Skip to content

Fix rounded macOS icon on older Macs - #8018

Merged
klopez4212 merged 3 commits into
mainfrom
kennylopez-macos-icon-padding
Oct 1, 2026
Merged

klopez4212 merged 3 commits into
mainfrom
kennylopez-macos-icon-padding

Conversation

@klopez4212

@klopez4212 klopez4212 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Older macOS versions display Buzz’s opaque icon as an oversized square. Bake rounded corners and transparent padding into the macOS .icns, preserving the original bee artwork and leaving other platforms unchanged.

Generation uses Hermit-pinned uv, Python 3.14.3, and Pillow 12.2.0. scripts/macos-icon.sh --check regenerates temporarily and compares all decoded representations; macOS CI runs it before packaging. Pixel reproducibility is verified independently of Apple’s ICNS container encoding.

Validated native AppKit preview, all 10 representations, fresh-cache generation, one-pixel/missing-representation drift rejection, workflow lint, and pre-push checks. Full local just ci is running. Packaged Dock checks on older/current macOS remain outstanding.

Signed-off-by: kenny lopez <klopez4212@gmail.com>
@klopez4212
klopez4212 marked this pull request as ready for review October 1, 2026 09:46
@klopez4212
klopez4212 requested a review from a team as a code owner October 1, 2026 09:46
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T14:29:50.580758Z f6a99d8 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@klopez4212
klopez4212 deployed to codex-review October 1, 2026 09:47 — with GitHub Actions Active
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Note: This is an automated, security-focused review generated by Codex.
Use it as a supplement to human review; false positives are possible.

Scope

  • Exact PR diff: 6b5bb6f5a3fbad1ca42d8f9b14a1418d333b6461...f6a99d8866ef14cda5dc0fffa15548ec7a26df91
  • Model: gpt-5.6-sol

💡 Click "edited" above to see earlier reviews for this PR.


Review Summary

Overall Risk: NONE

No concrete security, correctness, or reliability issues were found in the authorized PR range. Changes are limited to pinned macOS icon generation and verification tooling, CI path selection, icon assets, and an E2E synchronization adjustment.

Findings

No concrete security, correctness, or reliability findings were identified.

Notes

  • No additional limitations were reported.

Generated by Codex Security Review |
Requested by: @klopez4212 |
Workflow run

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: REQUEST CHANGES

Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..92d59c33493e280619b0446d025b3a1b2f5fef86 (exact head 92d59c33493e280619b0446d025b3a1b2f5fef86)

Risk: medium — macOS packaging/UI asset plus a claimed reproducible generator.

Behavior/contracts traced: generator → committed 10-representation ICNS → Tauri macOS bundle/DMG resource; artwork and alpha geometry; CI path selection; Windows/web/mobile asset isolation.

Blocking finding

[P1] scripts/generate-macos-icon.py:4 — the claimed reproducible generator has no repository-declared producing environment.

The script requires external Pillow, but the exact-head Hermit checkout cannot run it (ModuleNotFoundError: No module named 'PIL'). The repository does not pin Pillow or assert a compatible version, and CI does not execute this new generic scripts/ path: .github/workflows/ci.yml:68-75 selects Desktop because the committed ICNS changed, while .github/workflows/_ci-desktop-macos.yml:90-91 only packages the existing asset. Pillow controls LANCZOS resampling and PNG encoding (scripts/generate-macos-icon.py:25-26,40-42), and iconutil controls the final container (:43-46), with neither producing version captured. A future maintainer therefore cannot reconstruct the reviewed environment or reliably distinguish intentional pixel changes from tool drift. That directly misses the PR's explicit “Add a reproducible generator” contract.

Author action: make generation reconstructible from a clean checkout by using established repository tooling or pinning the Python/tool invocation. Add a cheap verification command/test that regenerates to a temporary output and detects representation or byte drift; if exact container identity is promised, record/assert the supported iconutil producer too.

Verification owner: author patches; reviewer reruns from clean Hermit checkout and mutation-checks drift detection.

Verified

  • The generated artifact is internally consistent in a manually supplied environment: Pillow 12.3.0 produced the committed ICNS byte-for-byte across three runs (SHA-256 prefix 774341fe); Pillow 12.2.0 independently matched.
  • iconutil extracts all 10 canonical 1x/2x representations. All have alpha and transparent corners; the 1024px nonzero bounds are centered at (97,97)..(927,927). Checkerboard inspection at 16/32/128/1024px found no clipping, halo, asymmetry, or bee deformation.
  • desktop/src-tauri/tauri.conf.json:63-68 consumes the ICNS, and desktop/scripts/package-macos-dmg.sh:69-73 uses the bundled icon for the DMG volume. Exact-head macOS and Windows package builds passed.
  • The diff is limited to the ICNS and generator. Sibling PNG/ICO/source assets and mobile content are unchanged. git diff --check, Python compilation, and just file-size-check passed on a clean exact-head tree.

Confidence gaps (not additional author defects)

  • A packaged candidate was not observed in Dock, Finder, Cmd-Tab, menu/About, or DMG presentation on both older and current macOS. Static representation evidence is strong, but cache/compositor behavior remains owned by reviewer/tooling or release QA.
  • A signed/notarized CI artifact was not inspected directly; the macOS Tauri build proves packaging acceptance, not final installed pixels. Release artifact validation owns that check.
  • At final review time, Desktop Core and smoke shards 2/4 remained in progress; the exact-head macOS/Windows builds, Rust, DCO, security, release-candidate, and completed integration gates were green. The named CI gate owns merge readiness.

— :bot: Jude’s code review agent

Signed-off-by: kenny lopez <klopez4212@gmail.com>
@klopez4212
klopez4212 deployed to codex-review October 1, 2026 13:44 — with GitHub Actions Active
@github-actions github-actions Bot removed the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 1, 2026
@klopez4212

Copy link
Copy Markdown
Contributor Author

🤖 @jedwards27 Addressed the generator-environment blocker in a0732dc.

  • Hermit now pins uv 0.12.21; scripts/macos-icon.sh uses managed Python 3.14.3 and inline metadata pins Pillow 12.2.0. No preinstalled Pillow is required.
  • scripts/macos-icon.sh --check regenerates into temporary storage and compares every representation’s name, dimensions, and decoded RGBA pixels. The contract is pixel/representation reproducibility, not byte identity across Apple iconutil versions.
  • macOS CI runs this check before packaging. Changes to the generator, wrapper, or uv pin select the desktop job.

Fresh-cache verification passed. A one-pixel mutation and a removed ICNS representation both failed verification as expected. Workflow lint and pre-push checks passed. The committed ICNS is unchanged (774341fe…). Full local just ci is still running; packaged Dock verification on older/current macOS remains outstanding.

@klopez4212
klopez4212 requested a review from jedwards27 October 1, 2026 13:44
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 1, 2026

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: APPROVE

Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..a0732dc8aeb987ef0bedebd80c8dc5993ed17562 (exact live head rechecked immediately before submission)

Risk: medium — this changes a user-visible macOS bundle asset plus its generation and CI enforcement path, but does not alter runtime, relay, identity, persistence, or non-macOS product assets.

Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generator → canonical iconset representations → /usr/bin/iconutil encode/decode → committed ICNS → Tauri bundle and DMG consumption; CI path selection and verification-before-package ordering; representation-set, dimension, and decoded RGBA-pixel drift semantics.

Findings: no unresolved blocking or non-blocking code/product defects. The previous producing-environment and drift-detection blocker is resolved. Independent systems/integration and product/UI adversarial passes both found the semantic contract appropriate: decoded representation names, dimensions, and RGBA pixels guard the visible payload without brittle coupling to PNG compression or ICNS container bytes.

Author action: none.

Verification owner: CI/release gate owns terminal exact-head macOS packaging and signed/notarized artifact checks. Release QA owns installed Dock/Finder/Cmd-Tab/About/DMG observation on older and current macOS.

Validation at matching clean HEAD a0732dc8aeb987ef0bedebd80c8dc5993ed17562:

  • clean-checkout scripts/macos-icon.sh --check: PASS using pinned Hermit uv 0.12.21, managed Python 3.14.3, and Pillow 12.2.0; tree remained clean;
  • mutation probes: one decoded pixel changed → FAIL with macOS icon pixel drift; one representation removed → FAIL with macOS icon representation set drifted; generator geometry changed → pixel-drift FAIL; controls passed and the tree was restored;
  • /usr/bin/iconutil extraction: all 10 canonical representations present; committed ICNS SHA-256 774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d;
  • visual/integrity inspection across 16–1024 px: transparent corners, centered rounded tile, optical inset, bee proportions, symmetry, and antialiasing remained sound;
  • actionlint for changed workflows, git diff --check, Python compile/help, and just file-size-check: PASS;
  • exact-head CI job 110398445978: Verify macOS icon representations passed before packaging began; DCO, security, lint, and the selected cross-compile checks observed at submission were green. Remaining required jobs were still running and remain merge-gate obligations.

Manual/native evidence: decoded representations were visually inspected on macOS. A signed/notarized installed artifact was not exercised in Dock/Finder/Cmd-Tab/About on the target OS range.

Residual risk: macOS compositor/icon-cache behavior on old/current releases and final signed/notarized packaging remain unwitnessed locally. This is an external verification gap, not an author-actionable defect; merge only after required exact-head gates are terminal green.

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..a0732dc8aeb987ef0bedebd80c8dc5993ed17562 (exact head a0732dc8aeb987ef0bedebd80c8dc5993ed17562)
Risk: medium — macOS bundle asset generation and CI packaging contract; committed icon pixels are unchanged in this follow-up.

Behavior/contracts traced: Hermit uv pin → managed Python/Pillow script environment → ICNS generation → decoded representation/pixel verification → changed-path selection → macOS CI verification before Tauri packaging. The semantic contract compares representation names, dimensions, and decoded RGBA pixels, avoiding brittle PNG/ICNS container-byte coupling across Apple iconutil versions. Non-macOS product assets remain unchanged.

Findings: No unresolved blocking or non-blocking code finding. The previous reproducibility blocker is resolved: a clean checkout reconstructs the pinned environment, and CI now selects and executes semantic drift verification before packaging.

Author action: none.
Verification owner: current CI gates for remaining in-progress general jobs; release QA/native macOS artifact gate for installed Dock/Finder/Cmd-Tab/About/DMG observation on old/current macOS.

Validation:

  • PASS — clean-cache scripts/macos-icon.sh --check using pinned uv 0.12.21, managed Python 3.14.3, and Pillow 12.2.0; all decoded representations match and tree remains clean.
  • PASS — independent one-pixel, removed-representation, and generator-geometry mutations were rejected; restored controls passed.
  • PASS — python3 -m py_compile scripts/generate-macos-icon.py, bash -n scripts/macos-icon.sh, and full-range git diff --check at exact head.
  • PASS — exact-head macOS CI icon-verification prerequisite completed before packaging; macOS package build is green at filing.
  • PENDING — several unrelated/full repository CI jobs remain in progress with no failures. These are external gates, not an author-actionable code defect.

Manual/native evidence: All ten canonical ICNS representations were inspected on checkerboards; centered transparent bounds, artwork proportions, and antialiasing remain sound. No installed signed/notarized artifact was exercised on old/current macOS.

Residual risk: OS compositor/icon-cache behavior and final signed/notarized artifact presentation remain unobserved. Release QA owns that confidence gap; it does not imply broken source or require author rework.

Signed-off-by: kenny lopez <klopez4212@gmail.com>
@github-actions github-actions Bot removed the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 1, 2026
@klopez4212
klopez4212 deployed to codex-review October 1, 2026 14:26 — with GitHub Actions Active
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 1, 2026

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..f6a99d8866ef14cda5dc0fffa15548ec7a26df91 (exact live head rechecked immediately before submission)
Risk: medium — user-visible macOS bundle artwork plus its reproducible generation/CI contract; the post-approval delta changes only synchronization in one Desktop E2E.

Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generation → canonical ICNS representations and decoded RGBA drift verification → Tauri bundle/DMG consumption; changed-path selection and verify-before-package ordering; committed pixel/alpha geometry; non-macOS scope; the new spoiler reveal → gallery inclusion synchronization.

Findings: no unresolved blocking or non-blocking code/product defects. The previous approval expired after the head moved. The exact a0732dc8..f6a99d88 delta is confined to desktop/tests/e2e/image-attachment-gallery.spec.ts (+11/-2): it scrolls the target into view, uses the existing bounded animation wait, then waits for the revealed image's actual opacity: 1 state before reopening the gallery. This protects the user-visible transition rather than adding an arbitrary sleep or altering production behavior. The icon/generator/toolchain/workflow contract is byte-identical to the previously approved head.

Author action: none.

Verification owner: CI owns terminal exact-head checks and recovery of the Hermit-activation infrastructure failure in smoke shard 3. Release QA owns signed/notarized installed-artifact observation on older/current macOS.

Validation at matching clean HEAD f6a99d8866ef14cda5dc0fffa15548ec7a26df91:

  • PASS — fresh-cache scripts/macos-icon.sh --check using pinned uv 0.12.21, Python 3.14.3, and Pillow 12.2.0; decoded representation/dimension/RGBA comparison passed and the tree remained clean.
  • PASS — committed ICNS SHA-256 remains 774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d; iconutil extraction produced exactly the 10 canonical RGBA representations. Visual inspection at 16px and 1024px confirmed centered rounded/padded artwork, transparent exterior, and legibility.
  • PASS — complete changed gallery spec: 14/14 tests, including the modified spoiler journey; an independent focused repeat of that journey passed 5/5.
  • PASS — Desktop check/typecheck/full tests, git diff --check, wrapper syntax, and generator help. Only pre-existing Biome warnings were reported.
  • PASS — exact-head required checks currently reported by GitHub: DCO, Desktop Build (macOS), Desktop Release Candidate, and Security.
  • INFRASTRUCTURE FAILURE — Desktop Smoke E2E (3) failed during cashapp/activate-hermit; build/install/test steps never ran. This is a CI/tooling confidence gap, not a PR-caused test failure.

Manual/native evidence: decoded representations were visually inspected on macOS. No signed/notarized installed artifact was exercised on an older macOS release.

Residual risk: old/current macOS Dock/Finder/Cmd-Tab/About/DMG compositor and icon-cache behavior remains unwitnessed on the final installed artifact. Release QA owns that confidence gap. Any further head movement invalidates this approval.

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..f6a99d8866ef14cda5dc0fffa15548ec7a26df91 (exact live head rechecked immediately before submission)
Risk: medium — user-visible macOS bundle artwork plus its reproducible generation/CI contract; the post-approval delta changes only synchronization in one Desktop E2E.

Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generation → canonical ICNS representations and decoded RGBA drift verification → Tauri bundle/DMG consumption; changed-path selection and verify-before-package ordering; committed pixel/alpha geometry; non-macOS scope; the new spoiler reveal → gallery inclusion synchronization.

Findings: no unresolved blocking or non-blocking code/product defects. The previous approval expired after the head moved. The exact a0732dc8..f6a99d88 delta is confined to desktop/tests/e2e/image-attachment-gallery.spec.ts (+11/-2): it scrolls the target into view, uses the existing bounded animation wait, then waits for the revealed image's actual opacity: 1 state before reopening the gallery. This protects the user-visible transition rather than adding an arbitrary sleep or altering production behavior. The icon/generator/toolchain/workflow contract is byte-identical to the previously approved head.

Author action: none.

Verification owner: CI owns terminal exact-head checks and recovery of the Hermit-activation infrastructure failure in smoke shard 3. Release QA owns signed/notarized installed-artifact observation on older/current macOS.

Validation at matching clean HEAD f6a99d8866ef14cda5dc0fffa15548ec7a26df91:

  • PASS — fresh-cache scripts/macos-icon.sh --check using pinned uv 0.12.21, Python 3.14.3, and Pillow 12.2.0; decoded representation/dimension/RGBA comparison passed and the tree remained clean.
  • PASS — committed ICNS SHA-256 remains 774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d; iconutil extraction produced exactly the 10 canonical RGBA representations. Visual inspection at 16px and 1024px confirmed centered rounded/padded artwork, transparent exterior, and legibility.
  • PASS — complete changed gallery spec: 14/14 tests, including the modified spoiler journey; an independent focused repeat of that journey passed 5/5.
  • PASS — Desktop check/typecheck/full tests, git diff --check, wrapper syntax, and generator help. Only pre-existing Biome warnings were reported.
  • PASS — exact-head required checks currently reported by GitHub: DCO, Desktop Build (macOS), Desktop Release Candidate, and Security.
  • INFRASTRUCTURE FAILURE — Desktop Smoke E2E (3) failed during cashapp/activate-hermit; build/install/test steps never ran. This is a CI/tooling confidence gap, not a PR-caused test failure.

Manual/native evidence: decoded representations were visually inspected on macOS. No signed/notarized installed artifact was exercised on an older macOS release.

Residual risk: old/current macOS Dock/Finder/Cmd-Tab/About/DMG compositor and icon-cache behavior remains unwitnessed on the final installed artifact. Release QA owns that confidence gap. Any further head movement invalidates this approval.

@klopez4212
klopez4212 merged commit 0ee2ad7 into main Oct 1, 2026
208 of 215 checks passed
@klopez4212
klopez4212 deleted the kennylopez-macos-icon-padding branch October 1, 2026 16:00
wpfleger96 pushed a commit that referenced this pull request Oct 1, 2026
…ty-from-device

* origin/main:
  Allow following channel messages before their first reply (#7692)
  Fix rounded macOS icon on older Macs (#8018)

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
yjc801 added a commit to yjc801/buzz that referenced this pull request Oct 1, 2026
Conflicts resolved:
- desktop/src-tauri/icons/icon.icns: upstream block#8018 now generates the
  rounded macOS icon from buzz-source.png. Swapped buzz-source.png for the
  fork's Waggle 1024px artwork and regenerated with scripts/macos-icon.sh,
  so the Waggle icon gets the rounded-corner fix and the new --check passes.
- desktop/src/features/agents/hooks.ts: dropped upstream's mutation block
  (fork moved it to channelAgentMutations.ts) and ported block#7999's
  syncAgentsToActiveHuddle call there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Junchao Yan <yjc801@gmail.com>
tlongwell-block pushed a commit that referenced this pull request Oct 1, 2026
Main added eight commits since the last merge: mobile onboarding and
push settings (#8019, #8025, #7526), desktop reads after channel writes
(#7999), following a channel message before its first reply (#7692),
two ACP fixes (#7568, #8022) and the macOS icon (#8018). They change
buzz-acp, desktop, mobile, CI workflows and tooling only. No file is
changed on both sides, and main adds no migration.

The merge is textually clean and needs no follow-on edit. buzz-db,
buzz-relay, migrations, schema and Cargo.lock are byte-identical to the
branch before the merge, and this branch's diff against main is
unchanged: the same 31 files with the same added and removed lines.

Co-authored-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@buzz.block.builderlab.xyz>
Signed-off-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@buzz.block.builderlab.xyz>

This branch was successfully deployed

1 active deployment
codex-review — f6a99d88 Deployed Oct 1, 2026 by klopez4212 via Run Codex Security Review #6371
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex-security-review-current The posted Codex security review matches its recorded range.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants