Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -100,13 +100,18 @@ jobs:
build-sign-notarize-nightly:
needs: decide
if: needs.decide.outputs.should_build == 'true'
# Run on the macOS 15 host that carries the signing/notarization secrets.
# Pinned to WarpBuild, NOT vars.MACOS_RUNNER_15 (= cmux-aws-macos-15, a
# self-hosted mini): the self-hosted runners are not provisioned for
# codesigning (no Developer-ID/WWDR chain in the keychain), so `codesign`
# fails with "unable to build chain to self-signed root" / errSecInternalComponent.
# Signing + notarization must run on the Warp image that carries the chain
# until the self-hosted minis are provisioned for signing.
# The Swift app still selects an Xcode with the macOS 26 SDK so it adopts
# Liquid Glass on Tahoe. The Ghostty CLI helper is built separately and
# injected before signing, preferring a pre-26 SDK when the runner image has
# one but falling back to the selected app Xcode when the image only ships
# Xcode 26. The helper build remains required and lipo-verified below.
runs-on: ${{ vars.MACOS_RUNNER_15 || 'warp-macos-15-arm64-6x' }}
runs-on: warp-macos-15-arm64-6x
timeout-minutes: 30
steps:
- name: Checkout build ref
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,12 @@ jobs:
# Build the app on macOS 26 so SDK-gated SwiftUI Liquid Glass code compiles
# into stable releases. The real universal Ghostty CLI helper is built on
# macOS 15 above because Zig 0.15.2 cannot link it on macOS 26.
runs-on: ${{ vars.MACOS_RUNNER_26 || 'warp-macos-26-arm64-6x' }}
# Pinned to WarpBuild, NOT vars.MACOS_RUNNER_26 (= cmux-macos-26, a
# self-hosted mini): this job codesigns + notarizes, and the self-hosted
# runners lack the Developer-ID/WWDR chain in their keychain, so codesign
# fails with errSecInternalComponent. Signing must run on the Warp image
# that carries the chain until the minis are provisioned for signing.
runs-on: warp-macos-26-arm64-6x

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release SDK lane test mismatch

Medium Severity

Pinning build-sign-notarize to runs-on: warp-macos-26-arm64-6x drops the vars.MACOS_RUNNER_26 expression that tests/test_ci_release_sdk_lane.sh still requires in that job, so workflow-guard-tests fails even though the job still targets macOS 26.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 2208eea. Configure here.

# Notarization wait times vary on Apple's side; v0.64.14 finished at 19m16s
# and v0.64.15 attempt 1 was killed by a 20-minute budget mid-notarization.
timeout-minutes: 40
Expand Down
Loading