Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
self-hosted-runner:
labels:
- blacksmith-6vcpu-macos-15
- blacksmith-6vcpu-macos-26
- blacksmith-6vcpu-macos-latest

config-variables: null
2 changes: 1 addition & 1 deletion .github/workflows/build-ghosttykit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ concurrency:

jobs:
build-ghosttykit:
runs-on: warp-macos-15-arm64-6x
runs-on: blacksmith-6vcpu-macos-15
timeout-minutes: 20
env:
GHOSTTYKIT_CRASH_REPORT_SUBDIR: cmux/crash
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci-macos-compat.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,12 +9,12 @@ jobs:
fail-fast: false
matrix:
include:
- os: warp-macos-15-arm64-6x
- os: blacksmith-6vcpu-macos-15
timeout: 30
startup_smoke: true
virtual_display: true
skip_zig: false
- os: warp-macos-26-arm64-6x
- os: blacksmith-6vcpu-macos-26
timeout: 30
startup_smoke: true
virtual_display: false
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,7 @@ jobs:
bun test tests/vm-db-read-model.test.ts

tests:
runs-on: warp-macos-15-arm64-6x
runs-on: blacksmith-6vcpu-macos-15
Comment thread
coderabbitai[bot] marked this conversation as resolved.
timeout-minutes: 75
env:
CMUX_SKIP_ZIG_BUILD: "1"
Expand Down Expand Up @@ -380,7 +380,7 @@ jobs:
# Keep lag validation separate from UI regressions so functional UI failures
# and performance regressions stay isolated. Broader interactive UI suites
# still run via test-e2e.yml on GitHub-hosted runners.
runs-on: warp-macos-15-arm64-6x
runs-on: blacksmith-6vcpu-macos-15
timeout-minutes: 20
steps:
- name: Checkout
Expand Down Expand Up @@ -568,7 +568,7 @@ jobs:
# Compile the same unsigned universal Release app that nightly builds before
# signing, notarization, and publishing. This catches DEBUG/Release boundary
# mistakes before they reach main.
runs-on: warp-macos-26-arm64-6x
runs-on: blacksmith-6vcpu-macos-26
timeout-minutes: 20
steps:
- name: Checkout
Expand Down Expand Up @@ -653,7 +653,7 @@ jobs:
CODE_SIGNING_ALLOWED=NO ASSETCATALOG_COMPILER_APPICON_NAME=AppIcon-Nightly build

ui-regressions:
runs-on: warp-macos-15-arm64-6x
runs-on: blacksmith-6vcpu-macos-15
timeout-minutes: 25
steps:
- name: Checkout
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -100,7 +100,7 @@ jobs:
build-sign-notarize-nightly:
needs: decide
if: needs.decide.outputs.should_build == 'true'
runs-on: warp-macos-26-arm64-6x
runs-on: blacksmith-6vcpu-macos-26
timeout-minutes: 20
steps:
- name: Checkout build ref
Expand Down
30 changes: 18 additions & 12 deletions .github/workflows/perf-activation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,11 +11,12 @@ on:
runner:
description: macOS runner
required: false
default: warp-macos-15-arm64-6x
default: blacksmith-6vcpu-macos-15
type: choice
options:
- warp-macos-15-arm64-6x
- depot-macos-latest
- blacksmith-6vcpu-macos-15
- blacksmith-6vcpu-macos-26
- blacksmith-6vcpu-macos-latest
workspace_count:
description: Fixture workspace count
required: false
Expand All @@ -35,7 +36,7 @@ concurrency:

jobs:
activation-session:
runs-on: ${{ inputs.runner || 'warp-macos-15-arm64-6x' }}
runs-on: ${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}
timeout-minutes: 45
env:
PERF_TAG: perfci
Expand Down Expand Up @@ -85,8 +86,8 @@ jobs:
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .ci-source-packages
key: spm-${{ hashFiles('cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved') }}
restore-keys: spm-
key: spm-${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}-${{ hashFiles('cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved') }}
restore-keys: spm-${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}-

- name: Resolve Swift packages
run: |
Expand Down Expand Up @@ -133,12 +134,17 @@ jobs:
run: |
set -euo pipefail
APP_PATH="$HOME/Library/Developer/Xcode/DerivedData/cmux-$PERF_TAG/Build/Products/Debug/cmux DEV $PERF_TAG.app"
swift scripts/bench-window-visibility.swift \
"$APP_PATH" \
"com.cmuxterm.app.debug.$PERF_TAG" \
30 \
--cmd-tab-activation \
--cg-visibility \
# The GitHub Actions runner process runs in launchd's system
# bootstrap, not the console user's Aqua session, so windows
# created by apps launched via NSWorkspace.openApplication do
# not show up in CGWindowListCopyWindowInfo([.optionOnScreenOnly]).
# Re-enter the Aqua session via launchctl asuser before running
# the bench so visibility polling sees real on-screen windows.
CONSOLE_USER="$(stat -f %Su /dev/console)"
CONSOLE_UID="$(id -u "$CONSOLE_USER")"
sudo -n launchctl asuser "$CONSOLE_UID" sudo -n -u "$CONSOLE_USER" -E \
env PATH="$PATH" DEVELOPER_DIR="$DEVELOPER_DIR" \
bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift '$APP_PATH' 'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility" \
> perf-results/cmd-tab-activation.txt
cat perf-results/cmd-tab-activation.txt

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ env:

jobs:
build-sign-notarize:
runs-on: warp-macos-26-arm64-6x
runs-on: blacksmith-6vcpu-macos-26
timeout-minutes: 20
steps:
- name: Checkout
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/test-depot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ on:

jobs:
tests:
runs-on: warp-macos-15-arm64-6x
runs-on: blacksmith-6vcpu-macos-15
timeout-minutes: 20
steps:
- name: Checkout
Expand Down
13 changes: 8 additions & 5 deletions .github/workflows/test-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,17 +20,20 @@ on:
default: true
type: boolean
runner:
description: "Runner OS (Depot runners for GUI activation support)"
description: "Runner OS (macOS 15 default for GUI activation support)"
required: false
default: "depot-macos-latest"
default: "blacksmith-6vcpu-macos-15"
type: choice
options:
- blacksmith-6vcpu-macos-15
- blacksmith-6vcpu-macos-26
- blacksmith-6vcpu-macos-latest
- depot-macos-latest
- depot-macos-14

jobs:
e2e:
runs-on: ${{ inputs.runner || 'depot-macos-latest' }}
runs-on: ${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}
timeout-minutes: 20
env:
Comment on lines 20 to 38

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 GUI activation capability assumption

The old description explicitly flagged that Depot runners were required for GUI activation support. The new default (blacksmith-6vcpu-macos-latest) silently drops that note, but E2E tests that depend on virtual display or GUI activation will silently regress if Blacksmith's latest image doesn't provide the same capability. The ci-macos-compat.yml matrix sets virtual_display: false for macOS 26, so if latest resolves to 26, any E2E step requiring a virtual display will break without a clear failure signal at the runner-selection level.

TEST_REF: ${{ inputs.ref || github.ref }}
Expand Down Expand Up @@ -172,8 +175,8 @@ jobs:
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .ci-source-packages
key: spm-${{ inputs.runner || 'depot-macos-latest' }}-${{ hashFiles('cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved') }}
restore-keys: spm-${{ inputs.runner || 'depot-macos-latest' }}-
key: spm-${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}-${{ hashFiles('cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved') }}
restore-keys: spm-${{ inputs.runner || 'blacksmith-6vcpu-macos-15' }}-

- name: Resolve Swift packages
run: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/tmux-corpus.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:

terminal-nightly:
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
runs-on: [self-hosted, warp-macos-15-arm64-6x]
runs-on: blacksmith-6vcpu-macos-15

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 self-hosted label silently removed

The original runner spec was [self-hosted, warp-macos-15-arm64-6x], meaning the job required a self-hosted runner. Switching to blacksmith-6vcpu-macos-15 (a managed cloud label) drops the self-hosted routing constraint entirely. If any network policy, secret scope, or tool availability was tied to the self-hosted runner context for terminal-nightly, the job may silently acquire a different environment without failing fast.

timeout-minutes: 30
steps:
- name: Checkout
Expand Down
30 changes: 15 additions & 15 deletions tests/test_ci_self_hosted_guard.sh
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#!/usr/bin/env bash
# Regression test for https://github.com/manaflow-ai/cmux/issues/385.
# Ensures paid CI jobs use WarpBuild runners.
# Ensures paid CI jobs use Blacksmith macOS runners.
# Fork PRs are gated by GitHub's built-in "Require approval for outside
# collaborators" setting, so workflow-level fork guards are not needed.
set -euo pipefail
Expand All @@ -10,29 +10,29 @@ CI_FILE="$ROOT_DIR/.github/workflows/ci.yml"
GHOSTTYKIT_FILE="$ROOT_DIR/.github/workflows/build-ghosttykit.yml"
COMPAT_FILE="$ROOT_DIR/.github/workflows/ci-macos-compat.yml"

check_warp_runner() {
check_blacksmith_runner() {
local file="$1" job="$2"
if ! awk -v job="$job" '
$0 ~ "^ "job":" { in_job=1; next }
in_job && /^ [^[:space:]]/ { in_job=0 }
in_job && /runs-on:.*warp-macos-.*-arm64/ { saw_warp=1 }
in_job && /os: warp-macos-.*-arm64/ { saw_warp=1 }
END { exit !(saw_warp) }
in_job && /^ [^[:space:]#][^:]*:[[:space:]]*(#.*)?$/ { in_job=0 }
in_job && /runs-on:.*blacksmith-[0-9]+vcpu-macos-/ { saw=1 }
in_job && /os: blacksmith-[0-9]+vcpu-macos-/ { saw=1 }
END { exit !(saw) }
Comment thread
coderabbitai[bot] marked this conversation as resolved.
' "$file"; then
echo "FAIL: $job in $(basename "$file") must use a WarpBuild runner"
echo "FAIL: $job in $(basename "$file") must use the expected macOS runner"
exit 1
fi
echo "PASS: $job WarpBuild runner is present"
echo "PASS: $job in $(basename "$file") uses the expected macOS runner"
}

# ci.yml jobs
check_warp_runner "$CI_FILE" "tests"
check_warp_runner "$CI_FILE" "tests-build-and-lag"
check_warp_runner "$CI_FILE" "release-build"
check_warp_runner "$CI_FILE" "ui-regressions"
check_blacksmith_runner "$CI_FILE" "tests"
check_blacksmith_runner "$CI_FILE" "tests-build-and-lag"
check_blacksmith_runner "$CI_FILE" "release-build"
check_blacksmith_runner "$CI_FILE" "ui-regressions"

# build-ghosttykit.yml
check_warp_runner "$GHOSTTYKIT_FILE" "build-ghosttykit"
check_blacksmith_runner "$GHOSTTYKIT_FILE" "build-ghosttykit"

# ci-macos-compat.yml (uses matrix.os with WarpBuild runners)
check_warp_runner "$COMPAT_FILE" "compat-tests"
# ci-macos-compat.yml (uses matrix.os with Blacksmith runners)
check_blacksmith_runner "$COMPAT_FILE" "compat-tests"
Loading