Skip to content

ci: fix macOS codesign failure and nuget-publish skip on workflow_dispatch - #22

Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
copilot/fix-macos-sign-nuget-publish
Sep 16, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
copilot/fix-macos-sign-nuget-publish

Conversation

@mamoreau-devolutions

Copy link
Copy Markdown
Contributor

What

Fixes two failures from run #35150675662 (Build Terminal, manual workflow_dispatch on master):

1. macOS sign and notarize osx-x64 / osx-arm64 failed

.../Devolutions Terminal.app/Contents/MacOS/Devolutions.Terminal: code object is not signed at all
In subcomponent: .../Devolutions Terminal.app/Contents/MacOS/THIRD-PARTY-NOTICES-GHOSTTY.txt
Exception: 'codesign ... Devolutions.Terminal' failed with exit code 1.

Stage-MacOsApp.ps1 copied the notices files into Contents/Resources but also left a duplicate copy sitting in Contents/MacOS, alongside the main executable. codesign, when given the path to the bundle's main executable, resolves and signs the whole app bundle, and treats stray non-executable files left in Contents/MacOS (a directory that's supposed to contain only executables/helper tools) as nested code requiring their own signature — which a plain .txt file obviously can't have, so signing failed.

Fix: Move-Item instead of Copy-Item for the notices files, so they only exist under Contents/Resources (matching Apple's bundle layout conventions). Updated Test-MacOsPackage.ps1's required-file check to match the new location.

2. Publish Devolutions.Terminal.Control to nuget.org was skipped

Its condition was:

if: ${{ needs.release-metadata.outputs.dry_run != 'true' && startsWith(github.ref, 'refs/tags/') }}

This run was a manual workflow_dispatch on master, so github.ref is refs/heads/master, never refs/tags/* — the job is unconditionally skipped for every workflow_dispatch run, dry-run or not. Every other release-type job (macos-sign, release) already uses the pattern github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/') to allow both triggers.

Fix: align nuget-publish's condition with that same pattern, so it runs for non-dry-run workflow_dispatch runs too, not just tag pushes.

Testing

  • python -c "import yaml; yaml.safe_load(open('.github/workflows/build-terminal.yml'))" — YAML parses.
  • PowerShell Parser.ParseFile on both edited scripts — no syntax errors.
  • No macOS runner available locally to execute the actual codesign flow; the fix is scoped to removing the specific file layout that produced the documented codesign error and is consistent with the general macOS bundle-layout rule that Contents/MacOS should only contain executables.

…patch

- Stage-MacOsApp.ps1: move (not copy) the third-party notices files into
  Contents/Resources instead of leaving duplicates in Contents/MacOS.
  Apple's codesign treats stray non-executable files sitting next to the
  main executable in Contents/MacOS as nested code requiring their own
  signature, which made 'codesign ... Devolutions.Terminal' fail with
  'code object is not signed at all / In subcomponent: ...GHOSTTY.txt'
  during the macOS sign and notarize jobs.
- Test-MacOsPackage.ps1: updated to expect the notices files under
  Contents/Resources to match the new layout.
- build-terminal.yml: align the nuget-publish job's if condition with
  the other release jobs (macos-sign, release) so it also runs on
  workflow_dispatch, not only on tag pushes. Previously it was skipped
  on every workflow_dispatch run (as seen in run 35150675662) even when
  dry_run was false, because github.ref never starts with refs/tags/
  for a workflow_dispatch trigered from a branch.
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit 924f627 into master Sep 16, 2026
12 checks passed
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) deleted the copilot/fix-macos-sign-nuget-publish branch September 16, 2026 21:29

This branch was successfully deployed

1 active deployment
publish-dry-run — a533eb28 Deployed Sep 16, 2026 by mamoreau-devolutions via MSI packages #133
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant