From 5799d9cc9c1c7161fd79f80da37e7960685eddab Mon Sep 17 00:00:00 2001 From: Kayshen-X Date: Thu, 9 Jul 2026 00:10:19 +0800 Subject: [PATCH] fix(release): tolerate apple agreement notarization block --- .github/workflows/rust-release.yml | 19 +++++++++++++------ crates/op-host-web/tests/ci_workflow.rs | 18 ++++++++++++++++++ 2 files changed, 31 insertions(+), 6 deletions(-) diff --git a/.github/workflows/rust-release.yml b/.github/workflows/rust-release.yml index 12eb8cf5f..dc1328ed6 100644 --- a/.github/workflows/rust-release.yml +++ b/.github/workflows/rust-release.yml @@ -264,12 +264,19 @@ jobs: # notarize + staple so Gatekeeper accepts the download. codesign --force --timestamp --options runtime \ --sign "$MACOS_SIGN_IDENTITY" "$DMG" - xcrun notarytool submit "$DMG" \ - --apple-id "$APPLE_ID" \ - --team-id "$APPLE_TEAM_ID" \ - --password "$APPLE_APP_SPECIFIC_PASSWORD" \ - --wait - xcrun stapler staple "$DMG" + notary_log="$(mktemp)" + if xcrun notarytool submit "$DMG" \ + --apple-id "$APPLE_ID" \ + --team-id "$APPLE_TEAM_ID" \ + --password "$APPLE_APP_SPECIFIC_PASSWORD" \ + --wait 2>&1 | tee "$notary_log"; then + xcrun stapler staple "$DMG" + elif grep -q "A required agreement is missing or has expired" "$notary_log"; then + echo "::warning::Apple Developer agreement is missing or expired; $DMG is signed but not notarized/stapled" + else + echo "::error::macOS notarization failed" + exit 1 + fi - name: Install NSIS (windows) if: runner.os == 'Windows' shell: pwsh diff --git a/crates/op-host-web/tests/ci_workflow.rs b/crates/op-host-web/tests/ci_workflow.rs index 1aa75be5a..7bfce0463 100644 --- a/crates/op-host-web/tests/ci_workflow.rs +++ b/crates/op-host-web/tests/ci_workflow.rs @@ -64,6 +64,24 @@ fn release_workflow_resolves_macos_signing_identity_from_keychain() { ); } +#[test] +fn release_workflow_tolerates_missing_apple_notarization_agreement_for_prerelease() { + let workflow = std::fs::read_to_string(concat!( + env!("CARGO_MANIFEST_DIR"), + "/../../.github/workflows/rust-release.yml" + )) + .expect("rust-release workflow is readable"); + + assert!( + workflow.contains("A required agreement is missing or has expired"), + "pre-release workflow should recognize Apple's external legal-agreement notarization block" + ); + assert!( + workflow.contains("signed but not notarized"), + "pre-release workflow should still upload signed DMGs when Apple legal agreements block notarization" + ); +} + #[test] fn release_workflow_installs_nsis_on_windows_runner() { let workflow = std::fs::read_to_string(concat!(