fix/macos launch (#18)

* fix: macOS Finder launch (store path, ad-hoc signing, vendored openssl)

- Store::open was resolving 'gridline.db' relative to the working directory;
  Finder/LaunchServices launches run with cwd=/ so the .expect() panicked
  (exit 101, silent 'app does nothing') before Tauri ever started. Open the
  store under app.path().app_data_dir() in setup instead (same dir as the
  demo DB), creating the dir when needed.
- Add bundle.macOS.signingIdentity "-" + hardenedRuntime false so the
  bundler ad-hoc signs the whole bundle. Previously only the inner binary
  got Xcode 16's linker-signed signature, which macOS treats as unsigned:
  quarantined downloads showed 'damaged and can't be opened', and after
  quarantine removal LaunchServices silently refused to spawn it.
- ssh2 now builds OpenSSL vendored (feature vendored-openssl): the release
  binary previously carried an absolute LC_LOAD_DYLIB to the build machine's
  /opt/homebrew/opt/openssl@3/lib, which dyld aborted on (and hardened
  runtime library-validation rejected even when present).
- README: document the macOS first-launch paths (right-click Open / xattr
  for the damaged-error case, re-run after every upgrade).
- release.yml: update SIGNING STATUS comment to reflect ad-hoc signing.

* chore: bump 0.7.8 -> 0.7.9 (release prep)

- Version sync across package.json, src-tauri/Cargo.toml, src-tauri/tauri.conf.json
- version.test.ts / bundle-config.test.ts / docs-coverage.test.ts expect 0.7.9
- README: both download tables -> v0.7.9 asset names; new v0.7.9 changelog entry;
  tag instructions -> v0.7.9; MAINTENANCE comment updated
- AGENTS.md maintenance note example -> v0.7.9
- ROADMAP: Shipped (0.7.9) section; Next up retitled (0.8.0) TBD
This commit is contained in:
2026-08-08 13:29:31 +08:00
committed by GitHub
parent 751746f784
commit 091d9df6f0
12 changed files with 102 additions and 53 deletions
+1 -1
View File
@@ -166,7 +166,7 @@ Cut a release by tagging the **`prod`** branch once the PR is merged — `git ta
**Before tagging**, keep everything in sync:
- Version number across `package.json`, `src-tauri/Cargo.toml`, and `src-tauri/tauri.conf.json`
- `src/lib/version.test.ts` and `src/lib/docs-coverage.test.ts` if they assert the version
- **README download links are static (versioned)** — both download tables (top **Download** section + **Which file should I download?**) link directly to the release-tag assets (`releases/download/v0.7.8/<file>`). tauri-action uses default versioned asset names (`Gridline_<ver>_aarch64.dmg`, `Gridline-<ver>-1.x86_64.rpm`, etc.) — update BOTH tables to the new names on every release (see the MAINTENANCE comment in README.md).
- **README download links are static (versioned)** — both download tables (top **Download** section + **Which file should I download?**) link directly to the release-tag assets (`releases/download/v0.7.9/<file>`). tauri-action uses default versioned asset names (`Gridline_<ver>_aarch64.dmg`, `Gridline-<ver>-1.x86_64.rpm`, etc.) — update BOTH tables to the new names on every release (see the MAINTENANCE comment in README.md).
- **Bundled pg tools:** `tauri.conf.json` `bundle.resources` lists `resources/pg_tools/*`; the `release.yml` matrix builds/downloads + checksum-verifies the static binaries before the Tauri build step.
### Adding a Tauri Command