mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
`Build on macos arm64` started failing on master with
security set-key-partition-list -S apple-tool:,apple: -s -k *** <tmp>.keychain
SecKeychainUnlock: The user name or passphrase you entered is not correct.
Every failure ran the `macos-26-arm64` runner image 20260831.0337; the same
job on image 20260728.0273 kept passing, as did `macos-15-intel`. The image
exposed an electron-builder bug: `app-builder-lib` hands the certificate's
`.p12` import password to `set-key-partition-list -k`, which authenticates
against the temporary keychain and therefore needs the keychain's own
generated password. Older macOS builds accepted the wrong password once the
keychain was unlocked; the new one verifies it.
Upstream fixed this in electron-userland/electron-builder#10101 (master,
v27 alpha) and backported it in #10172 to release/v26 on 2026-09-03, but no
26.x containing it is published (26.16.0 predates the backport, #10167).
Apply the backport to the installed 26.15.7 as a pnpm patch, guarded by
`tools/dependencies/app-builder-lib-keychain-password.test.mjs`: it checks
that the patched version is the installed one, that the compiled source
passes `keychainPassword`, and — with `security` recorded — that
`createKeychain` unlocks the partition list with the password it gave
`create-keychain`, not the import password. The test fails 2/3 on the
unpatched code. CI runs it next to the Vite patch guard; CLAUDE.md and
AGENTS.md document when to retire the patch.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
27 lines
1.8 KiB
Diff
27 lines
1.8 KiB
Diff
diff --git a/out/codeSign/macCodeSign.js b/out/codeSign/macCodeSign.js
|
|
index 9a69042fd48f4759a1c697bf23fa5b44f2da2366..193f42a8c4cb95ded694ba8ec0c27a5dcc94ed4c 100644
|
|
--- a/out/codeSign/macCodeSign.js
|
|
+++ b/out/codeSign/macCodeSign.js
|
|
@@ -156,16 +156,18 @@ async function createKeychain({ tmpDir, cscLink, cscKeyPassword, cscILink, cscIK
|
|
if (cscIKeyPassword != null) {
|
|
cscPasswords.push(cscIKeyPassword);
|
|
}
|
|
- return await importCerts(keychainFile, certPaths, cscPasswords);
|
|
+ return await importCerts(keychainFile, certPaths, cscPasswords, keychainPassword);
|
|
}
|
|
-async function importCerts(keychainFile, paths, keyPasswords) {
|
|
+async function importCerts(keychainFile, paths, keyPasswords, keychainPassword) {
|
|
var _a;
|
|
for (let i = 0; i < paths.length; i++) {
|
|
const password = (_a = keyPasswords[i]) !== null && _a !== void 0 ? _a : "";
|
|
await (0, builder_util_1.exec)("/usr/bin/security", ["import", paths[i], "-k", keychainFile, "-T", "/usr/bin/codesign", "-T", "/usr/bin/productbuild", "-P", password]);
|
|
// https://stackoverflow.com/questions/39868578/security-codesign-in-sierra-keychain-ignores-access-control-settings-and-ui-p
|
|
// https://github.com/electron-userland/electron-packager/issues/701#issuecomment-322315996
|
|
- await (0, builder_util_1.exec)("/usr/bin/security", ["set-key-partition-list", "-S", "apple-tool:,apple:", "-s", "-k", password, keychainFile]);
|
|
+ // `-k` expects the keychain's own unlock password (as used by create-keychain/unlock-keychain above),
|
|
+ // not the imported item's password used by `security import -P`.
|
|
+ await (0, builder_util_1.exec)("/usr/bin/security", ["set-key-partition-list", "-S", "apple-tool:,apple:", "-s", "-k", keychainPassword, keychainFile]);
|
|
}
|
|
return {
|
|
keychainFile,
|