Skip to content

Harden macOS code signing and notarization - #25

Merged
Marc-André Moreau (mamoreau-devolutions) merged 3 commits into
masterfrom
copilot/fix-macos-code-signing
Sep 17, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 3 commits into
masterfrom
copilot/fix-macos-code-signing

Conversation

@mamoreau-devolutions

Copy link
Copy Markdown
Contributor

Root cause

The repeated production failures were caused by invalid bundle layout, not just signing order. The NativeAOT publish left dt.runtimeconfig.json in Contents/MacOS; Developer ID bundle signing treats regular files there as nested code and rejects the JSON sidecar. Earlier fixes moved notice files and skipped the main executable, but did not remove the remaining non-code file.

The next latent failure was also addressed: notarytool accepts archives and disk images, not a raw .app directory.

Changes

  • remove NativeAOT runtime-config sidecars from the staged app and reject future non-Mach-O files in Contents/MacOS
  • add a macOS regression test that reproduces the original In subcomponent: ...runtimeconfig.json failure and verifies the corrected bundle
  • sign auxiliary Mach-O files in isolation while preserving their identifiers
  • verify every signature's Team ID, secure timestamp, and Hardened Runtime metadata
  • submit app bundles for notarization through temporary ZIPs, require an Accepted response, staple tickets, and verify Gatekeeper acceptance for both apps and DMGs
  • resolve the imported Developer ID identity instead of relying on a hard-coded display name, fail real signing runs on missing secrets, and clean up the temporary keychain

Validation

A production-environment signed dry run completed successfully end to end: https://github.com/Devolutions/devolutions-terminal/actions/runs/35164984505

  • both osx-arm64 and osx-x64 app submissions: Accepted, stapled, source=Notarized Developer ID
  • both signed DMG submissions: Accepted, stapled, source=Notarized Developer ID
  • macOS package validation passed for both architectures
  • all build, test, packaging, signing, and final dry-run release-staging jobs passed
  • final release artifact uploaded successfully

@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit cf48310 into master Sep 17, 2026
84 of 93 checks passed
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) deleted the copilot/fix-macos-code-signing branch September 17, 2026 00:59

This branch had an error being deployed

1 failed and 2 active deployments
publish-dry-run — 60029950 Deployed Sep 17, 2026 by mamoreau-devolutions via MSI packages #152
publish-prod — 60029950 Deployed Sep 17, 2026 by mamoreau-devolutions via Publish GitHub release #151
publish-test — 60029950 Deployed Sep 16, 2026 by mamoreau-devolutions via macOS sign and notarize osx-arm64 #150
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant