Skip to content

Re-sign compiled macOS binaries so bun compile output launches on macOS 27 - #984

Merged
TheGreatAxios merged 2 commits into
mainfrom
fix/macos-compile-codesign
Sep 13, 2026
Merged

TheGreatAxios merged 2 commits into
mainfrom
fix/macos-compile-codesign

Conversation

@brianjfox

Copy link
Copy Markdown
Collaborator

What

Ad-hoc re-signs binaries produced by bun build --compile on macOS so ./dist/corbits and released darwin builds launch instead of being SIGKILLed.

Why

bun build --compile appends the JS payload to Bun's linker-signed executable without re-signing it (oven-sh/bun#32159). The embedded signature no longer matches the file, and macOS 26+/27 kills the binary at exec with exit 137 and no output. bun run start keeps working because it runs dist/index.js under the Bun runtime and never touches the signature. The release smoke test only treated exit 126/127 as exec failures, so a dead darwin binary would have shipped silently.

Changes

  • package.json: build:bin runs codesign -s - --force ./dist/corbits after compile on Darwin hosts; skipped elsewhere.
  • scripts/release.sh: compile_bin re-signs every bun-darwin-* target after compile and dies if signing fails; warns if codesign is unavailable.
  • scripts/release.sh: smoke_bin treats exit 137 (SIGKILL before any code ran) as a fatal smoke failure.

Verification

  • bun run typecheck, bun run build, and bun run lint pass
  • bun run test not run locally: the suite preload requires ripgrep, which is not installed on this machine, and Bun 1.3.13 also segfaults partway through the run. Relying on CI for the suite; no test touches the changed lines.
  • Fresh bun run build:bin on macOS 27.0 / Bun 1.3.13 produces a binary that passes codesign --verify and prints --help with exit 0 (previously exit 137, no output).
  • compile_bin bun-darwin-arm64 from the release script, run in isolation, produces a valid, launchable binary.

`bun build --compile` appends the JS payload to Bun's linker-signed
executable without re-signing it (oven-sh/bun#32159). The embedded
signature no longer matches the file, and macOS 26+/27 SIGKILLs the
binary at launch with exit 137 and no output, while `bun run start`
keeps working because it never touches the signature.

Ad-hoc re-sign `dist/corbits` in `build:bin` on Darwin hosts, and
re-sign every `bun-darwin-*` target in the release script's
compile_bin so cut releases launch on current macOS.
The release smoke test only treated exit 126 and 127 as exec failures,
so a compiled macOS binary killed by the kernel for an invalid code
signature (exit 137) passed silently and would have shipped dead on
arrival. Treat 137 as a fatal smoke failure.
@TheGreatAxios
TheGreatAxios merged commit edb517f into main Sep 13, 2026
9 checks passed
@TheGreatAxios

Copy link
Copy Markdown
Collaborator

Thanks for the contribution!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants