Fix Mac codesign ambiguous identity error (#5688)

Add --keychain flag to all codesign commands to explicitly specify which
keychain to use. This fixes the "ambiguous" error when the same signing
identity exists in multiple keychains (build keychain and login keychain).

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
2026-01-28 23:08:32 -08:00
committed by GitHub
co-authored by Claude Opus 4.5
parent 77791da7c7
commit 8336db7b29
+11 -1
View File
@@ -6,7 +6,7 @@
# Environment variables:
# SIGNING_IDENTITY - The signing identity (default: "Developer ID Application")
# KEYCHAIN_PASSWORD - Password to unlock the build keychain (optional)
# KEYCHAIN_NAME - Name of the keychain to unlock (default: "build.keychain")
# KEYCHAIN_NAME - Name of the keychain to unlock and use for signing (default: "build.keychain")
set -euxo pipefail
@@ -26,11 +26,13 @@ if [ -n "${KEYCHAIN_PASSWORD:-}" ]; then
fi
echo "=== Signing nested components first ==="
echo "Using keychain: $KEYCHAIN_NAME"
# Sign all dylibs
find "$APP_PATH" -name "*.dylib" -print0 | while IFS= read -r -d '' item; do
echo "Signing dylib: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
done
@@ -38,6 +40,7 @@ done
find "$APP_PATH" -name "*.bundle" -print0 | while IFS= read -r -d '' item; do
echo "Signing bundle: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
done
@@ -49,6 +52,7 @@ find "$APP_PATH" -name "*.xpc" -print0 | while IFS= read -r -d '' item; do
fi
echo "Signing XPC service: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
done
@@ -60,6 +64,7 @@ find "$APP_PATH" -path "*/Frameworks/*.app" -print0 | while IFS= read -r -d '' i
fi
echo "Signing nested app: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
done
@@ -71,6 +76,7 @@ find "$APP_PATH" -path "*/Frameworks/*/Versions/*/Autoupdate" -type f -print0 |
fi
echo "Signing executable: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
done
@@ -80,10 +86,12 @@ find "$APP_PATH" -name "*.framework" -print0 | while IFS= read -r -d '' item; do
if [[ "$item" == *"Sparkle.framework" ]]; then
echo "Signing Sparkle framework with --deep: $item"
codesign --deep --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
else
echo "Signing framework: $item"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$item"
fi
done
@@ -93,10 +101,12 @@ echo "=== Signing main app bundle ==="
if [ -n "$ENTITLEMENTS_PATH" ] && [ -f "$ENTITLEMENTS_PATH" ]; then
echo "Using entitlements: $ENTITLEMENTS_PATH"
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--entitlements "$ENTITLEMENTS_PATH" \
--sign "$SIGNING_IDENTITY" "$APP_PATH"
else
codesign --force --verify --verbose --timestamp --options runtime \
--keychain "$KEYCHAIN_NAME" \
--sign "$SIGNING_IDENTITY" "$APP_PATH"
fi