Skip to content

ci(macos-x64): measure WebKit in a docker-mac-x64 guest; keep the hosted render lane - #261

Merged
zackees merged 8 commits into
mainfrom
ci/macos-x64-guest
Sep 17, 2026
Merged

zackees merged 8 commits into
mainfrom
ci/macos-x64-guest

Conversation

@zackees

@zackees zackees commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Fixes #251.

Result: a Linux-hosted macOS guest cannot render a sketch

The acceptance criteria allow recording why and keeping the hosted lane when the guest can't render. That's what this PR does. The reason was measured in a real guest, not assumed.

macos-x64-guest-webkit-probe.yml does the following:

  1. Cross-builds the Intel fastled binary on Linux.
  2. Boots a zackees/docker-mac-x64 Recovery guest (macOS 13.0.1) on ubuntu-latest.
  3. Loads a WebGL2 probe page in both:
    • the shipped viewer, via fastled --internal-viewer, the same WKWebView window fastled <sketch> opens;
    • Safari 16.1.

Each client reports through the fastled server's /viewer-log route.

Final run (35191433924):

client WebGL2 WebGL1 OffscreenCanvas rAF frames in 30 s
shipped viewer (WKWebView) NO NO absent 919
Safari 16.1 NO NO absent 909

Pages load and animate at about 30 fps, but neither WebKit client offers any WebGL. The guest has a plain QEMU VGA adapter and no GPU. bootstrap.ts makes WebGL2 a hard requirement, so no sketch can render there, and no screenshot of a render is possible. A newer macOS image wouldn't add a GPU.

Measured duration: guest boot plus probe took 391–579 s across runs, and the whole job 9–16 min. The probe is not a per-PR gate. It runs on demand, and on PRs that touch the probe, so it can be repeated if the guest image or GPU situation changes.

Findings about the Recovery guest, kept in the probe

  • Home directory: /var/root is read-only, so fastled needs HOME under /tmp.
  • Missing tools: no python3, open, screencapture, safaridriver, osascript or system_profiler.
  • Driving Safari:
    • Given a URL argument, Safari treats it as a sandboxed file path and asks for consent nothing in the guest can grant.
    • LaunchServices (LSOpenCFURLRef / LSOpenFromURLSpec, tried in this PR) brings Safari forward without loading the URL.
    • A home-page preference written before Safari's first launch does load the page. The probe uses that.

Changes

  • New: .github/workflows/macos-x64-guest-webkit-probe.yml, ci/macos-x64/probe-guest.sh and ci/macos-x64/webgl.html. The job fails unless both the viewer and Safari report.
  • macos-arm-live-test.yml: the comment now records why execution stays on the hosted runner.
  • Flake fix (found by this PR's CI, in the test(terminal): run the browser terminal suite in CI, on real Safari, and close the Windows slot leak #259 tests): the blocked-writer clients now type into the shell only after it prints, with a 30 s ready timeout, in both tests/frontend/test_terminal.py and ci/safari_terminal_smoke.py. The failing run was 35191433983: the login shell had printed nothing within 15 s.

No JSPI flags or product code changes.

🤖 Generated with Claude Code

zackees and others added 8 commits September 16, 2026 21:55
Temporary feasibility probe for #251.

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he guest

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ment

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Safari reads a command-line argument as a sandboxed file path and asks for
consent to read it, which nothing in the guest can grant. A dependency-free
helper calls LSOpenCFURLRef, as /usr/bin/open would. Also records the outcome
in macos-arm-live-test.yml.

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…r Safari

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ients

The LaunchServices helper brought Safari forward without loading the URL, so
it is removed. A home page preference written before Safari first runs loads
the page. The probe now fails unless both the shipped viewer and Safari report.

Refs #251

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rint

The slot-release clients sent their command on open. On a slow runner the
login shell had printed nothing within the 15 s ready timeout: only the
terminal's echo of the typed line came back (Linux x86 Terminal Test, run
35191433983). Wait for the shell's first output, as a user would, and allow
30 s. The Safari smoke used the same pattern.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@zackees zackees changed the title ci(macos-x64): Intel macOS viewer and Safari in a docker-mac-x64 guest ci(macos-x64): measure WebKit in a docker-mac-x64 guest; keep the hosted render lane Sep 17, 2026
@zackees
zackees marked this pull request as ready for review September 17, 2026 07:17
@zackees
zackees merged commit 4ebcabd into main Sep 17, 2026
19 checks passed
@zackees
zackees deleted the ci/macos-x64-guest branch September 17, 2026 07:17
@zackees zackees mentioned this pull request Sep 17, 2026
2 of 10 tasks
zackees added a commit that referenced this pull request Sep 18, 2026
CLI:
- `fastled <sketch>` no longer crashes with "Cannot drop a runtime" after
  starting the server (#269).
- `--terminal-cmd` / FASTLED_TERMINAL_CMD runs an agent in the browser
  terminal, and a configured session survives a page reload through a
  single-use reattach token (#254, #267).

Terminal:
- The shell starts in the named directory and emits valid exit frames (#257).
- A client that disconnects mid-write releases its session slot (#256, #258).

Viewer:
- Screen maps registered after setup() now reach the renderer, so sketches
  like Blink no longer show an empty canvas (#250, #264).
- The page no longer overflows the window by 40 px, and the title scales
  with the window (#268, #270).

CI:
- Browser terminal suite on Linux, Windows and real Safari (#259, #260).
- Linux render smoke that fails on a blank canvas (#247, #266).
- Linux dependencies install before setup-soldr, so the dependency cook
  succeeds (#263); lint covers ci/ (#265); an Intel macOS guest WebKit
  probe (#251, #261).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Run macOS viewer rendering in a docker-mac-x64 guest on a Linux runner

1 participant