Fix rounded macOS icon on older Macs - #8018
Conversation
Signed-off-by: kenny lopez <klopez4212@gmail.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🔐 Codex Security Review
Review SummaryOverall Risk: NONE
FindingsNo concrete security, correctness, or reliability findings were identified. Notes
Generated by Codex Security Review | |
jedwards27
left a comment
There was a problem hiding this comment.
Verdict: REQUEST CHANGES
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..92d59c33493e280619b0446d025b3a1b2f5fef86 (exact head 92d59c33493e280619b0446d025b3a1b2f5fef86)
Risk: medium — macOS packaging/UI asset plus a claimed reproducible generator.
Behavior/contracts traced: generator → committed 10-representation ICNS → Tauri macOS bundle/DMG resource; artwork and alpha geometry; CI path selection; Windows/web/mobile asset isolation.
Blocking finding
[P1] scripts/generate-macos-icon.py:4 — the claimed reproducible generator has no repository-declared producing environment.
The script requires external Pillow, but the exact-head Hermit checkout cannot run it (ModuleNotFoundError: No module named 'PIL'). The repository does not pin Pillow or assert a compatible version, and CI does not execute this new generic scripts/ path: .github/workflows/ci.yml:68-75 selects Desktop because the committed ICNS changed, while .github/workflows/_ci-desktop-macos.yml:90-91 only packages the existing asset. Pillow controls LANCZOS resampling and PNG encoding (scripts/generate-macos-icon.py:25-26,40-42), and iconutil controls the final container (:43-46), with neither producing version captured. A future maintainer therefore cannot reconstruct the reviewed environment or reliably distinguish intentional pixel changes from tool drift. That directly misses the PR's explicit “Add a reproducible generator” contract.
Author action: make generation reconstructible from a clean checkout by using established repository tooling or pinning the Python/tool invocation. Add a cheap verification command/test that regenerates to a temporary output and detects representation or byte drift; if exact container identity is promised, record/assert the supported iconutil producer too.
Verification owner: author patches; reviewer reruns from clean Hermit checkout and mutation-checks drift detection.
Verified
- The generated artifact is internally consistent in a manually supplied environment: Pillow 12.3.0 produced the committed ICNS byte-for-byte across three runs (SHA-256 prefix
774341fe); Pillow 12.2.0 independently matched. iconutilextracts all 10 canonical 1x/2x representations. All have alpha and transparent corners; the 1024px nonzero bounds are centered at(97,97)..(927,927). Checkerboard inspection at 16/32/128/1024px found no clipping, halo, asymmetry, or bee deformation.desktop/src-tauri/tauri.conf.json:63-68consumes the ICNS, anddesktop/scripts/package-macos-dmg.sh:69-73uses the bundled icon for the DMG volume. Exact-head macOS and Windows package builds passed.- The diff is limited to the ICNS and generator. Sibling PNG/ICO/source assets and mobile content are unchanged.
git diff --check, Python compilation, andjust file-size-checkpassed on a clean exact-head tree.
Confidence gaps (not additional author defects)
- A packaged candidate was not observed in Dock, Finder, Cmd-Tab, menu/About, or DMG presentation on both older and current macOS. Static representation evidence is strong, but cache/compositor behavior remains owned by reviewer/tooling or release QA.
- A signed/notarized CI artifact was not inspected directly; the macOS Tauri build proves packaging acceptance, not final installed pixels. Release artifact validation owns that check.
- At final review time, Desktop Core and smoke shards 2/4 remained in progress; the exact-head macOS/Windows builds, Rust, DCO, security, release-candidate, and completed integration gates were green. The named CI gate owns merge readiness.
— :bot: Jude’s code review agent
Signed-off-by: kenny lopez <klopez4212@gmail.com>
|
🤖 @jedwards27 Addressed the generator-environment blocker in a0732dc.
Fresh-cache verification passed. A one-pixel mutation and a removed ICNS representation both failed verification as expected. Workflow lint and pre-push checks passed. The committed ICNS is unchanged ( |
jedwards27
left a comment
There was a problem hiding this comment.
Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..a0732dc8aeb987ef0bedebd80c8dc5993ed17562 (exact live head rechecked immediately before submission)
Risk: medium — this changes a user-visible macOS bundle asset plus its generation and CI enforcement path, but does not alter runtime, relay, identity, persistence, or non-macOS product assets.
Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generator → canonical iconset representations → /usr/bin/iconutil encode/decode → committed ICNS → Tauri bundle and DMG consumption; CI path selection and verification-before-package ordering; representation-set, dimension, and decoded RGBA-pixel drift semantics.
Findings: no unresolved blocking or non-blocking code/product defects. The previous producing-environment and drift-detection blocker is resolved. Independent systems/integration and product/UI adversarial passes both found the semantic contract appropriate: decoded representation names, dimensions, and RGBA pixels guard the visible payload without brittle coupling to PNG compression or ICNS container bytes.
Author action: none.
Verification owner: CI/release gate owns terminal exact-head macOS packaging and signed/notarized artifact checks. Release QA owns installed Dock/Finder/Cmd-Tab/About/DMG observation on older and current macOS.
Validation at matching clean HEAD a0732dc8aeb987ef0bedebd80c8dc5993ed17562:
- clean-checkout
scripts/macos-icon.sh --check: PASS using pinned Hermituv 0.12.21, managed Python3.14.3, and Pillow12.2.0; tree remained clean; - mutation probes: one decoded pixel changed → FAIL with
macOS icon pixel drift; one representation removed → FAIL withmacOS icon representation set drifted; generator geometry changed → pixel-drift FAIL; controls passed and the tree was restored; /usr/bin/iconutilextraction: all 10 canonical representations present; committed ICNS SHA-256774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d;- visual/integrity inspection across 16–1024 px: transparent corners, centered rounded tile, optical inset, bee proportions, symmetry, and antialiasing remained sound;
actionlintfor changed workflows,git diff --check, Python compile/help, andjust file-size-check: PASS;- exact-head CI job
110398445978: Verify macOS icon representations passed before packaging began; DCO, security, lint, and the selected cross-compile checks observed at submission were green. Remaining required jobs were still running and remain merge-gate obligations.
Manual/native evidence: decoded representations were visually inspected on macOS. A signed/notarized installed artifact was not exercised in Dock/Finder/Cmd-Tab/About on the target OS range.
Residual risk: macOS compositor/icon-cache behavior on old/current releases and final signed/notarized packaging remain unwitnessed locally. This is an external verification gap, not an author-actionable defect; merge only after required exact-head gates are terminal green.
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..a0732dc8aeb987ef0bedebd80c8dc5993ed17562 (exact head a0732dc8aeb987ef0bedebd80c8dc5993ed17562)
Risk: medium — macOS bundle asset generation and CI packaging contract; committed icon pixels are unchanged in this follow-up.
Behavior/contracts traced: Hermit uv pin → managed Python/Pillow script environment → ICNS generation → decoded representation/pixel verification → changed-path selection → macOS CI verification before Tauri packaging. The semantic contract compares representation names, dimensions, and decoded RGBA pixels, avoiding brittle PNG/ICNS container-byte coupling across Apple iconutil versions. Non-macOS product assets remain unchanged.
Findings: No unresolved blocking or non-blocking code finding. The previous reproducibility blocker is resolved: a clean checkout reconstructs the pinned environment, and CI now selects and executes semantic drift verification before packaging.
Author action: none.
Verification owner: current CI gates for remaining in-progress general jobs; release QA/native macOS artifact gate for installed Dock/Finder/Cmd-Tab/About/DMG observation on old/current macOS.
Validation:
- PASS — clean-cache
scripts/macos-icon.sh --checkusing pinned uv 0.12.21, managed Python 3.14.3, and Pillow 12.2.0; all decoded representations match and tree remains clean. - PASS — independent one-pixel, removed-representation, and generator-geometry mutations were rejected; restored controls passed.
- PASS —
python3 -m py_compile scripts/generate-macos-icon.py,bash -n scripts/macos-icon.sh, and full-rangegit diff --checkat exact head. - PASS — exact-head macOS CI icon-verification prerequisite completed before packaging; macOS package build is green at filing.
- PENDING — several unrelated/full repository CI jobs remain in progress with no failures. These are external gates, not an author-actionable code defect.
Manual/native evidence: All ten canonical ICNS representations were inspected on checkerboards; centered transparent bounds, artwork proportions, and antialiasing remain sound. No installed signed/notarized artifact was exercised on old/current macOS.
Residual risk: OS compositor/icon-cache behavior and final signed/notarized artifact presentation remain unobserved. Release QA owns that confidence gap; it does not imply broken source or require author rework.
Signed-off-by: kenny lopez <klopez4212@gmail.com>
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..f6a99d8866ef14cda5dc0fffa15548ec7a26df91 (exact live head rechecked immediately before submission)
Risk: medium — user-visible macOS bundle artwork plus its reproducible generation/CI contract; the post-approval delta changes only synchronization in one Desktop E2E.
Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generation → canonical ICNS representations and decoded RGBA drift verification → Tauri bundle/DMG consumption; changed-path selection and verify-before-package ordering; committed pixel/alpha geometry; non-macOS scope; the new spoiler reveal → gallery inclusion synchronization.
Findings: no unresolved blocking or non-blocking code/product defects. The previous approval expired after the head moved. The exact a0732dc8..f6a99d88 delta is confined to desktop/tests/e2e/image-attachment-gallery.spec.ts (+11/-2): it scrolls the target into view, uses the existing bounded animation wait, then waits for the revealed image's actual opacity: 1 state before reopening the gallery. This protects the user-visible transition rather than adding an arbitrary sleep or altering production behavior. The icon/generator/toolchain/workflow contract is byte-identical to the previously approved head.
Author action: none.
Verification owner: CI owns terminal exact-head checks and recovery of the Hermit-activation infrastructure failure in smoke shard 3. Release QA owns signed/notarized installed-artifact observation on older/current macOS.
Validation at matching clean HEAD f6a99d8866ef14cda5dc0fffa15548ec7a26df91:
- PASS — fresh-cache
scripts/macos-icon.sh --checkusing pinned uv0.12.21, Python3.14.3, and Pillow12.2.0; decoded representation/dimension/RGBA comparison passed and the tree remained clean. - PASS — committed ICNS SHA-256 remains
774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d;iconutilextraction produced exactly the 10 canonical RGBA representations. Visual inspection at 16px and 1024px confirmed centered rounded/padded artwork, transparent exterior, and legibility. - PASS — complete changed gallery spec: 14/14 tests, including the modified spoiler journey; an independent focused repeat of that journey passed 5/5.
- PASS — Desktop check/typecheck/full tests,
git diff --check, wrapper syntax, and generator help. Only pre-existing Biome warnings were reported. - PASS — exact-head required checks currently reported by GitHub: DCO, Desktop Build (macOS), Desktop Release Candidate, and Security.
- INFRASTRUCTURE FAILURE — Desktop Smoke E2E (3) failed during
cashapp/activate-hermit; build/install/test steps never ran. This is a CI/tooling confidence gap, not a PR-caused test failure.
Manual/native evidence: decoded representations were visually inspected on macOS. No signed/notarized installed artifact was exercised on an older macOS release.
Residual risk: old/current macOS Dock/Finder/Cmd-Tab/About/DMG compositor and icon-cache behavior remains unwitnessed on the final installed artifact. Release QA owns that confidence gap. Any further head movement invalidates this approval.
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: 5fdb2e53659ee29002545f1022c138fe0b8282f9..f6a99d8866ef14cda5dc0fffa15548ec7a26df91 (exact live head rechecked immediately before submission)
Risk: medium — user-visible macOS bundle artwork plus its reproducible generation/CI contract; the post-approval delta changes only synchronization in one Desktop E2E.
Behavior/contracts traced: source PNG → pinned Hermit/uv/Python/Pillow generation → canonical ICNS representations and decoded RGBA drift verification → Tauri bundle/DMG consumption; changed-path selection and verify-before-package ordering; committed pixel/alpha geometry; non-macOS scope; the new spoiler reveal → gallery inclusion synchronization.
Findings: no unresolved blocking or non-blocking code/product defects. The previous approval expired after the head moved. The exact a0732dc8..f6a99d88 delta is confined to desktop/tests/e2e/image-attachment-gallery.spec.ts (+11/-2): it scrolls the target into view, uses the existing bounded animation wait, then waits for the revealed image's actual opacity: 1 state before reopening the gallery. This protects the user-visible transition rather than adding an arbitrary sleep or altering production behavior. The icon/generator/toolchain/workflow contract is byte-identical to the previously approved head.
Author action: none.
Verification owner: CI owns terminal exact-head checks and recovery of the Hermit-activation infrastructure failure in smoke shard 3. Release QA owns signed/notarized installed-artifact observation on older/current macOS.
Validation at matching clean HEAD f6a99d8866ef14cda5dc0fffa15548ec7a26df91:
- PASS — fresh-cache
scripts/macos-icon.sh --checkusing pinned uv0.12.21, Python3.14.3, and Pillow12.2.0; decoded representation/dimension/RGBA comparison passed and the tree remained clean. - PASS — committed ICNS SHA-256 remains
774341fe1f965cf02a6c4b7f8443552cacdc82c0a4bfe30e0b60b95450de8b6d;iconutilextraction produced exactly the 10 canonical RGBA representations. Visual inspection at 16px and 1024px confirmed centered rounded/padded artwork, transparent exterior, and legibility. - PASS — complete changed gallery spec: 14/14 tests, including the modified spoiler journey; an independent focused repeat of that journey passed 5/5.
- PASS — Desktop check/typecheck/full tests,
git diff --check, wrapper syntax, and generator help. Only pre-existing Biome warnings were reported. - PASS — exact-head required checks currently reported by GitHub: DCO, Desktop Build (macOS), Desktop Release Candidate, and Security.
- INFRASTRUCTURE FAILURE — Desktop Smoke E2E (3) failed during
cashapp/activate-hermit; build/install/test steps never ran. This is a CI/tooling confidence gap, not a PR-caused test failure.
Manual/native evidence: decoded representations were visually inspected on macOS. No signed/notarized installed artifact was exercised on an older macOS release.
Residual risk: old/current macOS Dock/Finder/Cmd-Tab/About/DMG compositor and icon-cache behavior remains unwitnessed on the final installed artifact. Release QA owns that confidence gap. Any further head movement invalidates this approval.
Conflicts resolved: - desktop/src-tauri/icons/icon.icns: upstream block#8018 now generates the rounded macOS icon from buzz-source.png. Swapped buzz-source.png for the fork's Waggle 1024px artwork and regenerated with scripts/macos-icon.sh, so the Waggle icon gets the rounded-corner fix and the new --check passes. - desktop/src/features/agents/hooks.ts: dropped upstream's mutation block (fork moved it to channelAgentMutations.ts) and ported block#7999's syncAgentsToActiveHuddle call there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Junchao Yan <yjc801@gmail.com>
Main added eight commits since the last merge: mobile onboarding and push settings (#8019, #8025, #7526), desktop reads after channel writes (#7999), following a channel message before its first reply (#7692), two ACP fixes (#7568, #8022) and the macOS icon (#8018). They change buzz-acp, desktop, mobile, CI workflows and tooling only. No file is changed on both sides, and main adds no migration. The merge is textually clean and needs no follow-on edit. buzz-db, buzz-relay, migrations, schema and Cargo.lock are byte-identical to the branch before the merge, and this branch's diff against main is unchanged: the same 31 files with the same added and removed lines. Co-authored-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@buzz.block.builderlab.xyz> Signed-off-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@buzz.block.builderlab.xyz>
Older macOS versions display Buzz’s opaque icon as an oversized square. Bake rounded corners and transparent padding into the macOS
.icns, preserving the original bee artwork and leaving other platforms unchanged.Generation uses Hermit-pinned uv, Python 3.14.3, and Pillow 12.2.0.
scripts/macos-icon.sh --checkregenerates temporarily and compares all decoded representations; macOS CI runs it before packaging. Pixel reproducibility is verified independently of Apple’s ICNS container encoding.Validated native AppKit preview, all 10 representations, fresh-cache generation, one-pixel/missing-representation drift rejection, workflow lint, and pre-push checks. Full local
just ciis running. Packaged Dock checks on older/current macOS remain outstanding.