Skip to content

Fix the notarization zip step: ditto -c takes exactly one source - #122

Merged
pg83 merged 1 commit into
pg83:masterfrom
lexasoft123:fix-notarize-ditto-multi-source
Sep 24, 2026
Merged

pg83 merged 1 commit into
pg83:masterfrom
lexasoft123:fix-notarize-ditto-multi-source

Conversation

@lexasoft123

Copy link
Copy Markdown
Contributor

Follow-up to #120, which merged before this fix landed.

The bug

The notarize step builds its submission archive with

ditto -c -k --keepParent Shitty.app Pretty.app darwin-submit.zip

but ditto -c accepts exactly one source: it fails with Can't archive multiple sources. --keepParent does not change that. The command was written on the assumption that it behaves like cp, and was never run until now.

Why it matters right now

With the signing and notarization secrets set on this repo, a Release run would sign both bundles, then fail here, and package-release needs sign-notarize-darwin, so no release would be published. Before the secrets existed this step skipped gracefully with a warning, so this only bites now.

The fix

Stage both apps under one directory and archive that single directory. One file, +10/-1.

Verified

Found by running the pipeline locally end to end, and re-checked with the exact zip layout this produces:

  • notarytool submit returned Accepted for the bundles signed with the Developer ID certificate, and again with the dedicated App Store Connect key now stored in this repo's secrets, so the credential and the archive shape are both proven against Apple.
  • Both bundles stapled and validated, and spctl -a -vv -t execute reports accepted / source=Notarized Developer ID, including with the quarantine xattr set.
  • Applies cleanly on current master; actionlint reports nothing beyond this file's existing findings.

Please merge this before triggering the next Release run.

🤖 Generated with Claude Code

Found by actually running the pipeline locally end to end: built st/pt,
packaged both into app bundles, signed them with the dedicated Developer
ID Application certificate, and hit this at the submission-zip step
before ever reaching Apple.

`ditto -c` takes exactly one source ("Can't archive multiple sources") -
--keepParent does not turn it into a multi-source flag. Stage both apps
under one directory first and archive that instead.

With the fix, the rest of the pipeline ran clean against Apple's real
services: notarytool submission came back "Accepted", both bundles
stapled and validated, and spctl reports "accepted / source=Notarized
Developer ID" on both - including with the quarantine xattr set, which
is what actually happens to a browser download and is the dialog this
whole pipeline exists to prevent.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.19%. Comparing base (a2a738b) to head (9a2ec42).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #122   +/-   ##
=======================================
  Coverage   89.19%   89.19%           
=======================================
  Files          81       81           
  Lines       19898    19898           
  Branches     4751     4751           
=======================================
+ Hits        17748    17749    +1     
+ Misses        951      950    -1     
  Partials     1199     1199           

see 6 files with indirect coverage changes

Components Coverage Δ
core 89.86% <ø> (+0.02%) ⬆️
platform-wayland ∅ <ø> (∅)
renderer-vulkan 80.40% <ø> (-0.22%) ⬇️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pg83
pg83 merged commit 81f3852 into pg83:master Sep 24, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants