rdmsm4x-changelog-20260903-0226-tyrell-build13-package-sign
Packaged and team-signed Tyrell 0.2.0 build 13 (Tyrell.app + nested TyrellBar.app, universal2, Team ZU2882L4HT) in the build18 worktree at HEAD 70d00c08; package/sign only, nothing installed or deployed. Undo: none needed (artifact lives in gitignored .build/; rerun the script to regenerate).
Tyrell 0.2.0 build 13 — package + sign evidence
[2026-09-03 02:27:28 EDT · rdmsm4x] request: fleet msg 20260903-021723-F4684800 (codex@rdmsm4x → claude@rdmsm4x) Scope executed: PACKAGE AND SIGN ONLY. No source edit, commit, install, launch, deploy, launchd, TCC, or database change.
Source gate (fail-closed) — PASSED
- worktree: /Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902
- HEAD before: 70d00c080f2c88b03bf3118ae4187b3f25e8cdbe HEAD after: 70d00c080f2c88b03bf3118ae4187b3f25e8cdbe
- 522a2b0b61fa8d8f4609138439eefb702b692b2e is an ancestor of HEAD (implementation commit)
- git status --porcelain --untracked-files=all: 0 lines before, 0 lines after (.build/ is gitignored)
Manager context
- host rdmsm4x · user richh uid 501 · launchctl managername=Aqua · manageruid=501 · SSH_CONNECTION none
- Claude Code desktop-app session; Bash sandbox disabled for the packaging step so codesign could reach the login keychain
- toolchain: Xcode 27.0 (27A5252f) /Applications/Xcode-27.0.0-beta.6.app · Swift 6.4
- identity in keychain: "Apple Development: Richard Doty (S65Q255HA8)" OU=ZU2882L4HT, expires 2027-08-05. No Developer ID present (script prefers Developer ID, falls back to Apple Development). Not notarized.
Command
zsh scripts/make_app_bundle.zsh (no --install) started 02:22:xx EDT, finished 02:23:45 EDT, rc=0
- all 5 declared products rebuilt --arch arm64 --arch x86_64 (incremental; products current from 02:17 run): tyrelld tyrell tyrellbar tyrell-app tyrell-mcp → all lipo "x86_64 arm64"
- prior .build/Tyrell.app (02:17:59, Identifier=tyrell-app, TeamIdentifier NOT SET) removed and replaced
- signing order: nested TyrellBar.app 02:23:44 → outer Tyrell.app 02:23:45
Artifact
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/.build/Tyrell.app (51M, 7 files, 11 dirs, 0 symlinks) Version 0.2.0 · Build 13 (CFBundleShortVersionString/CFBundleVersion identical in outer and helper Info.plist)
Outer Tyrell.app
- CFBundleIdentifier com.eastcoastscience.Tyrell · CFBundleExecutable Tyrell · LSMinimumSystemVersion 15.0
- TeamIdentifier=ZU2882L4HT · Authority=Apple Development: Richard Doty (S65Q255HA8) → Apple WWDR CA → Apple Root CA
- CodeDirectory v=20500 flags=0x10000(runtime) · Runtime Version=15.0.0 · Hash type sha256 · Sealed Resources v2 rules=13 files=2 · entitlements: none
- arm64 CDHash=ec6e20caaecc96cd7974a640ac2f3e1499a8baf2 (full ec6e20caaecc96cd7974a640ac2f3e1499a8baf21567186d3d08d48ac4bea5e7) hashes=923+3 page 16384
- x86_64 CDHash=66fc1e5432f8654bd1d29519298ee57baa37cde7 (full 66fc1e5432f8654bd1d29519298ee57baa37cde7541e5ae8322d060e21d1d05b) hashes=3757+3 page 4096
- designated => identifier "com.eastcoastscience.Tyrell" and anchor apple generic and certificate leaf[subject.CN] = "Apple Development: Richard Doty (S65Q255HA8)" and certificate 1[field.1.2.840.113635.100.6.2.1] /* exists */
- lipo: x86_64 arm64 (x86_64 15526688 B, arm64 15169856 B) · file 30718272 B
- SHA-256 Contents/MacOS/Tyrell = 36b5ee65416d571e3fc68a986367742fa2346efada8e779439a1018e16c2f95a
Helper Contents/Library/LoginItems/TyrellBar.app
- CFBundleIdentifier com.eastcoastscience.TyrellBar · CFBundleExecutable tyrellbar · LSUIElement true · LSMinimumSystemVersion 15.0
- TeamIdentifier=ZU2882L4HT · same Authority chain
- CodeDirectory v=20500 flags=0x10000(runtime) · Runtime Version=15.0.0 · Sealed Resources v2 rules=13 files=0 · entitlements: none
- arm64 CDHash=e7f48b875e1aeff83632518e60501687ea7c23ee (full e7f48b875e1aeff83632518e60501687ea7c23ee6c4b62b611b5c9d9ef11e763) hashes=614+3
- x86_64 CDHash=41a30bb651610dcfd730e77774a089981a7b1e59 (full 41a30bb651610dcfd730e77774a089981a7b1e59ae609d6aa6ae4b4f1f0d8ebb) hashes=2494+3
- designated => identifier "com.eastcoastscience.TyrellBar" and anchor apple generic and certificate leaf[subject.CN] = "Apple Development: Richard Doty (S65Q255HA8)" and certificate 1[field.1.2.840.113635.100.6.2.1] /* exists */
- lipo: x86_64 arm64 (x86_64 10312656 B, arm64 10087808 B) · file 20426112 B
- SHA-256 Contents/MacOS/tyrellbar = 0afa59a29b27d2ecadf10b91a177d10b8ede7483adf09fe75950787fdb3c59e1
Verification
- codesign --verify --deep --strict --verbose=2 Tyrell.app → rc=0: nested TyrellBar.app prepared+validated, "valid on disk", "satisfies its Designated Requirement"
- codesign --verify --deep --strict --verbose=2 TyrellBar.app → rc=0: "valid on disk", "satisfies its Designated Requirement"
- script gates passed: universal2 on all 5 products and both bundled binaries; no raw Contents/MacOS/tyrellbar; helper bundle ID distinct; Team ID both = ZU2882L4HT; runtime flag; DR binds helper identity
Replaced prior output
- prior Contents/MacOS/Tyrell SHA-256 1650c4554dd2c363ccd9e52b322555964bfb74d5c9063e3ab503925298f9ea3e (02:17:59, unsigned team) → now 36b5ee65…
- prior …/TyrellBar.app/Contents/MacOS/tyrellbar SHA-256 56ac782e0c499e14d3b53d0644c847e56fd8101643b442211606c2f7fcd941ba → now 0afa59a2…
- (1650c455… equals the untouched loose .build/release/tyrell-app, i.e. the binary content was already current; the bundle copy differs only by the team signature)
Bundle manifest / checksum
- per-file manifest: .build/evidence-build13-20260903-0222/Tyrell.app-manifest.sha256 (7 lines) — SHA-256 of manifest = 5d2fc45b8307e2dff5e3e8ee135f25c9901c2de17f74e58497781c9af934d3e5
- archive: .build/evidence-build13-20260903-0222/Tyrell.app.tar (ustar, uid/gid 0, entries from sorted list Tyrell.app-entries.txt, 18 entries, 53678592 B) SHA-256 = b8bb48b6fd0bccf7c498e6a28f496f8fa8bd7630ec7a58d92ae867a09ad54b29 — reproduced byte-identical on a second run. (tar to stdout pads differently → different hash; not an event.) Manifest contents: eded8ac82bced7892221428b87c43064cb2294cdbfc1770791aee69b535db549 .build/Tyrell.app/Contents/Info.plist 49689ae8c77f3cd2a9cbbb8517dbaaf85f9b52376120b98ad1c8dff97eaf75f2 .build/Tyrell.app/Contents/Library/LoginItems/TyrellBar.app/Contents/Info.plist 0afa59a29b27d2ecadf10b91a177d10b8ede7483adf09fe75950787fdb3c59e1 .build/Tyrell.app/Contents/Library/LoginItems/TyrellBar.app/Contents/MacOS/tyrellbar 6686de10a28a2fe11b36cbb86dcbacc827cfc4ea116b4dabf1845e5aee629e9b .build/Tyrell.app/Contents/Library/LoginItems/TyrellBar.app/Contents/_CodeSignature/CodeResources 36b5ee65416d571e3fc68a986367742fa2346efada8e779439a1018e16c2f95a .build/Tyrell.app/Contents/MacOS/Tyrell 6d77ccca2cfb302d23960b3fdd7c35062593275746447f67fb77917e75ceabce .build/Tyrell.app/Contents/Resources/Tyrell.icns b997aef317ddfb6a34eed35ce6237feae3f33b151a3535a4c1dfbd1a65bd600e .build/Tyrell.app/Contents/_CodeSignature/CodeResources
Loose release binaries (script re-signs these by design; tyrell-app loose copy is left as built)
8d08ec4fe3a408e653466420fd5290ee0b6fe89de7d215f3bb132f3cbf238118 .build/release/tyrelld 7771108da693ad497e244c57a0f90c9744ed4aa09e2ab829dd18456c5336f6c9 .build/release/tyrell 9ef1e22f751513063dd4c14b33b3cb3b9db33a25feb312d0777c008168d7c506 .build/release/tyrellbar 1650c4554dd2c363ccd9e52b322555964bfb74d5c9063e3ab503925298f9ea3e .build/release/tyrell-app 76c2c5b6d1274ad7a5608275257ff94297edff8c54f8e7b1b64c42a8b2c3687d .build/release/tyrell-mcp
Logs
- raw (ANSI, session scratchpad): /private/tmp/claude-501/-Users-richh-dev/c0107df5-793a-4af7-9505-6f0ed2ac0be2/scratchpad/make_app_bundle-20260903-0222.log SHA-256 d4b90b70046373a272d434fc07911e0cc24aebf7fa3844a999dbf2b745cae86d
- redacted (ANSI/OSC stripped, 571 lines): .build/evidence-build13-20260903-0222/make_app_bundle-20260903-0222.redacted.log SHA-256 747b046f96690b721cd00985cd1ced77451a39739259ae8ca3ee4f3820d5ef87
- secret scan of redacted log: 10 hits, all the Swift identifier "r.secret" inside a Sendable compiler warning (source line 134); no credential values. Build emitted Swift 6 Sendable warnings only, no errors.
Observations (not acted on — out of scope)
- Info.plist LSMinimumSystemVersion is 15.0 while the fleet platform-target rule names 27.0 / 26.7; the script sets it, codex/Rich own that decision.
- Evidence dir lives under .build/ and will not survive a swift package clean; the changelog copy is at ~/dev/LLM/Claude/changelogs/.