fix: fall back to Linux kernel keyring on headless boxes - #74
Merged
Merged
Conversation
…s reachable mynd up crashed on headless Linux boxes (e.g. a Raspberry Pi with no desktop session): Hive's device-identity bootstrap uses the OS keyring, the keyring crate's v1 API only ever wires up the D-Bus secret service on Linux, and a missing secret service made the whole server exit(1), which systemd then restarted forever (activating (auto-restart)). Replace the keyring crate with keyring-core plus explicit backends (src/secure_store.rs): try the D-Bus secret service first, fall back to the Linux kernel keyring (keyutils) when it's unreachable. Also stop a failed Hive bootstrap from taking down the whole process -- it now just disables Hive Mode for that run, matching the existing sync+hive conflict handling right above it in http.rs. Document the fallback and its reboot trade-off in the README and HIVE_PAIRING.md, and surface it from mynd up and mynd service install.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
mynd upcrashed on a headless Raspberry Pi because Hive's device-identity bootstrap needs the OS keyring, and on Linux thekeyringcrate only ever wires up the D-Bus secret service — unreachable with no desktop session — which killed the whole process and left systemd stuck restarting it forever (activating (auto-restart)).keyringcrate withkeyring-core+ explicit backends (src/secure_store.rs): try the D-Bus secret service, fall back to the Linux kernel keyring (keyutils) when it's unreachable. Also stopped a failed Hive bootstrap from taking down the whole server — it now just disables Hive Mode for that run instead, mirroring the existing sync+hive conflict handling inhttp.rs.HIVE_PAIRING.md, and surfaced it frommynd up's startup log andmynd service install's output.Test plan
cargo check --libcargo test --lib(668 passed, 0 failed on the changed code paths; the 33 filtered-out failures are pre-existingopencode-CLI-dependent tests that also fail on unmodifiedmainin this sandbox)mynd up --headlessstarts andsystemctl --user status myndreachesactive (running)