docs(macos): record production Dev ID FileProvider hydration PROVEN on 2026-05-18 - #372
Merged
Merged
Conversation
…n 2026-05-18 Run 26061402177 of macos-postinstall-smoke.yml on the petting-zoo-mini-tcfs self-hosted runner installed the notarized arm64 .pkg built by run 26057944325 from main commit c08a0a4 (PR #370) and passed the full strict harness with fileprovider_testing_mode=false. Evidence: - harness/expected-file-index.json: status=visible, manifest_exists=true, size=55, chunks=1 (PR #370 remote-index gate fired) - harness/hydrated-expected-file: exact 55-byte expected content - harness/hydrate-read-error.log: empty (no Operation timed out) Update the doc lede, add a 2026-05-18 milestone section recording the four stacked unblocks (tailnet endpoint, secret-set syntax, enforce_tls scheme derivation in commit 0b1dc0c, stale ~/Applications/TCFSProvider.app removal), update the prior production Dev ID Finder hydration blocker assertions in-place with dated "Updated 2026-05-18" inline notes, and update the Not Yet Proven section to scope what remains on Dev ID (evict/rehydrate, mutation upload/readback, conflict/status preservation, badges, continuous release-day coverage) — these layered proofs are TIN-133 work this week. Historical neo-local packets and the May 17 catread blocker are retained as context, not deleted, since this doc's value is the chain of evidence. Refs: TIN-133, #309, #370
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Update
docs/ops/macos-fileprovider-reality.mdto record today's milestone: the production Developer ID FileProvider hydration path is proven end to end through a notarized.pkginstall on a clean self-hosted runner.GitHub Actions run
26061402177ofmacos-postinstall-smoke.ymlon the registeredpetting-zoo-mini-tcfsself-hosted runner installed the notarized arm64.pkgbuilt by run26057944325from main commitc08a0a4(PR #370) and passed the full strict harness withfileprovider_testing_mode=false— the production Dev ID lane, not Mac App Development testing-mode.Evidence:
harness/expected-file-index.json:status: "visible",entry_state: "committed",manifest_exists: true,size: 55,chunks: 1— PR Add tcfs index inspect + seeded macOS FileProvider smoke gate (TIN-133, #309) #370'stcfs index inspect+require_expected_remote_indexgate fired correctly before FileProvider was asked to hydrate.harness/hydrated-expected-file: contains exactly the 55 expected bytes (tcfs macOS post-install smoke v0.12.12 run 26061402177).harness/hydrate-read-error.log: empty (noOperation timed out, no coordinated-read failure).What changed in the doc
## 2026-05-18 — Production Dev ID FileProvider hydration PROVENsection right after the lede with run ids, the index-inspect packet, the chain of four stacked unblocks (tailnet endpoint,gh secret setsyntax,enforce_tlsscheme derivation in commit0b1dc0c, stale~/Applications/TCFSProvider.appremoval), and an explicit honest scope (what's proven on Dev ID now vs what's still pending).(Updated 2026-05-18: ...)notes pointing back to run26061402177— did not delete the historical context.Not Yet Provensection bullets that previously claimed Dev ID hydrate as unproven.The historical neo-local packets and May 17
catreadblocker packet are retained as context, since this doc's value is the chain of evidence.Refs
tcfs index inspect+--seed-expected-fileand therequire_expected_remote_indexgate that made the seeded-fixture proof possible)docs/release/evidence/; this doc references it textually)Test plan