Set up, maintain, and debug the imsg-rpc Unix socket daemon that gives the gateway iMessage access via JSON-RPC. Covers FDA setup, code signing, launchd service, and the imsg source repo.
67
81%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Manages the com.joel.imsg-rpc launchd service that bridges the gateway daemon to iMessage via a Unix socket.
gateway daemon (bun, no FDA)
↕ JSON-RPC over /tmp/imsg.sock
imsg-rpc (com.joel.imsg-rpc launchd agent, has FDA)
↕ SQLite reads
~/Library/Messages/chat.db~/Code/steipete/imsg (we own it — modify freely)~/Code/steipete/imsg/bin/imsg/Applications/imsg-rpc.app/Contents/MacOS/imsg/tmp/imsg.sock~/Library/LaunchAgents/com.joel.imsg-rpc.plist/tmp/joelclaw/imsg-rpc.{log,err}packages/gateway/src/channels/imessage.tslaunchctl print gui/$(id -u)/com.joel.imsg-rpc | rg "state =|pid =|runs =|last exit code"
lsof -p "$(launchctl print gui/$(id -u)/com.joel.imsg-rpc | awk '/pid =/{print $3; exit}')" | rg "imsg.sock|chat.db"
lsof -nP -U | rg "imsg.sock|com.joel.gateway|/tmp/imsg.sock" # gateway socket peer
tail -10 /tmp/joelclaw/gateway.log | rg imessageHealthy state: PID present, exit code 0, gateway shows watch.subscribe OK.
launchctl unload ~/Library/LaunchAgents/com.joel.imsg-rpc.plist
launchctl load ~/Library/LaunchAgents/com.joel.imsg-rpc.plistAlways use build-local.sh — NOT make build — so signing stays stable and /Applications/imsg-rpc.app stays in sync with source builds:
cd ~/Code/steipete/imsg && ./build-local.shbuild-local.sh now:
bin/imsgimsg Local Signing/Applications/imsg-rpc.app via scripts/install-rpc-app.shThe imsg binary needs Full Disk Access. macOS requires a verifiable code signature to accept it.
Inspect available code-signing identities without exporting keys. Reuse the service’s established identity when valid. If a new identity is required, use the approved Keychain procedure; private keys must stay in Keychain or a task-owned restrictive temporary directory with cleanup. Do not use shared fixed temporary filenames or a hardcoded export password. Verify identity and trust before signing.
cd ~/Code/steipete/imsg && ./build-local.shopen "x-apple.systempreferences:com.apple.preference.security?Privacy_AllFiles"/Applications/imsg-rpc.app, Enterlaunchctl load ~/Library/LaunchAgents/com.joel.imsg-rpc.plistVerify: tail -f /tmp/joelclaw/gateway.log | grep imessage — should show watch.subscribe OK.
permissionDenied in imsg-rpc.logFDA is missing or csreq mismatch. Check:
sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db \
"SELECT client, auth_value FROM access WHERE client LIKE '%imsg%';"
# auth_value 2 = allowed, 0 = denied
/usr/bin/log show --last 10m --style compact \
--predicate 'process == "tccd" && (eventMessage CONTAINS "com.steipete.imsg" || eventMessage CONTAINS "kTCCServiceSystemPolicyAllFiles")' \
| tail -80If denied (0): go to System Settings → Full Disk Access → toggle imsg ON.
If missing: redo FDA setup step 3.
If tccd shows AUTHREQ_RESULT ... authValue=2 for /Applications/imsg-rpc.app/Contents/MacOS/imsg, FDA is granted.
imsg-rpc crashed after accepting. Check /tmp/joelclaw/imsg-rpc.err. Restart service.
connect ENOENT /tmp/imsg.sock but launchd says runningThe daemon process can stay alive while the Unix socket path is unlinked. Gateway cannot connect until the socket path is recreated.
launchctl kickstart -k gui/$(id -u)/com.joel.imsg-rpc
ls -l /tmp/imsg.sockGateway now attempts this heal automatically on repeated ENOENT, but manual kickstart is the fastest recovery during incidents.
You likely rebuilt without refreshing the app bundle. Re-run:
cd ~/Code/steipete/imsg && ./build-local.shLikely FDA denial. Run from terminal to test:
/Applications/imsg-rpc.app/Contents/MacOS/imsg chats --limit 1If that works but launchd still fails → FDA entry is for wrong path or wrong signature.
The gateway uses these methods over /tmp/imsg.sock:
// Subscribe to incoming messages
{"jsonrpc":"2.0","method":"watch.subscribe","params":{"participants":["handle"]},"id":1}
// Send a message
{"jsonrpc":"2.0","method":"send","params":{"to":"handle","text":"..."},"id":2}
// Inbound notification format
{"jsonrpc":"2.0","method":"message","params":{"subscription":1,"message":{...}}}| Path | Purpose |
|---|---|
~/Code/steipete/imsg/ | imsg source (we own) |
~/Code/steipete/imsg/bin/imsg | built binary |
/Applications/imsg-rpc.app | FDA target app bundle for launchd process |
~/Code/steipete/imsg/build-local.sh | build + sign + app sync |
~/Code/steipete/imsg/scripts/install-rpc-app.sh | creates/signs /Applications/imsg-rpc.app |
~/Library/LaunchAgents/com.joel.imsg-rpc.plist | launchd service (not in git) |
packages/gateway/src/channels/imessage.ts | gateway socket client |
apps/web/content/adrs/0121-imsg-rpc-socket-daemon.md | ADR |
7094ced
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.