Skip to content

Add zig-ctap2 test execution to fork CI - #1947

Closed
Jesssullivan wants to merge 73 commits into
manaflow-ai:mainfrom
Jesssullivan:sid/sprint1-ci-tests
Closed

Jesssullivan wants to merge 73 commits into
manaflow-ai:mainfrom
Jesssullivan:sid/sprint1-ci-tests

Conversation

@Jesssullivan

@Jesssullivan Jesssullivan commented Mar 22, 2026 •

Copy link
Copy Markdown
Contributor

Disregard, accidental remote push.


Summary by cubic

Adds zig build test and zig build test-pbt for the vendor/ctap2 library to Fork CI so CTAP2 regressions fail fast before Xcode builds. Tests run after building libctap2.a and exposing ctap2.h, and before Debug/Release app builds on macOS-15.

  • New Features

    • Fork CI builds vendor/ctap2, runs unit and property tests, then builds cmux (Debug and Release).
    • Adds a Nix flake check job (flake.nix) to validate the dev shell and flake config.
    • Introduces a fork release workflow that signs, notarizes, and ships a macOS DMG for LAB builds.
  • Bug Fixes

    • Corrects codesign flow in nightly/release: deep-sign the app, re-sign embedded binaries with cmux.embedded.entitlements, then re-sign the app bundle to refresh the seal.

Written for commit 7ecb250. Summary will update on new commits.

Summary by CodeRabbit

Release Notes

  • New Features

    • Added support for passkey authentication using security keys via Bluetooth
  • Localization

    • Added Bluetooth permission descriptions in English and Japanese for security key communication
  • Chores

    • Updated code signing process with separate entitlements for enhanced security
    • Added fork-specific app icon branding
    • Improved build automation and release infrastructure
    • Version bump to 0.62.4

Jesssullivan and others added 30 commits March 20, 2026 00:06
Implement full WebAuthn support via JS bridge + AuthenticationServices,
enabling hardware security key (YubiKey) and passkey authentication
in the cmux browser for GSuite, GitHub, GitLab, etc.

- WebAuthnBridgeJavaScript: intercepts navigator.credentials.create/get,
  serializes ArrayBuffer↔base64url, constructs spec-compliant clientDataJSON
  and PublicKeyCredential response objects
- WebAuthnCoordinator: native bridge using ASAuthorizationController with
  both SecurityKey and Platform credential providers, state machine,
  origin validation, exhaustive error mapping
- Integrated into BrowserPanel.bindWebView and BrowserPopupWindowController
  so WebAuthn works in both main browser and popup OAuth flows
- Added com.apple.developer.web-browser.public-key-credential entitlement
- Created cmux.embedded.entitlements for CLI/helper (narrow, no passkey)
- Fixed codesign order in release/nightly/build scripts: sign app --deep
  first, then re-sign embedded binaries with narrow entitlements
- Added NSBluetoothAlwaysUsageDescription for cross-device passkey flows

Addresses #124, manaflow-ai#1278. Supersedes approach from manaflow-ai#1021, manaflow-ai#1823.
Fork-only infrastructure for lab testing of FIDO2/WebAuthn work.
Not intended for upstream.

- Trans flag gradient app icon (AppIcon-Fork) with "LAB" banner
  to visually distinguish fork builds from upstream cmux
- generate_fork_icon.py: recolors debug icon banner to trans gradient
  (light blue #5BCEFA → pink #F5A9B8 → white → pink → blue)
- fork-ci.yml: build validation for macOS .app, Linux daemon, nix flake
- fork-release.yml: multi-platform release workflow producing:
  - macOS DMG (.app bundle with LAB branding)
  - Linux cmuxd binaries (amd64, arm64)
  - DEB packages (Debian/Ubuntu)
  - RPM packages (RHEL/Fedora)
- flake.nix: Nix flake for darwin .app packaging and dev shell
Add fork CI, packaging, and trans-themed LAB branding
Add WebAuthn/FIDO2/YubiKey passthrough for browser panel
Fix fork CI: remove cmuxd refs, fix hashFiles glob
Fix fork CI: use macos-15 runner for SDK compatibility
Fix fork CI: native xcframework target, skip macOS app
Fix fork CI: symlink GhosttyKit.xcframework to repo root
Fix fork CI: debug xcframework path, fix cache key
Fix fork release: dynamic xcframework discovery + build diagnostics
The setup-zig action's cache causes zig to skip producing output
artifacts (zig-out/lib/GhosttyKit.xcframework) because it thinks
the build is up-to-date from cached intermediate objects. Disable
the zig cache and clean zig-out before building.
Fix fork CI: disable zig cache to ensure xcframework output
Fix fork CI: use universal xcframework target
Building GhosttyKit from source fails on GitHub-hosted runners due
to Xcode/libtool compatibility issues. Upstream builds it on custom
warp runners and publishes to manaflow-ai/ghostty releases. Download
the pre-built xcframework instead — much faster and reliable.
Fix fork CI: download pre-built GhosttyKit from upstream
Fix fork CI: cmux-LAB (no space) avoids xcodebuild bundle conflicts
The trans icon (AppIcon-Fork) is sufficient to differentiate fork
builds. Overriding PRODUCT_NAME causes 'Multiple commands produce'
errors because multiple Xcode targets produce the same .bundle.
Fix fork CI: don't override PRODUCT_NAME
.preferSignInWithApple and .deviceNotConfiguredForPasskeyCreation are
only available in newer SDKs (macOS 26+). Use @unknown default to
handle them portably.
Fix WebAuthn: remove SDK-version-dependent error cases
Fix fork CI: install zig for CLI helper build
Jesssullivan and others added 22 commits March 22, 2026 01:53
Wire zig-ctap2 for direct USB HID FIDO2 (no Apple entitlements needed)
Fix remaining nonisolated static methods
Fix libctap2: native arch build, add ARCHS=arm64 to xcodebuild
Update zig-ctap2: IOKit write fix + IOReturn diagnostic
IOHIDDeviceSetReport returns kIOReturnNotPermitted (0xe00002cd) under
hardened runtime without this entitlement. Required for direct CTAP2
communication with security keys over USB HID via IOKit.
Add USB device entitlement for FIDO2 HID
Run unit and property-based tests for the ctap2 library before
building cmux, so test failures surface early in CI.
@vercel

vercel Bot commented Mar 22, 2026

Copy link
Copy Markdown

@Jesssullivan is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Mar 22, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 210a8b48-c7f5-4f72-9c7b-3e677701a5ad

📥 Commits

Reviewing files that changed from the base of the PR and between 76c1e63 and 7ecb250.

⛔ Files ignored due to path filters (10)
  • Assets.xcassets/AppIcon-Fork.appiconset/128.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/128@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/16.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/16@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/256.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/256@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/32.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/32@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/512.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-Fork.appiconset/512@2x.png is excluded by !**/*.png
📒 Files selected for processing (23)
  • .github/workflows/fork-ci.yml
  • .github/workflows/fork-release.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • .gitmodules
  • Assets.xcassets/AppIcon-Fork.appiconset/Contents.json
  • GhosttyTabs.xcodeproj/project.pbxproj
  • Resources/Info.plist
  • Resources/InfoPlist.xcstrings
  • Sources/FIDO2/module.modulemap
  • Sources/Panels/BrowserPanel.swift
  • Sources/Panels/BrowserPopupWindowController.swift
  • Sources/Panels/WebAuthnBridgeJavaScript.swift
  • Sources/Panels/WebAuthnCoordinator.swift
  • cmux.embedded.entitlements
  • cmux.entitlements
  • ctap2.h
  • flake.nix
  • libctap2.a
  • scripts/build-sign-upload.sh
  • scripts/generate_fork_icon.py
  • scripts/reload.sh
  • vendor/ctap2

📝 Walkthrough

Walkthrough

Introduces WebAuthn/FIDO2 support for cmux by adding a JavaScript bridge and native WebAuthnCoordinator that intercepts web credential APIs, integrating with a CTAP2 C library via USB HID. Includes new fork-specific CI/release workflows, updated code signing with split entitlements, icon generation, and Nix flake configuration.

