fix/macos launch (#18)

* fix: macOS Finder launch (store path, ad-hoc signing, vendored openssl)

- Store::open was resolving 'gridline.db' relative to the working directory;
  Finder/LaunchServices launches run with cwd=/ so the .expect() panicked
  (exit 101, silent 'app does nothing') before Tauri ever started. Open the
  store under app.path().app_data_dir() in setup instead (same dir as the
  demo DB), creating the dir when needed.
- Add bundle.macOS.signingIdentity "-" + hardenedRuntime false so the
  bundler ad-hoc signs the whole bundle. Previously only the inner binary
  got Xcode 16's linker-signed signature, which macOS treats as unsigned:
  quarantined downloads showed 'damaged and can't be opened', and after
  quarantine removal LaunchServices silently refused to spawn it.
- ssh2 now builds OpenSSL vendored (feature vendored-openssl): the release
  binary previously carried an absolute LC_LOAD_DYLIB to the build machine's
  /opt/homebrew/opt/openssl@3/lib, which dyld aborted on (and hardened
  runtime library-validation rejected even when present).
- README: document the macOS first-launch paths (right-click Open / xattr
  for the damaged-error case, re-run after every upgrade).
- release.yml: update SIGNING STATUS comment to reflect ad-hoc signing.

* chore: bump 0.7.8 -> 0.7.9 (release prep)

- Version sync across package.json, src-tauri/Cargo.toml, src-tauri/tauri.conf.json
- version.test.ts / bundle-config.test.ts / docs-coverage.test.ts expect 0.7.9
- README: both download tables -> v0.7.9 asset names; new v0.7.9 changelog entry;
  tag instructions -> v0.7.9; MAINTENANCE comment updated
- AGENTS.md maintenance note example -> v0.7.9
- ROADMAP: Shipped (0.7.9) section; Next up retitled (0.8.0) TBD
This commit is contained in:
2026-08-08 13:29:31 +08:00
committed by GitHub
parent 751746f784
commit 091d9df6f0
12 changed files with 102 additions and 53 deletions
+21 -9
View File
@@ -38,21 +38,33 @@ pub fn run() {
// another provider is already installed).
let _ = rustls::crypto::ring::default_provider().install_default();
let store = Store::open("gridline.db").expect("failed to open db");
let store_ref = StdMutex::new(store);
tauri::Builder::default()
.plugin(tauri_plugin_opener::init())
.plugin(tauri_plugin_fs::init())
.plugin(tauri_plugin_dialog::init())
.plugin(tauri_plugin_keyring_store::init())
.manage(AppState {
db_store: store_ref,
pool_manager: tokio::sync::Mutex::new(ConnectionPoolManager::new()),
ssh_manager: StdMutex::new(SshTunnelManager::new(Arc::new(Ssh2Backend))),
cancel_registry: crate::cancel::CancelRegistry::default(),
})
.setup(move |app| {
// Open the local store under the OS app-data directory. When the
// app is launched from Finder/LaunchServices the working directory
// is `/`, so a relative "gridline.db" path panics ("failed to
// open db", exit 101) before the UI ever starts. The demo DB uses
// the same directory (see commands/demo.rs).
let data_dir = app
.path()
.app_data_dir()
.map_err(|e| format!("failed to resolve app data dir: {e}"))?;
std::fs::create_dir_all(&data_dir)
.map_err(|e| format!("failed to create app data dir: {e}"))?;
let store =
Store::open(&data_dir.join("gridline.db").to_string_lossy()).expect("failed to open db");
app.manage(AppState {
db_store: StdMutex::new(store),
pool_manager: tokio::sync::Mutex::new(ConnectionPoolManager::new()),
ssh_manager: StdMutex::new(SshTunnelManager::new(Arc::new(Ssh2Backend))),
cancel_registry: crate::cancel::CancelRegistry::default(),
});
let state = app.state::<AppState>();
demo::ensure_demo_db(app.handle(), &state.db_store)
.map_err(|e| {