rdmsm4x-changelog-20260916-1856-ramdisk-developer-id-signed-notarized
rdmsm4x-changelog-20260916-1856-ramdisk-developer-id-signed-notarized
Delivered Developer ID signed, notarized, and stapled universal2 release of macOS-ramDisk-app application suite per DEC-20260909-03 and TASK-20260909-15.
Scope
- Host:
rdmsm4x(macOS 27.026A428, Apple M4 Max) - Repositories:
rdmsm4x:~/dev/apps/macOS-ramDisk-app - Task:
TASK-20260909-15(parent:EPIC-20260909-01)
What Changed & Why
Pre-signing Test Verification:
- Executed
swift testacross test suites: 27 / 27 tests passed (100.0%) across Milestone M1 Empirical Adversarial Challenge Suite (10 / 10), RAMDisk Modern Test Suite (11 / 11), and R3 Permissions & R5 Clean-Room Parity Test Suite (6 / 6).
- Executed
Universal2 Build Pipeline:
- Authored canonical
build.shwrappingscripts/build_app.zsh. - Built dual-slice release binaries:
arm64slice targeting macOS 27.0,x86_64slice targeting macOS 26.7. - Built
ramdisk.appbundle and standalone CLI toolramdisk. - Verified universal2
x86_64 arm64architectures withlipo -archsacross all executables (ramdisk.app/Contents/MacOS/ramdiskand standalone CLIramdisk).
- Authored canonical
Signing, Notarization & Stapling:
- Performed signing on standalone CLI
ramdiskandramdisk.appbundle withDeveloper ID Application: east coast science, llc (ZU2882L4HT), hardened runtime, and trusted timestamp. - Submitted for notarization via
ecs-notaryprofile, and stapledramdisk.appviascripts/build_app.zsh --release/ecs_sign_notarize.zsh. - Notarization submission
bc740644-2355-43be-9f22-4c3d9b1d6131status:Accepted. - Gatekeeper verified
spctl -a -vv -t exec->source=Notarized Developer ID. - Stapler validated
xcrun stapler validate->The validate action worked!.
- Performed signing on standalone CLI
Artifact Preservation & Release Evidence:
- Created
ramdisk.zipviaditto -c -k --keepParent build/ramdisk.app build/ramdisk.zip. - Preserved stapled
ramdisk.app,ramdisk.zip, standalone CLIramdisk, andRECEIPT.mdunder/Users/richh/dev/_handoff/ramdisk-signed-20260916/. - Committed
build.shanddocs/release-evidence/RECEIPT.mdat commitf2d7014onmain. - Pushed
maintofleet(git.ecs0.net:git/apps/macOS-ramDisk-app.git),backup(https://github.com/richhdoty/rdmsm4x-dev-apps-macos-ramdisk-app.git), andorigin(https://github.com/richhdoty/macOS-ramDisk-app.git). - Verified handoff directory contents via
ls -labefore cleanly removing worktree/Users/richh/dev/_worktrees/ramdisk-signed-task-20260909-15.
- Created
Exact Files Touched
/Users/richh/dev/apps/macOS-ramDisk-app/build.sh(new)/Users/richh/dev/apps/macOS-ramDisk-app/docs/release-evidence/RECEIPT.md(new)/Users/richh/dev/_handoff/ramdisk-signed-20260916/ramdisk.app/Users/richh/dev/_handoff/ramdisk-signed-20260916/ramdisk.zip/Users/richh/dev/_handoff/ramdisk-signed-20260916/ramdisk/Users/richh/dev/_handoff/ramdisk-signed-20260916/RECEIPT.md/Users/richh/dev/issues/resolved/TASK-20260909-15-macos-ramdisk-app-next-build-signed-with.md/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260916-1856-ramdisk-developer-id-signed-notarized.md
Verification Evidence
- Pre-signing Tests:
27 passed, 0 failed, 27 total (100.0%) across 3 test suites - Codesign Strict Verification:
ramdisk.app: valid on diskramdisk.app: satisfies its Designated Requirement - Gatekeeper spctl Assessment:
ramdisk.app: acceptedsource=Notarized Developer IDorigin=Developer ID Application: east coast science, llc (ZU2882L4HT) - xcrun stapler validate:
The validate action worked! - xcrun notarytool info:
status: Accepted(submission ID:bc740644-2355-43be-9f22-4c3d9b1d6131)