fix(claude): prefer current macOS Keychain credential - #6093
Open
AgentWrapper wants to merge 1 commit into
Open
AgentWrapper wants to merge 1 commit into
AgentWrapper wants to merge 1 commit into
Conversation
Contributor
🏆 Review leaderboardSep 24, 2026–Oct 1, 2026 · UTC
Ranked by distinct external PRs reviewed, then review rounds, then PR comments. Self-activity and bot activity are excluded. Show 9 more reviewers
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Code changes: +21 -24
Tests: +54 -0
Others: +0 -0
Related issue: #6105. This fixes the reproduced Keychain credential-selection failure; the affected Mac’s Keychain state is unverified.
Summary
Claude CodemacOS Keychain service when resolving a local Claude credential. KeepClaude Code-credentialsas a fallback for older installations.Validation
go test -race -count=1 ./pkg/agentcreds ./internal/adapters/agent/claudecode ./internal/service/agent— passed.go build ./...,go vet ./..., golangci-lint v2.13.2 — passed.go test -tags e2e -v ./internal/cli/...— passed with the AO session environment removed.npm run sqlcandnpm run api— passed with no generated-file drift.go test -race -count=1 -timeout=20m ./...ran locally. The changed packages passed. Goose, tmux, CLI, and system-check failures cleared in a clean-environment rerun. Codex protocol conformance still fails against this machine's installed Codex version; it is unrelated to this change. Remote CI remains the full-suite gate.Scope and risk
This proves one code path that can produce the reported mismatch; the reporter's Keychain contents have not been inspected. A stale
Claude Codeentry on a machine actively using an older Claude version and its legacy entry could cause the reverse mismatch. Environment-supplied credentials and differing Claude binaries are outside this fix.