Skip to content

CI: land trusted fleet peer artifact source on current main - #13575

Closed
teamleaderleo wants to merge 12 commits into
mainfrom
ci-peer-artifact-source-refresh
Closed

teamleaderleo wants to merge 12 commits into
mainfrom
ci-peer-artifact-source-refresh

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Supersedes #13540 on current main.

#13540 accumulated a well-tested peer/local immutable artifact implementation while main moved more than 100 commits underneath it. This PR reapplies the final tested feature diff onto current main, preserving newer router/guard changes rather than merging the stale workflow snapshot.

Source order

exact node-local object
-> trusted same-site peer
-> [optional R2 when configured]
-> GitHub Actions artifact
-> rebuild

R2 remains optional. CI_ARTIFACT_R2_URL unset means peer miss proceeds directly to GitHub.

Preserved implementation

  • exact transport-independent product identity plus producer run attempt;
  • immutable node-local publication, fill coalescing, leases and whole-object reclamation;
  • HTTPS exact-object peer source with no list/write endpoints;
  • runner-local bearer credential file;
  • monotonic per-request deadline rearmed before each underlying receive;
  • bounded peer-server socket time and active requests;
  • corrupt/truncated/mismatched peer => miss/fallback;
  • same-run provider provenance recovery for a peer hit during GitHub API outage;
  • local -> peer -> optional R2 -> GitHub workflow order;
  • lookup/transfer/bytes/restore receipts;
  • concurrency, drain, cancellation, corrupt/mid-transfer failure, two-node and six-consumer regression coverage.

Refresh mechanics

Files untouched by current main were carried forward exactly from #13540. The four files that changed on main were merged narrowly:

  • .github/workflows/ci.yml
  • scripts/ci/detect_linux_guard_changes.py
  • tests/test_ci_change_areas.py
  • tests/test_ci_linux_guard_routing.py

Current main's newer review-fabric/router coverage is retained.

Follow-up stack

Once this PR is green and merged, #13540 can close as superseded without losing work.

Refs teamleaderleo/glaeda#1068, #13384, #13364, #13365.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Reapplies the tested trusted-fleet peer artifact source from #13540 onto current main, giving macos test lanes a peer fetch between the node-local cache and R2 before falling back to GitHub artifacts. #13540 went stale as main moved more than 100 commits, so this lands only the final tested diff while keeping the newer router/guard coverage intact.

Source order

  • exact node-local object → trusted same-site peer → optional R2 (CI_ARTIFACT_R2_URL) → GitHub Actions artifact → rebuild.
  • R2 stays optional: with CI_ARTIFACT_R2_URL unset, a peer miss proceeds directly to GitHub.

Refresh mechanics

  • Adds scripts/ci/peer_product_source.py, an HTTPS exact-object peer source with HEAD/GET only, no list or write endpoints, bearer-token auth, bounded socket time and active requests, and one monotonic deadline rearmed before each receive.
  • Corrupt, truncated, or mismatched peer responses become misses and fall through to the next source.
  • producer_run_attempt is folded into product identity; same-run provider provenance recovery keeps a peer hit usable during a GitHub API outage.
  • Untouched files carried exactly from CI: fetch immutable products from trusted fleet peers #13540; the four that changed on main were merged narrowly to preserve the newer guard and CI-change routing tests.
  • Restore receipts now record lookup source plus peer lookup/transfer seconds and bytes.

Written for commit 535b801. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 6 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6f5663e6-363e-4a18-92ec-7ce52f23bd0b

📥 Commits

Reviewing files that changed from the base of the PR and between 0af2e7f and 535b801.

📒 Files selected for processing (12)
  • .github/workflows/ci-artifact-transport.yml
  • .github/workflows/ci-macos.yml
  • .github/workflows/ci.yml
  • scripts/ci/detect_ci_change_areas.py
  • scripts/ci/detect_linux_guard_changes.py
  • scripts/ci/node_product_cache.py
  • scripts/ci/peer_product_source.py
  • scripts/ci/restore-app-host-test-product.sh
  • tests/test_ci_change_areas.py
  • tests/test_ci_linux_guard_routing.py
  • tests/test_node_product_cache.py
  • workers/ci-artifacts/test/consumer-workflow.test.mjs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Copy link
Copy Markdown
Collaborator Author

Superseded by merged #13540. The peer transport is now on main; #13576 has been retargeted directly to main for the next product-layer slice.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant