Skip to content

Fix macOS release code signatures - #3794

Merged
csukuangfj merged 1 commit into
k2-fsa:masterfrom
LauraGPT:codex/macos-release-codesign
Jul 24, 2026
Merged

csukuangfj merged 1 commit into
k2-fsa:masterfrom
LauraGPT:codex/macos-release-codesign

Conversation

@LauraGPT

@LauraGPT LauraGPT commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • ad-hoc sign every Mach-O binary in each final macOS release tree
  • preserve existing signing metadata and verify each signature with codesign --verify --strict before archiving
  • cover universal2, x64, and arm64 full and lib-only packages

Verification

  • reproduced the invalid signature from the official v1.13.4 arm64 asset (b4e5d097...)
  • applied the exact workflow helper to the official assets: universal2 4/4 and arm64 33/33 Mach-O files passed strict verification
  • ran the exact sign/thin/sign path for x86_64 and arm64: 4/4 passed for each architecture, with no architecture mismatches
  • ran sherpa-onnx-version successfully from the repaired arm64 tree
  • actionlint and shellcheck passed for the changed workflow/helper

Fixes #3790

Summary by CodeRabbit

  • Bug Fixes
    • macOS release packages now include properly code-signed Mach-O binaries.
    • Added signature verification before release archives are created to improve installation and execution reliability.

@dosubot dosubot Bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Jul 23, 2026
@coderabbitai

coderabbitai Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 34a7bcba-408a-429d-9f56-7fdaff1e29d8

📥 Commits

Reviewing files that changed from the base of the PR and between a6ebe74 and a3e570a.

📒 Files selected for processing (1)
  • .github/workflows/macos.yaml

📝 Walkthrough

Walkthrough

The macOS release workflow adds recursive signing and strict verification for Mach-O files, then applies it to main, library, and per-architecture package directories before creating .tar.bz2 archives.

Changes

macOS artifact signing

Layer / File(s) Summary
Add Mach-O signing function
.github/workflows/macos.yaml
Defines sign_macos_tree() to recursively sign matching Mach-O files and verify their signatures.
Sign release trees before archiving
.github/workflows/macos.yaml
Invokes the signing function for main, library, and architecture-specific package trees before archive creation.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: fixing macOS release code signing.
Linked Issues check ✅ Passed The workflow now signs and verifies Mach-O binaries after packaging for all macOS release trees, addressing the invalid-signature issue in #3790.
Out of Scope Changes check ✅ Passed The PR stays focused on macOS release signing and verification; no unrelated code paths or features were added.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@csukuangfj csukuangfj left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for your contribution!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug][macOS arm64] v1.13.4 shared tarball contains libonnxruntime.1.27.0.dylib with an invalid code signature

2 participants