From 59fb526632796f42a8b173640f84a6e32bfc21ff Mon Sep 17 00:00:00 2001 From: Leo Li Date: Sun, 20 Sep 2026 01:36:56 -0700 Subject: [PATCH 1/3] ci: preserve remote tmux mirror crash diagnostics --- .github/workflows/ci.yml | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2da6cba62abd..4ec6e01f1983 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1105,6 +1105,7 @@ jobs: done - name: Run remote tmux mirror detach and placement regressions + id: remote-tmux-mirror if: ${{ matrix.shard == fromJSON(env.CMUX_APP_HOST_FOCUSED_REGRESSION_SHARD) }} run: | # Closing a mirrored workspace must never kill the remote tmux session, @@ -1153,6 +1154,39 @@ jobs: done done + - name: Collect RemoteTmuxMirror crash diagnostics + if: ${{ failure() && steps.remote-tmux-mirror.outcome == 'failure' }} + continue-on-error: true + shell: bash + run: | + set -u + diagnostics="$RUNNER_TEMP/cmux-remote-tmux-mirror-diagnostics" + mkdir -p "$diagnostics" + + # XCTest runs with an isolated HOME. Preserve its reports before the + # always-running app-host cleanup removes that home. + if [ -n "${CMUX_APP_HOST_HOME:-}" ] && [ -d "$CMUX_APP_HOST_HOME/.local/state/cmux/crash" ]; then + cp -R "$CMUX_APP_HOST_HOME/.local/state/cmux/crash" "$diagnostics/crash-reports" || true + fi + + shopt -s nullglob + suite_logs=("$RUNNER_TEMP"/cmux-remote-tmux-mirror-*.txt) + if [ "${#suite_logs[@]}" -gt 0 ]; then + cp "${suite_logs[@]}" "$diagnostics/" || true + fi + + find "$diagnostics" -type f -print || true + + - name: Upload RemoteTmuxMirror crash diagnostics + if: ${{ failure() && steps.remote-tmux-mirror.outcome == 'failure' }} + continue-on-error: true + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: cmux-remote-tmux-mirror-diagnostics-${{ matrix.shard }}-${{ github.run_attempt }} + path: ${{ runner.temp }}/cmux-remote-tmux-mirror-diagnostics + if-no-files-found: ignore + retention-days: 7 + - name: Run browser system proxy mirror regression if: ${{ matrix.shard == fromJSON(env.CMUX_APP_HOST_FOCUSED_REGRESSION_SHARD) }} run: | From 6980f8e0f8d7fed31f5469e4feae4b9a7dc8d37c Mon Sep 17 00:00:00 2001 From: Leo Li Date: Sun, 20 Sep 2026 01:53:50 -0700 Subject: [PATCH 2/3] ci: harden remote tmux diagnostics collection --- .github/workflows/ci.yml | 32 ++++++++++++++++++++++++++++++-- 1 file changed, 30 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4ec6e01f1983..3533348f7e7b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1124,6 +1124,7 @@ jobs: # host exited, crashed, or timed out. An assertion failure never earns # a rerun, and a second crash still fails the shard. set -euo pipefail + rm -f -- "$RUNNER_TEMP"/cmux-remote-tmux-mirror-*.txt for suite in \ RemoteTmuxMirrorCloseDetachTests \ RemoteTmuxMirrorFocusPolicyTests \ @@ -1161,12 +1162,39 @@ jobs: run: | set -u diagnostics="$RUNNER_TEMP/cmux-remote-tmux-mirror-diagnostics" + rm -rf -- "$diagnostics" mkdir -p "$diagnostics" # XCTest runs with an isolated HOME. Preserve its reports before the # always-running app-host cleanup removes that home. - if [ -n "${CMUX_APP_HOST_HOME:-}" ] && [ -d "$CMUX_APP_HOST_HOME/.local/state/cmux/crash" ]; then - cp -R "$CMUX_APP_HOST_HOME/.local/state/cmux/crash" "$diagnostics/crash-reports" || true + if [ -n "${CMUX_APP_HOST_HOME:-}" ]; then + # The console account owns the isolated home on runners where the + # GitHub agent is a different user. Validate the published identity + # before using its resolved path, then fall back to passwordless + # sudo only for this exact authenticated run scope. + ci_script_dir="${GITHUB_WORKSPACE:-$PWD}/scripts/ci" + # shellcheck source=scripts/ci/app-host-isolation.sh + source "$ci_script_dir/app-host-isolation.sh" + if cmux_validate_published_app_host_identity_values; then + crash_reports="$CMUX_RESOLVED_APP_HOST_HOME/.local/state/cmux/crash" + if [ -d "$crash_reports" ]; then + copied=0 + if cp -R "$crash_reports" "$diagnostics/crash-reports" 2>/dev/null; then + copied=1 + elif sudo -n true 2>/dev/null; then + rm -rf -- "$diagnostics/crash-reports" + if sudo -n cp -R "$crash_reports" "$diagnostics/crash-reports" \ + && sudo -n chown -R "$(id -u):$(id -g)" "$diagnostics/crash-reports"; then + copied=1 + fi + fi + if [ "$copied" -ne 1 ]; then + echo "::warning::unable to read isolated app-host crash reports" >&2 + fi + fi + else + echo "::warning::app-host identity validation failed; crash reports not collected" >&2 + fi fi shopt -s nullglob From 251b0501ddb4b3bed655baa1235e69c6ade6806b Mon Sep 17 00:00:00 2001 From: Leo Li Date: Sun, 20 Sep 2026 02:29:05 -0700 Subject: [PATCH 3/3] ci: allow privileged crash report collection --- .github/workflows/ci.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3533348f7e7b..5b1b6632ccb5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1177,7 +1177,12 @@ jobs: source "$ci_script_dir/app-host-isolation.sh" if cmux_validate_published_app_host_identity_values; then crash_reports="$CMUX_RESOLVED_APP_HOST_HOME/.local/state/cmux/crash" - if [ -d "$crash_reports" ]; then + reports_present=0 + if [ -d "$crash_reports" ] \ + || sudo -n test -d "$crash_reports" 2>/dev/null; then + reports_present=1 + fi + if [ "$reports_present" -eq 1 ]; then copied=0 if cp -R "$crash_reports" "$diagnostics/crash-reports" 2>/dev/null; then copied=1