Skip to content

fix(ci): route package gate to isolated self-hosted runners - #2608

Draft
seonghobae wants to merge 1 commit into
fix/strix-sandbox-state-diagnostics-aa11d478from
fix/package-self-hosted-only-20261009
Draft

seonghobae wants to merge 1 commit into
fix/strix-sandbox-state-diagnostics-aa11d478from
fix/package-self-hosted-only-20261009

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Scope

Follow-up to #2573, which carries closed #2261. Global runner routing stays with #2565; shared LiteLLM/auto/App integration stays with #2560 and its current owners.

  • Route both package producer and trusted inspector through CWL CI isolated with explicit self-hosted/Linux/x64/isolation labels. No GitHub-hosted fallback.
  • Preserve producer/inspector separation, exact central checkout, credential non-persistence and fail-closed artifacts.
  • Repair pre-existing time-sensitive audit fixtures without changing production freshness policy.
  • Make five sandbox fixtures declare synthetic guest home so the approved home-based scratch location does not alter their intended launcher/traversal witnesses. Production home denial is unchanged.
  • Remove linter error suppression. Declare custom labels only.
  • Record the complete user Goal: central self-hosted execution, conditional substantive AI App approval, literal auto and personal LiteLLM custody.

Verification

Candidate: ea25461bd3550f5bf4f3f657663235f6f610f52e.

  • Exact baseline cwd reproduced the CLI fixture failure.
  • Final CI-mode full suite: 5,351 passed, 4 skipped, 40 subtests, exit 0 (343.51 s).
  • Fresh focused suite: 137 passed, exit 0.
  • Independent review of the seven final file hashes found no new blocking source defect; parent verified 7/7 reviewed hashes.
  • git diff --check passed.
  • Actionlint 1.7.12 remains NONPASS on four job workflow identity schema properties; no ignore remains. Actual cross-repo checkout acceptance is NOT_RUN.
  • HTTPError cleanup ResourceWarning remains visible; not suppressed.

Remaining gates

Draft / HOLD. Actual group access, disposable runner assignment/cleanup canary and current-head required checks are not proven. No actual personal LiteLLM auto model review, formal author-distinct App approval, or protected merge is claimed. Reuse existing service-key custody; no duplicate key issuance, master key export, runner relabeling, protection relaxation or predetermined review verdict.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant