Skip to content

GitHub Copilot.app is missing NSLocalNetworkUsageDescription — MCP servers and shell cannot reach local-subnet hosts on macOS #5072

Description

@MrT-devops

Summary

On macOS 26, every process launched by GitHub Copilot.app (Copilot CLI, stdio MCP servers, agent shell commands) is silently denied access to hosts on the local subnet. Connections fail immediately with no route to host / Couldn't connect to server.

The app does not declare NSLocalNetworkUsageDescription in its Info.plist. As a result, macOS never shows the Local Network permission prompt, and the app never appears under System Settings → Privacy & Security → Local Network, so the user has no way to grant access.

Environment

  • GitHub Copilot.app 1.1.27 (com.github.githubapp)
  • Copilot CLI 1.0.93-1 (~/Library/Caches/github-copilot-sdk/cli/1.0.93-1/copilot --server --stdio)
  • macOS 26.5.2
  • Machine on a corporate LAN (192.168.80.0/20); target host on the same subnet (192.168.90.13)

Steps to reproduce

  1. Connect the Mac to a LAN that contains an internal HTTPS server on the same subnet.
  2. Configure a stdio MCP server (or simply use the agent's shell tool) that requests that server.
  3. Make the request from a Copilot session in the app.

Expected

macOS prompts once for Local Network access, or the app shows up in the Local Network settings list so access can be granted, and the request succeeds.

Actual

  • MCP server request: dial tcp 192.168.90.13:443: connect: no route to host
  • Agent shell: curl: (7) Failed to connect to live.topix.de port 443 after 2 ms: Couldn't connect to server
  • The host is up: arp -n 192.168.90.13 resolves its MAC address.
  • The same request works from Terminal.app, and works from the Copilot app when the connection goes through a VPN tunnel (non-local route).
  • Restarting the app and rebooting the Mac do not help.
  • plutil -p "/Applications/GitHub Copilot.app/Contents/Info.plist" shows no NSLocalNetworkUsageDescription key.
  • The unified log shows LocalNetwork: found bundle id com.github.githubapp by PID for each attempt, and no prompt is ever shown.

Suggested fix

Add NSLocalNetworkUsageDescription (and NSBonjourServices if needed) to the app's Info.plist, so that macOS can ask for, and remember, Local Network access for the app and the processes it launches.

Workaround

Run the Copilot CLI from Terminal.app instead of the desktop app while on the local network.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions