Skip to content

fix(cli): sign bundled frameworks before signing the Apple app - #5864

Open
LucaCappelletti94 wants to merge 1 commit into
DioxusLabs:mainfrom
LucaCappelletti94:upstream/ios-swift-framework-unsigned
Open

LucaCappelletti94 wants to merge 1 commit into
DioxusLabs:mainfrom
LucaCappelletti94:upstream/ios-swift-framework-unsigned

Conversation

@LucaCappelletti94

Copy link
Copy Markdown

A device build of an app with a #[manganis::ffi] extern "Swift" plugin fails to install with "No code signature found", because codesign_apple signs only the outer .app and leaves DioxusSwiftPlugins.framework unsigned. codesign without --deep does not sign nested code, so after dx build --codesign the framework reports "code object is not signed at all". The simulator skips nested signatures, which is why simulator builds work. Bundled -sys dylibs have the same problem.

With this PR, codesign_apple now signs each framework and dylib in Frameworks with the same identity before the app, as Xcode does. Symlinks are skipped, since dev builds point them at dylibs outside the bundle.

Widget extensions will likely need a follow-up, since each .appex needs its own entitlements and provisioning profile. #5466 contains a similar loop, and whichever lands second drops the duplicate, but that PR seems stuck since April.

@LucaCappelletti94
LucaCappelletti94 marked this pull request as ready for review September 24, 2026 18:38

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant