rdmsm4x-changelog-20260903-0912-ecs0lib-keychain-tvos-and-xcode-followup
rdmsm4x-changelog-20260903-0912-ecs0lib-keychain-tvos-and-xcode-followup
Made ecs0lib secure-keychain behavior truthful on tvOS in an isolated commit and independently reconfirmed the Xcode 26.6 pre-compiler stall as a SwiftBuild discovery-pipe deadlock, without changing global Xcode state or any protected/canonical source tree.
Scope
- Host:
rdmsm4xonly. - ecs0lib base:
8805372710261de772577fbe9a44f6eff445a9e3. - Isolated branch/worktree:
codex/ecs0lib-keychain-tvos-portable-20260903at/Users/richh/dev/_worktrees/ecs0lib-keychain-tvos-portable-20260903. - Commit:
ce2d8a13dbb777e39953096da74b9216b1f1ca67. - Xcode diagnosis:
/Applications/Xcode.appXcode 26.6 build 17F113, only through command-scopedDEVELOPER_DIR; global selection remained Xcode 27 beta 6.
Files and local state changed
- In isolated ecs0lib commit:
Sources/ECS0Permissions/ECSSecureKeychain.swiftTests/ECS0LibTests/AppleSecurityFrameworksTests.swift
- Reports:
/Users/richh/dev/_handoff/rtty-appstore-finalization-20260902/xcode-repair/TASK-20260903-20-REPORT.md/Users/richh/dev/_handoff/rtty-appstore-finalization-20260902/xcode-repair/XCODE-26.6-STALL-FOLLOWUP-20260903.md
- Coordination:
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-task-20260903-20.json- ticket moved by
ticket resolveto/Users/richh/dev/issues/resolved/TASK-20260903-20-make-ecs0permissions-keychain-portable-to-tvos.md; its desktop and dev.ecs0.net local HTML mirrors were refreshed.
- Disposable Xcode evidence:
/private/tmp/xcode-stable-followup-20260903-unmodified/private/tmp/xcode-stable-followup-20260903-wrapper
- No file under canonical
/Users/richh/dev/lib/ecs0lib, protected/Users/richh/dev/_handoff/rtty-native-nettop-20260903/universe/lib/ecs0lib, either RTTy checkout, or/Applications/Xcode.appwas changed.
What changed
- Conditionalized
LocalAuthenticationuse inECSSecureKeychain. - Added
AccessPolicy.isSupportedOnCurrentPlatformso.biometricGuardedis explicitly unavailable on tvOS while.standardand.deviceOnlyremain supported. - Unsupported biometric saves now return before deleting or replacing an existing item, preventing silent downgrade to device-only protection.
- Added focused policy-support coverage without changing supported macOS/iOS/visionOS behavior.
- Reproduced Xcode 26.6's unmodified
xcodebuildhang at the verbose clang macro-discovery probe. A live sample caught the clang child blocked inwrite(2)before any Swift compile. - Reverified the existing diagnostic-only clang-probe wrapper, SHA-256
9c9a3222cd1a109220e92707e33706eb04bf38a718fd832a5112be46f7d55a79, on the disposable project. It suppresses only the problematic discovery stderr trace and delegates real compilation/linking to stable clang unchanged.
Commands and verification
- Baseline tvOS
xcodebuild -scheme ECS0Permissions -destination 'generic/platform=tvOS'failed on unconditionalLocalAuthenticationimport. - Focused Swift test: 1 test in 1 suite passed.
swift test --sanitize=thread: 296 XCTest tests and 12 Swift Testing tests passed, zero failures, no Thread Sanitizer race report.- Generic
ECS0Permissionsbuilds emitted real platform-specific modules for macOS, iOS, tvOS, and visionOS. git diff --checkpassed; isolated worktree was clean after explicit-path commit.- Stable Xcode first-launch status exited 0; deep code signature remained valid.
- Unmodified disposable stable-Xcode build reproduced the pre-compiler stall; only that self-started process tree was interrupted after sampling.
- Same build with command-scoped
CC=.../clang-probe-safe-wrapper.zshsucceeded in 3.78 seconds; binary output wasstable-xcode-probe-ok. - Global
xcode-select -premained/Applications/Xcode-27.0.0-beta.6.app/Contents/Developer.
Backup and rollback
- ecs0lib rollback after owner integration:
git revert ce2d8a13dbb777e39953096da74b9216b1f1ca67subject to owner branch policy. - Before integration, omit the cherry-pick; the isolated branch/worktree contains all source changes.
- Xcode diagnostic rollback: omit the command-scoped
CCvariable. No persistent Xcode setting changed. - Disposable
/private/tmp/xcode-stable-followup-20260903-*directories may be removed after evidence is no longer needed. - The retained stable-Xcode recovery bundle remains
/Users/richh/Archive/xcode-dupes-20260831/Xcode.app; no reinstall or bundle rollback is indicated.
Outstanding owner actions
- Cherry-pick
ce2d8a13dbb777e39953096da74b9216b1f1ca67onto the intended FEAT-17 integration branch and rerun the full four-platform aggregate there. - Do not admit the diagnostic clang wrapper into a trusted/App Store
archive unless its exact hash and scoped
CCinjection become explicit, independently verified trust-chain inputs. Prefer a newer non-beta stable Xcode containing the concurrent pipe-drain behavior, or validate Xcode 26.6 on a macOS 26 build host. - The ticket CLI resolved TASK-20260903-20 but warned it was never
claimed even though the ticket file retained a valid
claim_history; treat this as a registry/index inconsistency to repair separately.
Apple Notes publication status
notes_changelog.zshwas run from the Aqua desktop session and waited its complete 600-second bound.- Result:
ERROR: Notes never became responsive within 600s. File copy is unaffected; retry later. - The per-host Apple Notes entry is pending and is not claimed as saved. This file is the durable local archive for retry.