I am building a cross platform desktop app that uses Electron with a cross platform .NET Core self contained application. That is using Kestrel for the WebServer in order for the NodeJS/Electron application to communicate and manipulate what is needed with certain C# 3rd party libraries.
This application works perfectly fine on a Mac and the NodeJS code will successfully boot up our Kestrel webserver app without issues.
However as soon as the application is packaged to be submitted for the Mac App Store (By code signing it), it will throw an error when trying to boot/run the .NET Core executable/binary for our Kestrel Server
✔️ Mac Electron Application
❌ Mac Electron Application built & signed for Mac App Store submission & gives the following error when it attempts to boot/call the server
server-error-data Error: Command failed: /Users/warrenbuckley/Projects/LogViewer/output/mas-dev/Compact Log Viewer.app/Contents/Resources/LogViewer.Server/bin/dist/osx/LogViewer.Server
Unhandled Exception: System.Net.Sockets.SocketException: Unknown error: -1
at System.Net.Sockets.Socket.UpdateStatusAfterSocketErrorAndThrowException(SocketError error, String callerName)
at System.Net.Sockets.Socket.DoBind(EndPoint endPointSnapshot, SocketAddress socketAddress)
at System.Net.Sockets.Socket.Bind(EndPoint localEP)
at Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets.SocketTransport.BindAsync()
at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.<>c__DisplayClass21_0`1.<<StartAsync>g__OnBind|0>d.MoveNext()
--- End of stack trace from previous location where exception was thrown ---
at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindEndpointAsync(ListenOptions endpoint, AddressBindContext context)
at Microsoft.AspNetCore.Server.Kestrel.Core.ListenOptions.BindAsync(AddressBindContext context)
at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.EndpointsStrategy.BindAsync(AddressBindContext context)
at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindAsync(IServerAddressesFeature addresses, KestrelServerOptions serverOptions, ILogger logger, Func`2 createBinding)
at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken)
at Microsoft.AspNetCore.Hosting.Internal.WebHost.StartAsync(CancellationToken cancellationToken)
at Microsoft.AspNetCore.Hosting.WebHostExtensions.RunAsync(IWebHost host, CancellationToken token, String shutdownMessage)
at Microsoft.AspNetCore.Hosting.WebHostExtensions.RunAsync(IWebHost host, CancellationToken token)
at Microsoft.AspNetCore.Hosting.WebHostExtensions.Run(IWebHost host)
at LogViewer.Server.Program.Main(String[] args) in /Users/warrenbuckley/Projects/LogViewer/LogViewer.Server/Program.cs:line 14
at ChildProcess.exithandler (child_process.js:299:12)
at ChildProcess.emit (events.js:187:15)
at maybeClose (internal/child_process.js:962:16)
at Socket.stream.socket.on (internal/child_process.js:381:11)
at Socket.emit (events.js:182:13)
at Pipe._handle.close (net.js:606:12)
My code for configuring the Kestrel webserver looks like so
https://github.com/warrenbuckley/Compact-Log-Format-Viewer/blob/master/LogViewer.Server/Program.cs#L17-L41
Looks like the socket is failing to bind on the port. I suppose your app is running sandboxed when submitted for the app store, I am curious if this requires the "com.apple.security.network.server" entitlement. The entitlement doesn't clearly say if this is required for loopback connections or not, but it's something you could try.
The gist would be in this file to add
<key>com.apple.security.network.server</key>
<true/>
Or use Xcode's entitlement GUI.
Thanks @vcsjones I will give that a try later today, head in another task right now & report back when I have tried it.
@wfurt, the Unknown error: -1 here is unfortunate... that suggests that the native bind call returned an errno we weren't expecting and couldn't map to a SocketError. It'd be great if we could figure out what that error is and add it to our mapping.
@vcsjones I could kiss you right about now. I spent days trying to get to the bottom of this. Adding that extra entitlement looks like it may have solved it. So will try a new submission to Apple & see if this works, but the MAS-DEV output test build seems happy now :)

@stephentoub I would love to be of help in anyway I can with this, but my knowledge of Mac stuff is limited, so if you need or want something from me to help with this I may need a bit of hand holding.
@stephentoub @wfurt it might already be fixed by dotnet/corefx#35133 for 3.0.
Its been re-submitted to the Mac App Store - hopefully this time it all just works & is fine.
Will keep you updated...
I confirmed that bind is setting errno to EPERM when it cannot bind due to sandbox permissions, so I believe the "Unknown error" issue has been addressed for 3.0.
Excellent. Thanks for confirming.
Most helpful comment
@vcsjones I could kiss you right about now. I spent days trying to get to the bottom of this. Adding that extra entitlement looks like it may have solved it. So will try a new submission to Apple & see if this works, but the MAS-DEV output test build seems happy now :)
@stephentoub I would love to be of help in anyway I can with this, but my knowledge of Mac stuff is limited, so if you need or want something from me to help with this I may need a bit of hand holding.