The frozen 'comfy' uv group cannot track a moving host by hand: a latest
ComfyUI checkout already needs comfyui-frontend-package==1.44.19, comfy_aimdo,
alembic and blake3 that the old pin never listed, so 'import comfy' fails
outright against latest. Make Tier 2 source ComfyUI's deps from upstream
instead of a hand-frozen list, keyed by trigger:
- schedule (nightly) -> latest origin/master + ComfyUI's own requirements.txt,
capped by constraints/comfy-ceiling.txt (torch<2.8, numpy<2, coremltools 9).
Early-warning canary; a hard upstream conflict fails on purpose, signalling
a needed toolchain bump rather than silently floating past the ANE ceiling.
- PR label / dispatch -> pinned requires-comfyui SHA + frozen 'comfy' group.
Reproducible gate, immune to overnight drift.
Make the runner self-contained so there's no manual local fiddling:
- clone ComfyUI into COMFY_DIR on first run; checkout the resolved ref.
- symlink custom_nodes/ComfyUI-CoreMLSuite -> GITHUB_WORKSPACE in-workflow,
refusing to clobber a real directory (guards a misconfigured COMFY_DIR).
- convert-if-missing for all UNet variants (none/8/6/4), cached across runs;
only the checkpoint stays a runner-local artifact.
- record resolved ComfyUI SHA + mode in the job step summary.
Add the Phase 6 quant tradeoff matrix (bench/scripts/quant_matrix.py) to the
bench lane and upload .md alongside .json. Pass --no-sync to every 'uv run' so
the post-install steps keep the deps just installed instead of re-syncing to
the lock and dropping them.