eeb391d0b1
Adds a one-shot `hermes desktop --setup-tcc-identity` command that creates a self-signed code-signing certificate in the login keychain (openssl + security import), grants codesign access to it, writes desktop.macos_signing_identity to config.yaml, and re-signs the packaged app with a certificate-anchored Designated Requirement. macOS persists permission grants (Full Disk Access, Accessibility, Files and Folders, microphone) against the app's code-signing identity, not its path. The default identifier-pinned ad-hoc signature is stable across rebuilds, but a certificate-anchored identity is the strongest guarantee — the same mechanism yabai/skhd rely on. Previously users had to create the certificate manually in Keychain Access; this command automates the whole flow and is idempotent (re-run after updates). Docs: desktop.md TCC section now leads with the command, keeps manual steps. Tests: 4 new — fresh cert creation path, idempotent reuse, non-macOS no-op, cmd_gui early-exit before build.