Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1928-hyperfile-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1928-hyperfile-developer-id-signed-notarized

Delivered Developer ID signed, notarized, and stapled universal2 release of hyperFile application and privileged helper suite per DEC-20260909-03 and TASK-20260909-10.

Scope

What Changed & Why

  1. Pre-signing Test Verification:

    • Executed HyperFileHelperPeerValidationTests via xcodebuild: 2 / 2 tests passed (100.0%) verifying client code-signature requirements enforcement.
  2. Universal2 Build Pipeline:

    • Preserved XcodeGen build gates (ARCHS: "x86_64 arm64", ONLY_ACTIVE_ARCH: NO) in project.yml.
    • Authored canonical build.sh supporting --test and --sign-notarize.
    • Built HyperFile-macOS.app universal2 bundle and com.eastcoastscience.HyperFile.Helper tool.
    • Verified universal2 x86_64 arm64 architectures with lipo -archs across all executables (HyperFile-macOS.app/Contents/MacOS/HyperFile-macOS, embedded Contents/Resources/com.eastcoastscience.HyperFile.Helper, and standalone com.eastcoastscience.HyperFile.Helper).
  3. Signing, Notarization & Stapling:

    • Executed inside-out signing on embedded helper Contents/Resources/com.eastcoastscience.HyperFile.Helper and standalone helper with Developer ID Application: east coast science, llc (ZU2882L4HT), hardened runtime, and trusted timestamp.
    • Signed, submitted for notarization via ecs-notary profile, and stapled HyperFile-macOS.app via /Users/richh/dev/lib/app-baseline/scripts/ecs_sign_notarize.zsh.
    • Notarization submission 393b5305-b29b-428c-9d9f-b0fabdd26307 status: Accepted.
    • Gatekeeper verified spctl -a -vv -t exec -> source=Notarized Developer ID.
    • Stapler validated xcrun stapler validate -> The validate action worked!.
  4. Artifact Preservation & Release Evidence:

    • Created release zip archives HyperFile-macOS.zip and HyperFile.zip via ditto -c -k --keepParent.
    • Preserved stapled HyperFile-macOS.app, HyperFile-macOS.zip, HyperFile.zip, standalone helper com.eastcoastscience.HyperFile.Helper, and RECEIPT.md under /Users/richh/dev/_handoff/hyperfile-signed-20260916/.
    • Committed build.sh and docs/release-evidence/RECEIPT.md at commit 1cddc31 on main.
    • Pushed main to fleet (git.ecs0.net:git/apps/hyperFile.git), backup (https://github.com/richhdoty/rdmsm4x-dev-apps-hyperfile.git), and origin (https://github.com/richhdoty/HyperFile.git).
    • Verified handoff directory contents via ls -la before cleanly removing worktree /Users/richh/dev/_worktrees/hyperfile-signed-task-20260909-10.

Exact Files Touched

Verification Evidence