Skip to content

ci: extract reusable web workflow - #13382

Merged
teamleaderleo merged 5 commits into
mainfrom
ci/rfc-13095-extract-web
Sep 21, 2026
Merged

teamleaderleo merged 5 commits into
mainfrom
ci/rfc-13095-extract-web

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #13378.

Move the RFC-owned Linux web jobs out of .github/workflows/ci.yml into reusable .github/workflows/ci-web.yml:

  • web-typecheck
  • react-apps-check
  • diff-sidecar-check
  • web-db-migrations
  • agent-session-web-resources

This is a topology move. The job command bodies, runner labels, services, timeouts, and route meanings are preserved.

Caller behavior

ci.yml now has one web reusable-workflow call. It receives the existing web, macos, and agent_session_web route outputs as strings.

The call is skipped only when all three inputs are explicitly false. Missing or malformed routes therefore enter the reusable workflow and fail closed.

Inside ci-web.yml, web-status validates:

  • web/typecheck/react/db jobs are required when web=true
  • diff-sidecar is required when macos=true or web=true
  • agent-session resources are required when agent_session_web=true
  • a routed job must report success
  • an unrouted job may report success or skipped

The caller's existing linux-preflight validates the three route values again and requires the aggregate web call to succeed whenever any of them is true.

Compatibility changes

  • tests now observes the aggregate web result instead of the moved agent-session job directly. It already waits on linux-preflight, so this does not add a new staging dependency.
  • ci-status observes one web result instead of five internal jobs.
  • the CI area detector scans ci-web.yml when classifying Linux-only referenced tests, preserving existing test-only routing behavior after the file move.
  • routing policy itself is unchanged here; the declarative area table remains a later RFC slice.

Regression coverage

The updated CI routing tests cover:

  • caller input wiring
  • selected web-job skipped/failure/cancellation propagation
  • all-unrouted jobs as valid skips
  • aggregate web skip rejection when any web route is true
  • aggregate web skip acceptance only when web, macos, and agent_session_web are all false
  • web job body checks from the reusable workflow
  • agent-session route ownership from the reusable workflow

Review boundary

This PR does not move macOS jobs, change the declarative routing table, remove the existing rollups, touch persistent-Mac routing, change R2 artifact behavior, or repair app-host flakes.

Migration sequence: #13378 guard extraction → this web extraction → macOS extraction → declarative area table → rollup cleanup / single ci-status → final route/result/merge-group matrix.

Refs #13095.


Summary by cubic

Moves the five Linux web CI jobs out of ci.yml into a reusable ci-web.yml workflow called once by ci.yml, preserving the job bodies as-is.

Behavior changes

  • The caller passes the web, macos, and agent_session_web route outputs as inputs; riffraff/malformed values enter the workflow and fail closed, since the call only skips when all three are explicitly false.
  • A new web-status validation job requires routed jobs to succeed while allowing unrouted jobs to skip.
  • linux-preflight validates the three route values and requires the aggregate web call to succeed when any is true.
  • tests and ci-status now observe the aggregate web result instead of the individual jobs.
  • The CI area detector and self-hosted guard test treat edits to ci-web.yml as touching every owned web area and follow the moved jobs into the new file, preserving Linux-only test routing and DB behavior test coverage.

Written for commit e0ec361. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features

    • Added reusable Linux guard and web validation workflows.
    • CI now routes checks by change area, including Linux, web, macOS, and Agent Session resources.
    • Added consolidated status reporting to clearly identify failed or skipped required checks.
  • Bug Fixes

    • Improved change detection so updates to dedicated CI workflows trigger the appropriate validation areas.
    • Strengthened routing and preflight validation to prevent required checks from being skipped.
  • Tests

    • Updated CI validation coverage for the new workflow structure, routing behavior, permissions, and failure handling.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

Warning

Review limit reached

Next included review available in 23 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 531400c0-c628-4fb8-8e2f-b6076d350dc8

📥 Commits

Reviewing files that changed from the base of the PR and between f88bade and e0ec361.

📒 Files selected for processing (5)
  • .github/workflows/ci-web.yml
  • .github/workflows/ci.yml
  • scripts/ci/detect_ci_change_areas.py
  • tests/test_ci_change_areas.py
  • tests/test_ci_self_hosted_guard.sh

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e6927311-c6ae-4447-b739-1fbfc0be36ce

📥 Commits

Reviewing files that changed from the base of the PR and between edc5d20 and f88bade.

📒 Files selected for processing (12)
  • .github/workflows/ci-guards.yml
  • .github/workflows/ci-web.yml
  • .github/workflows/ci.yml
  • scripts/ci/detect_ci_change_areas.py
  • tests/test_ci_app_host_home_isolation.py
  • tests/test_ci_change_areas.py
  • tests/test_ci_linux_guard_routing.py
  • tests/test_ci_reusable_workflow_permissions.py
  • tests/test_ci_self_hosted_guard.sh
  • tests/test_ci_swift_warning_budget.sh
  • tests/test_ghostty_zig_version_sync.sh
  • tests/test_ios_testflight_pro_distribution.py

Included review availability: Your plan provides up to 10 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The change adds reusable guard and web workflows, routes them through aggregate jobs in ci.yml, expands CI change-area detection, and updates workflow validation tests and scripts for the new file boundaries and aggregate results.

Changes

CI workflow routing

Layer / File(s) Summary
Guard workflow implementation
.github/workflows/ci-guards.yml, tests/test_ci_app_host_home_isolation.py, tests/test_ci_reusable_workflow_permissions.py, tests/test_ci_swift_warning_budget.sh, tests/test_ghostty_zig_version_sync.sh, tests/test_ios_testflight_pro_distribution.py
Adds four routed guard jobs and a guard-status job. Related checks now read the guard workflow.
Web workflow implementation
.github/workflows/ci-web.yml, tests/test_ci_self_hosted_guard.sh, tests/test_ci_change_areas.py
Adds routed web, DiffSidecar, database migration, and Agent Session resource jobs. web-status validates their results.
Main workflow aggregation
.github/workflows/ci.yml, tests/test_ci_change_areas.py, tests/test_ci_linux_guard_routing.py
Replaces individual guard and web jobs with guards and web reusable-workflow calls. Preflight, tests, and status checks now use the aggregate results.
Change-area and workflow validation
scripts/ci/detect_ci_change_areas.py, tests/test_ci_app_host_home_isolation.py, tests/test_ci_change_areas.py
Change-area detection reads all CI workflow files. Tests validate reusable workflow routing, aggregate gating, skipped routes, and workflow ownership.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Refactor

Sequence Diagram(s)

sequenceDiagram
  participant Changes as changes
  participant CI as ci.yml
  participant Guards as ci-guards.yml
  participant Web as ci-web.yml
  participant Preflight as linux-preflight
  Changes->>CI: Produce guard and web route outputs
  CI->>Guards: Pass linux guard inputs
  CI->>Web: Pass web inputs
  Guards->>Guards: Run selected guard jobs
  Web->>Web: Run selected web jobs
  Guards-->>CI: Return guards result
  Web-->>CI: Return web result
  CI->>Preflight: Validate aggregate results against routes
Loading
🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 42 functions across 9 files. (3 skipped: 3… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the primary change: extracting the reusable web workflow from the main CI workflow.
Description check ✅ Passed The description explains the change, rationale, caller behavior, validation logic, compatibility impact, regression coverage, and review boundaries. It does not reproduce every template section, but i…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The authoritative PR diff changes GitHub Actions workflow extraction, CI route detection, and routing tests only. The new ci-guards.yml and ci-web.yml workflows run existing validation and w…
Cmux Swift Actor Isolation ✅ Passed PASS — The reviewed range changes only GitHub Actions YAML, Python, and shell files. The authoritative diff contains no .swift, .swiftinterface, .m, or .mm paths. The only Swift reference is C…
Cmux Swift Blocking Runtime ✅ Passed PASS: The authoritative diff changes only GitHub Actions YAML, Python test/helpers, and shell tests. It contains no changed .swift path and no added or removed Swift blocking-runtime constructs such…
Cmux Browser Automation Off-Main ✅ Passed PASS. The pull request changes only GitHub workflow YAML and CI routing/test files. The rule-scoped files Sources/TerminalController.swift and `Packages/macOS/CmuxControlSocket/Sources/CmuxControlSo…
Cmux Expensive Synchronous Load ✅ Passed The authoritative pull-request diff changes only GitHub Actions workflows, CI routing Python, and CI test scripts. It contains no changed Swift files and no added or moved expensive synchronous load s…
Cmux Cache Substitution Correctness ✅ Passed PASS: The authoritative PR diff changes only YAML, Python, and shell files. It contains no production Swift, TypeScript, or JavaScript source changes, and therefore does not introduce a cache substitu…
Cmux No Hacky Sleeps ✅ Passed PASS. The PR changes three GitHub Actions workflow YAML files plus CI Python and test shell/Python files. The rule explicitly excludes workflow YAML. The added non-YAML lines introduce no sleep, timer…
Cmux Algorithmic Complexity ✅ Passed PASS. The authoritative diff changes only GitHub workflow YAML, a Python CI helper, and test files. The only changed shell files are under tests/, and their edits only update workflow paths. No prod…
Cmux Swift Concurrency ✅ Passed PASS. The reviewed range changes only GitHub Actions YAML, Python, and shell test files. It contains no changed Swift, SwiftPM, or Xcode project files, and the changed diff introduces no Swift concurr…
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only GitHub Actions YAML, Python, and shell test files. It changes no Swift source and introduces no Swift concurrency annotations, nonisolated async work, or Swift as…
Cmux Swift Package Boundaries ✅ Passed PASS: The authoritative pull-request diff changes only 3 YAML, 6 Python, and 3 shell files. It contains no .swift paths or production Swift source changes, so the Swift package-boundaries rule is no…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The PR changes only workflow, routing, and CI-test files. It does not modify Package.swift, Package.resolved, .gitignore, Xcode project/workspace files, or SwiftPM package references. The workfl…
Cmux Swift Logging ✅ Passed PASS: The reviewed diff changes only GitHub Actions workflows and CI Python/shell tests. It contains no changed Swift files or production Swift logging. The added print(...) calls are embedded Pytho…
Cmux User-Facing Error Privacy ✅ Passed PASS. The diff changes only GitHub Actions workflows, CI routing code, and CI tests. The new status messages and retry warning are GitHub Actions operator logs, not cmux app UI, product CLI, or produc…
Cmux Full Internationalization ✅ Passed PASS. The reviewed diff changes only GitHub Actions workflows, CI routing code, and CI tests. It adds no Swift UI text, localization catalog entries, web UI or API copy, web message files, locale regi…
Cmux Swiftui State Layout ✅ Passed PASS: The pull-request diff changes only GitHub Actions workflows, CI Python code, and CI test scripts. It contains no Swift or SwiftUI source files and no added ObservableObject, @Published, `@Ob…
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes CI workflow files, CI area detection, and CI tests. It does not change Swift implementation, SwiftUI/AppKit lifecycle ownership, or Swift synchronization/state behavior.…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The authoritative PR diff changes only YAML, Python, and shell files. It adds or modifies CI workflows and routing tests, with no Swift, Objective-C, storyboard, or XIB files. The patch also con…
Cmux Source Artifacts ✅ Passed The 12 changed paths are workflow YAML, one CI source script, and CI test files. Both added files are regular text workflow configs with mode 100644. No changed path is a scratch directory, log, image…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The authoritative PR diff changes only GitHub workflows, one Python script, and test files. It contains no changed Swift file under a production Sources/ path, and the patch has no Swift seam …
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 42 functions across 9 files. (3 skipped: 3 unsupported.)

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch ci/rfc-13095-extract-web
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; the prior routing and executable-permission problems are resolved and no new actionable failures remain.

Summary

Extracts the Linux web CI jobs into a reusable workflow while preserving their route-dependent execution and aggregate status checks.

  • Adds .github/workflows/ci-web.yml with the five moved jobs and a fail-closed web-status rollup.
  • Replaces the individual jobs in ci.yml with one reusable-workflow call and updates downstream gates.
  • Routes edits to the reusable workflow through all web-owned job bodies.
  • Updates CI routing and guard tests for the extracted workflow.
  • Restores executable permissions on the affected shell guard scripts.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Changes[changes routing] --> WebCall[ci.yml web call]
  Static[static-preflight] --> WebCall
  WebCall --> Reusable[ci-web.yml]
  Reusable --> Typecheck[web-typecheck]
  Reusable --> React[react-apps-check]
  Reusable --> Sidecar[diff-sidecar-check]
  Reusable --> DB[web-db-migrations]
  Reusable --> Agent[agent-session-web-resources]
  Typecheck --> Status[web-status]
  React --> Status
  Sidecar --> Status
  DB --> Status
  Agent --> Status
  Status --> Preflight[linux-preflight]
  Status --> Tests[tests]
  Status --> CIStatus[ci-status]
Loading

Reviews (4) · Last reviewed commit: "Merge executable-mode repair into ci/rfc..."

Comment thread scripts/ci/detect_ci_change_areas.py
@greptile-apps

This comment has been minimized.

@teamleaderleo
teamleaderleo changed the base branch from ci/rfc-13095-extract-guards to main September 21, 2026 19:28
@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 21, 2026 19:28
auto-merge was automatically disabled September 21, 2026 19:36

Pull request was closed

@teamleaderleo
teamleaderleo force-pushed the ci/rfc-13095-extract-web branch from f88bade to edc5d20 Compare September 21, 2026 19:36
@teamleaderleo teamleaderleo reopened this Sep 21, 2026
@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 21, 2026 19:38
@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit d42ce20 into main Sep 21, 2026
44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant