mirror of
https://github.com/LizardByte/Sunshine.git
synced 2026-08-07 10:20:46 +00:00
feat(macos): build a signed .app bundle in a .dmg (#4759)
This commit is contained in:
@@ -0,0 +1,181 @@
|
||||
---
|
||||
name: CI-macOS
|
||||
permissions: {}
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
publish_release:
|
||||
required: true
|
||||
type: string
|
||||
release_commit:
|
||||
required: true
|
||||
type: string
|
||||
release_version:
|
||||
required: true
|
||||
type: string
|
||||
secrets:
|
||||
# email address
|
||||
APPLE_ID:
|
||||
required: false
|
||||
# 10-character Team ID
|
||||
APPLE_TEAM_ID:
|
||||
required: false
|
||||
# app-specific password in APPLE_ID's account that must be named "notarytool"
|
||||
# https://support.apple.com/en-us/102654
|
||||
APPLE_NOTARYTOOL_PASSWORD:
|
||||
required: false
|
||||
# Developer ID Application: Full Name (TEAMIDHERE)
|
||||
APPLE_CODESIGN_IDENTITY:
|
||||
required: false
|
||||
# pkcs12 export from Xcode in base64
|
||||
APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64:
|
||||
required: false
|
||||
# pkcs12 password added by Xcode export
|
||||
APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_P12_PASSWORD:
|
||||
required: false
|
||||
|
||||
env:
|
||||
BRANCH: ${{ github.head_ref || github.ref_name }}
|
||||
BUILD_VERSION: ${{ inputs.release_version }}
|
||||
COMMIT: ${{ inputs.release_commit }}
|
||||
|
||||
jobs:
|
||||
build_dmg:
|
||||
name: ${{ matrix.name }}
|
||||
permissions:
|
||||
contents: read
|
||||
runs-on: ${{ matrix.os }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: "macos-14"
|
||||
name: "macOS-arm64"
|
||||
- os: "macos-15-intel"
|
||||
name: "macOS-x86_64"
|
||||
steps:
|
||||
- name: Install Apple certificate
|
||||
uses: apple-actions/import-codesign-certs@b610f78488812c1e56b20e6df63ec42d833f2d14 # v6.0.0
|
||||
if: inputs.publish_release == 'true'
|
||||
with:
|
||||
p12-file-base64: ${{ secrets.APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64 }}
|
||||
p12-password: ${{ secrets.APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_P12_PASSWORD }}
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
with:
|
||||
submodules: recursive
|
||||
|
||||
- name: Install dependencies
|
||||
timeout-minutes: 5
|
||||
run: |
|
||||
brew install --force \
|
||||
cmake \
|
||||
doxygen \
|
||||
graphviz \
|
||||
node \
|
||||
pkgconf \
|
||||
icu4c@78 \
|
||||
miniupnpc \
|
||||
openssl@3 \
|
||||
opus
|
||||
|
||||
- name: Configure
|
||||
env:
|
||||
APPLE_CODESIGN_IDENTITY: ${{ secrets.APPLE_CODESIGN_IDENTITY }}
|
||||
run: |
|
||||
mkdir -p build
|
||||
cmake \
|
||||
-B build \
|
||||
-S . \
|
||||
-DBUILD_WERROR=ON \
|
||||
-DCMAKE_BUILD_TYPE=Release \
|
||||
-DOPENSSL_ROOT_DIR="$(brew --prefix openssl@3 2>/dev/null)" \
|
||||
-DOpus_ROOT_DIR="$(brew --prefix opus 2>/dev/null)" \
|
||||
-DSUNSHINE_PUBLISHER_NAME="${GITHUB_REPOSITORY_OWNER}" \
|
||||
-DSUNSHINE_PUBLISHER_WEBSITE="https://app.lizardbyte.dev" \
|
||||
-DSUNSHINE_PUBLISHER_ISSUE_URL="https://app.lizardbyte.dev/support" \
|
||||
-DAPPLE_CODESIGN_IDENTITY="${APPLE_CODESIGN_IDENTITY}"
|
||||
|
||||
- name: Build
|
||||
run: cmake --build build -j "$(sysctl -n hw.ncpu)"
|
||||
|
||||
- name: Package DMG
|
||||
env:
|
||||
APPLE_ID: ${{ secrets.APPLE_ID }}
|
||||
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
|
||||
APPLE_NOTARYTOOL_PASSWORD: ${{ secrets.APPLE_NOTARYTOOL_PASSWORD }}
|
||||
APPLE_CODESIGN_IDENTITY: ${{ secrets.APPLE_CODESIGN_IDENTITY }}
|
||||
SHOULD_SIGN: ${{ inputs.publish_release }}
|
||||
run: |
|
||||
# build DMG and sign everything (see cmake/packaging/macos.cmake)
|
||||
# cpack can rarely fail with "hdiutil: create failed - Resource busy"
|
||||
# so let's allow 1 retry
|
||||
if ! cpack -G DragNDrop --config build/CPackConfig.cmake; then
|
||||
echo "cpack failed, retrying once with verbose..."
|
||||
if ! cpack -G DragNDrop --config build/CPackConfig.cmake --verbose; then
|
||||
echo "cpack failed again. Aborting."
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Notarize
|
||||
if [[ "${SHOULD_SIGN}" == "true" && -n "${APPLE_NOTARYTOOL_PASSWORD}" ]]; then
|
||||
# Notarizing allows the signed .app to run on any Mac with no prompts.
|
||||
# If you don't notarize, users must jump through the "Open Anyway" hoop as well as run
|
||||
# `xattr -cr /Applications/Sunshine.app` to remove quarantine.
|
||||
if [[ -n "${APPLE_NOTARYTOOL_PASSWORD}" ]]; then
|
||||
xcrun notarytool submit build/cpack_artifacts/Sunshine.dmg \
|
||||
--apple-id "${APPLE_ID}" \
|
||||
--team-id "${APPLE_TEAM_ID}" \
|
||||
--password "${APPLE_NOTARYTOOL_PASSWORD}" \
|
||||
--wait
|
||||
xcrun stapler staple -v build/cpack_artifacts/Sunshine.dmg
|
||||
fi
|
||||
fi
|
||||
|
||||
mkdir -p artifacts
|
||||
mv build/cpack_artifacts/Sunshine.dmg \
|
||||
artifacts/Sunshine-${{ matrix.name }}.dmg
|
||||
|
||||
- name: Test
|
||||
id: test
|
||||
working-directory: build/tests
|
||||
run: ./test_sunshine --gtest_color=yes --gtest_output=xml:test_results.xml
|
||||
|
||||
- name: Generate gcov report
|
||||
id: test_report
|
||||
# any except canceled or skipped
|
||||
if: >-
|
||||
always() &&
|
||||
(steps.test.outcome == 'success' || steps.test.outcome == 'failure')
|
||||
working-directory: build
|
||||
run: |
|
||||
python -m pip install "../scripts[test]"
|
||||
python -m gcovr . -r ../src \
|
||||
--exclude-noncode-lines \
|
||||
--exclude-throw-branches \
|
||||
--exclude-unreachable-branches \
|
||||
--xml-pretty \
|
||||
-j "$(sysctl -n hw.ncpu)" \
|
||||
-o coverage.xml
|
||||
|
||||
- name: Upload coverage artifact
|
||||
if: >-
|
||||
always() &&
|
||||
(steps.test_report.outcome == 'success')
|
||||
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
|
||||
with:
|
||||
name: coverage-${{ matrix.name }}
|
||||
path: |
|
||||
build/coverage.xml
|
||||
build/tests/test_results.xml
|
||||
if-no-files-found: error
|
||||
|
||||
- name: Upload Artifacts
|
||||
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
|
||||
with:
|
||||
name: build-${{ matrix.name }}
|
||||
path: artifacts/
|
||||
if-no-files-found: error
|
||||
@@ -89,6 +89,26 @@ jobs:
|
||||
GH_TOKEN: ${{ secrets.GH_BOT_TOKEN }}
|
||||
GIT_EMAIL: ${{ secrets.GH_BOT_EMAIL }}
|
||||
|
||||
build-macos:
|
||||
name: macOS
|
||||
needs: release-setup
|
||||
permissions:
|
||||
contents: read
|
||||
uses: ./.github/workflows/ci-macos.yml
|
||||
with:
|
||||
publish_release: ${{ needs.release-setup.outputs.publish_release }}
|
||||
release_commit: ${{ needs.release-setup.outputs.release_commit }}
|
||||
release_version: ${{ needs.release-setup.outputs.release_version }}
|
||||
secrets:
|
||||
APPLE_ID: ${{ secrets.APPLE_ID }}
|
||||
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
|
||||
APPLE_NOTARYTOOL_PASSWORD: ${{ secrets.APPLE_NOTARYTOOL_PASSWORD }}
|
||||
APPLE_CODESIGN_IDENTITY: ${{ secrets.APPLE_CODESIGN_IDENTITY }}
|
||||
APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64: >-
|
||||
${{ secrets.APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64 }}
|
||||
APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_P12_PASSWORD: >-
|
||||
${{ secrets.APPLE_DEVELOPER_ID_APPLICATION_CERTIFICATE_P12_PASSWORD }}
|
||||
|
||||
build-linux:
|
||||
name: Linux
|
||||
needs: release-setup
|
||||
@@ -161,6 +181,7 @@ jobs:
|
||||
- build-linux
|
||||
- build-archlinux
|
||||
- build-linux-flatpak
|
||||
- build-macos
|
||||
- build-homebrew
|
||||
- build-windows
|
||||
permissions:
|
||||
@@ -182,6 +203,12 @@ jobs:
|
||||
- name: Archlinux
|
||||
coverage: true
|
||||
pr: true
|
||||
- name: macOS-arm64
|
||||
coverage: true
|
||||
pr: true
|
||||
- name: macOS-x86_64
|
||||
coverage: true
|
||||
pr: true
|
||||
- name: Homebrew-macos-14
|
||||
coverage: false
|
||||
pr: true
|
||||
|
||||
Reference in New Issue
Block a user