Skip to content

ci: close the two edges the shared spm- cache namespace opened - #13933

Merged
teamleaderleo merged 1 commit into
mainfrom
ci/spm-shared-namespace-guards
Sep 23, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
ci/spm-shared-namespace-guards

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Follow-up to #13925. An independent review of that PR flagged two edges around the now-shared spm- cache namespace; this closes both. A second review of this PR cleared it with no confirmed defects.

1. perf-activation.yml gets the poisoned-cache guard

This is the substantive half. It was the only consumer of the shared namespace without one. test-e2e.yml:412-419 and test-depot.yml:168-175 both verify Sparkle and Sentry actually materialized and rm -rf the directory between attempts, because — quoting test-e2e's own comment — "resolve can report success without binary artifacts materialized". perf-activation.yml retried against the same possibly-poisoned directory and exit 0d on first success, then failed opaquely later in "Build tagged app".

This guard is the one that matters, because it detects a bad restore regardless of cause.

2. ci-macos-compat.yml moves to a compat-spm- prefix

Defensive hygiene, not a fix for an observed failure — stated plainly rather than dressed up.

ci-macos-compat.yml:17-24 has an x86_64 leg (macos-15-intel) and :11-16 an older-Xcode macos-14 leg. The Cache Swift packages step at :137-147 has no if: — run_unit_tests: false gates only the test step at :184, so all four legs populate and save this cache. They share path: .ci-source-packages with the workflows that now restore with a bare restore-keys: spm-, and since the GitHub cache version derives from path (and enableCrossOsArchive gates OS, not CPU arch), spm- can prefix-match spm-macos-15-intel-<hash>.

Two honest caveats:

Cost is nil: no spm-macos-15-intel-* entry exists in the cache today, and docs/ci/workflow-inventory.md:128 records this workflow at 0 runs in the last 7 days (last success 2026-08-13), well past the 7-day eviction window. It also costs compat nothing in sharing — its old restore prefix was spm-${{ matrix.os }}-, which was never a prefix of the pool's spm-<hash> entries either, so its arm64 legs were already isolated.

Known-better end state, deliberately not done here

Putting ${{ runner.arch }} in the shared key (as test-ios.yml:443 and nightly.yml:613 already do, and as r2-cache.sh:36 does for this exact directory) would close the whole class rather than today's one Intel producer, and would let compat's arm64 legs share the nightly-seeded pool cache. That touches five hot-path workflows and forces a one-time cold resolve on the contended pool, so it belongs in its own change. Filed as a follow-up.

Verification

  • YAML parses; actionlint rc=0. Its single SC2129 finding is at perf-activation.yml:70, pre-existing on origin/main; these edits are at :168 and :180.
  • Full linux-guard lane green locally (rc=0, 427 passing checks), including test_ci_pull_request_caches_are_read_only.py (parses ci-macos.yml/nightly.yml only, so the compat prefix is outside its assertions), test_ci_manual_macos_package_cache.py, and test_ci_self_hosted_guard.sh.
  • Repo-wide search for anything keying on the old literal (spm-macos, docs, guards): no stale references.

🤖 Generated with Claude Code

Sharing one `spm-<hash>` key across the arm64 pools made two latent
edges reachable that the pool-scoped keys had hidden.

`ci-macos-compat.yml` is an OS/arch compatibility matrix: it has an
x86_64 leg (`macos-15-intel`) and an older-Xcode `macos-14` leg, and it
caches the same `.ci-source-packages` path. Same path means same GitHub
cache version, so a bare `restore-keys: spm-` would prefix-match its
Intel-produced entry. `scripts/ci/r2-cache.sh:36` namespaces this exact
directory by `$RUNNER_ARCH`, so the repo already treats arch as
identity-bearing here. Move the matrix to a `compat-spm-` prefix so the
two namespaces are disjoint by construction rather than by luck.

`perf-activation.yml` was the one consumer of the shared namespace with
no poisoned-cache check. `test-e2e.yml` and `test-depot.yml` both verify
Sparkle and Sentry actually materialized and wipe the directory between
attempts, because resolve can report success without binary artifacts;
perf-activation retried against the same directory and failed opaquely
later in "Build tagged app". Port the same check.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 26 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 58009dbf-c685-45fb-bc02-7805907de22b

📥 Commits

Reviewing files that changed from the base of the PR and between ca867b7 and 8854503.

📒 Files selected for processing (2)
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/perf-activation.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Independent review. I verified both claims against origin/main rather than taking the description's word for them, and both hold.

Edge 1 is real. ci-macos-compat.yml's matrix includes macos-15-intel with expected_arch: x86_64, alongside macos-14 and the two Blacksmith arm64 legs. Its cache key on main is spm-${{ matrix.os }}-<hash>, which produces entries literally named spm-macos-15-intel-<hash>. Nine other jobs restore that same .ci-source-packages path with a bare restore-keys: spm-:

ci-macos.yml:456, :3233   cli-pipe-regressions.yml:58
nightly.yml:455, :628, :871   perf-activation.yml:169
release.yml:260   test-depot.yml:153   test-e2e.yml:332

Same path means same cache version, and restore-keys is a prefix match — so spm- matches spm-macos-15-intel-<hash>. An arm64 runner restoring an Intel-produced .ci-source-packages is reachable today. compat-spm- is disjoint from spm- by construction, which is the right shape; agreed that scripts/ci/r2-cache.sh:36 namespacing the same directory by RUNNER_ARCH is the precedent.

Edge 2 is real and is the one I'd have insisted on. perf-activation.yml:174-190 on main does exit 0 on the first successful resolve with no artifact check and no rm -rf between attempts. test-depot.yml:168-181 has exactly the guard this PR adds, down to the Sparkle/Sentry xcframework paths and the "retrying cleanly" message. perf-activation.yml was the sole consumer of the shared namespace without it. The failure it prevents is the bad kind — a successful-looking resolve that dies later and opaquely in "Build tagged app", several minutes downstream of the actual cause.

The ordering argument in the description is the load-bearing one: edge 2 is what makes edge 1 non-damaging rather than merely improbable. Worth landing even if the prefix rename were unnecessary.

One thing this does not close, and I think correctly. The bare spm-<hash> namespace is still shared across macOS versions on arm64 — a macos-15 pool and a macos-26 pool produce byte-identical key names. That is presumably deliberate (same arch, same Package.resolved), and edge 2's guard now covers the case where it goes wrong. Flagging it so the next reader does not mistake this PR for having made the namespace fully arch-and-OS-safe; it made it arch-safe.

Cost is one cold resolve per compat leg on first run after this lands, on a workflow_dispatch-only workflow. Fine.

Guards are green, including the full workflow-guard-tests matrix and workflow-guard-source-lints. Enabling auto-merge.

— Zarathustra g1 🌱

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 23, 2026 07:06
@teamleaderleo
teamleaderleo merged commit 587f661 into main Sep 23, 2026
51 of 52 checks passed
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 23, 2026
41f6862 ci: integrate canonical app-host compilation paths (manaflow-ai#13854)
165b05c ci: run the CmuxMobileShell package tests serially (manaflow-ai#13935)
ca53e05 test: repair the renderer gate and tmux mirror sizing fixtures (manaflow-ai#13873)
a1029b2 test(ios): stop the keyboard test seam renegotiating the grid (manaflow-ai#13932)
587f661 ci: namespace the compat cache and guard perf-activation's restore (manaflow-ai#13933)

# Conflicts:
#	.github/workflows/ci-macos-compat.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/nightly.yml
#	.github/workflows/perf-activation.yml
#	.github/workflows/test-ios.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant