Skip to content

fix: validate universal app binaries with supported lipo order (#45) - #52

Merged
bigduu merged 1 commit into
masterfrom
nova/fix/45-lipo-order
Sep 22, 2026
Merged

bigduu merged 1 commit into
masterfrom
nova/fix/45-lipo-order

Conversation

@bigduu

@bigduu bigduu commented Sep 21, 2026

Copy link
Copy Markdown
Owner

Summary

  • use Xcode lipo's supported input-file-first -verify_arch grammar for both the source universal executable and the copy installed into Nova.app
  • make the hermetic release-workflow fixture reject the historical operation-first ordering
  • verify exactly two successful architecture checks and reject an arm64-only fixture before signing or archive creation

Closes #45

Test plan

Automated / hermetic

  • git diff --check
  • bash -n packaging/macos/package-development-app.sh scripts/test-release-workflow.sh
  • scripts/test-release-workflow.sh
    • release YAML/DAG/shell checks
    • release-tag integrity checks
    • universal mock app assembly/signing/archive checks
    • explicit rejection of lipo -verify_arch arm64 x86_64 <input>
    • exact input-file-first calls for source and app-copy verification
    • thin mock binary rejection before codesign/archive
  • adversarial regression run: applied only the strengthened test to a detached baseline worktree while retaining the old production syntax; the suite failed before the packaging success marker

Real macOS/Xcode acceptance

Used the installed universal nova 0.2.1 executable (x86_64 arm64):

  • supported form lipo <binary> -verify_arch arm64 x86_64 exited 0
  • historical form exited 1 and parsed the binary path as an architecture
  • full development app packaging succeeded to an isolated /tmp output
  • independently verified:
    • app executable remains x86_64 arm64
    • strict ad-hoc codesign verification
    • com.zenith.nova bundle identity and exact 0.2.1 plist fields
    • executable --version / --help
    • all 10 icon representations
    • required archive members and checksum
  • created a real arm64-only Mach-O; direct verification and full packaging both exited 1, no zip/checksum was emitted, and xtrace confirmed the script stopped at the source lipo check before codesign or ditto

Non-goals

  • no version bump or release publication
  • no Developer ID, hardened runtime, notarization, or stapling changes
  • no updater or application lifecycle changes

Use lipo's input-file-first verify_arch grammar for both the source
binary and the copy installed into Nova.app. Strengthen the release
workflow fixture so the historical order fails and thin binaries are
rejected before signing or archiving.
@bigduu bigduu added the review:agent Agent review complete; human final review may proceed label Sep 21, 2026
@bigduu
bigduu merged commit 9607b07 into master Sep 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review:agent Agent review complete; human final review may proceed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[nova] fix: validate universal app binaries with supported lipo argument order

1 participant