diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 8d25f08db7..5855e3bd94 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -185,6 +185,12 @@ jobs: - name: Forbid in-tree use of plugin-compat pointers run: python scripts/check_compat_pointers.py + # The OS lanes import only files carrying the matching marker, so a test that fakes + # macOS (is_macos -> True, sys.platform -> "darwin") without `macos_only` is green on + # Linux over a faked branch and never runs on macOS (#111866, AGENTS.md ยง Don't fake the host OS). + - name: Forbid unmarked macOS fakes in tests + run: python scripts/ci/check_os_marker_fakes.py + # Advisory: profile-scope hazard shapes on the lines this PR adds (child env from os.environ, # raw os.getenv of a platform credential, HOME-only RPC binding, bare-PID liveness). One # process serves many profiles; every pattern leaked the launch profile at least once. Printed