Repository navigation
Re-apply Blacksmith macOS CI/CD runner migration - #4984
Conversation
Push-triggered probe (scoped to this branch) to check whether Blacksmith macOS runners pick up jobs before re-attempting the migration reverted in #4926. Delete before merge. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Re-applies the WarpBuild/Depot -> Blacksmith migration that landed as #4902 and was reverted by #4926. The revert was purely a Blacksmith macOS capacity problem (every SKU queued 8m+/65m+ while GitHub-hosted picked up in <10s), not a defect. A push-triggered probe on this branch confirmed all three Blacksmith macOS SKUs (15/26/latest) now pick up jobs in ~16s, so the migration is safe to re-attempt. Switches every macOS job to blacksmith-6vcpu-macos-{15,26,latest}: - ci.yml (tests, tests-build-and-lag, release-build, ui-regressions) - build-ghosttykit, nightly, release, test-depot, perf-activation, tmux-corpus (drops the self-hosted label), ci-macos-compat - test-e2e default -> blacksmith-6vcpu-macos-15; keeps depot-macos-* as fallback dispatch options and the Depot identity guard (now correctly skipped on the Blacksmith default) - re-adds .github/actionlint.yaml allowlist for the Blacksmith labels - re-adds the launchctl asuser Aqua-session wrapper for the Cmd-Tab perf bench (Blacksmith runners run in launchd's system bootstrap) - tests/test_ci_self_hosted_guard.sh asserts Blacksmith macOS runners Removes the temporary capacity probe used to gate this re-attempt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
📝 WalkthroughWalkthroughWorkflows and CI validation now resolve macOS runners via repo variables ChangesParameterized macOS Runner Selection
🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly Related PRs
Poem
🚥 Pre-merge checks | ✅ 17 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (17 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR re-applies the WarpBuild → Blacksmith macOS runner migration after a temporary capacity-driven revert. The core change routes all paid macOS CI jobs through two repository variables (
Confidence Score: 5/5Safe to merge — changes are limited to CI runner selection and tooling; no application code, signing logic, or production behaviour is touched. All twelve changed files are CI/CD workflow YAML, a shell guard script, and documentation. Every macOS job gains a vars.MACOS_RUNNER_*-based fallback chain so the provider can be flipped without a commit. The launchctl asuser wrapping in perf-activation.yml is correctly scoped to the Aqua-session visibility problem on Blacksmith. The Depot identity guard in test-e2e.yml was updated in lockstep with the runner-resolution expression and still fires correctly on explicit Depot selections. No logic regressions were found. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Workflow triggered] --> B{inputs.runner set\nand not 'auto'?}
B -- Yes --> C[Use inputs.runner directly\ne.g. blacksmith-6vcpu-macos-15\nwarp-macos-15-arm64-6x\ndepot-macos-latest]
B -- No --> D{vars.MACOS_RUNNER_15\nrepo variable set?}
D -- Yes --> E[Use vars.MACOS_RUNNER_15\ne.g. blacksmith-6vcpu-macos-15]
D -- No --> F[Fallback to hardcoded\nwarp-macos-15-arm64-6x]
C --> G{starts with\ndepot-macos-?}
E --> G
F --> G
G -- Yes --> H[Run Depot identity guard\nvalidate runner.name]
G -- No --> I[Proceed with job]
H --> I
Reviews (3): Last reviewed commit: "ci: make manual perf/e2e runner default ..." | Re-trigger Greptile |
|
Caution Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted. Error details |
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
tests/test_ci_self_hosted_guard.sh (1)
33-33:⚠️ Potential issue | 🟠 Major | ⚡ Quick winUpdate awk patterns to check for the new default runner.
Lines 33 and 40 still check for
depot-macos-latest, but the E2E workflow default was changed toblacksmith-6vcpu-macos-15(as reflected in line 61). Since these awk checks validate that the run-name and concurrency grouping include the runner with its default fallback, they should check for the new default rather than the old one.🔧 Proposed fix to align with the new default
/^run-name:/ { saw_run_name=1 - if ($0 ~ /inputs\.test_filter/ && ($0 ~ /inputs\.runner/ || $0 ~ /depot-macos-latest/) && ($0 ~ /inputs\.ref/ || $0 ~ /github\.ref_name/)) { + if ($0 ~ /inputs\.test_filter/ && ($0 ~ /inputs\.runner/ || $0 ~ /blacksmith-6vcpu-macos-15/) && ($0 ~ /inputs\.ref/ || $0 ~ /github\.ref_name/)) { saw_run_name_dynamic=1 } } /^concurrency:/ { in_concurrency=1; next } in_concurrency && /^jobs:/ { in_concurrency=0 } in_concurrency && /cancel-in-progress:[[:space:]]*true/ { saw_cancel=1 } - in_concurrency && (/inputs\.runner/ || /depot-macos-latest/) { saw_runner=1 } + in_concurrency && (/inputs\.runner/ || /blacksmith-6vcpu-macos-15/) { saw_runner=1 } in_concurrency && /inputs\.test_filter/ { saw_test_filter=1 }Also applies to: 40-40
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@tests/test_ci_self_hosted_guard.sh` at line 33, Update the awk pattern checks that still look for the old runner string "depot-macos-latest" to the new default "blacksmith-6vcpu-macos-15" in the conditional that matches inputs.test_filter/inputs.runner/github.ref_name (the if condition containing $0 ~ /inputs\.test_filter/ && ($0 ~ /inputs\.runner/ || $0 ~ /depot-macos-latest/) && ($0 ~ /inputs\.ref/ || $0 ~ /github\.ref_name/)); change both occurrences (lines checking for the runner in that awk expression and the similar one at the other occurrence) so the fallback runner match uses /blacksmith-6vcpu-macos-15/ instead of /depot-macos-latest/.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/perf-activation.yml:
- Around line 142-153: The workflow step assumes an interactive Aqua session and
uses sudo/launchctl asuser which will fail on Blacksmith macOS runners; update
the step that invokes scripts/bench-window-visibility.swift to (1) detect
whether an interactive Aqua session exists (e.g., check if /dev/console user
equals the current user and/or whether launchctl asuser succeeds) and if not
skip or mark the bench as Unsupported on this runner, (2) avoid unconditional
sudo -n & inner sudo -u usage — run the swift script as the current runner user
when possible or gate the sudo calls behind a conditional that ensures
passwordless sudo is configured, and (3) ensure APP_PATH/home layout is
consistent by only switching to CONSOLE_USER when CONSOLE_USER == "$(whoami)" or
when explicitly required; reference the invocation of launchctl asuser, sudo -n,
and scripts/bench-window-visibility.swift with flags --cmd-tab-activation and
--cg-visibility when implementing these guards.
---
Outside diff comments:
In `@tests/test_ci_self_hosted_guard.sh`:
- Line 33: Update the awk pattern checks that still look for the old runner
string "depot-macos-latest" to the new default "blacksmith-6vcpu-macos-15" in
the conditional that matches inputs.test_filter/inputs.runner/github.ref_name
(the if condition containing $0 ~ /inputs\.test_filter/ && ($0 ~
/inputs\.runner/ || $0 ~ /depot-macos-latest/) && ($0 ~ /inputs\.ref/ || $0 ~
/github\.ref_name/)); change both occurrences (lines checking for the runner in
that awk expression and the similar one at the other occurrence) so the fallback
runner match uses /blacksmith-6vcpu-macos-15/ instead of /depot-macos-latest/.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 71dd8b45-4bfe-4560-aae5-cd2c25fd9b49
📒 Files selected for processing (11)
.github/actionlint.yaml.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/perf-activation.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml.github/workflows/tmux-corpus.ymltests/test_ci_self_hosted_guard.sh
Make the Blacksmith<->WarpBuild switch a one-step repo-variable change with no PR, so a future Blacksmith macOS capacity outage (the cause of the #4926 revert) can be reverted instantly. Every paid macOS job now uses: runs-on: ${{ vars.MACOS_RUNNER_15 || 'warp-macos-15-arm64-6x' }} (and _26) An unset variable falls back to WarpBuild, so a missing var never breaks CI. The repo variables are set to the blacksmith-6vcpu-macos-{15,26} labels. - ci.yml, build-ghosttykit, nightly, release, test-depot, tmux-corpus, ci-macos-compat (matrix os) route runs-on through the vars - perf-activation / test-e2e defaults become inputs.runner || vars.MACOS_RUNNER_15 || 'warp-...'; explicit dispatch choices and the Depot identity guard are unchanged - test_ci_self_hosted_guard.sh now asserts each paid job references vars.MACOS_RUNNER_* or a Blacksmith/Warp label (never a free GitHub-hosted runner), the real intent of issue #385 - actionlint allowlist keeps the Warp fallback labels alongside Blacksmith/Depot - docs/macos-ci-runners.md documents the switch procedure Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 316e73b. Configure here.
| CONSOLE_UID="$(id -u "$CONSOLE_USER")" | ||
| sudo -n launchctl asuser "$CONSOLE_UID" sudo -n -u "$CONSOLE_USER" -E \ | ||
| env PATH="$PATH" DEVELOPER_DIR="$DEVELOPER_DIR" \ | ||
| bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift '$APP_PATH' 'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility" \ |
There was a problem hiding this comment.
Unconditional sudo with no fallback unlike test-e2e pattern
Low Severity
The launchctl asuser wrapper unconditionally requires sudo -n without first checking availability, unlike the robust pattern in test-e2e.yml which guards with if sudo -n true 2>/dev/null and falls back to direct execution with a warning. The stat -f %Su /dev/console call also lacks 2>/dev/null || true error suppression and the $CONSOLE_USER != "root" safety check. Since perf-activation.yml triggers on pull_request and can fall back to WarpBuild runners (when vars.MACOS_RUNNER_15 is unset), this step will hard-fail on any runner without passwordless sudo, where the old direct swift invocation would have succeeded.
Reviewed by Cursor Bugbot for commit 316e73b. Configure here.
Codex review caught that perf-activation.yml and test-e2e.yml set the
workflow_dispatch `runner` input default to a blacksmith literal. GitHub
populates inputs.runner with that default, so inputs.runner || vars.MACOS_RUNNER
never reached the repo variable on manual runs, and there was no Warp option to
pick during an outage. Flipping the variable would not have redirected manual
runs.
Default the input to 'auto' and resolve it (and the empty pull_request case) to
vars.MACOS_RUNNER_15 then the warp fallback:
(!inputs.runner || inputs.runner == 'auto')
&& (vars.MACOS_RUNNER_15 || 'warp-macos-15-arm64-6x')
|| inputs.runner
Add warp-macos-15/26 dropdown options so an operator can also select Warp
directly. Update the guard's e2e identity-guard assertion and the runner docs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/perf-activation.yml (1)
138-154:⚠️ Potential issue | 🟠 Major | ⚡ Quick winBench step hardcodes the Blacksmith-specific
launchctl asuserwrapper, butruns-oncan still resolve to the warp fallback.On
pull_requesteventsinputs.runneris empty, so Line 39 resolves tovars.MACOS_RUNNER_15 || 'warp-macos-15-arm64-6x'. Whenvars.MACOS_RUNNER_15is unset the job lands onwarp-macos-15-arm64-6x, yet this step now unconditionally re-enters viasudo -n launchctl asuser … sudo -n -u …(per the AI summary, this replaced a directswift …invocation). If the warp fallback doesn't provide passwordless sudo plus a console Aqua session,sudo -nfails immediately and takes the whole job down on every PR in that state.The Blacksmith path is verified working — this is strictly about the warp fallback that the PR intentionally keeps. Gating the wrapper on the resolved runner preserves the previous direct-invocation behavior off Blacksmith:
🛡️ Proposed fix: gate the Aqua re-entry to Blacksmith runners
- name: Run Cmd-Tab activation benchmark + env: + RESOLVED_RUNNER: ${{ inputs.runner || vars.MACOS_RUNNER_15 || 'warp-macos-15-arm64-6x' }} run: | set -euo pipefail APP_PATH="$HOME/Library/Developer/Xcode/DerivedData/cmux-$PERF_TAG/Build/Products/Debug/cmux DEV $PERF_TAG.app" - # The GitHub Actions runner process runs in launchd's system - # bootstrap, not the console user's Aqua session, so windows - # created by apps launched via NSWorkspace.openApplication do - # not show up in CGWindowListCopyWindowInfo([.optionOnScreenOnly]). - # Re-enter the Aqua session via launchctl asuser before running - # the bench so visibility polling sees real on-screen windows. - CONSOLE_USER="$(stat -f %Su /dev/console)" - CONSOLE_UID="$(id -u "$CONSOLE_USER")" - sudo -n launchctl asuser "$CONSOLE_UID" sudo -n -u "$CONSOLE_USER" -E \ - env PATH="$PATH" DEVELOPER_DIR="$DEVELOPER_DIR" \ - bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift '$APP_PATH' 'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility" \ - > perf-results/cmd-tab-activation.txt + if [[ "$RESOLVED_RUNNER" == blacksmith-* ]]; then + # Blacksmith jobs run in launchd's system bootstrap, not