Skip to content

fix: declare required-reason system uptime usage - #328

Open
jlipworth wants to merge 1 commit into
mainfrom
codex/fix-326-privacy-uptime
Open

jlipworth wants to merge 1 commit into
mainfrom
codex/fix-326-privacy-uptime

Conversation

@jlipworth

Copy link
Copy Markdown
Owner

Summary

  • Add SystemBootTime / 35F9.1 to the shared privacy manifest; no runtime or playback changes.
  • Audit all production uptime uses, including PMSKit retry timers, local raw baselines and exported in-app intervals against Apple's off-device exception.
  • Add source/four-product packaging regression checks and narrow development/release guidance.

Refs #326 (intentionally not auto-closing: signed archive acceptance remains open). #325 collection/review-demo disclosure work is separate; no App Store Connect answers or policy changes are included.

Verification

  • Canonical hermetic PMSKit: 121 XCTest + 1,707 Swift Testing tests passed; no live probes/media transcodes.
  • Four privacy regression tests; strict MkDocs, rendered links, Mermaid and repository hygiene passed.
  • Clean unsigned Release builds: visionOS Simulator, iOS Simulator, tvOS Simulator, arm64 macOS. Fresh executable mtimes verified.
  • All four actual app manifests match source; each product includes the expected Crypto dependency manifest (empty required-API/collection arrays, tracking false). Packaging checker validates platform identity and nested plist readability.
  • Passive iPhone Release install/launch: installed UUID matched, process alive, expected unauthenticated screen visually inspected, no fatal/assertion/uncaught-exception markers. Owned simulator shut down/deleted; no staged Mac app remains.

Remaining gates / limits

  • Exact signed Release archive manifests and Xcode aggregate privacy reports for all four platforms are not verified. Unsigned packaged resources are not archive/signing validation. Keep Privacy manifest: declare production systemUptime API use #326 open until this acceptance item is satisfied.
  • Native affected matrix conservatively selects hosted/UI lanes as well; those broad suites were not run for this resource-only fix. No visionOS launch claimed (main golden simulator-id file unavailable); no Mac launch claimed. No hardware/live-backend acceptance implied.
  • No signing/account/server changes, archive upload, version bump, tag, merge or issue closure.

Sanitized data-flow and validation evidence: docs/evidence/2026-09-15-privacy-uptime-audit.md. Private build/log/screenshot artifacts are not published.

@jlipworth

Copy link
Copy Markdown
Owner Author

CI completed for 57014b10: all five reported checks are green (PR docs/hygiene/PMSKit and push hygiene/PMSKit). Local four-platform unsigned Release packaging, hermetic tests, strict documentation/hygiene and passive iPhone launch evidence are recorded in the PR audit. The exact signed Release archive + Xcode aggregate privacy-report gate remains open; this PR has not been merged and #326 remains open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant