From 8aa341812ff0ccc64ad1b9fd194c7cd3ceca491d Mon Sep 17 00:00:00 2001 From: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com> Date: Tue, 6 Oct 2026 18:01:52 -0700 Subject: [PATCH 1/4] ci: refuse GitHub-hosted runner labels in workflows (failing guard) A GitHub billing block or hosted outage must never stop CI. Replace check_no_bare_github_hosted_runners, which let any job keep a GitHub-hosted label behind a '# github-hosted-required:' comment, with check_no_github_hosted_runners: no runner-selection position may name ubuntu-*, macos-* or windows-* outside the fork branch, the CI_TRUSTED_RUNNER selector's label list, and an exact exception list with reasons. It also checks that the manaflow-ai fleet in .github/runners.json is GitHub-hosted free. This commit fails on the 30 lines and the runners.json entry that the next commit moves. Co-Authored-By: Claude Opus 5.5 (1M context) --- tests/test_ci_self_hosted_guard.sh | 114 +++++++++++++++++++++++------ 1 file changed, 90 insertions(+), 24 deletions(-) diff --git a/tests/test_ci_self_hosted_guard.sh b/tests/test_ci_self_hosted_guard.sh index 972931a89198..bcda2576a94a 100755 --- a/tests/test_ci_self_hosted_guard.sh +++ b/tests/test_ci_self_hosted_guard.sh @@ -1172,31 +1172,97 @@ check_tmux_terminal_nightly_isolation() { echo "PASS: tmux corpus terminal-nightly uses isolated DerivedData, noninteractive xcodebuild, and expected-failure handling" } -check_no_bare_github_hosted_runners() { - # Every product CI job must route its runner through a repo variable (LINUX_RUNNER, - # MACOS_RUNNER_*) so the Blacksmith<->Warp / Blacksmith<->macos-26 overflow - # switch is a single repo-variable flip with no PR. A bare GitHub-hosted - # label (ubuntu-*, macos-NN) cannot be redirected, so it is forbidden. A - # GitHub-hosted macOS label may appear only as the MACOS_RUNNER_BACKGROUND - # fallback; check_background_macos_lane enforces that. - # The CLA policy guard is a separate immutable control-plane job and is - # intentionally exempted below: it may pin ubuntu-24.04 or use the - # CI_TRUSTED_RUNNER selector, never another runner variable or a - # self-hosted label (validate-cla-policy.rb and check_cla_guard_runner). - # Backend migrations and web complexity hold trusted tokens and use the - # CI_TRUSTED_RUNNER selector, which can only pick ephemeral GitHub-hosted or - # Blacksmith labels; test_ci_fork_runner_routing.py pins its exact form. - # Bare paid-provider labels (blacksmith-*, warp-*, depot-*) stay allowed for - # deliberate single-runner pins such as the testmanagerd-wedged - # `app-host-unit-tests` job. - local hits - hits="$(grep -rnE "runs-on:[[:space:]]*(ubuntu-[a-z0-9.]+|macos-[a-z0-9]+)([[:space:]]*$|[[:space:]]+#)" "$ROOT_DIR/.github/workflows" | grep -v "github-hosted-required" | grep -v "/cla-policy-guard.yml:" || true)" - if [[ -n "$hits" ]]; then - echo "FAIL: these jobs use a bare GitHub-hosted runner; route them through vars.LINUX_RUNNER / vars.MACOS_RUNNER_IOS so Blacksmith<->overflow stays a repo-variable flip:" - echo "$hits" +check_no_github_hosted_runners() { + # A GitHub billing block or a GitHub-hosted outage must never stop CI, so no + # job in manaflow-ai may select a GitHub-hosted runner (ubuntu-*, macos-*, + # windows-*). Jobs run on Blacksmith labels, the CI_TRUSTED_RUNNER selector + # (Blacksmith by default), or owned pools reached through the pickers. + # A `# github-hosted-required:` comment is no longer an exemption. + # Allowed GitHub-hosted forms: + # - the fork branch `github.repository_owner != 'manaflow-ai' && '