You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
KEL-249: verify profile fail-closed behavior on macOS 13 or earlier #282
Run KEL-135/T3's remaining real-OS acceptance row, macos-older-fail-closed, on macOS 13 or earlier when a compatible runner becomes available. The owner has no such runner for the foreseeable future; this is intentionally parked, with no scheduled execution date.
The available runner used macOS 26.5.1 / WebKit 21624.2.5.11.4. Nine of ten Mac rows passed. The media row passed under adopted public-grant-restart-v1; this does not claim disk-persisted permission revocation. No other Mac T3 implementation or acceptance task is currently outstanding besides the older-OS row. The completed implementation and evidence are preserved; current Mac session work is ended.
Acceptance when a runner becomes available
Use actual macOS 13 or earlier and valid signed debug and release fixtures, with exact source revision and commands recorded:
Verify the running app signature before extracting Team Identifier and signed identifier.
Persistent startup returns KELD-WV-009 before store lookup, profile/metadata mutation, listener, child, window, or content creation; record listener=0, child=0, window=0.
Explicit development mode uses a fresh nonpersistent store (persistent=false, identifier absent) and inherits no state from a previous launch.
Invalid/tampered signatures and invalid store/identity inputs fail closed without creating a persistent store.
Preserve executable digest/signature identity, exact OS/WebKit versions, store persistence/identifier observations, exit statuses, resource census and negative-control results for both build modes.
Update KEL-249, the parent KEL-135 evidence, and the spec with the real results; close this issue only when those observables pass.
A newer macOS run, mocked version, version override, or model review does not satisfy this row. Do not claim a physical path or ACL for an Apple-managed store.
Resume and dependencies
First identify a compatible real Mac or supported macOS guest with working signed fixtures. If a VM is proposed, validate support for that exact restore image and host before installation. Then add/use the native pre-14 fixture and publish its exact runnable command in this issue; there is no claim that an unrun command already passes.
Linux KEL-135/T4 admission work can proceed independently of this Mac deferral: T4 depends on T1 and its own upstream Wry API/dependency gate. T5 package/update/uninstall acceptance still requires the full T2/T3/T4 artifacts.
Deferred work
Run KEL-135/T3's remaining real-OS acceptance row,
macos-older-fail-closed, on macOS 13 or earlier when a compatible runner becomes available. The owner has no such runner for the foreseeable future; this is intentionally parked, with no scheduled execution date.7b91f34062fe947bd8c9a4de9fc64669dfb8d6ae, reviewed source63a548ec0bd0d9adfeaa198b242f77b1a3f3b9a8.The available runner used macOS 26.5.1 / WebKit 21624.2.5.11.4. Nine of ten Mac rows passed. The media row passed under adopted
public-grant-restart-v1; this does not claim disk-persisted permission revocation. No other Mac T3 implementation or acceptance task is currently outstanding besides the older-OS row. The completed implementation and evidence are preserved; current Mac session work is ended.Acceptance when a runner becomes available
Use actual macOS 13 or earlier and valid signed debug and release fixtures, with exact source revision and commands recorded:
KELD-WV-009before store lookup, profile/metadata mutation, listener, child, window, or content creation; record listener=0, child=0, window=0.persistent=false, identifier absent) and inherits no state from a previous launch.A newer macOS run, mocked version, version override, or model review does not satisfy this row. Do not claim a physical path or ACL for an Apple-managed store.
Resume and dependencies
First identify a compatible real Mac or supported macOS guest with working signed fixtures. If a VM is proposed, validate support for that exact restore image and host before installation. Then add/use the native pre-14 fixture and publish its exact runnable command in this issue; there is no claim that an unrun command already passes.
Linux KEL-135/T4 admission work can proceed independently of this Mac deferral: T4 depends on T1 and its own upstream Wry API/dependency gate. T5 package/update/uninstall acceptance still requires the full T2/T3/T4 artifacts.