{"record":{"id":"03ea5d90bb9a79ff","repo":"Hmbown/CodeWhale","slug":"macos-builds-require-codesign-to-package-computer-use","errorCode":null,"errorMessage":"macOS builds require codesign to package Computer Use","messagePattern":"macOS builds require codesign to package Computer Use","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"crates/tui/build.rs","lineNumber":90,"sourceCode":"    let identity = std::env::var(\"CODEWHALE_CU_SIGN_IDENTITY\").unwrap_or_else(|_| \"-\".into());\n    let signed = std::process::Command::new(\"codesign\")\n        .args([\n            \"--force\",\n            if identity == \"-\" {\n                \"--timestamp=none\"\n            } else {\n                \"--timestamp\"\n            },\n            \"--options\",\n            \"runtime\",\n            \"--identifier\",\n            \"net.codewhale.computer-use.helper\",\n            \"--sign\",\n        ])\n        .arg(&identity)\n        .arg(&output)\n        .output()\n        .expect(\"macOS builds require codesign to package Computer Use\");\n    assert!(\n        signed.status.success(),\n        \"Computer Use helper signing failed: {}\",\n        String::from_utf8_lossy(&signed.stderr)\n    );\n}\n","sourceCodeStart":72,"sourceCodeEnd":97,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/build.rs#L72-L97","documentation":"This panic comes from crates/tui/build.rs:90 inside build_computer_use_helper. After compiling the helper, the build script runs `codesign` (ad-hoc or via CODESIGN_IDENTITY) and .expect() panics when the codesign binary cannot be spawned. It guards macOS packaging so a missing signing tool fails loudly instead of producing an unusable helper.","triggerScenarios":"The `codesign` Command::output() call fails to spawn — codesign absent (no Xcode CLT / full Xcode), or the toolchain is stripped from PATH on a macOS build host.","commonSituations":"CI image with clang present but full signing tools removed; building in a Linux-style container cross-compiling for macOS; minimal macOS server images without Xcode; PATH sanitization in build wrappers.","solutions":["Install Xcode Command Line Tools: `xcode-select --install` (codesign ships with them).","Verify with `codesign --version` and `which codesign`.","Ensure PATH includes /usr/bin when invoking cargo (codesign is a system tool).","For custom signing, set the identity env var the build script reads (e.g. CODESIGN_IDENTITY) so release builders supply their certificate.","If cross-building for macOS from another OS, build on a macOS runner instead — codesign only exists on macOS."],"exampleFix":"// before\n.output()\n.expect(\"macOS builds require codesign to package Computer Use\");\n// after\n// ensure available: xcode-select --install && codesign --version\n.output()\n.expect(\"macOS builds require codesign to package Computer Use (run: xcode-select --install)\");","handlingStrategy":"validation","validationCode":"// in build.rs, before invoking codesign\nif !Command::new(\"codesign\").arg(\"--version\").output().map(|o| o.status.success()).unwrap_or(false) {\n    panic!(\"codesign not found; install Xcode Command Line Tools: xcode-select --install\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify `codesign --version` in CI prerequisites alongside clang.","Only build/sign the helper on macOS runners; cross-compile attempts should fail fast with a clear message.","Support an env-var identity (e.g. CODESIGN_IDENTITY) so release builders supply certificates; default to ad-hoc signing (-) in dev builds."],"tags":["build-script","macos","codesign","panic"],"backgroundTag":"command-not-found","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}