Skip to content

fix(linux): close the "Secret Service read failed" login loop - #67

Merged
savass33 merged 1 commit into
mainfrom
fix/linux-keyring-login-loop
Oct 2, 2026
Merged

savass33 merged 1 commit into
mainfrom
fix/linux-keyring-login-loop

Conversation

@savass33

@savass33 savass33 commented Oct 2, 2026

Copy link
Copy Markdown

Summary

  • On Linux images without the secret-tool binary, every login ended in an endless re-login loop: the missing binary resolved as a vault error, and the fail-closed write path then refused to persist the fresh token anywhere.
  • classifySecretToolLookup now names a missing binary for what it is (no vault on the machine, so nothing can be shadowed) and routes it to the documented plaintext fallback; a vault that ran and failed stays a fail-closed error.
  • Evidence: 4–5 support chats in ~2 days (agent 624) with the exact string the code produced on empty stderr.

Test plan

  • New: src/utils/secureStorage/linuxSecretStorage.test.ts — 6 tests (classifier + missing-binary behavior)
  • bun run test:isolated -- src/utils/secureStorage/ — 3/3 PASS
  • tsc --noEmit clean on the changed files (repo has ~1722 pre-existing errors elsewhere)
  • Behavior probes: ENOENT → missing + fallback persists/reads back; exit-2 shim → stays error fail-closed (no shadow write)
  • Independent adversarial verification: PASS (shim matrix, E2E, no-regression on stateful stores)

🤖 Generated with Verboo Code

On Linux images without the secret-tool binary, every login ended in an
endless re-login loop: the missing binary resolved as a vault error, and the
fail-closed write path then refused to persist the fresh token anywhere.

classifySecretToolLookup now names a missing binary for what it is (there is
no vault on the machine, so nothing can be shadowed) and routes it to the
documented plaintext fallback, while a vault that ran and failed stays an
error. Regression-guarded by 6 new tests; isolated-suite, tsc and behavior
probes (exit-2 shim stays fail-closed, ENOENT persists via fallback) all green.

Co-Authored-By: Verboo Code <noreply@code.verboo.ai>
@savass33
savass33 merged commit 22f8539 into main Oct 2, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant