ci: run unsigned iOS jobs on owned minis with counted simulator capacity - #14389
Merged
Merged
Conversation
test-ios.yml (mobile-core-package, ios-simulator-build, ios-simulator) and ios-screenshots.yml (screenshots) get a `runner` job that runs the new scripts/ci/ios_runner_pool.py. It applies the E2E pool rule (e2e_runner_pool.decide over pull request CI's picker) and only ever accepts an owned pool: otherwise the run keeps MACOS_RUNNER_TESTS / MACOS_RUNNER_IOS as before. An auto run takes the minis only when CI_PR_POOL_OWNED and the new CI_IOS_OWNED are 1, the pool has two machines free, and the glaeda-ios-sim entry of CI_OWNED_POOL_SLOTS leaves one simulator mini free per device family. The janitor now counts jobs carrying that capability label and a per-run capability marker. The build and simulator jobs ask for [pool, glaeda-ios-sim]; mobile-core-package takes the pool label alone. `runner: owned` forces the pool for a proof run. ios_version runs, App Store uploads and release calls stay on Blacksmith. The rescue watches test-ios and ios-screenshots dispatches like E2E and re-runs stuck or refused jobs on retry_runs_on. ios-streamed-validate and iroh-release-gate stay on Blacksmith but now delete $HOME/.secrets/cmuxterm-dev.env in an always() step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (15)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…code Review fixes for the iOS owned-pool route: - `runner: owned` now fails the runner job unless CI_PR_POOL_OWNED is 1 (otherwise the rescue never watches the run and a queued job waits for good) and CI_OWNED_POOL_SLOTS gives glaeda-ios-sim at least one mini. - seed_cache runs (ci-cache-writer environment, R2 write keys) never take an owned Mac, on auto or forced routes. - A swift_package run holds one machine and no simulator, so it skips the glaeda-ios-sim capacity check and uploads no capacity marker. - Jobs on a glaeda- label take CMUX_CI_XCODE_APP_PR, as test-e2e.yml does. - fastlane snapshot builds into DerivedData under $RUNNER_TEMP. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rustybret
pushed a commit
to rustybret/bmux
that referenced
this pull request
Sep 25, 2026
5a81d71 Merge pull request manaflow-ai#14122 from manaflow-ai/issue-14037-window-display-hang 1a5be43 Merge pull request manaflow-ai#13020 from manaflow-ai/13016-sidebar-new-local-workspace 9e61fc2 ci: rebalance app-host shards from measured timings on all seven workers (manaflow-ai#14393) 8848a92 Merge pull request manaflow-ai#14044 from manaflow-ai/13648-ssh-switch-latency caae250 Merge pull request manaflow-ai#13055 from manaflow-ai/13049-computer-use-onboarding 55dcb23 ci: let a warm owned Mac adopt a near seed instead of its kept build (manaflow-ai#14385) e4e3d88 fix: harden warm reveal and CI array guards ac5bdd9 Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13049-computer-use-onboarding d3865b3 Merge pull request manaflow-ai#14371 from manaflow-ai/14294-helper-staging-leak bd018b1 ci: run unsigned iOS jobs on owned minis with counted simulator capacity (manaflow-ai#14389) 7ca7818 fix: avoid inheriting SSH cloud directories locally f7c94b1 ci: run the dedicated step when a PR edits an env-gated test (manaflow-ai#14381) 566c83f ci: follow changed string literals in the reverse test impact report (manaflow-ai#14387) 87bf6ae fix(ci): skip installing the test module when emission is disabled 28147df Merge pull request manaflow-ai#14382 from manaflow-ai/14273-accessibility-children-cycle 4ff4cde Merge pull request manaflow-ai#14384 from manaflow-ai/12925-split-hint-stuck bf65819 test: assert mounted sidebar and project AX reachability 55e4147 project: group drag tests beside their existing suite 2867b94 test: release MainActor while awaiting hint dismissal 5847394 fix(ci): handle empty app-host output batches 2c52835 Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13648-ssh-switch-latency e8dd4e0 test: update sidebar regression for scoped Cloud creation 63608eb Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13016-sidebar-new-local-workspace 38ca93f Merge remote-tracking branch 'origin/main' into 14294-helper-staging-leak 209a484 Merge remote-tracking branch 'origin/main' into 14273-accessibility-children-cycle 9193381 fix: compare helper inventory independently of URL normalization 1c2fda2 fix: make sidebar AX queries preserve readable text without setters 373ed39 test: cover upgrades from legacy read-only helper generations c7a8d40 fix: normalize managed helper directory modes before atomic publication 69827d4 Merge branch 'main' of https://github.com/manaflow-ai/cmux into 12925-split-hint-stuck 088d07e test: preserve sidebar text and forbid AX getter writes 245daa1 refactor: preserve helper installation errors for diagnostics ce1d8bc test: isolate helper copy failure fixtures within tasks b7cf47b Merge remote-tracking branch 'origin/main' into 12925-split-hint-stuck 53f6251 fix: scope split hints to the native drag lifetime c2db719 fix: make helper replacement atomic and bound retries 2724342 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding 8280bd3 fix: handle optional restore bindings in workspace liveness 1f98d5e fix: prepare helper directory parent fbad4c1 Merge remote-tracking branch 'origin/main' into 14273-accessibility-children-cycle c59df55 fix: keep sidebar accessibility children acyclic 646d361 Merge remote-tracking branch 'origin/main' into 14294-helper-staging-leak b9ab24f test: reproduce sidebar accessibility children cycle 7464b12 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding b690bb1 test: keep canonical build guard stable across CI recipe changes c58c708 test: cover file-drop hint lifecycle teardown 266fbc7 Merge remote-tracking branch 'origin/main' into 13016-sidebar-new-local-workspace 81f274f fix: make helper cleanup event driven cd4a936 fix: reject malformed helper staging names bdd08d0 Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13648-ssh-switch-latency 0c23d10 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding cfe4407 Merge remote-tracking branch 'origin/main' into 14294-helper-staging-leak b1f4f89 fix: bound Computer Use helper staging cdc90c7 test: reproduce helper staging leak fdbcb3c Merge origin/main into 13049-computer-use-onboarding c80b7be fix: avoid AppKit frame constrain reentry 21983c5 fix: guard display frame reconciliation against reentry 343b4fb chore: keep renderer changes within file budgets d8e7469 fix: use warm reveal refresh policy in production path a1baca1 chore: keep renderer extension within file budget 772d634 fix: retain warm frame state across terminal hides b92dfdd fix: avoid redundant terminal refresh on warm workspace reveal ff4795d Merge remote-tracking branch 'origin/main' into 13016-sidebar-new-local-workspace f8c4493 fix: allow CUA from tagged dev Codex sessions 38e7acf fix: resolve post-merge restore build errors 5fd391f Merge origin/main into 13049-computer-use-onboarding c9f363f fix: preserve nonblocking scoped feed telemetry 63378ac test: keep first-use Computer Use telemetry nonblocking and scoped ed9c946 Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13049-computer-use-onboarding 16bfc27 fix: consume relay origin before serializing the ordering environment 3321b39 test: validate relay barriers with the host admission parser dcf085a fix: retain filtering for remote hook transports 3d60cd8 fix: keep relayed hook ordering out of local process routing 88cca73 test: retain relay origin in feed ordering barriers 126b2db Merge branch 'main' of https://github.com/manaflow-ai/cmux into 13049-computer-use-onboarding 75dde56 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding cbf9edb fix: preserve relay origin through feed target resolution 24a7c8c test: cover relay-origin feed admission and first-use attachment e167935 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding 23b1dfc docs: brand the provider as cmux Computer Use 12fd7b0 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding c4f611a fix: restore Swift parameter separators 203bec4 fix: validate both helper profiles before readiness a31f9a6 fix: refresh revocation before first-use admission 9e9df10 fix: keep first-use credentials and revocation state current d5e9bf4 fix: preserve readiness and relay feed admission d3e906b fix: restore scoped completion before daemon readiness e17514c test: use the direct capture outcome API ec9b6e8 fix: report stale capture verification as unavailable 1260836 fix: keep relay routing and Swift 6 compatibility fail closed 267168e Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding edf1834 fix: expose shared feed target resolver to CLI extensions b4f816d fix: bind onboarding work to view task lifecycle 55ffd3e fix: close Computer Use onboarding admission races 03772a9 test: expose Computer Use onboarding review regressions 5ddf044 Merge remote-tracking branch 'origin/main' into 13049-computer-use-onboarding a61e770 fix: restore Computer Use test API visibility 5b8d894 fix: expose setup status for Settings snapshot 811990b fix: restore onboarding completion key compatibility 797bbac fix: wire Computer Use Settings host actions 78128dd fix: expose onboarding completion status to UI b40ea20 fix: expose package transport to capture verification b1d2670 fix: expose helper startup to capture admission f8ea3c8 fix: expose runtime seams to package onboarding adapters 138d703 fix: import package transport types for capture verification 72966a2 fix: resolve feed targets through live delivery e7231ca test: restore Computer Use onboarding target wiring f0c6c1e fix: adapt Computer Use onboarding to current main architecture 66de110 Merge origin/main into 13049-computer-use-onboarding bb1d403 fix: close remaining onboarding review findings d8cff69 docs: document Computer Use core contracts f9d1a3c docs: describe automatic Computer Use setup a12ef64 fix: close Computer Use onboarding review gaps 6cb9cf2 Merge origin/main into 13049-computer-use-onboarding 1021c83 fix: notify Computer Use directly at feed ingress ba61825 fix: present onboarding before helper provisioning 7c0443f fix: accept live owned surface for first-use onboarding 7db2f4b fix: recognize all owned terminal surfaces for first-use setup 73e3144 fix: opt into Computer Use setup from first explicit request dce767a test: reproduce lost Computer Use hook surface in built CLI 4b40d82 fix: present setup before live session indexing a8d61c5 fix: make cmux-cua the only Codex computer provider c0773d9 fix: await live session indexing before first-use setup 82efcbf fix: open Computer Use setup on the first functional tool request 53256c9 test: require setup presentation on the first Computer Use tool b6625cd fix: recheck grants through the shared daemon control protocol ac17c49 fix: invalidate stale capture proof and roll back partial admission 1c21a39 fix: keep Computer Use setup status live through completion 1146f41 fix: make Computer Use setup completion runtime-owned and recoverable 3c44d5c test: reject stale Computer Use onboarding completion after disable b144586 fix: make sidebar New Workspace explicitly local 3e77548 test: cover local workspace creation from sidebar plus menu # Conflicts: # .github/workflows/ci-macos.yml # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/ci.yml # .github/workflows/ios-screenshots.yml # .github/workflows/ios-streamed-validate.yml # .github/workflows/iroh-release-gate.yml # .github/workflows/test-ios.yml
teamleaderleo
added a commit
that referenced
this pull request
Sep 25, 2026
…run for ios-screenshots.yml #14389 made test-ios.yml and ios-screenshots.yml rescue sources. test-ios.yml gets an owned-pool-watch job. ios-screenshots.yml cannot hold one (release.yml calls it with contents: read, #12149), and it had no run from 09-23 to 09-25, so the rescue keeps a workflow_run trigger for it alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lets the unsigned iOS CI jobs run on the owned Mac mini pool. They pick it with the same owned-pool picker that pull request and E2E runs use (#14205, #14225), and fall back to Blacksmith. Routing is off until
CI_IOS_OWNED=1is set. That variable is new, and this PR does not set it.What changes
New
scripts/ci/ios_runner_pool.py. It applies the E2E rule (e2e_runner_pool.decide, which callspr_runner_pool.decide) and accepts only an owned pool. If the picker would pick a Blacksmith pool instead (for example the 12vcpu overflow), iOS stays on its own variable, soMACOS_RUNNER_IOSkeeps its current meaning. An auto run goes to the minis only when all of these hold:CI_PR_POOL_OWNED=1andCI_IOS_OWNED=1blacksmith-6vcpu-macos-26, as for E2Eios_versioninput, no App Store upload, noseed_cache(it runs in theci-cache-writerenvironment with the R2 write keys), and not called from a releaseglaeda-ios-simentry ofCI_OWNED_POOL_SLOTS(for example{"glaeda-ios-sim": 2}) leaves one simulator mini free for each requested device family. Without that entry the lane never routes on its own. Aswift_packagerun holds one machine and no simulator, so it skips this check.Every other case keeps the default. No job is sent to wait in an owned queue.
Labels. Jobs that need the iOS runtime (ios-simulator-build, ios-simulator, screenshots) request
[glaeda-std-xcode-<pin>, glaeda-ios-sim]. They never request the pool label alone.mobile-core-packageruns host SwiftPM tests and needs no simulator, so it takes the pool label alone. glaeda classifies these jobs itself (isolated or simulator token), so they never take the root label. Both labels come from the picker's JSON output. Noglaeda-label appears in any workflowruns-on:line, so the self-hosted guard still holds.Capacity accounting.
pr_runner_poolgainsCAPABILITY_LABELSandcapability_slots(). Aglaeda-ios-simentry inCI_OWNED_POOL_SLOTSis not reported as a slot problem, andslots()still returns only pools.queue_janitorcounts queued and running jobs that carry the capability label.queue_janitoralso reads a per-run capability marker (macos-pool-persistent-<run>-<attempt>-<sim_jobs>-glaeda-ios-sim), so a run's simulator jobs count as taken before they exist.test-ios.yml
runnerjob (actions: read). The three macOS jobs readfromJSON(run_attempt > 1 && retry_runs_on || runs_on).tart-iosTart identity checks and the GitHub-hosted check all still work. They now read the runner job's label.runnerinput gainsowned, which forces the owned pool for a proof run without reading the queue. It is an explicit request, so it fails the runner job with an error, never a fallback, unlessCI_PR_POOL_OWNED=1(otherwise the rescue never watches the run and a queued job would wait for good) andCI_OWNED_POOL_SLOTSgivesglaeda-ios-simat least one mini. It also refuses what auto refuses.CI_IOS_OWNEDis not required, so the proof run can come first.glaeda-label setCMUX_CI_XCODE_APPtoCMUX_CI_XCODE_APP_PR, as test-e2e.yml does, so the Xcode matches the pool label; a Blacksmith re-run keeps it.runneris added to theios-testsgate's needs.ios-screenshots.yml:
screenshotsjob.runnerinput withowned.contents: readonly (release.yml fails at startup: generate-ios-screenshots requests 'actions: write' the caller does not grant (stable release blocked) #12149). Its runner job therefore cannot holdactions: readto read the queue, so auto keepsMACOS_RUNNER_IOS, and only a direct capture-only dispatch withrunner: owneduses a mini.SNAPSHOT_DERIVED_DATA_PATH) move to$RUNNER_TEMP. The Xcode pin follows the owned label, as in test-ios.always()step.Rescue.
ci-owned-pool-rescue.yml/owned_pool_rescue.pynow watch test-ios and ios-screenshots dispatches exactly like E2E. A job left queued or refused (a second simulator job on a mini) gets its failed jobs re-run onretry_runs_on, which is Blacksmith.Kept on Blacksmith
validate). Not routed. It binds ports 3000 and 13000, runsrm -rf /tmp/cmuxpg, uses shared~/LibraryDerivedData, putsCLAUDE_CODE_OAUTH_TOKENinto the GUI session withlaunchctl setenv, and flips the global dark mode. It also writes agent credentials under$HOMEand launches the app through launchd. The new secrets cleanup is general hygiene only; it is not a reason to route this job.$HOME/.secrets/cmuxterm-dev.envunderumask 077and delete it in anif: always()step. The file cannot move to$RUNNER_TEMPbecause the Mac app'sDebugDogfoodCredentialResolver,scripts/lib/dev-secrets.shandweb/scripts/load-dev-env.shall read that fixed path.ios_versionrun, any App Store upload, anyseed_cacherun, and the release call of ios-screenshots.Next: nightly/beta
The TestFlight uploads (plain cmux, INTERNAL, BETA) move to a dedicated release mini whose label takes only signing jobs, with Blacksmith as the fallback. That's a follow-up PR. Decision and host choice: manaflow-ai/cmuxterm-hq#627.
Rollout
glaeda-ios-simlabel ships (glaeda#1218) on minis with the iOS simulator role and an iOS 26.x runtime.CI_PR_POOL_OWNED=1(already set), so the rescue watches the run."glaeda-ios-sim": <sim minis>toCI_OWNED_POOL_SLOTS.gh workflow run test-ios.yml --repo manaflow-ai/cmux -f runner=owned. Do this only after step 1 is live.CI_IOS_OWNED=1.Tests
tests/test_ci_pr_runner_pool.pygainsIOSRoutingandIOSWiring. They cover capacity counting, package-only runs needing no simulator, the label shape, the switches, the blockers (includingseed_cache), forcedownedand its refusals withoutCI_PR_POOL_OWNEDor simulator slots, the Xcode pin, the janitor's capability counting and markers, the workflow wiring, signing and streamed-validate staying off the fleet, and a guard that every$HOME/.secretswrite has a lateralways()removal.tests/test_ci_owned_pool_rescue.pycovers iOS dispatch targets and a job stuck waiting onglaeda-ios-sim.test_ci_self_hosted_guard.sh,test_ios_workflow_dispatch_ref.pyandtest_ci_workflow_run_sources.pyare updated.test_ci_queue_janitor,test_ci_reusable_workflow_permissions,test_run_e2e,test_runner_label_policy,test_ci_actionlint_covers_every_workflow, and actionlint 1.7.7 on all workflows.tests/test_ios_simulator_build_once.pyfails the same way on unmodified main locally (the macOS/varsymlink), and this PR does not touch it.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Lets the unsigned iOS CI jobs (test-ios.yml, ios-screenshots.yml) run on the owned Mac mini pool, picked by the same pool picker that E2E and pull request runs use, with simulator capacity counted so minis never oversubscribe. Routing is off until the new
CI_IOS_OWNEDvariable is set to 1; nothing changes by default. Activation requires the minis to carry theglaeda-ios-simlabel and a matching entry inCI_OWNED_POOL_SLOTS.Routing
runnerjob running the newscripts/ci/ios_runner_pool.py; all macOS jobs read its choice and re-runs fall back to Blacksmith.CI_IOS_OWNEDandCI_PR_POOL_OWNEDare 1, the pool has two machines free, and theglaeda-ios-simslot entry leaves a simulator mini free per requested device family; otherwiseMACOS_RUNNER_IOSkeeps its meaning.ios_version,seed_cache, App Store upload, and release calls stay on Blacksmith. Aswift_packagerun takes one mini and needs no simulator, so it skips the capacity check.glaeda-ios-sim;mobile-core-packagetakes the pool label alone.runner: ownedforces the fleet for a proof run, failing unlessCI_PR_POOL_OWNEDis 1 andglaeda-ios-simhas minis (the rescue would not watch it otherwise).glaeda-label takeCMUX_CI_XCODE_APP_PR; the queue janitor and a per-run marker count simulator capacity, and the rescue workflow now watches iOS dispatches and re-runs stuck or refused jobs on Blacksmith.Secrets hygiene
$HOME/.secrets/cmuxterm-dev.envunderumask 077and remove it in analways()step.Written for commit d08b033. Summary will update on new commits.
Summary by CodeRabbit
New Features
Bug Fixes