#!/usr/bin/env bash # Exercise the Apple provider against a disposable user-default keychain. # This must run only as a dedicated, single-capacity CI account. set -euo pipefail mode="${1:-run}" case "$mode" in run|--preflight) ;; *) echo 'ERROR: usage: macos-native-keyring-smoke.sh [--preflight]' >&2 exit 2 ;; esac if [[ "$(uname -s)" != Darwin ]]; then echo 'ERROR: macOS native-keyring smoke test requires Darwin.' >&2 exit 2 fi if [[ "${NIGIG_SITE_LIVE_KEYRING_TEST:-}" != isolated-ci-native-v1 ]]; then echo 'ERROR: refusing native-keyring access without the isolated CI opt-in.' >&2 exit 2 fi case "${GITHUB_EVENT_NAME:-}" in workflow_dispatch) ;; push) if [[ "${GITHUB_REF:-}" != refs/heads/main ]]; then echo 'ERROR: refusing native-keyring access for a non-main push.' >&2 exit 2 fi ;; *) echo 'ERROR: refusing native-keyring access for an untrusted workflow event.' >&2 exit 2 ;; esac for command in cargo openssl security; do command -v "$command" >/dev/null || { echo "ERROR: required command is unavailable: $command" >&2 exit 2 } done normalize_keychain_path() { sed -E 's/^[[:space:]]*"//; s/"[[:space:]]*$//' } original_default="$(security default-keychain -d user | normalize_keychain_path)" if [[ -z "$original_default" || ! -e "$original_default" ]]; then echo 'ERROR: the dedicated runner has no restorable user-default keychain.' >&2 exit 2 fi run_id="${GITHUB_RUN_ID:-}" attempt="${GITHUB_RUN_ATTEMPT:-1}" if [[ -z "$run_id" ]]; then echo 'ERROR: workflow run identity is unavailable.' >&2 exit 2 fi case "$run_id-$attempt" in *[!A-Za-z0-9._-]*) echo 'ERROR: unsafe workflow identity for disposable keychain name.' >&2 exit 2 ;; esac keychain_path="$HOME/Library/Keychains/nigig-site-ci-${run_id}-${attempt}.keychain-db" keychain_password="$(openssl rand -hex 32)" created=false default_switch_attempted=false cleanup() { status=$? trap - EXIT HUP INT TERM if [[ "$default_switch_attempted" == true ]]; then if ! security default-keychain -d user -s "$original_default" >/dev/null 2>&1; then echo 'ERROR: failed to restore the runner user default keychain.' >&2 status=1 fi fi if [[ "$created" == true && -e "$keychain_path" ]]; then if ! security delete-keychain "$keychain_path" >/dev/null 2>&1; then echo "ERROR: failed to delete disposable keychain: $keychain_path" >&2 status=1 fi if [[ -e "$keychain_path" ]]; then echo "ERROR: disposable keychain still exists: $keychain_path" >&2 status=1 fi fi keychain_password='' if [[ "$status" -eq 0 && "$mode" == --preflight ]]; then echo 'Disposable Apple Keychain creation, selection, restoration, and deletion passed.' fi exit "$status" } trap cleanup EXIT trap 'exit 129' HUP trap 'exit 130' INT trap 'exit 143' TERM # An exact-path remnant means a prior attempt did not clean up. Remove only # this run/attempt's CI-owned keychain; never enumerate or alter user keychains. if [[ -e "$keychain_path" ]]; then security delete-keychain "$keychain_path" >/dev/null 2>&1 || { echo "ERROR: stale disposable keychain cannot be removed: $keychain_path" >&2 exit 2 } fi created=true security create-keychain -p "$keychain_password" "$keychain_path" security set-keychain-settings -lut 3600 "$keychain_path" security unlock-keychain -p "$keychain_password" "$keychain_path" default_switch_attempted=true security default-keychain -d user -s "$keychain_path" current_default="$(security default-keychain -d user | normalize_keychain_path)" if [[ "$current_default" != "$keychain_path" ]]; then echo 'ERROR: disposable keychain did not become the user default.' >&2 exit 2 fi echo "Using disposable CI keychain: $keychain_path" if [[ "$mode" == --preflight ]]; then exit 0 fi cargo test --locked -p nigig-site --lib \ repository::tests::apple_windows_native_provider_real_vault_lifecycle -- \ --ignored --exact --test-threads=1