Skip to content

Add release candidate app channel - #4512

Closed
lawrencecchen wants to merge 18 commits into
mainfrom
task-release-candidate-channel
Closed

lawrencecchen wants to merge 18 commits into
mainfrom
task-release-candidate-channel

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented May 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds a manual release candidate workflow that builds a side-by-side cmux RC.app and stable candidate assets from the same unsigned app payload.
  • Adds a promotion workflow that publishes the already-built stable candidate assets without rebuilding.
  • Adds RC bundle entitlements, RC app icon assets, and artifact-level metadata verification for stable, nightly, and RC bundles.

Release setup needed

Add APPLE_RC_PROVISIONING_PROFILE_BASE64 before running the RC workflow. It must be a Developer ID all-devices profile for 7WLXT3NR37.com.cmuxterm.app.rc with the WebAuthn browser entitlement.

Testing

  • tests/test_verify_app_bundle_channel_metadata.sh
  • scripts/compile-app-icon-icns.sh Assets.xcassets/AppIcon-RC.appiconset /tmp/cmux-rc-icon-test.icns
  • shellcheck scripts/compile-app-icon-icns.sh tests/test_verify_app_bundle_channel_metadata.sh
  • node scripts/release_asset_guard.test.js
  • plutil -lint cmux.rc.entitlements
  • python3 -m json.tool Assets.xcassets/AppIcon-RC.appiconset/Contents.json >/dev/null
  • actionlint on the new workflows and CI workflow
  • Release build with ASSETCATALOG_COMPILER_APPICON_NAME=AppIcon-RC succeeded

Note

Medium Risk
Adds new release automation and a new cmux-rc app channel (URL scheme/bundle ID/socket paths) which affects packaging, update feeds, and deep-link routing; mistakes could break release publishing or RC/stable coexistence.

Overview
Introduces a release-candidate (RC) distribution channel for the macOS app, including new release-candidate.yml (build/sign/notarize cmux RC.app, generate RC + stable appcasts, publish RC prerelease assets, upload RC appcast) and promote-release-candidate.yml (promote prebuilt stable-candidate-* assets to the stable tag without rebuilding, with guards against overwriting immutable assets).

Extends the app/CLI ecosystem to recognize cmux-rc alongside stable/nightly/dev: adds RC bundle ID, URL scheme allowlists (auth + SSH + web after-sign-in), RC socket variant/marker files and theme-reload targeting, plus tests covering RC socket autodiscovery and bundle metadata verification.

Remote daemon release manifests now optionally embed signerWorkflow (plumbed through build_remote_daemon_release_assets.sh and workflows) and the CLI uses it (with tag-based fallback) when printing gh attestation verify instructions; CI additionally runs a new test_verify_app_bundle_channel_metadata.sh check.

Reviewed by Cursor Bugbot for commit b1cc8c8. Bugbot is set up for automated code reviews on this repo. Configure here.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.


Summary by cubic

Adds a macOS release-candidate channel that builds/signs/notarizes a side-by-side cmux RC.app, publishes an RC appcast to R2 only when latest, and promotes the same built bits to stable without rebuilding. Also records the remote-daemon attestation signer workflow in manifests and verifies attestations against it.

  • New Features

    • release-candidate.yml: builds/signs/notarizes stable + cmux RC.app, generates Sparkle appcasts, uploads dSYMs, attests remote-daemon assets, supports publish=false dry runs, verifies/creates the RC tag at the candidate SHA, guards immutable assets (skip when complete; fail on partial), reuses the release appcast on retries, and uploads the RC appcast to R2 only when the RC is latest.
    • promote-release-candidate.yml: promotes stable-candidate-* assets to the stable tag without rebuilding; verifies the tag points to the candidate SHA, enforces immutable-asset guards (skip when complete; fail on partial/mismatch), validates the appcast references the stable tag, uploads the stable appcast to R2 only when latest, optionally triggers Homebrew, and reuses the release appcast for idempotent retries.
    • Remote daemon signer workflow: manifests now include signerWorkflow; release.yml/nightly.yml pass --signer-workflow; CLI prefers manifest.signerWorkflow for gh attestation verify and falls back to a tag-based workflow when absent.
    • Runtime identity: cmux-rc URL scheme, com.cmuxterm.app.rc bundle ID, default socket /tmp/cmux-rc.sock (+ slug variants/marker files); CLI prefers the channel default socket over stale markers and routes theme reloads to the RC bundle; Python client recognizes RC bundle IDs/markers/sockets; auth and SSH parsing accept cmux-rc://; web after-sign-in supports cmux-rc://.
    • RC assets/tooling/CI: cmux.rc.entitlements, Assets.xcassets/AppIcon-RC.appiconset, icon helpers (compile-app-icon-icns.sh, generate_rc_icon.py); CI validates bundle-channel metadata for stable/nightly/rc and strengthens socket autodiscovery tests to cover RC and default-over-stale precedence; release.yml ignores v*-rc.* tags and fails fast if invoked on an RC tag.
  • Migration

    • Set APPLE_RC_PROVISIONING_PROFILE_BASE64 (Developer ID all-devices for 7WLXT3NR37.com.cmuxterm.app.rc with the WebAuthn browser entitlement) before running release-candidate.yml.

Written for commit b1cc8c8. Summary will update on new commits. Review in cubic

Summary by CodeRabbit

  • New Features

    • Release-candidate (RC) promotion and RC release-candidate build workflows to publish RCs as stable releases.
    • Broad RC channel support across app, CLI, auth callbacks, deep-link scheme, socket discovery, and theme/override behavior.
    • RC-branded app icon generation and packaging support.
  • Chores

    • CI now validates app-bundle channel metadata during release builds.
    • Added scripts to generate and compile RC app icons.
  • Tests

    • New/updated tests for bundle channel metadata, RC socket variants, CLI autodiscovery, and related behaviors.

Review Change Stack

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@vercel

vercel Bot commented May 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment May 23, 2026 1:30am
cmux-staging Building Building Preview, Comment May 23, 2026 1:30am

@coderabbitai

coderabbitai Bot commented May 22, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds RC channel support across CI/workflows, app icon tooling, entitlements, channel metadata verification and tests, socket-variant/runtime changes, auth deep-link scheme, and promotion automation to publish RC artifacts as stable releases.

Changes

RC Build and Release Infrastructure

Layer / File(s) Summary
RC Channel Metadata Verification
scripts/verify-app-bundle-channel-metadata.sh, tests/test_verify_app_bundle_channel_metadata.sh, .github/workflows/ci.yml
verify-app-bundle-channel-metadata.sh accepts rc; added test creating temporary stable/nightly/rc app bundles; CI release-build runs the verifier.
RC App Icon, Tools & Entitlements
scripts/generate_rc_icon.py, scripts/compile-app-icon-icns.sh, Assets.xcassets/AppIcon-RC.appiconset/Contents.json, cmux.rc.entitlements
Added generate_rc_icon.py to recolor icons and overlay an “RC” banner, compile-app-icon-icns.sh to produce .icns, new AppIcon-RC asset catalog Contents.json, and cmux.rc.entitlements.
Release Candidate Build Workflow
.github/workflows/release-candidate.yml
New manual workflow that validates inputs/tags, guards RC tag reuse and immutable assets, builds universal app(s), prepares stable and RC bundles (metadata injection, icons), builds remote-daemon artifacts, runs regression tests, imports signing materials, embeds/validates provisioning profiles, codesigns and notarizes apps/DMGs, generates appcasts, prepares stable-candidate assets, attests artifacts, uploads artifacts, publishes RC prerelease, uploads RC appcast to R2 when appropriate, and cleans up.
Release Promotion Workflow
.github/workflows/promote-release-candidate.yml
New promotion workflow that validates rc_tag, derives stable tag/version, guards against partial immutable assets on existing stable releases, downloads stable-candidate-* artifacts from the RC release and renames/uploads them to stable release (or creates it), uploads appcast.xml to R2 when appropriate, and triggers Homebrew automation.
Socket Variant Handling & Tests
CLI/CLISocketPathResolver.swift, Packages/CMUXSocketPathDomain/.../SocketPathMarkerFiles.swift, tests/*, tests/test_cli_socket_autodiscovery.py
Adds .rc(slug:...) variant, rc default socket paths and marker files, resolver changes to include rc in candidate/fallback/tagged discovery, Python tests verifying RC marker/default selection and cleanup.
Auth callback & deep-link allowlist
Sources/Auth/*, web/app/handler/after-sign-in/page.tsx
Allow cmux-rc scheme in auth callback router, detect RC bundle prefixes for debug callback selection, and include cmux-rc:// in native deep-link allowlist.
Minor visibility and regression tests
Sources/CmuxApplicationSupportDirectories.swift, Sources/CmuxSSHURLRequest.swift, cmuxTests/*, CLI/CMUXCLI+ThemeSupport.swift
Make releaseFallbackChannelSuffixes private, minor whitespace change in supported schemes, expand SSH URLRequest test to cover cmux-rc, and add theme-support regression test asserting RC reload target bundle id.

Sequence Diagram

sequenceDiagram
  participant User
  participant RCWf as "RC Build Workflow"
  participant GH as "GitHub API/Actions"
  participant Xcode as "Xcode Build"
  participant Sign as "Signing/Notary"
  participant R2 as "Cloudflare R2"
  participant PromWf as "Promotion Workflow"

  User->>RCWf: Trigger with version, rc_number, commit
  RCWf->>RCWf: validate inputs, resolve tags
  RCWf->>GH: fetch RC tag, guard existing RC assets
  RCWf->>Xcode: build universal app, verify architectures
  RCWf->>Sign: import certs, embed profiles, codesign, notarize
  RCWf->>GH: publish RC prerelease with artifacts
  RCWf->>R2: upload RC appcast.xml (when latest)
  User->>PromWf: promote RC tag to stable
  PromWf->>GH: guard existing stable release assets
  PromWf->>GH: download stable-candidate assets from RC, rename and upload
  PromWf->>R2: upload stable appcast.xml (when applicable)
  PromWf->>GH: trigger Homebrew update
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~75 minutes

Possibly related PRs

  • manaflow-ai/cmux#4353: Introduced the app-bundle channel metadata verifier and CI wiring; this PR broadens the verifier to rc and adds tests/CI usage.
  • manaflow-ai/cmux#4484: Related changes to theme-reload socket→bundle-id mapping and tests; this PR adds RC handling for the same area.
  • manaflow-ai/cmux#3543: Adds variant-aware socket autodiscovery foundations that this PR extends with .rc variant support.

Poem

🐇 I nibble icons, paint a teal RC sash,
I hop through CI and tags in a flash,
From candidate builds to stable’s bright crown,
The rabbit hops, signs, and pins the crown. 🥕

🚥 Pre-merge checks | ✅ 16 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (16 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Add release candidate app channel' clearly and specifically summarizes the main change—introducing a new RC channel for the macOS app with corresponding workflows, identity, and routing.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed All Swift changes are enums with pure logic/immutable constants or properly-isolated Sendable struct. No MainActor models, mutable Sendable types, or actor isolation violations.
Cmux Swift Blocking Runtime ✅ Passed No blocking/timing primitives (DispatchSemaphore, .wait(), Task.sleep, asyncAfter, DispatchQueue.main.sync, NSLock) found in production Swift files modified by this RC feature PR.
Cmux No Hacky Sleeps ✅ Passed No production code sleeps found. Sleeps in tests/cmux.py are allowed test-only scaffolding per rule's exceptions.
Cmux Swift Concurrency ✅ Passed No legacy async patterns found in 10 modified Swift files. Changes use modern concurrency without DispatchQueue global, Combine, completion-handlers, or fire-and-forget Tasks.
Cmux Swift @Concurrent ✅ Passed No async functions or @concurrent/@MainActor/@nonisolated annotations were introduced or modified. Changes consist of constants, enum cases, switch branches, and test methods—all synchronous code.
Cmux Swift File And Package Boundaries ✅ Passed All Swift changes add only small RC extensions to existing files. Largest: +26 lines to SocketPathMarkerFiles. No files oversized, no mixed responsibilities, no boundary violations.
Cmux Swift Logging ✅ Passed No Swift logging violations found. Production code changes add RC channel support without introducing print/debugPrint/dump/NSLog, file logging, or secrets exposure.
Cmux User-Facing Error Privacy ✅ Passed No user-facing errors added. Changes are RC URL routing, CI workflows (operational), and tests. Policy allows operational runbooks/tests. No vendor names or credentials exposed.
Cmux Full Internationalization ✅ Passed PR adds RC app variant through routing/protocol changes (bundle IDs, schemes, socket paths, tests, workflows) with no user-facing text, string catalogs, or localization-requiring changes.
Cmux Swiftui State Layout ✅ Passed No SwiftUI state layout violations found. All changed Swift files are Foundation-based utilities, domain models, and tests with no SwiftUI imports, View types, or state management patterns.
Cmux Architecture Rethink ✅ Passed Swift changes add RC channel by symmetrically extending nightly/staging patterns with no timing repairs, mutable state, observers, or duplicate entrypoint wiring.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains only RC channel configuration and routing code changes. No NSWindow, NSPanel, NSWindowController, Window, or WindowGroup declarations found in modified Swift files.
Description check ✅ Passed The PR description follows the template structure with Summary, Testing, and Checklist sections; all required sections are present and substantively filled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch task-release-candidate-channel

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/promote-release-candidate.yml:
- Around line 172-175: The "Upload stable appcast to R2" job step currently sets
continue-on-error: true which allows the workflow to proceed even if the stable
appcast upload fails; remove the continue-on-error: true setting (or set it to
false) in the step named "Upload stable appcast to R2" so that any failure in
the upload will fail the workflow and prevent a stable release from publishing
without a successful stable feed upload; optionally add a retry mechanism or
explicit error handling around the upload command if transient failures are a
concern.
- Around line 28-33: The run step is unsafe because it expands ${{ inputs.rc_tag
}} directly into the shell and the appcast upload step is allowed to fail; to
fix, move the input into an environment variable (declare env: RC_TAG: ${{
inputs.rc_tag }} on the job or step and then use RC_TAG inside the script) so
the raw input is not interpolated into the script before validation, update the
script to validate the RC_TAG variable (the existing RC_TAG regex guard) and
ensure any assignment uses the shell variable (RC_TAG) rather than expanding the
workflow expression inline, and remove or set continue-on-error: false on the
"Upload stable appcast to R2" step so appcast upload failures stop the release
promotion instead of proceeding.

In @.github/workflows/release-candidate.yml:
- Around line 50-58: The workflow step named "Validate release candidate inputs"
currently interpolates inputs inside the bash run script (VERSION="${{
inputs.version }}", RC_NUMBER="${{ inputs.rc_number }}" and echoing
candidate_ref into GITHUB_STEP_SUMMARY), which risks shell expansion of
malicious input; instead map inputs to environment variables in the step's env
block (e.g., VERSION, RC_NUMBER, CANDIDATE_REF) and reference them in the run
script with plain shell variables ($VERSION, $RC_NUMBER, $CANDIDATE_REF), then
use the env variable when writing to GITHUB_STEP_SUMMARY so no ${ { inputs.* } }
interpolation occurs inside the shell.

In `@scripts/generate_rc_icon.py`:
- Around line 104-116: The loop currently skips missing source files (src_path)
and prints a misleading summary using len(SIZES); change this to fail fast and
report the real generated count: when the code detects not
os.path.exists(src_path) for a given filename, print an error with the filename
and exit non‑zero (e.g., sys.exit(1)) instead of continuing; introduce and
increment a generated_count variable where recolor_banner(img).save(...) is
called and use that generated_count in the final print that references DST_DIR
so the summary reflects actual outputs rather than len(SIZES).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 004d8dbe-ba43-4917-bfd1-b9a84b6ce666

📥 Commits

Reviewing files that changed from the base of the PR and between 2a621a7 and 4cf162a.

⛔ Files ignored due to path filters (10)
  • Assets.xcassets/AppIcon-RC.appiconset/128.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/128@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/16.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/16@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/256.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/256@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/32.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/32@2x.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/512.png is excluded by !**/*.png
  • Assets.xcassets/AppIcon-RC.appiconset/512@2x.png is excluded by !**/*.png
📒 Files selected for processing (9)
  • .github/workflows/ci.yml
  • .github/workflows/promote-release-candidate.yml
  • .github/workflows/release-candidate.yml
  • Assets.xcassets/AppIcon-RC.appiconset/Contents.json
  • cmux.rc.entitlements
  • scripts/compile-app-icon-icns.sh
  • scripts/generate_rc_icon.py
  • scripts/verify-app-bundle-channel-metadata.sh
  • tests/test_verify_app_bundle_channel_metadata.sh

Comment thread .github/workflows/promote-release-candidate.yml
Comment thread .github/workflows/promote-release-candidate.yml
Comment thread .github/workflows/release-candidate.yml
Comment thread scripts/generate_rc_icon.py
@greptile-apps

greptile-apps Bot commented May 22, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds a macOS release-candidate distribution channel: a new release-candidate.yml workflow that builds/signs/notarizes both a cmux RC.app and a stable-candidate-* asset set from one unsigned payload, a promote-release-candidate.yml workflow that publishes those pre-built stable assets without rebuilding, and the full RC runtime identity stack (com.cmuxterm.app.rc, cmux-rc://, /tmp/cmux-rc*.sock, cmux.rc.entitlements, icon assets, and Python client parity).

  • Workflows: release-candidate.yml builds two signed/notarized apps, embeds Sparkle feeds and daemon manifests with an explicit signerWorkflow, attests daemon binaries, and enforces immutable-asset guards; promote-release-candidate.yml downloads the pre-built assets, verifies the tag SHA, creates the stable GitHub release with a correct --latest flag, and uploads the stable appcast to R2.
  • Runtime identity: RC bundle ID, URL scheme, socket paths, marker files, and theme-reload routing are consistently registered across Swift (AuthEnvironment, AuthCallbackRouter, CmuxSSHURLRequest, CLISocketPathResolver, SocketPathMarkerFiles), the Python test client, and the web after-sign-in handler; the channel-default socket is now preferred over a potentially stale last-run marker file.
  • Attestation routing: manifests now carry an optional signerWorkflow field; the CLI prefers it over the tag-based fallback, which correctly points stable-from-RC users to release-candidate.yml (the workflow that created the attestations).

Confidence Score: 5/5

Safe to merge. The RC channel is fully additive — new bundle ID, URL scheme, socket paths, and workflows leave the existing stable and nightly channels untouched.

All changed Swift paths correctly thread the RC variant through actor-safe, nonisolated enum dispatches that mirror the established nightly/staging patterns. The workflow changes use env: indirection for dispatch inputs, enforce immutable-asset guards, and the attestation signerWorkflow embedded in stable-candidate manifests correctly points to release-candidate.yml (the workflow that created the attestations). The socket-resolver ordering change is well-tested with both Swift unit tests and the new Python integration tests.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/release-candidate.yml New 735-line workflow; builds two signed/notarized apps from a single payload, embeds manifests with explicit signerWorkflow, attests daemon binaries, and guards immutable assets.
.github/workflows/promote-release-candidate.yml New 285-line promotion workflow; verifies tag SHA, enforces immutable-asset guard, computes --latest correctly, guards R2 and Homebrew steps.
CLI/CLISocketPathResolver.swift Adds RC socket path constant and variant cases; reorders candidatePaths to prefer channel default over stale marker. Consistent with nightly/staging treatment.
Packages/CMUXSocketPathDomain/Sources/CMUXSocketPathDomain/SocketPathMarkerFiles.swift Adds .rc(slug:) variant with correct marker file names, tmp paths, and default socket derivation; mirrors nightly pattern precisely.
Sources/Auth/AuthEnvironment.swift RC callbackScheme derived from bundle ID with exact-match and prefix checks; consistent with SocketPathMarkerFiles.
Sources/Workspace.swift Adds optional signerWorkflow field to WorkspaceRemoteDaemonManifest; backward-compatible nil for old manifests.
CLI/cmux.swift Prefers manifest.signerWorkflow for gh attestation verify and falls back to tag-based heuristic that now recognises RC tag pattern.
scripts/build_remote_daemon_release_assets.sh Adds optional --signer-workflow argument; emits signerWorkflow into JSON manifest only when provided.
tests/test_cli_socket_autodiscovery.py Adds RC socket variant tests including stale-marker fallback test validating default-over-stale priority.
web/app/handler/after-sign-in/page.tsx One-line addition of cmux-rc:// to NATIVE_SCHEMES list; consistent with nightly and dev scheme handling.

Reviews (13): Last reviewed commit: "fix: keep rc tags out of stable release ..." | Re-trigger Greptile

Comment thread .github/workflows/release-candidate.yml

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

6 issues found across 19 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread .github/workflows/release-candidate.yml Outdated
Comment thread .github/workflows/promote-release-candidate.yml Outdated
Comment thread scripts/generate_rc_icon.py Outdated
Comment thread .github/workflows/promote-release-candidate.yml Outdated
Comment thread .github/workflows/promote-release-candidate.yml Outdated
Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/promote-release-candidate.yml
Comment thread .github/workflows/promote-release-candidate.yml

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 3 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread .github/workflows/promote-release-candidate.yml
Comment thread .github/workflows/promote-release-candidate.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/promote-release-candidate.yml (1)

162-179: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Don't turn release-list lookup failures into --latest.

Line 162 ignores gh release list errors, so a transient GitHub API/auth failure leaves EXISTING_STABLE_TAGS empty and makes Lines 164-179 publish this release with --latest. That can incorrectly move the stable "Latest" badge to an older backfill release.

Suggested patch
-          EXISTING_STABLE_TAGS="$(gh release list --repo "$GITHUB_REPOSITORY" --exclude-drafts --exclude-pre-releases \
-            --json tagName -q '.[].tagName' || true)"
+          EXISTING_STABLE_TAGS="$(gh release list --repo "$GITHUB_REPOSITORY" --exclude-drafts --exclude-pre-releases \
+            --json tagName -q '.[].tagName')"
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/promote-release-candidate.yml around lines 162 - 179, gh
release list is being silenced with "|| true" so failures produce an empty
EXISTING_STABLE_TAGS and can mistakenly make LATEST_FLAG=(--latest) for the new
release; update the logic around the gh release list call (EXISTING_STABLE_TAGS)
to detect non-zero exit status from gh release list (or capture stderr), and on
failure either abort (exit non-zero with a clear error) or explicitly keep
LATEST_FLAG=(--latest=false) instead of allowing it to flip to --latest; ensure
the subsequent LATEST_STABLE_TAG / LATEST_FLAG decision uses that failure
detection so transient API/auth errors do not mark a backfill as latest.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release-candidate.yml:
- Around line 698-706: The script currently treats a failed `gh release list` as
an empty LATEST_RC and continues with the R2 upload, risking overwriting the
appcast; change the LATEST_RC assignment and surrounding block so that if `gh
release list --repo "$GITHUB_REPOSITORY" ...` fails (non-zero exit) the script
exits non-zero instead of proceeding. Concretely, run the gh command and check
its exit status (or use `|| { echo "Failed to list releases"; exit 1; }`) when
populating LATEST_RC, and only proceed to the RC upload when the command
succeeded and LATEST_RC is set and equals RC_TAG; update the block referencing
LATEST_RC and RC_TAG accordingly.

---

Outside diff comments:
In @.github/workflows/promote-release-candidate.yml:
- Around line 162-179: gh release list is being silenced with "|| true" so
failures produce an empty EXISTING_STABLE_TAGS and can mistakenly make
LATEST_FLAG=(--latest) for the new release; update the logic around the gh
release list call (EXISTING_STABLE_TAGS) to detect non-zero exit status from gh
release list (or capture stderr), and on failure either abort (exit non-zero
with a clear error) or explicitly keep LATEST_FLAG=(--latest=false) instead of
allowing it to flip to --latest; ensure the subsequent LATEST_STABLE_TAG /
LATEST_FLAG decision uses that failure detection so transient API/auth errors do
not mark a backfill as latest.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 4e714cd1-6c1f-43a3-ab3c-01d99f101441

📥 Commits

Reviewing files that changed from the base of the PR and between 21dff8a and b523408.

📒 Files selected for processing (2)
  • .github/workflows/promote-release-candidate.yml
  • .github/workflows/release-candidate.yml

Comment thread .github/workflows/release-candidate.yml Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_cli_socket_autodiscovery.py`:
- Line 264: The test instantiates a PingServer with accept_timeout=1.0 which is
too short for slower CI runs; update the PingServer constructor calls (e.g., the
creation of default_server using PingServer(default_socket_path,
response=b"WRONG\n", accept_timeout=1.0)) to use a larger accept_timeout (for
example 5.0) at both occurrences (the one around default_server and the second
occurrence referenced around line 524) so the server stays alive long enough for
the subprocess to connect and the socket-selection assertions become
deterministic.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: dd5c9b1a-f520-405a-8f81-7ec7a84c6f6a

📥 Commits

Reviewing files that changed from the base of the PR and between b523408 and 2f5476b.

📒 Files selected for processing (13)
  • .github/workflows/promote-release-candidate.yml
  • .github/workflows/release-candidate.yml
  • CLI/CLISocketPathResolver.swift
  • Packages/CMUXSocketPathDomain/Sources/CMUXSocketPathDomain/SocketPathMarkerFiles.swift
  • Packages/CMUXSocketPathDomain/Tests/CMUXSocketPathDomainTests/SocketPathMarkerFilesTests.swift
  • Sources/Auth/AuthCallbackRouter.swift
  • Sources/Auth/AuthEnvironment.swift
  • Sources/CmuxApplicationSupportDirectories.swift
  • Sources/CmuxSSHURLRequest.swift
  • cmuxTests/CmuxSSHURLRequestTests.swift
  • tests/cmux.py
  • tests/test_cli_socket_autodiscovery.py
  • web/app/handler/after-sign-in/page.tsx

Comment thread tests/test_cli_socket_autodiscovery.py Outdated
Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/release-candidate.yml

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 2 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread .github/workflows/release-candidate.yml
Comment thread .github/workflows/release-candidate.yml
@cubic-dev-ai

cubic-dev-ai Bot commented May 22, 2026

Copy link
Copy Markdown

You're iterating quickly on this pull request. To help protect your rate limits, cubic has paused automatic reviews on new pushes for now—when you're ready for another review, comment @cubic-dev-ai review.

Comment thread CLI/CLISocketPathResolver.swift
@lawrencecchen

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 22, 2026

Copy link
Copy Markdown
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 3 total unresolved issues (including 2 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1edaf4b. Configure here.

Comment thread .github/workflows/promote-release-candidate.yml
@lawrencecchen lawrencecchen added the stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening. label Sep 23, 2026
@github-project-automation github-project-automation Bot moved this from Todo to Done in cmux backlog Sep 23, 2026

This branch was successfully deployed

1 active deployment
Preview – cmux — b1cc8c86 Deployed May 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants