Skip to content

Add gated development App Attest bypass - #3438

Closed
brow wants to merge 1 commit into
mainfrom
push-gateway-dev-app-attest
Closed

Add gated development App Attest bypass#3438
brow wants to merge 1 commit into
mainfrom
push-gateway-dev-app-attest

Conversation

@brow

@brow brow commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

What changed?

Add a non-default development App Attest policy for iOS Simulator enrollment. The bypass accepts only the versioned development sentinels and is unavailable unless the gateway is explicitly compiled with dev-app-attest-bypass.

At runtime, enabling the bypass now fails closed unless both gateway listeners are loopback addresses and buzz-ios-sandbox is the only enabled profile. Default builds continue to use Apple's verifier. The gateway also records attempts that reach the APNs HTTP send seam.

Why?

The iOS Simulator cannot perform Apple App Attest, which otherwise makes local push enrollment structurally impossible. This provides a narrowly gated development path without adding bypass behavior to the production gateway build.

How is it tested?

Build and run.

Added tests:

🤖 This PR was authored with an agent.

Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
@brow

brow commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@brow

brow commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

@builderbot review

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

@brow

brow commented Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Superseded, closing. This work landed on the single feature branch push-ios-blockers-1-2 (draft #2744) per tomb's single-branch rule, in a strictly later form.

Where it went: three commits (6d7f118fa / 06841bcf9 / a8826c57b) plus the guard restore 737457569. The branch version is not a copy of this PR's b342d21d4, it is the reviewed evolution of it: the bypass is now reachable only through a capability token minted from validated config (AppAttestPolicy::from_config) rather than a bare AppAttestPolicy::Development, and config validation additionally requires both listeners loopback and enabled_profiles exactly {BuzzIosSandbox}, erroring rather than silently disabling on a non-canonical flag value. crates/buzz-push-gateway/src/dev_app_attest.rs is byte-identical between the two (sha256 aeb7ef02...), and the push_gateway_apns_send_attempts_total counter from this PR is present there as well.

Adversarial review happened against the branch version, not this one, and produced one landing condition that this PR does not carry: the development_bypass_stays_a_non_default_feature guard is the sole detection for flipping default = ["dev-app-attest-bypass"], which matters because Dockerfile.push-gateway:20 builds the release image with no --features. Mutating that line with the guard absent was caught by nothing (both arms 40/0, clippy clean); with the guard restored it fails by name in the plain cargo test -p buzz-push-gateway arm, and the resulting no-features binary was confirmed to contain the bypass symbols. Nothing is lost by closing this.

@brow brow closed this Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant