Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260926-1845-ecspermissions-dpkeychain

rdmsm4x-changelog-20260926-1845-ecspermissions-dpkeychain

Implemented rebuild-proof keychain storage in ECSPermissions with Data Protection fallback and legacy teamid partition lists (FEAT-20260926-23).

Scope

Changes Made

  1. Additive API: Added Configuration struct on ECSSecureKeychain with storage policy (.dataProtectionPreferred / .legacyOnly), access group, team ID, and custom keychain support.
  2. Data Protection Path: Integrated kSecUseDataProtectionKeychain and kSecAttrAccessGroup. Catches missing entitlements (-34018) and falls back cleanly to the legacy keychain, exposed via activeBackend.
  3. Update-Not-Replace: Replaced delete-and-re-add in save() with in-place SecItemUpdate, falling back to SecItemAdd only on errSecItemNotFound. Preserves creation dates and persistent references.
  4. Idempotent Migration: One-time legacy -> DP migration on read misses without deleting legacy items.
  5. Legacy Partition List: Created SecAccess with partition list including apple-tool:, apple:, teamid:ZU2882L4HT to ensure Developer ID rebuilds access credentials without UI prompts.
  6. CodeSigningIdentity: Read-only helper querying SecCodeCopySelf to inspect process designated requirements, ad-hoc status, and flag per-build paths (releases/, daemon-<sha>).
  7. Test Isolation: Updated testSecureKeychainRoundtrip to use isolated temporary keychain files, preventing any writes to the user's login keychain.
  8. Rebuild Proof: Validated Build A writes, Build B (different code) reads silently with kSecUseAuthenticationUIFail. Positive control with ad-hoc signing verified to fail silently with errSecInteractionNotAllowed (-25293).
  9. Gate Execution: All 33 unit/stress tests passed in 14.28s; Universal2 release build passed (libECSPermissions.a has both x86_64 and arm64); all 11 consumer applications built and passed against this worktree.

Exact Files Touched

Verification Evidence

Outstanding Owner Action

For pre-existing generic passwords in the login keychain that need team-wide access across rebuilds, run: security set-generic-password-partition-list -a "<ACCOUNT>" -s "<SERVICE>" -S "apple-tool:,apple:,teamid:ZU2882L4HT" login.keychain-db