Skip to content

ci: extract reusable macOS workflow - #13405

Merged
teamleaderleo merged 25 commits into
mainfrom
ci/rfc-13095-extract-macos
Sep 21, 2026
Merged

teamleaderleo merged 25 commits into
mainfrom
ci/rfc-13095-extract-macos

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #13382.

Move the RFC-owned macOS CI jobs from .github/workflows/ci.yml into reusable .github/workflows/ci-macos.yml while preserving their job bodies, dependencies, artifact handoffs, runner selection, and routing semantics.

This slice is intended as a topology move only. It does not change persistent-Mac routing, R2 artifact transport, app-host failure handling, the CI area policy, or the existing rollups.

Migration sequence

#13378 guard extraction → #13382 web extraction → this macOS extraction → declarative area table → rollup cleanup / single ci-status → final routing/result/merge-group regression matrix.

Refs #13095.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Extracts the macOS CI jobs from .github/workflows/ci.yml into a reusable .github/workflows/ci-macos.yml, keeping job bodies, dependencies, artifact handoffs, runner selection, and routing intact. This is a topology-only move with no change to persistent-Mac routing, R2 artifact transport, app-host failure handling, or CI area policy.

  • ci.yml calls the reusable workflow and aggregates macOS outcomes into a macos-status job; the tests gate waits on this aggregate instead of individual macOS jobs, and macOS jobs gate on inputs rather than needs.changes outputs.
  • Change-area detection, package selection, artifact-transport and cache-receipts contracts, and product-input identity now treat ci-macos.yml as the workflow input so edits trigger the full macOS, release, and product-reuse paths.
  • macos-status rejects invalid route values and requires every full-suite lane; compile-only runs may reuse an earlier admission verdict.
  • Tests that read macOS job bodies, package selection, product publication, sharding, cache receipts, and read-only caches now target the new workflow; the self-hosted-runner guard splits ownership between the caller and macOS workflow, and the persistent-Mac router tests split ownership with admission reading inputs.persistent_* instead of needs.persistent-mac-compile-route.

Written for commit e2a2d22. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores

    • Updated continuous integration coverage to recognize changes to the macOS workflow.
    • Ensured relevant macOS and release validation runs when platform workflow configuration changes.
    • Expanded package-test selection so workflow updates receive comprehensive validation.
    • Aligned cache, artifact, release, runner, and notification checks with the dedicated macOS workflow.
  • Tests

    • Updated CI contract and regression tests to validate macOS workflow behavior, routing, caching, builds, and safeguards.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

Review limit reached

Next included review available in 42 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 17f8a8f4-880a-434e-b5d5-2e97c17b6946

📥 Commits

Reviewing files that changed from the base of the PR and between eec58f3 and e2a2d22.

📒 Files selected for processing (28)
  • .github/workflows/ci-artifact-transport.yml
  • .github/workflows/ci-cache-receipts.yml
  • .github/workflows/ci-macos.yml
  • .github/workflows/ci.yml
  • scripts/ci/detect_ci_change_areas.py
  • scripts/ci/product_input_identity.py
  • scripts/ci/select_package_tests.py
  • tests/test_check_ghostty_zig_workflows.py
  • tests/test_ci_app_host_home_isolation.py
  • tests/test_ci_cache_restore_receipt.py
  • tests/test_ci_change_areas.py
  • tests/test_ci_checkout_network_diagnostics.py
  • tests/test_ci_cmux_unit_test_shard.py
  • tests/test_ci_notification_semantics.py
  • tests/test_ci_persistent_mac_compile.py
  • tests/test_ci_product_publication.py
  • tests/test_ci_pull_request_caches_are_read_only.py
  • tests/test_ci_release_build_timeout.sh
  • tests/test_ci_release_helper_archs.py
  • tests/test_ci_release_sdk_lane.sh
  • tests/test_ci_select_package_tests.py
  • tests/test_ci_self_hosted_guard.sh
  • tests/test_ci_swift_warning_budget.sh
  • tests/test_ci_test_compilation_cache_seed.sh
  • tests/test_ci_unit_test_spm_retry.sh
  • tests/test_nightly_universal_build.sh
  • tests/test_reuse_app_host_products.py
  • workers/ci-artifacts/test/consumer-workflow.test.mjs
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

Landing note: the previous CI failure in workflow-guard-tests came from tests/test_ci_unit_test_spm_retry.sh selecting the first Resolve Swift packages step after the move to ci-macos.yml. That first occurrence belongs to compile admission, while this guard is meant to exercise the app-host shard retry loop.

Commit 44a4dce scopes the parser to the app-host-unit-tests job before locating the resolver step. No Mac job command or retry policy changed.

This PR still needs a real refresh after #13382 lands; its current branch predates the refreshed web base by a large amount. I’m keeping it draft until that refresh so we preserve the pure-move review boundary.

@teamleaderleo
teamleaderleo force-pushed the ci/rfc-13095-extract-macos branch from 44a4dce to d42ce20 Compare September 21, 2026 20:26
@teamleaderleo
teamleaderleo changed the base branch from ci/rfc-13095-extract-web to main September 21, 2026 20:28
@teamleaderleo
teamleaderleo marked this pull request as ready for review September 21, 2026 20:28
@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

2 similar comments
@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 21, 2026 20:31
@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

1 similar comment
@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo
teamleaderleo force-pushed the ci/rfc-13095-extract-macos branch from 781aaef to c507fa8 Compare September 21, 2026 22:48
@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 21, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo
teamleaderleo merged commit e6e0579 into main Sep 21, 2026
54 of 55 checks passed
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
The push-path trigger named ci.yml, but #13405 moved the macOS jobs that
consume these artifacts into ci-macos.yml, so pushes that changed the
consuming lane no longer re-validated transport. Point the trigger and
its test at ci-macos.yml.

The pull_request block already lists both workflows on main, so only the
push block needed this.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit to teamleaderleo/cmux that referenced this pull request Sep 22, 2026
The push-path trigger named ci.yml, but manaflow-ai#13405 moved the macOS jobs that
consume these artifacts into ci-macos.yml, so pushes that changed the
consuming lane no longer re-validated transport. Point the trigger and
its test at ci-macos.yml.

Also drop a duplicate definition of
test_workflow_retries_remote_artifact_delete_before_bucket_cleanup. The
later definition shadowed the earlier one, so the shorter version never
ran; the surviving copy is the superset that also executes the wrangler
stub.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
#13405 moved the macOS jobs into ci-macos.yml as a called workflow. A called
workflow does not inherit the caller's workflow-level env, so
CI_CACHE_R2_PUBLIC_URL stopped reaching scripts/ci/r2-cache.sh and every R2
restore in compile admission logs 'CI_CACHE_R2_PUBLIC_URL is not set; treating
as a miss'. test-ios.yml has the same gap. Declare it in both.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
…producer (#13676)

Both compile-reuse lookups identify the producing job by exact GitHub job name:

  scripts/ci/find_admitted_build.py:66      job["name"] == ADMISSION_JOB
  scripts/ci/reuse_app_host_products.py:306 job.get("name") == "macOS compile admission"

On 2026-09-21 #13405 extracted the macOS jobs from `ci.yml` into the reusable
`ci-macos.yml`, called from the `macos` job. GitHub reports a reusable
workflow's jobs as "<caller job> / <job name>", so the producer is now
"macos / macOS compile admission". Neither constant moved with it, so both
comparisons stopped matching anything.

Verified against the live API rather than inferred. Three runs created within
the last few minutes:

  'macos / macOS compile admission'  labels=blacksmith-6vcpu-macos-15
  'macos / macOS compile admission'  labels=blacksmith-6vcpu-macos-15
  'macos / macOS compile admission'  labels=blacksmith-6vcpu-macos-15

and a before/after split across the refactor: 25 of 30 pre-refactor runs
carried a job named exactly "macOS compile admission"; 2 of 207 post-refactor
runs did, both on stale branches whose merge commit still had the inline
`ci.yml`.

Consequence: `find_admitted_build.py` returns `None` unconditionally and
`reuse_app_host_products.py` records `producer_compile_unsuccessful` for every
candidate, so both reuse mechanisms are dead. Sampled
`macos-compile-admission-metrics-*` artifacts agree: every successful admission
reports a real ~1,015s compile and `classification: "hosted fallback"`, with a
measured reuse hit rate of zero.

Match the final path segment instead, so the lookup survives the job being
reached directly or through any caller.

This is fail-open in both call sites already (the `admitted` step is
`continue-on-error`, and the reuse path records a miss reason and compiles), and
reuse still revalidates product identity against GitHub's immutable Git objects,
so a wrongly matched producer cannot smuggle in a foreign product.

Neither edited file is in `PRODUCT_CI_INPUTS`, and `reaches_product()` returns
False for `scripts/ci/*` outside that set, so no cached product is invalidated
and no open pull request is forced to recompile.

`tests/test_ci_change_areas.py` fabricated the bare job name, so it passed
against production code that could never match. The fixture now uses the
composed name, and a new test derives that name from the workflows themselves --
the `ci.yml` job whose `uses:` targets `ci-macos.yml`, plus the
`macos-compile-admission` job's `name` -- and asserts both lookups accept it.
Reverting either fix makes that test fail, which is the signal #13405 should
have tripped.

Tests: test_reuse_app_host_products.py, test_app_host_test_products.py,
test_ci_persistent_mac_compile.py, test_ci_workload_profiles.py,
test_ci_guard_workflow_structure.py, test_ci_self_hosted_guard.sh pass, and
149 test_ci_change_areas.py cases pass (its shallow-clone cases need HEAD^1 and
fail identically on main).

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* ci: harden R2 canary cleanup and coverage

* test: exercise canary cleanup retries

* ci: retry R2 canary artifact cleanup

* ci: cover main CI transport changes

* ci: make absent R2 canary secrets idempotent

* test: execute R2 canary cleanup retry contract

* ci: trigger artifact transport on main CI changes

* ci: point the transport push trigger at ci-macos.yml

The push-path trigger named ci.yml, but #13405 moved the macOS jobs that
consume these artifacts into ci-macos.yml, so pushes that changed the
consuming lane no longer re-validated transport. Point the trigger and
its test at ci-macos.yml.

Also drop a duplicate definition of
test_workflow_retries_remote_artifact_delete_before_bucket_cleanup. The
later definition shadowed the earlier one, so the shorter version never
ran; the surviving copy is the superset that also executes the wrangler
stub.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant