{"record":{"id":"d18c56a59164f1be","repo":"rust-lang/cargo","slug":"credential-process-failed-with-status","errorCode":null,"errorMessage":"credential process `{}` failed with status {}`","messagePattern":"credential process `(.+?)` failed with status (.+?)`","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/util/credential/process.rs","lineNumber":80,"sourceCode":"        };\n        let request = serde_json::to_string(&req).context(\"failed to serialize request\")?;\n        tracing::debug!(\"credential-process < {req:?}\");\n        writeln!(input_to_child, \"{request}\").context(\"failed to write to credential provider\")?;\n        buffer.clear();\n        output_from_child\n            .read_line(&mut buffer)\n            .context(\"failed to read response from credential provider\")?;\n\n        // Read the Credential Response\n        let response: Result<CredentialResponse, Error> =\n            serde_json::from_str(&buffer).context(\"failed to deserialize response\")?;\n        tracing::debug!(\"credential-process > {response:?}\");\n\n        // Tell the credential process we're done by closing stdin. It should exit cleanly.\n        drop(input_to_child);\n        let status = child.wait().context(\"credential process never started\")?;\n        if !status.success() {\n            return Err(anyhow::anyhow!(\n                \"credential process `{}` failed with status {}`\",\n                self.path.display(),\n                status\n            )\n            .into());\n        }\n        tracing::trace!(\"credential process exited successfully\");\n        Ok(response)\n    }\n}\n\nimpl<'a> Credential for CredentialProcessCredential {\n    fn perform(\n        &self,\n        registry: &RegistryInfo<'_>,\n        action: &Action<'_>,\n        args: &[&str],\n    ) -> Result<CredentialResponse, Error> {","sourceCodeStart":62,"sourceCodeEnd":98,"githubUrl":"https://github.com/rust-lang/cargo/blob/eb98b54bc9f3c74519f43d066cb3fd02ebc88df0/src/util/credential/process.rs#L62-L98","documentation":"CredentialProcessCredential::run completes the JSON-over-stdio protocol with the external credential process, then waits for it to exit. If the child's exit status is non-success, Cargo reports the configured process path and the failing status. (Note: the format string carries a stray trailing backtick — a cosmetic bug.)","triggerScenarios":"A configured credential-process performs its work (login, get, store, etc.), emits a response, but exits non-zero — e.g. the process hit an internal error after responding, or was killed.","commonSituations":"credential-process binary misconfigured; secret store locked or unreachable (Keychain, vault, KMS); provider crashes on a specific action; provider returns success JSON but exits 1 due to a bug.","solutions":["Run the credential-process binary manually with the same args/env Cargo uses to capture its stderr/exit code.","Check the provider's own logs (most credential helpers log to stderr).","Confirm the binary path in [registry.<name>] credential-provider is correct and executable.","Ensure the secrets backend is unlocked and reachable from Cargo's environment."],"exampleFix":"# before\n# [registry.my-registry]\n# credential-provider = [\"cargo-cred-mgr\", \"get\"]\n# provider exits 1\n\n# after: run manually to diagnose\n# cargo-cred-mgr get 2>&1 | less\n# then fix the provider config / unlock the backend","handlingStrategy":"try-catch","validationCode":"use std::process::Command;\n\nfn smoke_test_credential_process(path: &str) -> Result<(), String> {\n    let status = Command::new(path).arg(\"--help\").status().map_err(|e| e.to_string())?;\n    if status.success() { Ok(()) } else { Err(format!(\"{path} --help exited {status}\")) }\n}","typeGuard":null,"tryCatchPattern":"match provider.perform(&registry, &action, &args) {\n    Ok(resp) => { /* use resp */ }\n    Err(e) if e.to_string().contains(\"credential process\")\n               && e.to_string().contains(\"failed with status\") => {\n        eprintln!(\"credential-process {} failed; run it manually to inspect stderr\", path);\n        return Err(e);\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Smoke-test the credential-process binary (`provider --version` / `--help`) before relying on it.","Keep the provider's logs accessible; most write diagnostics to stderr.","Pin the credential-process version and review it on registry/auth changes."],"tags":["auth","credentials","subprocess","configuration"],"backgroundTag":null,"analyzedSha":"eb98b54bc9f3c74519f43d066cb3fd02ebc88df0","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}