Move JPDFium dylib signing step AFTER cert import
My first placement put the sign-jpdfium-dylibs-in-bootjar step at the wrong point in the workflow: BEFORE the "Verify Certificate" step that sets APPLE_SIGNING_IDENTITY in GITHUB_ENV. So the gate `if: ... && env.APPLE_SIGNING_IDENTITY != ''` always evaluated to false and the step silently skipped, leaving the dylibs unsigned and notarytool still rejecting the .app. Move it to right after Verify Certificate (which sets the env var from the keychain identity). Also switch the gate to checking env.APPLE_CERTIFICATE (the secret that's set at job level and available from step 1) rather than env.APPLE_SIGNING_IDENTITY (set mid-workflow via GITHUB_ENV) — the latter is fine in `run:` blocks but flaky in `if:` evaluation depending on GH Actions evaluation timing.
This commit is contained in:
@@ -158,21 +158,6 @@ jobs:
|
||||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||||
DISABLE_ADDITIONAL_FEATURES: true
|
||||
|
||||
- name: Sign JPDFium dylibs inside bootJar (macOS only)
|
||||
# JPDFium's publish workflow has no Apple Developer credentials, so
|
||||
# the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned.
|
||||
# Apple's notarytool walks into nested .jars inside the .app and
|
||||
# rejects unsigned binaries. Tauri's own codesign walk doesn't open
|
||||
# .jars, so we have to re-sign them here, between bootJar build and
|
||||
# tauri-action, using this build's Developer ID identity. The script
|
||||
# is non-fatal: if APPLE_SIGNING_IDENTITY isn't set (e.g. PR build
|
||||
# from a fork) it exits 0 and notarytool will continue to report
|
||||
# the unsigned-binary error.
|
||||
if: matrix.platform == 'macos-15' && env.APPLE_SIGNING_IDENTITY != ''
|
||||
env:
|
||||
APPLE_SIGNING_IDENTITY: ${{ env.APPLE_SIGNING_IDENTITY }}
|
||||
run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh
|
||||
|
||||
# DigiCert KeyLocker Setup (Cloud HSM)
|
||||
- name: Setup DigiCert KeyLocker
|
||||
id: digicert-setup
|
||||
@@ -284,6 +269,17 @@ jobs:
|
||||
echo "APPLE_SIGNING_IDENTITY=$CERT_ID" >> $GITHUB_ENV
|
||||
echo "Certificate imported successfully."
|
||||
|
||||
- name: Sign JPDFium dylibs inside bootJar (macOS only)
|
||||
# JPDFium's publish workflow has no Apple Developer credentials, so
|
||||
# the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned.
|
||||
# Apple's notarytool walks into nested .jars inside the .app and
|
||||
# rejects unsigned binaries. Tauri's own codesign walk doesn't open
|
||||
# .jars, so we have to re-sign them here, between cert import and
|
||||
# tauri-action, using this build's Developer ID identity (set in
|
||||
# GITHUB_ENV by the Verify Certificate step above).
|
||||
if: matrix.platform == 'macos-15' && env.APPLE_CERTIFICATE != ''
|
||||
run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh
|
||||
|
||||
- name: Check DMG creation dependencies (macOS only)
|
||||
if: matrix.platform == 'macos-15'
|
||||
run: |
|
||||
|
||||
Reference in New Issue
Block a user