Skip to content

client: prevent duplicate secrets when updating imported items - #578

Merged
bilelmoussaoui merged 2 commits into
linux-credentials:mainfrom
mineiro:fix-migrated-secret-replacement
Sep 25, 2026
Merged

bilelmoussaoui merged 2 commits into
linux-credentials:mainfrom
mineiro:fix-migrated-secret-replacement

Conversation

@mineiro

@mineiro mineiro commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Summary

Imported secrets can have a different content type from their updates. That difference prevented replacement and left a duplicate item.

Ignore xdg:content-type when matching an item for replacement. All other attributes must still match exactly. Add file backend and D-Bus collection regressions.

Testing

  • Focused replacement tests passed with native crypto and OpenSSL.
  • cargo fmt --all --check and git diff --check passed.

An imported secret can have a different content type from its update.
Ignore that difference when finding the item to replace.
Comment thread client/src/file/api/encrypted_item.rs Outdated
let attributes = attributes.as_attributes();
self.hashed_attributes.len() == attributes.len() && self.matches(&attributes, key)
// The secret's content type does not identify the item.
let mut attributes = attributes.as_attributes();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wouldn't it be simpler to have a new as_search_attributes and make it skip that attribute, avoiding the current clone?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right. I pushed an update using as_search_attributes() for exact matching and removed the clone in the unlocked path. Thanks!

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

📊 Code Coverage Report

Metric Value
Current PR Coverage 83.37%
Main Branch Coverage 83.47%
Coverage Change 📉 -0.10%

Coverage report generated by cargo-tarpaulin

@bilelmoussaoui
bilelmoussaoui merged commit 954cecb into linux-credentials:main Sep 25, 2026
17 checks passed
@bilelmoussaoui

Copy link
Copy Markdown
Collaborator

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants