Skip to content

Name the executable in each update zip after its bundle - #575

Merged
thesiti92 merged 2 commits into
mainfrom
fix/update-zip-executable-name
Sep 24, 2026
Merged

thesiti92 merged 2 commits into
mainfrom
fix/update-zip-executable-name

Conversation

@thesiti92

Copy link
Copy Markdown
Contributor

Why

Squirrel renames an install to the update's CFBundleExecutable, not to the zip's folder name (SQRLInstaller renamedTargetIfNeededWithTargetURL: compares the installed folder name with the update's executable name). The Review zip from #549 carries Review.app whose executable is still Whiteboard, so a 0.0.33 Review.app updating to 0.0.34 was renamed to Whiteboard.app, the Dock tile broke, and ShipIt's relaunch failed at the old path. Seen on a real 0.0.33 → 0.0.34 update today.

The runner smoke run passed because its starting copy (the .59 Review zip) already had mismatched executable and folder names, which turns the rename off before that comparison runs. It did not model a genuine pre-rename install.

What changes

  • notarize-macos.sh: for each zip whose bundle name differs from the build's, rename Contents/MacOS/<exe>, set CFBundleExecutable, re-sign the outer bundle with the same identity and app.plist entitlements (nested helpers and frameworks keep their signatures), verify, then notarize and staple that copy on its own before zipping. One build, one extra notarization per extra zip.
  • validate-release-artifacts.mjs: assertZipBundle now also reads each zip's Info.plist and fails when the executable name differs from the bundle name. Against the published 0.0.34 Review zip it fails with the exact message; against a fixed copy it passes.
  • Comments and README say "executable name" instead of "folder name".

Validation

  • Script tests: 25 pass. pnpm lint, oxfmt, shellcheck, bash -n.
  • Dry run on the real 0.0.34 Review zip: after the executable rename and an outer-bundle-only re-sign, codesign --verify --deep --strict passes and nested code retains its team identity.
  • Needs a preview release to prove the signed, notarized copy end to end from an install whose executable and folder names match (e.g. preview .56 or stable 0.0.33).

Fixes the rename for every remaining Review.app install once 0.0.35 ships. Installs already renamed to Whiteboard.app by 0.0.34 are unaffected either way.

Squirrel renames an install to the update's CFBundleExecutable, not to
the zip's folder name (SQRLInstaller renamedTargetIfNeeded). The Review
zip from #549 carried Review.app with an executable still called
Whiteboard, so a 0.0.33 Review.app updating to 0.0.34 was renamed to
Whiteboard.app, its Dock tile broke, and ShipIt's relaunch failed at the
old path. The runner smoke passed only because its starting copy already
had mismatched names, which disables the rename before that logic runs.

For each zip whose bundle name differs from the build's, rename the
executable to match, fix CFBundleExecutable, re-sign the outer bundle
with the same identity and entitlements (nested code keeps its
signatures), and notarize and staple that copy on its own. The artifact
validator now rejects a zip whose executable name differs from its
bundle name, which is what would have caught 0.0.34.

Agent-Session: aad32659-bbbe-45b2-b163-317afc1a6a83
Agent-Session: 86ff23ef-37b3-4d9f-803a-8ceb8131e905
Agent-Session: d09f44bd-8378-4504-9cc6-dabf1d8c8bfd
Agent-Session: 3ccb2131-4dfc-455e-9130-f3ab322987f0
Agent-Session: a704726b-4b5e-4b6a-86b8-558acae718b8
Agent-Session: 5705d2ed-c03d-4268-a647-86ef3e2e5719
Agent-Session: aad32659-bbbe-45b2-b163-317afc1a6a83
Agent-Session: 86ff23ef-37b3-4d9f-803a-8ceb8131e905
Agent-Session: d09f44bd-8378-4504-9cc6-dabf1d8c8bfd
Agent-Session: 3ccb2131-4dfc-455e-9130-f3ab322987f0
Agent-Session: a704726b-4b5e-4b6a-86b8-558acae718b8
Agent-Session: 5705d2ed-c03d-4268-a647-86ef3e2e5719
@thesiti92
thesiti92 merged commit a9b14fe into main Sep 24, 2026
1 check passed
@thesiti92
thesiti92 deleted the fix/update-zip-executable-name branch September 24, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants