Skip to content

ci: fix macOS codesign "In subcomponent" failure in release signing - #24

Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
copilot/fix-ci-run-35154262459
Sep 16, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
copilot/fix-ci-run-35154262459

Conversation

@mamoreau-devolutions

Copy link
Copy Markdown
Contributor

Failure

Build Terminal run 35154262459 (workflow_dispatch release) failed in both macOS sign and notarize jobs at the Sign, package, and notarize step:

Devolutions Terminal.app/Contents/MacOS/Devolutions.Terminal: code object is not signed at all
In subcomponent: .../Contents/MacOS/dt.runtimeconfig.json

Note: the sign jobs only run on workflow_dispatch, which is why pushes on the same commit were green — this was the first real exercise of the signing path.

Root cause

scripts/Sign-MacOsPackage.ps1 signed every Mach-O file in the bundle individually, including the bundle's main executable (Contents/MacOS/Devolutions.Terminal). When codesign is pointed at a bundle's main executable as a standalone file, it operates in bundle context and requires every sibling in Contents/MacOS/ to already be signed nested code. dt.runtimeconfig.json is a data file, not signable code, so codesign bails out.

Fix

Skip the main executable (resolved from CFBundleExecutable in the bundle's Info.plist) during per-file signing. The final bundle-level codesign — which the script already performs with --entitlements — signs the main executable and applies the entitlements to it. This is Apple's recommended inside-out flow (sign nested code, then the bundle; never the main executable standalone).

Validation

  • PowerShell parser check passes (same check Test-MacOsPackagingMetadata.ps1 runs in CI).
  • Full validation requires a signed run: re-trigger the Build Terminal workflow_dispatch after merge.

Sign-MacOsPackage.ps1 signed every Mach-O file individually, including the
bundle's main executable (Contents/MacOS/Devolutions.Terminal). Signing a
bundle's main executable as a standalone file makes codesign operate in
bundle context and require every sibling file in Contents/MacOS (e.g.
dt.runtimeconfig.json, which is not code) to already carry a signature,
failing with 'code object is not signed at all / In subcomponent: ...'.

Skip the main executable (resolved from CFBundleExecutable in Info.plist)
during per-file signing; signing the bundle itself at the end signs the
main executable and applies the entitlements to it, which is Apple's
recommended flow.
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit 81ef175 into master Sep 16, 2026
12 checks passed
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) deleted the copilot/fix-ci-run-35154262459 branch September 16, 2026 22:08

This branch was successfully deployed

1 active deployment
publish-dry-run — 00fe605e Deployed Sep 16, 2026 by mamoreau-devolutions via MSI packages #142
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant