fix(macos): strip extended attributes from the App Store app before signing
- App Store Connect refused the package with error 91109 because the embedded provisioning profile kept the com.apple.quarantine attribute the browser set when it was downloaded. - Every extended attribute is now cleared from the app before it is signed, so no file copied into the bundle can carry quarantine into the package; com.apple.provenance, which macOS sets on every file and which cannot be cleared, remains.
This commit is contained in:
parent
b70ac24cc4
commit
8a8bf653fe
2 changed files with 12 additions and 2 deletions
|
|
@ -102,7 +102,9 @@ if [ -n "$helper" ]; then
|
||||||
identity=${MIDI_HARBOR_SIGNING_IDENTITY:--}
|
identity=${MIDI_HARBOR_SIGNING_IDENTITY:--}
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Sign.
|
# Sign, with no extended attributes: App Store Connect refuses a package holding a file
|
||||||
|
# marked with com.apple.quarantine, as a downloaded profile is (research R-103).
|
||||||
|
xattr -cr "$app"
|
||||||
plutil -lint "$app/Contents/Info.plist" >/dev/null
|
plutil -lint "$app/Contents/Info.plist" >/dev/null
|
||||||
codesign --force --options runtime --sign "$identity" \
|
codesign --force --options runtime --sign "$identity" \
|
||||||
--entitlements packaging/macos/helper.entitlements \
|
--entitlements packaging/macos/helper.entitlements \
|
||||||
|
|
|
||||||
|
|
@ -36,6 +36,13 @@ owner rewrites history before publishing and the count would fall.
|
||||||
used for hashing and random numbers, which are exempt. `ITSAppUsesNonExemptEncryption` is false,
|
used for hashing and random numbers, which are exempt. `ITSAppUsesNonExemptEncryption` is false,
|
||||||
so App Store Connect does not ask at every upload.
|
so App Store Connect does not ask at every upload.
|
||||||
|
|
||||||
|
**Extended attributes are stripped before signing.** The first upload was refused with error
|
||||||
|
91109: `Contents/embedded.provisionprofile` carried `com.apple.quarantine`, which the browser set
|
||||||
|
on the downloaded profile and `cp` kept. `xattr -cr` on the app before signing removes it and
|
||||||
|
anything else a copied file brings. `com.apple.provenance` stays on every file, since macOS
|
||||||
|
sets it on whatever an app writes and it cannot be cleared; App Store Connect's check names only
|
||||||
|
quarantine.
|
||||||
|
|
||||||
**Evidence**, `make appstore` on the development Mac:
|
**Evidence**, `make appstore` on the development Mac:
|
||||||
|
|
||||||
- `lipo -archs`: `x86_64 arm64` for both executables, once `x86_64-apple-darwin` was installed.
|
- `lipo -archs`: `x86_64 arm64` for both executables, once `x86_64-apple-darwin` was installed.
|
||||||
|
|
@ -48,4 +55,5 @@ so App Store Connect does not ask at every upload.
|
||||||
(8XMLMKNPUT)", which it reports as a development certificate, as it does every App Store
|
(8XMLMKNPUT)", which it reports as a development certificate, as it does every App Store
|
||||||
installer certificate.
|
installer certificate.
|
||||||
|
|
||||||
**Not checked**: App Store Connect's own validation, which runs on upload.
|
**Not checked**: an upload after the quarantine fix; the expanded package carries no attribute but
|
||||||
|
`com.apple.provenance`.
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue