Skip to content

Guard E2E Depot runner identity - #4944

Merged
lawrencecchen merged 1 commit into
mainfrom
feat-e2e-depot-runner-guard
May 28, 2026
Merged

lawrencecchen merged 1 commit into
mainfrom
feat-e2e-depot-runner-guard

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented May 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Fail the manual E2E workflow early when the default depot-macos-latest label resolves to a non-Depot runner.
  • Extend the existing workflow guard script so the identity check stays wired.

Why

The strict activation proof in https://github.com/manaflow-ai/cmux/actions/runs/26570108351 silently routed depot-macos-latest to an AWS self-hosted runner named cmux-aws-m4pro-5, then failed with a misleading app activation error. After removing that accidental external label, https://github.com/manaflow-ai/cmux/actions/runs/26571172281 resolved to a true Depot runner named depot-w8l2gw3nfv. This PR makes that runner-class invariant explicit in the workflow.

Testing

  • actionlint -oneline .github/workflows/test-e2e.yml
  • ./tests/test_ci_self_hosted_guard.sh
  • git diff --check

@coderabbitai review


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.


Note

Low Risk
Workflow-only guard and test assertions; no application runtime, auth, or data-path changes.

Overview
Adds an early Validate Depot runner identity step to the manual E2E workflow when the selected label is depot-macos-*. It compares the requested runner to ${{ runner.name }} and fails fast with a clear ::error:: if the job did not land on a depot-* host (avoiding misleading GUI/activation failures on mislabeled self-hosted runners).

Extends tests/test_ci_self_hosted_guard.sh so CI asserts that guard stays wired: runner.name is set, all Depot macOS choices are gated, and misrouting triggers the documented error plus exit 1.

Reviewed by Cursor Bugbot for commit 29176a0. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Add an identity guard to the E2E workflow so jobs requesting depot-macos-* fail fast if routed to a non-Depot runner. This prevents misleading activation failures and makes the runner class explicit.

  • Bug Fixes
    • Added a conditional "Validate Depot runner identity" step in .github/workflows/test-e2e.yml for any depot-macos-* (default depot-macos-latest) that echoes the requested label, checks runner.name starts with depot-, and fails with a clear message if not.
    • Extended tests/test_ci_self_hosted_guard.sh to assert the runner.name inspection, the startsWith(inputs.runner || 'depot-macos-latest', 'depot-macos-') gate, the misrouting ::error:: plus exit 1, and that no continue-on-error is used.

Written for commit 29176a0. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Added CI checks to validate macOS runner identity, fail fast on misrouted runners, and emit clear diagnostic guidance for corrective action.
    • Expanded end-to-end test guardrails to assert runner identity is captured, detect misrouting and duplicate-queue scenarios, and update success messaging to reflect the broader coverage.

Review Change Stack

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@vercel

vercel Bot commented May 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment May 28, 2026 12:20pm
cmux-staging Building Building Preview, Comment May 28, 2026 12:20pm

@coderabbitai

coderabbitai Bot commented May 28, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Adds an early E2E workflow step that enforces Depot runner identity when inputs.runner resolves to depot-macos-*, failing if the actual runner.name is not depot-*. Updates tests to assert the guard, its startsWith logic, fail-fast misrouting error+exit, the continue-on-error prohibition, and the PASS message.

Changes

Runner Identity Validation Guard

Layer / File(s) Summary
Runner identity validation guard and test coverage
.github/workflows/test-e2e.yml, tests/test_ci_self_hosted_guard.sh
Inserted a workflow step that checks when inputs.runner starts with depot-macos- and validates runner.name matches depot-*, emitting an ::error:: and exiting on mismatch. check_e2e_runner_fallbacks was extended with grep/AWK assertions to verify the RUNNER_CONTEXT_NAME, the startsWith logic, the misrouting error+exit path, retained continue-on-error prohibition, and an updated PASS message.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • manaflow-ai/cmux#4922: Extends E2E runner-fallback validation and touches test-e2e.yml and tests/test_ci_self_hosted_guard.sh with related guard logic.
  • manaflow-ai/cmux#4915: Related changes to the CI guard script and workflow wiring that run the same test script and add checks.

Poem

I’m a rabbit in the CI glade, ears high for every run,
I sniff the runner names at dawn and guard when things go wrong.
If depot-* is promised but another one appears,
I thump and raise an ::error:: — tests catch misroutes with cheers! 🐇


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (2 errors, 1 warning)

Check name Status Explanation Resolution
Cmux Swift Concurrency ❌ Error PR introduces 585 new Swift files with legacy async patterns: ObservableObject/@published in AuthManager.swift and 34+ other files, plus DispatchQueue synchronization. Replace ObservableObject/@published with @Observable and @State/value snapshots; refactor DispatchQueue to async/await, actors, or modern signals.
Cmux User-Facing Error Privacy ❌ Error Error message "resolved outside Depot" exposes internal CI provider infrastructure details (multiple runner providers) violating rules to keep provider implementation details in sanitized logs only. Remove provider-specific details from user-visible error; use generic language like "Runner identity validation failed" without revealing specific providers.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (15 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Guard E2E Depot runner identity' clearly and specifically summarizes the main change: adding an identity validation guard for the E2E workflow's Depot runner.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PR contains no Swift code changes; only modifies YAML workflow and Bash shell script files, making Swift actor isolation check inapplicable.
Cmux Swift Blocking Runtime ✅ Passed PR only modifies .github/workflows/test-e2e.yml (YAML) and tests/test_ci_self_hosted_guard.sh (shell); no Swift production code changes, so check not applicable.
Cmux No Hacky Sleeps ✅ Passed Changes add validation to test-e2e.yml (GitHub Actions YAML, explicitly out-of-scope per rule) and test scaffolding. No hacky sleeps, delays, or polling introduced.
Cmux Algorithmic Complexity ✅ Passed PR modifies only GitHub Actions workflow and test validation script—out of scope for algorithmic complexity rule which applies to production code, not CI/CD workflows or test scaffolding.
Cmux Swift @Concurrent ✅ Passed PR contains no Swift code changes—only YAML workflow and shell script modifications. @concurrent annotation check is not applicable.
Cmux Swift File And Package Boundaries ✅ Passed PR modifies GitHub workflow YAML and shell test scripts, not Swift application code. Check applies only to production Swift changes.
Cmux Swift Logging ✅ Passed PR contains no Swift code changes (only YAML workflow and bash script modifications); Swift logging check does not apply.
Cmux Full Internationalization ✅ Passed PR changes only CI/CD workflows and test scripts, which are explicitly exempt from internationalization requirements per the rules (operational docs, tests, developer-facing infrastructure).
Cmux Swiftui State Layout ✅ Passed PR contains only workflow and shell script changes with no SwiftUI code; custom check for SwiftUI state layout is not applicable.
Cmux Architecture Rethink ✅ Passed The custom check applies to Swift architecture changes, but this PR only modifies YAML workflow and shell script files—no Swift code is changed.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR modifies only CI workflow YAML and bash scripts, not Swift source code. The auxiliary window close shortcuts check is not applicable.
Description check ✅ Passed PR description covers all required sections: summary of changes (why the identity guard was added), detailed testing approach (actionlint, shell script tests, diff check), and includes reviewer tag.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-e2e-depot-runner-guard

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 28, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds a runner identity guard to the manual E2E workflow so that jobs requesting a depot-macos-* label fail immediately — with a clear diagnostic — if GitHub routes the run to a non-Depot self-hosted runner. The companion test script is extended to machine-verify the guard stays wired.

  • .github/workflows/test-e2e.yml: Inserts a new step before checkout that reads runner.name via RUNNER_CONTEXT_NAME, matches it against depot-*, and emits ::error:: + exit 1 on mismatch. The if: condition uses startsWith(inputs.runner || 'depot-macos-latest', 'depot-macos-') so the check applies to all two Depot macOS runner choices, not just the default.
  • tests/test_ci_self_hosted_guard.sh: Adds three assertions (grep -Fq for the env wiring and the startsWith predicate; an awk state machine for the reject branch) to keep the guard provably present in CI.

Confidence Score: 5/5

CI-only change that adds a fail-fast guard and matching test assertions; no application code, auth, or data paths are touched.

Both changed files are CI workflow and test scaffolding. The guard logic is straightforward — a case statement with set -euo pipefail, a correctly scoped if: condition that covers all depot-macos-* runner choices, and a safe env-var approach to read runner.name without clashing with built-in variables. The test extension uses grep and awk patterns that accurately mirror the workflow content. No production behavior is affected.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/test-e2e.yml Adds a "Validate Depot runner identity" guard step that fails fast when a depot-macos-* label resolves to a non-Depot runner; correct use of runner.name via env, set -euo pipefail, and case pattern matching.
tests/test_ci_self_hosted_guard.sh Extends the existing CI self-hosted guard test with three new assertions: RUNNER_CONTEXT_NAME wiring, startsWith gate for all depot-macos-* labels, and awk-verified reject branch containing both the ::error:: echo and exit 1.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[workflow_dispatch triggered] --> B{inputs.runner starts\nwith depot-macos-?}
    B -- No --> E[Skip identity guard]
    B -- Yes --> C[Validate Depot runner identity step\nREQUESTED_RUNNER = inputs.runner OR depot-macos-latest\nRUNNER_CONTEXT_NAME = runner.name]
    C --> D{RUNNER_CONTEXT_NAME\nstarts with depot-*?}
    D -- Yes --> F[Log: Resolved runner matches depot-*? yes\nProceed to Checkout]
    D -- No --> G[echo ::error:: misrouting message\nexit 1 — job fails fast]
    E --> F
Loading

Reviews (4): Last reviewed commit: "Guard E2E Depot runner identity" | Re-trigger Greptile

Comment on lines +43 to +59
- name: Validate Depot runner identity
if: ${{ (inputs.runner || 'depot-macos-latest') == 'depot-macos-latest' }}
env:
REQUESTED_RUNNER: ${{ inputs.runner || 'depot-macos-latest' }}
RUNNER_CONTEXT_NAME: ${{ runner.name }}
RUNNER_CONTEXT_ENVIRONMENT: ${{ runner.environment }}
run: |
set -euo pipefail
echo "Requested runner: $REQUESTED_RUNNER"
echo "Actual runner: $RUNNER_CONTEXT_NAME ($RUNNER_CONTEXT_ENVIRONMENT)"
case "$RUNNER_CONTEXT_NAME" in
depot-*) ;;
*)
echo "::error::depot-macos-latest resolved to '$RUNNER_CONTEXT_NAME', expected a Depot runner named depot-*. Remove depot-macos-latest from non-Depot self-hosted runners or choose an explicit runner."
exit 1
;;
esac

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 The identity guard only fires when inputs.runner resolves to depot-macos-latest. If depot-macos-14 is accidentally registered on a non-Depot self-hosted runner (the same scenario that motivated this PR), the step is skipped entirely and the job silently continues on the wrong host. Dropping the == 'depot-macos-latest' equality check and instead always running when the requested label starts with depot- would extend coverage to both options.

Suggested change
- name: Validate Depot runner identity
if: ${{ (inputs.runner || 'depot-macos-latest') == 'depot-macos-latest' }}
env:
REQUESTED_RUNNER: ${{ inputs.runner || 'depot-macos-latest' }}
RUNNER_CONTEXT_NAME: ${{ runner.name }}
RUNNER_CONTEXT_ENVIRONMENT: ${{ runner.environment }}
run: |
set -euo pipefail
echo "Requested runner: $REQUESTED_RUNNER"
echo "Actual runner: $RUNNER_CONTEXT_NAME ($RUNNER_CONTEXT_ENVIRONMENT)"
case "$RUNNER_CONTEXT_NAME" in
depot-*) ;;
*)
echo "::error::depot-macos-latest resolved to '$RUNNER_CONTEXT_NAME', expected a Depot runner named depot-*. Remove depot-macos-latest from non-Depot self-hosted runners or choose an explicit runner."
exit 1
;;
esac
- name: Validate Depot runner identity
if: ${{ startsWith(inputs.runner || 'depot-macos-latest', 'depot-') }}
env:
REQUESTED_RUNNER: ${{ inputs.runner || 'depot-macos-latest' }}
RUNNER_CONTEXT_NAME: ${{ runner.name }}
RUNNER_CONTEXT_ENVIRONMENT: ${{ runner.environment }}
run: |
set -euo pipefail
echo "Requested runner: $REQUESTED_RUNNER"
echo "Actual runner: $RUNNER_CONTEXT_NAME ($RUNNER_CONTEXT_ENVIRONMENT)"
case "$RUNNER_CONTEXT_NAME" in
depot-*) ;;
*)
echo "::error::$REQUESTED_RUNNER resolved to '$RUNNER_CONTEXT_NAME', expected a Depot runner named depot-*. Remove $REQUESTED_RUNNER from non-Depot self-hosted runners or choose an explicit runner."
exit 1
;;
esac

@coderabbitai

coderabbitai Bot commented May 28, 2026

Copy link
Copy Markdown

Actionable comments posted: 0

@lawrencecchen
lawrencecchen force-pushed the feat-e2e-depot-runner-guard branch from c518883 to 73febe5 Compare May 28, 2026 11:36

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 73febe5. Configure here.

Comment thread .github/workflows/test-e2e.yml Outdated
coderabbitai[bot]
coderabbitai Bot previously requested changes May 28, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/test-e2e.yml:
- Around line 56-57: The error message hardcodes "depot-macos-latest" instead of
reflecting the actual requested runner; update the echo in the echo/exit block
that references RUNNER_CONTEXT_NAME to use the REQUESTED_RUNNER variable (use
$REQUESTED_RUNNER) so the output reads "$REQUESTED_RUNNER resolved to
'$RUNNER_CONTEXT_NAME', expected a Depot runner named depot-*..." ensuring
failures report the exact requested label.

In `@tests/test_ci_self_hosted_guard.sh`:
- Around line 66-69: The test currently greps for the allow-branch pattern
'depot-*) ;;' which validates the wrong case; change the assertions to verify
the reject/mismatch branch in "$E2E_FILE" instead by asserting that the mismatch
branch contains the misrouting error message and an 'exit 1' call (i.e., ensure
the branch that handles non-Depot resolution logs the misrouting error and exits
with status 1); apply this fix to both occurrences that currently check for
'depot-*) ;;' so the test actually validates fail-fast behavior for
test-e2e.yml.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 476a7fdc-2e7b-4213-b2c1-d3a0d058a20e

📥 Commits

Reviewing files that changed from the base of the PR and between c518883 and 73febe5.

📒 Files selected for processing (2)
  • .github/workflows/test-e2e.yml
  • tests/test_ci_self_hosted_guard.sh

Comment thread .github/workflows/test-e2e.yml Outdated
Comment thread tests/test_ci_self_hosted_guard.sh Outdated
coderabbitai[bot]
coderabbitai Bot previously requested changes May 28, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/test-e2e.yml:
- Around line 51-57: Remove raw runner identifiers from outputs: stop echoing
RUNNER_CONTEXT_NAME and RUNNER_CONTEXT_ENVIRONMENT and avoid including
RUNNER_CONTEXT_NAME in the error text. Instead, print a non-sensitive status
(e.g., "Requested runner: $REQUESTED_RUNNER" and "Resolved runner: <redacted>
(matches depot-*? yes/no)") and change the error to a generic message that
mentions REQUESTED_RUNNER only in sanitized form or uses a generic placeholder;
keep the existing case guard and exit behavior around the depot-* check (refer
to the variables RUNNER_CONTEXT_NAME, REQUESTED_RUNNER,
RUNNER_CONTEXT_ENVIRONMENT and the case block) so the logic is unchanged while
removing unredacted identifiers from logs and error output.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 23e8a6d1-b3c9-4cb6-a363-9df6e9bdfed9

📥 Commits

Reviewing files that changed from the base of the PR and between 73febe5 and afb954a.

📒 Files selected for processing (2)
  • .github/workflows/test-e2e.yml
  • tests/test_ci_self_hosted_guard.sh

Comment thread .github/workflows/test-e2e.yml
@lawrencecchen
lawrencecchen force-pushed the feat-e2e-depot-runner-guard branch from afb954a to 29176a0 Compare May 28, 2026 12:17
@coderabbitai

coderabbitai Bot commented May 28, 2026

Copy link
Copy Markdown

Actionable comments posted: 0

@lawrencecchen
lawrencecchen dismissed stale reviews from coderabbitai[bot] and coderabbitai[bot] May 28, 2026 12:36

Stale CodeRabbit review addressed in 29176a0; final CodeRabbit follow-up posted 0 actionable comments and all checks passed.

@lawrencecchen
lawrencecchen merged commit b1a68e9 into main May 28, 2026
19 checks passed
@lawrencecchen
lawrencecchen deleted the feat-e2e-depot-runner-guard branch May 28, 2026 12:37

This branch was successfully deployed

1 active deployment
Preview – cmux — 29176a01 Deployed May 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant