Skip to the content.

Local repository readiness review

Home · Documentation · Pre-publication review · Evidence

Repository: macos-install-security-research
Local review: September 28, 2026
Git state at local review: initialized on main, uncommitted; no remote, push, Pages deployment, release, or tag.
Research state, September 29 update: Stage 6F.7 remains partial. The 147,253-object register has 76 bounded semantic paths, 147,177 pending paths, and zero whole-object closures. The local-review and first-publication checks below remain dated records; validate each subsequent revision independently.

Research state, September 30 client/mount checkpoint: Stage 6F.7 remains partial. The same-build Bootability client/mount pass raised bounded path coverage to 78 of 147,253, with 147,175 pending and zero whole-object closures. The September 29 figures and local-review checks below are historical checkpoints.

Current research state, September 30 option-client checkpoint: Six selected same-build client traces and the startupdiskhelper launch configuration raise bounded coverage to 85 of 147,253, with 147,168 pending and zero whole-object closures. No Brain/trust-cache override producer, accepted peer or device-side policy effect was established. Publication checks verify presentation and provenance, not runtime behavior or audit completion.

Published outcome: standalone repository and GitHub Pages site are public. The first corrected publication commit, 0da15ca, passed GitHub Actions validation and the Pages deployment. The hosted homepage, audit-status page, one finding page, one SVG diagram, and LICENSE each returned HTTP 200. The research coverage remains partial despite successful publication checks.

Check Local result
Public repository files 91, excluding Git and ignored build/dependency/cache directories
Markdown pages 46; 37 substantive source narrative sections assigned by the source map
Findings 100 unique IDs; claim/evidence/limit text checked against the byte-identical source CSV; 100 source locations, including 72 explicit-ID narrative locations and 28 labeled section-context locations
Diagrams 11 Mermaid sources and 11 rendered SVGs; 11 image references resolve in the built site
Public derived data Four CSVs and three JSONs; one SHA-256 manifest with 30 verified entries for diagrams and public data
Validation utilities Six: repository validator, retained-source verifier, rendered-site validator, external-reference probe, artifact SHA-256 verifier, diagram renderer
Authored links 804 Markdown links parsed by the repository validator; local targets and supported anchors resolve
Rendered Pages links 46 HTML pages; 688 local links, 158 fragments, and 11 images resolved under /macos-install-security-research
External URLs 74 unique authored HTTP(S) URLs checked; 73 HTTP 200, one Microchip HTTP 403, zero confirmed broken URLs, zero final-URL redirects, zero plain HTTP links
Jekyll github-pages 232 / Jekyll 3.10.0 built successfully with Ruby 3.4 and repository-local gems; local jekyll serve responded at the configured project path
Visual spot-check Headless Chrome displayed the homepage and architecture SVG at desktop width and the findings index at mobile width; Cayman tables scroll within their container
Source integrity Nine retained source-document SHA-256 values match the original audit workspace; three public CSVs remain byte-identical copies
Privacy and distribution No local home-directory path, local username, private-key header, raw Apple binary, installer image, or private-evidence directory in the public file set. Twenty textual private-evidence/ provenance pointers in two pages are intentional and do not promise public downloads.
License CC BY 4.0 selected for original material; third-party scope documented in the license note
CI and Pages Both succeeded on publication commit 0da15ca; future commits require fresh validation

The three initially malformed Apple documentation links with literal parentheses were repaired and rechecked. The remaining Microchip PM40100 URL returned HTTP 403 to the command-line probe; a search-indexed version of the same official product page was visible, so this is recorded as client-denied reachability rather than a dead reference. The external-link result is in external-links.json. External status can change after this snapshot.

The original pre-push Jekyll build used a placeholder repository name because no remote existed then. The published repository name now matches _config.yml’s baseurl; hosted Pages and the live page checks corroborate the local build. The early missing-HEAD message came from the intentionally commit-free preparation checkout and did not recur after the first commit.

The original 43-GB private evidence tree, Apple binaries and packages, reconstructed images, firmware and kernel collections, full decoder output, host identifiers/logs, raw NVRAM, and protected records remain outside this repository. The public checksums establish integrity of this draft’s derived files; the source hashes establish which retained report versions informed it. Neither independently verifies original Apple signatures or historical execution for a reader who lacks the originals.

The pre-publication review separates locally validated items, unfinished research, owner decisions, and optional improvements. No commit or upload had been made at this local validation checkpoint; later GitHub state must be checked at the repository itself.