Fix native CI permit handoff and bounded acknowledgement
PR and Push Build/Test / windows-build-and-test (push) Successful in 17m40s
PR and Push Build/Test / portable-build-and-test (push) Successful in 7m31s
PR and Push Build/Test / macos-native-full (push) Canceled after 1h37m21s

This commit is contained in:
codex committed 2026-10-08 11:55:44 +02:00
1 parent ea545bf719
commit 399f77a0f1
4 files changed
+172 -8

No files matched your search

+4
View File
@@ -6,6 +6,8 @@ The pipeline and its application/test prerequisites are consolidated on `codex/m
The configuration has not passed remote installation, build or tests. Run [4219](https://gitea.schweigert.cloud/Daniel/meeting-assistant/actions/runs/4219) proved native macOS 13.6/x86_64 but failed eight bounded disk-readiness attempts. Run [4221](https://gitea.schweigert.cloud/Daniel/meeting-assistant/actions/runs/4221) failed both bounded `sw_vers` attempts. Run [4245](https://gitea.schweigert.cloud/Daniel/meeting-assistant/actions/runs/4245) subsequently passed Recovery readiness and entered installation; it was stopped at the user's request before a native build/test result. Local validation checks preparation and ownership contracts, not native CI success. These results do not establish that PR 39 is ready to merge.
Run [4319](https://gitea.schweigert.cloud/Manuel/meeting-assistant/actions/runs/4319) passed the Windows and portable jobs and native Recovery readiness. The host published the permit ten seconds after readiness, but the guest's file-size check did not observe it and timed out after five minutes; installation never started. The unhealthy run was cancelled and normal owned-resource cleanup succeeded. The repaired handoff has offline shell evidence; a fresh Full native CI run remains required.
## Entrypoints
Run from a clean checkout of the commit to test:
@@ -17,6 +19,8 @@ dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --cleanup --output artifa
The output directory binds the run identity and must be fresh. `git archive HEAD` supplies the exact source to the guest; uncommitted application changes are not included. Cleanup uses the same output directory and removes only the saved container, image and anonymous storage volume with matching ownership labels and IDs. Retained artifacts stay outside that volume. Shared Docker caches are not pruned.
Before publishing successful Recovery readiness, the guest creates a fixed-size pending permit mailbox. After rechecking the owned container, disk and share, the host changes that same file's contents without truncation or rename. The guest reads and validates exactly three terminated lines plus EOF against its run token, selected disk and source commit. It retains `install-permit-received.json`; only a matching receipt starts the host's installation phase. A missing or invalid permit publishes `installation-failed` after five minutes. The installer still independently rechecks the serial, exact writable 64-GiB disk and exclusive erase guard before touching it. Offline validation models stale size metadata and exercises the real generated shell and host publication command; it does not prove macOS share behavior.
For a read-only Recovery check, omit `--full`. That mode does not install an OS or execute application tests. Offline checks use a pristine checkout of the pinned Dockur source and the two pinned compatibility archives:
```sh