Skip to content

Commit 297e527

Browse files
committed
apple workflow uses scripts
1 parent cfa2159 commit 297e527

5 files changed

Lines changed: 813 additions & 64 deletions

File tree

‎.github/workflows/apple.yml‎

Lines changed: 17 additions & 64 deletions
Original file line numberDiff line numberDiff line change
@@ -37,9 +37,9 @@ jobs:
3737
fail-fast: false
3838
matrix:
3939
config:
40-
- {name: "macOS-latest", os: "macOS-latest", cmake_extra: "-DCMAKE_OSX_DEPLOYMENT_TARGET=10.15 -DLSL_UNITTESTS=ON -DLSL_BENCHMARKS=ON -DCMAKE_OSX_ARCHITECTURES=\"x86_64;arm64\"" }
41-
- {name: "iOS", os: "macOS-latest", cmake_extra: "-DCMAKE_TOOLCHAIN_FILE=cmake/ios.toolchain.cmake -DPLATFORM=OS64" }
42-
- {name: "iOS Simulator", os: "macOS-latest", cmake_extra: "-DCMAKE_TOOLCHAIN_FILE=cmake/ios.toolchain.cmake -DPLATFORM=SIMULATOR64COMBINED -G Xcode" }
40+
- {name: "macOS-latest", os: "macOS-latest", platform: "macos", cmake_extra: "-DCMAKE_OSX_DEPLOYMENT_TARGET=10.15 -DLSL_UNITTESTS=ON -DLSL_BENCHMARKS=ON -DCMAKE_OSX_ARCHITECTURES=\"x86_64;arm64\"" }
41+
- {name: "iOS", os: "macOS-latest", platform: "ios", cmake_extra: "-DCMAKE_TOOLCHAIN_FILE=cmake/ios.toolchain.cmake -DPLATFORM=OS64" }
42+
- {name: "iOS Simulator", os: "macOS-latest", platform: "ios-simulator", cmake_extra: "-DCMAKE_TOOLCHAIN_FILE=cmake/ios.toolchain.cmake -DPLATFORM=SIMULATOR64COMBINED -G Xcode" }
4343

4444
steps:
4545
- uses: actions/checkout@v4
@@ -87,22 +87,10 @@ jobs:
8787
cmake --build examples/build --target install --config Release -j
8888
./examples/build/install/bin/HandleMetaData
8989
90-
- name: Codesign
90+
- name: Codesign Framework
9191
run: |
92-
if [[ "${{ matrix.config.name }}" == "macOS-latest" ]]; then
93-
codesign -vvv --force --deep --sign "$APPLE_CODE_SIGN_IDENTITY_APP" \
94-
--entitlements lsl.entitlements --options runtime \
95-
install/Frameworks/lsl.framework/Versions/A/lsl
96-
codesign -vvv --verify --deep --strict install/Frameworks/lsl.framework/Versions/A/lsl
97-
elif [[ "${{ matrix.config.name }}" == "iOS" || "${{ matrix.config.name }}" == "iOS Simulator" ]]; then
98-
codesign -vvv --force --deep --sign "$APPLE_CODE_SIGN_IDENTITY_APP" \
99-
install/Frameworks/lsl.framework/lsl
100-
codesign -vvv --verify --deep --strict install/Frameworks/lsl.framework/lsl
101-
fi
102-
codesign -vvv --force --deep --sign "$APPLE_CODE_SIGN_IDENTITY_APP" \
103-
--entitlements lsl.entitlements --options runtime \
104-
install/Frameworks/lsl.framework
105-
codesign -vvv --verify --deep --strict install/Frameworks/lsl.framework
92+
./scripts/apple_codesign.sh install/Frameworks/lsl.framework \
93+
--platform ${{ matrix.config.platform }}
10694
10795
# run internal tests
10896
- name: unit tests
@@ -112,13 +100,6 @@ jobs:
112100
install/bin/lsl_test_internal --order rand --wait-for-keypress never --durations yes
113101
install/bin/lsl_test_exported --order rand --wait-for-keypress never --durations yes
114102
timeout-minutes: 10
115-
- name: unit test (intel)
116-
if: matrix.config.name == 'macOS-15-intel'
117-
run: |
118-
mkdir -p dumps
119-
install/bin/lsl_test_internal --order rand --wait-for-keypress never --durations yes
120-
install/bin/lsl_test_exported --order rand --wait-for-keypress never --durations yes
121-
timeout-minutes: 10
122103

123104
- name: Package and Notarize macOS Installer
124105
if: matrix.config.name == 'macOS-latest'
@@ -127,23 +108,9 @@ jobs:
127108
APPLE_NOTARIZE_USERNAME: ${{ secrets.PROD_MACOS_NOTARIZATION_APPLE_ID }}
128109
APPLE_NOTARIZE_PASSWORD: ${{ secrets.PROD_MACOS_NOTARIZATION_PWD }}
129110
run: |
130-
# Get the version number from the framework's Info.plist
131-
LSL_VERSION=$(/usr/libexec/PlistBuddy -c "Print CFBundleShortVersionString" install/Frameworks/lsl.framework/Versions/A/Resources/Info.plist)
132-
echo "LSL_VERSION=$LSL_VERSION" >> $GITHUB_ENV
133-
echo "Debug: LSL_VERSION=$LSL_VERSION"
134-
135-
mkdir -p package
136-
productbuild --sign "$APPLE_CODE_SIGN_IDENTITY_INST" \
137-
--component install/Frameworks/lsl.framework \
138-
/Library/Frameworks package/liblsl-${LSL_VERSION}-Darwin-universal.pkg
139-
# Notarize the package
140-
xcrun notarytool submit package/liblsl-${LSL_VERSION}-Darwin-universal.pkg \
141-
--apple-id "$APPLE_NOTARIZE_USERNAME" \
142-
--password "$APPLE_NOTARIZE_PASSWORD" \
143-
--team-id "$APPLE_DEVELOPMENT_TEAM" \
144-
--wait
145-
# Staple the notarization ticket to the package
146-
xcrun stapler staple package/liblsl-${LSL_VERSION}-Darwin-universal.pkg
111+
./scripts/apple_package_notarize.sh install/Frameworks/lsl.framework \
112+
--notarize \
113+
--output package
147114
148115
- name: upload dump
149116
if: failure()
@@ -166,15 +133,13 @@ jobs:
166133
path: |
167134
package/*.pkg
168135
install/Frameworks/lsl.framework.zip
169-
# Note: the artifact will preserve the folder structure up to the common root, in this case all.
170136
171137
- name: Upload iOS Framework
172138
if: matrix.config.name == 'iOS'
173139
uses: actions/upload-artifact@v4
174140
with:
175141
name: build-iOS
176142
path: install/Frameworks/lsl.framework.zip
177-
# Note: the artifact drops the folder structure and only keeps the zip.
178143

179144
- name: Upload iOS Simulator Framework
180145
if: matrix.config.name == 'iOS Simulator'
@@ -202,16 +167,10 @@ jobs:
202167
name: build-iOS-Simulator
203168
path: build-iOS-Simulator
204169

205-
- name: Unzip macOS Framework
170+
- name: Unzip Frameworks
206171
run: |
207172
unzip build-macOS-latest/install/Frameworks/lsl.framework.zip -d build-macOS-latest/Frameworks
208-
209-
- name: Unzip iOS Framework
210-
run: |
211173
unzip build-iOS/lsl.framework.zip -d build-iOS/Frameworks
212-
213-
- name: Unzip iOS Simulator Framework
214-
run: |
215174
unzip build-iOS-Simulator/lsl.framework.zip -d build-iOS-Simulator/Frameworks
216175
217176
- name: Install certificates and provisioning profiles
@@ -224,25 +183,19 @@ jobs:
224183

225184
- name: Create and Sign XCFramework
226185
run: |
227-
xcodebuild -create-xcframework \
228-
-framework build-macOS-latest/Frameworks/lsl.framework \
229-
-framework build-iOS/Frameworks/lsl.framework \
230-
-framework build-iOS-Simulator/Frameworks/lsl.framework \
231-
-output lsl.xcframework
232-
233-
codesign -vvv --force --deep --sign "$APPLE_CODE_SIGN_IDENTITY_APP" lsl.xcframework
234-
echo "✅ Verifying binary signatures in XCFramework..."
235-
codesign -vvv --verify --deep --strict lsl.xcframework
236-
237-
ditto -c -k --sequesterRsrc --keepParent lsl.xcframework lsl.xcframework.$LSL_VERSION.zip
186+
./scripts/apple_create_xcframework.sh \
187+
--macos build-macOS-latest/Frameworks/lsl.framework \
188+
--ios build-iOS/Frameworks/lsl.framework \
189+
--ios-simulator build-iOS-Simulator/Frameworks/lsl.framework \
190+
--output .
238191
239192
- name: upload artifacts
240193
uses: actions/upload-artifact@v4
241194
with:
242195
name: mac-packages
243196
path: |
244197
lsl.xcframework.*.zip
245-
package/
198+
build-macOS-latest/package/
246199
247200
- name: upload to release page
248201
if: github.event_name == 'release'
@@ -252,7 +205,7 @@ jobs:
252205
UPLOAD_URL: ${{ github.event.release.upload_url }}
253206
run: |
254207
UPLOAD_URL=${UPLOAD_URL%\{*} # remove "{name,label}" suffix
255-
for pkg in lsl.xcframework.zip package/*.*; do
208+
for pkg in lsl.xcframework.*.zip build-macOS-latest/package/*.*; do
256209
NAME=$(basename $pkg)
257210
MIME=$(file --mime-type $pkg|cut -d ' ' -f2)
258211
curl -X POST -H "Accept: application/vnd.github.v3+json" -H "Authorization: $TOKEN" -H "Content-Type: $MIME" --data-binary @$pkg $UPLOAD_URL?name=$NAME

‎scripts/apple_codesign.sh‎

Lines changed: 159 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,159 @@
1+
#!/bin/bash
2+
# =============================================================================
3+
# Apple Code Signing Script for LSL Frameworks
4+
# =============================================================================
5+
# Signs macOS and iOS frameworks with the appropriate code signing identity.
6+
#
7+
# Usage:
8+
# ./scripts/apple_codesign.sh <framework_path> [--platform macos|ios]
9+
#
10+
# Environment Variables:
11+
# APPLE_CODE_SIGN_IDENTITY_APP - Code signing identity (default: "Developer ID Application")
12+
# Set to "-" for ad-hoc signing (local development)
13+
#
14+
# Examples:
15+
# # Sign macOS framework (with hardened runtime and entitlements)
16+
# ./scripts/apple_codesign.sh install/Frameworks/lsl.framework --platform macos
17+
#
18+
# # Sign iOS framework
19+
# ./scripts/apple_codesign.sh build-iOS/Frameworks/lsl.framework --platform ios
20+
#
21+
# # Ad-hoc signing for local development
22+
# APPLE_CODE_SIGN_IDENTITY_APP="-" ./scripts/apple_codesign.sh install/Frameworks/lsl.framework
23+
# =============================================================================
24+
25+
set -e
26+
27+
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
28+
PROJECT_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)"
29+
30+
# Default configuration
31+
SIGN_IDENTITY="${APPLE_CODE_SIGN_IDENTITY_APP:-Developer ID Application}"
32+
ENTITLEMENTS_FILE="${ENTITLEMENTS_FILE:-$PROJECT_ROOT/lsl.entitlements}"
33+
PLATFORM="macos"
34+
35+
# Parse arguments
36+
FRAMEWORK_PATH=""
37+
while [[ $# -gt 0 ]]; do
38+
case $1 in
39+
--platform)
40+
PLATFORM="$2"
41+
shift 2
42+
;;
43+
--identity)
44+
SIGN_IDENTITY="$2"
45+
shift 2
46+
;;
47+
--entitlements)
48+
ENTITLEMENTS_FILE="$2"
49+
shift 2
50+
;;
51+
-h|--help)
52+
echo "Usage: $0 <framework_path> [--platform macos|ios] [--identity <identity>] [--entitlements <file>]"
53+
echo ""
54+
echo "Environment Variables:"
55+
echo " APPLE_CODE_SIGN_IDENTITY_APP - Code signing identity (default: 'Developer ID Application')"
56+
echo " ENTITLEMENTS_FILE - Path to entitlements file (default: lsl.entitlements)"
57+
exit 0
58+
;;
59+
-*)
60+
echo "Unknown option: $1"
61+
exit 1
62+
;;
63+
*)
64+
FRAMEWORK_PATH="$1"
65+
shift
66+
;;
67+
esac
68+
done
69+
70+
if [[ -z "$FRAMEWORK_PATH" ]]; then
71+
echo "Error: Framework path required"
72+
echo "Usage: $0 <framework_path> [--platform macos|ios]"
73+
exit 1
74+
fi
75+
76+
if [[ ! -d "$FRAMEWORK_PATH" ]]; then
77+
echo "Error: Framework not found at: $FRAMEWORK_PATH"
78+
exit 1
79+
fi
80+
81+
echo "=== Apple Code Signing ==="
82+
echo "Framework: $FRAMEWORK_PATH"
83+
echo "Platform: $PLATFORM"
84+
echo "Identity: $SIGN_IDENTITY"
85+
echo ""
86+
87+
# Determine the binary path within the framework
88+
if [[ "$PLATFORM" == "macos" ]]; then
89+
# macOS framework: Versions/A/lsl
90+
BINARY_PATH="$FRAMEWORK_PATH/Versions/A/lsl"
91+
if [[ ! -f "$BINARY_PATH" ]]; then
92+
echo "Error: macOS framework binary not found at: $BINARY_PATH"
93+
exit 1
94+
fi
95+
96+
# Check for entitlements file
97+
ENTITLEMENTS_ARG=""
98+
if [[ -f "$ENTITLEMENTS_FILE" ]]; then
99+
ENTITLEMENTS_ARG="--entitlements $ENTITLEMENTS_FILE"
100+
echo "Entitlements: $ENTITLEMENTS_FILE"
101+
else
102+
echo "Warning: Entitlements file not found at $ENTITLEMENTS_FILE"
103+
echo " Signing without entitlements (may affect notarization)"
104+
fi
105+
echo ""
106+
107+
# Sign the binary first (with hardened runtime for notarization)
108+
echo "Signing binary: $BINARY_PATH"
109+
codesign --force --deep --sign "$SIGN_IDENTITY" \
110+
--options runtime \
111+
$ENTITLEMENTS_ARG \
112+
"$BINARY_PATH"
113+
114+
# Verify binary signature
115+
echo "Verifying binary signature..."
116+
codesign --verify --verbose --strict "$BINARY_PATH"
117+
118+
# Sign the entire framework bundle
119+
echo ""
120+
echo "Signing framework bundle: $FRAMEWORK_PATH"
121+
codesign --force --deep --sign "$SIGN_IDENTITY" \
122+
--options runtime \
123+
$ENTITLEMENTS_ARG \
124+
"$FRAMEWORK_PATH"
125+
126+
elif [[ "$PLATFORM" == "ios" || "$PLATFORM" == "ios-simulator" ]]; then
127+
# iOS framework: lsl (no Versions directory)
128+
BINARY_PATH="$FRAMEWORK_PATH/lsl"
129+
if [[ ! -f "$BINARY_PATH" ]]; then
130+
echo "Error: iOS framework binary not found at: $BINARY_PATH"
131+
exit 1
132+
fi
133+
echo ""
134+
135+
# Sign the binary (no hardened runtime for iOS)
136+
echo "Signing binary: $BINARY_PATH"
137+
codesign --force --deep --sign "$SIGN_IDENTITY" "$BINARY_PATH"
138+
139+
# Verify binary signature
140+
echo "Verifying binary signature..."
141+
codesign --verify --verbose --strict "$BINARY_PATH"
142+
143+
# Sign the entire framework bundle
144+
echo ""
145+
echo "Signing framework bundle: $FRAMEWORK_PATH"
146+
codesign --force --deep --sign "$SIGN_IDENTITY" "$FRAMEWORK_PATH"
147+
else
148+
echo "Error: Unknown platform: $PLATFORM"
149+
echo "Supported platforms: macos, ios, ios-simulator"
150+
exit 1
151+
fi
152+
153+
# Final verification
154+
echo ""
155+
echo "Verifying framework signature..."
156+
codesign --verify --verbose --deep --strict "$FRAMEWORK_PATH"
157+
158+
echo ""
159+
echo "=== Code Signing Complete ==="

0 commit comments

Comments
 (0)