Changes

Cohort / File(s) Summary
GitHub Actions Workflows
.github/workflows/fork-ci.yml, .github/workflows/fork-release.yml, .github/workflows/nightly.yml, .github/workflows/release.yml
Added fork CI/release workflows for macOS builds with GhosttyKit xcframework downloads, Zig/Nix checks, signing/notarization, and DMG packaging. Updated nightly/release workflows to split entitlements: app bundle signed with full entitlements, embedded binaries with narrower cmux.embedded.entitlements.
WebAuthn/FIDO2 Implementation
Sources/Panels/WebAuthnBridgeJavaScript.swift, Sources/Panels/WebAuthnCoordinator.swift
New JavaScript bridge and native coordinator for WebAuthn ceremonies. JavaScript intercepts navigator.credentials.create/get, serializes requests, and handles native replies. Coordinator validates origin, performs CTAP2 make_credential/get_assertion operations on background queue, parses CBOR responses, and returns WebAuthn-shaped objects with error mapping.
Browser Integration
Sources/Panels/BrowserPanel.swift, Sources/Panels/BrowserPopupWindowController.swift
Integrated WebAuthnCoordinator lifecycle into web view binding. Changed user scripts to main-frame-only. Added coordinator creation and cleanup in popup window controller.
CTAP2 C API & Module Map
ctap2.h, Sources/FIDO2/module.modulemap
New public C header exposing CTAP2/FIDO2 functions (ctap2_make_credential, ctap2_get_assertion, etc.) and error codes for portable USB HID communication. Module map wires ctap2.h into Swift via SWIFT_INCLUDE_PATHS.
Code Signing & Entitlements
cmux.entitlements, cmux.embedded.entitlements, scripts/build-sign-upload.sh, scripts/reload.sh
Added USB device entitlement and application identifier to main entitlements. New embedded entitlements file for disable-library-validation and allow-unsigned-executable-memory. Updated signing scripts to apply embedded entitlements to CLI/helper binaries after deep-signing app bundle.
Project Configuration
GhosttyTabs.xcodeproj/project.pbxproj, .gitmodules, Resources/Info.plist, Resources/InfoPlist.xcstrings, Sources/FIDO2/module.modulemap
Bumped project version to 0.62.4, linked libctap2.a, added ctap2.h header, and added Swift sources. Added vendor/ctap2 submodule. Added Bluetooth usage privacy descriptions in plist and localized strings.
Fork Icon & Assets
Assets.xcassets/AppIcon-Fork.appiconset/Contents.json, scripts/generate_fork_icon.py
New fork icon asset catalog with multi-size/multi-scale PNG entries. Generation script transforms debug icon banner from orange "DEV" to trans-flag gradient with "LAB" text overlay.
Development & Packaging
flake.nix
New Nix flake providing macOS .app and Linux RPM packages, dev shell with Zig/Python, and build instructions.

Sequence Diagrams

sequenceDiagram
    participant JS as JavaScript<br/>(Web Page)
    participant Bridge as WebAuthn Bridge<br/>(JavaScript)
    participant Coordinator as WebAuthnCoordinator<br/>(`@MainActor`)
    participant CTAP2 as CTAP2 Library<br/>(C via Zig)
    participant HID as USB HID<br/>(Security Key)

    JS->>Bridge: navigator.credentials.create(options)
    activate Bridge
    Bridge->>Bridge: Validate & serialize options
    Bridge->>Coordinator: postMessage({type: "create", options, origin})
    deactivate Bridge
    
    activate Coordinator
    Coordinator->>Coordinator: Validate origin against webView URL
    Coordinator->>Coordinator: Parse challenge, rp, user, pubKeyCredParams
    Coordinator->>Coordinator: Generate clientDataJSON & SHA-256 hash
    Coordinator->>CTAP2: ctap2_make_credential(client_data_hash, ..., allow_list, result_buf)
    deactivate Coordinator
    
    activate CTAP2
    CTAP2->>HID: Send CTAP2 request (USB HID)
    activate HID
    HID->>HID: User performs authentication gesture
    HID-->>CTAP2: Return credential response
    deactivate HID
    CTAP2->>CTAP2: Parse CBOR response, extract credentialID, attestationObject
    CTAP2-->>Coordinator: credentialID, attestationObject (raw bytes)
    deactivate CTAP2
    
    activate Coordinator
    Coordinator->>Coordinator: Decode CBOR, base64url-encode fields
    Coordinator-->>Bridge: {credentialID, attestationObject, type, transports}
    deactivate Coordinator
    
    Bridge->>Bridge: Transform to PublicKeyCredential
    Bridge-->>JS: Resolve promise with credential
Loading
sequenceDiagram
    participant JS as JavaScript<br/>(Web Page)
    participant Bridge as WebAuthn Bridge<br/>(JavaScript)
    participant Coordinator as WebAuthnCoordinator<br/>(`@MainActor`)
    participant CTAP2 as CTAP2 Library<br/>(C via Zig)
    participant HID as USB HID<br/>(Security Key)

    JS->>Bridge: navigator.credentials.get({publicKey: options})
    activate Bridge
    Bridge->>Bridge: Serialize challenge, rpId, allowCredentials
    Bridge->>Coordinator: postMessage({type: "get", options, origin})
    deactivate Bridge
    
    activate Coordinator
    Coordinator->>Coordinator: Validate origin
    Coordinator->>Coordinator: Parse challenge, rpId, allowCredentials array
    Coordinator->>Coordinator: Generate clientDataJSON & SHA-256 hash
    Coordinator->>CTAP2: ctap2_get_assertion(client_data_hash, rp_id, allow_list, result_buf)
    deactivate Coordinator
    
    activate CTAP2
    CTAP2->>HID: Send CTAP2 get_assertion request (USB HID)
    activate HID
    HID->>HID: User performs verification gesture
    HID-->>CTAP2: Return assertion response
    deactivate HID
    CTAP2->>CTAP2: Parse CBOR response, extract credentialID, authenticatorData, signature
    CTAP2-->>Coordinator: credentialID, authenticatorData, signature (raw bytes)
    deactivate CTAP2
    
    activate Coordinator
    Coordinator->>Coordinator: Decode CBOR, base64url-encode fields
    Coordinator-->>Bridge: {credentialID, authenticatorData, signature, type}
    deactivate Coordinator
    
    Bridge->>Bridge: Transform to PublicKeyCredential
    Bridge-->>JS: Resolve promise with credential
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

Suggested labels

aardvark, codex


🐰 A bridge to the keys,
JavaScript shakes CTAP's hand,
Security blooms forth.

Important

Merge conflicts detected (Beta)

  • Resolve merge conflict in branch sid/sprint1-ci-tests
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Tip

You can disable poems in the walkthrough.

Disable the reviews.poem setting to disable the poems in the walkthrough.

@Jesssullivan
Jesssullivan deleted the sid/sprint1-ci-tests branch March 22, 2026 19:48
@greptile-apps

greptile-apps Bot commented Mar 22, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds FIDO2/WebAuthn hardware security key support to cmux, wiring a new WebAuthnCoordinator + WebAuthnBridgeJavaScript stack into the existing BrowserPanel and popup flows, backed by a vendored zig-ctap2 submodule compiled to libctap2.a. It also introduces a fork-specific CI workflow, a signed LAB release workflow, a Nix flake, and corrects the codesign ordering in all signing scripts — but the nightly.yml and release.yml codesign fixes are incomplete.

Key findings:

  • ctap2.h (P0 syntax): ctap2_debug_last_ioreturn is declared after both #endif // CTAP2_H and the extern "C" closing brace. The symbol will not have C linkage in C++/Swift, causing a linker failure when libctap2.a is consumed by the Swift module.
  • nightly.yml / release.yml (P1 logic): The corrected three-step codesign pattern is only fully implemented in fork-release.yml and build-sign-upload.sh. Both nightly.yml (line 384) and release.yml (line 250) are missing the final top-level bundle re-sign (without --deep) that refreshes the resource seal after re-signing the embedded binaries — causing --verify --deep --strict and notarization to fail for production builds.
  • flake.nix (P2 style): Dev shell pins zig_0_14 while CI installs 0.15.2, so zig build test behaviour may diverge between local and CI environments.
  • cmux.entitlements (P2 style): Hard-coded team ID QP994XQKNH will break signing for any contributor not on that Apple Developer team.

Confidence Score: 2/5

  • Not safe to merge — two production workflows (nightly, release) have a broken codesign seal that will fail verification, and the ctap2.h header has a linkage bug that will cause a build error.
  • The P0 ctap2.h issue will produce a linker failure in any C++ or Swift consumer. The P1 codesign omission in nightly.yml and release.yml means every nightly and production release build will fail the --verify --deep --strict check and notarization. These are not latent or theoretical — they are on the critical path of every build triggered by this PR.
  • ctap2.h (extern "C" / include guard placement), .github/workflows/nightly.yml and .github/workflows/release.yml (missing top-level bundle re-sign step).

Important Files Changed

Filename Overview
.github/workflows/fork-ci.yml New CI workflow: checks out submodules, builds libctap2 via Zig, runs unit and property-based tests, then builds cmux Debug and Release with the fork icon; also adds a Nix flake check job.
.github/workflows/fork-release.yml New release workflow for LAB builds: builds, signs, notarizes, and packages a DMG; correctly implements the three-step codesign pattern (deep-sign → re-sign embedded → re-sign top-level to refresh seal).
.github/workflows/nightly.yml Codesign order corrected (deep-sign first, then embedded binaries with narrower entitlements), but the final top-level bundle re-sign to refresh the resource seal is missing — the --verify --deep --strict check will fail.
.github/workflows/release.yml Same codesign fix as nightly.yml but also missing the top-level bundle re-sign step; --verify --deep --strict and notarization will fail for production releases.
ctap2.h C header for libctap2; ctap2_debug_last_ioreturn is declared after both the #endif include guard and the extern "C" block, causing double-declaration on multiple includes and missing C linkage in C++/Swift.
Sources/Panels/WebAuthnCoordinator.swift New @mainactor class coordinating WebAuthn/FIDO2 ceremonies; calls libctap2 on a background queue, parses CBOR responses, and validates origin; custom CBOR parser is minimal but sufficient for CTAP2 top-level maps.
Sources/Panels/WebAuthnBridgeJavaScript.swift JavaScript bridge injected at document start; overrides navigator.credentials.create/get to route through WKScriptMessageHandlerWithReply; includes clientDataJSON construction, base64url helpers, and response serialization.
cmux.embedded.entitlements New narrower entitlements file for embedded CLI/helper binaries; grants only library-validation bypass and unsigned executable memory, preventing embedded tools from inheriting the full app entitlements set.
cmux.entitlements Adds USB device access and a hard-coded team-scoped application identifier (QP994XQKNH.com.cmuxterm.app.lab); the team ID will conflict with any signing identity that doesn't match this specific team.
flake.nix New Nix flake with Darwin and Linux package derivations and a dev shell; dev shell uses zig_0_14 while CI installs Zig 0.15.2, creating a version mismatch for local test runs.
scripts/build-sign-upload.sh Correctly implements all three codesign steps: deep-sign app, re-sign embedded binaries with narrower entitlements, re-sign top-level bundle to refresh seal.

Sequence Diagram

sequenceDiagram
    participant Page as Web Page (JS)
    participant Bridge as WebAuthnBridgeJavaScript
    participant Coord as WebAuthnCoordinator (Swift)
    participant CTAP2 as libctap2 (C / USB HID)
    participant Key as FIDO2 Security Key

    Page->>Bridge: navigator.credentials.create(options)
    Bridge->>Bridge: serializeCreateOptions(publicKey)
    Bridge->>Coord: postMessage {type:"create", options, origin}
    Coord->>Coord: validateOrigin(origin)
    Coord->>Coord: buildClientDataJSON → SHA-256 hash
    Coord->>CTAP2: ctap2_make_credential(...) [ctap2Queue]
    CTAP2->>Key: CTAP2 MakeCredential over USB HID
    Key-->>CTAP2: CBOR attestation response
    CTAP2-->>Coord: raw bytes (status + CBOR)
    Coord->>Coord: parseCBORMap → extract credentialID, attestationObject
    Coord-->>Bridge: {credentialID, attestationObject, transports}
    Bridge->>Bridge: buildRegistrationResponse(nativeResult, challenge, origin)
    Bridge-->>Page: PublicKeyCredential object

    Page->>Bridge: navigator.credentials.get(options)
    Bridge->>Bridge: serializeGetOptions(publicKey)
    Bridge->>Coord: postMessage {type:"get", options, origin}
    Coord->>Coord: validateOrigin(origin)
    Coord->>Coord: buildClientDataJSON → SHA-256 hash
    Coord->>CTAP2: ctap2_get_assertion(...) [ctap2Queue]
    CTAP2->>Key: CTAP2 GetAssertion over USB HID
    Key-->>CTAP2: CBOR assertion response
    CTAP2-->>Coord: raw bytes (status + CBOR)
    Coord->>Coord: parseCBORMap → credentialID, authData, signature
    Coord-->>Bridge: {credentialID, authenticatorData, signature, userHandle}
    Bridge->>Bridge: buildAssertionResponse(nativeResult, challenge, origin)
    Bridge-->>Page: PublicKeyCredential object
Loading

Reviews (1): Last reviewed commit: "Add zig-ctap2 test execution to fork CI" | Re-trigger Greptile

Comment thread ctap2.h
Comment thread .github/workflows/nightly.yml
Comment thread .github/workflows/release.yml
Comment thread flake.nix
Comment thread cmux.entitlements

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

14 issues found across 33 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="Sources/Panels/BrowserPanel.swift">

<violation number="1" location="Sources/Panels/BrowserPanel.swift:2472">
P2: Main-frame-only injection disables iframe focus tracking, so address-bar focus restore will not work for inputs inside iframes that previously relayed state via postMessage.</violation>
</file>

<file name="cmux.entitlements">

<violation number="1" location="cmux.entitlements:20">
P1: Hardcoded `com.apple.application-identifier` uses a bundle/team string that does not match project bundle identifiers, creating a real signing/entitlement mismatch risk.</violation>
</file>

<file name="ctap2.h">

<violation number="1" location="ctap2.h:82">
P2: `ctap2_debug_last_ioreturn` is declared outside both the include guard and `extern "C"`, creating inconsistent header behavior and potential C++ linkage/name-mangling mismatch.</violation>
</file>

<file name="Sources/Panels/WebAuthnBridgeJavaScript.swift">

<violation number="1" location="Sources/Panels/WebAuthnBridgeJavaScript.swift:285">
P2: Platform authenticator availability is hardcoded to true, causing inaccurate feature detection and potentially incorrect RP authentication flows.</violation>
</file>

<file name=".github/workflows/nightly.yml">

<violation number="1" location=".github/workflows/nightly.yml:377">
P1: App bundle is deep-signed before embedded binaries are re-signed, but there is no final top-level re-sign; this can invalidate the outer app signature/seal.</violation>
</file>

<file name="Sources/Panels/WebAuthnCoordinator.swift">

<violation number="1" location="Sources/Panels/WebAuthnCoordinator.swift:163">
P2: Cancellation does not stop in-flight CTAP2 work. The async completion always replies and resets state without verifying that the operation is still current, so a canceled ceremony can later reply again and force state back to idle even if a new operation is running.</violation>
</file>

<file name=".github/workflows/fork-release.yml">

<violation number="1" location=".github/workflows/fork-release.yml:22">
P1: Manual dispatch accepts a release tag input but checkout is not pinned to it, so artifacts may be built from the wrong commit.</violation>

<violation number="2" location=".github/workflows/fork-release.yml:167">
P1: Manual dispatch `tag` input is effectively ignored by preferring `GITHUB_REF_NAME`, which can publish/update the wrong release tag.</violation>
</file>

<file name=".github/workflows/fork-ci.yml">

<violation number="1" location=".github/workflows/fork-ci.yml:41">
P1: Workflow consumes a downloaded prebuilt binary artifact without integrity verification before extraction and use.</violation>

<violation number="2" location=".github/workflows/fork-ci.yml:84">
P2: Third-party GitHub Action is referenced with a mutable ref (@main/@v2) instead of an immutable commit SHA, which allows supply‑chain drift in CI.</violation>
</file>

<file name="flake.nix">

<violation number="1" location="flake.nix:30">
P2: cmux-darwin assumes a prebuilt .app inside build/ (ignored by .gitignore) and exits 1 when missing, which makes flake/Nix builds non-reproducible and likely to fail in CI because the source snapshot won’t include those artifacts.</violation>

<violation number="2" location="flake.nix:59">
P2: `cmux-rpm` does not include Zig as a build input, so `cmuxd` is usually not built and the install phase silently skips it, producing a package without the daemon.</violation>
</file>

<file name="scripts/generate_fork_icon.py">

<violation number="1" location="scripts/generate_fork_icon.py:113">
P2: Text segmentation uses a near-white threshold after introducing a white gradient stripe, so non-text pixels are treated as text and LAB replacement bounds/font sizing can be wrong.</violation>

<violation number="2" location="scripts/generate_fork_icon.py:174">
P2: Missing source icons are silently skipped but Contents.json still lists all filenames, which can leave the appiconset referencing files that were never generated and cause asset catalog validation errors.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread cmux.entitlements
Comment thread .github/workflows/nightly.yml
Comment thread .github/workflows/fork-release.yml
Comment thread .github/workflows/fork-release.yml
Comment thread .github/workflows/fork-ci.yml
Comment thread .github/workflows/fork-ci.yml
Comment thread flake.nix
Comment thread flake.nix
Comment thread scripts/generate_fork_icon.py
Comment thread scripts/generate_fork_icon.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant