You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

fastlane多Target部署提示描述文件不含entitlements报错如何修复

多Target iOS应用fastlane归档签名报错修复

问题现象

应用包含主应用、Siri扩展、推送拦截扩展、小组件多个Target,使用fastlane match做证书管理,自定义lane执行构建,流程可正常运行到archive阶段,抛出如下签名错误:

Provisioning profile "match AdHoc com.company.app.Widgets" doesn't include the aps-environment, com.apple.developer.applesignin, com.apple.developer.associated-domains, and com.apple.developer.siri entitlements and doesn't match the entitlements file's value for the application-identifier entitlement.

实际小组件的WidgetsExtension.entitlements仅配置了App Groups权限,未包含报错提及的推送、苹果登录、关联域名、Siri权限:

<dict>
    <key>com.apple.security.application-groups</key>
    <array>
        <string>group.com.company.app</string>
    </array>
</dict>
</plist>

登录Apple开发者后台核对,match生成的小组件对应描述文件权限,和之前手动生成可正常工作的描述文件权限完全一致。报错表现为系统强制要求小组件持有主应用的全部专属权限。
原有fastlane构建代码如下:

lane :build do |options|
    match(
      app_identifier: [
         ENV['IOS_APP_ID'], 
         ENV['SIRI_BUNDLE_ID'], 
         ENV['PUSH_INTERCEPTOR_BUNDLE_ID'], 
         ENV['WIDGETS_BUNDLE_ID']
      ],
      shallow_clone: true,
      clone_branch_directly: true,
      readonly: true
    )

    ios_targets.each do |id, meta|
      profile_env_name = "sigh_#{id}_#{ENV['MATCH_TYPE']}_profile-name"
      profile_path_env_name = "sigh_#{id}_#{ENV['MATCH_TYPE']}_profile-path"
      install_provisioning_profile(
        path: ENV[profile_path_env_name]
      )
      update_project_provisioning(
        xcodeproj: xcodeproj,
        profile: ENV[profile_path_env_name], 
        target_filter: meta[:name],
        build_configuration: ENV['BUILD_CONFIGURATION']
      )
    end

    update_code_signing_settings(
      use_automatic_signing: false,
      path: xcodeproj,
      targets: ios_target_names
    )

    gymOptions = ({
      silent: true,
      export_team_id: ENV['IOS_TEAM_ID'],
      export_options: {
        signingStyle: "manual",
        provisioningProfiles: { 
          ENV['IOS_APP_ID'] => "match AdHoc #{ENV['IOS_APP_ID']}",                                                   
          ENV['SIRI_BUNDLE_ID'] => "match AdHoc #{ENV['SIRI_BUNDLE_ID']}",
          ENV['PUSH_INTERCEPTOR_BUNDLE_ID'] => "match AdHoc #{ENV['PUSH_INTERCEPTOR_BUNDLE_ID']}",
          ENV['WIDGETS_BUNDLE_ID'] => "match AdHoc #{ENV['WIDGETS_BUNDLE_ID']}"
        }
      }
    }).merge(
      File.directory?("../#{xcworkspace}") ?
        {workspace: xcworkspace} :
        {project: xcodeproj}
    )
    gym(gymOptions)
end

排查修复步骤

按优先级从高到低排查:

  • 第一步:校验所有Target的Entitlements路径配置
    打开Xcode选中WidgetsExtension target,进入Build Settings搜索CODE_SIGN_ENTITLEMENTS,确认配置的路径指向小组件自己的entitlements文件,而非主应用的entitlements文件。80%的同类报错都是此处配置错误导致——如果路径指向主应用的entitlements,归档时Xcode会拿主应用的权限列表校验小组件的描述文件,必然提示缺少主应用的专属权限。
  • 第二步:修复update_project_provisioning的匹配规则
    该action的target_filter参数默认是模糊包含匹配,不是精确相等匹配。如果主Target名是其他Target名的子串(比如主Target叫App,小组件叫AppWidgets),给主Target配置profile时会同时匹配到所有名字包含主Target名的扩展Target,把主应用的profile错误赋值给扩展,导致签名校验失败。
    修复方式是给匹配规则加首尾锚定,做精确匹配:
    update_project_provisioning(
      xcodeproj: xcodeproj,
      profile: ENV[profile_path_env_name], 
      target_filter: "^#{Regexp.escape(meta[:name])}$",
      build_configuration: ENV['BUILD_CONFIGURATION']
    )
    
  • 第三步:移除冗余的手动签名配置逻辑
    当前流程同时用了install_provisioning_profile、update_project_provisioning、update_code_signing_settings三个action修改签名配置,逻辑重叠很容易出现配置覆盖。实际上match拉取证书和profile后,会自动设置所有传入app_identifier对应Target的签名配置,不需要手动循环修改。可先注释掉遍历target修改profile的代码段,仅保留match和gym逻辑,测试归档是否正常。
  • 第四步:修复gym配置中硬编码profile名的问题
    当前export_options里的provisioningProfiles映射硬编码了AdHoc类型的profile名,一旦切换MATCH_TYPE为AppStore或Development,这里的profile名会完全不匹配,gym会自动搜索本地其他可用profile,极易出现错配。
    修复方式是直接引用match生成的环境变量填充映射,不要硬编码:
    provisioningProfiles: {
      ENV['IOS_APP_ID'] => ENV["sigh_#{ENV['IOS_APP_ID']}_#{ENV['MATCH_TYPE']}_profile-name"],
      ENV['SIRI_BUNDLE_ID'] => ENV["sigh_#{ENV['SIRI_BUNDLE_ID']}_#{ENV['MATCH_TYPE']}_profile-name"],
      ENV['PUSH_INTERCEPTOR_BUNDLE_ID'] => ENV["sigh_#{ENV['PUSH_INTERCEPTOR_BUNDLE_ID']}_#{ENV['MATCH_TYPE']}_profile-name"],
      ENV['WIDGETS_BUNDLE_ID'] => ENV["sigh_#{ENV['WIDGETS_BUNDLE_ID']}_#{ENV['MATCH_TYPE']}_profile-name"]
    }
    
  • 第五步:清理本地缓存后重试
    本地旧的描述文件、Xcode构建缓存也可能导致签名校验异常,执行以下命令清理后重新构建:
    rm -rf ~/Library/MobileDevice/Provisioning\ Profiles/*.mobileprovision
    xcodebuild clean
    rm -rf ~/Library/Developer/Xcode/DerivedData/*
    

内容的提问来源于stack exchange,提问作者MDalt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 00:39:18