fix(desktop): warn instead of swallowing ad-hoc codesign failures in ACP staging

codesign_if_darwin ran `codesign ... >/dev/null 2>&1 || true`, discarding
both the exit status and the error output. An unsigned nested Mach-O
therefore never surfaced at stage time — it surfaced much later as
Gatekeeper killing a subprocess mid-session, the exact failure mode the
nested-Mach-O signing scan exists to prevent, with nothing in the build
output to connect the two.

Keep the failure non-fatal (an unsignable Mach-O fragment that never
executes should not sink the stage, and release builds re-sign with the
real identity anyway) but make it visible: capture codesign's combined
output and, on non-zero exit, print a stderr warning naming the file
plus codesign's own diagnostics.

Addresses the swallowed-codesign-failure finding from the
bundling-series code review (review 2ed3d00d on b52a665a).

Verification:
- Forced failure (Mach-O in a read-only directory): warning with file
  path and codesign's "internal error in Code Signing subsystem" on
  stderr; script continues under set -e, exit 0.
- Notable non-failure probed while testing: codesign xattr-signs
  non-Mach-O and even corrupt-header files successfully, so the
  realistic trigger is filesystem/permission trouble, not file(1)
  false positives.
- Full prepare-acp-tools-resource.sh run: no warnings, both manifests
  written, all 5 staged Mach-Os pass codesign --verify.
- bash -n: syntax OK.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Matt Toohey <contact@matttoohey.com>
This commit is contained in:
Matt Toohey
2026-07-15 13:52:14 +10:00
co-authored by Claude Fable 5
parent ff2d3c2241
commit fbb9f1b94e
+10 -1
View File
@@ -69,10 +69,19 @@ harness_cli_manifest="$resource_root/harness-clis.json"
rm -f "$harness_cli_manifest"
harness_cli_entries=()
# Ad-hoc signing failure is a warning, not a hard stop: an unsignable Mach-O
# fragment that never executes should not sink the stage, and release builds
# re-sign everything with the real identity anyway. But it must be visible —
# a silently unsigned binary surfaces much later as Gatekeeper killing a
# subprocess mid-session, which is undiagnosable from build output.
codesign_if_darwin() {
local file="$1"
local output
if [[ "$(uname -s)" == "Darwin" ]] && command -v codesign >/dev/null 2>&1; then
codesign --force --sign - "$file" >/dev/null 2>&1 || true
if ! output="$(codesign --force --sign - "$file" 2>&1)"; then
echo "Warning: ad-hoc codesign failed for $file — Gatekeeper may kill it at spawn time:" >&2
echo "$output" >&2
fi
fi
}