fix(macos): let terminal programs ask for microphone, camera and Apple Events (fixes #1483) - #1487
Merged
Merged
Conversation
Add the audio-input entitlement and microphone usage description for recording tools launched from the integrated terminal. Document user consent, virtual-input routing, and short-recording verification. (cherry picked from commit 42c210f)
…e Events macOS attributes programs run in VMark's integrated terminal to VMark, so under the Hardened Runtime they can only ask for a protected resource the app declares. VMark declared none: FFmpeg recorded all-zero audio with no prompt (#1483), and the camera and osascript failed the same way. - src-tauri/app-entitlements.plist: the app bundle's own entitlements, adding audio-input, camera and automation.apple-events to the existing runtime exceptions. Info.plist gains the three usage descriptions, translated for the ten app locales in macos-l10n/<lang>.lproj/InfoPlist.strings. - The Tauri bundler re-signs every externalBin with the app's entitlements but copies bundle.macOS.files unsigned. The macOS release therefore places the MCP sidecar through tauri.macos-release.conf.json, keeping the signature release.yml gives it with sidecar-entitlements.plist (JIT exceptions only). The layout is read from the checked-out tree, so a manual release of an older tag still builds as before. - scripts/verify-macos-bundle-entitlements.sh checks the signed .app: in release.yml before publishing, and in release-smoke.yml on the published DMG from v0.9.89. - scripts/check-macos-tcc-entitlements.test.mjs pins the plists, the translations and the release wiring. Builds on the entitlement change from #1485.
…n macOS Replaces the audio-only section from #1485 with one covering all three resources, where to change the permission, and what a silent denial looks like, in English and the nine translated guides.
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Programs run in VMark's integrated terminal couldn't use the microphone, the camera or Apple Events on macOS. macOS attributes them to VMark, and under the Hardened Runtime VMark declared none of these, so every request was denied without a prompt. FFmpeg recorded all-zero audio (#1483), and
osascriptand camera capture failed the same way.This lands @mao13811364454's fix from #1485 (their commit is cherry-picked with authorship kept) and extends it:
externalBinwith the app's entitlements (crates/tauri-bundlermacos/app.rs,sign.rs, CLI 2.11.5) but copiesbundle.macOS.filesunsigned and signs the app without--deep. So the macOS release places the sidecar throughsrc-tauri/tauri.macos-release.conf.json, keeping the signaturerelease.ymlalready gives it withsidecar-entitlements.plist(JIT exceptions only). Dev builds, Windows and Linux are unchanged.scripts/verify-macos-bundle-entitlements.shruns inrelease.ymlafter the build (it blocks publishing) and inrelease-smoke.ymlon the published DMG from v0.9.89.macos-l10n/<lang>.lproj/InfoPlist.strings).Fixes #1483
Closes #1485
Validation
Guard test:
scripts/check-macos-tcc-entitlements.test.mjspasses 22/22. It failed first (4/5, then 11/22) before each change, and mutations are caught: commenting out the verifier, or dropping the overlay from the build args.Release-style local build: run with the exact release args, from the repo root, ad-hoc signed (
--config src-tauri/tauri.macos-release.conf.json --target aarch64-apple-darwin).Assets.caris kept, and all 10.lprojfolders are present.codesign --verify --deep --strictpasses, and the bundled sidecar's--health-checkpasses.Verify script, checked both ways:
Layout step: all three cases were run using the shell code taken from the workflow.
Gates:
pnpm check:predeltapassed all 46, andpnpm check:allexited 0 (41,462 app tests, servers, build and size limits). The website build andplutil -linton every plist and.stringsfile pass.Codex review: round 1 had one Medium and three Low findings, all fixed. Round 2 returned NO FINDINGS.
Not verified here