Skip to content

🤖 Bash AI proxy SSH forwards: lifecycle follow-ups from #5774 review #5796

Description

@ThomasK33

Problem

Codex review of #5774 (SSH and Coder reverse forwards for the bash AI proxy) reached the six-round review cap. These non-blocking findings on its final head were deferred, not fixed:

  1. Reconnect without a new turn. When an owned SSH connection drops, the forward is only marked closed. ensure() runs only on the next envFor() (a new agent turn) or at startup, so a running remote job loses its proxy route until then. A transient restore failure has the same gap.
  2. Turning the switch off does not close idle forwards at once. updateBashAiProxyEnabled only saves the config. The service closes forwards on the next envFor() or proxy request. Until then the dedicated SSH connection and the remote listener stay open, but the proxy refuses every call with 503, so nothing is spent.
  3. Shutdown during a slow OpenSSH setup. stop() waits at most 1 s, but openReverseForward() can wait up to 20 s for readiness, so a process exit in that window can orphan the ssh master.
  4. A workspace that changed SSH host. Traffic refreshes usedAt only for the first host entry that lists the workspace, so the newer host entry can expire after 7 days while a job on it still runs.
  5. Concurrent hourly usedAt refreshes for one host each take the lock and fsync, instead of one coalesced write.

Expected

  1. Closed or failed forwards that persisted state still needs are re-established in the background, with backoff.
  2. The setting update tells BashAiProxyService to close owned forwards.
  3. Shutdown keeps a close handle for setups in flight.
  4. Traffic refreshes every host entry for the workspace.
  5. One refresh per host is in flight at a time.

Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $66.18

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions