You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac OS下从Flutter应用执行CLI工具遇操作不允许错误求助

在Mac OS上Flutter应用执行CLI工具遇“Operation not permitted”的解决方案

这个错误主要由Mac的Gatekeeper安全机制和Flutter macOS应用的沙箱限制导致,以下是针对性解决步骤:

1. 处理Gatekeeper隔离限制

从assets复制到临时目录的二进制文件会被Mac标记为“来自互联网”的隔离文件,直接执行会被阻止。在代码中添加移除隔离属性的操作:

final Directory dir = await getTemporaryDirectory();
final binaryPath = '${dir.path}/MyCliTool';

if (false == await File(binaryPath).exists()) {
      final ByteData binaryBytes = await rootBundle.load('bin_assets/MyCliTool');
      await File(binaryPath).writeAsBytes(binaryBytes.buffer.asUint8List(), flush: true);
      await Process.run('chmod', ['+x', binaryPath]);
      // 移除Mac的隔离标记
      await Process.run('xattr', ['-d', 'com.apple.quarantine', binaryPath]);
}
ProcessResult result = await Process.run(binaryPath, ['arg1', 'arg2']);

2. 解决应用沙箱限制

Flutter macOS应用默认开启沙箱,会限制执行外部二进制。修改项目的Runner.entitlements文件:

  • 开发阶段可直接关闭沙箱(不适合发布到App Store):
<key>com.apple.security.app-sandbox</key>
<false/>
  • 若需保留沙箱(发布用),添加允许执行自定义二进制的权限:
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
<key>com.apple.security.cs.disable-executable-page-protection</key>
<true/>

3. 发布版本额外处理

如果是要发布的应用,必须给CLI二进制文件签名,使用苹果开发者证书执行以下命令:

codesign -s "你的开发者证书名称" --deep --force /path/to/MyCliTool

签名后的二进制再打包到assets中,避免Gatekeeper拦截。

内容的提问来源于stack exchange,提问作者Fractale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 21:07:02