Skip to content

fix(vm): macOS openshell-driver-vm release artifact missing com.apple.security.hypervisor entitlement #3506

Description

@benoitf

User Story

As a macOS user downloading openshell-driver-vm-aarch64-apple-darwin.tar.gz from a GitHub release,
I want the binary to work without manual codesigning,
so that VM sandbox creation succeeds out of the box regardless of install method.

Problem Statement

The macOS openshell-driver-vm binary in the GitHub release tarball is shipped unsigned — without the com.apple.security.hypervisor entitlement required by Apple's Hypervisor.framework. The entitlement is only applied at Homebrew install time via the formula's post_install hook, not during the CI build that produces the release artifact.

Impact / Why This Matters

When this happens, any non-Homebrew install path (direct tarball download, install.sh pre-release mode, CI environments) gets a binary that fails at runtime when it tries to create a microVM through libkrun.

This results in a confusing runtime crash with no clear indication that codesigning is the issue.

This matters because:

  • The workaround is to manually run codesign --entitlements <plist> --force -s - openshell-driver-vm, which requires knowing about macOS entitlements.
  • If Homebrew's post_install is skipped (--skip-post-install) or fails, the binary is silently broken even for Homebrew users.
  • Codesigning logic (writing a plist, shelling out to /usr/bin/codesign) does not belong in a package manager formula — it should be part of the build pipeline that produces the artifact.

Acceptance Criteria

  • openshell-driver-vm-aarch64-apple-darwin.tar.gz in GitHub releases contains a binary ad-hoc signed with com.apple.security.hypervisor (verifiable via codesign -d --entitlements - openshell-driver-vm)
  • The generated Homebrew formula no longer writes an entitlements plist or calls codesign in post_install
  • install.sh no longer contains patch_homebrew_formula() (dead code once formula codesigning is removed)
  • Existing Homebrew upgrade path works — a redundant post_install codesign from a cached older formula is harmless against a pre-signed binary
  • crates/openshell-driver-vm/entitlements.plist remains the single source of truth for the entitlement

Reproduction Steps

  1. Download openshell-driver-vm-aarch64-apple-darwin.tar.gz from a GitHub release
  2. Extract: tar -xzf openshell-driver-vm-aarch64-apple-darwin.tar.gz
  3. Verify missing signature: codesign -d --entitlements - openshell-driver-vm → shows no entitlements
  4. Attempt to create a VM sandbox — fails because Hypervisor.framework rejects the unsigned caller

Environment

  • OS: macOS (Apple Silicon / aarch64-apple-darwin)
  • Install method: direct GitHub release tarball download (non-Homebrew path)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions