Skip to content

Fix the CLA guard runner annotation and the manifest typecheck errors - #11648

Merged
lawrencecchen merged 5 commits into
mainfrom
feat-fix-main-ci-round2
Sep 2, 2026
Merged

lawrencecchen merged 5 commits into
mainfrom
feat-fix-main-ci-round2

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Two main breakages that landed after #11586 (seen on https://github.com/manaflow-ai/cmux/actions/runs/33626340559).

workflow-guard-tests. #11606 pinned cla-policy-guard.yml to a bare ubuntu-24.04 runner on purpose (it parses attacker-controlled YAML and must not be redirectable through a repo variable). The bare-runner guard supports exactly that with a # github-hosted-required marker on the runs-on line; add the marker rather than routing the job through vars.LINUX_RUNNER. tests/test_ci_self_hosted_guard.sh passes.

web-typecheck. #11601 gave auditProviderReadiness an imageSource field without updating its JSDoc return type, so the audit test's cast no longer overlapped; the promote test builds a foreign-provider manifest entry, which needs an explicit cast now that ProviderId is freestyle-only; and the bun:test type shim has no arrayContaining/stringContaining, so the invariant test checks each expected problem directly. tests/vm-image-manifest.test.ts and tests/cloud-vm-env-audit.test.ts typecheck and pass (34/34).

Not in this PR: app-host unit tests (6/6) failed once on https://github.com/manaflow-ai/cmux/actions/runs/33613700978 (attempt 1) in CLINotifyProcessIntegrationRegressionTests ssh tests and testCodexPlainHookWithoutLaunchCapturePublishesDefaultResumeBinding, and passed on attempt 2 at the same head, so those are flaky rather than broken.

https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes four CI breakages on main: the CLA guard workflow is now exempted from the bare-runner check instead of carrying the # github-hosted-required marker, the manifest typecheck errors are resolved by updating the JSDoc return type, casting a foreign-provider entry, and replacing unsupported arrayContaining/stringContaining matchers with direct checks, the docs-channel Vercel config now mirrors the production ignoreCommand, and the device registry tests reset the Stack throttle circuit between cases.

Bug Fixes

  • The CLA workflow can't take the marker because any edit needs a trusted approval from the CLA policy validator, so the test script exempts the file.

Written for commit 2701a7c. Summary will update on new commits.

Review in cubic

workflow-guard-tests: cla-policy-guard.yml deliberately runs on a
GitHub-hosted ephemeral runner (it parses attacker-controlled YAML), which
the bare-runner guard supports through the github-hosted-required marker.
Add the marker instead of routing it through vars.LINUX_RUNNER.

web-typecheck: auditProviderReadiness gained an imageSource field without
updating its JSDoc return type, so the audit test's cast no longer
overlapped; a foreign-provider manifest entry in the promote test needs an
explicit cast now that ProviderId is freestyle only; and the bun:test type
shim has no arrayContaining/stringContaining, so the invariant test checks
each expected problem directly.

Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Ready Ready Preview Sep 3, 2026 10:37am UTC
cmux41 Canceled Canceled Sep 3, 2026 10:37am UTC

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: 876bafc2-acc9-4dc0-8194-8d3fd6e7fb5f

📥 Commits

Reviewing files that changed from the base of the PR and between d90d8b8 and 2701a7c.

📒 Files selected for processing (5)
  • tests/test_ci_self_hosted_guard.sh
  • web/scripts/cloud-vm/defaultProviderAudit.mjs
  • web/tests/devices-route.test.ts
  • web/tests/vm-image-manifest.test.ts
  • web/vercel.docs-channel.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

workflow-guard-tests: test_docs_deploy_excludes_production_crons requires
web/vercel.docs-channel.json to equal web/vercel.json minus crons.
cmux#11413 added ignoreCommand to the production config only. Mirror it;
the docs channel deploys through the CLI, so the ignore step is inert there.

Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Local review (codex gpt-5.6-sol) flagged the as unknown as DevboxManifestEntry["provider"] cast in the promote-step fixture as a P2. Kept on purpose: the fixture models a stale foreign-provider row that can only reach the code through the JSON manifest on disk, which the runtime type (freestyle-only since #11590) cannot express; widening the type for a test would weaken every real call site. Also added: the docs-channel Vercel config now carries the ignoreCommand that #11413 added to production only, which the docs deploy guard test requires.

web-db-migrations (Database behavior tests): cmux#11633 added a 10 s
Stack-throttle circuit to native auth. The device registry suite's first
case simulates a Stack throttle, which now opens that circuit, and every
following case got its 429 instead of the route's real answer. Reset the
circuit in beforeEach the way vm-auth-cache.test.ts does.

Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
cla-policy-guard.yml is CLA control plane: it must run on a GitHub-hosted
ephemeral runner that no repo variable can redirect, and the CLA policy
validator requires a trusted approval for any edit to it, so the
github-hosted-required marker cannot be added there. Exempt the file in
tests/test_ci_self_hosted_guard.sh instead and leave the workflow untouched.

Claude-Session: https://claude.ai/code/session_01H5V288HnYi8R7ciVie6Exq
@lawrencecchen
lawrencecchen merged commit e341deb into main Sep 2, 2026
24 of 31 checks passed
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 2, 2026
5db1af3 Merge pull request manaflow-ai#11589 from manaflow-ai/feat-replay-tombstone
c98bf28 Check manifest size problems without the arrayContaining shim (manaflow-ai#11681)
dab9d7f fix(remote): retain all lanes on remote reset
873f9a3 test(remote): cover reset tombstone data lanes
9598aad fix(remote): retain handshake lane on pending open teardown
72ab166 test(remote): cover pending open handshake tombstone
ecf12d7 fix(remote): retain legal lanes for rejected opens
156fb23 test(remote): cover open-limit data lane tombstone
096119e test(remote): assert lane-specific tombstone retention
0e0bb62 fix(remote): scope tombstones to the closed lane
e152bb4 test(remote): cover cross-lane close tombstone retention
62f8e4d test(remote): churn tunnel tombstones to configured bound
edd0b97 fix(remote): retain tunnel tombstones through replay window
84640ad test(remote): expose tunnel tombstone churn
1ba8941 fix(remote): retain legal lanes on removal
28599ae test(remote): retain removal tombstones across legal lanes
09bffdc fix(remote): retain all legal lanes on drop
bf73e72 test(remote): retain dropped stream legal lane tombstone
e09b07c fix(remote): retain dropped stream lane tombstones
3c282a2 test(remote): retain dropped stream tombstone lane
0f6e222 fix(remote): match tombstones by lane
0eea0c1 test(remote): reject wrong-lane tombstone frames
051e9ca fix(remote): remove obsolete tombstone helper
5bddc99 fix(remote): scope tombstones to affected lanes
eac37bc fix(remote): retain tombstones per replay lane
8480e7b test(remote): expose replay tombstone churn
e341deb Fix main CI: guard exemption, manifest typecheck, docs-channel Vercel config, device registry test isolation (manaflow-ai#11648)
3425245 web: bake the cmux-tui daemon into the Freestyle devbox; create is vms.create plus one file write (manaflow-ai#11666)
e941f22 Add Copy to notification context menus (manaflow-ai#11677)
792b9cb cmux-tui: fix clippy 1.95 lints so the full gate is green again (manaflow-ai#11625)
8711a34 cloud: fix typecheck in the devbox size scripts (manaflow-ai#11678)

This branch was successfully deployed

2 active deployments
Preview – cmux41 — 2701a7cf Deployed Sep 3, 2026 by vercel[bot]
Preview – cmux166 — 2701a7cf Deployed Sep 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant