Simplify dylib signing process and ensure resource libs are signed in mac crafter
authorClaudio Cambra <claudio.cambra@nextcloud.com>
Sat, 22 Jun 2024 09:29:52 +0000 (17:29 +0800)
committerClaudio Cambra <developer@claudiocambra.com>
Mon, 8 Jul 2024 07:41:45 +0000 (15:41 +0800)
Signed-off-by: Claudio Cambra <claudio.cambra@nextcloud.com>
admin/osx/mac-crafter/Sources/Utils/Codesign.swift
admin/osx/mac-crafter/Sources/Utils/Library.swift [deleted file]

index b8ffb78679929a44f3506888efbc2eea3fc4386c..16da33eb363e068fd717b6337738e02cad79b646 100644 (file)
@@ -19,7 +19,15 @@ enum CodeSigningError: Error {
 }
 
 enum AppBundleSigningError: Error {
-    case couldNotEnumeratePlugins(String)
+    case couldNotEnumerate(String)
+}
+
+func isLibrary(_ path: String) -> Bool {
+    path.hasSuffix(".dylib") || path.hasSuffix(".framework")
+}
+
+func isAppExtension(_ path: String) -> Bool {
+    path.hasSuffix(".appex")
 }
 
 func codesign(
@@ -34,30 +42,30 @@ func codesign(
     }
 }
 
-func codesignClientAppBundle(
-    at clientAppDir: String, withCodeSignIdentity codeSignIdentity: String
-) throws {
-    print("Code-signing Nextcloud Desktop Client libraries and frameworks...")
-
-    let clientFrameworksDir = "\(clientAppDir)/Contents/Frameworks"
+func recursivelyCodesign(path: String, identity: String) throws {
     let fm = FileManager.default
-    let clientLibs = try fm.contentsOfDirectory(atPath: clientFrameworksDir)
-    for lib in clientLibs {
-        guard isLibrary(lib) else { continue }
-        try codesign(identity: codeSignIdentity, path: "\(clientFrameworksDir)/\(lib)")
-    }
-
-    let clientPluginsDir = "\(clientAppDir)/Contents/PlugIns"
-    guard let clientPluginsEnumerator = fm.enumerator(atPath: clientPluginsDir) else {
-        throw AppBundleSigningError.couldNotEnumeratePlugins(
-            "Failed to list craft plugins directory at \(clientPluginsDir)."
+    guard let pathEnumerator = fm.enumerator(atPath: path) else {
+        throw AppBundleSigningError.couldNotEnumerate(
+            "Failed to enumerate directory at \(path)."
         )
     }
 
-    for case let plugin as String in clientPluginsEnumerator {
-        guard isLibrary(plugin) else { continue }
-        try codesign(identity: codeSignIdentity, path: "\(clientPluginsDir)/\(plugin)")
+    for case let enumeratedItem as String in pathEnumerator {
+        guard isLibrary(enumeratedItem) || isAppExtension(enumeratedItem) else { continue }
+        try codesign(identity: identity, path: "\(path)/\(enumeratedItem)")
     }
+}
+
+func codesignClientAppBundle(
+    at clientAppDir: String, withCodeSignIdentity codeSignIdentity: String
+) throws {
+    print("Code-signing Nextcloud Desktop Client libraries, frameworks and plugins...")
+
+    let clientContentsDir = "\(clientAppDir)/Contents"
+
+    try recursivelyCodesign(path: "\(clientContentsDir)/Frameworks", identity: codeSignIdentity)
+    try recursivelyCodesign(path: "\(clientContentsDir)/PlugIns", identity: codeSignIdentity)
+    try recursivelyCodesign(path: "\(clientContentsDir)/Resources", identity: codeSignIdentity)
 
     print("Code-signing Nextcloud Desktop Client app bundle...")
     try codesign(identity: codeSignIdentity, path: clientAppDir)
diff --git a/admin/osx/mac-crafter/Sources/Utils/Library.swift b/admin/osx/mac-crafter/Sources/Utils/Library.swift
deleted file mode 100644 (file)
index 1304f03..0000000
+++ /dev/null
@@ -1,19 +0,0 @@
-/*
- * Copyright (C) 2024 by Claudio Cambra <claudio.cambra@nextcloud.com>
- *
- * This program is free software; you can redistribute it and/or modify
- * it under the terms of the GNU General Public License as published by
- * the Free Software Foundation; either version 2 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful, but
- * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
- * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
- * for more details.
- */
-
-import Foundation
-
-func isLibrary(_ path: String) -> Bool {
-    path.hasSuffix(".dylib") || path.hasSuffix(".framework")
-}