Repository navigation
fix(macos): retain runtime protections and updater blocking - #4016
Conversation
Protect current and legacy staging directories and verify their physical state. Migrate legacy endpoint patches with a recoverable original and atomic replacement. Keep durable intent separate from temporary apertures and ordinary Apply signing.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Intel macOS test build. Paste this into Terminal, with GitHub CLI ( bash <<'SCRIPT'
set -e
work="$(mktemp -d)"
dest="$HOME/.spicetify"
gh run download 37212773310 --repo spicetify/cli \
--name spicetify-pr-macos-x86_64-964f1c3d5798646ba4b5d820e1c754ab3ecc6d50 \
--dir "$work"
"$dest/spicetify" daemon stop
cp -p "$dest/spicetify" "$dest/spicetify-daemon" "$work/"
printf 'Previous binaries backed up to: %s\n' "$work"
printf 'Quit Spotify, replace Spotify.app with a fresh official copy, then press Enter: '
read -r </dev/tty
tar -xzf "$work/spicetify-pr-macos-x86_64-964f1c3d5798.tar.gz" -C "$dest"
"$dest/spicetify" spotify-updates block
"$dest/spicetify" apply
SCRIPTThen test playback and restarting Spotify. The fresh Spotify copy matters because the fix cannot recover signing metadata already stripped by an older build. |
Summary
Keep Spotify's Hardened Runtime metadata intact after macOS Apply, and keep the requested updater block effective without rewriting clean executables. The previous ad-hoc signer stripped runtime metadata, while the legacy immutable cache directory did not cover the current updater's staging location.
The signing fix and update-protection replacement are separate commits so they can be assessed independently.
Decisions and migration
Updateand legacyPersistentCache/Updatestaging directories. Clear already-prepared updates and verify physical protection rather than trusting configuration. Native download controls showed that the legacy directory alone did not stop downloading, while protecting the current directory did; unlocking and relaunching restored downloading.Ordinary Apply still signs modified resources independently of update blocking. Linux/Windows protection paths and native-update platform guards retain their existing behavior.
Validation
Local verification used arm64 macOS 26.6.2, Rust 1.98.0, and official Spotify 1.3.3.264. Project toolchain settings were not changed.
-D warnings, and CLI/daemon builds passed. Neither binary was installed or started.All-target Clippy remains blocked by 48 pre-existing test-lint errors. One unrestricted parallel run failed the existing daemon instance-lock timing test; the final four-thread run passed. The installed Spotify executable hash, profile/configuration, running daemon, and existing update protection were not changed by fix validation.
Outstanding before ready
This PR is a draft, not end-to-end or release clearance.
Symlinked staging ancestors are deliberately rejected. Relocated-cache configurations must resolve to the directories Spotify actually uses; the default-path checks do not prove those configurations.