Skip to content

ci: bound the suite coverage gate - #13820

Merged
teamleaderleo merged 2 commits into
manaflow-ai:mainfrom
teamleaderleo:codex/bound-suite-coverage
Sep 23, 2026
Merged

teamleaderleo merged 2 commits into
manaflow-ai:mainfrom
teamleaderleo:codex/bound-suite-coverage

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

The new suite-coverage job has no timeout, so the required CI guard rejects every merged PR test tree containing it. Add a five-minute bound to this short policy check.

Validation: ran tests/test_ci_required_checks_are_bounded.py against main 83a6294a1d; it failed specifically on suite-coverage. The same guard passes with this one-line change. This unblocks the guard failure observed on #13795 without changing test scheduling.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Adds a five-minute timeout to the suite-coverage CI job so the required CI guard no longer rejects PRs running it. This unblocks the guard failure on #13795 without changing test scheduling.

Written for commit 5942f76. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Added a five-minute time limit to the suite coverage check to prevent it from running indefinitely.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 7 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d1af2f9b-9f3e-465a-9c6c-42b1e878da2c

📥 Commits

Reviewing files that changed from the base of the PR and between 03b8e9a and 5942f76.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e0fa5638-bbd4-420d-a89a-f06e13a64658

📥 Commits

Reviewing files that changed from the base of the PR and between 83a6294 and 03b8e9a.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Changes

CI timeout configuration

Layer / File(s) Summary
Suite coverage timeout
.github/workflows/ci.yml
The suite-coverage job now has a five-minute timeout.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 03b8e

No concrete merge-blocking risk remains in this workflow-only change.

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely states that the suite coverage CI gate is now bounded.
Description check ✅ Passed The description explains what changed, why it changed, and how the change was validated. The Demo Video section is not required because this is not a UI change. The standard Testing, Review Trigger, a…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The authoritative diff changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage CI job. It does not change Cloud terminal creation, transport, session attach…
Cmux Swift Actor Isolation ✅ Passed The pull-request diff changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage job. It contains no Swift production changes, so it cannot introduce or worsen the s…
Cmux Swift Blocking Runtime ✅ Passed PASS: The authoritative pull-request diff changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage GitHub Actions job. It introduces no production Swift code or bl…
Cmux Browser Automation Off-Main ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml by adding timeout-minutes: 5 to the suite-coverage job. The diff contains no browser socket commands, WebKit/AppKit access, worker ro…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only .github/workflows/ci.yml. It adds timeout-minutes: 5 to the suite-coverage job. The diff contains no Swift files and no synchronous agent-history load change.
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml. It adds timeout-minutes: 5 to the suite-coverage CI job. It does not change production Swift, TypeScript, or JavaScript code, nor an…
Cmux No Hacky Sleeps ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml. It adds timeout-minutes: 5 to the suite-coverage GitHub Actions job. The rule explicitly excludes GitHub Actions workflow YAML, and …
Cmux Algorithmic Complexity ✅ Passed PASS: The PR changes only .github/workflows/ci.yml by adding timeout-minutes: 5 to the suite-coverage job. It introduces no production Swift, TypeScript, JavaScript, shell, or runtime algorithm,…
Cmux Swift Concurrency ✅ Passed The review-scoped diff changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage job. It changes no Swift files and introduces no Swift concurrency patterns covered…
Cmux Swift @Concurrent ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to suite-coverage. It changes no Swift source, so the @concurrent check is not applicable.
Cmux Swift Package Boundaries ✅ Passed The pull request changes only .github/workflows/ci.yml by adding timeout-minutes: 5 to suite-coverage. It contains no Swift changes, so the Swift package boundary check is not applicable.
Cmux Swiftpm Lockfiles ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage job. It does not change a .gitignore, Package.swift dependency, Xcode package r…
Cmux Swift Logging ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml by adding timeout-minutes: 5 to the suite-coverage job. It adds no Swift code and no logging behavior.
Cmux User-Facing Error Privacy ✅ Passed PASS. The pull request changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the internal suite-coverage CI job. The job's existing stderr messages are CI diagnostics, not a cmux …
Cmux Full Internationalization ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml by adding timeout-minutes: 5 to the suite-coverage CI job. This is operational CI configuration and adds no user-facing Swift, web, m…
Cmux Swiftui State Layout ✅ Passed PASS. The authoritative diff changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage CI job. It contains no SwiftUI changes, so the SwiftUI state-layout rules do …
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to the suite-coverage job. It contains no Swift architecture change and does not introduce any listed sym…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml and adds timeout-minutes: 5 to suite-coverage. The authoritative diff contains no Swift files or Swift window code, so the cmux auxil…
Cmux Source Artifacts ✅ Passed The pull request changes only .github/workflows/ci.yml. The added timeout-minutes: 5 line is a deliberate CI configuration change. It is not local tool output, a generated artifact, a cache, build…
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The pull request changes only .github/workflows/ci.yml. The authoritative diff contains no Swift files under a production Sources/ path, so this custom check is not applicable.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 23, 2026 00:38
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Aligned timeout placement with the identical fix already pushed on #13749 and #13795. This avoids Git independently merging the same YAML key at two locations when those branches land. The bounded-CI guard passes. No behavior change; auto-merge enabled.

@teamleaderleo
teamleaderleo merged commit a1d6749 into manaflow-ai:main Sep 23, 2026
34 of 35 checks passed
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* test: require push and pull_request path filters to agree

A workflow that filters both events writes its input list twice, and the two
copies can disagree without either pull request seeing it. Two already have:
ci-artifact-transport.yml guards nine paths on pull requests and not on push,
and cmux-skill-contract.yml omits a test its own job runs.

web-complexity.yml diverges on purpose -- a pull request must not be able to
queue the job that runs its own edit -- so it is declared in EXEMPTIONS with a
reason rather than left looking like a typo. An exemption whose workflow no
longer diverges is an error, so it cannot go stale.

The guard lives in testbox-broker-guard.yml, which deliberately carries no path
filter of its own: a parity check over path filters cannot be gated by one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: guard the same files on main that pull requests guard

ci-artifact-transport.yml listed 21 paths under pull_request and 12 under push,
so nine files were checked on pull requests and unguarded on main. Four of the
nine are test files the job itself executes, and tests/test_ci_selective_layer_wiring.py
reads .github/workflows/ci-macos.yml and asserts on its contents -- so a push to
main that broke the selective layer wiring ran nothing. The push list is the
wrong one: it omits inputs the job demonstrably reads.

cmux-skill-contract.yml had the same shape at one path: its job runs
tests/test_cmux_settings_jsonc.py, which only the pull_request filter named.

Both push lists now match their pull_request lists, and
tests/test_ci_workflow_path_filter_parity.py fails if they drift apart again.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: check review-fabric routing through the router, not its source text (#13788)

test_ci_executes_review_fabric_contracts grepped
scripts/ci/detect_linux_guard_changes.py for each review-fabric path as a
literal string. #13775 made the guard routes derived from PATH_OWNERS and from
ci-guards.yml's run: lines, so those literals are no longer in the file and the
test fails on a clean main -- taking preflight, Guard status, linux-preflight,
tests and ci-status down with it on every pull request routing that lane.

The routing is intact; only the check was stale. Assert the behaviour instead:
the path must route linux_guard_tests, and groups_for_path must explicitly own
it with preflight. That second assertion uses groups_for_path rather than
classify_test_groups because classify_test_groups falls open to every group for
an unknown path, and so would keep passing if ownership were dropped.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* test: preserve negated workflow path filter ordering

* ci: bound the suite coverage gate (#13820)

* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
* test(ci): reconcile the required-check tuple against GitHub

REQUIRED_CHECKS mirrors a list that lives in a repository ruleset, which
is not in this tree. Nothing today compares the two, so an admin adding a
required check leaves the tuple stale and every guard still green, while
pull requests wait on a context no workflow produces.

These cases cover the reconciliation that does not exist yet, over fixture
payloads so the guard lane stays offline. Most of them pin the fail-closed
rule: an unreadable, empty or unrecognised payload must raise rather than
report agreement, because a reconciliation that passes when it cannot read
its source is the bug being fixed.

Red until scripts/ci/required_status_checks.py lands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: reconcile the required checks on main against GitHub

The required status checks live in the `main` ruleset. REQUIRED_CHECKS was a
hand-kept copy of that list, and nothing compared the two: an admin could add
a required check and every guard in the tree stayed green while each pull
request waited on a context no workflow produces, with no red check to name
the cause.

scripts/ci/required_status_checks.py now owns the copy, and
.github/workflows/required-checks-drift.yml asks GitHub every six hours
whether it is still true. It checks two directions, because they fail
separately:

  - the live contexts against REQUIRED_CHECKS, in both directions;
  - each required context against what actually reported on the last ten
    merged pull request heads, which catches a renamed producing job. There
    the settings and the tuple still agree, and both name a phantom.

The reconciliation reads `repos/:owner/:repo/rules/branches/main`, not
`branches/main/protection`. docs/ci/derived-not-declared.md recorded this row
as blocked on a token with `administration: read` that PR CI must not hold;
that is true of the protection endpoint and not of the rulesets endpoint,
which returns the same contexts to an ordinary repository read and, on this
public repository, to no token at all. The workflow holds `contents: read`.

Every unreadable, empty or unrecognised response fails the job. A guard that
reports success when it could not read its source is the bug this fixes, so
it is not a shape the new code is allowed to take.

tests/test_ci_merge_queue_required_checks.py now imports the tuple instead of
declaring a second one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: check review-fabric routing through the router, not its source text (#13788)

test_ci_executes_review_fabric_contracts grepped
scripts/ci/detect_linux_guard_changes.py for each review-fabric path as a
literal string. #13775 made the guard routes derived from PATH_OWNERS and from
ci-guards.yml's run: lines, so those literals are no longer in the file and the
test fails on a clean main -- taking preflight, Guard status, linux-preflight,
tests and ci-status down with it on every pull request routing that lane.

The routing is intact; only the check was stale. Assert the behaviour instead:
the path must route linux_guard_tests, and groups_for_path must explicitly own
it with preflight. That second assertion uses groups_for_path rather than
classify_test_groups because classify_test_groups falls open to every group for
an unknown path, and so would keep passing if ownership were dropped.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* ci: bound the suite coverage gate (#13820)

* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Sep 23, 2026
…ile, not display name (#13793)

* test: pin workflow_run triggers to the files they name

`on.workflow_run.workflows:` matches a workflow's display `name:`. Renaming a
workflow for clarity stops every consumer from triggering, and nothing turns
red: the consumer simply never runs again. Four workflows depend on a name this
way, and `merge-group-fail-fast.yml` is the expensive one -- when it stops
firing, a doomed merge group runs its macOS jobs to the end and every queue
entry behind it waits.

This test requires each consumer to declare the workflow file it means, derives
the expected name from that file, and requires the fail-fast watcher to confirm
`github.event.workflow_run.path` before it cancels anything. It fails until the
next commit adds those declarations.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: identify the fail-fast watcher's source workflow by file

Each workflow_run consumer now declares the file whose display name its
`workflows:` filter spells out, so the pairing is written down in terms that do
not change when someone renames a workflow for clarity.

`merge-group-fail-fast.yml` also checks that identity at run time. The
workflow_run object carries `path` next to the presentation `name`, and display
names are not unique, so the watcher confirms it was started by
merge-group-policy-checks.yml before it cancels a CI run. The CI run it then
watches was already located by workflow file rather than by name.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: check review-fabric routing through the router, not its source text (#13788)

test_ci_executes_review_fabric_contracts grepped
scripts/ci/detect_linux_guard_changes.py for each review-fabric path as a
literal string. #13775 made the guard routes derived from PATH_OWNERS and from
ci-guards.yml's run: lines, so those literals are no longer in the file and the
test fails on a clean main -- taking preflight, Guard status, linux-preflight,
tests and ci-status down with it on every pull request routing that lane.

The routing is intact; only the check was stale. Assert the behaviour instead:
the path must route linux_guard_tests, and groups_for_path must explicitly own
it with preflight. That second assertion uses groups_for_path rather than
classify_test_groups because classify_test_groups falls open to every group for
an unknown path, and so would keep passing if ownership were dropped.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* ci: bound the suite coverage gate (#13820)

* ci: bound the suite coverage gate

* ci: align timeout placement with in-flight branch fixes

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@teamleaderleo
teamleaderleo deleted the codex/bound-suite-coverage branch September 23, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant