Skip to content

ci: add bounded macOS cleanup canary#12

Merged
Eli Pinkerton (wallstop) merged 7 commits into
mainfrom
agent/issue-48-macos-canary
Jul 20, 2026
Merged

ci: add bounded macOS cleanup canary#12
Eli Pinkerton (wallstop) merged 7 commits into
mainfrom
agent/issue-48-macos-canary

Conversation

@wallstop

@wallstop Eli Pinkerton (wallstop) commented Jul 19, 2026

Copy link
Copy Markdown

Summary

  • add one manual, bounded organization macOS smoke for Unity 2022.3.62f3 / StandaloneOSX
  • protect it with the pinned v1.8.3 lifecycle-aware organization lock and exact cooldown verification
  • make native macOS license return fail closed with private, nonce-bound evidence and typed schema-5 outputs
  • add an independently scheduled same-runner fallback return, bounded process-group TERM→KILL cleanup, and late-fork coverage
  • preserve the related Windows cleanup evidence fixes already published on agent/fix-empty-release-reason

Why

The organization fork had no lock-protected macOS canary and no positive native return proof. A timed-out or ambiguous return could leave a paid Unity seat unsafe while the workflow lacked a bounded acceptance path.

Safety

  • manual dispatch only; no organization-policy changes
  • one paid macOS leg in smoke mode
  • private activation/return logs are never uploaded or printed
  • account-limit 20111 evidence dominates every healthy fallback
  • missing or nonzero return evidence quarantines rather than confirms
  • hard runner loss uses the acquire action's fail-closed post cleanup

Validation

  • yarn test:ci — 383 passed, 2 skipped
  • yarn test:workflow-policy — 10 passed
  • node scripts/verify-resource-cleanup-contract.mjs — RC001–RC020 passed
  • bash scripts/test-macos-resource-proof.sh — passed
  • yarn typecheck
  • actionlint .github/workflows/build-tests-mac.yml
  • changed-file formatting and git diff --check
  • five adversarial review rounds; final round zero findings

Post-PR acceptance

After hosted PR checks are green, dispatch Builds - macOS in smoke mode, verify exact central holder removal/cooldown state, and reconcile Unity Portal inventory before merge.

Fixes Ambiguous-Interactive/ambiguous-organization-build-lock#48


Note

High Risk
Changes Unity license activation/return handling and organization build-lock reporting; incorrect proof or release logic could leave paid seats stuck or falsely marked safe.

Overview
macOS CI is reworked into a manual workflow_dispatch with contract-only, smoke, and upstream-full modes. A fixture job runs test-macos-resource-proof.sh; the org fork can run one lock-protected StandaloneOSX / 2022.3.62f3 smoke (acquire → build → optional same-runner fallback return → release → strict verification of confirmed cleanup, cooldown, and evidence digest). The full Unity matrix stays on game-ci/unity-builder only when upstream-full is selected.

Action/runtime: Local builds on Windows and macOS now run ResourceCleanupProof end-to-end. consume classifies private activation/return logs into typed outcomes (including account-limit 20111, timeouts, missing evidence) and publishes resourceCleanupStatus, resourceHealth, resourceReason, and resourceEvidenceDigest (digest binds classifications, not raw logs). macOS requires native return log + completed:0 for confirmation.

Windows CI aligns with the stricter contract: cleanup classification runs after failed/cancelled acquire paths; lock release and verify only treat cleanup as confirmed when both resource-safe and resource-reason=cleanup-confirmed.

Reviewed by Cursor Bugbot for commit c5543f4. Bugbot is set up for automated code reviews on this repo. Configure here.

Copy link
Copy Markdown
Author

Exact reviewed head 245992abfcd482b287f6c4cea72de9cc28efa332 is ready for automated review. Five independent adversarial passes ended with zero actionable findings; local tests, policy tests, RC001–RC020, macOS late-fork fixtures, typecheck, formatting, and actionlint are green.

Cursor (@cursor) review

Copilot review

Please focus on same-runner always-return scheduling, bounded process-group cleanup, blocked-evidence precedence, secret-safe nonce proof, and exact v1.8.3 cooldown release semantics.

Copy link
Copy Markdown
Author

Fresh head 44a4e58 contains only the CI-requested Linux/Node 18 generated-artifact correction. The bundle was regenerated twice in node:18-bookworm with identical output; source tests and all five adversarial review rounds remain unchanged.

Cursor (@cursor) review Copilot review

Copy link
Copy Markdown
Author

GitHub Actions recovery rerun is green on unchanged head 44a4e58304be4f699bc724bbff950da4b3aaff00: exact-head and runner preflights passed; the single Windows Unity build succeeded; exact positive license return was classified cleanup-confirmed; central release entered cooldown; aggregate passed.

Cursor (@cursor) review

Copilot review

Copy link
Copy Markdown
Author

Fresh head 4a61b61f615e2a512a54ce6bc3b31adb929ca2a2 fixes the macOS-hosted fixture failure without starting the paid canary: Python setsid() plus a private ready/ack handshake proves a dedicated live PGID before Unity exec; cancellation before isolation uses bounded KILL; Bash 3.2 shared-PGID, missing-launcher, timeout, cancellation, parent-exit, and late-fork fixtures pass; RC001–RC020 and the full local gate are green; the acquire downgrade guard is now 360 seconds.

Cursor (@cursor) review

Copilot review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4a61b61. Configure here.

Comment thread dist/index.js Outdated

Copy link
Copy Markdown
Author

Cursor’s inline finding is fixed on fresh head 147dc22dbb55acfbfb5fa7fd002809d0d944126b: native macOS success classification now uses the already-trimmed returnStatus, a newline-terminated completed:0 regression fixture passes, RC001–RC020 is updated, and dist was regenerated on Linux Node 18. Focused/full tests and an independent adversarial pass are clean.

Cursor (@cursor) review

Copilot review

Copy link
Copy Markdown
Author

Fresh head c5543f484e2bc21aeadaa6cda0fabda87c9b3cb7 fixes the fail-closed canary admission mismatch observed in run 29715036805. Central v1.8.3 currently enforces releaseCooldownSeconds=1; the consumer guard now matches that existing policy without changing central/org configuration. Schema-5 lifecycle admission plus exact cooldown-started, reservation-state=cooldown, holder, and available-at verification remain mandatory. Policy, RC001–RC020, formatting, actionlint, and adversarial review are green.

Cursor (@cursor) review

Copilot review

Copy link
Copy Markdown
Author

Bounded macOS acceptance run 29715355239 is green on exact head c5543f484e2bc21aeadaa6cda0fabda87c9b3cb7: one 2022.3.62f3/StandaloneOSX leg, successful build, confirmed / healthy / cleanup-confirmed, normalized 64-hex evidence digest, exact same-holder release, cooldown-started, and aggregate success. Central state contains no unity-builder holder/reservation and no active incident. Final exact-head Windows smoke 29715145851 and all PR checks are green; the only review thread is resolved/outdated.

Merge remains intentionally gated only on the issue's Unity Portal inventory reconciliation. No organization or central policy/configuration was changed.

Copy link
Copy Markdown
Author

Final Unity Portal acceptance evidence (2026-07-19 America/Los_Angeles): the repository owner confirmed the Portal is clean and currently shows no seats held after macOS canary run 29715355239. This reconciles the account-side inventory with the workflow's exact-positive native return proof, confirmed / healthy / cleanup-confirmed tuple, schema-5 cooldown release, and central state showing no unity-builder holder/reservation or active incident.

@wallstop
Eli Pinkerton (wallstop) merged commit 1c6c4e8 into main Jul 20, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a bounded lock-protected macOS unity-builder canary

1 participant