Skip to content

fix: bind companion server to 0.0.0.0 and resolve active host dynamically (#109) - #124

Closed
Yash990-bit wants to merge 11 commits into
TypeSafeAI:mainfrom
Yash990-bit:companion-listen-all
Closed

Yash990-bit wants to merge 11 commits into
TypeSafeAI:mainfrom
Yash990-bit:companion-listen-all

Conversation

@Yash990-bit

@Yash990-bit Yash990-bit commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Related: #109 (remains open).

Closed without merge after network-boundary review. See maintainer rationale.

Summary

  • Bind the paired LAN companion HTTPS listener to 0.0.0.0, retaining 127.0.0.1 isolation for loopback operation and tests.
  • Preserve the listener and port across LAN address changes; update Bonjour and the pairing QR to the current primary address without application-initiated connection teardown.
  • Keep the token and certificate stable. Close the listener while offline and rebind across loopback/LAN transitions; withhold stale QR endpoints during those transitions. Physical network changes can still interrupt a phone connection.
  • Preserve the newer mobile thread-creation test when resolving the conflict, and extend the contributor's regression coverage for listener identity, credentials, offline status and loopback/LAN transitions.

Verification

  • npm run build && npm test: passed (15 core, 293 desktop, 1 browser bridge, 10 site, 9 store-desktop tests).
  • Added stale-QR regression failed before the follow-up fix and passed afterward.
  • Signed integration commit; all 122 local desktop/browser E2E tests passed.
  • Hosted CI cancellation was requested after the decision to close without merging; no hosted pass is claimed.
  • Updated docs/status.md.

Original fix and LAN regression contributed by @Yash990-bit; maintainer follow-up resolves current-main conflicts and covers transition edge cases.

…ally (TypeSafeAI#109)

Bind the LAN companion HTTPS server to 0.0.0.0 (wildcard) while retaining loopback isolation for tests, allowing phone pairing to persist across IP updates and Wi-Fi interface roaming without tearing down the server socket or changing ports. Update status() to dynamically resolve the current active primary LAN IP for pairingUri.
@vercel

vercel Bot commented Oct 6, 2026

Copy link
Copy Markdown

@Yash990-bit is attempting to deploy a commit to the 0xBuns Team on Vercel.

A member of the Team first needs to authorize it.

…#129)

Record signed release and public-download verification, advance the verified website fallback, and drain Gatekeeper output without weakening rejection handling. Build, typecheck, 310 unit/bridge tests, 114 desktop and 7 website E2E tests passed; all four hosted checks and independent review passed.
Provide labeled offline review workspaces, a reusable iOS demo QR, isolated demo state, and platform-specific review instructions. Verified native and desktop flows, signed distribution candidates, Apple validation, and green hosted CI.
Add paired iPhone thread creation and provider-native command discovery. Keep the offline review demo usable with the new controls, preserve drafts, and ignore stale creation and command results.

Validated workspace build, typecheck and unit suites; 116 desktop and 7 site E2E tests; 28 native unit tests; paired and offline demo iPhone flows. Both macOS and iPhone checks passed on the PR and branch runs.
…eSafeAI#131)

Record uploaded iOS and Mac Store beta builds, saved review notes, posted reviewer replies, and the remaining production listing and host-release work. Verify the published standalone v0.0.8 update checker and both themed banner flows.

Validation: workspace build and unit tests; two packaged update-banner E2E cases; live release feed and artifact digest; App Store Connect readback; independent docs review.
Normalize tool summaries, expose active work in the rail, and keep theme tokens consistent.
Share theme and typography tokens across the workspace, expose live CLI subagents, and keep tools compact with expandable details. Preserve browser address edits across delayed snapshots and make terminal fixture cleanup deterministic.
Add the standalone TypeSafe-styled usage preview with responsive, collapsible navigation and an explicit Demo Data presentation.

Use one deterministic fictional ledger across charts, filters, projects, accounts, sources and CSV export, including unpriced GitHub Copilot scenarios. Preserve unknown costs and document the preview boundary.

Verified with build, desktop typecheck, 327 unit tests and 129 end-to-end tests.
Apply the Coven accent to the existing logo silhouette while retaining the original pink artwork in other themes. Preserve transparent cutouts and existing background styling.

Verified built Electron screenshots, build, typecheck, 327 unit tests and 129 end-to-end tests.
@BunsDev BunsDev self-assigned this Oct 7, 2026
@BunsDev

BunsDev commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Thanks @Yash990-bit for reporting #109 and contributing this fix. I verified that current main still binds the companion listener to one address, so this change is still needed.

I’m resolving the conflict while preserving both your LAN regression test and the newer mobile thread-creation test. I also added coverage for listener identity, token/certificate preservation, offline transitions, and loopback/LAN rebinding. That exposed a small QR edge case: the old-host fallback could advertise a stale endpoint while offline. The integration now withholds the QR until a usable listener/address pair is available.

Build and test verification is underway; I’ll update this PR with the final results before merging.

Preserve both companion test suites and cover listener identity, trust, offline status, and loopback/LAN transitions. Withhold stale pairing endpoints while the listener is unavailable or awaiting a scope change.
@BunsDev

BunsDev commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Thanks @Yash990-bit for the report, implementation, and regression test. After integrating current main and checking the network boundary, I’m closing this PR without merging. My earlier update anticipated a merge; the additional review below changed that decision.

Two design issues remain:

  • listen(..., "0.0.0.0") accepts connections on every IPv4 interface, not just the private addresses returned by localAddresses(). That includes a public-facing interface if the Mac has one. An isolated probe using selected addresses 192.168.1.10 and 192.168.2.20 still reached the HTTPS server through excluded 127.0.0.1. It returned 401, so authentication is intact; the concern is expanding listener exposure beyond the companion’s documented LAN boundary.
  • Both the QR and Bonjour TXT endpoint still use only addresses[0]. A phone on an isolated secondary LAN is still given the primary LAN address, even though the wildcard socket would accept traffic on its own LAN. Widening the socket alone therefore does not complete the multi-interface pairing fix.

The follow-up commit 8d16684 resolved the test conflict and added offline/stale-QR and loopback transition coverage. Build, all 328 unit/bridge tests, and all 122 local desktop/browser E2E tests passed. Those checks do not establish the network-boundary or secondary-LAN behavior above, so I will not treat green CI as sufficient to merge this approach.

I’m keeping #109 open for a replacement that binds only supported local addresses and gives the phone a reachable endpoint on its LAN, with explicit tests for excluded interfaces and secondary-network discovery. The original contribution and maintainer follow-up remain on this branch for reference. Hosted CI cancellation was requested after closure; there is no new hosted acceptance claim. Thank you for identifying the underlying problem and doing the initial work.

@Yash990-bit

Copy link
Copy Markdown
Contributor Author

Thank you @BunsDev for the rigorous review, security audit, and for integrating the LAN regression tests in 8d16684!

The rationale on the network boundary is completely sound—restricting listeners strictly to authorized private interfaces rather than a wildcard 0.0.0.0 is essential to avoid unwanted exposure on public/untracked interfaces, and addressing secondary-LAN reachability in discovery/QR makes total sense.

Really appreciate the deep dive and thoughtful feedback on this PR!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants