Skip to content

Sign and verify macOS release binaries before upload - #11

Merged
kklimuk merged 1 commit into
mainfrom
fix/issue-9-macos-signing
Sep 25, 2026
Merged

kklimuk merged 1 commit into
mainfrom
fix/issue-9-macos-signing

Conversation

@kklimuk

@kklimuk kklimuk commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Summary

Fixes #9.

The v0.25.0 Apple Silicon executable was reported to have an invalid embedded signature, causing macOS to kill it before startup. Ad-hoc sign macOS binaries after compilation with Bun's documented JavaScriptCore entitlements, then require strict signature verification before artifact upload. Release checksums cover the final signed bytes.

Build and smoke-test Intel and ARM macOS binaries natively in CI and releases, including help/version, document reading, and schema validation. Update signing and recovery documentation, including resolving mise shims and using the Bun package fallback without PATH shadowing. Existing published assets are unchanged; this fixes future builds. Ad-hoc signing does not provide Developer ID identity or notarization.

Test plan

  • bun run check (lint, types, dead code); shell syntax, entitlement plist, workflow YAML, and diff checks.
  • 20 installer/upgrade tests pass.
  • Build, sign, and strictly verify on macOS 26.6.2 ARM64; exercise version/help/no-args, read/validate, and create/edit/read/validate.
  • Copy to a path containing spaces: checksum unchanged, signature valid, document operations pass.
  • Deliberately tampered disposable binary rejected without executing it; missing arguments/files and signing failure return nonzero.
  • Signing also verified with a Bun 1.3.10-built executable.
  • Adversarial security, correctness, and product review; recovery-documentation finding addressed.

macOS 27, native Intel execution, and remote GitHub workflows remain unverified locally. No LibreOffice checks were run during final review. The pre-commit full-suite hook was skipped to avoid launching LibreOffice; the checks above were run separately.

@kklimuk
kklimuk merged commit 3a78f02 into main Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docx-darwin-arm64 v0.25.0 ships with an invalid code signature; macOS 27 SIGKILLs it on exec (Killed: 9, exit 137)

1 participant