Skip to content

ci: accept the hosted-runner cla.yml from #14668 as the reviewed CLA base - #14675

Merged
teamleaderleo merged 1 commit into
mainfrom
ci/cla-guard-accept-hosted-runner
Sep 25, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
ci/cla-guard-accept-hosted-runner

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Since #14668 (06e064d) merged, the required "CLA policy guard" check has failed on every pull request against main.

#14668 pinned cla.yml's runs-on to ubuntu-24.04. That changed main's cla.yml bytes, and scripts/ci/validate-cla-policy.rb accepts the f567 action base only at its exact reviewed digest. Every PR is rejected with "base CLA action is not the exact reviewed workflow/helper pair".

This PR changes one constant:

  • CURRENT_MAIN_CLA_WORKFLOW_DIGEST: eb7b2307430453b4b7067fa0b20394b4ead6e9356b9668f1d198be6acb9623e1 -> ce0112907844270c70c5e2cc235e20f8a45eb7a0ef42a88f054ceb6dc0198a64 (sha256 of main's current .github/workflows/cla.yml)

No other check changes. CLA_RUNNER was already ubuntu-24.04, TRUSTED_REVIEWER_IDS is untouched, and cla.yml is untouched because a guard PR cannot also change policy. The regression matrices already refer to the constant, so they exercise the new base.

Review needed

This is a guard change. It needs an approving review from a trusted reviewer (@austinywang or @azooz2003-bit). The guard runs from the base branch (pull_request_target), so this PR's own "CLA policy guard" check runs main's validator and will fail for the same reason as every other PR. Merging it needs an admin override of that one check.

Verification

  • ruby scripts/ci/validate-cla-policy.rb: all 11 regression matrices pass, including "CLA action transition regression matrix (17 cases, 4 fixtures)".
  • A copy of this branch's validator that prints the rejection reason, run against test: count the seed-retry checkouts in the iOS dispatch ref test #14671 (base f8857c5, head 4377c0b):
    • main's validator: rejected the proposed policy: base CLA action is not the exact reviewed workflow/helper pair
    • this branch: PASS: CLA policy files are unchanged
  • No tests under tests/ cover the validator.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Updates the CLA policy guard's expected cla.yml digest so the required check passes again.

  • #14668 pinned cla.yml to ubuntu-24.04, changing main's workflow bytes and breaking the guard, which only accepts the exact reviewed digest.
  • Points CURRENT_MAIN_CLA_WORKFLOW_DIGEST at the new revision; all 11 regression matrices pass.

Written for commit 8560875. Summary will update on new commits.

Review in cubic

…base

#14668 pinned cla.yml's runs-on to ubuntu-24.04, which changed main's
cla.yml bytes. The CLA policy guard only accepts the f567 base at the
exact reviewed digest, so every pull request's required guard check has
failed with "base CLA action is not the exact reviewed workflow/helper
pair" since then. Point CURRENT_MAIN_CLA_WORKFLOW_DIGEST at the new
bytes. No other check changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 8 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3110ee17-c1e9-4b68-a505-bf4f0c44f846

📥 Commits

Reviewing files that changed from the base of the PR and between bd2d34e and 8560875.

📒 Files selected for processing (1)
  • scripts/ci/validate-cla-policy.rb

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit ce2a516 into main Sep 25, 2026
43 of 52 checks passed
@teamleaderleo
teamleaderleo deleted the ci/cla-guard-accept-hosted-runner branch September 25, 2026 18:24
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 8560875229, merged 2026-09-25 18:24:01 UTC

  • Not verified at merge: ci-status (failure), guards (18) (failure), linux-preflight (failure), tests (failure), CLA policy guard (failure)
  • Verified: Web complexity, web-validation, Fast static checks, Testbox broker trust boundary
  • Skipped by policy: browser, Claude wrapper regressions, GhosttyKit release check, macos, macOS admission gate, remote-daemon, suite-coverage, web, web-build, web-database-tests, web-tests
  • Full suite: runs on main after merge.

Labeled merged-unverified: if main breaks near this merge, look here first.

@github-actions github-actions Bot added the merged-unverified A judging check was not green at merge; see the merge receipt comment label Sep 25, 2026
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
a1ac750 Predictive local echo for remote terminals (manaflow-ai#13967)
e8e6a1a Split a single-argument tmux command string in __tmux-compat (manaflow-ai#14670)
eb3f0b3 ci: reuse the resolve's manifests on the first scheme build (manaflow-ai#14674)
56a1d4e test(ci): check each iOS checkout step's ref, anchor job lookup (manaflow-ai#14676)
0a51482 docs: keep contributor agent docs free of internal machines and apps (manaflow-ai#14672)
64939a3 ci: count the org glaeda-minis runners in the live pool picker (manaflow-ai#14678)
18e7750 ci: run E2E tests on the runner that built them (manaflow-ai#14667)
20cda9e Merge pull request manaflow-ai#12956 from manaflow-ai/12938-orbstack-daemon-bootstrap
1ee8b22 Merge pull request manaflow-ai#12834 from manaflow-ai/issue-12791-sidebar-rendering-stalls
5b87c90 ci: bisect package test failures across main's history, with a skill (manaflow-ai#14533)
ce2a516 ci: accept the hosted-runner cla.yml from manaflow-ai#14668 as the reviewed CLA base (manaflow-ai#14675)
e142cac test: count the seed-retry checkouts in the iOS dispatch ref test (manaflow-ai#14671)
465ccf3 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
e5441eb fix: preserve sidebar cache app target wiring
d4ca913 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
5a30066 fix(cloud): import shared route policy
6d49c7f refactor(cloud): isolate private port route policy
1322537 style(ssh): format browser proxy regression harness
1d9676d test: align remote Git metadata with directory trust policy
3e8a382 Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
fbb338b fix(ssh): route browser identities through guest loopback
da813a5 Wire AgentChatProseStreamWakeDriver.swift into the app target
5b4b943 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
6a90db3 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
91d432e ci: execute sidebar Git watcher regression tests
c473752 test: keep sidebar regression on the standard run loop
45e344c merge: preserve import coordinator while syncing current main
260f261 fix(ssh): use portable chmod syntax for macOS carriers
f90723f fix(ssh): keep stale projections out of Cloud image routing
f8838da fix(ssh): preserve remote file drops and IPv6 loopback routes
aea7e9d fix(ssh): carry remote loopback URLs through native browser routing
cb7221b test(ssh): cover loopback port preview ownership
8806879 Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
272453c fix(ssh): keep targeted reconnects scoped to their native viewer
fe0a782 test(ssh): reject unrelated pane reconnects in native workspaces
6e15d80 fix(ssh): preserve main behavior and TUI arguments after package merge
940cd10 Merge latest origin/main for CI compatibility
768e434 Merge latest origin/main into SSH TUI migration
c40ab2d chore(ssh): retain authentication localization entries
21db702 Merge concurrent SSH compatibility fixes
aee57ba fix: preserve compatible local SSH uploads without a companion target
6ee35b4 test: retain local SSH bootstrap for unsupported companion targets
41924e0 Merge origin/main into SSH TUI migration
7fe5fa8 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
bccce36 test: verify managed SSH respawn with runtime ownership checks
a37d876 Merge origin/main into SSH TUI migration
1136940 test: request UUID output for managed SSH runtime harness
2232f0a fix: aggregate native and legacy SSH session listings
7d42c80 test: retain legacy dispatch when no native SSH workspaces exist
0ff7f62 fix: localize shared SSH authentication errors
6feb176 fix: honor SSH profiles for provider-created terminals
afc61cb test: cover SSH provider default command and profile
b3d7cbf test(ssh): serialize shared catalog lifecycle fixtures
295dbf5 fix(ssh): replace native remote workloads through their TUI provider
6ce447c test(ssh): require provider-backed respawn with stable surface identity
460a007 test(ssh): identify Linux workload owners by executable path
ebb223b fix(ssh): lint loopback proxy policy plumbing
f8bf123 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into 12938-orbstack-daemon-bootstrap
18ac212 fix(ssh): thread loopback permission through proxy handlers
590dff5 Merge remote-tracking branch 'origin/main' into issue-13648-ssh-workspace-selection
7bd65e8 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
d4b16de fix(ssh): fail closed before native remote respawn reaches local exec
ac59a10 test(ssh): reject local respawn of native remote projections
d999e65 fix(ssh): treat TUI projections as remote image targets
5967c75 fix(ssh): route native agent forks through cmux-tui providers
f9c6797 test(ssh): prevent native agent forks from creating local terminals
3f684bf Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
cd0f1f4 style(ssh): format browser proxy regression test
20a1198 fix: bundle the published TUI client matching tagged source inputs
fe4f257 fix(ssh): allow authenticated loopback browser proxy routes
b05aa3e Merge remote-tracking branch 'origin/main' into 12938-orbstack-daemon-bootstrap
c2ba696 fix(ssh): share terminal catalog metadata and link routing
15656d0 test: keep direct ownership probe separate from detached tmux control
88ebcfe Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
be56208 test: measure hidden SSH reads and renderer presentation across selection
553cdd0 fix: classify native SSH projections through their authoritative owner
00750ab test: classify restored native SSH terminals as remote
365a6eb test: support isolated jump-host SSH selection fixtures
67b9fe3 Merge remote-tracking branch 'origin/12938-orbstack-daemon-bootstrap' into issue-13648-ssh-workspace-selection
0b14eb0 Merge branch '12938-orbstack-daemon-bootstrap' of https://github.com/manaflow-ai/cmux into issue-13648-ssh-workspace-selection
c2ce009 fix: preserve session and SSH options in managed TUI links
5e8bf78 test: preserve managed SSH session identity in TUI link launch
3983f4c test: require cmux-tui ownership across managed SSH selection
460950d Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
ec6a650 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
634509f Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
a71b3dc fix: retain initial sidebar snapshot observation
414e47f chore: normalize merged source whitespace
6734ee9 merge: sync latest main
264c7da test: pump common run loop modes for sidebar harness
8662152 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
d386ce0 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
13d30fa Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
4092d91 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
de85594 fix: handle blank browser import identifiers
fa8e093 Merge branch 'main' of https://github.com/manaflow-ai/cmux into issue-12791-sidebar-rendering-stalls
1d9afef fix: instantiate browser destination resolver adapter
110d737 fix: expose Foundation UUID in browser resolver API
4d4c8ea refactor: move browser destination resolution into CmuxBrowser
a73b116 merge origin/main into issue-12791-sidebar-rendering-stalls
4a6a7df test: isolate shared watcher lifecycle fixture
511d198 fix: import process identity from CmuxFoundation
683ca09 fix: close browser import review findings
c9de46c merge origin/main into issue-12791-sidebar-rendering-stalls
bb48a38 test: inject browser import coordinator in wizard coverage
3ee91b2 fix: preserve watcher on failed discovery and browser automation contracts
d790f65 test: reproduce installed watcher loss on descriptor failure
642c86a fix: scope browser import automation helper
f9f67f4 merge origin/main into issue-12791-sidebar-rendering-stalls
79e6a1a fix: continue issue 12791 rendering stall repairs
9ee3bb1 test: preserve Git metadata monitoring when watcher replacement fails
0bffb5f fix: construct sidebar snapshots only at lifecycle and event boundaries
2e683ce test: import Cloud fixture remote configuration from its owning module
8d16430 Merge remote-tracking branch 'origin/main' into issue-12791-sidebar-rendering-stalls
50b7233 fix: restore pairing preparation recovery lost in upstream merge
f165b33 test: split nested Cloud assertion to unblock hosted suites
d5464d0 test: verify native callback lifetime through queued teardown
ccfe1cd Merge remote-tracking branch 'origin/main' into issue-12791-sidebar-rendering-stalls
ad3672a fix: retain the FSEvents receiver through native registration
fee5924 fix: isolate sidebar discovery and bound workspace snapshot lifetime
dbba283 test: reproduce sidebar snapshots surviving workspace replacement

# Conflicts:
#	.github/workflows/ci-guards.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci.yml
#	.github/workflows/test-e2e.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merged-unverified A judging check was not green at merge; see the merge receipt comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant