Skip to content

fix(push): certificate-based APNs auth over HTTP/2 - #3431

Closed
brow wants to merge 6 commits into
mainfrom
apns-http2
Closed

brow wants to merge 6 commits into
mainfrom
apns-http2

Conversation

@brow

@brow brow commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Makes the push gateway able to actually deliver to Apple, by fixing transport and switching authentication:

  • enable reqwest HTTP/2 for the APNs transport (APNs is HTTP/2-only; without the feature the TLS handshake fails before any request), with a compile canary so removing the feature fails the build
  • replace ES256 provider-token (JWT/.p8) auth with client-certificate auth: a combined key+cert PEM is loaded via reqwest::Identity and installed on the client; the JWT machinery, bearer header, and p256 dependency are removed
  • config collapses apns_key_path/apns_key_id/apns_team_id into a single BUZZ_PUSH_APNS_CERT_PATH; apns_topic stays required (APNs pins the topic to the cert bundle id); no dual mode or token fallback
  • mount the certificate Secret with defaultMode: 0400 (Kubernetes defaults Secret files to 0644, which would leave the private key world-readable in the pod) and assert the mode in the chart render test
  • remove the dead RefreshCredential outcome (enum variant, trait method, caller branch, metric, docs): nothing constructs it under cert auth
  • chart schema now defines apnsCert and rejects legacy apnsKey overrides so stale token-auth values fail loudly

Validation

  • full buzz-push-gateway suite green: 22 passed, 0 failed, 7 ignored (opt-in live probe + PostgreSQL integration)
  • mutation checks: deleting the identity install fails the mismatched-key test; removing defaultMode fails the render test; removing the http2 feature fails compilation
  • live APNs sandbox probe through the gateway send path with the real (uncommitted) certificate: 400 BadDeviceToken, proving Apple accepted the client certificate; control without identity returns 403 MissingProviderToken
  • identity-load failure matrix (empty, non-PEM, cert-only, key-only, encrypted, mismatched key/cert) all map to ApnsError::Credential
  • clippy -D warnings, helm lint, full chart render script
  • independently accepted by a red-team and an acceptance review at commit c7bbf74; branch then merged origin/main (Cargo.lock only overlap) and the suite re-ran green at the pushed head

No credentials are committed; the chart mounts them from a Secret.

Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
@brow

brow commented Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@brow

brow commented Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

@builderbot review

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp and others added 5 commits July 29, 2026 14:41
Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
* origin/main: (70 commits)
  fix(catalog): update Amp tagline (#3806)
  fix(desktop): channel topic and membership metadata cleanup (#3642)
  fix(desktop): align data deletion labels (#2230)
  fix(relay): align NIP-11 max_limit with REQ ceiling (#3635)
  fix(desktop): allow linux-only media items as dead code off-linux (#3811)
  fix(desktop): report authenticated relay recovery (#3812)
  fix(desktop): don't gate hover affordances on the hover media query (#3657)
  feat(relay): gate kind 30178 team-catalog reads behind the shared tag (#3358)
  test(desktop): click visible thread collapse guide (#3800)
  feat(desktop): raise the install ceiling and make installs observable (#3368)
  fix(db): isolate usage metrics advisory-lock test on scratch DB (#3670)
  Add Devin as a preset ACP harness (#3225)
  feat(desktop): improve agent activity header ui (#3321)
  perf(presence): reduce heartbeat frequency (#3783)
  Tighten continuation message rows (#3724)
  Fix video reviews in thread replies (#3719)
  feat(release): make desktop releases immutable (#3568)
  Make relay reconnect backoff authoritative (#3774)
  feat(desktop): add password-protected backups in settings (#3701)
  fix(desktop): reuse profiles when joining communities (#2155)
  ...

Signed-off-by: npub15w828kxsxu2684ynste0uah2jwkgatd99flt7ds4523hzm8ju6cshdr8hh <a38ea3d8d03715a3d49382f2fe76ea93ac8eada52a7ebf3615a2a3716cf2e6b1@buzz.block.builderlab.xyz>
@brow brow changed the title fix(push): enable HTTP/2 for APNs fix(push): certificate-based APNs auth over HTTP/2 Jul 31, 2026
@brow

brow commented Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

Consolidating: tomb directed all push-notification work onto the single feature branch push-ios-blockers-1-2 (draft #2744). The reviewed cert-auth commits (head 89de724, judge-accepted) are merged there as f61f841. Closing this PR; branch apns-http2 retained.

@brow brow closed this Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant