Merge nucleic/quiet-opal-gecko-ah7w into dev
This commit is contained in:
+23
-2
@@ -100,6 +100,25 @@ in-tree means the patch can't be lost to a dependency re-resolve.
|
||||
paths close both ends so a failed connection fails FAST for the peer and leaks no fds. Marked
|
||||
`[Nucleic vendored patch]`.
|
||||
|
||||
13. **`Sources/ContainerizationOS/Keychain/KeychainQuery.swift` — prompt-free registry-credential
|
||||
reads.** Upstream's `get`/`list`/`exists` call `SecItemCopyMatching` with the legacy login
|
||||
Keychain's interactive authorization panel enabled, so any process that isn't on a registry
|
||||
internet-password item's ACL raises the macOS *"'cctl' wants to use your confidential information
|
||||
stored in 'ghcr.io' in your keychain"* panel when it reads that item — e.g. a `cctl` binary
|
||||
re-signed ad-hoc by a fresh `make vminit-image` reading a GHCR token an earlier build stored, or
|
||||
any tool linking `KeychainHelper.lookup` during an image pull/push/list. Nucleic's rule is that no
|
||||
automatic credential lookup may ever raise a Keychain panel. This patch wraps the three
|
||||
`SecItemCopyMatching` reads in `withoutInteractiveUI` (`SecKeychainSetUserInteractionAllowed(false)`
|
||||
— the only switch that governs the legacy ACL/partition-list dialog; the data-protection
|
||||
`kSecUseAuthenticationUI*` flags do NOT), so an already-trusted item reads silently while anything
|
||||
else fails with `errSecInteractionNotAllowed` — which `isQuerySuccessful` now treats as "not found"
|
||||
so the caller falls back to anonymous / `REGISTRY_HOST`/`USERNAME`/`TOKEN` env auth. `save`
|
||||
(the `cctl login` write path) gains a delete-and-retry on `errSecDuplicateItem`, since the
|
||||
now-silent `exists` can under-report an unreadable pre-existing item. Mirrors
|
||||
`KeychainOwnedAccess.withoutLegacyKeychainUI` in NucleicCore. Host-side (shipped by a normal
|
||||
`swift build`); `SecKeychain*` deprecation warnings are expected (built with
|
||||
`WARNINGS_AS_ERRORS=false`). Marked `[Nucleic vendored patch]`.
|
||||
|
||||
### GUEST-side patches (require rebuilding the initfs — see below)
|
||||
|
||||
Patches #1–#7 are host-side (the `Containerization` library), shipped by a normal `swift build`.
|
||||
@@ -191,8 +210,10 @@ rebuild whenever a guest patch changes. Built locally, not in CI: the host frame
|
||||
for `[Nucleic vendored patch]` to find every site, and patch #9 (per-exec cgroups) across
|
||||
`Cgroup2Manager.swift` / `ManagedContainer.swift` / `ManagedProcess.swift`, patch #10
|
||||
(`Socket.acceptStream` transient-error tolerance + `isTransientAcceptError`), patch #11 (the
|
||||
`UnixSocketRelay` per-connection containment + fail-fast closes), and patch #12 (the `VsockProxy`
|
||||
cleanup/`try!`/listener hardening in `vminitd/`). After re-applying any
|
||||
`UnixSocketRelay` per-connection containment + fail-fast closes), patch #12 (the `VsockProxy`
|
||||
cleanup/`try!`/listener hardening in `vminitd/`), and patch #13 (the prompt-free
|
||||
`KeychainQuery` reads: `withoutInteractiveUI` + the `errSecInteractionNotAllowed` handling +
|
||||
the `save` duplicate retry). After re-applying any
|
||||
`vminitd/` patch, rebuild + publish the custom init image
|
||||
with `make vminit-image` + `make vminit-image-push`, and bump `ContainerEngine.vminitReference`.
|
||||
5. Update the commit hash above and in the root `Package.swift` comment.
|
||||
|
||||
Reference in New Issue
Block a user