fix(vm): macOS openshell-driver-vm release artifact missing com.apple.security.hypervisor entitlement
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- macos, rust
- Lĩnh vực
- build-system, release
Hướng nghiên cứu
Start by tracing the release build that packages openshell-driver-vm-aarch64-apple-darwin.tar.gz, then read crates/openshell-driver-vm/entitlements.plist, the generated Homebrew formula, and install.sh. Verify the artifact with codesign, remove formula post_install signing and install.sh patch_homebrew_formula(), and confirm the release binary carries the hypervisor entitlement.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
User Story
As a macOS user downloading openshell-driver-vm-aarch64-apple-darwin.tar.gz from a GitHub release,
I want the binary to work without manual codesigning,
so that VM sandbox creation succeeds out of the box regardless of install method.
Problem Statement
The macOS openshell-driver-vm binary in the GitHub release tarball is shipped unsigned — without the com.apple.security.hypervisor entitlement required by Apple's Hypervisor.framework. The entitlement is only applied at Homebrew install time via the formula's post_install hook, not during the CI build that produces the release artifact.
Impact / Why This Matters
When this happens, any non-Homebrew install path (direct tarball download, install.sh pre-release mode, CI environments) gets a binary that fails at runtime when it tries to create a microVM through libkrun.
This results in a confusing runtime crash with no clear indication that codesigning is the issue.
This matters because:
- The workaround is to manually run
codesign --entitlements <plist> --force -s - openshell-driver-vm, which requires knowing about macOS entitlements. - If Homebrew's
post_installis skipped (--skip-post-install) or fails, the binary is silently broken even for Homebrew users. - Codesigning logic (writing a plist, shelling out to
/usr/bin/codesign) does not belong in a package manager formula — it should be part of the build pipeline that produces the artifact.
Acceptance Criteria
-
openshell-driver-vm-aarch64-apple-darwin.tar.gzin GitHub releases contains a binary ad-hoc signed withcom.apple.security.hypervisor(verifiable viacodesign -d --entitlements - openshell-driver-vm) - The generated Homebrew formula no longer writes an entitlements plist or calls
codesigninpost_install -
install.shno longer containspatch_homebrew_formula()(dead code once formula codesigning is removed) - Existing Homebrew upgrade path works — a redundant
post_installcodesign from a cached older formula is harmless against a pre-signed binary -
crates/openshell-driver-vm/entitlements.plistremains the single source of truth for the entitlement
Reproduction Steps
- Download
openshell-driver-vm-aarch64-apple-darwin.tar.gzfrom a GitHub release - Extract:
tar -xzf openshell-driver-vm-aarch64-apple-darwin.tar.gz - Verify missing signature:
codesign -d --entitlements - openshell-driver-vm→ shows no entitlements - Attempt to create a VM sandbox — fails because Hypervisor.framework rejects the unsigned caller
Environment
- OS: macOS (Apple Silicon / aarch64-apple-darwin)
- Install method: direct GitHub release tarball download (non-Homebrew path)
- Ngôn ngữ chính
- Rust
- Star
- 13.2k
- Fork
- 1.6k
- Merge trung bình
- 1 ngày 20 giờ
- Pull request đã merge (30 ngày)
- 333
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của NVIDIA/OpenShell
-
area:cli os:linux os:macos state:validated
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
NVIDIA/OpenShell#4042 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
state:triage-needed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
NVIDIA/OpenShell#3995 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
state:triage-needed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
state:triage-needed
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area:docs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của NVIDIA/OpenShell
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Outdated docs on front pageĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
rust-windowing/winit#4731 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area:cli bug priority:high
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
rtk-ai/rtk#4439 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
component:sight
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
agentic-os-org/ANOLISA#4622 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày