From 2015f9a91029638d327876141c85dcb3f64fa83e Mon Sep 17 00:00:00 2001 From: Dan Stillman Date: Mon, 28 Sep 2026 13:43:21 -0400 Subject: [PATCH] Re-sign Mozilla helper apps in unsigned Mac builds with custom components Mozilla's helper apps (GPU, content, etc.) use the hardened runtime and Mozilla's Team ID, so in unsigned builds they couldn't load our custom libmozglue.dylib and failed to launch. Re-sign them ad hoc. (cherry picked from commit df78b51dab9895113cae41482b9f1cd17d1d34a5) --- app/build.sh | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/app/build.sh b/app/build.sh index f5af4db27f..ccd11f1325 100755 --- a/app/build.sh +++ b/app/build.sh @@ -872,6 +872,13 @@ if [ $BUILD_MAC == 1 ]; then echo /usr/bin/codesign --verify -vvvv "$appex" done + elif [ -n "$custom_components_hash_mac" ]; then + # Mozilla's helper apps (plugin-container, GPU helper, etc.) are signed with Mozilla's Team ID + # and the hardened runtime, so without our signature they can't load custom components such as + # libmozglue.dylib and fail to launch. Re-sign them ad hoc, which removes both. (Signed builds + # re-sign everything with our Developer ID above.) + find "$APPDIR/Contents/MacOS" -maxdepth 1 -name '*.app' -not -name "updater.app" -print0 \ + | xargs -0 /usr/bin/codesign --force --sign - fi # Build and notarize disk image