Skip to content

fix(desktop): isolate packaged macOS maintenance profiles - #29

Open
nullStack65 wants to merge 2 commits into
mainfrom
fix/packaged-macos-isolation-20261009
Open

nullStack65 wants to merge 2 commits into
mainfrom
fix/packaged-macos-isolation-20261009

Conversation

@nullStack65

Copy link
Copy Markdown
Owner

Add packaged macOS --isolation-root <absolute-directory> for a disposable maintenance profile. The app claims an empty owned root, rejects home overlap and symlinks, sets Electron home/appData/userData/sessionData before startup and the single-instance lock, and passes a reduced environment and profile state directory to backend launches and restarts.

Isolation mode disables account-backed providers, cloud relay/auth, SCM discovery and PR adapters, device discovery, SSH, browser import, credential storage, updates and telemetry. The WebSocket discovery layer uses a lazy disabled service so it cannot construct live adapters. The affected provider readiness fixture now uses temporary paths.

Validation: 12 focused tests passed; server, desktop and shared typechecks, changed-file lint/format and diff checks passed. Independent Luna technical review found no source blockers. Electron-backed Clerk coverage was unavailable locally and remains required in normal CI, which installs Electron. Earlier typecheck and fixture failures are retained in the delivery evidence.

Release/native qualification stays with PR20. This source repair requires a successor digest-bound candidate; existing run37646685913 and its limited native receipts remain historical evidence for their exact bytes. Source landing does not establish native acceptance, promotion or installation.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository: nullStack65/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 365ef25f-210b-4a20-936a-b41f08d48891
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

Automated independent technical review — Luna child, no human vote or reviewer request. Reviewed frozen patch SHA2567ee031ee09b69a4f79aa06b6f48be3e67a2cdaa00c2222d77108223143023a2b, now exact head a717317/treea1986570b65affad1a2938c319fe1fa36abc6b26 (remote tree matches locally reconstructed tested tree). No source blockers found after repairing root case aliases/marker symlinks, inherited state/OTLP paths, cloud/service context propagation and the separate WebSocket SCM construction path. Reviewed 12 focused passing tests and terminal exit0 server/desktop/shared typechecks, changed-file lint/format and diff checks. Electron-backed Clerk tests were unavailable locally; normal exact-head CI must cover them. This review does not establish native GUI/runtime, rollback, release or installation acceptance.

@nullStack65 nullStack65 closed this Oct 9, 2026
@nullStack65 nullStack65 reopened this Oct 9, 2026

Copy link
Copy Markdown
Owner Author

Exact publication head is now f60ae72; the only additional commit is empty and preserves reviewed/tested treea1986570b65affad1a2938c319fe1fa36abc6b26. Normal CI has no runs/checks despite active enabled CI and an ordinary nonforce synchronization plus same-PR close/reopen through existing authenticated gh. No merge/check waiver. Release continuation and exact external actions: #20 (comment) . First local Knip and Electron installation attempts encountered cloud DNS/proxy failures; they are not passes. Required normal hosted CI and native artifact acceptance remain pending.

Copy link
Copy Markdown
Owner Author

CI event/authentication reconciliation and exact conditional current-actor handoff: #20 (comment) . Exact head f60ae72/base59152d9d; CI blob284d8e3a18f115f4183d6b5abcddebaf0dbc2221 identical main/head, default opened/synchronize/reopened eligible. Prior close/reopen actually used keyring-backed user OAuth gh (nullStack65), not an Actions token; cause of zero runs remains unknown. No repeated toggle/empty source change performed. A proven-distinct existing current actor route may use the guarded same-PR reopened event documented there; otherwise event-delivery diagnosis is necessary. Workflow ID362291206 is not a run ID. CodeRabbit success is not normal CI. Source/test/review/native Windows evidence and original failures preserved; no checkless merge or provisional application.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant