Repository navigation
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit f170546. Configure here.
| } | ||
| req.OverlaySize = *img.SizeBytes // Reserve the writable boot disk, not a Linux overlay. | ||
| req.SkipGuestAgent = true | ||
| req.SkipGuestAgent = req.SkipGuestAgent || !img.MacOS.GuestAgent |
There was a problem hiding this comment.
Desktop capability tied to system agent
High Severity
Instance create sets SkipGuestAgent whenever the image omits system guest_agent, and desktop routes then treat that flag as a hard disable. A template that only declares desktop_agent_uid therefore stores SkipGuestAgent and gets 501 on every CDP call, even though the two capabilities are documented as independent and guestAgentEnabled already ignores undeclared system agents without this flag.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit f170546. Configure here.
| cancel() | ||
| if err != nil { | ||
| http.Error(w, "selected desktop agent unavailable or incompatible", 503) | ||
| return |
There was a problem hiding this comment.
Start maps session-not-ready to 503
Medium Severity
POST /cdp/start treats every failed Probe as 503 agent-incompatible. The guest already returns 409 when the Aqua session is not ready, but Probe only checks for HTTP 200, so a logged-out or non-GUI console is reported as an unavailable desktop agent.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit f170546. Configure here.
f170546 to
0634b40
Compare
|
Real isolated macOS guest QA passed (reviewed combined PR1–3 + PR4 patches): manually deployed current Darwin shared binary as a nonroot gui/501 Aqua QA LaunchAgent on native2223. Opted desktop UID501 into only the private QA instance metadata, configured trusted loopback desktop origin, and exercised normal authenticated API CDP start/discovery/browser WebSocket/navigation/evaluation/PNG screenshot/reconnect. Handshake confirmed Darwin/arm64, UID/console501, GUI session and owned Chrome155.0.8059.40. Browser WebSocket URL stayed unchanged after viewer socket close, and authenticated reconnect worked. Killed only Chrome PID proven to match the fixed binary and private Hypeman profile: discovery returned409 until explicit start200, then the full CDP test passed again. Live unauthenticated401/read-only403/untrusted-Origin403 admission passed. Empty origin correctly disables routes503 and body-bearing start rejects400. This is manual isolated deployment/capability opt-in, not automatic image provisioning; screenshot is CDP browser rendering, not OS capture/input/TCC/viewer resize. Root system capability remained disabled. Original guest/storage/API untouched; QA VM/API stopped and slot released. Browser restart ownership remains a separate gate. |
e9fa76d to
a1ed358
Compare
0634b40 to
8ba7ec6
Compare
a1ed358 to
243ce9a
Compare
|
Simplification update at 8ba7ec6: guest NewCDPForwarder carries fixed-upstream discovery unchanged; authenticated host NewCDPProxy alone validates discovery and rewrites public URLs. Both retain body/path/query/encoding admission, credential/header isolation, redirect policy and fixed upstream; guest session/browser ownership remains enforced. Tests cover both discovery boundaries and two-hop WebSocket round trips. Post-restack desktop/API/agent/client/scope/config focused race suites passed 3 runs; focused CGO0 admission tests pass. No guest/VM changes or new OS capture/input/TCC/adoption proof. All PRs remain draft. This is source-level/synthetic validation, not a new live boot or production build proof. Default Codex independent review was attempted but is still blocked by authentication (HTTP401). Published atomically after checking reviewer heads with explicit per-ref force-with-lease; prior heads preserved locally. |


Stack
PR4 of the six-PR macOS integration stack; based on #500 (
feat/macos-guest-service). Restacked onto the reviewed #500 head0cf36ae; PR4 commits are now25087f7and0634b40. Reviewer process-group/timeout and readiness fixes are preserved. Keep draft. No live service or VM changes were made for this PR.Implemented
--role desktopto the shared Darwin agent, retaining the default system GuestService on 2222. The non-root desktop role serves a versioned HTTP interface on host-CID-only native vsock 2223; no privileged command bridge or guest TCP listener.desktop_agent_uidseparately from systemguest_agentcapability. Live handshake checks version, Darwin/arm64, selected UID, console/GUI-session readiness, managed browser ownership/readiness. VMM Running and root-agent readiness remain separate.macos_desktop_originconfiguration; default disabled. Never use incoming Host/Forwarded for debugger URLs. Present Origin must match configured origin. Strip API credentials/cookies/origin/arbitrary headers from both management and CDP transport.Local validation
Bounded, allowlisted test environment;
nice -n 10, GOMAXPROCS=1, GOMEMLIMIT=256MiB,-p 1.lib/desktop,lib/system/guest_agent,lib/guest,cmd/api/config,lib/scopes; focused desktop/macOS/disconnect API/instances/images/shim tests. Separate disposable combined-source QA of latest macOS guests 1/6: native VZ runtime and instance lifecycle #498–500 plus PR4-only changes also passes; macOS guests 2/6: OCI machine-image integration #499/macOS guests 3/6: Darwin shared GuestService #500 branch histories still lack the newest macOS guests 1/6: native VZ runtime and instance lifecycle #498 commits, so that combined-source result is distinguished from standalone branch validation.plutil -lint.autoreview --mode localattempted on implementation: reviewer authentication failed with 401; no independent automated review result.Remaining in this draft / explicit limitations