git.lucas.co / cce-compositor
Wayland compositor (wlroots)
git clone https://git.lucas.co/cce-compositor.git

commit359b99984c731ef12201234d8dcca2dfd8cc2e46
parent24b6584431
authorLucas Galante <lsgalante12@gmail.com>
date2026-10-01 20:02
cce-shadow: cce-secrets is shadow-safe, but browse only

The usage text listed cce-secrets as unsafe in a shadow for owning the
Secret Service name. That stopped being true with the 2026-08-29 keyring
migration: gnome-keyring owns org.freedesktop.secrets, and cce-secrets is
a plain client (the secret-service crate; it requests no bus name). It
ran in a shadow on 2026-10-01 without trouble.

The real hazard is the shared session bus and XDG_RUNTIME_DIR: a shadow
cce-secrets lists and can edit the LIVE keyring. Say that instead, and
point at CCE_KEYRING_SYNC_SOCK for testing one-time codes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

 scripts/cce-shadow | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/scripts/cce-shadow b/scripts/cce-shadow
index 90c23216..137e1760 100755
--- a/scripts/cce-shadow
+++ b/scripts/cce-shadow
@@ -267,8 +267,13 @@ default instance is "default"; CCE_SHADOW_INSTANCE sets it for a whole shell.
   env                 print the environment as shell exports
 
 Do not run inside the shadow: cce-authenticator (claims the PolicyKit D-Bus
-name), cce-secrets (Secret Service), cce-remote (binds 0.0.0.0:17017). Every
-other cce app is safe; cce-cloud's daemon socket is already display-keyed.
+name), cce-remote (binds 0.0.0.0:17017). Every other cce app is safe;
+cce-cloud's daemon socket is already display-keyed.
+
+cce-secrets runs, but browse only: the shadow shares the live session bus and
+XDG_RUNTIME_DIR, so it lists and can EDIT the live keyring. To test one-time
+codes, point CCE_KEYRING_SYNC_SOCK at a stand-in socket (cce-secrets/
+KEYRING-SYNC.md, "One-time codes in cce-secrets").
 EOF
 }