Releasing the macOS bar app was fully manual (run package_app.sh on a Mac, then
gh release upload --clobber), so Swift-side changes never reached users until
someone remembered to rebuild and re-upload the floating ccs-bar-latest asset.
Add a tightly-scoped Bar Release workflow that does it automatically:
- triggers ONLY on push to main touching macos-bar/**, or manual dispatch, so
regular PRs, dev pushes, and non-bar changes never start it
- runs ONLY on the dedicated self-hosted macOS runner (label ccs-bar); the Linux
CI runners never match it and it never competes for them
- least-privilege contents:write, single-flight via concurrency
Version is sourced from a new macos-bar/VERSION single-line file (the workflow
reads it; the asset is always the latest build regardless). package_app.sh now
defaults to that file when no version arg is passed, so the local manual path and
CI share one source of truth. Documents the release process in docs/ccs-bar.md.
Generate AppIcon.icns from the CCS mark at package time (sips + iconutil)
and reference it via CFBundleIconFile so Finder, Spotlight, and the Dock
show the brand icon instead of a blank bundle.
Refs #1525
Send the composite provider:accountId (row.id) for Set as default so the server
can resolve the CLIProxy account; feature the account closest to exhaustion
(lowest remaining quota) in the title instead of the healthiest; rename the
packaged asset to CCS-Bar.app.zip to match what 'ccs bar install' downloads.
package_app.sh assembles and signs CCS Bar.app (menu-bar-only via LSUIElement).
Default ad-hoc signing for v1 with documented Gatekeeper guidance; developer-id
mode wired for the notarized public-launch path.