Skip to content

Add sandbox + network.client entitlements to the LP-100A extension - #5

Merged
VU3ESV merged 1 commit into
mainfrom
feat/extension-entitlements
Jun 3, 2026
Merged

VU3ESV merged 1 commit into
mainfrom
feat/extension-entitlements

Conversation

@VU3ESV

@VU3ESV VU3ESV commented Jun 3, 2026

Copy link
Copy Markdown
Owner

Part of making the out-of-process plugin actually load in the Amateur Radio Suite.

macOS will not register/load an ExtensionKit .appex unless it is sandboxed (and properly signed). This adds the missing entitlements to the LP-100A extension:

  • Xcode/Extension/LP100A.entitlementscom.apple.security.app-sandbox + com.apple.security.network.client (LP-100A connects out to the LP-100A WebSocket server on the LAN).
  • Wired via CODE_SIGN_ENTITLEMENTS + ENABLE_HARDENED_RUNTIME (needed for notarization) in project.yml.

This is the LP-100A side of Proof 2 in the suite's SIGNING-RUNBOOK.md: embed this .appex in LP-100A-App.app, sign + notarize, and the extension registers for the suite host to discover and load.

No effect on the standalone app or the plain swift build.appex/Xcode-target only.

🤖 Generated with Claude Code

ExtensionKit extensions must be sandboxed for macOS to register and load them
(an unsandboxed/ad-hoc .appex is never discovered). Add Xcode/Extension/
LP100A.entitlements (com.apple.security.app-sandbox + network.client for the
LAN WebSocket connection) and wire CODE_SIGN_ENTITLEMENTS + ENABLE_HARDENED_RUNTIME
(required for notarization) in project.yml.

Used by the Amateur Radio Suite signing runbook (Proof 2): embed this .appex in
LP-100A-App.app, sign + notarize, and macOS registers it for the suite host to load.
No effect on the standalone app / plain swift build.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@VU3ESV
VU3ESV merged commit fc3c526 into main Jun 3, 2026
1 check passed
@VU3ESV
VU3ESV deleted the feat/extension-entitlements branch June 4, 2026 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant