f0e9902664
The Hermes Desktop renderer initializes Chromium's audio stack on user gesture (completion chimes via Web Audio API in completion-sound.ts, voice TTS via voice-playback.ts, mic capture via use-mic-recorder.ts, and an eager AudioContext prime in haptics-provider.tsx). On macOS 26+, that initialization registers the helper with the MediaLibrary TCC service (kTCCServiceMediaLibrary), which surfaces to the user as a "Hermes wants to access Music" permission prompt even though Hermes never reads or writes the Apple Music library. The Info.plist (built from apps/desktop/package.json's build.mac.extendInfo) already declares NSAudioCaptureUsageDescription and NSMicrophoneUsageDescription, but NSAppleMusicUsageDescription was missing from the desktop app entirely. macOS therefore shows a system-default or generic prompt for the MediaLibrary bucket instead of an honest description from the app. Fix --- Add NSAppleMusicUsageDescription to build.mac.extendInfo with copy that disclaims Music library access while explaining the system audio stack uses voice, TTS, and completion sounds. Add tests/test_desktop_mac_entitlements.py to pin every NS*UsageDescription key declared in the Desktop build config. The test: - parametrized over a (key, required_substring, reason) table - asserts no leading/trailing whitespace and no newline chars in any usage string (electron-builder passes them through verbatim; control chars render as broken prompt text) - asserts drift-protection: a new NS*UsageDescription key added to the build config without a matching test row causes a hard failure Pattern reference: PR #59486 ("fix(desktop): add macOS contacts privacy strings") is the open canonical for the same shape of fix for Contacts; PR #64582 / PR #65220 extend it for Reminders. The closed duplicate PRs Related, not in this PR ----------------------- - PR #62601 (sounddevice on macOS) is the gateway/CLI side of the same kTCCServiceMediaLibrary trigger. - PR #45952 (macOS permission broker foundation) is architectural work for centralized TCC handling; this fix does not depend on it. - PR #52839 (browser automation Chrome launch) mutes Chromium audio in a different surface; the same pattern is recorded there. Fixes #54551