Allow Git downloads to use the GitHub API token - #24128
Merged
Merged
Conversation
MikeMcQuaid
requested changes
Sep 29, 2026
MikeMcQuaid
left a comment
Member
There was a problem hiding this comment.
This change is far too broad. Will give detailed review tomorrow.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The keychain allowance must be macOS-specific to avoid weakening Linux sandboxing.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Enables Git credential helpers to read the macOS login keychain during downloads while preserving other keychain restrictions.
Changes:
- Allows Git downloads to read
login.keychain-db. - Adds tests for allowed and denied keychain access.
| File | Description |
|---|---|
Library/Homebrew/test/sandbox_shared_spec.rb |
Tests keychain access rules. |
Library/Homebrew/sandbox.rb |
Adds the login keychain sandbox exception. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
gritse
force-pushed
the
sandbox-git-login-keychain
branch
from
September 29, 2026 19:49
457db28 to
e9d050d
Compare
p-linnane
previously requested changes
Sep 30, 2026
MikeMcQuaid
force-pushed
the
sandbox-git-login-keychain
branch
from
September 30, 2026 08:39
e9d050d to
80382df
Compare
Member
|
@gritse changing the approach here considerably I'm afraid but improving some parts that may help you and documenting why the bits we're not fixing remain that way. |
MikeMcQuaid
force-pushed
the
sandbox-git-login-keychain
branch
from
September 30, 2026 14:53
80382df to
b68ce8d
Compare
…lpers `git-credential-osxkeychain` and `gh auth git-credential` read the login keychain, which the download sandbox denies. On macOS, allow reading only `login.keychain-db` while fetching HTTP(S) remotes, like `CvsDownloadStrategy#allow_fetch_credentials` does for `~/.cvspass`.
- Remove the database allowance inherited by checkout, submodules and other fetch children: it cannot restrict access to one credential. - Avoid treating the original URL as a security boundary when Git can rewrite transports with `url.*.insteadOf`. - Test keychain denial across transports on both platforms. Restoring keychain authentication needs a separately scoped credential design.
- Pass `HOMEBREW_GITHUB_API_TOKEN` only with `gh` on the original path and a configured helper for the rewritten HTTP(S) URL. - Preserve login keychain isolation and filter unrelated tokens and credentials during local Git inspection. - Exercise SSH agents, file-backed credentials and wrapper helpers with dummy tokens and document supported authentication options.
MikeMcQuaid
force-pushed
the
sandbox-git-login-keychain
branch
from
September 30, 2026 16:00
b68ce8d to
5bd434e
Compare
MikeMcQuaid
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Heavily edited by @MikeMcQuaid:
What and why
Allow Git source downloads to use the existing HOMEBREW_GITHUB_API_TOKEN through the configured gh credential helper, without granting access to the macOS login keychain.
Homebrew passes the token as GH_TOKEN during Git downloads and excludes it from local Git inspections, including inspections performed during a fetch. Other token variables remain filtered. No new
environment setting or sandbox permission is introduced.
This addresses private HTTPS downloads whose gh credentials are stored in the keychain. Although Git can launch gh, the helper inherits Git’s sandbox and cannot read the keychain. Users can retrieve the
token before starting Homebrew and pass only that credential into the download.
The FAQ documents this workflow alongside existing SSH-agent and file-backed gh authentication.
Security boundary
The keychain remains denied for all transports, including checkout and recursive submodules. No keychain allowance depends on the original URL, so Git’s url.*.insteadOf rewrites cannot expand access.
The supplied token is available to Git download commands and their subprocesses. Use a read-only token restricted to the required repositories. Retrieving a token with gh auth token preserves its existing
permissions.
Reproduction and usage
Requires a formula whose source is a private HTTPS GitHub repository, represented below by user/tap/formula, and a gh login with access to it.
With the token stored in the macOS login keychain:
gh auth login --hostname github.com --git-protocol https
gh auth setup-git --hostname github.com
brew fetch --force user/tap/formula
The sandboxed helper cannot retrieve the token. With this change, retrieve it outside Homebrew’s sandbox:
HOMEBREW_GITHUB_API_TOKEN="$(gh auth token --hostname github.com)"
brew fetch --force user/tap/formula
Alternatively, select a token stored in a user-chosen variable:
HOMEBREW_GITHUB_API_TOKEN="$HOMEBREW_MY_TOKEN"
brew fetch --force user/tap/formula
The credential helper must still be configured. Bare GH_TOKEN is filtered by Homebrew’s startup environment.
brew benchmarkresults.brewcommands to reproduce the bug?brew lgtm(style, typechecking and tests) locally?GPT 6 Astra medium with local review and testing.