Hmbown/CodeWhale · critical · Error
The update is not a valid notarized Codewhale release. Your…
Error message
The update is not a valid notarized Codewhale release. Your current app has been kept.
What it means
verifyReleaseBundle enforces Apple's Gatekeeper notarization: codesign -R with the Codewhale team-ID/identifier requirement plus spctl --assess must pass, and spctl must report 'source=Notarized Developer ID'. If either command fails or the source is not notarized, the bundle is rejected as an unofficial release and the existing install is kept untouched.
Solutions
- Download updates only from the official Codewhale release channel and retry
- Distribute through the official notarization pipeline: archive with team 5RDNSHA5TY, codesign with Developer ID, xcrun notarytool submit, staple the ticket
- Check spctl --assess --verbose=2 output to see the reported source and fix the specific gap (missing staple, wrong team)
- Confirm network access to Apple's notarization services if assessment fails intermittently
Example fix
// before (locally signed build fails the notarization gate)
code.verifyReleaseBundle(localBuild);
// after
code.spawnSync("xcrun", ["notarytool", "submit", "build.zip", "--keychain-profile", "AC_NOTARY", "--wait"]);
code.spawnSync("xcrun", ["stapler", "staple", "build/Codewhale Computer Use.app"]);
code.verifyReleaseBundle("build/Codewhale Computer Use.app"); Defensive patterns
Strategy: try-catch
Validate before calling
const out = spawnSync("/usr/sbin/spctl", ["--assess", "--type", "execute", "--verbose=2", bundle], { encoding: "utf8" });
if (out.status !== 0 || !/^source=Notarized Developer ID\r?$/m.test(out.stderr)) throw new Error("bundle is not notarized"); Try / catch
try {
verifyReleaseBundle(bundle);
} catch (e) {
if (e.message.includes("not a valid notarized")) {
keepCurrentInstall();
reportRejectedUpdate(e.message);
} else throw e;
} Prevention
- Only distribute updates from the official notarized release channel
- Run notarytool submit + stapler staple for every release build
- Pin the team ID (5RDNSHA5TY) requirement in release verification
- Ensure network access to Apple's notarization services when assessing
When it happens
Trigger: A bundle signed by a different team (not 5RDNSHA5TY), with a different identifier, ad-hoc/self-signed, notarization expired or never stapled, or spctl reporting a source other than 'Notarized Developer ID' (e.g. a local allow-list override).
Common situations: Distributing a locally built or self-signed build; a third-party mirror serving a re-signed app; macOS unable to contact Apple's notarization services (offline) so assessment fails; testing an update produced outside the official release pipeline.
Understand the failure class
Background: "invalid response format", "malformed payload", "missing data field": when an API returns 200 but the response shape is wrong — this error's family across 23 libraries.
Related errors
- The app signature did not verify
- agent action=claim widens an enforced write scope, and the…
- allowlisted read-only executable
- append_allow_rules only accepts action = "allow"
- application not found — call list_apps for exact names/pids
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/5a670c8b52669163.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/plugins/computer-use/app/install-macos.mjs:43
try { fs.renameSync(next, destination); }
catch (error) { if (backup) fs.renameSync(backup, destination); throw error; }
return { backup };
} finally { fs.rmSync(staging, { recursive: true, force: true }); }
}
export function verifySignature(bundle) {
const result=spawnSync("codesign",["--verify","--deep","--strict",bundle],{encoding:"utf8"});
if(result.status!==0) throw new Error(`The app signature did not verify: ${result.stderr?.trim() ?? "codesign unavailable"}`);
}
export function verifyReleaseBundle(bundle) {
verifySignature(bundle);
const requirement='=anchor apple generic and identifier "net.codewhale.computer-use" and certificate leaf[subject.OU] = "5RDNSHA5TY"';
for(const [command,args] of [["/usr/bin/codesign",["--verify","--strict","-R",requirement,bundle]],["/usr/sbin/spctl",["--assess","--type","execute","--verbose=2",bundle]]]) {
const result=spawnSync(command,args,{encoding:"utf8"});
// Gatekeeper ships with macOS. Requiring its notarized source also rejects
// local allow-list overrides; consumer Macs do not need Xcode's stapler.
if(result.status!==0 || (command.endsWith("/spctl") && !/^source=Notarized Developer ID\r?$/m.test(result.stderr))) throw new Error("The update is not a valid notarized Codewhale release. Your current app has been kept.");
}
if(!fs.existsSync(path.join(bundle,"Contents","MacOS","node"))) throw new Error("The release is missing its bundled runtime.");
}
View on GitHub (pinned to 73e0f67d83)