Skip to content

ci: default the PR suite policy and R2 cache for fork pull requests - #13717

Merged
teamleaderleo merged 2 commits into
mainfrom
ci/fork-pr-variable-defaults
Sep 22, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
ci/fork-pr-variable-defaults

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Pull requests from forks don't receive repository variables. In #13275's CI run (head teamleaderleo:docs/writing-guidance, a docs-only change), the changes job logged PULL_REQUEST_POLICY: and CI_CACHE_R2_PUBLIC_URL: as empty. So choose_ci_suite.py returned full_suite=true. That scheduled all six app-host shards, the lag build and package tests on the Blacksmith macOS pool. The shards are red on main for unrelated reasons (#13643). Every cache restore also missed, because the URL and CI_CACHE_BACKEND were empty.

Same-repo PRs get the variables. On #13688 the same step picked compile-only, and swift-package-tests was skipped. 11 of teamleaderleo's open PRs are fork-headed.

At 17:00 UTC today, the blacksmith-6vcpu-macos-15 pool had 9 jobs running and 22 queued, with the oldest queued 171 minutes. #13688's compile admission was created at 15:14 and started at 16:51. The full-suite fork runs add to that queue. I didn't measure how much of it they account for.

Resulting behavior

When a variable is absent, each defaults to the value the repository already sets today:

  • CI_PULL_REQUEST_SUITE defaults to compile-only (ci.yml's suite step). Fork PRs now get the same compile-only tier as same-repo PRs, and full-ci still opts one in.
  • CI_CACHE_R2_PUBLIC_URL defaults to https://ci-cache.cmux.com in ci.yml, ci-macos.yml, test-ios.yml and cli-pipe-regressions.yml. It's a public read URL, not a secret.
  • CI_CACHE_BACKEND defaults to r2 in ci-macos.yml's restore steps.

Same-repo runs are unchanged while the variables are set.

Validation and remaining gap

  • The tests that reference these workflows pass locally, as does tests/test_ci_self_hosted_guard.sh. test_current_cli_workflow.py, test_ci_change_areas.py and test_check_ghostty_zig_workflows.py fail the same way on clean main.
  • Remaining gap: this PR is same-repo, so its own run doesn't exercise the fork path. The first fork-headed PR run after merge will show it.
  • Separate problem: the Blacksmith macOS-15 queue is capacity-bound regardless, since ci: route pull-request macOS jobs to Blacksmith, keep overflow for the rest #13658 routed all PR macOS jobs there. Overflow to Warp is a repository-variable decision (MACOS_RUNNER_PR) and is not part of this change.

Part of #13095.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes CI for fork pull requests, which don't receive repository variables and so ran the full macOS suite with cold caches on every push.

Fork PRs now default to the compile-only suite and the R2 cache URL and backend, matching what same-repo PRs get. Same-repo runs are unchanged since their variables are still set.

Written for commit b7b254f. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Improved CI workflow defaults for cache configuration when repository settings are unavailable.
    • Fork pull requests now default to compile-only validation when no policy is configured.
    • Added a fallback cache service URL for CI, macOS, iOS, and CLI regression workflows.
    • Cache operations now use the standard r2 backend when no backend is explicitly selected.

Pull requests from forks do not receive repository variables. Their CI runs
saw an empty CI_PULL_REQUEST_SUITE, so choose_ci_suite.py picked the full
macOS suite (six app-host shards, lag build, package tests) on every push,
and an empty CI_CACHE_R2_PUBLIC_URL / CI_CACHE_BACKEND, so every restore
missed. Default each to the value the repository already sets.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4272edaf-b3d4-426a-9583-32bdd32e6ebf

📥 Commits

Reviewing files that changed from the base of the PR and between fa09041 and b7b254f.

📒 Files selected for processing (4)
  • .github/workflows/ci-macos.yml
  • .github/workflows/ci.yml
  • .github/workflows/cli-pipe-regressions.yml
  • .github/workflows/test-ios.yml

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

CI workflows now define fallback values for the cache public URL, macOS cache backends, and pull request policy when corresponding configuration is unavailable.

Changes

CI default configuration

Layer / File(s) Summary
Cache URL fallbacks
.github/workflows/ci-macos.yml, .github/workflows/ci.yml, .github/workflows/cli-pipe-regressions.yml, .github/workflows/test-ios.yml
Cache-related workflows now use https://ci-cache.cmux.com when CI_CACHE_R2_PUBLIC_URL is unset.
macOS cache backend fallbacks
.github/workflows/ci-macos.yml
macOS cache restore steps now use r2 when no cache backend is configured.
Pull request policy fallback
.github/workflows/ci.yml
The pull request policy now uses compile-only when CI_PULL_REQUEST_SUITE is unset.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to b7b25

The CI defaults are internally consistent and no merge-blocking behavior is established.

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: defaulting the PR suite policy and R2 cache for fork pull requests.
Description check ✅ Passed The description provides a detailed problem statement, resulting behavior, testing information, and known limitations. It does not use the template's exact section headings and omits the review-trigge…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS — the pull request changes only GitHub Actions defaults for CI suite selection and cache URL/backend values. The authoritative diff contains no Cloud terminal creation, cmux-tui transport, manual…
Cmux Swift Actor Isolation ✅ Passed The pull-request diff changes only four GitHub Actions YAML workflows. It introduces no Swift production code, so it cannot introduce or worsen the specified Swift actor-isolation mistakes.
Cmux Swift Blocking Runtime ✅ Passed The PR changes only four YAML workflow files. The authoritative diff contains no Swift files and adds only GitHub Actions expressions and comments for cache URLs, cache backends, and PR suite policy. …
Cmux Browser Automation Off-Main ✅ Passed The PR changes only four GitHub Actions workflow files. The authoritative patch contains no browser commands, WebKit/AppKit access, worker-router changes, or policy-test changes. It does not introduce…
Cmux Expensive Synchronous Load ✅ Passed The authoritative PR diff changes only four GitHub Actions workflow YAML files. It adds CI cache URL/backend defaults and a pull-request suite policy default. It does not add or move Swift code, agent…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only four GitHub Actions YAML workflows. It does not replace a fresh authoritative read in production Swift, TypeScript, or JavaScript persistence, history, undo, or sna…
Cmux No Hacky Sleeps ✅ Passed PASS. The pull request changes only four GitHub Actions workflow YAML files. The diff adds cache URL/backend and suite-policy defaults; it adds no sleep, timer, polling, retry delay, or wall-clock wai…
Cmux Algorithmic Complexity ✅ Passed The PR changes only four .github/workflows/*.yml files. The added lines set GitHub Actions environment defaults and cache expressions. They add no production Swift, TypeScript, JavaScript, shell, or…
Cmux Swift Concurrency ✅ Passed PASS: The authoritative PR diff changes only four GitHub Actions workflow YAML files. It adds cache URL/backend fallbacks and the compile-only policy expression. It changes no Swift source or Swift …
Cmux Swift @Concurrent ✅ Passed The pull request changes only four GitHub Actions workflow files. The review-scoped diff contains no Swift source changes, so the Swift @concurrent annotation check is not applicable.
Cmux Swift Package Boundaries ✅ Passed PASS: The authoritative pull-request diff changes only four GitHub Actions workflow YAML files. It contains no production Swift changes or Swift package target changes, so the Swift package boundary r…
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only four workflow files. The diff changes CI cache URL/backend defaults and the pull-request suite policy. It does not change a cmux-owned .gitignore, Package.swift, Xcode package …
Cmux Swift Logging ✅ Passed PASS: The PR changes only four GitHub Actions workflow files. The authoritative diff contains no Swift files and adds or changes no logging statements. The Swift logging rule is therefore not applicab…
Cmux User-Facing Error Privacy ✅ Passed The PR changes only GitHub Actions workflow configuration and CI cache/suite defaults. The changed CI_CACHE_R2_PUBLIC_URL, CI_PULL_REQUEST_SUITE, and cache backend expressions feed internal CI rou…
Cmux Full Internationalization ✅ Passed PASS — The authoritative PR diff changes only four .github/workflows/*.yml CI files. The changes add CI environment-variable defaults (https://ci-cache.cmux.com, r2, and compile-only) and deve…
Cmux Swiftui State Layout ✅ Passed PASS: The pull request changes only four GitHub Actions workflow YAML files. The authoritative diff contains no SwiftUI, Swift, AppKit, or source-code changes, so the SwiftUI state-layout criteria do …
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only four GitHub Actions YAML workflows. The diff adds cache URL/backend fallbacks and a pull-request suite policy default. It introduces no Swift code, lifecycle wiring…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull-request diff changes only four GitHub Actions YAML workflows. It contains no Swift files or Swift window code, so the auxiliary-window close-shortcut rule is not applicable.
Cmux Source Artifacts ✅ Passed All four changed paths are hand-written .github/workflows/*.yml configuration files. The diff changes CI expressions and explanatory comments only. It adds no logs, screenshots, recordings, temporar…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The authoritative PR diff changes only four GitHub Actions workflow files. It contains no Swift file under a production Sources/ path, so it introduces no test or debug seam covered by this ch…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit 88d80ab into main Sep 22, 2026
46 of 48 checks passed
teamleaderleo added a commit that referenced this pull request Sep 22, 2026
…re (#13777)

* ci: add a guard for repository variables with no cheap default

Fork pull requests receive no repository variables, so every `vars.X` a
workflow reads can arrive empty. #13717 found CI running the full macOS
suite and missing every cache restore for that reason, and fixed the
sites it found. Nothing stopped the next copy of the same expression
from landing without a default.

This commit adds the guard alone, so CI shows it failing on the 21 sites
that still read a repository variable with no literal fallback. The next
commit writes those defaults.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: write the cheap default next to every bare repository variable

nightly.yml read `vars.CI_CACHE_BACKEND` at 13 sites and test-ios.yml at
5 more with no fallback, so a run without repository variables restored
from no cache and rebuilt from cold. nightly.yml also read
CI_CACHE_R2_PUBLIC_URL bare while ci.yml, ci-macos.yml and test-ios.yml
already defaulted it, and docs-deploy-reusable.yml had a `runs-on:` that
an empty LINUX_RUNNER leaves unschedulable.

Each now carries the value the repository already sets, which is also
the cheap one: the compile-only suite, and the cache that actually has
the objects.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant