Repository navigation
ci: publish org-member dogfood app artifacts - #17204
Merged
Merged
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
teamleaderleo
force-pushed
the
fix/org-member-dogfood
branch
from
October 3, 2026 20:58
7fcc566 to
7e7fce6
Compare
teamleaderleo
added a commit
that referenced
this pull request
Oct 3, 2026
* ci: publish org-member dogfood app artifacts (#17204) * ci: satisfy dogfood workflow runner guards * ci: execute R2 presigner guard
lawrencecchen
added a commit
that referenced
this pull request
Oct 4, 2026
- ci.yml dogfood-build (#17204) runs on a Mac but needed only `changes`, so a red static stage could still bill Mac minutes. It now also needs static-preflight, the same lines as main's #17107. - cmux-next.yml's push filter is wider than its pull_request filter on purpose since #17114 (base pushes keep full side coverage for Packages/{macOS,Shared,iOS}/**). The parity test now records that in EXEMPTIONS with the reason. - #17164 gated macos-placement on needs.path_route.outputs.macos, but the side-lane placement test context had no path_route output. The context now carries a native route, and a no-Mac-work route must skip the placement. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
teamleaderleo
pushed a commit
to teamleaderleo/cmux
that referenced
this pull request
Oct 5, 2026
… test requires test_ci_fork_runner_routing failed 5 of 14 cases on feat-cmux-next (main passes). Workflow lines added on this branch selected Blacksmith or vars.LINUX_RUNNER without the owner fork branch or the fork pull-request branch: - ci.yml dogfood build (manaflow-ai#17204 on this branch): now main's expression, macos-26 outside manaflow-ai, no vars.MACOS_RUNNER_PR. - cmux-next.yml request-nightly-next, cmux-next-web-bundles.yml (3 jobs), cmux-tui-artifacts.yml (2 jobs), backend.yml:141: the canonical Linux expression (ubuntu-24.04 outside manaflow-ai; Blacksmith, not vars.LINUX_RUNNER, for a fork pull request). No rule is relaxed. 1 case remains: cmux-tui-artifacts.yml's pull_request_target trigger (manaflow-ai#17296), a decision for the CI owner.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Org-member PRs with the
dev-buildlabel currently receive a tailnet-only controller link, so contributors outside the tailnet cannot download the app. This adds a trusted two-stage handoff:workflow_runpublisher revalidates the open PR, exact head, repository, author association, and label before uploading the ZIP to the privatecmux-fleet-artifactsR2 bucketThe publisher uses the protected
artifactsenvironment andCMUX_CEF_R2_*credentials. The direct R2 URL remains the transport until the controller CDN origin is available.Validation:
test_r2_presign.py,test_r2_upload_requests.py,test_ci_production_secrets_protected_env.py,test_ci_pull_request_caches_are_read_only.py,test_ci_workflow_run_sources.py, YAML parsing, andgit diff --checkpass.actionlintreports only the existing SC2129 warning atci.yml:476.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Changes how org-member
dev-buildPRs get dogfood builds: instead of a tailnet-only controller link, the PR's CI run builds the exact head on a macOS runner, uploads a ZIP as a GitHub artifact, and a default-branch publisher revalidates the PR, uploads the ZIP to the privatecmux-fleet-artifactsR2 bucket, and posts a sticky comment with a 15-minute signed download URL and SHA-256 digest.The publisher runs only for open, same-repository PRs from MEMBER/OWNER authors with the
dev-buildlabel, uses the protectedartifactsenvironment withCMUX_CEF_R2_*credentials, and HEAD-verifies the signed URL before posting the link. Direct R2 URLs remain the transport until the controller CDN origin is available. The dogfood build is now a real macOS build outside ci-status, so failures are visible but never block merges; the 15-minute link expires between pushes. Tests added cover the presigner, protected-environment secrets, and workflow source rules;actionlintreports only the pre-existing SC2129 warning.Written for commit 7e7fce6. Summary will update on new commits.