Skip to content

feat(cli): add command-level keychain_access grant for macOS - #2093

Open
lukehinds wants to merge 3 commits into
mainfrom
fix/command-policy-keychain-bypass
Open

lukehinds wants to merge 3 commits into
mainfrom
fix/command-policy-keychain-bypass

Conversation

@lukehinds

Copy link
Copy Markdown
Contributor

Add a scoped keychain_access setting (read or readwrite) to command sandbox policies. This selectively lifts the agent's macOS keychain deny for a specific command child without exposing keychain files or Mach services to the agent itself or requiring agent-level protection bypasses.

Issue: #2092

Linked Issue

Closes #

Summary

Test Plan

Checklist

  • An issue exists and is linked above, or this is maintainer-directed routine work
  • All commits are signed-off, using DCO
  • Code changes follow the project's coding standards (AGENTS.md) and have appropriate test coverage
  • Public-facing changes are paired with documentation updates
  • If this PR implements a major feature, capability, or security-relevant change, a corresponding accepted NEP is linked

Add a scoped `keychain_access` setting (`read` or `readwrite`) to command sandbox policies. This selectively lifts the agent's macOS keychain deny for a specific command child without exposing keychain files or Mach services to the agent itself or requiring agent-level protection bypasses.

Issue: #2092

Signed-off-by: Luke Hinds <lukehinds@gmail.com>
@github-actions

github-actions Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

PR Review Summary

Size

Metric Value
Lines added +971
Lines removed -106
Total changed 1077
Classification Large (> 300 lines)

Affected crates

  • crates/nono-cli — CLI changes. Verify argument parsing, flag documentation, and UX behaviour across supported platforms.

Blast radius — Broad

This PR touches: source code,documentation,configuration / policy files


Updated automatically on each push to this PR.

@nogent-nolabs-ai nogent-nolabs-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nogent code review

No blocking issues found across 7 files.

Findings: none flagged in scope.

Automated code + security review. CI already covers clippy, rustfmt, tests, cargo-audit and commit-lint.

@SequeI

SequeI commented Oct 11, 2026

Copy link
Copy Markdown
Member

@panga let's see if this fixes the issue!

@panga

panga commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

@SequeI could you also test credential-file access beyond macOS Keychain: AWS credentials/config, kubeconfig, npm .npmrc?

My concern with NEP-0003 is the authorization model: a command should be able to receive scoped credential access without granting that access to the agent. The amendment should make this consistent for both Keychain and file-based credentials.

Attribute macOS Seatbelt denials occurring inside a mediated command's
own sandbox to its command policy and display targeted guidance in
supervised diagnostic output. Agent-level flags like --read do not
apply to command sandboxes, so the footer now directs users to update
the command's policy in `command_policies.commands.<name>`.

When `keychain_access` is set to "readwrite" (or when a keychain file
grant with `--bypass-protection` is used), allow writing to the
temporary `<db>.sb-XXXXXXXX-XXXXXX` files created during keychain save
operations. Harden keychain directories against symlink and hard link
creation to prevent malicious link swapping over keychain databases.

- Track child PIDs created during command mediation in `MediatedPids`
- Group and render mediated violations in `DiagnosticFormatter`
- Permit regular-file writes on `.sb-*` temp paths in keychain policy
- Disallow link creation and non-regular files in keychain directories
- Update documentation on keychain save behavior and link hardening

Signed-off-by: Luke Hinds <lukehinds@gmail.com>
@lukehinds

lukehinds commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor Author

I had to make some more changes to harden , will run some checks with tool sandboxing, although so far so good.

image

@lukehinds

Copy link
Copy Markdown
Contributor Author

and here is one password, I am not set up for kube etc , but this shows its good for more then one:

image

Signed-off-by: Luke Hinds <lukehinds@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants