Re-sign compiled macOS binaries so bun compile output launches on macOS 27 - #984
Merged
Merged
Conversation
`bun build --compile` appends the JS payload to Bun's linker-signed executable without re-signing it (oven-sh/bun#32159). The embedded signature no longer matches the file, and macOS 26+/27 SIGKILLs the binary at launch with exit 137 and no output, while `bun run start` keeps working because it never touches the signature. Ad-hoc re-sign `dist/corbits` in `build:bin` on Darwin hosts, and re-sign every `bun-darwin-*` target in the release script's compile_bin so cut releases launch on current macOS.
The release smoke test only treated exit 126 and 127 as exec failures, so a compiled macOS binary killed by the kernel for an invalid code signature (exit 137) passed silently and would have shipped dead on arrival. Treat 137 as a fatal smoke failure.
Collaborator
|
Thanks for the contribution! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Ad-hoc re-signs binaries produced by
bun build --compileon macOS so./dist/corbitsand released darwin builds launch instead of being SIGKILLed.Why
bun build --compileappends the JS payload to Bun's linker-signed executable without re-signing it (oven-sh/bun#32159). The embedded signature no longer matches the file, and macOS 26+/27 kills the binary at exec with exit 137 and no output.bun run startkeeps working because it runsdist/index.jsunder the Bun runtime and never touches the signature. The release smoke test only treated exit 126/127 as exec failures, so a dead darwin binary would have shipped silently.Changes
package.json:build:binrunscodesign -s - --force ./dist/corbitsafter compile on Darwin hosts; skipped elsewhere.scripts/release.sh:compile_binre-signs everybun-darwin-*target after compile and dies if signing fails; warns ifcodesignis unavailable.scripts/release.sh:smoke_bintreats exit 137 (SIGKILL before any code ran) as a fatal smoke failure.Verification
bun run typecheck,bun run build, andbun run lintpassbun run testnot run locally: the suite preload requires ripgrep, which is not installed on this machine, and Bun 1.3.13 also segfaults partway through the run. Relying on CI for the suite; no test touches the changed lines.bun run build:binon macOS 27.0 / Bun 1.3.13 produces a binary that passescodesign --verifyand prints--helpwith exit 0 (previously exit 137, no output).compile_bin bun-darwin-arm64from the release script, run in isolation, produces a valid, launchable binary.