macOS signing
기준일: 2026-07-26
공식 기준: macOS signing
macOS signing 문서는 OpenClaw 공식 문서(platforms/mac/signing)를 한국어로 정리한 가이드입니다. Signing steps for macOS debug builds generated by packaging scripts 명령·설정 키·코드 예시는 공식 문서를 그대로 보존하며, 해석과 절차 안내는 한국어로 제공합니다. 최종 동작은 설치된 CLI 버전과 공식 원문을 확인하세요.
핵심 요약
Signing steps for macOS debug builds generated by packaging scripts
한국어 가이드 범위: platforms/mac/signing 경로의 설정·명령·제약·예시를 학습용으로 재구성합니다.
문서 구성
공식 문서의 주요 섹션은 다음과 같습니다.
- mac signing (debug builds)
- 사용법
- from repo root
- Ad-hoc signing note
- Build metadata for About
- 관련 문서
상세 내용
mac signing (debug builds)
scripts/package-mac-app.sh builds and packages the app to a fixed path (dist/OpenClaw.app), then calls scripts/codesign-mac-app.sh to sign it. TCC permissions are tied to the bundle ID and code signature; keeping both stable (and the app at a fixed path) across rebuilds keeps macOS from forgetting TCC grants (notifications, accessibility, screen recording, mic, speech).
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
주요 항목:
- Debug bundle identifier defaults to
ai.openclaw.mac.debug(override withBUNDLE_ID=...). - Node:
>=22.22.3 <23,>=24.15.0 <25, or>=25.9.0(repopackage.jsonengines). The packager also builds the Control UI (pnpm ui:build). - Requires a real signing identity by default; the codesign script exits with an error if none is found and
ALLOW_ADHOC_SIGNINGis not set. Ad-hoc signing (SIGN_IDENTITY="-") is explicit opt-in and does not persist TCC permissions across rebuilds. See macOS permissions. - Reads
SIGN_IDENTITYfrom the environment (e.g.export SIGN_IDENTITY="Apple Development: Your Name (TEAMID)", or a Developer ID Application cert). Without it,codesign-mac-app.shauto-selects an identity in this order: Developer ID Application, Apple Distribution, Apple Development, then the first valid codesigning identity found. CODESIGN_TIMESTAMP=auto(default) enables trusted timestamps only for Developer ID Application signatures. Seton/offto force either way.- Stamps Info.plist with
OpenClawBuildTimestamp(ISO8601 UTC) andOpenClawGitCommit(short hash,unknownif unavailable) so the About tab can show build, git, and debug/release channel. - Runs a Team ID audit after signing and fails if any Mach-O inside the bundle has a different Team ID. Set
SKIP_TEAM_ID_CHECK=1to bypass.
사용법
### from repo root
scripts/package-mac-app.sh # auto-selects identity; errors if none found SIGN_IDENTITY="Developer ID Application: Your Name" scripts/package-mac-app.sh # real cert ALLOW_ADHOC_SIGNING=1 scripts/package-mac-app.sh # ad-hoc (permissions will not stick) SIGN_IDENTITY="-" scripts/package-mac-app.sh # explicit ad-hoc (same caveat) DISABLE_LIBRARY_VALIDATION=1 scripts/package-mac-app.sh # dev-only Sparkle Team ID mismatch workaround ```
> 위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과 `--help`를 확인하세요.
### Ad-hoc signing note
`SIGN_IDENTITY="-"` disables the Hardened Runtime (`--options runtime`) to prevent crashes when the app loads embedded frameworks (like Sparkle) that do not share the same Team ID. Ad-hoc signatures also break TCC permission persistence; see [macOS permissions](/platforms/mac/permissions) for recovery steps.
> 위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과 `--help`를 확인하세요.
### Build metadata for About
The About tab reads `OpenClawBuildTimestamp` and `OpenClawGitCommit` from Info.plist to show version, build date, git commit, and whether the build is DEBUG (via `#if DEBUG`). Re-run the packager after code changes to refresh these values.
> 위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과 `--help`를 확인하세요.
### 관련 문서
주요 항목:
- macOS app
- macOS permissions
## 실습 체크리스트
1. 공식 문서와 로컬 버전을 대조합니다: `https://docs.openclaw.ai/platforms/mac/signing`
2. 관련 CLI는 `openclaw --help` 및 하위 명령 `--help`로 옵션을 확인합니다.
3. 설정 변경 시 `openclaw config` / `openclaw doctor`로 유효성을 검사합니다.
4. Gateway·채널·플러그인 변경 후에는 필요 시 Gateway를 재시작합니다.
## 자주 쓰는 명령·설정 예시
```bash
# from repo root
scripts/package-mac-app.sh # auto-selects identity; errors if none found
SIGN_IDENTITY="Developer ID Application: Your Name" scripts/package-mac-app.sh # real cert
ALLOW_ADHOC_SIGNING=1 scripts/package-mac-app.sh # ad-hoc (permissions will not stick)
SIGN_IDENTITY="-" scripts/package-mac-app.sh # explicit ad-hoc (same caveat)
DISABLE_LIBRARY_VALIDATION=1 scripts/package-mac-app.sh # dev-only Sparkle Team ID mismatch workaround
관련 링크
이 가이드는 공식 문서를 한국어 학습용으로 재구성한 것입니다. 옵션 기본값·플래그 이름은 설치 버전에 따라 달라질 수 있습니다.