Appendix: debug and distribution signing boundaries
A helper rejected by macOS can trigger retries that resemble a latency regression. Diagnose identity before interpreting those samples as performance.
Ad-hoc signing supplies local structural integrity and a designated requirement, but not a distribution identity. Development, ad-hoc testing, Developer ID, and App Store distribution have different valid requirements.
Diagnosis
- Verify bundle and nested-code structure.
- Inspect identifier, team, and signing flags.
- Inspect the designated requirement.
- Check certificates only when the release mode requires them.
- Return to the caller/helper boundary.
Regression checks protect the identity contract for each release mode; local debug builds do not require a production certificate.