Wayland compositor (wlroots)
git clone https://git.lucas.co/cce-compositor.git
cce-shadow: cce-secrets is shadow-safe, but browse only
The usage text listed cce-secrets as unsafe in a shadow for owning the
Secret Service name. That stopped being true with the 2026-08-29 keyring
migration: gnome-keyring owns org.freedesktop.secrets, and cce-secrets is
a plain client (the secret-service crate; it requests no bus name). It
ran in a shadow on 2026-10-01 without trouble.
The real hazard is the shared session bus and XDG_RUNTIME_DIR: a shadow
cce-secrets lists and can edit the LIVE keyring. Say that instead, and
point at CCE_KEYRING_SYNC_SOCK for testing one-time codes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/cce-shadow | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/scripts/cce-shadow b/scripts/cce-shadow
index 90c23216..137e1760 100755
--- a/scripts/cce-shadow
+++ b/scripts/cce-shadow
@@ -267,8 +267,13 @@ default instance is "default"; CCE_SHADOW_INSTANCE sets it for a whole shell.
env print the environment as shell exports
Do not run inside the shadow: cce-authenticator (claims the PolicyKit D-Bus
-name), cce-secrets (Secret Service), cce-remote (binds 0.0.0.0:17017). Every
-other cce app is safe; cce-cloud's daemon socket is already display-keyed.
+name), cce-remote (binds 0.0.0.0:17017). Every other cce app is safe;
+cce-cloud's daemon socket is already display-keyed.
+
+cce-secrets runs, but browse only: the shadow shares the live session bus and
+XDG_RUNTIME_DIR, so it lists and can EDIT the live keyring. To test one-time
+codes, point CCE_KEYRING_SYNC_SOCK at a stand-in socket (cce-secrets/
+KEYRING-SYNC.md, "One-time codes in cce-secrets").
EOF
}