#!/bin/bash # release-maclustr-macos.sh — chaîne de release de l'app macOS MacLustr (maclustr-v2) depuis le laptop # quand la licence Xcode n'est pas acceptée (swift/xcodebuild/notarytool bloqués) : # 1. build + bundle avec la chaîne Command Line Tools (SDK macOS 26) # 2. signature Developer ID + DMG sur le laptop (codesign/hdiutil ne dépendent pas de la licence) # 3. notarisation + staple sur M4M64a (Xcode 26.6, clé API App Store Connect L379BDKR69) # 4. rapatriement du DMG stapled, installation dans /Applications (optionnel : --install) # Usage : release-maclustr-macos.sh [--install] [--skip-build] set -euo pipefail PROJ="$HOME/Desktop/Cluster/CLUSTER_APPLE/maclustr-v2" SWIFT=/Library/Developer/CommandLineTools/usr/bin/swift SDK=/Library/Developer/CommandLineTools/SDKs/MacOSX26.sdk NODE=M4M64a KEY=~/.appstoreconnect/private_keys/AuthKey_L379BDKR69.p8 KEY_ID=L379BDKR69 ISSUER=013e761f-e05c-4d93-a50b-f3d960adae4a INSTALL=0; SKIP_BUILD=0 for a in "$@"; do case "$a" in --install) INSTALL=1;; --skip-build) SKIP_BUILD=1;; esac; done cd "$PROJ" VERSION=$(grep -E '^VERSION=' build.sh | head -1 | cut -d'"' -f2) echo "=== MacLustr macOS $VERSION ===" if [ "$SKIP_BUILD" = 0 ]; then echo ">> build + bundle (CLT swift, SDK macOS 26)" SWIFT="$SWIFT" SDKROOT="$SDK" ./build.sh app 2>&1 | grep -E "error|Build complete|App bundle" | tail -5 fi echo ">> signature Developer ID" ./build.sh sign 2>&1 | grep -E "Signing|valid|error" | tail -3 echo ">> DMG" ./build.sh dmg 2>&1 | grep -E "created|error" | tail -2 [ -f MacLustr.dmg ] || { echo "DMG absent"; exit 1; } echo ">> notarisation sur $NODE" scp -q MacLustr.dmg "$NODE:/tmp/MacLustr-$VERSION.dmg" ssh "$NODE" "xcrun notarytool submit /tmp/MacLustr-$VERSION.dmg --key $KEY --key-id $KEY_ID --issuer $ISSUER --wait 2>&1 | grep -E 'id:|status:' | tail -2 && xcrun stapler staple /tmp/MacLustr-$VERSION.dmg 2>&1 | tail -1" scp -q "$NODE:/tmp/MacLustr-$VERSION.dmg" MacLustr.dmg echo ">> staple de l'app locale" # le ticket est aussi valable pour l'app : on l'extrait du DMG notarisé MNT=$(hdiutil attach -nobrowse -readonly MacLustr.dmg | awk -F'\t' '/Volumes/{print $NF}') rm -rf MacLustr.app && cp -R "$MNT/MacLustr.app" MacLustr.app && hdiutil detach "$MNT" -quiet spctl -a -vv MacLustr.app 2>&1 | tail -2 if [ "$INSTALL" = 1 ]; then echo ">> installation dans /Applications" pkill -x MacLustr 2>/dev/null || true rm -rf /Applications/MacLustr.app && cp -R MacLustr.app /Applications/MacLustr.app open /Applications/MacLustr.app && echo "MacLustr $VERSION lancée" fi echo "OK : $PROJ/MacLustr.dmg ($VERSION, notarisé, stapled)"