fix(release): tolerate apple agreement notarization block

This commit is contained in:
Kayshen-X 2026-07-09 00:10:19 +08:00
parent 4abd5119e7
commit 5799d9cc9c
2 changed files with 31 additions and 6 deletions

View file

@ -264,12 +264,19 @@ jobs:
# notarize + staple so Gatekeeper accepts the download.
codesign --force --timestamp --options runtime \
--sign "$MACOS_SIGN_IDENTITY" "$DMG"
xcrun notarytool submit "$DMG" \
--apple-id "$APPLE_ID" \
--team-id "$APPLE_TEAM_ID" \
--password "$APPLE_APP_SPECIFIC_PASSWORD" \
--wait
xcrun stapler staple "$DMG"
notary_log="$(mktemp)"
if xcrun notarytool submit "$DMG" \
--apple-id "$APPLE_ID" \
--team-id "$APPLE_TEAM_ID" \
--password "$APPLE_APP_SPECIFIC_PASSWORD" \
--wait 2>&1 | tee "$notary_log"; then
xcrun stapler staple "$DMG"
elif grep -q "A required agreement is missing or has expired" "$notary_log"; then
echo "::warning::Apple Developer agreement is missing or expired; $DMG is signed but not notarized/stapled"
else
echo "::error::macOS notarization failed"
exit 1
fi
- name: Install NSIS (windows)
if: runner.os == 'Windows'
shell: pwsh

View file

@ -64,6 +64,24 @@ fn release_workflow_resolves_macos_signing_identity_from_keychain() {
);
}
#[test]
fn release_workflow_tolerates_missing_apple_notarization_agreement_for_prerelease() {
let workflow = std::fs::read_to_string(concat!(
env!("CARGO_MANIFEST_DIR"),
"/../../.github/workflows/rust-release.yml"
))
.expect("rust-release workflow is readable");
assert!(
workflow.contains("A required agreement is missing or has expired"),
"pre-release workflow should recognize Apple's external legal-agreement notarization block"
);
assert!(
workflow.contains("signed but not notarized"),
"pre-release workflow should still upload signed DMGs when Apple legal agreements block notarization"
);
}
#[test]
fn release_workflow_installs_nsis_on_windows_runner() {
let workflow = std::fs::read_to_string(concat!(