Repository navigation
feat(release): let the Homebrew formula withdraw macOS - #349
Conversation
Carry mode pinned macOS to the last notarized build in the tap, which today is 0.3.2: a daemon too old for the formula's own service arguments. With Apple holding every notarization since 2026-09-29, offering that build is worse than offering none. The renderer gains a withdrawn macOS state. --withdraw-macos replaces the on_macos download block with a fatal NotarizedMacosBuildRequirement, so a macOS install or upgrade fails with the reason and a link to the releases page. Homebrew needs a URL to load the formula on macOS, so the withdrawn block names the release's Linux amd64 tarball with its checksum; the requirement stops the install. readPublishedMacos recognises the withdrawn stanza, so carry mode keeps it withdrawn on later releases, and the next release with a notarized build renders macOS and the cask in full again. The tap commit body for a carried release no longer claims macOS sits on the last notarized build, since it may be withdrawn. RELEASING.md describes the state and the matching disable! on the cask. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Homebrew formula generator now supports withdrawing macOS installs while continuing Linux releases. Carry mode preserves the withdrawn state, and a later notarized macOS release restores the macOS formula stanza and cask. ChangesHomebrew macOS withdrawal
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant ReleaseOperator
participant homebrew-formula.mjs
participant HomebrewFormula
participant NotarizedMacosBuildRequirement
ReleaseOperator->>homebrew-formula.mjs: Provide --withdraw-macos and Linux release inputs
homebrew-formula.mjs->>HomebrewFormula: Write formula with withdrawn macOS stanza
HomebrewFormula->>NotarizedMacosBuildRequirement: Check platform requirement
NotarizedMacosBuildRequirement-->>HomebrewFormula: Fail on macOS with releases guidance
Merge Risk: ⚪ Minimal · up to Normal macOS formula installs are blocked before the Linux archive is downloaded. The cask requires the separately documented disablement step. No merge-blocking issue remains after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change restricts macOS installation without adding runtime privileges. Withdrawal persists across later releases, but complete withdrawal also requires separately disabling the cask. That external rollout and behavior on a supported Homebrew version remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 4 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
Comment |
The withdrawn formula's message linked the releases page, whose only macOS downloads are 0.3.2 and older, and the README and three docs pages still sent macOS users to the DMG and the cask. The requirement message now says to remove an older build with `brew uninstall hypercolor`, and each macOS install section opens with a notice that macOS is on hold for notarization, that the older builds on the release page should not be installed, and how to remove 0.3.2 or earlier. The notices sit above the existing instructions so restoring macOS is a deletion. Also from review: the withdrawn-render test now checks a phrase that exists on one line, a new test covers the guard that refuses a template whose first on_macos block is not the download, the generated comment no longer claims the requirement is the only thing that could stop an install, and RELEASING.md says the disabled cask skips upgrades rather than failing them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The formula's refusal no longer links the releases page, whose only macOS downloads are 0.3.2 and older; it says to remove an older build with brew uninstall hypercolor. The disabled cask's reason names brew uninstall --cask hypercolor-app the same way. Rendered from the updated template in hyperb1iss/hypercolor#349. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
What this changes
The Homebrew renderer can now withdraw macOS instead of carrying an old build forward.
homebrew-formula.mjs --withdraw-macosreplaces the formula'son_macosdownload block with a fatalNotarizedMacosBuildRequirement. As a result, a macOS install or upgrade fails with the reason and the command to remove an older build, and no build is offered.Once withdrawn, macOS stays withdrawn:
readPublishedMacosrecognises the withdrawn stanza, so carry mode keeps it on every later release while Linux advances. The next release that ships a notarized macOS build renders macOS and the cask in full again, with no manual step.The README and the three macOS install sections on the docs site (installation guide, download page, install chooser) now open with a notice. It says macOS is on hold for notarization, that the older macOS builds on the release page should not be installed, and how to remove 0.3.2 or earlier. The notices sit above the existing instructions, so restoring macOS is a deletion.
Why
Carry mode pinned macOS to the newest notarized build in the tap, which is 0.3.2. That release predates the
--macos-ownerargument the formula's own service passes, and we don't want anyone installing it. Apple has held every notarization since 2026-09-29, so there is no newer notarized build to offer instead. The companion tap PR applies the withdrawal now and disables the cask.Verification
just verifypasses locally (Rust fmt + lint + test)just denypasses (required for dependency or license changes)just ui-testandjust ui-buildpass (required forcrates/hypercolor-ui/)just sdk-lint,just sdk-check, andjust sdk-buildpass (required forsdk/)just python-verifypasses (required forpython/)just compat-checkpasses (required fordata/drivers/vendors/*.toml)just docs-buildpasses (required for docs or README changes)cd docs && zola checkpasses (required for docs link/content changes)scripts/orpackaging/)just e2e-buildpasses with the normal Servo stack (required for daemon/UI/effect integration changes)just e2e-build-cpupasses when validating the CPU smoke fallbackjust e2epasses against the Servo stack (required for end-to-end behavior changes; starts daemon/browser)No Rust, UI, SDK or Python files change.
zola buildandzola checkpass with the new notices (97 pages).Workflow tests: the homebrew-formula, macos-release and macos-ci-coverage suites pass 32 of 32 under
node --test. As before, the one existingshasumtest runs here with asha256sumshim. The new cases cover four paths:--withdraw-macoswith other macOS inputs, and the guard that refuses a template whose firston_macosblock is not the download (removing that guard fails the test).A workflow test also runs the job's real checksum, render and push shell against a withdrawn published formula.
Real Homebrew: the companion tap PR's workflow installs the withdrawn formula and the disabled cask on macOS with Homebrew 7.0.7. The formula resolves 0.6.1 and then fails on the unsatisfied requirement with the notarization message, before anything is downloaded. The cask refuses with "has been disabled because it is waiting on a notarized release".
Independent review: a separate agent traced Homebrew's source and confirmed that install and upgrade both check requirements before fetching. It mutation-tested the carry and withdraw paths and passed the change. Its should-fixes (the releases link, uninstall guidance, docs, merge order) are addressed here.
Workflow lint: actionlint reports nothing new.
Notes for reviewers
mainmisreads a withdrawn formula as a carried build and would re-render a broken macOS stanza on the next tag.brew upgrade, which names the uninstall command. Cask upgrades are skipped with a warning, and the disabled reason names the cask's uninstall command.brew install --ignore-dependenciesskips requirements (it would install the Linux tarball on a Mac), andbrew fetchdownloads without checking them. Neither path reaches 0.3.2.🤖 Generated with Claude Code
Summary by CodeRabbit