Skip to content

Revert application-identifier injection from nightly signing - #2902

Merged
lawrencecchen merged 1 commit into
mainfrom
fix-nightly-launch
Apr 15, 2026
Merged

lawrencecchen merged 1 commit into
mainfrom
fix-nightly-launch

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Apr 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

PR #2727 added com.apple.application-identifier to the codesigned entitlements blob of the nightly bundle to fix passkey error 1004. That works for ad-hoc / un-notarized local Developer-ID-signed builds, but on the notarized nightly produced by CI, amfi rejects the binary on launch with RBSRequestErrorDomain Code=5 / NSPOSIXErrorDomain Code=163 (Launchd job spawn failed / EAUTH).

The currently-published cmux NIGHTLY build can't be opened at all.

The application-identifier entitlement is intended for App Store / sandboxed iOS-style apps. On Developer ID Mac apps, AuthenticationServices reads the application-identifier at runtime from the embedded provisioning profile, not from the codesigned entitlements blob. The embedded profile was already added in PR 2727 and already carries the right value (7WLXT3NR37.com.cmuxterm.app.nightly). The application-identifier injection is therefore unnecessary and actively breaks notarized launch.

Test plan

  • After merge, run nightly workflow: gh workflow run nightly.yml --repo manaflow-ai/cmux -f force=true
  • Sparkle-update or download the new cmux NIGHTLY.app and verify it launches.
  • In the new nightly's browser panel, register and authenticate a passkey on webauthn.io. The embedded profile should provide the application-identifier to AuthenticationServices.
  • If 1004 returns, we'll need a different workaround (maybe a per-bundle entitlements file with only application-identifier outside the codesign blob, or convince the runtime to read the profile differently).

Summary by cubic

Reverts entitlement injection in the nightly signing step to fix notarized launch failures. The nightly app now launches, and passkeys still work via the embedded provisioning profile.

  • Bug Fixes
    • Removed injection of com.apple.application-identifier and team ID into signed entitlements; use cmux.entitlements as-is in .github/workflows/nightly.yml.
    • Rely on the embedded provisioning profile for the application identifier, preventing amfi EAUTH (163) on launch.

Written for commit 08383c2. Summary will update on new commits.

Summary by CodeRabbit

  • Chores
    • Updated the macOS app codesigning workflow in nightly builds to use the standard entitlements configuration file directly instead of generating nightly-specific temporary entitlements, streamlining the build process.

Adding com.apple.application-identifier to a notarized Developer ID
Mac app's signed entitlements makes amfi reject the binary on launch
with errno 163 (EAUTH / Launchd job spawn failed). That key is for
App Store / sandboxed iOS-style apps; on macOS Developer ID the
application-identifier is read at runtime by AuthenticationServices
from the embedded provisioning profile, not the codesigned entitlements.

Keep the embedded provisioning profile (which already grants
com.apple.developer.web-browser.public-key-credential and carries the
application-identifier) and let the runtime resolve the identifier
from there.
@vercel

vercel Bot commented Apr 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Apr 15, 2026 3:02am

@coderabbitai

coderabbitai Bot commented Apr 15, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 22adcc2d-c6bf-474a-b752-9c0d4b094ad9

📥 Commits

Reviewing files that changed from the base of the PR and between e14710e and 08383c2.

📒 Files selected for processing (1)
  • .github/workflows/nightly.yml

📝 Walkthrough

Walkthrough

The nightly workflow's codesigning step was refactored to eliminate temporary entitlements generation. It now directly reuses the checked-in cmux.entitlements file for signing CLI, helper, and app binaries. Associated validation logic that checked for nightly-specific identifiers was removed.

Changes

Cohort / File(s) Summary
Codesign workflow configuration
.github/workflows/nightly.yml
Replaced temporary nightly-specific entitlements generation with direct use of cmux.entitlements. Removed subsequent validation check for nightly application-identifier. Simplified codesigning flow for CLI, helper, and main app binaries.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Poem

🐰 A rabbit hops through workflows clear,
No temporary files to fear!
One simple entitlements file to share,
Deep-signed binaries everywhere! ✨
Much simpler now, none need repair.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main change: reverting application-identifier injection from the nightly signing workflow.
Description check ✅ Passed The description provides comprehensive context including the problem, root cause, and solution, but lacks a formal Testing section matching the template structure.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-nightly-launch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

lawrencecchen added a commit that referenced this pull request Apr 15, 2026
Same reasoning as PR #2902: putting com.apple.application-identifier
in a notarized Developer ID Mac app's signed entitlements makes amfi
reject the binary on launch (errno 163). Only embed the provisioning
profile and rely on AuthenticationServices to read application-identifier
from there at runtime.
@greptile-apps

greptile-apps Bot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR reverts the injection of com.apple.application-identifier and com.apple.developer.team-identifier into the nightly codesign entitlements blob, restoring the plain cmux.entitlements file for all signing operations. The previous code broke notarized launch because AMFI rejects Developer ID binaries that carry application-identifier in the signed entitlements blob (reserved for App Store / sandboxed profiles); the provisioning profile embedded in the prior PR already delivers that value at runtime, making the injection redundant and harmful.

Confidence Score: 5/5

Safe to merge — minimal targeted revert that fixes a critical production regression (app fails to launch after notarization).

