feat(cli): ship the terminal client for macOS in every release - #48
Merged
Merged
Conversation
The terminal surface built on macOS but could not keep a secret there: the platform store fell through to secret-tool, which a Mac does not have. It now uses the keychain with the app's own access list — any binary signed by the TorroMail team reads the item without a dialog — so the app, the server and the terminal client share passwords and client keys. - torromail-keychain: new crate mirroring the app's teamScopedAccess(). It is the one crate allowed unsafe, confined to its sys module; the rest of the workspace still forbids it. An unsigned build never replaces an item it cannot read, since only it could read the replacement. - torromail-control: KeychainStore as the macOS platform store. - torromail-tui: keychain dialogs off for the run; the background check installs a launchd agent on macOS; notifications via Notification Center. - Release: scripts/build-cli-macos.sh builds torromail and torromail-mcp universal, signs them with the Developer ID under the hardened runtime, notarizes and packs torromail-<version>-universal-macos.tar.gz. The macOS release job runs it, and publishing now requires a download for every system. - scripts/install-macos.sh installs a signed local build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The terminal client (
torromail) built on macOS but could not store a secret there: the platform store fell through tosecret-tool, which a Mac does not have. Releases also shipped it only for Linux and Windows.What
torromail-keychain(new, macOS only): creates keychain items with the same access list the app'steamScopedAccess()uses — any binary signed by the TorroMail team reads them without a dialog. It is the one crate allowedunsafe, confined to itssysmodule; the workspace still forbids it everywhere else. An unsigned build never replaces an item it cannot read, because only it could read the replacement.torromail-control:KeychainStoreis the macOS platform store.torromail-tui: keychain dialogs are off for the whole run (as in the server). The background check installs a launchd agent on macOS (com.torromail.check, every 15 minutes). Notifications go through Notification Center.scripts/build-cli-macos.shbuildstorromail+torromail-mcpuniversal, signs them with the Developer ID under the hardened runtime, has them notarized and packstorromail-<version>-universal-macos.tar.gz. The existing macOS release job runs it, and the publish step now requires a download for every system (macOS, Linux x86_64 and aarch64, Windows).scripts/install-macos.shinstalls a signed local build. README, RELEASING.md and AGENTS.md are updated.Verification
cargo test --workspace --locked: all 41 suites pass. There is a new launchd test for macOS.client-key-*) are readable.torromail checkwith the installed build logged into all 6 real accounts via the app's keychain items.scripts/build-cli-macos.shran end to end locally withNOTARIZE=0: universal binaries, Team ID in the signature, smoke test, tarball.-rctag after merge is the safe first run.🤖 Generated with Claude Code