Skip to content

chore(personal): signed desktop releases for every Mac, plus a runbook - #31

Merged
r4iju merged 1 commit into
mainfrom
chore/personal-desktop-release
Sep 24, 2026
Merged

r4iju merged 1 commit into
mainfrom
chore/personal-desktop-release

Conversation

@r4iju

@r4iju r4iju commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Local desktop builds were ad-hoc signed. macOS privacy grants, keychain access and Little Snitch rules are tied to an app's signature, so every new build counted as a new app and each Mac re-prompted for everything. Installs were also done by hand per Mac, and matebook lost its app to one of them.

How:

  • scripts/personal/t3-alpha-build <version>: aligns every package.json to the version (so the server reports it too, not the stale 0.0.42), builds the macOS arm64 zip, and re-signs it with the Apple Development identity on studio. Only the version-bumped manifests are restored afterwards.
  • scripts/personal/t3-alpha-install: moved from ~/.local/bin. It now refuses zips that aren't signed by the team and checks the installed bundle's version. The old sources were wrong: LaunchServices lags one install behind, and the server version was never bumped. It also keeps only the newest backup and cleans up its staging folder on every exit.
  • scripts/personal/t3-alpha-deploy <zip> [host...]: copies the zip and this checkout's installer to matebook and sm-em over SSH, waits for each result, and installs studio last.
  • docs/personal/release-pipeline.md is rewritten as the single runbook: machines, upstream sync via PR, desktop deploy, mobile build/submit (with the EAS identity values), one-time setup.

Verified: built 0.0.46 with t3-alpha-build, then deployed it to matebook and sm-em with t3-alpha-deploy. Both now report server version 0.0.46 with the stable signing rule identifier "com.t3tools.t3code" and anchor apple generic and certificate leaf[subject.CN] = "Apple Development: Emanuel Franzen (T4J48V44Q2)".

Local desktop builds were ad-hoc signed, so every new build was a new app to
macOS privacy grants, keychain ACLs and Little Snitch, and each Mac re-prompted
for everything. Installs were also hand-rolled per Mac, and matebook lost its
app to one of them.

scripts/personal/ now holds the whole desktop flow:
- t3-alpha-build: aligns package versions (so the server reports the release
  version too), builds the zip, re-signs it with a stable identity
- t3-alpha-install: the installer, moved from ~/.local/bin; refuses unsigned
  zips, checks the bundle version, prunes old backups
- t3-alpha-deploy: installs a zip on every Mac over SSH, studio last

release-pipeline.md becomes the single runbook: machines, upstream sync,
desktop deploy, mobile build/submit, one-time setup.
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL labels Sep 24, 2026
@r4iju
r4iju merged commit d4007b0 into main Sep 24, 2026
7 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant