Repository navigation
Commit 369eccd
fix(phase4): set the default keychain for the macOS runner job
notarytool resolves its credential profile through the session DEFAULT
keychain, but a launchd runner job has no default keychain set, so
notarization failed with "No Keychain password item found for profile" even
though code signing (which uses the search list) succeeded. After the hook's
trust validation passes, set the dedicated account's login keychain as the
default and search keychain and unlock it, on macOS only.
The keychain password is read from a machine-local file owned by the runner
account ($HOME/.config/1helm/mac-keychain-password); it is never committed to
this repository or exported into the job environment. No sudo, no elevation.
Co-Authored-By: Claude <noreply@anthropic.com>1 parent b6c17eb commit 369eccd
1 file changed
Lines changed: 19 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
0 commit comments