Plaintext credential reads could come from memory instead of the file, but only under off-by-default storage.
An in-process credential cache with a generation counter is present but only applies when the v5 storage decision is on.
tengu_hover_rest Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.238: on
Read once, for one account on one subscription tier, against v2.1.238. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
Reads of the plaintext credential store can be served from a cached snapshot held in memory rather than re-reading the file, with a generation counter and an explicit invalidation entry point. Every write, delete and failed read clears it. This only applies when the off-by-default v5 storage decision is on.
- Controlled by the same latched pin as the rest of v5 storage:
CLAUDE_CODE_HOVER_RESTif set, otherwisetengu_hover_rest, whose fallback is off.
fromStoreCopy
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
Precomputed session resolution on resume, gated off
Both mention hover rest
-
v2.1.234
Resume reads the pre-compaction sidecar ahead of time
Both mention hover rest
-
v2.1.242
On-disk storage layer gains symlink and permission rules per data type
Both mention hover rest