You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Electron开发的my_electron_app在macOS启动失败(签名无效)

Electron应用签名公证验证通过但启动报SIGKILL(Code Signature Invalid)错误

问题背景

使用Electron开发应用,通过提交CSR获取Developer ID证书,依赖electron-builder完成构建、签名与公证流程。codesign和spctl验证均显示签名与公证状态正常,但启动应用时直接崩溃,错误提示签名无效。

已验证的签名与公证状态

codesign -dv --verbose=4 /Path/To/Application.app输出:

Executable=/Users/werad-03/Documents/my_electron_app/my_electron_app_v2_POM_with_TATA/TATA-desktop/dist/mac/my_electron_app.app/Contents/MacOS/my_electron_app
Identifier=my_electron_app02
Format=app bundle with Mach-O thin (x86_64)
CodeDirectory v=20500 size=1817 flags=0x10000(runtime) hashes=46+7 location=embedded
VersionPlatform=1
VersionMin=657920
VersionSDK=659200
Hash type=sha256 size=32
CandidateCDHash sha1=3e8e0f0d21d972f3466edee7c1f75acc1dc2ddb2
CandidateCDHashFull sha1=3e8e0f0d21d972f3466edee7c1f75acc1dc2ddb2
CandidateCDHash sha256=c6c6c4bcda74e158e023736305bafa34be3369b2
CandidateCDHashFull sha256=c6c6c4bcda74e158e023736305bafa34be3369b2fe7928bc9e530de342dd5101
Hash choices=sha1,sha256
CMSDigest=35493b34272c1732f1bc8e9d1d7aba27bd0599c01448f0a6d6ecf53ff9e5cd14
CMSDigestType=2
Executable Segment base=0
Executable Segment limit=167936
Executable Segment flags=0x1
Page size=4096
Launch Constraints:
  None
CDHash=c6c6c4bcda74e158e023736305bafa34be3369b2
Signature size=9123
Authority=Developer ID Application: DIGITAL SOLUTIONS - FZCO (95C3U6CXH8)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=21. Sep 2023 at 02:49:16
Info.plist entries=29
TeamIdentifier=85C3U6CXH7
Runtime Version=10.15.0
Sealed Resources version=2 rules=13 files=105
Internal requirements count=1 size=176

spctl -a -v --type install /Path/To/Application.app输出:

my_electron_app.app: accepted
source=Notarized Developer ID

应用权限plist内容

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
    <dict>
        <key>com.apple.security.cs.allow-jit</key>
        <true/>
        <key>com.apple.security.cs.allow-unsigned-executable-memory</key>
        <true/>
        <key>com.apple.security.cs.disable-library-validation</key>
        <true/>
        <key>com.apple.security.device.camera</key>
        <true/>
        <key>com.apple.security.device.audio-input</key>
        <true/>
        <key>com.apple.security.network.client</key>
        <true/>
        <key>com.apple.security.files.user-selected.read-write</key>
        <true/>
        <key>com.apple.security.network.server</key>
        <true/>
        <key> com.apple.security.automation.apple-events</key>
        <true/>
        <key>com.apple.security.device.screen-capture</key>
        <true/>
        <key>com.apple.private.accessibility.app-audit</key>
        <true/>
        <key>NSAppleEventsUsageDescription</key>
        <string>This app requires automation permissions to interact with other applications for reading mouse clicks and keystrokes.</string>
        <key>NSScreenCaptureUsageDescription</key>
        <string>This app requires screen capture permissions to record the screen.</string>
        <key>NSMicrophoneUsageDescription</key>
        <string>This app requires microphone usage permissions to enable voice calls.</string>
        <key>NSCameraUsageDescription</key>
        <string>This app requires camera usage permissions to enable video calls.</string>
    </dict>
</plist>

崩溃日志

-------------------------------------
Translated Report (Full Report Below)
-------------------------------------

Incident Identifier: 72A47E48-846F-4EFB-A47E-DE06AE872D51
CrashReporter Key:   61141667-4FFF-8213-8B3A-0C9970B0E1A6
Hardware Model:      MacBookAir10,1
Process:             my_electron_app [653]
Path:                /Applications/my_electron_app.app/Contents/MacOS/my_electron_app
Identifier:          my_electron_app02
Version:             2.0.1 (2.0.1)
Code Type:           X86-64 (Native)
Role:                Default
Parent Process:      launchd [1]
Coalition:           my_electron_app02 [782]

Date/Time:           2023-09-21 23:17:35.0485 +0300
Launch Time:         2023-09-21 23:17:34.9190 +0300
OS Version:          macOS 13.0.1 (22A400)
Release Type:        User
Report Version:      104

Exception Type:  EXC_CRASH (SIGKILL (Code Signature Invalid))
Exception Codes: 0x0000000000000000, 0x0000000000000000
Termination Reason: CODESIGNING 1 Taskgated Invalid Signature

Triggered by Thread:  0

Thread 0 Crashed:
0                                       0x7ff7ffe2f8bc 0x7ff7ffe2c000 + 14524


Thread 0 crashed with ARM Thread State (64-bit):
    x0: 0x0000000000000000   x1: 0x0000000000000000   x2: 0x0000000000000000   x3: 0x0000000000000000
    x4: 0x0000000000000000   x5: 0x0000000000000000   x6: 0x0000000000000000   x7: 0x0000000000000000
    x8: 0x0000000000000000   x9: 0x0000000000000000  x10: 0x0000000000000000  x11: 0x0000000000000000
   x12: 0x0000000000000000  x13: 0x0000000000000000  x14: 0x0000000000000000  x15: 0x0000000000000000
   x16: 0x0000000000000000  x17: 0x0000000000000000  x18: 0x0000000000000000  x19: 0x0000000000000000
   x20: 0x0000000000000000  x21: 0x0000000000000000  x22: 0x0000000000000000  x23: 0x0000000000000000
   x24: 0x0000000000000000  x25: 0x0000000000000000  x26: 0x0000000000000000  x27: 0x0000000000000000
   x28: 0x0000000000000000   fp: 0x0000000000000000   lr: 0x0000000000000000
    sp: 0x0000000305bb9bd0   pc: 0x00007ff7ffe2f8bc cpsr: 0x00001000
   far: 0x0000000000000000  esr: 0x00000000  Address size fault

Binary Images:
    0x7ff7ffe2c000 -     0x7ff7ffe5bfff  (*) <6f797d84-b330-3656-9a0d-7b3dbd3f8a07> ???

Error Formulating Crash Report:
dyld_process_snapshot_get_shared_cache failed

EOF

已尝试的解决方案

  • 从应用程序文件夹删除应用并重新从DMG安装
  • 关闭设备上的Gatekeeper
  • 重新签名并重新公证应用

排查与修复建议

1. 修复Team Identifier不匹配问题

从codesign输出可见:

  • 证书的Team ID是95C3U6CXH8(Authority字段)
  • 应用包内的TeamIdentifier是85C3U6CXH7

macOS签名验证会严格校验这两个值的一致性,不匹配会直接判定签名无效。解决步骤:

  • 在electron-builder配置文件(package.json或electron-builder.yml)中,添加或修改teamId字段为95C3U6CXH8
  • 确保appId的前缀与Team ID一致(如95C3U6CXH8.my_electron_app02)
  • 重新构建、签名、公证应用

2. 修正权限plist的格式错误

权限plist中com.apple.security.automation.apple-events键前面存在多余空格,会导致plist解析异常,触发签名验证失败。需要删除该键前的空格,确保所有键的格式规范。

3. 构建Universal架构包

当前应用是x86_64单架构,而运行设备是ARM架构的MacBookAir10,1。虽然Rosetta可以转译,但构建Universal架构(同时支持x86_64和arm64)可能解决潜在的架构兼容性问题。在electron-builder配置中添加:

"build": {
  "mac": {
    "target": "dmg",
    "arch": ["x64", "arm64"]
  }
}

4. 手动重新签名应用包

如果electron-builder的签名流程存在遗漏,尝试手动重新签名整个包:

codesign --force --deep --sign "Developer ID Application: DIGITAL SOLUTIONS - FZCO (95C3U6CXH8)" --options runtime /Path/To/Application.app

签名完成后重新用codesign和spctl验证,再尝试启动应用。

内容的提问来源于stack exchange,提问作者werad saoud

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 09:59:50