Re-sign Mozilla helper apps in unsigned Mac builds with custom components

Mozilla's helper apps (GPU, content, etc.) use the hardened runtime and
Mozilla's Team ID, so in unsigned builds they couldn't load our custom
libmozglue.dylib and failed to launch. Re-sign them ad hoc.

(cherry picked from commit df78b51dab)
This commit is contained in:
Dan Stillman 2026-09-28 13:43:21 -04:00
parent dcf6df66e2
commit 2015f9a910

View file

@ -872,6 +872,13 @@ if [ $BUILD_MAC == 1 ]; then
echo
/usr/bin/codesign --verify -vvvv "$appex"
done
elif [ -n "$custom_components_hash_mac" ]; then
# Mozilla's helper apps (plugin-container, GPU helper, etc.) are signed with Mozilla's Team ID
# and the hardened runtime, so without our signature they can't load custom components such as
# libmozglue.dylib and fail to launch. Re-sign them ad hoc, which removes both. (Signed builds
# re-sign everything with our Developer ID above.)
find "$APPDIR/Contents/MacOS" -maxdepth 1 -name '*.app' -not -name "updater.app" -print0 \
| xargs -0 /usr/bin/codesign --force --sign -
fi
# Build and notarize disk image