Repository navigation
ci: add a macOS 27 arm64 lane on the xcode-27 runner - #403
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe Rust CI matrix adds a macOS 27 arm64 job using ChangesmacOS CI coverage
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The change adds macOS 27 CI coverage and ensures tests continue after failures. The profile is correctly configured, and no concrete merge-blocking issue is evident; the new lane remains subject to its normal CI run. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The additional macOS lane inherits the existing restricted workflow permissions, host checks, and failure policy. No credential or publishing authority is added by the configuration. The new runner image’s ambient credentials and privileged capabilities were not independently verified. Retained concerns Security review detailsSecurity Blast Radius
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes — Reviewed the added macOS lane and its documentation against the shared CI job and GitHub’s runner contract.
- macOS 27 coverage: Adds an arm64 lane on
xcode-27, inheriting host verification and the full Rust quality and behavior suite. GitHub confirms the macOS 27 base image. - Platform documentation: Updates
DESIGN.mdto match the four-lane matrix.
YAML parsing passed, and independent code and documentation reviews found no actionable issues. The new hosted job has passed host verification and all quality checks; tests are still running. Local Rust tests were skipped because this diff changes only CI configuration and documentation. The review remained read-only because no simplification was needed.
gpt-6.1-sol | 𝕏
f688979 to
42f4e46
Compare
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes Compared the new revision with the previous review and checked the complete current diff against the CI workflow and pinned nextest configuration.
- Disabled test fail-fast: Set
fail-fast = falsein the nextest CI profile so later tests still run after a failure, without weakening failure reporting or the existing timeouts. - Rebased the macOS lane: Retained the required
xcode-27arm64 lane on the prerequisite branch and preserved the updated fail-closed and root-test requirements inDESIGN.md.
Workflow YAML validation passed, and nextest 0.9.146's upstream configuration confirms support for the setting. The current macOS 27 job has passed host verification and quality checks; tests are still running. Local Rust tests were skipped because this delta changes only CI configuration and documentation.
gpt-6.1-sol | 𝕏
7ff92f8 to
b27a7af
Compare
GitHub has no macos-27 label. Its xcode-27 preview image has run macOS 27 since mid-September 2026 (actions/runner-images#14404), so the lane uses that label. DESIGN.md's matrix list now includes macOS 27.
b27a7af to
6b3b2d8
Compare

Add macOS 27 arm64 to the full CI matrix on
xcode-27. Verify the runner's macOS major version and architecture before building, and document the supported matrix.The CI nextest profile now has
fail-fast = false, so a failing test does not hide later results. The rebased stack also includes #409's separate-process root acceptance check for ports 80 and 443; the new macOS 27 lane runs it with the other macOS lanes.Based on #409. Merge after #407, #408, and #409, which remove the kernel-table behavior that fails on macOS 27. Validation: the combined CI run passed formatting, Clippy, dependency checks, and the full suite on macOS 14, 15, 26, and 27. Every macOS lane also passed the separate-process root acceptance check. Linux and Windows portability checks, benchmarks, and automated review checks passed.