This records the original correction. For the current manifest-based addressing contract and updated fixtures, see endpoint manifest validation.
The native adapter previously loaded digest-pinned images but replaced their
Compose environment with an old Community-specific dictionary. Changing the OCI
URL alone therefore omitted NEXTAUTH_TRUSTED_SIGNIN, current storage variables,
relay settings, and other Studio defaults.
- All 101 regression tests pass, including the real Studio Compose fixture and
an independent reference generated by standalone Docker Compose
config --format json, with an empty process environment and/dev/nullas env file. No containers were started by that reference command. The fixture contains only published artifact defaults, not local credentials. - All six service environments match that reference before explicit native topology substitutions. Tests cover map/list forms, anchors, merge precedence, quoting, CRLF, empty versus unset values, image-environment precedence, duplicate keys/services, unsupported external env sources, and incompatible native ports.
- The local build passes strict code-signature, helper, linkage and entitlement checks. Yams is pinned to 6.2.2 and linked into the sandboxed host; its license is included. Permissions remain App Sandbox, network client/server, virtualization, and the previously approved two-name Sparkle Mach lookup exception. Sparkle's installer helper boundary is unchanged.
- The old app was quit cleanly; the corrected local app was started using the existing persistent volumes. No cache purge, database reset, or data deletion.
- The first VM start failed to acquire a DHCP lease. An explicit stack restart acquired a lease and all services started. DHCP configuration was not changed or replaced with hardcoded addresses to get past this transient failure.
- The UI changed from email-code verification to trusted local identity entry, explicitly stating that no code is sent. No account was selected or created during verification. Trusted sign-in is not the same as automatically choosing an identity, and is supplied by Compose rather than forced by native code.
- The running Studio process owns only loopback listeners on 3000, 3001 and 3900. Read-only HTTP checks reached the relay (404 at its root) and S3 (403 for an unauthenticated request), proving forwarding without claiming authenticated storage operations or realtime sessions were exercised.
This is still the known-stack adapter, not complete Docker Compose support. Commands, mounts and health checks remain platform-specific. Custom app-shell, space and portal hostname resolution, authenticated object uploads and full realtime sessions were not tested. Auxiliary ports fail closed on conflicts; their fixed internal ports are documented in the README. No release was minted.