Conversation
The Linux kernel keyring (keyctl/add_key/request_key) is blocked by the default Docker seccomp profile, so users running the container on Docker Desktop for Mac without --security-opt seccomp=seccomp/keyring.json would get a runtime error even though the binary compiled fine. Add `use_keyring: bool` (default true) to Config. When false, the in-memory key store is used even on Linux, making the seccomp profile optional. - SecretKey::store / retrieve take use_keyring; dispatch picks keyring or memory at runtime on Linux, always uses memory on other platforms - memory module is now always compiled (was guarded by cfg(not(linux))) - config.yml documents the option and its Docker-on-macOS use case - keepass tests pass use_keyring=false so they do not require a real keyring Fixes lixmal#227
allamiro
force-pushed
the
upstream/feat-keyring-config
branch
from
August 26, 2026 13:51
3b0de8d to
196f640
Compare
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Owner
Owner
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #227
Supersedes #311 (this PR includes that work plus adds the config option)
Problem
Issue #227 has two distinct parts:
Native macOS compilation —
linux-keyutilswas an unconditional dependency, so the binary wouldn't compile outside Linux. This was the scope of feat: abstract key storage, in-memory fallback for non-linux platforms #311.Docker container on macOS (the remaining gap) — even with a Linux binary, users running Docker Desktop on macOS may not have the
keyctl/add_key/request_keysyscalls available, or may not know to pass--security-opt seccomp=seccomp/keyring.json. This makes the container fail at runtime with a non-obvious error.Solution
Add
use_keyring: bool(defaulttrue) to Config. Whenfalse, the in-memory key store is used even on Linux, making the seccomp profile optional for deployments where the kernel keyring is unavailable or undesired.This PR includes the full key-store abstraction from #311 (split into
keyring.rs+memory.rsmodules,linux-keyutilsmoved to Linux-only target dep) and builds on top of it with the runtime dispatch.Changes
SecretKey::store/SecretKey::retrieveacceptuse_keyring: bool; dispatch picks keyring or memory at runtime on Linux, always memory on other platformsmemorymodule always compiled (wascfg(not(linux))),keyringmodule Linux-onlylinux-keyutilsmoved to[target.'cfg(target_os = "linux")'.dependencies]config.ymldocuments the option and its Docker-on-macOS use caseuse_keyring=falseso they run without real keyring privilegesread_to_vec()instead of fixed 32-byte buffer (from Bump regex from 1.10.0 to 1.10.2 #21/Bump core-js from 3.33.0 to 3.33.1 #22 — avoids corrupting non-32-byte keys)Testing
cargo test— 9/9 pass on Linux inside Docker (keyring not available in the test container)