Skip to content

fix(security): stabilize standalone pairing for Child enrollment - #6517

Merged
lidge-jun merged 13 commits into
devfrom
codex/release-261003-d
Oct 3, 2026
Merged

lidge-jun merged 13 commits into
devfrom
codex/release-261003-d

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Carry fix(security): require pairing for child link join #6076 onto current dev, retaining its original commits and authorship. Child join requires an operator-paired dashboard session; standalone enrollment uses the configured literal-loopback origin, a short-lived one-use grant and existing process attestation. The dashboard explains pairing, runtime-role and port refusals separately.
  • Add a real source-CLI/server HTTP regression for minting, bootstrap, redemption, replay refusal, CSRF and paired join admission. It obtains real sessions and reaches 409 host_not_confirmed without substituting HTTP dispatch, session control or joinHome.
  • Include the coordinator's semantic-preserving shared layout normalization from 29a9e91f400d24ac746a18dfe3af357f5da6dec3 with -x provenance, plus this test's unique registrations.

This is a Draft carry. The source PR's outstanding maintainer review is retained for coordinator disposition; this lane does not withdraw another maintainer's review. Its technical enrollment and independent security requirements now have the bounded evidence below. The source PR remains open; this lane does not merge or release.

Co-authored-by: luvs01 27862058+luvs01@users.noreply.github.com

Verification

Local evidence for the carried runtime and new regression:

  • bun test tests/gui/gui-pair-capability.test.ts tests/gui/gui-pair-client.test.ts tests/server/link-join-route.test.ts tests/server/link-management-routes.test.ts tests/server/server-management-auth.test.ts tests/server/management-route-registry.test.ts — 135 pass, 0 fail.
  • bun test tests/gui/gui-pair-http.test.ts — 1 pass, 43 assertions. Real source CLI mint and listener redemption; unpaired 403 forbidden, pairing_required, paired status, replay/origin/alternate-credential/CSRF refusals, and paired 409 host_not_confirmed. Owned subprocesses and temporary state cleaned up.
  • bun test tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.ts after shared normalization — 27 pass, 0 fail.
  • GUI focused tests (local-link-pairing, connect-pairing, remote-link) — 52 pass, 0 fail; GUI lint, i18n lint and production build passed. Build reported the existing large-chunk warning.
  • bun run typecheck, bun run privacy:scan, bun run structure:check, documentation production build and git diff --check passed. Docs built 561 pages and checked 77,932 internal links.
  • Independent security source review and new test/carry review: no established P0–P2 application finding. Operational acceptance remains separate.
  • Manual isolated macOS source CLI grant → actual built-browser redemption → real OpenSSH host confirmation → browser Child join returned 202. The old process exited; a new client process owned the original configured port, a real SSH tunnel authenticated, and persisted Child role/link matched. The dashboard reloaded as connected. The old session returned 401 and the old grant was rejected with 404 after role transition. Independent operational security review passed for this scope.
  • Native fixture limits: the Home used a synthetic empty catalog and Child Codex integration was enabled only inside the disposable home. No model discovery, inference, installed-package or native desktop claim. Diagnostic runs were excluded; final acceptance used uninstrumented production source. All task processes, tunnels, listeners and browser stopped; issued Home key/link revoked and SSH private keys removed.
  • Native evidence was captured at 58ad4971df220976f8ecb1f79a8883a4e0874031. Current dev e601cefcebcc20b2e04a04821ab45df6538d98f9, including merged auth PR fix(codex): classify revoked native sessions without stale attribution #6515, was reconciled as ef743072838bc29626dd5b8490efa78f4ff82d9f. Pairing, management auth/CORS, dispatch, GUI, client and link boundary paths are unchanged from the demonstrated native source. The post-B union passed 172 focused tests (1,929 assertions), typecheck, privacy and structure checks; independent interdiff security review passed. The native scenario itself was not rerun on this new head.
  • Full GUI suite: 2,848 pass, 0 fail, 28,206 assertions across 321 files.
  • Hosted before/after GUI screenshots remain pending authorized upload; the screenshot gate is not waived.

Full-local-suite exception: concurrent release worktrees share host resources. Focused regressions above were run; no full local suite or test:changed result is claimed. Applicable required CI must complete for the final current head; results from earlier heads are historical only. Packaged desktop, other native platforms, model discovery and inference remain unverified. CI event, tested SHA/tree, run and attempt evidence will be recorded after completion. The integration coordinator owns the final combined-lane regression and merge.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive source changes were independently reviewed for secrets, auth and unsafe defaults.
  • Bounded isolated macOS source enrollment/restart and independent operational security review passed.
  • Coordinator has recorded disposition of the source PR's retained maintainer review.
  • Hosted GUI screenshot evidence is attached.
  • Applicable required CI completed successfully for this exact head.

UI evidence

Visually inspected screenshots from the isolated macOS source fixture. No pairing code, session token or account data is visible. The original tested boundary source at 58ad4971 is unchanged in the current ef743072 integration; this is not packaged/Windows acceptance.

Before pairing: Child admission is disabled with operator guidance

After one-use pairing: Child selection is available

After real SSH join and process replacement: connected Child

Summary by CodeRabbit

  • New Features
    • You can pair a standalone computer through its local dashboard using an operator-created, one-time code.
    • Child connections now require an operator-paired dashboard session and a standalone runtime on its configured port. The dashboard explains whether pairing, runtime role, or port settings prevent joining.
  • Documentation
    • Updated Remote Link setup guides across supported languages with pairing steps and dashboard requirements.

luvs01 and others added 11 commits September 27, 2026 19:21
Keep paired-only join authorization. Allow the existing attested CLI grant flow only for the configured literal loopback origin in standalone mode, with runtime address/port checks, a kernel-local redemption peer, one-use codes, fixed five-minute sessions, and role/origin invalidation. Ordinary automatic sessions remain unpaired.

Expose explicit code entry during local link setup. Omit stale shared credentials only for the pairing exchange, retaining separate machine-relay credentials and normal API authentication.

Add grant/session negatives, a real CLI-capability/session-control/guarded-route composition test (SSH join stubbed), and browser transport/form regressions. Validation here: complete session/capability modules with relevant auth helper excerpts: original 3 pass/4 fail, patched 7 pass/0 fail. Complete browser API module with a minimal Window adapter: original 0 pass/2 fail, patched 2 pass/0 fail. All changed TS/TSX files syntax-transpiled. Full Bun, React, repository typecheck, full server HTTP transport and native SSH/restart suites were not run locally. Independent security review and exact-head CI remain required; keep this PR in Draft.
Carries source PR #6076 with original history; preserves standalone operator pairing and paired-only Child join.

Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Exercise production discovery, capability mint, redemption, replay rejection and guarded Child admission with isolated subprocess state.
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0076cc88-7581-4b50-b3ef-753dc1a7798c
📥 Commits

Reviewing files that changed from the base of the PR and between e601cef and ef74307.

📒 Files selected for processing (39)
  • devlog/_plan/261003_release_lane_d/000_plan.md
  • docs-site/src/content/docs/fr/guides/remote-link.md
  • docs-site/src/content/docs/guides/remote-link.md
  • docs-site/src/content/docs/ja/guides/remote-link.md
  • docs-site/src/content/docs/ko/guides/remote-link.md
  • docs-site/src/content/docs/ru/guides/remote-link.md
  • docs-site/src/content/docs/tr/guides/remote-link.md
  • docs-site/src/content/docs/zh-cn/guides/remote-link.md
  • docs-site/src/content/docs/zh-tw/guides/remote-link.md
  • gui/src/api.ts
  • gui/src/connect-pairing.tsx
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/pt.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/vi.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/pages/RemoteLink.tsx
  • gui/src/remote-link-api.ts
  • gui/tests/local-link-pairing.test.ts
  • gui/tests/remote-link.test.tsx
  • scripts/test-layout/layout.json
  • src/cli/gui.ts
  • src/lib/gui-pair-capability.ts
  • src/server/gui-session.ts
  • src/server/management/link-routes.ts
  • src/server/management/route-registry.ts
  • structure/gui-and-management-api.md
  • structure/remote-link.md
  • tests/fixtures/test-layout-expected.json
  • tests/gui/gui-pair-client.test.ts
  • tests/gui/gui-pair-http.test.ts
  • tests/server/link-join-route.test.ts
  • tests/server/link-management-routes.test.ts
 _____________________________
< Reviewing code like a boss. >
 -----------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ READY

  • all PR quality gates passed.

Hygiene

✅ Deterministic PR hygiene checks passed.

Retain standalone pairing carry and its unique real-HTTP regression after shared registry normalization and upload integration.
@lidge-jun

Copy link
Copy Markdown
Owner Author

Technical disposition for the reviewed replacement #6517 at ef743072838bc29626dd5b8490efa78f4ff82d9f:

The original unreachable-standalone objection is addressed. An actual standalone CLI command now mints a process-attested, short-lived one-use grant for the configured literal-loopback origin; production HTTP redemption creates a paired session. The new gui-pair-http.test.ts uses real CLI/server subprocesses and actual issuance/redemption, retains unpaired/replay/origin/CSRF/alternate-credential refusals, and reaches the real join handler without a paired: true authorization stub. The updated GUI distinguishes pairing, runtime-role and port refusals and provides explicit recovery guidance.

A separate isolated macOS source exercise completed real browser redemption, OpenSSH host verification, join HTTP 202, old-process exit, replacement on the original port, authenticated tunnel and matching persisted Child state. Old sessions/grants were refused after transition, and owned resources were cleaned up. It used a synthetic empty Home catalog and scratch-only Codex integration; it does not prove fresh-install catalog creation, model inference, installed packages or native Windows/Linux enrollment. The final acceptance path was uninstrumented. The tested pairing boundaries at 58ad4971 are byte-identical in the replacement head.

Independent exact-head coordinator security review accounted for all 39 files and found no verified P0–P2 defect. This is a process/CLI authority boundary, not proof of human presence or protection against a same-user process capable of invoking that authority. Required replacement-head CI passed at https://github.com/lidge-jun/opencodex/actions/runs/37135315210; inspected screenshots are linked in #6517 by immutable pr-assets commit.

I am recording the concrete technical conditions as resolved for the replacement and resolving this original reachability thread on that evidence. Ingwannu's historical CHANGES_REQUESTED review is not withdrawn, dismissed or represented as an approval; this is not approval of the stale original PR head. The owner-authorized replacement integration decision remains separate, and final integrated regression/release gates still apply.

@lidge-jun
lidge-jun marked this pull request as ready for review October 3, 2026 16:43
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner October 3, 2026 16:43
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T16:48:14.678048Z ef74307 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@lidge-jun

Copy link
Copy Markdown
Owner Author

Owner-authorized progressive maintainer integration into dev for release stabilization; this is a separate integration/security decision, not self-approval or dismissal of another maintainer's historical review.

The original source6076 technical objection is resolved by the reachable process-attested standalone CLI grant, real HTTP redemption and paired join admission, plus typed GUI denial/recovery guidance. The evidence-backed condition mapping is recorded above and in the source review-thread reply; that original reachability thread is now resolved. Ingwannu's historical CHANGES_REQUESTED review remains intact and is not represented as withdrawn or approved.

Independent coordinator review accounted for all 39 files at this head and traced capability issuance, exact origin/peer/method/process binding, bounded one-use redemption, fixed local paired expiry, live session revalidation, CSRF, role/port gates and browser transport separation. No verified P0–P2 defect remained. Explicit security review: PASS for that scoped boundary. Local process/CLI authority is not proof of human presence and does not claim resistance to a same-user process able to exercise that authority; existing Home apply/probe powers are not widened or represented as fixed here.

Main inspected the retained native receipts and safe screenshots: real source CLI/browser/OpenSSH join returned202, the original process exited, an uninstrumented replacement owned the configured port, its tunnel owner and durable Child link matched, and old sessions/grants were refused. Owned processes/listeners/keys were cleaned up. The exact tested pairing boundaries are unchanged from58ad to this head. This uses a synthetic empty Home catalog and scratch-only Codex integration; it is not fresh-install catalog generation, inference, npm-installed or native Windows/Linux/desktop proof. Diagnostic preload attempts are excluded. Immutable screenshot links satisfy the UI evidence requirement.

The new CLI/HTTP regression avoids injected paired authorization and retains negative cases. Focused boundary checks, full GUI tests, lint/i18n/build, type/privacy/structure and docs checks passed. I reviewed the newer Anthropic identity integration for overlap; it does not modify the pairing/enrollment boundaries. The prospective merged tree passes actual repository line caps and both layout-map parity checks. Final independent integrated regression and full cross-platform candidate CI still precede production publication.

The optional external CodeRabbit review context is still pending and is not counted as a passing review. Current-head independent review is complete and every currently published finding is resolved; post-merge/final review checks remain mandatory.

Hosted receipt: https://github.com/lidge-jun/opencodex/actions/runs/37135315210, attempt 1, pull_request, tested head ef743072838bc29626dd5b8490efa78f4ff82d9f / base e601cefcebcc20b2e04a04821ab45df6538d98f9. Current reviewed dev base 358b8ffd4c7f95237dadee1e9a5b4fedb671f4f4; conflict-free union tree b7c6853cd1f36bc8530be2b7f575e2524f2700ea. All four Linux shards and selected gates/storage/API/docs/structure/Docker/keyring/npm-global jobs succeeded. Skipped full-platform suites are not claimed passing; final integrated lane=all remains required.

@lidge-jun
lidge-jun merged commit a99de42 into dev Oct 3, 2026
41 of 45 checks passed
@lidge-jun
lidge-jun deleted the codex/release-261003-d branch October 3, 2026 16:49
@lidge-jun lidge-jun mentioned this pull request Oct 4, 2026
3 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants