Skip to content

reauth journal FilePin check fails after volume remount (st_dev drift) and blocks session refresh #268

Description

@0thernet

What happened

On macOS, the ~/.local/share/xcb volume was remounted/recreated (routine sleep/wake or system remount). File contents, inodes, and ctimes were identical; only st_dev changed (e.g. 16777233 → 16777231).

The committed reauth.json journal records FilePins (digest, device, inode, ctime) for device.json and account.json. FilePin.check compares all fields, so after the remount every Snapshot::load fails with Error::Conflict("relay sign-in state changed; credentials were not replaced").

Impact

  • xcb link --reauth fails immediately (before the email prompt) on completed(), resume(), and prepare() — all call Snapshot::load.
  • custody::permit_refresh propagates the same error, so the supervisor's routine session refresh fails; the session JWT expired and the relay lane went unauthenticated until the journal was removed.

Observed on xcb 0.10.5 with journal phase committed (the reauth had already succeeded — operation 01a0e885-b086-77a2-bf6a-52676a76bda2).

Recovery used

The completed journal was moved out of cloud/ (preserved in evidence); Snapshot::load → None → permit_refresh passed and the next supervisor refresh immediately wrote a new token with the committed session identity.

Possible directions

  • Journal::check could skip original.check_keys/check_session when phase == Committed — a committed operation's preconditions are spent; relay_state re-validates identity/result from live data anyway.
  • FilePin.check could tolerate dev drift when digest + inode + ctime all match — but that weakens the "identical bytes transplanted to another filesystem" guarantee, so it's a design call.
  • Snapshot::load could distinguish "journal exists but failed integrity" from "no journal" so refresh isn't poisoned by a finished record.

Repro path: xcb link --reauth to completion → remount the state volume (or restore the cloud dir onto a new filesystem preserving inode/ctime) → run xcb link --reauth or wait for session refresh.

Generated with Devin

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions