feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(desktop): resolve Chromium cookie keys on Linux - #7261

Open
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows
Open

feat(desktop): resolve Chromium cookie keys on Linux#7261
juliusmarminge wants to merge 14 commits into
browser-import-more-sourcesfrom
browser-import-linux-windows

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 16, 2026

Copy link
Copy Markdown
Member

Stacked on #7260 (browser-import-more-sources). Despite the retained branch name, this PR adds Linux support only; Windows Chromium is intentionally unsupported.

Chromium cookie key handling moves into a platform-specific module:

PlatformSchemeKey source
macOSv10 AES-128-CBCLogin Keychain, with consent
Linuxv10 AES-128-CBCChromium’s basic-storage peanuts passphrase
Linuxv11 AES-128-CBCSecret Service via secret-tool, using the browser’s application attribute

Linux requires secret-tool and a compatible Secret Service backend to import v11 records. Missing keys/tools/backend can yield a partial v10 import; skipped records are reported. Explicit permission denial or cancellation stops the import. Secret bytes are preserved apart from the tool’s output line ending.

There is no DPAPI, PowerShell, App-Bound Encryption bypass, or direct KWallet implementation. macOS keeps the existing in-process consent path.

Validation: synthetic v10/v11 decryption fixtures, mocked Secret Service subprocess results, denied/missing backend behavior, and trailing-whitespace preservation. No live Linux keyring lookup was performed during this audit.

Original implementation: Claude Code. Review fixes: GPT-5.6 Sol agents, coordinated through Codex.

Note

Add Linux support for resolving Chromium cookie keys

  • Enables Chromium browser cookie imports on Linux by resolving v10/v11 keys via the Secret Service (secret-tool) and macOS keychain.
  • Introduces ChromiumKeys.ts to handle platform-specific key resolution, including Linux empty-passphrase fallbacks and optional v11 keys.
  • Updates ChromiumCookies.ts to decrypt v10/v11 records with structured key material and strip SHA-256 domain bindings from schema 24+ cookies.
  • Risk: readChromiumCookies now accepts ChromiumKeyMaterial instead of a single Buffer, and decryptChromiumValue treats unrecognized prefixes as cleartext on macOS and Linux.

Macroscope summarized 85465f1.


Note

Medium Risk
Reads OS credential stores and spawns secret-tool to derive cookie decryption keys; behavior changes which Linux Chromium sources appear importable and may partially import when v11 keys are missing.

Overview
Enables Chromium cookie import on Linux by moving OSCrypt key resolution into ChromiumKeys and wiring each browser source with a linuxSecretApplication for libsecret lookup via secret-tool.

On Linux the importer always derives the v10peanuts key and an empty-passphrase retry key; it optionally loads v11 from Secret Service (chrome_libsecret_os_crypt_password_v2). Missing backend or secret yields a partial import (skipped cookies reported) while explicit unlock denial still fails the flow. macOS keeps in-process Keychain consent; Windows stays unsupported.

Decryption now takes a ChromiumKeyMaterial map: decryptChromiumValue handles v10/v11 prefixes, empty-key retry (crbug 1195256), schema-24 domain binding, and treats unprefixed blobs as legacy cleartext on macOS and Linux (aligned with Chromium).

Availability no longer blocks all non-macOS Chromium sources up front—unavailableReason only checks declared platforms, install, and running state; key errors surface during read. BrowserImport passes linuxSecretApplication and requires ChildProcessSpawner for the cookie read path.

Reviewed by Cursor Bugbot for commit 3c1d584. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Aug 16, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a0d1595-8e5e-4594-b3da-057657d6ef1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Aug 16, 2026
@github-actionsgithub-actionsBot added the size:L 100-499 changed lines (additions + deletions). label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@github-actions

github-actionsBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.4 KiB15.1 KiB
CodexThread snapshot wire6.9 KiB7.3 KiB
CodexLive turn WebSocket wire6.6 KiB7.8 KiB
CodexLive turn WebSocket decoded57.0 KiB66.4 KiB
CodexLive turn messages1021
ClaudeTotal thread wire13.3 KiB15.1 KiB
ClaudeThread snapshot wire6.9 KiB7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB66.4 KiB
ClaudeLive turn messages1021

Baseline: unavailable · PR result: 85465f1 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 1d228da to 6a2afeaCompareAugust 16, 2026 22:08
@github-actionsgithub-actionsBot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 16, 2026
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites against the Effect service conventions. Imports, Effect.fn.Return requirement typing, and dependency acquisition (yield* FileSystem.FileSystem, ChildProcessSpawner surfaced in the requirement channel and threaded through BrowserImport's captured context) all look right. Two error-modelling issues in ChromiumKeys.ts: an underlying failure is discarded instead of being preserved as cause, and the Windows DPAPI path can turn a real failure into a silently empty key reported under a misleading reason.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 16, 2026 22:18
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds Linux Chromium cookie importing with Secret Service access, external process execution, key derivation, and decrypted session-cookie handling, creating substantial runtime and sensitive-data impact. It also adds a static-analysis diagnostic suppression, so the changes require human review.

No code changes detected at 85465f1. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 6a2afea to 65f945aCompareAugust 16, 2026 22:53

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a typed ChromiumKeyError is re-wrapped at a translation boundary in ChromiumKeys.ts, losing its reason and nesting the error inside itself.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 65f945a to 0ad3689CompareAugust 16, 2026 22:58
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 0ad3689 to 032f5daCompareAugust 16, 2026 23:10
@github-actionsgithub-actionsBot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 16, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new ChromiumKeys module and its call sites in ChromiumCookies/BrowserImport against the Effect service conventions. Two findings on error modelling in ChromiumKeys.ts; the layer/import/dependency-acquisition side looks fine (resolveChromiumKeys takes FileSystem/ChildProcessSpawner from the environment and scopes the child process locally).

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 032f5da to cfbd7b7CompareAugust 16, 2026 23:14
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from cfbd7b7 to 5896abdCompareAugust 16, 2026 23:22
@github-actionsgithub-actionsBot added the size:XL 500-999 changed lines (additions + deletions). label Aug 29, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding on the new key-material plumbing in ChromiumCookies.ts.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: the new per-prefix key selection in ChromiumCookies.ts (the central behavior change of this PR) has no focused test. Everything else — the ChromiumKeys module layout, ChromiumKeyError structure, ChildProcessSpawner acquisition from the environment, and the test-only Layer.succeed spawner seam — follows the Effect service conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 29, 2026
@juliusmarminge
juliusmarmingeforce-pushed the browser-import-linux-windows branch from 2eff79b to 268598aCompareAugust 29, 2026 07:53
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding, on the new test file's diagnostic suppression. The rest of the change — the ChromiumKeys module layout, ChromiumKeyError structure with preserved cause, ChildProcessSpawner/HostProcessEnvironment acquired from the environment, requirements surfaced through Effect.fn.Return, and the now-uniform ChromiumKeyMaterial key shape with focused mixed v10/v11 coverage — matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.test.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumCookies.ts Outdated
Comment threadapps/desktop/src/preview/BrowserImport/BrowserImport.ts
Comment threadapps/desktop/src/preview/BrowserImport/ChromiumKeys.ts Outdated
juliusmarmingeand others added 14 commits September 2, 2026 16:00
macOS derives the OSCrypt key from a single keychain secret. Linux is looser: a
database can mix `v10` records (a hardcoded `peanuts` passphrase, used when no
keyring is present) and `v11` records (a libsecret/kwallet secret), so both keys
are derived up front and the record's prefix picks between them. A locked or
absent keyring is not fatal — those `v11` records are skipped and the rest still
import.
Key acquisition moves into its own `ChromiumKeys` module; `ChromiumCookies` now
decrypts each record by the scheme its prefix names and skips any it holds no
key for, so a partial result is reported honestly rather than failing the whole
import.
Windows is deliberately left out: since Chrome 127 its cookies are encrypted to
the browser's own identity (App-Bound Encryption) and cannot be read by another
process, so those forks are not offered there at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… key
Some Linux clients encrypted OSCrypt data with a key derived from an empty
passphrase (crbug.com/1195256). Chromium retries every failed v10/v11 record
with that key, so records it can still read were being skipped here. The key
material now carries the empty-passphrase key on Linux and the decryptor
retries with it when a record's own key fails — and only then, matching
Chromium: a record whose own key is missing entirely stays skipped.
Also drops an unexplained diagnostics suppression from ChromiumKeys.test.ts
that had nothing to suppress.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unprefixed cookie blob is legacy data stored in the clear, and Chromium's
OSCrypt returns it as-is on both macOS and Linux (os_crypt_mac.mm and
os_crypt_linux.cc alike: "old data saved as clear text"). The reader only
honoured that on macOS, so a Linux import counted those rows as undecryptable
and dropped otherwise readable cookies. The fallback now applies on Linux as
well; Windows stays excluded, since its app-bound blobs also lack the prefix.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…x key
secret-tool matched on the application attribute alone, so any other
Secret Service item carrying application=chrome would supply the wrong
passphrase and every v11 cookie would be skipped as undecryptable.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge