Skip to content

ci: read the owned-pool rescue's Actions API through the route App - #14499

Merged
teamleaderleo merged 10 commits into
mainfrom
ci/rescue-app-token-reads
Sep 25, 2026
Merged

teamleaderleo merged 10 commits into
mainfrom
ci/rescue-app-token-reads

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #14460. GitHub retargets it to main when that merges.

What

The owned-pool rescue polls the Actions API (jobs, artifacts, the run, the PR head) on GITHUB_TOKEN. That token has about 1000 requests an hour for the whole repository, which is what kept #14460 from watching more runs. The org's manaflow-glaeda-route App already has Actions access (cmuxterm-hq#639) and its own budget of 5000 an hour.

  • ci-owned-pool-rescue.yml mints an App installation token with actions, contents and pull-requests read. The step is continue-on-error and only runs when GLAEDA_ROUTE_APP_ID is set.
  • owned_pool_rescue.GitHub sends every GET with that token (READ_TOKEN).
  • Cancels and re-runs stay on GITHUB_TOKEN. ci-macos.yml routes a rescued attempt 2 back to the fleet only when github.triggering_actor == 'github-actions[bot]'. A re-run started by the App would silently skip that.
  • An installation token lasts an hour and a watch can run longer. A 401 on a read switches reads to GITHUB_TOKEN for the rest of the watch. If the token can't be minted, everything stays on GITHUB_TOKEN, as it is today.

Tests

tests/test_ci_owned_pool_rescue.py adds a Tokens class. It checks that reads use the App token while writes keep the repo token, that an expired App token falls back, that everything uses the repo token when there is no App token, and how the workflow mints and passes the token. All 80 rescue tests pass, and actionlint is clean on every workflow.

🤖 Generated with Claude Code


Summary by cubic

Switches the owned-pool rescue's Actions API reads (jobs, artifacts, the run, the PR head) from the repository's GITHUB_TOKEN to the manaflow-glaeda-route App installation token, which has its own 5000 requests an hour instead of the repository's shared 1000.

  • The workflow mints the App token with actions, contents, and pull-requests read access; a failed or skipped mint leaves all requests on GITHUB_TOKEN.
  • Cancels and re-runs keep GITHUB_TOKEN so attempt-2 re-runs stay attributed to github-actions[bot] for fleet routing.
  • A 401 on a read (the App token expires after an hour) falls back to GITHUB_TOKEN for the rest of the watch.

Written for commit 4796d7e. Summary will update on new commits.

Review in cubic

teamleaderleo and others added 6 commits September 25, 2026 05:59
…ission finishes

The picker places every job at run start, but the app-host shards,
tests-build-and-lag and cli-product-tests start only after compile
admission. When the owned pool was full at the start they stayed on
Blacksmith even after roots drained (09-25: 19 jobs queued on
blacksmith-12vcpu-macos-26, cap 5, while 9 of 16 std roots were idle).

A late-placement job reads the idle root runners live through the route
App after admission succeeds and gives the not-yet-owned jobs the root
label for admission's Xcode, one per idle runner. They fetch admission's
products as they do after an owned admission. Attempt 1 of same-repo PRs
only; any failure leaves the run-start placement.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review: a moved job waits for a root runner that another run may take
first, and a run whose picker owned nothing had no rescue watch, so it
could sit queued with nothing to move it back to Blacksmith.

late-placement now uploads a macos-pool-late-<run>-<attempt> marker when
it moves jobs. ci.yml's owned-pool-watch also starts the rescue for a
same-repo PR whose picker owned nothing but which has jobs after
admission (full or unit suite, or the CLI lane), with late=1. That watch
reads the picker's marker once, then waits at IDLE_POLL_SECONDS for
ci-macos.yml's late-placement job, and follows the run only if its marker
exists. Existing watches are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ment

# Conflicts:
#	tests/test-execution.toml
The watch polls jobs and artifacts on GITHUB_TOKEN, about 1000 requests
an hour for the whole repository. The org's manaflow-glaeda-route App
already has actions access (cmuxterm-hq#639) and its own 5000 an hour.

The rescue workflow mints an App token (actions, contents and
pull-requests read) and the script sends every GET with it. Cancels and
re-runs keep GITHUB_TOKEN, because ci-macos.yml's attempt-2 routing
requires the re-run's triggering actor to be github-actions[bot]. A 401
on a read (the token lasts an hour, a watch may run longer) drops back to
GITHUB_TOKEN; a failed mint leaves every request on GITHUB_TOKEN.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 18 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d92a1539-7f71-4419-9a08-8edbc84229b8

📥 Commits

Reviewing files that changed from the base of the PR and between 115588f and 4796d7e.

📒 Files selected for processing (3)
  • .github/workflows/ci-owned-pool-rescue.yml
  • scripts/ci/owned_pool_rescue.py
  • tests/test_ci_owned_pool_rescue.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Base automatically changed from ci/late-shard-placement to main September 25, 2026 12:07
@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit dbb24cb into main Sep 25, 2026
50 of 51 checks passed
@teamleaderleo
teamleaderleo deleted the ci/rescue-app-token-reads branch September 25, 2026 12:52
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 4796d7ed7e: every check was green at merge (8 verified; 11 skipped by policy). Full suite runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
c055747 ci: parse runner expressions in the fork guard, and gate LINUX_RUNNER on fork PRs (manaflow-ai#14192)
fc112a8 docs(testing): describe how run-e2e.sh actually picks the runner (manaflow-ai#14620)
0f6edfa ci(owned): keep seeds until the disk is actually short, not at a fixed 6 (manaflow-ai#14621)
1b78097 CI: one owned-pool rescue sweeper instead of a rescue run per CI run (manaflow-ai#14602)
c7e79f6 Hold Files tree reloads while its context menu is open (manaflow-ai#14451)
dbb24cb ci: read the owned-pool rescue's Actions API through the route App (manaflow-ai#14499)
36b8063 ci: store each app-host product file once in the product archive (manaflow-ai#14601)
0dba677 CI: run CmuxWorkspaces package tests (manaflow-ai#14592)
2244e98 Fix color detection in native tmux mirrors (manaflow-ai#14175)
3d2478e build: keep every built file in a project group so Xcode reuses its build description (manaflow-ai#14486)
a1a5ae9 ci(cmux-tui): cache cargo builds in the Rust jobs (manaflow-ai#14613)
560e640 ci(owned): keep 8 seeds per mini and pick seeds by cost, not a 2-commit cap (manaflow-ai#14607)
561d317 cmux-debug-cli: find a publish-hq build in the HQ tag app cache (manaflow-ai#14579)
c0aaac7 fix(events): survive receive-timeout reconfiguration churn during replay (manaflow-ai#13888)
3bd994a fix: keep split zoom when the zoomed pane outlives a tab close (manaflow-ai#12853)
ca984c7 Session snapshots can send binding actions to ghostty on a surface that is no longer live (manaflow-ai#12623)
a47d65b settings: expose local tmux session persistence (manaflow-ai#13210)
e3acb25 ci: give an owned Mac's full app rebuild 35 minutes to compile (manaflow-ai#14594)

# Conflicts:
#	.github/workflows/ci-artifact-transport.yml
#	.github/workflows/ci-cache-receipts.yml
#	.github/workflows/ci-guards.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci-owned-pool-rescue.yml
#	.github/workflows/ci-web.yml
#	.github/workflows/ci.yml
#	.github/workflows/cloud-machine-tests.yml
#	.github/workflows/cloud-vm-guest-install.yml
#	.github/workflows/cloud-vm-image-contract.yml
#	.github/workflows/cloud-vm-image-reachability.yml
#	.github/workflows/cloudflare-relay.yml
#	.github/workflows/cmux-skill-contract.yml
#	.github/workflows/cmux-tui-sdks.yml
#	.github/workflows/cmux-tui-spec.yml
#	.github/workflows/cmux-tui.yml
#	.github/workflows/indexnow-tests.yml
#	.github/workflows/iroh-v2.yml
#	.github/workflows/localization-catalog.yml
#	.github/workflows/r2-upload-tests.yml
#	.github/workflows/remote-daemon.yml
#	.github/workflows/repair-nightly-appcast-content-types.yml
#	.github/workflows/required-checks-drift.yml
#	.github/workflows/resolve-dispatch-ref.yml
#	.github/workflows/seed-derived-data.yml
#	.github/workflows/terminal-hang-diagnostics.yml
#	.github/workflows/test-e2e.yml
#	.github/workflows/test-ios.yml
#	.github/workflows/testbox-broker-guard.yml
#	.github/workflows/web-validation.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant