From 8e9f9bbf698dc5421bd4d543651106de66cde162 Mon Sep 17 00:00:00 2001 From: Mickael Couzinet Date: Mon, 28 Sep 2026 10:55:55 +0200 Subject: [PATCH 1/2] signing identity: an import macOS accepts `security import` refused the bundle the script writes, with "MAC verification failed during PKCS12 import (wrong password?)", and the identity was never created. Every later build of the helper then stayed ad-hoc signed, which gives it a new code identity each time and drops the Input Monitoring and Accessibility grants of the build before. What the user sees is the touch panel gone: macOS maps the untouched panel to the main display, so the Edge clicks on another screen. Two causes, both on current macOS, and the message names neither. The bundle is written with an empty password, which the Security framework no longer verifies, whatever wrote it: a throwaway password is enough, and it never leaves the script. And `openssl` was whatever the PATH offered first, which on a Mac with Homebrew is OpenSSL 3: it packages the bundle with algorithms `security` does not read, and the `-legacy` attempt in front of it needs a provider that build does not ship, so the fallback wrote an unreadable bundle every time. macOS always has LibreSSL at /usr/bin/openssl, which writes what its own tools accept, so the script asks for it by name and keeps `openssl` as the fallback. Co-Authored-By: Claude Opus 5 --- CHANGELOG.md | 5 +++++ scripts/create-signing-identity.sh | 23 ++++++++++++++++------- 2 files changed, 21 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 53e746a..e95a28e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -37,6 +37,11 @@ Anything that changes what the dashboard, the admin or a widget can do gets a li sessions after 30 minutes (on by default), and group the board by application. ### Fixed +- The helper keeps its Input Monitoring and Accessibility grants across rebuilds again, on Macs + where `scripts/create-signing-identity.sh` failed at the import step ("MAC verification failed"). + The identity was never created, so every build stayed ad-hoc signed and lost the permissions + granted to the one before, which shows up as the touch panel clicking on another display + (@mcouzinet, #8). - Spotify's progress bar moves: on a Mac whose number format uses a decimal comma the position read as nothing, and the bar sat at zero. It now glides across each second instead of stepping, lands at once on a seek, a new track or a pause, and empties when Spotify closes (@mcouzinet, #4). diff --git a/scripts/create-signing-identity.sh b/scripts/create-signing-identity.sh index 9c8f2f5..977ea93 100755 --- a/scripts/create-signing-identity.sh +++ b/scripts/create-signing-identity.sh @@ -60,24 +60,33 @@ with open(path, "w", encoding="utf-8") as handle: handle.write(text.replace(pattern, name)) PY +# macOS ships LibreSSL at /usr/bin/openssl, and the Security framework reads the bundle it +# writes. An OpenSSL 3 in the PATH (Homebrew's, which comes first on most Macs with one) packages +# it with algorithms `security import` refuses, and the import fails on the MAC check with a +# message about a wrong password. `-legacy` is meant to cover that, but only works on a build +# that ships the legacy provider, which Homebrew's does not. +OPENSSL=openssl +[ -x /usr/bin/openssl ] && OPENSSL=/usr/bin/openssl + +# A throwaway password rather than none: an empty one fails the same MAC check on current macOS, +# whatever wrote the bundle. It lives as long as this script and goes no further. +P12_PASSWORD="fremkit-$RANDOM$RANDOM$RANDOM" + echo "==> generating the key and certificate (10 years)" -openssl req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \ +"$OPENSSL" req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \ -config "$WORK/openssl.cnf" \ -keyout "$WORK/key.pem" -out "$WORK/cert.pem" >/dev/null 2>&1 echo "==> packaging them as PKCS#12" -openssl pkcs12 -export -legacy \ - -inkey "$WORK/key.pem" -in "$WORK/cert.pem" \ - -name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1 \ - || openssl pkcs12 -export \ +"$OPENSSL" pkcs12 -export \ -inkey "$WORK/key.pem" -in "$WORK/cert.pem" \ - -name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1 + -name "$IDENTITY" -passout "pass:$P12_PASSWORD" -out "$WORK/identity.p12" >/dev/null 2>&1 echo "==> importing into the login keychain" # `-x` marks the private key non-extractable: it can sign, but it cannot be exported back out of # the keychain. Only codesign is allowed to use it — `security` itself was on that list, which # let any script dump the key with `security export`. -security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "" -x \ +security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "$P12_PASSWORD" -x \ -T /usr/bin/codesign >/dev/null echo "==> trusting it for code signing" From d7713c9bd91b18d616cd6b2fd3273bc1bd0fe783 Mon Sep 17 00:00:00 2001 From: Mickael Couzinet Date: Mon, 28 Sep 2026 11:33:10 +0200 Subject: [PATCH 2/2] docs: the grant a rebuild left behind, and how to clear it Re-adding the helper under Privacy & Security does not help when the identity changed: macOS keeps one entry per past signature, ticked and useless, and matches those before the new one. It took a `tccutil reset` of both services on my Mac, which had three of each, to get the prompts back and the touch panel with them. Co-Authored-By: Claude Opus 5 --- docs/troubleshooting.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index bd81897..6088f4c 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -15,6 +15,7 @@ and "Notifications: active" above the toggles, and *Log…* opens the supervised | "Touch: taken by another driver" | Touchscreen Gestures, another driver or a `--probe` run holds the panel | Quit it, and unload its launchd agent so it does not come back | | "Fence: permission missing" | Accessibility not granted | Add "Fremkit Helper" under Privacy & Security → Accessibility, then relaunch it | | Permissions reset after every rebuild | Ad-hoc signature: a new code identity each build | Run `scripts/create-signing-identity.sh`, rebuild, grant once more | +| The helper is ticked in Privacy & Security and still has no permission | One stale grant per past ad-hoc identity, which macOS keeps in its cache and matches before the new one | `tccutil reset ListenEvent dev.fremkit.helper && tccutil reset Accessibility dev.fremkit.helper`, relaunch the helper, and accept the two prompts. Removing and re-adding the app in the list does not clear those entries | | Printer unreachable (`EHOSTUNREACH`) while `ping` and `curl` work | Local Network not granted to the app that runs the server | Allow it under Privacy & Security → Local Network | | "Server: external" | Something already answers port 4242, so the helper steps aside | Expected under `pnpm dev`; otherwise stop the stray server, or turn *Manage the server* off |