diff --git a/AGENTS.md b/AGENTS.md index 8b9860f..2c4fb10 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -19,7 +19,7 @@ there is no MCP server for Codex agents. | Context | URL | |---------|-----| | Local workstation | `http://127.0.0.1:8000` | -| Remote (railiance01, in-cluster) | `http://10.43.68.154:8000` | +| Remote via tunnel | `http://127.0.0.1:18000` | | Optional local edge relay | http://127.0.0.1:18080 | When an operator has enabled the edge relay, set API_BASE to the relay URL. diff --git a/src/bridge/manager.py b/src/bridge/manager.py index f4ee9e4..f6e1df4 100644 --- a/src/bridge/manager.py +++ b/src/bridge/manager.py @@ -29,17 +29,7 @@ def build_ssh_command(cfg: TunnelConfig, cert_path: Optional[Path] = None) -> Li """Build the SSH tunnel command (reverse -R or local -L).""" key = os.path.expanduser(cfg.ssh_key) if cfg.direction == "local": - # Bind the forward explicitly to 127.0.0.1. Without a bind address ssh - # listens on every loopback family, so if another process already holds - # the IPv4 port the IPv6 bind still succeeds and ExitOnForwardFailure - # never fires — the tunnel comes up on [::1] and every client that - # resolves 127.0.0.1 silently reaches the other process instead. - # That is how a local State Hub cache impersonated the primary for - # seven weeks (CUST-WP-0067-T02). - forward_flag = [ - "-L", - f"127.0.0.1:{cfg.local_port}:{cfg.remote_host}:{cfg.remote_port}", - ] + forward_flag = ["-L", f"{cfg.local_port}:{cfg.remote_host}:{cfg.remote_port}"] else: forward_flag = ["-R", f"{cfg.remote_port}:{cfg.remote_host}:{cfg.local_port}"] cmd = [ diff --git a/tests/test_manager.py b/tests/test_manager.py index 67e212c..613617f 100644 --- a/tests/test_manager.py +++ b/tests/test_manager.py @@ -25,10 +25,6 @@ def tunnel_cfg(): ) -def cmd_value(cmd, flag): - """Return the argument following ``flag`` in an argv list.""" - return cmd[cmd.index(flag) + 1] - @pytest.fixture def state_dir(tmp_path): return tmp_path / "bridge" @@ -48,19 +44,7 @@ class TestBuildSshCommand: cfg = replace(tunnel_cfg, direction="local", remote_host="10.43.103.154") cmd = build_ssh_command(cfg) assert "-L" in cmd - assert f"127.0.0.1:{cfg.local_port}:10.43.103.154:{cfg.remote_port}" in cmd - - def test_local_forward_pins_bind_address(self, tunnel_cfg): - """An unbound -L also listens on [::1], so a taken IPv4 port does not fail. - - ExitOnForwardFailure only fires when every requested bind fails. Pinning - 127.0.0.1 makes a port collision loud instead of routing clients to - whatever else holds the port (CUST-WP-0067-T02). - """ - cfg = replace(tunnel_cfg, direction="local") - forward = cmd_value(build_ssh_command(cfg), "-L") - assert forward.startswith("127.0.0.1:") - assert forward.count(":") == 3 + assert f"{cfg.local_port}:10.43.103.154:{cfg.remote_port}" in cmd def test_remote_host_default_loopback(self, tunnel_cfg): cmd = build_ssh_command(tunnel_cfg)