Name the executable in each update zip after its bundle - #575
Merged
Merged
Conversation
Squirrel renames an install to the update's CFBundleExecutable, not to the zip's folder name (SQRLInstaller renamedTargetIfNeeded). The Review zip from #549 carried Review.app with an executable still called Whiteboard, so a 0.0.33 Review.app updating to 0.0.34 was renamed to Whiteboard.app, its Dock tile broke, and ShipIt's relaunch failed at the old path. The runner smoke passed only because its starting copy already had mismatched names, which disables the rename before that logic runs. For each zip whose bundle name differs from the build's, rename the executable to match, fix CFBundleExecutable, re-sign the outer bundle with the same identity and entitlements (nested code keeps its signatures), and notarize and staple that copy on its own. The artifact validator now rejects a zip whose executable name differs from its bundle name, which is what would have caught 0.0.34. Agent-Session: aad32659-bbbe-45b2-b163-317afc1a6a83 Agent-Session: 86ff23ef-37b3-4d9f-803a-8ceb8131e905 Agent-Session: d09f44bd-8378-4504-9cc6-dabf1d8c8bfd Agent-Session: 3ccb2131-4dfc-455e-9130-f3ab322987f0 Agent-Session: a704726b-4b5e-4b6a-86b8-558acae718b8 Agent-Session: 5705d2ed-c03d-4268-a647-86ef3e2e5719
sidkmenon
approved these changes
Sep 24, 2026
Agent-Session: aad32659-bbbe-45b2-b163-317afc1a6a83 Agent-Session: 86ff23ef-37b3-4d9f-803a-8ceb8131e905 Agent-Session: d09f44bd-8378-4504-9cc6-dabf1d8c8bfd Agent-Session: 3ccb2131-4dfc-455e-9130-f3ab322987f0 Agent-Session: a704726b-4b5e-4b6a-86b8-558acae718b8 Agent-Session: 5705d2ed-c03d-4268-a647-86ef3e2e5719
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Squirrel renames an install to the update's
CFBundleExecutable, not to the zip's folder name (SQRLInstaller renamedTargetIfNeededWithTargetURL:compares the installed folder name with the update's executable name). The Review zip from #549 carriesReview.appwhose executable is stillWhiteboard, so a 0.0.33Review.appupdating to 0.0.34 was renamed toWhiteboard.app, the Dock tile broke, and ShipIt's relaunch failed at the old path. Seen on a real 0.0.33 → 0.0.34 update today.The runner smoke run passed because its starting copy (the .59 Review zip) already had mismatched executable and folder names, which turns the rename off before that comparison runs. It did not model a genuine pre-rename install.
What changes
notarize-macos.sh: for each zip whose bundle name differs from the build's, renameContents/MacOS/<exe>, setCFBundleExecutable, re-sign the outer bundle with the same identity andapp.plistentitlements (nested helpers and frameworks keep their signatures), verify, then notarize and staple that copy on its own before zipping. One build, one extra notarization per extra zip.validate-release-artifacts.mjs:assertZipBundlenow also reads each zip'sInfo.plistand fails when the executable name differs from the bundle name. Against the published 0.0.34 Review zip it fails with the exact message; against a fixed copy it passes.Validation
pnpm lint,oxfmt,shellcheck,bash -n.codesign --verify --deep --strictpasses and nested code retains its team identity.Fixes the rename for every remaining
Review.appinstall once 0.0.35 ships. Installs already renamed toWhiteboard.appby 0.0.34 are unaffected either way.