Visitar URL original
fix(keychain): drain timed-out sessions before disconnecting by Benehiko · Pull Request #668 · docker/secrets-engine · GitHub
Skip to content

fix(keychain): drain timed-out sessions before disconnecting - #668

Draft
Benehiko wants to merge 1 commit into
mainfrom
fix/keychain-session-timeout
Draft

Benehiko wants to merge 1 commit into
mainfrom
fix/keychain-session-timeout

Conversation

@Benehiko

@Benehiko Benehiko commented Oct 5, 2026

Copy link
Copy Markdown
Member

Linux keychain operations currently return an OpenSession timeout after 10 seconds and immediately close their private D-Bus connection, even though the backend may still be negotiating the session. The worker also leaks when it later sends its result to an unbuffered channel whose receiver has returned. This matches the suspected client-side trigger in docker/sbx-releases#663.

Keep the caller's timeout, but defer connection teardown until outstanding session requests finish. Drain late replies, explicitly close sessions returned after a timeout, and reject new negotiations once Close has been requested. The completion path handles both backend errors and disconnects without leaving a worker blocked on result delivery.

Connection/session reuse remains tracked separately in #648. A backend that never replies can retain a connection and its pending worker until a reply or transport failure; cancellation of the connection's owning context and process termination can still disconnect it. Production store operations already detach their connection context from caller cancellation.

GNOME Keyring versions

Version Evidence
40 The SBX reporter observed the crash on Linux Mint 21.3. Exact package revision unspecified.
46.1, package 46.1-2ubuntu0.2 The same reporter observed it after upgrading to Mint 22.3. This is also the version used for our isolated integration tests.
50.0, package 1:50.0-1 HEY CLI #352 reports the same missing-client/null-reply OpenSession crash family, using plain negotiation.
51.1 Potentially affected based on source inspection: negotiation can still fail without setting an error, and the reply handler can still use null results. A crash on this release has not been reproduced here.

These are reports and source evidence, not a tested affected-version range. We have not established the earliest affected version or verified a fixed GNOME Keyring release. The GNOME daemon crash itself was not reproduced during our investigation; this PR fixes the demonstrated premature disconnect and abandoned-result bugs without claiming that it resolves every trigger of the daemon crash.

Validation

  • The new private-D-Bus regressions fail against the original implementation at 28a231d: the connection closes with outstanding requests, and late sessions are not cleaned up.
  • Vee Linux VM: Ubuntu 24.04, arm64, kernel 6.8.0-142-generic, GNOME Keyring 46.1-2ubuntu0.2, GLib 2.80.0-6ubuntu3.9, Go 1.25.13.
  • Passed ten consecutive race-enabled runs of the timeout regressions, covering late success/error, multiple outstanding requests, cleanup before disconnect, reuse after a timeout, and backend disconnect.
  • Passed make keychain-unit-tests with the race detector on a private session bus and temporary keyring in the VM.
  • Passed the Secret Service package's unit tests with the race detector on macOS.
  • Pinned golangci-lint v2.12.2 and repository formatter checks for the changed package.
Avoid prematurely disconnecting pending Linux keychain session requests after a timeout.

Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant