fix(auth): fall back to file storage on any keychain init failure - #13
Merged
Merged
Conversation
ags auth login hard-failed in containers with "Failed to initialize OS
keychain entry ...: Platform secure storage failure" — the Linux keyutils
syscall returning ENOSYS (Unknown(38)) or being seccomp-blocked with EPERM
(Unknown(1)) surfaces as PlatformFailure, but init-time fallback previously
recognised only NoStorageAccess. The same propagation made `ags doctor`
Fail the Access Token check and skip the Network tier even when client
credentials were present.
Split the fallback predicate by surface:
- is_keychain_init_unavailable (init) treats NoStorageAccess and
PlatformFailure from Entry::new as "no usable backend" and routes to file
storage; malformed-entry variants still surface as errors.
- is_keychain_unavailable (operation-time race guard) stays narrow to
NoStorageAccess so genuine read/write failures on a working keychain are
not masked.
keychain_entry_opt returns None for an unavailable backend; all six call
sites use it. The token store emits a one-time, suppressible AGS_NO_KEYCHAIN
hint on init fallback. `ags doctor` classifies an init-time PlatformFailure
as a pass ("No keychain backend, using file fallback").
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
ags auth loginhard-failed inside containers withFailed to initialize OS keychain entry ...: Platform secure storage failure. The Linux keyutils syscall returningENOSYS(Unknown(38), syscall absent) or being blocked by the default Docker seccomp profile withEPERM(Unknown(1)) surfaces as keyringPlatformFailure— but init-time fallback previously recognised onlyNoStorageAccess, so the error propagated as a hardRuntimeError.The same propagation made
ags doctorFail the Access Token check and skip the Network tier with "earlier tier failed", even when client credentials were present and auth was perfectly possible.Fix
Split the fallback predicate by surface:
is_keychain_init_unavailable(init time) treats bothNoStorageAccessandPlatformFailurefromEntry::newas "no usable backend" and routes to file storage. Malformed-entry variants (Invalid,TooLong) still surface as errors.is_keychain_unavailable(operation-time race guard) stays narrow toNoStorageAccess, so genuine read/write failures on a working keychain are not masked.keychain_entry_optreturnsNonefor an unavailable backend; all six call sites use it. The token store emits a one-time, suppressibleAGS_NO_KEYCHAINhint on init fallback.ags doctornow classifies an init-timePlatformFailureas a pass ("No keychain backend, using file fallback").Tests
NoStorageAccess, ENOSYS and EPERMPlatformFailure, and rejects malformed-entry variants.NoStorageAccess.ags doctorwith client credentials but no stored token reports token-state as a warning (not fail) and does not skip the Network tier for an auth failure.