Skip to content

Commit 369eccd

Browse files
gitcommit90claude
andcommitted
fix(phase4): set the default keychain for the macOS runner job
notarytool resolves its credential profile through the session DEFAULT keychain, but a launchd runner job has no default keychain set, so notarization failed with "No Keychain password item found for profile" even though code signing (which uses the search list) succeeded. After the hook's trust validation passes, set the dedicated account's login keychain as the default and search keychain and unlock it, on macOS only. The keychain password is read from a machine-local file owned by the runner account ($HOME/.config/1helm/mac-keychain-password); it is never committed to this repository or exported into the job environment. No sudo, no elevation. Co-Authored-By: Claude <noreply@anthropic.com>
1 parent b6c17eb commit 369eccd

1 file changed

Lines changed: 19 additions & 0 deletions

File tree

‎ops/platform-acceptance/runner-job-started.sh‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,3 +30,22 @@ if not (
3030
):
3131
raise SystemExit("Phase 4 runner refused an untrusted repository/ref/SHA/CI event.")
3232
PY
33+
34+
# macOS only: prepare the dedicated signing account's login keychain for this
35+
# now-validated, trusted job. Code signing resolves its identity through the
36+
# keychain search list, but notarytool resolves its credential profile through
37+
# the session DEFAULT keychain, and a launchd runner job otherwise has no
38+
# default keychain, so notarization fails with "No Keychain password item
39+
# found". Set login as the default (and search) keychain and unlock it. The
40+
# password is read from a machine-local file owned by the runner account; it is
41+
# never stored in this repository or exported into the job environment.
42+
if [[ "$(uname)" == "Darwin" ]]; then
43+
kc="$HOME/Library/Keychains/login.keychain-db"
44+
kc_pw_file="$HOME/.config/1helm/mac-keychain-password"
45+
if [[ -f "$kc" && -r "$kc_pw_file" ]]; then
46+
security list-keychains -d user -s "$kc" /Library/Keychains/System.keychain >/dev/null 2>&1 || true
47+
security default-keychain -d user -s "$kc" >/dev/null 2>&1 || true
48+
security set-keychain-settings "$kc" >/dev/null 2>&1 || true
49+
security unlock-keychain -p "$(cat "$kc_pw_file")" "$kc" >/dev/null 2>&1 || true
50+
fi
51+
fi

0 commit comments

Comments
 (0)