mirror of
https://github.com/abue-ammar/tinycast.git
synced 2026-10-02 08:14:38 +08:00
fixing sign
This commit is contained in:
@@ -60,6 +60,35 @@ jobs:
|
||||
echo "prerelease=${PRERELEASE}"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
# Import the stable self-signed identity so every release is signed with the SAME cert.
|
||||
# This is what keeps users' Accessibility (TCC) grant alive across updates — without it
|
||||
# make-app.sh ad-hoc signs, changing the code signature (and breaking the grant) each build.
|
||||
# Generate the secrets with Packaging/export-signing-cert.sh.
|
||||
- name: Import signing certificate
|
||||
id: signing
|
||||
env:
|
||||
P12_BASE64: ${{ secrets.SIGNING_P12_BASE64 }}
|
||||
P12_PASSWORD: ${{ secrets.SIGNING_P12_PASSWORD }}
|
||||
run: |
|
||||
if [ -z "${P12_BASE64}" ]; then
|
||||
echo "::warning::SIGNING_P12_BASE64 not set — falling back to ad-hoc signing. Users' Accessibility grant will NOT survive updates until this secret is added (see Packaging/export-signing-cert.sh)."
|
||||
echo "strict=0" >> "$GITHUB_OUTPUT"
|
||||
exit 0
|
||||
fi
|
||||
KEYCHAIN="$RUNNER_TEMP/signing.keychain-db"
|
||||
KPW="$(openssl rand -base64 24)"
|
||||
echo "${P12_BASE64}" | base64 --decode > "$RUNNER_TEMP/cert.p12"
|
||||
security create-keychain -p "$KPW" "$KEYCHAIN"
|
||||
security set-keychain-settings -lut 21600 "$KEYCHAIN"
|
||||
security unlock-keychain -p "$KPW" "$KEYCHAIN"
|
||||
security import "$RUNNER_TEMP/cert.p12" -k "$KEYCHAIN" -P "${P12_PASSWORD}" -A -T /usr/bin/codesign
|
||||
# Let codesign use the key without an interactive prompt.
|
||||
security set-key-partition-list -S apple-tool:,apple: -s -k "$KPW" "$KEYCHAIN" >/dev/null
|
||||
# Prepend to the search list so `security find-identity` (in make-app.sh) sees it.
|
||||
security list-keychains -d user -s "$KEYCHAIN" $(security list-keychains -d user | sed 's/"//g')
|
||||
rm -f "$RUNNER_TEMP/cert.p12"
|
||||
echo "strict=1" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Build DMG
|
||||
env:
|
||||
VERSION: ${{ steps.meta.outputs.full_version }}
|
||||
@@ -67,6 +96,7 @@ jobs:
|
||||
BUNDLE_ID: ${{ steps.meta.outputs.bundle_id }}
|
||||
BUILD_NUMBER: ${{ github.run_number }}
|
||||
DMG_BASE: Tinycast
|
||||
STRICT_SIGN: ${{ steps.signing.outputs.strict }}
|
||||
run: Packaging/build-dmg.sh
|
||||
|
||||
- uses: actions/upload-artifact@v7
|
||||
@@ -91,11 +121,14 @@ jobs:
|
||||
**Bundle ID:** \`${{ steps.meta.outputs.bundle_id }}\`
|
||||
Built from ${{ github.sha }}.
|
||||
|
||||
This build is **not signed with an Apple Developer ID and not notarized** (this project has no paid Apple account). macOS will refuse to open it until you clear the quarantine flag:
|
||||
**Recommended:** install via Homebrew — it clears the quarantine flag automatically on every install and update, so there's nothing to run by hand:
|
||||
\`\`\`sh
|
||||
brew install --cask abue-ammar/tinycast/${{ steps.meta.outputs.cask_name }}
|
||||
\`\`\`
|
||||
This build is signed with a stable self-signed identity (**not** an Apple Developer ID, and not notarized — this project has no paid Apple account). If you download the DMG directly instead of using Homebrew, macOS will refuse to open it until you clear the quarantine flag once:
|
||||
\`\`\`sh
|
||||
xattr -dr com.apple.quarantine \"/Applications/${{ steps.meta.outputs.display_name }}.app\"
|
||||
\`\`\`
|
||||
Or install via Homebrew: \`brew install --cask abue-ammar/tinycast/${{ steps.meta.outputs.cask_name }}\`" \
|
||||
\`\`\`" \
|
||||
$PRERELEASE_FLAG
|
||||
|
||||
- name: Update Homebrew cask
|
||||
|
||||
Executable
+48
@@ -0,0 +1,48 @@
|
||||
#!/bin/bash
|
||||
# Exports the stable "Tinycast Self-Signed" identity (cert + private key) as a base64 PKCS#12
|
||||
# so CI can sign releases with the SAME identity every build. This is what keeps a user's
|
||||
# Accessibility (TCC) grant alive across Homebrew updates: TCC pins the grant to the code
|
||||
# signature's designated requirement, and a stable leaf cert keeps that requirement constant.
|
||||
# Ad-hoc signing (CI's silent fallback) changes it every build → re-prompt on every update.
|
||||
#
|
||||
# Run once locally, then add the two printed values as GitHub Actions secrets on the
|
||||
# abue-ammar/tinycast repo:
|
||||
# SIGNING_P12_BASE64 the base64 blob written to build/signing-cert.p12.base64
|
||||
# SIGNING_P12_PASSWORD the random password printed below
|
||||
#
|
||||
# macOS may pop a keychain dialog authorizing the export — approve it.
|
||||
set -euo pipefail
|
||||
|
||||
IDENTITY="Tinycast Self-Signed"
|
||||
KEYCHAIN="$HOME/Library/Keychains/login.keychain-db"
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
||||
OUT_DIR="$ROOT/build"
|
||||
P12="$OUT_DIR/signing-cert.p12"
|
||||
P12_B64="$OUT_DIR/signing-cert.p12.base64"
|
||||
|
||||
if ! security find-identity -p codesigning "$KEYCHAIN" 2>/dev/null | grep -q "$IDENTITY"; then
|
||||
echo "✗ Identity '$IDENTITY' not found. Run Packaging/dev-cert.sh first." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p "$OUT_DIR"
|
||||
PASS="$(openssl rand -base64 24)"
|
||||
|
||||
echo "▸ Exporting '$IDENTITY' (approve the keychain dialog if prompted)…"
|
||||
# -t identities exports the code-signing identity (cert + key) from the login keychain.
|
||||
security export -k "$KEYCHAIN" -t identities -f pkcs12 -P "$PASS" -o "$P12"
|
||||
base64 < "$P12" | tr -d '\n' > "$P12_B64"
|
||||
rm -f "$P12"
|
||||
|
||||
echo
|
||||
echo "✓ Wrote $P12_B64"
|
||||
echo
|
||||
echo "Add these two GitHub Actions secrets to abue-ammar/tinycast:"
|
||||
echo " SIGNING_P12_BASE64 → contents of $P12_B64"
|
||||
echo " SIGNING_P12_PASSWORD → $PASS"
|
||||
echo
|
||||
echo "With gh (authed as the repo owner):"
|
||||
echo " gh secret set SIGNING_P12_BASE64 --repo abue-ammar/tinycast < \"$P12_B64\""
|
||||
echo " gh secret set SIGNING_P12_PASSWORD --repo abue-ammar/tinycast --body '$PASS'"
|
||||
echo
|
||||
echo "Then delete $P12_B64 — it holds your private signing key."
|
||||
@@ -101,10 +101,18 @@ PLIST
|
||||
|
||||
# Prefer a stable, self-signed identity so the Accessibility (TCC) grant survives rebuilds.
|
||||
# Falls back to ad-hoc if it hasn't been created yet (run Packaging/dev-cert.sh once).
|
||||
# STRICT_SIGN=1 refuses that fallback — released (CI) builds MUST use the stable identity,
|
||||
# because ad-hoc gives a fresh cdhash each build and macOS drops the users' Accessibility
|
||||
# grant on every update. Import the release cert (Packaging/export-signing-cert.sh) first.
|
||||
SIGN_IDENTITY="Tinycast Self-Signed"
|
||||
if security find-identity -p codesigning 2>/dev/null | grep -q "$SIGN_IDENTITY"; then
|
||||
echo "▸ Signing with stable identity ($SIGN_IDENTITY)…"
|
||||
SIGN_AS="$SIGN_IDENTITY"
|
||||
elif [ "${STRICT_SIGN:-0}" = "1" ]; then
|
||||
echo "✗ STRICT_SIGN=1 but stable identity '$SIGN_IDENTITY' is not in the keychain." >&2
|
||||
echo " Refusing to ad-hoc sign a release: ad-hoc changes the code signature every build," >&2
|
||||
echo " which breaks every user's Accessibility (TCC) grant on update." >&2
|
||||
exit 1
|
||||
else
|
||||
echo "▸ Ad-hoc signing (run Packaging/dev-cert.sh once for a persistent Accessibility grant)…"
|
||||
SIGN_AS="-"
|
||||
|
||||
Reference in New Issue
Block a user