Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions docs/MACOS-UPDATER-HANDOFF.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# macOS 자동 업데이트 — 남은 작업 인계

## 공개 배포·설치 완료: beta.12

사용자 지시에 따라 `48fffce`의 beta.12 / desktop 0.2.6을 공개하고 현재
Applications 앱을 교체했다. 실제 설치 경로에서 production 모드와 업데이트
확인 설정을 확인했고 이전 origin을 유지한다. 기존 beta.11 앱은 로컬 백업으로
보존했다. 릴리스 ID `385189777`, 공개 태그 `v2.0.0-beta.12`; 서명·공증·전체
파일 검증 및 재검증 후 공개했다. 최초 지원 버전이므로 다음 공개 버전의 실제
버튼 A→B, OS13/권한·취소 등 추가 검증은 릴리스 노트에 미완료로 명시했다.
정확한 해시와 검증 기록은 [RELEASE-BETA12-ACCEPTANCE.md](RELEASE-BETA12-ACCEPTANCE.md).

## 최신 정책: 사용자가 누르는 업데이트

사용자 요청으로 자동 설치가 아닌 **Settings 위 업데이트 안내 → 클릭 시
Expand Down
105 changes: 105 additions & 0 deletions docs/RELEASE-BETA12-ACCEPTANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
# beta.12 click-update release acceptance

Source: `48fffce62492d04eb207d8c1cb66024ef3636877`.
Product `2.0.0-beta.12`, desktop `0.2.6`, SDK `0.16.4`.
Release ID: `385189777`; publicly published September 9, 2026 at 02:58:52 UTC
(11:58:52 KST). Tag `v2.0.0-beta.12` resolves to the exact source commit above.

## Scope and operator decision

The operator explicitly requested replacing the installed application and
publishing this beta, with additional end-to-end testing deferred to a later
version. Source, signing, notarization, archive, version and data-safety gates
were retained. Extended minimum-OS, administrator cancel/recovery, process-owner
and external-account scenarios are disclosed in the release notes; they are
not represented as passed.

The first updater-enabled release needs one manual installation for users of
older disabled builds. Future eligible updates use the sidebar Update button;
automatic checks alone never download or install. A later public version is
still needed to prove public A-to-B behavior.

## Build and cryptographic acceptance

- Fresh source snapshot, dependency installation and Cargo output. All 1,056
tracked source blobs match the frozen commit after building.
- Whole `npm run verify` and desktop native tests passed at this version.
- Native diagnostics confirm release mode, `updateMode: production`, correct
product/desktop versions, and the finalized payload runtime hash.
- The expected public key is compiled into the desktop. Packet SHA-256:
`6f0054b3ce55917aeb1bc07e18b6c7d266298fe356a361ab94972fc821f1a4c5`.
Private signing material was neither embedded nor uploaded. The password was
retrieved from the named login-Keychain item only for the signer child.
- Developer ID: `sangwoo ha (5987KT43TJ)`; hardened signatures and nested runtime
restamping were verified.
- App notarization Accepted: `36f480ed-1134-4e0c-bc34-9c8181c339a5`.
- DMG notarization Accepted: `9ef18dee-9001-4cc9-b25d-379381b22a64`.
Both were stapled before final hashes/signature generation.
- Official Minisign 0.12 verified the updater signature. Its macOS tool archive
was itself verified with the upstream public key before execution.
- DMG, app and updater archive inventories match. Quarantined copied-app
signatures, Gatekeeper, loader stamps and versions passed.
- Copied-app server integration: 7 passed. Separate data-survival smoke passed
with persisted job/event and idempotent schemas.

| Payload | SHA-256 |
| --- | --- |
| macOS DMG | `c6351841b7570c0cadc2e035ac7f4618cdee07935ea0da1c155fd0b8b3e2832d` |
| Signed updater archive | `bba0268c0b5d953f624604045379b018d7af8a0ed362fb905693260b31040e90` |
| Linux server archive | `9a2b5860898fd3b728987f116d5d88565b40d56f4cbfd013bada32fca442f580` |
| Linux deb | `036a9d9be144c328f44532cbc19c1a4b762fcf632b468a8c864989db501cfc04` |
| Linux AppImage | `c7aa4fe42450b80a4f5b7daf73ec8b61c66509f094c724845db5c86e15cbffa2` |

## CI and artifact transfer

Exact-source runs passed: CI `34302548199`, Linux server `34302548214`, Linux
desktop `34302548183`. Ubuntu 22.04/24.04 package/server/GUI checks passed.
Server provenance independently binds the downloaded archive to the source SHA.

The first desktop artifact transfer was mistakenly judged stalled; inspection
showed it had slowly transferred most of the file. A duplicate retry was stopped.
The retained prefix and exact remaining HTTP byte range were joined, and the
complete ZIP matched GitHub artifact `10085736889`'s SHA-256
`06200c0230651c88bc2a5aa4e11084deb9b75d2c0786d8c2f0cecaab49359159`.
Only the four expected entries were extracted, then individual checksums were
verified. No incomplete file was accepted and no check was relaxed.

## Installed application

The user-authorized replacement is at `/Applications/Gajae Code App.app`.
The seven captured old application processes exited after normal Cmd-Q; no
force-kill was used. Previous beta.11 is preserved at:

`/Users/devswha/Library/Application Support/Gajae Code App Backups/before-beta12-wwmklE/Gajae Code App.app`

An initial command-line placement retained App Translocation. The accepted DMG
was then copied through Finder's standard Applications/Replace operation.
Quarantine was not manually removed. Post-copy inventory and signature checks
passed, and the actual native/server executables now run from `/Applications`.

The UI confirms beta.12 / 0.2.6 and the native checks-only update controls.
The origin remains `http://127.0.0.1:60278`, preserving the existing WebKit origin.
The application was left running; no real provider request was sent. App data
directories were not part of the file replacement or deleted. Binary backup is
not a promise of automatic rollback of future user-data changes.

Local evidence: `/private/tmp/gajae-beta12-release.5ah7NF`, including context,
source-integrity, signing/notary receipts, local/Linux acceptance, artifact
transfer digest, installation and runtime records. The tested Mac is macOS
26.6.2; declared loader minimum 13.0 is not actual macOS 13 execution evidence.

## Publication and website

PRs #49, #50 and #51 were merged without squashing the frozen build commit.
The release contains twelve verified files: six macOS updater/DMG assets, two
server assets and four optional Linux desktop assets. The guarded verifier
completed a full `verified-draft` pass, then repeated download/signature/version/
inventory/history checks in its `--publish` invocation before changing the exact
release ID to public. A separate API read confirmed `draft: false`, the tag target
and all twelve uploaded assets. The public manifest URL was checked against its
independently pinned digest.

The same accepted DMG and checksum are also in Downloads. Website PR #52 updates
the advertised files to beta.12 only after verified publication. Its application
code is unchanged from the frozen release; website-only checks and the following
acceptance documentation do not change the published binary provenance.
9 changes: 9 additions & 0 deletions docs/V2-SESSION-HANDOFF.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,14 @@
# gajae-app v2 — Session Handoff (resume state)

**Published and installed: v2.0.0-beta.12 / desktop 0.2.6**, source `48fffce`.
Release `385189777` contains the signed/notarized macOS DMG and click-update
archive/manifest plus same-source Linux server/desktop artifacts. The installed
Applications copy runs in production update mode at the prior local origin;
beta.11 is preserved as a local binary backup. PRs #49/#50/#51 are merged.
Extended future-version update/OS13/authority scenarios remain explicitly
disclosed beta follow-up work, per the user's publication instruction.
See [RELEASE-BETA12-ACCEPTANCE.md](RELEASE-BETA12-ACCEPTANCE.md) for exact evidence.

Latest updater policy: the user requested a bottom-left notice above Settings
and explicit Update clicks instead of automatic installation. Discovery is
checks-only; download and safe restart bind the clicked native target. Cached
Expand Down
10 changes: 8 additions & 2 deletions scripts/release/UPDATER-KEY-CUSTODY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Local production updater-key custody

The matching public key is now compiled into the published beta.12 / desktop
0.2.6 application. The encrypted private key signed its updater archive and
official Minisign 0.12 verification passed. No private key/password was uploaded.
Independent backup remains deferred by the operator; see the release's explicit
acceptance/limitations in `docs/RELEASE-BETA12-ACCEPTANCE.md`.

## Verified local setup — September 9, 2026

The operator generated a password-protected Tauri key through the official
Expand Down Expand Up @@ -29,8 +35,8 @@ The repository contains no private key, password or signing credential.

This is **local key-provisioning proof**, not a published update, a production
app change, or final release acceptance. The release verifier must still use
official Minisign 0.12 as required by `LOCAL-RELEASE.md`. This key has not yet
been bound into a publicly distributed updater-enabled application.
official Minisign 0.12 as required by `LOCAL-RELEASE.md`. The original provisioning
proof preceded the beta.12 publication recorded above.

## Independent recovery backup remains pending

Expand Down
6 changes: 3 additions & 3 deletions website/src/releases.js
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,10 @@ export const GAJAE_CODE_URL = 'https://github.com/devswha/gajae-code';
export const APPLE_GATEKEEPER_HELP_URL = 'https://support.apple.com/102445';

export const RELEASE = {
version: '2.0.0-beta.10',
tag: 'v2.0.0-beta.10',
version: '2.0.0-beta.12',
tag: 'v2.0.0-beta.12',
channel: 'beta',
publishedLabel: '2026-09-07',
publishedLabel: '2026-09-09',
};

function releaseDownloadBase(tag = RELEASE.tag) {
Expand Down
4 changes: 2 additions & 2 deletions website/tests/releases.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,12 @@ import {
} from '../src/releases.js';

/**
* Reviewed public-release fixture: these assets were published as beta.10.
* Reviewed public-release fixture: promote this with the verified beta.12 assets.
* A local/test candidate can advance package.json before publication; coupling
* the page to that version would advertise download URLs that do not exist.
* Update this fixture with RELEASE only after verifying the new public assets.
*/
const publishedVersion = '2.0.0-beta.10';
const publishedVersion = '2.0.0-beta.12';

test('pins the published release and its GitHub URLs independently of local candidates', () => {
assert.equal(RELEASE.version, publishedVersion);
Expand Down