From 6f1333e302b64ba704f1de7df4f664c4ecb25e4b Mon Sep 17 00:00:00 2001 From: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:58:55 -0700 Subject: [PATCH 1/2] test: exercise workload source identity on a real checkout with a clean submodule --- tests/test_ci_workload_profiles.py | 38 ++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/tests/test_ci_workload_profiles.py b/tests/test_ci_workload_profiles.py index b998a566e962..b37e92699e85 100644 --- a/tests/test_ci_workload_profiles.py +++ b/tests/test_ci_workload_profiles.py @@ -488,6 +488,44 @@ def fake_git_text(*arguments: str) -> str: self.assertEqual(value["commit"], "1" * 40) + def test_source_identity_accepts_real_checkout_with_clean_submodule(self) -> None: + # The first line of real `git submodule status` output begins with a + # space for a clean gitlink, so the reader must keep leading whitespace. + def git(cwd: Path, *arguments: str) -> None: + subprocess.run( + [ + "/usr/bin/git", + "-c", "user.name=cmux", + "-c", "user.email=cmux@example.invalid", + "-c", "protocol.file.allow=always", + "-c", "init.defaultBranch=main", + *arguments, + ], + cwd=cwd, + check=True, + capture_output=True, + env={**profile.git_environment(), "GIT_CONFIG_NOSYSTEM": "1"}, + ) + + with tempfile.TemporaryDirectory() as directory: + base = Path(directory).resolve() + child = base / "child" + parent = base / "parent" + child.mkdir() + parent.mkdir() + git(child, "init", "-q") + (child / "file.txt").write_text("child\n", encoding="utf-8") + git(child, "add", "file.txt") + git(child, "commit", "-q", "-m", "child") + git(parent, "init", "-q") + git(parent, "submodule", "add", "-q", str(child), "vendor/child") + git(parent, "commit", "-q", "-m", "parent") + + with mock.patch.object(profile, "ROOT", parent): + value = profile.source_identity(None, None) + + self.assertEqual(value["repository"], "manaflow-ai/cmux") + def test_comparison_rejects_toolchain_identity_observation_mismatch(self) -> None: value = valid_result() value["toolchain"]["observations"]["python"] = "changed" From 97844b5e8785f3db88b1f3e18892d0c25a796864 Mon Sep 17 00:00:00 2001 From: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:59:39 -0700 Subject: [PATCH 2/2] ci: keep leading whitespace in workload profile git output git_text() stripped both ends of git output, so the first line of `git submodule status --recursive` lost the space that marks a clean gitlink. source_identity() then read the SHA as the status marker and refused every checkout with a materialized submodule as malformed, which blocks cmux.macos.dev-check and compile-admission on real checkouts. --- scripts/ci/cmux_workload_profile.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/scripts/ci/cmux_workload_profile.py b/scripts/ci/cmux_workload_profile.py index c9652d9a7da0..40e82d4aa45a 100644 --- a/scripts/ci/cmux_workload_profile.py +++ b/scripts/ci/cmux_workload_profile.py @@ -298,7 +298,9 @@ def git_text(*arguments: str) -> str: ) if completed.returncode != 0: raise ProfileError(f"git {' '.join(arguments)} failed") - return completed.stdout.strip() + # Leading whitespace is data: `submodule status` marks a clean gitlink and + # porcelain status marks a worktree-only change with a leading space. + return completed.stdout.rstrip("\n") def source_identity(expected_commit: str | None, expected_tree: str | None) -> dict[str, str]: