Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
fix(opencode): re-sign darwin binaries ad-hoc after compile
Bun's compile embeds the bundle after the linker has ad-hoc signed the
executable, leaving the signature invalid. macOS 27 enforces code page
validation and SIGKILLs the binary on launch (exit 137), so local builds
(build.ts --single) fail the smoke test and cannot run.

Re-sign darwin outputs with an ad-hoc identity when building on macOS.
Release CI builds on Linux and re-signs with Developer ID in
sign-cli-macos, so published binaries are unaffected.
  • Loading branch information
Ryan Wyler
Ryan Wyler committed Sep 29, 2026
commit 606f338062b8eb0604ff62d76dca3c1faef699e4
6 changes: 6 additions & 0 deletions packages/opencode/script/build.ts
Original file line number Diff line number Diff line change
Expand Up @@ -201,6 +201,12 @@ for (const item of targets) {
},
})

// Embedding the bundle invalidates the linker's ad-hoc signature, and macOS 27+
// SIGKILLs binaries with invalid pages. Re-sign ad-hoc; release CI re-signs with Developer ID.
if (item.os === "darwin" && process.platform === "darwin") {
await $`codesign --force --sign - dist/${name}/bin/opencode`
}

// Smoke test: only run if binary is for current platform
if (item.os === process.platform && item.arch === process.arch && !item.abi) {
const binaryPath = `dist/${name}/bin/opencode`
Expand Down
Loading