From 8336db7b299d439f1e86b3e20e0edfb5eaa560cb Mon Sep 17 00:00:00 2001 From: Dan Crosby Date: Wed, 28 Jan 2026 23:08:32 -0800 Subject: [PATCH] Fix Mac codesign ambiguous identity error (#5688) Add --keychain flag to all codesign commands to explicitly specify which keychain to use. This fixes the "ambiguous" error when the same signing identity exists in multiple keychains (build keychain and login keychain). Co-authored-by: Claude Opus 4.5 --- scripts/codesign_mac_app.sh | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/scripts/codesign_mac_app.sh b/scripts/codesign_mac_app.sh index 4abebac16e..9a2483d51d 100755 --- a/scripts/codesign_mac_app.sh +++ b/scripts/codesign_mac_app.sh @@ -6,7 +6,7 @@ # Environment variables: # SIGNING_IDENTITY - The signing identity (default: "Developer ID Application") # KEYCHAIN_PASSWORD - Password to unlock the build keychain (optional) -# KEYCHAIN_NAME - Name of the keychain to unlock (default: "build.keychain") +# KEYCHAIN_NAME - Name of the keychain to unlock and use for signing (default: "build.keychain") set -euxo pipefail @@ -26,11 +26,13 @@ if [ -n "${KEYCHAIN_PASSWORD:-}" ]; then fi echo "=== Signing nested components first ===" +echo "Using keychain: $KEYCHAIN_NAME" # Sign all dylibs find "$APP_PATH" -name "*.dylib" -print0 | while IFS= read -r -d '' item; do echo "Signing dylib: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" done @@ -38,6 +40,7 @@ done find "$APP_PATH" -name "*.bundle" -print0 | while IFS= read -r -d '' item; do echo "Signing bundle: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" done @@ -49,6 +52,7 @@ find "$APP_PATH" -name "*.xpc" -print0 | while IFS= read -r -d '' item; do fi echo "Signing XPC service: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" done @@ -60,6 +64,7 @@ find "$APP_PATH" -path "*/Frameworks/*.app" -print0 | while IFS= read -r -d '' i fi echo "Signing nested app: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" done @@ -71,6 +76,7 @@ find "$APP_PATH" -path "*/Frameworks/*/Versions/*/Autoupdate" -type f -print0 | fi echo "Signing executable: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" done @@ -80,10 +86,12 @@ find "$APP_PATH" -name "*.framework" -print0 | while IFS= read -r -d '' item; do if [[ "$item" == *"Sparkle.framework" ]]; then echo "Signing Sparkle framework with --deep: $item" codesign --deep --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" else echo "Signing framework: $item" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$item" fi done @@ -93,10 +101,12 @@ echo "=== Signing main app bundle ===" if [ -n "$ENTITLEMENTS_PATH" ] && [ -f "$ENTITLEMENTS_PATH" ]; then echo "Using entitlements: $ENTITLEMENTS_PATH" codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --entitlements "$ENTITLEMENTS_PATH" \ --sign "$SIGNING_IDENTITY" "$APP_PATH" else codesign --force --verify --verbose --timestamp --options runtime \ + --keychain "$KEYCHAIN_NAME" \ --sign "$SIGNING_IDENTITY" "$APP_PATH" fi