All changes are removals of known-broken behaviour. The remaining codesign pipeline is unchanged, the provisioning profile step still validates app-identifier and WebAuthn entitlement, and the post-sign check for com.apple.developer.web-browser.public-key-credential is retained. No new logic is introduced; passkey regression risk is explicitly acknowledged and mitigated by the embedded profile.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/nightly.yml Removes dynamic entitlements injection (application-identifier, team-identifier) from the Codesign step; all three codesign calls now use the base cmux.entitlements directly. Also removes the post-sign grep that verified application-identifier was present in the entitlements blob, since it is no longer injected.

Sequence Diagram

sequenceDiagram
    participant CI as CI Runner
    participant CS as codesign
    participant NT as notarytool
    participant AMFI as macOS AMFI
    participant AS as AuthenticationServices

    Note over CI,AS: Before this PR (broken notarized launch)
    CI->>CI: Create temp entitlements with application-identifier injected
    CI->>CS: codesign --entitlements NIGHTLY_ENT
    CS-->>CI: Signed with application-identifier in blob
    CI->>NT: notarytool submit
    NT-->>CI: Accepted
    CI->>AMFI: Launch app
    AMFI-->>CI: EAUTH Code=163 — application-identifier in entitlements blob not allowed for Developer ID

    Note over CI,AS: After this PR (fixed)
    CI->>CS: codesign --entitlements cmux.entitlements
    CS-->>CI: Signed (no application-identifier in blob)
    CI->>NT: notarytool submit
    NT-->>CI: Accepted
    CI->>AMFI: Launch app
    AMFI-->>CI: Launch succeeds
    AS->>AS: Reads application-identifier from embedded.provisionprofile at runtime
    AS-->>CI: Passkey WebAuthn available
Loading

Reviews (1): Last reviewed commit: "Revert application-identifier injection ..." | Re-trigger Greptile

@lawrencecchen
lawrencecchen merged commit 1085927 into main Apr 15, 2026
17 checks passed
@lawrencecchen
lawrencecchen deleted the fix-nightly-launch branch April 15, 2026 03:25
lawrencecchen added a commit that referenced this pull request Apr 15, 2026
…itlements

Two changes consolidate the inside-out signing work introduced by
PRs #2902, #2905, and #2906 into something a future reader can
understand without reading two 40-line YAML blocks:

- Check in cmux.release.entitlements and cmux.nightly.entitlements,
  each with the right application-identifier and team-identifier
  baked in. Replaces the PlistBuddy-at-sign-time injection that
  copies cmux.entitlements and mutates it per workflow run.
- Extract the five-step inside-out signing logic (helpers, plugins,
  frameworks, main bundle, verification) into
  scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml
  shrink to one line that calls the script with the right
  entitlements file.

No behavior change versus PR #2906 at steady state: same order, same
--deep boundaries, same grep-based post-sign asserts. The script
also refuses to sign if a helper ends up with the main app's
application-identifier, so future regressions surface at build time
rather than on launch under amfi.
lawrencecchen added a commit that referenced this pull request Apr 15, 2026
…itlements (#2908)

Two changes consolidate the inside-out signing work introduced by
PRs #2902, #2905, and #2906 into something a future reader can
understand without reading two 40-line YAML blocks:

- Check in cmux.release.entitlements and cmux.nightly.entitlements,
  each with the right application-identifier and team-identifier
  baked in. Replaces the PlistBuddy-at-sign-time injection that
  copies cmux.entitlements and mutates it per workflow run.
- Extract the five-step inside-out signing logic (helpers, plugins,
  frameworks, main bundle, verification) into
  scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml
  shrink to one line that calls the script with the right
  entitlements file.

No behavior change versus PR #2906 at steady state: same order, same
--deep boundaries, same grep-based post-sign asserts. The script
also refuses to sign if a helper ends up with the main app's
application-identifier, so future regressions surface at build time
rather than on launch under amfi.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
rodchristiansen pushed a commit to rodchristiansen/cmux that referenced this pull request Sep 2, 2026
…ai#2902)

Adding com.apple.application-identifier to a notarized Developer ID
Mac app's signed entitlements makes amfi reject the binary on launch
with errno 163 (EAUTH / Launchd job spawn failed). That key is for
App Store / sandboxed iOS-style apps; on macOS Developer ID the
application-identifier is read at runtime by AuthenticationServices
from the embedded provisioning profile, not the codesigned entitlements.

Keep the embedded provisioning profile (which already grants
com.apple.developer.web-browser.public-key-credential and carries the
application-identifier) and let the runtime resolve the identifier
from there.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
rodchristiansen pushed a commit to rodchristiansen/cmux that referenced this pull request Sep 2, 2026
…itlements (manaflow-ai#2908)

Two changes consolidate the inside-out signing work introduced by
PRs manaflow-ai#2902, manaflow-ai#2905, and manaflow-ai#2906 into something a future reader can
understand without reading two 40-line YAML blocks:

- Check in cmux.release.entitlements and cmux.nightly.entitlements,
  each with the right application-identifier and team-identifier
  baked in. Replaces the PlistBuddy-at-sign-time injection that
  copies cmux.entitlements and mutates it per workflow run.
- Extract the five-step inside-out signing logic (helpers, plugins,
  frameworks, main bundle, verification) into
  scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml
  shrink to one line that calls the script with the right
  entitlements file.

No behavior change versus PR manaflow-ai#2906 at steady state: same order, same
--deep boundaries, same grep-based post-sign asserts. The script
also refuses to sign if a helper ends up with the main app's
application-identifier, so future regressions surface at build time
rather than on launch under amfi.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview — 08383c2f Deployed Apr 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant