Skip to content

Migrate macOS auth into the signed shared Keychain group - #736

Merged
tolgaergin merged 2 commits into
mainfrom
codex/shared-auth-keychain
Sep 15, 2026
Merged

tolgaergin merged 2 commits into
mainfrom
codex/shared-auth-keychain

Conversation

@tolgaergin

@tolgaergin tolgaergin commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Problem and solution

macOS login credentials did not select the shared Data Protection Keychain group. Scope native queries to 823S8YKMRW.dev.lpm.vault.shared and migrate digest-verified legacy credentials with durable cleanup. Older clients reject the new shared_keychain authority instead of reusing old credentials.

Companion to lpm-dev/lpm-vault#24. Documentation is in lpm-dev/rust-client-docs#226.

Validation

Rust 1.94.0: workspace build, all-target clippy with warnings denied, formatting, 6,307 workspace tests, 5,131 serial CLI unit tests, and 99 CLI integration tests pass. Repository script/npm gates pass. Signed Rust/Swift credential exchange and absent-item deletion pass.

One direct finding verified and fixed; zero rejected, externally blocked, or pending findings. See SHARED_AUTH_KEYCHAIN_LEDGER.md.

Generated by OpenAI Codex (gpt-6-astra) using the Codex agent harness.

@tolgaergin
tolgaergin merged commit 0329431 into main Sep 15, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant