Index: /trunk/BNC/scripts/mac_package.sh
===================================================================
--- /trunk/BNC/scripts/mac_package.sh	(revision 11012)
+++ /trunk/BNC/scripts/mac_package.sh	(revision 11013)
@@ -11,8 +11,8 @@
 #          - optionally signs with a real "Developer ID Application"
 #            identity if CODESIGN_IDENTITY is set in the environment
-#          - packages the result as a zip (via ditto, which preserves the
-#            code signature - plain `zip`/tar can corrupt it)
+#          - packages the result as a dmg (drag-to-Applications, the
+#            expected format for external users) and/or a zip
 #
-# Usage:   scripts/mac_package.sh [path/to/bnc.app]
+# Usage:   scripts/mac_package.sh [--format dmg|zip|both] [path/to/bnc.app]
 #          CODESIGN_IDENTITY="Developer ID Application: Your Name (TEAMID)" \
 #            scripts/mac_package.sh
@@ -33,5 +33,24 @@
 fi
 
-APP_PATH="${1:-bnc.app}"
+FORMAT="dmg"
+APP_PATH=""
+while [[ $# -gt 0 ]]; do
+  case "$1" in
+    --format)
+      FORMAT="$2"
+      shift 2
+      ;;
+    *)
+      APP_PATH="$1"
+      shift
+      ;;
+  esac
+done
+case "$FORMAT" in
+  dmg|zip|both) ;;
+  *) echo "error: --format must be dmg, zip, or both (got '$FORMAT')" >&2; exit 1 ;;
+esac
+
+APP_PATH="${APP_PATH:-bnc.app}"
 if [[ ! -d "$APP_PATH" ]]; then
   # fall back to the usual qmake output location (src.pro: TARGET = ../bnc)
@@ -45,4 +64,5 @@
 fi
 APP_PATH="$(cd "$(dirname "$APP_PATH")" && pwd)/$(basename "$APP_PATH")"
+APP_NAME="$(basename "$APP_PATH" .app)"
 
 command -v macdeployqt >/dev/null 2>&1 || {
@@ -58,5 +78,5 @@
   codesign --force --deep --options runtime --sign "$CODESIGN_IDENTITY" "$APP_PATH"
   echo "   (remember to notarize + staple for Gatekeeper-clean distribution:"
-  echo "    xcrun notarytool submit <zip> --keychain-profile <profile> --wait"
+  echo "    xcrun notarytool submit <dmg-or-zip> --keychain-profile <profile> --wait"
   echo "    xcrun stapler staple \"$APP_PATH\")"
 else
@@ -68,12 +88,27 @@
 codesign --verify --deep --strict --verbose=2 "$APP_PATH"
 
-ZIP_PATH="${APP_PATH%.app}.zip"
-echo "== packaging $ZIP_PATH =="
-rm -f "$ZIP_PATH"
-ditto -c -k --keepParent "$APP_PATH" "$ZIP_PATH"
+if [[ "$FORMAT" == "zip" || "$FORMAT" == "both" ]]; then
+  ZIP_PATH="${APP_PATH%.app}.zip"
+  echo "== packaging $ZIP_PATH =="
+  rm -f "$ZIP_PATH"
+  # ditto preserves the code signature; plain zip/tar can corrupt it
+  ditto -c -k --keepParent "$APP_PATH" "$ZIP_PATH"
+  echo "Done: $ZIP_PATH"
+fi
+
+if [[ "$FORMAT" == "dmg" || "$FORMAT" == "both" ]]; then
+  DMG_PATH="${APP_PATH%.app}.dmg"
+  echo "== packaging $DMG_PATH =="
+  rm -f "$DMG_PATH"
+  STAGING_DIR="$(mktemp -d)"
+  trap 'rm -rf "$STAGING_DIR"' EXIT
+  ditto "$APP_PATH" "$STAGING_DIR/$APP_NAME.app"
+  ln -s /Applications "$STAGING_DIR/Applications"
+  hdiutil create -volname "$APP_NAME" -srcfolder "$STAGING_DIR" -ov -format UDZO "$DMG_PATH"
+  echo "Done: $DMG_PATH"
+fi
 
 echo
-echo "Done: $ZIP_PATH"
 echo "Recipients of an unsigned/ad-hoc build must bypass Gatekeeper once:"
 echo "  - right-click the app -> Open -> confirm, or"
-echo "  - run: xattr -cr \"$(basename "$APP_PATH")\"  after unzipping"
+echo "  - run: xattr -cr \"$APP_NAME.app\"  after mounting/unzipping"
