Skip to content

ci: add a macOS 27 arm64 lane on the xcode-27 runner - #403

Merged
clvsh merged 2 commits into
feat/root-low-port-inspectionfrom
ci/macos-27-lane
Oct 8, 2026
Merged

clvsh merged 2 commits into
feat/root-low-port-inspectionfrom
ci/macos-27-lane

Conversation

@clvsh

@clvsh clvsh commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Add macOS 27 arm64 to the full CI matrix on xcode-27. Verify the runner's macOS major version and architecture before building, and document the supported matrix.

The CI nextest profile now has fail-fast = false, so a failing test does not hide later results. The rebased stack also includes #409's separate-process root acceptance check for ports 80 and 443; the new macOS 27 lane runs it with the other macOS lanes.

Based on #409. Merge after #407, #408, and #409, which remove the kernel-table behavior that fails on macOS 27. Validation: the combined CI run passed formatting, Clippy, dependency checks, and the full suite on macOS 14, 15, 26, and 27. Every macOS lane also passed the separate-process root acceptance check. Linux and Windows portability checks, benchmarks, and automated review checks passed.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: 06c5b4fa-e8d4-4764-b1b9-050f1131ae3d
📥 Commits

Reviewing files that changed from the base of the PR and between f688979 and 7ff92f8.

📒 Files selected for processing (2)
  • .config/nextest.toml
  • DESIGN.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The Rust CI matrix adds a macOS 27 arm64 job using xcode-27. The nextest profile sets fail-fast = false. The design document adds macOS 27 on Apple Silicon to its listed CI matrix.

Changes

macOS CI coverage

Layer / File(s) Summary
Update CI matrix and profile
.github/workflows/ci.yml, .config/nextest.toml, DESIGN.md
The workflow adds a macOS 27 arm64 job using xcode-27 and checks for macOS major version 27. The nextest profile sets fail-fast = false. The design document adds macOS 27 on Apple Silicon to its representative matrix.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 7ff92

The change adds macOS 27 CI coverage and ensures tests continue after failures. The profile is correctly configured, and no concrete merge-blocking issue is evident; the new lane remains subject to its normal CI run.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7ff92

The additional macOS lane inherits the existing restricted workflow permissions, host checks, and failure policy. No credential or publishing authority is added by the configuration. The new runner image’s ambient credentials and privileged capabilities were not independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The added exposure is execution of the existing CI workload on another runner image. It inherits the existing workflow permission policy rather than receiving a new declared authority path. This does not establish the image’s ambient credential or privilege guarantees.

Resilience and Maintainability Implications

  • inferred — Reporting may run after a non-cancelled test failure, but it does not override the failed test step. Cancellation prevents reporting rather than providing an alternate successful completion path. This conclusion is configuration-based, not an observed runner result.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding a macOS 27 arm64 CI lane on the xcode-27 runner.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review 🔄 Running since 2026-10-08T18:37:25.353237Z 6b3b2d8 New commits
🔒 Security Review ✅ Completed 2026-10-08T01:34:18.635251Z f688979 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codspeed

codspeed Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 7 untouched benchmarks


Comparing ci/macos-27-lane (6b3b2d8) with feat/root-low-port-inspection (4771790)1

Open in CodSpeed

Footnotes

  1. No successful run was found on feat/root-low-port-inspection (b64bd7a) during the generation of this report, so 4d1119e was used instead as the comparison base. There might be some changes unrelated to this pull request in this report. ↩

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes — Reviewed the added macOS lane and its documentation against the shared CI job and GitHub’s runner contract.

  • macOS 27 coverage: Adds an arm64 lane on xcode-27, inheriting host verification and the full Rust quality and behavior suite. GitHub confirms the macOS 27 base image.
  • Platform documentation: Updates DESIGN.md to match the four-lane matrix.

YAML parsing passed, and independent code and documentation reviews found no actionable issues. The new hosted job has passed host verification and all quality checks; tests are still running. Local Rust tests were skipped because this diff changes only CI configuration and documentation. The review remained read-only because no simplification was needed.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

@clvsh
clvsh force-pushed the ci/macos-27-lane branch from f688979 to 42f4e46 Compare October 8, 2026 05:13
@clvsh
clvsh changed the base branch from main to feat/root-low-port-inspection October 8, 2026 05:13
@clvsh
clvsh added this pull request to stack #410 October 8, 2026 05:13

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes Compared the new revision with the previous review and checked the complete current diff against the CI workflow and pinned nextest configuration.

  • Disabled test fail-fast: Set fail-fast = false in the nextest CI profile so later tests still run after a failure, without weakening failure reporting or the existing timeouts.
  • Rebased the macOS lane: Retained the required xcode-27 arm64 lane on the prerequisite branch and preserved the updated fail-closed and root-test requirements in DESIGN.md.

Workflow YAML validation passed, and nextest 0.9.146's upstream configuration confirms support for the setting. The current macOS 27 job has passed host verification and quality checks; tests are still running. Local Rust tests were skipped because this delta changes only CI configuration and documentation.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

@clvsh
clvsh force-pushed the ci/macos-27-lane branch 2 times, most recently from 7ff92f8 to b27a7af Compare October 8, 2026 16:39
clvsh added 2 commits October 8, 2026 14:37
GitHub has no macos-27 label. Its xcode-27 preview image has run macOS 27 since mid-September 2026 (actions/runner-images#14404), so the lane uses that label. DESIGN.md's matrix list now includes macOS 27.
@clvsh
clvsh force-pushed the ci/macos-27-lane branch from b27a7af to 6b3b2d8 Compare October 8, 2026 18:37
@clvsh
clvsh merged commit 5b0ee6e into main Oct 8, 2026
11 of 17 checks passed
@clvsh
clvsh deleted the ci/macos-27-lane branch October 8, 2026 23:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant