From 66683c3be602be2ac6691c102c5cd6835a613796 Mon Sep 17 00:00:00 2001 From: "Brian J. Fox" Date: Sun, 13 Sep 2026 15:03:20 +0100 Subject: [PATCH 1/2] fix(build): re-sign compiled macOS binary after bun compile `bun build --compile` appends the JS payload to Bun's linker-signed executable without re-signing it (oven-sh/bun#32159). The embedded signature no longer matches the file, and macOS 26+/27 SIGKILLs the binary at launch with exit 137 and no output, while `bun run start` keeps working because it never touches the signature. Ad-hoc re-sign `dist/corbits` in `build:bin` on Darwin hosts, and re-sign every `bun-darwin-*` target in the release script's compile_bin so cut releases launch on current macOS. --- package.json | 2 +- scripts/release.sh | 15 +++++++++++++++ 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index b128f8707..7cf77934d 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,7 @@ }, "scripts": { "build": "bun build ./src/index.ts --outdir ./dist --target bun --external '@opentui/core-*' && bun scripts/copy-repo-plugins.ts", - "build:bin": "bun build ./src/index.ts --compile --minify --define process.env.NODE_ENV='\"production\"' --outfile ./dist/corbits && bun scripts/copy-repo-plugins.ts", + "build:bin": "bun build ./src/index.ts --compile --minify --define process.env.NODE_ENV='\"production\"' --outfile ./dist/corbits && ([ \"$(uname -s)\" != Darwin ] || codesign -s - --force ./dist/corbits) && bun scripts/copy-repo-plugins.ts", "typecheck": "tsc --noEmit", "test": "bun test ./src ./tests ./evals ./scripts --randomize --seed 424242", "test:paths": "bun scripts/test-paths.ts", diff --git a/scripts/release.sh b/scripts/release.sh index 5a5a8e4a4..1b1718432 100755 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -137,12 +137,27 @@ host_label() { # node_modules; leaving it external makes first TUI load fail with # "Cannot find package 'react-devtools-core'". # Keep this block in sync with package.json "build:bin" when those flags change. +# +# macOS targets are ad-hoc re-signed after compile. `bun build --compile` +# appends the JS payload to Bun's linker-signed executable without re-signing +# it (oven-sh/bun#32159), so the embedded signature no longer matches the file +# and macOS 26+/27 SIGKILLs the binary at launch (exit 137, no output). +# `codesign` only exists on macOS hosts, which is where darwin releases are cut. compile_bin() { # compile_bin BUN_TARGET OUTFILE local target=$1 out=$2 bun build ./src/index.ts --compile --target="$target" --minify \ --define process.env.NODE_ENV='"production"' \ --define process.env.DEV='"false"' \ --outfile "$out" >/dev/null + case "$target" in + bun-darwin-*) + if command -v codesign >/dev/null 2>&1; then + codesign -s - --force "$out" >/dev/null 2>&1 \ + || die "codesign failed for $target ($out)" + else + info "warning: codesign not available; $target binary is not re-signed and will not launch on macOS 26+" + fi ;; + esac } # Smoke-test a freshly compiled native binary before packaging. Cross-compiled From 38cf3d4f1271667fe84226f6ff00d4b3dd2b120f Mon Sep 17 00:00:00 2001 From: "Brian J. Fox" Date: Sun, 13 Sep 2026 15:03:20 +0100 Subject: [PATCH 2/2] fix(release): fail smoke test on SIGKILLed binary The release smoke test only treated exit 126 and 127 as exec failures, so a compiled macOS binary killed by the kernel for an invalid code signature (exit 137) passed silently and would have shipped dead on arrival. Treat 137 as a fatal smoke failure. --- scripts/release.sh | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/scripts/release.sh b/scripts/release.sh index 1b1718432..858e77a29 100755 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -176,7 +176,9 @@ smoke_bin() { # smoke_bin LABEL BINARY local rc=0 "$bin" --__release_smoke__ >/dev/null 2>&1 || rc=$? # 126 = cannot execute, 127 = not found — real link/exec failures. - if [ "$rc" -eq 126 ] || [ "$rc" -eq 127 ]; then + # 137 = SIGKILL before any code ran: on macOS that is the kernel rejecting an + # invalid code signature (see compile_bin), so the binary is dead on arrival. + if [ "$rc" -eq 126 ] || [ "$rc" -eq 127 ] || [ "$rc" -eq 137 ]; then die "smoke: cannot execute $label binary (rc=$rc)" fi # Non-zero from "unrecognized flag" (or similar) still proves the binary ran.