--host 0.0.0.0 is blocked because the shipped Web carrier has no TLS or authentication and can reach Agent tool effects.rc.7 fixed one carrier, not every carrier.
getRandomValues()The rc.7 fallback works on an insecure origin.
randomUUID()Host, Workspace, Session, Settings, and model calls can throw before fetch.
randomUUID()Image selection has a second secure-context dependency.
The UUID throw can impersonate a socket failure.
host.describeThe typed call mints an RPC id before fetch.
abort()The failed handshake closes both event streams.
connection lostBackoff starts a generation that fails the same way.
A loopback URL can still carry the wrong Origin.
127.0.0.1:3080The URL and Host retain the serving port.
Origin: 127.0.0.1A DNR rule removes the port before transport.
HTTP 403The RPC and native picker never run.
Capture the actual Host, Origin, Sec-Fetch-Site, initiator, and extension state in DevTools Network. Repeat in a clean profile or with the identified extension disabled for this site.
Choose the operator boundary.
Keep both DSH and the tunnel endpoint on loopback. The browser sees a real localhost origin.
ssh -N -L 127.0.0.1:3080:127.0.0.1:3080 user@hostThe gateway owns TLS, identity, revocation, rate limits, WebSocket forwarding, and audit.
public gateway → 127.0.0.1:3080Do not patch generated files or the trust fence just to make the port open.
--host 0.0.0.0 ✕Remote does not mean local parity.
A proxy can rewrite headers, but that does not create authentication. If it defeats the loopback fence, the proxy becomes the real security boundary and must be reviewed and tested accordingly.
A three-second guard is not a stream guillotine.
A slow-link report connected Signal timed out to streamOpenTimeoutMs: 3_000. The timing is evidence, but the pinned rc.7 source shows a different lifecycle: the guard bounds readiness waiting and does not abort either event pump.
describe + two event pumpsMeasure one opening timeline.
01DNS · TCP · TLSNetwork or certificate handshake02IdentityRedirect and authentication duration03UpgradeStatus and first response headers04StreamsOpen, first frame, close code05HistoryCorrelation to first Session renderCompare the same disposable Session on loopback and through the relay. A longer timeout changing the symptom is a useful experiment, not root-cause proof.
Prove denial before success.
- Anonymous HTTPReject or redirect before DSH.
- Anonymous APINo request reaches the RPC bridge.
- Anonymous socketReject the WebSocket upgrade.
- Authenticated turnStream one bounded read-only task.
- Revoked sessionReconnect must fail.
- Second principalNo Session or workspace leakage.
Route the symptom.
CLI refusalstartup policyDo not patch around it.403trust or capability scopeCompare URL, Host, Origin, fetch metadata, and extension state.randomUUID + no requesttyped RPC mintingUse localhost or HTTPS.connection lost + no describereadiness aborted before fetchProve the secure-context four-tuple.image-only randomUUIDdraft attachment IDRestore a secure origin.page onlytransport splitTest API and WebSocket separately.~3 s timeoutunknown emitterCapture stack before changing the guard.15 s helpsordering evidenceInspect generations and stream lifecycle.anyone gets inmissing identityStop exposure immediately.Primary evidence.
- Official Web CLI behavior
- Intentional all-interfaces refusal
- Trust fence and loopback-only capability contract
- rc.7 insecure-origin UUID implementation
- Typed RPC secure-context UUID call
- Draft attachment UUID call
- Plain-HTTP typed-RPC field report #3443
- Extension-rewritten Origin field report #3521
- Insecure-origin reconnect-loop report #4756
- Connection readiness guard implementation
- Slow-link field report #3413
- Official remote-listening discussion #76
Keep the denial and latency tests.
The full runbook covers SSH lifecycle, gateway ownership, remote capability differences, evidence capture, stream readiness, revocation, and regression gates.
Read the full runbook