Repository navigation
fix(desktop): keep macOS Local Network access across local rebuilds - #47
Merged
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Local builds of T3 Code lost LAN access after every rebuild: terminals and agents got
EHOSTUNREACHfor local devices even though System Settings still showed Local Network as allowed. Unsigned builds carried only Electron's linker ad-hoc signature (Identifier=Electron). macOS records the Local Network grant against the code signature, and an ad-hoc signature changes on every build, so each rebuild invalidated the grant. The app also never declared why it needs local network access.Builds without
--signednow sign with a stable keychain identity. The build checksT3CODE_MAC_SIGNING_IDENTITYfirst, then a Developer ID Application identity, then a self-signedT3 Code Local Signingcertificate. electron-builder's deep signing applies it to the app and every helper, so the requirement macOS stores (identifier "com.t3tools.t3code" and certificate leaf = H"...") stays the same across builds. Machines with no identity keep the old ad-hoc build and get a warning that links to the docs. All macOS builds also addNSLocalNetworkUsageDescriptionto Info.plist, anddocs/operations/development.mdexplains how to create the certificate.Verified with two consecutive local builds. Both signed as
com.t3tools.t3codewith a non-adhoc signature and helpers signed the same way; the cdhash changed between builds and the stored requirement didn't, and the second build satisfies the first build's requirement. The missing-identity fallback was also checked. The end-to-end LANpingafter installing two builds still needs a manual check.Made by Claude Opus 5.5 in Claude Code (via T3 Code).
🤖 Generated with Claude Code