Skip to content

Fix macOS signing keychain lookup; prepare v0.8.12 - #192

Merged
qwrobins merged 1 commit into
mainfrom
qwrobins/fix-macos-signing-keychain
Sep 5, 2026
Merged

qwrobins merged 1 commit into
mainfrom
qwrobins/fix-macos-signing-keychain

Conversation

@qwrobins

@qwrobins qwrobins commented Sep 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Fix the real macOS signing failure from release run 33933802313: the certificate imports and is found by security, but codesign cannot locate its private key when the temporary keychain is absent from the user search list.
  • Temporarily prepend the keychain to the search list, preserve paths with spaces, and restore the original list on success/failure. Keep the default keychain unchanged and retain all signing/notarization gates.
  • Add regression coverage for lookup and restoration, including empty lists; prepare v0.8.12 without moving the existing v0.8.11 tag. No v0.8.11 assets were published.

Validation

  • macOS signing script regression tests
  • Typecheck, Bash syntax, generated-artifact drift check
  • Actual macOS signing will be revalidated by the gated release workflow.

Greptile Summary

This PR repairs macOS release signing by temporarily prepending the signing keychain to the user search list and restoring the original list during cleanup.

  • Preserves keychain paths containing spaces and supports originally empty search lists.
  • Adds regression coverage for lookup and restoration across successful and failed signing flows.
  • Advances package and installation documentation to v0.8.12 while retaining the prior changelog history.

Confidence Score: 5/5

The PR appears safe to merge, with the signing lookup fix, cleanup behavior, regression coverage, and release version contract aligned.

No concrete correctness, security, release-contract, or repository-rule failures remain after reviewing the changed signing flow and its supported GitHub-hosted runner environment.

Important Files Changed

Filename Overview
scripts/sign-macos-release.sh Snapshots and temporarily extends the user keychain search list, then restores it through the existing cleanup trap.
tests/release/macos-signing.test.ts Adds regression coverage for signing-key lookup and exact restoration of populated and empty search lists.
package.json Advances the package version to 0.8.12 consistently with release automation.
CHANGELOG.md Documents the macOS signing fix and the blocked, unpublished v0.8.11 release.
README.md Updates the pinned installation example to v0.8.12.
docs/macos-signing.md Documents temporary search-list mutation, restoration, and unchanged default-keychain behavior.

Sequence Diagram

sequenceDiagram
  participant Script as Signing script
  participant Security as macOS security
  participant Codesign as codesign
  Script->>Security: Read user keychain search list
  Script->>Security: Create and unlock temporary keychain
  Script->>Security: Prepend temporary keychain to search list
  Script->>Security: Import certificate and private key
  Script->>Codesign: Sign using resolved fingerprint and keychain
  Codesign-->>Script: Signed binary
  Script->>Security: Restore original search list
  Script->>Security: Delete temporary keychain
Loading

Reviews (1): Last reviewed commit: "fix(release): expose signing keychain to..." | Re-trigger Greptile

Context used:

@qwrobins
qwrobins merged commit d25158d into main Sep 5, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant