feat(appstore): add a Mac App Store build track

Tauri has no App Store target, so mas-package.sh covers the distance between the .app and something
App Store Connect will take. The order is load-bearing: the provisioning profile goes in before
codesign runs because the signature covers it, which is also why Tauri's own signing is switched
off for this build.

The sandbox costs three things, all Apple's rules rather than choices. The updater is gone, and
falls out for free because the plugin was already conditional on the config declaring it; only the
release overlay does. The Check for Updates menu item is gated on the same condition, since a menu
item that errors when clicked is its own rejection risk. The library moves into the container, and
the system spelling dictionary becomes unreadable.

Two things the first upload taught us. The profile is kept owner-only where it lives next to the
signing keys, and cp carried that mode into the bundle; Apple rejects a package containing anything
a non-root user cannot read. And altool exits 0 after printing UPLOAD FAILED, so its exit status
cannot be trusted and the transcript is the only reliable signal.

Claude-Session: https://claude.ai/code/session_018HwEWvoE1NkkUjJCMLSnup
This commit is contained in:
pj committed 2026-08-31 17:26:03 +05:30
1 parent 39d4097773
commit 92b446973f
7 files changed
+339 -6

No files matched your search

+7
View File
@@ -33,3 +33,10 @@ src-tauri/target/
# Screenshots & Playwright MCP artifacts
.playwright-mcp/
/*.png
# App Store packaging output
target-mas/
# Beta app review contact details. Apple requires a real phone number and this repo is public.
appstore/metadata/review_phone.txt
appstore/metadata/review_email.txt