Repository navigation
ci: read the owned-pool rescue's Actions API through the route App - #14499
Conversation
…ission finishes The picker places every job at run start, but the app-host shards, tests-build-and-lag and cli-product-tests start only after compile admission. When the owned pool was full at the start they stayed on Blacksmith even after roots drained (09-25: 19 jobs queued on blacksmith-12vcpu-macos-26, cap 5, while 9 of 16 std roots were idle). A late-placement job reads the idle root runners live through the route App after admission succeeds and gives the not-yet-owned jobs the root label for admission's Xcode, one per idle runner. They fetch admission's products as they do after an owned admission. Attempt 1 of same-repo PRs only; any failure leaves the run-start placement. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review: a moved job waits for a root runner that another run may take first, and a run whose picker owned nothing had no rescue watch, so it could sit queued with nothing to move it back to Blacksmith. late-placement now uploads a macos-pool-late-<run>-<attempt> marker when it moves jobs. ci.yml's owned-pool-watch also starts the rescue for a same-repo PR whose picker owned nothing but which has jobs after admission (full or unit suite, or the CLI lane), with late=1. That watch reads the picker's marker once, then waits at IDLE_POLL_SECONDS for ci-macos.yml's late-placement job, and follows the run only if its marker exists. Existing watches are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ment # Conflicts: # tests/test-execution.toml
The watch polls jobs and artifacts on GITHUB_TOKEN, about 1000 requests an hour for the whole repository. The org's manaflow-glaeda-route App already has actions access (cmuxterm-hq#639) and its own 5000 an hour. The rescue workflow mints an App token (actions, contents and pull-requests read) and the script sends every GET with it. Cancels and re-runs keep GITHUB_TOKEN, because ci-macos.yml's attempt-2 routing requires the re-run's triggering actor to be github-actions[bot]. A 401 on a read (the token lasts an hour, a watch may run longer) drops back to GITHUB_TOKEN; a failed mint leaves every request on GITHUB_TOKEN. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 18 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ment # Conflicts: # tests/test-execution.toml
…ment # Conflicts: # scripts/ci/owned_pool_rescue.py
… into ci/rescue-app-token-reads
|
All contributors have signed the CLA ✍️ ✅ |
|
Merge receipt for |
c055747 ci: parse runner expressions in the fork guard, and gate LINUX_RUNNER on fork PRs (manaflow-ai#14192) fc112a8 docs(testing): describe how run-e2e.sh actually picks the runner (manaflow-ai#14620) 0f6edfa ci(owned): keep seeds until the disk is actually short, not at a fixed 6 (manaflow-ai#14621) 1b78097 CI: one owned-pool rescue sweeper instead of a rescue run per CI run (manaflow-ai#14602) c7e79f6 Hold Files tree reloads while its context menu is open (manaflow-ai#14451) dbb24cb ci: read the owned-pool rescue's Actions API through the route App (manaflow-ai#14499) 36b8063 ci: store each app-host product file once in the product archive (manaflow-ai#14601) 0dba677 CI: run CmuxWorkspaces package tests (manaflow-ai#14592) 2244e98 Fix color detection in native tmux mirrors (manaflow-ai#14175) 3d2478e build: keep every built file in a project group so Xcode reuses its build description (manaflow-ai#14486) a1a5ae9 ci(cmux-tui): cache cargo builds in the Rust jobs (manaflow-ai#14613) 560e640 ci(owned): keep 8 seeds per mini and pick seeds by cost, not a 2-commit cap (manaflow-ai#14607) 561d317 cmux-debug-cli: find a publish-hq build in the HQ tag app cache (manaflow-ai#14579) c0aaac7 fix(events): survive receive-timeout reconfiguration churn during replay (manaflow-ai#13888) 3bd994a fix: keep split zoom when the zoomed pane outlives a tab close (manaflow-ai#12853) ca984c7 Session snapshots can send binding actions to ghostty on a surface that is no longer live (manaflow-ai#12623) a47d65b settings: expose local tmux session persistence (manaflow-ai#13210) e3acb25 ci: give an owned Mac's full app rebuild 35 minutes to compile (manaflow-ai#14594) # Conflicts: # .github/workflows/ci-artifact-transport.yml # .github/workflows/ci-cache-receipts.yml # .github/workflows/ci-guards.yml # .github/workflows/ci-macos.yml # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/ci-web.yml # .github/workflows/ci.yml # .github/workflows/cloud-machine-tests.yml # .github/workflows/cloud-vm-guest-install.yml # .github/workflows/cloud-vm-image-contract.yml # .github/workflows/cloud-vm-image-reachability.yml # .github/workflows/cloudflare-relay.yml # .github/workflows/cmux-skill-contract.yml # .github/workflows/cmux-tui-sdks.yml # .github/workflows/cmux-tui-spec.yml # .github/workflows/cmux-tui.yml # .github/workflows/indexnow-tests.yml # .github/workflows/iroh-v2.yml # .github/workflows/localization-catalog.yml # .github/workflows/r2-upload-tests.yml # .github/workflows/remote-daemon.yml # .github/workflows/repair-nightly-appcast-content-types.yml # .github/workflows/required-checks-drift.yml # .github/workflows/resolve-dispatch-ref.yml # .github/workflows/seed-derived-data.yml # .github/workflows/terminal-hang-diagnostics.yml # .github/workflows/test-e2e.yml # .github/workflows/test-ios.yml # .github/workflows/testbox-broker-guard.yml # .github/workflows/web-validation.yml
Stacked on #14460. GitHub retargets it to
mainwhen that merges.What
The owned-pool rescue polls the Actions API (jobs, artifacts, the run, the PR head) on
GITHUB_TOKEN. That token has about 1000 requests an hour for the whole repository, which is what kept #14460 from watching more runs. The org'smanaflow-glaeda-routeApp already has Actions access (cmuxterm-hq#639) and its own budget of 5000 an hour.ci-owned-pool-rescue.ymlmints an App installation token withactions,contentsandpull-requestsread. The step iscontinue-on-errorand only runs whenGLAEDA_ROUTE_APP_IDis set.owned_pool_rescue.GitHubsends every GET with that token (READ_TOKEN).GITHUB_TOKEN.ci-macos.ymlroutes a rescued attempt 2 back to the fleet only whengithub.triggering_actor == 'github-actions[bot]'. A re-run started by the App would silently skip that.GITHUB_TOKENfor the rest of the watch. If the token can't be minted, everything stays onGITHUB_TOKEN, as it is today.Tests
tests/test_ci_owned_pool_rescue.pyadds aTokensclass. It checks that reads use the App token while writes keep the repo token, that an expired App token falls back, that everything uses the repo token when there is no App token, and how the workflow mints and passes the token. All 80 rescue tests pass, and actionlint is clean on every workflow.🤖 Generated with Claude Code
Summary by cubic
Switches the owned-pool rescue's Actions API reads (jobs, artifacts, the run, the PR head) from the repository's
GITHUB_TOKENto themanaflow-glaeda-routeApp installation token, which has its own 5000 requests an hour instead of the repository's shared 1000.actions,contents, andpull-requestsread access; a failed or skipped mint leaves all requests onGITHUB_TOKEN.GITHUB_TOKENso attempt-2 re-runs stay attributed togithub-actions[bot]for fleet routing.GITHUB_TOKENfor the rest of the watch.Written for commit 4796d7e. Summary will update on new commits.