Skip to content

ci: replace inferred routing with declarative area table - #13410

Merged
teamleaderleo merged 10 commits into
ci/rfc-13095-extract-macosfrom
ci/rfc-13095-area-table
Sep 23, 2026
Merged

teamleaderleo merged 10 commits into
ci/rfc-13095-extract-macosfrom
ci/rfc-13095-area-table

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #13405.

Replace the interim workflow-text/job-diff inference in scripts/ci/detect_ci_change_areas.py with the declarative .github/ci-areas.yml ownership table from RFC #13095.

Routing policy

  • macOS defaults to run. New and unknown paths therefore receive native compile/test coverage.
  • web and agent-session web remain opt-in.
  • include rules override neutral rules, so owned reusable workflow files exercise their own lanes.
  • test-only macOS source keeps Release skipped.
  • existing Linux-only guard tests are listed explicitly instead of inferred by parsing workflow text.

Fail-closed policy ownership

The caller checks the changed-file list before executing PR-controlled Python. Any edit to:

  • .github/workflows/ci.yml
  • .github/ci-areas.yml
  • scripts/ci/**
  • tests/test_ci_change_areas.py

forces every CI area.

This removes split_workflow_jobs, job_is_plainly_linux, ci_workflow_change_is_linux_only, --ci-workflow-base, and the workflow-text test-reference inference.

Regression coverage

The routing suite retains cases for docs, web-only, macOS source, test-only source, packages, reusable workflow files, and unknown paths, and adds checks that:

  • unknown paths run macOS + Release
  • the table is the only path-ownership source
  • policy-file changes force all areas before candidate Python runs
  • area-table changes also force every Linux guard route

Review boundary

This PR changes routing representation and policy ownership only. It does not remove the existing linux-preflight / tests rollups, alter persistent-Mac routing, change R2 artifact behavior, or touch app-host failure handling.

Migration sequence: #13378 → #13382 → #13405 → this area-table slice → rollup cleanup / one authoritative ci-status → final routing/result/merge-group regression matrix.

Refs #13095.


Summary by cubic

Replaces the workflow-text and job-diff inference in scripts/ci/detect_ci_change_areas.py with a declarative ownership table in .github/ci-areas.yml.

  • Unknown paths default to macOS + Release, so new files get native compile/test coverage; web stays opt-in.
  • Include rules override neutral rules, so owned reusable workflow files exercise their own lanes and test-only macOS source keeps Release skipped.
  • Mac-only test-product helpers and the persistent-Mac and web-validation scripts stay neutral for force_all, keeping their dedicated lanes.
  • Any edit to ci.yml, ci-areas.yml, scripts/ci/**, or tests/test_ci_change_areas.py forces every CI area before PR-controlled Python runs, and area-table edits also force every Linux guard route.
  • Removes split_workflow_jobs, job_is_plainly_linux, ci_workflow_change_is_linux_only, the workflow-text test-reference inference, and --ci-workflow-base.
  • Linux-only guard tests are now listed explicitly instead of inferred by parsing workflow text.

Regression coverage

  • Routing tests cover docs, web-only, macOS source, test-only source, packages, reusable workflows, and unknown paths.
  • New tests assert unknown paths run macOS + Release, the table is the only path-ownership source, and policy-file changes force all areas before candidate Python runs.

Written for commit 969afb0. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 77723022-bc7a-46e3-b6d1-9fe7b0da1150

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo force-pushed the ci/rfc-13095-area-table branch from d13a2c7 to 881f141 Compare September 21, 2026 22:56

Copy link
Copy Markdown
Collaborator Author

Review repair on current branch: the Linux guard self-protection list omitted .github/ci-areas.yml. That let a candidate area-table edit fall through to PR-controlled detect_linux_guard_changes.py, violating the existing regression that router/table changes must force every guard before candidate routing code runs.

Fixed in 969afb03958a962b48f78455f4620b1117ed0dcc by adding the area table to the workflow-owned protected list. The existing test_candidate_router_cannot_disable_its_own_guards already covers this exact path; the previous CI failure was that regression firing correctly. Current-head checks are rerunning.

Copy link
Copy Markdown
Collaborator Author

@greptileai review

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Reviewed head 969afb03958a962b48f78455f4620b1117ed0dcc, still based on ci/rfc-13095-extract-macos, against current main. This should stay draft while the migration is refreshed; the table idea remains useful, but this version predates important routing contracts.

  • Its ChangeAreas/output contract omits main's cli and swift_packages fields. Porting this replacement directly would lose independent CLI and package-test routing.
  • force_all for scripts/ci/** and ci.yml needs to preserve the newer publishing-only and content-sensitive workflow exclusions. Otherwise changes we have just made cheap become full native runs again.
  • The explicit Linux-test list duplicates ownership now derived from workflow/registry behavior. Preserve the registry-only change classification, including native-lane edits failing closed; a growing manual list must not silently diverge from actual test consumers.

A smaller migration is to preserve the current outputs, trusted-base safeguards, and content-sensitive workflow/registry classifiers, then move ordinary path ownership into validated data one rule family at a time. First add behavioral parity cases for CLI-only, package-only, publishing-only, workflow-only, Linux-only registry edits versus native registry edits, unknown paths, and routing-policy edits. Compare the old and proposed decisions before retiring each classifier.

This was a read-only code/design review, not a new test run. No code or draft status changed.

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Parked — Thornquay 💠 (triage, 2026-09-23). Still wanted: .github/ci-areas.yml is absent from main at a9b0329691, so the declarative table has not landed by another route. Blocked twice over: the base branch ci/rfc-13095-extract-macos (#13405) was squash-merged, so this needs retargeting to main, and it then conflicts in six files including ci.yml, ci-macos.yml and detect_ci_change_areas.py. Not rebasing now — the macOS pool is saturated and this is a required-check-routing change that wants a careful resolution, not a fast one.

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Independent review — approving.

What I checked most closely: paths in force_all match both include (scripts/ci/**) and neutral (the explicit control-plane helpers), so precedence alone decides whether editing persistent_mac_route.py forces every lane. _force_all() checks neutral before include, reversing rule_runs()'s order, and test_area_table_preserves_current_control_plane_ownership pins it (_force_all(table, "scripts/ci/persistent_mac_route.py") is False). The reversal is deliberate and covered rather than incidental.

Also verified:

  • macos.default: run keeps unknown paths natively covered, pinned by test_area_table_defaults_unknown_paths_to_macos_and_release.
  • An unrecognised CI helper still forces all areas: classify_files(["scripts/ci/future_unknown_helper.py"]) == ChangeAreas.all().
  • test_area_table_is_the_only_path_ownership_source asserts the deleted inference helpers are absent from the source, so inferred routing cannot quietly return.
  • Both routing tests are registered in tests/test-execution.toml under lane = "linux-guard", so they execute rather than silently not running.

Evidence: guards / workflow-guard-tests / ci passed (47s) — that is the lane carrying both routing tests. macos / macOS compile admission passed (20m4s). The 13 skipping checks are the macOS unit and release lanes that CI_PULL_REQUEST_SUITE=compile-only skips repo-wide; that is pre-existing policy, not a gap introduced here.

One no-action note: in _glob_regex, the **/ branch falls through into the ** branch without a continue. I traced every pattern in the table (**/CLAUDE.md, skills/**/*.md, .github/workflows/**) plus **, a/** and **/**, and found no input where the fallthrough changes the compiled regex. Nothing to fix; noted only because the shape invites a second look.

— Rockall g1 🪙
Run: run_cmux_land_ready_prs_20260923_A

@teamleaderleo
teamleaderleo merged commit 78b66f9 into ci/rfc-13095-extract-macos Sep 23, 2026
56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant