Skip to content

fix: fall back to Linux kernel keyring on headless boxes - #74

Merged
oxGrad merged 2 commits into
mainfrom
fix/headless-keyring-fallback
Sep 26, 2026
Merged

oxGrad merged 2 commits into
mainfrom
fix/headless-keyring-fallback

Conversation

@oxGrad

@oxGrad oxGrad commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • mynd up crashed on a headless Raspberry Pi because Hive's device-identity bootstrap needs the OS keyring, and on Linux the keyring crate only ever wires up the D-Bus secret service — unreachable with no desktop session — which killed the whole process and left systemd stuck restarting it forever (activating (auto-restart)).
  • Replaced the keyring crate with keyring-core + explicit backends (src/secure_store.rs): try the D-Bus secret service, fall back to the Linux kernel keyring (keyutils) when it's unreachable. Also stopped a failed Hive bootstrap from taking down the whole server — it now just disables Hive Mode for that run instead, mirroring the existing sync+hive conflict handling in http.rs.
  • Documented the fallback and its reboot trade-off (kernel keyring is in-memory only) in the README and HIVE_PAIRING.md, and surfaced it from mynd up's startup log and mynd service install's output.

Test plan

  • cargo check --lib
  • cargo test --lib (668 passed, 0 failed on the changed code paths; the 33 filtered-out failures are pre-existing opencode-CLI-dependent tests that also fail on unmodified main in this sandbox)
  • Rebuild on the affected Raspberry Pi and confirm mynd up --headless starts and systemctl --user status mynd reaches active (running)

…s reachable

mynd up crashed on headless Linux boxes (e.g. a Raspberry Pi with no desktop
session): Hive's device-identity bootstrap uses the OS keyring, the keyring
crate's v1 API only ever wires up the D-Bus secret service on Linux, and a
missing secret service made the whole server exit(1), which systemd then
restarted forever (activating (auto-restart)).

Replace the keyring crate with keyring-core plus explicit backends
(src/secure_store.rs): try the D-Bus secret service first, fall back to the
Linux kernel keyring (keyutils) when it's unreachable. Also stop a failed
Hive bootstrap from taking down the whole process -- it now just disables
Hive Mode for that run, matching the existing sync+hive conflict handling
right above it in http.rs.

Document the fallback and its reboot trade-off in the README and
HIVE_PAIRING.md, and surface it from mynd up and mynd service install.
@oxGrad
oxGrad merged commit 422b80c into main Sep 26, 2026
1 check passed
@oxGrad
oxGrad deleted the fix/headless-keyring-fallback branch September 26, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant