Repository navigation
Fix the CLA guard runner annotation and the manifest typecheck errors - #11648
Conversation
workflow-guard-tests: cla-policy-guard.yml deliberately runs on a GitHub-hosted ephemeral runner (it parses attacker-controlled YAML), which the bare-runner guard supports through the github-hosted-required marker. Add the marker instead of routing it through vars.LINUX_RUNNER. web-typecheck: auditProviderReadiness gained an imageSource field without updating its JSDoc return type, so the audit test's cast no longer overlapped; a foreign-provider manifest entry in the promote test needs an explicit cast now that ProviderId is freestyle only; and the bun:test type shim has no arrayContaining/stringContaining, so the invariant test checks each expected problem directly. Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
|
Warning Review limit reachedNext included review available in 11 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
workflow-guard-tests: test_docs_deploy_excludes_production_crons requires web/vercel.docs-channel.json to equal web/vercel.json minus crons. cmux#11413 added ignoreCommand to the production config only. Mirror it; the docs channel deploys through the CLI, so the ignore step is inert there. Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
|
Local review (codex gpt-5.6-sol) flagged the |
web-db-migrations (Database behavior tests): cmux#11633 added a 10 s Stack-throttle circuit to native auth. The device registry suite's first case simulates a Stack throttle, which now opens that circuit, and every following case got its 429 instead of the route's real answer. Reset the circuit in beforeEach the way vm-auth-cache.test.ts does. Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
cla-policy-guard.yml is CLA control plane: it must run on a GitHub-hosted ephemeral runner that no repo variable can redirect, and the CLA policy validator requires a trusted approval for any edit to it, so the github-hosted-required marker cannot be added there. Exempt the file in tests/test_ci_self_hosted_guard.sh instead and leave the workflow untouched. Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
5db1af3 Merge pull request manaflow-ai#11589 from manaflow-ai/feat-replay-tombstone c98bf28 Check manifest size problems without the arrayContaining shim (manaflow-ai#11681) dab9d7f fix(remote): retain all lanes on remote reset 873f9a3 test(remote): cover reset tombstone data lanes 9598aad fix(remote): retain handshake lane on pending open teardown 72ab166 test(remote): cover pending open handshake tombstone ecf12d7 fix(remote): retain legal lanes for rejected opens 156fb23 test(remote): cover open-limit data lane tombstone 096119e test(remote): assert lane-specific tombstone retention 0e0bb62 fix(remote): scope tombstones to the closed lane e152bb4 test(remote): cover cross-lane close tombstone retention 62f8e4d test(remote): churn tunnel tombstones to configured bound edd0b97 fix(remote): retain tunnel tombstones through replay window 84640ad test(remote): expose tunnel tombstone churn 1ba8941 fix(remote): retain legal lanes on removal 28599ae test(remote): retain removal tombstones across legal lanes 09bffdc fix(remote): retain all legal lanes on drop bf73e72 test(remote): retain dropped stream legal lane tombstone e09b07c fix(remote): retain dropped stream lane tombstones 3c282a2 test(remote): retain dropped stream tombstone lane 0f6e222 fix(remote): match tombstones by lane 0eea0c1 test(remote): reject wrong-lane tombstone frames 051e9ca fix(remote): remove obsolete tombstone helper 5bddc99 fix(remote): scope tombstones to affected lanes eac37bc fix(remote): retain tombstones per replay lane 8480e7b test(remote): expose replay tombstone churn e341deb Fix main CI: guard exemption, manifest typecheck, docs-channel Vercel config, device registry test isolation (manaflow-ai#11648) 3425245 web: bake the cmux-tui daemon into the Freestyle devbox; create is vms.create plus one file write (manaflow-ai#11666) e941f22 Add Copy to notification context menus (manaflow-ai#11677) 792b9cb cmux-tui: fix clippy 1.95 lints so the full gate is green again (manaflow-ai#11625) 8711a34 cloud: fix typecheck in the devbox size scripts (manaflow-ai#11678)
Two
mainbreakages that landed after #11586 (seen on https://github.com/manaflow-ai/cmux/actions/runs/33626340559).workflow-guard-tests. #11606 pinned
cla-policy-guard.ymlto a bareubuntu-24.04runner on purpose (it parses attacker-controlled YAML and must not be redirectable through a repo variable). The bare-runner guard supports exactly that with a# github-hosted-requiredmarker on theruns-online; add the marker rather than routing the job throughvars.LINUX_RUNNER.tests/test_ci_self_hosted_guard.shpasses.web-typecheck. #11601 gave
auditProviderReadinessanimageSourcefield without updating its JSDoc return type, so the audit test's cast no longer overlapped; the promote test builds a foreign-provider manifest entry, which needs an explicit cast now thatProviderIdis freestyle-only; and the bun:test type shim has noarrayContaining/stringContaining, so the invariant test checks each expected problem directly.tests/vm-image-manifest.test.tsandtests/cloud-vm-env-audit.test.tstypecheck and pass (34/34).Not in this PR:
app-host unit tests (6/6)failed once on https://github.com/manaflow-ai/cmux/actions/runs/33613700978 (attempt 1) inCLINotifyProcessIntegrationRegressionTestsssh tests andtestCodexPlainHookWithoutLaunchCapturePublishesDefaultResumeBinding, and passed on attempt 2 at the same head, so those are flaky rather than broken.https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes four CI breakages on
main: the CLA guard workflow is now exempted from the bare-runner check instead of carrying the# github-hosted-requiredmarker, the manifest typecheck errors are resolved by updating the JSDoc return type, casting a foreign-provider entry, and replacing unsupportedarrayContaining/stringContainingmatchers with direct checks, the docs-channel Vercel config now mirrors the productionignoreCommand, and the device registry tests reset the Stack throttle circuit between cases.Bug Fixes
Written for commit 2701a7c. Summary will update on new commits.