Skip to content

Should we sign disk images to prevent translocation? #792

Description

@jakob

It is apparently possible to sign disk images. This is a separate step from notarization.

More info: https://c-command.com/dropdmg/help/signing

If we sign the disk image, then the app will not be translocated when opening from the disk image.

I'm not sure if that would be useful for us.

Possible benefits:

  • autostart Postgres.app even when it is on the disk image (disk image might be mounted automatically, need to check)
  • nicer binary paths when creating a server with Postgres.app launched from disk image:
    • signed: /Volumes/Postgres-2.7.10-17/Postgres.app/Contents/Versions/17/bin
    • unsigned: /private/var/folders/xx/xxxxxxxx/T/AppTranslocation/xxxx/d/Postgres.app/Contents/Versions/17/bin
  • no translocation when people install app with cp -R instead of using the Finder to move the app

Currently we disable autostart and autoupdate when launching from disk image. We detect that by checking if the path contains "AppTranslocation". We would have to change that logic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions