diff --git a/ci/test/03_test_script.sh b/ci/test/03_test_script.sh index d00005c0450..c8292d989f4 100755 --- a/ci/test/03_test_script.sh +++ b/ci/test/03_test_script.sh @@ -183,7 +183,7 @@ fi if [[ "$CI_OS_NAME" == "macos" && "${GOAL}" = "install deploy" ]]; then unzip "${BASE_BUILD_DIR}/bitcoin-macos-app.zip" -d "${BASE_BUILD_DIR}/deploy" - if ! ( codesign --verify "${BASE_BUILD_DIR}/deploy/Bitcoin-Qt.app" ); then + if ! ( codesign --verify --deep --strict "${BASE_BUILD_DIR}/deploy/Bitcoin-Qt.app" ); then echo "Codesigning failed." false fi diff --git a/contrib/macdeploy/macdeployqtplus b/contrib/macdeploy/macdeployqtplus index c8244af1532..19c778c9cfd 100755 --- a/contrib/macdeploy/macdeployqtplus +++ b/contrib/macdeploy/macdeployqtplus @@ -488,7 +488,19 @@ with open(os.path.join(applicationBundle.resourcesPath, "qt.conf"), "wb") as f: # ------------------------------------------------ if platform.system() == "Darwin": - subprocess.check_call(f"codesign --deep --force --sign - {target}", shell=True) + # The earlier strip and install_name_tool calls invalidated existing framework + # and plugin code signatures. + print("+ Signing app bundle +") + sign_targets = [ + path + for pattern in ("Frameworks/*", "PlugIns/*/*") + for path in Path(target, "Contents").glob(pattern) + if path.is_file() or path.name.endswith(".framework") + ] + # Sign the app bundle last + sign_targets.append(Path(target)) + for sign_target in sign_targets: + subprocess.check_call(["codesign", "--force", "--sign", "-", sign_target.as_posix()]) # ------------------------------------------------