Skip to content

fix: harden Linux pairing credential storage - #721

Open
enaboapps wants to merge 1 commit into
linux-supportfrom
feat/720-linux-credential-safety
Open

enaboapps wants to merge 1 commit into
linux-supportfrom
feat/720-linux-credential-safety

Conversation

@enaboapps

@enaboapps enaboapps commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Closes #720

Summary

Wrap Linux Secret Service-backed token storage with serialized operations, nonempty save/read-back verification and fixed actionable errors. Preserve keyring identity, state schema, missing-entry semantics and Windows/macOS behavior. Failed read-back never deletes credentials. Add four fake-store/model recovery tests and documentation. Linux pairing/input remain disabled.

Validation

  • Frontend lint, 114 tests, 5 updater tests and build passed locally.
  • Rust formatting and git diff --check passed.
  • Local native Clippy/tests blocked by absent GLib/GDK development packages; all native CI jobs passed on Linux, Windows and macOS.
  • CI 34618899057 and CodeQL 34618899126: all green.
  • Independent latest-head review db48185: no actionable findings.
  • Tests use fake stores only, never real credentials or input.

No claim of physical Secret Service durability, transactional replacement or subscriber isolation. Production integration still requires bounded off-main-thread operations and hardware qualification. Independent of #719, targets linux-support; not merged or released.

@enaboapps

Copy link
Copy Markdown
Contributor Author

Independent latest-head review of db48185: no actionable findings. Reviewer confirmed Linux-only production selection, stable identity, serialization, read-back verification, sanitized errors and non-destructive failure behavior. Formatting passed; native compilation/tests still depend on CI because this host lacks development libraries.

@enaboapps
enaboapps marked this pull request as ready for review September 11, 2026 16:12
@greptile-apps

greptile-apps Bot commented Sep 11, 2026

Copy link
Copy Markdown

Greptile Summary

This change adds a Linux-specific credential-store wrapper that serializes access, rejects empty values, verifies writes through read-back, and returns a safe remediation message instead of backend details. It also documents the operating constraints and remaining readiness work for Linux credential storage.

T-Rex validation blocked

The focused credential recovery check could not compile because the environment lacks the GDK 3 development metadata file (gdk-3.0.pc). No defect was established.

Confidence Score: 5/5

No confirmed issue prevents merging this change.

No confirmed findings were produced. The focused runtime check was blocked before its test binary could be built because a required system development dependency is unavailable.

Files Needing Attention: No source file requires follow-up from this review; Linux credential recovery should be exercised in an environment with the required native desktop libraries before Linux pairing is enabled.

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex attempted the focused credential recovery test to verify preservation of pairing metadata during credential-store failure and restoration after recovery.
  • The test could not progress to compilation because pkg-config could not locate gdk-3.0.pc, so the test binary was not built and the runtime path was not executed.
  • Cargo output confirmed the environment blocker: pkg-config failed to find gdk-3.0.pc with PKG_CONFIG_PATH unset, and no source code changes were made.

View all artifacts

T-Rex Ran code and verified through T-Rex

Important Files Changed

Filename Overview
src-tauri/src/storage.rs Adds a Linux credential-store wrapper with serialized operations, verified writes, and safe error handling.
docs/linux-credentials.md Documents Linux credential-storage behavior, limitations, validation coverage, and remaining enablement gates.

Reviews (1): Last reviewed commit: "fix: harden Linux pairing credential sto..." | Re-trigger Greptile

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant