Skip to content

MacOS builds getting rejected by Apple #126705

Description

@borjandev

Is there an existing issue for this?

Steps to reproduce

  1. Switch to master branch at commit 3d25049 or later
  2. flutter create --org com.yourdomain example (change to a real bundle identifier)
  3. Ensure that there there is an app on App Store Connect which matches that identifier
  4. flutter build macos --release
  5. Use Xcode Version 14.3 (14E222b) and click "Product --> Archive"
  6. Click "Validate App" once the archive completes and perform the signing process which is a part of the same flow
  7. Click "Distribute App" and keep the "App Store Connect" selected, and perform the re-sign process for App Store Connect distribution which is part of the same flow

Expected results

App appears in TestFlight without issues.

Last known good commit on master is 4fb146e where the app appears in TestFlight without issues.

Actual results

App doesn't appear in TestFlight on master branch at commit 3d25049 or later

Instead, I get an email from Apple :

Dear Developer,We identified one or more issues with a recent delivery for your app, "Example" 1.0.0 (1). Please correct the following issues, then upload again.

ITMS-90238: Invalid Signature - The main app bundle alpha at path alpha.app has following signing error(s): --

prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreImage.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreImage.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftAppKit.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftAppKit.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftObjectiveC.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftObjectiveC.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftXPC.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftXPC.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCore.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCore.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftMetal.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftMetal.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftos.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftos.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreGraphics.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreGraphics.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreFoundation.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreFoundation.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreData.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftCoreData.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftDispatch.dylib --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/libswiftDispatch.dylib --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/FlutterMacOS.framework/Versions/Current/. --prepared:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/App.framework/Versions/Current/. --validated:/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/App.framework/Versions/Current/. 

/Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app: unsealed contents present in the root directory of an embedded framework In subcomponent: /Volumes/workspace/app_data/SWValidationService/mz_16570556546293624248dir/mz_9478577434763482248dir/com.yourdomain.example.pkg/Payload/example.app/Contents/Frameworks/FlutterMacOS.framework . Refer to the Code Signing and Application Sandboxing Guide at http://developer.apple.com/library/mac/#documentation/Security/Conceptual/CodeSigningGuide/AboutCS/AboutCS.html and Technical Note 2206 at https://developer.apple.com/library/mac/technotes/tn2206/_index.html for more information.

Best regards,

The App Store Team 

Code sample

Code sample
Any code, even the default flutter app

Screenshots or Video

Screenshots / Video demonstration

[Upload media here]

Logs

Logs
[Paste your logs here]

Flutter Doctor output

Doctor output
[✓] Flutter (Channel master, 3.11.0-5.0.pre.54, on macOS 13.4 22F62 darwin-arm64, locale en-MK)
    • Flutter version 3.11.0-5.0.pre.54 on channel master at /Users/devdemo/fvm/versions/6e9c0db20640629c66f23be89e80f3b487141a96
    • Upstream repository https://github.com/flutter/flutter.git
    • Framework revision 6e9c0db206 (3 hours ago), 2023-05-12 10:41:54 -0700
    • Engine revision c784d6d413
    • Dart version 3.1.0 (build 3.1.0-102.0.dev)
    • DevTools version 2.23.1

[✓] Android toolchain - develop for Android devices (Android SDK version 33.0.2)
    • Android SDK at /Users/devdemo/Library/Android/sdk
    • Platform android-33, build-tools 33.0.2
    • ANDROID_HOME = /Users/devdemo/Library/Android/sdk
    • Java binary at: /Applications/Android Studio.app/Contents/jbr/Contents/Home/bin/java
    • Java version OpenJDK Runtime Environment (build 11.0.15+0-b2043.56-8887301)
    • All Android licenses accepted.

[✓] Xcode - develop for iOS and macOS (Xcode 14.3)
    • Xcode at /Applications/Xcode.app/Contents/Developer
    • Build 14E222b
    • CocoaPods version 1.12.0

[✓] Chrome - develop for the web
    • Chrome at /Applications/Google Chrome.app/Contents/MacOS/Google Chrome

[✓] Android Studio (version 2022.1)
    • Android Studio at /Applications/Android Studio.app/Contents
    • Flutter plugin can be installed from:
      🔨 https://plugins.jetbrains.com/plugin/9212-flutter
    • Dart plugin can be installed from:
      🔨 https://plugins.jetbrains.com/plugin/6351-dart
    • Java version OpenJDK Runtime Environment (build 11.0.15+0-b2043.56-8887301)

[✓] VS Code (version 1.77.1)
    • VS Code at /Applications/Visual Studio Code.app/Contents
    • Flutter extension can be installed from:
      🔨 https://marketplace.visualstudio.com/items?itemName=Dart-Code.flutter

[✓] VS Code (version 1.79.0-insider)
    • VS Code at /Applications/Visual Studio Code - Insiders.app/Contents
    • Flutter extension version 3.64.0

[✓] Connected device (4 available)
    • Redmi Note 7 (mobile) • e960747            • android-arm64  • Android 10 (API 29)
    • Pixel 3 (mobile)      • 100.13.180.15:5555 • android-arm64  • Android 12 (API 31)
    • macOS (desktop)       • macos              • darwin-arm64   • macOS 13.4 22F62 darwin-arm64
    • Chrome (web)          • chrome             • web-javascript • Google Chrome 113.0.5672.92

[✓] Network resources
    • All expected network resources are available.

• No issues found!

Activity

  1. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor

    @borjandev Are you trying to re-sign already signed FlutterMacOS.framework?

  2. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor

    image

    Can you please try using a newer commit from master that exist only on master?

  3. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor
  4. borjandev commented on May 12, 2023

    @borjandev
    Author

    @borjandev Are you trying to re-sign already signed FlutterMacOS.framework?

    I am following the official Xcode MacOS app submission flows, same issue from the GUI and even from fastlane flows, the only variable is the commit change, once 3d25049 landed, every newer commit submission has resulted in the same rejection

    Can you specify a commit hash that you want me to test specifically?

  5. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor

    Let's try with 9c72f5a7e62e63c199739267f3feeee0559caf11

  6. borjandev commented on May 12, 2023

    @borjandev
    Author

    @godofredoc same issue with 9c72f5a

    • Flutter version 3.11.0-5.0.pre.57 on channel master at /Users/devdemo/fvm/versions/9c72f5a7e62e63c199739267f3feeee0559caf11

  7. XilaiZhang commented on May 12, 2023

    @XilaiZhang
    Contributor

    Umm my understanding is that we only sign binaries tied to a release, umm should we also sign artifacts associated with a random hash?

  8. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor

    3d25049 was included in a release candidate branch which caused the binaries to be signed. My first thought was something related to signing but if 9c72f5a is failing in the same way then the error may be related to the file structure.

  9. godofredoc commented on May 12, 2023

    @godofredoc
    Contributor

    @borjandev are these files in your app tree: entitlements.txt and without_entitlements.txt?

    If they are can you please delete them and try to sign again?

  10. borjandev commented on May 12, 2023

    @borjandev
    Author

    @godofredoc

    1. Checking

    find . | grep entitlements.txt

    ./macos/Runner/DebugProfile.entitlements ./macos/Runner/Release.entitlements ./macos/example.app/Contents/Frameworks/FlutterMacOS.framework/entitlements.txt ./macos/example.app/Contents/Frameworks/FlutterMacOS.framework/without_entitlements.txt ./ios/Runner/Runner.entitlements ./build/macos/Build/Products/Release/FlutterMacOS.framework/entitlements.txt ./build/macos/Build/Products/Release/FlutterMacOS.framework/without_entitlements.txt ./build/macos/Build/Products/Release/example.app/Contents/Frameworks/FlutterMacOS.framework/entitlements.txt ./build/macos/Build/Products/Release/example.app/Contents/Frameworks/FlutterMacOS.framework/without_entitlements.txt

    1. Deleting
      find . | grep entitlements.txt | xargs -I{} rm {}

    2. Checking again
      find . | grep entitlements.txt (none found)

    Used the Xcode GUI and default flows to upload, same issue, same email from Apple

  11. XilaiZhang commented on May 12, 2023

    @XilaiZhang
    Contributor

    thanks for explaining!

    As a side note, the engine revision of 3d25049 points to 689eb6e as the hash of the engine binary. I visited google cloud buckets of the engine binary and it looks like the FlutterMacOS binary in FlutterMacOS.framework wasn't signed. Not sure if this is the expected behavior. entitlements.txt and without_entitlements.txt are present in the zip. the libswiftCoreImage.dylib files listed here are not on the list of files we would code sign.

    umm if we are expecting 3d25049 to be signed, does this mean we published a release with unsigned binaries?

  12. christopherfujino commented on May 12, 2023

    @christopherfujino
    Contributor

    3d25049 was included in a release candidate branch which caused the binaries to be signed. My first thought was something related to signing but if 9c72f5a is failing in the same way then the error may be related to the file structure.

    When I look at the first release branch AFTER 3d25049, it looks like it had a different engine hash: 55c988f

    Thus I don't think flutter-team-archive/engine@689eb6e was ever included in a RC branch, and I don't think it was ever codesigned.

    I'm not sure the issue, but I don't think it's related to the desktop release codesigning process.

  13. borjandev commented on May 12, 2023

    @borjandev
    Author

    @XilaiZhang @christopherfujino @godofredoc

    The flutter master commit that started causing this MacOS rejection 3d25049 has the following PR linked to it #125598

    This #125598 PR contains 2 commits :

    reland "Migrate mac_host_engine to engine v2 builds." (flutter-team-archive/engine#41531) - acc49d3

    Roll buildroot to 5708f2051772fd02c949e5dc9397e54f8c7a4478 (flutter-team-archive/engine#41540) - deef282

    So one of these 2 commits above caused the issue (unless I am missing something?)

    If it's not connected to the engine v2 builds, maybe it's related to the buildroot change? With the PR flutter-team-archive/engine#41540

    deps = {
      - 'src': 'https://github.com/flutter/buildroot.git' + '@' + '37fa2f05f6b009a1a92879c03b0871d97100aa2d',
      + 'src': 'https://github.com/flutter/buildroot.git' + '@' + '5708f2051772fd02c949e5dc9397e54f8c7a4478',
    

    Which is linked to flutter-team-archive/buildroot#722 which has a ton of files removed as noted here https://github.com/flutter/buildroot/pull/722/files

    Glancing through the removals, the obvious ones removed in reference to 'mac' are shown on the screenshot below, so I am not sure if they are relevant?

    buildroot
  14. christopherfujino commented on May 12, 2023

    @christopherfujino
    Contributor

    Here is the diff in a github view: https://github.com/flutter/engine/compare/19045bb99c..689eb6ee

    I suspect the root cause is some subtle directory structure change (as speculated in #126705 (comment)). Note, a google search on the error message "unsealed contents present in root directory" results in https://developer.apple.com/forums/thread/93914, where a new QT release no longer had an accepted Mac framework directory structure.

  15. 44 remaining items

  16. christopherfujino commented on May 23, 2023

    @christopherfujino
    Contributor

    @vashworth it looks like I ALSO need my previous change, where I deleted it at the time we copied from the cache to the build dir

  17. added
    r: fixedIssue is closed as already fixed in a newer version
    on May 24, 2023
  18. github-actions commented on Jun 7, 2023

    @github-actions

    This thread has been automatically locked since there has not been any recent activity after it was closed. If you are still experiencing a similar issue, please open a new bug, including the output of flutter doctor -v and a minimal reproduction of the issue.

  19. locked as resolved and limited conversation to collaborators on Jun 7, 2023
  20. added
    P0Critical issues such as a build break or regression
    and removed on Jun 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

P0Critical issues such as a build break or regressiona: desktopRunning on desktopc: regressionIt was better in the past than it is nowfound in release: 3.11Found to occur in 3.11has reproducible stepsThe issue has been confirmed reproducible and is ready to work onplatform-macosBuilding on or for macOS specificallyr: fixedIssue is closed as already fixed in a newer version

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions