Skip to content

fix(link): require owned listener before tunnel startup - #648

Closed
luvs01 wants to merge 2 commits into
devfrom
codex/fix-link-tunnels-startup-on-bind-failure
Closed

luvs01 wants to merge 2 commits into
devfrom
codex/fix-link-tunnels-startup-on-bind-failure

Conversation

@luvs01

@luvs01 luvs01 commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Motivation

  • Prevent an attacker from occupying a persisted listener port across restart and having the automatic hub-initiated supervisor spawn an SSH reverse-forward to an attacker-owned service.
  • Ensure the supervisor only starts when the hub-link listener actually owns a listening socket on a concrete port so reverse forwards cannot target an unowned port.

Description

  • Added linkListenerOwnsTarget predicate in src/server/index/link-listener.ts to express when a listener actually owns a concrete listening socket (state === "listening" && port !== null).
  • Gate automatic supervisor startup in src/server/index/optional-listeners.ts so supervisor.start() runs only when the listener ownership predicate is true while preserving the supervisorStop shutdown hook for later registration.
  • Added a focused regression assertion in tests/server/link-listener-lifecycle.test.ts to cover failed/off/listening ownership states.
  • Documented the startup invariant in structure/remote-link.md so the design intent is explicit: automatic startup must not start tunnels when the listener failed to bind.

Testing

  • Ran bun run typecheck which completed successfully.
  • Ran bun run structure:check and bun run privacy:scan which completed successfully, and git diff --check returned clean.
  • Attempted bun test tests/server/link-listener-lifecycle.test.ts but the environment-provided Bun (v1.2.14) fails importing a node:zlib symbol used by the repository; the project requires Bun v1.4.0 so the focused test could not complete in this sandbox (the change adds a lightweight assertion that exercises the new predicate).

Codex Task


Devin Review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: luvs01/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1e358660-2b7e-4ba1-b57c-bf9d20d2a8ea


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@github-actions

Copy link
Copy Markdown

✅ Deterministic PR hygiene checks passed.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@luvs01

luvs01 commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

이관됨: lidge-jun#5966

@luvs01

luvs01 commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

동일 수정이 상류 저장소에 제출되어 이 포크 PR의 목적은 달성됐습니다. 상류 심사 결과에 따라 닫힌 상태를 유지하거나 필요시 재오픈합니다.

@luvs01 luvs01 closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aardvark bug Something isn't working codex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant