Repository navigation
ci: run all macOS jobs on paid managed runners (retire self-hosted minis) - #6422
azooz2003-bit wants to merge 2 commits into
Conversation
We're no longer using the self-hosted Mac minis for CI. Remove the vars.MACOS_RUNNER_* indirection from every workflow so macOS jobs target paid managed runners directly, with no self-hosted option: - vars.MACOS_RUNNER_15 / _26 / _26_RELEASE / _DISPLAY / _IOS references removed; jobs now pin warp (warp-macos-15/26-arm64-6x), depot (perf-activation PRs, unchanged), or hosted macos-26 (iOS). - perf-activation and test-e2e keep their manual `inputs.runner` override but default to warp instead of the self-hosted variable. - Make the tests-job pin permanent (it was a temporary 2026-06-18 workaround for the austin minis' missing GUI session) and update stale comments/descriptions that still advertised the self-hosted fleet. No workflow still references MACOS_RUNNER or the cmux-aws-macos-15 / cmux-macos-26 labels. Follow-up (settings, not code): the now-unused vars.MACOS_RUNNER_* repo variables can be deleted and the self-hosted runners deregistered. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
📝 WalkthroughWalkthroughAll GitHub Actions workflows that previously used ChangesRunner Variable Retirement and Hardcoded Label Adoption
Estimated code review effort🎯 2 (Simple) | ⏱️ ~18 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 21 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (21 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR retires the self-hosted Mac minis from CI and wires every macOS job directly to paid managed runners (WarpBuild or Depot). The root cause —
Confidence Score: 5/5Safe to merge — all changes are mechanical label substitutions with no logic alterations to the actual build, test, or release steps. Every workflow change is a straightforward find-and-replace of the vars.MACOS_RUNNER_* expression with the paid label that was already its baked-in fallback, so no job lands on a different runner than it did before. The guard tests are updated in lock-step and add new defence-in-depth checks. Documentation is comprehensively rewritten to match the new state. No files require special attention. The guard scripts (tests/test_ci_self_hosted_guard.sh and tests/test_ci_release_sdk_lane.sh) are worth a read to confirm the new AWK patterns match the updated YAML, but they are internally consistent with the workflow changes. Important Files Changed
Reviews (2): Last reviewed commit: "ci: update runner guards + docs for paid..." | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Line 676: The hardcoded REQUESTED_RUNNER value warp-macos-15-arm64-6x at line
676 violates both the test contract in tests/test_ci_self_hosted_guard.sh (which
expects REQUESTED_RUNNER to reference vars.MACOS_RUNNER_DISPLAY) and the runtime
guard logic in the guard script (which expects REQUESTED_RUNNER to match the
depot-* pattern). Replace the hardcoded string REQUESTED_RUNNER:
warp-macos-15-arm64-6x with a proper variable reference like REQUESTED_RUNNER:
${{ vars.MACOS_RUNNER_DISPLAY }} or equivalent, ensuring it resolves to a value
matching the depot-* pattern required by the guard script.
In @.github/workflows/test-e2e.yml:
- Around line 54-57: Update the guard test expectations in
tests/test_ci_self_hosted_guard.sh at lines 99-100 to match the new runner
expression format that now resolves directly to 'warp-macos-15-arm64-6x' instead
of using vars.MACOS_RUNNER_15. Replace the old expression check with the new one
that expects startsWith((!inputs.runner || inputs.runner == 'auto') &&
'warp-macos-15-arm64-6x' || inputs.runner, 'depot-macos-') to align with the
updated workflow at line 54 of .github/workflows/test-e2e.yml and prevent the
guard test from failing.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 0183b144-ce86-4da3-bd08-bdc7073d0cb7
📒 Files selected for processing (12)
.github/workflows/build-ghosttykit.yml.github/workflows/ci-macos-compat.yml.github/workflows/ci.yml.github/workflows/ios-testflight.yml.github/workflows/nightly.yml.github/workflows/perf-activation.yml.github/workflows/release.yml.github/workflows/reload-build.yml.github/workflows/test-depot.yml.github/workflows/test-e2e.yml.github/workflows/test-ios.yml.github/workflows/tmux-corpus.yml
Match test_ci_self_hosted_guard.sh and test_ci_release_sdk_lane.sh to the paid-only workflow config (literal warp/depot labels instead of the removed vars.MACOS_RUNNER_*), preserving their intent: paid runners only, depot identity validation, macOS-15-helper/macOS-26-app SDK split, and a new explicit check that retired self-hosted labels never reappear. Update docs/ci-runners.md to the paid-only model. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/test_ci_self_hosted_guard.sh`:
- Around line 711-713: The grep patterns used to detect hosted runners in the CI
check are too restrictive, using character classes like [a-z0-9]+ and [a-z0-9.]+
which miss runner labels with multiple dash-separated segments such as
macos-15-xlarge or ubuntu-24.04-arm. Replace the character classes in both the
main grep pattern and the exemption filter (at the two locations where this
appears) with [^[:space:]#]+ to match any characters except whitespace or inline
comments, ensuring the patterns capture runner labels regardless of their suffix
complexity while still stopping at whitespace or comment boundaries. This change
should be applied to both the grep pattern on line 711 and the corresponding
exemption filter pattern noted as also applying to lines 725-728.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: a487e26c-3f48-4158-bc85-3430286052e9
📒 Files selected for processing (3)
docs/ci-runners.mdtests/test_ci_release_sdk_lane.shtests/test_ci_self_hosted_guard.sh
| hits="$(grep -rnE "runs-on:[[:space:]]*(ubuntu-[a-z0-9.]+|macos-[a-z0-9]+)[[:space:]]*$" "$ROOT_DIR/.github/workflows" \ | ||
| | grep -vE "/(test-ios|ios-testflight)\.yml:[0-9]+:[[:space:]]*runs-on:[[:space:]]*macos-26[[:space:]]*$" \ | ||
| || true)" |
There was a problem hiding this comment.
