Skip to content

test(ci): avoid self-hosted guard SIGPIPE - #13630

Merged
teamleaderleo merged 3 commits into
mainfrom
fix/ci-self-hosted-guard-sigpipe
Sep 22, 2026
Merged

teamleaderleo merged 3 commits into
mainfrom
fix/ci-self-hosted-guard-sigpipe

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fix the preflight guard crash exposed by larger workflow job blocks.

tests/test_ci_self_hosted_guard.sh runs under pipefail. Its permissions parser exited awk immediately after the first permissions stanza, which can close the pipe while the upstream printf is still writing a large admission_block. That turns an otherwise successful guard into exit 1 with:

printf: write error: Broken pipe

Keep consuming the block after capturing the permissions stanza instead of exiting early. The parsed permission set is unchanged.

Observed on #13614 preflight job 106639077119.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes preflight guard crashes in tests/test_ci_self_hosted_guard.sh caused by SIGPIPE from printf under pipefail.

  • The permissions parser no longer exits awk early; it keeps consuming the block after capturing the permissions, so large admission_blocks no longer break the guard with printf: write error: Broken pipe. The parsed permission set is unchanged.
  • The remaining printf-to-grep pipelines were replaced with grep here-strings to eliminate the rest of the SIGPIPE risk.

Written for commit 43b258b. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved macOS self-hosted admission and observer validation checks to avoid premature command termination.
    • Increased reliability when processing permissions-related input under strict shell error handling.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c6a0b861-5f46-4c82-84c0-c95c0498cdff

📥 Commits

Reviewing files that changed from the base of the PR and between 38ced03 and 43b258b.

📒 Files selected for processing (1)
  • tests/test_ci_self_hosted_guard.sh

Included review availability: Your plan provides up to 10 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The CI self-hosted guard now consumes complete permissions input and uses here-strings for admission and observer checks. These changes prevent upstream printf termination under pipefail.

Changes

CI guard pipeline handling

Layer / File(s) Summary
Pipe-safe guard validation
tests/test_ci_self_hosted_guard.sh
The permissions parser continues consuming input after completion. Admission and observer validation checks use here-strings instead of piped printf input.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 43b25

The CI guard preserves its validation behavior while avoiding pipefail-related failures, so it is ready to merge.

🚥 Pre-merge checks | ✅ 23 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the root cause and implementation, but it omits the required Testing section and Checklist. It also does not state whether a demo video is unnecessary or provide review-status… Add a Testing section with commands and verification results. Add the repository Checklist with accurate selections. State that a demo video is not applicable, if appropriate, and include the required review trigger or explain its status.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the CI self-hosted guard SIGPIPE fix, which matches the primary change.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The authoritative diff changes only tests/test_ci_self_hosted_guard.sh. It adjusts awk/grep pipelines to avoid SIGPIPE under pipefail. It introduces no Cloud terminal creation, transport…
Cmux Swift Actor Isolation ✅ Passed PASS: The pull request changes only tests/test_ci_self_hosted_guard.sh. It introduces no production Swift changes and no Swift actor-isolation behavior.
Cmux Swift Blocking Runtime ✅ Passed The pull-request range changes only tests/test_ci_self_hosted_guard.sh (10 additions, 5 deletions). It introduces no production Swift code and no blocking or timing-based Swift synchronization. The …
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only tests/test_ci_self_hosted_guard.sh (10 additions, 5 deletions). The patch contains no browser, WebKit, AppKit, socket-worker, or main-actor automation changes. Bo…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only tests/test_ci_self_hosted_guard.sh; the authoritative diff contains no Swift files or production Swift changes. The expensive synchronous load check is therefore not ap…
Cmux Cache Substitution Correctness ✅ Passed PASS: The authoritative PR diff changes only tests/test_ci_self_hosted_guard.sh, a shell test file. It introduces no production Swift, TypeScript, or JavaScript changes and does not modify a persist…
Cmux No Hacky Sleeps ✅ Passed PASS: The PR changes only tests/test_ci_self_hosted_guard.sh, which is test-only scaffolding. The diff adds no sleep, timer, polling, fixed backoff, or wall-clock wait. It only keeps awk input c…
Cmux Algorithmic Complexity ✅ Passed PASS: The pull request changes only tests/test_ci_self_hosted_guard.sh, which is test-only code covered by the rule's explicit pass condition. The changed awk parser consumes one input stream, and…
Cmux Swift Concurrency ✅ Passed PASS: The reviewed range changes only tests/test_ci_self_hosted_guard.sh, a shell test file. The diff contains no Swift files or Swift concurrency code, so it does not introduce or expand any covere…
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only tests/test_ci_self_hosted_guard.sh. The authoritative diff contains no Swift files or Swift code, so the @concurrent check is not applicable.
Cmux Swift Package Boundaries ✅ Passed PASS: The reviewed range changes only tests/test_ci_self_hosted_guard.sh, a shell test. It introduces no production Swift changes and therefore does not violate the Swift package boundary rule.
Cmux Swiftpm Lockfiles ✅ Passed The authoritative PR diff changes only tests/test_ci_self_hosted_guard.sh. It does not change a SwiftPM package, Package.resolved, .gitignore, workflow, Xcode project, or dependency file. The Sw…
Cmux Swift Logging ✅ Passed The pull request changes only tests/test_ci_self_hosted_guard.sh. It adds no Swift, app/runtime, or production logging code. The custom Swift logging check is therefore not applicable.
Cmux User-Facing Error Privacy ✅ Passed PASS. The PR changes only tests/test_ci_self_hosted_guard.sh, a CI regression test invoked by the CI guard workflow. The changed lines adjust awk consumption and grep input handling; they add no…
Cmux Full Internationalization ✅ Passed PASS: The authoritative diff changes only tests/test_ci_self_hosted_guard.sh. It updates shell test parsing and SIGPIPE-safe pipelines; its echo strings are test diagnostics, not production user-f…
Cmux Swiftui State Layout ✅ Passed The authoritative pull-request diff changes only tests/test_ci_self_hosted_guard.sh. It contains shell/awk/grep updates and no SwiftUI, Swift, or state-layout changes. The custom check is therefore …
Cmux Architecture Rethink ✅ Passed PASS: The authoritative diff changes only tests/test_ci_self_hosted_guard.sh (+10/-5) and contains no Swift files or Swift architectural changes. The edits are local shell correctness fixes that kee…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only tests/test_ci_self_hosted_guard.sh. It adds no Swift code and does not add or modify any cmux-owned auxiliary window. The auxiliary-window close-shortcut rule is …
Cmux Source Artifacts ✅ Passed PASS: The PR changes only tests/test_ci_self_hosted_guard.sh, a tracked hand-written test script. The diff contains shell logic and comments only. No logs, screenshots, caches, build output, scratch…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The pull request changes only tests/test_ci_self_hosted_guard.sh. It changes shell-script parsing and grep pipelines. It does not modify any Swift file under a production Sources/ path, so it cann…
Full details: Description check

Explanation

The description explains the root cause and implementation, but it omits the required Testing section and Checklist. It also does not state whether a demo video is unnecessary or provide review-status confirmations.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 22, 2026 09:49
@teamleaderleo
teamleaderleo merged commit b1edf82 into main Sep 22, 2026
33 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant