DL-338
apple-container adoption is slow-rolled and macOS embedded ships on podman-machine (Matt, RIG-3490, escalated by the T-1 spike): the T-1 spike ruled the guestd unix→vsock leg RED — no host-side attach point through the container CLI — firing the escalation trigger at design.md:619-620; Matt’s ruling holds T-2 rather than adopting the spike’s proven --publish-socket substitute, so the gateway keeps its host-listens/guest-dials ordering (go/internal/runner/gateway/socket.go:4-13) and the inversion plus its guest-readiness handshake stay unbuilt. Narrows DL-330’s sequencing only — DL-330’s direction (apple-container as THE macOS embedded runtime, when adopted) is unchanged; a hold, not a settled transport, so the fork reopens with RIG-3490 if adoption resumes. Two spike findings must be re-read rather than re-assumed then: raw AF_UNIX over virtiofs is RED (confirming the compass-local-dev limitation, killing the “vsock takes the socket off virtiofs” dissolution argument), and CapEff is all-zero at uid≠0 even with --cap-add ALL, whose fix at go/internal/runtime/agent.go:319-328 is shared with the live podman path and unreachable by the podman test lane today (CI’s only -tags podman run is scoped to ./e2e/..., so 16 of 32 podman-tagged files fall outside that lane), so T-2 must widen that lane before any cover counts
Status: Active (Matt, 2026-09-07)
Record: ../../platform/apple-container-macos-runner/transport-slow-roll-amendment.md