Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1535-bookmarkroo-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1535-bookmarkroo-developer-id-signed-notarized

bookmarkROO next build signed with Developer ID, notarized, stapled, and preserved in handoff per DEC-20260909-03 (TASK-20260909-04).

Summary & Scope

Work Completed

  1. Pre-signing Unit Tests: Executed xcrun xctest on BookmarkRooTests.xctest in isolated worktree; verified 10 / 10 unit tests passed (100.0%) across 2 suites (BookmarkRooTests: 8 passed, BookmarkTypeClassifierTests: 2 passed) in 0.012s.
  2. Universal2 Slices & Assembly:
    • Built arm64 and x86_64 release slices via swift build.
    • Merged universal fat binaries (x86_64 arm64) for dist/bookmarkroo (app executable), dist/bookmarkroo-cli (CLI), and dist/bookmarkroo.app/Contents/MacOS/bookmarkroo.
    • Structured bookmarkroo.app bundle metadata (Info.plist, PkgInfo).
  3. Developer ID Code Signing & Hardened Runtime:
    • Unlocked signing keychains using fleet_sign_unlock.
    • Signed dist/bookmarkroo-cli CLI with Developer ID (ZU2882L4HT), --options runtime, and --timestamp.
    • Signed dist/bookmarkroo with Developer ID, --options runtime, and --timestamp.
    • Signed dist/bookmarkroo.app with Developer ID, --options runtime, and --timestamp.
  4. Notarization & Stapling:
    • Submitted bookmarkroo.app to Apple notary service using profile ecs-notary via ecs_sign_notarize.zsh.
    • Submission ID: a04d6fa2-0cd7-4983-8969-8ab830a3258e (Status: Accepted, "Ready for distribution").
    • Stapled notarization ticket to bookmarkroo.app.
    • Validated staple via xcrun stapler validate ("The validate action worked!").
    • Verified Gatekeeper assessment via spctl -a -vv -t exec (accepted, source=Notarized Developer ID).
  5. Preserved Artifacts in Handoff:
    • Preserved in /Users/richh/dev/_handoff/bookmarkroo-signed-20260916/:
      • bookmarkroo.app (Stapled universal application bundle)
      • bookmarkroo.zip (Created via ditto -c -k --keepParent)
      • bookmarkroo-cli (Universal Developer ID signed standalone CLI binary)
      • bookmarkroo (Universal Developer ID signed standalone app binary)
      • RECEIPT.md (Complete verification evidence and notarization receipt)
  6. In-Repo Release Evidence & Push:
    • Tracked receipt in Docs/release-evidence/RECEIPT.md.
    • Committed changes (build.sh, bookmarkroo.app/Contents/Info.plist, Docs/release-evidence/RECEIPT.md) on main at commit 5fc367b.
    • Pushed commit to fleet remote (git.ecs0.net:git/apps/bookmarkROO.git).
  7. Verification & Cleanup:
    • Verified handoff directory via ls -la before removing worktree.
    • Removed worktree /Users/richh/dev/_worktrees/bookmarkroo-signed-task-20260909-04 and task branch.
    • Appended verification receipt comment to TASK-20260909-04 and resolved the ticket.
    • Broadcast resolution to fleet agent bus (agent_msg.zsh).