# Haskell Foundation DevOps Weekly Update, 2022-12-21

**URL:** <https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474>\
**Category:** Haskell Foundation\
**Created:** [December 21, 2022, 1:41pm UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474 "2022-12-21T13:41:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chreekat](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/chreekat/32/2669_2.png) [@chreekat](https://discourse.haskell.org/u/chreekat)\
**Post date:** [December 21, 2022, 1:41pm UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/1 "2022-12-21T13:41:08Z")

</div>

Hello, welcome to week 27!

Like last week, I am working on [Mac notarization](https://gitlab.haskell.org/ghc/ghc/-/issues/17418) for GHC. Since it’s  
my main focus, I will say a few more words about it.

Apple “code signing” and “notarization” are malware-prevention systems built  
into macOS. They require developers to preprocess apps in a way that macOS can  
verify. My task is to implement those processes for GHC, test them, automate the  
process and tests, and add it all to CI. I also want to ensure that notarized  
versions of GHC can be installed with Stack and GHCUp.

Right now, the “GHC official bindist” install script (and GHCUp) uses a hacky  
workaround that bypasses the code signing and notarization requirements. (I’m  
not sure what Stack does here! Does Stack even work on modern macOS, other than  
via GHCUp’s “unofficial binaries”?) I want to make those workarounds go away so  
that we don’t have any more trouble with Mac than necessary.

Other minor things I finished in the last week:

- Bought a Mac Mini to enable the notarization work
- Used my shiny new Mac to begin investigating how macOS behaves regarding code  
signing and notarization
- Wrote a script to remove hundreds of spammy snippets on [GHC GitLab](https://gitlab.haskell.org/explore/snippets)
- Did some git bookkeeping for the gitlab server + bots
- Tried fixing my full-text search database, a tool I use for investigating CI  
errors
- Continued observing CI and raising issues

See ya next week!

---

<div class="post-metadata">

**Author:** ![romes](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/romes/32/2912_2.png) [@romes](https://discourse.haskell.org/u/romes)\
**Post date:** [December 22, 2022, 7:39am UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/2 "2022-12-22T07:39:05Z")

</div>

Thanks for the explanation!

---

<div class="post-metadata">

**Author:** ![mpickering](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/mpickering/32/4585_2.png) [@mpickering](https://discourse.haskell.org/u/mpickering)\
**Post date:** [December 22, 2022, 8:08am UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/3 "2022-12-22T08:08:45Z")

</div>

Thanks Bryan, this kind of change should be invisible to users but really important behind the scenes. Really happy to see you take this up.

---

<div class="post-metadata">

**Author:** ![hasufell](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/hasufell/32/1250_2.png) [@hasufell](https://discourse.haskell.org/u/hasufell)\
**Post date:** [December 22, 2022, 12:36pm UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/4 "2022-12-22T12:36:23Z")

</div>

> [@chreekat](#):
>
> Does Stack even work on modern macOS, other than  
> via GHCUp’s “unofficial binaries”?)

The only existing stack M1 binaries are unofficially built by GHCup devs.

I’m not sure how stack’s GHC installation works on M1.

> <https://github.com/commercialhaskell/stack/blob/2077c87af5660c78f1ecf1bd8d84de740a5e4793/src/Stack/Setup.hs#L1714>

At least I can’t see any `xattr` steps there. Are they still necessary? Who knows.

---

<div class="post-metadata">

**Author:** ![chreekat](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/chreekat/32/2669_2.png) [@chreekat](https://discourse.haskell.org/u/chreekat)\
**Post date:** [December 22, 2022, 12:46pm UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/5 "2022-12-22T12:46:29Z")

</div>

I also had a look at the Stack code (no “xattr” anywhere) and the issues pertaining to macOS (long list is long) and decided this is probably an opportunity to push things forward a bit.

Edit to reiterate that I think everyone should use GHCUp, anyway. 😉

---

<div class="post-metadata">

**Author:** ![hasufell](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/hasufell/32/1250_2.png) [@hasufell](https://discourse.haskell.org/u/hasufell)\
**Post date:** [December 22, 2022, 12:49pm UTC](https://discourse.haskell.org/t/haskell-foundation-devops-weekly-update-2022-12-21/5474/6 "2022-12-22T12:49:50Z")

</div>

> [@chreekat](#):
>
> Edit to reiterate that I think everyone should use GHCUp, anyway.

I’ve proposed: [Can stack utilize ghcup? · Issue #719 · haskell/ghcup-hs · GitHub](https://github.com/haskell/ghcup-hs/issues/719)
