Some checks failed
nigig-site / Owned paths and honest test contracts (push) Has been cancelled
nigig-site / Cargo check-all-targets (push) Has been cancelled
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
127 lines
4.1 KiB
Bash
Executable file
127 lines
4.1 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Exercise the Apple provider against a disposable user-default keychain.
|
|
# This must run only as a dedicated, single-capacity CI account.
|
|
set -euo pipefail
|
|
|
|
mode="${1:-run}"
|
|
case "$mode" in
|
|
run|--preflight) ;;
|
|
*)
|
|
echo 'ERROR: usage: macos-native-keyring-smoke.sh [--preflight]' >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
|
|
if [[ "$(uname -s)" != Darwin ]]; then
|
|
echo 'ERROR: macOS native-keyring smoke test requires Darwin.' >&2
|
|
exit 2
|
|
fi
|
|
if [[ "${NIGIG_SITE_LIVE_KEYRING_TEST:-}" != isolated-ci-native-v1 ]]; then
|
|
echo 'ERROR: refusing native-keyring access without the isolated CI opt-in.' >&2
|
|
exit 2
|
|
fi
|
|
case "${GITHUB_EVENT_NAME:-}" in
|
|
workflow_dispatch) ;;
|
|
push)
|
|
if [[ "${GITHUB_REF:-}" != refs/heads/main ]]; then
|
|
echo 'ERROR: refusing native-keyring access for a non-main push.' >&2
|
|
exit 2
|
|
fi
|
|
;;
|
|
*)
|
|
echo 'ERROR: refusing native-keyring access for an untrusted workflow event.' >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
for command in cargo openssl security; do
|
|
command -v "$command" >/dev/null || {
|
|
echo "ERROR: required command is unavailable: $command" >&2
|
|
exit 2
|
|
}
|
|
done
|
|
|
|
normalize_keychain_path() {
|
|
sed -E 's/^[[:space:]]*"//; s/"[[:space:]]*$//'
|
|
}
|
|
|
|
original_default="$(security default-keychain -d user | normalize_keychain_path)"
|
|
if [[ -z "$original_default" || ! -e "$original_default" ]]; then
|
|
echo 'ERROR: the dedicated runner has no restorable user-default keychain.' >&2
|
|
exit 2
|
|
fi
|
|
|
|
run_id="${GITHUB_RUN_ID:-}"
|
|
attempt="${GITHUB_RUN_ATTEMPT:-1}"
|
|
if [[ -z "$run_id" ]]; then
|
|
echo 'ERROR: workflow run identity is unavailable.' >&2
|
|
exit 2
|
|
fi
|
|
case "$run_id-$attempt" in
|
|
*[!A-Za-z0-9._-]*)
|
|
echo 'ERROR: unsafe workflow identity for disposable keychain name.' >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
keychain_path="$HOME/Library/Keychains/nigig-site-ci-${run_id}-${attempt}.keychain-db"
|
|
keychain_password="$(openssl rand -hex 32)"
|
|
created=false
|
|
default_switch_attempted=false
|
|
|
|
cleanup() {
|
|
status=$?
|
|
trap - EXIT HUP INT TERM
|
|
if [[ "$default_switch_attempted" == true ]]; then
|
|
if ! security default-keychain -d user -s "$original_default" >/dev/null 2>&1; then
|
|
echo 'ERROR: failed to restore the runner user default keychain.' >&2
|
|
status=1
|
|
fi
|
|
fi
|
|
if [[ "$created" == true && -e "$keychain_path" ]]; then
|
|
if ! security delete-keychain "$keychain_path" >/dev/null 2>&1; then
|
|
echo "ERROR: failed to delete disposable keychain: $keychain_path" >&2
|
|
status=1
|
|
fi
|
|
if [[ -e "$keychain_path" ]]; then
|
|
echo "ERROR: disposable keychain still exists: $keychain_path" >&2
|
|
status=1
|
|
fi
|
|
fi
|
|
keychain_password=''
|
|
if [[ "$status" -eq 0 && "$mode" == --preflight ]]; then
|
|
echo 'Disposable Apple Keychain creation, selection, restoration, and deletion passed.'
|
|
fi
|
|
exit "$status"
|
|
}
|
|
trap cleanup EXIT
|
|
trap 'exit 129' HUP
|
|
trap 'exit 130' INT
|
|
trap 'exit 143' TERM
|
|
|
|
# An exact-path remnant means a prior attempt did not clean up. Remove only
|
|
# this run/attempt's CI-owned keychain; never enumerate or alter user keychains.
|
|
if [[ -e "$keychain_path" ]]; then
|
|
security delete-keychain "$keychain_path" >/dev/null 2>&1 || {
|
|
echo "ERROR: stale disposable keychain cannot be removed: $keychain_path" >&2
|
|
exit 2
|
|
}
|
|
fi
|
|
|
|
created=true
|
|
security create-keychain -p "$keychain_password" "$keychain_path"
|
|
security set-keychain-settings -lut 3600 "$keychain_path"
|
|
security unlock-keychain -p "$keychain_password" "$keychain_path"
|
|
default_switch_attempted=true
|
|
security default-keychain -d user -s "$keychain_path"
|
|
current_default="$(security default-keychain -d user | normalize_keychain_path)"
|
|
if [[ "$current_default" != "$keychain_path" ]]; then
|
|
echo 'ERROR: disposable keychain did not become the user default.' >&2
|
|
exit 2
|
|
fi
|
|
|
|
echo "Using disposable CI keychain: $keychain_path"
|
|
if [[ "$mode" == --preflight ]]; then
|
|
exit 0
|
|
fi
|
|
cargo test --locked -p nigig-site --lib \
|
|
repository::tests::apple_windows_native_provider_real_vault_lifecycle -- \
|
|
--ignored --exact --test-threads=1
|