Skip to content

fix(cli): sign bundled frameworks before signing the Apple app - #5864

Open
LucaCappelletti94 wants to merge 1 commit into
DioxusLabs:mainfrom
LucaCappelletti94:upstream/ios-swift-framework-unsigned
Open

LucaCappelletti94 wants to merge 1 commit into
DioxusLabs:mainfrom
LucaCappelletti94:upstream/ios-swift-framework-unsigned

Conversation

@LucaCappelletti94

@LucaCappelletti94 LucaCappelletti94 commented Sep 24, 2026 •

Copy link
Copy Markdown

A device build of an app with a #[manganis::ffi] extern "Swift" plugin fails to install with "No code signature found", because codesign_apple signs only the outer .app and leaves DioxusSwiftPlugins.framework unsigned. codesign without --deep does not sign nested code, so after dx build --codesign the framework reports "code object is not signed at all". The simulator skips nested signatures, which is why simulator builds work. Bundled -sys dylibs have the same problem.

With this PR, codesign_apple now signs each framework and dylib in Frameworks with the same identity before the app, as Xcode does. Symlinks are skipped, since dev builds point them at dylibs outside the bundle.

Codesign recursion only reaches nested code that already carries its own valid signature. A framework built fresh in this same build starts unsigned, so there is nothing for the outer signature to recurse onto, it needs its own pass first.

Widget extensions will likely need a follow-up, since each .appex needs its own entitlements and provisioning profile. #5466 contains a similar loop, and whichever lands second drops the duplicate, but that PR seems stuck since April.

Fixes #5889

@LucaCappelletti94

Copy link
Copy Markdown
Author

@nicoburns thanks for running the CI. The Playwright failures seem to be also failing on main, with the wasm-bindgen panic in decode_generic_import and the walrus exceptions proposal not enabled error.

I tested locally your #5843 fix and looks very related to #5834 and #5859. I believe any of them fixes the issue, but I also suspect all of them are in "just need a reviewer" limbo.

I'll check yours out more precisely to see whether I can provide any feedback myself, but of course it won't count as a reviewer. Still, maybe it'll speed things along.

I'll rebase when any of them land.

@LucaCappelletti94
LucaCappelletti94 force-pushed the upstream/ios-swift-framework-unsigned branch from b9ca52d to f90859e Compare October 3, 2026 22:15
@LucaCappelletti94

Copy link
Copy Markdown
Author

@nicoburns I have rebased on main after you merged #5843 so now the CI may tentatively pass.

@LucaCappelletti94

Copy link
Copy Markdown
Author

@nicoburns thanks again for triggering workflow, all looks green so I will be waiting for a review. Talking about reviews, do you need me to take a look at any PRs to take a bit of work out of your plate?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Device install fails with "No code signature found" for a locally-built DioxusSwiftPlugins.framework

1 participant