Skip to content

fix: declare required-reason system uptime usage - #328

Merged
jlipworth merged 2 commits into
mainfrom
codex/fix-326-privacy-uptime
Sep 29, 2026
Merged

jlipworth merged 2 commits into
mainfrom
codex/fix-326-privacy-uptime

Conversation

@jlipworth

Copy link
Copy Markdown
Owner

Summary

  • Add SystemBootTime / 35F9.1 to the shared privacy manifest; no runtime or playback changes.
  • Audit all production uptime uses, including PMSKit retry timers, local raw baselines and exported in-app intervals against Apple's off-device exception.
  • Add source/four-product packaging regression checks and narrow development/release guidance.

Refs #326 (intentionally not auto-closing: signed archive acceptance remains open). #325 collection/review-demo disclosure work is separate; no App Store Connect answers or policy changes are included.

Verification

  • Canonical hermetic PMSKit: 121 XCTest + 1,707 Swift Testing tests passed; no live probes/media transcodes.
  • Four privacy regression tests; strict MkDocs, rendered links, Mermaid and repository hygiene passed.
  • Clean unsigned Release builds: visionOS Simulator, iOS Simulator, tvOS Simulator, arm64 macOS. Fresh executable mtimes verified.
  • All four actual app manifests match source; each product includes the expected Crypto dependency manifest (empty required-API/collection arrays, tracking false). Packaging checker validates platform identity and nested plist readability.
  • Passive iPhone Release install/launch: installed UUID matched, process alive, expected unauthenticated screen visually inspected, no fatal/assertion/uncaught-exception markers. Owned simulator shut down/deleted; no staged Mac app remains.

Remaining gates / limits

  • Exact signed Release archive manifests and Xcode aggregate privacy reports for all four platforms are not verified. Unsigned packaged resources are not archive/signing validation. Keep Privacy manifest: declare production systemUptime API use #326 open until this acceptance item is satisfied.
  • Native affected matrix conservatively selects hosted/UI lanes as well; those broad suites were not run for this resource-only fix. No visionOS launch claimed (main golden simulator-id file unavailable); no Mac launch claimed. No hardware/live-backend acceptance implied.
  • No signing/account/server changes, archive upload, version bump, tag, merge or issue closure.

Sanitized data-flow and validation evidence: docs/evidence/2026-09-15-privacy-uptime-audit.md. Private build/log/screenshot artifacts are not published.

@jlipworth

Copy link
Copy Markdown
Owner Author

CI completed for 57014b10: all five reported checks are green (PR docs/hygiene/PMSKit and push hygiene/PMSKit). Local four-platform unsigned Release packaging, hermetic tests, strict documentation/hygiene and passive iPhone launch evidence are recorded in the PR audit. The exact signed Release archive + Xcode aggregate privacy-report gate remains open; this PR has not been merged and #326 remains open.

@jlipworth
jlipworth merged commit 75d8284 into main Sep 29, 2026
5 checks passed
@jlipworth
jlipworth deleted the codex/fix-326-privacy-uptime branch September 29, 2026 15:24
jlipworth added a commit that referenced this pull request Sep 29, 2026
## Summary

Consolidates the still-relevant work from `codex/store-demo-provenance`
(`7f93e1ee`) and `codex/prerelease-disclosure-audit` (`a61eff14`) onto
current main (`181b9431`). No app runtime changes.

- Retain the public open-film/derived-artwork provenance snapshot and
active capture/reviewer plan; distinguish fixture images from final
store images.
- Recheck official Blender license pages and Apple screenshot size
guidance on 2026-09-29. Preserve historical catalog/hash verification
dates and require a fresh deployed-asset check before capture.
- Preserve merged #328/#329 privacy wording and archive-report gates
rather than replaying stale text. Add the explicit #259 deferral and
unchecked exact-candidate export/accessibility gates.
- Keep the original disclosure audit as dated evidence, with a
subsequent-disposition note. Remove current-sounding simulator/worktree
assumptions from the capture plan and add it to the active-plan index.
- Add a manifest consistency regression test; this verifies recorded
metadata, not the remote asset bytes or legal clearance of eventual
compositions.

## Validation

- 10 screenshot tooling tests.
- Strict MkDocs, rendered/source links, Mermaid, repository redaction
and tooling hygiene.
- Hermetic PMSKit tests (live probes excluded).
- Official source-page verification; no new film download or
deployed-server checksum audit.

No simulator, live playback, infrastructure changes, account edits,
uploads, version changes or physical-device acceptance. No final
screenshots produced. No new native build required: docs/spec/test
changes only.

## Remaining scope

Related #92, #259, #280, #325, #326; this PR closes none of them. Final
captures, storefront credits/editorial review, age suitability,
exact-candidate reviewer journeys, signed-archive privacy reports and
owner-approved account answers remain open. The source
branches/worktrees are preserved until this consolidation is reviewed
and merged; this PR does not remove them.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant