Native Vault transport audit
2026-09-15 — Candidate fix; not released
A published macOS ARM64 CLI 0.20.1 binary passed 32 of 34 real HTTP/PTY import checks. The two failures dropped an SSH import PUT response, either before or after committing the entry. Bun reused a pooled connection and submitted the PUT twice. Source-mode Node checks had not exposed this native-runtime behavior.
This does not establish duplicate stored entries. SSH import has no idempotency header, but the server's create-only and revision guards reject a repeated committed write. A hidden retry after an uncommitted first request can nevertheless commit the operation instead of leaving an uncertain outcome for the caller. Idempotency protection is operation-specific: access-key creation has an idempotency header, while HOTP issuance binds a durable request-file intent. Those contracts remain necessary; connection settings cannot make a lost response certain.
Tests used Bun 1.3.14. The official Bun fetch documentation describes disabling connection pooling per request.
The candidate disables connection reuse in the shared Vault transport using Bun's documented keepalive: false option. Authentication, JSON bodies, revision and idempotency headers, timeout, redirect refusal and sanitized errors remain unchanged. This applies to commands using that shared helper, not every HTTP client in DreamLake. Fresh connections can add latency. No new automatic application retry is introduced.
| Boundary | Executed evidence | Limit |
|---|---|---|
| Published native import | 32/34 passed, including interactive selection and cancellation; two uncertain PUT cases failed. | macOS ARM64 0.20.1 only. |
| Candidate native import | All 34 canonical/legacy routing, prefix conflict, selection, HTTP and PTY cases passed. | Synthetic SSH sources and loopback server; no user credentials or remote host changes. |
| Compiled transport | Nine checks passed: POST/PUT/DELETE dropped before/after commit, HTTP409, redirects and malformed JSON. Headers and sanitized errors checked. | Local actual HTTP with a Bun-compiled import of the production helper, not the hosted backend. |
| Regression sensitivity | Removing the fix fails both PUT and both DELETE drop cases (5/9 pass); POST does not replay in these tested cases. | Do not infer every POST or network-failure mode was affected. |
| Python | No Python transport change is proposed. Existing selected import and durable OTP intent APIs remain paired. | This native regression is not a fresh full Python/hosted acceptance run. |
The complete source suite passed 1,251 tests with zero skips, including typecheck. The native checks above remain separate evidence from source-mode coverage.
Reconcile an unknown result through the command's documented operation identity before creating a new operation. Never repeat an entire partially completed selection merely because the connection failed. Keep completed entries and preserve any original request file or request ID.
The PTY harness now accepts an explicit native executable through the test-only DREAMLAKE_TEST_CLI_BINARY environment variable. It otherwise retains source-mode execution. Tests do not replace HOME or modify the user's configuration.
The broader Vault help, generated-reference and CLI/Python acceptance checklist remains open. This evidence closes neither hosted private execution nor every credential consent/upload path.