forked from Manuel/meeting-assistant
45 lines
4.3 KiB
Markdown
45 lines
4.3 KiB
Markdown
# Native macOS guest on existing Docker infrastructure — 2026-10-03
|
|
|
|
Result: real macOS Recovery booted under software emulation, but the bounded experiment did not reach an installed guest or execute the native tests. This is not a passing CI result or a verified workflow recipe.
|
|
|
|
## Source and execution boundary
|
|
|
|
- Dockur source: [`16a5b470cdd601bae8b05b02d748d7edfb36c12e`](https://github.com/dockur/macos/tree/16a5b470cdd601bae8b05b02d748d7edfb36c12e).
|
|
- Local environment: existing ARM64 Docker Desktop, linux/amd64 container translation, x86_64 QEMU guest with TCG. This does not establish the runtime or resources of the upstream Ubuntu-x64 runner.
|
|
- Guest settings: `VERSION=14`, `MANUAL=N`, `KVM=N`, `NETWORK=slirp`, 4 GiB guest RAM, two vCPUs, 64 GiB sparse guest disk. Container memory was limited to 6 GiB.
|
|
- Container inspection: `Privileged=false`, `CapAdd=null`, `Devices=[]`, ordinary bridge network. Diagnostic ports were published only on localhost. No runner registration, host configuration, device passthrough or new secret was requested.
|
|
- Candidate archive: clean application/test source at `1164c26846686c1912fd1816cd06de80352e9504`, SHA-256 `30796a27c75792ab87d23dd4c4db991b426d9c55a0e7dc3d4dc45c41056846e1`. It was not executed in the guest.
|
|
|
|
## Observed boundary failure
|
|
|
|
The container built and downloaded Apple's Recovery image. Recovery mounted its installation-state share, found Sonoma's `startosinstall`, and passed the upstream unattended preflight. Native `sw_vers` and `uname` output identified:
|
|
|
|
```text
|
|
ProductVersion: 14.6.1
|
|
BuildVersion: 23G93
|
|
Darwin Kernel Version 23.6.0 ... RELEASE_X86_64 x86_64
|
|
```
|
|
|
|
The first target-selection attempt found no writable disk. Both virtio and SATA trials subsequently exposed `diskutil` failure: it could not use the DiskManagement framework. Its diagnostic listed unavailable DiskArbitration/single-user mode as a possible cause; that cause was not independently established. SATA also exposed an independent missing `io2` QEMU object, corrected through an ordinary QEMU argument without host capabilities.
|
|
|
|
The pinned Recovery patch replaces an early `rc.cdrom.sh` block, before normal daemon startup, with a blocking `exec launch.sh`. One final causal trial changed only this padded bootstrap to launch the installer in the background. Its old/new bootstrap SHA-256 values were `73fd171ea4c889f9946f04d6866047fedd417a69a241b3e84db469c13975d897` and `c5fc86f95e9c65dd7dc59536911c81c96928d4f9541b63121c22cad5690f3582`. The launch script also waited for actual `diskutil list physical` success before the unchanged writable-disk/size guards and captured diagnostics after mounting the share.
|
|
|
|
That trial still recorded 12 completed native `diskutil` failures and an incomplete thirteenth attempt:
|
|
|
|
```text
|
|
Unable to run because unable to use the DiskManagement framework.
|
|
Common reasons include, but are not limited to, the DiskArbitration
|
|
framework being unavailable due to being booted in single-user mode.
|
|
[exit 1]
|
|
```
|
|
|
|
There was no successful disk enumeration, selected installation target, target erase or `startosinstall` invocation. The background change did not establish a working bootstrap; the remaining daemon/framework cause is unresolved. This result does not prove that macOS under TCG on Ubuntu is impossible.
|
|
|
|
## End state and evidence
|
|
|
|
Final container: `c4d5b83f5199063df75d43236d610ef9b71c3b39c14b80a649b0e904d13e87c8`. It started at `10:46:24.987543461 UTC`; the authorized final boot boundary was start plus 16 minutes. It was stopped at `11:02:33.810090465 UTC`: `Running=false`, `ExitCode=143`, `OOMKilled=false`. No experiment container remained running.
|
|
|
|
Raw evidence is retained locally under `/private/tmp/meeting-assistant-macos-guest-proof-20261003/runs/c4d5b83f5199/`: `guest-disk-platform.log`, `physical-disks-ready.log`, `recovery-install.log`, their capture metadata, and `end-container-inspect.json`/`end-state.json`. Metadata identifies the full container ID, actual start time, capture time and log SHA-256; earlier flat logs are historical and were not treated as success in this run.
|
|
|
|
No guest SSH session, official .NET/Apple CLT bootstrap, Swift build or TRX result was obtained. The application's workflow, production runtime and tests were not changed by this experiment. Native Ubuntu CI remains open; local Mac qualification is recorded separately in [the CI evidence](macos-ubuntu-ci-completion.md).
|