Skip to content

fix(mac): validate DMG output and ship ZIP fallback - #9

Closed
luolangaga wants to merge 1 commit into
mainfrom
codex/fix-corrupted-macos-package-issue
Closed

luolangaga wants to merge 1 commit into
mainfrom
codex/fix-corrupted-macos-package-issue

Conversation

@luolangaga

Copy link
Copy Markdown
Owner

Motivation

  • CI-built macOS installers were still sometimes delivered in a state that Gatekeeper treats as “已损坏,无法打开”, so signing configuration alone didn't prevent bad artifacts from being published.
  • The pipeline needs runtime artifact integrity checks and a safer fallback distribution format to avoid shipping corrupted DMG files.

Description

  • Added a Verify generated macOS installers are valid step in .github/workflows/build-mac.yml that lists dist, finds the produced *.dmg, runs hdiutil verify on the DMG, and runs unzip -t on a produced *.zip if present.
  • Updated mac build environment handling by setting CSC_IDENTITY_AUTO_DISCOVERY to avoid entering a partially-signed broken state when signing secrets are absent, and preserved existing signing/notarization env vars (CSC_LINK, CSC_KEY_PASSWORD, APPLE_ID, APPLE_APP_SPECIFIC_PASSWORD, APPLE_TEAM_ID).
  • Extended artifact upload and release publishing to include both *.dmg and *.zip as upload/Release files to provide a ZIP fallback for distribution.
  • Updated package.json mac build target to ["dmg","zip"] and added mac entitlements files references (assets/macos/entitlements.mac.plist and assets/macos/entitlements.mac.inherit.plist) to ensure CI produces the ZIP fallback and proper entitlements are applied.

Testing

  • Validated package.json is parseable with node -e "JSON.parse(require('fs').readFileSync('package.json','utf8'))", which succeeded.
  • Ran YAML parse check ruby -e "require 'yaml'; YAML.load_file('.github/workflows/build-mac.yml')", which succeeded.
  • Verified diffs passed git diff --check style checks, which succeeded.
  • Note: actual macOS build/sign/notarize and hdiutil verification must be validated on GitHub Actions macOS runners; local environment did not execute a full macOS build in this change.

Codex Task

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant