docs: record native guest CI attempt and remaining verification gaps
PR and Push Build/Test / build-and-test (pull_request) Blocked by required conditions
PR and Push Build/Test / portable-build-and-test (pull_request) Blocked by required conditions

This commit is contained in:
dh
2026-10-03 13:08:31 +02:00
parent 1164c26846
commit 445bff99ce
3 changed files with 52 additions and 6 deletions
@@ -0,0 +1,44 @@
# Native macOS guest on existing Docker infrastructure — 2026-10-03
Result: real macOS Recovery booted under software emulation, but the bounded experiment did not reach an installed guest or execute the native tests. This is not a passing CI result or a verified workflow recipe.
## Source and execution boundary
- Dockur source: [`16a5b470cdd601bae8b05b02d748d7edfb36c12e`](https://github.com/dockur/macos/tree/16a5b470cdd601bae8b05b02d748d7edfb36c12e).
- Local environment: existing ARM64 Docker Desktop, linux/amd64 container translation, x86_64 QEMU guest with TCG. This does not establish the runtime or resources of the upstream Ubuntu-x64 runner.
- Guest settings: `VERSION=14`, `MANUAL=N`, `KVM=N`, `NETWORK=slirp`, 4 GiB guest RAM, two vCPUs, 64 GiB sparse guest disk. Container memory was limited to 6 GiB.
- Container inspection: `Privileged=false`, `CapAdd=null`, `Devices=[]`, ordinary bridge network. Diagnostic ports were published only on localhost. No runner registration, host configuration, device passthrough or new secret was requested.
- Candidate archive: clean application/test source at `1164c26846686c1912fd1816cd06de80352e9504`, SHA-256 `30796a27c75792ab87d23dd4c4db991b426d9c55a0e7dc3d4dc45c41056846e1`. It was not executed in the guest.
## Observed boundary failure
The container built and downloaded Apple's Recovery image. Recovery mounted its installation-state share, found Sonoma's `startosinstall`, and passed the upstream unattended preflight. Native `sw_vers` and `uname` output identified:
```text
ProductVersion: 14.6.1
BuildVersion: 23G93
Darwin Kernel Version 23.6.0 ... RELEASE_X86_64 x86_64
```
The first target-selection attempt found no writable disk. Both virtio and SATA trials subsequently exposed `diskutil` failure: it could not use the DiskManagement framework. Its diagnostic listed unavailable DiskArbitration/single-user mode as a possible cause; that cause was not independently established. SATA also exposed an independent missing `io2` QEMU object, corrected through an ordinary QEMU argument without host capabilities.
The pinned Recovery patch replaces an early `rc.cdrom.sh` block, before normal daemon startup, with a blocking `exec launch.sh`. One final causal trial changed only this padded bootstrap to launch the installer in the background. Its old/new bootstrap SHA-256 values were `73fd171ea4c889f9946f04d6866047fedd417a69a241b3e84db469c13975d897` and `c5fc86f95e9c65dd7dc59536911c81c96928d4f9541b63121c22cad5690f3582`. The launch script also waited for actual `diskutil list physical` success before the unchanged writable-disk/size guards and captured diagnostics after mounting the share.
That trial still recorded 12 completed native `diskutil` failures and an incomplete thirteenth attempt:
```text
Unable to run because unable to use the DiskManagement framework.
Common reasons include, but are not limited to, the DiskArbitration
framework being unavailable due to being booted in single-user mode.
[exit 1]
```
There was no successful disk enumeration, selected installation target, target erase or `startosinstall` invocation. The background change did not establish a working bootstrap; the remaining daemon/framework cause is unresolved. This result does not prove that macOS under TCG on Ubuntu is impossible.
## End state and evidence
Final container: `c4d5b83f5199063df75d43236d610ef9b71c3b39c14b80a649b0e904d13e87c8`. It started at `10:46:24.987543461 UTC`; the authorized final boot boundary was start plus 16 minutes. It was stopped at `11:02:33.810090465 UTC`: `Running=false`, `ExitCode=143`, `OOMKilled=false`. No experiment container remained running.
Raw evidence is retained locally under `/private/tmp/meeting-assistant-macos-guest-proof-20261003/runs/c4d5b83f5199/`: `guest-disk-platform.log`, `physical-disks-ready.log`, `recovery-install.log`, their capture metadata, and `end-container-inspect.json`/`end-state.json`. Metadata identifies the full container ID, actual start time, capture time and log SHA-256; earlier flat logs are historical and were not treated as success in this run.
No guest SSH session, official .NET/Apple CLT bootstrap, Swift build or TRX result was obtained. The application's workflow, production runtime and tests were not changed by this experiment. Native Ubuntu CI remains open; local Mac qualification is recorded separately in [the CI evidence](macos-ubuntu-ci-completion.md).
+7 -5
View File
@@ -5,10 +5,10 @@
Source repository: `/Users/dh/Documents/DanielsVault/_ops/meeting-assistant`.
Delivery branch: `codex/macos-support` in `Daniel/meeting-assistant`; intended PR target: `Manuel/meeting-assistant:main`, PR #39.
Fixed change baseline: `bd35ebc4c81bedf80caabb82481169124775fb36` (already contains main `7b2bcd36310ae6434a4ee6eeb3a47b6d1d431df4`).
Work was isolated under `/private/tmp/meeting-assistant-macos-ci-20261003`; the original checkout was clean and no workstation service was restarted.
Implementation and qualification were isolated under `/private/tmp/meeting-assistant-macos-ci-20261003`; the original checkout was clean. Updating that original checkout after publication unexpectedly invoked its existing post-merge deployment hook and restarted the workstation service. The immediately checked recording endpoint reported idle (`state=0`, `isRecording=false`) and health reported OK. Future checkout updates disable Git hooks explicitly. This qualification did not intentionally start a new recording.
Review covers this CI/test/shutdown delta. Earlier macOS feature and main-sync evidence remains in the respective OpenSpec implementation receipts; this record is not a fresh review of all earlier branch changes.
The evidence record and generated logs/TRX files are excluded from the substantive content identity to avoid self-referential hashes.
The hashes below identify the substantive implementation published in `1164c26846686c1912fd1816cd06de80352e9504`. The evidence record and generated logs/TRX files are excluded to avoid self-referential hashes. Subsequent factual documentation corrections do not change the reviewed workflow, runtime or tests.
| Reviewed file | SHA-256 |
| --- | --- |
@@ -45,9 +45,11 @@ The passes ran sequentially in fresh, independent reviewer contexts against the
No review repair changed the frozen substantive identity. All required structural passes are complete; runtime evidence and remaining Windows/native limitations are recorded separately above.
The subsequent README/evidence corrections update only observed artifact availability, publication status, and the checkout-hook event. Structural review is `not-required` for this factual documentation delta; the workflow, runtime, tests and binding instructions are unchanged. A separate read-only factual check confirmed the revised `auto` description against Dockerfile.auto and checked the limits against the saved receipts. Whitespace and the final documentation diff were checked; existing test results remain applicable to the unchanged code.
## Delivery and remaining limits
State at publication: structural review complete; current-head remote verification pending. This is not a merge-readiness or main-merge receipt.
The user authorized preparing this branch for PR CI and merging into main after tests pass. Authenticated Gitea identity `Daniel` has write/admin on the fork and read-only access to `Manuel/meeting-assistant`; it cannot merge there. The latest published PR head at intake was `bf6e1e7560c6bdfcebf69ad0e3240b4de647adb6`, so the earlier local main-sync commits also need publishing.
Authorized delivery is a normal push of this reviewed delta plus the earlier local main-sync commits to the existing fork branch, followed by a PR description update. The published commit, actual workflow status, and any remaining owner action are reported on PR #39. Main must not be reported as merged before the required remote checks pass and the repository owner performs the permitted merge.
A native macOS guest/Swift CI run on Ubuntu is not implemented; Docker-OSX supports software emulation, but its ready-made Catalina guest does not provide a supported .NET 10 + modern Apple-framework build environment. No unverified guest bootstrap was made a required PR check.
The user authorized preparing this branch for PR CI and merging into main after tests pass. Authenticated Gitea identity `Daniel` has write/admin on the fork and read-only access to `Manuel/meeting-assistant`; it cannot merge there. The earlier local main-sync commits and reviewed implementation were normally pushed to the existing fork branch as `1164c26846686c1912fd1816cd06de80352e9504`; PR #39's description was updated and read back against that exact head.
Upstream [run 4145](https://gitea.schweigert.cloud/Manuel/meeting-assistant/actions/runs/4145) was created for this head, with both Ubuntu jobs waiting and no runner assigned. Its live job view explicitly says `Need approval to run workflows for fork pull request.` The current account cannot approve upstream workflows. This is the existing fork-workflow approval gate, not a request for additional infrastructure. Main is not merged; remote Windows and portable checks have not executed for this head.
A native macOS guest/Swift CI run on Ubuntu is not implemented. Docker-OSX supports software emulation, but the documented installed-guest downloads and `auto` tags were unavailable when checked. An [isolated unprivileged Dockur/TCG experiment](macos-tcg-guest-feasibility.md) booted an actual macOS 14.6.1 x86_64 Recovery environment, but `diskutil` could not use the DiskManagement framework; the actual cause remains unresolved. The bounded trial ended without an installed guest or native tests, and its container was stopped. No unverified guest bootstrap was made a required PR check. Passing the two current Ubuntu jobs would still leave the user's requested native macOS coverage in Ubuntu CI unmet; the local Mac result does not close that requirement.