From 2a151b65f7101405012f0b31a6fdca2d4b0521ed Mon Sep 17 00:00:00 2001 From: Anthony Stirling Date: Wed, 20 May 2026 09:08:37 +0100 Subject: [PATCH] Move JPDFium dylib signing step AFTER cert import MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit My first placement put the sign-jpdfium-dylibs-in-bootjar step at the wrong point in the workflow: BEFORE the "Verify Certificate" step that sets APPLE_SIGNING_IDENTITY in GITHUB_ENV. So the gate `if: ... && env.APPLE_SIGNING_IDENTITY != ''` always evaluated to false and the step silently skipped, leaving the dylibs unsigned and notarytool still rejecting the .app. Move it to right after Verify Certificate (which sets the env var from the keychain identity). Also switch the gate to checking env.APPLE_CERTIFICATE (the secret that's set at job level and available from step 1) rather than env.APPLE_SIGNING_IDENTITY (set mid-workflow via GITHUB_ENV) — the latter is fine in `run:` blocks but flaky in `if:` evaluation depending on GH Actions evaluation timing. --- .github/workflows/tauri-build.yml | 26 +++++++++++--------------- 1 file changed, 11 insertions(+), 15 deletions(-) diff --git a/.github/workflows/tauri-build.yml b/.github/workflows/tauri-build.yml index 56ac939ffb..d2cb541795 100644 --- a/.github/workflows/tauri-build.yml +++ b/.github/workflows/tauri-build.yml @@ -158,21 +158,6 @@ jobs: MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }} DISABLE_ADDITIONAL_FEATURES: true - - name: Sign JPDFium dylibs inside bootJar (macOS only) - # JPDFium's publish workflow has no Apple Developer credentials, so - # the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned. - # Apple's notarytool walks into nested .jars inside the .app and - # rejects unsigned binaries. Tauri's own codesign walk doesn't open - # .jars, so we have to re-sign them here, between bootJar build and - # tauri-action, using this build's Developer ID identity. The script - # is non-fatal: if APPLE_SIGNING_IDENTITY isn't set (e.g. PR build - # from a fork) it exits 0 and notarytool will continue to report - # the unsigned-binary error. - if: matrix.platform == 'macos-15' && env.APPLE_SIGNING_IDENTITY != '' - env: - APPLE_SIGNING_IDENTITY: ${{ env.APPLE_SIGNING_IDENTITY }} - run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh - # DigiCert KeyLocker Setup (Cloud HSM) - name: Setup DigiCert KeyLocker id: digicert-setup @@ -284,6 +269,17 @@ jobs: echo "APPLE_SIGNING_IDENTITY=$CERT_ID" >> $GITHUB_ENV echo "Certificate imported successfully." + - name: Sign JPDFium dylibs inside bootJar (macOS only) + # JPDFium's publish workflow has no Apple Developer credentials, so + # the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned. + # Apple's notarytool walks into nested .jars inside the .app and + # rejects unsigned binaries. Tauri's own codesign walk doesn't open + # .jars, so we have to re-sign them here, between cert import and + # tauri-action, using this build's Developer ID identity (set in + # GITHUB_ENV by the Verify Certificate step above). + if: matrix.platform == 'macos-15' && env.APPLE_CERTIFICATE != '' + run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh + - name: Check DMG creation dependencies (macOS only) if: matrix.platform == 'macos-15' run: |