Skip to content

fix(link): Remote Link loads and probes SSH hosts from the local dashboard - #5928

Closed
lidge-jun wants to merge 1 commit into
devfrom
claude/remote-link-ssh-hosts
Closed

lidge-jun wants to merge 1 commit into
devfrom
claude/remote-link-ssh-hosts

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Summary

On a normal standalone install, the Remote Link page (sidebar Remote Link / 원격 연결) never loaded a single SSH host. Every dashboard /api/link/* route required a GUI session issued by the pairing exchange (isPaired → issuance === "pairing"). A standalone loopback dashboard, in the browser or the desktop webview, only ever holds a loopback session, and pairing grants exist only on hub runtimes. So status, candidates, probe, confirm-host and apply all answered 403 forbidden. The sheet said "No SSH host candidates were found" and gave the generic "Remote link request could not be completed." Against a running 2.66.0 sidecar, the dashboard's own session got 200 on /api/settings and 403 on /api/link/status and /api/link/candidates. The route tests stubbed isPaired to true, so they never caught it. The ~/.ssh/config parser itself was fine.

Clearing the 403 exposed more failures on real hosts:

  • The desktop sidecar runs ssh with launchd's PATH=/usr/bin:/bin:/usr/sbin:/sbin, so a ProxyCommand cloudflared … could not find its helper.
  • On macOS remotes, ocx lives in ~/.bun/bin, which a non-interactive ssh shell does not have. ocx --version exited 127.
  • confirm-host accepted any stdout as a version. A Windows usage banner and a 2.32.1 install both "passed", then failed later at apply with remote_port_failed.

Changes:

  • Admission (security-relevant). The Home-side routes (status, candidates, probe, confirm-host, apply, DELETE) also admit the current loopback-issued GUI session that reached the public listener bound to a loopback hostname, on a standalone runtime. Paired sessions still pass. Hubs stay paired-only, Tailscale identity sessions are still refused, and the hub-link ingress is not trusted loopback. POST /api/link/join stays paired-only, unchanged from dev. A join restarts this proxy (503 drain, closed listener) and moves Codex/Claude routing to the Home tunnel, and turning Remote Link on must never drop existing Codex connections.
  • Child role. GET /api/link/status reports joinAvailable to GUI sessions. The admin-token DTO keeps its exact keys for ocx link status. When it is false, the dashboard disables the Child card, including keyboard selection. A notice in all 10 locales explains that joining as a Child from the dashboard is not available in this release, and points to Home-initiated linking.
  • Home → Continue now opens the SSH host sheet and loads candidates right away.
  • ssh environment. ssh/ssh-keygen (probe, exec and the supervisor's tunnels) run with /opt/homebrew/bin, /usr/local/bin, ~/.bun/bin and ~/.local/bin appended to PATH on POSIX.
  • Remote ocx. Every remote ocx call goes through remoteOcxArgv: sh -c 'PATH="$PATH:$HOME/.bun/bin:$HOME/.local/bin:/opt/homebrew/bin:/usr/local/bin"; exec ocx "$@"'. That covers confirm-host, apply port/connect, remove/disconnect, join issue/revoke and teardown revoke. The fallbacks are appended, so an ocx that already resolved still wins. Exit 127 maps to remote_ocx_missing.
  • Version floor. confirm-host parses opencodex X.Y.Z[-pre][+build] into a bounded semver shape and requires ≥ 2.66.0, the first release with ocx link. It returns remote_ocx_outdated or remote_ocx_unrecognized and restores known_hosts.
  • Actionable errors. Error bodies carry a bounded hint: the last ssh stderr line, the runner's own failure, or the parsed remote version. Controls, bidi and tokens are stripped, and it is capped at 160 code points without splitting a surrogate pair. The dashboard shows it under a specific message. New/rewritten error texts exist in all 10 locales.
  • Docs: structure/remote-link.md (Dashboard admission section, citing both the github/star and machine-listener precedents), structure/gui-and-management-api.md, the route registry, and guides/remote-link.md in 8 locales.

Security review requested. The loopback bootstrap mints this session with no credential. Any local process that sends a loopback Host can drive probe, confirm-host and apply, including remote ocx commands over the user's SSH keys. That is casual-path protection like POST /api/github/star, not a secret-backed boundary like the admin token. It is the same trade-off src/client/machine-listener.ts declined for its machine routes, and this PR takes it only for the Home side, where nothing touches 127.0.0.1:<port>.

Role select: Child disabled with the not-available notice
Home → Continue opens the SSH host sheet with ~/.ssh/config candidates
A failed probe shows a specific message and the bounded ssh hint

Screenshots come from this branch's built dashboard served by a proxy with a temporary HOME/OPENCODEX_HOME/CODEX_HOME. Its ~/.ssh/config holds demo aliases only.

Verification

  • bun run typecheck, (cd gui && bunx tsc -b), bun run lint:gui, bun run structure:check, bun run privacy:scan, bun run build:gui: pass.
  • Exact changed test files only. The maintainer asked for no local suite runs, so the other shards are left to CI:
    • bun test tests/server/link-management-routes.test.ts tests/server/link-join-route.test.ts tests/clients/link-ssh-argv.test.ts tests/clients/client-link-teardown.test.ts: 51 pass, 0 fail.
    • (cd gui && bun test tests/remote-link.test.tsx tests/locale-parity.test.ts tests/i18n-locales.test.ts): 42 pass, 0 fail.
    • bun test tests/ci-workflows/file-size-ratchet.test.ts: pass.
  • New coverage mints a real loopback session through the real issuance code and management session control, with no isPaired stub. It expects:
    • 200 on status and candidates.
    • Probe, confirm-host, apply (202) and DELETE (200) pass admission.
    • 403 without trusted loopback ingress, on hub and client runtimes, for Tailscale identity sessions, and on join.
    • joinAvailable false for loopback, true for paired standalone.
  • The fake SSH runners match the exact remoteOcxArgv-wrapped commands and return 127 for a bare ocx, so reverting any call site fails.
  • Fail-without-fix controls (hunk reverted, exact test run, hunk restored): the pre-fix admission (403 instead of 200), the old (\S*) version regex, the unbounded outdated hint, join on the widened check, the bare-ocx call sites, and the GUI Child gate.
  • Before the fix, the real-host replays reproduced probe_failed for a bare-cloudflared ProxyCommand under the sidecar PATH, zsh: command not found: ocx (exit 127) on two macOS hosts, and a usage banner accepted as a version on a Windows host. No source file contains literal invisible or bidi characters (checked with perl).
  • docs-site build not run locally; left to CI.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Remote-link errors now provide clearer troubleshooting details, including SSH, permissions, and remote OpenCodex version issues.
    • Remote linking can find OpenCodex in common installation locations on the remote computer.
  • Bug Fixes

    • Home-initiated linking now checks that the remote computer meets the minimum OpenCodex version requirement before connecting.
  • Documentation

    • Updated remote-link guides with supported system requirements and setup steps. Dashboard-initiated Child joining is unavailable; start linking from Home instead.

…board

Root cause: every dashboard /api/link route required a paired session, but a
standalone loopback dashboard (browser or desktop webview) only holds a
loopback-issued session, so candidates, probe, confirm-host and apply all
answered 403 and SSH hosts never loaded.

Fix: the Home-side routes (status, candidates, probe, confirm-host, apply,
DELETE) also admit the current loopback session on trusted loopback ingress of
a standalone runtime. POST /api/link/join stays paired-only; pairing sessions
exist only on hub runtimes and join requires standalone, so no dashboard can
join as a Child in this release. Status reports joinAvailable to GUI sessions
(admin-token keeps the exact K16 DTO), and the dashboard disables the Child
role with a notice in all 10 locales that points to Home-initiated linking.
Docs, structure notes and the route registry say the same.

ssh runs with Homebrew and ~/.bun/bin appended to PATH, and every remote ocx
call runs through a sh prelude that appends the fallback dirs after the remote
PATH (exit 127 -> remote_ocx_missing). confirm-host requires ocx >= 2.66.0,
parsed to a bounded semver shape. Link errors carry a bounded, redacted hint
from ssh stderr, the ssh runner's own failure, or the parsed remote version;
server and dashboard cap it at 160 code points without splitting a surrogate
pair. Specific error guidance is translated in every locale.

Security: the loopback session is minted without a credential, so this is
casual-path protection like POST /api/github/star, not a secret-backed
boundary; hubs and join keep the paired-only rule, Tailscale identity sessions
are still refused, and hints are never logged or read from stdin.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 26, 2026 11:33
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T11:37:52.726598Z 518321e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6a3a3078-25b7-462c-83cc-d069c133b169

📥 Commits

Reviewing files that changed from the base of the PR and between f32f9aa and 518321e.

📒 Files selected for processing (34)
  • docs-site/src/content/docs/fr/guides/remote-link.md
  • docs-site/src/content/docs/guides/remote-link.md
  • docs-site/src/content/docs/ja/guides/remote-link.md
  • docs-site/src/content/docs/ko/guides/remote-link.md
  • docs-site/src/content/docs/ru/guides/remote-link.md
  • docs-site/src/content/docs/tr/guides/remote-link.md
  • docs-site/src/content/docs/zh-cn/guides/remote-link.md
  • docs-site/src/content/docs/zh-tw/guides/remote-link.md
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/vi.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/pages/RemoteLink.tsx
  • gui/src/remote-link-api.ts
  • gui/src/styles-remote-link.css
  • gui/tests/remote-link.test.tsx
  • src/client/link-join.ts
  • src/client/link-teardown.ts
  • src/link/ssh-argv.ts
  • src/link/ssh-runner.ts
  • src/server/management/link-routes.ts
  • src/server/management/route-registry.ts
  • structure/gui-and-management-api.md
  • structure/remote-link.md
  • tests/clients/client-link-teardown.test.ts
  • tests/clients/link-ssh-argv.test.ts
  • tests/server/link-join-route.test.ts
  • tests/server/link-management-routes.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

Remote linking now uses Home-initiated setup, with Child joining gated by session availability. Remote SSH commands use an expanded PATH and return bounded error hints. The dashboard displays specific link errors, and the guides describe the updated requirements and troubleshooting steps.

Changes

Remote Link flow

Layer / File(s) Summary
Remote SSH execution and hints
src/link/ssh-argv.ts, src/link/ssh-runner.ts, src/client/link-*, tests/clients/*, tests/server/link-join-route.test.ts
Remote ocx commands use a PATH prelude that preserves existing command precedence and adds fallback directories. SSH operations attach sanitized, bounded hints to applicable failures.
Management route admission and remote checks
src/server/management/link-routes.ts, src/server/management/route-registry.ts, tests/server/link-*.test.ts, structure/*
Eligible standalone loopback dashboard sessions can use Home-side link routes. Joining remains paired-session-only. Host confirmation checks for OpenCodex 2.66.0 or later, and GUI status reports join availability.
Dashboard availability and error display
gui/src/remote-link-api.ts, gui/src/pages/RemoteLink.tsx, gui/src/i18n/*, gui/src/styles-remote-link.css, gui/tests/remote-link.test.tsx
The dashboard gates Child selection and joining on joinAvailable. It displays translated errors and optional API hints. Tests cover availability, Home linking, and hint sanitization.
Remote-link guides
docs-site/src/content/docs/*/guides/remote-link.md
The guides describe the Home-initiated flow, prerequisites, and unavailable Child-initiated setup. The English guide adds troubleshooting for SSH access, remote ocx lookup, and version checks.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant Dashboard as Home dashboard
  participant Routes as link-routes.ts
  participant SSH as SSH runner
  participant Host as Remote host
  Dashboard->>Routes: Request status and Home-side link operations
  Routes-->>Dashboard: Return join availability or link result
  Routes->>SSH: Run remote ocx command
  SSH->>Host: Execute command over SSH
  Host-->>SSH: Return output and exit status
  SSH-->>Routes: Return command result
  Routes-->>Dashboard: Return result and optional error hint
Loading

Merge Risk: ⚪ Minimal · up to 51832

The Remote Link changes are mergeable after normal checks; no actionable issue remains from this review.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 51832

A standalone dashboard can now manage remote links without pairing. The change keeps important session and loopback restrictions, but it gives that session access to operations that modify trusted SSH hosts, issue link keys, and connect or remove links. Concurrent or interrupted operations warrant design review.

Retained concerns

  • Medium · security · observed: The intentional shift from paired identity to a current standalone loopback dashboard session makes persistent SSH and link-key operations available to a less strongly authorized caller. This is a boundary tradeoff, not evidence of a bypass of the new session controls.
  • Medium · security · inferred: Newly admitted dashboard callers can concurrently exercise pre-existing, unsynchronized host-confirmation and link-lifecycle transitions. A failed confirmation can restore stale known_hosts contents; apply and deletion can interleave after a link record is written. The transition mechanisms predate this PR, while their caller exposure increases.
Security review details

Security Blast Radius

  • inferred — A qualifying session can affect one standalone runtime’s link records, issued link keys, and SSH operations against selected remote hosts. The inspected gates do not extend that authority to hub runtimes, Child joining, or direct key issuance.

Security Findings and Attack Paths

  • inferred — No bypass or exploitation is verified. The material path to review is a caller with a valid standalone loopback dashboard session submitting host and link requests that previously required pairing, including overlapping requests against shared host and link state.

Trust Boundaries and Controls

  • observed — Principal resolution occurs before route dispatch, and current-session revalidation uses the production session predicate. A loopback-issued session must also reach trusted loopback ingress; a request header alone does not select that ingress classification.

Resilience and Maintainability Implications

  • inferred — Confirmation checks the submitted fingerprint against the pending probe, but its later asynchronous result is not tied to a probe generation. Snapshot restoration can overwrite another confirmation’s known_hosts update. Compensation handles several ordinary failures, while interruption and concurrent apply/delete recovery remain unproven.

Hardening Proposals

  • proposed — Consider serializing or generation-binding confirmation and link lifecycle transitions, with durable reconciliation for an issued key or remote connection left between steps. Evaluate these controls against the intended authority of a credentialless local dashboard session.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 32.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 56 functions across 23 files. (11 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: Remote Link now loads and probes SSH hosts from the local dashboard. This matches the PR objective and the implemented dashboard, SSH, and loopback-sessio…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 32.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 56 functions across 23 files. (11 skipped: 11 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun

Copy link
Copy Markdown
Owner Author

리뷰 · 우선순위 50 / 80

이 글은 원격 연결 화면이 SSH 컴퓨터 목록을 하나도 못 불러오던 문제를 고칩니다. 바탕은 dev입니다.

혼자 쓰는 설치의 대시보드는 이 컴퓨터 안에서만 통하는 세션을 갖고 있습니다. 원격 연결 API는 짝을 맺은 세션만 받아 줬습니다. 그래서 목록, 연결 시험, 호스트 확인, 연결하기가 전부 403이었습니다. 화면에는 후보가 없다고만 나왔습니다. ~/.ssh/config를 읽는 코드는 원래 괜찮았습니다.

이제는 그 세션으로 홈 쪽 일을 할 수 있습니다. 상태, 후보, 연결 시험, 호스트 확인, 연결, 끊기가 여기 들어갑니다. 아이로 붙는 POST /api/link/join은 짝을 맺은 세션만 됩니다. 붙으면 이 프로그램이 다시 켜지고, 이미 붙어 있는 Codex 연결이 끊기기 때문입니다. 이번 화면에서는 아이 카드가 꺼지고, 홈에서 연결하라는 안내가 10개 언어로 나옵니다.

SSH를 켤 때 Homebrew와 ~/.bun/bin을 PATH 뒤에 붙입니다. 맥 앱이 짧은 PATH로 떠서 cloudflared를 못 찾던 경우를 위한 것입니다. 상대 컴퓨터의 ocx도 sh 안에서 같은 폴더를 PATH 뒤에 붙인 다음 부릅니다. 버전은 opencodex X.Y.Z 모양만 받고, 2.66.0보다 낮으면 거절합니다. 실패하면 이유 한 줄을 160자 안으로 보여 줍니다.

types.ts와 config.ts를 나누는 일과는 겹치지 않습니다. 같은 원격 연결을 고치는 다른 열린 PR은 없습니다.

라인 - src/link/ssh-argv.ts:145 remoteOcxArgv. 상대 ocx는 항상 sh -c로 부릅니다. 맥과 리눅스에는 sh가 있습니다. 윈도우 OpenSSH는 PowerShell이나 cmd가 기본인 경우가 많습니다. 거기에는 sh가 없을 수 있습니다. 본문은 고치기 전 윈도우가 ocx --version 사용법 글을 돌려줬다고 합니다. 그건 ocx가 실행됐다는 뜻입니다. 고친 뒤에는 sh가 먼저 있어야 합니다. 본문은 고친 뒤 윈도우를 다시 확인했다고 적지 않습니다. 종료 코드 127은 remote_ocx_missing이 됩니다. sh가 없어서 127이 나도 같은 말로 나갑니다.

라인 - GitHub Actions test 4/4 (run 36239223294). 파일 하나씩은 통과했는데, 묶음이 시간 초과로 죽었습니다. 종료 코드는 124입니다. 로그는 "every file passed alone"이라고 합니다. 그 때문에 ci 검사도 실패입니다. 1/4, 2/4, 3/4는 통과입니다. 실패 로그의 마지막 파일은 interactive-confirm과 star-deferral이고, 둘 다 통과입니다.

메인테이너의 판단이 필요한 지점

src/server/management/link-routes.ts:102 dashboardSession. 이 컴퓨터의 아무 프로그램이나, 로그인 비밀 없이, 이 세션으로 연결 시험, 호스트 확인, 연결을 할 수 있습니다. 그 일은 사용자의 SSH 열쇠로 상대 컴퓨터에서 ocx를 실행합니다. 작성자는 이것을 POST /api/github/star와 같은 수준이라고 적었습니다. 허브, Tailscale 세션, hub-link 입구, 아이로 붙기는 여전히 막혀 있습니다. 이 수준을 홈 쪽에 둘지 정해 주세요.

2.66.0-preview.20260925는 숫자 세 자리만 봐서 통과합니다. 테스트가 그 결과를 기대합니다. 미리보기인데 ocx link가 없으면 확인은 통과하고, 연결 단계에서 포트 실패가 납니다.

너의 추천

홈 쪽은 이 컴퓨터 세션을 허용하는 쪽으로 두세요. 아이로 붙는 길은 짝을 맺은 세션만 두는 지금 구분이 맞습니다. 머지 전에 윈도우 원격에서 sh 없이 ocx가 버전을 내는지 한 번 확인하세요. sh가 없으면 윈도우만 ocx를 직접 부르면 됩니다. test 4/4는 다시 돌려서 초록이 된 뒤에 넣으세요. 다른 열린 PR은 닫지 마세요.

이 댓글은 grok-bot이 작성했습니다

lidge-jun added a commit that referenced this pull request Sep 26, 2026
…ards (batch 9D) (#5986)

A second `ocx` instance now leaves the live proxy's shared client routing alone across startup, management requests, restart, and stop. The batch also makes Home-side Remote Link usable from the local dashboard, keeps OAuth device guidance current, and offers one-time pairing on an authenticated remote hub that lacks a GUI session.

| PR | Change | Author |
|---|---|---|
| #5926 | Isolate sibling startup, shared writes, restart and stop from the live owner. | JUN (lidge-jun) |
| #5928 | Admit the local Home dashboard to SSH host discovery/probe/apply, improve SSH resolution and bounded errors, and keep Child join paired-only. | JUN (lidge-jun) |
| #5911 | Show Meta Muse OAuth only to eligible GUI sessions and replace stale device hints through login. | Ingwannu, with shared device-hint work credited to codingbo |
| #5978 | Show the one-time pairing form on Remote Link for a remote hub without a GUI session. | RHODIZSECURITY |

The owner's three original commits retain JUN authorship. Each contributor PR remains one attributed squash commit. The older device-hint variant (#5915) is outside this branch because #5911 covers the same login behavior; its shared implementation is credited to codingbo.

Follow-up commits after independent review:

| Commit | Result |
|---|---|
| `66967095d0` | Restrict the new pairing display path to hub runtimes; a non-loopback standalone keeps its local-session guidance. |
| `fa182b9d2d` | Keep sibling-home roster updates available while skipping the shared Claude Desktop profile auto-apply, including after asynchronous discovery. |
| `32d7893113` | Require a fresh, home-bound listener proof before an orphan stop can signal a discovered proxy. |
| `dda805fbad` | Require a short-lived, one-use sibling restart handoff record bound to the prior sibling runtime and home; a port env alone cannot claim sibling status. |
| `37f368cf20` | Keep the connected-client sibling recycle path valid when its runtime record has no server attestation secret; the same-home PID, ports and process-local mark still gate issuance. |
| `a42fcac751` | Capture the connected sibling's one-use handoff before link recycle stops the listener and removes its runtime record; spawn with that captured environment. |
| `d3cc7b80bb` | Remove the Kiro cooldown test's timestamp-order race exposed by macOS CI. |

`dev` advanced during review. Merge commit `a4d9aff73e` brought in `177c647d9c` and kept both the SSH PATH and listener-before-supervisor Remote Link contracts. Merge commit `43d314287c` brings in current `dev` `93e5d5bea5` without changing the owner's commits. Their combined dashboard structure document exceeded its line budget; `1e93a8401b` reflows the existing OAuth paragraph from 603 to 600 lines without raising the cap. The Kiro timing correction also landed independently on `dev`; the merge keeps that current test.

Screenshots from the built GUI (demo session and responses only):

![Home SSH host candidates](https://github.com/lidge-jun/opencodex/blob/506401dea3857034b87d296e8b74b38b0f2ce7b3/260926-remote-link-ssh-hosts/03-home-sheet-candidates.png?raw=true)
![OAuth device hint with callback paste hidden](https://github.com/lidge-jun/opencodex/blob/a5d102c17e03caf10766d0bb15c32ac365dbc094/260927-codex-bug-train-9d/9d-oauth.png?raw=true)
![Remote hub one-time pairing form](https://github.com/lidge-jun/opencodex/blob/f53b699ce5e1ac4cb3d6772f4e86c0dec10808e3/260927-codex-bug-train-9d/9d-pairing.png?raw=true)

Security re-review should focus on sibling start/stop and handoff (`src/codex/sibling-start.ts`, `src/codex/sibling-handoff.ts`, `src/client/runtime.ts`, `src/cli/index.ts`, `src/server/proxy-liveness.ts`), Desktop auto-apply (`src/server/management/agent-settings-routes.ts`), Remote Link admission and SSH (`src/server/management/link-routes.ts`, `src/link/ssh-argv.ts`, `src/link/ssh-runner.ts`), OAuth state and principal discovery (`src/oauth/index.ts`, `src/oauth/login-flow-state.ts`, `src/server/management/oauth-account-routes.ts`), and the hub-only pairing gate (`gui/src/App.tsx`). Independent reviewer sign-off remains required before merge.

Co-authored-by: Ingwannu <ingwannu@users.noreply.github.com>
Co-authored-by: codingbo <cnsdbo@163.com>
Co-authored-by: RHODIZSECURITY <180237049+RHODIZSECURITY@users.noreply.github.com>
@lidge-jun

Copy link
Copy Markdown
Owner Author

Landed on dev through bug-PR merge train batch 9D, #5986 (merge 6b2b66d), as the original commit, keeping dev's async SSH spawn from #5936. Closing since the content is now on dev.

@lidge-jun lidge-jun closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant