From e2d5cff17ed9fa5d528195a711b24d0d1fb07f9c Mon Sep 17 00:00:00 2001 From: austinpower1258 Date: Tue, 7 Apr 2026 02:56:51 -0700 Subject: [PATCH] Fix codesign: -path '*.app/*' excluded everything inside outer .app The find filter `-not -path '*.app/*'` matched the OUTER app bundle (cmux NIGHTLY.app/) in every file's full path, so Pass 2 found zero files and Autoupdate was never signed. Fix: use `-prune` on nested .app directories instead. This skips Updater.app's contents (already signed in Pass 1) while still finding standalone executables like Autoupdate. Co-Authored-By: Claude Opus 4.6 --- .github/workflows/nightly.yml | 2 +- .github/workflows/release.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 66f9771b01b..5bca097ee42 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -423,7 +423,7 @@ jobs: if file "$f" | grep -qE 'Mach-O'; then /usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f" fi - done < <(find "$DIR" -type f -not -path '*.app/*' -print0) + done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \)) # Pass 3: .framework, .plugin, .appex bundles (deepest-first) while IFS= read -r -d '' bundle; do diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ee610a46d46..53987af51d2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -284,7 +284,7 @@ jobs: if file "$f" | grep -qE 'Mach-O'; then /usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f" fi - done < <(find "$DIR" -type f -not -path '*.app/*' -print0) + done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \)) # Pass 3: .framework, .plugin, .appex bundles (deepest-first) while IFS= read -r -d '' bundle; do