Skip to content

ci: publish org-member dogfood app artifacts - #17204

Merged
teamleaderleo merged 1 commit into
feat-cmux-nextfrom
fix/org-member-dogfood
Oct 3, 2026
Merged

teamleaderleo merged 1 commit into
feat-cmux-nextfrom
fix/org-member-dogfood

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Org-member PRs with the dev-build label currently receive a tailnet-only controller link, so contributors outside the tailnet cannot download the app. This adds a trusted two-stage handoff:

  • same-repository MEMBER and OWNER PRs build the exact head on the existing macOS CI route and upload a content-addressed ZIP as a short-lived GitHub artifact
  • a default-branch workflow_run publisher revalidates the open PR, exact head, repository, author association, and label before uploading the ZIP to the private cmux-fleet-artifacts R2 bucket
  • the publisher HEAD-verifies a 15-minute SigV4 URL and updates one sticky PR comment with the download link and SHA-256 digest

The publisher uses the protected artifacts environment and CMUX_CEF_R2_* credentials. The direct R2 URL remains the transport until the controller CDN origin is available.

Validation: test_r2_presign.py, test_r2_upload_requests.py, test_ci_production_secrets_protected_env.py, test_ci_pull_request_caches_are_read_only.py, test_ci_workflow_run_sources.py, YAML parsing, and git diff --check pass. actionlint reports only the existing SC2129 warning at ci.yml:476.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Changes how org-member dev-build PRs get dogfood builds: instead of a tailnet-only controller link, the PR's CI run builds the exact head on a macOS runner, uploads a ZIP as a GitHub artifact, and a default-branch publisher revalidates the PR, uploads the ZIP to the private cmux-fleet-artifacts R2 bucket, and posts a sticky comment with a 15-minute signed download URL and SHA-256 digest.

The publisher runs only for open, same-repository PRs from MEMBER/OWNER authors with the dev-build label, uses the protected artifacts environment with CMUX_CEF_R2_* credentials, and HEAD-verifies the signed URL before posting the link. Direct R2 URLs remain the transport until the controller CDN origin is available. The dogfood build is now a real macOS build outside ci-status, so failures are visible but never block merges; the 15-minute link expires between pushes. Tests added cover the presigner, protected-environment secrets, and workflow source rules; actionlint reports only the pre-existing SC2129 warning.

Written for commit 7e7fce6. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: febd21b8-9714-43bc-8194-0a38366828eb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo force-pushed the fix/org-member-dogfood branch from 7fcc566 to 7e7fce6 Compare October 3, 2026 20:58
@teamleaderleo
teamleaderleo merged commit ed7ecab into feat-cmux-next Oct 3, 2026
44 checks passed
@teamleaderleo
teamleaderleo deleted the fix/org-member-dogfood branch October 3, 2026 21:00
teamleaderleo added a commit that referenced this pull request Oct 3, 2026
* ci: publish org-member dogfood app artifacts (#17204)

* ci: satisfy dogfood workflow runner guards

* ci: execute R2 presigner guard
lawrencecchen added a commit that referenced this pull request Oct 4, 2026
- ci.yml dogfood-build (#17204) runs on a Mac but needed only `changes`, so a
  red static stage could still bill Mac minutes. It now also needs
  static-preflight, the same lines as main's #17107.
- cmux-next.yml's push filter is wider than its pull_request filter on
  purpose since #17114 (base pushes keep full side coverage for
  Packages/{macOS,Shared,iOS}/**). The parity test now records that in
  EXEMPTIONS with the reason.
- #17164 gated macos-placement on needs.path_route.outputs.macos, but the
  side-lane placement test context had no path_route output. The context now
  carries a native route, and a no-Mac-work route must skip the placement.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
teamleaderleo pushed a commit to teamleaderleo/cmux that referenced this pull request Oct 5, 2026
… test requires

test_ci_fork_runner_routing failed 5 of 14 cases on feat-cmux-next (main
passes). Workflow lines added on this branch selected Blacksmith or
vars.LINUX_RUNNER without the owner fork branch or the fork pull-request
branch:
- ci.yml dogfood build (manaflow-ai#17204 on this branch): now main's expression,
  macos-26 outside manaflow-ai, no vars.MACOS_RUNNER_PR.
- cmux-next.yml request-nightly-next, cmux-next-web-bundles.yml (3 jobs),
  cmux-tui-artifacts.yml (2 jobs), backend.yml:141: the canonical Linux
  expression (ubuntu-24.04 outside manaflow-ai; Blacksmith, not
  vars.LINUX_RUNNER, for a fork pull request).
No rule is relaxed. 1 case remains: cmux-tui-artifacts.yml's
pull_request_target trigger (manaflow-ai#17296), a decision for the CI owner.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant