From d966eae50d8559c862a0e1d5efcf23461374d044 Mon Sep 17 00:00:00 2001 From: Tim Haasdyk Date: Fri, 25 Sep 2026 12:46:43 +0200 Subject: [PATCH] Ship the SDK's universal Mac Catalyst bundle, not a per-arch one The DMG was built from maccatalyst-arm64/, an intermediate of the multi-RID build that lacks the bundle resources (wwwroot, app icon), so the app opened to "There is no content at". The SDK does merge and sign a complete universal bundle, but SelfContained=true made the .NET SDK give the RID-less outer build the host RID, so it landed in bin/.../osx-arm64/ and looked missing. UseCurrentRuntimeIdentifier=false puts it back in bin/.../net10.0-maccatalyst/ (macios does the same for NativeAOT universal builds), which replaces the hand-rolled lipo merge and re-sign. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/fw-lite.yaml | 34 ++------------------- backend/FwLite/FwLiteMaui/FwLiteMaui.csproj | 2 ++ 2 files changed, 5 insertions(+), 31 deletions(-) diff --git a/.github/workflows/fw-lite.yaml b/.github/workflows/fw-lite.yaml index 160aa27bfe..f9de7ca88c 100644 --- a/.github/workflows/fw-lite.yaml +++ b/.github/workflows/fw-lite.yaml @@ -385,38 +385,10 @@ jobs: ASC_PRIVATE_KEY: ${{ secrets.APPLE_APPSTORECONNECT_PRIVATE_KEY }} run: | set -euo pipefail - # `dotnet build` with two RIDs emits a separate per-arch .app for each; it does NOT lipo them - # into one universal bundle (that only happens on `dotnet publish`, which we can't use here — - # publish trips EF's runtime model build under Mac Catalyst, see #1603). So merge the two - # per-arch bundles into a universal one ourselves, then re-sign (lipo invalidates signatures). - X64="bin/Release/net10.0-maccatalyst/maccatalyst-x64/FieldWorks Lite.app" - ARM="bin/Release/net10.0-maccatalyst/maccatalyst-arm64/FieldWorks Lite.app" - for b in "$X64" "$ARM"; do [ -d "$b" ] || { echo "Missing per-arch bundle: $b" >&2; exit 1; }; done - APP="$RUNNER_TEMP/universal/FieldWorks Lite.app" - rm -rf "$RUNNER_TEMP/universal"; mkdir -p "$RUNNER_TEMP/universal" - cp -R "$ARM" "$APP" - # lipo each Mach-O file in the copy with its x64 counterpart, writing back into the copy - # (managed .dlls are arch-neutral, left as-is). - while IFS= read -r f; do - rel="${f#"$APP"/}" - x64f="$X64/$rel" - [ -f "$x64f" ] || continue - if file -b "$f" | grep -q 'Mach-O'; then - lipo -create "$f" "$x64f" -output "$f" - fi - done < <(find "$APP" -type f) - # Re-sign after the merge (lipo invalidates signatures). --deep is unreliable for notarization, - # so sign inside-out: every nested Mach-O with the hardened runtime first (deepest paths first), - # then seal the app bundle with the entitlements. Verify before packaging. - while IFS= read -r f; do - if file -b "$f" | grep -q 'Mach-O'; then - codesign --force --timestamp --options runtime --sign "$CODESIGN_IDENTITY" "$f" - fi - done < <(find "$APP/Contents" -type f | awk '{print length"\t"$0}' | sort -rn | cut -f2-) - codesign --force --timestamp --options runtime \ - --entitlements Platforms/MacCatalyst/Entitlements.DeveloperId.plist \ - --sign "$CODESIGN_IDENTITY" "$APP" + # The SDK merges and signs the universal bundle here; the maccatalyst-*/ bundles are incomplete intermediates. + APP="bin/Release/net10.0-maccatalyst/FieldWorks Lite.app" codesign --verify --deep --strict --verbose=2 "$APP" + [ -f "$APP/Contents/Resources/wwwroot/index.html" ] || { echo "Missing wwwroot/index.html in $APP" >&2; exit 1; } # Fail loudly if the merged bundle isn't actually universal — the whole point is Intel + Apple Silicon. EXE="$APP/Contents/MacOS/$(/usr/libexec/PlistBuddy -c 'Print :CFBundleExecutable' "$APP/Contents/Info.plist")" ARCHS="$(lipo -archs "$EXE" 2>/dev/null || true)" diff --git a/backend/FwLite/FwLiteMaui/FwLiteMaui.csproj b/backend/FwLite/FwLiteMaui/FwLiteMaui.csproj index 1fd67f0d32..3b63fea0fa 100644 --- a/backend/FwLite/FwLiteMaui/FwLiteMaui.csproj +++ b/backend/FwLite/FwLiteMaui/FwLiteMaui.csproj @@ -18,6 +18,8 @@ referenced library and fail them with NETSDK1083. Skipped when a single RuntimeIdentifier is passed explicitly (e.g. the CI unsigned fork build's maccatalyst-arm64 compile check). --> maccatalyst-x64;maccatalyst-arm64 + + false Exe FwLiteMaui true