Apple code signing isn't working when building with nix
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 38/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- macos, rust
- Área
- build-system, desktop, security
Línea de trabajo
Comienza con los comandos de Nix en README y sigue la salida de build a través de signing, fixupPhase y la advertencia de install_name_tool. Confirma qué paso modifica devfiler.app/Contents/MacOS/devfiler después de signing y, a continuación, verifica que una aplicación recompilada se inicia en macOS y ya no informa de una firma de código no válida.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Shortly after devfiler was initially open-sourced, I was able to build and run it locally on an M1 mac using the nix commands in the README.
More recently, I wanted to re-build it to catch up with recent protocol changes in opentelemetry-ebpf-profiler, but I ran into an issue where it won't launch after building. The app icon flashes but the app never opens or displays an error.
If I try to run the executable from a shell instead, it reported:
% ./devfiler.app/Contents/MacOS/devfiler
zsh: killed ./devfiler.app/Contents/MacOS/devfiler
After some troubleshooting, I was able to use the Console app to find a "Crash Report" like the following:
-------------------------------------
Translated Report (Full Report Below)
-------------------------------------
Process: ReportCrash [70198]
Path: /System/Library/CoreServices/ReportCrash
Identifier: ReportCrash
Version: ???
Code Type: ARM-64 (Native)
Parent Process: launchd [1]
User ID: 501
Date/Time: 2025-08-09 11:33:42.8358 -0400
OS Version: macOS 15.6 (24G84)
Report Version: 12
Anonymous UUID: 3B6A222A-F595-8AE9-0C62-BC866F9E1776
Time Awake Since Boot: 2500 seconds
System Integrity Protection: enabled
Crashed Thread: 1
Exception Type: EXC_BAD_ACCESS (SIGKILL (Code Signature Invalid))
Exception Codes: UNKNOWN_0x32 at 0x0000000802400000
Exception Codes: 0x0000000000000032, 0x000000080240000
...
which led me to believe it's probably related to code signing. When building with nix, the end of the output looks like this, which makes me think that at some point in the process, the executable is getting signed, but then modified without being re-signed:
devfiler> Running phase: installPhase
...
devfiler> stripping references done
devfiler> signing files:
devfiler> signing: /nix/store/6n1lapf1yxp0565ip9q9syszwsivvi6h-devfiler-0.14.0/bin/devfiler
devfiler> signing: /nix/store/6n1lapf1yxp0565ip9q9syszwsivvi6h-devfiler-0.14.0/share/icons/hicolor/512x512/apps/devfiler.png
devfiler> signing: /nix/store/6n1lapf1yxp0565ip9q9syszwsivvi6h-devfiler-0.14.0/share/applications/devfiler.desktop
devfiler> signing done
devfiler> Running phase: fixupPhase
...
devfiler> install_name_tool: warning: changes being made to the file will invalidate the code signature in: /nix/store/6n1lapf1yxp0565ip9q9syszwsivvi6h-devfiler-0.14.0/Applications/devfiler.app/Contents/MacOS//devfiler
devfiler-mac-app> adding: devfiler.app/ (stored 0%)
devfiler-mac-app> adding: devfiler.app/Contents/ (stored 0%)
devfiler-mac-app> adding: devfiler.app/Contents/MacOS/ (stored 0%)
devfiler-mac-app> adding: devfiler.app/Contents/MacOS/devfiler (deflated 65%)
devfiler-mac-app> adding: devfiler.app/Contents/MacOS/libc++.1.0.dylib (deflated 70%)
devfiler-mac-app> adding: devfiler.app/Contents/MacOS/libc++abi.1.dylib (deflated 74%)
devfiler-mac-app> adding: devfiler.app/Contents/Resources/ (stored 0%)
devfiler-mac-app> adding: devfiler.app/Contents/Resources/devfiler.icns (deflated 26%)
devfiler-mac-app> adding: devfiler.app/Contents/Info.plist (deflated 57%)
So I think the issue is probably that install_name_tool is modifying the executable after it's signed, but I'm not familiar enough with nix or cargo to figure out what to change to make it re-sign or reorder the steps so that it signs after the modification.
- Lenguaje dominante
- Rust
- Estrellas
- 131
- Forks
- 20
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de elastic/devfiler
-
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
-
bug
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
-
Dependency DashboardAbierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 10/100
Todos los issues de elastic/devfiler
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
mishraprafful/multihull#150 ·
Los mantenedores suelen responder en 1 día
-
`npx --package=vite-plus vp create` fails with exit 127 when npm is the chosen package managerAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
voidzero-dev/vite-plus#2970 ·
Los mantenedores suelen responder en 1 día
-
ai_p2 comp-parquet-reader-v3
Dificultad 2/5 Medio día Aptitud para principiantes 66/100
ClickHouse/ClickHouse#124986 ·
Los mantenedores suelen responder en 1 día
-
bug(ktuner): exporter directories hide daemon processesPosiblemente ocupada @iloveeyjafjalla la tomó hoy. Abiertocomponent:ktuner
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
agentic-os-org/ANOLISA#6905 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
maniator/verticopolis#880 ·
Los mantenedores suelen responder en 1 día