feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(macos): build a signed .app bundle in a .dmg - #4759

Merged
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle
Mar 4, 2026
Merged

feat(macos): build a signed .app bundle in a .dmg#4759
ReenigneArcher merged 4 commits into
LizardByte:masterfrom
andygrundman:andyg.macos-app-bundle

Conversation

@andygrundman

@andygrundmanandygrundman commented Feb 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR should be able to build a signed or unsigned Sunshine.app from both CI and from a manual build script. 6 secrets are required to properly sign and notarize a Mac app. Since CI produces builds from pull requests containing unknown code, I took care to only automatically sign builds when github.event_name == push.

An unsigned build should be possible to run but requires jumping through a few security hoops: "Open Anyway" as well as possibly forcing the removal of the quarantine bit.

The .app bundles all dependent libraries in the Frameworks directory, as well as all web UI assets in the Resources directory, so everything should be fully self-contained.

I don't think it breaks any other build including Mac homebrew, but it's difficult to test all possible CI builds as some appear to require various secrets.

Screenshot

sunshine-dmg

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR!

Do you have a link for instructions on what I need to do to sign up and get the required secrets? I guess the first step is to enroll here (https://developer.apple.com/programs/enroll/)?

cmake \
node \
pkgconf \
icu4c@78 \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reminds me I wanted to check if we could get away with not linking to icu4c.

I saw this in homebrew, but not sure if it would work for us. https://github.com/Homebrew/homebrew-core/blob/3d2fa66822448968bde0ede5bc3f8396f2410db8/Formula/x/xerces-c.rb#L25-L29

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/prep/options.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadsrc_assets/macos/assets/dot_DS_Store Outdated
Comment threadsrc_assets/macos/assets/sunshine.icns Outdated
@andygrundman

This comment was marked as resolved.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking really good. I think these are my final suggestions.

I will also run CI to just confirm linting passes and everything.

Edit: there's a few lint errors in actionlint, cmake-lint, and yamllint -> https://github.com/LizardByte/Sunshine/actions/runs/22299335343/job/64535327417?pr=4759

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadcmake/packaging/macos.cmake
Comment threadcmake/packaging/macos.cmake
@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@codecov

codecovBot commented Feb 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@b000d43). Learn more about missing BASE report.
⚠️ Report is 229 commits behind head on master.

Additional details and impacted files
@@ Coverage Diff @@## master #4759 +/- ##
=========================================
Coverage ? 16.74% =========================================
Files ? 106 Lines ? 21747 Branches ? 9733 =========================================
Hits ? 3642 Misses ? 14287 Partials ? 3818 
FlagCoverage Δ
Archlinux11.07% <ø> (?)
FreeBSD-14.3-amd6413.06% <ø> (?)
Homebrew-ubuntu-22.0413.27% <ø> (?)
Linux-AppImage11.48% <ø> (?)
Windows-AMD6413.43% <ø> (?)
Windows-ARM6412.35% <ø> (?)
macOS-arm6416.96% <ø> (?)
macOS-x86_6415.54% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should solve all the lint issues.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci.yml Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/dependencies/FindOpus.cmake Outdated
Comment threadcmake/targets/macos.cmake
@hauntek

Copy link
Copy Markdown
6aa45715-71ca-49f5-8b9c-ca056aea1477

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

When running in the background, can the Dock icon be hidden? I noticed that quitting from the Dock doesn’t seem to have any effect. As long as there’s a tray icon, I can operate the program just fine.

Yeah, this doesn't need to affect this PR, but should certainly be fixed. The other related thing I know will be needed is a way to run it on startup as a proper LaunchDaemon. I don't really consider the Mac version to be in a usable state yet, this app bundle is just intended to help resolve the permission issues caused by running from Terminal, and remove the need for people to build the homebrew version.

@ReenigneArcherReenigneArcher left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've added all the required secrets, but have a few requested changes before this is merged.

The big points are I'd like the secrets to all start with APPLE_ so it's easier to identify them. And then to re-use the logic from our release_setup action which already provides a value for whether we should publish or not, which in this case would also be used for whether we should sign or not.

Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml
Comment thread.github/workflows/ci-macos.yml Outdated
Comment thread.github/workflows/ci-macos.yml Outdated
Comment threadcmake/packaging/macos.cmake Outdated
Comment threadscripts/macos_build.sh Outdated
Comment threadscripts/macos_build.sh Outdated
@andygrundman
andygrundmanforce-pushed the andyg.macos-app-bundle branch from b212c32 to b80fedaCompareMarch 3, 2026 12:09
…ed/notarized
- macOS homebrew build should still work as before
- New sunshine.icns dark mode (temporary) icon and DMG background image/layout
- scripts/macos_build.sh can be used to manually build everything
- automated signing is prevented for builds originating from pull requests
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from b80feda to d770478CompareMarch 4, 2026 02:09
ReenigneArcher
ReenigneArcher previously approved these changes Mar 4, 2026
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch 2 times, most recently from 1e0db02 to 24c05a0CompareMarch 4, 2026 02:27
@ReenigneArcher
ReenigneArcherforce-pushed the andyg.macos-app-bundle branch from 24c05a0 to 8fa02dbCompareMarch 4, 2026 02:46
@sonarqubecloud

Copy link
Copy Markdown

@ReenigneArcher
ReenigneArcher merged commit 423a864 into LizardByte:masterMar 4, 2026
72 checks passed
@moi952

Copy link
Copy Markdown

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

Is that normal?

Thanks

@andygrundman

Copy link
Copy Markdown
ContributorAuthor

Hi, I wanted to try the developer version, but the .dmg file isn't included in the release.

We're still trying to sort out the signing of the build and then it should be added to the list of releases.

@ReenigneArcher

Copy link
Copy Markdown
Member

Apple is holding up the notary process. Probably because my account is new and this is my first time signing and notarizing apps.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sunshine: Create macOS dmg package

4 participants

@andygrundman@hauntek@moi952@ReenigneArcher