0.18.3: the macOS binary runs under the hardened runtime - #82
Merged
Merged
Conversation
0.18.2's liminate-macos-arm64 can't start. It is signed with our Developer ID and the hardened runtime, but the Python.framework it unpacks at launch kept its original team's signature, and library validation refuses it: "mapping process and mapped file (non-platform) have different Team IDs". codesign --verify passed, so nothing caught it. PyInstaller now signs everything it collects (--codesign-identity), which means the certificate is imported before the build instead of after. build/build_macos_release.sh holds the build, sign and a run of the built binary; the workflow calls it, and so can a local release. A binary built this way runs with library validation on, including after an app bundler re-signs it with the app's own entitlements (checked in a signed CueCue bundle). Actions can't run right now, so the macOS asset for this tag is released by hand with that script (RELEASING.md, "When Actions can't run"). The release job no longer replaces an asset that is already there, so re-running the workflow later adds Linux, Windows and PyPI without changing the macOS binary CueCue pins. No language change. The fixture is renamed for the version, as before. 1753 passed, 2 skipped on Python 3.12; grammar projections up to date. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PqrbVBAmoTQETg9Yc6aXzz
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
0.18.2's
liminate-macos-arm64exits before running anything on current macOS:The binary is signed with our Developer ID and the hardened runtime, but the Python.framework inside the one-file archive kept its original team's signature, so library validation refuses to load it.
codesign --verifypasses, which is why the release looked fine.Fix
build/build_macos_release.sh: PyInstaller with--codesign-identity, which signs every collected binary with our identity. It then signs the outer binary and runs the built binary (--versionandexamples/program1_basics.limn).release.yml: import the certificate before the build, then call the script. The release job setsoverwrite_files: false.RELEASING.md: why the recipe signs collected binaries, and a "When Actions can't run" path.Evidence
externalBin).grammar_gen.py --checkis clean.Why now: CueCue's floor (the pre-publish check) runs Liminate as a bundled sidecar, and needs a macOS binary that starts under the hardened runtime without switching library validation off.
Release plan (Actions is billing-blocked): merge, tag
v0.18.3, and attach the macOS binary built by this script, notarized by hand. When Actions is back, re-run the tag's Release workflow. It adds Linux, Windows and PyPI and leaves the macOS asset alone, so CueCue's SHA-256 pin stays valid.🤖 Generated with Claude Code
https://claude.ai/code/session_01PqrbVBAmoTQETg9Yc6aXzz