fix(desktop): refuse same-home port fallback - #9003
Open
maxibotstef wants to merge 1 commit into
Open
maxibotstef wants to merge 1 commit into
maxibotstef wants to merge 1 commit into
Conversation
4 tasks
Contributor
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This changes packaged desktop startup behavior for the default port, replacing automatic fallback with a fatal startup error before the backend is spawned. Because the product default behavior changes and startup is gated by the port probe, the change merits human review. You can add or adjust custom eligibility rules. Learn more. |
2 tasks
2 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Changed
Packaged Desktop startup now uses the default backend port (
3773) or fails before spawning the embedded server. It no longer scans to3774+while retaining the same T3 home.An explicitly configured
T3CODE_PORTstill behaves as before.Why
If an older/background T3 backend already owns
3773, the sequential scan currently launches another backend on3774against the samestate.sqlite, settings, and provider state. The second backend appears healthy but creates split-brain writers; with Codex single-writer thread persistence this can surface asthread <id> already has an active writer.Failing before
primaryBackend.startcloses that Desktop-specific path without requiring process killing, database repair, or a speculative attach/auth lifecycle. The error explains that automatic fallback is intentionally refused and names the safe choices.This is the small Desktop boundary from #6097. Generic server-level ownership remains separate in #8442/#8960.
Fixes #6097.
UI Changes
Only the existing fatal-startup error box changes: when default port
3773is occupied, it now explains that T3 will not start a second same-home backend on a fallback port. No ordinary-startup UI changes.Verification
pnpm exec vp test run apps/desktop/src/app/DesktopAppErrors.test.ts— 5 passedpnpm exec vp run --filter @t3tools/desktop typecheckGO, no findingsChecklist
Scope check: no attach-to-existing flow, server lock, provider lifecycle, or live-state change is included.
Model: GPT-5.6 Sol
Harness: T3 Code / Codex
Note
Medium Risk
Changes desktop startup behavior when the default port is busy—users see a fatal error instead of a silent fallback that could cause split-brain SQLite writers—but scope is limited to port resolution with explicit
T3CODE_PORTunchanged.Overview
Packaged desktop startup no longer scans from
3773upward for a free backend port. When noT3CODE_PORTis set, it only uses the default port or fails fast if that port cannot bind on the usual probe hosts.DesktopBackendPortUnavailableErroris replaced byDesktopBackendPortInUseError, with a clearer multi-line message that explains T3 Code will not start a second backend on a fallback port against the same data directory. Bootstrap logging drops the “selected via sequential scan” path and only distinguishes configured vs default port.resolveDesktopBackendPortis exported for testing.DesktopAppErrors.test.tsadds Effect tests with a stubNetServiceto cover default-port success, occupied-port refusal (probes only3773, no scan), and explicit port passthrough.Reviewed by Cursor Bugbot for commit 6a426bd. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Refuse same-home port fallback in
resolveDesktopBackendPortresolveDesktopBackendPortnow probes onlyDEFAULT_DESKTOP_BACKEND_PORTacrossDESKTOP_BACKEND_PORT_PROBE_HOSTS; if any host cannot bind, it throwsDesktopBackendPortInUseErrorwith{ port, hosts }instead of scanning for an alternative port.DesktopBackendPortUnavailableError(which carried{ startPort, maxPort, hosts }) withDesktopBackendPortInUseError(carrying{ port, hosts }), whose message advises stopping the running server or changingT3CODE_HOME.MAX_TCP_PORTconstant and theselectedByScanreturn field; updatesdesktop.bootstraplogging accordingly.{ port, selectedByScan }or catchingDesktopBackendPortUnavailableErrorwill break — in-tree usages in DesktopApp.ts and DesktopAppErrors.test.ts are updated, but out-of-tree consumers are not.Macroscope summarized 6a426bd.