fixing sign

This commit is contained in:
abue-ammar
2026-07-18 00:07:56 +06:00
parent c4eb38724b
commit 9d7663ead7
3 changed files with 92 additions and 3 deletions
+36 -3
View File
@@ -60,6 +60,35 @@ jobs:
echo "prerelease=${PRERELEASE}"
} >> "$GITHUB_OUTPUT"
# Import the stable self-signed identity so every release is signed with the SAME cert.
# This is what keeps users' Accessibility (TCC) grant alive across updates — without it
# make-app.sh ad-hoc signs, changing the code signature (and breaking the grant) each build.
# Generate the secrets with Packaging/export-signing-cert.sh.
- name: Import signing certificate
id: signing
env:
P12_BASE64: ${{ secrets.SIGNING_P12_BASE64 }}
P12_PASSWORD: ${{ secrets.SIGNING_P12_PASSWORD }}
run: |
if [ -z "${P12_BASE64}" ]; then
echo "::warning::SIGNING_P12_BASE64 not set — falling back to ad-hoc signing. Users' Accessibility grant will NOT survive updates until this secret is added (see Packaging/export-signing-cert.sh)."
echo "strict=0" >> "$GITHUB_OUTPUT"
exit 0
fi
KEYCHAIN="$RUNNER_TEMP/signing.keychain-db"
KPW="$(openssl rand -base64 24)"
echo "${P12_BASE64}" | base64 --decode > "$RUNNER_TEMP/cert.p12"
security create-keychain -p "$KPW" "$KEYCHAIN"
security set-keychain-settings -lut 21600 "$KEYCHAIN"
security unlock-keychain -p "$KPW" "$KEYCHAIN"
security import "$RUNNER_TEMP/cert.p12" -k "$KEYCHAIN" -P "${P12_PASSWORD}" -A -T /usr/bin/codesign
# Let codesign use the key without an interactive prompt.
security set-key-partition-list -S apple-tool:,apple: -s -k "$KPW" "$KEYCHAIN" >/dev/null
# Prepend to the search list so `security find-identity` (in make-app.sh) sees it.
security list-keychains -d user -s "$KEYCHAIN" $(security list-keychains -d user | sed 's/"//g')
rm -f "$RUNNER_TEMP/cert.p12"
echo "strict=1" >> "$GITHUB_OUTPUT"
- name: Build DMG
env:
VERSION: ${{ steps.meta.outputs.full_version }}
@@ -67,6 +96,7 @@ jobs:
BUNDLE_ID: ${{ steps.meta.outputs.bundle_id }}
BUILD_NUMBER: ${{ github.run_number }}
DMG_BASE: Tinycast
STRICT_SIGN: ${{ steps.signing.outputs.strict }}
run: Packaging/build-dmg.sh
- uses: actions/upload-artifact@v7
@@ -91,11 +121,14 @@ jobs:
**Bundle ID:** \`${{ steps.meta.outputs.bundle_id }}\`
Built from ${{ github.sha }}.
This build is **not signed with an Apple Developer ID and not notarized** (this project has no paid Apple account). macOS will refuse to open it until you clear the quarantine flag:
**Recommended:** install via Homebrew — it clears the quarantine flag automatically on every install and update, so there's nothing to run by hand:
\`\`\`sh
brew install --cask abue-ammar/tinycast/${{ steps.meta.outputs.cask_name }}
\`\`\`
This build is signed with a stable self-signed identity (**not** an Apple Developer ID, and not notarized — this project has no paid Apple account). If you download the DMG directly instead of using Homebrew, macOS will refuse to open it until you clear the quarantine flag once:
\`\`\`sh
xattr -dr com.apple.quarantine \"/Applications/${{ steps.meta.outputs.display_name }}.app\"
\`\`\`
Or install via Homebrew: \`brew install --cask abue-ammar/tinycast/${{ steps.meta.outputs.cask_name }}\`" \
\`\`\`" \
$PRERELEASE_FLAG
- name: Update Homebrew cask
+48
View File
@@ -0,0 +1,48 @@
#!/bin/bash
# Exports the stable "Tinycast Self-Signed" identity (cert + private key) as a base64 PKCS#12
# so CI can sign releases with the SAME identity every build. This is what keeps a user's
# Accessibility (TCC) grant alive across Homebrew updates: TCC pins the grant to the code
# signature's designated requirement, and a stable leaf cert keeps that requirement constant.
# Ad-hoc signing (CI's silent fallback) changes it every build → re-prompt on every update.
#
# Run once locally, then add the two printed values as GitHub Actions secrets on the
# abue-ammar/tinycast repo:
# SIGNING_P12_BASE64 the base64 blob written to build/signing-cert.p12.base64
# SIGNING_P12_PASSWORD the random password printed below
#
# macOS may pop a keychain dialog authorizing the export — approve it.
set -euo pipefail
IDENTITY="Tinycast Self-Signed"
KEYCHAIN="$HOME/Library/Keychains/login.keychain-db"
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
OUT_DIR="$ROOT/build"
P12="$OUT_DIR/signing-cert.p12"
P12_B64="$OUT_DIR/signing-cert.p12.base64"
if ! security find-identity -p codesigning "$KEYCHAIN" 2>/dev/null | grep -q "$IDENTITY"; then
echo "✗ Identity '$IDENTITY' not found. Run Packaging/dev-cert.sh first." >&2
exit 1
fi
mkdir -p "$OUT_DIR"
PASS="$(openssl rand -base64 24)"
echo "▸ Exporting '$IDENTITY' (approve the keychain dialog if prompted)…"
# -t identities exports the code-signing identity (cert + key) from the login keychain.
security export -k "$KEYCHAIN" -t identities -f pkcs12 -P "$PASS" -o "$P12"
base64 < "$P12" | tr -d '\n' > "$P12_B64"
rm -f "$P12"
echo
echo "✓ Wrote $P12_B64"
echo
echo "Add these two GitHub Actions secrets to abue-ammar/tinycast:"
echo " SIGNING_P12_BASE64 → contents of $P12_B64"
echo " SIGNING_P12_PASSWORD → $PASS"
echo
echo "With gh (authed as the repo owner):"
echo " gh secret set SIGNING_P12_BASE64 --repo abue-ammar/tinycast < \"$P12_B64\""
echo " gh secret set SIGNING_P12_PASSWORD --repo abue-ammar/tinycast --body '$PASS'"
echo
echo "Then delete $P12_B64 — it holds your private signing key."
+8
View File
@@ -101,10 +101,18 @@ PLIST
# Prefer a stable, self-signed identity so the Accessibility (TCC) grant survives rebuilds.
# Falls back to ad-hoc if it hasn't been created yet (run Packaging/dev-cert.sh once).
# STRICT_SIGN=1 refuses that fallback — released (CI) builds MUST use the stable identity,
# because ad-hoc gives a fresh cdhash each build and macOS drops the users' Accessibility
# grant on every update. Import the release cert (Packaging/export-signing-cert.sh) first.
SIGN_IDENTITY="Tinycast Self-Signed"
if security find-identity -p codesigning 2>/dev/null | grep -q "$SIGN_IDENTITY"; then
echo "▸ Signing with stable identity ($SIGN_IDENTITY)…"
SIGN_AS="$SIGN_IDENTITY"
elif [ "${STRICT_SIGN:-0}" = "1" ]; then
echo "✗ STRICT_SIGN=1 but stable identity '$SIGN_IDENTITY' is not in the keychain." >&2
echo " Refusing to ad-hoc sign a release: ad-hoc changes the code signature every build," >&2
echo " which breaks every user's Accessibility (TCC) grant on update." >&2
exit 1
else
echo "▸ Ad-hoc signing (run Packaging/dev-cert.sh once for a persistent Accessibility grant)…"
SIGN_AS="-"