Sign bundled macOS helper binaries (#35264)

## Why

The macOS release workflow fetched `rg` and zsh while assembling package
archives, after the signing stage. This left the bundled helper executables
outside the workflow's signing and notarization checks.

## What changed

- Fetch, sign, notarize, and upload the pinned macOS `rg` and zsh binaries with
  the other release artifacts.
- Build package archives from those signed helpers via `--rg-bin` and the new
  `--zsh-bin` override.
- Verify the helpers' architecture, signatures, and absence of entitlements in
  the final package.

## Testing

- Cover the prebuilt zsh override and verify that package assembly preserves
  the supplied helper binaries.

GitOrigin-RevId: a3865c04fa2f0f4df32e627ee7202bc87bdc3241
This commit is contained in:
Channing Conger
2026-07-24 23:44:55 +00:00
committed by copyberry
parent 0d2a0aa76b
commit a453588416
7 changed files with 187 additions and 14 deletions
+3 -3
View File
@@ -78,6 +78,6 @@ The patched zsh fork used by `shell_zsh_fork` is fetched from the DotSlash
manifest at `scripts/codex_package/codex-zsh` when the selected target has a
matching prebuilt artifact. Downloaded archives are cached under
`$TMPDIR/codex-package/<target>-zsh` and installed at
`codex-resources/zsh/bin/zsh`. Pass `--zsh-manifest` to use a different
DotSlash manifest, such as the manifest published with a standalone zsh
artifact release.
`codex-resources/zsh/bin/zsh`. Pass `--zsh-bin` to package a prebuilt, signed
executable, or `--zsh-manifest` to use a different DotSlash manifest, such as
the manifest published with a standalone zsh artifact release.