git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/4] osxkeychain: bring in line with other credential helpers

From
Robert Coup <robert.coup@koordinates.com>
Date
Apr 2, 2024, 13:21 UTC
Message-ID
<CAFLLRpJZg3UhBRfihtjUsXcGSod4FhDCs8fD1k-=5SLnAdHeQw@mail.gmail.com>
In-Reply-To
<20240307094708.GA2650063@coredump.intra.peff.net>
Hi all,
Show 6 quoted lines
> All that said, I'd be surprised if testing osxkeychain in the CI
> environment worked. Back when I worked on it in 2011, I found that I had
> to actually run the tests in a local terminal; even a remote ssh login
> could not access the keychain. It's possible that things have changed
> since then, though, or perhaps I was imply ignorant of how to configure
> things correctly.

I have gotten keychain working in Github Actions before: there's some helpers for it, but you can also basically do it manually via the steps from [1]. Basically anyone who needs to do Apple code-signing in CI has to make it work.

@Bo, how are you actually testing this manually? Following these steps:

$ make $ (cd contrib/credential/osxkeychain && make) $ ln -s contrib/credential/osxkeychain/git-credential-osxkeychain . $ cd t $ make GIT_TEST_CREDENTIAL_HELPER=osxkeychain t0303-credential-external.sh

I get 'A keychain cannot be found to store "store-user".' in a popup dialog when #2 runs; then similar for other tests in 0303. For #14 I get a slight alternative with "A keychain cannot be found". There's a "Reset To Defaults" button, but that wipes everything. AFAIK I have a relatively normal setup, with a login keychain as default. macOS 14.3.1; arm64.

$ security list-keychains
    "/Users/rc/Library/Keychains/login.keychain-db"
    "/Library/Keychains/System.keychain"
$ security default-keychain
    "/Users/rc/Library/Keychains/login.keychain-db"
$ security unlock-keychain
password to unlock default: ...

I don't see any settings or code for setting which keychain the credential helper uses, so I guess it's the default one?

Cheers,
Rob :)
[1] https://docs.github.com/en/actions/deployment/deploying-xcode-applications/installing-an-apple-certificate-on-macos-runners-for-xcode-development
Previous: Jeff KingNext: Bo Anderson
Message 15 of 19 in “osxkeychain: bring in line with other credential helpers”
  1. 0/4 osxkeychain: bring in line with other credential helpersBo Anderson via GitGitGadget, Feb 17, 2024
  2. 1/4 osxkeychain: replace deprecated SecKeychain APIBo Anderson via GitGitGadget, Feb 17, 2024
  3. Eric SunshineFeb 18, 2024
  4. Bo AndersonFeb 18, 2024
  5. Eric SunshineFeb 18, 2024
  6. 2/4 osxkeychain: erase all matching credentialsBo Anderson via GitGitGadget, Feb 17, 2024
  7. 3/4 osxkeychain: erase matching passwords onlyBo Anderson via GitGitGadget, Feb 17, 2024
  8. 4/4 osxkeychain: store new attributesBo Anderson via GitGitGadget, Feb 17, 2024
  9. Eric SunshineFeb 18, 2024
  10. Eric SunshineFeb 18, 2024
  11. M HickfordFeb 18, 2024
  12. Bo AndersonFeb 18, 2024
  13. M HickfordMar 4, 2024
  14. Jeff KingMar 7, 2024
  15. Robert CoupApr 2, 2024
  16. Bo AndersonApr 2, 2024
  17. Robert CoupApr 2, 2024
  18. M HickfordApr 1, 2024
  19. Junio C HamanoApr 1, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.