Repository navigation
Migrate CI/CD to WarpBuild runners - #1500
lawrencecchen wants to merge 6 commits into
Conversation
Replace all macOS runner labels across workflows: - depot-macos-latest → warp-macos-15-arm64-6x - macos-15 → warp-macos-15-arm64-6x - macos-14 → warp-macos-14-arm64-6x Keeps job structure unchanged (tests + tests-depot as separate jobs). Ubuntu jobs remain on ubuntu-latest. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
|
Compare with consolidated version: #1501 |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughReplaces Depot/standard macOS runner labels with WarpBuild runner labels across CI workflows; introduces a Zig version guard (ZIG_REQUIRED="0.15.2") that downloads/installs the Zig 0.15.2 tarball when missing/mismatched; updates CI guard script and messages to reference WarpBuild. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested labels
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches
🧪 Generate unit tests (beta)
📝 Coding Plan
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (2)
.github/workflows/test-depot.yml (1)
1-1: Consider renaming workflow to reflect WarpBuild migration.The workflow name still says "Run tests on Depot" but now uses WarpBuild runners (
warp-macos-15-arm64-6x). This could cause confusion when viewing workflow runs in the GitHub Actions UI.💡 Suggested rename
-name: Run tests on Depot +name: Run tests on WarpBuildNote: Renaming the file from
test-depot.ymltotest-warpbuild.ymlwould be a more thorough cleanup but may require updating any references (e.g.,gh workflow runcommands in documentation).🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/test-depot.yml at line 1, The workflow name value "Run tests on Depot" should be updated to reflect the WarpBuild runner migration (e.g., change the name string to "Run tests on WarpBuild" or similar) and, optionally, rename the workflow file from test-depot.yml to test-warpbuild.yml if you also want the filename to match; update any external references (scripts, docs, gh workflow run commands) that reference the old name/file to avoid broken links..github/workflows/ci.yml (1)
186-189: Consider renamingtests-depotjob for consistency.The job name
tests-depotnow runs on WarpBuild (warp-macos-15-arm64-6x), which is misleading. The comment correctly references WarpBuild billing.Note: Renaming the job would require updating
tests/test_ci_self_hosted_guard.shwhich greps for/^ tests-depot:/. If you decide to rename, both would need to change together.💡 Suggested rename (requires coordinated change)
In
.github/workflows/ci.yml:- tests-depot: + tests-warpbuild: # Never run WarpBuild jobs for fork pull requests (avoid billing on external PRs).In
tests/test_ci_self_hosted_guard.sh:- /^ tests-depot:/ { in_tests=1; next } + /^ tests-warpbuild:/ { in_tests=1; next }This is optional and can be deferred since functionality is correct.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/ci.yml around lines 186 - 189, Rename the CI job "tests-depot" to a name that reflects it runs on WarpBuild (e.g., "warpbuild-tests") by updating the job key in .github/workflows/ci.yml (replace the job identifier tests-depot with the new name) and update the test that asserts the job name by changing the grep/regex in tests/test_ci_self_hosted_guard.sh (which currently looks for /^ tests-depot:/) to match the new job name; ensure the associated inline comment about WarpBuild/billing remains accurate and run CI tests to validate the coordinated change.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 186-189: Rename the CI job "tests-depot" to a name that reflects
it runs on WarpBuild (e.g., "warpbuild-tests") by updating the job key in
.github/workflows/ci.yml (replace the job identifier tests-depot with the new
name) and update the test that asserts the job name by changing the grep/regex
in tests/test_ci_self_hosted_guard.sh (which currently looks for /^
tests-depot:/) to match the new job name; ensure the associated inline comment
about WarpBuild/billing remains accurate and run CI tests to validate the
coordinated change.
In @.github/workflows/test-depot.yml:
- Line 1: The workflow name value "Run tests on Depot" should be updated to
reflect the WarpBuild runner migration (e.g., change the name string to "Run
tests on WarpBuild" or similar) and, optionally, rename the workflow file from
test-depot.yml to test-warpbuild.yml if you also want the filename to match;
update any external references (scripts, docs, gh workflow run commands) that
reference the old name/file to avoid broken links.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 360d6af6-e9c6-47f5-a12f-deaa9cff29b1
📒 Files selected for processing (8)
.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.ymltests/test_ci_self_hosted_guard.sh
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5ed5915ef
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| tests: | ||
| runs-on: macos-15 | ||
| runs-on: warp-macos-15-arm64-6x |
There was a problem hiding this comment.
Gate WarpBuild tests job for fork pull requests
The workflow still triggers on pull_request, but this job now runs on a WarpBuild runner without the fork guard used in other paid jobs, so PRs from forks will execute untrusted code on billed infrastructure (ci.yml currently only protects tests-depot). This migration changed the runner from GitHub-hosted to WarpBuild, so the missing if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository condition can unexpectedly increase costs and expand self-hosted runner exposure whenever external contributors open PRs.
Useful? React with 👍 / 👎.
WarpBuild macos-14 ships zig 0.15.1 but the project requires 0.15.2. The install step skipped because zig was found, just outdated. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aa419f8952
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| else | ||
| brew upgrade zig 2>/dev/null || true | ||
| else |
There was a problem hiding this comment.
Remove stray else from Zig install script
The Build GhosttyKit.xcframework step now contains two else branches in the nested Zig/Brew check, which makes the run script invalid shell syntax (bash -n fails with syntax error near unexpected token 'else'). In runs where check-release is false, this step will fail before zig build executes, blocking GhosttyKit artifact publication.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
1 issue found across 7 files (changes from recent commits).
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name=".github/workflows/build-ghosttykit.yml">
<violation number="1" location=".github/workflows/build-ghosttykit.yml:67">
P1: This adds a second `else` in the same shell `if` block, which makes the script syntactically invalid and causes the CI step to fail before build execution.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (2)
.github/workflows/build-ghosttykit.yml (1)
64-73:⚠️ Potential issue | 🔴 CriticalFix malformed
if/elsein Zig setup (shell parse error).The control flow in this block has a misplaced
else, which makes therunscript invalid Bash and will fail this step before build execution. The bash syntax check confirms a parse error on line 7:syntax error near unexpected token 'else'.🐛 Proposed fix
- name: Build GhosttyKit.xcframework if: steps.check-release.outputs.exists == 'false' run: | set -euo pipefail if ! command -v zig >/dev/null 2>&1; then if command -v brew >/dev/null 2>&1; then brew install zig - else - brew upgrade zig 2>/dev/null || true else echo "zig is required to build GhosttyKit.xcframework. Install zig and retry." >&2 exit 1 fi + else + brew upgrade zig 2>/dev/null || true fi cd ghostty && zig build -Demit-xcframework=true -Demit-macos-app=false -Dxcframework-target=universal -Doptimize=ReleaseFast🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/build-ghosttykit.yml around lines 64 - 73, The Zig setup if/else is malformed: fix the nested condition so the logic reads "if zig is not found then if brew exists then try to install (and fall back to upgrade) else print error and exit"; specifically, rework the block containing the commands brew install zig and brew upgrade zig so the inner if uses a single then/else/fi pair (e.g., if command -v brew >/dev/null 2>&1; then run brew install zig || brew upgrade zig 2>/dev/null || true; else echo "zig is required..." >&2; exit 1; fi) and close the outer if with a final fi. Ensure the commands 'brew install zig' and 'brew upgrade zig' remain in the inner branch and remove the misplaced extra else that caused the parse error..github/workflows/ci.yml (1)
82-88:⚠️ Potential issue | 🟠 MajorEnforce required Zig version (0.15.2) in all workflow install steps.
These blocks silently ignore upgrade failures and never validate the installed version. The project requires Zig 0.15.2, but runners may have outdated pre-installed versions (e.g., WarpBuild ships 0.15.1). When Zig is found but outdated, the install step skips, leading to flaky downstream failures that are difficult to diagnose.
This pattern affects multiple workflows and requires consistent hardening across all six files.
🔧 Suggested hardening for all affected blocks
- name: Install zig run: | + REQUIRED_ZIG_VERSION="0.15.2" if ! command -v zig >/dev/null 2>&1; then brew install zig else - brew upgrade zig 2>/dev/null || true + brew upgrade zig || brew install zig fi + INSTALLED_ZIG_VERSION="$(zig version)" + if [ "$INSTALLED_ZIG_VERSION" != "$REQUIRED_ZIG_VERSION" ]; then + echo "Expected zig $REQUIRED_ZIG_VERSION, found $INSTALLED_ZIG_VERSION" >&2 + exit 1 + fiAffected files:
.github/workflows/ci.yml(lines 82-88, 220-226),.github/workflows/ci-macos-compat.yml,.github/workflows/test-depot.yml,.github/workflows/release.yml,.github/workflows/nightly.yml,.github/workflows/build-ghosttykit.yml🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/ci.yml around lines 82 - 88, The "Install zig" workflow step currently skips installation when a wrong preinstalled Zig version exists and suppresses upgrade failures; change the step (identified by the step name "Install zig") to explicitly detect the installed Zig version (zig version) and compare it to 0.15.2, and if not exact, force install or re-install the required version (e.g., via brew install/upgrade for zig@0.15.2 or by downloading the 0.15.2 binary) and surface any errors instead of swallowing them; apply the same change to all six affected workflows so the step fails loudly on install/upgrade errors and ensures Zig 0.15.2 is present before continuing.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/ci-macos-compat.yml:
- Line 16: Add an actionlint configuration file that registers the custom runner
labels used in workflows—specifically "warp-macos-14-arm64-6x" and
"warp-macos-15-arm64-6x"—so actionlint will recognize these runner labels and
stop flagging them as unknown; create a YAML actionlint config and list those
two labels under the runners/labels (or equivalent labels) section so all
workflows referencing these labels pass actionlint.
---
Outside diff comments:
In @.github/workflows/build-ghosttykit.yml:
- Around line 64-73: The Zig setup if/else is malformed: fix the nested
condition so the logic reads "if zig is not found then if brew exists then try
to install (and fall back to upgrade) else print error and exit"; specifically,
rework the block containing the commands brew install zig and brew upgrade zig
so the inner if uses a single then/else/fi pair (e.g., if command -v brew
>/dev/null 2>&1; then run brew install zig || brew upgrade zig 2>/dev/null ||
true; else echo "zig is required..." >&2; exit 1; fi) and close the outer if
with a final fi. Ensure the commands 'brew install zig' and 'brew upgrade zig'
remain in the inner branch and remove the misplaced extra else that caused the
parse error.
In @.github/workflows/ci.yml:
- Around line 82-88: The "Install zig" workflow step currently skips
installation when a wrong preinstalled Zig version exists and suppresses upgrade
failures; change the step (identified by the step name "Install zig") to
explicitly detect the installed Zig version (zig version) and compare it to
0.15.2, and if not exact, force install or re-install the required version
(e.g., via brew install/upgrade for zig@0.15.2 or by downloading the 0.15.2
binary) and surface any errors instead of swallowing them; apply the same change
to all six affected workflows so the step fails loudly on install/upgrade errors
and ensures Zig 0.15.2 is present before continuing.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 6a362c6d-a569-451b-aa9a-67b1151e9019
📒 Files selected for processing (7)
.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/test-e2e.yml
| fail-fast: false | ||
| matrix: | ||
| os: [macos-14, macos-15] | ||
| os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x] |
There was a problem hiding this comment.
❓ Verification inconclusive
Script executed:
#!/bin/bash
set -euo pipefail
echo "== actionlint config candidates =="
cfgs="$(fd -HI 'actionlint\.ya?ml$' . .github || true)"
if [ -z "${cfgs:-}" ]; then
echo "No actionlint config file found."
else
echo "$cfgs"
for f in $cfgs; do
echo "----- $f -----"
sed -n '1,220p' "$f"
done
fi
echo
echo "== WarpBuild labels used in workflows =="
rg -n 'runs-on:\s*warp-macos-(14|15)-arm64-6x' .github/workflows
echo
echo "== WarpBuild labels declared in actionlint config =="
if [ -n "${cfgs:-}" ]; then
rg -n 'warp-macos-(14|15)-arm64-6x' $cfgs || true
fiRepository: manaflow-ai/cmux
Repository: manaflow-ai/cmux
Exit code: 0
stdout:
== actionlint config candidates ==
No actionlint config file found.
== WarpBuild labels used in workflows ==
.github/workflows/release.yml:17: runs-on: warp-macos-15-arm64-6x
.github/workflows/test-depot.yml:31: runs-on: warp-macos-15-arm64-6x
.github/workflows/nightly.yml:102: runs-on: warp-macos-15-arm64-6x
.github/workflows/ci.yml:53: runs-on: warp-macos-15-arm64-6x
.github/workflows/ci.yml:191: runs-on: warp-macos-15-arm64-6x
.github/workflows/build-ghosttykit.yml:13: runs-on: warp-macos-15-arm64-6x
== WarpBuild labels declared in actionlint config ==
Script executed:
#!/bin/bash
set -euo pipefail
echo "== Line 16 of ci-macos-compat.yml =="
sed -n '16p' .github/workflows/ci-macos-compat.yml
echo
echo "== Lines 14-20 context =="
sed -n '14,20p' .github/workflows/ci-macos-compat.yml
echo
echo "== Search for all runner labels in ci-macos-compat.yml =="
rg -n 'runs-on:' .github/workflows/ci-macos-compat.ymlRepository: manaflow-ai/cmux
Repository: manaflow-ai/cmux
Exit code: 0
stdout:
== Line 16 of ci-macos-compat.yml ==
os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x]
== Lines 14-20 context ==
fail-fast: false
matrix:
os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
== Search for all runner labels in ci-macos-compat.yml ==
17: runs-on: ${{ matrix.os }}
Create actionlint configuration to allow WarpBuild runner labels.
The repository lacks an actionlint configuration file. Custom runner labels warp-macos-14-arm64-6x and warp-macos-15-arm64-6x used in this workflow (and others) will be flagged as unknown by actionlint without proper configuration. Create .github/actionlint.yaml to register these custom runner labels so CI linting passes.
🧰 Tools
🪛 actionlint (1.7.11)
[error] 16-16: label "warp-macos-14-arm64-6x" is unknown. available labels are "windows-latest", "windows-latest-8-cores", "windows-2025", "windows-2025-vs2026", "windows-2022", "windows-11-arm", "ubuntu-slim", "ubuntu-latest", "ubuntu-latest-4-cores", "ubuntu-latest-8-cores", "ubuntu-latest-16-cores", "ubuntu-24.04", "ubuntu-24.04-arm", "ubuntu-22.04", "ubuntu-22.04-arm", "macos-latest", "macos-latest-xlarge", "macos-latest-large", "macos-26-xlarge", "macos-26-large", "macos-26", "macos-15-intel", "macos-15-xlarge", "macos-15-large", "macos-15", "macos-14-xlarge", "macos-14-large", "macos-14", "self-hosted", "x64", "arm", "arm64", "linux", "macos", "windows". if it is a custom label for self-hosted runner, set list of labels in actionlint.yaml config file
(runner-label)
[error] 16-16: label "warp-macos-15-arm64-6x" is unknown. available labels are "windows-latest", "windows-latest-8-cores", "windows-2025", "windows-2025-vs2026", "windows-2022", "windows-11-arm", "ubuntu-slim", "ubuntu-latest", "ubuntu-latest-4-cores", "ubuntu-latest-8-cores", "ubuntu-latest-16-cores", "ubuntu-24.04", "ubuntu-24.04-arm", "ubuntu-22.04", "ubuntu-22.04-arm", "macos-latest", "macos-latest-xlarge", "macos-latest-large", "macos-26-xlarge", "macos-26-large", "macos-26", "macos-15-intel", "macos-15-xlarge", "macos-15-large", "macos-15", "macos-14-xlarge", "macos-14-large", "macos-14", "self-hosted", "x64", "arm", "arm64", "linux", "macos", "windows". if it is a custom label for self-hosted runner, set list of labels in actionlint.yaml config file
(runner-label)
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/ci-macos-compat.yml at line 16, Add an actionlint
configuration file that registers the custom runner labels used in
workflows—specifically "warp-macos-14-arm64-6x" and "warp-macos-15-arm64-6x"—so
actionlint will recognize these runner labels and stop flagging them as unknown;
create a YAML actionlint config and list those two labels under the
runners/labels (or equivalent labels) section so all workflows referencing these
labels pass actionlint.
Homebrew's zig bottle for macOS 14 (Sonoma) is stuck at 0.15.1 but the ghostty submodule requires 0.15.2. Download zig directly from ziglang.org to guarantee the correct version on all runner images. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
8 issues found across 7 files (changes from recent commits).
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name=".github/workflows/test-depot.yml">
<violation number="1" location=".github/workflows/test-depot.yml:92">
P1: Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.</violation>
</file>
<file name=".github/workflows/release.yml">
<violation number="1" location=".github/workflows/release.yml:107">
P1: Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.</violation>
</file>
<file name=".github/workflows/build-ghosttykit.yml">
<violation number="1" location=".github/workflows/build-ghosttykit.yml:72">
P2: Copying `lib` into an existing `/usr/local/lib/zig` can create a nested `.../zig/lib` path and leave stale Zig stdlib files.</violation>
</file>
<file name=".github/workflows/ci-macos-compat.yml">
<violation number="1" location=".github/workflows/ci-macos-compat.yml:80">
P1: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.</violation>
<violation number="2" location=".github/workflows/ci-macos-compat.yml:83">
P2: Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.</violation>
</file>
<file name=".github/workflows/test-e2e.yml">
<violation number="1" location=".github/workflows/test-e2e.yml:103">
P1: Copying the Zig `lib` directory this way can create a nested `/usr/local/lib/zig/lib` and leave stale libs behind, which can break Zig after upgrades.</violation>
</file>
<file name=".github/workflows/nightly.yml">
<violation number="1" location=".github/workflows/nightly.yml:159">
P1: Verify the downloaded Zig archive (checksum or signature) before extraction/installation.</violation>
</file>
<file name=".github/workflows/ci.yml">
<violation number="1" location=".github/workflows/ci.yml:92">
P2: Copying the Zig `lib` directory with `cp -rf` can nest it under `/usr/local/lib/zig/lib` on existing installs; replace the destination contents explicitly.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz |
There was a problem hiding this comment.
P1: Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/test-depot.yml, line 92:
<comment>Verify the Zig tarball integrity (checksum/signature) before extracting and installing it.</comment>
<file context>
@@ -84,10 +84,17 @@ jobs:
else
- brew upgrade zig 2>/dev/null || true
+ echo "Installing zig ${ZIG_REQUIRED} from tarball"
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz |
There was a problem hiding this comment.
P1: Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/release.yml, line 107:
<comment>Verify the Zig tarball integrity before extracting/installing; the current flow trusts a downloaded executable without checksum/signature validation.</comment>
<file context>
@@ -99,10 +99,17 @@ jobs:
else
- brew upgrade zig 2>/dev/null || true
+ echo "Installing zig ${ZIG_REQUIRED} from tarball"
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz |
There was a problem hiding this comment.
P1: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci-macos-compat.yml, line 80:
<comment>Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and installing it.</comment>
<file context>
@@ -72,10 +72,17 @@ jobs:
else
- brew upgrade zig 2>/dev/null || true
+ echo "Installing zig ${ZIG_REQUIRED} from tarball"
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
There was a problem hiding this comment.
P1: Copying the Zig lib directory this way can create a nested /usr/local/lib/zig/lib and leave stale libs behind, which can break Zig after upgrades.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/test-e2e.yml, line 103:
<comment>Copying the Zig `lib` directory this way can create a nested `/usr/local/lib/zig/lib` and leave stale libs behind, which can break Zig after upgrades.</comment>
<file context>
@@ -92,10 +92,17 @@ jobs:
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+ sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+ export PATH="/usr/local/bin:$PATH"
+ zig version
</file context>
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig | |
| sudo rm -rf /usr/local/lib/zig | |
| sudo mkdir -p /usr/local/lib/zig | |
| sudo cp -Rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib/. /usr/local/lib/zig |
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz |
There was a problem hiding this comment.
P1: Verify the downloaded Zig archive (checksum or signature) before extraction/installation.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/nightly.yml, line 159:
<comment>Verify the downloaded Zig archive (checksum or signature) before extraction/installation.</comment>
<file context>
@@ -151,10 +151,17 @@ jobs:
else
- brew upgrade zig 2>/dev/null || true
+ echo "Installing zig ${ZIG_REQUIRED} from tarball"
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
There was a problem hiding this comment.
P2: Copying lib into an existing /usr/local/lib/zig can create a nested .../zig/lib path and leave stale Zig stdlib files.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/build-ghosttykit.yml, line 72:
<comment>Copying `lib` into an existing `/usr/local/lib/zig` can create a nested `.../zig/lib` path and leave stale Zig stdlib files.</comment>
<file context>
@@ -61,15 +61,17 @@ jobs:
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+ sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+ export PATH="/usr/local/bin:$PATH"
+ zig version
</file context>
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig | |
| sudo rm -rf /usr/local/lib/zig && sudo cp -R /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
There was a problem hiding this comment.
P2: Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci-macos-compat.yml, line 83:
<comment>Replace the Zig lib directory instead of recursively copying into an existing destination to avoid nested/stale libraries.</comment>
<file context>
@@ -72,10 +72,17 @@ jobs:
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+ sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+ export PATH="/usr/local/bin:$PATH"
+ zig version
</file context>
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig | |
| sudo rm -rf /usr/local/lib/zig && sudo cp -R /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
There was a problem hiding this comment.
P2: Copying the Zig lib directory with cp -rf can nest it under /usr/local/lib/zig/lib on existing installs; replace the destination contents explicitly.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci.yml, line 92:
<comment>Copying the Zig `lib` directory with `cp -rf` can nest it under `/usr/local/lib/zig/lib` on existing installs; replace the destination contents explicitly.</comment>
<file context>
@@ -81,10 +81,17 @@ jobs:
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ tar xf /tmp/zig.tar.xz -C /tmp
+ sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
+ sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig
+ export PATH="/usr/local/bin:$PATH"
+ zig version
</file context>
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig | |
| sudo rm -rf /usr/local/lib/zig | |
| sudo mkdir -p /usr/local/lib/zig | |
| sudo cp -Rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib/. /usr/local/lib/zig/ |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 422be6657d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/lib /usr/local/lib/zig |
There was a problem hiding this comment.
Replace Zig lib directory instead of nesting it
When this upgrade path runs on a runner that already has /usr/local/lib/zig, cp -rf .../lib /usr/local/lib/zig copies into /usr/local/lib/zig/lib instead of replacing /usr/local/lib/zig, so the old stdlib files remain while /usr/local/bin/zig is overwritten. That creates a mixed Zig installation and can break later zig build invocations in CI; remove the destination first (or copy the contents of lib/) to make upgrades deterministic.
Useful? React with 👍 / 👎.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
1 issue found across 7 files (changes from recent commits).
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name=".github/workflows/ci.yml">
<violation number="1" location=".github/workflows/ci.yml:89">
P2: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into `/usr/local`.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz |
There was a problem hiding this comment.
P2: Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into /usr/local.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci.yml, line 89:
<comment>Add integrity verification (checksum or signature) for the downloaded Zig tarball before extracting and copying it into `/usr/local`.</comment>
<file context>
@@ -86,10 +86,10 @@ jobs:
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
- curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-macos-aarch64-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
tar xf /tmp/zig.tar.xz -C /tmp
- sudo cp -f /tmp/zig-macos-aarch64-${ZIG_REQUIRED}/zig /usr/local/bin/zig
</file context>
WarpBuild runners don't have /usr/local/lib by default. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
.github/workflows/ci-macos-compat.yml (1)
16-16:⚠️ Potential issue | 🟠 MajorRegister WarpBuild runner labels in actionlint config.
Line 16 uses custom labels that actionlint still reports as unknown; add label registration in
.github/actionlint.yamlso workflow linting passes.#!/usr/bin/env bash set -euo pipefail echo "Find actionlint config files:" fd -HI 'actionlint\.ya?ml$' . .github || true echo echo "Find WarpBuild labels in workflows:" rg -n 'warp-macos-(14|15)-arm64-6x' .github/workflows echo echo "If config exists, verify labels are declared:" cfgs="$(fd -HI 'actionlint\.ya?ml$' . .github || true)" if [ -n "${cfgs:-}" ]; then rg -n 'warp-macos-(14|15)-arm64-6x|self-hosted' $cfgs || true fi🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/ci-macos-compat.yml at line 16, Add the custom WarpBuild runner labels used in the workflow (warp-macos-14-arm64-6x and warp-macos-15-arm64-6x) to the actionlint configuration so actionlint stops flagging them as unknown; update .github/actionlint.yaml to include these two labels under the labels/runners section (where existing labels like self-hosted are declared) so the workflow file that references os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x] is recognized.
🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)
84-95: Centralize Zig bootstrap logic to reduce maintenance burden.The Zig installation block (ZIG_REQUIRED="0.15.2" with tarball download and setup) is duplicated across 8 locations: ci.yml (lines 84, 230), test-e2e.yml, test-depot.yml, release.yml, nightly.yml, ci-macos-compat.yml, and build-ghosttykit.yml. Moving this to a reusable composite action or shared script ensures version bumps and security updates are applied consistently in one place.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/ci.yml around lines 84 - 95, The Zig install logic is duplicated across multiple workflows (the ZIG_REQUIRED variable, the conditional checking "zig version", tarball curl/tar/sudo cp steps and PATH export) which should be centralized; extract this block into a single reusable piece (either a composite GitHub Action or a shared script invoked by workflows) and update workflows (ci.yml, test-e2e.yml, test-depot.yml, release.yml, nightly.yml, ci-macos-compat.yml, build-ghosttykit.yml) to call that single action/script; ensure the reusable action accepts ZIG_REQUIRED as an input, runs the same conditional (checking command -v zig and zig version), performs the tarball download/untar/copy and PATH export, and preserves existing behavior of printing "zig ${ZIG_REQUIRED} already installed" or "Installing zig ${ZIG_REQUIRED} from tarball" and returning non-zero on failure so existing callers continue to behave the same.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/test-depot.yml:
- Around line 87-98: Add SHA256 verification for the Zig tarball before
extracting or copying to privileged locations: introduce an expected checksum
variable (tied to ZIG_REQUIRED) and after downloading /tmp/zig.tar.xz verify its
checksum with shasum -a 256 or sha256sum, comparing to the expected value and
exiting non‑zero on mismatch; only proceed to tar xf /tmp/zig.tar.xz and the
sudo cp commands if the checksum passes. Ensure the verification step occurs
immediately after the curl that writes /tmp/zig.tar.xz and before any use of
tar, sudo cp, or adding to PATH so that functions/variables referenced in the
diff (ZIG_REQUIRED, /tmp/zig.tar.xz, the curl download URL, tar xf, sudo cp -f
/usr/local/bin/zig, sudo cp -rf /usr/local/lib/zig) are protected.
---
Duplicate comments:
In @.github/workflows/ci-macos-compat.yml:
- Line 16: Add the custom WarpBuild runner labels used in the workflow
(warp-macos-14-arm64-6x and warp-macos-15-arm64-6x) to the actionlint
configuration so actionlint stops flagging them as unknown; update
.github/actionlint.yaml to include these two labels under the labels/runners
section (where existing labels like self-hosted are declared) so the workflow
file that references os: [warp-macos-14-arm64-6x, warp-macos-15-arm64-6x] is
recognized.
---
Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 84-95: The Zig install logic is duplicated across multiple
workflows (the ZIG_REQUIRED variable, the conditional checking "zig version",
tarball curl/tar/sudo cp steps and PATH export) which should be centralized;
extract this block into a single reusable piece (either a composite GitHub
Action or a shared script invoked by workflows) and update workflows (ci.yml,
test-e2e.yml, test-depot.yml, release.yml, nightly.yml, ci-macos-compat.yml,
build-ghosttykit.yml) to call that single action/script; ensure the reusable
action accepts ZIG_REQUIRED as an input, runs the same conditional (checking
command -v zig and zig version), performs the tarball download/untar/copy and
PATH export, and preserves existing behavior of printing "zig ${ZIG_REQUIRED}
already installed" or "Installing zig ${ZIG_REQUIRED} from tarball" and
returning non-zero on failure so existing callers continue to behave the same.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 08e6013c-1092-46db-b219-20b820965def
📒 Files selected for processing (7)
.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/test-e2e.yml
| ZIG_REQUIRED="0.15.2" | ||
| if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then | ||
| echo "zig ${ZIG_REQUIRED} already installed" | ||
| else | ||
| echo "Installing zig ${ZIG_REQUIRED} from tarball" | ||
| curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz | ||
| tar xf /tmp/zig.tar.xz -C /tmp | ||
| sudo cp -f /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/zig /usr/local/bin/zig | ||
| sudo cp -rf /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/lib /usr/local/lib/zig | ||
| export PATH="/usr/local/bin:$PATH" | ||
| zig version | ||
| fi |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "Check Zig download/install blocks missing checksum verification:"
rg -n 'ziglang\.org/download/.+zig-aarch64-macos' .github/workflows
echo
echo "Nearby lines to confirm whether shasum/checksum validation exists:"
rg -n -C3 'ziglang\.org/download|shasum|sha256|checksum' .github/workflowsRepository: manaflow-ai/cmux
Length of output: 10018
Add SHA256 verification for Zig tarball before privileged install.
The workflow downloads Zig from ziglang.org (line 92) and immediately extracts and copies it to /usr/local/bin and /usr/local/lib (lines 93–95) without checksum validation. This pattern appears in 8 workflows across the repository (test-depot.yml, test-e2e.yml, nightly.yml, ci.yml, ci-macos-compat.yml, release.yml, build-ghosttykit.yml) and exposes CI to supply-chain compromise. The codebase already validates checksums for other artifacts (GhosttyKit, Homebrew DMG), so apply the same pattern here.
🔐 Suggested fix
else
echo "Installing zig ${ZIG_REQUIRED} from tarball"
curl -fSL "https://ziglang.org/download/${ZIG_REQUIRED}/zig-aarch64-macos-${ZIG_REQUIRED}.tar.xz" -o /tmp/zig.tar.xz
+ # Verify integrity against the official Zig release checksum.
+ ZIG_SHA256="<official-sha256-for-zig-aarch64-macos-0.15.2.tar.xz>"
+ echo "${ZIG_SHA256} /tmp/zig.tar.xz" | shasum -a 256 -c -
tar xf /tmp/zig.tar.xz -C /tmp
sudo mkdir -p /usr/local/bin /usr/local/lib
sudo cp -f /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/zig /usr/local/bin/zig
sudo cp -rf /tmp/zig-aarch64-macos-${ZIG_REQUIRED}/lib /usr/local/lib/zig
export PATH="/usr/local/bin:$PATH"
zig version
fi🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/test-depot.yml around lines 87 - 98, Add SHA256
verification for the Zig tarball before extracting or copying to privileged
locations: introduce an expected checksum variable (tied to ZIG_REQUIRED) and
after downloading /tmp/zig.tar.xz verify its checksum with shasum -a 256 or
sha256sum, comparing to the expected value and exiting non‑zero on mismatch;
only proceed to tar xf /tmp/zig.tar.xz and the sudo cp commands if the checksum
passes. Ensure the verification step occurs immediately after the curl that
writes /tmp/zig.tar.xz and before any use of tar, sudo cp, or adding to PATH so
that functions/variables referenced in the diff (ZIG_REQUIRED, /tmp/zig.tar.xz,
the curl download URL, tar xf, sudo cp -f /usr/local/bin/zig, sudo cp -rf
/usr/local/lib/zig) are protected.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 271e669bcb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if ! command -v zig >/dev/null 2>&1; then | ||
| brew install zig | ||
| ZIG_REQUIRED="0.15.2" | ||
| if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then |
There was a problem hiding this comment.
Match Zig version exactly before skipping install
The version gate uses grep -q "^${ZIG_REQUIRED}", which treats prefixes as matches (for example, 0.15.20 or 0.15.2-dev both satisfy 0.15.2). That means these workflows can silently skip the pinned-install path and run with an unintended Zig version, undermining reproducibility and potentially causing build/runtime drift on updated runner images; compare against the full version string instead of a prefix.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)
84-96: Consolidate duplicated Zig install logic into one reusable script/action.The two install blocks are effectively identical; keeping both invites drift when patching CI logic.
♻️ Refactor direction
- - name: Install zig - run: | - ZIG_REQUIRED="0.15.2" - ... + - name: Install zig + run: ./scripts/ci/install-zig.sh 0.15.2And call the same script in both jobs (
testsandtests-depot).Also applies to: 230-242
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/ci.yml around lines 84 - 96, There are two identical Zig install blocks (using ZIG_REQUIRED, the curl/tar extraction, sudo cp into /usr/local, and PATH export) duplicated across CI jobs; extract that sequence into a single reusable script or GitHub Action (e.g., scripts/install-zig.sh or .github/actions/install-zig) that accepts ZIG_REQUIRED and performs the curl, tar, install to /usr/local/bin and /usr/local/lib/zig, and PATH export/verification, then replace both in-workflow blocks with a single call to that script/action from the `tests` and `tests-depot` jobs so updates are made in one place.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/release.yml:
- Around line 103-104: Replace the prefix grep check that accepts partial
matches by performing an exact version comparison: locate the shell snippet that
runs `zig version` and currently pipes to `grep -q "^${ZIG_REQUIRED}"` (e.g.,
the if-condition using `command -v zig` and `zig version | grep -q
"^${ZIG_REQUIRED}"`) and change it to ensure exact equality (for example by
using `grep -xq "${ZIG_REQUIRED}"` or comparing the output string directly),
then apply that same exact-match change to every workflow occurrence of the `zig
version` + `grep -q "^${ZIG_REQUIRED}"` pattern so `ZIG_REQUIRED=0.15.2` will no
longer match `0.15.20` or `0.15.2-dev`.
---
Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 84-96: There are two identical Zig install blocks (using
ZIG_REQUIRED, the curl/tar extraction, sudo cp into /usr/local, and PATH export)
duplicated across CI jobs; extract that sequence into a single reusable script
or GitHub Action (e.g., scripts/install-zig.sh or .github/actions/install-zig)
that accepts ZIG_REQUIRED and performs the curl, tar, install to /usr/local/bin
and /usr/local/lib/zig, and PATH export/verification, then replace both
in-workflow blocks with a single call to that script/action from the `tests` and
`tests-depot` jobs so updates are made in one place.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 0161d453-02e7-4b63-aef8-bbd7f6777d32
📒 Files selected for processing (7)
.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/test-e2e.yml
| if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then | ||
| echo "zig ${ZIG_REQUIRED} already installed" |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "Locations using prefix Zig version matching:"
rg -n 'zig version 2>/dev/null \| grep -q "\^\$\{ZIG_REQUIRED\}"' .github/workflows
echo
echo "Regex behavior demo (current pattern):"
for v in 0.15.2 0.15.20 0.15.2-dev 0.15.3; do
if printf '%s\n' "$v" | grep -q '^0.15.2'; then
echo "MATCH: $v"
else
echo "NO_MATCH: $v"
fi
doneRepository: manaflow-ai/cmux
Length of output: 1334
Fix Zig version matching from prefix to exact comparison in all affected workflows.
The current pattern (grep -q "^${ZIG_REQUIRED}") uses prefix matching and silently accepts unintended versions. For example, with ZIG_REQUIRED=0.15.2, it matches 0.15.20 and 0.15.2-dev, breaking version pinning.
This occurs in 8 locations across multiple workflows:
.github/workflows/release.yml(line 103).github/workflows/ci.yml(lines 85, 231).github/workflows/test-e2e.yml(line 96).github/workflows/test-depot.yml(line 88).github/workflows/nightly.yml(line 155).github/workflows/ci-macos-compat.yml(line 76).github/workflows/build-ghosttykit.yml(line 65)
Proposed fix
- if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then
+ if command -v zig >/dev/null 2>&1 && [ "$(zig version 2>/dev/null)" = "${ZIG_REQUIRED}" ]; then
echo "zig ${ZIG_REQUIRED} already installed"Apply this exact-match update to all affected workflow files.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| if command -v zig >/dev/null 2>&1 && zig version 2>/dev/null | grep -q "^${ZIG_REQUIRED}"; then | |
| echo "zig ${ZIG_REQUIRED} already installed" | |
| if command -v zig >/dev/null 2>&1 && [ "$(zig version 2>/dev/null)" = "${ZIG_REQUIRED}" ]; then | |
| echo "zig ${ZIG_REQUIRED} already installed" |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/release.yml around lines 103 - 104, Replace the prefix
grep check that accepts partial matches by performing an exact version
comparison: locate the shell snippet that runs `zig version` and currently pipes
to `grep -q "^${ZIG_REQUIRED}"` (e.g., the if-condition using `command -v zig`
and `zig version | grep -q "^${ZIG_REQUIRED}"`) and change it to ensure exact
equality (for example by using `grep -xq "${ZIG_REQUIRED}"` or comparing the
output string directly), then apply that same exact-match change to every
workflow occurrence of the `zig version` + `grep -q "^${ZIG_REQUIRED}"` pattern
so `ZIG_REQUIRED=0.15.2` will no longer match `0.15.20` or `0.15.2-dev`.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0b1b591f2a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| build-sign-notarize: | ||
| runs-on: depot-macos-latest | ||
| runs-on: warp-macos-15-arm64-6x | ||
| timeout-minutes: 20 |
There was a problem hiding this comment.
Increase release workflow timeout beyond 20 minutes
Adding timeout-minutes: 20 here makes tag releases fragile because this same job does a full Release build and then waits on two notarization submissions (xcrun notarytool submit ... --wait for the app and DMG), so normal notarization queue delays can push runtime past 20 minutes and cause GitHub to cancel the release before artifacts are published.
Useful? React with 👍 / 👎.
|
Superseded by #1501 (consolidated version, already merged). |
Summary
Swaps all macOS runner labels from Depot and GitHub-hosted to WarpBuild. Job structure is unchanged.
depot-macos-latest→warp-macos-15-arm64-6xmacos-15→warp-macos-15-arm64-6xmacos-14→warp-macos-14-arm64-6xubuntu-latestunchanged for lightweight jobsAffected workflows: ci.yml, build-ghosttykit.yml, ci-macos-compat.yml, nightly.yml, release.yml, test-depot.yml, test-e2e.yml
Compare with https://github.com/manaflow-ai/cmux/pull/new/task-migrate-warpcloud-consolidated (consolidated version that merges tests + tests-depot into one job).
Testing
bash tests/test_ci_self_hosted_guard.sh→ PASSgrep -rn 'depot-macos-latest\|runs-on: macos-1[45]' .github/workflows/→ empty🤖 Generated with Claude Code
Summary by cubic
Migrates all macOS CI/CD workflows to WarpBuild runners and pins
zig0.15.2 via tarballs for consistent builds. Adds 20‑minute timeouts to macOS jobs; Ubuntu jobs remain onubuntu-latest.depot-macos-latest→warp-macos-15-arm64-6x,macos-15→warp-macos-15-arm64-6x,macos-14→warp-macos-14-arm64-6x.tests-depot→tests-ui; update guard script/test for WarpBuild-only internal runs; updatetest-e2e.ymlrunner inputs/defaults and cache keys to WarpBuild labels.zigto 0.15.2 by downloading from ziglang.org; auto-upgrade if outdated; fix tarball tozig-aarch64-macos-0.15.2.tar.xz; create/usr/local/binand/usr/local/libbefore install.ci.yml,ci-macos-compat.yml,test-e2e.yml,test-depot.yml,release.yml,nightly.yml,build-ghosttykit.yml.Written for commit 0b1b591. Summary will update on new commits.
Summary by CodeRabbit
Chores
Tests