mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 09:01:03 -08:00
fix(release): pass the keychain password to set-key-partition-list on macOS
`Build on macos arm64` started failing on master with
security set-key-partition-list -S apple-tool:,apple: -s -k *** <tmp>.keychain
SecKeychainUnlock: The user name or passphrase you entered is not correct.
Every failure ran the `macos-26-arm64` runner image 20260831.0337; the same
job on image 20260728.0273 kept passing, as did `macos-15-intel`. The image
exposed an electron-builder bug: `app-builder-lib` hands the certificate's
`.p12` import password to `set-key-partition-list -k`, which authenticates
against the temporary keychain and therefore needs the keychain's own
generated password. Older macOS builds accepted the wrong password once the
keychain was unlocked; the new one verifies it.
Upstream fixed this in electron-userland/electron-builder#10101 (master,
v27 alpha) and backported it in #10172 to release/v26 on 2026-09-03, but no
26.x containing it is published (26.16.0 predates the backport, #10167).
Apply the backport to the installed 26.15.7 as a pnpm patch, guarded by
`tools/dependencies/app-builder-lib-keychain-password.test.mjs`: it checks
that the patched version is the installed one, that the compiled source
passes `keychainPassword`, and — with `security` recorded — that
`createKeychain` unlocks the partition list with the password it gave
`create-keychain`, not the import password. The test fails 2/3 on the
unpatched code. CI runs it next to the Vite patch guard; CLAUDE.md and
AGENTS.md document when to retire the patch.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
1 parent
50b980af7a
commit
52b33fe5a3
7 files changed
+240
-5
No files matched your search
@@ -85,6 +85,17 @@ pnpm nx show projects
|
||||
`patches/vite@7.3.6.patch`. Keep the patch until supported Angular tooling
|
||||
resolves a Vite version containing the fix, and run `pnpm run deps:vite:test`
|
||||
after related dependency updates.
|
||||
- `app-builder-lib` `26.15.7` (electron-builder's macOS signing) is patched in
|
||||
`patches/app-builder-lib@26.15.7.patch` with the upstream backport
|
||||
electron-userland/electron-builder#10172: `security set-key-partition-list -k`
|
||||
must receive the temporary keychain's own password, not the `.p12` import
|
||||
password. macOS runner images since `macos-26-arm64` 20260831 verify that
|
||||
password, and `Build on macos arm64` failed with `SecKeychainUnlock: The user
|
||||
name or passphrase you entered is not correct`. Keep the patch until
|
||||
electron-builder resolves an `app-builder-lib` containing the fix (26.16.1+),
|
||||
and run `pnpm run deps:electron-builder:test` after related dependency
|
||||
updates — the test fails when the patched version no longer matches the
|
||||
installed one.
|
||||
- A directory holding files consumed by other projects must be an Nx project.
|
||||
Nx builds its graph from TypeScript imports only, so a relative SCSS `@use`
|
||||
across project roots creates no edge and the imported file lands in no task
|
||||
|
||||
Reference in new issue
Block a user