Skip to content

fix(remote-connect): cancel relay tasks and prevent duplicate mobile commands - #2816

Merged
bobleer merged 1 commit into
GCWing:1.0.0-explorefrom
bobleer:bob/communications-validation
Sep 5, 2026
Merged

bobleer merged 1 commit into
GCWing:1.0.0-explorefrom
bobleer:bob/communications-validation

Conversation

@bobleer

@bobleer bobleer commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

Disconnecting or dropping a Relay client could leave its socket, heartbeat, or reconnect tasks alive, and a failed initial dial could leave the client stuck in Connecting. Give the connection one cancellable owner with generation fencing, full-duplex IO, write deadlines, and room/account restoration before accepting new outgoing commands. Due heartbeats take priority over a busy command queue.

Mobile device RPC could execute twice when an encrypted application error mentioned Unauthorized or HTTP 401. Retry authentication only for an actual Relay HTTP 401, preserving account-generation checks and the latest direct-login/timeout behavior.

  • Bound outbound admission to 64 messages and explicitly report saturation; failed-socket messages are not automatically replayed.
  • Add lifecycle, cancellation, reconnect, heartbeat scheduling, backpressure, and duplicate-mutation regressions.
  • Add a repeatable communications E2E handbook with 159 scenarios and a read-only worksheet exporter derived from the existing registry and RemoteCommand enum. The current inventory contains 684 operations and 35 commands, initialized as NOT_RUN.
  • Repair the App Server hook-overview test fixture and an SDK cleanup test that treated stdout EOF as process exit.

Type and Areas

Bug fix, focused transport refactor, tests, and developer documentation. Areas: services-integrations / Relay client, mobile-web, App Server test fixtures, and TypeScript SDK tests.

Motivation / Impact

Explicit disconnect and client replacement retire their transport work. Reconnection restores identity context, and sustained output cannot suppress keepalives. A remote tool's authentication error remains a single application result instead of causing another mutation.

Verification

AI-assisted change; focused automated verification on macOS arm64. Rebased onto 1.0.0-explore at 29fd98052.

Check Result
Remote Connect module 109 passed; includes loopback WebSocket tests and a heartbeat regression observed failing before the fix
Remote Connect production feature compilation Passed without adding dependencies or broadening features
Frontend communications suite 41 files, 364 passed
App Server management owner 7 passed
TypeScript SDK 66 passed; 1 Windows-only test skipped
Mobile account login / UI contracts 4 / 7 passed
Web checks; Mobile type-check and production build Passed
Core boundaries, repository hygiene, diff whitespace Passed
Worksheet exporter 684 / 35 / 159 rows exported to a fresh local directory

Commands:

cargo test --locked -p openbitfun-services-integrations --no-default-features --features remote-connect --lib remote_connect::
cargo check --locked -p openbitfun-services-integrations --no-default-features --features remote-connect
cargo test --locked -p openbitfun-app-server --offline --lib management::owner::tests
pnpm --dir src/web-ui run test:run src/infrastructure/peer-device src/infrastructure/api/adapters/peer-device-adapter.test.ts src/infrastructure/api/generated/remoteSurface.test.ts src/features/dispatch src/features/ssh-remote src/features/relay-deploy src/app/components/RemoteConnectDialog src/flow_chat/services/flow-chat-manager/PeerSessionRefreshModule.test.ts src/flow_chat/session-stream src/shared/utils/remoteSessionScope.test.ts
pnpm --dir sdk/typescript test
pnpm --dir src/mobile-web run test:account-login
pnpm --dir src/mobile-web run test:ui-components
pnpm --dir src/mobile-web run type-check
pnpm run build:mobile-web
pnpm run check:web
pnpm run check:core-boundaries
pnpm run check:repo-hygiene
git diff --check
node scripts/diagnostics/export-communications-matrix.mjs --output <new-directory>

Reviewer Notes

Real SSH servers, mobile browsers, IM providers, peer computers, and detached-dispatch fault injection still require the environments described in docs/development/communications-e2e.zh-CN.md. Local loopback and contract tests do not establish those remote results. A previous broader Shared IPC run had two failures during non-UTF-8 fixture-directory creation on macOS; Linux verification, the real Docker round trip, and Windows-native coverage remain outstanding.

The connection owner stays in services-integrations and preserves the existing wire format. The 64-message queue is a message-count limit; end-to-end byte budgets, server-side overload, and long-duration behavior remain explicit E2E follow-ups.

Checklist

  • This PR is focused and does not include secrets, temporary prompts, generated scratch files, or unrelated artifacts.
  • Relevant verification is recorded above, and skipped checks are explained.
  • Architecture documentation and the reusable verification handbook are updated; no new localized UI strings.

@bobleer
bobleer merged commit f9db36d into GCWing:1.0.0-explore Sep 5, 2026
12 checks passed
@bobleer
bobleer deleted the bob/communications-validation branch September 24, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant