Problem
Codex review of #5774 (SSH and Coder reverse forwards for the bash AI proxy) reached the six-round review cap. These non-blocking findings on its final head were deferred, not fixed:
- Reconnect without a new turn. When an owned SSH connection drops, the forward is only marked closed.
ensure() runs only on the next envFor() (a new agent turn) or at startup, so a running remote job loses its proxy route until then. A transient restore failure has the same gap.
- Turning the switch off does not close idle forwards at once.
updateBashAiProxyEnabled only saves the config. The service closes forwards on the next envFor() or proxy request. Until then the dedicated SSH connection and the remote listener stay open, but the proxy refuses every call with 503, so nothing is spent.
- Shutdown during a slow OpenSSH setup.
stop() waits at most 1 s, but openReverseForward() can wait up to 20 s for readiness, so a process exit in that window can orphan the ssh master.
- A workspace that changed SSH host. Traffic refreshes
usedAt only for the first host entry that lists the workspace, so the newer host entry can expire after 7 days while a job on it still runs.
- Concurrent hourly
usedAt refreshes for one host each take the lock and fsync, instead of one coalesced write.
Expected
- Closed or failed forwards that persisted state still needs are re-established in the background, with backoff.
- The setting update tells
BashAiProxyService to close owned forwards.
- Shutdown keeps a close handle for setups in flight.
- Traffic refreshes every host entry for the workspace.
- One refresh per host is in flight at a time.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $66.18
Problem
Codex review of #5774 (SSH and Coder reverse forwards for the bash AI proxy) reached the six-round review cap. These non-blocking findings on its final head were deferred, not fixed:
ensure()runs only on the nextenvFor()(a new agent turn) or at startup, so a running remote job loses its proxy route until then. A transient restore failure has the same gap.updateBashAiProxyEnabledonly saves the config. The service closes forwards on the nextenvFor()or proxy request. Until then the dedicated SSH connection and the remote listener stay open, but the proxy refuses every call with 503, so nothing is spent.stop()waits at most 1 s, butopenReverseForward()can wait up to 20 s for readiness, so a process exit in that window can orphan thesshmaster.usedAtonly for the first host entry that lists the workspace, so the newer host entry can expire after 7 days while a job on it still runs.usedAtrefreshes for one host each take the lock and fsync, instead of one coalesced write.Expected
BashAiProxyServiceto close owned forwards.Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$66.18