Skip to content

feat(macos): add a local community app installer - #91

Open
oscar2012-dot wants to merge 1 commit into
Hao0321:mainfrom
oscar2012-dot:macos-community-installer
Open

oscar2012-dot wants to merge 1 commit into
Hao0321:mainfrom
oscar2012-dot:macos-community-installer

Conversation

@oscar2012-dot

Copy link
Copy Markdown

What changed

Mac users can build and install a local community app with one command, or double-click Install-on-Mac.command after installing prerequisites. The helper checks the toolchain, builds from an isolated copy of Git-tracked source, generates the existing static font pack, packages local runtimes, and verifies an ad-hoc signature. Existing applications are never overwritten.

The macOS build invocation uses panic=unwind for the pinned objc2/WebKit cancellation path. Initialize the public studio and Wave 2 registries before loading App so a reopened project can resolve its transitions before the lazy Inspector loads; a regression test exercises that lookup.

Includes prerequisite, installation, update, project-opening and verification instructions, linked from both READMEs. This complements the CI packaging proposal in #89 with a local source-build route; it adds no release workflow.

User journey and platform

Install Xcode Command Line Tools and Homebrew dependencies, clone the repository, then run bash scripts/install-macos-community.sh or the Finder entry point. Default output is ~/Applications/Editkin Community.app; --check performs prerequisite checks without writes/downloads, and --output selects a new destination.

Tested on Apple Silicon, macOS 26.3.1. This is a local community build that still depends on installed Homebrew libraries. It is not a portable, notarized or official download. Intel and other macOS versions have not been tested.

Validation

  • Shell syntax and real prerequisite check passed.
  • Python packager tests: 10 passed. Installer isolation/negative tests: 9 passed, including FFmpeg capability, destination preservation and tracked-source isolation cases.
  • npm run typecheck, npm run build, npm run source:scan, and npm run source:verify:self-test passed.
  • npm test -- --maxWorkers=4 --reporter=verbose: 280 test files passed, 1 skipped; 2,170 tests passed, 4 skipped.
  • npm run test:journey: synthetic source import, edit, preview-state check, atomic save/reopen, 12-second H.264/AAC export at 960x540, and decoded output frame passed. This is source-level evidence, not a desktop UI export test.
  • Ran the complete installer from a clean public-source checkout. Font generation/gate, web and service builds, locked native release compilation, app packaging, runtime launch probes and deep/strict signature verification passed.
  • Launched that resulting app with the existing EDITKIN_SMOKE=1 handshake and isolated integration state: exit 0 after frontend/native startup. Manual editing/playback/export in this exact packaged GUI remains to be verified separately.

Security and provenance

  • Build-time downloads use the existing npm lockfile, locked Cargo dependencies and an isolated Python environment with pinned fontTools 4.60.2 (MIT license). Homebrew prerequisites are installed explicitly by the user. No application dependency or lockfile changes.
  • Runs npm, Python, Cargo, installed Node/FFmpeg, Apple binary inspection tools and ad-hoc codesign. Build outputs, the Rust target and Python virtual environment live under ignored .rd/; package managers may also populate their standard user caches. Creates a new selected .app without sudo, security-setting changes, signing credentials or existing-app replacement.
  • Uses only existing public synthetic fixtures, the repository's OFL fonts and existing ACES/plugin resources. No new media, fonts, models or prebuilt binaries are committed. Runtime notices are copied from local installations; binary redistribution still requires the separate release review.
  • Build metadata contains hashes and dependency basenames, with no private source paths. Reviewed changes contain no secrets, personal footage, client documents or local user paths. Raw local logs are not uploaded.

DCO

The commit contains a Signed-off-by: trailer using the contributor's GitHub noreply address.

Signed-off-by: oscar2012-dot <295733699+oscar2012-dot@users.noreply.github.com>
@oscar2012-dot
oscar2012-dot requested a review from Hao0321 as a code owner October 7, 2026 05:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant