Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1612-bitroo-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1612-bitroo-developer-id-signed-notarized

bitROO next build signed with Developer ID, notarized, stapled, and preserved in handoff per DEC-20260909-03 (TASK-20260909-03).

Summary & Scope

Work Completed

  1. Pre-signing Unit Tests: Executed swift test in isolated worktree; verified 39 / 39 unit tests passed (100.0%) across 0 suites in 0.196s.
  2. Universal2 Slices & Assembly:
    • Enhanced make_app.zsh to support --sign-notarize and dist/ staging; added executable root build.sh wrapper.
    • Built Universal2 fat binaries (x86_64 arm64) for BitRooApp (BitRoo.app/Contents/MacOS/BitRoo) and CLI bitroo.
    • Extracted App Intents metadata using appintentsmetadataprocessor into BitRoo.app/Contents/Resources/Metadata.appintents (11219 bytes).
    • Structured BitRoo.app bundle metadata (Info.plist, BitRoo.icns, PkgInfo).
  3. Developer ID Code Signing & Hardened Runtime:
    • Unlocked signing keychains using fleet_sign_unlock.
    • Signed bitroo CLI with Developer ID (ZU2882L4HT), --options runtime, and --timestamp.
    • Signed build/BitRoo with Developer ID, --options runtime, and --timestamp.
    • Signed BitRoo.app with Developer ID, --options runtime, and --timestamp.
  4. Notarization & Stapling:
    • Submitted BitRoo.app to Apple notary service using profile ecs-notary via ecs_sign_notarize.zsh.
    • Submission ID: 3c8ff59b-7323-4583-991a-88c70b1feda9 (Status: Accepted, "Ready for distribution").
    • Stapled notarization ticket to BitRoo.app.
    • Validated staple via xcrun stapler validate ("The validate action worked!").
    • Verified Gatekeeper assessment via spctl -a -vv -t exec (accepted, source=Notarized Developer ID).
  5. Preserved Artifacts in Handoff:
    • Preserved in /Users/richh/dev/_handoff/bitroo-signed-20260916/:
      • BitRoo.app (Stapled universal application bundle)
      • BitRoo.zip (Created via ditto -c -k --keepParent)
      • bitroo (Universal Developer ID signed standalone CLI binary)
      • RECEIPT.md (Complete verification evidence and notarization receipt)
  6. In-Repo Release Evidence & Push:
    • Tracked receipt in Docs/release-evidence/RECEIPT.md.
    • Committed changes (make_app.zsh, build.sh, Docs/release-evidence/RECEIPT.md) on main at commit f599134.
    • Pushed commit to fleet remote (git.ecs0.net:git/apps/bitROO.git) and backup remote.
  7. Verification & Cleanup:
    • Verified handoff directory via ls -la before removing worktree.
    • Removed worktree /Users/richh/dev/_worktrees/bitroo-signed-task-20260909-03 and task branch.
    • Appended verification receipt comment to TASK-20260909-03 and resolved the ticket.
    • Broadcast resolution to fleet agent bus (agent_msg.zsh).