Skip to content

Restore paired sessions and Preview after Wi-Fi changes - #459

Merged
Tryanks merged 1 commit into
mainfrom
codex/fix-network-recovery-409
Sep 18, 2026
Merged

Tryanks merged 1 commit into
mainfrom
codex/fix-network-recovery-409

Conversation

@Tryanks

@Tryanks Tryanks commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

Moving a paired phone and computer from home Wi-Fi to company Wi-Fi can leave Tcode retrying forever even when their new IPs are mutually reachable. The recovery added in #453 remembered known addresses but generally probed only .1 on a normal /24; the new computer address could remain undiscovered. QR generation could also prefer a virtual bridge address over Wi-Fi.

This change restores discovery of an unknown LAN address, authenticates the machine before sending credentials, resumes the existing subscriptions, and moves the same Preview browser to the authenticated endpoint. It follows up #409 and #453. The implementation review reconstructs the original implementation and documents decisions, attack boundaries, regression evidence and remaining field checks.

Changes:

  • Rank ordinary LAN interfaces ahead of bridges/tunnels, retain distinct discovered addresses, and include alternate addresses and a public key in new QR invitations. Probe bounded pages of attached private IPv4 networks; rotate interfaces and neighboring pages without starving lower-priority networks. Fresh hints can replace a full cache, while repeated oversized batches do not keep restarting recovery.
  • Preserve in-flight mDNS browsing and partially written WebSocket frames when new hints arrive. Every connection attempt considers alternatives, and successful recovery replays the existing subscriptions.
  • Verify a nonce-bound Ed25519 proof on the same connection before native LAN hello/Preview credentials. Existing valid pairings bootstrap their pin through an HMAC using the stored token hash. New QR pairing races identity checks and submits the single-use code only to the verified winner. Bound unauthenticated HTTP and WebSocket inputs before payload allocation.
  • Give transport the current authenticated LiveHost snapshot, independent of disk persistence. Preview retains its browser URL/history, cancels old connections and uses the new endpoint even if the address cannot be saved; it does not replay browser requests.
  • Serialize hosts.json field updates across processes, preserve pins and replacement credentials, discard superseded pairing results before saving, and commit AuthStore memory changes only after successful disk writes. Localize the new pairing failures in English and Chinese.
  • Fix the discovered block 0.1.6 uninhabited extern-static declaration with an API-compatible source patch. The vendored copy retains its license and upstream interoperability tests; provenance and removal criteria are included.

Validation:

  • Passed cargo fmt --all --check, full-workspace Clippy with -D warnings, build, tests and cargo machete 0.9.2.
  • Passed the CI iOS simulator, Android arm64 (API 26 / NDK 27.1.12297006) and Web compile commands with RUSTFLAGS='-D warnings'.
  • Passed the release build without compiler/linker warnings, the explicit loopback mDNS check, and the patched dependency's six C/Rust interoperability tests plus two doctests.
  • Regression coverage includes discovering a previously unknown home-to-office address through the production connection loop and receiving Index/SessionEvents snapshots; forged identities and oversized declarations without credential disclosure; single-use QR pairing; full/repeated candidate batches; subnet boundaries/fairness; browse and partial-frame cancellation; stale persistence; revoked/damaged tokens; and Preview migration with old servers still online or failed disk writes. Relevant bugs were demonstrated red before their fixes. The older known-candidate fixture now allows first-round recovery instead of requiring an intermediate failure state; its identity and persistence assertions remain.

Compatibility and limits: update both native client and server for LAN identity checks. These proofs do not encrypt HTTP or stop a transparent plaintext relay; HTTPS/overlay security remains relevant. Large subnets, unknown listener ports, IPv6-only discovery and OS background suspension retain documented limits. The unoptimized macOS development binary has an unwind-index capacity warning; the final optimized binary's unwind section is 2.57 MiB and emits no warning. Local workspace validation ran on macOS; GitHub CI must validate Windows/Linux. No connected phone was available for a physical home/company Wi-Fi migration, and this PR does not claim that field acceptance is complete.

@Tryanks
Tryanks merged commit 6c75ce6 into main Sep 18, 2026
6 checks passed
@Tryanks
Tryanks deleted the codex/fix-network-recovery-409 branch September 18, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant