Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1643-hypertune-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1643-hypertune-developer-id-signed-notarized

hyperTune next build signed with Developer ID, notarized, stapled, and preserved in handoff per DEC-20260909-03 (TASK-20260909-11).

Summary & Scope

Work Completed

  1. Pre-signing Unit Tests: Executed swift test across test targets; verified 274 / 274 tests passed in _ingested/agy-darwinsysctl across 3 targets (DarwinSysctlE2ETests: 220, DarwinSysctlCoreTests: 44, DarwinSysctlBridgeTests: 10) in 0.985s, and 1 / 1 test passed in SystemOptimizer in 0.001s. Total: 275 / 275 tests passed (100.0%).
  2. Universal2 Slices & Assembly:
    • Set bundleIdPrefix to com.eastcoastscience in project.yml matching PRD.
    • Built Universal2 fat binaries (x86_64 arm64) for HyperTune.app, standalone app binary dist/hypertune, and dist/systemoptimizer CLI.
    • Structured HyperTune.app bundle metadata with xcodegen and xcodebuild.
  3. Developer ID Code Signing & Hardened Runtime:
    • Unlocked signing keychains using fleet_sign_unlock.
    • Signed dist/hypertune standalone binary with Developer ID (ZU2882L4HT), --options runtime, and --timestamp.
    • Signed dist/systemoptimizer CLI with Developer ID (ZU2882L4HT), --options runtime, and --timestamp.
    • Signed dist/HyperTune.app with Developer ID, --options runtime, and --timestamp.
  4. Notarization & Stapling:
    • Submitted HyperTune.app to Apple notary service using profile ecs-notary via ecs_sign_notarize.zsh.
    • Submission ID: 3553d79f-a63c-4654-8d67-3423f3a6e65a (Status: Accepted, "Ready for distribution").
    • Stapled notarization ticket to HyperTune.app.
    • Validated staple via xcrun stapler validate ("The validate action worked!").
    • Verified Gatekeeper assessment via spctl -a -vv -t exec (accepted, source=Notarized Developer ID).
  5. Preserved Artifacts in Handoff:
    • Preserved in /Users/richh/dev/_handoff/hypertune-signed-20260916/:
      • HyperTune.app (Stapled universal application bundle)
      • HyperTune.zip (Created via ditto -c -k --keepParent)
      • hypertune (Universal Developer ID signed standalone app binary)
      • systemoptimizer (Universal Developer ID signed standalone CLI binary)
      • RECEIPT.md (Complete verification evidence and notarization receipt)
  6. In-Repo Release Evidence & Push:
    • Tracked receipt in docs/release-evidence/RECEIPT.md.
    • Committed changes (build.sh, project.yml, HyperTune.xcodeproj/project.pbxproj, docs/release-evidence/RECEIPT.md) on main at commit 2038422.
    • Pushed commit to fleet remote (git.ecs0.net:git/apps/hyperTune.git) and backup remote.
  7. Verification & Cleanup:
    • Verified handoff directory via ls -la before removing worktree.
    • Removed worktree /Users/richh/dev/_worktrees/hypertune-signed-task-20260909-11 and task branch.
    • Appended verification receipt comment to TASK-20260909-11 and resolved the ticket.
    • Broadcast resolution to fleet agent bus (agent_msg.zsh).