Skip to content

Migrate CI/CD to WarpBuild runners - #1500

Closed
lawrencecchen wants to merge 6 commits into
mainfrom
task-migrate-warpcloud
Closed

lawrencecchen wants to merge 6 commits into
mainfrom
task-migrate-warpcloud

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Mar 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Swaps all macOS runner labels from Depot and GitHub-hosted to WarpBuild. Job structure is unchanged.

  • depot-macos-latest → warp-macos-15-arm64-6x
  • macos-15 → warp-macos-15-arm64-6x
  • macos-14 → warp-macos-14-arm64-6x
  • ubuntu-latest unchanged for lightweight jobs
  • Updated CI guard test and comments

Affected workflows: ci.yml, build-ghosttykit.yml, ci-macos-compat.yml, nightly.yml, release.yml, test-depot.yml, test-e2e.yml

Compare with https://github.com/manaflow-ai/cmux/pull/new/task-migrate-warpcloud-consolidated (consolidated version that merges tests + tests-depot into one job).

Testing

  • Guard test passes locally: bash tests/test_ci_self_hosted_guard.sh → PASS
  • No old runner labels remain: grep -rn 'depot-macos-latest\|runs-on: macos-1[45]' .github/workflows/ → empty

🤖 Generated with Claude Code


Summary by cubic

Migrates all macOS CI/CD workflows to WarpBuild runners and pins zig 0.15.2 via tarballs for consistent builds. Adds 20‑minute timeouts to macOS jobs; Ubuntu jobs remain on ubuntu-latest.

  • Migration
    • Runner label swaps: depot-macos-latest → warp-macos-15-arm64-6x, macos-15 → warp-macos-15-arm64-6x, macos-14 → warp-macos-14-arm64-6x.
    • Job updates: add 20‑min timeouts; rename tests-depot → tests-ui; update guard script/test for WarpBuild-only internal runs; update test-e2e.yml runner inputs/defaults and cache keys to WarpBuild labels.
    • Pin zig to 0.15.2 by downloading from ziglang.org; auto-upgrade if outdated; fix tarball to zig-aarch64-macos-0.15.2.tar.xz; create /usr/local/bin and /usr/local/lib before install.
    • Workflows touched: ci.yml, ci-macos-compat.yml, test-e2e.yml, test-depot.yml, release.yml, nightly.yml, build-ghosttykit.yml.

Written for commit 0b1b591. Summary will update on new commits.

Summary by CodeRabbit

  • Chores

    • Switched CI to new WarpBuild macOS runners across workflows for consistent builds and releases.
    • Introduced a guarded, versioned Zig install requiring Zig 0.15.2; missing or mismatched installs are downloaded, installed, and verified before continuing.
    • Updated workflow references and platform-related cache keys to reflect the new runner platform.
  • Tests

    • Updated CI self-hosted guard checks and success/error messaging to align with the new runners.

Replace all macOS runner labels across workflows:
- depot-macos-latest → warp-macos-15-arm64-6x
- macos-15 → warp-macos-15-arm64-6x
- macos-14 → warp-macos-14-arm64-6x

Keeps job structure unchanged (tests + tests-depot as separate jobs).
Ubuntu jobs remain on ubuntu-latest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vercel

vercel Bot commented Mar 16, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Mar 16, 2026 9:32am

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Compare with consolidated version: #1501

@coderabbitai

coderabbitai Bot commented Mar 16, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Replaces Depot/standard macOS runner labels with WarpBuild runner labels across CI workflows; introduces a Zig version guard (ZIG_REQUIRED="0.15.2") that downloads/installs the Zig 0.15.2 tarball when missing/mismatched; updates CI guard script and messages to reference WarpBuild.

Changes

Cohort / File(s) Summary
Single-job runner swaps
.github/workflows/build-ghosttykit.yml, .github/workflows/nightly.yml, .github/workflows/release.yml, .github/workflows/test-depot.yml
Replaced depot-macos-latest/macos-15 with warp-macos-15-arm64-6x; updated step names/comments to reference WarpBuild.
Matrix / inputs / cache keys
.github/workflows/ci-macos-compat.yml, .github/workflows/test-e2e.yml
Switched matrix entries, workflow inputs, and cache keys from macOS labels to warp-macos-14-arm64-6x, warp-macos-15-arm64-6x, warp-macos-26-arm64-6x; adjusted defaults/fallbacks.
Zig installation logic (version-guard + tarball)
.github/workflows/ci.yml, .github/workflows/ci-macos-compat.yml, .github/workflows/nightly.yml, .github/workflows/release.yml, .github/workflows/build-ghosttykit.yml, .github/workflows/test-e2e.yml
Replaced simple brew install zig with a ZIG_REQUIRED="0.15.2" check; if missing or mismatched, download/extract Zig 0.15.2 tarball, copy binaries/libs to /usr/local, update PATH, and verify zig version.
CI self-hosted guard script
tests/test_ci_self_hosted_guard.sh
Renamed guard variables/messages from Depot → WarpBuild (saw_depot → saw_warp), updated pattern matching to detect warp-macos-15-arm64-6x in workflows.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

aardvark, codex

Poem

🐰 I swapped the old Depot for WarpBuild's bright cheer,
I fetched Zig's tarball and tucked its tools near.
Binaries snug in /usr/local's bed,
CI carrots queued, builds hop ahead.
Hop, compile, test — a rabbit-coded cheer!

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Migrate CI/CD to WarpBuild runners' directly and accurately reflects the main change: replacing all macOS runner labels across workflows with WarpBuild runners.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description check ✅ Passed The PR description covers the main changes (runner migration to WarpBuild), testing performed (guard test passing, grep verification), and lists affected workflows.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch task-migrate-warpcloud
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
.github/workflows/test-depot.yml (1)

1-1: Consider renaming workflow to reflect WarpBuild migration.

The workflow name still says "Run tests on Depot" but now uses WarpBuild runners (warp-macos-15-arm64-6x). This could cause confusion when viewing workflow runs in the GitHub Actions UI.

💡 Suggested rename
-name: Run tests on Depot
+name: Run tests on WarpBuild

Note: Renaming the file from test-depot.yml to test-warpbuild.yml would be a more thorough cleanup but may require updating any references (e.g., gh workflow run commands in documentation).

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/test-depot.yml at line 1, The workflow name value "Run
tests on Depot" should be updated to reflect the WarpBuild runner migration
(e.g., change the name string to "Run tests on WarpBuild" or similar) and,
optionally, rename the workflow file from test-depot.yml to test-warpbuild.yml
if you also want the filename to match; update any external references (scripts,
docs, gh workflow run commands) that reference the old name/file to avoid broken
links.
.github/workflows/ci.yml (1)

186-189: Consider renaming tests-depot job for consistency.

The job name tests-depot now runs on WarpBuild (warp-macos-15-arm64-6x), which is misleading. The comment correctly references WarpBuild billing.

Note: Renaming the job would require updating tests/test_ci_self_hosted_guard.sh which greps for /^ tests-depot:/. If you decide to rename, both would need to change together.

💡 Suggested rename (requires coordinated change)

In .github/workflows/ci.yml:

-  tests-depot:
+  tests-warpbuild:
     # Never run WarpBuild jobs for fork pull requests (avoid billing on external PRs).

In tests/test_ci_self_hosted_guard.sh:

-  /^  tests-depot:/ { in_tests=1; next }
+  /^  tests-warpbuild:/ { in_tests=1; next }

This is optional and can be deferred since functionality is correct.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci.yml around lines 186 - 189, Rename the CI job
"tests-depot" to a name that reflects it runs on WarpBuild (e.g.,
"warpbuild-tests") by updating the job key in .github/workflows/ci.yml (replace
the job identifier tests-depot with the new name) and update the test that
asserts the job name by changing the grep/regex in
tests/test_ci_self_hosted_guard.sh (which currently looks for /^  tests-depot:/)
to match the new job name; ensure the associated inline comment about
WarpBuild/billing remains accurate and run CI tests to validate the coordinated
change.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 186-189: Rename the CI job "tests-depot" to a name that reflects
it runs on WarpBuild (e.g., "warpbuild-tests") by updating the job key in
.github/workflows/ci.yml (replace the job identifier tests-depot with the new
name) and update the test that asserts the job name by changing the grep/regex
in tests/test_ci_self_hosted_guard.sh (which currently looks for /^ 
tests-depot:/) to match the new job name; ensure the associated inline comment
about WarpBuild/billing remains accurate and run CI tests to validate the
coordinated change.

In @.github/workflows/test-depot.yml:
- Line 1: The workflow name value "Run tests on Depot" should be updated to
reflect the WarpBuild runner migration (e.g., change the name string to "Run
tests on WarpBuild" or similar) and, optionally, rename the workflow file from
test-depot.yml to test-warpbuild.yml if you also want the filename to match;
update any external references (scripts, docs, gh workflow run commands) that
reference the old name/file to avoid broken links.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 360d6af6-e9c6-47f5-a12f-deaa9cff29b1

📥 Commits

Reviewing files that changed from the base of the PR and between 2e4c482 and f5ed591.

📒 Files selected for processing (8)
  • .github/workflows/build-ghosttykit.yml
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • .github/workflows/test-depot.yml
  • .github/workflows/test-e2e.yml
  • tests/test_ci_self_hosted_guard.sh

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5ed5915ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml

tests:
runs-on: macos-15
runs-on: warp-macos-15-arm64-6x

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Gate WarpBuild tests job for fork pull requests

The workflow still triggers on pull_request, but this job now runs on a WarpBuild runner without the fork guard used in other paid jobs, so PRs from forks will execute untrusted code on billed infrastructure (ci.yml currently only protects tests-depot). This migration changed the runner from GitHub-hosted to WarpBuild, so the missing if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository condition can unexpectedly increase costs and expand self-hosted runner exposure whenever external contributors open PRs.

Useful? React with 👍 / 👎.

WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2.
The install step skipped because zig was found, just outdated.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aa419f8952

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/build-ghosttykit.yml Outdated
Comment on lines 67 to 69
else
brew upgrade zig 2>/dev/null || true
else

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove stray else from Zig install script

The Build GhosttyKit.xcframework step now contains two else branches in the nested Zig/Brew check, which makes the run script invalid shell syntax (bash -n fails with syntax error near unexpected token 'else'). In runs where check-release is false, this step will fail before zig build executes, blocking GhosttyKit artifact publication.

Useful? React with 👍 / 👎.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 7 files (changes from recent commits).

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name=".github/workflows/build-ghosttykit.yml">

<violation number="1" location=".github/workflows/build-ghosttykit.yml:67">
P1: This adds a second `else` in the same shell `if` block, which makes the script syntactically invalid and causes the CI step to fail before build execution.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread .github/workflows/build-ghosttykit.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
.github/workflows/build-ghosttykit.yml (1)

64-73: ⚠️ Potential issue | 🔴 Critical

Fix malformed if/else in Zig setup (shell parse error).

The control flow in this block has a misplaced else, which makes the run script invalid Bash and will fail this step before build execution. The bash syntax check confirms a parse error on line 7: syntax error near unexpected token 'else'.

🐛 Proposed fix
       - name: Build GhosttyKit.xcframework
         if: steps.check-release.outputs.exists == 'false'
         run: |
           set -euo pipefail
           if ! command -v zig >/dev/null 2>&1; then
             if command -v brew >/dev/null 2>&1; then
               brew install zig
-          else
-            brew upgrade zig 2>/dev/null || true
             else
               echo "zig is required to build GhosttyKit.xcframework. Install zig and retry." >&2
               exit 1
             fi
+          else
+            brew upgrade zig 2>/dev/null || true
           fi
           cd ghostty && zig build -Demit-xcframework=true -Demit-macos-app=false -Dxcframework-target=universal -Doptimize=ReleaseFast
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/build-ghosttykit.yml around lines 64 - 73, The Zig setup
if/else is malformed: fix the nested condition so the logic reads "if zig is not
found then if brew exists then try to install (and fall back to upgrade) else
print error and exit"; specifically, rework the block containing the commands
brew install zig and brew upgrade zig so the inner if uses a single then/else/fi
pair (e.g., if command -v brew >/dev/null 2>&1; then run brew install zig ||
brew upgrade zig 2>/dev/null || true; else echo "zig is required..." >&2; exit
1; fi) and close the outer if with a final fi. Ensure the commands 'brew install
zig' and 'brew upgrade zig' remain in the inner branch and remove the misplaced
extra else that caused the parse error.
.github/workflows/ci.yml (1)

82-88: ⚠️ Potential issue | 🟠 Major

Enforce required Zig version (0.15.2) in all workflow install steps.

These blocks silently ignore upgrade failures and never validate the installed version. The project requires Zig 0.15.2, but runners may have outdated pre-installed versions (e.g., WarpBuild ships 0.15.1). When Zig is found but outdated, the install step skips, leading to flaky downstream failures that are difficult to diagnose.

This pattern affects multiple workflows and requires consistent hardening across all six files.

🔧 Suggested hardening for all affected blocks
       - name: Install zig
         run: |
+          REQUIRED_ZIG_VERSION="0.15.2"
           if ! command -v zig >/dev/null 2>&1; then
             brew install zig
           else
-            brew upgrade zig 2>/dev/null || true
+            brew upgrade zig || brew install zig
           fi
+          INSTALLED_ZIG_VERSION="$(zig version)"
+          if [ "$INSTALLED_ZIG_VERSION" != "$REQUIRED_ZIG_VERSION" ]; then
+            echo "Expected zig $REQUIRED_ZIG_VERSION, found $INSTALLED_ZIG_VERSION" >&2
+            exit 1
+          fi

Affected files: .github/workflows/ci.yml (lines 82-88, 220-226), .github/workflows/ci-macos-compat.yml, .github/workflows/test-depot.yml, .github/workflows/release.yml, .github/workflows/nightly.yml, .github/workflows/build-ghosttykit.yml

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci.yml around lines 82 - 88, The "Install zig" workflow
step currently skips installation when a wrong preinstalled Zig version exists
and suppresses upgrade failures; change the step (identified by the step name
"Install zig") to explicitly detect the installed Zig version (zig version) and
compare it to 0.15.2, and if not exact, force install or re-install the required
version (e.g., via brew install/upgrade for zig@0.15.2 or by downloading the
0.15.2 binary) and surface any errors instead of swallowing them; apply the same
change to all six affected workflows so the step fails loudly on install/upgrade
errors and ensures Zig 0.15.2 is present before continuing.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/ci-macos-compat.yml:
- Line 16: Add an actionlint configuration file that registers the custom runner
labels used in workflows—specifically "warp-macos-14-arm64-6x" and
"warp-macos-15-arm64-6x"—so actionlint will recognize these runner labels and
stop flagging them as unknown; create a YAML actionlint config and list those
two labels under the runners/labels (or equivalent labels) section so all
workflows referencing these labels pass actionlint.

---

Outside diff comments:
In @.github/workflows/build-ghosttykit.yml:
- Around line 64-73: The Zig setup if/else is malformed: fix the nested
condition so the logic reads "if zig is not found then if brew exists then try
to install (and fall back to upgrade) else print error and exit"; specifically,
rework the block containing the commands brew install zig and brew upgrade zig
so the inner if uses a single then/else/fi pair (e.g., if command -v brew
>/dev/null 2>&1; then run brew install zig || brew upgrade zig 2>/dev/null ||
true; else echo "zig is required..." >&2; exit 1; fi) and close the outer if
with a final fi. Ensure the commands 'brew install zig' and 'brew upgrade zig'
remain in the inner branch and remove the misplaced extra else that caused the
parse error.

In @.github/workflows/ci.yml:
- Around line 82-88: The "Install zig" workflow step currently skips
installation when a wrong preinstalled Zig version exists and suppresses upgrade
failures; change the step (identified by the step name "Install zig") to
explicitly detect the installed Zig version (zig version) and compare it to
0.15.2, and if not exact, force install or re-install the required version
(e.g., via brew install/upgrade for zig@0.15.2 or by downloading the 0.15.2
binary) and surface any errors instead of swallowing them; apply the same change
to all six affected workflows so the step fails loudly on install/upgrade errors
and ensures Zig 0.15.2 is present before continuing.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6a362c6d-a569-451b-aa9a-67b1151e9019

📥 Commits

Reviewing files that changed from the base of the PR and between f5ed591 and aa419f8.

📒 Files selected for processing (7)
  • .github/workflows/build-ghosttykit.yml
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • .github/workflows/test-depot.yml
  • .github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/test-e2e.yml

fail-fast: false
matrix:
os: [macos-14, macos-15]
os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

❓ Verification inconclusive

Script executed:

#!/bin/bash
set -euo pipefail

echo "== actionlint config candidates =="
cfgs="$(fd -HI 'actionlint\.ya?ml$' . .github || true)"
if [ -z "${cfgs:-}" ]; then
  echo "No actionlint config file found."
else
  echo "$cfgs"
  for f in $cfgs; do
    echo "----- $f -----"
    sed -n '1,220p' "$f"
  done
fi

echo
echo "== WarpBuild labels used in workflows =="
rg -n 'runs-on:\s*warp-macos-(14|15)-arm64-6x' .github/workflows

echo
echo "== WarpBuild labels declared in actionlint config =="
if [ -n "${cfgs:-}" ]; then
  rg -n 'warp-macos-(14|15)-arm64-6x' $cfgs || true
fi

Repository: manaflow-ai/cmux


Repository: manaflow-ai/cmux
Exit code: 0

stdout:

== actionlint config candidates ==
No actionlint config file found.

== WarpBuild labels used in workflows ==
.github/workflows/release.yml:17:    runs-on: warp-macos-15-arm64-6x
.github/workflows/test-depot.yml:31:    runs-on: warp-macos-15-arm64-6x
.github/workflows/nightly.yml:102:    runs-on: warp-macos-15-arm64-6x
.github/workflows/ci.yml:53:    runs-on: warp-macos-15-arm64-6x
.github/workflows/ci.yml:191:    runs-on: warp-macos-15-arm64-6x
.github/workflows/build-ghosttykit.yml:13:    runs-on: warp-macos-15-arm64-6x

== WarpBuild labels declared in actionlint config ==

Script executed:

#!/bin/bash
set -euo pipefail

echo "== Line 16 of ci-macos-compat.yml =="
sed -n '16p' .github/workflows/ci-macos-compat.yml

echo
echo "== Lines 14-20 context =="
sed -n '14,20p' .github/workflows/ci-macos-compat.yml

echo
echo "== Search for all runner labels in ci-macos-compat.yml =="
rg -n 'runs-on:' .github/workflows/ci-macos-compat.yml

Repository: manaflow-ai/cmux


Repository: manaflow-ai/cmux
Exit code: 0

stdout:

== Line 16 of ci-macos-compat.yml ==
        os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x]

== Lines 14-20 context ==
      fail-fast: false
      matrix:
        os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x]
    runs-on: ${{ matrix.os }}
    steps:
      - name: Checkout
        uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

== Search for all runner labels in ci-macos-compat.yml ==
17:    runs-on: ${{ matrix.os }}

Create actionlint configuration to allow WarpBuild runner labels.

The repository lacks an actionlint configuration file. Custom runner labels warp-macos-14-arm64-6x and warp-macos-15-arm64-6x used in this workflow (and others) will be flagged as unknown by actionlint without proper configuration. Create .github/actionlint.yaml to register these custom runner labels so CI linting passes.

🧰 Tools
🪛 actionlint (1.7.11)

[error] 16-16: label "warp-macos-14-arm64-6x" is unknown. available labels are "windows-latest", "windows-latest-8-cores", "windows-2025", "windows-2025-vs2026", "windows-2022", "windows-11-arm", "ubuntu-slim", "ubuntu-latest", "ubuntu-latest-4-cores", "ubuntu-latest-8-cores", "ubuntu-latest-16-cores", "ubuntu-24.04", "ubuntu-24.04-arm", "ubuntu-22.04", "ubuntu-22.04-arm", "macos-latest", "macos-latest-xlarge", "macos-latest-large", "macos-26-xlarge", "macos-26-large", "macos-26", "macos-15-intel", "macos-15-xlarge", "macos-15-large", "macos-15", "macos-14-xlarge", "macos-14-large", "macos-14", "self-hosted", "x64", "arm", "arm64", "linux", "macos", "windows". if it is a custom label for self-hosted runner, set list of labels in actionlint.yaml config file

(runner-label)


[error] 16-16: label "warp-macos-15-arm64-6x" is unknown. available labels are "windows-latest", "windows-latest-8-cores", "windows-2025", "windows-2025-vs2026", "windows-2022", "windows-11-arm", "ubuntu-slim", "ubuntu-latest", "ubuntu-latest-4-cores", "ubuntu-latest-8-cores", "ubuntu-latest-16-cores", "ubuntu-24.04", "ubuntu-24.04-arm", "ubuntu-22.04", "ubuntu-22.04-arm", "macos-latest", "macos-latest-xlarge", "macos-latest-large", "macos-26-xlarge", "macos-26-large", "macos-26", "macos-15-intel", "macos-15-xlarge", "macos-15-large", "macos-15", "macos-14-xlarge", "macos-14-large", "macos-14", "self-hosted", "x64", "arm", "arm64", "linux", "macos", "windows". if it is a custom label for self-hosted runner, set list of labels in actionlint.yaml config file

(runner-label)

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci-macos-compat.yml at line 16, Add an actionlint
configuration file that registers the custom runner labels used in
workflows—specifically "warp-macos-14-arm64-6x" and "warp-macos-15-arm64-6x"—so
actionlint will recognize these runner labels and stop flagging them as unknown;
create a YAML actionlint config and list those two labels under the
runners/labels (or equivalent labels) section so all workflows referencing these
labels pass actionlint.

Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the
ghostty submodule requires 0.15.2. Download zig directly from
ziglang.org to guarantee the correct version on all runner images.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

8 issues found across 7 files (changes from recent commits).

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name=".github/workflows/test-depot.yml">

<violation number="1" location=".github/workflows/test-depot.yml:92">
P1: Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.</violation>
</file>

<file name=".github/workflows/release.yml">

<violation number="1" location=".github/workflows/release.yml:107">
P1: Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.</violation>
</file>

<file name=".github/workflows/build-ghosttykit.yml">

<violation number="1" location=".github/workflows/build-ghosttykit.yml:72">
P2: Copying `lib` into an existing `/usr/local/lib/zig` can create a nested `.../zig/lib` path and leave stale Zig stdlib files.</violation>
</file>

<file name=".github/workflows/ci-macos-compat.yml">

<violation number="1" location=".github/workflows/ci-macos-compat.yml:80">
P1: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.</violation>

<violation number="2" location=".github/workflows/ci-macos-compat.yml:83">
P2: Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.</violation>
</file>

<file name=".github/workflows/test-e2e.yml">

<violation number="1" location=".github/workflows/test-e2e.yml:103">
P1: Copying the Zig `lib` directory this way can create a nested `/usr/local/lib/zig/lib` and leave stale libs behind, which can break Zig after upgrades.</violation>
</file>

<file name=".github/workflows/nightly.yml">

<violation number="1" location=".github/workflows/nightly.yml:159">
P1: Verify the downloaded Zig archive (checksum or signature) before extraction/installation.</violation>
</file>

<file name=".github/workflows/ci.yml">

<violation number="1" location=".github/workflows/ci.yml:92">
P2: Copying the Zig `lib` directory with `cp -rf` can nest it under `/usr/local/lib/zig/lib` on existing installs; replace the destination contents explicitly.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread .github/workflows/test-depot.yml Outdated
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/test-depot.yml, line 92:

<comment>Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.</comment>

<file context>
@@ -84,10 +84,17 @@ jobs:
           else
-            brew upgrade zig 2>/dev/null || true
+            echo "Installing zig ${ZIG_REQUIRED} from tarball"
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
Fix with Cubic

Comment thread .github/workflows/release.yml Outdated
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/release.yml, line 107:

<comment>Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.</comment>

<file context>
@@ -99,10 +99,17 @@ jobs:
           else
-            brew upgrade zig 2>/dev/null || true
+            echo "Installing zig ${ZIG_REQUIRED} from tarball"
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
Fix with Cubic

Comment thread .github/workflows/ci-macos-compat.yml Outdated
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci-macos-compat.yml, line 80:

<comment>Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.</comment>

<file context>
@@ -72,10 +72,17 @@ jobs:
           else
-            brew upgrade zig 2>/dev/null || true
+            echo "Installing zig ${ZIG_REQUIRED} from tarball"
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
Fix with Cubic

Comment thread .github/workflows/test-e2e.yml Outdated
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Copying the Zig lib directory this way can create a nested /usr/local/lib/zig/lib and leave stale libs behind, which can break Zig after upgrades.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/test-e2e.yml, line 103:

<comment>Copying the Zig `lib` directory this way can create a nested `/usr/local/lib/zig/lib` and leave stale libs behind, which can break Zig after upgrades.</comment>

<file context>
@@ -92,10 +92,17 @@ jobs:
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+            sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+            export PATH="/usr/local/bin:$PATH"
+            zig version
</file context>
Suggested change
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
sudo rm -rf /usr/local/lib/zig
sudo mkdir -p /usr/local/lib/zig
sudo cp -Rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib/. /usr/local/lib/zig
Fix with Cubic

Comment thread .github/workflows/nightly.yml Outdated
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Verify the downloaded Zig archive (checksum or signature) before extraction/installation.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/nightly.yml, line 159:

<comment>Verify the downloaded Zig archive (checksum or signature) before extraction/installation.</comment>

<file context>
@@ -151,10 +151,17 @@ jobs:
           else
-            brew upgrade zig 2>/dev/null || true
+            echo "Installing zig ${ZIG_REQUIRED} from tarball"
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
Fix with Cubic

Comment thread .github/workflows/build-ghosttykit.yml Outdated
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Copying lib into an existing /usr/local/lib/zig can create a nested .../zig/lib path and leave stale Zig stdlib files.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/build-ghosttykit.yml, line 72:

<comment>Copying `lib` into an existing `/usr/local/lib/zig` can create a nested `.../zig/lib` path and leave stale Zig stdlib files.</comment>

<file context>
@@ -61,15 +61,17 @@ jobs:
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+            sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+            export PATH="/usr/local/bin:$PATH"
+            zig version
</file context>
Suggested change
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
sudo rm -rf /usr/local/lib/zig && sudo cp -R /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
Fix with Cubic

Comment thread .github/workflows/ci-macos-compat.yml Outdated
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci-macos-compat.yml, line 83:

<comment>Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.</comment>

<file context>
@@ -72,10 +72,17 @@ jobs:
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+            sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+            export PATH="/usr/local/bin:$PATH"
+            zig version
</file context>
Suggested change
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
sudo rm -rf /usr/local/lib/zig && sudo cp -R /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
Fix with Cubic

Comment thread .github/workflows/ci.yml Outdated
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Copying the Zig lib directory with cp -rf can nest it under /usr/local/lib/zig/lib on existing installs; replace the destination contents explicitly.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci.yml, line 92:

<comment>Copying the Zig `lib` directory with `cp -rf` can nest it under `/usr/local/lib/zig/lib` on existing installs; replace the destination contents explicitly.</comment>

<file context>
@@ -81,10 +81,17 @@ jobs:
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            tar xf /tmp/zig.tar.xz -C /tmp
+            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+            sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+            export PATH="/usr/local/bin:$PATH"
+            zig version
</file context>
Suggested change
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
sudo rm -rf /usr/local/lib/zig
sudo mkdir -p /usr/local/lib/zig
sudo cp -Rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib/. /usr/local/lib/zig/
Fix with Cubic

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 422be6657d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml Outdated
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Replace Zig lib directory instead of nesting it

When this upgrade path runs on a runner that already has /usr/local/lib/zig, cp -rf .../lib /usr/local/lib/zig copies into /usr/local/lib/zig/lib instead of replacing /usr/local/lib/zig, so the old stdlib files remain while /usr/local/bin/zig is overwritten. That creates a mixed Zig installation and can break later zig build invocations in CI; remove the destination first (or copy the contents of lib/) to make upgrades deterministic.

Useful? React with 👍 / 👎.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 7 files (changes from recent commits).

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name=".github/workflows/ci.yml">

<violation number="1" location=".github/workflows/ci.yml:89">
P2: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into `/usr/local`.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread .github/workflows/ci.yml
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz

@cubic-dev-ai cubic-dev-ai Bot Mar 16, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into /usr/local.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci.yml, line 89:

<comment>Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into `/usr/local`.</comment>

<file context>
@@ -86,10 +86,10 @@ jobs:
           else
             echo "Installing zig ${ZIG_REQUIRED} from tarball"
-            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
             tar xf /tmp/zig.tar.xz -C /tmp
-            sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
Fix with Cubic

WarpBuild runners don't have /usr/local/lib by default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

♻️ Duplicate comments (1)
.github/workflows/ci-macos-compat.yml (1)

16-16: ⚠️ Potential issue | 🟠 Major

Register WarpBuild runner labels in actionlint config.

Line 16 uses custom labels that actionlint still reports as unknown; add label registration in .github/actionlint.yaml so workflow linting passes.

#!/usr/bin/env bash
set -euo pipefail

echo "Find actionlint config files:"
fd -HI 'actionlint\.ya?ml$' . .github || true

echo
echo "Find WarpBuild labels in workflows:"
rg -n 'warp-macos-(14|15)-arm64-6x' .github/workflows

echo
echo "If config exists, verify labels are declared:"
cfgs="$(fd -HI 'actionlint\.ya?ml$' . .github || true)"
if [ -n "${cfgs:-}" ]; then
  rg -n 'warp-macos-(14|15)-arm64-6x|self-hosted' $cfgs || true
fi
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci-macos-compat.yml at line 16, Add the custom WarpBuild
runner labels used in the workflow (warp-macos-14-arm64-6x and
warp-macos-15-arm64-6x) to the actionlint configuration so actionlint stops
flagging them as unknown; update .github/actionlint.yaml to include these two
labels under the labels/runners section (where existing labels like self-hosted
are declared) so the workflow file that references os: [warp-macos-14-arm64-6x,
warp-macos-15-arm64-6x] is recognized.
🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)

84-95: Centralize Zig bootstrap logic to reduce maintenance burden.

The Zig installation block (ZIG_REQUIRED="0.15.2" with tarball download and setup) is duplicated across 8 locations: ci.yml (lines 84, 230), test-e2e.yml, test-depot.yml, release.yml, nightly.yml, ci-macos-compat.yml, and build-ghosttykit.yml. Moving this to a reusable composite action or shared script ensures version bumps and security updates are applied consistently in one place.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci.yml around lines 84 - 95, The Zig install logic is
duplicated across multiple workflows (the ZIG_REQUIRED variable, the conditional
checking "zig version", tarball curl/tar/sudo cp steps and PATH export) which
should be centralized; extract this block into a single reusable piece (either a
composite GitHub Action or a shared script invoked by workflows) and update
workflows (ci.yml, test-e2e.yml, test-depot.yml, release.yml, nightly.yml,
ci-macos-compat.yml, build-ghosttykit.yml) to call that single action/script;
ensure the reusable action accepts ZIG_REQUIRED as an input, runs the same
conditional (checking command -v zig and zig version), performs the tarball
download/untar/copy and PATH export, and preserves existing behavior of printing
"zig ${ZIG_REQUIRED} already installed" or "Installing zig ${ZIG_REQUIRED} from
tarball" and returning non-zero on failure so existing callers continue to
behave the same.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/test-depot.yml:
- Around line 87-98: Add SHA256 verification for the Zig tarball before
extracting or copying to privileged locations: introduce an expected checksum
variable (tied to ZIG_REQUIRED) and after downloading /tmp/zig.tar.xz verify its
checksum with shasum -a 256 or sha256sum, comparing to the expected value and
exiting non‑zero on mismatch; only proceed to tar xf /tmp/zig.tar.xz and the
sudo cp commands if the checksum passes. Ensure the verification step occurs
immediately after the curl that writes /tmp/zig.tar.xz and before any use of
tar, sudo cp, or adding to PATH so that functions/variables referenced in the
diff (ZIG_REQUIRED, /tmp/zig.tar.xz, the curl download URL, tar xf, sudo cp -f
/usr/local/bin/zig, sudo cp -rf /usr/local/lib/zig) are protected.

---

Duplicate comments:
In @.github/workflows/ci-macos-compat.yml:
- Line 16: Add the custom WarpBuild runner labels used in the workflow
(warp-macos-14-arm64-6x and warp-macos-15-arm64-6x) to the actionlint
configuration so actionlint stops flagging them as unknown; update
.github/actionlint.yaml to include these two labels under the labels/runners
section (where existing labels like self-hosted are declared) so the workflow
file that references os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x] is
recognized.

---

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 84-95: The Zig install logic is duplicated across multiple
workflows (the ZIG_REQUIRED variable, the conditional checking "zig version",
tarball curl/tar/sudo cp steps and PATH export) which should be centralized;
extract this block into a single reusable piece (either a composite GitHub
Action or a shared script invoked by workflows) and update workflows (ci.yml,
test-e2e.yml, test-depot.yml, release.yml, nightly.yml, ci-macos-compat.yml,
build-ghosttykit.yml) to call that single action/script; ensure the reusable
action accepts ZIG_REQUIRED as an input, runs the same conditional (checking
command -v zig and zig version), performs the tarball download/untar/copy and
PATH export, and preserves existing behavior of printing "zig ${ZIG_REQUIRED}
already installed" or "Installing zig ${ZIG_REQUIRED} from tarball" and
returning non-zero on failure so existing callers continue to behave the same.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 08e6013c-1092-46db-b219-20b820965def

📥 Commits

Reviewing files that changed from the base of the PR and between 422be66 and d9b96c0.

📒 Files selected for processing (7)
  • .github/workflows/build-ghosttykit.yml
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • .github/workflows/test-depot.yml
  • .github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/test-e2e.yml

Comment on lines +87 to 98
ZIG_REQUIRED="0.15.2"
if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then
echo "zig ${ZIG_REQUIRED} already installed"
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
sudo cp -f /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/lib /usr/local/lib/zig
export PATH="/usr/local/bin:$PATH"
zig version
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

echo "Check Zig download/install blocks missing checksum verification:"
rg -n 'ziglang\.org/download/.+zig-aarch64-macos' .github/workflows

echo
echo "Nearby lines to confirm whether shasum/checksum validation exists:"
rg -n -C3 'ziglang\.org/download|shasum|sha256|checksum' .github/workflows

Repository: manaflow-ai/cmux

Length of output: 10018


Add SHA256 verification for Zig tarball before privileged install.

The workflow downloads Zig from ziglang.org (line 92) and immediately extracts and copies it to /usr/local/bin and /usr/local/lib (lines 93–95) without checksum validation. This pattern appears in 8 workflows across the repository (test-depot.yml, test-e2e.yml, nightly.yml, ci.yml, ci-macos-compat.yml, release.yml, build-ghosttykit.yml) and exposes CI to supply-chain compromise. The codebase already validates checksums for other artifacts (GhosttyKit, Homebrew DMG), so apply the same pattern here.

🔐 Suggested fix
           else
             echo "Installing zig ${ZIG_REQUIRED} from tarball"
             curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+            # Verify integrity against the official Zig release checksum.
+            ZIG_SHA256="<official-sha256-for-zig-aarch64-macos-0.15.2.tar.xz>"
+            echo "${ZIG_SHA256}  /tmp/zig.tar.xz" | shasum -a 256 -c -
             tar xf /tmp/zig.tar.xz -C /tmp
             sudo mkdir -p /usr/local/bin /usr/local/lib
             sudo cp -f /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/zig /usr/local/bin/zig
             sudo cp -rf /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/lib /usr/local/lib/zig
             export PATH="/usr/local/bin:$PATH"
             zig version
           fi
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/test-depot.yml around lines 87 - 98, Add SHA256
verification for the Zig tarball before extracting or copying to privileged
locations: introduce an expected checksum variable (tied to ZIG_REQUIRED) and
after downloading /tmp/zig.tar.xz verify its checksum with shasum -a 256 or
sha256sum, comparing to the expected value and exiting non‑zero on mismatch;
only proceed to tar xf /tmp/zig.tar.xz and the sudo cp commands if the checksum
passes. Ensure the verification step occurs immediately after the curl that
writes /tmp/zig.tar.xz and before any use of tar, sudo cp, or adding to PATH so
that functions/variables referenced in the diff (ZIG_REQUIRED, /tmp/zig.tar.xz,
the curl download URL, tar xf, sudo cp -f /usr/local/bin/zig, sudo cp -rf
/usr/local/lib/zig) are protected.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 271e669bcb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
if ! command -v zig >/dev/null 2>&1; then
brew install zig
ZIG_REQUIRED="0.15.2"
if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Match Zig version exactly before skipping install

The version gate uses grep -q "^${ZIG_REQUIRED}", which treats prefixes as matches (for example, 0.15.20 or 0.15.2-dev both satisfy 0.15.2). That means these workflows can silently skip the pinned-install path and run with an unintended Zig version, undermining reproducibility and potentially causing build/runtime drift on updated runner images; compare against the full version string instead of a prefix.

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)

84-96: Consolidate duplicated Zig install logic into one reusable script/action.

The two install blocks are effectively identical; keeping both invites drift when patching CI logic.

♻️ Refactor direction
-      - name: Install zig
-        run: |
-          ZIG_REQUIRED="0.15.2"
-          ...
+      - name: Install zig
+        run: ./scripts/ci/install-zig.sh 0.15.2

And call the same script in both jobs (tests and tests-depot).

Also applies to: 230-242

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/ci.yml around lines 84 - 96, There are two identical Zig
install blocks (using ZIG_REQUIRED, the curl/tar extraction, sudo cp into
/usr/local, and PATH export) duplicated across CI jobs; extract that sequence
into a single reusable script or GitHub Action (e.g., scripts/install-zig.sh or
.github/actions/install-zig) that accepts ZIG_REQUIRED and performs the curl,
tar, install to /usr/local/bin and /usr/local/lib/zig, and PATH
export/verification, then replace both in-workflow blocks with a single call to
that script/action from the `tests` and `tests-depot` jobs so updates are made
in one place.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release.yml:
- Around line 103-104: Replace the prefix grep check that accepts partial
matches by performing an exact version comparison: locate the shell snippet that
runs `zig version` and currently pipes to `grep -q "^${ZIG_REQUIRED}"` (e.g.,
the if-condition using `command -v zig` and `zig version | grep -q
"^${ZIG_REQUIRED}"`) and change it to ensure exact equality (for example by
using `grep -xq "${ZIG_REQUIRED}"` or comparing the output string directly),
then apply that same exact-match change to every workflow occurrence of the `zig
version` + `grep -q "^${ZIG_REQUIRED}"` pattern so `ZIG_REQUIRED=0.15.2` will no
longer match `0.15.20` or `0.15.2-dev`.

---

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 84-96: There are two identical Zig install blocks (using
ZIG_REQUIRED, the curl/tar extraction, sudo cp into /usr/local, and PATH export)
duplicated across CI jobs; extract that sequence into a single reusable script
or GitHub Action (e.g., scripts/install-zig.sh or .github/actions/install-zig)
that accepts ZIG_REQUIRED and performs the curl, tar, install to /usr/local/bin
and /usr/local/lib/zig, and PATH export/verification, then replace both
in-workflow blocks with a single call to that script/action from the `tests` and
`tests-depot` jobs so updates are made in one place.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0161d453-02e7-4b63-aef8-bbd7f6777d32

📥 Commits

Reviewing files that changed from the base of the PR and between d9b96c0 and 271e669.

📒 Files selected for processing (7)
  • .github/workflows/build-ghosttykit.yml
  • .github/workflows/ci-macos-compat.yml
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • .github/workflows/test-depot.yml
  • .github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/test-e2e.yml

Comment on lines +103 to +104
if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then
echo "zig ${ZIG_REQUIRED} already installed"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Locations using prefix Zig version matching:"
rg -n 'zig version 2>/dev/null \| grep -q "\^\$\{ZIG_REQUIRED\}"' .github/workflows

echo
echo "Regex behavior demo (current pattern):"
for v in 0.15.2 0.15.20 0.15.2-dev 0.15.3; do
  if printf '%s\n' "$v" | grep -q '^0.15.2'; then
    echo "MATCH: $v"
  else
    echo "NO_MATCH: $v"
  fi
done

Repository: manaflow-ai/cmux

Length of output: 1334


Fix Zig version matching from prefix to exact comparison in all affected workflows.

The current pattern (grep -q "^${ZIG_REQUIRED}") uses prefix matching and silently accepts unintended versions. For example, with ZIG_REQUIRED=0.15.2, it matches 0.15.20 and 0.15.2-dev, breaking version pinning.

This occurs in 8 locations across multiple workflows:

  • .github/workflows/release.yml (line 103)
  • .github/workflows/ci.yml (lines 85, 231)
  • .github/workflows/test-e2e.yml (line 96)
  • .github/workflows/test-depot.yml (line 88)
  • .github/workflows/nightly.yml (line 155)
  • .github/workflows/ci-macos-compat.yml (line 76)
  • .github/workflows/build-ghosttykit.yml (line 65)
Proposed fix
-          if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then
+          if command -v zig >/dev/null 2>&1 && [ "$(zig version 2>/dev/null)" = "${ZIG_REQUIRED}" ]; then
             echo "zig ${ZIG_REQUIRED} already installed"

Apply this exact-match update to all affected workflow files.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then
echo "zig ${ZIG_REQUIRED} already installed"
if command -v zig >/dev/null 2>&1 && [ "$(zig version 2>/dev/null)" = "${ZIG_REQUIRED}" ]; then
echo "zig ${ZIG_REQUIRED} already installed"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/release.yml around lines 103 - 104, Replace the prefix
grep check that accepts partial matches by performing an exact version
comparison: locate the shell snippet that runs `zig version` and currently pipes
to `grep -q "^${ZIG_REQUIRED}"` (e.g., the if-condition using `command -v zig`
and `zig version | grep -q "^${ZIG_REQUIRED}"`) and change it to ensure exact
equality (for example by using `grep -xq "${ZIG_REQUIRED}"` or comparing the
output string directly), then apply that same exact-match change to every
workflow occurrence of the `zig version` + `grep -q "^${ZIG_REQUIRED}"` pattern
so `ZIG_REQUIRED=0.15.2` will no longer match `0.15.20` or `0.15.2-dev`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0b1b591f2a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

build-sign-notarize:
runs-on: depot-macos-latest
runs-on: warp-macos-15-arm64-6x
timeout-minutes: 20

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Increase release workflow timeout beyond 20 minutes

Adding timeout-minutes: 20 here makes tag releases fragile because this same job does a full Release build and then waits on two notarization submissions (xcrun notarytool submit ... --wait for the app and DMG), so normal notarization queue delays can push runtime past 20 minutes and cause GitHub to cancel the release before artifacts are published.

Useful? React with 👍 / 👎.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Superseded by #1501 (consolidated version, already merged).

@lawrencecchen
lawrencecchen deleted the task-migrate-warpcloud branch March 17, 2026 08:52

This branch was successfully deployed

1 active deployment
Preview — 0b1b591f Deployed Mar 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant