Skip to content

SHARD-214: embed the shim in the daemon and ad-hoc sign it at first use - #178

Merged
presmihaylov merged 6 commits into
mainfrom
shard-214-shim-signing
Sep 19, 2026
Merged

presmihaylov merged 6 commits into
mainfrom
shard-214-shim-signing

Conversation

@presmihaylov

@presmihaylov presmihaylov commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

SHARD-214. Fifth of the M10 stack, stacked on #177.

Why. Virtualization.framework refuses a VM to a process without the com.apple.security.virtualization entitlement, which needs a signature. Only the shim carries it.

How.

  • Look first at pkg/vzshim/vzshim.go: its own package, because the shim imports pkg/vz and an embed there would carry its previous build. Without the binary the build still compiles and ErrNoShim names the fix.
  • The linker drops an unreferenced embed, so the version verb references vzshim.Embedded(); a test checks the built daemon with go tool nm.
  • Install writes a temp file, signs, renames, then stamps a .sha256 of the embedded bytes, since codesign rewrites the file.
  • The Command Line Tools codesign is enough; no Xcode.
  • The provider calls Install before its first boot in SHARD-218; here the pkg/vz boot test is the caller.

What. make build-darwin, pkg/vzshim, docs/macos-signing.md with the codesign -d --entitlements output.

Comment thread Makefile
Comment thread Makefile
Comment thread pkg/vz/shim.go Outdated
Comment thread cli/shim_darwin.go
Comment thread Makefile
Comment thread pkg/vzshim/vzshim.go Outdated
The daemon embeds shard-vz-shim and its entitlements, writes the shim into
the shard root on first use, and signs it there with codesign --sign -.
Only the shim carries com.apple.security.virtualization; the daemon and
the CLI keep the Go linker's plain ad-hoc signature. make build-darwin
builds and signs the shim, then the Mac daemon that embeds it.

docs/macos-signing.md says what an ad-hoc signature can and cannot do,
what a Developer ID adds, and what an MDM block looks like.
…mon, and make the install race-free

The shim imports pkg/vz, so an embed there made every build carry the
previous one and no two builds hashed the same. pkg/vzshim holds the
asset and only the daemon links it. Install signs a temporary copy of
its own and publishes it by rename, so sixteen first-use callers leave
one signed shim and no debris.
…one-line comments, and the install wiring is named as SHARD-218's
@presmihaylov
presmihaylov changed the base branch from shard-213-vz-driver to main September 19, 2026 18:29
…request

The kernel job compiles Linux twice per arch, 13 minutes, and ran on every PR that touched the Makefile. The kernel changes rarely and the manual release run already proves reproducibility.
@presmihaylov
presmihaylov merged commit 6b9b2ce into main Sep 19, 2026
3 checks passed
@presmihaylov
presmihaylov deleted the shard-214-shim-signing branch September 24, 2026 05:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant