Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1736-filelabeler-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1736-filelabeler-developer-id-signed-notarized

Delivered Developer ID signed, notarized, and stapled universal2 release of FileLabeler per DEC-20260909-03 and TASK-20260909-08.

Scope

What Changed & Why

  1. Pre-signing Test Verification:

    • Built and ran xcrun xctest against FileLabelerCoreTests.xctest.
    • Verified 21 / 21 tests passed (100.0%) across all 4 test targets (CloudKitJournalPublisherTests: 2, ExportTests: 6, FileLabelerCoreTests: 12, UniformTypesClassificationTests: 1) in 0.100s.
  2. Universal2 Build Pipeline:

    • Added canonical build.sh supporting --sign-notarize.
    • Updated project.yml with ARCHS: "x86_64 arm64" and ONLY_ACTIVE_ARCH: NO under FileLabelerMac.settings.base.
    • Built FileLabeler.app universal2 bundle via XcodeGen + xcodebuild with code signing disabled during build phase.
    • Built standalone FileLabeler CLI universal2 executable via swift build -c release --product FileLabeler --arch arm64 --arch x86_64.
    • Verified universal2 x86_64 arm64 slices with lipo -archs on all executables.
  3. Signing, Notarization & Stapling:

    • Signed standalone dist/FileLabeler executable with Developer ID Application: east coast science, llc (ZU2882L4HT) (1C07FCD80C36EAD5D9E3B73F7ACCCA5368DC73FB), hardened runtime, and trusted timestamp.
    • Signed, submitted for notarization via ecs-notary profile, and stapled dist/FileLabeler.app via /Users/richh/dev/lib/app-baseline/scripts/ecs_sign_notarize.zsh.
    • Notarization submission bae70988-e9e4-48c5-9c82-4e6962a93a5d status: Accepted.
    • Gatekeeper verified spctl -a -vv -t exec -> source=Notarized Developer ID.
    • Stapler validated xcrun stapler validate -> The validate action worked!.
  4. Artifact Preservation & Release Evidence:

    • Preserved stapled FileLabeler.app, FileLabeler.zip, standalone FileLabeler, and RECEIPT.md under /Users/richh/dev/_handoff/filelabeler-signed-20260916/.
    • Committed build.sh, project.yml, FileLabeler.xcodeproj/project.pbxproj, and docs/release-evidence/RECEIPT.md at commit ec88b8561c2d51839c03669c29c37ddeb59aabe0 on main.
    • Pushed main to fleet (git.ecs0.net:git/apps/fileLabeler.git), origin (github.com:richhdoty/labelist-filelabeler-app-project.git), and backup (github.com:richhdoty/rdmsm4x-dev-apps-filelabeler.git).
    • Cleanly removed worktree /Users/richh/dev/_worktrees/filelabeler-signed-task-20260909-08 after verifying handoff directory contents.

Exact Files Touched

Verification Evidence