Skip to content

🐛 fix(desktop): pin electron-builder to 26.14.0 to fix broken macOS update signing#15527

Merged
arvinxx merged 1 commit into
canaryfrom
fix/desktop-pin-electron-builder
Jun 7, 2026
Merged

🐛 fix(desktop): pin electron-builder to 26.14.0 to fix broken macOS update signing#15527
arvinxx merged 1 commit into
canaryfrom
fix/desktop-pin-electron-builder

Conversation

@arvinxx

@arvinxx arvinxx commented Jun 7, 2026

Copy link
Copy Markdown
Member

💡 Description of Change

Desktop auto-update silently fails on macOS: clicking "install update" does nothing and the app never quits/relaunches.

Root cause — a broken build artifact, empirically confirmed. The canary.12 macOS zip, once Squirrel.Mac extracts it during update, fails code-signature validation:

Code signature ... did not pass validation: bundle format is ambiguous (could be app or framework)

This is errSecCSBadBundleFormat — the extracted .app is structurally malformed, so macOS rejects the swap and the install aborts before the app quits.

Why it started ~2 days ago. electron-builder was floating on ^26.8.1 and the repo commits no lockfile, so each CI build resolves a fresh version. The canary.12 build (2026-06-07) picked up 26.15.0, which switched the macOS zip packaging to 7zip (part of the app-builder-bin Go→TS migration, #9829). 7zip does not preserve the symlink farm of .framework bundles, so after extraction Electron Framework.framework has an ambiguous layout.

🔬 Local reproduction (same code, same Electron 41.3.0, only electron-builder version swapped)

electron-builder 26.15.0 electron-builder 26.14.0
--dir bundle (assembly) valid valid
zip packer 7zip (downloads 7zip-darwin-arm64) ditto
zip size 350 MB 154 MB
extract → codesign --deep --sign - bundle format is ambiguous … Electron Framework.framework ✅ exit 0
extract → codesign --verify --deep --strict ❌ fails ✅ exit 0

The --dir bundle is fine for both; only the zip round-trip (the path auto-update uses) breaks under 26.15.0. The 2.3× zip bloat corroborates symlinks being dereferenced instead of preserved.

26.15.1 (latest) does not fix it — its only mac-touching PR (#9838) is pure lint/refactor; the zip change is untouched. So "pull latest" is not a fix.

✅ Fix

Pin electron-builder to exact 26.14.0 — the last release before the 7zip mac-zip regression, confirmed above to produce a valid, re-extractable bundle. The exact pin cascades to app-builder-lib / dmg-builder / builder-util (electron-builder pins those exactly), so the toolchain stops floating across CI installs.

✅ Change Type

  • 🐛 fix: A bug fix

🧪 How to Test

  1. Cut a macOS build with this pin.
  2. Extract the produced *-mac.zip and run codesign --verify --deep --strict <LobeHub.app> → exit 0 (26.15.0 yields "bundle format is ambiguous").
  3. Auto-update end-to-end → app quits and relaunches to install.

⚠️ Follow-ups (not in this PR)

  • Root cause is "no lockfile + caret range floats". Consider committing a lockfile for the desktop build and/or a release-gate codesign --verify --deep --strict on the extracted zip so a broken bundle can never ship silently again.
  • File an upstream electron-builder issue for the 26.15.0 macOS zip (7zip) symlink regression.

🤖 Generated with Claude Code

…pdate signing

electron-builder was floating on `^26.8.1` and the repo commits no lockfile,
so each CI build resolved a fresh version. The canary.12 build (2026-06-07)
picked up 26.15.0, which regressed macOS .app bundle signing: codesign reports
"bundle format is ambiguous (could be app or framework)" and Squirrel.Mac
rejects the update during code-signature validation, so the app never quits
to install — surfacing as "auto-update does nothing".

26.15.0 introduced the two suspect changes (mac signing rework #9822 and the
full app-builder-bin Go→TS replacement #9829). 26.14.0 predates both and does
not touch macOS app-bundle signing/layout. Pinning the exact version cascades
to app-builder-lib / dmg-builder / builder-util (electron-builder pins those
exactly), stopping the toolchain from floating across CI installs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@vercel

vercel Bot commented Jun 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lobehub Ready Ready Preview, Comment Jun 7, 2026 11:20am

Request Review

@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. platform:desktop Desktop client trigger:build-desktop Trigger Desktop build labels Jun 7, 2026
@arvinxx arvinxx merged commit 78657d4 into canary Jun 7, 2026
41 of 49 checks passed
@arvinxx arvinxx deleted the fix/desktop-pin-electron-builder branch June 7, 2026 11:20
@github-actions

github-actions Bot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

🚀 Desktop App Build Completed!

Version: 0.0.0-nightly.pr15527.15320
Build Time: 2026-06-07T12:05:45.811Z

📦 Release Download · 📥 Actions Artifacts

Build Artifacts

Platform File Size
macOS (Apple Silicon) LobeHub-Nightly-0.0.0-nightly.pr15527.15320-arm64-mac.zip 147.59 MB
macOS (Apple Silicon) LobeHub-Nightly-0.0.0-nightly.pr15527.15320-arm64.dmg 140.43 MB
macOS (Intel) LobeHub-Nightly-0.0.0-nightly.pr15527.15320-mac.zip 156.20 MB
macOS (Intel) LobeHub-Nightly-0.0.0-nightly.pr15527.15320-x64.dmg 147.57 MB
Windows LobeHub-Nightly-0.0.0-nightly.pr15527.15320-setup.exe 134.71 MB
Linux LobeHub-Nightly-0.0.0-nightly.pr15527.15320.AppImage 165.21 MB

Warning

Note: This is a temporary build for testing purposes only.

@arvinxx

arvinxx commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

Confirmed the root cause is upstream and filed it with a minimal, cert-free reproduction:

electron-builder 26.15.0 switched the macOS zip packer to 7zip, which dereferences .framework Versions/Current symlinks → extracted bundle is "ambiguous" → Squirrel.Mac rejects the update. 26.14.0 (this pin) preserves symlinks and extracts clean. 26.15.1 does not fix it.

Once electron-builder ships a fix, we can lift this pin.

arvinxx added a commit that referenced this pull request Jun 10, 2026
# 🚀 LobeHub Release (20260610)

**Release Date:** June 10, 2026  
**Since v2.2.2:** 131 merged PRs · 13 contributors

> This weekly release strengthens agent collaboration across cloud,
desktop, CLI, and workspace flows, with steadier runtime behavior and a
broader foundation for workspace-scoped data.

---

## ✨ Highlights

- **Agent execution across devices** — Unifies per-device working
directories, project skill discovery, and sub-agent suspend/resume
behavior across server, QStash, and device RPC flows. (#15543, #15566,
#15481, #15620, #15591)
- **Connector and sandbox platform** — Expands connector permissions,
custom OAuth MCP connector onboarding, sandbox provider support, and
user-uploaded file sync into cloud sandbox runs. (#15463, #15546,
#15184, #15550)
- **Desktop and CLI reliability** — Fixes desktop cold-start,
auto-update, Windows build, CLI skill discovery, and `lh connect` agent
dispatch paths. (#15547, #15525, #15527, #15562, #15632, #15634)
- **Pages and sharing** — Refreshes topic sharing, improves Page Editor
layout behavior, and routes Page Agent tool execution through the
server-side editor path. (#15581, #15556, #15588, #15023, #15610)
- **Model availability and provider updates** — Adds user-scoped LobeHub
model availability, Claude Fable 5, Qwen thinking preservation, and
MiniMax M3 updates. (#15590, #15639, #13494, #15376)

---

## 🏗️ Core Product & Architecture

### Agent Runtime & Heterogeneous Agents

- Improves sub-agent lifecycle handling, including async suspend/resume,
queue-mode QStash resume delivery, and blocking nested sub-agent calls.
(#15481, #15620, #15575)
- Stabilizes heterogeneous agent ingestion and streaming with raw stream
dumps, per-turn usage, image forwarding on regenerate, and
duplicate-text fixes. (#15602, #15577, #15592, #15585)
- Adds execution-device and working-directory controls across device
RPC, legacy defaults, and remote-spawned Claude Code sessions. (#15543,
#15566, #15591, #15572)
- Improves runtime diagnostics and compatibility, including Gemini
multimodal output capture, abort stream semantics, and trace quality
analysis. (#15535, #13677, #15508)

---

## 📱 Platforms, Integrations & UX

### Connectors, Sandbox & Tools

- Ships API-level connector tool permissions, custom OAuth MCP connector
onboarding, and connector-first runtime execution. (#15463, #15546)
- Adds sandbox provider support, cloud sandbox file sync, and safer
external URL file input handling with SSRF validation. (#15184, #15550,
#12657)
- Improves tool visibility and execution with pinned app-fixed tools,
ANSI output rendering, gateway-tunneled MCP calls, and automatic
headless tool runs. (#15509, #15516, #15469, #15492)

### Desktop, CLI & Web UX

- Restores desktop startup and reload behavior, preserves IPC error
causes, and keeps the tab bar new-tab action visible across routes.
(#15547, #15597, #15638)
- Fixes desktop update and build stability for browser quit guards,
macOS update signing, and Windows Visual Studio detection. (#15525,
#15527, #15562)
- Shows the plan-limit upgrade UI on desktop builds. (#15628)
- Adds the Agent Run delivery checker and fixes CLI device dispatch plus
skill list/search output. (#15489, #15634, #15632)
- Refreshes onboarding, auth source preservation, topic UI states,
referral/Fable campaign copy, and chat-input control bar behavior.
(#15629, #15544, #15573, #15614, #15616, #15617, #15622, #15643)

---

## 🔒 Security, Reliability & Rollout Notes

- External URL file input now includes SSRF validation for safer Google
file handling. (#12657)
- Database workspace-scope migrations are part of this release;
self-hosted operators should run the normal migration path before
serving the updated app. (#15446, #15465, #15468, #15472)
- The release branch was re-cut from `canary` and includes the latest
`main` release-version commit so `v2.2.2` is the verified compare base.

---

## 👥 Contributors

@ONLY-yours, @sxjeru, @hardy-one, @xujingli, @hezhijie0327, @Coooolfan,
@arvinxx, @tjx666, @Innei, @rivertwilight, @rdmclin2, @cy948,
@AmAzing129

**Full Changelog**:
v2.2.2...release/weekly-20260610-recut-3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

platform:desktop Desktop client size:XS This PR changes 0-9 lines, ignoring generated files. trigger:build-desktop Trigger Desktop build

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant