|
38 | 38 | mkdir -p "$BUNDLED_DIR" |
39 | 39 |
|
40 | 40 | USE_LOCAL_AXE=false |
| 41 | +AXE_ARCHIVE_FLAVOR="local-signed" |
41 | 42 | if [ -z "${AXE_FORCE_REMOTE}" ] && [ "${AXE_USE_LOCAL:-0}" = "1" ]; then |
42 | 43 | USE_LOCAL_AXE=true |
43 | 44 | fi |
|
92 | 93 |
|
93 | 94 | echo "📥 Downloading latest AXe release from GitHub..." |
94 | 95 |
|
95 | | - # Construct release download URL from pinned version |
96 | | - AXE_RELEASE_URL="https://github.com/cameroncooke/AXe/releases/download/v${PINNED_AXE_VERSION}/AXe-macOS-v${PINNED_AXE_VERSION}.tar.gz" |
| 96 | + # Prefer Homebrew-specific archive (unsigned for relocation compatibility), |
| 97 | + # and fall back to legacy signed archive for older AXe releases. |
| 98 | + AXE_RELEASE_BASE_URL="https://github.com/cameroncooke/AXe/releases/download/v${PINNED_AXE_VERSION}" |
| 99 | + AXE_HOMEBREW_URL="${AXE_RELEASE_BASE_URL}/AXe-macOS-homebrew-v${PINNED_AXE_VERSION}.tar.gz" |
| 100 | + AXE_LEGACY_URL="${AXE_RELEASE_BASE_URL}/AXe-macOS-v${PINNED_AXE_VERSION}.tar.gz" |
97 | 101 |
|
98 | 102 | # Create temp directory |
99 | 103 | mkdir -p "$AXE_TEMP_DIR" |
100 | 104 | cd "$AXE_TEMP_DIR" |
101 | 105 |
|
102 | 106 | # Download and extract the release |
103 | | - echo "📥 Downloading AXe release archive ($AXE_RELEASE_URL)..." |
104 | | - curl -L -o "axe-release.tar.gz" "$AXE_RELEASE_URL" |
| 107 | + echo "📥 Downloading AXe Homebrew archive ($AXE_HOMEBREW_URL)..." |
| 108 | + if curl -fL -o "axe-release.tar.gz" "$AXE_HOMEBREW_URL"; then |
| 109 | + AXE_ARCHIVE_FLAVOR="homebrew-unsigned" |
| 110 | + echo "✅ Downloaded AXe Homebrew archive" |
| 111 | + else |
| 112 | + echo "⚠️ AXe Homebrew archive unavailable, falling back to legacy archive" |
| 113 | + curl -fL -o "axe-release.tar.gz" "$AXE_LEGACY_URL" |
| 114 | + AXE_ARCHIVE_FLAVOR="legacy-signed" |
| 115 | + fi |
105 | 116 |
|
106 | 117 | echo "📦 Extracting AXe release archive..." |
107 | 118 | tar -xzf "axe-release.tar.gz" |
@@ -157,27 +168,31 @@ ls -la "$BUNDLED_DIR/Frameworks/" |
157 | 168 | # Verify binary can run with bundled frameworks (macOS only) |
158 | 169 | OS_NAME="$(uname -s)" |
159 | 170 | if [ "$OS_NAME" = "Darwin" ]; then |
160 | | - echo "🔏 Verifying AXe signatures..." |
161 | | - if ! codesign --verify --deep --strict "$BUNDLED_DIR/axe"; then |
162 | | - echo "❌ Signature verification failed for bundled AXe binary" |
163 | | - exit 1 |
164 | | - fi |
165 | | - |
166 | | - while IFS= read -r framework_path; do |
167 | | - framework_name="$(basename "$framework_path" .framework)" |
168 | | - framework_binary="$framework_path/Versions/A/$framework_name" |
169 | | - if [ ! -f "$framework_binary" ]; then |
170 | | - framework_binary="$framework_path/Versions/Current/$framework_name" |
171 | | - fi |
172 | | - if [ ! -f "$framework_binary" ]; then |
173 | | - echo "❌ Framework binary not found: $framework_binary" |
174 | | - exit 1 |
175 | | - fi |
176 | | - if ! codesign --verify --deep --strict "$framework_binary"; then |
177 | | - echo "❌ Signature verification failed for framework binary: $framework_binary" |
| 171 | + if [ "$AXE_ARCHIVE_FLAVOR" = "homebrew-unsigned" ]; then |
| 172 | + echo "ℹ️ Skipping strict codesign verification for unsigned AXe Homebrew archive" |
| 173 | + else |
| 174 | + echo "🔏 Verifying AXe signatures..." |
| 175 | + if ! codesign --verify --deep --strict "$BUNDLED_DIR/axe"; then |
| 176 | + echo "❌ Signature verification failed for bundled AXe binary" |
178 | 177 | exit 1 |
179 | 178 | fi |
180 | | - done < <(find "$BUNDLED_DIR/Frameworks" -name "*.framework" -type d) |
| 179 | + |
| 180 | + while IFS= read -r framework_path; do |
| 181 | + framework_name="$(basename "$framework_path" .framework)" |
| 182 | + framework_binary="$framework_path/Versions/A/$framework_name" |
| 183 | + if [ ! -f "$framework_binary" ]; then |
| 184 | + framework_binary="$framework_path/Versions/Current/$framework_name" |
| 185 | + fi |
| 186 | + if [ ! -f "$framework_binary" ]; then |
| 187 | + echo "❌ Framework binary not found: $framework_binary" |
| 188 | + exit 1 |
| 189 | + fi |
| 190 | + if ! codesign --verify --deep --strict "$framework_binary"; then |
| 191 | + echo "❌ Signature verification failed for framework binary: $framework_binary" |
| 192 | + exit 1 |
| 193 | + fi |
| 194 | + done < <(find "$BUNDLED_DIR/Frameworks" -name "*.framework" -type d) |
| 195 | + fi |
181 | 196 |
|
182 | 197 | echo "🛡️ Assessing AXe with Gatekeeper..." |
183 | 198 | SPCTL_LOG="$(mktemp)" |
|
0 commit comments