Files
galaxy/notarize.sh
T
George BrancoviciandClaude Opus 4.6 c9492c90ea Add code signing, notarization, and DMG packaging scripts
Enables distributing Galaxy.app to end users without Gatekeeper warnings.
Uses Samsung Developer ID Application certificate with hardened runtime.

Pipeline: cargo bundle → sign.sh → notarize.sh → package.sh → Galaxy.dmg

Entitlements:
- network.client (AWS Bedrock API calls)
- automation.apple-events (osascript for CLI install)
- cs.allow-unsigned-executable-memory (Metal shader compilation)

Orchestration scripts:
- build-debug.sh: full pipeline with debug build
- build-release.sh: full pipeline with release build

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-05-13 12:47:57 -04:00

50 lines
1.2 KiB
Bash
Executable File

#!/bin/bash
set -e
cd "$(dirname "$0")"
if [ "$1" = "--release" ]; then
APP_PATH="target/release/bundle/osx/Galaxy.app"
ZIP_PATH="target/release/bundle/osx/Galaxy.zip"
else
APP_PATH="target/debug/bundle/osx/Galaxy.app"
ZIP_PATH="target/debug/bundle/osx/Galaxy.zip"
fi
trap 'rm -f "$ZIP_PATH"' EXIT
if [ ! -d "$APP_PATH" ]; then
echo "Error: $APP_PATH not found."
exit 1
fi
echo "Verifying app is signed before notarization..."
codesign --verify --strict "$APP_PATH" || {
echo "Error: App is not properly signed. Run ./sign.sh first."
exit 1
}
echo "Creating zip for notarization submission..."
rm -f "$ZIP_PATH"
ditto -c -k --keepParent "$APP_PATH" "$ZIP_PATH"
echo "Submitting to Apple notary service (this may take a few minutes)..."
RESULT=$(xcrun notarytool submit "$ZIP_PATH" \
--keychain-profile notarytool-profile \
--wait 2>&1)
echo "$RESULT"
if ! echo "$RESULT" | grep -q "status: Accepted"; then
echo ""
echo "Error: Notarization was not accepted. Check output above."
exit 1
fi
echo "Stapling notarization ticket to app..."
xcrun stapler staple "$APP_PATH"
echo "Validating stapled ticket..."
xcrun stapler validate "$APP_PATH"
echo ""
echo "Done. Galaxy.app is notarized and stapled."