rdmsm4x-changelog-20260926-1845-ecspermissions-dpkeychain
rdmsm4x-changelog-20260926-1845-ecspermissions-dpkeychain
Implemented rebuild-proof keychain storage in ECSPermissions with Data Protection fallback and legacy teamid partition lists (FEAT-20260926-23).
Scope
- Host:
rdmsm4x - Worktree:
/Users/richh/dev/_worktrees/ecspermissions-dpkeychain-0926 - Branch:
feat/dp-keychain-0926(commitd6a8660)
Changes Made
- Additive API: Added
Configurationstruct onECSSecureKeychainwith storage policy (.dataProtectionPreferred/.legacyOnly), access group, team ID, and custom keychain support. - Data Protection Path: Integrated
kSecUseDataProtectionKeychainandkSecAttrAccessGroup. Catches missing entitlements (-34018) and falls back cleanly to the legacy keychain, exposed viaactiveBackend. - Update-Not-Replace: Replaced delete-and-re-add in
save()with in-placeSecItemUpdate, falling back toSecItemAddonly onerrSecItemNotFound. Preserves creation dates and persistent references. - Idempotent Migration: One-time legacy -> DP migration on read misses without deleting legacy items.
- Legacy Partition List: Created
SecAccesswith partition list includingapple-tool:,apple:,teamid:ZU2882L4HTto ensure Developer ID rebuilds access credentials without UI prompts. - CodeSigningIdentity: Read-only helper querying
SecCodeCopySelfto inspect process designated requirements, ad-hoc status, and flag per-build paths (releases/,daemon-<sha>). - Test Isolation: Updated
testSecureKeychainRoundtripto use isolated temporary keychain files, preventing any writes to the user's login keychain. - Rebuild Proof: Validated Build A writes, Build B
(different code) reads silently with
kSecUseAuthenticationUIFail. Positive control with ad-hoc signing verified to fail silently witherrSecInteractionNotAllowed(-25293). - Gate Execution: All 33 unit/stress tests passed in
14.28s; Universal2 release build passed
(
libECSPermissions.ahas bothx86_64andarm64); all 11 consumer applications built and passed against this worktree.
Exact Files Touched
README.mdSources/ECSPermissions/ECSSecureKeychain.swiftSources/ECSPermissions/CodeSigningIdentity.swiftTests/ECSPermissionsTests/ECSPermissionsTests.swiftTests/ECSPermissionsTests/ECSSecureKeychainTests.swiftTests/Proof/Harness.swiftscripts/rebuild_proof.zshscripts/run_gates.zshscripts/verify_consumers.zsh
Verification Evidence
- Rebuild proof transcript:
~/dev/_handoff/ecspermissions-dpkeychain-0926/REBUILD_PROOF.md - Gate report and results:
~/dev/_handoff/ecspermissions-dpkeychain-0926/RESULT.md - Ticket update: comment on
FEAT-20260926-23
Outstanding Owner Action
For pre-existing generic passwords in the login keychain that need
team-wide access across rebuilds, run:
security set-generic-password-partition-list -a "<ACCOUNT>" -s "<SERVICE>" -S "apple-tool:,apple:,teamid:ZU2882L4HT" login.keychain-db