Stop direct Claude Keychain reads and route owner CLI by profile - #2380
Stop direct Claude Keychain reads and route owner CLI by profile#2380ProspectOre wants to merge 24 commits into
Conversation
Redacted live credential-ownership proofExact PR head: This proof intentionally excludes account identity, credentials, token values, usage amounts, raw Keychain records, raw CLI payloads, raw unified-log lines, and private filesystem paths. The private verifier directory was not uploaded. Before / root causeRedacted historical live logs showed Claude replace its owned credential item and CodexBar prompt again 15 seconds later. That proves a user ACL grant was temporary: Claude's next credential refresh replaced the item CodexBar was reading. Exact-head results
Release executable hashes
The manifest was rechecked against the packaged app after the run; all four hashes passed. Broader validation
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
Exact-head redacted live proof — 2026-07-21 22:27 PDTCandidate: Build integrity:
Logged-in Claude owner-path result:
Runtime ownership/prompt audit:
Automated gates on the same candidate:
Behavioral boundaries covered:
Environment caveats, included for completeness:
No account identity, token, usage amount, raw Keychain value, raw log, or private artifact path is included or uploaded. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d0dc5e09f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Redacted exact-head proofThis supersedes the earlier proof and validates exact head
The public proof intentionally excludes account identity, credentials, token values, usage amounts, raw Keychain records, raw unified-log lines, and private filesystem paths. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b12c844e43
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b00d85e90b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7e6e23ff73
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-head redacted proof for
Raw account identity, credentials, tokens, usage values, Keychain records, logs, hashes, and local paths are intentionally excluded. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
|
CI follow-up: the current aggregate failure is the unrelated date-sensitive SpendDashboard test group, not the Claude ownership change. It is isolated in draft PR #2390; this branch remains unchanged. |
|
@clawsweeper re-review Please publish the exact-head review for |
Independent exact-head validation found a test-safety gap; focused follow-up submittedI ran That means this run did not reach the owner-CLI process/log audit; it did not modify the real credential or ACL, and I am not presenting it as a passing live proof. The failures are the concrete, independently useful gap now addressed by #2441 at
Focused validation on the follow-up passed, cross-provider review completed with no remaining findings, and the P2 live-proof review thread is resolved. The unrelated SpendDashboard stabilization was deliberately removed because #2390 already owns it. The live reproduction proving that Always Allow succeeds and then is lost after foreign-item replacement is recorded in #1823: #1823 (comment) Once #2441 is available on this branch (or equivalent isolation is applied), the verifier should be rerun with the explicit live opt-in so Phase 1 cannot be host-state dependent and the process/log ownership audit remains meaningful. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8cf84bb793
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b12e060f93
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Verification follow-up —
|
|
🦞🧹 I asked ClawSweeper to review this item again. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9ba5485bbe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
1 similar comment
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 30d8655967
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
Exact-head validation —
|
|
🦞🧹 I asked ClawSweeper to review this item again. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 55dbe9bfdb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
55dbe9b to
d24a053
Compare
|
Exact-head update: Addressed the new verifier-account-routing review: Fresh exact-head verification:
The PR body contains the updated redacted hashes and proof. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d24a053c72
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Inspectable redacted terminal transcript for exact head Phase 3 invokes the packaged verifier-only app lifecycle once. Its ambient user-initiated @clawsweeper re-review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f9d771840
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
2f9d771 to
cafa839
Compare
|
Exact-head update: Addressed both delegated-refresh profile-isolation findings:
Live verification also exposed that the dedicated Fresh exact-head verification:
Inspectable redacted terminal transcript from the completed exact-head verifier run: The verifier built and signed the exact source, confirmed a clean and stable worktree snapshot, audited all four first-party Release executables, temporarily enabled the stored background owner-CLI policy for the bounded run, and restored the original preference afterward. No account identity, credential/token, usage amount, private path, raw Keychain record, or raw unified log is included. |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@steipete This remaining Claude credential-ownership layer is ready for maintainer review. Exact-head CI is fully green, all review threads are resolved, Codex found no major issues, and ClawSweeper reports sufficient live proof with no findings. GitHub currently reports the PR clean and mergeable. |
Ownership shutdown + profile routing + account reconciliation
This is the remaining Claude ownership-boundary unit requested after #2484 landed. It is restacked on current
mainand drops the profile/cache foundation already merged through #2484, along with the #2441 test-isolation layer already onmain.Root cause
Claude Code owns the macOS Keychain item
Claude Code-credentials. Claude refreshes replace that item and its ACL, so any permission previously granted to CodexBar is temporary. A later direct CodexBar read can therefore ask macOS for authorization again, regardless of the user's prompt preference.CodexBar's own legacy cache can also retain an ACL for an older build at the same executable path. Path-only preflight therefore produced a false safe result before the secret read, at which point macOS displayed an authorization prompt for the changed code signature.
Fix
/usageprobe ignores ambient MCP configuration, so usage refresh does not wait for or execute unrelated user MCP servers. Normal Claude sessions are unchanged..config.json/fallback path. Existing path-based identities migrate only when they cryptographically match an observed UUID, preventing a false switch when the preferred file appears or disappears without weakening real account-switch detection.Preserved functionality
Environment OAuth tokens, profile credentials files, the CodexBar-owned profile cache from #2484, owner-mediated Claude CLI recovery from user actions, selected-account routing, web fallback/extras, and account reconciliation remain available. User Claude sessions retain their normal MCP/plugin configuration; only CodexBar's dedicated usage-only probe is isolated from ambient MCP servers. The removed paths are direct production access to Claude Code's foreign Keychain item and interactive CLI fallback from scheduled background refreshes.
Regression coverage
Tests cover stable active-account identity across preferred/fallback config-file transitions, guarded migration of matching path-based identities, preservation of real switch detection for nonmatching legacy identities, profile-scoped active-account baseline selection and legacy migration, the production ownership boundary, no-read behavior under every prompt policy, explicit versus background CLI behavior, background explicit-OAuth fail-closed behavior under every prompt policy, expired Claude-owned cache handoff to the owner CLI, retained user-initiated owner-CLI recovery, profile/account-scoped session reuse and cleanup, profile/account-scoped background availability, isolated usage-probe launch arguments, serialized profile capture, profile-scoped delegated-refresh joins and cooldown migration, MCP routing, selected-account reconciliation, profile-scoped refresh-failure persistence and file-only recovery fingerprints, terminal cache/file failures, preservation of existing OAuth/web authority selection, stale same-path cache ACL rejection, and strict no-data ACL preflight behavior.
Verification
Exact head
cafa839dd3e238a980ab673b2693fa6a5a6cd65a:make test: 764/764 selections, 64/64 first-pass groups passed, zero failed groups, retries, recoveries, isolated retries, or timeouts;make check: SwiftFormat 0/1,661 and SwiftLint 0 violations in 1,660 files;git diff --check: passed.Redacted exact-head live proof
Inspectable redacted exact-head terminal transcript
The verifier built and signed the exact source, confirmed a clean/stable worktree snapshot, audited every first-party Release executable, temporarily set the stored background owner-CLI policy for the bounded run, and restored the original preference afterward. No account identity, credential/token, usage amount, private path, raw Keychain record, or raw unified log is included here.
c8d25b7f1fefba4ffdd18ef79bb2c2a863e26a4b1e102415100baea3cf04f5b0;256d606977696a5ed9e6bd84c2acf07116a34c3b70e4bef685e3cd085178762a;efb319a35f42f5f71b961919eb588f3a5f5e4a0f25fe92bc40ace35c1311af28;claude; source:claude; usage shape: dictionary;securitydescendants: 0/0/0;The live run therefore proves the packaged exact head reaches the Claude-owned usage path without a CodexBar-owned
securitychild and without an attributable macOS Keychain authorization prompt.