morgan pushed to branch main at The Tor Project / Applications / 
tor-browser-build


Commits:
c4fb2737 by Nicolas Vigier at 2024-10-31T18:19:37+00:00
Bug 43245: Use separate entitlements for signing tor

Use a separate entitlements file for signing the tor binary, with
`com.apple.security.cs.allow-unsigned-executable-memory` enabled.

- - - - -


2 changed files:

- + tools/signing/macos-entitlements/tor.xml
- tools/signing/wrappers/sign-rcodesign-128


Changes:

=====================================
tools/signing/macos-entitlements/tor.xml
=====================================
@@ -0,0 +1,17 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" 
"http://www.apple.com/DTDs/PropertyList-1.0.dtd";>
+<!--
+     Entitlements to apply to the tor process executable.
+-->
+<plist version="1.0">
+  <dict>
+    <!-- tor needs this when connecting to PoW onion-services.
+         See tor-browser#43250 and tor#40988 -->
+    <key>com.apple.security.cs.allow-unsigned-executable-memory</key><true/>
+
+    <!-- Allow loading third party libraries to support pkcs11 modules -->
+    <key>com.apple.security.cs.disable-library-validation</key><true/>
+
+    <key>com.apple.security.cs.allow-jit</key><true/>
+  </dict>
+</plist>


=====================================
tools/signing/wrappers/sign-rcodesign-128
=====================================
@@ -82,6 +82,7 @@ $rcodesign sign \
   --code-signature-flags Contents/Frameworks/ChannelPrefs.framework:runtime \
   --code-signature-flags Contents/MacOS/plugin-container.app:runtime \
   --code-signature-flags Contents/MacOS/media-plugin-helper.app:runtime \
+  --entitlements-xml-path 
Contents/MacOS/Tor/tor:/signing/tor-browser-build/tools/signing/macos-entitlements/tor.xml
 \
   --entitlements-xml-path 
Contents/MacOS/plugin-container.app:/signing/tor-browser-build/tools/signing/macos-entitlements/plugin-container.xml
 \
   --entitlements-xml-path 
Contents/MacOS/media-plugin-helper.app:/signing/tor-browser-build/tools/signing/macos-entitlements/media-plugin-helper.xml
 \
   --entitlements-xml-path 
/signing/tor-browser-build/tools/signing/macos-entitlements/firefox.browser.xml 
\



View it on GitLab: 
https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/c4fb273735407f42d6ed8827ce45f0245f72f08a

-- 
View it on GitLab: 
https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/c4fb273735407f42d6ed8827ce45f0245f72f08a
You're receiving this email because of your account on gitlab.torproject.org.


_______________________________________________
tbb-commits mailing list
[email protected]
https://lists.torproject.org/cgi-bin/mailman/listinfo/tbb-commits

Reply via email to