Skip to content

[Bug]: Sparkle self-update leaves app bundle with invalid code signature ("Helium can't be opened") #339

Description

@roh777

Version

0.16.2.1

Have you tested that this is not an upstream issue or an issue with your configuration?

  • I have tried reproducing this issue in Chrome and it could not be reproduced there
  • I have tried reproducing this issue in ungoogled-chromium and it could not be reproduced there
  • I have tried reproducing this issue in Helium with a new and empty profile using --user-data-dir command line argument and it could not be reproduced there

Description

Sparkle self-update leaves app bundle with invalid code signature ("Helium can't be opened")

How to Reproduce?

  1. Install Helium on macOS (direct download or brew install --cask helium-browser)
  2. Let Helium self-update via its in-app Sparkle updater
  3. Attempt to relaunch Helium (via Dock or Finder)

Actual behavior

open -a Helium fails with Launchd job spawn failed / RBSRequestErrorDomain Code=5.

codesign --verify --deep --strict Helium.app and spctl -a -vv Helium.app both report "a sealed resource is missing or invalid", isolated to the subcomponent:
Contents/Frameworks/Helium Framework.framework/Versions/Current/Frameworks/Sparkle.framework/Versions/Current/Updater.app

Notably, codesign -dvvv on that Updater.app in isolation shows it is validly signed by "imput LLC (S4Q33XPHB4)" with a proper CodeDirectory - the failure only shows up under --deep --strict on the outer bundle. This suggests the outer app's sealed-resources manifest goes stale relative to the actual on-disk Sparkle payload after an in-place self-update, rather than the inner signature itself being corrupted.

The Dock shortcut also breaks afterward, since its saved bookmark data goes stale once the bundle is replaced/moved.

Workaround: quit Helium, move the broken Helium.app aside, and do a clean reinstall (e.g. brew reinstall --cask helium-browser), then re-verify with codesign --verify --deep --strict. A plain re-download without removing the old bundle first does not reliably fix it.

Environment: macOS 15.7.7 (24G720), arm64 (Apple Silicon). Installed via Homebrew cask helium-browser. Recurred at least 3 separate times across different update cycles on the same machine.

Expected behavior

Helium launches normally after updating.

Additional context

Diagnostics captured from a broken 0.16.2.1 install before reinstalling:

$ codesign --verify --deep --strict Helium.app
Helium.app: a sealed resource is missing or invalid
In subcomponent: Helium.app/Contents/Frameworks/Helium Framework.framework/Versions/Current/Frameworks/Sparkle.framework/Versions/Current/Updater.app

$ spctl -a -vv Helium.app
Helium.app: a sealed resource is missing or invalid

$ codesign -dvvv Helium.app
Executable=Helium.app/Contents/MacOS/Helium
Identifier=net.imput.helium
Format=app bundle with Mach-O thin (arm64)
CodeDirectory v=20500 size=476 flags=0x12a00(kill,restrict,library-validation,runtime) hashes=4+7 location=embedded
CandidateCDHash sha256=b84f0a174e5e5d8bafdfb6c67c38700a97c0790b
Authority=Developer ID Application: imput LLC (S4Q33XPHB4)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=29 Aug 2026 at 2:52:12 PM
Notarization Ticket=stapled
TeamIdentifier=S4Q33XPHB4
Runtime Version=26.0.0
Sealed Resources version=2 rules=13 files=62

$ codesign -dvvv "Helium Framework.framework/Versions/Current/Frameworks/Sparkle.framework/Versions/Current/Updater.app"
Executable=.../Sparkle.framework/Versions/B/Updater.app/Contents/MacOS/Updater
Identifier=org.sparkle-project.Sparkle.Updater
Format=app bundle with Mach-O universal (x86_64 arm64)
CodeDirectory v=20500 size=495 flags=0x12a00(kill,restrict,library-validation,runtime) hashes=8+3 location=embedded
CandidateCDHash sha256=fa52e6cbc8909104140654ee4d27fe9adfba0b71
Authority=Developer ID Application: imput LLC (S4Q33XPHB4)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=29 Aug 2026 at 2:52:09 PM
TeamIdentifier=S4Q33XPHB4
Runtime Version=26.0.0
Sealed Resources version=2 rules=13 files=1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingmore infoFurther information is requested

    Type

    No type

    Fields

    Effort

    M

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions