RTTy — the signed Mac App Store .pkg is produced and verified
rdmsm4x, 2026-09-10 17:27–17:55 EDT. claude@rdmsm4x, App Store
channel. Merged as richhdoty/RTTy PR #49, merge commit
10088bf. Follows PR #47 (484dc2e) and PR #48
(b25f316).
One line:
script/archive_standard.sh --signed-release now runs end to
end through the trusted launcher and produces a verified, signed Mac App
Store package; nothing was uploaded, because no App Store Connect
credential exists.
Deliverable
~/dev/_handoff/rtty-appstore-506-20260910/RTTy.pkg |
13,844,179 bytes |
| SHA-256 | 1516165a39c942477593af7c0a73e06098644142d1a6ff38731b0d081d0fa01a |
| sealed structural report | SHA-256
a3a5f7ea98526f7f4943af706496b7d9ed2ca0560dfd7022229f4d4370b51276 |
| candidate | 19f53bd, 0.3.831
/ 506 |
DistributionSummary.plist,
ExportOptions.plist and Packaging.log are
beside it. The package itself lives outside the repository; only the
evidence is committed.
Verification (executed, both bundles)
codesign -dv --verbose=2 rc=0 with
Authority=Apple Distribution: east coast science, llc (ZU2882L4HT)
and TeamIdentifier=ZU2882L4HT;
codesign --verify --strict --deep rc=0;
lipo -archs x86_64 arm64; embedded profiles
78907c14… ("RTTy macOS App Store") and
b9949370… ("RTTy Network Filter App Store") matching by
UUID; entitlements include App Sandbox,
group.com.eastcoastscience.rtty,
content-filter-provider, and on the app CloudKit
iCloud.com.eastcoastscience.rtty with
icloud-container-environment Production;
get-task-allow absent on both.
pkgutil --check-signature rc=0 on the
3rd Party Mac Developer Installer chain. Launcher
verify --unsigned-check on the sealed archive rc=0.
spctl -a -t install rc=3 is expected — a Store package is
not Developer ID.
The near-miss worth remembering
The first successful export produced a .pkg that passed
codesign -dv,
codesign --verify --strict --deep and
pkgutil --check-signature — and whose RTTy.app
carried exactly two entitlements
(com.apple.application-identifier,
com.apple.developer.team-identifier), with no App Sandbox,
no app group, no network extension and no CloudKit. The archive is built
CODE_SIGNING_ALLOWED=NO, so it holds no .xcent
and no signature; xcodebuild -exportArchive reads
entitlements from the archived signature and, finding none, fell back to
what the profile alone implies. Every signature check passed a
functionally gutted app. Only the entitlement assertion caught
it. Fixed by signing the staged appex then app with the reviewed
entitlements before exporting.
Also fixed
TrustedStandardLaunchCapabilityPolicy.json was stale
again: the 506 candidate 62472c0 re-rendered the project
graph and moved both count pins to 132/163 but not this file, so the
trusted archive failed closed. Re-rendered — +21 undefined symbols, 0
removed, all SwiftUI/AppKit from PR #45's appearance work. The release
gate is an xcodebuild build; this policy is consulted only
by the trusted archive validator, so the ordinary path cannot
notice.
Time cost worth recording
The installer key's ACL prompt blocked the first signature for
1 h 41 m (certificate installed ~15:43, approved
17:27:59). Diagnosed with a one-byte probe package rather than a
five-minute archive, and confirmed by sample:
SecKeyCreateSignature → CSSM_SignData → mach_msg → mach_msg2_trap.
Gates
swift test 869 / 5 skipped / 0,
71 / 0, 270 / 0. Eight script/policy
gates plus check_lib_pin.sh and
git diff --check, all rc=0.
Outstanding, owner-only
No App Store Connect API key and no app-specific password, so
altool --validate-app / --upload-app cannot
run —
~/dev/apps/RTTy/docs/app-store/UPLOAD_PREREQS_20260910.md
§2. Whether an App Store Connect record exists for
com.eastcoastscience.rtty is not knowable from this host
without a key (§3). Nothing was uploaded.
Also OPEN, filed rather than patched in passing: the delivered
payload's BuildInfo.json still reads
signingMode: unsigned-structural /
releaseEligible: false.
Undo
git revert -m 1 10088bf. Nothing installed, no system
state changed, no keychain modified —
security list-keychains still reads login, fleet-signing,
System, in that order. The package in ~/dev/_handoff/ is a
file; delete it if unwanted.