Read-only runs are now enforced on macOS: plan-mode delegations run under sandbox-exec, which blocks writes into their roots and renames of any directory above them. Linux still watches read-only runs; AGY_READ_ONLY_ENFORCEMENT=require refuses them there. agy's "authentication failed" error now classifies as unauthenticated.