Skip to content

ci: let CLA Assistant run on Blacksmith as well as GitHub-hosted - #18179

Merged
teamleaderleo merged 1 commit into
mainfrom
ci/cla-blacksmith-pr2
Oct 7, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
ci/cla-blacksmith-pr2

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Second of three changes letting the CLA checks run on Blacksmith (the first is #17453, merged as abe78bc141f5).

cla.yml now picks its runner with the same CI_TRUSTED_RUNNER selector backend-migrations uses. That selector allows only GitHub-hosted ubuntu-24.04 or the two Blacksmith Ubuntu labels, and defaults to blacksmith-4vcpu-ubuntu-2404. A new first step refuses any runner that is neither GitHub-hosted nor a Blacksmith VM, plus any glaeda host. These bytes hash to exactly the successor pin in validate-cla-policy.rb (317432cd… → 6ef80bb2…, re-pinned in #18186 for Blacksmith's current runner names).

If Blacksmith misbehaves, setting CI_TRUSTED_RUNNER=ubuntu-24.04 moves the check back to GitHub-hosted without a PR.

Tests: fork_runner_routing, self_hosted_guard, cla_guard_metadata_routing, job-scoped permissions and required-check path filters all pass, and actionlint is clean.

🤖 Generated with Claude Code


Note

Medium Risk
The job still runs with write permissions on fork pull requests; runner choice is broader but constrained by the new guard and existing policy validation.

Overview
CLA Assistant no longer hardcodes ubuntu-24.04. For manaflow-ai it uses the same CI_TRUSTED_RUNNER selector as backend-migrations: only GitHub-hosted ubuntu-24.04 or the two Blacksmith Ubuntu labels, defaulting to blacksmith-4vcpu-ubuntu-2404. Forks and other owners still get ubuntu-24.04.

A new first step fails the job if the runner is not GitHub-hosted or a Blacksmith VM (prefix checks on runner.name), or if the name contains glaeda, so ephemeral-only policy still holds when Blacksmith shows up as self-hosted. Comments note that validate-cla-policy.rb pins this workflow text.

Reviewed by Cursor Bugbot for commit e24be8c. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Updated automated contribution-agreement checks to use approved build environments. Checks now select supported environments based on repository settings and reject runs on environments that do not meet the approved criteria. These changes apply to repository maintenance workflows only and do not affect product features or functionality.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: dc25929f-fe6f-40c5-a148-cd15b541dba8
📥 Commits

Reviewing files that changed from the base of the PR and between 6fa0ea9 and cfacb36.

📒 Files selected for processing (1)
  • .github/workflows/cla.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The CLA Assistant workflow now selects a runner based on repository ownership and the CI_TRUSTED_RUNNER value. A preflight step checks the selected runner name and fails the job if it does not meet the allowed-name rules.

Changes

CLA workflow runner

Layer / File(s) Summary
Runner selection and validation
.github/workflows/cla.yml
Repositories outside manaflow-ai use ubuntu-24.04. Other repositories use an allowlisted CI_TRUSTED_RUNNER value or fall back to blacksmith-4vcpu-ubuntu-2404. The preflight step rejects runner names outside the approved GitHub-hosted or Blacksmith patterns and names containing glaeda.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to cfacb

The CLA workflow has no established outstanding issue from this change and is ready to merge after normal checks.

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed The check is not applicable to this pull request. The reviewed diff changes only .github/workflows/cla.yml, selecting and guarding CI runners. It does not change Cloud terminal creation or transport…
Cmux Swift Actor Isolation ✅ Passed The pull request changes only .github/workflows/cla.yml. The diff contains no production Swift changes, so it introduces no Swift actor-isolation issue covered by this check.
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only .github/workflows/cla.yml. It introduces no Swift changes and no blocking or timing-based synchronization covered by this check.
Cmux Browser Automation Off-Main ✅ Passed The check does not apply to this PR. The reviewed diff changes only .github/workflows/cla.yml; it does not change browser socket commands, worker routing, WebKit/AppKit access, or browser policy tes…
Cmux Expensive Synchronous Load ✅ Passed The PR changes only .github/workflows/cla.yml. The diff changes runner selection and adds a runner guard. It does not change production Swift code or any agent-history loading path covered by this c…
Cmux Cache Substitution Correctness ✅ Passed The pull request changes only .github/workflows/cla.yml. It introduces no production Swift, TypeScript, or JavaScript changes, so the cache-substitution check does not apply.
Cmux No Hacky Sleeps ✅ Passed The PR changes only .github/workflows/cla.yml. The custom rule explicitly excludes GitHub Actions workflow YAML from scope. The changed runner-selection expression and guard step therefore do not me…
Cmux Algorithmic Complexity ✅ Passed The PR changes only .github/workflows/cla.yml. Its runner selector checks a fixed three-label allowlist, and its shell guard only tests runner metadata and exits on a match. The diff adds no scalabl…
Cmux Swift Concurrency ✅ Passed The check does not apply to this diff. The changed-file inventory contains only .github/workflows/cla.yml; the patch changes runner selection and adds a runner guard. It introduces no cmux-owned Swi…
Cmux Swift @Concurrent ✅ Passed The pull request changes only .github/workflows/cla.yml. It contains no Swift changes, so the Swift @concurrent check does not apply.
Cmux Swift Package Boundaries ✅ Passed The pull request changes only .github/workflows/cla.yml. It introduces no production Swift changes, so the Swift package-boundary check does not apply.
Cmux Swiftpm Lockfiles ✅ Passed The pull request changes only .github/workflows/cla.yml. Its diff changes runner selection and adds a runner guard. It does not change a .gitignore, SwiftPM dependency pins, or Xcode project packa…
Cmux Swift Logging ✅ Passed The PR changes only .github/workflows/cla.yml. The diff contains no production Swift changes and adds no Swift logging covered by this check.
Cmux User-Facing Error Privacy ✅ Passed The diff changes only .github/workflows/cla.yml. Its runner selector and failure diagnostic belong to internal CI, and the error is a generic runner-policy message. The check allows provider and con…
Cmux Full Internationalization ✅ Passed The PR changes only .github/workflows/cla.yml. The diff updates runner selection and adds a runner guard; it adds no user-facing text, localized app or web content, or catalog entries. This is opera…
Cmux Swiftui State Layout ✅ Passed The pull request changes only .github/workflows/cla.yml. The diff contains runner selection and a runner guard, with no SwiftUI code or state-layout changes. The custom check is not applicable.
Cmux Architecture Rethink ✅ Passed The check is not applicable. The reviewed diff changes only .github/workflows/cla.yml and contains no Swift architecture changes.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull request changes only .github/workflows/cla.yml. The reviewed diff contains no Swift changes or standalone cmux-owned window code, so this check does not apply.
Cmux Source Artifacts ✅ Passed The only changed path is .github/workflows/cla.yml. The diff changes workflow runner configuration and adds a runner guard. This is intentional CI configuration, which the policy allows; the diff ad…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The PR changes only .github/workflows/cla.yml. The changed-file inventory contains no Swift files under production Sources/, so this check is not applicable.
Title check ✅ Passed The title clearly identifies the main change: allowing the CLA Assistant to run on Blacksmith and GitHub-hosted runners.
Description check ✅ Passed The description provides a detailed summary and reports testing results. It omits the Changelog, Proof, and Checklist sections required by the template; the Proof section should state that screenshots…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo marked this pull request as draft October 7, 2026 02:37
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Holding this one. The review found that the runner guard only admits Blacksmith names with -Runner-, and Blacksmith dropped that segment around 10-04 (current names look like blacksmith-4vcpu-ubuntu-2404-56ere4cqq7ryjqvc). Merging this as is would fail the CLA check on every PR. The validator gets fixed first, then these bytes get regenerated.

runs-on uses the CI_TRUSTED_RUNNER selector (GitHub-hosted ubuntu-24.04 or the two
Blacksmith Ubuntu labels, defaulting to Blacksmith), plus a first step that refuses
any runner that is neither GitHub-hosted nor a Blacksmith VM for those labels, or
that is one of our glaeda hosts. These are the exact successor bytes
validate-cla-policy.rb pins (#18186).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@teamleaderleo
teamleaderleo force-pushed the ci/cla-blacksmith-pr2 branch from cfacb36 to e24be8c Compare October 7, 2026 02:56
@teamleaderleo
teamleaderleo marked this pull request as ready for review October 7, 2026 02:57
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

merge-override: CLA policy guard fails only on the trusted exact-head review for this policy change; validator reproduces that as the sole reason, bytes match the reviewed pin, Leo OKed admin merge

@teamleaderleo
teamleaderleo merged commit c41b839 into main Oct 7, 2026
70 of 77 checks passed
@teamleaderleo
teamleaderleo deleted the ci/cla-blacksmith-pr2 branch October 7, 2026 03:04
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Merge receipt for e24be8cc07, merged 2026-10-07 03:04:01 UTC

  • Not verified at merge: CLA policy guard (failure)
  • Verified: backend migrations applied, ci-status, CI fast guards, CI timing, Fast static checks, GhosttyKit release check, guards (19), plan, tests, web-validation
  • Skipped by policy: apply-production, apply-staging, browser, Claude wrapper regressions, Dogfood build #​${{ github.event.pull_request.number }}, full-suite-coverage, linux-preflight, macos, macOS admission gate, remote-daemon, suite-coverage, ui-tests, and 4 more
  • Full suite: runs on main after merge.

teamleaderleo added a commit that referenced this pull request Oct 7, 2026
Same CI_TRUSTED_RUNNER selector and runner-identity guard as cla.yml (#18179), so
the required check survives a GitHub-hosted outage.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
teamleaderleo added a commit that referenced this pull request Oct 7, 2026
…18180)

Same CI_TRUSTED_RUNNER selector and runner-identity guard as cla.yml (#18179), so
the required check survives a GitHub-hosted outage.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant