mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
Sign the macOS jlink image (amy-<version>-macos-arm64.tar.gz) so users who download it directly clear Gatekeeper. Reuses the same Developer ID cert and the six MAC_* secrets as the desktop DMG; no-op when they're absent. - .github/actions/import-macos-cert: factor the throwaway-keychain cert import into a composite action; the desktop leg now uses it too (was inline). - create-release.yml (build-cli macOS leg): import the cert, then codesign every Mach-O binary in the bundled JRE (executables get hardened-runtime entitlements, dylibs don't) and notarize via notarytool --wait. Runs before the collect step so the tarred image is signed. Job timeout 30->45 min for notarization headroom. - cli/packaging/macos/amy.entitlements: hardened-runtime entitlements; the disable-library-validation key lets the JVM load the secp256k1 native dylib it extracts from a jar at runtime (would otherwise crash under notarization). - BUILDING.md: document the tarball signing, the no-stapling/online-check caveat, and that the Homebrew-core jvm bundle is intentionally left unsigned. Untested end-to-end (no macOS runner / Apple creds here) — validate with a workflow_dispatch dry-run once the secrets are provisioned. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015sso31DfSF9B6EFCVkEqWD
27 lines
1.2 KiB
XML
27 lines
1.2 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
|
<!--
|
|
Hardened-runtime entitlements for amy's bundled JVM (runtime/bin/java).
|
|
Required when codesigning + notarizing the macOS jlink image:
|
|
- allow-jit / allow-unsigned-executable-memory: the JIT compiler writes
|
|
and executes generated machine code.
|
|
- disable-library-validation: amy loads the secp256k1 native .dylib that
|
|
secp256k1-kmp-jni-jvm extracts from a jar at runtime; that dylib is not
|
|
signed by our Team ID, so library validation would otherwise block it.
|
|
- allow-dyld-environment-variables: the Gradle start script sets JVM env.
|
|
Applied only to Mach-O *executables* in the image; plain dylibs are signed
|
|
without entitlements. See .github/workflows/create-release.yml (build-cli).
|
|
-->
|
|
<plist version="1.0">
|
|
<dict>
|
|
<key>com.apple.security.cs.allow-jit</key>
|
|
<true/>
|
|
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
|
|
<true/>
|
|
<key>com.apple.security.cs.disable-library-validation</key>
|
|
<true/>
|
|
<key>com.apple.security.cs.allow-dyld-environment-variables</key>
|
|
<true/>
|
|
</dict>
|
|
</plist>
|