rdmsm4x-changelog-20260916-1535-bookmarkroo-developer-id-signed-notarized
rdmsm4x-changelog-20260916-1535-bookmarkroo-developer-id-signed-notarized
bookmarkROO next build signed with Developer ID, notarized, stapled, and preserved in handoff per DEC-20260909-03 (TASK-20260909-04).
Summary & Scope
- Host:
rdmsm4x - Application: bookmarkROO
(
rdmsm4x:~/dev/apps/bookmarkROO) - Ticket:
TASK-20260909-04underEPIC-20260909-01 - Identity:
agy@rdmsm4x/9eff3d0a
Work Completed
- Pre-signing Unit Tests: Executed
xcrun xctestonBookmarkRooTests.xctestin isolated worktree; verified 10 / 10 unit tests passed (100.0%) across 2 suites (BookmarkRooTests: 8 passed,BookmarkTypeClassifierTests: 2 passed) in 0.012s. - Universal2 Slices & Assembly:
- Built
arm64andx86_64release slices viaswift build. - Merged universal fat binaries (
x86_64 arm64) fordist/bookmarkroo(app executable),dist/bookmarkroo-cli(CLI), anddist/bookmarkroo.app/Contents/MacOS/bookmarkroo. - Structured
bookmarkroo.appbundle metadata (Info.plist,PkgInfo).
- Built
- Developer ID Code Signing & Hardened Runtime:
- Unlocked signing keychains using
fleet_sign_unlock. - Signed
dist/bookmarkroo-cliCLI with Developer ID (ZU2882L4HT),--options runtime, and--timestamp. - Signed
dist/bookmarkroowith Developer ID,--options runtime, and--timestamp. - Signed
dist/bookmarkroo.appwith Developer ID,--options runtime, and--timestamp.
- Unlocked signing keychains using
- Notarization & Stapling:
- Submitted
bookmarkroo.appto Apple notary service using profileecs-notaryviaecs_sign_notarize.zsh. - Submission ID:
a04d6fa2-0cd7-4983-8969-8ab830a3258e(Status:Accepted, "Ready for distribution"). - Stapled notarization ticket to
bookmarkroo.app. - Validated staple via
xcrun stapler validate("The validate action worked!"). - Verified Gatekeeper assessment via
spctl -a -vv -t exec(accepted,source=Notarized Developer ID).
- Submitted
- Preserved Artifacts in Handoff:
- Preserved in
/Users/richh/dev/_handoff/bookmarkroo-signed-20260916/:bookmarkroo.app(Stapled universal application bundle)bookmarkroo.zip(Created viaditto -c -k --keepParent)bookmarkroo-cli(Universal Developer ID signed standalone CLI binary)bookmarkroo(Universal Developer ID signed standalone app binary)RECEIPT.md(Complete verification evidence and notarization receipt)
- Preserved in
- In-Repo Release Evidence & Push:
- Tracked receipt in
Docs/release-evidence/RECEIPT.md. - Committed changes (
build.sh,bookmarkroo.app/Contents/Info.plist,Docs/release-evidence/RECEIPT.md) onmainat commit5fc367b. - Pushed commit to
fleetremote (git.ecs0.net:git/apps/bookmarkROO.git).
- Tracked receipt in
- Verification & Cleanup:
- Verified handoff directory via
ls -labefore removing worktree. - Removed worktree
/Users/richh/dev/_worktrees/bookmarkroo-signed-task-20260909-04and task branch. - Appended verification receipt comment to
TASK-20260909-04and resolved the ticket. - Broadcast resolution to fleet agent bus
(
agent_msg.zsh).
- Verified handoff directory via