Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: luvs01/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
…onnect Co-Authored-By: Epinephrine <luvs01@hanmail.net>
…readyz A port squatter could answer the unkeyed /readyz probe with the 401 challenge and receive the following keyed request; readiness now only runs while the LISTEN owner of the tunnel port is the spawned ssh process (unverifiable scans stay not-ready), and both probes use redirect: manual so a redirecting occupant cannot reroute the challenge or the credential-bearing request. Co-Authored-By: Epinephrine <luvs01@hanmail.net>
… ss fallback Three join-readiness hardening fixes: - scanListenEntries now keeps each listener's bound address and the readiness check only counts sockets that serve the tunnel's 127.0.0.1 bind — a listener on 127.0.0.2 or another interface no longer stalls enrollment until the issued link is revoked. - The POSIX scanner chain gains ss -Hltnp between lsof and netstat, so minimal Linux installs with only iproute2 can still verify ownership instead of failing every probe as unavailable. - Ownership is re-verified in the same iteration immediately before the keyed request, narrowing the scan-to-request takeover window that could have delivered the issued key to a port flipper. Co-Authored-By: Epinephrine <luvs01@hanmail.net>
|
이관됨: lidge-jun#6042 |
|
동일 수정이 상류 저장소에 제출되어 이 포크 PR의 목적은 달성됐습니다. |
Motivation
x-opencodex-api-keybefore the SSH tunnel actually owns the forward.Description
JOIN_TUNNEL_SPAWN_GRACE_MS) and require the spawned tunnel handle to be observed before issuing credential-bearing readiness probes by changingwaitForReadyto accept aClientLinkTunnelHandleand racing readiness probes againsttunnel.exited.fetchof the loopback/readyzendpoint with tunnel exit so an exited tunnel short-circuits enrollment and triggers the existing rollback flow instead of delivering the key.joinHomeso the readiness gate can monitor the supervisor handle returned byspawnClientLinkTunneland fail fast on tunnel termination.tests/server/link-join-route.test.tsproving that an already-exited tunnel does not receive the issued key, that issuance is revoked, and that rollback behavior remains intact.structure/runtime.mdto record the architectural expectation for client-initiated Remote Link enrollment.Testing
./node_modules/.bin/bun test tests/server/link-join-route.test.ts, which passed (11 tests, 0 failures) under the repository-pinned Bun used in CI emulation../node_modules/.bin/bun run typecheck, which passed../node_modules/.bin/bun run structure:check, which passed after the smallstructure/runtime.mdupdate../node_modules/.bin/bun run privacy:scan, which passed.Codex Task