and there is no error in the process of notarization. the exported app was placed in /Application, and the app still doesn't work. Indeed, " Signature check failed" appears in xcode running mode, and the tunnel extension works well. so wired
Your workflow here does not add up. You mention that you are Notarizing your app and running it from /Applications and the you mention "Xcode running mode," how are you testing your app?
Also, what is the actual error that you are receiving other than, "Signature check failed?" Your signature can fail for a variety of different reasons.
If you are running this with SIP disabled, make sure to enable SIP. You are just making life harder on yourself by disabling SIP.
If you are not setting the Sandbox entitlement for both your Network System Extension and your container app, make sure and do that.
Matt Eaton
DTS Engineering, CoreOS
meaton3@apple.com