Keep Linux secrets across a reboot (R71) - #101
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: LucaCappelletti94/coderabbit/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #101 +/- ##
==========================================
+ Coverage 84.21% 84.62% +0.41%
==========================================
Files 125 130 +5
Lines 30472 31240 +768
Branches 30472 31240 +768
==========================================
+ Hits 25661 26436 +775
+ Misses 3366 3283 -83
- Partials 1445 1521 +76
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|



On Linux the replica key and the refresh token lived in the kernel session keyring, which a reboot empties, so a rebooted device lost its device-local data to its own encryption. They now live in a store that survives: the desktop's Secret Service through oo7, libsecret's sandbox keyring inside a Flatpak or Snap, or files sealed under a wrap key the operator hands over as a systemd credential or, in a container, as a mounted key file. A locked or missing desktop keyring is unlocked or created through the desktop's own dialog within a time limit, and rotating the wrap key reseals every record once.
The refresh-token store now awaits like the key store, so no Secret Service call holds a runtime thread, and the workspace's minimum Rust version rises to 1.92 for oo7. Three recorded manual runs on real desktops remain, for a GNOME unlock dialog, KDE Wallet and a Flatpak build.