Platform Qualification
Authoritative support matrix for Linux, macOS, and Windows.
Authoritative statement on cross-platform runtime qualifications in accordance with docs/PLATFORM-SUPPORT.md.
Platform Classification Matrix
| Target | Classification | Meaning & Evidence |
|---|---|---|
| Linux x86_64 | SUPPORTED | Release-qualified: native runtime, parity, security, CI, and artifact evidence all green. |
| macOS x86_64 | CONDITIONALLY SUPPORTED | Implemented; Seatbelt isolation is Degraded (never full sandbox); native re-verification pending macOS runner. |
| Linux aarch64 | COMPILE-ONLY | Compiles cleanly; no native runtime evidence — do not assume x86_64 behavior. |
| macOS aarch64 | COMPILE-ONLY | Compiles cleanly; native runs awaiting dedicated Apple Silicon test runner. |
| Windows x86_64 | COMPILE-ONLY | Compiles; Job Objects, ACLs, and ConPTY verified by contract only — native runs pending Windows runner. |
| Windows aarch64 | COMPILE-ONLY | Compiles cleanly; no native runtime evidence. |
Capability Gaps & Fail-Closed Behavior
- Windows: Has no file-descriptor limit, no filesystem isolation, and no network namespace isolation. Requests requiring them fail closed with typed errors — never silently.
- macOS: Memory limits are best-effort (
RLIMIT_AS); Linux uses hard kernel cgroup v2 enforcement. - Windows Path Containment: Uses lexical comparison; reparse-point resolution requires privilege and is a documented limitation.
Qualification Invariants
- A target is SUPPORTED only with native runtime evidence. Compilation is not support.
- Degraded never means Available. Unsupported never means successful.