Repository navigation
Bump Sparkle to 2.9.3 to fix auto-update agent kill on macOS 26 - #6678
Conversation
cmux shipped the Sparkle 2.8.1 prebuilt helpers, whose Autoupdate/Updater.app
are built against the macOS 15.5 SDK (Runtime Version 15.5.0), while the cmux app
is built against the macOS 26 SDK. On macOS 26 the kernel AppleSystemPolicy rejects
the SDK-mismatched progress agent at launch ("Validation category (6) does not match
top-level policy match (8)"), so Sparkle times out with SUSparkleErrorDomain(4005) /
underlying (10) "agent connection was never initiated" and no update installs.
Sparkle 2.9.3's prebuilt helpers are built against the macOS 26.2 SDK (RV 26.2.0),
matching the host, which clears the validation-category mismatch. Raise the floor to
2.9.0 in both updater packages and the xcodeproj, and refresh the three lockfiles.
Fixes #5123
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (6)
📝 WalkthroughWalkthroughSparkle is upgraded from the ChangesSparkle dependency upgrade to 2.9.x
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryBumps the Sparkle auto-update framework from 2.8.1 to 2.9.3 across all three lockfiles and raises the minimum version floor to 2.9.0 in both standalone
Confidence Score: 5/5Safe to merge — purely a dependency version bump with no production Swift source changes and no behavioral logic added. All three cmux-owned Package.resolved lockfiles are updated to the same Sparkle 2.9.3 revision hash, both standalone Package.swift manifests and the Xcode project have the minimum version floor raised to 2.9.0, and no production Swift sources are touched. The change is narrow, internally consistent, and directly traceable to the upstream Sparkle release that ships helpers built against the macOS 26 SDK. No files require special attention. All six changed files update version pins and lockfile hashes consistently. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A["cmux.xcodeproj/project.pbxproj\nminimumVersion: 2.5.1 → 2.9.0"] --> B["Xcode workspace\nPackage.resolved\n2.8.1 → 2.9.3"]
C["CmuxUpdater/Package.swift\nfrom: 2.5.1 → 2.9.0"] --> D["CmuxUpdater/Package.resolved\n2.8.1 → 2.9.3"]
E["CmuxUpdaterUI/Package.swift\nfrom: 2.5.1 → 2.9.0"] --> F["CmuxUpdaterUI/Package.resolved\n2.8.1 → 2.9.3"]
B --> G["Sparkle 2.9.3\nUpdater.app built against\nmacOS 26.2 SDK\nRuntime Version 26.2.0"]
D --> G
F --> G
G --> H["✅ Clears AppleSystemPolicy\nvalidation-category mismatch\non macOS 26"]
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
A["cmux.xcodeproj/project.pbxproj\nminimumVersion: 2.5.1 → 2.9.0"] --> B["Xcode workspace\nPackage.resolved\n2.8.1 → 2.9.3"]
C["CmuxUpdater/Package.swift\nfrom: 2.5.1 → 2.9.0"] --> D["CmuxUpdater/Package.resolved\n2.8.1 → 2.9.3"]
E["CmuxUpdaterUI/Package.swift\nfrom: 2.5.1 → 2.9.0"] --> F["CmuxUpdaterUI/Package.resolved\n2.8.1 → 2.9.3"]
B --> G["Sparkle 2.9.3\nUpdater.app built against\nmacOS 26.2 SDK\nRuntime Version 26.2.0"]
D --> G
F --> G
G --> H["✅ Clears AppleSystemPolicy\nvalidation-category mismatch\non macOS 26"]
Reviews (1): Last reviewed commit: "Bump Sparkle to 2.9.3 to fix auto-update..." | Re-trigger Greptile |
Verification (assembled bundle)Built the branch locally (tag (was CI: Note: a true end-to-end "in-app update completes instead of 4005" dogfood requires a published build that an affected Mac installs and then updates from (the failing helper is the one in the currently-installed bundle). That validation happens once this lands in a nightly/release. |
Live dogfood on an affected machine ✅Reproduced the fix end-to-end on a Mac that deterministically 4005s today (macOS 26.5, arm64, Notarized Developer ID). Method: took the machine's real notarized nightly ( Result: the update to This confirms the root cause (SDK-mismatched Sparkle 2.8.1 prebuilt helper) and that bumping to 2.9.x resolves it on real affected hardware. |
…#6678) The both-diverged merge kept the refactor's stale Sparkle requirement (minimumVersion 2.5.1) while Package.resolved already pinned 2.9.3 (matching main's #6678 macOS-26 auto-update-kill fix). Since 2.9.3 satisfies 2.5.1 the app still built, but the pbxproj remote-package requirement diverged from main without a Package.resolved diff — check-package-resolved-policy flagged it. Realign the requirement to main's 2.9.0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Summary
Fixes in-app auto-update failing with
SUSparkleErrorDomain(4005)/ underlying(10) "agent connection was never initiated"on macOS 26 for a subset of users.Root cause (full investigation in #5123): cmux ships the Sparkle 2.8.1 prebuilt binary, whose
Autoupdate/Updater.appare built against the macOS 15.5 SDK (Runtime Version 15.5.0), while the cmux app is built against the macOS 26 SDK (26.4.0). On macOS 26 the kernel'sAppleSystemPolicyrejects the SDK-mismatched progress agent at launch:The progress agent dies,
-spkpnever registers, the host times out (~19s) and surfaces 4005. It is machine-state-gated, so it reproduces for some users and not others on the same OS. Controls: Helium ships the same Sparkle 2.8.1 but built from source against the 26 SDK (Updater RV 26.0.0) and is immune; Codex ships 2.9.1 (RV 26.2.0) and is immune.Fix
Bump Sparkle 2.8.1 -> 2.9.3. Sparkle 2.9.3's prebuilt helpers are built against the macOS 26.2 SDK (
Runtime Version 26.2.0), matching the host, which clears the validation-category mismatch. Floor raised to 2.9.0 in both updater packages and the xcodeproj so resolution can't drop back below the SDK-fixed line; three lockfiles refreshed.Verification
Updater.app/AutoupdatereportRuntime Version=26.2.0/sdk 26.2(vs 2.8.1's15.5.0).Sparkle @ 2.9.3and compiles/links cmux against it with no Sparkle errors (no API breakage 2.8 -> 2.9).cmux DEVbundle'sSparkle.framework/.../Updater.appreportsRuntime Version 26.xfrom the CIrelease-build.Note: scope is the dependency bump only. Inside-out signing (#1962) is complementary hygiene but does not fix this on its own, since the failing helper is validly signed and
spctl-accepts.Follow-up
Consider a post-sign guard that asserts the bundled Sparkle helpers' SDK major matches the host, to prevent a future Sparkle pin from re-introducing the mismatch.
Fixes #5123
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Note
Medium Risk
Touches the auto-update stack (Sparkle helpers bundled in releases); scope is dependency-only with no API changes in app code, but a bad pin could still break updates for all users.
Overview
Upgrades the Sparkle dependency from 2.8.1 to 2.9.3 so in-app auto-update ships updater helpers built against a macOS 26–compatible SDK, addressing failures where the progress agent never connects on macOS 26.
The SPM minimum version floor moves from
2.5.1to2.9.0inCmuxUpdater,CmuxUpdaterUI, and the Xcode project’s remote package reference;Package.resolvedpins are refreshed in those packages and the workspace lockfile to 2.9.3. No application or updater source changes—only dependency metadata and lockfiles.Reviewed by Cursor Bugbot for commit 2ff9f93. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Bumps
Sparkleto 2.9.3 to fix macOS 26 auto‑update failures caused by the updater agent being killed at launch due to an SDK mismatch. Sets the minimumSparklerequirement to 2.9.0 and refreshes lockfiles; fixes #5123.Sparkle2.8.1 → 2.9.3; raise floor to 2.9.0 inPackages/macOS/CmuxUpdater,Packages/macOS/CmuxUpdaterUI, andcmux.xcodeproj; refresh relatedPackage.resolvedfiles.Written for commit 2ff9f93. Summary will update on new commits.
Summary by CodeRabbit