Skip to content

fix(config): serialize secret mutations - #11388

Merged
jbg merged 3 commits into
mainfrom
jbg/security-secret-revocation-race
Aug 20, 2026
Merged

jbg merged 3 commits into
mainfrom
jbg/security-secret-revocation-race

Conversation

@jbg

@jbg jbg commented Aug 20, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • serialize secret-store mutations across Goose processes
  • reload the latest persisted secret map while holding the mutation lock
  • atomically replace file-backed secret storage instead of truncating it in place
  • preserve direct absolute and relative secret-storage symlinks while replacing their managed target

This prevents a process with a stale in-memory snapshot from restoring a credential that another process has revoked. It preserves existing read-cache behavior; only mutations refresh from authoritative storage.

Verification

  • cargo fmt --all -- --check
  • cargo test -p goose providers::private_file::tests --lib -- --nocapture (2 passed)
  • cargo test -p goose config::base::tests --lib -- --nocapture (62 passed)
  • cargo build -p goose
  • cargo clippy -p goose --all-targets -- -D warnings
  • git diff --check

This finding was discovered by Project Loupe

Signed-off-by: Jasper Hugo <jasper@spiral.xyz>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b48dfd337

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/config/base.rs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fa492bb39f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/providers/private_file.rs Outdated
Comment thread crates/goose/src/config/base.rs Outdated
Signed-off-by: Jasper Hugo <jasper@spiral.xyz>
@jbg
jbg requested review from DOsinga and jamadeo August 20, 2026 12:06

@DOsinga DOsinga left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the changed files locally. The storage-level lock and reload prevent stale secret caches from restoring revoked credentials, and the follow-up commits address Codex’s relative-path, chained-symlink, and lock-alias findings with regression coverage. CI is green.

@jbg
jbg added this pull request to the merge queue Aug 20, 2026
Merged via the queue into main with commit 0ed7b02 Aug 20, 2026
25 checks passed
@jbg
jbg deleted the jbg/security-secret-revocation-race branch August 20, 2026 14:25
alexhancock added a commit that referenced this pull request Aug 20, 2026
…bined

* origin/main: (85 commits)
  feat(desktop): sort configured providers to the top of the provider list (#11409)
  fix(cli): refuse symlink diagnostics outputs (#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (#11407)
  fix(config): serialize secret mutations (#11388)
  fix: decouple source file and tool response limits (#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (#11245)
  fix(security): suppress sensitive OTLP traces (#11381)
  feat(openrouter): forward session_id and add app category header (#10868)
  feat(acp): derive and forward thinking effort from the ACP harness (#10949)
  fix(aws_bedrock): replace flat model list with routing table, add Gemma 4 Mantle support (#10297)
  Add GPT-5.6 follow-up support for Codex and Responses API (#10460)
  fix(update): fetch attestation bundles from bundle_url (#10557)
  fix(security): fail closed on invalid default GCP credentials (#11363)
  fix(codex): reject socket-backed MCP extensions (#11304)
  fix: pass complete response to stop hooks (#11366)
  fix: contain and bound skill supporting file reads (#11342)
  chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386)
  fix(security): bound call graph traversal (#11193)
  fix: pin arrayref to known-good commit (#11389)
  feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267)
  ...

# Conflicts:
#	crates/goose/src/agents/agent.rs
lifeizhou-ap added a commit that referenced this pull request Aug 21, 2026
* main: (70 commits)
  cli: remove recipe secret discovery (#11435)
  fix(openrouter): escape Gemini tool response ref keys (#11276)
  fix(security): honor MCP tool model visibility in Code Mode (#11425)
  fix(providers): estimate cost for Azure Foundry models via inferred catalog pricing (#11264)
  feat(providers): add Gondola as declarative OpenAI-compatible provider (#11421)
  feat(otel): add request params, response metadata, tool call parity, and agent identification (#11261)
  fix(providers): coalesce consecutive Thinking blocks in collect_stream (#11317)
  feat(hooks): add PreToolUseResult event and stable tool_call_id across tool lifecycle (#11120)
  add MCP conformance tests to goose CI (combines #10800 + #10801) (#10940)
  feat(desktop): sort configured providers to the top of the provider list (#11409)
  fix(cli): refuse symlink diagnostics outputs (#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (#11407)
  fix(config): serialize secret mutations (#11388)
  fix: decouple source file and tool response limits (#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (#11245)
  fix(security): suppress sensitive OTLP traces (#11381)
  feat(openrouter): forward session_id and add app category header (#10868)
  feat(acp): derive and forward thinking effort from the ACP harness (#10949)
  fix(aws_bedrock): replace flat model list with routing table, add Gemma 4 Mantle support (#10297)
  Add GPT-5.6 follow-up support for Codex and Responses API (#10460)
  ...
lifeizhou-ap added a commit to Wolfe-Jam/goose that referenced this pull request Aug 21, 2026
* main: (107 commits)
  fix(providers): inform user of clipboard copy and remove copilot auth retry on timeout (aaif-goose#11160)
  feat(desktop): select saved recipes when creating a schedule (aaif-goose#10892)
  More provider test scripts (aaif-goose#10515)
  cli: remove recipe secret discovery (aaif-goose#11435)
  fix(openrouter): escape Gemini tool response ref keys (aaif-goose#11276)
  fix(security): honor MCP tool model visibility in Code Mode (aaif-goose#11425)
  fix(providers): estimate cost for Azure Foundry models via inferred catalog pricing (aaif-goose#11264)
  feat(providers): add Gondola as declarative OpenAI-compatible provider (aaif-goose#11421)
  feat(otel): add request params, response metadata, tool call parity, and agent identification (aaif-goose#11261)
  fix(providers): coalesce consecutive Thinking blocks in collect_stream (aaif-goose#11317)
  feat(hooks): add PreToolUseResult event and stable tool_call_id across tool lifecycle (aaif-goose#11120)
  add MCP conformance tests to goose CI (combines aaif-goose#10800 + aaif-goose#10801) (aaif-goose#10940)
  feat(desktop): sort configured providers to the top of the provider list (aaif-goose#11409)
  fix(cli): refuse symlink diagnostics outputs (aaif-goose#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (aaif-goose#11407)
  fix(config): serialize secret mutations (aaif-goose#11388)
  fix: decouple source file and tool response limits (aaif-goose#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (aaif-goose#11245)
  fix(security): suppress sensitive OTLP traces (aaif-goose#11381)
  feat(openrouter): forward session_id and add app category header (aaif-goose#10868)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants