Skip to content

Guard direct GhosttyKit setup against incompatible Zig - #4706

Merged
teamleaderleo merged 11 commits into
manaflow-ai:mainfrom
Bortlesboat:clawdbot/zig-version-setup-guard
Sep 25, 2026
Merged

teamleaderleo merged 11 commits into
manaflow-ai:mainfrom
Bortlesboat:clawdbot/zig-version-setup-guard

Conversation

@Bortlesboat

@Bortlesboat Bortlesboat commented May 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • centralize the active Zig compatibility check in the existing ghostty-zig-version.sh helper
  • enforce that shared check from both setup.sh and direct ensure-ghosttykit.sh entry points
  • extend the existing workflow-guard regression to cover both consumers and compatible/incompatible active binaries

Upstream alignment

Current main added a shared Ghostty Zig-version helper and setup validation after this PR was opened. This refresh uses that architecture and removes the old duplicate guard script, workflow step, and hard-coded version documentation. Prerelease/build suffixes retain current upstream compatibility semantics.

Testing

  • bash -n scripts/ghostty-zig-version.sh scripts/setup.sh scripts/ensure-ghosttykit.sh tests/test_ghostty_zig_version_sync.sh
  • ./tests/test_ghostty_zig_version_sync.sh (with the workflow's pinned PyYAML==6.0.3 and bashlex==0.18; passes)
  • git diff upstream/main...HEAD --check

The repository's required tagged macOS reload was not runnable from this Windows environment; this PR changes setup shell paths only.

Security / Privacy

  • no credentials, tokens, endpoints, telemetry, or local user paths added
  • the refresh commit is signed with the verified GitHub noreply identity

@vercel

vercel Bot commented May 24, 2026

Copy link
Copy Markdown

@Bortlesboat is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented May 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds a centralized Zig version guard used by setup flows, regression tests covering version scenarios, a CI step running the tests, and contributor instructions for Ghostty’s required Zig version.

Changes

Zig version guard enforcement

Layer / File(s) Summary
Version guard core contract and implementation
scripts/check-zig-version.sh
Reads Ghostty’s minimum Zig version, validates strict semantic versions, checks Zig availability, enforces matching major/minor and sufficient patch versions, and reports the result.
Setup script integration with version check
scripts/setup.sh, scripts/ensure-ghosttykit.sh
Replaces inline Zig checks with centralized validation before setup continues.
Comprehensive regression test for guard behavior
tests/test_ci_zig_version_guard.sh
Uses isolated Zig stubs to test accepted and rejected versions, missing or unparsable versions, automatic Ghostty version extraction, and bypass prevention.
CI validation and contributor documentation
.github/workflows/ci.yml, CONTRIBUTING.md
Checks out submodules, adds the regression test to CI, and documents the required Zig version and compatible installation options.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Suggested reviewers: lawrencecchen

Sequence Diagram(s)

sequenceDiagram
  participant Contributor
  participant SetupScripts
  participant ZigGuard
  participant ZigCLI
  participant CI
  Contributor->>SetupScripts: Run setup or GhosttyKit setup
  SetupScripts->>ZigGuard: Validate required Zig version
  ZigGuard->>ZigCLI: Run zig version
  ZigCLI-->>ZigGuard: Return installed version
  ZigGuard-->>SetupScripts: Return validation status
  CI->>ZigGuard: Run regression scenarios
  ZigGuard-->>CI: Report pass or failure
Loading

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error New setup stderr says "GhosttyKit requires Zig..." and "zig is not installed," exposing upstream/vendor names in user-facing output. Rewrite user-visible errors in cmux terms (e.g. compatible toolchain required) and keep Ghostty/Zig specifics in docs or internal logs.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed No production Swift files changed; diff is limited to CI, scripts, docs, and tests, so actor-isolation rules are not implicated.
Cmux Swift Blocking Runtime ✅ Passed No Swift/runtime files changed; the PR only touches CI, docs, and shell scripts, so the Swift blocking-runtime rule is not applicable.
Cmux Browser Automation Off-Main ✅ Passed PR only changes Zig/setup CI files; no browser automation code or routing files were modified, so the off-main browser-automation rule is unaffected.
Cmux Expensive Synchronous Load ✅ Passed No Swift or agent-history load-path files were changed; the PR only touches CI/scripts/docs, so the check is not applicable.
Cmux Cache Substitution Correctness ✅ Passed The diff only changes workflow YAML and shell scripts/tests; no Swift, TypeScript, or JavaScript production cache-persistence/undo/snapshot code was touched.
Cmux No Hacky Sleeps ✅ Passed The diff adds no new sleeps, timers, polling, or wall-clock waits in shell/runtime scripts; existing delay code in ensure-ghosttykit is unchanged, and workflow YAML is out of scope.
Cmux Algorithmic Complexity ✅ Passed The PR only adds O(1) Zig version checks and test-only fixed-size assertions; no scalable collection scans or hot-path algorithms were introduced or worsened.
Cmux Swift Concurrency ✅ Passed No Swift files are changed; the diff is limited to workflow, docs, shell scripts, and tests, so no legacy async patterns were introduced or expanded.
Cmux Swift @Concurrent ✅ Passed PASS: The PR changes only YAML, Markdown, and shell scripts; no Swift files or concurrency annotations are touched, so this check is not applicable.
Cmux Swift File And Package Boundaries ✅ Passed No Swift files or package-boundary-sensitive production code were changed; the PR only touches workflows, Bash scripts, and a test.
Cmux Swiftpm Lockfiles ✅ Passed Diff only changes Zig setup/docs/tests and CI; no Package.swift, Package.resolved, or cmux.xcodeproj package-reference edits are present.
Cmux Swift Logging ✅ Passed No Swift files changed; the diff only touches CI, shell scripts, tests, and docs, so the Swift logging rule is not implicated.
Cmux Full Internationalization ✅ Passed Diff only touches CI, scripts, tests, and CONTRIBUTING.md; the i18n rule exempts tests and operational docs, and no web/app/message/catalog files changed.
Cmux Swiftui State Layout ✅ Passed The diff touches only CI, scripts, docs, and tests; no Swift files or SwiftUI state/layout patterns are introduced.
Cmux Architecture Rethink ✅ Passed The diff touches only CI/workflow and shell scripts; no Swift architecture changes were introduced, so the rule is not implicated.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR only changes workflow/docs/shell files; no Swift/NSWindow/WindowGroup code was modified, so this rule is not applicable.
Cmux Source Artifacts ✅ Passed All changed paths are intentional source/docs/scripts/tests; no logs, caches, temp dirs, or build artifacts were added to source control.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The diff changes only CI/scripts/tests and no Swift files under production Sources/, so the no-test-debug-seam rule is not implicated.
Cmux No Ambient Global State ✅ Passed No production Swift files changed; the diff only touches workflow, docs, scripts, and tests, so the ambient-global-state rule is not applicable.
Title check ✅ Passed The title clearly identifies the main change: guarding direct GhosttyKit setup against incompatible Zig versions.
Description check ✅ Passed The description covers the purpose and testing, but it references file names and architecture that do not match the reported changes.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented May 24, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds early Zig compatibility checks for GhosttyKit setup. The main changes are:

  • Validates the active Zig release against Ghostty’s pinned major, minor, and minimum patch.
  • Runs the guard from both setup and direct GhosttyKit preparation.
  • Adds CI coverage for incompatible versions and legacy environment overrides.
  • Documents compatible Zig installation options.

Confidence Score: 5/5

This looks safe to merge.

  • The legacy environment variables no longer bypass validation.
  • Both production setup paths run the shared guard.
  • Prerelease Zig strings are rejected as intended.
  • No blocking issues remain in the updated code.

Important Files Changed

Filename Overview
scripts/check-zig-version.sh Adds strict release-version parsing and validates against Ghostty’s pinned Zig requirement.
scripts/ensure-ghosttykit.sh Runs the version guard unconditionally before GhosttyKit preparation.
scripts/setup.sh Checks Zig compatibility after initializing submodules.
tests/test_ci_zig_version_guard.sh Covers compatible, incompatible, missing, prerelease, and ambient-override cases.
.github/workflows/ci.yml Adds the Zig guard test and checks out recursive submodules for the test job.
CONTRIBUTING.md Documents Ghostty’s Zig compatibility range and installation alternatives.

Reviews (6): Last reviewed commit: "test(setup): exercise legacy Zig bypass ..." | Re-trigger Greptile

Comment thread scripts/ensure-ghosttykit.sh Outdated
Comment thread scripts/check-zig-version.sh Outdated
@Bortlesboat
Bortlesboat force-pushed the clawdbot/zig-version-setup-guard branch from 2aa4b9c to 2c6599f Compare May 24, 2026 20:35
@Bortlesboat

Copy link
Copy Markdown
Contributor Author

Refreshed onto current main in b16fa20. The CI conflict retains both the Zig guard and the newer upstream Zig-install/virtual-display checks. Ghostty still pins 0.15.2, the upstream-relative diff remains six focused files, staged shell sources pass bash syntax checks, and the upstream-relative diff check is clean. Per repository policy, execution tests are left to GitHub Actions.

Comment thread tests/test_ci_zig_version_guard.sh Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 165-166: Update the workflow checkout configuration used by
“Validate Zig version guard” to initialize submodules recursively before running
tests/test_ci_zig_version_guard.sh. Preserve the existing test invocation and
ensure ghostty/build.zig.zon is available on clean runners.

In `@CONTRIBUTING.md`:
- Around line 7-10: Update the Zig requirement in CONTRIBUTING.md to state that
the version must match Ghostty’s required major/minor and have patch version
0.15.2 or newer, including that newer minor releases are rejected. Replace the
placeholder install command value with the concrete copy-pastable example
ZIG_REQUIRED=0.15.2.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 8a6be3a1-c6bb-4ea9-bac5-e4cd3ec2fff9

📥 Commits

Reviewing files that changed from the base of the PR and between 2c6599f and b16fa20.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • CONTRIBUTING.md

Comment thread .github/workflows/ci.yml Outdated
Comment thread CONTRIBUTING.md Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit bd3f389. Configure here.

Comment thread scripts/check-zig-version.sh Outdated
Comment thread scripts/check-zig-version.sh Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/ci.yml (1)

87-91: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Disable credential persistence on this checkout.

This job only runs read-only git commands after checkout, so the token does not need to stay in local git config. Add persist-credentials: false here to keep repository-controlled validation steps and submodule content from reusing the checkout token.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 87 - 91, Update the Checkout action
configuration in the CI workflow to set persist-credentials to false alongside
fetch-depth and submodules, ensuring the checkout token is not retained for
subsequent read-only git operations.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/ci.yml:
- Around line 87-91: Update the Checkout action configuration in the CI workflow
to set persist-credentials to false alongside fetch-depth and submodules,
ensuring the checkout token is not retained for subsequent read-only git
operations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 7f291f32-666d-4bcb-afc5-a3f029066cbd

📥 Commits

Reviewing files that changed from the base of the PR and between b16fa20 and bd3f389.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • CONTRIBUTING.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_ci_zig_version_guard.sh`:
- Around line 109-113: Extend the test around the CI Zig version guard to
execute the guard with CMUX_ZIG_VERSION_CHECKED=1 and a legacy required-version
override configured, using an incompatible Zig version, then assert that
validation fails. Keep the existing source-text checks, but verify the runtime
bypass path through the guard script rather than only checking identifier
absence.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5a4eb686-336d-4606-9729-c37dbcbc78a1

📥 Commits

Reviewing files that changed from the base of the PR and between bd3f389 and 9a62046.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • scripts/check-zig-version.sh
  • tests/test_ci_zig_version_guard.sh

Comment thread tests/test_ci_zig_version_guard.sh Outdated
@Bortlesboat
Bortlesboat force-pushed the clawdbot/zig-version-setup-guard branch from b7e7300 to e5c59ba Compare August 7, 2026 00:06
@Bortlesboat Bortlesboat changed the title Guard GhosttyKit setup against incompatible Zig Guard direct GhosttyKit setup against incompatible Zig Aug 7, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator

Thank you for this, @Bortlesboat! ensure-ghosttykit.sh also runs in release workflows that use a pinned GhosttyKit build and never call zig, so a hard Zig check there could break those jobs. If it only runs when actually building GhosttyKit from source, we'd be happy to take it :)

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@Bortlesboat

Bortlesboat commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Moved the Zig check into the source-build fallback in 0243500. Cached GhosttyKit, a matching local artifact, and a checksum-pinned download now work without invoking Zig; source builds still require the manifest-compatible version.

Added a CI regression covering all three reuse paths with Zig missing and incompatible, plus source builds with missing, incompatible, and compatible Zig. The six reuse cases fail before the fix and all nine cases pass afterward. The existing Zig/workflow guard tests also pass. These shell checks ran under Linux; I did not run a macOS app build.

Refreshed against upstream 74b3778a12 in 25cef38069, moved the regression step into the new ci-guards.yml release-tooling group, and registered it in the test execution inventory. All nine scenarios, the current Zig/workflow checks, and the registry validator pass on the refreshed tree. The branch is mergeable again.

@Bortlesboat

Copy link
Copy Markdown
Contributor Author

I have read the CLA Document v2.2 and I hereby sign the CLA

github-actions Bot added a commit that referenced this pull request Sep 25, 2026
@teamleaderleo
teamleaderleo merged commit 537d53f into manaflow-ai:main Sep 25, 2026
55 checks passed
@github-project-automation github-project-automation Bot moved this from Todo to Done in cmux backlog Sep 25, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator

Merged, thank you @Bortlesboat! Moving the Zig check to only the build-from-source path was exactly right: cache hits and prebuilt downloads no longer need Zig at all, and a mismatched Zig now fails with a clear message instead of a confusing build error. Squash-merged as 537d53f :)

@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 55eb8062af: every check was green at merge (12 verified; 15 skipped by policy). Full suite runs on main after merge.

rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
b63ab49 Fail remote-tmux review when a wait is a timer instead of an event (manaflow-ai#11264)
b436c92 Fail closed when CLI forwarding loops back to the GUI binary (manaflow-ai#8788)
136eb2a fix(ios): make the last intermittent CmuxMobileShell tests deterministic (manaflow-ai#14721)
dc7f5bd fix(ios): keep terminal composer dock at bottom (manaflow-ai#14702)
cb4429b ci: add owned_build_state.py warm-keys for warm admission routing (manaflow-ai#14717)
be1ab5e ci(ios): charge in-flight auto runs simulators only when they took the fleet (manaflow-ai#14716)
5110582 ci: clear fixed DerivedData by renaming it aside first (manaflow-ai#14710)
1b8a603 fix(ios): unregister terminal output streams by registration identity; fix stale render-grid tests (manaflow-ai#14711)
3cae7dd refactor: move the browser WebKit support layer into CmuxBrowser (manaflow-ai#14398)
6693884 Run the Codex monitor Stop replay outside the hook handler frame (manaflow-ai#14715)
133a083 ci(e2e): take the owned Mac's gui token just before testing in the build (manaflow-ai#14705)
4c36ace ci: re-run every job of an E2E run whose build did not succeed (manaflow-ai#14712)
ab5ac72 ci: start owned E2E builds from the Mac's kept state, upload after tests (manaflow-ai#14692)
6a3d2d0 test(ios): align Mac switch and pool tests with build-scoped identity (manaflow-ai#14708)
0b16a8b Keep closePanel's unmapped fallback from closing another panel's tab (manaflow-ai#14704)
69c9518 close-surface: reject a blank --workspace or --window (manaflow-ai#14706)
8476043 ci: route warm admission by static runner labels, never write labels (manaflow-ai#14696)
537d53f Guard direct GhosttyKit setup against incompatible Zig (manaflow-ai#4706)
4b200e1 Restore Pi wakeup alerts across reloads (manaflow-ai#12861)
9b291c0 ci: resolve an owned Mac's kept Swift packages offline (manaflow-ai#14709)
31c9105 Stop attaching the unverified per-resume relay MAC (manaflow-ai#14694)
5443f43 Merge pull request manaflow-ai#13565 from manaflow-ai/feat-recover-forgotten-computers
e817240 Add app.equalizeSplitsOnCreate to balance panes on new splits (manaflow-ai#14703)
a358095 fix: never use a shell bootstrap executable in a resume binding (manaflow-ai#5848)
3f177af Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
8b4c97b Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
dce9509 ci: update iOS checkout routing assertion
5dbf06c ci: update CLA workflow digest after main pin
44c00fb Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
d22189d Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
eeca51a fix: make event reconnect policy instance based
9e29c96 Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
d860564 Model first Cloud receipt before remote graph discovery
87f1305 Verify forgotten Mac recovery with the real paired store
2237f8c Merge main and retain upstream test repairs
9ccaa7a Avoid type-check timeout in process fixture
a848b5e Simplify AppKit accessibility test setup
82a9769 Isolate process generation fixture from runner TTY state
4c129bb Enable and restore AppKit assistive access in mounted tree test
9a9acca Enable accessibility output in the hosted SwiftUI test fixture
5ce39d0 Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
a29a7ec Read proxy accessibility children and text through one attribute bridge
12938b6 Test accessibility walkers against modern and legacy proxy nodes
04a30c5 Revoke the original pairing in the targeted dial authority regression
ff1888e Import the extracted Cloud module in the team picker
9c9f259 Merge main and adopt the verified focus recovery fixture
5d41fc8 Align hosted UI fixtures with runtime paths and presentation lifecycle
87dbbd9 Preserve unknown legacy restore liveness after main integration
41a8d4b Revert "Establish running agent state in auto-resume fixtures"
6c7d14b Revert "Use the running-agent fixture for second-restore cwd coverage"
9d276b5 Route Kiro permission-mode fixtures through the mock delivery target
cdb4eae Restore the host app delegate after registration tests
4bdc410 Use the running-agent fixture for second-restore cwd coverage
0b58cbc Establish running agent state in auto-resume fixtures
20c6415 Wait for mounted project content in accessibility test
3ba7b6a Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
2c3c680 Make reparent focus test geometry deterministic
d2f563b Stabilize canonical cache recipe guard
cc60792 Merge current main into forgotten Mac recovery
7dc515f Merge branch 'main' into feat-recover-forgotten-computers
cfd4773 Preserve per-instance forgotten Mac recovery
6a95584 Canonicalize recovered directory identities
f083246 Preserve queued forgotten Mac refreshes
e5202a6 test(ios): use canonical UUID duplicate fixture
ca7ee53 fix(ios): serialize forgotten Mac recovery retries
db851c2 Merge remote-tracking branch 'origin/main' into feat-recover-forgotten-computers
35269cb fix(ios): rehydrate Macs after forget recovery
d0266b7 Merge current CI workflow identity guard into device recovery
45b7c72 fix(i18n): distinguish signed-in Mac recovery from connectivity
730260c Merge remote-tracking branch 'origin/feat-recover-forgotten-computers' into feat-recover-forgotten-computers
a17f8dd fix: complete forgotten Mac recovery without replaying revocation
d64766a test: reproduce revocation during device recovery registration
faf5b55 test: keep recovery authority limited to enrollment
a9c437a test: cover duplicate forget and recovery lifecycle gaps
033e7a0 chore: normalize project ordering
28f63ec fix: recover forgotten Macs from revocation events
7b8e322 fix: recover forgotten Mac registrations
f1aca40 test: validate recovery enrollment proof
62b4e14 test: cover authenticated forgotten-device recovery
9cb2f97 test: cover recovery after device forget

# Conflicts:
#	.github/workflows/app-host-test-rerun.yml
#	.github/workflows/ci-guards.yml
#	.github/workflows/ci-macos.yml
#	.github/workflows/ci-queue-janitor.yml
#	.github/workflows/ci.yml
#	.github/workflows/nightly.yml
#	.github/workflows/seed-derived-data.yml
#	.github/workflows/test-e2e.yml
#	.github/workflows/test-ios.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants