* fix(macos): let AI setup proceed when the login keychain is unavailable A missing/locked login keychain made GatewayActivationBindingKeyStore unable to mint the activation binding key, and onboarding refused every candidate and manual-key activation with 'Secure storage is unavailable'. The fingerprint only protects the crash/relaunch resume receipt, so degrade instead of refusing: write an ownerless pending record (still matched exactly, never as a wildcard), keep the full activation-ambiguity window, and skip only restart reconciliation, which needs fingerprint proof by design. A relaunch then repeats activation rather than trusting the receipt. Reported by Peter Steinberger. * fix(macos): render proper provider brand icons in onboarding AI setup Nearly every provider icon URL the gateway sends is a simpleicons.org SVG, which AsyncImage cannot decode, so the Connect your AI page fell back to generic symbols for every tool and provider; the two GitHub avatar PNGs that did render clashed as full-color rasters. Bundle nine monochrome template marks (Simple Icons CC0; xAI from LobeHub icons, MIT) and resolve them local-first by brand id/kind, including composed choice ids like xai-oauth. Remote icons now load via NSImage(data:), which decodes SVG, with vector payloads tinted as templates so plugin-supplied icons blend too. Every glyph sits in a uniform rounded well; install cards show host-only links, hover states, and a softer translucent surface shared by all setup sections instead of controlBackgroundColor. Requested by Peter Steinberger. * fix(macos): use failable UTF-8 decode in icon vector sniffing (swiftlint) * fix(macos): address ClawSweeper review of onboarding icon/keychain changes - Refuse relaunch handoff from ownerless (keychain-unavailable) completed receipts at the reconciliation trust boundary; such receipts can belong to replaced credentials, so setup repeats a fresh activation instead. - Decode and pass the canonical brandId the gateway sends for candidates, auth options, and manual providers so bundled marks resolve for opaque choice ids. - Scan the bounded XML prolog (comments, declarations, doctype) when sniffing remote SVG payloads; comment-prefixed vectors now tint as templates. * refactor(macos): move setup error enum to support file (swiftlint file length) * chore(i18n): refresh native source inventory * fix(macos): give keychain-unavailable activations attempt-specific unbound leases A nil owner made concurrent unbound attempts indistinguishable: a stale attempt's delayed response could complete or clear a newer attempt's record. Unbound attempts now mint a random per-attempt lease id with a sentinel fingerprint — live matching stays attempt-exact, restart reconciliation's fingerprint guard rejects them, and relaunch verification refuses unbound receipts before any handoff. * chore(macos): ship third-party artwork notices with provider icons Simple Icons (CC0) attribution and the LobeHub Icons MIT license text for the xAI mark now travel inside the bundled ProviderIcons directory. * fix(ci): refresh plugin-sdk API manifest for private-type hashing #120975 changed the baseline generator to hash private types but landed without regenerating the manifest; the check-plugin-sdk-api-baseline lane was gated off on that PR and first failed here. Regenerated via pnpm plugin-sdk:api:gen with no SDK surface change in this branch.
OpenClaw macOS app (dev + signing)
Quick dev run
# from repo root
scripts/restart-mac.sh
Options:
scripts/restart-mac.sh --no-sign # fastest dev; ad-hoc signing (TCC permissions do not stick)
scripts/restart-mac.sh --sign # force code signing (requires cert)
scripts/restart-mac.sh --background-only # keep services running without automatic windows
--background-only suppresses first-run onboarding, update and CLI prompts, and
the --chat/--dashboard auto-open helpers. Pairing, control-channel, and Mac
node services still start. Combine it with --attach-only when an external
process owns the local Gateway.
Packaging flow
scripts/package-mac-app.sh
Creates dist/OpenClaw.app and signs it via scripts/codesign-mac-app.sh.
Signing behavior
Auto-selects identity (first match):
- Developer ID Application
- Apple Distribution
- Apple Development
- first available identity
If none found:
- errors by default
- set
ALLOW_ADHOC_SIGNING=1orSIGN_IDENTITY="-"to ad-hoc sign
Team ID audit (Sparkle mismatch guard)
After signing, we read the app bundle Team ID and compare every Mach-O inside the app. If any embedded binary has a different Team ID, signing fails.
Skip the audit:
SKIP_TEAM_ID_CHECK=1 scripts/package-mac-app.sh
Library validation workaround (dev only)
If Sparkle Team ID mismatch blocks loading (common with Apple Development certs), opt in:
DISABLE_LIBRARY_VALIDATION=1 scripts/package-mac-app.sh
This adds com.apple.security.cs.disable-library-validation to app entitlements.
Use for local dev only; keep off for release builds.
Useful env flags
SIGN_IDENTITY="Apple Development: Your Name (TEAMID)"ALLOW_ADHOC_SIGNING=1(ad-hoc, TCC permissions do not persist)CODESIGN_TIMESTAMP=off(offline debug)DISABLE_LIBRARY_VALIDATION=1(dev-only Sparkle workaround)SKIP_TEAM_ID_CHECK=1(bypass audit)