From 782aea76f95312a511cc174085de2c6dc960a283 Mon Sep 17 00:00:00 2001 From: OmikronApex Date: Fri, 10 Jul 2026 14:03:15 +0200 Subject: [PATCH] fix(nightly): preserve mac entitlements through Velopack re-sign MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit vpk pack re-signs the .app; without --signEntitlements the codesign strips electron-builder's entitlements (com.apple.security.device.audio-input et al). Hardened-runtime app then gets microphone auto-denied by TCC with no prompt — root cause of silent-input nightly reports. Co-Authored-By: Claude Fable 5 --- .github/workflows/nightly.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 5bba85e..98cc7e0 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -287,6 +287,11 @@ jobs: # first, then hand vpk --notaryProfile. Do NOT pass --keychain: # notarytool defaults to the login keychain, matching vpk's own # internal notarytool call. + # --signEntitlements is mandatory: vpk re-signs the bundle, and a + # codesign without an entitlements file STRIPS the ones + # electron-builder applied (audio-input, allow-jit, ...) — the + # hardened-runtime app then gets mic access auto-denied with no + # TCC prompt. xcrun notarytool store-credentials "velopack-notary" \ --apple-id "$APPLE_ID" \ --password "$APPLE_APP_SPECIFIC_PASSWORD" \ @@ -299,6 +304,7 @@ jobs: --mainExe "$mainexe" \ -o release/velopack \ --signAppIdentity "$APPLE_SIGNING_IDENTITY" \ + --signEntitlements resources/entitlements.mac.plist \ --notaryProfile "velopack-notary" fi