Skip to content

ci: reuse the resolve's manifests on the first scheme build - #14674

Merged
teamleaderleo merged 2 commits into
mainfrom
ci/manifest-cache-first-build
Sep 25, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
ci/manifest-cache-first-build

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Part of hq#661 workstream 5 (compile speed on the owned minis).

The first of the admission's scheme builds spent 18 to 44 s in Resolve Package Graph re-evaluating all 91 Package.swift files. SwiftPM keys each evaluated manifest on xcodebuild's whole environment. The resolve runs under swiftpm-manifest-cache.sh run (fixed env), and so does the seeded cache, but the builds ran under the step's environment, so they never hit.

This PR:

  • runs every scheme build through the same run wrapper, with FileSystemMode kept on both the resolve and the builds, so they share one environment;
  • hands the caller's HOME, CI, TMPDIR, CMUX_*, CARGO_*, RUSTUP_* and Go variables to the script phases as command-line build settings. Build settings reach every script phase's environment but not SwiftPM's key;
  • passes PATH as CMUX_CALLER_PATH, since Swift Build builds a script's PATH from its own process PATH and ignores a PATH build setting. scripts/build-phase-caller-path.sh puts it back behind Xcode's tool directories, where Xcode would have put it. It is sourced by the Nucleo FFI, diff sidecar, wireguard-go and bundled-resources phases, and does nothing outside CI.

Evidence (toy project, Xcode 27, local package)

Manifest cache entries after each step, starting from a fresh manifest:

  • resolve under run: +1 (evaluated)
  • build under run with HOME, CI, CMUX_CALLER_PATH, CMUX_SKIP_ZIG_BUILD settings: +0 (hit)
  • build the old way: +1 (miss)

The same toy confirmed that script phases see the forwarded settings, that the restored PATH finds ~/.cargo/bin/cargo, and that a PATH= build setting is ignored for script phases.

After merge

Changing swiftpm-manifest-cache.sh changes the manifest cache key, so dispatch seed-derived-data.yml and seed-swiftpm-manifests.yml on main. Until then readers fall back to the old prefix entries, which miss.

Tests

  • tests/test_ci_canonical_build_root.py: builds share the resolve's exact environment, per-step noise (GITHUB_RUN_ID) stays out, forwarded settings and CMUX_CALLER_PATH reach every build, and the PATH helper restores the caller PATH behind Xcode's directories.
  • tests/test_build_app_bundled_resources.sh, tests/test_ci_test_compilation_cache_seed.sh, tests/test_ci_swiftpm_manifest_cache.sh pass.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Runs every scheme build through the same swiftpm-manifest-cache.sh environment as the resolve, so the first build reuses its evaluated Package.swift manifests instead of re-evaluating all 91 (18–44 s per admission). Script phases still receive the caller's PATH, HOME, CI, and toolchain settings via command-line build settings, which SwiftPM excludes from its cache key; a new build-phase-caller-path.sh helper restores the caller's PATH in the Nucleo FFI, diff sidecar, wireguard-go, and bundled-resources phases. Secret-looking variable names (*TOKEN*, *SECRET*, *PASSWORD*, *_KEY) are dropped from the forwarded settings because they land in the build log a DerivedData seed carries.

After merge

  • Changing swiftpm-manifest-cache.sh changes the manifest cache key; dispatch seed-derived-data.yml and seed-swiftpm-manifests.yml on main.

Written for commit ccb209d. Summary will update on new commits.

Review in cubic

SwiftPM keys each evaluated Package.swift on xcodebuild's whole
environment. The resolve runs under swiftpm-manifest-cache.sh's fixed
environment, but every scheme build ran under the step's, so the first
build re-evaluated all 91 manifests: 18 to 44 s per owned admission.

Run the builds through the same `run` wrapper, with FileSystemMode kept
on both the resolve and the builds. The app's script phases still need
the caller's environment, so hand HOME, CI, TMPDIR and the CMUX_*,
CARGO_*, RUSTUP_* and Go variables over as command-line build settings,
which reach script phases but not SwiftPM's key. Swift Build ignores a
PATH build setting, so PATH travels as CMUX_CALLER_PATH and
scripts/build-phase-caller-path.sh restores it behind Xcode's tool
directories in the Nucleo FFI, diff sidecar, wireguard-go and bundled
resources phases.

Changing swiftpm-manifest-cache.sh changes the manifest cache key, so
seed-derived-data.yml and seed-swiftpm-manifests.yml need a dispatch
after merge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 10 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: cf9680c8-1092-4523-8f25-9c9e7888c7f5

📥 Commits

Reviewing files that changed from the base of the PR and between f8857c5 and ccb209d.

📒 Files selected for processing (8)
  • scripts/build-app-bundled-resources.sh
  • scripts/build-command-palette-nucleo-ffi.sh
  • scripts/build-diff-sidecar.sh
  • scripts/build-phase-caller-path.sh
  • scripts/build-wireguard-go.sh
  • scripts/ci/compile-app-host-test-product.sh
  • scripts/ci/swiftpm-manifest-cache.sh
  • tests/test_ci_canonical_build_root.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@blacksmith-sh

This comment has been minimized.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@blacksmith-sh

blacksmith-sh Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Found 1 test failure on Blacksmith runners:

Failure

Test View Logs
test_paid_and_downstream_jobs_checkout_only_the_resolved_sha (main.IOSWorkflowDispa
tchRefTests.test_paid_and_downstream_jobs_checkout_only_the_resolved_sha)/
test_paid_and_downstream_jobs_checkout_only_the_resolved_sha (main.IOSWorkflowDispa
tchRefTests.test_paid_and_downstream_jobs_checkout_only_the_resolved_sha)
View Logs

Fix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need.

@teamleaderleo
teamleaderleo merged commit eb3f0b3 into main Sep 25, 2026
100 of 115 checks passed
@teamleaderleo
teamleaderleo deleted the ci/manifest-cache-first-build branch September 25, 2026 18:47
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for ccb209d5ec, merged 2026-09-25 18:47:11 UTC

  • Not verified at merge: ci-status (failure), guards (18) (failure), linux-preflight (failure), tests (failure), CLA policy guard (failure)
  • Verified: macOS compile admission, Web complexity, web-validation, diff-sidecar-check, Fast static checks, GhosttyKit release check, macOS admission gate, macOS status, Testbox broker trust boundary, Web status, web-subarea-scope
  • Skipped by policy: app-host unit tests, agent-session-web-resources, browser, Claude wrapper regressions, CLI product tests, late-placement, react-apps-check, release-admission, release-build, remote-daemon, suite-coverage, swift-package-tests, and 9 more
  • Full suite: runs on main after merge.

Labeled merged-unverified: if main breaks near this merge, look here first.

@github-actions github-actions Bot added the merged-unverified A judging check was not green at merge; see the merge receipt comment label Sep 25, 2026
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
a1ac750 Predictive local echo for remote terminals (manaflow-ai#13967)
e8e6a1a Split a single-argument tmux command string in __tmux-compat (manaflow-ai#14670)
eb3f0b3 ci: reuse the resolve's manifests on the first scheme build (manaflow-ai#14674)
56a1d4e test(ci): check each iOS checkout step's ref, anchor job lookup (manaflow-ai#14676)
0a51482 docs: keep contributor agent docs free of internal machines and apps (manaflow-ai#14672)
64939a3 ci: count the org glaeda-minis runners in the live pool picker (manaflow-ai#14678)
18e7750 ci: run E2E tests on the runner that built them (manaflow-ai#14667)
20cda9e Merge pull request manaflow-ai#12956 from manaflow-ai/12938-orbstack-daemon-bootstrap
1ee8b22 Merge pull request manaflow-ai#12834 from manaflow-ai/issue-12791-sidebar-rendering-stalls
5b87c90 ci: bisect package test failures across main's history, with a skill (manaflow-ai#14533)
ce2a516 ci: accept the hosted-runner cla.yml from manaflow-ai#14668 as the reviewed CLA base (manaflow-ai#14675)
e142cac test: count the seed-retry checkouts in the iOS dispatch ref test (manaflow-ai#14671)
465ccf3 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
e5441eb fix: preserve sidebar cache app target wiring
d4ca913 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
5a30066 fix(cloud): import shared route policy
6d49c7f refactor(cloud): isolate private port route policy
1322537 style(ssh): format browser proxy regression harness
1d9676d test: align remote Git metadata with directory trust policy
3e8a382 Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
fbb338b fix(ssh): route browser identities through guest loopback
da813a5 Wire AgentChatProseStreamWakeDriver.swift into the app target
5b4b943 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
6a90db3 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
91d432e ci: execute sidebar Git watcher regression tests
c473752 test: keep sidebar regression on the standard run loop
45e344c merge: preserve import coordinator while syncing current main
260f261 fix(ssh): use portable chmod syntax for macOS carriers
f90723f fix(ssh): keep stale projections out of Cloud image routing
f8838da fix(ssh): preserve remote file drops and IPv6 loopback routes
aea7e9d fix(ssh): carry remote loopback URLs through native browser routing
cb7221b test(ssh): cover loopback port preview ownership
8806879 Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
272453c fix(ssh): keep targeted reconnects scoped to their native viewer
fe0a782 test(ssh): reject unrelated pane reconnects in native workspaces
6e15d80 fix(ssh): preserve main behavior and TUI arguments after package merge
940cd10 Merge latest origin/main for CI compatibility
768e434 Merge latest origin/main into SSH TUI migration
c40ab2d chore(ssh): retain authentication localization entries
21db702 Merge concurrent SSH compatibility fixes
aee57ba fix: preserve compatible local SSH uploads without a companion target
6ee35b4 test: retain local SSH bootstrap for unsupported companion targets
41924e0 Merge origin/main into SSH TUI migration
7fe5fa8 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
bccce36 test: verify managed SSH respawn with runtime ownership checks
a37d876 Merge origin/main into SSH TUI migration
1136940 test: request UUID output for managed SSH runtime harness
2232f0a fix: aggregate native and legacy SSH session listings
7d42c80 test: retain legacy dispatch when no native SSH workspaces exist
0ff7f62 fix: localize shared SSH authentication errors
6feb176 fix: honor SSH profiles for provider-created terminals
afc61cb test: cover SSH provider default command and profile
b3d7cbf test(ssh): serialize shared catalog lifecycle fixtures
295dbf5 fix(ssh): replace native remote workloads through their TUI provider
6ce447c test(ssh): require provider-backed respawn with stable surface identity
460a007 test(ssh): identify Linux workload owners by executable path
ebb223b fix(ssh): lint loopback proxy policy plumbing
f8bf123 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into 12938-orbstack-daemon-bootstrap
18ac212 fix(ssh): thread loopback permission through proxy handlers
590dff5 Merge remote-tracking branch 'origin/main' into issue-13648-ssh-workspace-selection
7bd65e8 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
d4b16de fix(ssh): fail closed before native remote respawn reaches local exec
ac59a10 test(ssh): reject local respawn of native remote projections
d999e65 fix(ssh): treat TUI projections as remote image targets
5967c75 fix(ssh): route native agent forks through cmux-tui providers
f9c6797 test(ssh): prevent native agent forks from creating local terminals
3f684bf Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
cd0f1f4 style(ssh): format browser proxy regression test
20a1198 fix: bundle the published TUI client matching tagged source inputs
fe4f257 fix(ssh): allow authenticated loopback browser proxy routes
b05aa3e Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
c2ba696 fix(ssh): share terminal catalog metadata and link routing
15656d0 test: keep direct ownership probe separate from detached tmux control
88ebcfe Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
be56208 test: measure hidden SSH reads and renderer presentation across selection
553cdd0 fix: classify native SSH projections through their authoritative owner
00750ab test: classify restored native SSH terminals as remote
365a6eb test: support isolated jump-host SSH selection fixtures
67b9fe3 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
0b14eb0 Merge branch '12938-orbstack-daemon-bootstrap' of https://github.com/manaflow-ai/cmux into issue-13648-ssh-workspace-selection
c2ce009 fix: preserve session and SSH options in managed TUI links
5e8bf78 test: preserve managed SSH session identity in TUI link launch
3983f4c test: require cmux-tui ownership across managed SSH selection
460950d Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
ec6a650 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
634509f Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
a71b3dc fix: retain initial sidebar snapshot observation
414e47f chore: normalize merged source whitespace
6734ee9 merge: sync latest main
264c7da test: pump common run loop modes for sidebar harness
8662152 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
d386ce0 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
13d30fa Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
4092d91 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
de85594 fix: handle blank browser import identifiers
fa8e093 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
1d9afef fix: instantiate browser destination resolver adapter
110d737 fix: expose Foundation UUID in browser resolver API
4d4c8ea refactor: move browser destination resolution into CmuxBrowser
a73b116 merge origin/main into issue-12791-sidebar-rendering-stalls
4a6a7df test: isolate shared watcher lifecycle fixture
511d198 fix: import process identity from CmuxFoundation
683ca09 fix: close browser import review findings
c9de46c merge origin/main into issue-12791-sidebar-rendering-stalls
bb48a38 test: inject browser import coordinator in wizard coverage
3ee91b2 fix: preserve watcher on failed discovery and browser automation contracts
d790f65 test: reproduce installed watcher loss on descriptor failure
642c86a fix: scope browser import automation helper
f9f67f4 merge origin/main into issue-12791-sidebar-rendering-stalls
79e6a1a fix: continue issue 12791 rendering stall repairs
9ee3bb1 test: preserve Git metadata monitoring when watcher replacement fails
0bffb5f fix: construct sidebar snapshots only at lifecycle and event boundaries
2e683ce test: import Cloud fixture remote configuration from its owning module
8d16430 Merge remote-tracking branch 'origin/main' into issue-12791-sidebar-rendering-stalls
50b7233 fix: restore pairing preparation recovery lost in upstream merge
f165b33 test: split nested Cloud assertion to unblock hosted suites
d5464d0 test: verify native callback lifetime through queued teardown
ccfe1cd Merge remote-tracking branch 'origin/main' into issue-12791-sidebar-rendering-stalls
ad3672a fix: retain the FSEvents receiver through native registration
fee5924 fix: isolate sidebar discovery and bound workspace snapshot lifetime
dbba283 test: reproduce sidebar snapshots surviving workspace replacement

# Conflicts:
#	.github/workflows/ci-guards.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci.yml
#	.github/workflows/test-e2e.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merged-unverified A judging check was not green at merge; see the merge receipt comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant