如何修复py2app代码签名时Python.framework签名后程序无法运行的问题
py2app生成应用自签名Python.framework报错解决方案
错误根因
你遇到的not valid for use in process using Library Validation: mapped file has no Team ID and is not a platform binary报错,是macOS库验证机制的默认限制:只有苹果官方发布的平台二进制、或绑定了付费Apple Developer Team ID签名的二进制,才能通过库验证。你使用的自签名证书没有官方Team ID,直接签名Python.framework后触发了校验拦截。
完整解决步骤
1. 准备豁免权限配置文件
新建名为entitlements.plist的配置文件,写入以下内容,核心是关闭库验证限制:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>com.apple.security.cs.disable-library-validation</key> <true/> </dict> </plist>
2. 按从内到外的顺序执行签名
签名必须遵循「内部库→框架→主二进制→整包」的顺序,执行以下命令前先替换你的自签名证书名称为你创建的证书的完整名称:
# 定义变量 export APP="PyGitIssueClone.app" export IDENTITY="你的自签名证书名称" # 1. 签名所有.so动态库和.dylib文件 find "${APP}" -iname '*.so' -or -iname '*.dylib' | while read libfile; do codesign --force --verify --verbose --sign "${IDENTITY}" --options=runtime "${libfile}" >> CodeSigning.log 2>&1 ; done; # 2. 签名Python.framework(注意是签版本目录,不是仅签内部二进制) codesign --force --verify --verbose --sign "${IDENTITY}" --options=runtime "${APP}/Contents/Frameworks/Python.framework/Versions/3.9" # 3. 签名主目录下的二进制文件,绑定豁免权限 codesign --force --sign "${IDENTITY}" --options=runtime --entitlements entitlements.plist "${APP}/Contents/MacOS/python" codesign --force --sign "${IDENTITY}" --options=runtime --entitlements entitlements.plist "${APP}/Contents/MacOS/PyGitIssueClone" # 4. 最后签名整个.app包 codesign --force --verify --verbose --sign "${IDENTITY}" --options=runtime --entitlements entitlements.plist "${APP}"
3. 校验签名结果
执行以下命令验证签名完整性:
# 校验签名信息 codesign -dv --verbose=4 "${APP}" # 校验Gatekeeper认可状态(自签名会提示未认可,属于正常情况,本地运行右键首次打开即可跳过拦截) spctl -a -v "${APP}"
内容的提问来源于stack exchange,提问作者Sequestered1776Vexer
相关产品推荐
相关产品推荐

