Skip to content

Commit 1b1f192

Browse files
committed
docs: macOS native module signatures in README and 4.7.2 changelogs
1 parent cf73ced commit 1b1f192

3 files changed

Lines changed: 22 additions & 0 deletions

File tree

‎src/serious_python/CHANGELOG.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,7 @@
1+
## 4.7.2
2+
3+
* **macOS:** fix App Store Connect rejecting Xcode-distributed builds with `90238: Invalid signature … does not satisfy its designated Requirement` on bundled `.so` files ([#250](https://github.com/flet-dev/serious-python/issues/250)). Linker-signed native modules are re-signed ad-hoc while they are staged, so Xcode's distribution signing gives them valid signatures. See `serious_python_darwin` 4.7.2.
4+
15
## 4.7.1
26

37
* Fix macOS crashes during native scientific imports and NumPy operations by giving the asynchronous Python worker at least **8 MiB** of stack space, via `dart_bridge` 1.10.0. ([dart-bridge#21](https://github.com/flet-dev/dart-bridge/pull/21), [#85](https://github.com/flet-dev/serious-python/issues/85))

‎src/serious_python/README.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -319,6 +319,20 @@ produces a working app, but it cannot produce complete SDK-origin receipts. **Us
319319
the SwiftPM path for App Store submissions** until that path is replaced with real
320320
vendored XCFramework declarations.
321321

322+
#### macOS native module signatures
323+
324+
On macOS, the native modules under `stdlib/`, `site-packages/` and `app/` ship as
325+
plain `.so`/`.dylib` files, which Xcode's distribution signing (the Organizer or
326+
`xcodebuild -exportArchive`) re-signs with your certificate along with the rest of
327+
the app. A module carrying the signature the linker gave it comes out of that
328+
step with a designated requirement naming a different identifier than its new
329+
signature: codesign does not carry a linker signature's identifier over, but Xcode
330+
can build the requirement from it. App Store Connect rejects such an upload with
331+
error 90238 ("does not satisfy its designated Requirement"). The macOS build
332+
therefore replaces linker signatures with regular ad-hoc ones while staging these
333+
trees. The `SERIOUS_PYTHON_SITE_PACKAGES` and `SERIOUS_PYTHON_APP` directories
334+
themselves are left unchanged.
335+
322336
### Linux / Windows specifics
323337

324338
The CPython runtime (`libpython3.so` + `libpython<X.Y>.so` on Linux; `python3.dll` + `python<XY>.dll` on Windows), `libdart_bridge`, the stdlib, and native modules are copied next to your app's executable at build time. `PYTHONHOME` is the executable's directory. On Windows, extension modules (`.pyd`) and their dependent DLLs live in `<exe-dir>/DLLs/`, which is added to `sys.path`.

‎src/serious_python_darwin/CHANGELOG.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,7 @@
1+
## 4.7.2
2+
3+
* **macOS: bundled native modules pass App Store Connect's signature check after Xcode distribution signing** ([#250](https://github.com/flet-dev/serious-python/issues/250)). The stdlib `lib-dynload` modules and many wheel extensions (e.g. Pillow's `_imagingmorph`) arrive with the linker's ad-hoc signature, whose identifier is the file name including `.so`. When Xcode re-signs them for distribution (Organizer, `xcodebuild -exportArchive`), `codesign` cannot carry that identifier over and derives one without the extension, while Xcode can write the designated requirement from the old one, so App Store Connect rejected the upload with `90238: Invalid signature … does not satisfy its designated Requirement`. The macOS staging now re-signs every still-linker-signed `.so`/`.dylib` ad-hoc: `prepare_macos.sh` for the stdlib, `sync_site_packages.sh` for site-packages and the app. A regular ad-hoc signature's identifier survives re-signing, so the requirement and the signature agree. `SERIOUS_PYTHON_SITE_PACKAGES`, `SERIOUS_PYTHON_APP` and the provider XCFrameworks are not modified. CI now fails the macOS example build if a linker-signed library reaches the app bundle.
4+
15
## 4.7.1
26

37
* Fix macOS crashes during native scientific imports and NumPy operations by giving the asynchronous Python worker at least **8 MiB** of stack space, via `dart_bridge` 1.10.0. ([dart-bridge#21](https://github.com/flet-dev/dart-bridge/pull/21), [#85](https://github.com/flet-dev/serious-python/issues/85))

0 commit comments

Comments
 (0)