You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
docs(remote): say only the host ends a macos-app lease - #3253
ADR 0007 and remote-proxy.md said the lease's own release is allowed without a session. A tenant lease_release is refused with MACOS_APP_LEASE_HOST_OWNED, so both now say a tenant cannot release the lease and that it ends by host DELETE /admin/leases/<lease-id>, expiry, daemon restart, or closing a session when the host set retainOnClose to false.
Removed lease_heartbeat and lease_release from SESSIONLESS_COMMANDS in src/daemon/macos-app-lease.ts: both are exempt from lease admission, so assertMacOsAppLeaseAdmitsRequest never sees them.
Checks: pnpm check:affected --run passes at b6a6f59.
I read the docs hunks at 7a0cc02 and found two docs errors to fix before merge. The code change only removes two unreachable SESSIONLESS_COMMANDS entries in src/daemon/macos-app-lease.ts, so runtime behavior does not change. Please fix these two: DELETE /admin/leases in website/docs/docs/remote-proxy.md and in the ADR needs the /admin/leases/<lease-id> form, because the bare path returns 405 for DELETE (the same page already shows the id form at line 125); "only the host ends it" in docs/adr/0007-remote-device-leases.md conflicts with the list that follows it, so say that a tenant cannot release the lease and that it ends by host DELETE, TTL expiry, daemon restart, or closing a session whose host set retainOnClose false. Not blocking: the ADR line still lists the lease heartbeat as a carve-out, but the registry's leaseAdmissionExempt trait exempts it, so drop it from that list or point it at the trait. The PR body could also mention the dead-entry removal.
Two open threads still apply: #3253 (comment) (bare DELETE path) and #3253 (comment) (host-ends-lease wording). Both are in the notes above, so fixing them should let you resolve both threads.
I did not run the daemon or the tests. The Smoke Tests job failed at "Preflight iOS runner through public CLI", where prepare ios-runner could not start the daemon within 15 seconds. That looks unrelated, because the diff shares no code with daemon startup or the iOS runner, but I did not rerun the job. I know of no conflicts. Before merge, please fix the two docs as described and rerun the failed iOS preflight check.
@thymikee pushed b6a6f59. Both docs now use DELETE /admin/leases/<lease-id> and say a tenant cannot release the lease; it ends by host DELETE, expiry, daemon restart, or closing a session when the host set retainOnClose to false. I dropped the heartbeat from the ADR's session carve-out and updated the PR body for the dead-entry removal. pnpm check:affected --run passes locally. I will check the iOS preflight rerun on CI.
This list is no longer all requests that run without a leased-app session: lease_heartbeat still runs sessionlessly because its registry exemption bypasses this helper. Qualify the comment as describing only requests that reach macOS-app admission so future changes do not mistake heartbeat for session-bound behavior.
Document lease heartbeat as an exception to session requirements
website/docs/docs/remote-proxy.md:169
The next paragraph still says every command other than open and batch requires the opened session, which incorrectly includes the heartbeat now retained here. lease_heartbeat is admission-exempt and is explicitly tested without a session in src/daemon/__tests__/request-execution-scope-macos-app-lease.test.ts:88-94; document that exception explicitly.
The earlier findings on 7a0cc02 are fixed at b6a6f59, and I found no new problems. The remote-proxy page now says DELETE /admin/leases/<lease-id>, which matches the route in host-lease-http.ts. The ADR no longer says only the host ends a lease. It now lists host DELETE, expiry, daemon restart, and session close with retainOnClose false, and it says a tenant cannot release the lease. The src change only removes a dead entry that no admitted route reaches. I did not run the test suite or pnpm check:affected. I relied on the 16 checks, which all pass. The daemon-restart claim rests on a grep for persistence in lease-registry.ts, not on a live restart. I only re-read the ADR and remote-proxy.md sections this change touches. Both cubic-dev-ai threads are fixed at this head, so you can resolve them: #3253 (comment) and #3253 (comment). There are no conflicts. Nothing else stops the merge, so it is ready once the maintainer is satisfied.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
ready-for-humanValid work that needs human implementation, judgment, or maintainer merge
3 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #3236 (non-blocking review notes).
lease_releaseis refused withMACOS_APP_LEASE_HOST_OWNED, so both now say a tenant cannot release the lease and that it ends by hostDELETE /admin/leases/<lease-id>, expiry, daemon restart, or closing a session when the host setretainOnCloseto false.lease_heartbeatandlease_releasefromSESSIONLESS_COMMANDSinsrc/daemon/macos-app-lease.ts: both are exempt from lease admission, soassertMacOsAppLeaseAdmitsRequestnever sees them.Checks:
pnpm check:affected --runpasses at b6a6f59.