ci(github): add strict macOS verification - #1
Conversation
Current PR-head CI evidence — 2026-07-14
The 2m52s job passed every step: 95 Rust tests, Rust release build/fmt/strict Clippy, 25 Swift tests, Swift warnings-as-errors release build, strict format, LaunchDaemon plist lint, and clean tracked diff. The runner reported macOS 26.4, Xcode 26.5, Swift 6.3.2, and Rust 1.96.0. This is inspected PR integration-tree CI plumbing for the current PR content. It is not direct exact-head/current-SHA release proof and does not prove signed/admin installation, cross-UID/XPC isolation, notarization, real ChatGPT/iMessage/Discord/Reminders/XLSX routes, clean-machine installation, external-user validation, or The final evidence wording received two fresh isolated reviewer PASS reports after the merge-ref distinction was corrected. The PR remains draft. No owner/admin bypass or merge action is authorized. |
What changed
actions/checkoutto a full commit and Rust to 1.96.0Why
The reviewed bootstrap commit was pushed to the new public repository without a GitHub Actions workflow. Local verification was real, but no remote test result existed. This PR adds the smallest complete remote verification slice without representing CI as signed-build, cross-UID, product-E2E, or release proof.
User and developer impact
Pull requests and pushes to
mainwill run one boundedmacos-26verification job with read-only repository permissions. The workflow does not deploy, publish, sign, notarize, access secrets, or mutate repository contents.Validation
Proof boundary
This closes
OPENOPEN-CIplumbing only. It does not prove signed/admin installation, the protected cross-UID/XPC boundary, notarization, real ChatGPT/iMessage/Discord/Reminders/XLSX routes, clean-machine installation, external-user validation, orPRODUCT_READY_FOR_DEMO.Surgical-change record
OPENOPEN-CIMerge safety
--adminor an implicit owner bypass.