Skip to content

[GOV.32] Remove the ContentSandbox macOS launch-profile code and keep the typed fail-closed refusal - #173

Merged
deku2026 merged 1 commit into
mainfrom
task/gov-32
Oct 8, 2026
Merged

deku2026 merged 1 commit into
mainfrom
task/gov-32

Conversation

@deku2026

@deku2026 deku2026 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Claim: GOV.32 epoch 1 (w-deku-20261008-gov-32)

Task record: governance lane, task-gov-32. Authority: P2-023, under which macOS is outside the delivery scope. The task was added by the planning repair Design #341 / Plan #457.

What this changes

  • Deletes the declarative macOS entitlements input src/DesktopHelpers/ArcForges.ContentSandbox/macos/ArcForges.ContentSandbox.entitlements and its eng/provenance/files.json row.
  • Makes ProfileEnforcement.ThisPlatform a nullable ContentSandboxProfileKind? that is null on every OS other than Windows and Linux. HelperEntry compares the frame profile with it unchanged, so every launch frame there, including one carrying the reserved MacOsAppSandboxXpc, exits with the isolation-unavailable code (70) before any resource or parser is reached. The Windows and Linux branches are unchanged.
  • Rewrites Tests/MacProfileTests.cs to cover refusal only. It checks that:
    • the broker refuses a macOS launch;
    • the reserved value stays wire-stable at 3;
    • the Windows (1) and Linux (2) kinds are unchanged;
    • a helper given a MacOsAppSandboxXpc frame exits 70.
  • Tests/ContractFacadeTests.cs: the refusal check covers every non-Windows, non-Linux OS.
  • The README macOS lines and the doc comments of the reserved enum value now state that macOS is not supported. The value itself is unchanged.

No change to Windows or Linux containment. ContentSandboxLauncher.cs (the macOS refusal) and HelperEntry.cs are not edited.

Validation (independent reviewer runs)

  • Windows and WSL2 Debian, SDK 10.0.400, Linux-native clone: locked restore, build with warnings as errors, and the ContentSandbox tests: 110 total, 101 passed, 0 failed, 9 opt-in OS isolation tests skipped.
  • Python gates: design, dependency, licence boundary (--evaluate-managed and --evaluate-ide), reference baselines, runtime ownership, architecture naming evidence, reconciliation, provenance, native provenance and stage-integration verify all pass, as do the eng, tests/tooling and stage_integration unit suites.
  • eng/packaging unit suite: needs pack output first, which hosted package-validation produces.

🤖 Generated with Claude Code

Implements P2-023 (macOS outside the delivery scope) for the ContentSandbox
helper: the macOS App-Sandbox and XPC launch-profile deliverable is removed
and the typed fail-closed macOS refusal stays.

- Delete src/DesktopHelpers/ArcForges.ContentSandbox/macos/ArcForges.ContentSandbox.entitlements
  and its row in eng/provenance/files.json (the only provenance change).
- ProfileEnforcement.ThisPlatform becomes ContentSandboxProfileKind? and is null off
  Windows and Linux. HelperEntry compares the frame profile with it unchanged, so every
  launch frame there, including one carrying MacOsAppSandboxXpc, exits with the
  isolation-unavailable code (70) before any resource or parser. The Windows and Linux
  branches are unchanged.
- Tests/MacProfileTests.cs is refusal-only: the broker refuses a macOS launch, the reserved
  value stays wire-stable (3) and is never this platform's profile, the Windows (1) and
  Linux (2) kinds are unchanged, a helper process given a MacOsAppSandboxXpc frame exits 70,
  and a helper given its own platform kind passes the profile gate (exit 64 at the bootstrap
  descriptor check).
- Tests/ContractFacadeTests.cs: the non-Windows, non-Linux refusal check applies to every
  such operating system, not only macOS. No other test changed.
- README macOS lines (ArcForges.ContentSandbox and ArcForges.ContentSandbox.Broker) and the
  doc comments of the reserved MacOsAppSandboxXpc value in ContentSandboxTypes.cs and
  ContentSandboxLaunchFrame.cs state that macOS is not supported. The value is unchanged.

Write scope: the GOV.32 record files only, with no ADP-07 supporting files.
Windows and Linux containment is unchanged. ContentSandboxLauncher.cs (the macOS refusal)
and HelperEntry.cs are not edited.

Validation (local, not CI):
- Windows, SDK 10.0.400 from C:/Users/J7Rdm/.dotnet: locked restore, build with 0 warnings
  and 0 errors, ContentSandbox tests 110 total, 101 passed, 9 opt-in OS checks skipped, 0 failed.
  The five MacProfileTests pass.
- WSL2 Debian 13 on kernel 6.18.40.1-microsoft-standard-WSL2, SDK 10.0.400, Linux-native copy
  at ~/gov32: the same counts; the five MacProfileTests pass.
- Policy gates (python -I, with the repo eng directory added to sys.path): design_policy,
  dependency_policy, licence_boundary --evaluate-managed (61 projects), runtime_ownership
  --evaluate-managed (7 repositories), reconciliation, native_provenance,
  check_provenance --owner DesktopPlatform (973 files), reference_baselines, stage_integration
  verify (0 findings). Unit suites for these gates and tests/tooling all pass.
- Not run locally: architecture_evidence.py secret (RP-09 needs the hosted secret-scan job)
  and the nine Windows OS-isolation checks, which are opt-in and need a published hostile fixture.
- Static scan: App-Sandbox, XPC and entitlements references remain only in the reserved enum
  values, the broker's macOS refusal (ContentSandboxLauncher.cs), the null ThisPlatform,
  and the tests.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
@deku2026

deku2026 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Reviewed 45343a4 for [GOV.32] (ContentSandbox macOS profile code removal): approved

Independent reviewer session w-deku-20261008-rev-gov-32, which authored none of this. Posted by the coordinator under the 2026-10-08 publication protocol.

Round 1, by inspection:

  • write scope: the 9 record files only;
  • Windows and Linux containment unchanged;
  • the nullable ThisPlatform refuses every frame off Windows and Linux;
  • the wire value stays 3;
  • no residual App-Sandbox/XPC/entitlements code outside the reserved value, the launcher refusal and the docs and tests.

Validation was not yet run in that round.

Round 2, approved with full validation under SDK 10.0.400:

  • Windows: tests 110 total, 101 passed, 9 opt-in OS isolation tests skipped.
  • WSL2 Debian on a Linux-native clone: the same totals.
  • All Python gates and unit suites pass. The eng/packaging suite needs pack output, which hosted CI produces.

Non-blocking: ContentSandboxLauncher.ProbeProfile() on macOS still reports the reserved value as an unavailable profile, with a reason text about the removed bundle/XPC handoff. The launcher is outside this write scope; the refusal itself is correct.

@deku2026
deku2026 merged commit 6f21d73 into main Oct 8, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant