Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .github/workflows/reload-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,14 @@ on:
required: false
default: ""
type: string
backend_mode:
description: "Backend for macOS: remote requires backend_url; local requires your own local dev server"
required: false
default: remote
type: choice
options:
- remote
- local

# Surface tag/platform/nonce in the run title so the dispatcher can match its run
# by the nonce it passed (gh workflow run does not return a run id).
Expand All @@ -70,6 +78,7 @@ jobs:
CMUX_SKIP_ZIG_BUILD: "1"
SWIFTPM_MIRROR_CONFIG: ${{ github.workspace }}/config/swiftpm/mirrors.json
CMUX_DEV_BACKEND_URL: ${{ inputs.backend_url }}
CMUX_DEV_BACKEND_MODE: ${{ inputs.backend_mode || 'remote' }}
# A degraded cache must lose to a cold build instead of stalling this
# latency-sensitive lane for actions/cache's ten-minute default.
SEGMENT_DOWNLOAD_TIMEOUT_MINS: "2"
Expand All @@ -80,6 +89,22 @@ jobs:
with:
ref: ${{ inputs.ref || github.ref }}
submodules: recursive
persist-credentials: false

- name: Validate macOS backend selection
if: ${{ inputs.platform == 'macos' }}
env:
BUILD_TAG: ${{ inputs.tag }}
run: |
set -euo pipefail
if [[ "$CMUX_DEV_BACKEND_MODE" = remote && -z "$CMUX_DEV_BACKEND_URL" ]]; then
echo "::error::Set backend_url to the registered dev backend, or explicitly select backend_mode=local for a local dev server. Hosted runners cannot provision the HQ backend."
exit 1
fi
if [[ -f scripts/lib/dev-backend-origin.sh ]]; then
source scripts/lib/dev-backend-origin.sh
cmux_resolve_tagged_backend "$BUILD_TAG" "$GITHUB_WORKSPACE" "http://localhost:3777" >/dev/null
fi
Comment on lines +104 to +107

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Validation Silently Skips

When inputs.ref selects a revision without scripts/lib/dev-backend-origin.sh, this step succeeds without validating the backend selection. The tagged build then continues through setup before reload.sh fails while sourcing the missing helper, so the intended early validation becomes a later failure with less useful guidance. Require the helper or report an actionable error in this step.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The conditional preserves builds of historical source refs. I checked the parent of the commit that introduced this helper: reload.sh at e42dc540df directly uses its local dev origin and never sources dev-backend-origin.sh. Its absence therefore does not cause the later missing-helper failure described here. The remote-URL presence check is unconditional; revisions that implement the backend resolver additionally run its URL/mode validation. Requiring that newer helper for every historical ref would reject otherwise buildable legacy sources. Keeping this compatibility path; no source change for this finding.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You’re right. The historical reload.sh at e42dc540df does not source dev-backend-origin.sh, so its absence cannot cause the later failure described in the comment. The unconditional remote-URL guard still enforces the new hosted-runner policy, while resolver validation is correctly limited to refs that contain the helper. I’m withdrawing this finding; no source change is needed.


# Self-hosted runners reuse their workspaces. The checkout action's
# cleanup is not sufficient when a previous job leaves generated source
Expand Down
Loading