Skip to content

ci: route ci-macos.yml edits job by job so shard edits skip the Release build - #14141

Merged
teamleaderleo merged 4 commits into
mainfrom
claude/ci-route-by-job
Sep 24, 2026
Merged

teamleaderleo merged 4 commits into
mainfrom
claude/ci-route-by-job

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

An edit to .github/workflows/ci-macos.yml selected the macOS area and release_build whichever job it touched. Under full-ci, a PR that only changed the app-host unit-test shards paid for the Release build.

The changes job now passes the base ci-macos.yml to detect_ci_change_areas.py (--macos-workflow-base), which compares it with the PR's version job by job:

  • Every ci-macos.yml edit still selects macOS.
  • release_build is selected only when a changed job mentions release_build (release-admission, release-build, swift-package-tests, macos-status) or feeds a job gated on inputs.release_build through needs.X.outputs.
  • An edit before jobs:, an unreadable file, a missing base, or a trusted base router that lacks the flag keeps the previous behaviour.

The ci.yml comparison in the detector now returns areas instead of a Linux-only flag. A caller job selects only the area of the workflow it calls (macos → macOS + Release, web → web, cli → CLI). Plainly Linux jobs still select nothing, and every other job still runs all areas. In CI this path only matters if ci.yml edits are ever sent through the detector: the changes step still removes ci.yml from the file list before routing.

Context: most unlabeled CI-only PRs already skip the compile through "Skip compile when build inputs are unchanged" (build fingerprint equal to the base's). The saving here is the Release build on full-ci PRs that edit ci-macos.yml, plus fewer jobs gated on macos.

Validation

  • tests/test_ci_change_areas.py: 229 passed. The 7 new tests (job edits on the real ci.yml and ci-macos.yml, a synthetic outputs-feeder workflow, classify_files wiring, and the real changes step run in a temp repo on both router paths) fail at the first commit.
  • All tests/test_ci_*.py: same 6 failures as origin/main (test_ci_canonical_build_root.py, environment), 836 passed.
  • tests/test_ci_self_hosted_guard.sh passes.
  • Not verified: a live CI run of a ci-macos.yml-only PR; actionlint (not installed where this was prepared).

🤖 Generated with Claude Code

https://claude.ai/code/session_012pAcDGiHaibDaMU4CPvXAP


Generated by Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Routes CI workflow edits job by job so a ci-macos.yml change confined to the app-host unit-test shards no longer triggers the Release build.

  • The detector now compares ci-macos.yml against the base revision per job; an edit selects macOS always, but release_build only when a Release job or a job whose outputs feed one changed.
  • ci.yml edits select only the area of the reusable workflow the changed job calls (macOS, web, or CLI), instead of a Linux-only flag; routing jobs, the preamble, and unknown callers still select every area.
  • Missing or unreadable base files keep the previous behavior (fail open).

Written for commit ecefaac. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • CI checks now run based on which workflow jobs changed. Linux-only changes avoid product-area checks, while changes to macOS, web, or CLI jobs run checks for the affected areas.
    • macOS workflow changes run macOS checks; release build checks run when release jobs or their outputs are affected. If a workflow comparison is unavailable or unclear, CI runs broader checks.

teamleaderleo and others added 2 commits September 24, 2026 04:32
An edit to ci-macos.yml selects the macOS area and the Release build no
matter which job it touches, so a change confined to the app-host unit-test
shards pays for the Release check under full-ci. Add failing tests for
job-by-job comparison of both workflows: a shard edit selects macOS
without release_build (through the normal and the trusted base router), a
Release job or a job feeding it through outputs still selects Release, and
a ci.yml caller job selects only the area of the workflow it calls.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012pAcDGiHaibDaMU4CPvXAP
A ci-macos.yml edit selected macOS and the Release build whatever job it
touched. The changes job now passes the base ci-macos.yml to the detector
(--macos-workflow-base, to the trusted base router too when it knows the
flag), which compares the two job by job. Every edit still selects macOS;
the Release build is selected only when a changed job names release_build
(release-admission, release-build, swift-package-tests, macos-status) or
feeds a job gated on inputs.release_build through its outputs. The
preamble, an unreadable file, or a missing base keeps the old behaviour.

The ci.yml comparison now returns areas instead of a Linux-only flag: a
plainly Linux job selects nothing as before, a job calling ci-macos.yml,
ci-web.yml or the CLI lane selects that area alone, and anything else
still runs every area.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012pAcDGiHaibDaMU4CPvXAP
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 86189d35-4b5e-43c4-90f1-405870ae9c49

📥 Commits

Reviewing files that changed from the base of the PR and between 832f621 and ecefaac.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • scripts/ci/detect_ci_change_areas.py
  • tests/test_ci_change_areas.py
 ___________________________________________________
< Your TODOs are starting to look like a manifesto. >
 ---------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit 0605515 into main Sep 24, 2026
39 of 40 checks passed
teamleaderleo added a commit that referenced this pull request Sep 24, 2026
…dits (#14145)

* ci: test that routing-policy edits skip the Mac standalone lanes

PR #14141 edited only the change-area detector, its tests, and the detect
step of ci.yml's `changes` job, yet run 35956687867 queued `Claude wrapper
regressions` and `remote-daemon-macos-tests` on the Mac pool: the
standalone route selects claude_wrapper, remote_daemon and
remote_daemon_native for every ci.yml edit. Add tests that run the real
detect and standalone steps on that diff shape and expect those lanes and
the CLI lane off, while an edit to a lane's own caller job, the preamble,
or a lane input still selects it, and an unreadable base fails open.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012pAcDGiHaibDaMU4CPvXAP

* ci: select the Mac standalone lanes only when their ci.yml job changes

The standalone route set claude_wrapper, remote_daemon and
remote_daemon_native for any ci.yml edit, so a change confined to the
`changes` job (PR #14141) queued `Claude wrapper regressions` and
`remote-daemon-macos-tests` on the Mac pool and held ci-status on them.

The detect step now saves the base ci.yml, and the standalone route
compares it with the head job by job. The wrapper lane is selected when
the `claude-wrapper` job differs, the remote-daemon lanes when the
`remote-daemon` caller differs (its native_tests input lives there), and
both when the preamble differs, the base is missing or unreadable, a job
name repeats, or the lane's job uses a YAML alias. Edits to the routing,
status and Linux jobs only decide whether a lane runs; the Linux guard
tests cover them. The Linux browser lane still runs for every ci.yml
edit, and every path rule for the lanes' own inputs is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012pAcDGiHaibDaMU4CPvXAP

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant