Revert application-identifier injection from nightly signing - #2902
Conversation
Adding com.apple.application-identifier to a notarized Developer ID Mac app's signed entitlements makes amfi reject the binary on launch with errno 163 (EAUTH / Launchd job spawn failed). That key is for App Store / sandboxed iOS-style apps; on macOS Developer ID the application-identifier is read at runtime by AuthenticationServices from the embedded provisioning profile, not the codesigned entitlements. Keep the embedded provisioning profile (which already grants com.apple.developer.web-browser.public-key-credential and carries the application-identifier) and let the runtime resolve the identifier from there.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe nightly workflow's codesigning step was refactored to eliminate temporary entitlements generation. It now directly reuses the checked-in Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Same reasoning as PR #2902: putting com.apple.application-identifier in a notarized Developer ID Mac app's signed entitlements makes amfi reject the binary on launch (errno 163). Only embed the provisioning profile and rely on AuthenticationServices to read application-identifier from there at runtime.
Greptile SummaryThis PR reverts the injection of Confidence Score: 5/5Safe to merge — minimal targeted revert that fixes a critical production regression (app fails to launch after notarization). All changes are removals of known-broken behaviour. The remaining codesign pipeline is unchanged, the provisioning profile step still validates app-identifier and WebAuthn entitlement, and the post-sign check for com.apple.developer.web-browser.public-key-credential is retained. No new logic is introduced; passkey regression risk is explicitly acknowledged and mitigated by the embedded profile. No files require special attention. Important Files Changed
Sequence DiagramsequenceDiagram
participant CI as CI Runner
participant CS as codesign
participant NT as notarytool
participant AMFI as macOS AMFI
participant AS as AuthenticationServices
Note over CI,AS: Before this PR (broken notarized launch)
CI->>CI: Create temp entitlements with application-identifier injected
CI->>CS: codesign --entitlements NIGHTLY_ENT
CS-->>CI: Signed with application-identifier in blob
CI->>NT: notarytool submit
NT-->>CI: Accepted
CI->>AMFI: Launch app
AMFI-->>CI: EAUTH Code=163 — application-identifier in entitlements blob not allowed for Developer ID
Note over CI,AS: After this PR (fixed)
CI->>CS: codesign --entitlements cmux.entitlements
CS-->>CI: Signed (no application-identifier in blob)
CI->>NT: notarytool submit
NT-->>CI: Accepted
CI->>AMFI: Launch app
AMFI-->>CI: Launch succeeds
AS->>AS: Reads application-identifier from embedded.provisionprofile at runtime
AS-->>CI: Passkey WebAuthn available
Reviews (1): Last reviewed commit: "Revert application-identifier injection ..." | Re-trigger Greptile |
…itlements Two changes consolidate the inside-out signing work introduced by PRs #2902, #2905, and #2906 into something a future reader can understand without reading two 40-line YAML blocks: - Check in cmux.release.entitlements and cmux.nightly.entitlements, each with the right application-identifier and team-identifier baked in. Replaces the PlistBuddy-at-sign-time injection that copies cmux.entitlements and mutates it per workflow run. - Extract the five-step inside-out signing logic (helpers, plugins, frameworks, main bundle, verification) into scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml shrink to one line that calls the script with the right entitlements file. No behavior change versus PR #2906 at steady state: same order, same --deep boundaries, same grep-based post-sign asserts. The script also refuses to sign if a helper ends up with the main app's application-identifier, so future regressions surface at build time rather than on launch under amfi.
…itlements (#2908) Two changes consolidate the inside-out signing work introduced by PRs #2902, #2905, and #2906 into something a future reader can understand without reading two 40-line YAML blocks: - Check in cmux.release.entitlements and cmux.nightly.entitlements, each with the right application-identifier and team-identifier baked in. Replaces the PlistBuddy-at-sign-time injection that copies cmux.entitlements and mutates it per workflow run. - Extract the five-step inside-out signing logic (helpers, plugins, frameworks, main bundle, verification) into scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml shrink to one line that calls the script with the right entitlements file. No behavior change versus PR #2906 at steady state: same order, same --deep boundaries, same grep-based post-sign asserts. The script also refuses to sign if a helper ends up with the main app's application-identifier, so future regressions surface at build time rather than on launch under amfi. Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
…ai#2902) Adding com.apple.application-identifier to a notarized Developer ID Mac app's signed entitlements makes amfi reject the binary on launch with errno 163 (EAUTH / Launchd job spawn failed). That key is for App Store / sandboxed iOS-style apps; on macOS Developer ID the application-identifier is read at runtime by AuthenticationServices from the embedded provisioning profile, not the codesigned entitlements. Keep the embedded provisioning profile (which already grants com.apple.developer.web-browser.public-key-credential and carries the application-identifier) and let the runtime resolve the identifier from there. Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
…itlements (manaflow-ai#2908) Two changes consolidate the inside-out signing work introduced by PRs manaflow-ai#2902, manaflow-ai#2905, and manaflow-ai#2906 into something a future reader can understand without reading two 40-line YAML blocks: - Check in cmux.release.entitlements and cmux.nightly.entitlements, each with the right application-identifier and team-identifier baked in. Replaces the PlistBuddy-at-sign-time injection that copies cmux.entitlements and mutates it per workflow run. - Extract the five-step inside-out signing logic (helpers, plugins, frameworks, main bundle, verification) into scripts/sign-cmux-bundle.sh. Both nightly.yml and release.yml shrink to one line that calls the script with the right entitlements file. No behavior change versus PR manaflow-ai#2906 at steady state: same order, same --deep boundaries, same grep-based post-sign asserts. The script also refuses to sign if a helper ends up with the main app's application-identifier, so future regressions surface at build time rather than on launch under amfi. Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Summary
PR #2727 added
com.apple.application-identifierto the codesigned entitlements blob of the nightly bundle to fix passkey error 1004. That works for ad-hoc / un-notarized local Developer-ID-signed builds, but on the notarized nightly produced by CI, amfi rejects the binary on launch withRBSRequestErrorDomain Code=5 / NSPOSIXErrorDomain Code=163(Launchd job spawn failed / EAUTH).The currently-published
cmux NIGHTLYbuild can't be opened at all.The
application-identifierentitlement is intended for App Store / sandboxed iOS-style apps. On Developer ID Mac apps, AuthenticationServices reads the application-identifier at runtime from the embedded provisioning profile, not from the codesigned entitlements blob. The embedded profile was already added in PR 2727 and already carries the right value (7WLXT3NR37.com.cmuxterm.app.nightly). The application-identifier injection is therefore unnecessary and actively breaks notarized launch.Test plan
gh workflow run nightly.yml --repo manaflow-ai/cmux -f force=truecmux NIGHTLY.appand verify it launches.Summary by cubic
Reverts entitlement injection in the nightly signing step to fix notarized launch failures. The nightly app now launches, and passkeys still work via the embedded provisioning profile.
com.apple.application-identifierand team ID into signed entitlements; usecmux.entitlementsas-is in.github/workflows/nightly.yml.Written for commit 08383c2. Summary will update on new commits.
Summary by CodeRabbit