Hmbown/CodeWhale · critical
macOS builds require codesign to package Computer Use
Error message
macOS builds require codesign to package Computer Use
What it means
This panic comes from crates/tui/build.rs:90 inside build_computer_use_helper. After compiling the helper, the build script runs `codesign` (ad-hoc or via CODESIGN_IDENTITY) and .expect() panics when the codesign binary cannot be spawned. It guards macOS packaging so a missing signing tool fails loudly instead of producing an unusable helper.
Solutions
- Install Xcode Command Line Tools: `xcode-select --install` (codesign ships with them).
- Verify with `codesign --version` and `which codesign`.
- Ensure PATH includes /usr/bin when invoking cargo (codesign is a system tool).
- For custom signing, set the identity env var the build script reads (e.g. CODESIGN_IDENTITY) so release builders supply their certificate.
- If cross-building for macOS from another OS, build on a macOS runner instead — codesign only exists on macOS.
Example fix
// before
.output()
.expect("macOS builds require codesign to package Computer Use");
// after
// ensure available: xcode-select --install && codesign --version
.output()
.expect("macOS builds require codesign to package Computer Use (run: xcode-select --install)"); Defensive patterns
Strategy: validation
Validate before calling
// in build.rs, before invoking codesign
if !Command::new("codesign").arg("--version").output().map(|o| o.status.success()).unwrap_or(false) {
panic!("codesign not found; install Xcode Command Line Tools: xcode-select --install");
} Prevention
- Verify `codesign --version` in CI prerequisites alongside clang.
- Only build/sign the helper on macOS runners; cross-compile attempts should fail fast with a clear message.
- Support an env-var identity (e.g. CODESIGN_IDENTITY) so release builders supply certificates; default to ad-hoc signing (-) in dev builds.
When it happens
Trigger: The `codesign` Command::output() call fails to spawn — codesign absent (no Xcode CLT / full Xcode), or the toolchain is stripped from PATH on a macOS build host.
Common situations: CI image with clang present but full signing tools removed; building in a Linux-style container cross-compiling for macOS; minimal macOS server images without Xcode; PATH sanitization in build wrappers.
Related errors
- macOS builds require Xcode Command Line Tools to package…
- The app signature did not verify
- app-icon blob has unexpected height
- app-icon blob not found in the founder sheet
- application not found — call list_apps for exact names/pids
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/03ea5d90bb9a79ff.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/build.rs:90
let identity = std::env::var("CODEWHALE_CU_SIGN_IDENTITY").unwrap_or_else(|_| "-".into());
let signed = std::process::Command::new("codesign")
.args([
"--force",
if identity == "-" {
"--timestamp=none"
} else {
"--timestamp"
},
"--options",
"runtime",
"--identifier",
"net.codewhale.computer-use.helper",
"--sign",
])
.arg(&identity)
.arg(&output)
.output()
.expect("macOS builds require codesign to package Computer Use");
assert!(
signed.status.success(),
"Computer Use helper signing failed: {}",
String::from_utf8_lossy(&signed.stderr)
);
}
View on GitHub (pinned to 73e0f67d83)