handling files when stages and dirty at once
This commit is contained in:
44
build/adhoc-sign.cjs
Normal file
44
build/adhoc-sign.cjs
Normal file
@@ -0,0 +1,44 @@
|
||||
// Ad-hoc sign the macOS bundle after electron-builder packs it.
|
||||
//
|
||||
// Why this exists: `mac.identity: null` tells electron-builder to skip signing
|
||||
// altogether. The .app then keeps only the linker signature that Apple put on
|
||||
// the prebuilt Electron binary. That signature says `Identifier=Electron`,
|
||||
// seals no resources, and does not bind our Info.plist. macOS reads a bundle
|
||||
// like that as tampered-with and shows "Malware Blocked and Moved to Trash".
|
||||
//
|
||||
// A real ad-hoc signature over the whole bundle fixes it. The app stays
|
||||
// unsigned in the Developer ID sense (no notarization, so a *downloaded* copy
|
||||
// still needs the quarantine flag cleared), but it is no longer flagged as
|
||||
// malware and runs fine locally.
|
||||
//
|
||||
// Replace this with a Developer ID identity + notarization when the app ships.
|
||||
const { execFileSync } = require('node:child_process')
|
||||
const path = require('node:path')
|
||||
|
||||
exports.default = async function adhocSign(context) {
|
||||
if (context.electronPlatformName !== 'darwin') return
|
||||
|
||||
const appName = context.packager.appInfo.productFilename
|
||||
const appPath = path.join(context.appOutDir, `${appName}.app`)
|
||||
const entitlements = path.join(__dirname, 'entitlements.mac.plist')
|
||||
|
||||
console.log(` • ad-hoc signing ${appPath}`)
|
||||
execFileSync(
|
||||
'codesign',
|
||||
[
|
||||
'--force',
|
||||
'--deep',
|
||||
'--sign',
|
||||
'-',
|
||||
'--options',
|
||||
'runtime',
|
||||
'--entitlements',
|
||||
entitlements,
|
||||
appPath
|
||||
],
|
||||
{ stdio: 'inherit' }
|
||||
)
|
||||
|
||||
// Fail the build rather than ship a bundle macOS will quarantine again.
|
||||
execFileSync('codesign', ['--verify', '--deep', '--strict', appPath], { stdio: 'inherit' })
|
||||
}
|
||||
17
build/entitlements.mac.plist
Normal file
17
build/entitlements.mac.plist
Normal file
@@ -0,0 +1,17 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<!-- V8 compiles JavaScript at runtime. -->
|
||||
<key>com.apple.security.cs.allow-jit</key>
|
||||
<true/>
|
||||
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
|
||||
<true/>
|
||||
<!-- Electron sets dyld vars when it spawns its own helpers. -->
|
||||
<key>com.apple.security.cs.allow-dyld-environment-variables</key>
|
||||
<true/>
|
||||
<!-- node-pty is a native addon signed with a different (ad-hoc) identity. -->
|
||||
<key>com.apple.security.cs.disable-library-validation</key>
|
||||
<true/>
|
||||
</dict>
|
||||
</plist>
|
||||
Reference in New Issue
Block a user