🧹 Nitpick | 🔵 Trivial
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
pattern='^[[:space:]]*runs-on:[[:space:]]*(ubuntu-[a-z0-9.]+|macos-[a-z0-9]+)[[:space:]]*$'
for line in \
"runs-on: macos-26" \
"runs-on: macos-15-xlarge" \
"runs-on: ubuntu-24.04-arm" \
"runs-on: macos-26 # iOS exemption comment"
do
if [[ "$line" =~ $pattern ]]; then
echo "MATCH: $line"
else
echo "MISS : $line"
fi
doneRepository: manaflow-ai/cmux
Length of output: 199
🏁 Script executed:
# Check what runner labels are actually used in the repo's workflows
find .github/workflows -name "*.yml" -o -name "*.yaml" | head -20Repository: manaflow-ai/cmux
Length of output: 635
🏁 Script executed:
# Examine the current guard check more closely
grep -A 20 "check_no_bare_github_hosted_runners" tests/test_ci_self_hosted_guard.sh | head -40Repository: manaflow-ai/cmux
Length of output: 2277
🏁 Script executed:
# Find actual runs-on labels used in workflows
grep -rh "runs-on:" .github/workflows | sed 's/.*runs-on:[[:space:]]*//; s/[[:space:]]*#.*//' | sort -uRepository: manaflow-ai/cmux
Length of output: 466
🏁 Script executed:
# Check if any actual workflows use inline comments on runs-on lines
grep -r "runs-on:.*#" .github/workflowsRepository: manaflow-ai/cmux
Length of output: 42
🏁 Script executed:
# Check what bare GitHub-hosted label formats actually exist in the workflows
grep -rh "runs-on:" .github/workflows | grep -E "(ubuntu-|macos-)" | grep -v "{{" | head -20Repository: manaflow-ai/cmux
Length of output: 522
🏁 Script executed:
# Test the proposed regex fix against real patterns
bash << 'EOF'
set -euo pipefail
# Current narrow pattern
current_pattern='runs-on:[[:space:]]*(ubuntu-[a-z0-9.]+|macos-[a-z0-9]+)[[:space:]]*$'
# Proposed fix
proposed_pattern='^[[:space:]]*runs-on:[[:space:]]*(ubuntu-[^[:space:]#]+|macos-[^[:space:]#]+)[[:space:]]*(#.*)?$'
test_cases=(
"runs-on: macos-26"
"runs-on: ubuntu-24.04"
"runs-on:macos-26"
" runs-on: macos-26"
"runs-on: macos-26 # comment"
"runs-on: warp-macos-26" # should NOT match (paid runner)
"runs-on: ubuntu-latest"
)
echo "=== CURRENT PATTERN ==="
for line in "${test_cases[@]}"; do
if [[ "$line" =~ $current_pattern ]]; then
echo "✓ MATCH: $line"
else
echo "✗ MISS : $line"
fi
done
echo ""
echo "=== PROPOSED PATTERN ==="
for line in "${test_cases[@]}"; do
if [[ "$line" =~ $proposed_pattern ]]; then
echo "✓ MATCH: $line"
else
echo "✗ MISS : $line"
fi
done
EOFRepository: manaflow-ai/cmux
Length of output: 538
🏁 Script executed:
# Check the actual lines in the test file around 711-728
sed -n '705,730p' tests/test_ci_self_hosted_guard.shRepository: manaflow-ai/cmux
Length of output: 1694
🏁 Script executed:
# Check the second guard function around line 725
sed -n '720,735p' tests/test_ci_self_hosted_guard.shRepository: manaflow-ai/cmux
Length of output: 887
🏁 Script executed:
# Verify the proposed pattern handles the exemption filter correctly
bash << 'EOF'
set -euo pipefail
# Test the proposed exemption filter
exemption_pattern='^[[:space:]]*runs-on:[[:space:]]*macos-26([[:space:]]*(#.*)?)?$'
test_exemptions=(
"runs-on: macos-26"
"runs-on: macos-26 # comment"
" runs-on: macos-26"
"runs-on: macos-26 # longer comment here"
"runs-on: macos-26-xlarge" # should NOT match
"runs-on: macos-15" # should NOT match
)
echo "=== TESTING EXEMPTION FILTER ==="
for line in "${test_exemptions[@]}"; do
if [[ "$line" =~ $exemption_pattern ]]; then
echo "✓ MATCH (exempt): $line"
else
echo "✗ MISS (not exempt): $line"
fi
done
EOFRepository: manaflow-ai/cmux
Length of output: 357
🏁 Script executed:
# Check if ubuntu labels are used anywhere with problematic patterns
grep -rh "runs-on:.*ubuntu" .github/workflows | head -10Repository: manaflow-ai/cmux
Length of output: 750
🏁 Script executed:
# Verify the current guard actually works on the real codebase
bash << 'EOF'
cd "$(git rev-parse --show-toplevel)"
# Run the actual guard function to see if it passes or fails
set +e
bash tests/test_ci_self_hosted_guard.sh 2>&1 | head -50
exit_code=$?
echo "Guard exit code: $exit_code"
EOFRepository: manaflow-ai/cmux
Length of output: 1701
🏁 Script executed:
# Double-check: are there any bare ubuntu- or macos- labels NOT using variables/expressions?
grep -rh "runs-on:" .github/workflows | grep -vE '(\$\{|\$\(|\{\{)' | grep -E "(ubuntu-|macos-)" | sort -uRepository: manaflow-ai/cmux
Length of output: 154
Regex for hosted-runner detection is narrow but currently effective; hardening recommended for future-proofing.
The regexes on lines 711 and 725 only match macos-[a-z0-9]+ and ubuntu-[a-z0-9.]+, missing patterns like macos-15-xlarge or ubuntu-24.04-arm. The guard currently passes because the repo uses only:
- Bare
macos-26(properly exempted for iOS) - Paid runner prefixes (
warp-*,depot-*,blacksmith-*) - Variable expressions (
${{ vars.LINUX_RUNNER ... }})
However, the pattern should be broadened to catch any future bare hosted labels with extra suffix segments. Change [a-z0-9]+ to [^[:space:]#]+ to match runner labels up to whitespace or inline comments, and update the exemption filter to handle comments as well.
Suggested hardening
- hits="$(grep -rnE "runs-on:[[:space:]]*(ubuntu-[a-z0-9.]+|macos-[a-z0-9]+)[[:space:]]*$" "$ROOT_DIR/.github/workflows" \
- | grep -vE "/(test-ios|ios-testflight)\.yml:[0-9]+:[[:space:]]*runs-on:[[:space:]]*macos-26[[:space:]]*$" \
+ hits="$(grep -rnE "runs-on:[[:space:]]*(ubuntu-[^[:space:]#]+|macos-[^[:space:]#]+)[[:space:]]*(#.*)?$" "$ROOT_DIR/.github/workflows" \
+ | grep -vE "/(test-ios|ios-testflight)\.yml:[0-9]+:[[:space:]]*runs-on:[[:space:]]*macos-26([[:space:]]*(#.*)?)?$" \
|| true)"
@@
- ios_bad="$(grep -rnE "runs-on:[[:space:]]*macos-[a-z0-9]+[[:space:]]*$" \
+ ios_bad="$(grep -rnE "runs-on:[[:space:]]*macos-[^[:space:]#]+[[:space:]]*(#.*)?$" \
"$ROOT_DIR/.github/workflows/test-ios.yml" \
"$ROOT_DIR/.github/workflows/ios-testflight.yml" 2>/dev/null \
- | grep -vE "runs-on:[[:space:]]*macos-26[[:space:]]*$" || true)"
+ | grep -vE "runs-on:[[:space:]]*macos-26([[:space:]]*(#.*)?)?$" || true)"Also applies to: 725–728
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@tests/test_ci_self_hosted_guard.sh` around lines 711 - 713, The grep patterns
used to detect hosted runners in the CI check are too restrictive, using
character classes like [a-z0-9]+ and [a-z0-9.]+ which miss runner labels with
multiple dash-separated segments such as macos-15-xlarge or ubuntu-24.04-arm.
Replace the character classes in both the main grep pattern and the exemption
filter (at the two locations where this appears) with [^[:space:]#]+ to match
any characters except whitespace or inline comments, ensuring the patterns
capture runner labels regardless of their suffix complexity while still stopping
at whitespace or comment boundaries. This change should be applied to both the
grep pattern on line 711 and the corresponding exemption filter pattern noted as
also applying to lines 725-728.
…ettingsCore + wire 110 fork files Key upstream commits: - SSH ControlMaster PTY-resize fix (manaflow-ai#6432) - profiling capture action (manaflow-ai#6433) - hookless agent forking revert (manaflow-ai#6434) - notification jump-focus fix for nested tabs (manaflow-ai#6416) - ~100% CPU re-render loop fix - right-sidebar custom sidebar tabs (manaflow-ai#6430) — adds SurfaceKind.customSidebar - terminal scroll-speed multiplier (manaflow-ai#6422) - Settings recover from offscreen frames (manaflow-ai#5770) Strategy: - Default 3-way merge (no -X theirs) — only 15 conflicts vs Frankenstein corruption in P58's -X theirs attempt. - Took fork's TerminalController.swift wholesale (huge fork v2 handler surface). - Took upstream's pbxproj wholesale — re-added CMUXSessionDaemon + CMUXSettingsCore packages to BOTH cmux + cmux-cli targets (P58 only added cmux-cli, leaving CmuxSettingsRegistry symbols undefined at link time for the app). - Wired 110 fork-only Swift files (Sources/Herdr*, StableLayout/, etc.) lost when taking upstream's pbxproj. - Removed dup TerminalController+CustomSidebarCommands.swift (fork TC already has all v2CustomSidebar* handlers). - Removed dup titlebarShortcutHintShouldShow (now in RightSidebarChromeStyle.swift). - Added SurfaceKind.customSidebar + SessionBlueprintEncoder case for it. - Made Workspace.isProgrammaticSplit non-private (consumed by Workspace+CustomSidebarPane). Manual conflict resolutions: - AppDelegate.shortcut routing: kept fork's selectNext/PreviousTopLevelTab but composed with upstream's preferredMainWindowContextForShortcutRouting. - Workspace.swift session restore: combined fork's Claude restorability filter with upstream's Self.resumeBindingForSessionRestore helper. - WorkspaceContentView canvas mode: nested fork's shouldBypassTopBar branch inside the non-canvas arm. Build green: cmux app + cmuxTests both compile clean. Co-Authored-By: Claude <noreply@anthropic.com>
We've decided to stop using the self-hosted Mac minis for CI and run everything on paid managed runners.
What
Removes the
vars.MACOS_RUNNER_*indirection from every workflow, so macOS jobs target paid runners directly with no self-hosted option:${{ vars.MACOS_RUNNER_15/_26/_26_RELEASE/_DISPLAY/_IOS || '…' }}expressions replaced with their paid default: warp (warp-macos-15/26-arm64-6x), depot (perf-activation on PRs, unchanged), or hosted macos-26 (iOS).perf-activationandtest-e2ekeep their manualinputs.runneroverride but default to warp instead of the self-hosted variable.testsjob pin (a temporary 2026-06-18 workaround for the austin minis' missing GUI session) is now permanent; stale comments/descriptions that advertised the self-hosted fleet are updated.No workflow references
MACOS_RUNNERor thecmux-aws-macos-15/cmux-macos-26labels anymore. All 12 changed workflows passyaml.safe_load.Why
The self-hosted minis (austin, studio) had no logged-in GUI session, so
testmanagerdcouldn't broker the XCTest control session and thetestsjob ran 0 tests there — randomly red on unrelated PRs. Paid managed runners (warp/depot) are ephemeral, always in a usable session, and don't have this failure mode.Follow-up (settings, not in this PR)
The now-unreferenced
vars.MACOS_RUNNER_*repo variables can be deleted, and the self-hosted runners deregistered in Settings → Actions → Runners.🤖 Generated with Claude Code
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Summary by cubic
Move all macOS CI to paid managed runners and retire the self-hosted Mac minis. Update docs and guard tests to enforce paid-only macOS runs and prevent the flaky XCTest GUI-session failures.
Refactors
vars.MACOS_RUNNER_*; pinwarp-macos-15/26for most jobs,depotfor perf PRs, andmacos-26for iOS.inputs.runnerfor perf-activation and test-e2e; default now warp with Depot identity guard.docs/ci-runners.mdand guard tests with the paid-only model: ban bare hosted macOS runners (except iOS onmacos-26), block any return of self-hosted labels, and assert the release SDK split using literal Warp labels.Migration
vars.MACOS_RUNNER_*repo variables.Written for commit 71b8ecb. Summary will update on new commits.
Summary by CodeRabbit