Skip to content

Accept that macOS's own stores remove their files too - #660

Merged
goldyfruit merged 2 commits into
mainfrom
ci/macos-stores-both-ways
Oct 7, 2026
Merged

goldyfruit merged 2 commits into
mainfrom
ci/macos-stores-both-ways

Conversation

@goldyfruit

@goldyfruit goldyfruit commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #652. On #648's nightly, the macOS 15 uninstall comparison failed on one line:

GONE       home: /Users/runner/Library/Suggestions/mifeaturestore.db-journal (it was there before the install)

That file is the journal of a SQLite database belonging to macOS's Suggestions agent. The agent removed it on its own while the job ran. The uninstall never touches ~/Library/Suggestions.

machine_state.allow accepted Apple's own stores in ~/Library only as adding files. The agents that own them also remove their files as they go, so the same Apple names are now accepted in both directions:

  • containers named com.apple., group.com.apple. or with an Apple team prefix;
  • Application Support/com.apple.*, HTTPStorages/com.apple.* and Preferences/com.apple.*.plist;
  • the stores only macOS keeps (Suggestions, DuetExpertCenter, PersonalizationPortrait, PrivateCloudCompute, Spotlight's metadata, Siri's speech service log).

A UUID-named container is still accepted only as added: an extension of any program can have one, so one that disappears may be someone's data (CodeRabbit's catch). LaunchAgents, where the installer writes, and everything outside Apple's names stay checked.

Test plan

  • The failing line from the macOS 15 job, fed through machine_state.sh's own matcher, is now accepted. A removed ~/Library/LaunchAgents plist, ~/.venvs/users-own, a UUID-named container's data and a third-party container are still reported.
  • every_ci_job_that_uninstalls_proves_the_machine_was_given_back, which checks that every allowed difference has a reason, passes.
  • The macOS jobs on this PR. They cannot prove the change on their own, because the agents only sometimes remove a file during a job.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Updated macOS file monitoring to allow removals of matching Apple-named containers, support files, HTTP stores, preferences, and listed system stores during long-running jobs. UUID-named containers remain allowed only when added.

The journal of Suggestions' database was there before a macOS 15 install
and gone after its uninstall, and the comparison reported it as taken: the
allow-list took Apple's stores in ~/Library as only ever adding files. The
agents that own them add and remove their files as they go, and the
uninstall touches none of them, so the same Apple names are accepted in
both directions. LaunchAgents and everything outside Apple's names stay
checked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 00426793-df5f-48ce-98d5-642f1886ab43
📥 Commits

Reviewing files that changed from the base of the PR and between 2db8584 and ca46dca.

📒 Files selected for processing (1)
  • .github/scripts/machine_state.allow
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/scripts/machine_state.allow

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The macOS allowlist adds removal patterns for selected Apple-named files. UUID-named containers remain allowed only when added. The comment now notes that Apple services can create and remove files during long jobs.

Changes

Apple-owned file allowlist

Layer / File(s) Summary
Allow selected Apple-owned file removals
.github/scripts/machine_state.allow
The comment describes Apple services creating and removing files during long jobs. The allowlist adds removal patterns for Apple-named containers, support files, HTTP stores, preferences, and listed macOS stores. UUID-named containers remain allowed only as additions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to ca46d

The change appears ready to merge after normal checks. It accepts the specified macOS-managed file removals without exempting UUID-named container removals or LaunchAgents.

Architecture Summary

Architecture risk: 🔵 Low · up to 2db85

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/scripts/machine_state.allow: The comment now says Apple agents can add and remove their own files during long jobs, and gives the Suggestions database journal as an example; the old comment only noted that agents run during long jobs.
  • observed — Modified behavior in .github/scripts/machine_state.allow: Added home removed allowlist entries for the same Apple container, support-file, HTTP-storage, preference, and system-store patterns already accepted for home added.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: allowing macOS-managed stores to remove their own files.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9f7dc72f-9e33-4e5d-aac2-4934928caf18
📥 Commits

Reviewing files that changed from the base of the PR and between 8005835 and 2db8584.

📒 Files selected for processing (1)
  • .github/scripts/machine_state.allow

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.

Comment thread .github/scripts/machine_state.allow Outdated
@goldyfruit goldyfruit self-assigned this Oct 7, 2026
@goldyfruit goldyfruit added bug Something isn't working enhancement New feature or request labels Oct 7, 2026
@goldyfruit goldyfruit added this to the Duck Hunt milestone Oct 7, 2026
An extension of any program can have a container named by a UUID, so one
that disappears may be someone's data, and accepting its removal hid that
from the comparison. Only Apple's own names are accepted as removed; a
UUID-named container is still accepted as added. From CodeRabbit on #660.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@goldyfruit
goldyfruit merged commit 50cc45a into main Oct 7, 2026
38 checks passed
goldyfruit pushed a commit that referenced this pull request Oct 7, 2026
Brings in #660: macOS's own stores in ~/Library may remove their files too,
which failed this branch's macOS 15 comparison on the Suggestions journal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant