# macOS PR validation on existing Ubuntu infrastructure — 2026-10-03 ## Scope and identity Source repository: `/Users/dh/Documents/DanielsVault/_ops/meeting-assistant`. Delivery branch: `codex/macos-support` in `Daniel/meeting-assistant`; intended PR target: `Manuel/meeting-assistant:main`, PR #39. Fixed change baseline: `bd35ebc4c81bedf80caabb82481169124775fb36` (already contains main `7b2bcd36310ae6434a4ee6eeb3a47b6d1d431df4`). Implementation and qualification were isolated under `/private/tmp/meeting-assistant-macos-ci-20261003`; the original checkout was clean. Updating that original checkout after publication unexpectedly invoked its existing post-merge deployment hook and restarted the workstation service. The immediately checked recording endpoint reported idle (`state=0`, `isRecording=false`) and health reported OK. Future checkout updates disable Git hooks explicitly. This qualification did not intentionally start a new recording. Review covers this CI/test/shutdown delta. Earlier macOS feature and main-sync evidence remains in the respective OpenSpec implementation receipts; this record is not a fresh review of all earlier branch changes. The hashes below identify the substantive implementation published in `1164c26846686c1912fd1816cd06de80352e9504`. The evidence record and generated logs/TRX files are excluded to avoid self-referential hashes. Subsequent factual documentation corrections do not change the reviewed workflow, runtime or tests. | Reviewed file | SHA-256 | | --- | --- | | `.gitea/workflows/pr-push-build-and-test.yaml` | `a6251c435c55967ca2babd58c136ba739ed7c18674e93fff96b477f7b7e1366e` | | `MeetingAssistant.Tests/MacOsDesktopControlManifestTests.cs` | `1df35cf6071f3cdae7d06af8566d59bd2af6c8c5c8c6ca9e04c24197a391975e` | | `MeetingAssistant.Tests/MacOsFactAttribute.cs` | `c756088c1efca9dfe7509a8597845d94e2076445a9f7a2ecec08cd41d333ba7e` | | `MeetingAssistant.Tests/MacOsMeetingAudioSourceTests.cs` | `11c3e36bb31a8aa3b7542ff44367bb0e71ad68360e494fa219b77c0ced3e2456` | | `MeetingAssistant.Tests/MacOsMeetingIntegrationTests.cs` | `51337c27d6126e8e37f4e3b268307830678b8365de51b0c9ce49557ac40160f4` | | `MeetingAssistant.Tests/PyannoteDiarizationWarmupHostedServiceTests.cs` | `0d3494860ce044a2e73e7edba11017b910ca5c0207e2a79da8ff08bde2ff0dfe` | | `MeetingAssistant/Transcription/PyannoteDiarizationWarmupHostedService.cs` | `bcabf6007c9c942845336c1dd958852a8d6dcc383225b4bb1ea97903ef2848e8` | | `README.md` | `79e834ae2953ba690defd4ab10a24e08ae2ce2186ab689afc0ab607e579498e9` | | `openspec/specs/meeting-transcription/spec.md` | `c77edffc0b6ea374e250df758a9be76cbc3ee1146422fc374901c02f216676f6` | ## Requirements and observed evidence - Existing Ubuntu infrastructure: both workflow jobs select only `ubuntu-latest`. The native `macos:host` runner requirement is removed. No KVM device, privileged container, new secret, guest image, or runner registration is required by these jobs. YAML parsing, each job's shell syntax (`bash -n`), and `git diff --check` passed. - Executable macOS managed coverage: the complete portable job's restore/build/test shell steps ran in an Ubuntu 24.04 amd64 `.NET 10` container with `TZ=Europe/Berlin`: **572 passed, 5 explicitly skipped, 0 failed, 577 total**. The skipped tests require a macOS environment and are not counted as passed. Three formerly guarded source/registration/approval tests now actually execute on Ubuntu. A separate `linux-x64` RID build passed the source identity test, proving lookup through the extra output-directory level. Raw Linux log: `/private/tmp/meeting-assistant-portable-final.log`; TRX: `/private/tmp/meeting-assistant-macos-ci-20261003/artifacts/tests/portable.trx`. - Native macOS coverage: the same test/runtime source contents built and signed the Swift helpers on this Mac and passed **577/577**, no skips. Raw receipt: `/private/tmp/meeting-assistant-native-ci-20261003/artifacts/tests/macos-warmup-final-green.trx`. This is local qualification; Ubuntu does not compile or execute the Swift helpers. Earlier real capture → Azure transcription → summary evidence is recorded in `openspec/changes/add-macos-desktop-controls/main-sync-completion.md`; no new live recording was started here. - Accurate Windows verification: `win-x64` RID alone does not select the application's Windows desktop TFM. CI now explicitly builds `net10.0-windows10.0.19041.0` through the existing Wine/Windows .NET SDK, then runs the portable tests under that Windows host. A fresh Windows DLL and fresh TRX are mandatory; a zero exit code without executed work is insufficient. Full Wine validation on the current candidate remains pending on the actual Ubuntu-x64 runner. The local Apple-Silicon Docker attempt hit `rosetta error: invalid gdt selector index 5`; it is not a passing Windows result. Raw attempt: `/private/tmp/meeting-assistant-wine-ci.log`. - Safe warmup shutdown: two real macOS full-suite runs exposed `ObjectDisposedException` from `PyannoteDiarizationWarmupHostedService.StopAsync` at `CancelAsync`, in different endpoint fixtures. A public concurrent-stop reproducer with temporarily increased scheduling overlap produced the exact linked-source exception. Under identical instrumentation, changing only cancellation-source ownership to `Interlocked.Exchange` passed; after instrumentation removal all four lifecycle tests and both final suites passed. Raw red/green receipts: `warmup-overlap-linked-red.trx`, `warmup-overlap-instrumented-green.trx`, and `warmup-overlap-final-green.trx` under the native checkout's `artifacts/tests`. The permanent test coordinates real stop callers with bounded waits; a race test is scheduling-sensitive on the original code, so the instrumented counterexample and original full-suite failure remain part of the causal evidence. The existing single-stop test still proves pending model work observes cancellation. - Test isolation: the macOS audio endpoint fixture supplies its own speech pipeline and no longer starts the unrelated external pyannote model warmup. Its actual mixing, recording-stop, and native-process-termination assertions remain. This fixture isolation is not presented as the production race fix. - OpenSpec: CI/build/test plumbing needs no new change under `AGENTS.md`. The runtime shutdown bug is specified as an addendum to the original accepted pyannote warmup requirement in `openspec/specs/meeting-transcription/spec.md`; strict validation passed (`openspec validate meeting-transcription --type spec --strict`). No active change was archived. ## Standards coverage and sequential review Sources: repository `AGENTS.md`, applicable specs, and `code-review` criteria. DRY owns duplicated platform/test/CI knowledge; SOLID owns lifecycle resource ownership, dependency boundaries and test isolation; KISS owns bounded concurrency test clarity, command naming, accurate documentation, and remaining manual standards. Tests, source builds, OpenSpec validation, YAML/shell parsing and whitespace checks provide automated coverage. The passes ran sequentially in fresh, independent reviewer contexts against the nine frozen hashes above. Each inspected the delta plus adjacent implementation and repository standards; none edited files or claimed remote CI success. - DRY (`/root/review_dry`): clean; platform decisions are centralized in `MacOsFact`, and the two CI host contracts do not justify further indirection. - SOLID (`/root/review_solid`): clean; atomic cancellation ownership, the public stop regression, and the exact fixture dependency removal preserve coherent responsibilities. - KISS (`/root/review_kiss`): clean; bounded stop coordination, CI command names, platform boundaries and README instructions accurately describe the checks. No review repair changed the frozen substantive identity. All required structural passes are complete; runtime evidence and remaining Windows/native limitations are recorded separately above. The subsequent README/evidence corrections update only observed artifact availability, publication status, and the checkout-hook event. Structural review is `not-required` for this factual documentation delta; the workflow, runtime, tests and binding instructions are unchanged. A separate read-only factual check confirmed the revised `auto` description against Dockerfile.auto and checked the limits against the saved receipts. Whitespace and the final documentation diff were checked; existing test results remain applicable to the unchanged code. ## Delivery and remaining limits State at publication: structural review complete; current-head remote verification pending. This is not a merge-readiness or main-merge receipt. The user authorized preparing this branch for PR CI and merging into main after tests pass. Authenticated Gitea identity `Daniel` has write/admin on the fork and read-only access to `Manuel/meeting-assistant`; it cannot merge there. The earlier local main-sync commits and reviewed implementation were normally pushed to the existing fork branch as `1164c26846686c1912fd1816cd06de80352e9504`; PR #39's description was updated and read back against that exact head. Upstream [run 4145](https://gitea.schweigert.cloud/Manuel/meeting-assistant/actions/runs/4145) was created for this head, with both Ubuntu jobs waiting and no runner assigned. Its live job view explicitly says `Need approval to run workflows for fork pull request.` The current account cannot approve upstream workflows. This is the existing fork-workflow approval gate, not a request for additional infrastructure. Main is not merged; remote Windows and portable checks have not executed for this head. A native macOS guest/Swift CI run on Ubuntu is not implemented. Docker-OSX supports software emulation, but the documented installed-guest downloads and `auto` tags were unavailable when checked. An [isolated unprivileged Dockur/TCG experiment](macos-tcg-guest-feasibility.md) booted an actual macOS 14.6.1 x86_64 Recovery environment, but `diskutil` could not use the DiskManagement framework; the actual cause remains unresolved. The bounded trial ended without an installed guest or native tests, and its container was stopped. No unverified guest bootstrap was made a required PR check. Passing the two current Ubuntu jobs would still leave the user's requested native macOS coverage in Ubuntu CI unmet; the local Mac result does not close that requirement.