Repository navigation
CI: pin signing/notarization jobs to WarpBuild (fix self-hosted codesign errSecInternalComponent) - #6264
Conversation
…ernalComponent) vars.MACOS_RUNNER_15 (cmux-aws-macos-15) and MACOS_RUNNER_26 (cmux-macos-26) resolve to self-hosted minis that are NOT provisioned for codesigning: their keychains lack the Developer-ID/WWDR chain, so `codesign --sign` fails with 'unable to build chain to self-signed root' / errSecInternalComponent (nightly build-sign-notarize failed repeatedly; the same code signs fine on Warp). Pin the two signing+notarization jobs to the Warp images directly: - nightly.yml build-sign-notarize-nightly -> warp-macos-15-arm64-6x - release.yml build-sign-notarize -> warp-macos-26-arm64-6x The non-signing helper build (release build-ghostty-cli-helper) stays on the shared var. Revert to the vars indirection once the minis are provisioned for signing.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughTwo CI workflow files ( ChangesmacOS Runner Pinning
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
Poem
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2208eea. Configure here.
| # runners lack the Developer-ID/WWDR chain in their keychain, so codesign | ||
| # fails with errSecInternalComponent. Signing must run on the Warp image | ||
| # that carries the chain until the minis are provisioned for signing. | ||
| runs-on: warp-macos-26-arm64-6x |
There was a problem hiding this comment.
Release SDK lane test mismatch
Medium Severity
Pinning build-sign-notarize to runs-on: warp-macos-26-arm64-6x drops the vars.MACOS_RUNNER_26 expression that tests/test_ci_release_sdk_lane.sh still requires in that job, so workflow-guard-tests fails even though the job still targets macOS 26.
Reviewed by Cursor Bugbot for commit 2208eea. Configure here.
…6264 follow-up) (#6265) #6264 pinned release.yml build-sign-notarize to warp-macos-26-arm64-6x (the self-hosted minis lack the signing chain). This guard still asserted the old vars.MACOS_RUNNER_26 indirection string, so workflow-guard-tests failed on main and every PR after #6264 merged. Update the expected needle to the pinned Warp runner. nightly.yml is intentionally not covered by this guard; the self-hosted guard already accepts the warp-macos-NN-arm64 label.
…h as fallback (#14821) * ci: build the nightly app on the trusted owned minis first, Blacksmith as fallback build-nightly-app was hard-coded to blacksmith-12vcpu-macos-26, so a push to main never considered an owned mini (run 36239331473). Attempt 1 of a push or schedule run on main now asks for vars.CI_SEED_TRUSTED_POOL, the trusted owned pool (no pull request runners; the glaeda hook admits only main's push and schedule jobs), because the job holds the ci-cache-writer R2 keys and the Sentry token and its app is signed and shipped. Forks, rc/**, dispatches, fast dogfood and re-runs keep Blacksmith. - owned_pool_rescue.py / ci-owned-pool-rescue.yml: watch nightly.yml runs like a picker-less side lane (NIGHTLY_WORKFLOW_PATH). Recognise glaeda-trusted-* labels. Allow one queue round behind a DerivedData seed. A stuck or refused build is re-run on Blacksmith, unless a newer nightly run on main is still pending. - nightly.yml: an owned runner folds its workspace path into the release compile-cache key, so the mini and Blacksmith lineages never evict each other (Blacksmith's key is unchanged). Clear build outputs a persistent runner kept. - runner_label_policy.py: CI_SEED_TRUSTED_POOL may only name a glaeda-trusted-* label; the health report and variable check read it. - Signing and notarization stay on Blacksmith (unproven on owned Macs; #6264). Docs list every macOS job's route. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * ci: send the nightly app build to cmux15's trusted runner only Both trusted minis carry glaeda-trusted-std-xcode-26.6, but cmuxs-mac-mini-6 also runs the team dev-build worker as the same user, so the shipped build should never land there. Seeding keeps both, so CI_SEED_TRUSTED_POOL is unchanged. build-nightly-app now asks for ["<CI_SEED_TRUSTED_POOL>", "<CI_NIGHTLY_TRUSTED_RUNNER>"]: the trusted pool and one runner's own glaeda-runner-<name> label (glaeda-cmux-runner's runner_label()). Either variable empty means Blacksmith, so this is inert until cmux15's runner is re-registered with that label and the variable is set. - runner_label_policy.py: CI_NIGHTLY_TRUSTED_RUNNER may only be a lowercase glaeda-runner-* label (also safe inside the JSON runs-on). - ci-health-report.yml / ci-repo-variables.yml: report it. - ci-owned-pool-rescue.yml: watch nightly runs only while both are set. - Docs and tests follow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>


Why
The nightly
build-sign-notarize-nightlyjob fails repeatedly at "Codesign apps":Root cause: repo vars
MACOS_RUNNER_15 = cmux-aws-macos-15andMACOS_RUNNER_26 = cmux-macos-26resolve to self-hosted minis that aren't provisioned for codesigning (their keychains lack the Developer-ID/WWDR chain). The Warp fallback label never triggers because the var is set. Same code signs fine on Warp (the 03:12 nightly succeeded); it fails whenever the job lands on a mini. (Same runner-routing root cause as the earliernpm: command not foundnightly failure.)Fix
Pin the two jobs that codesign + notarize directly to the Warp images, bypassing the self-hosted vars:
nightly.ymlbuild-sign-notarize-nightly→warp-macos-15-arm64-6xrelease.ymlbuild-sign-notarize→warp-macos-26-arm64-6xThe non-signing
build-ghostty-cli-helperjob stays on the shared var (it doesn't sign). This is "for now" — revert to the vars indirection once the minis are provisioned for signing (or moved behind runner groups). Workflow-only.🤖 Generated with Claude Code
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Note
Low Risk
Workflow-only runner routing for two jobs; no app, signing secrets, or build script changes—only where CI executes existing sign/notarize steps.
Overview
Nightly and release codesign/notarize jobs no longer honor
vars.MACOS_RUNNER_15/vars.MACOS_RUNNER_26, which were routing those jobs to self-hosted minis wherecodesignfails with missing Developer-ID/WWDR chain (errSecInternalComponent).nightly.ymlbuild-sign-notarize-nightlynow useswarp-macos-15-arm64-6x;release.ymlbuild-sign-notarizeuseswarp-macos-26-arm64-6x. Inline comments document that this is temporary until self-hosted runners are provisioned for signing.Non-signing work (e.g. release
build-ghostty-cli-helper) is unchanged and still uses the repo runner vars.Reviewed by Cursor Bugbot for commit 2208eea. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Pin the signing and notarization CI jobs to WarpBuild macOS runners to fix codesign failures on self-hosted minis. Nightly and release signing should now pass reliably.
Written for commit 2208eea. Summary will update on new commits.
Summary by CodeRabbit