, implementation, preserved error contract, and verification results. It does not include the required Scope and approval information or explain why this focused bug fix qualifies for the no-approval exception.
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a focused bug fix that bounds both cloudflared download phases and preserves the existing installation error contract. The accompanying test covers stalled requests, while all unrelated runtime paths remain unchanged. You can add or adjust custom eligibility rules. Learn more. |
003d910 to
822e4f1
Compare
Dismissing prior approval to re-evaluate 822e4f1
cloudflared's downloadAsset ran httpClient.execute and response.arrayBuffer
with no deadline. A wedged-but-alive endpoint (or a stalled drip) parked the
relay-client install forever - same unbounded-wait family as the codex/app-
server request timeouts and the OAuth/relay-unlink CLI timeouts.
Wrap both network hops in Effect.timeout(CLOUDFLARED_DOWNLOAD_TIMEOUT)
(10 minutes, generous for a ~40MB binary). Expiry flows through the
existing mapError into RelayClientInstallError{reason: download_failed},
so the install error contract is unchanged.
Authored with AI assistance (Muse, Meta's Muse Spark) under the
contributor's direction. The contributor reviewed the diff and ran the
focused tests before opening this PR.
822e4f1 to
89f9bff
Compare
|
Rebased again onto main after #16998, #10585 and #11184 landed (89f9bff). The stalled-download test sits after the new Windows rename tests. I also dropped a duplicate |
Dismissing prior approval to re-evaluate 89f9bff
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
* fix(web): link pull requests to threads in folders that aren't Git repos (pingdotgg#15946) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): find messages and plans in the current thread (pingdotgg#10439) Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): improve terminal scrollback navigation and snapshots (pingdotgg#17091) * docs(internals): add a checklist for adding a provider (pingdotgg#17229) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mobile): keep native screens ordered during stack pops (pingdotgg#17231) * fix(server): pairing tokens work on Node versions that cannot bind booleans (pingdotgg#16730) * fix(mobile): HTML pages in a thread no longer trap scrolling on Android (pingdotgg#17211) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): centered scrollers no longer shift when the scrollbar appears (pingdotgg#17077) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): distinguish thread search matches from code tints (pingdotgg#17263) * fix(server): Pi extension wakes get an owned continuation turn (pingdotgg#17214) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): Pi discovers optional T3 tools on demand (pingdotgg#17220) * fix(web): stack merge dialog closes as soon as you confirm (pingdotgg#17116) * fix(server): Pi editor dialogs prefill the answer composer (pingdotgg#17206) * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines (pingdotgg#17264) * fix(server): Pi discovers workspace skills and commands (pingdotgg#17190) * fix(mobile): preserve navigation after native swipe back (pingdotgg#17268) * fix(server): keep newly discovered models out of legacy groups (pingdotgg#14314) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(editors): open remote projects in JetBrains IDEs over SSH (pingdotgg#17271) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(desktop): expect JetBrains IDEs among remote editors (pingdotgg#17291) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): recognize authenticated GitHub Enterprise hosts (pingdotgg#11059) Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * fix(connect): relay client updates itself and skips incompatible cloudflared (pingdotgg#17275) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): relay client install waits out a brief Windows file lock (pingdotgg#16998) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(shared): release relay install locks on cancellation (pingdotgg#10585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(shared): bump managed cloudflared to 2026.10.0 (pingdotgg#11184) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): bound cloudflared download with 10-minute timeout (pingdotgg#14139) Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> * refactor(provider-core): add provider-core and provider-testing packages (pingdotgg#17299) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(settings): drop the legacy per-driver providers map (pingdotgg#17300) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-pi): move Pi into its own provider package (pingdotgg#17302) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(models): tell users when a CLI update unlocks a new model (pingdotgg#17307) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): collapsed composer reserves room for wide send actions (pingdotgg#17016) * fix(muse): workflow subagents no longer stall on hidden approvals (pingdotgg#17329) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-core): share attachment prompts, notifications, and event loggers (pingdotgg#17330) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts (pingdotgg#16950) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): environment-hosted browser tabs behave like a normal browser (pingdotgg#16963) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs (pingdotgg#16961) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): desktop opens remote environments' browser tabs locally (pingdotgg#17316) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(desktop): the t3 command warns instead of installing behind another t3 (pingdotgg#17351) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): images, video, HTML and PDF preview in a thread before its first message (pingdotgg#17352) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-muse): move Muse Code into its own provider package (pingdotgg#17331) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): semantic branch naming hint lines up with its setting (pingdotgg#16972) * fix(mobile): restore chat image previews in the v5 stack (pingdotgg#17361) * feat(mobile): fade working threads and match web's status labels (pingdotgg#17368) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership (pingdotgg#16956) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): add room for thread timeline markers (pingdotgg#17372) * fix(web): drop sidebar context before cancelling pointer drag (pingdotgg#17373) * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing (pingdotgg#17375) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(auth): show connection permissions and enforce session lifetime (pingdotgg#17370) Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> * refactor(provider-opencode): move OpenCode into its own provider package (pingdotgg#17345) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-cursor): move Cursor into its own provider package (pingdotgg#17349) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-acp): move the shared ACP adapter into its own package (pingdotgg#17354) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-grok): move Grok into its own provider package (pingdotgg#17357) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): speed up long thread message sync (pingdotgg#17387) * fix(desktop): cancel backend pipe reads to avoid slow shutdown (pingdotgg#17386) * refactor(providers): adapter factories yield their services (pingdotgg#17381) * fix(web): show a row spinner instead of a banner when expanding a folder (pingdotgg#17378) * fix(server): a timed-out browser drag no longer exits the server (pingdotgg#17360) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): a logged-out Claude CLI no longer reports as authenticated (pingdotgg#15459) * fix(server): Pi loads every selected skill without losing prompt text (pingdotgg#17194) * fix(server): keep the Claude MCP token out of process arguments (pingdotgg#17408) * fix(server): reconcile Pi native session rewinds (pingdotgg#13839) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(provider-pi): cover continuation offers through the driver (pingdotgg#17407) * refactor(provider-acp-registry): move the ACP Registry into its own package (pingdotgg#17405) * fix(server): relay client updates no longer drop the host off T3 Connect (pingdotgg#17366) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Jono Kemball <Noojuno@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: chise <lqff.yt@gmail.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: jztmanyl <jztmanyl@gmail.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Grzegorz Mandziak <4248465+alimek@users.noreply.github.com> Co-authored-by: Scott Norteman <snorteman@gmail.com> Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com> Co-authored-by: Aaron Queen <bompus@users.noreply.github.com> Co-authored-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Daniel Alvim <danielalvim@tuta.io> Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Problem: cloudflared's
downloadAssetranhttpClient.executeandresponse.arrayBufferwith no deadline. A wedged-but-alive endpoint (or a stalled drip) parked the relay-client install forever — same unbounded-wait family as the previously fixed codex/app-server request timeouts and the OAuth/relay-unlink CLI timeouts.Fix: wrap both network hops in
Effect.timeout(CLOUDFLARED_DOWNLOAD_TIMEOUT)(10 minutes, generous for a ~40MB binary). Expiry flows through the existingmapErrorintoRelayClientInstallError{reason: "download_failed"}, so the install error contract is unchanged. 2 files, +59 lines.Validation:
fails a stalled download after the download timeout(TestClock + forkChild + never-responding HttpClient): FAILS on base (hangs to the 60s vitest timeout — the defect is literally a hang), passes with the fix.relayClient.test.ts: 6/6 green with fix.tsc --noEmitclean onpackages/shared.vp fmtclean.Authored with AI assistance (Muse, Meta's Muse Spark) under the contributor's direction. The contributor reviewed the diff and ran the focused tests before opening this PR.