Skip to content

Add universal macOS release artifact guard - #4744

Closed
austinywang wants to merge 9 commits into
mainfrom
issue-293-intel-x86-64-mac-support
Closed

austinywang wants to merge 9 commits into
mainfrom
issue-293-intel-x86-64-mac-support

Conversation

@austinywang

@austinywang austinywang commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Refs #293.

This is a scoped first increment for Intel Mac support durability. Current main already builds Release and Nightly macOS artifacts as universal binaries; this PR turns that into one shared artifact-level contract so release paths cannot silently ship an arm64-only app, embedded CLI, or Ghostty helper.

  • Add scripts/verify-universal-macos-app.sh to verify the app executable, bundled cmux CLI, and bundled ghostty helper all contain arm64 and x86_64 slices.
  • Wire the guard into stable release, nightly, CI release-build, and the manual scripts/build-sign-upload.sh path.
  • Force the manual signing/upload build path to use ARCHS="arm64 x86_64", ONLY_ACTIVE_ARCH=NO, and generic/platform=macOS.
  • Add a shell behavior test for the verifier using a fake lipo over fixture app artifacts.

Architecture note

The build system had multiple owners for the same invariant: Xcode project Release settings, release/nightly workflow inline lipo checks, CI release-build, the Ghostty helper run script, and the manual signing script. The stronger boundary is a single verifier that inspects the produced .app artifact after Xcode has run. That makes the bad state observable at the artifact boundary, not inferred from workflow text or project settings.

Remaining outside this increment: a real Intel-hardware launch smoke. This PR verifies the shipped Mach-O slices for the app, CLI, and helper; it does not provision an Intel Mac or add an x86 runtime UI test.

Test plan

Not run locally per task and repo instructions. CI should run the new workflow guard test and the macOS release-build artifact verification.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.


Note

Low Risk
Changes are build/CI guardrails and permission tightening around release artifacts, not runtime app logic or auth/data paths.

Overview
Introduces scripts/verify-universal-macos-app.sh as the single post-build contract for Release macOS .app artifacts: the main executable, bundled cmux CLI, and ghostty helper must each include arm64 and x86_64 slices, with an optional --require-sdk-prefix (e.g. 26.) on the app binary.

Replaces duplicated inline lipo / otool checks in CI release-build, nightly, and release workflows with calls to that script. scripts/build-sign-upload.sh now forces a universal xcodebuild (ARCHS, ONLY_ACTIVE_ARCH=NO, generic macOS destination) and runs the verifier before signing.

CI hygiene: workflow default permissions drop actions: write; release-ghostty-cli-helper / release-build get scoped job permissions. workflow-guard-tests gains tests/test_verify_universal_macos_app.sh; existing lane/self-hosted guard tests assert workflows and the manual script use the verifier with --require-sdk-prefix "26.".

Reviewed by Cursor Bugbot for commit 9822afe. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Adds a universal macOS artifact verifier to ensure the app, bundled cmux, and ghostty helper are universal (arm64 + x86_64) and built with the macOS 26 SDK. Centralizes checks across nightly/release/CI and the manual signing path, and tightens CI permissions (refs #293).

  • New Features

    • Added scripts/verify-universal-macos-app.sh (reads Info.plist, supports --label and --require-sdk-prefix) to verify app, CLI, helper slices and SDK.
    • Nightly, release, and CI call the verifier with --require-sdk-prefix "26."; CI runs tests/test_verify_universal_macos_app.sh. scripts/build-sign-upload.sh now builds universal via generic macOS destination and runs the verifier before signing.
  • Bug Fixes

    • --label and --require-sdk-prefix require values with clear errors.
    • Tests cover wrong SDK prefix, missing slices, missing embedded CLI; CI guards assert release-build uses the universal verifier and that workflows/manual script pass --require-sdk-prefix "26.".
    • CI permissions are least-privilege by default with explicit per-job overrides.

Written for commit 9822afe. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores

    • Centralized macOS universal-app verification into a single reusable verifier and updated CI/nightly/release workflows to call it for consistent architecture checks.
    • Build/upload flow now runs integrated post-build validation to catch packaging issues earlier.
    • CI workflow permissions tightened to reduce write scope and strengthen security.
  • Tests

    • Added integration tests covering the verifier’s success/failure behaviors and error reporting.

@vercel

vercel Bot commented May 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Canceled Canceled Jun 6, 2026 9:21am
cmux-staging Building Building Preview, Comment Jun 6, 2026 9:21am

@coderabbitai

coderabbitai Bot commented May 26, 2026 •

Copy link
Copy Markdown

Too many files changed? Review this PR in Change Stack to see how the pieces fit before you dive in.

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds a reusable Bash verifier for macOS universal app bundles, integrates it into CI workflows and the build script, and adds integration tests validating success and multiple failure cases.

Changes

Universal Binary Verification Script

Layer / File(s) Summary
Core verification script implementation
scripts/verify-universal-macos-app.sh
Implements argument parsing, lipo resolution (via CMUX_LIPO or system), reads CFBundleExecutable from Info.plist, constructs paths for app executable, bundled cmux CLI, and ghostty helper, and defines verify_binary_archs() to require both arm64 and x86_64 slices per binary.
Integration test for verification script
tests/test_verify_universal_macos_app.sh
Creates a temporary .app fixture and fake lipo shim, asserts verifier succeeds for valid fixtures, and asserts failures for missing --label value, missing architecture slices (arm64/x86_64), and missing/non-executable CLI.
CI workflow integration
.github/workflows/ci.yml, .github/workflows/nightly.yml, .github/workflows/release.yml, tests/test_ci_self_hosted_guard.sh
Replaces inline lipo checks in nightly and release workflows with calls to ./scripts/verify-universal-macos-app.sh; tightens workflow-level permissions in ci.yml; adds CI guard step to run the verifier test; updates guard tests to verify the workflow invokes the universal verifier script and that the verifier contains verify_binary_archs checks.
Build script integration
scripts/build-sign-upload.sh
Updates xcodebuild invocation to explicitly target macOS multi-arch builds (arm64 x86_64) with ONLY_ACTIVE_ARCH=NO, keeps unsigned builds, checks helper presence, and runs the verification script before continuing.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • manaflow-ai/cmux#5077: Overlapping changes to nightly universal-architecture verification that call scripts/verify-universal-macos-app.sh and validate app/CLI/helper slices.

Poem

🐰 I nibble at scripts with a curious hop,
I check each slice — arm64 and x86_64 on top.
One verifier now replaces inline repeat,
CI and builds clap their tiny rabbit feet.
Hooray — universal apps pass the crop! 🍎


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Cmux User-Facing Error Privacy ❓ Inconclusive No result was produced after verification. Marking as INCONCLUSIVE. Re-run the check or adjust instructions to produce a final result.
✅ Passed checks (17 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: adding a guard to verify universal macOS release artifacts (arm64 + x86_64 slices). It is clear, concise, and directly relates to the primary objective.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PR contains no Swift code (only shell scripts and YAML workflows), making the Swift actor isolation check not applicable.
Cmux Swift Blocking Runtime ✅ Passed PR contains no Swift production code changes—only GitHub Actions YAML workflows and Bash shell scripts for universal macOS binary verification.
Cmux No Hacky Sleeps ✅ Passed PR adds deterministic binary architecture verification (lipo/otool inspection) with no sleep, timeout, delay, or polling synchronization patterns introduced in production code.
Cmux Algorithmic Complexity ✅ Passed New verify-universal-macos-app.sh operates only on fixed-size collections (3 binaries, 2 architectures) with no scalable collection iteration, nested scans, or unbounded operations.
Cmux Swift Concurrency ✅ Passed PR modifies only YAML workflows and Bash scripts; no Swift code is changed. Check applies only to Swift code, making it inapplicable here.
Cmux Swift @Concurrent ✅ Passed PR contains no Swift code changes, only YAML workflows and Bash scripts. The @concurrent annotation check is not applicable.
Cmux Swift File And Package Boundaries ✅ Passed PR contains no Swift code changes—only YAML workflows and Bash scripts. Check applies only to production Swift changes and is therefore not applicable.
Cmux Swift Logging ✅ Passed PR contains no Swift files; check is for Swift logging violations only. All changes are YAML workflows and shell scripts.
Cmux Full Internationalization ✅ Passed PR modifies only CI workflows, build scripts, and tests with no changes to user-facing text, localization catalogs, or web i18n—all changes are developer-facing infrastructure.
Cmux Swiftui State Layout ✅ Passed PR modifies only GitHub Actions workflows and bash shell scripts (no .swift/.swiftui files); SwiftUI check is not applicable to non-UI changes.
Cmux Architecture Rethink ✅ Passed PR modifies only shell scripts and YAML workflows for macOS artifact verification; no Swift code changes present, making the swift-architectural-rethink check inapplicable.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains only YAML workflows and Bash scripts; no Swift code changes present. Window close shortcuts check is not applicable.
Cmux Source Artifacts ✅ Passed All changed files are hand-written source, test, scripts, or configs intentionally part of build/test infrastructure; no generated artifacts, build output, or caches.
Description check ✅ Passed The PR description is comprehensive and covers all required template sections: Summary (what changed and why), Testing (CI verifies the new guards), and Checklist completion is evident from the detailed scope.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch issue-293-intel-x86-64-mac-support

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

socket-security Bot commented May 26, 2026 •

Copy link
Copy Markdown

No dependency changes detected. Learn more about Socket for GitHub.

👍 No dependency changes detected in pull request

@greptile-apps

greptile-apps Bot commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Centralizes macOS universal-binary enforcement into a single post-build verifier (scripts/verify-universal-macos-app.sh) that replaces duplicated inline lipo/otool checks across the nightly, release, CI release-build, and manual signing paths. The manual signing path (build-sign-upload.sh) also gains explicit universal xcodebuild flags and SDK prefix enforcement, closing a previously flagged gap. CI permissions are tightened to least-privilege per job.

  • New verifier reads CFBundleExecutable from Info.plist, checks arm64 + x86_64 slices for the app binary, bundled cmux CLI, and Ghostty helper, and optionally asserts an SDK prefix via otool; argument parsing guards both --label and --require-sdk-prefix against missing values before any shift.
  • Test suite covers the success path, wrong SDK prefix, missing arm64 slice, missing x86_64 slice, and missing embedded CLI using a fake lipo/otool injected via CMUX_LIPO/CMUX_OTOOL.
  • Guard tests (test_ci_release_sdk_lane.sh, test_ci_self_hosted_guard.sh) migrate from hard-coded lipo string greps to checking for the verifier invocation and its internals, with build-sign-upload.sh now included in the SDK-prefix contract check.

Confidence Score: 5/5

Changes are confined to CI/CD guards, build scripts, and test scaffolding with no runtime app logic touched; all release paths now enforce the shared SDK+arch contract.

The verifier script is well-structured with robust argument guards. All four release paths now call it with --require-sdk-prefix "26.", previously flagged gaps are closed, and the fixture-based test suite covers both the success and failure branches. The one noted gap — no automated check that nightly.yml continues to pass --require-sdk-prefix — represents minor test coverage debt, not a correctness risk in this PR.

No files require special attention. The comment in tests/test_ci_release_sdk_lane.sh overstates nightly coverage but the nightly workflow itself is correct as shipped.

Important Files Changed

Filename Overview
scripts/verify-universal-macos-app.sh New verifier script: reads CFBundleExecutable from Info.plist, checks arm64+x86_64 slices for app binary, CLI, and Ghostty helper via injected lipo, optionally checks SDK prefix via otool; argument parsing is robust with pre-shift guards.
tests/test_verify_universal_macos_app.sh Comprehensive fixture-based test covering success path, bad SDK prefix, missing arm64 slice (helper), missing x86_64 slice (helper), missing CLI binary, and both missing-value argument diagnostics; uses fake lipo/otool via CMUX_LIPO/CMUX_OTOOL env vars.
scripts/build-sign-upload.sh Adds explicit universal xcodebuild flags (-destination generic/platform=macOS, ARCHS, ONLY_ACTIVE_ARCH=NO) and calls the verifier with --require-sdk-prefix "26." before signing; closes the previously flagged gap where this path lacked SDK enforcement.
.github/workflows/ci.yml Removes global actions: write, adds per-job permissions (actions: write for release-ghostty-cli-helper, actions: read for release-build), replaces inline lipo/otool checks in release-build with the shared verifier, and adds a workflow step to run the verifier test suite.
.github/workflows/nightly.yml Replaces the inline arch-slice check (which lacked SDK verification) with a call to the shared verifier including --require-sdk-prefix "26.", a net addition of SDK enforcement for nightly builds.
.github/workflows/release.yml Replaces inline lipo/otool/SDK checks with the shared verifier; functionally equivalent to the removed code but now uses the single authoritative contract.
tests/test_ci_release_sdk_lane.sh Updated to check for --require-sdk-prefix "26." (verifier API) instead of the old inline grep pattern, and extended to cover build-sign-upload.sh; comment updated to acknowledge nightly coverage via the verifier test.
tests/test_ci_self_hosted_guard.sh Migrated check_release_build_signal from hard-coded lipo string greps in ci.yml to a job-section-scoped check for the verifier invocation, and cross-checks the verifier script itself for the three required verify_binary_archs calls.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[xcodebuild universal build\nARCHS=arm64 x86_64\nONLY_ACTIVE_ARCH=NO] --> B[.app artifact produced]
    B --> C[verify-universal-macos-app.sh]
    C --> D{Info.plist readable?}
    D -- Yes --> E[Read CFBundleExecutable]
    D -- No --> F[Fallback: basename .app]
    E --> G[verify_binary_archs: app binary]
    F --> G
    G --> H[verify_binary_archs: CLI binary]
    H --> I[verify_binary_archs: Ghostty helper]
    I --> J{--require-sdk-prefix set?}
    J -- No --> K[PASS]
    J -- Yes --> L[otool LC_BUILD_VERSION sdk check]
    L --> M{prefix matches?}
    M -- Yes --> K
    M -- No --> N[FAIL: wrong SDK]

    subgraph callers [Callers]
        P1[release.yml\n--require-sdk-prefix 26.]
        P2[nightly.yml\n--require-sdk-prefix 26.]
        P3[ci.yml release-build\n--require-sdk-prefix 26.]
        P4[build-sign-upload.sh\n--require-sdk-prefix 26.]
    end
    callers --> C
Loading

Reviews (8): Last reviewed commit: "fix: address release verifier review fee..." | Re-trigger Greptile

Comment thread scripts/verify-universal-macos-app.sh
Comment thread tests/test_verify_universal_macos_app.sh

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/verify-universal-macos-app.sh`:
- Around line 17-20: Guard the shift in the --label case so the script doesn't
"shift count out of range" when the flag is the last argument: in the --label)
branch (referencing LABEL and shift 2), check whether a second argument exists
(e.g. test $# -ge 2 or test -n "${2:-}") and only then set LABEL from $2 and
shift 2; otherwise set LABEL to empty (or leave as default) and shift 1 to
consume the --label token so the later "Missing value for --label" validation
can run.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 134ca6f9-c2b8-4747-8f79-7b9e8c8ea4f8

📥 Commits

Reviewing files that changed from the base of the PR and between 89533ee and 5e2a30e.

📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
  • scripts/build-sign-upload.sh
  • scripts/verify-universal-macos-app.sh
  • tests/test_verify_universal_macos_app.sh

Comment thread scripts/verify-universal-macos-app.sh
Comment thread .github/workflows/ci.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 10-13: The workflow-wide permissions block currently grants broad
write rights via the actions: write entry; remove the actions: write line
(leaving contents: read) or instead move and scope actions: write to only the
specific job that needs it by adding a per-job permissions block; update the
permissions block to the minimal scope required and ensure any job-level
permission overrides use actions: write only where strictly necessary.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: b7336aa3-7f87-4232-a117-928e6bd68767

📥 Commits

Reviewing files that changed from the base of the PR and between 37bee4a and a849de9.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 10-13: The workflow-wide permissions block currently grants broad
write rights via the actions: write entry; remove the actions: write line
(leaving contents: read) or instead move and scope actions: write to only the
specific job that needs it by adding a per-job permissions block; update the
permissions block to the minimal scope required and ensure any job-level
permission overrides use actions: write only where strictly necessary.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: b7336aa3-7f87-4232-a117-928e6bd68767

📥 Commits

Reviewing files that changed from the base of the PR and between 37bee4a and a849de9.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • .github/workflows/nightly.yml
  • .github/workflows/release.yml
🛑 Comments failed to post (1)
.github/workflows/ci.yml (1)

10-13: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Narrow workflow token scope at Line 12 (actions: write).

actions: write at workflow scope is broader than required by the visible CI steps and increases blast radius if any CI step is compromised. Keep least privilege by removing it (or scoping write only to the specific job that truly needs it).

Suggested minimal hardening
 permissions:
   contents: read
-  actions: write
+  actions: read
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

permissions:
  contents: read
  actions: read
🧰 Tools
🪛 zizmor (1.25.2)

[error] 12-12: overly broad permissions (excessive-permissions): actions: write is overly broad at the workflow level

(excessive-permissions)


[warning] 12-12: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 10 - 13, The workflow-wide permissions
block currently grants broad write rights via the actions: write entry; remove
the actions: write line (leaving contents: read) or instead move and scope
actions: write to only the specific job that needs it by adding a per-job
permissions block; update the permissions block to the minimal scope required
and ensure any job-level permission overrides use actions: write only where
strictly necessary.

Source: Linters/SAST tools

Comment thread scripts/build-sign-upload.sh Outdated
echo "Ghostty theme picker helper not found at $HELPER_PATH" >&2
exit 1
fi
./scripts/verify-universal-macos-app.sh "$APP_PATH" --label "Release app"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 The manual release path calls the verifier without --require-sdk-prefix "26.", which means an app accidentally built against macOS 15 (or any non-26 SDK) would pass this gate and continue through signing, notarization, and upload. Every other release path — release.yml, nightly.yml, and CI release-build — all pass --require-sdk-prefix "26.". The PR explicitly lists this script as one of the hardened paths.

Suggested change
./scripts/verify-universal-macos-app.sh "$APP_PATH" --label "Release app"
./scripts/verify-universal-macos-app.sh "$APP_PATH" --label "Release app" --require-sdk-prefix "26."

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_ci_self_hosted_guard.sh`:
- Around line 121-124: The current check uses a substring match on the variable
section which can match comments or unrelated text; change the condition to
match a command token boundary so it only passes when the verifier is actually
invoked. Replace the glob test on section with a word-boundary regex using
Bash's =~ operator, e.g. test that section matches
'(^|[[:space:]])\./scripts/verify-universal-macos-app.sh([[:space:]]|$)' so the
script name is a standalone command token (allowing trailing args) when checking
in tests/test_ci_self_hosted_guard.sh where variable section is evaluated.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: cf0f0cfb-a9ec-455d-8de3-f4425ce1f4e6

📥 Commits

Reviewing files that changed from the base of the PR and between a849de9 and acf2897.

📒 Files selected for processing (1)
  • tests/test_ci_self_hosted_guard.sh

Comment thread tests/test_ci_self_hosted_guard.sh Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit de49750. Configure here.

Comment thread .github/workflows/ci.yml
@teamleaderleo

Copy link
Copy Markdown
Collaborator

cmux-reconcile: partly-useful

Usefulness verdict: Evaluate only guard consolidation and test value; the absence of architecture checks is no longer a valid premise.

The diff introduces a shared verify-universal-macos-app.sh and shell tests. Current release workflow already checks arm64/x86_64 slices for app, CLI, helper, and tunnel. A common helper may reduce drift, but a rebase must preserve the current artifact coverage rather than replace it with a narrower check. Keep as a potential refactor with a concrete duplication/coverage benefit, not “add Intel support.”

Reviewed patch head: 9822afe475cac02d681aaca76b6c6ade7c7e855b. Source/diff triage on September 18, 2026; no new build or runtime validation. No issue state, label, or merge decision changed.

Older issue/PR tracking index — remaining scope and competing implementations are recorded there.

@lawrencecchen

Copy link
Copy Markdown
Contributor

Mac fleet instructions for head 9822afe475cac02d681aaca76b6c6ade7c7e855b. Planned tag: pr-4744-9822afe4; this is not yet a published build.

JOB_JSON=$(~/.local/bin/cmux-ci submit --kind cmux --command 'CMUX_FLEET_BUILD_TAG=pr-4744-9822afe4 /Users/Shared/cmux-build-fleet/recipes/cmux.sh https://github.com/manaflow-ai/cmux.git 9822afe475cac02d681aaca76b6c6ade7c7e855b' --artifact artifacts/cmux.app.zip --workspace https://github.com/manaflow-ai/cmux/pull/4744 --source-digest 9822afe475cac02d681aaca76b6c6ade7c7e855b --cache-key cmux:pr-4744 --min-free-bytes 268435456000 --label cmux --label ram48)
JOB_ID=$(python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])' <<<"$JOB_JSON")
~/.local/bin/cmux-ci wait "$JOB_ID" --receipt artifacts/fleet/$JOB_ID.json
~/.local/bin/cmux-ci publish-hq "$JOB_ID"

Use an existing campaign job ID if one is already posted; do not submit a duplicate. A wait timeout leaves the remote job running. Published results will include an exact-head artifact link and timing/disk receipt. This recipe validates the macOS app only, not iOS or tests. Never use maclease or put credentials in a PR comment.

@teamleaderleo

Copy link
Copy Markdown
Collaborator

Universal macOS artifact checks are now part of the current release pipeline; this PR is superseded by the main CI contract in 8dd69c0.

This branch was successfully deployed

1 active deployment
Preview – cmux — 9822afe4 Deployed Jun 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants