From 4cc98f599493c0f5428cbf06b2498b69b1ccbd7d Mon Sep 17 00:00:00 2001 From: agentHits <140916359+agentHits@users.noreply.github.com> Date: Tue, 22 Sep 2026 10:05:31 -0400 Subject: [PATCH 1/2] fix(desktop): ad-hoc sign bun sidecar on macOS after prepare --- desktop/scripts/prepare-sidecar.ts | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/desktop/scripts/prepare-sidecar.ts b/desktop/scripts/prepare-sidecar.ts index 502127870dc..35a0e0ba5b7 100644 --- a/desktop/scripts/prepare-sidecar.ts +++ b/desktop/scripts/prepare-sidecar.ts @@ -55,5 +55,11 @@ mkdirSync(binaries, { recursive: true }); mkdirSync(resources, { recursive: true }); const destination = join(binaries, `ocx-${triple}${target.startsWith("bun-windows-") ? ".exe" : ""}`); copyFileSync(executable, destination); +if (process.platform === "darwin") { + // Bun linker-signed output is killed by macOS page validation (CODESIGNING + // "Invalid Page"); seal ad-hoc so the bundled sidecar actually launches. + const sign = Bun.spawnSync(["codesign", "-s", "-", "-f", destination], { stdout: "inherit", stderr: "inherit" }); + if (sign.exitCode !== 0) process.exit(sign.exitCode); +} cpSync(join(repoRoot, "gui", "dist"), resources, { recursive: true }); console.log(`Prepared ${destination}`); From ecb51082d905a23e7a5a535d0c5cec7c179507f0 Mon Sep 17 00:00:00 2001 From: agentHits <140916359+agentHits@users.noreply.github.com> Date: Tue, 22 Sep 2026 10:36:18 -0400 Subject: [PATCH 2/2] fix(desktop): gate sidecar signing on darwin target, not just host --- desktop/scripts/prepare-sidecar.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/desktop/scripts/prepare-sidecar.ts b/desktop/scripts/prepare-sidecar.ts index 35a0e0ba5b7..1a91411a6a3 100644 --- a/desktop/scripts/prepare-sidecar.ts +++ b/desktop/scripts/prepare-sidecar.ts @@ -55,7 +55,7 @@ mkdirSync(binaries, { recursive: true }); mkdirSync(resources, { recursive: true }); const destination = join(binaries, `ocx-${triple}${target.startsWith("bun-windows-") ? ".exe" : ""}`); copyFileSync(executable, destination); -if (process.platform === "darwin") { +if (process.platform === "darwin" && target.startsWith("bun-darwin-")) { // Bun linker-signed output is killed by macOS page validation (CODESIGNING // "Invalid Page"); seal ad-hoc so the bundled sidecar actually launches. const sign = Bun.spawnSync(["codesign", "-s", "-", "-f", destination], { stdout: "inherit", stderr: "inherit" });