diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..a729e15 --- /dev/null +++ b/.gitattributes @@ -0,0 +1 @@ +*.af filter=lfs diff=lfs merge=lfs -text diff --git a/.github/workflows/apple-release.yml b/.github/workflows/apple-release.yml new file mode 100644 index 0000000..9812b69 --- /dev/null +++ b/.github/workflows/apple-release.yml @@ -0,0 +1,230 @@ +name: Apple release (macOS DMG) + +# Builds, signs, notarizes, and publishes the direct-download macOS build: +# - a Developer ID–signed, notarized VniDrop-.dmg, +# - a Sparkle appcast.xml (both attached to the GitHub Release), and +# - an updated Homebrew cask pushed to the sudosylabs/homebrew-vnidrop tap. +# +# The App Store / TestFlight build is NOT produced here — that goes through Xcode +# Organizer / App Store Connect. This workflow only covers direct distribution. +# +# Trigger: push a tag vMAJOR.MINOR.PATCH (must point at a commit on master), or +# run manually with an explicit version (produces artifacts, no Release). + +on: + push: + tags: + - "v*.*.*" + workflow_dispatch: + inputs: + version: + description: Release version in MAJOR.MINOR.PATCH form + required: true + default: "0.1.0" + type: string + +permissions: + contents: read + +concurrency: + group: apple-release-${{ github.ref }} + cancel-in-progress: false + +defaults: + run: + shell: bash + +jobs: + build: + name: Build & notarize DMG + runs-on: macos-latest + timeout-minutes: 90 + permissions: + contents: write + outputs: + version: ${{ steps.version.outputs.app }} + steps: + - name: Checkout + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + fetch-depth: 0 + persist-credentials: false + + - name: Verify tag is on master + if: github.event_name == 'push' + run: | + if ! git merge-base --is-ancestor "$GITHUB_SHA" origin/master; then + echo "Release tags must point to a commit on master" >&2 + exit 1 + fi + + - name: Resolve version + id: version + env: + REQUESTED_VERSION: ${{ inputs.version || '' }} + run: | + if [ "${GITHUB_REF_TYPE:-}" = "tag" ]; then + version="${GITHUB_REF_NAME#v}" + else + version="$REQUESTED_VERSION" + fi + [[ "$version" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]] || { echo "bad version '$version'" >&2; exit 1; } + echo "app=$version" >> "$GITHUB_OUTPUT" + + - name: Select Xcode + run: sudo xcode-select -s /Applications/Xcode.app + + - name: Install Rust toolchain + uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # v1 + with: + toolchain: stable + targets: aarch64-apple-darwin + + - name: Cache Cargo + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: | + ~/.cargo/registry + ~/.cargo/git + target + key: apple-release-cargo-${{ hashFiles('Cargo.lock') }} + restore-keys: apple-release-cargo- + + - name: Install tooling + run: brew install xcodegen swiftlint create-dmg + + - name: Install Bun + uses: oven-sh/setup-bun@v2 + + - name: Download Sparkle tools + # generate_appcast + sign_update ship in the Sparkle release tarball. + run: | + set -euo pipefail + ver="2.9.4" + curl -fsSL -o /tmp/sparkle.tar.xz \ + "https://github.com/sparkle-project/Sparkle/releases/download/${ver}/Sparkle-${ver}.tar.xz" + mkdir -p /tmp/sparkle && tar -xJf /tmp/sparkle.tar.xz -C /tmp/sparkle + echo "SPARKLE_BIN=/tmp/sparkle/bin" >> "$GITHUB_ENV" + + - name: Import Developer ID certificate + env: + CERT_P12_BASE64: ${{ secrets.DEVELOPER_ID_CERT_P12 }} + CERT_PASSWORD: ${{ secrets.DEVELOPER_ID_CERT_PASSWORD }} + run: | + set -euo pipefail + keychain="$RUNNER_TEMP/signing.keychain-db" + kpw="$(openssl rand -hex 20)" + security create-keychain -p "$kpw" "$keychain" + security set-keychain-settings -lut 21600 "$keychain" + security unlock-keychain -p "$kpw" "$keychain" + echo "$CERT_P12_BASE64" | base64 --decode > "$RUNNER_TEMP/cert.p12" + security import "$RUNNER_TEMP/cert.p12" -k "$keychain" -P "$CERT_PASSWORD" \ + -T /usr/bin/codesign -T /usr/bin/security + security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$kpw" "$keychain" + # Prepend our keychain so codesign/xcodebuild can find the identity. + security list-keychains -d user -s "$keychain" $(security list-keychains -d user | tr -d '"') + rm -f "$RUNNER_TEMP/cert.p12" + + - name: Store notarytool credentials + env: + NOTARY_KEY_P8: ${{ secrets.NOTARY_API_KEY }} + NOTARY_KEY_ID: ${{ secrets.NOTARY_KEY_ID }} + NOTARY_ISSUER: ${{ secrets.NOTARY_ISSUER }} + run: | + set -euo pipefail + echo "$NOTARY_KEY_P8" | base64 --decode > "$RUNNER_TEMP/notary.p8" + xcrun notarytool store-credentials vnidrop-notary \ + --key "$RUNNER_TEMP/notary.p8" \ + --key-id "$NOTARY_KEY_ID" \ + --issuer "$NOTARY_ISSUER" + echo "NOTARY_PROFILE=vnidrop-notary" >> "$GITHUB_ENV" + + - name: Write Sparkle signing key + env: + SPARKLE_ED_PRIVATE_KEY: ${{ secrets.SPARKLE_ED_PRIVATE_KEY }} + run: | + printf '%s' "$SPARKLE_ED_PRIVATE_KEY" > "$RUNNER_TEMP/sparkle_ed_private_key" + echo "SPARKLE_ED_KEY_FILE=$RUNNER_TEMP/sparkle_ed_private_key" >> "$GITHUB_ENV" + + - name: Build, sign & notarize DMG + run: apple/scripts/build-dmg.sh "${{ steps.version.outputs.app }}" + + - name: Generate appcast + env: + RELEASE_REPO: ${{ github.repository }} + run: apple/scripts/generate-appcast.sh "${{ steps.version.outputs.app }}" + + - name: Upload artifacts + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: vnidrop-${{ steps.version.outputs.app }}-macos-dmg + path: | + apple/dist/VniDrop-*.dmg + apple/dist/appcast.xml + if-no-files-found: error + retention-days: 14 + + - name: Publish GitHub Release + if: github.event_name == 'push' && github.ref_type == 'tag' + env: + GH_TOKEN: ${{ github.token }} + GH_REPO: ${{ github.repository }} + run: | + set -euo pipefail + tag="$GITHUB_REF_NAME" + version="${tag#v}" + if gh release view "$tag" >/dev/null 2>&1; then + echo "Release $tag already exists; refusing to replace assets" >&2 + exit 1 + fi + gh release create "$tag" \ + "apple/dist/VniDrop-${version}.dmg" \ + "apple/dist/appcast.xml" \ + --verify-tag \ + --title "VniDrop $version" \ + --generate-notes + + update-cask: + name: Update Homebrew cask + needs: build + if: github.event_name == 'push' && github.ref_type == 'tag' + runs-on: ubuntu-22.04 + timeout-minutes: 15 + steps: + - name: Checkout + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + persist-credentials: false + + - name: Download DMG artifact + uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0 + with: + name: vnidrop-${{ needs.build.outputs.version }}-macos-dmg + path: dist + + - name: Render cask + env: + VERSION: ${{ needs.build.outputs.version }} + run: | + set -euo pipefail + sha="$(sha256sum "dist/VniDrop-${VERSION}.dmg" | cut -d' ' -f1)" + sed -e "s/^ version \".*\"/ version \"${VERSION}\"/" \ + -e "s/^ sha256 \".*\"/ sha256 \"${sha}\"/" \ + packaging/homebrew/vnidrop.rb > /tmp/vnidrop.rb + echo "Rendered cask:"; cat /tmp/vnidrop.rb + + - name: Push to tap + env: + TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }} + VERSION: ${{ needs.build.outputs.version }} + run: | + set -euo pipefail + git clone "https://x-access-token:${TAP_TOKEN}@github.com/sudosylabs/homebrew-vnidrop.git" tap + mkdir -p tap/Casks + cp /tmp/vnidrop.rb tap/Casks/vnidrop.rb + cd tap + git config user.name "vnidrop-release-bot" + git config user.email "release-bot@users.noreply.github.com" + git add Casks/vnidrop.rb + git commit -m "vnidrop ${VERSION}" || { echo "no cask changes"; exit 0; } + git push diff --git a/.github/workflows/apple.yml b/.github/workflows/apple.yml index 415aebe..64a810b 100644 --- a/.github/workflows/apple.yml +++ b/.github/workflows/apple.yml @@ -76,3 +76,8 @@ jobs: - name: Build and test Apple app run: make check-apple + + - name: Build direct-download macOS target (Sparkle, unsigned) + # Keeps the VniDropDirect (.dmg/Sparkle) target compiling; signing and + # notarization happen only in apple-release.yml on a tag. + run: make build-apple-macos-direct diff --git a/.gitignore b/.gitignore index d3bdd2e..5b43b44 100644 --- a/.gitignore +++ b/.gitignore @@ -24,3 +24,4 @@ config.override.mk # Local design export scratch output/ .screenshots +apple/RELEASE-MACOS.md diff --git a/LICENSE b/LICENSE index d645695..c4ca95b 100644 --- a/LICENSE +++ b/LICENSE @@ -187,7 +187,8 @@ same "printed page" as the copyright notice for easier identification within third-party archives. - Copyright [yyyy] [name of copyright owner] + Copyright 2026 VniDrop + Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. diff --git a/Makefile b/Makefile index 81b36df..4010dc8 100644 --- a/Makefile +++ b/Makefile @@ -122,6 +122,12 @@ open-apple-project: apple-project ## Generate and open the native Apple Xcode pr build-apple-macos: apple-project ## Build the native macOS app (unsigned by default). cd $(ROOT)/apple && $(XCODEBUILD) -project VniDrop.xcodeproj -scheme VniDrop -configuration $(APPLE_CONFIGURATION) -derivedDataPath "$(APPLE_DERIVED_DATA)" -destination 'platform=macOS' CODE_SIGNING_ALLOWED=$(APPLE_CODE_SIGNING) CODE_SIGNING_REQUIRED=$(APPLE_CODE_SIGNING) build +build-apple-macos-direct: apple-project ## Build the direct-download macOS target (Sparkle, unsigned) — CI compile check. + cd $(ROOT)/apple && $(XCODEBUILD) -project VniDrop.xcodeproj -scheme VniDropDirect -configuration Release-Direct -derivedDataPath "$(APPLE_DERIVED_DATA)" -destination 'platform=macOS' CODE_SIGNING_ALLOWED=NO CODE_SIGNING_REQUIRED=NO build + +build-apple-dmg: ## Build the signed/notarized direct-download .dmg (see apple/RELEASE-MACOS.md for required env). + cd $(ROOT) && apple/scripts/build-dmg.sh $(VERSION) + open-apple: build-apple-macos ## Build and launch the native macOS app. @test -d "$(APPLE_DERIVED_DATA)/Build/Products/$(APPLE_CONFIGURATION)/VniDrop.app" || { printf 'Built macOS app was not found.\n' >&2; exit 1; } $(OPEN) "$(APPLE_DERIVED_DATA)/Build/Products/$(APPLE_CONFIGURATION)/VniDrop.app" diff --git a/apple/.gitignore b/apple/.gitignore index 40759f5..19c342e 100644 --- a/apple/.gitignore +++ b/apple/.gitignore @@ -18,3 +18,7 @@ Local.xcconfig .swiftpm/ DerivedData/ *.xcuserstate + +# Direct-download (.dmg) build outputs — apple/scripts/build-dmg.sh +.build-dmg/ +dist/ diff --git a/apple/.swiftlint.yml b/apple/.swiftlint.yml index b9a3f8e..66fd294 100644 --- a/apple/.swiftlint.yml +++ b/apple/.swiftlint.yml @@ -32,3 +32,18 @@ custom_rules: regex: '\b(Text|Label|Button|Toggle|Link|NavigationLink|Section|Picker|Stepper|TextField|SecureField|DisclosureGroup|Menu|GroupBox)\("[^"]' message: "Pass a typed L10n.* accessor (or Text(verbatim:)), not a raw string literal." severity: warning + raw_alert_message: + name: "Raw NFC/alert message" + # User-facing UIKit/CoreNFC prompts (e.g. NFCReaderSession.alertMessage) must + # be localized, not hardcoded English. + regex: '\balertMessage\s*=\s*"' + message: "Assign a localized value (String(localized: L10n.*)), not a raw string literal." + severity: warning + raw_invitation_error: + name: "Raw InvitationError literal" + # InvitationError.raw is the escape hatch for genuinely dynamic system/core + # messages; a string literal here is a loose user-facing string that belongs + # in a typed InvitationError case mapped to L10n in UserFacingError.swift. + regex: 'InvitationError\.raw\("' + message: "Add a typed InvitationError case + L10n mapping instead of a literal .raw(\"…\")." + severity: warning diff --git a/apple/README.md b/apple/README.md index 4912d53..e99f093 100644 --- a/apple/README.md +++ b/apple/README.md @@ -34,12 +34,30 @@ Prerequisites: Xcode, Rust with the Apple targets make apple-core # Rust core, Swift bindings, and XCFramework make apple-project # generate apple/VniDrop.xcodeproj make open-apple-project # generate and open the project in Xcode -make build-apple-macos # unsigned macOS build +make build-apple-macos # unsigned macOS build (App Store target) make open-apple # build and launch the macOS app -make build-apple-ios # unsigned iOS simulator build +make build-apple-ios # unsigned iOS simulator app make check-apple # iOS simulator tests ``` +### macOS shipping channels + +The macOS app ships through two targets that build identical sources: + +- **`VniDrop`** (`Release`) — Mac App Store / TestFlight. Sandboxed, no + self-updater. +- **`VniDropDirect`** (`Release-Direct`) — direct-download `.dmg` on GitHub + Releases + Homebrew cask. Adds the **Sparkle** auto-updater behind the + `DIRECT_DISTRIBUTION` compile flag, so the App Store binary never links Sparkle. + +```bash +make build-apple-macos-direct # unsigned compile-check of the direct target +make build-apple-dmg VERSION=x.y.z # signed (+ notarized) .dmg +``` + +Full signing, notarization, appcast, and cask flow: see +[`RELEASE-MACOS.md`](RELEASE-MACOS.md). + Use `APPLE_PROFILE=release` to request a release Rust core, or set `APPLE_DESTINATION` to override the automatically selected iOS simulator. Code signing is disabled for the app and test targets; local and CI builds do diff --git a/apple/Tests/UiFeedbackTests.swift b/apple/Tests/UiFeedbackTests.swift index fdbbfbe..9250f79 100644 --- a/apple/Tests/UiFeedbackTests.swift +++ b/apple/Tests/UiFeedbackTests.swift @@ -21,13 +21,13 @@ final class UiMessageControllerTests: XCTestCase { func testErrorSuppressesUserCancellation() { let c = UiMessageController() - c.error(InvitationError.message("QR scanning was cancelled")) + c.error(InvitationError.cancelled) XCTAssertNil(c.current) // cancellations are swallowed } func testErrorShowsNonCancellation() { let c = UiMessageController() - c.error(InvitationError.message("The transfer was refused")) + c.error(InvitationError.raw("The transfer was refused")) XCTAssertEqual(c.current?.tone, .error) } } @@ -36,20 +36,23 @@ final class UiMessageControllerTests: XCTestCase { final class UserFacingErrorTests: XCTestCase { func testIsUserCancellation() { - XCTAssertTrue(InvitationError.message("NFC reading was cancelled").isUserCancellation) - XCTAssertTrue(InvitationError.message("User canceled the picker").isUserCancellation) - XCTAssertFalse(InvitationError.message("A database error occurred").isUserCancellation) + XCTAssertTrue(InvitationError.cancelled.isUserCancellation) + XCTAssertTrue(InvitationError.raw("User canceled the picker").isUserCancellation) + XCTAssertFalse(InvitationError.raw("A database error occurred").isUserCancellation) } func testToUiTextMapsKnownReasons() { - XCTAssertEqual(InvitationError.message("The transfer was refused").toUiText(), .resource(L10n.Error.permission)) - XCTAssertEqual(InvitationError.message("invalid ticket").toUiText(), .resource(L10n.Error.invalidTicket)) - XCTAssertEqual(InvitationError.message("Select at least one file to share").toUiText(), .resource(L10n.Error.shareEmpty)) - XCTAssertEqual(InvitationError.message("Camera access is required").toUiText(), .resource(L10n.Error.camera)) + // Typed cases map directly at the UI boundary. + XCTAssertEqual(InvitationError.shareEmpty.toUiText(), .resource(L10n.Error.shareEmpty)) + XCTAssertEqual(InvitationError.cameraUnavailable.toUiText(), .resource(L10n.Error.camera)) + XCTAssertEqual(InvitationError.nfcFailed.toUiText(), .resource(L10n.Error.nfc)) + // Dynamic `.raw` payloads still fall through the substring hints. + XCTAssertEqual(InvitationError.raw("The transfer was refused").toUiText(), .resource(L10n.Error.permission)) + XCTAssertEqual(InvitationError.raw("invalid ticket").toUiText(), .resource(L10n.Error.invalidTicket)) } func testToUiTextFallsBackToGeneric() { - XCTAssertEqual(InvitationError.message("something entirely unexpected").toUiText(), .resource(L10n.Error.generic)) + XCTAssertEqual(InvitationError.raw("something entirely unexpected").toUiText(), .resource(L10n.Error.generic)) } func testToUiTextMapsTypedTransferFailures() { diff --git a/apple/VniDrop/App/AppGraph.swift b/apple/VniDrop/App/AppGraph.swift index d261499..9cd7f97 100644 --- a/apple/VniDrop/App/AppGraph.swift +++ b/apple/VniDrop/App/AppGraph.swift @@ -13,6 +13,7 @@ final class AppGraph: ObservableObject { let filePreviewRepository: FilePreviewRepository let approvalCoordinator: ApprovalCoordinator let transferNotificationCoordinator: TransferNotificationCoordinator + let backgroundActivity: BackgroundActivityController init(dependencies: AppDependencies, coreRepository: CoreRepository? = nil) { self.dependencies = dependencies @@ -39,6 +40,7 @@ final class AppGraph: ObservableObject { visibility: visibility, messages: messages ) + self.backgroundActivity = BackgroundActivityController(repository: coreRepository) AppLogger.info("lifecycle", "graph created", ["platform": dependencies.environment.name]) } diff --git a/apple/VniDrop/App/RootView.swift b/apple/VniDrop/App/RootView.swift index 4954e07..dacdc03 100644 --- a/apple/VniDrop/App/RootView.swift +++ b/apple/VniDrop/App/RootView.swift @@ -14,6 +14,10 @@ struct RootView: View { @Environment(\.scenePhase) private var scenePhase + /// Drives the approval sheet; toggled from the pending-approval `onChange` so the + /// presentation can be deferred until the Share/QR sheet has dismissed on macOS. + @State private var showApproval = false + init(dependencies: AppDependencies) { let graph = AppGraph(dependencies: dependencies) _graph = StateObject(wrappedValue: graph) @@ -58,6 +62,7 @@ struct RootView: View { navigation(windowClass: windowClass) SnackbarHost(controller: messages) ApprovalModalHost( + isPresented: $showApproval, state: approvals.state, onAccept: approvals.accept, onRefuse: approvals.refuse @@ -81,22 +86,43 @@ struct RootView: View { switch phase { case .active: graph.visibility.setForeground(true) + graph.backgroundActivity.didBecomeForeground() settingsModel.refreshNotificationPermission() // Reconcile against the durable snapshot: while the window was // unfocused/occluded (common on macOS) live events may not have // rendered, leaving progress/status stale. Task { _ = await graph.coreRepository.refresh() } - case .background, .inactive: + case .background: + graph.visibility.setForeground(false) + // Hold the process open for iOS's grace window so an active + // transfer can finish and notify before suspension. + graph.backgroundActivity.didEnterBackground() + case .inactive: graph.visibility.setForeground(false) @unknown default: break } } - // A pending approval is a blocking modal; close the sender's detail panel - // (e.g. the Share/QR sheet) so the approval sheet isn't presented under it - // on macOS. + // A pending approval is a blocking modal. Close the sender's detail panel + // (e.g. the Share/QR sheet) first, then present the approval sheet — but on + // macOS a sheet presented while another is still dismissing is silently + // dropped, so defer the presentation until that dismissal finishes. .onChange(of: approvals.state.current?.id) { _, id in - if id != nil { sendModel.closeDetailPanel() } + guard id != nil else { showApproval = false; return } + let wasShowingSheet = sendModel.state.detailPanel != nil + sendModel.closeDetailPanel() + #if os(macOS) + if wasShowingSheet { + DispatchQueue.main.asyncAfter(deadline: .now() + 0.45) { + if approvals.state.current != nil { showApproval = true } + } + } else { + showApproval = true + } + #else + _ = wasShowingSheet + showApproval = true + #endif } #if os(macOS) // macOS keeps `scenePhase == .active` even when the app loses focus, so diff --git a/apple/VniDrop/App/VniDropApp.swift b/apple/VniDrop/App/VniDropApp.swift index 3882b17..09475e1 100644 --- a/apple/VniDrop/App/VniDropApp.swift +++ b/apple/VniDrop/App/VniDropApp.swift @@ -8,6 +8,10 @@ private let mainWindowId = "main" @main struct VniDropApp: App { @StateObject private var externalInvitations = ExternalInvitationController() + #if DIRECT_DISTRIBUTION && os(macOS) + // Sparkle auto-updater, present only in the direct-download (.dmg) build. + @StateObject private var updater = SparkleUpdaterController() + #endif var body: some Scene { #if os(macOS) @@ -18,6 +22,11 @@ struct VniDropApp: App { .ignoresSafeArea() .onOpenURL(perform: openInvitation) } + #if DIRECT_DISTRIBUTION + .commands { + UpdatesCommands(controller: updater) + } + #endif #else WindowGroup(id: mainWindowId) { RootView(dependencies: makeAppDependencies(externalInvitations: externalInvitations)) diff --git a/apple/VniDrop/Core/BackgroundActivityController.swift b/apple/VniDrop/Core/BackgroundActivityController.swift new file mode 100644 index 0000000..17479a9 --- /dev/null +++ b/apple/VniDrop/Core/BackgroundActivityController.swift @@ -0,0 +1,77 @@ +import Combine +import Foundation +#if os(iOS) +import UIKit +#endif + +/// Keeps the Rust core alive across the app moving to the background, within the +/// bounds Apple actually allows for a serverless P2P transfer app. +/// +/// iOS suspends the whole process (freezing the core's network threads) shortly +/// after the app leaves the foreground. When a transfer or share is active we +/// take a `UIApplication` background-task assertion so iOS grants its finite +/// grace window — long enough for an in-flight transfer to finish streaming and +/// for its completion/failure notification to fire. There is no App-Store-legal +/// mechanism to keep serving or receiving *indefinitely* while backgrounded, and +/// `BGTaskScheduler` wake-ups run only opportunistically and cannot detect an +/// incoming peer connection, so they are deliberately not used here. +/// +/// macOS does not suspend the process on focus loss, so this is a no-op there and +/// the core keeps running normally. +@MainActor +final class BackgroundActivityController { + private let repository: CoreRepository + + init(repository: CoreRepository) { + self.repository = repository + } + + #if os(iOS) + private var assertionId: UIBackgroundTaskIdentifier = .invalid + private var idleCancellable: AnyCancellable? + + /// The app moved to the background. Hold the process open while there is live + /// work; release as soon as it drains, on return to foreground, or when iOS + /// ends the grace window (whichever comes first). + func didEnterBackground() { + guard assertionId == .invalid, hasActiveWork else { return } + assertionId = UIApplication.shared.beginBackgroundTask(withName: "vnidrop.transfer") { [weak self] in + // Expiration handler: iOS is reclaiming the window; end cleanly to + // avoid the watchdog terminating the app. + self?.endAssertion() + } + // Release the assertion the moment work finishes instead of holding it for + // the full window (battery, and it lets the process suspend sooner). Events + // still deliver on the main actor while the window is open, so the core's + // active counts drop here when a transfer completes. + idleCancellable = repository.statePublisher + .map { ($0.status?.activeTransfers ?? 0) == 0 && ($0.status?.activeShares ?? 0) == 0 } + .removeDuplicates() + .sink { [weak self] idle in + if idle { self?.endAssertion() } + } + } + + /// The app returned to the foreground; the process is live again, so drop any + /// held assertion. + func didBecomeForeground() { + endAssertion() + } + + private var hasActiveWork: Bool { + let status = repository.state.status + return (status?.activeTransfers ?? 0) > 0 || (status?.activeShares ?? 0) > 0 + } + + private func endAssertion() { + idleCancellable?.cancel() + idleCancellable = nil + guard assertionId != .invalid else { return } + UIApplication.shared.endBackgroundTask(assertionId) + assertionId = .invalid + } + #else + func didEnterBackground() {} + func didBecomeForeground() {} + #endif +} diff --git a/apple/VniDrop/Core/CoreRepository.swift b/apple/VniDrop/Core/CoreRepository.swift index ed9c81a..997feba 100644 --- a/apple/VniDrop/Core/CoreRepository.swift +++ b/apple/VniDrop/Core/CoreRepository.swift @@ -156,7 +156,7 @@ final class CoreRepository: ObservableObject, CoreGateway { return .failure(CoreNetworkLifecycleError.transitionInProgress) } guard !sources.isEmpty else { - return .failure(InvitationError.message("Select at least one file to share")) + return .failure(InvitationError.shareEmpty) } return await runCore { let result = try self.requireCore().shareFiles( @@ -353,7 +353,7 @@ final class CoreRepository: ObservableObject, CoreGateway { private nonisolated func requireCore() throws -> VnidropCore { guard let core = self.core else { - throw InvitationError.message("Initialize the core first.") + throw InvitationError.coreNotInitialized } return core } diff --git a/apple/VniDrop/Core/ExternalInvitationController.swift b/apple/VniDrop/Core/ExternalInvitationController.swift index d0a82cc..2850e39 100644 --- a/apple/VniDrop/Core/ExternalInvitationController.swift +++ b/apple/VniDrop/Core/ExternalInvitationController.swift @@ -23,23 +23,42 @@ final class ExternalInvitationController: ObservableObject { } func reportOpenFailure(message: String) { - continuation?.yield(.failure(InvitationError.message(message))) + continuation?.yield(.failure(InvitationError.raw(message))) } } +/// Semantic, UI-agnostic invitation/transfer failures. Cases carry no display +/// text: `Error.toUiText()` (UI layer) maps each case to a localized `L10n` key, +/// so there are no free-form English strings to keep in sync or substring-match. +/// `.raw` is the escape hatch for genuinely dynamic system/core messages (e.g. a +/// `CoreNFC` `localizedDescription` or a picker's failure reason), never shown +/// verbatim — it is still routed through `reasonHints`. enum InvitationError: LocalizedError { case empty case tooLarge case invalidEncoding - case message(String) + case shareEmpty + case cancelled + case coreNotInitialized + case unsupportedOperation + case noWindowAvailable + case viewControllerUnavailable + case filesystemUnavailable + case invalidInvitationURL + case nfcUnavailable + case nfcFailed + case cameraUnavailable + case qrUnavailable + case bugReportingUnavailable + case selectionFailed + case deleteRecordsFailed + case raw(String) + /// Developer/log-facing only — never surfaced to users. Derived from the case + /// so there are no hand-written English blobs; `.raw` passes its payload through. var errorDescription: String? { - switch self { - case .empty: return "The invitation is empty" - case .tooLarge: return "The invitation is too large" - case .invalidEncoding: return "The invitation is not valid text" - case .message(let m): return m - } + if case .raw(let reason) = self { return reason } + return String(describing: self) } } diff --git a/apple/VniDrop/Core/FileSystemService.swift b/apple/VniDrop/Core/FileSystemService.swift index f50916e..401d388 100644 --- a/apple/VniDrop/Core/FileSystemService.swift +++ b/apple/VniDrop/Core/FileSystemService.swift @@ -12,6 +12,10 @@ struct PickedShareFile: Equatable, Identifiable, Sendable { var isTemporaryCopy: Bool = false /// When true, `value` is a directory (path or security-scoped folder URL). var isDirectory: Bool = false + /// macOS sandbox: a security-scoped bookmark captured at pick time so access to + /// `value` can be re-acquired when the core imports the file (the picker's own + /// scope ends immediately). Nil on iOS (which copies into the container instead). + var securityScopeBookmark: Data? = nil var id: String { value } } @@ -48,7 +52,7 @@ extension FileSystemService { func canRevealReceiveFolder(_ folder: ReceiveFolder) -> Bool { false } func revealReceiveFolder(_ folder: ReceiveFolder) async -> Result { - .failure(InvitationError.message("Revealing the receive folder is not supported")) + .failure(InvitationError.unsupportedOperation) } func discardPickedFiles(_ files: [PickedShareFile]) async {} diff --git a/apple/VniDrop/Features/Approvals/ApprovalModal.swift b/apple/VniDrop/Features/Approvals/ApprovalModal.swift index 53a6e01..7123dbe 100644 --- a/apple/VniDrop/Features/Approvals/ApprovalModal.swift +++ b/apple/VniDrop/Features/Approvals/ApprovalModal.swift @@ -5,13 +5,17 @@ import SFSafeSymbols /// be swiped away. The endpoint id is the trusted identity; display names are /// peer-provided. struct ApprovalModalHost: View { + /// Driven by the host so presentation can be deferred until any competing sheet + /// (the Share/QR drawer) has finished dismissing — macOS silently drops a sheet + /// presented while another is still animating out. + @Binding var isPresented: Bool let state: ApprovalState let onAccept: (String) -> Void let onRefuse: (String) -> Void var body: some View { Color.clear - .sheet(isPresented: .constant(state.current != nil)) { + .sheet(isPresented: $isPresented) { if let request = state.current { ApprovalSheet(state: state, request: request, onAccept: onAccept, onRefuse: onRefuse) .interactiveDismissDisabled(true) diff --git a/apple/VniDrop/Features/Send/SendModel.swift b/apple/VniDrop/Features/Send/SendModel.swift index eda9c95..951bb77 100644 --- a/apple/VniDrop/Features/Send/SendModel.swift +++ b/apple/VniDrop/Features/Send/SendModel.swift @@ -154,7 +154,7 @@ final class SendModel: ObservableObject { } func onFilePickFailed(_ reason: String) { - messages.error(InvitationError.message(reason.isEmpty ? "selection failed" : reason)) + messages.error(reason.isEmpty ? InvitationError.selectionFailed : InvitationError.raw(reason)) } func clearSelectedSource() { diff --git a/apple/VniDrop/Features/Settings/BugReportService.swift b/apple/VniDrop/Features/Settings/BugReportService.swift index 5bdfad9..17be101 100644 --- a/apple/VniDrop/Features/Settings/BugReportService.swift +++ b/apple/VniDrop/Features/Settings/BugReportService.swift @@ -20,7 +20,7 @@ protocol BugReportService { /// Offline-safe no-op used until the diagnostics transport is configured. struct NoopBugReportService: BugReportService { func submit(_ draft: BugReportDraft, deviceInfo: DeviceInfo?) async -> Result { - .failure(InvitationError.message("Bug reporting is not configured")) + .failure(InvitationError.bugReportingUnavailable) } func previewLogBytes() async -> Int { 0 } } diff --git a/apple/VniDrop/Features/Settings/SettingsModel.swift b/apple/VniDrop/Features/Settings/SettingsModel.swift index b5d3c3f..8158926 100644 --- a/apple/VniDrop/Features/Settings/SettingsModel.swift +++ b/apple/VniDrop/Features/Settings/SettingsModel.swift @@ -206,7 +206,7 @@ final class SettingsModel: ObservableObject { } func onReceiveFolderPicked(_ folder: ReceiveFolder) { preferences.setReceiveFolder(folder) } - func onReceiveFolderPickFailed(_ reason: String) { messages.error(InvitationError.message(reason)) } + func onReceiveFolderPickFailed(_ reason: String) { messages.error(InvitationError.raw(reason)) } func resetReceiveFolder() { preferences.resetReceiveFolder() } /// Whether the current receive folder is the platform default (so the reset @@ -475,7 +475,7 @@ final class SettingsModel: ObservableObject { loadStorageUsage() messages.show(UiMessage(text: .resource(L10n.Storage.transfersDeleted), tone: .success)) } else { - messages.error(InvitationError.message("Could not delete \(failures) transfer records")) + messages.error(InvitationError.deleteRecordsFailed) } } } diff --git a/apple/VniDrop/Features/Settings/SettingsScreen.swift b/apple/VniDrop/Features/Settings/SettingsScreen.swift index 5b436fa..4d2945b 100644 --- a/apple/VniDrop/Features/Settings/SettingsScreen.swift +++ b/apple/VniDrop/Features/Settings/SettingsScreen.swift @@ -24,6 +24,21 @@ struct SettingsScreen: View { var body: some View { NavigationStack(path: path) { Form { + #if os(iOS) + // iOS suspends the app in the background, so serving/receiving + // can't run indefinitely there (unlike macOS). Tell users up + // front so the platform limit doesn't read as a bug. + Section { + VStack(alignment: .leading, spacing: 6) { + Label(String(localized: L10n.Settings.iosBackgroundNoticeTitle), systemSymbol: .moonZzz) + .font(.subheadline.weight(.semibold)) + Text(String(localized: L10n.Settings.iosBackgroundNoticeBody)) + .font(.footnote) + .foregroundStyle(.secondary) + } + .padding(.vertical, 2) + } + #endif Section { NavigationLink(value: SettingsSection.preferences) { SettingsRow(icon: .personCropCircle, title: String(localized: L10n.Preferences.title), value: model.state.username) diff --git a/apple/VniDrop/Platform/FileSystemService+iOS.swift b/apple/VniDrop/Platform/FileSystemService+iOS.swift index b0fcc51..5827dc9 100644 --- a/apple/VniDrop/Platform/FileSystemService+iOS.swift +++ b/apple/VniDrop/Platform/FileSystemService+iOS.swift @@ -32,10 +32,10 @@ struct IosFileSystemService: FileSystemService { func revealReceiveFolder(_ folder: ReceiveFolder) async -> Result { guard canRevealReceiveFolder(folder) else { - return .failure(InvitationError.message("The receive folder is not VniDrop Documents")) + return .failure(InvitationError.filesystemUnavailable) } guard let url = URL(string: "shareddocuments://\(folder.value)") else { - return .failure(InvitationError.message("The Files location URL is unavailable")) + return .failure(InvitationError.filesystemUnavailable) } let opened = await withCheckedContinuation { continuation in DispatchQueue.main.async { @@ -44,7 +44,7 @@ struct IosFileSystemService: FileSystemService { } } } - return opened ? .success(()) : .failure(InvitationError.message("Could not open VniDrop Documents in Files")) + return opened ? .success(()) : .failure(InvitationError.filesystemUnavailable) } func discardPickedFiles(_ files: [PickedShareFile]) async { @@ -62,7 +62,7 @@ struct IosFileSystemService: FileSystemService { accessPolicy: ShareAccessPolicy ) async -> Result { guard !files.isEmpty else { - return .failure(InvitationError.message("Select at least one file to share")) + return .failure(InvitationError.shareEmpty) } let sources = files.map { $0.toIosShareSource() } return await repository.shareSources( diff --git a/apple/VniDrop/Platform/FileSystemService+macOS.swift b/apple/VniDrop/Platform/FileSystemService+macOS.swift index 55628ec..9bf6135 100644 --- a/apple/VniDrop/Platform/FileSystemService+macOS.swift +++ b/apple/VniDrop/Platform/FileSystemService+macOS.swift @@ -42,8 +42,24 @@ struct MacFileSystemService: FileSystemService { accessPolicy: ShareAccessPolicy ) async -> Result { guard !files.isEmpty else { - return .failure(InvitationError.message("Select at least one file to share")) + return .failure(InvitationError.shareEmpty) } + // Re-acquire security-scoped access to every picked source (from the bookmark + // captured at pick time) and hold it across the whole share call. The core + // imports the bytes during shareFiles(), so access only needs to survive that + // call; without this, the import fails with EPERM under the App Store sandbox. + var scopedURLs: [URL] = [] + for file in files { + guard let bookmark = file.securityScopeBookmark else { continue } + var stale = false + guard let url = try? URL( + resolvingBookmarkData: bookmark, options: .withSecurityScope, + relativeTo: nil, bookmarkDataIsStale: &stale + ), url.startAccessingSecurityScopedResource() else { continue } + scopedURLs.append(url) + } + defer { scopedURLs.forEach { $0.stopAccessingSecurityScopedResource() } } + let sources = files.map { ShareSource(kind: .path, value: $0.value, displayName: $0.displayName, isDirectory: $0.isDirectory) } diff --git a/apple/VniDrop/Platform/PlatformPickers.swift b/apple/VniDrop/Platform/PlatformPickers.swift index 9ecb917..184b45c 100644 --- a/apple/VniDrop/Platform/PlatformPickers.swift +++ b/apple/VniDrop/Platform/PlatformPickers.swift @@ -107,9 +107,15 @@ enum PickerSupport { ) #else let size = isDirectory ? nil : (try? url.resourceValues(forKeys: [.fileSizeKey]))?.fileSize.map { UInt64($0) } + // Capture a security-scoped bookmark while the picker's scope is still held, + // so the core can re-acquire access to open the file at import time (under + // the App Store sandbox). Non-sandboxed builds don't need it but it's harmless. + let bookmark = try? url.bookmarkData( + options: .withSecurityScope, includingResourceValuesForKeys: nil, relativeTo: nil + ) return PickedShareFile( value: url.path, displayName: url.lastPathComponent, sizeBytes: size, - isTemporaryCopy: false, isDirectory: isDirectory + isTemporaryCopy: false, isDirectory: isDirectory, securityScopeBookmark: bookmark ) #endif } diff --git a/apple/VniDrop/Platform/ReceiveInvitationActions+iOS.swift b/apple/VniDrop/Platform/ReceiveInvitationActions+iOS.swift index e0610d0..b83a445 100644 --- a/apple/VniDrop/Platform/ReceiveInvitationActions+iOS.swift +++ b/apple/VniDrop/Platform/ReceiveInvitationActions+iOS.swift @@ -29,7 +29,7 @@ final class IosReceiveInvitationActions: NSObject, ReceiveInvitationActions, UID picker.delegate = self picker.modalPresentationStyle = .formSheet guard let presenter = topPresenter() else { - return onResult(.failure(InvitationError.message("Could not find an iOS view controller"))) + return onResult(.failure(InvitationError.viewControllerUnavailable)) } presenter.present(picker, animated: true) } @@ -37,12 +37,12 @@ final class IosReceiveInvitationActions: NSObject, ReceiveInvitationActions, UID func scanQrCode(onResult: @escaping (Result) -> Void) { cancel() guard let presenter = topPresenter() else { - return onResult(.failure(InvitationError.message("Could not find an iOS view controller"))) + return onResult(.failure(InvitationError.viewControllerUnavailable)) } ensureCameraAccess { [weak self] granted in guard let self else { return } guard granted else { - return onResult(.failure(InvitationError.message("Camera access is required to scan QR codes"))) + return onResult(.failure(InvitationError.cameraUnavailable)) } let scanner = QrScannerViewController { result in self.qrController = nil @@ -57,7 +57,7 @@ final class IosReceiveInvitationActions: NSObject, ReceiveInvitationActions, UID func readNfcInvitation(onResult: @escaping (Result) -> Void) { cancel() guard NFCNDEFReaderSession.readingAvailable else { - return onResult(.failure(InvitationError.message("NFC reading is unavailable on this device"))) + return onResult(.failure(InvitationError.nfcUnavailable)) } let reader = InvitationNfcReader { [weak self] result in self?.nfcReader = nil @@ -80,7 +80,7 @@ final class IosReceiveInvitationActions: NSObject, ReceiveInvitationActions, UID let result = documentResult documentResult = nil result?(Result { - guard let url = urls.first else { throw InvitationError.message("The selected invitation URL was invalid") } + guard let url = urls.first else { throw InvitationError.invalidInvitationURL } let started = url.startAccessingSecurityScopedResource() defer { if started { url.stopAccessingSecurityScopedResource() } } let data = try Data(contentsOf: url) @@ -157,19 +157,19 @@ final class QrScannerViewController: UIViewController, AVCaptureMetadataOutputOb } func cancelScan() { - finish(.failure(InvitationError.message("QR scanning was cancelled"))) + finish(.failure(InvitationError.cancelled)) } private func configureSession() { guard let device = AVCaptureDevice.default(for: .video), let input = try? AVCaptureDeviceInput(device: device), session.canAddInput(input) else { - return finish(.failure(InvitationError.message("No camera is available"))) + return finish(.failure(InvitationError.cameraUnavailable)) } session.addInput(input) let output = AVCaptureMetadataOutput() guard session.canAddOutput(output) else { - return finish(.failure(InvitationError.message("Could not configure the QR scanner"))) + return finish(.failure(InvitationError.cameraUnavailable)) } session.addOutput(output) output.setMetadataObjectsDelegate(self, queue: .main) @@ -220,7 +220,7 @@ final class InvitationNfcReader: NSObject, NFCNDEFReaderSessionDelegate, @unchec func start() { let reader = NFCNDEFReaderSession(delegate: self, queue: .main, invalidateAfterFirstRead: true) - reader.alertMessage = "Hold your iPhone near a VniDrop invitation tag" + reader.alertMessage = String(localized: L10n.Receive.nfcWaiting) session = reader reader.begin() } @@ -233,7 +233,7 @@ final class InvitationNfcReader: NSObject, NFCNDEFReaderSessionDelegate, @unchec func readerSession(_ session: NFCNDEFReaderSession, didInvalidateWithError error: Error) { if finished { return } let cancelled = (error as NSError).code == 200 - finish(.failure(InvitationError.message(cancelled ? "NFC reading was cancelled" : error.localizedDescription))) + finish(.failure(cancelled ? InvitationError.cancelled : InvitationError.raw(error.localizedDescription))) } func readerSession(_ session: NFCNDEFReaderSession, didDetectNDEFs messages: [NFCNDEFMessage]) { @@ -242,7 +242,7 @@ final class InvitationNfcReader: NSObject, NFCNDEFReaderSessionDelegate, @unchec .flatMap { $0.records } .compactMap { payloadAsInvitation($0) } .first - guard let ticket else { throw InvitationError.message("This NFC tag does not contain a VniDrop invitation") } + guard let ticket else { throw InvitationError.nfcFailed } return ticket } session.invalidate() diff --git a/apple/VniDrop/Platform/ReceiveInvitationActions+macOS.swift b/apple/VniDrop/Platform/ReceiveInvitationActions+macOS.swift index 2586941..e2ab9f5 100644 --- a/apple/VniDrop/Platform/ReceiveInvitationActions+macOS.swift +++ b/apple/VniDrop/Platform/ReceiveInvitationActions+macOS.swift @@ -22,7 +22,7 @@ final class MacReceiveInvitationActions: ReceiveInvitationActions { } panel.begin { response in guard response == .OK, let url = panel.url else { - onResult(.failure(InvitationError.message("cancelled"))) + onResult(.failure(InvitationError.cancelled)) return } onResult(Result { @@ -33,11 +33,11 @@ final class MacReceiveInvitationActions: ReceiveInvitationActions { } func scanQrCode(onResult: @escaping (Result) -> Void) { - onResult(.failure(InvitationError.message("QR scanning is unavailable on macOS"))) + onResult(.failure(InvitationError.qrUnavailable)) } func readNfcInvitation(onResult: @escaping (Result) -> Void) { - onResult(.failure(InvitationError.message("NFC is unavailable on macOS"))) + onResult(.failure(InvitationError.nfcUnavailable)) } func cancel() {} diff --git a/apple/VniDrop/Platform/SparkleUpdater.swift b/apple/VniDrop/Platform/SparkleUpdater.swift new file mode 100644 index 0000000..1aef1c8 --- /dev/null +++ b/apple/VniDrop/Platform/SparkleUpdater.swift @@ -0,0 +1,49 @@ +#if DIRECT_DISTRIBUTION && os(macOS) +import Combine +import Sparkle +import SwiftUI + +/// Owns the Sparkle updater for the direct-download (.dmg) build. +/// +/// Compiled only under `DIRECT_DISTRIBUTION`, so the App Store / TestFlight target +/// (which must not ship a self-updater) never compiles or links Sparkle. The feed +/// URL and public EdDSA key are read from Info.plist (`SUFeedURL`, `SUPublicEDKey`). +@MainActor +final class SparkleUpdaterController: ObservableObject { + private let updaterController: SPUStandardUpdaterController + /// Mirrors `SPUUpdater.canCheckForUpdates` so the menu item can disable itself + /// while a check is already in flight. + @Published private(set) var canCheckForUpdates = false + + init() { + // `startingUpdater: true` begins the automatic background check schedule. + updaterController = SPUStandardUpdaterController( + startingUpdater: true, + updaterDelegate: nil, + userDriverDelegate: nil + ) + updaterController.updater + .publisher(for: \.canCheckForUpdates) + .assign(to: &$canCheckForUpdates) + } + + func checkForUpdates() { + updaterController.checkForUpdates(nil) + } +} + +/// Adds a "Check for Updates…" item to the application menu (right after the +/// standard "About VniDrop" item), matching the macOS convention. +struct UpdatesCommands: Commands { + @ObservedObject var controller: SparkleUpdaterController + + var body: some Commands { + CommandGroup(after: .appInfo) { + Button(String(localized: L10n.Updates.check)) { + controller.checkForUpdates() + } + .disabled(!controller.canCheckForUpdates) + } + } +} +#endif diff --git a/apple/VniDrop/Platform/TransferShareActions+iOS.swift b/apple/VniDrop/Platform/TransferShareActions+iOS.swift index c9fe5fd..11e090f 100644 --- a/apple/VniDrop/Platform/TransferShareActions+iOS.swift +++ b/apple/VniDrop/Platform/TransferShareActions+iOS.swift @@ -36,7 +36,7 @@ final class IosTransferShareActions: NSObject, TransferShareActions { func writeInvitationToNfc(ticket: String, onResult: @escaping (Result) -> Void) { cancelNfcWrite() guard NFCNDEFReaderSession.readingAvailable else { - onResult(.failure(InvitationError.message("NFC is unavailable on this device"))) + onResult(.failure(InvitationError.nfcUnavailable)) return } let writer = InvitationNfcWriter(ticket: ticket) { [weak self] result in @@ -55,7 +55,7 @@ final class IosTransferShareActions: NSObject, TransferShareActions { @MainActor private func present(_ controller: UIViewController) throws { guard let presenter = topPresenter() else { - throw InvitationError.message("Could not find an iOS view controller") + throw InvitationError.viewControllerUnavailable } presenter.present(controller, animated: true) } @@ -76,7 +76,7 @@ final class InvitationNfcWriter: NSObject, NFCNDEFReaderSessionDelegate, @unchec func start() { let reader = NFCNDEFReaderSession(delegate: self, queue: .main, invalidateAfterFirstRead: false) - reader.alertMessage = "Hold your iPhone near a writable NFC tag" + reader.alertMessage = String(localized: L10n.Transfer.nfcWaiting) session = reader reader.begin() } @@ -89,14 +89,14 @@ final class InvitationNfcWriter: NSObject, NFCNDEFReaderSessionDelegate, @unchec func readerSession(_ session: NFCNDEFReaderSession, didInvalidateWithError error: Error) { if finished { return } let cancelled = (error as NSError).code == 200 // readerSessionInvalidationErrorUserCanceled - finish(.failure(InvitationError.message(cancelled ? "NFC writing was cancelled" : error.localizedDescription))) + finish(.failure(cancelled ? InvitationError.cancelled : InvitationError.raw(error.localizedDescription))) } func readerSession(_ session: NFCNDEFReaderSession, didDetectNDEFs messages: [NFCNDEFMessage]) {} func readerSession(_ session: NFCNDEFReaderSession, didDetect tags: [NFCNDEFTag]) { guard let firstTag = tags.first else { - return finish(.failure(InvitationError.message("No NFC tag was detected"))) + return finish(.failure(InvitationError.nfcFailed)) } // CoreNFC completion handlers run on the session's `.main` queue; these // framework values are safe to use there. @@ -109,18 +109,18 @@ final class InvitationNfcWriter: NSObject, NFCNDEFReaderSessionDelegate, @unchec if let queryError { return self.finish(.failure(queryError)) } switch status { case .notSupported: - self.finish(.failure(InvitationError.message("This NFC tag does not support NDEF"))) + self.finish(.failure(InvitationError.nfcFailed)) case .readOnly: - self.finish(.failure(InvitationError.message("This NFC tag is read-only"))) + self.finish(.failure(InvitationError.nfcFailed)) default: guard let message = self.invitationMessage() else { - return self.finish(.failure(InvitationError.message("Could not encode the invitation for NFC"))) + return self.finish(.failure(InvitationError.nfcFailed)) } tag.writeNDEF(message) { writeError in if let writeError { self.finish(.failure(writeError)) } else { - session.alertMessage = "Invitation written" + session.alertMessage = String(localized: L10n.Transfer.nfcWritten) session.invalidate() self.finish(.success(())) } diff --git a/apple/VniDrop/Platform/TransferShareActions+macOS.swift b/apple/VniDrop/Platform/TransferShareActions+macOS.swift index 20878b9..7854f42 100644 --- a/apple/VniDrop/Platform/TransferShareActions+macOS.swift +++ b/apple/VniDrop/Platform/TransferShareActions+macOS.swift @@ -17,7 +17,7 @@ final class MacTransferShareActions: TransferShareActions { panel.allowedContentTypes = [] panel.begin { response in guard response == .OK, let url = panel.url else { - onResult(.failure(InvitationError.message("cancelled"))) + onResult(.failure(InvitationError.cancelled)) return } onResult(Result { try ticket.write(to: url, atomically: true, encoding: .utf8) }) @@ -28,7 +28,7 @@ final class MacTransferShareActions: TransferShareActions { do { let url = try writeTemporaryInvitation(ticket: ticket, transferName: transferName) guard let view = NSApp.keyWindow?.contentView else { - onResult(.failure(InvitationError.message("No window available"))) + onResult(.failure(InvitationError.noWindowAvailable)) return } let picker = NSSharingServicePicker(items: [url]) @@ -40,7 +40,7 @@ final class MacTransferShareActions: TransferShareActions { } func writeInvitationToNfc(ticket: String, onResult: @escaping (Result) -> Void) { - onResult(.failure(InvitationError.message("NFC is unavailable on macOS"))) + onResult(.failure(InvitationError.nfcUnavailable)) } func cancelNfcWrite() {} diff --git a/apple/VniDrop/Resources/AppIcon.icon/Assets/Drop.svg b/apple/VniDrop/Resources/AppIcon.icon/Assets/Drop.svg new file mode 100644 index 0000000..f6b4544 --- /dev/null +++ b/apple/VniDrop/Resources/AppIcon.icon/Assets/Drop.svg @@ -0,0 +1,8 @@ + + + + + + + + diff --git a/apple/VniDrop/Resources/AppIcon.icon/Assets/Mask.svg b/apple/VniDrop/Resources/AppIcon.icon/Assets/Mask.svg new file mode 100644 index 0000000..65754f3 --- /dev/null +++ b/apple/VniDrop/Resources/AppIcon.icon/Assets/Mask.svg @@ -0,0 +1,17 @@ + + + + + + + + + + + + + + + + + diff --git a/apple/VniDrop/Resources/AppIcon.icon/Assets/U.svg b/apple/VniDrop/Resources/AppIcon.icon/Assets/U.svg new file mode 100644 index 0000000..3828215 --- /dev/null +++ b/apple/VniDrop/Resources/AppIcon.icon/Assets/U.svg @@ -0,0 +1,8 @@ + + + + + + + + diff --git a/apple/VniDrop/Resources/AppIcon.icon/icon.json b/apple/VniDrop/Resources/AppIcon.icon/icon.json new file mode 100644 index 0000000..b790233 --- /dev/null +++ b/apple/VniDrop/Resources/AppIcon.icon/icon.json @@ -0,0 +1,62 @@ +{ + "fill": { + "linear-gradient": [ + "extended-gray:1.00000,1.00000", + "display-p3:0.55433,0.59923,0.92884,1.00000" + ] + }, + "groups": [ + { + "blend-mode": "normal", + "blur-material": null, + "layers": [ + { + "image-name": "Mask.svg", + "name": "Mask" + } + ], + "lighting": "individual", + "refractivity": { + "depth": 0.5, + "enabled": true, + "strength": 0 + }, + "shadow": { + "kind": "neutral", + "opacity": 0.6 + }, + "specular": true, + "translucency": { + "enabled": true, + "value": 0.8 + } + }, + { + "layers": [ + { + "image-name": "Drop.svg", + "name": "Drop" + }, + { + "image-name": "U.svg", + "name": "U" + } + ], + "lighting": "combined", + "shadow": { + "kind": "neutral", + "opacity": 0.6 + }, + "translucency": { + "enabled": true, + "value": 0.4 + } + } + ], + "supported-platforms": { + "circles": [ + "watchOS" + ], + "squares": "shared" + } +} diff --git a/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/Contents.json b/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/Contents.json deleted file mode 100644 index bf7455d..0000000 --- a/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/Contents.json +++ /dev/null @@ -1,7 +0,0 @@ -{ - "images" : [ - { "idiom" : "universal", "platform" : "ios", "size" : "1024x1024", "filename" : "app-icon.png" }, - { "idiom" : "mac", "scale" : "2x", "size" : "512x512", "filename" : "app-icon.png" } - ], - "info" : { "author" : "xcode", "version" : 1 } -} diff --git a/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/app-icon.png b/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/app-icon.png deleted file mode 100644 index 91e521f..0000000 Binary files a/apple/VniDrop/Resources/Assets.xcassets/AppIcon.appiconset/app-icon.png and /dev/null differ diff --git a/apple/VniDrop/Resources/Info.plist b/apple/VniDrop/Resources/Info.plist index a2613e4..84d9cb3 100644 --- a/apple/VniDrop/Resources/Info.plist +++ b/apple/VniDrop/Resources/Info.plist @@ -20,6 +20,8 @@ $(DEVELOPMENT_LANGUAGE) CFBundleDisplayName VniDrop + ITSAppUsesNonExemptEncryption + LSMultipleInstancesProhibited @@ -55,6 +57,20 @@ $(CURRENT_PROJECT_VERSION) LSApplicationCategoryType public.app-category.utilities + + SUFeedURL + https://github.com/sudosylabs/vnidrop/releases/latest/download/appcast.xml + SUPublicEDKey + /vcOgyrhPi3e58yL8M7hZvDCOgsAKyBsQu/7ChAUk1M= + SUEnableAutomaticChecks + LSSupportsOpeningDocumentsInPlace NFCReaderUsageDescription @@ -73,8 +89,6 @@ UIBackgroundModes - fetch - processing remote-notification UIFileSharingEnabled diff --git a/apple/VniDrop/Resources/VniDrop.entitlements b/apple/VniDrop/Resources/VniDrop.entitlements index 09743a1..a404c90 100644 --- a/apple/VniDrop/Resources/VniDrop.entitlements +++ b/apple/VniDrop/Resources/VniDrop.entitlements @@ -2,10 +2,12 @@ - + com.apple.developer.nfc.readersession.formats - NDEF + TAG + + + diff --git a/apple/VniDrop/UI/Feedback/UserFacingError.swift b/apple/VniDrop/UI/Feedback/UserFacingError.swift index 77cab8d..25f1ede 100644 --- a/apple/VniDrop/UI/Feedback/UserFacingError.swift +++ b/apple/VniDrop/UI/Feedback/UserFacingError.swift @@ -5,6 +5,9 @@ import VnidropCore /// `ui/feedback/UserFacingError.kt`. Never exposes raw `reason=` blobs. extension Error { func toUiText() -> UiText { + if let invitation = self as? InvitationError { + return invitation.uiText + } if let vni = self as? VnidropError { switch vni { case .Ticket: @@ -40,6 +43,7 @@ extension Error { /// True when the user intentionally backed out of a flow. var isUserCancellation: Bool { + if let invitation = self as? InvitationError, case .cancelled = invitation { return true } if let vni = self as? VnidropError, case .Cancelled = vni { return true } let haystack = technicalDetail.lowercased() if haystack.isEmpty { @@ -76,6 +80,39 @@ extension Error { } } +/// Maps each semantic `InvitationError` case to a localized user-facing message. +/// This is the sole `InvitationError` → `L10n` boundary: no substring guessing, +/// except for `.raw`, whose dynamic payload still falls through `reasonHints`. +extension InvitationError { + var uiText: UiText { + switch self { + case .empty: + return .resource(L10n.Error.invitationEmpty) + case .tooLarge, .unsupportedOperation, .noWindowAvailable, + .viewControllerUnavailable, .qrUnavailable, .bugReportingUnavailable, .cancelled: + return .resource(L10n.Error.generic) + case .invalidEncoding, .invalidInvitationURL: + return .resource(L10n.Error.invalidTicket) + case .shareEmpty: + return .resource(L10n.Error.shareEmpty) + case .coreNotInitialized: + return .resource(L10n.Error.startingUp) + case .filesystemUnavailable: + return .resource(L10n.Error.filesystem) + case .nfcUnavailable, .nfcFailed: + return .resource(L10n.Error.nfc) + case .cameraUnavailable: + return .resource(L10n.Error.camera) + case .selectionFailed: + return .resource(L10n.Error.selectionFailed) + case .deleteRecordsFailed: + return .resource(L10n.Error.repository) + case .raw(let reason): + return reasonHints(reason) ?? .resource(L10n.Error.generic) + } + } +} + /// Maps a receiver delivery/refusal reason code to a user-facing message, never /// surfacing the raw core code (e.g. `destination_exists`). Unknown codes fall back /// to the substring hints, then a generic message. diff --git a/apple/project.yml b/apple/project.yml index 806fc85..faf3d7c 100644 --- a/apple/project.yml +++ b/apple/project.yml @@ -12,6 +12,15 @@ options: macOS: "15.0" createIntermediateGroups: true +# Build configurations. Declaring `configs` replaces XcodeGen's Debug/Release +# defaults, so both are re-listed here. `Release-Direct` is a release-type config +# used only by the VniDropDirect (notarized DMG + Sparkle) target; the App Store +# `VniDrop` target ships under plain `Release`. +configs: + Debug: debug + Release: release + Release-Direct: release + # Project-wide build settings (applied to every target/config). settings: base: @@ -26,27 +35,44 @@ packages: SFSafeSymbols: url: https://github.com/SFSafeSymbols/SFSafeSymbols from: "5.3.0" + # Sparkle powers in-app auto-updates for the direct-download (.dmg) build only. + # It is linked exclusively by the VniDropDirect target — SwiftPM links products + # per target, not per config, so keeping it off the App Store target is what + # guarantees the store binary never bundles a self-updater (App Store forbids it). + Sparkle: + url: https://github.com/sparkle-project/Sparkle + from: "2.9.4" -targets: - VniDrop: +# Shared definition for the two shipping app targets. `VniDrop` (App Store / +# TestFlight) and `VniDropDirect` (notarized DMG + Sparkle) build the exact same +# sources; only their destinations, extra dependencies, and the DIRECT_DISTRIBUTION +# compile flag differ (set per target below). +targetTemplates: + AppBase: type: application - supportedDestinations: [iOS, macOS] configFiles: Debug: Signing.xcconfig Release: Signing.xcconfig + Release-Direct: Signing.xcconfig sources: - path: VniDrop excludes: - "Resources/Info.plist" - "Resources/VniDrop.entitlements" + - "Resources/VniDropDirect.entitlements" - "Resources/**/.DS_Store" settings: base: + PRODUCT_NAME: VniDrop PRODUCT_BUNDLE_IDENTIFIER: com.vnidrop.app MARKETING_VERSION: "0.1.0" + # Placeholder only — the real CFBundleVersion is stamped at build time as a + # UTC YYMMDD.HHMM timestamp by the "Stamp build number" phase below, so every + # build is monotonic and self-describing (shown as "MARKETING_VERSION (build)"). CURRENT_PROJECT_VERSION: "1" GENERATE_INFOPLIST_FILE: NO INFOPLIST_FILE: VniDrop/Resources/Info.plist + CODE_SIGN_ENTITLEMENTS: VniDrop/Resources/VniDrop.entitlements # Mirror the Info.plist identity so Xcode's Identity editor shows it too # (the editor reads these build settings, not the manual plist). INFOPLIST_KEY_CFBundleDisplayName: VniDrop @@ -59,10 +85,11 @@ targets: # AccentColor asset mirrors VniDropColors.brandPurple — keep them in sync. ASSETCATALOG_COMPILER_GLOBAL_ACCENT_COLOR_NAME: AccentColor configs: - debug: - CODE_SIGN_ENTITLEMENTS: VniDrop/Resources/VniDrop.entitlements release: - CODE_SIGN_ENTITLEMENTS: VniDrop/Resources/VniDrop.entitlements + # Produce a dSYM in the archive so symbol upload succeeds. + DEBUG_INFORMATION_FORMAT: dwarf-with-dsym + release-direct: + DEBUG_INFORMATION_FORMAT: dwarf-with-dsym dependencies: - package: VnidropCore - package: SFSafeSymbols @@ -84,6 +111,52 @@ targets: echo "error: SwiftLint not installed — run 'brew install swiftlint'" exit 1 fi + postBuildScripts: + # Stamp CFBundleVersion as a UTC YYMMDD.HHMM timestamp into the built + # Info.plist before code signing. Runs for every build (Xcode GUI archive and + # CLI alike), so both the App Store and direct-download channels get a + # monotonic, meaningful build id. CI/reproducible builds can pin it via the + # VNIDROP_BUILD env var. MARKETING_VERSION stays the human X.Y.Z version. + - name: Stamp build number (UTC timestamp) + basedOnDependencyAnalysis: false + script: | + build="${VNIDROP_BUILD:-$(date -u +%y%m%d.%H%M)}" + plist="${TARGET_BUILD_DIR}/${INFOPLIST_PATH}" + if [ -f "$plist" ]; then + /usr/libexec/PlistBuddy -c "Set :CFBundleVersion $build" "$plist" + echo "Stamped CFBundleVersion = $build" + else + echo "warning: Info.plist not found at $plist; CFBundleVersion not stamped" + fi + +targets: + # App Store / TestFlight target. iOS + macOS, sandboxed, no self-updater. + VniDrop: + templates: [AppBase] + supportedDestinations: [iOS, macOS] + + # Direct-download macOS target: Developer ID signed, notarized, ships in a .dmg + # and self-updates via Sparkle. DIRECT_DISTRIBUTION gates all Sparkle code so the + # App Store target above never compiles or links it. + VniDropDirect: + templates: [AppBase] + supportedDestinations: [macOS] + settings: + base: + SWIFT_ACTIVE_COMPILATION_CONDITIONS: "$(inherited) DIRECT_DISTRIBUTION" + # Notarization requires the hardened runtime. + ENABLE_HARDENED_RUNTIME: YES + # Non-sandboxed entitlements: a sandboxed Developer ID app needs a + # provisioning profile, which direct distribution avoids. (App Store target + # keeps VniDrop.entitlements with the sandbox.) + CODE_SIGN_ENTITLEMENTS: VniDrop/Resources/VniDropDirect.entitlements + # The Rust core's macOS slice (vnidrop.xcframework) is arm64-only + # (build-core.sh builds aarch64-apple-darwin only), so the direct build is + # Apple-Silicon-only. Pin ARCHS so the Release-Direct (universal-by-default) + # link doesn't fail looking for x86_64 symbols. + ARCHS: arm64 + dependencies: + - package: Sparkle VniDropTests: type: bundle.unit-test @@ -91,6 +164,7 @@ targets: configFiles: Debug: Signing.xcconfig Release: Signing.xcconfig + Release-Direct: Signing.xcconfig sources: - path: Tests settings: @@ -112,3 +186,21 @@ schemes: config: Debug targets: - VniDropTests + # TestFlight ships the Release build; make the Archive/Profile actions explicit + # so Product → Archive can never pick up a Debug configuration. + profile: + config: Release + archive: + config: Release + + # Direct-download build: always the Release-Direct config (Sparkle + notarization). + VniDropDirect: + build: + targets: + VniDropDirect: all + run: + config: Release-Direct + profile: + config: Release-Direct + archive: + config: Release-Direct diff --git a/apple/scripts/ExportOptions-DeveloperID.plist b/apple/scripts/ExportOptions-DeveloperID.plist new file mode 100644 index 0000000..27229b8 --- /dev/null +++ b/apple/scripts/ExportOptions-DeveloperID.plist @@ -0,0 +1,19 @@ + + + + + + method + developer-id + signingStyle + manual + + teamID + ${DEVELOPMENT_TEAM} + + diff --git a/apple/scripts/build-dmg.sh b/apple/scripts/build-dmg.sh new file mode 100755 index 0000000..6504a7f --- /dev/null +++ b/apple/scripts/build-dmg.sh @@ -0,0 +1,158 @@ +#!/usr/bin/env bash +# +# Builds the direct-download macOS artifact: a Developer ID–signed, notarized +# .dmg of the VniDropDirect target (the Sparkle-enabled build). Produces: +# - apple/dist/VniDrop-.dmg (signed + stapled when notarizing) +# +# This is the direct-distribution counterpart to the App Store archive flow; it +# never touches the App Store `VniDrop` target. The Rust crate is not modified. +# +# Usage: apple/scripts/build-dmg.sh [version] +# version MAJOR.MINOR.PATCH; defaults to MARKETING_VERSION / the git tag. +# +# Environment: +# DEVELOPER_ID_APP Codesign identity, e.g. "Developer ID Application: … (TEAMID)". +# Auto-detected from the keychain when unset. +# DEVELOPMENT_TEAM Apple team ID (10 chars). Auto-derived from the identity. +# NOTARY_PROFILE Name of a `xcrun notarytool store-credentials` keychain +# profile. When set, the DMG is notarized and stapled; when +# unset the build still produces a signed DMG and prints the +# pending notarization step (useful before creds exist). +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)" +APPLE_DIR="$REPO_ROOT/apple" +DIST_DIR="$APPLE_DIR/dist" +BUILD_DIR="$APPLE_DIR/.build-dmg" +PROJECT="$APPLE_DIR/VniDrop.xcodeproj" +SCHEME="VniDropDirect" +CONFIG="Release-Direct" +APP_NAME="VniDrop" + +# --- Resolve version (arg > git tag > project MARKETING_VERSION) ------------- +resolve_version() { + local v="${1:-}" + if [ -z "$v" ] && [ "${GITHUB_REF_TYPE:-}" = "tag" ]; then + v="${GITHUB_REF_NAME#v}" + fi + if [ -z "$v" ]; then + v="$(sed -nE 's/.*MARKETING_VERSION: "([0-9.]+)".*/\1/p' "$APPLE_DIR/project.yml" | head -1)" + fi + if [[ ! "$v" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + echo "version must be MAJOR.MINOR.PATCH (got '$v')" >&2 + exit 1 + fi + printf '%s' "$v" +} +VERSION="$(resolve_version "${1:-}")" + +# CFBundleVersion is a UTC YYMMDD.HHMM timestamp stamped by the target's +# "Stamp build number" build phase. Pin it here (one value for the whole archive) +# so the app, DMG, and appcast all agree; Sparkle compares it to order updates. +BUILD_NUMBER="$(date -u +%y%m%d.%H%M)" +export VNIDROP_BUILD="$BUILD_NUMBER" + +# --- Resolve signing identity ------------------------------------------------ +if [ -z "${DEVELOPER_ID_APP:-}" ]; then + DEVELOPER_ID_APP="$(security find-identity -v -p codesigning 2>/dev/null \ + | sed -nE 's/.*"(Developer ID Application: [^"]+)".*/\1/p' | head -1)" +fi +if [ -z "${DEVELOPER_ID_APP:-}" ]; then + echo "error: no 'Developer ID Application' identity found in the keychain." >&2 + echo " Create one in Xcode ▸ Settings ▸ Accounts, or set DEVELOPER_ID_APP." >&2 + exit 1 +fi +if [ -z "${DEVELOPMENT_TEAM:-}" ]; then + # The team ID is the 10-char code in the trailing parenthesis of the identity. + DEVELOPMENT_TEAM="$(printf '%s' "$DEVELOPER_ID_APP" | sed -nE 's/.*\(([A-Z0-9]{10})\)$/\1/p')" +fi +echo "==> Direct build v$VERSION (CFBundleVersion $BUILD_NUMBER)" +echo " identity: $DEVELOPER_ID_APP" +echo " team: ${DEVELOPMENT_TEAM:-}" + +# --- Build core + regenerate project ---------------------------------------- +# Release core needs LTO disabled (workspace thin-LTO miscompiles proc-macros). +echo "==> Building Rust core (release)" +CARGO_PROFILE_RELEASE_LTO=false "$SCRIPT_DIR/build-core.sh" release +echo "==> Regenerating Xcode project" +( cd "$APPLE_DIR" && xcodegen generate >/dev/null ) + +rm -rf "$BUILD_DIR" && mkdir -p "$BUILD_DIR" "$DIST_DIR" +ARCHIVE="$BUILD_DIR/$APP_NAME.xcarchive" +EXPORT_DIR="$BUILD_DIR/export" + +# --- Archive + export (Developer ID) ---------------------------------------- +echo "==> Archiving $SCHEME ($CONFIG)" +xcodebuild archive \ + -project "$PROJECT" \ + -scheme "$SCHEME" \ + -configuration "$CONFIG" \ + -destination 'generic/platform=macOS' \ + -archivePath "$ARCHIVE" \ + MARKETING_VERSION="$VERSION" \ + DEVELOPMENT_TEAM="$DEVELOPMENT_TEAM" \ + CODE_SIGN_STYLE=Manual \ + CODE_SIGN_IDENTITY="$DEVELOPER_ID_APP" \ + | xcbeautify 2>/dev/null || true +[ -d "$ARCHIVE" ] || { echo "error: archive failed" >&2; exit 1; } + +echo "==> Exporting Developer ID app" +EXPORT_OPTS="$BUILD_DIR/ExportOptions.plist" +sed "s/\${DEVELOPMENT_TEAM}/$DEVELOPMENT_TEAM/" \ + "$SCRIPT_DIR/ExportOptions-DeveloperID.plist" > "$EXPORT_OPTS" +xcodebuild -exportArchive \ + -archivePath "$ARCHIVE" \ + -exportPath "$EXPORT_DIR" \ + -exportOptionsPlist "$EXPORT_OPTS" +APP="$EXPORT_DIR/$APP_NAME.app" +[ -d "$APP" ] || { echo "error: export failed" >&2; exit 1; } + +# --- Build the DMG ----------------------------------------------------------- +DMG="$DIST_DIR/$APP_NAME-$VERSION.dmg" +rm -f "$DMG" +STAGING="$BUILD_DIR/dmg-staging" +rm -rf "$STAGING" && mkdir -p "$STAGING" +cp -R "$APP" "$STAGING/" +ln -s /Applications "$STAGING/Applications" + +echo "==> Building DMG" +if command -v create-dmg >/dev/null 2>&1; then + create-dmg \ + --volname "$APP_NAME" \ + --app-drop-link 380 205 \ + --icon "$APP_NAME.app" 130 205 \ + --window-size 540 380 \ + --no-internet-enable \ + "$DMG" "$STAGING" >/dev/null || { + # create-dmg exits non-zero if it can't set the fancy layout; fall back. + [ -f "$DMG" ] || hdiutil create -volname "$APP_NAME" -srcfolder "$STAGING" \ + -ov -format UDZO "$DMG" >/dev/null + } +else + hdiutil create -volname "$APP_NAME" -srcfolder "$STAGING" \ + -ov -format UDZO "$DMG" >/dev/null +fi + +echo "==> Signing DMG" +codesign --force --sign "$DEVELOPER_ID_APP" --timestamp "$DMG" + +# --- Notarize + staple ------------------------------------------------------- +if [ -n "${NOTARY_PROFILE:-}" ]; then + echo "==> Notarizing (profile: $NOTARY_PROFILE)" + xcrun notarytool submit "$DMG" --keychain-profile "$NOTARY_PROFILE" --wait + echo "==> Stapling" + xcrun stapler staple "$DMG" + xcrun stapler validate "$DMG" + spctl -a -vvv --type install "$DMG" || true +else + echo "==> NOTARY_PROFILE unset — skipping notarization." + echo " The DMG is signed but NOT notarized; Gatekeeper will block it until" + echo " you run 'xcrun notarytool store-credentials' and re-run with NOTARY_PROFILE set." +fi + +SIZE="$(stat -f%z "$DMG")" +echo "==> Done." +echo " dmg: $DMG" +echo " version: $VERSION" +echo " size: $SIZE bytes" diff --git a/apple/scripts/generate-appcast.sh b/apple/scripts/generate-appcast.sh new file mode 100755 index 0000000..762bd43 --- /dev/null +++ b/apple/scripts/generate-appcast.sh @@ -0,0 +1,68 @@ +#!/usr/bin/env bash +# +# Generates/updates the Sparkle appcast for the direct-download build. Runs +# Sparkle's `generate_appcast` over the DMGs in apple/dist/, writing: +# - apple/dist/appcast.xml +# +# The URLs point at the matching GitHub Release download assets, and +# each item is signed with the project's EdDSA key (from a key file or the +# keychain). The resulting appcast.xml is uploaded as a release asset; the app's +# SUFeedURL (/releases/latest/download/appcast.xml) always resolves to the newest. +# +# Usage: apple/scripts/generate-appcast.sh [version] +# +# Environment: +# DIST_DIR Folder holding the DMG(s). Default: apple/dist +# SPARKLE_BIN Dir containing generate_appcast. Auto-located when unset. +# SPARKLE_ED_KEY_FILE Path to the EdDSA private key file. When unset, +# generate_appcast reads the key from the login keychain. +# RELEASE_REPO owner/repo for enclosure URLs. Default: sudosylabs/vnidrop +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)" +APPLE_DIR="$REPO_ROOT/apple" +DIST_DIR="${DIST_DIR:-$APPLE_DIR/dist}" +RELEASE_REPO="${RELEASE_REPO:-sudosylabs/vnidrop}" + +VERSION="${1:-}" +if [ -z "$VERSION" ] && [ "${GITHUB_REF_TYPE:-}" = "tag" ]; then + VERSION="${GITHUB_REF_NAME#v}" +fi +[ -n "$VERSION" ] || { echo "error: version required (arg or tag)" >&2; exit 1; } + +# Enclosure URLs resolve to the specific release's assets. +DOWNLOAD_PREFIX="https://github.com/$RELEASE_REPO/releases/download/v$VERSION" + +# --- Locate generate_appcast ------------------------------------------------- +find_tool() { + local name="$1" + if [ -n "${SPARKLE_BIN:-}" ] && [ -x "$SPARKLE_BIN/$name" ]; then + printf '%s' "$SPARKLE_BIN/$name"; return 0 + fi + if command -v "$name" >/dev/null 2>&1; then command -v "$name"; return 0; fi + # Sparkle SPM artifact bundle lands under DerivedData SourcePackages. + local dd="${APPLE_DERIVED_DATA:-$HOME/Library/Developer/Xcode/DerivedData}" + local hit + hit="$(find "$dd" "$HOME/Library/Caches/org.swift.swiftpm" -type f -name "$name" \ + -perm -111 2>/dev/null | head -1 || true)" + [ -n "$hit" ] && { printf '%s' "$hit"; return 0; } + return 1 +} +GENERATE_APPCAST="$(find_tool generate_appcast || true)" +if [ -z "$GENERATE_APPCAST" ]; then + echo "error: generate_appcast not found. Set SPARKLE_BIN to Sparkle's bin/ dir" >&2 + echo " (download from https://github.com/sparkle-project/Sparkle/releases)." >&2 + exit 1 +fi +echo "==> Using $GENERATE_APPCAST" + +# --- Generate ---------------------------------------------------------------- +args=( --download-url-prefix "$DOWNLOAD_PREFIX/" -o "$DIST_DIR/appcast.xml" ) +if [ -n "${SPARKLE_ED_KEY_FILE:-}" ]; then + args+=( --ed-key-file "$SPARKLE_ED_KEY_FILE" ) +fi +echo "==> Generating appcast (v$VERSION) → $DIST_DIR/appcast.xml" +"$GENERATE_APPCAST" "${args[@]}" "$DIST_DIR" + +echo "==> Done. Enclosure prefix: $DOWNLOAD_PREFIX/" diff --git a/localization/strings.json b/localization/strings.json index b02514d..2196c4f 100644 --- a/localization/strings.json +++ b/localization/strings.json @@ -3430,6 +3430,40 @@ "ru": "Дополнительно" } }, + "settings_ios_background_notice_body": { + "context": "Settings overview: explains iOS/iPadOS background limits so users don't think the app is broken. Apple platforms only.", + "targets": [ + "apple" + ], + "translations": { + "en": "iPhone and iPad limit what apps may do in the background. VniDrop keeps a transfer that's already running alive long enough to finish and notify you after you leave the app, but it can't keep serving or receiving on its own once it's been in the background for a while. For long transfers, keep VniDrop open. On Mac, transfers continue in the background normally.", + "fr": "L’iPhone et l’iPad limitent ce que les apps peuvent faire en arrière-plan. VniDrop maintient un transfert déjà en cours assez longtemps pour le terminer et vous avertir après avoir quitté l’app, mais il ne peut pas continuer à envoyer ou recevoir seul une fois resté en arrière-plan un certain temps. Pour les transferts longs, gardez VniDrop ouvert. Sur Mac, les transferts se poursuivent normalement en arrière-plan.", + "es": "El iPhone y el iPad limitan lo que las apps pueden hacer en segundo plano. VniDrop mantiene una transferencia ya en curso el tiempo suficiente para terminarla y avisarte tras salir de la app, pero no puede seguir enviando o recibiendo por sí solo cuando lleva un rato en segundo plano. Para transferencias largas, mantén VniDrop abierto. En Mac, las transferencias continúan en segundo plano con normalidad.", + "it": "iPhone e iPad limitano ciò che le app possono fare in background. VniDrop mantiene attivo un trasferimento già in corso quanto basta per completarlo e avvisarti dopo che esci dall’app, ma non può continuare a inviare o ricevere da solo dopo un po’ in background. Per i trasferimenti lunghi, tieni VniDrop aperto. Su Mac i trasferimenti proseguono normalmente in background.", + "de": "iPhone und iPad schränken ein, was Apps im Hintergrund tun dürfen. VniDrop hält eine bereits laufende Übertragung lange genug am Leben, um sie abzuschließen und dich zu benachrichtigen, nachdem du die App verlässt, kann aber nicht von selbst weiter senden oder empfangen, wenn es länger im Hintergrund war. Lass VniDrop bei langen Übertragungen geöffnet. Auf dem Mac laufen Übertragungen im Hintergrund normal weiter.", + "pt": "O iPhone e o iPad limitam o que as apps podem fazer em segundo plano. O VniDrop mantém uma transferência já em curso ativa o tempo suficiente para terminar e notificá-lo depois de sair da app, mas não consegue continuar a enviar ou receber sozinho depois de algum tempo em segundo plano. Para transferências longas, mantenha o VniDrop aberto. No Mac, as transferências continuam normalmente em segundo plano.", + "pl": "iPhone i iPad ograniczają to, co aplikacje mogą robić w tle. VniDrop utrzymuje już trwający transfer wystarczająco długo, aby go dokończyć i powiadomić Cię po opuszczeniu aplikacji, ale nie może samodzielnie wysyłać ani odbierać po dłuższym czasie w tle. Przy długich transferach nie zamykaj VniDrop. Na Macu transfery są kontynuowane w tle normalnie.", + "nl": "iPhone en iPad beperken wat apps op de achtergrond mogen doen. VniDrop houdt een al lopende overdracht lang genoeg actief om deze te voltooien en je te melden nadat je de app verlaat, maar kan niet zelf blijven verzenden of ontvangen als het al een tijd op de achtergrond is. Houd VniDrop open bij lange overdrachten. Op de Mac gaan overdrachten normaal door op de achtergrond.", + "ru": "iPhone и iPad ограничивают действия приложений в фоне. VniDrop удерживает уже идущую передачу достаточно долго, чтобы завершить её и уведомить вас после выхода из приложения, но не может сам продолжать отправку или приём, пробыв некоторое время в фоне. Для долгих передач держите VniDrop открытым. На Mac передачи продолжаются в фоне как обычно." + } + }, + "settings_ios_background_notice_title": { + "context": "Settings overview: title of the iOS/iPadOS background-limits notice. Apple platforms only.", + "targets": [ + "apple" + ], + "translations": { + "en": "Background limits on iPhone & iPad", + "fr": "Limites en arrière-plan sur iPhone et iPad", + "es": "Límites en segundo plano en iPhone y iPad", + "it": "Limiti in background su iPhone e iPad", + "de": "Hintergrund-Grenzen auf iPhone & iPad", + "pt": "Limites em segundo plano no iPhone e iPad", + "pl": "Ograniczenia w tle na iPhonie i iPadzie", + "nl": "Achtergrondlimieten op iPhone en iPad", + "ru": "Ограничения фона на iPhone и iPad" + } + }, "settings_network_title": { "context": "Settings overview row and Network settings screen title.", "translations": { @@ -4595,6 +4629,23 @@ "ru": "Поделиться" } }, + "updates_check": { + "context": "macOS app menu item that checks for a new version via Sparkle. Direct-download (.dmg) build only; never shown in the App Store build.", + "targets": [ + "apple" + ], + "translations": { + "en": "Check for Updates…", + "fr": "Rechercher les mises à jour…", + "es": "Buscar actualizaciones…", + "it": "Cerca aggiornamenti…", + "de": "Nach Updates suchen…", + "pt": "Procurar atualizações…", + "pl": "Sprawdź aktualizacje…", + "nl": "Zoeken naar updates…", + "ru": "Проверить наличие обновлений…" + } + }, "value_unavailable": { "context": "Placeholder shown when a device-info or metadata value can't be read.", "translations": { diff --git a/packaging/apple/.gitignore b/packaging/apple/.gitignore new file mode 100644 index 0000000..4080ad7 --- /dev/null +++ b/packaging/apple/.gitignore @@ -0,0 +1,7 @@ +# Exported screenshots (large; regenerated from the design source) — not tracked. +*.jpg +*.jpeg + +# macOS / editor junk +.DS_Store +*~lock~ diff --git a/packaging/apple/AppStore.af b/packaging/apple/AppStore.af new file mode 100644 index 0000000..45a0299 --- /dev/null +++ b/packaging/apple/AppStore.af @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:2aa9a22a914aa9503f202cf2f2336e9dc236a7aa2cb09fc52a6f1ac61fc90ca7 +size 10653377 diff --git a/packaging/homebrew/tap-README.md b/packaging/homebrew/tap-README.md new file mode 100644 index 0000000..9296b54 --- /dev/null +++ b/packaging/homebrew/tap-README.md @@ -0,0 +1,54 @@ +# homebrew-vnidrop + +Homebrew tap for [VniDrop](https://github.com/sudosylabs/vnidrop) — direct, +private device-to-device file and folder transfer for macOS. + +> This repo only holds the Homebrew **cask**. The app itself lives at +> [sudosylabs/vnidrop](https://github.com/sudosylabs/vnidrop). The cask here is +> updated automatically by VniDrop's release pipeline on each tagged release. + +## Install + +```sh +brew tap sudosylabs/vnidrop +brew install --cask vnidrop +``` + +Or in one line: + +```sh +brew install --cask sudosylabs/vnidrop/vnidrop +``` + +## Update + +VniDrop updates itself in-app via [Sparkle](https://sparkle-project.org), so you +normally don't need to do anything. To update through Homebrew instead: + +```sh +brew upgrade --cask vnidrop +``` + +## Uninstall + +```sh +brew uninstall --cask vnidrop +``` + +Add `--zap` to also remove VniDrop's application support, cache, and preference +files: + +```sh +brew uninstall --zap --cask vnidrop +``` + +## Requirements + +- macOS 15 (Sequoia) or later, Apple Silicon. + +## What you get + +The cask installs the Developer ID–signed, notarized `VniDrop.app` from the +matching [GitHub Release](https://github.com/sudosylabs/vnidrop/releases). App +Store users should install from the Mac App Store instead — that build does not +include the Sparkle self-updater. diff --git a/packaging/homebrew/vnidrop.rb b/packaging/homebrew/vnidrop.rb new file mode 100644 index 0000000..f81fca9 --- /dev/null +++ b/packaging/homebrew/vnidrop.rb @@ -0,0 +1,36 @@ +# Homebrew cask for the direct-download (notarized .dmg) macOS build. +# +# This file is the source template. The Apple release workflow substitutes the +# version + sha256 for each release and pushes the result to the tap repo +# (sudosylabs/homebrew-vnidrop, path Casks/vnidrop.rb). Users then install with: +# brew install --cask sudosylabs/vnidrop/vnidrop +# +# `auto_updates true` tells Homebrew that the app updates itself via Sparkle, so +# `brew upgrade` won't fight the in-app updater. +cask "vnidrop" do + version "0.0.0" + sha256 "0000000000000000000000000000000000000000000000000000000000000000" + + url "https://github.com/sudosylabs/vnidrop/releases/download/v#{version}/VniDrop-#{version}.dmg", + verified: "github.com/sudosylabs/vnidrop/" + name "VniDrop" + desc "Direct device-to-device file and folder transfer over the network" + homepage "https://github.com/sudosylabs/vnidrop" + + livecheck do + url :url + strategy :github_latest + end + + auto_updates true + depends_on arch: :arm64 + depends_on macos: ">= :sequoia" + + app "VniDrop.app" + + zap trash: [ + "~/Library/Application Support/com.vnidrop.app", + "~/Library/Caches/com.vnidrop.app", + "~/Library/Preferences/com.vnidrop.app.plist", + ] +end