Skip to content

[bug] macOS keychain 多行 secret 被 hex 編碼取出——pb key run 對 4 把 PEM 交出壞掉的值 #28

Description

@YJack0000

從 #26 拆出的獨立風險(刻意不在該 PR 修)。

SecurityCliKeystore::get 用 security find-generic-password -w,而 security 在密碼含換行時會印 hex。64 把裡確認 4 把中招:三個 Apple ASC .p8、一個 GitHub App PEM。pb key run 與 pb key copy 交出去的是 3350 個十六進位字元,不是 1675 bytes 的 PEM——任何拿去用的東西都拿到壞掉的值。

不能盲目 hex-decode:vault 裡有六把 key 本來就長得像 hex。正解是 keystore.rs 那個 TODO 早就要求的 security-framework 重寫。

驗收:

  • 多行 secret 經 pb key run 注入後 byte-for-byte 等於存入值
  • 既有 4 把受影響 key 驗證可用(ASC API 呼叫、GitHub App JWT 簽章)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions