Skip to content

CI: route tagged iOS entitlement guard to release-ios - #13556

Merged
teamleaderleo merged 2 commits into
mainfrom
fix-tagged-ios-release-guard
Sep 22, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
fix-tagged-ios-release-guard

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

The current release-guard split moved release checks from the retired release group into release-ios, release-notary, and release-tooling, but the tagged iOS device entitlement fallback step was left behind on matrix.group == 'release'.

That makes the current structural contract fail:

tests/test_ci_release_guard_structure.py explicitly rejects any remaining legacy release group.

This patch:

  • routes Validate tagged iOS device entitlement fallback to release-ios;
  • adds that step to the explicit release-ios ownership map.

No peer transport or app-host artifact behavior is changed here. This was surfaced while validating #13540 against current main and is split out so that PR can remain scoped.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes the tagged iOS device entitlement fallback guard so it runs under release-ios instead of the retired release group, and records it in the release-ios ownership map.

Written for commit 7fb2206. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes

    • Updated iOS release validation so tagged device entitlement fallback checks run in the correct release group.
  • Tests

    • Added coverage to verify the validation step is assigned to and gated by the iOS release group.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1a29f449-ffba-4738-8fcc-6eaeeb257941

📥 Commits

Reviewing files that changed from the base of the PR and between 0bbcbb3 and 7fb2206.

📒 Files selected for processing (2)
  • .github/workflows/ci-guards.yml
  • tests/test_ci_release_guard_structure.py

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The workflow now runs the tagged iOS device entitlement fallback validation for the release-ios matrix group. The structural test verifies this group assignment.

Changes

iOS release guard routing

Layer / File(s) Summary
Guard routing and validation
.github/workflows/ci-guards.yml, tests/test_ci_release_guard_structure.py
The workflow gates the tagged iOS device entitlement fallback step on matrix.group == 'release-ios'. The structural test expects and validates the same group.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 7fb22

The guard now runs under the intended release-ios group, with matching structural coverage. It is ready to merge.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: routing the tagged iOS entitlement guard to the release-ios group.
Description check ✅ Passed The description clearly explains what changed, why it changed, the affected structural test, and the scope limits. It omits the template's Testing, Review Trigger, and Checklist sections, but the core…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The PR changes only CI step routing and its ownership test: the tagged iOS entitlement check moves from matrix.group == 'release' to matrix.group == 'release-ios', and the expected map recor…
Cmux Swift Actor Isolation ✅ Passed PASS: The authoritative PR diff changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. It contains no production Swift changes, so it cannot introduce or worsen…
Cmux Swift Blocking Runtime ✅ Passed PASS: The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. No Swift files changed, and the added lines introduce no blocking or timing-based …
Cmux Browser Automation Off-Main ✅ Passed The pull request changes only CI workflow ownership and its structural test. The diff contains no changes to browser socket automation, browser.* commands, socketWorkerMethods, processV2Command,…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. The diff updates CI matrix ownership and its structural test. It adds no production Swif…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. The diff contains no production Swift, TypeScript, or JavaScript changes, and it d…
Cmux No Hacky Sleeps ✅ Passed PASS: The pull request changes only GitHub Actions YAML and a Python structural test. The runtime-no-hacky-sleeps rule explicitly excludes workflow YAML, and the diff introduces no fixed waits or timi…
Cmux Algorithmic Complexity ✅ Passed The PR changes only a CI workflow condition and a Python structural test. It introduces no production Swift, TypeScript, JavaScript, shell, or runtime algorithm. The complexity policy explicitly passe…
Cmux Swift Concurrency ✅ Passed PASS: The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. The diff contains no Swift code and introduces no Dispatch queues, Combine state, …
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. It contains no Swift changes, so the @concurrent annotation check is not applica…
Cmux Swift Package Boundaries ✅ Passed The reviewed range changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. It contains no Swift source or Swift package changes. The Swift package boundary check…
Cmux Swiftpm Lockfiles ✅ Passed PASS: The PR changes only CI workflow ownership and its structural test. It does not change a cmux-owned .gitignore, Package.swift, Xcode package references, or any SwiftPM Package.resolved file…
Cmux Swift Logging ✅ Passed PASS: The pull request changes only a GitHub Actions workflow and a Python structural test. It adds no Swift files or Swift logging statements, so the cmux Swift logging conditions do not apply.
Cmux User-Facing Error Privacy ✅ Passed PASS: The diff changes only an internal GitHub Actions matrix condition and a structural test expectation. The tagged entitlement command remains a CI test command, and no user-facing error, alert, AP…
Cmux Full Internationalization ✅ Passed PASS. The diff changes only a GitHub Actions matrix condition and a structural test ownership map. The changed text is CI configuration and test data, not user-facing Swift, web, metadata, API, markdo…
Cmux Swiftui State Layout ✅ Passed PASS. The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. The diff contains no SwiftUI code, state declarations, GeometryReader, lazy/list…
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. It changes CI step ownership from release to release-ios and updates the struc…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS — the pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. The authoritative diff contains no Swift files or standalone window code, so the …
Cmux Source Artifacts ✅ Passed The pull request changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. These are intentional CI configuration and test-source files. The diff adds no local out…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS. The authoritative PR diff changes only .github/workflows/ci-guards.yml and tests/test_ci_release_guard_structure.py. It contains no Swift file and no change under a production Sources/ pat…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo merged commit 76b343e into main Sep 22, 2026
44 of 51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant