# docs(tokenstore): correct warnedLoosePerms locking claim (Copilot review)

`8fc80b0`→[main](/content/gh/entireio/cli/commits/main/index.html)·   peyton-alt·3d ago·1 file·+3 added/-1 removed

The comment claimed every caller of load holds mu, but tests call load directly without the lock; scope the claim to production call paths.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

## Sessions

01KXGWVPHC0SH8P5T8DPMRGFRJView transcript

## Changes

1

- internal/entireclient/tokenstore

- Mfile.go+3/-1

```
29 unmodified lines

30
31
32
33
33
34
35
36
37
38

29 unmodified lines

path string
	mu   sync.Mutex
	// warnedLoosePerms dedupes the loose-permissions warning to once per
	// store instance (guarded by mu, which every caller of load holds).
	// store instance. Like the rest of the store's state it relies on mu,
	// which every production caller of load (Get/Set/Delete) holds; tests
	// that call load directly are single-goroutine.
	warnedLoosePerms bool
}
```

Minternal/entireclient/tokenstore/file.go+3/-1
