Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1333-firmwaredb-universal2-developerid-signing-notarization

rdmsm4x-changelog-20260916-1333-firmwaredb-universal2-developerid-signing-notarization

Summary

Resolved TASK-20260909-09 by creating build.sh for firmwaredb, building universal2 binaries (x86_64 arm64) for both CLI and macOS GUI application bundle, signing with Developer ID (Developer ID Application: east coast science, llc (ZU2882L4HT)), hardened runtime (0x10000), secure timestamp, notarizing via ecs-notary profile (1ca01d58-34ed-4d95-bb4d-ca0785136076), stapling the ticket, and verifying Gatekeeper acceptance (source=Notarized Developer ID) per DEC-20260909-03.

Scope & Repositories Touched

Changes Made

  1. Added build.sh in firmwaredb:
    • Compiles release slices for arm64 and x86_64 into dedicated scratch directories (.build/release-arm64 and .build/release-x86_64).
    • Merges architecture slices via lipo -create for both firmwaredb (CLI) and firmwareDB.app/Contents/MacOS/firmwareDB (GUI application).
    • Enforces Universal2 lipo architecture gate (lipo -archs asserting x86_64 arm64).
    • Assembles dist/firmwareDB.app bundle with Info.plist, PkgInfo, and resources.
    • Integrates Developer ID signing and Apple notarization via ~/dev/lib/app-baseline/scripts/ecs_sign_notarize.zsh.
  2. Fixed ~/dev/lib/app-baseline/scripts/ecs_sign_notarize.zsh:
    • Renamed zsh read-only variable status to notary_status on lines 49-50.
    • Trimmed whitespace on extracted status to avoid mismatch with "Accepted".
  3. Committed and Merged:
    • Worktree branch task/firmwaredb-signing-task-20260909-09 committed at f7625b1 and fast-forward merged into main of rdmsm4x:~/dev/apps/firmwaredb.
    • Bugfix in app-baseline committed at 59cfd70.

Verification Evidence

  1. Unit Test Suite:
    • swift test: 68/68 passed in 0.345s (0 failures, 100% pass rate).
  2. Universal2 Architecture Gate:
    • lipo -archs dist/firmwareDB.app/Contents/MacOS/firmwareDB: x86_64 arm64
    • lipo -archs dist/firmwaredb: x86_64 arm64
  3. Codesign Verification:
    • codesign -dvvv --verify --strict dist/firmwareDB.app:
      • Valid on disk, satisfies designated requirement.
      • Authority=Developer ID Application: east coast science, llc (ZU2882L4HT)
      • flags=0x10000(runtime)
      • TeamIdentifier=ZU2882L4HT
      • Notarization Ticket=stapled
  4. Apple Notary Service:
    • Profile: ecs-notary
    • Submission ID: 1ca01d58-34ed-4d95-bb4d-ca0785136076
    • Status: Accepted, statusSummary: Ready for distribution, issues: null.
  5. Stapler & Gatekeeper:
    • xcrun stapler validate dist/firmwareDB.app: The validate action worked!
    • spctl -a -vv -t exec dist/firmwareDB.app: accepted, source=Notarized Developer ID, origin=Developer ID Application: east coast science, llc (ZU2882L4HT).

Rollback / Undo

Addendum: Preservation & Delivery (2026-09-16 13:45 EDT)

Per portfolio lead verification requirement:

  1. Re-built Universal2 slices in worktree /Users/richh/dev/_worktrees/firmwaredb-preserve-20260916.
  2. Signed with Developer ID (hardened runtime + timestamp), submitted to Apple notary service (Submission ID: 0a882bf0-431a-435f-b5ac-99e56e65a12a, status Accepted), and stapled.
  3. Preserved release artifacts in /Users/richh/dev/_handoff/firmwaredb-signed-20260916/:
    • firmwareDB.app (Stapled Universal2 application bundle)
    • firmwaredb (Signed Universal2 CLI executable)
    • firmwareDB.zip (Ditto archive of firmwareDB.app)
    • RECEIPT.md (Full checksum and verification report)
  4. Added and committed in-repo release evidence:
    • docs/release-evidence/RECEIPT.md committed at 26c2b24 on main in rdmsm4x:~/dev/apps/firmwaredb.
  5. Hand-off directory existence and integrity verified prior to worktree removal.