Skip to content

ci: allow the iOS workspace SwiftPM lockfile in the resolved-policy check - #8191

Closed
azooz2003-bit wants to merge 1 commit into
mainfrom
fix-ios-lockfile-policy
Closed

azooz2003-bit wants to merge 1 commit into
mainfrom
fix-ios-lockfile-policy

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 15, 2026 •

Copy link
Copy Markdown
Collaborator

workflow-guard-tests fails on current main (and every branch cut from it) with Unexpected cmux Package.resolved location: ios/cmux.xcworkspace/xcshareddata/swiftpm/Package.resolved. #8180 committed that iOS workspace lockfile, but check-package-resolved-policy.py only recognized the macOS project's workspace lockfile. It slipped through because PR CI is disabled during the advisory experiment; found while dispatching CI for #8186.

The iOS workspace is a cmux-owned Xcode workspace whose resolution should be tracked at exactly that fixed location (same intent as the macOS lockfile: resolution changes visible in PR diffs), so the fix generalizes the expected-location check to a tuple of workspace lockfiles and adds the iOS one. python3 scripts/check-package-resolved-policy.py goes red -> green on this branch.

🤖 Generated with Claude Code


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Summary by cubic

Allows the iOS workspace SwiftPM Package.resolved path in check-package-resolved-policy.py to stop workflow-guard-tests failures. Extends the lockfile policy to cover both macOS and iOS cmux-owned workspaces.

  • Bug Fixes
    • Generalized the expected lockfile check to accept workspace-level paths and added ios/cmux.xcworkspace/xcshareddata/swiftpm/Package.resolved.
    • Keeps resolution changes visible in PR diffs and restores CI to green.

Written for commit 4355072. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Updated package lockfile validation to recognize both supported Xcode project- and workspace-level locations.
    • Prevents valid workspace configurations from being incorrectly flagged during checks.

…heck

#8180 committed
ios/cmux.xcworkspace/xcshareddata/swiftpm/Package.resolved, but
check-package-resolved-policy.py only recognized the macOS project's
workspace lockfile, so workflow-guard-tests fails on main and on every
branch cut from it ("Unexpected cmux Package.resolved location"). It
went unnoticed because PR CI is currently disabled for the advisory
experiment.

The iOS workspace is a cmux-owned Xcode workspace whose resolution
should be tracked at exactly that fixed location, matching the policy's
intent that resolution changes stay visible in PR diffs. Generalize the
expected-location check to a tuple of workspace lockfiles and add the
iOS one.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5654ce39-9b28-4af7-b69c-f3eb54464de8

📥 Commits

Reviewing files that changed from the base of the PR and between 271a51f and 4355072.

📒 Files selected for processing (1)
  • scripts/check-package-resolved-policy.py

📝 Walkthrough

Walkthrough

The package resolution policy now recognizes both the existing project-level and additional workspace-level Xcode Package.resolved locations.

Changes

Workspace Package.resolved validation

Layer / File(s) Summary
Accepted lockfile paths
scripts/check-package-resolved-policy.py
Adds WORKSPACE_PACKAGE_RESOLVED and updates is_expected_lockfile_path to accept paths listed in it.

Estimated code review effort: 1 (Trivial) | ~3 minutes

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the change: allowing the iOS workspace SwiftPM lockfile in the policy check.
Description check ✅ Passed The description covers what changed, why, and testing, but omits template sections like review trigger and checklist.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed Only a Python policy script changed; no Swift sources or actor-isolation-relevant code were modified.
Cmux Swift Blocking Runtime ✅ Passed Diff only changes a Python policy script; no Swift production code or blocking synchronization was introduced.
Cmux Browser Automation Off-Main ✅ Passed PR only changes scripts/check-package-resolved-policy.py to accept another Package.resolved path; no browser-automation routing or tests were touched.
Cmux Expensive Synchronous Load ✅ Passed Only scripts/check-package-resolved-policy.py changed; no Swift production/UI code or load paths were touched.
Cmux Cache Substitution Correctness ✅ Passed Python policy-script change only adds another expected Package.resolved path; no cache-opportunistic substitution or persistence/history/snapshot read was introduced.
Cmux No Hacky Sleeps ✅ Passed Diff only adds a workspace lockfile constant and expands expected-path validation; no sleeps, timers, polling, or wall-clock waits were introduced.
Cmux Algorithmic Complexity ✅ Passed Only adds a 2-item tuple of fixed lockfile paths; membership check in is_expected_lockfile_path stays constant-time and no scalable scans were introduced.
Cmux Swift Concurrency ✅ Passed Diff only updates a Python policy script; no cmux Swift code changed, so no legacy async patterns were introduced.
Cmux Swift @Concurrent ✅ Passed No Swift files changed in this PR; only scripts/check-package-resolved-policy.py was modified, so the Swift concurrency rule does not apply.
Cmux Swift Package Boundaries ✅ Passed Only scripts/check-package-resolved-policy.py changed; no Swift production files were touched, so the boundary rule is not applicable.
Cmux Swiftpm Lockfiles ✅ Passed PASS: The PR only updates the policy checker script; no Package.swift, Package.resolved, .gitignore, workflow, or Xcode project files were changed.
Cmux Swift Logging ✅ Passed Diff only changes scripts/check-package-resolved-policy.py; no Swift production/runtime code or logging changes were introduced.
Cmux User-Facing Error Privacy ✅ Passed The only new path is in CI policy logic; no end-user-facing copy now exposes prohibited vendor/provider details.
Cmux Full Internationalization ✅ Passed Only a CI policy script changed; no user-facing Swift/web/UI text or locale assets were added or modified.
Cmux Swiftui State Layout ✅ Passed Only scripts/check-package-resolved-policy.py changed; no SwiftUI/AppKit source files or state/layout changes are present, so the rule isn't implicated.
Cmux Architecture Rethink ✅ Passed Diff only updates a Python policy script to accept another fixed lockfile path; no Swift lifecycle/ownership changes.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR only changes scripts/check-package-resolved-policy.py; no Swift windows, WindowGroup, or cmuxAuxiliaryWindowIdentifiers edits, so the shortcut rule is not in scope.
Cmux Source Artifacts ✅ Passed Only scripts/check-package-resolved-policy.py changed; it’s a hand-written policy script, not generated output or an artifact path.
Cmux No Test Or Debug Seam In Production Source ✅ Passed Only scripts/check-package-resolved-policy.py changed; no Swift production Sources/ files or test/debug seams were added.
Cmux No Ambient Global State ✅ Passed No production Swift files were changed; the patch only updates a Python policy script and adds a constant, so the ambient-global-state rule is not implicated.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-ios-lockfile-policy

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR fixes a CI breakage introduced by PR #8180, which committed the iOS workspace lockfile at ios/cmux.xcworkspace/xcshareddata/swiftpm/Package.resolved—a path that check-package-resolved-policy.py did not recognize, causing workflow-guard-tests to fail on every branch cut from main.

  • Defines WORKSPACE_PACKAGE_RESOLVED as a tuple containing the existing macOS workspace lockfile and the new iOS workspace lockfile, then updates is_expected_lockfile_path to check tuple membership instead of equality—a minimal, correct fix.
  • XCODE_PACKAGE_RESOLVED is retained as a standalone constant and still used at line 340 for the xcode_package_reference_changed guard, which is appropriate since that guard is specifically about the macOS Xcode project file.

Confidence Score: 4/5

Safe to merge; the change is a targeted one-line fix to a CI policy script with no production runtime impact.

The fix is correct and minimal—the tuple membership check works as intended, and XCODE_PACKAGE_RESOLVED is correctly preserved for the macOS project-level guard. The only gap is that there is no analogous guard for iOS workspace project-level package reference changes, mirroring an existing asymmetry that was accepted for the macOS side before this PR.

scripts/check-package-resolved-policy.py — the xcode_package_reference_changed block could be extended to also cover the iOS workspace project file if that project uses Xcode-managed SwiftPM references.

Important Files Changed

Filename Overview
scripts/check-package-resolved-policy.py Adds the iOS workspace lockfile path to WORKSPACE_PACKAGE_RESOLVED and updates is_expected_lockfile_path to use tuple membership; fixes the CI failure. No equivalent xcode_package_reference_changed-style enforcement exists for the iOS workspace project file.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[tracked_lockfiles from git ls-files] --> B{is_allowed_vendor_path?}
    B -- yes --> C[skip]
    B -- no --> D{is_expected_lockfile_path?}
    D -- yes: lockfile in WORKSPACE_PACKAGE_RESOLVED --> E[pass]
    D -- yes: has_skipped_part --> F[skip]
    D -- yes: parent in Package.swift roots --> E
    D -- no --> G[error: Unexpected Package.resolved location]

    subgraph WORKSPACE_PACKAGE_RESOLVED
        WR1["cmux.xcodeproj/project.xcworkspace/.../Package.resolved"]
        WR2["ios/cmux.xcworkspace/.../Package.resolved NEW"]
    end

    D --> WORKSPACE_PACKAGE_RESOLVED
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[tracked_lockfiles from git ls-files] --> B{is_allowed_vendor_path?}
    B -- yes --> C[skip]
    B -- no --> D{is_expected_lockfile_path?}
    D -- yes: lockfile in WORKSPACE_PACKAGE_RESOLVED --> E[pass]
    D -- yes: has_skipped_part --> F[skip]
    D -- yes: parent in Package.swift roots --> E
    D -- no --> G[error: Unexpected Package.resolved location]

    subgraph WORKSPACE_PACKAGE_RESOLVED
        WR1["cmux.xcodeproj/project.xcworkspace/.../Package.resolved"]
        WR2["ios/cmux.xcworkspace/.../Package.resolved NEW"]
    end

    D --> WORKSPACE_PACKAGE_RESOLVED
Loading

Comments Outside Diff (1)

  1. scripts/check-package-resolved-policy.py, line 338-345 (link)

    P2 No enforcement for iOS workspace project-level package reference changes

    The xcode_package_reference_changed guard (lines 338–345) enforces that when cmux.xcodeproj/project.pbxproj gains or loses Xcode-managed SwiftPM package references the macOS workspace Package.resolved must also change. There is no analogous check for the iOS workspace. If ios/cmux.xcworkspace (or its contained .xcodeproj) has its project-level SwiftPM package references updated without regenerating ios/cmux.xcworkspace/xcshareddata/swiftpm/Package.resolved, the policy script will silently pass. This is a narrower gap than the one this PR fixes—Package.swift-driven changes are caught by the existing dependency closure logic—but project-level XCRemoteSwiftPackageReference edits inside the iOS project file would slip through the same way the macOS case would without its dedicated guard.

Reviews (1): Last reviewed commit: "ci: allow the iOS workspace SwiftPM lock..." | Re-trigger Greptile

@azooz2003-bit

Copy link
Copy Markdown
Collaborator Author

Superseded: main got a fuller rework of check-package-resolved-policy.py that accepts the iOS workspace lockfile (verified passing on a current checkout). Closing in favor of that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant