Restore paired sessions and Preview after Wi-Fi changes - #459
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moving a paired phone and computer from home Wi-Fi to company Wi-Fi can leave Tcode retrying forever even when their new IPs are mutually reachable. The recovery added in #453 remembered known addresses but generally probed only
.1on a normal/24; the new computer address could remain undiscovered. QR generation could also prefer a virtual bridge address over Wi-Fi.This change restores discovery of an unknown LAN address, authenticates the machine before sending credentials, resumes the existing subscriptions, and moves the same Preview browser to the authenticated endpoint. It follows up #409 and #453. The implementation review reconstructs the original implementation and documents decisions, attack boundaries, regression evidence and remaining field checks.
Changes:
LiveHostsnapshot, independent of disk persistence. Preview retains its browser URL/history, cancels old connections and uses the new endpoint even if the address cannot be saved; it does not replay browser requests.hosts.jsonfield updates across processes, preserve pins and replacement credentials, discard superseded pairing results before saving, and commit AuthStore memory changes only after successful disk writes. Localize the new pairing failures in English and Chinese.block 0.1.6uninhabited extern-static declaration with an API-compatible source patch. The vendored copy retains its license and upstream interoperability tests; provenance and removal criteria are included.Validation:
cargo fmt --all --check, full-workspace Clippy with-D warnings, build, tests andcargo machete0.9.2.RUSTFLAGS='-D warnings'.Compatibility and limits: update both native client and server for LAN identity checks. These proofs do not encrypt HTTP or stop a transparent plaintext relay; HTTPS/overlay security remains relevant. Large subnets, unknown listener ports, IPv6-only discovery and OS background suspension retain documented limits. The unoptimized macOS development binary has an unwind-index capacity warning; the final optimized binary's unwind section is 2.57 MiB and emits no warning. Local workspace validation ran on macOS; GitHub CI must validate Windows/Linux. No connected phone was available for a physical home/company Wi-Fi migration, and this PR does not claim that field acceptance is complete.