Repository navigation
Accept that macOS's own stores remove their files too - #660
Conversation
The journal of Suggestions' database was there before a macOS 15 install and gone after its uninstall, and the comparison reported it as taken: the allow-list took Apple's stores in ~/Library as only ever adding files. The agents that own them add and remove their files as they go, and the uninstall touches none of them, so the same Apple names are accepted in both directions. LaunchAgents and everything outside Apple's names stay checked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe macOS allowlist adds removal patterns for selected Apple-named files. UUID-named containers remain allowed only when added. The comment now notes that Apple services can create and remove files during long jobs. ChangesApple-owned file allowlist
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The change appears ready to merge after normal checks. It accepts the specified macOS-managed file removals without exempting UUID-named container removals or LaunchAgents. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
- Configuration used: defaults
- Review profile: CHILL
- Plan: Advanced
- Run ID:
9f7dc72f-9e33-4e5d-aac2-4934928caf18
📒 Files selected for processing (1)
.github/scripts/machine_state.allow
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.
An extension of any program can have a container named by a UUID, so one that disappears may be someone's data, and accepting its removal hid that from the comparison. Only Apple's own names are accepted as removed; a UUID-named container is still accepted as added. From CodeRabbit on #660. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Brings in #660: macOS's own stores in ~/Library may remove their files too, which failed this branch's macOS 15 comparison on the Suggestions journal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
Follow-up to #652. On #648's nightly, the macOS 15 uninstall comparison failed on one line:
That file is the journal of a SQLite database belonging to macOS's Suggestions agent. The agent removed it on its own while the job ran. The uninstall never touches
~/Library/Suggestions.machine_state.allowaccepted Apple's own stores in~/Libraryonly as adding files. The agents that own them also remove their files as they go, so the same Apple names are now accepted in both directions:com.apple.,group.com.apple.or with an Apple team prefix;Application Support/com.apple.*,HTTPStorages/com.apple.*andPreferences/com.apple.*.plist;A UUID-named container is still accepted only as added: an extension of any program can have one, so one that disappears may be someone's data (CodeRabbit's catch). LaunchAgents, where the installer writes, and everything outside Apple's names stay checked.
Test plan
machine_state.sh's own matcher, is now accepted. A removed~/Library/LaunchAgentsplist,~/.venvs/users-own, a UUID-named container's data and a third-party container are still reported.every_ci_job_that_uninstalls_proves_the_machine_was_given_back, which checks that every allowed difference has a reason, passes.🤖 Generated with Claude Code
Summary by CodeRabbit