RTTy Mac App Store channel — target restored, signed release implemented, blocked on one certificate
rdmsm4x, 2026-09-10 14:55–15:45 EDT. claude@rdmsm4x, App Store
channel worker. Merged as richhdoty/RTTy PR #47, merge
commit 484dc2e.
One line: the Mac App Store target had not compiled
since PR #42 and now archives again (universal, sealed, validated);
archive_standard.sh --signed-release is implemented and
reaches its last preflight check; the .pkg cannot be
produced until Rich creates a Mac Installer
Distribution certificate.
Scope
Standard (App Store) channel only. dist/,
VERSION, BUILD_NUMBER and the Direct release
files were not touched — the Build 506 Direct worker
owns those. No upload step was added anywhere. No keychain was
reordered. Nothing was deleted.
What
changed, in
~/dev/_worktrees/rtty-appstore-archive-20260910/apps/RTTy
| File | Change |
|---|---|
script/archive_standard.sh |
--signed-release implemented:
new --extension-profile, --signing-keychain,
--signing-home, --export-directory; profile
authentication; xcodebuild -exportArchive (method
app-store-connect, manual signing, both profile UUIDs,
uploadSymbols); post-export verification by execution |
script/standard_archive_validator.py |
count pins 125/156 →
128/159 (the second copy main left
behind) |
script/TrustedStandardLaunchCapabilityPolicy.json |
re-rendered (renderer output only) |
script/TrustedStandardVerifierBundle.json |
re-rendered after every bundle-member change |
docs/app-store/UPLOAD_PREREQS_20260910.md |
new — the two blockers, click paths, verification commands |
docs/release-evidence/app-store-20260910/RUN_LOG.md |
new — 9 trusted-construction runs, exit codes, hashes |
ISSUES.md,
SESSION-STATE.md |
two OPEN items filed; checkpoint written |
Commands that mattered
# the trusted construction (the launcher REFUSES a git worktree — it needs a standalone clone)
git clone --no-hardlinks --branch <branch> <repo> /private/tmp/.../base/RTTy
/Applications/Xcode.app/Contents/Developer/usr/bin/python3 -I -B \
Tests/ScriptTests/standard_trust_anchor_fixture.py invoke --production-anchor \
--repository "$PWD" --trusted-verifier-commit <V> --candidate-source-commit <C> \
--trusted-verifier-bundle-sha256 <SHA> construct --unsigned-check --output-directory <NEW>
# re-render, documented order, renderer output only
python3 -I -B script/standard_project_graph.py render-graph --root "$PWD" \
--template-root <MUST-NOT-EXIST> --spec-output <MUST-NOT-EXIST>
python3 -I -B script/standard_launch_capability_policy.py --root "$PWD" \
--graph script/TrustedStandardProjectGraph.json --executable <built RTTy> --output <MUST-NOT-EXIST>
python3 -I -B script/standard_verifier_bundle.py render --bundle-root "$PWD"Do not pass -- before
construct to the anchor fixture: argparse's
REMAINDER keeps it and the launcher then sees
-- as its action and fails
exactly one launcher action … is required.
Verification evidence
Unsigned construction on the merged tree (6e73d01), rc=0
in 1 m 42 s:
- app and
RTTyNetworkFilter.appexbothlipo -archs→x86_64 arm64 - executable SHA-256
0e2c5d46774bad1fefb08688ffb9d74632500819b9b83d06a8ed8e3e0849a5e1 0.3.831/506,LSMinimumSystemVersion 26.0BuildInfo.json:standard-app-store,unsigned-structural,releaseEligible false,gitDirty false- sealed report 373236 bytes, SHA-256
1efe603ec4e89524722e7c409d3a487c2e76c7dcfd31313708082c04bb4b3f69 swift test798 / 5 skipped / 0, 71 / 0, 270 / 0 — identical toorigin/main3f4ed33measured independently in its own worktree. No loss in the merge.
Four measured defects that each returned a wrong answer rather than an error, all fixed:
- Certificate validity is HOME-derived. Under the
trusted launcher's private HOME,
security find-identity -v -p codesigning ~/Library/Keychains/login.keychain-dbreturns 1 identity; under the real home the same command on the same file returns 3. Apple Development and Apple Distribution chain through an intermediate the isolated home cannot reach, so they read as invalid, not absent. security cms -Dneeds a default keychain; under that HOME it failscert import failed: A default keychain could not be foundfor a profile that decodes fine.- macOS App Store profiles key the identifier
Entitlements:com.apple.application-identifier; the bareapplication-identifieris the iOS spelling. - Both installed Mac App Store profiles omit
get-task-allowrather than setting it false.
Blocked — owner actions
- Mac Installer Distribution certificate
(
3rd Party Mac Developer Installer: … (ZU2882L4HT)). Measured:xcodebuild -exportArchiveexits 70,error: exportArchive No signing certificate "Mac Installer Distribution" found.security find-identity -v→ 6 identities, 0 Installer class. - An upload credential — an App Store Connect API key
in
~/.private_keys/, or an Apple ID plus app-specific password.altoolcannot read notarytool'secs-notaryprofile. - The App Store Connect app record for
com.eastcoastscience.rtty— not knowable from this host without a key; recorded as unknown, not guessed.
Click paths and per-step verification:
~/dev/apps/RTTy/docs/app-store/UPLOAD_PREREQS_20260910.md.
Undo
Everything is one merge commit: git revert -m 1 484dc2e
on richhdoty/RTTy main. Nothing was installed,
no system state changed, no keychain modified
(security list-keychains is byte identical before and
after: login, fleet-signing, System — in that order). The scratch clones
and archives live under the session scratchpad and are disposable.
Not done
- The signed export branch of
archive_standard.shhas never executed — it stops at the installer-certificate preflight. Code review only past that point. - iOS not archived:
script/archive_mobile.shline 494 failsowner-mediated cryptographic signing authorization is unavailableunconditionally in signed mode. Measured by execution with the real identity and the real iOS App Store profile, rc=1.