Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,11 @@ Anything that changes what the dashboard, the admin or a widget can do gets a li
sessions after 30 minutes (on by default), and group the board by application.

### Fixed
- The helper keeps its Input Monitoring and Accessibility grants across rebuilds again, on Macs
where `scripts/create-signing-identity.sh` failed at the import step ("MAC verification failed").
The identity was never created, so every build stayed ad-hoc signed and lost the permissions
granted to the one before, which shows up as the touch panel clicking on another display
(@mcouzinet, #8).
- Spotify's progress bar moves: on a Mac whose number format uses a decimal comma the position
read as nothing, and the bar sat at zero. It now glides across each second instead of stepping,
lands at once on a seek, a new track or a pause, and empties when Spotify closes (@mcouzinet, #4).
Expand Down
1 change: 1 addition & 0 deletions docs/troubleshooting.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ and "Notifications: active" above the toggles, and *Log…* opens the supervised
| "Touch: taken by another driver" | Touchscreen Gestures, another driver or a `--probe` run holds the panel | Quit it, and unload its launchd agent so it does not come back |
| "Fence: permission missing" | Accessibility not granted | Add "Fremkit Helper" under Privacy & Security → Accessibility, then relaunch it |
| Permissions reset after every rebuild | Ad-hoc signature: a new code identity each build | Run `scripts/create-signing-identity.sh`, rebuild, grant once more |
| The helper is ticked in Privacy & Security and still has no permission | One stale grant per past ad-hoc identity, which macOS keeps in its cache and matches before the new one | `tccutil reset ListenEvent dev.fremkit.helper && tccutil reset Accessibility dev.fremkit.helper`, relaunch the helper, and accept the two prompts. Removing and re-adding the app in the list does not clear those entries |
| Printer unreachable (`EHOSTUNREACH`) while `ping` and `curl` work | Local Network not granted to the app that runs the server | Allow it under Privacy & Security → Local Network |
| "Server: external" | Something already answers port 4242, so the helper steps aside | Expected under `pnpm dev`; otherwise stop the stray server, or turn *Manage the server* off |

Expand Down
23 changes: 16 additions & 7 deletions scripts/create-signing-identity.sh
Original file line number Diff line number Diff line change
Expand Up @@ -60,24 +60,33 @@ with open(path, "w", encoding="utf-8") as handle:
handle.write(text.replace(pattern, name))
PY

# macOS ships LibreSSL at /usr/bin/openssl, and the Security framework reads the bundle it
# writes. An OpenSSL 3 in the PATH (Homebrew's, which comes first on most Macs with one) packages
# it with algorithms `security import` refuses, and the import fails on the MAC check with a
# message about a wrong password. `-legacy` is meant to cover that, but only works on a build
# that ships the legacy provider, which Homebrew's does not.
OPENSSL=openssl
[ -x /usr/bin/openssl ] && OPENSSL=/usr/bin/openssl

# A throwaway password rather than none: an empty one fails the same MAC check on current macOS,
# whatever wrote the bundle. It lives as long as this script and goes no further.
P12_PASSWORD="fremkit-$RANDOM$RANDOM$RANDOM"

echo "==> generating the key and certificate (10 years)"
openssl req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \
"$OPENSSL" req -x509 -newkey rsa:2048 -nodes -sha256 -days 3650 \
-config "$WORK/openssl.cnf" \
-keyout "$WORK/key.pem" -out "$WORK/cert.pem" >/dev/null 2>&1

echo "==> packaging them as PKCS#12"
openssl pkcs12 -export -legacy \
-inkey "$WORK/key.pem" -in "$WORK/cert.pem" \
-name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1 \
|| openssl pkcs12 -export \
"$OPENSSL" pkcs12 -export \
-inkey "$WORK/key.pem" -in "$WORK/cert.pem" \
-name "$IDENTITY" -passout pass: -out "$WORK/identity.p12" >/dev/null 2>&1
-name "$IDENTITY" -passout "pass:$P12_PASSWORD" -out "$WORK/identity.p12" >/dev/null 2>&1

echo "==> importing into the login keychain"
# `-x` marks the private key non-extractable: it can sign, but it cannot be exported back out of
# the keychain. Only codesign is allowed to use it — `security` itself was on that list, which
# let any script dump the key with `security export`.
security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "" -x \
security import "$WORK/identity.p12" -k "$KEYCHAIN" -P "$P12_PASSWORD" -x \
-T /usr/bin/codesign >/dev/null

echo "==> trusting it for code signing"
Expand Down
Loading