ci: derive whether a scripts/ci helper reaches a routed lane - #14063
Conversation
An unknown scripts/ci helper used to fail open to every area. The router now walks back from the helper through every tracked file that names it: scripts and composite actions are followed, workflows outside ci.yml's call tree and Linux-only guard tests are dead ends, and anything else (a routed workflow, product sources, the Xcode project, an absent file, a read failure) keeps the fail-open answer. e2e_warm_derived_data.py leaves product identity: it only warms the dispatch-only E2E lane and never changes ci-macos products. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Warning Review limit reachedNext included review available in 3 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
Review of the derived helper routing found the call tree was read only from the pull request's ci.yml, so a quoted or removed `uses:` line could unroute a workflow and its helpers. Calls may now be quoted, and the routed set is the union of the base's call tree and the head's. E2E products no longer take e2e_warm_derived_data.py through PRODUCT_CI_INPUTS. Instead the E2E identity hashes every scripts/ci file its build job names, so an edit to one still invalidates E2E products without touching the compile-admission identity or naming the helper where routing would follow it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Independent review (a separate agent in its own scratch worktree). No blockers. For each of the 14 helpers that now derive as unrouted, it grepped every referrer. Each one is run only from nightly, release, test-e2e, test-ios, persistent-macos-compile, Linux guard tests or docs.
Checked and sound: composite-action tokens, the workload-profile chain, hyphenated names, the transitive call-tree walk, read-only — Dulcinea g1 🎐 |
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
a3b7014 ci: skip the CLI lane for project.pbxproj edits outside the CLI targets (manaflow-ai#14071) 789edd3 ci: bootstrap the app-host known-failure catalog from main's census (manaflow-ai#14074) 2c2314e ci: route focused tests to one front door, and half of them to 12 vCPU (manaflow-ai#14067) d7409fc ci(e2e): read adopted DerivedData over parallel ranges (manaflow-ai#14051) 99dc5a3 ci: derive whether a scripts/ci helper reaches a routed lane (manaflow-ai#14063) cf8b073 ci: stop routing the Claude wrapper lane on test-registry edits (manaflow-ai#14065) # Conflicts: # .github/workflows/ci.yml # .github/workflows/perf-activation.yml # .github/workflows/test-e2e.yml # .github/workflows/test-macos-suite.yml
A pull request that edits a
scripts/ci/*.pyhelper the router has no list entry for runs the macOS, web and Release lanes, even when no job inci.yml's tree can execute that helper. #14051 queued macOS compile admission for a script only the dispatch-only E2E workflow runs. Hand-maintained lists (CI_CONTROL_PLANE_ONLY,CI_PUBLISHING_ONLY, #14061'sCI_DISPATCH_ONLY) fix one file at a time, and every new helper starts on the expensive side.The router now derives the answer. Areas only gate
ci.ymland the local workflows it calls, so the question is whether any job in that tree can execute the helper.ci_helper_reaches_routed_lanewalks back from the helper through every tracked file that names it as a whole name (git grep, then a boundary match, sotests/test_foo.pydoes not count as namingfoo):ci.yml's call tree (dispatch, schedule, nightly, release) is a dead end.is_guard_only_testrule.git grep.It runs inside the trusted base router and reads the pull request's tree only as data, through the existing
CMUX_CI_HEAD_TEST_REFERENCE_ROOT. Listed helpers keep their explicit routing.e2e_warm_derived_data.pyalso leavesPRODUCT_CI_INPUTS, which #14016's review added. Keeping it there made every edit change the compile-admission identity, and routing followed the literal name into the macOS lane. Instead, the E2E identity (e2e_recipe) now hashes everyscripts/ci/file the E2E build job names. An edit still invalidates E2E products, and nothing else.Review follow-up: calls in
ci.ymlmay be quoted, and the routed call tree is the union of the base's and the head's, so a pull request cannot unroute a workflow by editingci.yml.Effect. Replaying the 600 most recent pull requests merged since 2026-09-16 through main's router and this one, against today's tree: 104 touched an unowned helper. 11 of those would have skipped the macOS lane (#13972, #13970, #13901, #13900, #13899, #13875, #13867, #13695, #13694, #13680, #12934), and 4 more would have skipped only web or Release. All 11 edit dispatch, nightly, release or offline tooling. Of the 46 unowned helpers today, 14 now derive as unrouted and 32 still fail open.
test_execution_registry.py,cache_restore_receipt.py,xcodebuild_noninteractive.pyandrun_python_test_lane.pystay routed.Tradeoffs. Name matching over-approximates: a comment or a shared stem keeps a helper routed, which only costs CI. An indirect execution path that never names the helper (a computed path, for example) would be missed; the walk covers scripts, composite actions, workflows and tests, which is how helpers are invoked here today. A new helper nothing names yet still fails open.
Validation. New router tests on synthetic repos cover: a dispatch-only run; a routed workflow running the helper directly, through a script and through a composite action; a product-source referrer; a test on a native lane; an unreferenced helper. They also assert that
e2e_warm_derived_data.pyis unrouted andtest_execution_registry.pyis routed in the real tree. All 139 linux-guard tests pass locally. Because this edits the router, it runs every area once. Supersedes #14061.— Dulcinea g1 🎐
🤖 Generated with Claude Code