More signing fixes. Also update FMOD Studio.

meow-7.2.2
Tonya Souther 2020-02-29 16:50:08 -06:00
parent b0b16a622a
commit fc030684cb
2 changed files with 40 additions and 6 deletions

View File

@ -1058,11 +1058,11 @@
<key>archive</key>
<map>
<key>hash</key>
<string>d892f61440dd1888327d764b04158c88</string>
<string>d62d82f427dfe77e417b50f503b295b6</string>
<key>hash_algorithm</key>
<string>md5</string>
<key>url</key>
<string>file:///opt/firestorm/fmodstudio-2.00.05-darwin-192862021.tar.bz2</string>
<string>file:///opt/firestorm/fmodstudio-2.00.07-darwin-200602210.tar.bz2</string>
</map>
<key>name</key>
<string>darwin</string>
@ -3580,9 +3580,9 @@ Copyright (c) 2012, 2014, 2015, 2016 nghttp2 contributors</string>
<key>archive</key>
<map>
<key>hash</key>
<string>e5635e173c75dc0675b48ab5f5e4868b</string>
<string>e5a4261599f47045428b520b20405022</string>
<key>url</key>
<string>http://automated-builds-secondlife-com.s3.amazonaws.com/ct2/12143/71451/vlc_bin-2.2.8.511703-darwin64-511703.tar.bz2</string>
<string>file:///opt/firestorm/vlc_bin-3.0.8.200601940-darwin64-200601940.tar.bz2</string>
</map>
<key>name</key>
<string>darwin64</string>

View File

@ -1766,11 +1766,45 @@ class DarwinManifest(ViewerManifest):
signed=False
sign_attempts=3
sign_retry_wait=15
#<FS:TS> The order of these is critical. When two things need signing and one is contained within the
# other, they must be signed from the innermost out.
things_to_sign = ['Frameworks/Chromium Embedded Framework.framework/Chromium Embedded Framework',
'Resources/SLPlugin.app/Contents/Frameworks/DullahanHelper.app',
'Resources/SLPlugin.app',
'Resources/SLVoice',
'Resources/mac-crash-logger.app']
#<FS:TS> Even though we're signing the old version of SLVoice used with Vivox for OpenSim,
# its presence will prevent the application bundle from being notarized because that version
# was compiled against a version of the macOS SDK older than 10.9.
if self.fs_is_opensim():
things_to_sign.append('Resources/voice_os/SLVoice')
while (not signed) and (sign_attempts > 0):
try:
sign_attempts-=1;
self.run_command(
sign_attempts-=1
#<FS:TS> This is ugly as hell, but it's the only way to make sure that every dylib in the
# entire package gets signed, as required for notarization. Apparently the --deep option
# isn't sufficient any more. Don't ask me why.
contents_dir = os.path.join(app_in_dmg, 'Contents')
try:
all_dylibs = subprocess.check_output(['find', contents_dir, '-name', '*.dylib', '-print'])
except subprocess.CalledProcessError as err:
sys.exit("failed to get list of dylib files")
for dylib in all_dylibs.split('\n'):
if dylib: # ignore any empty lines
self.run_command(
['codesign', '--verbose', '--deep', '--force', '--option=runtime',
'--keychain', viewer_keychain, '--sign', identity,
dylib])
for item in things_to_sign:
# Note: See blurb above about names of keychains
sign_path = os.path.join(contents_dir, item)
print "Signing %s" % sign_path
self.run_command(
['codesign', '--verbose', '--deep', '--force', '--option=runtime',
'--keychain', viewer_keychain, '--sign', identity,
sign_path])
print "Signing main app bundle %s" % app_in_dmg
self.run_command(
['codesign', '--verbose', '--deep', '--force', '--option=runtime',
'--keychain', viewer_keychain, '--sign', identity,
app_in_dmg])