Hmbown/CodeWhale · critical · Error

The update is not a valid notarized Codewhale release. Your…

Error message

The update is not a valid notarized Codewhale release. Your current app has been kept.

What it means

verifyReleaseBundle enforces Apple's Gatekeeper notarization: codesign -R with the Codewhale team-ID/identifier requirement plus spctl --assess must pass, and spctl must report 'source=Notarized Developer ID'. If either command fails or the source is not notarized, the bundle is rejected as an unofficial release and the existing install is kept untouched.

Solutions

  1. Download updates only from the official Codewhale release channel and retry
  2. Distribute through the official notarization pipeline: archive with team 5RDNSHA5TY, codesign with Developer ID, xcrun notarytool submit, staple the ticket
  3. Check spctl --assess --verbose=2 output to see the reported source and fix the specific gap (missing staple, wrong team)
  4. Confirm network access to Apple's notarization services if assessment fails intermittently

Example fix

// before (locally signed build fails the notarization gate)
code.verifyReleaseBundle(localBuild);
// after
code.spawnSync("xcrun", ["notarytool", "submit", "build.zip", "--keychain-profile", "AC_NOTARY", "--wait"]);
code.spawnSync("xcrun", ["stapler", "staple", "build/Codewhale Computer Use.app"]);
code.verifyReleaseBundle("build/Codewhale Computer Use.app");
Defensive patterns

Strategy: try-catch

Validate before calling

const out = spawnSync("/usr/sbin/spctl", ["--assess", "--type", "execute", "--verbose=2", bundle], { encoding: "utf8" });
if (out.status !== 0 || !/^source=Notarized Developer ID\r?$/m.test(out.stderr)) throw new Error("bundle is not notarized");

Try / catch

try {
  verifyReleaseBundle(bundle);
} catch (e) {
  if (e.message.includes("not a valid notarized")) {
    keepCurrentInstall();
    reportRejectedUpdate(e.message);
  } else throw e;
}

Prevention

When it happens

Trigger: A bundle signed by a different team (not 5RDNSHA5TY), with a different identifier, ad-hoc/self-signed, notarization expired or never stapled, or spctl reporting a source other than 'Notarized Developer ID' (e.g. a local allow-list override).

Common situations: Distributing a locally built or self-signed build; a third-party mirror serving a re-signed app; macOS unable to contact Apple's notarization services (offline) so assessment fails; testing an update produced outside the official release pipeline.

Understand the failure class

Background: "invalid response format", "malformed payload", "missing data field": when an API returns 200 but the response shape is wrong — this error's family across 23 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/5a670c8b52669163. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/plugins/computer-use/app/install-macos.mjs:43

    try { fs.renameSync(next, destination); }
    catch (error) { if (backup) fs.renameSync(backup, destination); throw error; }
    return { backup };
  } finally { fs.rmSync(staging, { recursive: true, force: true }); }
}

export function verifySignature(bundle) {
  const result=spawnSync("codesign",["--verify","--deep","--strict",bundle],{encoding:"utf8"});
  if(result.status!==0) throw new Error(`The app signature did not verify: ${result.stderr?.trim() ?? "codesign unavailable"}`);
}

export function verifyReleaseBundle(bundle) {
  verifySignature(bundle);
  const requirement='=anchor apple generic and identifier "net.codewhale.computer-use" and certificate leaf[subject.OU] = "5RDNSHA5TY"';
  for(const [command,args] of [["/usr/bin/codesign",["--verify","--strict","-R",requirement,bundle]],["/usr/sbin/spctl",["--assess","--type","execute","--verbose=2",bundle]]]) {
    const result=spawnSync(command,args,{encoding:"utf8"});
    // Gatekeeper ships with macOS. Requiring its notarized source also rejects
    // local allow-list overrides; consumer Macs do not need Xcode's stapler.
    if(result.status!==0 || (command.endsWith("/spctl") && !/^source=Notarized Developer ID\r?$/m.test(result.stderr))) throw new Error("The update is not a valid notarized Codewhale release. Your current app has been kept.");
  }
  if(!fs.existsSync(path.join(bundle,"Contents","MacOS","node"))) throw new Error("The release is missing its bundled runtime.");
}

View on GitHub (pinned to 73e0f67d83)