Skip to content

Preserve the provisioned macOS CLI's code-signing identity - #46495

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/ab00072e48189551adb0e70008210fee6d36241d
Sep 18, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/ab00072e48189551adb0e70008210fee6d36241d

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Preserve the provisioned macOS CLI's code-signing identity

Why

Existing login-keychain access rules identify the CLI as codex. Packaging it in an app bundle must preserve that code-signing identifier independently of the bundle identifier and provisioned App ID.

What changed

  • Sign the provisioned CLI with the identifier codex, retaining com.openai.codex.cli as its bundle identifier.
  • Require the expected signing identifier and team during signature verification, and reject unexpected bundle identifiers, executable names, or package types.
  • Document the identity distinction and keychain compatibility limits.

Testing

Extend signing-driver tests to check the signing identifier, verification requirement, bundle metadata, and provisioned entitlements, and to reject altered bundle identity fields. These tests use generated credentials and stubbed native tools; they do not verify runtime keychain access or credential recovery.

## Why

Existing login-keychain access rules identify the CLI as `codex`. Packaging it in an app bundle must preserve that code-signing identifier independently of the bundle identifier and provisioned App ID.

## What changed

- Sign the provisioned CLI with the identifier `codex`, retaining `com.openai.codex.cli` as its bundle identifier.
- Require the expected signing identifier and team during signature verification, and reject unexpected bundle identifiers, executable names, or package types.
- Document the identity distinction and keychain compatibility limits.

## Testing

Extend signing-driver tests to check the signing identifier, verification requirement, bundle metadata, and provisioned entitlements, and to reject altered bundle identity fields. These tests use generated credentials and stubbed native tools; they do not verify runtime keychain access or credential recovery.

GitOrigin-RevId: ab00072e48189551adb0e70008210fee6d36241d
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/ab00072e48189551adb0e70008210fee6d36241d branch from decfbb8 to c0e1b78 Compare September 18, 2026 22:53
@copyberry
copyberry Bot merged commit c0e1b78 into main Sep 18, 2026
1 check failed
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/ab00072e48189551adb0e70008210fee6d36241d branch September 18, 2026 22:53
@squizzeak
squizzeak deployed to issue-triage September 18, 2026 22:53 — with GitHub Actions Active
@squizzeak
squizzeak deployed to issue-triage September 18, 2026 22:53 — with GitHub Actions Active
@squizzeak
squizzeak deployed to issue-triage September 18, 2026 22:53 — with GitHub Actions Active
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 18, 2026
@squizzeak
squizzeak deployed to issue-triage September 18, 2026 22:54 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — c0e1b782 Deployed Sep 18, 2026 by ernestasromeika via Translate non-English issue #13997
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants