Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -423,7 +423,7 @@ jobs:
if file "$f" | grep -qE 'Mach-O'; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f"
fi
done < <(find "$DIR" -type f -not -path '*.app/*' -print0)
done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 .xpc contents not pruned in Pass 2

Pass 1 signs .xpc bundles as whole bundles (line 419), but Pass 2 only prunes .app directories. If any .xpc bundles sit directly inside Frameworks (not nested within Updater.app), Pass 2 would re-sign individual files inside them after Pass 1 already committed a bundle signature — invalidating it. This isn't a regression from the original code, and the --verify --deep --strict check on line 435 would catch any resulting invalidity. For correctness, consider also pruning .xpc dirs:

Suggested change
done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \))
done < <(find "$DIR" \( -type d \( -name '*.app' -o -name '*.xpc' \) -prune \) -o \( -type f -print0 \))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pass 2 prune misses .xpc bundles signed in Pass 1

High Severity

Pass 1 signs both *.app and *.xpc bundles, but the new find in Pass 2 only prunes *.app directories. Since Sparkle 2.x bundles Installer.xpc and Downloader.xpc inside the framework (each containing a Mach-O executable), Pass 2 will descend into those .xpc bundles and re-sign their internal executables individually. This invalidates the .xpc bundle signatures created by Pass 1, and Pass 3 (which signs *.framework) does not re-sign nested .xpc bundles — causing codesign --verify --deep --strict to fail. The -prune clause needs to include -name '*.xpc' to match what Pass 1 handles.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e2d5cff. Configure here.


# Pass 3: .framework, .plugin, .appex bundles (deepest-first)
while IFS= read -r -d '' bundle; do
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -284,7 +284,7 @@ jobs:
if file "$f" | grep -qE 'Mach-O'; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f"
fi
done < <(find "$DIR" -type f -not -path '*.app/*' -print0)
done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Same .xpc pruning gap as in nightly.yml

Same observation as nightly.yml line 426: Pass 2 prunes only .app directories, leaving .xpc bundle contents reachable. Consider adding .xpc to the prune list:

Suggested change
done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \))
done < <(find "$DIR" \( -type d \( -name '*.app' -o -name '*.xpc' \) -prune \) -o \( -type f -print0 \))


# Pass 3: .framework, .plugin, .appex bundles (deepest-first)
while IFS= read -r -d '' bundle; do
Expand Down
Loading