Skip to content

Allow Git downloads to use the GitHub API token - #24128

Merged
MikeMcQuaid merged 3 commits into
Homebrew:mainfrom
gritse:sandbox-git-login-keychain
Sep 30, 2026
Merged

MikeMcQuaid merged 3 commits into
Homebrew:mainfrom
gritse:sandbox-git-login-keychain

Conversation

@gritse

@gritse gritse commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Heavily edited by @MikeMcQuaid:

What and why

Allow Git source downloads to use the existing HOMEBREW_GITHUB_API_TOKEN through the configured gh credential helper, without granting access to the macOS login keychain.

Homebrew passes the token as GH_TOKEN during Git downloads and excludes it from local Git inspections, including inspections performed during a fetch. Other token variables remain filtered. No new
environment setting or sandbox permission is introduced.

This addresses private HTTPS downloads whose gh credentials are stored in the keychain. Although Git can launch gh, the helper inherits Git’s sandbox and cannot read the keychain. Users can retrieve the
token before starting Homebrew and pass only that credential into the download.

The FAQ documents this workflow alongside existing SSH-agent and file-backed gh authentication.

Security boundary

The keychain remains denied for all transports, including checkout and recursive submodules. No keychain allowance depends on the original URL, so Git’s url.*.insteadOf rewrites cannot expand access.

The supplied token is available to Git download commands and their subprocesses. Use a read-only token restricted to the required repositories. Retrieving a token with gh auth token preserves its existing
permissions.

Reproduction and usage

Requires a formula whose source is a private HTTPS GitHub repository, represented below by user/tap/formula, and a gh login with access to it.

With the token stored in the macOS login keychain:

gh auth login --hostname github.com --git-protocol https
gh auth setup-git --hostname github.com
brew fetch --force user/tap/formula

The sandboxed helper cannot retrieve the token. With this change, retrieve it outside Homebrew’s sandbox:

HOMEBREW_GITHUB_API_TOKEN="$(gh auth token --hostname github.com)"
brew fetch --force user/tap/formula

Alternatively, select a token stored in a user-chosen variable:

HOMEBREW_GITHUB_API_TOKEN="$HOMEBREW_MY_TOKEN"
brew fetch --force user/tap/formula

The credential helper must still be configured. Bare GH_TOKEN is filtered by Homebrew’s startup environment.


  • Have you followed our Contributing guidelines?
  • Have you checked for other open Pull Requests for the same change?
  • Have you explained what your changes do? Performance claims (e.g. "this is faster") must include brew benchmark results.
  • Have you explained why you'd like these changes included, not just what they do?
  • For bug fixes, have you given step-by-step brew commands to reproduce the bug?
  • Have you written new tests (excluding integration tests)? Here's an example.
  • Have you successfully run brew lgtm (style, typechecking and tests) locally?

  • I did not use AI/LLM to create this PR, or I disclosed the tool/model below and reviewed its output; I did not attribute commits to AI and will answer maintainer questions and review comments myself without AI/LLM.

GPT 6 Astra medium with local review and testing.

@gritse
gritse requested a review from a team as a code owner September 29, 2026 19:00
Copilot AI lite review requested due to automatic review settings September 29, 2026 19:01

@MikeMcQuaid MikeMcQuaid left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change is far too broad. Will give detailed review tomorrow.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The keychain allowance must be macOS-specific to avoid weakening Linux sandboxing.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Enables Git credential helpers to read the macOS login keychain during downloads while preserving other keychain restrictions.

Changes:

  • Allows Git downloads to read login.keychain-db.
  • Adds tests for allowed and denied keychain access.
File Description
Library/​Homebrew/​test/​sandbox_shared_spec.rb Tests keychain access rules.
Library/​Homebrew/​sandbox.rb Adds the login keychain sandbox exception.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread Library/Homebrew/sandbox.rb Outdated
@gritse
gritse force-pushed the sandbox-git-login-keychain branch from 457db28 to e9d050d Compare September 29, 2026 19:49
@gritse gritse changed the title sandbox: allow Git credential helpers to read the login keychain git_download_strategy: allow login keychain for HTTP(S) credential helpers Sep 29, 2026

@p-linnane p-linnane left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See inline comments.

Comment thread Library/Homebrew/download_strategy/git_download_strategy.rb Outdated
Comment thread Library/Homebrew/extend/os/mac/sandbox.rb Outdated
@MikeMcQuaid
MikeMcQuaid force-pushed the sandbox-git-login-keychain branch from e9d050d to 80382df Compare September 30, 2026 08:39
@MikeMcQuaid MikeMcQuaid changed the title git_download_strategy: allow login keychain for HTTP(S) credential helpers Allow Git downloads to use the GitHub API token Sep 30, 2026
@MikeMcQuaid
MikeMcQuaid dismissed p-linnane’s stale review September 30, 2026 11:59

Changes addressed.

@MikeMcQuaid

Copy link
Copy Markdown
Member

@gritse changing the approach here considerably I'm afraid but improving some parts that may help you and documenting why the bits we're not fixing remain that way.

@MikeMcQuaid
MikeMcQuaid force-pushed the sandbox-git-login-keychain branch from 80382df to b68ce8d Compare September 30, 2026 14:53
gritse and others added 3 commits September 30, 2026 16:12
…lpers

`git-credential-osxkeychain` and `gh auth git-credential` read the login
keychain, which the download sandbox denies. On macOS, allow reading
only `login.keychain-db` while fetching HTTP(S) remotes, like
`CvsDownloadStrategy#allow_fetch_credentials` does for `~/.cvspass`.
- Remove the database allowance inherited by checkout, submodules and
  other fetch children: it cannot restrict access to one credential.
- Avoid treating the original URL as a security boundary when Git can
  rewrite transports with `url.*.insteadOf`.
- Test keychain denial across transports on both platforms. Restoring
  keychain authentication needs a separately scoped credential design.
- Pass `HOMEBREW_GITHUB_API_TOKEN` only with `gh` on the original
  path and a configured helper for the rewritten HTTP(S) URL.
- Preserve login keychain isolation and filter unrelated tokens
  and credentials during local Git inspection.
- Exercise SSH agents, file-backed credentials and wrapper helpers
  with dummy tokens and document supported authentication options.
@MikeMcQuaid
MikeMcQuaid force-pushed the sandbox-git-login-keychain branch from b68ce8d to 5bd434e Compare September 30, 2026 16:00
@MikeMcQuaid
MikeMcQuaid added this pull request to the merge queue Sep 30, 2026
Merged via the queue into Homebrew:main with commit 6547679 Sep 30, 2026
51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants