| | |
| | | # Optional environment: |
| | | # PRIVATEVOICE_SIGNING_KEYCHAIN |
| | | # PRIVATEVOICE_APPSTORE_MIN_SYSTEM_VERSION (default: 13.4) |
| | | # PRIVATEVOICE_MACAPPSTORE_BUILD_ROOT (default: build/macappstore) |
| | | # |
| | | # Usage: |
| | | # cd privatevoice.src |
| | |
| | | |
| | | SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" |
| | | PROJECT_DIR="$(cd "$SCRIPT_DIR/.." && pwd)" |
| | | MACAPPSTORE_BUILD_ROOT="${PRIVATEVOICE_MACAPPSTORE_BUILD_ROOT:-$PROJECT_DIR/build/macappstore}" |
| | | |
| | | INFO_PLIST="$PROJECT_DIR/build/darwin/Info.plist" |
| | | BASE_ENTITLEMENTS="$PROJECT_DIR/build/darwin/entitlements-appstore.plist" |
| | |
| | | ;; |
| | | esac |
| | | |
| | | BUILD_DIR="$PROJECT_DIR/build/macappstore/$OUT_ARCH" |
| | | BUILD_DIR="$MACAPPSTORE_BUILD_ROOT/$OUT_ARCH" |
| | | APP_BUNDLE="$BUILD_DIR/$APP_NAME.app" |
| | | PKG_PATH="$BUILD_DIR/PrivateVoice-Dictation-$VERSION-build$BUILD_ID-$OUT_ARCH-macappstore.pkg" |
| | | SHERPA_LIB_DIR="$GOMODCACHE/github.com/k2-fsa/sherpa-onnx-go-macos@$SHERPA_MACOS_MODULE_VERSION/lib/$SHERPA_ARCH" |
| | |
| | | strip_extended_attributes() { |
| | | local item="$1" |
| | | if command -v xattr >/dev/null; then |
| | | xattr -cr "$item" 2>/dev/null || true |
| | | chmod -R u+rwX "$item" |
| | | xattr -cr "$item" |
| | | fi |
| | | } |
| | | |
| | |
| | | [[ -z "$found" ]] || fail "com.apple.quarantine attributes remain under $item: |
| | | $found" |
| | | fi |
| | | } |
| | | |
| | | remove_appledouble_files() { |
| | | local item="$1" |
| | | find "$item" \( -name '._*' -o -name '.DS_Store' \) -delete |
| | | } |
| | | |
| | | assert_no_appledouble_files() { |
| | | local item="$1" |
| | | local found |
| | | found="$(find "$item" \( -name '._*' -o -name '.DS_Store' \) -print | head -n 20 || true)" |
| | | [[ -z "$found" ]] || fail "AppleDouble or Finder metadata files remain under $item: |
| | | $found" |
| | | } |
| | | |
| | | assert_pkg_no_quarantine_attributes() { |
| | | local pkg="$1" |
| | | local expanded |
| | | local found |
| | | expanded="$(mktemp -d)" |
| | | pkgutil --expand-full "$pkg" "$expanded/pkg" >/dev/null |
| | | found="$(xattr -lr "$expanded/pkg" 2>/dev/null | grep -F "com.apple.quarantine" | head -n 20 || true)" |
| | | rm -rf "$expanded" |
| | | [[ -z "$found" ]] || fail "com.apple.quarantine attributes remain in package: |
| | | $found" |
| | | } |
| | | |
| | | TARGET_ARCH="${1:-$(uname -m)}" |
| | |
| | | |
| | | step "Removing extended attributes from app bundle" |
| | | strip_extended_attributes "$APP_BUNDLE" |
| | | remove_appledouble_files "$APP_BUNDLE" |
| | | assert_no_quarantine_attributes "$APP_BUNDLE" |
| | | assert_no_appledouble_files "$APP_BUNDLE" |
| | | |
| | | step "Fixing rpaths" |
| | | install_name_tool -add_rpath @executable_path/../Frameworks \ |
| | |
| | | |
| | | step "Removing extended attributes after signing" |
| | | strip_extended_attributes "$APP_BUNDLE" |
| | | remove_appledouble_files "$APP_BUNDLE" |
| | | assert_no_quarantine_attributes "$APP_BUNDLE" |
| | | assert_no_appledouble_files "$APP_BUNDLE" |
| | | |
| | | step "Verifying app signature and entitlements" |
| | | codesign -vvv --deep --strict "$APP_BUNDLE" |
| | |
| | | fail "Signed app application-identifier mismatch: signed has $SIGNED_APP_IDENTIFIER, profile has $PROFILE_APP_IDENTIFIER" |
| | | |
| | | step "Creating signed installer package" |
| | | productbuild \ |
| | | COPYFILE_DISABLE=1 productbuild \ |
| | | --sign "$APPSTORE_INSTALLER_IDENTITY" \ |
| | | --component "$APP_BUNDLE" /Applications \ |
| | | "$PKG_PATH" |
| | | |
| | | step "Verifying installer package signature" |
| | | pkgutil --check-signature "$PKG_PATH" |
| | | assert_pkg_no_quarantine_attributes "$PKG_PATH" |
| | | |
| | | step "Mac App Store package complete" |
| | | echo " App: $APP_BUNDLE" |