Skip to content

Resolve and configure Source windows for remote hosts - #941

Draft
thesiti92 wants to merge 4 commits into
remote/7-remote-askfrom
remote/8-source-windows-trust
Draft

thesiti92 wants to merge 4 commits into
remote/7-remote-askfrom
remote/8-source-windows-trust

Conversation

@thesiti92

@thesiti92 thesiti92 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Stacked PR 8 of 9 for remote reviews (base: remote/7-remote-ask; #934, the rename, is merged). Review in order; each PR builds and passes its suites on its own.

Manual test plan

Purpose. Builds what a remote Source window needs before anything opens one: the whiteboard+<serverId> resolver over the review channel, the read-only pin and title for every Source window, and their registration in the navigator. A Source window layers settings as stock VS Code does, but no workspace file, folder .vscode/settings.json or host machine setting can lower its read-only rule. There is no UI entry point for a remote Source window yet (PR 9), so the remote half of the read-only check runs at PR 9's head.

Setup. Worktree at origin/remote/8-source-windows-trust. No host is needed for steps 1–3.

Steps.

  1. (cd apps/review-desktop && TSX_TSCONFIG_PATH=tsconfig.test.json node --import tsx --test --test-force-exit code-oss/src/vs/review/services/remote/reviewWindowAuthorityResolver.test.ts code-oss/src/vs/review/services/configuration/reviewSourceWindowConfiguration.test.ts code-oss/src/vs/review/electron-main/remote/reviewRemoteHosts.test.ts) → all pass.
  2. Local read-only pin. The window shows the review's own checkout of the reviewed commit, so the settings file must be committed: W='{"files.readonlyInclude":{"**/*":false},"files.readonlyExclude":{"**/*":true},"window.title":"wb hostile title","editor.fontSize":40}'; awk '/^const fixture = String.raw/{f=1;next} /^;/{f=0} f' apps/review-desktop/scripts/e2e/journeys/remote-source-window.mjs | sed "s#^ git add \.\$# mkdir -p .vscode; echo '$W' > .vscode/settings.json; git add .#" > /tmp/wb-source.sh; mkdir -p $H/laptop $H/bin; printf '#!/bin/sh\nexec node %s/packages/review/dist/cli.js "$@"\n' "$PWD" > $H/bin/whiteboard; chmod +x $H/bin/whiteboard. With Desktop running: HOME=$H/laptop DEV_REVIEW_HOME=$H DEV_FAST_REVIEW_CLI_NO_DELEGATE=1 PATH=$H/bin:$PATH bash -s -- Local-source Local-second < /tmp/wb-source.sh → a laptop review whose committed .vscode/settings.json tries to lift read-only.
  3. Open Local-source → Diff → Open file on f.ts → Source window, not titled wb hostile title; typing in f.ts changes nothing and shows the read-only notice.
  4. With a host online with language features, api /reviews-api → its entries still have available.sourceWindows: false, and the remote review's Diff view offers no Open file.
  5. At origin/remote/9-source-windows (needs PR 9's entry point), the same against a host, driven as remote-source-window drives it: S wb-test-a 'bash -s -- Remote-source Second-checkout' < /tmp/wb-source.sh (the step 2 script, so the checkout commits the same .vscode/settings.json), and echo "$W" | S wb-test-a 'mkdir -p ~/.dev/whiteboard-remote/server/data/Machine && cat > ~/.dev/whiteboard-remote/server/data/Machine/settings.json' for the host's machine settings. Add the host; Open file on f.ts → the window is titled Remote-source — Source — Whiteboard, its explorer shows .vscode, f.ts is read-only and typing shows the notice. Other settings layer as stock VS Code's: the host's editor.fontSize 40 applies.

Covered by unit tests.

  • reviewWindowAuthorityResolver.test.ts: waits up to 60 s for a connecting host, then fails <alias> is offline; re-resolves a moved forward; other authorities pass through.
  • reviewSourceWindowConfiguration.test.ts: the workspace file, a folder's settings and the host's machine settings cannot lower files.readonlyInclude/files.readonlyExclude.
  • reviewRemoteHosts.test.ts: removing a machine's last alias closes only its windows.

Cleanup. Quit Desktop; rm -rf $H /tmp/wb-source.sh; if steps 4–5 used a host, common cleanup.

Reviewer notes

  • Remote hosts are trusted the way VS Code Remote trusts them: a Source window layers settings and registers host extension contributions as stock VS Code does; only the read-only pin and the title stay Whiteboard's (docs/superpowers/plans/2026-10-05-adopt-vscode-trust-model.md, rulings T2, T3, T5).
  • Not a defect: after a first success the resolver waits on a host that is connecting (the stage-4 ruling); removing the host closes its windows, which ends the wait.
  • Not a defect: the resolver does not override getConnectionData; the base service caches it per authority.
Common setup for all plans

Common setup (read once)

  • Test each PR in a worktree at its head branch: git -C <core> worktree add --detach ../review-prN origin/<head>, then pnpm install there. Run everything below from that worktree root.
  • Helpers (bash or zsh):
R() { node apps/review-desktop/scripts/e2e/remote/remote.mjs "$@"; }
export WB_TEST_RUN=manual-$$                  # before the first `R up`
S() { ssh -F /tmp/wbt.$WB_TEST_RUN/ssh_config "$@"; }   # host aliases are wb-test-<name>
H=/tmp/wb-home-$WB_TEST_RUN                   # isolated Desktop home
mkdir -p $H/review-desktop/state/user-data/User
echo '{"review.experimental.remoteHosts.enabled": true}' > $H/review-desktop/state/user-data/User/settings.json
awk '/createRemoteReview = String.raw`/{f=1;next} /^`;/{f=0} f' apps/review-desktop/scripts/e2e/journeys/remote-host.mjs > /tmp/wb-review.sh
sed -e 's/open\\":false/open\\":true/' -e 's/wbrepo/wbrepo2/g' /tmp/wb-review.sh > /tmp/wb-push.sh
edit() { printf '{"sessionId":"%s","edit":{"type":"insert","content":{"type":"markdown","markdown":"%s"}}}' "$2" "$3" | S "$1" 'whiteboard api session_edit -'; }
  • Launch (dev build only; a packaged build ignores both env vars): DEV_REVIEW_HOME=$H DEV_FAST_REVIEW_SSH_CONFIG=/tmp/wbt.$WB_TEST_RUN/ssh_config pnpm dev (prefix DEV_FAST_REVIEW_DESKTOP_BACKGROUND=1 to keep it from taking focus).
  • Desktop API: D=$(ls $H/review-desktop/instances/dev-*.json); URL=$(node -p "require('$D').url"); TOK=$(node -p "require('$D').token"); api() { curl -s -H "x-review-token: $TOK" "$URL$1"; }
  • A remote review: ID=$(S wb-test-a 'bash -s -- Remote-order' < /tmp/wb-review.sh | head -1) (repo ~/wbrepo, review "Remote-order" with a prose line and a code peek of f.ts). /tmp/wb-push.sh is the same with open: true in ~/wbrepo2.
  • Settings: ⌘, → region Remote hosts → type the alias in SSH alias → Add.
  • Fork unit tests: (cd apps/review-desktop && TSX_TSCONFIG_PATH=tsconfig.test.json node --import tsx --test --test-force-exit <files>). Package tests: pnpm --filter @dev.fast/whiteboard test <files>.
  • Journeys: stage a runtime per apps/review-desktop/scripts/e2e/TESTING.md ("Staging the runtime"), then node apps/review-desktop/scripts/e2e/run.mjs --runtime "$REVIEW_E2E_RUNTIME" --journey <name>.
  • The harness has pause/resume (there is no unpause).
  • Cleanup, every plan: quit Desktop first (its ssh masters count as leftovers), then R down --all; R verify-clean; rm -rf $H /tmp/wb-*.sh. Without an aws sso login session verify-clean also prints AWS could not be checked and exits 1; no other line may appear.

@thesiti92
thesiti92 added this pull request to stack #943 October 5, 2026 19:37
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from c2ef751 to ee2a783 Compare October 5, 2026 19:38
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch 2 times, most recently from 6437262 to a845e8c Compare October 5, 2026 20:19
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from a845e8c to c03c240 Compare October 5, 2026 20:34
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch 2 times, most recently from 37fd82d to c03c240 Compare October 5, 2026 20:41
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from c03c240 to f94f9ee Compare October 5, 2026 21:24
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from f94f9ee to 2092b59 Compare October 5, 2026 21:38
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 2092b59 to dd8c379 Compare October 5, 2026 21:47
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from dd8c379 to 4c9ade0 Compare October 5, 2026 23:08
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 4c9ade0 to 0515a89 Compare October 6, 2026 01:08
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 0515a89 to 915abf7 Compare October 6, 2026 01:58
@thesiti92 thesiti92 changed the title Guard a Source window bound to a remote host Resolve and configure Source windows for remote hosts Oct 6, 2026
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 915abf7 to 45a5e72 Compare October 6, 2026 02:46
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 45a5e72 to 13435fb Compare October 6, 2026 03:46
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 13435fb to bd3c517 Compare October 6, 2026 15:57
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from bd3c517 to 3144c17 Compare October 6, 2026 16:06
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 3144c17 to 0b48fa4 Compare October 6, 2026 16:16
…aves the setting

Main answers getRemoteHostState from the gateway's list, and closes the
whiteboard+ windows of a machine once no alias in the setting serves it.

Agent-Session: 01a10c6b-6286-7d63-bec6-b36570f309dc
Agent-Session: 459ae7ec-7302-42c5-b473-4e315a7e4e19
Agent-Session: fe2ac599-fe10-4bdd-a496-a121682ac842
Agent-Session: c7d5d811-b851-4c36-93a4-ea2325ac973a
Agent-Session: 01a10cab-5911-7c00-92f4-5e3404373ba2
Agent-Session: 17be59a9-37ae-45bc-ad47-3cdb1660c6c2
Agent-Session: 0742d3f8-2ac6-4fee-8102-c6e930f316ad
Agent-Session: 01a10cc6-7bb1-7652-8fe2-f99e54e4d14e
Agent-Session: bc41ade8-aab1-4279-b31a-ea472fcfaacc
Agent-Session: 01a10d6d-cc61-7a60-8be6-0d3d48878694
Agent-Session: 96eed70a-4af6-4249-a91d-8064746610b6
Agent-Session: 04f92d25-41e1-4ba0-aef1-7a1a1d409286
Agent-Session: 01a10d75-7d32-7f11-8d5a-7aa1c81b5390
Agent-Session: 01a10db4-61fc-7181-82a9-ac2de659fb25
Agent-Session: 8a675162-2f63-4f2c-8be7-66b7ae4cdd6a
Agent-Session: a5134983-fbca-42d2-ac6c-fe14cf3ce20e
Agent-Session: 01a0fd55-7d25-70c3-bf87-46cdb881d91e
Agent-Session: 0d820415-6c71-402c-97ca-ee76e5dcb9c6
Agent-Session: 9c8a2d13-4198-4d4b-bf1d-4de6fccd0f19
Agent-Session: 99df4638-b570-4eeb-b115-0311294ee04d
Agent-Session: c155cff4-ccd6-416d-a2e3-f65113f2d163
Agent-Session: edffabb0-c704-439a-bf69-7b366f2f332d
Agent-Session: 13cd2035-0029-45cb-a2c9-65f0c01b6460
Agent-Session: e9b9e23e-de55-4291-9391-cd234f736397
Agent-Session: 5368a6f5-df0c-4411-8eec-4b9cccbfbef0
Agent-Session: f086ac47-f054-41fb-8279-be4df7aa2dee
Agent-Session: 7633c50b-998d-4b1e-8ca2-ffb350a26066
Agent-Session: 3a3376c5-3f72-46df-930c-a66d5c3bcce5
The resolver asks main for the host's forward on each resolve and waits
while the host connects or moves. `reloadWhenOnline` reloads a window
once an offline host is back.

Agent-Session: 01a10c6b-6286-7d63-bec6-b36570f309dc
Agent-Session: 459ae7ec-7302-42c5-b473-4e315a7e4e19
Agent-Session: fe2ac599-fe10-4bdd-a496-a121682ac842
Agent-Session: c7d5d811-b851-4c36-93a4-ea2325ac973a
Agent-Session: 01a10cab-5911-7c00-92f4-5e3404373ba2
Agent-Session: 17be59a9-37ae-45bc-ad47-3cdb1660c6c2
Agent-Session: 0742d3f8-2ac6-4fee-8102-c6e930f316ad
Agent-Session: 01a10cc6-7bb1-7652-8fe2-f99e54e4d14e
Agent-Session: bc41ade8-aab1-4279-b31a-ea472fcfaacc
Agent-Session: 01a10d6d-cc61-7a60-8be6-0d3d48878694
Agent-Session: 96eed70a-4af6-4249-a91d-8064746610b6
Agent-Session: 04f92d25-41e1-4ba0-aef1-7a1a1d409286
Agent-Session: 01a10d75-7d32-7f11-8d5a-7aa1c81b5390
Agent-Session: 01a10db4-61fc-7181-82a9-ac2de659fb25
Agent-Session: 8a675162-2f63-4f2c-8be7-66b7ae4cdd6a
Agent-Session: a5134983-fbca-42d2-ac6c-fe14cf3ce20e
Agent-Session: 01a0fd55-7d25-70c3-bf87-46cdb881d91e
Agent-Session: 0d820415-6c71-402c-97ca-ee76e5dcb9c6
Agent-Session: 9c8a2d13-4198-4d4b-bf1d-4de6fccd0f19
Agent-Session: 99df4638-b570-4eeb-b115-0311294ee04d
Agent-Session: c155cff4-ccd6-416d-a2e3-f65113f2d163
Agent-Session: edffabb0-c704-439a-bf69-7b366f2f332d
Agent-Session: 13cd2035-0029-45cb-a2c9-65f0c01b6460
Agent-Session: e9b9e23e-de55-4291-9391-cd234f736397
Agent-Session: 5368a6f5-df0c-4411-8eec-4b9cccbfbef0
Agent-Session: f086ac47-f054-41fb-8279-be4df7aa2dee
Agent-Session: 7633c50b-998d-4b1e-8ca2-ffb350a26066
Agent-Session: 3a3376c5-3f72-46df-930c-a66d5c3bcce5
A configuration layer over a workspace service keeps the read-only rule
pinned against the workspace file, the checkout's folder settings and a
Whiteboard host's machine settings, and titles the window with its review
and side. Every other setting layers as upstream's.

Agent-Session: 01a10c6b-6286-7d63-bec6-b36570f309dc
Agent-Session: 459ae7ec-7302-42c5-b473-4e315a7e4e19
Agent-Session: fe2ac599-fe10-4bdd-a496-a121682ac842
Agent-Session: c7d5d811-b851-4c36-93a4-ea2325ac973a
Agent-Session: 01a10cab-5911-7c00-92f4-5e3404373ba2
Agent-Session: 17be59a9-37ae-45bc-ad47-3cdb1660c6c2
Agent-Session: 0742d3f8-2ac6-4fee-8102-c6e930f316ad
Agent-Session: 01a10cc6-7bb1-7652-8fe2-f99e54e4d14e
Agent-Session: bc41ade8-aab1-4279-b31a-ea472fcfaacc
Agent-Session: 01a10d6d-cc61-7a60-8be6-0d3d48878694
Agent-Session: 96eed70a-4af6-4249-a91d-8064746610b6
Agent-Session: 04f92d25-41e1-4ba0-aef1-7a1a1d409286
Agent-Session: 01a10d75-7d32-7f11-8d5a-7aa1c81b5390
Agent-Session: 01a10db4-61fc-7181-82a9-ac2de659fb25
Agent-Session: 8a675162-2f63-4f2c-8be7-66b7ae4cdd6a
Agent-Session: a5134983-fbca-42d2-ac6c-fe14cf3ce20e
Agent-Session: 01a0fd55-7d25-70c3-bf87-46cdb881d91e
Agent-Session: 0d820415-6c71-402c-97ca-ee76e5dcb9c6
Agent-Session: 9c8a2d13-4198-4d4b-bf1d-4de6fccd0f19
Agent-Session: 99df4638-b570-4eeb-b115-0311294ee04d
Agent-Session: c155cff4-ccd6-416d-a2e3-f65113f2d163
Agent-Session: edffabb0-c704-439a-bf69-7b366f2f332d
Agent-Session: 13cd2035-0029-45cb-a2c9-65f0c01b6460
Agent-Session: e9b9e23e-de55-4291-9391-cd234f736397
Agent-Session: 5368a6f5-df0c-4411-8eec-4b9cccbfbef0
Agent-Session: f086ac47-f054-41fb-8279-be4df7aa2dee
Agent-Session: 7633c50b-998d-4b1e-8ca2-ffb350a26066
Agent-Session: 3a3376c5-3f72-46df-930c-a66d5c3bcce5
A Source window resolves whiteboard+ authorities through the resolver
and reloads once an offline host is back. Its DesktopMain wraps the
workspace service in the Source window settings, and the new openWindow
option `reviewSourceTitle` sets the window's title.

Agent-Session: 01a10c6b-6286-7d63-bec6-b36570f309dc
Agent-Session: 459ae7ec-7302-42c5-b473-4e315a7e4e19
Agent-Session: fe2ac599-fe10-4bdd-a496-a121682ac842
Agent-Session: c7d5d811-b851-4c36-93a4-ea2325ac973a
Agent-Session: 01a10cab-5911-7c00-92f4-5e3404373ba2
Agent-Session: 17be59a9-37ae-45bc-ad47-3cdb1660c6c2
Agent-Session: 0742d3f8-2ac6-4fee-8102-c6e930f316ad
Agent-Session: 01a10cc6-7bb1-7652-8fe2-f99e54e4d14e
Agent-Session: bc41ade8-aab1-4279-b31a-ea472fcfaacc
Agent-Session: 01a10d6d-cc61-7a60-8be6-0d3d48878694
Agent-Session: 96eed70a-4af6-4249-a91d-8064746610b6
Agent-Session: 04f92d25-41e1-4ba0-aef1-7a1a1d409286
Agent-Session: 01a10d75-7d32-7f11-8d5a-7aa1c81b5390
Agent-Session: 01a10db4-61fc-7181-82a9-ac2de659fb25
Agent-Session: 8a675162-2f63-4f2c-8be7-66b7ae4cdd6a
Agent-Session: a5134983-fbca-42d2-ac6c-fe14cf3ce20e
Agent-Session: 01a0fd55-7d25-70c3-bf87-46cdb881d91e
Agent-Session: 0d820415-6c71-402c-97ca-ee76e5dcb9c6
Agent-Session: 9c8a2d13-4198-4d4b-bf1d-4de6fccd0f19
Agent-Session: 99df4638-b570-4eeb-b115-0311294ee04d
Agent-Session: c155cff4-ccd6-416d-a2e3-f65113f2d163
Agent-Session: edffabb0-c704-439a-bf69-7b366f2f332d
Agent-Session: 13cd2035-0029-45cb-a2c9-65f0c01b6460
Agent-Session: e9b9e23e-de55-4291-9391-cd234f736397
Agent-Session: 5368a6f5-df0c-4411-8eec-4b9cccbfbef0
Agent-Session: f086ac47-f054-41fb-8279-be4df7aa2dee
Agent-Session: 7633c50b-998d-4b1e-8ca2-ffb350a26066
Agent-Session: 3a3376c5-3f72-46df-930c-a66d5c3bcce5
@thesiti92
thesiti92 force-pushed the remote/8-source-windows-trust branch from 0b48fa4 to ae59e6b Compare October 6, 2026 17:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant