Merge bitcoin/bitcoin#34914: contrib: replace deprecated --deep codesign flag, fix accidental --verify skip on ci

da7d7dbc7c contrib: remove deprecated --deep codesign flag (Sjors Provoost)
ad4eeaf859 ci: avoid modifying GOAL in 03_test_script.sh (Sjors Provoost)

Pull request description:

  Replace the deprecated `codesign --deep` with explicit, and minimal, per-component signing of Frameworks, Plugins and the top-level bundle.

  The CI signature check introduced in #34787 is updated to use `--strict`.

  Can be tested with:

  ```sh
  cmake -B build -DBUILD_GUI=ON
  # delete artifacts before rebuilding the `deploy` target
  rm -rf build/Bitcoin-Qt.app build/bitcoin-macos-app.zip
  cmake --build build -t deploy
  codesign --verify --deep --strict --verbose=4 build/dist/Bitcoin-Qt.app
  ```

  Fixes #32486, supersedes #33592 (this is a condensed version)

  Additionally this PR modifies `03_test_script.sh` to avoid modifying `GOAL` in place. That was causing the `codesign --verify` step to get skipped entirely.

ACKs for top commit:
  fanquake:
    ACK da7d7dbc7c - I think we should try and cleanup `macdeployqtplus` somewhat, but that can happen in future.
  willcl-ark:
    Light ACK da7d7dbc7c

Tree-SHA512: 54e6d38a327a9a241d842728390770e7819d45180c69c288f1e26c5706aff8ebedbb4f608c4a45b2b186e3369181b116aa82134a38fcaabf3af3711be14b9863
This commit is contained in:
merge-script
2026-09-11 10:55:50 +01:00
2 changed files with 18 additions and 5 deletions

View File

@@ -123,15 +123,16 @@ cmake -S "$BASE_ROOT_DIR" -B "$BASE_BUILD_DIR" "${CMAKE_ARGS[@]}" || (
false false
) )
BUILD_TARGETS="${GOAL}"
if [[ "${GOAL}" != all && "${GOAL}" != *codegen* ]]; then if [[ "${GOAL}" != all && "${GOAL}" != *codegen* ]]; then
GOAL="all ${GOAL}" BUILD_TARGETS="all ${GOAL}"
fi fi
# shellcheck disable=SC2086 # shellcheck disable=SC2086
cmake --build "${BASE_BUILD_DIR}" "$MAKEJOBS" --target $GOAL || ( cmake --build "${BASE_BUILD_DIR}" "$MAKEJOBS" --target $BUILD_TARGETS || (
echo "Build failure. Verbose build follows." echo "Build failure. Verbose build follows."
# shellcheck disable=SC2086 # shellcheck disable=SC2086
cmake --build "${BASE_BUILD_DIR}" -j1 --target $GOAL --verbose cmake --build "${BASE_BUILD_DIR}" -j1 --target $BUILD_TARGETS --verbose
false false
) )
@@ -182,7 +183,7 @@ fi
if [[ "$CI_OS_NAME" == "macos" && "${GOAL}" = "install deploy" ]]; then if [[ "$CI_OS_NAME" == "macos" && "${GOAL}" = "install deploy" ]]; then
unzip "${BASE_BUILD_DIR}/bitcoin-macos-app.zip" -d "${BASE_BUILD_DIR}/deploy" unzip "${BASE_BUILD_DIR}/bitcoin-macos-app.zip" -d "${BASE_BUILD_DIR}/deploy"
if ! ( codesign --verify "${BASE_BUILD_DIR}/deploy/Bitcoin-Qt.app" ); then if ! ( codesign --verify --deep --strict "${BASE_BUILD_DIR}/deploy/Bitcoin-Qt.app" ); then
echo "Codesigning failed." echo "Codesigning failed."
false false
fi fi

View File

@@ -488,7 +488,19 @@ with open(os.path.join(applicationBundle.resourcesPath, "qt.conf"), "wb") as f:
# ------------------------------------------------ # ------------------------------------------------
if platform.system() == "Darwin": if platform.system() == "Darwin":
subprocess.check_call(f"codesign --deep --force --sign - {target}", shell=True) # The earlier strip and install_name_tool calls invalidated existing framework
# and plugin code signatures.
print("+ Signing app bundle +")
sign_targets = [
path
for pattern in ("Frameworks/*", "PlugIns/*/*")
for path in Path(target, "Contents").glob(pattern)
if path.is_file() or path.name.endswith(".framework")
]
# Sign the app bundle last
sign_targets.append(Path(target))
for sign_target in sign_targets:
subprocess.check_call(["codesign", "--force", "--sign", "-", sign_target.as_posix()])
# ------------------------------------------------ # ------------------------------------------------