Skip to content

ci: let CLA policy guard run on Blacksmith as well as GitHub-hosted - #18180

Merged
teamleaderleo merged 1 commit into
mainfrom
ci/cla-blacksmith-pr3
Oct 7, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
ci/cla-blacksmith-pr3

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Third of three changes letting the CLA checks run on Blacksmith. It follows #17453 (merged) and #18179 (cla.yml).

cla-policy-guard.yml gets the same CI_TRUSTED_RUNNER selector and the same runner check as cla.yml. That way the required "CLA policy guard" check also survives a GitHub-hosted outage. The validator does not allow guard and policy files to change in the same PR, so this PR is separate from the cla.yml one.

Tests: fork_runner_routing, self_hosted_guard, cla_guard_metadata_routing, job-scoped permissions and required-check path filters all pass, and actionlint is clean.

🤖 Generated with Claude Code


Note

Low Risk
CI-only change that mirrors an existing cla.yml pattern; runner selection stays on a short allowlist with an explicit runtime check, so the security model for this pull_request_target guard is unchanged in intent.

Overview
Aligns the CLA policy guard workflow with the same trusted-runner routing already used in cla.yml, so the required check can run on GitHub-hosted ubuntu-24.04 or approved Blacksmith Ubuntu VMs when CI_TRUSTED_RUNNER is set (defaulting to Blacksmith for manaflow-ai).

runs-on is no longer pinned to ubuntu-24.04; it uses the CI_TRUSTED_RUNNER allowlist with a safe fallback. The guard step now accepts GitHub-hosted or Blacksmith runners by name and still fails on disallowed environments (including runners whose name contains glaeda).

Reviewed by Cursor Bugbot for commit b89235c. Bugbot is set up for automated code reviews on this repo. Configure here.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Chores
    • Contribution-policy checks now use supported GitHub-hosted or approved Blacksmith runners. For the designated repository owner, unsupported runner settings fall back to an approved runner; other repositories use a standard hosted runner. Runner names containing glaeda are rejected. These changes affect validation workflows only and do not change application behavior or user-facing features.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7dfda569-9ee4-426b-a0e6-4246245bd665
📥 Commits

Reviewing files that changed from the base of the PR and between 8c69aea and b89235c.

📒 Files selected for processing (1)
  • .github/workflows/cla-policy-guard.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The CLA policy workflow selects a runner based on repository owner and configured runner labels. Its guard accepts GitHub-hosted runners and specified Blacksmith runners, and rejects runner names containing glaeda.

Changes

CLA policy runner selection

Layer / File(s) Summary
Runner selection and validation
.github/workflows/cla-policy-guard.yml
Non-manaflow-ai owners use ubuntu-24.04. For manaflow-ai, the workflow uses an allowed configured runner or falls back to the 4-vCPU Blacksmith runner. The guard permits GitHub-hosted runners and specified 2- or 4-vCPU Blacksmith runners, but rejects names containing glaeda.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to b8923

The CLA policy guard is configured to accept the allowed Blacksmith runners, so the reported runner-name concern does not appear to block the check. No actionable merge risk is apparent from the supplied change context.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description includes a useful summary and test results, but it claims the guard supports Blacksmith runners without disclosing the reported runner-name mismatch that can make the check fail. It al… Update the runner guard to accept current Blacksmith runner names, rerun the relevant checks, and revise the description to reflect verified behavior. Add a Changelog line (or “none”), a Proof note explaining why proof does not apply to thi…
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the primary change: allowing the CLA policy guard to run on approved Blacksmith runners as well as GitHub-hosted runners.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed The diff changes only .github/workflows/cla-policy-guard.yml to route and validate CI runners. It does not change Cloud terminal creation, transport, or input handling, so the custom check does not …
Cmux Swift Actor Isolation ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. It introduces no production Swift changes, so the Swift actor isolation check does not apply.
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. The diff contains runner selection and a runner guard, with no production Swift changes or blocking/timing-based Swift synchroni…
Cmux Browser Automation Off-Main ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. The custom check applies to browser socket automation routing and worker-lane code in Sources/TerminalController.swift and `Pa…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. It adds no production Swift changes, so it does not introduce an expensive synchronous agent-history load on a main-actor or int…
Cmux Cache Substitution Correctness ✅ Passed The diff changes only .github/workflows/cla-policy-guard.yml. It contains no production Swift, TypeScript, or JavaScript change, so the cache-substitution check does not apply.
Cmux No Hacky Sleeps ✅ Passed The only changed file is .github/workflows/cla-policy-guard.yml. The applicable rule explicitly excludes GitHub Actions workflow YAML, and the PR does not change a covered runtime script. The check …
Cmux Algorithmic Complexity ✅ Passed The diff changes only runner selection and runner-name validation in .github/workflows/cla-policy-guard.yml. Its contains(fromJSON(...)) check scans a fixed allowlist of three runner labels, and t…
Cmux Swift Concurrency ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. It does not change cmux-owned Swift code or introduce Swift concurrency patterns covered by this check.
Cmux Swift @Concurrent ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. The diff contains no Swift changes, so the @concurrent annotation check does not apply.
Cmux Swift Package Boundaries ✅ Passed The reviewed diff changes only .github/workflows/cla-policy-guard.yml. It adds runner selection and validation logic, with no production Swift changes. The Swift package-boundary check does not appl…
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only .github/workflows/cla-policy-guard.yml. Its changes update runner selection and validation. The diff does not change a cmux-owned package .gitignore, SwiftPM dependency pins, o…
Cmux Swift Logging ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. It adds no Swift changes or logging behavior, so the Swift logging check does not apply.
Cmux User-Facing Error Privacy ✅ Passed The diff changes only .github/workflows/cla-policy-guard.yml. It selects GitHub-hosted or Blacksmith CI runners and emits a runner-requirement error in a GitHub Actions step. These are internal CI c…
Cmux Full Internationalization ✅ Passed The diff changes only .github/workflows/cla-policy-guard.yml. It updates runner selection and a CI failure message. These are operational workflow changes, not user-facing Swift or localized web con…
Cmux Swiftui State Layout ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. The diff contains runner selection and runner validation changes, with no SwiftUI state or layout changes covered by this check.
Cmux Architecture Rethink ✅ Passed The custom check covers Swift architecture changes. The reviewed diff changes only .github/workflows/cla-policy-guard.yml, where it updates CI runner selection and a runner guard. It introduces no S…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml. It adds no Swift code and does not change any cmux-owned window, so the auxiliary-window close-shortcut check does not apply.
Cmux Source Artifacts ✅ Passed The PR changes only .github/workflows/cla-policy-guard.yml. The diff updates workflow runner configuration and guard logic. It adds no local output, generated artifacts, scratch directories, or othe…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The pull request changes only .github/workflows/cla-policy-guard.yml (9 additions and 7 deletions). It does not change any Swift file under a production Sources/ path, so the check does not apply.
Full details: Description check

Explanation

The description includes a useful summary and test results, but it claims the guard supports Blacksmith runners without disclosing the reported runner-name mismatch that can make the check fail. It also omits the required Changelog, Proof, and Checklist sections.

Resolution

Update the runner guard to accept current Blacksmith runner names, rerun the relevant checks, and revise the description to reflect verified behavior. Add a Changelog line (or “none”), a Proof note explaining why proof does not apply to this CI-only change, and the applicable Checklist information.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo marked this pull request as draft October 7, 2026 02:37
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Holding this one. The review found that the runner guard only admits Blacksmith names with -Runner-, and Blacksmith dropped that segment around 10-04 (current names look like blacksmith-4vcpu-ubuntu-2404-56ere4cqq7ryjqvc). Merging this as is would fail the CLA check on every PR. The validator gets fixed first, then these bytes get regenerated.

Same CI_TRUSTED_RUNNER selector and runner-identity guard as cla.yml (#18179), so
the required check survives a GitHub-hosted outage.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@teamleaderleo
teamleaderleo force-pushed the ci/cla-blacksmith-pr3 branch from 8c69aea to b89235c Compare October 7, 2026 03:04
@teamleaderleo
teamleaderleo marked this pull request as ready for review October 7, 2026 03:04
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

merge-override: CLA policy guard fails only on the trusted exact-head review for this guard change; validator reproduces that as the sole reason, bytes reviewed in 18186, Leo OKed admin merge

@teamleaderleo
teamleaderleo merged commit 3289039 into main Oct 7, 2026
67 of 71 checks passed
@teamleaderleo
teamleaderleo deleted the ci/cla-blacksmith-pr3 branch October 7, 2026 03:09
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Merge receipt for b89235cfbb, merged 2026-10-07 03:09:16 UTC

  • Not verified at merge: CLA policy guard (failure)
  • Verified: backend migrations applied, ci-status, CI fast guards, CI timing, Fast static checks, GhosttyKit release check, guards (19), plan, tests, web-validation
  • Skipped by policy: apply-production, apply-staging, browser, Claude wrapper regressions, Dogfood build #​${{ github.event.pull_request.number }}, full-suite-coverage, linux-preflight, macos, macOS admission gate, remote-daemon, suite-coverage, ui-tests, and 4 more
  • Full suite: runs on main after merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant