From fbb9f1b94eefdf1b7f1a3a25c54019bd9f8deb67 Mon Sep 17 00:00:00 2001 From: Matt Toohey Date: Tue, 14 Jul 2026 15:50:38 +1000 Subject: [PATCH] fix(desktop): warn instead of swallowing ad-hoc codesign failures in ACP staging MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit codesign_if_darwin ran `codesign ... >/dev/null 2>&1 || true`, discarding both the exit status and the error output. An unsigned nested Mach-O therefore never surfaced at stage time — it surfaced much later as Gatekeeper killing a subprocess mid-session, the exact failure mode the nested-Mach-O signing scan exists to prevent, with nothing in the build output to connect the two. Keep the failure non-fatal (an unsignable Mach-O fragment that never executes should not sink the stage, and release builds re-sign with the real identity anyway) but make it visible: capture codesign's combined output and, on non-zero exit, print a stderr warning naming the file plus codesign's own diagnostics. Addresses the swallowed-codesign-failure finding from the bundling-series code review (review 2ed3d00d on b52a665a). Verification: - Forced failure (Mach-O in a read-only directory): warning with file path and codesign's "internal error in Code Signing subsystem" on stderr; script continues under set -e, exit 0. - Notable non-failure probed while testing: codesign xattr-signs non-Mach-O and even corrupt-header files successfully, so the realistic trigger is filesystem/permission trouble, not file(1) false positives. - Full prepare-acp-tools-resource.sh run: no warnings, both manifests written, all 5 staged Mach-Os pass codesign --verify. - bash -n: syntax OK. Co-Authored-By: Claude Fable 5 Signed-off-by: Matt Toohey --- desktop/scripts/prepare-acp-tools-resource.sh | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/desktop/scripts/prepare-acp-tools-resource.sh b/desktop/scripts/prepare-acp-tools-resource.sh index 4e9026564..4bc67126f 100755 --- a/desktop/scripts/prepare-acp-tools-resource.sh +++ b/desktop/scripts/prepare-acp-tools-resource.sh @@ -69,10 +69,19 @@ harness_cli_manifest="$resource_root/harness-clis.json" rm -f "$harness_cli_manifest" harness_cli_entries=() +# Ad-hoc signing failure is a warning, not a hard stop: an unsignable Mach-O +# fragment that never executes should not sink the stage, and release builds +# re-sign everything with the real identity anyway. But it must be visible — +# a silently unsigned binary surfaces much later as Gatekeeper killing a +# subprocess mid-session, which is undiagnosable from build output. codesign_if_darwin() { local file="$1" + local output if [[ "$(uname -s)" == "Darwin" ]] && command -v codesign >/dev/null 2>&1; then - codesign --force --sign - "$file" >/dev/null 2>&1 || true + if ! output="$(codesign --force --sign - "$file" 2>&1)"; then + echo "Warning: ad-hoc codesign failed for $file — Gatekeeper may kill it at spawn time:" >&2 + echo "$output" >&2 + fi fi }