From bf1c28b4800c1456c4964e241d175284fd4b9970 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Tue, 15 Sep 2026 20:04:56 -0700 Subject: [PATCH] ci: fail lint when a test fakes macOS without @pytest.mark.macos_only (#111866) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit scripts/ci/check_os_marker_fakes.py flags test files that make the interpreter believe it is on macOS (is_macos -> True, sys.platform -> "darwin", platform.system -> "Darwin") while carrying no `macos_only` marker: the macOS lane imports only marked files, so such a file is green on Linux over a faked branch and never runs on the host it exists for. A `# os-marker: ok — ` comment opts a host-independent line out. _BASELINE holds the files that already faked macOS when the check landed; a stale entry fails the check so the list can only burn down. Wired into lint.yml next to the compat-pointer check; two invariant tests cover a flagged fake vs marked/opted-out files and host-honest platform reads. --- .github/workflows/lint.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 8d25f08db7..5855e3bd94 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -185,6 +185,12 @@ jobs: - name: Forbid in-tree use of plugin-compat pointers run: python scripts/check_compat_pointers.py + # The OS lanes import only files carrying the matching marker, so a test that fakes + # macOS (is_macos -> True, sys.platform -> "darwin") without `macos_only` is green on + # Linux over a faked branch and never runs on macOS (#111866, AGENTS.md § Don't fake the host OS). + - name: Forbid unmarked macOS fakes in tests + run: python scripts/ci/check_os_marker_fakes.py + # Advisory: profile-scope hazard shapes on the lines this PR adds (child env from os.environ, # raw os.getenv of a platform credential, HOME-only RPC binding, bare-PID liveness). One # process serves many profiles; every pattern leaked the launch profile at least once. Printed