v0.24.1 — Session passwords stay out of process environments
A security patch. Upgrade if you share sessions from a machine that runs other programs as you, such as coding agents, MCP servers or install scripts.
Security
- A session's browser password no longer sits in any process's environment. The machine daemon handed a browser-started session its password in
SHELL_ONLINE_E2EE_PASSWORD, and every background session kept it there for its whole life. Any program running as the same user could read it (ps -E,/proc/<pid>/environ). It now goes between shell's own processes over a pipe. SettingSHELL_ONLINE_E2EE_PASSWORDyourself still works as before. - The program a session shares no longer inherits the session's password, name, command or browser request. A
shellrun inside a browser-started session silently reused the parent's browser password and published the parent's command and name as its own, andshell password rotaterun from inside rotated to the same password. The accounts service now also lets only one session claim a browser request.
Sessions that are already running keep their old environment until they restart. After upgrading, restart the machine daemon so browser-started sessions use the new handoff.
Removed
- The agent-record transcript added in 0.24.0 is withdrawn. It found a record by the directory the session started in, so sessions started from the same directory could resolve to the same file. The chat reads the screen again. The relay still accepts the reserved opcode, so hosts running 0.24.0 keep their connection.
Fixed
- Chat renderer: messages no longer arrive with a screenful of blank space, new output arrives again after leaving the chat and coming back, a reconnecting device no longer draws the conversation twice, headings with a running clock hold still, and a tool's result is no longer read as part of the prompt above it.
shell lsno longer shows a session whose machine is gone as still running. Its uptime now stops when the machine was last seen.
Full notes: CHANGELOG.md