Repository navigation
ci: point restored products at their own package frameworks - #14930
Conversation
Debug builds link every Mach-O with an absolute rpath to the DerivedData they were compiled in, ahead of the bundle-relative ones. A consumer that restores a product into its own DerivedData on an owned Mac often still has that producer path: the canonical root's kept build of another commit. dyld then loads that commit's package frameworks first. On main the bundled CLI died with "Symbol not found" in CMUXAgentLaunch, failing dozens of CLI and hook tests with status 6, and tests-build-and-lag's app crashed at startup. restore-app-host-test-product.sh now rewrites that rpath, in every Mach-O under the restored products, to the products' own PackageFrameworks and re-signs ad hoc what changed, innermost first. A product restored where it was compiled has nothing to rewrite. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 2 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (11)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
The absolute replacement did not fit: on cmux11s the CLI product's restore failed because the runner's _work/_temp products path is longer than the linker's load-command padding allows. An @loader_path-relative path is always shorter than the 81-byte producer path and still holds when the whole products directory is copied. Also from review: print the failing tool's stderr, delete a second producer spelling instead of duplicating the rpath, re-sign every bundle around a rewritten file, and list the script with its neighbours in ci.yml's router and the routing tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Merge receipt for |
5090403 UI test frames: sample XCTest screen recordings; SIGKILL stuck prompts (manaflow-ai#14956) 9943115 Canvas: keep agent panes from moving the viewport; honor Reduce Motion (manaflow-ai#14939) f873b5a Fix duplicate-instance handler terminating unrelated helpers (manaflow-ai#13845) 0c151d1 Open Settings panes at their natural top (manaflow-ai#14950) cfdde0b cmux-tui: inject Claude hooks through a PATH shim, including under sr (manaflow-ai#14908) 320a966 ci: correct the producer rpath length in the relocation docstring (manaflow-ai#14947) 8f79066 Hover never outshouts selection; focus, badge, and feed pill edges (manaflow-ai#14941) 5617ac3 cmux-tui: publish the agent's session id on the agents roster (manaflow-ai#14904) 533a5b9 fix: stop WindowAccessor storing a deallocating window (manaflow-ai#14946) 9546e06 reloadp.sh: exclude only this build's own bundle from the stable check (manaflow-ai#14889) e27f361 docs: say full-ci runs only selected cmuxUITests targets (manaflow-ai#14945) 28d1eaf ci: point restored products at their own package frameworks (manaflow-ai#14930) 75caaa5 Land hot-path sidebar, feed, palette and notification state changes in the next frame (manaflow-ai#14927) 6b58884 docs: tighten CLAUDE.md and CONTRIBUTING.md; move procedures to skills (manaflow-ai#14920)
Main's app-host shards and tests-build-and-lag load a different commit's package frameworks on the owned Macs.
Every Mach-O in a Debug build has an absolute rpath to the DerivedData it was compiled in, ahead of the bundle-relative ones:
A consumer restores the product into its own DerivedData. On an owned Mac the producer's path usually exists anyway: it is that canonical root's kept build, from whatever commit last compiled there. dyld loads package frameworks from it first. When their API has moved, the load fails:
On the last three main runs this is most of the red:
cmuxexits 6restore-app-host-test-product.sh, which every consumer uses, now runsscripts/ci/relocate_package_framework_rpaths.pyright after the product lands:PackageFrameworks.get-task-allow), flags and runtime.rsync -aLleaves atX.framework/XandVersions/Current/X: install names always sayVersions/A, so dyld never loads them.Verification
codesign --verify --deep --strictpasses on the app, andget-task-allowis still there.DYLD_PRINT_LIBRARIESshowsCMUXAgentLaunchloading from the clone's ownPackageFrameworks.nothing to rewrite.tests/test_relocate_package_framework_rpaths.py: path matching, framework-copy skipping and signing targets, plus a macOS round trip. The round trip links a small binary with a producer rpath, relocates it, verifies the signature, runs it, and checks that a second pass is a no-op.Not covered here: cmux7s has one canonical root, so a shard holding a root-2 product that lands there still fails at
take-root(shard 3 of 36295033926). That is fleet config and goes in a separate change.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes app-host test products on owned Macs loading package frameworks from another commit's DerivedData, which caused
Symbol not foundfailures across CLI, hook, and session-start suites on main.restore-app-host-test-product.shnow runs a new script that rewrites each restored product's compile-time package-framework rpath to an@loader_path-relative path into the product's ownPackageFrameworks— an absolute replacement overflowed the linker's load-command padding on deep runner paths — then re-signs ad hoc what it changed and its enclosing bundles. Adds unit tests and a macOS round-trip test.Verification
codesign --verifypasses, the CLI runs, and a second run is a no-op.Written for commit 606dd70. Summary will update on new commits.