Repository navigation
ci(gallery): diff each PR's touched gallery states against its merge-base - #18205
Conversation
An entry is touched by its own file, by anything its covers import, and by a changed stylesheet of its host's page. Gallery and build-config changes touch every entry. The per-PR gallery renders only these. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…base Renders entry x variant x theme at the merge-base and at the head (twice, so a state that differs from itself is reported as nondeterministic and never as a change), boxes the changed regions, and writes a diff page with highlight, slider and onion-skin views, a sticky comment with before/after thumbnails and a summary for the feed. The render job runs the PR's code without secrets; the publish job runs only the base branch's scripts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Passes: CI passes on CI passes on Written by |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 4 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit d7795dc. Configure here.
| # thumbs.txt names plain file names (report.ts SAFE_KEY); take only PNGs from the render. | ||
| src="$RUNNER_TEMP/render/diff/thumbs/$key" | ||
| if [ -f "$src" ] && [ "$(head -c 8 "$src" | od -An -tx1 | tr -d ' \n')" = "89504e470d0a1a0a" ]; then | ||
| cp "$src" "$upload/$prefix$key" |
There was a problem hiding this comment.
Thumbnail URLs miss sanitized filenames
High Severity
Comment thumbnail URLs use the raw outcome key, but pr-media.py always runs sanitize on the uploaded name and collapses -- to -. Manifest case ids join parts with --, so every uploaded PNG lands under a different name than the comment's img src and the sticky before/after images 404.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit d7795dc. Configure here.
| set -euo pipefail | ||
| sha=$(git merge-base "origin/$BASE_REF" HEAD) | ||
| echo "sha=$sha" >> "$GITHUB_OUTPUT" | ||
| git diff --name-only "$sha" HEAD > "$RUNNER_TEMP/changed.txt" |
There was a problem hiding this comment.
Checkout fetches every repository branch
Medium Severity
The render job checks out the head SHA with fetch-depth: 0 so git merge-base origin/$BASE_REF HEAD can run. On this repo that fetch pulls every branch (thousands) and has already been measured at several minutes, which competes with two gallery builds and three Playwright passes inside a 30-minute timeout.
Reviewed by Cursor Bugbot for commit d7795dc. Configure here.
| function highlight(o) { | ||
| const frame = el("div", {class: "frame"}, img(o.head, "head")); | ||
| for (const b of o.boxes) frame.append(el("div", {class: "box", style: "left:" + pct(b.x, o.width) + ";top:" + pct(b.y, o.height) + ";width:" + pct(b.w, o.width) + ";height:" + pct(b.h, o.height)})); | ||
| return frame; |
There was a problem hiding this comment.
Highlight overlay ignores screenshot size
Low Severity
Changed-region boxes live in max(base, head) coordinates (diff.width / diff.height), but the highlight view positions them as percentages of that max size over the head PNG. When the head shot is smaller than the base, the boxes do not line up with the pixels they describe.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit d7795dc. Configure here.
| /^webviews\/package\.json$/, | ||
| /^bun\.lock$/, | ||
| /^scripts\/gallery-matrix\//, | ||
| ]; |
There was a problem hiding this comment.
Webviews lockfile skips full re-render
Low Severity
EVERYTHING treats root bun.lock and webviews/package.json as gallery-wide, but the render job installs from webviews/ and uses webviews/bun.lock. A lockfile-only dependency bump there marks no entries, so the workflow runs and then skips the diff.
Reviewed by Cursor Bugbot for commit d7795dc. Configure here.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37569422881 at 552e7cb failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37569270312 at f60b3d7 failed: cmux-next checks (god files, concurrency, crash safety, l10n), cmux-next generated files. |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37569941713 at 46215de failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37569551101 at 5976099 failed: cmux-next checks (god files, concurrency, crash safety, l10n), cmux-next generated files. |
|
The feat-cmux-next push run https://github.com/manaflow-ai/cmux/actions/runs/37570246034 at e8a5696 failed: cmux-next checks (god files, concurrency, crash safety, l10n). |
…18336) * ci(gallery): publish on the trusted runner selector, not a bare GitHub-hosted label #18205 gave gallery-pr.yml's publish job `runs-on: ubuntu-24.04` with a `github-hosted-required` comment, which tests/test_ci_self_hosted_guard.sh no longer accepts as an exemption. The job runs trusted base-branch scripts with a write token, so it takes the CI_TRUSTED_RUNNER selector like the other trusted write jobs: an ephemeral Blacksmith VM by default. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * ci(cmux-next): run the companion workflows' guard tests in the checks job tests/test_ci_workflow_guards_are_wired.py fails on feat-cmux-next because no workflow runs three tests that read a workflow: - test_cmux_next_generated_catch_up.py (#17658) - test_cmux_next_regenerate_bundles_workflow.py (#18154) - test_next_batch.py (#17535) The checks job now runs them as one step, and its path filters include the tests and the workflows they guard. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>


Summary
Each PR that touches the webviews now gets a gallery diff: which gallery states it changes, shown against its merge-base. This is the first part of the per-PR gallery (cx-4oa.1): the base diff and the diff page.
Which entries.
webviews/scripts/gallery/touched.tspicks the entries a change reaches:*.gallery.ts;coversimport, followed through relative imports;Renders.
.github/workflows/gallery-pr.ymlrenders those entries x variants x both default themes x Chromium and WebKit withscripts/gallery-matrix/runner.ts, on Linux. It renders three times: once at the merge-base, using the base's own gallery code, and twice at the head.Comparison (
compare.ts). Each state ends up as one of:Report (
report.ts,pr.ts):summary.jsonholds the same summary for the team feed's PR card.Security. The render job runs the PR's code with a read-only token and no secrets. The publish job runs only the base branch's scripts:
outcomes.json;Same-repository PRs only.
Not in this PR:
gallery-prartifact, and the comment links to it.Testing
scripts/gallery-matrix/compare.test.tscovers:webviews/test/gallery-touched.test.tscovers:gallery PR diffrun executes the matrix tests, and that run's results will go in a comment.webviews/testruns incmux-next web bundles(signal only).Changelog
none
Proof
CI only. This PR's own run renders every entry, because it changes
webviews/scripts/gallery/. Its step summary will show the comment.Checklist
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Adds CI that renders and diffs gallery states on every PR to
feat-cmux-nextthat touches webviews. Each PR now gets a diff page and a sticky comment comparing the gallery states it changes against the merge-base.touched.tspicks the entries a change reaches: an entry's own*.gallery.ts, anything itscoversimports, every entry of a host whose stylesheet changed, and every entry when the gallery, build config, or lockfile changes.summary.jsonfeeds the PR card.outcomes.json; only plain-file PNG thumbnails reachpr-media, and only same-repository PRs are supported.Not in this PR: Freestyle VMs (CI has no Freestyle key), publishing the gallery and diff page to the gallery host (until then they live in the
gallery-prartifact, which the comment links to), feed card integration, and the play-step, filmstrip, and layout-shift numbers.Written for commit 09787bb. Summary will update on new commits.
Note
Medium Risk
New CI runs untrusted PR code in render (mitigated by read-only token and isolated publish), writes to pr-media and PR comments with contents-write, and pixel diffs can be noisy or miss logic-only changes.
Overview
Adds per-PR gallery visual regression on
feat-cmux-nextwhenwebviews/**(and related paths) change: CI picks affected entries, renders the matrix at merge-base vs head (plus a second head render for flake detection), pixel-compares screenshots, and posts a sticky PR comment with before/after thumbnails.Entry selection (
webviews/scripts/gallery/touched.ts): maps changed files to gallery entries via import closure from*.gallery.ts/covers, host-global stylesheets, or a full-matrix rerun when gallery/build/lockfile changes.Diff pipeline (
scripts/gallery-matrix/compare.ts,pr.ts,report.ts): classifies each state as changed (boxed regions + side-by-side thumbs), new, removed, broken mount, nondeterministic (head ≠ repeat head), or unchanged; emitsindex.html,comment.md,summary.json, and artifacts.Workflow split (
.github/workflows/gallery-pr.yml): render runs PR code read-only (Playwright on Linux); publish uses only base-branch scripts to rebuild the comment fromoutcomes.json, upload PNG thumbs topr-media, and update the bot comment (same-repo PRs only).Reviewed by Cursor Bugbot for commit 09787bb. Bugbot is set up for automated code reviews on this repo. Configure here.