The refusal is intentional--host 0.0.0.0 is blocked because the shipped Web carrier has no TLS or authentication and can reach Agent tool effects.

rc.7 fixed one carrier, not every carrier.

Generic Connection RPCgetRandomValues()

The rc.7 fallback works on an insecure origin.

Typed WebApiClientrandomUUID()

Host, Workspace, Session, Settings, and model calls can throw before fetch.

Draft attachmentrandomUUID()

Image selection has a second secure-context dependency.

The UUID throw can impersonate a socket failure.

Readinesshost.describe

The typed call mints an RPC id before fetch.

Shared generationabort()

The failed handshake closes both event streams.

Visible symptomconnection lost

Backoff starts a generation that fails the same way.

A loopback URL can still carry the wrong Origin.

Request authority127.0.0.1:3080

The URL and Host retain the serving port.

Extension rewriteOrigin: 127.0.0.1

A DNR rule removes the port before transport.

Trust fenceHTTP 403

The RPC and native picker never run.

Capture the actual Host, Origin, Sec-Fetch-Site, initiator, and extension state in DevTools Network. Repeat in a clean profile or with the identified extension disabled for this site.

Choose the operator boundary.

Recommended · one operatorSSH local forwarding

Keep both DSH and the tunnel endpoint on loopback. The browser sees a real localhost origin.

ssh -N -L 127.0.0.1:3080:127.0.0.1:3080 user@host
Deliberate · many devicesAuthenticated HTTPS gateway

The gateway owns TLS, identity, revocation, rate limits, WebSocket forwarding, and audit.

public gateway → 127.0.0.1:3080
Rejected · shipped CLIDirect network bind

Do not patch generated files or the trust fence just to make the port open.

--host 0.0.0.0 ✕

Remote does not mean local parity.

Ordinary remote methodsmay pass a declared Host and Origin fence
Settings + credentialsremain pinned to loopback
Directory + native openremain pinned to loopback
Preset authoringremains pinned to loopback

A proxy can rewrite headers, but that does not create authentication. If it defeats the loopback fence, the proxy becomes the real security boundary and must be reviewed and tested accordingly.

A three-second guard is not a stream guillotine.

A slow-link report connected Signal timed out to streamOpenTimeoutMs: 3_000. The timing is evidence, but the pinned rc.7 source shows a different lifecycle: the guard bounds readiness waiting and does not abort either event pump.

Measure one opening timeline.

01DNS · TCP · TLSNetwork or certificate handshake
02IdentityRedirect and authentication duration
03UpgradeStatus and first response headers
04StreamsOpen, first frame, close code
05HistoryCorrelation to first Session render

Compare the same disposable Session on loopback and through the relay. A longer timeout changing the symptom is a useful experiment, not root-cause proof.

Prove denial before success.

  1. Anonymous HTTPReject or redirect before DSH.
  2. Anonymous APINo request reaches the RPC bridge.
  3. Anonymous socketReject the WebSocket upgrade.
  4. Authenticated turnStream one bounded read-only task.
  5. Revoked sessionReconnect must fail.
  6. Second principalNo Session or workspace leakage.

Route the symptom.

CLI refusalstartup policyDo not patch around it.
403trust or capability scopeCompare URL, Host, Origin, fetch metadata, and extension state.
randomUUID + no requesttyped RPC mintingUse localhost or HTTPS.
connection lost + no describereadiness aborted before fetchProve the secure-context four-tuple.
image-only randomUUIDdraft attachment IDRestore a secure origin.
page onlytransport splitTest API and WebSocket separately.
~3 s timeoutunknown emitterCapture stack before changing the guard.
15 s helpsordering evidenceInspect generations and stream lifecycle.
anyone gets inmissing identityStop exposure immediately.

Primary evidence.

Keep the denial and latency tests.

The full runbook covers SSH lifecycle, gateway ownership, remote capability differences, evidence capture, stream readiness, revocation, and regression gates.

Read the full runbook