diff --git a/CHANGELOG.md b/CHANGELOG.md index 53e746a..e95a28e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -37,6 +37,11 @@ Anything that changes what the dashboard, the admin or a widget can do gets a li sessions after 30 minutes (on by default), and group the board by application. ### Fixed +- The helper keeps its Input Monitoring and Accessibility grants across rebuilds again, on Macs + where `scripts/create-signing-identity.sh` failed at the import step ("MAC verification failed"). + The identity was never created, so every build stayed ad-hoc signed and lost the permissions + granted to the one before, which shows up as the touch panel clicking on another display + (@mcouzinet, #8). - Spotify's progress bar moves: on a Mac whose number format uses a decimal comma the position read as nothing, and the bar sat at zero. It now glides across each second instead of stepping, lands at once on a seek, a new track or a pause, and empties when Spotify closes (@mcouzinet, #4). diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index bd81897..6088f4c 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -15,6 +15,7 @@ and "Notifications: active" above the toggles, and *Log…* opens the supervised | "Touch: taken by another driver" | Touchscreen Gestures, another driver or a `--probe` run holds the panel | Quit it, and unload its launchd agent so it does not come back | | "Fence: permission missing" | Accessibility not granted | Add "Fremkit Helper" under Privacy & Security → Accessibility, then relaunch it | | Permissions reset after every rebuild | Ad-hoc signature: a new code identity each build | Run `scripts/create-signing-identity.sh`, rebuild, grant once more | +| The helper is ticked in Privacy & Security and still has no permission | One stale grant per past ad-hoc identity, which macOS keeps in its cache and matches before the new one | `tccutil reset ListenEvent dev.fremkit.helper && tccutil reset Accessibility dev.fremkit.helper`, relaunch the helper, and accept the two prompts. Removing and re-adding the app in the list does not clear those entries | | Printer unreachable (`EHOSTUNREACH`) while `ping` and `curl` work | Local Network not granted to the app that runs the server | Allow it under Privacy & Security → Local Network | | "Server: external" | Something already answers port 4242, so the helper steps aside | Expected under `pnpm dev`; otherwise stop the stray server, or turn *Manage the server* off | diff --git a/scripts/create-signing-identity.sh b/scripts/create-signing-identity.sh index 9c8f2f5..977ea93 100755 --- a/scripts/create-signing-identity.sh +++ b/scripts/create-signing-identity.sh @@ -60,24 +60,33 @@ with open(path, "w", encoding="utf-8") as handle: handle.write(text.replace(pattern, name)) PY +# macOS ships LibreSSL at /usr/bin/openssl, and the Security framework reads the bundle it +# writes. An OpenSSL 3 in the PATH (Homebrew's, which comes first on most Macs with one) packages +# it with algorithms `security import` refuses, and the import fails on the MAC check with a +# message about a wrong password. `-legacy` is meant to cover that, but only works on a build +# that ships the legacy provider, which Homebrew's does not. +OPENSSL=openssl +[ -x /usr/bin/openssl ] && OPENSSL=/usr/bin/openssl + +# A throwaway password rather than none: an empty one fails the same MAC check on current macOS, +# whatever wrote the bundle. It lives as long as this script and goes no further. +P12_PASSWORD="fremkit-$RANDOM$RANDOM$RANDOM" + echo "==> generating the key and certificate (10 years)" -openssl req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \ +"$OPENSSL" req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \ -config "$WORK/openssl.cnf" \ -keyout "$WORK/key.pem" -out "$WORK/cert.pem" >/dev/null 2>&1 echo "==> packaging them as PKCS#12" -openssl pkcs12 -export -legacy \ - -inkey "$WORK/key.pem" -in "$WORK/cert.pem" \ - -name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1 \ - || openssl pkcs12 -export \ +"$OPENSSL" pkcs12 -export \ -inkey "$WORK/key.pem" -in "$WORK/cert.pem" \ - -name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1 + -name "$IDENTITY" -passout "pass:$P12_PASSWORD" -out "$WORK/identity.p12" >/dev/null 2>&1 echo "==> importing into the login keychain" # `-x` marks the private key non-extractable: it can sign, but it cannot be exported back out of # the keychain. Only codesign is allowed to use it — `security` itself was on that list, which # let any script dump the key with `security export`. -security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "" -x \ +security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "$P12_PASSWORD" -x \ -T /usr/bin/codesign >/dev/null echo "==> trusting it for code signing"