mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
fix(desktop): warn instead of swallowing ad-hoc codesign failures in ACP staging
codesign_if_darwin ran `codesign ... >/dev/null 2>&1 || true`, discarding both the exit status and the error output. An unsigned nested Mach-O therefore never surfaced at stage time — it surfaced much later as Gatekeeper killing a subprocess mid-session, the exact failure mode the nested-Mach-O signing scan exists to prevent, with nothing in the build output to connect the two. Keep the failure non-fatal (an unsignable Mach-O fragment that never executes should not sink the stage, and release builds re-sign with the real identity anyway) but make it visible: capture codesign's combined output and, on non-zero exit, print a stderr warning naming the file plus codesign's own diagnostics. Addresses the swallowed-codesign-failure finding from the bundling-series code review (review 2ed3d00d on b52a665a). Verification: - Forced failure (Mach-O in a read-only directory): warning with file path and codesign's "internal error in Code Signing subsystem" on stderr; script continues under set -e, exit 0. - Notable non-failure probed while testing: codesign xattr-signs non-Mach-O and even corrupt-header files successfully, so the realistic trigger is filesystem/permission trouble, not file(1) false positives. - Full prepare-acp-tools-resource.sh run: no warnings, both manifests written, all 5 staged Mach-Os pass codesign --verify. - bash -n: syntax OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Matt Toohey <contact@matttoohey.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
ff2d3c2241
commit
fbb9f1b94e
@@ -69,10 +69,19 @@ harness_cli_manifest="$resource_root/harness-clis.json"
|
||||
rm -f "$harness_cli_manifest"
|
||||
harness_cli_entries=()
|
||||
|
||||
# Ad-hoc signing failure is a warning, not a hard stop: an unsignable Mach-O
|
||||
# fragment that never executes should not sink the stage, and release builds
|
||||
# re-sign everything with the real identity anyway. But it must be visible —
|
||||
# a silently unsigned binary surfaces much later as Gatekeeper killing a
|
||||
# subprocess mid-session, which is undiagnosable from build output.
|
||||
codesign_if_darwin() {
|
||||
local file="$1"
|
||||
local output
|
||||
if [[ "$(uname -s)" == "Darwin" ]] && command -v codesign >/dev/null 2>&1; then
|
||||
codesign --force --sign - "$file" >/dev/null 2>&1 || true
|
||||
if ! output="$(codesign --force --sign - "$file" 2>&1)"; then
|
||||
echo "Warning: ad-hoc codesign failed for $file — Gatekeeper may kill it at spawn time:" >&2
|
||||
echo "$output" >&2
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user