Commit graph

5 commits

Author SHA1 Message Date
9eede3b366 fix(appstore): drop winit's private blur call that App Review refused
- App Review's automated check rejected the first submission for importing the private `CGSSetWindowBackgroundBlurRadius`. winit's macOS backend calls it for window blur, and the import stays in the binary although no window here asks for blur.
- Every winit crate is now patched to grmrgecko/winit, which is libcosmic's pinned revision with the private calls removed and blur doing nothing on macOS. The fork has to move whenever the libcosmic revision does.
- The App Store bundle is no longer signed when either executable imports a private window server symbol, so a dependency update cannot bring one back unnoticed.
- The `com.apple.security.network.server` entitlement, which the same check questioned, stays: network ports bind UDP and take incoming sessions. R-110 records the answer given to App Review.
2026-10-03 09:39:12 -05:00
9099ca3fcb build(macos): wait up to an hour for notarization in the release build
- The Docker release build gave up on Apple's notary service after rcodesign's default ten minutes, which failed the release and left the app and disk image unnotarized, so Gatekeeper rejected the download until the user allowed it in Privacy & Security.
- Apple holds a team's first submissions for longer; the build now waits up to an hour for the verdict before stapling.
2026-09-29 14:35:59 -05:00
8a8bf653fe fix(macos): strip extended attributes from the App Store app before signing
- App Store Connect refused the package with error 91109 because the embedded provisioning profile kept the com.apple.quarantine attribute the browser set when it was downloaded.
- Every extended attribute is now cleared from the app before it is signed, so no file copied into the bundle can carry quarantine into the package; com.apple.provenance, which macOS sets on every file and which cannot be cleared, remains.
2026-09-28 15:12:13 -05:00
b70ac24cc4 build(macos): build the App Store Connect package with make appstore
- The App Store variant was only signed ad hoc to run locally, so nothing it produced could be submitted; with a Mac App Store Connect provisioning profile in .signing/app-store.provisionprofile it now embeds the profile, adds the profile's App ID and team to the app's entitlements, signs both executables with the keychain's Apple Distribution identity, and wraps the app in an installer package signed with Mac Installer Distribution.
- A profile whose App ID is not the bundle's is refused, and a missing distribution or installer certificate stops the build rather than producing an unsubmittable package.
- CFBundleVersion becomes the build's UTC time to the minute, since App Store Connect rejects a build number it has seen, while CFBundleShortVersionString stays VERSION; ITSAppUsesNonExemptEncryption is false, as the build's only cryptography is hashing and random numbers.
- The bundled daemon keeps only the sandbox and inherit entitlements, which a helper inheriting its parent's sandbox requires.
- Without a profile the variant builds as before, ad hoc or with MIDI_HARBOR_SIGNING_IDENTITY, to run on the building Mac.
2026-09-28 14:38:49 -05:00
488e42b9c8 First commit 2026-09-28 13:59:10 -05:00