From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Jim Myhrberg Newsgroups: gmane.emacs.bugs Subject: bug#49271: 28.0.50: native-comp: Signing macOS self-contained .app bundle fails due to new *.eln location Date: Thu, 1 Jul 2021 21:43:39 +0100 Message-ID: <496EAC1F-D201-4DBA-8D0A-021E3D429B53@jimeh.me> References: <83zgv7mtly.fsf@gnu.org> <7E142F36-1D22-424E-8B3B-7AC74C1A8772@jimeh.me> Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.80.0.2.43\)) Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="26524"; mail-complaints-to="usenet@ciao.gmane.io" Cc: 49271@debbugs.gnu.org To: Alan Third Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Thu Jul 01 22:44:15 2021 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1lz3Xi-0006jX-SU for geb-bug-gnu-emacs@m.gmane-mx.org; Thu, 01 Jul 2021 22:44:14 +0200 Original-Received: from localhost ([::1]:34972 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lz3Xh-0002Sb-Uq for geb-bug-gnu-emacs@m.gmane-mx.org; Thu, 01 Jul 2021 16:44:13 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:40928) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lz3XW-0002SF-H2 for bug-gnu-emacs@gnu.org; Thu, 01 Jul 2021 16:44:02 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:50442) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lz3XW-0002hN-6z for bug-gnu-emacs@gnu.org; Thu, 01 Jul 2021 16:44:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1lz3XV-0005G8-Uf for bug-gnu-emacs@gnu.org; Thu, 01 Jul 2021 16:44:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Jim Myhrberg Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Thu, 01 Jul 2021 20:44:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 49271 X-GNU-PR-Package: emacs Original-Received: via spool by 49271-submit@debbugs.gnu.org id=B49271.162517223120190 (code B ref 49271); Thu, 01 Jul 2021 20:44:01 +0000 Original-Received: (at 49271) by debbugs.gnu.org; 1 Jul 2021 20:43:51 +0000 Original-Received: from localhost ([127.0.0.1]:33755 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lz3XK-0005FZ-IS for submit@debbugs.gnu.org; Thu, 01 Jul 2021 16:43:50 -0400 Original-Received: from mail-wr1-f52.google.com ([209.85.221.52]:39607) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lz3XH-0005FL-Ta for 49271@debbugs.gnu.org; Thu, 01 Jul 2021 16:43:48 -0400 Original-Received: by mail-wr1-f52.google.com with SMTP id f14so9447248wrs.6 for <49271@debbugs.gnu.org>; Thu, 01 Jul 2021 13:43:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jimeh.me; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=rvPB/+HqRVz0lgNPXSNepCJseeawXhscuOuaffXmwZY=; b=EmtwphwfxAW+euGYNbGetbKQ5f34pX6JlkX82Q3YeKdUD15kzyYG6VbWuPZBLkVA8/ WAjtSJJpFHYPcX8lL56OvmuI74LvjJElHteCbUZjarnbMj2ae591gl4I04HdT6NN3AVr G+aCuqFfIIjjPbKKaquhDkeqPaw4H3q72mjLjv668BZe0wKX0+fdgVwq2UUWtfMhkTty fyanPlRB1gWNaTvNYJmQjqfVCT9x0ALqp+j6QmVDnZfu2U/Z5FZf8xPBaLFH8ceiX1OI 5WqGi0BhKYrbPUOuWWJuEJoe9/XRI0wLNlbSPOKLnf5n2EL5WwASciZawM3z1zojaDvr qajw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=rvPB/+HqRVz0lgNPXSNepCJseeawXhscuOuaffXmwZY=; b=scT5hvg13llH0fK27oZP2qaW9Wc2ZAcJ/+sqwX0orAs65o16XmR41JTgQt+sJ/YBPs NktJ7vg1hFThHm+osoQuLZoYeocqcqocW26TfGxNBmzrt3kDpom9iZVU/8DPzfB6pDhW HT3V2b0mXSMqVJrHJJGt5XRqf/mq02UzT4TSWcN9ksKBaZfhOmE6oQCkUaw7M3mb0wws OkB+1fiMMkDUTu+moMXI2LEuGE6lKZ1t+JTNTfNYajgzKozmoVLlBeo5kTEZxX/my++x szJxeIzeSW2PYDRrwLhCRPgoKPb2DizSGH0uzAYhMlThZTNUKytAF0vp/9y0hYS9DYEC jRNQ== X-Gm-Message-State: AOAM533atnUsWhOkDVBeJzOtjmOTsSvzZzor4UXyOzL1jqco6yxyYQ/A TrEsWwreSrjC8cGXrY8KJ40kmg== X-Google-Smtp-Source: ABdhPJyayu52+KaIG1Om64kFCZuBLQcHGFIUCADn+JQyt7DVqNK/bCmmBrx1gIk75sQMq9UC+Q5aXw== X-Received: by 2002:a5d:4906:: with SMTP id x6mr1742348wrq.387.1625172221336; Thu, 01 Jul 2021 13:43:41 -0700 (PDT) Original-Received: from smtpclient.apple ([89.238.143.233]) by smtp.gmail.com with ESMTPSA id r9sm2323531wmh.40.2021.07.01.13.43.40 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 01 Jul 2021 13:43:40 -0700 (PDT) In-Reply-To: X-Mailer: Apple Mail (2.3654.80.0.2.43) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:209289 Archived-At: > On 1 Jul 2021, at 21:13, Alan Third wrote: >=20 > I'm curious what you're actually doing. We have some code that runs on > ARM based Macs only that does this >=20 > codesign -s - -f $@.tmp >=20 > where I think $@.tmp is... something... executable? >=20 > I'm wondering if we should just install everything into the app bundle > and sign the whole damn thing. >=20 > I don't really understand this whole codesigning thing. It seems to > make no difference here, but I'm not trying to run the app on another > Mac or on an ARM Mac, so I think it's normal that I shouldn't see any > difference. I can't say I know what the `$@.tmp` thing is either, or really = understand codesign for that matter. I've managed to make it work through trial and error... lol To explain a bit more of what I'm doing though; I basically got bored of = making my laptop sound like a jet engine for 25 minutes every other day as I = made new builds from the master branch, so I set out to make nightly builds using = GitHub Actions which I could just download and/or install/upgrade via brew = cask: https://github.com/jimeh/emacs-builds With the heavy lifting done by my custom build script: https://github.com/jimeh/build-emacs-for-macos The signing and notarizing stuff also lives in the build script repo, = but as part of a new (and somewhat hacky) "emacs-builder" CLI tool written in = Go, which is designed to automated a bunch of the steps. Because of this, you can see the full build process I'm doing on GitHub = Actions: = https://github.com/jimeh/emacs-builds/runs/2957583013?check_suite_focus=3D= true As for the *.eln file, previously when they were in Contents/Resources I = had to sign each one individually before signing the bundle as a whole. But I = didn't check if that was still needed after they were moved to Contents/MacOS a = few days ago. But I have checked it with them under Contents/Frameworks, and signing = the *.eln files is no longer needed as codesign finds them when signing the .app = bundle itself.. As for exactly what I'm doing, this is essentially the main command = which signs the .app bundle: codesign --sign --deep --timestamp --force --verbose \ --options runtime --entitlements = \ /path/to/Emacs.app And the entitlements I use are: - com.apple.security.automation.apple-events - com.apple.security.cs.allow-jit - com.apple.security.cs.disable-library-validation - com.apple.security.network.client Which seem to be enough for everything I do with Emacs to work = correctly. I do also sign a custom little "emacs" shell-script in = Contents/MacOS/bin, which I add to make it easy to expose a "emacs" CLI tool, all it does is = correctly resolve the path to the .app bundle, and execute the main MacOS/Emacs = binary from its absolute real path so it can find everything it depends on = within the app bundle even when symlinked to somewhere else. I'm happy to answer any questions you might have :)=