Skip to content

test: pin persistent control-plane guard groups - #13609

Merged
teamleaderleo merged 6 commits into
mainfrom
fix/guard-build-graph-ownership
Sep 22, 2026
Merged

teamleaderleo merged 6 commits into
mainfrom
fix/guard-build-graph-ownership

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

#13607 landed the production ownership repair that originally motivated this PR.

This branch now keeps only the useful follow-up regression: assert the exact workflow-guard-tests groups selected for persistent-Mac/build-health control-plane inputs.

The existing test already checks that these paths select the outer Linux guard lane. This tightens it to prevent accidental fan-out inside that lane:

  • helper scripts select preflight;
  • test files select preflight + quality-determinism.

No production routing or ownership data changes remain in this PR.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b137b5fe-3a37-4226-81bd-eca092b13839

📥 Commits

Reviewing files that changed from the base of the PR and between 6cfa1b0 and bf5bb34.

📒 Files selected for processing (2)
  • scripts/ci/workflow_guard_groups.py
  • tests/test_ci_linux_guard_routing.py

Included review availability: Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The change adds workflow ownership mappings for build graph health tooling and updates persistent macOS routing tests to verify both guard outputs and routed Linux test groups.

Changes

CI guard updates

Layer / File(s) Summary
Guard ownership mappings
scripts/ci/workflow_guard_groups.py
Adds step ownership for nightly prune Python setup and build graph health validation. Adds preflight ownership for the build graph health script and test.
Routing assertions
tests/test_ci_linux_guard_routing.py
Adds per-path expectations for routed Linux test groups while preserving guard-lane output checks.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to bf5bb

This updates CI guard ownership and validates routing behavior without an identified production or merge-blocking risk.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: repairing build graph health guard ownership.
Description check ✅ Passed The description clearly explains the regression, the ownership changes, the routing test changes, and the intended result. It lacks the template's explicit Testing and Checklist sections, but it provi…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The pull request changes only CI guard ownership data and Linux guard-routing test assertions. The authoritative diff contains no Cloud terminal creation, cmux-tui transport, PTY readiness, inpu…
Cmux Swift Actor Isolation ✅ Passed PASS — The pull request changes only two Python files: scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift or other production Ap…
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only two Python files: the CI ownership manifest and its routing test. The authoritative diff contains no Swift files or Swift runtime synchronization changes. The cmux Swift …
Cmux Browser Automation Off-Main ✅ Passed PASS. The authoritative PR diff changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. It adds CI ownership entries and routing assertions. It does not change b…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The diff contains Python ownership data and routing-test assertions. It adds no producti…
Cmux Cache Substitution Correctness ✅ Passed The pull request changes only two Python files: scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The diff adds CI ownership entries and routing assertions. It does not…
Cmux No Hacky Sleeps ✅ Passed PASS: The pull request changes only two Python CI ownership/routing files. The diff adds ownership mappings and strengthens assertions. It introduces no sleep, timer, polling, fixed delay, or wall-clo…
Cmux Algorithmic Complexity ✅ Passed PASS. The pull request changes only static Python ownership tables and a test-only expected-group map/assertions. It introduces no production Swift, TypeScript, JavaScript, shell, or runtime algorithm…
Cmux Swift Concurrency ✅ Passed The pull-request range changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. It contains no Swift files or Swift concurrency changes. The custom check is there…
Cmux Swift @Concurrent ✅ Passed PASS: The PR changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The diff contains no Swift files or Swift async/isolation code, so it cannot introduce a `@c…
Cmux Swift Package Boundaries ✅ Passed The reviewed range changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. It contains no production Swift changes, so the Swift package boundary rule does not a…
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only CI ownership tables and a CI routing test. It does not change a SwiftPM package, Package.swift, Package.resolved, .gitignore, Xcode project, or workflow file. Therefore, the …
Cmux Swift Logging ✅ Passed PASS: The pull-request diff changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. It changes no Swift files and adds or materially changes no logging statement…
Cmux User-Facing Error Privacy ✅ Passed PASS — the PR changes only CI ownership tables and a CI routing regression test. The added entries map internal workflow steps and build-graph test inputs to guard groups, and the test asserts routing…
Cmux Full Internationalization ✅ Passed The pull request changes only CI ownership data in scripts/ci/workflow_guard_groups.py and routing assertions in tests/test_ci_linux_guard_routing.py. The added text is operational workflow identi…
Cmux Swiftui State Layout ✅ Passed PASS: The pull request changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift or SwiftUI changes, so the SwiftUI state-…
Cmux Architecture Rethink ✅ Passed The pull request changes only Python CI ownership data and Python routing tests. The authoritative diff contains no Swift architecture change and no sleeps, delayed dispatch, polling, locks, observers…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift, Objective-C, window, or close-shortcut c…
Cmux Source Artifacts ✅ Passed The diff changes only two intentional Python source/test files: scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. It adds ownership declarations and routing assertions.…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The pull request changes only two non-Swift files: scripts/ci/workflow_guard_groups.py and tests/test_ci_linux_guard_routing.py. The authoritative diff contains no Swift file, no production …
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

Copy link
Copy Markdown
Collaborator Author

Latest current-head proof: guards / workflow-guard-tests / ci, aggregate Guard status, and linux-preflight are all green after the final ownership correction. The manifest now matches the exact workflow-owned-step set 112/112 with zero missing/extra entries. The remaining active Mac compile is the router-edit fail-open path, not the regression this PR repairs.

@teamleaderleo
teamleaderleo merged commit 8909f5f into main Sep 22, 2026
58 of 61 checks passed
@teamleaderleo teamleaderleo changed the title Fix build graph health guard ownership test: pin persistent control-plane guard groups Sep 22, 2026
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
The Linux guard router kept a hand-written copy of every
workflow-guard-tests step (STEP_OWNERS) and every path those steps run
(PATH_OWNERS), and a test required the copy to equal the workflow. Two
PRs that each passed alone could land a copy that disagreed with the
workflow: #13535 added "Validate build graph health tooling" while
#13585 introduced the copy, and every PR failed guards until #13609.

Ownership now comes from the workflow. Each step's
`if: ${{ matrix.group == '<group>' }}` names its group and each path its
`run:` executes belongs to that group. The router reads ci-guards.yml
with a small line scanner, because the changes job runs on bare python3
without PyYAML; a test holds the scanner to yaml.safe_load field by
field. An unreadable workflow fails open to every group.

STEP_OWNERS is gone, and PATH_OWNERS keeps only the 24 indirect inputs
(imported scripts, the agent-chat working directory, the ghostty
submodule, skill files). Routing is unchanged for every path the old
tables knew. A step with an unknown group fails its own PR with the
exact file to edit.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant