Repository navigation
ci: dispatch UI tests from a default-branch workflow; PR CI keeps no write token - #15226
Conversation
…-only ci.yml's ui-tests job held actions: write, and a pull_request run takes ci.yml from the pull request. The job now validates the selectors, uploads them as ui-tests-request-<attempt>, and waits for the verdict of ci-ui-tests.yml, which runs from the default branch on every CI run attempt (workflow_run: requested), re-validates the request against the run GitHub reports, runs main's dispatcher, and cancels the dispatched run when the CI attempt ends first. No job in ci.yml holds actions: write. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Find a queued labeled run's dispatch run from the run's creation, and only a default-branch dispatch run counts. - exec the dispatcher so a cancelled step reaches it and it cancels the dispatched run; never cancel a run it only attached to. - Do not dispatch for an attempt that already completed. - Bot re-runs (owned-pool rescue, failure attribution) start the dispatch for the new attempt themselves, since a GITHUB_TOKEN re-run may emit no workflow_run event. - Retry single reads; read the request every two minutes; fall back from the App token only on 401/403. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 1 minute. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (14)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
|
Dogfood build of cmux DEV pr-15226-a5a2b742.app The link opens this exact commit in the cmux dev menu bar app. The build starts on each push and the page waits until it is ready; a newer push replaces it. It signs in against production, so Cloud or backend changes still need a tagged build with a development backend. |
A read right after the re-run may still show the old attempt, so the rescue passes target.attempt + 1 instead of reading it back. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
CI failure attributionCI passes on Written by |
…, not a sleep Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Merge receipt for |
ba94a13 CI: let Iroh release gate reuse unchanged TUI artifact 71a921c fix(web): stop orphaned Cloud VM alert pages (manaflow-ai#15138) 9971c2c Keep newer iOS connections alive when a recovery is superseded (manaflow-ai#15141) c307ab0 cmux-tui: only connect to derived local sockets served by this user (manaflow-ai#15144) 1220252 codex-teams: keep the watcher's socket password out of its arguments (manaflow-ai#15140) b3a73f0 chatmux-relay: keep cmux-tui sockets and journal cursors private to this user (manaflow-ai#15156) b0d5083 ci: dispatch UI tests from a default-branch workflow; PR CI keeps no write token (manaflow-ai#15226) 1255448 test: fix three app-host tests that keep main red (manaflow-ai#15204) 0fc4975 test: pin the fixture PATH inside the zsh watcher sleep test (manaflow-ai#15237) 758aaeb fix(ios): clear read notifications on foreground return (manaflow-ai#14725) 4c15bb3 cmux-browser: stop requiring GPL for web/package.json (manaflow-ai#15231) 97fe6b4 test: keep the Cloud notification harness workspace unselected (manaflow-ai#15215) 61083e3 test: keep workspace cwd inheritance tests off the shared standard defaults (manaflow-ai#15227) eae4994 Pin password badge actions to their source runtime (manaflow-ai#14921) fd96369 Check the owner of the Claude shim directory in the app, workspace commands and nushell (manaflow-ai#15185) 0ebf8d7 Fix main-thread freeze during SSH paste detection (manaflow-ai#15113) a98c560 test: pin font magnification in the Cloud outline attention test (manaflow-ai#15213)
Pull request CI no longer holds
actions: write. Theui-testsjob in ci.yml was the one job with it, and apull_requestrun takes ci.yml from the pull request, so a same-repository author could rewrite that job. #15193 made it run main's dispatcher but left the token in PR CI.Now the dispatch runs in a new workflow,
ci-ui-tests.yml, which always runs from the default branch. It starts on every CI run attempt (workflow_run: requested).ui-tests(contents and actions read only) validates each selector ascmuxUITests/<Class>[/<method>]and uploads them asui-tests-request-<attempt>. It then waits for the dispatch run serving its attempt and reports that run's verdict, so UI tests still start on their own, still gateci-status, and the result stays on the pull request.ci-ui-tests.ymlreads the CI attempt from the API. It serves only a same-repositorypull_requestrun of.github/workflows/ci.yml, and returns at once when the pull request changes nothing undercmuxUITests/. Otherwise it waits for the request and checks it again: the head SHA must equal the one GitHub reports, the selectors must match the same pattern, and the merge SHA is used only to fetch objects. It then runs main's dispatcher with routing variables it reads itself. If the CI attempt ends first (a newer push, orui-testsgave up), it cancels the dispatched run, unless the dispatcher only attached to someone else's identical run.workflow_runevent. Those two now dispatchci-ui-tests.ymlfor the new attempt themselves. A duplicate joins the same concurrency group.Transition: open pull requests still on the old ci.yml keep dispatching from their own job. The new workflow finds no request for them and exits when their attempt completes, so nothing is dispatched twice. The new workflow only acts once this merges.
Tests:
tests/test_ci_ui_tests_dispatch.py(new, 24 cases: validation, request wait, verdict lookup, cancellation, workflow shape), plus the updatedtest_ci_change_areas(no job in ci.yml has actions write),test_ci_owned_pool_rescue,test_ci_classify_failures,test_ci_workflow_run_sources,test_ci_fork_runner_routing,test_ci_linux_guard_routing, and actionlint, all passing locally.— Icicle g1 ⚙️ (run_worker_20260927_686a3a99)
🤖 Generated with Claude Code
Summary by cubic
Removes the
actions: writetoken from PR CI. Theui-testsjob was the only job holding it, and apull_requestrun takes ci.yml from the pull request, so a same-repository author could rewrite that job; the UI test dispatch now happens inci-ui-tests.yml, which always runs from the default branch.The
ui-testsjob (nowactions: read) validates the selectors, uploads them asui-tests-request-<attempt>, waits for the dispatch run serving that attempt, and reports its verdict, so UI tests still start on their own and still gateci-status.ci-ui-tests.ymlserves only same-repository pull requests, re-validates the head SHA and selector pattern, runs main's dispatcher, and cancels the dispatched run when the CI attempt ends first, unless the dispatcher attached to someone else's identical run.actions: write, and the new workflow'spermissionsblock is empty.ci-ui-tests.ymlfor the new attempt themselves, since aGITHUB_TOKENre-run may emit noworkflow_runevent; duplicates join the same concurrency group. The rescue passes the attempt it started (attempt + 1), because a read right after the re-run can still report the old attempt.scripts/ci/ui_tests_dispatch.pyandtests/test_ci_ui_tests_dispatch.py, both registered in the guard and execution test suites.Migration
Written for commit a5a2b74. Summary will update on new commits.