Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260910-1752-rtty-signed-mac-app-store-pkg-produced-and-verified

RTTy — the signed Mac App Store .pkg is produced and verified

rdmsm4x, 2026-09-10 17:27–17:55 EDT. claude@rdmsm4x, App Store channel. Merged as richhdoty/RTTy PR #49, merge commit 10088bf. Follows PR #47 (484dc2e) and PR #48 (b25f316).

One line: script/archive_standard.sh --signed-release now runs end to end through the trusted launcher and produces a verified, signed Mac App Store package; nothing was uploaded, because no App Store Connect credential exists.

Deliverable

~/dev/_handoff/rtty-appstore-506-20260910/RTTy.pkg 13,844,179 bytes
SHA-256 1516165a39c942477593af7c0a73e06098644142d1a6ff38731b0d081d0fa01a
sealed structural report SHA-256 a3a5f7ea98526f7f4943af706496b7d9ed2ca0560dfd7022229f4d4370b51276
candidate 19f53bd, 0.3.831 / 506

DistributionSummary.plist, ExportOptions.plist and Packaging.log are beside it. The package itself lives outside the repository; only the evidence is committed.

Verification (executed, both bundles)

codesign -dv --verbose=2 rc=0 with Authority=Apple Distribution: east coast science, llc (ZU2882L4HT) and TeamIdentifier=ZU2882L4HT; codesign --verify --strict --deep rc=0; lipo -archs x86_64 arm64; embedded profiles 78907c14… ("RTTy macOS App Store") and b9949370… ("RTTy Network Filter App Store") matching by UUID; entitlements include App Sandbox, group.com.eastcoastscience.rtty, content-filter-provider, and on the app CloudKit iCloud.com.eastcoastscience.rtty with icloud-container-environment Production; get-task-allow absent on both. pkgutil --check-signature rc=0 on the 3rd Party Mac Developer Installer chain. Launcher verify --unsigned-check on the sealed archive rc=0. spctl -a -t install rc=3 is expected — a Store package is not Developer ID.

The near-miss worth remembering

The first successful export produced a .pkg that passed codesign -dv, codesign --verify --strict --deep and pkgutil --check-signature — and whose RTTy.app carried exactly two entitlements (com.apple.application-identifier, com.apple.developer.team-identifier), with no App Sandbox, no app group, no network extension and no CloudKit. The archive is built CODE_SIGNING_ALLOWED=NO, so it holds no .xcent and no signature; xcodebuild -exportArchive reads entitlements from the archived signature and, finding none, fell back to what the profile alone implies. Every signature check passed a functionally gutted app. Only the entitlement assertion caught it. Fixed by signing the staged appex then app with the reviewed entitlements before exporting.

Also fixed

TrustedStandardLaunchCapabilityPolicy.json was stale again: the 506 candidate 62472c0 re-rendered the project graph and moved both count pins to 132/163 but not this file, so the trusted archive failed closed. Re-rendered — +21 undefined symbols, 0 removed, all SwiftUI/AppKit from PR #45's appearance work. The release gate is an xcodebuild build; this policy is consulted only by the trusted archive validator, so the ordinary path cannot notice.

Time cost worth recording

The installer key's ACL prompt blocked the first signature for 1 h 41 m (certificate installed ~15:43, approved 17:27:59). Diagnosed with a one-byte probe package rather than a five-minute archive, and confirmed by sample: SecKeyCreateSignature → CSSM_SignData → mach_msg → mach_msg2_trap.

Gates

swift test 869 / 5 skipped / 0, 71 / 0, 270 / 0. Eight script/policy gates plus check_lib_pin.sh and git diff --check, all rc=0.

Outstanding, owner-only

No App Store Connect API key and no app-specific password, so altool --validate-app / --upload-app cannot run — ~/dev/apps/RTTy/docs/app-store/UPLOAD_PREREQS_20260910.md §2. Whether an App Store Connect record exists for com.eastcoastscience.rtty is not knowable from this host without a key (§3). Nothing was uploaded.

Also OPEN, filed rather than patched in passing: the delivered payload's BuildInfo.json still reads signingMode: unsigned-structural / releaseEligible: false.

Undo

git revert -m 1 10088bf. Nothing installed, no system state changed, no keychain modified — security list-keychains still reads login, fleet-signing, System, in that order. The package in ~/dev/_handoff/ is a file; delete it if unwanted.