-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathbuild.sh
More file actions
executable file
·83 lines (73 loc) · 3.25 KB
/
Copy pathbuild.sh
File metadata and controls
executable file
·83 lines (73 loc) · 3.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
#!/bin/bash
# Build Valkyrie and assemble a runnable .app bundle.
#
# Needs only the Xcode Command Line Tools — no full Xcode. Swift Package Manager
# produces the executable and this script wraps it in the bundle macOS expects.
set -e
cd "$(dirname "$0")"
APP="Valkyrie.app"
CONTENTS="$APP/Contents"
VERSION="${VERSION:-1.0.0}"
echo ">>> Building (release)..."
swift build -c release
echo ">>> Assembling $APP ..."
rm -rf "$APP"
mkdir -p "$CONTENTS/MacOS" "$CONTENTS/Resources"
cp .build/release/Valkyrie "$CONTENTS/MacOS/Valkyrie"
# Ship the flash engine, the lz4 decompressor and libusb inside the bundle so the
# app needs nothing installed. Without this, a user would have to clone a repo,
# install four Homebrew packages and compile C++ before flashing anything.
if [ -d Vendor ]; then
mkdir -p "$CONTENTS/Resources/bin"
cp Vendor/heimdall Vendor/lz4 Vendor/libusb-1.0.0.dylib "$CONTENTS/Resources/bin/"
chmod +x "$CONTENTS/Resources/bin/heimdall" "$CONTENTS/Resources/bin/lz4"
echo " bundled: heimdall, lz4, libusb"
fi
if [ -f Resources/Valkyrie.icns ]; then
cp Resources/Valkyrie.icns "$CONTENTS/Resources/Valkyrie.icns"
ICON_ENTRY="<key>CFBundleIconFile</key><string>Valkyrie</string>"
else
ICON_ENTRY=""
fi
cat > "$CONTENTS/Info.plist" <<PLIST
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>CFBundleName</key><string>Valkyrie</string>
<key>CFBundleDisplayName</key><string>Valkyrie</string>
<key>CFBundleIdentifier</key><string>dev.local.valkyrie</string>
<key>CFBundleExecutable</key><string>Valkyrie</string>
<key>CFBundlePackageType</key><string>APPL</string>
<key>CFBundleShortVersionString</key><string>$VERSION</string>
<key>CFBundleVersion</key><string>$VERSION</string>
<key>LSMinimumSystemVersion</key><string>13.0</string>
<key>NSHighResolutionCapable</key><true/>
<key>LSApplicationCategoryType</key><string>public.app-category.utilities</string>
$ICON_ENTRY
</dict>
</plist>
PLIST
# Strip extended attributes before signing. They travel into a zip as AppleDouble
# "._" files, which some unzip tools materialise and codesign then counts as
# unsealed additions — the app looks tampered with on the user's machine.
xattr -cr "$APP" 2>/dev/null || true
# Ad-hoc signature so macOS will launch it locally without a developer certificate.
# The nested binaries are signed first — signing the bundle alone leaves them invalid.
for nested in "$CONTENTS/Resources/bin/"*; do
[ -e "$nested" ] && codesign --force --sign - "$nested" 2>/dev/null
done
codesign --force --sign - "$APP" 2>/dev/null || echo " (ad-hoc signing skipped)"
echo ">>> Built $(pwd)/$APP"
# Optional: ./build.sh package -> a release archive.
#
# --norsrc --noextattr matter. Without them the archive carries AppleDouble
# entries, and any unzip tool that materialises them as "._" files makes codesign
# report the app as tampered with on the user's machine.
if [ "${1:-}" = "package" ]; then
ZIP="Valkyrie-$VERSION-AppleSilicon.zip"
rm -f "$ZIP"
ditto -c -k --keepParent --norsrc --noextattr "$APP" "$ZIP"
echo ">>> Packaged $(pwd)/$ZIP"
codesign --verify --deep --strict "$APP" && echo ">>> Signature verifies"
fi