From 9d7c10b6ab80c2e2520781c9227abb3f4e8152b9 Mon Sep 17 00:00:00 2001 From: Obed0101 Date: Wed, 23 Sep 2026 20:38:47 -0500 Subject: [PATCH] fix: sign and verify Darwin binaries before beta18 packaging --- CHANGELOG.md | 6 ++++++ src/mendcode/packages/opencode/script/build.ts | 8 ++++++++ 2 files changed, 14 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 900cd6a2..354a302c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## 0.1.44-beta.18 - 2026-09-23 + +### Fixed + +- Re-sign compiled macOS executables and verify their code signatures before smoke testing and packaging release archives, preventing `Killed: 9` on launch. + ## 0.1.44-beta.17 - 2026-09-23 ### Fixed diff --git a/src/mendcode/packages/opencode/script/build.ts b/src/mendcode/packages/opencode/script/build.ts index 9a9e3d33..addcef89 100755 --- a/src/mendcode/packages/opencode/script/build.ts +++ b/src/mendcode/packages/opencode/script/build.ts @@ -251,6 +251,14 @@ for (const item of targets) { }, }) + // Bun's compiled Mach-O can have an invalid embedded signature even when the + // build succeeds. Sign the final binary before smoke testing or archiving it. + if (item.os === "darwin" && process.platform === "darwin") { + const binaryPath = `dist/${name}/bin/${binaryName}` + await $`codesign --force --sign - ${binaryPath}` + await $`codesign --verify --strict --verbose=2 ${binaryPath}` + } + // Smoke test: only run if binary is for current platform if (item.os === process.platform && item.arch === process.arch && !item.abi) { const binaryPath = `dist/${name}/bin/${binaryName}`