Skip to content
M31A

Platform Qualification

Authoritative support matrix for Linux, macOS, and Windows.


Authoritative statement on cross-platform runtime qualifications in accordance with docs/PLATFORM-SUPPORT.md.

Platform Classification Matrix

TargetClassificationMeaning & Evidence
Linux x86_64SUPPORTEDRelease-qualified: native runtime, parity, security, CI, and artifact evidence all green.
macOS x86_64CONDITIONALLY SUPPORTEDImplemented; Seatbelt isolation is Degraded (never full sandbox); native re-verification pending macOS runner.
Linux aarch64COMPILE-ONLYCompiles cleanly; no native runtime evidence — do not assume x86_64 behavior.
macOS aarch64COMPILE-ONLYCompiles cleanly; native runs awaiting dedicated Apple Silicon test runner.
Windows x86_64COMPILE-ONLYCompiles; Job Objects, ACLs, and ConPTY verified by contract only — native runs pending Windows runner.
Windows aarch64COMPILE-ONLYCompiles cleanly; no native runtime evidence.

Capability Gaps & Fail-Closed Behavior

  • Windows: Has no file-descriptor limit, no filesystem isolation, and no network namespace isolation. Requests requiring them fail closed with typed errors — never silently.
  • macOS: Memory limits are best-effort (RLIMIT_AS); Linux uses hard kernel cgroup v2 enforcement.
  • Windows Path Containment: Uses lexical comparison; reparse-point resolution requires privilege and is a documented limitation.

Qualification Invariants

- A target is SUPPORTED only with native runtime evidence. Compilation is not support.
- Degraded never means Available. Unsupported never means successful.