Hmbown/CodeWhale · critical

macOS builds require codesign to package Computer Use

Error message

macOS builds require codesign to package Computer Use

What it means

This panic comes from crates/tui/build.rs:90 inside build_computer_use_helper. After compiling the helper, the build script runs `codesign` (ad-hoc or via CODESIGN_IDENTITY) and .expect() panics when the codesign binary cannot be spawned. It guards macOS packaging so a missing signing tool fails loudly instead of producing an unusable helper.

Solutions

  1. Install Xcode Command Line Tools: `xcode-select --install` (codesign ships with them).
  2. Verify with `codesign --version` and `which codesign`.
  3. Ensure PATH includes /usr/bin when invoking cargo (codesign is a system tool).
  4. For custom signing, set the identity env var the build script reads (e.g. CODESIGN_IDENTITY) so release builders supply their certificate.
  5. If cross-building for macOS from another OS, build on a macOS runner instead — codesign only exists on macOS.

Example fix

// before
.output()
.expect("macOS builds require codesign to package Computer Use");
// after
// ensure available: xcode-select --install && codesign --version
.output()
.expect("macOS builds require codesign to package Computer Use (run: xcode-select --install)");
Defensive patterns

Strategy: validation

Validate before calling

// in build.rs, before invoking codesign
if !Command::new("codesign").arg("--version").output().map(|o| o.status.success()).unwrap_or(false) {
    panic!("codesign not found; install Xcode Command Line Tools: xcode-select --install");
}

Prevention

When it happens

Trigger: The `codesign` Command::output() call fails to spawn — codesign absent (no Xcode CLT / full Xcode), or the toolchain is stripped from PATH on a macOS build host.

Common situations: CI image with clang present but full signing tools removed; building in a Linux-style container cross-compiling for macOS; minimal macOS server images without Xcode; PATH sanitization in build wrappers.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/03ea5d90bb9a79ff. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/build.rs:90

    let identity = std::env::var("CODEWHALE_CU_SIGN_IDENTITY").unwrap_or_else(|_| "-".into());
    let signed = std::process::Command::new("codesign")
        .args([
            "--force",
            if identity == "-" {
                "--timestamp=none"
            } else {
                "--timestamp"
            },
            "--options",
            "runtime",
            "--identifier",
            "net.codewhale.computer-use.helper",
            "--sign",
        ])
        .arg(&identity)
        .arg(&output)
        .output()
        .expect("macOS builds require codesign to package Computer Use");
    assert!(
        signed.status.success(),
        "Computer Use helper signing failed: {}",
        String::from_utf8_lossy(&signed.stderr)
    );
}

View on GitHub (pinned to 73e0f67d83)