the + # console user's Aqua session, so windows created via + # NSWorkspace.openApplication do not show up in + # CGWindowListCopyWindowInfo([.optionOnScreenOnly]). Re-enter the + # Aqua session via launchctl asuser so visibility polling sees them. + CONSOLE_USER="$(stat -f %Su /dev/console)" + CONSOLE_UID="$(id -u "$CONSOLE_USER")" + sudo -n launchctl asuser "$CONSOLE_UID" sudo -n -u "$CONSOLE_USER" -E \ + env PATH="$PATH" DEVELOPER_DIR="$DEVELOPER_DIR" \ + bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift '$APP_PATH' 'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility" \ + > perf-results/cmd-tab-activation.txt + else + swift scripts/bench-window-visibility.swift "$APP_PATH" "com.cmuxterm.app.debug.$PERF_TAG" 30 --cmd-tab-activation --cg-visibility \ + > perf-results/cmd-tab-activation.txt + fi cat perf-results/cmd-tab-activation.txtTo confirm whether the wrapper is even viable on the fallback (in case you'd rather not branch):
Do WarpBuild macOS runners (warp-macos-15-arm64-6x) run jobs in a logged-in console Aqua session and provide passwordless sudo / launchctl asuser support?🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/perf-activation.yml around lines 138 - 154, The step currently always uses the launchctl asuser + sudo wrapper (the long line invoking sudo -n launchctl asuser "$CONSOLE_UID" sudo -n -u "$CONSOLE_USER" -E bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift ..."), which breaks on non-Blacksmith runners; change it to detect support and fall back to the original direct swift invocation: use APP_PATH, CONSOLE_USER and CONSOLE_UID as already computed, run a quick probe like sudo -n launchctl asuser "$CONSOLE_UID" true (or another non-destructive check) and if that exits zero run the existing wrapper invocation, otherwise run bash -c "cd '$PWD' && swift scripts/bench-window-visibility.swift '$APP_PATH' 'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility" without the launchctl/sudo re-entry so the job doesn’t fail on warp runners.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/perf-activation.yml:
- Around line 138-154: The step currently always uses the launchctl asuser +
sudo wrapper (the long line invoking sudo -n launchctl asuser "$CONSOLE_UID"
sudo -n -u "$CONSOLE_USER" -E bash -c "cd '$PWD' && swift
scripts/bench-window-visibility.swift ..."), which breaks on non-Blacksmith
runners; change it to detect support and fall back to the original direct swift
invocation: use APP_PATH, CONSOLE_USER and CONSOLE_UID as already computed, run
a quick probe like sudo -n launchctl asuser "$CONSOLE_UID" true (or another
non-destructive check) and if that exits zero run the existing wrapper
invocation, otherwise run bash -c "cd '$PWD' && swift
scripts/bench-window-visibility.swift '$APP_PATH'
'com.cmuxterm.app.debug.$PERF_TAG' 30 --cmd-tab-activation --cg-visibility"
without the launchctl/sudo re-entry so the job doesn’t fail on warp runners.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 7833ec58-4e88-49fc-bfeb-30afee289624
📒 Files selected for processing (12)
.github/actionlint.yaml.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/nightly.yml.github/workflows/perf-activation.yml.github/workflows/release.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml.github/workflows/tmux-corpus.ymldocs/macos-ci-runners.mdtests/test_ci_self_hosted_guard.sh


Re-applies the WarpBuild/Depot → Blacksmith migration from #4902, which was reverted by #4926.
The revert was purely a Blacksmith macOS capacity problem, not a code defect: at the time every Blacksmith macOS SKU sat queued 8m+ in a probe and 65m+ on live main CI, while GitHub-hosted runners picked up in under 10s, so every main push got CANCELLED.
Capacity is back. A push-triggered probe on this branch ran trivial jobs on all three Blacksmith macOS SKUs and they picked up in ~16s and finished successfully:
blacksmith-6vcpu-macos-15blacksmith-6vcpu-macos-26blacksmith-6vcpu-macos-latestWhat changed
Every macOS job moves to
blacksmith-6vcpu-macos-{15,26,latest}(1:1 with the former 6x Warp jobs, macOS 15 vs 26 preserved):ci.yml— tests, tests-build-and-lag, release-build, ui-regressionsbuild-ghosttykit.yml,nightly.yml,release.yml,test-depot.yml,tmux-corpus.yml(also drops theself-hostedlabel),ci-macos-compat.yml(matrix os)perf-activation.yml— default + dispatch choices → Blacksmith, SPM cache keys scoped by runner, and the Cmd-Tab activation bench re-wrapped inlaunchctl asuserso it runs in the console Aqua session (Blacksmith runners run in launchd's system bootstrap, whereCGWindowListCopyWindowInfo([.optionOnScreenOnly])can't see on-screen windows)test-e2e.yml— default →blacksmith-6vcpu-macos-15, keepsdepot-macos-*as fallback dispatch options. The existing Depot identity guard now correctly skips on the Blacksmith default and still validates explicit Depot runs..github/actionlint.yaml— re-adds the Blacksmith label allowlist (keeps the Depot labels test-e2e still references)tests/test_ci_self_hosted_guard.sh— asserts Blacksmith macOS runners on the paid jobs ([Security] HIGH-1: Self-hosted CI runner exposed to fork pull requests #385)The temporary capacity probe used to gate this re-attempt is removed.
Test plan
./tests/test_ci_self_hosted_guard.shpasses against this tree🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.Note
Medium Risk
Changes which provider runs release/nightly and main CI and adds launchctl/sudo for perf benchmarks; mis-set repo variables or runner env differences could cause queueing or flaky GUI/visibility tests.
Overview
Routes all paid macOS CI/CD jobs through repo variables
MACOS_RUNNER_15andMACOS_RUNNER_26, with WarpBuild labels as workflow fallbacks when variables are unset—so Blacksmith vs Warp can be flipped viagh variable set/deletewithout a code change (docs/macos-ci-runners.md).Workflow updates:
ci.yml, release/nightly, ghosttykit, compat matrix,test-depot, andtmux-corpus(dropsself-hostedlabel) usevars.MACOS_RUNNER_* || 'warp-…'.perf-activation.ymlandtest-e2e.ymladdrunner: auto(followsMACOS_RUNNER_15), Blacksmith/Warp dispatch options, runner-scoped SPM cache keys, and updated concurrency/run-name expressions; Depot choices and identity guard remain for explicitdepot-macos-*runs.Blacksmith-specific fix: Cmd-Tab bench in
perf-activation.ymlruns underlaunchctl asuserthe console user so window visibility checks work outside the runner’s system bootstrap.Tooling:
.github/actionlint.yamlallowlists Blacksmith labels;tests/test_ci_self_hosted_guard.shnow requiresvars.MACOS_RUNNER_*or Blacksmith/Warp labels (not Warp-only).Reviewed by Cursor Bugbot for commit 2a06dc9. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Re-applies the macOS CI/CD runner migration to Blacksmith and routes all macOS jobs through repo variables for fast Blacksmith↔WarpBuild switching. Capacity is back; Blacksmith SKUs pick up in ~16s, so main CI is unblocked.
MACOS_RUNNER_15/MACOS_RUNNER_26with WarpBuild fallback; repo vars point toblacksmith-6vcpu-macos-{15,26}inci.yml,build-ghosttykit.yml,ci-macos-compat.yml,nightly.yml,release.yml,test-depot.yml, andtmux-corpus.yml. Update.github/actionlint.yamlto allow Blacksmith (incl.blacksmith-6vcpu-macos-latest) and keep Warp/Depot.test-e2e.yml: default runner isautoand resolves tovars.MACOS_RUNNER_15then Warp; keepsdepot-macos-*options and the identity guard; scope SPM cache keys and run metadata by the resolved runner.perf-activation.yml: default runner isautoand resolves tovars.MACOS_RUNNER_15then Warp; scope SPM cache keys by runner, and run the Cmd-Tab bench vialaunchctl asuserfor Aqua visibility.tests/test_ci_self_hosted_guard.shnow enforces use ofvars.MACOS_RUNNER_*or a Blacksmith/Warp label (and updates the Depot identity assertion). Remove the temporary capacity probe.docs/macos-ci-runners.mddocuments the switch (repo variables, no PR) and how manualperf/e2eruns followauto→ repo variable → Warp.Written for commit 2a06dc9. Summary will update on new commits.
Review in cubic
Summary by CodeRabbit