Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260909-1740-rtty-builds-503-504-six-host-deploy

rdmsm4x — RTTy Builds 503 and 504 cut, deployed to all six hosts, and verified — 2026-09-09

One line: RTTy shipped twice today from rdmsm4x — Build 503 (0.3.828, dashboard fixes) and Build 504 (0.3.829, Rich's new app icon) — each gated, each deployed to all six fleet Macs with a rollback armed, each verified on every host by execution; the fleet's move to Developer ID signing is measured and blocked pending one provisioning profile.

Scope

Hosts changed: rdmbair15m5, rdmbair13m5, jdmbair13m5, rdmpw3265m, rdmpw3275m, rdmsm4x — all six run /Applications/RTTy.app at 0.3.829 build 504.

What changed, in order

  1. PR #37 (4202b54) — dashboard applications section sized from the window it actually has; default window 1150x720 → 1150x1500 so the automatic application checks are on screen at open. The flows graph draws ~310pt instead of ~95pt.
  2. PR #38 (9b30fd3) — the Chart/Split/Table and 1m/5m/15m/1h controls overlapped at every width: each segmented picker carried a fixed frame narrower than the control draws (140 vs 166.0, 130 vs 172.5, 160 vs 187.0). Replaced with fixedSize() + ViewThatFits; four regression tests pin it.
  3. Build 503 = 9251d3d, VERSION 0.3.827 → 0.3.828, BUILD_NUMBER 502 → 503.
  4. PR #39 (98f62be) — Rich's new app icon, adopted through the repo's reviewed normalizer.
  5. Build 504 = 141c90e, VERSION 0.3.828 → 0.3.829, BUILD_NUMBER 503 → 504.

Release gates

Both builds: 10 of 10 gates PASS, rc=0, 75 assertions, native and Rosetta each 1052 executed of 1057 discovered, 0 failures. Build 504's gates ran at 141c90e and were not rerun for the deployment, because the archived bundle is the gate-produced one (BuildInfo.gitCommit 141c90e, gitDirty false).

Four gate runs failed environmentally before the first clean one, none a repo defect: RTTY_PROVISIONING_PROFILE not exported; errSecInternalComponent over ssh; _LSOpenURLsWithCompletionHandler -600 racing the running app; -25211 osascript is not allowed assistive access locally.

Finding worth keeping: signing and gate 7 need different contexts. codesign resolved the identity out of login.keychain-db, which no ssh session can unlock, while gate 7's System Events probe needs the sshd Accessibility grant no local session has. Reordering the user keychain search list to fleet-signing, login, System for the run — same certificate, same SHA-1, present in both — let one context run all ten. Proven both ways on a throwaway copy: fail before, rc=0 after, no --keychain flag. The order was restored to login, fleet-signing, System immediately after each run.

Artifacts

Build Commit Executable SHA-256 ICNS SHA-256 Archive
503 9251d3d ad2e6a43a07f83b4fcaf5bfa1f9c355e8b632d62bff6576b61ce6246832cfe5a 778c9091…cc09 RTTy-direct-0.3.828-build503-9251d3d.zip, 86e16c34…ba57
504 141c90e 5016c2b85e653b6b3bb31e6bf7df9e9398710536e6f670d09c55458d62376bd4 155ba5f4…e592 RTTy-direct-0.3.829-build504-141c90e.zip, 91214d31…e3b2

Both signed Apple Development: Richard Doty (S65Q255HA8), team ZU2882L4HT, development profile 9d6a4fb0-44e7-40c4-aca0-f252bddecd51, universal x86_64 arm64, LSMinimumSystemVersion 26.0.

Deployments

Verified after each deployment by execution on every host: version, build, lipo -archs, executable SHA-256, ICNS SHA-256, signing Authority, process count, and — for 504 — the running process's executable path read with lsof -p <pid>, because a relaunch can otherwise re-activate a process still executing from the moved-aside rollback bundle.

Receipts show two CDHashes (8f5c70c7… on arm64, 2682e654… on Intel). That is codesign -dv reporting the slice native to each Mac, not drift; the executable SHA-256 is identical everywhere.

Commands of record

Backups and how to undo

Every host carries /Applications/.RTTy.app.rollback-build503-141c90e (Build 503). Restore = quit RTTy, sudo mv the rollback back over /Applications/RTTy.app, open it. Earlier rollbacks (501, 502) were left in place on the hosts that had them; nothing was deleted.

Repository: main at 91c8d74, tags v0.3.828-build503 and v0.3.829-build504, pushed to origin, backup and fleet. Evidence: docs/release-evidence/build-503/ and build-504/.

Outstanding owner actions

  1. Developer ID + notarization (DEC-20260909-03) is blocked for RTTy Direct. Measured on copies: a Developer-ID-signed bundle signs with hardened runtime and a secure timestamp but fails to launch (NSPOSIXErrorDomain Code=163, Launchd job spawn failed); the same bundle with no entitlements launches. The blocker is the restricted iCloud entitlements without a Developer ID provisioning profile for iCloud.com.eastcoastscience.rtty; the development signing path also adds get-task-allow, which notarization refuses. Rich installs that profile, or decides to ship Direct without CloudKit — a feature removal, and therefore his call.
  2. The Dock tile was not visually verified on any host — no Screen Recording grant in this session. killall Dock on the hub is the one command if the old artwork persists.
  3. App Store / TestFlight remain blocked on the Apple Distribution certificate and App Store profiles.

No secrets are recorded here; keys are referenced by name and location only.