Skip to content

Preserve CLAUDE_SECURESTORAGE_CONFIG_DIR across agent restore - #9419

Merged
austinywang merged 3 commits into
mainfrom
issue-9412-restored-claude-agents-lose-their-accoun
Aug 3, 2026
Merged

austinywang merged 3 commits into
mainfrom
issue-9412-restored-claude-agents-lose-their-accoun

Conversation

@austinywang

@austinywang austinywang commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #9412

Restored Claude agents fell back to the ambient account because CLAUDE_SECURESTORAGE_CONFIG_DIR, the variable that selects which directory holds .credentials.json, was not in safeEnvironmentKeys. sanitizedValue drops any key missing from that set, so the value was discarded at capture time and the replayed environment carried nothing. CODEX_HOME is allowlisted, which is why Codex sessions restored correctly and Claude ones did not.

Mechanism

Added "CLAUDE_SECURESTORAGE_CONFIG_DIR" to safeEnvironmentKeys in Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/AgentLaunchEnvironmentPolicy.swift, beside CLAUDE_CONFIG_DIR. It falls through sanitizedValue's default branch unmodified, which is right: it is a directory path, not a secret, and cmux has no reason to rewrite it. Principled fix, one line at the actual gate. Residual risk is that the variable is undocumented by Anthropic and could change name; an allowlist entry for an unset variable is inert, so the cost is bounded.

Deliberately not adding it to claudeAuthKeys in CLI/cmux.swift. That list exists to tell Resources/bin/cmux-claude-wrapper not to scrub keys it would otherwise strip, and the wrapper's CLAUDE_AUTH_SELECTION_ENV_KEYS never touches CLAUDE_SECURESTORAGE_CONFIG_DIR, so an entry there would be inert. This confirms the open question in the issue.

Symphony verification

Regression test: ClaudeSecureStorageConfigDirectoryPolicyTests in Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/AgentLaunchEnvironmentPolicyTests.swift (two cases: capture via selectedEnvironment(from:kind:) keeps the path while ANTHROPIC_AUTH_TOKEN is still dropped, and sanitizedValue returns it unchanged).

Two commits so CI shows red then green:

  • commit 1, test only. cd Packages/macOS/CMUXAgentLaunch && swift test --filter ClaudeSecureStorageConfigDirectoryPolicyTests -> Test run with 2 tests in 1 suite failed, both expectations returning nil.
  • commit 2, fix. cd Packages/macOS/CMUXAgentLaunch && swift test -> Test run with 281 tests in 40 suites passed.

Package-only change with no Swift app or UI surface, so no tagged reload or e2e workflow run.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Preserves Claude agent account on restore by keeping CLAUDE_SECURESTORAGE_CONFIG_DIR in the captured and replayed environment.

  • Bug Fixes
    • Allowlist CLAUDE_SECURESTORAGE_CONFIG_DIR in AgentLaunchEnvironmentPolicy so restored agents don’t switch to the default account.
    • Add dedicated ClaudeSecureStorageConfigDirectoryPolicyTests verifying the path is preserved and ANTHROPIC_AUTH_TOKEN is still dropped.

Written for commit b024fef. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes

    • Preserved Claude Code’s secure storage configuration directory when restoring agent sessions.
    • Continued excluding sensitive authentication tokens from captured environment data.
  • Tests

    • Added coverage verifying directory preservation, value handling, and authentication token protection.

austinywang and others added 2 commits August 2, 2026 19:02
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The launch environment allowlist now preserves CLAUDE_SECURESTORAGE_CONFIG_DIR during agent restoration. Tests verify that the directory is retained, its value is unchanged, and ANTHROPIC_AUTH_TOKEN remains excluded.

Changes

Claude secure storage restoration

Layer / File(s) Summary
Preserve Claude secure storage directory
Packages/macOS/CMUXAgentLaunch/Sources/CMUXAgentLaunch/AgentLaunchEnvironmentPolicy.swift, Packages/macOS/CMUXAgentLaunch/Tests/CMUXAgentLaunchTests/ClaudeSecureStorageConfigDirectoryPolicyTests.swift
The environment policy allowlists CLAUDE_SECURESTORAGE_CONFIG_DIR. Tests verify directory retention, auth-token removal, and unchanged sanitization.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • manaflow-ai/cmux#9265: Both changes modify the environment variables preserved during agent restoration.
  • manaflow-ai/cmux#9372: Both changes allowlist Claude-specific environment variables in AgentLaunchEnvironmentPolicy.swift.
  • manaflow-ai/cmux#9416: Both changes extend the same allowlist and add focused preservation tests.
🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes satisfy issue #9412 by allowlisting and preserving CLAUDE_SECURESTORAGE_CONFIG_DIR while continuing to exclude ANTHROPIC_AUTH_TOKEN.
Out of Scope Changes check ✅ Passed The changes are limited to the requested environment allowlist update and focused regression tests for issue #9412.
Cmux Swift Actor Isolation ✅ Passed Production diff only adds a comment and an environment-key string inside the existing Sendable policy; no actor, protocol, model, store, or background-access isolation changes. Added code is tests.
Cmux Swift Blocking Runtime ✅ Passed The production diff adds only an environment-key string and comments; added tests are deterministic. No semaphore, wait, sleep, delayed dispatch, polling, sync, or lock APIs were added.
Cmux Browser Automation Off-Main ✅ Passed The PR changes only Claude launch-environment policy and tests; no browser socket commands, WebKit/AppKit routing, worker methods, or browser automation symbols changed.
Cmux Expensive Synchronous Load ✅ Passed The PR only adds an environment-key allowlist entry and relocates/adds policy tests; it introduces no agent-history loader, file parsing, syscall loop, or interactive/main-actor path.
Cmux Cache Substitution Correctness ✅ Passed The diff only adds an environment allowlist entry and regression tests; it does not replace any authoritative read with a cached or opportunistic value.
Cmux No Hacky Sleeps ✅ Passed The PR changes only Swift source and Swift tests; the cumulative diff adds no sleep, timer, polling, delay, or wall-clock synchronization code.
Cmux Algorithmic Complexity ✅ Passed The production diff adds one entry to a static allowlist; it introduces no nested scans, rescans, sorting/filtering loop, join, or slower scalable algorithm.
Cmux Swift Concurrency ✅ Passed The PR adds only an environment-key entry, documentation, and synchronous Swift Testing coverage; it introduces no Dispatch, Combine, completion-handler, or fire-and-forget Task patterns.
Cmux Swift @Concurrent ✅ Passed The Swift diff adds only a static allowlist entry and synchronous tests; no async, nonisolated, @concurrent, or actor-isolated code or call sites changed.
Cmux Swift Package Boundaries ✅ Passed The production change stays in the existing CMUXAgentLaunch SwiftPM target, with tests in its test target; it adds no app-target logic or new package-boundary violation.
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only Swift source and test files; it does not change Package.swift dependencies, Xcode package references, or .gitignore files.
Cmux Swift Logging ✅ Passed The PR adds only an environment allowlist entry/comment in runtime Swift and regression tests; it adds no print, debugPrint, dump, NSLog, Logger, or diagnostic logging.
Cmux User-Facing Error Privacy ✅ Passed The production diff only allowlists an environment variable and adds a developer comment; tests contain the token fixture. It adds no user-facing error, alert, output, or recovery text.
Cmux Full Internationalization ✅ Passed The diff adds only the literal environment key, a developer-only comment, and regression tests; it introduces no user-facing text, localization keys, catalogs, or web locale data.
Cmux Swiftui State Layout ✅ Passed The complete diff only changes an environment-policy allowlist and package tests; it adds no SwiftUI views, state, GeometryReader, lazy rows, or render-time mutation.
Cmux Architecture Rethink ✅ Passed The PR makes a local allowlist fix and moves tests; the existing policy remains the single owner, with no timing, polling, locks, observers, duplicate wiring, or split UI lifecycle.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The PR changes only CMUXAgentLaunch environment policy and test files; it adds no NSWindow, NSPanel, SwiftUI window, shortcut, or auxiliary-window registration code.
Cmux Source Artifacts ✅ Passed The PR changes only a Swift source policy file and a Swift regression-test file; neither is local output, generated artifact, cache, build output, or scratch directory.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The only production change adds an environment key and comment; no DEBUG guard, test/debug accessor, or widened visibility was added. New test code is under Tests/.
Cmux No Ambient Global State ✅ Passed Production diff only adds a key and comment to the existing private static let safeEnvironmentKeys; it adds no global function, mutable state, namespace type, or singleton.
Title check ✅ Passed The title clearly and concisely describes the primary change: preserving CLAUDE_SECURESTORAGE_CONFIG_DIR during agent restore.
Description check ✅ Passed The description explains the issue, implementation, rationale, regression tests, and verification results; omitted template checklist items are non-critical.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch issue-9412-restored-claude-agents-lose-their-accoun

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@austinywang
austinywang merged commit 4de8711 into main Aug 3, 2026
6 checks passed
@austinywang
austinywang deleted the issue-9412-restored-claude-agents-lose-their-accoun branch August 3, 2026 02:17
@austinywang austinywang mentioned this pull request Aug 3, 2026
@coderabbitai coderabbitai Bot mentioned this pull request Aug 7, 2026
4 of 5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Restored Claude agents lose their account: CLAUDE_SECURESTORAGE_CONFIG_DIR is dropped by the launch-env allowlist

1 participant