Skip to content

fix(desktop): keep macOS Local Network access across local rebuilds - #47

Merged
connorch merged 1 commit into
mainfrom
fix/local-macos-signing
Oct 7, 2026
Merged

connorch merged 1 commit into
mainfrom
fix/local-macos-signing

Conversation

@connorch

@connorch connorch commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Local builds of T3 Code lost LAN access after every rebuild: terminals and agents got EHOSTUNREACH for local devices even though System Settings still showed Local Network as allowed. Unsigned builds carried only Electron's linker ad-hoc signature (Identifier=Electron). macOS records the Local Network grant against the code signature, and an ad-hoc signature changes on every build, so each rebuild invalidated the grant. The app also never declared why it needs local network access.

Builds without --signed now sign with a stable keychain identity. The build checks T3CODE_MAC_SIGNING_IDENTITY first, then a Developer ID Application identity, then a self-signed T3 Code Local Signing certificate. electron-builder's deep signing applies it to the app and every helper, so the requirement macOS stores (identifier "com.t3tools.t3code" and certificate leaf = H"...") stays the same across builds. Machines with no identity keep the old ad-hoc build and get a warning that links to the docs. All macOS builds also add NSLocalNetworkUsageDescription to Info.plist, and docs/operations/development.md explains how to create the certificate.

Verified with two consecutive local builds. Both signed as com.t3tools.t3code with a non-adhoc signature and helpers signed the same way; the cdhash changed between builds and the stored requirement didn't, and the second build satisfies the first build's requirement. The missing-identity fallback was also checked. The end-to-end LAN ping after installing two builds still needs a manual check.

Made by Claude Opus 5.5 in Claude Code (via T3 Code).

🤖 Generated with Claude Code

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T01:21:27.217003Z 1bca0c9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M labels Oct 6, 2026
@connorch
connorch merged commit 3bc2c9b into main Oct 7, 2026
8 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant