diff --git a/Cargo.lock b/Cargo.lock index 71fe540..aac221b 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1882,7 +1882,7 @@ checksum = "75b325c5dbd37f80359721ad39aca5a29fb04c89279657cffdda8736d0c0b9d2" [[package]] name = "dpi" version = "0.1.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" [[package]] name = "drm" @@ -7793,7 +7793,7 @@ checksum = "d6bbff5f0aada427a1e5a6da5f1f98158182f26556f345ac9e04d36d0ebed650" [[package]] name = "winit" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "cfg_aliases", @@ -7819,7 +7819,7 @@ dependencies = [ [[package]] name = "winit-android" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "android-activity", "bitflags 2.13.2", @@ -7834,7 +7834,7 @@ dependencies = [ [[package]] name = "winit-appkit" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "block2 0.6.2", @@ -7856,7 +7856,7 @@ dependencies = [ [[package]] name = "winit-common" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "memmap2 0.9.11", "objc2 0.6.4", @@ -7871,7 +7871,7 @@ dependencies = [ [[package]] name = "winit-core" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "cursor-icon", @@ -7885,7 +7885,7 @@ dependencies = [ [[package]] name = "winit-orbital" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "dpi", @@ -7901,7 +7901,7 @@ dependencies = [ [[package]] name = "winit-uikit" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "block2 0.6.2", @@ -7921,7 +7921,7 @@ dependencies = [ [[package]] name = "winit-wayland" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "ahash", "bitflags 2.13.2", @@ -7947,7 +7947,7 @@ dependencies = [ [[package]] name = "winit-web" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "atomic-waker", "bitflags 2.13.2", @@ -7969,7 +7969,7 @@ dependencies = [ [[package]] name = "winit-win32" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "cursor-icon", @@ -7985,7 +7985,7 @@ dependencies = [ [[package]] name = "winit-x11" version = "0.31.0-beta.2" -source = "git+https://github.com/pop-os/winit.git?rev=9567503#9567503d34130113e36b0167a2b8829c3756e429" +source = "git+https://github.com/grmrgecko/winit?rev=2b36ab9e35cdf59916d1ceef1b49fc8169266ae8#2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" dependencies = [ "bitflags 2.13.2", "bytemuck", diff --git a/Cargo.toml b/Cargo.toml index 9d354fd..20cfec2 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -135,6 +135,23 @@ integer_division = "warn" [patch.crates-io] btleplug = { git = "https://github.com/grmrgecko/btleplug", rev = "3a9da4bd65697593d127c124cf332b835d240802" } +# winit's macOS backend imports the private CGSSetWindowBackgroundBlurRadius for window blur, which +# the Mac App Store rejects in any binary that links it (research R-110). The fork is libcosmic's +# pinned revision with that call removed. Every winit crate is listed so that all of them come from +# one source; move the fork along with the libcosmic revision in crates/gui/Cargo.toml. +[patch."https://github.com/pop-os/winit.git"] +winit = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-android = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-appkit = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-common = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-core = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-orbital = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-uikit = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-wayland = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-web = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-win32 = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } +winit-x11 = { git = "https://github.com/grmrgecko/winit", rev = "2b36ab9e35cdf59916d1ceef1b49fc8169266ae8" } + # Dependencies build without debug info in dev and test builds. Each of the workspace's test # binaries otherwise links libcosmic's debug info, which made relinking after a one-line change # take about two minutes on the development Mac instead of about ten seconds. The workspace's own diff --git a/packaging/macos/bundle.sh b/packaging/macos/bundle.sh index e7c2f5e..3b55b38 100755 --- a/packaging/macos/bundle.sh +++ b/packaging/macos/bundle.sh @@ -102,6 +102,16 @@ if [ -n "$helper" ]; then identity=${MIDI_HARBOR_SIGNING_IDENTITY:--} fi + # Refuse private window server calls: App Review rejects a binary that so much as imports + # one, and a dependency's macOS backend brought one in before (research R-110). + for executable in midi-harbor midi-harbor-daemon; do + private=$(nm -u -arch all "$app/Contents/MacOS/$executable" | grep '_CGS[A-Z]' | sort -u) + if [ -n "$private" ]; then + echo "$executable imports private APIs the App Store rejects:" $private >&2 + exit 1 + fi + done + # Sign, with no extended attributes: App Store Connect refuses a package holding a file # marked with com.apple.quarantine, as a downloaded profile is (research R-103). xattr -cr "$app" diff --git a/specs/016-app-store-submission/research.md b/specs/016-app-store-submission/research.md index b7ada4a..368be97 100644 --- a/specs/016-app-store-submission/research.md +++ b/specs/016-app-store-submission/research.md @@ -57,3 +57,43 @@ quarantine. **Not checked**: an upload after the quarantine fix; the expanded package carries no attribute but `com.apple.provenance`. + +--- + +## R-110: What App Review's automated check refused + +**Status**: **VERIFIED** (2026-10-03) locally; resubmitted the same day, verdict pending. Built as T255. + +The first submission came back with two automated messages before any person reviewed it. + +**The private API was winit's.** The check named `_CGSSetWindowBackgroundBlurRadius`. Nothing in +this project calls it: winit's macOS backend does, in `set_blur`, with `CGSMainConnectionID` +beside it, and libcosmic's iced pins `pop-os/winit` at `9567503`. No window here asks for blur, +but the linker keeps the import whether or not the call is reached, and the check reads imports. +winit 0.30.13 and the fork's other revisions in the cargo cache carry the same call, so no +update removes it. + +**Decision**: `grmrgecko/winit`, branch `no-private-blur`, is `9567503` with the two declarations +removed and `set_blur` doing nothing on macOS. The root `Cargo.toml` patches every winit crate to +it, since patching `winit-appkit` alone would leave two copies of `winit-core`. It moves with the +libcosmic revision. The direct-download build takes the same patch, having no use for blur +either. `bundle.sh` now refuses to sign an App Store bundle whose executables import any `_CGS` +followed by a capital, the prefix of the window server's private calls; the public +`CGShieldingWindowLevel` does not match. + +**The server entitlement stays.** The second message said `com.apple.security.network.server` had +no matching functionality. It has: each network port binds UDP ports and takes session +invitations from other machines (R-097). The helper does the listening and carries only the +sandbox and inherit, which is the likely reason the check saw none, though Apple does not say. +The answer is a reply and a note in App Review Information describing RTP-MIDI and how to see a +port from Audio MIDI Setup on another Mac, not a change to the build. + +**Evidence**, `make appstore` on the development Mac: + +- Before, `nm -u` on the full binary listed `_CGSMainConnectionID` and + `_CGSSetWindowBackgroundBlurRadius` for both architectures; the headless binary listed neither. +- After, `nm -u -arch arm64` and `-arch x86_64` list no `_CGS` private symbol in either + executable, and `strings` finds no `CGSSetWindowBackgroundBlurRadius` in the app. +- `codesign --verify --deep --strict` passes on the bundle. + +**Not checked**: App Review's verdict on the rebuilt package, and its answer to the reply. diff --git a/specs/016-app-store-submission/tasks.md b/specs/016-app-store-submission/tasks.md index 2240019..4b45b95 100644 --- a/specs/016-app-store-submission/tasks.md +++ b/specs/016-app-store-submission/tasks.md @@ -3,3 +3,4 @@ Tasks by their numbers in the project-wide sequence, which continues across every spec. - [x] T245 Build the App Store package with `make appstore`, per FR-S01 to FR-S03 — done: with `.signing/app-store.provisionprofile`, `bundle.sh --helper` embeds the profile, adds its App ID and team to the app's entitlements after checking the App ID is the bundle's, signs both executables with the keychain's Apple Distribution identity, sets the build number to the time in UTC and `ITSAppUsesNonExemptEncryption` to false, and wraps the app in a package signed with Mac Installer Distribution; without a profile it builds as before. Checked on the owner's Mac (R-103); not unit tested, since it is a build script. +- [x] T255 Remove what App Review's automated check refused (R-110) — done: every winit crate is patched to `grmrgecko/winit`, which drops the private `CGSSetWindowBackgroundBlurRadius` call, and `bundle.sh` refuses an App Store bundle whose executables import a private window server symbol. Checked with `nm -u` on both architectures of both executables; not unit tested, since it is a dependency patch and a build script. The server entitlement is kept and answered in App Review Information. diff --git a/specs/README.md b/specs/README.md index f650510..8abe010 100644 --- a/specs/README.md +++ b/specs/README.md @@ -137,8 +137,8 @@ exception is 014, whose task list started again at T001: its T001 to T034 are ci - **Requirements**: FR-S01, FR-S02, FR-S03 - **Success criteria**: SC-S01 -- **Research**: R-103 -- **Tasks**: T245 +- **Research**: R-103, R-110 +- **Tasks**: T245, T255 ### 017-appimage