mirror of
https://github.com/wu736139669/hapi.git
synced 2026-10-07 19:06:11 +00:00
The previous revision told people to run 'security unlock-keychain' first, which cannot work from launchd's Background domain: the command cannot prompt for the passphrase there, and an unlocked keychain alone does not let a background process read the private key. It also guessed the session up front from `launchctl managername`, which flagged legitimate deploys (an SSH session that unlocked first signs fine). Detect nothing in advance: run codesign, and when it fails with errSecInternalComponent / "User interaction is not allowed", print the two remedies that actually work - run the deploy from a Terminal window on this machine, or allow the signing key for all applications in Keychain Access. Verified both paths with the pinned identity (real sign succeeds; a shim that returns errSecInternalComponent prints the guidance and exits 1). Also ignore .opencode/ (OpenCode's per-project scratch dir, ~60MB here).