Skip to content

feat: verified macOS development DMG and deferred official signing (#49) - #70

Merged
cam11505 merged 3 commits into
mainfrom
codex/v1.3-issue-49
Sep 27, 2026
Merged

cam11505 merged 3 commits into
mainfrom
codex/v1.3-issue-49

Conversation

@cam11505

@cam11505 cam11505 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Scope and user decision

Refs #49 (do not close). Immutable parity baseline: v1.2.2 / bb0197b0291707287517ba8bdfc3a10ce1ad1149.
Prerequisite main: 061a3d830b1231ded9a4da27e10f07ab24acb380 (PR #69 merged, #48 completed).

On 2026-09-27 the user explicitly chose no paid Apple enrollment, official signing or notarization for now, and continued macOS development-build testing. Official #49 remains deferred/not passed; credential-free #50 integration may follow this PR's merge. #51 official RC/tag/release gates are unchanged. Physical Mac QA stays deferred, not passed.

Implementation

  • Credential-free native app/DMG qualification, download SHA-256/manifest, and independent re-mount/content/copy/LaunchServices verification.
  • Upload clearly named ArchiveLens-<version>-macos-arm64-development.dmg as a development CI artifact only after both verifications pass; record release_eligible=false, unsigned/ad-hoc and not notarized.
  • Bundled SPDX SBOM, immutable baseline/exact source commit, existing licenses/notices/backend; Windows flow unchanged.
  • Retain separated, protected-main official candidate code with fail-closed Developer ID/hardened-runtime/timestamp/entitlement/notarization/staple/Gatekeeper checks. No unsigned fallback, publication or tag action.
  • Ephemeral keychain/private-material cleanup and credential diagnostic suppression. Real official runtime/signing evidence remains untested/deferred.
  • Developer setup/download/test guide in docs/MACOS_DEVELOPMENT.md; future paid setup explicitly deferred in docs/MACOS_SIGNING.md.

Verification

Final head: f8229269903deb6a31bf135a81db9df26a275cee.
Local full suite: 260 passed, 4 skipped; Ruff check/format and git diff checks passed.
macOS run 36294022303 succeeded: development app, native arm64 inspection, packaged self-test/Finder opens, development DMG mount/content/copy/launch, independent inventory/re-mount/self-test, and development artifact upload.

Downloaded DMG: ArchiveLens-1.2.2-macos-arm64-development.dmg, 46,727,577 bytes; SHA-256 64aaef26c9ccbbc668ef89275158b135d8cf3899fed992c2b05e45b9ab637698 matched both manifest/checksum and independent report. Tested merge ref 1da40dbf45cd884d1d1900406b767aae31f1aa76 matches the head tree 28029cf6954fb73bc2255e91abd213a219a86a7a. Manifest records 223 arm64 native files, development=true, release_eligible=false, and notarization not performed.

Windows/Ubuntu run 36294022254 succeeded: source tests, license audit, portable and installer, exact-commit checksum/release-set verification and artifact upload. All current PR checks passed.

Remaining official gates (not waived)

Keep #49 open until the user resumes the official track and real Developer ID signing, Apple Accepted app/DMG notarization, staple/Gatekeeper and independent official artifact evidence pass. The current app version remains 1.2.2 during v1.3 development; exact tested source commit identifies each developer build. No v1.3 GitHub Release is created here.

@cam11505 cam11505 changed the title feat: prepare fail-closed macOS signing and DMG gate (#49) feat: verified macOS development DMG and deferred official signing (#49) Sep 27, 2026
@cam11505
cam11505 marked this pull request as ready for review September 27, 2026 04:27
@cam11505
cam11505 merged commit 492a6f8 into main Sep 27, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant