Files
elizaos--eliza/packages/app-core/scripts/codesign-mas.mjs
T
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

504 lines
15 KiB
JavaScript
Executable File

#!/usr/bin/env node
/**
* Mac App Store post-package codesign.
*
* Walks a built .app bundle bottom-up, signing every Mach-O binary with the
* narrowest applicable entitlements. Most nested code gets
* mas-child.entitlements (app-sandbox + cs.inherit). The bundled Bun helper,
* which imports Apple's JIT write-protection APIs on macOS, gets
* mas-bun.entitlements (child entitlements + allow-jit). The outer .app gets
* mas.entitlements and does not receive broad code-signing exceptions.
*
* Apple TN2206 mandates inside-out signing: deepest binaries first, then
* frameworks (sealing their resources), then the outer .app. Anything not in
* that order fails `codesign --verify --deep --strict`.
*
* Usage:
* node codesign-mas.mjs --app=path/to/Built.app
* --identity="3rd Party Mac Developer Application: Acme (TEAMID)"
* [--installer-identity="3rd Party Mac Developer Installer: Acme (TEAMID)"]
* [--team-id=TEAMID]
* [--dry-run]
* [--out=path/to/out.pkg]
*
* Env equivalents (CLI args win):
* ELIZA_MAS_SIGNING_IDENTITY
* ELIZA_MAS_INSTALLER_IDENTITY
* ELIZA_APPLE_TEAM_ID
*
* Exits non-zero on any signing or verification failure.
*/
import { spawnSync } from "node:child_process";
import {
closeSync,
existsSync,
openSync,
readdirSync,
readFileSync,
readSync,
statSync,
} from "node:fs";
import path from "node:path";
import { fileURLToPath } from "node:url";
import {
assertMasEntitlementRuntimeEvidence,
assertReviewedEntitlementsFile,
assertReviewedEntitlementsText,
loadEntitlementReviewManifest,
scanAppleAppBundleForNativeRuntimeSignals,
} from "./lib/apple-entitlement-audit.mjs";
const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename);
const ENTITLEMENTS_DIR = path.resolve(
__dirname,
"../platforms/electrobun/entitlements",
);
const PARENT_ENTITLEMENTS = path.join(ENTITLEMENTS_DIR, "mas.entitlements");
const CHILD_ENTITLEMENTS = path.join(
ENTITLEMENTS_DIR,
"mas-child.entitlements",
);
const BUN_ENTITLEMENTS = path.join(ENTITLEMENTS_DIR, "mas-bun.entitlements");
const MACHO_MAGIC = new Set([
0xfeedface,
0xfeedfacf, // 32 / 64-bit
0xcefaedfe,
0xcffaedfe, // byte-swapped
0xcafebabe,
0xbebafeca, // fat
]);
const FORBIDDEN_MAS_CODE_SIGNING_EXCEPTIONS = [
"com.apple.security.cs.allow-unsigned-executable-memory",
"com.apple.security.cs.disable-library-validation",
"com.apple.security.cs.allow-dyld-environment-variables",
];
/**
* Mach-O basenames that get the Bun-specific MAS entitlements
* (`mas-bun.entitlements`: app-sandbox + cs.inherit + allow-jit).
*
* Kept as a Set keyed by basename so the smoke harness and the signer agree
* on which binaries are "the Bun helper". Today there is exactly one entry
* because we ship one Bun runtime; if a fat-bundle ever ships a renamed Bun
* helper, add the basename here.
*/
export const BUN_HELPER_BINARY_NAMES = new Set(["bun"]);
/**
* True when `target` is the Bun runtime helper inside `appPath` — the only
* Mach-O that should receive `mas-bun.entitlements`.
*
* Anchors on the relative location `Contents/MacOS/<basename>` so a stray
* `bun`-named binary buried deeper in the bundle does not silently pick up
* the JIT entitlement.
*/
export function isBunHelperBinary(target, appPath) {
const rel = path.relative(appPath, target).split(path.sep).join("/");
const basename = path.basename(rel);
if (!BUN_HELPER_BINARY_NAMES.has(basename)) return false;
return rel === `Contents/MacOS/${basename}`;
}
function parentAppExecutablePath(appPath) {
const infoPlist = path.join(appPath, "Contents", "Info.plist");
if (!existsSync(infoPlist)) return null;
const content = readFileSync(infoPlist, "utf8");
const match = content.match(
/<key>CFBundleExecutable<\/key>\s*<string>([^<]+)<\/string>/,
);
const executable = match?.[1]?.trim();
return executable
? path.join(appPath, "Contents", "MacOS", executable)
: null;
}
function isParentAppExecutable(target, appPath) {
const executablePath = parentAppExecutablePath(appPath);
return executablePath
? path.resolve(target) === path.resolve(executablePath)
: false;
}
function parseArgs(argv) {
const out = {};
for (const arg of argv.slice(2)) {
if (!arg.startsWith("--")) continue;
const eq = arg.indexOf("=");
if (eq === -1) {
out[arg.slice(2)] = true;
} else {
out[arg.slice(2, eq)] = arg.slice(eq + 1);
}
}
return out;
}
function isMachO(filePath) {
const st = statSync(filePath);
if (!st.isFile() || st.size < 4) return false;
const fd = openSync(filePath, "r");
const buf = Buffer.alloc(4);
readSync(fd, buf, 0, 4, 0);
closeSync(fd);
return MACHO_MAGIC.has(buf.readUInt32BE(0));
}
function walkFiles(root) {
const out = [];
const stack = [root];
while (stack.length) {
const dir = stack.pop();
for (const name of readdirSync(dir)) {
const full = path.join(dir, name);
const st = statSync(full);
if (st.isDirectory()) stack.push(full);
else out.push(full);
}
}
return out;
}
function walkDirs(root) {
const out = [];
const stack = [root];
while (stack.length) {
const dir = stack.pop();
for (const name of readdirSync(dir)) {
const full = path.join(dir, name);
const st = statSync(full);
if (st.isDirectory()) {
out.push(full);
stack.push(full);
}
}
}
return out;
}
/**
* Returns the signing units inside `appPath`, ordered deepest-first.
* A signing unit is either:
* - a Mach-O file (.dylib / .so / .node / executable / no-extension)
* - a *.framework directory (signed as a unit; its inner Mach-Os are signed
* individually too, but Apple wants the framework directory itself signed)
* - a nested .app or .xpc bundle
*/
function findSigningUnits(appPath) {
const machos = [];
for (const filePath of walkFiles(appPath)) {
if (!isMachO(filePath)) continue;
machos.push(filePath);
}
const bundles = walkDirs(appPath).filter(
(dir) =>
dir !== appPath &&
(dir.endsWith(".framework") ||
dir.endsWith(".app") ||
dir.endsWith(".xpc") ||
dir.endsWith(".bundle")),
);
const byDepth = (a, b) => b.split(path.sep).length - a.split(path.sep).length;
return {
machos: machos.sort(byDepth),
bundles: bundles.sort(byDepth),
};
}
function runOrPrint(cmd, args, dryRun) {
const display = `${cmd} ${args.map((a) => (a.includes(" ") ? `"${a}"` : a)).join(" ")}`;
if (dryRun) {
console.log(`[dry-run] ${display}`);
return { status: 0 };
}
console.log(`+ ${display}`);
const result = spawnSync(cmd, args, { stdio: "inherit" });
if (result.status !== 0) {
process.exitCode = result.status ?? 1;
throw new Error(`Command failed (${result.status}): ${display}`);
}
return result;
}
function runCapture(cmd, args) {
const display = `${cmd} ${args.map((a) => (a.includes(" ") ? `"${a}"` : a)).join(" ")}`;
const result = spawnSync(cmd, args, {
encoding: "utf8",
stdio: ["ignore", "pipe", "pipe"],
});
if (result.status !== 0) {
process.stderr.write(result.stderr ?? "");
process.stdout.write(result.stdout ?? "");
process.exitCode = result.status ?? 1;
throw new Error(`Command failed (${result.status}): ${display}`);
}
return result.stdout;
}
function plistLint(filePath) {
if (!existsSync(filePath)) {
throw new Error(`Entitlements file missing: ${filePath}`);
}
// Quick sanity — full lint requires `plutil`, which only exists on macOS.
// Validate XML well-formedness with a minimal regex check; macOS will
// re-validate during `codesign`.
const content = readFileSync(filePath, "utf8");
if (!/<plist\b[^>]*>[\s\S]*<\/plist>/i.test(content)) {
throw new Error(`Entitlements not a well-formed plist: ${filePath}`);
}
}
function assertSourceEntitlementsReviewed(manifest) {
assertReviewedEntitlementsFile({
filePath: PARENT_ENTITLEMENTS,
targetId: "macos-mas-app",
manifest,
label: "macOS MAS parent entitlements",
});
assertReviewedEntitlementsFile({
filePath: CHILD_ENTITLEMENTS,
targetId: "macos-mas-child",
manifest,
label: "macOS MAS child entitlements",
});
assertReviewedEntitlementsFile({
filePath: BUN_ENTITLEMENTS,
targetId: "macos-mas-bun",
manifest,
label: "macOS MAS Bun helper entitlements",
});
}
function assertNoForbiddenMasExceptions(filePath) {
const content = readFileSync(filePath, "utf8");
const forbidden = FORBIDDEN_MAS_CODE_SIGNING_EXCEPTIONS.filter((key) =>
content.includes(key),
);
if (forbidden.length === 0) return;
throw new Error(
`MAS entitlements file contains forbidden code-signing exception(s): ${filePath}\n` +
forbidden.map((key) => ` - ${key}`).join("\n"),
);
}
function assertSignedEntitlements(
target,
targetId,
label,
manifest,
{ allowAbsent = false } = {},
) {
const entitlementsXml = runCapture("codesign", [
"-d",
"--entitlements",
":-",
target,
]);
if (!/<dict\b/i.test(entitlementsXml)) {
if (allowAbsent) {
return null;
}
throw new Error(`${label}: signed code has no readable entitlements`);
}
return assertReviewedEntitlementsText({
plistXml: entitlementsXml,
targetId,
manifest,
label,
});
}
function sign(target, entitlements, identity, dryRun) {
runOrPrint(
"codesign",
[
"--force",
"--timestamp",
"--options",
"runtime",
"--entitlements",
entitlements,
"--sign",
identity,
target,
],
dryRun,
);
}
function entitlementsForMacho(target, appPath) {
return isBunHelperBinary(target, appPath)
? BUN_ENTITLEMENTS
: CHILD_ENTITLEMENTS;
}
function entitlementTargetIdForMacho(target, appPath) {
if (isParentAppExecutable(target, appPath)) {
return "macos-mas-app";
}
return isBunHelperBinary(target, appPath)
? "macos-mas-bun"
: "macos-mas-child";
}
function main() {
const args = parseArgs(process.argv);
if (args.help) {
console.log(
readFileSync(__filename, "utf8").split("\n").slice(2, 32).join("\n"),
);
return;
}
const appPath = args.app;
if (!appPath) {
console.error("error: --app=<path/to/Built.app> is required");
process.exit(2);
}
if (!existsSync(appPath) || !appPath.endsWith(".app")) {
console.error(`error: ${appPath} is not a .app bundle`);
process.exit(2);
}
const dryRun = Boolean(args["dry-run"]);
const identity =
args.identity ?? process.env.ELIZA_MAS_SIGNING_IDENTITY ?? null;
if (!identity) {
console.error(
"error: --identity or ELIZA_MAS_SIGNING_IDENTITY required " +
'(e.g. "3rd Party Mac Developer Application: Acme (TEAMID)")',
);
process.exit(2);
}
const installerIdentity =
args["installer-identity"] ??
process.env.ELIZA_MAS_INSTALLER_IDENTITY ??
null;
plistLint(PARENT_ENTITLEMENTS);
plistLint(CHILD_ENTITLEMENTS);
plistLint(BUN_ENTITLEMENTS);
assertNoForbiddenMasExceptions(PARENT_ENTITLEMENTS);
assertNoForbiddenMasExceptions(CHILD_ENTITLEMENTS);
assertNoForbiddenMasExceptions(BUN_ENTITLEMENTS);
const entitlementManifest = loadEntitlementReviewManifest();
assertSourceEntitlementsReviewed(entitlementManifest);
console.log(`MAS codesign for ${appPath}`);
console.log(` identity: ${identity}`);
if (installerIdentity) {
console.log(` installer-identity: ${installerIdentity}`);
}
console.log(` parent entitlements: ${PARENT_ENTITLEMENTS}`);
console.log(` child entitlements: ${CHILD_ENTITLEMENTS}`);
console.log(` bun entitlements: ${BUN_ENTITLEMENTS}`);
if (dryRun) console.log(" mode: DRY RUN — no commands will execute");
const { machos, bundles } = findSigningUnits(appPath);
// 1. Sign all loose Mach-O binaries with the narrowest matching
// entitlements (deepest first).
console.log(`\nSigning ${machos.length} Mach-O binaries:`);
for (const target of machos) {
sign(target, entitlementsForMacho(target, appPath), identity, dryRun);
}
// 2. Sign nested bundles (frameworks, helper apps, xpc, .bundle) deepest-first.
console.log(
`\nSigning ${bundles.length} nested bundles (child entitlements):`,
);
for (const target of bundles) {
sign(target, CHILD_ENTITLEMENTS, identity, dryRun);
}
// 3. Sign the parent .app with parent entitlements.
console.log(`\nSigning parent app with MAS entitlements:`);
sign(appPath, PARENT_ENTITLEMENTS, identity, dryRun);
// 4. Verify.
console.log(`\nVerifying signature:`);
runOrPrint(
"codesign",
["--verify", "--deep", "--strict", "--verbose=2", appPath],
dryRun,
);
if (!dryRun) {
console.log(`\nAuditing signed entitlements:`);
const nativeScan = scanAppleAppBundleForNativeRuntimeSignals(appPath);
for (const target of machos) {
const targetId = entitlementTargetIdForMacho(target, appPath);
const entitlements = assertSignedEntitlements(
target,
targetId,
`signed Mach-O ${path.relative(appPath, target)}`,
entitlementManifest,
{ allowAbsent: /\.(dylib|so|node)$/i.test(target) },
);
if (!entitlements) continue;
assertMasEntitlementRuntimeEvidence({
entitlements,
scan: nativeScan,
label: `signed Mach-O ${path.relative(appPath, target)}`,
});
}
for (const target of bundles) {
assertSignedEntitlements(
target,
"macos-mas-child",
`signed nested bundle ${path.relative(appPath, target)}`,
entitlementManifest,
);
}
assertSignedEntitlements(
appPath,
"macos-mas-app",
`signed parent app ${path.basename(appPath)}`,
entitlementManifest,
);
console.log(`\nNative runtime evidence scan:`);
console.log(` Mach-O files: ${nativeScan.machOCount}`);
console.log(
` JIT/executable-memory findings: ${nativeScan.jitExecutableMemory.length}`,
);
console.log(
` native library findings: ${nativeScan.dynamicLibraryLoading.length}`,
);
}
// 5. Optional productbuild for MAS submission.
if (installerIdentity) {
const pkgOut =
args.out ??
path.join(path.dirname(appPath), `${path.basename(appPath, ".app")}.pkg`);
console.log(`\nProductbuilding MAS .pkg → ${pkgOut}`);
runOrPrint(
"productbuild",
[
"--component",
appPath,
"/Applications",
"--sign",
installerIdentity,
pkgOut,
],
dryRun,
);
}
console.log(`\n${dryRun ? "[dry-run] " : ""}Done.`);
}
// Run only when invoked as a script; the smoke harness imports
// `BUN_HELPER_BINARY_NAMES` / `isBunHelperBinary` from this module.
if (process.argv[1] && path.resolve(process.argv[1]) === __filename) {
main();
}