mirror of
https://github.com/open-jarvis/OpenJarvis.git
synced 2026-08-14 08:52:06 +00:00
Notarization is the last thing tauri-action does, so any credential or
account-state fault surfaced ~10 minutes into the macOS job -- after the
Rust toolchain, npm install, two Ollama sidecar downloads and a universal
cargo build -- as one opaque line:
failed to bundle project: failed codesign application: failed to
notarize app: Error: HTTP status code: 403. ...
That message conflates three unrelated causes, and the signing step
succeeds in all of them, so the log actively misleads: the certificate is
clearly valid right up until the failure.
Add a read-only `notarytool history` call immediately after checkout. It
submits nothing and exercises the identical auth path, so all three
failures reach us in ~2s with the specific cause and fix named:
401 invalid credentials -> APPLE_PASSWORD is not an app-specific
password, or was minted under a different
Apple ID than APPLE_ID
403 inaccessible team -> APPLE_ID is not a member of APPLE_TEAM_ID
403 required agreement -> the Program License Agreement lapsed; only
the Account Holder can accept it
xcrun is preinstalled on macOS runners, hence placement before the
toolchain steps rather than beside "Configure Apple signing".
Skips cleanly when APPLE_CERTIFICATE is unset (unsigned builds never
notarize), mirroring the existing signing step, and errors when a
certificate is present but notarization secrets are missing -- previously
that combination signed successfully and then failed at the very end.
Transient network faults retry 3x; credential errors are deterministic
and exit on the first definitive answer.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>