ci: notarize Mac builds with the team App Store Connect API key - #16291
Conversation
The nightly DMG and Computer Use helper notarization tests now require notarytool to authenticate with --key/--key-id/--issuer, a mode-600 key file decoded from ASC_API_KEY_P8_BASE64, no Apple ID credentials, and deletion of the decoded key on exit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Release, nightly/RC and the v0.64.25 repair workflow now authenticate notarytool with --key/--key-id/--issuer instead of an Apple ID and app-specific password. scripts/ci/lib/notary-auth.sh decodes ASC_API_KEY_P8_BASE64 into a mode-600 file inside the caller's private temp dir, which an EXIT trap deletes. The notarize scripts fail before any upload when a key value is missing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Repository guideline files applied to this review (2)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughCI notarization scripts and workflows now use App Store Connect API key credentials. A shared helper validates credentials, decodes the private key with restrictive permissions, and supplies authentication arguments to ChangesNotarization authentication
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Refactor Merge Risk: ⚪ Minimal · up to CI notarization now uses App Store Connect API-key credentials instead of Apple ID credentials; no concrete merge-blocking failure is established in the supplied change context. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Private key-file permissions, early credential validation, and normal-exit cleanup limit exposure. The shared credential connects Mac notarization and iOS operations, however, and its actual permissions and release-environment eligibility remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
CI failure attributionCI passes on Written by |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Merge receipt for |
4e9d779 ci: notarize Mac builds with the team App Store Connect API key (manaflow-ai#16291) b520727 Make Stop cancel Agent Chat before startup acknowledgement (manaflow-ai#16058) a66a8bb Exempt authorized DEV clients from relay rate limits (manaflow-ai#12229) ca831d4 fix: restore main compile (OpenCodePaths in CLI, Codex auto-naming scope) (manaflow-ai#16260) # Conflicts: # .github/workflows/nightly.yml # .github/workflows/release.yml # .github/workflows/repair-v0-64-25-helper-rpaths.yml
* test(ci): notarization must use the team App Store Connect API key The nightly DMG and Computer Use helper notarization tests now require notarytool to authenticate with --key/--key-id/--issuer, a mode-600 key file decoded from ASC_API_KEY_P8_BASE64, no Apple ID credentials, and deletion of the decoded key on exit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * ci: notarize Mac builds with the team App Store Connect API key Release, nightly/RC and the v0.64.25 repair workflow now authenticate notarytool with --key/--key-id/--issuer instead of an Apple ID and app-specific password. scripts/ci/lib/notary-auth.sh decodes ASC_API_KEY_P8_BASE64 into a mode-600 file inside the caller's private temp dir, which an EXIT trap deletes. The notarize scripts fail before any upload when a key value is missing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(ci): read the fake notary key mode on Linux and macOS Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 4e9d779)
Summary
Mac notarization in
release.yml,nightly.yml(nightly and RC) and the v0.64.25 repair workflow authenticatednotarytoolwith an Apple ID and an app-specific password. Those two secrets have no source of truth we can read back, which blocks moving production secrets into thereleaseenvironment. Notarization now uses the team App Store Connect API key that the iOS lanes already use:notarytool --key <p8> --key-id $ASC_API_KEY_ID --issuer $ASC_API_ISSUER_ID.scripts/ci/lib/notary-auth.shdecodesASC_API_KEY_P8_BASE64into a mode-600 file inside the caller's private temp dir and builds the auth arguments. Every caller removes that dir with an EXIT trap, so the key does not outlive the step.notarize-nightly-dmg.shandnotarize-computer-use-helper.shstop before any upload when a key value is missing. TheASC_API_*secrets stay repo-level (iOS jobs need them), and repo-level secrets reach thereleaseenvironment jobs. After this lands, CI no longer readsAPPLE_ID,APPLE_APP_SPECIFIC_PASSWORDorAPPLE_TEAM_ID. The localscripts/build-sign-upload.shstill uses the Apple ID path.Testing
e84eb7302baadds the failing tests:bash tests/test_notarize_nightly_dmg.shexited 1 andpython3 tests/test_notarize_computer_use_helper.pyhad 11 failures. With835366bc7a4both pass (3 shell checks, 14 Python tests). The fakexcrunasserts eachnotarytoolcall has--keypointing at a mode-600 file with the decoded content, the expected key ID and issuer, and no--apple-id/--password/--team-id; the tests then check the key file is gone and that a missing key value stops beforenotarytoolruns.tests/test_ci_self_hosted_guard.shpasses,actionlintis clean on the three workflows,python3 scripts/verify-local.py --affected origin/mainpassed 15/15.xcrun notarytool historywith a team API key from the maintainer's machine authenticated and listed the team's nightly submissions, which shows a team key has notary access.ASC_API_*values. The notarize jobs run in thereleaseenvironment, whose branch policy allows onlymainandv*tags, so a branch dispatch can't reach them. The first nightly onmainafter merge is the live check.Changelog
none
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Mac notarization now authenticates
notarytoolwith the team App Store Connect API key instead of an Apple ID and app-specific password acrossrelease.yml,nightly.yml/RC, and the v0.64.25 repair workflow.scripts/ci/lib/notary-auth.shdecodesASC_API_KEY_P8_BASE64into a mode-600 temp file that each caller deletes on exit.ASC_API_KEY_ID,ASC_API_ISSUER_ID, andASC_API_KEY_P8_BASE64; it no longer readsAPPLE_ID,APPLE_APP_SPECIFIC_PASSWORD, orAPPLE_TEAM_ID. Localscripts/build-sign-upload.shkeeps the Apple ID path.ASC_API_*secrets stay repo-level, which also lets them flow into thereleaseenvironment jobs.notarytoolreceives the key and deletes it, and that missing secrets stop before any upload. A real notarization with repo secrets isn't verified until the next nightly onmainafter merge.Written for commit 0050a10. Summary will update on new commits.
Summary by CodeRabbit