Skip to content

Keep Linux secrets across a reboot (R71) - #101

Merged
LucaCappelletti94 merged 7 commits into
mainfrom
feat/r71-linux-key-custody
Sep 29, 2026
Merged

LucaCappelletti94 merged 7 commits into
mainfrom
feat/r71-linux-key-custody

Conversation

@LucaCappelletti94

Copy link
Copy Markdown
Owner

On Linux the replica key and the refresh token lived in the kernel session keyring, which a reboot empties, so a rebooted device lost its device-local data to its own encryption. They now live in a store that survives: the desktop's Secret Service through oo7, libsecret's sandbox keyring inside a Flatpak or Snap, or files sealed under a wrap key the operator hands over as a systemd credential or, in a container, as a mounted key file. A locked or missing desktop keyring is unlocked or created through the desktop's own dialog within a time limit, and rotating the wrap key reseals every record once.

The refresh-token store now awaits like the key store, so no Secret Service call holds a runtime thread, and the workspace's minimum Rust version rises to 1.92 for oo7. Three recorded manual runs on real desktops remain, for a GNOME unlock dialog, KDE Wallet and a Flatpak build.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: LucaCappelletti94/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1b865c4e-84fb-4c0c-b433-83f5896632fd


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.06683% with 100 lines in your changes missing coverage. Please review.
✅ Project coverage is 84.62%. Comparing base (2d4e895) to head (41860c6).
⚠️ Report is 4 commits behind head on main.

Files with missing lines Patch % Lines
...onnetto-client/src/keyring/linux/secret_service.rs 80.27% 2 Missing and 27 partials ⚠️
crates/connetto-client/src/keyring/linux/sealed.rs 90.15% 0 Missing and 19 partials ⚠️
crates/connetto-client/src/keyring/linux/mod.rs 90.86% 2 Missing and 16 partials ⚠️
...rates/connetto-client/src/keyring/linux/sandbox.rs 85.43% 4 Missing and 11 partials ⚠️
crates/connetto-client/src/auth.rs 83.52% 0 Missing and 14 partials ⚠️
crates/connetto-client/src/bin/connetto-client.rs 90.19% 0 Missing and 5 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #101      +/-   ##
==========================================
+ Coverage   84.21%   84.62%   +0.41%     
==========================================
  Files         125      130       +5     
  Lines       30472    31240     +768     
  Branches    30472    31240     +768     
==========================================
+ Hits        25661    26436     +775     
+ Misses       3366     3283      -83     
- Partials     1445     1521      +76     
Flag Coverage Δ
client 62.74% <85.91%> (+1.01%) ⬆️
rest 58.13% <3.03%> (+0.05%) ⬆️
server 53.00% <11.20%> (+2.07%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sonarqubecloud

Copy link
Copy Markdown

@LucaCappelletti94
LucaCappelletti94 merged commit a3c28ae into main Sep 29, 2026
61 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant