midi-harbor/specs/016-app-store-submission/tasks.md
James Coleman 9eede3b366 fix(appstore): drop winit's private blur call that App Review refused
- App Review's automated check rejected the first submission for importing the private `CGSSetWindowBackgroundBlurRadius`. winit's macOS backend calls it for window blur, and the import stays in the binary although no window here asks for blur.
- Every winit crate is now patched to grmrgecko/winit, which is libcosmic's pinned revision with the private calls removed and blur doing nothing on macOS. The fork has to move whenever the libcosmic revision does.
- The App Store bundle is no longer signed when either executable imports a private window server symbol, so a dependency update cannot bring one back unnoticed.
- The `com.apple.security.network.server` entitlement, which the same check questioned, stays: network ports bind UDP and take incoming sessions. R-110 records the answer given to App Review.
2026-10-03 09:39:12 -05:00

6 lines
1.2 KiB
Markdown

# Tasks: App Store Submission
Tasks by their numbers in the project-wide sequence, which continues across every spec.
- [x] T245 Build the App Store package with `make appstore`, per FR-S01 to FR-S03 — done: with `.signing/app-store.provisionprofile`, `bundle.sh --helper` embeds the profile, adds its App ID and team to the app's entitlements after checking the App ID is the bundle's, signs both executables with the keychain's Apple Distribution identity, sets the build number to the time in UTC and `ITSAppUsesNonExemptEncryption` to false, and wraps the app in a package signed with Mac Installer Distribution; without a profile it builds as before. Checked on the owner's Mac (R-103); not unit tested, since it is a build script.
- [x] T255 Remove what App Review's automated check refused (R-110) — done: every winit crate is patched to `grmrgecko/winit`, which drops the private `CGSSetWindowBackgroundBlurRadius` call, and `bundle.sh` refuses an App Store bundle whose executables import a private window server symbol. Checked with `nm -u` on both architectures of both executables; not unit tested, since it is a dependency patch and a build script. The server entitlement is kept and answered in App Review Information.