Repository navigation
Conversation
Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linux keychain operations currently return an
OpenSessiontimeout after 10 seconds and immediately close their private D-Bus connection, even though the backend may still be negotiating the session. The worker also leaks when it later sends its result to an unbuffered channel whose receiver has returned. This matches the suspected client-side trigger in docker/sbx-releases#663.Keep the caller's timeout, but defer connection teardown until outstanding session requests finish. Drain late replies, explicitly close sessions returned after a timeout, and reject new negotiations once
Closehas been requested. The completion path handles both backend errors and disconnects without leaving a worker blocked on result delivery.Connection/session reuse remains tracked separately in #648. A backend that never replies can retain a connection and its pending worker until a reply or transport failure; cancellation of the connection's owning context and process termination can still disconnect it. Production store operations already detach their connection context from caller cancellation.
GNOME Keyring versions
46.1-2ubuntu0.21:50.0-1OpenSessioncrash family, using plain negotiation.These are reports and source evidence, not a tested affected-version range. We have not established the earliest affected version or verified a fixed GNOME Keyring release. The GNOME daemon crash itself was not reproduced during our investigation; this PR fixes the demonstrated premature disconnect and abandoned-result bugs without claiming that it resolves every trigger of the daemon crash.
Validation
28a231d: the connection closes with outstanding requests, and late sessions are not cleaned up.6.8.0-142-generic, GNOME Keyring46.1-2ubuntu0.2, GLib2.80.0-6ubuntu3.9, Go1.25.13.make keychain-unit-testswith the race detector on a private session bus and temporary keyring in the VM.golangci-lint v2.12.2and repository formatter checks for the changed package.