Skip to content

ci: skip Linux preflight when macOS is unrouted - #13550

Merged
teamleaderleo merged 3 commits into
mainfrom
fix/ci-skip-linux-preflight-without-macos
Sep 22, 2026
Merged

teamleaderleo merged 3 commits into
mainfrom
fix/ci-skip-linux-preflight-without-macos

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • skip linux-preflight when the change router explicitly reports macos=false
  • keep fail-open behavior when the route is missing/invalid
  • allow the final tests aggregate to accept a skipped preflight only when macos=false
  • cover both the skipped no-Mac path and the required Mac path in the existing Linux-only routing suite

This prevents iOS-only/docs/web-only changes from spending a Linux runner on a gate whose only purpose is admitting macOS work.

The workflow edit is confined to Linux jobs, and the regression lives in tests/test_ci_linux_guard_routing.py, which is already wired into the Linux guard lane.


Summary by cubic

Skips the linux-preflight gate when the change router explicitly reports macos=false, so iOS-, docs-, and web-only changes stop spending a Linux runner on a job whose only purpose is admitting macOS work. Missing or invalid route output still fails open and runs the preflight.

The tests aggregate now accepts a skipped preflight only when macos=false; a skipped preflight with a real macOS route still fails. The Linux-only routing suite covers both the skipped no-Mac path and the required Mac path, and asserts the exact job condition to lock the migration contract.

Written for commit bce038a. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • CI Improvements

    • Linux preflight checks are now skipped when changes do not affect macOS.
    • Validation continues to require successful preflight checks when macOS-related changes are included.
    • Invalid or missing routing information continues to trigger preflight checks.
  • Tests

    • Added coverage for macOS routing and Linux preflight outcomes.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 66641f28-c66b-41be-84be-13bcfaf93abb

📥 Commits

Reviewing files that changed from the base of the PR and between 2c4282e and bce038a.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • tests/test_ci_linux_guard_routing.py

Included review availability: Your plan provides up to 10 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The CI workflow now skips linux-preflight when the macOS route is false. Routing validation accepts a skipped preflight only for that route. Tests cover both route outcomes.

Changes

macOS Route-Aware CI

Layer / File(s) Summary
Workflow routing and result validation
.github/workflows/ci.yml
linux-preflight skips when the macOS route is false and runs for missing or invalid route outputs. The tests gate requires success for the enabled route and accepts success or skipped for the disabled route.
Routing behavior tests
tests/test_ci_linux_guard_routing.py
Tests cover conditional preflight execution and the tests-gate outcomes for enabled and disabled macOS routing.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to bce03

The workflow skips Linux preflight only when macOS is explicitly false and preserves fail-open behavior otherwise; route-specific gate checks and tests support merge readiness.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The diff updates Linux CI routing and tests; it does not change Cloud terminal creation, cmux…
Cmux Swift Actor Isolation ✅ Passed The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py; the authoritative diff contains no Swift files or production Swift changes. The custom check theref…
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It introduces no production Swift changes, so the Swift blocking-runtime check does not apply.
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The diff adds CI routing logic and tests. It does not add or modify browser socket commands, …
Cmux Expensive Synchronous Load ✅ Passed The PR changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The review-scoped diff contains no Swift files and adds no synchronous agent-history or workspace load. The custo…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It introduces no production Swift, TypeScript, or JavaScript changes, so the cache substituti…
Cmux No Hacky Sleeps ✅ Passed The PR changes only GitHub Actions YAML and Python test coverage. The rule explicitly excludes GitHub Actions YAML, and the test changes add deterministic routing assertions. The diff introduces no sl…
Cmux Algorithmic Complexity ✅ Passed The pull request adds only a workflow condition, status branching, and test coverage. The new status checks use a fixed two-value set and do not scan scalable collections. The changed test code is tes…
Cmux Swift Concurrency ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It changes CI routing and Python test logic, not cmux-owned Swift code. The added lines conta…
Cmux Swift @Concurrent ✅ Passed The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The review-scoped diff contains no Swift files or Swift code, so the @concurrent check is not app…
Cmux Swift Package Boundaries ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It introduces no production Swift changes, so the Swift package boundary rule does not apply.
Cmux Swiftpm Lockfiles ✅ Passed PASS. The pull-request changes only .github/workflows/ci.yml routing logic and tests/test_ci_linux_guard_routing.py. The patch contains no Package.swift, Package.resolved, .gitignore, `.xcod…
Cmux Swift Logging ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py; it introduces no production Swift changes. The only added print calls are Python CI/test-ga…
Cmux User-Facing Error Privacy ✅ Passed PASS. The diff changes only GitHub Actions routing and CI tests. The added error and status messages are internal CI diagnostics, not cmux app, CLI, or product API output. The rule explicitly allows i…
Cmux Full Internationalization ✅ Passed PASS: The PR changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The additions are CI routing logic, comments, test assertions, and operational error text. They do not …
Cmux Swiftui State Layout ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It introduces no SwiftUI changes, state declarations, GeometryReader usage, lazy/list row c…
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift changes, so the Swift architectural rethink criteria…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift changes and no standalone cmux-owned window code. Th…
Cmux Source Artifacts ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. The workflow edits are CI configuration, and the Python edits are hand-written regression tes…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The reviewed range changes only .github/workflows/ci.yml and tests/test_ci_linux_guard_routing.py. It contains no changed Swift file under a production Sources/ path, so the custom production Sw…
Title check ✅ Passed The title clearly and concisely describes the primary CI change: skipping Linux preflight when macOS is not routed.
Description check ✅ Passed The description explains what changed, why it changed, and the affected tests. The missing explicit Testing, Demo Video, Review Trigger, and Checklist sections are non-critical for this CI-only change…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Copy link
Copy Markdown
Collaborator Author

@greptileai review

Copy link
Copy Markdown
Collaborator Author

@greptile-apps review

@teamleaderleo
teamleaderleo merged commit 0bbcbb3 into main Sep 22, 2026
43 of 50 checks passed
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps

* Enforce Cloud display provenance and independent guest displays

* Keep display creation compatible with baked Cloud images

* Fix guest display target wiring and session supervision

* Harden embedded display helper and Dock restore ownership

* Close Cloud display lifecycle gaps

* Harden display discovery and helper restart recovery

* Finish Cloud display build and readiness guards

* Preserve display state and bind guest listeners privately

* Invalidate display catalogs when VM state changes

* Preserve Dock display duplication identity

* Preserve Cloud display refresh and browser locations

* Run guest display service as the desktop user

* Align Ghostty submodule with current main

* Invalidate terminal Cloud navigation callbacks

* Keep guest display ports out of forwarded resources

* Complete additional display recovery paths

* Synchronize guest profile and slow-route readiness

* Finish guest display startup and restore routing

* Keep unresolved display restores retryable

* Fence guest discovery to provider lifetime

* test: cover display transport recovery and duplication state

* fix: preserve Cloud displays during transport recovery

* test: preserve display identity across browser reconfiguration

* fix: retain display identity across route reconfiguration

* test: cover route observation after display reconfiguration

* fix: retain Cloud restore lifecycle state

* test: drop Cloud provenance after external navigation

* fix: clear Cloud provenance on external browser navigation

* test: cover display catalog and readiness cancellation

* fix: fence display catalog and readiness lifecycles

* test: cover delayed display restore and scoped helpers

* fix: complete display restore and supervisor isolation

* fix: require discovered guest display resources

* test: cover guest component recovery

* fix: preserve Cloud provenance and supervise displays

* test: reject failed display catalog responses

* fix: fence display discovery by response and auth

* test: filter untrusted display restore targets

* fix: fence display restore targets and VM kind

* test: fence browser Cloud service identity

* test: exercise recovered display supervision

* fix: recover display supervisors and port identity

* test: recover scoped display process commands

* fix: recover scoped display processes by command

* test: cover Cloud restore and destination comment fixes

* fix: address Cloud display review comments

* test: cover display port ownership and recovery

* fix: harden Cloud display supervisor and route lifecycle

* test: stay within Swift file budget

* fix: sanitize display errors and readiness probes

* fix: restore Cloud resources in Dock scopes

* fix: recover global Dock projections and daemon readiness

* fix: preserve Dock connections across Cloud route changes

* fix: bound display startup and preserve duplicate URLs

* fix: defer Cloud activation for hidden restores

* fix: preserve ownership checks across latest main merge

* fix: remove duplicate projection query declarations

* fix: restore provider display lifecycle after main merge

* fix: use merged hostname route API

* fix: restore New Display hover button after main merge

The latest origin/main merge moved CloudTreeRowHoverButtons into its own
file, and the conflict resolution kept main's copy, which dropped the
displays-pool New Display button and its hasButtons entry. Re-apply them
in the new file, and restore the blank lines the resolution stripped from
SurfaceCatalog.swift so the PR diff stays limited to behavior changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: keep SurfaceCatalog within its line budget

The blank lines restored in the previous commit put the file seven lines
over the Swift file-length budget, so drop them again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: route cloud desktop clicks through portal

* chore: keep cloud fix within file budgets

* ci: pin agent review checker to workflow commit

* docs: record trusted agent review execution

* test: lock agent review gate to trusted checker

* #13531: retire and background-reap cold warm-slot task state

Squashed onto current main after #13530 merged.

* fix: separate terminal stream and viewport lease lifetimes

* fix: keep viewport lease across UI output stream churn

* ci: dispatch #13474 follow-up iOS test

* ci: remove temporary #13474 follow-up dispatcher

* ci: run direct #13474 ownership test

* fix: request Greptile without GraphQL review capture

* ci: remove temporary #13474 direct test workflow

* test: decouple Greptile request from review GraphQL

* docs: separate Greptile request from ledger capture

* fix(iOS): preserve tagged App Group when signing supports it (#13541)

* fix(ios): preserve supported tagged App Groups

* ci: keep iOS-only tests off macOS runners

* ci: run tagged iOS signing regression on Linux

* ci: freeze legacy iOS test routing path

* fix(ios): harden tagged signing fallback detection

* fix(ios): fail closed on partial ASC signing credentials

* fix(ios): validate ASC key path before device signing

* chore(ios): report tagged device signing backend

* docs(ios): keep cheap regressions off macOS routing

* test(ios): bind fallback entitlements to retry build

* ci: catch nested iOS-only test routing footguns

* test(iOS): bind fallback entitlements to retry command

* fix(iOS): correct retry assertion pattern

* fix: keep cold-task cleanup moving past failures

* test: cover resilient cold-task cleanup

* fix(review): require proof for repaired findings

* iOS: keep the composer bar out of the home-indicator band when the terminal disconnects (#13471)

* iOS: add failing disconnected-composer-seat fixture and regression test (#13470)

CMUX_UITEST_WORKSPACE_DETAIL_DISCONNECTED=1 mounts a workspace shell whose
one retained terminal is Disconnected, with no Mac or sign-in; scenario
drop-after-focus starts connected, focuses the composer at t+2s (real
keyboard), and drops the Mac to unavailable at t+9s.

The new XCUITest rides the dock probe through the raise and the
blocked-input resign, waits for the settled keyboard-down rest, then
asserts the dock's constraint-resolved bottom edge leaves the whole bottom
safe area below it. On the iOS <=26 keyboard-guide seat the dock instead
rests at the raw screen bottom, so this test fails until the fix.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* iOS: floor the keyboard-guide dock seat at the bottom safe area (#13470)

With the keyboard up over a connected terminal, the Mac dropping to
unavailable blocks input, which resigns the keyboard. After that show->hide
cycle UIKeyboardLayoutGuide rests at the RAW host bottom instead of the
bottom safe area (usesBottomSafeArea notwithstanding), so the accessory
toolbar and composer bar land inside the home-indicator band -
permanently, because blocked input means no keyboard event ever re-seats
the guide.

Add a required dock.bottom <= host.bottom - resolvedBottomSafeAreaInset
floor, active only with the guide seat, and downgrade the guide equality to
999 so it yields exactly the clamped distance when the guide rests too low.
The floor is slack whenever the keyboard holds the guide higher, follows
the same resolved-inset sources as the plain seat, and deactivates with the
guide in the chrome-hidden state (whose dock parks at the raw bottom by
design). The iOS 27 notification seat already computes from the resolved
inset and is unaffected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix: restore working Greptile review trigger

* fix: restore working Greptile review trigger

* fix: restore working Greptile review trigger

* fix: restore working Greptile review trigger

* chore: preserve current Greptile trigger template

* Split the release guard critical path (#13502)

* ci: split release guards into parallel groups

Squashed onto current main after #13501 merged.

* test: include split release groups in guard matrix contract

* test: include split release groups in guard matrix contract

* fix: use current Greptile review mention

* fix: use current Greptile review mention

* fix: use current Greptile review mention

* test: reject legacy Greptile app mention

* ci: skip Linux preflight when macOS is unrouted (#13550)

* ci: skip macOS preflight when macOS is unrouted

* test(ci): cover skipped macOS preflight routing

* test(ci): preserve preflight contract migration marker

* ci: ignore unrelated review status comment churn

* test: pin unrelated comment filtering

* docs: record review comment filtering

* fix: use documented Greptile review trigger

* fix: use documented Greptile review trigger

* fix: use documented Greptile review trigger

* fix: use documented Greptile review trigger

* Speed up CI critical path and remove obsolete review gate

Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route.

* docs: clarify eligible review gate triggers

* test: exercise trusted review request path

* CI: route tagged iOS entitlement guard to release-ios

* ci: route tagged iOS entitlement guard to release-ios

* test: own tagged iOS entitlement guard in release-ios

---------

Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps

* Enforce Cloud display provenance and independent guest displays

* Keep display creation compatible with baked Cloud images

* Fix guest display target wiring and session supervision

* Harden embedded display helper and Dock restore ownership

* Close Cloud display lifecycle gaps

* Harden display discovery and helper restart recovery

* Finish Cloud display build and readiness guards

* Preserve display state and bind guest listeners privately

* Invalidate display catalogs when VM state changes

* Preserve Dock display duplication identity

* Preserve Cloud display refresh and browser locations

* Run guest display service as the desktop user

* Align Ghostty submodule with current main

* Invalidate terminal Cloud navigation callbacks

* Keep guest display ports out of forwarded resources

* Complete additional display recovery paths

* Synchronize guest profile and slow-route readiness

* Finish guest display startup and restore routing

* Keep unresolved display restores retryable

* Fence guest discovery to provider lifetime

* test: cover display transport recovery and duplication state

* fix: preserve Cloud displays during transport recovery

* test: preserve display identity across browser reconfiguration

* fix: retain display identity across route reconfiguration

* test: cover route observation after display reconfiguration

* fix: retain Cloud restore lifecycle state

* test: drop Cloud provenance after external navigation

* fix: clear Cloud provenance on external browser navigation

* test: cover display catalog and readiness cancellation

* fix: fence display catalog and readiness lifecycles

* test: cover delayed display restore and scoped helpers

* fix: complete display restore and supervisor isolation

* fix: require discovered guest display resources

* test: cover guest component recovery

* fix: preserve Cloud provenance and supervise displays

* test: reject failed display catalog responses

* fix: fence display discovery by response and auth

* test: filter untrusted display restore targets

* fix: fence display restore targets and VM kind

* test: fence browser Cloud service identity

* test: exercise recovered display supervision

* fix: recover display supervisors and port identity

* test: recover scoped display process commands

* fix: recover scoped display processes by command

* test: cover Cloud restore and destination comment fixes

* fix: address Cloud display review comments

* test: cover display port ownership and recovery

* fix: harden Cloud display supervisor and route lifecycle

* test: stay within Swift file budget

* fix: sanitize display errors and readiness probes

* fix: restore Cloud resources in Dock scopes

* fix: recover global Dock projections and daemon readiness

* fix: preserve Dock connections across Cloud route changes

* fix: bound display startup and preserve duplicate URLs

* fix: defer Cloud activation for hidden restores

* fix: preserve ownership checks across latest main merge

* fix: remove duplicate projection query declarations

* fix: restore provider display lifecycle after main merge

* fix: use merged hostname route API

* fix: restore New Display hover button after main merge

The latest origin/main merge moved CloudTreeRowHoverButtons into its own
file, and the conflict resolution kept main's copy, which dropped the
displays-pool New Display button and its hasButtons entry. Re-apply them
in the new file, and restore the blank lines the resolution stripped from
SurfaceCatalog.swift so the PR diff stays limited to behavior changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: keep SurfaceCatalog within its line budget

The blank lines restored in the previous commit put the file seven lines
over the Swift file-length budget, so drop them again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: route cloud desktop clicks through portal

* chore: keep cloud fix within file budgets

* #13531: retire and background-reap cold warm-slot task state

Squashed onto current main after #13530 merged.

* fix: separate terminal stream and viewport lease lifetimes

* fix: keep viewport lease across UI output stream churn

* ci: dispatch #13474 follow-up iOS test

* ci: remove temporary #13474 follow-up dispatcher

* ci: run direct #13474 ownership test

* ci: remove temporary #13474 direct test workflow

* fix: keep cold-task cleanup moving past failures

* test: cover resilient cold-task cleanup

* fix(review): require proof for repaired findings

* devex: add edit-weighted build graph health report

Squashed onto current main.

* ci: skip Linux preflight when macOS is unrouted (#13550)

* ci: skip macOS preflight when macOS is unrouted

* test(ci): cover skipped macOS preflight routing

* test(ci): preserve preflight contract migration marker

* devex: anchor build graph reports to an immutable ref

* devex: keep build graph history tied to the selected commit

* test: cover immutable build graph report inputs

* Speed up CI critical path and remove obsolete review gate

Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route.

* CI: route tagged iOS entitlement guard to release-ios

* ci: route tagged iOS entitlement guard to release-ios

* test: own tagged iOS entitlement guard in release-ios

* devex: distinguish history commits from source-touch commits

* test: pin full-window and source-touch commit counts

---------

Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
* test: cover Cloud display ownership and readiness gaps

* Enforce Cloud display provenance and independent guest displays

* Keep display creation compatible with baked Cloud images

* Fix guest display target wiring and session supervision

* Harden embedded display helper and Dock restore ownership

* Close Cloud display lifecycle gaps

* Harden display discovery and helper restart recovery

* Finish Cloud display build and readiness guards

* Preserve display state and bind guest listeners privately

* Invalidate display catalogs when VM state changes

* Preserve Dock display duplication identity

* Preserve Cloud display refresh and browser locations

* Run guest display service as the desktop user

* Align Ghostty submodule with current main

* Invalidate terminal Cloud navigation callbacks

* Keep guest display ports out of forwarded resources

* Complete additional display recovery paths

* Synchronize guest profile and slow-route readiness

* Finish guest display startup and restore routing

* Keep unresolved display restores retryable

* Fence guest discovery to provider lifetime

* test: cover display transport recovery and duplication state

* fix: preserve Cloud displays during transport recovery

* test: preserve display identity across browser reconfiguration

* fix: retain display identity across route reconfiguration

* test: cover route observation after display reconfiguration

* fix: retain Cloud restore lifecycle state

* test: drop Cloud provenance after external navigation

* fix: clear Cloud provenance on external browser navigation

* test: cover display catalog and readiness cancellation

* fix: fence display catalog and readiness lifecycles

* test: cover delayed display restore and scoped helpers

* fix: complete display restore and supervisor isolation

* fix: require discovered guest display resources

* test: cover guest component recovery

* fix: preserve Cloud provenance and supervise displays

* test: reject failed display catalog responses

* fix: fence display discovery by response and auth

* test: filter untrusted display restore targets

* fix: fence display restore targets and VM kind

* test: fence browser Cloud service identity

* test: exercise recovered display supervision

* fix: recover display supervisors and port identity

* test: recover scoped display process commands

* fix: recover scoped display processes by command

* test: cover Cloud restore and destination comment fixes

* fix: address Cloud display review comments

* test: cover display port ownership and recovery

* fix: harden Cloud display supervisor and route lifecycle

* test: stay within Swift file budget

* fix: sanitize display errors and readiness probes

* fix: restore Cloud resources in Dock scopes

* fix: recover global Dock projections and daemon readiness

* fix: preserve Dock connections across Cloud route changes

* fix: bound display startup and preserve duplicate URLs

* fix: defer Cloud activation for hidden restores

* fix: preserve ownership checks across latest main merge

* fix: remove duplicate projection query declarations

* fix: restore provider display lifecycle after main merge

* fix: use merged hostname route API

* fix: restore New Display hover button after main merge

The latest origin/main merge moved CloudTreeRowHoverButtons into its own
file, and the conflict resolution kept main's copy, which dropped the
displays-pool New Display button and its hasButtons entry. Re-apply them
in the new file, and restore the blank lines the resolution stripped from
SurfaceCatalog.swift so the PR diff stays limited to behavior changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: keep SurfaceCatalog within its line budget

The blank lines restored in the previous commit put the file seven lines
over the Swift file-length budget, so drop them again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: route cloud desktop clicks through portal

* chore: keep cloud fix within file budgets

* #13531: retire and background-reap cold warm-slot task state

Squashed onto current main after #13530 merged.

* fix: separate terminal stream and viewport lease lifetimes

* fix: keep viewport lease across UI output stream churn

* ci: dispatch #13474 follow-up iOS test

* ci: remove temporary #13474 follow-up dispatcher

* ci: trim unused workflow-guard setup and duplicate capture work

Collapse #13483-#13486 onto the current split guard matrix.

* ci: run direct #13474 ownership test

* ci: remove temporary #13474 direct test workflow

* fix(iOS): preserve tagged App Group when signing supports it (#13541)

* fix(ios): preserve supported tagged App Groups

* ci: keep iOS-only tests off macOS runners

* ci: run tagged iOS signing regression on Linux

* ci: freeze legacy iOS test routing path

* fix(ios): harden tagged signing fallback detection

* fix(ios): fail closed on partial ASC signing credentials

* fix(ios): validate ASC key path before device signing

* chore(ios): report tagged device signing backend

* docs(ios): keep cheap regressions off macOS routing

* test(ios): bind fallback entitlements to retry build

* ci: catch nested iOS-only test routing footguns

* test(iOS): bind fallback entitlements to retry command

* fix(iOS): correct retry assertion pattern

* fix: keep cold-task cleanup moving past failures

* test: cover resilient cold-task cleanup

* fix(review): require proof for repaired findings

* iOS: keep the composer bar out of the home-indicator band when the terminal disconnects (#13471)

* iOS: add failing disconnected-composer-seat fixture and regression test (#13470)

CMUX_UITEST_WORKSPACE_DETAIL_DISCONNECTED=1 mounts a workspace shell whose
one retained terminal is Disconnected, with no Mac or sign-in; scenario
drop-after-focus starts connected, focuses the composer at t+2s (real
keyboard), and drops the Mac to unavailable at t+9s.

The new XCUITest rides the dock probe through the raise and the
blocked-input resign, waits for the settled keyboard-down rest, then
asserts the dock's constraint-resolved bottom edge leaves the whole bottom
safe area below it. On the iOS <=26 keyboard-guide seat the dock instead
rests at the raw screen bottom, so this test fails until the fix.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* iOS: floor the keyboard-guide dock seat at the bottom safe area (#13470)

With the keyboard up over a connected terminal, the Mac dropping to
unavailable blocks input, which resigns the keyboard. After that show->hide
cycle UIKeyboardLayoutGuide rests at the RAW host bottom instead of the
bottom safe area (usesBottomSafeArea notwithstanding), so the accessory
toolbar and composer bar land inside the home-indicator band -
permanently, because blocked input means no keyboard event ever re-seats
the guide.

Add a required dock.bottom <= host.bottom - resolvedBottomSafeAreaInset
floor, active only with the guide seat, and downgrade the guide equality to
999 so it yields exactly the clamped distance when the guide rests too low.
The floor is slack whenever the keyboard holds the guide higher, follows
the same resolved-inset sources as the plain seat, and deactivates with the
guide in the chrome-hidden state (whose dock parks at the raw bottom by
design). The iOS 27 notification seat already computes from the resolved
inset and is unaffected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* Split the release guard critical path (#13502)

* ci: split release guards into parallel groups

Squashed onto current main after #13501 merged.

* test: include split release groups in guard matrix contract

* test: include split release groups in guard matrix contract

* ci: skip Linux preflight when macOS is unrouted (#13550)

* ci: skip macOS preflight when macOS is unrouted

* test(ci): cover skipped macOS preflight routing

* test(ci): preserve preflight contract migration marker

* ci: install bashlex only in its release owner

* test: pin release-only bashlex ownership

* Speed up CI critical path and remove obsolete review gate

Start macOS validation after cheap static checks, remove the obsolete agent review gate workflow, and fix the stale iOS guard matrix route.

* ci: port guard setup ownership to split release groups

* test: pin split guard setup ownership

* CI: route tagged iOS entitlement guard to release-ios

* ci: route tagged iOS entitlement guard to release-ios

* test: own tagged iOS entitlement guard in release-ios

* ci(iOS): resolve manual test refs before checkout (#13566)

* ci(ios): resolve manual test refs to full SHAs

* test(ci): cover manual iOS short-SHA dispatches

* test(ci): fix iOS workflow job parser

* ci: run iOS dispatch-ref regression on Linux

* iOS: allow all photo library task attachments (#13441)

* iOS: allow all photo library task attachments

* iOS: export Foundation for recovery API

* iOS: accept video attachments in terminal composers

* iOS: show videos in composer photo pickers

* Clarify composer picker comments

* Keep photo library attachment picker unfiltered

* Bound Photos library attachment transfers

* Make Photos attachment timeout authoritative

* ci: route tagged iOS entitlement guard to release-ios

* Add structured iOS connectivity diagnostics to Axiom (#13459)

* Add structured iOS connectivity diagnostics to Axiom

* refactor: move telemetry helper to file scope

* refactor: keep diagnostic bounds in payload assembly

* fix: bound event surface telemetry

---------

Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant