• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

umputun / ralphex
84%
master: 84%

Build:
Build:
LAST BUILD BRANCH: dependabot/github_actions/actions/setup-go-7
DEFAULT BRANCH: master
Repo Added 21 Jan 2026 08:02AM UTC
Files 55
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH fix-oauth-token-persistence
branch: fix-oauth-token-persistence
CHANGE BRANCH
x
Reset
  • fix-oauth-token-persistence
  • 298-image-port-flags
  • 300-non-english-plan
  • add-default-branch-template
  • add-dirty-worktree-check
  • add-notifications
  • add-org-monthly-limit-pattern
  • add-reset-flag
  • auto-create-initial-commit
  • auto-plan-mode-detection
  • base-ref-skip-finalize
  • claude-command-external-review-tool-flags
  • code-review-fixes
  • codex-error-hints
  • codex-first-class-mode
  • codex-task-model
  • codex-wrapper-script
  • commented-defaults
  • configurable-colors
  • custom-config-dir
  • custom-external-review
  • dashboard-tests
  • dependabot/github_actions/actions/checkout-7
  • dependabot/github_actions/actions/setup-go-7
  • dependabot/github_actions/goreleaser/goreleaser-action-7
  • dependabot/go_modules/github.com/fsnotify/fsnotify-1.10.0
  • dependabot/go_modules/github.com/go-git/go-billy/v5-5.7.0
  • dependabot/go_modules/github.com/go-jose/go-jose/v3-3.0.5
  • dependabot/go_modules/github.com/slack-go/slack-0.23.1
  • dependabot/go_modules/golang.org/x/crypto-0.45.0
  • dependabot/go_modules/golang.org/x/net-0.55.0
  • dependabot/go_modules/golang.org/x/sys-0.44.0
  • dependabot/go_modules/golang.org/x/sys-0.45.0
  • dependabot/go_modules/golang.org/x/sys-0.46.0
  • dependabot/go_modules/golang.org/x/sys-0.47.0
  • dependabot/go_modules/golang.org/x/term-0.42.0
  • dependabot/go_modules/golang.org/x/term-0.43.0
  • dependabot/go_modules/golang.org/x/term-0.44.0
  • dependabot/go_modules/golang.org/x/term-0.45.0
  • dependabot/go_modules/gopkg.in/ini.v1-1.67.2
  • dependabot/go_modules/gopkg.in/ini.v1-1.67.3
  • display-lines-changed-stats
  • docker-support
  • drop-go-git-backend
  • dump-defaults-and-update-skill
  • error-patterns
  • external-git-backend
  • feat/agent-frontmatter-model-v2
  • feat/branch-override-flag
  • feat/claude-model-config
  • feat/claude-retry-patterns
  • feat/configurable-worktree-path
  • feat/fya-base-image
  • feat/per-phase-claude-models-v2
  • feat/plan-model
  • feat/scalar-config-fallback
  • feat/use-branch-override-in-progress
  • feature/claude-plugin-support
  • finalize-step
  • fix-290-validate-plan-tasks
  • fix-321-tighten-codex-patterns
  • fix-322-marketplace-name
  • fix-checkout-keep-untracked
  • fix-codex-not-installed
  • fix-codex-stderr-limit-pattern
  • fix-codex-stderr-reporting
  • fix-dashboard-task-numbering
  • fix-fenced-code-block-checkbox-parser
  • fix-isignored-global-patterns
  • fix-issue-317-admin-allocation-pattern
  • fix-other-option-plan-questions
  • fix-plan-file-resolution
  • fix-plan-panel-task-done
  • fix-process-group-cleanup
  • fix-progress-append-on-restart
  • fix-review-loop-exit
  • fix-review-signals
  • fix-scanner-buffer-size
  • fix-session-limit-pattern
  • fix-sigint-handling
  • fix-stale-cli-in-container
  • fix-tz-env-docker
  • fix-uncommitted-changes-handling
  • fix-version-unknown
  • fix-windows-build
  • fix-worktree-plan-commit-case-mismatch
  • fix-worktree-support
  • fix/303/pre-init-config-dir
  • fix/docker-timezone-from-host
  • fix/force-exit-cleanup-timeout
  • fix/issue-288-progress-failed-footer
  • fix/not-logged-in-error-pattern
  • fix/plugin-seed-skip-manager-state
  • fix/standardize-plan-date-format
  • fix/strip-comments-markdown
  • fix/strip-leading-meta-comments
  • fix/transient-http-retry
  • fix/update-script-mode-397
  • fix/web-race-test-guard
  • fix/windows-comment-setsid
  • force-exit-timeout
  • generic-plan-filename-branch-fallback
  • graceful-prompt-variables
  • interactive-plan-creation
  • interactive-plan-review
  • master
  • move-plan-on-completion-config
  • opencode-wrapper-model-effort
  • pi-provider-support
  • plan-draft-preview
  • preserve-anthropic-api-key
  • progress-files-location
  • progress-fresh-start
  • project-local-config
  • ralphex-adopt-skill
  • ralphex-local-gitignore
  • refactor-git-service
  • refactor-main
  • refactor-smells-and-duplication
  • refs/tags/v0.1.0
  • refs/tags/v0.10.0
  • refs/tags/v0.10.1
  • refs/tags/v0.10.2
  • refs/tags/v0.10.3
  • refs/tags/v0.10.4
  • refs/tags/v0.10.5
  • refs/tags/v0.10.6
  • refs/tags/v0.11.0
  • refs/tags/v0.11.1
  • refs/tags/v0.12.0
  • refs/tags/v0.12.1
  • refs/tags/v0.13.0
  • refs/tags/v0.14.0
  • refs/tags/v0.15.0
  • refs/tags/v0.15.1
  • refs/tags/v0.15.2
  • refs/tags/v0.15.3
  • refs/tags/v0.16.0
  • refs/tags/v0.2.0
  • refs/tags/v0.2.1
  • refs/tags/v0.2.2
  • refs/tags/v0.2.3
  • refs/tags/v0.26.1
  • refs/tags/v0.26.2
  • refs/tags/v0.26.3
  • refs/tags/v0.27.0
  • refs/tags/v0.27.1
  • refs/tags/v0.27.2
  • refs/tags/v0.27.3
  • refs/tags/v0.3.0
  • refs/tags/v0.4.0
  • refs/tags/v0.4.1
  • refs/tags/v0.4.2
  • refs/tags/v0.4.3
  • refs/tags/v0.4.4
  • refs/tags/v0.5.0
  • refs/tags/v0.6.0
  • refs/tags/v0.7.0
  • refs/tags/v0.7.1
  • refs/tags/v0.7.2
  • refs/tags/v0.7.3
  • refs/tags/v0.7.4
  • refs/tags/v0.7.5
  • refs/tags/v0.8.0
  • refs/tags/v0.9.0
  • refs/tags/v1.0.0
  • refs/tags/v1.0.1
  • refs/tags/v1.1.0
  • refs/tags/v1.1.1
  • refs/tags/v1.2.0
  • refs/tags/v1.3.0
  • refs/tags/v1.3.1
  • refs/tags/v1.3.2
  • refs/tags/v1.4.0
  • refs/tags/v1.5.0
  • refs/tags/v1.5.1
  • refs/tags/v1.6.0
  • refuse-diagnostics
  • remove-docker
  • resolve-renamed-plan
  • review-agent-prompt-contract
  • rewrite-dk-script-python
  • runner-phase-engines
  • skip-post-codex-review-no-findings
  • task-header-patterns-config
  • task-model-effort
  • task-model-rename
  • unbounded-line-reader
  • verbose-completions
  • watch-mode-reactivate-tailing
  • web-fixes
  • web-planner
  • web-ui
  • web-ui-improvements
  • windows-timeout
  • worktree-isolation

20 Jul 2026 03:44AM UTC coverage: 83.727%. First build
29715424248

Pull #412

github

umputun
fix: harden OAuth credential bind mounts and keep older wrappers working

Follow-up fixes to the credential write-through mounts, from a multi-agent review.

Mount emission (scripts/ralphex-dk.sh):
- use --mount type=bind rather than -v for the two credential files. A missing -v source makes
  docker create a DIRECTORY at the target, corrupting the credential path; --mount fails the
  container start instead, so the is_file() guard can no longer be raced.
- CSV-quote the source: --mount parses as CSV, so a comma in the resolved path (reachable via
  $HOME or CLAUDE_CONFIG_DIR) split the field and docker rejected the spec. -v tolerated it.
- no SELinux option on these specs: docker's --mount has no relabel option at all (podman's
  relabel= has no docker equivalent; z/Z are -v only). The parent ~/.claude and ~/.codex are
  -v mounted with :z and docker's z relabel walks the source tree, so the bound inodes are
  already labeled.

Container init (scripts/internal/init-docker.sh):
- keep copying the credential files when the wrapper supplies no bind mount. The init script
  ships in the image but the wrapper updates through a separate channel (--update-script vs
  docker pull), so "new image + old wrapper" is a supported combination that otherwise left
  the container with no credentials at all. seed_claude_home/seed_codex_home probe the target
  before copying — docker establishes mounts before the entrypoint, and the fallback creates
  the file itself, so the probe cannot be deferred until after the copy.
- gate the chown on the same probe: a bind-mounted file must not be chowned (it would mutate
  the host file's metadata), but a fallback copy lands root:app 0600 and needs the full
  chown -R to be writable by app.
- anchor the chown exclusions with -path; ! -name matched at any depth.

Tests and docs:
- cover both wrapper generations in init-docker_test.sh and wire the harness into CI — it had
  no references anywhere and never ran. Ownership is not ... (continued)
Pull Request #412: fix: persist OAuth token refreshes from container to host

7795 of 9310 relevant lines covered (83.73%)

226.79 hits per line

Relevant lines Covered
Build:
Build:
9310 RELEVANT LINES 7795 COVERED LINES
226.79 HITS PER LINE
Source Files on fix-oauth-token-persistence
  • Tree
  • List 55
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
29715424248 fix-oauth-token-persistence fix: harden OAuth credential bind mounts and keep older wrappers working Follow-up fixes to the credential write-through mounts, from a multi-agent review. Mount emission (scripts/ralphex-dk.sh): - use --mount type=bind rather than -v for the tw... Pull #412 20 Jul 2026 03:48AM UTC umputun github
83.73
29566449686 fix-oauth-token-persistence fix: harden OAuth credential bind mounts and keep older wrappers working Follow-up fixes to the credential write-through mounts, from a multi-agent review. Mount emission (scripts/ralphex-dk.sh): - use --mount type=bind rather than -v for the tw... Pull #412 17 Jul 2026 08:28AM UTC umputun github
83.78
29566174422 fix-oauth-token-persistence fix: harden OAuth credential bind mounts and keep older wrappers working Follow-up fixes to the credential write-through mounts, from a multi-agent review. Mount emission (scripts/ralphex-dk.sh): - use --mount type=bind rather than -v for the tw... push 17 Jul 2026 08:22AM UTC umputun github
83.78
29561552992 fix-oauth-token-persistence fix: persist OAuth token refreshes from container to host Add rw file bind-mounts for ~/.codex/auth.json and ~/.claude/.credentials.json so token refreshes inside the container write through to host files. Previously, init-docker.sh copied them f... push 17 Jul 2026 06:59AM UTC umputun github
83.74
See All Builds (754)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc