Skip to content

CI: macOS validation and bootstrap become advisory (nightly and main pushes, no PR runs; the user's 2026-10-05 decision) - #711

Merged
seathatflowsinourveins merged 5 commits into
mainfrom
c5/macos-advisory-20261005
Oct 5, 2026
Merged

seathatflowsinourveins merged 5 commits into
mainfrom
c5/macos-advisory-20261005

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes: it makes macOS CI advisory. validate-macos, bootstrap-macos and bootstrap-macos-brew no longer run on pull requests, and they leave the required checks. They still run nightly (06:47 UTC), on filtered main pushes and on manual dispatch, so a macOS regression is fixed forward. This follows the user's decision of 2026-10-05 (~01:50Z, an AskUserQuestion answer): "Advisory only".
  • Base commit: 5df0e0ede
  • Lane: lane:shared. docs/lanes.md's required-context count goes from eight to seven, so the trading-custody owner must ACK.
  • Owned paths touched:
    • .github/workflows/adoption-bootstrap.yml;
    • .github/main-ruleset.json (the committed target);
    • catalogs/foundation/automation.json, docs/github-automation.md, docs/lanes.md, adoption/platforms/macos-arm64.md;
    • five test modules;
    • the decision record.

The live ruleset 23739774 was already changed by the coordinator on 2026-10-05, with an API read-back: validate-macos is no longer required. This PR brings the committed target and the docs into line with it.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
The new workflow skips all three macOS jobs on pull_request, and the old one runs them local_integration The PR-event test fails the original workflow (133 failing subtests, exit 1) and passes the new one (exit 0)
The committed ruleset target equals the live seven-context ruleset source_review .github/main-ruleset.json; live read-back from gh api repos/.../rulesets/23739774 on 2026-10-05
The workflow has no security findings local_integration zizmor --offline .github/workflows/adoption-bootstrap.yml: no findings (5 suppressed)

Local commands run

$ python3 -m unittest tests.test_workflow_hardening tests.test_adoption_bootstrap_macos tests.test_github_automation_practice tests.test_codex_broker_reaper tests.test_shell_parser_ci tests.test_merge_guard_doc
388 tests OK (36 skipped)  [GPT builder job 064]
$ zizmor --offline .github/workflows/adoption-bootstrap.yml
No findings to report (5 suppressed)  [coordinator]
$ python3 scripts/validate.py
status passed (10,044 hashed files)  [coordinator, after the registry commit]
$ python3 merge_tree_landing_check.py origin/main HEAD
LANDABLE

actionlint was not on PATH in the builder's sandbox; zizmor ran instead.

Decision record

docs/decisions/2026-10-05-macos-ci-advisory.md: the user's decision, #699's portability catch, the fix-forward path and the overturn rules.

Built by GPT bounded job 064 (GPT-6.1 Sol at max). Review chain:

  • Claude read: 4 P2 and 6 P3, all fixed by the GPT repair round (5f6eb31).
  • Claude delta read: all ten confirmed fixed; three new P3s, fixed by the coordinator (7e4d69f), along with a fresh ruleset read-back (enforcement active, strict false, merge methods squash only).
  • Registry last (331d008).

This PR lands after the v2026.10.05 re-pin, because adoption/** is on the release window's hold list.

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement label Oct 5, 2026
@socket-security

socket-security Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

seathatflowsinourveins pushed a commit that referenced this pull request Oct 5, 2026
Attribute the chosen option to the asking agent's label and record the exact
01:41:33Z answer, 01:42:03Z ruleset change, and subsequent PR #711. Cite the
PR's hosted CI separately from its builder-run 133-failure control and
388-test result; remove references to untracked handoff reports and split
the stale-count control from the passing final check.

Add dated advisory forward pointers to both superseded decisions. Align the
remaining Linux bootstrap descriptions with nightly 06:47 UTC and the full
workflow path filter. Strengthen all three macOS gate controls, pin manual
dispatch, and resolve the workflow comment's source. Mark runtime-workers'
eight-context lists as 2026-09-28 observations, preserving their values.

Sources: GitHub Actions workflow syntax and expression status functions at
github/docs 2bd66de8cea336061c9ea060c9b37385136e6ab3; the coordinator's exact
timeline; PR #711 and adoption-bootstrap CI run 37255957059, validation run
37255957046; retained 2026-09-28 runtime-workers observations.

Validation: 521 selected unittest tests, 38 skipped, exit 0. The strengthened
control first exposed swallowed assertion failures (exit 1), then passed
after the helper raised directly. zizmor 1.30.1 --offline reports no findings
(5 suppressed), exit 0. git diff --check passes. validate.py reports only
expected registry drift; manifests/evidence.json remains coordinator-owned.

The first publication check also found a host executable path in untracked
zizmor metadata; that directory was redacted and the check rerun. Keep every
.bounded-job-064 file untracked and outside the commit.

Repair round after the Claude read of PR #711 (GPT bounded job 064, round 2): four P2 and six P3 findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the c5/macos-advisory-20261005 branch 2 times, most recently from ab3bea4 to 331d008 Compare October 5, 2026 03:26
@seathatflowsinourveins
seathatflowsinourveins marked this pull request as ready for review October 5, 2026 03:26
Scout and others added 5 commits October 5, 2026 11:04
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every
pull_request; retain full runs on filtered main pushes and manual dispatch,
and move the weekly bootstrap schedule to nightly 06:47 UTC.

Match the committed ruleset and dated automation catalog to the coordinator's
seven required contexts, including the merge guard's documented count. Keep
the Linux PR detector working and label the
retained macOS selector as historical. Record the user's 2026-10-05 advisory
decision, #699's portability catch, the fix-forward path and overturn rules.

Sources: GitHub Actions workflow-syntax#jobsjob_idif and
events-that-trigger-workflows#schedule, github/docs at
2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements;

Validation: the final PR-event test fails the original workflow with 133
failing subtests across all three macOS jobs (exit 1), and passes the new
workflow (exit 0); 388 selected unittest tests (36 skipped), including the
merge-guard stale-count red/green control; git diff --check.
actionlint is not on PATH. validate.py exits 1 for evidence registry drift
only. Evidence registration remains with the coordinator. The count-only
docs/lanes.md correction follows that file's lane:shared integration policy.

Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed
the #699 citation from its branch-local head to the landed main commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Attribute the chosen option to the asking agent's label and record the exact
01:41:33Z answer, 01:42:03Z ruleset change, and subsequent PR #711. Cite the
PR's hosted CI separately from its builder-run 133-failure control and
388-test result; remove references to untracked handoff reports and split
the stale-count control from the passing final check.

Add dated advisory forward pointers to both superseded decisions. Align the
remaining Linux bootstrap descriptions with nightly 06:47 UTC and the full
workflow path filter. Strengthen all three macOS gate controls, pin manual
dispatch, and resolve the workflow comment's source. Mark runtime-workers'
eight-context lists as 2026-09-28 observations, preserving their values.

Sources: GitHub Actions workflow syntax and expression status functions at
github/docs 2bd66de8cea336061c9ea060c9b37385136e6ab3; the coordinator's exact
timeline; PR #711 and adoption-bootstrap CI run 37255957059, validation run
37255957046; retained 2026-09-28 runtime-workers observations.

Validation: 521 selected unittest tests, 38 skipped, exit 0. The strengthened
control first exposed swallowed assertion failures (exit 1), then passed
after the helper raised directly. zizmor 1.30.1 --offline reports no findings
(5 suppressed), exit 0. git diff --check passes. validate.py reports only
expected registry drift; manifests/evidence.json remains coordinator-owned.

The first publication check also found a host executable path in untracked
zizmor metadata; that directory was redacted and the check rerun. Keep every
.bounded-job-064 file untracked and outside the commit.

Repair round after the Claude read of PR #711 (GPT bounded job 064, round 2): four P2 and six P3 findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… a weekly leftover, the catalog version label) and the confirmed ruleset read-back

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…n (the job no longer runs on PRs)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…: registry last)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session 5f (trading custody): trading-lane ACK at ba04ac4f59564fd17b80e80449c9e140957e10c7 for this lane:shared PR. The command center's foundation ACK is at the same head.

The basis:

  • A GPT-6.1 Sol cross-family full read at this head returned ACCEPT with no findings.
    • The macOS jobs no longer run on pull_request, but still run on schedule and on main pushes.
    • The required contexts' names and triggers are unchanged.
    • test_workflow_policy, test_workflow_hardening and test_adoption_bootstrap_macos were run.
    • The registry rows match.
  • A delta read of the refresh onto main 095d4fad8 returned ACCEPT. Adaptive paper engine: exchange-calendars XNYS as the primary session calendar (never-rebuild), overnight-cap fail-open fixed #735's calendar push path is kept.
  • The live ruleset 23739774 requires exactly seven contexts, none of them macOS, which matches the user's 2026-10-05 decision. The trading lane does not depend on macOS PR runs.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: landing at head ba04ac4f59564fd17b80e80449c9e140957e10c7. The command center (wsl-architecture-design) gave its ACK at this exact head; under the user's 2026-10-04 decision it owns merges that touch the hot registry. The read-only cross-family review (GPT-6.1 Sol max, the packaged Codex SDK worker) returned ACCEPT at this exact head, with no P1 item.

Observed main 6cf063c4fd7d82e9cc56c02f29dcc68f51d40b09. coordination/merge_tree_landing_check.py (sha256 a11649fcf2e5844c…) exit 0:

main 6cf063c4fd7d82e9cc56c02f29dcc68f51d40b09 head ba04ac4f59564fd17b80e80449c9e140957e10c7 base 095d4fad89c7896c7f1766fdaa9981554a19403a merged-tree b4717d4ca394e531b0b378c01bb6cbf993ff7ee1 merge-tree-exit 0
ok   1: clean three-way merge
ok   2: merged-vs-main paths 19, outside PR-owned 0 []
ok   3: main drift 37 paths, overlap with PR-owned inputs (registry excluded) []
ok   4: registry foreign rows equal True, order preserved True, PR-owned rows 15, unowned top-level keys differing []
ok   5: merged files[] sorted by path with no duplicates: True (10172 rows)
LANDABLE
condition 5: merged files[] sorted and unique (tree b4717d4ca394e531b0b378c01bb6cbf993ff7ee1)

Required checks at this head: 7 pass . Unresolved review threads: 0.

@seathatflowsinourveins
seathatflowsinourveins merged commit 4ead283 into main Oct 5, 2026
25 checks passed
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: post-merge observation. Landed as 4ead2838d8cc76965e6ef35efa6c9cee52153efd (parent 6cf063c4fd7d82e9cc56c02f29dcc68f51d40b09), tree b4717d4ca394e531b0b378c01bb6cbf993ff7ee1. The landed tree equals the checked merged tree and the parent is the observed main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant