Skip to content

fix(ci): avoid argv limit in dogfood publisher - #17220

Merged
teamleaderleo merged 1 commit into
mainfrom
fix/dogfood-publisher-stdin
Oct 4, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
fix/dogfood-publisher-stdin

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

The Dogfood artifact publish workflow passed full GitHub API responses as environment variables to /usr/bin/python3. Larger runs exceeded the OS argument limit and skipped publishing the exact dev-build artifact.

This changes the lookup to write the PR, jobs, and artifacts responses to temporary files. Python reads those files, while the trust predicate and outputs stay unchanged. The temporary directory is cleaned up automatically.

Validation:

  • actionlint .github/workflows/dogfood-artifact-publish.yml
  • YAML parse and git diff --check
  • Reproduced failure: run 37166119662, step Find the trusted org-member dogfood artifact

— Copperleaf g2 🌾
run: run_20261003T220704Z_nightly_next
intention: repair dogfood artifact publishing on main


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes the dogfood artifact publish workflow so large CI runs no longer exceed the OS argument limit and skip publishing the dev-build artifact.

  • The PR, jobs, and artifacts API responses are now written to a temporary file each instead of being passed as environment variables to Python.
  • Python reads those files to look up the trusted org-member artifact; the trust predicate and outputs are unchanged, and the temporary directory is cleaned up automatically.

Written for commit bda6966. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated the artifact publishing workflow’s handling of GitHub responses. Existing verification checks and publishing decisions are unchanged.
    • No changes to app features or behavior are included in this update.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 90d664b5-1b75-41e8-bc5d-f3f7d13b3836
📥 Commits

Reviewing files that changed from the base of the PR and between 00f182f and bda6966.

📒 Files selected for processing (1)
  • .github/workflows/dogfood-artifact-publish.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The workflow stores PR, jobs, and artifacts API responses in temporary files. Python reads and parses the files. The trust checks and publish decision remain unchanged.

Changes

Trusted Artifact Response Handling

Layer / File(s) Summary
API response file handoff
.github/workflows/dogfood-artifact-publish.yml
The workflow writes API responses to temporary files and passes their paths to Python. Python reads the JSON files for the existing trust checks.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to bda69

The workflow preserves the existing trust checks while moving API responses to temporary files. No material merge-readiness risk is apparent.

Architecture Summary

Architecture risk: 🔵 Low · up to bda69

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/dogfood-artifact-publish.yml: The workflow now stores the PR, jobs, and artifacts API responses in temporary files, removes the directory on exit, and passes file paths to Python instead of embedding response bodies in environment variables.
  • observed — Modified behavior in .github/workflows/dogfood-artifact-publish.yml: Python now reads the three JSON responses from the supplied paths using Path.read_text(); the parsed data and subsequent trust checks are unchanged.
🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the CI fix: avoiding the argument-size limit in the Dogfood publisher.
Description check ✅ Passed The description explains the problem, the change, and the reported validation. The demo section is not relevant to this CI-only change. It omits the Changelog and Checklist sections, but the descripti…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed PASS. The reviewed diff changes only .github/workflows/dogfood-artifact-publish.yml. It redirects GitHub API JSON responses to temporary files and reads those files in Python. It does not change Clo…
Cmux Swift Actor Isolation ✅ Passed The check does not apply to this pull request. The authoritative diff changes only .github/workflows/dogfood-artifact-publish.yml and adds no Swift changes. Therefore, it introduces no Swift actor-i…
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only .github/workflows/dogfood-artifact-publish.yml; no Swift files changed. The Swift blocking-runtime check does not apply.
Cmux Browser Automation Off-Main ✅ Passed The custom check applies to browser socket automation changes. The authoritative diff changes only .github/workflows/dogfood-artifact-publish.yml, which writes GitHub API responses to temporary file…
Cmux Expensive Synchronous Load ✅ Passed The custom check applies to production Swift changes. The reviewed diff changes only .github/workflows/dogfood-artifact-publish.yml and contains no Swift-path changes, so this check is not applicabl…
Cmux Cache Substitution Correctness ✅ Passed The check applies to production Swift, TypeScript, and JavaScript changes. The PR changes only .github/workflows/dogfood-artifact-publish.yml; it does not change any of those production source files…
Cmux No Hacky Sleeps ✅ Passed The pull request changes only .github/workflows/dogfood-artifact-publish.yml. The runtime no-hacky-sleeps rule excludes GitHub Actions workflow YAML, and the patch adds no sleep, timer, polling, or …
Cmux Algorithmic Complexity ✅ Passed The diff changes only the Dogfood workflow's API-response handling. It writes three JSON responses to temporary files and reads them in Python. The existing checks scan the jobs and artifacts lists on…
Cmux Swift Concurrency ✅ Passed The diff changes only .github/workflows/dogfood-artifact-publish.yml and contains no changed Swift paths. The custom check does not apply to this workflow-only change.
Cmux Swift @Concurrent ✅ Passed The pull request changes only .github/workflows/dogfood-artifact-publish.yml. The authoritative diff contains no Swift files, so it introduces no Swift @concurrent annotation changes covered by th…
Cmux Swift Package Boundaries ✅ Passed The Swift package-boundary check does not apply to this pull request. The authoritative diff changes only .github/workflows/dogfood-artifact-publish.yml and contains no Swift changes.
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only .github/workflows/dogfood-artifact-publish.yml. It changes how the workflow reads GitHub API responses. It does not change a SwiftPM dependency, package .gitignore, or Xcode pr…
Cmux Swift Logging ✅ Passed PASS. The reviewed diff changes only .github/workflows/dogfood-artifact-publish.yml and contains no Swift source changes. The Swift logging check is not applicable.
Cmux User-Facing Error Privacy ✅ Passed The PR changes only .github/workflows/dogfood-artifact-publish.yml. The diff writes GitHub API responses to temporary files and has Python read them; it does not add user-facing error or recovery te…
Cmux Full Internationalization ✅ Passed The PR changes only .github/workflows/dogfood-artifact-publish.yml. It moves GitHub API response JSON from environment-variable values to temporary files and reads those files with Path. The trust…
Cmux Swiftui State Layout ✅ Passed The check is not applicable. The PR changes only .github/workflows/dogfood-artifact-publish.yml; the reviewed diff contains no Swift or SwiftUI source changes.
Cmux Architecture Rethink ✅ Passed The check applies to Swift architecture changes. The reviewed diff changes only .github/workflows/dogfood-artifact-publish.yml; it contains no Swift changes. The workflow moves API JSON from environ…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull request changes only .github/workflows/dogfood-artifact-publish.yml. The diff contains no Swift changes, so it does not add or materially change a cmux-owned window covered by this check.
Cmux Source Artifacts ✅ Passed The diff changes only the tracked GitHub Actions workflow .github/workflows/dogfood-artifact-publish.yml, which is an intentional configuration file covered by the rule’s pass criteria. The added JS…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The reviewed diff changes only .github/workflows/dogfood-artifact-publish.yml. It changes how the workflow stores and reads API responses. The diff contains no Swift file under a production `Sources…
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

CI fast guards failed on bda69664a5 (https://github.com/manaflow-ai/cmux/actions/runs/37167261194). It does not block the merge; a red guard merged into main breaks it for every open PR.

Validate macOS jobs select a pinned Xcode (red on main too, not this PR)

Main has failed this step since #17206 by @teamleaderleo (self-merged) (#17169). Merge main again once the fix lands there.

Validate owned Mac build state (red on main too, not this PR)

Main has failed this step since #17168 by @teamleaderleo (self-merged) (#17169). Merge main again once the fix lands there.

Validate fork runner routing (red on main too, not this PR)

Main has failed this step since #17206 by @teamleaderleo (self-merged) (#17169). Merge main again once the fix lands there.

Run canonical CMUX CI guard profile (red on main too, not this PR)

Main has failed this step since #17206 by @teamleaderleo (self-merged) (#17169). Merge main again once the fix lands there.

Agents: python3 scripts/ci/guard_attribution.py fix applies the mechanical fixes locally. This comment is updated in place on each push.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

CI failure attribution

CI failed on bda69664a5 (run 37167261322 attempt 1): 1 code, 1 unknown.

Job Verdict Why
Fast static checks code a static check failed
guards / workflow-guard-tests / ci unknown no known signature; failed step: Propagate failed independent fast guard
Matched log lines
Fast static checks: FAILED localization (1.22s)

Not re-run automatically: Fast static checks, guards / workflow-guard-tests / ci are not machine failures.

Written by scripts/ci/classify_failures.py (ci-failure-attribution.yml); signatures are its SIGNATURES table. A machine verdict is the runner's fault, not this PR's.

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

The PR-specific workflow checks are blocked by an inherited main failure. Current PR run 37167261322 and main run 37156366448 both fail Fast static checks in the unchanged localization catalog, with the same machines.new.plan.* parity errors. The current PR change only moves the three API JSON responses from environment arguments to temporary files; it does not touch localization or the trust predicate.

— Copperleaf g2 🌾
run: run_20261003T220704Z_nightly_next
intention: document inherited main red before merge

@teamleaderleo
teamleaderleo merged commit 467f490 into main Oct 4, 2026
65 of 71 checks passed
@teamleaderleo
teamleaderleo deleted the fix/dogfood-publisher-stdin branch October 4, 2026 01:17
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Merge receipt for bda69664a5, merged 2026-10-04 01:17:36 UTC

  • Not verified at merge: ci-status (failure), CI fast guards (failure), Fast static checks (failure), guards (19) (failure)
  • Verified: backend migrations applied, CI timing, GhosttyKit release check, plan, tests, Web complexity, web-validation
  • Skipped by policy: apply-production, apply-staging, browser, Claude wrapper regressions, Dogfood build #​${{ github.event.pull_request.number }}, full-suite-coverage, linux-preflight, macos, macOS admission gate, remote-daemon, suite-coverage, ui-tests, and 4 more
  • Full suite: runs on main after merge.

Labeled merged-unverified: if main breaks near this merge, look here first.

@github-actions github-actions Bot added the merged-unverified A judging check was not green at merge; see the merge receipt comment label Oct 4, 2026
rustybret pushed a commit to rustybret/bmux that referenced this pull request Oct 4, 2026
5f6b50c fix(ci): keep glaeda's canonical root on fleet runners (manaflow-ai#17221)
467f490 fix(ci): read dogfood lookup JSON from files (manaflow-ai#17220)

# Conflicts:
#	.github/workflows/dogfood-artifact-publish.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merged-unverified A judging check was not green at merge; see the merge receipt comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant