The Compose test helper expects host UID/GID on every non-root host, while the Docker driver deliberately remaps only on Linux. A Darwin host at 501:20 should therefore keep fixture account IDs 33:33 (www-data) and 1001:1001 (vscode). Root-host Compose CI exercises the root bypass and does not prove non-root remapping.
Original baseline: d68e5d3fd4fff78fac63321dbcdc316cc1aa0b5e. Implementation base: 74810ddd4de91fb6061eb3263108b84ea48e5f3d. See the original oracle, the driver contract, the deliberate Linux policy in e60434d, and Compose test addition fc7a182.
The accepted scope corrects only expectation selection/diagnostics in e2e/tests/up-docker-compose/helper.go, adds pure coverage in helper_test.go, and adds two validation steps in .github/workflows/pr-ci.yml. Production behavior, fixture images/users/defaults, SSH username, content and ownership assertions remain unchanged. No provider, runtime, sidecar-pin, package-download, account, socket-permission or protected-check changes.
The accepted CI-first contract replaces this issue's original mandatory extra local privileged process and two-fixture changed-ID requirements. Stronger account-inventory/collision coverage remains future production work. It is not an additional local gate for this test-only correction, and no observed failure is waived.
Acceptance:
Historical evidence is retained: focused Darwin UID cases passed 2/2; full Darwin Compose passed 51/55 with feature-permission and package-download failures. A real Linux 1000:1000 run passed www-data remapping but failed vscode SSH with duplicate ubuntu/vscode UID1000 accounts. The collision remains a separate, unfixed production defect; no fixture account is deleted or reassigned here.
On hosted 1001:1001, vscode already matches its fixture IDs and is not changed-ID proof. Root-only CI is not non-root proof. Hosted acceptance remains pending until actual exact-head execution. If identity, Docker access, SSH, ownership, selection, or any required check fails, diagnose the failure rather than modifying accounts, permissions, assertions, or gates.
Related discovery: #1449. This correction remains separate from #1451/#1450 and does not close the image-consolidation or sidecar trackers. Hosted final-head reviews and protected merge remain required.
The Compose test helper expects host UID/GID on every non-root host, while the Docker driver deliberately remaps only on Linux. A Darwin host at 501:20 should therefore keep fixture account IDs 33:33 (
www-data) and 1001:1001 (vscode). Root-host Compose CI exercises the root bypass and does not prove non-root remapping.Original baseline:
d68e5d3fd4fff78fac63321dbcdc316cc1aa0b5e. Implementation base:74810ddd4de91fb6061eb3263108b84ea48e5f3d. See the original oracle, the driver contract, the deliberate Linux policy in e60434d, and Compose test addition fc7a182.The accepted scope corrects only expectation selection/diagnostics in
e2e/tests/up-docker-compose/helper.go, adds pure coverage inhelper_test.go, and adds two validation steps in.github/workflows/pr-ci.yml. Production behavior, fixture images/users/defaults, SSH username, content and ownership assertions remain unchanged. No provider, runtime, sidecar-pin, package-download, account, socket-permission or protected-check changes.The accepted CI-first contract replaces this issue's original mandatory extra local privileged process and two-fixture changed-ID requirements. Stronger account-inventory/collision coverage remains future production work. It is not an additional local gate for this test-only correction, and no observed failure is waived.
Acceptance:
Historical evidence is retained: focused Darwin UID cases passed 2/2; full Darwin Compose passed 51/55 with feature-permission and package-download failures. A real Linux 1000:1000 run passed www-data remapping but failed vscode SSH with duplicate ubuntu/vscode UID1000 accounts. The collision remains a separate, unfixed production defect; no fixture account is deleted or reassigned here.
On hosted 1001:1001, vscode already matches its fixture IDs and is not changed-ID proof. Root-only CI is not non-root proof. Hosted acceptance remains pending until actual exact-head execution. If identity, Docker access, SSH, ownership, selection, or any required check fails, diagnose the failure rather than modifying accounts, permissions, assertions, or gates.
Related discovery: #1449. This correction remains separate from #1451/#1450 and does not close the image-consolidation or sidecar trackers. Hosted final-head reviews and protected merge remain required.