Skip to content

fix(cli): finalize macOS signatures and verify release artifacts - #1673

Merged
luokerenx4 merged 2 commits into
devfrom
fix/cli-bun-signature
Sep 30, 2026
Merged

luokerenx4 merged 2 commits into
devfrom
fix/cli-bun-signature

Conversation

@luokerenx4

@luokerenx4 luokerenx4 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The v0.94.1 macOS CLI can contain an invalid embedded signature even when its published SHA-256 matches. Bun 1.4.2 fixes the ARM64 tail-page hash, but the x64 compiler still carries stale signature coverage. Finalize both macOS executables with system ad-hoc codesign before generating payload hashes and reject invalid final archives before channel publication. Related: #1670.

  • Keep .bun-version as the exact compiler source of truth; pin 1.4.2, derive the remote-smoke Docker image from it, and verify the actual PATH Bun for compiled broker probes.
  • Sign only build-owned CLI/probe/fixture outputs in a temporary copy. Preserve and check entitlements/runtime flags, run native strict verification plus static page verification, then replace the output. No Developer ID, notarization credentials, user-side re-signing, or Electron changes.
  • Verify final tar bytes, actual files/modes/link targets, manifest identity and macOS code/special-slot hashes. Dev and package-manager preparation share this gate; beta/stable publication verifies downloaded candidates again.
  • Add a read-only PR/manual workflow for Linux x64 and both native Mac architectures. It saves exact-head candidate archives/reports and verifies the preserved Mac bytes again on Linux.

Validation:

  • Focused signature/archive/channel/install/update/rollback suite: 102 passed, 1 skipped.
  • Root and UI typechecks; build:server: passed.
  • Real Linux Bun 1.4.2 CLI build: passed isolated identity upgrade, no Node/Bun on PATH, startup/resources/UI, and two independent PTYs with resize/input/stop.
  • Compiled multiprocess Runtime feasibility: passed connector/UTA recovery and runtime-lock release.
  • Static checker accepts both independently re-signed official v0.94.1 test copies and rejects altered pages, entitlements, coverage, manifest and payload.
  • Full local rerun after restoring dugite, moving npm cache and using normal umask: 7408 passed / 3 failed / 5 skipped; one additional node-pty collection failure. The three failures are process-cleanup cases; observed leftover test children are PID-1-owned zombies. No unrelated test changes.
  • Docker installer gate blocked by Docker Hub HTTP 403. Native node-pty build blocked by Node header download HTTP 403. System codesign/native Mac execution did not run locally.
  • Real isolated Linux installer transaction: official 0.94.1 → this candidate → rollback passed. Injected staged --version SIGKILL returned 137, retained the old active pointer/binary, cleaned staging and retained both releases.

Mac acceptance: download the matching architecture artifact for this PR head, verify the .sha256 sidecar, unpack into a fresh temporary directory, run codesign --verify --strict --verbose=2 on bin/openalice and run --version. Use the checked-out install script with --archive, --sha256, --install-dir , --no-modify-path and --yes, plus a separate OPENALICE_HOME for startup/PTY checks. Keep the existing installation/home intact. Do not disable Gatekeeper, change TCC permissions, or re-sign the candidate locally.

Merge to dev is authorized after conflict resolution and exact-head checks. No release publication or changes to PR #1672.

Original implementation head: 1759efbc4a43df45fad1d50e2a8377b1c90b9b5b.

Original-head CI evidence (historical):

  • Dev PR Clean Build: passed workflow contracts and complete workspace build.

  • CLI artifact acceptance: All four jobs passed: Linux x64, native macOS ARM64, native macOS Intel x64, and final verification of their preserved archives on Linux.

  • ARM64 Mac artifact: cli-candidate-darwin-arm64-1759efbc4a43df45fad1d50e2a8377b1c90b9b5b, expires October 7. Contains the archive, sidecar and report. Native codesign strict verification, static full coverage, compiled recovery, identity upgrade and dual PTYs passed.

  • ARM64 tar SHA-256: 510792b4f8574ac63769fa9951c4ea51f549a35af3f1a1d385e1fa3660f182b2; contentIdentity a727492be28b21d1.

  • Intel Mac artifact: cli-candidate-darwin-x64-1759efbc4a43df45fad1d50e2a8377b1c90b9b5b, expires October 7. Native strict signature verification, retained runtime flags/entitlements, recovery, identity upgrade and dual PTYs passed.

  • Intel tar SHA-256: 1a92f37065fea9c6774600d2570dad51639e12772099aab5569e7fcd5d276e13; contentIdentity addd346781fb2cfd.

  • Both Mac artifacts passed the final Linux extraction/file/manifest/full code-page signature gate. This is actual native runner evidence, not macOS 27.0.1 user-device acceptance.

  • Windows x64 and ARM64 cross-compilation with Bun 1.4.2 and final archive verification also passed in isolated temporary homes. Native Windows execution was not attempted.

Latest-dev synchronization:

  • Merged dev b61658122c9e25ef7ec0fc2d295c3c18b7ad10ec without rewriting history. The sole conflict was PLANS.md; all current task entries and updated test-plan descriptions are retained.
  • Exact current head: 4b8f25d6b7d96cf9e3cb5f8a5135470f0c5d11f8.
  • Current clean build passed, including the complete required critical-local gate and complete workspace build.
  • Local complete critical-local gate passed with accepted=true receipt bound to this clean head; root and UI typechecks passed. Full hermetic suite rerun completed: 7428 passed, 3 failed, 5 skipped; one additional native node-pty collection failure. The same three cleanup failures occurred before synchronization. Exact surviving test PIDs are PID-1-owned zombies; native node-pty remains unavailable after the blocked Node-header download. No new failure class and no unrelated fixes.
  • Current artifact acceptance: all four jobs passed, including final archive verification on Linux; native Linux x64 and both Mac jobs passed signature/archive negative tests, compiled process recovery, final release build, native strict signature verification, same-version identity upgrade and two independent PTYs.
  • Current ARM64 artifact: archive SHA-256 80aa9cc30961586cff35e56caa11de4299f414a5423c5dfd1dd45982ee7b0787, contentIdentity c1b7923c325e4167.
  • Current Intel artifact: archive SHA-256 095d570816bb4ba9d190cd8cb2e1479df7d114ce59a5778d62b369b61dd4603c, contentIdentity 5e63fd87d4ac7eaf.
  • Artifacts expire October 7; these are CI candidates, not a release. macOS 27.0.1 user-device/TCC acceptance remains separate.

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
openalice-demo Ready Ready Preview Sep 30, 2026 6:43pm UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 4b8f25d6 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants