Repository navigation
Fix codesign: path filter excluded all files inside outer .app #2680
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -423,7 +423,7 @@ jobs: | |
| if file "$f" | grep -qE 'Mach-O'; then | ||
| /usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f" | ||
| fi | ||
| done < <(find "$DIR" -type f -not -path '*.app/*' -print0) | ||
| done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \)) | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Pass 2 prune misses
|
||
|
|
||
| # Pass 3: .framework, .plugin, .appex bundles (deepest-first) | ||
| while IFS= read -r -d '' bundle; do | ||
|
|
||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -284,7 +284,7 @@ jobs: | |||||
| if file "$f" | grep -qE 'Mach-O'; then | ||||||
| /usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$f" | ||||||
| fi | ||||||
| done < <(find "$DIR" -type f -not -path '*.app/*' -print0) | ||||||
| done < <(find "$DIR" \( -type d -name '*.app' -prune \) -o \( -type f -print0 \)) | ||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Same observation as
Suggested change
|
||||||
|
|
||||||
| # Pass 3: .framework, .plugin, .appex bundles (deepest-first) | ||||||
| while IFS= read -r -d '' bundle; do | ||||||
|
|
||||||


There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
.xpccontents not pruned in Pass 2Pass 1 signs
.xpcbundles as whole bundles (line 419), but Pass 2 only prunes.appdirectories. If any.xpcbundles sit directly insideFrameworks(not nested withinUpdater.app), Pass 2 would re-sign individual files inside them after Pass 1 already committed a bundle signature — invalidating it. This isn't a regression from the original code, and the--verify --deep --strictcheck on line 435 would catch any resulting invalidity. For correctness, consider also pruning.xpcdirs: