rdmsm4x — RTTy Builds 503 and 504 cut, deployed to all six hosts, and verified — 2026-09-09
One line: RTTy shipped twice today from rdmsm4x — Build
503 (0.3.828, dashboard fixes) and Build 504 (0.3.829, Rich's new app
icon) — each gated, each deployed to all six fleet Macs with a rollback
armed, each verified on every host by execution; the fleet's move to
Developer ID signing is measured and blocked pending one provisioning
profile.
Scope
Hosts changed: rdmbair15m5, rdmbair13m5, jdmbair13m5,
rdmpw3265m, rdmpw3275m, rdmsm4x — all six run
/Applications/RTTy.app at 0.3.829 build 504.
What changed, in order
- PR #37 (
4202b54) — dashboard applications section sized from the window it actually has; default window 1150x720 → 1150x1500 so the automatic application checks are on screen at open. The flows graph draws ~310pt instead of ~95pt. - PR #38 (
9b30fd3) — the Chart/Split/Table and 1m/5m/15m/1h controls overlapped at every width: each segmented picker carried a fixed frame narrower than the control draws (140 vs 166.0, 130 vs 172.5, 160 vs 187.0). Replaced withfixedSize()+ViewThatFits; four regression tests pin it. - Build 503 =
9251d3d, VERSION 0.3.827 → 0.3.828, BUILD_NUMBER 502 → 503. - PR #39 (
98f62be) — Rich's new app icon, adopted through the repo's reviewed normalizer. - Build 504 =
141c90e, VERSION 0.3.828 → 0.3.829, BUILD_NUMBER 503 → 504.
Release gates
Both builds: 10 of 10 gates PASS, rc=0, 75
assertions, native and Rosetta each 1052 executed of 1057
discovered, 0 failures. Build 504's gates ran at 141c90e
and were not rerun for the deployment, because the archived bundle is
the gate-produced one (BuildInfo.gitCommit 141c90e,
gitDirty false).
Four gate runs failed environmentally before the first clean one,
none a repo defect: RTTY_PROVISIONING_PROFILE not exported;
errSecInternalComponent over ssh;
_LSOpenURLsWithCompletionHandler -600 racing the running
app; -25211 osascript is not allowed assistive access
locally.
Finding worth keeping: signing and gate 7 need
different contexts. codesign resolved the identity out of
login.keychain-db, which no ssh session can unlock, while
gate 7's System Events probe needs the sshd Accessibility grant no local
session has. Reordering the user keychain search list to
fleet-signing, login, System for the run — same
certificate, same SHA-1, present in both — let one context run all ten.
Proven both ways on a throwaway copy: fail before, rc=0 after, no
--keychain flag. The order was restored to
login, fleet-signing, System immediately after each
run.
Artifacts
| Build | Commit | Executable SHA-256 | ICNS SHA-256 | Archive |
|---|---|---|---|---|
| 503 | 9251d3d |
ad2e6a43a07f83b4fcaf5bfa1f9c355e8b632d62bff6576b61ce6246832cfe5a |
778c9091…cc09 |
RTTy-direct-0.3.828-build503-9251d3d.zip,
86e16c34…ba57 |
| 504 | 141c90e |
5016c2b85e653b6b3bb31e6bf7df9e9398710536e6f670d09c55458d62376bd4 |
155ba5f4…e592 |
RTTy-direct-0.3.829-build504-141c90e.zip,
91214d31…e3b2 |
Both signed Apple Development: Richard Doty
(S65Q255HA8), team ZU2882L4HT, development profile
9d6a4fb0-44e7-40c4-aca0-f252bddecd51, universal
x86_64 arm64, LSMinimumSystemVersion 26.0.
Deployments
- Build 503, 15:38–15:47 EDT, six hosts. jdmbair13m5 rejoined the fleet (Tailscale up, 21 GiB free where it had 101 MiB) and was armed with its own Build 501 rollback; the other five with Build 502.
- Build 504, 17:31–17:37 EDT, six hosts, canary rdmbair15m5 first and the hub last, one rollback baseline (Build 503) everywhere. Accepted in 55–56 s per host with 4 ping children and 0 nettop children.
Verified after each deployment by execution on every
host: version, build, lipo -archs, executable
SHA-256, ICNS SHA-256, signing Authority, process count, and — for 504 —
the running process's executable path read with
lsof -p <pid>, because a relaunch can otherwise
re-activate a process still executing from the moved-aside rollback
bundle.
Receipts show two CDHashes (8f5c70c7… on arm64,
2682e654… on Intel). That is codesign -dv
reporting the slice native to each Mac, not drift; the executable
SHA-256 is identical everywhere.
Commands of record
- Build/stage:
RTTY_CODESIGN_IDENTITY=<Apple Development SHA-1> RTTY_PROVISIONING_PROFILE=<abs path> ./script/build_and_run.sh --stage - Gates:
ssh richh@rdmsm4x 'zsh -lc "cd ~/dev/apps/RTTy && … && zsh ~/bin/fleet_sign_unlock && bash script/qa_release.sh"' - Deploy:
zsh ~/dev/_handoff/rtty-build50{3,4}-20260909/release/build50{3,4}/tools/deploy_build50{3,4}_fleet.zsh <host> - Hub relaunch:
osascript -e 'quit app "RTTy"'→lsregister -f -R -trusted /Applications/RTTy.app→open -a RTTy
Backups and how to undo
Every host carries
/Applications/.RTTy.app.rollback-build503-141c90e (Build
503). Restore = quit RTTy, sudo mv the rollback back over
/Applications/RTTy.app, open it. Earlier
rollbacks (501, 502) were left in place on the hosts that had them;
nothing was deleted.
Repository: main at 91c8d74, tags
v0.3.828-build503 and v0.3.829-build504,
pushed to origin, backup and fleet. Evidence:
docs/release-evidence/build-503/ and
build-504/.
Outstanding owner actions
- Developer ID + notarization (DEC-20260909-03) is blocked for
RTTy Direct. Measured on copies: a Developer-ID-signed bundle
signs with hardened runtime and a secure timestamp but fails to
launch (
NSPOSIXErrorDomain Code=163,Launchd job spawn failed); the same bundle with no entitlements launches. The blocker is the restricted iCloud entitlements without a Developer ID provisioning profile foriCloud.com.eastcoastscience.rtty; the development signing path also addsget-task-allow, which notarization refuses. Rich installs that profile, or decides to ship Direct without CloudKit — a feature removal, and therefore his call. - The Dock tile was not visually verified on any host
— no Screen Recording grant in this session.
killall Dockon the hub is the one command if the old artwork persists. - App Store / TestFlight remain blocked on the Apple Distribution certificate and App Store profiles.
No secrets are recorded here; keys are referenced by name and location only.