Skip to content

fix(auth): fall back to file storage on any keychain init failure - #13

Merged
phil-accelbyte merged 1 commit into
mainfrom
fix/keychain-init-file-fallback
Jun 23, 2026
Merged

phil-accelbyte merged 1 commit into
mainfrom
fix/keychain-init-file-fallback

Conversation

@phil-accelbyte

Copy link
Copy Markdown
Collaborator

Problem

ags auth login hard-failed inside containers with Failed to initialize OS keychain entry ...: Platform secure storage failure. The Linux keyutils syscall returning ENOSYS (Unknown(38), syscall absent) or being blocked by the default Docker seccomp profile with EPERM (Unknown(1)) surfaces as keyring PlatformFailure — but init-time fallback previously recognised only NoStorageAccess, so the error propagated as a hard RuntimeError.

The same propagation made ags doctor Fail the Access Token check and skip the Network tier with "earlier tier failed", even when client credentials were present and auth was perfectly possible.

Fix

Split the fallback predicate by surface:

  • is_keychain_init_unavailable (init time) treats both NoStorageAccess and PlatformFailure from Entry::new as "no usable backend" and routes to file storage. Malformed-entry variants (Invalid, TooLong) still surface as errors.
  • is_keychain_unavailable (operation-time race guard) stays narrow to NoStorageAccess, so genuine read/write failures on a working keychain are not masked.

keychain_entry_opt returns None for an unavailable backend; all six call sites use it. The token store emits a one-time, suppressible AGS_NO_KEYCHAIN hint on init fallback. ags doctor now classifies an init-time PlatformFailure as a pass ("No keychain backend, using file fallback").

Tests

  • The init predicate covers NoStorageAccess, ENOSYS and EPERM PlatformFailure, and rejects malformed-entry variants.
  • The operation-time predicate stays narrow to NoStorageAccess.
  • Regression: ags doctor with client credentials but no stored token reports token-state as a warning (not fail) and does not skip the Network tier for an auth failure.

ags auth login hard-failed in containers with "Failed to initialize OS
keychain entry ...: Platform secure storage failure" — the Linux keyutils
syscall returning ENOSYS (Unknown(38)) or being seccomp-blocked with EPERM
(Unknown(1)) surfaces as PlatformFailure, but init-time fallback previously
recognised only NoStorageAccess. The same propagation made `ags doctor`
Fail the Access Token check and skip the Network tier even when client
credentials were present.

Split the fallback predicate by surface:
- is_keychain_init_unavailable (init) treats NoStorageAccess and
  PlatformFailure from Entry::new as "no usable backend" and routes to file
  storage; malformed-entry variants still surface as errors.
- is_keychain_unavailable (operation-time race guard) stays narrow to
  NoStorageAccess so genuine read/write failures on a working keychain are
  not masked.

keychain_entry_opt returns None for an unavailable backend; all six call
sites use it. The token store emits a one-time, suppressible AGS_NO_KEYCHAIN
hint on init fallback. `ags doctor` classifies an init-time PlatformFailure
as a pass ("No keychain backend, using file fallback").
@phil-accelbyte
phil-accelbyte merged commit d54120e into main Jun 23, 2026
5 checks passed
@phil-accelbyte
phil-accelbyte deleted the fix/keychain-init-file-fallback branch June 23, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant