Skip to content

ci: remove automated PR catch-up - #15959

Merged
teamleaderleo merged 2 commits into
mainfrom
ci/remove-pr-catch-up
Sep 30, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
ci/remove-pr-catch-up

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Remove the automated PR catch-up workflow that created bot-authored merge commits and left pull request CI in action_required (#1024). In September it ran 302 times, with 300 skipped and 2 successful runs.

The supported path remains scripts/merge-main.sh, documented in docs/ci/merge-main.md. It selects a green main base and uses a trusted local resolver for generated-file conflicts.

Removed:

  • .github/workflows/pr-catch-up.yml
  • The automatic selector scripts/ci/auto_catch_up_select.py
  • The PR merge, verification, artifact and comment code from scripts/ci/catch_up_pr.py
  • Selector replay fixtures and the two PR catch-up test files
  • CI guard steps and test-execution registry entries for those deleted files
  • Automatic catch-up documentation, /catch-up command guidance, and related workflow references

The shared local resolver moved to scripts/ci/merge_main_resolver.py; scripts/merge-main.sh and the installed project-file merge driver continue to use it. Hook installation and trust tests were updated to copy the renamed resolver.

The CLA workflow’s historical trusted-status exemption remains byte-for-byte unchanged because it is an immutable CLA policy transition that requires a trusted maintainer review. No active catch-up workflow remains to produce that status.

Validation: python3 scripts/verify-local.py passed 15 of 16 selected checks; Swift syntax had no selected files. The focused suites passed: 23 merge-main tests, 22 project-file merge-driver tests, 15 hook-installation tests, 5 trust tests, and the test execution registry check. git diff --check passed. The broader change-area suite has two inherited stale-head fixture failures on fresh main, reproduced on the base commit as well. No app builds were run.

Changelog

Removed: automated PR catch-up and its selector, verification, fixtures, tests, and documentation.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Removes the automated PR catch-up workflow that merged green main into open pull requests with bot-authored merge commits, leaving pull request CI in action_required (#1024). The workflow ran 302 times in September with only 2 successful runs; branches are now kept current through scripts/merge-main.sh only.

  • Removes the workflow, selector script, merge/resolve/artifact/comment code, replay fixtures, tests, CI guard steps, and related documentation.
  • Moves the shared generated-file resolver to scripts/ci/merge_main_resolver.py, which scripts/merge-main.sh and the project-file merge driver now call; hook installation and trust tests copy the renamed resolver.
  • Keeps the CLA workflow's historical trusted-status exemption byte-for-byte unchanged because it is an immutable policy transition and no active catch-up workflow produces that status anymore.

Written for commit 5d6cfc4. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Changes
    • Automatic and manual pull request catch-up are no longer available. To update a branch from main, use the documented local merge command.
    • Branch updates can now merge changes to separate translation-catalog entries automatically. Conflicts affecting the same entry require manual resolution.
    • Local merge guidance clarifies that force-pushing over a merge is not supported.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 45 seconds.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 24c1a0ef-5730-48b7-aaa3-b9e180c773e5

📥 Commits

Reviewing files that changed from the base of the PR and between 7f8b717 and 5d6cfc4.

📒 Files selected for processing (21)
  • .github/workflows/ci-guards.yml
  • .github/workflows/pr-catch-up.yml
  • CLAUDE.md
  • docs/ci/merge-main.md
  • scripts/ci/auto_catch_up_select.py
  • scripts/ci/last_green_base.py
  • scripts/ci/merge_main.py
  • scripts/ci/merge_main_resolver.py
  • scripts/ci/workflow_guard_groups.py
  • scripts/generate-cmux-config-schema.py
  • scripts/git-hooks/post-merge
  • scripts/install-git-hooks.sh
  • scripts/merge-main.sh
  • scripts/merge-pbxproj.py
  • tests/fixtures/auto_catch_up/replay.json
  • tests/test-execution.toml
  • tests/test_ci_auto_catch_up_select.py
  • tests/test_ci_catch_up_pr.py
  • tests/test_ci_merge_main.py
  • tests/test_install_git_hooks.py
  • tests/test_preflight_trust.py

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 26521700-ea2f-4602-87e4-216304c36784

📥 Commits

Reviewing files that changed from the base of the PR and between af7e327 and 7f8b717.

📒 Files selected for processing (21)
  • .github/workflows/ci-guards.yml
  • .github/workflows/pr-catch-up.yml
  • CLAUDE.md
  • docs/ci/merge-main.md
  • scripts/ci/auto_catch_up_select.py
  • scripts/ci/last_green_base.py
  • scripts/ci/merge_main.py
  • scripts/ci/merge_main_resolver.py
  • scripts/ci/workflow_guard_groups.py
  • scripts/generate-cmux-config-schema.py
  • scripts/git-hooks/post-merge
  • scripts/install-git-hooks.sh
  • scripts/merge-main.sh
  • scripts/merge-pbxproj.py
  • tests/fixtures/auto_catch_up/replay.json
  • tests/test-execution.toml
  • tests/test_ci_auto_catch_up_select.py
  • tests/test_ci_catch_up_pr.py
  • tests/test_ci_merge_main.py
  • tests/test_install_git_hooks.py
  • tests/test_preflight_trust.py
💤 Files with no reviewable changes (7)
  • tests/fixtures/auto_catch_up/replay.json
  • tests/test-execution.toml
  • tests/test_ci_auto_catch_up_select.py
  • tests/test_ci_catch_up_pr.py
  • .github/workflows/ci-guards.yml
  • .github/workflows/pr-catch-up.yml
  • scripts/ci/auto_catch_up_select.py

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The PR removes automatic and manual pull-request catch-up workflows and their selector. Local merge-main tooling now uses the trusted merge resolver, and contributor guidance identifies scripts/merge-main.sh as the supported branch catch-up path.

Changes

Merge-main transition

Layer / File(s) Summary
Local merge resolver and merge-main tests
scripts/ci/merge_main.py, scripts/ci/merge_main_resolver.py, tests/test_ci_merge_main.py
merge_main.py now calls merge_main_resolver.merge_and_resolve(). The resolver uses the MergeResolverError name and merge-main commit metadata. Tests cover catalog key unions and same-key conflicts.
Trusted resolver integration
scripts/ci/workflow_guard_groups.py, scripts/ci/last_green_base.py, scripts/generate-cmux-config-schema.py, scripts/git-hooks/post-merge, scripts/install-git-hooks.sh, scripts/merge-main.sh, scripts/merge-pbxproj.py, tests/test_install_git_hooks.py, tests/test_preflight_trust.py
Guard ownership, hook trust checks, merge-driver installation, and preflight fixtures now identify merge_main_resolver.py as the trusted helper.
Remove PR catch-up automation and guidance
.github/workflows/pr-catch-up.yml, .github/workflows/ci-guards.yml, scripts/ci/auto_catch_up_select.py, tests/fixtures/auto_catch_up/*, tests/test_ci_auto_catch_up_select.py, tests/test_ci_catch_up_pr.py, tests/test-execution.toml, CLAUDE.md, docs/ci/merge-main.md
The catch-up workflow, selector, replay fixture, related tests, and CI test entries are removed. Contributor guidance describes scripts/merge-main.sh as the supported branch catch-up path.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 7f8b7

The change retires the automated PR catch-up workflow and points contributors to the local merge-main script. The resolver rename is applied consistently, and no merge-blocking risk was identified.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 7f8b7

The removal reduces automated access to pull requests. One upgrade path needs attention: an older installed hook can copy the renamed resolver without checking that it matches trusted main, if that file has been modified locally.

Retained concerns

  • Medium · security · inferred: During an upgrade, a previously installed post-merge hook does not check the newly named resolver against trusted main before invoking the new installer. If the resolver differs in the working tree at that point, the installer can copy it into the trusted merge-driver directory, where a later project-file merge can load it under the local user's authority.
Security review details

Security Blast Radius

  • inferred — The identified upgrade exposure is confined to a clone whose old installed hook runs while the new resolver differs from trusted main. The potential execution authority is that clone's local user, not the removed workflow's bot token.

Security Findings and Attack Paths

  • inferred — If a modified resolver is present at canonical-main HEAD when a previously installed hook refreshes the drivers, the old path list will not detect that modification. The new installer can copy those bytes; a later project-file merge loads the copy. The record does not establish that this condition occurs in normal upgrades or is directly reachable from a fork checkout.

Trust Boundaries and Controls

  • observed — The hook requires HEAD to equal a main ref from the configured canonical remote. The updated hook checks the renamed resolver; installation rejects a Python interpreter resolving inside the checkout and configures isolated execution of installed merge drivers. These controls limit, but do not close, the old-hook upgrade gap.

Resilience and Maintainability Implications

  • observed — The migration test verifies installation after a trusted-main fast-forward using the current hook, but does not exercise a previously installed hook checking the old helper name. Installer copies and Git configuration updates are ordered operations, not an atomic upgrade.

Hardening Proposals

  • proposed — For automatic upgrades, verify every file to be installed against the trusted main tree at the point of copying, so an older hook's narrower path list cannot authorize a new helper. Cover migration with an old installed hook and a modified new resolver.
🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (3 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the primary change: removing automated PR catch-up.
Description check ✅ Passed The description explains the problem, resulting behavior, removed components, supported replacement path, testing results, known limitations, and changelog entry. It omits the template checklist and d…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS: The pull request does not change Cloud terminal creation, persistent cmux-tui transport, manual renderer admission, or terminal input routing. The authoritative diff changes CI catch-up workflow…
Cmux Swift Actor Isolation ✅ Passed PASS: The review-scoped diff contains no changed .swift files. It changes workflows, documentation, Python and shell tooling, TOML, JSON, and tests only. Therefore it introduces no production Swift …
Cmux Swift Blocking Runtime ✅ Passed PASS: The pull request changes no Swift files. The authoritative diff contains workflows, documentation, Python, shell, TOML, JSON fixtures, and tests only. Therefore it does not introduce or material…
Cmux Browser Automation Off-Main ✅ Passed The PR does not change cmux browser socket automation. The authoritative diff changes only CI catch-up workflows, Python merge tooling, documentation, hooks, and related tests; it contains no Swift ch…
Cmux Expensive Synchronous Load ✅ Passed PASS: The reviewed diff contains no Swift files or production Swift changes. It changes CI YAML, Markdown, Python, shell scripts, and tests, and deletes the PR catch-up workflow and helpers. Therefore…
Cmux Cache Substitution Correctness ✅ Passed PASS: The authoritative pull-request diff changes no Swift, TypeScript, or JavaScript files. It changes Python, shell, YAML, Markdown, TOML, and test files only, so the cache-substitution correctness …
Cmux No Hacky Sleeps ✅ Passed PASS. The PR does not add or expand fixed sleeps, timers, polling, or wall-clock synchronization in covered runtime scripts. The diff removes the catch-up selector and workflow, including its prior re…
Cmux Algorithmic Complexity ✅ Passed The PR does not introduce an algorithmic-complexity violation. The authoritative diff removes the catch-up workflow, selector, fixtures, and tests, with 4,145 net deletions. The production resolver is…
Cmux Swift Concurrency ✅ Passed The pull request changes no Swift files. The authoritative diff contains workflows, documentation, Python, shell, TOML, JSON, and test files only. Therefore, it introduces no cmux Swift concurrency pa…
Cmux Swift @Concurrent ✅ Passed PASS. The authoritative pull-request diff changes no Swift files. The changed-file extension inventory contains no .swift paths, and the Swift-specific diff scan found no @concurrent, `nonisolated…
Cmux Swift Package Boundaries ✅ Passed The authoritative PR diff changes no Swift, SwiftPM, Xcode project, or workspace files. The changes are limited to Python, shell, YAML, Markdown, TOML, JSON, and workflow/test files. Therefore, the Sw…
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only CI/workflow, documentation, Python, shell, and test files. It does not change any Package.swift, Package.resolved, package .gitignore, or Xcode project/workspace file. Theref…
Cmux Swift Logging ✅ Passed The pull request changes no Swift, Objective-C, or Objective-C++ source files. The changed-file inventory contains only Python, shell, YAML, Markdown, TOML, JSON, and extensionless files. Therefore, t…
Cmux User-Facing Error Privacy ✅ Passed PASS: The pull request changes only CI workflows, internal merge scripts, developer documentation, hooks, and tests. It adds no cmux app UI, product CLI, or product API path to a cmux end user. The ch…
Cmux Full Internationalization ✅ Passed The PR changes only CI workflows, Python/Shell tooling, Markdown guidance, TOML, YAML, and tests. The authoritative diff contains no Swift UI files, app string catalogs, InfoPlist catalogs, web messag…
Cmux Swiftui State Layout ✅ Passed The pull request changes only YAML, Markdown, Python, shell, TOML, and fixture files. It adds or modifies no Swift or SwiftUI code, so the SwiftUI state-layout check is not applicable.
Cmux Architecture Rethink ✅ Passed PASS: The authoritative PR diff contains no Swift source, interface, or documentation files. All changes are workflows, documentation, Python scripts, fixtures, and tests. The only added Swift-related…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The reviewed diff contains no Swift, Objective-C, or Objective-C++ files. It changes only YAML, Markdown, Python, shell, TOML, JSON, and an extensionless file, so it adds or changes no Swift-own…
Cmux Source Artifacts ✅ Passed No changed path matches the forbidden artifact patterns. The PR only modifies or removes workflows, source scripts, documentation, configuration, tests, and a required replay fixture; the only rename …
Cmux No Test Or Debug Seam In Production Source ✅ Passed PASS: The authoritative pull-request diff contains no Swift files under a production Sources/ path. The custom check therefore has no applicable changed production source and no test/debug seam can …
Full details: Docstring Coverage

Explanation

Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (3 skipped: 3 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Review at 7f8b717: No correctness findings. The resolver extraction preserves scripts/merge-main.sh and installed merge-driver behavior, and the deleted selector, workflow, scripts, fixtures, tests and executable references are gone. Fixed: none needed. Left: the pinned CLA workflow retains its historical cmux/catch-up-merge exemption and two comments, plus the validator history comment; removing those triggers the repository-mandated CLA policy migration and trusted maintainer review.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

CI failure attribution

CI passes on 5d6cfc45e8 (run 36712328070 attempt 3).

Written by scripts/ci/classify_failures.py (ci-failure-attribution.yml); signatures are its SIGNATURES table. A machine verdict is the runner's fault, not this PR's.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Dogfood tours of 5d6cfc45

sidebar-and-chrome-tour at 5d6cfc45: not run

skipped: CI left no app build for this head (its compile failed or was cancelled)

Tours are picked by the paths globs in dogfood/scenarios/*.json; a Dogfood-tours: a, b line in the description picks them instead (none turns this off). Look at every frame before merging: a green tour only means no step failed.

Merge-main commit by scripts/merge-main.sh.
Merged by scripts/merge-main.sh: origin/main at 40a636e.

Merge-main-previous-head: 7f8b717
Merge-main-base: 40a636e
@cursor

cursor Bot commented Sep 30, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 30, 2026 13:29
@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 30, 2026 14:01
@teamleaderleo
teamleaderleo merged commit 8da92cb into main Sep 30, 2026
165 of 171 checks passed
@teamleaderleo
teamleaderleo deleted the ci/remove-pr-catch-up branch September 30, 2026 14:44
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 5d6cfc45e8: every check was green at merge (21 verified; 25 skipped by policy). Full suite runs on main after merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant