Skip to content

Cross-process Linear OAuth refresh wipes valid connections (invalid_grant race) #418

Description

@arul28

Severity: High (data-loss: silent Linear disconnect) · from 2026-05-29 audit.

When desktop and ade serve share the encrypted cred store, a near-expiry Linear OAuth refresh can race: Linear rotates the refresh token on first exchange, the losing runtime retries with the stale token, gets invalid_grant, and unconditionally clears the shared credentials (linearCredentialService.ts:550-558, headlessLinearServices.ts:1264-1266) — forcing a reconnect though the connection was valid. Introduced by #395.

Fix: cross-process file lock + re-read the cred store on invalid_grant; treat a rotated/fresh token as a benign race and keep the connection.

Fixed by PR #400. (Note: that PR's sleepSync uses Atomics.wait, which blocks the main thread — switch to async sleep before merging.)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions