docs: propose routing CI by capability instead of by vendor - #14010
Conversation
Jobs name the vendor that owns the machine (`blacksmith-6vcpu-macos-26`), not what they require. Eleven `MACOS_RUNNER_*` variables carry three distinct label values, and ten of the guard's thirty-four check functions exist only to police which vendor string appears where. This proposes jobs declaring capabilities (`[self-hosted, macos-26, gui]`) and capacity advertising them, with a single vendor translation layer for providers that own their label names. Proposal only; nothing implemented. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 3 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
Step 0 resolved:
|
Open question 1 answered: Blacksmith does not support customer-defined labelsFrom Blacksmith's instance-type reference: only fixed tag names, So the vendor translation layer is permanent, not transitional — for as long as any sponsored Blacksmith capacity is in use. The document should say that outright rather than listing it as unresolved. It does not invalidate the design: owned hardware still gets capability labels, and the translation table stays small because Blacksmith exposes exactly three macOS distinctions (version, 6 vs 12 vCPU). But "eventually this goes away" is not true of it.
|
| Tag | vCPU | RAM | Storage |
|---|---|---|---|
blacksmith-6vcpu-macos-* |
6 | 24 GB | 150 GB |
blacksmith-12vcpu-macos-* |
12 | 48 GB | 250 GB |
cpu-12 (nightly universal build) and disk-large (release-build) both resolve to the 12-vCPU tier, so the vocabulary loses a label: one macos-large covers both, and neither smuggles a specific vCPU count into the job description.
It also supplies the figure the document says is missing for "disk-heavy". CLAUDE.md puts the CMUX workload default at 120 GiB, against 150 GB on the 6-vCPU tier — which is why release-build reclaims disk before large cache restores, and why the 250 GB tier is the real requirement rather than a preference.
Two further facts worth folding in:
blacksmith-12vcpu-macos-15exists and nothing in the repo uses it. If a macOS 15 lane is ever disk- or CPU-bound, that tier is available today.- macOS 26 images ship both Xcode 26 (default) and Xcode 27, switchable via
DEVELOPER_DIR. Relevant to howsdk-15is framed: the dual-Xcode requirement here is SDK 15 + SDK 26, which this does not satisfy, but it does mean "which Xcode" is already an image property the pool varies independently of the macOS version.
Sources: Blacksmith instance types, Blacksmith quickstart, Blacksmith pricing.
Counts now match main at 02972b7: 9 MACOS_RUNNER_* variables after #14002 and the MACOS_RUNNER_26_LARGE merge, and 35 guard checks called 40 times, 15 of them deletable. Step 0 and the Blacksmith label question are settled, so the document states the answers. cpu-12 and disk-large become one macos-large label because Blacksmith sells them as one tier. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
9567d6e refactor: give About and Licenses windows explicit ownership (manaflow-ai#13148) fae46b6 ci: stop retrying a missing cmux-tui manifest (manaflow-ai#14168) 8421357 Point PR checklist and welcome note at the hidden Review Trigger block (manaflow-ai#14167) b9415db ci: run app-host product consumers on compile admission's pool and Xcode (manaflow-ai#14163) ac0ceae fix(sidebar): order panels without reading split-container geometry (manaflow-ai#13931) 37edc16 ci: judge Web complexity's trusted files in the pull request's merge (manaflow-ai#14018) 679f4e2 ci: leave three-day-old queued ghosts to GitHub instead of retrying them (manaflow-ai#14166) 07a2e22 fix(web): enumerate complexity-gate sources with git ls-files -z (manaflow-ai#13682) c72f659 cloud: share concurrent VM stats reads (manaflow-ai#13327) aa51f16 ci: trim package setup before the macOS compile admission build (manaflow-ai#14160) 82ea1ed ci: land the fleet review fixes manaflow-ai#14159 merged without (manaflow-ai#14165) adddb59 docs: propose routing CI by capability instead of by vendor (manaflow-ai#14010) f862390 ci: fix three fleet command gaps from the manaflow-ai#14159 review (manaflow-ai#14164) 77d56b3 agent-chat: make installed harnesses first-class (manaflow-ai#13347) 7dc57f6 Clarify writing guidance for issue and PR descriptions (manaflow-ai#13275) ccf4963 ci: name the hung test when a Swift package test step stalls (manaflow-ai#14055) 9fca985 ci: guard the fleet routing switch, Xcode pin and quarantine (manaflow-ai#14159) 02972b7 fix: thin around and Developer ID sign the bundled cmux-tui SSH payloads (manaflow-ai#14154) # Conflicts: # .github/workflows/app-host-test-rerun.yml # .github/workflows/ci-guards.yml # .github/workflows/ci-macos.yml # .github/workflows/test-ios.yml # .github/workflows/web-complexity-trusted.yml
Every macOS job in cmux names a vendor's machine label instead of what the job needs.
tests-build-and-lagneeds a macOS machine with a foreground Aqua login session; itsruns-onsays this instead:This PR adds
docs/ci-runner-capability-labels.md, a proposal to have jobs declare capabilities (runs-on: [self-hosted, macos-26, gui]) and have runners advertise them. Adding a machine, such as a Mac Ultra, then means registering it with the right labels. It needs no workflow edit, repository variable, or guard change. Documentation only: no workflow, test, script, or variable changes, and nothing in the document is implemented.Why
On
mainat02972b7a73, workflows read 9vars.MACOS_RUNNER_*variables, plusCI_PAID_MACOS_OVERFLOWandCMUX_CI_XCODE_APP_PR. Their fallbacks use three macOS labels:blacksmith-6vcpu-macos-15,blacksmith-6vcpu-macos-26, andblacksmith-12vcpu-macos-26.tests/test_ci_self_hosted_guard.shdefines 35check_*functions and calls them 40 times. Ten of them only police which vendor string may appear where. #14002 found a case of this drift: one variable served two jobs with incompatible macOS requirements, and the fallbacks disagreed.What the document proposes
main:macos-14/15/26,x86_64,sdk-15,gui,ios-simulator, and a large-machine label.mainthey cover 15 of 40 calls, and four more checks shrink.build-ghosttykit.yml) and ends withtests-build-and-lag.Settled since the draft
The PR comments settled two points the first draft listed as open, and
3b8514awrites the answers into the document:runs-onaccepts a computed label array (${{ fromJSON(...) }}), and a runner must carry all listed labels. This was step 0(a). GitHub's syntax reference does not show the array form (github/docs#20495). Community reports (#78674, #50172) describe dynamic multi-label jobs that queue forever. Step 0 therefore needs a deliberate no-match run, not only a syntax check.blacksmith-{6,12}vcpu-macos-{15,26,27,latest}) and no customer-defined labels (instance types). The vendor translation table stays for as long as Blacksmith capacity is used. Owned machines still pass their labels through unchanged. The proposal still stands.cpu-12anddisk-largeare one Blacksmith tier (12 vCPU, 48 GB, 250 GB), so they become onemacos-largelabel.release-buildnow runs on the 6-vCPU pool, so only the universal Nightly build uses that tier. Its threshold is still Blacksmith's tier, not a measured need.Still open
tests-build-and-lag. That lane moves last.CMUX_PRODUCT_RUNNERwould need to be replaced by machine-reported identity. What owned machines setImageOSto has not been established.Validation
At
3b8514a:python3 scripts/ci/run_python_test_lane.py --lane linux-guardexited 0 with noFAIL:lines, andbash tests/test_ci_self_hosted_guard.shpassed. These show that the new doc breaks no guard. They do not test the proposal. The counts above come fromgit grepover.github/workflowsand the guard file atorigin/main02972b7a73.🤖 Generated with Claude Code